42208 lines
1.9 MiB
42208 lines
1.9 MiB
2024-12-14 17:54:44.662380 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 45705
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdb52
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412656823
|
|
ack = 1692640772
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x6a9e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\xec\xd4\x0eF\xd5nV\xbb \x10B\xf91W\xcaN9\x14\x16R\x01\xfc\xd6\xdb\xdfM8r\x05h\x16/\xc3\xd4\xf2\xfa\xcaK\xb9_\x85s\\jt\x12\x8f\x93\x835p\xf7\x9a\xa4z\xea6\x81\x14\x9c\x1a7\xf9\xdd\ro\x9d`\xb0}qx\xfaC\xa5.v\xd3\xbf\x10e\xf3\xb1,\xcf\x9eB\xb02\xacK\xe9 >z\xc6\x0f\xd5\x96\xe7Ri\xfe\xf1\xd9\x94~O.\xffR.<\xe7J\x9e\\\xa5\x19\xf3I\x86\xacm\xc8\x1b\xa0Kc\xa4\xed\xa1\xff\xd2\xb5\xa05\xc0(4\xc2\xb7;m\x10l\x10~W\r\x9c:\xdf7\x1b\xac=\x99[\x0e\xe3\xdf\xe4\x0f\xe1\xa4r\x96\xd7\xa94\xf8\x0e2\xd9\x86\x08\xc9\xb9\xe7\xdab\x866,\x84S"W_\xf2\x05\xac\xe6(-\xbc,\xad.V\xd1j\xb5=\xc4\xa1z\x18\x1e\xde\xa4'
|
|
|
|
|
|
2024-12-14 17:54:44.670497 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 49795
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcb58
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030874465
|
|
ack = 17610682
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1517
|
|
chksum = 0x5e8e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\xff\x80\x0e\n\x835\xbe?\x7f\x8a\x01@\xd3\xd4,\x17\t\x07\x93|\xfe\x98]qX.4\x97\xaa\x9cd\xa0\xfeL\x83k\x9c\xed\xad*\x08\x85\xca5C\x8b\xdf\x99\xd2\x1a\xdf\x10\xb4\xffW\xc6ri\xb9\xa8xk\xf0\x024m\xc1;q\xdb\xab\xd6\xe2\xf6A\xa7O\x01\xec\x92 \xc5f\xea\xbb6|\xb9:!3\x91%\xe38t\xd3\xc3>8?%G\xc3J\xee\xdb\xbc\x89\x18\xf8\'\xbc\xf2\xfb_\xdf\x12\x03\x00\xb1\x85n\xe9\xd9hm\xcdQ~\xd9"W\xa3\x83#\x9a\xbb\xe5\xc9\x99*X\x84\x8a\x08Hs\x8c\xbcl\xff\\^\xd3\xa4\xef\x19\xdd\xdc\'\xfa\x93\xa3\x9drF\x03\xb7\x87L\xc6\xe29\xa6K#B\x1b\x99\'Y\x0f\xc0\xb3\xb3\xa9$^EO\x12\xf2\xda\xdc\xe5U\x97iKM\xe7\xef^\xfc\xf3\xb9\xb1\xf3<\t\x84'
|
|
|
|
|
|
2024-12-14 17:54:44.704389 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16602
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692640772
|
|
ack = 3412657040
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2069
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:44.714593 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16603
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17610682
|
|
ack = 2030874682
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4139
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:45.038204 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https S
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 3487
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124376388
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 64240
|
|
chksum = 0x175f
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 17:54:45.138990 - Ether / IP / TCP 20.42.65.91:https > 192.168.1.11:40843 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 6769
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xdd1a
|
|
src = 20.42.65.91
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40843
|
|
seq = 2099794998
|
|
ack = 4124376389
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 65535
|
|
chksum = 0xf21b
|
|
urgptr = 0
|
|
options = [('MSS', 1440), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 17:54:45.147469 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3488
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124376389
|
|
ack = 2099794999
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 517
|
|
chksum = 0x1753
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:45.161497 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 557
|
|
id = 3489
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124376389
|
|
ack = 2099794999
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 517
|
|
chksum = 0x1958
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x16\x03\x01\x02\x00\x01\x00\x01\xfc\x03\x03\x03LN\xbcB\xedc\xbd\xf9\x14y4\xb7-\xfb\xdf]\x99\xba\xff\xfa\xcf\xaa\xe0n\xc9b\xa2\xed\xdf\xf6\xbe 7\x82\x80I1\xff\x98L+\xd6\x0f;F\xb3\xb5\x0e\xb5\xcc\xcaT\xc1n\xe4\x96\x9d\xce4\xcd\xd4\xa6;y\x00$\x13\x01\x13\x02\x13\x03\xc0/\xc0+\xc00\xc0,\xc0'\xcc\xa9\xcc\xa8\xc0\t\xc0\x13\xc0\n\xc0\x14\x00\x9c\x00\x9d\x00/\x005\x01\x00\x01\x8f\x00\x00\x00%\x00#\x00\x00 mobile.events.data.microsoft.com\x00\x17\x00\x00\xff\x01\x00\x01\x00\x00\n\x00\x08\x00\x06\x00\x1d\x00\x17\x00\x18\x00\x0b\x00\x02\x01\x00\x00#\x00\x00\x00\r\x00\x14\x00\x12\x04\x03\x08\x04\x04\x01\x05\x03\x08\x05\x05\x01\x08\x06\x06\x01\x02\x01\x003\x00&\x00$\x00\x1d\x00 s@\x19\x10\xcd\xb7\x8a\xa0\xb5\xff\xcf\xfd\x1f\xc9\xe0\xd66\x8b\xbd\t$\xe0J\xc8\x99\xbc\xc0%\x8d\xe9\xf3v\x00-\x00\x02\x01\x01\x00+\x00\x05\x04\x03\x04\x03\x03\x00\x15\x00\x93\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00)\x00[\x00&\x00 \x8d3\x00\x00mpB\xf1~/\x1aiC\x02\x17\xb4\xdb.\xfb'\xf0+\xf0\xa6\t\x89\x07\xd9\xbc\xd7\xaf.\x19\xa3\xcf8\x0010{;/8\x03F+y\x11u\xeb\xf7\xef\xb8\x82\xd2\x01B\xc3\x8a\xddOm\x0f4x\xeb\xa5\xfaV\x06\xe1\x15=\x1ec\x13\x87\x9c\xfa1\xfbqL\xe1\xa5!\xd5"
|
|
|
|
|
|
2024-12-14 17:54:45.234366 - Ether / IP / TCP 20.42.65.91:https > 192.168.1.11:40843 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 139
|
|
id = 6770
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xdcc2
|
|
src = 20.42.65.91
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40843
|
|
seq = 2099794999
|
|
ack = 4124376906
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 16383
|
|
chksum = 0xd38a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x03\x00X\x02\x00\x00T\x03\x03\xcf!\xadt\xe5\x9aa\x11\xbe\x1d\x8c\x02\x1ee\xb8\x91\xc2\xa2\x11\x16z\xbb\x8c^\x07\x9e\t\xe2\xc8\xa83\x9c 7\x82\x80I1\xff\x98L+\xd6\x0f;F\xb3\xb5\x0e\xb5\xcc\xcaT\xc1n\xe4\x96\x9d\xce4\xcd\xd4\xa6;y\x13\x02\x00\x00\x0c\x00+\x00\x02\x03\x04\x003\x00\x02\x00\x18\x14\x03\x03\x00\x01\x01'
|
|
|
|
|
|
2024-12-14 17:54:45.238707 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 477
|
|
id = 3490
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124376906
|
|
ack = 2099795098
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 517
|
|
chksum = 0x1908
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x14\x03\x03\x00\x01\x01\x16\x03\x03\x01\xaa\x01\x00\x01\xa6\x03\x03\x03LN\xbcB\xedc\xbd\xf9\x14y4\xb7-\xfb\xdf]\x99\xba\xff\xfa\xcf\xaa\xe0n\xc9b\xa2\xed\xdf\xf6\xbe 7\x82\x80I1\xff\x98L+\xd6\x0f;F\xb3\xb5\x0e\xb5\xcc\xcaT\xc1n\xe4\x96\x9d\xce4\xcd\xd4\xa6;y\x00$\x13\x01\x13\x02\x13\x03\xc0/\xc0+\xc00\xc0,\xc0\'\xcc\xa9\xcc\xa8\xc0\t\xc0\x13\xc0\n\xc0\x14\x00\x9c\x00\x9d\x00/\x005\x01\x00\x019\x00\x00\x00%\x00#\x00\x00 mobile.events.data.microsoft.com\x00\x17\x00\x00\xff\x01\x00\x01\x00\x00\n\x00\x08\x00\x06\x00\x1d\x00\x17\x00\x18\x00\x0b\x00\x02\x01\x00\x00#\x00\x00\x00\r\x00\x14\x00\x12\x04\x03\x08\x04\x04\x01\x05\x03\x08\x05\x05\x01\x08\x06\x06\x01\x02\x01\x003\x00g\x00e\x00\x18\x00a\x04\x9cI\xf1\xc6\x928\x87F\xdda\xd8\xa6\x8a\x08sZ\x8d\xc2\xaaL\xce\xf7\x96\xf0\x85\xb5E\xa4\xa5\xa9<\x97\\\x1a"\xc7P\xcd\xcc\xcf,$R}\xf3\xee\x12\xc1\x170\xa2\xb6~8\xc5\xfa\xac\xf7V\xa3\xc2RQ\x83\nR-\xac?\xc8=\x9ap\xa5\xb3L\xa6&\xb3\xdc\xa8\xafJ\x89\xc7la\x96\x94\x8b\x18$\xfa\x08h\x07\x00-\x00\x02\x01\x01\x00+\x00\x05\x04\x03\x04\x03\x03\x00)\x00[\x00&\x00 \x8d3\x00\x00mpB\xf1~/\x1aiC\x02\x17\xb4\xdb.\xfb\'\xf0+\xf0\xa6\t\x89\x07\xd9\xbc\xd7\xaf.\x19\xa3\xcf8\x0010H\xbe\xed\x1e\xd2\xc2\xe0\x10\xf5z\xbc#\xbb\xad\xb6h\xf4pMV$\x98\xe2,\xcbl\xb1\x87\x0f^\xc4)\ri\xc5\x13\x99,\x9b\x05\xab\x85\xb6\xc8\x8e\x08(\xcc'
|
|
|
|
|
|
2024-12-14 17:54:45.247336 - Ether / IP / UDP / DNS Qry b'gew1-spclient.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 31667
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64320
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 11609
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'gew1-spclient.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:45.252992 - Ether / IP / UDP / DNS Qry b'gew1-spclient.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 31668
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55006
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 257
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'gew1-spclient.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:45.266789 - Ether / IP / UDP / DNS Ans b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 125
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb713
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 64320
|
|
len = 105
|
|
chksum = 0x9081
|
|
###[ DNS ]###
|
|
id = 11609
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 2
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'gew1-spclient.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'gew1-spclient.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 185
|
|
| rdlen = None
|
|
| rdata = b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 39
|
|
| rdlen = None
|
|
| rdata = 35.186.224.26
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:45.279411 - Ether / IP / UDP / DNS Ans b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 174
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb6e2
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 55006
|
|
len = 154
|
|
chksum = 0x795a
|
|
###[ DNS ]###
|
|
id = 257
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 1
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'gew1-spclient.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'gew1-spclient.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 92
|
|
| rdlen = None
|
|
| rdata = b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
\ns \
|
|
|###[ DNS SOA Resource Record ]###
|
|
| rrname = b'dual-gslb.spotify.com.'
|
|
| type = SOA
|
|
| rclass = IN
|
|
| ttl = 201
|
|
| rdlen = None
|
|
| mname = b'dns1.p05.nsone.net.'
|
|
| rname = b'hostmaster.nsone.net.'
|
|
| serial = 1647020872
|
|
| refresh = 43200
|
|
| retry = 7200
|
|
| expire = 1209600
|
|
| minimum = 3600
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:45.290306 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 1567
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca83
|
|
###[ Raw ]###
|
|
load = b'\xc8\x00\x00\x00\x01\x084k\x98\x9b%:\xa7\xd9\x00@F\x00\xaaI\xb9g\xf5\xdd|\xcb\xb4\xec\x8b\xf9O\xd2\xd5\xcfX\xe2\xa4\\\x95D\xa6\x1f\xb8s#}$\xbdb~d\x90t0g!\xb0\xb0\x84\x91\xb8\xf1\x9d\x18d\xff\x9a\xd0\x18*U[\x14\xe5%Y\xc0\x98\x91\xa3\x0c\xaf\t\xdf \xc8vD\x89#j\xd8M~k6+-\xdd\n\x08\x1d\x8c\xf3\xd1M\xb92\x94\xe8\xd0L\xda\xf2\xbf*\xbe\x96\xc0\xf7zXk\xa5\x19+O\xfa\xc0\x8f\x80\xc8\xa3\xc6[1O\\\xbe\x00N\x199\xa8\x04\xb4\xd7\x16]\xa8\x02:\xa4\xe7\xd30F\xea\x19%\x81\xc4\x16\xe1`\xd4\xc5\x82\xd8h\xac~\xab\x0chh\x0fn\xc3[\xd3\xfd9?{\xef\x9d\xaa\xe9\xedi$\xf1\x91\\[\xc5\xc1\x99\x06!\xff\xc0\xe8\xf7fF\x0b\x9a\xe6\xc3\xaf\x03\xa1CS\x82\xde\x07\x026O\x9c\x0b\xd4\xaam\xec\xe3\xed@:\xddq$E\x1fL\x9f4\x8a\xd2\xca\x13\x93E\xe74\xde\x0bg+\xf8\x82R\xa0\xa0\x8aY\xe9\xc4)\xa9\x0e\x01\x80\xc4*\x1a\xfcs\x05}^a\xf6<\x16M\x1d<,\x10\xcc\x99yy\xfa/\x88_$g\x13\xa5\xfaA~\xf3_\xd4\xfbK\x9c\x19\x1b\x9c\x01$\xeb%e@\x03f\xf3\x96\xe5\x8a0c\xfe\x83\xb7\x9aj\xcd\xd4\x8fS\x9ba\xbe/W5\x05\xec2\x1d\xd0\x11\xc6to\xb2\x16\x9d]\x7f\xb8\x15x\xa7\x80\'\x97\x88\x8f\xcd\xe8\xd4\x89\xee\x8b\xc9FJX%{B\xdd\x9e\x17i\xb6!\xb3\xd9\x81\x94s\x9e\xf5j+0\xf1\xe9wn\x8d)\x83\x94\x84+\xe2\xaflGj\x02\x92R\xeeX\x8d\x8a48+\x7fV\x08\xff\xe7k4_\x91[\x1c\x98\r\xf66r\xa3o4H\xd0\xb2\x92}\xd0\xcaa\x91&\xb0OD\xd6<ty7\x9b5\x13$\xa4\x18J\xb1\x03\xfdq\xbbn*\xe5\xfdR\xb3\x17\xd9K\xb7f%oG\xa9\xb2UI^j\x82AD\x8e\rq\x11\xd2#\x08\xcaV\xb8P\xa7u\x9a\xbf]\x1c\xda\x08\x8e)5\xd5\xce2\xeaT\xb9\xf5\x19J\x88-\x97\xa8gF;lj(\xf6\x85U\xcas\xf4\x1a\xfc\xc2\xb75k}\x8d\'\xac\xe5b\x15\x88a\x94v%_\xbf\xfc\x80-\xf8\xbc\xdf\xe5\xa1\xdb\x17{\xb0\xee+\xba\x02)\xc6\xa3U\x0f\x0e\xc6Y\xd0\x99|\x11\r\xc8l\xc6&)4 \xe0Q\xf8\xd4\x82T\xeaJ\x89\x98V\x94P\x93p\xbd\x82W\xa1OT\x05\x19\xbb\xbd\xdc\xcef@\xf6\xb8\x11^\xb9\xfaIi\x1f\xce}\xe93D\xbc\x08\xfd\x1f~D\x07\xe0\xc1!_?\xe6~\x8e\x10\x9af`G\xb9\x16\x11\x90\xf9\xe3\xb6\xabp\xa9\x93C`\xa2\x9aD\xd5\xf28\x01\x9c\xce\xa4\xa6\xb8\xf2\x80q^d\xd6D\x99\xe5o\x14\xff\xd2\xcd\x16\x94\xd7\xe6\xd1H_\xcaqO0\\\xe4\x0b\xda\x86\x03\xafS\x870q\xcev\x11d\xf3\xf4@\x1e\xdc\xef\xda\xd9PZ\xff\xc6Id\x8fQd\xef\xa5\xa2\xf9\x18\xcdDK\xed\xe4m?C-Vn|\x06p\xb7\x94\xf0vR\x86\x0cI$)\xacb\xb4JV\xe9\xb2x\xcf\x01\x05\xe31\xb3\xed`\xe5]f\xcf\x83\xcc>\xe3O\xf0\x95\t%d\xb6\xfb\x8a\x1c\xa1P\x05n\xf8\xd0\xd2\x0c\xbe\x1eM\xf4\xe4>\xd6-\x8d1\x16\xc9X\xa6\x8bU\xaf\xef\xa0\x1a\xc9\xffV\xe3\xc1\x877\x92%\xb3K\xd5\xad\x0c\xb5\xb8/C\x82\xd5\xdau\xc9\xaa\xac\x15s\x0e#\xaef\x8b\xe4bkg;\xe7\x0c\x89\xc6\x015\xba\xc0kl8-\xfd,s"\xf2\x02\x93\xd4\x9ad\xfct\xe20\xe3\xb5\x00\xdc\xc7>\xc2\xda\x8b\xd5%?\xd9V%\xcck]YJ\x94\x13l\xa9Sc-6l\xeb\xd1\x94P\x8fni\xe6O\xa1\xbfhyE\x0b[\x83w5iH\x7f\xd9E\xbf"\x12\xb2U\x13=\xba\xd0\x8e\xafP\xc4\x95\xac\x91,\x0e{"|\xcc\x83\x0b\xdb\xddx=\x16\x95\xa49\xbd\x03\xa5\x8co\x90oFb\x85b\x9a\xab\xae\x0b~\x1fa/\xf0\xfa\xd9\xe0}\xd0\xd9\x9af\xfe1\x8dr\x07GH=\xfc2\t\xea\xfa\xa4\xa2d\x08.\xef\xda\x85\xe4\xbc\xdb\x85l\xf1\xf4\xbb\xbe\x07,\xbeb\xee\xfe06\xa3\x88\x8a\ti\x9c v\xbb\xf9\xc9\x7f\xe6\xb2\x90\xfal6\x8e\x9e\x85+\x87\xf9Y\xef\xfd\x80\xe9\xe8\xb2\xfe\xaa\x95]\xe0\xe74\xd3{\x96\xf0.aT\x1dd.\xcc+{\xd4#\x0cT4\xe5\xbfI\x9b\xed\xf3\x94\x956\xf6\xf5Y~\xd7\n\xd3k/\x85\xcdc\xf3,\xc5\xa2\xa1,1\x1f\xeb\xbf\x90\xbb\xc2g\x16Z\x81\xe2Xqg9\xfa\xfe!H\xb5\xa1kh\x00\xf3\xa2\xfb*N8n\x86\xcb)\xe1\x8f\x9e\x04\xaa\x1e\xd1,;`\x013ea\x07\x8f\xac"8J\xb6\x91\xa15\xa7\xa8\xc6\xeaGJ\x9eFW\x7f\x1aj\x85\xf1m\x0f\xf6\x00\x82\xc0TP\xea\x00#+\x9e\xb1l\xd8\xe6\xda\xa0\x12+EE\xbc8\x1a\xec\xa9\xd5)d\xe0P;\xbe\'it\xaf\x8b\xef\xb7\xb1\xf1\xe1\xbe\xe6`T\x11\x13\x03\xaf\xaf\xe9\xdc'
|
|
|
|
|
|
2024-12-14 17:54:45.301471 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 1568
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca83
|
|
###[ Raw ]###
|
|
load = b'\xc7\x00\x00\x00\x01\x084k\x98\x9b%:\xa7\xd9\x00@F\x00\xaaI\xb9g\xf5\xdd|\xcb\xb4\xec\x8b\xf9O\xd2\xd5\xcfX\xe2\xa4\\\x95D\xa6\x1f\xb8s#}$\xbdb~d\x90t0g!\xb0\xb0\x84\x91\xb8\xf1\x9d\x18d\xff\x9a\xd0\x18*U[\x14\xe5%Y\xc0\x98\x91\xa3\x0c\xaf\t\xdf \xc8vD\x89\xd8}Bs\x84\x82\xa3\xbd\x98ER\x08\x97\xb2\xd2D\x05\r\xe6\x158k\x94\x06\xc2#\xc2\xd1\t?=\x88\n1\xbcO\xac@\xce3\xdb\x84~\x1c\xc7\xfco\xc0e\xd2\xaf\x95@G\xfd\xe7\xf7\x81\xf9\x94\xdd)HC]\xce\xac\xe0\xa8\x08\t\xd4\xdc\x0c\x0f\x85>W\xce\xcd\xe6\x8a\x81O\xc8L\x97\x9f\x90\x7fBjR\xf5\xa9\xcc\x9c\x1d=\xfe\x16\x8dj\'\xca\xe6\xf6\xb3M^n\x96\x02Mj\x0ew\r\xef\x88u\xd5\xb0N\x7f^~\xf9\x1e\xc1\xc3{\\R\x1b\xb3>n\xccx\x82;\xc7l\x1f\xd5\xa6RJ\x9e!\x03\xbb\x85y\xbco-\x01\x9c\xbb9\x1fK\xf1\x13\x01\xa1I\xe0.JaR\x02\x90u\x96+U\xae\x08\xdf\xddx\xd3\xdaH\x9e\xdc\xeb\xe0")4\x13_>>\x9b\xa5\xbfr\x8c\x89R>\xbat\xc2jhh\xd4L\xc8\x93\xdc,`\r\x0e\xc9\xc5U(&\x15\x17\xb6s\xb9=L\xa2\x9d\x95\xad\xfb\xfbl\x02 \x01\xf6a\xb0\xfd(\xcb\xc8\xfd#\x7f\xc6\xf8N\xf3\xed\x0c-\xdc\xdb\xca\x7f\xb9\xf9=\xf1\xe8hY\x0e\\P*\xfb\xeb\xbdxi\xd7w\x9c\x97\x0c\x05\\z\xaf\x1f73\xe6\x7fQu\x9ci\x17\x89\x9b\x7fC\x98\xeb\x19\xca\x94C|\xd2\xe9-,\xda\x9c\xb5h[\x0eW\xa0XQ\xd0M\xce\x0en\xb5\xb7\x14\xbf$\xc2\x99\xef\xae1\xbf\xc6\xc1\xc2B\x8f\xb9;\xca\x8f\x0cjKf\xd9\xb7-g\x8d:F\x81\xcd\x10\x99I-\xe1<\xeba\xe5GJ\\\x88:\xc5\xd7\xba\xf8\x01bNrq\x92\xafF\xd1\xef\xa9d\xbd\x18\xdf1\xb9$E\xee7\x8db\x98\x0cW\xd6\x8b\xe2\x99,\xf6;\xa6\x9dW]\x96\xec`\x0b\xc5~;`C\xf0\xf0w\x04\xe1\xfe\xa5\xf7\x99]\xee\x88-\xd2uXyb\xe9\xfa\x90\xa3g4\xddC\xb0LxhG[\xfc]\xdf\xe0\xf0\xe9^\xd3\xe7\xaf\xdc0\xe4\xb7.\xed\xcd,\x7f\x98\x8f\xe4\x1d\xeb\x807"5\xdf\xc6\xe3\xdc\xea\x8b\x11\xed\xcd.\x12\xcf\xd1\xdb\xedbf\xea\xdf1\xe0\xb7?c"l\x03#\x85\x11-\x1b\x81\x00Yw\xa7_\x89\x9d\x9a\x1d\xcd]\x7f\xf9\xdfZ\x1ew\xab}\xea\xaa\x81[\x8e\x0f\xda\xc9i\x1a\x8c\xe6\x82\x06\xe3\x8c\x0b`\xca\xc0\xc0\xa8\x830\x00\xa2C\x12\x0fO\xcf\xdf:\x11\xb8\x8d\xd1\xf0D\xfaR\xde\xa3\x14%\xf7\n]N\xb5c8\xc4\x8c)\xf3\x87\x11\xe1oh\xdd\x8eFT\xd4\xe0m\x08Q\xb5\xe3e\x05\x1c\x1e\xfa1\xba\xb7\xe6\x97Ac\x89t\xc4\xa7\xf5Nf\xc6\xd6K\n\xff\x9b\x84f\xc5\x9e9\xc7\x9a\x0eH\xf3\x9a\x0cr\x8c\xae\xa6O;\x7fk\xfd\x8e\x02=\xe2f\xc7vI\xf3\x18\xd51\x8e\xef\xab\x86\x9f\x8fx\xbeZ\x19\x99\xf3\x93\x92\x0c\xed6j\x89\n\xd0\xfcV_\xf8\xa4\xf1.\xd1\xf9\xf3\xe2`\x1c[\xe0]>\xf4\xd7\xe8\xc0\xd3\xb0\xca\xbd\xa6\xfe\xa5\xc3\xc6P\xed*x]\xdc(}\x05~\x8c\x84\xdd{\xe3\xbc\x91\x18\xcch\x9b\x80c9]\xd4XKv\xb4[\xdfmg(.\x92\x1fSDk\x03\xeeh\xac\x0f~\x8be \n=\xfda\x9fH\x8b\x13 8Hz\x80\x82\xab\x82\xb2\xd0K\xc0U7Q\xcfb\x16\xa1U-\x8e~\x98iW/\r\xd66C\x02_s%\xb1$&a\xa3\xf0\\\x18z+=\x9fe\x8d\xa4K\x85\x929.\xc4Y\xdc\x9d%\x0e\xd1\xf3\xffg\xf8\t\xd20k\x1cE\xda\x19\x80P\x1d\xa1\x17\xe2^\x01\x90;\xddq\xc0\x97\xe8\x1f\x8dD\x12\xffE.\xc7\xeb>\xa9\xb3h\x80G\xc1\x0c\x8f\xc2s\xb5\xed]$\x81|\xb6k\xe8\xc9n\x88.1\x0b<\xac\xde\x92\x8e{\x1f\xe1\x7f\xe8\xcfh\x8a\x80\x8e\xd1U\xd1\xe9\xd4\xa0\xfb\xde]\x0f\xdc1\x14\xc2<n0\xd0\xdd6\xe3\xd8)f\x04[\x96\x8f\xc7c\n\x11|\xd8=\x06,\n\x9d\xdb\xfb]\xd0\x9f\xbe\xb3\xd3\x06\xe5r\x19\xf3\x12\x80\x82\x8f\x1b#b\xf4\xef\xc9\x82\xde\xbc\x89\x06\x88\xeb\xe2\xe7\x0bp(IY\x95\xbek\xfdj7(\xacT\x8e#W7\xc9(\xedi\xf6>8kx\x91\xd6\xeb?\xc7P\xb3\xd3B\xb29\xd5\xc3O1\x82\xb2\x8f\xc0\x0f\xad/ \x90\x13|!m\xc0\xf4\x16\x93\x14\x8d\xfbp\xa0\x83\x18\xa4\xa7\xc4\xbfQ\x99\x86,\xd3K=)\x87\x83o\xbd\x98\xf4~;d\x80\x93\xa2\x88\xf2Jk\xd4\xfd\xd6\x9b\x1e\n\xde\xfb\x04\xcag\xcb\x86\xba0\x03\x07\xbb\xda5\\\x1f\xbd\x17\xb1"D\xe2\xff\x97Q\x8f\xaa\x11\xc9\xf0\x00\x0er\xdci\xc9\xbdC\xb07\xf5\xec\x8a\x99\xa1\xe8%\xf1\xbb\xdbl\x92p\xa8\x9c\xaf\xc5\xfeUg9\xe1\x8f\xf56\x8f(I\xb8\xf7\'\xec^'
|
|
|
|
|
|
2024-12-14 17:54:45.307108 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d21
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 48
|
|
chksum = 0x75c1
|
|
###[ Raw ]###
|
|
load = b'\xca\x00\x00\x00\x01\x00\x08\xf4k\x98\x9b%:\xa7\xd9\x00@\x16\x9c\xa1i\xfd\xadZS\xefkq\xda\xf3\xf8\xc1*^\xe8;_\n\r4'
|
|
|
|
|
|
2024-12-14 17:54:45.317736 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7867
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 1258
|
|
chksum = 0xac60
|
|
###[ Raw ]###
|
|
load = b'\xc0\x00\x00\x00\x01\x00\x08\xf4k\x98\x9b%:\xa7\xd9\x00D\xd0\xc0\xa7\xd70\xab\x114\xe9J\xae\x18\tL\x0e\x94\xe7PMA\xa8\x9fF\'\x90\tc\xc3\xb3X\xbe\xc6\xee|\xa9\xce\xd2\x9c\x99\x9d\xc0\xc0)>\xc7\xb0\xbd\xe6k\xa8\xe14\x1cu\xf8\x946@\xb9\x95\xfc\x14JVz/\xb7\x00\x9f\x99\xd0\xcd\xe2%bp\xa1\xd4\xf9\xb2\x97\x83\x86\x8c\x0f\x97[\x882\xabS\xb3\xe4\x14\x9d\x88\x11\xc1\xaa)\xe1\x8b;\x0f\xca\xcet~\xffxI^\xed`\x12\x1c \x9e\xf2R\x83\xc2\x96~m\xc1/\x98\xcb\xf8b.\x90\xbb\x8b\x9d\x89\xd7\xc8\x92\x91a/\x9f\xd1O#\xa6\xb6\x8fw#\x15\xbfgh\xed\x9cO\x91\xd4\x9f%\'8\x83\xd7\xa8],Z0\x01>h\xbc\x19\x14db\xab\xffe\x00\xa0\x92\x7f}\x19\x01?a\xb0\xe5u\xa4<\xed\x01\xf7\xaa\xb1[\x92nJ\xf5\\\xc1K\\\xbai.\x8c\xc0A2\xd2\xc9\xb1\xc6\x81\x8b\xbf\xf7\xc3\x91\x825\x90.R \xff\x88\xe6{Ah\x9aC\xfay)\xe0=\\\x90\xdd\x1a\xeb\xd1\x84Q\x81\xbc\x90\xc8\x97J\xae@\xb4_\x7fk\xb0\x9bf\xccL\xe9\xa4\xadP2\xdf*\x99ys\x9b>\xc4\xe0\x87\xf7\x17.O\xbeW\x0f\xd5P\xf14\x12}W\x13\x0c~V\x1fq:\xa8\xe8\x9b\x0f\xd1*\x10\xa8\xdal\xe5\t\x0b\'\xfb\x18\xcd\r/\x19)\x07v\xfbB\xde;(l-\xfc3\xbf16zE\x13\x84\xea\x04#\xd8\xae\xf3\xb3\xab\x15\x93\xb9\x08\xf2\xa4{y\xee\xf7\x85T\xcc\x1fd\xdd+\x8b\xe6W\x89\x05,\x93\xe7\xb8\xc7z\x9c\x19\x83\x983$\r\x86w]\xde\x8f\xbd!%\x96\xecC[\x05\x87f\n\x94\x87\x05S5pde/3\xaa\xfe\x07!\x1c\xcc\xf1\xb0\t\x8d\x07Z\xbafr\x94jP\xa0\xdc\x85Z\xb4T\xf1\xd8\xd1?\xa7\xfc)C\xa3\n\xc8\xd0\xdd8\x97DhG7Tm\xc6\x99\xe7=\x9e0\x90\xf6\xf4\xbf\xa1\xa1\x9d\x93\x87$\x12MZ\xc9\xe7\xd0:\xd1\xafG\x88\xf5(\xa1b)x\xcf\xb1\xc7Rp\x91\xdb\x00\rD\xd1]\xca\xa0\xe81k\x19\xf6L\xda0\xf9<\xec\xff\xd7\xc6q\xbb\x9a\xd6v\xb1B\x94X\xb0\xb0\xa1\x9c\x86\xe8X\xb7\xd6hP\x90%~\x12\x89\x9a-\xed\x1fc\xa6\xc0\xdf@\xbd\xdb\xd8;\xd4\xe0L8&rU\xec\xeb\x12x\xd96\xb7\xbcr\x8e\xc7/\xdf\xaf\xf7\xb1D\xdf;\x0f\xe2\xa3\x06_\x10\xcf\x96\xdd\x14\x9co\x13\xdc\xfb\xd5\x8dq\x97\xb4\xe2\x8cN;-u\x0b%\x06\xa8\x02S\xba\xeam\x96KvW\xfd\x0b\x80\xe0kR\xd4\x96\xad\xa7\x917q\xae\xd9R\xdba\xd5\xc4I\xa1Q\xa9\x8e\xdf$=\xc0\xdf\x1eI\x1e\xd4M\x95\xbdA{GP\x9e\x16\x01bg\x98\x14t\x87\xafo\xfdP\xc6Ha\xc6*\xb7\x0f\x0bW\xe2\xe2>\xa0*k&\x85\xdf\x04{\xb3LoAYY\x01\xb1\x02\x1c\x98\t\xed\xab\xf3Up\xe6\xd9\x1b\xfb\x1d\x98\xb8\xe6-|\x1e\xfe\xb1\x04\xa1X\xcf\xe6Q+\xdf\xef3\x8d\x84\xb0\x8f{\xdc\x87\xc9\xd5\xea\x81"\xe2\xc8&\x97&z?\x8aIq\x85T\xed7\x87\xeb\xef\x84\x1f)K\xe1\xea\xe9hrA\x07\xfd\x93f\x90<ue\x1e\x85\x8b\xf99\x0c!\xe2\xad\xd4\x03\'\xe9\xc8\\\x96:^\xa7\xab\x96\x1e\\\r-P\xba[\xe6N3#\xeb\x9b\x15\xcf\x94"\x11M=\xf8-H\x01\x80D\r&\xd6j\x1f\x1a%\x02M1R\x85E\xec\xfc\xbeCil^\x82z\xd9E\x8a\xc9\xd0\x15\x87\x14\xb0\xd8\x11\xc9\xb2\x8bQO\xb31\tz\x8c7\xbcP5N\xde\xe7\xd5\xec\x88T\x1aH\xe1\x11\xea\xbf&\xc0-\xc2*\xc4\x12\xcc\xe7;n\x86\xd0\x94/\x83\xa55\xcfF\xc4T\x16\xe7\xf0\x04|\x10X\x0772#\xfe\x0e\xf1[pk\x19\x9c\x0cXpd\xf2\xd4\\\x03\n\xe6A \x8d\x14\xad\xda\xc0B\x15\xb5\xc7\xc3\xfb\xbb\xa2\x82\xf6\x08{\xe2\xb4\r\xb3\x86\x95\xc6k\xf9\xd7l\xdf\x7f\x15\xcc|5\x8b_2V\xd7L\xed=\x0cni\xad3\x8f\xb6\xeb\xfd\xf9\xce\x04AHgt\xeco3\x8d\xee\x90\xd1\xbbM\t\x80LV\xac\x0b\x8d\x17\xbd;\xe5<\'EK\xa7e\x0eB!\xb6\x84\xe2\xa0f\x9f\xa6\xef\xb5\xcf"$\xc1\xf8\xe0\xa6\xbf\x0b\n\xe9\x15\x83\xfc\xfa_\xd0\xe3\x91\'\xa2\n\xbb .l\x81;\x1f\xb3)\xafq6\xa6\x9d\x87\xeb\x90\x1b\xb5\xe1v\x94\xb5Q\x9aZix\xda\tU\xa1mo\x9au\xb0\xca\xa5\x82\xebl\xcc\xfb=\xcfqKg\xae[j\x03\xa4\xec%4\xf1\x82\xcd\xb9B\x97><\xf7\xbd#\xbe\xcd\xcb[\x00zD>j\xe6\xda\x1e\x86\xef\x1a\xe1\x97\xb1\xde\xf0\xa5\x9dX\xa0@\xf7\xcc^\xe6,\t\xae\xe6\x900a&\x81J\x1d\x94\xf8\xb9\x0eHx\xb0p\x02\xc9\xe06vdI\x0c\xf52\x9dWV\xc3(\xd2\xc1ud\xa6;\xf3\xd4{\xdb\x1d\xfa\xb9\x14\x86#\xdcE\xbd9\xc0Vf\x9fv\xb9\xe6\xe1\x13\x92\x0fl\xef\xa8\xc3\x02-\xb6'
|
|
|
|
|
|
2024-12-14 17:54:45.321136 - Ether / IP / TCP 192.168.1.11:40844 > 35.186.224.26:https S
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 1569
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40844
|
|
dport = https
|
|
seq = 2444971193
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 64240
|
|
chksum = 0xc5ae
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 17:54:45.329338 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 1570
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca83
|
|
###[ Raw ]###
|
|
load = b'\xc2\x00\x00\x00\x01\x08\xf4k\x98\x9b%:\xa7\xd9\x00@F\x00\xaaI\xb9g\xf5\xdd|\xcb\xb4\xec\x8b\xf9O\xd2\xd5\xcfX\xe2\xa4\\\x95D\xa6\x1f\xb8s#}$\xbdb~d\x90t0g!\xb0\xb0\x84\x91\xb8\xf1\x9d\x18d\xff\x9a\xd0\x18*U[\x14\xe5%Y\xc0\x98\x91\xa3\x0c\xaf\t\xdf \xc8vD\x89z\xa3^\x13D\x84\xf6/K\xf6A\xfcf\xca;\x0b\x1c}\xf1)\x9d6\x91\x93\x1e\x06\xeebQ\xa3\xeb\xebg\x8d)\xf0L\xee&\x97\xe4\xcc\xa6s6PD&\x89\x99\xc1a\xe2^\x16\xb7\x92\xef\xa8\xf6 ;\xcdS\xda*\xe2 \xd8\xed\t\xa1\xda]\xc4\xdf\xca\xe3\xb3\x8bn\xe4\x9f8|r\x97w\xd4;\x8a\xfa{\xf4\x7f\xe4\x1e5\\\x8d\x12\x1f\x1d\x80G.\xe4\xcb\x03\xa4H\xa0\xf3\xe6\xa0\xac\x96\x16,\x1eE\xef>AXP\x8f\xb76u\x81`\xaazFs}{V\xf8\xe1\xe9\xb4N\x1c\xee\xb7\x9f\x97\x11\x84\xd4\x06\xa6\x0cm\x8f\xf6\xadl\xfd\xc6\x0b$\x8a\xb5l\x08\x1e\xed2\xa4\xa395\xaa\x89d\x95\xd6Z[\x94\x962\xcbl\x96\xab\xdeFn\xaaSY\x82"\x06\xa3:\xf2\x9a\xc3\xc1\xba\x92\xdd\xc6\xf4>\xadJ\xb0\xd4uLV\xff\x80\xf6\x87\x9ds5\x1c\x02\xeef\xa17\xbb\xde\x8b\x9f\xa9\x12h(M\xbb\xb5x\x95\xd6\xd4\'\x1f?(\xdc\x89.\x06k~5\xfc"\x0e\x19\xcf\xaf\xb4\x87\xa1\x88\x0f\xcdr\xb4+Mj\xedC\x9b\xcf\xc4\x0c\xfd\xd6I\xce\xc6\x84\xb2\xf8\xd3\x1abw\x0c)\x8d\xe8\xcf\xa9\xd9R\xc5b3\xf8\xb0<\x99_\x16e\x19\x07\x01\xeb\xdc \x00\x88\x01X\x81\xd9f3|\x94\xcc\xaf\x18\xe8\xb0d\xb5\xc3a\x8d\x9c\x8d\n\xb1\xa3f\xb1H_\x1d5\xf4\n%\x9a\x03\xb9\x12\xaa\x82\xfdZ\xa5\xbf\x0b\x81D\xf0\xe6\x10\xa6\xd9\xf6E\xbb\xb1\x94\xf3\x08\xfdY\x130}\x01\xa2\xa5\xd5\xed\xfb\xc8e\x9b\x1a\xd6qjO{\xfe!\xb9J\x9c\x7f\xd1\xfbB\xe2\xef$\xda\x1dI{\x88t\xda5\xcd\xde\xdb~\xc8\xa9\xcc\x0b\xdf+\xbf\xa5\xc4A\x14X\x02\x17\x15\x14\xc1\\L\x9f\xaf\xd9m\xae\xbf\x14\xa0\xedN\x8c\x1amv\xa9\xa1\x81L\xaeVD\xe0\xbc\xf6\xd9\xe8\xa0Z\xfa\x05\x08\xac\x0b\x8bs\xb3\x1e\x1a\x1f2\x03\xcb\xd0\x93\x11c\x0e\tk\xf2j\xc4K\x0c\xb1\x1b\x12(W\xfb\xd7\xa5\xa2\xc4!\xea\\Z\xb6C\x12B~\xbf\xec\xcdB?h\x90\x18\xbb_\x11ZSa:\x9f\xf1\xff\xdb\x12H\xba\xf4D.5\xa6\xa8>\xdd\x16\x86\x02\xbe<\x1a\x8c\xefLr\xd4\x04\xff\xbf\x9a\x99D\x8a\xbbv\xcaz\x1f/\xbbk\xff\xb6\x97}\xf4X\x07zwu\xf3\x82\xa7\x11\x8b\x0c\x02\xb3\x01\x1d\n\xdb\xa8\xb2|\x00E\x1b%\xcb\xf5\xe1\xb2\xb1\x1f\x0b\x11\xac3\xe5\xbb\tZ\x881\x8e\x84QMk\xf8l\x08\xf0:\x13\xb8\x10\xaao\xce\x1f\xb6\x1en\x88\xad\x1c4\x8f\xf7\xf3\xb2\xde\xbcb\xf9!\xc5<\xe2r\xb5\xc5\xe3hX\\fk\xa0\x1dt\xc3\xa1\xde\x0c\xd7\x9ae2\xf3y\x1f#\\#\xdf\x99f\xdd\xd0\x85\x12\xdd\xbaZ\xa8\r\nX\xab\xf3\xb0D\x00\x00C\x14=:_\xa9\xf7%4\x97G\x8a\x95\xafMO\x1b\xf8\tN\xf9G\x92}\xd4w\xa0\xd5\xa6+\x1b\xfa\xed\\-\xb9\xdd\xb8{\x94C\t\xe4\xe5\x1d\x86\xb5A\xc0/\xdf$\xc8\xe8\x07\x89\xa1}\x06\xbdb\xeb\xbd\x9cTd\x9eN\xcb7\xce\xday\xb2\xe3\xdb+6\x9d\x0fxF\x00\x07\xbf\x04\xc6\xc2nh\xc6\xb2\tY\xe1\xc8\x970.}4\xda\xcb\x8b\r\xda\x8a\x9c\x00\x8f\xa81\xeb\x07\xbda\t>*\xca4F\x8cv\x02\xf1|\x8d\x0b\xc9\xc9\xe3\xd7E/\x92\x7fC\xb1-|dB\xf3\xa1\xd0\xb5\xf6Z\xa3J\x1e\xee\x0f,G\x0b+\x16\xb8\x0e\xfa\xf5\xe3t\x8a\x1f\x15\x01\x7f\x8a\xb5\xad\xd2\xf6\xc5A\xa9f\x04\xa1\xd0\xe6\x11\xbe+1\xda\xdd^\x185#\xae\x948\x9a\xac\xb9m\x1a\x89\xab\xa6sN-\xbf\x8f\x13T\x99\xb9\x8fdNzB\xa2\xb3\xd7,ag3\x8d\xe7\xb8A;\xc9\xb5\xcdm*\x8d\xd4\x16a\x00\xe1q\x99\xa6\xd4\xb0\xa0|\xfb\xa1%\xc18\xedR\xb4\xbc\xda\xb7(\xbf\xdc|,\xb9\xf7\'z|>w\xfd\xc9\xe0r\xe3\x02\x04\xfd\xb1\xe5V\x95\x8f/\x1f\x9c:\xefj\xe4\xe8F\x98\xfe\xfeD\x1c\x7fK\xfe\xe4\xaf,\xef\xf6\x17\xfc\xf0C7\xa4\xa4\x8b\x12r\x1e\xe3\x93\xa8\x87\x9c\x00r\xf7b;\xbe\x1a\x92\xd7\xa2H\x8a\xd2\r\xea\xf6\xcdH\x07\x1c\xc3`\xec\xc5\x0f\xe3\x96\xc4\xc4\xfe\xc4\x9f\r#gj\x81\xa1\xe1\x12\xf7)\xbf\xfe\xcf\xf9\x82=k\xdb\x8b5\xed1Qg\x98\x99\xea\xe4\x8e\x13Io\x10Jbc\x03\xcb"\xbe\xcf8A\xe8Q\xfe\'\x05\xe0\xe33q#\x8a\x01I\xfe\x0e1\xe3L\xae\xd5\xa9\x1d\xcf=y\xe6\x9a\x90\xd3\xb5\xfeQ\x97f\x0e\x8c\x87T\xcc\x11\xdc\xca\xdc\xber\x07\x8f\xc8\x02\xe4f=\xc7\xa4\xf5\xce\x07%\x11\x94\xc9T\xab\xf6\x18\xa2i\xff\x87\xdd&'
|
|
|
|
|
|
2024-12-14 17:54:45.335965 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7867
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 1258
|
|
chksum = 0x271a
|
|
###[ Raw ]###
|
|
load = b'\xcf\x00\x00\x00\x01\x00\x08\xf4k\x98\x9b%:\xa7\xd9\x00@o\xfco\xcc\xca\x1a\xd0\xb2[G\x98\x9d\xd5\xafm\'\xe9\x13\x99\x9c\x9f\xc6\xba~\x1b\xa0\x87\xf6\xd7D\x8dS\x90\xb9\x83/:o\x11\xcf\x1e\xd6N\xab\x06\x13\x86[R\x10\x92FU\xe9\xa8\xb6@\xed\x03#f\xff\x1a\x94z(N\x15\xfe\xc9M|)\xc1\x0e/\xa5\x903HR$B\xdey\xaf&\'\xe9f\xf9\xd1\x8d\xd0\xcf_\xb8\xb4\xca\xc5+bq\xb3\x14\x95\xcdu\xd2\xa0\xb1/\xe0\x00\x00\x00\x01\x00\x08\xf4k\x98\x9b%:\xa7\xd9DP\xb4)\xc7\x84\xbe\x8d\xfah\xf6\x1b\xae\xc9\xe2/\xc8\xaf\x19\rH\xfd^f \xf91\xc4\x88\x8c7\xf4\xc7_\x06]1\xa3\xfd\x9cT\x83*\xa8\x1c\x085\xdc[\x8e\x93\x18`\xc5\xc9\x92\xa3\x13\x8fh\x93\x96m\xb2k\x0fAD6N\r{u\xad\xd6\xef\x02\\\xbc\xb38l\xbd\xe3\xf5\xaf\xcd\x9e\xb4\xdei\xb6\xac\\\x90[\x8b\xbf\xeeJ\xfevb\x1b\xf7TS\xa3u&\x08\xdc\xd7\x9f\x8a\xca{\xaf\x1cTk\xe8\x1a\xb6\x8a\xa8{\x0b&\x95\x7f\xae\xe6\xdb\xf6fK\x86\xa4\x18\x9c\xaa\xe8\xc7Gdj\xecq \x10\xdf\xf8\x9f\xfc/\xe4\x1cl\xd2EnA\xf7\x8e D\x02\xb1t\x11\x9aS\xce\xf2vJ\xc3V\xa6\xdb\x85\x82E\x8e\xc0^\x0fc\x8bo\xf2v\x83q\xfa\xcaF"`a-\xcez\xabQ\x924w6X\xe0\x06\x12\xd95\xdf\xc1\x8a\x12!=\xbax\xa4\xe5h4\xd6B\x1d\x01\x87\xc9+\xc2\r\xa6\xb1\x0e\x96t\xb1\xd8\xa6e\xf0$J>\x85{\x113\xf0zE\xbffY\xc0\x89\xbc\r\xae6\x0e\xff\'\xa6\xf5\xf4 \x06/i\xe1\x13\x02c.\xb4\xce\xf6\xb0\x95\xcb\xe0\xe5\xd9h\xe5\x8b\x98\xd9\xc4qN\x17\x88>/\x83\xeaO\r\xca\xdb\xcc.C\xe4\x91\xd8!\x8d\xd5\x98i\xbd\x9b\x0f0\x06\x0bfbU\xd2\x0f\xc1GP\xd1\x15\x11.\x8d\x89)\x92!\xafe\\\x8c\xa7\xab\xdd\x9d@F\xc8\x8e\xd6N\xd9\'\xc74\xc4Z\x88q\xe9\xfdV\r\xed\x8dX,"_V**\xe4m\xc7\xebNR\xae\xf0\xbf\x05\xdc}\xd5\xcf\xeb\x9bS}qqH2\xc4\t\x1a*k)u\x8c\xb7Y(%p\xf4\xe6\xe7P\xe9\x9a\xe3\xdd\xb6E\x15\x1d\x80\xc0\xe9\xcf\xdb{\xa3e\x05\xfeW\x8e\xc2k\xb7\x85\xc2U\x8c\x89I\xd6{5\xb5uP(\xd3)F\xa3\xd2E\x18\xc5\x7fq\x901\xbdA\x98\xd6\xe6\xaf\xffS\xbfSF\x9b\xfd\xfb[$\x101\x86I\x93\x8a\x1c9\xda\xac\x88\x9e\xa1:\x14ib?0\xfe\x1dm\xf4\x93\xae\xa2\xcc\xab\xf1\x8a\xff=(\x92vo!&^j\x1e\x1c\x1f\xff\xe0:\xec\x86\xbc\xe1\x87\xa2\xff\xb78\xea\xce\xfd}\xfcL\x8f\xefy\x00 a\xb8[\x1d\n\xbb\xe1\x0c\x8d\xb9\x08\xc3$.\xbb\x8d\x1e)\xa1\xba\xc1\xc2\xda=\xddk\xe7&\xafl3\xe4C\xeb\xb8\x89\x80*\x03\xb0\x0b\xff\xeeG\x05\xd67\xc8\t\x9fK\xf2\x8c\x88\xe2l\x012M\xac=x\xf4I{E\x1a\x01\xed?H\x08\xa6\xfc\xec\xf5\xc6V\x96\xcexR"\x12\xf2\xb7l\x8d\xb7\x89N\xb52\xf4\x9d1\x06\xa2T\xac\xdcJ\xba\xcf\xdf\x1bDx\x15"\xbe\xb2\xe7A\xf1Z7A\xfb\xa6d2\xce\xef\xe1\x1e\\tQ\xc2\xc6\x00\xe3\xe2;\\\xab\x11^=\xc8j\x01\xa3(\xde\xban\xa9\x9aH/\xd1\x7f\\\x1a\xa3\x7f\xe8\x13\xcb\x8c"\x94\xd0\xfd\xb30\x9e\t\x85\x88e\x1f\xd2\xc8\xb9(\xbe\xc0\x07\x8c\x08\x94\x9d\t\x10f\xccB\xc9\xc3\xa3\xa8t\x8d}\xb7\t\xb5\x05\x7f\x01`<|A\xcd\xba\xc6\xa1\x06r"\x0e\x81,\xb2fy\xb1\xbey\xe4\xd4\xce[EjZd\x17\x85\xd5\xc4\xf1\xa5\xbb.\xd5~\x85K\xe9Eq\x83Nyyp\xae\xfd\xae\x16eu\xa2\x18\xe14\xbc8i?\xfa\xd9\\\x1d\x8e\x851n\x04lz\xf5QK\xf2\xa7P?\x01C\xfa\xeb@\x90G\xab\x00r\xc6\xfc\xa3\xc0\xb8\xcbj\x83\xa7\x9fVH\xb7m\xe0\x9aPH\xa1\xf1z\x05\xee:\x05\xc6|b\x95(\xa0\xda\xf1"\xe7Q\xfb\xa8\x01q3\x0e\x1c;\xad\xaas\xfb7m\x80#\xb4\xdb\xfa\x8e\xad\xfb\x05}_\xce\xffY\xcb\xcd$j~_G=Q2\\\xcd\xaa#IC\x01\x8e\x03\xe8YK}\xacZr"\xa4\xad\xd6\xfe\x9f\x9a)\x0e\x93\x7f\xd9r\xa6\xdc\xdeh\xb0\x8f.\x89\xc8\xe0\xb5a\xd8!i9\xeb\xc8k\xf2\x9b\x93GrZ\xa7/1z\xcc\x98\xe1\xc4l8\xc7\x1f\xa8&\x80\x97v\xe5\xf2\xd3\x15\xfcH\x04\xd9\xc5+?\xff\x92\x0e.<q\xbe\xaeZ\xca\xbc\x0c\xbc\xa4fyK\x86<\xc8\xc2\xb4\xce\xf4\x14\xb5\xb6v\xf52J\r\xbe\xf4\xef\x92\xf5\xd8\xe5\x9104\x18Y\\\x83\xab\xe5\xbe\xc0\xcc\xdb\xa3\xe3Z\xcb\xc2i\x03i\x0bm#k\x10\xe2=\xe3\xeePNT\xcb\x96\xd7\xa5\xc6\xd5\xbe\xc0\xba\x84\xbb\xf6P\xe3\xabk\xb35\x9b\x0c\x12h:\xfc\x1c\xdeq0{\x95\xea\\\r\xa3\xed\x8d\xe3\xbcg'
|
|
|
|
|
|
2024-12-14 17:54:45.342706 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7867
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 1258
|
|
chksum = 0x7c42
|
|
###[ Raw ]###
|
|
load = b'\xe6\x00\x00\x00\x01\x00\x08\xf4k\x98\x9b%:\xa7\xd9D\xd1\xd8\x1c\x03/\x08\xc9\x8e\xa2\xe3\x1e\x18\x06&\xae\xbe\xaa\xbf\xde\xeft\xfd\xc8@\xcd\xc3\x04\x8f%\xd6I\xbe\x15\t3A\xcf\xc2c\x1b\xb7\x8f\x0f\xf0\xa8\xd2}76:\xe51r\xc7\xb3\xf4\x1ac\xca\xd4\x9eB\x0e\x06\x9d,\\\x1f\x89\xba\x9f \x15\xec\xd1"\n\x82\xc7G\xf6\xbf\x13\x9a\thq\x1aRn\x9d\x07t\x11I\xc9\xf6\xe0\x1ccI>\x98m\xbd\x04\xedT\xb1\xca\x93\x10Z\x1e\xe51}\xad\x10\x10\xa1\x13\xe3\xe0\xf5\xfd!M\xf3\x94\x7fm\xb0\xb5\xd3O\xa9\xd8R\xb7j\xef\x15\x118\x8e\xfb\x05\xd7J6\xba\xbbP]\xe3\xd2\xbc\xdf\xd0e\xb9[\xad\xe3\x87\x0b\xed\xe9\x14#\xef\xc2ad*\xecn\x99\xb3\xbe\xd1Bl\x81\xdeN\xb7\x0f\xb4\xc9\'\xf1\xaf\xa9\xf3\xae\xac\xb5\x92cU\x95\xb8r:7\xcd#7\xf5\x82\xf4r\xd8X\xed\xc9\x85\xfe\xd92\x137$j}b\x18\\0\xedw\x98\xf5\x93\xa5\xc1=ub1\x1c\x03\xfd$G\xfaA\xa4sb\x85\x15V\x07\x8fUjow\xfe\xa9\x99\xe0\xd6\x10\x0c\x13!\x99\x00\xad$\x1emh\xbc\x10f\xcf\xf7w\x8ccl\x99\xfa\xec\xb5\x8a\x9e)\xdf\x16Q\xab\x95\x8f\xae\xe3\xf1r.\x12E_\xa3\xca\xac]\x1c\xc8c\x04\xb9\xfa2\xcd\xa7T\xc3;\xbf\xbb3?\x8eIT]\xb4z\xa1\xd4\xee(\xed\x1d\x9f\x02\xd8\xa3\xf2G\'\xbd\x89\x93\x80x\xe9\x87\xb9\xd0\x19\x9d\xc7 s|\x8b\xc4\x0e\x0f\x1c\x9a\xde\x155 \xa8\x8e@/\x81s\n|\xc6RE\xd6\xc3\x10\\\xa5\xc77\xd7\x1f\xab\xe85\xd1#\xfb\xa5\xc1P\xad\xab\xb6\xf2\x89\x8ey{MO\xd9\xc4v\x0f\xbbu\x10.d\xaf\xae<\x06\xbb!+h\xfe\xd6\x01(\xff\x9c\xe0p1\x9c\xf5\xf3Eh\x00<\x8d\x1c~;\x9ea\xf0\x83\xa2\x00s\x9f\xb4\xabR,\xb0\x87M\xb2j\xd0\x08\x0cB\xea\x8d8\xc2\xf5kU\xb4\x80:\xc8Ba{\x9c\x8aXl\xe2e_=\x0e\xb1\xc0t\xe2\xfak\x98\xe4\xb5U\xed\'L\xa0vw&\xfa\x8a?\xe8\xcfAw\r\xa6*\xa7\xc8\x03P%\xd6\x11DD\x16|\x97\xdc\x9e\x88\x8b\xe6Y\xf4wC\xe7\xfb\xa6\xb4\xb08s\\E\xe5\x08\xed\x01#\xe4\x94f \x1b\xb6\xc3A\x8cR\xc8/Q3\x1a$\xb1\x12c1\xd0\xce\xb8*\xa9$\xbdb\xd3\xe7\xfc2\x05\x10\xdbT\x965Z\x87hvD\x06\xa2s;j\x13,W\x8d\xe4j.\xb4\x85\x18\xcb\xda\xb6X\x1c\x1d\x1au\xd8\xf0\xa588\xaa\x1c\x0eu\xed\'I\xebU\xb7\x04\xcel\xbb\xba\x1aZ&\xe8f\xde\xc5CW\xea\xb6\x1c\x18\xda:\xaa`\xad\x8c\x7f\xb8&\xe2 \xae\xae\xc34\xcb\xa4&4\x9b\x0c\x98\xbf\x81\xa9\x18\xe6\x8e\x89\x8d\xdb\xc0U3\xd3\xd3\xeb\xa9\xda4\xb5F\xb7\xf3l\xf3Ux\xe7>\xab\xe0\xb9\x8e\xd4\xcb\x01\x13\xb7\xb7\xb9\xb9\x0bn\xdduL\x08z\xff8\x07\t\xb3\x9b\x88E\x08\xe9p\xe1\xd4<\x8cy\t\x9d\x154o\xd4!Ur\x06\x08\xf9\xe6u\xd8\xbbo\xa2\x9a\x08\xa1h\xa0\x9f\xa0)X\x8b\x8f\xb0.\xe0\x1f\xf5V\xc5;\xd0\xe4\x1ak\xf4\xe5F\xf0\x1e\xcd\x85\n\xfbG1\xec\x90\xa8i?\x97_\xefA\x90d\x04y\x85\xf4\x1cSC\x96\xcav\x1e\x1f1\xe70\x13\xe0\xd7Q\xcd;d\xc4lV\xf1\xf0-\xaa\x06d\xd3\xee\xc2\xcb9\xfc\t&wk\x06e\x80H\xcd\x83\x0cF\xe0>\x90\xf509\x92\x94;;O\xbb\xfbN%\xfd\x11U\xea\x93I\xdfF\xd9\x84\xb1xDO\xa0U\xd5\x9d\x18\xb4\xea\x037\xf2\x9c8!\xc1\xea\x00\xdf\xcf}X\x0e\xd9j\xa4g\xd7QX\xef\x04\xfa206\xce\x98CH\x9dX\x95\xa6\xecft\x16`|\xc9\xb4&\x8eh>=\xbe2\x16\x13dP\xe7\xcb\xe4\xc6\xafS\xa3\x1ag\x07nD\x10\xae\xefR\nnv\xef&\x19\x16Z\x8eY\xe1\xb8/\xfbcG\xc2\xf3E\x18\x0b\x1a}<\x1c\xb4\xbe\x8e\x03\x9aT\'\xac\x05\xb1\x7fp\x81\xe7\x86Y\x13\x94\xf6\xd28\x8b\xf0\xa3\x83\x0c\x88\xa7\xb5b\xb0\xf5\xc3KI\x03\xb5\x9d\x0f>N[\xb5*\xceQ\xc2\x98z\x19\xc6\x18\xe0\xb4O\x8c\xcc\x9d\x98\xffs}\x0c[\xba\'\xeaF\xd0\xd5#\x05\xfbZ\xb4\xbe\xf3\xfe\xf7\xf4\xb5\xef\xcfyN\xbe\xb67\x89\x8d/\xc6.\xf5\x8eN\x95\xef\xe9\xffoC\x83\x98\xda\x95\x82\xc3\x13\xcb\xb0\xcd\xa9\xa5\xcf\x83\xe2\xc5\xb9\x96\x05\xbc,\xfc\x81\xd3q\x0e\x1dQ\xc1\xafj\x9d\xff\xe8\x9f\x93\x1fS\\\xcd@\xa65V\x98\x95\xc5\x1au\xbf\xec\xdbCr!R\xefE\xbd\x8fX\x8f\xb65\x80\x86\xa1\xa6\x01\xde\x96\xe8=\x8d\x9a\xb8\xfc\x91\xfd\x0bQ\x93\t\xd2\xa0[:\xbe\x88\xa2\xa5\xef\xb2B\x9b[a\x1e~\x18\xf7\x12\x88w\xd1\x068\xaex\xa6\xcd\xd3\xaf\x0e\x91\xd4y\xed\xbd\x9d\x1c\x83Cl\x17V\x95\xf4\x9d\r&\x0e\x9e\x04\x05e\x03\xe6\x9d\x043\xd1\xbfrx\xb0q}\xd9\xf4\xc6\x8e'
|
|
|
|
|
|
2024-12-14 17:54:45.355729 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 530
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7b53
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 510
|
|
chksum = 0xd2e2
|
|
###[ Raw ]###
|
|
load = b'\xe1\x00\x00\x00\x01\x00\x08\xf4k\x98\x9b%:\xa7\xd9A\xa8\xf2\x01_\x89y\xdb\n\x11\x1d\xa3:\x1e<\xf1\xfd9\xd7\xa4\x02k\x04\xe7\xd2za\tWS$yyhl\xa9\x88\xe4\xf0\xeeTHI\xdd\x7f3\xc7B\xf2\x13\x1d\x13\n\\\x91\x05\x81\x92\x99\x93\n\x8b\xd4w\xbf\xba\x1fA\xd3\x9d\x80\xd4\xddy\x1d\t\x83S\x19\xcc\xeb\xf8\x9aE\xf9Ks\xc8\x0b9\x87\xac\xa2V\xc8\x00F\xd9\x1d\x80\xf7b\xef\x89\x9b\x0f|\x816\x14\x90\xc9&WGH\x05\x13F\x0e\xfe\x00\xb5\xcb\x15\x85\xdck\x06\x8b\xfduL\x84f\xae\x8as\xfa\x85\x13]\x0e\x1b\xbc6+=\xbc$\xfb\xa4\x95\xa2\xf4\xcb\xad\xfb\x92\xb9\x9f\xf8\xda\x8bo\xcc\xdd\xaf\xa6\x12=M2d\x8c\x11^\x90\x9c\x87\xb4\xc7\x11\x9d\x8c\x0c\x12\xe1\xde&\xb0\xa8B\xd3\x1f\x1a2lA\xe6TOO\xec\xae\xa3\x91\xeb\x92\xa9?QU3\xc53\xc83\xf1f\xa5\xea\xf6h\xb6M\x9f|\xbf%(\xc9\xa5\x0f\xb8\xe8:\x1f\x1a\xc9\x91N\xe8\xf7"\xf8j\x80H=ik\'\x17*\x81\xeat\x8c\xa81!@\x11\xf7\x03\xa2\xa3\xc5hrN\x91\xa5\x0e~\xa3\x8a(\xcb\xf3/t\x006>\xc8\xf0\xe6\xc1\xff.\xe8\n\xa9\x14\xd5|\xa2\x930E\xde\x04\x86\x12EE\xddK\xa1\x03^\xb5\xb2\xd7\n\xa9^:\x02\x9fB\xa3H\xba/\xb7\xd0\x9dS\x9e\xf7\xb1\xd7\x03\x83\xbd\xe2\xa5\xea/\xc0L\xe5D.\x0b#\x9e\x9e\xe9=\x93\x8e\xd0\xf0s\x1a\xff w\xee\xb2\xe6k\x9b\x07Nd\x15\xe6\x8a$\xd9\xd1\x17\x88\xc6\xa7}\xbd\x19\xcf\xac\xdd1~\xecr\xc2\xf5\x9c\x9b$\x8a\x1a\x02\x9enAT\xa1x5\xb8\x00T\x1fm\x89xs\xd47jF\xb18?F{u\xe7%0D\xe4w\xcdW\x8b\xe5%5v\xae\xf3\xcfZ\xbdx\xcf\x1dV|\x83u\xa3\xd5g8\xe5\xab\x86\xf9\xdd\xf6\xbf\x82\xcb\xa8\xac\x02I\x1b\xba\xeeT\xef\xd6\xd2\xca<c\xa1\xc7\\\x9b\xc9>\xb7\xf9\x1chCa'
|
|
|
|
|
|
2024-12-14 17:54:45.365207 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 67
|
|
id = 1571
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 47
|
|
chksum = 0xc5c8
|
|
###[ Raw ]###
|
|
load = b'\xed\x00\x00\x00\x01\x08\xf4k\x98\x9b%:\xa7\xd9\x00@\x16o/\x87\xa1_0[m\xe8W<QU7\xb6p!El\xe8\x18#'
|
|
|
|
|
|
2024-12-14 17:54:45.372467 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 196
|
|
id = 1572
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 176
|
|
chksum = 0xc649
|
|
###[ Raw ]###
|
|
load = b'\xe3\x00\x00\x00\x01\x08\xf4k\x98\x9b%:\xa7\xd9\x00@H\x10\xbf\xdea\xf5Xl\xf8\xa6\x93x\xae)\xef\xc0\xe1\x9c\x96+\x9fa\xabn\x83\xe2y@\xee\x99+\xe4c_\xafn\xd0\xea\xb9\ta\x85f\xd7\x9eP4g\xac\xfb\x87\x16\x9d\x10t\xb6\xee4\xeaHhZ\xcb8D\x01\x89\xdd\x8d\xf7\xabL\xec]\xf4k\x98\x9b%:\xa7\xd9\x9e\x13\xb3\xab\xdcDn\x97\xff\xf7\x14:\x88\xc0 \xdeY\x9b\xf7\xac\x95\x1a\xa3\x9c\x03\x88xD\xc5bxzU@~\xf9.\x12C\x81:)\x10\xea\xf2\xd6\xeexA\x91$\xb8\xcf\x1a;\x8b\xd9\xe4\x1b\xee\xdf\xcd|E\x07^\r&\xba\x0b'
|
|
|
|
|
|
2024-12-14 17:54:45.378378 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 895
|
|
id = 1573
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 875
|
|
chksum = 0xc904
|
|
###[ Raw ]###
|
|
load = b'M\xf4k\x98\x9b%:\xa7\xd9\x1c\xf5\x14.\xb4!\x1c\x8fp\xbctZ/\x89\xd6\x136\xac\xd5G\x80\xf1\x02\xd3o7\xe0\x92\xc57\x9a\xa4\xf0w\xbdp?\xa7\xa5\xf1\xd7\x88\xba\xc4\x1f\x9e6f\x8co\xa0\x89\xc4\x82/\x113i9;=E">\xe0\x8e\xd8\xca#S\x1c\x831\xa3\xd8?\xc377^\t\xd0}\x89\xda\xa8\xbc\xfbr\x1cM\x97\x96\x1ao\xf5\'O\x9e\xcc\xfc\xad\xe2$w\xd6=9cY\xce\x98\x86\xc5q1G\x00B\x13\xe8\xe1\x8c\xe5\x04L\x8a\xea\xb7Mr\xcc`\xec\xb9\xb2\x0fw\x06\xac\x0c;_#\x88\xedX\xd6\xcbl\x8c\x910w^\xb5\xa3n\xe0\x14[nTE\xbb\xf62\xf4\xa6\x9d\xd7:\x8cr[\x8fw~\xd4`mh\xb0\xafl\x9dCuF].\x0b>\x99\x8c\xecI\xd6m\xcc\xc0\xc51m\xd1\x0e"\x88\x02\xd3\xe4l\xf1\xb0\x7f8\x85\xb3$\x12\x1dP\xa2\xe9\x14\x81\x8b\xd3\x1da\xbbiO\xb6\xc3\xe6\x8e=,\x8c\x93E\xbe\xcc\x8e\xeb\x84\'\xe49\x1dK\xde\xc9>LK\x99v\n*\xa7\x8e\xa3\x08`\xf7zv\x95\x91\xac\xee%\x08\xd3\x8euR\xb0\xf0\xec\xa9\xd3\xee55Q\xa8k\xc1(fhlV\xfd\xdf\x86\xecS%\xb6U@\x83\xab1\xab\x98N\\\xb6s\xb3g\x9a\x89\x18\x1fM\xec\x05\x86\x00\xe5\x85\x0b3\xc5\xebeq8\x82\x0cM\xefl>\x13\x01\xe1V\x1b\x0f\xd5\x8dg0-\xf7\x1d4\x04\x0fkm(U@\xaa\xf3\xe0qs\x9bA\xff\x9f\x8b\x9bq\xfe\xe4=.-"7iHl\xf7\x96\x8a\xff\x0bs\x0f\xe7\xd5\x87\x95\xd6\xf5RX\x9f\x84\xb5\x08+!\xc06\x1fk\x8d\xdb\xd8\xb4^\x1eR\xf0\xfa\xc5e@\xcd\xd0f\xa7&\xab4]f%\x95\xa4\xc4\xa0\xd4@\xe4\xed\xcc#\xccZ\xd6\x81\x9a\xe5E\xa6\x1b\xb4|\xb9r\x84\xfb\x03\x13\xa1\x16\x08um\xde.\xaa\xd7\xc5>c#~\xe3B\xc3HHK\xb8\xd7\x17\xc2\x94=\xaa%\x06\xae\xf2\r\x85!\xcdEz\xd4\xc2\rEDoN\x91\x05E\xa8R\x85\xe6\xe7a^\x82\xb0\xb8q\xa6M\x90\x84z\x1b\xa5\x96\x17\x876xf\xc5y\x9f\xce\xf9W\xa2\x1cHN>\x11\x92\x92\xec\x86<\x13\x9c\x04\xe5\x99O!M\xd1;~\xfb\x95$\x82\xe5\xebm\x0e\xde\x97c\xdd\x0b+Ym\x08\xcf\xa8\xaau\x97,T\xdeA\xad\x15\xce\xe8\xf3\x03\x92\x1b$2O\x97\xd6\xea\xc5\x0fS2> \xbf\xfcz\xd1|\x1d\x9c\xc6K\xaf\x82ml\r\x06\x9f\xf9\xb4\x95\xb6$\xc9>l\xb4\xd5\x02Y\x1d\xae\x14\x17d\xf6\xd4HYv\xa0\x8dL\xe3~\xb8\xd1\xa7\xc7Vrz\x8a\x83\x00d\xcc\xd6`-\x9c\ng\xfea\xbd\xd8\x17\x8f\xf7\xb6u\xe1a\xa4\x98\xa1?\x96g=I\x0ew\xfd\xb3$\xbfy\xdf\xf3j\xa5\xacw\xdd\xee\xb0Pu\x9ao\xe6T9%\xcbR\xc71\xdc\x01\x81\xf6t\xdc&)N\xda\xaf\x08\xb4\xed\x95\xb7\x1aS!`[e\xfa\xfc>R?K\xf2\xae\xdf\xaeTT\xc9?\xf6f\xc7\x0c\x1es\xff<F3\xb5I\xbe\x80s9\x01{\xaa\xa2J\x10\xe1\t\x17.\xf9\xa2\xbeY\x95p[\xb3\xbb\x05\xe6"gD6=e\xcb2\xa2s\xa7\x924\t\x84j\xea\xf0\xddH\xa0x)\xac\xf7)n]K\xba.m\xbf\xab\xa9\xe1\xe4\x073z\x9d\xd7O\x89O\x14\xe2\xd3,`V\xe9{\xa3\xfet\xde\x87\xe7Lf\x13\xd7~E\x17\xad\xd3\x17\xd9\xa1\x12\xd0\xed8'
|
|
|
|
|
|
2024-12-14 17:54:45.394728 - Ether / IP / TCP 20.42.65.91:https > 192.168.1.11:40843 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 4420
|
|
id = 6771
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xcc08
|
|
src = 20.42.65.91
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40843
|
|
seq = 2099795098
|
|
ack = 4124377343
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 16381
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x03\x00\xbb\x02\x00\x00\xb7\x03\x03\x87#|\x9bW\x9do\xb6F\x8e\xac\t9Yc\'`\x0ce\x8ba\xc8:\xfa\x84\x14\xa3\xdb\x02\xd8\xe0\x89 7\x82\x80I1\xff\x98L+\xd6\x0f;F\xb3\xb5\x0e\xb5\xcc\xcaT\xc1n\xe4\x96\x9d\xce4\xcd\xd4\xa6;y\x13\x02\x00\x00o\x00+\x00\x02\x03\x04\x003\x00e\x00\x18\x00a\x04\x8c\x82\xd9\x88\xa6tF\x07\x19?/\xf7\xd8\xc0\x88\x13\x91:\xfeILT+5/G!\xfc\x91\xc2\x8c\xd4}\x1d\x01bpJD4#\x1c\xa4[\x19>U>\r\xe1\xb2.\xe74\x91\xd8\xa4\xbd\xd0U\x91\xcdd\x0c\xbb\xfbAr\xec\xad\x8dH\xeb\x1fR\x8e\xf6r\xf5\x1e\xc392AJ\x85b\xb3\x02}\x8c\x18\xad\x10\xb5\xfd\x17\x03\x03\x10\xed\x9e\xa9g\xb1\x83\x11\x88Yb\xa3\xee[\xe4\xb5\xb8"\xbb\xfeEZ\xc0\xbd\xca\xec\xa3\x03:\xf1\xd7\xdc\xa8\xf6\xd5k\x04\x88\xdf_\x85\x88N\x86TA\x19xhN\x15c\x9a\xbd\x9f\xbeH\xf4]\xcadK\xe2\x8b\x1f\xe5D\xb4\xdb,{\xf7N=\xbb\x99\x19\xce\x81\x83\xfft\xf1\xe8\xbe\xa7\xd2\xd2\xc1/\xb9\xaf\xe3\xf7\xf3\xd3)sc\x80\xccLD\xcb\x9b\x84\xfd\xcb\xea\xf8\xce\xba \xeb\xe7\x9f\xa1G9\xe4sO\x95URK$E\r\x11\xe1HWp\xdds\x92\xa4\x86j\xe4\'\x08\xe9\x7f\x08\xa9\xa0\xac\x121a\x86\xc4/\xc6\xcd\xdbP!>\xa6c4o\x9dPT\xc4\xbb\xfdt\xb4\xb0\x90\x83\x1bhb\x9f\xb3r\x87\xcaq\xb0G\xd7b2\x0e\x06\x9cS?7W\xcc\xfeH\xb2\xbf\xa6\xb7\x8d\xc6\x14\x0c\xbb\xe8\xc5{N\xcc\x0c\x07\x9co\x1e\x91?\xcb+\xb5L\xc9r\xf0aK\xb9l\xd1M\xf0\xe8?\x03P\x82Q\x95\xbbF\x017\x19\xd1\xbf\xe8\xc3o\xb8\xcb\xe0\xbd\x15W\xa1\xfc\xe5\xf1vBD\xdd\x85>\xec\x9c\x81\x10\xae\xed\xabg\xaa\xbe\xe6\xaf\x92x\xf3\xebW\xe9\x13/\'I\x08\xf7(\xb7\x84\xc4t~\x8b`k\x9e\xf9z>\x7f\x97\x05\xd1w\xdbL\x9c\x93F\xaa\xdb\x99\xe80\xc1\xf7\xfc#-\'\x95P\xe4\x12\x80\xc9\x9b\x00\x90\x9c+\xf6D=\x03n\x9d\xb2F\xd9\xd5~\x03\xd5\x13\xe1\x0e#\x14\x93\xe9\xcc\x04\x01b6\xaby\x10\x88\xb7\xed\x16P2\x96\x1fg\xa2kf"\xd4\xa7\xa7\x13\x17\xd4\x9e\xbd\xa8\xdb\xee)y<e\xdf\x8c#f\xd0\xbdZ2k\xd2>\xa2Y\x1a?\xf3\x12\xe0\xd2\x91lX\x85Q\x9fX;O\x9e\xf1\xd3QC\xf8\xc2t\xa6\xb1\x05\xc4\\\xb5\xa5/\xb1\xaf=`~\xe4=bz\xf0\xadma\xeeL\xd7Euu\x9e\xd4\x92\x96-k\xfb\xaf\x89\xb1V\x17\x93TvG\x11\x9a\xb1-\xa6\x80\xab7A\xd8\x8az\xd6\xe7\x13\xff%\x93s\xc1\xc7\x94\xacG\xc7\xa0\xb3a\xff\xf7)\xce\xaaY\x1fz\x9a=\xe3\x89\x15\'R\xc2!\x03\xd5\x15\x85\x8c,\x07\xb9\xbbt\x17T\xb18^4YV\x9c.2~\xc7\xfa[%l\xc5\xee=I\xc2K\xe7#X\xb9\xc4U[\xa9%\xa7\x0c\x82\xc0\xd9\x91`\x0e\xc8\xe8SHd\x1b\xa6\x0f4\xf4x\xf2\xda\xb3\xbe3,\x94A_\x12;m\xf0!>\x8d\xeb\xce\t\xfdv\xcf\x93$\xe8z\x8f\x12\xdc\x90\x13\xde\xc2\xdb\x0f\xa3 \xd7\xfd\xac|\x8cmK(y`\xea\xcc\xdeI\x15\xf4Z\x16\xf7\x15\xed\x9a\xc1\xc2\x9d\xc7/\x0c\x80\xafgO\x0fvn\xea\xe0\x9f\xac\x16Ie\xcf;\xbc3Z\xb7\xd8M+L\xe1\x87\xf6&\xb5O=\xbc\x10\xb9U(p\xd7PE\xfe7\xcd=\xbf\xf9<\xe6\xec\xc2\xbb\x1c\xd2\x95\x8bZ\xf8>\xe9\xaf\x95gAA4?d\x95[\xe6\x1f\xda\xc1\xb7!\xdf\xdc\x96\xc0\x1e\xb3\xa6\xd3vw\xc4\x95\x14i\xc5\xaa\xf3J\xaf\x10\xf3\xca\xf5\xeb@\xbcWi\xdd`\x1b2\x85\x1a\x9d\x98\x08\x02~\xe3\xb7\x9a~\xe1<\x88\x989\x96\xd0H\xe1\x04\x96\xc3G+\x1by\xa2D\xf2\x8d\x11\xb3_\xc6<\x17NI\xddpfv\x95\xd0\xf9\x07N\xc2yrv(\x85H\x08\xb4\x83\x1fv\x8b6\xa40/\xb8L\xd3\xf6\xc9\xa3\x0b|\xf7\xecc{\xc1\xfd\x92\xf6\xe4`\x8f0\x05i\xa0\xad?&0ww\x9ft{\xde\x0e5\xe7(&\x02\nD\x07\x8b\x90d\xf8\xdb0\xcd$\x13\x91Q\x86\xa4F\xf4\x03&\xd5Y\x938k\x97\xa3\xa2\x0f\xe9\x86\xad>\x16\x8a\xf4\xb3\x97M\xc3\xe1\xdd&H\x16\xc4\xd0\xe0NrE\x01\x90D\xc1\xfc\xbf\x8d=X\x02\x84\x08\xc6\xa7\xc9T\x0c`\xa0\xcf\xe5\xff\xdc\x04\x03]-\xec\x90rC\xe5\x9a\xb7\x0bI\x08\xf2\x11\x83\x1c0#\x1c\xaa\x82#\xbb\xae;\xcb\xdaXM\xd4\xeb\xd1\x93\x88~2w\xa9\xf1\x87\xbd\x1a-\xf3\xc1y\xdd\x90g\x8eE\xc6\x19\x97q \x99\xd0\x8b\xd9+\xa1\xee\xff#u\xfbT\x90\xeavw4\x8f;\xc3\xe3\xc4+:Kd\x13\xf5\xc1\xab\xb7\x9et\x95\xfa\x0eb\xc7\xec\x80\x0f\xfb\xdd\xady\x803\xd4\'\xb5\xd7_\x89\x8d\xc8\xddm\xea\x89|{\xc3\x85\x0f@\xb8Z\xa4{\x91\x87@\x8d\xed\x18\xdd\xa3\xbbj\x14\xd8_ely\xa23\xc9\xb8\xc6(\x8c\x04|\x18\xb7E\x9d\x07\x9a\\Lq\xdc\xfa\x9ahYZ\xb9Q\x04\x89\xbdKh\xf1\x10\xbbM\x9c-\x80t\xa3\x03(\xfd\x90\xfd\x85\t5\x8eR\xfe\xcb\x8c%\x1c<\xb4\x15]\x95\x16M\xdd\x88 d\xd2/.\xf4\x02T\x96\x94\x8e\x87\xa2\x7f\x83\xb2z\x96\xfc\x14*\xd8\xa7\x12[X\xf2\x1957\xa1\xbf\xf9\xf1S\xfb\x95Dq\xc2\xef\xc4a\xd4\xab;\xb0o\xba\xb6N\xbb\xde\xa7obz\x99\xa4\\24\xfa\xa6\x17\xa2\x86\x81\x02\xde\x80D\xf5\x85\xads\x96\x1f\x99k\xbcX5\x17\xd7\xb3\xdd\xb6\x1d\xdf.j~ \xcaj\x92\x8c\xed[g\xdb>B\xb9\xac\xd0=$\xf1\xc3\x1ema|]\x8b\xd2$\x93\t\xfas\xeb\xe9\x82Z\xf7\\\xa6?m\xdb\xfd(\xa2\x15\xb7\x96\x8f\x90\xb8\xce\x8a\xadO\x8b\xa6\xba=\xa7\x8e\xde\xb3Z\x91\xd9\xa1;\x17\x14\x9c\xf3\xd8s\\F\xb5\xa6&\x8b\x03(\xcfq1\xbb\xeeT\xf7\tQO\xe7\xa9\xe6#\xa1\xae\xb5\xe7R\\\xf6\xbc\xba\xdd\xbc\xdf\xc6\xbb&\x00\xf7\x94gGH\xc3h\x86\x8d\x0e>JU\x9d\xc0\x03zV\xfdv\xf7c\x88\x83\x7f\xd3\xd0qj\xdb:PX\xd7N\xf9\n\x88\xafv\x8f)\x0f|\x88\xf9f\x88?n\xaf\x03r\xd7\xfe\x84\xdf\xff\x89u]\xa1\x81\x86\xfe2\x14\r\xfd\xcb\x19\xbb\x94\xe5\x12\xdeW\xe0^l\x03\xff\xda\xdf\xe7#\xb6P\x81\xe7\nM\x80=\xfe%\xe4+;w\xfe\xab1\xedr\x85>k\x01\xe5\xc9%\x81e\xefK]\xe0\xbf;\'\xf5\xf2\x1f+Ms\x12\\\xc5\x15\xf54\xc5\r(p\x0c\xf5[\xdb\x93\xc0x\xb1\xb0Y\xa4\xaf\xfd\x9ccS\xc4\xff\x98"=\x98\x99w\xa4\xf8n\xe3\xa1\xc5\xfbC\xc9`\tOA\x97#\xdd)\x87\xeb\x9f\x08L\xd7\x15\xc6\xf6@\x07\xfd0q=\x10rS\xdd]-oLvP\xc4~\x07\xd0P^\x84\xc7A%\xa8_\xc4\xb6\xb3\x9f\x9f\xb5\x9a3\x14\x06\xb3\xcdA\xd5\xc2\xe3\xe0h\xe2H!\xe8\xb4=\x8a\x11E\xb1\xe8CwcC\x15\x1b\xc35\x1f~\xd3UcG\x13\x17\x1aM\xc4\xd4\x8d\xd8\x9eI\x11\xfe\x01jt\x88\xd6w\x80i\xfa\xb3\xd6\xd43\\ek\x1b\n]W\x89\xbc[\xce_\x9d\x08j\xc9\xa1\xf7\xaa8\xd6\xa4\xed_\xa9D\xcf\xc6\xac\xd6\xf0\xea\x1a}\xf2z\xba\xb2\x92ep(\x05\xcf\x8b\x98\x12\x02\x95\xaf\x14\xcfW\xeeB\xf5\xee:\x98\x95\xbby\xa1\xae\x1d\x9d\x19\x0fy]O\xfa\x8a\x14\x00\x91\xae\xffFX\x02\xe9/// \xef_F\x10\x1a\xb4}JJ\xec\x07\x9c\xd7\x08:I\x08)2\xb2\xe14l^\xb6\xf3\xec\xc2=\x1f\x89t:\t\xefp\x9d~\x05\xb4\x17\x17\x0cJ\x11/\xac<\xdf6\x9f\x9b\xfco\x9a\xd0^OU\xde\xd1\xcb\x80\x12\xa4\xa2\xe6f\xb8\xa2-}\x97\xfaU\xbb#\x0f\x0b\x91\xcf9\x7f\xe5\x88\x8e\xf0\xd0GH{\x15\xbd\x99-Q\xba\xa2\xd9\x12f%\xd9\xb4\xf65L\x19yu\xbe(FW>\xe2\xa6p:\x8b\xd9\x1c\x8cM\xb9!\x8a\x0fM\x0f\t\xefP\x07\xde\xd4\x03P\xa26\xccXb\xb2u\x1e\xa3\xe1\x04\x81\xa5;\xd3\xef.\xd6\xec\xf9d\x1d\xa4\xa8\xa0\xbe\xd6\xe5\x02\x1e2\xb1\x9e\xefgk\x96h\x8b \xbaej\xc1\\\xeb\xf3T\xc9\xed\xa6\xb3\xaaOT\xfa\xd1\x01\xcd\t\xff0\xa5;\xa1\x89\xb4\xff\x0b\x02Z\x8c \xe6\xf6\xf7\x08=\xf5R<\x18\x82\x96\x95\xb28\xb2M\x01\xb3|\x82\x87\xe80]\xe0|9\xaa\x87\xa3a\xf3(\x98\xa8\x82\t\xe1-\xc0\xa757\xc4\x95\xa9\x84\x06\x89r-v\xff\x80\xc2B\x06\x94K\xd4\x14eF\x01\x85\x84,\xdfvK\x9f;J$V\xcaPX\xdb\xfb\xa1\xde,a\x83r\x97\xf5\xa5\x18\xd5@\x1a.m|\n6Sk?\xec\x94\x0c\xb1R$Z\xf8\xd3\x85H\x883\x93\xba\xe9l\x8fHt\x93\xe3\x1fn\xdcMwU\xfcq\t\x84\xb5fr\xa5\x91\xa0\xf4#\xf2L\x95\x8a:V\x17\xb1\te~\x03\x96\xb0\xf1\x8a\x80F5\xed\x0e[[\xf4ID\xf1\xe9\xf8`\x8f\xba\x0b\xb4\xa5\xb0[\x7f\x86g\x0cOLdU6\x06Y\x1a\r\x9ch(r\xc9\xefv\xdf.\x15\x00\xa0/9\x03\x9a\xc2f\x8e9/\x19\x86\xa1\xa4Z\xd9\x99Q\x9d\x1f\xed\x89\xea\x12\x12"\xc5]\xf3^%ia<\xd3|\x04\xb4\xf3\xdfB\xbd\x8a\x90\x9a\xd8\xd3]\x95\xcc\x06\xedD/C\x04\xef\xa1\xf0\xf7\x03\xad\xf6\x82\xee\xfc\x1d}\x1b\x8d-VF\xb1\x12zw\x8d\x8b\x9a\\oU\x85\xa1\xe9\x0e\xb5V\xf7\xefQ\x176\xd5A\x02\x8f\xcf\xe5Hby.\x07\x84\xc1:v\xd3\xaa$\x13\xe5\x975\xda\xdd\xc1}\xdd\xf0C\xfe\x10u\x94\x04d\xce\x87)\xc3\xd9\xc3\xd2K{F5\xe1\xd0I\xbd<a\x94\x80~\xbbs\xe5:Y\xaa\x1a@\xd1\xf2\x03\xae\xd8\x9e\xd5uh\xb9PC\xdd\xa8sL5i8\xb4\xc9:\xd8;\xbe\xe3\x0f@\xd5\x15_\xeb\x18\x03\xabu\x11\xe5\xb0\x08P\xd9\xa1E\x1f\x89\x8d\xc1O\x1a\xb3Q*\xf9{\x05\xef\xd5\\(\x02\x04\xac3\x1fx\xd3>\x1dweR1\x9c\x0eZ\x85\xfbF\xed\x10\x94\xb4\x84Z\xbaC\x18/\xd4X\x8a\xa6\xbc\x86O_\xe9\x1c\xceCy\xfc;U\x08\xb65x\xbe\xe3n\xe3\x8f<\xb0\x84\x04\xa3\xe6\xbb\x9fP\xde\x17\xf7\xb7\x7f\xaeGZ3\xc4\xd9\x00\x96\xd1m\x92\xbeWJ\x99\xf3\x91\x9bM\xd5\x80\xe5=\xe4W4\xf5>\xce\x04\xb4t\xf72A3K\xe1\xef\x10`tvF\x13\x93\x88\xe2V\x80\x1f\x13\xfa\x8c\x11n\r\xf5\x82m\xfcHC\xd5\xa1\xd9\x17\x1f\\\xdb\xd2\xeav\xfa\xd5\xc3h\xc9>=\xde\xb8r\xab\x11\x895$\xa1H\xd3\xe44\xa3\x82\x1cM\xe9\x86`0#K^E\xe4\xd0\xe9\xf0\x7f"\xa5\xa6\xabwz\xa2c\xf4cz\xbc}\x03y\x8ey\x89\xe8M+\x93\xfd(T\x98\xa2\x90.\x15[\xd3q\x19\xacZ\xd9\xc6\x17o-=.\x1b\xa2R\xd7\xfa\xc8\xe0\xa5H\xe2\xd1]\xa7$\x9f\xe3\x81P\x9c\xa2\xa2\xeb\xb1\xd8=\x11\x1e\xc8&\x1e\x05<_\xae\'\x06\x91\x14u\x15s\xf0|!\x8c\x00\x19\xca\x96{\xc2\xb8\xd6\xda\xd3\xa1e\xc7T-\xff\xd6\xa3\x0675\t\xc7\xf9\x1bH\xfe\x85D\xad\x1e\xfc\xd5\xfd\x1c\x97\x81?1l\x12\xe0u<#\x8e\xf4*\xf8\x1f\x05\x96\x10\x0bG\x8d\x13\x031\x8fuw\xf2c\xfe`\xe9N\xda\xd9;z\x8a\xa9\r\xf9\xa2\x84\xf5\xa2Z\xf9\x10ft\x10\xd0_\x93\x9b\xfb\x9f\xd8s\xaaJ\xd6\'\xe042\x06\xf2A!\xcf"\\.\xac\xa9X\x1f\x82\x1a\xc5\xbf\xa1\xf8\x89\xa2\xee\x02\x80\x7fI\xa4\x96\xbcl\x88\x95yo\x82{a\x14x\x1e\x12\x00\x16c}\xe5\xd7`\x93\xd7\r\x1c<Y\xa1\tkg^\xd5\x14\xe4\xe2X#\xcd|\xf7\xc9\x9f@\xf6\x02\x0e\x7fl}\xd9SKho\xbd\xe0`\xedJ\xe7\xfeuB\xca\xaczO\x0e\xdf\xe4\x8c \x9b]$\n\xec\x9fz\xcb\xe8\xdd4Y\xaa\xf0\x8b\xa9\x86\xb2\x1c\xebz\x05J\xe4\xab\xd4\xad\xb94\x85\x9c\x18\xcc#\xd3\x86\xe5\xc4v)kF\xe3Z*\xd7\xa9MD\xea\x98Qm\xe7\x15\xba\x96kl\xe5\xcb\xdb\x1a\x03\xdd\xa1\xb2\xccR\xb5\xf1\x89` \xe8\x0c\x03\xc3K{`\xcd\x9b\x8b\xe2 \x87\xd0ly\xf1\x86\xcb\xb7Z\xb7\x9bk\x0e:\xd4\xe91M;\xde\x0e0\xc1\x155\xd1\xf4T\xe5m\x06\x86Q&\x0e\x03D[E$\x01\x88\x86\xee\x19\r|wk\xd4\xec\x7f\x08f\x02>}\x93a}\x90Fu\xbd-~\xdd\xed\x00\x97\xadq\xe4\xa2>\xa9Vom]\xac\x1dE\x05|/\x84\xb2zC\x0fi\x84\x0b6\xe5\xa5\x9d\x06\xae\xc8#j=\x19e6^Z+E.\xe9}\x17\xea\xdd\xb1{A\xcc\x9b\xc0\xbfD\xb5\x9e\x11\xf7\x19\xc40\xfac\n\x06\xe5\xdd8\x81\xed\xf1N\\\xa6X\x8a5\xfdg\'\x9f\xf8\xd7\x90\xf3Y\xda\xa4\xd1B\x8c\x0f\xd6 l\xd8S\'b\xcdBH"\x93\xed\xa0\xbf\xd1\x1a\x0f\xb8\x9a\xcb^\xc2\x15\xdbEB\x9d!\x12d\xff\x1f\x1e\x17\xf3"I\x80R\xbd\xc9.;U\xf8Te\x07\t\xebq\xe9\x1b\xf7_oj\xd1\x84\xd9\x01#^o\xff\x11\r\x990\xfa\x82\xb3\xfd\xcf\xec\x03\xae\x08\xa8\xa3Z\xc31\x0b\x91\xb4\x94V{\x04\xdclPV\x93\x8b?(\xd6(v\xd8YZ7\xec(}\x99\xdd\x85fP:O\xf6U\xfeJ\x0e\xf6\xaf\xd3\x82{h\x9b\x94YGH\xeac\xc6\xcf\x109\xc4nq\xfdx\xae\xbdp\xd5\x017\x8b\x81\xb3\xf5\x9c\x0c\x9f\x81W~\xe1^#V\xc9K}\x9d.\x0c\xd4\x1eZ\x04\xdf\x9e\x06Q\x9a&\x81xe=\x1c\xe9\xef"Q-\xeb\xf5U%&^:-sVXlFRH\xf1f\xbfj#\xad\xf8%;\xb1.\xf6:\xc4\xf6\x85\x06\xfe\x8e\t\x03\x86\xe4rs\xef]\xf4\x7f\xd2\xe3\t\xbf\xb0\xe7>k\x17Lsd\xc5T-D0r\xd2F\xe0O\xab6\xd0\'\x81\x96\xb4c\n*\x9b;s\x88\xef\x9c:2\x97\xe0C\x8bn\xa1\xde\xa3\xef\':.6T\xc2D\xb4\x14ye9\x13Q\xc2\xf1\xb1\xd2\x13\xd6\xab\xde{\x1c\xe9\xf6\x8d)\x9c\xf60\xa9\x8d\x14s\xe3/\x1f\x7f\x98RH\x89P\xac\x81\xd4!\x98\xe1\xc0dmn\xd5q2\xed4\x1b!g\xf6\xa6Z\xc9\x95\xfd\xbdW\xa8`}>\xf81%)+\xf0\xaau\xf6\xdd\xe9t\xc8^\xba\xb5\xae\xb4\x13\xc3Z\x98\xf2\x08K\xebt\xdb\xd4VM\xab\xaeJY\t"2s\xdb\x8e\x90\xa6\xcf\xa0\xbd=\xdf\x9eMU\xe2\xef.\x17\x8b`\xcd\xa3 i#*\xecW_;\xcd\xa4@\x13[\xfe\x8f\xe8\xfc\x16\x1c\x91\xa3\'\xa8\\-\x05k\xcf\x1d\xac\x91%A\xe6*\xc1\x03JU\x08^\xdc\x15\xcf\xdb?G\x95bg\xa4$MK)Q\x8a|\n\xef\x8f\xbb\xacK\xd0\t\xb31\x9b!\x11\xe6\x8f\x13+\xd8\xd7?\x85_(\xc9\x01\xf8h\x88\xbft\xad\xc1b\xf3\xfc\xf3v\xca\x9fv.&\xfd\x1f\x10\xd3?\x9ct\xedb\'\xe9\xc4\t\x08\x95\xef\x7f\xb2>\xe7\xc8\x8aJ\xe7\xd8\x1d\xd3y\xfc\x9f\x11E\x01\xed\xe6\xd1\x0f\\\x89r\x01\xc0\xf4_@Q\x0b\x88N\x0539\xec\xa2f\xe5\xd0K\x81A\xcb\xc3\xabC-3*\xb2\xc5\xf3Z\xc1\xf7\xe3\xc8\x19\xfa\xa9\xac\xe7c\xdb\xed\x0f\x80\xfe\x85AR\xef\x96V\xf0:\xbb\xef\x80P\xf6\xe3\x94B\x94k\x9aWJ\xd8\xa1\x89\x10\xc0\xac\x8c\x96O\x8f\xde2dHE$\xd4\xef\xed}\xfbA8\x1a\x1dE\xb1\xd1\x98\xd9\x84\xc5\x06"V5U\x1bizC:8%%\xe9\x8b\xc1@\xd8\xae\x0e\xbd\xc7\xc8\xa9\x8ab\xf2>P\xf2\xe4\'\xc9^\x14\xe9\x14U\xf2\xb9=\xcc\x07\xb7\x83$\xce\x04 \xe7\xa2z\x9a\xfb\xde(\xb2\xe5\\\xe4\xeb\xec\xbf\xa8\xa2yD7\xb4vRa\x12\xd8\xad\x9f\xee4\xe7\xeb\xad\x06\x92$SGk\xd5\x8b\x10\xf7l\xf9\x1cM\xe8\x92\xb3\xfcv(\n\xd4\x16t\xeaZ\xc0\xf5\xcd2C\xa5H0\xa7\xac\xf6\x18\x14i/l\xcb\x97e\x15\x9e\xc3Y[\x98\x88{\x12\x87&\x1b\xefQ\xca\xb2\xfe\x8fqN\xaa*4\xc8uq\x1c\xafT\xa7\xff]&\xc8\xae4\x02\xa6\x85*\xd3ma\xc4(\x1d:R}\xfa3\xec\x1bSP1\x1e\xdc\xf1\xec\xd2\xe9\xa7\x13r\x1d\xab<Pe\xbbf}\xbb\x91B\x8c\n\xe4i\x87v\xcfd\xa1oG}\xbb\xe3\x8c\x18\xfdE\xd0][z\xad\xbd\xb9\xec\xc4Q\xeb\xa6\x0e\x86\xef{\xd5\xe6/6\x08Y\xa5\xf5\xd96\x96\xd1m\x04\x19\xc5\xc8\x9b\xc1\xd7\xd2v\xce\x14H\xd0\xcc\xea?\x01@\x03\xaa\xfc`C2\xb9\'%f\x9b\xcb[\x0fT\xb6,Vy\nV\xa7dN\xbe\xcb\rLS,\x81\x07\xb93\x93aBB\x82\x0f\x1aynx&\x95\x88\xc9|/\xef\x00\xbf\x8f~\xfc\xd7\xed\xf9F^}\xdd\xed\xe2\xc6A\xfb\xa4\xd3\xa4\xb9\xf0{\x95K\xabd\xf0\xe2J\x83\xd0T\xaa\xdey{\x8ay=dH\x97\x99"\x85\xdc\x0bS\xc7\x8f\x95^\xbdCF\xce\x80\x9e\xeb[\xea\x8b\xe5\xee^!\xa5\x14\xcfA`\xe3\x96\x88G\x89\xfa\xc0\x0c\x1a[\xcf\xb2\xa4\xb1\'K\xe0\xec\x86Co\xb8\xea\xb2B\x8a\x1e\x92Bu\x11\x08\xec\r\xc1\x0f\x99<\x7f\x1b(@Zq]c\x1f\xeb\x04\x9fV\xc9\x9e\x03\xaa\x17\xd5\xc6$\xc3\xc3j\xaf\xc5*y\xb1\x00\xb1\x8a1c\x13v\xa9\xaf/!Q\xc4;\xfd1\x87`$`\xe8\xc3'
|
|
|
|
|
|
2024-12-14 17:54:45.398132 - Ether / IP / TCP 20.42.65.91:https > 192.168.1.11:40843 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 190
|
|
id = 6774
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xdc8b
|
|
src = 20.42.65.91
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40843
|
|
seq = 2099799478
|
|
ack = 4124377343
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 16381
|
|
chksum = 0x7b0b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'X\xb1\xee\x9dhZ\x04M\xfd\x07\xf7Q\x9de\xfa\xc5\xc14\xeb\xe2\xc6Q\xc5\xa7\xc2\xb2t\xa3@\x80\xc0\xa2f\xa9"?\'u\x83\x8b\xfe-\x1a\xb8\xbb\\\xa0\xad\x1a\x8e\xeeBn\x88\xf8\xce\\\x0eO\x85\xc6,\x9b\x9c\x80\x95\xf0\x90\xb2\xdfZ\xec\xf4\xaf\xefP\x9b\x9f+\x9d$&\x8e\xb4\x83e+\xc4a\x83\x03\xb8&!\xf6\xc2-S"j5\\V+\xa6\xae\xaf\x83\xbe<Z\x19tn\x16:<\xd1q\xad~\xfb\x8a\xe7\x8cez\xd9$R\xb1\xb5\xf1\xcb`A\x82\x9b\xfb\xdew(\x9b2v\xa5\x0e\xd2\xa8\xc8'
|
|
|
|
|
|
2024-12-14 17:54:45.400651 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40844 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x3f3c
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40844
|
|
seq = 3502955288
|
|
ack = 2444971194
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 65535
|
|
chksum = 0x7e07
|
|
urgptr = 0
|
|
options = [('MSS', 1412), ('NOP', None), ('NOP', None), ('SAckOK', b''), ('NOP', None), ('WScale', 8)]
|
|
|
|
|
|
2024-12-14 17:54:45.403664 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3491
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124377343
|
|
ack = 2099799478
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 517
|
|
chksum = 0x1753
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:45.407301 - Ether / IP / TCP 192.168.1.11:40844 > 35.186.224.26:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 1574
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40844
|
|
dport = https
|
|
seq = 2444971194
|
|
ack = 3502955289
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xc5a2
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:45.410719 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3492
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124377343
|
|
ack = 2099799628
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 516
|
|
chksum = 0x1753
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:45.416429 - Ether / IP / TCP 192.168.1.11:40844 > 35.186.224.26:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 1575
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40844
|
|
dport = https
|
|
seq = 2444971194
|
|
ack = 3502955289
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xcb26
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x01\x08\x16\x01\x00\x08\x12\x03\x03x\x18x%>\xc1Q\xc3\xbe\x1d\xf8H\xf3\xf42\xd7\xf7t\x16\xc0\x1cJ\x93\xe0\xfb\xdeg\xc2\xa5q\x17K \x11\xb0\x11]\x9c\x00U5n\x18u\x8a\xd6\xfeZ6\xb0\xcfa\xb1F@r\xf5R\xf8X@\xcb0\xed\x93\x00 \x1a\x1a\x13\x01\x13\x02\x13\x03\xc0+\xc0/\xc0,\xc00\xcc\xa9\xcc\xa8\xc0\x13\xc0\x14\x00\x9c\x00\x9d\x00/\x005\x01\x00\x07\xa9\n\n\x00\x00\x00\x10\x00\x0e\x00\x0c\x02h2\x08http/1.1\x00\x00\x00\x1e\x00\x1c\x00\x00\x19gew1-spclient.spotify.comDi\x00\x05\x00\x03\x02h2\x00+\x00\x07\x06JJ\x03\x04\x03\x03\x00#\x00\x00\x00\x1b\x00\x03\x02\x00\x02\xfe\r\x00\xfa\x00\x00\x01\x00\x01\x0b\x00 \xcce\xcc\xd0\x80W\xd9\xf4FV\xe9\xbdp.\x84\x0f\xe5\x1e3X[\xe4\xe3m\xd5\x14\xc4\xe2\xf1\xce\x9d\x07\x00\xd0s\xc1\xcf%E\xd9K\xf0\xfcI\xf8\xabA^\xe8\xb6\xa5K\xbc\x804\xa2\xe0\x0c\xb0\x98\x8e\'\x97\x0c!+\xc3\x99\xab\xab\xac\x8b\xf0d\x1e\x9b\x13\xe5\xfa-\xd2\xae\x10+gM\xa0\x18\xd8\x97\x7f\xdd\xc5-\xef\xc3\x02\xcc\x97\x19\x818A.\xdep?\xa8j\x02\x04\xd9\x10"Na0\xda5\xdb\xa5g`dn\x98?\xee\x99/\xb8\x81\x81\xfc\xb5$\xc2*\x11\x14\xd9\xe2\x9e\xcf:^&OD\xaa\x9b\xact\xf4\x00\xf5nx\xdf\x7f\x08\xd0\x9e\xed"\xbez\xd1\x1ex\xfc\\\xc90\xb5\xa4\xb1\x11D\xb0\xd7=\xba\xc5\t"\xad\\\x12\x99\x89Lc\x8c\x8e\x1fR\xc0`\\\xdd,\x1d6\x16z6\x80y\x8b\xe5\xe0\xd3P\xcb\xa4\x80\xa6\xc6\xe8X\xb6\xc5\xe3m)\xfc\xa3\xba\xa1l\x869\r\xdb\xf7\xbf\xfc\xe0%\xec\xf6\x00\n\x00\x0c\x00\n\xfa\xfac\x99\x00\x1d\x00\x17\x00\x18\x00\x05\x00\x05\x01\x00\x00\x00\x00\x00-\x00\x02\x01\x01\x00\x17\x00\x00\x00\x12\x00\x00\x00\r\x00\x12\x00\x10\x04\x03\x08\x04\x04\x01\x05\x03\x08\x05\x05\x01\x08\x06\x06\x01\xff\x01\x00\x01\x00\x003\x04\xef\x04\xed\xfa\xfa\x00\x01\x00c\x99\x04\xc0\x93\xbc\x14\xa0M\xbfQ\x02xg\x1a\x06N\xc7\xf2\x84PC\x1dw\x16\x03\xa2Q=\x9b\rnx\xd9\xce\x1b#\xd8\x9c\r2D\xe0+i\xb1\xb7\x96 v\xab\x19\xb0xrG\x8a\xce\xf0\xa8\xd1;l0\xb5\xa8\xd7\xd5\xba\x1etiQv\xc6\xba\xb8\xcd{\xd4+$\xf4\x845\x9b\xb6fj\xaa\xfc\x19\xc4@&Dr\xb9k\xa1k_\xc5\x13w\xc8\xd0.\xf4\x9b\x12 <\x9drzO\x05\x06\xaa\xf3g}X\xb8]\x18kj\xcdg*\xde\xd4\x80\xac\x91\x1c\x00\xa5yp\xfaj\xbb8tzk\x8f\xf1bJ\xfd\x1b\xc3\xc2;0\xac\xd2\x8d\t4\x05\xaf\xa3$I\xfb\x83\xc7\xf2\xa1\xb0\xe2~f:\x1e\xdbJ9\xa7\xf8\x88C\xd9Z%\xb3\x85\xcd\xb7\xb4t\xb3J#\x0c_\xb0qS\x81,\x9c2\xa9\x8e\xd0811\xd1l\xd7\xea\x0e\xff|S\xec \x84\x94\xcb\x02\x07K\x1d\x175F\x81\x0c\x0b8\x00\xa4x\xdb\xac\xf3\xe5\x80\xf6[\xb9_l\x95$\xda\xca\x8c\xe3\xc3)t\xc8\xa7H\x9d4Ut?\x00\xa1?\xd7N\xb0yl\x15w\x1a\x08X]\x9c\xc4\xad\xcb\xb6w\x9d\xaa\x95\xd0S\x80\x12Lj9\x88{N{~JT\xc2\xfae3\xccH\xab(\x92\'N\xc2\x91-\x9ao\xe5Y\xb9\xa25[@|\xa3\xe09\x01\xee\xf6\xb7\x12\x11`\xc4\xa9*\xc1\xe4+}\x10\x03\xbc@(\x80@\x06\x86J*]R\x0b\xddQzX\x10\xc3\x9e\xfa\xa3k\x98S\xc4\xac1\xe4\xa9}\xfc\xa6a\x10\x04\x99\xbd\x88\x0f+\\\xa7\xcf\x9c\x9c\x840\xa4\xcf{j\x03\xc0|\x0b%\xa7\x7f\xfb\xbb\xb8\xe8L,\x87d\xb4\xe9e\x90P\xad<\xc0\xa2\xb3\x90#\x8f\xcc=\x96z=\xcd\xe88z\xdc\xa6\xfaU\xa9#v+Md:\xed\x02\xbcUp\x00\x124\x0b~\xdbw7,\x9b\xa6\x13b\xbf\x11"\xefFT\xb9:g\x03uMy)\xb0\xf3\xa5\x07z\x86$\x94\xe2\x9dg\xd4\xc1\x80`DYPh&+\xac\x9f{"\x8a\xf9m\xa4\x98C\x0cx\xbaI\xdc\x9d+\xc5\xa0\xab\xb4\x85k\xe2\x06A9\x0bJ\xcc\x88\x86\\4\xceY\x0b\xd3J\xb8C"$\x0et\xadS\xf5\x8c\xd8\ty\\\xea\x82\xadQ"\xd6\x90T\xffq\x1e\x8b\xa9\x89KdT\xf8pr\x9fBH\xb4R68u\xb0\xaa&vz\xe5LN\xb50*\x99\x80 \x8b:\x1c\xb79\x07\xc6\x9cJ\xd6u9&5AF4<{\xc9\xebB-DXi\xb8\x05\'\xf7\xacw\x07L\xc6\xd6\xb2.\xd2\xb6\xa7\x83\'\x873\xf6Y\x9c\xa6+Tj\r]\xbcQ\xe8\xe7\xca\xfa5\x84U\xa4%\x8b\x99\xc2iFo\xe2e\xae\x06Vk\xdfL\xbb\x88\xc4\x95\\\xd7\x92\xdd*\x96i\xda\n\xd8\x13\x16\x91S\x8akv*\x1b\xdc\x04\x82\x15\x8e=\xa8U\xa3\xec\x05\xa0\x99\x7f]JH\x802,\xcad\xa0RL\xa4\xa1C\x9aivHpQ\x7fc\x9cf\xad\xa8\xb8\xf5\x86\x07c\xd7\x95\x8e\xd3{\x11vV(\xe8\x082+\x8a\x1b\x08\x9c\xf7!At\xf3\xb7\x9a\x04\xb2\x1e\xd4\xb9\xba\xe7D\xaf\xca/\xb3(\xa0\xb2\xe7\rO\x13\xb2\xb93\xa1\xc4\xf2\x82\x96y\x9a\xaa8Y\xc4\x12B\x88zXy\x87v\xda\x917\xe9\xd7Hxc\\\xe8d\x85\xa41Z\x88p\x00I\x89\xaf\xb3y\xca\xae\x92\x03LU\x84\x95p?\xcf\'T9\xd2\x10\x91U.7\x82uv\xb5`\xe4\xd2\x1b=eo\xb6E\xce\xbc\tc\xbd\xb14\xe2\x86\x9d\x02VkW6mi'
|
|
|
|
|
|
2024-12-14 17:54:45.420690 - Ether / IP / TCP 192.168.1.11:40844 > 35.186.224.26:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 703
|
|
id = 1576
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40844
|
|
dport = https
|
|
seq = 2444972606
|
|
ack = 3502955289
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc839
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xc1\xa5\x94\x99\x0b\x14\xe5\x0c%\xa3u\xc9\x87\xbe\xddJ\x15\x04\xe3\x9b)d\x9e\xff\x12M(9\x8e\x96\x13O\x1f9\x9f\xa9\x02\x8e4\x91`\x0f\xc3i\xfek\x19\xf0F\x14\x0b`N\x1c|d\xba\xb0\x83\xbaIP\xd5\x03\xb3<\xd7\x9e+ed\x99\x89\x89R\x1a\x13\xb3\xd1"-\xd0\xc2e\t\x86:\xc9e\x07\x84%\x83\xf7t\xa2\xa4\x91\'\xc1+}[{\xd0\x1c\x86\xa5\x82\x8d\x00\x9d\xa6\x7fk\x02\x1a\xf7\xc6\x7f\xa5\x19\xccH~\x94y\x8fT6q8\xc1C\xd8s\x17p\x90\x9e\xd1d\x05\xe9s6\x99\x02\x8e\x02\xc0\xb2\x7f\x06t\xbf\x06y\x03\xf2\x0cn\x14*C\x93G)\x95\xcd\xf3\xfb\x13\xdc\xe0Xd*C\xcf\xa3\xc7\x0f\x10\x977\x18g\x9f\xe0v\x96\xcaS\xd6uj\xba\xc2\xbe\xe0E\x89\xecGI 7\xcd\x97\x0b\x0cdUz?@e,s \xaf2J\x16t\x92\xbc\xb80\xa7\x1c\x0c,\xa9\x143\xa1\x80\x9e,\xae\xd7:^\xcdrD%\xe0S.\x82u\x9ay\xc3u\xc5J8\x8b\xa1\x89\xe7\x95\xca\'%\x1a\x9b\x04d\xcb\x00\x14\xc3\x1ce\xdc\xba\xec4\x8bK\x83\x05k\xb2l{\x12ub \xcb\x8b\xf5\xcb7\x84bk\xc1\xb5\xf0\xfb\x0f\xa4\xe4\xb4\xba\xef[$\xeb\x05H\xd0\xba\xa6j\xe2U\xa4\xb9\xb2\xf2\x11\xd6\x89\x15.\xc5&\x99P\x8e\xdcJ\x00\x1d\x00 \xa5\x14\xf1\x99S\xf2\xb6S\rsN\x8dT\xd9d\x8eH3\x908\xf2\xb4\xa5\x0e\x91\x009\x94\xc0\xa9\x08\x00\x0b\x00\x02\x01\x00**\x00\x01\x00\x00)\x01\x10\x00\xeb\x00\xe5\x025\xf0\x13\xca\xd4\x9b\xa0\xb7\xb5\xe0\x10R\xbd\xa7]fH`\x00J6S\x97\t7\xd2\xfa\t\x9bj\xb1\xf5\xa3\xe9D\x7f\x88\x0e\xb08@\x0c\xf0\xd8y\x14I\xe52\xa8%\xa2\xf54\xce\x9c\xb1$\xba\xbc\xcf\xa5\xf9\xbb\xb9\xd4\xb7\xc3Pb\x0e}\t\xeb~\xa0\xfff\xc72\x87L\x81\x8f\xf3x|\xee\x94k\x9a8%\xe1\x8e\x94W_`A\xb7\xc2\xad\xe9\x8f\x9aa\x1c[:\xc2\x15u\x9b\xe1\x9e\x9c*\xfb\x17\xd2g\x1dr\x1f\xb5\x1c3\xde\xb6\x12\xf3\xcf\xaa4\x15\x9f\xcc\xd4w\xbd\xb8\x00GB\xad\x81+eE\xa5\xaeC\xdb\xf8\xa0}\x82\x97D\x9cfG6m\x9f\x1cW[s\x97.kD!\xd9_\x0f\xda\xfdF}fh\t\xd0\x83\x9a\xf4\xec\x9a\xe0\x98\xf4;V\xea\xc69\x1a\xa7\xfc;"~\xf8\x87\x84\xd4\xab\xd9\x8b\xa3\xce\x07\x10wMADK\xaa_\x17:DgP\x97\xd5\x16\xd9\x00! \xcbJ\xc2\x8cS\x9ai\xe1\x10\x07\x9a\xe4\xe0\xc7\xf5\xc7\x05\xd4\xab\x85\x80d,\x99H\xe4\xeb\x807\xccJ\xda'
|
|
|
|
|
|
2024-12-14 17:54:45.424785 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7867
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 1258
|
|
chksum = 0x205d
|
|
###[ Raw ]###
|
|
load = b'\xca\x00\x00\x00\x01\x00\x08\xf4k\x98\x9b%:\xa7\xd9\x00@v\x1e\xf99\xf9f\x1d\x14\t\xcbw_V\xd7\x0b\xbc\xd4\xd0\x98\xf2\xbb\xdc\x03z\xca\xb2[\xdd\xe3<u\x14\xc6\x95\xbf\xd8\xe9!Q\x94\xa7\xca\x07\xbe0\xbc_Sn\x9f\xb2\xbb\xd3Sl\xdb\xff\xb4Z\x18_YzT0Yv\xfb\t\x14\xb4\xff6\xd20\xe8R\x12\xac\xce\xc3\xcbVZRD\xc8\x9f\x96\x8c\xb9\x99A\x99\xf0\x0f\xfd\xa6\xe1O\x0e\x92\x82R\x90\xab\x91\x1a[\xf5\xef\t}\xc0$"\xa7:j\xe2\x00\x00\x00\x01\x00\x08\xf4k\x98\x9b%:\xa7\xd9DIs\x835\x89\xe0\x98\xfaT\xc6\x84\x1d\x97h\x83\xfc\xc8\xcb\x91,\xe4\x0f\xa1\xc4\xcd.\x81\x86\x85\xb7\xb2`/<\xdd\xd4vf\xcb\x00\xbe\x02\x1ev\x91\x19a\xa3\xdd\x88No\xdf\xe4Z\x88\x1b\xb9}J9\xca\x8c;\xc2v\'\x16\xda\x1f\x85\xa8\xb8\'0\xf6;\x05?\xc0/\xb5\xc7\xf5\xd1\x9d\x8fu8\xb1r\xeaq\x02\xb8OA.\xd3q\x153\xb5;\xc03v\xf0\xa6\xcc\xa4vF\x7f\xb5\xc8\xa6\x8eI\x17\x00(c\xb28R\xde`\xcc)\x94\xe3v@3[\xa1\x8e\xdc\xd6\x97t,\x13\x16\x1a\xd2\x0fQ\xef\x11\xf2\xe7 \x93\xb0\xe4\x19\xdcuy\xadm\xee\xe7\x02\x95\xd9P\x11U\xc37*\x98}\x96\x86\x17kl\xaa\xf9\x02Pn8p\x9e\x9at\x00\xde\xf8\x92`\xab\x01\xa3N\x16*#j\x03\x17\x88\x05\xa3n\x17\x7f(K]\xad\xad\xa6"\x1e\x99\xe8\xd3ol\x81\x8eMoCh]\xd3\xec\xb4X\xb6ez\xe8\xd5\xe9\xb5\xcaQ\x82\xa2/@\xb3_a\xf7\xd3|hg\xf6yC\xc9\x17V(\x1e\x0b*\xfci\xe5\xf0E\xd6\x13\xdb\x85L\xc7\xc8\xd6*\x04*\x88\nX\xb9u34\x85[\xdc\x91N\xb7j1j%\xac\xa2!\xb2j3\'\x03?mDT\x908\xaf\xf2m\xc8\xe9n\xc53\xfd\x0e\x8e\x8b]\x9a\xa6\x83h\x8d\xe2\r\xa2;\x84mv\x9f\x9d~\xd7\xf6(\x1c\xecY,\x04\xaa/P\xd5*,\xae\xe1V\xed\x01\xfb\x9f\xd98\r\xbb\\rvC\xc5$"E\xd2\x062\xef\x89G6-\x89+\x1a\x01u\xbe\xeb\xe3\x89^B\r\xd1\xce >I\xb6G\xdf7>\xdb\xd9\xc4\x0b\x93R\xdcB\x97\xbd\x83\x1d\xee\xed\xe8\x11(\xf3\xb4\xff\xae\x8d\xf1n\xf8\xce\x94aK\xa6\x9dR\xb0\xf6y\x17N\x0c\xfc\xbb7\x88\xcc\xa9\xf6\xdf\x04\x12i_\x9d\x82\x84\x9b\x99k\x1e\xce\x18\xde\xf2Lj\xe3\xf2~V`^^\xe80\xe7T\xb4AB\x9be\x1d\x841\xb0\xfaGf\xd3X\xb3n1m\xf5\x81{W\xbd\x8d#\xba\xea\xd6\x1e\xaeM_\xb6\x9eBa\x16\xd5\xd1\xde\xa3\x17\x82,L\xf7\xed\xe7-I\x18\x08\x1f\x9c\xe2\xc4\x8a\x1e\x15\xb1\x83\xd2#\xef\x05\x876#\x14\x8cH\xdbHNiM\x00\xdfA\xce&\xa5\x9e\xc5+D\xf1\xaao?a\xd9\t\xeafaz\x92\xc8\x8b\xb88\x7f:\xc1\x01\x19w\x17\xf03\xbe\x87\xbd\x9d\xea\x0f*\x01\xbf;\xf7\xbe\xdd\xca\xdb\xd8\xb4t\xafI[\x0f\xef%x\x80}\xa3f\x91\xad\x06\xe7\xe9\x96\x1d\xfa\'\xe8f\x03\x0bo\x00\xb8\x8e\xcb\xddAq\xc5\xcf\x96\xbf\xa4\xce\xdc\xf3@k\xbe\x88\xd3\xa2\xa3[\xc3\x16\xf9\xb4\x15\x9cjqc\xf4I->n\x90\xa5A\xd5\x1f;\xed\x1c\x05\x11\xe1.j\x08\xd7z\'D\xa2\xd9\xec;\x90\xe6B\xde\x0b\xd6G1F3A\xe9\xb3\x82\xebYUN$\xea\x1a\xb13\xb3\x19!\xa8o*\x19\x1e\xa2\x98\xb7\x9a!\xd4\xb6\xeb\xefW\xa5\xcaTzW\x83 \xa7\xc1r\x18\xe1@IA\xf6\x97`%\x18@\xb4\x0c\xbey\xee_H1\xf3\x8a\xf0zf\x82\x8b\x13K\xb4\xcd\xef\xe4\x84""\x8d:-*\x03\xe1\xfa\x15"\x0b\xa4\xed\x80\x9d\xe5K\xfb\x19\xee\xe6v\x7f\xf5\x93\x7f\xcb\xc8\xb0\x16\x18n\x92\xbc\xb4\xd4\xff\xbeMuq\xa8\x01w\xb7\xdf\xb4\xe2g\xdb\x85\x94\xc9\x9a\xa7\xd1\x83M\xc74B\x9e\xfe\xe8\xee\xe7\x00,-\xec\x03=\xdb\x8f\x8b"XSk\x8d@\x16\x1b\xc2F\xbb\x9d`\xb4\xc2\xe28X\xa2\xd8\xef\xde\xac/*/\xa2t8\x81\xd2\xd6\x8e\xb0W\x83\x95*\x91\xb3j\xee\x1dgm\x93u\x17;\xf6\x13~\x12\xa0\xa6\x901-A\xcav\xd0\xb7\xbac\x12\xc6\xce\xef\xc3)~\x10\x1d\x9bV\xff\xde\xb8 \xd9\x1e\x9b,k|\x8aX\xd8\x10\x1b=\xd1q\x120.TL\x14\x99\x89\x14\xb3\xa6\xe5x;\x9e\xcd\xf2i4\xe7\xf6\x9d\xb2\xc8\xf3]Fm\tE\x8a\x1b:\x7fH\xf6+\xe4|G\xd4\x99\xca\rg\\ \x17\xda\x98\x82\x86R\xb1\\\xaf\x8bl%\x86\x9a^{\xc7\xf8\xa1wCt\xbd\r\xd8\tN\xb9\xed=w\xcd`\x95\x9a\xa4\xcc\x13T\x18!\xea\xb5\xad\x01\x803\x8b4\xb3\x8f\xb8\xa4\x1f\t5y\xa6\xa0\n\x88\xed\x02\xd1x\x0b\xa0)2\xaa\xa0\x864g<\xd5\xb8\xda\x83Q\xbc_q&\xfa\xeb\x88\x95t\xe1\x1eU\x7f\x9c\x13r\xb4V\n\xd34\x8e*\xdbf'
|
|
|
|
|
|
2024-12-14 17:54:45.427985 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 191
|
|
id = 1577
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 171
|
|
chksum = 0xc644
|
|
###[ Raw ]###
|
|
load = b'\xeb\x00\x00\x00\x01\x08\xf4k\x98\x9b%:\xa7\xd9\x00@I\xe0G\xbfGa\xbc\x8e\xa4\x1e\xc9`\x90b\x02kt4C\xff\x9e\x19\x1a\xfe\xb0=@\xd6\x98\x94\x02\xbe\xa0L{\x82X~\xc9*M\x93\xdc{u(\x0f\x0f\x94\x8f\xce\xe3c\x9a\x83\x92\xdc\xa6\xf3|:\xbf\x92\x17\x96*g\xa6~\x13\xe4\x99eNM\xf4k\x98\x9b%:\xa7\xd9\xed\xb1\x18\xe7\x08\xa9;&\x1a-\x91\xdfw\x8b\xd5\xca\x00\x12\xe0\xe2\x15\\\x9e\xf5\xbe\x86\xebZ\x96y\xa9<z\xccD\xd6!\xbd\xbe\xc8\x7f\xfc.,O#>[\xd8\xd8\x03\xcf6^\xaa\xd8\x1e%\x93}\x04\x82\xbb\x8b'
|
|
|
|
|
|
2024-12-14 17:54:45.431830 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1480
|
|
id = 3493
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124377343
|
|
ack = 2099799628
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 516
|
|
chksum = 0x1cf3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00E\x98\xbf\xd4WT^\x1f\xc4o\x1f\xf5\x90\xc9lj{z\x1d\xa64\x0f\x9e\x82\xf3!_w\x1bJ\x7f1\xbb\xf4\xa8\x15g\xad\x96\x16-\xcd\x19\x0b\xaex\xcfDDB\xd4<ud\x83\xbaB\x16\x82\x07Xsk\x85\x93\x8f\xb7\xf9\xdc\xac\x17\x03\x03\x17\x8b"\xb5`P\x14\xef\xa1\x14(H7\r\x80\xa2\xefcp\x14\x9e$i\xd8\x18[\x8d\x9a\xf9\xc8\x8d\x18\xb6Y\x1e\x8d\xa0(\xe4\x03&\xb44\xba\x1b\xdc\xf6\x82t\x14{2\xbf\xf2\xa5@\x1bc\x86(\xce\xaa\tI\x11A8wP\xfa\xd4\x89\x8a\x19\xbalZa\x86\xd9\xe87 \xb56\xe3\xa8\xbc\x06s~\x17\xc9\xf5 \xfb\x08P\xfc\x85\xb9?\xe9\xc2\xa4:5v\x98nu.k\x88\x0c#\xeac\xfa\x9a\xa2\x10\xb2\xb7\x19\xfc\x93c]\x97WN\xdb\xb3Dl\x91\x86\xa7\xf7J~\x1c\xec\xed\x08\xfcbD\xbc8\xb7\x82\x87\xbe{\x98\xc1\x82\x92Q\x9d0\x83\xb1\xcaS\xf7\x9f\x1b\xda\xe4\xd69\x81\x08\xae\x19\xe2\xff@\r\xb2\xddPk1L\xc6\x1b "\x01P\x93\xc5\x81}x\xfe\x98\x134EGc\x12\x04@\x1cN\xf9\xa1u\xcd\xac\xf8\x80\xa2\xe6\xbc\x9fC[c\xde\x1a\x89_X)\x13\xbc\xf5=\xcf\xaaD{\xf2\x96T\xadju\x80\x17\xd2zD\x18#\xdf3-\xb7{68(\x9e.nV\xe0D\x1b\xf0\xa5K\x84\x9c\xf1\xfe\xc7\xb6\xb8\xdfq\xe9\xb1LyF0d#\x863\xbc\xd4WI\xb4\xe0\xb5\xa1\x9d*\xa7qP\xa7\xa6\x8c{\xf5jY\x02M\x14\xa3f\xeaG\x0f\xf9H(*\xbf<o\x81\xaf`\x8c\x83\xab\x1f\xe7\x8b\xd7-\xa2\x1by\x18o\xbd\x9f\xc6\xb7\x92\xe9:\xcb\xb0\xdf\x9d\xed\x83<\x0e1\xd9c\xddM\xb7F\'\xbb\xc4ZA\xed\xc1Z\xdb.\xf4L\x9bNp\xb4\xba\x93\x17\x05l1\x17\x115bp-iLU\x8b\x107ca\x12\xb9\xd0I~\xda_\x10\x86\xfa\x98i\xbe\xda\xae\x18s5O".\x98\xb1\xb0\x16\xab\x88\x8eKgv\xf5v\xadj~N\xac\xdf\xb03\xe8R\xe7\xf7\x92t*\xbaRF\x95\xf2\x17\x10\x99p\xd9\xf0Zy\x9b\xdcl$_\xf7\x81@E\x02\xf3\xfa\x13i\xe0\xcb\xdd\xc1a\x94/@\x1d\xe3\xe8\x9f\xd6\xe3\xbb\x89\x86VtQ\x16\xf2U\xa3\xb5mY\xd9\xbb\xc8\x01$]\x8a\xf0*?\xb2"\x0f\xee\xda\x0e\xcaI\x95\xd9\xee\x06\xf1\xbe"\xf1y\xa8z\x86\x89jl\xd2\x93}0\xc9\x85\x99\xcb\xe1\x1e%M(\xe2\xb2\xd6\xa6\x1c\x0e\xe5\xf1L\xe5E\xae\xc62\xb0>\xb3\x9e\xda\xc4\x8dE\xed\x9f\xec\xe3X\xbdC\xc1Q\t\xa7\x81:\xcaF\x19N\xbe\xf5\x88r\xe3\x02%\xb9\x16\x08\xbe\xca\x0c\x89\x00\x06GX$\x11\xde\xbcG\x9b9J!$\xa9]\x80iA\xba!\t\xcc\xc0\xdb\x80\xe9\xbc\xab_,\xb0\xdf\xed\x0e7\x98\xe2\xc6;\x12Xp\xaf\xb3\xe1\x90\xc0\xe9\xfcz\xab\x1a#^ m\xfc\x91\xc2\x93\xe1r\xf6\x11\xd5\x8e\x02\xad\xb65W\x15\x065\xb3\xe7\xe3\x89Z\n!U\x91\xf2C\xca>\xc4\x85x\xb4\x96HJ\xcb\x80K,)\x9f}o\xeb{\xf5\x87y\xcd\x9ek1\xdd\x05\xbc\xeeu\xdb\xe3LS?\xc2to\x96nX0\x99h\x88LD\x95\x12\xe1\xf7c\xfa\xf1\x9a\xf9\xc2Ns\x973\x9f\x97\xfbt\x0e\x01\x12\xb4\x113]\xd4\xfc\xd0-\xb1\x9bd\x07t\xec\xdd\xf8\xb2O\xa2)\x01\xe4L\x14\x9e\xa9\xc1\x9a\x0c\xb1\x0b\x0bR*\x1f\x94\xe6)Z \xfd3\xe5\x19\xd3\x1aK\xa1yJ\xa5\xd2\xed\xd5\x97_\x88/V\x9b\x071\x07\xafqw|D%\xc6h\xf5o\xd1\xac\xc3M\xeb\xbc\x90m\x1f\xf1\x8b\xd8\x88/=,\xdb:\x02\xdeF\x9c\x90\xab1\xcf\xce\x03\xcfV\x8a/\xe5\x8f\x9b\xcdX1\xb8\x91\xd5\x04\xe6z\x01l\xd4A\x19\x95#\xaer1\xaa\xbb3R\x91\x86\xbf7\x88\xc1\xf3\xf4\x901\xdb\x06\xa1\x94!\x18&r\xf0\xab\x12|\x8eZU\xe3\xd6\xa5\x11R\x9dD\xdcw\xcbf(_\x04\xc9QK\x1f\xc9\x81S\x94^\x9b.\x03\xd4sa\xa8\x86\xb5\x0b\xa0\xa0]ro\xd7\xfah\xa3\xdd\x16\x0c\x99\x92\xd85\xe5_T1r\x1dd\x01g[\xa6\x9c\xc9q\x90QQ\x1f\xa7\x0e\xc5I\xa4\x80;\xb9\xf5~,x\xc6\x88K@\xc7m\x8e\xea\xab\x03\xc6\x83\x03\x19H\xdb\x92\xef\xf1.\xff\xca\x08\xd3:\t \xf9\xdb\xa6\xe9+\x93\x05\xe2\x11\x90\xf3I}\xd0\xadoW\xf0\xca\xa2\x95_}\xc2p\xff!`\xdc\xe7\xadzXZ\x01~\x87\x13\xc7\xe5\xf5\xf5\t\x1f\x0c\x9f\x06\xd2\xc7\xf3\x82u>\xb2C(%\xfd\x80P\xccJ\xcf\xe5z\x0f}\r\xc3\x88\x18"\xd9-\xcb\xae\xc8\x17n$\x1d\xb7\x9eM\x90?\xd9\x7f\x03C\x05"\xe7F\x8f\x8c\xb6Y\xe1Ox\xf6%@\xfdau\x0eRO+\x836\x85\xc8\xf2\x87\xac\xdfH\x81\x8c\xe3Je\x10\xaa\xb7g\xcc78P\xba%\x19\xd6rc&nx^jO\xc0\xa0\x9f\xfa\xf5\xcf\xcc0\xb7\xa0<dH.c\x0e\xca\t=*\t\x19\x15\x0e\xf0E\x923\x8a$\x82\xfc=j\xaf;u\xdeu\xa9D?\xea\xa4,\xac\xd6\x19m\xf1.\xce\xd1\xf7\x00\x93\xfc\x92\x03\xcf\x83\x1d\xd2BN\xdc|\xd7\xfbWhdZ\nTJbE\xe3,\xae\x0b!p\x85w%\xf4AwS\xcd9\x17\xd1\xb9\xf2$\xb5*\x19[E\x15\xfan=\xbc\xca\x89d\r\x9e\x9f\xfa\t[\x163{b\x08\xcf\xb22"\xa5\x1bwe\xd4\x01\x0bt;\xdf@\xaf\x9f\xb9\xef\x04q\xee\xbb\x9b\xe1\xa2o\x98\xbb\x8c:\x04jvr(U\x1f\x1a\x0c2\xb9\x11c\xc4^\xd7\xa1].rg>\xedj\xec\xeb\x02\x9fWZ\xf6\xfaj$\xf3\xd1\xabl\xf2Q}\xe2\xa6\n\x16\xae\x86a4'
|
|
|
|
|
|
2024-12-14 17:54:45.437278 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1480
|
|
id = 3494
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124378783
|
|
ack = 2099799628
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 516
|
|
chksum = 0x1cf3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xc4\xc8y\n\x19\x91\\a\xe6\x94\x95\xaf\xee%\x91\xae\x82\xc4s}\x1090MS\xf6u\x18\x80\xef\'b\xed#\x15\xe6\xdcu\xbf\xdf\xfcE\xefv\xc9Xt(\xd2\xf2rH\xc6w\xd5\xfa925g\x95m<\x1c6\x86\x89\xf2\xbc\xf1\xcf\x18\xe9\x8a\x950\xdd\xe9\\\xd5b\x94[\x18g\xc9UG\xebc\xac9\x91\xe3\x14\x98\xd6\xdc\xc7\x15\x8c\xb2\x0e\xed=!X\xf3u\x1aVn\xc7V4\xd3\x90h|^\x9e*G\x99g\x9b[\xdf\tU!=\xad \x84\xe4\xc0\x8d\xbc{\xa0\xf3\xbb\xbd\x1c\xbe\xae\xc0_\xdd\xa26\x87b\xf5S\xa9\xa6\xff\x0c=\xd6\x9a\xc7\xe1\xc13\x93uS\'=\x01\x96\x9b\xc9\x08\x9c@\x99\x1e\x1en\xec;\x15s\xb8&\x1a\x84\x9a\x80\xbaB\xefQJT\xd3\xed -\xaf\x1cT\\\xea\xb5K\x10\xddM\xcb\x86\x9e\x1b&\xd9\xd3\x12E\xee\xed<\x19"\xd5\xda\x85Ch\xd0\xb8C\xe3\xb6x\x9f\'\xa0\xb3v\xfcZ\xd3\'|\x05I\xb0v\xd1#\x82\n\xcdF\x929\x9cK\xa2<\xdb\xe6\xd5\x92\xa8\xe2De\xf1\xe6\xcd\x14>\xd3\xd2g?\x0c\xcc\x8a0\xc4cKI\xa3\xc7T3)\xd3\x07#\xc5\xd9"\xfc\nz\xa7\xb6\xd7h\xb4\x7f\x86\x9c\xc3\x17S\x8b\xd2\x1e\xd4\xafd`!\xed\x1c~bq\xa1\x91, \xd2\x99\xfc\xae"t\x06$\x1f\xb2\xbd3\xcd\xe9]B\xd2=Siy\xca\x19\x1aY\x83\xf6t\xf0\xa6BC\xdd\xbc\x03s\xaa\x03\xd7o\x93lt\x98Y\xce\x1e)\xc9)<\xf8\xc2\x12\t\xf3M:\x1a1\xd6\x05nW\xfe\x92R=\xfa\r~\xf9d\xa9\x97\x0bN\x9b\x1b\xf4\xa8t\xbc\xbcg\x1e\xa9\xb5\xd4Y}\xec\xc8s\xd4\xc0\n[x\xa6\xdb*\xf3\xb9\xcf\x87DC\xdc\xb5p\x0c\x8fO}]\x1f\xa2F\xfeP\x1a\xbeb&R[\x15\x18+\xc9\xff\xa4W\xc2\xe2\xd7]\xe3\xb8\xc1\xf3\xa1\x82pX\xf89p\x15\xb2\x81\xcf\x01\xb3\xc9*\xce3>q\xed+$\x90F\xfbN\xeb\xa1@\xee*p\xe9E\xd3\x90\xb5i\xb4\xf1\x91\x01\xbd\x95\x8e\xa3\x97+1 \x8f.\x81#\xe3\xbf0\x9a\'\x9f\xff\xaf\xebmc\x82\x86\x03\x1f\xef\x0b\xe7E\xf4\xc8\x8a78"P\x15\x15f^\xb4\x9a\x8b\xbd\r\xd2\xc8(\xda\x92mkF\xec\xf2]\x91CV\xf8\xa3\xef\xa57\xaa\x86\xed\xa8^\'\x8e\xc2\xe9\xec\x80\xe3{`6\xcbA\x1b\'#\xb7\xa5\xdd\x80\xce\xff\x8d\x9e3\xa2C\'\x89\xc1}\xb5\xe4h\tC\x85\xc6\x91\xfb\xa8\xc5r\xe6\x07\xd2W\xb4\\\xb8\xfc\x96\r\xd0\xc9\x9c\xac?y9\xcb\x08\xee\xef2\x04%\x11t\xbe\xe2\xae\xfeR\xbd83\x8c\xc0\xba8\'C\x891xuj\x910\xc1\xce\x85\x97\xd1Ok\x0fn\x1e\xfbuWJ\x005\x0f1*\x0b\x15Fi%\x058T\xaf\xa7\xbfk\xed\xae3*a \xef\'w\xa0\xa1\xee\xea\xae\x1f\x9f;F\x88\xe7\na\x99\xbd\x99\r~\xe14\x86\xffga\xa6\xca\xa0hZ\x9d\xb9\x07%\t2\xceJL\xfc\xc8\xe3\xa8\x95\r\x17\xce\xc08\xcb\xa0B\x9b\xad\xdc\xab\xe3\x1d\x80a\xab\xa7B|>v|[\x1a\x0e\x02\xad\x1e?\xf6YV\xbc\x9f\x8a\x1e=\xb2+\xcd\xe5zY\x1fa[\xee\x88-\xff\xb2NR\xedhh\xf0\xe5\xe2\x17\xbf\x92$\x9f\xab\x10P>\x7f\x89\xa4\xc7W;\x9cB\x8c\x97\xa4\xf0$\xdce\x85F+\xf8\x98\xa5\xa7Jt\x82e0\x17\x92\xfa\xca\x97d{\xbb\x0fB\x89\xa1>\x00\x81\xd5:f\x16n\xd7e\xe3\x9a\x03\x0c\xf5\xcbi\x06U\x82\xd0\xe1\x84#C\xd3\x80\x9c=Nb\xde\xb3))2\xae\xf9\xb8\x1f/\xac\x13\xd8\xa7\xcc?Y\xe4+\xb1\xacF$\xb0\xa1\xb75\x9d\x8a\x06\tv\xc7{\x17l]\xee\xce3\x92Eg\x0c\xb9\xc86*\x9eff3\x94\xb2o\x1b\xb0\x00\x8el\xcb8sp\xd6\xd1\xbb\xf9\xd3\xb2\xaeO\xdc\x93\xeeK==$\xb9\xd9G\xe4\xfa\xa7p\xe1#c#\\\x11\x97\x88}\xf1\xc3\xf9u\x19 \x85\x0f\xa5A\xa0\x1e\xd7\x1b\x9b-e<!\x9dD,C\x9f\n\r`f0SB\x99\xd2T?b\x91h\xb2jE_"\xe1\xe0\xf5>\x9c8\x15\xdb\xa2\xe0\xaf\xd5\xc2;"\xbbC2\x8ea\xba\x11\x14&\x9f<#\xf6\xaa:\xc0\xbdt1FN\xf4\xcd\n6f\x16n.\xff\xe3;\xa82foy\xa7;\x1d\\/~\xd7\x19\x10X-\xc9\xb2\x0b\x14\x1b\xaf\xf8\xb8\xe4\x92\xb7\xd5\xbd\xab3\xeb{]\xe2\x9e\xa3\x80dy\xaew\xa3\xa6A\x17%\xed\x1a\x1a\x93\xc9}\xc9G"\xb8H\xd1\x1f\xff\'\tl\\\x1f$\xdfzH\x1d\xb5\xce)\x94\xe6\xf0=[\xb4E\xe2z\xaa4\x0b_\x90c]\xdamY\xff_G\xeb8Q\x06\x05\x8a\x19,\x81\xe9>\t\xcc\x12\x07\x98\xa2N\xcf\x16!A\x81\xe8\x1b\xae\x7f\r\xfd\x87\xc1\xe6clW\xf5\x8e\xb9?N\x18\x1c\x1d)G|\xd1\x1c\xddK\xc6\xfa\x04\xc9W=X\x8c\x82\x91\xf7\xb9\xccK\x7f\xb8\x1b\xf4=\xbe\x95\x91)\x90)\xa7\x8cwG\x99\xe86\xc9\xa9\xd8\xb1\x89\xdc\xabX&O\xc6\xd8\xb2\xdc6f\xc69?\x11\xb0\xeb\xf0#78k\xae\xc2\xe4\x1c\xd7q\xa4\xa2\x02<-\x16\xee\x1e\xe9\xec\xe2\xb2\x18M\x90\xa5M\xa2\n\xab\xcd\x99\x03{+\xc558\x07\xb4\xf7\xa0\xde\xa3\x07\xb0\xab\x1a\xb75\x84y]\xd5\xb5\x1dP\xfe\x8b\x87\xdf\xd9@\xa6E\xac\xf6<\xef\x93\xb5\x11\x03\xa1\xbf\xd1+\xe5\xd6\xb5\x8a^\x93:\xbe\x1b\x12\xfa\xe6\x9f\xb1S\xfc\x93!\xd7I\xb2\xe2\x1b\x7f\x97\xc8\x80,Zv\x96\x93\x81\xb9\x1d\x0e\x91!b\x9c\xeb\xa1\xe2yh)\xd1\xf6\x90 C8\x80\xe6\xcf\xbb\xde\x01\xdb8f~\x80`\xff\xfe\xae\xdf\xc2\x86H!\x8e\xcf\xc4\xc4W\xcb ^'
|
|
|
|
|
|
2024-12-14 17:54:45.443454 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1480
|
|
id = 3495
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124380223
|
|
ack = 2099799628
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 516
|
|
chksum = 0x1cf3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xb7|S5\xf4\xb4\xfd(\xb44\x9f\x9d\x89\xd7\x10\xdbGvS\x91\xe5\xd3|\xab\xb4Cjc\x08\xee\x8eM\xc4i\x04%m\xde\xe94=\xf2Xs\xf6u\x96\x04LD\x19t\x9a\x8e+:\x9f\xbd\x9d\xc8@\xdd4\xa3\xfb\x8ct\xd3\xa8\xba\xe2\xde\x85\xa5\xa5\xf4\xce\xeb8F!\xa1\x04,\x99\x05 E\x08\xb1\x95\x855\x08\xeb\x81/VA\xecS\'<\xe2N\x003\\\x9ch\xbb\xb1\xd0\xff\x96\x12\xcc\xb6\x85\xfc\x9eIzJ\xaa*\x9d\x90\xa3\xac\xfeJ\x8b3\xae\x81\xdd\x06\xf5E#UaM\x97\xc8\x11\xfa)\xa5\x16\x88\tD\x0c{=\xdc\xa3\xcf\xea\xb7\xd9O\xf4(\xba:\x1ak&\x96pC\xd7\x06\r\x03Z1\x8fm\xe37\xb5\x98\xa6\xe0\xc3Lj[8\'h5\xe5\x1b\xedmm.t\x1d+\x97 7}\xd5\x9f\xc7\xd2\x18\x8d$\xa9\x12r\x19\xfbR\x9c~\xf0S*\xc9\x00\x9f@m\xe4\xfd\x0b>\'\xb1\x97\xccN\xedI$,\xe4H\xba\xf4k\\\xb1\xef\xde\xae\xd0\xdcZs\x85\xabZL\x9b\xc2\xb9\x98C\x00\xf7(6\xb9\xc9\x8a\xce\xd7\xb4=Z\x9c\xf9\xee\xce\xd8\x8e\xe5\x90\xda\xda\x94\x9e\x10\x01\xe0\xa0\xe1\x8e\xc81Ex\xe0\xcca-7\x02\x8bx+\x1b\x1bC\x19\x94u\xe1z\x02\x04\x0c\xd3\x06\x84\x05iC\xb1\x1b\xea\xbap\x16\x19\xd28w\x1d\x95\xc2\xc7\xc35\x8cX4\\\xb9\xc8#\n\xf8\xa7\'\x00\xbb\xec\x15\xc8y\xf7k\xaaB\xce\xd8\x12)\xbcUM\x18\x04\x11\x8a\x91l6\xd3\xc8\x9f#\xc4\x14\x8ba\\\x9d\x9c\x8d\x88\xcco\xd4Z\xbba\xc3e?.\x7f\x0c\xea\x06\xd6Ep\xca\x9b\xe1c\x8a\x96\xe3\xe1P\xf9\xb7\xcav\x8dT\xe5\xff\xf7\xb7\x95\xee\x07\x13\x19\x93\x97\x1c+\xac\xb6o\xc8\x06L\xd9\xber7D|)\xf8nG\xb7\xd0\xa4\xd2\xb3\x0e3o\xdbe\x10|\xfa!\x16!\x8a\xdd\x80\x01--,UQ 5$T\xfc\x8b^\x10D\xaay^\xc35m5j\xd9si\xa1\xe7\xd5\xd5\\#\xe6\xcd\x01\xc8*\xaf\x9a\xbd\xea@\x08\xf2\xe1\x80\xd0\xdb\xd0\xdc\x0e\x00\xc9\x99n\x8a\xa7#v"I5\x08m\xa8}}P`\x8evi\x0f\xe5\x93\x80\xcf\xd7q\x9at\\m\xd4\x8c\tN\xd9\xc1\xf0\x99?(\xcc\xb9Iep\x9a0\x0b\xff\xa3\x83M\xc9\x997\xbe\xd3jHeu\x88\xbe\x17\xbb\x0cXi\x96IYm\xdd|\xe7\xf0\xb9\xa6{\x93\xeed\xf7\x89\xe5\xfaXT\x97>\x0e\xdd\x08\x92T\x95\xd0\xd7\x16u\x97\x1aZj\xc4\x171\x1c\x1b\xa1!&\xd7Cc\xf7\x81,(\x11T\x82W#\x9c\n\xe7K\xeb\xd2\xba\xf6uw\xb2JM\xa70\x1d\x01\x82\x81\xe7j\xfd=i\x94\x89VZ\xd4\xf9|\xa1\x9a\x1a\x9f\xa8\x00\xfd-P\x04\xbffxr\x04\x9c\xe9\xffb\xcd\x7fwI\xe4\x13Z\xcf\xe1\xbbN\x05;\x0b\xa1\x9e\xf3\x82o5\xacT\xb7I)e\xcb"\xe2\x9c\xdan\xbe8\xa7\x19H\xccV\xa1fA\xbc\xe4)\xe9\x05u\xe3r\x03\xfe\x07\x85\xc9\xd2\xe6\xf4\x1c\xd2\xf2\x11\xf5\xa39\xf5g\xab!cT\x1c$\xce \x7f\x8d-W\x17o\x0bC,\xdc\xf2,\x11k\x81\\\xf7\xccx\xaa\x9a\xea\xa0\x88\xfb\x01\xf7*\x18\xcfk\xf9B\x05\x89}\xef\xaa\xff^\t\x8fs\xab\x8d\x1e\x9c\x88\x96\x02\x9d\x1c\xb3l\xadkh]\x01\xe3G\x05\xa9\xab\xab\x88z\x8b\xb9P-\xf8\x86\xce\x03P-]\xee\x89\x10+4\x14Rz\xde\xbf\x10\xf65\xfe\x8fS\x06\xd6\x91\x80tT\x136\xae05R\xd9\xe6\xf8?\xda#\xab\x06\x14\x1c\xd1\xbf\xf1ph\x04\xa2\xe8}k$xK\xcb\xcd\xe2\xea\xea\x97\x8e\xfd=\xa3\x9fP\xc9\xa0\x00u\xb0\x04\x02\xae\n\xda\xd2\xbd\x8f\x11Rzp#U\x01\xe8\x0b#\xac\xfb\x14\x86\xae\x16\'\x87\xfe\x86\x10\xff^\x81\xdd\xa1\x7fv\xf0\x13e\xf3$T\xe7\x1a\xf7\x8f\xae\x81d\xf8\x97\xd6\x99o\x14\xfa\x06\xaa4\xcf\x04%QQLk\xc62\xce\x83\xe5W\xa1#\xe5\xd2HA/d\x8a\xf2\xd9.#\xb2\x9d\x17\xa6\xbd\x9aJ\\\x8a\x04\x0eFWx\x9a\xd6\xad\xb9\x16\x18\x85\x05\xb7\x9fd>\xd9\xc1\xffr\x0e\x960\x10\xc8\xef_@3\xfc\xdf\x9dT\n\xf5\x87\xea\x03[A\xbe\xacV\x17\xb7u\xbc\xaf\xb5w>\x92,\xd0\x88\'q\xc4\xfb\xb9\x1e\xc3\xe3\x89\xe2!\n\xb4\xfa\xb0H\xcd\x95V\xce\xd5\x81&\x16\xdd\xf2\xcfeV1\xd2\x84r\xa9~\xa2@\x93\xb2\xe0DX\x1b\x0cwm\x99\t%\xc8\xce\xb7\xf2\xc9:\xc4i0\xd5\x9aa3\xf9w\x9cg\x8fI{\x8b/\xe7\xe1\xf4B\'\xb2\x16s\x80\xdb\xf4\xde`\xf2\xf7\x91&\xa4z\x02u[\xaf\x8dX\x9e\x8b\x02\x02BL\r\x18\xa1\xf26I\xe7\xa8\xd8.\xac\xf7%O\x1c\xecfQ\xf1\x92a\xcd\x13\x15tB\xd8\x80\x19"h\xa2\xb9\x98\x97k\xd8\xdd\xddYU}w\xdee\x16f>\xea_\xa1\x7f\x94!^O/\xf9-\xa9\x96\xd9\x1d|\x93\xfe\xffU=\xfb\xcb\xb9\x96\xac&}\xc6!f\xc3\xe0\r\x0f\xf3P\x80\xf8~\x818\x8aD\x84\xc3&\xa1\x1b\xafO@\xb8\x88\x92\x0eN\x1ac\x97\x08\x8d\xf1\x7f\\\xf4eG\x83\xd4)\xb7\xac\x11k\x96\x9c\x17\xa0\x8b\xc9\xfa\x1e\xb9\x1e\xc4\xe5\x04|z\xfcT\xec\xb4\x94\xae\x98\x96\x84\x07"\x9be\xd4l\xdc\xb0\x0fQ\xec_\x99\x18 \xaa\xec\xb1\x87k\xb0\xc5\xdb\xd5\xdc\xe1\x02\x15F4\xb52\xbd$\xc1\xc8\xce\x18\xa3H\x95J\xc0U\x8ae\x81\xbd\x00\x00\xd8`\xc3U\xefM\xa34\x1d\x96\xe0\xb6 \xfabn\xad\xa5u\xd7\xc5\xa9I\x8b~R\x86{\xce\xef\x86Z\x02\xdc\xf0\xc3\x7f\xce,\xf2\x87`\x96\xf8!\xea(6"\xde\xe3s=#\x92\xb3\xc3g\xe7\x90OU\xb0\xd0\xc5bt\xabW\xcf\xa0'
|
|
|
|
|
|
2024-12-14 17:54:45.451331 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1480
|
|
id = 3496
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124381663
|
|
ack = 2099799628
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 516
|
|
chksum = 0x1cf3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'W\x0c\xde5@\xb1rt\x143\xec7\xca]"8Q_K\xf5\xc92R\xac\xd1u\x08\xd9\xd7(\x88\x0e(\xe7\xf6\xd6\xdb\x12\xb6-iz\x118ai\x97\x18-\x01H\xa4~\x8d8df\xe5\xbe-\xec\xc8\xfc%ia\x8d\xc5\x06\xcf\xf6I\x1f\xd2\xa3P\x9c\xe0g\xad\x9c\xad\\\xd0\xa9\xb1\xf2bw@\xd1\x1a\x88\xc7\xe2-\xf8\xa0\x85\xe6\xbak\x91$a\x8f\x96P\xbd\x1bhd\x14\x9e\xdb\x0e++\x99\x0b\xfd\xab\x80%\xc3@O\xc4\x85\x1e\x86\x97\x05\x1bT\xcc\n\xdc,\xbf\xec\xf4\x9e\x05\t\xa8\xe5\x18\xc2\x8c\xc9\xbc\x06\xf2C\r\xbe\xe3\x19\x1av?\x83"\x91\xbf\x9f\xaf\x818G")\xe6\xddB\xbc\xbc\xe1-\x0b\x06\x88\x91\xdb\xac\x947\xee\xc6\xafl\xda~t\x02\xd5\xbd\x1d\x96\x95\t\xdd\x02L\xd03\x0f\xc8w\xb1\x0c\xe8\xef\x17\xfe\x9fdHW1\xc4\x11\xb7\x03O\x9f\xdf\xd0\xaa\x8c"\x0eO\xe6\x99!\xc9M\xfcq\xf8\x1e{.\xfepV9\x8a\xc7&\x8e\'\x87\x0c\xff,W\x00\xfb\xdaN\xfa\xe8\x87\xb6\xb5\xbcp\x00\x93\xed>I@\xa7|\xa2\x0e\xc7f\xbe\x9cN\xbd\xc7_N\x83\xafZ\xe9\x8c\xd7U\x8d\xfet\xfd#\xef\xdb\xbb\xd9G\xbf\xda\xc1T\xd5\xa5\x82Mf\xa0=]\x92\x974j7\x96\x8d\xdd\xe9_\xf3\xd7\x9b\x06\xc6\x03R\x9e\xe8|\xfa\xaa\xaaR\xab\x0ee\xc5\x1e\x1b\xc0\t\xf6\x04\x16>\xac\x01\x16\xa8\x1a\xa9c\xac\x8ej\xfd2E\x88\xac\x9b\x02\xb7\xb2\x19\xb0\x08JS\xf6E<\xcc\x00\x9f9-\x96Ka\xbb`\tl6\x89G\x02^\xad\xa1:\x9f\x7fs\xe3\xe2\xa83\xbes\xf5"\xfa=~HR(\xfbu@U\x82\x13\xa4\xeevE\xef\x81f\x80\xed\x91\x14\xcfWcZ\xbca\\\rH\xc4F\xe0?\xe7\xcd\xb5\x98Zj\xb4\xe9\r\xca\xf3M\x16\xce\x88\xe7\xedv2\x05\xd4y22\x89\xb8\xd1\xaee\x95#B\xe3@\r\xce}\xccV\x83\x01\xfc\xb5\x95\xf8\x0b\xa6\x03\x94@R\xe9\xf5\xea)M\x1b"D\xd9\xc0\xc9(J\xbdZ<\xd0\x1e2\xf6\x08\x152\x10\x9c\xda\xe5\xcd\x9c\xbc\t\xe5\xb5\xf3\x1d\xd4\xf4\xab\xb8K\x13\xef\xfb\x17\xa1i\xad<\xe4\x12\xca\xba\xf4\xc6\xc6\xda\xdd\x9c\xbe\xd8q\xa8P\xbbV\xfbd\xab\x08\xa1\x91\x12\x13\xd1 \x07@\xeeJ\xa2\xdcx4\xcf\xef\x1d7\xcf\xd85N\xb5\xce\xcaT\x92\x03v^`\x8fw\x82\x98\xe2\xaeWn!\xd2\xd9\xe4D|\xf8\xfb@\'t\xcb\xe7\x07)\xab\nd\x1eh\x7f\xb7\xd4\xf3\xd15\x15\x9a\xd4)\xf6{\xa2\xfckR\xee\xba[S\x82\xc3\x08@M\xfd]f\xbc[/\xf7\x8d\xf7\x17I\x8b\xac\xdc\x93\xdfr\x83\xb83\x95\xa6{TP\xc8\xc9\x12\x9c\x91(SL{a\x10\xeeT\xc1d\xbc\xb4\x108\x11\x9a\xd9\x02\x1cN\xf2\x13\xff\xb4\xd0\xfdT$\xdezUn\xbe\x90\xcf\x11\x8a\xe1\xee>l\xa4:Y2\xff\xa1i\x0c\xc9T\xbem\xd0\x8dC\xbe4\x18/\xc8\x16\xdc\xf7\x0cb\x8d\x01y&\xbf\xff:\x9d\x17\xea\xed\xae8R\xd83\x7f\x86\xc3\xe3\x94\xf6\xcc\xfd\x1a\xc7\xead\xa3\xbe\xd8\xec\xc9q\x16\xf9\xd1k\x8a<\x1a/\x0e_\xcf\x9c\xa3\x16j\xf1\xc1\x17C\xcf\x91\x15z\x8b\xd9\x11\x17\xf2$\xc1\x9f-\xc2r\xbc\x19\xf8XS\x02\x17\xb1\x1dpC\x02\x07\xa5E\xf2\x87\xc3\x93\x86^\x85E\x91\xba,Y\x89\\\xbb\xfe\xab\x16\x00\n\xb8\x86g\x96\x84\xcd5\xaa]\xbek(`\xb4Gi\x9a\xf6\x97^\xd9\x15x*\xbb\x01\x93\x19_:\x16\x83\\~:#\xa1#\x9f\xb8\x8eA\x00\x1eL\xb9\xcaK\x86Gw\xd1@\t\xb8\x1b=v \xf1b\x05\xa5\xce\xb1\xa4"\xb7\xb0\xdfl\x10\xee\xc6\xa0\xcb|xS\x9cE\xaa\xe7\xcc\x12&k\x98En\xca\xa0\xcc\x02\xcb\x91\x87\x9fM\r\xe5,k\xed\xc68D\x15*RcW6\xdd\xe6\x84E\xe7\xc0\xb8\xe5\xcf\xf3%\x08\xfe4\xd3_\xaa\xd11\xceg\xd3\xf1\x06\xf6\r+\x19\x8d9)=\xdc\xa3\xec\xe1\x04\x05o\x85\xe9\xc2"\xa1RG\x12gJ\xdaz\xdd\x1f\xcb\xa9X\x07NW\xcbV\xf5\x9f\xbb\x9c\x94\x03\x91\xe3\x98tb\x8d\xc0\\"\xa0A\xb4\xeb \xcc\x85\x9b,\x86\xf6\x89u\x80\xc1\xb6\xa9u\xcba\xbfS\x0c7>\xa5\xa6\xd1\x10\xfb\xb1,I\xad6\xa4#\x17b\xc7:\xd7\xe4\xff\xcc\xa1\xcaD`\xe3g\xe0\xc1?\xafT\x06\x83\xee\xc3>\xdb@\xf9.!\x83\xfe3\x8e\x08~\xa9\x9ds\xca\xe3\xec\xee\xac\xb0\x0e=\x07\x91\xf7\xdd\x1eU@<\\\x1eX\x95\x18,\xe1\xf3`\x89.\xc4N\xa0W_j2=\xbcjkl\x1a\xe4\x96\xd7\xd6\xdf=\xd7\x9a\xeaG?I\x17`\x9e\x08\xa7\xe1\x02\xc0\xa7\x85d\x05\xf6Ata\x19\xf0f\xa8;\x9bB\xa1ar\\\xfe\xad9\xe7cw\x06\x9b\xc1\xfbYE\xc26\x19\x1e\xb8 \xb80\x9d5r\xbb\xe0k\xa4\x1a;,\x88\xe6\xfeA\x1c\x18\x10,\x1f9\xdb\xc5M\x12U(\x9d\x15\xce\xeb}j\xb4\xf7I|O\xdeybp\xfe\xcc\x83\xe7\xbe\xaf\xc5F \xa9(\xab\xe7e\xf6;`.\xad\x98\xabQA\xef\xae\x10\xc0\x8c\x9f\x06+n\xe4\x85\xce\x1f\x137\x06\xbb\xa0\x8a\x06\xd3\xac \xe5\xa2)s\x8e\x96\xb9\xc5\xa3\xafi\x1eruI;\xe7oa \xf68\t\xd3c\xcf$\xbd\x00z\xaf\x9e\xdf\xc1!\xef3A4v!\x10xN\x9e\r\xf48O\xe72\xb4\xd5\x8bX.H\xfd\x87\xc2\x8c\x0b\xb3L\x97T\x9b\xfe\x10\xb8\xff\x16\xd3\xdb@jH\x91\xa4\xf6\x99~z\xa9\xde\xde\x02R\xc5\xe7Xds\xf3B]\x9b7\xe7}:U\xe5\xb1\xee\xf9D\x07\x83e3\xcd\xf1\xb1>\xe0\xac\xfbSw\xf2\xb3U\xac\xe6?\x03\xe3\xd6\x80\xbd\xb8\xd9\xccu\xf9\x8c\xb7\x84'
|
|
|
|
|
|
2024-12-14 17:54:45.459533 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 386
|
|
id = 3497
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124383103
|
|
ack = 2099799628
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 516
|
|
chksum = 0x18ad
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x01#M5\x80\x92M\xf1\xdd\xb5\xf6\x1b\xe1=\xbb#\xf8\xad4\xeb\xd9p\xee\x98\xeb\xd3\x14\x879\xff\x18\xe67|\x14\x12\xe3+|\xa4\xc3\xb6\xfc\x87.\xec\xc0\xb2\xf2\xae\xca\xf9\x9c\x88\xe6c\n\x89\xb2:CO\xafJ0\xfbB\x1deGoc\xcb\xca\xc4(\ni\x96x\xc1\n\xa4uS\xea\xb4\xa3\x8b\x0c\x87\xbfhD\xf8\xc4S;n\xbeW\x9b#,\xc5\xcar\x0c\x00\x90H\xdf\xd0m\xaa\x99\xd1\xbb\xde\xc6\xc2\xc2?YzK>C\x02g\x02=\x9b4eF*\xeb?\x95\x8cBj\xbb,\x02\x88/ib\x87*E\x98\xa9\xa2\x8bSZ\x1f\xbf\x18\xc1*\xbb\xe9\xc9\x89m\xc6\xeb\xfd$\xf4j\x84\xce\xaaK\xe2DH0\xdc\x9as_\xc9\x02O\x1b\xbfU\xea"\xf354\xe8\xc5h\xe8\xc0\xec&\x8c\x94\x7f\x84\x8cK\xb5C\xf5\x0b\x0c\x81\xd9\xbb\x9b\xe6g\x85i\xa6z-zF&\xf7#\n<\rl\x02\xebf`\xad\x1b\xbcE\x818\xc6\xcf\x18\xae\x05\x82\xdf\xd4\x18^\x8a\xfbq\xe1\x0e\x96ASf.\x13\xa9\x1c\x17wz0D\xd5\xde\xc7\xa3\x7fcXDIuh\xe9k\xb0\xb3\xea\x96R\x02\xc4\x8d\xb0\x12\xed\xe3\x9f\xcd\xb8\xf3[\x88s\xae\xd1g\x19vJY\xd9\xc8\xaa=\x89G\xbb\xe6\xe5i\'\xc6\x0fVC}E\x08\xcfW\xdcR!\xf9-\x17\xf4`\xd5\x0b\xf6\x93\x8d'
|
|
|
|
|
|
2024-12-14 17:54:45.468834 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 546
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7b43
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 526
|
|
chksum = 0x1130
|
|
###[ Raw ]###
|
|
load = b'K\x83\xf2\x9d\xdf\xfbO\xc1\x04\xd7\xaaoO\xba\xcb\x9b7\xcd\x86\x06bD\x95a\xcd\x0c\xc8\xed\xfe )7\x06\x9f\xb9e\xe3G\x1f\xdc\xbe\n\xf4\x8d4To\xcf\xf8\x10#\x91On\xc7\xeb\xa9%-\x98\xc3\xb0)\x0bp\xe0P\xbd\xe7\xc1{\xb5\xd3\x8d\xfdS\xa4:\xbd\x83\x1a\x1b\xcc8\xa7\x18\xf3\x06\xdc-\x1e\x9aj\x17,!\xb4\xe7<\x81\xaa\xcd\xd3\x15(.\xd1\xafb\xc6\x16\xb2R\xa2q\x82\xf9\xad\x1e\xb2\x82\xe6\xec\xf6\xee\xb2\xeb\x12b\xea\xe6\x9by\x1f\xc3\x0f\xfa\xc8\xf1\xcbl\x97\x9dU\xc5\xf1~\x7f\xb2\xe0\xdb1\xa4\xb6<\xf7f\x89\xf4\x01q\xcc\x07\xe7\xc0\xdc\x9c\xc8\x8e-<\xae7^<&\x9d(\xad\xe2\xb0c\xd5\xa5;\xf8\xe1\xe9\xb0\x9b\x15\xd1\xe4&\xcf`\t=5\xa8\x1b\xd0vUA\xbfJ\x11\xcdo\xa7\xa3u\\\xbc]Ug\xf7\xb6\x99\t\xe8\x92\xa7\x0f\x85/\xe0w\xa6z\xc0U\x95\x07\x8fnG\xf0i\xfe\'\x89\x11J\x11tGc1\\\x0f*:W\x8a\xb6\x87?c\xad\xba\xc1#\x1dY&\x06\xa5u\xa2L\xb2y\xfe"\xc5F~Kw\xe7\'\xe9\x03\xc0$D\xf43\x8a\xaf\xa87\xc9\x82fW\xa8\xde\xda\x9f\xfa\x02\x835\xed\x18*\xee E\xdd\x17Wr&\x90\x12TIam7\xf94\xf7\xa7\x0bp<\xfb3J]\xe9q\xe4 \x7f\x80\xb0\x81P6j\xf8c/\xfc\x1d\xec\xd2\x18|\xab\xa8%\x1d\xad\xc2\x0bp\x1f+\xdf\xa7\xe34\xb8\xf5\xd3J<6!J\x82\x91\xed~\xfb\x80\xf3:\xf1<p(\xe8\x1e\xa1\x03-]\xad\x85\x18w\\Y\xf6r\x1aR\xb2\xa8\xf8\x14v\x00\x86\xdb\x9d$\xdbh\n.\xf1:\xcb}\xf3\xb2\xc4\x9enDM+C\x7f\xf2\xb3\xa18zH\x93\xf6\xae\x17\xf5`\xd9\x11Z?\xe6\x99\x10\xde5\xd4\xb7\x8fa\x11\x12{\xe7~\xe7\xbf\x97_\x96\x18n\xae65\xec\xecp\x97\xcb}\xf6\x17#\x9e_\xf2\xbe\xaa\xca\x0b\xc8c\x0e\xb6]\xf5\\\x9f\x8c\xc1\xb6\xba\xae\xba\xba\\I\xbfH\x91\x82\xc2\xfe\x96\xe4\xa9Y\xd0'
|
|
|
|
|
|
2024-12-14 17:54:45.471660 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 149
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7cd0
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 129
|
|
chksum = 0x6ec8
|
|
###[ Raw ]###
|
|
load = b'Em\x98\xba\xe8:y\xaa\xd0\xb4k\xba<\x9d\x8e\xb5\xad7\xb0\x87\xaf\x8a\x1b\xf6\xfa"ZO\x1b\xcc\xa4\n%\xc8\x87\xa6\xad\x95\x89j H\xff\xc1\xf5+g\x0b\x0f\x9a\x86\xce3\xc3>\xca\xbf\\\xc4\xa8\x01%uh\x19\x08\x9ao\xff\xdf+Lr\x99\xab4\x132Z\xd8\xd1\xef\xbe\xd4[L\xc7+\xa9s1hd\xc9\xb3E\xe1\xf7\xee\xdc\xb6\x7f~J\x04\xd3\x08k\x85\xc0\xb1\xc3~\x06\xed\x9bH\x87g\xef\x9a'
|
|
|
|
|
|
2024-12-14 17:54:45.475411 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 55
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d2e
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 35
|
|
chksum = 0x1ad7
|
|
###[ Raw ]###
|
|
load = b'H\xd7z7X\x8c\x8b\xc6\x11\xab\xb1o\xcf\x94<\x972\xec6\xba2\xf1\xa2Z\x87\xc3\x12'
|
|
|
|
|
|
2024-12-14 17:54:45.478514 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 61
|
|
id = 1578
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 41
|
|
chksum = 0xc5c2
|
|
###[ Raw ]###
|
|
load = b"B\xf4k\x98\x9b%:\xa7\xd9\xb6\x14\xa3\x81\xb7a\x9b\x94\xc1\xf3z\x8f'G\xd8\x81\xb5E\xee9\xdck9("
|
|
|
|
|
|
2024-12-14 17:54:45.481039 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 61
|
|
id = 1579
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 41
|
|
chksum = 0xc5c2
|
|
###[ Raw ]###
|
|
load = b'_\xf4k\x98\x9b%:\xa7\xd9\x01h\x81y:@\x1e\xe0\xa4/(\xa7\xb0\x8b\xe1\x0f]3MS\x1d\xa5id'
|
|
|
|
|
|
2024-12-14 17:54:45.483558 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 61
|
|
id = 1580
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 41
|
|
chksum = 0xc5c2
|
|
###[ Raw ]###
|
|
load = b'[\xf4k\x98\x9b%:\xa7\xd9\x03\x9fJ\xbf1\xc9i\x0e\x0euF\x04\x82\xf7\xae\xee\x9a\xec\xabj\xea\x965\x85'
|
|
|
|
|
|
2024-12-14 17:54:45.485950 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7e30
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 33
|
|
chksum = 0x8c68
|
|
###[ Raw ]###
|
|
load = b'T\xa1T\xca\\\x87\xc9H]\x11\xab\x18\x8b)\x1f\xbf[DJ\xe4-\x8eQ\xcb6'
|
|
|
|
|
|
2024-12-14 17:54:45.488775 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40844 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 48515
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xc1b8
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40844
|
|
seq = 3502955289
|
|
ack = 2444971194
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1054
|
|
chksum = 0xb9ea
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (2444972606, 2444973269))]
|
|
|
|
|
|
2024-12-14 17:54:45.492366 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40844 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 48516
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xc1c3
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40844
|
|
seq = 3502955289
|
|
ack = 2444973269
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1050
|
|
chksum = 0xb275
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:45.495003 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 181
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7cb0
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 161
|
|
chksum = 0x47e9
|
|
###[ Raw ]###
|
|
load = b'JE\xa4\x94=\x12\xae\xb0\xbd\x8f\x9b\x9c\x19\x87\xbd\x88(\x98R\xceq\xd8\x06\x83\xba|{\x90\xebVH\xe0loYU\t\xb7\x01\xacSA?d\x02\xe8(\xf1\x1b\x80\\\xcdx\xa1\xfd\x19\xda6\xb0\xc5\xa1\xf8K6\xb1e\xfcz>\xc5]G\x9c_C7@\xe7\xef\xbd0\x14\x9af\xb5\x12\r\x1f\xe5\x8c\\\xe4Ho/wL6\xd0IKz\xaf\x11\xf4\xdd~"\xdbuh7\xab>\xa2U\xac\tY\xa0\x94M\xf90\x1a\xe7RT\x8eJ}\xd4\xb2\x16\xc8\x16\xd2FT\xd6\xf6\xbb\xdcW\xf0\x9f\x97\xf9.d\xcd:\x01'
|
|
|
|
|
|
2024-12-14 17:54:45.497790 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40844 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 252
|
|
id = 48517
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xc0ee
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40844
|
|
seq = 3502955289
|
|
ack = 2444973269
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1050
|
|
chksum = 0xdedd
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x03\x00\x80\x02\x00\x00|\x03\x03\x16\xea\x89\xce\xe5"\x17,S5\xcb\x17\x89o\xc5\xe4\x02\xf2uY\xd0\x1d\x8b\xeb\x85c4\xd0m\t\xae\x85 \x11\xb0\x11]\x9c\x00U5n\x18u\x8a\xd6\xfeZ6\xb0\xcfa\xb1F@r\xf5R\xf8X@\xcb0\xed\x93\x13\x01\x00\x004\x00)\x00\x02\x00\x00\x003\x00$\x00\x1d\x00 $\xf7\xc8\xf2\xbc\xd0\x80k3\x05\x9eQN\xa6]T\xc0\xad\xbcba@P`\xfeF\xb0R:\xe7\x85v\x00+\x00\x02\x03\x04\x14\x03\x03\x00\x01\x01\x17\x03\x03\x00DWTn#\xf4\x9cH\xf1\x1b\x0b9\x04\xb0\xd3[7\xce\xa4\x01\xeeH8\x89;l\x92\xd1\xe3X\xa4\xa3\n`)}Pp\xcbvJ\xef\xbe\xc3|\xb5x-\x0f\xdf\xb5s2\xd0\xba\xb6#\xa6\xf29\xfe(\xc1\xfd\xe4&v\xa0\xd9'
|
|
|
|
|
|
2024-12-14 17:54:45.500372 - Ether / IP / TCP 192.168.1.11:40844 > 35.186.224.26:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 104
|
|
id = 1581
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40844
|
|
dport = https
|
|
seq = 2444973269
|
|
ack = 3502955501
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc5e2
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x14\x03\x03\x00\x01\x01\x17\x03\x03\x005\xe4\x8cl+\xc7%\xe0'W\x8d\xc5\xad\xdd\x97\xee\x9cbF7\x8b\xe0(\x02\x11\xf2\xc8c\xe3\x1c\xb1\xc2\x0e\xd8We\xcc=\xc5\xb0\xa1?\xb5\x807 \xd7KH\xa1'\x18Y_"
|
|
|
|
|
|
2024-12-14 17:54:45.512690 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40844 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 626
|
|
id = 48518
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xbf77
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40844
|
|
seq = 3502955501
|
|
ack = 2444973333
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1050
|
|
chksum = 0x126b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x02\x07\xbfLx9\x1b{\xb3A\xb0\x04\x1a\\Y\xe2I\x12a#\xba\xbbf\xa0~B\xdb\xec\xa1\x06&\xa4\xadd\xb4F\xf7\xed<\xc8M\x0c\xbe\xd6\xc8\x8b\x9f\xd0%\x82\x87\x02Y\xdb\xc6\xfa\xae\x0f\x00\x90w\xe2\xc2\'\xbb\\ \xff\xb0\xd1\x19u\x95\xe2z{\x97\x07\xf2*\xc9\x86\xcc\xc8Aq8\x11)\xba\xcf\xben\xb0\xcaLV#4_Q\xfa\x8er\xe5\xf9\xa24\x17\xb5\x91\xc4\x1f\x1eD\x8e\x9d\xe8(\xef+\xbe\x19\xe03%\x19{\xd7;\xb2\xbf/Ih\t\x92\x9b?\xb8+qL\xfbo`q\xb9x\xad\xd1\r5v\x15$i\x0b|\xc0\xdb\x8a\xdc"q\xc6\xe5I\xc8=\xbb?A%.G\xd5\xc9j\x98\x1e\x84\xff9*U,<\xdcw\x9c\x04qZ\xb3}UW\x0bl+\x1a)~J\xef\xc1\xb1\x99\x92\xcbIq]\x14\xc6\xd07\x1c\xe0|\x9a\x9b\x15\xe53\x8c\xfe\x8c\xc2A\xf95\x00D-\x98\xc35\x07\xed*\x98\x82\xc5=\xc7j\xbd\x02\x03\xfbA\x96\xae\xae\x91\x0c\x8c|\xf9\xeam\xd7^\x04Zx\x11\xb6 Uu\xa6\xac\xad\x08N\x17\x1c(Nf\xfa\x06\xf2\x01\x99"\x11j\xbd\xa1\xf1\xfa*\xc5\x88\xd2\xc1\x1b\xa4\x8a\x1e\x1a\xb1\xfe\xd8\xb0\n\x1fI\x1fW\xfbN\x04\xf9\xa6\xc7\xf28T>(3\x9dY\x1b\xf4h\\O"\xd3@\xaa@-\x18\x8e$\xcc\x9fJ\xcd\xc1\x12"\xb0\xc5\xce\x08"\x86\x95\xecarl1\x90\xe3p\xd4L\xab\xb5\xba\x8b\xd1\x85\x92\xfaD\x0b\xfc\x07y\xb9\x82v\xfe\xea8\t\x7f\x0c^\xd8v%\xbd\x13\xa3\xf2\xff\x92\x06\x7f\xe9\xe9\x8c\x86e\xe61&\x98]\x05\xdd\x05a\xdcY\x01\t\x05\x18\x8b\x83\x9a\xb9\xc2v\xe1\x1f\xc7\xea5\x91c\xd7"mr\xe4\x82\xbbw\xd6\xe6z\xf1|u\xdd\xfc\xf4\x89\xed\xab\xa0\xf6B\x9d\xf4\xcc\xc7H\xdff\xc5\xee\xd9p\nQvW,\xfa\xc9A\x14|\xa9w\xac\xff\x0b\xd5&\xe2,\xd0m\xcc\xef{Q8\xeb\xbc\xfe\xe9I5\x07i\x10IA<\xce\x8e\xc1^\xfa\x00\x93\xbd\x13\xc3\n\xa1V\xc0f\x07\x17\x03\x03\x009\x80\xbc\x10Y\x07#\xf5b\xb3\x96\xcd\x82Z\x95\xe6N\xc6i\xd7x\xc6}\x9e(\x11x\x826{b\x81\xf0\tl\x88\xdb\x93\xf6\x93,T\x8d\t*\xf8\xe7\n\xce3\xf1\x17\xdcW0>\xd4&'
|
|
|
|
|
|
2024-12-14 17:54:45.518476 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 66
|
|
id = 1582
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 46
|
|
chksum = 0xc5c7
|
|
###[ Raw ]###
|
|
load = b'R\xf4k\x98\x9b%:\xa7\xd9\xd1\xfdK\xd8%B\x83\xa2\x9d\xd0p\x1d\x02\xbd\x1d5>\xf3\x92\x9c\x15H\xd4\xe7\n(j\x95L'
|
|
|
|
|
|
2024-12-14 17:54:45.524446 - Ether / IP / TCP 20.42.65.91:https > 192.168.1.11:40843 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 6775
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xdd20
|
|
src = 20.42.65.91
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40843
|
|
seq = 2099799628
|
|
ack = 4124381663
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 16385
|
|
chksum = 0xcc2a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:45.529603 - Ether / IP / TCP 20.42.65.91:https > 192.168.1.11:40843 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 6776
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xdd1f
|
|
src = 20.42.65.91
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40843
|
|
seq = 2099799628
|
|
ack = 4124383449
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 16385
|
|
chksum = 0xc530
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:45.538038 - Ether / IP / TCP 20.42.65.91:https > 192.168.1.11:40843 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 143
|
|
id = 6777
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xdcb7
|
|
src = 20.42.65.91
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40843
|
|
seq = 2099799628
|
|
ack = 4124383449
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 16385
|
|
chksum = 0x5dcf
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00b\xbdd\xf9^\x1b\xe9\x10\x99\x97\xd9z\t\x08\xd1L\n\x80"\xc4\x90\xbc\\sG\xea\x19\r\x1e\x83\xdf\xccq3\xe1n07+\xf9v\xb5$\xcde\x1d2\x8f\xc1Z\xc8\xcd\xf2\xa6v\xdb\x95?\x1b\xa9\x90\xafYh\xec\x91_Z\xe4\xa6x\xb6\x90\xf9M\x04\x1c\xa3\x17\xc8f\x93\x9e\xacA\x07\xc5\xc9\xb3&P\xab\x90uI\xf0\x8d?\xd3'
|
|
|
|
|
|
2024-12-14 17:54:45.544375 - Ether / IP / TCP 20.42.65.91:https > 192.168.1.11:40843 FPA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 504
|
|
id = 6778
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xdb4d
|
|
src = 20.42.65.91
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40843
|
|
seq = 2099799731
|
|
ack = 4124383449
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FPA
|
|
window = 16385
|
|
chksum = 0xc3c8
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\xcb\x99\xf9\xb1,\xf4\xe1*_V\x13\x07\x10aI\xf0\xe53\xbc\x83\xab\x88\xbf\xf0%"\xf8[(\xcf\xa0\x1b\x1f\x0cD\x9f\xc1\xf8\x04\xe7\xba\xbe+H\x0b\xca\x06\xca\xc4\x93\x0f\r\n\xa6\x02\x90n\xdc\xb7\xd9\xf0jb`\xde\xa0\x16\x028a3\x12\xee\x988\xef\xd1Q\x95YIV\xb4\xbdG\xd4\x97\x9f\xd8b\x0b\xb2\x1a\xbd\xd5J\x8c\xb4\xb2\xf3\xd1\xdf_<\x92\xa6$\x99E\xba!C\xb7\x18\x86\xaa\xc8\x89(\xd8l\x9c\x9e]==FO\x87j\x0ci\x0cD\xcf\x89\x0fC\xdc\xb2*q\xa2f\x81_-\x1fU\xc16\xb6\xdeD\xa76\x1f\x84\xacB\xedD\x95\xe7\xe2\xa8\xd3\xa8\x13\xf8\xdbn\x9e\xda\x11h\x0c\x90\xe5\rA\xe6\xf4\x86\xf7r\x98-Ow\r\x83\xf9\xac\x9c\xc5\x1a\x9cf\x088\xe5CK\xe0\xb1\x01P\x88l\x97\x85\xc1\x07\x82\xf8I\xac\x05\xe8\xde\x0cr\xca\xe7\xf2x\xd3\x15\x18\x02\xb2\xd1M\xb3"\xbb\x172\xda\xd8\xf7n\xac@\x98\xc6\x01\x83\xc0-\x8b\xe6\xec\xda\xa4\x06\xfd\x98\xe5\xd0\xb4\t>Q\x11\xd0\xc5\x8f\xdb8\x12\xd3C;\x10\x8f\\\xfb@jW\xaa\x17\x91\xbe\x92.T\xb3\xc8IV\x12\xc1\x1b\xe7\xd2\x15D\xd9\xa0\x86\xc8\x10\n\x01\x00\x82YG|\x1alibP\xe9#\x1d\xba n\xdf\xbd\xe1\xc1\x85\xea:[\xf2\xdb\x8d\x88\xf1\xdeC8\xc0%\xe7h\x11i\x90Q\xee6"\x19\xabhe\xee\xca32dDA\t\xdf%^\x84\xcb\x92\xef\x82\xf5\xe0<\xe6\xb7zI;@(\xf6\x9d\xb4\xe2\xb6\x803\xb5X\xb0ya\x19\xdb\x8b\x96\xee\x95\x9aF\x02(\x89\xfc\xe8\xe9v\xacP\xd3m\xb7+\xefsQ\x04\x10\xe5:\xa0\xf3\xe4\xf0Wg\'5CUa\xbbj\xee\x19`H;m)q\x8ey\xb4#`7\xdezs\xc0\x93\x84\x15\xae\xe3;JJv'
|
|
|
|
|
|
2024-12-14 17:54:45.551200 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3498
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124383449
|
|
ack = 2099800196
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 514
|
|
chksum = 0x1753
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:45.557002 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 64
|
|
id = 3499
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124383449
|
|
ack = 2099800196
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 514
|
|
chksum = 0x176b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x13\xf4ft\x1a\x10a\xb8\xbc\xa2rj\x8b\x0c\x96\x1a\xe9=P\xe7'
|
|
|
|
|
|
2024-12-14 17:54:45.559775 - Ether / IP / TCP 192.168.1.11:40843 > 20.42.65.91:https FA
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3500
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.65.91
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40843
|
|
dport = https
|
|
seq = 4124383473
|
|
ack = 2099800196
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FA
|
|
window = 514
|
|
chksum = 0x1753
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:45.562721 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d31
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 32
|
|
chksum = 0x7514
|
|
###[ Raw ]###
|
|
load = b"S\x8f\xf0\x81\x8c\x12\x8ewad|+\x89\xb6\x9d\x89\xa1\x07\xc4\xbb\xd7\xd0T'"
|
|
|
|
|
|
2024-12-14 17:54:45.566685 - Ether / IP / TCP 192.168.1.11:40844 > 35.186.224.26:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 1583
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40844
|
|
dport = https
|
|
seq = 2444973333
|
|
ack = 3502956087
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xc5a2
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:45.569696 - Ether / IP / TCP 20.42.65.91:https > 192.168.1.11:40843 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 6779
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xdd1c
|
|
src = 20.42.65.91
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40843
|
|
seq = 2099800196
|
|
ack = 4124383474
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 16384
|
|
chksum = 0xc2e0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:45.892589 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 554
|
|
id = 442
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x53d7
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414048991
|
|
ack = 3211592045
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x7c3b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\xfd\x88\x06\t\x074\xe1\xdd\x05\xe3\x8d:| \xd7\xa8\xf6H\xa4\x8d\xe7<\x92k\xfe\x88\xc3t\xd8\xd1\xb3\x11\xc2\xfeH\rH\x9c\x8evYH&\xcd\xeb\xea\xb8|s\xc6\x7f\xacr\xbe\xe8\x10\x9f\xfe\xf6\x03\x8esy=\xb9\xed\xf7\xbf\xd1\x84\xf2p\xdb&O\xec\x0f\x0c[\x13\xd7o\xab\x99\x8a\x15\xa5n\xf5w\\\xe8\x8f`\x84[\xc4\xc1a\xd4j\xec\x05\xde\x82\xca\xb6\x19#\xee\xc9Y\xcc]#\xe1\xc55>\x1f\x97\xa3\xfb\xe6\xa3\xac\xc7QC0\xf32;\xe2s\xc0\x9b\xbf\x0cr\r\xe5!Cb1\x88~l\x19\xeb\xec_\x0e%\x8d\xe7%\x1e\x95\x0f5.\xfb\xb9\xf1\xf0\xb56\x94\x04\xa6[I7\xc4\xc6\xd0\xb2\xcc\xcdD\xcc\x0fml1\xa9\x96i,\xd0V\x05\xdcX\xaao\x12\xae\x99\x1c\xbe\x10\xff\xa9WD\xb5\xd6C\xb9\xcf\xf4]\xabH\xb1j\x16\x9c\xe2\xad0r\xba\xd5T\xfcc\xc3|\xbfS\xa6\x94\x80,\xafD\xc1\x89\xd6\xc6\x90(\xafK\xe9\xf0\xa8\xd5\x00\xa0\xd9\x06\x8eJ%2\x84\x91)\xce\xac/Wk\x18\x10\xa3\xf5K\xb0lQ()$\xd1\xd4\x99\x01\xe8\xdf\xd4y\xeeb\xa3\xb4\xafz\xb3\xfcb[\r\xf1\xbf\xb0\xaa\xdaM\xff\t\xb0X3\xdf\x89I\x9e\x9aCXd.;\xf5\x99a/@\xc8\xaf\x82n`\x02\xe5\xa0\x16\xa3:=\x1a\x87\x1c?`%L\xe6R\x90\x1f\xffR\xd0\xf7\xc1\xf1dZ\xe8p\x1a\xbf\xb5\xa9\xbdu\xa6q\xfb\x8c\xbf\x1e\x0f\xe6y\xc0%\xc0\x87^)w>\x84\x90\x1c\xf23\x88\xdc\\iP\xd9\xd0\xea\xefk\x1b\xbb\xff\xb8kb\x1a\xb8\xaf>\x9d\x91:\x89&\x8f\xa2E\x85V\xae\xaf\x1b\xe7k\x0eJ\x0c\x89\x00V\xf1\xaf}t0NE/\xd2/H\n\x06\n\xf7q\xc2.\x8fl\x04\x93\xe5\xe2n).g\x12\xa4\x1d\x9c\x19\xb25\x8f\n\x00\xd1\xcf^\x9flt\x13,\xfbY\xb1\x1b\xc9\xbf\xc2\xb6\xdd&m\x86\xf2w\xfe;l\xb7\x07$\x1a\x93\xa67\xd7me\xf2\xdd\x12%\x86C\x07\xe5#_\xf3'
|
|
|
|
|
|
2024-12-14 17:54:45.944942 - Ether / IP / TCP 192.168.1.11:39688 > 162.159.136.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3083
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.136.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39688
|
|
dport = https
|
|
seq = 3211592045
|
|
ack = 414049505
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0xed57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:47.081742 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 61826
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158778477
|
|
ack = 3359206964
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4102
|
|
chksum = 0x8fb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\n\xf8w\n\xdfX\xe4\x99\xc9\xe9\xad\x02-{!D\xbd\x80\x8aL\xf8e;\xaa\x94UgR\x14\x84\x8ci\xf2\x9cT\xde\x86Q\t\xb0\x84B\xe8\xc3B\xb8%\xaf\xb9U\xb6e\x93\xcc\xb9\xa3k\xa4H\x93\x8fF\xd2\xdd\x93\xda\xd8H\n\x7f\x0ca\x9e?\xa9\xe4\xea\x9a\x82\xb6\xcbE\xea\x15E_\xed\xd9D\t\n\xf4\x7f\x93\x17\xd0&\xa4\x00\x18\xcdL\xd0\xfb\x0e\xb3\x13\xebo\xdbw\x0e\xa3\x80\x834-^p&\x7fq\xcb5\xdeb\xed\xd3\x93\xe2\xe5\xd4+\xfb-\x85rS\xde\xc1xr\xfd\x13\xca\nV\x82\x8bCQ\xb9\xd2\xb4\xb9\xcb\x08\x80B\xf9\x87\x14t"\x01\x8e\xa8\xb5\xac\xa8\'\xb3a\x93\x02)\xba\xec\x11\xbau\x9a\xaeh\x8e\xb8\xba\xa4m\xc7\xb4\x0f\xb5\xe0\xc8\x8e\xb5\xfa\xcbK\xb5\xdc\xe7P.\x17\xf8\x86pR\x88g/A\xf6\xd5\xd3U>\xc2\xd8\xdb\xb0\xab\xb6_\xfc\xecOqe\xe1\xa4\xd1\x15\xc0\xba\xc2\x88%z\x1e\xd6\xe6\x8e.\x06\xe2\xe9\xbdS\x81;:=\x12\t\xadRmu\x0e\x1d_Ba\xa4\xb1\xa7\x11\xd6a\xae\xe8Ux\xaa\xdd\x10\x0f\xc7\\~\xe2\x90\x15Q\x012\xc7\xaa4Eb\x18\x02,\x18\x8d\x1e\xa8``!u\xdf\x15\x93^\xa1?\xf1.\xec\x08\xc00\x96\x970\x88=\xac\x05\xa1\x93o\x19w`"\x9f*\x86I\x19\x87V1\xc3\x96\xf5\x12\xfe\xbc\x07\xf4\x07\x94"G2[\x93\xc19\xf4\x9fb<^\xdc\x08\xfc s\xf9\x15\xfae\x11\xa1\x90"g\x1b\x0f>\xf6\xa9\x1b\xcf\xca^lu\xd6k\x8f!\x8b.\xc8\xb2\xe5S\x99]\x89a\xd2$\xcb\xd0\xcb\xcc\xb0P\xe9\x028eV\x8c\r\xfd\x1au\xaaYv^\x8c\xd7_\xc1G\xb0=\xd2\xcdVY\x8b\xafDF\r\xa1\x04\xbd\x00=\x91m\xdd\xc7\xb2\xcd]\xaf\x1c\xc1\xa5f\x86\rVJX\x8a\x9c\x9dL\x0b84rf\x0c1\x95\x92\x0e\xec\x88o\xb7\x82\x88\xe5\x8eMMR\x96\x19\x9b\xffB\x97`\x9aU_]E\xfb9U\xc2\xcesH\xd3z\x92\xa5\xa1\xe2\xd3\xc6\xb4\xf4\xbb\xc0\x1e\xc9\xc1\xb4\x85\rn\x9eS\xda2\x05\x92\xa8\x16\x91\x90\xade\x82QY\xb5Q\x9eJ\xe3?\xea%\x87\xfdgb\xbe\xce\xee\xfc\x9e/Plrj\xaf?$\xe8\x1c\xc0\x1bK\xef\xe5\xd5\x16t<\xed\xc5\xbb\xae\xd5\x85\x8f\xe2\x87E\x9f\x1e\xc8\xb0\xd3.7\xae\xb9\xd9G\xa5\x1c\xdd\xedb\xd6\x1d\xe2\x80\'<\x07\x7f\x19\xf7\x1dP|\xd3\\\xea`*\xa2\x1c\\o\xbd\xf8\xb2k\x17\x04"\xf2\xb3\\\xc4K>>G\xe8h\xfe\xc2\x9d(\xd5[\x07f\xd1\x9b`pFG\x98<\x08O\x07\x1bp\xe23m\t\xf1s\xb6\xff\xdck\xa9U\xef\xc1\xea\x12\xea\x1e\x89t?\x14r|@\x8e\xa8;\x17o\xd4\xde@\x08\xc6\xe0\xe8\x16\xdbE\xee\xa3\xd6b\xb8\xb2rt\x1f\xb5ei\xfc\xad\x0f\xb8k\xe7\xe7x\xb9i\x03h1\x9c4q>N\xd4_\x15/\x82\xca\xa9\xca\xda\xbb\xf8|#\xec\xd1\xe3u\x80,h\xdc\x84\xc5b\xe6 4\xea\xdc\x9f.um\x96]\xd6\xe9:h\xb8\x87\x07\xechq\xc8\xf5\x12g\xab\xec\x9f\xe5\xddC\x8b\xb8\xf7\x12\x92A]\xae}t\x87\xa7\x18;\x9eA\xd3 \xbe\x9f\xff@\xb8\x93\xff\x87=\xa1\xce\xa5\xf2\xd81\xbd\xa3\xaa\xca\x1b\xbe\xa8/\xbc\x90#\x8e\xc2\xa4\xcc\xbf@G\xd1\xee-\xfcI\x07\xc9\x1aUs\xf7FcpIY@\xf4\xbd\xb43y\x8fu\xd4\xce\x1b\x12 z:\x96{\xa3.\xbb\xcf\x9e\xad\xc8Qf4q\xf3\x1d\xc2\xa1\xfb\x9dI\xe2\x85\xb9*h\xd39\x1b\xb8tK\xb78\x02\x92\xefm\x00\x04m\xe9k\xd6\xa1\xcd\x1b\x87l\xb0\xdc\xe4\xef\xde\xa1\x02)\xecS\xa6k\x18R\xe2k\x1e\xdc\x0b\xe8?%\x10\xfdv\xf5\x17\xc9C\x18\xe8S_\xceb\xc8\xab\xea\x94\x00\x92\xf6\xf3\xea\xcb\xc1\xc4\xfe\xc3\xcd\xf3\x06i\xdf\xf0v\xa0\xef.\xda\x8d\xaf;\xfe\xf3k\x0c\xd6`\x87\x88\xec\xfd\x88k\x86\xa5Dx\xdb\xbb\xed+n\xc5\x87r\x0e\xfd\x84\xe6\x88\x12\xf0\x8cj\xb9\xb1\x9c\x06N\x14\x987\x8flf"\xe6\xac\x9e\xd9\x98%\x89\xae\xf4\xb9K\x91z\xb2y\xf8s\x13\xa6\xaf(\xeb"`R\xabQ%\xd2*4\xe2\xed\x11\xa0\xe3\xbc=\xec#$M\xfeK%\xb4\x02Y\xc9$x\x1e\x91\x87\xd5\x17\xee&C\x17\xa2~\xd4\x93\x1e\x9eG\xb9\x90\x14\xdf\x1a\x19\xf5\x8d;wz\x05\xfb\x88\xcaF\xea\xc2f\x1a\xe4\xc2\xca\x19G\xe0\x02\xac2\x95\xaeb\xee\x86\x0eW0\xb6\xe2(\rm\xf6\xf8y\xca\x81\x19\xae\xbdJ!;\x10\xce\xa4\xd2\xccH0g\xb7i#\'\xa1\xc6$#\xab\tUe\xa8\xdc~d\x03\x83\x08\xe7\x80\xcb\x02\x8fn\xd0\xb5Z\x1ec\xfcE)FG\xc7\x04\xf8\x90GT\x16fA\x13|\x94\x91\xe4|e\xfb\x8d;(<\x992u\x89uxe\xf4D\xe4\x1bX\xae^<\xd2\xf4\xd7GK\xd3x\xa6\x12\xd9\x08\xb6;\xa6_`v\xd8a\xa3_\xae\x88\x0b\'\x12\x1d\xd6\x8d\x913\xac\xad\x8e\x0f\x94\xcd\x80t\'\x84A\xcd\xbe\xa4X\xa1D]\x16Y\x9a\x05\x17\xf9\xa8\x0e\xca\xab\x81\x13\x94\xcf\x96/.G\xa1~-\xf5\xb6\x88\xa0\xbb\xef7\xcb>\xde\xe3\xf9\x01\x0b.\x81\xe2\xc1\x1eg-\x1cP]B\xbf\xe0\xa3Z\xc8;\xe0\xfb\x04\xe9\\pI\xd8\xd6\xe0B%|\xc2\xeb\x9998\xc0k@\xda\xe8\xd96\x18\xa8\xdd\x90\x8bH \xfe\xaf\x81\xa2\xd89\xd7\xef"\x9aA\x8c\x1b\xea\xa8\x99\x9a\xd6vd\xf8\xb1xZ@\x06\xc1;\x97+\xa1o\xc7\x9a\xa6\xd1\x06\xfd2x\xd6<\x18\xa6tz{\xe5=\x82}\t\x06\xec'
|
|
|
|
|
|
2024-12-14 17:54:47.098281 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1441
|
|
id = 61827
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158779889
|
|
ack = 3359206964
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4102
|
|
chksum = 0x8f0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xad\xe5\x08\xdc\xae\xb5y\x9a\x8eg\x01r\xf0\x86w\xe6F8\xe3)\xb03\xc6^h\x1b\xafw\xc3\xbd\x92\r=\xe3\xd3\xbd\xc9\xa4\xde\xb4\xd7e\x1e\xc6\x85\x8b\xfd\xc5*b\xfeRA=\x8a\xe2zt\xf4\xd8\xa2\xe8\x90B#\x02"\xcc3:\xf3\xb4\xf0)y\xff\xf40\x85P\xab.\x8e\xc2*uB\x85\xf6\xc2kx\x04N\xbc=\x8fL\'\x00?\xac\xdeXj\xaf\xa05\xa4\xa3N\xd6:\x83\xda\xad\x08\x97c\xe4i\xe6eAx\x9d\xb5^:$\xd7\x8a8\xc6\xfd\x90\xbd\xa7\xd9\x11\x8da\xf6Va\x15\xf6r\xba\x01\xa1cQ:\xb6\xe7\xe2z\x12J\xf8\xd5\xf4\xfa\x04\xdc\xa4\xc9\x08\x9b\x98\x83\x9e\xc3[\xed\x8e\xc8\xa3\x99\x99\xa4\'\xfd#\x84\x12\x1c \x04\xd13\xbc:\xcc{\x16.\x8d_\xe6h\x07&\x87h\x00c\r\xc7L\xa7q\xfeD\xda|\x19\xba\x1f,\xf9\x15\xfb\xee\xd9\x00\xff(\xde\x0e\x803\xb3\x05\xddQ[\x1f\n\xfeR\x84\x1e\x9f\t\xf8Nv\xe0_\xfdR\xe2I\x06 \x0b\x15\x90\xe5\xb0*\x86#n\x9c1v\x97\xb8\xd4\xa3\x9aN\xdf\x96\r\xb3Cq\xe5k\xd2\xef\xbcR\xe1](98\xb3x\xee(v\x01\x00\xf7\xf7\xe4O,b>6N\xfe,\xde<\x8bcs\xbf\x1boM\xf8k4\xb3\xc0i-\xe4t1\xee\xf9\xda\x9cK=\xbe\x01\x8b\x92\xbb\xa8^\xe5rk\xc4\xfc\x97\xc5\x8a\x1a,\xdaG\x06\xf5\x84\x7f\xe0\x15s_\xddz{\x8cY\xa3&^>\x13\xd9\xbf\xcc\xc6;\x86H8\xce`\xc5\x0f\xa9\x15\xe38\xd8I*\xf3\xfa\xb1\xb3\x07T\xb2\xd6\x08\xbc\x07_\xb2\x05\x15T\x99C]\x8c\xeb\x97;\xe7\'\xc3\x0bj\x06\xd5\x1a\xad\xf1\xb4\t\xdd\x1e\x8f\xb3\x0b\xe8#~\x9c\xac\x89`\x0e\x10&X\xe2+T<\xcd8a\x1a\x87j\x8f\xaf\xea\x93\x94{\x16n\x86\x89\x9b\x17\x15\xf1\xd9\xf3UN<\xf1?"#\x85q/\x97&\xfc\x9c\x98L\xfdY^\xca\xc55\xcf~\xcb\x0b1\xbb}6S\xd2\xaa\xc1\xb6z\xf7k\x1eXK\xc4\xb2y\x95\xa6\xd5\xfd{\xfeD\xf4\xe3\xc8\xf3\x9bDUUI\xe6\x82G\xf9\x0f]\xb8\xc0\xee\xeb)\xb5\x8f+\x07\xacg^N\xfe\xd2\x8e\xc2\x84J\xe8f(\tG\x0c\xeey\x9d\xb1\x92E\x8f\xec:\xb1E\xbd\xb3\xd5\xc3\x81MT\x06\xb8\xef\x87\x0f\xb40VaV\xc0\xbe\x9f\x8b\xefZ\x12\xf9\xfa\x18<ZOR(\x8a\xd8\x05\xe7\xb5x\xbd\xb8\x8f\x83u\xe4\x07\xd0\x89\x88>\xc3\xdd\xff\tdQ\xe07\x10C1\xd5X\xc3\xe5~\xfc\xe2\xa3OL\x0b\xc0-6\xbcD\xe5\x0f\xda\xe0\xdb1\xfd \xaf\t\xf5W\x87R\x85\xdb\x1b\xbc\xf2\xbc\x04\xb2\x02\xf2\xad\xd57\x92P\x15\xedd@\x80\x87 \xfcHL\xcc\xf3\x83_\xfd\xf8,\xdal\xd6\xa0\x1a\x96R\\\xbc\x01\x88\x87\x8d~)\xbc\xf3\x16\xca\xb0\x0b\x04\xbe\xaf\xd9\xe4\xe1\x07N\xac\xbd\x8f\xdb\xb1\xfc\x05\x95\x12\x93\xbd\x97\x06N\x9by\x83:\xdf\xa7\x06)M\xc29\x8d\x18\x87\x93\xdbJ\x07i\x94\x11^S\xce\xfd7@X\xd3\xd2\xa4\n\xf7@\xf8\x8d\x94/d\xf5\xa9\xfa\x03D\xf8\xa3N\xe5\xe7.,\x87C#fH(7\xe7\x19\x81\xc7\x8a\x05I\xed\xe3Q\xffL\xbf\xdb\xd4\xef\x89\x1f\xb3\x8bJ\xfe\x85\xbbyw\xef\x8a\xf3A\x00\xff\x8dw\x1c\xa7\xe8\x87)y\xbc\xa8\x92FaP]\x02\xe6\x0c\xa0\xd6\xd3\xd4n,d\x84\x95\x842\xd4C-\xe8\x7f\x08\xab\x11\xb4^\xfa\xce(\xb8\x93)d/\x08p~\xc3d\xeb\xae\xde\xdb\xae\xd3w\x9a\xa2\xc0P\xa1H\xa6\x18\x17r\x84\x1aI2E\x8bo\xa2]6\xbc%\xb1\x88\xdc\xf6\xb9s\xf4\xf9\x81\x89\xd8\xc9\xfc\xf8\x13\xa7\xfe\x02\xb5\x04\xe9\x81\x05H\xf7\x85sA\xa8\xf17\x9b\xd8\r\x18\x01\x99\xd7;(\x82e\r\x84\x94 \x00r\x16yS<\xf3:!3\xb0\x13z\xa6j+\xe3uJ\x82=\xaf\xf6\xa2\xb3\xb1\xbaR\x16k\x14/y\xf1]\xde\x92+s\xb8\xb1\xd8t\xba\xe4\xe9\x92E\x94\x07\x13\x9b\x14\xb3m\xeel\xd7\x82\xc0O\x84i\xd8Ui\x1b\xe1\x9fS\x11\xb4%\x0c\x84\xdfn\xc8\xed\xa0K\x14U~\xa4\x8d\x06<\xc4\xfb\x9c\xcf\xda\xbb;\xe3\xe4\x8d\xe6\xd4\xb5\x03\x97d\xfd?_@\x190*k)\xba\xec}\xa4h\xfc\x00?\xd6\xc8\x06\xf2\xed\xe3V\xe4\x94"\xb6\x134\x838\xben\xbc\x86)4\xe7=w(\x99\x9c/\x0b\xbfp\xa2\xc2t\xed\xda\xbeLA\x1c\\K\xa24*y\xae\x1ee\xf0\x8f\x18`@\xe8\xb0\x9d\xb9\x8c\xa9\xee\xcd\x15B\x8e!\xda\xcd\x0bn\xed\x17\xc8n\xe66\x07Ov\xda\xa0\x11\'\x88\x10\x9c>]\x8f\xee\xaf\xe3\x80\x96\xd1H\xbf\x00\xd4hx\xc6V\xf9NmA\xfb\x9f\x0f\x11\x8a\\\xce\xa1\xce7\xcd\xb7j3\xd0\x0b\xf7\xde+\x07)/]\xcf\xbd\x0c\xe7\xdd\xe5\xa4\xd3oc\x1a\xf4q=\xa5\xcb9_\x99\xd3\xd4eA\x98\xe2\xc1L\x8a]\xb1x\xf0\x8a\x06oF\x84\xc9\xc1\xe6NA\x0eW\xb5\xc9\xe3\xc4\xa0\xc2\xa6\x15C]\xbeUS\xe5\xd4^\xbe\x8f\xca\x86\'U D^\xfco\xddN\xd6\x91\x03\x0b\xe0\xfa\xc3I\xf8\xda\xbf)\xe0\x81r\x8d\x12\x918\x9c]b\xd4\xe8QQg\xc9Q0p\xb5_\xa8P\xc0|\xcc\x877\x86\r\xac\xeb\xe7}\x1f\x0e\xd3a\x83u\x8ev\xcd\x9e\x98\xb5z\xfb!\xac\xde\x0e\x1f\x1aK\x0b\xec|\xc4\x9d\xdd:\xd58F\r\x06S,\x94\xfc\x9e=\x86\xd5\xc0Q\x81,\xf5\x1b\xdd\xf0.\x967G\x81\xa7\x96\xd0\x0c\xd6\xc91\x05\x9d\xb4]\xd9\xd4 \xe2_o:\xc9\tj\x92\x0f\xfe'
|
|
|
|
|
|
2024-12-14 17:54:47.104896 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 103
|
|
id = 61828
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158781290
|
|
ack = 3359206964
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4102
|
|
chksum = 0x3b6
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00:\xc7x\x90\xb6\x8d7\xe1\xddhi\xf2\x8bH\xd2\\|m\xd7\xe3\xc5%\xc4kT\'\t\xd6\xf2"\n\x83"\x05\xecy\xa4>\'\xb3\x88f3\xd5X\xfd\xde\x11~\x0c\xb2\x11\xd0\xcc\xca\xc7\xb5\x93\xef'
|
|
|
|
|
|
2024-12-14 17:54:47.116828 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43642
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95f9
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359206964
|
|
ack = 158779889
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2958
|
|
chksum = 0xf6e6
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:47.124262 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43643
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95f8
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359206964
|
|
ack = 158781290
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2969
|
|
chksum = 0xf162
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:47.133122 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43644
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95f7
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359206964
|
|
ack = 158781353
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2969
|
|
chksum = 0xf123
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:47.326117 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1031
|
|
id = 43645
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x9217
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359206964
|
|
ack = 158781353
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 2969
|
|
chksum = 0xf132
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x03\xda8\xbd\xda\xb6\xae\x16\xb3\x14j\xa1\xc3\x7fV\xcdCpuF\x8d\xff\x80\x9f\xbe\x15\xcc@\x89\x91%\xa3 \xc7\x13\x1d\x04\xd8\x1ej\xa5\xaf\xb2\x93\x1e\x1cMs\xe0\x81\xa5\x00[\x81\xab\xc5mS\x03I\x89\x81\xaa\xce\x988)\x97U\x0e\x1e\x1b\xdc \xff\xf5y\x84I\xc9#\xc5U,!b\xda\xca[\xbf\xc2\xc48\x92z\x88\x06Vl\x9f\xc4\xaay0j\x008\xebi\x15\xa0\x1d\x9c\xea\x18\xfb\x05\xa7\xc4\x12F\x92\\\xd5.?\xedw\xc7\x82\xa08\x18\xcdMy\x8e\xe9\xf5\xa1\xee\xb5\xa71t]\r\xdc\xcd\xe4J\x8cw\x1f\xa4\x88D.\xa5\xce\xc5H\xacF^\x83;j\x17\x7f\xe2\x8c\xdbFZ=YX\xd8\xb3\xe7\xfdJ&\xd5\xc2G4\x9fG\x9d\x07\xe3\xd8\x9e\x90m\xa4\x95\xa8\xff\x9eG\xb9l\x98\xc1\xcb\xc4\xbf\xac\xea\xc6j`\xf1\x17\xac\xda\xc6\xe6\x92\x96\xa7\x96\xec\x8e0\xc3\x9d\x91\xc3\xf3\xb3\\v\xccE\x8c\x90\xf4\xa7\xe2\xcd\x07,\x8a\xd1*\x8c\x89\xa1\x02\xd5pl\x80\x0c\xa3t\xae\xb82\x87\x14\t\r#\x8d\'\xd4\x19\xb4`\x01\x12\xca5m\xf2ZQk\xb7Hh\t\xaa\xccE\xa4a\x9940\x1f\xf9\x1d\xc1i\x83\x8b*\xf3\x06yi\xb7\xe9\x07s8(\xce\x06vP\xbf\xd5\xc0\xb7Wo\x85$W\x8a\t\x8cG\xd5\x830\x8b\xa1T\xbc!Zx-\xf6\x9d\xd2\x15q\x01\xfc\x92vx(\xf4*\xcc\xd7(2\xca\xc8+,\x87\x96J\x0e\xd5\xaaE;\x18\x17\xc3P\xc6\x9a\x822\x83\x93R\xfe\xa8@\xad\xe4}{\xd5f\r\x00D\x96\xa7G\xf8\xef\xee\x8d\x15\xb3\x90\x94\x89\x07G_\'\xde\x10\r\x18d\xf1\r\xf4P!\xf6\xd3\x95\xe5\xf3[\x96\xed\'\x80x\xb8?\xf1|v,f\t\xa5\xe3:\xbb\x96\xe8c\xec\x10[\xbd\xcd=Rd\xa3\x15\xc3\xdf\xd4H\xbd\xbd\xee7\x18\xbcI\xbc\xe1!_w\x86:\xa6\x03w9\x94\xad\xd5\xd5\xac\xbf\xd6Rq\x86\x806\xcb(\x96\xc99\xf8\xf8\x13T\xd8\xffs]X\xf4\xcf\xaa?\xbe\xd7\x8a\xe6\xc8$O\x89;\xf5\xe76Dy;P\x90\xd2\xcboc\x85\x8a\xb0U\x8fO6\x99E\xac\x1e\xa6\x18c\xbe\r\x9a)\xcf\x0c\xa7\xeaZ\xe0j\xd0\x84\xf2\x97\xc1OZ\x07\r\t\xf1\xdf\xec\xa1#^g\x160tCS\xc7\x17\xdal\x97\xaf\xf6\x9a\x9b!m.\xeb\xc3\xea\xc8ISN\x95g\xe5\x1d"\xd4\x120zub\x88\x9eUQ\xa1\xe1\xa54\x89\xc1\x16\xa0Kl~g6\x9c\xf8\x1c\xdbgo%\x08\x7f@\xc6\xcf\xbe\xe6\x8fX\xc5\x04|\x07Mm\xa3\x83\xef\x11\xbcY\x996\xf5 \x83\xc6\xad\'\xf9D\xa6\xa0A\x81\x8cB\x12\xca\x17\xd4\x88&\xe7\xea[\x10o\xa0\x8a\xa96\xdd\xcd\xa50\x11\xbbN)~9\xc6\x833\xfb\xb6\x8b\xb4V\x01<\xea\xfb\xce\x14Y\x85\x88\xbf\'\xdeH\x18\xa6\xed,|\xda!\x0f9\xee\xe1\x11\xa7\xd0D\x86K\xf4\xe6\xec\xeb\x98\xb9\x83\x93\xbd\xad\x9e\x11\x16\x93uh\xe9o$\xa7\xf2\\\x9d\xd3u \x1c\x1cR\xfb1\xd7\xe2\x1a\xc1^\xadd\n\xa9\x0f\xd0*op`\x96\x8e\x98\xd5\xc4\x01\xd8\xbb\x90\x0c{\xac\x12\xab\x80\x0b\xbaw`lKC\xcbpk\x9bn\xf6\xce\xdb"\xafi\xc9!\xf6Z\x03\x0b`\xfbJ/t\xe7^\x12\x99\x1e\x9d\xd2\x13\x00\xd8K\x15\xce\xf77_W\x183\xbf\xcb\n\xa7U\xdd\xa4h\x86\xc4\xfbdN9\x9eo\xbb\xdc\xa3\xc5\x9d\x0b\xd5\xaf\xfa\xf5\x8dC$\x8d\x06\x07`\xc6p\xed`T\xba\r\xfc\xf9bQzE/4\xfauL\x8e\xf2\x0f\xbf\xe6pxx\x0cA\nf$\x10)\xf4V$\xe3d\xefK\x96\xf8\xaa<G~\xccq\':\xe7|\x04\xb0R\xa3F;\xefw\x9b\x1cf1\xa0V\xf0\xd8\x95<\x94@\x86Ry\xd18\x93@5yc/\x96:\x9b\xaa*p\x98\nY\xce\x8b\xe1+3f.\xfa\xd5\x04}J\xd65\x87D\x00\xc3\xc0y\xd2b\xf2\x00\xb9'
|
|
|
|
|
|
2024-12-14 17:54:47.331786 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 215
|
|
id = 43646
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x9546
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359207955
|
|
ack = 158781353
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 2969
|
|
chksum = 0xd59a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xaa`\xd9mC\xc3\x92\xe4\xa3\x01Q2\xb5\xaa`l\x8a\xfa{\x8a*\xcc\xa02\x9ct\xf1-Qr\xe93\xbe\xc50\x96\x03\x94Z}AB\x99[_Rb\x955Y\xeb\xfe\xbb\x01\t\xd7\x0fQ\xf1\xe8\xbb\xc5\xf2\xa0\xcc\x9e\xab\xa0C\x89E\xb3\xe0\x10\x0e\x0b\x95\xd8 I\x80\x18\xacO\x1eY\x0b\x80\xbf%s\xb5\xc5\xb2{F\x98:\xec\x96\xd2\xee\xfa\xa2\xcd\xf8\x06k\x9bC\x94R\x16\xad\xf9@=\xda\xa1\xc7;\xd1\xb7Ln\x92\xb72\t\x12Y\x9a^\x0e\xbc\xce\x9f\xb5( \x14\x16p\xcdP\xdd\r-\xbb\x82z@"\xf9;\xa2\x96n\xe2\xa8\xa3\xe0\xd9h\xb1V%\xe0P\xb9\xd5'
|
|
|
|
|
|
2024-12-14 17:54:47.336057 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 61829
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158781353
|
|
ack = 3359208130
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4098
|
|
chksum = 0x377
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:47.339867 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 61830
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158781353
|
|
ack = 3359208130
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4098
|
|
chksum = 0x39a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xb8\x19{4~\xed"%,\x1e\xa7\xe2\\\x94V*[\x9f.\x80\xeaS\xb8\xc4\xbf\xca\xb6\x84\xff\x17'
|
|
|
|
|
|
2024-12-14 17:54:47.344450 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 61831
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158781388
|
|
ack = 3359208130
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4098
|
|
chksum = 0x39e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"Q\xde5[\xb3\x8cB\xab5RZ\t\x1d/\xa0L\x11.U\xfe\xba\x95&\x97\xd3xl\xed\x1d\x93\x0c\xc9\xb2\xdd'
|
|
|
|
|
|
2024-12-14 17:54:47.348388 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43647
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95f4
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208130
|
|
ack = 158781388
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2969
|
|
chksum = 0xec72
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:47.352782 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43648
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95f3
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208130
|
|
ack = 158781427
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2969
|
|
chksum = 0xec4b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:47.416581 - Ether / 192.168.1.11 > 224.0.0.252 2 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fc
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 6
|
|
tos = 0x0
|
|
len = 32
|
|
id = 30391
|
|
flags =
|
|
frag = 0
|
|
ttl = 1
|
|
proto = 2
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 224.0.0.252
|
|
\options \
|
|
|###[ IP Option Router Alert ]###
|
|
| copy_flag = 1
|
|
| optclass = control
|
|
| option = router_alert
|
|
| length = 4
|
|
| alert = router_shall_examine_packet
|
|
###[ Raw ]###
|
|
load = b'\x16\x00\t\x03\xe0\x00\x00\xfc'
|
|
|
|
|
|
2024-12-14 17:54:47.428628 - Ether / IP / TCP 192.168.1.11:40768 > 104.199.65.9:4070 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x98
|
|
len = 760
|
|
id = 2582
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 104.199.65.9
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40768
|
|
dport = 4070
|
|
seq = 998631578
|
|
ack = 3458560332
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0x1a8a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xdf\xc1\xf3\xbf\xef\x88dw\x90\xcf\xfe\xe0u\x0e\xde\x91\xaf\xa8a"\xc34\x8d\xce\x98\xa8F\xda`?\x1f\xeb[3\xf3\xcf[\x87\xb5E@$\x82\xffFt\xda\x1d\x1dL\xbf/"\xff\xff\x00`6!g-\x1f\xf0\xe3\x06\xd8&9E\x9d\xdanF\x0b\xc3\xf1\xe2\x13\xebC\xe7\xeeShu3\xc1\xea\x95v\r\xf0\x00^\x19R\xe9\xf7S=m\xc7 \xe42\xc08\xad(\xd9\xc4ig\xed\xbd\xd4\x80\xd9\xd5\x06\x03,\xfcj\xa10v%\xfe\x87\xd4n\xabm(\xb5\xb6\xe2E|\xeb\xbaT\xe4: w\xde\xb6z\x02\x1d?\x07\x0f\xbd\xf8\xfb\xf8\xaf\xd9yo\x99S\x8fV hK\x1d\x01\xcf\x85\x904\x1c\x9c-\xf9"\xf4\r,\x8d \xf3\xf6\x0f\xbc-\xaa=\xa5\x86m\x95\xc6]\tH\xa6u\xf8\xec\xd4S\xe8%\x97\xd3\xfdA\xcd\x95s\xbby\xe0s\xdf\xc4\x90\x94\x10N\x11\xa8zuT\x95\x8a\xebz6\x1b\x19\xe3\x86T\xeb\x02XD\x02\x9c\x08\x86V\x98r%\x99H\xe4\x0f\x9b\x932\x84P\xc6\xd5Zk\xac\xcb\x81\x07;|\xfa\xa2r\xf9\xb0E;\xae\x15t\xd0f\xe0B\xf0\xaa%\xa9\xb3&U\xff\x04\x8d\x81\x93%T*\x91\x13R>3\xb7\xf0\x173\xb4\x19\xf9\xb2%<&`$Z\xa9\xff\x89\x97\xa4\xc4.\xfa\x01\xfd\xf9\xcf\x87\x8d\xe9\x11E\xbd\xc7\xe5\xa0\xf5\xe5\x1e!\xf4\x16\xbc+DbM:\xba\xca\xacg\xda\xb1\x9e\xdd\xfaD\xba\xb8\x94\x7fmp\xcc\x03<\x0c"\x1f\x8a\xc9*\x81\x1cI\xf0\x1aHQ\xb1\x1a\xcb7[\xd7c\x1c\x10\xb5\xf7\xe2o\xda\x18\x0c\xbf\xe1\xc1\x91\xb5\xb9>\'\x9b\xb67Z-\xc9\x15\xeb\xbc\x07\xdc;\xa7\x1b%\xd83\x8f\x8c\x1f\xd2\xf7\x9fG\xea\x88q\xe5\xd8\x9d\xa3\xb3\t\xce.\x8e\xdb\xa2\xbc\xa3\xb38k\xd9\x7f\x1d\xc3\x9f\xf0\x10\xe8\x9c/\xe9\x0eC\x94\xa8\x06\xad\xba\x8d\xb8n\xc6\xa7\xd4\xdbz\x94i\x08\xc1\x90j\x135\x9d\xc7\xa4PX\xa6\xb0$\xb4\xc5[~d:m\r\x95h\x98\tS\xcd\x07\xb92XD\xaf[\x95\xa8\xa2\x10\xdc\x8d\x01\xf0\xd4\x87=\xd5\xc9\xaf\x89{1\xa9\xe9,:\xb4;1\x93D-\xbb\xd2\x87\x05\x0f\x89\xe8\x8b\xc0\x0eS\x0c\x01C9\xe2\x14\xb8\x93\x86\xa7\xd2\x90\xaf\x8e\xe1\xef`\xee-g\xf3A)\xfc\xb7\xf8@@\xadsJ\x1dj\xd4jl\xfe5\x01\xe8\x93\x848z\xb0\x92\xeb\xdb\xcb\x1b\x0b~x\xc9\x8b\xba\xf6aG\x05\x9d\xa00\x085b\xd8\x05\xf5\xa3\x038R\x8d\xf8\\\r\x8d\xf1O\xee\x18\x16R`\x94\xe9\xf8\x91A\xfd\xb8\x8fKZm$96\xa9\x9e\x9a\xf0\xef+\x9f\xe5\xaa\x84t\xe9_\x94\xeb\xe3\xe3\xd0\xf4 \xa41\xc6\xc8r\x92\x8cCl\xb1\xd9f3\xb86\x07Pw7\xb1`C@\xbfq\x1b\xbd\xc3X\xe4k\x1eX}\x08:y_?\xd9s\x9e\x8c=\x1e\x19^4'
|
|
|
|
|
|
2024-12-14 17:54:47.464190 - Ether / IP / TCP 104.199.65.9:4070 > 192.168.1.11:40768 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 95
|
|
id = 14942
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x9eb7
|
|
src = 104.199.65.9
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 4070
|
|
dport = 40768
|
|
seq = 3458560332
|
|
ack = 998632298
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 6
|
|
chksum = 0x6aa5
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b',\x13\x15-\xf8\r\x8f\xcc\xc3\xba=\xc2\x19\x0ea\x92\xfa\x05\xc2F\x92\xcbO\x0e\x04\xc6Z%\xf2B\x02t\xa3|\xf2\xaeZ\xf7v2\x13\xd2\xa3\xb5%\x83;k(\xef\x82\xee\xb92\xa8'
|
|
|
|
|
|
2024-12-14 17:54:47.508218 - Ether / IP / TCP 192.168.1.11:40768 > 104.199.65.9:4070 A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x98
|
|
len = 40
|
|
id = 2583
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 104.199.65.9
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40768
|
|
dport = 4070
|
|
seq = 998632298
|
|
ack = 3458560387
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x2c91
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:47.552985 - Ether / IP / UDP 192.168.1.11:57621 > 192.168.1.255:57621 / Raw
|
|
###[ Ethernet ]###
|
|
dst = ff:ff:ff:ff:ff:ff
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 48709
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.255
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 57621
|
|
dport = 57621
|
|
len = 52
|
|
chksum = 0x9f
|
|
###[ Raw ]###
|
|
load = b'SpotUdp0\x977M\xb3\xe9=C\xf2\x00\x01\x00\x04H\x95\xc2\x03\xb3}cPK\xb7\xed\x7fT~\x1d\x0f\xd7\x01\x15-#vA\xf6'
|
|
|
|
|
|
2024-12-14 17:54:47.555161 - Ether / IP / UDP / DNS Qry b'i.scdn.co.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 55
|
|
id = 31669
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64354
|
|
dport = domain
|
|
len = 35
|
|
chksum = 0x8391
|
|
###[ DNS ]###
|
|
id = 19876
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'i.scdn.co.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.556930 - Ether / IP / UDP / DNS Qry b'i.scdn.co.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 55
|
|
id = 31670
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 57277
|
|
dport = domain
|
|
len = 35
|
|
chksum = 0x8391
|
|
###[ DNS ]###
|
|
id = 55003
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'i.scdn.co.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.559501 - Ether / IP / UDP 192.168.1.11:57621 > 192.168.1.255:57621 / Raw
|
|
###[ Ethernet ]###
|
|
dst = ff:ff:ff:ff:ff:ff
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 48710
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.255
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 57621
|
|
dport = 57621
|
|
len = 52
|
|
chksum = 0x9f
|
|
###[ Raw ]###
|
|
load = b'SpotUdp0\x977M\xb3\xe9=C\xf2\x00\x01\x00\x04H\x95\xc2\x03\xb3}cPK\xb7\xed\x7fT~\x1d\x0f\xd7\x01\x15-#vA\xf6'
|
|
|
|
|
|
2024-12-14 17:54:47.568559 - Ether / IP / UDP / DNS Qry b'spclient.wg.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 69
|
|
id = 31671
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 54254
|
|
dport = domain
|
|
len = 49
|
|
chksum = 0x839f
|
|
###[ DNS ]###
|
|
id = 28586
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.571195 - Ether / IP / UDP / DNS Qry b'spclient.wg.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 69
|
|
id = 31672
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60325
|
|
dport = domain
|
|
len = 49
|
|
chksum = 0x839f
|
|
###[ DNS ]###
|
|
id = 1181
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.574538 - Ether / IP / UDP / DNS Ans b'image-scdn.cdn-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 312
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb658
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 64354
|
|
len = 292
|
|
chksum = 0x7c6c
|
|
###[ DNS ]###
|
|
id = 19876
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 7
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'i.scdn.co.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'i.scdn.co.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 173
|
|
| rdlen = None
|
|
| rdata = b'image-scdn.cdn-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'image-scdn.cdn-gslb.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 38
|
|
| rdlen = None
|
|
| rdata = b'common-eipb-ak.spotifycdn.com.edgesuite.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'common-eipb-ak.spotifycdn.com.edgesuite.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 10336
|
|
| rdlen = None
|
|
| rdata = b'squadcdn.scdn.co.splitter-eip.akadns.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'squadcdn.scdn.co.splitter-eip.akadns.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 29
|
|
| rdlen = None
|
|
| rdata = b'i.scdn.co-noeip.akamaized.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'i.scdn.co-noeip.akamaized.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 182
|
|
| rdlen = None
|
|
| rdata = b'a1520.dscc.akamai.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'a1520.dscc.akamai.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 15
|
|
| rdlen = None
|
|
| rdata = 2.18.188.131
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'a1520.dscc.akamai.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 15
|
|
| rdlen = None
|
|
| rdata = 2.18.188.146
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.579110 - Ether / IP / UDP / DNS Ans b'image-scdn.cdn-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 341
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb63b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 57277
|
|
len = 321
|
|
chksum = 0xca8c
|
|
###[ DNS ]###
|
|
id = 55003
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 5
|
|
nscount = 1
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'i.scdn.co.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'i.scdn.co.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 64
|
|
| rdlen = None
|
|
| rdata = b'image-scdn.cdn-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'image-scdn.cdn-gslb.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 60
|
|
| rdlen = None
|
|
| rdata = b'common-eipb-ak.spotifycdn.com.edgesuite.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'common-eipb-ak.spotifycdn.com.edgesuite.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9333
|
|
| rdlen = None
|
|
| rdata = b'squadcdn.scdn.co.splitter-eip.akadns.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'squadcdn.scdn.co.splitter-eip.akadns.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 29
|
|
| rdlen = None
|
|
| rdata = b'i.scdn.co-noeip.akamaized.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'i.scdn.co-noeip.akamaized.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 141
|
|
| rdlen = None
|
|
| rdata = b'a1520.dscc.akamai.net.'
|
|
\ns \
|
|
|###[ DNS SOA Resource Record ]###
|
|
| rrname = b'dscc.akamai.net.'
|
|
| type = SOA
|
|
| rclass = IN
|
|
| ttl = 504
|
|
| rdlen = None
|
|
| mname = b'n0dscc.akamai.net.'
|
|
| rname = b'hostmaster.akamai.com.'
|
|
| serial = 1734194891
|
|
| refresh = 1000
|
|
| retry = 1000
|
|
| expire = 1000
|
|
| minimum = 1800
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.581060 - Ether / IP / UDP / DNS Qry b'api-partner.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 69
|
|
id = 31673
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63964
|
|
dport = domain
|
|
len = 49
|
|
chksum = 0x839f
|
|
###[ DNS ]###
|
|
id = 50622
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'api-partner.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.582538 - Ether / IP / UDP / DNS Qry b'api-partner.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 69
|
|
id = 31674
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53344
|
|
dport = domain
|
|
len = 49
|
|
chksum = 0x839f
|
|
###[ DNS ]###
|
|
id = 284
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'api-partner.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.583914 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https S
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 25543
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299531834
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 64240
|
|
chksum = 0x806f
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 17:54:47.589014 - Ether / IP / UDP / DNS Ans b'edge-web.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 118
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb71a
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 54254
|
|
len = 98
|
|
chksum = 0x364f
|
|
###[ DNS ]###
|
|
id = 28586
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 2
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'spclient.wg.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 184
|
|
| rdlen = None
|
|
| rdata = b'edge-web.dual-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'edge-web.dual-gslb.spotify.com.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 34
|
|
| rdlen = None
|
|
| rdata = 35.186.224.24
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.591189 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xc77b
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808769381
|
|
ack = 1299531835
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 64240
|
|
chksum = 0xa4af
|
|
urgptr = 0
|
|
options = [('MSS', 1384), ('NOP', None), ('NOP', None), ('SAckOK', b''), ('NOP', None), ('WScale', 7)]
|
|
|
|
|
|
2024-12-14 17:54:47.595143 - Ether / IP / UDP / DNS Ans b'partners.wg.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 144
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb700
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63964
|
|
len = 124
|
|
chksum = 0x1bed
|
|
###[ DNS ]###
|
|
id = 50622
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 3
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'api-partner.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'api-partner.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 247
|
|
| rdlen = None
|
|
| rdata = b'partners.wg.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'partners.wg.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 289
|
|
| rdlen = None
|
|
| rdata = b'edge-web.dual-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'edge-web.dual-gslb.spotify.com.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 13
|
|
| rdlen = None
|
|
| rdata = 35.186.224.24
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.597725 - Ether / IP / UDP / DNS Ans b'partners.wg.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 193
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb6cf
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53344
|
|
len = 173
|
|
chksum = 0x922e
|
|
###[ DNS ]###
|
|
id = 284
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 2
|
|
nscount = 1
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'api-partner.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'api-partner.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 94
|
|
| rdlen = None
|
|
| rdata = b'partners.wg.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'partners.wg.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 94
|
|
| rdlen = None
|
|
| rdata = b'edge-web.dual-gslb.spotify.com.'
|
|
\ns \
|
|
|###[ DNS SOA Resource Record ]###
|
|
| rrname = b'dual-gslb.spotify.com.'
|
|
| type = SOA
|
|
| rclass = IN
|
|
| ttl = 426
|
|
| rdlen = None
|
|
| mname = b'dns1.p05.nsone.net.'
|
|
| rname = b'hostmaster.nsone.net.'
|
|
| serial = 1647020872
|
|
| refresh = 43200
|
|
| retry = 7200
|
|
| expire = 1209600
|
|
| minimum = 3600
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.600916 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25544
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299531835
|
|
ack = 3808769382
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:47.609602 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1424
|
|
id = 25545
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299531835
|
|
ack = 3808769382
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x85cb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x01\x07\xd1\x01\x00\x07\xcd\x03\x03\x02\xa5o\xc0P\xd8\x87\x9d\x86\x96\x1el\xcd\xf8y\xd5S\xe6\xf0\x1c\xa2\x9c\x82\xdf\xf9\xe4q\xa8FZ>\xe4 \x9f\xd6{\xcc\xdfW\x072Q\x1ap\xeb\xf0\xb6p<\xcb[_\xea-\x91\x80\xd6*S>\xe5\xf3$\xe9\xf2\x00 \xba\xba\x13\x01\x13\x02\x13\x03\xc0+\xc0/\xc0,\xc00\xcc\xa9\xcc\xa8\xc0\x13\xc0\x14\x00\x9c\x00\x9d\x00/\x005\x01\x00\x07d\xea\xea\x00\x00Di\x00\x05\x00\x03\x02h2\x00\x17\x00\x00\xfe\r\x00\xba\x00\x00\x01\x00\x01H\x00 \xd7y\xaa\x04^\xdeMR+b\'r+\xc6\x0b\xb2V{\xb2\x9c\x0fyH\xbee#\x8a\xad\x19@p[\x00\x90rn\xb6\x86,\x11\x94(\xec\xa6\xcf\xbce\x1a\xca?\x0fP\xd8\xe6\x89L\x16\xa7\xeb\xba\xbb\xabsu\xd8jJ\x18\xf1-\x8d\xe4\xd4~qG\x82N1-\x9d\x94\xf3g\xeb.\x9a\xaf\xb7\xf4\xfdy\x89w\xa8&g\xfe4\xaf\xaev\xa2\x99\x1b7a\xc1\xb5\xd7\x10\xb0\x1e\x99\x15Q\xe5\x12C&\xd3\xc76\xdd|\xd6=p\x9413\xd7\x908h\xc4K\x11^\xdc\x9c\x92\xb8\x80m:\r\xfe+\x80)\x18\xe6\xc9\xb6SJ\xf9l\xf2\x8f\x90[\xcf\x1e\x88t\xe6h\x9f\xb5\x14\xb6\xeaV\x1f[\x04\x00\x05\x00\x05\x01\x00\x00\x00\x00\x00#\x00\x00\x00\n\x00\x0c\x00\n\x1a\x1ac\x99\x00\x1d\x00\x17\x00\x18\x00-\x00\x02\x01\x01\x00\x1b\x00\x03\x02\x00\x02\x00\x00\x00\x0e\x00\x0c\x00\x00\ti.scdn.co\x00+\x00\x07\x06\xfa\xfa\x03\x04\x03\x03\x00\x12\x00\x00\x00\x10\x00\x0e\x00\x0c\x02h2\x08http/1.1\x00\x0b\x00\x02\x01\x00\xff\x01\x00\x01\x00\x00\r\x00\x12\x00\x10\x04\x03\x08\x04\x04\x01\x05\x03\x08\x05\x05\x01\x08\x06\x06\x01\x003\x04\xef\x04\xed\x1a\x1a\x00\x01\x00c\x99\x04\xc0\xaa7Hg\xac\x1d\xdf<g\xfb\x11T\xa5?i\x11\\\n\x92\xab\xb2\x1fXN#e}\xb07\x9d\xa2w\'\xdc\xbfXU\x87\xc5\xd0r\n\x98\x1c\x0csS\xab\xa6\x18\rt\xc6\xcc`]\xf1t\xcf\x87\x8aA\xf9\x08\x03s\xd8\x98A\xd8c\x959\x16\\&f.\x16Z\xd0\xe2?m\x02\xabI\xa66\x8c#\xb6\x87\xd1\x85\xfav\x8a\x90\x87\xbd\xef\x03\xb9]\xe6z\xbd\xe5E\xd6\xb6vp\xfa%\x1f:^\xce\x00c\xe1X\x18\x89\xb3\xce1!4x*\x00\xdd5T\x7f2K\xe5I\xbb\xef\x81\xaa\xeb\xf1\xb7\xf7\xb1\to\xa3A\x8fQ6\x83\x1a\xcd\x9d\x99\x86_\xa7\x87n\xc6^C\xc0\xc5\xf8p&b!\x04\xb7\xe8\xad\r\x07\x08\xb3\xb7.\xf7\xc4\x15m\x84\x85\xf2\xd7i\xf5\x16e\xc5\xdcZ\xe8\x01\x8aQ@\x90\x17\xdc\xb8Yi4X\x0b\xb3\x077\xc0\xd4\x97d+\x80\x9e\x02\x18\x9b\x93w596\xca\xef\xcbt#Wy)\x10\xbf11\x94\xa0\x07aNT$1\x94\x11J\x17{@pcU\'~,\xf4]}vo- T+\x89S\xd3\xa3\xb7\xad3\xa9aEbHv9\x0c\xa0\x97\r\xf7\xa3s[\x9c\x81r[\xee\x86\x7f\xb6\x00u;\xab\xccB\xb7D\xff\x81sR\x03\x8a\xf2E\xa2\xc40,\xe5\x10\n\x1c\x90yw\xa7\xac\xe19\xab\x0cC\x81x\x87\x14\xee\x0b\x11\xdedm\xf0\x05\x1c\xb5\xf6\x894F\x059bm\x80\x86(&\xa3\xb0\xd7!w\x01\xcbaX\xc2\xae0\x88\xa6of\x0euh_\xb6\x8155F\xc0R\x03\xbd#f#\xcc\xe4\xb5\xf7\x02\nLeI\xda\x8be@\x17A.\x9a\x91\xac\x8a\xcf\xacI1t\x81\x10\xb6\xca\x9e\xf9\xd9\x1fZ\xc4\x98\x14\xd2\xae\xfe\xb44t\x8a\x1d\xe6\x1a\x1b\x05xY\xbc\xd8QuB?\x9e!\x01\xdcK\x17]\xe6J|\xd6\x19o\xc0\x0cE\x10V-\xb3\x90\xd9,\x02*\xfc\'H,U\xae\xc7\xbb\x19\xc1=\x82\x86dw\xb9O8iq\xb3\xf0O\t\x93\x98\'\x92\xb9\xb0\xf5\x0f\xac\x08\x85\x1a\'\xb7\xca{9\xba\x0bh\xd9+\x91\xa2\xe6|\x1dc|R\xe5\xad`kF;c\xb5\xe7\x04\xa5\xa0\xb2W\xc5;=TAG\x88\x1c\x8dQ2\xa23\x90m8y\x0f0I\x91\x00\xa1W\x17\xca<\xa9\xeb"\xc8\x1b\x98\x87\x17f\xb0\xd2.\xbd\xb1!@X=\xff\x16Q\x8c\x86V\x08\xfc\xc9\xc3p9\xabS\x95\xcd2K\xcb\xcb\x0fJ\x96M\xaa\x99\x8f\xe5\xa8R\x08\xb2\x0b\xbds\x05\xf2\xc6\x92\xbe\x81\xc2%\x13\x87\xd2r\xb4Y\xc6\xb5\xb6g\xa7j:\xc4\xc8\xe4\x13\x16+\x1f3\xd6\xb2\xafD\xc5\xac\xf5}\xdcg\x1a%rSC9U\x9d\xf4$.B\x16s\xe94\xf0R\x85\xec\x86ek`$J\xc5\xc8\xf6\x19G\x9e\xb4\x0c\x91\x9c\x8e\xb7\x95\x1d\xb7\x06\xbeY\xb4\x85i\x8c\x94\x08\x86\x80\x03\xe0\x8e\xb5\xb4\x18&BZ8!h\xc2\x08H`;k\x81\xb7\xae\xf9[\xb1P\xa0\xca\xed\xfc!\xbe\xe4<\t\xaa\xa0\xc34hJ\xe3\xc5\n\xc3|\xb8\x80W/\xe6m\x13\xc4\xc3\x1e9u\xe50\\\xfa\xb9\xc1\xf4\x1c\xaa\xd9\xca\xad\x8f\x15/\xa1\xc6ZseyZh\xc0\xa8\xa1B\x13\x8cK\xdfJ-9\x85\x08\xdf\xc8m\x9870\xdc\xf3s~\x88]\x11\xe4\x8f5\xb9\xc6\xfd\xfa\xa2\x8c\xa3\xaa"\xa9GV\x96H(\\\'\xe3\x88@\xc4\x87\xc8:\xab\x84{\xa3\xb3\x9e\xa3d\x17\xbc\xb7\x15%\x95\xc9\x95e\x07\x90\xc8*\x9b3T\xfa\x1c<\x87Lc\xe1\x1d)\xda\x9d\xc6)7y\xba\x96*p\xc2\x12\xf8\xb1K\x18\x1c\xd4j\x15\x10\'K\x17(a\x1d\xd6\x89\xc8\x87\x94Dv\x7fO9'
|
|
|
|
|
|
2024-12-14 17:54:47.619039 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 662
|
|
id = 25546
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299533219
|
|
ack = 3808769382
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 513
|
|
chksum = 0x82d1
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x10/H\x90>5;S\xd92\x1f\xa3s\xe9\xfb\x99v\xb1\x14\xbe\xf8\xba\xee\xc0\xcb\xc0\x00e\xbd%\xb6\xf6\x06m;s;N\xa6\x9e\xd5\x1bK\xebz\x8b\x87\x88@\xd3\x00\xa9H\xf1\x88`\xcc\x85\x9fz\x9eb\xb5\x8b\xa7\x82\x98\xf7\x17\xc4T\x9c\x97Vpnb\xd0c\x0f\xf3\x8cr\x02EDHe\x91gK\x1d\x84sj\xe4`\x93\xe4\xa6\x1c\xa1\xa8\xa1\xd7\xbd{\xf7c\xbdz\xcd\xed\xd8ln\x11G}\xd4\x17l\x85"^p\x98%\xabd\xfa\xe7\xaf\x04\x80f\x13\x16V\xcau\x917\xd8\xaa\x03\x15\x1b%v_\xe8p\x1d\xf2\x8c\x0f\xc3\xe63Q\x01p\'\x13\x91\xc2:J^\xf8\xa5\xbe\xe2\x92\xf9\xe9\xce\x06G\xa6Q\xd8\x03\x80\xea\xce[\xb0\r\x9dg\x14\x969\xac\x1cv\x0eY\xdb\x7f\xfe9\n\xdfi/aB+\xe9\n\x8dg\xc5@\x0b\x17\xb2)\x03\xb4\xb1g\x8b\x05QS\x06\xf9X\xb4\xe0l\x17,\xcd=\x85_\xe0\x03]\xd7\xd8\x15\x9c\x95hS\xa8s\xc8\x16\xa2i\x95%\xb8\xca\x9f\xd4F*\x86\xa3\xbf.\xa2\x9f-\xc383y\x1c\x07\xb6\x9b\x99\xde\x9cP\xece\x1e\x95\xab\xa6\xbdBy/\x00\x1d\x00 \xc5R/9c\xc8\xb3p\xe4l1+\xc6\xf12\x00\xc4v\xeb\xe6\xc7i\x00Z\xdf\x935\'\xff#+w\xfa\xfa\x00\x01\x00\x00)\x01\x1b\x00\xe6\x00\xe0\x00\x02E@\xdd\xe2\xf1\x12\x9fD>\xfd\xf4\xa5!{\x9e\\K2\xc9\x07y\xe6u\xac\x9c\xde\x11\x03\x94\x90\x07\nAa\xe5)sm\x88V\xf5\x13\xe9\xb0b\xa4\xbb\x85h\x14\xcfHS4c\xd1\xbc\xca\xdb\xc5\x01>4:3N(\xd0\xfb+\x91\x17\xbfg\x1a\xf0\xc9\x00\xc1\xce@\xe9\n\xf9\x18\xe7:J}&\x9e\x90M\xe7sQ\xdf\x02n,\xaf\xa3A\x90\xe4HG\xeb\xf1\xff\x13\x1c\xaa\xa9\xaa\xf2\xb0B\xb9\xdc|\xcc\x1bO-B\xdc\x16\xe5O\xcc[\x81\xff\xef\x9f\xfa\xe3\x93\x12\xfc\'\x08\xedV\x03\xd4\xc7\x92\x92L\xfd}\x90\x83\x83$S\xfe\xf8NUT\xc5_`t\xe6\xe9\xdf\xc0P\xec\xb1\xbc&\xd6\xba\xdf8\xb1\xed\xd4QC}\x94\x0322\x87\xa8\x86VZ\x87n\x14\x83\xa7\\<9\x11L\xe6\xaf\xae\x8c0\xc8F\xf8$(\xeay\xcb\xf2\x8e\xf3\xebm\xf2s\xb2\x0010\x90+\xb4H\xce\xf8\x1cO&(6\xdb{05N\xb0\xaf%\x80\x86E\xd4\x87\x85\xb8Y^\x17\np6\x16\x1dE\x84Y\x03\x95F\xd3\xd4\xdb\xf94\xd6h\xb8'
|
|
|
|
|
|
2024-12-14 17:54:47.628042 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 30883
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca81
|
|
###[ Raw ]###
|
|
load = b'\xc7\x00\x00\x00\x01\x08J\xa4\xfd\xe9\x04\xea\xaf`\x00\x00D\xd0\xfd X\x98t\x00z:\xf6\xf1~|\xcb\x01\xa2y\xbb\xc7|\xe8B\x04/\xb1W\x0e\x05\xea\x02Q\xebN\x9a8+\x19\xd5g\rfSP?\xfb\xec\x15K\x94^\xe5i9\x83\x02\x06Io\xb3\x8a\x89\xe5l4\xb5\x06\x89\xe4\xa9s\'^)\xf6\x15\x9eo\x9e|\xd4\xael\xe2\x17\x84\xb9\xe7\xa3\x93\x9d_\xa5<\x9e\x19\xe9\x85*\xe3\x8dO>I\xbcH\x8a\x95%\xab\x03\x02El\x8b\x81\x84_\xd3\xb1\x07\xf1\x81\x99\xe5\x82\xe6\xd4\x8b\xd3t\x8bu\xd0\xe6\x00r\xbe#\xaf\x7f\x07?f\xbb\xb6\x1d\xa6!/Ca\xafa\x96\xf7\x12\xce\x83}\xfb\x90$B\x8a\xadw\x06f\x1d\x91\xfe\xcc\xfae\xa4\x0b\xf4\x8a\xb3\r\xc9\xef\xf8\xae\x9e$x\xeb\x1alN9\x8a\x14\x1ao&;\x0c*\xc2\x15\x06\xff\xa9aO\x14\x14q\x0e\x94\xba1\xbd\x88\x91\x80\xf7\xbe\xf1;T\xd6W\x17q\x0e\x82\x8b\x8ez\xf7[\x15\n\x84\x1c$\xb6lf\x85\x00\x026\xea\xad\x8d\'Q7{\x04\xa4j?\x89\xdefF\xa0l\x16\xf5\x9b-s3M\xa7p\xf7~\xc6\xbe4\x11\x8d5%\x90|\x1a\xc3\xab\xa7\x9f\xd2_wKL\xbb\xbb\x1dpB\xe3\x84\x87\xf1\xf4\xe8U\xcd-I!\xdf\'j\xb4Kl,\xa5FLiw\xce\xea\xca\x1c;\x05\x8f\x1a\x9cp\x89M44\xdbvc\xc2\x17v\x8c\x9e\x15l\xeaThk\x90b\x18\x7f\x8eR\xc1:\x03&\r\xedZL\x03\xa6\x88\xd4J\x1bq\xd0f\x9d\x1d\x84\xc1"~/C\xb2\xe7\x9a}\xe3g\xab\x98%\xcb\xb2\x1eD\xe5\xe2E\xac\xe9K\x13wFR\xe2\xae\x1e8\x7f\xd3\x19s\xba\nM\xac\xec\x1e\xa2\xf7\xec\xd7\x03:\x8d\x1c\x1e\x92\xb4}\xc7\x16Xg\xa9\xc4\x97\xe703\x99\xaa\xe5\xb7\x13\xc1\x0c\xf4\t\xe1\x88\xac\xbe\xe4R\xe5\xc3\x1a\x82\xd6\xe49\x16\xaa+\xd8\x1f\x8e\xe3|W\xd8\xcf\xed\xb7s7\xe4o\xb6\ry\x06\x9a\x18\x83vK&d\x15`\x9f\xb97VUc\xddz\x81\xa8GM\x1e\xdafmEeH\xbd\x12dM\x9eCHD\x81\rV\x16[\xaf\xe5\xe8[\t~\x95\x81\xb2ev\xb8\xd7\x88\x88\xfc\xa6\x06}\x97\xe3\xf7\xa8~j9\x86F\x12\xa5J\x0e\xde\xda\x13\x00\x13\xc8\x18\x86\x98\xfd\x16\x01\x0e\x99f\xd1\xbf\xdb[^\x88(\x87\xcaJ\xef9}G\xfd\xb9\x00\xc4\x81\x1e\x9f\x02\x8f\xf1e\x92\x8d3$J\xe9+\x0e\xb2\xb4\x1d\xcbu\x03\x06ig\x01\xf7\x0f\x13\x98\xddm\x1b\x1b{\n\xe0=e\xdd\xe5I=\x1a\xd5#\xea^\x9f)\xf6\xe9\xa5\x167\t\xcb.\xceX\x07Z\x80\t\'\xf4[\xdb\x19\xe2\xc9#\xbdk\xae\xbbJ\xb62\xa6\xd4I\xfa\xef3\x91\xdc\x81\xba\x16=\xe5\xc2\t\x97\'\xe6\xb6ks!\xc0\xa5\xf7pd\xd6\xaa\'7\x05O\xeea\xcf\n\xfd\xe72\xd6\xd5n^\x88\x1f\r\xb8\x1cL"c+\xf9\xa5>\x17\xf9M\xe5\xfe/q\x03n\x00\xfa$\x187\xcf\xae\xa1\x15\xdb\xc5\xf5|:\x07\x94!;\x9b$\x03\x8c\xa8P\xed\t\xe3\x1d\xe7\x1bR\xa6C\x93\xc6L\xc1\xeei\xc9\xac\xf2\xc9\xe7G\x06/*\x14b4>\xa6>\xae\xee\x08\xf7|*\x07\xb4d/\xf52\x92\xfd{\t\xcc\x89\xccr\x99\xa6\xb5\x0c<\xcfz\xe9;=s\x81\xf5_\n\xe0\x98s\xe9?\x10\xedz\x1aw\x1c1\x86=\xb0k0\x81\x8d\n^\xbc\x9f|\'f\xd22\'\x13\x96\xd5\xafG\xa3\xc7\xec\x9d~\xcc\xda\xd8\x17Jl\x9a\xa7ha\xa0\x835\xb6\t\x9a\xed\x03\x984\x0f\xf2\x82H\xeb\x91_\n\xc0{\xeb\xb9{N\xbcx\x1a\xacQY\xa8n\xf0\xce\x82\xbe\xd40\rUWx\xef\x0e\xd3\x88\x9d\x89\xadsm\x8d\xa3\xa5\xda[=\x1e\x96\xa2J\xebGEiV]\x91%\xa21[\x8f\x90\x1f\xeb\x1f\xccW\x11\xf8*\xa97,\x9f\x06\xd2\xa8t\x9dO\x00V\x7f]\xf8P\x08\xff\x86\x8c\xdb\x9ea\xb0O\xc0\x96\xces?\xd3[@\x1b\xf8\xf4u\x97\x84\xef\x1a\xb5\x151\x84\xb4\xc6-ziMl\xf9\t\xd3\xa1\x99\x88P\xa7K\xacP\x90k8\x8a\x02\xe3\xe2\xaf\x08\xa9\xb6\x021=c\xa8\xee/\xf7\x13\xda:s\x01\x91\x95\xc2X\xeee<9\xb4\xc8\xbf\x9b\x9f\xe6\xb9t\r\xff;*b\xf7\xd0\xb5\xf9&\xe5\xc5\x0fy\x0b\x1d\xd0>;l\x89\xe0\xc4\t4\x11\xc8\xcaN\xc5\xde\x02\x87g\xd9\x8fo\xd5\xf1=\xb5\xb3\xd8s\x9aGg\xd7\x00\xfc\xeeP\x9c\x9f\xe5\xca\xf3\xf3\x88\xad\x90\x08\xfe,\xce\xd0Se\xd5\xa3\xa3vaL?\x96\xe6\x0c^u\xab?&\x0e\xacE`\x89\x0f_u;\xea\xb06q\x06\xdd\xfd\xc6P!;A\x03h99\xcd\xed\xaa\xe9\x13[y\x9e\x9dm,\xcc\xe6 \xf4\xe8K8\x81\xe9\xe6E\xb1\x05\x9d\xd3\xaf\x98\x0b\\\x0c8\xf0w8\x029\x92O\xc3\xb8K\xad\x0f\x89,\xdf\xed22H\x8a\xa2\xf3[G\xee\xeb\xe4\x9b\x87%`3\xd8-\xa3\xac\xf6p\x1d'
|
|
|
|
|
|
2024-12-14 17:54:47.638203 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 30884
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca81
|
|
###[ Raw ]###
|
|
load = b'\xcf\x00\x00\x00\x01\x08J\xa4\xfd\xe9\x04\xea\xaf`\x00\x00D\xd0\xcdx\xa2\x0e\x0c5\xf3A_\xed\xa3Z2F\xfb\x1fL\x92\xf3\xa1\xf4\x80`\xb4-~\x94U\x0b\x12u\x84\x105\xa9e\xf0`\xf9f\x84\x89\xc0\x11d\xdfz\xab\x83k\x18\xf8\x91Z\x9a\xf22Z\x19 \xd7\xca\xbf?\xa7\n\xab<y\x9d\xc8G~\\}\xdey\x15\xb3b\xea,\xc4\x95P\x8d\xd9\x8c\xfc\xa4\xc9V\x15\xe6\xbc\x17V\x8f\xb2\xa1\xd0M\xbd\x13\x87\xe0\x9d\x18\xb5\xf9\xdc\xbe\xb8\xf7R<5\x12"K\x84AG\xc1\x7f\xa4\xa5s\x8d\x96\x18\x92\x97\xdc\xb8\x7f\x87\xdc\x06\xab\x7f\xb7x\x01T\xb2.t\xbe\xf4\x81\xcb\xc7\x14\xb8\xba\xedl\x9cs\x825S\xdd0@F\x15\x08\xe4&uC\x97`I[\x1e\xaf\x8a\xff`\xc1\xff\xb0\xc65S[m\xac\xa2\x8aO+b\xb0\x0f\xf7~\xbb\xfb\xb2_\x86s\xffR\x92k\x14\x91\xa4\rz \xff\x8bkP\xebWw\xe9U\x8e\xaav\rc\xb6\xa0\xb5\x91\x175\x84d,c\x12\xd7\x8d\x06\xca\xa3P\xc2\x8ckBco\x02@\xe36dJ\xbd\xd6aA4\xce\xd4=;*\x8c\xea~Q\xcdSd\x0b\x83\x02\xbb\xc3\x0f_\xa3\xbf\xabLS\x88\xb5\x0f\xf5\xd1M\xe8\x05\x07\xc3]\xcb\xfe\xe5\xa3t\x1c\xd5\n\x81\'\x84\xb7\x9f\xb6)\xd7\xf9\x0e\xf1\x997[<a\x1e\xca\xe0\x94\x964\x9b*\xe0\xc7\xee\xd4gE6\xcd\xbfu\xe4_rE\xff\xac\xcf\xacE\x1fV\xca\xcem\xe6=\xfcV\x81\xba\x9d\xb1O\x96\xc8\x89B\xb6\xcf\x94\xc7Cz\xbd\xa7?\x97\xdb\x9f\x19\x81\x8a\x9e\xb0\x03\xc9dYO\x88\x9d4\xdf\xcf.m\'*!\xb0\xa3a\x93\x10\x04!\x04\nq\xb7\x0cT\xff\xcf\xf2\xf1\xa8._\xe4\xac\xa4\xc0y\xd6)`:\xc0\x99\xd3\n\x1e\x87\xc6\xe1[\xbc??\xb3\xd6d\x94?\xda=.aW\xf9\x86Z\xe7\x8bQ8Z\xd1M\x95/\x01\xec\xd6[\xa3\x05\x98:\x8d\xe22\xa8\xe6]\xfc$\xb9Xxj6G\xfc;\x89\xc6-l:\xeb2\xa1\x96\x81Z(9\xacu\x97\x13\xcb;\xb6\x1ftG\x0c\xc2\xf6\xce_n\xa5\x8b\x91\xec\xa4\xfcb^\x08\xb2\x8e(Z\xcac\xe3v/\x15\xe9\x7f\xcfZ:\xf2Ni}\xb5"\x01\r)+R6\xe8<\xe0a\x89\xab\x98\x9d\x80\xb03\x94\xba\xfa\xd6^\xfex_\x95\xb6\x1b\x8a\xcb\x0e\x0f\x0c\x13\xbc\xba\xef\xb6\xe0\x96\x8b V<:\xdc\xb9\x07\x0fU\x1b\xc9=+X\x1c\xda\xfe\x0b\xdb\x02\xcci\x11P\x06\xbc\xd0\x0e\x87\xfcd@\x977(Dp\xbc<\x0e\x943e\xe1\xff\xc0R\x01\x84\xa2\xda\x81\xc84\xc1!\xd5s\x93S2KG\x02\xa8\x9fj#Dn`TW\xb9\x84U\xb5`Ke]\xc2\xfc\x00[\x800\xd5t\x8aBP\x07\x98\xa1\xd6\x17\xe6\xaf\xd7\x83\x06\xa7\xd8\xbb\xe9S\xc3_\xb4\x85]\xdb\xa9\x9e\'\xc7E\x91\xf1\x02o\x8c\xa3e\x99\x8c\xcd\x02\x14\xea\x98\xfd\xa7roBp\x16\x189\xaefv\x94\xb4\x10!\xe1\x98K\xa6\x19\xc5\xda9\xdd\xcb\xb0\xca\xad\x99\x92\xeb4\xeed\x18\xbb\x88\xaegp8`\xdf\xb4\xd0\xcf\xe4\x7f\xe4\x8b\xe7j~WxR\x86\xe5\xf2\xa1\xd1\xf3\xb4\x9f\x0fx\xa1\x89\x87\xc0\x14\x05g\x86\xfb6\xa6\xc0\x88-\xb2\xbe\x8eoQ\xed#b\xa6&\xde3K\xb3\xee\xd9\xe5=\x10\x81B\xfd\x85\x13_\xe8N\x91*eL\xc27\xfe\xe7\xf7s\x97\xcc\xb7\xf8p\x14\x9a\xb2\xe05S\xe7\xb2$u\x00d\xfcpx\x14\xa3\xff\xa7\x8e\x025\x96Q\x8a\x99\x16\xb2\x89;\x9e\xdfw2D8\x88\x9d\xd4\x8b\xb7=Z\xe6%T\xadq\n\xf6\xc7 J\xb1\x9c\xf2n\x00\xd5\xb4\x17\xbe\xf4\xf8\xee\xf0\xe3\xed_@8qHK\x1bGL\xb0\x8a\xb2\x7f\xb8B=\xaf\xcf\xa7\xa36\xe4\xf9\xfb!\xd59B\xb1{\xc2a7\xed2\x19\x97uq\x97\xc2\xa9\x10\x18\x99\xf6v\xd1#J\xc9\x18\n\xf3\xb0\t3\xd6{\x8ey\x81\x17\xfa\x1f\xcdY\xc8\xc8d\xf9\xcd\xe8gx\x95\x01\xe1\x10u\xa1\tOx\xd3\xfd\xdfG\x94\x1c\xde\xe6\x0e^\x02y\xef\xa5S4hP\xf5\xb3\xf4_\xeb\x95F\t\xd9n\xc6q{\x86\x06\x8cT\x86\\u\xd2\x14@[\xca\xc0\x9e\xecB\x9d/\xc3\xdf\xe7f\xce\x99\xd7\xe2{UY|,-\r\x18J\x08\xc9\xc4w\xba\xb5\x04aH\xe8a\x96\xbcL\x1d(a\xb8\xda\xe0]\x93\x89\x00\xc9L\xcb3o<T\xddV\xd7\x85\xffHWBs\xd7\xf1\xd4*I\xa1O\xe3\xc2\xec0\x978\xd2\xeaB\xb4\xc6\xdf\xd0=_q\xe2c\xa3|\xd4_\xb0\x8f\xba\xa6\xa9\xa7\xe0<\xcfzb\xc5:Bg\x16Qk\xdb\xbf\xbc\xc2jk[\x01.\x06\xf7{9\xa8u^=\xcaS*\xcb\xfb\xc8\xf9N\xccv\xf8\x9c\x80x8\xfcZ\xc1\xe2S\x1c>\xc1\xde\xfb\xe8hA\x1a\xdd\xb1\x8b\x12\xae\xd7\xd4\x84\xe7A\x08a\xe6+\xb2\xe2W\x8f\x90%7\xd4\x92&\x85vK\x13\x91\xba\t\x12\x1e\xd9\x06!/\xce\xf3'
|
|
|
|
|
|
2024-12-14 17:54:47.644436 - Ether / IP / UDP / DNS Ans b'edge-web.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 167
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb6e9
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 60325
|
|
len = 147
|
|
chksum = 0x82a6
|
|
###[ DNS ]###
|
|
id = 1181
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 1
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'spclient.wg.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 262
|
|
| rdlen = None
|
|
| rdata = b'edge-web.dual-gslb.spotify.com.'
|
|
\ns \
|
|
|###[ DNS SOA Resource Record ]###
|
|
| rrname = b'dual-gslb.spotify.com.'
|
|
| type = SOA
|
|
| rclass = IN
|
|
| ttl = 223
|
|
| rdlen = None
|
|
| mname = b'dns1.p05.nsone.net.'
|
|
| rname = b'hostmaster.nsone.net.'
|
|
| serial = 1647020872
|
|
| refresh = 43200
|
|
| retry = 7200
|
|
| expire = 1209600
|
|
| minimum = 3600
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.653609 - Ether / IP / UDP 192.168.1.11:63056 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 30885
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63056
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca81
|
|
###[ Raw ]###
|
|
load = b'\xc6\x00\x00\x00\x01\x08\xc5\xa6\xeb\x0f\xbbm\xbf\xd6\x00@F\x00\xe2\x9b\xa6\x84\xa5\x7f\x19\x81\xb2e\x8ck1IU\xf6\xf3\x1b\xe2&&q\x8a\xeb\x87a\xd9\x82\x97\xe8(\x98\xb2\xb7\xbb0\x0b\x01r\x97\x82p]\xaf\xee\xf3\x10\xfa`$\xecY\xc0\x02y\xc5\xbfW\xa6\x85\\\xdb;\xf7\xb4\xd8 \xf6\x02D\x892\xcb\xc9E\x97\xe5MF\xb2E\x9c\x83\x9d\xec\x07QYK\xcfU\xff\xb5\xcd\x19\x9e\xda(\x14@\x0b\xbc\xd5\xcf\x8c\x19\xd09\xdf\x1fK\xdc\xe5\xbfF\x87\xd3*z\xab\xce\xc9\xd8\x9cB\t\xb2\x05\x1d-O\xcah\x08\xec<\xe8\xf1\x89Q\xda\xa1\x1c\xfd<\xff\xeb\x98"\xfe\xf4G\xd4\r\xcc\x1e\xe0\x9b_\x9a]c\x0f{97\x96i\xd5\x9dC\x89~\x9b\xfd\xef\xdf\xc9\xb85z\xfa\x12\xa5H\n\xe4\x9b\tj\\\xcfe\xf0\xe0Wo\x13u\xe6\xe9\x0f\x84\x97Yu\xa8\xd2y\x16M\x18\x96\xab\xe5\xe8UDv\xf2\x1c\x1c\x1a\xa1\xd5\xbc\x8bC\xa5\xdd\xb8\x8a(%\xa0jbZ[o{6\x11@\x1b_c\xe4\x0f\xb2\xb8\xa6CW\x13\xdd\xac:j)6A\xd0\x94a\xf10\x1eS\xcaU\xf8\x89\xeb\xc9:\xbd\xcf\x05\xf7_\xb7\xbf?^\x03\xbc\xdc\x1e9\x1bp\xdc\xab\xd2\xcf]\xd5c\x00\x9a\xc6\x8a<\x97\xf6\xe3\x9c`U\xff\x1c\xfbM\x0b\x06\xd8\xe55\xb0\x0f!\xfb\xa9\xdf\xb1\x91\'\x8ak\x81*\xb3\xd2\xe1t\x12p\xcf\xcfp2\xa8s\xd7Ni\x1b\xe3\x17\xc9$P\xca5\xab\xb5\xfd\x00\x15\xe2\x8b\xcb\xcep\x92;\x9d\xdc\t"\xbc\xf2\x9f\xe9\xac\xd6\x81\xcc\xa5\x92\x16\x907q\xe2\xd9\x90\r \x10\xaa>@\xa1:\n3\x97-P\xef\xd4\x8f\xeepeY\xb0\xf4r;Jd\x06\xb0\x0e\xa2\x08\x1b\xb8X\x88\xfcdu\x04X\xefO\tv\xdf\x7fj9\x9b~\xfc\x99S\xb5a\xb0{\x88\xb1kF\x92\x80\x8aZ\xcf;\xddJ\x9b\xe1\xd9\t\xd5<\xc99-d?\x8d\x9ab.\x86\xfd\xc2\xa53\x17X\x91\xef\x97;\xbd\xae\xd3I\xe5\xd7\x9eDj(\xfch\xa8\xf6w\xdb\x90>;x\x14\x98\xbd\xbdF\x03n\x00\xfa\xa0\x03\xf2\x90i\x19L\x0b\xdc\x8e\x19\x8bO2\xe8\xbdv\xde\xb0\xac\xcf\xc3\x91\xf3QP\x0b\xe1\xe4\xfd\xa4\xa8\x9b~e~\x0b(a$\xac\x94\xb3\xf9\x13\x1d\xcd\xac\xd5\xb8\xa1c\xa5I\xf5\'EN\x132\xbe\xe4\xae\x8e\x1c\xe2So\x92w\x01g0sV\x16\x00!I`\x83\xa4Zj2 z\xdb\x10\xc8\xe3\xbfw\xbc\xab\xc4\x19t\xd6?\x05$%\xca\xa9\r\xcd\xf6\xcd\n\x9cHm\x08\x80\xda\x8c\x87i\xae\xd8\x0cy\x91\xd8\x0b\xec\xaa\xdd\xb0\x98\xcf\x00\x84K\xba%\x02E\xf05**LRWO-l\x853\x15\t"\xbf\n\x941"\xdd]\xe7\xa0|\xa0\x9d\x85\xf5\xa0\xaa\xe4\xd8\xc6\xd3\xb6\x04\x7f\xde\xd4\x07\xed]\'\x814\xa8.N\xb2\xa9la\x16\xd9\xdd\xc9N\xf8j\x88\x02\xee\x11\xff\xe59\xff\xc6u\x02"\xd4\x07N\xf7\xacvo\x15\xb5}G\xce$\\\x968\x861\\n4\xec~JbJ\x17\x15\x0fS\n\xb7\xcb\x9bc\xc9.\xe6*eL\xf7\xbc\xd0i\xdc\xd3\x0e\xd9\xd2\xf22]\xbe\x96D\xa59\xbd\xf1\'\xc7\xa0}v\xc7\xb8U\xdap\x87\xb1\xca}G2 \xf2"`\t.\xdb\xd7\xber\t\x8e\x92\x92\xc1\x91\x00q\xeb\x88\xe5\xed\xb4\xf5\x81\xa26r\x12\xc8:\x11\xa9\xaa\xcd\xb8}\x0b\x1e1t\x91\xde\xf9\x94\xe1\x9d\x00\x93\x16Q\xe53P\xfb\xd0l\xd4\xdd\x85\xd0\xf3.]\xc2\x89\xa3\x07S\xaf\x94R\x04\xc7\xb5K]\x87\xf5>.ex\xdd\xcb\x04\xcdE\xcd\x91\x88_\x99\x14E=\xc2\x9c#\x18\x80\xc4t9\xab\n.\x0b\xce\xca\xf0\x1d]\xa6\x0b`\x04\xf7{\x8eg\xb7\xe2\xaa\x82T\x899\xae\xdco\\t{\xce\xe2\x93\xeb\x8cL\xee\xc4\xc8\x84\xdf\xc6\xde\xf5\xc9\xd9%\xa5\x90\x94]\xb2\xee\xb3\xef\xd3y6z\xd2\xb3F\x1d\x0b5D\x7f3Y\x90\xf3C\xe3\x8f\xa7ANeR\x92\\\x12V\xf3,^\x1dH\xbd\').dz\xd5\xb8\xecl2\xa0H\x95\xf4a]N\xe4\x9e=k\x8f\x15yj\xec\xf1\xae\x1f\xc9\xd0\xa8\xb6c\xa0\xf6\xb66P\xca\'\xfb=v\xa4\xb5\x1a`#\xd1Z\xd5 U\x8a\tD\xf1\xb4F\x03\xf7\xb1mp~\xa3\x02\x83\x1fFi\xaf\xed\x9e\xf3\xe9Oj$\x94M\xaf\xc8\xb5\x9b\xa7*\x9b\xce+\x00\x11\xb6\x81\x06\x0cp\x9cS\x92\xcc?\xec\xea\xcba\xc4\xa0\xdea:M`\x92\xa9J\x00\xa3\x01&9\xe1\xf8\xd4\x92\x89\xcdqw\xc8\xdf\xf1\x16\xb8e\xb7\x7f\xc3B\x8a+S\\\xc6\xda\xdaJ\xa3\x87.\xc86C/\\\xdd\xca\xb4\x83\xd4\xf6\xdf\xc7V\xcf\xca\xe4\xec\xbb\xbb\xa1\xc4K\x0e\xbat<*\xcc\x01\xf8\xaf\x90\xa1#\xcf\xc5$4\x94\x05\xafV<\xd2\xbf)}\x8f\x0b\xf0w\x0e\x062\x95\xaf\xbb\x00-\x8fsc\xec\xf8\x11\xdf5\r\x01\xc8\x9e\xac\xf3\xe8\xaa7e\xbeg{d\x9a\xb7+\x017\xee\x17'
|
|
|
|
|
|
2024-12-14 17:54:47.663807 - Ether / IP / UDP 192.168.1.11:63056 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 30886
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63056
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca81
|
|
###[ Raw ]###
|
|
load = b'\xc0\x00\x00\x00\x01\x08\xc5\xa6\xeb\x0f\xbbm\xbf\xd6\x00@F\x00\xe2\x9b\xa6\x84\xa5\x7f\x19\x81\xb2e\x8ck1IU\xf6\xf3\x1b\xe2&&q\x8a\xeb\x87a\xd9\x82\x97\xe8(\x98\xb2\xb7\xbb0\x0b\x01r\x97\x82p]\xaf\xee\xf3\x10\xfa`$\xecY\xc0\x02y\xc5\xbfW\xa6\x85\\\xdb;\xf7\xb4\xd8 \xf6\x02D\x89 E\xbf\x175\xfcx\xa1tJ\xdf\xb9\x06a\xa0\x18\xe86\xfc\x16\xf5?\xf9\x08\xf0\xb9\n=\xe9\xa0\xd8\xcb\x8e\x81\x05\x1d\xdc\x0bi\x13b\x01\x13G\x1a\x86\xf0\xca\xd7\x92\xc2,\x07\x0c\xba\x0bZ$\xb3\x0c\xb8\xc1 \xe8\xa7\xee\x89\xa6-/\xb1\x99G]wI\xd2\xbbQ\x11P\xb5\xbd\xeb\xfd\x8c\xf7\xdcnd\xe2\xf8O\rkQ\xfa\x1d\xa8\xa5\xf2B]\xfaC8\xb4\xe4Lb\\f\xcey[\x1e=t\x07\xec\'{\x7f=%\xa1\xe9y\xfak\xa9\x06[\xd1\x89\xeeH\x84\'|47\xf0\x12\xfbC\xc4\xeb\xf7\x879\xf4\xdc#\tB\xe5\xb2\xcc\xed7\xa7\xe8\x9c\x95\xda\xc7\xab\\ |\xbf\xc7Vvy\xbc:\xd6\x00WS][j\xf1\xf1\x00\xb9\xd9P=\xf0\x0e\xdbX\xa6/o\x0b\xed\x07\xb1|\xe2\xacrx\x0f\xdd\xe2$\xeexaf\xe8\x9c\x94\xe6\x16\xfaR$S\xe4:~\x16\xc5\xfe)\x0c\xbc\x98\\#\xbc7\xd5>\xf6\x8f>\xe1\x9f7\xb3D\x98PRP\xb4\x02"6\xa6YJ\xd4cg\xd3\x90\x1f\x11\xdf\xdc\x80\n\x8c\xed\x8b9\xee\xb1[E\xa3\x17w\xf1\x19\x01\xccc*/>\x9e\xafW\xfd\xd7\xe4\xbe\xc4z\xbb\x84\x9b\x1c8~\x7f\xb8R\x0f\x98o(f\xe1\xef\xa1h\xa9\xd5\x08\n\x1c\xe5W\xb6\n\x13v\x16\'o\xe5\x9c\x96>\xbbiu\xb62\x94\xee\x02\x12&&l\xe7\xbal:?\xb7i\x14\x90\x93\xf7X\xa8\xe6\xe2\x08\x18t\x97O[\'\xb5_\x8e\xf7\xf6\xb7!\xad\xfc\x0f\xd3\x17T\xaa\xb5\xcb\xc5bZ\xf9G\xfah\xdb\xae\x19\xf9\xbeX\x9f\xa2\xf54\xac\xca\x0fJ\xc5\x94\x865\xffi89t\xa9\x85\x7f\xf6\x92\xd8\xe8\xfa\\o\x99k\xe0\x9d58\xf7\xdc\xeb\xbf\x8e\xf3m\xac\x13p&\x8d\xe5\xfe/\xa9\xacX\x83`\x15r\xf2\xe6\xb1T\xbc7Xc\x9e\xd3W\xe4\x8c\xe5\n\xd34\xf5\xe7\xe5\x1a:\x1e\x9e\x12T1\xabY<\x17\x11\xe7_oG1\xce\xf8\x16G\xa7\xe6\x1d\x84H\x9a\xbaA\r \xb4\x8aRF(\xa1\xdaw\x8d\x00\\\x11M\x8a\xdc7V\x02\x83\xa9\xa1*\x90J\x99Rh\xa3VH+\xa4af\xd9hM\xf4\xf0t\xbf\xe6\xa4"\x8c\x1a>b-\'@Ok\xf5\x85\xfb\xf4\x83b\x81\xa6\x9a\xd4r,\x0b2\xa2\x90\xc3\x83\xba\x80\xe8>/\xe4_\x86\r\x81\xd6\x19\x96b\x99\x0cG\x9c\xc5\xcd\xf1\x1bZH#\x8c\xea\xe4\x7f\xc9\xdf\'\xfe\x91\x03\x9f\xcf\xbf<\x91;SOk\x16ft\x8e\xcb\x87\xc9\xd9\xb3\xf4\xa7\xd7<t\xcc\xd1\x1e6am\x11\xd7\xf4\xc7\xcd\tPA\xc3\xc7\x16|\xba\xba\xdaq\xc5\x9c\xbf\xf0\xa8\xd8h=3\x97u\xf6Qd\x08\xdd\x176Be&g\xb4\xa9Q\x14mF\xdc\xfdQ\xb2\xcc\x9b\xd0\xe8^\xbe\x91w\xf6#\xb99L\xe4\xf7\xfc\rO\xf6\x19\xb5\x13njb8i\xc1\x87\x8d\xe7\x81\xdc_\x8f\xe9\x11\xbe\xeeQ\xd3\x0bx`\x1a1\x10a\x81X\x1b)\xf3"*\xc2\x14\xae\xa5/\xd0\xffA\x1a\xeeR>\x87\x88o\xac\xf8\x07\xbd\xf1\xb5t\x00{k\xd8\xe5\xbb\x93\x90\x16b !zm\xb3Yf\xb5\xbf\xb0U\x8d Y\x0b\xb9\xcd\x82o\xf8\x9es\xaf3\x0c\x89\xa35m\xb6k\xc6\x815\xdf\xa9\x9e|t\xcf\xa9`SV\xd9\x07Z "f\xbb\t"\xdehc\xc2\\\xb7\xb7\x1e\xb4j\x91\xebQ\xb2nW\xb6w<\xdb\xbc\xe4n\x12\x8c\x12\x13s\r\x05\xb2K\x11\x12\xd6\xbe\xd4j@s\x1d\xae`sq\xa9\xe0\xf4\x18\x05\xd2\xb4{0,\xf2{G\x91\xae\xaf\x17\x9dD\x0f\xe67\xca\xb9;JrC;F\x9c\xcf\xae\'&d{^\xa7\xcd#\xd5\xabsC\x11\xd1\xe1\xb6w\x98/\x83"\x9a\xdbOWXL\xb67\xdf\xc9\x87\xb0}\xde\x01hs\xb2\xcc\\5\xdf\xa0\xe6\xd4%\xe1A%V\xe3.\xea\xe7*\xf1\xec&W\x1e(\xb2\xc6L\xbf\xd5U\x9c\xf1\xf9\r\xc2\xa7\x907\xac[4a\xf7\xa1\xc4u\xc2h1\xd9,\xd4\x0cl\xdc\xb5\xcb,\x83,4\x85\xc3\xb1\xa7Q\x92\xa4\x8b\xca\xf8c\xf6\x8a\xb8\xc7"\xe4\x92\xb1V\r\xe8/e\xee\xbc\xf6wK\xb4kSF\xfa\xe7a\xc6\x06`t\t\x18\xcd\xdf\x80\x80^\xd4\xe4\xbc\x800\x97\n\x9d\xc3xM\xb1(E\x1d\xf4\x1aF\xdf\xe2\x89\xcaN\xbf7imG~\xadqK\x8a\x90\x9c\x15\x9a\x11\x1d\xda\xea\xc3\xa8\xc4\x86\xa6\x95\xcd\x8f\x86\x13\xc6\xf64\\ Z\xf11,d\x1a&\x0b\x01\xca\xe3\x8b\xbe\x86\xad{\x0f\x9aU~\xec\xa8\xcc.\xdc\xe6-\xc1\xf9gPb\x8dV\xa2\x1d\xbf\x08\xa8\xc9\xeaw\x9e\xec\x90\xf9@\xc3\x03\xebI\x9a\x07\xe7'
|
|
|
|
|
|
2024-12-14 17:54:47.668916 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 304
|
|
id = 47879
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xb78
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808769382
|
|
ack = 1299533841
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xd3f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x16\x03\x03\x00\x80\x02\x00\x00|\x03\x03\xa4\xd7\xdf\x0c\x92\xd8\xe8\x12Y\x14\x11Wl7QK\x9f\np\x8c\x89\xb0q[\x01\x02\xc0f\x14Q\x93\xe5 \x9f\xd6{\xcc\xdfW\x072Q\x1ap\xeb\xf0\xb6p<\xcb[_\xea-\x91\x80\xd6*S>\xe5\xf3$\xe9\xf2\x13\x02\x00\x004\x00+\x00\x02\x03\x04\x003\x00$\x00\x1d\x00 \x98t\xdb\xb2C\x18U\xae\x8b\x9a1\x0b\xdaY\x9b\x18\xc2\xacU\xa5q\x95H\x9aZ\xfcE\xc6k\nsy\x00)\x00\x02\x00\x00\x14\x03\x03\x00\x01\x01\x17\x03\x03\x00.&\xdb\xd7\xc9C\xbf\x1fb\x04)\xf4h\xa9/99\x13,\xf1;\xea_+MP\x7fM\x96RX\xdb`%\xea\x0f}'\xbf\x9bL\x08[S\xfdKu\x17\x03\x03\x00E~\xf5MJ\n\x8b.\x8e:\x1a\xaa\x0cl&). \xd4\nf\xd0\r\xb6+\x12t1Z0!\x84\xe3khTp\xb7x\xb9\xf9>\xc1\xadc\x7f\xc7!\x1d9b\xb35\xd8\xf4v\x83\xd4}\xc85\xc3r\x1dQ5\xb7\xcc\x8b\xa1"
|
|
|
|
|
|
2024-12-14 17:54:47.673277 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d23
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 48
|
|
chksum = 0x70f6
|
|
###[ Raw ]###
|
|
load = b'\xc8\x00\x00\x00\x01\x00\x08\xea\xa4\xfd\xe9\x04\xea\xaf`\x00@\x16\xed\x7f\x0b#\x9a\x02\xacK\xd0\xbb\xb3\x8e\xf10\x82\xad\xe8\x05\xda\xd0\xef\xa9'
|
|
|
|
|
|
2024-12-14 17:54:47.681669 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7869
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 1258
|
|
chksum = 0x560e
|
|
###[ Raw ]###
|
|
load = b'\xc0\x00\x00\x00\x01\x00\x08\xea\xa4\xfd\xe9\x04\xea\xaf`\x00D\xd0\x9c\x8ag%\xd2\x1as\xcd\xd8/\xaf!p\r\xaa\xf3\xb8\x0bE\xfd\xed5Qw\xb1f$q_\xe6\xa8\xe0J\nyp\xe5h\xfa\xbb\x99vB\xd2\x86\x0e\xcd\xd0\xb1Yf-\x1a$\x8a\xae\xd5^\x16\xf3\xf3\x8c\xe6\xfc\xf50\xa5{\x08\x08\xf4#F\xb1R\x03\x14eA-\x03\x99N\xc9\xc9!\x1d\xbf\\\xb0$\xf7\xbc\xdeV\xb5\xec\xa7\x12\xb8b\x13\x01\xea\\\xcd\x07\x92YVb\xb8\xd4BW\xfc\x04\x82m\xe7\xb6\x1d\xa4\xa1C\xb3\x97\xac\x04\x82x_L\x8d?@\x8b\x16\xf3Nn^\xc3\x9aE_\xce\xe8;\xa3\x15\xf1\xdf0%\x17\xc67\xa0\xda\x91\x85R\xcb}e\x0cI\xc0\xef\xf5\x04o\xf3\x1f\xdc\x9f\x98\xb6s\x8a.z\x80F\xce\x0e\x82I\xc1\x91\xbd\xdcP\xce\xb3\x19\x9a\xfc\xf2\x14\xcc\xea\xd9\xfc\x84\x02q\x96\xf9\xa3\x14%!\xbb:]\xff\xdc\xb06f\xe7\t\xdd\x1a\x15\x13_\xe9\xe4C<\x87\xff\xd8\x1c\x99\xe8Y\x11\x848\xc5\xd9H7H\xb6\x17/$R\xed\'}&\x1f0\x8f\xab\x07\xb0\xf4(\x8e\x12U3\xd8\xa8\xc4\x96\xfd\xa0 {\x96\x7f\xe3\xdb&\x05<\xf09\xcePO1\xf8\xc0q|j~\x84}E\t\xb2\x11F\x8cb,\xcb\xf3{\x1d\x06\xca!\xe8\xa7E\xc6\xf0\xd9\xe6cy\x96V\xcb;{\xb7$sY\x8d\x01~G \xab\xbaiqJ\xe7u|\xc8^\xe1~at7{\x9a\x00\xf5\xdc\xa03\x16}1\x013N\xd1\xdc\x15\xe8=\xdb\xab\x99<}\x0f\xa5"\xdf]\xd3"n\xab\x80Y\x97\xe2\xdd\xc0$\xac\x184\xed\xf29d_w8.\xb5\xa9\x1c\xber\'\x0b\x07\xbdmP\xb5\xa4?\xe6\'\x8d\xba\x0f6\xdcl\xffr8:\xb8\xd6@\xa1\xa4\xb5\xa9@\xd4w\x18\xad\xd2\xc8P\xd4\xaa\xab\x01\xe9\x19)\xdf\xcd\xbf\xeb\r6\xf7\xa0q\xcc\x9dz\xcf\xd6=D\x99\xac\x07kh\xb3\xbb\x91\x84\xd3g\xa8\x07\xfd\xde\xdch\x97\xb9\xbc[A\x18-I\xd2\x89b\xb7\xa0\x0eF#[>\xe7\x0c\x1f\xee\x1e\xc3\r<\xcd\xfe\x81\x80\xa8\xd24\x96\x85N\xd7\x83\xad\xd7\xd2\xcf^\xe8\xf2\xb4<K\xb7\xa8&\xee\x9fO\x9fc\xc7\xfa\x8b\xf9\xd0\xbe\xa8\xc4\xb7\xb4\x03\x13j\x14E\x1a\x060j8}\xb3\xe3\xae\xe1\xb9\xab8SC\xf2\xbd\xd9\xa4\x8f\xfc\xe0\x0f7\xf7\x13\x85\xc2\xa8\xca<&\x02\xec\x1c\xcd\x1d\xbc\xe9i`A\xf4\xf8\x08T\x1f\xe1\xeb;^g\xde"\x1c\xb0<\xe9\xd2`\x82W\\\xa0\xa1@P ?\x9e!n\xb1\xe8$\xaau\xa3\x1f\x86\xb1x\xa9+cDD\x11\xc3\r\xe5\xde\xd4\x9d\x13p\xd3~\x89\x92k\xa6:r\nP\xf0N\xfe\x1evD\xaa*\xf3\xeb\x9f`\xc7\xfd\xa1bd~\xd7\xb2\xc2.7\xb7\x0b\xea\xac\no\x8e\x98\xac7\xec\x8c\x04m\xe4 \x94\xcf\x82\xbe3V\xd8\xbc\x8c2\x1a\xfb\x9c\xfai8\x99 un\tyK\xc8A\xde\xff5\xe7\xa9\xde\xe9,be\xd7/\xc6\xe0\x8d6\xe9\x14\x0f\xc4\xc0`\x7f\x0fD\xe8\xe4\xfe\xe2\xb3V\x17\xa9,\x9a\xc4\xd8\x11\x9f\xd3j\t\xda#\xa2\x99\xe1\xd6R\xdb\x01\xe5+ZV\x86X\\\xa1\x0f\xce+\xfc\x07\xe8\xf0\xb00\xab\xc4\t\xf3\xdb\x99\xf8P\xd4\xba_>\xdd=>\xe2\xbb\xc7\xe1P\x8a$\x8d\xba\xd0\x8f\n\xc0\x9a\xcd\xbc\xa8s\x06\x9b\x87\xc8\x16\xf4iH\xd5\x7f\x8e\xc3d\xc8\xe5-\\%o\x93\x1c\xdc\x1eH\x9a\x02:2\xe8\x1b|\xdbJu\xe4y\x03[\x8f\xf6\x98\xc95\xe7\xa5\x92\xc4\xc7D\xc5\xeba4~\xa2%\x05\xc5\xaf\xb4v\x14cj\xdaj\x05~\xdc\xb5\x87>\x01#\xd9x\x98\x8al\xa7\x8a\x8ap\x86\xe6%:\x8e\xd1\x805Y\x00\xe0\x06\x18\xb5\xec\x8f\xf3\xbf\\\xca\xf2\x8c\x1b\xc5~3[Y\xac\xab?\x0e!\x85,\xd9\xdeN(\xcc\xceO\xee+\xb4G\xb9\x07\xb9\xf88o\xd4\x8e\xe6\t\xb2\xfcR\xc5\xbf\xbb\xba\xff\xf0\x83\xe7\xba\x8c\xcbY\x0b\x05\x06\xa1\xf6\x7f\xe2\xc2\xce\xa8\n\xca\xb6\x9b\x95\xa1\xb5\xc9\x07[X(\x04\xe0\x88\xde<\xb1t\xf4/D\xf73\\\xc0\xaaB\x1cJ\x8c\x0e3\xc0\x03\xe3\xbe\xdc\xde\x06\xb5\x9dhD\xe3\xca\x00_\xffQ\xd1\xb8~\xfc\x84\xed\xdb\x12\x821\x99\xa19\xfa\xe5\xe0tvt\x17\xa5\xe0\xf4f\x8aB$\xea\xd5\x83ph}7\xcd\xd0-O\xbf%xl\xbc\xf0\x1f\xe8\xbc7\x15BR\x19a`\x1a\xcd\x16\x91\xad\xae\x8e\xab?x;E@R\x0c\x0c\x99_\xca\xe9|\x1cp\xb3\xb3p\x05ZK\xcbR\x1f\x1bP&\xb7\xe7\x14\'\x90\x10\xce\x01\x02\xf7\x8f0\xbd\xcd\xbe:\x9e\xae\xfc\xf8\x8c9$\x9f\xd8+k\xac\xbe%LL\xe2\xfbP\xc2\x00,\xbaUA\x1bK\x19\xaf\x97\xbb\xf3\xba\xb0\x0b\x1c\xd2\x93l\xee\xfb\x04\xf6\xc7+\xc4\x1dW\x1e\x9d\xbb\x85\xebL~\xb1\x1c\xc4[\xe0\xf2\xd6\xd5}\x10\\\x88,\x0e\xd6\x17\xbc\xcd\xc4\xfd\xb8\xc2\x114W\x07z\xbc\x8b{\xefSR\xc5'
|
|
|
|
|
|
2024-12-14 17:54:47.695078 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7869
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 1258
|
|
chksum = 0xfda7
|
|
###[ Raw ]###
|
|
load = b'\xc2\x00\x00\x00\x01\x00\x08\xea\xa4\xfd\xe9\x04\xea\xaf`\x00@o/\x11^\xd1(/Z}c\xec\x1c-;>\xd3?\xbam\xcb\xd3\x98\x9a\xe0\x1f\xdc\xce\x0b\xc8\x8c\xa0P\x8e(o\xba\xa0y \x06\\\xe9\x85\x08\x08NMR\xd5\xd5\xdd\xe5oIx\xa3*\xd2\x91\xc7\x96=\xed\x07\xb3\x86pg\xec\x87G\x94\xb51\xebE\xb8\xc4\'\xc9\xe26<\x8c\xa9g~\xeaS/N\xd9\xb7y\xfc.\xe3\xa0]\xebn+\xfdV\x84^\xa9V]\x83\xe1\x19\xeb\x00\x00\x00\x01\x00\x08\xea\xa4\xfd\xe9\x04\xea\xaf`DP\xc3\xe4[\xcc\xec\xd1xs$ \xb8h\xb4\xf9X\x89\t\x1a\xac\xd2\xb7\xf8\x13\xc5\x17\xcb)\x8bS\xbc3EC\\\x0clo\xbcc\x0cdZTPE\x83\x0c=\x1d\xda\xbf\te\x0emP\xa7\xd3\\H,\xf1X\x04\xa84\xf8\xd3\x14\xf5\xcf\xfb\xa9\xdf\x0f\xe0\'5U4[\x0b?l\xb5\xfd\x9b\'\xb4\xe7\xaf\x88\x91\x8b\xc3\x1e\xdc\x1a\xae\xbd\xbf\x96\xbej\xd2\xac\xa0O\xff\x16\xe8\x86\x8c\x8b\xa1\xa8\x97\x03\xaa\xa9\xa9pr\x1e~\x862\x9d\xbb\xe1\x12\x82\x1b\xc0\x94\x8e+\x9d@\x9f\xd5\x1afiZQ\xae\xbb\xb9(\x12\x96\x8eP:\xf0\x94\xfb\xd7[\xa9\xe3(\xfc"j03\xb5dV\x1b\xcd\xfbBp#mrN\x0f\x19\xd8%\xe8,\xc9S!UJ\xefQI\xaf\xe807\xaa\xfe,\x8b\xa1\xca\xc5T\r\xe6\x18\xbf0y\xceS\xd1XD\x8c\xa1\x1c\xea\xe8N\xcb-C\x9czw\xe6\xdd!q@\xf7\xdc\xf8~T\xd8)\x94k(\xb4\xfa\xca\x17\xa8\x1d\x8d\x11\xc2\xe4j\xbd\xb6\xb7\xb7\xc8\xb4\x0c\xe0\x8c\xb6\xff\x95*Q.\x99 H\xfe.\xdbl\x9a\xb9\x90A\xa8\x1a][\x14\xfci\x1a9\xbd\xd7\xe1>\xbd\xb0\xd63C\xc1\x0b\xc5\xee\x0b\xf5y\x17\x80\xc8\xb32\x9e\xe3C\xcd\xb1\xebg\xbc\xf7t7\x88\x8e\xe4\xf6\xd0\xe8\xc2^gY\xcb\xfe\xd4\xd2[c>O=\xbf\xdb\xc8_\xba2\xdc\xfe_M\xcb\xf5\xf8\xf5\xfeDx\x10\xfcA\x1f1]9\x7f\xdeUU3e_!\xea\xb9\xe9eUs\x93Yzm\xab\x07?\xfa%\x87%\x01h\x8d\x98\x03\xcc^o[\x91\x8f9\'J\x10i;\xf8\x90\xeb8\xab\xffd\xb6\x89\x9b\xc1%\x17j\x08m\xc7\xaa\xb1bq^\xa4\xaa\xc5\xe40> \x05\xf4\x8a\xa6\xab<\xf4F\xb9\xe5j\xc1\x98\x01*\xa6l\x98Z\x98>\xc9\x0f$\xc1~]op:\xd5\xad\xbd/\t/ou\x08\xb50\xfd\xc6\xab\xb3\x8e\xf4\xefs!H$\xa2>E\xc2\xb2\n\xf6HC\x1a\xd7\xba\x9d\xc8\xf7\xfc<Kv\x92\x95j+\x8b\'P\x1b\x8dG\xc7\xce\x1c\x1e\xb4\x9f\xef\x90\x7f\xe1f\xfeW:\xb3\x13g\xbf`\xdc\xde~\xf16\xcb\xec\x0bC\xfc\xb9E\xf9+\x04\xaf\xd98t1\xa8<\xaf\xf9\xc61Q\x9e42\xd7T\x81`i\xd82\x04\xcb\xf9\xb1\x85\x1c\xc3\xc3>\xd7\xce\xb8\x14!\x8d\xd7oQ\xe1\xe5J\xe3\xa9\xf6\x80_\x14\xd8m\xf7\xbbK3j*"\x0bf\x89\x9al\xb6\xa8\xa1h\x8dT\xf5\x8eP\xdd\x05\xb2=\xe1^\xc1\x1d\x94\x80\xd2F\xc4$|\xd6\xe5\x1b\xf7\r2GJ%\xa5\xd3\x11t\xf7{\n\xb4\x9d[\x97\x89h\xcbE\xa3\xc2\xdb\xe9.\x94XrS\xf9\xe7t3\x9f\x866,\xa0\x8f\xa3\x1b\x10\x96\xd2\xb1A\xd2K;H\xc6\xd3\x86@I\xb1o#\xe14nZo\xb7\xc43/\x8d\xae{\x92\xfb\xaa\xac\x0c!W\xdb4\xc8\xe0\xd38=\\$W\x14\x81\xd9X[U/\xa6\xc0\r\xda\xbc\xdb\xc4\xa4\xab9\r\xc3\xdd\x8c\x9c\xab\xff5\n\xe7\xde\xae \x1c[\xe6\xffW\xa5\x89\xf6\x07\xef#"\xe8\xf3c\x0b\x15s\x06\x1c\xddI\x08\xf0\x9b\x99D\xab\x1c:\x81\x8e+\xf2>O4\x10\x84-\xa9\x01\xdb\xb7\xd1\xff\x86\xe9\x1eR=\x01U\xaa|\xb9\x01a3\x82\x07\xa0\xca\xe6\x19\x1d\xe6\xc4\x9d\xb6\x01\xa9\x97xd\xec\xf9\xb1\xe0\xd3\xf4\xfakTy\xfa\xc2\x1b\x82\n7\xf6u\xff??\xbb\xbe7\xc0\xb9\x128\xb4c3\xb2\x1a\xf1\xaa\xc7\xe9G\xe9\xbf\xd1O\xc1K\x8e\x14\xfaz\xd47A\xfc\xad\x03\x1a\xcaU\xb4e\xa4\xa4\xca\xe5\xdf\x19w\xac\x93\xe0@C\x86\xef\xd6\rN\x88\xbc?\x96l\x9ca\x9c\xc8\xada\xa9\xa0\x11\x15\xfb\xab\x9f\xd3q\xab\xde#\x9c\xaa\x0cd(o8\x80e\xe6\x13\xc9\xbe\x0fW\xe8\xce\x87\xd6p\x8d\x82\xed \xd1P\x8c\x0e\xaa\xbb\xfe\xb6\xc5S1\x08\x8a,\xa4\x89\x89\xf2@\xef\x15\x1f\xd4C\x8b\xa3\xb7\x93i\xff\x88\xbfD\xe4\x8a!\xeb\x047e\x93\xf7H4\xd2\xe1\xdb\xc8\xb6j\xeb\x04\xa8B\x1f\x8b\xc56\xde\xc2W\x0bT"\xc7\xd1\x87\xc4\xfe\x0f\x7fV\xe71\xff\x0cR\xb1\xb9Y\x06G\\\xcf\x07\x8a\xe64\x94K\xd4\x842\xce\xc6\x94\xcd`\x9bc\xb6\x85\xa8iu\xb9vu\x12gF\xe7\xc0\x899\xf2;\xb2\x8b>>i{\xe7\x1aFn\xcd\xaaj\x1d\x0f/\xdb"=\x00;\xf3\xd3\x0c\x1b,\xac\xe7\xe1\xdb'
|
|
|
|
|
|
2024-12-14 17:54:47.703256 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7869
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 1258
|
|
chksum = 0x40d4
|
|
###[ Raw ]###
|
|
load = b'\xe9\x00\x00\x00\x01\x00\x08\xea\xa4\xfd\xe9\x04\xea\xaf`D\xd1\x0b^\x8a\xcdu\xe4\xa2\x103\xeb\xd3\xfb\xdaL\xbb\x9cP\xa8!\xff\x18>\xa4F\xb2\x9d\xb6\xbd\xb2\xc2O\x03z"A\x1f@\xde\xa07\xbc\tAm~b\x85\x95\x1a\xfc\xf38{\x8a\x80hdk\xaer\xc5|;\x95\xadn\xf5\xc7\x84\x1cj\xa9Fm\x15\xe7\x1f\x9aa\x853Q\x90)Gd\xcc\xb6r)d9$[\x96\xd4\xe1\xa9\x882\xaft\xc0\xfd\xa83\xf6\xbf\xb9\xf5\\\x05\x08\r\x15x\x96}\x14\xf4\x92\xf0\r#\x05\xd6\x00\x87<\xdf\xd6`S\x85\xd9\x8f~\n\xb5\xc95\xad\x85\xc2\xbduV\xf1\xd9%\x9bF\x95y\xdc\xa9\x98GY\x0cx_]S\xf4m\x03\xfc\xc5A\xd5"\x90k\x9cR\xb1r\x04I\xa6[\xd6aq\x1b\xa0\xc9JKc~\xdbF3)\xefX\xdb\x15\x19\xef.!(\x87\x06%\xd2\x94\x13\xb9\x84\x02\x83\xfa#\xad\xf2\xef\x11\x97IeD\x08%\xb8!c\xb6-x\xa9\xe8/a\xef)\x8a\x94\x1f\xf5\xc1\xfd\xc42W\x80\xf2T\x85&BP\xdc\xe4\xbc\x9dh4E8V\xceG;\x1e\xed\xd2\xbe[\x00\xc7\xec@Zr\xd34\xc0\x1d\xcd}D\xaf\xbf^\xca\xa3\x03K\'8\x196"\x03\xed\x00\x95\x12\xa1\x94\xd2Dh|\xa4\xe6\xd9\x97r\xc5e\x9a\x92a\x87\n\xc6_\xaaca\x19\xacP\x82q\x8d\x01\x1aq/\xb6\xab\xb2\xa4\xf9\x19F\x16jr\xf8-O\x81\xf9*\xbc\xa1Q\x7fd\'k\xd8\x0e\x1d\x08\xef\r\xbe*6\x91\x16\xdb\x15P-\xeeoz\xc7$\xcb\x8c\xadTZ\xc3\x95\x05\x83\x89\x9eWE\xa4le\xbd>D\xf6\xbb\xea\xb8\x10\xe15\xf0\xf8N\xbe\x19\x17\x9a\x9an\r\x91n\x81\xaf\xa3\x8elwy\x15iY\xd4\xf2\xc2\xf0\xcd\x05.\xba\xa2\x15\xf08\x95\xaei\xe3\x1a\xa8\x0e\x8b\x8d;\xf5}\x8dR \xf6\xd0\xc9\x92\xc2e\xa2;iK\xb5cm\x0e\x93\r\xef\x13\xfb-\xc3\xdaI\xb5\xb22|\x9b\x0f\xd1F\xc6\xfc\xce\xd6\xbf\x1e\xaf\x87\x89\t\xb0]\xc8AK\xbb\x93\xac\xca\x16\xd2+y\x12\x8b\xfa\xb8\x96\x7f:\x10\x80qk\x07\xd2\x99^\x1a\xab\xcco\x82\x05\x87\xab\xfce\x14\xca\td)\xdd\x8fyc9I\xfe\x07\t\x96\xd5\xeb\x7f\xb8\xd1\xfb\xb1\x1c\r\xd7\xd2\x0b\x02\xe6\xd1Ev\xda\x84k\xae\xfd]\x8d\x0e\xf6\xeb\xac\xa9\x93\x84\xa6t\'\xce\xc0\x19\xcb\xc7\x0b\tC\xe55\xd6b\n\xc1\x93\xf2\xbcAF"\x90n\x03\xd5\xce\xbc|F&\x9e@\xd67\xfeO\\]\xc6\xab\xcaO\xc1\xf8.G\xaf7\xf6\xcb~\x90\x83\x07-\x82\x85\xdc\xa5\xfdF\xfa0<\x93\xfb\xf3\xcf\x7f\xdb\x81\xef\xef\x7f\x90\xe3\xedV\x11\x00,\x10K\xd6\xd9\xfc\xeb\xf7\xdb\x8e\xdc\xaf\x9d\x06\'h\xa7Z\x07y\x8d\x8dN\xaf\xe1%*\xb3\x06|f,T\xc4\xa2\xc6\xfb9F\x1e\x01_\xe9\x19]\xb9/\xf4\t\x11t`W\xd9\xc2\xd6\xad\xd9\xd2S\xdf\x98\xb4=W\xe0*=\x13=\xa2ly\x10\xa2\x9b\x13\x93\x05%\xbe\xe1\x93v\x86\xa3\xb4\xa1\xc3Us\xf7\xbdoGr\xf6\xad\xd2\xdd\x93\x8a:\xee\xf6\xa5y0\x95$;\xbe\x92`\xdf4\x7f$\x9e\xa67\x81%W\x05(\x9b/\xb4MQ\x00\x80\xd6T\xdb\xe7\xfd\x0eCM\xde\x18P\xe10Hf]\xfbAg\x19\xfcr)h\xde\x84\x9b\xe5\xa0\xaaV\xc1\xd1\x94\xd6\xbf\x94\xca\xf9;\xc3@\x9c\x9f\x8f@\x85\\\x13\x82\x86\x92\xfd\xef\xcb\x1e\xe5\xf1\xba\xf0\xc1\x99\xe2\xc1\xb7\x07\xd3\xb3\x896\xd6>\x1fw\xc2\x10\xfc\x80\x18u\xf9^\x96C\x9a\x11vj\x8dEE"\xa6+2\xb1`\xc9d\x92&2\x13\x10\x98Y\xa5\xc6_\x8a4\xd5\x8dS\xe7)\xbd\xc5\x07\xc6\x19\x05\x08\xdfO\xa1\xa6#\r\xe0@J\x0ep\xd3\xb3|\x93\x89\xe0\x0cI\x94\x15\xb1<\xbeso\xb1S\x9ap\xd4,I\xd8\xebn\xf8E\xcb=.kkx~*EzS=rA\xfa\xeeD\xee=\x9fri`\xf6(\t\xea`\xde\x8f\xb5\xadO\xc9R\xd4\xec\xf2v{\x9e\xd3\x98\xde\x8e\x12\x99^\xfe\xcc7\x9a\xa0=\x9d\x04\x11v\x18O\xeb\x84\x85\xf7\xbb]\x82\x93\x0b\'z\x1e\x94\xf7\xec\xe0\x19\x89q\xbe\xc0l\x8f\x80\x18&\xb9\x14\x80\xf1y.WY\xbe\x19}\xc9\xa6\x8777\xe0\x0b\x01\x9e\xf7\xd8B\x18)\xeb\x0eB\x05I\xdb\xfau[\x05\x19\x7f\x8e\xb2\xf0\xd2\x93\x88f\x04`#\xb2\x1eg\xa3q\n\x1c:\x1c \xf1\x97\xe3\x18\x99\x97\x91)\xf6\xb1~\x98\xd1\xa9i\x83\x9f\x93\x8e\x9b\x96:\x19\xacOxpogW\xa7\xbc\x0eq\xca\x9ep\xae7\xb1l\xf0\xd9"\x17D\xe2>\x9b\xa7\xec\xffh\x8ag\xad\xa4-\xb1.\x95\x1b1\xc1%<\x9a\x16\xa5:\xad\x00\xf5_\xd2F\xef\x88\xac\xad\x92\xe6\xc5\xf5\xf7\xbc\x9d\x0fl\xec\xb1\xc5\xd3R,\xd5\xf9\xd4\xda\xe43\xc2\x86\xdd\xd1~u\xd2_\xd3\xc5\xea@\x1c_\x96z\xc6j9\xf6H\x02\xc8\xf2PmM<\x0c\xcci\\\x01\x949'
|
|
|
|
|
|
2024-12-14 17:54:47.711077 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 532
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7b53
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 512
|
|
chksum = 0x62cf
|
|
###[ Raw ]###
|
|
load = b'\xe3\x00\x00\x00\x01\x00\x08\xea\xa4\xfd\xe9\x04\xea\xaf`A\xa5--o\xea\xdeO\xd4b\x86\xdch\x1b\xca\xda\xb6\x05\x92\x88\xc6\xd5\x022\xd5\xb4$8\xca\xf6_\x05\x8a\xfa\xdc=\xd9\x95\xd4\xb2\xb6\xf7\x80\xe9\xf7Q\xdf\x8b\x13^\xba\xff\xa5U\xff\xfd\xf3@0\x1b\xfe\xd1D3\xa6\xfb\xb6P\xcf\x15\xcb-\xf9\xeb\xb5\x0f\xd7\\2\x91\xbc\xd0\x18\x92c\xe1=\xfd\xa0N\xcb\xfc\xc42\x0c}8\x83\x8eO\xc9}\x9e\xef\xfc\xb3\xb9\xd1\xd6\x19\xc5\xd0\x8e\xb3B\x81\x93\xb4T\x07\xb3\xa7r\xb5\xc2\xd9\xd2p\xc1\xa7\xab\xc5\x9e\xe5\x8d&v\xb1Dt+\x8f\xf5\x90\xab\xc6N\x83H\x92\xa2m\xcb\xe3\x1e~!_\xae-\x93>\xaa\xb1\x8dKYAu\x00\xb9i\xb4\x9bq\xa7\xab\xe6.\x1a\xdc+>=\xf4&\x04.8J\x87\ta\xdb\x0fc\xf7\x1e\xd6\xce/\xa4i\\2Gs\xc1\xe4\xad\xf8\xab\xc1A\x1dH\xb3\xa5,\x83\xdc\xad\xd2\xa5=\xee\x02vf\xa0\xff\x8c\x0b\xca3\xdd\xf3\x9c\x99)E\xd0F\xba\xf9\xb7\x81\x98\xcbC\x8cfF\xc1lup\xb0\xb5.\x0b\xb8\x19\x85\x03\xf7\xcaGzz\x1b\xf2\x12O\x8b\xe1~\xee,\x1e\x17\xe5;,;\xf7\x8f\xb9{\x19-\xc2\x0fd\xbd\xa8q\x1e\xe3\xee\x8f\xdb\xb5\x1cc]\xc8\xfb\xee\xc7|\x07\xa5\x1aj\xfc\xa1r\x9d\xd9\xe6\x9c\xec\xc3L\x98y\xb8\xba\xdeu"\xcf\x8f\xc4\x97,\x15G\x93^\x0f{\x1b\x9e!Z\xc6\\_A\x01\xf2\xee@\xf9\xedO\x047o6\xb4\xe0g^\xaaX\x10\x04^\x0b\xc5\xca&\xb5\xb3+8\x0e\x91\xdd\x15\xd3\x04\xc0\x89\x97\xf1\xe5\\\xaa\x0e:\x8cvg\x1a\x14cA\x1e\x9bcJ\xfdDO\xe9\xcd\x96\xd2\x7f\x04P\xbe\x95:\x87q\xc2\xf2\xe4]\xee\x00\x8cQ\xe9h\x8f\xbd_\xefi\xd0\xc5$o,x\x00\xc9\xbc\xd9\x14b@m\xbbw\xc1\xf8A\xf3\xeb\x94wv\x9d_\xc2\x11\'\x0b\xf5ZA\xe6\xe5\x9bu\xa1\xcf=\xf0\xdc`UV/\xbe\xdd\x12m\xce\x1c]|'
|
|
|
|
|
|
2024-12-14 17:54:47.715099 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7e23
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 48
|
|
chksum = 0x836b
|
|
###[ Raw ]###
|
|
load = b'\xcd\x00\x00\x00\x01\x00\x08\xe5\xa6\xeb\x0f\xbbm\xbf\xd6\x00@\x16q\xcah\x87y\xa9\xf0;\x91-C\xdc\x0e\x0c\xda\x93\xea_\x07\xb9\xb93'
|
|
|
|
|
|
2024-12-14 17:54:47.721131 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7969
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 1258
|
|
chksum = 0x1c72
|
|
###[ Raw ]###
|
|
load = b'\xc6\x00\x00\x00\x01\x00\x08\xe5\xa6\xeb\x0f\xbbm\xbf\xd6\x00D\xd0\xeaao<M\x1a\xeb\xe6\x8d\x91\xeb\xb8\xa4\\L\xe0\x17\xa8A\xff\xde\xe3\x11|Q\xf8p\n\x1d\x16\xad\xe2T\x1c\x8f\x953\xeeh\xb2\xe0\x1fs\x00\x83\x9e\\\xe5\x93\xb7\xb7p\x8b\xf3._\xe1MF\xc4\xdb\xe7\xae\xd9\x16\xf2\x1bF\x0c\x86]\x04w\xaaCV\xeb\xecM?\xc0|CF2\x04\x14Q9\xb6N"S\x9b\xb9\x03i\xb0\xc8\xbc=\xfbv\xbbT\rNs\xe6\x03cP\xa2\xc3T\xf3V\x97\xc8]\xa4@\x89\xcf\x0f\xec\xc0\x8a*\xdb\xf6\x97\x9a\x19\xdb6V\xc0\xa69\x8fW\xa9O\xe8\xe8\xa6\xff\xcd\xd7\x81\xb3\xbev\xbb\xcb\x04\xb5vG\xe9\xae\x08* \x01\xcf\xb3qj\xf6\xfd)-\xee\xf2*\xdf\x0fru\x8e\xc4\xfat\x0f\xeb\x9d\xbb\xa1\xe01\xfdp\xd9\xdd\xeab5\x04h\xd3(\x99+\xc2\r\x01`\x190\xb5\x1c\xf5m\x0f\xeb\xda\xa14\x0b\\8f\x1f\xc8\xe9\xd4LE?$\xbch\xfa\xe2\xa2\xfdXv\xd6\xa2\x89KV>\x89L\x11\x03\xda\x0f\x19M\xedF\x99\xab\x15\xed\x1f\xac\xbf\x16l\xf1\x94L\xa4\xb1\xbf\xbf\xde;\x93t\x91#\xaf\t\xeb\xd4\xb1\xc52\xd2\x80`I!6\xb8B\x03M\xba\xd4\xd8u\x04\xbce}8\xee\xe7\x04\xe4\x9d\xa0SZ3p\x08\xc6F?N\xfah\xd8yM\x14\xcf#\x88YO\xf3>\x80\x01\xf5\xfd\xc5\xd8\xc5\x8b\xb8\x9c?m\x8c\xdd\x089\xf4\xa7\xe9\x1c&\xda\x94\rp\x03\xb4$L\x0b%\x02\x19\x97/6\xde!\xb2\xca_\x10-\x9bz\xf7\xa8j\x8cy\xbd\xc9\x91\xcb\x8c\x1d\xb1\xca)LF\x83-\x87\xfcv/\xfd\xda0\xdb\r\xc2 \xaa\xc3|\xc4\xc7\xaeK\xe2\x7f\xac\xdc\x83\xb8s\xec|\xf8\xa1\xda\xcf\xd2,\xf2\x83/FI1\xa3\xc2\x93\xab\xbe}\xfc\x1a +\x01S\xa0I\x00\x91B\x1e\x9b\x16DT\xf8\xc9\xb3\x82\x99T\xba\x95\xb9\x97j\x05BN\xfcn\xe6F\x9c?n \xa6\xa8\xbb\x82\x17\x8c\xf3\x812\xe2\x12\xd2\x1b\x86\xb9P\x12\x06\xd2 \x95\xf6w\x1aOh\x98\xfeA?\xf0?\xab7,\x90rQ(\xbe\xdfp\xa8z\xecCy\x84\xcd\xc2\'\xff\xeb"n<\x9d\x04\xe0\x13)\xcd\n\x05\xdfE3X\xcd\xa6\x90\xa9\xfe\x0e\xb8\x83/\x94\xe00E\xbfh\xbc\x8b3\xab\xe9\xe5\xddP]*\x00%\xc8\x0e\x0eo\x07\xa9JO\x86\xaf\xcc\xed\xe4\x193.?|k,p\x1d\x13\x98\xbd$kT\xfc\x8d\xc2q\x84\x9e\x15\xa5O\x94\x93\xfcVd\xab\x8b\x1f9X<\x08\x18r\xe7j\xea\xa2\xaf\x99L\xe8\xaeU\xd3r\xc22\xeb\xcc\x0bd\xb0w\x03\x85\x8fG\x03(O\xef#^v\x00\x82\xa1*\xbds\xa5C\x02\xf4m\x06\xf7\xce3\xb9\xe8-Z9|>|\xd0\x93\xdd\xd8\xe1\xa9l{V\x9a\xb3\xf3\xf9W\x91\x9e\xdb\xfeE_\xd2\xc4c\x803\xdf\xa0>_=\xa7\xc7\x1f\xf5\xa6)5\xa4\xa8$\xc6!#.\x17\x9a\xd9\x87L\xbb\xcf\xe8fb\x93\xc7\xec\xc8\xf6\xd8\x99\xc9R-\xcf\xe3\x86$\xd5\x9f\xda\xcck\xa2\xbc\xceMu\xeeU\x82\xc6>\x94\xef\xd9B+"F&\xfe\x8b\xcd\x1c$\x12\xa8;\n\x9eD\xc2nE\xd0",,w\xf9\xa1{8\xd34\x96\x84k\x04\xd7\x8eb\x01\x99\x16\xf5\x8cmR\x0e\x81\x8bvk-\x1f1@\x10\xd6\xf4\xc1\xfcW@\xe0\xdf\xd1A\xd2uG|;\n@\xd2\xb05\xe9\x00\xae\xd9\xa4S\x80@)M\xa9\x9c\x00\xc3\xfdD~\xe8\xde\xff\x9ax<~\x8c;\xba1}\x88\x8a\xd3\xd0S\xe6\x1d\xd0\xc0\xa6\x98\x83\xd1.}\n=\xf2|0\x12{\xbb!\x1f\xb7\x1b\x9a\xea\x85P\x94\x01F,\xd1\xb5\xe5\xd7\x0bh\xbe\x91j\xb2q,Y\xcc\x95.n\x99\x81\xceK\x0c\xc5\x81\xb52\x12\xdc\xb2\xee\x99\xf2\xc5Y\xc6[\xbd\x98\x11\xfdz\xcbye\xf0\x16\x11\x01\xac)Q>l\xa4>\x00\xf7\xc7g\t\xa4h\x8f\xd5Y\x10\xef^\xe5\xa7\xe9YR\xa0\xe0B+\xaf\x94$ ]MSb\xb6w\x11\xb7a5\x0cb~\xe1\x87DL\x07\x1fX\xe4*\x01\x07\x8f\x86\x07A8\x15\x95"\xdbk\x93\xef$\xdd\x16\xb7\x0b,\xa7]\x7fe^\xe2\x10l\xac\'=7;\xb3\xee}UA\x90\x18\x11\x01\\\x0c}!L\xb38e\xa3\x1e\xba!\xfa\xcd\x1ed\xe0{\xf1\x9d\xce\xb4x\xe3n\x04.\r\x81\xf7\xb8NP7IO$G\xca\x1e~B\xd0\xb2\xabg;\xf8\x06i\xfe\xcc\x9f\xe5\xff\x1c~\xcb\xcaP\t\xbc\xd5\xe2\xf8\x064\xa1\xa2\xbf\x80\xe9\xfb\x02\x83Z\xb2\x01\x04~\xa5^\x91\xc9\x94\x97/\x98\xfeQ\xfd`\xac\xefB\xac*\x85\x16\x0f\x8b\xec\xa5\x17b\xf0\xdbo\xa2\n\x9a>\xbe#y\x170v\x8c\x8eY\x0eo\x8c\xa5\xb6\x8b\xfd\xa0g\xaa\x1a\x1b\xe2Q\xa2\x1b\xce\xd2\xcb\xa1P*.\xbe\xd0\x8b\xaexI\x9c`\xdc\xdf]\xe1\x06\x8dS\xfe\xad\x86f\xf9MEM\xe6\xf0X_X\x83\xdb>\xd6E%\xf8m\xe3\xc6\xaaO\t'
|
|
|
|
|
|
2024-12-14 17:54:47.727029 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 67
|
|
id = 30887
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 47
|
|
chksum = 0xc5c6
|
|
###[ Raw ]###
|
|
load = b'\xea\x00\x00\x00\x01\x08\xea\xa4\xfd\xe9\x04\xea\xaf`\x00@\x16\xf6\xbbCz\x9f\xbe\r\xe7\xa1s\xdacm\xc4\x8d\xe2F\xe5\xc0\x881\xfb'
|
|
|
|
|
|
2024-12-14 17:54:47.730340 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 30888
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 48
|
|
chksum = 0xc5c7
|
|
###[ Raw ]###
|
|
load = b'\xea\x00\x00\x00\x01\x08\xea\xa4\xfd\xe9\x04\xea\xaf`\x00@\x17q\x8e\x9f7\xf9\xa9UY\xa9?WeF\xc0\x9ft\xfc\x13?\xf8\xdf\x84*'
|
|
|
|
|
|
2024-12-14 17:54:47.737757 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7969
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 1258
|
|
chksum = 0xdb54
|
|
###[ Raw ]###
|
|
load = b'\xc8\x00\x00\x00\x01\x00\x08\xe5\xa6\xeb\x0f\xbbm\xbf\xd6\x00C\x98&\x7f\x8a;\xb8\xdd\xf4\xc4\x8c\x01;\xc8(C\xbd\xbds\xf4\xbf\xcaT\xa8\x1bH\xa6(!\xc5L{\x92\xcea\xf7A\xd2\xf9\xbf\xb8\x8f \x1b\\n\xfc\x02o\xff&SF\xba2&\xc7\x7f=e\x1f\xee\xe6\xe2[\x8d\x1d\xb1=\xc6EI\xf4\xa4\xfb\x04\x02x\x11\xb6k\nq\x0e\x97\xcd#)<\xa9>\x92V\xb1G\x0b\x86\xe8Y\xa2\x1f\x1d:\xb2a\xd8\xc5\x8deh(|\xc3\xae8\xdd\x9e\xddtE\xddz\'\x1c\x05n\xf0\xed\x1f\xd7\xb1\xaa\x00\xa8\x06\x8b/ckATS\x10\xd5\xd4_\x1e6~6\xc2\xc6\xed\xd6b,\xaer=8\xcf3\x00eP,\xb2I\xda\xa8\x9a\xf5\\\x117\xf5;\xacL\xe3\xb7\xb3%d\xf7\xb1\xb9\xa9\x1c\xa3!\xb3\xb2\xba\xf7\xa6u\xd3n:\t\xe9~\xf9\xd6F\x90\x9c\x02K+F\xd0\x00\xb7\xc5\xe6\xe0\xa1\x90\xf4{-\x04\xdc\xf3gQ\xc3\xba\x14\xff\xf0\xef\xb6\x13\x98P\xa2\x89\x9b \xbd\x18\xb1\xed\xfdP\x192\xba\xa3\xcb0 \xec\xc3\xff\xa4\xdf\xad\x19\xae\xd2Qm\x10C\xd5\xb8\x08\t\xa1\xbb\xaeL\x90~\xf4V\x9b\x8d\xc2\x9cv\x8c\x03\xac\xbf\xaa\xa9UC\x0e\x906\x81\x9b\xc3+X\xa7\xf0d\x9a\x8eu\xd7{\xc9\x07\xb8\xc7\x1d\xe6\x08\xd0\xaaY\xf9\x8b\x03\xef\xa0\xb7?\x94\xb81\rM\xb4U>\xfa\x9d\xab-\xf4(\xfe\x03\x98:]9y]\xae\xcc\xb8&8\x86\xaf_>\x89\x18\x83\x93\xd65>\x1c\x12\xdcg\x86X\xc0,37\xdbz\x82\xf4\xbe\xd3}V\x03\xac\xc8\xea!\x1b\xc2\x08\xe7\xb6\x0f\x98\x83\xf3\xfd\xf8\xe2\xac\x174\xa5A\xba\x96\x1b\xea\x0f\xdb\xefl\x96\x8b\x8cJ\xa5z/ue\xa0Y}@\xe9\xbc\x10\x98\x9c\x9fO\x16\xec\xd3d\xa8,\r*\xac4\xe2\x08;\x84\x1bP{\xf1\xef\x84a\xafUM\xdc-\x82j\x1e\xa82\xf9\x1d1\x98\xa9\x02\xeaE\xd7\x82\x128sFA,\x97\xea\x96\x10?$\xff\x18\x05\xbd\x087&:u\x0f\xbf\x12\x1e\xef\x1d\x10\xee\x84=\x16\xd4\xf1\xa8\x0cU3\xd4\xf9\xe4\x91\xb6\xef\xeb\'6P>>\xbf9_{.K\xd7n":\x04\xfdJ\xe0\x93G:>\x1d\xd0\x94J\xa2.\x1aX\xb0\xc5\x14hQp\x13\xd2\x94$\x95\xb7\x98\xce~\xd8\xf4\x92\x99\xa3\xaaA\xce\xd5;\x0b\'\xb0\xabp\xd0\xca<\xe6\xf9\xe2h.\xa8p\xcb\x10E\x90>\t2W\xdc\xce\xb5\xd9%\xd5\xb9\x83T{\xef\xa8\xcf\xa6\x1ex\x1e \x0f\xa5Ms\x9f&\x1aJ\xc9\x87c\xe7\\\xbb"\x95\xd7\x94\xcb;:s\xe1\xb2\xdc\x19\xe6I\x99\xd0J\xf7\xbb\xac\xa0\xbd?\xc0.\xae\xa6O\xab\x82\xe6\xcc\xa2u\xf6\x9c\xb3\x1c\xfc<\x02\xaf\x9a\xb2\x12i\xbbPf\x99\xfb\x88V:mho\xea\x81h\xfa\x02\x9a\x07\x9fX\xb9\x0f\\\x06Y\x8a\xac\xac \x1e\x06\x15\xb9D\xbb\xc2\x92\xda\xf0\xe8\x9f\xc0\x91L\xa0h\xaa\xfd\x13\x8a0l\xf7RY\x05\xfen\xd0\xd1\x9c\x8eS\x1dz\x86\xf1!\xcc\x07QR\x00\xda2_\xdc\xa3\xf4\x99\x96j,\xc8\x012\xe1\xbf\x0ff\x91~\xc0\\\x10\x92\x14\xe7\xe7U%\xf6\x0c\xe6\x0c4el\x0ex\xef\xe5t&\x04\xbc)%_\xfb\x85\xdew\x16?*\xd5F\xb2\xa8\xde\xb5\x9c\x1b\xe2\xb8\xac\x1fg\x81\xde\x07`\xdb\xff\xf2v\xb0\\\x98\xc2R\xd1\xe9}a\xd8#\x8d 3\x10\x89`ZS\x0b\xe4\xa2"/\xd3\x9c\xe8\x8d\x8bp!HieQ +)\x12F\x8f\xa1 U\xbd\t\xc0o\xad\xc1\x16\x9d\xe5\x8beDM\x1e\xa1\x0fl\xff\xbb\xbdy\xb6M\xaep\xf6\x8e\xe8\xba\x93\x8b\x03\xdeYN\xbb0\xf7h\xbf\xf4\xf1\xd5qt#\x03\x90z[\x12\x0cxH\xbf\x1f\xe6\x00\x00\x00\x01\x00\x08\xe5\xa6\xeb\x0f\xbbm\xbf\xd6@\xe4\xde\xd4\xacdJ\x129/T\x99g\xe9\x05\xfc#\x8b\xbaa\tp\xba\xc9\xf2\x96\x89\x80\xb5fq\x07\xbe\r\x15\xb7\xeaUl\x99\xd0j\xa9h\x1f\x9c\',q N\xd2$\xffGw\xda\x14\x11\xa23\xa8D\xdc\xd1\x1d\x95D\x05\xfc+c\xcbi\xbc\xd2\xcd\x06\xc6n(\x87\x94\xf2H\x16\xe7\x82\x06\xf9\xe3\r\x15\xae2I\x97\xca\x8a\xb7\xc6EF\xb8\xac\xb5\xef\xf0\xcfI~\xaa\x10Q\'A\xeb]S\xcen\xb1\xe3\x97\x8c\x1c\x15^\x8a\xf8\xf4!\x11}a\x18:y\x13RB\x16\x19\xab3\x1b\xe5\xc5\xcd\xeby\x13\xddh\xf5A\xfai\xe8\xaf&\x83Q\xf8C\xa9\x84^\xe5\x1dp\x1a \xffbN\x90\x006c\xceU>\xe3\xa3\x8d\x02\xe8\xefTI\x9e\x16\xfa\xbf\xb8\xc8\xdb\xd1\xe1\x81\xf5\x10*$\xca3\xf7\x85\x1b|+l\x08l\xd9\xb6\x8c\xc2\x8a5v\xfd\xffQ\xc4\xf6$\x8d\x01J\xcc6\x95\x88\r\xb6\xb2l\xbd2\x8b\x9b\xd7\xe4\xcfHA\xe5P\xf0\xealJn\r&\xd9\xbd\xb3m~=\x958\xab\xa0\xbf\x8ei6\xea\xd6\x017\xcd\x9a1\x8a\xcd\x96\xbe\xc5\x9aBc\x10\x1f\xb0\xe6\x9aL\x82C\x87"\x1f'
|
|
|
|
|
|
2024-12-14 17:54:47.745584 - Ether / IP / UDP 192.168.1.11:63056 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 194
|
|
id = 30889
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63056
|
|
dport = https
|
|
len = 174
|
|
chksum = 0xc645
|
|
###[ Raw ]###
|
|
load = b'\xe3\x00\x00\x00\x01\x08\xe5\xa6\xeb\x0f\xbbm\xbf\xd6\x00@H\x08J\xde"f\x1f\x05\xed\xb4\xb6\x8a >\x1e\x97\x95\'\xafPB\x8e\x97\x99\xbc\xe9+{\xdaI\xa9\x08\xd4G\xdd\xba6A\x18 \xc2v\xc7^\xf2\xa0\x93\xb2c\x89;\xc8\xa7\n\x0e=\xbb\x8fQg\xc0\xf2\x04\xa5\x83\xfd\xf4\xc6gl\x18\\\x91I\xe5\xa6\xeb\x0f\xbbm\xbf\xd6A\xa7\xc4\xe0\x81z\t\x9b\xd2>\x7f&\xdfL\xc2z\xfem\xb1\xe5Y\'\x1bF\xeb_\xc2\xb2\xe5!\xea\xa38\xcfx\xe7\xd3\xb3x\xa3\xef\x13\x86RH\xf2K\xde\\\xc16\xa8\xa8\xc4\x8e\x95:\xd2\xe2L\xad\x19\xb9P\xd0\x88\x11\xd9'
|
|
|
|
|
|
2024-12-14 17:54:47.751300 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 65
|
|
id = 30890
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 45
|
|
chksum = 0xc5c4
|
|
###[ Raw ]###
|
|
load = b'\xe6\x00\x00\x00\x01\x08\xea\xa4\xfd\xe9\x04\xea\xaf`\x00@\x14\xc5\x81ht\x10\xabjV\xec=)\xdanv\xca\x1dY\x8f\xe8\xe6'
|
|
|
|
|
|
2024-12-14 17:54:47.755968 - Ether / IP / TCP 192.168.1.11:40846 > 35.186.224.24:https S
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 30891
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40846
|
|
dport = https
|
|
seq = 3398705404
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 64240
|
|
chksum = 0xc5ac
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 17:54:47.764163 - Ether / IP / UDP 192.168.1.11:63056 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 483
|
|
id = 30892
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63056
|
|
dport = https
|
|
len = 463
|
|
chksum = 0xc766
|
|
###[ Raw ]###
|
|
load = b'\\\xe5\xa6\xeb\x0f\xbbm\xbf\xd6\xaa"\xd1\xf2\xe7G\x0cbW\xebv\x08\x91}\xfc\x04\xeb^)\xf5\xec\xbf<\xa0\xa6\n\xb3\xee\x80\x98xu\xac\x04\x06\xa8\xaf\xc6\xe5N\xd7\xcb\xa2\x96p\x13\xe4\x85\x0f\x95\xd0\xa6\xf8\x18:a\xb1\x8e\xe3\xa5\x00\xaa\xed\xb2\xe40\x19\xe8E|\xf1\x8d\xce&\x017\xa1\xccY\x1a\x85\xa5R\xad\xeeF\xa0\xb9?$\xaf/\x1f\xfb\x9b\x82\xfd\x89T\x95w}\xae\x9f\x14\xbeV\x9e\xc8[\xe0\x91\'\x84QU?\xc9\xbf\xe4\xea\xebmR\xa3;\xc9\xc3\xdb\xf4\rr/\xb7r)x<\x99\xa2\x1f\xe9\xe0\x95\x1b5g\xa1i@t\xc3\xd1T\xd2J\xd1\xf8k\x06\x97\x03\x7fK\xd5\xcd<\xa5\x11\xbd\xd1\xe1V]v8B\xcf\xe3H\x85TH\x01\xc2\'o\xdch\xb7\x9a\x8f\x90t\t\x13W\xa2\xb8\xd6q\xbe\xf1\xa2\x87\x83\xc6J\x9d\xc8\x1e\x99\xe7O\x95\xf4\x1f\xf7IK\x0c\xaf\t\x94\xafp\xc6\xc8Z8>*{*\xa4N\x8f\xdf\xa8/\x80lT\xe7n\xe4\x16\xb3T\x18G\x1fV\x87\x90\xcf+n\xbc\xf5y\x84\xc2\xa6m\x86\x03\x7f\x8a\xb1\xce\x88\x18Y\xdf"bo\x18\xfd\xb4\xa9\xc8W}x\x9e\x83A\x80\xe9\x8b\xfc\x94E\'=\xfarH\xf8W\xa7\xc6\x0e\xa5\x0f\xaff\x0c\xab\x9bGK~)\xbb\xa8\xba\xe4\x83(\xbdr\xce\nh\x11\x85\xd1\xf203\xa5[Q(9$\x13\xb3t\'+\x9e\x88\xbb\x00\x13D\xea\x98 \xd8S\xb7\'\xcelC\xd0\xbcde\xe1R\xc7h\x91\x17qeH1p[B\x17h\x9d5C\x18J\xc1>\xeb^_x\x14\xb2\x87\x97\xaa\xbe\xf6\x9a\x9c\xe6\x98\x93p\x80.\xfc\xc4\xdc\x9d\xee\xc2e\x17\x15\xfcN\x07\xd7K\x8a\xfaa\x8b\xfa\x0c\xa2\xd5\ti\x15\xf6\xc2\x1eu\x13A\xc4:{\xc5I\xc6\x99\xac\x8c\xec'
|
|
|
|
|
|
2024-12-14 17:54:47.771887 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 612
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7c03
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 592
|
|
chksum = 0x4e3c
|
|
###[ Raw ]###
|
|
load = b'J\xedy\xe5b\x83\x1d\x97\xfaT\xf7\xbc\xacb:\xd6\xb2&\\\xae\x08\xc6\xee2\x1b\xc9\x8e\x19\xd3C\xfa\xfc\x1a\xe1\xba\x13\\\xc35\x12\x87\x11\x8aJ\x1b\x07\x9dt\xef\x9d\xf8\xd6wt\xb0\xa8K\xb22\xd0\x01\xfalu\xd7\x07\x82\xd3~\xef\xcf\x04\xea)\x1cJ\xe3Lu\xeb=\xb5\xf1\x86io\x04d^\xcd\x85\x98\x8c\xa2\xe4\xed\x98\xd9oi\x0f\xe7\xe3\xf4$\xff\x03"\xb5\xa0\xc8\xa7\xf7\xee\xa1B\xa2\xaf"\x13c\x86\xe7}\\\xb8\xb3\xf1\x84H\xe3\xd2\xbaO\xefk\xe7S\xa9\x90Wf\xa5lrM\x12\xc6\x90\x8a\xcf\'\x1e\x10\x8f\x902\xca\xf8\xadL\xa5qS\xd4"\x1cU\xcf+\x89uWD\xc47\xbe\xc9\xcd\x9b\xf4\x1f\xdfG\x01\xa1\x0b\x02\x9e} \xc4\xc1\x14\xa0\xb0\x19\x8f%\x8b\x8e\\9\xa8\xc54]k\xf95\xb8\x7f\xd9r\x02r\x97\xf2\xc7\xc7\x16\x16\x1d\xf7}\x8e\xbb\x1a\x9a\x8d\x0c\xa8\xaf\x8a\x8a->\x88\xd5]\xcb\xff$|\xc0\x8d\xfa\xc7\x07\x8d\x17b\x8bf\x98\xeb\xf0\x88-O\xb3\x0c&_\x02\xaa\xd4\x86f\x1fNm\x89\xff\xce#\xea\x83\xe1\xef\xf2p\x98J3\xad\x88\xfe{\xb1#\x12\xf0\xee\xe7gP\xc6\x89|\x9c \xd6\xd9a?m3_FU\xfb\xda\x1b\x08\x9d\x11=\x0c5\xcaS\xb1\xc69\x92Q\xf9"\nz9\xb9\xf3\xbbsK;\xab\x8eC\x7f{\x80D\xb2l\xd7\x96\xca\xe6\xd7\x1e&\xecS\xdc{1G2\x8f\xa7r\xef\x81\xaa*\xa1\xf0\x9d\xef&\xc8\t2\xa1O\x9e\rF\xebl\xcb\x11j\xd4w\xaf\xbajH>T\x19\xee\xd9\x00\xb5\xf1\xe3\xb7\x10\xac\xda\xd5\xfa\x1fJ\x17\x1f\xab\xa2\xbc\xdepBMq5\x19<\xfa\xc4\xfc\xe1\xb2\xba\x9a\xa3\x8f\xa1\xeef\xa2\x824\r\x16\x9b\x17\xc9>5P\t\xd1\xbc\x11\xf6\x1a\xe67Ki\xe3\xa7>\xcaQ\xff\xcai\x89\xb0p\x9fcn\xef\xf6\x15\xffX\xac\x8b?\x1c\x97r<\xcc\x06F\xe7U\xb5]^\xd2\xf7@a\xd4\xf9\x9a\xa2\xce\xc8M~\xf2\xac\xf4\x12lg\xceQ\xf3\x07t\xf2\\\xb8%wv=\xfeMR\xce\xdd\xf3\xed\x00*\xcb\x98\x8d\xa3\xcdC&\x01P\x1a\xf9X>\x81\xceV\xf3>\x9f\x1c\x0ej\xaf\x88\xc1\x18\x0c\x8a}W~%\xc1\x04\xcb&\xb3\x93\xe3\xeb\xd1\xd2\xa0\x13\xe4\xb8\xfb\xff\xed._P"*\xb7M'
|
|
|
|
|
|
2024-12-14 17:54:47.776096 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 149
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7dd2
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 129
|
|
chksum = 0x9887
|
|
###[ Raw ]###
|
|
load = b'Q\x7fC\xdeW\x19\xb9\xdd\xba\xb2\xb9t\x8e]\x91dI\xc4:\xdc\x81O\xa9\x93\xe4\x1b\xc3\x92\x915[\xb8\x01\xb1"\xde4e\x10\x9a\xc5\xf4\x06\xacH\xd2\xa0w\x1a\xebZ\xae\x85\x06aI\xa0\x15\x0f\xc1\xbf8\xa6\xcc\\\xb7\xc2\x17P\xcc\x95\x13\x0c\x8ff\x99&\xadP\xe1\x17q0-\xdf\xcb\x80\xb4\xd4A\xebll\x0edg\x7f\x89\xde\xd2B[r\xf7e\x05jY\xc76\xe0\xb9\xf4\'D\xd7@o\xa6\x1e\xc7'
|
|
|
|
|
|
2024-12-14 17:54:47.780019 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 69
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d22
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 49
|
|
chksum = 0x4346
|
|
###[ Raw ]###
|
|
load = b'\xef\x00\x00\x00\x01\x00\x08\xea\xa4\xfd\xe9\x04\xea\xaf`@\x18\xd1\xf8\xc9\x83\x89Po\x03DS\x14\xc0\x0fr\xd2\xbdh\\\xb9)\xf1\xfe<\x7f'
|
|
|
|
|
|
2024-12-14 17:54:47.783242 - Ether / IP / UDP 192.168.1.11:63056 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 59
|
|
id = 30893
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63056
|
|
dport = https
|
|
len = 39
|
|
chksum = 0xc5be
|
|
###[ Raw ]###
|
|
load = b'H\xe5\xa6\xeb\x0f\xbbm\xbf\xd6\x1d\xbd\x1e\x98c\xc2\xbb\xb8\x01\x84\xd3\xec\xb5\xfdF\xd9>\xdd\xd6\xbb\x956'
|
|
|
|
|
|
2024-12-14 17:54:47.786508 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 55
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7e30
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 35
|
|
chksum = 0x51e8
|
|
###[ Raw ]###
|
|
load = b"I\xb5\x04W\x81\x81'q\x1b\xee\xa0P\xb1\xef\xf2\xed\x10s\x85\xaev\xa0\xcfP\xd6\xfe\xe5"
|
|
|
|
|
|
2024-12-14 17:54:47.788480 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25547
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299533841
|
|
ack = 3808769646
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:47.790590 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40846 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x3e3e
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40846
|
|
seq = 4001694221
|
|
ack = 3398705405
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 65535
|
|
chksum = 0x2c3c
|
|
urgptr = 0
|
|
options = [('MSS', 1412), ('NOP', None), ('NOP', None), ('SAckOK', b''), ('NOP', None), ('WScale', 8)]
|
|
|
|
|
|
2024-12-14 17:54:47.792820 - Ether / IP / TCP 192.168.1.11:40846 > 35.186.224.24:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 30894
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40846
|
|
dport = https
|
|
seq = 3398705405
|
|
ack = 4001694222
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xc5a0
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:47.798153 - Ether / IP / TCP 192.168.1.11:40846 > 35.186.224.24:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 30895
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40846
|
|
dport = https
|
|
seq = 3398705405
|
|
ack = 4001694222
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xcb24
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x01\x06\xe0\x01\x00\x06\xdc\x03\x03\xceNW\xf6x\x839[\xca\x01\xf7\xcc\xc3 )\x18*\xeaFz"A\x13\x92\x93+&\x8e<\x87\xb9^ o3\x84\xa74Mv\x97\x1eZ\x90V\xd2%\x1crBn\xd39\x18\xefk\xa7J\xec\xc9"\x90\xd4"\xcd\x00 zz\x13\x01\x13\x02\x13\x03\xc0+\xc0/\xc0,\xc00\xcc\xa9\xcc\xa8\xc0\x13\xc0\x14\x00\x9c\x00\x9d\x00/\x005\x01\x00\x06s\xfa\xfa\x00\x00\x00\x17\x00\x00\x00\x00\x00\x1c\x00\x1a\x00\x00\x17api-partner.spotify.com\x00#\x00\x00\x00+\x00\x07\x06JJ\x03\x04\x03\x03\x00\x05\x00\x05\x01\x00\x00\x00\x00\x00\r\x00\x12\x00\x10\x04\x03\x08\x04\x04\x01\x05\x03\x08\x05\x05\x01\x08\x06\x06\x01\xff\x01\x00\x01\x00\x00\x10\x00\x0e\x00\x0c\x02h2\x08http/1.1\x00\x12\x00\x00\x003\x04\xef\x04\xed::\x00\x01\x00c\x99\x04\xc0y\xd5\xf4\x8c,ijV\xba\xf7G\x83\xe7\xdc\xccq9m\x1e\xc9~\xc9?\x87\x1fH\xb1/\xd5\xe0nX\\\xa7\xa4gr\x8e\xe2d\x89LD\x85:\xe0\x08/\x08\x9bp(V[\xe3\x8e\x95\xb8o\x9f&\xceo\xbb,t\xe0\x1e\xcc\xc9\x06\x89\x91;\xdd\xd0\x1d\x19\xf8\r\xa5\xb6\x9a\xb0)y\x01[U]r\x80J\tp\xff\xd8T\x98`\xa2Y\x84\xa6.X\x90\r\xe8\xa0?{\x04@47\xcf\x04T\xb0i\xa4hq~Q\x9b\xc1Zy\xb7\xd7:;l\xba\x91\x1fD`\xe4*\xa7\xefD\xb6|\x9196\x82v\xdf<C\xbdf\x8d\x9aB\x99\xf9,\x9b\x02\x88\x8d\x05XWt\x1b\xce\xd0#\x9f\xb0e\x80\xf5\xc5d\x01\xcb"\xb2\xd7)\xd0\xa6\x80\x82\xa1.\x90\x14!E\xf5\x8e\x11\x03tW0\x9d\x1b\xba\x9b\xf0\x12T\xd9 /\xa2\xd3\x81 \xfal\xd2\xbbJ\';\x82\xbcw\xa2\x0b\x97\xa6]\xda2\xae\xbcA\x1b\x12-^g\xc8\xb6U\xb67\xd7V\xc2b\xc1\x1e\xa4B\xa2\xe2\xce\x18B\xac\xbe\x91BO:n\xa7\xf5>\xc5\x9a\x1b\xf74\xa93\x0c!\\\xb2g\x15\x80\xa8\xfaCO\x8c\xd7\x0f\xbe\x02p\x03\xb9,\xd7\xaa~v\xc1>%\xf5/\xc1\x9b\xa3b\xd4\\\xba\xf8.%)\\w\xe1#_\xb0\xcdK`\x0f\xe6\x8c\xa0\xcf\x10\xb3\xfc F\x12\x91\x1fW\x03\x7f<C\x01\x7f\x1bXgV\x17\x8c\x93\xcc\x0e\xb5/\x8e+>`\x12\x93\x0fzW\xc7v\x8e\xf8\xd43\xdb{r`\x02\xc0p\xf1\x8en\xf6u\xc1Fx\xfb\xdcV\xaa\x0c\xc0\xdb!\x13\x02\xd3\xbbA\xb4d\x1e\xd1o\xb7S\x9a\x91\x9bN\xce{\xbe\xc5\xd7\xa4ia\xc7\xda,j\x87\x84\xc2\xf4W\x03D\x89Go\xecy,\xe6\xc7\xc9d\x00\xccI8)d\xb7\xd5\xa8<\xda(\xc1;\x14\x1d"2\t%\x1c%\x826)\xc9\x02u\xda\xb46Dy\xb8\xe2\xd1f\xe1\x93i\x06\xaa#\xe4\x04\x8f\x86W^j\xe4\x89\xccW\xc7\xd78_+\xa2?\x9d\xa5x\x9a\x9cE\n\xe6\x05t\xe4\xad!\xcc\x7f\xf9\xd7\x9fZ\xb9\xa8\xaf\xb8\x18@\xb4\x8clY\x95\xc1\xf1\xac\xe2\xd6\xae\x9f\xc2\xc3H\xc1<F"\xcd\xd5\xf64p:y\xb4V\x9b\te\x9aU7\xc6\x13PX~\xf9;"Xn\x07\xc9\xaf\x90$B[\xf2\x96\xb5Z\x89\xfd\x18*\x84\x999\xaaf\x8by\xb0`\xbd\xf1\x81C2z\x1fda\xbc\x93\x0f.\x93.\xdd)M\xa4\xd2{\xb5,\x97\x9d\xb9u\xaaa\xc1O\xc9%\x92\xe4-#\xc7\xa0\x9d\x19\xbf[\x85\xb10#\xb1Wj\xadr;A\xd6\x95\x92; p\xda\xc1\xb3\x95|1\xaf\x82A\xfa\x82\xcd\x00\xe8\x1e\r\x9a\x9b\x8b\x05\xcb\xb1a\x03od\'\x9b\x04\x9e\x01\x11\x1f}\x10\x03\x1b\xf9\xc8\x07\x1a{\x9f\xc8\xc2pXrd\'\t\x9edz2\x9af\x9a\x02\xae\x1f\xec\x04\xf4L\\\xde\xc1\xaf/c\x0f\xb1\xf5\x1c$\x01t\xb5\x0cG\x8f\xb9\xcd\xd0T\xab\xdc\xa4/lg\x84\x84A\x02\x0b\x04\xb0\x89\x01\x15\x160O+\xd4\x10?\xd1O\x12e0\x04\x85\xc4%\xb7\x97\xa5\x8a\xa7;\xfb\x17\x01\xf6\xb5\x95:W\x88x4H8>4|\x04\xae\xe6\xc8\x1fz\x14%\xf0\x93\x8e\x93\x93\x07D#n\xc5\xb6\xfal\xa2c\x06\x18\x0c`\x08dL\x1e\x80\xb60\x01\x85-Z\xfa-\'25\x1e\xe5\x1bY\x95[\x1d5\xbd\xb0\x00fQk3\'\xd6\xb0Q0\xa6\xad\xe8\x8d\xfdf?\x07zG\xb7t\xa4\x0b\x13\xa7\xfb@\x07\xf6a\x84V8OJ\xf3\xa0\xa4x\xc1a\x1b\x88\x18 \xcd\xf8\xd2\xbd\xa3QnSf\xb0\xdd\xa9$\xad\xb9\xb5\x81@/@\xc6\x816`\xcbp\x03\xaa\\\x93!\x85\x05\x1a\xff5"\x12,s\xce63m\x1c\xa3\x84*\xbcC\x961\xbbKb\x80\x0ch\xf4\xcc$\x8d\x95O\xf1b3fvPK6A\xcc\xa3n^:]C\'\xa7+G\x02t\x92g\x9d\xb0\xbd\x8b\x1b6\xe9\x06\xb8?"\xb9\xd7*c)\x82[Ik\x96%\x07d\x84\x89\x0c)\xbbM\x19\x8c\x995X\xc8\x9eC\xc4Z\x1c\x7f\x84\xf2\x93\xa2\xf5o&%\x84\xe9h\x12\x9dZRT\xe1\xc5\xcd$<\xed\xa1\x1b\\\x94C.\xe2\x90\x8f\xe5H\xf2\x81G)\x0c\xc3|\xc7Y\x16\x166G\xd9@\x91k\xb8H\x93p\x19\xc2\xbdz\xf8g\x90\x0c\xbf\xf0q\x08\xc6\xb0\xc2n\xca\xa9\xa2\xc6\xab\xdcC=\x0fu\xc6\x87\xfa3M\x8a\x114\x96\x17 \xd1\xc2\x9a\xd74\xd1\xa8\x13\xb4\xc7|FKA%\x83_a\xe6Mdr\x9dD\xe9\xcbI;?*:\xce\x86j"\xa5\x15\x0brB\x88\xb1!\xccl)J\x18\x9a\x96M\x9c\xaa1'
|
|
|
|
|
|
2024-12-14 17:54:47.801870 - Ether / IP / TCP 192.168.1.11:40846 > 35.186.224.24:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 393
|
|
id = 30896
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40846
|
|
dport = https
|
|
seq = 3398706817
|
|
ack = 4001694222
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc701
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xeb\xadbH\xa7~BO\xb1\x12}\x16\xa8\xa1\xd2\x1b#"\xe1\x03&\xf6\xb4e\xc6I\xa7\xd8\xbf\xe5r\xa7b},\xe5\x8c\x8b4\xbds\xb0lI5S\x00\x1d\x00 w\xc41\x18\xa0\x13\xd58n\x83\xdb\x80\xdc\x9ckm\x1d\xc9\xa1\x17C\xd7\x86\x00\xfa_\x83<\xc9|d)\x00\x1b\x00\x03\x02\x00\x02Di\x00\x05\x00\x03\x02h2\xfe\r\x00\xda\x00\x00\x01\x00\x01\xa3\x00 \xacK\xe0\xaf\xe5OQ \xb1vA\x84YE\x0f\x7f#\x84\x1fKn _\xacz\xb6 \x18\xe3\x8d\xb6-\x00\xb05\x98\xdb\xf2\x98Y\x9b\x83\xc6Y`\x190\x0e\x1c\xa0w\x17\x7fU\x14\x9f\x9f*\xdd\xf9 V\xb5\xac\xe2s\x01\x13\x8edh\xbd\xaf\xff@=\xc6o\xac\xde\x18\xe9vT\xb6p,\x9a!\xfdl\x81T\x8d\xd5\x96\xc8`)\xbf.\xfa4c\xa5\x11\xad\xd1\xf1\xce\xe4\xa7\xe7\xf85m\x8c`A`E=-\xf3jf\x0e\xba\x9bT\xe6N\xa7\xe4h\xbe\x04\xb7o\x9c\x82\x86\x1f\x0e\x17\x92\xe0I\x9d;\x92\x82\xb2s\xe0\xebu\xcb\xfd\x0cl\xec\xd4\x9f`\x19\xd8\x7fzB\x10u\xb6J\xbe\xb1\xf5\x99n\xc6w\x10\x1c::\xdd\xaa&`\x86|\xd8]\x11\xa2inV\xcc\x04\xc5R\x8dp\xca\xfb\x1bl\xd7\xcd\x00\x0b\x00\x02\x01\x00\x00-\x00\x02\x01\x01\x00\n\x00\x0c\x00\n::c\x99\x00\x1d\x00\x17\x00\x18\xaa\xaa\x00\x01\x00'
|
|
|
|
|
|
2024-12-14 17:54:47.804918 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40846 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 53669
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xac98
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40846
|
|
seq = 4001694222
|
|
ack = 3398705405
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1054
|
|
chksum = 0x4f1d
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (3398706817, 3398707170))]
|
|
|
|
|
|
2024-12-14 17:54:47.807755 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40846 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 53670
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xaca3
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40846
|
|
seq = 4001694222
|
|
ack = 3398707170
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1048
|
|
chksum = 0x61e2
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:47.812502 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 408
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7ccf
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 388
|
|
chksum = 0xbeb5
|
|
###[ Raw ]###
|
|
load = b'L\xd6\xa5\xe6\xfe\'q.\xe6\xb9`\x1b\xb8\xd3cl\xa2\x15}x?E\x00\xd2j\xfc\xf4\xc1p4\xe0\xed\x81\xce\xddB\xe7\x10\x9a\xa2\n\xf9\xd9 \x8c<\xf3\xb16k\nk\xb5\xfa\xc57Q\x00"%\xcc\x90;=$|G<|\xb7\xa7\xd1X\x14^~\x9c\xff\xda\x14\xde\xd2L;?\xa5\x03\xd1S\xe7\xa8\xf6F0\xe7\xc3\x0f9\xaf\xf5\xcd!\x1f\x1e6)=J\xa4(\x8d\x06\xeb\x92\xd3\xb3\x1a7\x9e\xc1\x9f\x89\n\xdc\x19r\x13\x01\x82RH|\xdc\xaev\x16\xe3|01^\x81\xaetM\xff\x19\xb0\x94(\xfb\xbd\xf6\xad\\\x14U\x91Zj\x1f\x99\xf0\x8c\xb0F\xa5ra\xdb\x06+x\xa8({\x8c\xc3\x94\x964\xff\x95e\x91v6\xe63\x8b5\x0fc43\xfe\xe3\xb0\x0f\xc7/\xb6\xa3\t\xa0\x8d,]4\x05=\x12\xd8\xfd\xb0\xeb\x94y@\xa9\x8b\x97;\xd7e._e\x96+x\xcf\xf2\xf8\xb5\xcdH\xf4a\x14\x97W{\x01h\x1c\xb7\xba\xb2\xd2\xd5\x18\x80\x04\x8c\xc4\xb2LV\xb4a\x80\'\xdb\xd0\xc0\x9a\xd8\xf0\x8d\x8e>\x85\xa2l\xe2\xfe\xe9B\xd40\x9b.L3\xdc\x0e\xd4kj\xa2\xc8\xd1\xecv\xb6\xb8\x07\xb8x\x9ajP\x03p\x15\xbd\xb8\x8e\xe77\xe6\xc6\x04=\xa4_"\x10U\xf3\x038\x82k\x01\xe2\xcc\x0b\x94v\xf8\x06\x9f\x81\x17\xed\xa1\xab\xcb\n\x8f\xc8\xc7\xc2\xa9\xb7\xf3+XT?\xa5\xb4|\x1eM\x8c$3Y\xddD\x83\x04\x13,\xa5B\x91TY\x8e\x84\xed\xa6\xd1\xe7&\xee'
|
|
|
|
|
|
2024-12-14 17:54:47.815172 - Ether / IP / UDP 192.168.1.11:63056 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 63
|
|
id = 30897
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63056
|
|
dport = https
|
|
len = 43
|
|
chksum = 0xc5c2
|
|
###[ Raw ]###
|
|
load = b'T\xe5\xa6\xeb\x0f\xbbm\xbf\xd6\xad\x0b$\x95z\x8bb\x00\xa2\xb7\x83\x1a\x82\x8d\x9b\x8f\xdbj\r\x87\x9b\xb5\xa5\x84\xb8\xe4'
|
|
|
|
|
|
2024-12-14 17:54:47.820317 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40846 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 53671
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xa71e
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40846
|
|
seq = 4001694222
|
|
ack = 3398707170
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1048
|
|
chksum = 0xd638
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x03\x00z\x02\x00\x00v\x03\x03p\x97\xb4\xea\xb3\xea\xfc\x1eS\xed|D_\x84^\xef\xd8\xac3\x88\x9f\x9e\xffb :\x03\xe1\xd7\xfd8\xff o3\x84\xa74Mv\x97\x1eZ\x90V\xd2%\x1crBn\xd39\x18\xefk\xa7J\xec\xc9"\x90\xd4"\xcd\x13\x01\x00\x00.\x003\x00$\x00\x1d\x00 )5x\x1a\x15G\xfd\xa3\xa9\xfa\x10}\x9c\xd6\xa9\x1f\xfa\xd0\x1d\xce\x00\x17\x95\xc3\xdfc\x8f\xe1\xf4J\xc7C\x00+\x00\x02\x03\x04\x14\x03\x03\x00\x01\x01\x17\x03\x03\x0c\xf7X\xd4\xc3\xea3\xc3\xa7\xcf\x88\x10\xcf|OY\x8fkH\x16s2 \x98\x81\xbc\xf7i\xee7\xa0\xc4X5\xbe\xc3\xf9\xe5D\x8f\xd7\x10\x8c\xfe?\xfeXer\xe8\xb5\xfe\x03\x86\xbb7g\xe3hs\xf4\xd1d\xb7v\x1ee,2\xfa$\xca\x80\x92\xbe\xed0\xf9\x8a0\x87\xbd\xad\xdb\xde_\x0f\xe4\xebB\xca\x10\x88\xb4\n\xf0Ea#\xb9\xa1\xf1\x854t\xdf,\x04\xee\xca\x03:\x1f\x86\x8c\x16\xfe\xf2\x9cz\x83\x97\x00\x9eV\xe4\xf0\x83\x07\xd6\xc5x\x1a-\xb5\x9b\xf1\xb8\x01\xf9Mv$="d\xbbi\xa9\x13\x0fH:\x96\xc1\x17*A2\x1e0\xab\xaa\xfc\xa6\xa3\xcf\x8a#\xebsD<5=\xb57n\x1a\xfe\x9e\xfbL\xff(\xa1\xdc\x987;\xd8lc\x0fO\x81h\x9dk\x92\x86/\xa4s\x18\xdd\x17O\x98\t\xa9\x1eL\x87\xbf\xe3|\xfcG\xc9|\xb6\x84\xd0\x96^\xfe\xd7\x9cj\xbce\xf73\x8a\xf8\x9c\x88\x93\x87\x80-] ?\x8c\xfe\xf6\xea\xd8\xa5B\x94\xbet\xc4\x01\xc38\xaf\xaf\xfa\x95\xbb\xedC\xa7^\xc9\xe6\x06;\xee\xaf\xab~4\x19\xb7R\x13\xc0bi3?\x1e\xab=\xb4)\xf7G\'.\x904c\xfc\x8cH\xf4\xfb\x0c^\xfdg\xdc\x86]\xd2] y\xf9\xcb\xaap\xcb6\x08,\x02\xec\xee\x9aC\xe7\x94\x14c\xc9\x11\xdf,Mw\r\x12\n\x0cv\xa0\xe5;\xc5\xea\xa4\x06v\x15\xfas\x97\x1cK\xa3\xb8\xaf\x1f\x96N\xbd1\r\x9d\x04{\x8aL\xac\xa7\x19~\xcf\xa7\xf9~\x86\xe7[b^\xf2\x81hZ#&\xd8lcD \x8b\xf6\xeaV\xc7\'\x86\x1a~\xa3b\xb2\x18\xe3\x0f\x8d\xf2\x18ee\x16BN\xa6]\xb6\xf5\xb2c\xf1\x8dH\xc3\n\xc5\xdd\x87\x08\xb7|\x98\xdfW\xb6g\xf8d\x95\x84f|\xf0k=]\xfaWy\x87\x16\xae\x15J\x9e\xd34\xb9)\xa3O\xe2S\xa8\xb3\xa9\xd8M\xb2y\xf2\x1b\x92}\xc6k\xa9\xc6\xf2\xe5z\x86,\x96O}8)-=%!\x8b\xbe>\xd3\x04+\xfd\xe7|F\x15Z=\xe8\xd0\xcc2\xc8\x1a\x8e\xdd\xe8\xe2\x9f\x11\x0e\xd5v\x86\xae\\\xee\\\xaa\xfd\xfe\x0c\x04\xaa\x7f\\\xd62\xa0\xe3\x037\x17\xd7\x12\x8a\xf0\x1ft\\\x1f\xa1\xff\xd7\x03\xba\xbb@\xe5\x06\x94\'p\xeaa\xb2H\xec\x18\xed\x0f\xd8\xb0\x08)}\xdcrr*<O\xc1\xf8<RzF\xbc\xd6\xa1-\x96\xec\x1c\xc2\x00\x0b\xe5\xfd\x9f\xd3A\xee\xbf\xc9\xbcS\xe0$\x93\xa3\x84\x16\x88\x8b\xc2\x7f\xc4\x94Y|\x0f\x81\xc8/\xdd"\xb5\xb5A\x1b\x8c\xd3\xed\xc1\xc4+\\wK\xc7n\x04\x93\xda\xac\x9f)N\x97\xc3\xceW)C\x95-xRICB\xdf\x8b\x89M\x88~\x1dg\xa7\xc0dX\x8f\x13\xd6\xfa\x10\x14\xdc\xd2\xe0\x8e\x9d@\xdfV\xd9\xbdi\x98\xb5m\x8c\xabP\xdbX\x9a\xc6\xd1\xb8\xbc\xbc\xac\xcd\x011\xef\x93\xb8\xf4\x91\x18\xfa`\xb3\x91\x86\t\x1d\xc0\x88 l=\xb0h\xa0\x17:\xac\x9a#\xc6\x7f\xe6)v[]\xe6\xd7\xd1\r[\x98n\x19\xd1\xe3\x9d\xff:pp\xac\xe5\xce\xdc\xb0\x13\x7fH\x01\xcc\x85\xb9\xe7\xf5|d\x89\x02s\x8c&x~>}\xe9q\xf6\x81\xc1\xcfR\xfd\xa2\xdc\x8f\xa6\xb0w\xe2\xdf\x82\xf0\xfd\xcb\x962\x05U\xe23\x92\xd1\x8e\xb7>\x82r\xd9\xbc,RY\xea\x89\xac(\x00+\x92\xefpGf<h\x18[k\xc5\x10\xd1r\xcek\xfa\xcc<\xbd\x84w\xda\xba)\x82\xc3\xfa\xddW\xfbpj\xdf2cuz\x9d\x1b$\xc2\xea\xe2\x1a\x14\x96l;\x0f\x0e\xf8\xca&L)\x03f\xb1\x89\xe9\xb6\x19-c~\xd0Fgf\xf0\xeb\xb0CS\xa0T\xcd\x7f0\xc1\x89v\x0b\xba\x07\xcfW\xbc\x87\x85\xae\x8d$\xa6\x1bW;\x16\xc5\xfc\xaa\x83\x9d\xa2u\xd8\x08YDt\x9a\xab\xa1\x15N\x91!\xcdu@\xbf[F\xf9\xef\xa40GIo\xea\x87,1)Rr\xae\xfa(\x1b\xc63\x85j#G\x81Q\t\xe4\xcbN$\xcd)\xc4O\xf08\x9ca\xb6=\xd6\n\x856\x93U1\xf3:\x0eM\x9d?\x02c5\xc9\'\xdbZi\x87ww\xbc\xd6*\x8eA\x1b\xbf\xbb\x0bp\xf9=\x07hq\x140h\x0b\x174\x86\xcd\x0c~#H\x9b\xed\xca$x\xb4\xba\xa2\xc49\x1fU\x9aO\xf7\xa8u\xb35Q\'\xe7\xb5?\xf0+r#\x84\xd0\xcf5\x03\xd3l+\xadUH\xab7s=\xeb>\x88\xdd\xa9\x9a\xd2Y\xd7\xb0\xcaq\xf7\xbc0\xc2\xbb\xa8B\x9f7\x80\xe5^\x0f\xb1\x19E\xc2\x91Qh\n\xeb:\x15\xb5_\x12\x9b\xdd^Q\xb4"\xe2\xb8\x8d\x0b\xd6\xf9<"\x97Oor{\xce&\x9a\xd1\x18\xf1U\xf0\x8b\x04\xc9v2\x02\xcf\x04\x8b\xbf\x88&d\xb93d\xc3\xf4\x03_\xed)O\x92\xfe\x83!\x9cO\xfazi\x040Cq\x8d6\xa3\xc2\xf2#\xdf\xe3o\x82\x17\x96<\x1a\xf97\t\xe1\xa7\xa0zR\xa5\xa3e\x9b\xda\x10\xce\xcd:\x87\x07#!\x00\xfc\x18\x82\x14\x1b\xa3\xf5\x93\x13<ppM`\xedY\x10\x9c\x84\x0b\xbf\x18\x9c>\xfcM\xd7\\\x8d-\xd7\x12*\x7f>\xeb\x92\xbcZ\xb6E%!\xe9\x8e\x99\n\x83\xd0\xb9\x805'
|
|
|
|
|
|
2024-12-14 17:54:47.825725 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40846 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 676
|
|
id = 53672
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xaa25
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40846
|
|
seq = 4001695634
|
|
ack = 3398707170
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1048
|
|
chksum = 0x1b02
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xcf\xf21b-QT\x0c|\x10\xd8\xa6\x91\x83^g\xb9\xa2N\xab\x91\xa6$%\xcb\x8d\xfc\xee\xe5@\xf9\xdfL\xd5\x0f\xc7\xda\x16\xe6w\xdb\xa7\xcf\xa1\xde\xba\'?\xfd\xf7\xfaD\x16K(\xea\x05\x84\xf2\x01\x8cB|\x0e\x96<\nVH\x90\xfb\x07\xd7\xcc\x80\x93\x89\xcf\xbd\xe8\xb4\xd9l\xc8Kb4V\x83\xda\x14Wp\xf9\xfb\xb6\xad4\xebf\xf5\xad\xb6m\xb7]*\x0fRwrv[\xefb\xb7\xb2\xfa\x8aI\xd1\xf3\x80\x0f\x9c\xffL\xc2\x95\xd2A\\Q\xb1\xb0I\xbb\x9b\xc9\xd0\xd5\x9c0\x81bL\xeb%/&O!\x08\x02\xf4\xf1\xddO\x8f\xc2\x92\x9c\r\xfb\xcdE\xd8l\x81\x8a\x16\x9c\xdb\x1f\xbc\x88\x92\xb3ms\x18\xd5\x14\xc2\xaa\x04\x93\xa7\xbb@\xc2T]-jj\x11|F\xa5|>\xda\x1f\x07\xa9bC\x89*8X\x8eN\x17C~\x12\xc4f\xdb"\x98\x96n\xb0\x93r.\xeb\xd7"\xc6\x07\xb3\xa1J\x87\xf6\xed1\x1cx\x8e\'< 8\xdb\xd7\x9c\t\xad\x1bz\x1b?O_\xd4X5t<\x90\xdb\x94]\x17,\x16\x19\xc2 \xc4?GE|\xac\xef+\xc7N\x8dIo\xe8 _\xd1\xd5\xacX8\xb9\xe0\xee\xb0b\xa0\xaa|\x16\x0f)\xc4\xaa\xf9\xa0\x00\x85\xd34\xefr\xb4Q\xc7\xe6 Q\xba\xcd\x19\xa8\xcc\xb0\xa9\xc6\xb5\xad\x01\xd4\xf8\xbc(%\x05\x17\xc0`-\xeez\x08L~\xe3\xd9{\xee\xd6\xaa\xe4\xa6u\x98\xc6T,\xc0c}7\xc8\x1eI\x0f\x18(\xc2\x07\t\xdf!;44<\x8b\x80\xcb\xc3\xd27.?\xc1\xc6\xf3\x01\xa1\xd7\xa9\xa0\xb0F%\x8e[hXI\xcb\xe4\xa6\x81\x9bB\xa0\x16\x8c\xb9Jf\xd9\xce\xafd\xce*\xc8\xd6\xd9\x12\x90z1%\x95\x96Q\x92y\\7\'?\x93\t4\xb2\xf5\x16\xa1\xc7\x02\xf9\xab\xc4\xe7\xc4Z"\xc6\xfcR\x04\xaa!\x8f9\xa5\x07\x06\xd1\x89\xf6Ao@U\xe5\xac\x88Q\xa0\xb0\x98\xf9:p&39\x9d\xd0lc6\xc7\x17\xb5\xf8\xb4\x16\xe1\x8f\xc8\x1c\xc4J\xa1\x86K6S\xd8~^/\x92<\x94\xc0\x80gz\x1dS\x11\xcc\xbf\x00\xb0lL\xa8S\x1d\xd7\xfc\xa8\x04-\xd0\x96\xe6(,++\x7f\xfe\xf5\xd4\x19\xb0\xe4K\xd4p\xe3X\xe4\x86\xda\xbe\x18`l\xd7\x88\xda\xa9\xc8f\xf8S8u\x97-<\xa5\xb9a\xd8\xcf\x95\x84(\xf1\xa1\x97\xec\xeb\xb9\xf7\x92\n\xaf\x04\x8c\x83\xc7\xec\xe5\xc7\x92\x0f|\xbf0\xea\x10`&\xc4\x9f\x91\x1f\x96!\xdd]+\x021\x06\xcb\xfc\xe4w\x82\xf6\x15Y\xf4\x9b<s8\xb0B'
|
|
|
|
|
|
2024-12-14 17:54:47.832894 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40846 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1449
|
|
id = 53673
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xa71f
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40846
|
|
seq = 4001696270
|
|
ack = 3398707170
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1048
|
|
chksum = 0xee46
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00\x8b\x92\x01\xb8\x97\xea<\x88\xc26\xea3\x05L\x89\x95]\x07\xe6O\xd4\xedy;\xc2\x93\x08\x91\x12K\xa3p\xa8\xc83\xean\x97\xa7\xb7<\xf3\x06\xd8\xbe(\x02\xf2\xa5v\xc0\xe5\xbe\xdc\xac$\x04k\x9aw\xe8\x9f\x8a\x84\x93\xa0\xc4 \xc51{E\xc7\xc4\x0e+a\x1c\xaa\x8d\xb3\x86\xb6\xcc\xd8\x8f\xa1\xf3\xf3);\xc9\xc0\x90\x1e\xf2izJ\x82)k\x83e\xbbR*T\x1f+\xcd\x81\x1b\x88T\xcc\\\xd2Y\x19\x00\x99\xb5C\xcb~3}Z\x13\xcb\xca\xd0\xca9\x0f\x02\xe2\x18$l\x81\xfc\xd6@I\xc2C\xda\x12\xf4\xef\x9d4\xacE\xab\xa4fCy{\xb2H8\xc2d\xe5\x83F\xd4\x1ec}\xc0\xa6nJn\xe1\t\x01V\xbf\xddl`p\xd3HU\x84\xcd\xc9\xe5\xfb\x83W\x89n\xfc!\xa1\xd3\xce&\x95\x83\r\x81\xc6\x95\x99\\\x13Z\xc78\xd5\xabt8\xab\x1a@\x9f\xaf\x82\x9f\xcb\xcd\x15:\x13\x0b\x85\xabr\x9f\x1c\x87\xfa,\x8e\xe6\x0c\x84\x8d\xa7\xc6\x81\xa3\x19\x1e\xfa]5\x8d\xd4\x8a\xde\xe8W\x16@\xcb\xcc\x99\x1d\xfa\xa0\xa83\x9c0\xf0x\xd0_O\x02oo\x12\xf3\xf4%a\xcad@px6\x83\x8b\xb5%\xa0f\x152\x1a\x19\xa5\x87\xb8~8\xbfc\xdf\xa0\x96h\xe1~\x80\x13\xee\xfa\xfa6\x0c\x8f#\xef\xe3s\x07}\x12\xd73\xf8g\n\xe0\x1fW\t\xa8\x9c\xdc\x8aa\xb9~6q]\xfbK/\x81o\xeaw\xa5\x06\xf6\x11\x93\x93\xf9\xf8\xcd,\xae;[x\x10\xa9\xfa4;\xc8\x96\xbc\xf8K>\xa1\xb6\xd5\t=,\x98\x83@\xe7\x8a\x9b\x91\xdeQ\xaa\xfd\x03\x87V\n2\x88\xb6z\x836\xf9\xab!\xcb\xeb\x1e\x9f\xc2\x8dk5\x99\x88;\xf3}\xcf\xdb\xe5\xa6\xcbL\xe1\xd7\x02\xda:\xe0\x99\xbb\xb4I\xfa\xaa\xef\xdesm\x06\xd2\x8bN\xdc\x8bH;\x08w\xfb\x1c,v\xce\xf4\x19\xd4v.\xf1`qN\x06!Jg8\xdb\xc0\xf2\x90\x99\x82\x13\xa0\x8b\xf8\xb4%\xc1\xael\xa12\x89L\x90Q\x92\xfe\xc1j\xd5\x1a\xa1.wp\x81\xb8\'r\xc2\x0c\xf4\xb0\xd7%\x8eO\xb7)&\xa9\x0e\xf7n\xf3\xde\xda\xfdo\x90\x06h\x02\xd0&\xd0\x18\xa1\xb6\xc7\xd4[\x93\xcb\n\x1e\'YV\x87u+S:E#\xf2\x94\x08\x82\xcd5\x07y\x98\x11\xe5\xee\\S!|\x83eD\xfd\x00\xe8"\x15\xde\xbc\xb7\x03\x8d\xbe\xc6\x18$n\x9e\xc5\x87\x03\n\x02\xddlt\xedbU\xcb\xa5\xb3\x18\xb8hx\xff1U\xf3\x9b\xc8P\xed=\x04\x8fC8\xcd\xe97\xc3\x1e\x1f\x81\xdf>X\x0cfLgf\xf1\xfe\x861\xec\xb4\xcf\xc5\xee,\x1cPU\x13\x10&HF=c\xafd\x12o\xcf\x9d\xd5\xd4\xf9\xc3\x0f"\xec\xc3RHLW\xb1\xa4\x9ba\xc7\xf0\x8c\xf3;U:\xec\xf8\x00F";\xd8\xeb\x12|\xc9\x9e\xa0;s\xb0\x13rK\x16\x00\x05\xc3\xa5]\xb3fi\x00*\xf3"\x96$3\x1c\xe0\xf9\xb1l6y\x80\x93\x11\xc87\xc0\x82\x92d\x9d\x83\xb5\x11\x7f\xe80\xde\xa4 \xaeT\xbe:H\xf8\xaf4\xd5>_\xeb\xa6\x1aH$\xaf\xf4H\xbd\xe8FT\x81\r\xb0\xa98\xee\xa6t>\x8eX#C\xc6\x04\x9e\x15\x95\xa5\x87e\xc3n\x8a]\x80\xff\xec\xef\xdf\xb0\xa3>\r[\x0fB\xa9\xe1/y"\xf7\rc\xfe\x0e\xe2\xa0\x88\xaa:\x8e\x7f$\xdde\x11-\xef\xf6\xc82HA\xd5\xe0\x99\x7f\xc5 S\xef\xed\xf5y\xd3\xb0~\xfe\xf9(\xf5\x9e6\xd0e\x8c<\xaf\x8f\x9d?\x1b\xe26\xeb\xf3\xa36f\xfb\x06\xa5\xea&\xf9/\xfc\x1a\xb3\xd6\x01\xe6d\x02\xde\x9e\xd3\'\xd8B\xf7|\x88\xd7\\\x97\xa6\x9b\xcf\x17\x1b\xbd\x99!u\x04z\x9c\x9e~\xe7\xf4\x9c\x07\xb8\xdf\xf7\xe4\xac\xc2\xd4\xc7\x8cw \xef?\xbfS\xdf\x08,\x80\xb2\xe3\xa4\x1b\x9e\xf0\x84\x9b\x9d\'\xbb|q\xe0S\xa8\xed\xdey\x96}\x14\x88\x8f\xc66H9e\tj"\x8an\xbc\x0f\xc5/\xf4\xf4\xcb\x93N^\xc13\x88\xf1\xe7/m\xe3\x84\xfd7\x806%\xe9\x84\xf0\xf6\xf33\x16|U\x03 "#\x0cz\x9bFbNL0\x15\xb2\xb2L\x81XU\xc0\x0c\x03 Fl\xf5}\xf3~\xea\x86\x92\x83\xe9`r\xef\xff\xc9\xa3 \x90\xb1D\xae\xc3\xe3\x0e`\x19?\x1f\xfbD\xc8\xa2sf\x8a\xe9${\x89g&r+m\xdb\xa1W\x98w\x04\x0cK\n\x9a\x8c\x1c\xadpD\x8b\x9c\x13\xf2\x86\x9d\x1c\x9b\xb1\x8b\x95\xa2\x8e\xba\xfb\xdc\xe9\x971o%\xd1\xe2y=\xbaN%\x15\xf9\xe9\xa9\xfc"\xcb=GkK\x1d\xfa\xbf\xd9\x8d)KT\x04P-r\xf4\xb8L\x84\xd7\xb6u\xb1\x1a\x87\x112\xf9\xce\xa4>\xfe\x86.\xc8\x9d\x0f\x88+X\xef,/\x08\x07\x92\xa8\ts.\xfcM\x0b\xb4+R\x0fK\xca\x0fO\xf1X\xbe\xbc\xa9M}\xe9]-\xb9\x84\xdd\xf0K\xe6> \xc39\xa8\xdb\x8a_\xd1\x86(\x90\x07\xf8\x84\xadv\x11\x0e\xd4\x80A\xa1\xce,\xfc}\xb0\xb7\x1b)\xf0\xbf\xcf\x0b\xf4J\x87\xe8K^\xefC\x98\xc9\xef\xcd=\x85v\xe9N\xf3\x9cA7\x07@\xb9\\S\xf9&\xab\x14Z\x1b\xc0J\x0c/\x06\xbc.\x8c-\xa2S\xce\x89\xd5\xa1\xa5\x81\xa9\x806S\x97\xbc "m+\x0e\xa3W#9:\xf9\x86\xa6I\x98S*U:J\x9a\x99\x14\xea\xdc\x99\x12\xac\x9c\xa7\xf6\x0e\x97\x0f\xac$\xf4R\xf4\xdf\xcc+\x99 8\\\\\xef\x0b\xd8P\xef\xf9\xd6\x80\xbb\x98\x89`\xc4\'\x88K6I3a\xf6\xae\xceNg\xf0Z\xc3i\x18\xa4\x18\xf3\x8d\xd0U\'\x1aY\'\xf3\x06\xb3\xc9v\xbf\xb1\xbb\x10\xb5\xda\x17\x11\xc4\xf0\xa8\xad~G\xbe\xff\xc1\x16\x08\x9d\xac\x97R\x9e\xdf'
|
|
|
|
|
|
2024-12-14 17:54:47.837929 - Ether / IP / TCP 192.168.1.11:40846 > 35.186.224.24:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 30898
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40846
|
|
dport = https
|
|
seq = 3398707170
|
|
ack = 4001696270
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xc5a0
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:47.847077 - Ether / IP / UDP 192.168.1.11:63056 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 790
|
|
id = 30899
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63056
|
|
dport = https
|
|
len = 770
|
|
chksum = 0xc899
|
|
###[ Raw ]###
|
|
load = b'F\xe5\xa6\xeb\x0f\xbbm\xbf\xd6S\x0fk\xc0\x8b\xf7N\x0b\xa5\x0fR\xe2\x18h\x1e\x89\xef\x8e\xf8z\x027\xeeM\xf4g$\tj\xad[\xc9rq\xb0\xd4\xc7r\xe6\xab@\x10\x8eS\xb8\x8e\xb4\x15X\x17[ \xfev\x8f&\xfa5,\xd3\xb5\xcbmZ-a\x86\x8e\xabz0\xc2\x18\x81\x92\xad7\xb2\xe2|\xbbuH\xf8\xff\xec\xdcx\xe2*h\x04\xe2F\x86\x04k\xca\x85\xf8\xc4o\xd4E\xe6\xa9\xe5\x9f\\\xbf,`L\x0en\xef*\xfbA\xa2\xd5\x08\x8a\xf7)1nMV\xa4=Yeu\xd71c\x9d\xca\xb3\xf5\xd1\xdbF\xb7z\xd6`ch_\x81Q{\xaa\x82\xbf\x80\x83\x809\xbd\xa61\x8c\x93\x19G\x02[#\x95\x80\x89\xa2\xde\xf7\xfcZ[\xf8\xbbQ\xff\xc3r\xe10^\xa4\xc09\xb5\xc5[\xb0!\xa0\x1er\x1b\xd0\xe3\xaa\x02<\xe9\xa0Z\x8e\x88z\xd0\x0b\xa7h\xea\xb5I\xb2T\xbd\x05\xd7I6\x8f\xe2\xc9G\xa3\x13\xcaz\xba\x95&\x05&T\x86\x88=\xb4\xc3\x0b\te\x9c"\xf4 \xbe\x88\xbf\xc7\xcd\xa0m</\x1fDI\xc3\x9d,L|\x03\xcbn\xf0&\x04\xad\x9a\xbdv\xbfZ\xbe\xad\x10\xe4x)|\x83\x06\x07|\xa5\x18\'\xb1!\xd0\xcfE\xefa\x05\xbd\xb9[&a#"\xe5a\xaa2\xca \x08%\xd9\xbf\x98\x0b\x8a\xe3\xacU\xde\xd6\x85\x9a\xdf\xb5\x15\xd4\xe36\x1c3\\\x8b\xc1\xf1(|\x87$3(\xeeM\xa0\x1a\x96Z\xb3Q\x02g\xde\xabi\xd2\xde\x1c\x0c\x8d\x00*E\xd5K\xea8\xdb\xb0\x0c\x01\x9e\t"m)A\x01\xab\xbbk(\x11\x00:K\x906\x86\xac\x19 \tW\x9b93a\t\'\xa71\xd3\xc3\xb1\xf5\xd3?_\xaf7\xeb\x17*\xa2\x9d\xa7\xa8\x86\x1b\x02+\xba@l\x02\xe2\xd9\x1dX\x8b@\xb5\xed\x9eq9\x92\xd0\xdd\xa9Go\xf6$7\xa1\x17\xc9\xe6$\xd0\x0c\xe0Hb\xbcU\xa7\x1f<\xceD\xa9RS\x05\x949[G\xfa\xf6\x8ew\xaa4\xa3\x9b\xe5\x13\x90\r7\xca\xb8W\xedo\x80r\xc1\xc0\x1d\x84\xb1\xf6\xd93y\xe2\xcc\x10\x98\x19\xadW3\x1d\x88c\x93i\xec\x19e\xb8\xef\xc2\x7fOO\xb1\x16\xa2\xd5\xdaI:6)S\xfb\xfa\x1e\xcf\x91\xf0\x19JR#\x8d\x08\x04\x8f\xab)\xd4\xdfqN\xbd\x98\xc7\xef\xb7\xd2\xc0\x9e\x00\xf5F#Y=R\xd2g=\x8b\x9b\xabXI\x8c\xf5\xa3\x13U\xfc!f\xf4q\xed^.r\xb2\xbf\x8bg\x0e\x19^\xc7\x93v\xd1\x14X\xbcsK6\xcf0\x19\x8a\xbe\xd3W\xb0\xed\x8a\x9e\xe59\xf9\xe9X\x00l(3Y\x91\xa3n [<\x86@i\xe3\xfc\xe4\xc3\xad\x88c\xb4\x8f\x00\xb2o\x96\xda\x95*\xebN\xb0\xae\xe0M\xbcI\x8e]l/\xc4`z\x90\xa7?\xfb9\xd1\xb5\xcc\x17\xbb\xe4\x93]\xc9t\xf3q\xb2\x18\x97)B\xd4\xfb\xa4DV\xe8\xda\xdd\xc5t;\xdb\x8d`\x83\x8f\xb1(\x17\xf7Md\xa1\xdd\x97\xa3\x1f|\x16\x81\x8e(\xb1\xb7\x8f\xc6\xd3*.(Q\xd1\x19\xe8\xa8#m]\x91Y\x1b\x1e\x14 \xd1O\r9'
|
|
|
|
|
|
2024-12-14 17:54:47.853037 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 55
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7e30
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 35
|
|
chksum = 0xf93d
|
|
###[ Raw ]###
|
|
load = b'^\xb6\xf1/\xa8\xf4a[\xa8\xad\xc8\\\xb4\xe2\x128\x0e\x9b\x99 A\xa8\x10UO\xc3m'
|
|
|
|
|
|
2024-12-14 17:54:47.856875 - Ether / IP / UDP / DNS Qry b'spclient.wg.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 69
|
|
id = 31675
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 54253
|
|
dport = domain
|
|
len = 49
|
|
chksum = 0x839f
|
|
###[ DNS ]###
|
|
id = 13715
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.861478 - Ether / IP / UDP / DNS Qry b'spclient.wg.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 69
|
|
id = 31676
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 51436
|
|
dport = domain
|
|
len = 49
|
|
chksum = 0x839f
|
|
###[ DNS ]###
|
|
id = 30762
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.865063 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 120
|
|
id = 25548
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299533841
|
|
ack = 3808769646
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0x80b3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x14\x03\x03\x00\x01\x01\x17\x03\x03\x00E\x8d\xc10\x1bfeda}i\xf6s\x19&\x92\x8f2\x18\xc5\xe6\x833\xe1\x8em\xc8\xcedzL\xc3"h\xb0\xdf\x0bH\x80+@f&\xa3\xca|\xc1\xbf\x94\xc9L\xa6\x9cZ\x11\xc07R\x062\t;\x96|W\xea\xf0K\xc0]'
|
|
|
|
|
|
2024-12-14 17:54:47.868085 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 111
|
|
id = 30900
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 91
|
|
chksum = 0xc5f2
|
|
###[ Raw ]###
|
|
load = b'\xe5\x00\x00\x00\x01\x08\xea\xa4\xfd\xe9\x04\xea\xaf`\x00@B\xdb\xd6\xfaR~\xba\xfe\xf4\xa8<\x04X\xc8t\x8a\xccZ\xab\x95\xdbE\x04^4\x10\xea\xd4\x0e\xf8\xce&\xe0\x88\x99\xc4b\x8f\xe4\xed\x92\xee\xb9I\xed\x8cuX\x1a\x05%\x1d+v\x11\x1e\x12/F\xda\x1c\xc6W\x93[4\r'
|
|
|
|
|
|
2024-12-14 17:54:47.871067 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 30901
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 81
|
|
chksum = 0xc5e8
|
|
###[ Raw ]###
|
|
load = b'L\xea\xa4\xfd\xe9\x04\xea\xaf`b\xf8Ae\xb4\xd5#\xf4\xd9\xf3\x9a\x93\xff\x85\xa9\xb6F"\xa8\x86K\xa8\xad\xa4\xc8\xb5\xfa1\x1ew\xfe?L\x97x5\x96\xac&\xd5.n\xdeH\x07\xb9,\xd3\x0c\xab\xff\xed\xda\x9b\x0c|\xbe\xe8D*\xe8\x83\x7f\x93'
|
|
|
|
|
|
2024-12-14 17:54:47.873395 - Ether / IP / TCP 192.168.1.11:40846 > 35.186.224.24:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 104
|
|
id = 30902
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40846
|
|
dport = https
|
|
seq = 3398707170
|
|
ack = 4001697679
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 507
|
|
chksum = 0xc5e0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x14\x03\x03\x00\x01\x01\x17\x03\x03\x005\x84+4\xd7&&X\x91\x8d=\x1b/\xc3Z42/sS\x14\x00\xa7\x7f\xd4\xd8\xc9\x12H\xa2\x88\xe3\x9e\x97\x85-o\x96*\x19\x05\x89\x99.\x07R\xf1MCz\x1f\xdf\xc0'"
|
|
|
|
|
|
2024-12-14 17:54:47.877573 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 132
|
|
id = 25549
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299533921
|
|
ack = 3808769646
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0x80bf
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00W\x9av\x9c\x89*\x16<G\x11f\xd1\xb7\x9b\x8c\xe6\x11_\xe8]\x8f(\xdd\x15\xe2\xbd\x120i\xd7\x19\xfc\x0f!\x153u\xe5\x81\xb0L\\\xe453\xbe\xd9\x17"\xf0\x00\x97\x8a\xe3\x00\x86L\xb7(\xef@\xb6#\x99\x81\xc4\x14kC\xd3\xf5\xcb\x95\xba\xaer\x1f\x7f\xe4\xe3\x0f\xcb\xb77\x12)\'~'
|
|
|
|
|
|
2024-12-14 17:54:47.881987 - Ether / IP / UDP / DNS Ans b'edge-web.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 129
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb70f
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 54253
|
|
len = 109
|
|
chksum = 0x841
|
|
###[ DNS ]###
|
|
id = 13715
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 2
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'spclient.wg.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 184
|
|
| rdlen = None
|
|
| rdata = b'edge-web.dual-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'edge-web.dual-gslb.spotify.com.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 13
|
|
| rdlen = None
|
|
| rdata = 35.186.224.24
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.884876 - Ether / IP / UDP / DNS Qry b'i.scdn.co.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 55
|
|
id = 31677
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 61259
|
|
dport = domain
|
|
len = 35
|
|
chksum = 0x8391
|
|
###[ DNS ]###
|
|
id = 3408
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'i.scdn.co.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.887942 - Ether / IP / UDP / DNS Qry b'i.scdn.co.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 55
|
|
id = 31678
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53494
|
|
dport = domain
|
|
len = 35
|
|
chksum = 0x8391
|
|
###[ DNS ]###
|
|
id = 25435
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'i.scdn.co.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.890930 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 60
|
|
id = 30903
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 40
|
|
chksum = 0xc5bf
|
|
###[ Raw ]###
|
|
load = b'S\xea\xa4\xfd\xe9\x04\xea\xaf``\x80\xa5hy\xe1&\xe2Fp\x1fz\x82"JKb\xa5\x04Z\xe01S'
|
|
|
|
|
|
2024-12-14 17:54:47.896515 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 666
|
|
id = 30904
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 646
|
|
chksum = 0xc81d
|
|
###[ Raw ]###
|
|
load = b'[\xea\xa4\xfd\xe9\x04\xea\xaf`\x04\xa6\xd4\xd7\x8b\xd0R\xd3`\xab\xa5-g\x92/\x90\xfb}i\x08bw\xbc\x18E\xba\xe4\x97\xec\xf8\x89\x80\xd0\x02H\x98\x10\xc0jNl\x06\x1d\x16\xaeo\x08`w\xcfQ\x1f\xec\xd3\x19\x8d\xa8T\xe6\xf0\xaa\\\xe8\x04\n/\x90\xde*\x14Rn\x95\x87H!\ng\xe3)\xedS\xdf>\x03\x803\xfd\xeee\xb44\xd2\x07\x19\x9b\xe3FO\xa3%\xbb\x989\x83\xc7\xc5b3\xb4\x83\xfc\x89\xd0\xf2;VWO\xcaVa\x94nh\xbfw\xf5\x95\xec\xbc\x96\x17\xd895\x0c\x80\xb3\xf1\xf5\xa3\xb3AD\xd95\x15\xf2\x1c\xf7b!\x9a\x10f6\xc9\xe0 \x1er\xb4S[\xbdc\xc0j\x07\x11\x80\xa3\xd5~\xff\\\x0fw\xedsn\xae2{[\x05-\xf7aX|CSQ\xc0\x8d7,R\xef\xf8{\x05!\xaeUut\x8du0\xdd\xc6\x99A\xfb\xffo\xae\xdfcC\xab\x05\xae\xf1C^+\xf2\xc0\x8c\xf3\x8c\xd8Y\x16\xe9\xba\xee\xaa\xd5\x10AV\x0e\xf7\xf7\x84(\xde9x\x06Y\x8dj\x97<\x97\xd2\xe2fm\xd7\xede\xb7\xf2A\n\xdb\x9a\xf6x=\xbc\x85G\xa6/\x04.\x05\xc8\xd2\xc9\x89\x02\x0bu\x16-\xe7wr\xe4\xcd\x91\x10h[^\x085\xa0\xcf\xb0\x0ex\xdf\x02\xdfg\xa55\xab#y\x95^@\xee\x13`\xfbx\x9f\x19\xf3\xf9o\x07\xd7k\x02\xd0\x9d\xe7\x0f\xa3\x0e\x8f \x055\x1b#\xa5\xe3\xd1\x82\xf4\xea\xe1*\xf1\xcb\xc1\xd5\xb9\x83\xa9;\x9c)\xe9\x88/dW\xe5\x03\xdb;gS;\xda;\xf1\x97tb\xcd\xedo\xe5?1\xc5\xe5W[\xeb\xd0\xcf\xbam{\x18P\xcf\xad\xb5\xff\x1a\xbc5\x82Y|\xccM-V\x91\xb7\x18\xe5\x8e\x19\xe5sf\xd6]x\xafr\xdav\xa2\xb2\x82\x1f\xeda\xafg\x88\x92\xf5G\xec\x14\xe1}\x01\xcfl\xeb\xef\xb5),1\x8eO\xf8\xbf\xe7^\x0f?\x8bc\xe7\xc0\x8dV\x9fF\x8a\x92<B\xe8Vg$"K\xa9\xb4\xfc\xe8\xb0\xbe\x0ca\x05\xb6\xc5\x8b\xa9\x14\xe8\xd8HaCDPV\x1f\x0b\xb9\xd9\x06\x1cY\xf7=\xcc\xa2H\xf8S\xed\xba\xbe\x02\xc2\xaa\x0b\xea\x07j\xdew\xba?\xdc\x85\xd9\xd6\xd4r\x10\xc0k[\x1d%~\xf3p\xd4\xd8\xae\xe3~lL\xb3\xa3\xd0\xcb\x82:`,\x883\xd4\x87\xad\xac{\xfcV5\x0bs\x9f=W\xc9\x00Z\x0f\x9a\xc9\xf6L\x97JQ\xe6\x8c\x12\x9c+\xf0\xd7\x187\xdb\xe00 \xc9\xbch\x84\xc5\xf1\xb5^\xfe\xa8\xec\x1a\xcbvz\xa1\xa0\xc1\xfdHW\x9e\rM\x15\xc1'
|
|
|
|
|
|
2024-12-14 17:54:47.900163 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 382
|
|
id = 30905
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 362
|
|
chksum = 0xc701
|
|
###[ Raw ]###
|
|
load = b'S\xea\xa4\xfd\xe9\x04\xea\xaf`\x1a\xa0\x1e\xaf\xdb8}a3\xb5f\xe6{x\xd5\xde8\xd2\xbf\xef%(s\\stN\xb5\x8ap\xd0m\xd2 \\\xf6\x0f\xdc\xe0\x91\xf1u\xf5`sG\xd9\xe8\'\xefq\xa4\x15S3/\x8c\\\x84N\xc4\x87n\xb2\xb6\x18\xf6\xf0\xa87\xb1q\xb2k\x8a/\xa6A\xb8(6\x0c\xad\xf3\xde\xff:8\xcd\xaa\xfa\xa9\xd0f\xe3}\x80\xc9\xed\xdb-NRg\xe0\xda\x17\xf7\x11\xb6\x1d\xc0\x10\x93D\xe3\xd2\xc9\xac\x11\x90\x95&\xd8\xd6S\xe2>-\x80\x9e\x12\xf6\x18\xcb\xe5\xae\x14f~\x1br\x98\xc6\x0c\xe5\x84(^\xe5C\xad\xc2G\x9c\x11",\xaeO\xc4\xbd\x92T\xb7(\xb4\x92\xa9\xa3O8\xd3\xb5\xc1\x946Z\xf15\'n\xb2\x98\xae\xae\'\x8dzS\xcb\xe5\xa0\xbbq8\x12\x8cU\xd2\xe5;\x02`\xbd\xb8e\x1b,\xe0\xbd\xcc\x06Ji\xce0\x9386\xb0EF\x1e\xa8?\xcc,\xafj\x91\xe2\xd5n \xa1\x95<\xb7D\x81\x10\xfe\xe5Y\xb9|\xf3\xaf\xd4\xe4]\xc0\xd1\xf1\x15\xe1\xaa9\x0c\xe9\xd2J\xac]\xf2\xd7]\xc9\xf4R\xde\x92\xf9u\xd8\x07@\xb6\xf4r\xa2\x19\xe9\x19\xfc/4L\xb9\xd5`L\xcd\xaf\xaeB\x86\xf7\r\x13\x94&z\xc2h\xea\xd4\xd7\xcf\x1f\xcf\x12T\xe4\x05\xc8v\r/\xdd\t\x87\xfa\x13\x00kF\x98\xd3\x7f\xe6\xe7 \xa2\xe2\x96\x81\x9b\xec\xc9\x07\x10}\xfc'
|
|
|
|
|
|
2024-12-14 17:54:47.903927 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1274
|
|
id = 1584
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 1254
|
|
chksum = 0xca7f
|
|
###[ Raw ]###
|
|
load = b'E\xf4k\x98\x9b%:\xa7\xd9\xef`\xab\x81\xca\xb5(z\xb52#\x98\xec\xde\xf8w\xd4\x05Q\xa3\x9a\xd5a\xc8\xb31\x8d\xbf\x1f\xee[\x1e\\\xf3\x1eY\xef\'l\x89\xe6\t!\x88o.\x1eB\xfc\x0f\x18XA\xc29\xc4\x1c\xd4ea>\x9c29\t!J\xe8\xe0KC\xa4\xe8\xcb~\xae&\xb3@\xe7\xd9\x85\x10\x95S\xf4=\xc0\x16\x0b\x10\xf7\xd4\xfe\\\x90\x0f\xfd\xc1U6\xe8\xb5\x1aL\x10\xee \x00\\\xdb\xa6\xd0\x16\xe4\x17\xe8\xe0\xf4\x1b"?\x0b\tt\x90\xa8\xfb\x8dE\xb8\xf1\x99)\xfd\xcby\xf7\x8eM\xbf\xdd\xcb\x15\xdc\xc2\x99\xdf\x92SHJ\xe6\xcb\x81\x17\xec3\x8d\xfaA\x0c\x1b\xb5\xc54\xcb\x92\x91\xf8\xff\x82\x98r\x84\x94u";\xdd\xd8)\xe6\xbcT\xff%\xfe\x16\xd4k\xa9S\xf4y\xf7\x1e\xab\xf6H\xbe\x07\xd4"\x1a\xdc\x84\xc1^\xde\xed\xff\x17Dr\xc7\x00\xb5\xa16\xcaH\xd6\xe8\x9d\x00[\x82x\n\x1d5\xdd\xe30|\x87\xb9\xe8\xc0B!\xeaJ\xaa\xa6\xd3B;\xac?\xab@\x1a\xab\x9d\x0f-r\xd4#(\xdc\xb1{\xbf=n\xbc\xe6^\x82\x947[3\xadl\x90\xe2\x16\x13\xdb\xcf\xd6\t(\xd3\xa2\x95\xf6\xa85E\x0b\x95\x9f\xdcU\xd2\x16\xfc\xc5\x9d\xd7\xeaj>]\x1f\x86\r\xb8\x1fy \xc4\x07\xed\xa7\x0f\xd3\xc9N\x06R9\xc8\x8bo\xa6E\xe6\x142y`\xef\xd2v4\xb3\xf9F`\xc8\xf2\x16\x98\xda.\x8b\xc0\x91\x19W/\xaa\x92\xd3\xd2A2\xafD)q%\t\x8bu\xfa\x81\xfe\x1d\xc3\x06\x87\xdb4<\xc37\xc1d\x16\xd5\x1c\x88\xd749\xe8vS\x01^q\xdd\xc8\x80m\xb6u]\xfa\xc5\x89\x82Q\xe9\x06\xb2\xca\x9aX\x014V=\xfb\x1a\x1c4\x17\x1a\xff\x15\x81!r$\xe3\xeb\x8d|\xf8W\xec\xa6\xb83\x15\xb3\xc2\x9b\xfa\x13\xd9\xc4=w\xb4\xad\x00\x08\xf7\x9a\x95e\xb7p \xcev\x84\xdf"\xffw\xc1{\xbc\x0f5\xd3K/\x92rU\x13d\xf0W"\xa8\xbe\xfe\xa0\x98\xc2\x03\xcb\x9c\xc9\x9fx4\x12\xb2\xf7W\xbf\xa3\xf3\xe1\x1bA\xa6W\x8f\x8c\xb1\xe0\xa8\x06x\xad\xcfP\xa86\x85\xf0\xed\x98\xc0\x8d\xed_\xee\xee\xa8v\xdb\n a\x04h\xf4tL;1\x89\xee\x85Vw@\xc2\xab\xd8\xe9;\xa0\xa9\x95\x84\xf01\xa61\xa4\xd1\xe1\xc9pk\x03K\x86\xbc\xb6\x12\xec\xc8\xd4\xd7\xed\x8a\x83\xac\x08il0\x1fb\xd56\xf1\xd6\x89\xa5\x1fJ\xe7\x91\xe8\xfe\x99\x8fo\xf0\x84\xec\xbaU\xf6i[\x81{5\xe2\x1a\x16$\x00\x89\x89$W\xbfo\x85Z\x7f\xa7\xca\'\xa7Ef\xe0.!\xbbU,+g\x95\xfe=\xffA\t-\xebk\x9d\x7f\x80\xf5\xeft\xd6\xbe\x0f\xc5\xe7\x13\xe9\x81\xaf\x1e\xe7T\x0flP\xcc\xfe\xaa\xfc\xfc\x93\xac\xf0\xe6\xb2v\xb6\xf5\xd3\xa4\xa23=\x85\x15\x11\xb3hJ\xb0p\xd5\xba\x81\x18w\xce\r\xc4DoCj\xfea\xd5\x05\xdbN\x84e\x98gS\xd4\xad\x02w\xb5\xf5s<\x8c\x7f<`"\xd4\xe1\xe5\xcd\x16\x1a\x83\xd2\xd35\xd9\x02\xd5\x04\x80n\xc72y\xa6\x11W\xb0\xf3c\xc6T\x13\xc5\xec\x9c\xe4vDw\x8a\x99\x9a\xe4\x8c\xe2V#~\xdc\xa5d\xf0\xe5\xef\xe3\x8b\x00\xa9\xf3<a\x0f\x03\xe7C@-\x04x\xe98\xb6\x86\xc3/\x97\xb6<\x990\xe9\xf7\xc2\t\xc2y\xdf\xa4\x81{\x06\x03\xf2l\x12\xbc\x15\x11W\x8d\xf8\xb5BG5c.\t\xbe6]7\xe0\x08j9\xc7^\xe0\x8d\xfc\x07\x82\xd4%\xf0C\t\xa2\xb9-\xa7\x9b0\x007w{\x1dSC\x94?\xf5\x14\x07\xafF?\x17\xe70\xb1:\x10\xf13\xfb*i\x16X \xff^F\xc0K\xa1b2.qN\xb0\xa3L4\x95\xc9\x80{$\x19\xe1\xd8\xfd$0\xe8c\x1fp;\xec\xd9\x87\xdfi2\x91\xb1\x01\xb6|\x0e\xd8\xa8Cx\xcb3\xf4\xea\xe8\xd61f|\x94 \xc9\xab\x86Px\xd9d\xf7\xdc\n\x9f\xca\xc7z\xa6\xd3R\x94"\xff\xd3A\xd3J\x98\xd2\xdc\xd5\x81L\x12\x107j\x1et#\xf1Q\xc0\x18\xa0\xfd\xba\xe33b\x1c4\xcfS_`\xd8SR\x85\xd5E\x17\xe8\x89\xdd\xbd\x03\xf3\xba\x8a\x01\xe7\x1bv\x1a\x7f)h\x14\x03\xbd (:T\x97\x18c\xb8(fC\xe8+\xd9\xdcG\x17`i\xffv\xaah\xabV\x88\xea\x1c\xaa\xbe>|SY\xf3\xb2>\xe8H[\xbc\xf6_\xc3\x9b\xcfg-c\xcf\x1c\x92z#\xe8&U\x17@H\xfa\x05\xcc\xe8 \xc7\xade\xb5\x06\xd2\nI\x1e\xe9\xca*DB\x1d6\x1c\x00ps\xfd.\xcb\x06\xae\xfau\xf5\x93/\xf1@\xfb\xac9\xf8mv\xd6\xa3\xc9\x16\xe3\xb5\x13r\xf7\xa9\xa0\xd4\xaa\xee\x8d\xday\x8d\x06^\xbfU\xd6\xf2\x8dQ\xe0\x99\xeb\x93\xcc\xfe\x97X\n\x9e6\x01\x19iy\'\xd4T\x8d\xf3\xfbd\xc5m-\xcby\x03\x91{\x94\x9a\xc7\xe8\x87\xdc\xa7uJ9j\xc0\xcfT\x03\x97\xc6\x18\xe29\xd5\xa0G\x94\xe4\x84\xb7q\xd2\xaa\xb1\x98A\xeb3~\xdbgo\xae\x9e}\x95\xea>'
|
|
|
|
|
|
2024-12-14 17:54:47.909572 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1238
|
|
id = 1585
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 1218
|
|
chksum = 0xca5b
|
|
###[ Raw ]###
|
|
load = b'U\xf4k\x98\x9b%:\xa7\xd96\xa6\xbe\xd4\xf7dE\xf4g\xa1\x8a\xef\xbf\x93\xbf#\xc7J\xd08\x1e\nV\xc7\xe6\xda\xf7\x95C\'TgN\xc9p`\x0e\xf2\xca\xb0W\xc0JR\x0c\x94I\x82\xfc;\x86E\xf1\xdaEi\x02\xa3\xba[\xd9R\xf2>\xd1\x05.\x93p\xb3+\x9d\x80C\\\xe8~\x04\x93\x99\x85\x11\xe1=\xc9\xf8: dN\xef\xa8\x96}\xf9\xff\xc5\xbfW~\xf8\x80\xf5\xe9L\xe9\xc9\x9c\xe4G\x01G\x16"b\xb5\xc5\xfb\xf5\xb0f\x9eC\xe1i\xa2\rc%YA\xc2P\xfb\x04:\x84\x1c2?\xca\x9aZd\xb6\x16p\x9b\x9e\x08-\x1f\x9c\x19\xf3\x0b)\xdbr\x17E\x93\xef,\'\xf3\xfe\xc5r2Y\xb3\xcd\xf3\xc5\x9f8\xc7\x08\xc1O\xb7\x0e\xa3\x81\xcc\xe3\x94\x81Z\xcfu\t0W:+f\xdf\xfcVr\xae\xf0_\xa2\xfdi\xd0\xa5\x19w\xb2!\xcc\xc1c\xe8l\xf3\x93 \x0e\xb3|\x0e\xd6Dm\xd8\xac`\x8c<\xb8\x17\xfa\xb0\x16\xb5\x0f\x83\x1a\xe8\xfc\xbf\xa6\xac\x06B\xf4\xfd#\xa3\xa3\xce\xc6\xe9J\xed3\x7f\xb1\xf7\xf7\x02\x18\xfc;<\x96\xd2p6[\xda\xe7WS\x1f\xea}\xffI\x95\xf7\xd6\x97~M\xe0\xd7\'\x91\xfd\x10\x8d\xd8t\x96V\xd9\xcb\xcfqT\x86\xae)\xe5\x06,\xfe{\xd9\x0b\x83\x97G\xae><\x15\xe5\xc5Rv\xfb\x8aM\x82T\xf5$\xbc\xcf\x1a\xb5^\xfb\xf6\x0c<\x8f\xedPy\xad\xe6\x9a\x1d\x17\x97?\xa7\xc7\x1c#\xf2\x17q\xc8\xaa\x7f\xe6\xd9Z5i\xb8\x13\x93VM1P\x13%\x97Z\t\xafqR\xdc\xbf\xabY\xad\x8f\xe7\xd4\xd0 $\x02\xe4\xf74\xee\x9e\xc1\xdf\x95\xdb\xe9\xb1\x83l\xd0\xf9\x9bW\xb5;\x82\xaa V`\x9c\xac\xd7\xb9[\xb8\xce\xddJ%\x14\xb6>\xfcE\x800\xe0\x8eI\xbb\xe8%T-`\x07\x84Omh\xf5\r\x98/\xe03d\t\xd0%{\xa5\x14HI\xce\x8a\x00\xdd\xc4\xb4_\xf3>H<\x90{cw\x85\xb85\x11\xce{\x82\x91#\xb8\xed>\x81cj\xaf\xd4\xa4\xfaL\xe4=\xc1,\x17\x162\xe1\xe8\\=\xcbkat\xdf<L\x97\xb8\xdc1\x89I\x7f\xc5\x83\x05r>/\xa5\xdbTBh\xa6\xc2\xbe\x167\x8b\xfe\x0c\x80\xea\xa1\x91F!\xb7\xab"\xdbR\x89\x1a\xe3\xd6Q\x9b*UR\xb2\xaf\xea\xa65=\x15\xe9\x89\xc3\xb5\xfe\x98H\xdb\r5_TWO%\xfa\xed\x81)\xfd\x04F\x1f=\xf1\x07~\x81\xce\r\x0b6^\xa3\x06\x80\xfbL_u\xa5h\x1f\xb5d \xae\xed$Bm\xcb\xe6W\xba\x1f\x88\xf9\xc6\x92\x00o\xd4_v\xd0\xffN\xc0\xa9\xcc\xf7\xef\xa4+\x17\xdc\x9a\x1a\x7f.\xb8\x89\tx%d\xa5\xea\xce\xcfR\x14G\xbc\xce\xbf\xdd\x8e\xb1\xf7\x06\x07\xd7C\xd5\x8d\x86\xa7\xfc\xd7b\x04C\xeb\xbe\x99}G\xc8\xc5\x90\x16\r1W\x92\x02Lq9 \x18k\xf6\x82\xe8g \xfat\xbd\x15#\x06[:N\xcf\x146\x93]\xc7s\xfbUS\xa5/w\xc2~\xde\x8c\xee\xdf\x9e\xc2j \xb3\xc2\xedEw\xea\x17\x1a$ "5\x99?\t\x18\x91\x98\xba\x84\'j\xc3\xfd~^\x1b\x026kL\xbb<\xa8\xfb\\S\xf1\x02{X\xac\'qKH\x93*v\x1f\xf7\xaakl\xae\x17\xede\xacc<\xd2\xc4m\xdc\x8eb\x04}+w\xa7\xd8jR\x98T\x1d\x8eb,&<E$\x7ffBZ:y-\xc9\xea\n\xa0{Y9\xca\x08\xbf\xa43\xb9- q\xd6\xc79\x95.\x14\x19\xa1\xb5\x1e\x1a\xa3\x03\x964D^\xa0\x97\x85\x06\xc2[\xf5Y!WG\xe7/\x81\xd0v\xbd\x97\xb8Y\x9d<fe\xbe\xe7\x12d#\x0e\xd3\xb4\x80[)"\x80\x82\xad7Z\xf9u\x14[\x0b\xae=a\xa5#!m\xe7Xc\x83\xa9F\x98Ij\x1a\xe6bPW+\xdecj\xfc\xe84\x94g\x83#\xbd:\x16)+\xcd\xb0P5m\xf9"~\xc9,\xc3\xff\xef\xc5"\xda\x18I@\x9eux\xe9X|\x9a/\xdbB\x84\xb1\t\n\xd4\x929\xd3\x15\xf3\x08\n\xbe\xaa\xe8u%\x97\xf6\x9eO\\:\x12\xde\xd7\xf2m\x13P\x88W\x1e\x94<q\xe67K\xda\xcf#L|\x9c\xd1yvvgHx\x15]\x9e\xdc\x0b\xae\xa7y\xbbMa\xfeVC\xfc:\x05\xc7X^\xca&\\f\x01\xa8\x04\xbf\r\xafl\xe0\xbe\x95kb\xee}\xa3\x1738u\xa5\xce\xd0\xdf\x01\xe5>\xc3*\x07Y\xbb\x08\x99b\xd4\x06\x96\xb6\xea\xf1i\x7f\x0f\x97",\x9f\x85\xca[\x18 \x04U\xdc\xfc\x08RH\xd7^g\xc0i\x0cz\x8c\xff\xc5\'\t\r\x89\xf3V\r\xb7\x7f\xb4\xbd\x04\x97\xb4\xc4\xe7\x1e=g&i\xcf\x10\xf1\xbd\xcd\x82\x8c\xda|A4\xee\x17\x1b\xee\xea&\x84\x92\x1al\xff\\p\xb5\x8bf"\xc6\xdd\xac@.D\xa7Tr\xc3 \x06\x0e\x06\xd3\xab<\x10\xb0\xb4\x1fJ\x80e\xde~\xff'
|
|
|
|
|
|
2024-12-14 17:54:47.914785 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 497
|
|
id = 25550
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534013
|
|
ack = 3808769646
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0x822c
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\xc4\xc8\xe8e\n\xd9\t\x89\xffw\xad\x94\xf8\xba\x95\xc4Z-\x03C\xb3\xd9\x14\xe0\x076`x0\x9a\x885?\x81\x9b\xb7u)\xbe\x95\xd1dY\x16\x16\xfct\x8c\x1f\xa9\xa9 \x1ck\xaa\xf9\xe4\xc9\xeb\x12i\x13\xc4@sG^1\xfb\x9f\xdd\x13\x0b\xcd\x95T\x11=_\xea"\xe5\xb3\x8eo-W\xfe\\\x1d\xce\x9f\x08p\x18\xed\xa0\x1f\x87c\xcd\xf6\x10\xd1|1\x00\x83\xd8\x1e\x0e\t\xd0X\x9dY\xd7\xad\x95\xca\x17\xdc\x19\x1e@\xeb\xe6)\xb9\xe0\xa5Y\x1c\x8a\x84(ZY\x83j\xb9\xb9\x1a\xba\x1f\x9e\xb96\xf3\xef&ka\x99P\x02z\x86\x8c\xf2F\x05\x9d\xab4.aq\xbe\xb1\xd54Og\xf0-\xd2\xbf\xbd8\n\xa1L\xa4\x9b\xceM\t\xd8\'q\x07\xc5Zy\x16\xd7\xa2<\xb4J :\xf2\xf0c\xb9\x92\xe4\x94U\xb6\xb8\x90\x0b-\xe2c)\x80\xc3\x1cb->\xa6\xac\xdb\xd2c\xdb4\xca\xa4\xa3\xd79\xc5\x13\xf0\xf6p\xae\xacO4\x15t\x12\x9f\xc5\xf6F\xd0\xf8\x14pu\x9c\x85A\xd1\x89\xcc\x10\xe6\'\xe8wf\x1d\xd9\x97\xa6tJ\xd5\r3i\xc5V,\xfd\x11\xc6\xc7\xa8\xdf\xd7_\x84v$\xec\x80\x07U\x18\x8c\xd0\xb3^\x8d\xc7E\xe8\x0c3\xbfS!\xa8\xd4iBh3.(\xf8\x87\xf1\r.\xe2\xf0\x84\x11D\xc5\x90\xb6U\xe8\xc0w\xd4v\x15\x89vY\xcb-q\xee\xde}\xbdt\xc6\xc5\xe9\xc2\x80\xf4\xed\xcb\x01\x0f\x8b\xec&\x07\xbb7\xb4\xeeBt\xb8@\x97\x10\xc9\x85\xec\x14aG\x8d&\xb5\xb4\x1f\xd77\xc2\x9b\x8a\xf1\xaew\x0c\x92\xd2\x14\xe5X\xb0\xa1\xbd\xfcV\xdc\xf2\x7fy\x85\xd3\xb06\xdf\x0c\xb1\xb1(\xa0\xbb]H\x95\xfe\x13v\x97!\xee*\xd2I\xca\x94UW8\x1ej\x9f\xd9|^\xcd<2c\x8c\x99|\xf6u\xaa'
|
|
|
|
|
|
2024-12-14 17:54:47.918041 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 127
|
|
id = 25551
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534470
|
|
ack = 3808769646
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0x80ba
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00R\x132\x05ZY\xc6lZ\x8e\x07\x84"\xeb/\xbfJO\x95\xa5\xec\xbe\x0b\xdc\xf2L*Q\xcc\xc7\xddB\xc7\xd9r\xf2\x13\xb8\x06\x03<P8\xb8\xc309\xd8*\xf9`\xf3\x9dvS&\x03S\x88h\'\xa4FF3\xd6*\xf6\x12\x01\xf3\xa7I\xf3\xcbqG*k\xdcX\x87\x01'
|
|
|
|
|
|
2024-12-14 17:54:47.924576 - Ether / IP / UDP / DNS Ans b'image-scdn.cdn-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 321
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb64f
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 61259
|
|
len = 301
|
|
chksum = 0xf457
|
|
###[ DNS ]###
|
|
id = 3408
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 7
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'i.scdn.co.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'i.scdn.co.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 173
|
|
| rdlen = None
|
|
| rdata = b'image-scdn.cdn-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'image-scdn.cdn-gslb.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 38
|
|
| rdlen = None
|
|
| rdata = b'common-eipb-ak.spotifycdn.com.edgesuite.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'common-eipb-ak.spotifycdn.com.edgesuite.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 10336
|
|
| rdlen = None
|
|
| rdata = b'squadcdn.scdn.co.splitter-eip.akadns.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'squadcdn.scdn.co.splitter-eip.akadns.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 29
|
|
| rdlen = None
|
|
| rdata = b'i.scdn.co-noeip.akamaized.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'i.scdn.co-noeip.akamaized.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 182
|
|
| rdlen = None
|
|
| rdata = b'a1520.dscc.akamai.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'a1520.dscc.akamai.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 15
|
|
| rdlen = None
|
|
| rdata = 2.18.188.146
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'a1520.dscc.akamai.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 15
|
|
| rdlen = None
|
|
| rdata = 2.18.188.131
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:47.931148 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 47880
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xc7f
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808769646
|
|
ack = 1299533921
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0xd503
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:47.940277 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 612
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7b03
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 592
|
|
chksum = 0x1085
|
|
###[ Raw ]###
|
|
load = b'@<m\n\x0c\xf6\xf2\xccK\xb3\x06\xde\xd2pM\xfd<0Z_\x1d\x16.\xdb\x8a\x042\x9f\xc2 \xd4%\xf0eX\xab>\xb2\xaeI\xd0\xe3*\xc2\x16\xa7\xef\xc1N\xfax.\x1f\xda\xc4\xf0\xfe\xa7\xba\xb3\xe7\xe9\xe4y\xe4\x7f\xc6\xea\xd5,H\xea\xe6\xf2\xfc\x1e\xe0\x853\x8b8^\xd8\xeb\xa0\x16\xc0\xd5P\x8d\xa8C\xb0P\xb5\xc4v\x7fO\xbdb\xdc\xfd\xe3\x86\xb8o\xef\x1bw\x07JW\x87\x1fJ\x0c\x9e<\x0cF;\xbd\xddy\xe0\xc8\x9a\xdb\xff\xff\x02O\xd2B\xf7;-|\xa6\x8b\xc7\xa66\x10.\xf5\x0f\xc0\xb5\x10\x99\xe4!.\x98\x98\xe1\x8aB\x02\x86\x8da\x01\x1a\xf7\x86\xe6\xecM/bw\xec\xb1E\\\xc83\x8e\xe2\x87\x8f\x1e~\x9dA\xf2?\x07b\x00\xfc\xfe\x862\xcc\x1e\xf8\x17v$\x82\xf3b_\x1c{\xd0\xf1%\xf6\xf5>\xabzZE\xc25\xe0\x02\xb5\xa9\xbc^\x9ejtj}\x11\x84\x90q\x9c\xce\x91\xc0\xe2\xcb\xe4\x0f\xf5i0n8\xd478\x92\xf8^\x00&\x9b\xd9n\x0fw#z_^\xee\x025\xfa\x01\xd5b+"\xb2\x83\xf7q\xa5\x81\xe5E\x06\xa1\xfa\x15*\x03\xdb\xc4]7_\xe2\x07\xe6\x9b\x1b\xbf\xe2#Vq\xd2H\x05\x89JPw.LN\xdf\xc0\xfa.\x1a!\xe6\x8c\xd5\xd9\x97\xcc\xc6\xa4u\xa7\xef\x01\xe1?Q:\x13y\xca\xc2\x10\xd7\xe0\xff\\6BQ7\xb7yU<v\x8d6\x0c\xc4\x8fh\x05<y\x15\x8d\xeb1\xb4\xd2\x94\xb3Y\xde\xab3R\x8d7\xa8\x98?$\x8c\xad.\xe3}\xbfQ\xa1\x8e\xeb\xcf\xcd\xfc\xf8\x05\xea\xf8\x06\x0e6\xb7\xf9;\n\x0f\x88\x7f\xad\xb4\xf0\x94\n\x0e\xdb8S\x06\xe9\xae\xb6O\rksb\xde%"\xbb\x93q#\xe6\xf5\xf4\xaeWnv\xb6\xdf\x80\xe7\x87 \xc0H[x\x92\xc1\xbb\xaf\xfdP\x87j:\xe6\xa6-\xa3\x8a\xfc\x8bN\xc5\x94T\x91\x9d#\xbc\xce\xb2"&\xde\x83\x9bsT\xfdP\x1a\x1e\x1a\x16\x91\r\x99Cy\x1c\xd8\xbb\xcc\xa8\xf7\xfd\xd6f\xb0\x85i\x19$7\x1e8s\x01\xb3\xf5\xc8\x8d\xc9\x02\x1e\xc2\x19\xcd\xa89\x8b;\xd2\xb4\xa9\x89\xeb\x04\xbc\x91\xff\xd7J\xf9\xbb>B\x10\xdad\x1aRh\n\xa9\x99U\x11\xbd;\xda7\xf7=!\x84j\xc4*-\xd3o\x15\xb5\xf60B\xa3!\x0b[\xe2\x80Jn\'5\x18'
|
|
|
|
|
|
2024-12-14 17:54:47.948623 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 149
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7cd2
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 129
|
|
chksum = 0xde9c
|
|
###[ Raw ]###
|
|
load = b"Z%\xe8c\x89^\x8d\xdf\x160\xdc\x0b\x92\xf5\x03~Gs#\x90\t'\xf3r\x08\x86.\x0f0J\xe1\xf882\x92W\xd2#!\xda\xea\n\xc8C&\xf6|\x9f\x84\xe2\x95\x0c\xed\x0b;\xfe\x0bF\x1aT3\x8f\x19\x88{#\xed\xf5r\x8f\x9f\x1aH\xb95\x8cZEI\xcf\xb7U\x9f\xb9@ \x93\x0b\x9dU\xafb@\x9f\xb5\xc4\xfa\x9e\xbc\x17\x91\x03\x90\xc2lV\xf9|X\x8ek\x8d\x93\x88\xd5W\xb5\xe0\xd7`\x06"
|
|
|
|
|
|
2024-12-14 17:54:47.953155 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 311
|
|
id = 47881
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xb6f
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808769646
|
|
ack = 1299533921
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xdb3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\n\xda\xb0\xb7#@\xa9\xf1U\xdc\xb8\xb9\x98\xa0G\x1b\xefy\xbdg\x1c\xc8\xcdq\xfd\x8c\xc2\xb59.Zeh\xba\x14\xda/N-w\x05\x10\xc9\xbb9j\xba\xaaYw7\xf3\xcd\x1b\xcd4)\x98\xddj\xc2\\\xf0=\xbd\x00\x1aK\xb6If\x00Q\x07x\xb9\xa6p\xa4|\xf2&\xa3\xec<$\x81\x17\x86M\xb7\x0b\x8b\xfc\x91\xc1q\x97\xce\xea\xd7-\x94\xe5\xb8;\xe8\xd2\xe3\x94r]2\xc53\xcd\xf7\x1aP\xd2V\xb3v_P\x89\xb5\xc2\x86\xb5\xb6u\x80\x93\x9b\x04\x1d\xb3+\xce\xe5\x0b\xd2\xde\x93j9\x14E\xfd\xa3N\xe47q/h\xf7\xbb\x84\xb2\xd4\np.\x07\r*\xa3\xe9\x14l\x8f>\xa0\x1f\x92ZBIg\xd8s\xfe7E\x1e\xb5\xdb\x81\xf1\x1d\x88^b,\xc0\x83\x01hj\xf4\x08M\x93\xd0a\xd0\x1bd{1?k5\xc0\nd\x00<%\x1dQ\xbfdt\xf3\xe8W\x8d\x96\xfeQ\x04/Z\xfd\x0f\xbccdV2*6\xb2r\x0e`\x13\x1e\x97\x08NnsO\xd8\x011Rj\xebY%\x91\xa2'
|
|
|
|
|
|
2024-12-14 17:54:47.955829 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 47882
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xc7d
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808769917
|
|
ack = 1299534013
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0xd398
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:47.960291 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 47883
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xc3f
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808769917
|
|
ack = 1299534013
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xea8c
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x008\xa6Z\x95\x8e\x05\x95\xfb\xcaz`H\xb0\x95\x83\xfdq\x86\xd8\x0c\xf29u\xed5\xd8\xb9fT\x94\xdb2z\x0f\xc0\x08'\x1fh\xff\x14\xc7:`yqpdT\xfa\xa8\xa4\xb2\x8d\xc0\x0et"
|
|
|
|
|
|
2024-12-14 17:54:47.963667 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 47884
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xc5c
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808769978
|
|
ack = 1299534013
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x16ca
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1a\xd8\x19\xff<\x06\xe7\xae\x868M\xf2]:\xdd\xd2>[6c|v\x90\x00Mml'
|
|
|
|
|
|
2024-12-14 17:54:47.966526 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25552
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534557
|
|
ack = 3808769978
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:47.969037 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 61
|
|
id = 30906
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 41
|
|
chksum = 0xc5c0
|
|
###[ Raw ]###
|
|
load = b"T\xea\xa4\xfd\xe9\x04\xea\xaf`'\x80d\xbe+\xb7\xa5\xf4u\xd4\x0c3\xeb}\xbe\x18\xcb\xe1c\x9b\x8d\x9b~0"
|
|
|
|
|
|
2024-12-14 17:54:47.972018 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 61
|
|
id = 30907
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 41
|
|
chksum = 0xc5c0
|
|
###[ Raw ]###
|
|
load = b'Y\xea\xa4\xfd\xe9\x04\xea\xaf`\xfe\xc9\xf5\xb5,\x8c\x17#D\xfe\x03\xbf\xde\x99\xac\x9f\xf0\xfd0T\xa4\x07\x10\x88'
|
|
|
|
|
|
2024-12-14 17:54:47.977377 - Ether / IP / UDP 192.168.1.11:63056 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 60
|
|
id = 30908
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63056
|
|
dport = https
|
|
len = 40
|
|
chksum = 0xc5bf
|
|
###[ Raw ]###
|
|
load = b'L\xe5\xa6\xeb\x0f\xbbm\xbf\xd6\x06.&xS\x05&\xa5\xbb\x8b\x9d\xd0I\xb2\xc7\xab;n\x0fa\xae@\xd9'
|
|
|
|
|
|
2024-12-14 17:54:47.979825 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 25553
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534557
|
|
ack = 3808770009
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 511
|
|
chksum = 0x8082
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1a2\x92&7\x06L\xdc\xdf\xdb\xebv\x18\x0e\xba\xf6C&\x15P\xb6M"\x8c\xaf\x9bV'
|
|
|
|
|
|
2024-12-14 17:54:47.983031 - Ether / IP / UDP 192.168.1.11:61224 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 30909
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 61224
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca81
|
|
###[ Raw ]###
|
|
load = b'\xc0\x00\x00\x00\x01\x08\xca\xcc~X\x91`\xedq\x00@F\x00\xb7\xf1\xdf\x1c\x0b \x07\x171\xae\xac\x02\xf3\x14A\xa2G@\x03F<O\xae@U\x7fU\xaep/\xe8^\xf1}/\xb5$\xd4\xd9~=\x18f\xec\xa6\xc2l\x1e\'/J.Qt.\xac;\xaf\xe7\xde\x93\xe7\xf0\xd6\x06\xe1)\xa8\x02D\x89Bv\x0c\x19\x14#y\x1a;\xa3\xc1\x18\xb8\xd4</ ~s\xeeh\x06\xa65\x7fPKW\x16[\x90_\x1f.\xcb\x84\xbd|\xd4\xcc\xfd\x80[w\x03n\x85L:\x15\xa4\x85\xa8\x90\xcf%\x93\xc5%\x92`{,y\x94\x82\x86\xc0\xa5\x17\x0b\x16\xad(\xd3\xb24\x1f\xb1\xd9\xe6\xeeP76\xbe\xc5\xac1RWg\xeb\\L!\x91:#\xb6\x7f\x08\xf9Vy>q\x1b7\xcd\xa7\xd1LYs;\xcf\xea%(\x15\x1b\x81\xe3x\xba\xbd\xbc\xde\xea\xf6\x06e\xcd?\xa2\xdbzo\xc6S\x8b\xad\xefv\xf3"\xdd]\x0fY\xb27%qoa\x9a\x02\xd3\xa8\x0f\xa2Pg\xe2\x93\xf5\x06{$\xdd\xc9\x9d\xb3\xe7\xd9D\x8c\x84_\xe8\x82\x85\xd0 +\x91Jd\xcbs\x889g\xfd\xaa\xe8\x11\x96e\x02\xab\x02\xc3]\x80M\x12\x04\xc0\xf2\xd5\xf8\x19W\xd74\xab\xb7\xd8\x99\xe1>\xacz\x83\xfd\xb6r\x03\x1c\xb2\xcc\x87\xfb\x93\xa5j\xf6\xf0J\'m\x9e\x88\x1c|hm\x170[MB\xb7\xc2\x9c\x85\xfb\x8f\x12\xca\x89_\xcc\xbdp\x92Aa\x9cv\xfa\x04\x07M\x15\xe4\xb8\x88\x9dc\x1ag\xe5b\xc1tZ\xf7\xdb\xeba\xf3V\x10S"0\xfb\xf6d\xb1\xcd`E\x19.\xa5*\x14\x86\x1d\xa7\xac\x12\xf9s\xb7\xe4\xe2\xc6\x16;\xec\x05\xc6\x92\x90\xd7\x15\xb8b\xeb\xa4~\xf5&\xdcn\x0c\x1e\xb4\x1e\xcc\xa8\x81\xedX\xed\x00\xf9P\xe3\xf2\xdd3\xaev\x9a>\x9d\xf1q\xb8e\n6)B\xa0\xe8\x0e\xe7P\x0bu\x83\xe6a\xe4\xc9d\xb4I\xd41\xa8S\x80\xc3\x8eIEI\xa6\xf98\x88/\xe2\x7f4C\x1bc\x87\x1eb\xc3\xa3\xad\xca\x9ekT5\xd7\xcdh\xfb\x83},G\xe1(\x0e\xf8*\xda\xdc\x89\xcb\xc4\x0bCD-\xba\xe2\xb0IM@3\x0b\x0b";\xd4\x14\\\xf5\'2\x10\xd3\xda\xc3\xa4\xfe\x0c\x13^\xac\xda\xc9B\xf82\xaclKx\xe1\xa2\xec\x08c\xe7 \xad\xca\xdeh\n)\x87\x14\xc8p\xce\xa3\x8c\x0e\xa2+\x8a\t6\x97V\xfa\x8f\xade\xbc\xd9,\x1b`w\x13tk\x8d\xe3%K\xec\xbe\xc4t\xdd0\xdd\x16M\xd1%\xaf#\x8bg\x9e\xe1\x02\xd5\x08G\xc2\x7f\xe3\r\xb5\x96\xe4\xbc\x95rN\x86\x9e\x91(\xfc\x19\xf1\xc1\x85\xd5*\x89\x19(\'\x1d\xb8\xb3s\x7f\xddi\x87@\x1e\xaaKd7\xc3[g\x04;\xb4\xac\xbc\xe3o\xbeZ\xcd\x0c\xc3\xa8a\x1dR9\xd4O\xfbI(H\xf0\xeeJ\xd1\xdf\xf2\xe4\xe1#~<\xd3\xb7-#\xb9O&|\x9d\x8c\x05Sd\r.\x19\x1f\xcf$\x17\xff\xaf@4\xdc_\x94,\xf2\x1c\xb4g\xb9S\xd0\x9c\x92\x9dDT\xd5\xdan\xd1\xc3\xda\x81r\xfc\x1168m\x19\x84\x03\x97N\xebnc\xf7\xd92c\xaeM\x13\xae;\x17\xc1\x83\xcd\xef\xc3\xd3 \xd5\x06\xeb\x9d\xa8M\x10Q\xca:"5I\x1d`y\x05\x19\xb3\x82\x90\xfbZ\x1d\xe1|A\x0c4\xa9\x14\x8a\x91\xf9b\xf3"\x8aW\xa4j\x975\xa5\xc5\xed\xab\x88\x0f\x02\xfe\xffn$\x87\xc3\x115\xe5\xde\x89C\xfc\xd7\xc1\xc6~Q\x89\xf1|\xcb\xc0\x97\xa08V\x8d\xec\x0c\xdcu\xd3J\x0e\xfe\xbd\x8d\xb0&\xab\x8b4\xda\x03o\xf3#\xd6\xed\xd9\xac\xac\xf2\xee#\xd0\x14u\xc2\xfa\xfeY3_k/\xee\xc5\x07G;\xd7P\x8fx\x94\x9c\\h\xdf\xd3ik\xd0\'\x94\x1d\xed\xbc\xd2.\xfbB=\xb9\xc1\xe7Q|\xfa\x8f;\xfe\x87\x12x\x8a\xf6\x80\xe08\xdb\xe3\xb4\xc4\xd7\xe6\xe7\xaf\xfapx\xb0\xf2\x83\xf3`\xe6\xa3PV\xfa\r\xf9\x92\xd9\xca?\xb1L1\xd7r\t/\xe8\xeaX\xecM\x8c\xc6\xa7,\x0c4\x0b\\\x8b\x04,\xe7!\xf6;\xfd\xe5\xbcm\xe6\xa3\xa9\x94V\xf1\xfdd\xb4\xe6\xe0O\x05\'\x1a\xc4\xeaYY\xb1\x022\xa7\x88\xb1\xe9\xcen\xe9\x84\xe5\xf6\xe0D\xe14\x14[\x1c\xebD4\x82\xf2`0\xebx\xeaO"\xee\xb7m\x16\x8f\xed\xa4q\x00h\xbay)T\x1a\xdf\xa4\x12\xeek\xac\x12]\xd2<\xdc\xab\xab\x9f?\xbd\xee\xe8+\xa9)\xa4\xbe;\xe6\xf3PNs\xa59\xbd}j\x80\x8e\xc7b\xd4z\x80\xa8D\x1e:3\x10\x7f1\x8b42\xe6\x026\x8c\xe4E\xb5h\x81z\xbb\xccy\x92"Chj\x1f<(\xcd&W\xdd\xf0/J\xfdBW(e\x9e\x88\xb8\x85\x86\xee@\xb2\xe4l\xd9\xb4\xccT\x9e\x85L\xe0SnI\xcb?\xbe\x1bk\xf8>\x16\x88\xe0_\xaeJ\xb2~\x1b.~\xf6z\xeeq\xca\xef\x1b\xf6\x17\xac\xdd\xdf\xdc\xabmN\xdf[\x15\xe9\x9eH`\x07\xd9\xe6\xd6\r\xd2%\x85yt\x1f-%O\xddj\x93.\xb3L\xa906\xa8\x9bj4\x89ued'
|
|
|
|
|
|
2024-12-14 17:54:47.987658 - Ether / IP / UDP 192.168.1.11:61224 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 30910
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 61224
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca81
|
|
###[ Raw ]###
|
|
load = b'\xc4\x00\x00\x00\x01\x08\xca\xcc~X\x91`\xedq\x00@F\x00\xb7\xf1\xdf\x1c\x0b \x07\x171\xae\xac\x02\xf3\x14A\xa2G@\x03F<O\xae@U\x7fU\xaep/\xe8^\xf1}/\xb5$\xd4\xd9~=\x18f\xec\xa6\xc2l\x1e\'/J.Qt.\xac;\xaf\xe7\xde\x93\xe7\xf0\xd6\x06\xe1)\xa8\x02D\x89\x07\x0f\xab\x84\x88X\x1d\xfaV\xff\xaf\xb0\x9c\xed\xc2\xd9\x1d\x85\x08\x9c\x142\n(P|\xfci\xa8\xaa\xb6\xcfA4\xc5\xcf\x01g\x9a\x0fh%F\x1c\x13HO\x84[\x04KJ\xaa\xbd\x89V\x8c]&\x92K\xb3:\xa6\xb2SYN\xc3QUfO\xcc\xe4M\xaaW\x96F\x06\x0c9\x00\xce_\x1c\xb7\x81\x9a:\x035;\x13\xe9SY\xa7%\xf2\xc3\xf1\xfd1*\xa4\xd8L\x9e\x0fSa9\x96\x0e\x86\x92\xbf\xcf\x02FT\xf6/5\x93n\xc2\x8eA\xb8\xf1\xef\x1e<\xe1\xe3\x84\t\x85D\x13\x14\x8cK-\x08\xf7\xca\xeaEm\xe9\xe9\xb2\xb1``\xab^\xb4\xf7#\xda\x01\x9d\xc1X\x19+\xb4\x19\xd4\xfb\x97\xcf\t\xf8\xaf\xf3\xb8N\xe4h\xe2IV|t\xc7\x93\xd8\xf5f \xe1\x0e\x86X\x98Z\xc8\x9b\xfe\x14\xc1\x14s\x9bi\xdd\xb0\xcb|\xe7\'\x1d\xf1*\xc1\xd9!\xb4\x14U\xc76;(#h\x8d\xb1P\x12=\x9a\xe4C\x82\x0fOe\\XP\xf9E\xb2\xa4\x1b\x98qY]\x01\xf3bJg\x94\xba\x08l\xba\x95\xf2\n\x17)\x01,\x102\xf7\xacD\x8aq\xeei\x9e\x07\xd3<d\x8c\xcc\x94\xc1\xd9\xe1\xe3\x07\xad\xee\x18\x9f\xbf\x1f\r\xdc\xa1\x00\x99g\x96\x18w\xb7\xac.\xe5\xaf\x9a\x8dW\x08\xa8\xe0\xb6/\xd0Y &\xf4\x06\x84\xaeY\xd8\xa2\xdf\xd9\x17B\xb52\xde\x1f\x82j\x1e+\xed-R6!\xce\x02$\xab\xae\xff\xae\x9b\xb9\xa8{\xd9D\xdc{}\xdb\xd8T\x8c\xd4\xab\xe7#\xb9\x8b_\xc6\xfb\xd5\x85\x80*\xa3\xe2m\xff\xd2MZ\x13\xac\xb3\x181=\xc8\xff\xe3\x005\x13\x10\xf2\x16\x14VG\xcc\x19\tC\x9f(\xcc\x99\x8f \x0b\x96"\x1a\xec)\x131\\\t\x1d\xa2(\x82\xa0\xbbJ)<\xa3\xea\xdcWH\x93H\xbe\xb6\xac6\x1c!\xf8X\xc1\xa5\x05@\xd2\xbe\x9bF\x82U\xfa\xc8w\x8d\x80t\xe2\xc4\xbd\xaa\x8c\x7fK\xa4f\x14\xed\xb7\xcd\xf8\r\xab:z\xd9\xef\x9b#\x07\xce\xfe0\xfe)\x01\xa4\xed\xbb\xf0\xfd\xe5\x99D\x9ak\xa6\x0fY\x84\xbe\x99\x18\xfc\xb0\n\xcd\x97-2}b\xda*#\x9c\xb6\xd3\x16\x1b;\xa1\xd2\x8d\x04\xe1\x95\xccr\x90\x87N\x87K\xc8\xd1>N\t\x1ej\xbb\xc9\xde\xe55\xae\xceO\xa3\xcb\x19\x11C\x97\xa3 \xdb\x93~\xae\x00\x8fV\xf6A\xb1\xd7d`\x1cO\x18\x9c\xeay\xbfE\xc6\x90m\x9d\x13\xbd\xa4\xe7h=\x96d\xf4\xf2\x02p`@c\x96I\xee\xd9V\xa6X\x9e\xa0Y\xb8\xe5\x12~\xa3b\x05\xad\xa6\xdd\x1eu]v\xa0//\x95z\x96%\xa5\xd9\xeaS@\x9cz\xe9\xd5\xcew\x01\xeb\x966\xb4V\x98\x1a\xdbtkT(\x18\x11\x8e`6\xc5\x90\xef:\'\x15\xde\xa6\xa86\xdb7"\xecj\x96#\xf4\xb6p\x9aO`g\nlL\x06\xed\xe7/M\xd8r\xb0:[\xe1\xe9\xb2\x16\xa3\xc22\xff\xcc\xf2\x01\x89M\xe1\xb0\xfa\r\xa70\x0e\x9b\x9a\xfdhM\xea\x87\x83&$i\xa8!\xf9o%\xfc\x1cAHcD\xa7\xa38\x94\xcc6E`V/\x1f\x8a]\x8em\xc4\xd7\xed\xd5\x84\xbd\x1e\xaeQ\x97]\xe1Eq\x10\xc0\x88\xbe\x95\xb5\xf8\x12\xcd\n\xca\x84\x8d\xf4I\x94\xc2C@BZ\x02;\x1a\xe2\xc8o~\xd4\xc3\xad2X\x94f.;\x89\x97#\xb04?{F\x11Y\xb6\xaa\xcc\\\xb0\xcd\x92\r5R\xa9\x84\xa9BQ\x92\nG\xd4\xf8P\xe5\x04\xaf\xb5\xd9\x1er\xafV\x15\x07g\xfb\xaa\xa9EM\x1dI\x8c4\xe2R\xca\x80rFU\x06\x90\x16\n`\x02\xee#I\xf9\xa6C3\x91\xc4B\x02\xf4\xf6c\x01\xd1\xd4\x1b\xda{\xefnz\x82\xa0\xa7\x952\xaf\xb5n\x1c\x16u\xf9\xd0p0\x02\xdeE\xe7\x8ea>\x1e\x9d\xd4\xbf\xd9$\xbdf\xed_\xac\x11T\xf1\xd9\xda\x84\x96TQ\x0e\x8e\xe7\xc5R\xd6\x11\xa0\xe1\x80\xab<\xc4c\xb9\x11#!\xf8\xa7\xa2\x93o~3\xc0\xe1\xea\x91uc\xefw\xf0\x08L\xb0\xbdjC\x83vO9\xba\xea\xde\x8b\xc2\xf5\xc8\xf0\xe4\x1e\x92\xcc\xa5\xa6\x9b\x97\xdd\xf8^\xeee\xa3\xed;\xdb\xbe8[\xd2\xfa0\x05\x87sJ\xa6_\x12_$\x06\xb9\xc8\xe4M-&\xad\x8e@1\xe3>eNAddXV\xc5\x99\xb6V\x17\x02"u\xf7So9\t\xe2J;\xe8\xb5\x115)\xf3m\x16\x9d\xfb\x95\xe2\xd8Y\x99\x16\xc5\xd4\xe3\x98\xd4DC\xd4\xd3.\xf1\xdf\xef\xb3\x13\xf3\x93Z\xfe^\xfb\xe0\x9a\x8ao\x02U\xfe\x89\xd7\x07/\xa5\x99\x83\xdd\xb4\xed\x945\xffD\xc7\xd9\xd6\x97\xe0\xadN\x1a\x06\xdeT+r\xc4G\xe4\xe2\x1d"\xa6\x14J\x0f\xf3\xf933\x96\x9c\xe5\xa71\x8c\xeeSP\x93\x89\xb9'
|
|
|
|
|
|
2024-12-14 17:54:47.991631 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https S
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 45327
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364267278
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 64240
|
|
chksum = 0x807e
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 17:54:47.995077 - Ether / IP / TCP 192.168.1.11:40821 > 35.186.224.24:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 123
|
|
id = 30911
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40821
|
|
dport = https
|
|
seq = 373744437
|
|
ack = 2746219139
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc5f3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00N\xb0\xc1\xd0S\xdc\x9b<t\xda\xa6\xbd0\x9f$z\x1d\xe7\x1e/5\xa7\xbc\xd9\x1b \x01O.\xfcy\xab\xbb<S\xcb\x14\x90M\x16\x14\x83\xc5\x1a$\xc9\x1f\x8d\xfe\xcf\x9b\xab\x1c+\x16\xfd\xa5\xb7\xe7\xc0\xac\xeeU\xe633j\xce\x8b1\x88)\xd5T9s\xaf\xcb\x95'
|
|
|
|
|
|
2024-12-14 17:54:47.998663 - Ether / IP / TCP 192.168.1.11:40821 > 35.186.224.24:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 30912
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40821
|
|
dport = https
|
|
seq = 373744520
|
|
ack = 2746219139
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc5c7
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\xde\x86\x1d\xfcqB\xa2\x1b\xec\xcd\xc3\x80Z Z\x9f+\xb3\xd1\xa2r\xb9\xd9\xa7\x96\x8a&\xb2\xc7\xf1d\xd6\x16\x13'
|
|
|
|
|
|
2024-12-14 17:54:48.005522 - Ether / IP / TCP 192.168.1.11:40821 > 35.186.224.24:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 30913
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40821
|
|
dport = https
|
|
seq = 373744559
|
|
ack = 2746219139
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xcb24
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x17ltuf.d\xf7\xfc\xe0z+\xe8\x9f\x91\xac\xdbB\xa7\xe2\xe1\x0f\x0f\xc1I\x0e\xbf\xd6k\xea|\x964\x03\x11\x9e\xf4i\x10\xe4\xa6\x00\xc8`\xe4\xd7r\xa1xN\xa6N\xbe\xf1\x92\x0b\xbaI\x9e\x98\xb7fW\xc1\xf0x\xf3\xf1\xab@l\xca\x97\xd44\xbe\xe4>\xb0\xf1K\x10\xfb\x96\xdb\xac\xb2n\xd0\x02\xbcq\x05\xad[xP\xa8\xbe\xdd/e\xf2\xc9J\x8c\xba\xe3\x95\xd5\xcd\x7f\xd4m;\xbfy\x98\xbd\xaea\xb9\x85t\x1b\xe7I\x15\x90Dn\xa7\xcd\xa2\x80g\x1b\x02\xc6\xb1\xfb\xa7\xa2\xa8=\xc6qO\t\x8c\x7f6\xecf*\x93\r\xbf\xef\xe2p\x95%z\xe9\x8a\xe0\x9c\xf7^\x8f(\x877.\xb7Fr\xdcW\x81\xe5&\x8eW6\xba\x9bjm\x96\x8b\x0f\xd3\xb3\\\x89C\xe5\xa9d\x9e\x1a-\xf0\xfb\xae\xab\xeb\xc9e\xae\xf2\xce\x1a7/\x15`qm$\xc2x\xe2\x11\xb1\x9fqh\xbb\x88\x87l\x95\xd6r\xfd\xe2\xc5\xe7\xd0\x99\xad\xd8\xda\xa2(\xa9\x10E\xe5Iw&\x1e\xb7T!C\x1cM{\xe7\x9511\xd7^z\x08\xdf\xd2\n\xdfU\x7f\xdc\xbbn\xd9VL\xe7\xccd}(m)a\x1e8(\xac\xa6\xaa\xe6p\xf9\xf3?\xe4\r\x8aQ\xfbq\x87W\xbe"\xce\x07P`\x1b\xc6n\xc5r\xdb\n\x98\x0c\x14\x19#\x8b\xe9\x90\xbc>3\xf2 \xb9\xe8T!W\xe6\x98$\xc8?\xcb!\xa4/\xa0\x85\x96\xeb\xf7]\xb9\xfa\xed\x7f\xa7\x88\x91n0\xe7-\xbf>\xb0\xa4\x8a\xf8\x81\xb7\xe5\x0c\x84\xf8\x01\x9e\x12\x08\xa6\xdfNHw]\x9b\x0e8S\xf1\xcc\xff"f\xab\x18\xee>\x0c\xd5\xdb\xed\xe4t7\xc3\xe4\x08G\x8e\x89\xd1\x08\xc9\xa8\x98>.\xb2\xa5\x02!V\xcddq\xab\x08p\x7fa"\xb1\xf6Q\x06\x93\x19\x9a&z\x1e[\xd23\xb1#\xea\xbb \xa9\xba\x14\x96\x9f\xeb\xc3\xbep/\xb4%\xc6\x02\xb6ik\xf8\xaeEo\xab\x9e\xc4\x00\\\x92\x0c\x08\xe3\xfe\xd0\xf8=\xae\x8b\x1cm\x82K\xe2J\x8c\x81:a\x16\xcb%\xf3\xf6\xea,\xcd \x84\xbfE\x9f\xfc2\xef{\xd4\x7f=N\x04\'\x99\xa1\xe3o\xac\xdf@\xac\xca\x19\xa3\x01\xa6\x19\xd6\x8eH\x88\xcd\x8e\x90\x9f\x89J6\xc4}\xc5q\x8aTJ\x13n\xfd\x95\x8a\x06V\\@\xd5\x98Vt\xc9\xfa\xb6)\x94:\xfc*\xf44I\xc3\x97\xe9irf\x99\n)\x88\xf6m2\x9ds\x99\xdf\x0fz\xf8\xc5\xcd\x05I\x9f\x98\x96\x04E,\xf5\xa9\xef\xa6(\xde\x1a\x11\xda\x9a\xba\x9aV\xa3\x99\x87RCii+\xc1\tF\x88\x7fg\x1c}\x8b\xae\xcd\x06\x08\xbe\xcc]\'\x86?\x0f\xfd\xc1\xe0i\xb1tS\xce\x9f\xdf\x8d\x92O*\xe2\x8f\x94\xa0\x07I\x1bz\xb9*\x1bO\xbb\xca_u*\x97\x80\xf3\xc4\xe1\xa9@\xa2\x80\xcc\x11\xb4\x06\x04\xb8FU1\x8a\xe7\xe0\x05%\x8b\x86kK\x16\x0b\xca\x0c\xa3\xe0\x95\t\xe1X+g\xcf)\rM\xa3T\xad+\x80\xcaP\xe8\xe6P\xac\x07x\x1a1q\xe8;\xef\x89p\xa3\x9d\xe5\xf8;\xc8\xce\x07\x80"\xbe\n6\xf5/\x82r\x03\x1c\x86\xca\xdd\xd8\xcdo^\x94\xdebR\x87\xe9\x92[\xbdfFy\xc9\xb1\x08\x83\xf8\xa9oi\r\xc0\x97\x14E\x02C4\x0b\xc7H\xff&\x92I\xd6\xa7\xd9\xa0\x8b\x9e\xf4,\x14\xb6\xd3\x14\x85\x88\xf82]\x846-\xf6\xc6\x016\xbd\xe5\xaa\xef\xe7\'E\xeei\xa3\xf5\xd1K\xe3g\xb9S\x9f+\xe68\xa0L(\xb8\xae?\xd4\x17\x11Ng\xc6\xc90\xb3\x05\x0c\x9a&6\x94^&\xed]D}\xd1\xeb\x0b\x01\x05z\x12B\xc8-\xc9D\xea\xf2f\xb6\xf9\xf1\xd6\xef)\x1d\xf9q4\xf5\xcd.\x8fx9\xcd\xed\xd1U\x0f\xef\x82\xee\tJ\xfc\x01\xd0\xd6\x12i<\xd7\xdf\xdb\xc2\xbf\xc0*On\xf0\xc3\x10B1A\xfb\x95\xa6\x84?\xe8\xb8\x80im\xec,]\x1c\xaa\xe2\xa7\x1aV\xb4\xe3\x0f\xcec\xc4\x85*{"\xd4M=C\x89*\x94Bs\xf0\xdb\x13h>\x05Qlj\x8cW\xfa\xad\xb8\xcc\\&\x8a\xad\xb6\xb7\x9aa\x95,-\xadt+\xb5\xe0P\xae\xf34\x05\xbb\xd6\xceG\xb4\xe4M\xb0x7\xd7e\xb2\x0c\xfc\xcfJ\xd0\x85?\xba\x0fb\xc1\xc8\xe4\xf7\xf5U\xae\xeao\xfe\xe5\xcd\x8e\x92I\x1a\xff\xf3H\x14z\x9d\x8e\xacKy\x07#i\xbf\xafS[*\'\xaf\x082\x9d\x86\xa9\xc3\x9a\\x]V\x10n\xde\x94\x1e\x9b\nJ\xe4c\xad{\x0c\xcb\xac\x1c\x01Tj\t2\xa3\xfb\xa3\\\\\xfc"\xfb\xd54w[\xb6qX\xe7\xc0\xb9Cm}\x1e\x90X,\xaf\xf0^\x9e\xb6>\x8bz\xcb\xf2K\xa0\n\xf3\xee\x91K\x9bN\xac\'l-\xc1\xf0[\xe2w\xca\x8d\x12C]S\xc3\xcb?\x1a0\xa9\xac]\xdf`\xca\xcf\x14\x1c\xdd.io\x10\xf6/\xcf~\xeeo\xd4\x1d\x8b<:\x16\xe8\x8f\xbe\xc3\xb5\xa9\x96\xf5\xab\xdf\xb5\xa6\\j\x0c\xf4WZC\xc7\xb9\xc5q/\x94\xbbk\x1c\xe3\xc9\xea\x14=\xe1E`\x86\xe3B\xa7\x9a\x9bZ\xe4!\xcc(y\xf6\xc9\x96\xd5[;Y"u9\xa1T\x034\xd6:\xa7O\x8fH\x8a\x0cd\xe9\xce\x04\x06\xcd}\x10d\x1a\xbb\x8az\xa8$\xbd\xa1&\xa7\xc0\x02\xa1L\xec:"\xeb\x02s\x93qm \xec\xb4z\x92 \xfaf\xe7H\x99\xe6kH\xc4\x90\x9b\x8cp\x01 d\xab{uM\xddj\xe3v\x8f\xc9\xaa5\x92\x05P\xe4\x96\x96\xf9\xf6o\xebo\xa7\xa8\xf0\xf1W\xaf\xb2N\x82P\xfa\xbe\x14\xc0p\x7f\xbf\tg\x12n\xae\x97nOCX\xd5^\xf90\x7f:\xb8\xdf.\x8e&\xdbV\xd3\xacz\x91\x07\x9b{k\xfb\xce\xc4k\xe8c1\x8d\x98\xf1\xeb+\x88\xf23\xb4\xd3q'
|
|
|
|
|
|
2024-12-14 17:54:48.011977 - Ether / IP / TCP 192.168.1.11:40821 > 35.186.224.24:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 30914
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40821
|
|
dport = https
|
|
seq = 373745971
|
|
ack = 2746219139
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xcb24
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'a)\xd1Q.\xc5?1G\xbb\t#\xf1\x900\xb6e\xe3L\x15Y\xe1|\x02Y\xb04\xf1\x81\xb3\x80\x1d\xc6Y\x08L\x9e\x9f\xbb\\\xa65k\xacg\x9c\xc7\x13|f\rY\xc2\xc9i\xb6R\xbb\x8f\xf0\x95\xa9\x1f3_\x0eR&W\x17\x87\x00\xd8P\xe5\'\x01D\x00\xf1\x8c\xaa\x02d\xc94\x03\x14J!\xe4\xe6%\xd1n\xfa\x93m\xec\'O@TG\xa3x\xa2P\xb8Dx\x88\x01\xf3\xa56\x87\x0e\xcd\x15\xaa\x1aAa\xd5\xa1;3\xaf\xde \x01\xb9\xfb\xf5\x18\x93N\x16\xd9l\xdfs%\x96_\x80\x10\xfai\x17~\xcc|\xbf\xe7\xfbIq\x855.\xbb\xf1c+\xd8\x8e\x85;\xa8\xe1\xeet\xadI\xff\xcflQ|-inm/\x13xb\xbd\x88\xf2\xa0\xfa/E\xc9jI\xb4v\xcdO`\xc6\xe4\x06\x076\xcb5\xf2\x07\x1eY\x93+\xcb\xa8\xa7B\xc6\x1fp<OO\xd6\xea*\xac\x91\x82\x85L\xbe\xfc"a\x14\xb6\xccbf\xcc\x0e\x92\xd6\xef\xdc\x0f9\x06\x1d\xf0\xafbe\x95~:\xf8\xf6\xd5\xab\xe9\xf6l\xe6.&\xb49*S9\x0f*\xad\xdbp\x1c\xc0S\xec\x13\xee\x115T#\xbc\x99\xe2C\xb7\x0b\xc3\xd6KE\xa6]\xf7\x02\xec\x15\xe6A\x16\xfc\x9d(\xe4U!\xa9`\xa0r\xca\xecA\xa8\x03E\x89\x97Bw\xa5a\xce\xa5\x07\xd4\xb8\x89\xc9_4\xd9\x9f\x1d9\xb5\xedV!\xa0\xa8\xa3\x19\xfe\r\xe6\'\xe2\x9e|i0O\x04\xaa]\xeb*\xa1\x04"\xcc\x18\xad$@\x92\\b\x88\x926\x06\xe2\x98\xaf\xd6\x8e\xae0:\x1a,\xe5\xdb\x89@\xf4\xf4\xbci\xcf\x00\xfb\xa4\xd7\x02p\xa8-\xfe\xceZ\xa4\xb2\xb9\xea\x9a\x86G3\x9fe\x03N\xc3|\xf4k\xdbP\xe7\xd4\xa0\xf2N\xb67vo\x16\xa1\xb3\xc7Nx\x86\xdc\xf7g%\x84\xfb: \xa1\xd9\xf3"1\x802\xbe\xb6\xb9\x9c\xa2,\xbca\xd8fd"{(C\x1cL\x8b\x8b\x8b0\xd9\xed\xed\x0f\x08\xab\x8cF\xfc"\xb7\tg\xec\xfdl\x98\xa1f\xd9:\x19\x1ej^.;\x9e\xe7\n\xf4\x83b\n\x81\xb3)\xb0\x16\xa3\xce\xe6\xe2\xff\xa4\xd1`(\x92\x7f\x85/\xcbL\x870\x95?\x1e\x8b\x0b\xd7x;\xf0\x13z(\xef\xc3\xb6\x17\xc8$\xfb+\xf9\x97(\x15h\xbfR\xf7\x02\x16+)4\x13\x9d\x18\x11\xd6U\xeb\x90\xb1\xd3\xe5\xe7\x0c;\x07\xe5\x95Y\x13\x07\xa00I\xcan6{\xde0\xef\xed\x05l7F7\x9d\xff\x04\xb1<\x96\xa9\x80qX \xf1\xbc\xd3\xbaz\x9a\xd8\x13k\x89\xd5o\'C8=5\x11\xfe\xf2t\x9a8\xa0}2\xb9\x89\xd6\xcc\xad\xdav\x9a\xe2\x1a\x02\xf0\x99\x9d5~\xef\xb2\xa4\\\x8d\xa1R\x9e\n\xac[\x07\xc0\xa8\x1d\x0b\xfa5KW\xa3(_\xe2Mv\x82P\xb1\x17\xffVN\xe7\x1bg\x14\xf8\x86\x14\xe6\x16\xa8\x1ax\xe7\x8e\xa9}\xf7\xc0\x81\xaa\xea \xc9\x14\xaf\xcd\xc0\xa1L\xab&\xb1\xbd\xc5>K\xc7\xe9B\x1a\x1e&$N2(\x01\xbc$\xce6;\x07\x8fO\xb2(\xcaa\xd6\xaa\x93\xf5\x94\xf0\x13\x01w\xa3k\x90\x84-\x85sY`-\xb5w\x87\xc4\xdeBmk\xdf\x9ahU\xb3\xdcV\x9b\x13!\x8b\x0e\\\xdbtd\xbc\xccl\x8e\x15~\x1b\xc2\xc7\x90\xc3\xa4\xc0\x90\x80\x0b\x9b?Z\xedt0\xaa\xb1(\xa2j\xae\x84>\x8c\xa39\x8eL\n`\xe5\xf7:\x15]r(\xd0z\x97\xdf\xa2\xbb6\xb7d\x1c\xd1>\xc3\xc1o\x88f\xa5\xa9\x15(\xa88\xac?\xce\xc0_\x9b^\xb3\xd4\xe2\x7f\x8dw\x02e\\\xc1\x03\xd3\x11\xf3$H\xd6\x13\x1d\xde _H\x11\x19\x99\x1f\xc36Z\x01\xf1\xe9V\x13\x95JjMn\x18\xa9\xba\xbd{\x11F\x8b\xe4\xa2\xc2\xe6\xc6?\xe1]z8\x16W\x9b\x02"oZ\x99\xa3C\xc8\x96\xcf\x18}\xde7\xe0[ueo\x7f\xaa\xb3{m\xb5E:0\x83\xb0h\xdb\xde)\x95\xc3\tN\x9c\x86\xab)\xfc\x91\x8fk\xe1\x01\x1c\xd9\xa3\xfd}\xe3\x9b+?\xae\xef\np[\x9b\x93\\\x9br>\x93\x03?`\x86\xd66\xe6g\x8dn\xfb#\xefN\xd0\xf2z7\xd2a\xaf\x806\x04\xfa\xd1N3\xc0u`f\xaa\x7fuK\xc3\x19\x9dcH\xbd\xc2\x13f17w\x00v\x83\x9131A\xe4\xafZLH\n\xe2\x88\xe0\xdf5\xb8\xb5\x88\xae\xd4#\xc5\xebo%c\xb8N\n\xaeq\xa6]\x0fe\x99;\xc4\x90\x13\x1fS!\xa9\xd3\xbbA\xc8\x14\xaf\xe1\x87\xa7A\xc8\xc16\xb9\xc0\t\xe9\xb4\x8a-\xaeG7\xd5\x95\'F\xfb\x84I\x15\x05\xb0\xb54>n\xee\x80\x02\xad\xee\xcf\x0b;xn\xca\x81<|_\x1d\xb8\x96\xd4r\xf2n\xd5\xe0{\x1d7$\xab\x08\'pC$[Y\xb8\n\xa9C`\xab\xe7\x90\xce\xb08cQ\xac\x8bb\xa3L{\xe4u7uB\xa0!\x8b\x9fLq\xd6\x91fM\xa0II\xcc\xa9H\xber\xcd\x9f\x95rCaT\t\x95\xe2\x11\xe0po\x8a\xb4\xf4\xd7W\x19\x9ew\x8a\x06\xfb\xc9\x93\xdd\x865\xb8oo!X\xdcB\x19\xbcC\x0b\x80j\\1\xee2\xc94sy\xd1\xd0\xee\x8bu\x1a\x8fg\x9c\x9cF\x87\xdf\xf1\x83c\x9f\xd4\xe9\x84\xd9\xbb\xf1\xae\xfe]\x07|\xfd\x82\r\x03\'\xa8\x9f\xb4\x16oO\x8c\x81\xced\x16w\xe1\xe9\xa0\xca\xa2\xc5\x7f\xce\x84\x8e\xd6\xaa\x8e\x91\x12q\xbe\xe8|\x95\xe2\xff\xf5\xf3l\xad\x19_K)D\xec\x1d\x9a\xee\xde$/\x84yenu\xea\xae\xbf\x97s"\xddT\x86*\xec\x90\xb3he\x19j1\x99uFI"8\xa2\\\xf8\xaeM\x96\x9a]\xdc\xdd\x89\xfa\x94\x96\xec\xf9\xb7\xedG\xed\xc9N=\xbff;\xde\x81\x12\x9cm\x0b\xa6\xd1c/-?\x94'
|
|
|
|
|
|
2024-12-14 17:54:48.020221 - Ether / IP / TCP 192.168.1.11:40821 > 35.186.224.24:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 30915
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40821
|
|
dport = https
|
|
seq = 373747383
|
|
ack = 2746219139
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xcb24
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xf7\xa5Lt\x14O\xd3\xf2\xc9\xe8\xa1\xc8\xde_\xf8\xb2\x8c+\xca\x18Ky4\xbc&\x03\x8b\x99\xbbN\xdf;\x80\x00\x11\xf8\x8f*\xd9Wj\xc9\xf3wv-\xa6\xbb\xb5\x86t\xc7\xb2\xe3\x18\x9f\xae6\x99{\xc1\xca\x95\x17X(\x1e\xfb,\x96Oy\x9c\xc5\x8e:%\xc7\xad\x1a\xfa\xee\x89pH\x08\xf5=g\xbea\xc5\x1b\x8e\x04+\x99\xa1r\xbf][\xe5{\xde/\xffp\xf4\x85M\x83Iz,\x022/X\xfb\xc4\xed\xe2%P\xa7g\xf8C\xebl\xc69\nG\xe9\xefa\xe4,\xd2\x99\xa6p\xd5\xd5\xa6\x01\xa4&$1=\x03\xa5\x1a\x14\xb8{\xba\xe8\xe9\xea\xd9\x04\x83\x1c&\xb6\x9b\xed\x13\xefb>\xf3*\x9b\x7f\x91\xc3\x8f\xa64\xe0!\xbb\x0f\xbfU\xad\x91\x85\x817\x9f\xdcBs\xd51\xcf\xb3i\xd0\xd6=\x92\xef\xc0\xc0\x86\xbd\x9aVYp\x0e\x1d_J\x96>\xcf5^\xfeN\xaa\x8a\xf0\x1a]\xa8K\x13\xf0\xfff\xd6\xf7\xab\x0b\x114\xb9c\xef\x04\xe2/\xf0J\xd3\xf4#7x\xeb*R\xfbar\xbc\xe2j\xf3\xaef:wlmk\x99\xf44\x7f\t\xe72#\xbc\xa6\xd52\x05\x84\x95\xcd\xde\'m\x84\x9b\xd4\xfd\x11:\xb2\x95\x9e\x8c\xa5d\x07\xcf\xca\xecI\xa1\x97\xce\xec\xae\xa7\x0fuc\xdd\xa0\x8c\x19\x19s\xd9\x11\xfe\xec\xd6\xc3-"\xd8\xc4\xc1\xcc\'\xb6\x00m\x1e\xf8~y!\xb2e\xc5\x1b\r\x07\x16\xb7JRN\x00{M\x0e\xf4\x05\x1d\xea\'\x16s\x87\xe1\x90\xe3bj\x7f\xc0\x9a\xac\xe8\x17ro\x8d\x90\xcd]\xb0\xe6\xee33\xfe;+\xcd\xd2\xa3%\xbb\x92vJ\xc1<\x03\xfc.\nSg\\s\xd7\xadt\x9b\x1b@\x0e)\xfb{Eq8\x11<\xb8[i\x891k\xbd\x96/\xda\x91\'NXRZ^\xcf\xf6;\xb8N\x9a\xb3\xc1\xfd\xb0B\x99`\xc3\x04\xcd\xdd\xc5\xbd\x1c\xfb/\xff{\x92+D\x9d.\xde\xe7\xb4\x8e\x8d\xbe\xdc\xc0\xfdV1Z\xc4\xac\xee\xf9\xee\xeb\xf8}\xc54\x93@}\xb2]2\x02\x07\xd5(\xe6\xe8R\t\x9e\xb8\x1a`"\xccDI\xff\xc6\xec\xefl\x11naQi\x1f\xd1\xc0\x88^\xfc~\xf2\xde\xb0\xcf\xb0\x0e\x0f\xa3\x1e\xa1\xe6\xa2\x08\xa5\xcb\xff\xd7`}$\x80\x0e\xb4qt\xa6<)\xe9\xf4\xd4\xc6\x15J\x12Q#\x06T\xa9\xd7\x98\t[M\xc9G\xc8\xe7n\x9e1\xee\x07Eh\x98@|\xff\x18\x0b\xdc\xa7V\x8b\x94\xfexH\xf7\xb6\x9d\x17\xc2\xbb\xdb/ \x80\xca|\xb3\xa1\x9c.\xbd\xd7\xc2\xef\x89\xf5\xceL\xb2M+3\x8c\xe65\xfb\xfe\xa9\xc9}y\x1a\xbe8\x07\xa0\x8e\xda\x05\xf1\xc33\x98\x17=>\x0c_\xd5\xbb/nO\xb8hK\\\x1a\xb8W\xa6\xc2\xdb3\x8b/\x91Wg\x93\x92s6o\x00\xa6\x8b\xc0p5\x10{V\n\xc7\xa0dL\xe1\xd7\xec\xc6\xde\xc2 \xf7\x03\x9a\xf6\x82\xe7=\x8c\xf85\xa4\xc8\xcd}\x7f\xb7fD\x8b\xcf\x96\xf1x[q\xde\x8c\xc2\xbb#\r\x17\xe0vO\xab\xb3\xeb\xfe\xee\xc7@>ts\'\x0bp\x1b\xbe\x08\x1craUUL\xd9\x80\xfc,\xd1\x9c\xfe\x7f1\xcek6RL\xc7MH\xc4\xcd\xe0\xe4\x0e\x00P\x84S\xa5fD\x00)E4\xb0w#\xbc\x06\x1f\xbe\x05=\xce;\xd7h\xd4R\x8b\x83\xf3\x19{\x9b\x03\xef\xa5\xd3t`VC\xda\x9e\xab\xa2\x92\xb4J\x02\x1dO=+\xcf\xd0I\xc4\xaf>\x04\x98\x9b_k\xe7\xc9~\x98\x17\xc9\xbc\x14\x8a\x95\xb3-k\xf0\x9d\x89\xe6\xc6\x8a\x14>\xecXz\xaf\x8e\xda\x84\\\x17\x91\x85\xe6!X\x92\xa9\xf7q\x0e\x03\x87\x88\x99\x88P\x135\xc4\x9b\x97\xb2]\x1fh\xa4r\xc8,?\x0b\x80\xcb\x92\xc4H\xeaet\xdeh\xde\x8d[\xe5FN\xfaJ\x0b\xe8\x7f\x02F$<\x87\xae\xf0\xdd\x85y\x8d\x95j\xf5\xf7 I4v\xc3\x01\x91\xa9K\xe6\xe8\xbe\x8c\x9f\xc00\x0e\xff%hE6\xee\x07\xec^xe\xffm\xaa\x83\xc9\xd0\x15\xa0X\xd2GWo\x8fW\x1fGisO\xb8\xb7\xd7\xa8\xd7\x84\xbb\x83\x1fl\xb8\x06d\x01\x05\x94;B\xb1t8\x15\x98\xef\x14>\xc5\x9e\xef:?\xe6;:3&\x08=v$r\xf6\x1d\x18\xba\x1a\xf8\xa8\xb6\x00\xe0qJ\xb9\xa9\xfe$\xe8\xed\xc07iU\xe5*\xce\xc7\xf6\x97 \x0e\xc7j2\xe9\n\x19\xc2\x16R\xc5\x81\xde\xb1[%\x81rI\xd5\x7f\x95-*\x85\xd1\xc1u0\xfd\xd4\xbc\xc6\x1ev\xa3.\nK\xa6]D\xef,G\x12\x03^F\x8a\xfd:\xafg\xf2\xf2\xb5s\xf7\xa5\x8e\x95\xf1\xea\xf8\xce93\x0fL\x0e\x08\xe9\xf3g\xaa\xa1\xbf>\xde\x0b\xdf\xfbA\xb8\x11q\x1dGT\xce\xa9\xfbP\xa3\xf6)kC\x82)\x80\xcdz\xac\x13\xb0x\xf3y\xe1\xec\xa0\xc6+8\xa3\xa8\xeb;\xedx\xf5A8\xe2\xd1\xe9\xa7\xb5T\xae\xe3L}\x94\xf8=\'\x86W\xaeU\x14\x03\x03u \xf0`\xb5\xb8\xc1\r\xe2TV\x04^\x1b\x16\xde\xb5\xf8\x81\xb8\xc8\x10\xcf\xd1*\xa7|\x16\x9a\x90~\xc30\xf3\xcf\xc9o~\x88-F?{\xb2\xb3\x8a\x8f\x8a\\\xa8\x8e\xf2\xe7h(\x16\xb3\xb6IaH\xf8}Ng]|H}y\xeb\t)F\n\xe2d\xd1\xff>\xe8f\xff\xf5\xf0O\xcc^\x83\xccX\xc6\xa5\xa9\x1f\x10\x1a\x9a\x1f\xc7\x9eOM]U\xc3\xc4.\x8f\x01:Wl?-\x87\xb7\xee\xf9`##\xf9\xef\x9aF\x84\x02\xd5\xfb \x1apv\xc9\xb4\xef\xf1B\xa9K~\xce{\x0c\x8b\xbfL\x922\xcaGZV\x97\x8b\x9d\xcc|\xd3S\x80\x8c=\x8a~\xc2Q\x11\x8fth\x80A\x8c\x1b\xf3d.\xeb\x8d\xc7\xd9i6\xd7{\xb6\xa1\x9b;\xfd\x10:\xf0G\x08\xb8\x80\xaes\xfb\x08'
|
|
|
|
|
|
2024-12-14 17:54:48.028168 - Ether / IP / TCP 192.168.1.11:40821 > 35.186.224.24:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 30916
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40821
|
|
dport = https
|
|
seq = 373748795
|
|
ack = 2746219139
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xcb24
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xa3\xb5\x944\x19\xbf\xab|\xf7H\x16\xce\xc0j\xd5\xf2}\xe9\x0fQ\xa6c\xca\xd1\x9dv\nv\xa3.\xd4b\x9f\xd7\x93[}uVa\xe7\xebx\xde\x16vX\x12\xf9d\x88\x0e\xce\xd7\x82\xd9\xcfTXb\x81\n\x0f%\x82\xe9\xa4I\xbf\x9cH2\xdb\xf7\x93(+\xa5F\xa8\x10k\xce\xcdDj\xe9\x0bQ \xf2,\xf9\x19\x04\xb4\xf8\xc1\xa0d\xbd\xd3\x89T\x9eo\xd2zV\xd5\xe9\x857}\xfa^\xc7/|\xb3\xc3(Z\x04\xc5\xf9\x1c\x0b\xaey\xedp$\x85\xb3\xed\xe99VCvP <\xb9pk\xe3\xa2\xcd%\xa5CJ!\x1c,H@Lk\t\xc7\xe7\x11(j^\x06q\xa2\x03\xce\xd4\xa6YI\\\x96i\xbe\x98\x88R\x88C/\x074\xa6\xcav=Z\xd4\r\x86H=OR\x9a\xc8m\x1ek\x16\x92J^\x01$\x8a\x84\xab3\x06"f\xef\x83M\xff\x0b(\x99-bo\x02I\xb73\xbe\xda\xf6\xd2\xbb\xbc\xf4\x1f%\x11\x14\xefS\xc6\x87\x92\xa31C\xff>M\x1fI\x13E\xbb\x9a;j?\xf9v\xb4\xe4\x06F\xd9u\xfa\xb7]=){\xdaK\xec\x1d\xc9&\xa4\xce*$\x91\xb1\xee\xe2L\xc3U++\xcdb@\\\xf8\x1b\xc8\xde\x18\xf8w^\xfdP\xbd\x8e\xaf_\xf6\x0b\xc6\x92\\\n\xf2$\xd0{\x9a\x98\x1f\x99\xb4\xa9cV\xff\xc7\x9d\x93U\xd5\xb5\xca\xd5\xe6\xe4\x18z\xa5\xe9K\xcb\x85\x96/\x11\xb2X\x9bB\xf6\xd0\xa6^\x16%\xb3t\xbec-\x1c_\xff\xa1\x14\xaa\xd3\xe6v\x16N\x19\x89\xaf\xf5\xbe\xda\xea\x04\xee\xd6\xd5\xf6\xa1uk\xf8\xfc\xc7V\xc2\xbf\xd7\x93\x80\xe8\xb4\xb5\x08\xd4\x81j\xd7Fg\x82\x15e\xda\r\x8dG\xc6\x85:+IN\xfe\r\xc4R\xb3\x1c\x19\x04N!\x05ULg\xc8\x92\x14\x0b\x90\xd9\xfe6j\x81\xe1\x0e\xb5\x934\xd9\xee\xa2\xdbc\x0c\xdc\xe7\xea\xe9\xd7!\x03M\xda\xdb\x89\x00c\x14\x0f\'I\x8f*z\x15\xd3\xdd(zj\xfe\x92\xa8\xa4\x93\xcd\xb7\xeeF\xde\x19l8}C\x95\x9fU\x7f\xe4\xd1\xdd\xe7:\x0c|n\xdb2\x93\t\xc1\x95\x13O\xf5\x1f\xa2WT\x02\xcb2j\xd91\xda\xc3aV]x\x11W\xa36\x12\x9b\xa7\x9d\xf0~8\xe3$t\x8e\xfe^\x99g^\xb6\xa5b\xf4\x89:68\xc7\xf8\x9b\r|\xe6\x86\x15\x92\xac\x9e\xeaO\xa4\x99O[\xeb\x83\xc0]p\xb4X}!\xa3\xb3\xd2e\x98\x0f\xf89n\xa9]p\xc1\xc2\xd6\xeaG\x1d\xb5\xc1[3xE\xbdd4-T&\xfc$:\xb5R\x93:\x01\xdc\x1d\x91\xab\x82\x8e[\xc1W\x88\xbcf\xd1\xa2\x9d\xf3d\xc8\xda\x0c\xd0Z\x85\xd28},6)\x9aM\x9c\xd2V%\xb1k\x93\xb3\xb3N_G\xbf\r\x9d\x01F\x04\x88w\xe8\xeb.}}Lw\x0e2\xa2Z=\xd0\x91\xe25\xc2\x1f\x81!\xdc\xb5\xeb\x07q<\x15\xfa\xcc\xb6\x8eU-\xb4\x06\xc3\x12Y\xff\x9fIY5;\xd8wj\x94\xab\xe7U\xa2i@,\xe4\x80\x93\xbc\xac_e\xac\x17\xceGbUp[\x91\x97\xedi\x88^T\x8d\xe8\x96\xbe`\xa1\xef\x99v\xd3a\xea\xc9"\xbd\x04v\xdf\x1b\xa1\x0b\x8f=\x83\xae\xad\xa38\x1a}uk\x15\xa7\xaa\xc2\xde\xe9\xed\x855\xbb\xdb\xff\xd4\xb0\x8b\x9c\x87\xf5\x0f\x8a\x0c\xfe\xae\x02\t\x0cA\x02\x03\x8f\x9f\x84\x81,b\x0f|\x8c\x1b$s\xb4\\\xb4\xd2\x91.\xa8\xc1Oty\x8c\xd5\x90\x83\xd0.\x00U\xed\x15\x8ej\x8d\xb4u\x1f\xa9\xea\n^\xe6\t\xd6U\xbbN\xc5\xe6\x90\x9dn\x85m\xbd\xda\xdek\xee\x85\x080\xd8"\x19>\xca\x99Y\x1c4\xab]j\x0f\x08\x14I\x9e\xfb\xc4u\xd9\xff\xd2\xdf\x82[\xf2\x0e\xac\xbb\x1a\xf7})?E7\xb4\xaf\x9a\xa8&\xdb\x116\xb3\xbfO\x85\x8d{\xa1\x7f\xf9\xfa\xfc\xef\n\xa9PQ\x00\x92\xf9\x7fv1\x0f\xa3\xde\x14\x83\x94\x81\x9f\xb5\xc3\x1cAB\x9f,D1~\x1c\xca\xef\xcc\xba\xa2\x07\x91\xcfE+9\xcf\x9f\xaf\xecf\'c\xb41\xbfx=\x95\xcaS\x16\xd9\x8f \x19\r\x1cP\x19YG\x9bjX\xf6!\x83\xe4\xcc-R\x15&O\xedg\xeb\xa9\x86\x82]\x96\x12\xff\xdb\xb8\xb0(+\x86\xe7\xd8\xa8Y\x11\x93\xf98\xdd\xe7\x82h\xbeR\xbb<\x92\xc3_\x8d\x1a\x9aD\x8a?\xf8\xab\xbeT|\x83\x870\x97\x08\xcd\x99\xe6\xc1xg\x17<,\x83\x05C\x11tfnU\xed\xc5\xb5Z\xdf\xd7w\x9d4H\xdc\xcep(9{\x0f\xd2\xb2HC\xc2s4"+\xdd\x19+\xff\xd8\xb1\xd8mw.\xda\xc5\x1b\xd2\xb6\x00P\'\x15\xe3\xe3\xba\x04\xd4;\xbbV\xf2\xddi\xd6\x97\xdb\xec\x82\xd8\x10e\xbb\x87|\xe4\x13L\xf1\x0baf\xb7\xb78\xfa\xfc\xf7\x0f\x9c\x9bhC9\x8cZ\xad\x02\x9f\xaf\xfc\xdf\x02i\x90\n\xc9\xef\xb5k\x1e?9\x87\x03\xea\xd9cJ\xed\xd1\xcez@\xc7\xef\'\xcf\xeb)\xaa\x0f\x83Ie\xa9\x86WY\r\xd2\xb0\xec7.\x99\x7f\x89z\xb0HB\x8f\xe5\x19\xcd\x17_\xc9\x8b;\xf8\x13\x0f\xd5,\x10\xf6IxZ\x7f\xff\xdbN\xbc{\xf1\'\xa7\x86\x1aYi2\xcb\xc6\xae\xc8(\x0f\x89\x0f\x9eL\x02Q\x8e\xf8\x85Z\x9c\xedD\xd9\x98[fH\xbb\xbb\xb6.\xd3T\x83E\x84\'\xe4\xae\xe5\xf6UG\x87Z\xf2\xb6\xfd\xcb}Z\xa6\t\x84l6\x90\xe5\t\xce\xa7q\x02+\t\xae\x03\xe0\xb2\xf3\xf4\xd1\xa1\xb76\\\x03$\xbcc\xef\x88\xcf\x19/\xe2$\xd3\xaf\x10\xd2{\xc9\xe9\x8a\xb5\\4\xc8P\xf8b\xa9\x1cJl\xca\xb3D\x167\x868ye\x81)10\x89p\x93\xf5\x93|{\xacu:>v\x1dRtF\x82-\xefa1t\xc4%!\xb5\xd9\xb0\xab\xb1'
|
|
|
|
|
|
2024-12-14 17:54:48.034277 - Ether / IP / TCP 192.168.1.11:40821 > 35.186.224.24:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 393
|
|
id = 30917
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40821
|
|
dport = https
|
|
seq = 373750207
|
|
ack = 2746219139
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc701
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'&\xbb\x0c7/jM-\xaf\xf6\xf5y\xca3w\\oA}\xe7,\xf1;\x1b\x9e\x07\xb8\x88\x83\x9e\xb5>F\xfd\xa5\x8d$\xbf\x0e5\x80\x0e|<\x81O{8J:>c\xcd8\xcf\xe4\xe6g\xcc:1r}\x8a\xc2v\x89u\xfc\xe2U\xc2HQQ\xec\xf0H4%\xb0M\x8fT\xe6\xa9\xab\xd7\xab;\x06\xb3\xaa\xe54&\xa2\xd6\x91\xd8\xca]\xd3J_*\xa1$\x7f\x1d\x85\x00\xf3\xe2\xbaA\x90\xe6\xebC\xe3O\x1b\xf8\xce\xb5\x91\xd4)\x96\x9b\xbc6n\xccL\xf8V]X\x88\x87\x1f\xd1~\x13\x8b@^\xb4\xf5a\x80z\x94\xe1\x14x\xdd\x1es\xbcc\xa1\xfc\xf4R\xc7\xe7\x11+\xba\xfbN\x15\xf0\x15]\xf7S)\xd45\xf0=\xc6\x18^\x134\xc8\x11(\x19\xb0]\x7f\xc8\xc8\x05\xc6&&\xfe\xacO\x1b8~\xee$i\x90\xd1Bx\x82d\xd1\xbe\xac_$6\x18\x08\xa4\xf1\x8eI\xe2\xa2._q\xb7\xf0:\x8d\xe5\xe9\'\x8a\xabM:P\x124\x106D\xbc\xaa\xe8\xd8(6\x9cP\xac\xa9\xf8\xd8\xb6a\xbf\x1e\xa0\xce\xfa\xf3\xfc\x0fR\xf0o>\xed\x08\x80\x7f\x11\xb7&\xad\xb3>\xdd\xfb\xb1$\xb4\x9bv<0\xe1%\xcd\xba\xa9!{\x9a\x04\x00\x8f"\x0f*\xe7\xb5\x94\xbc\xb2\xa1\xd8\xda \xf5\xde\x96$Z\xf3\xb2\x1f\xd5CYo9{>\xeeM\xeb\x07\x92=\x19$\xfa\x91\xa4\xe6\xe5\x85R\xdc\xfc-'
|
|
|
|
|
|
2024-12-14 17:54:48.039304 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1274
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x786d
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 1254
|
|
chksum = 0xe5e8
|
|
###[ Raw ]###
|
|
load = b'@\xd6\xee\x1c\xcc\xbe?\xf4\x7fx\x88vL\x10\xa2\xb6\xdb\xcd\'\xfb\xfc\xb2\xa6\x87i\x92P\x06V\xd7\x07btk\xce\xab\xfa\xb3\xe7$w\xa3FZ\xacP\x19S*\xbd\x02\xb5\\\x0e\x12q\xd4P\x8b--u\x14\xee0lb\x8f\xba\x1c\\Z\xa4\xe2\xe1\x8f\x97\xe2\xa7U\xc2Z\xec\xe1\xca\x93\x03`\\J\xad\xa2i?\xc6\xe0@(\x0f\x0c\xba.\xd0\xedQ\xe7t\xc4!\xca"\x1d]\xa9\xd9o\x9cc5\xe5\xdb\x19\x03\x7f\xe5\x9b\xab{\xbcK\x84\xcd!\xaf1n\xe7\xee0\xf9\xfd\xfb\xe6\xa3o\xf5\xd0\xc2X\x93N\x90\xf2\xe9x\x84\xe6W\xde\x9b\xf5\x93s\x16\x1b\x07\xd3\xcc\xd6\x02\xb6\xcfDlm\xb6\xd3\x1d\x11\xae\xe5aY\x16jl\xf7\xcc\xd7?Q~3\xd4\x97\xa3\x92\x02\xf7\xf6E\x88\x8d\xab\x1bw(oz\x03\xea@\xec,Q\x9e.\xfa:\xce9\xad\x9b[P]\x97#\x92\xf4\x1b\x97l\xe1\xcc\xa7&^w\xd5\x0c\xd6\x1eUc\x10\x9cS]}\x9ak\x8f\xae\xf8 \x08\x94\x99\xf5?\x88M\xf8\xec2\x88\x7f\xf0E\xb4\xe4\xbc\xbe\x9bL\x15\x9f\x1d\xbb\x18I\x82\x94\xc9L\xa6\xff\xf9\xeb\x9e\xab\x1e\xa2\x105\xd5x\xc4\x89\x82\x9e\x9f\x864J: \xdb\xaf\x98\xb2\x1fE\xccK\xd3\xb2\x16{IEWL\xca\xbe\x81N\x85v\xf8\xe9\xfa\xf1\xf7\xc5\xb78\xf0*Xk\x01\x05\x8bhB\xa3E\xfeBKMjh@\xbb\x15\x93H<2v7Z7\xfb\x1a1\xe5\x0e\x89\xdd(\x1e\xf3\xf7\x8b\x18\x87\xdfC\xea\xa7\xf1\xa7\x98\x1f\x05\x15\xc8\x82\xc3\x1f\xc0\x9c\x9c\xd4\x18d\xdbC_\xaa\xaf\xb9*\xf2\xfa\xe0\xeb\x10y\xbbz\x91c\x08V\xb0n\xd0EFO^v\xd5\xe6y\xb3\xe5\x1d\x8e\x11.\x12T\xb1_\xbe\xe6%h\xa2O2\x149\xf1{^\x85~\xc0]V\x01\x9d\xc2\xe9:G/\xea\xa0A\xd2\xe8;U,.\xc2PE\xfb\xc7\xfa-K\xe1v\x9c\xe4\xe2g\xf2\x19\x9fL\xc8IU\x98\x85=,f-y^M\xbb\x11\x87\xc7A\x07\x12(r\x95o{E\xc3s{\x01L\x887OSb\x8f\x120\xb0?\xa9\xf4\x86\x06\xd3evOL [@\x14\x8a\xd7\xfa\x8b\xa3\xfa\x9dk\xef\xab\x99%"\x7f\xab\xa29\xf7\x02p\xb3\x1d\x87\xd6\xd0\x8d\x19\xa86\x13\xf8\x1d\xe0/\x05\x01\xd3\x03\xf5\xc0\xe4k\xd5s\x12#KfN\x17q\x89\xa9\x05`\xb0\xfd\x14A\x06"\xdcT\x844\x84\xa6D0\xae\xdb\x10\x0ch\xa8\x03tDoD\xdcHd~\x01\xca\x92\xac\xef\xae`<\xf6\x1b\\\\\x96\xb9\x84\x9dK\x8a0\x17\xc8`P\x7f\xd7\x18\xe7y\xefE\x96\\\x89}\xaf0\x16\xcac\xd7\xa1\x81\nC\x1b\x16C?\xe1\xbax\xa6\xb3\x9f\tK\xae\xa6\x1d8\xfeSr<\xeb\x0cB1\xdd\xd6N\xbf\xa5\xd5OX\xcb(\xc7F\x1f>O\xec|\xf3 \xf9h5\x85\xe8M\xe8\xf4+m\x08)\x8c\x10l\xbd\x0eUL\xf3\xa3u\x90l\xd0\x11<\xdbF\x8a\tF\xde\x15\xdf\xf4\x02\xef<\x0b>\xe8\x1e\xd4C\x84\xfb\xc2\xdb\xb10\x0f\xc6A\xbbDf\x9d\xd7\x95\xa4\xef\xe8Lr\xf6\xf6>\x0c\xe1\xf0\x1cY\xdc\xfe;\x81\x96_\xd5p\xe0\x08Z\xac5]\xc14\x18!\xbaS\xa2\xa5\xf0|\x9b\x0f\x03\xc5\x94\xffl\xe2\x89\xf6\xe20\xcf[f\x95\x9cf\x8a\xb2\x8f\x18\xf6"\xe1Y\xf3\xd2\x89\xe5\x0f\xe2\x92\xce\x88\x94\xef\xaa\rJ\x05\xd4\xb2\x16{\xf8k\xd3\xc2\xb6\xbciz?t\x80\xfa\x9c\xf4\x8a\x92\xce\xb7jwQ\xc9-\xe7\x19\x1fUB\xd5\xa2\x1d\x9e\r\x0c\xd8*\x0c\x16\x1d\x8aKh\xeb\x17*\xe3\xa4\x02\x9f\x8a\x8f\xaa\xbf\xa8xv\x83\xef1\x87\xa8\xf8\x15\xab\x8a\xf9\xb23=Dl\xc0\x1c\xe2<^`]\xe0\xd2r{!`\x03\xbc\xb5V\x9b\xda\r\xcb\x12\xa6\x81\x16\xc0\xa6\x95\xca)\xac\x97\xa8\xdc\xf8\xfa\x9cc\xc6\x89N\xa0{\xb9B\xe1<\xeeJ\x1e\x16\'\xaf\xd8uWP{\xd8}f\r\xb1\x19\xbbw1\xbd\x8e\x85s\xd1\xd2\x0e\xaf\x8ea\xda0\xb1\xf8\x05]x\x90\xb0e-\xc4\x1c\xf9>\x82{\xd3N\xed\xbb\xe7\x8a\xf1n\xe5\xf4p\x86R\xdck|\x9a\x189\xa5\x06\xb9\xe2\xf2p6a\x8a?\x0e\xc7\xf9_\x16\xd2K\xb2\x17B\xb2o8\xf9|qo\xc7;\xaah\nj\xdbd=\xc9\xc6\xf4\xfb\x1f\xec\x8d\xdd\xf6\xd9\xf5\xb9\x03\xca{\xd7\xc4\x88\xe5\xb8\xc9\xa7\xaf\xdbe\xa7;\xd1N~\xe6\xe9\x19[`\xe6Xb\xb6\xe1z\xf7O\xc9\xae\xbb\x8f\xb6\x80\x0f|\xe2\xe6\x9fVIG\xa1\x9f"\xdaC\x08B\xca\xca\x08l\xc9\x0b\xa1\x8fX\x19\xbdHn\xce\xa7b\xca6\xf2\xa4r\xd0\x19\x85&\xb1\x86\x13\x93\xc2\x10\xa7\x9aR\xee\x8b\x86D\x11\xaa1\x16j\x0c\x7f:\x06ZHD\xf5\x9ef3(<@\xdc\xe0\x18\xf0\xf4\xc3z\x02U(\x8e\xf8\xab!\xc4K(Z\xd7\xec\x1d\xc1zS\xc2\xbbx\xbf];W\xb9\x18\x14\r%Q\x17\x07\xf1\xd8\xea\xde\xe6/\xd5\x05|'
|
|
|
|
|
|
2024-12-14 17:54:48.045314 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 512
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7c67
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 492
|
|
chksum = 0x9c9e
|
|
###[ Raw ]###
|
|
load = b'A\xcf\x92\xf4\x13\xe8\xa4\xff\x8dL#\x8f\x1f\x1cn\x0b\xf9#\xaf\x8f\xad<W\x85\xd1\xee\xab\xc5\x91\xbdgd\x87\xf15/\x07pFMdL)O\x9dW\xaaD\xe0\xb8\xc6\x9elp\x03A\xfc\xe8\xa5\x00\x80KM\x9fF\xdf\x04\xe0\xe5\xf0\xeaZ\xb8O\n\xb3I\x83\xb2R\xea\xd5`\xb5\x1a\xbd\xb4-(\xec_:\xbb\xd4\xa3\xf9^\xe6C-k\xb1\xd8\xce\xbb\xb7v \xa8\x19\xc0\x86\xc3\xc5\rt\x8c\x0b\xbcNt>W\xdf\xf3\xc3\x0e\xbd\xf1\x7f\x81p\x05<\x0c\x9f\xae\x97\x032\x18\xc9L\x1ez>\x10\x95\x97QAr\xf9\xa8$\xaa\xba\xa58\t\xcb\xb52\x0c)\x1ch\xeb4g\x1b\x9d>\x19G\xf4\xc0e\xaf\xd5\x84\xbe\xa7\xbe\x81\x1a\xbd[\xafr\xd1\xc2\xdf\xe7C\xce\x95\xcf\xd5\xa7\x15fuG\x03\x1f\xd3\x0e\xa0\x0b\xf3\xf5v\x8a\xae))\x03k\x04*\x17\xd6\xc9!\x8f\xf5\x06\xb3-\x0c$\xbfud\xa2M\xed\\s\x03\xed\x806\x98)\xfbo\xe1[\xed\xdbB\xe3Y\x8b\x02\xf6E\x96\xf58\xed\x07y\xc9\xdf\x96,?Nv\xff\xd7\xb1&\xac\xbd\xbbX\x83\xe6\x1d\xfd\xbb\x02\xef\xc0\xdb\xcf\r#CSX\xfe\xff\xfa\x9ba(\x8d\xda\xfb/\xd8\xed\xeb\x05e\x0b\x8fK4\xd5)x\x96\x108`\x7f}\xbczK\xc6:v\x86q\xec\x16P\xf1.\x19EF:\xbe&\x9da\xa4-\xf3\x19*\x1f\x9bL^\x8f\xbd\xe7(\x0f\x1dr+8b5\xac`.\x9c\xf4\x9b\x82@\xd3\xd6\x16\x03CR,\xc1\xafB\xdf\x81d\xbb\xd5\xa3\xd8C7\xc9\xb8\xd8Y04F\xb6\x9c\x1c^@\xe8\x81xcS\\K\x02\xc9B\xc5\xbe\xc0\xfc\xc0\x15\xa2\xf4\x96\xff\x08\x83\\\xfe\xf6\xf5^\xb7\xde\xebg\xe0\xa2\x97\xa0\xc5\x82\xda8\xb4p\xeb\xb6|\xbe\x1f\xf8j\x12\x88\xf8[\xfd\xdf\x19\xc0\xd0\xa5\xf8\x91t\x93\xc0\xcb\xde\xb9\x00D\xfb\x9f\r\xf80\xd7\x9c:H9DUW'
|
|
|
|
|
|
2024-12-14 17:54:48.049292 - Ether / IP / UDP 192.168.1.11:63056 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 63
|
|
id = 30918
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63056
|
|
dport = https
|
|
len = 43
|
|
chksum = 0xc5c2
|
|
###[ Raw ]###
|
|
load = b'X\xe5\xa6\xeb\x0f\xbbm\xbf\xd6\xb3\xd8\x02.\xfc\xe8|\x04z2\x7f\x9c\x9e-\xf0\x18\xf5\xc8\xed\xd9 \x9bp4H\x13'
|
|
|
|
|
|
2024-12-14 17:54:48.053385 - Ether / IP / UDP / DNS Ans b'edge-web.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 192
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb6d0
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 51436
|
|
len = 172
|
|
chksum = 0xed15
|
|
###[ DNS ]###
|
|
id = 30762
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 1
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'spclient.wg.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 285
|
|
| rdlen = None
|
|
| rdata = b'edge-web.dual-gslb.spotify.com.'
|
|
\ns \
|
|
|###[ DNS SOA Resource Record ]###
|
|
| rrname = b'dual-gslb.spotify.com.'
|
|
| type = SOA
|
|
| rclass = IN
|
|
| ttl = 32
|
|
| rdlen = None
|
|
| mname = b'ns-cloud-d1.googledomains.com.'
|
|
| rname = b'cloud-dns-hostmaster.google.com.'
|
|
| serial = 1
|
|
| refresh = 21600
|
|
| retry = 3600
|
|
| expire = 259200
|
|
| minimum = 300
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:48.058448 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40846 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 658
|
|
id = 53674
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xaa35
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40846
|
|
seq = 4001697679
|
|
ack = 3398707234
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1048
|
|
chksum = 0x615
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x02\'\xf9\xfb\x17\x14\xfe\xc6\xd4\xd2\xc1\xf1E\xaa\x12V\x7f6c\xe6\x91\x04\x99\x8d\x15\xea8\x01f\x10.\n\xf0\xaa\x8a\xc4=\xf5\xb8\x1f\xe1\x1b\xc5\x8f\x88Q\'4&wR\xb6\x14\xd87\xe3A\xbb\x85\x17\xd1p:%\xa5\xd1\x93\xecM,\x1e\x88\x05S\xf3(x|\xd4c\xf8"\x10\x95\xf4f\xf6\xa0\xf1\x9bOB\xd0\xe9_^-\xdd\x8e\xbc\xdd\xd3\xcbh\x7f\xa3Bb\xa1\x7f \xcc\xb9\x82qap\x8d\xf5?\x98\xd2J\xe6QZj\x9d_\xa1\xed\xd8\xb8s\xd1"\xab#\x98G\x05hE\xbf\x94D\xc4\x9a+SUBx\xe0#8\xe1\xe4\xfaU\xf2\x00\xda\xc4\x0c]`\t\x08F\x86J\xa5}\xfd\x11\xaf\x9d[\x8e\xd7\x0cka\xa7\xa4\xd0\xa6\xd8z\xe7n\xdcs\xba\xaa\xa9\xbfhj#\xc6t\xf5\x0f\xd6m\xceg\xfa^\x8b\x03\x11\x03*\x14\xba\xa5\x05;\xd3\x19\xf31\xa71\x87V\nh\xde\x8a\x82\xe1\xc6\xcd\xe3\xa6%\xb4\x90#\xb2\xb4d\xf3n$\x1b\xfd\xa3\xc3{\xf1\xe4Qg<\xc8\x01U\xa2J\xbe`\x8ao\xff\x13\xa53\x1b\'\x9b\xb9\xb8\x1bIH`\xb5r\xe0\xc9\xa3\xf7\xfd\xaf\xfb\x17\xd8\xd1\xf3\xd9\xe3\x9e\xf7Q#\x17h\xf5\xfa#\x89\x83\xec0\x07\x14\x8e!\x85\x1a:\xde,;\x9f\\\x1b#d\xb0\xd1\x92\x1c\xfe\xdd\xc6\xd4\xc7\xa5\xd0\'\xe9\xcek0\xa3\xe2o\xeeV\xd9\x8d\x17\xf6_\xe4\x88*\x8c\x07erE\x1e\xba<\x05\xfdQ\xe2\x00Y\x8fYD\xe74\xd6\x01\xd4\xe3\xa3!s\xc1\xbe\x1a\x15=\xfd\xaf\x7f;\xf5\xbdX\x98\xbe\n\xf0\xe3\xad\x12\xb0\xd5\xe9\xd5\x8f\x06W\x11hW\x96=\x18a\x14\xad\xe60\x1b0\x8c\xa6V\'\xaelT\x11\xeb\x90WqOF/"\xb4r\x0e\xa5\x05\xba\xcf\x8eW\x9bM\xdd\xe2<\xfd\x11ed\xf4\xca\xa0\x8a&\x94\x94\xca\x89Y\xd4\x17\xb8Y\xe2rZ\xfe~\x900\xaf\xd3J\xf2\nO\x97\xff\x97\x03\x03\xbb\xfdTlj\xc7\xe9>\xc6z\xd0Y\x81qe\xb1J\xfb l\xc0-\xbc\xb2>U"\x08\xc2"\xd6~p6A\\\x1cI\xb8$\xb2\xe1\x95F\xaaNP\'1\xc2\xf5yY\x03\xa8\xc0\xe2\xa7\xda\xc1\xaa\xb7\xc5a\xbd\\\xf1\x1d\xf8\x17\x03\x03\x009\xe6\x986\'\x07\xf5K\xe1\x0f>\xe2u\xce\xbd\xca\xcb8\xdd\x94L\xcfb;1\x94\xb0i6\r\x9aN\xb9\x0b\xd5\x92\xbd\xe5\xd7e\x8e\x1e\x16I&\xcas\xa7e\xc2p\xfc\xc9v3\x86>)'
|
|
|
|
|
|
2024-12-14 17:54:48.063582 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 55
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d30
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 35
|
|
chksum = 0xade0
|
|
###[ Raw ]###
|
|
load = b'J\x87\xd2\xd0\xcb\xc6=\xbd\x98S\xae\xd1-49+U\x85\x1a>\x03\x9f)\xa2\xe8\x18>'
|
|
|
|
|
|
2024-12-14 17:54:48.066614 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 47885
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xc7a
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808770009
|
|
ack = 1299534557
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0xd11c
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:48.070310 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 61
|
|
id = 30919
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 41
|
|
chksum = 0xc5c0
|
|
###[ Raw ]###
|
|
load = b'D\xea\xa4\xfd\xe9\x04\xea\xaf`\x85Ui\xa5\xc6O\xc1XE(\xa4m\x99-\xe5\x1a*\xd81\x8ajKy\xe3'
|
|
|
|
|
|
2024-12-14 17:54:48.073330 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 340
|
|
id = 47886
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xb4d
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808770009
|
|
ack = 1299534557
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xb53a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x01'\x7f\x86\x19)\x9eb\xf4%\xdf\xc4\x98\xa9\xd73\xd9\xcc\xdb\xee\xda\xce\xd1\xdfc>\xb2\xea\xb9\xb1\xc6\xcf-6-:(V\x89^\x9aqQ\xb0\xe8z\x85)\xa2\xbe\x01k:\xe9\x81\xae\xa7u\xd4\xd4K~\xbf\xd6~\x83\x1aW\xc5v(\x1cK&8\xe1^\x18\xce5@C\xdcY\xce\x17\x9e\xdb\xe3\xc1>b\xa9\x1c\x9cx\x9d\xcdm\xad\xc9\xba\xdb\x07\xed\xe6\xc2\xecF\xc9r\xb6\xf5\x92\xc4\xa4\x18\x89 V\x95\xa4I\x88O\x96\xe4\xde\xc2\xfb\xde\x92\x12\\\xe8\xf3g.e\x07O\xd5\xccO&,\x7f=\xae\xc7\xd2l\xce\xf1\x96\xfaJ\xf8\xd93\x9b\x88\xe3_p\xeaY)\x86\xbf\xf6\xe2\x08x\x04B\xa7\x14\xac\xeam\x10F\x1f6\x10\xc9\xb5\x1a\xd9j\xbf\x9b\xf9\xf3\x1fi}\x98\x7ft\x04Z\xcfS\xa0,\x94\x1248Z\xc5\xab\xfdO\x15\xc0\x92~\xf2\x1bo\xd3'\xa55\x07h\xb9*\xe2f\xf5\xb1\xdb\xd3\xbdz!\xba\x17$\x9fFL\x19\x97\x08\x99O`Px%4\xcb\x86\xf5[\xe0\xad\xcd\xb7-B\x90n\x1fG\xe6\xbf\x00\xcb\x1a\xf0s\x8b\xae\x19\xa9f\x94\xf2WN\xc5D\x7f\xb7\xa1k\x1c\xaeGB]"
|
|
|
|
|
|
2024-12-14 17:54:48.087531 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 8800
|
|
id = 47887
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xea3f
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808770309
|
|
ack = 1299534557
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03@\x11\xe9\\\x93\xddW\x99\xa1\t\x8a\x99\xb35\xf28\x17,\xf9\xc2\xa3\x84rY\xef.\xb9\xa8\x93\xf9\xbfP\x1e[\xec\xf3fp"Y\xfe`~m\xb8u\x9b\x19\x98?B\\\x7f\xbc\xba}Q\xa0\x0c`\xfa\xa6\xb3\x82l\xf6\x06\xcf\x14\xad\xc3C?\xfa\x16r\xf6\\O\xda\x06\xe7\x82$\x17\x92_\xc9\r\xc5\xa9\x06\x90h\xe2(\xd1\x0f.\x155\xe9X\x82\xfa\xdf\xa3\xcd\x0f\xa3\xb5V\xa2\xec\x12\xdd\xb6n\xb9.\x9dWs\x1e\t\xc6dx\xbe\xe3\xd7m\x8c\xedI\x0c63"\x97\x15N/\xf3-\x88\xb8#?\xb8\xfeQ\x04\xcb\xb1^A\xdb\xe3\xa9\x87\xf3\xd2\xdbD$\x14\x85Tw\xca\xbdW\xc9\xe4\xdc\xc1]\x01}3s\xd0\x88J\xae\xedH\r+\xaeI\xad\xe7\x9a\xfcT\xb4ax3=\x0eT\xc7!\x88jTr\xdd\xfd\x9f6:\xfc\x86\xb1\xf1\xb2|U\x1b\xa6\xc3ZLVe\xf77\xfa\x16kt*}\xb7\t<b\x85\x01\xab-\x15\x18\xe3]_S\x1b\xdb\x14\xc5\xe9\x07\x0bT\x94Y\x93\x14\x06y\x01\x13\x14\xbf\xfd\x0c\x90\x0e\x05\x92\x93\x088B\xe6\xf0\xad\xd9#\xa9\xe3s\xe0Y@\x07\r\xef{\xb0\xa9I$4\x01\x95t\x92)\x99l\x88\xb5&\xa2b\x0em\xa6\xbf\x16\xba\xc9\x99}\x90k?\xa54 [\x1ef.\x1f[\x8f#\xf1\xe3^\xd4f\xeaP^\x87\xdb\xb0y\x8eg\x96h\xb7\xfd\xeci\xb1\xa1\xa12\xd9\xeb\x8ag\x00\x83\xef\xdc\x0e\t\xf3;55?x\xbc3\xee\xb5\xc4\xc0\xcd\xef2\xd7a\xe5\x13\x11]\xc2\x88\xc6\xa4}\xd0\x9b\xc1\xc3\x90Y\xf8"\xd9\xab\xf0\xf2[\xb5\xe4\xda\x9c\xd2@\\x\xad\xe8y\x0c\x8f\xd7\x8fK\x97\x9f\xeb\xea\xfe\xcfkP\xc6h^\xd3 \xec\x82\xe3_0\x96\x04\x00\xbec\xdd\xdb\x12#\xef\xdf\x01\\\xf7\x8a\x9e\xa9m\xd0\x8a;\x84\r=[\x1bH\xbb!$F\xfd\xa3\xe3\xa5t\xd2\x9d\xcd\x95\xa9cJ\x05\xce\x9a\\#\xf0d\x06\xcel\x9f:\xf7r\xdft\x99\xb0\xd9\xf7J1>\x96dub\xd2\x8e\t%\xd2\x92\xcf\xc2\x94D N\xf30\x83\xab\x8bg\xe6}\x86\x0ee\x18l\x120\x119w\t\xb9b\xef\xec%\x96F\xc4-\x12\xa9\xa8H\xe3:8=\x05F$c \x02\x10\xbe:\xea\x1f\xe6\xc7`10V\xd0ut\x89\x00\x0e\xcd\xa6^\x84\x11k\x80\xccy\x11\'\xe1rD\xc3\x91\xff\x08sF\x1a1p}\xbd\x82\x97Y\x16$\xa7\x13\x19$\x8c{\x80;\x02\xdfxL\xb0\xd8xs9\x11\xe7\x18\xa0\x18b3F\x8f~\xb4\x1f\xae\xb2c\xf5\x05\x92\x13\xde\xdeO\xdc6W\xb6\xcb<\xcdfb\x00v);\xd9N)%r\xd4U\xccWiU\xbc\xc0C\x03t=\xb0L\xca\x9e\xe5\x98\x04\xd5:\x10\xbb\x9a\xae\x08E~\x85\xfe]\xbd\xe3\xfe(\\gZ\\ \xb8"\xb5\xe4\xae\xc1\xf7\xc4I-\r\xac2\r\xdf;\xcb|\r;:\xd7\xb5F\x9d\xc7v\x1e\x12\x1dN@c&\x0e\xd8\\8\xe3"\x95}u\xb8$U\x7f\xfe\xdc\xee\xf5\xc7\xb3\xc4IML<3\xd3\x90\x10\xa1P\xc85\xb6\xdf#\x8c\x00\xf5\xd2\xcd\xd6!\x1e\xb9h4\xec\xa7\xb0a\x13\xb5\xee\xd2\xff\n\xf6\xab:\xb8p\x02\xb2\x9f9x\xe77\x00B\x1ca\xa7\x0f\xa1\x89c\x96\xed\x88d4\x0b\xceK{\x08\xf5\xc1\x88\xd3\x18\xd9^\xdd\x9c\x99\xd3\x00\xb0h\x08t\x99Y \xc6\xb8\xde.\x94\x0b7v\xadB5!\xc8\xae\xa6Ch\x01B\x1fK\x1a\xdfYx5Z\xe0\xab#\x0c^\xba:\xe6\x11}\x13\xc8h\xdd\xe9\x1b\x0f;\xe1lM5\x0be\x1a\x86\xcc\xd0\x9cAoi\xa5@p\x9c1\x82l\xa0\xc3\xe4G7O3\xb8\x847\xd0\x05\x14\x87\x1e\xbeFf\x97\x94\xba\xdd\x01\xbf\xd3I3@8\nO\x13\xe6\xe8\x17>\xcbs\xb0\xb5\x1c<\x80\xaemI\x90\x95-\xc8\x1b2\x19\xcd\x8a\xd2\xf4\x8c\x9bqz^P\x97rO\xe4yU\xd1\r\xf9\xa085=f^{\x85\xf3\x9d\xcbh\x86\xe4\x81\x97\x83Q\\\x91A\x18\x04>\xd6\x94l\xf5\x8c\xd4(\'\xfd[*\xa1\x05\xcdv\xe7c\x96\xc4\x16\xe5\xd2:;\x13\xaa\x16p\x00\x04\xe1\xf8K\xcc\xff\x8c\x94\xd2(\xd5\xb6\xd6\xb4\xfd\x0f<\xa2\xeeDkv\x89S\x0f\xd5\xa1\x8cj_9#G\x97v\xd5d\xbe\xb9\xb9\x7f\xd8\xf3\xe5B\xdf\xf8\xa1\xcf\x16\xeb{nI\x9f\xdel\xbdl;\xe9\x8aU\x10\x13\x12@@f\x1b\x86\x9f\xcb\xf8A\x19\xaa\xe6[dQq"\xe4\xe71=\x87\x07\xe9ky\xa7\xa25\xe3\xc7\x0e\xad\x0c\xe4\x86\x9c\x1a\x8e\xc15^<F\xe1\x18\xc7Tp\xc0\xe4\xd4G\xaf\xc2\xd72r*\x071w\xcc\xac33\x99\x97\xd2\xa0jSj\xe8(s\x91\xce\x92\x05d\xf4$(p\x8a\xec\x02\xda\x02\x90\x1b\x19~\x00\xb7\xaa\x11NLa\x8ae\x88\x95aW[?\x07\xe7\x87e}\xcd\x1d\xb8\x05\xb1\x88\x19\x03:\xe2\x82F\xd4\x0eO\x9f\x96\x1dI\xd9\xe4\xe9~\x1e\xe7\xac$\xea"\xcd\x85\xab\xa46\xe2\xb2e\xbb\xdd]\xdc\xd63B\x03`}\xbd\xec\r\xa0`\xe0x[xF\x00\n\xe8\xabI\xd6\xa2}@\xbd\xc6\x9c\x7f\x91\xc8M\x91\x07r\xdc?\x83\x90oa\xc5\xf3\x97\xb8\x12\xd6\xe6\xe8(k\x9c\xecYs1\x1c\xfc(6z\xfe\xa6\xfc\xc1\xfb\xd3v\x03\xb1Z\x19^\xbe\xb9\xb8\xf7G\xf75[{\x12R\x01bU\xa7\x92g\xebB\x12y\x13w\xd3\xeeP\x19\xb8*\xe9\xc1q\xaf<S\x12\xee\x1b\x8e\xe6\xcfw\xc2\xd5\x83h\x11\xc3\xef~Tm\xc6PiB~GA\xc3\xdb\xfa\xd6\x87u{\xd3*\xa4IQ\xe8M\xec\xe4{]\xa8\x85\xc9\x0fB\x01\x86\xc0\xf67\xadt\xc3\x1e\xecF\xea\xad\xf2\x8bB\xe8\xdbUh\xaf\x1a\xbc(\x9f\xa2A{_o\t%\xb7\x01\xe5"\xfa\xa7\x8a\x17\x91q\xb7\x15\xca\xbc\xd9\x9e\x8a7\xa4\xac)\xff\x93\x82\x90\x9c\xb2(\xb7\xa0\x1e\xf1!t\x0bk-b\x06\xf0\xb5\xa9o\xdbg \x1d\x03}dH\xec6\xab!\xc0^\'\xa1\\\xcf\xd4\x03i\\\xb3\xa2\xe7\xd5q\xc8\x8b\xeb\x8e\x82\x91\xb2\x8c\xca\xf4\x0f~\x1d\xbd\xa19a\x02\x0e\x8f4\xad\x87F#\xae\xb1c4\x0b_BW\xbd\x9a\x84B\x9e\x94\xeb\xe2\xed)\x19@\xa4\xea\x9f\xc3\xe1Qf\x05a\xa2vqy\xbc!H\xdc?QBeY\xb5\t\xef\x9a\t\x90\x18\x8bc\x03.\xfb\xa9\xf0g/\x02\xe8?\xaf\x01pT\x0c\xcb\x83\x85\xf2h\x91\xb7ug\xd7 \x1d&K}i3\xc8\xed\xdbq\xe9\xc2\xaa\xac\xdc*\x996q`\'\xb8\xfe"z\xfd\xd9\xb2\xd0z\xfb\xe3\xc0)\x183\x9e\x15.\xfa\xf4,\x95\xd6\xf8\xc4F\x9a\x94\xd6{\x13-\xc5\x8a\\\xbd\xde\xd3\xe2C\xf4\x86\xb4_\xf2\xb8b\xed\x83dn\xd4\x96aR\x9d\xc5\x88\xda\x85\x19\xf7\xac7H\xca\xcc\\\x07\xab\xf7SR\xa6\t\x1bb`0\xe6\xb3\xc0\xa6\\\xc4\xa7\xe8\xaf\x8bk\xe3K\x19\xd7|X\xa0\xca\xf9\\\xc2\x15sdU\n\xb1B{\xd5\xb8\\\x12\xc9o\xa4\x8f\xa3\xd0T\x9c\xd9s(#\x1aQn>\xa1z\xa7Z\xa6]\xe2\nR:<\xb9\r\x95]\xcc\x9d\xfc\x9e\x18\xc0T\r~\xb6o\x83\xc1\x1e\xaaYm\xe26_g!\xca\x04\xed\xc9L\xb6\x07=a\xe9\xb9\n4l4\xbfOR\t|E/\x0caVctr\x1f\xf1UKL(\xec\xa3_\x7fH\x93\x97\xdfGmvK\xe4\xf1$R\x8cF\x8a\x11\xc2\xf7\x15,\xfd\x80R\xc3\xeb\xc3\rm1\x14\xa0\xda#:\xef\x8c\x8e\x0b\xdb\x92\xa3\xb8\x14\xc2\xe6\x0b\xf1OkE\x8b\xfe\xd8\r\xa4\xbfH~\xe1`YA\xb1\xc8w\xf8\x96\xe7/\x85\x08\x9d\x99\x10\xb7\xa7\x17BD\x10@=\xe1\xa00Lyx\xbb?\xe7\x87\xf6t\x9eD\xa9\ni\xe4\xf7\xc2\xc3\xd5\x9c\xb4\xcd\xa3\x9b>\x9c\xdd\x1fh:\xf1\xbc|\xc93\xf8\xfd\xec\xad1\xec\x9d\xc7\x8f[+\xc6\x95\x8c$;\x84,\x01\x01\xbe\x1f\xbc\x92\xda{?\x95\xd9\xee\x83\xc8\x11\xae\x18\xd4D\xdd\xb2\xb4\x81%k(\x10\xdb\xa7\xd4L\xd5\xf3&h\x95\xcc2hH\xe7n\xa4\xca\xa1\xbdI\xf3\xa28\xcfo\xd7\x9b\xb3g \xe3\xceC\xed\xcd\xd2kN\xbejho\xf1V\xb3\xcb:\xc6\xd4\xb5\x11\x86\x9a\xd8\xff\x1dxh\xce\x06PC~\xedR9Q\x07}\xb8\x13\xc9-\x02\xa0\\mQ\x17\x1fG-/\xbc\x04\xcbZ\xd8:\xd9\xfb\xb8x"#\x19\x8f\xc2&<\xf8\x12X\r\xc4`\xa3\xe3\xb8\x91\xd7\xb7\xb9\t\r\xca\x0e\xedB\xfa6\xb5\x87\xa3m\x9ah\xf6\xb0rh\xce\x16\xec^\'\xf8kI`\xd86\xd53\xda\xaa\x91\xc3\xf4_R;a|\xe7\xe5\x02\x19\x99\xd9c\x15E$\xd1\t\xe47\\\x85\xffX7\xa4\xc8|\xb5C\x0fk\x9c\xddXN\x12\x9d\xf1C\xa2Hl\xbe\xf0\xe8\x9cm\xd3\xdeu\xc1\x87{\x99\xd8\x0f.}\xa9R\xf2y\x9ai\xa3\x16YTge\xda\x1b\xaa\xa6\xdb\x9d\xeb\x1f5 \xef\x190\x95\xe4\x0f\x8d\x07\x9d\xc6\xa5\x83S\xbc\x14e9\x85<\x9c\xd4 {\xb0\x9a\x949\x8b\xf0\x88\x1d\xb1>wB\xbf{)\x15\xea\x92\xd9\xe5>\xf2\xc4J\xcelQ>\xa3\xbae\xe3\xa7}\xca~\x05\xa1\xa0\xb9CS\x0e(\x03h\xbf\xc0+\xca\xa3\x94s\x05|\x7ff5\xaa\xbfh[\xc5v\xf7\x1e\n\x81\x182)V:q"\x0b\xc0\xe8b\x18a\xb1g7$\x03d8\xfb\xca"\xa8\x81m\x81<\xfbO\x91<7\x15s\xcc\x7f\xd99\xc2\x8a\x12}\xc8\xd7\xa6/F\xe6Y\x1f(\x81\xd3\xeaO\xc1\xa1\xa8\x13\xc9\xf8\x0c\xffn:,\xc8\tY\xad{\xe3\x0c\xfb\xe2Ja\x83\xa00\xe9\xf1@\xc7j\xf6.[1\xa4\xebC{\x93\xa6\xac8D-H\xc5+bI\xdfj4\xda\xa5x\xbb}x((\x1e\x99?,\xcb\xe0\r\xfapv\xad\xc5\xbdQ\xe4\xa3{ \xe8\xbfp\xbd\xba\x17\xfak8\xedEK\xb4\x95\xb8\xd9a\xef\xa9\xa7\xbc\xff\xc2\x88f\xc2\x86\xc9J\xed\x14\xa7\x14\xc4A9]\x01\xf8\xcf\xb3\xe7&L\xa6\x8f\xad~\xf1\xc1dwL\x81<m\xec!\x18\x1f\x00n\x8d\x17\xd0\xd3XpU\x7f\xb60\x18\x1e\x94:\xfcs\xd6\x0fbJ\xe8\x99\x1cx0\x8c\xc6\xdf\x1bB\xda\x8f\xa0$+\xd3\xa7\n\xb5\xbeU<\xa71hK+\xab#\x00B\x7f\xf0\xc9f\x9a\x97\x80\xd8\xf3\xa5gnk\xf7\x83Qc\xb9X\xc3\xa1D\r\x90\xd4]\x98\x868_M\xda\xeb\x14\xc1\x8be\xbc54\x12M\x8f\x13\x05\xa2~\x12\x8dX b\xb2CH\x10\xa7\xa4\xe7\xb4\xee%SN\xc3\xf9\x8d\x03-P\xaf\xa7\xee\x8f\xc1\xd0\x83\x82\x9b\x11\xe6\x1330%3\x07\x91?\x84F\x93,F\x7f\x08M\x8b\x92\xc9\xf41\x12t\xc9\xf8\t\xa3\xed\x12G(\xc1\xa8\x82\xed\xd4\x18\x7f\xae\xdaS\x07z\xa9"l\\\xb4\x99\xe0\xce\xfe\x04\xf0\xfa}H\xb5\xad\x95t.\x8a\xf9\x0b\xdd\x02\x10L3\x139t+\x82\xea\xf4\x8d\xf0\xd0e\xa3T1\x18\x8b\x17\'~\\\xd0\xfd7Xu\xe8\xc2\xfd\xb4\xeaQ\x12RH,et\xdcW\x86ne\xba\xf1L\xe8[\ng\xccW\rt?\x0c\x84\xc6\xc3\xb6\xd5K\xb3\xb6\xd2nx\xb8\xe7\x15\xa9\xe6</\xe87\xd0\xc8\xefP\x1c\x04E%\xd9\xd8\xac\x8fp\x13\xb2m\xd8\x0b\xd9\xfd6\xae\x17\xc2\xa7\x80d\xba\xb6\xf9\xa5\xb6\xd0R\xbf\xea\xb2\xc1G\xc4\xfc\x19\x1e\xdf\rk\xa2b\xfe\xad\x88\x08\xa8\xee\x86n\x93\x9f\xfc\xc1\x14!)\x0fR\xd6\xf3\x18$k\x98\x15\xcf/!kw=\x9d\x85[\xf7j\x1c_\xcbz\xe7\xfb\xd17m`\x0b\xad\xac\xa4W\x0bS\xc2l\xdfi\x1b\x06a\xd1\x89"\x10\xf9V\t\x0bqL\xfe\xec\xa4\xe0\xb5\xf5}\xb2\\\xeb\x8d\x93\x82\xfc\xca`\x9d\xf2\xadI[\xef93\x8f\xb2\x01r\xd6\x82\t#\x1b\xd0\x00\xb1]\xe5\xb3\xca<\x8c\xcf\x88\x8ct\x94\xb0\x1b\x9aM\xc5\x10i\x84\xedGy\xfcW\x89\xdc.\x04\xa1\xc8\x88o\x0e\x06\x97u\xd8n\xd3\x8e\xaa0\xf5^\xf1\x18B\xc4x\x9e\xf0g&\xfa\xd7\x0c\xa1\xff\x81\xe2j\xb5\xc4\'q:\x0c9VS41\x84\xec\x16\xe3;g\xbe\x04\x8fV\xd46\x9am\xe0\xca\x1c2\xeb\xe5\xe1\xf1A\xc4\xb1\xb2`\x80\xad\xd2w\xb2K\xc7\xf50\t$y\xdc\x93\xe3\xa5\x0ez\xd2fY\xcdJZ\xb1t\xee\x98\xad\xd4:\xc0g\xfa\xd5+\xc0\xb3\x9e\x1eY=\xd9\x07\x98\\g\xcex"\x18VZ\xa4%\x00\xaf%Y\x1c1\xa9@\xe5\xd1\xc9\x1bZ\xbd\x02\xc6?\x1e\x19X\t\xb5(\x04\xa8\x14\xb9\x8a\xca\x93a*\x90\xf1\x84\xd2\x9b\xec,\xd0\xe3?\n\x1c\x94J\xd4D*\xe0\xbfan4e^\xf7\xf9\xbb \x8aK\x01\xf3C\x9c\xc7?\xa6\x8dG\x80i<U\x9a0\xc6E\x81\xda\x16\n\xf9\xf0\xc6\xce\xb2\x81-\x12\x8azy*?\xa7\xf4P\xe9\x85<\xdb\xf4;u\xa9\xa1\xe8\xb4HC\xb6D\xee\x80\x12\x91\xea\x8b\xae*\x10=\xb0\x94.(q\x8b\x7f\xa7\xaf\xf9P\x8cy\x9e2o\x8a;\xdf\x89\x87\xd1v\xa1\xb3(Oj2\x80\x98\xba\xd7\x08\xd4\x956\xf9a\xd0 T\x85\xe8I\x88\xab\x16\x13Dq\x82\x0fEl\x9ds\xbb\x14\x8a5\x9d3\x88\xdb\xba\xdc \xe0\x1a\xbf\xea{7\x8e\x96\t?U\x14U:Q\xe6\xd9U\xe3\xf3\xf6\xa5\xc5(&\x91\x1a\x89\x1d?\x01\xc5hV-c\x12[ACT\x97\xfe\xbf\xc9y\x0c]\xc8\xfa7\xc2H\n\x87%\xf6\\\x1alO\nAM\x7fD)\xc5O\'\xaa\xbe2V\xa6\'\xa4\x8f\xd0D\xee\xf69(8T\xe5\xba\x19\x18i\x04\xf4|.\x9b^\xa7/\xdb\x116\xca\xbei\x93\x86D\x94\xd4\x93\xd59lJOv\xfe\x9e_\x87[Q\x9e\x87\xf9\x87\x07_\x92Dc\xd2P\x16\x86\xd2\xc8\\\x8bj2\xbcR\xd6\xa9\x1e\xe3Yka\xfa\xdc\xa2K\x1a\x91\xe4Mb\xea5w\x1aL\n6\x98\xf8\xcd\x00\xd8GV\xa2\xe2R\xa1\xfd\x0c\xcar9\x11\x08\x00\xe9E\x85\x17\xefq\xce>\xa2\xd0\x9f\x8f\xbe\xe8\xc0+\xdd\xb4\x1f\x14\xf6\xf1\rJ\x99\xaf\xd3\x9c\xab\x12\xa1\xbbc\xeb\x1f\x9f\x13\xaaN\xa7=\x81\x89\x05\x8c\x929\xb5\x8a\x00\xb7|R%"\x11IG\xda\xef\x8fI! \xdc\xc5\xd2h\xda\x802\x87\xb3i7\x9d\xfcG\x17W\xd3\xe8\xa9\x13Sp\xcd5\x9a\xb3\xbcq\x03\x06\x1b\xf1\xe4k\x04\x85v\x03\xb7}\xd7W\t#\xf2\xa8\xef\x85<\x82\xeal\xa2=r\\y\x7f\xf6\x0ei\xfe+5\x9b\xc9\xae\xab\x8bq\xca\x8c\x05p\xd3\x0cH\xdb\xdc\x08\xa3\x85E\xe9ur\xe7\xda\xbb\x1e\x02\xcd[\xae\xa960\xee1|\x8f\x1eH8\xaaT\xe3\xe8\x074v\x80\xd7\xc1\xef"\xe2S8ruk\xaes\xf0nq\xfa%\x1f\xa6wP\xbb}\x8e\xde\xb5\xe5\xbb\xed\x8e%\xfe\x08\x0e\xe8<A\xc1\xe3\xe2_f8=x`\x83az\xc1\xeb\xc1\xdc\xa2\xaa\x1dC\xd7\xfc@\x94\xe8?.\xa33\xc4\xea\x07\xafG\x8fn\xbe\xae\xe7\xfb\x9c\x94\xbaq\xc3<\x97\xb7\x94\xfb\x91\xe8\xb62V\xa6N\xdf]\x7f\xea\x93\xdb\xb8\x95\xcf\xadg\x9e\n\x12\xb2\xf1\x19^|Z\xc4\x1f\xf0\x18E_\xff\xcc\x92\x0b\xf5\x8b\xa2%zXpK\xf8\xdb\xc6\x9a\xfd;e\xae*>\xc2\x8e\xdbc)BI\xaa\xe3*\t[\xc4\x90\xdd\xf3\xa7\xde\xe5*\x99X\x17\xfc\xca\xe2/\xd4\xf3i\xbdc%9\xdeZ\\m\xf6U\x01~3\xf8\xddD\x1els\xbe\xe6<\xc39\xd1`/\x8b\xa3H\xc9w\x9ca\xed\xeb\xe1|\xc8\xf2HD\xe3\xb9\xc0\xc2PaQ\xf8\xda"\x85\xef\x85\x1c\xda\xdf\x80\x0c\xa6\xd7\xb3,\xcf\xdd\x03\xcbq!\n\xf87!\xf6i\x14\xe3<\xb7@\x1c\x97:\x80\x1c\xc9A\x84\xda&c\xc1\xa3\xfb\xe9\x9d(\xa9\rm"t\x01\xb0\'zf\x94:g\xea\x01Vf<;\xe7|m\x9cl\x91qa\xdf\xbb\'\xd0\x0c\xe4\xe0S\xb5!\x03\x08\xda\xa2\x9c\xdbz&\x89\xe1*\x7f\x19\xfa7_G1C9\xf8\xaa6\xecif\x02D\xcf\xb0a\x17\xcd\x9a\xcc$5\xad \xc0P\x9f\x8c1\xf0\x0c\x0b\x8e\x8c\xfa\xd5\x8dr\xeb\x92\xec\xbe\x9f\xcc\xdc\x87mPKA\xb5\xbb\x94\xbe1xX\x06M\xad`\xc86\xbb\x05]F\x1d\xdd\xd2\\\xafi\nA^\xe4\xf9!B\xb5\xa4[\x9b\x97\x86\xf4\xec\x0c\xb6\x8b\xcb\xc8\xa5U\x1b\xe3\xff?l\x82S]=\xe7\xd7\x86wEE\xe5\x14\xce\x9auO\xc2\xc7.\x0b\x8b5\xe9\xf7\x10\xd7U\x86\xea\xf8_y\x9d\xe3\xfa\xa2y5\xb8\xb4\xdd\xc1\x82\x99\xaeA\x93\x8ce\x00R\xa7*[HmM\xccB\x84\x99\xd0y\xe4\xde\xe6\xa9`\x1a9\xe0\x8fxyX\xdcx1W\xddE\xd5\x16b2\xe7n\xfbQ\n,@u\xd4l\xda5\xf2/\xaa\xa3.\xf1z2\xab\xb3s\xb1\xe4K\xc1~\xf8\xfb\xd6J\x88\xac\x17P\xa9\xacX\x02 8\xe9\xe6\xf8q\xe4\x9d\xa1\xe4\xb6XF\xf8\n\x03\x89"\xf6\xf7\xae"\xb0\x00\x7f\x80\x04\x95\xc1^\x1a^\xa5\xcc\xed\x89[q\x82\x9f-%\x81\x17"v\xac\x00\xbc\x1e\xc9\xfc$lH\xba@\xbd\xbb\xdc^k,\x9f\xe2\x0b\x8f\x1b-\xa8CQ\xc3\xb5\xa8\xe8(\xa4\x96\x7frL\xe7\xf5+Q\x9c\xf0S(\x92\xbc\x12\\ \xcd|\xca\x1b\xa3\xef\xbe\x88@ot\xe0\xe4\x19%]\xa8\xc9\xd45\xa1\xe5~\xcb\xba\xd9\xa5\xa5\xbe\x8d\xb6\x92\xcb5m}\x0c\x12wf\x1e0>i\r\xca/\t\x03_\xc5\x93\xe2\xddE\x1a\xa6\xb4\xb4\xe9TQ\x94K\x1c\xca\xe0\xa7\xbd\xe7\xe0\xf4y\xa3\xec\x8c\x14\xca\xfb+En\xe7v\xf0\x06\xe5\x07z_\xdf\xd4\x04)\x9f)$8C\xdf\x02\x8a\xfc\xf2U\xf7N{\xfa\x05\x0f\x17\x07\xab\xf0Y@K\x86Z\x9dj1\xe3\xaa5+\x9f/H\xc0\x95\x07\xef\xbc\xd9D\x9d}\x97&/\xddz\x06\xd3\xf4\xdf\xf6\xdbK\x003z\x14\rr^A^\xc8+\xa9\n\x9b\x91\xd3u\x9c&We\x05\x82\xd11"GEavP\x06g\x08\x0f\xe9L\xaa;Ko\x9bD\xd2\x03\xec\x832\x1e<fG\xf3O\xe7<\xcc.&ql9\xe0\xe2\xb4\xff\xfav\x96\x9f\x11M\xd05&\xcf\xe5\xb2d8.\x12 \xb6\xe5\xcc\xe2\x8d\xa3/\xdf_\xc7\xd4B\xddP[uv\xb1\xf7LP:S>d\xa7M\xfa\xd3\xe3(G\x84\xa7\x9d\x07\xf8zc(*\t\n\xb3#\xc2\xfb\x7f\xc3\xe9U2\xbf\x1ct\xe5|\xbc\x07\x9e>\x8b\xc5\x13/\x15h6\xae"\xc8O\x8f\x8a\xc1\xb3\x8e\xc5\x9f\xd51\xfb6\x93\x15\x06\x99\xc74\xe9 LB\xe5\x14\x1c=W0HgO%\xcc\xa9\xe8\xf9G\x18\xa8\x8e\x97\xf7\x9c\xd9\xa5\xa0O;\x1c\xb6qH\xadc|jR\xb2\x9c\x8f\xdc\xa6\xc4\x83\x87S\xa7\x1c\x84\xabA\xa0J(S\xef]\xab\xffl6\x85.\x19\xde\xcfOj\x13\xc7\x0c\x92\xd6\x0f\xf3\x95\xb5\x0e\x937\xc0\x0b\xf4\xd3U\xd4\xacKp\x88\xcb\x15y\x88\xcfm\xc7\xe9+a\x0c\xa1\x9fV\xa7+,\x1d%\xaee(\xa4\x06\xff\x8eI\xf0\x9d\x16!\x0b\x879X\x8e\xad\xb9\xd4\xe1t \xb3\xdc!\xec.bt\xc0\xda\x15`ol-\xef\xc9\xde\xf6\xd2\xd6o\xb8?e\xda\xc5\x19<\xf8\x12\xdc\xef<\x9c8\x8dUp;\x03\x9f\x0c\xe64cLKlI\xfcf\xb2u\x87f \xe8\x98\x7f\x95\x11\x1a\xb6\x91\x07\rSF5\x08EV\xf6\x10\x98\x00\xd6\xab\xa1\xf3X\xdc\x13\xbc\xcf\x1e\xa0:1\x8b\xc3\xa9\xaa\xe3\xeb8\xd0\x99R@\xb8\x00`i\x91v\xe8!!\xba\xef\xe2\xaf\xfcC\xb5\xb9\x1b\xfd\xf4\xbd\xcey\xba/\xfb,\x1e\xd7\x1fK\x1e\xb4pX0B\xb6=\x9c\x1f%\xdc\x9c\x1c%R\x9c\xd3\x15r1d\x06A\xac\xd5\xbb\xd7\xfd(\x1c;N\xdc2\x06p<\xe0:=y\x97\xc9&\x1c\x1f\xe7\xb0\xe1\xdb\xa9\x9d \xc2 j2\'\x99\n\xb0\xebi\xed-\xf7\x88\xce\xb4u\x96>\xb1^\xdb"0\x81\xcd\xbc\x03\x815\xc0s\xcd%\xbe\xa4w\xe7\xa0\xafD)\xb8\xe6\x82\xb30\xe7\x9cP\xc1\x0e\xda\xa6[,\x15\x06\xb7|p}\xc1\xa8N\x89\xb0\xec\xef\x80C\xba\xa1\x9elx\x97~n\xd2\x90\x02\xe5&\xcf\xaaHJi^zV\x0e\x1ep\x98\x83l\x04F\xa7\xc6\x00\x94\xfe]:/Y\xe8}\x91\x15\x1fU\x1c\x87\xf8\xdd\xee\x1f\xd5\xf7`o<q/\xba\xa56k3\x8b\xb5\x9d\xa3s\xacC3SF\xb1\x83u\xc1\x18\x1c\xa9\x91Ei\xda\xdc\xd6-\x02&3\x9d\xa1\xb2U\xe5\xb8\xd3m\xde\xc2\x8e\x85\xb7\xb9\xe29B\xceKf\x1d\x8b\xbemh\x06\xa7\xa0\x87\x9e\xfe>O\xe4e\xcaE\x1b\xd1\xf9\xc6\xcc~\xc5i\x16y\xd7\xd2\xe1\t\xd9o\xc5\x83\x91\x129a;\x05fm\xa1<\r\x0f\xa1\xd4\xdd\x0f\xe6\xd0=\xa3\x12K\xa7E\xe0p\x8a\x99\x88B\x01(=C@^\x99\xc7\xbe;]z\x91l\xc7ai\xd4\xa8\x0bf#t\x982\x10\\\xb7\xc9D.\x96\xfdvm\xb1\xbcr_\xa0_\xf0=\xe41\xb4\x80\xcb\xdc\xf0_M\x03_\xc9\xe5\xb6\xbd\x9e\xd4D/E\xf6\x8b+h\x1c\x95D\xef\x0b<\xe0QR]\xcf\xb4\xb1\x08\xc8a_*\xcd\xbeZE*\x8d\xa0\xbe\xd7\x11\xeb\xe2\xa4|D,S\x19\xf4\x06\xa9\x8d\xc4\x8c\x17x\x86\x86\xb9\xc8)k\xd3!+\x12C\xb3\xc5$\xc4i\\N`\x16\x0bzQ]\xb4\xa1@\\\x1c+\x8c\xa6R\xad\xef*\x03T4|\n\x1f\xc8\x9b\xb56\xa0y6\xf1\x8f_;NYK\xdc\x9f!\xa2\xdc\x15f3W\xab\xd6a\xe1_-O\xfcO\x96\x0c\x94\r\x91\x8d\xffiR\xa0oU\x03\xc6i\xea\xf3\xaa7\x146/ \x8f-\x0c\x97\xad\x17Co\n\xb3\x8f\xd54\x1c\xe6\xf9\x90\x1f\xba\x15\x97\xfb\ny\x0bg\x17%\xc9\xa8.T\x9bj\xbf\xa3t\xf5\x02J\xdaq\xde\x82ika\xeb_\x0f!\x8d\xcd\xe9\xb2\x1b\x867\xfa-l\x04*!\xb2\x16\x84,\xa7Ek\xbe\xfa\x07\xe70\x99\x90\xa5]\xb1\xfc\x9e=\x8fj\xd5\x8bE\x87\xb0=\xa4\x10 \x1f\xab\xd8\xb7\xe5E\x05\xa1\x96\xfb\xce\x1d\xd4\xd9J\x87\xea>;\xc4_\xe0jW\x18U\x83\n\x16\xb2f\xb9\x1f\xe9\xa8|\x8f\xadF,1\x9a\xc0\xf2\xb5\x95\xc2\x13\x8c\xb6#\xadN\xbb9(\xf8\xbb;\xc3\\\x8b\r\x01\xd9M\xb2\x94v+\xd2\xc8#\xaf\xa1\xc1Y*8\t |\xb4\x92\xae\x95\xc1\xe9\x8d}<\x0b\x05^\x04M/)D8\xd0\n\xeei\x9a\xd2\xeb\x88\x0b*\xb3\x809\xca-\x1c>/\xbas\xb4ZkN\x11\xc7\x9eo3j\xdd\x18\xee\x8a\x14Ug\xa5g[\xa2l\x17U\x01X\xddr^\xf8\x8f\x17688\xa9n\xa3YL\xfe\xc0Rp\xf9\xf2\xa9Y\xec\xeb\xc9\xd0\xbb\xae\xb4\xa8\xfa4\xe3\x98\x11\x06 \xf3\x03\x90\xba\xa9\x14\x98\xa1\xfbs\xb9\xe7\xbfm\xd7\xcd\x98P\xbd\x03\x80`*)\xf7\xb3wf\t\xd3\x08i\x00\x86)!\xc0\xbc\xb77:\x05\x86\x12\xcf\xf5:\x88N\x7f\\\x1b\x80%k)\xf1pc\x15\xf2(\xf0\x86KG\xb2\xee8&n\xf9\x89,L"\xfc\xd6g-\x08\x03~\x9b\xdf\xae.\x9c\xe5\xc7\xa4%.<\x94\x1e\xfa\xdbcGf]\x96\xbd\\\xb4\x91qs)\x8a\xa8\xd1T&\xa3L\xc63\x17q\x81\x0b\x13\xef\xcbG6@gAG\x00\x96\xa0\\\xf6\x8c\x9f6i\xa1Rq\xe9T\xe9 pt\x10R\xb4Z\xdfK\xc4r\xda\x93\x14\xd8\xe7R\x8e\x12O\x9c\xdd?s\x18\xdf\ts.G\xc6q:\x95\xfe\x14\xb7\xccxte\x01\xc5<|TL\xe6}G\xe2\xf3\xde\x8f\xe7\xa6o\x98\xdf=\x82v\xf87*;\x8e\xe3f\xe8\x89\x9b\xb9QK\x8fW\x0b\xcdg\x92\xe0\xb3T}"\xb6\xd5\xa5\xfb\xc6\xa2\xfd\xec\xd9\x84!\xe1x\xfb\xef1\xf1\xfa[?\xea $\xa9\xdc\x15\x8a\xe5\x8b\xb5\xf4a/\xb5W<A%<\xdeL\x04\xad\xd8\x9d\xfd\xbelN\x10\xdbuD\x9b\xe2s\'-\x89\xe8\x9f\xe1\xf7yC\xd4U\x10\x9b\xe1j\xaf\x0c\xdd\xc9\x9a\x8a\xc9\xcf\xb4 >\x18\xcfM\xd9\x81\xf6I\x1f\xf9\xf5,\xfd\xcc\xaa1T\xd8V\x8bB\x85\xb6\xb8\xe5X\xdeo"\x13\xc2\xb4\xec3\xb1\x9ai\x00\xb7\xbc\xb7\xeaT\x19(\x92\xc5\x80\xc5\x8c6\xad2\xca\xc2\x8a\xce3\x7f\xbf\x90\xae\x9b\x06\xbc\xae\xad$2\xfa\xfac\xab\x04\xe4\x90\xda^b\xde\x9b\xec\xcbP\xeaEq\x8f8\xe1\xeeU\x17\xd2\x1c\xc8\x16\xee\xf4\xfe\r\xff\x9fX]0n\xb9w\x01p\\\xf2d\xb2B\xa9B&>-\xee\xf4\xa3X7\xcfH\xa4\xf902<\xa7(G\x02\xd0\x9b\x81X\xf80\x92\x1a\xa6\x11\r\xd3\x00\xff\xeeW\x10*F\xde\x15\xc1\x11\x80\x9a\xce\x83\xea[z[l\xc1\\|\xcf\xd5\xcf\x8el\xb3\x125\xec\x07\xf6\xba\'\xe2M\xdf\xf3\xf1\x17\x95\x16\x95\x94+\x05K="\xdbO\xcb\xcal\xc6S\xf6_\xf1\x18`j\xdf\x12C\xce\xb9\x1b=\x03\xad\xa0\x19+\xcb\xc5\x9e.\xcah\x10[\xb3\x9dB\x10J\x8b\xe7\xff\xef\xcetz\xaa#\xc8\xd9\xa6\\(\xe6\x02\xc1\xf2T"\xe4 p%=.\xa3\xbbX\x0f\xda4\xbdd\x89A\x91\x06g\x84\x8f\xfa\x859\xf4\x9b<\xe0\xf4-\x91\xd5L(|#B\x02\xdfy\xe8\x8e\x9e\x89\xc7\xac\x1a)R\xd8\x16\xf8Tve\xf8h\xd6\x8d\xfcw.7\x13S\x07\xb8\x95qB\x8d\x97E\xd7\x17\xc7\xf0b\nA\x16\xba\xd7\xfcA\x9d+\x00IS\r\x0b\xca\xe8\xc7\x16\xd7\xbb`\x01{\xec\xa1\x8e?\'\x91\xbd\xdcb\xe9\xa5\x0co\xf3\x7f\x95eN\xf2c\xea\xd7\x8dx\xa7\xc8\x06\x8e<\xf4d~\xad\xbd\x146\xe1\x9b\xf3\xf0\x88*\x87\x03\xe7\xf5\xd3\xa7\xfe\x16\xdd\x85\xc3\x88R;@^G1\xfd\xb4B~\xf3\x1f:\x9d\x94p\xeb\x10\xc6\x07F\x8feh\x0f\xa10\xcd\xdc0\x0fK\x8bHW\x9b\xd5\xf4\xb2\x1d>\x85\x0e1\x14\xc4\xcc\xa3\x07\xe2\xe4\xa8\x08,\x01\x8e\xc6\xd8Uh\xa1\\\x90\xad\xe4aS\xc9\xa5\xb6\xb4lg\xa7"\xf1E\x7f\x8d\x96;\xb6e\x97\xd9\x8d\x11\xe4`\x9f\x85\x19a\'\xc2B\x1e9\xbbr\x00\xcf\xe8)\x0b\x8a\xfbk\x1b\xc7\x13\x169n\\\r\x11H_x\x9ce\xbe1\x0bCv\x8a\xb6Z\xb2\xa4\x8a\xc2JW\xc4\xb4\xb9Q\xf69\xceS\\\xad\xd3\x9b@//\xd5\xeeoq\x98\xd0m\x1aQr\xd9r\x91\x9c\x86\x02\xa2so\xf3\x06\xdf\xa6s]\x96TE\xd7\xb8\xf4\x11v\xa6\xfa\xcc\xdd\xff\xcb\x86\x16nN\xafO\x9b\xc3f\x03\rj8Q\xf1\x8f\xd3_\xfd5\xa2\x13\xaf#\xb0B\xba\xbf\x96\xf0\x06:\xed\x12\x98]\xa4O\x0e\xfb\x99\x15KJ\xb9\x9b\xa7\x1b\xb3\xb1\x07\x91\xc3\xce\xb7d\xe1C\xee\x8b\xcb\xce4\xfc\x0eP\xea\xd9>\xbb\xc1\xe2\xaf\x8d\x16\xac\xab+\x964M\x96tg\xe4\xa8\xc7[\xb3\xfb\xd7/%y\xb9\x1c\xf9\xd6\'\x13\xe4\xcf\xdeO\x93\x8b\xcb\xa8\x04\x85\xc3QD>\x91\x8b$\xa8\xdbv\xf1\xb6\x8a\xaaf!\x98h\x9eOx\xaa\x16\xf4u\xe0)\x9fs\xa9\x9bLg0\x1eE\xe0M\x8b\xdfP>q\x82\xd6/`\xd3\xa0\x16\xe1\x15Q\xbb\xa8\x0bD\xdc\xad1\xef\x13J\xcdek\x80:\x97v\x9d\x0fo\x91\t\xfdl\xdc:U?\x03\xfc/:\x84)TA9h\xfd\xdbk\xe1\x17c%\x08T\xc9\xa6\xe8\xc4\x80\xb2\xf3\xb8EQ\xde\xd5Y\xcdl\xecR;6\\UQe\xf8q\xf9\x9a\xdb\x80c?\x8e&\x99}z\xefK`\xae\xbe\xcf\xdb\xdd\x04#\xbf\x02\xb0\xd2MC\xcauV\x1a\xdf\xad\xa1B\xe6\xd2g(Tzs\x12\x07{\xc0\x9f\xefE+?\xbb\xf0\x00\x9f\xad\xc3Xf%={\t\x04r3\rK\x1e\xd3\x12&\xd2\xf4\xec\x8e\r9}\xa8Rt\xc5\x97"\xab\\\rV\x90\x9e\xc0\xe0\xe6>4\x90u:\x8d\x8cf\xed\xadL\xb6\xd1n\x91o\xd1\xbbs\xd2\x8b\x14\n\xcd$\x8aX\xd6\x01\x11\xd5Zq\xc8\xa8\xba\xd1\x99,\xde\xceL\xc3= \xab\xfb\xce\x19\xa54!\xe0\x0cx!O\xc6\xe4P\xa3\x13&\xa4\xef\xc1]\xdc\x8a\xa7\xd2\xba[\xde\xc0=\xad\x9a\xd2\xbdq\x0b\x0c+\xb8\rU\xca\x8f\xeaG;.\x98\xc1\xa29(F\xebt6o\xec\x00\x91+\x9e\xfb|\xc7F\xffJ\xf0\xceH\xd2\x81\xc1\x8eC\x8fQ\xc4\xf5\x97\x040\xb3S\xe6-d\xc7\xbb\xca\xfbk:\xf5O\xdd\x8a\xa86m\x1b\x08Q\xe8\xaa\xdb\x93\x0fzV\xf0\xe2\x19\xa9\x13\x8c\xfd\xb5\x87~3\xc8\xb3\xb9\x00\xedS"\x05~A\x9b\x1d\xac\x9a\xac\r\xb8~\xe6\xe3\xfa-\x1b\xeb\x86\x18\xef}\xed\xe1BA\xffN\xa7\xba\x90`\x80\xe2\x1c\xffC\'4\xc6\xbe\xbd\x0f\x12\xbe\xbf\xf6u\'t\xaf\x13b\xa7R\xb8\xaeB\nw8P!\x8cK\x81S\x05\x06\xbap%\xefZ\xc0\x01>\xf1\xee\xf7\xa3i\xe1\t&\xebyw\xe9`-4R\x99B*s\xf3\xdd\x04\xcb\x82\x08(\xc8q\xdc\xcbG\x19wT\xd4\xf5\xb6\xca\xd7\x15\xba\xf0\x01{ug^\x8b\xd1\x92h+\xc9:\x14-Y\xb7(\xdaj-]\xf3\xe3J\xe6O\xa9|\x93\x97\xdb\x0b\xe8Sb@h1.\x8c\xd5\xb2\xed\xaf\x94D5 J\xcb4\xdfQ4#\xc5\x15\x98\xd8%\x17\x19\xda\xe9\x08\xc7\xe0\x90\xce\xe3\xe7nw\x1f\x1d:\xc0\x15\xb5i\xfe\x1ec\xbf5\xe2o\xd8\xbaw|`\xdb\xf1(\xe9\xc6\xc5|\xcf\xef\xc4S\xb3$7L\'\xfe\x0f\t\xe1{\xe6;\xbdp2\xbbQ\x8f\x9a..\x05\xda\x05 \xaa\x1eu<\x10\xa6\xd6\x93q\xbb\xdc\x0b\xb2\xeb\xdcP\xd0\xe6]|\x9ay\x8d0H\xc4X\x95q#\'\xdd\xa6\x8bKj\xa1RL\x1b&\x040\xdf\xe5\xc3\x05\x7f\xe4\x07qsLH5\xa8\xa0\xc2\x8f\xb0\xcc\xbc\x92\x04h-\x84\x06\\@j\xc2\x97}S\x18\xe2\xae\xc9\xd5Y\x00\xea/*\nC\xc4\xd7\xb8\xfa\x08\x88\xc0D\xec\xcb\xe1%0\x89\x8c~w+\xdd\xba\x9c\xe7%d^\xa9\x7f\xe9\xdc\x83i~\xed\xb6F~\x81\x9fv\x05)1\x15\x1e\xb0\xb5*\xad\xcaFC\xc1\x8f\x9f3_r\x0e&!\xb6\xeb\xa1qq\xc2\x1e\xc9N\xd6\xb20\xc7\x9b=\xc3\xac\x02\xdb\x11/\x98\x94\xb8\r\xf3\x8f\x80(\x18Nw\xcf\xc2\x85\x05\x1c\xd8\xf9Y#\xc0\xc2\xf3h\xf9\xdd\x10 \x85\xa4lH_`\x05\x85\xe9_\xe9\x8eJ\xf7P[c\x19\x08.\x14\x1fG\xc4\xdc\xcf\xdc\x85R\xe0\x92\x8b-t\xd9\xe9\xb6hF\xbf\xec\xae\xf4\xb0\x11\xe8\xa6\x85\x16\x08\xdb\xd0W0\xcb?5\x80\x14\x04z4\xc9\x01\x98\xeb\xba\xf8b\x1c\xa1>+O\xa3\x0b\x8eQ\xc3\x82\x1b\x0e\x97\xbe:\xbf\x96\xa2@\x16\xe0\xb0\xb31<wC\xce&\x04\xc8U\xa0c68\xd6\x02\xa6\xec\xcd\xf48U\xd3\xd0J\\\x16U\x0e\xcd7\xdb\x85:\xb6\x0b\xee\xa4\x18\x06H\x10mh`~>\xad\xccd\x14z\xff\x18J&\xdc\xb6\x89U7\xb3\x81\x86\x13\x1c\xb9\x96\x97\xc6\x80\xbb\xfc\xa2D\xf3B\xb3\xb9\x01\xc4\xa5T\xb1,f\xa0\x0f\xb1qrt:@\xa4\xc5\xb7\x16\xafh\x16\x15\x03\xe5?\xa3&A\x1f\x81\x11\x8d\xe1\xe5KA\x8a\xf6\x93\x1c\xbb0\x08\xb9\xb57\xdes\x16\xc9g\x1a[SAd\x883x\xb7b\r\'\xbao\x95\x9a\xc3O\xf9\x18\xf1k6\xacg(\xffm\xa6\xf6\x8bT\x8afC\'\x81\xc5\xfd\x04\x8eC\xc0\x98M\x13\xf6\xbb\x87=[%\xea\xf86\x1d-\xfe\x14\xef\x92\x83\xce\x89=(\x1e\xdfl\x11\x97\xe2\xc0E\xf1>\xac\x10.\x82\xd5\x86\xb8\x94\xedai\xc09\\}9\xdc\x06S\x07\xb4\x8c\xe4@\xd8\xa4\xb2\xdf\x9f\xc85\xc7w\xe3\xe5\xd9\xc5{=\xd5\xf8\x06\x10\xdc5=\xaaT\xec>\x08\xe1s`\x02\xff\x1f[\x92\xe1\x1d\x9f\xc1>\x04b\xd3\x95\xc68\xcf\xff}\xac\xc7&h\xdb\x8b\xa1A$\xba\x8a\x03M<\\\xf1\x1bv\xc9\n\x8eb\x8d\xc0\xfco.\x04\xf3.g\xe0t\x02\xff\xe8?\x14Fp\x81\x14>\x03\xb7\xf3V\x14>\xb7\xe4\x1f\xf0\x84\x0b\x03\xc4j\xf9\x87\xd8@\xb6\xc57\xca\x1e\xe3\xed\xd3i\x1bq)6\xe5\r\xe1\x16pF\xf6L\xf8\x04\r\xbb_\xa9\n\x18\xf7\x03\xa2\x99\xfa\xa3\xech\xf6\x84\x0c\x1a=\xe8\n\x13\r\x1fi8\xfe\x18{\xd5\xffoX\xa8\xb35P>\x92\xd1\xc0\x98\x83h\xe8\xca\xd71\x12\x19_\t\xec\xbf{\xae\xad\x80]\x8b\xed04L*\x0e_5\xc9\xb9j\x1e{HIP\xe4\xef\xe3N\xa8f\xffu\x87\t\xeb\x98!\xb0FEC\x86\x08[\r\x05\xeb\xbd\r\xe6\x980\xa94\xe3 t\xb8\x8d\x13\x06\xe8\xce\x98\x15Db~a\xdcR\xc6\xd1\x8fh\x95\xd1(\xc1\xe6i9\xc5\x94/\x15\xb7\xc6;Uh\xe5\x10\xf8\xed\xb1\xc5\xf0-\x05\xeblp.\xfb"\xcb\xd5\x9ac\x04\xfc\x90\x07\xaf~\xdf\x8f\xa6\xde\xd1\xc1\xe2B\xa47\x04\x83\x93\xc8\xe8H\xb0\xa0\xb2;\xccr\tQ\x16]g\xa8\xed\xb8r0\xb4\xfcsi2[\x15\x94\xb4f\x1b\xa0`\x11\xa3\x97\x9f\xe0y\xd48\x06?\x12P\xd9\xe3\x06\x96g} \xca_\xec\xda\xd2x\xf4\xb2\x85\xf4X\xbb\xc6\xd2#\xd6!\x86\x04az\xe7\x1fR#\x8dS\x90\xe9\xce\xf2f\xe6\x9b\xc5\x9e\x1eo\\\xc6\xfcH2#5^7O\xd69},5\xba\xd9\x8d\xba\'O\xc9\x9aR\x91\'Y\xbe\xba\xa8\x01;\x9a\xad\x0c\xca\x05\r\x8d\xaf\xc01Y\x7fV^\xd3\xb2z\x88T\x919\xb1\xbfBB\xb5<\x8e\xd3?P9\x00\xcf\x06EN\xdd\xf3\xacr\x8c\x98\xb4\xf8\xdf\x9c\xc8\x940\xf3\x03T\xb2-\xfdfg\xde5W7\x8e\xb4\x08\xa6\xb5\xea\xd1RzV\xb6\x13~;\x8b\xc2\xc7\x03L{_\xc3\x88F\xe0\xa2\x9bx\xfa\\\xdbe`\n/\x8b\xf7\x02|\xd3\xf1\xa6\xba\x8eJ\xb9k\x8fz\x00\xed1^Y\x94\x85\xde\xe2\x1e\xfe}\xfa\xf4\xc14><\xe6\x18\xeeQj\x1dMU\x10\xeeD\x8a\xff\xd9*\xfa\xde\xfaHp7J\x8d\x1e:dV\x1f$/\x9f\x18Cw\x83\xb0\xb3\xd3\x0ei]?\xfec\x1a\xd3\x8c\x03\x80\x155\xc3;\x94\xd8>f\xcd\xa0\xd75\xb9j\xe2\xfa\x18\xd7fGA\xf6\xd7\x12\x80\x92\x9d1\xcf&T\x9b\x928\xa1\xcd>\xf8\xae\xe3\x8f\xea\x9fq\xe9t5{ \xab\r\xbe\x95:q\x95!\xdd\xfbn\x106\x05PsAx\xff\x17\xadVj\x96/\x8a\xa0\xd5o\x01\xbc\x81#\xcdAI\xee\xd7[\x9b\xd1\x06\xc5\xc5\x93\xbdn\x9c\x9f\xa9]\xc0ce\xcc\xfd\xef\x18\xed\x97\xef3\xc6\x8e\xa4c\xe1\xac\x86\x8b\xd2\xcc"Cyf\x8f\xa3\x12\x7f\x8c\xa6\xf5\xf7\xde\x10\x17\x14C\xa0\x05\x86\xde\xb4\xa7s\x82/\x8a\x83\x99\xc3=2\xedC#\xdc\x97\x02\xfe\xee\x91\x9d\x93\xa2\xfd\xe4\xcf\xe68(\xdaz\x87\xfc\xa2\xc7\x16\x80\x19\xf8S\x03\xca+9KO\x0f\xe3_nI\xce\x15}\xd2\xa3\xda.Pp\x8b\xd8\x9f\x86s~\x03N\xd3z\x0e\xf8\x8e\xcav\xd8\xa4\xc8b\xc5P41\x13\x94:\xfa\xcfP&\x8dr\x9ej\xb2\xc9\xbf\x03\xb8U\x99\xcd\n\xcf&P\xc0\xadR\xc2Q\x03}t\xdf\x84\xa7\xa6\xf5\x08\x14\x89\xf39\xa8w\xbb\x95`\xab\xb6O\xa9\xe9\xbd'
|
|
|
|
|
|
2024-12-14 17:54:48.090982 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25554
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808779069
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.094960 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 55
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d2e
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 35
|
|
chksum = 0x31c1
|
|
###[ Raw ]###
|
|
load = b'R@\x878\xda\xe0\xc2\xacZ\xa6\x96\x04}\x0f\xae\xb8%|%\x04\x003SnW\xd8\xaf'
|
|
|
|
|
|
2024-12-14 17:54:48.100405 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 2960
|
|
id = 47893
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x10a
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808779069
|
|
ack = 1299534557
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x19\xf6\x12\x82s\x1bPy\xa7\x07\x07\xb8\x86\x80\xddY\xb8\xe2\x9f\xcc\xae\x1a\x83\x8b]\xc3]\x9b%\x9b\x8dAM\x96\x89\x8c\x92\x1f\x8d\xeaNLkg\x128\x8fO{\xdf\xa6\xa4\x16\x0ek\xe5\xb9\x0fx-l\xbd=@5\xa5_v\xa84{\xb0\x9d\xef\n\x0e\x036h\xdb\x97i-\x16\x8e\xe2\xb6\xf6\xce\x12 l\n\xc0\x91Z\xcc9\x97\xacE\xee\xb3\xfc+\x82\xf4j.@r\x98\x15 \xa9\xb6/\xd8c^\xf3\x1b\xb0\xe1\x03\xecdKaN\x81\x05\x02\x81\xf4r\xf83Fz\xf7\x0b%\xb3\x97c\xf2\x7f\x0c\x9e\xd1\x98m0\xbe\xd9\xdb\x01\xf2b\xba\x19\x1b\xf8%\xfb\xa0\xb6\xbct)0\xf5\x1b\x10_\xc4:\xa8\xfb5m\x1c-*O\x1d!\x94\x00\x0c&\xf95\'\xf6\x06\xe0\x11e)U\xc2Ci!\x95\xd5\xac:,4\x00|\xf1\x02\x07\xd3\x87m\xbc\x91\xa1p\'\xb9v\x11e\x8dF\xd2\x13W\xf7\x82LF9s\xcd\xa6\x01\xd0\xe0\x95\xbc\x80+\x88\xe2\x93\x9fsJ\xa0K\x01(\xe3\xecG\xf1\x85\xd8\xf9S\xca\xd42\x7f\xd8\xf5\x0b\xb2\xf3\x14\xcb\x04\xe8l\xb6\x99dLrM\x80Te=\n\xa6\xa8\x87l\xbb\xceC\x01\x84x\xa9\x9dv2b\x05\xc1\xee|\x8d3\xbdx\xda\xaf\xefj\xb1\xd0\xd4\xea\\\xe5~\x9b8G\xb0\xe9\x05\xb6\xde\xb7;\x19\xc30l!dWM\xcc\xc7\x13\xbaO\x8a\x8a\x10e\xd3\xc36\xea\tY\xab\xc82\x18\r\xea\x04>Y\xcf\x94"\x82C\xed\xdc\x858:#\xe6\x04\x1b\x1a\xf7\xd4??)\x0c\x8e\x9f\x12\xdb\xa3l\x8bo\r\\8\x15\xf8\x1b\x9b\xf1\xe3t\xa2\xca\x98\x7f(\x87\x05pZ\xd0\xde\x96\xcd\xdd\x87\r\xf6\xd9#\x19x\xe8\xb8\xff\xedX\xfbo{\xd5\x8d\x95\xcf*z,a\x10\xee\x8e"\x02 {\xaacK\x08\xebN~\xe0\xd4\xb5j\x16\xa9r\xb9l\x8dEFrR\xd1q\xbf\x97\x8f\xb4gw\xe4\x17&,a6\xd1\xfci\xdb\x0b\x1fo\xdc\x81I\xdc\x1fV8e\x11[\xa4e\xd9f\x81d\x17\xa4\xbevV<\xa0\x1d\t\xe3\x04\xa1?\xc2\tk\xe0\xb2_\xfd\xd9\xcd\xfe\x98\xb6\xfd\x8e\x17>\xc0\x8dH\xa8\x12\xe0\xd8m\xb9\xeb_\xe6M\x07\x83\xa7\xb5\x860\xa9\x93y\xcaQ\x92#gT\x9a4&\xa7\xa6\xe3%s\xa8!\xd6q\x04\xb6\x7f\xa59\xdc\xa5\xa0!e^\xe2\xb8\t\x99kU\x1b\xcb~\x03\xc15\x16\x18,\x87&\xca\xe5D\xa1\xaf$W\xb0n\x82x\x1f\xe4W\x03\xdc\xb5\xa9\xaf!\xa3\x05EP\xd1w&\xd9\xe8\xd9tdH\xceo\xe0\x1f\x83S}U\xf2\xd6X\xc5(,\x8am\x93i\xf5\xe0O\xdb\x1a\xe4pxz9\xd9\x1d{^%\xfd\xb5\x8dl\x12\xba\xdd\x1aQ\xfaS\xd8<\xe11\xf5\x18\xfd\xbb[\xc0\xb6\x95N\t%B\xd8\x11*a\xee\xb8\xb5l\xbe\xeaLJ\x03\x03\x84@\x90]\xb6\x88\x0b\x1d\xf7\x186iP8{N\xaa\x8fF\xad0\x1f\x04;\xf3\x14))5\x02\x94\xb6\xb6Q\xc5Z\xe5\x97Q\xaf%#\xf0\x96\x1f;H\rR\x08\xe9\xf7\xef\xcfVc\xef\xc4\x9a-\n\xfd;2\xd6\xc6\x04\x89\xf5\xbaS\xef\xd7\xe3\xe0#N\xf6-jPq\xe8\x8f\xcf+O\xa2y\x01\xf1\xe3\xcf\xc3\x13\x98\x93\xfd \xacv\x91\t\xb3\x8b9\xedZ\xb0\xdc\xba\xe7N1\xcf\x16\xabc\x12\xbeQw]v\xe9$QvL<[|c\xd5\xf2\xb8\t\xa4\xbc\xc7\xf2\x9er\xec#5m+\xaa\x8c0zl\x8da+ \x88\x97\x1e\xaf\xf4\xa3eR\xac\xc6\xd3\xa4\x8d\xb2.n\xe8\xb9\x86\x16sS\x1f\xf6ee\x13\xe6\xe0\xbf\x13\xacW M\xb6\xeb\x98\xadM\xefS\x97\xf4\xa4\x11\xad&\x88\xe1;\xc7\xffr\xfcA\xcal\xe8\t#B\x19iqN:\xd4\x8c\xc9\xb1\xf1\xb2\xcf\x7f*<7\x1b\xc5\x08\xb4\xc1me`\xb52U9\x16\xebg\x18\xab\x9cs\xc8-*\x04Z\xe4)\xdb\x9d\xf7\x07W\x13(\xf2\x83r\xce\x01S\xa2C\xc2\x86\xab=\xf57\x88"\x0f\xc7\xcb)\xeaQYs!\xcbO\xa3$\xbf\xc8\xa3j\x89@\xea\xd1|}e\xce\xded\xa1\xa8\xe9\xcf\x04\x9d+\xa1\xf6\xee\xc5\xa6\xc3\xf4z9j\x16\xa2\x1f\x94\xe7$\xb7\x87Ui&0k\x87*\x14c2\xc9\xcd}\x82\n\x8f\x14\xadX\xe13\xa6<\xd2%\xbb\x17\x88\xf0\x1f\r\x83Z\xce\xac\xa7L\x0cx\xa0\xbcG\x16(\xd6p\x87uV!M\xc1\xabK\x8a\xc0\xd1\x13e\xa0g*:\xf5^\r\xfc\xfa#\x8fo\xa9\x8c\x90?\xe2\xf8\xf7v+\xca\xf8\x00\x84}d_;\xd9\x93\xb9\xac\xef\xb6\xcf\xe8\x9d\xc2)\'\xd5\xde\x0bE\xe5f\x1d\x12Y\x9dWg\xb3\x12\x8fvU\xa2}+j+s\xf8X$]\xeaYz\xbb\xe0,\xea\xf4T\xb9\x12\xa1\x8a\x10Zj\xc0<\xdc\tV]\x8d@1\xed\x86cMI\xa2\xb1S\xb9Z\x10\xb5w\xd1\x9a\xfe\x1b?\x1f\x82\xa9\xc2\xf2\x9d\xbd\xdd3\xdb\xed\x99XV\xc8H\x05Z\x92\x8b\x93n\x98\xcd\x0eP\x9f$D\x87;\xf2Jh[U\x08\x86\xba\x91\xe1\xeb\x89\xa3\x9f\x8e\xc9\xe0\xab\xe6\xee\x8d\xdc\xa3\xb8&\xaaD\x04\xf9\xb69m(Byp\x16K\xc9\x89I\x8f\xdcr\x95\xdf\xbd$a\xb9\x99\xcf\xf6\x0e\xc7\xdbh\x90\x07\x7f\x81\xe0"\xd3O\x8d\xdcH\xe1e\xc8\x9a\xb0,I\xbc\x922RG\xc7gZ\xa0\x04\xb8\xb5\xe6\n\xeb\x1d\xb9^RHn>d\x01\xee\xda\xf7\x86 \x05\x8e\xbf\x93i\xcca\xa2\xe9\xf3\xe7$ _\x1e\x05\x8a\xd2@\xc4\xb5\xd7\x81\x93\xd06\rM\xef\x8e=6\xdc\xa7Z\xf3a3\x87\x10<\xca\xc2\xbc\xa1\x17\x1a\x91 \xf8\x88E\xe2U\x9d\xc4X4\x02\xe38(\xde\x95\x95\xf1X6\xa9\xf1,\xb6h|\xafU3\'\x91\xda^=\x03\xb4\xb3\xea,\xa5U\x92=\xd3\xdck\x11\xef|\xa5\xa8\x87m\xad\xe7\xf3X\xc1\xc6 \xf2\xa1gD=\xc2\x1c\x90\xb4\xddqX\x8b\xea\xa6\xe8zn\xc9p\xe8\x93\x05\xb1]\xb5n\xf3x]\xa5\xcc\xdb{\xefSc.\x15\xa3\x9fV3\xe9i4?1D\xd0\xacP|\xff_\xc8\xb0=p8q\xd5\xc3>+\x9c(WY7\xde\x82\x8f\xcf\xeek\xe8\xc2\xd5\xc4\x1d$\x8b"&oa\n\xa73\xde\xb82<U\x90\x9a\xf7\x0e?\xa4\xfa\xe2d\xa7X\xf3\xc13\xdc\x83c\x81\xcaF0G\xe2\xea\\\x9d\x16\xc8L\xc0s9\xfd\xa6\xef6\xc3#\x95\x06\x80!\xe6\x9a\xd3\xfa"\xad\xc1>\x1db;^\xc9\xba\xf3\xddV\xed\xba\xca]\xe7\x81\x00.\xb0\x87\xec\x88N\x1d\xa4\xe9x(/\xe4\xd0Y\xa9\xd5\x86\xcb\xf3\xdf\x85\xc90\x94$6\xe19v\x18\xcb\xeeHZ\xf2\xa2\xd3u[\xa9\xafP\xb5<\x90b\xeb\xdbAS06\xc2e$\xa4\x8f\xb6N\x19\x94\xe4\xd2m\xf7\xae\x18\xa6\x7f|\xfb\x7f\xa2\xd7\x96N\x19\x9b\xea\x96\xe7\x05P\x07\xe5\x9f\xc6\x1e\xe1\'\x7f\xc2\xfb\xc2h\xe6E\xb3g\x86\xd8\xf9C\xd4\xdf\x18^\xeel\x89\xb1!D\x89\xd5\x08\xafi\x12\xa6*\x94[\xf1\x1di\x17\xb48\xe6\xe7W\x9f\x18\xd4\xc8\x8a\xf1]\x95\x08\xdf\xfbZ\xd4\xbe\xdbW\xf8vA[\x91D\x80y\x18\xc0$\x9d\\\xe8\xdd\xad\x94\x13Dl\xda=\xfez\xde\xff+\x99\xed\x16\xfa\xbb\xbe\x9a\xaa\xfc\x95\x8c\x10\x1d\xc1|\x8doc\x1c\xc2\xcf\xbe\x9b\xaf"L\xe0\xe5h\xf2O\x9fQh?i\xc1C\x01+\xc7\xa1b^\x0f\x1c\xe7\x14\xa1\x9a&\x8b\x99.\xd7\x01~``\x94x7\x00\xf6V\xcd\x01\xab\xe3\x95\x86I\x16n\xc9\tM\x13\x92\xad\xb8\xab\xed\xa8\x9e\xf35\xf8\xd3\xfd\x18\x95\x04\xbb\x8dP]\xf5\xf9\x11Y%\x90\xff\x0b6\x16 #|\xb0B\x888\x18\x8fE\x19T\'\xe0\x1c\x9b\xf6k\xe1x\xeb\x87\x92U8\x8b\x10\x93\xcd\xec\xc1\xee\x06B\xb8\xad\xc4M!\x9c\x11C\x0c\x8do\xd7\xc1\x13K\xb2p\x96\x91\x8d\xba\xbf\x94"\x8d\xfb\xf4\x86\xe9\x14\x9a\xdf\xe2\xc7\x8d5\x1bF\x94\x7f\xb6\x0e/F\x82\x9cO\xf1\n\x9bp\x17hL\xb6\xfd\xae\xde\x13\xf3\x080r\xe9\xfd\x0f\xf7\xfe9*Q\x8az\x18\x03\x17\xd8\x02P\x83\xacXT\x14\xe9LSI"\x8d?|i\xd1P\x88\xfd\x15\x15\xf3\x1dqoq\xdc\xb6\xc2\x9d\xf4d\x98\x10\xc5\x05\xc0 \x86\x042n\x11\xd2\xcc6>~\xb8\x11n`\xf2@\x14Iy\xaa\x04\xc4\x0e\xe7d\x9c\xaf\xf8\x0e\xc8\x08\x8e\x97\x83l\x0e\xc3x{c\xf7\xdb\xc2j\xbb\x1b\x90\xe0\xaay\x9d\xeb\xf6\x9e\xa9\xfa\xdf\x18O\xad\x13\x11\xe0(N\x98\'\x8f\xcbO\xc1Q\x02\x15i\xe5\x82\xec(*\xb2\xfd\xfd\r\xe6*\x8d\xa40\xd3\xb6\xf8\x04\x00^\xdf}\xf0G\xba\xf7\xe3\xca\x15\xb8r\x845\x92\xe2\xaaH*i\xf6\xbc\x86\xdd\xa1\xfe \xdd\xc5\xaaa\xe2\x9c\xcd8\xcbt5"2\xb5\x00p\x8a\xb0U\xe9\xbc2]\x96\xcc\xb0\xa2\xf4\xa77F\xf9\xf4\x9c\xb4\xf9+\x07\xdfM\x05\x17\xdc\xc0,l\x19%\x8ed\x1b\xaeb:\x94\x90\xc6\xedp\x1dl\x85#\r\x8c\xb9\xeb\xd6v\xd5\x8d\xaf4Xc\x06\xca|\xfcc\x97r%\x1a\xf3wZ\xb4\xbd\xcb"\x88\xff\x04*\x03\xac}e\x11\xd8E{\xa9\xfe\x9c\x14\xd4LW%gOp\xeb\xb7||\x83?\x017\x91\x86\xf1R\x94\x9f:\x06\x9a\x0f\x03\xe0\xb7\x01\x90\x98\xb3a\xad\x91\xb9!\'\xd7\x00\xd5\xc8\x91Wxlm~C\x04\xac\x1d\xc7\xd0\xd68\x87\x01\xc8_\x7f\xae/p\x11\xcf\xcb\xa8;\x137\xbb:<\xf05\xc6{(!#M\xde\x97~\x92a\xee@\xa7\x87\x91\x1bY6\xc1tsYP\x8a\xa75\x18;\x8bI\x0c\x08&\x1f\x13\x19\xe9|G`\x91\xe2\xef\x0cR\xb1=\xe6|\x9b\x11/DSQ\x81Ub2[\xbc\x9e|<.Kfs\x0e\xd5\x05\xc5R\xf7\xbd\xa7D\x1d\x16d\xd2\xa7\xfb\x99S\xe2\xca\xb4W\xb5l|p\x9d\xfaAd\xd3/t!:\xf1\x9f \xc0\xaeK\tg;?\xe7\xedA\'\xa3\xa1\x93=\x95\xa2y>M\xc8_ \xcb\r\x9f0\x8bW\x81B\x96\x04"\x8d\xe5\xed\xca\xd7\xbc\x81Z\xcc\xa9\xf9\xe2\x1bmS\xc6\x8c\x9f\xfb\x80=\xd3\x07Q\xe2$\xf1\x11#\xfeu\xa2d\x84%_\xf4\xa8A\xb7cK\xec\x80\x9b\x18E\xc9eI \x11\xa6/p\x7f\'\xaf\xfd\xa7\xdc\xbe\xff\xa0\x99v\xaa\x02\xf6\x08\x94\xfb\x10p\xa6P\x00l0\xa3oVM\x93\x06\xbe8\xf6\xa0\xbc\xaa]9\xd0;\x0e\x19\n\x8a\xb3d>\xe1\xc9=\xd12\xbc^}\xd2\x02\x17h\xbc\x03\x142\x93\xf16z\x8dR\xc8?\x83\x983\x9ex\xfd\xf7\xcc\t|sL\xcc\xa3\xbc\x15\x92$\x8f\xb42\xc0\xc9\xb5\x8e1\x93\x91\\\x80\x96\x92@\x8a\x150\xa4\x85\x8b\xf9\x9e\x89\x9ey~&\x16t+\xaf\x98\xf5\xf4g\x97\x15\x80\xf6\xc1\x07\x9e(\xa4n\xbe\xb9\xf0\xef\xf0\xf7mr$\xdc\xd77o%Vj \x1c\x12D\xaf\xc9\\\xe50@\xc1N\x9e\x0c7\xca\xbf\xc4\xd5ze\x08?\xea\x88\xc3\xc5\xa5\xe6\xf3\xf5\x8e\xca\xee9\xba\x08\x17c\x87%\x96\x04\x1c\xa1\xbc \xd2\x87B\x8c\xa9\xa2pf\xb2x+\xc3\xc7\xfa\xfa2!\x99j\xeb\x89\x8a\xa5\x84\x10\xdf2\xddt\xb9\t\xfb\xcd\xa5\x1d\xee&\x90L\x18kfJ\xdb\x00\xea\xe6\xecCH\x06B/\xee\x89\xaed\\\xb2\xd4\xbfo[\xfb\'92pA\xa9K\t\x93v\xb4\xe1\x06f\xbd\xa3\x80B\xc0\xaawAT\xa2\xae\xf9\xb5\xee;\x13#\xdb\x97\xce\xf6\x19\x8c<SK\x8f~\xb3\xb6D7\\\xde6\x05\x90{-\xc2\x17\x0b\xcb\x93\xc0\x87\x88\xf7\xfb\xd4\xfd\x8bB\xf0ae\x13E\xf8\x0e\x19\xf0\xa9Vi5Q\xc8=\xed\xe9\x98t\x05\x1f g\x0b\xd5\xb4[\x9b\xab:x\x07\x06\x86\x0b'
|
|
|
|
|
|
2024-12-14 17:54:48.103481 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25555
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808781989
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.107751 - Ether / IP / UDP / DNS Ans b'image-scdn.cdn-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 341
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb63b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53494
|
|
len = 321
|
|
chksum = 0x4cd4
|
|
###[ DNS ]###
|
|
id = 25435
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 5
|
|
nscount = 1
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'i.scdn.co.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'i.scdn.co.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 64
|
|
| rdlen = None
|
|
| rdata = b'image-scdn.cdn-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'image-scdn.cdn-gslb.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 60
|
|
| rdlen = None
|
|
| rdata = b'common-eipb-ak.spotifycdn.com.edgesuite.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'common-eipb-ak.spotifycdn.com.edgesuite.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9333
|
|
| rdlen = None
|
|
| rdata = b'squadcdn.scdn.co.splitter-eip.akadns.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'squadcdn.scdn.co.splitter-eip.akadns.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 29
|
|
| rdlen = None
|
|
| rdata = b'i.scdn.co-noeip.akamaized.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'i.scdn.co-noeip.akamaized.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 141
|
|
| rdlen = None
|
|
| rdata = b'a1520.dscc.akamai.net.'
|
|
\ns \
|
|
|###[ DNS SOA Resource Record ]###
|
|
| rrname = b'dscc.akamai.net.'
|
|
| type = SOA
|
|
| rclass = IN
|
|
| ttl = 504
|
|
| rdlen = None
|
|
| mname = b'n0dscc.akamai.net.'
|
|
| rname = b'hostmaster.akamai.com.'
|
|
| serial = 1734194891
|
|
| refresh = 1000
|
|
| retry = 1000
|
|
| expire = 1000
|
|
| minimum = 1800
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:48.125900 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 11720
|
|
id = 47895
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xdecf
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808781989
|
|
ack = 1299534557
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'n\xf68M\xcf\x8f\xdb\xc77@*\xd8=:Zn\xde\xf9\xd17\ra\x9c\x9d\xbd`\xc3\x1aN\x08\xf0=&t\x90\x80(\xa1YJ\xd3\x8b ~\x90k\xb8\x85\x89\xc4\x05\xbc\xa0\xec\xa5P\xd5\xfax\xc2(\x88\x9a\xe9\xa4\xb8\x0b\\\x19\x1a\xcf\xa2\xf0\x07\xb5\x00V\x99\x91\xcd$>\xb9\xf3\xf7\n\x90r\x8c\xdeX\xcc\x7f7\xd1\x13:\xebh\xe5\x89\x83\x9e\\/O\x15\xab\x0bz\\l3\x0bA\xc6\x96V\x1e\x8e\x8c\xd3\xfc\xf5\x86m\x11\xd5\x0f\xfb\xacM\xd6\xd6\x91w\x95\xbf\x8f3^\x18P\x8c\xc2yl}\xfd \x9fX\xcc\xcf\xfe\xb3\x91\x88\xae\x0eP\xf6\xd8+\xd8v\xe1\x99\xa2M!\xbc`\xce\x1e\x9c\xdbQRW\xd87\x98\xb0\xda.Q\x04BL3\xbal\x8c\x8b\x10\xd7\xbd\xc6\xc0\xd4G\xc8\xe6\x90\x01\xa2\xd4\xc1u?\xb2;^\xb6\xb6I\xb8F\xc4\xbf\x842&*\x90\xd1\'\x19X\x1d\x88+X\xcb\xe3\x14F~2 \xdasY\\\xed\x85\xec\x85\xc9\x9aI\xcf\x85]\xe1\x83"c\xff\x9c\x8b0\x0f\xee\xfa\x03f\x7fl\x96fh\xd8\n+\x85\x08du\xd1\xf7Ei\xde(\xb6\xd9\xc2\x12!\xcc\xe1\xf1\x9b4*\x9d\x9d\xbc%\xdb\xbfmb2\xee\xac\x08\xf0;\x0b=-\xec\x82 \x04\xc1=t\xf8/|\x04\xb1k\xfe/\x8b\x00\xdaF\nq\xc5\xe3\xab\x99\xa8\xb8\x1dB\xbaP\x89c\x10m\x98od\xac\x04\xd7Hw\xea\xaa5\xb3\xffc\x8fY\x1a\x0e\x9c&\xd6\xcc\x1fJ\xeec\xd5/6\x01\xc7\xa24E\xcfjIt\x03\x9f\xdc\xfc\xd1\xba{p[*\x9e\xd8\xc3\xae\xbchP\xa1\x18\xfe!2\xc10wV\xea\xb6\xee\xc6~\x1c\xe8X\xceRfU\x06\xc4&\x8d\xc5F\x80\xdc\x87\x9e\xd7,\x99\xb2\x16\x1c\xca\xb1q\xb0\xe0&-\xd0\xdf3e\xcd\x95\xdd\xfeBXG,\xf2\x10\x01{\x0e\\\xd8\xb2\x99\xa1IRn\xb5\xa9\n~\x94\xc2o\xe7\xec\xc0^\xd7\xb1\r\xa4\xcd Uls\x8b\x85\x19Us\xa22\xd2\xf30.\xc2\x90/u\x9f\x98Y\x03a\x0e\x10\xc9[\xa9\x9a\xd43\xcdY\xb4E\xd6f\x19\xf0#\x1eQ\xdfd\x08\x8a\xd1\x0e\n\xfb\x803\x86x\x86\xb5\xa1\x7f\xd6]\x07\x1du\xc61\x9e\x05"\xb1c\x91,\xabw\x9cr\xaay\xdf\xc1\x8b\xe3g\xfb0\xd1t\xfd\x03\xac\xa0\x16\x96\xdc,\xd5i\x95\xaeq=N#\xfc\x12\xc7\xcfu\xfa(\x10\\\xc9\xb7,\xdc\x02\xfa6\xcc\x08\xb7\x06\xc5\x10i\x1f\xb4\x85Ea8C\xcf\xe3\xd7w5\xb9\x87^\xc6\xc7`.\x7f\xb8ok\xc2\x9d\xf7;\x05\xd2\xa4\xe1fl\x00C\xfeW5\xd4\x8ao\x90\x1ehF]6"\x8fG\xb7\x04\x08\xea\xf5\xb6\x94\xedqi\xdb\x1f*\xeau\x11|\x91;E\x98\x10\xfe\x1b\x07I\xf1\xb8\xa6gH\x06\x10\x12\xea\x83\xd7\xc7/\xd8\xf5\xb7\x871C\x11\xa3\x9f<\x0eS\x1e\xf6\xe1\x99$\x99\x90\x11tm\'\xd3\x82L\xc9\x06\xfct\xdc\x0e\x03\x8b\xc7\xf0a*\xc9\xfb$\xeb\xe9\xb9Pv\x19y\xb01\xd9\xb9@\xbf\xc4\xfe\xb9#>\xc7\x91\x82\x1f\x8d\xa2}T[\xd5\x17\xe7t\xb8GA\x84\x13\xb4\xa9\xa5\xf4\xd3\xc5\x00\xba\xe3n\x8f\x18\xb2n\xb7Qd\xaeu\xe1\xba{\xc2\xe3\xe9\x80v\xf7\xae\x1dR\xd0\x98\xbd\x12G}t\xf4\x8a\x15\x18\xb4cb3\xf7\xf7\x97W\x9e\xb4\xccd*mH\xceU\xfeYN\xfe\xd9\xf9\xfc\x16\x05tUKH8\x9f\xa2\xb7-a\xc4\x9b\x04\x87\x8d\x01(\x17\xa2o\x81l\x0c\xc3}a\x9d\x8fQ\xa8.@,CA=\x94\xd4#=\x03\xfd(\xf82a\x9d\x94\'\\@\xb1@\xdb\x1e\x8d\x997\x17dL\xc4\xcd\x0b\xebf*\xa8\xc2\x19\xf4\xab\x0ep\x1fe\xfc\x0b\xae\xda\x8f\xd5\x84 \xc8\xbf$\xc5`P\x129\xe0\xb5\xfdE\x01\xa5\xdb\xfc\x89\t\x08~\xb9>t\x01J\x1c\xfb\xfc>\xa1L\xa4C \xc4&4\xc2\xa9\xe6\x00\xb0\xfd\x0e[\x1ak\xa9b\xa9K\xdb\xb1\x0e\xf8\xf6z\xcc]\x08}\xac\xc6O\x83\x19Y~\x94\tp64\x9a{.\xc2\x12\xe3\xf2\x08!\xe34\x05\xefC\x93\x8a\r\xc16\x0f\xd5\xee}\x87&\xa37\x97\x84\x9f}\xc0\x83\xae\xf6_\t\xb9\xad\xa2E7\xd9\xe9z\x03k#\x9f\xd0\xa1\x10\xe1,\xfaF\xc0`9\x87q\x11\x9c\xa9\xa1G;#dxG\xc0\xe40\x9aWXe\xf4\n\x1d\x80w\xdf\x0b\xb5\x17\x90\x92\xc8\xa3R;[.\xd1S7\xcbCc\xe3!N\xf7\x04\x81\xdf\xab\x92#\x97\x07\x13y\t\xd6\xf2\xaeW\xb5j\xf1\x8e\x96IGs|\xcd\x1a\xb6\xa0\x0b\xffpm\xa2}\xc8?\x95\xfb=\xf3\x1d\xd0l\x04q\xc4a\xab=\x1c\x82\xf6H\xd2\x19\xdfR4\xe0\xb1\xc7~Ji\x1e\xf7Y\xa9\xa7Q\x93E\xb6\xca\x1e~\xf5[|\xca\xb7\x9dKP\xd1\xad\x82(2\xa2+ ~\x80E\x88\x9d\xea9d \xe1\xb2\xf9[\x00g\x94\xc9\x1a\xfe/T\x17\x1e\x1d&\xefju\x9a`g\xcb@\xf1$5\x01\xd2a\xa4\x1d\x18\x99\xb7;\xd6\x9d\xdb\xb6\x9d[h\xf9\xb6\xbc\x90\xa89D\x87h\x06M)j\xac\xe3\x11\xeb\xa9\x93\x0f\xa6\xc3\xf4\xf5\xd9\x99]u\xebO\xa1\x0b\xc4o\xde0I\xa3\x9e\x03\xed|\xa1E\xd7\x815y\xfee\xf9+*S\x9ch+8\xd6\x9a\x91\xda?\x82\x1a\x83\xfa\xae\xb3$\xa0\xa1X\xcdG^\xe6\x99\xf3\xb6\xc1\xa3{Y\x8a\x1fV\xc8\x849\x8e\xfc\x1e\xbbu\xffauf\xb2O1\xaf\x91\xba?\xae;)\xb3\xd7\xd3,\xa2\xb4\x82D\xfa\x88<6\xb9`\xb0\xa8\xcaM\x08\xfcZsb\xa3\\%A@S\xa0\xd8\xec\x92\\\xac\xbb\xea\xde4\xcb\x80\xc7\x87\x90\xbb\x0b\xe1\x169\xbaPS\xbc(4v\x06k{\xe6\xd6]Y\xb8\xe6\xd1\xce\xdcj^\x14\xa6\xda_\xac\x94\xc4\xb7\x97T\xf8~PB\xef\x0f\xc1F\xe0\xf5\x0e\r\xe8\xbd~\xc5)\xee\xabH\xc8\x84\xce\xcc`T\xe9`Lg0\x05\x08\xdb]r\x0c%\xe7\x9e\xd1\x896\xce\x8e\xef\xf3\xcc\x16\x08\xa7$\xb8\xf4\x02\x8aG\x01\x9b\xea\xe5\r\x1b8\x8aG0\xf0\xdf\xb0V\xb2=\xa2\x90\x021\x1ak\x99\xb7\x1f\xb3\xf7l\xff|\xb4\xb1\x9c\xf8\x89\x14\xe9j\xe9\x1a\xde\xf1\xd88y\xf7\xd2.DE*GAG\x9f\x822\x0f\x0e\xc7M\xe9\xa4\xbb[\xb3\xc3\x12?\r\x84\x88hB&\xd0*|\xc4c\xd3i>\xbf\x17\xfc\xa9\'\xf4d j\xb2\x056\xb0\xd0\xf8\xe1Ht\x13\xa7\xe3\xde$\x1bd\x033\xcc;\x06\xee5\xd7@\x1f3\x0c\x1b\xab\x9ff(\x9aG\x90\xcb\x81\x0e\xb3\xb0\xa7\xc6\x80z?|k\xba\xc6A\x83ck\x9b\xcd\x0c\xca\xf7\xee\xce+G\xae\xf8\xe6\xc79.\x0b\xf7bb\xdf\xf6\xcf\x96x6\xca\x88Q9\x11\xa7\xab\x10(\xdf\x9fa.\x1cx$\xb6k/q\xdbP\x02\x85h43I\xac\xb7qw\x11n4]9G\x82;\xec\xfaL\xf6rJ2\x9e\x96\x05d\x83\xda\xa1\xd4\x03\x8d\x998\xc5\xa7#\xa7\x12\xf0\x8fGF\xc0\xa2\xf3h\xb5\xb7j\xdeV\xc87\xb5\xcc\xa3\xb8\x8d;p\x97p\xd7X\x99\xe35\xe7R.\x03\xd95\xfb\xbe\x1c\x96\xda"\xfd\xc0\x80\xceT%7sk\t\x0e\xb0\xece\xe6.\xe2f\xd7\x13k\\I\xdd\xe2\x0f\xb9I\x03\xbeCc\xc7\xd3#\xc6\x90}\x88\xe0\x7f\x12\x84\xe3\xe7M\x8c\xba\x02r\xc2\x9d\xa3\x98\x82\x7f\xf3\xe2\xa1w\xce\xda\x82\xba\'m\x1f\xe1\xc2\xd5S\x99\x08\xbe\xab\xdc\n\x94c\xf5&H\xa4fi\x16\x95!o2\x0f\x80\xd2\x7f\xb8:$\xdf!(\x15e\x04\xc1\xd5\xd6\x07$\xc8E\xbd\x84\n\xc0\xd5[\xfa2>`YZ\xfeX\x12\x1e\x17\xe8\xc2\xd1\xa7_\xfa\xb0 \x8f/\'%\xcb\x8c29\xf1Ij\x1a\x0c\xe6 \x1b\xcd(\xbb\xca\xf4#\xcd7\x08p\x9a\xc3\xa5@\xe2b2E@2\x1d[\x0eY\xbf\xcf\r\xde\xb9\x93\xfd\xf0\x19\x97\xc3$\xf3\x8e\x93\xc0\xea=;K}x\xf53[_\xf7\x98\xce\xc8\xdfl\xe7\xb8\xe9\x9b"s\x19\'\x8al\xf2S\x9e\x1eY\xc7\xc5|\xb8\x98j\xa5\xfd\xf6)\xd1\xbb\x14f\x9cH\x0c\x91\xb4\x9f\x179\x049\xd3x\xe2\xe7\\+Of\xae\x1a#\xdb\xc3T\xfb\x19":U^\xc3\xf7dw\'#l\x0cr\\\xef\x87\x93\xa9\t\xac\x91V\xc2\xfe\x0bZ\xa5\x90\x80\x05\xe37\xe7F\xa8\xa5Ky\x1d;"\x8c\x8e\xaa\xde\x91\xf2f\xa6\xd1\xf7\xad\xf6\xd7\xd6[\xc2\xcfi\xf8-&1\x07`\x93\x05\xa0\x80Z\xd3\xb3\xe3t*\x86\xa9\xb5\x8a\xd6H\x94\xad\x1a\x8e\xea\xef0\x85fV\x96\xedL\x1d\x9d\xfe\x95pq\x04N\xe4\xb6\x0c\x04\x15\xc9\xe0\xba\xe8\xa72\x03\x87_\xe69q\x9an\xff0a\xbd\x17-\xd6\xfap\x03\xc6@\x17\x07\x14\x9b\xa3\x1c\xce\x86=\x9d\x1f\xfc\xd9f\x8f\xc3\xbf\xf9y\xc9\xd5\xaa\x99\xddG\xf2\xc8\xd6!\xf7\x0b\xdd\xfd~90\x9f!=\x1e,%\xf1\xd0\x85\x8f5:1_Y\xb1\xea\xfa97\xe4p9\xfb\xdb:\xaa\xc9*\x8e\xe7\xce\xde\xb5\x85P\xe4\xad\xf7\x13*\x93\x12\xbc\x89#*\x93>\xd0\x82\x98k\xe1Zo\x81\x00\x88\xf7\xbb\x17\t\xb5\xab\xfb\xb9y\'H.\x8b%\xf0"yK\xfaiU\xef\xaa\x08ME\xe6\xd6\xaf\x18\xebd-\xc2\xff\xc7[\xc3N\xc9\xa0\xff\x19M\'\x88\xb3\x15;LUV\xde\xd1\x95p\xe8\xcb\x1dc0o\x15O\x1d\xa0\x19\xd0p\xc4\xd3^\xee\xd4O\xa0Y\x84\xa8\xd8\xaf\x84\x8e\xe2\x80\xb9\\\xe5\x12D\xeab_4\xdcp\x05\xf0\x89;i#\x9e\t)t,\xd4b\\kVY\x17\xff\x8f\xa3\xfd\x98\x18%\xfe#\x1e~\xdd\xd3\xda\xdf\xbb\xf2\xa8\xdc\xb2\x1f\xf1\xb1\x02\xd0\xe1\xc0nyp\xc2\x95\xad\xe2\n\x91\xf9\xac\x0e\xb3\x87{p6\xa3\')E\xb9\xcb\x08\x9d\xd2\xf5^\xf6\xdaS671\xb2\xe0\x94\x1b3MJ\xd0\x9f\xbb\xd6\x9d0\xad\xdd\xc9\xe2UH;\xe1ks\x9dC\xc6}#Z\xe9\x83\x80\xe2x\xef\xf1\x83\xc6\x8bg\x03\xed\xe5\xc7\x07\x9cB\xb4\x0f\x84H\x08VB\x8a=IX\x1c\xf6\xde\x88\xb4\x8e\x0f\x96Z\x82\xc5\x05\x17hR\x14&\xa5Ez[w5\x16\x86\x11\xc4\x89`\xd0M\xf8Rs/\xca\xd7\x1fr2\x0b:p\x04\x14\x16Wh\xc4\xe9=\x19\xe4\xc2S\xf6H\x0e\xd1\x97^\x1dU\x81\xef,\xa2\x11\x12\xccA\x13\xd1\n\x16\x0f\x12\x8a\x8fK\x9f\x02{\xf1\xb6\x94I\xa7\x9c3i\xf1u\x12<\x88/e\xaa[lC\xe6\x0c(U\xa0\xcf_y\x95\x05>)\x08b\xfe\x9eBz\xb0~\xb0\x85<a\xdd\x7f4\x9c\x04J\xb2\x7f\x99\xe8\xeb\xf2\xcb[\xe8\xd85a\xc2M\xed\xc7\x9b\xdf\'|\x05@1\xc8\xb9\x06\xedj\xbf\x87\x8b\xaa\x98*\xc3\xc3\xd4l\xa9^\xed\xd1\xe1\xe6\xa5\xe7\x05\xee\x12\xbc\xeb\xa1\x97\x83\xae\x8fI%\xa41\xc3P`\x94k\x806X-m\x02\xf8;p\x1a\xec(\xc6p\x13\xb8^$\x9b-{\xa9\xa5d"\x16z*\xea\xa9\xbb\xa8\xa0,\x10\xc8K={\xd4\xa28\xb3\xc2\x92\xea\xdb6~\xae\x0c)W\xa7\x81\xe4\xbf\xef\x95!Pc\xc1$\x7f>2Y\xd2P\xec\xe0l\x9b#\xcf\x82y\x1b\x7f\xc9+^\xf2\x98\xf6`\x8d\x82\xd4\xb2\x02uG^\xed\xa2\xd0\x88J{\x900\x0b\x91\x9e.q\x8c\x1d\xcd\xb7\x8a\xaa0\x8d\x8b\x96\xee\xd2\xa8\x1f\xd7\xc4+\xea\x0f\x8a\xcaqKL\x02\xf0%T}\x9fT\xc6\x0b}n\xe8\x8d\xceYa\xa1\x08:\xca"\xed\xc4\xe6W\xa53\xe3\x8a\x8fW\xab\x97\xbf{\\*E<t\xd4\xf5\xda&\xdcG\xea\xecB\xee\xf6\x82\xe3\xac>x\xe6\xdaJ\xaa\x07\x0b1Z\xec\xd4K\xd1\xfa\xd4\xe1K\xf8\xad\xb2Wb\x8a\x97\x04\xbf`\xdeo82\x9bp\xbe\x03\xd0&i\xd6\xa3\xb1\xfcb\xb1{\xa3B\xda\x1c8{t\\H[b9;4y\xa4 \xadxL\x80\xf8\xd6\x19\x00\xac\xae\x9c\xaf\xddM-?}h\x9b\x93\xc2g\x02?_\xa3\xcb\xa0\xd8\xf7"M\'7SG\xedr\xbd*\xcd\xc49\x1f\xffc\xd5\xa5O(\x85}\x15!\xa6\xfb\xf6\xb3\x16*\x08P\x92\xaf\xa3\x17\xa77\xeb\x01\x1f\x88h\x89\xbe\x94\x15\xbe\xd7\xe8\xe9\xc8\x00qjh\n\xce\x1f\xb0|\xfd\xf7\x84J6pO\xb6\x80p\xccTW\r\xab\x1ai\xee\xda\xe6\xc2\x9e\xa4\xbf#v;\xb3\xbb\xefg\xb7\x8a\xff\x9e\xc4&\xbe\xdds\xf3\x02\x87\xb45\xce\xcc\xf0\x8d\xc3J,\x1c\xce\xfdK\xb3\xd6\nk\x11B\x93\xf8\x11>p\xdb\xc9D\x94\xa5\xb8NjJ\x16_\xef\xe0E\xbf\x16CC\x7f^\xff\xa9\x02\xec<\xcc_4f\xa5\xb2\xf4\x99|\x99-)cr\xe9n@E\x0e\xcd\xde\x82\xa8\x97LhA\x981A?\xcb \x85T\x843\xd9\x8c{X\xb1lU\xc8e\x0e\xac;\xea\x02\xeft\x81\xbe\x0b\xea \xba\x9e\xe34\xce\xa2\x9eF\xbd\x9fp\xed\xcb\xbc\x05(\x94\x91\x1e\x1c\xd1\x10\x17BNwW\x883\x9b\xc0\xc6y\x05<\xc9Ak\x0b\xa6c\xf8I\xf3\xd7\x94+t\xed\x825\xa2\x8d\xec\x0f\xec\x14_3\x1a_\xa9\xe7A UBo\xca\x06%v\x8cG\xb9]\xf6\x15\x19:2\x8bu\xf4\xea\xf1\xd4u\xcc\x86\'\x86\xde\xf3\xf6\xf7\xb2\x15\x90\xfd\xa7\x1e\x1b\x18W@{\x13\xc9\x18I\xdd\xe6\xd6pLf\x8dn\xba&=\xf8\x1c\xbc\xc1\x15\x00\x7f\x11\x19V)_\xcb`4\x94\xe7\\\xf7\xc2\x90\xfc\x80\xf9\xef\x19\x1dYv\xce,F\x9a\x95\x1c,\xe6\x8f\x14c\x98c\xa6\xf9\xce$|\x98\xa0\x0f\xb2\xe0G\xbfb\x05\x88\xd3\\\x898\x03\xf7\xb8\xb3\x0b\xda\x06\xcd\x00\x0f\xf2\xac\x10\x01\xf2\xa0E\xcf0O\xb0g\xf6\x96j\xc24\\\xd7\xe2p\x81\xb1\xeb\xf1-`Tx\xdd\x90\x8b=\xf9\xb1\x1b\xe7\\}\x84\x9f\t\x08\xd4e*\x91;\x9fQ\xc3\xca2\xf5$t\x1f\x14\x8f\x0c^\x0b]\xc0\xa2\x00\r\xffn\xbf\xb1\xb5\x88\xbf\xcaeu\'\xcb\xbd8\x0b\\1\x07\xad\xfb\xfc\xb1!\xe6\xb4\xae=\xb6`\xd3\xca\xb8tU\xf7h\xb4-\xbfb\x11\x1a\x87\xa4\xfbu\x80]\xc3\xbc\xea<\xed\xb1\x15\xda.\x01\xa1CjR\xee\x96<\x8c\xddC\x0f[\x01\x8b\x98\x83\x88\x89\xcdNk\x02\x0e\x9b\x94\xaf@\x9eHh\xd3\xfdZG\xeb;\xc4\xc6n\xbeh8\t\xb0\x08\'\xec\xee\x9c\x86y\x97\xc8Bc\xf6\xb7@\xf6S9\xbc\r\xda\x93\x9b\x19\xf8\xb1\x1b\xab}\x08\x9aR\xba\x8fZ\xf9\x99\xf9\xbe&T\xcc?0\xb6\xcb\xe7\x7f5\xc3\x8b+\xc6G\x1c\xba\x1c4\xb6e\x14U\xb5C\xbc\xdb\x98\xa2\xdc\xa1\xc1\x17\x12\x0e\x9f\xf9\x06\x94$+Wfu)PeL(o\x00W\xe5 \xdbON$8\xa5\xd2(\xaf\xe8\xa10\xd3Dy\xe2\xef\x94i\x92T3JCB\xb6\xe2\x0f\x13\x882\xe3go\x07\xd2\x87ukt0\xe1\x1e\x87\xdfGt\x9e\x1a\xce\xb5wt\xdeFW\x04\xb8a\xf2\x8e\xb3\xc6\x97\x9f\xe5\x81\xbb\xe3\xb8\xa1u\xfe\xd6\xce_\x0fu\xe6\xda\xae<\x9e\xeb\xed\x88\x05\xb8\x12\xear:\xeb\x9eD\x80\xcfu\x83\x04nqT~\xe9\x88\x9a\xfb]\x08F\xdf\x18\xfc\x0c-\xe2y D\x19\xc3cf\xab\xc2\xc4j\xf4\xf9@\x1a\x97s\xa3Wu\x0e\xaf1\xba\xa5\xa7\xbc\xce\xee\xd8h\x81\x89\xfe\xf5\xd8\xca\'\x0e\x97\xe8A\xf1\x08\x03\x8c\xf0LD\xdfD\xe8K\xc0\x03\xde\xa9\xa4\xaa\xd6\xf82\x12`\xae\nH\xf6\x1a\xed\xe3C\x944\x9e\x89\xea\xeai\xf94\xdaXV\xf6T\x14\x0f\xe3\xf8b@\xaa\xe6J\x8a\xc6q\\\x9c\xf6;\x06\x9c\x06\x0fF\xa9l\x95Y\xf6\x07Nx\x1a*\xb1v1\xfc\xb52\xc3-\xf1\x8c\x11:\\\x13\xb1\xf9\xb7{\xb1J\x9e!LE\x82W\x88\\\xbc\xb1C\xe1\x9cL\xcfcxe\xcdB\x03\x81Q\x88\xf1fz\n\x9bE\xf1\xe0V*\xe2\xcea5C]M\xb0M\xc1\xfb8\x04x\x84\xc6\xc0\xe8\x10d\xdb\xda\xf0A\xd4ux.\xe1\xc3\x1e\xc4[\x1c\xe5\xa3\x1eL|O!z\xb9\xc9\xdak\xf9U\x8eO\x1e\xe0\xc6W\x00\xca \xcf\xc9\xfe\xdb\xda\x1d\x06\x88\xc2\xd2\x9fE>Z\xe2\xa4\xd0;pf\x8f\xc6sg\x12r\xc0)\t\xb1\xfa\xd6\x16G\xca\x8d\x06\x05/\x81\xddGr\x0e\xbf\xaa3!\xa3Q &\xa4\x02\xd1v\x9e\xc7AV\xda\x89q\x18\xc2f\x0e\xf3T\x93\xd5\x80\x06\xc7\x92D\x05\xd3\x8f\x1e\x9cL\x9a\xc0j\x1a)$\x0c\xbdG\xd6\xacC\xc6U\x1d\x9c\x17\x92\xd8\xbf\xa8x9\x8d\x18\x9at\x94\x86}\xd1Q\xc7W\x9b\x1eB;\xc0\xd3\x80\x8c\r\xed\x19\xdb\xae\xfc\xec\x02\x86\x9f(\x96?LpL\xfe\x05\xa7\x0f\xb4\xeaJ\x9d\x7f82g\x19\xa9\x9b3\xcc\x05\xccv0@\x08f\xd4:Vg\xf3\x16\xbd\x0c4\x8b\xff\x80\xb8\xc5\xbe\xca1{8 Q\x92\x8ef\x0e\x9f\xe1\xfb\x81v\xc5\x1ct\xa6o\xf4a\x9f\xd7\x95\xba\xb1x\xfd\xf7\x865\xcc\xa0?9\xb7\x15\x01\xd2$\xb9\xa2&\t#t\x01j:g1\x980\x18&\xd0\x01\xdfKlv\xdd\x04u\x00\x9b\x01\\\x11\xf9\xef,~\x928(-\x08F\xc7i\xe5$3\x9a\xd1\xb7\xd3\xf7kb \x8f\x05)\xfd\x11c\xfc$s\n\x7f~\xe9\xc9\x89\x13N\xcdKv\xee;\xeaH%1K\x15TJ\xb9\xd4\xfa\xae[8\x03L\xe3\x06\x8b\xb9\xde\x9bY\x81i,\x11\xf59mr\x1d\xbb\xdf\x87]N\x12Ap\xb2\x9a\x17\xff]*\x02\xc3\xfe\x8d\x97\x19\xf6\xf8pw \xdak\xcduB\xf6Ou\x00\x1a\x84\x1fZ5~{V\xc6\xa5h\x1bd\x16\x0b{\x0bG\xbbl\xf9\'3\x16?\x05E\x8bu\xb9\x1c\xbc\xdc\xa2/\xf6aX\xb0"Ns|W\x98\x96T\x13\xd3\xca\xd3\xbc \xaa\x06\x08\xb7\xd3\xe2\xa8<\x99\xa6S7C\xfc\xfa<d\x15\xce\x00\xc2\xdb\x9b\xbc\xacUXv\xab\xb2\x8e\x0c\xe8\xa06\xef \xa8T\xbb8\xb1\x13\x8a\xe7ts\xabG\r"H\x156\xd44\xf7x}l\xd1\':\xe0x\xb5\xe2m\x87\x1f\x8a\xec\xca/\x00\xd0\xda\x8b\xcc8F\xba\xad\xa6\xaa\x88\x8b\x14\xde\xef\x89\x94\xff\xd8\xe3\xc9\x19\x99\xfbD\xc5+wg\x004\x00\xbd\xf1\x07\x99y=\x8ax\xe7\xe9U\xd7\xf7\x84\xec#\xd1\x1e\x04\xd1[\x02H\\\xfcbv\x99 9$W~\xdd\x87\x986h*\ne\x8b\xa3\xe21F\x01\xa0*\x92\nw\x87\xc8QnPV\xc7\x9f\x02O#\x01N@\xc8:\xb0\x98=\x9eZ\xf3t0\xb6\xb5\x0f\xa2q\xcf\x98O\xf2*V\x1cI&\x9f\xa5\xc3\x9b\x7f\xa5l\x04\x1b*\x81~C66\x9bn\xec4\xef\xdd\xedJ\x1c\xd7E*\x19\xc8bb\x98\x0c(\x0c\xaa\xc7\x93\xca\xac\x95|\xab`\xde\xf1?\xd0m\xe5\x13\xabPb\xbdXU\x8c#\xebT\xdfc){\xd2(\x95\xfd\x8c\xf0\x17\xde&f\xdd\xball\xfe*\x01\x91\x95\xbd5\x81\xd5\x82\xab\xab\xa0\x1bF\x9b\xf7<\xdc\x92h\xa7c\x10c\x88jV\xc81\xf2\xc9\n_\x8e\xfb\x8b\xa5\xc8\xcf\xbe?\xd15\x0e?\xdf;\x1en\x17\x03\x03\x00\x1a\xe3\xd6x\xd0eD\x0b(\x06\xa4\xf525\x15\x02\xef5Z/=\xab\xaaK\x8ao)\x17\x03\x03@\x11\x07\x18\xd82\xca\xf7%\xbb`\xd2\x19\xe2p\x98d<\xef\x00\x05\xf2\xe3\x8b\x850?\x84<\xaa{\x12\x9c\x18\x18\xc2\xb3\x00\x8a\xb9\xf9\'\xcb\xe7\xa5\xda3\x99IlI8\xf1\x80s\xc8\x15\x9eG\xcf\xc3^\xa6\x95/\x9ep\xf4\n\xfcU\xa3T7{-\xb5\'y;\x00\x80\xb3\xcd\'Nx\xd9\xd9,\t\xf1\x14\x066\x9a\xc2\x1a\xc7\xd24\x03\x1f\x9a-\xb8r\xf6:\n\x19J{\xc1\xb8\x7fJ\x97\'6\xae4SN\xe3\x88\x1b;(q\x1bO\xd7}=-\xbe\x9b\xcd\x10d\xcf\x955\x0f\x13b`\xfb\xc1\xd6\x1d_\xa6\xc4\xf0u4Z4\x91\x99erkIq[\x18`\xc2\xd3UGd\x81\xa9|-t\x9d\xfeMm|F\xf2\x82S}\xe0Fb\xfa\xd9\xa2\x8c\x1a\x9d\xb0\xa74?\xcb\x93\xbe\x8b\xe1\x07`p\xd3\x9c\xde \x8bo\x0e\xf8\xb2\xa0.:|\xcdu\x8f\x01\xa6$F\x9e\xaa\x05\xc2\x06{\x90\x92\x8e\xf1\xcd{Q\xb3g\xd4m\xe5\xb6-\xf7\xe3\xda\xa0\xbb\x89 A\xce\xfbpYW\xe1\x9a\xad\xafzk\xaf\xbdi\x84\xd5\xef\x04Y\xee\x17\xf5\x8d\xd5\xab/\n\xb4\xc6\xc9\xd6\x05\t\x10\x87"2gi\x00\xca\x1c<\xdd\xad\x12 \n\x97\xe1\xdc\x84\xb7\x90\x81\x11\x06\x12\x11\\F\x8d\x1b\x8c\r\xa9\xb7~\x80\x9cT\x92A\xe7\xffg^L\x95\xeb\x8c\xe8\xac9lU\x169h&?\xe9}#!\x18o\xb1X=S>Q\xb1\x7f\xf0r\xedM\x9b\x81\x92Pv=#\xa9\xf9+n4I"-7E7*\xc1$r\xbe\xf78qb\xcd\xae\xceu\xc3\x87\xafv\x1f\xe9.\xba\xd1\xd3\'W\xfa>(%\xb3\xbc\xb1\x14\x93\\G,\x9b\xc6\xa9\x8f\xa0\xce\xc9\xe7\x0b\xd1\xa6|\xfdjS*eg\xe2\x81\xa3\xe8\xe7[\x19\xccK\x80\x8fR+\xc79ZX\xcaK\xca=\xce\xb5\xeb 0F<\xb3(\xb6\xe6\x13e\xc8\x84\xdd\x92E\xd9\xaf\x8e]\xc7\\/f\x18\x92\xaa0V\xc8\xe1\xcaPH:\xf3q\xcd\xf4\xcd\xe0\xad\xe9!$\xba+\x9d\xfap\x8fX8\xf4\xe12\xe0\xd8\xde\xd7\xdc\xe2\x19z2\x7f\x8f\xf5\xaa{q\xc1\x17\xbeV\xa0M#+\x1c|J\x16\xa1\xdeK\xb4)\x14P\xfa\xffy\xe6OW|a\xaa\x9aqw;L\x8e\xe3\x15e\xbf?\xf9a\xbd\x95L4\x93\xbd\xcb\xbaAZ\xd7\x13\xe2*\xa7\xe5\x9b\x13M\xb2\xd0=\xd0X\xd1T\xf3v\x9a\x8b\xa1\xd8\xed\x0e9oe\xc3(\xa2\x04#\x84\x8d\xac>\xff|\x13\x88\xe0\x13\xb9\x95\x87\xd9N\xa2\xf2\xa5\x81\xffI=\xecG2\x8cIFHh\xeb\xa7D\xfe\x08\xe5\xa8\xef\xc0\x95I`\xe1ws\x95\xa9\xe0\x91\xe1\xd1\xd2n-\\\x0b\x87\x94\xf5\xcf\xe4\xf6m\x00+\r\x7f?1~+`\x13\x911\x9c\x12\xf1!\xf4\x19\xbe\xbc\xed2\xf4w\'R&\xbf\xccG\x81\xe0\xdc\xaeG\xbd\x88\x03\xc7+\xc6\xd3\x05\xb1\xf8}\x91F\xd0\xc2\xb0\xa0\xa5\xd1\xd2\xd9\xcf).\xe7.Vy\xf5[\xbf\xcfDeH):\x95n\xc9\x7f(H\x88k\xa2\xe1Mh+\x16\xf5\x8c\xd6\xef\x83\x0e6\x08\xdb\xf53\xe3}\x19\x00"\xb9\xbe\xa8\xef\x02{\xf2\x8eN\xf8\xd1\xe3\xeb\xdd\x8e\x8f\xd1\x93\\\x16&F\xe5\xa8\t\xcd\x07\xade\x97_\xdc-<@F\x96\xd3<\x06\xc6\x1c\xdbyC2\x96}\xa5\xd9\\\xcb\xd1\x0b\xf1~\x8b\xe5\xf5\x1b\x13\xc4r6\x8c(\xe6\x17B\xcf\xe6\nI\xcaf\x8a\xca\xd3\x88\x80!\xab\xe4\xcb\xf1\xf8\xbd(\x18)6\xfeJ\x92\xbdq\xf8\x01\xf1\xb2Yd8\x81\x8b\xa9\x15\x97d\x87\x86\xc3\x99\x1d\\\x89d\xeby\xec\x18u@\x1f\x0c\xc3e;\xd6:\xcb\xc7\xfe\xf7\x80\x12S\xec\xde\xdc\x15\xac\xa7{-\xc7\xd7\xafe\x1eX\xaf\xe9i\xd9\x97j\xceXP\xd2\xb8\xdc\xe6K\x84`\xfc\xe1\xee~1:\xdbx\x04\x0b\x06\x838J\x10*\xbb\xaa\xd4\xc2\xc7\xcc\xaeH\xa8\xd4\xcbH$P\x85\x1a\xeb\x98\x1a"\x17\xaa\xc6.\x8d\tj\x99\x12\x10\xfak\xb7&x\xc3lsW\xcf\xc2;Q\xad\xee\x08\x7f8\x97\xdc|\xc0ey3\xb6*\xb4%@7 \xddi\xa3\x9e\xc2\xce;Qa\x00\x96\xb0\xfby\x8e`\x1a\x93\x88\xa4Z\x00\xcf\x8ez{\xf4t\xeb\x86$7\x8c\xba\x9e#\xed\xb0\x8a)c\xa2\xa4G6D\x1e\x83\x91,\x11l0}\xaf\xbcuv\x1b\xcf\xb9\xb3\x01\x8d\xa9[\xb6\xd4\n*U[~\x04\xc7`\xb0\x8b\xd7\xb7\x9a\x9b\x88\xc0m\x05\x1b\\\xd5\xd4\\\x1b\xab\xe50}4\xd4\x0b+\x952\xc2\x1f\xa9\xf7\x1d\xee\xb1\xf4\xb4\x99\x06\xc70\x17"\xd7Vd]T\x81\xde9u\xbe\x80\xf9V\xb64\xccj\xe5\xcd\x7f>\xbf\xb3\x82/\xad\xd7 S\xech\x99\'\xfe\xfe\x9cnU/l\xca\xf2\x06\x06\xd9O\xf9\x19H\xe0\xe1\xc3\x16\xc2\x12\xaex"\xe5n\xab\xe6lp\xd0\x1c\xd5\xfa/\x1bO\xf8\x96\xf2?\x14\x96%\xa9!P\xbb)\xeeKln\x80\x9a+\xfe\xea;\xd9v\xadl\xa6\xa6S\x12]\xf2Q\xbb\x06\xc2\xb9\xc7I\xdf\xa7\x1fL\xfbi\xd4N\xbf\x81~\x8dwim3i\xd7\xc6\x96\xc4\xe7 p\xf7\xdf\x04\xb0\x80GgdI8#\xeafK*\xaet:|~3iR\xeb:2\r%\xae\xd0t\x17\xb2\x80\xd9\xb8\x7f\xbd\x91\xd2\xf4c\x8f\xc36\x96\xac\xae s,Xj\x16)^\xe3\xf7\xcc\xd2\xd7gM\xeb\xad\x1cT\x94\xe3\x13\xd4\x01\xb4\x11|\x91\x98\x1d{\x8a\xe1\x04@\x7f\x90p\xbb\xb7sO/\x07\xb7OGa\xd0\xaa\xbf\xf22\xdf\xcd\x85\x7f\xb0<,\xccF\x83r6)\x0b\xaa\xa7\xf0\xf4\x1eB\xeb\xcb\xd6G\xbc\x016m\xb1\xd0\xf4o\x0f\x83\x1e\x97>\xcb\xbcFr|I\x16<\xf3\x1d\xfe\x11\xa8\x1a\x8e=\xb2\xb71\x89\xea\x87\xcd\xb5\x9dNb\x97\x83\xd1\xbc\x9e\xc6dlQ\x89,NV\x06\x88\xfb\xe9\x97\xcd\x13\x10\x84\xfa\x0ej\xcb\xe4\xe0\xd3\x99@\x12|N\x18c5\x156U\x8d\x8etY3\xa98*7a\x81\xe1DH/\x03\xb7\x11\xd4\xe5\x81\x01F-\x9b\xd53\xde\xc6\xaf\xcf\x14\xd1\x9c\x1e\xb5Q\x11D\xc1\xd8\xf6\xefH$\x1a\xca\x85\xb4p\xfa\x14Uh\xc7\xb5>\xfd\x91{\xb2\xff\xd2\x0b\x8f\x80\xe2*\x17\xb5"\xb9\xc5WO\xd80j\x13\xb9sz\x90\xde\x98~\x14\xe4\xdf\xd1\xb3\xe1#Q\xa4\xcdb\x8f\xb2\x89?Y\xd7\xd4\xfc\x8a4Ul\x95\xffsU\x0b\xf4z{\xe6;\xd2h\xa2\xb4S\xa3\x88\xb5i\xf3\x91\xdb\xe1\x1d-`\x16\x88\x95\x90\x8a\xe1\xc3Y\x11\xaavK\xd5{\x9bi\x84\x8fn\xb0\xc8\xfe\x89\xf6\xfd\xad\xd7\xc3\x845U\xde\x0c\x1b\xd7\xfe\x89\xcd\xb0\x8fc\xbev3\x1e\x87\x0c\x1e\x10\xe9\'\\\x15\xad\x89\xd3u\xb1u\xa3\x80\r\xf2\xde\x0c\x99\xce\xd5,\xaa\xe0_\xb5\x174:Q\xdb\xda\xbd8\x91\x03\x97\x13g\xe87\x96\xb82\x85\xcdQ\x00\xfa\x8a\xa4\xc3\xcc^\xf6f\xf1\x11\xb3V\x93\x01\x14\xd97\xcf\xe8\x84,\xfbj\xd3T\xc7Y\x11\x1f\xb4\xcd,dpE\xf4\xae\x99X\xcd\x8eh\xda\x966\x8e\xfb\xe0\xf71\xf2\x02N4\x91j\xd7g\xd7\xff\xd4\xc4_W&\xd8\xf9\x94?x\x16\xdbr\xeb\xdc}F\xc0\x85\xadk*t?q\x8a\xe1N\xc3\xc4j\x84\xa4\x8e\xe6\x97\r\x85J\xdb\xf7\xc5\t\xfeDH\x9ah\x8b]\x99\r\xff*^\xa3\x8e\xcd\x85\xe8\xfb\x07Y\x82\xe7\xb3\xe1\xcc;\x8f&8\x881\n\xd7<\xb9/}u\x1a\x1a\xf9\xb8\xe9p;HY)X\xa0\xaa\xb2\xb8v\x1a\x03\x8a`\xba\xccV\xe64\xa9\xc9on\xb5\x83H\xc86\xdf\xa5\xd9\xd69\x82\xd1\xb3\xb0\x9d\xb0Kx\xb3\x83go\xee\xaf\xf5k\xce\xee\xf4\x91\x7f\xfat\xc0\xdc\xaf\xa9C\x03\xac\xa7\x85\xfb\xf1\xe9\xb6\xe4\xeb\x14\x97@\x8c\xdeEgP\xbdb!u\xd9<\xd0\x9dL\x87\xc7\x92oU=\xbf\xb5\t\xbcm\xf76\xdab\xc4\xda\xc3,\x92\xd0\xb5LV\xf2\xe2\xf0\x89z\xf5\xd1\xdcg\xee\xef\x84\xfa\xaeS\xe0\xc8\x90\x1c0\x15\x9fp\xe7\xab\xc2\xd0"\xad\xe1\xab\xa6\xb62\xd6\xb1w\x91c\xd7\xb9\xd1=z,\x15sv \x8b*\xa5\x9bx#G^P\xde:\xb4\x8eiF\xc9`\t\x17\\\x00\xe6\xc4\x8a\x7fg\x18\xc3\x80\xcc\x84\xf4\xafl\xa8\xf92)\x9b\xbe\x7f\x08>\xd3c\xc1M\xc3\xea_\xd1\xfd\xa8Cj\x04\x98j_QS\\97S\xcdMe\xd6\t\xfa\xc1\xa4\xa7\x81\xdb\xf6\xb2\xfb\xd4\xff\x1c\x87D\x84\r\\\x95x\xb6\x00\xb4\xeb\xa7\xd9y\xc2(\xee\x0bd\x95+\xf9%"#`$#\xe5X\x83\x17\x12BW\xd4\xd3\x8a\xbb~r\xa3\xa9\xb2\xd9\xa3\xb5$w\xf6V~Z\x82\xde6B~^1U\xa1\xda\xf0N\x1a\xd5\xc5z\xb5L<\x81\n\x98(\xe9\x02\xe3|0\x1c\xe4\x13d\x84\x0c\xd2,\x1e\xe1\x9d\xcdvP\xc2Zq\x0c;\xbb{3\xa0\xe3<\xa7\x9dS\xf4\x97\xddvf\t\x9b\xa3|\xec\xa1\xc6\xc2_\x97{\xc6\xa2\xfb\xb6\xe30\xc3\x10\x99^\xe7,\xba\x9c\x03s\t\xf9P(\xeegn\xf45\xbfz\xa41i/x\xe4\n\xdf>\xcd\x0f\x03\xb2\xdd\x99\xe6\x87\xfa\xc9\xe3\xfa\xc4\x0bZm\xf4\xca\xad/sO\xfa.B\x8f!\xb6g\xfcAz\xb5q\xf9A~au\x8b\xd0\xeaI\x1d\xd6\x8a\xf4\xd0\xad\x9c-\xe6n\x96\x99\x19Y\x80g\x1fyg\x08\x0fEd\rL\x8dv\xf1\xecY\xc8\x08\xf7\x8450\t\xe0\xad\xb6\r@p\xb5\xb2\xee\xd7Si_\\\x97<\xd6\xa1\xed\x0b\x9a\xbf\xed\xc3\xc6E\xb3\xc3&\x8eR^\n\x9c\xa3qY\xc4\xb6AWWiY%\xeb[Y3;p\xfdg\xe5\xb7[\x9d*\x85a\xe0\x8d\x1a!m\xe4\x8a\x99h\xcf2\x013aW\x81\xac\xa5\xbb\xca\t\xc8D\x1a\x82\xf6\x94Ub{-\x0eE\x99\xc4\xfe] \xfeK\xd2\xba\'~\xe0\x06N\xe5\xe8;}\xbf\x88\xe2\x91}53\xdd6(?\xff\xd9\x14\x94\x11\x03/\x0f\x94\xa0|Ud\xe8\x8e\xde\x1bq\x80In[k\xb0\xd5\xa6{\xfb\xb0\xb6\x17\xf6y~\x02;\x15b\x1e\xc2*+\x8bh\xef\'\'\xf1M_\x94-\xac\xe4\xe7\x00o\xfa\xb3\xc9\xa2\xd4\xe9}?*\x8acw\xc4\xa5t\xd8\xfe\\]\xc5\x1d\xd5\xda\x07\x95\x9b\xcb1\xbb\x00\xd1\x13bm\x17`\xd9\xec\xb1bf\xb2\x95\xdc\xa6\xbe\xb8:\xd3\xe7\x13\x96I2\xc2\xb3\x88\x92\xb6=\x81?\xb8B\x03,>\x84l=\xde\xe9\xbe.\xe5\xeaj\x94\xbc\xef\x85j\x86\xdf\xce\x818B\x82/^\xe2X\xbb\x92\x0b\x85\x07e\xcfy\xa1\xa1gB-\x139GW\xfaG3\xac3\xcc\xdd\xa2\xe6mj\x9f\xb6x\xa2\xa7T\xe5C\xde^\xd3\x80\x89\xcb\xffRX=\xfc\xd0y\x04G%1@f0G6\xac^\x1f\xb3/\xd2O\x05V_\x94"\xc3#\x98\x0f\xb3u\xce0\x11\xc9l\xd8\x8c\xc3\xb2\xcc\xec\xd8\t\x8aME\xc6\xa2\xcf\xf5~\xeaH\xef\xbfC_\xf3\x16\x8bA\x04A\xa2|\xc2\xb8\xa5\xaf\x98R@\xb7\xf7g\x82d\xb6\x0c\x9b\xdc\x933v\xd5\xd1\x02i\x97b\xafU\x07\x01s\xa4\x1e\x1f\xc2\x8a\xa3eb\xe4\x9a\xa8\xdd\x93U\x9d\xb8I\xb2H:\x03\xbc\xc6\x93\xbf\xb5\xc4\xc66\xc7\xed\x8a\xd7\xb9Y\x1e)\x07\xdb\x085\xf9\x18\xb7F\xfb\x89\x91[\x8e\x80|+\xe2~{\xdc \x86\x967K\xaa\x14\xe6aS\x85\xf7?3\xf9\xe0\xbc\x18\xce\xbbI\xaei:\x87Y\xe0/\x9d\xf0\xd0\xbd\xfa37$\xb2\x14\xebw\x98\xc9\xea\xbd\x9c@\xa38N\xfa4\xcaF";w\x9e\xcc\xd3\xec\x01\xb6\xad\xc9\xb1\xd0\x1fE2\xcb\xe3\xc0\xc9\xa5\xff\x81d\x84s\xaf\xe9\xe6\xb0\xc8\xe4\x9d\xf5,\x98\xc2\x9d_\x02\x9b\xe2]\xfe\xa2X\xc6\xd9\xd9\x9fm\x86_\x12\xdf\x12%\xfc4V\xa0,-\nNG\xbd\x82\xe7\xc6\xb5\x81.\x9al\xa4\x81\xffg\x9a_\xfb\xb5TR\x055\x10\xd3\x1e%\x0f\x97\xc0\xf2\x8e\xa0u\x0f\x1b\xa8x\x04$\x8a\xfb\xe2\xcb\x98\x9b\xbaV\xa5/\x01\xb2<@\x90\x03J\x8c\x129\x11\xcbnJ-\x9b\xb2\x96\x06\x82M\xabd\xf7Pu\x926\x1e\x9a\x0f5\xce\xe2\xd7\x1e\x1c.\x90\x0c\xa0\xad\x95[VG\xee-GT\x90{\xf0p(\x0e\xb3\xdb\x9f\xe5\xc1n \x0b\x0b\x95\xfd\x19$5\xc85g\x84\xf9k\xfa\x1f\x80\x85\x87\x84\x02\xb8\r~y\xff\x89tL"\xc9\xce\xe5\x88\xac\x96T\x8d6\xc2\x821\xefF\xfb\xe2\xb1\xb8\xb9\xf7*|w\x0b\\\x95\xa7\xc2\xa2\xdfnV\xd4\\\xc6\xc9\xe9G\xc9\x99\xcd"8\xeaF\xcdPy^e\x05\x13\x98$\x81\t\x8eJ#,\x11\xd0\xb9\x9c\xc7\xea\xfb\xfd\xd2\xbdk\xf8fI\xed\x07\xf0\xbf\x9f\xaf\xf8\x008\xf5eE\xd4\xbe\xfcP\xda\x91W\xe5\xc9\xfa\xd8$Pa~\x7feH\x89)8I\xff\x00\x9e\xbd\x97\x87\xde\x9fy\xa1n\xca\xa0>\x84\xac\x00\x98\xd9\xf5\xad\xc5\x86\xf6\xa87\xa2\xc9\xb7ur\xef\xca\x83}\xd9\xdd=j4\xa6\x17*\xabR\x82!\x06\xfb\xb0\xdc\x1e\xcd\x82\x16\xd7\xa9\r&\x07i!\xff\x1a\xf8\xf5`\x96\xc5v&\xbb\x1d\xdf\xed\x03\xf81dJ\xa3]\x84b\xff\xee\xc5\x0c\xfa\x8f\x93\xf3\x10\x95)\xd8\xf93\n\x04uF\xf7E\xcc\xdb\xb9(m\xdd"zZ|a(\xab\x97W\xfcq7\xa3\xe3n4\r\x18C!\xe1\xfb\xe2\x1b\xc6d@\x19\x0f\xbf\x0c{:\xf6\xbd\xcd\xc0\x1d"[z4\xc4vKf\x86\x9a\x0f\xbf\x82&^\x1e\xbe_\x8f\xf7\xfb\xff\xbe\xf5N\x0b\xde\\\xff\xcd\x850\xad\xe8\xb5,\xa7\x96RP\xb1a\x7f\xa3\x1dH\x90_w:)\x88\xf5\xc8\x12\xbf\x17\xf1\x0f\x9b)1:\x17Is{9\xf9C\x8bu\'\x1e\xa9\xd4\xf9\x9a\xaf\x99\xd5\t\xd7\xb3B3\x89Q\x0e%\xd7\xb8\xbdsU\xe7\xd2\xae\xb3\x1bJ\x16,\xf2ea\xd1\xc1\xe9\xeb\x8f\n\x91\x06\xb7z\x01\xebY!\xde\xcfZ\xa1\xc9*\xce/\x1eIV\x14s\xa9v\xe2\xec\x90u\xd7\x82\x9e1\x83\xcbe6(\x98\xcc\x95\xc3XjY\xc4\xe3z\xa9\xf8\xcb\x05\xb5\n\x91\xd5\xd0\xe8S\xd2\xd65\x94\xdaJ~\xe3\x1c?\xf1\x83\xf1\xfc\xae\xc3\x05\xaf,\xb9\xdc\xaf\xfd\x96~\x05|O;\xafC.\xb5\x0e\xab\x82\xfd7t:\x84\x9ex0\x94(\xf7\xf8\xa2F\xd6\x93"\xa7GA\xb5G\xf6\xa1)n\x99\x82\xde\\\xb9=\x90FI\xd1@n\xabv\xb8\xa0\x8b\xf8\xb6\xc6\xe5hob\xb7p^\xc1\xf7`1\xdb;X\xbf\x08\x97u\x1d\x174\x96\xf6\x10\x02\\\x0b\x89+M\x8e/\\\xca*\xf5T\x03\x85\xc3\xf0O\xcedz)S\x0b\x83\xa2\x0f*\x90\xe7\xa8\x83;\xb0\xe7SNrEH\xc5\xcd\x06\xa5\xda\xe3+0c\x14\x9d\xa7c(\xdc\xa4\xe8\xa8\x9d\xfa\'5\xc0n\x9f\tB\xe5\xb7n\xd7\xf4\x8f\x86\x0e\xe3\x94Dc\xcc\x13\x81~\xc6\x19\xfe\xda\xb7\xacx\xd7\xa75O\xfcc\xc8\xd5U<\xe7\x0c*l\xf0}\xff2;\xd5CzF\xe2\r\xec~\xf3k:9\x7f>\x8eK\xe4e}\xb3\xa8\x910(\xbeO\xa6jlHw\xac\x91\x1e\xf2Y\xad\x1e\xb2H([$}\x87P\xbb\xd2\xcd^\xc1\x95\xda{B\xb4E\x17+\xad\x97J\x94\x99&.\xcf3\xfe)\xc1BU\xe9\xeci\x95\xeeU\x84\xf4M\n \xc8\r *\x8bs\x00\x9d\xe6\xf1#z~\xaa9Q\xfe\x89g\xc7"\x9b\xc0\xcb\xfe7\xab}0\xbbV\x8d\x87o,\x18\xe2+\x14-x\xa4\xe6\x04r8\x0f\xcf=\x9e\xe1\xaa\xf5\x91\x8e\xc8\x98\xbd\xa9\xc5H\x13\x0eye[H\xbb\x8bn\xafl\xe8\xf5\x86\x9d\x1fO\x86\xcbh,U\xb3\xdcj\x1av\xddR\xcc\xf2\xc5\x01\xe3\x00\xab*h\xcbd\x8dW \x9dT\xd5\xf4\xd0I\x8e\xf0E\xbe\xf4C\x86\xfc\x88%\x9a\x1b\xf1\xa7G\xae\xf7r\xda5\x95n\xdf_\xba\xff\xd0\xdbw&\x1f\x10\xbb!\xdc\x1e_~\xb9<\xd9D\x0b\xc24%B\'\xd5\x10\x1f\xed+\xa0Cr%V=\xa8\x1f\xf7\xf9\xc2\xde\xa4{\xa16\x8b\x8b\xbes\xad\x90\x1f\x03\xb0Q\xfcW\x98/C\x1a\xf1J\xd9\xed\xbd\x14\xbc\x92L:\xa2\xe2\xe3\x9d\xecf\xceO\xd4\xac!\x9cfh\xc3y\x94\xb1\x82\xdb\xf8\xfa\x82\xbf\xda\xa6D\xa6\xb5\x85\x1a\xc9\xe0#\xd4\xf9z\x1d\x08=\x14\x03Y3\x94\xc9\\\xcb=\xe4Y\x83\x1e\xcc\xdf=\xcc\x1cG5\xed0\xf1uk\x87\x86\x99#b\xdc\xf2\xf3\xb3<G\xf5\xf1\xe2\xffe13\xb7$\x97\x8cK\xbd\xfcl\x0b+\t@\x04\xab\x9fp\x9b/\xbb0\x1b\xee\\6\x085\xaas!\x13{Rj\x8fp\xf8e\xb8\xe1]y\xfc;jU\x01\x1aj\xde\xeaz\'K\xd4\xa5\x93\xc04\xdfA\xed\x0e\x9f\xa1cu)\xc8\xf3\xab\x08!\xe7\xc9\x9aL!\xa1^\xfa\xc5\x92\xd3\xb5sp\xcd\xa5B\x91!i\xe5\xe4\xb7y\xc5\x8d\xe1\x97\x1aT8\x91\x1c\xb4\xd3a\xb5R\x07\x85\xdc1\t\x9c\x0e\x06gr\xef\x89x1\x0cT\xc8\x8b\xa9\xf9\xca\xb2\xc8\x10\xca(Y.\x91\x12<\xa3D1\xf5\xed@\xc9\x18\xfc\xc9\x13"\xfbQ\xb1=XoD"\x0e8I\xe9W\xfa\xae\xb99:l\xbd:jx\xc3\xb4\xb56\xf5C\x99\xa9(\x10$y\x00\x8b\xfe\x0c\x18\x85\x17z)\xdd\x13!0Y\xb2\x06\xc2\x89\\yu7\xe4,\x10.gJ\xcc\xe1\x9d\x15\x04\x0f\xff\x01\xe1n\x18\xec\x9e\x81\xf4\x14\xde}\xe1\x19\x95\xc8\xd7\x90\x9f\xa0\x1f\xe5e\xbcT\x1fuV\x9b\x04u\xfa\nH\xe1\xcf\x06b\xee,\xa1\x16\xd2\xf5\x03\x0c\x85\xe2 \xdbx\xc0h\xb0\x9d\x08\x96\x8da\x8eq\x82\xe1d&\xdb`qQL\x9f,\xc7:e\xfb\x07j\xae\x17r)+\n\x9f\xd9i.\xbau\tE\xf0\xf3\x1f\xaa\xd4\xec\xc69\x06\xb9_\xdav\xcdK\xa6\x0f\x12\x828(\xabbs\x0c\xd8P\x9cI\xd24\xf7Cx\xae\xa6vy\x7f\xdf\x9a\xdfX\x0f\x14Kv\xf2\xe8N\x10\x1c\x84\xceLx)P\x0bT\xbb\xa6\x03\x96H\xc8i,u^8\x8a\xd89#Q%\x03\xd8\x93\x8e\x9dz,3\x14\xa6\x7f\x1b|0\x08Sf\xc7!\x88\xc7\x07\xbe)\xb5\x174\x02\xbc\xee\x95\xcd9\x9e=\xc7\x18\x81\x1cZ\xc0\x86h\xc9&\xef\xbf>yv5\xeecB9\x19]\x17\xcd\xadq\x9b\t\xaa\x1a\x88f\xa4\x82\xc6\xf9\x0c\x11\x105\x8chz\xc9\x12$\xe2\xce\xbddS\xfa\xda(=\x11\xf6YHT`\xf1\xa7\xeb\xd8\xb9\xbfZ\xb1_\xc1\x8e\xec\xc0S\x06\xed\x16 \xfdv\x9c\xbey\xca=[\xa8\xf4\n\xa7\n\xce\x1f\xe5\xec\xf8\xcfS\x89o\xce\x89\x84\xae\x04M\x8c\xf1\xeduj\x82\x1d)G\xf0!g\xd2;\xdd\x0c\xff\x04\x1b\x02\x0b\xdd\xf3\xc6\xd0\x1ca\xd7\x19\xb4:L\xe4\xd1\xcd\xd5G\xdab\xd1\x9a\x00\x9a\xec\xa0\xd0\xa6\xd3\xc4\x145G\xf5\xc0\xcf\xfa\xce\x0e\xe5\xd3L\xd6\x07D9QkI\x92\x08\x1b\x1f2u\x806)(\'\xeeh\n\x89\x88\x81J\x08\x11\xb3\xb6\xb1\x0f&\xb9\x15c\xb5\x07\xefW8\xea\xecA\x82\x91c9\x03\x92\xb1\xd8\x18\xa3\xe3\xcd\x0e\xde\xc7\xa8\xd3\xd75\xf7$\x95[\x9d]\xb8\x84\x82\xe3\xb8\x9d\xdb7\xb4Gu`\x1c\xec\xd0\x16\xda\xce\x9b\xc2\xfa\xf6Y\x08\xcd\xd3c@\x9a\xda\x96H\x05\xc1Q\x1d\xfb\xa0p\xf3\xfd\x07\xd5q\xc5:\x9d$\xb6\x9b7\xef\xc99\xb3\xb9P\x9a]\xde/\xf7\x8dy\x1fc\'\xb5\x92\xa1\x97\x81E\xa1?\xe77>>\x7f\xbfN$Z\xfcBJ\xf1\xa6\xad\xf4\x04t\x9a$\xf6\xef\x0eZk\xe5\xc6\x10+\xa0\xce\x9c\xa99U\xdde]\xf5\x82\xfa\x86\xe9\xc1\x04\'ht\xb6\xd8\x8c\xfd.\xe9\xc9l\xae\xa60m\x84\x98\xbc\x1b\x9b\xc4\xbc\xa4\x91\xa9\x85\xdf\x97^\xcb8\xebBILK\xd7\xa7\xba\xfe\xf3\xc7\x0c\xc9\x02\xf2\x96\xb2TF\x16\xa4.\xa0\xf5X\xfds"EZ\xf8\xbe\xaf\xf4\x11\x81\xf6\xba\xba\xa2\x7f\xca\xa6\x06\xe65\xdc~Q\xadC\x9cu\x04\x7f\xdf\xde\nIc\xce\x80\xe2\xb4\xf8\x80\xcd@Iw)f\x87$\xf0\xc9\xa51\xf9\xcc)\x96\xb4;A\x19\x0e\xaeL\xf9\x8a\xdduj\x86\xf0\xba\xb4\xad\xd36D\xf5C\xe1\xc52H\x8c\x84R\xd8\xb1r6\xf7\xe0\x16\xf6[%\xcd\x97\xcc\xfdZ\xe3_\xfe\x88\x0c\xe5\xb7\x14q\xf3&\xa8\xba,\xe9X\xe2~\xbe\x91\x8c\x93p\xb0\x8a\xd0,\x99\x1fJ\xdd)\x86\xe2}\xb6\xaa6E\x92\xde\xef0\xdb\xf7?\t\x0cy\xbdB\xbd\xa07X\xe0\xce\x8e\x8cR \n\xc5>\x0cCW\xea\xc7\xeb\x17\x1a\xb7\x16`2\x91]\xe4\x9d,\xb3#H\xe7\xd6&\xfd\xf2S\xa0S\x9b\x93\xa8\xbd\xff\x8b\xa3u\xa5h\t\xd9iM\xdb\x1f\xfd\xd8l\x00\xceU\xf8\x16\x10~\xa1\x83\xa9\x8f\x82hS\xdf)dL\xd6\xe5;]\x88{Gcx\xb7\x8198`\xad\xff$\xf6\xec\xe0F3\x0f2aT \x84\x17g!g\xdf\xd1\xb5Y1P\x1a\xaaG \xb4\x8b\x8b\x88\x91Q\x81\xdeW\xcf\x8c\xdb\x97\xce$\xccNI\xbb\xcd\x00\x14\x1d\xac\xfa\xd1Y\x05\xb7J\xbe\x98(\xa2\xce\x8f\xf6\xbf\x94D\xdc\x00.\xac\xe5\x01\xa5\xb3\xc5\x12\x94\xa5\t\x0e1\xec\x12j\x97\xdck\xb1\xf5\x98bW&<\x00y\xf2\xbaZ\x94\xd3?$,\xf53D\xd9\x04t\x9d\xcd\xd5\x90\xcd\x8f\x01\x06 ?(w\xfa\x1c\x0c\xcc+Z\xd4\x05i\x94\xe8\xc7\xe7K/\x86V\xa6\xf1\x88\xea\xd8\x83y\xf2\xd8xH\x87\xd7(\x9bn\xe7\xafR\xa9\xaa}K\x88\xe5\x1eK\xb0J;\xd5\xa2\xbe\xc8]\xe2\xd9}\xc4@WU\x98\xa0/\xbf\xef\xd8\xc3\x04\x99\xc0\x84\x98C\x8bSs\xfcH\xdbD(\x94\xc3g\xe7\xa3\x9e\xb8\x10\\\x89J\xe5\x9a\x02\xe2EXg\xf6\xbeu/\x8a\x1f$\x12-A\xd3^\xc4A\xc7\x8e&I\x8do`SGa\xc3<|\xed\x85\xe6\x04*\xe2.\xb5\xb5\xc8\xa7\xd4\x1c\x95R\xdegu\x8e:\x8e\x1d\xe6\xdc!\xab\x8cv\xbb\xe7\x12P\x03\xe3\xe1-!\xa6!9\x81\xde6\x8a\x14V\x96\x1d\xdd\x0f8\x89~\xe1\xc7\x03<\xde\xce@K\xd4XB\xbc~h\xd0D\xa5\xb40\x1d\x94\xdd\x1d\xc2\xbb\x82k\xf7\xd9U\xd6\t\x83\xe4/\x9a\xbd\xbe\x03\xa3Z\x9c\xf1q\x15`\x1e\xf6\xb1Z\x14 k\xc7\xe4\xf4\xafB\x03)M&\x9c\xa6\xec\xe6*\xbf\x86d"7\x0f%\x96\xc3\xc1\xab]s\x10\x11\x08m\xe2\xbfRfm\xa2f\x80m\x82\x94jP_l\x11\xb7\xd8\x1e\xdc\xf3"l\xfa\x91\x85\x9f\x03\xb8\xd9\xaf\xda\xf0\x03\x95\xd9\xc3\xc5\x89$;\xfbH\xbc{\xb3\x18\x86z`\x91\xf6\x02\xeeP\x87\xc1\x95\xb6j\xe94\xf0`Y\xa6\x07o\'\xdb\x0f\x18\xf9B\x9b"\x9e\xcag`\xfb\xc6+\xd5z\xb8B\x11\x96\x19\x874\x05Y\xa4l7\x0fC\x82Q\xec}a\xf4\xbfh\tejh\xe8h\x87/\xd4\x8f*\xd9OR$\x8a\x94\xa25\xd6c\xbb_\x0e\xa7\xd6\xbf\x84.(\xac\xf1\xe6\xffA5AKIi\x91\xfa\x93\x94\xc5\x90\xeb\xab\xf4\x9b2\x04\x9f\xab\xb3\xfc/\xaf\xd2\xff>q(\xd8B^sFf;\xc0Xb\x9d\x969\x9cCk<\x9e:\x98\xfaKk|\x14e\xdc@\xb0n\xe3\xb9\xd0\x8e)}\x9a\xbf\x90\xafd\xc8v\xd2\xada\xcc\xb5S\xbaS\x8c\xcba6:\x1an9\xfc\x15\x90rJZv[\x7f\xb7\x83pm\xdb\xe5G\xab\xa2w\xd1\xe5xIyu\x95\x92\xa4\xec\xb4wr\xc2%\xc6\x1a\xef0Kj\x05\xa7lHT\x97\xc9G\xb0x\x8f\x96\xdfu3\xf0\xda\xb6G\x86\x1aq\xa9\x15\x98+\xf2\x0f\xe0\x13\xf8\xf2^\xff\xcc\xcb-\xaf\x8b\x12d\xd4,zU\xc6\xa1\x0c\xd0\xdd\x89T\x1d! \xb8|\x00\xd5\x970\x08\x11\x03\tD\xfa#\xb7A4\xc1\xe4"\xe4n\x962j"\xb8\xc4\xc4`\xd5\xe7\xd7\x1c\xe0\xe2\xeb\xc0\x90F\xfet\x88\xba\x9ce\\Z9J\x8c[\x92\x8f\x91r=\xf6\xc8\xb9T\x8b\xf5\xfa\r\xe1\xc4+4\x94J<U\tX\xed-\x89\xc4>g\xa4\x9c\xc2\r\\\xcd?@J\x17\xf1\xb2\x11\xb8\x8bN1\x95\x18\x82\x13x\x990\x08\xbf\xdf\xeek\x02\xc4\x7f\xc5\xa6\n\x9fU\x85}\x94?_\xae\xb0\xfa7\xff\xadE\xcdg&/\x17p<P\x10\x81\x1e\x03o\xcf-\x06a`p\xcf\xa3\'\x9a\xc1\xd1\xd8\xda\xa8\xce\xd4?W"M\x86\xee#Po\x1a\xe6\xd6-\x7f\xe65\xf59\xea\xf2\x9c\xbc\x11?\x17\xccg\xf1\xad V\xc3\xd8|I\xec\xee\x829\x14@:\xcfKu=GP\xf5\x10\xf1\\1\xa4\xc1T\xfd\xc4F\xd9Q\xce\x85!\xf8\x1b7\x04\xfd,C\xcc\x8f|3\x9f\xd4\xf2\x1d\'\x1e \xa25=\xd6I\x13\x06R9\xf3\xd60aN,\x90q\xd65\xe1\xcb"\x11\xe0\x9c\xb7l\'\xbe\xc42\x83\xf4\xb4;\xac\xcb\xd1o\xeae\x03\x8b\xc6\xc9L}\xbf\x9a\xbf>!\xf7c\x940.y\x1diS\x9a9\xc9\xaa\xf2\xacP\x829\xe8\xdec\x05\xff\xf6\xea\r]\xa22\x8a?\x0et/w\xc0Oy<\x1a\xfap1\xd4\xcf\xc6Y\xb1\xe41r\xa4\x8e\x19\x9b\xd8IA\xf2\nM\xb05\xd7N@:\xfep,i\x1c\x9f0\xc6?\xdf`U=?e\xa7\x85\xee\x17P\x18Z\x18\xacwv\xc0\xf6\x14<K\xc3\xb1\xdd>e\x82AL\x80\x1bn>&4\xb1\xc7_uU\xcf\xa8\xe7\x86W\x16\x14\x97\x03\x8f%\xbc\\\x9eF\xf7\xf1\x9a\x105\xb8q\xc7\x7f\xe0\x02\x1e\xc2\x96z\x1a%)\x817\x1d\xffXW\xf9\x07\xf2a\x90\xda\xe1\xbe.\x82/_3-\xfaC\xcc\x8e\xae\xdbw\xc5\x0b\xfc\xe2\x9e2\xf9\x8d(\x1b\x8a\x12\x13O\xcb\x86\x85\x81\xab\x04\xfc\xca^w&v \xcfyn*\x81)\xcc\xb2\x0c\x16W\x04\xc1|x\x91\xbd\x19\x94\xc4\xdb\x02\xd0h\x05\xc5^\xe1\xf1}\xc0\xa48qRC\x13\x88\xb0I\xea\xbe\xdd\xed\xe0I$\xc2M\x1e\xdc\xdb\x13.I\x14\xe7L!J\x87\xe5\xa7\xf2\x9c4;&~\xf7L\xd74\xe0\xcb\xef\x18?\x16`1j\xa7\xd1\xba\xb1\x0e\x80\xd0c\x1d\xf5P\xb2Bd\x0b\x8eXI\xd0w\x8f\x87\xb3\xb4\x9d\x7f\xa5^\xa8\xdc w\xed\xa2\x93*\xcb\xe7S\x94\x81\xad\x7f\xad\xf3\xcb\x98E\x86\x13Ir\xb2\x072SHi\x17?y\x9f,L\xb5\x9a\x9b5c$7\xc7IS.5\x10A\x89Z\x06\xa3\xaaw\x19\xc4\xd0;\xb2#D\x81\x0b*\xb2\xfb\xce\x00\x82h\x10\xef\x12%\xb6\x7f\xba\xd6\xba/\x1d\xf8\xe1K\xdc\xf6\x88\xd7\xd6j\xad+_-\xc0\x033\xcc\xd5k\xdc\xfe9\xba?\x98\xc8\x97\xde\x0c\x99\x12\x9b\xd4:\x88\x0e\xb3\xb8\xe4\xda\xc3h\xbc\xeb\x00\xea\x1a\x8d#)@\x86\xbac~\x13\xa5h\xd9d\xc6\xd1\xddk\\J\\\xe0U.\x15;\xb1\xd1\x7f@:#\x15c\x07\xd9\x12c\xcd\xff\xbb)\xd1Zc]e\xe3\x01\xcc>\n\rF\xaf\x9ey\xe5\x13{\x8e\xc2\x85\xaa8MT\xcd;R\xe9\xf0\x15\x91!\xd1\x85c\xeca\x8d\xc4y\x8d\x99D\x89i\x88\x8cn\xcf\x1cx\xa3\xb7f\xf9\x92;\xe7\x81lA\xc2\x88Vr\x0e90m\xdd\xc6\x1e\x04\xaf\xe2p\x8eN\xc0\xbc\xfb\x04_\xd6\xbe\x1b\xd4\xf7w\xc0\xfb\xa1\xe5I\xa8C#/E\xfb\x0b\xe1\xf7k\xa4\xc0\x1b\xb7\x06\xdfI\xf7\xd1\x86U\x01\x88\x83d\xa2\xb6\xe6\xffgnn\xb6\xa1\nj\xe7\xd9i\xb8\x9e\xdb\x18\x00\xdf+\xffV\xba\xcee\x08\x960\x0fP\xf3b\xc3\x941\x06sE\xbc\x1b\xfe\xbcO\xff\x9f\x83\xc3\xf6\xee*\xb3\xf9\xe3\x05\xed\xa3\xc6,\xe3\xa0X\x15\xce\xf7$\x9c\xaa"\xa7$>\xfc\xce/\xb6\x9eY|4\xc8\x06\xa3\xc0)\xd0S\x1b\xc2\t\xf2\x93&\x8fC\xf8c\x86\x9c"\xd3P\x86\x04\xbchl\x9b?wI\x81\x8b\x0em\xf2@\xa2\x82\xe7\xc7\x03fA\xcc\x91\xaa%%k\x80\x8a\xed|\x9b!\xd8\xa36|\x1e\xa6\xc1\xfb'
|
|
|
|
|
|
2024-12-14 17:54:48.129963 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25556
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808793669
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.139590 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 5880
|
|
id = 47903
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf597
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808793669
|
|
ack = 1299534557
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'W\xd6LW\x7fA\x97\x92T\x1f\xce\xfa5\x16S\xf4\xb1\x95\xc0\xcf\xbf\xb7cP\x82;\x93\xa1\xef\xef\\\xbc\xeb\t\x1c+I\xa3\xfa\xfb0\xef &\x15\xdd\xee\xaf\x9f9\xa1S\x9e\x83\x1e\xe1\xb7\x1dY\x92\\,\nF\x92\xa1\x08\xda\x1f\x94\xb8\xa4z\x90=\x92\xaa\x08\xe0B\x92\n4\x81\x11/\xfd\xcc\xe7mwgG:g\x19.\xf0H\x10,\x9c\x11\x17sf\t\x7f\xc3-\xc2\xee\x95\xa6\x1a""\xf3\xf1\xcf&$\x19\x84\xdd(Hn\xb0}\xff\x91$\xe1\xfaK<\xa4\x80\x8f\x1c\xb8\xd7L\xe9\x84\x82\x05\xf0H\xb8\xff%\xe7x\xb5A\xa5\x13fJ\xe4\xb7\xc2T\x0c\x0e8G3\xcc\x1f\xbc\xd1\x8b}\xe3\x00\x8eKJ\xe1\x07\xe2\x0b\'\xa2\x96/\xb4c\xab\xb2\x83]\xd3UN\x93\x9a[\xcd\xd4\x90\x1c\x16LR\xad\x8f\x8c\xe0\xd2s\x872=\r\xb0\xfa\xcd\xbe%<\xde\xad\xb1}T\xb3N1]c1\xc1\xcbfr\x8e\xdbT\x80W\x89\xcf\x8a\x15e\xfa\xd1\x1eKZ\x01.\xa1er\xcc}^\x1b\xfb\xca\xc0\xcf:\x8c\xf8\xf4M%\xd6q\xdd\x94\xb4\xf6s\xeb\xe2\xb2\x0e\xe0\xd9\x13\x90\x7fo\x1a\t\x94\x1a\xcb\x19:%\xa4\xdd\xaa\xe3\xb44\x96\x17\x08MB\xd7K\xe0R|\xeag\xdd\xb5\xbc\xe82\xb2\xd0?\x8eK\x9c\xe8NE\xa0P\xb2\xd2\x8c\xfd)\xa4\xf6\xe0\xd39\xe5 \xd7r\xd1Xh$\xc2\xe8\xcb\x8c@\xcdZI\xd1(V]\xdet\x90\xb3\x87S\xb6\xc2\xc64\xd8\xca`aJkU\xf6\xcc\xcdsp\x11\xb8C\xea\x97\xd9\xe5\xa4\xb7\xe8\x8f\x83T\xf2\x1bA\xa6`\xd5\x03\xab\x04\xb0\xc4\xe6\xa2\x91\xa5\xf3\xd2\xf3\x99pH<k\x15\x0c^\xacq\xacTj/p\xdf\xdc(\xa5PT\xfe\xba\xfb\xb0\xd0\x01\x94\x8b\xcek\x9d\xd0\xbb\x80\xd5\xec\xf9.4>C\x99!a\\\xfc\x9d\x97L\xa9<\x0f\xa0N\xd9fC\xe4E\xfcM\x1b\xb4\r<\xe2_\x1bFv\xca\x9a`A\xb0\xf6\xe9\x10K4\xfa\xbfc\xb1r5\xb4\xc3\xec\x11\x89\xb1\x15\xec\xd8\nH\xc8[^\xcc0\xecu\xc6gef\xf0o\x86\xa2\xaf}\x8a\xaf\xb3\xf0\x9b\xa21\x85O\x03\xed\xdbX\x97\xcad\xec\xcff{\xf18\x84\xb1\xb1\xa2\x1e\x9d\xecC\xf8\x1cA\n\xdfo2~\x94mMnP\xcf\x7fd\x1e\x8f\x85\x18 \xf4\x0f\xa8\x0b\xd7\x17\xf4V\x1d/U%\xe8fA\x0f\xe8:S\x16\xb3\xf1\x16D\x04\xe36\xefR\xaf\xd5{\xd4\xf9\x89\x8d/M,>\xfe\x18l\x9f\xac?\xb6\xb9}S\xf4A\xeb|\xf5\x0bm`\x1d\'\xf20\xf1K\xf3\xaa!\xe8\xa4_&\xe6R1\xcb\xbc\xe8Z\xbb\xb5\xf3\xcc\xa9ta9\'\xd0G\xaeQ\xf6\x15\xea\xfc\\\x19\xb4\x0e\xb4\x8b%\xd3\x81\xe0\xf5\x9ec\xda\xdb\xfb\xb2\xd62\xa5Ot\xf9|\x9e\x91\x8d\x86\xe0\xb3\xfd\x95\xa7\xd7#ju.q\x06$#\xa7\x82 \x0fN\xb7i\xb1l\xac[\xd9 \xcc\x7f\xd1\xa1M\x07+\x8b\xd6d\xcd\xe4\xf7\x0ed\xb0\x8b}N7aN;|0\x0eeyh\x0c\xfe\xcb\x7f\x93p\xdb\xb7MZyf\xbc\x1b\x00-^\xde\x1d\x15\xb0\x93\xa5$\xfb\x83w\xaa\xaeD\xc4\x84\xd1/\x076\xc0\x83acq1\xf5\xc8\x87e\x84\xbc\x86\xa2\x952\xec\xca\xe0\x9b\xabA\xa3\xfc\xff\xd6F\xd3\x08G_m\xabc\xd8)\xbc\xda\x9c\n\xe75\x9b\xa4\xf2\x1d\x88R\xbd\xdc\xca8\xdf\xa3\xc3\xb0\xb1t\xa17\xa3\x00\x82\xa4C\xf8\x8b\x84\xbb\x889\xd4\xf2\x14\x01\x8f>\x8d\xc1\x8buj\xe8\xc9J.\xeb\x8f/\x18\xe5\xd5\xe9\xb5.\xd9\xce\xa06\xae\xde\xf5\x01\x9dB\xd2\xf41\xac\x1d\x07\x00\x8a\x1f\xff\xaa\xba\x1f\x13\xab97b[g\xac\xd6=\xa2Z\xd7\xd3\x86\xd4\x1d|\xa5\xaa\xd1\x81\x077\x0e\t\xcc.\x9aHy\x88\xdd~\xef\xf9\x1b\xbd\x91\xa6(\x1e\x16U\xd4\xef&|\xb1\xe2@\xdc\x01ASH\xcaD\xcb\xfe2\xd4\xb9\xb1H\xf6\xa2/M\xec\x9a\xce\xd7\xc9\x89\xe9\xeeq\xcf\xd7E3\xf8\xe6G\x1c\xc4\xc3"K\xa7\x8bK\xab\xf5\xc4\x14\x91\x85\xf5\xb6_\xafT\xc4n\xa4C\xbe\xf1\x14\xb2C\xfe\xeapU=\xdd\x9c\xec%\xe2K\x8a\x01\xdd\x9a\x97A\xfd\x9e\xa6\xb2\x86\x19]>\xa2\xba\xe9\xe5\xc3\x12\x1b\xad\xe3\xf5\xaeY\x15\xc5\xfc\xc8\xad\x16\x0bb\xb1GJ5\xa1R\x9f\x8f\x07\xb4\xca\xad\xca\x11\x92\x86Tu\xa1\x19H_Nz\x88\\H\xcf\xff9\x91\x81\x02i\x88\xbd\x91*\xc6\x88\x9d\xd4\x0c\xc5\xd0z\xb1\x0f1\xb9D\xe9\xf4\xfa\x08T\x8a\xe8\x9b\xfe\nz\xdc v<D_*w\xc0\x06\x9f\xbe\xf7i^\xc9\xe3\rMOd\xae\xe9\x84\xf3\x86\xfd\x88\x8d\xca\\B\xb9b\xe4\xd9\x8bTl\x93\x04\xeas\r\x9aQ*\x91h&\xe7\xf1c\x8f\xaa\x9fzT\x91\xf8]e\xbb\xef\xfa\x8a\xb6fZf S\xb2\xf1\x83\xfd\xff\xc0\xe7\xa2\x00\x96\x85\xb7NA:R>c\xb6\xc38\xe7\x84\xf3\xf9\n\xec\xbc~qc\t\xc5 \x07obh\xd9\xf1\xbe1\xd5\x1dM\xca\xaaKK\xa9\x7f\x1c\xfc\x13\xd2\x9b\xbcY8\xf6\xb2^}\x95\xa6 G\x15\xff\xb69\x08\xd4\xde\x96\x06\xb9\x02\xf9#3\xe4\n\xc6\xbc\xd2{\x1b\xee\x83\xf4\xda\xfd\xaf\xf1\x96\xa7\x93\xc2\xfe\xd5\x1f\x17\x93\x8d\xf5\'N\x0c\x85W\n\xc4\xef\xed\x9eF\xef\xb1f\x10)\xb1\xfaXn\x11\xed\xeb=\xbe\x04\r@\xb4\xb3\xdc\xdc/\xb6\xf2\xfe\x881e\xa0/\x12\xf98D\xda\x86r\xaa;\x8d$2\xc6&x\x84\x90\xee\xec\x1c\xa0\xc3#-i\xb7\x06\x06\x01B\xa4\x05\n\x00\xb0v\x89\x16\xa2\x1f\x02\xe36+\x18U\xe9Jx \x0f\xe9\xdb\xbd\xc6G\x066\x886\x13foG\xf7E\x04(?E\x91\xe2e\x85\xa7)[\xb7yP\xfd\x97\xcer\xa6\x169\x13\x8e\x9d\xa6/\xbb\x95\x1b\x95\x9e+\t\xc7\x87\xc8)\xe6)4\xe7\xe8\xa2\xb6yg\xda\x85\x06\t\x98\x9c\xc3\x95Q\x15\x89\x84\xd2\xa6\xc3\x1e-\x94\xcf\x06}\'V\x1b\xa0M*$Y\xbd3S*\xe2\x81@\xf1\xf8\x86\x7f\xb9\xe1\xba\xd0\xd0@2^V\xb0v1e\'\r\xcao\x1aX\xa09\x08;\xa3\x8a\xd4\x8d\xf8\xdd\x90\x85\xe8E\x8b\x88X{lt\x9a\x83]QCUr\xca\xeb\x11z\\\x15\xba\x87w0H\x01\xc5\x08\xad\x17\x85\x7f\rA\xaa\xd4\xa7\x13\xfe\xf9\xe0Fg\x98\xc2K<\x0b\xd7\xcfg\x19\x96\x0etmC\xe0\xe2\x08u\x80\xe6\xdd\xe3&f\x7fmM\xe5\x0eM\xf1\xef\x99E\'\xe4\xa6\xab\xfc\x08+\xd5\xa0\xff\x0b\x8f#\x185(\xef\x06\xd8\xb2|\xd2U\x92\xc8j\xfa\x1dj\x10\x1f\x0e\xea\xa5Q\x98\x99\x19\x92\xf4\x19\x06Y\x01A\xdf\xee\xeeO\xc4\xbe\x9bf\xea\x1f\xc1\xaeq\xde\xab\xaf KWD:T\xa5\xa2\xc0\xb0\x92\x8e\xa3\xd6\xc9\x12\xf2\x8a\xdd\x99\x95\x86O\xa1X\xf7\xc2Md\x1ett\x93M\x91\xd8\xd7\xfb}\xca\x06\xd2\r\xa9(~" \x03\x06u\xeaG.\xb1\x01\xaes#\xb2D\xbc>n\\\x92\x81#\x15\xd9[\xae\x95]A\x92\xd8\xa8\xbd\x19S1#\x15\x95y\x15\xca\x06#ljj#Z\x8e\xc9h\xa7\x1d\xd1y2\x1cV\x83\x903\xdcq\xc0\xea\x17q\x98\x11?\xf3\x92\xb2rd8\x7f\xad\xbcq\xe5\xd5\x10\xfb\xd2\x1b\xd4\x0b\x82H\xa0\x81\x8cF\xd4\x1e\x80\xc9\x07\x7f\xd2]\xd8<\xb1\xb7A\x87U\x90\xeb\xa1nD\x16L\xd4c"\x94\x1d\xaf\xc03\xfe\xbe\xc7\xb7\xde\r(\xd1.\xc9\xa6:\xbff\x18Lm\xc6\x8a\xf1\x16i\xf8fI\xc6N\x91\xdaE\x9c\xca\xf4\xd9\x81\xdc\x03\x10\xbdIe\xf2\xf7\xa8\x89\x1cy\xc4w\xdcu\xc1N\x11\\\x05h\xb6\xbf0A\xfd1\xf1\x08\xe6\xcf\x8d\x19\xb6E\xa5<\xe0\xcae\x87\xdb\xa5\xba\x9fs\x9eQ\xf1n\x8e\xbe\xbcU\x01\'\xad\x89vAE\x9f-\xb4\x8fy\x94?\x8b\xc7\'\x8e\xbe\xe0\x11\xbe\'%\xc16\xd1d7%\xb4\xe2\xf3\n@\xebrt\xee\x9c\xc5}\x00\xc8\xcf\xe9\x83x<\n\xec\x14g[\xdc\xd2\x90\x97\xb6*\xfa\xf1s\xae\xe7\xd5j+\xb4H\n\xbc\xc4\xa4\xe1\x0c\xd1\xec\xd1x\xf8vN\xf8V\xf4\xa0L~s\x80@\xac\x1a\x9b:F;\xc5J\x0f\xe2\xad\x0eg\xabdm(\\\rS_ap\x90\xcd\x9d\xac\xc9\x12\xcd\x03\xeb\xca\xf2\xf1\xbfe\xed\xa6"V\x1b\xc0\x18\xab\xd6\xbcet;\x16,\xbb\x06W\n\xf0|\xde\x8c\xa7\x8a\xbdw\xca\xa1N\x0e>\x83^\xf0\xb5b\xea\x10\x17Z@\xb2)\x9c\xe4W\x88\x03\x18\xff\xa0\xe4\x9f\xdb\xbd\x01\xa0\xd3\'\xe9\xeb\xe0_O\xd5\xc8\x9al\x02]\xba?\x91\xb3\x18\x01\xf0\x17\xac\xfd\xcc\x90\xda\x08\x10\x12\xcd\x8b\xc7\xdb\x95e\x1bz\xfc\x12\x0c3\xafn\x08I4\xa6\x88\x99\x7f\xaa\x93n|\xcc\xc7wI\xb9L\xc7<\xbd\xba3\xb0u\x08D\xad\x0f\x8cMzv\xb9\xe7\x05\xd2\tv$KFP\x92y\x9d\xf5sg\x05\xa3\x1f\xbd\xcf\xa8&\xafk.\xcb1\xb2\xaa[(H~fq\x83\xf7\xb3\xadQ\xc6k\xb3\\Ne\xa5\xb8\x18\xcb\xba\x12\xb7\'s*\xde\xa3e&\x94F\xf3D\x17f\x95\xd5\r\x94\xe2\xbf\xff\xe8k\x13t\xf5\xef\xa2\xb4z\xe4-\xcc+"Kg\xfe\x95\x90\xd9\xbc\xe5\xe0\xaaJ\xb0\xcb\xd4\x89\xedGT\'\x93\x7f\x88\xae\xb6\x7f8\x83Z(\xbfK\xd5\xd4\x7f\x12A;\x9b\x88 E\x8a\x0c1\xc5V[\t\x0c\xd2\xb4\xc5\x04\x83\x90w\x1dJ\xa1\x9c\x816k?\xa6\xc1*\xe99\x16\x1a\x16/\xc6\xc3\xc1sX\xee\x16\x10\xbe\xc9\x836\x9f\x88\xfe\xcb]\x1be\x9c\x8c\xd4\x16N\x8c\xbc\x12@\xebv~\xcd\xcd\xf2\x14\x0e \x9f~\x01\'R\x019\xfc\xfcG\xa5\xb8\xa1\xeb\xac~\xd5\xbe]`\xe0\xbf"L^7nm\x12\xa2\x0f\x19@\xce\xac\xdf;\xa6bZ|\xce\xff\xf2\xa0\x9b\xdf\xc5\x1a"\xc2\xcc\xd66h,\x92\xc3.~\x8fZJ\xe79\xa8n\xa4\xd4\xbb\xb8ca\x82\xdd\xa7jo\x9c0\x80P\xcd\xa9;x\xdf\xb8\x06\x11\xebz\x07\x159\x97p\xe2\xa3\x8dNC\xa6\xeb^\r\x96\'7\x8b\xeaI\xe1\xef\xa2\xd1\x11\xcd\x8b\x8b\x0cE\'\xc2\xc7\x94A\x06\xf1a$+L\xe5*\x18\xebj\x86\xc3KsL$`\xceIa\xf1v/\xf3\xbaV\xc5\xa7\x98/\xf2\x89\x17\xb1\xd3R\x01\xaas\xb0\x7fQ\x10\xe6%^\x83R\xaf\xd0\xe1u\xfe\x13\x81\xd4=\x1a\xae?\xb9\x0f\xd2Qnz\xbap\xc4\xeb\x16\x1a)A\x82\xbb\xfdV/\\\x05\xa6)\xd3O\xc8"\xc6\x02\xa6:*Af\xf1\x99\x0f\xd5>\x9b-\x12\xd6E\xdf\'+\xf9\xad\xd6-\xc1\xa8_\xc6\x83\x92\xbe\x7f(\xe8\xb6S\xd9\x98\n\xda\xf7\xe4\xdf<{\x87Uba\xe5\xca\xfd\xea\x9fk\xf4C\xa2\xd2\\\xd2\r\t/\xc9\x80\xb6"6L\xf7\xae\x16\x13\xeb\x81\xcf/\x14@\xe3D\x81MDN\x0e\xbc\xd0\x14\xa2\x08\xc6\xb8\x04)\x17\x91"6\xc3*\xe4\x13M\x9a;\xb0n\x7f6\xe7{\x07Q\xb2T\xf5\x93Fe\x88\x02\x94\xe3,K\x99xl\xc5\x97(F\xbfA\xdd\x1e\x05Y\xa2\xb85\xd4}\x16\x88S2%\xd3`+y\x1b\xd9\x9d\x9b!@ti\xd4\xb2\\\x92k}}\xe39\xaa\xc2\x81\x0b)\xe5H\xd7\x83\xd3\xec\xff\xbd\x9d\xc4h\x06&L\xa5\xaf\x0b\xbc=\xf1\xed\xf4:\xd2d\xe0\x01\xcd\xb2T$~\x8dE\xcf9\xa2\x9e\x16\x8c_"m\x13\x01\xe1\xdc*\xf3\x87*\xa8 L\xc7\xc5\x91\x82+\xb3\xda\x9f\xfd\xf8kQ\xa6/\xf8\xe4\xce\xde\x12+\x80k\x1d\x14ZW\xc2\xb4\xa6\xb1\\Mc\xc4\xc2\xea\xe1B\x94\x80o\xf8\xd3\xdb\xe7\xed(\xae\xc0\x11U.\xf0\xc1\x1ez\x81\xde\x1a\x15\xa2\x88\xd5\xc2"y\xb3P\xe5\r\x8d?_~\xa3\xc7<\x87\xa1\xce\x12\x8c\x89\x87YL-\xa0?\x97)&\xf9\xc0"\xac\x0b\xe3C_Z\x88\xd0v\xbb\x7f\x03\xd4\xbd\xadd\x83\x97x+?q\x91&\xb0\x18;\x90I\x1e\nv\xa5\x89oS\xfb\xdc\xfb\xa2\xfa\xea\x14\xecw\xa0\t\xd3\xc9\xcdmD\xb7\xd6`\x96`c:w)t\x8dN\xec\xe8\xb723\xd4\xa1\xe0\x03,\xd2\xdd\x04F\xa9.FeC\xe0\xf4i\xa1\xed\x94q{\x8a\x91\x0blt\x92\xc5\xf9\x9b\xa6\xa9\xa4\x94\x14W7\x11r\x9a\x10D@\t\x0e\xbf\x93O\xa3\xffS_s;W\xbdJ0\x97R\xc83&]C\xcc\xfc\xd1\xcc\x94R\xd9]\x1e\x7fm\x8b\x9f\xb0\x86\xd0\xf4t\xcf\xac\x9a\xdd\x01$\xde\xac\xa4\xf4\xce\x08s/\xf4\x13~\xdc&C,\xf93\x08\t\xd3\x7f\x9f\x1f\xdc\x87k\x8cl\x86\x80h\x02\xf9\x1cN\xd1\x17J[rJ\x99\xf6\x8c\xabks\xc3#{\xc7\xd0z\x92\x08Z\xfb\xa9\xe9\x15\xa4^\xa2\xeb\xaf\xcao\xc0e\xc4\x16q>\xcb\xb4Q\xfcl\x92\xf3\xa3.\xbf\xfe\x017\x1aI\xc3q\x1f\xf5\xd3\x9aV\x87\xd7\xdb\xe9Q\xf7.\xe02\x05\x1cf\xfeI\x8f\xda[\xffAZ\xa7\x1c\x96\x17$\x92\xabQ\xf7\xf5{d<\xcb\x05\xfePf\x929\xa7\xc0;\x93\xb0\x11\xf8\x02\xd6\x02\x08\xcbMf\xeb\xe4\xd8\xd9\x9cn\xe2Jl\xc5\x8cre\xa6\x88L\x08\xdeV\x83\xf0\x91M\xd3\xd5\x98\xb8&&\xe0G\x0b\xf2\xa1\x92t\x9b v\xe9\x9e`\xde\xf3\xc4\xb0\x03\xd4\xfe8\x0f\xcd\xfb\xdav\xf9\x003<\xb1\n\xd8\x02\xf4\x08>\x87C\xd9\x05\x12\x1f:*me\xe8\xd0\xf2\x13\x83N:\xd1K\x16_\x8e\xab\xb6\xc6\xf2\xa4\xe0_Y\xe5\xd8\xc9\xd5\x8dD\x80\rH\xe6\x85f.\x81s\x15\xfa\xbbw\xe1\xcd*\xfe\xba,4\xaa8\xc7<\xd0\xaeh\x9e\xd1\x12\xca\xe6\x07J$`Gk\xb7\\j\x90\xe9i\xdahM\x963\x97\xd6\xd3\x0e\xdd\x7f\x7f\xed\xca\x80s\x01\x98\xd6\xcb\xe5\x1d\xff\x08\xa2\xf2\x0e\xaa\xdarL\x98Ax\x902)\x04\xcdG\x99\xde\x08\x9f\xcb\xf0\xd0\x91i\xf5\x8a*\x1f\x95\x1b\xa4\xb2\xd3\x1d\xc8\x13\xac\x925\x82\\\xb5\xef\xe4%5\x8e\xb7\x84\x178l\xb3_B\xe8~\xd2\xa0\x98\xa3$\xb4}4\xdb &\x18\xce\xd7\xbb\xafV\xa8\xb3\x0b\x07\x8dZU\xa8U0\xd2W\xb8\x1b\xad^\xe11\x83\x94A\xae6\xad`\x88Tj\r2\xcc\xc0"\xaa\xdb\xea"\xda3\xa2\xe3\x88*4[b9`Rr\x9d\xec\xef`\xcfHel\x1b{\x08\x9ec\x90u\x81z\xc8Pv\xc1\xcd}\xde/;\x02\x12s~Z\xf0e\xf9\x87\xdde\xbf\x16\xb4\xed\xa7\x93\x98\xe8\'J\xa42\xaf\xc6Bs\x10\xfe\x1cr\x99\xdc\x12\x19\xa7\x02.{\x11Dz\xb8\xb3\x11\t\xb9\xdf@\t\'39>\x8c\x0eJJ\xac\xdc\x96.w\x18VSKz\xde\x02D\xc1nhSLh\x1eLUE\n\x0b>QB\xbf\xa3aJS0x\xbad\x86\x9a\xcb\x03\xdd\x1f\n,K)nA2\x12W8%\xc9\xaf\xe5PsA<ky0\xf0^\xe8[\xb3\xc45\xe8+\xcb{\x07\x83s\xe6\xf8F~9\xde\xc2"{\xf0\xfef\x15\x04/\x02\x86<\xc4\xb6\xb5\xdc\xfc\x89$\x1b\xcdo\xfe\x92/\xa7\x94\xbc\\\xb3\xa4\xc4\xe8+\xea\x99\xe4\xbb\x10:\xc4\xca\xa3gxpP<\xbfXY\x92P2\xd6#\x00\x9a\x8f\x15\xee\xe3\x82\xa7!\xb1\x91\xb9&L\x19Z\x13\xc3\xdd\x1e\xc4\xbd\x87\x1c\xfcp\xacf\xd5\xc1\xa2ti\x97.\x98\xba~?g9\xeb\xf6\x9c\x99\xffE\xc9\x00&\x99v)Ts\xefb\xd0\xadQ\x89\xa9\xfc\xc8\x1b\xc9\x8d\x01\x92%\x907\x80\x9d\xee\xe4\x86\x89\x1c=m\xd2\xff\x9aP\x90\xda/\x02\x93\xa2&T\x80\xc2\x19\x9a_\x84\x0e\x1b\xc8\xae\x13\x1b.\x8c\xbb\x8f\x1d_N\x13#(\xfd\xa2\xe8\x97\xc3%\x1b]\xb7\xf0\xd7\xf8=\x96\x1ea\xb1\xbd\xc7\xf3\xe3\x10M\x7f\x14\xbfI\xb1\x84\xe7\x85\x87\x02\xbc0S\xa1\xb6\xf0\x867\x88V?\xcf\x0ec\xb9F\xe4\xe2\xbd\xa1\xde\x1b\x80\xc9\xec\xce\x8e\x8c\xb9qv\xeb\xfb\xb2<\xb3\xc2\'F\xc7\xc1G\xf6x"r%Gyn\x16\xfa\'\x13\xe7\xc4=\xe4\x03pI\x18p\xf6\xf1\\\'\xec2\x17\'\xd1\xcc\x84\x91nb\x88\xc7\x13\xcf\xf8\xed\xad\xc0(\x87\x8aU\x12`\x1bX`F@5w\x90\x0e~\xa1@\x97\xe6\xa5\x94\xae\xc7@\xd1\xec(\xa0b;=\xecP\xf3hN\x8b\xaf\xc8k\xd3!\xc3G\xca8&d\xf4\xc9\xb266\xf3L\xbfg8dGT\r\xf7\xa6\xc7SOm\x17\x96!\xb5o\xaf\xc5\xb0m\xfa\xe8F\x88v\xc65\x96\xbcE\xe2\x8c\xb2\xce<\x06\x01\xd6\x00\tu\xe7*\xe9\x8bh\xd5w\xbeY\xd5a\xbe\xe5\xf9\xb6\xa3g\xfe"\xd7\xc9\xc00\xdd\x12K\x1a\x18\xd7\xf5\xf2c\xf4Mc\x19\x05\x83\x8dc\xb5go\xbbnu\xd3\xb9\xb8\xd9\x99\xcd\x87I\'\xe9\xeaW\xbb\xd5\xe1\xb0\xe6\xc7\xd2\xe3%\xca^\xc8\x86\x0e\xbe\x0e\xf3\x12\xa8\xb7o]\x0e\\\x99\x07\x84\xef\xf6\xafF\xe0p\xb9\x90\xfc\x81\x18\x91%\xa1\x11\x7f\xdd\x81\x88\xe3\xed.\xb8\x8e(h\xff\xd8\xd5\xbc\xca\xcb\xe7\x80\xefdk4 \x19\xfc\x81\xea\x7f\x156\x861\x89M\xb6\x0e\x7f\xf4\xd8X\x1f\xa1/\x03!\xc1.~\x13\x88\xde\x87GA\xcf}\xfc\xa2\xed{\x8c_\x9c\t\xbc>\xe6\xf4\x0f\xd5\xe0G\x02\x19*\x9b#\xd3\xd6\x15\xaaf+\x95\xa3\xc5-X\xefBB\xa28\x7f\xee_\xf9-,\xe5\xa0\xe1\x0e\xaa\xfb\x0b\xaa(L\x9a\x9b\xa4\xa2\xf7\xc87\xc3\x11\x8d\xfd\xea;c\xb3\xc4(o\x93\xf6\x01\x84(y\x98m1\xa2\xf54\xedv\x97t\xa4o\x14\xf0\x8c\xdc\xde\xdb\x86\x92\xbc\x04w\x0e\x92\x15\xba+\xfa\x9d\xa2u\xed6\x043\']\xfb\xb7\xbe\x03\xcc"\x16\xbd\x89\xe2\x1b\xa1\xb5\x1fg\x8b\x97\xc30\xec\x1f\x0eZ:\xbc\rz\x0f`\x12R\x93I\x92\xf5\x94\x84\xb7\xc9\xfa\xd0|\x07\xdc\x1b\xd7\xb0J\xaf\x9d\x8d\xaf\xcf\x8c\xfdD\xc6s\xe9\xd2S=\xaf\x10\x17xCr\xe0\x8f\xc6\n\x8a\x13t1o\xc5`\x11\xd7\xa6\x87Q\xff\x9e\xcc\x83v\x80\x1c\xaf{\x12L\xeag\xd0\xa9\'\xae\xe5\xa8\x1b$\xc33\xd63\x1c\x8f.\xb2\x9co1\xb9\xd1Tb\x06\xbb\xb8Y\xf5\x9d\xd1\x04\x0bV\x8dJ\x82\xf2\x93/;d9N\x13\xacZ\xaa\xc4J+\xc9sW+I6\xb4\xa7M\xdb>a\xe6\xdb\x12\xaeD\\?\xa5\x19\x1c\x80wD\x1b{t>\xec\xbb\xa8\x9b$\xb0\x01[\xd1\x11\x01c\x8e\x1dk\xb8\xeb=Mh`\nX\x00"\xcd@\xd5mi\x9d\x97\x91}\xfe<i\xaa+\xdfa\t^\xe7\xa6lc\xf7s`\xcb:\xdb*\xbc\xfe\xb9\xa9\x11\x10_M\xc4\xda\x033\xf8\xa4\x8c\xf9\x1a\xf2+\xdaO*\x05,\xf7\x99z8\x99\x12Wm=n\xa8\xc1\xbb1\xd0\xac\x0f\xd5n\x01\x03\x85\xf6.\xb4&t`r\xf4r\xb5;+\xfb\x7f/\xd5\xb7?A?\x1a\x7f\x06*\x8b~\xa4\xe5\xc9\x1e\xbf\xb0\x0c3\x14\x0c3\xc8.\\\xf0C\xdc\x9f\x94\x85\x80\x9a\x0c\x1d\xd7\xb8\xcaY\x98\x16]E\xbe\xa0\xdd\xa0\x94\x87\xdb\xb1\x8d1Y}\xff6\xd7\x88Y\xd7\xf3\x807\xfe\x8d.\xe4\x97\x0fV\xa2\xf0:M\xc7\xaf\x94\xd0D\x84+\xacO\x1ak\xa7\x9e\xb9\xaa\xb1\xf8q\xd9\xa1\xb9\xd6?\xd8\x87\xb8\xd9n\xbfU\xe6/[\x1c\xbd\xe4\xc8\x85\xea\x98-\x97J#\xd6\xac\xe2\xc8\x85E<\xd8t\xd3FS\xef\x90WNBQl!\xae\x94\xf6\xd8\xfd\xb6\x16<\x17\xd4;\xd83\xcb\x16n%\xda\x8b\xa9$T>b\xa1\xd9\x04\x0e%\x96+N\xf6?h\xb9o\xd1cP\xa7P\xd7p\xf3\xc0\xben\xe0D\xed\x01\x14\x8e?\xa0\x9a|^\x1f~`*\xfe\xc4\x96\xa9]\xe3%\xf8\x9d^\xb9\x1bJN\xd6\x97C\xde\xdd\x8e|\x95\x89\x03w\xcfo\x91\x92\xc7;\xbd\x11m\xe3N\xb8]\xa2]\xa3\xf1\xd4\x8a\x17\xcb.\xc6L]\xd5\xae\xfcb2\xd5\xafk\xe8/\x99(\xe9=C\x03\xb6\x84\x87\x9c\x1d\xd4\x05\xb1\x8c\xb5\xa5\x88\xd5\xfb\x9e\xc1]{-\x91\r\x15K\xe8\xb36U\xbc*b\x8c\x1c\xc9\xab\x00\xd61\'\x7f\xad\x85Ki\t\xbb*\xc5\x08\xe5\xf3i\xcd\xa7\x0e\xcf\xe7\xcf_\x82\xbc\xf1\xce\x9ef\xa0\xfeUa\xd1\xeb3\x96\xa9\x05[\x8d\xcfgh^\xe6\x9c3\xb2Z\xb6\xed:Y\x11\x07\xad\x8aHY\xcaJ\xc4\xe3\x87\xd7\xf1\xfe,\x9a\xb1T:\x96\x87\xe8\xa4\x9b\xaf\xf5E\xb0\x07Ms\x80\x10\xfb%\xa0\x00\xbdcsds\xcf\x95\xed\xa9\xce\x1c\xe42X\x1bZ\x8dO\xec\xd1\x0cp\xb3\xe6\x848\xc1\xd7\xb6\xe0\xc9E\xcd\x8d\x0e\xca_\x9e\xabL\xc6\xfar1\xef>M\xeav6\xd9_,\n\xbf\xb4/\xaf\xcc?_\xda\x8e?w\xacI\xf5L\xe1\xd6B\xd2\x9cdV\x91\xc3\x1b\xec<!q\xb7\x80\x93\'\xd6h@p\xf5\x18V\xe0I\x8a\x1fOR\\\x97\xcc\xd6R^\x18\x83\x0b\xe5.\x9f\x0bUKw\x9a\x86\xdcDwSHtdO<\xca\xc1\x08~\x93Y\xaa\x8c\xbc\xfdb\x07\xc9\xeb>\x7f\x07\x0c%\xb1E\xa9\xec\xd6\x10\xf5k$\xce\xa8\xb6s\xf7\xcc\x819n\xac\x88"k\x15\x1b\xa3<H\x99\xf3E.\x15\xb9\x85\xdc\x88\x9f\xfa\xf8\xbb(\xd5oV\xe3\x99\xf42D\x18\xae\rM\xa2B\xdb!m[\x91?&\x17\x90\x93\xa2\x81\xe6B\xdc\xcf5<P\xb8\x1f#\x16\x9d>\xda\x8a7\x1fs\xf4\xd4\xc4\x9b\xe2n\xb6Su?\x13O\xd4\xacj\xf9\xd8\xef\x8dO\xd2,\x12\xd7\xb3\xc6\xd4\xe7\xe5\xf1\xc0V"\x91\xc47\x15\xb4A\xb9f\x15\xa6\x84\xdf>AY\x8b@)\x05\xc5\xe1\xbb$\x83\x8a<\x89[\x18\x84\xeb\x8c\x91\xa74Uu\xeeO\xc9X\x14\xb71\x84e$K\xd2\x83\xe0\xf8-\xb8T\x89\xb8\xbbaM[\xfc3\xe0O\x0e\'V\xa2\xfb\xca\x8c0=\x0c7\x19\x97\xeeG\xdb\x86rE\xa3\xf9w\x84\xfcO\xbdVT\xf6\xbc)QK\x16F]\xe2[\x8c<\x8d\x15\x8d\xba>$!\xb7^\xcd\xf5y\n\t\xad\xe4E?\xd2;\x17\xe4P\x17\x00 \x1c\x10\xb0\x9di\x18\xd0\xd2\xc2K\xe4\x9e_.\x19\xe0\xeb\xabNH\x8c\xd8\xcfJ\x05\xc9\xaa\xf8b\xc5<U3\x15\x968i\x1e\xc2\x14)\r\xe8\xa5\x87~\xeb\xa1\xe5\xa2\xca\xdd\xe3\xad\x0f\\\x98\xb0\xb3m\xae\xc5n\xfe(\xdf\xa2.]\xdf\xd4\xfb3\xc8\xdc\xf83\xd6\xbf/\x0c\x87\xb7sgB\xe6\xfa`\xb7\xe1\xdc\xec\x82p\xc3\xa0\n\x06\xfd\xbd\x88Mm\x02\xe3\x81,\xdc\x0e%N\xd6z\xf1\xef\x91n\x98\xa89z\xa7\x97\x94\x85\x02T\tkx\\\xae\xfc\n\xec#>!\xb2\x99\xffX\xe5\xc4\xf0\x8cL\x1a\x18\xa3XX=\x04\xf5\xfe;\xcf\xf4\xdeQ\x91\x98\xec\xcf6\xdc\r\xe54\xe5\xa6,a7\xd9\xf2}K\x92\x0c\xe9\xd0R\xed\xce\xca\xcd\xd9<\x84\xcb\xf8H\x87\xb6,\x93k\xf5\xb3t\x8f9\x155\xde\xf7Q\x0b\xd4\xd6\x0ef\xdd\x16!\x98zSu\xd6\xc2\xe48\x8dL\x8d\x92z\xa4\xc0\xd5\x9d4\xd7\x99\xb88\xc9H\xb4\xe7\xbe\x06\xa6xk\x072\x96*\xa5\xf6i\xabW&\x9fJe\x91\x9e\x89\x97\xc7\xf4rUR\xeeT\x18x\x15\x1b\x81\xa2_\xf1\xb0\xaat"+\xad\x96\xb2\x17J\xed"\x02:\xbe\xf8\x02\xd9\xe3\xaa\xb6\xf0p\xcc\xa0u\xb1\x19\xf0\xdc?P\x1e\xe7\xc0\xe1\xe0\x0fB}`\xef6`V{\x9e\xd8/\\e\x89\x80\x87\x9c\x18\x86\xa4\xe8\xceQXu\xa1\x18\r8\xd5^E\xc2\x9e#f\x86\r-\xb4\xc7i3\xa7\x9e\x17k\xe4\x85\x1066!l\x95SZ\xf6\x1f\xd6Nm\xdb\x0e\x8a\xc6$V_\r\xd9{\x19\x9b'
|
|
|
|
|
|
2024-12-14 17:54:48.144129 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25557
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808799509
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.159841 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 5880
|
|
id = 47907
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf593
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808799509
|
|
ack = 1299534557
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'#0\x17\'\xb7\x89JP\x05\xe86\x96\x87\xec\xa1\x19\x95\\$\xe1\x02~}G\x17~\x9f5\x89\x9eC\x84[\xdb\x05\xb5L\xe3\xcfsl\x12\xdbk\xfee5\xddu\xc0\xae\xd5\xc5\x83\xb1\xfdB?\xcd$\x06\xfef\x03\xcei\xd6<VC\xe1\xb3\xedX\x17\xad\xfd\x91z\xe2\x08\xb8\r\xa5\x8a\\\xd2\x15\xa4\xf7\xed`jPG\x9b\xa1\xbd#\x8f46\xdf\xa0\xfa\x02K\x7f\xd3h\xd4\xcf\xf2O^\xdc\xea\x8c\x02\xb0\xc9\xf0AT\xc5\xd9<@<\xd5Il<\xc9U)n\x98{3?i\xe6(\xe6\xa0\x0b\x0b\rP\n\\\xdc\x0b\x9e\xcf\x81\xfa\xf8\xf9\x1a\x0b\x80\xb8\xfb\x9bJ\x9a\xadb\x83\x89\x86\xdb+\x82\xd7\xe7\xb8\xfb\xd6l\xda\xbf\x00\xfd\xa4\xd8\xc1e^\xe3\xc9-\xfcM\x89\xdaMP\xa7#\xed\xae{\xe0K_\xc3\x9c\xb1{\xdc_\xda\xcf\xbd"\xed\x9b\xb1\x0b\xb6\x90\xd0\x12\xae\x8c\xa6\xcd\xc1\x9b\xc9\xdfhma\xb7I\xa4\x8a\xce\x0c%\xaeJ\xae]\x04\x1e\xb7 Fd\xeb\x97\x1e%\xf6e@\x0cr\x16L95[\x00\x1d\x9d"kl\x96\xc4\x18\xebL7$h\x8dM~\x81\tTSLcF]\x1b:\xbb\xd4/\xd1l\xbb\xd7&\xa8\xe0\xc5\x9a}\x97\x91=\xd0\xfd\xaf\x0f\xce#zBK\x8b\xc1\xe2C{-2\x1d\xdf\x05s\x1f\xb6^\xbe\xa8\xfa\xd3\xb9\xa2li\x92\x03\'\xf6C7\'#\xe9X\x16\xc2\xda\xae\x83|\x80)\x1e4\x85n\x0b\x97\xb4\x91E#l\xbf\xcakG4\xe1F\xb8 \xd5\xb0\xf4\xe6\x02\xec\xee\xad\x91\xe3\x03-\xe3\xa9\x19Xi\xd6?\xe6\x7f\xee\xc38\xe0\x1a\xec\x1a\xbc\xbf\t/\x86\xb0\xc72Y\xed\x8e\x9b@\x90\x8bG\x0eW\x7f\xa7\t\x1d\x14]\x90\x04\x94\xbc\xc0z\xc6\\\xf5Mqe\x9d\x04\xa9\xd6\xd1-~\x84p\xa5F\x12\xdd\x7f\n>R\xfb\xfd\xd3\xa6\x84q/\x08:\xaf\x98~\x92\x083\xe7\xd3HSi\xa4u\x89v\x84\xa0\xd8=\xf4Iw\xa7 \xb5\xba\xe0-\xcd\xb0j\xc8l+\xf7G]\xbf\xd8\xaeti6=I\x04\xf3\x96s#\xcf4\xb5\r{\x80\xa2\xb6@\x96X\xb5\xf4q$\x85\x1e\xe1\x0c\xe8+K,j\xed#\x14\xc8\xaf\xdf\xb8\x0eL\xdaN\\~\xa2\xf5\xdb\xf6\xb7~[\xcd\x15\xb8u3\x07\x88\'\x15\xa6\xbe\x7f\xe7\n\xb2p\x91\xab\xa4\x1e\xf5\xc4Q\xd3\x8ft\xa0\x98\x7f\x11\xe5\x8e\xc0\xc4\xfe\xda\xf5\xf4\xf5"z\xac\x896\x1f\x1bY\xde&}>k\x9f\xc2\x16\xe48\xdc\xd6\xc0l\xa5\xd6`\r\t\xb8K*g\xdaK\xc5\x96\xa6&\x92_f\xd1:\r\xbcMf\\\xd3\xdb\x06ac\x1d t,\xa313*\x8f\xce\xf5Q\xc0-\x85\xc9\tF\xb3\xa0})\x7f\xe7\x10G\rq\xfa\x03j\x8b\xf1\xde\x7fi\xa7\x10\xcc\xaa\x1dMYfj\x9fA\xfb\xc3\x86i\x8f!\xe7}\xb9\x96\xd74\xa4\xf0\x97\xda\xeeu\xb89\xa8\xc6\x0e\x93\x11\xd4#\x0b`\xc5\xeb\xb1\x1de\xf8\xad\xb7H\x12G\x87\xa2.\xca+\x03A\xe8\x8dK\xce#\xfc\xbd\xd8\x11\xd9V\xcd/\x16#\xa1\xfa\xe1\n/\x8f\x1d\x9a>\xe9\xe0:}\x1ck\x13\x11V\xf4M\xcc-*"\x9e6\xcf=\x02\x06\xad\xfc\x8b\x0c\x88\xec:p\xe6\x85\xfbw8\xf7\x13\xc7\x85W\xa3\xbe%\x83\xdf\x94\x8d\xd4\x01\xc8\xda@\xea\x17\nKJ-\x8a\xf9Q\xad\xb2\x03hJ\x14\xff\x15K+MKP\x13n\t\x90\x86\x95\xbdm\xe0\x8f\xbc\xeb\x92\x02p}\x02\xc5\x9d\x99\xc2\x00\x1bV\xe5XzSd\xd7\xc8\x86vN\xb3\x8d)\x84pa\x0b\x92\xacf\xd6\x1b\xd1;b8\x05$r\xa4\xad\x0b\xf9Vj\xd8\xdd\xbck\xf6\xc8\xb5O\t\x82@\x90/\xe9S?\xb3\xbe-\xf6u\xd2\x83\xc3\x1e2\xe2l\x0ft\xd4\xfb<\x98\xf9xL2\x83\x82?&\xaa\x11D\xdfq\x8d\x15\xaeE\x84\x1e\xd9\xe9?\xf8bx\xbfy\xb6lu\xb0\x19\x00\xde\x17e\xb1\xed\xad\xc1\x03\xcd\xb6\'D\xb2w\xc9H1f\xbd\xdf\x0f\xf8\xb8\xb4\x96e\xec\x8a\xc5\xb2\xa8\xd2\x16\xff\xc95\xd5kC\xe5\xfdG\x99\xc3\x98\xfe\x07\xc0\xbct\xff\xf3\xa5\x84\xc9\xf2\x8c\x0f\x9c\xec\x86\xc31\xd7 \xfa"\xc0\xb2\x90&`\xbe\x01ER\n\x14\x9dk\xa8!l\xcc\xe7z\x96uh\xa7%\x04\xc8\x0c\x1d\x85])\x849\x0e.\xa6\xd5t\xf9\xd8+\xc3`\xe1\x01\x84\xba\xad\r\x93\xddDv>\xe5\x9f\xfd\x11\x1d_\xe6\xfe7i\x10\x13-\xcf\x9bhp\x8c\xa8rv\x11\xe2~\xa2\xa5DCh\x1a\x8b\xdcvW\xa1\x05\xa9\xf5P_\xa0\xdbv\xe1\x86\xf6w\xea\x18\x165\xb2K\xdb\x04\xc2s\xd4\x19\x84\xd6[\xfc\xca@\x1f\xdd\'\xc4a\x18\xb5\x7f\x1bG6\x85-|\xc4N\x1f>\xe8\x15>\x88s.A:\x8a@\x81\x84\xa1\x8e\r\xeb\xd5\xa0oK]\x0c\xf7\x1ecQ\xe3\xff\x83i\x0c\x01=\xfd?\xa1\xbd[\x1at\xef\xea\x94KE\x95n\xfd\x83}\x1a1J\x03j\xa7\xe4X\x91\xdf\xc7\xcd\xa7\x10\x9a\x96\xc9\x08#\xa8\t+I\x82\xb3\xf6M\xb1W!h\x86\x01\x15\xf0\xd4\x01\xac9H>3\xfa\xc9\x1cYi\xd0\x19\x06\xb3\x069\x96\xadb|\x99\xe8sh\xdfV?\xe3C8\xa9\xe9V`\xa1\x05Bv\xd7\x0e\x90j\xff$~TpT\x0bZ\xda\x87\x8a\xfd\x17\xb1\x8bm\x14ED\x8c-\xa7\xf0\x07Ze\x9a\xd0\x18\xbd\\\xcfs\xa4E\xde\x82}*j\xa4\x93g3\x82I\x87!\xda\xca(1U\t\xdf)\x8eF\xc1\xe4\xa6\x90\xa8\x1b\xb3\xaf\x11\x02\xb9\xec\x95\xd8\x91\xe5\x03\xd8.N,\x80\x0fe`\x16\x14v\xc4A\xa9\'\xee\xe1\x8a\xc0\n\xed\xc7\xc1\x82\xd9>^\xa5\x08\xeb\x9b\x16\x10\xe43f\xa2A\xfa\xc2\xd8\xb7\xa62P\x92-\x15\xde\x084{1\xf98\x1c9/T\x0c\x8c\xdd\x1a\x85\x85\x07\xd7\x18\xfa4D\xb9\x89A\xf7\xc9Xx%\xb4\xa9\x1a\x90\x97\xf7\xb2-\xba\x03\x9a\xef3=\xa1\xe5S\xfb\x1cd\x96\xe8\x99\x81\xcb\xbe\x8c\x86\xc5>\xb5\xe4\x13\xd2\x00\xcb\x14C\x86f\x04\x15\x0b\n@\xa1I\xcd\xacq\xe3E<\xdf\xae\xe1\x1e\xc6\x84j\t\r}\xf4\xe1n\x813\x8f\xb2\xf4\x06\xdcu\x1cL\xd7\xdb\xb8\x8d\xe1\xdc\x93cl\r\xc6\xb4\xf2\xf6e\xc4e\xdb\x84\x96\xa6gE\xfe\xb9\x038\x0b\xaeng\xf0Y\xe0\xc2K\x8f[\xd7\x0b\'\xda\xc2\xb3\x86\x1e\xb3\x1c\x14\xec\x9f?\xc08\xe5\x83\xcd\xd1\xa4S\xb9\x05\xd4\xf5\x10BN\x84\x950\x9c\x86@#\xb1\xd0,L\xa3a\xe4\x84P\xe6n)_\xb3\x82\xfeZ\xba\xac\x07\xbc\xda\t\xd1\x1f=\x04tb\x14N\xefye\x9d\x03\xac\xe1Z\xacv\x80-\x80\xe2\x1ez\x92\x00\x11\x87\xfb\x91F\xdbD\xe4\x9d\xf0\xa0\x82\xdd\x1f\n5\xdc\xf2`5L\x11\xd4\xd4\x15z\x08/\xb0\x9f\xf5\x10\xf7\xb3\xa6\x81\xe2\xba:\xa2\xd1\xdf\x8aU\xb9\x8d\xd2\x08XR\x04\x14\r&t,\x88Ou\x97d;\\\xcb\xc4\xcctpcI\x8d\xa4I.\xc9\xfa\x9f\xae/b>+\x88\xfa\x06\x82CB$\xcc|\xe5b@\xc3n\x9f\x8a\x86\x0e\xc49\xe4G\xfc\x08 (Vl\x93\x9b@\xab\xf4\x11\x97\xe1u=\x1b\x08\x04O\x83\xa1\x11\x1f\x12 =\xb5\xaa\xe0\xf6?\xf0t\xc6\x06\xe6meh\x9b\xe344k~\xf0PX=\xd4\x99\xdc@\t\x8b\xdd\xc7\x8dZ\x91\x16\x91\x03\xd78\x9dB\x89\xf3\'\x8eoJe\x9b\xe9\x86+x\xc4\xcce\xd8q\x91\'\xb7\x81\x90}0\x83\xec\t\xd5\xe2\xfeYF\xf0F\x1eb\xd8\x00\xbe\x1a\x901\xe7\xe9\n\xd8\x08\xb4P\x80\xe9\xe8\xfd\xe4\xfe\xcco\xb8\xff\x02\x04\xd60%\xf8\x8e\xe0\xca\xd1MR\xf16\xbam\xed\xbc\xbd\x023\n)\x1a\xcd\x1c\x84\x95\x01\x01y\xcdd\xa4\xb5\xd8\x88\xbf2~+\xd5\xe1\xd3\x9dQ\xc3\x82\xde\xf1\x93pbO\x9a\xb5\xd4\xfe\xc7!\x88\xbfh\xb6\xdc\x9f\xc9\x12\xbd\x1a\xb4\'6/d\x81\x1a#\xc33\xa3\xf59bMc$dt-\xa0\xb7\xbc1\xbf\xd2\xef\xe1A\xbb\x8a\xb5\x1b\xdc\xea\x15P:\xf1\xd4\x06d2V\xa6\xfc\xb8\xbf\xca\xbe\xeb\x9f\xbc\t\x7f\xe4\x8e$\xe1\xab\x14\x8c\xfe\xcalv\xa2\x908\xf852"kVD\xfcka)sk\xf0\x8f\xf0w\x1f\x1c\xc7\xbf\x1d4)<,\xd0\xefN\xee\x83\xc8\xb6E\xbc\xc3\xac\x99\xdaFe\xd7\xd9\x93\xaf>\xe9:\x05\x96iR\xfe\xd4\xd4\x8eJ\xc6\x11c\x1f\xcc\xf6\xe8A\x0e/\xae\x8f\xcf\xb3\xe91\x86\xf3"\xb7&N6=M\xccC\x8dn\x16&\xae;4\xeb\xfb\xb6i=\xbe8\x9f\x9a{\x80\xbfjwH\xc8iL\xbc\x9b\x08\xee\xe8E\x94\xac\x1d\xb2\x8e\xcdW"i\xe4\xee*0,\xb3\xf8/\x8b\xf99\xcdF^Bk\'\xe2\xad\x07\xf8\x92\xb6bn8\x0e\xc3\xf0\xd1\x8c\x102\xf9\xf9\xc0Q\xf9`$\xb2\x9b\xc4\xc5\xf3\xd9\xb8XR.S}\xd0\xbf\x93\xbf\x11\xe3\x8f\x80\x98\'\xab-\xddI\xc4\xec[@47WO\xc4\xe4\x05I!\xc53\x9br#\xc1x\xa7\xd0\x16f\x8f\xdf\xaa\xdf<\x98\xb9\x86\xe7Lm\xcc\xe9\xcb\x93T\x80\xd4\xdb\x1d\x18\x80\xdeJ\xa8\x7fN\x7f\x05\x80\xab\x93\xf2o\xf3\xc2\x9b\x0e\x81\x9e\xda\xa2x\xef\x99\x0c76Kh\x9c\xc9\xae\x05\xe3\x0b\xd7\xc7jd\xa5q\r\xf3V\xeafH\xabq\xd1si\x85\x1aJ\xc3\x9b_3\xb0\xc5\xe2\xb7\xfa\xc7\xa0G\xdf\xeb\xf9/\x82\x06\x1bG&\xc3.\xfdZ\xd1\xcbot\xe2[\xb5\xc8\xd4^\x9dSEkR]\x94dzZ\xd1\x08\t\xd2\x8a~1M\xf8\x82\xdfTL\\\x08\xe6\x0b\xe4I/\xdf\xef\xb0\x0c\xf0{A"\x05:\x8d\xe7\xf7?D\xf7\xa4\x91\xc4T\xa7b\xcf\xf6@\xa6\xc6\xdf\x14\xc65\x12V\xd6\x9b\xa8u\xbd\xc9\x1b\xfd\xba\xec3\x89+v~5\xc8v\xa1\xe3p\xa7\x94)\x824.X\x1d\xe5\rM\xa7\xf7\xde\xa1\xacC\xc2Up\xea\xa6\xb1\xf0H\xd1/I\x10\x9b\xb5\x97\xd0k\x9d\xc3\xec\xb9\xcfT\x00@\xaan\xdd\x02\xd7\xa87\x96\xa6\xf6\xd8!Z\xb1f\r\xdc)\x95\x81\x00\x832l&H\xc3\t7EJ\xdd\x83\x17\xcfJ\x91\x8b\x03\xffXo\x88\x00AC\x10\xa7W\xadB\xf96\xb0\xe6\x89\xf8\xa9\x1f\xdb\xabK\xaf\xdf\x95\x80$\xe3Yv\x88\xf9\xbf5\xc1\xd7\x15\xc8\x12S\xb85\x8e4\x15\xb5V\xf5\xb2\x00\xf4\xa1"\xdc\xff\x10\x95\xdd\\h3u}\x97_C\x99\x05L\x15\x82\x9fq8\xc6\xfc\xc9\xdc\x99\xceO\xb6[\x8c\xb6\x0b\x162\xbfW1c3\x9f\x89\xb4q\xed<V\x0f\xfd\xc0\xc7\x14\xb9\x93\xa2\xca\xab\x9a\xbb\xf1\x97V\x87\xe8\x1ae\xbd\xe4\xb38\x19\x17\xe3\x898\xbeL\xcc\x93{\x0b\x8b\x1a\'\xba\xc7\x1a\xf5\xb1\x0f\xe1\xc7\x96k)}\xcc\xccW\xb2K&\x98\xcfv\x1eX.\xe6\xdb\xbd\xff\x8d\x9c\xcf\x85z\x97\x96:\x8b \xa4%o\x08p\xaf\xb7\xc3e~\x94\xb6\xd1\xba\xed\xd2\xb2\'\xdf\xd9\xd9\xf4\x86\x1e\x1b9\x9b=6\x00\xbd\xeb\xa8\xe6\xc1\xcb))q\xfa?\x93\x0f\xdb;3\xea\x1cC\xd5 \xa6!\x94\xc2\xd4\x81\xfc(G\x99j\x12[akg\x06`K\xb1\t\x90lu=\xf3v\xbf\xed\xe4\xfd\xdbv\xcd\xab\xbb\xb1\xc77\x18N\xd0\xcb\xe2\xd75\x08N\x15\xa2\xf7\x04\x92\xe4\xa8\xfac?|LH*\xd4\x9a\xec*\xcc\xe0\xa8\x96\xf3\xe0\xba\xf4\x01\x92\x80\xb1N\xdb\r\x9d\xcb\xd0\xb6S8u\xcf\xf4w\x88\x9c\x7fX\xc6v{cun\xce\x12\xcf\x00\x8a\x9c\xe9\xb0:\xab\xb4n\x86\n\x8b\xce\xd0k\t\xbc\xe39\xb9\xbd\xfb|\x12\xc4@\xa53b!+K\x1b\xec?\xfa:\xb8\x7f\xb8`\x07l\xba\x1a"\xc83\x081G\x96\x91\x92\xd1!D_\xc3\xbe?\xb3v\xa8\x9brv\xf9\x8d\xd60\xc6;\x8c\x12:W\xca\x11\x83\x01|\xe6\xa6\rh\xecO6I\x82lH\xeau\xdcc\x806\xf9\xd4\x8e\x89I\xb0\x06\x9e:\x04\xbah\xb3\x963\x9a*\xfd\n\xd3\xcb\xb9\xc2\xe2)\xbf\xb1\xafU\xb1\r\xbb\xb7my\xf4\n\xfbq\x8a\xab\xa2\x8f\xd7\x06\x01\xe0\xa7>"h\xdcJ\xfc`T\xc9x\xfa\t\n\xcb4\xfc\xdd7w\xa5\x8f\xf6R\xd8\xef\xf4\xee\x17\xe2e\x81\xc0\xf3\x98\x1aq\xdb\x83\xff\x85T\xa0o\xf58\xf5\x9er\x94\xcf\xdc\xa7\xd8\xc8\x9ba\x8a$`\xdf;T\xc2\xdb\xf0\xa3v\x828C\xcd\xd6\x0ciq\x07\x14>itU\xe2x\x05\xb9r\x0fH\x91o\xda"\x949X\xba\xce9"\x9a\xfd\xf0\x14[\x15\x9eI\xf6t\xe3\x10\x8d\xe0@\x86\xb0\xf5\xdd?\xc9\xd4\xaa\xef-#e;p\n\xdc*\xfb\xf2N\xd9\xe6\xf0\x9eSc\xb8#_\xd6\xbb\xc7\x0c\x93\xb6\xe8\x8ed\xa8\xaep\xd6,\xf8\xafJf\xd9\xaf\x03\xdc[e\x05}\x12\'\x8f\x840U\xa6?\x15\xb0\x04\x1es\xcb8\x99>E\xa8\xc7b\xbe\x1a}\xa3)\xf1IGh\x82m\xaf&\xa1\xf8\x85\xdbgRy\xa65\xacY\x8a\x83\x1c=hW\xc5Gn<\xa4\x9bs\x8e\xd1\xa2@\x8d42_\xb7\x80\x13\x96s\x8f\x7f\xa9jP\x82)6P\\[zjt\x97l\xf4\xd1Z\xb1\xaeh/\x0c\xf8r.\xc7\x07[\x9f\xb1\x94&;`\x99\xb8\xd8\xeb\xa7\xfc\xba|\x91\xfbA\x86`c\xa9\xe5\x02\x9f\x1f\x1a\xc0\xea.WO\x8f\x8a\xaf\x89"\x9d)\xb0_MD\xc1!\xf9\x88OVK\xba\x00b\xbd\xcc\xdf\xe7\x19{\x7f\xd8w>\xa0\xc2\xc9\x03\x0fGS\xb1\\\xc5\xd3\xb6v*\x93\xe2vy\xfc\x1eh\xd9\x05\x9b\'&\xbe\xb7\xa9\x056\xe3D\x99O\x92\xcdcz\xc8\xac\x8f\xa0\xb3\xf5=)\x16\xfdA\x82\x97\xbe\xfb\x02\xe0\xbf\xf9\x19F\x98}x\x93\x1b\xb3_\xc9S\xd5\x16\xd5\xda\xad}R;\x19wU\xb8l\xcc\x04\x05k\xcc\xea\x05\xf7\xcd \x8c\x06l\xf1`<\x9d9J\xf0\x9a\xd1\x8e\xfc\x84\x96\xa0\xb0\xc5\x88\t\xc8\xf8!B\x97\xeaJ\x92X\x94\xd1\x81\xff$E\x91\xc7\x13\xca\xd82.\xb4A0=\x0fB\x11\xe6\xf6L=\xe1j\xc2\x8f|\xc5g\x88TT\xff\x9a\xf5^\x15`T\xbf[?O\xa3G\xdc_\x8e\x9d+D\xc22\xdf\xf5Y0,\xe7\x9b\x93\x8f\xbd\xd9\t\xd8\x12\x8f\x1d\xdfq\x94\x1bn\xd4\xa6\x87;\xf1\x12gHJ.(\x00q\x04I\x97\xc5\x02\x03\xf5\xb7Hc\xf3\xc7\xe8\xa5J-\xea7c\xc98P\xc7]\xb9\xe0\x13\x15gsk\xc51F\xc5YFrV^j\xfa\x8f\xbe*\xc47\xf1\xa9x^5\xf8rE\xefpt\xc6\xdc\xbfq\xe7\x8b\xfc\xb7i\xc7>\xf8\xdc\xa9\xce;)\x94\xdc4\xf3\x07\xe8n\xaf\xe8\x14\x13\x87\xa2t\xd5wRL\r\xdd\xc5\xd8\xb1\xd2\xb1\xc6\xab\xe1\x8d\x17\x03\x03\x00\x1a\\X\x99@\xef\x96\xfa\xbb\xf3?\x12\xc4\xc9\xd5\xe5\xd8\xeb\xec\xc0\x9b\x85\xa4\xd0\xb6\xa9\x18\x17\x03\x03@\x11i\x80"t\x07D\xbc]W\x10\x03\x12T\x9d\x12\xd1\xd5\x01\xe1\xbf5q\xb2}\x964\x19`$9\xa9\xb9\x03\x90-w\xbd\xb1\x80\xbe\xc3\xf8\xd9a\x98\xae2\xa8\xcb2\xaf\x03\x8e\x0e\xc1O\x10\x07\x08\x18+\x175\x01\x08D\xe1|\x968\xa7\xb3\xf1gn\xddl\xe7\xca\x970[e\x0e\\j\xfcI\x1e\x90mbwut\xc3H\x1d`\xc5[1\xa0P`\xc5,J\xd4\xef\xa9<\x9f\x03/3\x8e\xb4/\xed\xae ee\xae\xb2\xf1"\xb2<\x84\xa8\x0f\xaa\xa7\x99\xad\x04\xfa\x0c6\x95\xeb\x08\'\x97\x1bm\x85\x82\xfa\x1f\xa7?\xce\xab\x89\xe7\xe6sw\xbe/\xd7\xac\xe5\xc1\xd2H\xd1\xe79"fz\xf8\xcd\x05\x9a\xd97\x8a\x98\x1a\x84\xa8\xbd\xf0\xbd\x81\xf4\x99>mV\xd5\x8e3\xd5u\xc8Si5\xef\n~\x943g6\xaf^\xf3\xa0orzC\xfb\xfe]\x87\'\x15i\xd5}I\x7f\xf3\xccA\xe3\xd4\x08\xd65y\xc3\xae\x83\xbb\x82z\xe6l\xda\xc1\\\x8at\xa2DG\x9c;d\xac"\xa4a\xd5\xd4\xbb\xcd[\xb5\x03?Z\x90D\xf9\x01\xe0\xc6f\x1eJu\x9e\x98\xd0\xdc\x1d5\xbc\xb8\x8a\n\xed\xe9\xd7)\xff\xf3\x0cb\xb1\xf4`\x7f?\x1fdD\xf2Q\xb1[\xd9D\xb3@\xe4E\xe7\xd5jc\xc1-D\xed\x0f\xe2|3>\x8e>N\xb1\x8b\x9e\xd9w\xd8\xd7\xb6\xbb?\xab\x8f\xf1\xeb\x16x\x02[\xfc\xd4c$>\xf6\xe6 {\xb1|\r\xaf\xd7\xd1\x1a\xbf&\xd4\x87\xdbG0\x9a\x92}K2\xd0\xff\xa3Y\xc2+\xb7T\xe2\x910;xT\xab\x97\xfem\x8a\x83r\xcd\xd9\xf9vH\xcc\xf4y\x98\x11\xe1Qy\xe2G\x99"\xd4\x17\xa7Cv\xfc\x9f\x0815{P?OF\x96C\xa6`\x02\\\xa4\x08\xe2\xc5$\xb2\x88\xf1\xb6\x01f\x8f\xf3+}\xcd\xe8v|\x13\t\xa9\t|\x83\x1d\xc0\x89@\xca-\x02D\x0b\xbeA\xcct\xd6\x01\x19U\xbb\xd8\xff\\\xe0G\x07(`&\xc9I\x99\xcb\x06\xfe\xea\xc6\xb8\xe0\xfb_!|\xf1\x9f\x94\x99\xcd\x11V9\x89Y\xcc\x1b\x14\x97|wC\x9b\x05\x9b\x98`&\'\x05\xccKV\xe6\x942\xb9\x94-\xdax6\xbb%\t\xe5<Y\xed#\xc3h\xefE*\xf6\xbf\xaaaqF\xcb\xb1d\x93\xfd\t\x06Lc\xab\xcf\xf7\x8c\x11\x85\x9a\x12\xbc\x05\x8a\xb5\xa4\x05\x02`\xd0b\x04f\x82B\x82\xfe\xe81%\xc0\xa3"\x9d\xa3?\'\xe9\x91\xa8.=\xef\xb6\xf7\x17z\xebF.[Rg\xd6n\xf3\x04\xbc\xf9Z8\xd3Y\xc6\xf3\xa5\xae\xf4\xa1\xbd\x90\xde\xe6\x96\xf4R(,w,\x9d\xfe< \xb2\x86\x11\x9e\xa0\xb4\xf4%(K\x94\x94d\xe9\xc8\x8e\xfb\x96\x84_\xad\xa4xAH\xe2\xe9ao\xad\x14ZI\x14C\xc6\xf4\x04\x02\xf5]9\xda\xaf\xf6QD{\xed\x022\xdc. \xc0`wj\xe9\x15$\x99\x7f\xb2qn\xba81\xfe\xd3Z\x01\x10\x9c\xc7l\xbd\xda_J-}\xaaK&\x1d\xe3e\r\x1d\xff\x8dH)\x14\x86\xe2q\xcc\xca\x04\xdblK\x9d\x95Y]\xd1\xf3v\x95k\x08<t?\xe45\x07\x8e\x1d\xaa\xbc\xe5\xab\x1caK\xba\x96\xa3!gS\x0b\xb3x\'\x0f\xe4\xec\x88h\xc4\x1e\x8c\x00\\z\xf9]s?z\xad3\xbc\x13\x9aiFZ\xf5v\xabcA\x93u\xc9f\x88\x1d&\x17\xed,:oO9\xaf\xf4\xe3\x8eC\x12@K9\x8f\xc2/\x85$\x17\x9f\x1bKf\x15A\xad\xd8-\xf0\\\xe4\xb9\x0cHh\x8dCv\xa2\xb3\xba\x81be0\xfd\x05\xac\x06\xfaux\xbe\xfdsY\x91ra\x90\x94\xd7\xd9b\xbb\xb0NNt\xcf\x16\xf7\xc8\xbe\xc3N\xf4\'7\x87\xbav\xd2\xd1T\x12X\x1c\xb2\x0c]\xec\x8f@\xa1\xeb\xfd\xee\x9d\xcb\xe1\x1f:\xac\xad\\G\x0e\x14\x9cq\xf4g\xc9\x9b\x08\x97c90X\x15\x87\'|\x92\xab\xe7\x06\xfd&\n/\x85\x89\xd1$)\xa6\xc7\x9b\xe4\xa4L\xaaT9\xc2,\xf92\xdf\xa3\xef\xcb\xfax\xa9\xed\x0e\xc6*\xf0\xe0\xd4V\xb8\xbe\x9aK\xd1\x88/\xdbrN\x9d\x0c3\x96f4Y\xdfE\xc9\xa4\x95*\x9bV\xb5]lg\xdc\xdbH\x8f9U\x99\xe6r\xc2\x82$\xcaB\x07\xf9@\x9fx08\x914\xe1\xdf;\x92\xf0\xa3\x8e/\xd8=\xf8\x13u\xc9\x15C\xdb\xbc\xee]fy\x19x\x9a\x83\x1127\xa0\xa7b\xb0q\x87\xdaM"\xf1\x8f]\x9f`I\xb0\x00\x1e=\xfd\xe8\xbf\xd9\xa7\x8a\xa0\x90\x98\xb9e\xe8\x89\x7f\xecXp\xa7_uo\x9a\x12\xc2\x92z\xf9\x0c\xfe+\x0f\x03\xaf4/\x82\xea\xc9H\xdb\xaeJ\xac\x9a\xde\xf5\x85\x01\xc6{\x9e\x19n\x1b`M/i\xf5e\xd9.\xd0|\x94\xb7\xb4\xc7\x96\xe2\xbf\xb3zGQ\xdf\xb4\xfb\x8c_(\xd5\x81\x82s\x8f\xac\xfa3w\xa8V\xa2\xce_\\3D\xe0%\xb4\x03\xa4\x19\xd2,xe \xaa\xa9\xae\xac\x7f\x01\xbe\x08`\xfc\x91B\xb4#z\x8f\xee\xfd\x11`K\x02\x10SY\x96\x9dW\xee\x11>\x13\x88\xbd\x0fV\x9a\x06\xe9\xea\x18\x85\x86-\x18\x1e\xfc\'\'\x9a\xa6kI\xb8/\xb2\xeaz\xa8;\xb1\x1c\xb3\xf5\xb0\xc1\x16\xa3O;r\xf0\xd1\xfey\t\xecy\x90\xd1A?\x98aO\x8e\'L\xa0\x98\xc8\x9a=B\x17@\x99t\x1b:\xc8\xd81\xe3\xd7\xccC\xaa\xa0 \xe1\xa2c\xca#4\xb7\x19^\xe8)\x8c\xb2\xac\x86\xa6l\xb4\xd8\xa2h\xb2\x91\x8b\xdcVnV;`\xf6Y\x11\xc4ic\xd6\xe4\xae\xd7\xb8\xcfvwN\xcd\xd5\x9c\\"+X\xe6\xd2%a\n\x85&\xde\x0b\xb7\x8d\x8ex4w=En\x8d\x93\x95S~\xaf\xae#\x90x\x9e5\x86\xc2I\x851Z\x0e\xefx\xfb\xc1K$p\xe7\xc1=d\x85\x89\x0cIc3`\xd7a\xb0\xbb\xcatO\x1ex\xcf-PQ\xe165\xcf\t\rp\xb2k\xe0yK\x98\xe6\x80\x18\xae\xcd\xd0\xa3^\x82\xa83\xd8\x8f(.o;Q\xd8E*\xc0\x8d:_!V~1C\xaf\xd7\x8a|\xd7\xbb\xfe:\x95!\xf1\x12cb\x10\xd7\xd4\x8f\xc56(M\xbb\xe8\xed$\xb00@wD\nx\xea\x9al\xda`0\x97\xca\x9eT\x8e\xf8lU\x93\xfb\xed\xc1\x16\xda\xe3\xe4\x9e\xdd\xfc\x850\xd2\xe56~\x85\xba\n#\r\xa3e\x9ce\xdcx\xce\xce\xdf\xe1\x16^\x1c\xec\x9a\xe7\xdf\xf1\x16\xac\x9fr\xb8\xa9\xa6]d1;\xa7\x82\xec\xdbVu\xceH\xd58J\ry\x9b\x1f\xf3\x18\xf2\x8fz%R\xb4lz\x83uG\x8a\xd8\xb5\xcf\xaf\xf6\x82\x06\x15m{nTM\xed{\x0f\x1b{\xe05T\xcbdx\xb0\xdb\x9b\xb8\x90<\x16\xf8\x8a\xd8\xbbpS\xfb\xdf\xc0Y\xf6\xa7\x98"\x90\xb1\xce\xa0&>\xce=\x103\x8cu\x05\x10mY\xb4\xfbEa\xf43>\xf8y\xc0\x1dPa\x91\xc4\xb2T)5x\xe70C\'\xf9\x89\xcd\xa7\x9cQM\xb6\xc2\xe7\xa9M|\x9bc\xc8Q\x15BIbf pv\xb9\x9e\x0f\xa0E!\x91\xfa\xe9<\x1e\xad2\x8b \x80\x12\xdd*\ryw\xe2\xda3`\xf0\x8c\x94FQw\xe0A\xe4I\xd4\x12\x0e~s\x11}Z%z\x88\xf6\xc5\x17\x08\xf1,\x9dX\xfe\xeb\xc7uj<-\x93,\xd7\x8f\xe0\xd5\xde\xd2\xbeu%r\x8a":K\x94\xadVG\xa5b;\x83\xa9*)\xec\xdc\xda\xa9R\xd6\x91h\x92\x9e\x9a\xa3b\xe0\xabj:\x0f\xf2\\\x00gr\xdft\xb3+\xa1s\xfe\x16j\x18<w\xca\xa5|\xb1\xd7p\xb6\xd3J_w\xf6\xa6p\x0e\x9a\xc7\x04\xa7\xb0\xa4%\x8f\xe6\x0f\xae\xbc\xca\xb2\x05\x9f\xcdJo\x7f\xee\xe4\x8c!\x91\x13\x14\x06\x06iU\x87\xdd5K"\xb1&\xddZ\x1d\xe3OM/[\xb7\xee.9s^\xd7\x08:\xc8\xa5l$\xd0:}\xb9\x16Od^\xe6\x9f\xd5\xbc\x91\x1f\xabdkn\x1b\xa2+#\x82f\xea\xc2\x9b9k ^\xd7\xbf\xee\xaf\x99\xe0\xd4K\xc6\xf4r\xadI\\\xec\xcf\xc2\t\x82L\x81%\x82\x1e\xce\x8a[\xdci\x82\x8b\xc4\x19\x89\x9fKX\xf0\xcb\xd7\xb9\x07\xf0m\xb6\xb9\xe4%\xf4K5\xa8\xc9\xde]L\x8e\xfa\xc0G6\xf7\x83\x96\xa4p1]\x01\xf3\xed\x00\x0b\xd8\x1a\xc3iA\x97\xb2:\xf1\x81K\xd00\x85\x19\x1b\xb8;2\xa6f\xc3\xf5\x02\x802p\xc7\xe9Y\x9f)\xf1\x0f\xa4\xb3U\xf0q\xef\xfe\xa7\xc5\xe4\r\x83^!\xfeBV\x02h\xdc\x18~\xe1\xaa\rH\xbd\xc8mI\x9a\xf8\x17(j\xccK!\xa0!\x08;\r\x84\x9f\xe6u&\xe5hi\xf2x\x90\xde\x83<(\x0c\xd0q\xde\x19iHP\x01\x0e\xbc\xd8\xa24\x10\xafv\x83|\xd5\xbd\x11b\xcf9\xdes\x97P};\x97`\xec\xb7\xe3\xf5\xd0\x15\xefz?x\x10\\~\xed\x9a+\xe4a\xa5@'
|
|
|
|
|
|
2024-12-14 17:54:48.165267 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40821 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 17087
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x3b8b
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40821
|
|
seq = 2746219139
|
|
ack = 373744520
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1041
|
|
chksum = 0xad0a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:48.169560 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40821 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 17088
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x3b8a
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40821
|
|
seq = 2746219139
|
|
ack = 373744559
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1041
|
|
chksum = 0xace3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:48.172894 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40821 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 17089
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x3b62
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40821
|
|
seq = 2746219139
|
|
ack = 373744559
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1041
|
|
chksum = 0x4fcf
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\xab\x16\xdf\x1f\xac\xcb\x03\xd5\xedn\x89\t\xa1y\xb5|\xf3/#w\xf2\xde\xb0\xcfpO\'8Z!\xa8\x85\x85V'
|
|
|
|
|
|
2024-12-14 17:54:48.176203 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25558
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808805349
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.183999 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 2960
|
|
id = 47911
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf8
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808805349
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'<\x17o\xad$\xb4M\x89\xb5\xbbj\xe5\x8b\x9a\xd6\x82\xb9\x8c\xd4\x11=ND\x85\xfe\xbcu\xff\x03\xf6\x03\x961\x8f/\xae\x8b\xdfd\x19\n$=\xdf\xd1\xb9#\x10 \xdb\xed\x8by/\x0bo$\xfe\xa3c5\x9c\xd5*\xfa#\xdd[\x9bQG?u\xcf\xb9]\xb7\xb9/\x00\x80\xbc\x97\xec\x80\x89\x11\x06\xc4\xd8\x12\x9ac\xa7O\xfbL\x9f\xf6y\xb3\n\xd2\x07[\xe0\x11\x0ey\x1c\xb8{\x9dfE\xa4\'>\xf3J\xc8\x94\x1c3\xe1\xaf\x8b}\xbdpk\xfe\xe0g\xd5\xf8W\xd8z\xf2I\x15\\\x06\xb0\x1cj\xaf\xb1Qw\x1a\xcd\xd7Rv\xf3\xde\x12\x19\x00Rm\x17\xd4\xae\x94o\xdb\xc3\xf5\x1ew\x97\xfe\xdb\x82y$[U\xfc7\xc1c[\x88\xc5\x1bp\x19^f\xf5\x16\xfe\xb7\xa7\x01rQ\x91LOa\xc0\x0f}9\'\n\x898,e\x9e?\xe3\x1d\xb3\x91\x00\x0b\x14G1P\x9e|\xbe\xd8\x94\xa58\x97\xfdC\xee|\x109\xef\xe4\xb1#a\x06\xca\xf6\x1f\xf8\xd25\xdb#k!(\xec\x92\x08\xe4\xa3%\x08\xdb\xd39x\\\x8fm\xb0\xe2;3D\xe7\xa0!\x9b|\xc2=\x13\xcc\x00\x19\xa6\xdc\xe1\xfe\x92\xf7\xddM\x9bJU\x92\x90$4\xfd/\xe2\x1a"n\x97\x11*m\xb40\x03=\x83\xc9\xd6\x8e\xd3U\xcaEF\x11Y\x98\xcf\xf3h\xf5\x9f\x080\x84G\x81\x069\xc3\xe4\xf5+!\x7f\xbd\x93\xfa\xc3\x86\xcd\xb4L\xe65\x18X\x8e\xe7=\x97^\x9c2\xd8b-\x19\x94i\xc5\x8fl\xc8o\x13\xcf\xb5\xa9\xdd\x83\x85\xce\xe2\xba\xcc\xb0]D\x9c\\\xbf\xfa\xc3\xba\xfdX\xfe\xf8o\xca\x04\x1bB\xf3W\xb7\x93\xf0\xc5\xa3\xd2\x9fs(\x03\x07\r0G\x82\x83/X\xe7{\x19\xd3\x12c\x83Z402rd\xbaN\xf3\rU;\xba\xbb+\xe6\x85O\xc7\xda\xce\xaa1\xf1\xbbT\x0c\x9d\x0f\xaaN\xa8\'~\x9c\xaeF\xac\x03\xb4J\xa5$\x9b\xdb#\x06\xec\x16t{9\xeb\xcb\xfa\x7f\xe8\xcd\x8a\nMB\xb6\x18\xa5\xf6\x07\xaek\x8e\xf3\xaf\x01(\xccF@\x1d\x08\xf4q>K\xa1\xffz\x8c\x12}X\x82;,P\x14\xf2\xff\x95\x8c`\xb5o\x1cP6\xde>U\x88c\x9b&\x1d\xb4r9`4a\\\xc8x\xebO\xbd\x08\xa2\xc1(\xe4V<\x1b\xe6\xe4:\xf4b\xd9\xe2\x95/\x02\x1bu\x9c-\x00o\x01f\xe7C\xd0\x81\xf0\xd6~\x9a\x9d\x92\xff\tp\x99\t\xe5[P\xaa@\x83\xed\xa1\x9e\xfb\x97\x87\xfc\'\xeb`\x03\xc8>\xb6\n~9\x92\xcf/\x93\xd5\xf7\xa1\xa7r\x97\x94\xe4\x81C\x8f \x97\x01\'\xc8\xac\xdc\x9b\xda\xe8\xbf*T\xf21q\x98\xc0\xa9M\xba\xea@q`(-\x88\xb7+\xaaJv\xcd\x18\xf4l\xc7Q\xbcN\xcd\xb7\xe1\xb3\xf6VO\\\xd4\xc3\x1d\x8a\x97\xfdx\xba\xa6_^\x00"i\xed\xc1\xb0\x13\xf1\t&-\x93\x8b\xcdL,0\x1dI\x07d+\xc6\x86\x9ae\xad\x81&\x89w\x89\xa1\xc7=\x93\x8a\xa1\x7f\x13.P\'\xb1\xd7M\x89MaZ\xd5N\xda\x8eS\xbcT\'\x816\xdd/\x94\xf9*\x89\'\x91\x96x\x89k\xdcf\x97$\x1e\xac\x1b;$|\xd2\x8eO=hl\x88\x188\xb2^\x97\x9ex \xee\xcf\x17\xbd\xe2\xce\xaa\xc9\xb5I\xbc\xa0J\xd4m\xbc\xa6F\x19\xab\xfc\xf9\xb9\xe89\x84@\xbc\x1c6V\xcb6\x04\xdf\xe3\xfc>y\xe8\xc6\x12(W\xa5\xfa\xf1\xa26b\xd8\xb0\x1b#\xd3\x92\x1d\x87\x12[\x19J}b \n\x15\x99h\x95<\xb0\xfe\xd4\x926\x93j\xe4$\xb4"p9GW\xd0\xd60\x98f\xe7\xfa\xf9\xbb\xdb?\xf4\xadQbSH\xb8\xf7m\x96\x9ft\xab\x9b\xf6\xb3\xc1V\xdd\xe1\x98\x9a\xbb:t\x90\'\x1d\xc8/$\xc5\xcc\x18\xd6\xb87\xb2(\x86K\xbe\xdc\xa1\x0c\xb4\xd2>8o\x9c\xcd\x91\xff\xed:\xd2\x07\x96\x82Oa\xba=\t\x82\x18\xe0\xbd\x02;\xe3\xcd\x13e\xf7\x9ec\xf8\xa9bG\xa6j>G\xba\x1c>\x8b\xd7\xb1\x16LD&:\x89\xcc=\r\x1c\x88;<\xc4\x19\x03K\xd9\xfd<\xb0\xa9\x81\xbb\x88\xab\xc4\xecs<\x99\xe0\xaf \xc3\xcf\xd6.\x96\xec\x11\xe5"/\xb3\xd96\xea]\xf6S\x85\x069\x89M\xe9\xff]\x02\xb5Z\xe4\xf4\x9b\xd4\xda\x94p2\xb2\x1eL\xb1\x97\x0b\x02\x878C"s\x86\x9fk\xdau\xef\xf1#\x17|\xe0\x86\xca\xa5\xec\x00`\xca\xd0\xd3!\xe5\xe1\xde\xe8\xfe$#9m\x0fw\x95\x11\xbfSYJ;\xb6\x9aK=\xb0\xef\xcb&\xaa\x95\xfcN\x08\x80JJu\xe1\xbf\xdb\xb6\x83\x81\x85\xba]tH\xd8b\x8f\xeaV\x92\xf6\x89\x827\x1c\x97\x18@\xcb\x1bq\xc4s\xd3\xea\xd2\x0b\xd7\x88\x88\x07\\O\x8a\x9a\x97\xbf\xe3p\xcd6=@\xd6\xc8\xc6\xec\x1b\x1e\xbe=\xea\xfbt\xec\xfa\x9dp\xd8\x91\xb6w\xf3C\xc0\xfc\x0e\x04\xcd\x87\xcb\x16E\x02\x80\xec\x0c\xb3\xc8\x7f\xd6\xcc\x1f|\\\x83\xdfx\xd2\x18\xbc7+\r\xb6\xdcMd\xac%\xfd\x86\x8c\xb8t0\x1a\x8a\x9aE\xbd"\xdf\x08"\xfa\n4_Cf]\xf39\xffx\xe0\xb0t:1\x11B*\xed:\xa8\xcc\xb1\xa5\xd6\xa2\xe6\x92\xbd\xd5\xe3\xbf\xbe\xc4\xde\x07\xd4\xc7\x85\xb1\xcaZJ\xf7\xea\x88\xf76"\x08\xb7\xbeFTG\xf3\x81\x0c\xc1\xd5@\x86\x9a3\xdb\xa5\'\xef\x08\x9e4\xc4UNp4?\xfe\n3\x9f\xe4\xb6\xdd\xadA\xfb.e,Ff\xb0\xa4U\x8f\\\n4\xb6Y,\x97\xa1?\xce\xbd\xe9:\x8c\x1e\xd6\x167\xcd\x12\x84Yw\xfd(\xdf\'\xd3 \xdb\xbc\x9cc0\xcbL\x1a\xd2m\xe6\xdd\xf2\x91\x8a\xe4Z\x1bk\xe08\xac\xed\x8bimg|\xf1\x13\x179\xc6l~Q(\xc8\xbc\x14+\xf0\x83\xb2\x82\xdc\xecn\x04\xde\x19\x83%.c;\xeb\xf0\xc3\x86\x8cN}\xe4\x0e \x18g\xf8\xc8-\x11\xb8\xadlQ\x96@^"o\xd0\x00\xc19H\xc8\xd7\r\xb5\xb7Bd\t\xd3\x19(\x88\xc6O\xadt\xae\x1a\xdfT\xc75\xb4Nm\xf5\x1c\x13\xebx&Zz\x01\xe8A+V\xca\xc3Y\xd9\x94#\xd3\x98\x11\xb8>\x9c\xfcnW\xb2\xcag}\x86\xa9\xd6\x01\x9e\xcf\xfeL2\x93\xf1\xe4E\xf5\xd9\xde\x1c\xa0\xf5F\x1aY]\x19,=\xc4}\xa2\x83\xb89\x00\xea\xba\xd8*\xd4\xe3g\x13\x95\xec%\xb7\xa4\xa0\x12\xef\xdb\xe6\xdc$\x07\x10\xb1\xc2\xa9m\x01\x0e\xc1I\xa72\xee\xde\x14f\xaa; \n\xdc\xb5%x\x83\xba\xf6\x9c\x9cu\xeb\'\xf1_\xf1\tiH\x86\xd7)6\n\xbd\xcb\xcb\x9fbVMFD\xec\xbf(\xbc+\xb3I\x87b\xa7\x81h \xc1\xeb\xb4\xb00D\x84\xab7\x8e\xa8\xeb\xf0\xcf\xd6\xda\xad\x96\x064\x83m\xf9^\x03\xa6\x02\xce\x81G\x16\xd1\x1b\x1e}\xa4\xc2\xf7\x040\x03\xa83\x17\x05\xf7t\xb3\x88:\x00_p\x85hu\xe2)&\xd3S\xfc\xa9u\xa0x\xb5y\xbe\xa8+e]\x80t\xbd\nOM\xc8\x16\xa6X\x10\xd3\xbd\xaf\x99\x11\xe5\xb7\tExP\xcfH\xc6\x04\xe5\xbb.\x9cb\xbf\x84\x96\x0e\x7fNl\x86.C\xb8\xf0\x1f\xaf\xda\xf8\x90~`\xbf\x86\x10{\x05\x83\x00u\xbf\x03y\x01i\xe6\x1b\xf5%l]a\x18\xcc~\xbfh\x9f\xac\x9aV\'t\xbe)EA\xa8\xedn\x03\x8f\xee\xe6\xe8dJ\xdc\xb0\x82\xf5\xde ]D*\xc5\xb80\x80\xc7%\xd0m\x12\xcc\xbd\xfd&x\xd3\x82\xb1z\xf8\xdf\x0bP\xff\xa8\xfc\x0eY\x14\xea\x08\xd5\xdf\x8a\xb9\x8f\x08\xfe\xedG\xb6;\xd3\x07\xef\xd6\xafL\x8d\xd1,\x02\xae2\r\x00\xe5\xf9Fj\xa43\xe6F\xd1\x12|\nF\xd0\xe7\xc9)\x19\xbc\x83)\xa4K\x07(E\xf7\xc9\xe9\x0f\xda\x05J\xac\xce\xb3%\x9f\xf0:0\xfd\xfa;U\x8bv%\x99,\xe3\x8b$:\x1924\xeex\xb1\xccL\xcc\xd0\x8f\xa1\xaa\x84\x06\x8fr<%\x8f\xb3\xfd\xac3\xc7\x82\xe58x\x7f7\x90A[\xda]\x89\x8fN\xffTp\x19?\x9d\x9fJ\x16\xad%\xdcX{\xdc\x14\xd1\xc7\x1b\x7f\x808\xfe\xcc\x91u_(\xf6\xbfw(@\x05k\xc1\\\xa3L\xf3-\xc2\xa1\xe4\xf6\xff3A\x97\xc7\x85\xa1\x82\x83!\xaen\x9c\x8cG_\x92|\tc\x92C5LB".`\x93\xcf5\xea?\xc2\xc0W>f\x93\xe01\x9b\x87\x8b3\x06\xc3DI\x0e\'\xffd\r\xf7\xdf$\xad\xc8\xef\xda\x97\xdbuAB\xbc\x83D\xd9G\x82"\x1b)\xca4\xdd\x1f\x87\x97\xea\xe7\xe5\xc1k[\x80;\xbd\xf8\x93\xce,\x12I."\xb3\x1df\x94o\x9e%\xcc\xcf\xee\x0e\x12\x88\xec\t\xc3]y\xca\x1c\xfe\xd5~\xd6\xf0\xf9\xf1\xfc\xd3\xbf\xed\xe4~\xa5C\x06`N\r@\x1fm\xea\xf6\x16\x82\xba)\xcd0VyG\xbd\xcc.a\xf8\xbe\xaffd\xa7.] \xea\x05%\xa7e\xdeh\x02\xe6.\xfd\xcb5aK\xd3\xe2\xdf\r9\xbb\xf0p\xbdM\x87Fz\xdd\x80\x04\xfc\xb5?\x83\x16\x82\x94\x08\xf7u\x92\xbf\x8e"\xa4\xb1\xc7\xe7k\xcc\xd1\x19\xd4\x8c\xdf\x12\xa6\xf4G.\xaa\x99\xf2m|\xa0\\\xe4\x88x\x9a\xcd\xeb\xf3\x16\xce\xa8\xf0\xc8\xd8\x97\x17\xfe\xf5,\xc5\x80DQ/\xfb\xe7o\xd7:\x02\x13Q\xf4I\x97\xc7\x90~\xd9\xc1\x1b\x82\x87\xf7\x1c\xe8\xfd\x04\x8b[\xf4\xcf\x1b\xc3\x03\x14\xd2\xbe\x8f\top\xaf\xab\xe0\xfdw\xafD\xd84\x06i\xee\x89\xa5@M5\xb1t\x1c\\\xa2\xfd\xd7}c2\xde\xc2\xd6\xc2w\x9c\x13v\xfbd\xcdPYS\xdapV\x84\xaaV\xf6#\x14\x15\xae\x19\xc2\xa8C\x89\xdd=\xbe\xbc\x8cSbz\x15R+^\x1aD~\xe3\xa6\xcf\xd2\x98\x89\x83\xad\xe6/ $\xa0Z\xbe\x04q:\xa8\x12\x01&\xf7\x97\x04#\xaa\x1e=b\xd6\xddP\xfb\xb6\xfa\xc2\xb5\xa4#\x18\xc2t\xc0\x02J\x1b\x00l\xaby>S\xca\xcf\xe6\xad\x9a\xe6\xba\x08\x15\xdb\x11\x15\x04\xe1\x9d\x05\'\xb8\xefE\xa1rG\xc2gA\xef\xf2\x12\xc1\x1f\xb4\x04x\xd1g\x9e"\xad\t\x14\xe8\x16\x97\xd5\xf3\x0bf\x84(hw\xc7\x93\xc4E\x11\x13[q\xa5xP\xf0\xf6\xfc\xeb\x87\x03\xb6Mh\x05\x88\xc1\x9cQ\x81\xcc\xed.\xbeguD\x9f\xe0A\xd7\xf4\xe8\x13_sX\xf3h\xd7\xb7lJ\x15]\x84\xdb\xecN\x98\x07\xdf@\xdeg\x81?\xff\xed\x00\xfd\xae\x06\x185\xff\x1c\xe0r\xd27\taE\xd3^\x05\x14\xc5\x1b\xed\xf6\x81\xa7pB0\xc3\xac\xc1\x03\x01%\xe4\xfc\xfa+\xc2o\xd6e\x9f\x0c\xf9\xc5\xe6\xbau\xbf\xdb8\xc9\x14*\xe6\xac,V\xeca\xf7\x10\xb3\x9f\x10\xfa\x83[1qFl\xa6\x85\xe2Vi>c\x99tL\xaf\xcan\xc8V,\x10\x02\x0f\xdaC\x87\x93\r\x89\xf5F\xcd=\x02\x8aMS-N\xb9\xbbCG\xfb\xd7\x8b\x9f\xd8\xd5\xeb\xaba\xfax\xc1\xddg\x94\x88\x03O\xa8\x8f\x01\xcb-\xfc8"\x03f\xc5\'\xc3o\x83\xb1\x97%B&|f\xee\x15\x850\x18\xee\x8e@K\x11uC\xe5\'(3L\xf0\x93\xde\xb2\xfe\x9f\x9a\x8c/~k\x16\'\xa2[\xf3\xf0\x18\x86N\x8f\xda\xbe\x8b\xa5\x0e\xa1\xff\xd0\x95~\x9b\xf3\x9d`\x16\x89\xfd]uD\xa5\xe2\x03n\x7f\x18m\x96\xeeq\r\xc8\x1bs@f\xcd\x8e8\x86\xef\x16F\x956\\\xb9Y\x00\xe5\xfc\xef)\x1bE\xeda?\xebW\xdb\xa8\xce\xdb\xf3\xa6\x18F\xf0\xf47\x01\xf4\x15\xf2\xda\xe9\x9bm\xcc\x88t=\xe9\xd8@\xa7\xa79\xa7-\xbfXp?r.\xe1\xb4|~,{q\x02\x0bZO\xaf\x1a\x93\xb2\xfcZ\x9e4p\n4b\\\x1b\x06\xbds \\\x85s\x03A\xc2\x80\x0e\x8a\xf9\x8f\xa8\xe7\xed}\xcf\x05D)\x0c\x89\x11\xb2\x1b\xd9U\'\xb4\xa5`\xed\xdd\x1eh\xb8\xc7\xfc4\xf9\x9fu\x8c\xf33\xb0\xb8efx\xaa\xc3X&jE`\x86\xed\xe1s\xd5\x86F\xfa\x9f\xddz,W'
|
|
|
|
|
|
2024-12-14 17:54:48.187194 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40821 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 17090
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x3b88
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40821
|
|
seq = 2746219178
|
|
ack = 373748795
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1025
|
|
chksum = 0x9c40
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:48.195735 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 2960
|
|
id = 47913
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf6
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808808269
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'-\x7ff\xb3\xb9\x11\xf5\xfa\xd2\xdf\xe1\xcc\x9e\x13\tz\xea`45f\xbf\xa2\xef\x80(n\x95\xccI\x08\x7f\xa3U\xbfh\\\x07\xaf>o/,\xb4\xf1\xdc\x1f\xc4\xed\xaa\r1\x80\x0c\xc0Z"\xd9\x18\x90`\xdd\xa0\x17\x89\\\x08\xa8\xdd\x16\x14\x07\x87\xda\x93\xec\xa8:\xd7\xc4F\xe8\xce\xd57\xd8\xab\x9bY\x95z\xa4\xd9\x92\x98/\x80(\xa4\x91C@\xf2n\xe9\xf0\xeb\xeb{Pl\xfb\xe8)\xd2|\xf0\xc6\xe3\x94\xa95\xcd\x9d\x97J%\xb8\xee\xcc\x1b\xb9\xea\x8b4\x01\xf4*z\x9c[\xa7\xf8\x86\xf4\xbf\xfbZ)f\xedUy\x17\xb52\xdf\x02\r\xf6\xe9\x15L3\xe5=\x8ae\xb6\xa8\x16xF\x17\xfa-\x92\xefU\xf9\xb0\xd4\x00$1h\x1bV\xb9=\xea?\xf5\x97\xef\xce\x1cWr\xa8\xe13\xcfT\xf4_Fj!\x0f\x86\x08R\x03v\x8e\xf9H\x9d\xdb:q\x8a+\x8fgo\x9f<\x8d8!\xe9\x04F\xde\xbe\x03\x03\x0f\x87\xb2\xfcq\xdc\xaa\xdd\x06\x89\xc6z\x8c\x11\xdb\xa4\x9a\xder4\xd8\xec\xee\x99\xaf\x92-*\xd6i\x12\x89\x11*\x95\xbd\xc4\xb2@\xb2\x1c\xa7\xf1\x07\xbe\xa3\xf5gDZ\xa9\xa33C}\xed\xd3\x80\x0f^b\xb5<41\xb0r\xdd}\x01\x80L\n\xc6*\t8@\xe1\x0cLb\x95\ri\x91w\xa8S\xd1R%\x92)\xfe\xee\xe7\x85\xb7\x8b\xed\xa3\xb7%\x18\x0e\xea\xab+\xe4\x8e\xbb \xa5\xcd\xf1\xd9\xa8\xbf\x066T\xa5\xfa\x96\x08\xce\xebGP\xe3-Gm\xe0\xe71\x91%\x8c\xb3\x10\xe3\xaf\x1a24.ds\xe4+\x8d\x98\x95Z@a\xeb\xc3\x95\x997\x82A\xd2\xe8\xcd\xa7H(\xaf\xcd\\Av\xf8I{\x8d\x0ch\xcbU\xec\xd84z\xef\x1d\xa7:V\x99,t7\x95pgv\xe6,Tx\xe9\xb9\x95"b.\xceX\xab\xa8\x98I\xf6\xbe\xd3\xd0\x9eGr\x19a`\xbc>\xed\xdd\xf5D\xc2#D\xdf\x0b\x96\xe4\x05k\xc6\xf1\xb7\xb8\xae/\r\xc6\xb9\xe2[\xe0c\xf3\xdba\x05\x063?\x15\xe3/h\x1e\xc0u4\x04~I\x9d\x1f\xd5\x9e\x91lT\xad\xda\xd2\xd3\xc2;:\xe2Y\x801\xfc\x8b\xad\xe9\xf0pLN\xd1ky\x97`u\xba\xbf\xd19\xaa\xe3r^\xcb\xcc\xdf\xfcy<\xfe(\xfb\xb51o3B\x11\'s\x08$}\xa9}w&0G\x07\x8a\xf0\xcb\xb7}\xfb`Ac\xeb\xea\xd4nR\x8c\xd2\x10\xc3\\\xb72\xc8B\xb9\xe5B\x9ab\xb7\x03L\xed(K\xcf\x08\xf5:`\xc6\'\xd4;\xcb\xbc\xd1\xe6\xd5\xa0\xc8T\xf7\xd3\xbbH\xe6\xc5U\xce8\xb6D\x04\xaf\xeb\x81\xe9V\xab\xae\xa2\x7f%\xa9\x9d\xfc\xc5;dwyN\xf3*\xc2\xe9o:\xcdf\x03kx7sq\xa7\x1d\xc4\xae\x01\xec\xb8|\xb0\x0f\x81\x88\xda\x97\xdf3\\\xe4\xbcx\xaf\xd1\x9cw?a4\xcc\x97\xb6\xf6\xb5\xf8G\xe7\xf7\x9eO\xe4"\xb9\xcbz4eG\xd1\x8e7\xd0,\xedR\xb0\xcc\x1c\xd2\x00\x8e#$\x07\xb95I\xc3\x0b\xbe\x10\xdb\x9c\x98:`\xde\xc2w\x94\xbbE\x8c\xa4\nBc*\xc2\x1a\xae\xa0\xcd\xe6\x04\x8b\xfd\xb2yIH\xb0|\xffp(\xf9\x9cY=\x95\x0c\x83\x9a*\x10\x03^\xe8k\xbez\xdfFuX\xf0\xc9oD\xce\x9d\'\xed\xcd\x83\xaa\xbe\x12\xefky\xe5\x98\x05\x0e5*\xdb\xa1z1\xad\x1e\x00o\xf7h\xa8\xdb\x08\x87 \xe1\xe2\x02\xc7n\xdf\xca0\x116\x8d}\xc1\xac\xeb\x93\xee$\x9eK\x07\x80zd\x1053\x8c{\xa6\x07\xac\x83\xc6\x8c\xbb\x9c\xce-\xcb5r\xdb\x8b\x8c\xd3\x9e\xb30|\xf3`\x82\xab\xaf\x18\xa7\x12:\x17\xed\xe8\x08\x967\x0bJ\xe2\xcd_\xa4}\xc7\xa0\xa0\x18\x0f\xda\x86\x18\xad\xf9iV\xd9\xc8\rn\x17\xb2r5\xda\xff\xf4N\xe9T\x9d\xe4\x90\xc1>\xb7=Oc\xf3s\xb4\xfb\x8fe\xac\x0c\x9f\xa4\xea\x90m}\xae]\\\xad\xb8\xa1EL~\xe9\x01\x80z\x1af\x12\xbb\r\x9f(\xe8\xb0-\xe0\x17\xe1\xec\xae[\x16J\xe3\x1b;\x08>\xa00C\xde\xd6\xf1\xc7[u|\xcb\x1c\xddW\xfc\xd7\xbd\x90\xe8\xaf\xc2\xf9H9\xf9\xf6\x94]\xfd\x91|#\x93J\xe0\xa8\x86-\x0e\x13"` \xbdG\x0cbE\x89K\xa0\xc7\x17\x02(:\xe9\xe3\x14Ij\xafG\xdcZ\x01\xb0\xbd\xc9\x8661\xec-E\xc80\x99\xe7\xd0\x9c"+\xc7K\r)\x14gI\x0e\xa4K\xe6w\xcc\xe7#\xa7\xb0\xd2e\xd2M\x94\'\x96\x89\xb5\x83\x8f\xa0v\xd4\x1bT\r\xa1\xcf\x82G\xb2 \x8d\xf3M\xfe\x03z\xd9\xf0\x18s\xd5\xa1\xf4\x9a\x9a\xe1\xb0\xf5wo\xac\x08\x17d\xceOe\x95\xf4\xe1\x0bc\xa5\x83\xadR\xe6\x0f"\xce\x86\xf0+\xc6\x12\x02\xf1>\xb1\xdd\xc8\x92\x85\xcb\xa5=k\x0b\xc51\xcae8dW\x12\x8d\x84[@\xf6\x99\x13\xb4\x8f\xcd&\xa1\xf6\xc7\x14\\\x923f\x81\xfe]\xbfE\xa8\x87\xfa)\xacBQ\x92\x01\xb6\xc3\x89D)\xed\xc6B2/\x13\xcb\xa6\xf3\xcb-\x94\xe4\xcc\xa6\x95@L\x87\xf5\xd4\x83]V\x1b\xfa\x89\xb8\x11\xa3\x82\x1f\xc35_\xb2\xfb\xcc4\x1d\xff\x1a/\'@c\xec\xeaR\xd2\xb3&\x0e\xcc\xc5A\x84j\xf1\x97\xb6]<\x0c\xfb\x96Q\x8d\xc2@\x17\x97\x91\x891\xf3\xac\x15\xf2t[\xd1Y\xceeE5\t\x98\xb3\x84Iq[\x81\xc9D\xde\x04\xd0\x06\xf85\x97\x1f\xd2\xb2\xa3;\xae\x9e4i\xd2\xf6\x98\xa8\xf5\x88\x13,%\xda\xf2\x83x\xa0\xb9\x06sNq\xb3\xd3U\xe6,N\x01\xaa\x99\x0e\xeb\x15\xd4t\xc2h\x82\x1a\xfb\x906\xc7ws\x89% feW9b\x9d\x84O\xdd<nP\x88\xfa\x9e\xc31\xcd\x00\xef\xf6\xcd$"^\x88x\xbf\x862\x96\x07\x93\xf6\xdbE\x95\xde\xcbz\xce1\xa3\x0b\xdf\x0b\x94\xf4\xa3l\x80\x07\x0b\t\x07\xdep\xe1\xdba\xc0g6\xfd\xc2\x94\xd1W\xa5\x1e\xaa6\x146\x9e\xcc\x89p\xd4\x13q\xbf\x8ad\x18?_9\xb3\xc8\x83\xf44C\xd4\xdcj\xc3C\xd6\rn\xbf&\xef\x8b!\xf9\xc4G\x8a\xfe\xa7\x98\x04k6\x11p\x8b\x89\xf2#\x17\xb1\x0frs_\xbe-\xb4:"\xfdI\xba\x98\x8b\xba1\xba\xca\x04\xe9\x08\xbeE\x1c\xb2\x07\x1f\xaf~\xdc\xf3~2\x18\xce\xfb\xf1?\xa0\xdf\x18,\xba\x97\x9c\x1c:{i.\x80\x8d90\x89\xe3g\x94\xe9\x7f+\x0b\x97\xb8\x94@@L\xb9I\x810\x8cw\xf8P\xe9\xe1\x8d\xdc#Q\x97\xe4}\x8b.9\xbe]\x90\x1a\xc1\xa4\x86F\x06\xae\xa2~\x7f9\xb7\x0c|\xef\x1b/\x93\xd1Fcp\xd7\xe5\xfd\x8a\xb6\xf8"/\xfe\xaf\xdaS|Y\xcf2\x04\xb0]N\x85\xd9*\xd3\xf0\xd7\x0c,\xf3\xbc\xe8G\x0bv\x98a\x13\xc7\xf4\xfeoK\xfe\xfe.E\xff^A\xad\xe2\xad\x86\xbb\x96\x12\xc4\x04\xc2\xf1\x99P\x0eR\x94@\x19l\x84\x17\x07\xf5A\x85\x8f<B\x88s\x8e\xbc\x10\xd6i\x82.gg\n\xdc>\xfd\xcb|i\xf2\x85\x1fc=\xd3%!\xd9Dw\x9dK\xe2\xddKv\xf3\x16?\x01\xd01\xf2\xe9~\xe9\x14b\xca\xfd\x7fO \\\xbe~\x0e\x8a2\xed\xab,\x8a\xb4z\xc9\x842\'1\x18\t\xd6\xc0\xf3e\xcc\x8d\xde\x85\xbc\x90\xc7\x99\x0c!\xb3HcXw\x0b\x88\xa8=J\r\xd7\xf7F\xbb\x82?,\x869\xe7h\x98\x13\xa0DoCvf\xc1\x82\n\xf4\x9b\xb6\'\x12\xda\x1fWh\xc1\xf8Bn\xd6\x87vN\xf7\x04J\xde+\x1e\xc8QhZ\xe6\x81\xae\xd2\xaar\xe9SJ\xd0\x15kb\x86p\x06R\x1b\xd2\xd1\xd9W\xb9q\xeb\xeb\xe6\xfa\x12u%\xd8\x1a=\x00U}\x9d\x1eEM\xea\x88p\xc0\x95O\x9b\x9cEX\xb73\xc1\xba\xcd\xfc\xe9\xd0\xd2\x08\xe4~\xef:\n\xc6\x94l\xee\xc4\xdf\x8b\xf6o\xe9-\xedv\xdf\xd1\xea\xa0\x83U\xa3\xc8\x8bu2U\xeb\xeb\xba6\xd0\x90oS\xa5\xfd;\xcd\xc0\x9ee-\x06F\xa8)3Z\x92\x05d{?\xae`7\xf2X\xb2\xdd\xa9\xfcvAz^t\xd5\xc5\n\x05;\x050\xc9\xda\xe3\n\xda\t\xcc\xc55\xcd\xe0\x8d}\xf9\xdb\xc0t6\xe4\x14\xc7e\x1e<R>\x9eG;U{=\x14\xfau\xd2\'\xe9$\x18\xb8j\xb9\xcf\xe0\x02\xc3C7=\x19\xa3\x9b\xe7\xfc\xc8(R\x9a\xb9#8\x9e\xc7v:Pt\xdd&\x9bx\x9b#\xea\xf8{\x15\xb6\n\xb4xc\x0b\xda\xce\xb3\x8c\xff\xa5\xe4\xa5\xe51U\xeb\xed\xbd\xd1\x02\xa2N\x93\xa5$\xee=\x88\xc5\x7f\xf0\xff\x15!>\xc0c\xbfj\xa8\x9e\xb0\xf8f\x1a%\x8a\x86\x06m\xae\xf7\xce\x10\\\x8c\r\x9b\x1d\xe1\xa7\x11\x9c\xfd\x82\xcd\xe9\xd4\xea2B\xcf"E\x10Z\x91\x86:S\xa3 \xbd3\xd1\x7f\x94\xa4\x1d\xdf`T\x91r$d\xd5\x96\xe9\xe9\x0b\xcf:\xa8\x88\x0c\xf84\xb7\xf8/y\x97o\xf1\x95\xcc\x98\xa2W-\x15\xa6\xf8m\xd1\x87V-\xf2\x17\xe3 \xbcsB\xf8\xb6}?\x82\xd5d\x0e\x05\x17&9>\xb2\xec\x08{\xd3\xca\xa6\xb8\x81\x16,I\x97\xf1_\x16\x94\xde\x10\xe9xusP\xf9x\x1b\x87\xdb\xb2\xe44}\xbe\xce\xaf\x8aC\x82\x9e\xc2|5\xc7\x17|\xf1\x94\x82\x92\xf6A3\x0b;dF\x1f*\xff\x1f5c\xde\xec\xd5x\xc3\x18\xdau\xb8\xe3\xe5\xb2\x11\x00n\xc5\xd4F\x8f2\xf3y\r\x1eGh\xc7\xdb\x8fQ\x1c\xbf\xcd\x1b=O\xfc RF\xfa\xe1\xb5o\xa2\x1eB\x00{\xd7dh\x808\x8f!k\x1a\xc0"3{\x14\xd3\x11\xbel3\x06\\F\xe2,\x8d\x06\xfe\xa9\xb0G\t2\xe8\x08\xa7\xe3B\x9e\xd9\xd8\xf9P2\xfd\xdd&0^\xab\xfd\x97\xfeq_T\x1fV\xae\xc3?\xcc\x98\xd4\x01%}G\xb0Ih\xaf\xb3.X`\xd86\xb4e\x0b]a\xd4\r\x15\xe2h\x92\xeag\n\xa7\xb4\x97=\xe8\x93\xa5l\xce\xedB\xd6nVZ\x1b\xec\xf4\xe8\x95\xda\xa9\xc5\xc1\xa0Wa\x0f\xff\xa3\x90\xf2x\x1b\xa1\xc1\x12\x90/\xba>\x9e\x85\xe1K\x10b]8Zm\xc9-\x03s\xbfsm\xe4x7P\xe4\xa8 \xbaW\x19*H\xdcO\x99\x98\x01\xa2\xa7\xdcw\xc7\x98<n\x02\x7f(\xa7\x84T\xf0&\xa9n\x13\x918GA~\xb6H+\x1byES\xdf\x84\xd09\x86\x90\xa9>:\xb2B#\x1a\x0b\xac\x0b8\xcbGQ$W-\xa5\x05\xea\x81x#\xe6\xe0a\xc5\x9d\x17\xa7\x0cT\x11\x9c3\t\xada\xdby\xf1j#\x108V\xb57 \xe5\x98NY\x83;E\xc9(,w\x95\xeb\xd2\x16.D\xafNU\xa2c\x15]\x00O&\xd45\x17\xfcg\x98\xe3\xa0\xc7\xb5\x07\xb4q\x97\x8cD\x96\\3\x0c\xe0\xd3\x83\xfeU\xbb]\x96\r\xc6\xd6\xda\xec(\x8b}\x1ac\x97v\xa4G\x85\xd5\xc2\xaebS\xe6z\x1f\x8a\xf0M\x0f$\xb8C\x1e\xcfO\xd2\x1e"\xe3A\xe2\xfb\xbc\xcf[\x1a\x9b\xb4gq\x9c\x89\xab\'\x06Ksf\x97\xc3S\x1c\t\xbf\xeb\x1a\xda]|\x10\xc7\xe17j\xcfR\xea6\xb0\xe2\xcdn*$R\xc2x\x01\xcb\x17\xac\xday\xb3\x03\xd8\x98\xd5#\xe0\xa9>y\xc5ux\xfd\xeb,B\xd3f\xa7A\xf2bE\xfb \x12\xd4\xba\x1b\'\xa5\xb87=;\x08M\xcd&p.K\x15\x93v\x96\xe39n+\xc2C+\xebz\xc8t\xa2\xf9\x95\xa8\x81FQ\x90\x96x\xa4KF\xbb\x81\xaavG2\xc5:\x07i\xcbnz\xa3\x80\'nd0\xc0\xa6\x1f\xe4\x89\x91\'@9\xd4\xf4\x1f\xa0\xa0\xe7fT"\xfc\xd7\xae\x91s@\xbb\xcf\xef-\x19U\x05\x1c\xe39\xbfM\x14\xb0S\xa0\xcdk\xf8>\xd8\xac\x88\xf7\x13q\xc1\x9da@\x7f?n\xa26\xc6\x9d\x9f\xa1\xedqd \xea\\\xdd\xe7\xcb\x12ra:U\x8a\xcd\xd7\x93\x8d8\x9a&\xc6<;\xd89=cO\x90\xe5\xfbL\xa6IZf.\x97p#5\x8b\xe9\xda\xe9\xb3\xa8\xc5'
|
|
|
|
|
|
2024-12-14 17:54:48.199460 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:61224 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d23
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 61224
|
|
len = 48
|
|
chksum = 0xd242
|
|
###[ Raw ]###
|
|
load = b'\xc6\x00\x00\x00\x01\x00\x08\xea\xcc~X\x91`\xedq\x00@\x16y\xf1oBz\x85\xe3\x05x{\x9a\x077\xae|\x8aTR\xf9g\x14\xad'
|
|
|
|
|
|
2024-12-14 17:54:48.204227 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:61224 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7869
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 61224
|
|
len = 1258
|
|
chksum = 0x124
|
|
###[ Raw ]###
|
|
load = b'\xc5\x00\x00\x00\x01\x00\x08\xea\xcc~X\x91`\xedq\x00D\xd0\xa2\x97\xab\xf4\xf2L\x08\xcb\xb5\xef\xab<\x04\x03\xa4\xee\x02\x10(F\xc5\x12\x05\x92+|\xbbW\x08Y\x11\x92\xa7[\xe5\x9f\xde\xc69\xb0O\xc6P9^\xb3\xbfl\x19\xd2\xcfk\xc0\xb9\x90\xb2\xc6\x13\xa1\x1c\xa0\xb5\x115q \xe1\x8b\xb3\x90%C\xeb\x1a\xcd\x16,\x82\xde\x90;\xdb:\xd1\xe7\x06Sz\xa2g\xc7*fW\xc6\xb0\x88\xb7\xca\x0f\x91d\xba"c\xa6\xd1\xa8\x19B\xd5-j\xc2w\x95Bc\xe7d\xe5B\xfbD\xd9\xc4\xd5\x908_\xd2\xab\xad\xc6\x19|>`\x93Bu"8\x86\xa9[Ua\xb5\xac(\xea\x95\t\xef5\xb5i\xbd\xb0\xdd\xca\x01\xa5\xc5\xa2"\x9a\xa5\x94\xb3_\xd2\x84rV\xa1\xb6Ys1~\xe8\x94\xdc[\x1a\xf39\xe1Jf\xc4\n\xb7\x9c\xa4\xa3\xc9h+\xe8\x8a\x02d\xf8\xf0\x82\xf5q\x927X\xc9~\xc4 \xdd\xef\x02\x8b\xa0\x87%\xab_\\\x18\xa0\xca|\xb8\x85:\x86\xbe*\xfag\x83\x13\x83\xb4T\xbc\n{\xea\xfe\xf9\xa0\x89\xa0\xc9\x04\xc9\x12\xb7\xba\xc0\xbb\xda\xcc&\xc0\x03\x14\xaap\xc5\x9b\xd6R\xd4%\x0f\x9b\xc0\xef~\xef1\x94=\x0e\xdee\x01\xcd\xe8 PH\xa9"\xf10\x15\x18\xc1q\xc0\x84W4\x12\x9d\xba\x06])\xf6\x9a\t\x15\x19d\xe6w=\x14 g\xa7\x0e\x99U\xdb\xbb$\xdd\x82P\xad\x99\x02l\xf9\x91\xfe828\xdeQ/\xb8\x88\xeb\xcc%\xf6V\x1e16J\xf5\x82\x18\x18\x91\xf1\xacuh\x1a)J\xe8\xa9\xbb\xcf\x8d\x1cEs\xac\x06\x8d\x04\xcc\xc5\xf3>dUW\x84\xf7\xaf\xf7T3\xdf\xe9T\x8f\xdf\xc2\xc8\xb6#\t\x90Hz6\xf0K\xa4\xee\x88s\x8bz\xc7\x9f\x84\x81\x0eX\xf1X`\x7f:Lt@\xc6d|\xa7@\x80\x07\xa9[\xa8pk\xf7y\x1b\xaa\\\xde\x11\x85"\xfb\xe3\xbd;\x9f\x10!\x88\x9c9\x85\xfft\xb0\xf5\xdd\xc7\xb8\x11\xf9[\xd4\x0e\xdc:\xe5\x0b7\x99LG?\x98\x19(\xc0m\xac\x9bM\xcd\x18\xdc)3\xe1G\xce\xa9XH8\xdb.}\x80\xbd\xb6F\x1e\xca\xbdT\xb2\xba\xb2\xd8FE\x92\xb7\xcbwu\x03\xcb%]\xd5\xa45\xfb=\x1b\xdc\xb1\x1fK\x8a \xd0\xeej7\x82"\r\x98[\xe6\xc5a6\x1ab\xf6K\xf9fT\x0fJ\xa2p\x91O\x9c-\xd4\r\xfe\xde\xfbO\xa7\x7f\x12\xd9"A\xff\xee\xb5 \xd6rR\xda<O\x10\x08\x96\xd8\x8c\xd3Q\xee\x82`\xbd\xc2\xfa#\x05\x95\xdfT\xd3\xa5\xa48\xef\x1a\xb3\xedl\x1b#\x98\x8d3\x9e$2\xea\'{U\xe6\x8f\xdfKm\x83j\xa9j\xfc\t\xec\xc4\xd7"\xbf+B/\x13\xc9\xb8S\x99\xb9\xbc\'\x03\x16z\xad=(\x15\xb8\xebi\x10\xf2w%\xde\x9f6\xe4\xc2\xc4i\xabC`\xa8\x89h25C\xe5W\x17\t\x0e\xd9\xff\xc1\xe4\xb9\xd0\xee\xfe\xbf\x96J:\x9a\x82\x1f\xa9\xa0_\xf0\x1c\x88\x7f\xe0\xdf\xea/\xbc\xc3\xd4O\xb6\x969\xa1\xcejW \x94\xf5|#\xb2\xef\xc8=e=\xfdk+\xf0eH{\x93\\\xc1\x8a<c@\xd3g\xcb\xcc\x11\xc3m\xb3\xb0\x95\xddZ\xf9\xb3\xd7o\x0bD\x90\xab`,\xd7\x8f\xec\xdb\xf0[\x07-\x0b\x02\xb3\x03\xef\x85]p\xff\xbd\x95\x12s\xbcY*\xe7\xec\x196z\xfd\x8dD\xcd\xddNe01e\x8b\xfd\xb4\xdd\xce\xe84t\xb0\xe9\xe7\xeb\xb7\xb4\xa9\xc9\xc5q\x89\xa1\x99\x85T\xbd\x167&\xaa\x16SM\xfb\x1b\xbb\xf4J\x90\xf3\x9a\x8c\x05\x18mn\xcc6|\xbfT`\xfdO\x86\xea\xd4\xf3\xc3\xdd!\xe5\xbc\x957\xe2|\rn\xc1;\xad}M\xdeo\xf9\x91\xedO~5\xe1\x04f\x11\n\x13\xfbOE\xd60:ze\xc5\xba\x8f\x8bf\xf3\x14\xda;\xf3\xc7C\x18\xd7\xab\x8aA\xb4\xea\xb89\xd5%=\xc7v\x97s\x08o26\xbbSv\xd2\x8fs\x92\x11\xa9\xf2\xb7\xd3\xa0rbA\x81\xf0[k\xde\xca\xc5;B}6\x85\xcd\x8bz::aI\r\r\x0b\xfe\xd2Tl\xd0\x07=\xf1\xe3\xdf\xfc*\x9d\xa5I!8N\x15.@\r\xc0\x07\x01hS\xa4\xf4,+\xb5\x90\xe8\xbf"\xfax\xf4\x81\xe5\x05\x92k\xfc\xbc\x9de\xcd\xac\x1c7\xeb\xc0\x7f\xfdQN\'\xb7\xba))\xed\xc9YCw%\xcd\xf50\xa0#;\xec\xb18T\x01\xed\xcf&\xa3\xee\x9d\xf8\xcb\xa3\xc8H*-\x92\x1bs\x9e1\xcd\x0f\xbb\x1f2Y\xdb\xc2\xf0<T\xfc\x7f\xe1j\xb6\x85C\xcd\xd91\xda~\xfd\xfc\xec[\')\x0b\x84\xdf$vr\x9c\x11\x97NW}\xdc\x93_\xf1H\xbc\x83\xd8\xf7\xcf\x8f\xca\xcf\x90\x1dM\xc2\xb3\xfcm\xdc;P\xc3\xaaN\xdd\xcf\x00\x97]]\xb0^B\xc6\x15[\xaa\xde,\x92\x1d\x19t\xba\xce\x13\x10!9\x80\x82\x16<8&\xfa\xfau\xea\xf8\xb2g?\\L\xf4O\xb2,UN\x8e*\xb9I\xf1\x86z\xe3\xc0\xfc\xad\xceX\x11\x1952\x878\x02\xcb\xb3\x19A/d\x92\'v\x82\xd1\xa1\xbb^q1]xW~\xdd'
|
|
|
|
|
|
2024-12-14 17:54:48.207373 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40821 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 17091
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x3b7b
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40821
|
|
seq = 2746219178
|
|
ack = 373748795
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1025
|
|
chksum = 0x44bc
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (373750207, 373750560))]
|
|
|
|
|
|
2024-12-14 17:54:48.211918 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40821 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 17092
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x3b86
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40821
|
|
seq = 2746219178
|
|
ack = 373750560
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1019
|
|
chksum = 0x9561
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:48.214670 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25559
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808808269
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.217848 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25560
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808811189
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.232083 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 5880
|
|
id = 47915
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf58b
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808811189
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'B\x13\xc6P\x13\xd6\xb5\x16[\\e\x8au\xf0\xde\xc8_\r;qc\x9c\x98\xb5\x04\xd4L\xf8\xe1\x87f\xa2\xd2\x04\xd2\x99\xde\xe5\x88\x82\x90\xc2\xb9\x00\x18\xa5J\xb3\x0cUY\xfd\xc5|p\x10U\x16<\x1dR/\xce2\xc6?t@\x1bd-\x91\x8f\xc8\xf5\xbc$\n\xd13\x10.\xab\xe8S\x19jYQ\xfe\x8a{\xafY~\x83\x98\x95\xc4\'*\xc5\xf8\x81\xa2\x0b\xa3\x89\xa5\xed\x7f\x14\xe8j\xdbl\x7f\x90\xe7\xa9\x8dR\xd1\xf2 \x1f>\x8f\x81\xd0\xb3\xd4A\xe7\xdf\x89i\xe4\xd9\x1f\x9fG4\xdd9=a\xad\xa3\x85A\x83\xb21\xc4=\xf7\xeeGJ\xc2\x1d*\xca\x18\x89\x1b*|\xc0P|\x9b:\xcd`\x8b\x89g\xb9\x8eY\xe1\x10\x9a"q\xe1\x0c\xda,\x01~X\xc2%\x98$\xb5V\x82\x8e\xbd\xdc@\xa3\xc4\x93\xff\x0cI\xc9M\xc5Wez\xb6\xd6O\xec\x84]<\xb3\xff\xc6\xb2K\xd4n8\x0bD\xcc\xdbG\x85\xf5m\x03\'\xf5\x19\n\xf7;\xb6\x01\xea\x0b\xf6\t\xaeL\xbb\xb7\x07\x98\x9b\xa5\x93F\x85\x1bCK\xc9L\xa7U_s?i\x9c\xe3\xb2 \x1d\x84;\xc9>(\x92[\x88\xf3\x14\xcd\x87$\xb1\x0e\xdf#\xdd\x04\xf6\x8eB\xe4\x17aH\x8f/\xf0\x8d7R\x0b[T\xd9|\x1c\x1fu\xc8\x89U/\xcd@c\xc73-\xc5\x15\x0b\x17\x9a\'\xcb\xe5\x8a\x9c\xb4\x06\xb8>\x88\x9d\xb8=\x1d\xc7P\x97j\x13R\xad\xcaT\xf2\xec\xden\xd2it\x12\x02\xa1\xa7&\xb1\xd8;\xfe\'\x05\x8a\xb3\xe0\xbf\xb6\xa8\xe7\x04m\xb9s\x80\xeeI\x88\xd1c\xe1\xcav\xd0"F@\xe3u\xf5z\xd9\x13\xeczQ\x83\xa3\x86&\x1b6\x19\x94K\xcc\xe8\xa1/\xf7;Q\x04&W\x864ir\xb2\xf2\xa7A\xf3N.\xe9\x0f\xafV\x9c\xec\xde\x83\x02\xd7=\xf0\x1b\xca\xdf;8\x8aI\xaa\x16\xf6\xff\x88\xdb\xda\x86)\x17\xdc=8\xe2;\xec\x1a\xe9f>\xac\x8fD\xaa\xc1\xf4\xa35Z\xe8T\x97\x96\xa2\x05\xc6\xab\x835\x99\xa7\x1c0v<\x9c\xa1bk\xe7\xc0\xa9\x14\x108\x9f\x06hvq\x11Q\x98^\x0f\xe6a\x01\xba\x7fZ\xa1xh\x17\xb4\xc8f\x9cnMo\x04\xeeM\xfd\xe9B\xed\x08\xeb*\x10F<\x88\xf6\xbd\xc1V\x8dF\x01\x1d\x9cB\x84\xcd\x8edFcL\xe2#\xdf\xb1]\xbe\x04\xe0T\xf4\x8f\x1b\xaa\x8fw\x14r\xb3\xa9\xdb\xd0f\xe4\x9d\xeb\xe6\x8apP\x89o\xc2\xc0wU\xc7\x86\xd8\xf2\xb8\xf7\x97"A\x06\xe3\xcb\x8d4\xd99\x8fMe2X\x8a\xbc\xe1a~[\x02\x00\xa3\xab.H\xf3\xc7\xdb\x87\xaenk\xdc\x8b#\xb9\x95v\xb9\xbdz\x7fo\x85\xfa\xbd\xc7\xb3\xcc\x92\x9agR\x99\x92lJ\x85\xd9Ed/\'\x9e\x85Zo\xde,A\xfb^\x02\xe8\xd0\xd6\x9f\n\x82V\xbc2\xc7\x19\x84\x9a\xc9\x85\x9f\xd9\x90\xf3\xb5\xc7\x04\x80\xe8n\x13\x1b\xd7\xec\x19\x14\xda\xb9\xeb\xcf($\xd5\x07\x99\xd8Wj\x13F\xf1\xebE`7\x95[\\\xab\x1b3&S\xc2x\xb78\xa4\xfaN\xd3\xe8\xf1\x7fY]\xed\x898\xaa\xfe\xcbu\xc7\xc2\xea\xcf\xde\x1cX\xd5\x85\xd3\xb4\xd0H\x95\x03\xf6&C<\xae\x7f\x0f\xb0\xe9U\xc3\x87T\r\xe1x\x1c[\xfb!\x8d\x1f6w\x1c\xcdE+\xd3\x0f\xa4\x97\x053\x9d\x06\x0c#\xb4B\xed/\xb0\xda\xd8\xdeH\xebc\x1b|[\x0f\tv\x95\x17\x84\xc7\xa7Np@\xa9~?\x94\xab\xa8Y\n\x1c\x8b\xe8\xa9kZ}*\xd56\xd8\x7f\xe5Y\x94\xf6!\xdd\x96\xfeq@\xf8\x95[3m\x9e|F\xe1\x81\\r\xe3\xb0\xa1Oj\x03\\kf\x9d\x86\xaa\x88*r7^)A\xdb%B\xb1k\xc5\x98)\xaf1(2\xb4\xf1\xab"\xdf=\xf5\xc2K\x7f\xa2\xbb$\xd4(\xd8!\xb0x\x988s\xdc\xd9\xd4\xc1\x19\xc2\xe0\x95\x9b\x8ef\x1dej\x17D\xa7\xd1\xd1\xae{\xcd;\x1b\xb0\xc67\x91\xa3mA\x18\xe6\x80lW\xf6\xbdE\xbc9\xc0\x9ac\xeb?\xa1\xfc6\xef\x94\xea\xa6\xb7\xfc3\n\x04\xd9\x7f=\xb7\xa3`$\xea~\xf9\xe3\xc9\x0b\x0bu\x84\x9d\x04\xb2\xb9\xde\x82Q\x03\x01*\x97\xb5\xa0\xe4\x1fx\xb3Y\xd5\xe3\x81\x9e8\x1c\x17,\x03\x87\xd4!\xea\x9d\xf6\xa9\xd6T\xcd\x8b\x9e\xde\x0f\xb7\xbe\x9dW\x8f\xb5c\xcf:\xf8\x1f\xb1\xd04\xa4u\x92\xdf\xac\xb5\xac\xf8{R\xfb\xe1\xc5\\q*\xb5}\xa0\x87\xb3QI\xfd\x00\x7fc\x8c\xe7\x9aj\x9dA\xda\x98\xcbZ\xe4\xd6m!\x8d\xe1\t\x97\xce\xfc\xd3A\xdd\xf6\xbf\xc6\xdf~3\xff+\x0b\x06u\xb3V\x84G\xa9F\x9e\xaa\x04\xbd|\xc2\xfbB6C3%\xe72\xae\xf3\x9e\xf2\xeb\xff\rt\'os0:\xa6\xd2\x1c\xb7z\xaa\xd7\x0en\xe7\xe3\xf2\x88e?P\xbc0\xcc\x84ds\xe5\xfc\x95!W\xf1\xc2\xf3\xbd\xd5\xc8\x19\xe6*n\xb3\xb9G\xac\x11ry\xe3\xde\xfeu\x9b\xe6\x83\xf3\xa0\x9e\x8at4\xed\x1bL-\xc9\x0c1,\x7f~\xb6Xd^\xf4\xd6\xf5\x0b\xd1\xaef\xcd\x0cP\x8b\x16\x8e\x81z\x94\xf4P\xd0\xa8\rcNA~\xb0\xe9\xd2\xefB\xa1,\xee\x9e\xdf\xc26Y\x17\x8a\xc7gp\x00\x88\xc1\xba\r]\x99\x80\x01\xa2\xda.\x0f"p\x96\xb8E\xeb\x1a\xd6\x8b\x0b\xa4\x04-l\xa5o"\x93\xe7\xc4\xc9*@_p\xc9\rn\xe9(\x8b:L\xfc\xfe\xe8\x07\x81u\x02\xdc\xfa\xd4l\xdd\xec\xb5\xb0\xdfb\xd6\xac&\xfb\xa88\x87VBnh\xf4c\xb5\xe0\x9f\xc5g\x17\xa8kx\xc5y\xac)\xebr\xab\xca\xd2&b\xa4?\xe5N7\x11\xa5\x95\xa0h\xca\xc3\xd4\xe7\x0b?1q\x17\x1e\xfc\xac\xcfe\x82\x96\xd8\xab]\x84j0{\xd4,%WE\xe3\xb9\xe0\x83\x88F\xbc\xf7\x80\xf6j$\xeb\x8a \xbf\xc2\xf8\xb5\xe1\x1d\x99\x9f\xb5\xdf!Bum\xed^c\x94U\xa8\x7f\xc5G\x9e]\x9a\xc7i\xdc\xf5\xea\xa9\x88z\x8b\xbe$\xfb\xa0I?"\xdaB\xef\xbf\x9c\x8a\xe28\x9bq\xc4\xf2]\x86\x92\xcb\x10\xb8\x86G\xd8\xd7\x91}W*\x06\xb0\x1a\xce\xc7\xd8/9\x030\xa1{_o\r\xe7,\xe2\xdd\xac\xb5\xe6\xe4\xf97\xdd\xf5\x8cr\xf4\xfd\x986\xea;\x91O\x11\xec\xca\tI\xdd\xd5\x12\x8b#\xa0\xaf-e\xca\xb6\x03\xd2\xa1\xb5\x82\xa5\xee\xbbc\xdd\xee@\x93\xce\x89\xc3}\xdfH\xf6\xf4e\x945\xec\x19\xdd\x9d\xb3:\xc1\xfe_)-L\x0e\xfcL\xb2M\x12F\xd8\xb3-\x12\xedw\xbb\x9c\xcf`\x83\xdc\xac\xc3\xe4\x93\xdb\x97\x8c\x98\xbe\xee:V\xb7\xa5>\xc1\r\xae1e\x96B\xfe\xa3\xd4\x82\xa4\xfc\x89H9\x91\xfc\xb4w\xf9\x8c}\xd4\xf4\xb1\xb9\x16\xb0?\xf4z\xc4SC\xcb\tV\x90}\xac\x13\x8b\x92W\xf0\xe3\xdcUrg\xdf3E\\\xc60\x95\x9dC\xc7\x1a\x85\xe7\xe8\xab\xfc\xd4\xd6jq\xb8{\x89\x9a\xd8\x00\xdem\xe4\xbb\x9d\x17w\xd0\xeb\xf6\xf5\xd5\x19\xfdktiRM\x12\x0e\xa9u\xb7\xa8\xc0\x16\xac\xc3\xf5\xbagd1\xad\xad~a*\x9f\xe5\xa2\x86\xdaQ\x88\x96\x8ab\x08m\xe3\xd0\xa2I\xe5 $n\xbcK\xac%\x93\xf8\xc8\xbe&\x96\x10\xf7\xc15#\x07\xf3@-\x8a}\x8a\xdb\x19Sc\xcc\xb2\xae\xbe\xd0e\x05}\x88\xc0H\xdbhR\xfe\xf0\\\xf53D\xda)Rp\x8f\x9d\xa2E$=\x07\x9aQC@.\xa6\xa85\x1d\xe4\x98\xeb\xdb\xa1\x11\xd2\xd4x\xd0m\xbc\x95h\xe4\xc3d<8\xe3_\xf0\x95\xedL\x9e\xc5y\xe4\xacmD\xaaH\xef\x8c\xf6\xf9\xc0\xa2\xd4\xc9\xdb^\xf57(\x0eB.m\x1f\x0b5D>\xbfa\x0e\x97o\x81\'\xe8\x87\x9b\x08#\x94\x16H\xb7\xe5\xe5\x04\xc7\x04\xc4\xcf\xe8\x1d\xa3a\xc5\xfc\xaf\r\x0c\xe0\x102\x90\xde\xf6z\x9a_\xf9\xe7\x0fK[\x8f\x8c\x9f\xcb\x9f\xab\xab\xd2\xac\xec\x1dPdQO%\xc0\x0c\xcf\xe0\xc3\xac\x0ba\x9e\x12\xa6\xf8L\xe3/0\xfc\xebe\xa6\x01\x03\xa5\xae\xe6\xf1\x8d\x05\xaf\x82\x07\xc5\xe1]|2\xc1\xa6\xb8\xc1\xf8\xd5X`U>\xd4\x8d\x16\xab[\x19C\x92\x84EFj$\xf4\xaa/\x9a\x0b\x98\xe8\xa2\xcd`\x05\x9f\xc4\xbd$\x9d\xdc\x07h\xe9c\xcbV$u6BU\x13\x7f,\xfb\rc\xe0\x93M\x9a\x91 \xa8\x9f\xe9\xf2\xb2\x16:\xe8\xccG\x94\xd9\x9d;\x88\xbe*l\x9eI\xf5Q3\x88G\xd4:n\xd94#`\xef\x84\x88^wln\'\xa1\x12\xc9\x1c\xe4\xbf\x92B^\x1a\x04\xf9aK\x18\xd5\xf9\r\xcf\xa1\xf0\xebuD\xb8q\x06\xe4\xa9\xcf\x91\xe5`J03a\x01\x00\xfe\xeb \x11\xddQ\x8d_\x16\x90\xb2i\xbf \xd0m\x80\x1e\xad\x15\x827\xbey?\x9f\n\x0b\xbd~\x13-d\xe70\x80J\xc6R\xb4\xf0\x19S\x0f\xf8\xe2sB7\xe2H\xa3\xacd\xf8\xce\x15\xec\x14q\x8fE\xf1\x89!76m\xff\xb9\x82\xa2\xb3\xdc\xc6\x00\xa4\xe6\xae\xf8\x01\xf3\x89G\rA\xa7$\xfe\x8c$P\x17~sR\x8f9\x8fL^3`\x81\xf5\xd7t\xdfJ\x9fR\xa0\x0eo\xa5U\x93\xea\x05L\x99\xb5\xdf\xa1\x99\xf1\x90\xd6o@b\x0fz\xb1#\xb2\xb4\xa9\x8332\x9c@\xa4\xd6p8\xda\xcf\r~*\xd1\x1d\x1c\x895w(w\xea\xb2\x9b\xdc\x92\xd8t\xea\xf7T\xe5 \xd4\x88AL\x1f\xde2cl\xbf\xca\x12W-y}\x0e\xbb\xbd"\x89U\xa5b\x9cV\xa3@\x90\xc1!\xe2#\xef\xc2\xd7\xa0\xaa\x87\xd5\xc8,\x97]\xcc\x8fol|\x99\x9f\x04\xd5\xb0(p*Y\x99Nr\xba#\x1e\xfb7Rb?^q$\xd8\xe19T\x1d\x7f\x01)H/\xd2\xed\xb8\r\xfdGiTuu\xcaI\xda\xd5\x88\x89De\xb7\xfe5@\xea\xba\xb6\xb6:6u\x12\x87Kp\x1b\xacB\x95Z\xfd\x82\rQ\x8f]RV\x9a\x17\xe3ei\xb8,~\xb2\xf0\x04\xea\xed<`\x1e\x00\xd1\x1b\x95\x96\xe0d\x8c}\x92\xad\x12Ov\xaa\xec\xc2j\xd6%Y\x0fU)D\xe9\xa4\xa5\x0e\x9f\n\x95\xfdMFH\xed\xd5:y\xabtZ\xdd\xde\x14\xc0\xd6\xccK\xea\xff]\xeb\xe5sT\x14\xbd<E"i\xbe\xe7m\xa0\x801\xc8W\xc2J\x8b\xc7EFF\xc0+#X\xf1\xc4\xe5b\xc4\xe8\x0e\x93\xc9J\x03\x1b,\xe5/\x04Y)b\xef}\xe6\xaa:\xc3\xe2\xda\xf5\xa06\xe2\xd0\xaa\xa1a">\xae\xbd[g\x00:?\xb9}\xab\x84l\x17\x9cx\x7f\xb6|\xb0\xcay\x80\x0cHN\xe1<\x99\x96\xd2\x97\x19\xc5\x14\x1a\x882\x16@%\xf7\x87\x8a\x91\xfcFR\x8e>\x96~\xe3K\xa40\x05\x14\x05\xd40_-\x13\xf7\xbb\xe0J\xf7\xec\xaaS\xc8\xc3\x80mX\xbd\xb6D0\x14\xeaH\xb1\xca\xe5\xcf\x14w\x11\x0b\xa9[\xa6\x11&\x81vK\xc8\x1e\xf9\x03\'\x15\xf8\xcc\x1ao\xb0|\xbf\xb8E\x0c\x86\xc1\xa8\xf3\xea\x16\x86\x9c\x1b\xe4\xa2\xbb\xd8\x03r\xc3\xa6\x00\xefB0J\xbbt\xde\x81f\xa5I\t\x17r[:`j\x14j\x97b\x8d\x93iq\xb7\x04\x9fj\r\xc2\xa1\xae\xdd\xca\xcdhU<\x0e\x03\x00\xd4\x9d\x8a\xaf\xc1\xea\xdcs\xcegf\x0e\x82\xb5%\xe9a\xb1h\xde>\xaf\x82\x1b\xab%A\xcb\xd8\xd7ak\x13F\x1d\x9e\x18}+\xfbQ\x1cQys-l\x9b; 2\x83]s\xa6C\xf3\xa8;\xcaF\x0b\xd8\x0b\x01\xaeud\x8b\xd4\x1f\xf5\x8dj\x9f^\xdd\xb1\x16\xc7\xfczQ?\xbc\xfd\xceA\xe5\xc9\xe8\xe5%K\xbb@\x93\x1a+^g\xd3\xe3\xce\xd1\x96"5!%3@@*\xee\xa7\x03f\x8daO\xf7\x94p\x17n\xba\xc6\x98\x9eLB\xa9\x01\x15d\xf5\xc4m\xe2\xc8\xc9\xfd\x1e\x8a\xb4\\\xc3\xe3\xdb\x12\x8b\xd2Z\xffqqX \xb7\x07\xc7\xde\xf6\x91\xafj\x96\x02m\x11\x0f\xf2,\xa1\xcb!\xa4f\x0b\xf1d^l\xed\x1fx2\xe0\xc2\x02\x86\xc7\xfaT\xb5\xb5z\xfd\xd1\xdepht\xc0\x17\xfc\x05_\xf0\xa4\xf7\x0el6\xc5\xec\x90\xd5\xdb\xa8\x01\x00\x82\x80_\x98\'\x1e7[\x9c\xc8z\xbf\x01\xf7\t\x1f\xf9\xb6U#<\x86\x85\x90\xca\x8eX\x88G\x94\xac\x8e\xd0\x1a\x8e/\xb3\xcf\xee9\xec0\xce\x82\\\xf0\xde\xf6\x0f]C\x1e\xd4\x97\xf9?\x0f%\x12\xac\xbfO\xd9\x98\xfab\xb6\xe7\xcd\xd2R`\xd5\n4F!\x9a=\x08\x8b\xdc}xB\xcf\xbe\x12\xae\xc3\xb3\x0f\xc1\xfc45~\x01\x95\xec\\#[>\x9a\x973c\xe9X\xc16\x0c\\\x83\t\x03N|\xcf\xd2\xf9Ce\xe2\x8cF\x82\xc3\x9e\x004fF\x96\xd5\xf7hg\xf41|\xbcN\xf0\xf5\xb9\x87\xda!\x0f\xe9\xea!.\xff"\xe6\xfaH\xd8\xb8a\xf6A\x92\x00"\x8fw\xc4\x0c\xc0\x82\xb8\xb4\xe3\x9d\xf4B\xc6Aen\x120\xfa\x88\xab\xadj\xb0\x9b\x94\x12\tf\xe8\xccC\x8b\xc0\x12\xfd5\xfd\t\x8a\xba\x1f\x08\x1ex3\x01*\x122Ns\xf8\xe8\xcc\xcfr\xfe\xb3}\xc4ix\x86Y\xb5\xab#\x06\x1ek\xb7\x1e\x13\xc9\xd2\xd4\x9e\x97\xc1X\xcb\xbb\xca\xc7\x8f\x89\xfd\xc0t\x80\x1ah\x9d*\x8d\xb2\xd6\xd0\xa4ZL*\x16As\x95w\xf4\xdf\x19\x15MZI\xc0\x8ao8f\xf2\x1d\x88 Z\x9a\xc7\x8e\x0b;I\n\xcc\xa8\xe2\xeb\x1ba\x19u\xeb\x9d\xf3\xfa\xd2\xe9\x9f\x02/\xc3\xe3n\xa6BfH\x16j\x926\x81@\x85oL\x8eR\x95\x15\x99\xd5}1\xdf\xa3p\xb2\x1bUK{\x123\x8d\xe0\xb6\x94\xe5T\x162\xbd\xbc~\x8c\xb0\xb2\x0f\x91\xcd\xbeo}\xd6\xa8\xc9 9V\t\x11\xfa\xb6\xc8Q\xa3\xc6-\xf4\x06\x9d\x897\xab\xd8\x1f\x9c\xbc\xb3\xe7\xe8,k\x90\x85\x04\xfb\xbf\xc6d\x05q\xbe1\x95N\xaa\x03\xd6F\xa2S\xcdJM(\x19y\r\x15\x07\xd3b!\x8d\xfag\xb2JJ\xf7\xd1\x9cF\xe5\xaf\xf2\x866\xceF\xc7\xcdM\xe2\x022\x02f\xff8\xf6\x9c1\xfe\xda\xc8G\xaf\x048\x83N\xa2Gq;\xd1\x0c\xa1\xc58\xbbV\x0b\xe9F,"\xcc\x0e\xe4\x03u\x8be\x99\xfdz\x84\xad\x13?\x1a4\xb9W\xea\xce\xa3\xb0TL\xc7\xf0C\xdc\xd2\x90*\xa5\xa1\xe6:44\x1c9\xe6\xed\xfc\x02q\xed\x96\xc3\xe9o\x84x\xf0 \xc2\xd0\r:\xaf@\xe4\x1f(L\xd2\xf1=\xaf\x06\xf6\xc7\x0b\xf2\xf6\xf9\xc7\xd4\x03J\x892\x1e\x04\x89N\xa1\x9e\xae\xc1\x16!\xbc\xd8s\xd9e{\x96\xb9c\xc1z\xa4\x92\r\x80e\x13\x06U\x8eL\xe6"\xe3\x18v\xb0\xc6_\x0f\x85w\'\xd1[&\xc2\xc2\x10\xf4\x1e\x97*\x1b\xe0G\xe6\x0c\x97\xd0\xa9\x93t\xf2\x82\x97\x03\nr\x90\xd0?i\xed\xd9\x92\x8e\x97\xbew\xc9b\xd8S\x00\xe2\xebCGm\x95T\xadQ\x92\xe9\xfd\xb0\xfd0{r\xa83p\x07\x86m\x81\xc8\x10\xc8~W~\xb6\xec\xfeO\xae\xdcAUwE!\xadq\xba\xdd[\r\x8c\xe5pu0\xb3\xf2\xc8HD\xddS\xbc\x0f\xe3\xdcz\x8fX\xf6\xee\xc0\xfe\xfe&p\xc9\xab\x81\x96\xd6\xdc\xaa.\xe8\xa6f\xaf\xfbk\xe8H\xd6\xf3\xe9V\xb5?\xa3V\x99\xde\\\xb2\xad\xfdW\x94\xb7p\x01\xc4S:S\xa6\xeb\xa4\xc1\ry\xd2\x861\xc7\xa1j1\xbb\x8a\xb7\xba:y\x05c\xa8G\xea~"#\r\x98\xdb\xc2\x8e\x14\x97\xc8\xb4\xb6\xec\x8eV\xe2\xda\x17\x9a\xabV\x1e\xa7S\x1dY\x90\xe4h\xec\xc7\xab9\xff\xd2m\x7fS\xd9\xbc\xb1\xe72kI_\xe4\xfe\xa3X\xc3@\xe1\xc1P\x05\x81T\xf7`KC\xc5\xe2t\xc4\xae\xf3l\x8e\xf6\xd8\x82\xd5h\xaf\x95c\x87A\xe4J;\xb4\xaf\xd6y\x80\x0c\x02\xe7\xce\t\x1c\xd0\x9e\xf6c\x87\x8d\xbbz\x88\xe1\xb7\x83Q]CW\x0c\xa1\x08n\x9brwPVJlOS>)\xed[\x8e\xbdh\xa1\xa4\xc29k\x9c\x1er8\xde)\xbb\x9d\xa0W\x92o\xe1\xc2A\xb3#WA\x03\xc94\xad|\xe1\x0f\xc9\t\xf2/\xf0\x17H\x138H\x90O\xcbt1\x02\x17N\xfa\')\xfaQ\x96\x19\x08$\xb8\xe2s\xf1\x8d\xba\xcb\x9e"\x93\xd2\x99-\xa2>\x8dz\xc4#^\xc3\x7f\xa2\xde\xd0r\x90P\x9cv\xe01\x06\x96R%\x91J\x9e\xfc\x9dW\xbb8\x0c\x01lq\xb8\xbb\xde\xd5\xc2\xa4\xe2c\xdf\xcf\x16l\x9a\xdf\xd1x\xa8#\x8c\x0b\x88\xa6\xb5\x85!s\xa0\xa5\xb6\x1b\xf2\xaa\xacL]\x9d)wKh\xe3\xecOwC\xfeWj\x1b\xbc\xcd\xdc\xa2\x85\xbc\xab\x1b\x89\xe7m(\xb2=\\;t7DA\xd4\xa5Jxoi\xce\xad\xf7\xa3\xa2\x98\xc7\xb0S\xdd\xe2\xd7\x7fQ\xa8.\xa34/\xda\xf7\xde>\xd2\xd1%\xa6\xfbz\x07\xf6\xbbz\x06]O\xfa\x9d\xa2\xce\xb5\x00\x94F\x93\xa9\x81o\xcc\xe5\xdc=\xf0yWA\xbft\n\x15\x0cT\x08\x10\x82\x0b\x08N\xf7\x19,j\x03\xd2\xd79g-\xb2\xb7\x93\xf7\xde\x06\x01\xe6\xb4\x19\xeao\xa3\xa7\xba\xd4\xba\xe8\x06\x9b\xdb\xe1\x04\x96\xb0\xf7\xa2}7\x83[\xd8\xda\xfe\xc9i\xac\nV\xc8\xc90cJ\x8e=e\x9d\xec\x1a\x90\x1d\x92\x83\xbbA~o\xf6\x8f\x1e\xd5F\xde\x86\xdc\xd1\xa5\x84\xec)O\x93\xa8\xcbrQv\x8c\xdcrr\\\xa9#\xdax\xc3\x17;\xe4h\xcc\x85\xe2\xfc\x1f\xe0\x04j\xf7\xf0\xd8\x04A\xa7\xd6Y`\x1a\xba\x17B\x8b\x19^\xaa\x86\x9e\x8d\xdfF2\xc1\xcb\xbd\x8fIi\xb4\x18\x81\xfa$\xec\xac7\xc7\xae\xfd?+9\xa5W\x14\xc89y\xea\xda\xdd\x88\x1f\xc3\x1e\x89\x15Y]\xed9\xf8\xd0\x8ct\xee\xe5\xb7\x81N\x8a\x98\xe5\x1c\xdc\xbe*>0W\xaee\xcdRT\xe9H.U\x80\xa3\xcbI@d\xb4X\xbd\x89\xb3\xb2)Q\xddC\xaf\x0e\x9f\xe0\xfdQ\xd4\xb3\x06\xa4B\x97\xc0\xc1\x03(u{\xdf/\xe027\xe0\xce\xd4q\x0b\xd3$:\x0eBiU\xe0\xa8f\xb2\x91\t\x84\xc7(\xa1\x18\x97\xdc\x98\rp\xa4\x88;\x85\x8b)\x83:!\x18a"!\xa3\xc4\xc9\xc9\xe0y\xe6\xcc2\xac0)\'P\xf9\x85\xa0\x89\xc4\xea\xbf\xca\x1e\xc2\x1b\xfd\'\xfa\x00Z\xa0E\xfb\x8f|\x98ol\x90\x1az\xf7NU\x02D\x9f\x18\x1c\x8e\x7f=\x8c\x17\xe3r\xae\xd9\x85\x1bn\x9e\x11|:/\xa2\x98t\xf9.\x8c\x9f\xd6\xc7\xcd\xb4\xd8\x188\x9c\xca0\x8dS\xcakQb\x02wi\xb8\xb5\x0f.\'\xf5\xb4\x01\xdf{\xda\x1a\xad\x8c\x91\x94e\x16`X\xb1\xe7\xba9\x99o\xf1\x15\xebTn\xa4U\xf2\xd1I=@\xb9\x81w\xbf\x13\xf1\xb4O\xed\xe2H?\x99\'\xc83\x9c&#\xd9\xbd\xac0J\x1fv8\x88\xf4UZu-o\xe8\x94\x1d\xb6\xed?\xe1\x0bJ\x0b\xdc\x95\xc6\x18g\xbf\x980\x88\xb5\xaf\xd2\xab\x1c]D\x9e\xbc\xd7(\xb4\xd3>\xd7\x9f\x0e\xd7\x97\xc3\xeb\x99\xd9\x1f\x9df\xa0=\x9f\x1ac\xd3\x97e\x8eK\x02\xed\x9d\x16_\xe8\x145\x16kio\xe8\xb8W\x82\xd6\x9cG\xe0\xb2\xf89\xa5`m\xc57kw}\'\x1b\x83\x8c!N\xbe\x82\xf8\xbd\x14\xd3\xb3BF\x9c\x80\xaf\xd2\xb3\xb1Jy0kp"\xd8d\x0cC\xf6\xe9\xac\xa7\xb4\xd10S\xd37\xc4\x86|\xd21\xeae0dt\xd3\x0b\x94 )\x0e\xf8\xfb\xc9\'\x86\xd7.\x06pP\xe2\xe8\x91\xe2~9\\\xc5-\x81\xed\x99\xa0B"\xd0\x82\xd30\xda\xc0\xe9n%R\xce\'Y\xaa\xe5\xc4\xd7|\x8a\xb2/\x14\x8a\xc7\x19\xa53|\xcfj\xd9\r\xbb~\x1c\xd6\xd4\x1c\xf4\x1f\xd4\xf1\x8c\xa5\x98\xed\xfc(\xcd`\xe7\xbd\xf8\xb9/\xe8=\x9e\x8b\xce\xd7\xbb\xc1\xa2\xe3l\x9c\xa6\x80u\xc5\x98\xde\xd1\x0b\xd2\xfb\xab\\\xf7dk(\xad\x98\xf0/\x1d\x99t\xf4\xad\x8c\x0e\x8aU.\xb0\xa4\xaa\xba\x96Z\x02\xaa\xef\xd0\x0f&\xfc\x83\xc8\x1c9\xa6\xe8\x99\x8b\xbe\xe0i\xf7Q$\x83 +\x81\xbdQ\xba\xf3\xd0\x80\xb3\x03\xfc\xe4X\x94\x86\x04\xd1\x12\xdfM\x96\x03f\x018\xe7j\x82Y!\xdf\x190\x8b\xc4\x91\x17\xb0\x81\x94\xb2\xb9n(\xe9\xf0\x7f>Q\xd36\xe0\x18\x06d\xb7\xf0\xad\xb2\xa5\x93\x0er9@\x7fF:\xe3\x0e\xe7"~gy\xb5\x8c1\x86\xf1\x04Wz\xbd\xd4c\x07\x87\x82p\x80\xef\xdd\x1e\xe9\xf6\x05l4\xf9\x0b\xaa/\x116ovq9\xf6VPx{\xc5\xaa\x9d\x9d\xa0KMa\x08E\xfc\xe5\x16\x88(\xbe2\xc3\xcaU\xdb\x818K\x823\xf5<H\xb3\xf5I\x0eg\xed\x85\x1b\xee\x18j\x94\xe0\xfbw4\xd7\xc4\x94\xb9\x10+\x1e\xa1\xadT\xd8\xf5\xfe\xf0E\xf02\xa6R\xcd`G\xe9\xe4i\x1b%ZMS\xc2\xe4vI\xd6\xa7e\xdd\x8e\x8fi\x1f\xcbp\xddx\x03\x15\x95mUR).\xda;\x07a\x07^\xd1{\xb1 fo\x11\xd3\xd0\xeep\xbc\xa5S\xfc{)\xcb\x1b\xde\x07\xe8+Byt\xf2\x04E`-:$\x02d\xe9\x17nUBw\x85?\xba\x8dO\xb7\xfaD\xf8 ;\x9f\xf0\xfe8\xa1L,%1QF\x9b\x0f\xd4\xfe7\xaaE\xf5\xe3,q\x1c\xd2y\xae\x0cm\xa8\xe9-\xe0{H\xd66\n\x85\x1fV\xd3\xcc\x1f\x04\x8f5>q_0\xf0\x06+\xc8\xcf\xd4y-\x0e\x08\x8e\x17\x82#u\xed^Z5\xf3\x9d\xdaS\xe3\xa1\x13\xc0\x96\xc4\xd0\xe1\x17\x17\xf4\xe4\x8c\xfbW\xc9\xed\xb6\xeb\xd9\x92\xd7Aq\xb9<\xb1\xcf\xc6\x8d\xae\xf17~\x12\xd4\x05\xc9\xdf\xb31\x88M\xe4d?c+\x91\xde%\x10\x96n\xa3\xe0\xb9\xa6\x9a\xdc>\x1bA}\xecmd\xd9\xf5\x89\x880\x8an)\x7f)\xa5\xdb_w9(\xda\x18\xa6\xd7g>\x11\xd1\xd9\x92k\x1dn\xdc\xe4\xe8c\x83D!\xd9S\xfdG}\x0f<j\xad\xa2\xf6\x13\xd5\\\x05\x02b\x03\x1aG\x8e\xb6Ry]\xe0\x8f\xfa\xfa\xaf\xf6\xe7b\xc5\'\'P\xf6\x93\x1f\xf7\xeb\x19\xc7\x1d\x83\xf2\x81NK\x14\xd9x\xc6~\xe7\x1e\x81\xf5\xdc\xc9M\x158A;8>>\xc2\xee\xc9\xa5w\x08R\xf3\xd3_\xc8\x05K9V\xc0E\x07\xac\x83\xe1\x8c\xef\xb9\xa1q>+\x88l\xef\xc0\xee\x81[\t\xbd5\x02\xaf\xa9\nH\xe8\x80/\'\xf3\x98\xe1\x0eg\n|\x81(\xe1\xdfKJ\xc7HjAV\xc7\xd1\xff\x98\xab`/\x8f\x19\xd7=\xe4\xe7?\xf2\xe4\xc1\xda*/\xee-\xfc\x9d\xc6\x86\x11\xe5\xb6Q\xeei\x81\x93\xef\xbc\xb9|\xd3O\xe4\x93y+\xa3\xe1\xf5\x9aQ\x18\x8b5e\x93[`k 7w\xdeT\xf8\x91\xc0\xfe\xbd\x9d\x11[r\xcf3\xd4{\xd2CW\xea2\xfbY\x87\x0cj"\xd9$\x85\xa4\xaa\xe4\xf8\xee\xf4\x84b\x8c;\xba\x997\xae~2\xbf #\xed\r];7\xc5\xc3<!Pp\xafv\xa1\x1ah1\x10\xf0\x9a\x03\xe8W\x04$/\xd1\xa50\x13\xb5\xf8\xff\xa8\xc0q\xd2Ii_\xcb\x7f\x7f%bB\xe6j\xdb\xeb\x11W\x1b\x1c^\xcd\xcb\x98<Am\xfe \xa0\x87:\x90M\x80X\xfaGY\x93m\xe6\xea\xa3+\xe2\xaf\xef\xc4\x1a\r\xee\xabD:\x9b-\xca1\x0c\xdf"&\xeb\xf9\xf5\x99\x98\x14\xa5y\xbe\x91{b\xcd[4\xd6\x16Kh@\xad0\xcaA\x92\x8dQ\x0e\x1e\xaa\xffA:\x981\xc2IX\x0f\x95m[XJ\xf3Q\xfd\xb19K\xb4\xc2\x85+\x8f\xda\x93\xf20=\x86\xe9b\xdapn(\xed\x10\xd2U\xaa\x0b\x06\x9e\xd6\xb0-&\xcd\x1e\x8a\xe9\r~\x90\x10\xdd\x91Y\xdb\x98\xfd\x99K#\n4\xb9^\\\xf1\x15K0\xef=]\\\xb3\xb4\x7fcv\x91\n\xfb\x86S\xb361\xe5\nBlzm\xaa\xa8\xc3\x05h\x9e\t\xe5P:\x1c\xd8Y5\xe9Y&\xd1\x84\xe3HT\xfc\x9a\xdd\xa2\x17K\x85\xf5\xdbd\x91-^n\xa7\x1c\xf4:\x91\x17\xbcf07\xc50\x10\xf1\xc2w\xb1\x87\xafuk89\xb9Z\xf5\x19\x0fr4\x8ei\x86\xd59\xeb&'
|
|
|
|
|
|
2024-12-14 17:54:48.235988 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25561
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808817029
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.246406 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 5880
|
|
id = 47919
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf587
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808817029
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xd0\x9aW?\xc0\x06\x9c\x94\x1c\xe2\xb2\xa03{r\xa9\xc3ct\xeea\x95j\xd0\x80%\xaa\xb5\xf41?w\xdd\x9d}\xfc\x1c\x94bY\xe21\xb2]\n\xbdw\xeb\xbb\xa92TP\x16eC\xe7g\xc3\x96H|2\x1e\xf1\xa0EL\xc9|\x87V\x11\xef\x8b\x9e\xa4\x07\x99\xa5\xb0\xaf\xed\xee\xe7\x8b-\x0c\x05S\x80/4\x84zk\xc8\x83\xddY\x15\xd4\xf5+R\xb3\xe3\xdeO\xa96Q\xd7\xda\xa9\x82\xc8\x88\xabt\x06\xd2\xdb\xbf\x08\xe1\xab\xce\xfc\xbes\x9b\xa0\xe9A\x97\x11{\xb9\x1e\xfbO\x11W\xf3#\xa1\x0b\x96\x87z\xbb\x8b\xf2<\xe9\xedn\x1d\xa1f0\x07\xfc+\x97\xcf\x19}\xc8\xbb\xb8\xcc\xaf\xba\x9aD\x8f\x10(\x01<\x1e\xda\xf85\xfbm\xcb\xf4\xd4\xb9\xc6\xe2\xc81\xfe\xdf8\x9a\xed\x06\xb9\xe1\xf8\xbf\x0f\xda\x9c\xeb\xd2\x86\xa2\x1b\xa66\xaf\x009\xc7`\x07-}\xd42\x85\x04Z\x9b\x83\xf3\x82T\x16t\x89\xed\xf9#L\xef\r\xff2\x18\x89\'|\xa1\xd3\xb4\xcf\xeaL\x81\xd1\x15\xdb\xd2\x1b*x7+\xd1\x00\xc2\xdf\xf8N\xe2\xce|\xdf\xdck\xc2#\x04\xbb\x8d\x1b\xc1\xfa\xa3q\xbe\xc3P;\x04\x9e%\xceG\xbc\xd3-\x8e\xbd\x83\x18\xe3\x05\x05u~(]\xd94\xc9jP\xfa=\x80\xe1G\xab\xea\x9b\x004\xe3\xe2#f@a\x957\xcb\xe2\xcf\x9dFh\xd9/Sq\xbe\xbd\xf5\xc4\xfaS\x88B\x193d\x85HJ\x1a\xe4\xd04EYu\xf6\xd9\xf0\xdd\x08\xd3M\x8cp\xd3\xeb\x97\xcd\x04\xeb\x7f\xd3\x8cn\xecT\xc4\xaf\x90\x99\xf3\xd8\x19\x08\xea\x99\x93\xc34\xb9h\x89X\xf7\x06\xe1\\E\x99\xdcv\x12\x8b\x96\x9c\x02Ezjn\x8d}\x05\x9f;\x03\x90F\x9e\xce\xa2\xfd1Ug/\xd7\x81\x84\xb1\x98\x7f\x98\x9fb^;g\xef\xd8\x1e\x196\xb2\xe9gn\x8d+\xd1\xfb\xe4\xc6\x1d\xef\x1c\x03\x16\x03\xa0\xfd\xe7\xac$\x92<\xa4\x98\x8e@\xd1;\xab\x1d\xd34\x85/^\xf9\xf3\xc0\x9b*R\\\xd5\xd9{-:\n\x8cV!=\xca\xac<\xca\xfe\x01\xa8.r\x13l\xaf\xa9\xff"%/\x9d\xc3\x1d\xa0b\xcdJ\x8a\xb4\xf3\xfd\x9d\xa1#\xf0 \x88\xa9j\x96\x07\xfc~\xb2\xe4P\xc6\x85\xa9_Z\xab\x91g\xde\x87\xc9\xfeC$i\xdc"nP\xa56-ie\xed\xfd,\x8e\xce\xe2\xe4\x97\x16P\xfc\xa5^\x0b"\x14y\x87\x95a\xdc\xc9dr\xd5\xf8\xb5\xa4R\xe2<fL!\xb8\xf2\x7f\xeb\xe7\xd2\xa1++\xe4\xf1\xf0\x97\xc4&\xaa\xc3!x\x80\xb2\xf3\x9e\x1e\xfb\x05\x80\x80\xe3\xccEj\x0cZ\x0c\x024>\xa7\xdc\x0e\x81p\xc1\xdc\xabqh\x1e\x89E\xf0\xa1\x81\x8d\x0cg\xa9@\x04\x92\xd6S\xc0\xa73\xa3\xc4\x17?:4\xfe\x84\xa5\xfd\xd5/a\xb7\x8a\x08\xd3v\xf4M5h\xa1\xa7<\xc6\xa1\xa3|w\x1fg\x99\x1f\x87%\x1bn\x1c.\xea\xf4\xf1\xc6\xc9F\x18t\xfa\xba\xc6j\xb5V\x15\x8c5\xa0\xd1\x02\xf2r 9\xd4\xf9\xf8\xf0\xf5\x0e+v\xde/y\xd7\\/\xc6\x7f\xc4&\xa8\xb7\xff\x97\xf9C\xeb4\x1ez3,\xeaDd\nQZw\x84\xd6\x86.5\x05w[\xe2M\xca\xa7y\xbah\x87\xd12>\x93l\xdc\x17\xcf\xc3xR\xb9\xea\xd9aH\x828\xc3\xce\xb0\xe4\xd2\'\x9c\xce9\xce\xca+\\`\xa4\xa5\xb4\x02\x95\xfaI_\xae\xbc\x94\x1e\xd26\xbd\xbdT"_\x9e[\xef\xaa \xb0H<dhi\xf8TvrEm\xc3>\xb0\x1d\xdc\x01!MH\xe4Oo\xc6\x0eH\xeay\xde\x98(\xca\xe2A\xdf\x06\n]\xdd\xb4\xbaD\xda\xe3\x17rJ\x1a\xb2}\x7f\xfb\x84\x84\xb4B\x10I\x8a7\x95:\'Y\x17\xa3\xf7\'j7>co\xed\x13\x8f\xa5GKW\x00\xa9\xdf\x98\x82\xd1c\xffo!\xa7\x8c\xb5\xc2{\xdd\x0b\x19\xcd\xf5|&/\xd6\xc8y\xd8\xd4F-\n\x97\x9d\xc8lyd\xc5\xccU\x16)\xb2\xf9/\xb4\xc4\x0fn\xdb\xf9\x9a\xc9\x0fTb\xa1\x99\xf8\xf9\n6\xbdg\x8b\xe0\xbf\x07\xdd\x92\\\xeeT\xb6I\x87q\xe9\xdf\x04\xba\x12\r\x96\x08T<\x9e\xcd\xe6fX*[\xc14\x10hU\x08;\x06\xef!b\xd1\xd9\xef\x00\xc3\x97\x91L\xf1\xb6\xe5\xa2\xef|-\xa56\x0eafY\xb7f\x9a\xdaW\xb0\xb1$M?\xf3\xf1TG\x8f\xb5\x03\r\x18\xe0\t\xbe\xd3(\xd1\xc2\xcf\xe8HDZ\x11\xf0\xcc\x8d\xf1\xce\x87\xfa\xdb\xc2\x1fH\xed\x11\x81\x1c\xf7/c\xd7|\xc7l?.\xc5t\xa0\xdb\xeb\xbe\x1a\xe6_\xe5\xc2\x93I\x87\xafn9?\xd7\xbfW\xe9\xdfN\xd2W\xb5\x8b\xf7\xa2v\xaf\x1ar\xba\xadL\x03M.\xec\x06\'~\xc6(cW\x14f=c\\B 1u\x89E\xa9\x15\xce\x12L\xa1u\xc6\xf5jW\xf7]\xfe\xf2`\r\x8e\x9b\\\x93\xf49\x8a\xe8\xe4\x9f\xfa-o\xff\xe6|\x84\xce\xf3>F\x98\x80\\\n\xd9\xd5\xb2\xde\xfd&K|\x8a;)n\x0f+\xc6\x7f\xca\x04R\x15\xdc\x07~\x1d#\x8f\x08\x02\xf8\xcd\x14\x16<\x8fr\xdc\xa5I\xd7Z\x05!Swoc)\xe9\xdcb\n\xa2\x07\xeb\x9c\xdb\xaa\xaa\xae\xa2uoJ\xad\x10\x8b\xa7\xe2\xe1\x94\x9f\xfdY[u"!2\x87\x82*K\x03[\xc87\x9b\x94\xce\x03?vl\x85\xec~\xee\x06\x01\x92s\x8c\xa9C\x1c(\xf9\x9c\xfbXE\x13aZ\x93;\xfd\x1c\x12\x98\xd3\xfd\xb7\xd2dzd9\x0b%\xf8\xa9xA\ni#\xb8\x1a\x876M[\xa5\xdbJ\xb5wc\xc0%[\xf6\xbc\x98\xa3\xc2ew\xfc\x9fk\xa97\x8d\xed\xcf\x8c\x82Ib\\o\x92\x03;\xdf\xae}\xe3\xe7\x86H$\xbfa}K\xf6\xc8\xb1\xa5l\xcc\xc0B\xca\xe1\xb3\xdb\x86CL\xb4\xc3z\xa1:>\x98\xf2\xcfk7\xc6\xe76\x9f-\x91m01M\xf5\\\xf5\xde\xeb\xd0{\x04\xce\xcd\x87k\xcd3\xc2\xa4\x84u \xb2\x02\xcd\x8e\x9f\xf9jb,\xbd\xf7\xb6\xd8t\xaa\x9a\x06\xbd!\x05\xff\xe1\xde\rbB\xc8\x7f^\xbb\xf3)iyk\xdb\xb6\xb7\xf4C"\xbe\xe2K6 \x86\xcf\x84\xa9p3{\x85w\x9cU\xd7\xfa\xb7e\xc6\xd1\xf2nV\x17\xde\xb4b`6\x00X9\xac\x08\xc3\xbc\xb8\xe8\xa88]^\x9f\xa45\x0be\x95\xb4};\xa2uq\xc5\\P\xa2\xd7\xeb\xbfo9\x1cAB\xcc{\xe5\xa4\xe7<n7\x0c\x80\xd2 ;V?{m\xe1\x8f\x9c\xf7k\x08\x1ed$\xeb\x01Hq\x00hJ\xe5\xee\x1fJ0\x89%\xb4fu\x08\xb1\xad\x9d\xefY\xf9e\xbd:\x94\xf6`\x0b\xedH\x8c\x8c\xe2\x08:\xeaS\x0bS\x98\x9d\xf0EA\x11\xfc\xf1\x0cY\xffN;\x1a\xdc\n\x01w\xca\xde5\xb2\x1b\xd0bJ,\x01\x8e\x91\x9c\xb6H:\xbaO\x05\xb8VC\xdb\x90\xc2\x98b"\xc9\xcbx\xb9_\xcc\xb5\xa7l\x9d\xc6(\x8dU\x86\xc7\xb1I1"\x8b\xca\x03\xb7\xf1\xbf@z\xc6\x0c\xa6\t\x9eUx\xb7iW@\x1d\xa5\xe5c\xf2\x19pjM\xe6\x8f$\xfa\x98\xf3\x10+.Ggr\xd4\x8f\xd7Q\xed\xe5\xfe\x99\x07*\xe0\n\xf5*\xfe \xd0L*t\xc7V\xc3\xbc\xdbR\xa7\x98\xf2\xcf4+/O\x0bG\xaf%0\'\xf6}\x06p\x1as\xa8\xe1\xa5\xcb\x03u\x8b;c\xc0\xc0\x1b\xc2\xf6\xb1*J\xc4m\xa6\xc4\x07Jyx2\xf6\xd6\xc4\xc9\xe4gL\xacI\x83\x04\x88B\x02m\xbbTK\xd4\x84u/D\x11o\xc9Y\xbdc\xfb\xb9l\xff\xac \xf4\xfe\xaaz\xd8\xae[\tZw\xf1\x84\x8c\xca&\x9bE)\x95\x94\xde\x01\x10\x89\xe7Uc\x1d"\\/9\xa5-\xdc\x87\xb6U\xccH\xb9\xb7\'\x9b\xedv\x02eA\xa2\xf4\xb0\xd3\xe9\xc2\x8a\x92wI\xd6,\xe1\x0c\xdd\xa6bJ\xa8\x9d\x0c\x8a\xe9,\xaaE\x1e:x\x98\x8cQ\x8e\x89\xeb\xaf\xb2*\xad\'\xfbG\x10\x9fl\x06\xfd\x1b\xa8g\x06\xfcBR\x1f+\xabs\xa2>\xf5\xa5\xd2\xaep\xe8\xca\x84`\x7fG<\x81\x08RT\xb7\xe6\xa7k\xb2)\xf1\xbd\x0fS\xaf\xa0,\xaaupE\xb4\xac\x93\xb2%\x0c\x01dB\x9f\xd3-Q\xc8\xe6\x80\x00\xb8\xe1O3}q\x02\xde5\xbd\x93o\xc7\x17\x80{\xb8\xce\xd6\x96\x9dS\xd4\xddUs.\xb1~\xdbV\x99\xb2\x8b\x00\xe5l\x8b\x92A.\x02\xe6x>\xcb\xb17b$?\xb9{\x15\xbe\x8e\xe8\xc5\xe7=%\x7f\xec\xfb\x99p\xb6f\xd3\xc4\xfe\xa1\xee\xeb\xcb\x8f\x97\xad&\x19`\xd7\x83\x01\x9a\x95\xd1\x13Q\xd5\n\x8f\xc9\xb5\xcd6y\tN\x02\xdaU\xdc\n*\xfaD\xe1\x97\xf6\xcd\x16\xbe\x8b\x16\x9d\xa1\x87\xc0\xa4\xa5\xc9\x99\xe4\x94V\xe9\xb9\x00\xed\x1a\xaf\xb0\xef\x1c\x96\x87\xf4;uffO\x91\xe0\x0b]\x19%\x95~\xaf\xd6jZ<0A\xdeL\x97J\x14Y\x1fS\xa0\x83\x90o!\xb0aV\xa8\x1e\x0e\x07\xda\x1c\xc9A\xac_\xd4\xd7OY\xc5\xb1\xccu\xf2\x9b%\xc1p\x0f\xc7\xb3j\xa6L\x03\xe3L\x113\x9d*\xe2_1\x93\x88\x9aF/\xfe"\x1f\x05\xff\x03\xae\x01\xd3\xfa\xeb6R\x0f\x11;WE\xd9\x10\xd0R\x01\x17Ml\xe4\xb4W\x9a\xb5\x0eh\xde\x921*,j\xfdkul6K\xde\xaa\x06o,\xaf\xd3\t\xd9\x06\x18\xfa\xd8\x9di\xa1\xabr\xb2C\xc1\xce\xc9\x1f\x10\xcarO\xca\xd6=\xcc\xbb\xf4\x88\x9e\x93\x83\x87\xa2\xddU\x0c\xaa\xf3\xb9d\x8d\xe0\xfb\xb6\'\xb8\xac\x86%\r\xfd\xc0\x8e\x14\x02\x17c0\x94\xcf\xda>G\x0e\x121/K\x1f%7\x94\xe8~\x12*\x0f\xc5\xcd\x1f\xe5He\xa1j\x99o#\x13\xc7C\x9dBH\xc1\x87@\xa3\rG\xc0\xd6\xb7\xa1]\x1c^\x9e\xc0\xfe\x1e/\x02\xf3\x1e\xcd\xd0N.g\xc0wP\xe4\x03!\xd8}\x02~\x8a\xf6\xea\xc2\xed\x1d\x82\xeb\xd6i\xe0\xfbiKy\xc9<3+\xb0\x8d\xf1\x15\xf2\x03\rd\xf7 \x01\x0b_\xb9\xf9\x84\xbf\x95\xca\x8d\xe8\x95\\\x1eF\x85\xfed?\xba\xf4\xa4\x9f\x96D\x1f\xbf\xb5j\x9a\t\xda\x8c\xb0s\xa1e\xda\xa15W\xe6j\'\x13\xfe\x83G\x84g\nd\xa1\xdc|\x03\xd2\xc3k{\xb5\xd0\xc2\xed\xc6\xe9\x05\x1d\r\x07\xe0&\x1e_\xd3B\xca\xf2\x91\xc4P\xc9\x81p\xed\x04L\x84 \xe0\xfd\xf3\x01d\xa1\xb2\xeb\\\xcd\xa9Z.\xab\x1b\xa7\xab\x17W\xdba\xca\x1e.3\x05\xacE{\xa9\x83N\x1e\xc9spx\xf12\xa9\xc4\x17\x03\x03\x00\x1a\x14\xad\xc2\x96\xf1\x1cg\xa7\xaf=t]Y\x07\x02d:.\xddJYvUlR.\x17\x03\x03@\x11]\x05\x16\xc4@\x95\x99\xe8\xac8\x9am\x95s\xb7\x8ex\t[\xf3\x85\xd0u\x18g\x1esP\x81\xc1\xf2\xf1\x07\xf2\x9a\xc0\xb2\xb2\x9a\x80\xff\xe7\x97~\x9d1\xd1B\xd7Q\x1f!JE\xcf\x7f\xde\xa7\x07\xed\xba\xa3\x1c\x04\xf9\tj\xa39z\xe5\x19v\x84\xbb\xc2!\x93\x15<\xaa| \x8d7W\xf3\xe3\x9e\xd6xN\x15\xd7\xf0\x8d\xf5\xe9\xf6J\xc4\x1b\xea\x0br`\x1e\x8e\xc2s)\xbe1\xecAE*\xa2\xde\xbes\xebC\x84U\xf0O\xc5I\x8d?\xd1m~K\xa3\x03\xcag`;\xb4\x06\x10\x1b{\xc7\x00\t\x03;\xf7_\x0b\xb6\xdb\xc5%\x8fu\xe7\xac\x14\x01\xaf\x91N\xa7cty\xf9\xb8\xe3j\x84d\x9f-x \x80H\x13\x92\xb3\xf4\x9a\x97\tj\xc4T\xc7\x04\xf8\xc1\x00Et\xa4\xbbp\r\x87v\x9a\x03W\x00\xa1\xff\xb81E\x9a\x93^`\xcb\x96\xeb\xd9\x9b\x85k\x8e\xae\x03\xac\x0bh\x07\x9f/\x8a\\\x13\xc5\xcbGv\xb1\xdf\xb4\xc3)\x0b\x1c\x8f\xdb\xe1\xb3jz\x03\x1e\x8c\x1e\xbfF\\\xd5\x14\xa0\x08\xc6|\xaf\xd76Nj\x90\xd2\'\xfaRZ\x85\xfcF\x1a\xaa\x91\xca\x8b(ik\xc5\xc1\xa4\xdb\xc5\xfd\xf8\x03\'\xe2&\xfb\xf3\xbb\xe0\xf3\x9b\x1d\xec\xf0cU\x1d\xf2\xcf[\x85\xf4\xc7\xef=\xbe`ju\xed|\xf7\xb8\xcer\xe82\x8f\xb3\xd8\x19\xc4\xfeO\xa72\xc6\xd7U\xaaO\xeeQ\x02v\\\x13\xd8\xb3L>\xfc\x86<\x823\xe9\xc7[f\x8e&!\x0f\x87"Gmz\xca|W\x8f\xf4\x05L\x8ea\xa9|\xd71\xa7\xbat\x8d\xe9\x17b\xe7\xb3v\xa5\xd3\xdd\x96\xebQy&\xcf*\xc9\x19\xa1\n\xba\x89v\xa2\x002,\xfbe\xae\x16\xc7R\xff\x1d\x89\xa7\xff\xd5\n\x82 /\xbe\n\xfb\x9c&\xea\xba\xbe\x07\xe3\xf7u\xf7dZ\x8f?\x19\\\xc4S \xae\x81|\x8d\xf8&ve)\xb2\xb0G~D~~L\xa7\x1a\x17\x9eWC\xee\xda\x9e\x83\xf0\xe4\xbcd\x06\xa1z\xe9B\xae\xd8\x16\xd9\x9f6\xf0j-\x8b\xa0\xa8B\xd4]h\x8c\xd84\x13\xbf,\xb27~\xaa\xc9\xce\x8e^\x8dfA!\x03\xe1\x14\xf1\x16\x9b\xb0\xc9#\xd3}\xa0\xa0\x0eq\xe2y\xc7j\xb1\x02\x964\xfd\xf1\xfd\x1fU6\xde\xb0\xa3Q\xce\xca\x99\xa7\xd4\t\x95\x86l\x92j\xb7\xcf\xb7\xa1\xed\x96\xc5\x14s\xea\x8dM\xd7l\x04y#\x15VE\xab\x8f\t\xd8\xa6\x88/\xb5Z\x99Q\xf9\xafw%Ju}\x11lF\xf6\x8d\x91DW\x1e\x92\x1d\xb7\x0b\xe9\xe0{\xde\x99)j\'\x0f\x04\xfc5\xc3|*W\x87_!8y\xa9\x02\xe6\x02\xf646\x90\xa4\xe5,\xc7C\xcb\xf2\xd4 \xee\x92F\xc4\xdei\xdc\xcc#\xd7\xc0\x9e\xc3&\xedBuI\xe90\xc3\xb6#\xa61t\x02\x90]\xfd\x9f/c\x9d+\x834\x95B\xea\x9f\x93\'\xdf\xa2$\x07\xdd\xdf\xc8\xdb_[\xec\x0b:3\x92\xb1\xb8W\xaeS\xce\xd6\x02\x18I\xa6"\x82\x1bh\xd8L\r\xd8G\xde\x08\xd8\xcdo\xc4N:\xbd?\x95\xc1-=\x9b+\x84\xb1\x80\x11\xdf\xdd\xa8p\xd5\xd8LPk(\xe4\x07\xdc\xc2\xd5\x13C?\xb1\'\xa6p\xd3uW[\xeb\x84\xbd&!\x97\xc4\x8d\x87\xad\x1f{\xc8n\x1fOC1\xde\xde\xdd\x82\x0f\x8bc\xf9\xe3\xa9A\xba\xa7\x0e\xda\x8cR\xd6\xcc%[\xd2p\xc54\xdb.\x06\xafz|\xfe\xf8W\xa7\xe5\xd8\xd7:\xf4i\xf6/\xfdeY\x91\'\xd2\xfd\xb6Y"\x8e\tTK7B\xdap\x9e\xc8P\x02~\xb1\x13\xd3\\Wh\xdbW\xd3\xb3\xa9\xbfX\xf9\xb8\xd0\x01wr\x16T\x10N\xd0\x86o\x92\x8f-\xe2\xba{\xa70\x90\xe9Q/8\x9e\xf8\xb7r\xcc?\x136\xd2\x83\x8e.o{v\x83\x8d-a\xbd\x04\x9d\xc1\xcb\xdd\xbaj\x99\xc3\x98\x95\xa4\x8e"\x83\xe0\r\xb7?XkC\x93\xf1\xb0\xb6\xa2!\x80\x013=b\xb6\x9f\x11j\x8e\xc7\x8f\x91\x8e\x9df\xe6;ha\\|\xdc\xaa(0\\\xe0t^\xfbg\xb3\xa3l\x9b\xde=\x05\xe2\x816\x05\xb1\x9c-\x18\xafu\xe8\xe6\xbc\xdfQ.\xe5j\xcd+\xdc\xddc\x19\x071\x11|k\xec$\x8fA\xf5\x1f\x13\xc2\x91bN:\xf9w\x15\x9c\xe4\x12\xf7R\xdd\x17VS\xdc\x85f\xc9X\x82z&K\xb7U]\x0b\xb2\x1a\xd9\xdd\xdb\xbej\xdc\xfd\x7f\x172\xa6\x81\xc7y\xdbeV@\x8d\xb5\xec\xbb\xcck\xe0m\x8b\x02V\x17\x8cF\xf2\xa9\xf2\x18w\x0f\x0b\x7f\xb06\xabqf|\x8f\xe4\x10E\x16\xf8Z)\x8cI\x1ej(\x8f=\n~.\xf8\xea_\xe1\x86\xf1\xe3\xe3d\xef,\x95:-\x1c\x0eQ&\xb9\xef\x12\x1b0u@\xc6\xd9\nNE\x89\x82\x18\x9c6\xf00\xc6\xcds\\-K\x8a\xa0\x80\xf0\xdd;\x94\xaa\x05\x81E(\xfeP\x8f\xa9\x86\x08\xe40}O\x95\t\xee\xd4\x99`\xee-c\xc0\x12\x05g\x1b\xaa_gi\xf4\xe6e\xdd\xb4\x83\xf3\x82Lu6%)j;l\xbfP"\xbc\x1c)\rc\xe3\xe7\xfc\xe5\xd1\x84c\\mY\x878%\x9c9\xe1\x00#\xd8!\xf8\xe0\xa7\x8cI6\xfa\x16\xc65\x0e4\xf7\x14y*E\xb7V\xf7X\x90\x07\x85\xbd+\xa0sP\x9f\xad;\xd9\x07\xefr\xf0\x83\x8c\xa7S\xb8S\x7f \xa7ut^\x13\xd0/\x84\x81K3o\x92\x07\xca2#\xa2W\x91\x8a\x030K\x8a\x8fl\x81\xce[~\xe7\xa3h\xa5\x89\xfa\xd7\xfb\x90}\x0b\x1f`\x99\xd4U\x0b8\xd5\xf9\x82\xa6%68\xca\xbd\x90n\x02F\x11\xab\x966\xb9\x96b\xe1\x92\x8cr/\xdc\x8e\tb*\xec\xa3\xd6\x80\x04\xd9\xb7\x05\xed;^<\x85\x84\xb8\xc9\xf5o\xa5#\x8e\xb3\x8d\xda d\x1aY\xebu\x87\xca\xb7\x04b\x9a\x94\x92\xf7\xbe!F\x17\xeb\x8eK\xb4\xa9\xeau\xa7\x13\x8d\xbc\xa5"\xb1\x93e\xd8\xff\xe1\xe3\xbb\xeb\x1ak.\xce\x0eq\xa6I\xfd\xfc\xccg\xe6\x0c\xeaO2\x04\n\x8d\x08\x1b@\x92\xcb{\xf5@D\xa5m\x05/\xc5\xc7\x9a\x97Y\x8b\x00\xbe\xcb33\xc9\x04\xaf\xb6\xe7\xfb\xba?\x07\x15\x89\xfc?T\x8d\xe6\xa8\xf9{\xb7l\xdf\xfb1\xe2\xfa\xd3\xa2\xe8\xd5\xf9\xa0\xf5\xdaF\x7f\xa0\xa5\x8c\xf0\xafQ\xe2`\xfc\x8fMQ\x8a\xfc\x92\xad\xbc\xeeR\x15,\xbf\x00\x99\xa2x\xb7\xc7\xaf\xb7\xe3\x13\x8a!\x9f\xd2\xcb\x89\xb8\x84\xd5\xf5\\\x16\xe1W\xad\xa3\xf5,1\x95\xfe!<&HR\xe7\xd3Yu\x8f\x86\xabO\xd1\x17$^Pd\x14\xf0\xef\xd6k:\x14\x82(\xf5\xe7\xb4\x1e\xea\x02\xe5\x9b>]\xb4\xebs\x88\xf3Y\xce(E\'\xa9\xde\xa4)\x94\x9f\xfb+\xfa\x8f?\x7fzd\xa8\xfb\xce\x8b\xae(Y\x0f\xd4e\x0e\xa4\x0ec\xf6\xac\x9a\xfb\xf7z\xb1\x84\x85O\x85\x058"\xec"\x81\x1b\xb3\xb2\xb6 *U\xdfn#\x0f\xde\xbc\x0eO\x9ft\xb1\xffW\x830c7\x1aV\xbd\x0e\xe2\x7f\x96\xdd\xc3!\x1bY\x0e\xf7\xd5\x1d\x0b\xb15a\x9d]\xe6\xf4\xf3\x8a3Q\x86\xc9GI]\x18\x18\x9fT-\x9e\x06!\x85\xdb 4\xa59\xa3\xfd\\\x0f\xad\x19"ymE>\x9f{\xb1ZWV\x8e\xfa\xc7q\x8e\x90\x94\xc6T\xf1\xc5\xd7D\x08\x98A\xb8i\xde\xbb\xa4\xfbSL\xbf\x8d\x87\xe5s$\x0b\x95\x99\xbf@#L4\x8b\xec\xbb\x19W*\x11\x03\xba\xeaG#\xe95p{\xd3\n\xcf\xb8cS\x8c\x05\x88X\xf7\xa5O~|\xb0D\xaf\xef\xb8\xaf\xdd\xfe\xd3\xe0\x97\x8a3%n\x89H\xe1\x05\xceF\xe4c\x15\xaf\xe0\x12\x8b#\x9c\x86\x82\xffv\xd2\xfc\xf5d\x1f\xae\x16\x97\x0eI=\xe7\x993s\x8bI\x8aj7A\xb5[i?\xd6X\x19\xfbEc\xc6\xf2\x1c*\x15\xc6\\\xa1\xcc\x82\xf1\xc4fEk#\xcf@\xa2\x96\x8f\xe1\t\xdf\x17\r\xaci\x1f\x02\xa6\x0b\x1c\xbc\x88\xe5\xf0\xc3\x06\xa2\xcf\xf7\x7f\xcc\x1a3/\x83\xbb-\xb3\x8b8\x01\xc1\x07\xa7\xe0h\xcbLi\xd0\x1e\xeb\x97\xf4C\xf0^T\xe1\t\x9d\xacc$\x05\xaa\x8d2\x92\xed?\x1bB\xf1c7\xa5[ \x1e\xeb\xa7\xbc\x0f*\xea;\x1e\xc3\x88(\xa2\xba\xd3\x98\xa3B\xbb\xa4R\x8a\x1d\x08G\x8b\xa3`\xf3\xa6";\xae\xea:i&\xdd\xd3\x91<\xa0\x12@\x12\xec"\xa7\xaey\x12`(H0\xed\x90\xde@\xe5~\x9c\xe6H\xdc\x91\xfeK\xd0\xbb\xe1\xe8\xa2\xd0\x02\xec$g\xd2C\xe3\xcb&4\xce\x16\x8a%=\x18\xeb\x0f\xee.\x1e9\x99\x04\xc4\xaf0\x9e\xa1S\xce\xeb\xe0\x13\x8eZv&\xc0\xabo\xa2I\x98\xd4\xc7\xdfw\xf8v#\xbf{O\xdb\x8cT\xf7\xd4bL\xd6Za\x8e\x02\x94\xd0\x93\xf3\xad\x8b\x02\xa22\xd5\'\xea\xbcr\xffP\x00\x9e\xe6\xafC\xaa\x15\x1c\xb7\xad\x80\xec<\x9e\xc8\xb5\xf7\x81m{\xce\xbb\x8f\xfa~\xf3\x90\xc7B\xd0a\xacg\xe6\xcf\x920rY\xda\x16\xcb\x13E\'S\xd1LqF\xb0\xd7\x1e\x9e\xac\xf9\xbe\xae\xf7\xe5p\xfbh\xde\x03\xbb4\x02\xa0\xd8\xce\x0b\xd8M\xe7\'\xab\xf49?\xe20\xa0\xbb\xd7\x1a\xeb0\xd1\xfc\x82\xa1,\'\xa1\x14\x96t\xa8\x98\n\xa6\x1f\x8bk\xcd\x9e\xa7\xb2\xf9M\x01\x1fw\xacG)\r6\xc2\x17\x84.\xec?\xe3\xbaP~\t\xfad\xc1\'=+d\xe15\xb5\x91D\x9a\xd6\x89\x90\x94}\x12\xfb\xb1zf\xc3f\xd5\xfeSM\xa7\x852\xf1\x99\xac\xf3w\xfby"\xbbhJ\xec\x01\xe7\xa1>\x80\xd94\xa5\x93\xcdgv\xc7 \xc6\xb9\xba\x19IL\xca\x0c\xc7\x14g#\xf3\xca\xe3\x84\x93,\'\xc1s\xfb4Bw\x1cVmV\x9d\x06\x0ex\xa7&\x83\xaa\x98\x95\x8e\xfaw^\xa85\xb5O\xda\x97q\xd4\x9b<7r\xf3\x08\xcc>\xb1A\x1d\xedFv\xd3\x95\x8e\x9b\x9eKf\x98\xcb\xbb\x82+\xe3\xb4\xef\xc7\xc4\xea\x85c\xf9\x0f\xf84\x94\xa8F:\xed\xd3\x8f.\xf5\x1f%H\xa9!\xc8\x00\x0c/\x04\xbc\xd1\xe9\xf0\xdeS\xa1\xd4\x87G\x05\xce\t\x08\xf4\xcb,\xb9\x91\xb0\xf6\xb8\xe3\xd4$9\xff\x0e\x03^5\x17\x0e\xc7\x1a\xfc\xdf/\xce\xb6\xdc\xe2\xc0\x08\x19kJXY*\xfab\x12\xe3\x15P\xe4\xcf`\xafo#-\x11R\x8c\x8f\x16\x102\x05m\xac\xdf\xd1x\xce\xa6\x83\xd4\xa1\xfa\xb93\xbd\xab\x1elR\xa8\xae :[\x91\xa5\xfba\xf5\x81\xb1z\x19Z-\xe7\xa4\x8f\xe4\'\xf9e`\xb70\xbf[\xf4\xcd~\x8b\x08\x03\xa4\x81\xf5\xb1ue\xd7\xbc\xdb`\n\x84\xc3\xaf`iWu\x8d\xbf\xde\x14\xb8\xd9\xbc\xa3.\x8ft\x99J`\xfc\xc29*W\xe1\x98l?o\xae\xb9d\xedJ\xb369\x87\xec\x9btgA\x15"\x81bZ\x85\x1fv\xaeeA\x1d\xcb\x90d\xc5D\x1eI\x01\xd1\xc9\xd4\xc5\t\xa3\xa7-\x0f\xa5\xf0\xdckL\xb9O\x179\xf4\x01#\x87\x11\x96\xdc\x91\xfc\xb0\x1b\xa8\xfb\x8d\x82\xd1%\x87X\x12\xe0\x03\xb63\xa0\x9ec\xf4.\xe2$%\xc8\xe7\xd5\xec\xf6"\xf3P\xc6\x1as3\x97W\xfa\x929u\xd6\xa8\xd9\x89\xc7\xc2\x9d\xb0\xe2/\'~z\xd7\xf2\xde\x7f\x1a\xb3\x91\xbd\x90\xaf\xfe}i\x9c\x0e4\xa1\xee\x8d\\\x96\xaf\xc1M\xe66!\x00?\x88Y\xc9S: \xfc\xbbw\xd4\xdeRj%\xe2\x14\xbc\xb1-\x9fX\x95\xeer9\x0c\xc8\x81\x17h\xa5qHt\xfe\xfbwU%e=Wg\xd5D7\xc1\x8b^\x98\x90\xf7\xd1\xe6\x179B\x12\x80\x8dlQ{\xd6\xb4IzK\x86\xc8\x85\n\x11~\x8dQ\xfeD\x95\x11\xef\xabD\xb7\xd9\xa2\xeb3\xfcq\xbcE\x80c\xaa)\x92\x16b_/\x8d\xb9tt{\x88m\x99\xa2\x18\x9bx2\x13J\x06\x9f\xa2YT\xb8\x0f\x9bn%\x859\xa5\x12\xe8s\x00\x8a{\x8e\x1c\x13\xaf]\xdeB\xd4 \xcb\xbd\xa11\xd7\xa1e\x8c\xd9\xe0\xb3\xf8F\xeb\xa6\x8d\xaa\x10\xac\xfc\x1dE\xbd\xda\xd1\x88\x98\xde\xe8=hj\xa6\x92$\xc9\xf5Tem\xd2P\xd6\x01@2\x1bB\xf3z\xac\r6\x02wx\xa6{z\x03]\xccR&\xc2\x9c;$\x08\xd2\t\x90E\x1a@mw\x8b\xc3\xd4\x07\xbbd\x1d\xc2\xdb\x95\xd9\xfa\x99\x8f\xf0n:\xde\xb5:\x1f\x0e%\x98\xd8\xba\t\xd7\xac\x91\xd8S5\x9b\xcf\xeb\x9d\x17\xce\xcd\xcc\x85\xe1\xcb\xfb\x00R\x9a:Z\xad\xf7\xf1\xdd\xf4z\x04\n\x0e1\xe5\x18$S2@cE,\x97|\x85\xd1\x11\xdb~y\xc6\xe8\xc2\xa1\xb1\xdb\x17\xf8\xa0e\xe8\xfc\x17\x187\xce\xa2\xacKP4\xf3\xd0\xc7\xa6<\x9f\xa4BG\xb6\xab\xc8\xfb\x02\xa2\x13\xe8v\x05e\xd3+\x01\x86\x06K\xbd@\xd2V\x14X\xbf\x81t\x8b\x02]\xbc\xc9\xf6\xbe\xc6\xaa\xb5\xc7\xee:K\x16>"3\x84\xbc\xa9\xe93(T\xba%#\xc0\x84\x1d\xfbK\xfe\xe7\xb7\x8eJ\x84\x96\xbe\x03\x80Yq7\x03\xd1#?[E/\x16B\xf2+\xf9\x07\x152<\xf0B\xd6#\x80\x92Tr\xf7l6\r\x9bZ\xc7\xf5\xf47\xc3\n{\x9a\xe8\x05\xa4jL\xba\x92\x16\x14\x99`f\x17\x7fS\xac\xef7j\xf3\xbc\x07\xee(R\xa2\x85\xc3H\x82s\x9b\x7f\xe8\x95A\x01kV\x93h\xdb\x99p\xb6\x1az\xcf\x91\x07&\xc3;\ry\x0c\xfe\xa7\xa1\xf1\xf0#\xd2'
|
|
|
|
|
|
2024-12-14 17:54:48.249471 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25562
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808822869
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.252391 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xc76c
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505859800
|
|
ack = 2364267279
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 64240
|
|
chksum = 0xecee
|
|
urgptr = 0
|
|
options = [('MSS', 1384), ('NOP', None), ('NOP', None), ('SAckOK', b''), ('NOP', None), ('WScale', 7)]
|
|
|
|
|
|
2024-12-14 17:54:48.264565 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 5880
|
|
id = 47923
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf583
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808822869
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x19\xf8\xa1\x7fv\x18\xf9\x1aXE\xeb\x9eJ\xf3\xdc\xcea\xf8\xef\xa6l\xbf\xa4\xc2\xd1\x11]\x86n\xbb\x86x\x06\xb1{w\xf6\xcf\x894\x88A\xa4\xda\x04\xb5;#V\xf6\tZ\xc8\xca\x12\xc9\x85\xcc\x98L\xf5\xad\x1f\xf4\x0cc-t\xf5\x95\xc6\x90\xf7\xf3\x87Y\x92\x85\xc2<\xeb\xbb\x92\xab\xf7\xe1@\xab0Bljh\x99\xab\xc66\r\x9d\xe9Q7Kc\x13\xf6\xd0\x8f4@\x1d/\x10^\xf6\x8a\xb6\x02\xda\x82\x83\xe4D\xad5\xe4\xbf\x8b$t\x14\xd3\xaai\xc3\xb0\xb8\x12\xf5\xcbN\xe8\x7f^\x06w2>\xbd\xab\xb9\xc4{\xaa\xc7l\xfbkq\x9a\x8b$\xdcS\xedd\xd0:\xe1g\xbd\xe7\x17L\x9d4\x990 7\xe0\xb9\xd7T\x8a|\x11\xf3>]O\xafq\x8f\xbbL\xb6DB7)\x1a\xdf.^\xb7\x12\xb9x\xdam\x1b\xb606\xe7\x84T\x1b\x943_\xfb\x92n8\xa4\x12}\x14\xa7\x87b\x7f~\x1c\xdc\xcb\x94K\xe41j\x00\x00t\xe0W\xf5\xe5\x85\xf2\xf4D!&\xac\xb5\xcf\xa8W\xaf\xd6\x7fef|\x95\x9f\xf2!\xa3\x0c\x829J\xb1a:bY1"#\x16\xca[F\x83C\xe6\x0b\xac\xa7\x92l\xb7|\xb2\x05\x129\xbe%\x07\xe1\xa0\x80kZ\xe6a\xbdgP\x85\xe6\x92\xc0%\'Q\x88,\xb3\xafby\xad\x01r\x8a(\x84J\xfa>_\xe6,3\xc8\xff\xdf\x11\xd5\x0cS\xd7\xa6a\xe5y\xe6}\rY\x8b\xda~\'"\x01M}\xa6\xcbILc\x85ub\xa7\x15;C6\x97(\x1e\xd2\x19\xb9j\xcc~0\xbf\x8d\xc4\x14o\xe8\x9b\xb7\xea\xa5\xf3\x16z2\xed\xe9\xb5L\xb3}\xde\xf3\xeb\x1bk\xfa/\xda\xf8\xccI\xbc/x\x00\xe5\xe7\xe3o\xc8\xd5[\xef\xf0"\xc8` \'\xd7}\xa4\xd1+\x9a\xe7\xcd1(*O\'N\x9fn\xde\x057\x04\x1c\x9b\x17\xce\xce\x8a\xff\x9c\x00\xc1s\xe5vW\x0f\xb0\xb7\xa0\x96@k\xfaJ\'\x9d\xfdEO\xd4\xa35\xbb\xa2/\xaf\x93\xfd,NcV|\xdc\xbc\xf8\x99}\x8aPQ\x1b\x13J\x85`\xa7a\x88\x0b\xcc\xea.v6\xb1\x08]\xf9\xca&8\xea\xf3G\x12nJ\x91s\x18\xc5;\x0e\xf81\x8eV\x9b\x81i8\xa7I\xea\r\x9a\x0b\x99\xd5\xd3F\xaf\xb8\xdc\xa9\xe5\x02\xa6ns\xa9\x96\xb2\x8f\xcc>\xd7\x9a1\x93\x0b6\xaa\xfb\xd0^X\xc4T\x9d\\\xa0\xce\xf6\x08(\x02\r\xc6S\xcfL\xc6+\x97\xc7k\xb5E{\xf3+\xad\xa8P\x7f\x83\xf0\xcc\xc4T\xda\x11zd\xe5v\x1d\xcc!\xf6\xca\xe2:PF4\xda\xbb\x9b\x1c!\xf1\xf63\xe8sH\xe9\xe1w1\xe3tsB\x1d\x00\xe4Y\x8f\x9e\x92\xce*\xa2\x06\x17j\xa0\xb3\xf0\x93\xe1\xaeZ\x8606\x86a\xd5\x16J2n*\x92U\xf0\xf4\xb0\x1a\xec\x8cE\x8f\x12H\xcb.B\x11\x1e!\x82\xe5\x15{\x83\n#\xd3\xab]\x9c\xcd<\x9ey$}\x80%\xb7\x10\xedl\xa0\xf5\xe0\x9bjs\xf2O\x7fW\xad\x1f\xff\n\xaci\xf3v\x07x\xf35b\xfe\xc6\x82u\x0b\x85\x8f\x99*\xfdo\xa1\xc1\x15\xe9@q\x05\xef\xe3!n\xf96\rmT\x94W\x9eB\xf9T=\x1e\xe5\x96P\xb4\xb1\xe3\xd6\x05b\x17\x0f\xe0\xea\xc9\x13\x0c\xc8\xd4\xe9\xc9{\xac"\x93\xd7[\x9ef\xe71N\xe4\xff\x11\x98u$8\x8b\xd2/;\x8a\xb2_h\x17\xb0oN\r\x82\xd6\xbfW\xea8\xe4b\xde\x97U?-V\xfa&\xf9\xfa\xb4\xd2f\xc98x5\'x\xc7\x1b\x00\xa9{\xe3\'\xc4\xf0\x7fS4\xbd\x05\xa4\x13 \xbc\x8f\xaa\xfe\x19\xf6N\x1d\xb9Pc!|\xd4%\x1bD\xf4\x14\xc5\xf9\xaf\x02H\xf6\xc8\xb1d\xac$\x19\xdak\xc6\x00f\xed\x9a\x17\xa3\xe7\x95\xbc\xd1\x1fq\xa1L\xda\x0bQ\xf6\xd9\xb9\xe8\xcb\x95\xac*-Y\xbd\x93k}C\xb5\x0c\x1b\x04\xe2\xb2\xf3;e!a\x0b66\xbam\x92\x01,b\xde\xf3|\x11\xf7\x89\xecA\xe9n\x1d\x8e\xf6J\x02\x03\xbbn/\xf3\xce\xba\x03?&Ps\xe4\xe8FRh\xc5\xa4g\xd01\xa7x\xe2\xd0ye\xee\x922H\xb8\x9fN0a\xc5QXs\xd4@4\xc7\xe2\xbd\xf2P\xb37\xd0\xc5l\x17\x96\x83{Ze\x189#\x16SLIPxe\n\x12\xa6\x81W\xd5W\x0c|.s\xc4\x16\xc6W\x87T\xcd\xfc)=p\xa6\x83\xe5F,oh\xbb\x17(1\xc2U<y<\x93O\xd1\xc1\x8d%\x9f6\x96\x1a\x80\xad\x15\xcd\xc0\xff\xfbEz\x82\x81\x8bb\xf09;v\xd9\xa3\xea\x16\xb4p(\xd9\xf8Z\xb3\xdc\xa4[\x1f6\xf0\x1cwD\xe88=\xd9\xdf`\xbb\xa4\xb1\xaa\xc4\xd7c"\xfa++;P\xbb\x02,\xff\xee0\x87\xde\xdc\x92I\xe7\x97\x17\xba\xa6\x9f\x86Opcg\x92\x14\xc9S*\xc2\xder\xe0\xd7\xe1l\xb8gV\x88T\x99.\xf2x\xaf\x94d\xba\xaf8|\xaf\x15\xdf\xc7\xc8\xda~\xe8tK$4\xdb\xbf8\xe5\xd7a*\x981\xa2\x9e\x9c\xa4\x9eg-\x13h\xc4u\'\xae\xa8\t\xd8\x83\x13\xb1\x1e\xcc\xa7\xfb\x13B\xe8L\x01:\xb6DK\xa3*#\xfc\x07<\x04^\xd9\xb6\xbe\x0fC"2\xc8`\x15w\xe9\xa2\xb2\xce\x89\x994\x17\x82\xa9\x84\xc9%`\xe9?\x99\xaa\xc9\xadP!9\x88\xfe\x00s\xdd@2\xfb\x0f\x97\xcb\xd5\xa1\x92\xf5\xb7\x15\xde\x012\x8aQX,9\xe2\xf3\xcdg\xf9)\\J\x1dX\x8dI\xa7;\xd1c9\xab\x94q\xbd\xa0\xc0*\xb2\xdeGyX\xbdM\xa1\xf0GB";1\x96\x1aY\xfd\xfaD\xb3-S\xaa4\xd3@eH\x03\x07\xe9.h|AW|G\x95\xa8}\x0e\x89\x8a\x1c\x90\xde8\x0f\xce:\x10\xc2W"\x03\x8a\x00\xfc\x05<9\xba\x9b\xe7\xe1q\xb8\xf8\xc4U\xaf*r\x82Z9Ts\x80\xe30\x81\xa90\x8f\xb3b\x89\xc3\xd2_\x95\x04\xaa\xaf\x9aS9H}\x9cw\x83\xab\xe3&\xe034\x02\xa6yQ.\xde\x8a\xd9\xe3\xcf\xb3\x18pP\xeb`\x00\xa6O\xf9.\xd3h\x80l\xb7\xe5\xab\x95\xd1U\xbd\xb9c\xc7\xa6\xe9\xedE/)Iyu\x91\xd9\x8d\x15\xc7\xae\xc3p\xde;\x931%\x92\xa6n\x83\x98L\xff\xcdDqWD\x98\r\x02\xcd\xc5\x92}-\x90\xdad\x8a\x91N\xda\xbe\x88\x91\xa9\xc1\xe4\x9f#K\xbe\x11\xc3\xfa\x8d\xa6\xf4\xefT\x93\xa9f\x8e\xcf\x117\xf8\xbaO9D\xf2xW\xc6:\x88t,\xcd\x0c\xde\xcb\xe2v\xb2\xab_\xb3=\x97\xbd\xde\x12\x1d\xe1\x18\xa5w<Q\xc3\x1c\xd8\xc9\x1f\xf3~\x1d\x1f\x98\xb8a\xcd\x98u\x8aM\x8c\xa4\xd2\xc5\x92\x9a\xd3\xce\xdcBR\x08kP\xa0\xfdR\x04\x9dd\x0b\x0f\x02\xd8\x94p\nI\xdfg=\xb3)X\x00\xee\x05\xbf!\x0bsC\xe5\xd3\xf0\xcc\xd3\x81)\xafT\xe0\x94\xc0k\x90\xc7\x17\x97\xd6\x03r\x9dn\x1b9[\xcc\xba\xbb\xa8\x001\x02\xc7`\x16\xebq!\xc0\xa6\xb9\xef\xfe\xce\xd1\x8d\x96\xee\x7f(7\xfd\xa5\xca\x80\x7f+\xdb7\x06j\x80\x84\xd8d\xd6\xa9\xed\xc7\nWp\x0b\x9f\x12\n\x8e\xe9\x945\x8aQi\x85*!\xf9\xc4\x8f\x9c\x17\x9ep\xee\x1fo\x9b\xf1\xe5\xabh\xee\x1d\x80\xa5(\x8f\xdctw]\xc6\x17\x86#\xe9\xfc\x9e\x01_\x9c`8E\xbaH\xda=\xde\x9dV\xab\xc6\x15\xe8V\x1e\xec\xccj\x12\x9c@{H [\x1b\xe1\xf9\xdd6zpnw\x90\xb4\xb4\x81(K?\x8f\xea\xc4\xb1t\'\xee_\x87\xe7\xd9\xfc\xf0\x97\xb0\x14\xfb\x80\n9k\xa3,\xbcR\xcf%\x9c\xfe\x7ff\xc8\xbfa\xb7\x93\xdbA\xc5\xe2_\xf7\xbf#\xac\x8f\xf1Q\x98\xf7E\xab\xfb\xa5\xa9\xaf\xb4Un\xcbYT\x19\xb3\xc1?\t{~\x92\x98\\\xcao\x14\xb0\xf81Vm\xea\xf9\xdf\xe0\xae\x8c\x982V\xf0z3\xc3\x18^\x9c\xb5\x92F[\xb7U\xd7\xd5\xbe\xc9\xcft\x87\xb1[#\x06\x1a\x99$\xd0\x1daG\xa5\xfd\x12\xe9\x1d)\xad\xd6\xc2\\\x8fr\x80OY\xf3y\xe3/\x1b\xbb\xe2\x1e\xb7su\x8f#\x0e\xd2j\r\x91\xdc.A=\x8e\xb2\xaav\xa7\x13\x8aN\n\x9b\x1c\x8b\xf6\xdbk(:7\x94\xb9\xcb\x80+\x80e\xa5\xfd.]\x9b\xe8\x94\xc3}\x1b\xa9HQN_M0\x07is\xa5\xc3\xcfV\x9e\x84\xfbs\x8c\xf5\xa4\x97u\xfb\x8b\x81\x0f\xe2\xa7@\xb8\xdd\x85\xb8^nO\x0cP\x1a\xadm\xe45@H]\xb1\x98\xe4\x94\xa0\xd1\xc5Q\'\xa8\xe3\x86rH\xa1T\xfd\xa3\x94\x0c\xbb\xc4c\xdd\x81\x1f\xf6\xa6\xf8\x1c9=e\xb5\xcb\xa0\xb9\xc0\x1d\x13\x82\xfe\x1d\xe0-\xd4\x7f0y\x92+RSiR>\xaa\xeb\x9e\x1a7\x05#\xcf\xe2\xf5\xffA\x01S]\xba9\xe7\xcas\xe8\x1f\xa3:\x17\xbaf\xe2u3\xb2e\xa2\xdfZ<z\x98\xa9b(g\xa0.`\x91\xc1\x15vF\xbc\xa5\xad\x9b\xd9.\x9e\x8a\x92J\xb7`[\xc7\x85\x90_}\x9f\x84L\r\x0c\xe4[taCr\x15\xa7\x89\x1e\xf8_\x12`W\xe00\x1av\x00 \xeeO.\xb2>9t\x93\x0e\xc1f\xda\x19?\xd6AL)\xbe\xf6\xf3e\xbb\xafd\\\xfa~f\xe9\x80\xae\x04\xbf\xe1\x8aX\x9aQ\xa1RF\x82\x8a\x92\xc2L&\xcf\xe5\xfc!\xb8)d\xdcku"\xcc}\x91\xcc\x7f^/\xb2\xb3\x9bB\xa8\xe5\x18\x0c\xf5?\xa0\x10\xfa\x13\xba\xda\x84Kj\x10\xc3\x0co\xe0\xc0\x08Hi\xa7\xca\'[\xa9\x84\x05\xf4MF\xc9\x1c\xc52\x0b\x91c\x95oC`7u.\x03\xe6\x89\xe3\x0f\xd0\xda]9e\xbf4]\xd11\x96\xc7\xa8\xc5v\r\x9a,\xd4\xdf\xa0\xc9Pa\xf7\x1ae\x1d\xa8\xb6\xe5\x86\xc9\x91\x9er\xceN\xc1"\x955\x10\x1fyca\xe1\xc3#D\xf5\xce\x0b\xe8\xd2D2\xe3Z\xe9\xc7\xe2A\x14\xa6j\xda\xeb\xe1E\x0c\xbe\x18op\xe8\xe7(Pe.\x0c9\xcc\xb4\xdc\xe5=\xba\xc2T={}bE\xf5\xc2\xfd\xea\n\xb9\'Z((\xec\xd4\xc5\xbc\xcf\xc9\xc8\xd6\xb9\x8b\xd0\x19\x19w\xd6h\xcf\xe7\x86\xc1\xea:\xdd\xa7\x8c"~\xac"11}s1t\rGQ\xaco\xd4\x9a\xc3\x0f\x9d\x0b\x00\xe7\xefi\xfe\xcd\x95\x88\x94|P\xc6\xc9>\x84b\x17\x90\x80\xe6M1\x14=\xbe\x01\xe2\xd6}\xbb\xb9q\xb6\x0f\nfG\xd2{\x0bO8~P\xc5v\xb8\x13)\xa7A>\x94v\x8dy\xb6\xebe;\x1f[[\xe7\x0bq\xedq(\x1d\xa2\x97_\xb5\xba\x8f\x90\xdc\xdeq\xef,nq\xa0$\xde\x85\xdb\x06\xe8uw\x0ff"\x07E\x89`+#\xc0G=:\xa0\x80\xb8A\xdf {<\xd1%\x02\x1b\x82\xd9\xa6\xd2\xbe\xa8\xd9\xbcyY\x90Ikh\x93\xe9\xec\xc3*\x97\x89\x9d\xea\xbbV\xbc\rR@6\xf1\xa0%g\x8a\x82\xf9\x8d\xb3\xd3\xe7p\x14\x99\xef\xd8L\xda@x\xbb/\xa2Z\xf0\x93\x81\xa5\x90\xd9\x96\x1e\x118\x13Gh\xf0\xed\xbc\x14uO\xd9\x83o\x9a\x9f?\xaf\xcd\xf1%9\xd7Z#\xee?p\xca\x93J\xe5v\xa5\xb4z\xeb_\xb1\x1d@\xc3\x94SE\xb1\xe4;\xa9\x7f\xd26\x82\xdc\xd0\xd0\x1b\'\xff\x12\xf2NF:`\x96\xf0O\xaa[\x85\ta\xc39s-\xc8\xe2\x9e\xf0&\xa1\x8b\xf0\xbf\x9d\xd2\xd3\xe4\xfd\xc3&\x1c\xaa\xd2\xec\xe3\xdd+\xb4\xe4\xb9\xc56.\x14\xbf\x85\x03\xd98J\x11\x93$\x18\xf4Z\xae\x06\x80M\xfd\xbat\xaf\x9bv\xb8|\xac\x01\xb5\x90\x1d\xef\xdc\xc8\x18\xb7\x9e\x91\xca]\xfb\x9a+%\x94\x12J\xdfT\\*\x8d\x8a\xed\xe2\x03\x80v\xf3t[{\xc7,d\x1a-"\xec\xb0\xbb\x1fV\xd7\x97:{A\xfc\x98\x14\xff*\xd6\x8d\x96\x94Cw\xffAr)\xdd\x13\xad\x82\x10\xbbnC\xd0\x16\xe7\xca\x82l.rgXJm\x87\xa1\xc7\x19\r\xb14\x05l\xbb\xaf\x1f\xc26e\xd2!\xe2\x15\xd8\x16XO\xe8\xef\xe0\xbeo\xba\xb1\xd9\xe5\xcc\x99\xa65\x0e\x95,x\x9f\xf3\x88&=\nJ\xfe@\xfe\xb4\xa5\xf1\xe2Q\xfb\xab\xff\xf7\xaeA\xd4J\xb2\x89*\xcc<\x10\xf5\xa6oV\x1b\x03\xbc\xe5h5\xa1\x1b\x1fe6\x18\x94\x8d_\x1dL\x83q-\xd5\x97\x97\xb0L\x7f\x10\x0f\xb7\x93\x1c\x90\xb8\xab}x\xffZ\x81sq\x02\xf9k\xaf=\x9e\x9a\xf1\x98\xb6\x9c\x9co\xadZ\xa3/\x1d.\xef\xd8\x97\n\x03\xd0$\xa1\x9d\xc7\xf8\xd3l1.<\xd3\xeb>\x89Ti\x18.\xfc\x98\xaf\x8f\xa9\xc1\xb5\x15\xf2\xe7\x8bW`a\xa9u.\xd6\x16\xc9\xb9l\x08\xfb\xd2E\xfa\x85\xa4\xd1_\xf4\xb6\xe2\xbd\xcbH\x95\xaf\xd6\xb4\xa0Y\xd0\x9c0S\x85P\x04\xf7\xcbD\xfa\x87\xce\xf89(*\xa2\x89_\xb8\xa9`N\xd7\xe2>x\x83\xb9\xca;\xfeK\xbe\r\xf5\xdb\xdf,\xa9\x01\x8aP\xaf\xee\x16\x8d\x86[\xc6\x98\xb8\xe9"\xb4\xde\x9c\x9d\xf6\xcd|\x05\x95\xfdjq\xda^#\xf9\x8e\x17J\xebQ\x93\xd3S\xa7(:\x9905\x00\x1e@\x8c\xb5R\x9e)\x13\xcc\n\x1a#\xf3[0\xacp\xbd\xf5\x00\xb8O??\xb83\xce\x99\x7f\xd5\x84\xb7\x90\xdd\xfd_R>\xd4Ih\xc0>\x07\xc2\x01\xca\xb4^\x0f\xbe7rG-\xcf\xd3\xc7,\x8a\xbd\x84\xa6\x7f\xa2\x19\x0c\x96\x1bH\xf9\x9d\xe2\x1e(\xf5\x85\xc2!\x1e\xd6\xd9\xd4\xe7\xdc_\xa0\xe3\x03\xd9\x0b\'.T\x9cm\xeb\x89\xbb\x06\x11\x1fq\xb2\xc3\x95\xcf0S\x99\x02\xc4\x12\xfd\xeacG\xe5\xf9\xef\xb2h0P\x8b\x9f\xf0\xf9\x00v\xb0b*>L\x14\xdf\\\xbb\xf6\xa6V,\xae\x89R\xfa\xef\x02\xf1\xbed \xb7\xdc\x7f\x056\xa3\x8b$\x87\x13\x95)m\x83\x00\xb1\x0fej\x91\x00\x81z\xe9\x81\r\xe79\xfe\x9abVxM+\xd70\xe2\xbc\xcf\x91SV\x8bS\x08a\xaa\xb9\x86\t\xcc\xfd)a\xf9Bz\xc5=\x1a\xad:\x19q\xfd\x9eqV\xe6\xbaG`\xc9\x97\xfa\x8aH@\x92s\xe0\n\xa1(\x1bw\xcf\x90\x91+5\x14-E\x91\xd9\xe8\x06f\xe5\x17\xc7\x89t\x18QS\x19\xd7\t\x04\xa1\xa7/uK\x8cA;u\xe7gOI\xe8-2\xf9+\xa9\x0bB_\x0b^\xa8\xe3\xa6\x80\xf3\x18\x9b\xbe\xbfT`\xd2\xe4\x0b\xb2\xa6\x8d\xff1\x9d0\xb8\xb2\x9d\x93\x89kJ\x06\x15R\xc7\xb1<\xc5\x0b\x1d\xbbc\x97\xfa\x9d:\xaf\xb0\n\xc8\x98\xb3\\X\xd3^\xec\xf1h\xa1[\x12aIq;@\x84\xa1\x14\xd2o\xe0\xfb&\x9f\x004\xe7\x87\xfa\xb0\xf6\x17\x00~Vh_w\n\x1b\x87\xc6Z\xc1i\x8c-l\x14\x8a\xd1l\xe9\x1f\xad\xaeYO5{\x97\xe0\x86{\xb2\xf2\xe3\xe6\x12Bf\xa05Zp\xd0?\x89\n\x062C\xba\xf7}&5\xe8>\x86\xbc\x0f\xbb0\xc1\xdbOx\x90\x07\xe3\'U{7j\x7f\xd7\xef\xc0z\xaa\xe4j\\#\x13q\xea]\x04 ]f|V\xc5\x85\xf6\x19Wx<\xd7\xfd\x15\xb13\xd0\xcb\xa5\xb5`>\xf2\x9c\xed}\x8e\x00\xfc\xea\x0e\x13\xf7\x9f!\xd6\xa01\xb7L\xfc[\xe6"\xe2z7\xd8\xb3\xcb#\xd0(\xfckr\xb8\xaeL\x08\xb7LA>1\xa9-L\xbf\x90B\xdde\xf3\x1eZO`\xd5k\xdd\xd2\x87\x0b\xbd\x00R\xfc\xc3\x94:\x00\xbd\x9d\xbe\'\xef3\xb2\\X\xe3d\xdd\x9a\xef\x89\xcd\xc5\x9d\xc9\xda\xac\xe8\xfe\x19\xcd\x18\xf3\xd8\x06z\xe8\x87\x9bg\x1f\xc1\x8e\xde?\x9b\xc0h-*\xd2\x86F\x1fBy\x19}\x0b\x80\xc3yFn\xaf\xad\x9f\xee$6\xa3\xcff#nr,\x12*\xf1\xa7Q\xb7\xe7\xf7\x02\xbf\xb6\xd5\xfd\x8b\x02?\x1a\xfa{\xae\xbco%\x88Y\xf5\xb6\xdaT\r\xe0\x03\xa7w\x7fw\xda\rp\xb6T\xfeze\'T\x8c\xdf;6\x103\x81\x82E\x14\xc3\x9a\xac\xe9\xe9m\xa7\xa7H]\x16-\xaf0\x82\xd5\x94\x81&bt\x14\xaf\xd7\xff\x0c\x0b?M\x95\xac\xa9u\x90\x04F\xaf\xed\xbf1\xf7I\x10\xacG\xc8\xed\xbb%\x15\x89\xef\xeb\xae\x19\x9d\xd21<Oz\xfem\xa9\xc2\xc0\xd7\ti\x9d\n\xad\xf5\xa8E1\xbb\x95?k\xdb\xce\xa2{\xb9\xac\xbdo\xce\xf7\xcb\x08\xb58\xc6@`\x8d{zW\x86BmN|\xd7;\xd6TJY\x7f|\xeb#z[\x9e\r0\x12P\xc0L\t\x9cI\xba\xb6\xdf,\xe2e}\x83Jr-#\xcf\xb5\x8f%J\xee\xafy\xfd":\xd6%+\x1c\x8cr\xec4\xf9\xe8qX\xa1\xb7&\x87I\x9e\xa4f\x1e!X2\x19?9\x8e~\xb1,\n\xfe\xf9\x8e5_B\xbe\xd5\xcd\t\xfbm\xfa\x84\xd1\xfcl\x1e\xf0J.\xcd\x93{<)\\\x08y\x101\x19\xff_\x1f\xeb\x1e\xac*l\xd5\x90,\xf93\x87\x86\xccU\x8cm\xc5=\xbd\x88\'\x99y\x80#r\x16\xc8\x19\xe5\xc8\x10\xe7\xe0\xf3\xd6\xed-\\\t~J\xb9,\'7+\xa1\xbb\x86x\xa0\xe9\xfd~\x88t\xdd\xa1\xf51lO-r\x97.\x84x3\x996\x0c\x8f\xb6Y\x98d\xaa\x1f\x86\'\xe1(\xfd\x92\xd6D0\xf0Z\xf2\r\x84\xeb\x19\xb3\x8cY\xda\x1c\xb62\xc7\x8c\x8d\xf3]\xe0\xc8\xef\xef\x9d\x0e\xeb\xac\xbbd\xc1\x1cu7\x0fK\xbal\x9bq\x12\xd3\xb7\xc3\xea\x1b"@\x1c\xbe;\xc1[\xfa\x19\x94N\xd7\rg\xbe\x0c\xcb|p\x02=\xf7\x87n*7}\x84m\xad\xad\'0\x97or\x18nV,A\x85\xb9\x9b\xff\x1d\x0e\x1a1\xdb\xe0\xe9*H\xb9f\xecL\xeaNV\x14\n\x91Q-\x1c\x92\xbf\x82? \x1cNq\xfe\xf0\xd7\x9c\xb4i\xaf\x15\t7\x9c%\xc7S\xa1\x11\x06\xcf\x98\xa5\xa3\xb3\xdbIa\xe4\xcb:`\x0b\xcb\xf7\x84\x06\xd8*\xcd\xe1r\xa8\xae-X\xb8\x10\x17\x15BH9}H\xa9\t5\xc6\xd2\x7f\x1b8t\xf4\xd8\xb3wH\x18wQp\x83\x0et=\x86\xc71\x90\xf6\xe0\x16$\x91\x15\xaf\t\x80\xff\x9e-\xca\x06$i\x82hf\x15\xc3\x01\xc47x\x0c(\x97,|f\x03\xbb7\xf0\xd4\x80\x9c47kh\xa3\xe0\xe2\xac\xb3J\x93o+\x14w\xb7\x9e\x82\xaaH\xe7\x8a\xa5\x99S\x97\xcc/&OV\xab\x1f,\xa6\x98\x97\xd7b\xa6g\x01\xe4\xdf\x15\x12[\xc67\xff\xb5\x97\xbe=\xf9\xbf&\x82\xeb\xd2y\xb8\xa5\xb2c:\x8a\x01(o\xe0.\x11\xe3\xb7\xe3\xe4\x14v\x1c\x0f \xf2\x8c\xfe\x8d\x97F\xf0\x8d\xd5\xa6\xab\xceA\xd1\x80\xb6\xaa\x96n\xca\x96\xbeB\xa0\x00S\xa2\xdc\x1bY\xe6\xb8\xdf\xf4\x11\x03\x02n\xe7\xa4\xaa\x92\x04|\x03i\xfc\x97\x1f\\\x90\xa1\xc5\x959\x8a\xbdm`\xe2\xc7\xa5\x08$\x1c\x12\x9a}\x10x\x0b\xaf\x8eJ\x90\xb0\xc0\xfe\x8b\xaf:\xdc\xb8Xhb\x03\x0b?t@-%\x1e\xd7\xefP\x0e\xf6\xd8\xfa\x1a\x9a\xae\xaa\xa2r$*\xf84\xabV&kV\x16\x17 1GET\xfe\njv\xe3\xc7\x87\r\x84x\x9dv\x82|\xd5#e\x1c\x11<\x95\xbf\xa3\x10FK\xaa\xd6\xfdf\xc4\x8bY\xa5\xe3\xab\x1c\xcd\xfe\xcb\x11\xf0\xce\t\xe5g\xe2>\x89\x83\x8e(\n\xb1l\xc3\xda\xb3\xfe<#(#3\x90w(\xfa\xa10?_^\xa2T\x85\x1dx\xb5\xe1\xf9\xa3\xa5\x7f\x1b\xb3\x1du\xd3\xde\xce\'\x19\xb6"\x18JIk\x9c\x8e\xa6G\x8c\x05s\xce\x98\xf2\xefk\x1e\x10h\x0c\xc4\x1d\xe2\xc5\x93\xe2\xdc\x1a\xa2}\xec\xd3\x9c\\H EVv\xc1{\xd2\x93\x9f\xeb\x04xQ\x9c\x17\xd6g\xfd\xach\xf5\xfaC\x06\xf6o\xfa\xa6\xd4F\x1f!\xba\xabo\xc4\x7f(r\x14OvW\xd0\xf5K\x9c\x06\xd3SX\x8d$\x12\xfdRJ\xdf}\x95n\x1c\xe8\xaa\x02\x9b0\x03\x0c\xd6\xd1\xec"a\x01Q\xb8\xbb/>\xda\xdd}\x8b\x98\x95\xb4\xe3j\xb0\xa3(\x06E\xb3\x1a\xd4\xb9\xbdk1\xa6\xe2\xc9\x16\xab\xd0\xc6\x87\x9cZi>pmT\xf3\xbd\xee\xb1c%J\x8a\xc4\xc2\xe3-\xef\xe0O\x1ea\x13\xe1\xf98\x83\x82\xe7u;\xcd\x12\xb8\xc9\xd7\x16=\xb7vG\xf8\x82\x97\xd3\xf6\xae\x87j\x1f\xe4\x0c\xff\xdc\x06\x92\xab(\xf7\xf2\xad\xedLn(\xa4\x94\xb3\xae@\xec\xa6\xc0\xd9\xb0O\xbc1\xb3g\x01\x87\xf7\xfaj\x9b}E\xa9>\x91}:\x82O\x8dr\xa0<\xbc"9/\x9b \xe6\x16\xc3\xd1E\x01Z%(6\xb6\x14\x9e#\xff|="\xed$\x11\x07\xf2\t\x8d\xed\xd7\xc3)\x90\xa9\x11\x90\xc0|\xe8 \x08\xc9\x95\xc6c\xde\x07\xfb\xdc\x9a]\xcc\x95(\xbchd37d\x18\x93H\xc4.\x8c\xae6\x81-\x0c\xa2\x86.\x10U0\xe0\xa9\xce\x83\xbe\xfa\x07B\xa9m\x01\xcc\x14\x13\xe8\x94p\xc2\xf2\x84\x104\\q\xff\xddu\xc5\xffL\x11\xd1\xc0\xcc\xef\xaa\xb6-o\xfdt\xd4+\x9ew\xa02\xb9\xe8\x96\xb5\xe7\xa9\xff\xad\xadTj{$<V\x98\xfb\xe9\x16\xd6\x9f\x13\x9e\xc8<Y-s$\x1f;\x96\x18?\xfb\x9b}ZrM\xf1c#1\xf1DU\xbc4!V\xf2\x8e\xbc\x0f2\x1b\xe9\xea\xb3g\xa7\x0b\xfbh\x9e\xf8\xc6:5Rp\xc7+\x07\xfc\xc1\r_l\x18>\xc9\x02md\x9a\x1b/\xa5\x9c\xa1\xf8\x19\xc4t\xb1\xba6\x97\x0fC\t.\x03\xb8P\x1e\x91\x91\xd3\xba\xc5Nr[\xf8\x81\x84\xe3\x8a\xae\x173\xccO\xca\xa5\xd0D\xde\xcaa\xc3&\xf4\x1d\xe9;3}\x03\xa2\xe8N\x0f\x99*\xd12v\x85\x02\x9a\xc3Lo\x7f\xdb9\xde,\x1b~3\xc1\xd3\x81\x1ek\x1aO\xe9\xa9\x9c\xb5\x85\xf0^\xa7\xbf\x86\x94\x93D\xc2\x95n\xde\xc7\x9cX\x14\x1e\x03\xbe\xcd\x10{\x9c\xe3\n\xe7\x13p\xfaCd\xfd\xb9H\xc0\x04\xa4\xf8A0(\\\xee\x7f\x8dn\xd4\xe9\xe6u6?\xc2\xd4\xc1\xf94\xc0N\xady\xb7\x0e\x1d|\x8a\xe0\x1eT\x08\x98\xa8\x80\x8f\x81\xe5\xe7\xa9\x89T\xc0\x8e\x0f\xb8\x9fe\x18\x9b\xab\xbd\xdc\x81\xae.\xe7\xa5E\xb4|I\x9f\xe1_\xdf\xa8\xbe\xe1Qx\x81\xff]N\xd3\xe7\xbeYo\xb7\xfc\x8b\x94\xde;\x01\xff\x93\xb5\xda\x8aT\xe9g\x17\xcdm\x87\x19\xeb\xcd\xe2\xab?\x7f\xd9\xfdr\xde0h\x9c}\x10\x0cU\x06\x03\xaa\xa6\xcaRo!2P\x9f\xa6\xb9/Fu<$\xd3\xe3\xabL\xd1\xef(g\x8eW\x0b\x8c\xb0>\xbb\xe3]\x9bN\xfd\x0c\xb7\xfe\xcb\\\x8c\x8e\x84G\xb8\xf1P\x90\x94\xcc\x17\x83\xf4m\x1a\xc1\x893!0\x7f\xd9\x0e\x91\xf9\xeb&\xdc\xbb\xc3m&3\x0es\x03h\x06.\xe6\xa0Z\x8aEL\xae*Dm\x99\x81\x02\xef\xfcw\xb6\xaeW\xbf\xad\x9c\xaa\xbaA\xb9\x9f^\xf6\x84g\x9c{\xd5<b\x08\xc4\xf8\xefP\xa88\xf1?\x9a\xa2\xc6\x9bpi4\xa6\x0c\xb0\xac*\xbcS\xdd\xfdC\x8d\x10 \x1b\xe0\x81\xf5\xf4\t\x94X\xbc#\xd6\xe0~\xdbu\x13\x96\xc0\xfa\xe5#!}_\x1fN\xcc\x93\xc5\xab6][_\xc7\xdc\xc6\xd1\xee\xd1\xfa\x0b\x04\xacd\xa6\x00a+\xed\xa0\x85aI\xee\xb4\xedK\xe8@M\xac\x80\xdbO-_\x7fw\xe5\x1e\xa7\xdc\x10n\x07\x06k\x14\xd3o\x14\xd7\x1a\xf8\x90\xa4c\xee?\xe2\xbaB\xd8\x8e.`c\x98l\xd6\x9c\x10\xe8\xe7\x06\x9d\xd1\x17\xa4\xab*j)T\xf2~\x0f\xbf\x01]\x89\xe4}\xa5rv\x178$\x90\nV\x1bj\n\xaf\xa5K\xac\xael\xd8\xab:edd\x84\xc6-\xf7\x96\xcf\x1d\xd23\xf6\x04\xed\xd1\xc4d0Rd\'d\x9d`P\x7f\xe7\xbf\x9f,J\xfe\xffNk\x88\xf6\xffI?n\xcdA{\xa8\x99Br\xff\x03\x12\xd2x\xc3\xdc\xf6\xabd/m\xf0\x90\x13\x1b|\xa9gsS\rb=\x7f\xd6\xcd6LWv)\xad\xf0s\xae\x8f?\xf5\xf4\xae\xcf\xea\x1c\nh\xd9\xc1+\xc7a\x81\xfc\xb4\xab\xd9\xe6\xf3\xfe\x93V\xf4\xd1W\xd1\xec\xf6ub\xe5!\x06\x01\xf1\x03\xcd;\x98?\xdc\x98u\x02\x04\x88>I\xc0tM\xdd\xc2\xb6\x05\x19\xb7P\xd1\r\xcf'
|
|
|
|
|
|
2024-12-14 17:54:48.267488 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 45328
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364267279
|
|
ack = 3505859801
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8072
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.269836 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25563
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808828709
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.274545 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1424
|
|
id = 45329
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364267279
|
|
ack = 3505859801
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x85da
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x01\x06\xf2\x01\x00\x06\xee\x03\x03w\x8b\xab%\x84\x7f\xa6\xee\xd6\xd0\xa9B\x03\xb1o\xc8n_\xef\xa8\x9d-\xa7\xaa6\xa9V\xa9\x8f\x85hZ q\x13_jo\x7f\xfdy\x00\xd5\xba\xe7OW\xdd\xc3\xe3\xe9\xaa\x14V\xfdA\x9br\xeb=\x85\xa8\xc7\xbd\xe0\x00 \x8a\x8a\x13\x01\x13\x02\x13\x03\xc0+\xc0/\xc0,\xc00\xcc\xa9\xcc\xa8\xc0\x13\xc0\x14\x00\x9c\x00\x9d\x00/\x005\x01\x00\x06\x85\x8a\x8a\x00\x00Di\x00\x05\x00\x03\x02h2\x00\x0b\x00\x02\x01\x00\x00+\x00\x07\x06\xda\xda\x03\x04\x03\x03\x00\r\x00\x12\x00\x10\x04\x03\x08\x04\x04\x01\x05\x03\x08\x05\x05\x01\x08\x06\x06\x01\x00#\x00\x00\x00\n\x00\x0c\x00\n\x8a\x8ac\x99\x00\x1d\x00\x17\x00\x18\x00\x05\x00\x05\x01\x00\x00\x00\x00\x00-\x00\x02\x01\x01\x00\x10\x00\x0e\x00\x0c\x02h2\x08http/1.1\x00\x00\x00\x0e\x00\x0c\x00\x00\ti.scdn.co\x00\x1b\x00\x03\x02\x00\x02\xff\x01\x00\x01\x00\xfe\r\x00\xfa\x00\x00\x01\x00\x01}\x00 \reo/\x02Q\xc8\x84\xa7\xcb\x1f\x80\x19\xdb\x82\xdf?|\xb2E=n\xb8^&\xb0\x1fL\xfa\x98\xc02\x00\xd0\x05\x0fa\x8c\xf3N\x1a\xad\xd0\x9e%\\G5#\xe0\x89A\xb2\xe4#\xe4.Z\x0eU\xff\xdad\xffs\x91\x83\xc36\xfd\xd9[!\x13\xe8I\xdf\x14#\x833q\xb4\xb9`$\x9f\x9a\xac\x1eb\x01T\xb7;\x8f!\x0e\xa1\x0b\n\xeaG=\xa3\x9f\x12\xc8$\r\x97\x86\xdb\xaa\x93ve\x9a\xf1\x1c)\xa1\xc2^J\x133\xd4J,\xaa\r<\x96P\xbd\xb3\x16\xe4\xda\xb2V\xfb\xebhP\x1a9\xdb\'=\xd7T\x81\x07\x8e\x00\xec\xc2is\xb9~\xe40B\xd65\xd7\xd1\xe5\xb1hH\xb1\x9d\xc9g\x0f\xbe\xe1O\xbe\x15lS\\T\x19Q\xd8\xfd\x84G\xbdI\x7fx8\xd0\x8f3\xf53\x7f\xa0{\xc9\x8d;L\xd8\x88\x1b\xc89y\xa1\xa6z`\x06\xd9$\xe2\xb0\xb1\x1c\x04 \xf3R\x13\xe9\xf4\xdf8\x9c\xd2\xcf\xbd;\x00\x12\x00\x00\x00\x17\x00\x00\x003\x04\xef\x04\xed\x8a\x8a\x00\x01\x00c\x99\x04\xc0d`)\xd4\xc0zc\xa1\xb6\xdf\xe8\xd9\x98\x9bZcR\xce\x1f\xf8\xb9\x9fl\xe8k\xbf\x8c\x01\xdc\x7f\xb6\x7f\xdbs\x1f\xd1\t\xbe\xb9\xcbj\xa2\x94\xbf\t\x88\x0c\xad\xfcYz\xc8\xa3\x01;\x18R$5\x80Hl\xad\x03%\xb51\x16\x1b\x1a\xcb\x8b\xf5\xc0)\x90\xb3\x9eWRj9E/[z\xbag\xcc\x99%4\xf1\x16q\xc0i\xb3D5\x90\xb7Q\x9fn\x98\x06C\x80\xa0\x04\xf4\x86\x06\xf9\xb3\xf5az&\xf1N@\xba\xad\xc0 z"\xcbA\x19cG=\xfaG\x1b\xb3\x7f\xbbTV!\x0b\x03:*]\xbd\xab\x9b>%\x1fYu\xca\x03\xea\xac+\x01$\x87cz\x85a\x99\xedV$C\x84j\x12\xd5\x83g\x8b=f\x11\xaf\xbaY\xbef\x9c\x97z\x97\x16QJ\x86!\x055D&\x9d\xeb6t|Wy\x01\x87Au\xb2}\xe2\x07\x9b~\xe9\xae_p\r\xbf\x9b\xaa~wPn\\@\xdc0\x0e\x91CG\xda\xd9\xa3\x82\'\x1b\xcc\xa8\x10\x9f\x00\x85\xb6R\x1a\x86Q\xc4\x05\xe76}\xa4N\t\x03W\xc7\xc6_\xd2c\xc7\xc2h\x88\xd1\x1cK\x94p\x9f\xe1\xebn\x1b\td\xd2*}\x0c&\x13\x14\xf4\xae\x937A\xe7\x0c\x04Q\xbb\x16\xeb\xf1f\xb8%\x98\xb5b`\xd1\x1a,\xa6\xe2l\xd0\xf3>\xb6\x97D\xed\xa1\x1c\xc8\xc9\xcdj\x91\x88\tE!\xc9\x988\xc77A\x18\xc6PP\xf8}\x92\xb6@\xd0WcO\xeb\x0bQw&\xd8\t[\xbbr\xa7\x0b\xdazM\xa9\x9d\x8d\xa8(\x93\xe5\x81\xce*r\xcadT\xb4\x14<\x1d\x17\xb3\x7f\xb5A`\xf8\x9a\xf4U9 \x03\xc18\xb0R\x83Td\xe8\x08\xc7\x98\xf2r1\x83Xn\xd7Ky\x87H\xd1X\x9c\xf3KD\xd3\xf7j\xc5\xa7z\xd1\xe9\xaa\x04\xd0D\xdbE\xc9\x07\x97\x14\xd5\x8aa\xbb\x17.\xc4\x10Fl\xb6\x05U\x04#\xc6\x15\xbbz\xe7\x9a\xc7\x1a\x1b\xebSwgB\x92 \x8a\x1d\x83\x8bE\xb6v\xbc\x1d\x85;\xc8t\x82\xe6{\x97\xe3It\xb6\xd0\x89\x9fP\x97]\xa9\x8f \xc55\xff\x1b8\x07k\xab\x0f\x11fn9\xa7\x97\xd1\xaf9\xab\x9e\xd3\xeb\xacg"\x85\x9e4=5\xa0&\xa4\xec\x0f\xba\xf0\xa8Z\x06\xa3\xe6\x109\x1e\xf4\xa1S#T\x9b\xe8{.\xd6o1l\xce\xf3\x12\x0f\xa8\x07\xa4w\xfa\xc3\x86+\xc2\xf2t\x1f\xb3\xa0\x1aY\x9a?\x86\xc9\xc8B \x85!\xa3\x8d\xa6\xd7\xab\xf0x)\x9f\x95\x81\x0e\x10\x07\xfb\xc8M\xb8y\x12x\xda\x13\xb1@\x9b\xa88\xbe\x10\xc9u\xf8\x11\\$Sk\xa9\xa2\x08{\x98\x843IpY\xb2:\xd1\xdc\x87Mw\x0e\x07\x02#\xd6\t\xc1xk\x92\x81\x0c\xc3\xcbS\xc5\xddz/.\x07\xc4\xeds1\x86\xa2\'\x03\xf2\xbee%\xab\xa5\xa9\xa3\xbbc\xc5\x86\xb1\xc0GA_\x12\xf37\xa3\xa9\xa8j\xf2\n\x87\xd25\xe8\xaa\xa2\xf3\xcb\x0b\x16\x10tn\x9a\xc6\xfb\xd1\xbe\xdc9\x887@\x90\x80#Bb\x86y\xe3\x18\x94\xfd\xa3\xa4))\xc2\xa4,\xb7d\xc16^@Ah4i\xe7\x11\xac\xc8\xac\x96\xee\xb1\x04\xab\xe2SM\xd8n\x88\xccE9\xa1h\xa9B\x02W\x81!\xa6\xc9\xa3\xc6\xfcw\x99\x03\x14\x08#\x8ct\x08\xb1\xb6\xe5\x94\x91\xa6S4\tJ\x90(\x86\xf1\xe5`\xd2\xa8\xc3>e;\x07\x82|\xab\x01MN\xbb\t\x1a\x1b\n\xdc\xabnK\x18Mce\xc1\x98\x08? \x19\x0eu\xf1\xb4P\x00"\xcfZ\xad\xf8'
|
|
|
|
|
|
2024-12-14 17:54:48.279000 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 439
|
|
id = 45330
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364268663
|
|
ack = 3505859801
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 513
|
|
chksum = 0x8201
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xcc?a\xc6]U\x05uO![\x84E\xae=\x12\xce\xd6\xd0\x97:<\xbe\xef\xb7\xc6\xc4\xb3I\x94\x1c\x8b4k\xc5\x10\xf8\x10\xcb86\x17\xa1\xc6TP\xa0M\x01\x08\xe5\xa6\x9cj\xab\xbc\xe4\xab\xa1\x87\xb0m\xbbA(h\x8a]v\x16\xbc&B\xaf.\xdc\xcdx\x17\x95\xdf \x81"7\x82\xb2\x80yX\x9c\xc2\xff\xc4_\xf6\xd9\x9cF,K\xfc\xdb\x94\x1e\x9a\xb8\xd0\xea<\xafG\xabH\xb7}\xda\x18\'\xc0\xc5.\xe3\xf1\x06\x07\xbc\xcb\xaesY\xa8s\x9a\x94g\x82e\xb1[\x13\xa0zS\x03h\n\x93\xa7K\x14\x88\xdf;\xaa\x9cE\x94\r\xc0\xbdPD\xb8\x92\x97\n\\\x87\x03\xfe\x82_\x8d|ZDyF3R\xa2\xe3%\xb1\xefC\xbb\x16\xe9;+\x8a\x9c\x11\x84s\xd30T\xdc\x13\xc8\x92\xac\x10\xfdX\xa5\xc7|L\x8a\x00\t\n\x84\x1eT\xf7/\x07\x14w\xe1FL\xa4\xd3\xa0\xb4b\x1b_\xb8\xb4\xc5\x95\x95\xce(\xc8\xbd;\x11x\x86\x92\x1d\xac{\xb6\x83\x92m\xc1`\x01%\x82\xde\xf3E\xc1\x88g\xe4\xbc:\xbbR\xabXTH0\xb4"\xb2A\x8a\xa2\xe1?\xb0\x16\r2S\x06G ;\x93y3\xddqBK\xa6;\xe38\xae\x10:X}\xc7\x10\xe1\xd2k\x8e\xc89\xbd1\xac\x1f\x93\n\xfd\x14\r\xe4\xb3O\x95Xe\xd6\xc2\xc7\xe6\xb6\xb0\xc9\xe3\x1f\x0b)7\xbe\xe1\xdaxa\xf9P%\xdd\x1f\xf4\x84M\xfb\x00\x1d\x00 \xeeV\xd0f\xfe\xe8\xb8No\xc9L6\xb8\xaf$\xec\xab\x8d\x04a\xf9~XP#\xaa\xc7\x0fp\xf2m\x1e\xba\xba\x00\x01\x00'
|
|
|
|
|
|
2024-12-14 17:54:48.287279 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 5880
|
|
id = 47927
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf57f
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808828709
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xbd\xa9\xe7d\x17t",\x94Y\xa4\xdfn\x8d\xb8\xbf\xcbD\x88r\x02cS*\xdds!\xfaY1>\x9dq\xac\xf1:\x0e~\xb3\xa7Vd\xb2\xc7z\xd2^}\x9c\xb5\x9d[\x92\x8a\xb8\xb1\x9c\xb99\xe5/\xde;Z\xe2\xd6j\xf9c\xddH\xd1"\xd7\xbd\xd88\xfa^.\x82%\x9cX\xd2g\xbdy\x8a\x856j\xcd\x04\xe2(H\x07\xbf\x9b\xed\xa5\xb7\x00\xed\xbc\xb8|\x18\x91J\xfc`\x98\xbe\xc6\xbd\xa8G\x19\xf8\x1b\x99\xa2\xffA\xd5\x08\xfc<a\xff{=\x16\xf3\x8e\xe8\xfa<p(\xd9\xd7\x85\xe6\xf8\x1c\x96\x9e\xe5\xcbkwBETF&W=\xe6uTg\xefIX\x89\x94\xc9\xaf\xf7\x1eLl\xd0\xcc\xbb\xdfU\x14\xe7\xb8\xc4y\xfb\xef\x1d"K\xe0\x8fl\x07\x89<\xab\xa4=Um\xcc0\xc6\x87B\xde\xfb2~2\xea#\xab\xcao\x15\xfa\xb4?N\x9d\xeb\xe6k\x87)\xa7M\xd8\xb6&n!\xc1\xed\xff\xd5!S\n\'!\x875\xd9\xacY\xc1\xe4e{i\xf4F\xe1$\x08\xb9\xf0\xf5\xef$@2/s\xedb8\xd8\x08A0\xd3\x84|\xce\xdb\x97\xda\xec\x94\x04Wm\tZo0\xd9W\xa7\x1a#\xe7\xd6\x9f\xc3\xc01\x855x1\xb1\x9a\x06\xb0\xceO@\xa3\x88E\x12\x8d\'*\xfe\xfd+\xa2\xb9T\x1f~\xa0Y\xd8>#9\x0e\x9a!\xc0\xe3\xcayLS\xf3LB\x96\x87\xe9D\xc5L\xb6;j\xfd\x96\x82\x0e\xad\xeb\xa9\xf5Q\x94\xaa\xb1\xc8\xefr\xe1b\x1c\xe4.P(\xdd!\xf2\xe5\x111<T\xf0\xb6\x1fn\xea\xe2]%\x06\xd0\xf67\x08h\xf4\x9e\xdaj\xf0\xd2\xfc\xf9\xce\xa1\x1e\x1c\x9et\xffo\xa1O\xe5:gA\x12y\xfd\x89\x8dZlJ\xf83\xe03l\x90\xa5\x8aPqj\x1a\xab\x8dh\xeeH-\xa9\xf4!\x1d\xc3X\x92\x96\x0e\x03\xddS^\x8eW\x8cP\xf14\x82\tK|\xbf\xd9\xc8\xbf<x\xe0frDKr\xd6\x11/\xbf\xab\x96\x12\xc6\x17\x95\xcds\xe5\xc1\x1a\x93\xd0\xc5\rXe`6Q\x93\xd9\xc4\x96\xa2P\xbf\x90\x05\x12\x95"\xb7\x82n\xce\xbd\xab4\xe3\x04\xc4\xbfv\xb5\xb6\x80-4\xfe#\xd1r\x8f\x9dJB\xf7-\xcf\xa7 \xaa\xb0\xeb\xcdd\x03\xe0\xda\x83\xb5f\x17\xaejp\xef\xbe\x84GN@\x96\xcd\x9a\xbfU\x94\xe84\x8c\x9e\x15\x90M\xdd\xa3\xfa\xf68\x17+OD\xb2b\x17g\xcd\xf6\x17\x8dg\xa0\xed\xa7\x85\x91\xe9\x9b\xe7\xba\xeeO\xa7Z\x18=\x95\\\x8d\x1b\xff}\xf9\x0b\xd3\x02\xcd\xcd\x87OK~\x91\x8b\x05\x9aXM\xc8\x1b\\5\xdb\xf8\x99-\xc23*\x02\xe1+\x08wG\x14\xec,}\xa7){\x985\xb9O \x07\xa8v\xfdf\xb7\x1d\xe7@b\x1d\xcb\xd5N\xef\xe0\xa4\xaa\xb1>\x16\xd95\xde2\xdeA\x90\xfb\xf2\x12\x82T\r\x9du\x9e\x99G\x82O\x8a\xd8x\xfa\xbc\xa9\xfaMLf\xfa\xe2\xe5+K\x18Z\x18\xd8\xcf%0\xa9\xd4\xec\xc1\x9a\xca-8b\x8c\xcc\xafV\xcf8\x93\x0c2\xde\xd6{\xf5\xa3\x11\xcd*M\xc6\xd5\x8ej#zd\x0b}\ru4\xd2\x94\xb0\xf8\xa4N\xbe\xee\x13o~\xd6\xb5\xedy\xb5\x15\n\xc4r\xdf\xc8\xd2~i\x857k \x9a\x87\x1d[V*\xf6\xf3\xef\xca\xc0\x97)e\xceY\xb9\xfb\xfe\xc1\x03\x9d\x85\x10\xb8D\x83\x0f\xa9u\xe2\x18.Y\x7fuG\xe5\xf9@%=\x88\xf9\xde\x9d\xbet`YhPo\xacQi\x1a\xc3<\x93\x03\x82;$\x0c\x88j\xee=\xe4\'~y\x95[\xc9\x9c\xf2\x04\x99%\xc0/\x1f\x95Z3Jh\x03a\x14+\xd2\xb1P5\xe9s\xfb\xe8q\xae\x88\x1c\xaf\xfbz[\xcf\xb4\x05\xf2\x17F\xbb\xf76:\xed\xccK\x9e\xd2\x9f\x18\x067\xe5\xb9\xbf\xc7@,\x8d\x83\xd6\xef[\xab\xc5\xe9!\xca\x9b\x8b\xd5N\x11U\x82\x8a\x10\x7f\xb4\x0f\x0e\x00\x97\xd0\xbdo\xcf%\xd1\xc22s\t\xbe\x16\xb9\xf7{\xd8D\xdbw\xcd\xd3\x8c;,6\xcd\xcb\xff\xca\xdb\x12\xe9\x15!RDs\xe9\xc3.8?\xe5\x1bD\xb3\x1f\x9b\xc2\x97\xce\xff\xbf\x11\xc2i5\xa0|o1\x13\xe3Q\n\t,>\x86\xf3k_N\xa2\xfd\x0b\x9f\xaa\xa9\'Ss\xf3\x17\xcf\xd7\x1a\xfa\x993\xbb\xb1\xa5\xc20%\xdc\xc6w\xfcf\x1a\x87"\x91P\n\x08H\x03\x80\xccs\xc1R\xdaGZ\x8a>\xdb\xcc\xb8\xe7s\x0e\xee\xa4C\x96x\x9d}\x0e:\xb92s\r\xf8\x11\x91\\O\x83i\xf0(\x10\xbfxB$\xc7\xca\xd2\x13\x80\xed\xb4\xfc\xf2\xffx\xe3\xd3\xea\x16\xdf\x7f\xf1\x03\xda]\xdc\xba\x1d\x7fj\x98s\x8aqS\xa1\x95W\x88\xd5\n\x1aNL>\xd9,\xb8\rH\xdeAE\xb9\xbd\xd4\xfc`\xd46\x94\x1dlA\xd1\xbb4aX\x916^\xa3\xdd\xbb\xb9\xc0*\xb9\xc6/\xc0\x0f\xdflk%\x16/!\xf9T\x0c\xe2\xa7x\xef\x1f\xe3\x81r\xb6\xbc\xe7\xfc`\xcc\x1f\xcb\x8e\xcc\xac5\x95W\x93%y\xc9\x86I\x9dO\xae\xd6P\xdb\x10\xf0d\xa5\xb8C.\x8d\xd2:\xafW\x93\xdf\x1c`MN\x98O\x0bN\x10\r|\x93\x93\xfb\xfa$\xe3M\x80F\xdd\x94\xc8t\x80o\xc9\xc2\xb3\x96hj.\xbe\xac\x8d3:\xa4/\xe65\xd4?E\xf0\x1e\xcc\x96\x89\xfd\x8f\x8a17\x03\x12\xe2H\x88\x14Vo\n\x83\x0c\xf2\xd3\xf7\xf6\xdcf\x83b\xa1. !TH6h\x19l\xd0\xdd`"\xbd@-\xd5\xd3r\x98c\x0f\x18\xe9\xd0Ux\xd4\xf8\xa2k\x7f\x0b[\xe5\xd1`{\x9d\xaa\xb2\x9b\x95-\xfd\x96\xa6\xb1\x11*G\xc7\x8a\xcf\x15h\xe2+\xc2\x03\x92\xd2\x86\x84*\x9d\x80\x930c\xe4\x14\xefj\xff\xda\xbb\xfb\xb7\xf7\xb2;\xad\xb8X\xdd]I\x0br\xa4\xacq\xf0o\x1d\xf9@\xc7\x9b\xd6\x1e**\xb3H?F\xd7\x1e%M\x14\xb9\xd8\xc5\x13\x98\x83"\x1f\xca\xb5E?d\x9bu\xad\xcf5\xe8\\\x99s\x98qE\xaf\xf9\xfd\xe9\x12-\x90i06\xf0\xca\xefB\x18\xf9M\xef\xe9%SsH3P\x96\x17\x8f\xd6\xa7\xa9\xc2\x17\x0b\xe9\x84\xb9\x08\x9d\x1f<\x8d\xac\xbd\xfe\x16^\xb3e$KF\xe62_$A\x0e\xe54k\xee!\x0btt\x14\x1a\x97.\xb6\xbcd\xfd6^\x80s\xfa\x9fzU\x0e\xa0\x14>"h\x12\x14\xa1\x93\x1d\x91\x03\x1d\xc2\x90\x99\x93>\x92\xfeR\xd5\xeb\x80\xe3\xc3\x10\xc2\xee$\x05\x14,\xc2_[\xa9\xe8\xa0D\xbf\xf8"zY\xd0b\xc7V\xcc\xe3\xb6\x0f+\xdd\xbbd\x8c1\x92\xf0UN\xa0C\x1av\x10\x93\x06\xbb\x17\x18\xd2\xd4\x937]\xa9\xb1P\xdd\xcby\xa7z\x97g\xba\xbc\xb4\xee\x1e\xf3DJc\xaa\xba\x81\x82\x07\xa9\xe0{\x9f\x8c\xb4S\xf3}%\xda\x9e\x19\xd9\xbfG\xc0X\xbb\xb8S\x08Mz\xf2*\xe2)\xa8\xc8\x96\xa7\xe4\r\xe9\xab\xbei\x12\xd8W\x01#\x8aP.\x8a\xb7]g\xd8\x99\x1e\xd9\n\x067&\xbc\xf1\xe7\xa5\xbd\x852\x05\xa3f\x07$\xcd\xebJ\xd8\x9fs\x95/\x00A\x14\x93t\xebu<\x1a\xfd\xb4]\x15\x0c\xef\xdf\xe0o\x902\x02>S\xfbS@\xf51\x15x\xe2\xbe<\x94\xee3\x9d\x82\x8d\xd3"\x84\xd6L\x96\xda\xed\xbf\x90\x05\xab\xb5\xd4\x0c\x89<\xe9\x13\xc5-\r\xa8\xde\xd5\x0e\xb4\xe0\\[N\x1dy\xf4\xaf\x84K\x88\n\xa6?\xa4\x8bl"AY\x93\xa8\x91M`e\x18\xc4Y\xcdF\xd0\x93\x1b~\x87\x04bi\x1b\xb2\xd0\xb4`\xb8-i>dduX\xce\x8cV\x0e\x06d\xc1\xa4\x1brF\xa6\x14K\xecL\x86\xa7R\x9ab\x12\xb3\x85=$\x9c\xc5\x1eU\xc9D\xa9\xe6\xb3\nSh^\x95\x93\xa5\x91\x94\x01/\x9f!\x91\xad\xe4[;8Q~\x84\x12\x15\xe6\x9a\xb7\x0bs\xab\x06\x95l\x8fw\xc0f\xad+\x96$\xe0|\x84mw\xc4\xd5\xdb\xc7\xd5\xb8qW\x94k\xf8B\xc0\xfa*\r9s)\xbb\xba\xb6\x14\xd8\x7f\x85~\x88\x02\xaaA!svB\x18d>\xf2D\xae\x8c\xe0\xeb\xb1Br\x90\xb2\x14\xfa\xc1\xa9,"\r?5r\xb9n\x01:\xbf\xde\xf4\xbfh\x06\xdb\xf5g\xdb\xac;\xb0\x98\x16\xd2H\x995_\x7f\x89\xfdb\xbeW\xe0_|\xbe0\xaa\x0b\'\xcf#\xd7\xc20\xe28\xdc.uvX\xcfY\xb2:\xca\xce\x00\xc2\xedy\x02q\x88\xd6\x87TM\x11\x8f\x16\xc6\xd1P\x99\xa1\x11\xdf\x14`\x1f\x80\xa7\xb0Q\xc3\xe5*\x02M\xea\xc6CX\xbaZ\x030\x14\x04&\xbeN\xec\xc5%\x15WN\xe4N\x8e\x1f\xc8\xc0\x11\x97m\xa3N\xdcG\x81r\xa6\xb2\xba\xb92Q\xf4M\xed-j\xca\x02\xa1\xae`\xaa\x95\xbbs\xaf\x01\x83\xe6\xf3[\x05\xe7\xab\x81\xa6g\x87\x9aW\x9c\x91{\x9a\xb2\xdd\xb56\xa7\xb0\x1b!\x8bQj\xf2*\xda\x01\xa5\xc8\xfb\xa6\xd2\xa9\xe2\xd5\xa78\xff\x88\xc0c\x90\x98p\\Y\x14\xe8\x87(\xd48\x8b-\x8b\x12!\xf9)\x00\x18m\x1d\xa6\xd6\x9c\xd6\x9eB\xf1\xfdt\xa1\xc0\xb5\xc3\x94\x04w\xeeA3G\xbb\x82\x85\xe0\x9d\x9e\xae\x06h\xa2\x8bwST\x94\xa8W\xd9K\xef\x0c\xad\xfb\\\xbcO\x0e\x99HG<6.\x11\xacy\xf9;Y"\t<2\x04\xd5\xec\xca\xb0fuV\x88Z&Sw\xc0(\xa0\xa81\xa2bz=s\x1bp\x90r~TO\xad\xdcO</\x0f\x8e\xf42\x94Y\xc5\x80\xb5\x1d\xf8\x99\xf2\xae\xf0\xb7\x82\x0b\xe4o\x89x\xa6B^\x8az i\xdd#I\xf7\x07\xbb\xa5\xa1b\xd4%`\xb2\x01\xd2*\xff\xe7\xd1\x8c\xc9L3\xb5i\r\xcf\xed&-\x18\xbaRN7O{\xea\xf5\x0c\xa1\x0e\x00\xee\xb8\x07\x01\xf1\xb6)\xb4\x7fba\xbd\x9d\xbc\x91\xf2\xa29%\xaf\xb0\x1aY\x83\x10L\xb0W\xcb\xf2-\x87\xcbn\xad?\x0c\xe2;$\xcd\xe4\xed\xfa6$\x16\x9c\xdb2\x87\xdbW\xb5\x18\xd0\xd2v\xf1n\x85_S\x15+\x1b\x7f\x1a\xfc]/\x08\xde\x88\xf58w\x146\x1d\xa4\xd3WL\xc4dt9\x8dd\xf9P{\xdd\xcc\xa6A\x81\xea\x1bp=|\xc3:\n\xfbQE\xdc%\x80\r\x1d-\'\x83\xb3\x8f\x11\xce\xb5A\x88;\xb7\xb4\x8f~\x80{\xc3\xd5\xb3\x0be\xeaV\x02\x104\x1b\xf6\xe2\x8a\xeb\xed\x017:\xef\xef\xaf\\Z\xb3\x13y\xea\xbe\x93\x83\xb9\xe21d\xd4> \x9a\x19r\xe6q;}\xec\xf6\xe6\x92&\\a`\xc5\xe1\xd7\xfd\xb3\x1cO\x00U\xdb@`\xb1\xecK\xfe\x83U\xae\xa6|a\x04\xc4J\xeb5\xe1vK\xcb\x89\x0f\xa3X\xee#O\x9b\xe7*\xb6Q\x01|\x1c\xdc\x00\xb7\x92\xac\xe3\x85\xed\xda\xd9 \xbc\xbd\x8a|\x05\xa2E\x8bel\x83\xbd9\x0bD[a\xa0\xafb\xbb\xdb\x17\x9b\xbeS\xda\x93\x8eY\xd4\xa7\x92\xc7\x929\xef8\xc2\x1b\x05\x07\x94\xf1\xbaU\xc8\xc0\xea}\xcdh\xcdq\x8e\x93\xd7\x95I\x97\xd3\xc6\xc9\x06\xe1\xb2\x93\x92\x9f\x02\r^0S5r\xad\x18G\xd3A\x88\x18\'\xdcH\xecYR5a\xd6\xecd\x7f\xc0\x82b$!\xbdF$a\xc9\x88gy:\\\xc8\xbb\x82\x970s\x08\x88!\x1c\x82\xd7\xa1\xd4\xacM7\x9f\x8f*\x0f\xfeS&\xd0\xa60+\xc6\xa9\x18z\xca\xe2\x81>\xfa\xa2\xfe\xdd~\x13^\xf5\x9a\xf3\xbf\x1d\x8b\x836r\xbe\x0e\x85\xbc)Z<\xb4,\x88\xb1\xc5\xad\xdfj\xe2&\x88Usq\n?\xba^#J\xa0\x16,\xebjt\xd9\x9f\xe7\xe4\xf0o\xee\xa2\xdcn\xe3\xe0|@,\xe2\xe9F<%\xbdvsYo\x17&\xbc\xa5\xb4\xda\r\'\x905\xf2\xee\xe3(\xc8\x9c{\x9cd\x16BA#\xc0\xf7j\xd8uT\x9b\xe4\xfb\x0e\xb1P\x15\x17\xa8\xa0\x99,\xe9\x9e\x91\xbaQ\x82\xdb\xb3>?:\xcd\xfc\xd7,\xb3e\xcc\xed\x13\xed\x92\x06,\x88(\xdc\x0f\xbfsN\xbd0\xbc\xcc=\xd2X\xdd\xda\xec[\x8f\xb6\xf0\xe6\xb30*\xd1QU\xf7\xc1/\r\xadd\x91\x8e|\x0fE\xad\xf2\xeb\xb9\xf6\xa6\x96\xa5\x0e\x8b\xdd\x06\xeeu\x8e\xe8\x86q\xf2\xdc\x1b\xdar\xb9\xe4\xe3\xf1-\x9d\xf3\xb6a\x8ds\x1a\xd1p\xf2<Z\x99\x0cm\xd7A\xf9\x8a\xbb\xadL\xce\xd1\xf0\x8a*Y\xbd\xfdF\xfc\xd9\x99\x1f\x17\xf2b\x08x\xa4\x9c\xc9\xdc\x97Y\xb5\xc9\x9d&\xf0\xc7\x88\x0e\x80B\x15y\xb9\x81\xbbO\xb8\xd8\xcb\x0cd\xe1\x0c\xa1\xccd\x8be\x1e\xdfH\xae@\xa6L\x04\x10>\xee16Belp\xaa\x95\xab\xff\xdc\xe4\x06\x1c|\x14\x03\xc0b\xf2\xe1\xc2\xc1\xb8\x07\x8a\x93\xe6\x04\xeb\xe6*\t\xa6\xf45\xb7\x10\x88\x89W\xe0\xb4\x02\x97\x9b\xdf6Q\xd4\x05]J0\xa2\xc9\xa1$o\xef\xf9\xcd\xed:x(Z\xad{Y\x1a\xad\x88\xb19\xfb8\xf8\xaf\xe8\x96"\x7f\xa8\xf5V\xc7\x81\xfbyj\x9a\xef,\x03\xcf8\xe8\xfc\x981le{-\xf1\x17J\xa9F\x1c\xe2\xe0X\x9d\xff\x0bbc\xd6\x9b5\xd8\xb4R\xf9\x8f\x8d\xb8&?d\x80+\xf6\x86\x8b7k\xc8\x07\xfc\xd3\xfa\x13\x1eo5\x81c\xcc>\x1f\x1a\x96\xef\x02CJ\x11\x8a#1=4\xdd\xb6\xf0\xf2\xe5\x8d:\x84o\xf3\xbc\x18\xf4j\x86U<k\x83\x9d\x162@@\x08\xdd"V\xba\xb15\xa6J\xd2\x1fa\xd3\xe3\xd3\x95\xea\t]D\x06\xaa\x7fz5\xca\xb3Rr\xfc\xc7=\xbaE\xd4\xc2\x17\xb5\xf7"\x86\x8a[\'\x00=D\x9c+\xc7?\x18\xc2\xc2\x17hgd\xa0\xd3\xe8\xfc\xb3eD\xfe\n\xb9M~\xa8\xc3\x8b$!t{\xb6\x94\xd2\xd9\xb2V\'\x97\xeb\xac\xb8\x97j\x87\x02\xa2\xdd\x9b\xe6\xa9\xe5\xaa:\xc1\xa5\x91\xa4L\x81m\xbe\n\xb9\xcc\xa9\x8d8\x08\xf2\xf7`\x0c\xee.\xde\xc5(\xf8\xbeFV\xd8\x06\x8e$\xdf\r"\xfa\x0b\xc6\x17ni!\xce\x97QN\xb9\x006\x99\xd3mZ\x07M\xa7\x97\x86\x82\x07\xa2\xba\x10\xe5\x12\xd2\xd1J\x02|N\x12\x82\xdd+w\r\\\xf5J\x7f\x93\xd2\xc0X\xc1Q\xa6\x10\xa3v\x96!=\x9e\x8fi\xf4U\x16x\xf2\xa3\x1d\x8aa`\xd5\xe3\xe9\xf1\xff\xe0\xc5\xe2*\xea\xb5\x9c\xf7\x87W\xb8\xa4\x905T\xc6\xba\x1f[\x02\x15.*u\xf5T\xda_!\x0c.\x86V\xb1se\x1d\xe6\x81\xcb\x84\x8d\xca\nlL^G\x9d-\x9c\xc8k\x80K\x19\xf6\x0e\xf3h\x08\xa2\xbb\xc8\x04T~^m\x08D\xdb\x12\xb6+|\xab\xd3\x17\x9fg\xcf\x86k05\xc7\xf7\x13<\xcd|\x82T\x9aG\x06H\x18D\x1bEK\xdf\x06\nn\x10\x83C\x05\xf3\xb4\x0e\x19x\xe1\x930?\xe2\x0b`\xa8:\x0f\xff\x7f&P\x06=\x10b\xf7\xda\xc6\xb0\x10\x94Wz\x1a\x1840\xfdg\xea|\x06\xb2\x8fY"#\xc7j\x1e\xfd\x1d\xe6\x8a\xfc\x15\xc5FC\xa4\xaa\xd0\xdc\x94~nL)+\xaa\xb3\xc5\xb3Fp\x9dCM6\x96\x13\x8f\xc6\xfeOw>\xd4\xc6~\xfah\xc3a\r\x92\x17-V\xb3\xa7\xa6c\x9dR\xf4\xf2\x9a\x96\xcfk\xee<\xbc\x90w\xba\xb4\x8a`\x10}I\xc6\xf4(\x18\xa25\xcb\xa0\xfc\x96}1v\x8d\x87\xf5\x8a\x12;\x97\xfac\x18\x01\x99,\xa8\xd7\xbev\xc4\x0e\x0f3\xff\xb0tc*\xc6AC\x82j\x01\tO\xff\xa5u"t\x1fw\x8e(\xcc\x0f\x0e\x00\xa6qV\xf0\x04\r\x12$-n\xe6\xfe\x04.M\xc4b\x96_!+\x1e\x8b\x13/#\xd9d \xa7\xc5\x1a1\xdc\xd9SXu\x85\x80\xb5\x12\x16\xeb\x03&\xff\xa4\xdfy\x95\xf0p\xfe\xf7\xd1^~\xa1\x0b\xa0\r\xa2\xbc!\xd4\x16\xccQ\xd6\xc9\xa9JEf*\x00\xc8.\xf6\xe5\xdc\xa1\x84J\xc16\x9d\xea\xa9o\xd5\xfdC\x19\xff8=\xb3\xffn\x9b\xfbt\x1b\xcc\x91%0o\xde\xeb\x15\'\x15K\x96j\xe9UO\x8c\xden1\x144\x8e\x9c\xc22\x9b-VQ\xbb\x9f\xfd1\xf5\xeb\x93\x8c!u\x05\xf6\xe3\xcd\xd5\xdd$P\xbb\xcc\x9f\xaaK\xbb\xf9\xc3%\xb7\x99\x88\xb1\x97\xaf=\xef\xf8Ly\xe4{\x8a\x12\x04Rq\x94d\xa7do\x82\xafW\xb3\xf3P\x9bg\x15\x90\xdbc\x94N\xaf\xe3\xfc\x9c\xdd\xe0\xb5O\xe9dMz\xa9\x8a\xeam\xe0xV\xac\xd2v\xe1\x94\xb0\x1a\x10\x89\xfb\xa7\x05\xf3\x0f\xbd\xd7\xc0\xe6P7\xda\xfe\xaaS\x83\x95\x0eJc\xa6\x84\xdcz\x93\xb1\x17U\xbay\xaf\xc6\xcb\xd7\xa3\xa2\x11\xcb\x8c\x9c\x83\xab\x9d\x83[\xaa\x9a\xc3\xa6i\xa6j\x04\xf3\xc4\xe1 \x96\xf7\xfc\xb6\xcc\xf7U\x7fT\x0bbW\xcb\xcc\x92^\x88\x81~\x98\xcc\xd75\xd6\x0c\x16\xb9\xb5\xe7\xf0>g\x1a\xf7\x86]?\xbf=\xf7s\xaf\x0c\xd2"\xf5\xf8"\x0b\x9a\xc3\xccs\x08\xba`\x83\xbe\xe0\xe0\n\xd4\xa5s\xac\xca\xec\xe7\xbe;\x82\xfdCc\xe8\xc4\xb1\xca\xb6r\x98\x07\xe90;r\x03l\xe8pd\x82\xd7Y\xe3s\x15\\\x86E{\xddd\xef\x9f`\x91xa\x84\xcdn\xe6\xd6\xd9A_\xfbF0\xa5\x1f\xd7\xb7]\xd5L\xe9~P\xbf\n\x98C\x0c\xfaSs\x9cr0\xbdJ\x96L{\x00\xd3\x95\xa1x\xdf\xeeb\x02\x10:Hci2\xf3/\x9d\xdf&|\x8c\x9aq\x9eP\x83\xae\xceLB\xc5\xf2*m\x02U\xdb\xe5J\xc2\x02\xed\xd8K\xbdX<\xd6\x05\xdd\xb9n\xd8\xce\x1c}\x8b\x94\xf6\x8f\x94\xac\x98\xd6\x06\x89gn\xb0<\x05\xb8\xfc\xe6Z\xe8\xd5\xbeST\xc4)\x1bh\x9b\xb7\xc1-\xb3\xc7\xd4\xa5\xc2\x9a\x10\xbfHE\xf7\x06\xc5Dc\xf6,\x92\xab\x8f\xa0|\xd3m\x81\xe5\xb63\xbd\xd6\rh{\x98\xd4\xfcG\xbc9C\xebx\xedc\x867N\xeae\xe8H\xaa\xef\xc6\xc4\xf4,>\xd0\xae\xc7Kz\x15\x9an\x1f\xdd\x01\n\xdc\xf9\x0fJ[\n\xc58/P\xb7%d\x01\xc2e(\xf7P\x9a\x7f\x9b\x15d"\x12\x93\xcc\x0bT\x0f\xd0\xc4\x83\xd4\x96\xa0s\x87\xa7\xb2\xc7F(\xf7\x92\x1b\xccps\x0f\xf8\xfe\nDNf`\xef`\x98\xbf\xa2;\x04\x12&\x10\xa4\x11~\xfc?\xd6\xab\xe3\x92\x7f\xd1\x91#\xf1Z\xfbs!\xd1\xf8\xc9\xa1nt\xe1\xd5I%\xdf\xe3]\xfbv\x97\x985\x9b\xa060\x1c*@a\xc4w3\xce\x11\x05\xa2\x03\xb4\t;c\xcdDK\x010b\x8f^P\xac\x83\x03\xe7\x18\x00/\xad\x98g\xfb\xa7\xa0\xe48kQ\xc0\xbe\xcfCW\xbe\xafj \xe9\xb2\x9d\xd8\xae\xf0\xdc\xfe\x97\x9b\x04^\xa1,\x8b~\xa8\x05\x1af\xe2>2\xfdW[\xea\xa9QJ\x0fR\xael\x8f|v\xe9u\xafS{(\xf7\xba`\xe2H\x04\xf0\xb6\xb8\xa2\xd3\xcf;U\xbcZ\x0cU\xb5\x0c\x04jm\x96\xe0)B\x9c\xff\\r)\xe6\x07\x15\xeda\xba\x98L(\xbf\xc0\x93\xfb\xc9?\xc3>\x99\x1b\x8b6\x94sZ\x19\x1en\xc7\xffO\xb7b\xe3\xa5\xdd\n\x1b\x98\xdbm\x14\xf5\xe7\x1e\xd5\xedT\xaa1\xe4\xb8\x92;\xa1\xba\xb3\xabRc\xae\xc9[\xbb\x9f\xa05\xaf8\xbc\xf9\xec0VfZ\xcd\xa6E\xc5\xc6\x8d+\xb3\xee\xb9\x8au\x8f\x19\xed\xd8"\xe3;K\xda\xa37>\'\xc1F\xbf\x9c\xdb\x06\x1a\xe1\xdfA\xe3\xfb\xb3\x15\xf0\xd5|\xe3\x05$\x9d\x8c\x10\xcb\xe3\xc0j\x8d\xdf\x9b\x9b#=#.U\xb0\xab\xe4\xc9\x1e\x8e`7\xa0:\xd6\xe6C\xdd\x84\rO\xf8\xd9k\x83\x87\xf9\x85\xea0\x02\x02\x13Ca\x04\xc8\xc8\x88,+1\xe4x{\x88vY\xb9(df\x07\xb1>\x8e\x12\x10\xf9\xc9h^\xd7\xf7\xc4I\xbfd\xa5\x80\x86\x97\x83\xb3\xaf\x06\xd0hj\xbb\xf0\xb1\x81j\xc2\xa8\xe3 \xa3w\xd0`\x19\xdb8\x10\xce."MC6[]\x15\xcc \xf8=7\xe0\xcf>n[\xbbJ\xd1\xca \xb4\x00\xba\xf1W\x87\xff\xd3\xff\xe8\xdc\xed)\x8a\xc0|\xe6\xf9E\x1a\x12C\x8c\xdc\x17\xce_\x8b\x99\xdf\xcc\xbdH\xc3F\xd5\x83q6G\x8e\xbd)\x97aJ\xd5C\xda\xf2\xac\x14\x1dF\x9f\x93\xfb\xb6\x14\x8f\xf6\xb6\x0c\x9ey"\x9b)\xfa\xc5\xac2~z\xbd\x15\xf9\xdcwS\x93\x18q\xb9\xe9\x00\xda\xb0\x1a\x05\xc9U\x08H\xd2\xb4\xdbb\xcc\xe8G\x13}\xb0R\r\x00\xc4\xf1\x81\xb0\x8d\xb9\xde5\xee\x8b\x99\xbbj\x9b`\xd5\xf6\xf8&R@6\xc0vS|\xbcZ<\xf4\xdf1\xf6\xc4\x82\x1c\xc6\xc6\xcd,\x9b\x8a\xdf\x87.>Gg\x1b\xb8x\xff6t\xfb\x11\xb3\xc9\x11\t\x9d\xeach\xca\xd2\xb3\x02\xe5X\x9c\xf9\xb9,k\x19\x13\x92m\xad\xadiS\xf9\xb2\x8ed\xe5d\xb6\x0e\xf0\x8f\xa4W\xdb\xaf8\xf2V:\'%\xbf\xfb)W\x15\xf1?\xc6"\xc5n\xd6\x8dIE\xbd~\x18\x8fb#\x93\x8d\\>\xea\xee\xe2352\x1e,\xfe\x93\x99\xf6\xc3\x1d\x01o\xa0\xf9\xaf\xba\x7f\xef\x1d\xa8\xd3H/J`\xb2\xc5\x93\xf8\xf5\xa5\xac\x9cw\xa2`kj+u\x1c\x18Hc\x88\xf7\xf6RO\x11\x1a\xe3V\xba\\3\xf46\x9ff\xc4\xb6\x05lL\x10v\xe6.\xaa\xc9\xc6\x8c\x8e\x04\x18\xf4\n\x1c\xd9\xdd\x8a\x19\xf0I^3\xa5\x8d\xba\x98\xe6\xb4\x95+\x12\xd8u1\n\xd5\x00\xe6\xfa\xd5\xc1\x9d5\xa3\x99/q\xb9Q =1\xd4\x00\x13\x84[\xca,U1\xa7\x13\xdc\xaf\xf4\xfe\x1e\xa6@\x00\xf0Pt+:k\x18G\xd8\xba?\x16\xc6\xa2\x9b\xea\xc5\x8en\xbe\xc5$9[\x87\xc2\xe0\x8ad?\x9f\xcf\xd9\xa6\tT t#]a\xcf\x96$\xf5\xb3\xee\x0c\xd3%\xaf9\x9d\x86\xa2UKw\xeet\x0f\x08\xbfy\xaat\xdf\xffh\n\xfe\xd3e\x99#\xecV\x82\x12H\x11"\x1b\x99\x7fG\xc1\xc9B\xef\x933N|\xd9\xc5\xa7\xfe\x17\x14\xf1FL \xe8\x18\x895\x12\xffG\x1c\x86%q>\xad\xcd\xf0Ka\xdc\xb5w\xdcM\xb934\x04\xa0E\x1d\xe9-\x97\xd1D%ji\xc9\xb8\xd3p\x86\x10\xa807\xa2!\xa9\x0c\x1e\xf4Y\xef\x9e2\x0c\xc4)\xec\xa2\xf8\'7\xbd\xa9\xa1H\xf1\xa7\xf29\x14&=\x1c7\x91\xbe\x9d \xe7\x7fJ\x0eR!3\xa8;:\xcb\x87b\xa1K\x1a\xef\xef\xf4#\xa5\xd5\xb3\xa6TB\xca\xca\x9b\xdd\xbfi\tS\xd6\x02W\xf1/|\x9eO4\x1f\x16\xd5\x81t\xcbw\x8b\x91\xa8\x0b\x1a\x96^\xdb\xaf\xf4\xed\xde/9UL{^\xd2\t\xbex\xb4+\xf3\xact\xa2\xc9\xcc\xb6R9\x07\xbf\xea+\xfbs\xcb\xfe5\xaexO)\x10\xc0\xaa\xe6\xf1\x91\xdcT\xe9\x8d\x04\xcfU\xe6umQ<>\xb1l\xbcgh\x80$BZ\xf4r\x7f\x11\xff\t!>\x0c=\xe2\xe8i\x02\xab\xb8\xf6\xc5\xbb\x8e\xbd\x82\xa1[Ba\x10.\x1fJ\x94\x12\x80\x0b\xaf\x18\xd9\xe5\x8e\x10\xcf\x87\xe9dq?\xd9x-}\\4\x7f\xda\x93\xbcu\x9c\x12\x86\xc6\xeb\xd3\x94\nSSu\xa6\x96O\xd7\x1b\xca\x98\\t\x90WU\xd2}|,\x1b\\\xe3z#e\x0f\x9a\x08\x0f\xa4!\xc6\xa7\xcbF{O\x95#k\xaf\xbd\xf1\x04\x8e\xa3\xd5)P\xa8\xecN\xb1\xa6E\x9d\xeea%x\x1d5*\xb1\xa4\xefY\xea\xdf\xee\xf9\x80\xec\xfb8\x91\x84\xd1\xa1\xa5\xa9K0\x98X\xa4\x8a\x92\x8c\xc0$\xa2\x0f\x121<E\xd8:\x94\xa9\x8e\x96\x92\x87\x93\xc9\xf8MA\xcfT\xc9p\xf9??\xd2&\xdf\x16\x89\x9c\x88\xe9\xfe\xf73\xf5f-\x96\x16\xe2\x04\xf0:\x98\xab7\x05\x19\xba\x07\xcf\n\x8f\xd9\xff\xbb\'\xf5\x03\xf5\x06B]\xd8ZL\x10{\x95\x1f\xdb[\x1e#l=\xea\x82\xec\xcf\x03Tt\xf1i\xde\x11*\xbc\x10\x82\xc1\xae\xfc\xaa\xd3\xec;\x1b\xb0\xd4\xaaDn\xa5gE3\xc10\x06\n:4i\xaa\r\x9b\xf4\x8e8z\x03V\xd6\xe3\xf0\x84\x19\xc6\xa7j*\x19\x92\xee\xb6\xfaI\x96\x17\x94D\xf6\x17#H\xc5\x87Y{\x13\xe4P\xcca"\xb6\xe0\x82Q\xcfB\n\xc7*/g\xd1}\xfbB8\x15\x81\x86K,\x05\x1a\x08\x84\xb8\xa8\xf51\xf1\x0f'
|
|
|
|
|
|
2024-12-14 17:54:48.290829 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25564
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808834549
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.295323 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 478
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7b89
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 458
|
|
chksum = 0xd36e
|
|
###[ Raw ]###
|
|
load = b"S\x02^b\xef\xa7\x00\xa7\xf9j\x9ah\x94\x83\xfb\xcdt\x18\xc4\xba\x86Cc\xd4\x86\xef\x0bG-%\xf4Y\x0bk\xc4Y\x98\x87\x12\xc5\xb0T\xbc\r\xc4(\x0b5\xc8\x0b}\xe4\xfe\xcdL\x9d'\xb2\xfd\xb5\x1eY%\x80\x08\xa1\xe00\xf0\x19\xa2\xe6\xe5\xe2\xf2\x87\xed\x0c\x07\xa9\x15\xe3\xff\xf8Ba\xa80\x95\xa8C\xe3\xbc]\xf8\x94\xf7\x1c\x9aq\xdd#\xbdl\x99uU\xc93j\xf8^8\xcb\xfb0J\x7f\xc6^=/=\xc6\xc4\x8c\xeb\xc3J\xae\x0b\x1cG\x80x\xfc\x82\xa6a\xcd\x047\xd9\xb8s\xd9Jj\xf5\xc9\xba65\x84.\xae\xfe\xe0)!\xe2\xd6M<)\xac'\x87l\x84L\x86\xa8[\xb7\x9f\x93\xed\xafR E\xa6\xd6\xd3\xc1\x8e\x1a\xff\x07\xffQ\xb5\xa1)\xf9q\xb3\x81\x02\xc6\xe0Q\xd625\xb77]\x99X\xc8\xd2\xfc\xff\x1a\xd0\x119\x8a\x1dq9+\x16\xe8\xee\xed8\x8f\x9d\xbc\xaeInFl+t\x87\xd4\xcf;)\x13K\xd5\x91\xf4\x0c\xaed:\xdfn\xe2\xbf/\xdc\xfd\xa1\xc1IXbo\x8f\x95\xc1*r]\x06By\xbb\xf6\x85\xf3\xb8\xb5{\x9cZy6\xd5\x81]'R\x08l0!\x0c\xaa\xf8v\x11E~%\xb9*BJP\xbe!A|<\xa2\xfe\x91P`#7\xf5\xf8\xa4\x897w\xf0d$D5\x86\x82#\x8d\xe2\xff\xcb\xa5\xdb\xbad{R\x81\x00f\xbc\xc1\x9dI\x12\x16\x17>z\xeb=\xe8\xfbUi\x85\xb1\xa1\xe6>lq0\x92\xb5c\xe9\xd2\x0b\x07\x9b\xcd\xce\xe3\x01\xf2.\x1dT\x9a\xf8;\x97\x84\x91\xe7j\x11T\x85\x8e;[\x8c@^J\xb73c\xc6QEg\x9b\x7f\xb8\t\xdd;\xfdY\x93\xe7\xfdH\xb8\x13\x82*\xfb\xcf%\xb8\xe5\xe3\x92/\xf5OTlU(\x9crJ\x1cH\xbe\xba,\x03"
|
|
|
|
|
|
2024-12-14 17:54:48.306614 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 5880
|
|
id = 47931
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf57b
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808834549
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xdd\xa6\xef\xf6\xc11\x8d\x83q\x99Z\xc9\x05\x9b\xf5%\xb6\x00\xc0:\x1d\xbd\xb2}bVg\x8b\x9a|<\xf2c\xb5C\xfbA\xa9\xd7\xfa\x94\x11\xfcr\xca\x95\x8e\xf5!\xca\xf2\x12\xda\xd4\xb6 \xe8\xf6&\x02\xc3\x12CN\x18\xad\xd6\x08\xd8\xae\xe0\xf9\x84s\xf8N\x98AK\x9c\xa9\x91\xcc\x87\x8b@j\xb1\x00>fS\x1aFmQKo\xfa\xfc\xf2r\x9f\xae\xfa\xc8`=\x86\x1f\xd9B-w0\xe1{&\xb3\x9b<\x98\x17\x92\x1d\xbbS\xf7\xb44\xa7U\xcc\xd6T(\x80`\xd2W\x0e\x92o\x13^\xc5q\xd8n\xb1\xda\xd7\x10\xdd\x89\x15\xb9\x1bu\x98~_\\\xd440C\xc6U\xad \xd4\xb1\x9cI\xa1J\xf4\xb9\x87j\xd5V\x88x#<\x07\xf0Y\x88x(\xe0\xa6&\x87\n\x08_I\x0b\xceB\xfc\xdfv@\x9e{\xf3\xc24p\xa2k\ty\xc8\xcc\xc5l\x12\xc5\x0f\xdc\xf6v\xf4\x1dp\xea.F\x8c\xa7\x03\xc3\xa4\xed\\\x87\x91wC\xe9\xfd\xdb\xf6=\x95$\x86\xe6\xd2\x0e\xeaE._w\x9b\xb8\xb8\xf9\x11\'-\xc2\xc2\xdbN\xbb\x14\xfc?\x85\xc8\x9c\x00\xc2\xa8j\xfb\xebup\xd3}\n\x86S\xc1\xc4\x9c\x19\x0c\x89\xa3\x81ON3GLF\xf5\x90\xdc\x18\xbb[\xf5\xd4w\\f\t\xf2\xe4bo\xa7\x9f\xbf\x9e\xb53\xfd\xf2\xfd;\x0b\xb1\xa5\xe4i\x9b\xda\xff6\xb3\xcf&\xa8\xd4\x0c\x9f\xb7q\x1ei\xff\x99\xad\xb3\xf4\xf1~z\xcc\xb20\xe5h\xa6~\xf8}0r\xfd\x7f\xfeg$\xdb\x83\xd2\xe7\x00\xfa\xa4g)\xcf9\xba\xc3\xb7\xb1yp\xa9\x06\xc7\xe2\x8a\x8b\xbe\xe8\x7f\xf8\xee7\x8d\xaa}\x07\tV$:m\x9aO\xe82*+\x15\x9f-\x14I\xa7\xed8\xcbu\xf3\xa2ZO\xb3\x11\xb1\xf80\'\xbf\xb1\xd0\xf1\xe3]4\xd7_\x9a\xfd \xb1\xfewv\xecIw\xf8\xf5\x89\xdf\xa7;\x85*l?\xfazN\x18\xce\xa84M\x95\x1a\x1f\x10K\xe1AQ\x07\xc74H\x97d\x01\x8c\xdd\x02j\xf9k\xb4+\x8a$:\xean\xb0w\xe0@\x15\x00\xa9/\xd1\x8d\xcc\xe5\xb4I\xcf\xe0k\xbc\x8aFuK\xcf\xd9\xd7\xa8n\x86\x15H\xbb~\x14\x1dFRj`8\xa0+i\xa0F\xaa\x1d\xcd\x7fb\xa8\x91\x85K\x1a\x17\xe1\x08\xdb\xd4\xe0z\x13\x15\x1btkJF)YM\n{\xbe\xb1Z\xaa\xe9\xb8\r\xbf\xd8\xea\xbd\x9e{#\xe3\xc5\xf0(\xac\xdcdm\x81\xf7\xc2\x0ee\xda\xcfg\xf2\xd5=\x10\xfa\x95z\xa4\x82v\xe4*dE\xf8\x9f\xa6\x02\t\x90M\xa3\xb9\xa5\x18V\x00\x0c\xf5\x96\xee\x15w\x0ck\x8d\xa3;&\xab\x9do.\\d\x81\xc6MC\x1a\xe8\xc8\xd5\xb4\xe2\xdb\xf6z\x84\x0b\x95\x06\x94\x93\x99\x01\xe9\x82:\xd6P3\xa0E\xc1\x07\xfa\\\xd9\xc9\xce\x9e\x1b\x08\xd1\x1bo\x05\x08usr\x96h\xa4*\x84\xcc@%\xf9\x9a\x19\xee\xea\x10\x10\xcf%\x8e\xfe2\x1b\xfe\x94\xe4\x8d\xc8B\x12zq\xb4\xee\'"82\xf07\xd9R\x9b\x0bl\xd8\xe9\xf1o\xbcW\x0f\xf5\xc6\xdc\xfd\x9e\x14\xea\t\xd1uE[-\xa0\xe7E\x89:\xc3\x1f\xb6v\xfa\xce\xfd\xeb\x95v]\xd0-\x04\x9e\x94\xe9l\xfe\x9b\xba\x8f\xa8\xd5,)f\xe4\xab\x81\xcf\x9c}f\xc0\xad\xb0~pv\x12\xc1\xd7\xd4\xe7\xf7n\x0c\xaf\xd2\xd1VRI\xfb\xcc\xd2\xc7\x0fb\xd4cI\xb4d\r^\xf8)\xd5\r\xe5H{\x83\x84\x11\x9b\x1f^ZA\xfe\xe3\x85OT\xc0\x0e\x91\n\xe9\x0b\x05\xeb;/\xba+(U\xe6T\x958\xedU\xcfty\xdd\xb0\x8f\xfb\x0b\x9e;l\x1f\xd2\xe7N\xca\x83\xc9\x18\xcf\x01i?\xddn\x15\xe5u2\x10sI\xdf\xff\x1fcv\x90\xbd)\xf8\xbbtA\xcd\x95\xcc\x93\x85[7\xd7q\xf2\xf3\x844\x80v\xc0FM\\3r}\xedw\xee\xe7\x88\xd5\xb8\xbf\x02Y?\x87O\x18\x15\xc5\xf6\xfe\x1f\x1f/|\xad\xc6\xe9\x99"\xc8\xbe\xb3\xe7\xa4M\xc0\x11W\xb1\xb7\xebN\x87[b\x99\xc9>\x97I\xe0G\x1f4<\xe7\xed^O\x04+\x81\xad\xfb\x15\x94\xce\xdd\x98\xadKI\xbf\xad\xe4\x9f\x8f\x95#\xde\xec}iw\xdb}mk\x17S\x08E\xdf\x85\x82\x10\x1b\x94v\xdf\xd27\xc64\xbe< \xdb\x85\x10\xc8\xbb~\xe6x#d\x06\x15(\xca=Eq\xb3\x0c\xef+\xf0\xaf1\x9c\x1f\xca^Mp\x0f\xab:\xec\xbeI\x1b"\xb2?\xee\x80\xe9\xca\x85\xdd>\xc3\xeb(\x98&\x9c\x95\x18\x13|x\x14\xfe\x14{vo\xcf\xf0\x07\xfc\xae\x98\xa3\x1b!\xfe\x8c?\xc8\xfbJ\x85\xf8dJ\xde\x86\xb6O\x92\xcf\tZ\xd2\xe0\xfc\xe9|\xc39\xd5\xfe`\xf6\xaf\xd7\xc3\x9d\x8f\xcb\xab/!M\xae9\x97\x8a\xdb\x8e\x82\xa4;1;\xad\xf8\xebQ\x04\xedEk\x85\xdd4\x7f\x17:\xa4M\xb9\x82,eoAFCt\xa4\xab-\x0c\xda\xd9\xf9`\xaf8\x0fn\xb4\xeeV\xd9\xae$`\x9f\xee\x99"X\x05H\xe3\'\xc0\\\x0c\x93MA\xe6\x08/\xd2\x0c+F\xc7\xb7\xaf\x15@w\nc\xa1D\x1c\xca\xa6\x8bC\x16P\x1a\x7f\x9f\xa4jc\x8b\xb9\xf2\xc1O\x9f\x85\x07?\xb9 \x90>\xf7\xc6\x06q\xf2\x91\x89\xc6\xf2\xf4\x87+0\xbf\rr\xaf\x88jr\xd4\xef\x10\xa8*\xf65N\xb5\xea:^\xa9V\xff\xe9\xb9\xbdk\x9ajh\xa3/Gamj\xee\xc3\x8cJ\xd0`\xdbY\xc9\xf3\x1f\xfc^\x12RE\xd2u\r7\x95xZ\x819=\xf1\xb4\xf4\xff\xce\xc6\xe4\x7f\xe3\x10\x08\xf9\xfc\x01O\xf2\x97\xa4wQ\xfa3\xcd\xfb,%\xe3\x122\xd0\xb4\xca\x10\n\x8f%\xa2\x9e\xfa&\xc8qm!\xf0ufC\x80@\xffq\xc7\xf7\x87 \xfb\x9c\xa9\x8c\x04\xc7\xa9%\x06/\x1f\xb7\x11\xdd\xc8#\xef\xa7\xeeA\x83\x8d\x89\xa1,\x8d\x1aR\xa8\x9e\xea\xe8(R\xf9:V\x04_:ff\x82\x1d_\xb1^\x17-\xed\x7f\x86R^\x0c\xdf9\xc7\'\xb0H\xa9Y~r\xe3p\xff\xa7\xee(\x08\'*[\xd2\x17\x03\x03\x00\x1a\x81\x8d\xbfA\xe5x?L\x84\xbd\x1e\xd7\x97n\xff\x1e\x8e\tiv\xf9ej(1t\x17\x03\x03@\x11\x0b\x9c\x7f1\xe8\x90^\xd7;\x0b\'\xaaB5\x9d6\xff\xe70~\\\x06\xfb\xcf\xe0\x88\xfa\xe1\x1b9\xe6F\x7f\xf8(\x1d\x822\xe2\xe9a\xb9\xbb\xf8;\x93\x07K\x04\xbe\x9d\tep\x96S(\x8d\x11\xb06g*\xa0l\xac\xe3\xcc[.\xcb\xa1I\xec\x90|\xe5A\xa1\xf5\xe18\xbc\x93\x0b\xd7H<\x84\xbb\x80\xb9\xd8\xecID\x1a\x9d\xed\xd9E$\xe0\xe1\x01\x9c\x85c&\xf8\x03\x96^\x11\xdb,;\x88\xbc}\x7fO\x1ceVl\x9e\xb8O\xdf\xf6\xa9\x03\xb1\xa2\xf9\xa1\x86\x1b\xc7\xb4.V\x07\x15%\x03\xadD\xa53\xda\xb4\xa4\x16>\xfd\x1a\xee\x03\xa4P\xf6\x02rq\xdc\x92\xc9\x10\xc69\xad\x9d\x99\x8b\x88Q\xbb\xa1\xdeS\xe8\xe1-p\x82\xf3\x03E\xdd\x05\xf5\x9b\xed\xb5Zo\xe6\x81\xafY\xba[\x8f\xf8\x00\xd6\xfe2Q\xc3\xeb\n\x08\xf78*\x05\xaf\x98Z\x8b"2\xb0r"\xf3\x97\x95<c\xb7\n&\xa6u\xa3\x0e\x01uh\xa9\x98\xc8u\x86\t\x9c\x11i@\x07mo\xa2!\xa8\x1eM:\x8c\x94\x02K\\go\xaa\xdc\xd9:\xe7\xb0\xec\xf9\xefK1dk\x9a\xc5k\x1b\x02\xa5b\xe9\x9b$J\x1aX\xb2\xdf\xcbL\t\x8e\xe0PT\xe6M\xa9%\xd8\x1d\xbd\xd8\xa2\xb7G\xa4\x02\xca\xd0,\xf0c\x89<B\x15\xb2\xb1\xf37\xbaG\x111\xc89\x15\xce4\xa3\x03c\xeb\xc7\x19~\xdbi\x1b\x95\xb4c\xaf\x00\x8e\xc2\xb5\xc9\xd2i\xdd\x1b\'t_\xd7\x1a\x9b\x1b\xf3P\xb8A\x87\x86yW\x9ee>\x1f\xfc\x90\x15*$\x8br\x1b\x16u\xda\xb9\n\xac\x8f\x82WP\xbdDs\xc3X\xe0W?\xa1\xd5\n\x0b\x11A\x1f(\x12\xb5mn\xf77@.\x8cSl\x1e=\x05\xbar\xf1\xdf\xb0\xf8\x06O\x92\xd9N\x924G\xdb\x1a\x81D\xd7\x11\x88`\x12\xe1\xd9\x99\xf0\x94\xfb/I\x95\xee\xd5#\xc8`I\xb3\x83z\x86+\xa3\xa8Mq \x937\xb6&\xaa\x83\x86!\xcf\x874\x89\xfb\x9e\xae\x87\x0e>\x83\xcf"\xca\xeb6\'\x1f\xed\x14+\xfe\x8a\xad8W\xe4\xa0\xf3|\x03~@nu@\xe6\xa9\xd0\x98\xa1D\x8cC\x11\xe2\xcd\x0e\x1b\xb3\xce\x05(\tSn\xf62\x05\x1f\x0c\xa4\xdd+\x1e1x\x03L\x85\x19\xe5\xc3\xaa\xf4\x82\xec\xe5T\x9e\x1a\xd1\xa1\xf2\xf4\x91\xea=\xc0\x05a]\x95\xe6\xbf\x06\xbf\x98\x8f\xc7\xc5\xecQ\xff\x8cMU\xd9z(\xe0>Q\xc0\x1c\xa6Xj2\x0e\xac)\x10\x15\xf0|\x9e\xd5\x9d\x02\xeb\xa0\xda\rBQ\xc5<\x94x\xe6\x8e\xf4\xba\xef\xc5ck\xa2.\x8f\x0b\xfd\xd1\x14\x16\x12=\xd5n6\x00\xd3nM\x98 \xadF\x80\xcfc\xa8\x00\xcb)\\\xac\x0e\xe2\xe66\xb9u\xc7\x03\xec\x1c\xeb$fR\x1f\xcdr\xf2\xa0\xcd\x879h\xb1w7,\xed\xed\xe4\xf9\x11\xe7\xd5\x98\x8e\x89;\xbb\xb3\x86\xa7\xb698\xd5\xfbc9\xb0y\x87\xadxd\xc2R\xea\x01\x13\xad0\x9ck\xe3\xd4\x9e\xa5\x16\xdc\x11\xb1S\x8d\xf8\xe1QU\xb6\xaf_\xbd&\x85=\xf2R\'\xd4fQ\n\x8a\xa9\x02Wx:Y\xed\x9d\xfft\x0f\xee\x0c\x92\xe5\xe8\xa5\x85\x99\xce0Jd\xfd\x9f\x06\xb1\x01+\xa9\x8cN\xef\x0e\x00\xb3e^\x1f\x80l\xb6(\xfa\xdf\xf1\x91=\xb4O\xedq\xd1.{\x00v\x81\x9f\xa8\xaf\x8b-\xc1o\x7f\x9c*\xa17\x87\x84xa#\x86\xf9[|\x0f\xd2\xdc\xd3\xc7\xb2\xb9VnwSZ\xb1\x07`\x18\xaa\xff\xd6\xe2[\xb3\x05\x9e\n\x10\xcb\n_\x80\xb5\x18\x16\x9aW\xfcg\xa5\xb7I\x1c\xd5+\xf7\x93\x99\xe0~\x0c\xf23>\xf4\x9e\x849\xcd|\x13\x9bIe\x14\xbaj\xd1\x97\xcb=\xc6\x00\x8b\xf0\xd0\xba\xb1\x10\x1f\x85(\xd8\xe9^T\xb5#v\xff\x16F\x8bE\x833\xd5\xe5\xeev\x9cOE\xf0\xc6\x8c\xf8e7\xd9\xe0\x031\x87\xcd\x15\x92\x8f\x12\xb1\x1b\xad\x98\xac0}\xb6&k{r\x86}\xfe\xad\xad\xdb\x92w\x05i\xf0\xcd\xaa:\xdcy`B\xbcx\x98\xec_W\x07\x97\xb55\xeb\xd9;\x82\x0ei\xc1k\xbb\x07a%\x05\xea\xbc\xa78l\x98\x96\tzy\xe6T\x93\xf6\xc7q\xad\x01F\x99hl\x18\xfa\xf9\xe2Iq\xf9yA\xf6\x8ax-E[X5G\x9b\x8c\x8b\xd5;;\x15|\x1b\x8f\x01\xbd\x7f3z\x97\xb4\xdf\x82\x06\xb6\n-\xdb\xdb8B\xfe\xf7\xd6O\xff\x10\x8c\xd1s\x7f\x1cp,\x07\x8c0r6\xb3\xbf\x89\xbeR\xb1\x90<\xf5&CRZ\xc8\xa0\xc9\xc0\xec\x00\xffUT\\\xee\xf4s\xd8\x00\xa4\x02\t\xeb\xfe@\xd9\x0e!\x1aa\x825q\x89\xe96/\xd0O2RN\xe8 \xf7v\x1b\xbc\x99\xdc\x17\xe10\xdc\x8d\x1c_\x81\xb4\x04\xa49\xbd\x0eZ\xd3\x19\x9d\x14\x86\xcb7\xb9$>\x93\x8e\xc1\xb8\xcf\xe8h\x1cBd2 \xe45\rN\xcb\x9a}\x95J#y\xa3\x89\x0eL\x14\x1a\xa9_\xc8_\xed\xdfS\x1f\xc4\xaf\xb3\xb2\xff\xa44"-\x91\xf6*\xde\xb5\x88h5~\xc7\x0f?1< \x13\x90B\x12K\x04?B\x1d\x8f$\xaah\xedwz\x89\xe2n\x89\x12F\xec\xd0m\x80\x13\xf0X\xba\xfc\xe3\xf7\x1f\x86\xf8\xf1\x1bO\x1eo\x97\x13\n\xcc\xbbJ\xf5"\xb7\x05\xcd\xe1=\xbea!j\x0b\xbe\x81c\x10\x90*;\xef>I&\xc4\xb04\xf7\x8e\x08\x96\xd9\x1f?m2\x97\x1c\x9b\x1f\xa9\xcd\nZ\x84R\x84T4[\x14\x06\xa0K\x0c\xcc\xa7\xe5C\x9b\xfc\xb6\x0b\x1eK\xdf>\xddJ\x95\x9c\xf3\xed\x01\xd1\xf2\xad\x9f\xfd\xc8]K\x87<X\x086\xce\xdd\xed:\xc8\\iI\xb6WW\xe8\x8f\xe7{-\xd3\xa0^\r0\xae\x14X\xa9\x88\x90Ed3\x87\xcaA=\xfa\xab_\xcfm\x1ek$\x15w;b\x06!\xa8\x00\xe0Jq\xfe$x\x97k\xc4:\xbfq\xe8\xbd\xa7+\x10\xe2\xfbf\x08b\xb0\xeb\x83\x90}JB\xebN\xb4\xbc\xda\xce\x14\xb3nzd\xe6s\x84*\x07\xfc\xbc3\xff\xe5\x00rw\xe5\xaa\x05GM=\x95\x12\xdb\xb9{\xf9W/\xf57\xf9\xf5\x04\x97(\x9a_\x8b5\xa3\xd4\x00\nu\xdf\x89\n\tO\xaa\xbd$\x8c>\x00\x11\x17x\xb9\xcd\xc80mj\x7f\x0b\xec\x9b\t\xf8\xfd\x17:\xef\x9d\xf0f\x87\xc5\xf2\xa2\xa3\xca\x17\x01S\x99\x11\xdd\xc5\xca\xe5\xfb\xfcXKDD\xc0\x1b\xb6,\x1d\xc7\xe0\xf0\x86\xf8R9-\x98s\x06-|\xf9\xfd\xca\xe5\x07=j\xa1\x94\x97\xc9\xd8\x12\x16$P\x96c\x85bUg\xb0I\x13\x06\x10\xb6)I\x1dZNP,z\xba%S\xdf\xc9Z\x14\xf4\xc9\xdc\xe6\x88HL\xb6G\xd7\xe9\t\x1d\x9a\xf6U)\xa2\xd1\xabQ\xad)\xb0\xb9\xff\x140]\xc2,\x96{\\\x11E\x8e\'\x9d\x18;\x17?\x8a\xa44\xc5\xd1\x8be\x9c\x9a\x8d\xa36\x9e/\xb4r\x89\xff\x83\x84[\xc4\x1a[(m\xc2\x18\xd0S#\x9c\xef\x1dK\x90\xb5H\x11\xee0\x13,\xff4vo\x99\xe5\x07\xbe?\xff\xb3\x83\xa5\x81\xd6\xc4\x195oe\xfc\xbb\x8a\x07\x9b\xc6\x94\x14\x10\xbd\x0e\xf0\tkj\nk\xa2\xfa\xe9]A*\xf0\xe3\xe9\xfde\xcbp\xe2GL\x1azh\xfd\x99q\xf5\xe6\x1f\xb8\x88\xba\xf0!@\xb0Dgl\xc2\r\xae\xcd\xf1\x1fKD\x8b2:J\x16\xac\xc1 d\xdd\xccK\xc8\xfbM\xea\x9f\x08\xd5\xf8\xe7\xbb3/t*\xf0\x8b\x03\xf2=\x0fN\xec\n#Z\x7f\x1a7Gg\x05?\xb7\xd3Z{H\xc0\xf7i\xa4\x80\xb2\xaa\xff\x97Oh@\x96#\x05\xc1\x84\xec\x02S\xaf\x85T\xc5V|\x0cQ\x17\x15T\xdd(F&@8\x13\xf0\x94\xfd.\xab\xd4\xc2rSXn\xaf\xd8\xe3\xf7U(\xd5\xf4\x9c\x0e\xd3m\x05\xd2\x04\xfd\xc46\xef\x80,\x170\xa6@\xb1\xb4tRH\x00\xbaj:\xe6\xa0\x9e"\x97\xa1\x18\x0e\xaa\xf5\xc8U]\xed\xd5\xaa \xbb\xdd\xc5-\\h\xfd\xdf\xc1\xd5\x99\x97\xb2\xa8\x04w\x82\x84\x93\x10U9\xa1\xf4\xd0\t\x1b\xc16\x9dw\xb9O\x8cR\x94\x0bgM1+\xab\x8a\xc1A\xc7\xa4V\x00.1\x14|\x89\xbdw(+*\xec\xd8D#\x1c\x97\xd0\x83\x11k\xe1\xe2\x83\x94D\x88\x97X\x80\x1a\xcf+\xf1\xe3\xed3t\xf3>\xe0EN0AU\x11\xd5\x90\x96$\x8f\xfa\x16X\xde\x94$\xcb\x9b\xffI\x84\xb5\xc1~u\xac!\x01\xe0\xbb\x8b\x06#A\x0e\xddI\xd8\x92\xd5H\xc1\xaa\x8c\x19\x16K\x19\xf6kf\xa4\xf8\x86\xf5\x18\xa9\xc4#n\xc0\xb1"\x06\xd9\xd1\xa4\xbaB\x9bW\xaa\xa6F*\x87\xf3\xee2!1\x17:\xa0\xb8\xccq3_=\x0c\xd6\x89\xaf!\\\xd6\xa7{")\x1b\x007\x1f+.PE\xfa0]\xf5:p\x81h.#t_\x83\xfa~\xeb@*!\x87\xc8$z\xf6\xb3sc^\xd0\xecU\xae\xb3F\xb4\xba\xb3\x1e\x85\x88\xdf\xf2\x85\x1a[\xbc\xa1/\x17\xe0\xcd\xe6\x90\x17\xeb%&\x1dB\x9b[|\xd2f\xf3)\x07\x94\xa8e7\x01\xcf\xee\xef\xc8`\x93\xc2\xd1w\x85\xfe\x02\xf6\'6\x8e\x96\xbb\xfc\x82\xef\x9e\xfe\xab\x1a{\x8d\x1b\xf04\xa7\xda\x83\xbf_\xee\x8e\xb39yh\x03\xaf\xff&\xc2\x15\x00\x07\xbe\x1b\xbe\xac\xb0p_c\x962d\x15\xd7dw\xf1n\xb1\x8e\x1f^u\xbc\x17\xd9\x18\x93[\x90\xe56{\x9b\x08\xe3\x81\xf5\xa0\xdf\x1dR\xafC\xe1\xa1\x06Y\xab\xd9\xcal\xb42f\x8e\xdb\xa2\x91\xb3\xad\xeeJX\x16\xa9\xa0\x01\xc1\xe4\x88\xebj\xf0\xb1\xa4%\x10\x00\x16\x01\x16 N]8n_\x1e\xbf\x03\x12\'\x95\xeb#\xdb\xfe\x99J\x0f\xcc\xc7\x95\xd1BY@\xe0\xd8\xad\xf5\x12\xb59\xda\xca\x9e+\x0e=\x16r\xfeAT\xfe\x1d\x1cT)\xd2R\\H\x9b\x1c\x19I2`\x1b\xd2\xcf\xc3\xdf\x9c{\x96;\xe6wH\x11\xf6\xc5\x9d*NG\x02\x8d\xec\xfd\x971:\xe1\x82\xf9g\x00\x84]P\xaa\xf9\xd4\xdbh\xe8\xb0\x10A\xce\x91e\xc06{\xfeN4\x9av!N\x05\'{\x83\xd6\x84\xa0+8\x88W\xb7M\n\x9d\xc4p\xd3\xa8\xfd\x1d\x06~O%$9\xa0\xaf\xb3f}\xe7\n\\\x1b\xb5\xee\x9cm\x88\xe6q*|\xf11@\xb2\x95\xf6#,\xe1\x08{=\x05\xf5\x91\xc5!\xa4\xfb\xb3\xb1\xe0$\x89\xa1bBq\x03\xa6\xd0\x8e\xd7\\q\xf7z\xedk\xd7\x0f!\x14\xb6\xb8e\xd4\xc4n\xdaP\xa1+@\\\x1a\xea{\xfdJ\xb6CaF\xe0\xab\xed\xf8\xd4\xe0\x83\x1eP?F-\x88\x8a\xa3\xbb\xb3,\x97^\xbc\xbc\x98\x95BM\nv\x13t\x18\x1a\x8ca\x1a\xa7-$\xd8\x11\x94\xecW1\x84\x1a\xa6\x90\xbd(X\x8a\xefq"c\xa3\x8e\xfe\xe2*\x93\x90\x89\xc5\xf2N\x1bI\x90\x13bq\x88\x1f\xe5"\x17\xfag#Q\xa9\x0c\x80\x10z5\x95h\xc7\xa8o\xbcW\xbdi\xa3\xccL\xb3\xc20gz\xae\xdb\xaf\xb1\xb6#d\x1cV\x19,Sp/\xdd\x15i\xce\x8b\x00\x92W\xd4\xfa\x7f90QP(\x1c\xd3}B[\x01\xf4R\x07\x02\xfa\xf3\xe8\xfc\x1e\x0cs\r\xba\x96=\xd1@!B \xa8\x99\xce\xbcv:8\x1d\x89\x8d\xcc\x02\x89\xad\x92\xc7,\xf6X\x08\x91zv\x00n\x85\xc2d\x1c.\xb6v\xe9\xd2\x86\x1f;\xd1\xdd\x02\x1ecn9>\xa7\x08O<\x92\x837^/\x92\x97\xc4\xe0\x98\x11v|+\xa2\x1f\xb6\xb0\x80q"\xd1\xc4%A\x1d\xec\xfaW1\xe1A\xa1\x13\xb2.\xeeZ\x14$XG)>%?f\xc6<\n\x03y\xed\xa1k\xce\xbd-\x16\xbc\xbc\xcc\xf1\xc5x}\x92j>N*H\x8e\xa9N\x14\x1e \xd0\x87x\x0f=\xd3\xd9G\x10\xa4\x0f\xa1\x7f\x02\xc9\x8d\x95\xee+\xca?]\n\x8av\xddg_\x95\xca1.\xd7I{\xdb\xc3\xaa\xd0e\x01U\x9co?A\xed\xcc\xd9\x91\xdd\xad(\xbd\xe0\x16\xf4\x91\xf7\x10S\x0fm\xc9I\xe7\xe6\xa7m\x1a2X\x8c{Ul;\xa1\x7f\xa0\x18(s[!\xd5=\x17\xe5\xce\xab%\xf0\xbd3\xce\x88\x94M \xe3\xca\xf8Me6\x06\xf5\xa2t)\xdd<\x1fb\x1b\x0c\xbf\xdfW"\x07"\x85\xd2\xac\xf10\xcb\xa0\x89\x87\x145(\xcc\xf3*\xb3\xf3i\xb0\x9d\xf5D\t\x03\x90X\x1d\x85\x11\xe5v\xbaE\xb9c\xd67\xf6\xe2\xaa\xaf9\r\xca\x14~\xcb\x7f\xf2\xb1\xc6U\x9c\xac^\xf1\xae\xf9\xe8\x0c\xc6\xc4\x9e\xdf\xd9;\xdc\x12ly\xf9\xabX\xfc\xabL.\xc3\xdf\xc2\x90\xeb2\x013\x1bI%\xba\xa4\x8b3\xea\xacv\xe8PQ\xb3\xab4\xd8\xa5\xf0Q\x17\x94\xbb\xe26\x96]?^\xd8u@\x82\xa5v\xa8\xa0\x8et!\x9f\x88\x03\x7f\xe2\xe3\xe0b\xacy\x98\x98\x8dM\'F\x9afe\xd8\xa4\xab\x8e\x94l\x94\x96\x00\x85\x8b\xde\x1f\x89\xbd\x83\xe5\xdfBG\x9ee|\x99\xdd\xd2\x8a\xde\xe3`\x9a?\xd8\xab\x07\xfbl\\$\xd0\xf0"1\x9d\x81\x13\xa7\xc5c\xad\xb4\x80E9\xb2f~\xfb-\x0f\xa5\xc3\xb1\x90%\x11\x0fL\x18A\xbf\xc6\x9ak\xd6\xf5\r8\xe4\xfc\xf2\x95\x9bxk\xa1O.Y\xdb\xd5\x9f\xfb\xf67\xf3\xcf\xb7K\xa05\xec$\xf5\x0b\xb4\xae;\x16\x17K@\xc3I_<\xbc\xb5\xee\x7fSJP\x02s\r\x12\xcd!\x1b\x1d\x04Qb\xe2\x0b\x1d\x00b*<\xbf\x92\x04*$\x81u\xc4\xa5\x03`\x8c\xe0@\xd8\xe0`\x10\x97\xb5O\x13\xd6\xf3l\xcd\x8c\xa7\xfb\xf59c\xd0{lf\x0fcM\xe8\xc1J\xc5\xaax)\'\x05!\xed\x8ee\x11z4\x07B\xbb\xc4+\xcd\xfe\x8d\x96T\xa3R\x98\xa7,\x1dcO:\'~\n\xeb\x1c\xed_q\x99\xbav\xb2\xea\xac\xde\xf6\xa7\x00\xd3C\x82G\x9c7U]\xacd9\xd0\xce\xb3\xae\xebHn2\x87\x87z\xe7\xe3\x9a\xb8W\xd7ZP&\xb6\x88C9\xcf\xe5\xba\xef\x9a\xbf\xb9\x17\xad\xd9\x9cP\xd6O\x1d\xc8\x1a\x9b\xbf)\x9e:\xb4\xa3\xd4>\x8f\x80\xaf\xb7\x04+\x94\xef<\xe2kW,\x80\xa1\xb1-\xd7\x82<0\rY\xc7W\x0b\xe6\xc7O\xe4Js\xc3\xa5\xb4\xacN\xa0:\x9az\xbc\xca\x15h\xde\xed\r\xf9\xd7u\xae\x84?\x9d\x08\xfd\xb8\xc1fE\xb1\xd8d\x19\x9d\xf9\x10\x13\xd6\xae\t\x0b\xdfT\xf4\xf0\xef=\x06\x83\x1c\tq\xb4v\xc8\x0f;\x18\xe5\x9d\xdb\x04~\x01b\xcf\xf2\xc9}\xf5\xd3\xcbz\x99CI".{[b\xa89\n\x1a\x8c$\xdd\xd6\xfb\xe7\xae\xc3_\x8bY_\xb7\xc4\xbc\xb1\xc6\xf1\xa5iAc6\xca\xe7\xceh\xf73G\xe3?+W\x1e\xbeQr\xe3n\x88\xb7\x03\xdeb\xb8$\x9f\xca\x17\xc7\xe3\x98\'\xe0\xa1\x1f\xf4=t\xc3\x7f\x1a/[\xe2\xc5\xd0\xf89\xe5L\x1e\x96f<\xee\x98Q\x07\xc7\x8fn\xe7f,AT\xa0\x83\xd9\x91\x10U\xa0\xa8\xdaD\x8b$P!\xeb\xc8\xf1#&\x91\xe5\x82x\xf3\xa8\xdfh>\xe6\x95\x8ay\x106\x0b\xee:\r\xd7Nc6\xed\x91\x8d1|\xf2\x81\xc1=\xac\xf7;\x99\xe7J\xcd?\xcb@U\xc1\xa2\xd7-\x07\x1d\x1c\x04\x83\xf7\x84T\xe7\x82W\xb9\xafm\x056@\x95\xd0{\x1c~\xb5\x9b\x1e\x1f.\xb6\x8d\x93\x98Os~_V\xa2\xdc\x19u`8s+.\x8e\xe6<WE\t\x98\xec\xeb\x82t\xc1*W\x92 \xf2\xd0\x01\xbd\xf9\x1a1_k\xf3AUZ\xe2\xd2Xq\xaeW\xcd\xaf\x0b?f\xe1sB\xcfv}\x93}\xae\x08nHG@\xdf\xe0\x054\xe0\r\t\x18\x80\x93\xdd\x94k\xd2\xc9\xf7\x94&\x91Xz\x05<\xaaLz\x93\x19\xfb\n\xb2)\x06\x88\xf2\x14=e \xc03\xd6`\xb6x\xfbc\xff\xc6\xd4\xde\xa1\x19m\x92v\xccG\xc2\x919M\x12t\xfd\x84\x0e\xf6\xc1\xbe\xbd{<)\xa8\x82\xb3A\xb0O\x8a\xf4r\x18\x88\x93^\x8a\xf7^ \x14\x8b\x10\x11V\x14n\xf4\x08\x0c\x1dm\x07\xfeOy\xbd|&I\x1d3\xe0Y\xc4\xc3<\xcdV~EB\x13\x0e*\x90z\x8f\xbe\x99\x9e\x0c\x07\x13!\xcf\xc9\xb3\xefceT\x86\xd3\x80\xfc\x96\xc8\xf6\xdf;\xca\x0b\xf9\xf8{M\xb1b\x12m9\x1d\xf6\x02(\xcf\xa5\xb1\xc4Q\xc4\nr\xe1\xf6D\xc5\xfa\xfeV\xd8\x17U\xc7\xbc\xcei\xe4\xcd\xe4n\x1d\x03\xce\x0bB&Q\x7f\x19\xf4P\x05\x97\xcc\xb4\t=\xb9a\xfb\x8e\xf4\xce\x88W\xbc=)\x18\xba\xdb\xb7sY\x1d\xc1\xc3\x00T\xc7\x1a\xcc\x94\xf7^\x86\xbd\xee\xafqe\xe9\x93\xc0\xa3\xefe\x99\xb0K"\x91\xa4\xb1O\xb6\xfbn\xb7\xb9\xd7\xf5\xe8E\x97\xc1\xe1\xe72\xc4\xdd\x02\x7ft\x01\xddPm"\x11\xf7\xf8<\xdb\xe0\xfa\xd9\xc8\r\xcb_\xd4\xad\xca:\x8e\xe9\xff%\x88!\xb0f\xfa^)S^t\x170\xba\x04\x17\x07\xdb%4}TX\x99jN=\x96\xff0\n\x16n\x9d\xccL\xdaI0\x1deW\xa5^\xb9(\x91k.m[\x04\x86Qg\x9eon\xa5\xf6\x84\nJf_\xf9\xc6\x9f\xd1\xb5 \xed\xf1\xfa\xc6\x12\x0f\xea\xe6u\x1f\xecc\xae\xcc>UZ\xc1\x9e\xc2\x8a\\8V*\x0bQ\xcd\xa4\xe1\x1a\xfaH\x0e\xcbN,RFVC\xbc\x06\x88\t\xdc6\'$\xfa\x18\xc5WW\t\x99\xf4\xb2\x99!\xbb\xb0\xe5l\xf6$\xf6g\x95\x0b\xee\'\xb0\xc9 \xef\x97\xa7g\xb8t\xb0i+C\x0c\x89D\x9aI\x04\xe4\xf78*4\x94\x9c\xbcNH\xf9\xb2B\xc7\xe3\x8e3/\xf1\xbf<2\x1f\xf3\xdcX\xdd\x10\xb8f\xfc\xc8G\xb7\x92\xda\x05@J\xf4\x90\xf1u\x9438\x05\x8f>\xc74\xa5\xd3\xc5\xd3\xfc\xef\x07\xb9\x19\x92\xb1\xb2\xf6;\xf8&\xbaD\xabk\xaaL9\x10^\x1eiF\x19h\t\xcf\xb1\xb0\xf5RD\xee'
|
|
|
|
|
|
2024-12-14 17:54:48.309556 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25565
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808840389
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.316622 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 5880
|
|
id = 47935
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf577
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808840389
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xa3\xa37gI\xe6\xc6msM\x18\x8bz\x80\xd5R\x00v\x91s&f|\xb6\x89\xc1\xd7q\xe0\xb1\xcb\x04\x87\xb2-\xda\x8f\x05\xcd\t`3e\xbb\xcf\xa1\xd6\xcc\xbeP,Q\xcd\xc5\xcb\xf1\x1e\x15\x12\x9d\xb3{\x8c \x0e\x8e\x8b\xf1\xc1(\xff}^\xb0\x9f0U\xb0v\xdc\xde@\xf3\xe6\x8c\\\xa3\x88U\xe7I\x0e\xa7\x13Q\xa5\xa9\n\x14M\x1fj\xc5\xbb\xc4+\xfe?s~Lxp.\xab_\xb4\xd3\x81e\xd5\xf2\xb2\x0fb4%\xae:6j%\xba\xc2\xce\x91\x11\xbf<\xad\xafL\xeeN:{\x97g\x1d`/\x16?\xd6"\xc4\xcb$\xb7a\x88}x\xbc\xa7@\xbb\xd6L\xc6\xaf\x95\xda\xb2\xc8,\xb54\xa8\xc2;\xa4\xad\x88\x95\x90\xc4>\xc51S\x0e\xcf\xb7SK]\xe8\xcdh~3\xb4\x89\x83\xa2f)\x16\xb23\xc7\xa2Z\x91.`\r-\x91\x83\xbf\x10\x03l\xdc\x9bA\x17\x89\xc1*\x84L\xbdN+\xd1\x0fM\xdb\xb1\xb6\xeb\xf0\xf4\xf4\xcf\xdf\x1bv\x9c\x9c\xe4r\x15\xca\x98D*\x1b|\xc5\xac\xd1\x17\xeb\x08\xfa\xafm\x03\xf8\x08h\x94o\xfe;; \xc8\xcf \t\x84{u\xd3\x1e\xc301;aDp\x8e\x99\xb7\xda\\\xe5\x95\xc6\x0fq\x88{+o#\xf9\r\xec\xcb\xce\xdb-\x8f\xfd8?mG\xde\xdf\x0f\xa9P\xb4\xf61 \xfe\'Z4\x94\x17\xec\xd8\x04\xfe\'\x04,\x84\xc5\x03\x82\xdccGh\xb6\xc6\x8c\xcdm\x9b\xe3\xe1?\x0e\xf9\xbaT\xe8\xfe$\x95\xf9Q\x93\t\x0e\x90\x9c\xa8<`\xd4Q\x8at\xf8\xe4\xa1\xbc\x1a\xcf\x10\x8b\xdc\xc0\xd3\xbf\x07\x14\xe7:\x8dU\xe9!u\x81\xa0\xa5\'\xff\x15\x94\xfc\xb2C\xd5w\x9fe\xaf\x1b\x1c\x1fc\xb7\x88g\xf1O\x0b\xab\x03\xd9s\xa4\xa0\xec\'\x83G\xf7)/\xd0y1\xae;\xd3\x91\xdc\xcc\xad\xf2\xdc\xd3\xd1\xe2R\x14\xd2\xad5\xfd\x03\x91?\xc4dd\xab!\xa8\xa0\xba\x11\x1e\xb7\xb7o\x97IKq\xc8b\x1b0\xb1\x9e\x03\xec\x86\xb5\xc7)\xe1\x80\xd4\x15\xb5|]\xdcq\xf5I\xab,\x00\xce8\xe63bb^\xfeB\xc5\xd9&v\xdfB\xceS6\xe5\xecp;n\xab\xbf\x07\x81Y\x81\xf7Z\x8f\xa9\xfd\xb0\x13Zn\x18jO\x8f\xb1\xbb\xd9\t\x8f \xcdV.\xc9sr\xf9\x06\xde\xdb-Ga&\xe0T\xc9\xfev\xbcU6\x13\xd3/\x00\x98Q^\xc9\x8c\n\xee\x0e0\xfa\xf5\x8fZ\n\xef\xef\xb2\xaeC=\xfe\xd7\x05|\\)\xeaP\x07\xac}\xa0J\x19d\x87qH\t\x9e\xdfR\xd1\xfa\xc3\xbb\xbc/\x871\xc5\x1f\x1c\x89\x1e\x17\xd1\x8c)\xb0\x15<\xb4\x18\x7f1\xe2\xce;\xbe\x8ex\x9a\xa6\xa1\xe2\xb17\x8a\xfcU4\x8b\xbc\xf5\x03\x16\xd5\x9b\xcay2\x04+\xaa\xd8\xb1\xe4\x9e\tQ\x89\x86N\xef\xc0n\x92\x9b\x1f7l\xe8V\xdd\xdb\xc70k\x93\x0e\xae\xd8\xa9\xe9\xc2\xc1\x12M\xc3=\x1c\x8e\xa7\x0f\x01\xdc\xba&kv\xd8V\xa9\xc4\xb7\xa8_\xc0\x03\xdf\xd5F\xf5\x1cA\xb29\xeb~\xff\xc1\xd9\xc6\x83s\xa8\xaf-=g6\xfaG&\x99 8W^p\x96}\xce\xf3Q\x89\x9c\xcc\xa5\xe0\xd4\xbb\x07a\xa6\xf5\xa2\xd5r\x14\xc9\xfd\xc2%\x8b\x1e\xfe\xde\x97E\xcaPo\xee\xd0\x08\xd3]p\x12\x12\xaf\xf2u\xa6\xf6%\x10\xadwe\xe2\xd13`~1\xf3\xb5\x01\xc9$\x16/\xb0-\xd9\x13\xc9n\xad"}\x96\xd2\xc6\r\xbd\xb1\x04xH\t:\xc5\xe9\xe96`(]X\x9c\xbcVj3\x95b\x01\xa6\xd2\xb4mv_9\xa9^\x1d\x8d\xa0P\xed\xee]A\xc4l\x9b\xd8K\xc2\xa7[+\xad\x8b\xc9b\xd0q\xea\xb9\t|\xe8P\xdbp\x87\xb2\x84\x8f\xcb\x02\xc4\xd9\x0b\x19w\x03\xa1j\x0c\x9ar\xef\x9d\xbf\xd3\xd7\xd6\x1a\x17\x84\xb4\x1d\x14\x11Q\xb3\x88\x13\x0e\xf8<\xe3\xf5W\x159\x02!\xa5\x18\xc2.jn3\x9c\xcf\xd9\xfd\xb2\xceM\x0cDX\xa9\xe9F\xf8*\xa6\x8b\x19"0Dq$AS\t\\\x1f\xf2\x9b\x87\x084\xe3\x13\xa9\xb1%\xad)\xb4\x08y\xe1\x07\x16\xd8\x992\x01l\x1cy6\xa9\x04\xafa\xe4\xfe\xe45 \x07\xdfPt6\xad\xc7p\xce\x00\n\xdb<a\x81MaG\xfb\x18\x1b\x88Df\xdb\xfc\x17\x8d\x89?\xd7\'\xa2\xd0\xe5\xfe_\x82\x05Q\x89\x85\xa9\xe4O\xc9\x96\xd3s\xd3J9\xc6\x18P\xdb\x91\x13\x94\xf9\xd1r\xb6\x9d\xf8\xc3v\x04\xd1\\\xd25<\xf77\xa2\xe1\xcb7D\xe4C\xe6i\x93E\xae\xe71c\xd8p %)\xf0\xc4r\xba\xbb\x07`\xd4\xdcx\x1bHG|/0\xd7\xbd\xfc\xda X\xd0\t\xd9\xb2\x9d/v\x8b)N]\xa2DRi\x97!WSN&\x8d\x9a\xfe\xed\xc7\xb8\x07\xd6\xfb\x81d\xcbl7\xc1\x9f\x88n\xeff\xc6\xb4\xd1\xc9\xdbWyX\x8d\x87_|\xd6\xfbi \x18(\xff6"\x05e\xb1qo\x08\xeba\xb9\xc9\x86\x85p\xd4\x9e\xbfXKJ\xd3\xab\x0e\xc0*\xc4\xd4\x9d}\xba\x0e\x1eSh\xd2X\xc8g\x18w\x88.\x1c\x81\xfa\xd3\xadZ\xc6:F\x9b\xfe\xb8`,\x99Y\xdb\\\xa2\x12i\xce`\x13=nN\xc5E#|k_Sd\xae\x8b\x9bpA\x0b\xe9\xeff\x0c\xad\xa4\x9e\xdd\xdc\x8a\\\x85\xb2P\xf3\xab\xd3\xc0\xee\xde\xfarh\xbaH\\\xeb\xa5^\xee\xb8\xacy\xe7\x98\xe9Y\x00"+q\xb1|U/\xbd<~E\xab?\x97d\xaa\xfb\xdc\x04\x8e6Nd\xacO\xfe\xa6\x06\xfa\xeb\x120\xae(\xd9^\xe5d\xac\xdc.\xfb\x11\x8a\xa1y\x93z\xdd\x97\x04\x92\xeb.\xd3P\xe0\xa9\x96\xa0\xfft\xf1\xb0\x1dIW\x89C\x9de\xbcR\x08\xa5sj[\xa7\xc7\xa6(\xba\x07\xd4\xc0\xbd\x15*\x0cW\xbf%[\x1b\xaa\xfeP\x93\xbc\xa5s\x88\xabr-\xc8\xfa\xe1\x8a\x16\xa8o\x08\x96\xfc\x9e\xb98\xdf\x00\xe9~(\x88\xf9\xac\x89\x98;\x0f\x11e\x01 4\xe2\\X\x03\x1c\x88I\x91\\\x8cy\xaeJ9\x13\x10y\xd6\xda\x8d\x13\xd9H\xb9\x8c\x9fF\xbb\xe0\xf7S\xf7\xf3\xb4\xd9b\x0f\xb6{B\x05u\x98\x9d\x046\xb9\xe0;\x80A_\xb9\xd3ucJ\xeb\xc3\xe1\xc0\x8d\xc8K\x06\xdb\x89l\xbe5CS\x13\x18v\x8a<?\x8a\xb8\x1d#\xea\xc7\x00u,\xce\xd5\xd4>\xe5\xd1k\x99vJB2K\x9e\x84\xae\xd7_\xee\xd8<T\xe8C:\xaa\xa35\x13\xd9\xcd{\xdf\x8c\x88K\xe4&\x1a\x14n\x7fk\xe1\xd1|\xe0\x1e\xafyV\xa0\x82\xedo\x9e\xe3\xe6&k\xf0\xcb\xfb(GImt\xbb\xc9\xec\xa1J\x11\xf9&\x867\xee\xfc-,GiP\xd063\x14\xe8\xa1JY\xb0R\xec*/\x91)\x15\x00NBy\x0f\'\x1ea\xf6\xd7\xa7D\x92\xe2k31\x14\xe0\xc8c\x97\\\xa0\xd10\xd3P2\xd4\xd9~\xba\'6(Z\x82\xe8DU\xc6\x99Uk!\xcc\xa3z\xb3|\x8ai\xa6\xcb\x81\xee/O\xf1\x1b\x01R\x80\xb5\xaaw\xd8\x9a&jI".#\x1a\x83\xf0\xc0\x97N\t\xf4X\xc2\x17\x94\x0fC_\x0e\x01\xab\xbbl\xb4\xcf\x8e5?\x0f0J8\xef\x80#\xacR{\xdb\x90Y\xb4b\x8bS\xd9\t\x1f_\xb8&).\xae\xbf\x0fSZrW\xc9\xdc;ZB\xbd\x0e\xfe|,\\\xf1@\x1f\xdb\xa2\x86!\x97\x139A\xa8\x86\xe4U\x1bQ\xec/\x94\xcc\xe9\x9dRK\x11\xae\x92\xfb\x98HIWt\x0c\xd4\xed\x83\x0b\xc5\x9a?\xe2\x13\x8e9\xad\x0f\xe0\x80|\xa6\x08\xa2\xeeX\xf0<T\t\xbcxb9\xfb\x12\xf2\xb7\xf2\x94\xc9\x14\xebp\x83]\x7f/\x17\x8d}m\x07\xf8\xfa\xaa`\x1d\x06,\xdd\xccg\x8cC\xdb\xf4\x1f\x1f\xa5\x98\xabn\xf3tF\x0f\xcdHw\x13d\x8d\xf0\r\xfa\xa8\x07_z\x82i\xefB\xd7\x03\xd9\xa4\xda-\xb1\xd0k\xff\x1baS\x91V\xfd\xd5-\xed~\x07\x87\x7f\x16M\x08\xc5\xac\xfa\x00,\\\xd8\xf8\xab\xb7\xd8&\xb8u{\x06\r\xec\xdf\xba\xb6+}v\\2\xb34\xfce\xb6\xe0\xd5G\xdd\xe9(\xf7f\x90\xee\xc5A\xe4`d`\x93y\x0c^\x17\xba\xa7v\xd4\xbdJ\xe2l\xad1\xcat\xaa`\xfcP\xcdw\x07\xe4J\xe6l\xf6D\xa3\xc5\x05\x05\xd9t\x8d\x8b\t\xdd?J\x92\xa9pwT\xab\xfc\xdd\xc0P\x95Z,CZ\xee\x15,w@\xfb\x88e\xb2\r\xcb\xf1s\xee\xea\x94\xb3\xb2\xc1\xd7\x81\xc5\xb5E8U\xe9(\x80\xe3,\xba\x03\xa5)\xa0\xd6G\xc4\x065\x15#\x93\x8cT?=\x81\xae\xdcm!@\xf1\xef\x9d\x11\xcax&\xee0\x14\xd0\xe4\xd3\x1e\x99\xca\x14y\x81\xfb\x94\x9c\xf7W,\x97\x1d\xb63\xaa\xa1\xae\x1f\x8f\x9b\xc2\x95BR\xbc\x8d\x04Cu0\xc0\xb6\xd9\xc7\xc7t\x93\r\xab\xe0\xd1\x84\x9aGx!7\xc3\x964\xf9\xf8\xa2\xc1\x03\x04\x05\xf9W\x8d|\x9b\xd5:\xec\xc5\x15\xf1\x8f\xdaf\xd7\xae\x89Y\xb0\xdd\xe5 yW\xdd\x1c`\xcc5\xab\xd5\xcf5\x0bA\x06\x0b\xa1\xecg=@\x8e\xbc\x80\xfc\x89Z\x84\x96\x9e5\xe1\xc9\x88\x18\xd7\xf1\xf6dh2\x12S\xe1N\xfb\xf4A\xa6\x8d\r{\xd82\xa9\'!\x15\x0e\xcf^3\xca\xe3\x8b6\x82Z\x16DqQ\xa0h\xc7Rw\x14*\x1c\x08!T\x9fD\xee%\xf2\xf09\x9a\xc9\x15\xb6\xd3\x16.\xfc\x94\r\xc8"\xd5\x17\xf4d\xa9\x05O\x90\xae\r\x1d\xbc\xfex\x04^\xbc\xfb&\x03\x16\x957\x1e\x08\xea\x82\xf9\xed\x99\xc7\x14\x15\x19\xc5]E\xe2\x17\x16\xe4\xa9\x9f\x1dZBp/\xee\xa8g90\xc9\x1a6Jh\xf3?\x0bN]\x0b"\x87\xb0{\x1b_c:/\x7f\xc8B~\x00\t\xa7\xdddkrv\xe2\x1d\xeb\xe7\x92\x0e7\xd63\xdf%\xdd\x1f\xa2o\x13T(F\x93\x01\xd4>AY\xb6\xed\xd9\x17\xc1;\xc2\x94\xb6\xfck"`I)\x07\xd2=\\\xe9\xecM\xa2=\x15\x98\xdc\x05\xa3\x03F\xd6l\x05$\xc2\x05\xbfe\x0b\xd1\xb6\xc1\xc2+\xc5\xbdxr5~\xee\xaaw\xbc\x8f\xcd\x9d\xe78x]\xa3\xbb7\nN\xe7=:\x1f\xac\xdc\xee\xa9\xc2\xbfJeLrU\x0c\x06\x7f\xec\xf3\xca\x12w\x17k\xd2Q\x0f\x0e\x048\xbdM\xfd\xb23\xf1\xa0\x01\n/\xb4}\xea \x08\xb7\xb8\xea\xf7d\xc2\x11\x8f7`Y\x80\x06\x10\xefDJ\x90\xac\xac\x9d\xfc\xd5b\t\x8aqtb\xc6 \xa4>\'\xa3\x1af\t?\xba\x19\x8cJT\xa0\xe9\xa0\xb3\n\x9e:\xd2\xbewK\xa0\xb2\xe2\x9c\xcf\xde\x1b\xc3|@\xf8\xb8\xff\xeby+\x05J#\x1br}x\xd0X\xf9~\xa0\xec\x8ce"\xf6\xd5\xa1\x8eJ\xfe8\x95\xabPO\xda\x93h\x04t:i\xa9\xd9\xc3\xd8\x1f&\xfb\xf8X\xd4X||\xae:\x0e\xb1wl\xa5\x86\xf6\xb5\x98\x00\x17V\xf0\x9b>9\xd2k\xf3I`\x14\xe3\xa8\xac\xfb\x9a-\xe2a\x92\x00\xc7\xec\xf8\xa20\x19C\x11d7\xda\xb1No\x89\xcd\xfb\x14\x7f\x1d\xdcs\xbc\x8c\x82\xe7\x8f\xb8\x92<\xf9\x1fp\xa3\xa4\x00\xc1t\x03\xd7\xc0^\xaf%\xf9\xc85[\xe9g~\x9d\xb0[8\x84\xaa\xf1\x82\xac\xfa\\gw\xbe\x11\x88_\xbb\x90.>E\xeb\x04\x96X\x94Z\xad\xa6\xbb\xfe\x99\xe8\xa7\n\xb2\t\xcbo\x04H\x80\x93-\xe5\xfe\x12i\xd5G\x80V(N\n_\xc8\x87\xa2\xee\x9a\x12/P\xf6\x9a\x8f\xb5f\x92$\r\x18\x8f\xad\xebo\xd0\xa5\x88!\x185\xd3eA\xa1!<\x91\xbf\xfb\xcbBAv\xbd\xe5\x07m\xe9\x0c\xc6B\x89T<\xb2\xa4g:\xc6g\x90\xef\x0b\xb9\x0c\xcc\xd4\xbf\xad\xe5\xf3\x8d\xf1[\x04\x83\xbb\x07\xa4\nph\xc9\xfd3\x03\xe4W\xff/B\xd1\xfb\xe4\xc3\x19\xa0\x89\xb6\xd3\n\xc7\xee\x0c\rD\x0e\x95>\xd3c\xa1\x91\xf1\xd8\xb9\xf0\x86\xd2\xea\x0f*\xc7\xe9x\x87\xa1GZ\xa9\x94F\r(\x18\xcc`mRk[\xe9S\x9a\x06\xad#c^\x12\xd9\xeb\xc7ml$\xf7\x17\xbc\xcd\xb9\xad3\x9a\xe6\x01\x91\x12\x12X\x93\xac$\xff}%[\xac\xcf\xc1\x86\x8a!\xe34\xec\x82\xb8\xda\xe7U\xb5\x11\x9dDUB\x9a\x08g1I|\x01\xcc!G/\'6\x92\x12\xe0\x0b\x0c\xd12\xf9\x9ddbh\x14x\xee\x97\xe7\xd7I\xdaQ\x8e:\xaa6\xc1\x146\x04\x1c\xfbB\x8d\xc5\x9a\xf4\xc8\xc7H\xbd\xae3\xf1\xe4\xde\xd4\x06\xce\x06Sb\x80\xb4_JF\x03\xb2"\xa9\xc3W\x81Fkz}\xc7LU\xfau\xcf\xa3P\xb4\xe8,-\xab\xa7mtt\xe6\x1e\xb1k\xe4\x1aptO}\x1a$?\xf2)62dm\x88\xc7\xd5\xdc[^w\xb9\xde\xa2\xdf\xa2Qv\x1b\xe4\xc0PU\xfc\x1f\xccT<\xc1_\xaa\x05O\x8d\xfbZ?y\xecY9\xe4[\x19\x163h;quA\x0bv\xc9}\xee\x9aa\xb3\x88\x17Xy0\xd7E\xf8\xbc&\xcc\x89>\xc2\xb2\xe6^\xdbA\xccd\x86I\xde\xad\x1dN\xff\xcf3Y\nG\xcfT~\xdc\xaf-\xcd\x94\x15\x9a\xb3\x16\x8c\x96\x0c\xbe\xfe[\xe8\xc5\x18\xf7\xfb)\x7f\x98\xa8\xa9\xb8N\xc1s-\xce\x04\xcf\x1c\x14\x05\x00\r8\x95\xe6\x88j\x10\nL_w\x85"$!\x1a\xd9\x13\x8f\x83\xa0\x97\xcbS!\xf4i$\xaaMc\x03\x92\xe9cZ\xc9\xaf,\x94\xf7\xac\xfa\xdf\x88\xba\xf5N%3\x1f\x15z0^K-\x16\x0eI\xb4o\xc2\xb7\xd9\x9e\xc8\x15\xf12\x9b\xad\x0c\x0f=\x90\x91\x1db\xb0\xd9\xc5\tK%\x12\x1d9$x\x14\x13\xf1\xef#\xe1\x1d$\xf5\xc5\x17<\xe5\xf6\x1bU\xfeh\xe4\xd7N\x8f\xbf\xb18\xf9\xfbLQ\xed\x98\xa3\xad\x9b\x0f9\xc5\xba\xf7\xb9/A,\xc0\xa9\x8f\xab\x9e\x91\x97<\xb6\x898\xacB\x03\xb5\x0f\xddf\x01\xf0\x8b\xaahK\xbc=s\x01Q\xdaP\xbe\x05\x16`\x84l\xa9w\xd3\xc6\xd9.\xaaC,\xe8\x04\'\xd6\x8f\x0fh\xa6\xc8\xbf_\xc2\x01\x0c\xdd\xe2\x17ow3\x00\xa8\xd1\xda\xad\x83\x9b1\xd8\xca\x97\x88\xc2l\xf8YvxP\x80?\xa9\xdf\xdb\xa6\xe9\xa8D\x02&d\xfa\xe08r\xf3\xfep3-\xa5\x998n\xc5r\x90\xe0@\xa4\xb8\x91\xe9\x8eg\x10\x17\xa7\x19}\x96\x18\x9f\x94\xb3\x85\'\x1c\xd4\x02\xb6v\xd0Q(y@EG\xdc\xb9 n\xf5x\xae\xb7+\xa4\x08L\xc2\xdfq\'\x82\xb4dH\x84\xaf\xca\xe5\x9a\x9b\xbf\x1f\x1d\xf18\xeajo\xe9\xf6\xf9\xf5\x88\xc0Su\x08zr#\x9eXp\x92\x8e\xee9\x14\xd5C\xa9\xdc\x18\xdf\x15\x08Py\xc1\xe4-};\x9aB\xc8\xc8\xb4\xf9\x98L-w\\\xfe\x1aA\'h+f\xbdQl}1\x1e\x87\x0e\x1b\xf3gv3G\x04\xa7u<\x9d\x06u\x18\xdd\xf4\xf3$\x8f\xa2+Zl\xcf\xa1\xca\x92^\xdckb\xe9\xc8*\xfb\x96\x1c\xc6\x1d\x93x\\C\x0cD\xa1[\x0f?}(<\x1e\x8b\xc0\xe9Ej \x83\x8d\x1bf\x80\x10X~\xba$b\\R\x19_\xb5\xd5\x8a\xd0\x07\xcd\xb3\x15\xfc\xfe\x89$\x00\xbc\xa4\xd4\xb3\x95<0)\xbev+\x98\x10\xa0@\xafUD\xe9{\xf6\xe3\x18\xcf\x89\xdb\x81\xbc\xa4"~\xaa\x08^\xc21\xbf\x81\xd2\xf1_\xfaN\xe3%\xb6\xbe\x0b\xa1\x8a3"F\xf9\xd9\x15\x93\xd1m}\xef=\xceT\x15Gv]\xcc\xf6\x87\x7f\x87\xd2\xc3\xd6\x0f\x80\xeeK\x16\x98\x19S\xa6\xd3\x98C!\xb8k\x1dSY\x19p\x1c\xed\x96\x1fe\xa98\x9f \x9e\x1f\xaf\xe0c\xde\xd6\x06B\xf5\xdcu\xca\xfa\xf2\x96\x17\x1f>2\xe7\xa8(\xde4\t\x1a\'yP\xc2\xfa\t\x1b\xcb\xa3\xfc\x84q\xee\xd1\xfe\xd0\x10\xc8iwy3\xe6\xd6<5&B<\xe5a\xe5\n\xd1\x92*\xe4\x8e>\x83o\xf1\xe1\x00\x17gqV\x98\xd5!\xee\xec\x81\xbc\x98\xbd\xd6\xc4\xbf\xfe\x12g\xa1\xb6@\xcb\xaeQ\x05\xed(d\r\xcd\x86\xd5\xef\x814\xa7;\x8e\x00\xf5Z\x01\x88S \x15\xcf\xf5@o\x9f/\x1f|=\xef[\xefg\x96\x0c\x1c2\x86x\xc6\x8df\xd2w\xac,-\xe9\x93\x8e\xbb\x8a\x1d\x01H\xd7\xc8Y\'\xdc\x16\xe0\xce\xbf\xfd)E\xf0\xbc\xc7\xfd8%\x10\n\x11\xe1\xa2u\x1b\xc7\x07\xf2\x91X\x953Y\x84\x89\x0b\nM\xd8\x97\xeb\xb3\x0b\x99\xfe\tj\xe3\xf4\xd5\'\xd7\x9f\x9d\x7f55\xe8E/\x08G\xa8\x134Ue8N\x02\x80\x1b\xfe\x84\xc68*\xe3F\xd2r\xccE\xbf=s\x85\x959z\x07\xff\n\x97\xa8\xfa\x02)\xaa\xf4}\xb9q\xcb\x01\xccg;\xedrT$\x04/1l:.&\x06\xd8)q\x85\xdb\x92\xa0\xc0\xea\xe2\x17\xc7\xe5\x9c\x84\xd4\x90\xbe\xe5\x93\xefo?q\x84\xdat6\xe8\xb3\xcd\x13Q\xdcz_]\xa3\x99G\x8aK-Zn\t\x16\x11\x0fi\xf4\x9c\xed\xc4\xf7\x14~\xf3^\x82nw\xbe?\xeb\xdch%\xc8\xe91\xc6\xcd>\xc3\xe3\xf3R\xc3\x88\x9cD\xaf)X\xb9@j\xde\xe59U\x1f\x99X\x15\x1e\xa1\xd5X\r\xf2+\xe5\xb9\xa8\xd2\xc9V<\x93\x17\xab\x12\xa7p\x8cy\x903~\x0b\xcb\x88rIKP\'S\xc1\x8aJ\xe8x \x97\xeaJ\x82\xf6\xe1%\x00\x19C\x03OGz_\xcc\xc8\xfe\xee\x0etyt\xf1\xb6\x1a~\x10\x8eOR$\xd7q\xeec\xf23\xb3\xe5Gb\xca\x0c\x8av\xcd\xd0\xf8\xacIu\xa3\x1f\xc7\xb0\x93\xd8\xe7\xec\xdexj`\x7f\xec\x8f\x98\xc0\xaa\x0f\xcf\xa8J\xed\x83@Y=/tx\xecS\xbb\xe9\xcc\xaf\xf4|\x94\x00\x87\x1c\x7f\xa1\x1d\x85\xdf\xaa\xbc\xc5~b\x94\xd8\x8f&\x9c\xa5\xfb\x1e\x90\xb2\xf1\xf3}a\xea\x04\x9d{:\x1f\x8ae\xb3v\x19c!UrD\xc6\x07\x172u\x93C\xbea\xe9C\xaeRM\xde\x98T{.\xff\xa0\xfa\x1aD\xd3h\x12DA\x857\xfc\x0f\xb5\xc7\xf8\xbf\x9b\xd03w\x9b\xb4\x1dzO4\xf4\xd9!\x9c`~a\xf6\xd3\xad\xfbB\xb4\xc0o\x9a\x98\x92\xc5L8mNX\x8c\xf7D\xfcA\xd1\x19lp\xec\x9fI|q,U\x93>\xc7J\xbb\xcd\xa2\xe9\xe5~\xd5V\\\x02]\xc1\xad\xac\xf4B\x9d\xd1r\xa0rU\x01 &\xc0\x0e\xa6\xf0p@\x99\xf7\xbd\xce\x15\x83dkj?p\xd9\'3h\xca\\\xa8X0\xbe\xd3\xabc\x9cA\xe2\x961\x8d|\x97\x8e\x8e\rM\xccut\xab\x96vI\xf7\xdf\xeaXI\xf4\x16M\xfc\xd8\x06\xf0F<\x8f\xad\x8d\x9a\xe3\x80\x9e0\xb9wp\xc1t\xe1U \x0f\xfc\x1c\xd2\xe4db\xb0Q\xa9\xbbg\xf5-\xdcDl%\xd3B\x0f\x82[\x05\x82\xd2\r\x95\x08\xd7w\xee\xbb\xcd\xab\x96\xc1g\x0e\x98?\xafA\x13\x7fH"\xda;0\x82\xbdv\x7f&\x0b&w8\x88\xdb|\x19\xafVH\xe0\x86\xb5\x14X\x7f\xdb9/lcm\xbb\xc0\x80\xc46K\xf7\xb9\x9bL\xa6\xa7b\x18\xac\xad\x93\xf6\x1at2\x10\xb7\xfc\xafE\x9e\xb8\xcdWNpIz\x96K\x7f\xf9\xf6\x06\xd8\xcf\xe8A\xe0\xeb/q\xf9{\x0eh\x95\x15\x88\xd6\x9e\xabH1I\xeah\xa6H\xb6eUn\xbaK\xe4%a\xaf\xd7\xce{\x05\xad\x94[B\'\\\xa9}9\xd9H)\x85\xd1m] \xe5\x8a\xfa\x92b\xc8\\0+\x07\x19H\x005_\x87VM9\xa5\xa53\xaf\xee\xe9\xcd\xc2\xa0\x90\xe3\xa0\xd1\xc5\xa5F\xdf\xc71\xda\x98\x82\x12\x11\xe8o\x915\x9f\xcfu\xc3\xe6\xc7\xcb0\xf8\xb8&\x06\x01\xf6\xde\xcb\xa1\xf2q4el\xe0\xe2\x0c\x8dk\x8d^\xf0\xcaNk\x9bm\x1f!\xbe\'\xd6\x91\xb7\xe0\xcb\n\x00H\xb9(\x95&^\xf0\xa4\xf9Z\xbd\xc8\x13`y\xf5\xbf!x\xd8t9\xda~\xfc\xadW\xec\xbc\x91\\R\xa9j\xcc\xcf\xf5\x8fY\xde\x17\x94\r\xd0\x9c\xb1)U5\x07w\xf5\x98\x99\xc3*\x96m\x12g\x8d\x85\x86s\xf5\x19`Fk\x17\x9b\xd6\x85\xe9\x11\x80X\x06O\xda\x0b\x93\xb433\x05w\xe9\x92\xc1\x9c\xca\x14A\x8f\x19\x9a>\x8d\xf1{L\xba\x8f=qvD\'8\xb4#\xf0Ej\x0b\xb0\x83&BE\xc3\xa2\xca\xb3\xb7b-2T\x03en\x07Ek\x1c\xf39\x04\xf3}\x8a0\xff(\x82\x85\x9d\x9c\x03\xeb\xb7\xc4Y^|\x8bX\x0b$\xf0\x98p\x1f\'\x01\xc7\xc6\xa7\x01\xce\x98%\xea\x07\xefuf\'i-?\xc7q\x1bF\xfe#\xfa\x078\x9c1\xeeg\xb7$s\xa4.%\xf0\x8e\x1a\x86\x9dRX\x11\x8a\xacx\x0e\x97\xaaZ"\xa7<v\xc7\x98\x96,\x88[\xa8\xb1\xda\xdc:\xae\xf6\x07\x05f\x82:\xe4]\x9f\xd2\xba\x9b\xb5*\xa5T\x1a\xafi\xe7J}\x1f\xe3d\xed"I\xdf\x00\xbc\xa3\x0cd\x8eao\x86W\xea\x0cG>Q`\x1aj\xeb\xc3\xa8tr\x89\xd39\xe1K\x0f \x16\xa8\x00\xe5\xa4\xc3\xea\\#\xc6\xc7H\xe5x\xc8JR\xa0j\x05\xfc\xc6\x17\xc3\xc7\x88\xdc$\xaa\xfe\xbcT\xb1"\x03\xc6\x8d\xe4\xed\r\xe9{\x1d\xbd\xd6\xcc\xab\xbd\x9e\xfd\xc1\xe3`\x1e\xdb\x97\xa9\xb3t\x99\xee\x93\xe6\xc837$\xb4\xd73\xce\xf9\xd93-\xb0V\xdf\x82\xb4MrS\xd0\x03F\xa7"\x0c\xc4\x91\xf1>\x1d.\x87MXi\xa5#\xc1\xf5\x1c\xc4\x03\xae\xca5\x01\xde\xeb\xa3:\x8a\x9e\xba\xb9\xac@\xec\x14z\xa5ds\x15\xceN\x7f\xf2\x1etlm\x9b\xfc \'?\xc0q\xc8\x90I|\xac\x1f|\x8e\xd0\xb9\x01\x00\x84C\x98\xb42\xec\x85\xa6P\x16\x08\x8a\xf8\xab+\x1cG\x00\xe9\xd9D%\xcf\xbb,\x0c\x1d\xaa\x89\x05d\x98\xc9x\x83\x84\xab\x0cmZ^\xcd\x0ca\x8e\xa4\xf5\x01\xab\xa9\xa7\xf6Q\xc9j\xe3\x8b\xec\x08\xae\xfc,\x81C\x14\xd3L\xa7A\xa1@\xf9\xdao2Av\x0f\xe1\xeb\xe9=\xe3\x04ZD5ecp\xc1\xabm\x9e\x19\xaco\x93\x9b\xc9\xaan\x1b\xd5\x14]\xe2\xe6J;\x9a\xeew\xfc\x92\xeeN\xdbu!-\xc3z\xa0\xe0\xf1b\x9d\x10\x84\x8c\xbf\xc0\x0c\xc2J<I\xe2\x83\x18 \xf06\x8e\xa0\xf3\x86/\xd9Wx\x03)\xff3\xca\xcf\xef&\n\x02\xfc\x13\x9a\xa8nv\xdd\xba\x11\x10_\n\xdf\x1a\xcd$\x95e\x0b\xd6\xda>\xb1\xa1e\xbf9\xf9\xc9\x84\xf8)\x8b\x7fE4\xec~x\x98\xee\xc7{\xba\x18j\xbe\xe3Z\xfb[\x83zR\xae\x11\xe1\xe4i\xa1\x15\xfb\x88[2\xf6\xce$\xd3k\x93\xa5\x92\xe2\x1a\xe2\x9f\xe8\xcf/\xc9\xc8\xc2\xf1\xa5\xb73\xc8b\xff\x10u\xdb\x97\x83\xecu\xa0\xa3\rbZ\x15V.\x98Nw\x9e\xd7\xbc\xa63\x8a\x19\x95\xf95u&\xe5\x11f\xa8s/\xe5\xe2\xcd\xa1ij\xa7:\xec.\xae\rB\xe7\xe7X^\x8e\xcew|\xecr\xc8\x89\xe3\x8f\xce\x88,FU\xdf\x11\xd0-\x1d\x01\xc2\x0eK\x89\xd4\x9d\x1a\x05\x89Oe \xe30n\x8e\xfa0\x8bL_\x1dk\xf9\x91b\xa6\x04\xbd\x16\xa7\xf0w\xf7Ou)\xc2\x85\xba\x12P\xd5\xd7\xdf#\xc5B\xe8:\xfc\x93\xb6\x159\xfb-\x12c\x1f\xa0\x9a\xd6\x98\x83\xfcH\xc7\xc7\xee\x06\x0f\x97JY\xf4\x02\xd9\xc0\x8c\xd6\xbdLjseFKcy\xaf\xa1`H\xe1\x11?\xf2\x0c\xf5uc\xd3\xeb\xe8m\xc9\x982\x08|\xf3\xfb\x13\xbb\xb1\xfd\x11K\xe0p \x1aiX\xe5\xb5\xe8@t[\xb2\xf5\r\x98\xe9\xf4\x19\xd8\xe8\xc29*6J:`\\\x01[\xf9\xa5/\xb7S\xf79`\x06\xf7\xcco\xbc\xcf\xe4^\xe32q\xb8\x81o\xa2p\xa4\x88\'\x82\xde\x93\xbc\x03\xfeT\x14\x9f\xe00m\xacr\x9d\xc5\x01\xc3\xf6\xe7\x1dR\x15\xc9u\x9bT\xc5\xceq^\xa2\x00\xeb\xdcM?\x00N\xba\xde\xec\xc6\x07J\xf7m\xb8!\xc8\xb4aE\x9dl?(\xd4A\x01\x00Lr\xe4W]#M\xf5\xca\x95\xa3\x8e\xdb)\x94u\xb5\x91x\xa3\xf7B\xaa\xb3&\x07\x00\xf5\xbdc\xfa\x99\x9am\x06+\xc4k\x9a\x1e(<?W1\x90\xd1\xc5\xdb'
|
|
|
|
|
|
2024-12-14 17:54:48.327820 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 5880
|
|
id = 47939
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf573
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808846229
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'c&\x85\x1b\x8c\x05\x81yJ\xb7\xfb\xde]\x9d\x8b,40\xe2\x1c\xca_\x9c\x9d\xca\x8e\xc8\xb3b_G,\xcb\xfe\xc9\x82\xcfH\x8b\xfc\x86(K\xdbB\x19\x80\x7fI#\x1eQ;!\xdbF\xe67\xa8r\xb7\xab)\x8e\x99\xa3\x0cvB3\xbe\xd7\x03\x8d\xcd\x1fg\x8a\xecW\xe2l\x1f\xf8`ma\xa14\xc1\x92\x8fU-\xb5[\xab\xc1m+\xf6\xd6\xc4j]\xf1\xc5t\xaa\xea\x8fb$\x93\x8aU\x1a\xec\xdc\x1fa\xc4\xdb\x03J$_\xd7\x12<$\xb5\xa5\xd72\xc7\x99\x02S\x0f\xfe\xb5\xac9\x90\x1f\x80\xec\xfbC/\xeaS\x8f\xf0|\x87\xa2\xa6\x86\n\xfd1\xd7\x9b\xc0\x83k\xba\x10\x05\xf3\xcb\x02a\xeb\xb9\xaa\x06\xef\x94\x95\xda\xe26\xcb\xc0o\x0c\'E\x11\xf4\xe8\xf5V\xaar\x82\xb3f\xc5Q\x89|jlg\x99\x12\x02\xb1?\xf2Eo2\x7ft\x80x\x91\x11s\xf7\x96\x83l\x1f\xf45B\x8f\xae\xcf\x8c\x8c\xfb\xf0(\xc8\xb9\x8b\xaf_\x84M\x0cK\xe4:=\xbf\xafk\x01\xe2t\x06|k&\x04UBt\xc3G5\xb0m.\x88\xfc\xbfj\x81b\x16\xac\xb4\xc1\x9e\xc0\x17\xa2\xed\xc6\xaf!\x1b`8\xbad:\xacm\x8dV\xc6\xf8\xea\x7f\xdb1X\xfcVE\xc6!\xb5p\xec\x82\xc7\xf1\xa8\x804\xc3}C\xd0\x04\x94M\xeb\xd9\xf9p9\xd6\x81\xeeGFdL\xe09\xe7y\xcc^\t\xd3\xe5Q\xb9e3\x8c\xf3\xcb\x8b)\xb5\xc6\xfe6\xe9\x19\xdc\xd9<\xcdPZ\x98oES\x93\x99\x80\xdf/\xcb\x1fl`&\x1c`\xa4\x96-\xac[\xad\xd1\xc1*CIu\x84\x10Fs`\xb7\x8e\xe7\x9aR*e\xfe\xae\x03\xe8\x80a\xd4?\xa5f\xd0\xe0.\xb7\x93\x9b\'\xc1\xce\xa9P\x84\xb0M\'\x86\xd1\x92\xdc\x9d\xc1\x00\xe0p\x94\x80\xd2\x88\xf1\x00\xaa\xc6\x90\xf4\xa5\xee\xe4\x10\x1aB\xca\xd2\xde\xab\xdb\xe5\x06"\xdf\x02\xb5\n\x14\xab\xab\x91\xf2\xe2\xa9\xdb\xf8}\xd7\xea\x089\xf7\x81\x7f\xd6f\xc4\x84\xe2\xca\xc1\xbf\xf0\x06d\x16\xd9n\xbe\xdd\x96\x9f\xfd;\x1a\xfaW<>\xa0\x02\x85P\x9ew3\xe6\xc9<\x1d\x13\xf2\n\xaa6\xe9\xfd\xf4\x83:Y\xd2\xcdU\xca\x99\x16\xcd\xe2\xa2\xd0\x02Fhq\xf8\xb4\xd8z\x8d\xcf\xa4{\xc6\x89M\xf4\xd4\n*\xaf\xa6\xbb\n\xb6RK\x95\xcaZ\x8e4\xb78a\x96\xd2\xee\xec\xb95\x85\x07\x7f7\xbb\xd8(\xaf\xdf\xe4\x08=\xacq\x18\x90\x13D\xb3>\xbb\x06\xdd\x95-\xc6\x95\x8d\xbe\xd9~\x1f\x9e\xe4<&F\xc4=^ s\xeb\xbacp\xd9\xcf\xe2\xfe\xc9!\xc3\xd2z\x08*\xee\x89\xe7\x8ft\xaf\xadW\t\x9f\xdc\xe3\x13\x04\xc3%\xbd\xf5}\xb8\r.\xe2\xae\xa9\x152\xe0b6%\xb3d\xbf\x8d\xc45\x16\t!\xc4?\x0c\x83\xfd\t\xa4\x1c\xcfTO5\xfe\n\xae\x94\x17,\xb5v\xabW\xfe\xe8\x80\t\xfa\xfc\xc1\x8fu\xe6\x895N\xa9K:\xd5\xb7U\x89\x83\x87H\xc2\xc5\xfe\xc5\xc6\xebh"\xc8$\xca\x13\xa7\x0e\x0b$\x01\xe9\xaf\x92Em\xf8\x96\xab\xf1[\x04\xf6\xae\x92s\xc2p,\x85\x9bPg\x88@\xea\xeaX\xc5)\xd6\x10s\xcc\x89\xfd4\x03=R\xd9\xff1\x08\xf3CRP\x01\xb2\xa5kH8\x1a\xe9\xf40B3\xf5<\xeb\xf7\xe3e\x0c\x0c\x84B\xc6\x9e\x07\xb5\x92\x81\x16}+\xffp\x16\x19\x00\xecJ[\xa7gW:\'\xc3\xf9\x91\x03R\x17|"\xf1\xd8\xb8s\t\xcf\x81\xb8OB\xd8\xe7c\xf9\x03\xac{\x1av(1\x961\xc4\x92P\x8d\xd37\xdcwB\xc1\xd0\x14)\x9du\xb5\xd5\xb7\xb3\x8ee\xcf9T\xc4\xe6\xd9@\xcb\xefk!\xc7\xd6}1\xe9\xbb\x87_\xea\xban\xcb\xb2C\x82B rA\xa2\xa6\xaaHob\xbd\xb9N\xe0\xd5\x1c\xfd\x9c\xd8\xe7g\x88\xf5\xf0v#\xe8v\xf8\xe4\xd4=s\x93\xeb7\x14\xbf\xd3\xde\x9f\xb1\x90\x18\xb2_#\x93e\x17\x03~f6\x08\xa3\xcbT\xa1\x04e\xfe\x89\xb1\xbcj\xf1\x88\x9f\x13\xc9\xd7\x04&\xac#!#\xd3\xa4\xbe|\x17\xb0\x96\xf9eM\xc06Lq\xe0\xec"\xc7M(L\xce\xb9\xf9y\xb5\x90\xcb@\x94U\xcc1H%\xe7\x96\xf5*\xea\xee_\x99\xa2\xa5\xa6\xe9Z\x8b\xe1\xe5\x18\xf6w\x8b3\xd5\x02\x8e\xc8\xdf\xbb\xc5:\x04ZWpd#n\xae\x97cL\xaa\x08\xe9\r\xb1\xae"\xd0\xc3\x19n\x13\x8b\xfcB\x9beB/\xd3\xdeb\xe7\xfemi\xb9\x98\xdd\xb6(\xd2kO\x9b(]o\xc91o\xb5CR\xd6/\x14h\xddu\xc2\\\xfa\xfb\xb5O\xed\xf2amB\xf3\xd1(\x02(\x99%`\xe6\x04^(\x8c\x10\x0fp\xa5>ON\xf8p\x92\xf5\xbfv\xbb\x15\x1bj\x06`\x14\x9b(\x08|\x97!\xaezg;\x8d\xa5\x17\xbe+\r\xf7\x16\x0b\xbe\x15\xbe\xb1\x13G8\xad\xd5\x19\x0c\x160c\x9c\x1dNh\x81\xd7\xf9\xb0\x81\xeb\x83{\xad\x8e\xfc%<\xa9\xd8a\x99\xc4\xb5\xcd\xcf\xd7\xf7{\xe7\x05P\x0b\x83\xf1\xf4\xe9\xba@\xd8\x02T<\x01\x95\xe1\xb3\xe8\xe6\xc7\x12{h\x82C\xb3\xad\x88\x96\xe4\x91S\x1c\x1drE\xb4\x18=0\x0c=\xc5V\x06N\xbc{\xca\x12x\xe5-\x87\xaf\x9f\xbfb2`\xa7\x1c{\xab\x1d\xf7\xdb\x81\xe3*\xc5\xf0\xfc!\xf0\xa0\x83z\x14\xe8\xdd,\x0c\x14\x00\xd8\xe8Y\xd5F\x03w\x8a\xcf\xa6\'>\xc8\xf7\xf2Kl\n\x01\xbb\xb6\xd06\xa7\xe9p\xff$Vp@\xa4\xa7\xec\x92\xf5\xcbE\xc1\x13\xf3\x16\x92`>\xdb\xb9\x858\xba\x00\xebW\xbcB^>!6\xb0)\xdaid\t\xe0C\x81[$/6\x86i4\x99\xfe|\xc5<d\x82\xac\xf8\xf38\r\xf4Y\x1cNC\x85\xda\xfbU>.\xf2\xeb\xc5\xb1\x16`\x1f\x8c\x0e|^\xdd\xb3\x12j\xd3\x86\x89&\xab\xdb\xff\x7f\xed\x13\xd2\x06\xbeO\xbb\x91\x81^\x8c3*UO\x8b\x17\x95\xab\x9c\xfc3V\xce\x08\xe0l\xa2\x89\xfb\xcei\xe4!\x10,i\x05u\xac\xe7U\xe25<\xe1\xe0?\xc2Db?.?\xb1Ga\xe0\x84\xdc\xcf\xd3\n\x8a\xb8\xa5yR:\x1a\x1bZ\x89\x88\xac\xbb\x86>\xc1xkFOu\x0f`\xe4\xc9\xb1L\xdc\xabK\x15L~v4T|\xd0\xb9\xf9\xd9E\xcf\x95\xebx\xcd\xbch\x8d\xe0}T\xe0.i\'%\xc79\x9b4\xea\x8f\x95\xe1O\xc9\xb3:\xd7\x87\xfal\xc0\xd3\x86\x81\xb9\xa6\x91P\xbep\x14\x15Q\xb7\xa0\x0b\x1b\x99D\xe6\x00\x87\xcb\xb9\xc1eu\xd7\xc9\x9d\xcce\xbb\x01e\x9b\x08s?=5\xb1d-\xf9\xc4\xe0vR\xb2\xafg\xef>\xf3\xbd \x8a\xcc\xa0T\xc0\xc0\xaf\xc9w\xba|\xb0\x06c\xe0\x89\x17\x9b\x05]#\xcaXi#\xf5[^\xbb\x9f\xd9\x07{\xe0\x96\t#lK\xce\x9a\xc8b\xd6\xc6\xa7 I,\x96\x84l\x1b\xf2\x9e\xe7\xea:\xd5t\t\x9b\x9a\x1cK4\xe2\xd7wJ\x9d\x05\x05r\xeb\x0b\xde\xfe\xae\xd1\x99\xca\xf6\xe1\xa5"}b\xf2\xda\x10\x97\x03\x8b\x95AKu^\xd4\x01\xbf\xe0\xe7\xee\xf2K\x8c<|\n\xc0}\xa23\x81\x80\x93QY\x13?\xbe\xfa\xfbE\xc6\xe2\xfe\xac*Yp\x7f\x84\xf7\x84R/\xc9c\xdc\x7f\xbb\x84(\xbd\xff\xdcl+l\xb0\xeb\x19\xff4\x8b\xa2ni\xb0\x9c\x12\x8c\xf6\xb6\xff\x16\x1b<\xd5\x7f\xd2\x8f\xb4\x1a\xf1\x8e\xf5\xd3/\x07\xe8N\xc6(v\x81 \n-\xb96\xda~\xd6\xabhp\xe7\x83\x05\x13\x89\xa5~\xda\x9bw\x14 \x7f%\x97/Q\xd5\x11\'!:\xecY\x8b\xc5\xb0+q\x96\x10\xf4\xa6\xb3\xc8L\x16\x1f\x86\xea\x0e,\xa3\xe3\x07\x05\xc3?43\xf3?o\xe4\xcd\x9bbvz\xa4\xd6\xb0\xb3\x9e\xd8\x13\xb2\x05\xafH\xa4mS^\xed\xa1\x81\xe4\xf6\x89\x98aa\xe8\xa3\xed5\xa10\xc7W\x0f$\xccJ\xc6\x1e\x89!k\xcb\x1c!,\x14\xe9\xff\xb4\x1b\xd3\x0e$\x11\xc5R\r\xbc\xd9\xb3l\xdc\x95jG\xa8\xb9\x90\x15\xce\xee\xe7\x12f\xec\x1du\x92\x94\xa6\x91\x13\xf6f>\xc7\xd3\x82\x04S\xcf\x7f\x19WsO\x91\xad\xb5o\xc3\xe4\xb09\x14\xf5\xec\xf0\x18\xdf?D\xb0\x07\xb6\x99:\xdb\x0f\x9b\xa7e2c>\xdd\x14a;\x1b\x0e\xad\x9e7\xca$\x7f?1\x85\xb59\x88P!\xecT\xb1d\xea\xd1\xeb\xff\xb7x\xa6\xe4\x13s9\x1d*\xaf\x96\xf2e\x1b\xbe\xf9\x12\x0cCK\xe3h\xf2\xde3\xb0T2,\x1alD)\xe5\x810\x9eEE\xe9F0C\x8d\x1e\x18\x99\x95\xb0\x8b3\xa0["f\xe7\xd5\xe5\x9e\xe9\x99\x18\x0cY\x00\xa8o\x9d\xde\xa6#\xc4c%m:\xb7d\xf3\xd4\xb5\x0c\x91\x99O\x99\xb17\x9ei3\xab.\xc9\xe4\x92\x05.\xdeYc>\xd3\xfeG\xc1wi\xffC\xe9\xfe\xdbq\x9b\xcf\xc6\t\x90\xef\xd9V/\xb0\xc6%\xe9\xfd\xf4l\x0e\x9a\x10\\\r\xef\xf5\xc8\x06\xac\x18ff8*\xc3\xcfK\x9d\xfe!\xb2^7\x82\x80\xf3+\xb0&U\xe6\xfcJ\x1c\x932\x8a\xaa\xe8{\xb3\xa1A\xe8\x90\xc5\x109\x7f&F\xc0L\xa7j\xbb?\x92\xc0\xb8\xd7~\xa0\xd3\xcb\x89\xddt\x1a\xa1\xecI\xc2\t\xfc\xdf\xa4\x8eh\xda\xff\xa6\xd4\xe49LH\x7f\xc3A\xd3\xa8\x82xR\x0c\xeb\xdf"\x05_\x93\x1d\xe7\xb6\x8a\x01U*\xc6\x9c\xd1\xd9an\t\x1f$\x92\xf1\xbc\x93\x05\xa9\xe9\x9a2\xd1\x07dg\x08\xf9JX\\`w\x87Ai\xfc\xa6bY71\xb0\x97\xe0\xed^\xe9\xc3\xaee%\xdct\xb9\x8f\x97\xd4N\xfe\xd2\x866L\xd3Q\x82\x1de\xcc\rH\xc0\x86\x9d\x1c}\x8a\xaet\xceC\x88_\xab9\xb45\x99\xa5Ow\x84\x8crq\x89y6\x9b\r\x8c\xb1\x97\x13"\xa4^7\xb9\x8c\xa9|\x91\xe7\x9f.\xc7\xd0UH\xdf\x9f\xb6\xd9/9\xcb\xa5\x06\x981\x12jfJER\xcd\xf0\x84\x83u\x91\x9b\x8a\xe6\xa0\xa3\x9d\xb8YHty\xb2\xa7\x80\xe2Ab\x9fN\x8aQ\x8e\xff\xa9\xea\x05\xb2f\x855\xe9\xba\xfa\x97lh\xdd(\xb7\xed\xd8\x9b\xe6;\x19\x17x\x8a2\x95!0$n\xc8E\xb9z0\x1e\x8d\xcf\x15\x1a\xe9\xbf\xb8\x8c\x179\xe2\xdf\x88l\x89\x98\xba\xbbtg\xa8R]#Y\r\x8d\xdb\xef+\x86\x82\x9e\x13\xd5\x1e\x0eA\xd9\xca\x1d)\xd0\xcf\xda\xec\xfa\x919\xb0\xbc\xd8p\xa9\xc56\xdb\x0cSf\x9e\xdc[\x16\xfc:\xa8\xb3M\xbf\xb6\xc1\xf3\xe1b\x9cB\x80?S\xa6\xddw\x8f\xe2\xcf"\x88\x9f\xc5\xd5\xe42_[J)\xda\x19\x80\xfexHI/g\xae\xbb\x08\xaeT\x03\xe1\xb9O\xcb\x16I) \x87)\x1a\x03\xbdc\x9a\x9e\xce\x1cM\x8e\xd6\xf8\\\x19,\xf2E\xaf\x8f\xdd\x8d\xee\xe7L\xc4\xd8;%0\xd0\xd0F\x077\xdb\x1e+\x8a`w\xe7y\x9014\xc4~\xce\xb4]B]\x82\xc9\xc4\x8a6e\x06,\x18\x0e\xfd7\x08\x9e]h\x01\x93\\\xbc\xed\x04\xe8\xe14\xcd\x14\xff\xc7Il\xe5Do%UH\x07B\xaf\xfcs\xa9\x8cL&!\xc1\xb9#\x9d\xfa\x06\xadpO*\x1b/\x92m\x05\xec\xf3\xe8r:w\xc0\xc3\xfbG\xa09\xf0G\x86Ng\xb7\xc5{\to\x8c*\xbb7 \xad\xaa:\xbbi\x92U5\x16#\xac\xbdm\xa6V\x08H\xffu\xc9\xae\x14N\xe3\xe8mS%\xb8\x98L\x83\xc5\x9e\x92\xc8P+&\xb9n[\xd3\x12\xd9\x80<c%\x08"\xd6\xdb\x85\xe0\x8b\x8c\xac\'P\xad\x1d\x86\xb5W\x14\x91M\x90(\xab\x99\xdc\xd11\x99\xf2D\xe7\x90\xed\x82\x0e\x88\xf5F\xb2\x80E\xe8\xd5\xe5\xc7\xb7\xb5Y\xa9zP\x04i8\xba\r3\x9d\x15\xc7G\xc0\xd7\x81\xd7\x9cS\x044\xf9\xf7I\x10\xb7\x97L\x82h\x0b\x88c\xf6\xfe\x14\x19\xdf\xf0D\xec\xcd,\xf4\xecU\xda\xf2\x8ej;\x8b\xad\xaa-c\x87\xbd\x1d\x12\xe2\xe1\x03\x17\x0c3\xc9\x9f\xa2\xfb\xd1X\x1e\xb7D\x8f\x15^\xfeWK\x04\xfeG@\xe5\x0f=z\xfb\x83\x94\xa1\n}\x17\x1c\x12Y\xb1Z\xea\xad3\x91\x95\xbc\x83\xb5\x1a\xa5\xee^1\xe4\xad\xa7d\xabJ5g\xce8\x92\x93\x9b\xe9\x93\xfdKf\xee\xd4\xb9M\xaa+\x83T\xa5\xc5\xbc\xadM\xf9\x00\t^\xb0\x94\x1f\xeb==\xa6\xc2\xda5e\xb6_\xad&1\xeb0\xb7IK\xf2 \x19;\xae\x9f\x06&\xac\x84\xc2\xbd\x17\xe6\x96\x80\x0f;x\xa3`!\n\xe7\xa6\x93\xf1\x9eJ\x83\xd0#\xa6\x90\xa4\xb2\x19\xc3\x94\xc7\xec\xcb\xc8\x0c\x02:\xda\xf9\xe5\xd3\xb6\x81\xeat\xc6\xe6\xf06\xc0<\x87@\x03\xd8\xf1[\xe1\xff\x9dHRU\xf3\xf4\xed\xf0*u\xdal\xf9\xb9\xa2[\x88*\xa2\x16\x925\xbc\xa3u?\x15\xcc&r\x05\x90\x0fN\xa3\x7f\x14\xd6!(\x87m\xea\xfd\xa8\xa2\xad/b\x817d\xdf\x1a\xce$\xa1)5\xfd\xb8k\x0c\xb0\xd9\xb7\x03\xf9\xee&\xee\x08\x9d\x08\x9c\xf6\xad,\x14\x88\xa5\xf3\xc3\x16\xd0\xa2x\xf2#\xaf\x18-#\xcdT\xf2\xea\xd6\xd7\xfc\xb6\x9a\xa8M@!I\x1f\xcdP\xb0u\xde\x1f.p\xe2\xb3\x1f_\x0eH\xa5^\xddB6\xae\xc9\xf0Q\xd5\xab\xbc\xe6N\x1a\x98\xf45{\xb3\xf9\xf4m^\x98\xd9\x04\x92\xd8\xeb\xa9\xc1N\xca\xaas\xe4`\xc6\xddcq3\xfb\xec?\xf7\xea\x11s~X\xf2o?\xe7\xd6\x02\x1e\xd1\x17&R!!\\\xd9/\x08\xeb\x13\x87\xfax%\xf6\xee\xc7?\xb4-\x1c;\xf5\x08\x1dLV|3\\\x98>\xedS\x15?<!K\xe52\xbf\xf3\x9f1\x14\x89~y\x06\xd0\xc0\xce8\xd4$\x14q\x99\xd2\x89\xc7l\x89\x91wr\x12\xcc\x99\xf8\xfc\x7fL\x1c\xb9\xd5P\x92o\xae\xda%s+%F|\xb2C \x18\x88\xe4\xb1\x84\x8e\x1ct\xab\x9e1\xdd\x1e\x94}rp\xbce\x1d\xce\x1d\xf3;\xaeI\xd4\xa08\x83\xc7\xec\xb9\xa0\xc5\x14\xb7\xca\x03\xca\x16\xb6<ZJOu3q\xce\xcc\xabt`~&\xd6\xc4\xce\xc8\xb34Q\xc9\x9b\x86 \xda\xb1\xa7*=\xef\xe0\x88\xfc\x11?<\x9b\x06\xa8\xe2\xa8{\xf5\xbf\xe1\x07\x13b\xad\x04\x93b\x010\xec\xb7\xb0\xbc\x07\xb1\x0f\xdb}CF$W/\x88\x86[x\x83\x01?\xec8=\xd8\x1f<l\x08@\xb03a\xd6\x08n\xa2\xb8|\xe5\xc6\xfe\x08\xc2a\xb4\xf5\x18\'\xe2\xae\xbc\x10\xa6V\x0e!\xa1\xdch9\x84\x807\x87\xd7K\xf5\x97\xef\x1a\xfc\xb6\x0b\xe0\xa7\xd3\x00\xd0}\x1e)\xb2L"\xea\xf8$\xf7\xf5\xda\xe4\xc4\x8b\x0f\xeb\x8e\xcf`&\xbe\xa57\x87\x03\xeeT\x9c\xfb\xdb\x9c\x89@\xae:,\xf0K\xf3\xf4\xb0\xa9\xc2\x13\xc2(T\xef\x1f\xb14k\xa3W?!\xe9j\xd7b\x82\xd0\xd2\xa49\x9b\xc6\xcdb\xa6P_\xec\xdb\xfc\t:]/\xe5\xcat^\x0c\x99O%\x98Y\xc6\x80\xf7\x89\xfa\xffg\xdcr\x86\xd8\xbd\x00\x12O&\xf4\xfcs0}\xee\x18\xc8\x94n\xd3\x05y\xb7\xa4\xe3\x9b\xf4\xc0lr"\xad`_xLF~mK\xbf\xf5\xf2\xba>\xf3m\xdb\xcb\xe0\xfam\xcb\x84\x83\xa5\xf5t\xf8c\xac\xb6\x83\x98\x96c\xa5U~\x1e\x16o\x8d.\xf1\xf9\x08V\xe7t\xe0\xb0\xebt\'\xb7\xaa\xe3\xa3\x08|\x06\x95\x1a\xefof\xfd]C\xe8c\xcb\x97&?\x1a\x1e\xe1\x98>\xf5)\x86\xc3 \xe9p\x89h[\xbf\x0b\x84\xca!\xa4\xd1\xf6pj\x16\xe3\x1eq\x9e[\xeeIV)\x06y}\xb3\xa7*\xf7\x1b\x99\xb5\xbaEv)\xc32.eOq\xab\x02\x00\xf8\x8e\xe0\xde\xd1Ijh\xb4\x95DYN\xe8<\xbfgJ\x8171!\xcak\x86G\x0f1\xc4<\x1b\x1c\x99V\xb5\xae\x982\x83W\xb9\xa0\xfeO\x9b\x1f\xd5}\xdd\xc4x\xe2t\xc1\xed~7q\xdb\xa4\x06\x94\xca.\xe8\x86\xfd\nv\xe3.\xbb,\x13\xcb;i$\xfe\x03PUQ\xd1f\xe1\x9aN\xd5N\xb4\xe40\xe02/(\xd8]-\xff/bm\x14\x15*\xc5\x05\xbf\x90\xe07\x0c\xa5\xf6q\tI\xe5\n\xb7\xbc\xb4\xd8~\xff\xfb\xf5\xa8Z&\xae\xc1\xe6\x88$h\x8f\xf1A\xed\xba\xa1@\xaaR \x9c\x92\xb8\xec\x8b\xb4v\xd3\xdd\xc5\xcfc\x8a\xfeHrmt\x89\x8e\x17\x17\xa9F6\xc4\x94\xb8\xe5\xe5A\xcd\x1c\x8e\x19\xce\xc0\xeb\xd4\xa7\x9b4\xfb\x14(\x01\x0f\x8d\xc9\x19\xeb\xf4w\xf2j`\x05\xcb\'\xb7\x8fgk\xbfL\xb5I\xec\xc9\xae\x8f\xd0\x14\x9e\xb6\x02f,\xd3\x80IP\x84n\xb3\x1b\xf3\x11\xa6\xf5:\x16\xbcy\x8a\x9d\x01w\xbd\xa6\xa1\xbd:\x05\xa7\xe4?\xbc\x93\xda\x85\xb2\x97l\xb4:\x92\xb6#\x0ev\xf7\x01k\xbd*\xf1\xcd\xc0\xd6e+\xe8\x8aZ\xec#\xbb~\xc9\xa3\xf5\x11\xc5)\xbfB\xc8\x1f\xbd\xfeG\xb0e\xb6\xeb\t\xe0!\x91\xd8\xab#\xfem\xc0\xd5\x01P{J\x9e\xa5\x13\xb9\xa6\x90\x1a-\xc5\xd5\xe6\xb3\xd0\x0c`\x83]\x91\xbe\x15\xc3\xc7\x9e\xec\xf7\x82{t\xd0\x8a\xb7\xef\x05\x8cJ\x82\xac0\xd0\x98=\xc9\x1ao\x0e\xe8:w\x19\x83E\xca\x15\xea\x03\xe8\xb9E\xb8\xa09\xdd\xabW\x10\x90\x1a/\xd0\xbd\xdcuB\xb8^7N\xe1/\t\x1c7\x07\x13\x12\xd8\x96T0\xd3\x0f\xf7j7\xa5\x99\x0cv\x8c\x11VE\x8d\x82W1\x94\x82\x83\xd7\xf4`TT\xf6\x94j\xf4\xe72\xa4W\'\x91@6\xf2\x82\x16\xd9\xa4 [\x0c\x06\xbe[\xa88\xa9\xdcz&\xc8J\t\xa3\n\xdd\xe6\x01\x87\x11\x95~\xb3Ug?\x1d\x10\x8f\xea\xf6\x00U$\xdaY\xdc\x9a\xf5>jf\xfd\x12p3.\x1a\x9c\xe6\xe6\xe9\x90\xfe\xd8\xe7\x00\xfe\xd5\'.\xee\xe5\xff\xf7\xac\x96\xea\xd0\xdf\x0b\x02\xd9\x8cX\xd4\xc1&\xa5\\\x8d\xef\xf6\x99\x84b\xa5\xb1\x9a\xd2\xad\x99l$\xd6\xccb\xf7\xc9i\x05\xa4]\x89\x90\x98\xaa\x15\xaa\xc6]\x7f\xc4\xc5\xd9\xedn\x9dFcV\xac\xcdQ\x91aX\xa0\xd9\xf3s\xf2\x93\x95\xdc=\xd8"@\xe4\xbd\x11\x96\x90+\xe9\'\xf9Z8L\xc7M\xb0\xe5\x99\xd0\xf0L\x97\xf1\xc1\x04\xdcP\xd9?\xb1\x81I\xfc\x1f07\x0b\xd8\xeaf\xa8\x1e\x11\xc8zl\x82\xdb\x14\x07\xcb%\x1bba\x1f\xacT\x9fHz%\xe7\xeb\xbd\x8b\xda\xb7\xb7D\x97\x91\x96\xd4\xe4\xb3\x9b\x05;/t\xfa[n)\xfb\x13\x81{\x83\x90l\xbc\x8c\x82\xe6"\x14\x0cC\xc3\x82h\x0c\x9a\x9e\x93\x0ff\xa0G\x1d\xf6\x1f)\xa1lZ\xa3\xcfS\xea$\xbbXwO,\x95\x97\xa5"&q\xa2\x883\xfb\x9a0\xda\xf7\xfc\x8b\xf2\xa7(\xd3\x02\x17:\x8a.\x8f0{e\xfc\xa0G\xd4\xcd\xf2\xa7\xdd\xb2\x1b{\xc2\x12\xabP5\xc0\x9a\x8aA\xb8\r;\x92\xcb\x19\x80M2z\x9f6\n;_\x96\xe2ERR1\x96\x19>\xf5s\xb1\x14\x1aU\x0b\x8e\xd4I\xfb\x19\xb0\x0bm/\x9c6*\xaa\xa2\x14&\xc2[\xfb\x08\xe3\xf07\xab\x86\xd3\x1fB\x95\xf5\x18\x84\xe6\xc5\xf6\x04\xfa\xd4\x9b\xeaTL^,\xed76\xc1Y\xd8=\x80\x00O\x12\xcd\xa6m\xb2G\x9d\xbf\xcb\xa3E\xb4\x7f\xb2\x9a\xe6K\x11\xc1N\xa1=E7\xd9\x10\x19\x9d\xa3\x7f\xf4\x86Z-\xc3t\x86~yXd\x11\xcd\x94\x81<\x9e\xda\xa8\xc8\x88\xf8\xa0\x90\xe8\x93\x1a\xa2d\xe9\t\xe0\x8eO\xf8\x8d\xca\x85.?\x95\x13\xe9Z\x84\xed\x08\xb3\x82G)\x92?"X\xf4\xa8F\xcf\xc1&\xd8fVzY\x04\xc6X\xd7Q\xd4^\xb1\xa6\x99\x08\x11_?.\x10hRR\n\x17\xb9\xb9/\xb8\xeb\x08p\xc7\x06\xd9\x9dy.Z\xe2{CU\x04X\xd2\xd1%#\xc6\x87\xb0\xe5\x9b\x1d\r\x82\x96\xb2\x13\xeb\x93 \xda\xbc/L\xe5>\x0e\xdb\xe8\xf4_~{8\x00!8y\xc1\xaf\xf7\xac\x86\xf3LL\x1b\xc2\x13\xf7^\xcb\xfe~A`l\xcc\x897q\xd3KAO\xe7\xe9\x9fIA\x86!\xfcA\r\xd2|\xfeq\xc4mc\xd7\x10\xef\x0ce\xe1\x14\xaaqje\xc4\xc7K\xf0lz\x06y\xef\x93\x8e{\x0bk\x1f\xe3\x9d[x\xa0\x8c\x84\x8a5\x848\x00jt\r\x8a\x0b?\x92\x91N\x93\x01\xeaE\x16\x89c\x0c)jhTH\xcc\xe4\x01\xb0mM\xd3\x8e\xe1\xbbU\xbb=c\x8c\x81\n\x00\x9f\x9b\xf2#\xd6"2\x1b\x10\xaf\xb2\x82\r\xb872t\xdbX<\xf5\xb8\xcf\xc8\xf8\x8c\xb7`L~W\xdc[9\xf9\xbb\x97.]\x0f&{\xfc\x03\x18\x9c\x95\x14\x98\xb8\xd4\xd0\x9a\xcd\xcc\xeb\x93\xffW\x05\xa1\xd2\xf1L\x96i?\x9ds@\x8c\x1d\x03\xde\xc6\xdf\x10\x7fU+\x9ac.\xa16\xa0\xe3\x81;\xa6\x12\xcf\x91\x08\xcc\x14\xfa\xfb\x07 \x03\xa3\x88K~iy\x82\xa2rTD\xa5\xd3\xad\xc8\xfeC9\xc9\xc09r=\xe7\x80\x96\xfa(\x96*Ae\x89\x94~\xe4n\x07<S\xae\x80\xf1\xd29\xde\x03\xa3\xa3\x85\xdc\xa1\xd6\x0e\xb5\x98\xdbON\xfe\xdf?\x91ys6\x8fe\x86\xfc\xf7r\xdf1%\xcc\xb5\xa8\xee\x97\x9c\xd8\xf4\x9a\xe5E \xbd\xa3\xd6E\xb0\xeb\xa6\x0b;c\xb7\xf5\x00\xa0g,9\xae\x91\x03fK\xf4\xacQ\x80Pa\xbb\xd1\xa5\x80\x8d\xf5\x8d[n\x94\x8d\xb08\xbc\xa2oU\xd3\\\x83\xeb\xc75\xa6\x14\xb8\xc4\xbf\xa8\xc9\t;8\x85=\x83\x83t\xd8\xf2\xf2\xe8\xa0"\xce\xdd\x18\x064!N_\xa0\xd4\xc0\xd5I\xf6 \x0c\xde\xf78\xbdw_\x1f\xe8\x9b=o\x97\xc0\xc9\xe0\x04\xc9\x9d\x97 \xea\x06afoW\xd1\xd5S/\xf5\xb7.>v%\xd2\x12S\xae\x93Z\xd1\x18i^z\xcc\xe8\x171\xfa#\xb0\xdf\xf9\x01y\'\x9f\x18\x80\xfc\x8fD\xaa\xa1_\x03y\xf9\x9e\xb6\xd6\xe9\x1aK\xeeGY\xcb\xdc\xc3\xf6\x02\xe9\xed\xe8x\x1b\x87\x9f\xcc\x8e1\x16\xbc\xc4\xc2E\xdb\n\x84\xaa\xd8\xa6b\xaa\x05\xc4R\x00Z\xcb\x9a/\\\xe3uD\xb2\xbb\x95\xd0E\x86\x97S\x0e\xa4\xc8\xe8\xcawU\xc2(\x8dcn\xfe\xa0\x12\x11]\x93\xb9\xd9g(\x1a\xb8\xb0FZ\xea.\xce\x861\xee/Q\'\xa3\xb7\x17\x9f\x98\xd2\x16\xa11\xe4\xaf\x03\xa0\xc9;\xac\x0b\xa7\xcb\x05\x1d\xa86\x15k\xcc%\xf2j^\x9a-\xb2\x1d\xb0\x12F\x7f\x95G\x80|\xd5\x93\xbc=\xf0\xa4Wi;]3m~\xb5D\xe4\x9c\x0f\x05\xb6\xbe\x9d\xa9\xe34\xb3!\x0b\xb8\xd7Y\xa3\xc8%\x06\xe4\x7f\xee\x0c\x1d\xa6|\n\xee7\xb6\xe9\xe7\x9f%!\x82\xf1\xcb^.\xe5\xd5\x04P\x0c\x1b\xcc\x94\x0fE\x15\xc6\x12\x9d\x90\x0fx]\xed\x85\x99\xb7J\x95\xad\x88\xa4S\xf3\x11\x8d\xd1@\xf4\xc2F\xael\x9c\xaa.\x93\x07\xce\xc6\x800\x15\x11\xd0T\xaa\xd9\xael\x1f^TN21\xb5F\x9e\xc09\x9f\xc7[5\xc0\xf4\x99Q\x88\x9fF~N\xe9P\xe1\xc4\xffD\xdcX\x94\xfe\xd0|\xa6\x0e\x8c\xf6.\xe3\xfej\x1c\xcd\x06\xac\xc6\xee\xdeE(\xcc\x85\xfe39\xcf\x18\x17B~4\x8awb\xe2]\x99\xe6=6N\x8f\x03\xc3\xd2\x0b\x85\xd6\x17\x80\x92i,k\xa9\xc9\xd3\x9b\xce\xf2\x98w!kdGuQcN\xc2\x9a\x97\xcf\xc7+\x99\xc0\xbf\xd1Q\x01o\x7f\xc6\xfa\xd5\xa3\x17X\xbd\x92\xf5R\xed\x0f\x15Yk\xf7\xc7D\xa8d\xac)0\x13\xd6\xd0\xd1\xdeC"Ut\xec\x0e\xb8\x85\x82\x007\xd8\xbaU\x13\xe8J\x87\x0c\xe3\x81\xcc\xf2!.\xe9\xae\x98Q\x1f\xd1\xad\xebK\xa1O\x98w\xd9\x03{\xa6\x1e&\xef\xec\xa9\xbc\xc9\xc5\xe7\x7f\xa3`\x18p=\xb2\x07Q\xffW\xc7\xc7\xf1\xd3\xad\xd3\xda\x05x\xfc\x9c\tS \xdf#0\x0b\x9eN\x97s`:)f\xe8\x82\xe9\x03\x8f\xec\xfe"\xe2\xda\xaf\xb3:\xc9{\xae\xd5\'\xe8Lv\x02FM\x16\xb9jQ\xca\xdf\xd5\x8b\xca\xa6\x84\xffR\xe8w\x87\x00M?(\xa6\xd0c\xfe\xdb\xbb\xf3@\xae \x1b\x9d\x10\x19\x85\xd6\xab\xf7\xf2\xed\xd7\x89\x92\x10\xb9\x1b\xc4\x18\xa0\xe1\x1a;\x95F\xf8\'\xfdi\x1c3'
|
|
|
|
|
|
2024-12-14 17:54:48.330463 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25566
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808846229
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.332673 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25567
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808852069
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.338279 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 2960
|
|
id = 47943
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xd8
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808852069
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\t`\x92\x9d\xac\xc3@|\xf5\xfe\xc9\xc2\x02\xf6\x9a\x13\x81$\x8dn\xa3\x82\xd1\xbcIV\x19\x85\xc2kd\xccD\xf0+\x990l\x93r\x89\x8a*W\x17;\xd4x\xd6\xf8K\x14~\xe0G\xf5\xdev\x93\xf4|U\xcf\x19\x97\xcb\xe3\xc3\x1fW\x1b\xe8d\xe3\x9e+R\xeeJ\xb7W\x1c\x14p\xfb\xbf/\xaa\xb4Q(C\xee\xa4\xa8\x8bpN\xeb\xe3\xc0V\xa3\x90ocOp|\xb7=\xbdx\x83G\xa2v\x1f\x84w\x1d~\x13\xfb:"\xb7sJ\xee0/\x0c\x0b\xc1z\x0b\xee\x17\xc5\xae\xfe\xe5\xb2\xb8\x9am\xa1\xe0g\xa1\xc3\x88Km\xf4\xbd{\xf5@\xce\xc4a\x904"\x8dTT\x1e\xbc\x03\xff\x84\xe4\x95$\xef\xe8\x05\x97c\x15\xe1\x9e!"\xc3\xf8\xe6D\xad+\xfeus\xce\x05\x97V!\\\xfe<\xddu\x01\x07\'\xf0\xb5\x1b\xe7\x1f\x8f\x8eZ\xd1\xd7\xc1W_\xc9\x92\xad\xd2\xaa7pkC\x84\xaa81\xf8o-\'\xaf\xc9d\xc3s\xc4\xe2\x84\x1at\x88\x9e\n\x0f\xf8\xd2e\xa3:\x8f\x1e\x98\x87sz\xd6FW-\x81\xad\xbf(Y\xbbZSE\xbe\xad\x97\xad]\x01M)N\xc4\xa5\x1eF\xa0a\x85d\xaef\xcc\x7fU\xe9\x0f\xac\x1cF\xb27\x11\xfe\t\x7f\x9cpP\r\x92\xc6\xc5\xdc\xb0\x1b\xeb\x088\xea\xa4\xb0&\xe0V\xcaTq\xd2(&rq\x8bN\x88\xf7?%\x87)>\x80\xf6\xe2\x94\x87hn^\xec\xf1\xfel:S\xef-\n\x87\xc7<\xae\x92\xac\xa4\xd3z\x1b\x1dnoOt\xf1\x8dC<1\x9a\xd9\x93\x00\x8b\xf6\x9f\x8a5\x05\'\x17\x03\x03\x00\x1a\x07\xde\xb9q\xf4\x86g\xea%\xa3\xdd\x90\xd5$\xae\xe6\x07\x15HP\x93\\\xd7\x7f\x01\xc5\x17\x03\x03#\x00\r\x88\xed\xb6\xc4!H\xd6\xe6e\n\xd8;U\x9eG\x04\xb9\x02\xf4\xda\x0e\x07g\xd2\xb4,\xa3\xdc\xea\xa4\x8d3\xb3\xa8%\xb2\xe0M~\x08\xd3\x92\x15W2\x80W\xe1\xf7B\x19\x7f\xd6\xe9\xa9\xbd=\x8a\x14\xb5\x8aq\x98\xe3\x95Z*\xf7 \xbc\x8f\xef\xa3UF\n\xaa6\xbf\xea\x94k\xa2\x16z\xa3\xab`\xb2\'?\x87V\xe6\xe2\x92,\xca\x87\x8b%3\xabx\xbf\x0f\x074\x02B\xff\xbf \x82\x02\xf7\x0b`-i\x8bk\xd2\xa7>\xf4b\xa1\xff\x05H\x17\xde\x95p\x1fll[\x19\xf7\x83\x91\xf6\xcc\xa3\xaf\xc4\x08@\xe4\xea\xc3\xaaM/F\x93V\xbc\x96[\x96\xaeu\xcfD\xf3h\x88Z\xb9\xedz\xc0\xd9t\xde\x95U\xa6-\xbeF\xa6\x15\xd7\xeb\x01\x86\xc3\xfcpu\xae\xdap3\x19\xd5\x9a=;`\x15\x17%*\xbd\xc8\x96\nE\xc9Q\xe3\xed3\x9f\x90\x07\x04\x11|\'A\xa9\x95\x0c\x03\xd5c\x8am\xf7,\x8f\x0bP\x89\xfb\x84\xdc\x941\x10y\x96\x08\x9e\xaf\xf6\xd3\xb1)\x98\xdb\xa3d\x0fY\xbcz\xeezG\x16>F\x1fI\xf8\xff\x15\xacp\xd8\x0f[\xf41,\x06T\xadR\x04Z`\xe7\xe3\xff\xb6F\xff\x9b5B\xa8{.\xab\x8c\x1c\x8e\xeb\xc2\x8e\xa1\x99\xed\xa2\x11\xdaG\xfd\xddY\x01W\x0fe\xe6O\xfbv@\xc4\xb2\r\x91\xad*L\x14\xfa\xcet\x13bO\x0fQ\xa5X\x1dT\x88q\x93\xac\xaa\xe1\x1e\xe8\x8e\x19\xb1Yx\xf8I\x9d\xaf\xb3\xff\xc1m\xe8a>\x06_\x07\xee+*\x9e\x1d\x18"\xbe\xc5\x88\xea\x93;\xa1t\xd9j!4\xd8\xb1@6\x89\xf1\xcf\x86B\xb7\x9ai\xf3\x90+\xa6\xa1\xcao\xd1\x9eh\x04.}c\xb4\x973\x85\xdf\x8a"\xe4\xf0\xd4\xcaB\x14\x1fS\x1d\xbf\x1e\x90oe\xc4\x7f=\x12{\x9eK\xf09\xc6\xf1n\xd7\x98\x14\xba}\xe2\x1c\xeb\x8a&\x92\xb0X\xc8\x97D\xa8\xce \xbd\xf4\xf0\xb0\xe3\xf3\xebv\xca\xd9\xb2\x04\xe5\t\xfc\xe8\x99j\xaf\xe6x5aT\xc61\xd6#A"\x96\xeaU/c\xb8\xbc\x89\x9d\x8c\x86jbJ\xd3\xa8\xfd\xde\xbb\xa7>\x16\x00\x02\xdb\xa9\xbc\x04\xcd\x84\xbb\xba\x85\x08;\'\xef\xcf\xc7\x8d\xa3\x17\xb6M\x01\xdc\xc4\xfb=\x1cp\x9b\xe1\xf4DeH1\x0b>\x1f:K\xfa\xa1\xae\x81\xa2\x9e\x9c\xb2v=\x9d\xbb\x93^\xbf\xaa\xddp\xc9>[\x05T\x13\x89\x95q\x7f\xc3\xb4\xe4\\\xba\x9d\x87\x84\x05]P\x9f\x85\x1ea\xc3\x19\r\xde(\xea\x1f\x05\xb9\xad\xfe\xca\x00\x8f\xe7k"pM\x19\xdd\x13\xef\xf1\x84\xea \x17;\x8a\x089\xa0\xa64\x98\x8d\xef+etK\x86\xedo\xbf\x93\x9eN\xd9\x10m\xa0tw3\xa1\x03\xf5]\x99D\xd7\xf7\xea\x9fU\xc0\xc5P{9n\\"\xb9W4\xe68\x86*\xcc/?\x90\x8f\xc3\x01\x91\x84x4\xb0\xbc\x1b\x11\xdd\x0f\x90\x84\xc2\xae\x8b\xe0\x90\xc21\xe7NN\xadj\xfe&\xb9\xc2\x140ts!\x15\x08\xd0a\x89\xf8[\r\xa4\xbex\x0f\xbf\x06\x99\xe2\x82\xc9\x89n\xcc7I\x0e?6\x8c:\x84\xb5\x91\x96\xcd\xb9\xd1\x82\x11K\xc0\x83\x00\xd3\xb5S\xd8\xe1\xa2\x92R\xa3\xb6u\xdan\xb8\xa9\xd4L\xf3\xbc\x862\x81\x8d\xa7\x08\xafl\xf9\xa6\xb8\x0c\xa6_5\x08\xfeS\xd9\x06\xd7-\xb1\xc5\xb7O\x86\xf4)\x95\x9bS\xc8\xac\x9f\xd7\xbe`\xc8a\x83\x11:\xac\xdb\xf1\xa5\xc5`\xbc\xeb\xa4M\x9e\x7f\x13\x0c\x8f\xa97\x80\x1c\xd6\x1b\x85O\x18\xdaV96\xd4a_\xaf\x88\xbf\xd4\xcd\x08\x87\xa6\x97\xe97t\x03S\xfe;\x8c\x06\xf9\xbc\xd5\x12\xbf2[\xdb\x9c\xc8\x8b\x03\xd6\x94y\x08\r\xac(~\x84\x1b\xea\xdc\xc0\xd1\xf4\xba\x03\x86#\x1b8`\xdcj\xdf\x83\xe8\x0c\x90\x89\x82F\xbf\xc1\x94\xa7\x96(!\xca\xc9\xfd.o|\xe6Is\x85a\xc2\xe1\xfc\xb0p\xb3\xc09#\xc8[\x1b\x1b\x1f\xfb\xde\xa9\xe7\xe6\x13]\xc3\x03u\xa6\xc9\xbc\x8e\xdf\xa7\xd8E#\x93\tZS\'\xeb\xc6\x08\x90Et\x95\xe1\x89\xc8{ZBr7\x01\x94`\x84~\xd3B\xae\xe5\xf5,\xb8<l\xed\x12\xce\xa7\xae\x8a\x84$H\xa2\xfa\x15\xfd\x8fjT\x14\xcd\xe3\xd7\xaf\rDt\x07S?JJ\xb6p\x16\xf8L\xda\xcdW\x85-\xc2A\xac\x01e\xc7n\x02=8\x174_\xb1E\xc2\xb7\xea\xcb\xf4\xbb7\x86\xbf\xb7o\xafO\x8a\xf0\x06\xbdd\xbe\x9f\xc0\xb4\xdaU\x83k\x16^\xde~\xb5\xb8{I\xaf\xdd\xaf\xae\x1c\xcc\xd6\xeaC:\xd4e\x85\xbdZ\xa9X\x1e\xbf\x95\xefW|I\x93S\xcat\x13\xe7\xf2\xac\x10R\x1bj\x88$\x98D\'R\xb5\x91\x14\xf4k&S\x03\xfb|\x08\xb4*\rm\xbd\xbc\x1a\xb5\xe40~\x8d\xe3\x10N\xcbS-2\xe6\xb3/#\x98\x11\x1fB\xbc\x81\x97\xaf\x1e\xc4g\x95@N]Z\x12b\xfc\xc6\xdf5\xb2fq/\xea\xfd\x18\xbc\xd3\x94+\'Rq\x06\xe0P\xe0\xf9\xa8\xec\x06_\x14"\xfd\x00\xbe\xe4\x9a\xba5\xadZ\xf1+5\x95\xf7\r *\xf3\xe3\x92D>\xe2\xd5RiYIk/x\x89i\xa2eP\x11\xaeb\xdc?\x04/S\xf5\xb6b\x8f-\xaa\xe3i\xcb\xf5G\xb07\xa6\x0b\x98\xe9W\xa9\xc9\xac\xe8\xf1\xeb\x07\xd8=\xbdr\x00q\x92;\x0c\xfb\xdf\xcd\xc4\xbb\xeeP\xf8\x90\xbf\xf4R\x03BFv\\\xe7vE|\x02\xce\xb7`Ak\xf3X\x1b\xc8yqj8\x10i\xce<\x06\xbaW\x7f\x19z\x08wX\xae\x87\x88V\xdeT\x02\xe0\x05\xb0\xd3+ \xf3\xc0\xe6\x8d\x87\xe1\r\xd5\xfd\xa8\xff\xa9ZqW\x0f\x1e=\xd3\xf1\xaf0N\xbe\t\xb1lo\xact\xcd\x8e\x7fe\xdb\x9dIBg6\xe8_/\xb2p\xfebB\xbb\xa9\xb8\xd4\xc1!\xea\xd9>\x12u\x84-\xda\x11\xea\xbd]\x7f\x82WUA[\x980N}\x80\xc0\xe7@at\x02\x91,(T@;\x92\xe8\xd4\xff\x00\x9cJ\xddO\x19\x038\xe4\x9d\x17\x18h\xa4+\x1b\x95\xac\x022\x12\xe7\x11U\x00\xff\xa4\xf8Q\xbd\xb5\x10\x8f\xd3\x06Hf\x05\xd35\x14[\\\xac~-\xff\xad\xf7\x1c\x89\x88\n\xd4\x9e\x9f\xf0\xb2\x9fw\x84"\x86U\x12\\\x10QeI%\x9at\x8e\xaas\xb8PX\x03\\\x18y\xa7?w9!\xaa4P\r\xdc\xb3\xf4\xe0\xb6(\xbb=\x0ekL\xbf\xcb\x88\xfc)\xcc\xb0\xb0k\x18#\xfe\xbe\xda\x85kr\xbeF\x8eB\xc99\x1c\x9e\xb0\x05\x15\xe3E\x0c.\x08\xcb3\xd9\x13\x8b\x99y\xed\x9d\\!Y\x08S\x15\xb62\x9f\x953\xdf\xb5\xca\x02`\xf5v\x98\x08&\xa9\x99C\xeb\x00\xbc\xfc\xfd\xcc\x93\x1a\xc0s\x1a \xd5\xf2\xde)>\xc58?|\xc4\x9f\x91\xfa\x82\x94\x93\xc9\'\x1c\x92Yf\xbf\xa1\xb6\'\xf2\xb9"\x83\xae.\x11y(\x93D\xe5\xc6E\x1f[t\xc9VH\xc9-?\xc8\x08\xdc\xc7\xde\x1a\xa3\x8fX\xd4\x0b\x17D4<Z^J\xaf\x16\xfe\xb1\x062W\xf5\x94q\xc8\x01\x99\xac\xa2\x1ebNJ]\xbcn,\x87\xa5\xdf\xee\x0fX\xd41p\xef\x90\x07\xfaMT&\xfb\xb6\xaf\x14y\xc0\x1f2\xf7\xc2\xe1\x1d}K\xac\x14\'\x1d\xee\xb8\xf6w\'\x88}|D\x13T\x08"\x00vy\x170P\xaebRR\xd1*.\xf3\x85\x9a\x90\xe5c\x8bFv\x81\x9as\xf3p(R=\xb9\xf5\xa0\x04\xc4\xa0\x86km\xb3\xa5p\xe2=B(\xc6\xb3\x10\xdd\xe3\xaf\x81\xc2\x8c~\x17\x8c\x98\x83\x94p+&vF\xf1\x8a$\xa4\x05\xc0\x846\xac\xce\x11R\t\xc0\x0c\x18\x8f\xf4WQ+G\x9e\x9e_m\xf9\x08\xe2!\x08\xede\x19\x1c\xa6.\x9d3f2\xf8\xdc\x80\xa3\xa8\x7f\xfa\xe9\x19\xe6\xe0\xaf\x86.M\xdb\xef\xbe\\\x1e\x08\x91\xee&\xfc\xb6\x96n\xa3\xd2X\xd2\xb0T.q\x11:!8C\xa8q\x9fK\xfb~\x14\x1d\x14\'/\x9d+\x9f\xb7\x1b\xf9Z\xed}X\x1c\xdd\xc5\xf5\x9eT\xd5c\x0f\xce\xb1\xa7\xdf\xd9\n\x0ee\x8c\xfb=\xd9:\xa4\xde+\x1eS\xbf\x98\x1a\x00-\xf3\xb0\x16\xf4\xe2\x1f\xa0\xfaMZC\x16z\xfa~\xd0h\x16\xcf`\xd5L\xac\x83\x0e\x92m\x8c\xa7\x93\xb3\xb3\x12&q\xeb}{\x83%4Y\x1c\xe3\xdb*\xae\xca\xa1D2\xcf,wG\xb5\xa0\xd1{Z\x83\x92\xd4\xe8]\xe3\x8b\xed\xc5V\xd0)\xfdu=\xa1{\xd6\xc3\xb4 U**9\x81\xfay\xce\xf6\x8d\xd4X\x86\x92\xe9NE\xd7\x93\xbc\xc3K$&\xa4C\x0f\xfd\x80\xac\xf2\x1eI\xd5%n\xf7\xfd\xaa\x11\x98\x15A\xc3~/\x00P\x91\xec\xfe+Q\xc1\xbb\x82\xc2\xa8\xaa\x15\xef!\xb7\x0bh|\xe7D1\xa8\x88\xa1\xc1\xf5\xfe\x05s\x02+\xdd7K\x8bS\xd4os\xe5\t\xc7Z\xeb%\xfc*\xb6\x11\xc9\xec\xd3\xe9qP\xbeN\xd5.\x1b\x81\x90\xbd\xf7\x82\x83\x8a\xe3\xd1\xd2QN\xd31E4:X{\xc4K\xb2\xb2\xf6dT)\x8d\x84\xe9\xcda\x8dj\xd8\xa3\xc0\xb5\x00\xa5^\xbe" \xde\xce$D\xda\xab\xbd\xf7\x12\xd4\x10tE\xd2\xa2\xf2\xac\xfb\xad\x8aY\t\xbeY\xc8\xa3\x142\xccvi\x9e\xdb\xfeoJBq\xb2\xed\xb4u\x93\xf1~K|\\\x1cz<M\xec\xbe\xdb\xc2.`uz\x83\\\xe0\xbd\xcb\x92\x17\xa4\x88 3\x8a\xd8\xfa\xafg\xdf7)\xa9\x86X\xc1D\xd2\xeb\x11E\x02\xa4]\x90\xc09\xbb!_sP\x8a\xb5@\x98L=c\x92\xf5\xe1\x17\xcd\xd3\x1e|\xfd\xe5U\xb6\x08g\xe26\xa9\x92P\xe2\xbe8p:\xba C\xac\xf9$\xe1\xe3\x80\xbf\xfd\xce\xed\xea\x84\x19\xf7\xce\xe3\xc0:cF{6\xe4\x84\xbd\x85\x1b\x04\\J*\xacZ\x8a\xd0\xb2\x1bU5\xa1\x95J\x9b\x9d\xf40Z\x93\xc4\x08U\xafdA\xe2`<\xbb\xbf,\xd1\xd7\xbb\x12\xf8\xd0\xb0\x9c\x1d;QV\xf0\xb7\xf2H!.\xdf{u\xa8\xb4\xae-\xc7<c\xf4^$^\xb5\xbfx\xfa-\xf7\x86>\xc4=\x97\xf8\x83B/T\x83\x93\rDT\xbc6m\x0c\xbaR\xd4\xc0\xf4\xe1RZ\xe1\xaf@\xab\x19\xa1\xb47\xdcJ\'Z!\xa8\x04\xac\x0e*\xd8>\x06e\x83\xf5\xfaS'
|
|
|
|
|
|
2024-12-14 17:54:48.342773 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 64
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d27
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 44
|
|
chksum = 0x11c1
|
|
###[ Raw ]###
|
|
load = b'Z{\xfc1)4s\x84\xba\xaf\x9aP\xc3\x0f\x80;\x07\xb6Q=\x0b\xce\xa5\xf7c\xfd\xba\x86\x9b\xf71\xc3\xb5\x11\xfb\xd0'
|
|
|
|
|
|
2024-12-14 17:54:48.354994 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 8800
|
|
id = 47945
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xea05
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808854989
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'b\xcb\x90q\x03UI\t]u*q\xf4\xec\x91\xbe\xeb~\xe6T\xac\x9a\x1c\xf0\x05\xa1\xed\xd2\xd2\xc1\x160P\xf0\x99\xb79\xe2\xc4\xf1\xab9A\xa7\xe1B\x0f&|L\x91\xfc\x17\xdfYZ\xdc\xd8$l\xff\xe8\xab\xb0\x87cc\xda\xf5;\x17\xa6\x97\xf6\xdd\x94/\xe4\xdd\x1cI\xf6\xee\x00gl\xc3Z\xdcp\t\x16|\x10\xc9\x9a\xba\xea\x93\xae\xc1\xbb\x1b\xaf}\xa5k\x9bU\xde\x17z\xf9\xb4\x11\xf4\xcbr\xd9\xf76J\xdfJmV\x02\xdc\xbe\t"p\x0f\x8a\x05k*\xf9\x89\xf4\x82h\x168V-/\xba\x04x\xc3\xd9x\xf7^\x03a\xa4\xd6p5\xaaM`\x00\x82\x0b\xa7\xdf~\xf1\xbbk\x00\xfb\xbb\x03\x0e\xbc\x06\xf1\x9b\xa1)/\xbc\x18\xb8v\x1c8\xa6H\xde\x95 Wv\xbf\xbal\x88\xf8\xed\xb9gE7\x06K>X\xba\x0b\xd3\xe0\xf4\x9e\xd5\xa3}P;\xe8\xe9\xa8\x95w\xde\xf4\x0e\x97\x02\xf1\xb4S\xb1\x97C\xb7n\xb8\xfdn\x14c\xd6\xdd\x99\x16iP\xa2\xcf\x17\x07\x12>9\xcbC\x89\xebPbz\xccG\x06b\xb2~\xa6M\xb5k\x85\xdc\xa1Gu\x17\xaf\xa7\x9b \xe7\xb0\xb6Y\xe1\xd5\xa3C\xf8\x03\xfa\xdejX\x8a\xfd\x9c\xa3s|\xac\xf8\xac\xcaK\xe9\xdc\x1f\x93\xeb3\xe4\xd2l\xe3\xcc\x04\x91B\xa3\xbe\xb9\x11S\xf5\x96I\x97\xdf\xeaGb\xd5-\xca}\xadV\x95\xfe\n\xfd\xd5\xf6\xfc\x12;\x9a|q\xbf\xc1\xa0\xef\x04k\xda\x95\x9f\x0e\xd8\xfc\xafV\xa1\x0b\xa0\x99\xa2\xaf\xccz\xf6^x\xaf\x9f\xee\xc7\xb2\x7f9\xb1\\O\xb8\xa2\x1e\xe4\xe3\x81T\x8ar\xb5:\xac\xc4\xdb\xb2\xb6\xf5\x9dz/f\x8d\x8d\xd9\r\xf0|7\x01\xa5\x1c\xeb\x0e\xd2yJ\x0e\xebju:\xa7\'\xf4z\xee\xfa9\xefCu\xed\xae\x9f\xb2\xaf\x08\xc7P\x82d\xf8V3\xaf\x983\x1b\xb1\xee\xef\x90\xc6\xdf\xc27)D=\xed\x11\x97z\xb4&n\\\x7f\x05Qh\xf9\xc8\x80g\x8d\x958\xf3\x0fm\xfdf\x06\xf2J\xd5\xe8X\xf7qZsr\xeeU\xa0%\x8d\x0f\x1b\x94=gm@Z\x8b\xa8l\x9a\x9f\xd9^\xcbot\xb4-\x9c\xf3Ulz\x08}\xf2v\xa0\xce\x8a\x94OV\x11\x07\x0f\xa3\\\x95C)4R\xb1\\\xbf\x10\xa4#M^\xe6\xff7\x8czu\xe6\xbf,\xad6\x97\xfb[\xbdp\xf9\xe5!\xf5h\xf4D\xf0#\xa2\x1f\x84U\xe4\x97\xaf\xe0\xd2P\x0f\\\xa4\xae\xcf3\x9dQ\x7f*+\xc3\xb5\x18\xdd\x99\xeb\x04\xc4\xad\x0fpAR\x07\xdaT\xbc\x0b\xee\x1d\r\x92\x00]GF\xed\xfb\x1cc\xa2\x1e\xe9\xf2G\xd5sp\xda\xb2B\xc1\x86\xcc\xe0R\x98l\x06%\x07\xd2\x89\xc3\xb4\x88F\xe0b\xae$\xa1\x08\x8ck\xa3R\xb5Wc@\xc2A\x012\xffb\x1a\xea\xcf}\x9fm\x88,M\x8d0\x92\x80\x04\x9e\xdc7w\x89y\xe4$n\x00\xe5"\xaa\xe4t\xc0p\x1e\x14\xd7\x81\xe4\xd5\xf9\x99d\xf5@\xfa\x15utx\xf7MDC\xaf\xc1\x97\xdb\x0c\xd6\xb1?-\xe6\\\xe7\x9dqj\xa8\xabq\x8f\x99>\xf7<\x14+\xe5\x97\xcb\xadm\xcc#^I\x17\xaa\x98\x15\x8d\xef*\x97\x99NJf\xefR\xc7F \xb7X\xb0\xc4W\xa9\x02\xfc\xc8\xf4B\x87\xa7W\xce\xea\n~\xf4\xeb\x9c\xd4\xc8\xc6sU\x9eMd"\xa8\x7f\x9d{ks\xd6IT$\xe3~\x17\x8a\xaaY[{Qb\x0e\x8c\xcb\xbf\xea?\n\xc4MC<\xae4\x9f\xf07.\xdfSC \x8e:\x12\x85T#\x17*\x80\x03\xc8\xf4\xa5<\xa1\xfa\xe8\x83\xd5vQO\x7f\x00\xbb8\x0b\x0c\xcbp\xa40\xb0\xfa!\xaa\xf3\x0cg\x93\x95\xe8\xc6\x8dF\x81\xec\xe0\x00{kr\xd1\xd8\x8c\xb9\xc3\x14\x1a\x03\xc6\xf86\xf8\x0b\xcf\x08\xb2\xe3y\xcf==5\xac\'\x8c\xc2\x92\xab\x0c\xbb\xfd\xb6\xcet\x16RX&\x95g%\xfb\x08\x1c\x04kB\x12\x89\x99\x86\xb8)d\xd12>NRuo\xe0(y~\x0e\xcdz2&\x99\x8ba3\xb0\x9c\xd9\xd4\xeaZ0\x97\xc6\xf8\x17z\xaca\xe7\x12rw\xe9\x19\xa7\x15,r\x0c\xdb X\rA3\xf4\x05\xa2H\x1cj\\\xfb\x83\xf8m\xe7\x86.\xae\r\x9e\x06\xe7\xa855\xa1\n\x97\xae\xe7\x97\t\x1eG\x92\x8a\xf5g\xe0\xfd\x1a?\\\xa4JF\x00\x02\x9dMQ\xe75R\xa3\xdb\x13/\x12\x84x\xaa\x19\x86S1\x8aHy\xf4\x142s\x07\r\x8co\xa8lCK\xb2\\}U\xfb\xd7/\x18\xb0\x08-\xeaY\xd7\xb5\xc3K\x16sX\x93\xe4\xde m\xbdFn\x1e\xa9,\xc0\xdd7\xcbC\xe0\xa7\x94\x92\xbe\x00\x91\xec\x17\xd0\xc5\x81\xf3t\xb5\xb4I\x8e\xae\x11\xb9}\xef|i\x8aF=\xd9\x0e\xcd2\n,\xbd\x89C\xa2\xb1*\x94\x95\xa0\x82\x05\xe8\xd0\xc6\x1e\xef\xafRi\xea\xf5\x03(\xc7\xb0\x19\x15\x07\xcd\xc7\xd8Z\x15T\xc5n\xd7\x1aY]..G&7\xee\xe7\x1a\x9fjI\xadH\x14.\xd7\xfbp\xccCd\xcbW\xda\xee\xa8f\xc5\xc3\xea\x11\x00U\x14\xa6\x10;&\xe8\xc6(\xd7\x9f\x9e\xe0\x08\xc0\tl\x86\xc1N\xb5E\xf5~ \xa9Z\xf0\x90\xf8{y\x89 q\x87\x12\xa9\xac!]\x1d_?jG9+Y\xae/\x17\xddH\x9d\x994&0\xca\xbdDuIC\xe9\xe6\xbf\x0f\xaf{U\xf5O-\xc6\xfdk\xfe?\xce\xdc\xf7\xf4;\x8bK\xc0\x93nyj@!(\xec.\xb5g\xd6!\xcf\x90\xf1\x0ei\xfd\xf1\xc9\xb2\xd8\x8d\x9f\x1d#\x07p\xa2k\xb5\x1a\x82\x9a\xb0o\xad=\xb93\xca\xb0\xaa\xf4\xf7H\xfb\x00\x91Li\xa2\x00\x8e2j\xaf\x98}e\x81s\xec\xfa{\xd0X*\xa3[J\xb6\xa3\x08.g\x98\xbb\x82\xa9\xae+\xefb\\.\xb9\x8f\xe2\xf0\xa94\x8f8\x17\xf4\xb7\xe86 oyp,\xa1\x07\xb0\xde:\xd9\x94\xdeb\n\x8d\xf4)\x03\xce\x1d\xc0Pl\x1b92\x8c\x84$#|,Pt\x99\x0f\x8aNYc{\xbe\xec"\xa3\xe9b\x96\xd0,\xd2\xbf\x85\x9dED\x8ce2R\x18\xb2\x92\x8e}\\)@\xc3\xb2w\xa89\x90\xaf)\xc8\x04\xd23r\xd8\xc2\xce\x892F\xd5\xbc\x01\t\x0e`zP[d\x85\x1e\xad\x17\x95\xc4\xb3\x06\xc0\xe1\xc3T9\xc2*\x15<\xa4\xb0v\xe0zuY\x9bx\x16z\x1a6\xbb\x84\x9d#\xd0\x8ddSE`\x7fduc\xa7H?\x82\x85\x11\x12\xe9\xe2N<\x1d*\x04n9\xd2\x9d\tb`\xdd\xadr\xc3\xeb"\x8f5l\xd1rF&\x84\xd5\xcb\x00\x10\xd2\xad\xbe\xea\xab\x0e\'\x0e7\xbd\xa5\x8e\xf2x\x9b#\xd9\xf1\x89F\xff\xd02\'\xba\xdf;\xbe\x89\xa9\xdeQSp\x01\xcb\xd9\xe9\xe6\x94@\xa5\xfa\xd9\xeb\xad\xa9\x12\xb6\xb7`I\x0b\xa4m1\xdd\x9f\x91-\xea\x8a\x00*\x9b\xf3+\xa1\x0f\x11\xe6\x07\xa1\x1dg\xab\x1e\x95[\xfc!\xc0\x9d\xb7O\xcb\x81\xb1\x18-\xa5\xfb\xaa(\xab\']\xee!\x0c\xd6v\x9f\xc4\x9d\xb9\xe0X\xa8\xff\x90\xd8\xb5\xbf\xad}Y`\xa2\xacP\xee\xd8B8\x03\x0fc\x97\xb5o\x12r\xb4\xd7M\x03\xb1\xae\x11\xe6\xfa(M\xb2r\x96\xa4gF\xed)\xc3\xc1\x7f1dvU\xe6a\x9c\xe2\x8c\xd7\xc1\x92\xbf\x15\x17\x8djx]\xf9\r\xf54\xb2\x18\xb2j\xbc3\x08p\xb8\xcbq=`\xfch\x9a\xb6\x97F/o\xf6\x86=\x14QN\xad\x8cD\x10\xfah\x83\x16\xe8%\xe4n\xfcX\xe3\x066f\x1c\x16\xb6\xc08\x0b\x83x"( \xf0[ \xc0p\xdb\x07tU\x0f\x89v\xa0\xac\x10k\x08\xfb\x1b\x15\x1d\x04\xfa\xf6\x08\xcc\xea\x02\xcc@\xcd\x19D\x18\xf6\xcbQ\x0f\xafb\x89%@\xaf\xc6\x8e!\r?J\x1e\x01c\xab\x81,\xb48\xaaGftYt\xa5}\xee\xff\x80}\xf7\x95V\x98)\xbc\xe98\xfb|:*h[\xaa\x8f\x10@&X\x03\xc9\x12\x82\xfb\x80\xf6\xeb\xdc CDC\xa5\xf67\xfa\x84\xfaC4!\x11\x0b\xe8\xf2\x01\x7fV\xec\xf0\xf17\x02\xee\xc1\x8c\x8cp\x89`r\x97\x12m\xae\xa3\x07\x9al\x8c4P4\x0fYH\xb2\x1a\x90FP2\x02:\nA\x1c|>`9\xc0\x18\xe3AN<\x1eD&\r\xf2\xcf\x03r$\xe4\xa5Mv\x08\xa7\xc7z\xd5\x13\x89s\xcc\xf7O\xe10\xbe\xdeU\x9e\xf2\xecN\x07\x8c\x0b0|\xbf\xa9S_\xe6S\xa1\x97\xe6\x92d\xe1\xd3\xe1Si\x16\x07\xc1\x17\xcb\x11\x06\x1d>\xdf#c\x8d[GgW\xb9PR\xc5\x84$\xbb\xde#\xc7V@\x80\x1232x\x1b\xfd\xdf\xb6\x9f\xa8E\x1c\xb7\xb3-{\xdc\x14Un0\x13U\t\xa7\xb5\\[\xb7\x95\xa0\xb3\x9b\xfa\xdf\x0c\xfe\xa5"\xff`\xb3f\x9a|\xbb\'\xc2P\xabj=\xe1\xc5O\xa6ty_<\x82\xe8H8X\x9b\x8e\x1b#\xfd7#\x9e\xc6\xdbwx\xed=.\xe6j\xcblQ\xf3N;\x054\xd5\xf5\xb9\xd2\xb9\xe6{j\x96\xb7yn\xa8\x8e\xc0\x8f\x9dF\x01h\x82\xf5\xed\xda\x1a\xa0\xd9|\x0e\x1d\xce\x045z)\xd7P\xd4\x14C:\x1c\xbf\x05m\x1fq\xb0_\xbd\x0e\xf0h\xf4z\xfen1)o\xfex\xf6\x92X\xf5\xae\xad\x94\xb4\xa5\xa7\xbfi3I\xaa~\xfe+a\xb5\xb7\xaek\x19\xcf\xa0o[\x1adR\xfb(\xd4\xe7\xa9(\xef\xabB\xd0\n\xc8w\xf3o\xf8<\xc6\xc14m\xb8>U\x05L[\xb0d\x9c\xaa\xf8\xf0\x14\x13&\'\xbbn\xf6\xd7\xe2}\xd7?\t\xf2A\xbcm\xa7\xe2\xd0\xe3-\xec\xc2\xf8\xb8\xf8\x98\x93&\xb0\xd5\xbc*\x0c80\x999\x86\x9e\xd8h\x8c}?K\xabT\xf4C\x82\xdeK\xc8@\xcb\x93\xccM<\xaa\xe8\xff\r\x86\xbfH\xd7\xc1\x07\xc9\x1c\xce":\xe5z\xa6\x8d\xc3T/\x1c\xa4YEo\x0b!as\xf5Sq\xce\xd91\xb3-\xa2:\xe0\xa49|\x83\xe6VrL\x16<\xae\xd2V\xbb\xefF\x01l\xb9\x85\xed\x9cK\xfd\xff\xf7rsG\xf1\xf4qT\x8e\xfa\xc3`\x1f\xbe\x9263\xe6O^i\xbc\xd6#B\xca(\xc8\x1e\xb2Pa\x11#N\x11w4\xad\x93\x03\xa0c\x15\x83\x8c\xfa\xf5\xe98\xf7H\xef/\x89\x01\xd0\xe7i\x11\xab\xbb\x9c=\x80\xa8\x14L\x1f\xe5i!t5D\x89\x0e\xa6Y\x9b\x02\xd4\xa7\x7f\x1f(=\x1d\xb6}\x81\x89\xc6H?\x7f?\xa1^s\x8fjc, [\xee\x01v=\xf3\xadH\xeb\xbc\x0f\xc7\xaac\x8bk\xadz\xcc=5\x05a6\x05RP\x16H\xdc\xb8ah\xe8\xc3\x1aa\xa4\xfb\xdd\xed\xd0\x10\xab~Zc~\xfe\xcf\xbb\x83(\xfd\xe4}\xe2+\x00\xa0\xa5@\xaf\x10\x1a\xa0l\xe4\xea#Z7\xa5r\x9fJ\x0cwO\x9c\xb8\x0c.\xeb\xde\xb9\\\x13\xff\xbch\x11\xa5\xb7\n\xd2GE\xed\xa9J\x8c\x08\xee\x10[DJ\xf0\xa3]P#\xee\x82\x90q\x1ae\xd5\x9c\x8b\xb2(\x16@\xe1\x0fE\x03\xfe\x8f\xe7\xcc\x8f4]\xdc\xecT\x12\xf1U"\xeb\x14e\rc\xac\x8e\x95m\x90\xd68\xa0\xf6%\x1d\x1e\xb2\xd6y<J\x1a]\x0f\xb5\xa3\xa9\x91\\\x01\xa6\xb9T\x02~J\x1c\xed\xa1\x14\xd6\xf8\x11\xad\xc0\x8a\x99\xb2%\xa4\x8bPb\\|\xe2\xf9\xa4\x1d9"\xcb\x89?-f\xbaQ0\xec\x92\x13H\xfcCv\xb2\x01\x9c\n:\xaak\xca\xb0;\xfd\xea\xb6N\n\xd5:\x97\xb7\x9eO+\xb1\t\xf6\x92J\x05M;\xe0x\xe3\x01\xa7\x86Qb]3\xb3\xdb\x96(\xa7ct5?\xfa\x7f\xf3~u89+\xb8\xf3\x9bS\xf1:x`\x8c\xa2q *\xf6\xef\xd3\'\xb5{\xe3}\xeb\xb5\xf5F\xde$L\xdd\xa0\xbb\xea\xd0\xd3ta\xe62<\xca \x1cF\\\xf7|\xbc\x88\xb8\xcb(\x11\xc6C\xc2\x7fI7\x90\xa0\xc0W\xfa:\x1b\xe8\x0b\x0e\xc6\xe9m\xe87\xb1\x1ff\xb9\x1e\xc6G\x0ft\xb4\n\xc0-\x9b\x1c\x03\r\x98(\xfa\x8aR\xe2.\x94\x9d\xd2\xe2\xe0\x90\xd7N\xa0\x8dh\r\x0b\xcc2P\xd4\x92\x1a\xd0\xa5\xda\x80\x9a\xb4\xadA\xdbD.\xf6\xb5\xa6\x81\xc7\x8eU\xe6T\x8cX\x97\x13\xc0-&aOSK\xfa\xf8\xeb\xebH\x15\xa7\x08\xec\x8a\x1b\xe4^U\xd8A\xc0\x8eVX\x81\xf0n~b\xa2\xfd\xbc\xa0b\x9c4F4\xcb\x05h\xb3J\xdc\x1b\x87\x1b\x9c\xf7A\xf2\x7fR\xca \x9a\x88\xbf\xa3?\x13\x06\x9b\x8c\x16\xe3\xea\x9f\x1a\xe0\xfd\xac\xa5\xdb\xb9\xc4\xae\xf5bB\xfc\xca.\xa5\x0f_\xeb\x82\xf6p\xcebm,\xbcf\x009\x00\x9c/w\xd2or~G@\x9a\xde\xc2\x8f\x92\xd4\xec\x85\xd2\xfe\xd1{N\x1b\xd0\x9e]b\xd8\xec\xb4\x8e\xf6[\xd9\xe4&\x1a\x8a\xb2<\xfb\x9b\x00\x03\x85,Y\xf9V\xcd\xf44\xf6y\x81{\xdeh\x11\xed\xc6n\xe5V\xefr\x15\xa69#r-\x17\xd3\x86m\xfd\xc3\xe9u\xceX4=\xd7<\x11\xaf\xd8tR\x03\x82m@I=yb\x0eGy\xe4\x8a\xb6\x82\xb6\x80\x91\xa5l\x9b\xf50\xad\xb1\x83\x8d\xfd\xadp\xc4\x80&s\xfa\x9e/e\x81\x9ak\x95\tl\xcb\xe7\x1f\x99\x11m\xe6\xe0\xb5\xb4\xd2A-O\r\xa9\xb3\xbb3\xe9n]\x84\xbb\xadf\x1de\xa6\xd6\xc8Q#11k\x03\xe8)\xfc\xa5c\xf2D\xb3-*\xfb\xb5\xcd\xc8.\xf3n@\xf4$r\xa6\xd8\xfc\x8c\'\xa8\xf6&\xd7\xd29\x87 \x1f&\r\xd4\n\xac\x02Uv\xdb\xe8\xdb>\x10\xb8nIy\xdeN\x00\xab\xe8\xe9\x15\x1dOO\xa2\x0e\xc2\xa4\xac\x88X/[\x07\x01e\xa7T@\xe2\xcbz)H\xe4\xad4\xd7\xb0\x0c;\x89\x97\x82\x83\x9f\x00\xd9W\x04&\xca\xd2\xac\xd5?*&\xcf\xec\xe9\x82\xc5\x0cnN\xd7\x8c\x9b+\\\xe1\xc5\xef\xce\x910#3\xa7,\x90\t\xefF1HvP\xf6W\xc5\xec=\xba\xbc\x17\xa5\xb5\x13\xe3\xfd\x81:\x95\xbb\x02\x84\x8d\xaes]\x04\x1d\xf5b\xbd\x0fa\x15=\x8c\xe3\x95\xe4\r=}\xafm\x18!&`\x87\xc0Y\x9cS%\xcb\x94\xd2\x92k:\xec\xc0\x12(\x1d\x08^?\x85\xf6Q\x9b~\x0c\xc6,\x91%(zh\xd4GD4\r\xa7\xe4\x9b\xb06\xc0\x9fc\xba\x96\xf1\xe6\x9bI\xf3\x0b\xe6\xe7\xc5\xfd_\xdc\x80A\xa9*\xc0\x9eF\xc3\xcf*\xe5\x8f\xbd*t\x03\t>\x1cG\xdb\xfd\xe1\x10of\xc4\x91\xb4\xfes,\x02X\xc2\xd0~\x824Z\x94\xc1)4\x01\xe7\xcf\x81t\x90\x155\xa8h \xaf\x9961..]t\xd6\xdc\xb2\x14\r\xdfx\x08\x06k\xab&\xac\x02\xfe\xf5(\xcd{+S9\xab\xd2\xcf\'M\x1fI\xe7\x086\xdf\xe4:n\xa2\xb5F\xe7.BS\xc5~,\x83_5\xd2\xed\x86\xa3\x1a\xf8zB]\x01\x84\xf8\xbc\x19\xdeK\x8f\xbc\xd2\xb4\xf7\x8d-G\xd9K\xcejq.+\xa3}\'\xb9lv\xfe\xaf0\xeeT\x11\x06~\xbb0\xe1\xc7\x850\xd3\x98\xd8\xf4x\xbd\x11<\xdc\xc6\xe2\x0b\x8d\x06F\x17\x80\xb0-\xba\x17g\x93\xb5\x17\\8\x1a\x9b>_`m\xd58\xadk\xa6\xa0\x9aa0\xd0b"\x0f\x07\xa2\xef\xf4#\x02\x80\xa0d{\x8f|\\\x01g\xfe\x1b\x1c\xec\xecl\x0eJ\xe4\xd7;\x0c\x859\xa06\x8bC\x84\xe9\xfd\xc0\xf8BWZ\xbdF\x7f_\xe2w\xc10\xdd3\x03\xb5a\xbe\x00\xb8$\xdf\xc4\x11-\xf2\xac-\x0c%\xd3\x8d\x90\xbf\x8a\xfe6\'\xc5\xdc\x99`\xd3\xb8\xb9\x0eT\xc0\xf0i\xda\x8d\xea[\xab\x16\x1dr\x97\x0eGAe\xb1s\x90Plz\xac\xa3v\x05V\xbb\xf4\xd63\xa7o\x91\xf9<vY\xc7\x827\xb0x\xfdm\r\xd7H\x8e\xab\x9e\xb7qQ\xda\x15q3\x0c\xae\xae\x9bA\xbe\xc9kE\xf7\xad5\xb2>1\x84\x9e[j\xca\xbe\xe6\x92\r\xd8\xc6\xa3C\x04n\xbd\xd4\xba_\x11\xe6\xafOR\x93\x07\x18\xdc\x0bH\xa7`[\xa0u=\xc2\xdf\xcb\x84}X\xcb\xc5N/-\xfd\xc71\xba>\x89\x95}%\x97. e,\xa1\xaa\xeaHI\x03\xb5\xfc\xd0\xc6\x8f}\xb3<\xcf\xc7?\x07\xaa\x9a?\xa7\x8c\xf4\xd4\xbe`\xa2O=\xfa\x00phz\xe6\xca\xf7\x12\x0b\ry\xf0\xeb\x93\xb1<\xc2\xa8\x1fq\x9c\xa2,\x1e\xdb\x9e\x96({-N\x85\']\xb5n\x90/-}zE\xf5\xf3\xf4\xdb}U\xa1\xfa\x84!\x047@\xe8\xfb\xee\xf8\x9d7\xd0\x92"\x98&\xe7\xee\x10\xf3\xbb\x8e\x87q\xcfMv%\xff[aY\xa8\xb56\xcb\x85\x8d]\x1cd\xa46&c%\x02\xe9\xa7r\xe1\xb8ZS\x96N5fF\xa0Xg\xd9i@F\xc4\x19\x1a\x1e\xf2\xa9\xef\xa3\xb6\x99\xfb\x8cohQ\xf5\xe2\x81^\xd8\xe0\xa2\x99\xdbR\xa4\xe7}\x8d+Z8\xc8\x89\xd2\xed\xe86\x90\xbaI\xdc\xc6\n\x86`|\xc1\xbfD\xa8\xe77\xbd\xfe\xa4\xbdf\x8b\xffX\x1a)v\xceM\x0eI\x07\xb5\x14\xee\'\x938\x17\xa2m$\xcc\x88Dh\x1bg\xc4b\x11_\xd26\xd4>\x1fp\x05\x05\x964\x9cV\xb0\xd9\x9c!\xf4\x05RHjxN\x05\xde\x00i\xe0\xe3\x10$Iv5\xe8\x0b\xcc((\x05Q"\x97\xb7\xa3)\x07\xa5\x18\x96w\x03E[\x97\xad\xa42\xd64\x84l\xb1!q\xe1\xcb\xef\xbcMLi_\x1b\x8a\xe8\xd2;\xe3xx\xb07\xef-\xf5j\xc3\xa9\xe8\xc8\x1f\x17\x02\xb9\xe8e\xa6\xbc^\x0b\xac\x80_\xc2\xa5\xbf\xfc\x8f\xed\xfe\xefY\x13\xfe\x85\xad:,\xbb\'\x14J\xf0\xbe\x87I\x17^Ob}\'O\x9dv\xde\xe8WDUp\xd6a\xa9\xc3gv \x8c\xc2\x8dm\x16\x86e\x16\xaf\xc5\xbb1(\xd7r5Vw5{\xcf49\xe4\x18\xae\xd9R6\xf1\xbd3\x1e\xcb+5\xff\xc9\xe3:dW\xf1M\x12\xb5\xb3\xa8\x0e^}\xd7\x92\xa9\xac\xc2\xb3\xf1\x11\xbem\xc9\xbaT\xf2\xd9\xafV(\xe8\x11\xba\xd9\x92\xd9\xdeb\x13\xdex\xff\x01\xe0\xd6\x83*K\x97\x15?kEn\xd60:\x0e\xe5\xfa\x9c\x8e\xf5\xb3\xc6IS\xbfw\xd7X\xdc\xfdG]}\x7f\xc7\x92\xec#\xa2\xe2_\xd70x\x95\x1c@\xc3\xd2"\xd97\x0f\xc1\x05w\xa3+s\x83\xd5\xd9\xae\x015\xb6\xf1\x1f\xf9\xee\xba\xbb\x1e\x98\xae\\\xba\xc6\xb8\xfe\xdd\xf7<yRd\xfc\x9d{\x99\x80,\xce(@\xe9\xbc\xfd\xd8\x8co\x12\xb92o(\xe3p\xb9\xfe&0$\xa6\x9c\x90\xad\x10B\x0f\xcf\xfb\xc9\x16nH\xea\xdbn9\x0f\x15\xff\xfb\x88\xbf\xffw\xc9\x9a\xbe?\xfck\x9e=\xee2\xf4\xee\xfc\x11N\xb4\xb5\xe182y\xe9S\x99\xd7\xe5\xaa\xa3]v\xe0\x1a\x83\xe0M:\x1cGe\x15Z~\x0f!vx\xc1\xf3\xcf\x9a)\x91\tZ\xb8*\xd2R\xf9\xd4K#%\xd5\x1a3\x06y\x92\xc58\x82_^\x01g\xce\x94 \x0b~H\xba\xaa\xd8n\xd1$8\xb1\x10\xfcZB\x0b"\x1a\xab\x81\x876\xf3(\x8a+\xafip\xa35\x91"#\xbe\xca\xff8".?l$\xebv\xbb\x06\x9d2\xe3P\xbf\x16;\x8c\x0b\x8b\x04\x8e\xd0\xd1\xa0\x9e\\\x93\x16\x99\x80\xd7\xb5\xdb\xc6\x89y\xc3\x9f\x8dm\xa8\xc8\xe1\xff\x90\x98axU?SU\x9a\xae5\xca\xce\xd5h\xa3?\xb7>IX@/\x908*\xa8\xaa\xf3\x83\xab\xfb`\x96^%&\xee\xf5f\xe1\xba9H\xcb9o\x92U\xcf\x17M=Q^^i\xdbC\xa1)Cv\xe9+k|x@\xbf|\x7f\xf3\t\x18O\xf6\x10\xf6\xe9LZ\xc2\x8f\xf9\'\xb9\xad\xc1\x8a\xb4S\xaf\xd7\xe5o#\x9c-\x13\xcd\xfd\xdc\xeb}^\xe8Re\x03\xd8\xe2\x10r\xe3\x1aK\x18\xd4\x14\x8f\xac\xb9\xc7\x8e\xc4C\x00\xa3\xc4\xfa47\x06nw}Ux\xc7\xa7{\xf2o2\x86.\x85F\xd0r\xfe\xe94\xa5h\xb3\x14S\xd3\\\xa8\x03f\xfcu\xe0#\xbe\xbb<\xdcM\xc0\x98\xf0\xf7\x0c\xbf\x15\x18b\xb2\xdaa\xe5\xed\xf5\x7f&\x08\xfa(\xcd\x89\xd2/Z\xad\x02\x8d\xdc\x91\x11\x9f\x14Fp\xed\xb8\x9chB\xad\xa2\xbdPVQJ\xe6\x02\xcc\xde\\\xf1\x18\x9d\x1a\xf5/\x13\xb6k\x85\xbe\x90\x05o\xc7\x96\x1aq\x92x\xe0\xd4\xb3!ul!H\xba\xf9\x0e\xf95}\x86\xd4\x13D/\'\xb5YB\x8f\n8\xca\x99N\x0ew\xe5\xcf\x9eJQ}WU@\x1b\x13\xf8\xab\xdc\xc2\xe0\x04>Q\xaa\xa4\xd1\x90\x08\x83t\xc4*>\xb7\x172/\'\xea\xf8]\x9b\tU\x9a\x14\xd0\xef\x1eR5k\xab\xb4\x85V\x14\xd37\x84\x92\x16\xae\xa8\xce\xb22\xc4\x91W\t\\\x8e\x9e/\xcae\xdbV\xfe\xde\x84Z\x07\x17\xba\xdfF\xdb\x83\xfe~\xcac\xadF2{al%\x99_/{\x9a\xf8\x13\xcanf\x9a&\xaf\xd8P]B\x12\x8fhb\xbb\xe9K@6@\xc8$\xe8\xd7w\x95\x98\xe40\xbaV\xf1\xbb\x9aIn1\x7f\xa0\x80q\x03\xf2\xcao^19\xd3\xcb)\xabp\xcf\xe6\x7f\xdf\xe7g\xd4<\xa7\x97:\rk\xae\x07\x9d\x9b\xba\x07;\r0\xda\xe8\xb0\xe3h\xd79l\xd8\xe6\xf6\x8b\xfeC\xb7-\xd2#\x82\x08\xfd\x03]q\xd5\xe2\xdb\xc1S\xaeYi\x15/\x83\x15\x7f\xbac\x0e\xceKf\x9f\xacvoA\x17\xa0vE\xf3\\\xbf\x91y!\x19r\x02\xab=L\xb0\x8c\xd1[G~\xa6]X\x06X\x9e\xachj\xd5\x0c\x03^\x1a#\x82\xc4\xe8C\x13\xbc\xf8\xdb>\xe8\x08\x96}Z\xb1\xaf\xa7x\xf2\x96\xe9`\xdeX\xcc\x856[D\xc7\x14\x97\xe4\xe2\xfa\x9eS\x1d<\xc2\x16\x8e\xf4:\xf3Y\xc2\xac\xe1\xe7+\xb0\x9e\xea3\xc6\x8d\x98V\xeb\r\x04\xcc0t\xb1\xb2\xd3\x1ai\x0b|\xc4-`KN\xf3\x98P\x94\xda[\x08@aH\xa3\xf9\x9c\x84\xd3[0y\xff\xd4O\x94\x9e\x08\xc6,\xcf>\x04\xc3/e\xdc\x08\xf8\xb2\xe2\xf6\xe9r\x18-\x1c\x18.\xbf\xbe\xae\xbd\x82KI\x9eA"\x82\xa3\x80\x04\xaa\x8a\x02\x9dh\x05\x97\xa6\x7fQ\x97\x9dQh\xa3\x02D%xf\x15U\xbcH\xf3\xb4\x8b\x1f\xc3A\x84g\xf3\xfa\x9d\xe1\x0bj#1zkN\xfec\xc1\xf64o\x94\xa80F\xcf\xd4\n\xb8\xa2\x82\xaa\x15l\xa9\x1f2\xfdP\x92\xcd\xc1\xb5(3T\xcf\xd3^3\xfb\x974\x1a\xab\xb77\x81]\xe2\x02A\x9f\xff\x16\xc1\xc5^\xf8\x80\x97\xba\xca\x9b\xda\x9b\'\xfb\x03i\x80\xf8\xf1\x8d\x03,<\xb7\xa5T!\xaaqg\xfd\xb2\xa5\xc9\xc5\xbe\'U\xe1X)\r\xdd\xbdw\xff\x16=\x17\xe1\xf6\xa11\xcb\xe7\xdd\xc8\x9bb\xe0v\x8e\x97\x91><-\xcd\xb4\xc6\xd8U\xcbvo\x13Jis\xd1T\xc2\xbb\xe9\xb3^\xf7\xf2b\xe9V\xff\xc6\x13e\xe7\xb0\x8bi#LY\xeb\x9bB(\xa5z`\xbbL\x93\x9dK@\xdayS\xe6\xa6\x8eR\xe0I"r\xfbl\x1d\x89xNS\x00\x84\xf5\xc0\xa5\xcc\xcf\xe2\xf1\x92\xe1\xb7\x0eH`=7G\xe5\x8c\x02\xe5\x8f~\xa6q\x9d\xac\xc1G\xe2&\x97,\xb15U71\xb2w\xf0\x98MSp\xf85\xb8`\xd5\x82\x8c\xd3b\xba\xbc\x8c\x1a\xa55\xd1\xb7\x13\x0b\xfb\xcc\x9d\xd9\xc0\xf5\x95\xc7Q\x97\xb4LH\x91g\x03\xe8P\x90\xa9ga\xb8>;\xea\x16\xb2.\xcd\xe8\x13\x89!\x9c\x1dDA\xc5\xc6U2\xdf\x0b\xda=\xd3\x92\xa2D\xfb\xaa\x0c\x93\x9dL\xf1}\xd9%d\x1dHL\xdd\xe9g\x11M\xfc6F\x06N\xa8r\xf6\xd1d\xacA\xb8}\xde\xd8(\xe4{\x9a?!\x11\x02\x0e=\xa8\xa6\xf9\x99\xdf\xb50\xb6!$1e2\x06V\xcdT\x8cy-+\xdb\x1d\x87_\xf8\xb9u\xe6X\xaa\x88=`$\x8a\xccy`(f\x14\xa7\xfb\xe0\x903\xc2\x8c\xf6\xfd\xe5>\x87\x972\x8a\x9ej7\xa2H*(\x97*\xb1\xf8\x9d\x1ae9oK\xa6\x89v\xea\xd8P\xa9\xb5\x8a\x03\xb8\x8d"E 2\x83\x11&Z\xc1\x963\xaf_\xf2\x181\xb4b>\x9fq\n#4\xabj^\xb9w\r\xa5\xd2L\x8ac}X\xf7\xac\xd4I\x96\x8f\xd7\xfb\x92\xa3\xb6`+\xd5Z\xe3\x0e}\x9fn\xcc\x85\x99\xca\x07\xe0\xa1L\x03xu\x1e\x10\x1d}\xe7)\xd1j\xa6\x9alQ\xc7T\xbe_"}@\x16\x0e\xd2,t!p\xdb\x82{:\x14}v`\x8c\x85\xa1\xec\xa5?TI\xd1\xf9\xca\x93:\xf3\xf1\xaf\x93]J\xad\xd6\x87A\xc0\x1b;\xfb=9(ZR\xd9p\xef\x86\x0e\x02\x1d\xa3e\x1c\r\xf40\x97\xa1\xd2\xdb\x0e\xc9\xdfnJ\x19\x83\x1e\xb7\x02!\x9a\xdatv6\x12\xa4\x042\x0e&_L\x93ZL\xdew\xe2"J\xb4[@\xae\xa7\x8c\xb0Kix\xb5\xbaIu!\x04\x01\xd2\xb9\xd7@]\x1c[\x9ap\x88\xd9\xac;\xd9\xed\xfd8$\x95[\x10Y\x08%t*8\xa4I\xca\x84Oy\xb3?d\xbe[\xda\xa4\xa0\xb3~\xf9NU4u\x81+\xef\x8a\xb1s\xec(\xffsj\xc7\xa5\x85.w\n\x96\xf5j\x9b\xe0\xb0\xb9\x18\x14\x8e!ES\xc5\xbf\xc8\xecq\x99K\x97-1,*\xf3?[\xd7\xdc\xc9xC[K\xe7\x9f\xc4\xcdI4=\xea\x9eT\xf6 h\x12\xab\x01\xea\xd2\xefi1\x8e\xf6BM&F\x94>\xd3\xf3\x95\xf4(\x97\x94n#P\x01#=\x97\x90?Y\x92@\xe6\xd77\xfb\x9fh\xa9\xbe\xbe\xb9\xddi\xdb:\xbd9\xe6l\x886\xf7k}\xd4\xa2\x1e\xa7\xd7Yix\x89I\xc1\x93\x97\xb5\xe1\xf5b\x8e#\x1f\x7f\xa6\x04\xed\xbe\xd0h~D\x97[\xb5\xe8\x02\xe2\x19NTo\xd2\x8e-w\x80\x01[g\x9e\xfb\xde{\x01\xd6O\xbc\xf6\x86X\x1b\xa1\xa61\xcbu\xe3\xa2\xad%\xb4\xf5\xf7\x15\xc6\x8f\xf1\xf1\x02\x95KQ$&\x98\x80\xc4p\x90\xce\xee\xf6S\xffe\xe7\xf1\xbeDf\xba\xbe\x91\x9e$v\xafM.\xf33jY\xb1\xf6\x84\xd9\xb3\x08\x97\xcb\xef\x9ed\r\xed\x8c\x7f\xdd\xf9\xd7&c_\xd8-\x1fG\x99\xcc\x18\x88\xd9\x18\x8acB\x99\x05\x84\xa9\x0b\xc7U\x88\x8f&\xd4M\x934J\x17\xc9?\x82H\x95\xa2\xc6\xd8$\xdb\xa4]\xad\xe13\xca\x02\x87\xc7j\x13\xfb\x87\'\xb8\xa8\xdcP\x10P8_\xd0/\xb2\x82\x87o\xd5o\x8c\x0c\xedr\xa9\xcf\x07\x8a\x91m\x85\x1d\xff\xa2\xaf\x02_\xf9|\xa96\xd9\xa3\xde\xb6\xad\x0e\x9d,\xa3\x86( \xd3\xc14\xa2\x9e\x11\xcb\xc0\xf3\xfb\xc9d[\x9dn\xa6R\xa9Y\xaf\x9f\xcehX\xc7??@\xf2\xc3\xe6\xb0\xac/\x0b\xb1\xb8\xd8\xbc\xad\x8b\x95K Iz\xf0\xe4\x04\xb8\xd0\x17\x03\x03\x01(YP\xa28\xabu\xb0UWa\xec\xad\xa8!\x96RI@\x1aS\x82p\'\x9c2n\x19\x01\xb9Z\xfe2:t*Y\xd7H\x85\xb9\x1d\xa8\xcf\x84\xbeh\xfe\xb3\x9d:\x7f;\xfd1Ep\x03\xe5\x92\x0ez\xa5\x02\xd23\x1e\x93F\x85\xc7\x88\x95T\xf54\x85\x1fq\xf1\x8da\x9fr\x99S\x7f\x06\xe1\xf2!\xa4O_6?\xad\xde\x12\xfe\xd9\x00]\xc4\xc8\xd3\n\x97\x7f\xf5\x0b\xe8\x8d\x8b\x8d\xa7\x97\xa9\x8a\x03<g=2\x1c\x82cf/EEl\xb8\xdc\x00I\xd0J\x02)\x1c\xa8\xa0/\x83\x19?\x94w\x17\xef\xcc\xbf\xe3#\xbdL0\xfb\xd7He\xd1\xcc\x94[\x05\xdfl\x100\xb82\xd1,<\xf1\xb6\xd8`\xc3%X\xf66\x0e\xb1_\xc1\xa2\xa6`\xd4u\xe8\x1cu\xe0\xc3&_\xe1\x13Ti\xbe:\x92)\r^\xf07lo/7q\xd5\xde\xaf\xbd{n\xb79\x90\xc4@\xa9>\xa6\xba\xfbU\x9e$\x87\xca\xf5?\xff\xefI\xe0\xa1\xb5Y\xabfJ\xf5ncTi\x87.\x85\xf4{\x0ek7\xac\xc6\xe1\xab\xba\xde\x8e\x01\xd2\xdf/{\xaf3:d\x99\xb5\xa9,\x86\xe3\xe7\xf9\x89\xb8=^$\xd4\x8bRz\x17\x03\x03@\x11\xb4d\x91\\\xc9$\xdd\x89\x80\x14\xa4\xe3\xcf\xed\xd5\xed?\xae\xb5k\xcapdK\xc4\xd2_\x95\x1b}\nl"\xef\xb4\x87\xdb\x1b\xdb@e\x96\xbc\xea\x93\x1a\xce\xe6;\x034\xd8\xf4\xf0\xb7\xdf\x0f0suN\x08\xcc\xa9\x13o\x9b0\x86\\\n\x93\xd8\xd2\xdb\x91,\xd2"o\x1b\xb1\xad\x9f\xe2\x96\x8e\xa9m\xd6\x19\xd7:?\x13\x8f\xb2\xb79W\xcb\xc7\x13\x9f\xe9 rX\x91\x1e\xf5\x81\x1d\xcb\xca\xaf\xf0\x88\xeb!\xde+\xbb\x01A\xda\x05\x0b\xe02\xcd\xa4{u\xad\xe5\x0b\xcf\xf1\xd6n\x16P\xa52\xd5R_\xc2G7\x11\xb6\x90\x07\xe7\x86\xe4\x96\xaaA\xd9\xcd\x08i\x19\xe8\x85v\xda\xc9\xd4\n\x01\xa0\x035\xa0\xc3\x1a\xc4\xb0\x83\xfb\xa9\xf6\xa7\xd9\x0f\xcc\x81hp\xd4\x17Q\x00\xf8\xf8sY\xe1S\x16+`\x1e\xb1F8\t7t\xe9\x1a\xba\x15\xcc\xf7\x1afY\x0b\xe4\xc4RJ\xf2\xe7;\xbdS\x90iO\x9a\xbc\x02;\xfc\xcc\xad\x94\xbc\xb2\xa4\xf0\x800.@\x88\xdc\xdb\x8c\x91\xfc\xd7\x7fT|\xdf|6l\xd5\x8c \xa8DVOz\xa8\x989a\x85\xdc\xc9\xe5L@xi\xd2\x81\xa6.\xc2>\x96>\x1c\xe6\x97"\xbe0:Y\xff\xd2\xcfZ{4\x85x\xaf\xe0\xc4"O\x16\xe8c\xdc\xb3\xb8\x11\xb7\x11\xee\x01F\xd8H\xba\x06\\._\x89\xb6\x96\xb5=\xbf\x08\x82\x1aw\x94T\xe9\n\xec\x8b\xb0U\xff\xcah\x0e\xfeK\xb3\xd5\xc6!\xf4*|\xeaK\xf0@\xa8\x05\xf0\xcf)/\x97\xf6\x7f\x99\xea\xf3R\x91\x14\x9c\x9e\r4Y\xfd\xd3\x16\x15|\xa8I\xd4=\'[\xc5\\\xcb\xe3{0\x1b\x88B\x0c\xc3^\xa9\x19\n;\xdb\x99&\x8f\x8eZ\xf0\r\xf7\x98v\xcen0+\xb2DF:\xf4\xa6\xe8\xfc\x8eTdp3\xb3\x18e\xac\xc2T\x109\xf7V\xc9I=\xe9\x88\xdfm\xec\x1b\r\x7f\xe0[#5\xfc?\xc1~\x00\x84\x83\x1cS4\x99"W\xcd\xc8\xf8\xf1eg\xe2:\x88\x16]%\x8a\r.\xa1\x90\xfc\xe3\xc93\x14\x10\xc4\x9e\xf9\x1d\xd5\xaa\xf9\x9dag\x97\xae~1\x81\xf7\xe5\x19l\x1c\x8d\xfeS\x95\xef\x9b+\x18\x0cD\xf0\x19\x05\x06T\xcaE\xa7\xb7LJVt\xa5a_#\xe3Q\x88\xe3\x06"\x05\x03\x88r\'\xfb\xab\xa84\xe8\xe5@\x1a]\xe0D\xdc\xbe\xdbE\xd0\xceT\xec\x8a\\\x12\x9e\x9b\xac\x7f\xces\xe7\x7f\xd8n\xa5/\xcbR\x1a\xdb~\xd3zf%Z&\xcd\xff\xb5\xc8\x98\xab\x9e7\xe6W\x1d)\x98Y\xb9!*&\xe6q{0\x90\xb3\xb18\x05\x8e\xe3\x064?I\xc2s\xbb\xd6\x8bEF\x1f\x19\x0e\xea\x85$%\xc8\xe5#\xb9\x81\xe5\xfb9xu\xcd\x97\xf4\xedS\xfd\xc6+iy\x97%\xd1r\xa4H\xd9j\x1a\xdf:-\x0b\xa9\xe8\xcd\x97\xa1\x85\xfc\xa4\xc7\x88\xe4\x81W\xb4\xa0j\xee\x13r\x04\xd9aa\xc3\xe1\x8f"\rz\x1e\\E\x1c\xd0 _S\x0cADP\xd7\xf7\xe0\x15\x08\xa8\xce\x8b\xafa\x1b\xef\x11p!\xc4I\x8d9\xfe.1O0\xdftw\x9a#\x81+\xacKN\xdd\xc4\xd0\x9b\x8d8f\xff\x9e\xe7\x05\xfbP[_\xbb\x16<D\x11\xcc\xda\xff\xda\x83\xda)\xad\xc2\x11\xdc\xc8\xd9\x1e\x01\xd9(\x04\x8aKJ\xc2\xac\x9d\x8d\xd4\xa4\xd5\x89l\'X}\xf8\x9c\x83*\xab #G\x90\xb7\x1d\x96\x02{\x82\x8e\xfa\x8fp?\x99\xe2+ov\xe8u\x96\xba6\x90d\xc2\x1d\xbc\xfa\xcfT~\x837\xf7\xd6\xe8\x19\x83\xc0>9o\xda\x9b)\xa9\x18\x1b2@hR\x01\xb3\xb4&:\xaf?\xed\xe7`\xc0\xc61\xed\xc9\xaa\xa2\'\x1f\xe7\xd7K0\xf9]*\xec\x08\xce\xbd\xd1\x00\x0b\x93>\x89\xa8\xed\xc2\x1e\x9fJ\xec\x7fe\x80\xf4\xcb\x03\xd4\xee\xdbW\xc3Nw\xb7t\x81"?P\xa6?\xe9\xadd6\xf6p\xdc%\x99\x97q\xbc\x12o%\x0b\xe1\xfa\xdc\xba\x8fM\x06\xc7\xfc\xd4\xeaF\xf0\xbbt\xc8N\x91P[\xbd\x1dC\xaa\xec\xb6]Ha\x12T;\xe3\x02\x1d\xf6\xc4|\xea"\x17&\x93(O\xf0\x13:K{#\xa8\xaft8\xe8\x9e\x0ei\x80@v\x88\x82\xce\xb6S\xcc\xd9\xee\xb1k\x90\xf5\xa4\xf9T\xb6\xf3T\xfc\xa7\x11\xd0\xf0>W\xc0h\x93\x10\xb6\xa4m\x9d\x04\x05)B\x1a\xaa\xc1a\xdd\xaalc!uwcy\xf0\n\xd1ysp\xad\xff\x1bpo\xa4:BoB\xa1\xdb\xbf\xb4\xc2\xcd\xca\x89Z\x0b\xea\xdd\xbe\xf23m\xc7\n\x1a:\xcc\xa1\xf7x5\xbf\xaa\x06\xf3\xac\x82\xb7\xa5\xc1\xec\xf9\x8c\xf8\xd86\xa5\x96a\x016\x07\xff ;%\xb5\xef\x93-\x9f\x954\xb4\x97n3\xd9\xbb\xfa\xab\xf1~\x19\xc9\xbd\xf69\xf95\x8a,J~\x98\x19\xcc, \xa3\xca\xb2=\xd0\xb8\x9e\xe2\xfb\x00\xd4\x8d\x89\xc4\xbf\xf2V\x0eZ\xa4L\x8a\xdc\xca0T\xe1\xa2D\xc5\xf4\xc8\x0cj\xf5;\xa6\xbc|\x1b\xe4\xc5\xb8\xfeH"\xb2\xca\x93\x9d\x1ek\xc7\x9f\xfc\nji4\xc6*\xe4\xd5\x84\xba\x86\xc7\xc5~\x92\x17\x1eyB\xa2E\xe37\xb9\xf1\x03,\xf7)v\x8c\xca\xf4\x05&\xe1=\x8f\xa8s\xaa\x9d\x90\xe0\x08\x87\xb3~,\x8c\xc6l<\xa0\x04\xcaI\x8a\xd9\xa0\xc3\x92\xc2! /[\xd1\xd1\x17"\x85\xc6W\x19z\xd3\xdb~V\xe4-\x97\xb2\xcb"\x8b\xe9\x93\x11\x98\x8a\x9e\x86@\x12\xaec\x0c\xbe\xe86\x07\xba~\x9a\xc3\x1c\xa7\x82;\x98\xf9>_(\xe6F\xb8vE\x1f\xd7LJ\xad\xc599n\x84\x01fA\x91*\xa8\xc9,&\x95\xa0\xaa\x1e\xd0\x80\xa0Rn\xf3>|\xdb\xda\x91\xe6`\xe3\xf0=\xebh\x15Q\x8f\xd6m6\xbb\xbc&\x90\x95<\xee\xcf\xaeE\xd8\xacP\xde\xb5\xc4_j\x0f\x84\xbe!4t[$\x9b\xe9\x9b\x08\xb8\xc7\x02\xe8\xaab\x13!\x1f\x9c\r\x18M\xc06\xfc\xd9}\x0f#t\xd5\x8a\x87\xf3\x97\x9fK^O\xd4\x05\xf3K\xfa\xa2\x90sz\xeb\x0f\xd5\xd0\xd4\x05+W]\x1e\x12\xc9:\x91;u\r7nH,\xa3\xefh\x14\xcbf.\xact<K\xfb\x94\xad\x04v\xbb\x99\xbbj\xd1\\\x03T\xecL1\xc9\xf1\xb0\n\x7f\'186aW\xcf\xef\x8f\x9a\xc2\xda-N\x1b\x133\xe5\xaf]\xd1YZ\xe9\x1aL\xb1_\x8f\x82\xdf\tu3\xab\xfa\xb4$\xf8M\x04?B\xa2r0\x14\xa0\xbb\xe9@{\x9a\xf1\x8a\n\x04\xe9\xf5\xac\xa2\r\\\x8a0\x82\x98\xd70\x97Y\xf3\x88h.\xe87;\x03\x1a\xb1W\xf4\xcc\x9c,{D\xef\xff\x04\xe8\tF9pq\x87\x0b\t\xf2\x8e\xc2\xa6\xe1\xcd\xe6/)\xe6\xcc\xa85\x02n\xbe<\x99\xdf\x97H\x8e\xd5T;\x1bf\xb9\xfe\xe4o\x9b0V\xe3)\xbe+0\n\xed@\xb3w\x04\x03*\xd7\xaap\xeeU\xb8\x8eEv\x07|\x96\xef\x89\xaf8:,\x13X\xadM\x02+\x03\xd64F\xa5\x84\xd9\xdf\xc3\xb5\x11\xd4\r4\xab\xa0\xb8\xe1wn\x1d\x1bD=\xd3\xdaI!k]k\x1b\x91\xe6j\xbb\xdf\x8b\x992\x05J%\xafye\xf3\xf4\xde\x85\x99 \xe8\xde\'>\xdb,\xe3S\x03\x83\xd2\xc2;\xbc\x80\x01\xddQ\xc3\x92\x8bSL\xb9!\x89+(\xe9\xe6\xa11o\xd3q@\x167\xeb\x11\xb2k\xc4\x13f\\\xacq\x1a\xd3\xab&2\xa2\xeb1\xce\xba\xdcM]\x9d\xdc\xd2M\x16\xb0R\t\xeeMo\x96\x9e\xbfK,+\xd5\x13\xa8\x8c\xca\xf0\x95%\t*\x8f\xbb^\xde\xd9!\xa3b\xcb#\x99LkU\x7ful\xa5r\xd69\x88\x1bP\xee5^\x1a`\x18\xba[\x1e\xdd7\xb0\x07\x84G\xdc\xf7At\xea]J\xa7o\x0fldM\x8f\xba\xe7\xe7aP\xa9\x1d\xb4+\x0eXV\xc5\xf0\x8cp\xd8J\xf6\xd0\xaf\x04\x02\x1e,\x97\xed\xd5Y \\\x82\xef`vU\xe7\xd3\x1b\xb2C\xbc\xb1\x16O\x98!P\n\x1eY\xb7&\xa9\x03\x02\xddkc\x15\xae\x11\x19\x87\xf7\xcc\xac|k\xf6\xe8\xfa|\xc2\x11\xe6*\xe6e\x10W\xc9}\x83\x10f\x80\xad\x17\x96n\x8ep\x9b\xf7\xfe7\xdd\xc0)\xdc\'\xa4 %\xc8\x1as@'
|
|
|
|
|
|
2024-12-14 17:54:48.358661 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25568
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808854989
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.363245 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 827
|
|
id = 30920
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 807
|
|
chksum = 0xc8be
|
|
###[ Raw ]###
|
|
load = b'Z\xea\xa4\xfd\xe9\x04\xea\xaf`\xce\xce.0\xe0\xa3e\x11\xd7`E\x13\xba*\xe7\x11\xa0T\xebF\x1b}\xd5\\j\xe2p\xc4\xf2*\x15g\x92\x01v\x95G\x18\xe2\xae4^h+\x93\x7fO\xf5\x88\n\xea\xfc\x7f\xd8\x95W!\xea\xd3\xab\x87V{\x0c\xa0G\x9e\x8b\xddyx\x0c46\xa5\xc5t\xc9F\xc1\xa8\xc6\x8f\xbc\x9c\x8c\xd3f\n\x94\x9bw\xd2!\x95Aa\x1b\x1c\x9eAS9\xc4\x9aJ\xe6_\xb5\x86*%\xfcO\xde\x89\x89\x05\xd9;\xdf{To\xaf\x85\x19#\xf5w\x11\xab\xa0\x00\x8ec\xc0[=\x90\xa6\x06\xb8\x80\xb5\xae-k\xb2J\x10\xca3\xca\x9cK\x99\xd9\xb7\x9b9Al\x1f\xad\x08_)\x07J\x9b\x04l\x1bE\xec8{\xd8\xf2\x96T\xda\x90K\xa1\xa7\x06\xb7\xf8-\xee\xb6\xf6\xe6\xf7\x8e\xbc\xe4\x12\xf8 \xfe>\xc5\xca\x1e\xa3a<\x91\x05!\xb5\x00\xe7]p\x97X\xda\xe7\xea\xf1.\x05"b\x1c}\x86\x0e\xd8\xa3\xceD*=az\xc5t\x0b\x98\x93\xf2\x14\xe7p\\OM\xe8\xec)\x90\x1b0\xf1\x05\x19\xe7\x8cI\x84\xfc\xee\x9fx$O\xdbBw\xee\x7f\xba\x1c\x83\xa2\xe4\xf3\xa9\xa9Z\x0e8r\xa9\xd0\xc9\x9e\x1b:}5d\xcd\xc8~\x907\n\x01`\x08\xee\x05\xd6<H<\xba>\xb2\xde\xf1\x99\x8c\x083\x93\xfds\x01\xc2VD\x04\xbf+\x8bWQ\xd5\xaci6\xf5P@\xdb\xa3\x13\x95g\\N\x18\xd8Z\xf0\xf8\xf5_\xdd\xcb\xd2\x1c\xb4f\x9b3},)o\xa8\xf6g\xd7\x99X\xc1\x04T\\\xcb\xd0\xdax6\xc3\x8a\x89\xd3\xe7"\xefH\xadc\xbdJ\xbd\xbc\xaa*\x89\x17\n\xba\xc4\x8e)\xafS\x98Vn\x06\xdaTjlq\x8b"\xc3N\x06w\x8c\x9d\xf8\xc7\x02x\x1f\x98p\xd0\xfe\x84\x9e?\x08\x7f8\xd7-\xd5fd\x1f\x08t\x11\x87\xdf\xc7\xcdkv\xc7[:\xaeJOf\xaf\xe2RQ\x03\x9f\xbd\xe3\x8d&\xc5\xe90\x12D\xc6\x0b\xe2\xb2W\xe9\x13S\xa6\x80i\x1f\xcb\x1f\x81\xc2\xdaX0\xa7\xcd\xbe\xde\x80J\x02\x9f\x11 \xb3\xf8?\xb16\xfe\x96\x99\x96~\xb6Y\x8ey\x18Z\xb9\xf4\xeav\x0c|6\x15\xff_\xe4\xb6\x99z\xd3B\xb1\xb0\x8d\xbci\xf3\x14<:M\xd2\xde\xb3\xc4\x14\xbekF\x0c\xc0\x18\x0f:$E\xc3\xa7\xc0j\xfc\n\xc9\xc8\xde\xa2\xdf"\x95\xfbQ\x0bJz5;m\x17\xcd\xa9\xf1.\xf2p=N4\xa4\xf3Kq\xc8z\xc2c\x98.\xbb:\x91\x9bh\x8f\xc5E\xf9\xc9\xf1\xc5\xdd4\x9d1x-\xdd\x90\xf8\x16\x8e\x94/i\xf5\xc9B\x05\\e&\xa5\xe6g\xb4\xc8\x84M\xe8\xd2\xfd\xc5\xe2\xb3j\x05\xaa\x88\x8e7\xe9\xda\x87V\xf44\xca$ \x86\x12^\xdd\x81H\x8f\xaa\xb2\xde\xb48\xb60\xcb!A\xaf\xd2\x9f\x91\xc0r\x03xgU\xf7\xe3\x01\xf7\xcc\xb5?\x0e\x81@j\t\xb4\x88\xd6\xaa@\x0e\xfb8\xa0\x9f3\xd5p\xaf4ON\xf2\xae\x82l\x07;\x84P>3y-\xb7\xa4\'\xb7\x9f\xca\x9eP{DU\xde\xcav4\xb0T\xdb\\\x91\xb2\x8a\xc4Q\x94\x8f\xd1\xf1\x96\x90\x97[\x94\xc2\xf9\xb9\\\xd1RH\xdf\xa3Mb\x9buW\x03Y>\x98\x1d"x\x93t\xe6\x0c'
|
|
|
|
|
|
2024-12-14 17:54:48.365731 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25569
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808863749
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.380860 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 11720
|
|
id = 47951
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xde97
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808863749
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x9eP\xf2\x12/\xf7[\x98\x0eI\xb0;\x16`\x8a2\xb2=\xd4\xc3\x1a\xc9\x973\x89\xcd\xca.7\xb2<l"\xad0\xda\xb0\xc4se\x00t\xc3\x98\xd6\x85WQ\xa6\xd5\xd9\x97^Jg\xc0\xc0\xcb \x8a\xb7\xe7\xca\x9c\xd8K\x89A>\x8c\xbbX\x1f[<\x94X\xc0\xd1\xae\xbb\x12\x83\x84HR\x97\xe9a\x05\x08qc0\xa9\x93\x87\x9e\xee\x1fOe\x83\x17\x00U\x89\x92@8e\x93?\x1b{\xab\x94\xdf\xdb\x98`\xad\xf0-W\xe0\xbb\x04\xf0\x1e\x051_\x86\x99O]1Z%H\xd6\x98\xba\xaa)\xed\xe64%\xf2\xcf\x8b\xec\x07K\x021\xb3X\x9c\x97]4\xdd" \x86\xf2q\x86\xfc\x0f\xe2\xf0\xc1\x97\x85!\x0b.F\xdc\xa6\xb2<\xd5=h\xb6\xabs\xb0\xac-U\x0f\xb1\x92e9FA\xceoi\xa8\x81u\xc7\x8a\xfa83\xdf\xbd%3\x87c2\xb2\xa2\xbf>=\xd2\x19 !\xb3\xa3\x81\xf8\x80\xecD\xe4N/\xf6\x03\x87\x0b\xc8\xd9\xe3\\v\x1b0\x97yxJW3\xdeO\xeeo\xae\xb4\x80!\x8cmDo\x0fT\x8e\xfd\x19;9\xf6cl@\xdc\xe2?\xe2\xbd@7g\xa6\x17\xca\x90\xd4\x8c\x86\xa2=0t\x9a\xf0h@\x9dDZ\x90\xd6\xfb\xaeB_q\x83\x0f\xe4\xe9\x924\x9c\x1c\x02CW;\xec\xc1!\xb2\xa9\xb0\xb4P\xa3:\xafHF\x9b\xb0T\xcbt\x7fY42\x97\xa1i\x88\xcfu\x82\n~s\xc1=3\xfc.q\x8ax\xa4\x08\xaa\xb9\xfdV\xeaZs\x18\xb7 \xd1\xe3\xd9\x90\xd01)\x19\xe4\xf8l\x1c\xed1_\x89\x15\xda\x98a\x15\x9d\x85\xf3G\x05\xbc\xc5\xfehA\x80\xd8\xc6\xaf\x93\xea\x02\x82I\x1e3\xd2f5\xa7L\\\x9d\x1c+\xb17\x91p\x87\xe38\x08r>\xa0\xda\xde\x10\xbd`\xbd\xd5\xeb\xcb\xb8\xa2\xdfJ\x1e\xc64\xa3\xae4o\x9c\xdb]#\xa3Z5M\x14\xcfC\x01+\xd1\x93\x83\xad\xc3Y\xc7\x00U\xfe{\xff\xf1p<\xb9#O\xf4\xa1\xc7L\xad*\x0b\xd6}l\x94NU\xb1\xfc\x0b\xc2\xe4\x82\x91z\x1b\x1eQ\x0b\x07\x1en\x86Z/\xfe5\xf5\x17ab\xc5~1\x0b\x1c(\xe6\xa4\xd8\x82\x16\xba\xd5sQ\xdb\xa8P\xc4|\xd8\x9a>C\x91\xa5\xcfq\xe8\xd6\xdd\xe7\xa6\x19\xaa|\x901S\xd2M\xd6%I\xf6P\x9c\xb4%L\xb6Gq\x98\x15\x9f\xae\n\x06\xce\xa1\xd4\x98\x7fC\x89\xf9dp\x98\xdbBki\xec\x08\x17g\xd9\xed\x12\x92\x0bV\xfa\xcd\xf7w\x04\x1c\xf0K]\xf0\xbf\xe3\xc16\xf6\x0ch\\\x7f\xfa\xa7\x99\x99\xc4zCy\xd1\xad\xf6\xe1x\x8c\x00\xe6\x82p\x817s\xae\x84\'\xf7uw\xe9\x9d\xe7\xcd\xd3\x10\x8f8\xad\xd2$\xf5\x19\x11\xc3\xe9,\xa9\x80V\x9a\xb5\x16~@\x14D\xee\x1e\xa2\xd5\xa7\xa7M[\xe3\xe7\xe3`\xc4\x80\xe6\x1cQ\x993F\xf9\xfe\x10\'\xdc/L\xaa\xe1N\x88\x05\xdeY5\xabV\xdb\xefo?kE\x97~jq-U\x01\xc11\xe5\x08\x1a\x89\xc2S\xd6\xde\xdew\x0b\x1e\xe8\xac#g\xa4\xd0\x0e\x19\xd6\xb8\x1f\xb7\xb2\x81\xe91\xa4&\xd7#\xd3\x8fG1\xc2\x80\x07\xe8\xb1)\x83\x15\xf5M\xfb\x90I3\xb0\x9a*\xac\xdc\x90X\x00\x8b\x9f\xd9\x1cv\xdf\x0e\x85\xf1\x1b\xf9\xbb \xabUz\xa9\xf7\xc3\x83\x0f\xa8\xa5>7cL\xaf;\x86f\x1a\xc2$\x0c\x86\x89\xe0\'\x17@\xd3\x8a\xeaa\xe7\xb8\xc5NNL\xce\xbbLE\xb9\x8a\xab\xfcvY\xf8\xb1dT;\xfa6\xae\x82q\x90)\xe1\x89\xd3\xb0\xea\x11\xccd_:n(\xce\x05\xdd#\xd1\xe9\xb8\xd0\x18WI\xec\xb5\x12\xc2\x82\x11c\xe4\xbbB\xe4]\xd5J\xd8\x99\xd6\x8c\xa1\xa3`T\x0e\xe4\x1d\x1a*\xb9\x00\xde\xb7,\xd4@\xec\xf6\xce\x16\x0f\xd0\xccY\xed\xcd5\x9b\x06\xb4\xa4\xc0\xe7\xdc\x8aJ/T\xe2\xeb\xddW8Fj\xfd\xeb\x17s\xc9\xf2W\xd7\xda\xf3\xb53\xf0\x97\xef\xe6\xb5c\x17~\x13oX\xb7\x19\r\xb5\x82.\x01\xdf\xac\x17\x0by\xcb\xc7/\x8bF\xc9\xfe\xbd\x7f!\xd6@\xd4iUR\xa2V\xaa\x9a\xe9b1\xf9\xfc\xa6\xce{;\xc2\x08\x85\xad5\xab\x0e\x0cP\xbd\xcc\x7f|dC\x8d\xce\x81\xdcl\xf1>\xdeF\x8eB\xbd`s\xd7\x1b&:1\x05\x19\x1fS\xb5Tq\xde\xec\x98`y\xfa)\xed\xf7%\xf0v\xad3J\xcc7#\x12\x9a\xd8J\xfb\xd8\xc6s\xd3j\xc1{\xb3\'\xa1\x95F\xaczy\xbc\xd3\xdc\xf4%\xd6\xe9\x12"\x16\x99\xe6/X\xb5\xac\x95G\xce\xd5\xfb_=`\x0cA\x01\xc9\x15\x9c\xf1\xfa,\xdf\xc2[\xea,3\xe3\xa1\xf9\x95\xc5\xfb\xeb+\xa9\x83\xa3\xb8\xe7\xdc\x9a5\x89S\xa2J\x1a\x87\x9dv\xc9s:U\x8cUD\xc7L\x94\xf7\x10\x05\x8d\x85K\x9e\xf9\x10E\x9e\xa2~;\x9e\xc5\x9er\xf18U;\x0f\x92B.\x7f\x90\xa3\xe5\xa0\x0bt\xddZ\x87rO\x01\x89\x00\x99C\x1a(\'ZK\xbc\xf1r\x15,B\xc26x\xa1z\xdc\xac\xef\xa2\xac\x8c\xb4\xe4\xfbB\xb8\xf6S{cZ\x97\xec\xcd\xcfs\x9b\n\x99\x1a\x8e\x9d\xe6v\xf6Rw\x8f\x7f/7\x164\x82(4\xd1>\x15\xd6\xef>[\xe2{|c\x16\x93\x9c\x02\x82\xff\x17\x15"\xb2\x7f\x07\xc4\xec\x17"\xca5\x9b\x00\x8c\xf0\x96"\x9f\xf7\x14\xc4\x86<\xed\x98P\xe1N\x00\xb3\xee\xc3\xe0\x9a\xa3P#L\xfc\x8ekr\xfd\x8a\x98Wjkpm\xbbJ\x082\x7f#\xae\x15\xc3\xc8\x08\\\xcdDc\xf3\xb7\xa5.(\x847\x07\x05\xfc\xa4\xefr\xb2\x1d\xf8\x1a\xd4\xf3\x08\\r\xa3\x06\xf0\x91\xa4\x1a\x80c\x94?;a\x8f\x80e\x0f}\xc4\xe0\x8f\x01p)\x97\xe5"\x16fQ5hm\xce\xd5M\xb3\xebk\x90#Q=\x95\xb7\xc0\x00\x05p\x7f\xe0\x86\xc0$1\xcb\xc2{h#{\xd8}\xdb\xc59\xca\x98\xbb\xf9\xe7|\xc1\xeb\x9e\x97\n\x12\xf0\x14\nw\x96\xcbp+\xe0\x11\xff9\xc4\rJ\xef\t\x86\xe1\xd9j\xa0j\xa6\x05\x9a\xf0\xe0\x89\x10\xe1\x14\xe0\xbd.\x01w\x89\xc7\xd6B4,\xc2\t\x08\xaf\x08\xc7\x11\xf2\x19f\xc4\xf0tVsIQ\x9a\x9d\xad\xe2\x1e#!\xcd\x18\xb52\xf2-d\xafO\x99\xa0\x16$\xd9\xe4Y@\x8e\xcef\x0e\xd4\xbeO\x98\xe4k\xbc\x81\x00\xa0%F\x92E\'\xf9N\xa5|yE\xd2Xv\xba3\x90\xc8E\xa1\x94\xbaM\xa5\x01\x10-\xa4{%\xcc\xa2\x8fe\xce\xff\x9b\x93\x01&\x86\x19g\x87\xbe\xa0\xaa9\xbc\xfaC\x8a\xe2\xcc>m\x9fS\x00\xd1p\xf1nI/^;O,\xadt\xb0\x1d\xa6\xa6Oc\xad\xe1\xee\x93yF\xfa\xf6\x98\xc1\xba,\'\x90Z\x81\xf4\x94|<\xa7\xea\xe5i \xa7\xe7<\x07\xb1\x17I\x08Wh\x12h\xcf^\xfd I\\\xab\xfa\xd9\x9b|\\dF\x8e.E\xe1\x85\xd1b\xa8\xca\x94\xa5\x16Yl\xf1\x8f\xf1"H\xb8\xe6\x06\x01\xa2{\x1c+\xf6\xff\x13\xear\xc1J\xfd\x91sl\xcd\xa8\xac\xa6Jy\xf0\x8c\xd94\xc4~\xa5Ml\xf0\xc0\xebo\xc7\xc0\x87b\x88\x1de{Y\xb6\xbc\r\x87\xaf\xfe\xb3"\x93\xcf\x85\xee\xec+\xcbS\x14V\x18N1;\xa7n\x1d3\x07\xb5\x80|?\x90\x0f\xe3B\x82m\xd7uG\x0e\xf3Z\xda\xfc\x0c\x1dT\xf8\x05\xacy~\x04l\xaf\xbd\xb8>\x1c\t\xb8\xa0\x06*Vr9\xe0\x17\r\x00=\x8c\x8dP]i!p2k\xad\x94t\xf49\xe8\x15\xccf\xf8Y\xb1X\x02V\xd7\xb4\x00U\xa1\xc6\xcdU\xea\xbaS\x9e\x82\x85\xe2\xdcx\x1cx.\xfb1\x04,\xc0\x1e"TB\xbb\xf1Q\xe8|}\xe9-\xc5D\xa5\x0f\x07\xf9K\xfcB\x89\xbf\xe8M5\xf1w#\xcc\xe7\xf56\xcd\x7f\x07\xc9\xe0\xa8\xa1\x99\x9f\xd3\xfc5\xbdG\x9e\xe9\x13m\xc3\x08\x83 \xb7\xa8\x98\x82\xec$\x15\x10\xdc\xc2.\xac\x036\x19\x90\xf4\xf3\x7f\xba_\xad\xd6\xac\xa9\xab\xb0\xefR\xb4\x88\xa0+\x80\xf4N\xbcsv\xdd\xb0\xfb\xc6f\xf8f\xbeu\xba\x91\xb8\x86zg_\xcb[\x00\rb\xb4Q\x1b\x14\x08\x95\'\xcb\xec\xdf\xc9\xdc\xb7\xc1\xf2@\xdb|\xfd\xe1\x9d\xe7\xeeY\xe7Goj\x8a[\xa2\xba\x14\xba"m\xb0\xf5\xda\xb8\xea\xc3\x82\x1f\xce\xc3u\xfe\xe9\x8f\xc0r\xf5\x842v\xa2\xcc\x96.\x99\xc6\x9fKu\xeb\x98\x11\xfbT\xc6\x8c\x01?g\xac\x0b\xa4!\x9d\xd3.\xaemEH\xe7y\x87\xcc\x95^\xa4\xfe\xff\xe1\xe5\x00\x9c\xb9\xf6\x14\x9c4U\x7f\x8bwi\xab\x8c\xa0\x97\xe0\xa1`L;]\xe8Z\x1b\x1d\x14\x0e\xa2IO\xe6\xb8V?Dj\xb5[\x94\xd4\xc5\xf7u\xd3\x91\x9e\x0ea\xcet\xde\x03;[\x93\xb6\xa4\xdaG\xd0\xd6\x92g\x19\x93\x897\x96\\\xa8\xd3\xb1d\xd5\xd4s\xa7W\xb5\xd8\x0e\rK\xbd\xd6\x9a\x1e\x87\x8f>\xd1\xfc\x0fv\x01Lz3e\x80CXR(\xd1\xd8\xdd\x8d\xa9\xf5f(@q\xe2M4j\x886\xe8\xab\x9c\xec\x19\xb9\x99\xfa\x1c\xf2v\xb7\xd2\x12\xbeh\xe8\x8d\xe6\xddue{\'\xee\x80\x0bR\xdb\x0e\xe3\x15)\xf6\xee\xad\xf1\xa7ed\xf5G\xd3\xb3C4uBx\xf7\xb3\xeb\xb8\xd8Mu\xeb\xfb\xc0([\xd9\xc97\xa0\x98\xfa\xc9*\xb2\xa1Rb\xa9mt\xf4YO\xe6\x1e\xdaU\x07ly)\x96\xb3\xa3M%vq\x1an*c_\xb8\x15A\x1b\x15\xe0\x95U\xbd\x1eO\xda\xee\xfc\x1b\x18c\x19\x80?o\xb8\xe7!T:q\xeduV<\xdcLY:\xdc7\x80\xd5D\xd27a\xf9p\x8d\x1a\xc9\x93\xcb\xebV6\x1f\x8a\x95\xc2\xf1*\xc1?\xc9\xc1M<\xd7G\xb8\x99\x8c\x04\x97\xa4\xe3%.\x179^\xad*\xd2yH\xd7\x89\xc6\xaf;\xb9\xab\xc6\xd61Tg\xeb\xae2\x9f,2\xa7\x12\x9eNQ\x8d\x07Ij?\xbe\x99\xd2\x0bE\x07\x11y\xbd\xcf\'\x9bD\xb2[/=\xbd\x1c\xb4\x91|\xf5\xccT\x13\x8d\xc6\x7f\x95G\x0eg\x1f\x06\xee\xd8\xdeg\x16\x89\xd7\xca\xcb\xc2\x9fl\xaf\xfff\x8d\xf0\xe6V\xde\x93&|a\xe00\x99-\xe1\x18\x1b(\x1a\xc6un?\x9byjQ\'\xfb\xc9\x18\x8f\xe1\xd9c\xe7\x8c!4\x87\xac\xd7c<X\xeb\xed\x11\xebOh\xfe\x9f#\x04k2\x14$k4]\x18\x941q>\xb8\x1e\x00\xdb\x84>\x91\x8d\xf9y\xcd\x92I\xb7\xd0\xadXVy;\t\x85\xe4\xe1V\xe2\x94\x8b\xf1SW\xb0\xbd\x80+J\\\x89e\xf5\x8f:F\xe3\x03sE\xd8\x88(\xb4\xa1\x97\xcd\x07\xcc\x1f\x10F\xacA\x1f\x13{\x08\xb0\x1d\x85\r\xb9xa\x08\xe2\x8f\x88\x90e\xdc\x91a%\x0e^\x1e~\xb5\xe6\xb2\x81\x833h\xf84%WWEP\x03\x85\xf9\xccP1;\xe5\xd5\xca$+\x9f\xb9$\xa7\xfa\x02H\x84\x87\x8e+\xb2U\xeb5s\xf7DC4\x8a\xb9x\x9b\xca\xed\xdd\xa6\x909\xa4\xfa\x18\xf9ky\x140E!\xfa8N\xd4\x83\x94\xc1\x8d\x9aXa\x13\x97\xc3W&\n3\xccb\x8d\xe3\xfbJJ\xf1\xfa\x90p\x9cC\xbf\xe7-8w]\x8c\xaa\xb6\x93L\xef\x83\xcb\x17\x90\xff\x0b\xd4\xc2\x9d\x1a\x0f\xb8\x10\x068m\x90\xd4\xb2\xec\xb2\x0c\xa2\x9eW}\x1f\xddM\xc6n\xe1\x9a5V\xb4Q\xe2\xe4r\xad\xa847\x02@\xaa\xd8C\xcaP\'\x06\x10s\xbeC\xebgzn\xd7q4\x11\xc7\x15"H=o\x15D\x10t.quiC\xe1\xf2\x0c_\xd2\x14\xd6\xc3\'b\xa7\x01B%\xffXc%\x0e\xac\xfe\x18t\xcf\x98\x180\xa3\x1c(\xc4s\x86T\xe9\xa6\xd7k#7\x9d\xe5\xb6\xe4+r\xfb\x8db\xc6\x12_j\\\x13\x1c\xf01\xdea\x96a!\xcfN\xbf\xafP\xb7/<\xab\xe0\xfackJz\x02\xcaF\xb4\xd8\'.\xec~\x17\xc2\xc3\xdc\\\x19\x03\xce\xbb\xa5a\x86\x1c\xec0\x1fc\xff\xe3M\xbb>\xb8\xda\x98\x99=D\x15Ni\x1f\xfd\x1f\x98~\xb4\xa8\xf0\x1a\xd36\xf95q\xb5\xbe\xebuu\xa7\xccK\xe8:\xbfK\xe5\xf7n\xf4\x14\x11\x1f\x08\xbf\x8c\x85\xaf\xcf\xf4m\xbbL\xb7\xbeB\xb0+YAK\xce\xbbB\xa9\xe3\n\x832\t\xeeW\x89\xc4T\x95[\xf7_\xb3\x05\xcd\xf2.xp\x15=\xa2z\x81\xee\xe0\x97\xdd\x96\xa5\x80\x83\x8f\xbdH&\xab\x97\xf79\xe8\xeb\r2u\x85\xac\x9ae\x96H\xc4G\xb1P\x92\x03\x8b\x0bk\xd3\x1d\xfa\xdf\xad\xdfnn6\x9c#\xae\x95\xd7\x00\x01!\xb1\x1c\xad\xb0w=P)\x87\xa4\x82\xa3$\x15\x17\x83]\x0b\xe8R\xae\xe2g\x02\xc3\xd0\xc5&\x8dU\t\xa6\x07\x06\x1b\xf8\x91o+H\xdb\xfd\xe8\x1d\xc1\xe0)\x97\x89\xc1t\xad\x18\xc3\x1f\x83\xfa\xb5I\xffR\x91\xdd>\xf6\x99"\xd1kD\xaf\xc8^|\xf5/\x15\xa6\xbe/\xdb\x19C\x07\xae\xad\xcb\xbc\xa6l\xe1\xbeZ9jh\xd38\x1a\xcf\xac\x9b3\x9cg:b"\xde\x8d_c\xee\xc4\x06,\xd94\x01\xa2\xd1\xaf\x14\xb6Xy\x04\xa1\xbd9{$\x94\xe1\xb3\x1f\xcb"K\x94\x1f8\x85\xb7\xf7s\xa48!s\xfc\xdd\x1c2\x1fKpa\xda\xeb\x81\x9c\x94\xcc\x13\xf3\x8c+\x07\xde\x18%\xb1x\xa4\x1a\xbe\xe7\x0c\x81\x86x4\x9d\xca\xeb\x05\x1aJ\x91g-,\x08\xa1jE\xca\xc8\x99cB@\xd9\x1d\xb2E\xd8E\xdb\xe7\xec\x81A\x85\xa0\x86\xc5\xd1Y\xbeg\n\xa3{k\xf6\x05\tC@S^P[*\x04_E\x96j\xf5U[!\xe7\xd0r\x84?\xd2TU9\xb8\n\xcb\x1d\xca3\x0euw\xbb\xc0\xc5\xcc\xbc\x95\x91R\xe7\xfbN\x04\xb7\xad\x9a\xcf\xb5\xd8\x9fk\xe1i\xe7a\x9a\xe3\nb\xe2\x0bw%\x8c\xec\x1f\x19[\xbc\x0cY\xfa\x808\xb1nT\xdd+\x93\xe5\xfeF\x89\xe9\x16?\xd9\xa4,\xa9\x1d\xf1\xee\xa7\x0e\x147\xed\xd5\x02\x15\x85tD\x84U\x1e\xa4\x9d\xb1\xd6\xa2\xfc\x94\xcb\xa8f\x8cNp:(\\2\xebcX\xc1 \xdc\xab\xf9\x9e\xe0u\xf3C\xbe\xdc\xce$r\xbd\x06\xd4m\xcf\xf6\xe7\xf2q/I\x80Q\x90\xa2jK \x89c\x9f\xd7\xea}a\x83\x8d\xdf\xb2\x8ab$z^\xca\x03E\xe8\xd8\xd6\x10hz/u\'&F\r-y\xb7++\x17\x93\x9c\x1b\xc8*J\t\xb8\x1bk\x8f]\xe3u\x91\xa3\xbf$\x02$\x1bk\x06A\x9aX\x07)\xa5M\xad\xaf\xcd\xa6\x08\xb0\xa3]\xb8i\xc8)\x7fV\xc4N\x10\x85\x00+\xd9\x0e\xed\xecc8X>\xb4\xcb\x90GK\x9e\x08\x85\x9aXw\x03\x82\xc90\x89\x8e\xea\xa1\x85\xbds?\x80\x99\t\xb9CR\xc1\xb0~/G\x90a\xdb?9\x0c\x04\x90\x1a\xf4v\xf2\xe3S/\xd5\x0f]R\xc0\xfb%\x1d\x0bc(\n\xbd}Ou\xa8\x15g\x8e\'\xb8\x95\x03\xe4|\xf9\x8dnp\xa7\xc1\x10\x83\xad=\xb0\xc6\x05a\x1d>\x98\xd4\x9e\x84\x8e@\xce\x84\rX\x1a\xf2%\xe9\xd4\xd6F\xf4\xddt\xfb\xe3\xd8\x98\xa2\xfc&q\xfe_\xdcW\x9f\xb8\xcf\xce\x9e\x1f\x19Z\x05I\x9e\x95\xe5l\x14w\xaf(M*\xda|\xf3r\x83\x8b\xa1l\xcd\x00\xda\x9bO\xceHx#\xea\xabt\xf9\x05\x89\x85\xf2H\x88\xda$\xbe\xf8\x10\xbd\x00ft6\xbb\x84\x1f\xaa\xc1\xf2S\xdf\xbd|\xf4\xac"Oo\xfen\xd5\xba\x98\x7fO\x99\x91m\xaa\xb6yc\xb3\x08\xd7\xa7\xf4j;\x88U\x14]9\x1e\x87\x0fH\x0b#\xdb\xe0\x8f\xa2[7\xf4\x10\x937\x0c\xb9M\xce\xd0=\x99\x95\xf7\r\x0er\xb4b\x0b\xbf_/\xbe|\xd4\xd0C\xddf\t\x02\xd6i\x1e\x94f\x80H\x13.\x8d\xa2e\te\xec`\xde#\xb0\x00\xb1\x05\xef\xfa!\x80!\xd6\x07\xd0\xf9\xe5\x7f\x17t\xbfn\xec\xc4\x00(\xa4\xcb_\x07\xdbCG\x83\xc5\xb2\x8a\x17\x8eJ\xc3\x10\xbe\x9e\x9e\xedy\x13\xdb\xe76\xfc\xceh\xf0\xa1\xc9_\x06\x12?\x92QEGv<$\x87$,\xc3}b&P\xf3a\xb5\xe7\xbe\xbc\rB\xaf\xc0\x94\x04\x04\xd4\xa7\x12;vM<\x95&"\xbc\x88\x00\x8e\xd8B\xdav\xa1\xd6\x95\xc3`\xe0x\xd9\r,xs\xe6\xf4~\x9b\xd7\x80\xa3z\x1fR/P\xf8d\xbe_~z:\xbc\xbd|\x05\xd6t\x16V/y:\xee\x8e{iHZ|\x08\x04s\xff\x15\xd2\xb7\x0c\x88}\xd6n\xd4\xa9dy\x135UR\xba\x1aA\x125\xa5\xac\xaa\xd1o\xcb\x80B\xa1o\x17\xa6\xcegL/>\xd4\xb9;\xba^\xc2\xe6\x9f\x9b\x1e\xc1\x9bn|\xb5\x83\x8f\x96L\xa8\x1e\xd8\x15\xbc\x00\xffD?\x9f\x98\xac\x83\x82\xad\'\x1f]o\xf5\xe91\x11O"\xd4\x88\xf0\x1e\xbe%\xbe\xe1\x0c\xbf\x01\x03g\x9f\x8b\x0c(\xb0\xdd\x85u$\xf6u\xf0Don\x01\xbd\x1f\xaf\xea\xfc\xb2\x87\xfe/\x1cfs\x9fa\x10w\xf9\x93\x0e\xb6p\xd2\xee\xd8\x81\x8c\x1f\'\xcf\xc0\x91h\x92\xc6\xaf\x84*o\x01\xd2 \xf9\x86\x8d\xcc\x8eveV}\t\xd6\x18^\x1b;T\xd3@\xedL\x12\xe3v\x95G\x86\xfa\x98\xfd\xf1R\xc0M\x93\x8avYI+\x87$%\x89S\xc1\xa6x\xf0\xd7\xd5\xfa\xa1\x857\xb1\xf5\r\x7f\xf9>\xbf!\x0e=\x89\xe3\x9d\xa2y8_W/\xb1\xc4D\x962\x15\x90QSY\x10Y\x1c\xba\x98\xe3\xaei\xb4P\xc7\xc1\xc6K\xa8x$V5\x99\xb8\xf9\r%\xc7\xb8R\xa3\x04o\x11)%\xe0g\x16\xca\x9a\xe1\xc8\x04\xc8\xac\xca\x97\xdf3\xf3wXtM\x81\xa7(<4\xc0^\xcd)kDF3\xa5\xb4W\xbc\xf0\xa2\xf6\xbf\xec\xd0\x83j;@"D\xad\xeexA\x1e\x123 \xe4b\xc6\xafD=\xe1;\xcd\xe4\xf2\x00\xfa@yF\x84J\xe79-\x02=\xbay\xdb\xdc-\x00\x9d\'6\xa4\x1e\x05\x9d_#\xc5\xf6\xe34\x03#\xa42\xca\x8c\x9f\xf7\xec\x13\'\x9b\x11\xbc>\xe0W\xdc)sYt4r\x9d\x87\xe7\xc4\xdd<\xe9g\xe7\x03\x10"Es\x7f\x86\x0e\x89\r\xb7\xb3\xc5\xeb~@\xc01\r\x0f_\xdf\xb4\xa7D$\xfe\xa1\xad\x9e\xcb\x93\x80\x96[\xe0\xb9\xc7\x12\xdc\x8b\x03o\xf4\xb9E\xce\x87\xf3\xd6\xc8Q\x11\x02 zIh\xda}J\xef\x87\xe9\x1e7\xb9\xbd\xc9\xff\xb5EZ\x03\xd9w\xe0j\x19\xbfv@G\x90kJ\x00AkI\xc5+S\x88\x81\x03\x1f\xa3\x94\x94T(\x91~\xee\x06T.\xe7-08\xcc\x0f\xba\x85D\x81\x1d[QH\xfb\xe0\xac>\x07T\xcd\x1e\x89e2t`\x10\xce\xd6((h\x13\nu0B\xe7\xbf\xd1\xd7\x8f\xa5\x16\xca\xed(\xeee\xf3Y\xa9>\n4\xe3\x15f\xf77\xbc<"\xfe\x91\xde\x1c[\xe4o2\xc2\'4\xba$P1\xd5\xfe\xa9\x9f-\xdcAT7p\xd1\xa19\x0f\x0b\xb3\xec\xa7\x94\x93Y^\xf3\x99G\x1b\x14\x85\xb7\xef\xba\xd5\x16\xdf\x05\to\xc8\x00I\\3\x15\xd8\x95\xc4\x19\xf6/i|\xad8`/#\xc2\xdf\xad\x0f\xbf\x95\x91mh\x9c\xc7M\xd9E\xa9l\x16\xad+\xe5\xe4\x1d\xf8\xc5\x12U\xea\xb6i\xd1\xb8z\xdcB\xc0\x88\xdf%\x90\xd8\xd9P:\xedlN\x92\x1d\xf7\xae\xc9\xeeC\xe3VK\xfa\\\xd4\xa8\xc01\x04\x1c\xda\xfe\x17\xac\xf3\x13\x1cp9p\x9c\x7f\x8e\xb7\xa9\xb8\x05\xd1/\x9e\x9b\x93\'p%S,LQa~\xd8\xdd\xe6R\xa6\xfa\xa8\x948\x94}:r\xe0\xa5"]t\xc5\x94\x10\xfcS\xb8\x89\x8f~\x05\xc9\x19\xc9QQ\x8f\x96\x12\xbd\xa9\xe0G2\xdbp\x9d\xe9\xcb\xba^\xbf\x1a\xef\x19\xf2C\x86\\\x88\xf8\x0b\xd8\x85\xa8\xce\xa8\x1b\x0e\x03\x95\x8e\xc9\xc97<\xbc^\xc4Q\xfb\xbb\x06\x92\x90%&\xc18\xd0/\xeb\xb7\xa7\xfb\xb7\xd7k\xfbO\n\x04%\x98\xc6\xfb\xb1h\x1ex\xbf[\xe2Y;\x89\xdc\x9b\xe1\xf7\xe1\x02\x89\x08\x8eE@\r?\x06\xb4\xa9|\xdb\x89\xd5\xf9\xcfg\x18u\xcaf#\x1f\x13M\x0e\x8eK\xf9\x82\xe2\xec\xb4\xb6P\x8f\xba\xe7\xd0\x07\x97\x19o\xa7RvQ\x8e\x84\x8e\xb3\x0b"\xdb\xe2#\xf0$5\xbb\xaf\x9f7\xfa\xa5G\xd4[\xb8+\xb1\x1c>\xb9\xc1r\x8c\x111\xa7!\xcd&\x7f\xb7\xe6GL}\xbbz\x08+\xdeD\xda(\xd2 (\xfb\xa8\x84\xc3X\xbb\xf7\x1a\x1f\xb5\x1a\xeb\x12\x89n\x8bM4\xef\xf2t_\xcf\xd2o\xef.\x1a+`\xa0\r\xd0\xb3h\xe4%\xa7\x85v\x15\xba\xb5\xd9\x15~E\xc7{\xcav_\x92\xd0\x10\xbftG\xfb\x99\x9a\xa4c\xdc\xb6\xc2\x1b\\b"T\x87\xef\x811\x1e\x98\xf7\xf8\xb7\xec\xd9\xbe\xc1\x99\xab^\x90\xec\xfc\xbcr$\xd0Ntf\xf3\xb8l\x03 \x92\xfb\xfey\n\xa2\xd4{@\x7fK\xa7y\xa3\xec $\x1e\xe6/\xf8:\x86<\x01[\x84\xa5\x9b\xec\xcav\x7fi\x8fr\x97$\xe8\xa3\xbcA\x03\xd2\x85\xff\xe5\x12\xdd\xfd\xc6\xb2\x16P<Y\xa2\x19\xd8\x9dgQc\xd17zH\xb7E9\xb0\xa7\x91R\xee\xd4\xc4E\x0bq{f\xa0\x1dI\x7f2\x13\xebQT\xf46pLn\x01\tv\xbe\x9d\xf6\x0e\xb0>\xe2\xd01\\\x91\xa90\xcdU\xf9nS\xb4B=\xb8/Yl\x93\xd7\x92\xdd\xd0\xf47\t-\xc6\xd7f\x95\x10\xce\xf8e\xa6\xf9j\xff\x98\xa46\xc0\x1d\'\xb1\x02L\xc3\x18\xc7\xc9L\x82H\x14\xccQ`\xf4L\xb5\x03\xf0_\x06\x1b\x028P\xd5\x01\x1e\x8d\\\xc0_\xfe\xbc\xed"\xce\xb3}\xf9\x86t\xe9t\xd4/t\xfb\x85/\x9f5H\xe7\x95\x86 \xcd\xf1\xa1\x97\n\xffi2\xb0&?\xad\xaa<.\xb0M\x0b\xb0h\xd4\x04a\x1f\x9d\x905\xbd\xc0.qZ/\xd5\xddi\xef\x85\xb1\xd9\xe6\x8c\xbfd\xce\x1eN\x18\nw\xe5/h@$}\xd3\x17\xae\'HpG\xaa\x84Zj\xd8\x92tCM\xc1\x06K%\xf2\x89Q\xbc\xcf\xad44\x1eb!i1O5\xfe$(\x90$\xa1\xf0:c\xd2\x93\x87\xcf\xc3\xa3Q,\x17U\xb73\xa4Z\x1e\xbd\xdc\xaf\xda"\x01m\x1a\xa7i\xf1qn\x18\xe7\xb5\x19\tq\x14\xd4\xf9;\x82\x92\xa1h\x88X\xd0\xe9\xb7\xdcLM\x83\xac\x06\x8aL\xd2\xfbo\xc5\x05\x10\xe9:K\x04\xcf\xee\x0e\xa0\x0ffDA\xa3\x86\xaeb\xa4\x0b\xff(G\xf0\x18\xcb\xa7\xbfie\x9f\xa6\xba\xb1\xc0\xd6\xfbS>\x15)\x0f\x87<Z\xe8u\x8c\xd0A\x0fX\x9dpU0>\xf1x\x1d\xa7\x04U\'\xd98\\\x95\xada\x03T\x1d\\\xa2\x03\xfdE\x1f\xb2|\x9f\xc3\xdc\r\x1a\xc9\x8a\xed`:H\xd1\x11\xb8~\x91\x9b0.\xb5\xf8W\xa0\xb6\xc3xb\xba\xfb\x17\x02\x95\xc2yt\x9c\x86\xe1O4\xfd\x13\x9a\xf2\x97\xd2\xf7\xa6\xa1\x8d\xf97\x96!c\x97\x97U\x85^\xbb\xc81\x0b\xcfD\xa2\xe6\xe9}\x91\x19\xbe0\xc5\x05%9F\x8a\x88I\xd4S\x10\xfc\xbb\xad3\x1c\x9e\xc8\x92\x93\xa6d\xa8X)\xe7\xbb\xda\xa9^f\xb1\xfc\x93x\xf8\x08x\xc0\x01\xd2\x1e\x9c\xc9WlN\x11\x83\xb8|\xc0\x19\xad\xa0\xe4\x8e\x87\xed\xdb\xb2\xd7\xf6\x91\xc0\xf0\xd1\xf4\xb2\x08\xfe\xe4\xadwM\xd1\xfcjQ\x8b\xe7>\xd2\n\xc1\xe4\xd6\xd8\\\xed=\xf0\x9e\xa6\x1f?g\x81w\xf5mo\x8d\xf4\xeb\xb1\x88\xe3\x8bq\xdb\xd2\xe3\xee\xab\xd6R\xc2.\xcdP\xaa#\xc6\xa33\xdf\x8a\xf0\\\xa7\x16\xa4\x1e6s$\xba\x1b\\\xd6[e}t\xd8\xd0j\xbcL\xa0\x84\xee|w\x12x#\xac#\'\x96\x8dH\xac>\xef}\xd25\xb3\xc0v_\xea\x81b/F6\x0f\x85\xf5\xd6\xdc\xc6_|\xa0\x19\xc4\xad\xec\x95\xfb7\xb3\x1d\x9c/O\xd0\x17\xaf>\xad\xb6\xe1\x07\xe8\xe8\x12q\xa2?\xf0\xe9}S\x8b\xd4x0\xfeG\x0e\xc2\xd1\xabm9!\x85d\r\x86\xbe\xdc|5u \xc98\xf1\x97\xfdJ}\x9d\\&\xd1\xce\xcb\x9c\xbf\xaf*\xfc\xf8\xdd\x1c\xa2jj\xe6\xc4U\x93T\xa7\x13\xf76\x08\x8b)]\xfd\xb0\xb6\x88\x9d\xd8\xbf\x8b\xad\xae\x8acnG\x7f6\x10\r.\x1e\x19\x10|Dq\xea\xa4\x8c\xd3\xa3\xe08">\xa26\xcb\xc7\xad\xcai>FD\xf4\x99\x1a"\x850\x1e\x8a\xb7\x82@s\x03\xd7\xa5\xa09\xdb\x82\x04\xc1\xe4\xa8\x93\xae\x11\xbf\x91V9\xc2\x80\xd0\xc8\x92\x913\xacu\x7fJ\x0f\x80s\xf0\x0c\x0f\xfa*0\xef\x07\xd6a\xb7\xe5\xe1\x89l#\xd1\xa7\x7f\x9c{\xc0R\x9c\x0e\x92\xc7\ny\x1f\x0e\xbb\xfc\x98I\x83>\xc0\x8c\xb7\xc2\xb3`\xfa\xa6\x9afR\xca~\xbf\xd2\xa8\xf5)\xbc\xb7Q\x81\xdc\xe9\xd7P\x16h:\xcb\xcd\x86\xf1y<\xd4n\x17\xfc#\x87!\x83ts\xad\xe7\xcbSdm\xd0v\xd6Of\xd2:D2"\x13\xdd\xa3\xcfL\x1fP\xf1\xc3\xa4\x0b\x94\xe5\xd4\xfeu\xd0/\xc9\xdf\xa2\x05\xe7\xd0\xe4\x1cJK\x8b\x06\xb3\xc3\x83PI>I\xec)\xba\x91\xd8\xd2\xec\xe8\x8cn]\xb3_`\xdc\xe4f/\xf3^\xb0Jt\xad\x02}S\x90^r\xc5 qP\xd8-p4\xd9\xb7\xc9\xe8\xcd\x1eM\xdf\xc9\xb0\xbd\x8eL\xd97\xdd^i\xa1(\xe6\xa3\x0fl1;\x8f\xb0\xf0\xe5t\xde\xb5\xf6r+\x0c;\xd7\x0e"\xc7\xe4%}F\xbb\xc7T9Lp]\xdbc\xa0J\rq\xac\xc2\xa7i\xbc\xd8\xd5\xb5\xf5Jv?\x00=I}z\x12\xd0\xdf\xc4[\xb0\xd7\xcf\xfe\x00\x0f\xddx\xf3G\r\x8e\xed\x1d_\x0f\xc0\xc3\xe7e\x8b\xd7K\xc4\xef\x07\x855\x88\x87\xd0,\xb5\x1b\xd09M1$\xe9\xca\xf4\xe0\xec\xebX\x82\xffw\xd0\xd0?!\x0f\x87\xe7\xfa\x9e\xd3\rD\xba$\xd6p\xf3>\xb8-j\xdfK\xde\xe5MU}s\x7f\x97\xc5Y+\xbd\xc8\x80A%\xc3\x05m\xfb\x9c\x85\xda\x86\x04\xa5z\xef7\'^\xd9\xe1\x9c\xa9\xe9$\x1e\xd5\xd5"kP\xa6\x9cS)\x96\xf3\xa9\xf4;\xbf\x00\xcc\xae\x12\xb6/\xa9\x9fO(\xf8?\x19\xcf\x1e\x01cDl\xef\xb3\x07A\xc2\xfa\xc7\xc7V\xd9\xc9\xaer\x1aRP\x13\xfdM\x9d\xf2b\xca\xcc\xeb\xd6o\xaf\x91\xab\xedr\xaaF\x9f\x9a\xd4\x9a\xd9%\xf6[tX\x0b\xbc1\xfe\x93\x8fN\x95\xa1\x83\xd6\xbaDn\xfb"\xb9#5\xbf\x1c\xffp\x13\x15_-\xf0m\x00\xa5k\')\xd7\xc0g\xf5AR\xbd\x91\xa6\x95\xa2\x87\x8a\xdcQ\x95\x96x\xe8\x1e2Xi\x08\xcbPX\xe2x\x15~a\xdf\xe0\xf6\xea\x0c\xd1.5?\xa8\x08-\x98\xef\x9b\xc5\xb7q\x08\xbc\x92.!\xb5\xc6`\x12\xda\x9c\xc0\x93\x87\x1a.C\x1f\xf3W\xe64\x0c\x9dz \x88\x16\x12\xed\xfep\x80\xb1\x1c\xb9?\x98\xc5@Tew\x0f\x01\x9c\xe3\xcc\x0f\x0fS\xc5\xdfa[\x02}>b\x957x\xe9^"U\x93%\xa1\t\x18\x9fn:\xfa\xedr\xb8\x97?5\xecK\xf7\x99\x19\x81\xcf8\xec\xf0*\x87*K#\x80+\xfb\x8bb\xf84\x07a\x15br\xcf|\xd3T=\xe0g\x86d\x93.\xe8\xa7.\'\xfa\xd3\xec\xed\xb1\x92\xb4-\xbe\rx\xab\xb2\xae\x820\x9dYr\x15\x95\xac\xea\x92\x82\xda\xf1\xbeF\xa7M\xceF\x02\x8ema\xe7\n,j\x8c3\x8c\xc5hq\xff|w\xe3\xef\xa86\xedr\x11\x8a4\xe2\xc3o\x06$ \xfd\xb5z\xcf\x16\xcdG\xac\xef\x8b\xbf\x9eE_Kqu/\xef\x1f\xcd\xf3\xdfL\xbf\t\xcbk\xb5\x8fz8\xceM\xdc\xf8\x00\x99\xeb\x7f\xfe\xe0:\xd2\xe5\x7f\xbeA\xcew<;Y\xdc\xeb)v\xd8\x17\x92(\xe4\xa1v;\x10\xdczOl\xc1\xb7\xa6\x0e@F\xd9\x94\x84\x1e\'\xd0.Hu&\xe0\x16!dq\x00\xcb\x9c\x8aS\xb0*\x88\xe1<\x8ev+\xbak\xb1\x1am\xb3%\x13I\n\xbe\x86\xf8\x914\xb1\x7f\xbe\xa6q\xe9\xcf\x88\xb1\xc1\xe7\xd5P\xbd\x9b@\x0e\xa8\xf4`\\#9\xbd\xa5\xd5\xec\xe4\x80\x9dP\xff\xb0\x14P\x80\x89\x8d9\xc8\xb7\xe6\xb3O\xaeY\x84\xafi#\xcdqzt8\xb0\xcf\xd9\x14\xa5\xd9\x8d\x87\x01\xef\xdb\xaa+\xf9t\x88\x0eB\xe1.\xa2f\xfc\x1b\xe2\x84\x82u#\xf6\x10\xce(b5\xe5\x15\xda\x88\xc2m\x93`=\xba2XR\xe5\x15Kx\xe8?\x15\x0f\xbe\xc2\xdb.Qj\xed\x0e\x91\x84\x81g/\xfb\x1f\x18\xd4=G\xe2\x11\x95I\x17\x11\xc5\xa2\xf3\xd3\xb5\x98I$\x19M9\xc3\\W\xbd9\x0f\xb4\x0e\xb1\x01f\x1dM%\xc1\x90\x84\xafW\xdfI=\xc2\xc1g\xe2\x98\xb4\xe2\xb0\xd8P@`e\xf4\x94\xd3\x9a\x0c+\xe1 \x99G\x84\x14\xda\xf1\xcb\x85(\x13A\xeb\\\x1b\xfd\xe1\xa8\xb4EN:\x0464\x07*\xce\xec\x83P\xb1\x9c\xfc\xe0\xce\xffM/\x1fY\x03\xbd\xe2`\xe781\x86\xf8U\xc6~\xf5t\xb6h \xfc\xd9\x81\xbd\xac\x91\xa0uLLm?\xaa\xff#M\xd1\x97*o\xa2\x7faF9\x8a\x8d\r\x00\xc5f4\x95\xfa\xbci \x9bf\x16\xef\xbaV\x94\xde:\xf2\xee\xef\xd6p\xf7\xf3\x8d*$k\x84Of\x92Z\xff7Y\r\xac\x8eg\x07\x9e\xd24\xb3\x14\xe40\xbc|\xd7Z\x14\xff\xb3.G\xd5\xd9\xab\x18\x9b\xc4r\xf8/&!\xfa\xed\x92:i\x89Y\x88JY\xdbM\x9eor\xde\xcb\xe4\xcbm\xb8\xf1\x88\xd5\x07+\xc0=\x18\xd2\xeb\xd7\xf6\x90\xda\r\x12%\xb8R\xc5\x19vZEK\x96E\x89@\x8cec\x9b\x06u\xd6\xe9\xe0!\xd5\x9e\x8e+\xcd\xc7?\xbdh(\xaf\x88\x96;\x92\xff\x06J?\xa6\xed\xcf\xd9\xaa\x97\x17q\rj\x8fQ\x82\x94\xdb6\xd9\xcb\x9a\xac\xad\x84\x89,\x16\r@7\x8b\xff\x99\x16\xe5\x8b$`\xd9\x15\x15\x0bM\xe3\xdf\xa4{\x81\x9f\xf5\x9as\\\x0cT\x02\xc8\xf7\xed:\xb3?\x8dE\xf9\xc4\xa2\xd1_\xddzU\x98~)?\xe3\xff\x92\\6\x00\x9bP\x10\xe5\xd4\xc8\xd6;06\x1a\xca\xfe\xbb=(<p\xdc\xa3}@<6\x11I\xc7Ub\x11\x1a+\x1ek@\xdfL\x1ff\xcb \xd2\xd3wU(hh\xa5\x004\xefU\xc0\xe8\xddn\xd1\x9dR|K\xf3\xc1\xd3\xbc$\xd0\x12\x16I\xe7\xee&L\x04\xaer\xb1\x15\xf3\xa7J\xf6x\xd2\xd4\x8ao\x9a3\xa2@"f\xc8\xef\x86\xe7\x08\xd6\xeb\xddD*iU\xd3g1\xb7\xfb\xb6\xc2\xd0e"\xf0-\xe5F9`\xee\xba\xaa\xc6\xb5\xd0\xfe\xa2\x18R\xee\xc5\xe0V3\x07I]\x88v\xc8\xa7\x1a\x17\t\xe8\xfc\x94<\xff\xcaS\xc6\x95\xe8%d\xfb\x8a\xbb&\x97\xc3\xca\xf59\xfal\xe0\x8f\x9483\xdf\xf8c\'\xf4\x04\x15\x9c\x95\x7f\x04\xbbF\xa5\xe2_^\xf1\xbc\x8d\n\xa9\x01\x93\x8f\xe1/\xbb\xdc\x1f\x88k\x8a\xef\xde\x10e\x08\xdb\xc35i\xd1}\xfe\xae\xb1d\xed\xac\xd8\xe1\x9c\xba\xa6@*S\x81\xdf\xa6r\x0b\xc5\xd1\x9eY\x1fE\xbe\x844\x03\xb1\xac\xb0\xc6\xa2\xd4{7\x16\xf6\x08\xdcZ\xf8\x9b\xe2%\xf1\x9b\x13\x85\xdal\xca\x9cTX\xbd\x9eQ\xca)\rAaX\x04 \x80\x81\x80N\xdf"W\xae\xac\x96y@N\x1f\x1d1\xcc\x16\xe9\x01\x9e\xa5\xb4\x8d\xe4(\xe3S\xbf_\xec\x0e\x91{\xf4\xb8s\x0e\x18\xb5\x8eG\xb8\x82$\x86\xc3;\x86\x837\xa6\x0cf+@\xf9\xa2\'\xaf\x1e\x83\xc5\xff\x15\xf9\xcc\x1ec\x89\xc9!\x8e\x0c/9\x007\\\rzB\x92\x1bM\xccy\xc1\xff\xa2$B\xc8L"\xb7~\xda\x84\xfa\xaeg\xc6_?\xba\xc8\xb6\xde\x10\x97\x11\x15\xfb\xcd\x08\xd1\xc1\x06\xbc\xfeU\xdb;^\xbdW\xe9\xfd\x98G\xf2\x83\x1dL\x85ed\xdd\xe0G\x03\x7f\x9b1\xcd\xd3\x8f\xe1^\xfd|\x82\xa6\xee=\x90\xf3\xbd\x1d4\x04\xb0_\x89?\xd8\xc3\x17\xbb\xd5bv\xc9\xc2\xc6*w\xf5\x02\xb9?\xf1\x87>\xbc\xbf{\x08\x04\x14\xbb\xad\x8bl\xea\x0c\x1b\xf9\x02)<\x8f\x1e3S\x9b\x17i\x94\x12\x06\x91!*\x8eX9\x0e\x9d.V\x8ema\x01\x03\xd3\xce\xc8\x16)e\xc2\x15\x92\x15\x8al\x03\xd5\xf5\x13\xf9"G\x91{\xb5\x0c\x84\xf1/\x95\xa1\xcaqw\x85\x19n%fh\x9c(V\x0e\x83\xe2\xd1\xd2\xc7\x93s\x8d\x04r5+C\x9b&\xc0\x04qyq\xff=\xf9\xa8\xcf\xd8P\xa8k)9\xb8\xc1E\xa11+\x9e\xc9\xd9]S\xf2Q!\xf5\x8a\r\xa9~\xa2#\xce\xe1\x03\xf8\x12\x0b\xe4\x97\xb5\xd0\xfc\xa9\x15,S\xb9\x06\x88\xd5\x83\xd6\xc8\x04/\xb6\xae\x914\xcaU\xb5)j\xf4\xe6\xe6\xf1<\xad;\xfbS\x9f\xfc&\x81\xea<\x01\xf9Uq\xa4\x08r\x87\x14\x82\xce\x85\x83\xab\xa5L(,14l\xf5\r\xef\xda\x96l\xd2Gw\x90\'{\xe9\x8b\xb5\x8b\x01\x11<H{!\xac\xbf\x1b\\\xc6M[\x91}\xe2\xce\xb3b\xe6#\x9a5=z\x84z\x15\xadv\rO\xfe\xa2\x18}`4\x80#\\\x0e\xd3\xe6\xfa\xf5\xc6TyM\x97\xa1M}/\xb9\xff\xa9\x9a\xc4%\xc2\xc1\x85\xcc\x98r\x85\x97\xd5"\x0f\xbe\x18\x99g4\xf8\x8bW"r\x02#{-\x1d\t\\\x9f\xd9\xef\xfcJ(\xeaR\x03\xed|\x1e\x18\xb8\xf1>\xdaUV\xed\xa6kx<GnF\xcb\xac\xbc\xbc\xb8\xe3\xf6\r\xe1"\xe0\xbb\x92\xbe\xf6).\x10\xa9$\x8b\x0cX\x91\xec#\xd9\xa3\xb8\r\xc2Ni\xf1\xda\nf\xc2V\xd4D\xa3&\x99<\xcaD\xb56\xe7\x1b\xd8\xa8w\x1c\x15Dy\xee\xf5!\xcb,]\xcb\xd1\xb3\x87\x9c\xfa\xd2\x1e\xab\xa7\r5;d\xb7v\xd6\xf79m\x9a6y4\x03\x98\xee\x16E\xabk\xda\x8ca\xdcDSp.\xa2\nl\xeci\x94ZR#\xd1\x956\xd1\xceI\x1a^w\xd0\tB\xa9\xdc\xd9\r\xbb\xf2E_\xb9\xa0\x8c\xbf\xd4fI\x1d\xd0jt\xc2\xee\x06\xfb\xde{Z\xf2 \x14\x8ag*\xb9Y\xfc/\\\xf6}\xb9\x96\xb7=\x99\xf1Hu\x95;\\\xaf\xe1\x99\xc20_p\xf8(\xd2\xccE\xc2\xdb\x08D\xb2\xb6\xbd\xe6\xe5\xee-\x8f\xc4)\x9c\xbes\xda\xd2\x80\x8a\x11\x8aU\xf8\xe7\xbbM0\xc0\xcb\x7f\xbb\x7f\x8a\x0bH\x94C\x16o\xc3\xebx\xa6\xe3\x0b\xc8\xc4\xeb\xe9\xc0\xb8\xa3>\xe5\xa9\xbd\xcd\xb1\x8c^\xf8-\xad\xed>\x1c\x9b\xf7u-u\xf3\x19;\xd6\xcf\x80\xc2\xd1\x13\x8c\tO\r\xd1c\xdd\xf8\x90hPfh`f\xbf\xc3\x13\x1f\xc1\x0b\xf3[\x92C\xa0\xd3P\xfas\\@\xa3\x9e\xbff\xbc\xbc\x87M\xa8\xd04`\xed\xd3\x04_\xf0\xc3\xa2\xc7\xfd\xfb-V\x81\xb6\x84ix\xa1\x8f\xd9\xb7\x00\xd8ZzN/\xa5\xf0}\xc0A\x8e\xd0\xef\xe3-\x9c!\xd4\xd1a\x96\xfb\x1d%%%\xe8\xfd<\xec\x86\xa9a!\xe2+l\xa4\xdak\xb8\xd0z;d\xe3\xb0A6\xd4,H\xb5m"[\x18\x9bQY4fbM\x0f\xdd\xa8\x8b\xa6{\x08\x0c)\xab\xdf\xd4\xbd\xb1k#/U6\x17\x96\xa08\x80\xe2\xdf\xc5\xbe\xd2\xbf\x18\xe1n=\xd2\r7\xcb\xf0l1\xd7\x15\xdegO\x0c\x9a\xf5\x98B:3\x00\x9e\xc6\xed3\xfc\xd4f\xa0\xe8\x12\x0f\x8d\r[\x00\xcd\x84j3\xb9\x11\x0f\x95\x90\x8d:Nuf1\xe6\xd3\xbb\x0b\x85\xab\xbc!\xa6\xab\xdc\xc79e\xb1|\x07\xd0\x10a[\xe2\x84Lrl\xf7\x84\x90\x8e\x84\xe2\x89\x9f\x92/\x01\x93\xda\xb72\xf6\xdd\x13\xe6\xde\x0c?\x12\x82\xf7E7\x86\xfa\x076\xa9\x9b\xe0?\xfbt\xff|M\x8e\xec\x82?(j\x15\xaf\xb7\xe8\xc3\xd9\xe1\xcb\x06\x16\x97\xe0\xf3O\xbb\xdd$fT\x951\xf4\xf7\xc1zhM9V\xa3!\xa7S\xe6o\xedT\'(\xa5\x9c4>\x8d\xac\xa6);@a:\xc7\xc8\xc1\xb6{=\x8e\x8c\x9b\x19\xb5J,\x8fz+\xb2\xcf\xef3\xeb\xc6\x0eVH\x1a\xe2}\xec6\xfe\xdd\xb6@\x0f\xd3\xe7\xa6X\xb3\xa7\x94_\xef\xcc\xa2\xfbY\xb9j"\xd3r\xf9\x1e\x92\x973\xc8\x1f3\x0egs\xdf\xf8Z\xffW\xde\xb1\xf5\xa1zs\x98^\x81 \'eS\xf1qn\xfb6\xb7\xf7\xc9\xa86\x0eT\xde!Uz+\x91h\xde4\x0f\x81N\x10A\xfc\xeb":\xc8VU&\xc9\x94x\x03\xd4\xe0\xe9#\xf7\xf0M\x10\xd8\x14^M\xb9_\x8dg\xa5\x8aZu\x7f\xbfe\xcf\xb2x\xc5\xb1T#\xb9R\x1bT\x82!w!\xcd\xe8\x03\xf8\xcf\xda\\\x95\x9f\x7f\xb0-\x0e\xe3\r\xc2\n\xc1\xaaqg\x80\xc3\xb4\xd0\x15U\xe0\xd7\x9e\x10\x86]O\xa8\xe4\xe4\x0e\x81u\xef;\xa9`Ou\xb4`Og=\xae\xac\xee\xed|\x98\xb00\xd8vs\xa7>\xf0\x90\x1bC\xeb\xf1L7V\x9b\xe9\xb21\x8c\xee\xf0\xc8\'7\x1d\x9d\xadd\xc5\xe6\x7f\x9e\x1fo\xeds\x9b\xcd\\x[\x9f\x9f\xd1\x0eSW\x80\x96\x10\x97\xe4\xefj\x88\xb6Q\x84\xc5\x8e\x05\'\x99NF\xadL\xd4\xf0\x1f\x17ma\xf9IC\xe6\x05\xbb\xfe\x924\xa1\xbc\xef\n-\xa0\xdc\xaach?\xee:puR\x19\xe3\x9c\x8a\xc1s"\xd6\x15D\xf2\x9dq&\x82\xd9#K\xfe\xaeH\x93\xff\x012\x80\x90\xf6\xc9\xfao\xd9f\xc9FM3@\x90*\x05\x14\xd2\xcf\xb3\xf7\xe4P\xa8\x1b\xbb\xcd\xcd\x83\xc1\xd3\x19G\xfa\x91\xe9\xed\xe1\xd9\xb5\xd5\xdfP\x8a\x82\xc3z\x90p\x9b\x17\xc0Dky\x97\xec\xde\xaaM:\xd9\x97-\xab\xa6\xa7\x83\x90\xadV1\xae\x8e\xb4\x9c\xb0\xea\x06\xdece\xc40\t"\x86\x01\xec[2\xa0\xe6\x8e\x86F\x04$\xc9\x03Y^\xef\xe1\xe3sY\x9e\xfdRb64\xf9\xb7\x8c\xfdV\xc5\x00:CT\xc1\x90Hty&\xbfi\xd8\x14a\x8d\xb6\x0b{\xafKF\xb0\xf2\xb3\xde\xfe\x82\x1d\xff\xc4\xb2\x18\x14\xfe_\x94\xc5?%\xc3kA\xf7\x0f\xc4\xc2\xa5udXK\xb1\n\x1eS"\xef\xdd\x01"\x00Y(}[f\x93\xd1\xdc\x91F\xf0"\xcfO\xa5\x17\xe1\x83Ov\x89Vq\x99\xd7\x8d\x19\x07\x06\x86\x96\x18\r\xd0\xa6\xa4\xc6\rwG\xca\x9e\xae\xc1\xe4=\x02O_\xa1U\xd9@\xf4\x03+R\xac\x17s\x04\xecU^\x83\xa5JQ\x91M:\x98\xf3\x90\x15\xb9\xe1-i\xb7\xc2\xa7\xeeQ\xf3\x11\xa4\xe9\xb02Y\xb1\xa3\x8a\\T\xc4<\xbb\x15EH~\'W\x9ac\x93\xd6\x94V\xd2\x8b\xa0EZ\xf1\x16\xd8\xbb\xf5\xcbL\xc0\xb9\x8e\xf65\xb6\xc2\'\xbc\xa5\xf3\\\xaej\x0ejv\x85\n8\xcc\xf4W\xbc\xd1B\xd2\xc3f\xe7\x07\xb7\x1eehyC?\x15\xae\xaf\xed28T^+[4\xf4gi\xb0IQ\xb9K\x82\xe1n\xa3\xc9\'5#\xe7\x94)\xb2)\xa3*\xd8\x98\xde\x8ce\x1c\xa9VG\x8d\x03\x00\xa4\x06\xe6\xb5\xa4T\xa7.rq-\xd3\x19\x94\xdad\xd7`\xed\xe3B\xc2\xe0\xa2\xc5\x8fj+8?\xd9\xbaM`x\xc5\x9f\x1d\xa6\xcd,\xdb\xd4w#\xd4\xd0\x0e\xf1\x85\xd2\xc7G\x14\xab:\x89w\n\xf40N\xac;v^t\xc5\x8e.J\xe4\xff/\x1e%\xea\xe8\x8e\xfcz?\xf1<\x92\xb2\x85c\'\xfd\x08\x8c\xf4~\xe3\xbe\xdan\xe8\xe9\xdf\x05\xe5*\xb1}B\x8eg/\x06\x05\xfa\xf4\x86\xe82q\x8a\xae\\J\xcc\xc6f=\x82w\xa2?\xc0b\x99Xr]\xf2\xc9\x83\xd8\xb1\x020\xa0|\x01\xb6\x0b\xa4\xc9\x06Z.\xcb\x8a\x93\xf5\x0e@\x9fpB>\xdd\xfc\xd7\xa9H\x18\xb3\xba\x9f\xdeW\xe7L\x1a\xa9\xb9\xda\xff;\xfb\xc8\x063\xf2\xec\xe7D\x98\r\xb8\xa8U\xaf31\xf4\x04\x8c\xc5\xf91\x1f\xb0\xf8\xb9\\*\x1f\xba\xbc)Nl\xe0\xa3\xd7\xee\x98\xe6\xc2\x0bhV\xf0Yo\xc0?\x93fmI\xa1\xd4\xecB\'\xc5\x08ER\xca~\xa3\x80\xcd\xd4\xacl\xc9\x03\xa5\xf2\x87\xeeZ/cRSCM7\x97>\xa7\xd7AS[\xc8\x9bj\x83c\x9a\x12\xc8\xe2Zi\xa7\'\xa1\x8dD\xd1\xb9&>o\x0c\xa9\x81\xb9\xca\x16Up\x87\x123%\xd2P\x97C\xcb\xd7~\xb0\xff\x96\xf8\xb1\xf3\xfd\x17\xd0J}\xfan\x98\x06\xf0\xa0\x8fb\xb7H\xcd\x9c\x99?\x9f[@\x02\xf3\xc6\xae]\xd6\xda\x82\xdc\xf9e%J\x87u&XjZ\xa8\xf1\x95\xdd\xf3\xddLa\x0e\xd3\'+Ba\x97P\x16\x83\xc7\x0e\x87\x1a"\xfe\x9f\xfd\xe8\xf9\x92\xc2\xe6\xbb\xdd\x03\x86\x19\x0f\xde\x128\xe7\xe3\x04\xe0\x88\xb6*\xc1\xf2rt\x17\xcd\x01m\xfbO#i\x17e\xe7\xf4QxZa7\x9b\xc3Wp\xdf\x8b \x1c\x81,-\xb1\x87}\x91OJ5\xb6\xce\x9f\xeb\'g1\x1d8E\xb91\xd0xZ\xb5\x02WPS\xdf\x86zV\x8c\xbe\x8e\x88\xfb\x96\xc4:X\xd1\x86^\xe9\x08.\x91\x85)\xf6\'?\xedrY1d\xdc#\x0c6\xed\x9e\xd5\xde\xe2\xf46.k\xbaQ\xf3pT\xb4\xab\xf4M\xbe\xb6Tv)\x9d\xecG#\xde\xc1b\xa4\tV\x1f\x07\xca{9\xf9\xaf^\xea\xba\xfb\xec\xa9\x8a\x8es\x93\xf2\xf4\xac\x16\x08\x00%\xec\\\xbb\x01\xfb\xcc\xd4J\xf0\xad\x12<$\xe04\xfb\xc2&\x80\x0c1\xe3\x02\xdc\xe4r|\xd5\x13\x8a\xf9`\xeag<x\x155\x06\x84b\xe7\xe0b\xa6|\x18M\xab\xb3\xc1~m\xfdf\xe7\xf5\xff\x95h\x11\xbby\x91\xb1&\x05\x07P\\\x17;=\xa0\xba\x02\x05UC\x85Z[\xbct\'\x8fS\xdd"1\xdc=\x03\x08\th`}2\x0c\xbb\x11\x8buTf)=\x17\xaf\xfb\x14\x1c\xf8"S\x82\r\x0e\xac\xd8\xf0\x9dF\xd3z\x15\xf16\x8c\xb2\xf3\x0evK\x93\x9e\x87?k1\xaa\xbd\xf9\x9a\xbd\x00\xbfs\x90DS\xdaB}\xe9"\xef\t\xe2\x93\xaf^\xa2\xda\x176q\xda\x06\x0c\xeb$8G\xdf\x86\xc4s\xfc5\xa5\xd1j\xf7\xf0\xf3\xba\xcf\xce\x9c\x1f\xec\xae\x91B3\x8e,F\x02W\xd3\x03\xab\xbe>\x1cZ\x1f\xdd\xe9\x12&\xde\x90\x1c\xb4J!\xec\xda\xcf\xa2\x03N\xe7Q\x1aD/J\x972\xab\xef\x05*\xb6\xb1a-\x91qNU\xb4\x96\x8d=\xc5\xbb<\xe9\x8ah\x8cm\xd2\x05\xd0\xd8\x87c&\xe5\xd4V\xf6\xa3),\xb3\xe0\xcc\x7f\x10\x95\xdf\x03)\xaf1\xee\xdeJ\xf4_\xa6xI\xceR\xb6\xef\x14\xb4:2\x1f\xf9G\xa2\xf7\xaf\xca4\xb1J\xa8\xf7\xdf{\xe2\xbdNjUT\xbd4\xb5\x86Z\\\xc2\x9e\xb3\xaa\x12I\xbd\xc5\x9c\x17GT\x15=,y\x1c%\xde\xc4\xed\xab\xa0\x8aRF\x89\xca\xa0G2rR\xbdD \xc1PC\xe7\t\xd3\x8d\x8e\x12wJ1K\x15\x94O\x9d\xb2\xfa\x8e\xf3^\xeb`\xfa\xa8\xfc\xc1X\xb0\x11\r\'\x81\x88j\x90#K\xe2\xda\xe7r8\xd5\r\x03"q\xa3}\x03O\xee\x8bj\xc7t\x97\xa1\xbb\xf9\xea\x9eV\xf4|)\xa8+\xf5\x07\xa5\x1b\x88\x99,\x89\x8e\xf6K\xc1j\xb9\x87Dd\x93\x11b\x7f\xf5\xdb\xc2{\x81F\x00$\x8cv\xff#"\x86\x03#x\xeb)A"\xea\x1c\xa8\xab\xb6\xac\x11=;#\xb9\xb5\xdeQ\xcaJ\xaf_\' \x18\x9b\x96[d(\xec\xba0\xfa\xa1\xa8G\x8aO!Y$\x13\xed\x83\x0c\xc5\x0fY\x01\xb6\xf4K\xd753rWOh\xd3\x1c\xdd\x8f\x05\xf6I\x10\x17\xd5\xa3 \x9e#jB\x86\xd8T\x8c\xa0\x12\x8a}.\x85\xc2\x14n\x94\xa9<\xd8\x1f\xea{\xa8\xf4\xbdd\xf8}F\x90P;~\x17\xabl\x01IR\xb5{\xaa\xe7\xc7\x0fk\xef\x16\x0c)\x00\xc8\x8e\xa8}m\xa4-931\xaa\x8d\xd4\xc7\x91"\xde\x95E\x7f#\x81\xff\xb7W\xf2\xcf\xf3\x11r\xa9OC\x9a\x95\x17\x7f\xf6y~~\xa7\x86".w|\r\xc1U\xad\x82&\x1b\x81\x0e+\\D\xea\xd3-%\tt\xf3\xb2\xfc\x9a\xff\x92\n\x84r\xd7\xf9\x97\xdd\x81\xa1\x8f\xd63\xa9%\xc3\xb0\xf9\x93\xfa\x03\xc1\xfe[u\n\xdc\xc8\nG\x8b\xb6^\x17\x16|\xc98mG\xda\x92\xc0\x837\xf5n\x12j\xd83\x93\x0bH\x9ar\x0e\xad;A\x0c\xcd\xcb\x03\x96\x08\x02\xdae\xa3\x81\xe1t+\xbb/\xe3\\\x1b_\xa9\xf4-w\xe5`\x83\xfb6\t\x8a\xda\xa2_\xc4W\xb4}S\x0cc\xb0\x80\xb5i\x93E\xfctO\n\xf8]\x1c\xb2\xe0\xca`\xb7q\xffq\xb8w\xe6\xe4\xdd\x07\xd7{\xeb\xb2\xec\xf0\x90\x0f\xa3{P\xf3DA6"%\x83z\xa6\x0c8h9\nur+\xf3\x89L\xbb\xd5k\xf5\x84\xef\x00 \xa4\xb6\xd0\xb1\\\xce\t[\xebL\x873y\xcb\\\xe5\xfa%\x92\xfb,\xe4\xf8\xf3\xc4\xfc\xfb\xd3\xe2\xdc\xe3*/w\'W\xae\xb3K"=\xc6\x90nF\x80\xac\xb7I\'\xc3\x90\xfd"\x0e\x9dCj\xdc\xfb1c\x02\xbc\x96\xbd\xd3n\xc1\xf1@SxF\xbb\\\x122\x180\xa3\xc1<\xeb\xdb&\xa0 \x98~\xa9\xc7y\t\xfdr\xce\x18\xde\xf0x\xef`\xe8\x07*\x15\xaaJ\x7f\x08`j\x19f\xb4\xbc\x83\x97,*\x0f\xe4\xc1\xef*[\xcf\xc7\xc7:\xe9<!\x03\xde8?\x8d\xe0\xb1\x8e\n\xdd\xfdK\xe4/\xfb1\xac\xeaV\x17Y\xb1\x16\x9fJ\xcb\xa1\x06`\x0f\xc3U%\xb8d\x90\xd23\x85\xd4\x00\xb3\xbcC\x90\xc4\x1e[L\xcc\xff\x95\xea\x08\xbd\x90\xa1LC\xf4C\xce\xdb2\x9b\xa4\x05`%\x00/\x9c\xe1c\x16\xe1\x98\x9d\x99\x86\xb3\x01.\xf9 \x193\x9f5D\x85\xdf\xb2\x1a#\xd1S=\x12\xb0\x80\xbe6\\\xa7\xd0\xed\x19\xadN\x19C%\x96\x9f\xdf\x81\xab\xc9\xa4\xda\x12\xa61!\xeb\xa3j\x1ai\x9dr\xc2\xec\x03{\x10\xbe\xe6\xb0\x04W(\x0e\xf8\xac\xde^z\xbdY\xda\xcb\xf3W\xc2\xf6K\xceF\x03zP\xda\xf3)\xee\xf0\xcfu]\x94\xd9\xc5\xc2\xf1\x80\xedI\xbb\x06\xa4^,\xe9\x84\x936\xa7~\x7fRT\x81\x83:mZ\xbcf\xdf\xe3\x1bT\xd4\xe4\xee\xdf\xbf\xd7L\xb6\xed\x88\x1bA\x8d\xcc\xe3x\xa6I\xdep\xf2\x96K8`\n\xa0E\xa8\xeb\xc7\xde6\x1e=4\xce\xfa\x80{\xa1\x1c \xfc\x8a\x9a\x7fx\x1b\'\xdb\xc5z.\xab\xc8.\xcf\x0bG\x13|\x11Cf<\xf2\x14\x9f\x90\x81\xc1ru\x95\xa621`2H\xbf-\xcc"\xc4s\xd8\\g\xdb\x12`\x0b\xa1Ps\x0f\xefW\xe9\xe2\xc5hRt#\xa0+\x9f\n\x8b\xca\xa7\xe0\x93F<\xa1*~[\x7f>p?N\xbd\x8e1a:\x1c,\x01N\xaf\xaa\xd5\x8cs\xb7\x97\xf87mo\xe2!x\xab\x9c\xae1C\xb3j\x16-\xd8\xc4K\x07T\xc2>\x003\xafPS@o\x81\xebn\x01\xd4\r\xcc\xa5\xa4\xb9\x16\xbd\x8c\xc7\xca\x84\xe6\xcf\x14\xa0+\xb0\xbf\xc0\xfd\x9c3Zt\xbd\n\xf9\xbd\x0e2\xf3\xb8V\x17B\xa0n*\x10\xe1m[~\xdb\xbd\xfd\xf29\xe8\xc9\xd5\x10\x0f\x01s\xd7\xd6\xcbv\xbf\xf1\x10\xf0\x0f\x14q\x00\xf1\xf9\x97l0\xe5W\x1b\x91\x8b\xb0\xaa\xe6\xbc\xfd\x95\xf8\xb4<\x95\x05$.\x9e*\xd8)\xa3\xf6PGDZ\xd9Z\xf6}\xce\t\x14\x15 (\xefc!\x9ey\xa6\x1dlk\x0fyQ\x8b\x01\x88p\x19n\xdb\xbcdJx-\x9f\xec\xf0\xd6\x000\xcfZ\xb3\nl\xde\xce<\x91\xcc\x1b\xfb2\xc0\xbb,eS\xd6\x1b\xa5V*\x16\xa8\xb5\x7f0\xa9L\xa6k\x04\xc1\xd3\x19\x8c\xfaY\xd9\xeb9\x8b\xd8E\xee\xb2\xfbIf\xf8\x04\xa1\xad\xbb%\xc7\xc3h\xde@x\x1a_\xddg\xcd\x14\xa3\x9fW\xc8U\xbc\xb3"U\xe9\xe4\xbb\xbbo\xdbK\xd7\x0f9n\xb0\x9agu\x97\x9e-\x04\xadl`\xed\x8e\xaa0\x9eq\xd9%W-F[\x1a\x9bY\x7fC\x02\xa3N\xdb\xber\x88\x01P\x12?\r\xcf\x96\xffH\xb3\x9e\xed\x99\x1d\x14l\xd0\x03\x81P1h\'\xc6F4\x98\x7f\r\x1d\xa31\x14\x02Lx\x8f\x06\t\xa9\x98\x04\xfa\xd0%\x80W\x03\'\x98Mlk`\x1f\xe5\xe5A\xac\xdb\xadS\xcfz~\xc8\xcch\xce14\x99\xc9\xa7W\x87\xdd\x08!\x8f\x1faL\xdf2\xeff\x98C\xb5#\xfa;\x92=\x9c\xd7#U\x8b\x93\'n\x953\xfb\xb7\x05\xec|'
|
|
|
|
|
|
2024-12-14 17:54:48.383624 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25570
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808875429
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.404250 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 11720
|
|
id = 47959
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xde8f
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808875429
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\'\xf1\x10~\x97\xf8LO\xdeH\xa1\xb4\xa8\x88o\x1d\x060\x9f;I\x90\x0b\x12\xb0\xa6\x84\x194\x90#\xfa\x9d\x80\xf9}g\x96\r\xfd\xdd\xd3\t\xce\r\xe0I\x94\xb0\r\xde-Vk\xfa\x03\xa9\xea\x95\x12\x1ap\x85\x8f\x05\x9b\x05\xe2\x82qs\xac\x1f6\xa2$\xb5K\x9e\x834n\xf5G@\xc5\x16\x1a\x95\xa7\xdc\xc0\xe1\xfa;j \xba\xc8\xc1\xc1^\x01\xa635|$\xe6~Dl\x02U\xbd\xb8v\xf5\xf9l\xe3"mW(\xb6\x8d\xe4\x1b\x83y\x03\xfc\x0e\xf9\xe1_\xa3\xf70\xc8{\xcd\x84\x92\x92\x88K\rqw\xf2\xb3~P\xb9\xb6B)|\xd6\xcb\x8ci,#\x05\xa4\xf8\x0c\xbb\xbf2H5\xa6\xa7\x87\x92\xac6\xcbQ \r\xf6\xa2k ;\x06c\xb5\xb5,u\x1b2\n\xcc\xeb\x93l\x11\xa5>\x87\x87/05\x0f4#\x98]x\x1b2\xa7\x9e\x17\xe9Et@\xd7\xbf\xa7g\x98\xdbb\xe6\xd8""\xfc\xdf\xe4\xc9\xbdTK\xe8\xb9\xbeH\xef\x8br\xf1\xd4\xefu8\xb9/\xa8/\xfc\x0c\x87\xd6h(/\xa3\r\xd7+\x9d\xe6\x1f\xb9\xa5B=\xbc\xc6z\x18\x03\x0c\xf0\n\t\xeaF#\xb0?xq?\xcb\xd2\xa1\xd2\x9a_\x13\xe2P\x80[\x8at\xeb\x8cE\xee\xef\xa2\xbcG\xd7Z{\xd5)\xc2\x9b\xfd\x91M\xf91O\x08\'\xef\xac\xab\xae\xe3\x98\x13\xe9X>"g?\xc0\xb0(y\xb0b\xbc\x13\x91\x93\x03\xae"\xc1\x07\xf4\xb9\x03\xde7\x14\xceQ(w}N\x04k\x7f\xe6p\x95\xb2e\xfeSoo\xdb\xb29c\x86\xed\x94\xa3\xc4\xc4%^\x07y;\xd1\x8fl\xf0Z\xfd\x9c\xc8\x1b\x10\x9f\x0b\xdb!?NC\xdbsv\xed\x8a\xf0_\xe5hU\xe8\xf8x\x83%\x91\x16\x1f+\xd6b\xf5S\x14Q\x00\x93ecA\xd6\x18\x1d\xa6\x86\x10\xb6\xef11,z5Xe\xa1l%M\xcct\x02\x1f$\x0e0k\xddBm\xd8\xb6\x17^\x8b\xbf\xbe\x87G\xbc\xb8G1\xba\'X\x07\xd2\xf9\xe4!\xbdg\xa4\x95\xc5\xb0l\xf4\xabe\xaen\xe7m\xa3\xe1\xae\xe1s\xd9{\xdd\x07\xd3P\x82\xbfnV\x10N`8\x85\x83\xe0/\xb42\xbd<\xbdA\xf6\xf9X\xf1@\xaf\xab\xfay\xcf\x9e\x17&\xb1\xc2F\xf1\xd1\xa2^\x8b\x01\x18\xae\x9e\x9ez\x80N\x14-Qiy3\x15\x9b$O\xa9\xba\xe6\x81\xe3}w\xc1\xce@X\x83\xb3\xfcrht\xad\xd0\x0c\x96\xaf\xcd\xc6\xa6\x03u\x84\x1c\xdf^o.\xdc\x1d\x00q7\x8d\xd6\x80\xfeY\xd3,\xe4\x1e=\xd1\'\xae\xbf\xd0\xdc\xcb\xf3\xdc+\x15/H\xd9E~\x8aIB\xb8m\xb9\xcf\x88*L\xcfH\xa7\xaf\xe7\xdf/\x05\x12%\x1d\xb2#\xb5\x8f\xdb~\x0e\xa5q\xf3\x9c\xc4j\xeazG\xa9\xa3\xabR\xbd\xa7\xb3W\xff\x9d\x7f\xd2$$u\xa7\x88=\x91\xfb\xdf\x91\xbb\x0c\x07\xfd\xe6\xa0\xe1\x0b\xdc\xbe\x93\x96)\xd7P\xe0\x0f\xe4\x16\x86\xdf:D\xb2C\x9e\xfe\xf9\xc4\t\xf1[\xedry:\xd8t\x863\x16\xc5%\xdb\xf7\xddV\x82|B\x0c\xe9|\x7f\x18\x1fR\xeeHgJ\xec\x81\xb87O\xf1\xbet-\x11\xf9\xd5y\xc9\xb8UX\x8c\x0f\xf5\x83+w\x1f\xfa7\xc2\x97@\x8f\xd1\xd1^\xebsH2|\x1f\x7f\xdf\xce\x0b\x96\x81.\xfd\xf5\xf10\xa8\xf3\x90\xd22\xf4\nK\x99\xfd\x9f\xc4\xd09\x13\xc4\xc5\xab\xe7\xae]\xca\xb1\x107\xcf>V\xda@\xb2V\x90=0\xbc\xd6\t\x88\x02\xbf\x89d\xf4{y\x9e0\x0e\x8f\r\xdf\xef\xdfvY4C\xf1a)\x8ek\xa6\r)\xb9t\naz\xb6M\xcf\x89?\xc9\x0f\x05\xde\xecWJ\x8a\x9d\xf0\x8c\n\x9fJ\xabv\xde[\xf9\xbaze5F\xe2n\xf1\xb7\x1f\x00\xf7\xf0\xad\x18\x9d\x90oN\xaa\x9b\xab;#\xf86M\xb7\xdaUB\xbb\xe1\x1aW\xe6\xdc\x02p\x1f\x1d\xadz\x8e\x80q\xbee.\x8a)f\\G\xb0\x188P/\xe0J\xd8t\x0b\xb0\x11\xf1xq]\x13\xbd\x1fA$\xe6`\xfc\x0c\xa1\x82\x12\xf1\x8a\xae\xc1\xbd\x85\xe0\xedam\xb9\xa4\x89\x8d\xb9\xa0/:\x8f\xdaV\x7f\xc7A\xeeYt\x0f\xf4\x92\x0b\xa6B\xe4Y\xce\xa2\xd7\xa5\xda\\\xe0\xbc\xf2\ri\xe2N\x8aX[sZ=\xcd[\x19\xe0\xa1\xd9w\x0b!\x16\xfb\xfc1\xd0\xb44\xf4\xc6\x0e\xeb\xe4\xbf\xc5Q\xd9\n2Ir\xd0\xce\xd3\xde\xd0@\xd9\xcf\x8c>\xf2e\x9a\xe4zH\x8a\xba\xa6>\x83JT\xc4*\xb2\x9e\x8e\xbe\xbf~\xd9~U\x0b\xc1\xa1\xae\xa9\xd0Y[\xe9\xfci\xe3\x14\xe9T z\x0c{\x93\xf2\xa7\x1c\xd2\xf5M\x91[\x19\xad^\x17\x9a\x8a\xbf\xa9\x87\x18\xd9\x1c_x\x93/d\xf8\x0b\x9c\xc2\x1bK\xe2\x00\xc8\x89\xd7\xbd\'1\x9d\xea\x14\xf9\x94j\xf0\x95|,\xa51\x12\x9d\xb9Pv\xc5?\x10\xbd\x99lI\x80\x99\x1c+|\xfb[6\xcb\xb2\x1f\xf4\xa8\xe7I\x85D7-\xf6\xf3nk:=R~\n\x80\x0b\xb4$\x12\xcf\xb3,\x9b\xb4\xb6T\x02hp\x08\xa7S\xd7\xd9\xea\xa4WK\xc5s/\xad&;\xf8Xo\xa9\xf7\x03^\xbfA\xe7\x7fM\xb4\x9fb0E^\x9e\xa3\x00\'\x8e1\x1d\xc1\xc4\xdd|\x03\x0c\x9f\xc4t\x1d\xddD\xea\x16f\x85\x93\xa3\xfd[_6w\x05\x1b{\xc2\x95\xc9\xd5\xd4)\x10\xf3E\xa2`\xb6\x81\xe1\xe2;C\x18u\x96\x12\xf5(|I\xc6\r(\x98\xe8y\xd4.5\x0f\x9eF\xc3\x89\xdc\xf0\xcf]y\xa1\x1bm\xb6\x05F\x8cK\x8e\xa7/+\\*\xda\xcbh\x8d\xa6\x96;*\x9f\xcdE\xed\x14\x8b=y\x8azK_\xc6O\xc9\xcf \x13Y\xdfw\xb6\xf52\xb7\xc8\xb0\xe8\x12\xe0\x9c\'\xb8\xc2\xde\x93\xc6\xfe\x8cM\xc7\xae:]\xe6/\x91\x81\x8f\xfe\xe7\xcf}\xba\x17hCJ\x18\xde\xe2I\xb7M\x84\xddO\xc6,\xd4}\x84?\xac\xe8\xc5Y j\xfd\tc\xee\xfd9\xd1\xf3\xeeC\xbf\xdf\xd7\xa8a\xe2\xdd40F\xc0\x8a\x9a\xf1{\xde\x05\xf9\xd7O.L\xf5\xad\x9c\xd33\xf5\x87\xb9@.B\x1c\xddi\xf4vk>m\x11\xd1\xdc\xa0\x03q\x0c\xb5\xf01nY \x1al\xe0\x8a\x81H)\x15,\xd1\x90\x0f\xc9\xe8\xcb\xfe\x869\xb3\xb6\xa3\xa4w\x0bF\x92y\x83\xf3\n\x82\xc8[\x84\x06\xda+\x81\xc2`\xe6d:\ry\xb2\xa1\x0f\xf9\x9f\xc3h\xd2\x86/\x10(\x10\xbbN\xca\x10U=)\xb4,[\xaf\x96\\\xb5}s\xa7l\xbe\x93\xef\xc3\xb2\xd2\xc2\xa2\xde\x8e\xfd\x19\x80\x17\x030\\\xb2\x83I\'\xf3"e\xffh\xaa\xa0\xa9\x9c\x9b\xadi\xb2?Ds\x84h\xa1\x91\xea\x03\xb0=-\xb2\x0e\xc0\xd1\xffI\xa7l]\x8e+\xe9\xf1\xd0\x98\xe6\x08\xd3@\xd06W\xd2\xd1\xd2a/\x7f(\x03\x96\xe2\xd2T\x80\xe0\x1a\x8ab3\xef\x0c\xb1\xa3+\xa2\xc3m\x89\x8b\x14dz\x9a\xb8pn\x1aM\x17\xb4\xa9I\x99x\xc7\x9c\xea\x9e\x19\x81\x82\xedWKT+~\x9d\xf1A\x140T\xfa\x05s,\xe3!\xc6\x1ed;1\xcf\x88{\x0e\xb7\n\x9eGL\xb0[\x9c\xf0K{\n\xfa\xcd\x07\x1c\xda\xa7f\xb8\xda\xaaM#\xdc\xe1h\xcc\x10:\x19d\xe2\x06H\xaeO\xe1\x0b\xa7R\xe4\xfd\x12\xb1\x83\x9f\xb7K(\xa9\x83\xd1\xc9\xb6e]"uA\xec\xdd\xbd\xad\x15A\xdfD\x15\xbb\x15\xe6<;\r\xcaI\xfd\xc8\xc3\xd2c\xd4zT,o\xa4E\xf1\xab\xce\xdc$\x8a\xd0\xe1\xa8/h\x1d\x15\\(2\xeb\x98[\x8b\xd1Q\xb8\x92\x05+rbO\xff\xa1\xa4\xfbe,p\xeb\xcdg7i\x9b\xdf\xbbi\x0b\xdc\x8dag\x99\xdb\xa7%\xe4*El\xc6\nY\x95\xab\xd5\xe9\x91d\xeag\x1c\xd8p\x88\x9d\xb3<\xb8\xa8(q\xf2\x06W\x1ckAz?h\x99\xf5\xa6\x8cSh4\x0b\xd4\xddl\xb8,\x95\xc0\x91xX\xf1\x08\x07\x1c\xeb\x90\xaf\xb0\x93\x9e\xe7Pf\'\xcaoN\xb7\xe5\xe2\xe0\x8aL\xefYH"&\xc8u\xca\xfc\xb5\tO\xddS*\x9b=~\xf5s\x98\xfb[\xc3\xf8\xb0\xf1\xe7\x93\xfe\xf7\xc4l\'\xc6ph\x91G\x85\xcc\x85W\xdd\xde\xafS\x16\x80\xba\xa9\x98%7\xe7\xf8A[h\x9b\xd9R\xa1\xf0^}*\x82i\xed\xd0\x19l\xe4P\xe0kz\xd4\x99F\x96\x83+5\x97\xb7\xdd6\xfd\x91\x98\xe0\xa6\xa0\xbd\xa2\x83P\xc2\xdb\t\x18\xdc\xef\x00\xb5\xd1\x14\xd5\xcdOt+9_\x15\xac>=1\xf3\x06B\x02l\x91P\xfe\xfa\x10CT\x8b\xbb\xd0cDIt[3\xee\x8dkz\xf3\xcd\x9c\xddZ\xeb\\\x08\xd7\xc5\xd90`cX\xe9\xb52FN\xe8kF\xcf\xa1\xbf\xa0\xf8u\xf1\xde\xe2m\xce\xe7,\xfcp\xd5G\x81\x13\xa9\xf0\xcc\xb5z\x94nukwb\xb7\xab|/\x9f\xf1Q\xa4\x10 \x16aS\x16&q\xe8\xc4\xb5\xaa\x9e#\x0e\x12\x8c\xed\xc5o\xd4\x81\x13\xe5_\x08f\x01 \x11\x8a\xbc\x97%\xc1\x14W\xd1\x89\xaf\xc4y?\xa3;\x19]\r\x02S\x85+sY\xba@[=\xe5\xdb/\xca\x1cIvI\x8d\xf2\xed6\xd4qe\x1eO\xf6\x11\xb1a\xdb\xa6Dhz\xac\x96\xd8\xf8\x17*\xf5`\x14`\x01wx\x19\xb2\xed\x80N\x06\xfc\x0c\xe3\x91\x88 \xbc%\xcb\xda\xdeh\x93\x0b:\xd9\x86O(\xaf\x81\xf7\xe4\xcf\x0e\xb5N\\\x9a^\xd1\x92IO\x15\r\xd3sY\x15\xd18^\x9d\xc0\xa8)z\xffy\x10\xc5\t\xa3}\x1f\x8aK\x8d\xa2\x8e\xaa5\xf7\xbb\xb9RF\x06\x1fj(\x97%q\xd7a\x18_\xb6\x0f\xe3\xd2\xe5\x1d\x02\xfawXg\x9e\x15p(\xa1\x85v\xafH"\x80\x1cf\xf1\x19\xa5f\x10\x04\xc7\xad_\x9b\x19\xe6\\\xd1\xef\xc85[\xa2A\xaf\xc6\r.\xa30\xcf\x82\x81\xbfV\xcb6\xd2a\xff\xfb(\x95\xc7$\xe4\xc1\xfe\xa6Z\xf0\xb2Z%\xbb\xf5\xd6]`S\x04\x85W\xcc\xdf\xc4lZ\x94\x88,\x0e1~\t\x05\xe1f\x07\x86\xfc{`/\n G\xe6\xa09\xc8\xb4\xadk%\xe5Z\x08=.\xbb\xfc\xf0\xeb0\x7f\xe9\xc3\xeb\x12\xaa\x9e\xeeI\x10\xccS\xbb\xb6\xb8\x835\xd6\xd8\xa0F\x1f\xc7$\xe8\x10\xa1%\x8d\x93\xe2/Y\xef\xe55\x83\xf8\xa1\x04\xd1|\x10\x13\xad\xe4\x10u\xdd\x95\xb6\x8a,\\\xe3\x98\xc8\xd8Q\x06\xacR;\xe5\x9d\x05\xf3\x9d\xff\x1c\xaan\t\xc2K\xec\xdc\x88\xab\xc4\xd2\xc4\x18\x1c\xb5\xb4<\xfa\xef\xf84:-\xce\xa1\xd5G \xca~\xec\x89\xb0\x9c\xd6.\xa8\x14.\xcb"\xa2L\xb3\xe0\x88Zy~\xcb\xb2\xc5\xa1K\xd7\xbc\x88J\x82\x86D\xacx\xdd\x04\xca\rG\xfe\x11\x19\x86\x1bv\xcb\xc7\x94\x96\xed\x92\x80\xeb@\x80\x17\xc8\xd8#j\xea\xc6\x10\xa8\xd9^\x10U\xd5\xd2\x19\x92\xe6\x91\x912\x14\xd24\xb29\x1e\xc6\x16\xb9\xb4\'\xc2\xf6\xcc=\xa9\'*?\xa8\xb1\xf5\x91\xf8\xb7\xcc7\x13.\xd5e\xda&X\xe2\x1fMA=\x11T\x1853}\xfe\x82\xfb\xd0%1p\xe0V\\d\xf5\x88A\x189r\xa7\x1f\xf2ol\xbe\x12hzz\xc3P\xd3\xa4\xbd(s\xab\x84X\x17\x04\xda~A\'\xe2\xe2\xb0\xfbE[\x9f\x01U\xcaz\x8e\xcf\x17\x03\x03\x00\x1aD]\xcbq\x06iS\x8dTXD\x96xF+\xc8\xf2\xf1\xa2\xc5\xd4\x9a\xe4\xb1z\xdd\x17\x03\x03.\x1e.X\xbc/\x04\x0e\xa1~CZ\x10\x80\x15\xb3\xf8\xb3\x94:{\xee5\xb8`\x89\xb5\x82BW\xf7\x9bi\x92\x10;\xe8\xed\xf7\x8b\xac\x9b\xc5\x9c\xa7\x01_\x9e\x81B\xb4\xd4\x1c\xa1\x95\xb0 \x9a\xa9\xc0\xaa*\xbd\xaa\xc8\x84T$\xd4\xdb\xc3"\xa1\x14[\xc2J#\xf9\xa0h\xd5"*)\xbb\x04\x18\xfad\xabC}\xa6\x05\xbc\xd8<UJ4\xd0%\xd4+\xff\xca\xa2\x06\xe8\xd2\xb5\xe7i\xbc\xe2\x1d\x14\xe6\xb7\xcc\x91l0\xc1\xc3\xe8\xde\x11R\x82\x92R\x01s\xe4\x9b{\x1e\n\x8d$\x9fQ:\xc9\xa8\n\xc3\xba\xceX\x99\xce\x02\xc5*\xfe\xd3\xc72F\xc8\xe0\xb1y~\xa4\x88\xbb\x8f\xdc\x96\xb3\xb7\x14\x14Z\x10\xe3\x03\xe5\xeb+\x01g\xda~\xe6\x82\xe9\xb1\x8f\x05\\\xbf4\xf6\xe6\xcbfN\x0eh\xabr\x99\xf9\xf5\xf7\x89\xc8\xc5I\xdd\x1f\x81z\xc1\xcf\x18:\xd5\xb3}\x9b+\xe2\x00\x85\xb8\x92q\xe6\x0b\x1d\x11[\xb9\x11;\xd4,Y\x10L\xc6\xd3\x0fWYTq4\xbb\x90\xfe5\x82-pj\xd2\xb6Xs\x05Rp\xa3\xa9Pu\x0f\x99\x81\x16^-v\xe6\xd1\xa6\x84\xf3Z\x8a\x06\xbc\x97\x8d\xf7l\xee\x08\xd5\x92\xf2B\x15\xe3\xc5\x85\r\xf2\x1d\x9a\x88\x90\x0c\xc2a\xb8\x98\xe2\x82\xa5\'\xf6\x85\x1d+\x8a\xa5\t;@B%\xde\x84\x86\xa10R\x93&\xc0\x1cb\x81R\xceO\xf73\xa3\xbdV\x86Mv\xdfw\x8a`\t\xeb\xff\x01\xe3h\xec\xc3\xf5\xf1e\xa8\x05k\x9a\x96>\x14\xa9\xe4\xdc\xbcX\xc0\xc0k\x9a\x97\x01\xa9\xfa\xfbxT\xdfS.\xc5B\xb7\xd9\xb4\x99\'\xfa\x9f\xf0\xa0\xa1\\\xf1^Ry\x87\x14g$\xd6)\x17a\xa1\xf8_\x03\xc3h\x9d\xc4(\xdbk\x08\xf3\x8a\xda<\xd4\x9c\xcc\xd1\xf4\x11o\xd8\xf1\x9bS\x15\xea\xfa\x87oB2\x90]B\'\x86\x82\xdc\xc5e\x94\xe3E\x9f,}\xd0/l\x9e>\x07W-\x98\xa2\xdf\xbd\x1e\xbd\x91d\xe1Y\xea3X$|\xc3\x1a\xa7\xf2Mw\xc9d*\x92\xf3#5jr\xc8\xcc\xc1l\xd5\x18t\xec\x99(\x9c\x8d\xc0{\xb2\x85\xa7v\xe7\x05\xaa*\x0e*\xb2\xa0k3\\\xd3\xd3\xe6\xef\xca\xb7`YL\xb9,\xc3S\x1b#t"A%\xe8\xb5l\xdb\xc9\x9c\xb6\xac\xc6\xb7m>\xa4_\xe0\xf9\xdc\xc4jl\x06Tn\xf2\x08l5~\x12i\'\xe6j.\xa6\x8aNWX\x83\x0f\xca.\xa4\xe9J<\xf9\xef\xed!\xc8\x1e\xb2fGuB\xe4a\t\x1d/\xd3\xcf\x07y\xa2\x14\x1b\x05\x8d\xa66\xd5\x86\x06\xd6\xbaE~t\xac\xd6KAS\xdb\x0e\xcd\x83\xf8\xd8\xb8\xc6\x14sEo\xd8M\x81\xcfr\xf4J\x8a\x8d\x13+!|\x88\xc2\x9d\xa3#\x8e\xcax7(\x860#\xfe\xf5\xe6\x05:<\xac\xd0E\x15\n\xbb2\x01$\x9c\x15\xb7\xe3\xba/q\xd9\x9f\xb3\x8a+\x18\xb0\xdc\x8e\r\xa4\xe4)\xce\xa3\x1f1\x13Ex:\x1a\xd1\xfe\xdf\xa4\xdcy\x98!DR\xd5(.\xe6U\xe4\xe4\xd9\x96\xa3\xa2\xd7\xad~\xf3C\xf3N\x81\xfeD\xf1\xd5\x18\x94\x8f#\x89\xe2`R%\ns(\xe4\xa9\rZF\x95\x1fX\xcdd\x87\xb4\xb7\x85\xfa_\xee#\xdf\xafH\x97K\x98t\xa3i\x9a\xd8\x8c\xc5K\xf8J\x89\x80\x84\xccMg\x97\xab\x9e\x18\xa6t\x9c\x800\xc2{\x0fb\xa9?;WV_73\xb5\xf2\xad\xfb\xc6\x1d%\xe8[\xe8\xdf\x88\xdeU\x8fz\xb4\xf1-\xac\x08\x05\xdf\x14\xf8\x87\xb7{\xfb\x14\xebR\xb4\x85\xe4\x14gL\x80\xa0\xbdk\r\xf3\xc20\'\xb5\x0b\xb8\xbd\t\t\xaa\x7f\x0f\xfc\xbf\xa9\xb3\x05{<>hW\x0e\x1d\xee\xb7\xccb{a\xa7\xb3\x95\x1b\xff\xfa\xdc\x13\xd4]\x06!{\xd6\xe6)\x83\xc3\x19[\xa7O\x84&1Q\x83\x1e\x1e\xea5w\xb1WQ7\xdcD\xf5\xea\x10\xe2\x1d\xb6\xb1i\x8f(\xc52\x91\x9bi\xd37w9@\xfe"\xbb\xc0\x91\xb8\xfbZPF\xe4>\xe8\xc2h\xf9\x0f?$\xd6\x1d\xf94\xcbD,nDb\xfe%\xd1BD\x1d2\x08\tt\x85%\x05["\x0b\xce\x0e\xbe\x00e\xa9\'\xf7\xdbx\\\x85w\xb3F\xaa%?\xe4\xf5WN\xb6\xda\xe3e\x80?\xb2t*\\kR\xa8\x95a\x13z\xf9\xc6W\x82\xd4\x15\r\xdf5\xbd*\xdb\xd3\xe3;\xe9\x8b\xc8\xa6\xe7\xaf\xd97\xa2p\xdc\x83\xc8WIcr\xdcJu\xa8(\xc4<G\x1a\x00h09\xa0\r\x81\xdd\x87F\xc93\xba\xf3WJ\x00NE\xfb\xe3T\x07\x0cE\x98n?:\xdemL\xa4N\x9c\x9b\xd4\x8f\x96\xb1\xf6E\xd9B6\xb9\xc5\xda<\x96\xab\x8c\xc3=\xd1\xc4\xae\x97\xcf2t,{_\xab\xe1\xc8Z8!\x9f\xe6_\x0f\xec\xc7\xba\x11S$(\xe2fJa\xaa\x89\x03\xd5P\xbe{t\xe8\xac >}\xfaL\x98\x14\x83\x8cn\x1f\x84\x00\xa3\x1c\xf9\xae\x9e\xc2\x04\xee\x9d\x9bO\x00a\xe5{/\xa5\x01\x1c\xe9\xa8\xbb\xddi\x9c\xe7\x9f\xde\x16:zS\xe0\xcf\xfa>\xc6.\xbc\xdf\x10c\x86\x03\xe6-\x10\xd7\nu;\x9cL\xa2I"\x11\x93+$\x1b\x04/_\x98Ej\xfa3\xab]e\x0e[\xdaG\xe7\x92\xd7\xca\xc8K2.\xc1e\xcf\x92i\x94\xea\x06t\xe2\x11\xbd\t\xbd\xf9\xe2\xfb\x9ew\x02^\x84\x17\xb3\x03\xd14\x7f\xd4\x8e\x9b\xceO{K\xe0\x86\xfeo\x13\xc5\xbc""\xf8\x97\xc28%\xba\xe2\xd7\xe5\x95X\x07\x8d4\x8a\xf3\xb0={\x9bd\x0cJ\x0c\x99k;^\xd1\x1f=\xaf\xc8\xfaVLL\x16+\xf1\xef\xa6\x9b\xf4\x87"\xe9\x1a1\xde\xb7\xde\xbb\xf0\xcaF\xa3\xda\x07\x04\xb0\x81\xc5\x92\x96/j,\xee\x88\xaaD\x8f\x1a\xb8{\'\xc0O\x0flR\xc1\x7f\x04(\x7fX\xf4\xa3\xcf\n\xd1`\xfb\x94Dz\x85\x01\x1b\x02\x18\x08\x98\x9c\xd7\xf2,^M\xe7\x94\xceG\x16\xe9\xcdr\'k\x89\x19,\xd4\xcecZ@\xe3\x9f\x97\xb91\xb4e\xb0\x9e\xba\xf4\xa0\xb5\x85A<Z\x08\xf3\\|\x02\xa6Y\xadM\x05\x87\x91\xf2;\xe8\x1b\xad\x90\xa5j\x03\xcfD\x9e\xc4\xac\xc4\xa0\x9b\xa2\xb8\x17\x97t\xd3\xe5\xbd\x82\xd7\xf32(\xbc)\xb8\x86lK \xe6\x92.d\xf8\x9e\xc9Y\x16&\xc5,/>\x96\x14\x06\xbbN\x083\xd2\xcb\xd9c0\x82,N\x07=\xe5\xda\xcd\x01\xc2\xfb@1\xbd\x0b&\x8ac\xb7\xee\x90\n\xc0\xb7\xc4\xd4C2\xa5~\x977<;\xc7v\xeewAt<\xd2&\x87vd\x08\xd3\x84\xc9\xa5MZD2\xeb\x85\xa6{\x04\x04\xf5\x8c.\xe79\x12\xfbq\x10\x94\x8b\t\xfb\x17\x0f\xf7\xc8\x8a\xab\xe1\xed\xc7"\xdbTX\xb4\xc4\xbc\\\xf5J\xca\x908\xcf\xef\xe5\xb6\xea-P\xc4\xe7+\xde\x90\xdc@a\x896\x0b\xfeKY\xad[fB\x13\x8d\xdf\x04\xa8\xd8711ut\x82\x9f\xc7\xb3\x08\xef\xfc\xf6\x0f\xdf\x90\xea\xca~\x08\xa7\xa5R\x85\x14\xfcSj\xeff\x9f\xa2\xc9\x90\x0e?e\xa5\xd8\xd9\xff\x9f\xd1\x03r\x92g\xf6\x98\x8f\xb6\xb0\x0bc\xca\xe4\xa4\xe8\xd5\xfdg$\xdcR\xf3\xbfI<\x12\x8f\x89o+\'\xe3G\xf7`\x89\xebG\x8ci\x19\xa6J\xf9FY\xb8\xce\xd0\xbe\xbf\t\x99\xc0\xb9\xe2\xd0j\x17Y\xa4w+\xe5\xa9\x91\x9c\xfa\x8f\x9b\tyt%\xb6\xdd\x8dv\x19\xf0\x9b\xaau\xff\x96\xf5\xe3\x8c\xa4\xedOu\x8d\xa8\x0f\xda\x0e7\x82d=\xbf\'\x8d\tPo\xb8\x8f\xf1Vj\xf4\x16\xe4P\x8b+\x14*n\xdc\\%\x17y\xa5\xe3\xa5Q\xe0\xd9\xbd\xd0\xf8\xff\xdd\xad\xe6\xccQ\xffj\x83\xee\xbc\xea~V\xdc\x04\x0e\x8b\x8dJ\x06\xecB[\x07\x9d\x1c#\x8b>\x1e\\\xcf\xc0$\x0c\xa9c\xbcg\x83o#=\xd9\xb8\xf3Ne\xc5\x81IM\xd1\xc6K\xdf\x11p\xd0\x18\xafAR\xe8N?\x06\\\xba\xf50\xf7\xb5\xbb`\x8e[d\xa9\x82\xee\xc8H\x0e\xd7R\xcd~5\\G!\x86\xa9\x84\x98\xf8,\xcb\xac\x97+p\xdd\xb2\xac\xaa\xea\xee\xa5\xfcR\x05D\xc8{x\xb7\x81\x06p\xabZ\xd5P\xbd\x12\xab\xf9\x96.m\xb4\xb2m\xc0\x05\xd9S\xd7\xde\xc8\x91P\xf5\x97\x00D\xcd\x87\x7f\x97\xf3\xa4*\x87\xe5\xe1\xf8\x1c\xc3\xc1*\xcfOs?\x12\x0fF\xe0\x9b\t\xa7\x0f\xa1\xe1\xd4%\xd6#o\x99\xf0`\x97\xb6{\xae\x85:\xee\xe5\\\xb9\xe9X\xb2G\x00\xd5\xf4\xea\x9c\xf8m\xb9\xf8u\x80\xca\x9a.\x8b\x9b\xfcFFh\xbf5\x9b\xec\xc2\x06\xf6M\xfe\x04\xf1\xc8\xb8\xbb&G\xef\xa1\xe6\xa8\xc7-\xf0li\'\x91\x8dn\x08\xb8\x84\x00ze\xa1\x0c<-\x8e\x12\x12k\x8dr\x0c7\x1a\x15r\x84$\xb5\xb2\x15s\xf5\x1f!\x1a_3\xb7|\xe6=\xc3\x13\x1f\xed\x1ePI_$\t\x9e\x03_\xcbwIsM\x8a\\\x89\xea|p\xaa/\x14\xfc\x81\xd6\x1b\xf1|\xca\x1eg\x17B\xa9\xa1\x7f\xbeZ\x81j\xd0\x80r?O}\x9b\x93\x87\x88\xc6F\x14\xec}\x836^\xd79\x1fX`v\xfe-\xf3\xc1N0\xc6\xfc\xd3\xc9\xef\xf8\xe1w\x1d)\xef\x16\xeb\x0c\xe23\xe9\xba\\\xa8\xeb\x04r\xc2\xc9\x19\xf9E\xf3k>a\x06\xdc\xb2,&+\xdf\x7fj\xd1\x7f\x1f\xd8\x1c\xdf;\x14\x83\x04\x8c[\xd4q*\x1cH\x18\x95j\xc7\xef\x8b@[&i\xe73~\xc5["\x8d\xc7\xe9\xd45\x1e\x1aa^\xe2\xa5\xe1z\xc0\x8c)7\xff\xe51X\xe7\xd2K\x8d\x8b\xa6\x9e\x9e\xb6m\xd6y\x97V\xb2\\\x9a\xbc\x03p\xf2^\x99-\xa20\xef\x93\x89&3\xd4X\x00u\x94hj\xeb\xab63v\xfb5\xa4P\xd5\x00J\x9f\xef\xad\x86\x17\xa0|v\xa1j\xc0\xa6~\xdbzY`\x96!\xe6\x08OQ\xff#\xdf\xea}rx\x97\x05v\xde4 \xea\xc1ob_\x95\xec\xe7\xf4\xc7%\x84\r\xee~\xcc \xc4R\\\x0b\xa4\x9e\xc3\xfa\xfd\xf1\x07\xb1\x8e\xee\xd9\xa5\x92\x96\x13\xc3\x1e\x9e\xf3C\xae;\x9f\x9d\xe7;Uf\xf6\x86\x8b\xc2\xba\x80\x12\x12\xd0\x97\xa1\xdarH\x1f5,*\xe0/p\x02~Tut\xe0\xc9\xf9Z\xce\xe55j\xc8\x0e\x810\xedq\xbc\xc2S\xe5r\xc2\x08"T{\xb9\xfd\xd6*\x81\xd4\x04\x95Gr\x83p\xf7V\x14\xdc\x8e\x7fhI\x1a`\x14\xeb\x81;B[\xf7L\xe5\xef\xac_\xda\xbb\xb6\x9b\xba:^\xad\xf0\xf2\\\x14\xa2\xf6\xfe[Z\xccuB\x8d\x0e\x7f\xb9\xd6~\xda\x80\x06\xebz\x18\x9b=q\x81U\x8bm~\xf8\xf6]\xfb\xa5\x9a\xbfV\xa9\xdc\xcb\xa5\x02\xd5\xe9 +\xf9\xce\x7f\x1b\x98\xde\xfe^\xcd\xebXu!\xfa\xebf\xd63R\x04\xa6\x07\xd7\xe7\r\x8f\x7f\xde\xf7\x97\xc2\xb3\r>\xe2\x95\xe1\xb58\xea\xa6E\xc4\xd2\xa7\xc8\xbf)\x94\xf6\x0f1M\xe6\xf7`\xb9\xaf\xb5f\x16\xfe\xd6\x1bn~pS\'3\x1b<#\xe6wE&#\xe0\xd2j\xc2\xd3\x99a\x13\x85\x92\xaf1\xb8\xe8\ra\xaaj&\xeb\x15XN#\xe0;a\x99\x843U\x8a\xcc%\x08o\xa4;nn\xa4\x83\x8f\x86W\x06\xeb\x08\xb1PA\xfe\xe5o\xe16\x05K\xfbt\xa5l\xb8\xcd\xbf\x9c%\x8a=\xed<\x0e\r\xf3\n\xd7\xb4\xd6\xc4\xed\x9c\x12\xc4\x9ay\x95\x99\xc0\x97\xbd2\x89(\x89p\xfbG\x1a\xd6\xf8q\x1fs\x95f37\xaf\xa5\xffdk\xaf\xfeb\xca\xc6i\xa7\xeb\xce\x9c\xf3\x80s*b\xd4r.g\xc5o\xa2\x17\x81\xd6\t!\x8b\x1a\x8f\xc7\x97\xef\n3\xb1h\xda\xcbo\xa6\xf9q\xce0\x97X7\xbc\x9aD\xd8\xae\xd7\xca\x1f\xdf\xcd@r\xe5\xfe\x02\x07\x1d\x8c\x12\x8fR\xbb;d\xc0\x94\x0b\xd6h\xf4\x98\xff>\x1e[g>4\xf5<\xda\xb2<IN\x81\x1c\xd7{\xe6\xa8P\x83\x19\x15\xf6\xc3+\x8f\xb7\xd3\xb4X \xf1\x8a\x00\x8e\xbd\xbaA3o\xa72\x83\x84\x13\x0b\xac\x00\xa8j\xf8B\xf6\xdd+w\x85\xae\xf8\xa2\xf2rfm\ro\x16\xe5\x8e\x9f\xbc\x9f\x98d[\x16\x97m\x89\xeb!\xc42!\xd4y\xbc\xd1\xd05\xfa\t\xb4\xb7\x1a[\x81f\xd1(%\xde\xbf\xed\x18\xefO\x8e\x08\x89\x96\xda\x90\x81\xe2\x07{l\xdb\xb6\xa5\x97ES\xbe\xea\x19s\xe22\xf6\xf7\x1a\x91\xe1\x9f]\xd4\\\xee\xaf\x1fa`A\xa7\xfa\x19\xacn\x9c\xc6\xb8e\x8e\x00\x07\xca\xffi[%t_u\x90\xcc\xb9\xe4\xa3\x14qr\xdb\x0c\x07[\x9f\xb9/\xdeJ\x84u5e\x18\xb2\x19\xa4}\xb4\x01\xf4B\x16\x84\xd4\x93\x99\xd8{2\x10\xf4S\x05\xe4\xeb\xb8C\xd5\x99\xb5\xdb3\xa8\xb7\xfa!\xda\xad\x1fX\x00\xdeqB\x91h\x8fN\x05\xa9 \xb1\x9b\xa62%\xc4\x80\xccCY!r!\x8c\x80\xfa\x92]\x82\xe3;\\\xaa/\x9a\xf7K\x1b\xf5\xf7\x92\\\xca\x1as\xe6\x8cO\x05\xe3PKK\x9e\x93p\n\x17\xc0%`?\xbfx\x8c\xa0\x91*\xeb\x0f \x8a\xffL\x14;\xa4\xb4v\x15\x03@M\xa6\xdd4\xae\x0b-\xf0\xfe\x04$y\xdd{\x17\\\\\xf5\x8a%=z\xf3X\x8b\xb86?i\xc2\xba\xb5\xd5\xe0\xff\t\x16\x8aj\xd0\x97\xf6\xda=\xbc1\xfc\x07\xc6#\x0e\xe0\n3\x9c\xba\xe7]\xb0\xc0\x10E\x01#\x83<\x017\xc4?\xc6\xc9\xe7\x13\xdd\x15\x984\xf8v\xb6Mn\xd4\xbd\x1aW\x91\xf9\xe1\xd9d,S\xb0\x14\xc2N\xeb\xb2\x1b\xaa\xc7\x06\xf3\xa1\xcb\x7f\x15\xf2\x97@ah\xffG_X\xfb\x8d\x83\xc8\xe5\xb3&\x11\x17\xe1\x99$\x9a\xb1\x95\n\xd8\x1e\x1f\xa1\xc9\rf_\xfc\xd1\xcd\xb2\xde\x9e\x12z\xb5\xa4z\xf3\xb8\xf2\x03\xcd\xa4\x9b\xe8C\x01\xb1\x8eu\xffB*7\xd9{Zf\x0c\x9f\x12@>,\xe9\xc0\t,\xa0\x85\xc3\xa6C\xf4\x91\xc9_\xca\xe3\x94\x1f\xb3E\x12\x0c\xe8\xcev\xcd\xb1[j.\xa597\x05\xa1x:\x98\x110\xe3K2Q\x01\xb9\x8d!\xc7\xc1\xa0G\xecH\r\x19\xd2d\x0e\x14%\xeb\xb2\xca mZ\x02\xaf\xff\xc8\xd1\xe0\xe8l\xc3y\x1e\x96Wm+\xde7\x06S\x83\xcb\x19!%\xe7\xffAK\xadw\xa4\\^\x96\xd2(\xbc>\xda\x8e\x08\xd5\x1dF\xa2\xd6(\x8e\x0e\xaa\xe3\x93\x91\xff\x1f\xe97\x12\xa6\x01x\xdb\x1a\xbco\xdfc\x18lw(\xf8\xdd&\xf9\x89\x19?\x07\xd7<\xcbwN\xac\xd4?\xd4\xf6\xce(1Z&\xf41^*\x1ce#P\x0f,j\xab-\x00\x17\x9dM"\xd6L\x9etV\x8co\xe4\xf9\x93\xe7\xc9$\xbf\xf97H\x0f\xd9\xa9\xb4\x0eJ\xfd\xf4\xdbJ\x11\x0b\x97\xd5t\n\xbce\x86\x08c\xc8\xd5\xc8\xc6x\x99W\xe0u\xa7FD\x0e\xec :\xb0\xb0O\x86_U\x19\xa3Rk\xd0\x86%\xa9\xef\xb4\xe6^9\x9a\xf8\x1e\xcc\x89\xf8\x7f\xdd!\xc6X\xab\x1bI\x820\xa0\xae;\xb6K\x8a\x088\x96\xaf\xf6;G\xc0\xfb\x1e-\xd4\x95#5\x9a.\xa2R\x9a\x8d\x83#\xed\x88\xcb\xb8@\r\x8b\xe9C\xc2\x85\xf5t:\xf2\x10\xf5V\x0by\xd3zv\xbe)\xc3\xb9\xbb\xcc\x16\xa2\xc0\x81S\xac\xdd\x8bl\xc1\xbb6\xcb\x85\xa4\x07\x81p\xb46/\xcc\xef_\xf4TY%M\x11d\xc0\x19bR4\xe156\xac\xcf\xf5/\x02k\x1f\x0bK\x03\xa2\xe3\x86\x81\x10\x88=\xb1\xb0o+\xa1\\H\xec\xffXi\xd9\x00\xf2\xdb\xa6fU\x8c\xb9\xac\xdd\xeeJ\x0b\xf6\x12\xde\xa8\t\xb5\xe2\xfc~u\x84{>!K\xcc\x9a\x8b\x13\n4\x82\xe0B\x98\xaf\x13\x93m\xcdg\xa5\xfeR#\xab\xaaw\xaa\xd69\x1c\xcd\x99\xa9\xa9\xc5\xed\xa7\xde\x06\x98\xc65\n\x03Vd\x9c\xc6\x81\x05\x03\xb7\x03\x92\xf5\xc7|\x01\x92\xb79\x83$\xab9\xfc\xb8\xa8|\xdb%\xb4a\xf9r\xc4\x88\xad\xc0\xe9\xd5*\x10b\xfe\x14\xe0`\xaewI\xf8\n\xd2l\xfa\xd4\xfa=\xea\xfa\xc8\x91\xfd\x9a\xcd@\xc61\x02\x8f\x87\xf8^$\xccY\xf99\x9b\xa0=\x19\xac\xcbvz+\xc8N\x19VYV"\xc3Ni\xe9\x8ev*\x8e\xa1\x99rh=\xe2~\x96\xce^\xede\xbb^\xae\xe6\x17\xfc7l\xe4\x1f\xb1\x1b-w\x92Z\xf7d\xcd@%y\xbb\xcda\x0e\xf8ht\x94\xc5\xf5\xad\xef\xc2mh\xf9\xe7\xafv_{\xdeW#O\xb5\xac\xddb\xbc\xee\xe4\xca\xae3~\xddhD\xaa\xff\xa0\xd3\r\xdb\x99\xec]\xd8|\x06Y\xe2\xfd\xda\x01\x14\r\xc4\xfa\xab\x99\xe1\xc6\'\x92\xa0bS\xddV\x86\x02\xdf\xcfK\x97\xef\x9a\xfe\n\xbf\x10\x92?\xd1\xc7A9]KyK\xfe\xed|\xa1\xab=\xdbm;\xfc\xabNE\xb2\xf8\x00\x80\x9d^9\xe9\xfe~\xd3Eh\x8d\x83\xa9P\xf8M\xe43}\xe1\xbf0\xdf\xd9\x9e\xe0\xa9\x8a\xbaFW4b\xa6\xd4\xe7\xddVV\xe4L9M\xa8\x80\xe2\x89^u=\xee\xd645[\x10\xc3\x97\x0f\x81\xf7`G\x9e\x9c\x85\x0e\x8a)\xb1e\x90\xda\xfb[\x058\xdfG{\xbaq3\x98g}\x10q\x8c\x80\'\xa1\x89i\x86\xc1\x95\xdb\xe5T9(\x1f\xd3g.s\x82\xcb\'-p#\xa9\t\x1b"\x89\xc3e\xf0\xc3LF\xc8[l\xc7\x0e\xe2\r\x88JR\x188\x02jVHCx\x02\x16\xce$N9\xcf\xd9J\xc1Sx\x10\xd1/,\x87\x14e*\xa5\x99\xc0@\xfc\xda\xdfwu\x11\x11\x9d\xa8x\xa3c\x16R\xf4\x87/\x91*\x8a\xfd\x8ee\xceM\xa8T\xba\xe6R\xd3\xd4\xaf~"\x83MV\xd5\xd4e\xac\xf8\x86\xb1\xce\xa3W\x1d~[\xf6\x1d\xeb\xe2$4\x87J@\x81\xd9\xcd\x95\xa6\xab\xa76\xb2\xba\xf53\xa7\xc6\x1c5\xa1N\xa3o\x1a\x8a|\xf6.3r\xb7+\x99\x7f\x87\x81\xcd\xb4ET\xa8\x00\xe7s\xb5\x0f\xec3`\x85\x1e\xa8\xb0"\x97o\xd3DVO\xdf\xeb\x16nJ\xda\xd4\xa5\x9d\x13\xc5\x9e\x87\xc6\x06J\xb8\xf9^B\x9b\x0fS\xb2E\xd6\x8e*\xae\x9b\xd2\x82+\xab?\xcc\xc31~&!\x19#\xc3\x96\x10V\x92Ig\xaeH\x15\x96\xc7\x94\xfa~\xb2\xf3##\x05u{A\r\xcaBqb\xfb\xcd\x8dvn\xb2\xbc\x86|,\xbcx\xe5\x81Y\xa2M\xcc\x02\xbf\xf5\n\x8b\x8f\xe9\xd2\x9d\xfd*\t\x94\xd1$\xc7_\xba\x8ciH\x05\x9c@\x01q\x8e\xe6jl\xe1\x1c\xbf\xabjA\xe4I\xde\xb2\xbeX\xf1E!\xa3\xb3A}\xbdV\xef]\xcc6\xed\xb3\xa2\xd6\xd5|\x85\xdb\x8f\x04\xac\xf3\xec\x920\xc7c\xa2\xa90\xb5\xbd\xf0%\xba\x96\x03\x89,w\xbbqP\x0c\xec\xc0\xe7\xf2\x1d\xf3\xc0U\r\x82M\x0c\xb2\x1f_uT\xc5,\x9f\x85\x0cD.\xa5\x11p,\xa2\xefC#z\xb1\x90\x93 U\xa8\x1d*\x85\xa4[#\x16\x0c\x11l0\x9c\xed\x9c\x03\xa6\xe6Qsg\xb7\t2\x100\x9a5\x15H&\xb9\x83\xda\xdf\x18\xa7\x8c\xbc\t\xc3\xa4l\xc7\x05\x87\xc4\x9a\x00\x95\x82;\x85[g-I\r\xb34\xd5\x03(\x9d\x1c3#5\x05t\xd6e\xa8\xe0\xea\x1e\xf2\xc2g$\x1b\xc2[\x01\x0f\\Y\xaba5\x1f,\n\x19\xe4\xe9\x88MO<\x93#{\x8f\x08\xe4\xbf\xd0\n\xdd3)\xebe\x88^^Zj\x01\xf7\x1d\x06\x8ci\xa0\x88\xcbf\x92N\xa3n\x99\x18\xe7\xa0\xd9\xbd\x0b\x1d\x9d\x04g\x86A\x8c\x9a=3\xfd\xd4\x90\xf4CnC38\xd2\\u\xdc\xd9\xae\x0cDN\xca\x9e\x1c\x96\xfeOa>\xb6\xf9\xf5C\xbb\x00CR\xf6\xf0\xd2V\xe5C\xa1h\xd7\x06\xa2!\x18\x8b\xf4\x9f\xff\x1d\xa6\x1b\xa6]\xf9?\x16\x9a\xdc("\xf0z\xd3\xdb\xa6\xa4\x8c\x81\xb0\xa0\xb6\n\x1f\x8d\x84\xca\x04\x03\xf4|\xc9\x0f-\xa3\xe6\xec\xbf\x9c~\x87\x8da\xd3\x81\x1e\xd3\xd0\xa4)\x84^\x86\xee\x82\x8e\x0b\x0b\x99\xa8\t\xd5\xc3\xfd\x81\x84\xdd\x95s\x19cE\x83\xbf\x9b\x83\x80M(\x8b"\x8f=\x0e\xaeJ\xdc;\xf0c\xaa\xd2\xe8\x86L\xfa\xee\xe5\xdc\xbbh\xcf\xa8a\xca\xe6\xbf\x00\xd5Z\x99\xbcZ1wm05\x98Xtv\xda&ll\xa1\x0c\x89\xfaG,\xb4v\xac\xed\x0b\xaa\xca\x083\x01X\xab\xf1\xf1\r\xf9(_\x8eW\x90\xc6\x86O8\xc5U^\xbc\xd8;\xdb#\xee(\xa3\xd6\x81\x97\x15_P6;\xeb\xd0 \x89\xba\xebM\xfeu\xc1\xa8$\xc4~\x98\xe1\xed\xfc\x1b\xe2\x1f\xf3\x1f\xd5\xe6\x01\xc7\xaa\xdeD\xb5\xed "\xe8\xd7\x98G\xac5\x8c\xcf\xbeEU\xa1u\x8cRXb\x8eg\xe5\xb2\x10\x96P\xc2\x93&\xb0\xdf\xdc\xf3\x10\x10\'H\xa9\x03\xd4\xbdd\xf3\x8a\xc64\x15o\x90L\xc7\x12\xeco\xcdQ\x0cfV\x07\xec\x19\x01]g\xae\x12\x8c\x02\xe3z\xaf#\x12\xf1rF\xf86\x0e`\x1b~-\xa6m\x8b\xa0\xad=\xd9\xdc-\x05\x98db}!/)\x822\xfc\x1f\xf1\xf6\xff\x06\x1c\x90\x80\x90Ry\x04\xab\xf2\tk\r\x06\xd2\xb0V|\x0c\x8f\xd5Q\x0b\tZE\xcb\xd8\x89\xdaU@\x19\x95\xc44\xf2\xe5\x11\x04\xb3\xe2nB[\xabU\xceQa\xfc`\x98(\xe9\xe1\x13\xd9}\x9c\xa7gW\xb9\x18z\xca\xd8\x95 8\xda\x94p[b\xad\x10U\t\x0e\xb6\xa1\x9c\xce\xcd\xdf\x7f"\xac\xb9t\xff\xac\xd5w\xce}\x89\xa6Yb\xf0.\xe1R\xc3\x0f\xcd\xd4\x1f\xd6\xe3\xe4\t\xfd\xb0*\x82\x91\xa0\x8f\x02\xc0\x08\xf8\xf4\xbe\x8ct#54\xc6\xe3\x9b5\xb8xv:\x8e\x815g\xc4`\xdb\xa7\xd2\x81z}\xac\x00\xfeE\x93\x8dQ\xb0LS\xb7\t\x88\x17\xa3\x80,\x1f\xbc?S\xe5\xe4\xcbV\xa2\x11Zj\x04\x93Y\xc8Q\x0e\x82<h\r\xb3Y\x8fbt\xc5\x1fs\xb3\x9e=\xfc\xd8\x88~\xf4\xef\xcf=\x84\x14\xfdS5g\xf8L\xbf\xcf\xf0V \xf2`\xee\x94\n\x90o?\x03\x97\xebXZ\x8f~`\xbay\x0e\x99}I\xe6\xa2O\xe6\xae\x81\xcfb\xabD.\x0fo|\xb0\x93\xcb@\x93\xdc\x19\x9c[i\xf6T\xb0V\x8bJ\x15d\xf0s\x9a\x9dc\xd7\x07\x16\xa6lp\x049\x00Z\x15^\xe8\xa3b\x86P\xfe\xf0\xd3\xe1\xff9\xca\x158\xd4\xc9\xa4\x14\xd4\x0b+\xebG\xbd,r\x00Hd\xdfK\xe9\x84\xe4O\xa5\x14.\xc0\x88\xc6]\x04\x90f\x88]\x10o\xea\'\xfd\x1dsy\xc9g\xf0\xef\xc0\xfd\xfa\xfc\xd3&\xab\x06\xa6\x89\x95!\x95\xe6\'\xb5\xa6\xc0KXZ\xea7e\xab\xac,M\xc4u\xe2\xf3\x9c\xd6\x80g\xec\xdbw\xa5B"\x00\x99S\xf8\xdd\xa5%76$%\xa5\xc8"\x9b\x15Z\xa2\x9f\x15V\xcdf\x9c1\xf0\xde\'\x15*\xbf\x15\x15\xe9F\xb3h;s6\xc2\xbb\xe1T\xce\xe0=\xc9\xcaV\xca\n\xa1\xc8\x8b\x8f\x07F6\x92\xd4\xbb\xac\x07\xa3A\x146\t\xde\x7ft\x0e\xbeK\x1d1\xe6\x1ccoK=\x1b+\xe9\x15\x80\x15a\x85\x8c\xff\xbc\xfe\xd6]\xa8Y\x97r1\xc5\xfb\xfb\x9e\x9e}\x9ds\xfc|\x04\xf7\xa2.\xf8%\xc0Z\x8a\x90\xfe\xa7B\xc3\x8e\x0b?\x849\xdau\xe5\xe8=F*]\xa6\xc9\xdf\xcfN\x89\xd0k\x91\xc1\xde}J\xcf(\x00\xd0\xdf]\xf1U\xba\xdf\xb7\xe6\x1e\xc3\x8c\xbf\xac=\x19\xc6\x979V\xb1\xda\x13\'\xe4\xe7\x85\xe5|\xda\t\xb3\x84N\x1fC|F\x12\x83\x99wq\x85{\x13\x97tK\xc0~(\xff\x0b\x8b\x92\xa5`V\x975\xe1\x17\xc7\xb6\xb4\xa6\xa1w0\xe6r\xfb\xaf\x05\xc8\xe2\xe2\x0b\x9aP~\x9f%\xac\'g6\x06\xce4?\xed\x16\x1b\xd2\xd8Q\x90\xd9\x80\xf7\x84\\\xbf|\x9b\x7f\xed\xea\xc7\x9fq\xf1\xe3\xbd\x9a\x92.j.3@\xd5\xb8\xd3w\x8e\xa3\xd6\xf2\xe6Vs\x0f\xeaG\xa8\xc4\x92\xfd\x10\xb3r\xc8j9\xac\xe1\x13^\xbc\x07 \x14\x90\xb7\x89s#\x13\xcf\xcfc\\\x7fuY\xbc\xd7\x7f\xb0\x10\xca\x92\xc5\xdb\x872\xbb\xdc\xd0E;\xc6t\xbf_\xddj\xed\xe1SD\x02J\xf3>\xa0GR\xca\xdbt\x0b\x0b\xfa$\xa0ft\xd4\x97@\x8b9$y\xf2.L7\xa2\n\x16\x98/\x8d\x17SKX\xc65\x05\x94\xa1\xe7\x83\xb4\xa63\xf2E\xfe\xbc^{*Z+s\x960\x1d\x19f9\xa8\xb2\xb0 \x9e\x8b\xae\x1f\x8cX&"\xfe>:\x8fXt\xa53\xcb\x1d\xe0*\xd1\xe8\xa7(\xc66\xc9\x90N\xd3\x15\x17Q\xc9\xd2\xd7\xbc\xf2|\r1\xa2O0:\xac\x0bhN.\xdd\xc59u.\x04,\xe3|\xdb\xb3\x13\x98\xdd\xc6@\x99\xd2\x1b\x90\x12W`\xe2\xf3\n\xb7\xa2\xe0\x12\xd6\x1f\xf2z#\xe6\x8d(\x99@\xab\x02A`|\x89v|C\xad\t\x0bYT,$\xca7;\x88\xcey\x87\x8f\xf2\x18\x99\xf3"\x1a\xa6\xeeIi\xb6~A\x1e\xf6\xf8U\xae\xa2\xf1\xd8\x18j\x02\xedU\xdcw\xfcB\xb6\xe5{\xdb\x83\x8e*\x9b\x8e\x98\xfcN\xb3\x89\xf2\xe2/\xb1Hy\xb4\xc9*\x87N\xf1<\x95\xcb11jJ\xeb\noH\x06\xc7"cZ[\x9bV\xb1\xdd\xe7\xebL^\xa8<E>sAfe/\xd1\xc7O\x96\xe6cF\x9c\x87[\xf7\xd3_\x81Y\x17\xb2\xf5\x8a\xecN\xca\xd2\xd2pv\x18\xcb\xa4B\xeb\xe9\xfd\xa3\x8cDE\xd2}\xf7B\x9f\xba\x90e\xab\x05\x17\'=5\xe3\xa1\xcb\x7f\xee\xfd4\x06B\xa9q\xb4\xfcA\xd1\xc2\xe9\xac\xb5\x90\xbdz\xf4@\xc1e\xc8\xbej\r\x82\r\x8e\x9f^\x9f\x17\x06t\xcc@,\xed_\x94\x0cblY\x06\xd5\xab[t\xf1i\x1c]\x9cG\xab\')\x15\xdc\x05\xa0\xd1\r|\xfeuC\xcfc\x18Y\xea\xfa\x10\xcc-\xe9\xb1l\xde\x08\x01\x92\x8f\tS\xaf`\x88\x0fA\x9a\x02\x82g\xe3K\x145\xcc\x9b8?\xd3o\x04cvM\xd2\xba\x96I\tx\x18\xce\xe2}\xae\x00K\xd7\xeah\xbc \xf2\x15Pa\xce!\xca\xe0\xde\xce\x1e\x14\xff\x10\xcf\x17vU\xceD\x80\x1f\x8d\x0e\xfc\r3\x80\xf09\xa3x\xb1\x85\x04\xdc\x04\xc1\x03\xf6\xa7\xc2\xd7X/\x13^\x93j\x99\xf0\x0c\x1ccR\xba\x83S\xc0\xfeQv\xf1+\xb0\xdfh\xeb\tj\x8c\xfe\xa0z\xa4\xdaH\xcb\xe4\xf7\x1e6}\xc1\xdd\x8eG\x00\xfd\xd4\xc1\x86|\x8f*\xbf\x1b\xf5ko>\xca\xe8\xf7\xb4\xd9\xf1\xc9\x10Q\xd32\xf6\x15\xd3\x1b&\'!\xfa\xaf\x048`t{\x82\x11\xe5\xf3IOn(|\x0ci\xd4\xf4\x040\xd6i(S \xb8\x9a9\xcc\xec\x9eX\xae/\x02o\x01fi9\x876\xd4\xde\xcc\xac$_k?4\xa0_)\xc1\x99\xae\x9embK\x98 ,\xfb\xa6\x05\xa0 s\x7f\xa3&Nh}\xcd\xe1\xe4\xd3\xf7Mj\xb7V\xc0{W\x18\x82\'S\x12\x16\x0e\xba\x95\x99\x1d\x070\x1d\xdbi?\r\xe543\xaf0Q\x11\xedP\x0b\xba:Q\xf3\xb1\x12<\xf0\x0c#\xf9\x83\xdf\x13]-\xba\x83\xac\xf2\xd8$S\xb4++\xc1\xe9\x1f\xc5\xa5Dnu\xba\x05\x8a\x9c\xea3rJ\x9c\xde\xd1#\xc6\xf7UF\x00/\xdf\xaf\x00\x92\x88\xadu\x97\x1cs\xa1\x10\xc8p Zn\x8d\x87W"\xf9\xc3?H\xf8}\xa8,Oua\xbc:\xec\r\xc9\xa7\x8b!\xef\x9eK1\x140\xc7~\xab\xa4\x82hs\xcf\xeb\x99j\xc6&k\x0f\x02\xd1\xf7[H&Gt\xa1\x9b~\xaa\xe4\xee\xf8m\xa3\xa2\xf9f\xc4\x99!UY\r\x0c%Xn\xcd\x1f\xc2\xbd\xe10&\x8c\xf2\x95\x16\x08\xf2\x9a\xac\xa9\xca\xb0O\xa1\xab\xb2\xe7\xb9\x02\xcd\x00\xbb*%Z\xeb$\xf3\'\x11pO\x82\x96I\xb6\xb2\xf6.:\xb8\xcf\xdb\x0bo\x171\xccH\xa9\xb8\xc1\xe7\'\xca\xbc\xdf\\.\xb9\x19u\xc1\x9eB\xbc\x9c\x1f\xbb\x87>\xf2 `\xb0\x12\xcf\xf5\x1a\x93F\xabTkwj\xdfi\x16\xbfZ\x99D\xd4B\xe3\\\x00\x9f\xebR\xce\xa97\x83\xbb3\xdf\x8e\xe0%%\xd8\xc3\x0f\xdf\xfa\xc6\xd4d\xd5\xa6r\xda\x0c\xf9\x95\x0c8;Ji\x8f\xcc\x15\x8f\xa0+\x91s\xaf\xcc\x83!,\x94\xfaL\x0fD\xee\xc5Q\\\\\xbf\x90\xeb%\xc2\xf3\xbf\xd6@\x95\xeb\x1c\xb5\xc5\xa9^\xbe\xc6P\xfe\x8a\xaeN>\x19\xad\xfd\xb0\xcf\xf4\x9c?\xe3\x12\x14v#\xc7;\xf9\xc3\x7fA\xdet\x82M#\x022\xa8j\x82\xa9\x06\x8dg\x13X\x96\xd0M\x0c\xa1\t\x9dA\x91\xdb\x15\x9b\xd8\xfb ]\xf9N\xba\xfb\xd5>\xa2\x89\xe1\x1c\xce\xd5\xcf\xae\\\xa9A\x85b\xd7\xb8\x83eW&\xb0\t\xc5\xb3\\\x83I\x92)I\xd9\xfd\xd8t\x94P\nTI\xd0\xb8\xc1\xbd\x06\xd5#5^\xc3:\xe5\xd3z\x06\xcb\x1d\xbb-.\xa5\xa9\x95r\x8fH\x00\x81\xef9-Og\xc9Qq\xae1\xd9\x11\xad%p\xe8;m\xf9,\xa0Nk\xb3D5FpCsN\xe4\x9b=\xdaBJe\x80F\xc6wqQ\xdc\x8e5\xb1\xdc\xcb\x03[x\t\xc2\xf6,Ajl~\xdf\xaf\x12\x1f\xe4\x15\x98\n\xe6\xdc7r A\xe3-<\xb4:\xaa1\xd7\x80\x02\xf1\x00\xad+\xd1\xcfH\xa8I\x04\xed\x0f9\xb4m\x05\x9d*\xc1\xf7\xe6.b\xaeL\x84\x89\xba\xe3\xb5\xe5\xf4)\xfaN\x80\xea\x81\xfe\x9ee\xc5/\xd1\x90T)u(U\xfb\xf5\x0eM\x13\xbb8\xdb\xe6\xb5#\xc9#+a\x94\x92\x98\xb3\x9b\x13\x19\x8b\x87\x05\x12+\x8f\xc9f\xa4)I!7\xf3\x0bp\xde\xba>\xb7\x9cA\xcb`\x99$\x14\xb0\x0e)`\x89\xf7\x98\xe4\x86Bcw\xd2\xc6L\xec\xcd\xec\xd0\xd4\xf0\xa3\x8d\x97\xcf\x9d__\x18/|\'H/\x19\xafO\xb2\x05\xf7\xa2g;\xf1\x93\xce\xac\xcf\x95\x03\xb3\xfd\x03,\x9b1\x8cE\xb2\x07\x82\xec\xd9\x88\x8de\xec\x14\x07\xef\'\x1eUw\x9f\xf3\xf1\xc35W,\xae\xaad\x7f\x9f3\xf6Xj\xc2\xf0\xf2\xac\x01c2M9\x0c\xf4\x07>6\x0f\x00\x93\xe0I\x97bi~\x1c\xfe\xc7Z\x0enQ`\x80\xcc\xf2\xf6\xc7*\xa7\xf4\x08\xc8C\xfb\xee^\xa1@\xcd\x82\x1d\x10\rf\xda/\xf5\x1b\x993/\x0fSd*g\xefy\x95,\xad\xbeg\x14{\xa7@/\xc7@kG\x10-}"\xa9\xa0\x0e.\x85r&;N\xf7\n\xf6gVB\xb6\x0c<^\xf0\x95\x1fyu$\x0b\x82\xa8\xc6\xe8q\xc6\\\x8bxU\xa8\x11\xc4\xf3\xcb^s$\r\xf8\x84\xb0\x83a\xbb\x14\xb5\xd9\xfb\x07\x04a\xf9\xad\xcd\x85\xae\x19\x1f\x9aZ\xce\x96\x18\xcc\'\x98y\x02\xcd\xf9Z\x94U\xf7\x950\x05\xc2!}T\x04\x19\xfe\x0ctu+\x18\xb6=\xd2K\xd7f\x9eq\x89\xd1\x0eA\x0chG\xc0\xf9\xfb\x1c\\7\x96\xf2\xdd^4\x88C\xb0j\xec\xe7\xe9H?\x03|D\xbb\x05\xb6yX5.J\x06\xc87\xbf\x92@0\x88\xcd\xd5]\xc5\xa6\xc1\xdd\x1d\xf2\xb6\xcf\xd2V\xc1\xd2W,\x89\n\xbc#\x9aHt\xb0C\xe1\xa3\xdf\x94az\x151\x85\xfa\x1eO\x80s\x0e3\x84\xb1\xc4\x0b\xc2\xecd\xcf\x143&\x94\xe2\xa1\xa1\x89\xb9jt\x1bh\xa1.\x1c{\x10-al\x1a\xed<\xd8x\xbf\xd0 \x1c5\xfb\xf4\xc8K=t\x7f\xa8\xed\xab\xd3\xe5o+D\xa2\x9f\x98(\xe0\',\x8f\xa1\xfe1\xd4\xb3\xb9C\xd5\xef\x0b-\xdeI\xfe\x862\x1c\xb3\xf1\xa6\xf5\xf8\xda\x95\x8c\x0e\x1f\x10"\xdfJ\xaa\xf0`2\x00tM\xf3vgNE\xb2\x1d\xeb\xe9s\xe70\xc6\xa2n\x06^\xe5\xb7\x0cbX\xc8\xb7\xa9W\xd3j\x8cua<\xbb\x88\xdc\x08e\xc1{\xdc\xce\xd3\xc1\xf4\xe4>\x0b\x13\x811H\x96\x916\xc3\xff"\xea\x91\xdf\x8c\x8b\n\xc4\x9c\xb1\xc4F\x1a\x064\xc6\xcd\x18\xee\xfb \x8a\x1b\x18\xf9\x85\x88\x1a\xa9\x19I\x9c\x96,\x8c;e\xed\xbf\x15G>0\x1b\'\xb0\xc4\x86d\rI\xd5T\x7f\x11b\xcd\n\xbbc\xfc\x9af\x93\xeb\x8d\x95\x89\xc8\\\x84\x13\xf0\xbe\x87\x9agK\xa8f\xc3*\x11\x18\x85\xb96\x1d\xf8U\xf0\x0e\x11\x98\x99!bp\x87\xf1\xc9pF"\xfe\x005k\xff\xb7\xef\xdde\xe5\xc7\xe7?\xc6\x04\xfe\x8e\xd1\'\xbd\tm\xf6\xed\x83p\xd3\x17jE\xd5\xe3\x1e1\xb11\xcfr\x1adV\x04c\x86trz\xd8\xa9\x99nS<\x99P\xb4\xaa\xc1P\x02(jjxz\xa9\xdf\xb0\x00\xff\xda\xad\xd6\xc9#\xde\xdd\x0f\x16\xa30m\xb7\xe3\x91\xa6\xf3=\xc3j\x95\x0e\x0f\x17\xfa\x03\xa6Z\x01J^\x8dyP\nK\xb0\x05\xff\x02*0\xf5g\xc18\xa8\xf2F\xe2B\x90-\x98w\x91\xd0\xb4\x98\xe4\x12\x1b\xe0\xe5\x03-\x9d\xf2\x11\xa2E9\xb3\xe4\ti\xcf\xf7T[\xa5G]\xa5\x8f\xe8\x9f\xc5\r\xce\x8fu>O"\x1e\x89\xd6-s\xcd[\xb4\\i\x90\xef\xee\x0e=\x1c\xc5\x05\xbc\x8a\xd2\x95\xdc\xcb\xaf.n\x13\xf5\xf7\xc3\x9b\xd6a\xe2_\x9d\xad\xb3:\xc2\x9f\xee\xcc%\xdc\x8ff\x8b\x0c%\xc3x\xfd\x9e).\xad\xb0\xa6\xe6\xcfP\xc0\xcas\x84\xd6\xb5\xf6N9[\xaf_\xff\xe5>*9o\xfa\xdft\xc0\xa4\x81\xeeZJf>S^\x10\xa9\x1aj\x1b@\xde\xb0\\0/ScC\x95\x98\xce\xcd\xf9w\x941N\x84\xe7\xb4K\x03\x08\xae9\x8e}\x1f\x19E\x8a\xbf\x0e\x15\xdb\x03m\x10\xef\xa3\xae\xe4\xa5\xfd\xfd\x1c=\'a\x88\x1dED\xcal\xa3\x03\x1e\x9a\xed\xf3Z$\xaeF$\xc5~Ec{\xb9\xaa{\xa5\xb9/\xd2\xd6\\\xea\xa9\x7f\x82V\xdb\'\r\x87\x1f\x88\x8d\x13F;\xf5g\n\xd4c]\xa7\xce8\xecD\xfa\xf1P\x8b\x84{\xea#Ol\x17\xb4\xca\xb1\x82\xf91\xbe$\x1e\xad\xdf\xcaCAS0\xfb\xed\x8cD|\xb7K\xf09\xa2\xfb}Zcs\xa2\xf77\x14\xbf\xc1\xb9\x03\xcf\xc6p"\xbe1^\xe5f\x15aO\xd0k\\\xc0\'\x13\xb4t1&j\xeev\xca \x17\xa0T\x13\xbaj\x93~\xe5\x82\xfe#{\xa17\x10T!9$\xac\xfc7\xf0\x81\\\x9a_C\xfc\xba\x10\x92\xb8?\x9a\x8e\x07\xd1d\x89\x82G\xc8m\x04{\x12\xf2\x9bU\x12\xe9\xb3\xe6\x7fC\xf4\xab{]eZ\xd0\xd6/>7\t\x7f\x0c{\xe8Lp$\xfd\x96\x85;\x9c-\xc0k\xfd\x98\xd03\xcc\xa4|\x9f/R^\x87\x86\x0f\x1a\x0f\xf1\xf9b\x93_\xa7\xc4Jz\xb1P\xf8\x17\xa3\xec\xbe\xb3\tO\xad\xcbE~\xd5\xadF\x18E\xf4\x96j\x8aW\t\xccr\n\xdc\xe1\xa0\xc0x\x954\xfeGL\xa20\'S!\x9b8\xbc\x19\x02\x1dI\x8e\xa7\xe5\xc8O\xf6\xda\xda.\x10\xcb\xd2vF\r\x8b\xb0\x99\x1a\xfe0\x19m7]\x07\xa0\x1b\x05UE\xff{\x8a`\x17\xc7G\x82\xfa\xeel\xd8o\xe0R\xaf\x9d\xdax|Oh\xabk\xc8\xa0\x0b\xd4W{\xf2\x9b\xde\xb9\xdd`\xcb\xb9\x8e\x93\xcc\x12\x02\x1b\xa2\'={\xf8eeK\xf3\x9c\x98\xea\xcf}\xd2\xf1\xe7|i\x19\xcf\x1f\xcb^,\xaf\xc1:6L\x03\x18\x13>\xf21\xc3\x04\x8e\x8aE\xa13$K<#\xa6\x9b&jy\xaf\x81\xb1}\xecI\xf7\x9dAr\x8a\xbd\xc6\x12\xf9\xf0)\xba\x8d?\x0e\xef\x16+\xa5~\x16\\gc\xd8c`\x99\x80\x0f\xe7NH\x1c\xbfw\x06J\x13\x08{\xa1\xe0\xdf\xb6\xe7\r\x8f\xb6\xf4N]\x922\xfaW\xe6\xc1gU\x05\x86G:h\x9c\x01\x82\xacrN\x02\x9b7\x00s\xac\xaa\xe7\xfbY\xdf="=\xfcb\xa6\x9a\xf8`\xfd\xdb\xc1\x81\x1eD\x11\x192\x06q\x08\xb9\x16\x8fcU\xe5\\\x15-\x89\x05+\r)\xed\xfe\xcbG\x94\x92\'\xef\x1eD\x92\xd4\x96-;\xd5\xbf.\xb3\x80\x11\xcc\xdb\x98P"\xd0\xe5DI}\x8f!<j\x07\xb7\xaaL]x\xf8\x93\xf1\xd7atO4\xcfkxY\x19B\x97\x0f\xea\xe2^^\xf5\xa2\x84\xdfs\x15:F\xaat\xac\\\x9c\x1cH>\xdb\x12@\xeal\xce>E\xb2\xe9|T\x06DKY\xcfq>\xed\xd84\xe9\xcd\x959e\xe4\xf4\x97\xe7{\xe3\xf9\x88O@\x84N\xa6\xa7hVURs.(\xcf \x02\xc32&\xb9\xdeC\xd9\xd0"#D\x9dSJ\x8c\x99\x8a\xc3\'\xb3\x8f\xb4\x99,4\x80p\x1d@5\xe8F\x98\xde3\x1chs\x994\x12s\xad\x99\xe0\x1d\xc2\x18#\xfa\x8b4dD\xb0\xf3$X\xb3\x03\x00\x13\x88,\xc4\xe2\xf3_zr\x86\xf2~X\x129\xe4b\x97iD6m\xf4\x81?l\xb7\xe7K\xe5_)\xa5kdP\x13\xbav\xb2-\x0c[\x84\xd3\xbc\xec\x87\xe6\x81\xc6\x8fSVR\xd0\xbbI\xf8\xdf\xe5\x1cZ\x8aTA\xf7,\xa8\xc1t\x07dd\xe0rZ\xeb@1*\xb6\xd0w\xa0s\xdf\xcd2\x9e\xfdiA\x01R\xeb\xbb\xbbnV\xa0\x9c\xda\xd9'
|
|
|
|
|
|
2024-12-14 17:54:48.408490 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25571
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808887109
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.414859 - Ether / IP / UDP 192.168.1.11:61224 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 30921
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 61224
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca81
|
|
###[ Raw ]###
|
|
load = b'\xc8\x00\x00\x00\x01\x08\xea\xcc~X\x91`\xedq\x00@F\x00\xb7\xf1\xdf\x1c\x0b \x07\x171\xae\xac\x02\xf3\x14A\xa2G@\x03F<O\xae@U\x7fU\xaep/\xe8^\xf1}/\xb5$\xd4\xd9~=\x18f\xec\xa6\xc2l\x1e\'/J.Qt.\xac;\xaf\xe7\xde\x93\xe7\xf0\xd6\x06\xe1)\xa8\x02D\x89@\xd8\xd5\x1b\xb8\xb0\xd9\x15\xba\xae\x0c\x02\xef\x8c\xd3\'\x08Pj\xc6\x08\x9c\xcb\re\x1d\xe8\x07\xb2\x84\xc3\x1a\xbc@\x06|LX9\xc8n\x92)oJ\x1dF+\x1ed\xf7C\xaa\x87\x93\xd7g=\xa1\xf9\xe6\x9a\xbc\x11\x8d$p\x83^gM\xb1 s\x1d\xc3\x8b\x1d}\xc2\xfb\x027\x1b\xe6\xc9\x1e\xd9\x8f\xb1\x13\x06\xcc\x8c\xf0)d\xde\xec\xc1\xea\x0b:\xc1\xfe\n\xb2>s\xc8\xce\x9c\x91\x9c\x11\xba\x92\xa1Z\xb1\xbb&.c\xba\x08\xa5\x14&#\xf8$\xa4\x99\xf6\x9c\xd3\xed?\xa3q\xf8\xce\x80x\x89\xde\xbf\xe2\x84\x1f\x82\x8dO\xae>3\xc1\xda\x97\x84\xbc\x88\x82\x96<\xd6\xdf\xc1\xa6K\xfa\x92\n6\xea\xc0x\xe6\x08\t\xdc\xc0\xe3\xe5\xb8\xc6\xcbW\xa90\x84\xd6-+K\xf5\xcaO\x1eB \xea\xd67\xc4\x0c\xbd\xd8\x03(\x08}\xb6\xbfI\xf5\xa1\xd2\xb1\x9b\xfa@\xb2\x90\x17U\x03\xb4+\x1a\xab\xf5\xcaY\x81\xd5\xe1\x10\x06b]hXs\xd9t\x7f\xd3}rkg\x83\xc9\x1b\x99\xfa\xb01\x18\xa8\xe2\r\x1b\xae\xeb\xa1\xdc\xd5\xb8.\xd9\x14`\xba\x02!\xdd\xd1q\xad\xaf\x05\x7f\xceY+\xec5*\x84\xa7\xc6\xff\xb0\xb0c\xed\xc7Vw\x8a\xcb\x12\x98T4kyt4\x0c\xf3Ya\xffP\x02e("\xa5\x0b\x1a|\x9d\x8e\xab\x93\xa7\x98b\xe3\xa0\xdd\x9e9\xc6g\x98\xf0PT\xbd\x03AY?^\xca\xec\xc66\x01(\xfdS\x89\xebs\xbe;f\xd9\x1e\x86t\xa6\xb4\x0b`w\xfb\xa1\x8b\x85xt\xdd\xfa\xc0\x82I\xfeK:\xf6S<\xd8\x1c\x08g\x1c\xa2Pj\xb8\xebC\xc6\xe2I\xfd\xeb\xefu\x17\xce\x84\xfcjV\xd5\x16\xefHG\xaam\xbb\r\xde\xf8\x92t\xcd~\xe6}Cz\xd7\xc0\xa1j:"\\y`\xdf\xdf#0\xb6\xc4\xec\xd0?T(W\xd9\x80.{\xc3\x85T\x1dx6\x01\xd2:0\xb4$\x9b\x08\xb4\x1e\xdah\tn\xc62\x7f\xc8\x8b\xda\xd9\x8a\xa7m\xb2\x9an\xf3g\x1b\xe1\x8dc\x85\xab\x81\xdf\x8b\x8d_g\xae\xcbDIW\x13\xc4\x87\xde\xf5)\xa4\xaf\x10\x91b\x03\xc1/?\x7f\xafz\x99\xc4p\x95\xa5\x03\x92\x1b\xac\xa8\xfb\xc7\xe4\xb8\x19v\x90\xc4z\x1fI\x89;\xd6N_\xe8 E\x10\xac\xab\x7f?h\xbf:~]i\xb9J5V,l\x13\r\xc81z\x15\x97\xe6\x86\x03V2\xbcS\xedB!D\xcd .\x8fQ\xe7\x98\x0b i\xd0A\xe1\xe7\x0f]h\xc2]W^xd8\xd0\xf5\xa9\xb1\x0c\x95\xd6\xf3\xc5\xd8\xf8\xf9\x1c+q\xdcW\x8f\x9av\xa6\xea\xc6\tig\xf1\xf7\x9aw\xf0\x8c<2\xdfw7\xf4\xfa]:P\xb4\xd8P\x18\xae1\xfa\x14~\x9c]7\xa9\n\x8a\xf1\x1eH\xd8\x8f\xac\xdcKX\xee\xb4\xa8W\xe1C]\xe9\x03\x9d\xe2\xb8\x0e\xe6e\x14c\x07!\x19\xab\x13\x89\xc8\x94@\x1c5\xb0\xbd\xfb\x1e|\x1e1~\x03\xc5\xb1\xca\xb6@\x0fv\x8f\xb1\x9bJ\xab\x92\x05\x0b\x8e\xbd\xc1-\xfa\xcf?\x80\xcb\x95\xe6wY-\xc3W\x05\xdd\xe6\xf0\x80\xaf0\xca4\x97\x0cA\xc4\xaf5\x85-\x95\x03y\x90@\x19)NL\xd2\x9a\xc7>\xa4\x19\xd1\xdbo5?\xa2E|\xcc\xd4\xa3\xb9~\xdf\xef\xc5\x99\x0c\x80\x1c\x9fU,i\x15\x06\xc8K\xb5\xed\x11\xfaF\xac\xaeP\xaf\xa6\xd3\x1aU\xba^R\x14\xfd\r|\xd7\xea\xa6\xe6\x02\xc9<]\xd2\x960 \x11\n[\xa7o\xd3h\xe00\xabs\x8c-\xac\xa4es\x7f\x04\x89\x19\x84\t\x96;}9\x18/(\xb6\x99\xdcT\xfc\xfb\xfdz\x1a\xf5\x0fzFz\x83\xd0\xf5#\xf0\x88Q\x99u\xa9\xc8;\x8a\xfdY\xa0\x16*&1\xa6\xd2\xb1.p\xa60\x08\xfb\x08\xa1\x92\x1b\xa6@\x0c\xeb\xe6]\x86\xd5\xf6\xfeS\x80B\xa0T\x92\xe2\n\x80\xfb\xc6y\x83\t\xc0|\x17\xceH\xce\x8e"\xd9h\xcb\xb1\x81\xa7\xe4\x94T\xd3\x08\xa4d\x91U\xcb\x89\xecp\x98\xe3\x0c\x04\xf1\xb3\x9e\xa4\x18\x189A\xc1\xb6\xf2\xf9\xe7\xa2\x9c\xaa\xd0\x93\x8d\xb8\xa7\xd3l8\xed\xe5\xd0\x92\xa0c<i$"V\x06kvb`x\x9eV\x90;\x88\xb4\x92B\xe2]\xfa#\xa8\xfa\x81}\xf2\x8f&J\xbe\xda\xa9\xe4b\xe8\x8f\x17\xfc\xb4\xf7\xfdW\xd6\x0c\x89\xe2(\x8f*\xd1\xa9\x11\xee\xda\x1bI<\\45\x8b\xefR\xd2x\xe5"\x826\'\xc7\xbd\'\xa2\xabi[/\xaa(\xc1\x14\x83@\x80\xb5\x15=\xc0L\x1b\x9d\xfc<\xda\xf1\x19\x97\xa4!\xab\xa0\xba\xfe\xc5\xedq\x8dn\xa1\x15\x84A\x8b\xca\xb08m\xc3q\n.\x87\x9e\xc6\xc6\x86\x15d\x85\xb4;kj\x1d\x8a\xcf\x17%\xfc^Q\x00r\x8b-]\xd0\xc4]\xb9\x0cw\x0b\x8d'
|
|
|
|
|
|
2024-12-14 17:54:48.423369 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1500
|
|
id = 47967
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x674
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808887109
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0xce71
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'z\xc1c4\x81q\xcb>\xd8H\'\x0e\xac\xa9\x1b?yX\xa4\xa3\xfa\xfe[\n7\xd6\xbe<\x8c\x01\xac\xf1\xbd\x86\x11\x8a\x14Q\t\xb4\x07UAh\xe3m\xec\x8c\xc3\xa3\x89 =O\xc9\xf4\xbb\xf2\x8a6\x14q\x9cQ\xba\x91\x03\x03\\qRJ_b\xbf\x99\xb6\xc4\xc1\xd3\xc9\xafM\xce\x9e\xbb-\x9e\x93\xb9#\xfe\xb7`\xb1\x89\xcah\xcf\xb2g\x18_\x14\x90\xbd\x84.\\sR,\x80\xa8\xab&>a\x0f\x0f\x07y_VVN\xaa\xccj\x1fw}\xbfJ+\x19\xd5\xc1\\\xef\xac\x8969\x01\xbb\xbd\x03\x94\xc8\xcfW\xccal\x03\xc7!\x0eZ\xfd\x14\x82\xbe\xfem\xce\xce\x1c\xc2@\x9e\x9c^\x18K\xd4D\x924\x1d\x141]\x08\xfb`\xa5\xa3w>2\xe1\x9c{\xb7 \x10\x94\xf7\xb7\xcc\xe1\xaeY\xde\x8cX\x0c\x04gO=\xf4\xba\xb1\x89\xads\x8d\x86\x8c\xfb\xd3\xd8QMh\xb4j\x0f\xd7\x0e\x9e\xc0\xb7\xc8\x8e\x03\xb7s\xeb_\xe7;\xa3)4\x8d\xc1=\xa4t\x03f\xe2\xa3\n\x06zI\xb2K\xd1*Q\xac+\xbf\xa5\xa0m\x80\xf4\x8azbW\xfe\x0e?c\xe5\x8c\x94Q\xbc\xc4\xf7\xe8\x1e8\xecY\x90n\xd3\xf3\xfak\x80sF6\xaa\xbcY\\<\xe1\xae\x13\xa5s\x19\xc9\xc5^\x7f\tE/\x85rJ\x92\xc8\xbf\x8f\x87\x0c\xc8\xb7*N\x9bxu\x08\xd2\x88=\x8c\xc0m\xc0n\xcc\xe2.\xad\xbd)\xfb\xd0\xed}\x19S\xe0\xbf\xfc\xef\x9f\xe8\x0bI\xd6i\xe3\\5\xc0\xce\xf6\xa2\x18\x9c\xa3\xb7\x07\xce\x96\xcc\xabv\x83\x1ba\xf4\x13\xb0e%\x9an\x7fE8\xde\xa8\xb3\r\xe0\x19eo\x80\\%\x0e\x1f\x92\x1c\x17\xe5k\xb0\xe3\xd2\xb0-u\xb8\xe8\xafz\x1b\xf3\xf7\xd5\xedJ\xe52\x1a\xe7\xe8\xdc\x8br\x8d\xad\xb0\xde\xba\xfe[\xf4?\x8e\xfa5nFe3a+\x9f\xc3\xb4\x80\x95\xa7\xbc\xda\xfd\xc9\x19\xbcCA\x13\xa0\xa7\xd0d\xbej\xe2\x8fp\x9a]\xb2\xf3-F\n\x85_V+\xac\x84\x82$\x9dSt<1\xd2\xb9\x07`\x01\x85e~^X\xa0\xcf\x7f\xf4\x98\x1c\xdb\x81d\'\x942\xa0\xcf/\xe9\xd9l\x95\xaa\x1d\xd0v\xe3(]\x99\x04\xfc\xa6\x0f\xc9\x92\xb3 #\x857I\xd5+Z5\xe8 Sy\xe9\xe37\xec\x886\xce?L\xef}\xf4\x0c\x95\xe3\x1e\xc3U\xc4\xca\x91eD\xc6\ta^\xd6\x89\xbc\xe7.{\xaf\xdf\xed\xe0\x14\x13j\xc9*\x84\xb2\xf1f\x91\xdeM\x0f\'\xc5n\xee\xe7\xf3\x15D6\x8e\xb3"\x81\x95:lqP\xfc\xff0fOG\x8b\xe1 \xf2\xad\x85\x85)\r}\xdc\xae\xca\x80\xd7\xbcx\x84f\x8eP\xec\xcdx<\x0b\r\x9dP\x08\x1f 5\xd1\xea*\xe2\xd2Um\x9e\x11\x10=\xbc\xed\x8e\x83_\xe3C9\x8e\x82\x00V\xe8\xaf\xf0\xb3\xc16*\xeaf^\x1e\x14\x13\xb0Y\xae\xf1\xb3\x0c\xfa\xc6k\x96\x87\xf7\x1a\xeb\xa1U\xfc\xa3cE>A\xcch\xb4\xf9\x19\xc2\xdb\n!\xbb<`\xca+!\xd6L\x02l\x16@sY9/\xdcDg\x9e\t}D\x92M\x9ee\x82S\x84\xcb\'H\xe5\x8c\x022\xd7\x0c=>\x14\xa4\x84_\xbas\xf9\xd1\xaea<9+|\xa8\x07l\x0e\x97p:\xc0\x88\xab!(\xae\xfa)\xb7\x8dA\xcf\x84\x9b##5\x15\xf05nR1\x97\xeb\xa9\xa4S\xbaw\xcbV=z\xd8\xe7\x9d%\xf0\x8c\xd2*%K\r7\xa7\xb7m\xe4|\xeb\x98\x11\x95vhY\xe6f\x108\xb3\x84\x93\xfa\xf9\x0f\xc8V1\xe5\xc6\xadP\xea\x0e\x83}&\xf9\xe6\x05!\xb8C\xd8\x98N\x92\xbc\xeeC\xd4\xe2\xb0w\xaf\xdf\x0f^n\xd9\x92\x88vm\xdb\xbe\xaa\xaf\xf0\xa1\xf7\x82:T\x92gS\xb5\xda5\x17\xf9\x11\x94=`,3WJ\x85\xc5|\x93\x1e~,\\j\xf3S \xbe\x0c\x084|\xbcd)\x82:\xee[\x1am}\xd6.2\xa0\xa8<\x0cp\x98\x04U?\x1eJO\x1dl\x19*b.\xc7#\x10\x08\x9b5\x891\xf9y\x04\x1a&\xbd\x0f\\!\x9c\xcf,l\x1b\x94W\xa0\x0e\xc2N\xef\t\xe5\x05\xb6Rf\x12\r\x9bz\xedT\x05\x08\xbc[B\xe7\x8br\xdaBo}\xe6\xc5\xbd\xd33\x18\x9c09\x0e{?\xd7\x12\xd6\xe4\x03\x126\xda\xe7\x04\xa6\x08\xd9\x17!\x8b[\xd0\xfa\xc1\x181A\x03\xe3\xc5\x87X\xc0\xc0eb\xfc\xc1\xfd\xc3\xe9z\xc7\xb9xo\x81\xd2\x83 \xfc$\xaf~A\x8fKFo\x9bW\xef2\x8e\x98\xd7Bu\xc1\xe1\xc5\x10# \x9d\xf1\xbbx\x9f\xc5\x1f.\xa8\xd2\x83\xe9\xdb\x14U-\x04\xd6\xc9TN\xaf\xb9\xba\x97\x90\xceR\x19y\xdd\xe9\xa0\xb9\xef\xab\x12\x93|\xb7\xb3B\x8bk\xe9o\xc7\x06T\x9e\xe77v/\xeb\x02\x0f\x84\x9a\x02\xcdL?\x08\xca\xf7]\xb3\xc2Z4\xdb4\xf8\x1b\x17o#-\x99\x117u\t\xe4\xaa\xad<\x14Kit\xd2\x0e\x18\x98(\xd14\x9bb\rEyD\x84q\xe1S\x19\x9e\x98\xf2\xf0\x13yi\xbf\x18\xa5\xd0Y\x035\xc5\xca\x8ev\xfe\x9d\x1e\xae9\xa2\xc27\x8bq*\x83\xca6\x1d\xa1\x9ab7\x08B\xecY\x9c_y\x1bqd\x153\x07G\xec\x964\x1d\xd3;\xd95\xc6\xf4\xf1\x92\xe4\xe5\x0c\xd7o\xf1\xf4\xf4\x1cds\xa1\xdb\x98u\x19\xad\xda\xddPK\xd7\xfa?\x1a6\xb0\xc5\xc5[\xe7\x14"N\xb4Bp\xaaMW\x01\x07\x13\xf2U\xc6q\xea\x0b`\xb5\\Q;\x16\xb4,\xfaZ\xd6\xbd\xae\x16\xfd]\xe8\x9a\xa1\xaf\xe1\xd3\xe5\x11E\xf9\x8c\x07i\x01\x07\xcc^\xe4\xd6\x1e\x06\x96\xe6\x84\xf2\xf3\xb7B\xa4\x955L^\xb1\xe0E:\xb95\xed\xf6\xf2\xff=\x8a\x80u\x82x\x85\xb1\xc7\x05\xd5v\xd7\xdd\xba\x08\xcf\xba\x84\xd1x6\x1c\xafp!.\xc9\xb1\x9f\t\xfbNC\xb7\x0b\x15g\xd0u\xc6\n}\\\xb6\xa76\xeb\x98\xafil\xae\x02\x8e)\xfb\xfb\x07\xb3S\xc3\xd9\x9e/\xfau'
|
|
|
|
|
|
2024-12-14 17:54:48.429678 - Ether / IP / TCP 2.18.188.131:https > 192.168.1.11:40845 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1479
|
|
id = 47968
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x688
|
|
src = 2.18.188.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40845
|
|
seq = 3808888569
|
|
ack = 1299534588
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xe9e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xbe\x19E\x10\xc1\x06\xe2\x1b\xde\xcb\xcd\xd3\x1eff%$v$\x127\x90\xb5\x9f\x01\xe6C\xab\xa8\xe2\x1e!\xae\xba\x92k\xa1\xe0O\xca\xd7\xef;J#\xe5E#\x8c\x85\xa1\x0f=\n\x97>"\x83\x7f\xd7\xc907\xe9\xebS\x97K\x11\xd3\xe8\xc5a\xdcc\xde8M\xe9\x13u\xc73q\xb2\xc9\xe6\x98k\xbe\x03\xda\x95;5\xad\x1d\xe6Mp\x87s\xc6\x83\xb5\xe3<oxV\xfb\xd8\xa5t\x1c\xe7P\xb8\xbcf\xae~\xb3\xa9O\x05\xf0\xf3p:\x9a\xee\xf2\xee)\xd5[DY<\x03\xb2dW\xb7\xe04\x0c\x9a\xefJ+\x05*b\xfd\xd7\x9d\x111\x1f)\x85*]\xdd\x86\x9a\xb8\xe9._\x9c\xa5\xf9Wr0\x03b\xd6\xc4\xc0?\xe6fd\xd3\xd2\x83\xdf\xf0<iK\x98\x8a\x1c\xe7\x1ex1\xca\x0f>u\xd8\xbf7Zwg\xb5W\xf7\x81\n4+n\xc4XEW\xe7\xb4E\x84\x1e\xf7>\xc0\xfa)\xf3H$\x8b9\xb7\x94\x9d\xea\x06\xc0(\x10\'\xa8\x9c3\x9a\x17\x80\x8e\xe7#\x85F\xe4\x16\xda\xbav\xb8`\xacGH\x0c#\x07\xbe\x94htu\xe5{\xf3\x1dy]\xf1<\x0ei=\x1a\xeb\x9a\xb9\x84b\xcf\xe1\xb4\x88 \x94\xe8\r\xc5v\x0f\xdf\t\xe8\xc6\x1b\xd4b\xcb\x87M\xd4\xe1\\7\xb0T\xf8\xbb\x84-\xac\r\x7f\xe2n\xf7X\xa3\x82\xefK`\xde\xeej\xe6\x938\xd8\xa0\x17>$\xf6\xfc\xa1\xb2O\n\x9c\xf6\xc5\xc9\xb7K\xff\xd8\xb0d3\x0f\xc0\x03t\x81\x02\xd1\xe4\x11V\xedW\x8a\xb8\xac\xfc\x1a\x88\xe2m\xb4\xb0/8k\x8d\r\xfcU$6\xe7\x99z\x1d\xcb<\r\xfa\xff\xda\xd9\xe5\xc2\x1b\xa2\xbf\xce\xea\xf8J[\xfc\xf5\x19\x1c<\xe7\xf7\x99A\x99\x90\xd9\xb9\x13\x07\x8bG0`\x13c 5\xd5\x1f\xea3\xf8`\x0caK3\x8b\xfc\x1b\x99C\x0c\x07\xc3\xa4\t\xdb\x91&/\xed\'f.\xf6\xf5\x12\x94\xa3\xfa|\x13\xec\xc6\x10\xf8\xc6\xe5&\xcb\xa0\x810\xf6\xe1\xe4n\xd0{ x\x8a{Jz^2=\x17\xa6\xf7\x99\x14#\xa1\xf5\xdf\xb8~_\xaf\x1e\xab)\xa0\x8ai\x91\x1dAi\x8b\x83;[\xac#\xdc&6\x84l\xb2\xa26:f\xfa"t8\xb3\x15\xf0G\xf5g\xa1\xe5y@<\x07\xc4\x1a\xee\xa4\x14~\xa5\xb1x\x11C\xc3j&\xbf\x1f\xad\xc0\xa3\xf9\x8d\xdc\xcf\xed\x1b\x13V\xfa\x0fo\x80X\xb5\xd3\x1e^\x1e #c\x9e\xe7\x00\xb0}\xe0O1\xde\xfe\x88\xd3\x8e,\x95\x8f\x03\x16Gg&\x05>\x06xv5\x8a\xee\xdf\x7f*dXr]\xbfguq\xb1\xb0\x81\xa2\x1b\xbb\x87t\xdb\xf6\xc4gqX\x8eX`\xe7 5\x87\xa1"\xd4]\xb3\xe8T=4\xf7/Ww\x87\xd3\xe3\xe3\x1ey8\xfd\xa1\xaf\x0e\xf0,\x95\x8c\xadB\xf7\xec8\xf0\xd9\x91\xd9\xa7\x0b\xa4D\x9e\x0f\xe2\x0b\xc9\xc8\xa2P\xc8\x86X\xcc\xdeU\xfc3\xde\xcf\x0cr\xbcY4\x81\x8a\xc5f\x16\xdb\xad\xc9y&S\xbed\xf2\xc7\xbc\xa7\xabMhMS\xfdv%\x1cy\x0bY\xf2,\x1d\x9dd\x02;\xcc0\x93h\x83\xf7ML=,$\xc3\xd0\xe4\xd4\xae\x08?g\xb4jVZ\x96\x016\xd4#\x0b\x98\xa7\xa7\x94hf\x9b\x10Py\xbbn\x1b\xba\xf2\xdb.\xa2\xaf\x7f\x8e\xe6\x14#\xdd\x12m\x93%\x83\xfd\x98\xea\x9dr\x8f6*\xa4w#\xa7W\xc3MT\x84M\xf21\x1c{J\xac\xbe\xde\x1a\xe6(K:\xdd\\\xe8\x83\xcfl\xbf\x7f\x90\x11|"\xbe\x7f_\xb4A\xc1,\xa1\xdd/\xfa\xf6\xe1\xfc\x03%p\xcfK7cH\x9d<\xf8\x02h\x85\x80H:\xb3\xff\x97rMe;\\`8\xbf\xca$\x8b\xdb\x99\x9bM\x06\x9b{\xae3\xfc\x01\xb1\x8fG\xc5\x15OyZ1`"\x02|\x8a0\xe9OD?I\xd1\xbe\\[\x84eU\xc6\xd7Ux\xe8c\xd0\xa6\xe0S\xf3\xb2\x8e\x9eh\x19\xfc1\xa9\xbe\xf0\x1d&zCs\xe7!\xc7f\x87N\xb1W7)3\x88\xf8\xc9\x08.\xd9\xef\xb5\x16u\xf1<\x05\x15\xa6\x9fN&\x16 \xf7pP\x14\x92]\xcfd0\xcc\xb6\xf5\xf8\x02\xc7\x0f~\x80\xf6\x10\x01\xe48{KOw\xc0\xe1\xfb<\xbf<\xbb?\x86TH\xd9O\xa4Q\xa8\x8a\xba\x9c"4A\xad\xf8\x842\xa4\xdfAB\xc2\xa3\x8e\x1c\xb693\xc4\xdabS\x08Bm1\xed\xd7@=\xc7P\x85I\x15\xc1>\x9a\x99\xfd\xa2;c\xa4,\x9f\xf7pj\x12\x03\xf3\xebW\x9d%\x15\xba\xa8\xd2aGHx\x8fi8\x8a\xf3_\x9c\xf8;\xcc\xe6\xed\xc6CDT\xbbe\x02\x8d\n\xa1\xbe\x13a\x87=(vU\xf7\x0bpQ\xc0\xdcG\x17\xdb\xef\x8bis\xeap\xab\x98\xe5\x1681\xef\xb6\xc1\xc2\xf16`P\xcf6\x19\x80cF\xf0\xfe\xe6\xc2\xe1\xda\xf5&|\x166\x87pi\xaa\x05\x0c\x01~\xe61\xea\xfa\xfc\\\x8d\xef\xc9K\xbd>9\x0e\x83\x88%i\xabC*I<$\x90\xc5\xa8\xde{\x89\n\xa40~\xe5V\x82O\x13\xf4\x81\x951A\x9fYU\n6\xa7\xa5\xc4\xf6\x80\xda32\x8d\x1d\x14\xe7\xe5Lli\xcb\xf6\x90\xfaPd\x0cHh\x11\xdc\xa3o\xd7\xe2\xf73\xad\r_\xa6.\x9d\x80\xcd\xb1\xb0^J1e\x90\xe8\xcf\xafv\xce\xf1\xea\xafWA^\x9b\x12\xf0\xb6\xa9x\x97\x83\x8b\xba\xd9Y\x1cv\xea\x87\x8e\x9cD\xccY=T\xe3h\xbaC\x9f\x86\x177\xa2\xd1n\xda\xc8e\xfa\xd0\xe7\xb7\xff\xce\xd0h\x7f\xae\x05\xf7\xb7\x98\x05\xab\xf2\xb1\x10\x14}\xfb\xb7\xb6\x1d@\xb7\x15\xe0&\xbc\x0f\xc40\xfc\xa9\xcft\xa9(\xfap\xd6pq\xf6N\xe1\x97S\xf5]t\xe6R\xa6\x84\x86\x04\xcd6g\x9d\xbc\x97xf\xaf\xe2J\xd2)\x06+\xb5\xfc\x86\xc9m\xfbv^M\xc8\xe1\xc6\x10\xbf\x86\xe9\x9d\xda\xf2\x99\xa3\x84{\x1eF\x9e'
|
|
|
|
|
|
2024-12-14 17:54:48.432144 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25572
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808888569
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.434860 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 60
|
|
id = 1586
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 40
|
|
chksum = 0xc5c1
|
|
###[ Raw ]###
|
|
load = b'J\xf4k\x98\x9b%:\xa7\xd9P\xaa\x10\x1d\x1e\xaf\xbc!\x8aW\xear!\xa13\x8f\xe6[z\xc9\xe1\xb3\xf6'
|
|
|
|
|
|
2024-12-14 17:54:48.439377 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 30922
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 90
|
|
chksum = 0xc5f1
|
|
###[ Raw ]###
|
|
load = b'^\xea\xa4\xfd\xe9\x04\xea\xaf`\xf6\xf7D\x01\x835A\xac\x94n\xb4\xf9p\n\xe3\xa1\x1d:\x13\xe6\xc4\xbd\x06\xcbZ\n\x02\x90f\x8a\xcduT\xe1V\xb9\x94\xad\x1dV;\x82\x1fN\x8a\x9a\xb5\xa63jf\xa1\xf3\x90Y3\x18\xef=\x87\x91\xf9"\xc4J$\x9aS66\xe0\x84i'
|
|
|
|
|
|
2024-12-14 17:54:48.445003 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:61224 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7869
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 61224
|
|
len = 1258
|
|
chksum = 0xb4d4
|
|
###[ Raw ]###
|
|
load = b'\xcc\x00\x00\x00\x01\x00\x08\xea\xcc~X\x91`\xedq\x00@o\x9d\'\xc9\x0f\xd6\xa9\x1a\xb9=\xcct\xac\xc3\x04+\xc1Z\xe7>\\\x0c\n\xc3Ba\xac\xcf1\xd4\xb3de\xf4\x06\xc8w\xd7\xf2\xa1s<\x96\x03c\x89(\xe1g\xdc\xc2_\x14\xb7\xbc\xab\x00\xfa\x86\xfd\xf9\x0f/\xe5\x02h\xd027n^\xff\x9bMyD~{\x85\xb2\xa6%\xcb\xfeN+OO\x1a\xce(\x14\x0e\xb4^\x9f\xc1O\xacK\xff\xdew8\xdeHW\xb68\xd9\xdc\xd1\xe7\x00\x00\x00\x01\x00\x08\xea\xcc~X\x91`\xedqDP\xffn?+t\x8f\xb0\xcb\x87\xca\xc9!\xd2\x98\x9dxq\x0f+\x83\x90|\xb1\xbe&\xa4\x87\xbb(\x1ct\x1eY\xe3xf\xeb`\x81\x05\xddX\xed;J\xb8\xd3\x8dz\xaf\x896%b\x0b\xb0\x81\x14\xee\xd1Y\x03\xfd\xb1\xbf\xea\tb,\x06N\xec\x8b\x86v\xa2\xdb>\nFx\xfeSv\x97\xe6\x88\x10r\xe7\xe6\xabR_\xc9O\x88\xc1\'{=\x9d\xac\x12]\x8f\x8d\xc1\xfc7\xb8\x03J_\x1f\x89\x98\xa9\xd31\xd7\xac\x83\xf0\x93\xaa\xde\xf7!\x98\tM\x0e\x0c\x9f\xd2\xe48*\xff\x83P\xb3\x99\x04rU\x0b\x89\x90O\xcd]J\xcf\xd0&\xecO\x04\xf0\xa2"\xec\xd3\x19\r\xa2-\xb6\xc4\xe6\x80\x83\x12\xdf9\x07\xe7\x86\x0eU\xd1\xbaY)x\x9f\x8dUL%\xaa\x86\x02\x81\'\xa1\'\xbd#t\x85\x9d\x187z\xe2\x99X\xe1\x9f_\x98\xf1\xaa\xe7\x85\xe3p\x8e\x06;t\xf8\xe93\xaa\xec\x8fz5[\x7f[l\xe9\xf5\x92\x1e\x95a\nuN\xf9m\xff\x93\x9fN\x8d\xfb\x19\x9f8\n\xb2\xd1xv\xd0\x90\xccc>\xec\xef\x18\x11&\xe1\xb6(/2)T\x927(\xf5U<\xa06*\rz;\xdel\xab\x88r\xa4\x0c\xdc_\xfd\xc3\xecm\x89\x9aI\xe0\xb1\xdb\x18;\x17\xff\xfc\xe5\x7f\x83\xd8\xc3\xa0\x1blt\xc7\xa9x\xb7\xc5\xd3\x9f\x16Z`\x01\xc7\xa85(-\xf4p\x8d\\\x9eE\xf1o\x10c8\n\x0c\x93\xa6\xf0\x8fE\xdc\x9f\x8cg0e.\xa6r\xf7\xbf\x97\xee\xab\xb4\xa4\x8f8\x8f\x8a\xa5\x05z\xd3\xa4\xf3\xf7O#\xca\xb2x\x87!\xa3\xb0N\xd5p\'\x88\xb2\xcd\xa0\xec\xaa\x08\xbc\x9d\xea1*!\xe7\x10/\xaf\xf9e?A\xd9\x97\xbc\xe9\x99\xf8\xb4\x1d\xe0s%\xcf\x04k\x8ck\xc7\xc2\x19\x7f\xdfV\xbd1\xef\x04\xfd\x98{\x0e\xe6\xc0\x01\xae\xc0w\x1c\x08\xb2\xc7\xc9\xed\xae\xca\x84\x85f{\xa63\xff2)\x86\xb7\x17\x915\xfb;\x93\xf1\xf7\xfaa7L.ph\xb9;\'\xc4\\J\xc8YV\xe8TH \xe9\x0ex\xd7DU~\x94#m\xda1=\xeb\xbb\xb4\rA\x170\x02!l \xfb0\xbf"\x82bN\xe3\'\xb1F\x9f\xc4o\t\xbf\x88]\x03\x86w\xb1\xc0s\xa1\xa1\xaeX\xa8z\x83t(\x8df\x05n\r}\xfapN\xb8.Gw\xf0v\xe1\x88\xaaq\xf4\xc2#\xdbQ\x88\xe7\xc9\x0b-\x16\xae\xd8\x12\xc3!L\xc6\xef\xcd\xa8Cf\x03\xe7\x83\xbd\x86U\xcd\xdeB F\xc3V\xcej\xe8\xc2\xea\x88\xe7\x10zoX\xb1\xf6#\xa8\xa7[\xe5)Al\xc8\x10N\xe1\x9bl\x00\xa4?\x05\xcc%\xfe\x14\x18\xd9a\x13HN\xdeh\x84=S\xfc\xf748#\xf10$\x8e3\xfb\xefi~\x84\x8d\xd9L\nS\xbe\x16\x1f\xe3\xe0.c\xb5P\xad,]\xe4xvB2\x88\x0b\xc0+\xf4Bz\x1ab\'\xf1\xfd\xaf\x10\x02\xb3\x10\xeb\x94\xdc\x16\xdf\xa3\xc4\xf7D\xbbq\x08\x1e\xe9\xc4\x8f\xa1\x87\xe4u=o\x16\xb5\xa6\xcb\xa8\xd3\x11\xc3]\xff\x88\xed\x99q#a6c0\xec\xea\x83\x81\x89\x8a\xdb\x1as@\x03\xe8\x85\x0f\xf8\x1c&?K\xeb\xbd\x17\x08#}\xe1\x99\x7fb%\x19\xca\x1b\x94\xce\xb7\x8a\xdf\xcf\xec\xe9DHB\x19\x9a\x9d\xb6m\xea\x93P\xb7\xfaH\xc4[\xa3\x04\x92\x91^\xb6\xa4\x88\xb1\xd4\xde\xafO\xfc\xed\xbb\r\n|#6\\m\xe8\x11\x05"3\xfc\xaf\xf4kX1_BE\xdci\x0b\x94\xf1}\xf3\x7f\x86\xce}\x87\x89b\x7f\x12\xd4\xdb\xec\x05K\x8a\x1f\x90-\x12V\x02K\x92\x02\x9b\xb1\x90:\xcd\xa7~\xac<l\xbd\x1d\x83\x15|\xe3\x0c%\x03X;~9b\xaa@\xfaj\x88\xb5bFDUHj\x0f.\xdc;\x1e\xa4\xed\xb2\x98Y\x7f\xbbq\x86j\x16\xa4U\x91\x8c\x80TML\xd5\xe2t\xe2\x98\x9a\xf0\x18\xe8\xd7}z\xfd\x8d\x0bI[\xa4\x1a\x15\xb0\xa4\x07M\xaf\xf2{w,\x01\xf85\x18\x9f\x88\xd1x\xc9\x82\xf1\xec\xff\x1c\xb4lY\x8a\xbb\xbd\xc3JI\xf2\x89\xdff\xcb\xc5\xf7M\x8d\xf9\x08\xd5\x85\x00\x8e\xdd\xc3\xfe\x1a"\x8c\xcf\xe5\xc6\n3\x81Rn\xc4L\xca\xbe\x9bY\xad\xeb\xd2\x13\x897\x97SUPZ{q\x02\xf0\xef\x04\n\xa9\x92\xe8C\x02]\x0f\x9dN\xb3:\xc9\x84\x03\x8a\xdd\x01\xc6.\xea\xbd\xd6[>\xc7\xe0\x7f\r\xd6\xd3n\xff\xaahX\x0cs\xff\xf0\x80\xe9\x94\xc3\x91\x9e\x1f\x18\xa9z\x9aQ\x06\xb3\xeb\xa9MF\x8a\xe6\xe8'
|
|
|
|
|
|
2024-12-14 17:54:48.449653 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:61224 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7869
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 61224
|
|
len = 1258
|
|
chksum = 0x26b4
|
|
###[ Raw ]###
|
|
load = b'\xef\x00\x00\x00\x01\x00\x08\xea\xcc~X\x91`\xedqD\xd1\xe2\x16=\xae\x10#\xb8zUfS\xf1\x8e\xc8\xddXx\xdf!8\x91\xedY\xe6\xa8S\xee\x02\xb9eJ\xb7,\x1c\x0c!\x81F\x98O\xc5\xa9~\xd4\xce\x89\xb1\xbd\x93\x10\xbfW\x8a\xd0y\x94\xe6g\xd2\x93\xc2\x8fff \xf7f\xb2rJ\x9e\xa9\x1d+7C\xef\xb4\xb2S\r\xc4?\x96\n+\xb8\xfd19\xccp\xcfp]\xa5^"\x1c\xda\xe4\x10\x04\x1bZ\xe8\x96t=o\xe5\xe3\xc4y\xb4\x1e\x84\xd9\xce\x810<@\x17X\x1cQ\xd5\xd9\x87\xeb\xe9U\xd3S\xac\xe6\xae\x8e\n\xf7S}\xfdF\x9f`\x1b\x1c\xc2V\x95|v\xae\x7f\xafE\x82\xa0\x04\xf2\x8fl\x92\xfb-G\xeak\x1f\xe9\xccNR\xd5\xdc\x80\xa2\xf7\xa4\xfdfUt\xbe&\x9a\x03\xfe\xbb\x05{@\r\x99\x92\xec\xda6P\xd5Rj\xe5~]\xa0B\x88\xbb;\xb7Fk\xf3\xfe\xfa=~&\x93\xd9\x11\xa3\x8b+n\x82\xf33\xdf\x9ap[\xfd\x81U\xfe<\x86\xe6\x17Y\x96\xa3\xa8\x1b\xde\xa8\x8a\xfc\xa2\r\xba\xb0\xd7\x1dVZ\xfe\x01\xb2\xfe\xac\xbb\xbd\xdc\\\x04\x0f\x00\x9ayH\xb3?\xed~\x13\n\x05\x85\xa28\xbb=\xbb+\xbcI\xb5\x00~2\xe1%\x06WS\xd9Q(\xa7\x1b\xfc\xe7q\x14\xda\x11\xb2\xfd\xd6 \xcf,\x89\xb5Gw\x0c&\xfc%y\xd1\x98(eh\tE|E\xf1\xf5?%Z\x1d7\x8e\x04\x91\xe1\xa7\x07\xc8\t8\r\xad\x827\xf4\xb1(Y\xe2-\x17\xfcH\x99\x02\xee\xef\xd0\x00\xc2\xf0\xe2\xc6\x91\x17\x01\x7f\x00\xf4\xb2\xdb\xdf\'"i\xd2"#\xf2\xc8Z\x04\xf2\x1f\x04^p6==X\x95\xab\xc6\xc5>j~\xfe\x12\xb0\x86\xd2\t\xba\x02\xbe\xe2\xa5\x16\x7f\xc3\x95{\xe9#\xbbuHw\xbfW#\xb7\x8b\x951\x16-G\xc3#P\x0bm]\xce\x07\xc5\xde\xdd\xa8\xea3\xe7"\xf6-\xd9\xb1\x0b[K\xcc\x8d\xecV\x8d\x1ah\x907\x05\x81\x04\x84,~\x01\x14\\\x16\x94\x9f\xc0\xdf_\xc0\xe1\x1ab\xe9O\xf2>\xb7\x8at\x90~\x01\x04\x1e\x1a\x83tvu^\x89\xc1\xd3\xbe\xaf\xd9r\xb7\x9cE\x00\xefk\x97\xaf\xdc\xa2l\x03\x07\xe7]\x99:\x04\xc7\x89\xabQ7\x9fo\x8a6y7\xd2z\xa8\x14\xd1TQ\xceGZ\x11\x8f\x895\xc8\xd9.\xbe\xc5n\x84Z\\\xf3\xcc\x88,\xd5\xa0J9\x8csS18\xe6\xb8\xdffh\x18\x0c\x98\xa4\x91d\xfbz8\xf8^!\xcboP\xd5\xbe\x96\x81v\xd4g \xb7\xce9\xcb\x97\xf7d\x93\x8b\xc4%\xff\xa1\xef\n\xc65?M*\xb6@\x9f\xa6\xb5`\xf5c?\xe1?7c\x19\x82|><\x14#\xbe\xc9\x1c\x0f\xa9\xf7ff\x8a\xf5\x81\xac\x9d%\x07M\xfeI~#B\xfe\xffF 1\\Gn\x8b\xd3\xbd\x95\xa3\xcde\x04aH#\xa6\xfd\xd4\x95\xb9.\xcc\x81:\x8e\x92\x1a\xe3\x1b\x01xx\x93G\xeb\xd9\xb6\xcc\x98\xa9Cs\x13W\xc0\x08\x80\xd8H\x8d$I`\n\x14y[\x07\xb1\xbb\xad\xb7\x90&\xa0o\xd8\xef]^:\xdc=\x1d\xdc\\\x97m\xfd\xcc^\xc6=-x<\xab\x17\x9bj\xcf\xf9\xdb\x91d#:\xcb\xc7\xd0\xb7\x87\x90\xfa\x90\\i\xdfC\x82h>\xce\xea\x93\x90q\xf4\xf6\x90\xbe%\xd6\x04\xe0<\xd8\xa2"\xe0\x15\xc5\xaf\x9b\x84\xe1u\xe0\x18\x1f$|a\xe2\xd2\xa4\xce\xe5\xcb\xa7\xbf\xcf\x17a\xc9\xa4\x93\x1a@\x92|\xa1\xcb6\x81\x80\xa7\xb7z\xef`G\x08\xdbvr\x07SL\x03\xb1\x91\xd5\x03\xdd\xb9a\x10\xa7\xb2\xb4\xab\xb4\xfb\x82Wj.\x8f\xbdKc\x80\x8f/\xba\x82\xf6\xa3\x88\xa9m^\xf1\xdeDn\xbf\xb9\xa4f\nq<j\x14\xc2R\x12\xc5\x89\x80\xd5\x80Bb\x1b\xbd\'\x9a\xccw\xeen4\xdeV|\x8d\xd3\x9b.k\xf4\x9a\xe0\x89\xd8\xfb\x1c|9\x0e\xcf\xc4\x95\xe4L3\x1f}f\xbe\xff\x9c#\xcf\x8d"%\x06\xdf\xdd0\xd8\xbe\xcc+\x1c\xa8^L\xd0\xee\x80wT\xc2~\xb6r\xc2\xeae\xe8\xf7f\xf9Pl]\xe1\x03z\xe0\x9b\x8b\xa8,Op\xc1k!K\xe99\xc9\x9b\x8bE\x1fi\x0c8b\x9a\xc9kg\xc0\x94\xa4\xab\xe1>\xf6\xf7\xf4\x98\xbd\x0f}\x03W\x82\x0c\'\xbf\xb9e!N+\xf3\xb6T:\x17\xe5#2\x86\x1fxw` \x8e\xb4%l\xda\xfd\x85\x1f/!\xa8\xe4\xa8)l\'\xb6\x96U\x84\xbc9-\xf2)4\x90\xd7\x8e\x85w+\xa7\xfcw8<\xe9L\x01\x96\xef\xb0g\x0f\xe0}r\x19\xddU\xafN\x85\xda\x08\xa5ma\x9fa\x8a\x93Fq\xa8L\x12+\x99\x0c\xfe8\xe9R~\xe0E]\xb5z\n\xb5\ty\xd9rZ\xea+\xfe\xbe\x88\xd3\xf1\t\xba\xf3\x00z4qn\xb4}w\xa2\xe1\xef\x8cj@!\x87\xd7\xedY\x1dx\xb3\xf4Q\xdfI\x1f3F\x08\x86\xfa\xb1(\xb8\xf8H7\xb9\xd3\x1dT\x00\x04\x837t\x10\xe7A\x0bf"\x10d\x14i\x12\xe6I<\x8c\xe2\x82\xfa\xfd\x92\x881(\x04\x84\xbcv\xc5\x07J^\x13\xa1\xc1\xbc'
|
|
|
|
|
|
2024-12-14 17:54:48.454565 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:61224 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 524
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7b5b
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 61224
|
|
len = 504
|
|
chksum = 0x4431
|
|
###[ Raw ]###
|
|
load = b'\xe6\x00\x00\x00\x01\x00\x08\xea\xcc~X\x91`\xedqA\x9d\xef\xf9\xfd#\x90\xd0\x03\xf1\xfcm\xf3?\xcf\x1f\x17a\xfe\xcf\x97w\x0f\xdc\x98R\x18-\x8b\x97\x16\xa3\xeb\xbc\xc9\xba\xd5\x1bP\x83\x0b\\\xf5\x89\x8c\xa3\xef\x8c+-\xc8\'\x9d\x96\x99J\x9fO1\xc71OU\xb3\x1d\xcd\xbf,\xffj]\xd6$\x92&\xb8/R\xc7\xf6<\x05\x00\x01\x1b%\x9e.\x11^\xcc\xd2\x15\xdb\\=%"u\xb3\x1f\xa5\xfc\xceQ\xabR\xb3\xee\xa7=j@=\xb4r\xabL\x07\x00(\x9c\x9e\x8f\xe6\x8aY1!\x9e\xb8\xba\x80\x9d[f\xf4\xc4c\xd7\x81$j\xba\x0f{\xa0O[i\xb4\xdd-\x84\x806\'iD\x99S\xa7:\x03\x99gK8\r\x01\xed\xa8\xaf\xc8\xa6ft\xe6\t\xca\x18\xe0\xd4ZZn\xfa%\x953\xb5O\x92=\xc8E!\r*\x9b\xc0\xdd\x05\xe7P\x9f\x83v\xf3\x91\xd8\xd3\xb3W\xc9X\xe5L\xaeOp\x01\xa4\xeb\xbd-\xeb\xc6\x9d\xda\x18\x9a+\xec\xd5\x02e\x82\x0e\x066J\xf3\xe2\xf8\xc1\xd7\x7f\x8a\xb0\x0f>\x1b\xb17\x15\x1cA\xa9\xd1\xe6\x1b\x87~\xec)O\x0cK\xfa\xcf\x08\x01{\x94\xf8\x87A\x05\\\x84\x8aZu\xb5\x0b\xee\xceT\x86!\x9d\xb1w\xc5\x9d\x91\x80\x1f\xbc\x86\xea\x13%\xbb\x81\xafg\xdb&L%\xa7)+f\xdd\xbb\xfcl\x04\xadq\x08\xf7\x80\xfe\xb4\x97\xb14\xbc\xfa\xe2\x08\xe2 \xcd\xc0\xb5\t\x8d\x89\x8fn\x0f\xc3\xb1\xe6\x0bsi\x8b\xc1\x0f\xe2=#\xe2\xab.@\xaa?\xf6\x04|\x80\xd8\x07A\xed&\x12\xd6\xf9\xb4\xe3W\xb4\xb7\xce)\x87f\xfd\x0c|\xdc\xd4\x14^\xa1<\xcb\xda\xe1\xff[=\x1c\x1c\xc7\xde\xe39\xbe\xffO\x15Cl[\xc9K[\x0bV\xb0s\x93\xab2C\xde\xcawU!M\xf7\xfd\xe6\xacR\xa5\xe9R\xad\x81\xc8\xb0\xdb\xe6\xa9\x1e\xa15\x9c\xe1\xd6E\xb2\x18\xf4.\x19\x18\x0e\xb2\xe1G\xe2\xf1\xf5\xf6\xd8\x14\xbb\xf4\x12G\x0b\xf9\xbfb=L\xf1s{'
|
|
|
|
|
|
2024-12-14 17:54:48.457948 - Ether / IP / UDP 192.168.1.11:61224 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 67
|
|
id = 30923
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 61224
|
|
dport = https
|
|
len = 47
|
|
chksum = 0xc5c6
|
|
###[ Raw ]###
|
|
load = b'\xee\x00\x00\x00\x01\x08\xea\xcc~X\x91`\xedq\x00@\x16\xfbd\x15\x84nM\x1e9\xf6\x89j\x81\xf6Vf\x89\x13X\x85\xe8\x1f\xef'
|
|
|
|
|
|
2024-12-14 17:54:48.461196 - Ether / IP / UDP 192.168.1.11:61224 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 190
|
|
id = 30924
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 61224
|
|
dport = https
|
|
len = 170
|
|
chksum = 0xc641
|
|
###[ Raw ]###
|
|
load = b'\xec\x00\x00\x00\x01\x08\xea\xcc~X\x91`\xedq\x00@G(\xf0\xf06d\x04T`\xbeCi\xf0`\x90\x165]:\x8c\x97 \x08rk%\\X\xd8j\x15;\x84?\xf4\xd2a\xc2z\xc0\x84%\xdc1\x19\xad\xfcW\xda~\xaf\xf2\x9d\xff\x93j9\xffZ\x93~\xa2\xeb\xeb\x9b\n\x8f\x0f%\xe8\x0c\xc8F\xea\xcc~X\x91`\xedq}r\xf5\x1d$vyD\x95\xcd\xe1\x14lsJ\xfeH=ew\xa7[\nm\x00\x84\xc9c2\r7)\xf7[\xc3-z/9\xb9[`\x9d\xd5>\xd9\xd5.\xce\xdb\x04l\xc0*\xca\x06uL=\xd0XL\xb0\x1b\x05'
|
|
|
|
|
|
2024-12-14 17:54:48.467551 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:63056 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7e33
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 63056
|
|
len = 32
|
|
chksum = 0x4297
|
|
###[ Raw ]###
|
|
load = b'Gb|u\x9d\x8c\x96B\x19\xdc\x08/1\xc7\x11\x7f\xf7\x04; \x19\xa0V\xc7'
|
|
|
|
|
|
2024-12-14 17:54:48.473107 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1236
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7991
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 1216
|
|
chksum = 0x8eb0
|
|
###[ Raw ]###
|
|
load = b'H\x8a#\x88\xba\xf21\x7f\xdetNv\xd6(i^\x16l\x9dCWyq\xff}\x90\x03\x1f\xea\xf2\xdb\xe3\xac\x19\x08\xb2\x8c\xfb\xefE\xc6\xc0\xf2\xbb\xa4\xc4\x19\xf8,\x0b\x86U\xdep\x97\xdfn&5\x0c\xff\xb6\xd7_nq-\x99\xba\x17}\x87\xa3\x85\xf0QA.\xe9v\xc9;v\x8b\xd0\x04K\xf2\x17<|\x1eoG\xa9\xa9\x076\xbd\xf4o\xbb\x9b\x17U\x84\xea\x10\xaej"B,\x1a\xb7\x1eY\xde]\xa1\x89X\xa1\xcb+=\x13ey?/\xb1\t\x9b\xf8\x0b\xef\xd0\xdc\x7f\xc3`\x1bbf\xe8\xff2\x96\xdd\xe9I\x0eD\xc2\x8a\x15\x92\x94`e2\x91aL#k\xb0s\xfc\xc9\xdfH@\xa2\xbb5\xa5\xd2\x02\x86\xa1\xe5\xb50\x12\x99\x88\xa3\xbc\xc0\xdc\xa4\xf8\x82\xe1h\xa9\xec\xe1V\x95\xf4\xd3\x97U\xfdt\xd0\x00\x91\x96K%\x03\xb4!\xdct\xda\x19K\xcd\xce\x1d\x9a\x8a!U\xe1\xfcd\xeaq\x82\xb82E<\xa1\xba\xa5\xec\xbe\'[\xdcfD\xdd9\xf8\xfe\xd0h\xf3\x89k\xcc:5\x01F\xfc\xf9\xff\x15\xfdqq\xa26\xee\x1d~?\xda\xe1\x16\x18\x85\xabk\xa5?\x07\xf1\xfd\x8d\xf6+E\xc8>"t\xe7\xe4\xe0\x82F\x9e\xfbb_\xf0e(\x01\xeeo\xe3\xbaZ\xb1a\xa0\x8c\xa8,f\xad-\xbe\x8b\xff\xc1\xe9\xe0,\xab1\xf7\xb6\x92A\x89\x06\xad\xec\x95\xfa0\xaf*\xdf\x0c\xcb{T\x9dx|\x94\xa8\xec\x1b\xb9*\xa1A\xa0\xf0\x88\x9d\xa1~z^\xf1\xbb\xf0l\x93\xd3pt\xe7Y\xba\xe9=|\xd3\x19`}\x84<r\x93 ,l\xf7\xfcu\xba\xde\xe3\x90\xdd\xb6\x93\xac\x10%\xee,_\x7f\xce\xc9\xb3!w^\xf3g,\x91\xab\xcaQ*|\'\xc9\xb2\x99\xff\x08\xd1\xe8\x7fW\xe180%_\x8a%\xa9N\x9fSB\xe1v#{J\xd26\xb9\xc4\nl\xaa\xfd\xab\xd8\xf0\xea\x87\xe6\xfd\x8e\xd1\x88\x81\xa4\xa9\xb9\xd0t\xba5[\x13\xa3/\x1d\xf3g7\xe6\xb1\xeb\xa2\xa1\'\xf9\x19\x89\xf9\x8e\x8d\xa6\xbc;\xf7\x96\x1cF{\xd2\xb9D\xac,y\x00\xd0\xa3\x88\xab\r\xf2\xe9\x9d\x03kCB*\xfc*\xb2\xbc\xedVI\x1d5{\x8e<\x0b\xf7\xf9\x83f\x85l2Of5k\xafi\xfc\xeb\xd6k\xbb\x19%\xce$-\x14\xddK\xda\xc1\x98\xdf \x96\x97\x02\xfb\xb4\x12\xd2<\x13\xf5,\x8c\xfb"w\xb4\xcf\xd6P\x1bd)D\xb2gv\x00\xe6\xff\xd5\x1b\xe8\xbb3u\xf6u\xdd\xb1G\xe6\xe8\xe3\xf6\x99\x7f\x0f\x17\x7f\xd1\xc7\xab\xee\x84\xda\x81\xd1\xd4$\xf1\xd4\xcd\x1d\xd5\x859\xf2y\'%O\x1b\x89\xd4J\x89\x8ce\xaf{\xba\xe0\xca\x9b\x1fj2C\xc2\x9cI\xa0\xce\xa2\x93\xc1\xa6C\r1\x01;*\xf0V\x8cH\x7f\x93\xdehYvK\\x\xdfl\xd7\x85\xada\x7f\x84\x9d\xff\xa2_g\xf6.F\x1eE\x07v\xf8\\\xc2\x96>\xacg:\xcc\x86j\x993\xb6\xe0c!~\xd0O\xb8\xbb\x13;\x0c\xc2\xe7$\x97\xdc\x00\xcb \xf7\xccK\x81\xe8\x01\x90y\xfa<pK\x13\x1eA\xab\x11\xde\xefG\x90\xfe*)f\x9b\x86%=\xb1\xad%7\xfe\x08\x06E\xfe|3\xd7DH<]$\x00\x1d\xdbeO\x0b\xb4K\xfbr/\xdd?G\xc5\xfe}\x84\xc5\xe4d\xf8\xef\xaf\xb0\x01\xb8\x80M\xb3kJ\xe4\xf0@0\x13\xca\xbb4FApc\x0bE\x86$\xea#\x9c7\xde\x8d\xd3\x83:<\x1b\xd2\x10\xa2T%\xe5\x99\x8co|u\x19#\x03\xd1y\xcfM\xbe\xf2\xad\x9b.,Fm\xa1ca%\xa2\x17Ty\xe2z\x83\x82\xd0\x99\x0e\xa0\xa9\'\x86\xe0%\xcdS\x18$f\xa8\xe8\xbb\xf2\x81k\xf8u^\x85s\xae\\h\x91\x8d\xa0\xd7\xb4m_\xc7\xe0\x97A\xb8\xa4\xff\xe4`\x0b{\x0b\xdb\xe4\x06\xf0=\xb8\xff\xa6\\\x97\'\xfb\x88f\x86r\xc5\x9dp\xb7\xc0\x1d=p\xa1\xadv\xec\xa9\x9f\nI:c\'\xde|\xe3r\x1e\xc30@!x\xbe\xeb\x1e\xa0]"\x93\xa0\xbcE\x87\x0c]\xb0f\x19\x08K\xff\xbb\xce\xbc\xd0\x89Y\xcdu|\xaf\n\xa3\x87Z\xa4\x9b\xd5\x8c\xe4e\xa2\xd4\xb5\xfa\xb8\xa2\xde\x03R(\x02w\xb0\xad\xee\xbc\x97\xe3\x84\xf9\x8d\xe1`\xa4C\x1d\x81\xdf{\xae\x91\xdd\xb2[\xf3\xcc\x04\t=\xdf\xd12^\xbd.\xf1\xba\xabq\xc5L\xe0\x85\x94zO\x16V\x12\xd8\x00N\x93T\x95\x8f\x84K}\x153\x1c\xb5s\x11n\xf8\xfb\xf1\xae\xcc\xc1\x9awg\xa5T"d\x8c\xd6\xa9JFAI\xbe\x89 \xb6\x12\x07\x0b_#\xf1m\xf3\xc1\x00\x92\xce\x9f\xf6\x948\x927O\x06"\x18D\x9d\xf7\x13\xc6\xebi[a\x96\xe7\x05\xbf\xecq\x92I\xd1%\xbfG\xebJ\x02\xde\xc3\xef\x19\x18\xa9}\x9c#0V>zb-\x16|\xa8\xed\xe5\x07+u>f\xd8\xa2\xe9i#\xe6\x15H\xd7\xe3T\xdf\xceF\xac\xc2\xf6\x8f`[\x11\xef\x0b'
|
|
|
|
|
|
2024-12-14 17:54:48.478695 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1016
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x796d
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 996
|
|
chksum = 0xf1cd
|
|
###[ Raw ]###
|
|
load = b'@\xbdYw\xd7f\xa33\x88\xf6\x93\x9c\x99!}\xca\xf2\xc4\x16\xe5X\xb1\xcf\x13R\xacg]\xcd8\xe3\x01\xa6\xb1\xc2\xc9*\xe9< 1\xe0\xf2\xd7\xfe\xf1"\x12\xfc\x8d\xb1\xaex\x93\x1d\x91e\x14r\xe8\x93m\xcc\xb1o1\x18Vp2X\x90\xc1\xdf\xf4\x1f\xc0\xda\xeb\xc3T\\J\x1b\xe8\xf22p\x01w\xdb\xe3{\x8cD\x11X\xeco\xe1}_\x96\x8b1\x95\xc6O\x1c>;F6\xf5{SFC\xecQ\xd4\x9d\xc5P~XfR\x96\x8d;[CKB>\x88\x84K*VY\x94\xe5\xeb`\xde\x8f\xfa\xaa\xfa\x9a\xe5\x8c\xe3\xd4M"\xd2\x15\xfa\r\x088\xda\x0b\xff\xe9w\xa6\x86?O\xc9\x82\xda.\xf2\x9e\x82\x19\x863\x7f;\x8fQ\x80\x15\x83\x83N\xf7\xc5e\x86Hu,\xf3\xb87\xf0\x86\xb3\x94x\xeea\x06vh\x18\x1c\xee\xa7\xd6\xd7\xe4\nG\x11\x1ak\xbc`\xf6\xaa3c\x02\xf5\xf8\x0c\xce\x0b\x1e\xbe\xd7\x8a"\x7f{X\xaf\x8b\nf\xd8\x93{\x82\xf2\x03\xc4/\xd5\x88\xb1\x90\xfc\x06\xf6\xbfV\xedD\x9e55\xc6\xe0\n\x96\xb1\xce5\xda\xf1Z\xa7\xff\x9f\x08=#%\xaf\x8e\xa9\x9aD\xfaa\x98\xa9\x9eM\x90\x10V\xe5\xb5\xa8\xf5B?\xbf)h\x1c\x16:\xb7=\xe9\x08*\xb7\'%\xeb\xd5JVW\xc1Tt\x1bk\xfa3=P\xd54m\x9d[\xa8\x90\x0f\x99q\x9d\n\xe3\x0b~\\\xd8\x80\x8a$\xaf\x90\x94\xb90\xcdJ\xf8\xd1\x93\xf2f\xe7\xac5&\x8e\x95\xa3\x1a\xff\x8b\xb9\xb4\x19fw\xa4!CKR\x00\x027`\n\x0e\xb3\x80\xaf\xb9\xa0z\x05P\xf6hYv\xe1\xe7\x16\x18\x8c.M\xbb\xa3\xc0c8}\xaa\xafE1$\x19B\xcfb\xa9O\xac*\xa1]\xb1w\xbd\x96\x86\xfe\x18\xe9\xf8\x1e\x05\x0f\xb8\xee`$\xee}\x08:\xda\x03Q`\x8a5\xac\x94\xdb\xdd$\xf9\xa9\x8d\x1d6VAU.\xc3-\x8cb\r\xc0+2\xa7\xffz\xbcF\x98\x97\x95z\xf0w\xda\xb1\x96hOdi\xde@-X)\x8c?\x8a\xbf\x10\xc5\x87\xe1y\x1a\x9f\xfa\xac\xf6\x981=\x02OU\xb8\xf7.M*\xe0v\x90\xe6\x82H\x9a\xceY!\xbc\xae\x1f\xdcR\x82\x0c)I\x1e\xc3\x01@\xd0]\t\x7fTR\xaa\x8e\x08\x91\xd3\xbaL\xc4\x19#\xf5t\xdco\x9cz\t\xc6i\xf0H\x06>1t9M\x83\xd6\xecdx\x8d\xc9X\xe9G\xc3\xcf<vS\xda\xe0\xaf\x15*M\xda\x85\xf8\x14<\x9c\'\x84\x06q\x84\xd7.\xd8)\xe9\x9c\xcd-\xcc1\xef \x915eo\xe9e\xb5\x89a \xb6^\xd1\x9ff\x1c\xf5B\xba\x9eZ#K\x94\x8eM,\xf1\xf7\xfb\x1dx\xbb\x8c\x84 \xc1v(\x1f\xc9\xd7|\xcc\xc2V\xbf\xa2v|\x99\xb2\xc6\x85\t\xaf\\VS\xa8v\xe6N\x1f\xde\x10\x86F\xf8\x030>\xc0\xce\xa5w\xc8\x05{\x0f\x1d\xdf\x11\x87\xb7\x93\xc4\xb6\x85#\xf5\x13HN\x8f\xa1\xc3\x06\xad\xb2\x13f\x8bS\x18\xe1:\x82\x02\xa3\x84\xb7*\xeeZ\r\x16F `I\x81\xe1\xd2\xb6\xa8\xf2+\x8e\xb7\x00\x89\xda\xf6/\xa5J*\xd9\x19\x82p\x92>\xdfx\xe6\'\t\xed}\xd6a\xda\x1e\xec\x9e\xa3\xe1\x01\x92\xcf\xeb\xa1\xd1iZI\xfe\x90^\xc3C\x9c\xb4\x19\xf3\x12\xab\xc2]\xa2\t6\xb2\xa0\xc5D\xa1\xb9j\x12\xe0d\xe1\t\x84][Oo\xcb\xac(\x19/Ht\xa6\xb6\x01/\xfb\xb0\xac\x7f\xbc\x82\xb2\x8d\xc9\td\x973jn\xebe\xd0\x14"\xc7\xbb\x193*#\xeb\x9fR\xbfP]\x83\xa2(\'^\xa0\x816\xd4\x13K\xaab\x05\'\xf2\xe7?\xe8\xf2\xf8!\x04\xed\xad$>o\x92\xf1\xcfM\xb2\xf4\xb2\xc4\x8e\xd8Z\xa2S:\x8d\x8d\xf9\xb1d$\x0b\xff\xb4\xfb!\xf0\xe0y\xee1\x96v\xa7\xdbG\x9b\xdb,\x0f5<\xc3E3\xac\xc8p\x95\xfc2\xdb\xe4\x1bm(b\x02\x9fh\xb8\xd0\x92F\xa1\xf8YF\xd2\xfd\x83\xba,m\x17$\xbd\x8f\x83Q\xed\xb8SX\xb9w7\x92'
|
|
|
|
|
|
2024-12-14 17:54:48.486952 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 2960
|
|
id = 15339
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8025
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505859801
|
|
ack = 2364269062
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x03\x00z\x02\x00\x00v\x03\x03T\r\xf1:\xd2\x98Sf\x02\xc2\x12\xd2\xb4\x08\xda\xe12\xf1\x10\x9fGz^[\x06\x03\xee\xc8\xd0\x8b@\xf6 q\x13_jo\x7f\xfdy\x00\xd5\xba\xe7OW\xdd\xc3\xe3\xe9\xaa\x14V\xfdA\x9br\xeb=\x85\xa8\xc7\xbd\xe0\x13\x02\x00\x00.\x00+\x00\x02\x03\x04\x003\x00$\x00\x1d\x00 T\x88\xca\x19s;\xf8P\xb8:)[\x8bm\x19@\xa3qk\x96\xbeW\xbdb\xae\x0e(.\xc2sVH\x14\x03\x03\x00\x01\x01\x17\x03\x03\x00.|\xad\x97\xed\xf5\xa7e\xd1\x1a\x7f\xca\x83z\xbbh#\x84\x9c\xc2B\xf1\xe4\xb8\xf8\xeaL_z\xe6\xffuHB\xaf3\x8f\xc0\x0b7\xd0)`\xcd\x91#\xaa\x17\x03\x03\x0c\xc3_\x97\xb7\'f\xa8A\x05\x8a\xeb{f\xe4\xa5\xcdJ\t\t\xb0Q\x83\xae\xb8\xdd\xa5`\x8f\xf0t\xef"\xf7\x83d\x0f3\xb5\xfb\x1dh|\xd2\x8c\xe3\xe2\xc3\x9a\xed6\xdaH\xd2\xb6(\xff\x16+\xf3G\xf0\x03\xaa\x1f\xe5M\xfe\xee\x91ln\x81!\xed\x9f^\xcal\x15\xfb\xb1]\xad\xb1%\xa3bh\xbcj\r?9\xafxK\xbe\x8ceL\x1bs\xadzh\xb2!\xb46\xac\x1f\x9b\xceeL\xa8\x8ftP\xb6$\xc4\x1b\x8f\xb8\x93{\x00\xa5\xc4\x05\xb7\x00\xcc\xf9\xde\x01\x13\xa1s\x99\x99\x95\x0f\xa2\xe1\x17\xf1\xf1\x0f\xcfP\x02\xb8\xd1\x06\x93n\xbcA\xdc\x86:\x10\xf3F\x90\xbe\xb9\x84kk\x01\xf32}L\x9b,a\x12\xa2\xdd\xe9\x8b\xa1X\x82\xa11\xeco\x07\xea\xcc\x82\xe4X}\xe8\x1f\xbc\xdb9\x92%8}_lE\x83\x8b\xe0\xc2\xe2\x05\xae\x9b\x071V\xf85a\xdc(\x9d\x12\xb3\xb2)\x9f\xa7}\x0b ?\x97\x01f\xc8)\x17d\t\xc3\xc1\x9f\xdd\x99\xa9q\xea\xcb\xa6\xc3\x15\r\x1d\x01\xc5\xc9\xebK\xffh\x1d\x14(CL\x04\x0c\x13>\xa49\x01F\xe7\'hJ\xa5\xf6\xe9Z\xbc\x0b"\x1b\xa5S\xa8\xda\x81R\xe3\\\x11\x0f\x80@!\xe9\x11<\xc8`i\x7fc`\xa9\xae\xbbf=\x84#\xbd$\xff\xba\xb8hc^\xa2&_\xd7\x82w\xc6\x15=\xa7\x7f\x1f\xf6ibzx\xa1\x0b\xcb\xad*\xbe\xc9\xdd{^\xfak9U\xa2\x12%d\x921\xa24\xca\xbf\xd7\xb2\xa2\x16.g\x93\xb5M\x04:\xe3\xbdc\xa0m\x9a\x18\x82T\xeb\x99gQ\xe3\xcb\x8ex;$@@\x9a9xqV\x81!\xc01\x9ch\x16\xa9\x9c\x1eQa\xb9\xa10\x0e\x99\xccUB\xa6T\x0bf\xa2\xa47,\x04L\xbc\xb3\x12\x9f\x9c\x19<\x9e>\xc1)\xb7\xfdB\x17=T\xed\xc3\xab\xf9\x1a\x83\x8f\x89lP2\x18\xe4wU`\x06\x0e\x816>\xc0\xa8\xef\x1d\x84*ur\x17\xda\xf4\x87\x94*\xc6\x04pu\x17&j\xba\x8d\xfe\xf4P\x84l\x07\x1f\t\xb0s\x015}\xa5F\xbd\'\xb7X\x95\xf9\xb3\xd6\xe0\x84\xf4{M\xc0\x17\xe2\x9e\xff\x9c\xa9\x9c@e\x9e\xf8S\xb2\xb6\xd9\xae\x88i\xed\xd2\xf1Y\xe5\xb3\xf2\x0c\xc1Q\x06_\xf5s\xb7:\x9f\x91/\xc5\x8fZ\xccv\xf4\xc4\x9d\xe1\xb5\x90\xc4\xa9\xdd\xe3\xbc\xc6\x12p\xb4\x9b\xa8\x16\x01\xe6\xc3\xc2\xe7m\xd9\xba|Hi\x1e\x8a\x15\xf1\x05\x91\x10\r@\xfc\x1eAbpr\xe9\xbe\x1fb\xbd\x9b\xca\xad\x02\x9b\x01\x97h\xf5K\x8a\x03*\xb3\xbd\xef\x83\xa9u\xc8\xbd\xe4f\xe3\xdc@0\xa9T(m\x8f\xd1\xb8t\x05*\xd9 \xbf\x07\xaeS\xec\x9a\x9b\x1e\xe9|[.\xb5\xe2Y\xe02\xbc\x1d\x1d\x81\xe7\x9c}>\xd2\x1bp\x95\x11x\xef\xb9\x9c\x18\x82\xe9\xa7\x80\xd7g\xff\xf6-\xce.!3\xc0\x7f\x97.\xa9\xfb\xe2\x1a\xd5\x10\xc7`\x15H\x89\xab\xa2^\xfb\xe2\xc6\x02\xa7\x9f\xba\xed\x8b\x0bK\xa3\xaf\x94[\x9dX\x9fN\x8e\xe2\xb9\xaa\xd4\xfbg\xb2Z\x06n\xab\x1a\xe1L\x18\x1b\x1d\xe5\xea\x02\x0c\x93\xf2\x80\xd3"\xbf\xd4N\xe9j\x0c,\x02\xea\xaeQ\x1e\xaf9\xa2\xd5\xc1\x8c\x9eGX\xf5/,\x96\xd0\xc8A%%7\xa2r\n%}(lz\xfe\x0eGj0\xfc\xe7\xdbc\xc6\xef\xed\x14\xc9\xbb\xf9\xe2T\xc2\x89\xffW\x86\x96\xa0\x93\x08\x1b\xb8\x8cE\x1db\xd0\'\xac\x85C\t\xc6\xd7\xdeR\xe4\x06F\xfbH\xf8(BxM6\x83\x8d\xed4\xb0\x07\xeb\xc7\x1co\x1ce\xe3\xffV|\xf3\xcc\xcf\xcc\xa0jB\x05}\x8d\xa9`_\x90\xe7\xe95!\xfcj\xf2\xf9\xde\xafF\x9b\x88\x951+B\xfc\xf1\x98\x07A\xdf\xb4VV Cx<9\xa5\x90%@&!\x89\xa9\x9a=\xd0\xff?~yd\xb4.R\xf2\xd7p\x1c\x99}_\x98j\x81~\x10\x1c\x94\x0fAh>\xd8\rY\xc3ym\xd5\xfb.\xbf\xe0\x9e1Gw\xc0D(\xb7\xf5\xe4\xb5""\x83b\xba\td\xf8I\xa3\xf4tOV\t\x81\xcd\xd9\x14\xaf\x89\x15\xda\xf1:\xecT\xc5\x15\x1e\x80\x14&\xd71ME\xbf\xc0\x86\'\xfb.\x81Q\xec}\x8d\xe8\x82\xd2\xca\xd0"\x8c\xe0\xfeMh\xb4\x8c\xc4\x03%$\xffA\xec\xa7\xe7,m\xf2N\xa8Q\xadCH\xd8{\x11\\I\x06\xe4\xc73\xe9\x93\xdc\x8c4\x1aT\x99\xb0\x81\xad\xc3\xe7\xd4/\x9d\x924b\x7f\x81\xf8\x074\xfc\xb2\xa80\x85\xae\x04~y\xbcH\xac\xe2\xd0\x02\x1c*\xc6\xb2\x99\xd8\x97\xeeE\n\x9f\xec\xb1\x96\x91\xcf\xad~VT&\xa8\x16u\xd7\x9fZ\xc2\x80`\r\x087{F\xc6 ~\x9d\x0b\xd9\xc2\x14$\xee\x98\x1e!87\xf8~\x0f\x8d;\x06s\xb6\x9e\xfe=\xdb\xc9-N\x97\xd0\xf9\x8b\xc6\x93\xc0[K\xd6U\xed<xp\xea\xd1r\xcd\xb3\x03\'))\xbd\xf6\xde_jQ\n=\xc3\xc9}\x18!\x9b"\x1d\xc5\xf9\xeb\xb0\r\xa7\xc7\xf1(\x0b\xect\xd6\x7f\xc9#\xce~^C\xe5\xfa\x96\xd3v\xc2/\xb66\x8f\xdf`\x944I\x0e\x14\xf0\x10_\xdf\x1erp\x86p\x88S\xa7\xb9\xc5C\xa6\xe9Ag\xb2\x1d\x9d~\xc3\xa0\xa7\x03\xd2\xd2\t\xf0\x15"t0\x9a\x99\xdc\x81\x106\x8f\x1f^\x85\xc6cd\xc9t\x14\xfc\x17\xcaP\x83\xe1P\xd9\xa6\x13\x1c\xad\xf69M:~\x85W\x0b\x13\x14\x95\xcd\xb3\xc7\x89\xbc\x84g\xef\xbc\xb2fXi\x1c\x01%\xb7@\xb3\xde\x9b\xd8\x98\x15\'?\x02a\xcb\xb0\xbd\xe2\xe6I\x01]\x83\xfb\x04\x9eQ\x89\xc0\x1e\xedh>\xe8Q(\xe6}\xda\x00\x0f\xfe\xf2\r3\xd0\xb4\xa9\xac\xad \xd5H_C2\xb16Q~\xf3\xedh\xee\xaa\x9e\xd0N\x1a\xef3!v\xb8\xa7l\x90\x17\xc1\xab\x1e\xc8\xfc\xad\xb8\x9b\xcaLQ\xc3\xb4\xbb\x83<(\xa4\xb4rN\x80j,\xfd\xbd[\xcee\xf6G\x9bo\xb1(\x8c\xb9\x98\xb8\x1aB^\x08\xc0\xf4\xc4\xfe\xc1%L\xfd\x85\x0e\x80\xcc\'Q!\xfa\xabe\xed\x85\xcbIUcp\x03\xd1B\x1b\xc9\xe8\xc0\xaa)\xc3y\x80\xbd\\\xc6\xd31\xc4\xe4\xd0\xe2\x81c\x87\x1e\x17\xb9\x15=\xe5\x90\xa8\xc5\x9a\x05\xa57Y\xd8\x99\xdf\x88+CD\xc7\x8b4\x13\x88ys\xcf\x9fG\x9c\x8dL\xee\xfe\x89-m\x8d\xbfj]1\xf4\x08\x13\xb64\x1d~zqz\x96\xbf\xc0\x08GBL\x01\x1f\x94\x02O\xd64e\xf9\xa9][\xa4\x08\xa4\xf5\xd3L\xf9\xa3O\x84$\x89\xe3f\xbdx9\xcd\x1c\x17\xe2c\xa5\xa7\xa5\x84<1\xe2~\xfd\xbf\xab<\x92\x91N=W`\rp\xd3:\xe2\xa1p\xce\xb9\xb8\x0clc\x93+\xab\xe8>s?D\xb6\xd5 \xbc4\xe7\x1f\xd3\x08\xf9%\x07\xf2R\xf4~\x0e\x9c#N\x9eF]GN\x0e\xef\xf7"\x0b.\xd3\x92aO\x7fq\x9f\xdc\x1f\xec>\xc2\x1evf\xa8\x0ci\xff+\x8b\x02^\x93\xefE\x089\xab7\x05\xd5\xf6O\xa2C\ri\xecd\x8c\x1e\\Bn\xea\xdc\x84\x9c\x85\xc6\x1d\xf7W\x12\x1eV\xcd\x91\x17=1/\xa2\xe5^\x13\xcd#D\xcd\x16\x01\xf4\x08\x9c,#h\x19\xbb\xd7pA\x8b\x0b\xdb\x94\x8d\x80\xcb\xc0_\x8f\xc6\x16\xc2\x88\xa1\x17\xad)j\xa7X^\x9d{\x07V\xe5\xad\x1f\x18\x11\x0f\xac9\x02\xe0&\xa3\x98^\xee%7b\xf1m\xfb\xbe@h\x9fga\xd27-o\x0b6 \x9c\xcd\x8cF\x83Bh\xdaF`^\xef6GM\x14\x15vf0\x15&K\x80\x07*\x14\xf7\x97J\x18;>\xad\xf3\xf0\xc2\xb7mzS\x96;\x1c|;\xd0\x86\x85\xf4\x01\xf2\x81(g~=J\x9cM\x0e\xa5"\x1fN\x80\x9b\x97k\xbd\xcf-aK8\xc4\xe5\xfd\xb2jH\xc1\xcb\xd4D\xc0\x9a\x96/\x12\x00\xf4\xac\x07N\xed\x02tQ4\xff\t\xfc\xeeva=\xc8\x0f\xaa\xab\x8fb\xe1c\x850\x0b\x86]2#\x96\'\x9f\x00X+u\x84\xc9~\xbb \x1e\xe3!\xd3\x12\x9b\x9e\xf8\x87\x07\x1e\xf3b\xa9\x88\xed\xae\x8a\xec\x8e\xc8\xc6\x0e\x82\xdaM\xe0\xca\x96\xfe#\x90.}\xd0\xb7Y\x12\xbaT\xa5\x1b\x1eF\x94\x0b\x048\x93I\x114>.\xb8+\xf3\xb2\xea\x17\xdeE4-=F)<\x03\x86\xa8?\xfd9:\xfa\xa8\xd3 \x87\xaa-\xa1D\xe5\x93-\x08\'\x1e\xca\xa2C2\x04\x120\xee\xc3\xba\x05\xc0qSD\xb0>\xf7\xe5\xe8\xc6Ay\x07\x7f\xa0\xab\x94\xe1\x85Y\xe8\xae\x08\x0f\xf9H\xab\x93\x82\x14W\xba\xcb\xfa\xf0h\x82\xa7R{:u\x04\xc4\x8b\xf9hY\xaa_\x14\x93\x8b\xe9\xe5\x08S\x951\xfcq\xe6\x7f\xc2\x06\x91|s,\x18\xec\x9c\xe8\x1d\x16\x18\xdc&\xe5\xca\'A\xd4(\x13vT\xa8I\xe2\x19\xa2\xd6\xb7VI\x83r\x1eh\xe3\x13\x16\x80\x90\x95\xb7t\xe2\xc5M\xa5>+\xe5\xa7\x98\x1e\xef\xd5\xa3[\xe24\xed\xe2\x97\xe7\xe7S*Vs\x8eo\x95\x96\xc9\xfa\xfb\x04.\xc2MHjz\xed\x8bozp8M\x98\x03\xb9j\x16\x12X\x84\\\x06\x9d\xb6\x0e\x86Q\xda*\xe4\x97%\xcc\x7f^\xc4g\x82\xf8L\xb06V\xfea\t\x8e\x88$\xb8\x80)X\x86\xe6\x94]\x80\x04\x9dH\r@\xd8F\xca\xcb\x89\xd0\xa3\xf1\xc7;U\xdd\xce\xf6\xf0&\xa1f\x06\xdb\xd9\x0e\xf1\xb7\xca7\x9dV\xd5E(\xb1\x1b\x8fU\x1e\x86"\xcd\x1c\x0e\x03\x90\xa5\xb8\xcc\xbe\xa8\x08\x880\x830\x8b\xa5L$\xcc\x00\x0e*z\xcc\xab\xd4\xd0U\xcbc\x94\xb5\xe1%\xd9}\x8d\xd2<b\x1b\xa8b jH\x97\x83&`\x991y,ha\xa0\xdb\xd8uE-\xd6\xc9?x7\xd0\xcf%P\x843\xc7w\\\x96\xfcWX\xff\xfd:\xe3\x0e\xfc\x9baW\xael\x9dF\xae"\xed/!k\x80\x06\xbc\x97\x02\x99\'I\x10\x01\x00D\xeb*g\x0b\xf1\xa9\x94$\x8b\xa3\xf2\xe3\x15\xc9T\x03\xc2\xd9E\x86\xc6?\xea%IN{\x89r\xc2.U\xb6p\x12Z\xaf\x81\xd6\x18jr\x8c\x0c\xa3\x9cU\xc2\xb0\xc5fk\xdc\xbb\xe7I\xda\x0f\xe4:\x8c\x08\x15mT7\xd7LE\xe7\xad\x99\x10N\x1a\x98O\x1da\x00\xb1F\x0c\x92\x8b[\x80\xad\x9d\x87\xf9!\x00\x88\xa9s\xc5?:\xf6#\xf8\xee\xc6G0\xfd\xadS\xeb\xe6\xc6\xb6_\x146\xaf\x93\xd0\xe2\xf1=\x0f\x8e\x95-\xe7\x99\x0b\x81\rM$"\xcek\x163\xca\xdc\xf9b\x1d\xcf\x9c\x8e\x15{h\x9f\xee)\xe1\xbe\x99$\tkh~\xb5\x99@\x00\xe6\xadO\x18\x13\xffq\x17\xb20\xd7\xab\x9e\xc5D\xb2\x03\xc8\x19\xb0\xed\xcf \xddmP\xc8uJ\xd7\xe8\x068\xa9U7E\x87\xe5*\xee\xe4O\xe8g\x95:\xb7\x9c\xc1\xc3\x98\x17(!y\xc8n\xb6\x9c\x9fl\xc1\x15\xeb\xb7\x07\x96\x8c\x86\xd5\xdb\xba\x19T\x01)?\x89\x9ef\x996\x81{\xd1J\x98\x14\xcd`~\xbc\x07ih\xcduo#\xb7k\x8f\xa7\\\x17y8\xe6S\xad+lX\x9a\x7f\xdb\x1f\xd4\rv\x8dIB\x03\xda\xf7\r\xc3S\xbaf\x0f\xe1\x1c\xd3G\xc2\xd7\xe9\xf5\xf1@\x07zH\x95\x03"*0\xe9\xc0Q\xfb,\xda\xc5f\xd9'
|
|
|
|
|
|
2024-12-14 17:54:48.494704 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:61224 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7869
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 61224
|
|
len = 1258
|
|
chksum = 0x6ae2
|
|
###[ Raw ]###
|
|
load = b'\xcd\x00\x00\x00\x01\x00\x08\xea\xcc~X\x91`\xedq\x00@vN\x8bqzfy\xce\xe5\xccB5\xf0\xed\xbe\xad\xccat\x98W\xe7T+\x15^\'T\xc7\x1a\xdd\xbbX\xbd\xb8\xf7\xdb\xab\xc2E\x8e\xe36i\xb2\xa3\x9b\x0eD\xf3[x\xc9\xd6\xd5\x9c\x99n`\x11\xfd.\xcf\xd9\x06[\xed\xe4\x19\x7f\xf1\xe90\xbd{\xc1p\xe5Ub2[4!\n\xb32\r@d\x06\xdf\xf9\x18`\x1e\x02&)\xaej\xd3qn\xdajIM\xca\xe8y\xdd2\xb0T\x88\x9e\x02F\xe6\x00\x00\x00\x01\x00\x08\xea\xcc~X\x91`\xedqDI|\xd1\xa25\x068\x93\x04\x97\xdd\xe2\xfat\xfe\xf2r\xa7i\x0c\xf2\x9e,.\x08\xe1L\x85\x80\xf4\xf6\xd63\xcd\xb0\xd7\xbd\xd2\x9d\x83F,!\x16K\xf3r\xd0\xe79\xd0^ER1<\xa4\x07{\xb5~\xf4n6\xde\xb9\xf7\xca\xb0W\xe3\x94\xa9\xe5\x8b\x1bl\x8c\xac\x0c\xed\xb2\xec\xd2\xdc\x7f\xa1\xc9\xa5k\x00\x15:uV|#\x89!\xaf2:\x86|X#8\xc1\x11\xa8B\x07\xcez<\x8dP\x97Q=\x1cq\xea\x19\xb6{\x9d\x8bQwt\x07}\x14\x18\x0cBOTfv\x11I\x06dR)\xc9k\x1d\xabYZ\x17k\x96CP&C\xd8\xbb\x97\x0ef\x92\x8a\xfb\xe4"\x9992A\x8d\x8cl\xc86\x7fE\x1ft\xe6_/\x81\xe62X\xdf\x98}\x14\xa6aX\x89\xda$\xf0\xb4\xf7\xecf\x1b0\xe3\x07\x93\xefL\x99\xf4o\xc2\xb2o\x9a\xa0\x86\xca\xb7\xa0\x02s\x04\x9c)o\x02~y<Uvdb\xe0\xff.9\x83\xdb\xec\x86\xb7\x99\x8b"\xc4\xb77`\xe8\x11\xd8\xffi\x901\x9e\x14Q\x7fg\xfa\x83\xdb\x15\x0b\x0b\xb6\xbd^+\xb7\xb71M\x1c\x06\x95\xf1\xee\x99\xf1\x9fm\xe2\xfae\x7fNZ\x1au\xf0\xe4\xd7\xf7\xbf\x0e\xfb\xec\x18a\xf8s%6\x80\xbd\x8a<\xf8\x95\xe4\r\xf3\xd6_;\x88{\x95~\xce\x8cB\xdb\x1aY\x8a\x98\x12\xec\xda\xfa\xcc\x08\x0c\xbf]\xee\xdb\xc3X\xbd\xe7\xa9\'cL*\x937\xc1\xf6a\x1b\xae\xb4\xc0]\x9f\xe8\x99:\x00\x01\x88\x99\xbdb\xf6\x8a\x80\xd4C\xeac\xd2\xca>&e\xe8\x96\xb5C\xd9R\xbc}A\x9c\x98%\xf3.\xc6\x17\xaf\x85b-\tf%\x0f\xcdc:q\xa7\x9a\x0eo\x1e\xcc\xd7\x19T>\xf4\xad|\x84\xc0\xa8\xff\xac0\xe1\xe6\xf7\xdeKQe\xa2\xd2s\x8a\x93\xa4#\xbe\x9b>\xf0\xf2\rzs\xe2E\xb0/\xe9+W\x05\x95\xe6\x8f\x07P\xef~H7\xf4\xbb\xf0\xaf<\xfd\xce\xc6=4\xf8\xfbN\xec\x1ao\xd2iu\xd9\x03\xbb\xb5w\xe5\xb9I\x99\xce\x89r\xb5\xd4%\x18\x8d\x10\xb6D"wR\r(z\xfe$Z\x9a\xf5\xb9\xfc\x8f\x02u+A\xa0\x8f7\x16\xe89\x7f\xedR\x9b\xc1\r\xeb\xe1\xbdSGf\xa4\xbf3VUY3\xe0\x9eb\xef\xef\xb3hE\x0b2\x92b\xadg\x91y\xfb\xa8\xf3\xb9@\xed8!\xda\x0bG\\#\xc0\xa5\xb6\xb0\xb8i\xb5\xa6\x8bX\xcd<\xca\x87z\x81\xfa\xc5\xe0$h\xeet\xb3\x80\xe4\xef\xda\xf9\xfes\xed\xf0\'\x930\x04V\xa1\xbf\xf5\x8eY\x87\x977\x15I\xa8\xe0i\xfa(\x13a\xf2xU\xcd\xe9S\x99\xe7\n\xd2\xd6 \x14\xdczF\ryvo2\xec\x13Kl\x92uz\xac\xca\xf5\x0c&\x82\x93\x92ZE2\xe4R)\xdb\x94<O\r\xcb\'8\xd6\x90k(\xc7\xa5\x1d5{\x90m\x15@7\xbe\x16\'\n\x89\xc5Q\x01\x08;?\xa4{1\t~b\xfbo!\xfcS\x94\x1d\x82M\xca\x86\x92\xb8\x89\xbb\xfe(u9\xfcT\xbd#7\x17\x89w\x11\x9c\x11\xaf\xf2\x89\xa9\x9c>\xf6\xb9y\x97;\xea\x8dm5v\xfb\x0e\xa8-3\xa8\xafW|\xb0~\xb2\rX\xdcP\rv\xfc\x194\xe2\x7f3a\xdf`+\x92\x95\xb1\xab>\xa2!k,\xbb\xb9Np\xe2\xe8\xc4\xb1\r\xbd\xef1\x9c\x9f\xdb\r\x8c\xb8o\xc1.\xcbK\xadd\xf7\x01E\xab[\xfc\xfb\xbct\x80\xc7\x83\x14\x1eh\x95o\x1f\x12\x07\x03\x03\x988\xe0\x0c\xd6\xdc3g\x988Q\xbd_8,C;}\x11=.7\xa0k\xbe\x8e7\xf3\x0b\xe4\xa5M6\xb2\xe0\x14\xd1\x06\xe8\x19\xba\x99\x98\x08\xee\xcb\x92\xa6b\x05G\xd2%\x19=q\t\xbd_S]\xf6\x85\xee\xe7\xe91v\x8a\xaa\xa7\xec1\xbe\x89\x90\xfc\xb3\xac\xdd\xa8z\xdd0\x1c\x8bP=\x1cl\xbd\x1c\x18\x11[6\xb6\xcf\xad\xe2m\x80\x1a\xab\rgK@\x0f\x12\xb2=\xeerIq\x8a\x9c\xec\x04#4\x1b\xe9\xbf\xe4\xe3\x97\x02\x15\xb6\xdf\xaa3w\xf6Z\xc3}\xa4\x9eI?\x9d\x9a\x14\xaa\x80\xe0LG\x0f\xba\xdcgN$\xfc\xda\x12|b\xd3D\xd9\x99\xd5\xb4\xee\xe3\xf5\x0c\x85\xd8\xea\xea\x93\xe5)\xbeC2z\xaf\xa4r\x8a\xc9\xf8\r_\x8br\x87\x1e\x8d\xbb?\xcbU\x19_E\xe7\xcdG\xd7\xa7\x02`^S\xf0V\x8ao\x16\xf6\nn\\\x93%\xd5\xcc\x0eN\xc0@\xec7\x8d\xd3l\x0co)\x13\xbf\xb9\xb3\xb1vw!=g\xc9'
|
|
|
|
|
|
2024-12-14 17:54:48.499805 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 751
|
|
id = 15341
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x88c4
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505862721
|
|
ack = 2364269062
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xd567
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xbc\x13J\x067\x9f\xcd\x96]\xf7\n\x98|\xa0Djaw\xf2\x1d\x08\xb3\xbe\x91\xa4\xb1A\x9ex\x86\x02\xa8J\xd7+\x07\x15\xbe/b=\x96Q#-\x86F#\x11\x91\xae\xd3\x14\xe8\xfcj\xc0\xf9ys\x1c\x010^\xb9FWF}\xff\xad(\n\x15\xa5\xa69y\xbe\x1c\xac\xbe\xdad\xf6\x82|\x82Yi\xbd?w\xcb\xd2DT\xcf\x1b\xc1\x0e\xc1\x12\xa8\xb6\x97\x16\xe4;)\xff=\x9c\xd6\xa3\x8e\xe4\xf0O$\xc4\xb2\x0e\x88\xb5j\x00&-\x95\xc3\x17\xb7\x9b\xea\x8fIR\x03\xf2\x90\x8c\xfa.{\xc1\xaa\xfbry;\x99N\x1d\xba\x06z\x19\x08\x0c1\xfd]I\xeb\xef\x02\x8cPA\xca\xd9\xd2\xaf73|\xe0\x1f\xd3\x01\xe3\x06\xd9\x89R\xd7S,Lh~/\xffa;5\xb0xY\x0b\x80\xb4/hE/\x93\x89\xe8\x84\xbe\xc9U\xb0|*s\xf0\xfd\xdfDc:p;\x07`\xc1\x86\x1b\xb371\xceS.\xac\xc8\x94\x84\x8eti\x97*\x91l\xce\xac\xe4\x81\x03\xfc\xf0Y\x06nFf6\xbb[\xc8,\xe0\xadx\xf0Y)m\x9a\xdbKC\xde^&\xb7.\xd5\x1e\x96e\xb9\t\xe1`*\xd1w\xde"\xde\xcd}\xb6\xf7\x9fQW\x92/\x1c\xe9]`\x04\x1f\xa9\xfa\xe2.F\x8d\xf0+a\x8d\xa1 Z\xf5r\xd9\xe3\xdd^\xbe#\xe5$\xbaMx\x89a=\xb9\x9fmed\xd3\xbfC\xb7|O\xb3\xbf\xe5\xc3\x80\xdc\x1em13\xdf\x86CN-\x112\xddU5\xc8!Z\x97\xa5\x92j\x96[X\xdd)\x11\x9c\x07V\x9c\xf5\x95\x07\x98\xd8\x08\xb5Y\xf8\xf3_\x1dg\xe1\xf8\x0e\xa2|\x93\x18\x97}\x8f\x97]\xa1\xca\xd4\xf05&OR\x1d\xe9\xdd\xcf\rycO?\xe5\xef(\x01\x96\xcd,F\xfd\x17\xc89\xc0\xb2\x7fcDs\xeb\xbf\xbe\x05\x05K\x9b\xd9x8\xfb\xb9\x7f\x80\x83Ax\x8f\xfc\xbeJd\x9c&f\xcb}\x14\xcc\xb7\xc3\xdc\xe2f\x0e\x81\r7U\xd7h\x93\xad\xe3\xad\x80\xf2\x0e\xfe\xad\xaa|h\x9b\x91\x08Q\x11\x7f\xce\xf0\xbd\xaf\xdd\x18\xe7y\xfd\xc7:z\xff*.\xdf\x1e?\x03k\xb5\t\xb8hSK8Z\xfbY\x17\x03\x03\x00`\xd40\x0b\x91\x81\x15\xdaac\x84f\xfb\x10\x0f)I\t\xca,\xf3\xe4\xc6\xbe\xd2k\xeb\xcb\xd9sz\xb4u\xdf"\xc6I\x9b:\x08R\x9ev\xb9\xf7\xf5\xf4T\x16\xe94uv\xc7n\xfc\xb1\xbc\'\x13\x8d\x1c\xe2\x9bs7\xef\xfa\x0er\tA\x08&\xdf\x80\x8fLN]\xcd\x08@\xae"#\xa6K\x83V\x91\xb5&\x0e\xaa\x87\x12\x17\x03\x03\x00E\xbb)G\x9cTv\x8b\nz\xf8\xf6o\x99\x02v\xac\x9d\xb8\x98\x1f$\xf3+\xac\xc2+\xe8\n\x9a\xc1~\xd5Q.\xc1b\x94\xd7\xef\x97\xe09\xcf\xc3\xd0p\xfe\x98P\x9f\xde\x95\'\xadE\x86\xbe\x80\xe1\xe0p\xbf\x1b\xf8p\xab\xc3\xca\xf4'
|
|
|
|
|
|
2024-12-14 17:54:48.502535 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 56
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d2f
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 36
|
|
chksum = 0xb917
|
|
###[ Raw ]###
|
|
load = b'B\x93\xd9\xa6\x08\x14\xf3\xf7\x0b\xc4\x89\xe2}\x08\xfc\x90\xd3\xff\xb6R?\xd3\xdd\xc2d\xc9X\r'
|
|
|
|
|
|
2024-12-14 17:54:48.504971 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 45331
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269062
|
|
ack = 3505862721
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8072
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.508924 - Ether / IP / UDP 192.168.1.11:52783 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 63
|
|
id = 1587
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52783
|
|
dport = https
|
|
len = 43
|
|
chksum = 0xc5c4
|
|
###[ Raw ]###
|
|
load = b'U\xf4k\x98\x9b%:\xa7\xd9\xbf<a\xc6\x8d(\x041\xcfs\x86\xf6\x98\x85\x040\x8f\xdb\xf2\x9cs?#\x12\xf3\xbd'
|
|
|
|
|
|
2024-12-14 17:54:48.513208 - Ether / IP / UDP 192.168.1.11:61224 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 186
|
|
id = 30925
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 61224
|
|
dport = https
|
|
len = 166
|
|
chksum = 0xc63d
|
|
###[ Raw ]###
|
|
load = b'\xee\x00\x00\x00\x01\x08\xea\xcc~X\x91`\xedq\x00@I\xfbK\xc8S\xa9[\xeb\nd\xab\x92=Zoo\x05\xc7\xa4\x8b\xc0.>\xb9j\x1a}\xda\x02{\x92i0\x19\xc0\xa5#l\x08\x81q\x93\xf1\x1d/\xc0\xa9q\xf7\x8c\x135\xf4\xfe\xa9\x00j\xba\x87\x03\x0b,\x89\xb0b\x14h\x9d\xeb2\x96\xff\x80\xebD\xea\xcc~X\x91`\xedq\x8e\x99\x185I\xf8\x12\x96l\x9d\xf0\xe7\x01\xa4\xa6\x86\xf3\xfa\x89\x82\x9d\xfe\xf89\xc2W%/\xff\xb8\xa4"J\x02\xd7\xc0\xf9\\Cc|\x9ex0\x99\xb2\xf1\x0c\xca\xdd\x81\xa7\xac\x9d\x0c\xacW\xa9"'
|
|
|
|
|
|
2024-12-14 17:54:48.517183 - Ether / IP / TCP 192.168.1.11:40846 > 35.186.224.24:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 30926
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40846
|
|
dport = https
|
|
seq = 3398707234
|
|
ack = 4001698297
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xc5a0
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.521239 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 120
|
|
id = 45332
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269062
|
|
ack = 3505863432
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0x80c2
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x14\x03\x03\x00\x01\x01\x17\x03\x03\x00E\xff\x91\xd2\xe3\x80\xce`\x94*\x99\xf4\x08\xc9\x89I\x03\x91\xfe\x99fW\x8a\x12(\x07Y\xea\xcb\xdf\xc2v\x1a\xe9\xedP\xeb\x81\xf5\x01\xeeK#\x8ch\xd6\x94\x18M?\xc7\x08.\xcb\x15\x15\x86\xa1p(T\x96\x1a\xdf\x89\xd0\xdb\x9d{\x97'
|
|
|
|
|
|
2024-12-14 17:54:48.524574 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 132
|
|
id = 45333
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269142
|
|
ack = 3505863432
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0x80ce
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00W\x1d\x81<\xb8\xf5\xdc\x9c\xc2\x7f/\xc9l\xc0G`\xdcek\xc4\x1e\x02\xeaP]]5\x87\xbf4\xe5\x1dF2\xc4\x13P\xafd\x11\xb9\x0c\xa2\xf8\xf5}\xe2\xbc\x14\xb2Y.\xcb?\x1a[+\xdd;Z\x96\x13hI\x9cA\xd7\xd0\x1a\xd1\xbf\x87\x91\xce\xf4\xe0\x86\x19\xcaf8\xeep\xc1\x91i\x0c\xd7'
|
|
|
|
|
|
2024-12-14 17:54:48.528734 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 303
|
|
id = 45334
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269234
|
|
ack = 3505863432
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0x8179
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\x02X\xa3P<\xe0\xf9H\xa0\xe2D\r\x90\x99jb\x07*q\xf5\xc5\xb04bq/}\xec<L8\xab\xf7\x90\x97\x13\x82D\xab\x9a\xb1\xc9N\xa8\x12\xf8\x84\x8c\xc9C\x08\xe9G0\x18\xbf\xae\tr\xc9\xdc"\xae\x81\xe9du\r\xa5\xf1\'\xae\xa3\x92g&\x03_\xcaG3\xfa?\xc8\xb6\xaf\xa1\xae\x05s\x93|\xffJ\\\x0f\xe2\xe3Q~\xf3\x1d~\xa4*\x8a\x8f\x0cRGL\x8fH\x8b\x18\xebw\x1ff%\xdeM\x0e\x14U\x10\xae\xd3\x15a\t\xc1K;x\x8f\xb8\xdd\xbb\x84\xb3\xaa^v\xc8\xf7"\xe0\x8bg\x1f\x04\x86\xc7\xe6X\xf7\xe6\xbfp+_\xd4\xc7\xc1\x0b\xf1\x11\x06\xcaij\xec\xa4\n\xc2\xc0\x06%\xd9\x02@\xfeXI\x12P\'\xc4\x12\x15R\xc7@\xd4-\x88\x9d\x87v\xd3\xb7\xac\xc1\xe0t\xad\x95\xb8\x9cm\xe9\xe4|IW:\xb2F\xe3\x82\xd9R\x8f\xf8\xe4\x8e\xc7G/%qO\xeaUR\x1fv,\xc2`1\xf7=\xfe*5t\xe3\xcc\xd8\xb1\x9cJL_\x8d\xa1\xda'
|
|
|
|
|
|
2024-12-14 17:54:48.532715 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:61224 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 612
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7b03
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 61224
|
|
len = 592
|
|
chksum = 0xa79c
|
|
###[ Raw ]###
|
|
load = b'Z\xa5\x89\xa6\x9dx|\xaf\x9a\xee\x9d\x9a/\xa4\x81D\xa6\xc5\xb2\xf0\x8a86\xa6Di\xaf\xbcP\x927\xab\x08\xb8Z\x8di\x95>\xe7\'\xb7q]\x94M\x1bv\xf8\xa1Qw$9$\xc8\xe2L7\xb2g\x9fMgZ\xd2,\xdc=x\xe9\xaf\xdb\x1e\x00\x9a\xa5\x9dpm\xc9\xdc5Q\xc2t\x17)_\xbeB\xfc\xe7\xf1\n\x05\x86\x8a\xb6o7\xe0h\xa7\x12\x18\xd9K\x00\xff!\x19Mt\x05\x83U\xadm\xcb\xdaL\tK\xb35\x16<\x0c\xe4\x1d+\x8bYcC\x91\x8d\xf1~\xd9_w\x85\xa9\x91\x00\x12"\x87\xb1\xe9B+\xed\xb7K5\x85\x96\xa5e\xea\xf0\x059\x0b\xbb\x84\xd8\xea\x92\xd4\xde\xd1-\xad\x81q\xe4\xca\x03\\\xc0\x93z?\xc6\xb1\xf9G~\xa4,\xc8\xe6`\xab}\xeaP\x7f\xa6h\x8d\x11\xd8\xc0\x1a\xdc\xb2`\x8b\xad6\x9d\xbd\xd2\x16\x87\x19n\x801\x15\xf6\xd2\x82\xfdh\xbb:\xcf\x83\xd5\xfa\xd8\x0bIq\x01\xe5E\xf0\xa2\xfc\x9c\xe7V\xc2[\xcd\xf4F\xf4\x05\x98\xffn\x89\x1b\xbd\xef\x1b\xdb\xc4tO\x1c\xa2\xac\x80\x88\x80\xda\xf9y!/\xfc\x97| #\xb6Y\xd2\x04\xd8\xca/\xfb\xac\x99\x85\x18Og\x00w\xcb\xe3\x80|\xa6y\x10\x9e\xfa>\xa2s\xc9\'\xbd\x9cz\xa54+a\xce{?$\xe2n\x86\x11U\xcb\x8d\xf1\xac\x11\xfdR\x01\xa5\xf0\xee\xbdT&\xb1nP\n\xac>\x83\xc1\xba\xc0:\xde\x90 \x11\xf9\x92\xdeN\xbf^\xbdzC\xcf>\x1el\x07#[\xe5F\x8b\xc0/\xcc\xac\xbd\x7fsE\xc7\x88\xd9\xaf\xb8\x85\xc9\x95\x8bh7\xc0\x91\xfd\xa0\xf7v\x9a\xc2\xa6D\x90 lz\x96\x08\xb5I\x89\x16\t\xf2Y:h\xf2\x970\x15!\x9c\xc3T#]\x0f\xd7x\x01\x16\xee\xed\xa6B\xfd\xe4\x86x\x82\x8f\x84v\x00\xfa4+I\xe2\xd8\xe1\xc5J\x07\x87;P\'J\xb0\xf2\xcad\xf2\xa0\xe0\r\xa5\xc9\xcf\x01\t\x9f\xd4[\xed\xd2"\x9b\x17\xa1\x11m~\xfd\x80\x1f\xf0\\\x11\xff\xd5\xe3#0\xa1\xcdI\xd9U>\x12=\xd3\xfbU)r\x08Y\x9be96#\xed\x9e\xed\xe3\x94\xfb\x02\xd8\x8eZ\xc2\xa0N\x04Y\xa2\xca~\xe9\xfe\xf9\x00 \x0f\x14\x9cH\x94\x91G<\xb4\xb5\x05\xa13\xb0\xcb\x80<\xe2\x96\xeb_\xf1\x00\x97\xc1\x8d\xd8R\xf3\xc6\xcc\x85\xa4\x9d\x99\rN<\x9e\xd9'
|
|
|
|
|
|
2024-12-14 17:54:48.536002 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:61224 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 149
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7cd2
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 61224
|
|
len = 129
|
|
chksum = 0x6328
|
|
###[ Raw ]###
|
|
load = b'K\xb8cJ\xbf\x96\x9a\xbf\xb8}\x9e\x84\xb0\xdcp\xec0\xb9\xe9\r\xd4\xc0\x87>\xdc\xd9j\x0fC~\x9c\xben\xc9\xc2\x94\xd2\xbf\xb5j!zf\xa1*\xf0V\t\xc9\xa2\xf6\xcf\xb7\x1clP\x10D\xc9&\xb3|\xd2\xf7\xf5K\xf3\x87l\xd7\x1a\x91\xba\xe0\xa0\xdaG\x93\xf0\x93\xa7\xfdQ\xeaeP>\x8d\xea\xa9%28D\x7fo\x7fm,s\xeb\x17\xb1\x8a(\xac\x7f`\x977\x98\x07\x84\xc0N\xd1\xc6\xd5\x84@\x18'
|
|
|
|
|
|
2024-12-14 17:54:48.539525 - Ether / IP / UDP 192.168.1.11:61224 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 61
|
|
id = 30927
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 61224
|
|
dport = https
|
|
len = 41
|
|
chksum = 0xc5c0
|
|
###[ Raw ]###
|
|
load = b'^\xea\xcc~X\x91`\xedqC\x02v&\xc09\xd8^\xc4N\x04L\x97\xaf\xe8\xef\x99\rl\xf5\xec\x02\x8a\r'
|
|
|
|
|
|
2024-12-14 17:54:48.543167 - Ether / IP / UDP 192.168.1.11:61224 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 61
|
|
id = 30928
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 61224
|
|
dport = https
|
|
len = 41
|
|
chksum = 0xc5c0
|
|
###[ Raw ]###
|
|
load = b'F\xea\xcc~X\x91`\xedq\x12I\xbfM\xbe\xb3B\xcaR\xbcF\xaf[\x82\xed\xbb<r\xa5)MD`a'
|
|
|
|
|
|
2024-12-14 17:54:48.546133 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:61224 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d32
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 61224
|
|
len = 33
|
|
chksum = 0x40bc
|
|
###[ Raw ]###
|
|
load = b"Xrvv'\x88L\xb7\x8a\x16\xad\x02FG0a(\x0f\x13\xfa\x98\x13\x0c\x7f7"
|
|
|
|
|
|
2024-12-14 17:54:48.548370 - Ether / IP / TCP 192.168.1.11:40821 > 35.186.224.24:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 30929
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40821
|
|
dport = https
|
|
seq = 373750560
|
|
ack = 2746219178
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xc5a0
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.550534 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 15342
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8b8a
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505863432
|
|
ack = 2364269142
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0x10fb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:48.553121 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 15343
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8b89
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505863432
|
|
ack = 2364269234
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0x109f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:48.556286 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 582
|
|
id = 15344
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x896a
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505863432
|
|
ack = 2364269234
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x01\n\xa1\x07Ew?\x93\x96\x7f\xd0tMOo\xbc\xa7i\x13\x87\x19dO\x02\x19\xf3\xc1\xd0p\xb9\xc2\xaa\xefT\x1dL\xaa2H\xa8\xb1\xb4\x8cb\xf5\x9d{\x15\xfb\xf9P1R\xf6\xcaz\xf8\xafx\xc3\x9dW\xc0pD\x8f\x83\xbc\xb4\xa5\xdf\x9f\x04Iv\xc3u\xa1\xdf\xca\xb9\xbdZ\x0e\x07\xdd\xb3\x07U\xed\xdf)\xcc\xbe\xdc\x7f\x92\x1fb\x18\xd5\xf9QWx\xf5\xe0\xda\xbd\xd5\xef\xbc\x1cO\xddv\xa1y\xd0\xf2\xb98UL\x7fk\x16\xd0%\x95mfbO\x0c\xe4\xb6\xe5\x06\xe3\xd7\xd8\xa7}\xd0_\xd0\x87\x84\x83\xe7\xd6%\xeb\x0c\x18gP\x1b\xc6\x8bY\xf3\xc1\x05\xa1\xca\x98v3E\xdd6%\xb2\xeb4\xaa\x1d'{\xc1\xae8\xd6\xf4\x0f\x8dY\xf0b\xc9\x99\xf5T~\x10%\xf4\x8fl\x1ai\xd9G;\xeaq`M\xbd\xb9V\xcf\x17\xa1\x14$\x93\x92a\xeau\xaf\x1b\xb9J\xd7b\xfb\xe6\x04\xd1_4\xaf?\x06%\xbff\x8f37\xbd5\xc9e\xbd=~\xf39\x8b\x0e]\x07oF\xbb\x81\x8b\xaaq\x1a\xb8\xb6\x17\x17\x03\x03\x01\n\xac\x03*\x9dk\xcdHAC\\\x83\xfe\xf9\xa1\x83\xa8\xcb\xbc\x8a\xae\x98A\x13\x08~\x1et\xfa\x00R\x1c}\x9el@`'\xebY\xbc]*Ik\xad\xe7X`\xb3>\xbd\x92\xba.\xe5H\x1d\xbe2\xdba\xa9S\x9d\x12\x9aL\xf2\x16.w\xd5\xbf*.\x94a3^\xd5uaA\xb3N\xaa\x11\xb8\x041\xa1\xd9\xe8'e\xfe@\xa5\xa7\x92\xcfr'\x8a\x9a\xe9\xe63)u6\r\x009)S\xe44&ZC~v\xb9[O\xc4\x87\xea\xec_iN\xc2\xf6\xaf\xc9.\x05!l\xed\xe71\xb2J\x136(\xf2\x02\xb1\xe3\x12x\xa8H\xca'\x0e\xdf\xdd\xd1n\xe0\xb3\x066+\\\xf9\x8c\x96\x07@\xf1]\xd2\x98\xc3xa\xa2\xa8j\r\xb8&+\x02\xda\xda%P\x00\x95\xf2\x1b\x87{\xcf\xb6\xde\xf5}.\xda\xbdY,D+\xa5\xbcB\x04\x897\x94\xf1\x05\x0f|\x02\xa5_\xd2\xfb\xe2\x96y\xda!\x11?C\x836\xa8\x10\n\xa5\xae\xd4[+~L\xd3\x18\xd0h\xff\xe5e\xc7\x06\xf7\xc1C\xb1+6\xf1\xdeI"
|
|
|
|
|
|
2024-12-14 17:54:48.559856 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 15346
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8b49
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505863974
|
|
ack = 2364269234
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x700e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x008-t8|y<8\x04\x83\x9f\xcc\xd85\x0f/Y:\xce8-\xbb\xe8:e\xe5\xd6\xec4i\xc7\x85{\xa2=\xdf\xba`yc\xc5\xb5A\xbf\xde\xb2\xa2\xff6\x1b\xc3i\x19\xa9\x90\x98\x03'
|
|
|
|
|
|
2024-12-14 17:54:48.562633 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 15347
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8b66
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505864035
|
|
ack = 2364269234
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xa267
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1a\xd9\xe47\xc8\xb7\x08\xde\xfe\xfetpM@n;\xca\xa3\xd7FS\xa4t\xebV\xa5\x91'
|
|
|
|
|
|
2024-12-14 17:54:48.565042 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 45335
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269497
|
|
ack = 3505863974
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 508
|
|
chksum = 0x8072
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.567640 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 45336
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269497
|
|
ack = 3505864066
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 508
|
|
chksum = 0x8072
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.570091 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 45337
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269497
|
|
ack = 3505864066
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 508
|
|
chksum = 0x8091
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1an\xb8K3\x99\xf0\xe7-J\x06|\xae\xcc\x1d\xa9\xa2\x0f\x92\xe4n\xd0\x9b9.\xbe\x8b'
|
|
|
|
|
|
2024-12-14 17:54:48.572890 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 664
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7acf
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 644
|
|
chksum = 0x7caf
|
|
###[ Raw ]###
|
|
load = b'Q\xeb\xd1\xe6\xb5p\xb5@\xa9\x8f\xc9\xd7\x08\x05\xb6X_o\xea\xc4T\x1aux\x86\xdaV\xa5&\x7fH5\xfb\x15\x00\xd1a\xf8\xd7}\x07\x1a\x83\xc5\x1a\xbdl\xf0\xde&\xbf\xb6\x8a\x04\xf4\xc4\xd2\xc0#F|\xa9\xfdW\xc05S\x92\xaf{\xfd\x91\x95\xff\xf3\x8b\\\xac\x12\xbeI\xe1E\xb1\xa7\xe9\xd1<\xee\x93\xfe\x12\x8a)XYR\xc0\xa6G\xea\xdf\x95\x8e\xc9\x0eb\xa7\t\xe4a\xecY\x19\x92d\xa0\xdaz=\xf6\xc0\xb90\x161R\x02\xfdy\xbe\x12\x88\xae\xbd\xac^E\x00\x93\xc18\'#\x17A\x11\xf0fRn\x97+L\x8a\x80\xcaEs%\x96A\xa4\xa2\xf2`\xc7s\xfd\xafD\x08J\xa4\xfeWOPM\xcc$!J\xc3H\xf7s\x96\x1ale\xdd\xf0\xe4\xed\x9c\xa20@\xabO\x88\xb4W\xce\x9f\xc1\x9c\xa9L4\xb5\x9e,]\xbd\x81\x9fs\xb9\xea<\x0cc\xe7\x9e\xad*]\x9d"kVh\xec\x12\xf1\x97\xd1\x0e\x03C\x97S3wb*\x14cv\xde\xac\x12\x12,\x06"\xc8\x8e\x9b\xe9,\xdc\xdd*\xa9o\x19\xc7\xcf\xc0rNQ\x13\xd0\xa7\x91dD0\xcew\xe2\xaec\x10\x86\xb3\xdd\x7f\x15y\xee\x8c(g7\xd6\xf0\xf2\x05\xda%\x1f?\x9dC\x93\x84`\'J\xae\xa9\xe3\xf2\xa4nK6\xf0^\x8e?A\x08\xf3\xb9\xdfg\xab\xce""\x176YS\x82>\xda\xe4\xb4\xc4\x9bd9\xbf\x80B\x91E\xfb\xf2\xe2\x99~\xa95]g\x1b\xec1\x14Z\xc4\xb6\xab\xe4\x07\x87E\xb2MuW#\x9c\xc2\xef=|\xe1\x0e\x93\x18\x02L\x0f\xc4\x95\xc0\xcb\x15\xda\xd3\x7fU\xbb\xe6\xaf\xf6\xf0\x05\x84\x0b\xe4\xaf\x80\x00\xa4\xe6\xfd\x01\x8f\x16\xb9\x14\xa3\xd1$\x80\x15\x97\xce%Sy\xe8D\xc0\x8f.G\xd9\xd2\xb6\xcdII\x14\xb95a\xd7\xda]\xfe\x02\xebv\xc5\x12\xeb\xda\xbdJ\x1d\xdfK\xeaP\x10\xca\xa3\xab\x1d\xae\xbf\xed--\'\xd80\x12\\\x08q\x8e\'\xb6\xb6\xa7#\xa0\x9f\xf7J\x1da\xbf\xc2\xdb\xce\xcbr\xb0\x10\x95\x870\xd5/N}\x02\xd1Zm\xf4:\'\x91\x88\x99B\xa4yg\xe6\x81\r\xeex(\xe2\xac\x07=m\xce2-k&\xa7"\xfcX\x07?\x98\xf88\xf7:L\x1e\x07{\xa5\xe9f\x9c Zs\x03\'ph\xb5\xa0\xe8H\xe4\x16\x8c\xe0\xa2^\xe7|N>\xe3\x13Y\x0c!j\xa8\xfc\xc7uVg\xc1\x82\x15W|\xbd\x1e\xf8\xb7\x81\xc2=\x816\x10Z\x84\xb2\x05\xba0o8c\x0c\xa0?\xc2\xb8:\xb0\x96^\xa5EoEAo\x8auT1\xcew'
|
|
|
|
|
|
2024-12-14 17:54:48.577089 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 63
|
|
id = 30930
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 43
|
|
chksum = 0xc5c2
|
|
###[ Raw ]###
|
|
load = b'A\xea\xa4\xfd\xe9\x04\xea\xaf`\xa8\xe7\xba@\xe1\x1b\xe3\xfd;\xdcc\xbc\x8f\xd2m\xe34o\x08\xf9\xc9\x8bVn\x87\xe6'
|
|
|
|
|
|
2024-12-14 17:54:48.579896 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 340
|
|
id = 15348
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8a58
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505864066
|
|
ack = 2364269497
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xbcb5
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\'\xc7!\x12\xfc\xf7\xe7\x02\xccL\xa5\xdb\xa2\xb3\x1f\xcf\xdd\x02\xfbA\xb3u\x06\x04\x0f\xe6\xa9\\\xb5\x9f\x8dZt\x97\xa5\xd9\xfah\x01\xa1V\x023\xd9y\x979\x82\xa7S\xde\xce\xf6T1\xfa\x83Zd\x98\xa2\xb3\x0e\x0e\xd1\xf5\x92\x10w\xb7\xc8\x04\xba\x85\'\xab2R\xcb\xc3\x0cBhNG\xd7\xfb\x9b\x14\xa5-\xb6\x0c\xfe\x18\x87U[\xcd\xecD\xa2\xfc\xb9\xed\xe2\x1e"?\x00\x9a\xf3\xdd/\x08\xc9\x18b) \x14\xadl\xf5\x90\xdf\xe3/xF\x8cY+!\xe1F\x8a\x08\xd0\x94\x0f\xcb\'j\xc7\xa8\xdb8M\x0f.\x83QB=\xd2\xc9\xdf"^t\xa9\xfe\xd7R\x18L\x84:\xa9\xa9\xbf\xc3S@\xc9\xd0o\x86:\xb9B\x90&\x81O\x10\x1f\xe9X\x1b\xca\xe6\x8d\xd9WM\x89\xfc\x98\xa1\x89\xc4.\xb6\xdc\x82k\x855\x13b\xf6\xd0\xaa\x92\x15b\xc2\xaeR\xfd\x93\t\x99\xf7\x0c\xf2p\xf7\x91\xc6@\xac\x0c\x85\xa1\xfc\xd4\x93_\xea\rQ9\x01\x18M\xf8\xdc$\x06\x1e\x11N\x83\x8b\xc6|W\xe2\xd6\x1a\xb8%\xe4\xca\x94\x8bV\xd5\xddA\xa6\xec$8#k\xd6\xb7T\xdb\xda\xc2F3C.\x97\x97\x93\xf2\x97pZ'
|
|
|
|
|
|
2024-12-14 17:54:48.583207 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1384
|
|
id = 15349
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8643
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505864366
|
|
ack = 2364269497
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x3791
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x05;\xfaU\xd12\x9b\xbape(\xcf7\x11\xc4\xcb\x1e\x189VN}\xb9U\xf1^\\\xdd\xe9\xd2\xb9J\n\x05\xe5\xde\x86Mm\xff7\xe7"\xc3\x95\xd2`\xb7\xa7\x1f^\x1b\x10[d\x806\x9f\xe8\x07\xd6\x8c\xc24\xce\xab\xc3\x0f\xe3\xbe\xfe\x86Jg\xbd\xdc\xcd\x16JqSG\xd9n\xea\xd6\n\xaa\x16*P)\xb0\x8c\xe91H\x1b\xc7\xa5\x9bVg!\t\xf3\xac_\x90\x11\xabT\xf1\xc7,\xa6"9\xbe\x01\xbf5e\xba\x9c\xb7<\x1a\xcd\xc6\n \xe1i7.3H\x86\x1fa\xd7\xce!Y7\x94\xea\xd1\xc3\xaf\xe4\x02\xd6]9\xb1\xde\xd1\xe4/\x9eD\xd33\xf7a\xd9\xdaN\x04\xa9\x19\x1e+\x010\x80\xd9h\n\x8a\x9f\xec\xdd\x7fH?\x99i?\xba\xaa\x81\xe1\xf7\x92|f\xf3\xb1T\x8acu\x01\x97\xce\xb4\xd2-\xdc\xc0\x96\xd8\xb6\x1d\xe2\\\x1a\xa8\xc9F\xf7j4\xcd5{_F\xe9F9.BW4@\xd2\xb9\xd0w\xd7F)\x83u\xdflB\xbc\x12~\x8b\xe0\xd9\x85\xa1\x9e\x05\xab\xf1\xacc1q6Y\xcc\xf8\x88\x8bo\x16\x88\xf4\xed\xbf\xf9\xb9\xb5#\n\x84>\xd8\xb8\x82i>\xe7\xbc\xd9\xda\xc6d\xd7\x98K\xd9\x14I=\xee\x04\x1a%\x98H\xb9\xdb\t\xc0\x06\x08\xb8.r\xe8\x91\x00n#\xc1l>\x10\xcf\xa6<\nI\xc6\xbd%Jw\xfb\xcaH\xcf\xbaN\x99\xc5\xa9X\x03\x99\xaa\xb9\xb9\xcb8\x83\x1d\xdc\x1eb\xd6\x9cZ\xce\x18r\xb0\xe9E=.I\xeb\xef-\x84o\xdb\xd4p\xad\xbeP\x91\x17\xdf)\xc5\x13\xc0\x99V\xe5\x92F\xe4\xa5\xab\xb9F-\xa9N\x80#Y\xc3\xea"\xb2\xba\x9a\x16\x13dI\x16\x8di\x18\xb2\xa0\xfd\xc3\x84Q\xd9\xdf*,`\x0flp\x97\x034\xdfG\x03\xbe\xe3`;\xcd3Z3BA[\xf5b\x05f\xd0_\xba\x08^9\xf6GuH\x92\xcci\xd8\x8bW;\xd4\xc7\x8e\x9ag\xd1B0\xce\x08\xb3B\xdds9\x14\xa5l>u5!\x90\xf9"\xc8C#\xe3)$\x84g\xb1wk\xa3=e\x1fL\x85\x9a\xd4I\xb8\xf8\x8e\xdd\x8d5\xfc\xa3\x94\xea\xb8c~\x19m\xc5^\xf2\xcb\xc3\'{\xac\x0f\xf2\xe7\x0f\xca\x88j\xea\xef\xe7\xcb\x86\xcdx,\xab\x8d\x82\'Ys9\xea\x9b\x04\x12\ta6\xdc\x18=\xe6-\xf5#y\x90\xabG\x1a\xb3_\xbdL_\xa03\x17\n\xe9\xe3\xfe\x0b\xa8\x93\x9a\xffEW<\x15j5\x10\x85z\x825\xe0\xe3\xe1\x7f\x99#\xad\x80\x19\xae\xcb\xf9\x7f\xf7{\xd3BF\x0b\x1aA\xa1,\x04\xfd\xd6\xf4\xe3\xe6\xd9t\xad\xc6M\xb1v\xac\x8b\xe4\x16\x8c\xcb\x0fM\xd3t\x0b\x9a\xa9\xe7+\xb9\xfbf\x0bP4\xb6\xa0H\x12\\v\xa8\x90\x93\x8a\xc67F\xeb\x1c`\x06\x06$J|\xb9e~mu8\xb6\xd5\xaf\xe5\x98\x10\x1d\xfb[\x87\xe5H1X]\xae\xd2\x99\xf7|t\xf6\xbd\x0c\x7f\xa1\xd6l\x8f\xa6pU\xb6\xd1\xdei\x15\xc7\xe9\xed\x8d\xbe\xfd\xf7\x0e\xdew\xf2Y\x97\xc0\xe4\xe6ZQ\xa8\xda9\x8b0J\xdaU\x9af\xce\xc5\'\xfa\xe882@dK\xe2!:\xc7\x8an\xd3\xae\x18p6\xe8]\xb8\xc8\xf2\xef\x1c\x8b\x1c{+\xc6\x0cv\xb0\xe9\x98Uw\x96f\x89\xe6\xe6\xa0\xea\xab\x85+\xd84|\xb1\x07\x83\xe1\t\xc2!H\x81Z\xe0hgLt\xb2\x1e\x11\xc6\xbb\xee\x96\x0f\x01U\xb1\xf5\xb1:(J<\x0b\xc4^\xaa\xfb\xaf\xb4u\x1a\x0c\x97ho\x96\xfe[\xe1\xa2H@\xaa\x92\x19\x10\xfbsv\x17^\xbf\xcf\xda\xc4\xbf\x81\x17f\xec*Q\xc7\xcc,\xcbk\x02\xb7G\x94\xd2\xe9\xc7\xe5\x0b\xdcU*\xcf\x13\xb2\xc7c\x11\xaa\xc5OL\x18\xff\xbf\xb8\xbe\x90\xc7\x0e\xf6\xc5\x0b)@\x98\x8fQ\x8eC\xe0\xdc\xdc\xd4Kc\x9d\x16\xd7D\x17\\a\x1b\xc3`\xd3-z%K\xe2\xaf\x16\xb6\xc6\xae\xfbf\x08\xd2\xf4\xbc\xef\x02\xd4\xb3\xc0\x1e_i\x14\x80\x8e!\t"\x84\x9dcL\xf2d\xf4 P\xdb>\xe4\xb4j\x1au\x13c\xea\x0f)\x08\xc3\xd7\x8dI_1\xb3\xc8N{\xa4\xe5\xa0\x84\xd8b|n\x9e}[X\xf9b\xa6\x04\x12Ev\x1d\xf9\xa3\x1e)\x11l\x1c.\x80^f\xa8F\xe0A>#\xf4\xd4s\xe2\xa5\xc3QU\xeey\xd9\xb2\xad\x9b\xd6\x1er\x9e\x94v%N\xadWr\xd1o\xb6r\xec\x8dPov\xa2\xf7Wp\x82\xf4\x8f\tj2\x8f\x86\xec\xfc\xec\xc5 \xe9\x86\xa1\xbe\xbd57!\xd86\x9f5\xbe\xdbb\x96\x93\x17/\xf3\x84\x80\xe3\x03\xe1IVt\xaf*N\xcf\xe5\x02\xd9\'}\x01\x8e\x91J\xa7t\xbap\xc8\x05M)\xea{(\x05^5HF\x9d\xd8\x95\xecpV}49\xff\x1b\xfc\x8d\'\x98\x0221\x9evL\x95o\xd2\x88\x7fM\x86\x19G\xed\xf88\xbd\xff\x87[8\xb9\x19\xfe\x1bm\xe7\x82\x04TQJ8xX\x925\xee\xda2H\x0c\xeef\xee:l\xf4+|\xa2\xb9M\xf7\xb2,\xa8\xe8\xf4\x0e\x0b\xb9\xf1\x87\xd5Pi\xcd\x11\x86\x19\xe3\xe1\x06\xc6h\xec\xb79\xef\xa2\xd0\xaeg\xc1\xfe\xb5\xb2\xb9Y|(\xb2k!\xff\xecL\xfaJ\xef\xfa\x83\xb2\x9f\x80n8eB\x02\x9b\x1eY\x1f-9Q\xf5kK\x8e7\x1d\x952\xf8\xc9D\x0fH\x9f\xbf\xc8\xc8\xe7M\xae\xb8[g4\x9f\xfe\xbd\xe5Wl\x15\t^>v\xe8 \x9a\xcd\x13\x18\xfcf\x1e\x99\xc4\x91H%3\x80@\t\xac'
|
|
|
|
|
|
2024-12-14 17:54:48.607163 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 16100
|
|
id = 15350
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x4cc6
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505865710
|
|
ack = 2364269497
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03@\x11}\x12\xd3\xfd\x046,\xda\xfbm\x8e\xdde\xd9h Po\xdc\x96\x85\x9e\xb4\xe2\xbe;\xf9\x02\x05\x99\xb4`\xf3\xfd\xa8%j\x91\x8b\x02\xf1\xe5R\xeb\x03Nc\xec5a\x86=\x8ca\x91\xb5\tP\x1bC\xed\xa0:\xee\xdb\xacR\x0c/A\xb0\xda\xe2|\xf2k\x18>w\'\x90Q\xc5f\x1a\xd7\x07\xa1M09\x0e\x91\x99H\xb4\xbe\\\xac@\xf3\x01\xd5\x06\xa4\x02\x85\x10\x90\xc4O\xba\x88`\xde\x0b\xa0\xf8\x95\xbdK\xa7{\xd4\xac\xa6zB\xcb\t\xac;(\xb6Onl\x063g\xba\xfd*\x93\x9b\xb9co\xe9q\xe9%D36\x81\n\t\xed\xe9>\xdb\x98\xe9\xeb#zs\xd1\xac2\xb2=\x17D6\xcbt\xcc;[\xae\xcc\xfc\xd5r;\xa4\x87\x9e\xf5\t\xf9Nt\x8e\xd80\xc48\xd1\xfc\x0f\x81\x13\xf8\xe4\x87\x08\xbc\xc6\xd8\xabZSl\x90o\x14\xf9!\xacT\xa7d\xbd\xac-\nd\xdf\xb2T\xa8X\x93&\xbf\x1c\xc3N\xeb\xf5\x0c\x17\xa4W\xad\xc7\x03\x1a\xd4&\xe2v\xd7\xfd\xba*+\x02_\x9a\x83\xba\xa2\xdd\xb9mZ\x83\x9b;\xc4\xa7NEl\xf6\xacH\xf4x~4|\xe0b\x0cF\x1dW\xb8\xd0\xcb\xc2=\xde!\xf1\xc9p6\x81\x10\x11\xaa\xc5KZv\xa0N\x00\x8e\xa9\xfdN6\xbd\xf4\x8c9\xde\x95\xf5\xaey);`\xacQi\x9f\xb4L\x84\x9a\xee\xb9\x90*K\xf4\xed\x9a\xf5\xd6\tF\xf8Xj\xc7\xe4s\xda&J\x90\xb6FB\x0eNU\x92\xdf5\xc0m\x95[y#\x1b\x84p\x1a\tcr!z&j\xf8\xf4\x0e\xc9P\xed\xe38E\x15>9\xef50\x8d\xaev\x1d\xf7\x03\xff\x1f3.-\x96\xd1%\x18\xa5\xde\xa7,\x0c9Z9\x85\x95\x1a\x1a\x86G\n\x1f_@U\x94[\x87\x0e\x9e\xf9\xe9@\x05>\xc1\x97\x97\xd2\xf9*\xfe}Zr\xea\xda $R\xd7\x880\xea\x04D\xa8\xe2\r\xbdW\x9fP\\0\xba\xce\x91\x95\xec>A\x08|c$(\xc6\x83\x0e?\xa8\xa9E\xcal\xeca\xcf\xa7\x9e\xd9\x88\xee\x1e\x07\xc3:\xf9e\x15up)\xe0\xc0\xfci\xf1\x85G\x0e\x99K0\xabcCS\x03\xec\x8ch\xa6\xeb\x15\x82\xd3"K;z\xe4\x11\tv\x08\x056\xa5q\xa7\xe3A\x8b\'\x96\xfe\xf42\xc5\x99_\x14\x01\x8c`\x04K\xd4 Q\xed\xffj"\x85\n\x87 \x89*Cs\xaa\x1e\x8fU\xfa\x13c\\\xee\xb8\xb5\xc7{+*\xfe\xf9\xf6\xf4\xedoj\x85c\x85\xc4\xddh5\xe2\x11^,\x086\xc4I\x93\x90\xc2V\xdf\xbc\x0b\xb2\x1aR\\\xbepv7\x9d\xde\xbb\x85\xdb\r\x07\xf0f\xde\r\xdfF\x8a\x0c\xebjVb\xe6\nq\xa6Py\xe46\x8d\t{D\x8d.\xc1\x18G\xb4\xf9\x8b3\x0f\xc2\xa36\xc0\x0b\xe9%\x1e\x113\xbb!\xa6\xd8\n\xb8\xd6\\\x9d\xe8\x19\xe1{nb8q\x17\xcd\xa5U\x94\xd0Ai\x01Jy\xdf-2\xbc\xe3?\x8b\xf6Y{\xc8/*t\xa8m\x07\x8bV#BU\x08w\xeei\xbb\xc8\x94%E\x95K5v\x08h\xd6\x85^j\x98\x8f\x83\x1c\xb1\xf1\x19Tf\xc1\r\x85B\xf0tu\rv\x86\xdd\x05\xf5\xdf#\xd0%\x9f\x83\x8a\x88\xc8\x8c&\xb5\xd8\x1f4\x93W%\xe4\x8d\x00\xf9\xf9>=Fw\xb3\x1a),\x89\xfaA\xf1\xe8j\xbbA\xac\xf2\x15\xbb\xba\xe2\x8d\xe3<j\xb4\xb5\xe8\x14\x1b)\xe1\x94\x91j\xe6\xe6f\x03T\x0f\xc5%\x05\xd9\xd4\x87v\x9fdB\x03,\x11\xfc{\xe2\xba\xdd`\xa8\xcf\x86\x8d\x84\xd7 \x13\xc9{\x91E\xd5\xef*\x90X9\xd7\'Q.\xbe\x97\xba\x9b{\x14\x96f\x8f\xef\xff\x14m\xc7\x00\xfe\rF\xbe\x82R\xd1*G\xbc\x08\x8dI\xba\x9f\xa8\xebdvS&P\x15\xc2\xf0E\xfb\x00v\x93\xab;\x92|\x8e\xdeR(\xfdy\xe3P\xce\xd3\xb3\x81\x07\xb4\xdb\x92\x06\xfe!E}\xbb\xd6Z\x1ct \xd1\xe3U\xd1\xbaJ\xf7\xa5\x00\xa2\x96\xc9\xf1\x97\xf3\xd2g\xb8\xd0g&|\xcb\xd8\x9f\xc0\xa4\xfc\xf7(\xb6\x12"\x8e\xe4)[\xb2\xa8\x8e\xd2\xe1\xcd\xa4\xde\xa6?\xd8\xd1\x06\xe8\r\x11\x00\xdf:\xb8`\xc7\xaa\x9e7Y#\x8e8\xee\xc3]\x0f\x92l\xe0}.Z\xd7\xb04Ga$\x07r\x8e\xda\xcc\x96\xbc.\xb3\x9bH/\x9d\xc0\x1euO\xee\xe5z\xba\xd8\x06\x00\xd7\x0bQ\x186\xfe0\x9e\xc2\xd8Z\x90"\x96\xfd\xaa\xdb\x9e\xfa\xe4\xdd\xc6\xd6{T\xe3\x1c\xa40\xa0]|\xe9ki\x16\xb5\xa6!%\x83F\x0b\xe9\xc6G\xb0l\xc0\x84\xdd!\xe9\x16\xbc)\xd4\xf3\x8eP\xd9z\xc3\x88\xf2\xd1\x95\x04\xa7\xb9\xb3c\xd0\xc8S\x05\x1a\xc1k%Lr\xc4(\x05s\r\x89\x9f&\xa5\x86\xbf\xe9\x8c\xd3\xad\xf6w\x90\x1dA\xc9\xd1\x9eJ\xd7\t\x15 \x0f\x0f\xc2|\xda\x1e\xfa\x88\xff\x91\xb6V,{\xc6:\x16\xd1\x92\xc10\xde-\xd0T\x85\x8a\xd3=\x03\x9b\xc4\x1bN\xb0\xb1\x81\xb8\x89\x02\x80\xf4)\xe1\x05\xba\xe3\xbbBxh\x81\x93\x18\x14\xa3L\xc5\xb6s\xc5\xe5*\x16\xbf\r|ng\x07\xb2\xf4M\x99\x93\xb6d\x84\xe3\xe3\xe1\x016H\xb1>Q\xafX\x9e\x95p\x13\xb8\xd5\xa1\xab\xbf\xa9W\x9b\xcd\xa4\x13\xa1K\x10\xbf\x88/\xa2\xdb\xbb\x84&Z\x97\x80\xd3\xac\xc8h\x7f&\xbbr4\xe4O\x7f\xef\xcf8\xfb\xc9\x01\x80\x07Z\xceOH\xc7\x96\t\x00\xca\xaf\xf1\x13\x01v\xe4\x0cP\xd2\x02\x97\xfd\x87\xd5\x14\xde\x81\xf3\xa4\xb8_\xf0\x1f\xa6kaW\x95\x83(\x19\xd8Z\n\xe6\t\xa1\xaf/\x81\xb6\x81\x1c\xed=\x88P\x99\xe5\x9d{\x0bf \x92\xf7\x14\x8b\xaf\x9dA^\xf2??\x1d\x96\\g\x84\x18\xfaO\xe8<q\x80\x0f.\x8f\x8a\x94\xae\xc7\xc4\xc4\x11\x93rC\x9c\xea\x13G\xff\x0b n\xb4\x13}\xc9q\xc9W\x1b\xd4\xc7h\xd5\x04\xd0\xeb\xb4\xc0V\xe9n\x9f\x88\xc1\xf2\x8er\xd6\xd7\x10\xf4\x93J\xb1\xf0\xc0GW\xf7\x9e\x92\xcc2}\xd2\x06\x7f\xffP\x061$\xc6\xb6\x8a.X%\xac\xed\x8ap \n$b\x9a\xbc\x9c\x0eN\xc3\x97L\xd2c\xd8\xb1\xfc\xb5j\x0f\x13\x8fT2/\xe3\x13FI"\x125\xf7\xfeS\xb2\xd6\xc60\xcb\x0c\xee\xb4\x11\x05z)gJ\x11\x9d-\x10\xf9I1\x05\xa5:\xe0\xd2\x0b\x05\xa4\r\xeeLC\xf4\x9d\'\xcb\x1a\x7fU\xde\xe7W\xef\'\x01\x01\x9cu\xabj\xd1\x86\x80\xfa|3\xf3j\x9a\xabW\xd0\xc2\xe7\xcfK\x1b\xda\xf7\xc1<\xab\xb1\xd7h\xcd\nK\x9f\xc9\x8ck\xbf<GK\xc7Y\xae\x95H\x96/\x1a\xabT\xbf\xe86z\xd0\x14\x17\xb398\xe4\x81\xfe\x7f\xbf\xd4\xff\xd0\x1e\xca\xce\x85{\r:fw\xf5\xe4\xfapNi^\xbd?\x9c"39o\xe0\xdaj\x17nbW\x08H\x83J)gs\x04\xfb;\xc9\x94\xf1\xd3\xe7k\xf6Z\xd5V\xffGD\xc1m\x92\x0c\xf6\xe6\x06\xa8\xbdr9N\xc7\t\xc6\xa9\xfbQ\xa3\x8d\xdf\xf0\x056\xd5bE\x04m\xc3\xd8\xf5\x0c\xbf\x1eP0\xe3JK\x0b\x12\xfd\x8eH\x1dWX\x93$\x7f\xd9\x88\xfe\x9aC\xb8N\x8d\x08X\x01\xdeO\x983wT\xaa\x999\x10\x13\xbdlNmZ(S\x0c\xb4\xce\xe1\x00\x01\x84(\xcf\x9c|\xcc\x9b\xb9\xcb\xc7\xa7\xa7\xb6-Q\xdb|\x1a\x91\x1a>BR\xff\x03\x8e\xeb\xbdQ*\x86\xb3w\xca\xfadjP\x9b\xcc\x93\x94&t*Y\x02L\xdc[\x00\x12\x98X\xfdZ\xb4a\x84\xd0_\xc2\xad\xcfxR\xdd\xba~\xfet\x08\xc8F\xda\x9f<\xaf2\xd3\xfe\x06MjFY\x10O\xc8Z\xc5\x99\xfd2\xed\xa3\x12W=\xa8\xb3)K\xa6V:\x17\xe9\x1e.:F\x90\x97"w\n\xea\x01~4\xa9\xf1\x9d\xf1F\x81\x04\xa07\xfe\x92\xa5\xbey\xbf\x86\xab\x04(\xd8\xb7n\xd0\x05\x14\x05?\xdb\xdf\x0c+\xbe\x9b~|"\xcaC:\xe9`\xceC\x82Z\xdfKZc\x8fd\x8c5\r2q[\xef1\x84\x7f\x19\xff\xb3\xd4\xc1~\x1dG&\xccu~\x19U\x12\xe1\xda\xc0%\xc6\x9a\xfc\xbe\xe4D\xac\x91;Q\xfe\xf6\x13\xba8\x83\xd6\t\xce}B\x87\x976\xe0\xd1\x99\xbf`\xa7l\xb0\xbe\x043am:(\xc8\xd7@\xec;\x9dR\x13\xedL\xeeS\x18x\xc0\xed\x05\xd0\x99d\xa8\x98\xb1\xeb\x05\xe2\xc9\xe2%\x93T\xc2\x05\x9f\xab\xdf\x17\xf0\xaa\xac\xcd\xd1*z\xfcsA\xa5\x91\x8e\xc4+\xd8P\xeci6\xb9\xe1-\x05~\x9deV\xba\x0cy P\xb2\x1co\xb1f\r\xfc\xe5\xf4\xceC\x0erHq\x07\xea\xd0\xdcD\xa0\x07Z\x1bD\xee:\xaa\tW*"F\xd2\xee\xb1!\xf7H\xa5\x87!^\xfby*fIMA\\\x86\xd8\x92]M\xf4V2\x80\xb2\x9f\x05`\x9f5\x9cA\xe7\x0b4 T\x8b\xe3\x9d7eE\xba]\x82a\xd4\xd0t\xa4\x16\xc76PXH\x9a\x0b\xfe\x92E\xd1\xcev\xd8\x08i\xf7D\xbd\x81;\x01n\xf6k.\x88UlKlga\xa2j\xa1\x9fY\x05\xef\xbf2Vb\xc7\xb00`o\xdc\x9b*\xa8\xf9\xff,\x9f\xb2g\x83rU\xccf\x18\xc8-\xa8W \xb6\xc2\xde\xf4\xae\xbab\xc5\x7f!\xc2#\x96.\xd1\x0bl\xeb\x96ku\xd3H\xdf\x93\x9b^\xa9\xfa)2\xa1\xa6\x14\x976H\x8fP\xa8)\xe7\xbe\xe7\x9dP\xebU\x84>\x16y-\xc1}\x9e\x85\xe8\x88\xce\xb3s\xbb\x8f\\\xba\x89\x1etrc\xd1\x103c\xc7O:\xa3\xc6\x1e\xb4\xcdf\xc4\xa5\xbb>U\x01_v\x96\x01]\xe4\x93\x1eh\xb0\xf9\xcb\x8b@\x96\xd2\xf7\xd8+\x96\xffV:j\xd4k[\xb42.\xaaA\xb6\xd7mjE\xe3\xc5\xe9\xda\x00\xf0\x9a!=\xcb\xd8\xca\xce\x8f\xc4\xe7\xc5+\x05\xcdvR~\xc4t_\xd3>\x99\xbe\xe9\x99\xa8{\xf5\x8f1\xfdF0\x10\x16Zd\xc3Z\xdf9G\xd9o\x04p\xe1\x1d\xd0\xbd\x1c\x18\x0f\x05\xc8\xed\x18j\xc5-\xf6\xcc\xf53\xc0\x0b*\x1a\xeb\xa2\xa5!\x9b\x86Ee\x88\xfd\x8b\xa5\xfc\xf5\x87\xcbV\x14\x9a\xe1.\xac\x04jp\x02\xef*=\xf4\xf6\x81J\x1c5\x8a?7\xcfs\xf1\x15eI\xf8\xd7\x8e~\xc7\x9b\x99B!)\x03*\xbe\xa6=\xe6\x9a\xe3s\xbb\xf8\xa4\xfd\xeeg\xad\xeb\x9b\xbc\x0cc\x84\x1a\xa0\xb3\xadT\xbb\x08\x9d\xa0\xa7!T\xe5\xaaE=\xab.\x1d<\xab\xfa"\x9dU\x1f\xd46\xdd\x18\xbbx\x16\xf8\xf1\xdf\xbe*\x17\xa5\x02\xc6\xcc\x06<\xaf=\xcfl\xbc@i\x0f\x14\x84l\'\xe4w\x19y\xb8[\x97\x15\xbd{\xb7b[\xd1\xee.e\x17*\xf3\x94\x00b/\xae0\xbf4\xa1W\x96f\xc1\x9aQ\x99\x00%\xb5/\xa4]+E\xd6\xd5\xec\x05\x0c\xbd\x8d\x91~\x96\xdf\xdd\x9c\xfd\x1em0\x82"\xbe\xad9h,\x96\xb0\x1cw\xc9\x7f\xe6\x19\xea.\x80\x7f\xc0\x93\x94T\x10\xa2\x99z\xb8\x80\'\x81j\x83I\xce\x87\xf1",oPW%\xf8\x8e\x98hx\x85;\xe6_\x88\x8e\xc0\xd5[\xf8!\xa3\xe6\xe9\x87\x9f_Z\xfd\xdc\xb0%\xec\xca\xb1\x13\x8b\xb8o(:\xd5\xfe`iGb\x8c\xd8U\xd6\xe4\xac\xads\x18\x0c"\xad\x06\xd7\x0fx\x8c\x9fCL\xa8\xd4\xf3bG\xf67~\xc2\x06\xb4w\x03\x97\xe1\xafI\xda4\x91\x80{\xaa\x1a\x18\xd0B\x91O\x98\x1d\x19\xb3\xb0\x84D\xcdB*4&\x01\xa0s\t\x18\xb7\xdb\x0em\xebc\x81\xf5yf\x9fe\xb6\x95*@\xf4\x9d\x84\x00\xfc\x80~\x18<Ha\n\xf0H\x90\x8e\xdc\xf3c{-\x94\xe0E\x99\xd7\x82\xffo&\x82oj:.8X\x08\xf6l\xf0\xbb \xa0\xd9\xf2\x8ci\x12Y,9\x9e\xb1\x05p\xef\xcd\x03\x07\xfa\x1a1\x10\x86I\xad.8CoVt_\xd4\xbd\x89Z\xe4\xb3F\x13\xfex\x0b\xad\x9d=\xbc\xdc\xc7\xcc\xa7\x04\x03\xdc\x14~\xbc\x9b\x01\xaa\xe5\x92\xe8\xfb[\xf1\xd8\xaf\x9c\x11\x8e\x1ewC%N\xd4\x82\'\x00O\xf2#\x817\x12\x0f6|\xbb\xd6\x1co\xeb@\xe8n!\x03\xc7\x1ei\x1b\xcd\xdfR2ov\x90\x90\xdf\xfe\xec\xa9\x9e\x0e\xf1E\xe5l\xe6\x03KB\x82\x13\xe5i\x7f\x95\xee\x7f\xde5\x1e\x8a\xd0\x14\x1e\x1a\x8b\xe1S\xe75\xa1 ww\xe5`7\x8by~\x8bQ\xfc\xa3\xc8\xc5E\x07-@\xe6\xdd\xca8$\xd8\xf5\x98MA\x118\xadL\xc5{\xe4^u\x9a\x1efH\xbb\xd2\x10;\x13\xd6\xd6\x9c\xb9\xe7\x85\xde\\\xeb\xe5\x01\xd5;\xec\xc8\x03O-\xd8c\xdc\xf9\xcf\xbb\x92\xd0\xff\x1c\xd0\xc2\xfe\xc2\x8d6L\x17\xc1\x02\xcc\x18\x17\x1e\xc3\x17\xfdn\xb2f\xbc\xfe\xedO\xc0\xe3:\xe0\xa4W"t&\x01t\xdc\xb0@\xc5\x02\x83y\x861\x96\xe6\x13{*]\x0bJ\xdb*\x0b\xf4lA\xd3-\x0b\xe9\n\x8b\xb5\xd7\x96\xc7\xf1\xd0K\xef{N\xf1W\x08nF\x04W\x95\x02\x97\xf7\xb3\x8bl:xFc\x06\xc8\xf1j\xb27\xe2\xaf&r\x12\x93\x13\x0be*#!\xbe{\x83\xf3\x96y|I\n\xd7t6UF\x97\xbb,\x00x D\xa4\xbd\xf8\xfa\'\xed\x03~Mc\x06Sv\xc3\x1b\xd8\xb6t\x12\xb2\xc3\xb7_\xdeN\x9b\xfd&c\xf2\xb7D\xae\xbf\x12\x98\xf8\xbf\x0c\x8d\x96\xb2\x83Ie\xa3\x0fR9\xd6l\x00\x0fz\xe1\xe6\xc1aX!\x8c:\x89\x08\x88\xc8\xaa\x1d\xaf\xfe\xb0\xc7\xe2\x04p\xa5D_\t\xec\xa2\xd9\xb6\xbb\xa5\xf2\x1a\xff0\xce\xd7\xd3\x11\xc8\xbd\xca Roi\x92@\xb7F\xa7\xb2\x89\xd2\xb7\xc7TT,\xa5\xa97\xb7\x1c\x94\xed"8S8.\xef\x8d\xb3\xeb\xe8c\xba\xd5\xa98mc\xea\xf7{\xe9\xe23AeB9\n\xcd\x1c/\xce\xaeP\x12&\xbc\xc3\xcc+\x0f;\xf6vc\x9be\x85\xda\x14)U+)\xe3v\xb3\xb8\xaf\x84\xd4\xc7^\xa4\x89\x8a\xc3\xc0\x1e^\x17\x15:N\x80\xe9\x8cF\x8a\x95HC\xe0G\xb5\xf2\xda\xbe}]&\xd3\x03\xeff\x80\rLe\xd3\xcc\x0e\xef\xf0\xff\x17q+\x0c\xe9\x8dx^(:\xd9\xe2\x7f7T8\xa0c\xb9\xb1pO\xdb\x939\xac\xd7\xe2\xad8\\\x82\xd7\xa5\xfe|\xfa\xa6\x03?\xf7\x97zZ\x82\x89\x99\xee,\x8f\xeaXt\xb1\xad;k\xbb\x10\x88\xaf\xca\x0f\x83/\x14\xcd>\x8a\xdaR\xa7\x03\x1e\x1c\xde\xff6\xb2m\xad\xfc\x93#\x15\xa7g\xf1\x17\xc9\xb5\t[C&\xf9\x9a\xbc\xd6\x14\xdbj\x84n\xc2 \x96F\x1e\xb8f*3\xa17\x9e\r\xa5\x9b\xe7\xccz\x17\xe3Y\xd2\xa9>\x07H\xdc\xc1\xd1\xb3/OZJ\x0bw\xd9\xe0\x9a\x9a\x15\x00\xb5C\xd2\xe6\xaaf0\x06\x14\xf7\x1a\x8d\xc3\xfd\xa2\n_e\x17l\xc4O\x06\x08\xa7\x80\x12\xc7\xc8i\xba\x87\xd8Oy@\x84\xfas\xde{12mb\x82\xdc\xebmp>\xac\x9fL\xa3J\nT@`\xbb9$r}\xdb\xbc\xe7\x9809\x95\xff\xeeKX\xb1\x05\xcfz\xa3w\xf2\x87\xf3\x9d\xc0,`\xc2\xc9(\xea\xf8\x81V\x8c3\xf4*^\x8d\xde\xea\x8c\xd5U\x1dfj\xddR \xbf\xc8\x84\x7f\xe1k\xd8\xa7\x85]8\xcc{\x9c\xdf\xfa\x1b\x01Z6.^\x90\x976\x90\xff\xa4\xa5\x8e\xddA%\x10\x1e\x8aA\x0e\x8d\xe9\xebg\xba\x19t\xa1\x91\x93T\x9b\xe3z\xa9\x82\x92\x00Hu\x1b\xb5\xcd\xa9\xf23}\xa2\xe6\xa7a\xfa\x1f\xe7\xb4V\xf2\xab\xa2\x12\xf0\x8d#\xc0=\xaf\x1e\x82$\x1f\xb2\x1a\xfeN\x8f\x10\xc2\xfch&\x1e\xdb\xd4\xb4\x91\x9aW3\xc3\xf8R\x98yE\xcc\xe0\xfa\xc7\xee\xc1\xefu\xf5\x92\xb9\xee\xe1\xddS\t\xf5\x0c\xbf\xc7\xf0\xe3\xada1X2\xbe}\xd6\\\x1d\x89\xee\x15\x9f\xc8H\x85\x9f\x8a*\x06\xd4\x03\x9a.\x0eo\x0eD\x13\x8eV\xe7k/:\xb9\x18O@\xb2mx\xcb\x03\x10\x05[5l\x08\xc2@T\x16\x92\x1e\xbb\x1c\xf5\xa9\xee\xfdX\xaem\x16RH\xa2\x03\x010\x8d\x88~\x1e:\x05_\xe1>\t\x85KS\xb4\xe1\x8d\xb3>\xb1\tK\xd9\xf60\x8az\x08\xf5\x83\x10t\x11\x97\xcb\xd0\xdf\xd3\x89T$\xc3\x83\\+\x84\x12\xd4Z\xbf\xa4\xee\xc9GyO\xa3!\x9b7\xfe:\x9d\x93\xceW\xf5\xa0\xe2\xe9\xd3\xca\xcf\x01-$\xf5r\x8c*\xd7\xa0\x13>\xd9G\xca*\x88k\x0cL\x1b\xdc?\xca\xe8.\xdaI,\xc9\x1238%\x19\x89e\xf2,\x0fo\xfcU\xe4\xe5\x01RQ0\x9a\xf4F[L\xe77<\xc9\xcf\x96\x19\xf4\xa4KR\xcd\xfe\xb9\xa9\xc4P\x90\xd9\x17\xbf\xd8\xe8m\x99\xb7@\xd4\x1a\x07z\xfd\xfc\xf3\xd3\x97\xb6\xfc\xa5\xb0\xfc\x1b\xdb0\xdb\x04\xb9\xba\x8b\xf2\xae\x1c\x07\\\x86-\x06\x81\x00\'\xaaHx\xd5aSc6^5o\xb1\x85L\xea\x0c0\xad?\x85b\xe9\xa9\x8czo\xe4\xa7\x92\xdd\xb4:\x89S\x89Y\xbdt\x0e\x89 vM\xe4\xd5\x00\xa9\xcb\xba\xc8\x9b\xf7\x08z\x18\xe4\xe4\x17\xc9\x7f8|\xc2`\x0c\xc2\x9b+\xd6V\x88\xa5\xbb\xa9\xb2\xcc;FS\x95\xea{*`\xb41\xc5\xe4\xf6G\x86\xd2\xe8\x9e\xff\x0e\xe8\x9a$\r\xd8D\xd8\x1806\x1f\xad\xd8<\x01Ai\x02y\xf2\xec\xc6R\xf9\x0e\x86+wH=)y\xb0\x95\xf6\x84\xcc\xeb\xa1\xa1f\xd5e~\xa3\x01ks\xbb<\xd4\xfc\x04\x10_\x9f0\xcf}\xc1\x82\xb9#F\xb03\xa3?\x9feK.\xd6\x93\xc8\x87\x9c\xb0\xb81\xb7\x19\xa6\x80\x1fQ\xe1\xa3\xb5QB7\xfa\x87\x81\x98\xf2\xb3\x94M.\xd2\x968\\\x03\x82\x0c\x02\xb7\x80M8\x91\xfdy\xd55\x04\x04\x9a\xddFI=W?(1\x84]jcx\x1c\xfek\xb7cX\x9e\xa3\x7f\xccI\x9c"\xc0\\%\xc5\x9f\xa6\xa6^2\xbe7\xb6\xabP\\\xadh\xd8\xbf#:\xb6\xfbsv\x1a~\xec\xf1h\xf6N\r80\x03\xbeI\x14\xe6\xfb$\x00\xa0R\xfc\xad\xff\xd8/\xe0\xee\x86\xa9e)!eM\xe7\'!\xfb x\x13\xbfC?e\x9e0\xa6HW/\xb9(\x12\x11\x13oK\x08?\xe4b|\x8a+\x84\x8ch\xf3\x92\xc0\xd1\x12\xa5n\xe1\x03\xa2\x0b\xf4\x8e@\x1c\xb6\xd3\xda\xd4\x99\x82\xcb\xdd"\t\x0c<\x18\xe7!\x99}R\x1a\x88\xc1\xa9\xe9R\x8d\xad\xc2\xee,\x153\xf8\xf98\x98\x1c\xde\xdcvQ\xf5E{\x93\xa9\x89\xb5\xf6e\xa4*(\xb8\xb3\x08%Q\xd3\x80\xe9\x8eAw\x0b\x00M\x03\x08\x19\xf9\x8f\xdc\xc0\x1c\xce\xe7\xfbW!4\xd4\x18+\xd7PDCSx\xad_\xf9\xeb\x8fn\xd4\x8a\xa1\xcf\x1a\xddO\xda\x16P\x80~,j\xd7\xac[\'\xccc\xdd@\xa9I"\xaa\x06c\xd8F\xbeg\x13>\x19l#\x81\x926\x02,\x05\x12\xb4{\xb1\xbe\xdca\xd9%\x95\tw\x88\xb5e\xc6\xdd\x05F<&7G\x06\x83}\xd1\x926\xaf\xb2+\x00\x8a\xcd\x88\xbc\xf4\r\x93z\x1dvU\xb0\xac\xda&\xc0\xd0\xf8\xfc\xe7y\xf3\xb5\x7f:\x0c6\x8d"\x9c\x0c\xdaD\xce\x08<?\x08\xcf\xf2\xa5_\xb6M\x80\xa0\x91G\x08o&\rMqP\xcc\xad\xfd\xee\xd1\xb3\x1d\xd1\xcea\x06\x85\xd9\x9a\x05~\xb6\xbe\'\xb3f\xbfr\x98\x7f\x1e\x06\xe0\xc4~w?BR\xe1\xc4\xd9\x892\x11\xec4\xc8\x9d\xd2\xac\xec>-X\xf2j\xb5\x1aTk>\x8a\xcdm\x11\xc2\xba\x87_\x12{y\xa5C\xa5F\x06S7\x9b\xdfN\xc4\xa8*\xd3\xb4Y\xa5/\'K1\xbd5\rO$\xdf\x96\xec\xd4\x00\x94\xb2\xc9dw\xf3\xb6\xads\xa3\xbf\x89wX\xfd\x10V-\xd4\xd1\x8a\xa0\x13V\x7fW?\xf8\xc9\xd1\x93\xee\xbd\xc8M\xb4\xd4\x99\xe6\x05\xdfV6\xd7gsx]\xca\x8a\xc8W\xdc\x14\xcb\xc5\xe0Gj\xd2Fl\xd4\x0e\xf1\xb0D\xe6\t\xf6\xc4\x0f\xdf\xe1\xf7\xbd\x96,\x9a\xca\xbb\x10\xbe\xf4\xb9\xa9=\x07/\xaazEiDA:\xca\x9f\x97\x96!OA\xaa\xdd\xf7\x00q\xd7\xdc=]\x98d@\x9b\x1a\x9e\xf9\x08\'\xd6\x04;\x06\xa7\x04\xa3\xe6g\xd4\xe9\x08F\xcc\xff\x89\xf5\x03\xfdz\x1c\x90\x8b\x9c1\xc5\xcb\xa4\x9b\x8a\x02\xaf\xe9aX\xaf\x14\xb6\xa0\xaa\x9c\x13\x19\xd3\xa8Ax\xe40\x92i1+\xcc9\x86Q\xc6?\xa6\xcd\x10D\xf0\x87\x9fP\x02\xa4\x87_\xc5\xe6&\x10\xc6\xcb\xfb\xb0Y\n\x05`%e\xf8\\x\xab5\xb0P\xbbz\x0f\x1dW\x82`\xe9Sf\xab}P\x17\x1c<6\x8c\xe1\xaa\xe5w\xbf\xd47s\x1f\x15W\x12\xff\xa1t{\xa0\x93\xa6ZZ1\xe4\xd1\x9bw2\xdc\xb8\xb5\x9a\xdc\x97U\x88\x80\x88\xb1%\xaaPe\xb3Zo\xebHT\x1eJ\r\x12\xdc\x83\x83\x7f\x81\xc08\xc1j^\xb3\xd55\\\xb9\xf3\xc2\xaa\x8a\x86\xdd\r\xa0\xd8\xd1\xcb,M\xd8^\xad\xed\x0c\xf4_a\x9f\xca\xa6\x14%\xf3\xced\xefB5\xf8\xdd\x08\x12\xb8:?\x9ay\xacrk\x15\x11\xf6_^F6w\xce\xfe\xdeJ\xf6l_\xf9\x0e\x1fQ\x8c\x06\xf5\x96\xbf\x89~O\x10\x02\xc7\xafq\xf3z\x0c\xa0_\x8c\xfe \x83\xaa\x80 \x90\x1c\x86d\xb3\xb5\xae\x92H\x1b\x90\xd5=\xdc\xec\xd9\x913K@\xd0v\x12\xab\xa7]h\xb0\xa2\x0b\x98>}\x11\r\x0c\x14\x14!7\xb0\x9b\xd34;E\xd76\xf7\xc4FG[\x8b/X\xf6\xcf\xbfz\x95\x8a\x1ew\x1d\xd2\xbe\xa4o\xe5K\xbd\xe0\xfa\x96\xfbbX\xbcq\x9a\xd3\xb7\xcaG\xcd\xe4\xfcB\x83\xdc$\xe5p\xd7\xbd_\xc5M=\xeaH`\x8f2r\xcf\x9c\xebbS0.\xc7\x06\xfb3\xf8\x0f\xfa\xe9\xd1\x9f\x00\x07\x9bBy\xec\\\xc8\x1b%\xad\xc5NM\xb2\'t\x0f\xe6\x98\x17\xf0\xba;\xd8\xd1\xc1%\xf1\xdeO\x01.\x076M\xafw\xac\n|\x949\x0c\'N\xba\xf4\xee\xe3-&\x96P9\xd0\xf4\x04\xd0\x8a\xa5&\xe4\xb1\xad\x91q\xc6z\x8d\xcd\xf9\x9c\x97\xf1\xef\xab\xef\xdd\xaa\xa9!\xd9\xff%N\x81\x12!\xd0,\xb1\xbe\x02\xe7\xc2\x93._\xa5\xd7\x82\xa2\x8b\x92\x99\x8b\xda\xc6f\x1b\xdfr\xc08\x19\xac\xbf\x1a\x82=\xb7\x92\x85\xc2\xb0.\x0f\r\x95y\x0f\x89\xc3m{\xc60]\x01\xde\x7f\x824\x81\xa7\x19\x19%\xa4#U\xba\x85<\xcdd\xdf\xaa\xbc\x8d\xe6]\xc6S\x088\xeaD\xce\x05\xfc\xfc*u\'<\xb4\xd9\xe5F~f\xce\x184\xd6\xf6Q\x88)\xe8}L\xa3\xde\xe6\xbb\x0fE\xd3\xcbwAe8\x8a"b$\xb7\x19b(\xd1\xf2\x0e\xc0=\xe8\xe4\xb6\x0e?NK\x91\xba\x88\xf90y\xa6\xaa\xe8\xd1\xa4X\xfd\xa9@\xcb\x8ad\x81\x86\xe9\xd1J\x97\x16\x9d\x986>\xab\x13\x0co\x8c\x91\x83\x18w~\xffz\xbb\xce Qq\x15\xa7\xe9\x9ap\x15\xf8\xd4\xb1?\xe4\xb6\xf2\xbb\x9b%5\x11\x7f\x8d\xc2\xcc\x94\xdc>\\\xd7\xa52\xb5\r\r\xf7Q\x8f\xa4\x01>^jK\xbaZ\x0c\xffQ\xb6!\xc6\xf3\x9aG\xe7!\x18\x140\xc5G\x8dU\xf0#\xdc\x9d\x13OS\x18\xaeV9ys\xc6f\x13\x16\xd3\xee \xa8\xdcp\x9ct.\xca#1\xb7\xcaGD\x97Ij\xa05\x90\xa0\xd3\xc3b\xa6\x9c\xb8w\xbc\xc737\r0N\xad\x19\xc5\x1fs\xac;\xc4\x9f\x99\x9d\xb6\xc6\x004\x08\x11\xf6\x9b\x8c\x9c\xafzXk\xc4=_d_\xd9\xba\x96\xc2\xb4D\xf3\x0c\x88%\xb7r\xc4v\xf0a%\xaf\xf5\xfeu#>k\xa5\xe5\xa8\xb4\x01\x1e\x97\xd2\xc2\xadH\xeeg\xe9\xcf*y\xadc:_\xd6\x04\xee\xe7P\x91$\t\x8cU\x99V\x16!\xcc\xa1t\x0cC\xe3a;F\x8b\x85\xde\x92\xe9\\\xd5s\x8f\xa0$\x9cc\x1e\x9aD\x1cB\xb7v\xb6\x0e5\x19\xa4{\xe1\xec\xb1\xe2\xf6\xb9\xe2\xc5\xa6\x8c\xe0\x1eP\xef\x9b`\xaa\xa3\x10\r\x02,wPL\xc3\nL\xdd\x1f\x14.\x93\x96\xad\xbes\xc7\xe4\xd8\xc6\xee\xda3\t\tC\xd1\xc1n\xbeS\x9fQ>\xe82\x14\x04\xa2\x08\x08C\x10\x1e?M\xd2\xe7\'a@\x12g\xc3\x04\xb5\x16:\x89\xb4$\xdeuS\x90W&\x1d\xb3\xdb\x0e;Gi\xdc\xe1\xcd<\x01\xa0\xe6s\xbc\xd1\xe3\x08\x18\xe8\xdbz\x96\xcd\xf36\xc6A2/\xd0\xf3\x88\xba\xaa\x8b\xa4\xe5(^u\xf7\xd3m\xe6\x08\xd2\xc4\xc2R\x8bx\xect\x8bT\xc1]\xa8\xbd\x13\'\xcfO\xb4\tEz\xabK\xd2\xd6\xcd\x0c\xa4\x9d\n\x8ewx}\x92\xd0\x9a\x14\xa6\x81\x91ty\x1c\xd42\x01\xdbkD}u\xd7\xfc\xc1\xf2\xe3\xf9\x0fU\x0c\xb9\x18k)\xa5\xe9\xf3*\xea\x9f\xc1\xf3\x9e\x84\x03\x18h\n\xcf\xc3\x1ec\x03\xe8\x1c\xf2F\x8c\x06\xa7+\xf4\x01n\xb0\xa2c\xd8e\x84\xf9E(\x195At\xe1 \x1a*\xd7\x0b\x8c\xfe\xa1\xc4\x80\x80o\xf0\xd3Sm\xe8\xb0e\xabLJ)!\xa6\x1ar\xb5r\xf7\xe7\xd8V\x84}\xbcG\x82rt\n\xfaJ\x10\xb7\xbd\xc3i6\xe0\xf5\x85\x0e\xf1~w\x0eH`1\xa9R\xcd\xfe\x17\xeb\x9f\xc4\x00\xd8\xd7v\x0b\x128\xadv{\x18\x1a9\xc4\xef\\\x17\x8a\xfe\xa8W=\xb4\xa9\xcb\xb5\xb0\xc7\x1b\x1e\xde\x7f\xc8\x8d\xa8\xcc\xe8\xb4=d\xd7\xa1g1\xad\xac0\xe7\x14QX\x92\'~w\xee+$\xd9R\xbfR\xd8P\xd3~\x18u\xfd\x15\x8a\xbc\xcf\x96^\x8b\xe9\xda\xc9\x98l\xc89\xb1\x0f3\x92T\xb0\x04\x84:\xdc\x12y\xe9%\xd9\xbf\xc1v?\xf2#\xc4\x08\x06\xf0\xf2\x1f\xc5\xfe\xf3"\xb4\x85y\xe1Z\xed#[XQ\xa4Y\xf1\x14&\x0f\x8c~>\x01Q\x89\x8e\xbd\xed\xe7\xf4\xed\x81\xe0v\xf9\x90\xb1\xf6\xdd\xa8fvU\x03\xc99\xb5\x950\xc5\xc3\x1f\xf7\x05+\x14%\x85\xaa\x1bg\xc8\x81\x8fln\xa3R\x93m\xc7J\x08_Q\xc7?x\x91%\xabJ\xe7\xc8t\xe8\x81\xef\xb0\x15mq$:\x07D\x1c\x99\xfbItX\x07T\x96#\xa97B\x97\x14\xc6\xf5\xaa\xf1\x1c\xbc\xb4\xd0\xd8(9\xb1%\xa4\'f\x11vb\xcb\x1d\\\x15\x83\xee\xcc\xc9\x02\x13=\xd6E\xf1yg<\x96\x1a\x894Sk\xf2^C=\x83R[*\xf7!\x83\xd6]\x90\x88d(Em<\xfe\xfa_A8\xec\xbcX\x07\xff\xe0\xa7\x84\xceh\x7f\x1e\xd7N\xd9\xc9\x1eG\xa8\xe0\x8f\x8c\xfa\xff&\x94M\xe8wx\xc5\xaez\xbe\xd6\xdei\xfc\r\t\x94\xd2,\x88yR\xf8\x97+\xbc\x98T`hX\x06\x9e\x88g\xa7\x99\xd3\xbcE\xce#b\xf0\x86w@6\x97?\xf7&\x00\x1c\x1a7YS\xb1p>\xea\x15n\x93!\xfc|R\x0c*\xf0\xe8\xe7\x15<M5\xd9\xf4\xf6CDr*bjo\xb35\x91\x1c\xa5\x03\x0b\x80\x1e\x1f\xfe\x0b\xe2\xacFx\xba\xc21\xbd{7>\xb5\xc3\xd6lv>\xf38\xb0\x1eh\x94\x03\xa5\xf0\x1e\x1fA\xcc\x0bN-9pm\x10\'$\xcaD\xbf\xf8Q\x1ad"s\xff\xf3\xebv{\x0b\xf4R^\xb9c@\x08}g\xe9x3\xeew)s\x8f\xfeF\x91V\x85\x1a`K\x11\xcb\xa3\xd8\x1a\xed\x11\xd1\x1b\xe6PHb\xc0\x06)\xaf^\xc7\x94IX\xfa\x1e\xb0\xfc\x9f\xddPs\x84\x9a\x03\r]\xe1\x8f*t\xc6\xc5s\xae\x9c$f\xe3\xcex M\xff\x89\xa9\x85\x801\x0b\x9aQ\xbf\xac\x94\x08\xe9X\x9d\x8f\x8b\xeay\x11Bt\xb7O\x0e\x9a5+\xc1\xae\x9e$N\xe2\x9e4\x1d\x86#H\x9c\xac\xc9\xe8\xe7c\xa22\xf4\xab\x16M\x13\x1b^NpR\xf9iV\x17\x9ck9\xd2,\x95$\x1c~\x02\x8e\xb1\x93\x7f(Z\xec\xde\xc0\x99A\xa2\xf42\x91\xdc\xe1\x8ff\xabyW\x9a\x9b\xad\xf5H\x86\xe6>\x97#e\x88\x8f:\xd6\xf7\xb7\xbd\xd4\x90\xc6\xea\xf1b \xd9\xbaI\x0f\xd5\x83\x1a\x0c\xe9f\xfdTY\xab\x9f\xba\xbb\x1e\xe3\x8e\x81:\xa3\xfa\xac\x1e\xb2\xcdy\x8a4e\xaa\xa1\x05\xe7Q\xd2\xcfB\x14\xb4/=\xaf/\x07\xcf\xb3c\xf1V\x91\xb8\xbb\x99u\x94\xeag`\x86\xd5\xde\xfd\x81[\xd0bm;L\x96\xa7S4w_\x10Ai\xa4\xfb%\xd9\xa0\x86\xb1C\xc3\xaeL\xcb\x18\x9d\xe1~M\xef<\xef*\x86\xce\xd5C\x86+.\xdc\\gO\xbc\xdc\xc3\x9b\xf6\x8c\n\x06I\xfc|>\x91a,\xd6\xfa~F\x91y\x13\xd4\x06)\x1d\xf6I\xc3\xb5I\xa1\xce\x81\x9f\r\x90Q\xc2L\x9d6)\x06S|\xfd\x04p\xda\x17\x0f@\xc7cj\xce\x83\xfb\xdfz"h\x04m\xf19.\x10F\xcdL<\xe1\x00~9\xd7*FuZ\xbd\x15Gb\xe2\xdd\x0c\xf6\xf7T\xcc\xe9\xf6&\xdb\xa4MP}\x16;\x02\x0c\xae#\xd3\xd4\xf5\xda\x1a\xa6\x05\xb9\xe3\xa6+\x7f\x95\x97\xab|)l4f\xd3\n~\n``\xeeP\xf0\x1c\xd9\x8a\x91h\x02\xf9/\x94\xa8&\xd8\xcae\xfc>H\x11\x8fE}1M\xed\xe2\xe6\xa4\xee\xe0\xd7\xd4\xd4\xd6\xee\xb4\x00\x9eq\xbc\xe5\xda\x07W\xf9r\x18\x90\x94Qa\xd8"\xe9\x02\x01/RA\xb3\xd8n\xcd-cG\xd4\x1b\xa7\x7f\xe4\r\xce,\xceQ\x90\xae-r\xe2\xe2\xf1R\xb2\x86\x1f\xe9G1\rc\xfb>\x06s\xe3\x84e;\xba;f\xa5w\xaa\xa0\x0c\xfe\xc6\xed\x01\xc2Z4@\xe6\x99uuu\xed\xb6\xdb\xd1%\xb6\x1e\xb4l\xca\xfd\x0bjWwZ1Ro\x9b\xd2W\xb3m0<\x91HT:]q\tc1B\xd4M\xcdI>\xd5\xcbr\x84\xec\x8f\xfd{\xd6\x82\xcd\xee\xac"W\xde;\xbdD\x1aD\xb5\x14\x08\x9d\t\xf3\x8cb\xf8\xe7OH\xa9-\x91\x8f\xa7;\xff\xeepm\xfdB\xc1\xe9\xf5\xc0\xfc\xfa)7\xef\x86\x17\xcc.\xdcim\x12^\x93*\xf6\n\xf2\xc1\x13\x91\x06\x94xs<\xc5\xf5G\x1b\x84\xc1\xb9P\x86\'x\xb4\xab\x93E\xfa\xc7\x00\xdc\xd8\xb4\xf8\x00\xa7\xdc\x834&\x00\x83\xdd\xe8x\xe7f\'\xaewq\x13@\x1d\xa1\xb2T\xf17^\xa3\xa4s\xdb\xc3-\x022\xf2\xd2\xd8CM\x9aZ\x10\xdf\x81>\x19\xdd"7\xc26\xfc0\xba A\xa1\x87!f%\x0c\xc1\xd2\xac\x0b\xd4B\xfd\x12%3\xecg|R.\'\xab=z,\xd3\xba\xd2\xa3\x81\xf1\x1d\xe7\xd2\x86s1\xf0\x02V\xf8\xec\x0e\xbd\xeaZ1\xa7\xcdN\xf0\t\xa24\xb61\xba\xce\xaa\xf6VP\xd0\x03B\x00S]\x05\xae\x9c\xba\x03\x83\xebWT\x0c\xd6\x97\xd9\x86}\x13\xf49u\xd3\xd3\xd6\x8eiGA\x83\xca})\x89\xd1\x14\xcf\xb9,\x1e\x9c\x8c\x00*\xfd\xa0CZ\xb6\x17\xba\xe0g\xe3YbZ\x03\x1f\xc2\xe7\x88>\xde_\xf4ok\x95\x13\x07\xfe3\x8d\xaea\xad\x95/v\xea<\x10i\x00\x96[q\xeabT"\xaf^\x96+\xb2\xda\xebn\xd2#\x82\xf8\x84\x07B;\x88\xef\x02\xb0\x13\x18/\xc1\xe2!\x00\xa2\xe4\xaf\xac\xc6\x90\xa5y\x86\xc44\xc7\xe5\xc8`\xfa\xf4\r\xc0\xf2\xb3\xe1\xbd3Np\xb0\xa4\x14\xc6mE\xf2\xcd\x18"\nH\x07e\xd2\x8c\x03+@]O\xffq3\xe5\xb0\xe3\x8b\x8d\x06i`\xf8\xe6\xd2\xf5\x9a\xc3\xe7\xc2\xd8}-`\x0ce\xcb\xa1\xb0)U\xdb\xf2\xeb\xe0\xc8\nP\xac`\xb9t\x03\xb3\xf0\x8ae\x00T\xf3O\xd9U\xbf\xd56\xc7\x94\xd9\x1b\xbc%\xbd\xb6h\x97v\xbd\xdaUV<P\xcb^\x80\xf4|\x06@\xb8v\xe3Po~\x8f\x90n\rq\xac\xff\xdc\xa2\x11\x1bk\xa5\x94*-\x94l\x05\xf8\xe3<3\xaf\x15$\xd7\x9e\xae\x9d\\\xa7\x835\xd1\xccv\x12\x8dX*\xd9^r\x9a#\xb7A\xe6\x03\xf0\x1c\xcf\x96\xf6\xe3\xae\x9d\x0c\xc8*\xfc|\xa5I\xb6\x90Cl\x1ey\x12\x8f\xcd\xb1r\xd2S\xa0 \xabA\xcf\xf9>7\xadOu\x920\x8c~\xea\x8cF\x8e\xb7\xf9\xa3\x8a\xcd\xf0\xebq\xac\xa0\x8eY!>\xbd\xab\x87*Z\x0f\x00\x8d\x80\xcc\'\x9c\x94\x18\xeb\xe7\xb6Q\x9d\xb0\t\x85r\xc2\xd9+\xcd\xc0$\x88\xe8U\x8aKiJ\x822\\\xf1q\x03NO\xfa\x83Ne[2t\x10\xd7\x17>\xb3\xa2\x99/\xed\xa4m&\xa3,\xcb\x87\xe9\xc7\xe0\xc6\x9b\x95\x94\xdc{\xf6\xcab\xe2\x98{\xf8\xcd\xaeU\xf6W\xe6\xce\xfe\x82\x1a\xc4\xe22\xaf(! }kIgeT\x13\xedm?\xb3\x14\xeaB\xae}1\x0c%4\x90\xf3\xc2[\xb3\xd8\x92\xb8+\xb3\xc8\xed\x01>T-\xd8\xc1\xfd\xc6\xa2\xc4p\xc9\x1bVd\x8f\x9e[E\xa3\x11ngB\x90\xea$U\xd7\xad(9\xceAo\x8d\x81z\xd2Y\xd0\xfd\xa5\x08\xe4\x87\x07\xaf_!\xce\xcb\xd4\x15\x8b\x8e\xc2\x928\xb3}\x90\x0cpa3\xaf\xfa\xe6;\xee\xabJ\x190\xc1\xb9\x18.\xb1k\x9c4\xceY\x89\xa5\xee\xea&\\\x04F\x96\xa3.u&\xde\x9b_*\xb8G4c\x80\xef\x94O\xcd\x87\x9e`\xff\xda\xbc\xd7\x95\x0e\x9e\x81j\xaa%\x89\xcc\xc5\x13\xe5T\x9ag\xa7g\xca\xef\xc3\xcc\x8c\x1a\x96\xd8\xca\xf4P\x88\r\xfe\xb9\xec"HC\x93t\x14\xcc\xdc\xff\xa9\xcd&\xb4\x1e\xae\xb4(\x1b\x81+\xcfNh\xaa\xf5\xf0hM\x9b$\xa9\xae\x98\xda\x89\x18\x98\x93\x08\xd4>\x0fw$\xe8W`\xf1\x07d\x8d\x0f")\xdcH\x1d\xd26JM\xc8\xaa\x1a\x15n\xbd\xecC.\x16\xb2\xaa\x8fF3y{\x10F\xa2H\x93C\x0c\xee\xb3\xf3\x9e{\x9d\x18\xce\xaf0\x82I\xaa\xfb\xe2\xfe\xdc\x14n\x13-c\xd1$\xd4R\xde\xabE)\xe7)h\xc8\xc6\x16\xb7a\xe0\xd0\xc3\xe1\xd5\xba\xb3\xddu"\xa7gI\xc2\xdaj\x04\xfd\xa4\x8f\x87S\x10\xcd\x7f\x11|\x8e\xeeERJ\xb3\x07T 6/\x17d\xe3\xd1Y\x83\x9fK\xd4{"\x0bF\xf3\xae\x85,r\xee\xbeN\x83\xe2(\xbc\xc2\xc5P(\x19\xe4\xd2Qk\\ \xdc\xdf\x1f*Y\n\xc7\x14\xac\xe3\xe7Y\x84Z\x9f\x9f\xd4+7 j\x81\x1c\x05\x8fA\xed\xd4Z\xd9\xe1\xa0\xacI\xe1\xd7\xf7\xee\xbc\x9cg\x86S\xea\xba\xc7E"\x9c\x96\x016\x8e\x1a\xff\xd5\xb9\xaf\x16\xf9\xa3\x95\xc1\x9c\xa4\x8d\x18h$&\xd1~(\xc2\xd2\x0b\x0eG\xea\xfdb\xa3\xe8\x96U<:Sf\x19(\x07\xdd5e\xfc\xba\xf2\x10\x98R\xc6f\xae!\xfc\xc9l\x1ej\x02{\x01q\xe1a\n\x14\xbdA\xf8\x82\xef\xb1\xdf\x88K\x89F+2\xaf\x85\xea:\x85C\xb1\x83\xf2\x85`\xe2<\xbc\xeb\xd8\xcf\xc6W\x13\x030\x0cX\x85\xdc\x0c\x98\xd8\xea\xc8\xbc\xd4v\x8c\xf0\x06\x10eO}D:m\x18\xaf\x95\'/\x1f\x18\x14\'\xb3\xa7n\xc9\xd6_~+&RF\x0f\x95\xbb\x06m\xa0\x92\x13\xb9.2\x7fLFi\x06\xb1\x88\x8cda\xd8\x07\x82\xde\xcc\xaeE\x0c\x8d\xd1R\x80U\x95\x90\xe66\x0f-\xba\x13w\x95\x16\x10\xdb\xc7\xedK\x12,j\x05\xc5\xd0u\x16dS)D\xf7dtX\xc2\xeb\x8aQ\xe2U"\x111\x0f\xa6\xde}\xfb.d\x91\x94\x96\x1c\xbd%j\x02{y40\xfb$\xba2\xf3\xc2V\xc6\x93i6\xc6\xec\x14\x126\xcb\xe0\xe3\xfd\xb3l\x87t\xa9\x8c\x95\x8c\xddi6\xc8\xea{n\xce#\xa7\xd0\xb2\x811\x03\xd3]\xc6ZNz3\x150\xba\xef\xea\x9c\'(\xd4\xa6\x81q%\xc4\xcc\x9f\x194\xael8`\xee\x9c;\xa1\xadOK\'\xd6\xcf\x95jl\xd8e\xd5&\x9bv]\xfeM@S/:^P\x8fZ\xc1\xe2\xc1\xd7\x857#\xf5\xab\xe9<n\xae q\xfe\x92\xa0\x81\x9e\xa8EX\x83\xb5\xf9mA\xe0\x1a}\x9eUB\xe6\'\x80n\xd2\xbd\xe6\xcfC\xa2\xe8\xda;\x05\xdc\xec\x81;\xc1/\x91\xa1n\x14!\xdf\xce\x084\xc1\xe4\x8bZW\x0b\xae\xb4\xac\xc3\x8e\xa8j\x0b\xadVg79\x1b\x19\x1cF\xf5\x08\x8b<\\zh\x05Y6\x9b0\xac\x94=\x92\xed1]\xdf\xee)\x10VG\xe6N\xf4\x85\xaeE\x93\xd0\xa6\x9bu\xfd\x9ea\xb0\x14\xf5\\\x9d\xd6\xb3{\x7f\xb6S\x91\x11\xe7\x1e\x96\x9f?\xa3\xa7\xa2\xd6\xdf\x1f\xbaam$\x9aq=\xddt1aP\\\xbe\x9c\xa4\xe8\x10\xbd\xc3&\xa0\xbfyQI\xa2\x98\xdd\x0fF\x8d7\xc4\xa1j\xa1x\xc6\xcb\xca\x94\xf1\n\nK\xf7\xa7\xe2\xf9\xc8\x1d\x8e\xbcY1\x9bb\x84\xb67\xd6\xdd\xf6[*E\xc48C\x11\x02\xe0\xaa\x9c\x00#\xf4\x9c\x8ef\x93!h\x0fJ\xc9P%\x87\xaf@G\xaaB\xba\xc4\xcf\xfe\x1f\x11%\xc1\x03E\xdai\xa5`\xc1\xef\xaf\xea\x02Y\x9a\xe0B\x1fw_\x13VC\xeb>0\x99(\xfe\xd1Vl\xf8\x87s\x1ai\x92:\xee\xe2\xe6\xc2qj\xcd\xb9|\xf1 \n;\xe6K\x1c\xba\xf9\xf7\x1d\xf9\xae\xeb\x93\x9b\xa4\xbbf\x8a\xef[]j4\xee\xa2\xf56G\x96W\xb7d\x19\xf4\xa0\xd5\x8a\xa3\xd0\xc4^\x95$\xad\x1dE\x94\xd2\x1f\xa8\'\x05\xbdk\xff\x18\xdb\xbd<\xef\xb1v5\xfc\xac"n\xf3\xba\x9b\xd9\x17N\x95Dt\xb0\xd2\x9a\x0b\xb0j\xe307\x88\xa9*\xd4\x0c$\xdds!\xd5\xd1\xccpfqq\x82\x98I\xf9\t\xda\xe3\x19\xc9m\x91&A\xe7\x89\xb8\xea,Lw\t\xe6\x87n\xd83Q\xa0R\x86\xf2/\xe0j=\xf8n\x1d_3\xd3\x18,\xaeY!\xf2\xf8 \xa2A\xfbQ>\xa4U\x8c\x12R\x81\xfd\x92T\x92/\x88N\xfa\n\xe1\x9csw-\x0c\xa7\xb1_vh\x0b\xa1\xb6{\xeb\xd0\x18\x8d\xc2\xb1Y\xa1u\xda\xf2\x9b-\x19\x10eS\x99\xd7\x0b~\xadmMIJ\xf8\xeei\xf8\x8e\xc6)\xc9\x88\x9e,\x0e\xf7E_d=\xb8\xc1\xb4\x12QD\xfa\x9b\xd3\x19\xb8\xa5#\xa4\xe3\n\xa1cV\x02\xf4\xa6^\xc8BF\xbd \xad\xb3\xd6BW\n\x89\xfa\xd7\x84\x02]KC\x04LR$Z\xd2e\x16i\x97\xed&\xa4\x90"\x98\x91\xd1e\x0b\xbc&:\x1b\x0e\xc6\xc5\xb0\xcfa\xfc\x83\xe1\x1f\x1ds\x1f0\x1a\x07\x87\xcc\x97DX\x81p\xd7\x83\x0f\xff\xdf\xdc\xd9\xc1V\x90\xf6<\r\xd02\x1e\xdd\\\xa2p\xbb`v1\xc0W\x8e\xb5\xb5\xf4\xf3\xfaR\x02\x9c\x08{\xa9h\x1ch\xbeo\xce\xfd\xc7\xb6 \xfa\xa0\xe2\x02K_\xca\xd6\xae\xff\xc9\x98@\x8f\x88\xd3e\xff\xe9%r\xf4\xcb_\xffi\xa38\tv\xe6\xed\xac\xee\xc7\xad\xce\xe1\xf8\x85\xf7\xd4\xa8\x08Xb\xe5\x1ey~\x95n,o\x95mT\x8b\x91\x0e\t\xd4\xbf\x1a\xd3\x8f0\xde\xf0\x99\xd8l\xfd\xe8\x04\xbdP\xf4\xccw\xa3(\x96\x16\xfeH|\xf3\x85?\xcaw\x02\xb4\xb4\xac\x9er\xb5X\xe5\xe8\n\x88\x11\x9b1A.\xde\x98\x88\nK8\x1c7\x0el\x0c\x16n\xc9+W7\xf3\xacK\x06T\'\x1a0\xe1(\xce\xcc\x80F9\xd0\xa3Tp\x178vl\xe5ow\xa3\x9e\xe5eW\x19\x07\x93y\x88\xab\xc5\xc2\xd6\x8cG@\x9e$\x07\xa9P\x17\xe9@\x81b\x1b\'9\xf1\x0e\xdaZ$\xa0\x9f\xc5\x03\xec\xcb\xc0\xe4u[d\x82\xee\xde\x96\xe6jRD_\xa9\x89Va2C\xfc\xb5\x04\xc0\xebt9%\xe2\x01!\x9c6\x84\xd9\x92\x02\x8d\xd6\xe6lso\xd9\x1b\xe6T\x90\x8fc\x0eyb/}\x00\xe8YC\xfeHI*f=H\x81v\xdf\x0e\xe2\xfdwc^|U\x1a\xf2\xb4y\x9bi\x16\xd6\xb4!\'\x01s(\x1b\x9a\xf4D:.\x96%\x13Ku\xf4\xa1\xfe\x03\x90\x1b\x895\x9dW$\xf5\xb1\x81+)ko^r\x16\x9c;MW;X\xdc\x02_\xbeyk5\xff\xef+\xf8\x19w\xbd\xebl\xc2\xc2Pr8Q\xcel\xc1pbd\xf8\x88\xde&6\xd9=2\xd1\xb7J>`\x1b\xab\x157\xd0\xec\xc1\x97p\x0cy\x1c\xc8\xe4?\x0f\x99\xaf\x14\xef\xb3o\r\xa3\xcaI\xa7#\x0f\xf6%\xa4\x87\xbc\xa5\x8c7[\x18R\x9f\xf1j\xba\x94\xf3\xa8\xaa\x10(;\xe5\xcf\xaa\xf9\xd9\xaa\x0f\\\xc8\xfe\th\xc8\x1c\x1f=\xfc\xfd~#w\x80\x13\xc8q\xc4\xf0UE\x1e\xad\xc1\x8b\x863\x98\x96\xf4\xac\xcc\xfd\xeex\xba\xad8\xa4\xbaIkR<\xb9\x7f\xf0\x93\xf3\xc8\x8c$\xd2O\x05\xf7J\xbeW\xe5\x97|\x89r\xbc\xae\xfa\x06\xc0\xa9\x1a;\x96\x9b?\xa5\xdc~\x1e\x99\x9e{\xf8\x0b\xe0"\x05\xd1@o\xea}\x1c\xb7$RU\x02\xb9\xa2\x9a\xce\xb6\xb3\x07/\xa4\xc8S%g\x98\xe4d\xa7L(J\xbe\xbc\n\x0eE\x19MD\x01\x88p\x937\x82}\xc3:}\xed\xb4\x14|\xe5q\xa00F\xbd@\x8c\x12L\x9e\xb1xQ\xdbO\xbc\xd0\xfa\xaf\x9b\xc9\xc0\xa5M\xbe\xaflZ\x9b\x92\xbf^\xe9FR\x9b\xa5\xe5\xbd\x0bj\xd01?Q\x0e\x832\xa6tJ\xd0\xa2\x15}\xf7\xb0GP\x9c\xb1\xe9\xfd\xfe\xad!\x8fSc5A\xaam\xd1\x1b\x805\x01\xf4\xfe\xc1\xe8\xd0\x94\x10\x00\x1eFM\xee!\xdf\xa4\xf8\xb8\xc7\x07\xac\xfd\xf4t\xe5\xbe\xd2\xe3k\xa6\xfa\xc0a\xab\xf0\xb8\xe0\xd6\xd1\xb0qv\xce1\x1c\xb2]b\xda/ub\x96\xda\xd6\xbfG\xe3R\x82\xbc6\xc8\x8e\x18i\x98\xd5\xd7S9\xe8\xed\x889kre\xe8\x03\\u\x14/\x12C\xa6t\x11\xd0\x8e\xd4\xf8\\\xc9\xb6\xcd\xe6\x90\xe3\xef\xf6\xbe\x98"\xf6\xca!\x89Y\x1d\x8d\x19\xbd\xe6e>\xfa\xe7\xc8S\xfc\xcbY\x935r}5@\x05\xc8\xf8\xae%\xcc\n/-\xc01\x8b:\x17\xe0\'U\x10=o\x98"\x10o\x05\\\xdct\xe0\x9e\xd8\x91h\x91\xbe/\xeepe\xca\xf1uC\x10\xb0\x02\x14\xe1Q\x14\xdf\xcc\xc7\x1e:\xe0U\x9b\xed0\xd1\xd4\xe3\xf5B\x06\xf0\x16\x94N\xa7\xf9\xfcb\x0e\x90]\xb1$\xbcu\x11af\x9c9\xd5w\xad\x17@\xd2\xa3\xefW\xb5Y0\x16\xbf6[\xa8\xdb\x87\x91\xa8\x9b\xee\xc7\x1e\xa1\x8d!#F\x9a\x9b\xdf\xf7 \x93<5\'U\xe1\xc0\xf6\xc5\x02\x88y{\x02\x9a\x93\xe2\xe7V\x05\xc9\xd6i\x8b\xe1\xd9\x88\x0be\xccBv\x9d`\x8e\x7f5J\x03\x96nl\xc7\xd5\x7f\x1dh\xb9\xdf\xf7\xce\x0b\xd3}\x03G\x9f?l >\x9b\x16\xb3\'P\x97a\xfc\t5\xe6tA"\x98\xa4\x86\xe7wAm1\xe8u\x15\xe0}\x1eo\xf8\x03v\x8ez\xfb\xba\xecM\xca\x08\x86XU\xc7\x05\xa4L\x11\x99F\xc2t`\x1cu\x91fnU_|\x83Om\xba\x9b\xb5/%-\xfc\xecB\xd5>\x86\xa70\xcdw:\xbeGkNk\x02\xa5\x9dx\x9e\x8a\xdf\xa8\x91\xd5\xae?\xdd\xb1\xb7iny\x96"\x99s\xb1\x0e\x0c\x80\xb5\x94\x85}j\x91\xe4A\xeb\xb8\xd7\x07%M\x8dc\xe93\x97|\xec\xd5\xf4\x15\xfdx(\xe8\x04\x08\xb2\x94\xfe\xc9\xc2p10\xfeY\t$N(\xa4\xf1\x9dkpgs9c\xcbZ\x81\xa9\xc0F=W\xf1C&bF\xc0\x88\xa4\x80c\x82ls\x1bl\xc2d\x08u\x0e\xe9LBI\xbc\x9ec\x9dB\x1e\xa3\xc8\xafrM\xe2j|\xdc\x10\x96\x0e\xbb,D]a%?\xe8\x06\xbf\x06~AJ\x00\xb9\x01\xbe\xe6\xa5&v\xd5\x92\'\xba*\xc3\x884-\t]\xfe\x15)R\x90\x9b6#\x9d\xcb7\x08\x80\x9d\xbe\xfb\xe9R\xc3X\xc2\x88^`\xb2\x87\xf7_L\xff\xd4\xf3P\x14\x8a\xf1\xb9*<\xf7\xdfyR=\xe39]\xc1\xfbI\xbf\xa7\xb9\x05\xbf\x19\x10\xaa\x1az\xb8K2\x9f\xde\x00\x8d\xe5\xa5\xc7\x8bE\xa8\xd3\x80=M\xa2\xd5={\x9b%\xff\xd6\x14\xd9a\x19iSxXT4\xd1O\x91U\\8\x82\x934\xc5\x8e\xcaU\xca\xd5Sh\x9eT\x13\x99Br\x1c\xa8\xe2\xe1\x18\x02\xf2\x97)\xf7-zL\x97 \xcds\x17*\x8f\xb8N\xaa\xd0g\x92\x1b\x0c\x02<i\xe8\xdf\x95\xe7C\xd6\x81\xd4\x90\xca\xd1\xbc^K9\xddh\x08\x96EY{\xc4\x0c\xae\xb26\\\xb5\x08\x92\x07\x19\x93l\xe6FQ\x06\x1fd\xb8\xb9\xe3`\xc8\xad\xea";\x87&\xa6l\x85\xec\x91\xbd\xf1\xc1\x86\x92\xc6\xd38\x91o\xe69\xb4\xbc\xd7\xb2\xe5)\x00\xa5\xa5X\x19\x94\xc0\nV\'afTa\xc4\x87R\xd9ox\x9f\xa9\xbf\t%\x94\x0f\xcfb\xae|\xf5U\xef\xe2\x1d\xa4y\xf9V\x92\xecm\xbeJ\xb6I5]e]!\xd5\xf7t\xbc\xb9\xe0SU\xf0\xf8\xb8\xd6$HG\x99\xac\xb2\x00\x1ee\x1e\x15\xa17\x95\x9e\nn\x93\x1b\xf9@\xfd\xf2\xf3\xf2\xc9\x9b\x8a\xea\x90\xaf\x12D\xa8\xa2\xdc&mue\xfa\r\x86\xf4\x8d\x19\x1f\xb8\x15\x94n\xb8\xa9\xb4\xa0\xb6\xd3|\xa3\x19\x9dp\x01.1g)\xdd\x16?u\x98\xa9\x83\xd3\xad\x81\xe1Xz\xa6\x13\x1f>\x9cU\xd7\x18\xfe\n\xb55M\xa5\x1c\x15}w)S\x16\xfe\xa0\xf8c)\t\x05av2\xe3\x1e\xb8\xd7\xc6|\x118\xd3t{v"\x8fR\x9dP\x0f\xe4\x8eE}\xe4\xc6\xad\x06\x1d\xc0\'1\xf1\xbcn\x1f\x80\x19v\x836\xe9/$\xe7^\xf2\xd1v\xfcl\x0e\xdf\xc5\xe1XMi\xc2kv\xa6F\xef\xde\x15 \xaf\x146gf$A\x0bI\xdc\xf7\x84\xa6N\x06j\x90\xc5\x96\x8a\xfb\x9b\x8e\x12\xcf\\6hf~\t\\\rAq\xd9\'\xfc\x05\xb8\xfa\x19\x1d\xbfy\xdazb\xa1\x04\x05\x1a\xb5\xfb#\xf2\xf09+\x93XB"\xd9\xb4=7\xad\xa9\x8cgd@\xf3/V\xbd*\xc0\x0e\xafY\xe9\xbc\x1dX\xe9X\'\x9a*\xf4\x81\x8d\xcf\x11\xdf\xe3K\x05\x0e\xe2\xe60\x8aV\xf7\xc4Z\xbdQ\x0e\xc8\xa1?\xc7X0\xa0\n\xc8w\xd5\xb01\xa3\'\xf9)\x90\x92\xde\xfa>\xd8\xbd\x16\xc2\xfa^\x90cv\x8c\x91\xffV{\xbc\x04B\xfe\xa7\x00QJ\xb1\xd4h\x8c\xda\x15\xb9\xaa\xa8<H\x1d\xa6\x82yU\xe9\xb3\x7f\'\xce\x0c\xee2\xdd7\n\xa0\xfd\xf7[\xb5\xdf\xf5\xcfTVY\xebE\xdd\x83Q`!\xe92\xce\xc2"\xae\x1e\xc1\x88\xce<\x10\r*\xbe]\xd9DS\x9d!g\x80\x1ea\x92\x8f{\xa1\xefJ\x08\x0e6\xd8\xea\x9c&"\xc3R\xa8\xa8\xfd5\xa1\xbc8\xac;\x8a\xdf\\8\xd7\x96b\x87\n\xceJAe\x9fU\x80Y\x12\xafXg\xa1\xdd\xd0\x8b\x94\x8d\xc6_yR\xd7\x0b\xcdjS7\xa1F\r\xeca\xe7^\xd7?\x81\xc5\xbf\xc7\xea2\x92dD\x02\x1a\xb2\xf1\xfd$\x94F\x89\xd6\xc3N\x1c\xfe6\xd8\xd2!\xfc\x0c\xc4\x97\xdb\x1c\xae\x86\x01g\xf6\xd1\x8f\x99YH\x9b\x86*\x9d\x16\xa7|&\xb7Y\xa6\xd4\xdf\x8a\xad\x9e\x81i=\x96\x03Kf$\xeb\xf1=\x14fX\xb3R\xd3\x92\xbc]2\xe1\xa2\x03K\xb5\x8e\xfbT\xec\xae\x85=\x84\xb7\x1do\xc9\x9b3JT\xbfz\x96\\~\x9fS\xd9\xb7p6\xe2\x1f\x16\xf8\xa6%\xd7>\x0b\xa1\xa7=4{\x19+\xf0GLM\xae\xe6\xfc\xf5\xe4\x9cVsz9D%\xfb2P \xd0\xc5\xa2@#=\xa1\x85+\xc5_\xb5u\x08Ze\xc9$\x80\xef\xd2\x9a[\x9ezb\xfd\xef\x12#Z><\xa3\xc0/\xa5\xee\x95b<\x8b\x8e\xd6\x0f\x18\x0b\x90\xa8Q\t\xc0h\xd8\x81\x82\xb1\xa7\xc7\xc8i\x82!)n\x1c\xa9`\xe4D\xf2\x7f|\x1b\x9f\x97\x0e*\xb0;\xc6\xd6\xdc\xc9\xd3O\xb4\x03\xc2\x80\x99\xf5m5\xf0\xe7\x87\x11mQy^%\x11\x11\xe2\xd1\xcc\xfcc\xa17\xbe`\x83z\x13+pY\xfa\xf9\xef\xa7\x1d\xd2?\x811N\xf7\xe9\xf8\x8cM\xb0O4\xce\xce)_\x1d.\xdcV\xbb\x82\xa7\xe8\\\x06\xc7\x1e;\xe5\xac`\xeaC\xbb\xe7\x04_\x90\xa4.x^-\xc2\xcfp\xf2\xba\x13\xcd\xe3F7@\xac\x9a\xa6k\x80\x0e\x8fm\xe0\x03\xc7\x8a\xbc\xfda>\x14q\xd5\x9a|\xf9lc\xd4\xaa\xba\x9c\x13\xab\n\xc3xQEP\x90\x05mC\xcb\xd1XP\x16r)KJB\x87\xbd}L\x04\xd75Kj\x1d\x07c\xf5D3D\x1bI6\xba%\xf1u\x0cv\xef,`\x89\x04\x1f\xd6\xf6 D\xa0:*&7b~F\r\xc3#a\xda\xae\xdb!\x92\x9f+\xda\x10\xeca}v\xc8\x85\xe8\x99ZH\xf9\x9f3\xa2\xa9\x9cQ\x12\xe9\x9dX6\xa0\x17D\x8f\xde\xf2T\x0co;Zn\x9c\x17\xacw\x1b\xa8\x82\xc1\tyD\x15%\xb3j\xec:\x0b}\x02\xf2\xfb\xc3t9\x05\xa7(\x98\x0b]\xc1C\xe5\x98\xd6|l%\xc1[n\xc4)t1\xa8\xac\xa4\x83\x1e\xc8\xb0\\\x89\xfa\xad.\x8c\xbe\n)h\x9d.\xb2\xbar*\x17\xdc\xd2\xd3\xe8p\x81\x99\xd4\x95_\xc4\xa2\xb1\xff\xd5Um{\x08/\x18C9\x9akm\xe2Ct\x83\xc3\xc5-i\x90\xa62\x00\xd1\x17\xcd\x18}\x8c\r#\xd0!\xc7\xc0W\xe7\xccg\x0f\x1eT\xf3\x17?\xffr_Q\xc7\x92\x08\x11\xfc\xa6\x1b&\xda\x87@\x1e\x0ec\xa7S\xd6\xb0\xe5\xbd\x1a\x07\xcfwX5\xd8\x8f2\t\x05qN7\x06\xb6\xcf\x87\xaf\'\xf5\x83\xfc\xe9M\xd76\xc9p\xff\xc9\xb1\xc3J\xc6\xe1\xfbBL\xbb\xb9\xc3%\xb2wu]\xcfh\x9cI\xf7\x1d`\xb71\xb7\xda\x98\xb0\x04\xa1\xea\x00\xe8\xb7h\x10\xcdw\xf1\xe8\xe8;z\xf7\xfa\xf3<C\xa3\x88\xe5\x7f!m\x17\xc3\x902\x92V\xe3T\xc3\xd3\xb7\xfd\x18\xeb\xc9\x85\x1b;\x81\xe1]\x0c\xde\xc3\xcdn\xcdA\x00}Cd@\xf6\x8e\xd0\xb7\xa0\xc6\x88\xa1\xfe\r\xe5k\'\x88\x81\x9dx\x97\x9b\xbf1\xb2\xf3\xc5-\x1a\xd1I\xd45v\xb5\x11&\xa0\xb7\xa4\xd71\x08\xe07\x1e\n\xe8\x17\xbc;\xbenO\x11D]\xa5\xb6\x971\xdcA\x95\x0f\x1aA\x17%sX\xfe\xfe\xe0\xf6G\xd8Gw\x0f/E\xeb@\r\xa06\xbc\x94\xa2\xac\x11J<\x86,\xbc>\x84\xba\x9f\xa0\xf5\x92\x87\xf6\xf4\x1f`\rIy m?#\x1dXzt\xefAz\xb4\xa6\xe1\xf0[W:\xe8Q\xca\x0bK5t\xf0\x06\xdb\xb8w\xad+\x8c\xaa\x96c\'\xb5\xce\xa9/\xc8Q\x8c\xa8\xa2\xd4a\xf9\x1a\xe4\xbc\xe7\x1f\xae \xcb\x0c\xd2\x8f\x9b\xbc\xe2PHx\xe7~\x82\xe2[\xe8\xee\xb2\x80l\xddJ/J\xc2\x96\xd1:\xb6r\x05g\x94\xd2X,\xddP\x89U\xdb(\xdb\x7f\xf4\xb1\x8b\xcfY\n\xdf\xd8\xb7\xf1\x1c\x00\xa4\x0b3\x12\xfc\x14p\xd2\xe5G\xcd3\xdd\xf09r\xa07\x80\xeeJ\xf8\xa6K\xbc\xb3\xa5\x1d8\xc2\xbf\xec\xec\xf9Ho\xc4\x00\xd4\x83^\xf4\xc7\xb0Zq\xd5Vr\x18\xa0\x85E\x07!\xc2\xa7\xae\xdd\xd3j\xe7?\x07\xab\xd7P\x03\x84H1\xffT\xc4\xc5\x13\xb6j\x82\x7fu\xd7\xd7.n\\+ZA\x1d\'\xb5\x97\x9f\xbb\xa8\x81& \x84\xd6\xc9$\xd0\xdc\xd6\x9d\xbb\xb6\x13\xcc\xc0\x16\xfb\x07\xdc\xa3\xa9\xbe1\xa00\xe7\x1b\xd2\xfe{\xf7\x8b\x9e\xa2\x9b\xc3]\x07\x86\xba\xbb\x89\xa9\xf9\xfa:\xa0\xc0\xf2\xe9\x1c8t\xc7[\xddF6\xe2s\xf0\x05\xed\'z;\xb8P\xc3\x9dtX\xe5\xe6\xd2]\x8c\\\xc5\x06\x05p\xe8\xaa\x0e+\xbe\xce\xef\xf1\x97\x0f\xf2$\x12&y\x84\t\x9fxZL\xdd\x8a*\xa8-\x066x\t\xc8L\xcd\n\xde-\x03\x84S\xf5[Wh\xcb\xbf\x96"\x19-8\xe7\xd8\xccn\xc8v\xc2\xe8m\xd9\xf1\xce\xc1\xd5\x08\x9fl\xdf\xde\x1b\xdaM-\xe6\xc9\x8e\xd9\xef.6\x86\x87\x9c\xbaH\xae\x08\x99^\x1fI3\xb0\x05_#EDOJ\xf4\xa4\x14\xc1\xfe\x9e*7\x19)\xed\x19p\x9e\xb5\xf2\x96\xbe\xe6\x1a\xf8\xa1\xbd\x15q\x95\x98\xb2C\xf0\xb8G\xdc=\xa2\x15\x8a\xafZ\xcc\xe0q\x98\xe2\xea9v\xe5_N\xe70g\x1d\xe03\xa5\xfe*\x01\xff\x1e_&\xdfq\xe1\xec~\xaa\x16\xb1\t\x94\x19\xf67\xae+\xe7\xd6\xa9\xa0T\xdc\xeew\x8a8\xc2\xc8\xcc\xc6W\xc7q\xbcb\xfc\x10\n\xc9}\r\xe7\xdf\xf5rcv\x12\x8b%\xc3_\xf0\x17K\xf5\x19\x187\xcaYO/a4\x04q1\xb4?X\xab\xd4+\xd0\xea\x9ci\x10\xferR\n\xdb)\x1cP\tZ\xe4q%)<\xa1g\xe5\x9b;\x84\xad\x84\x13i>\xa2l\x16m\x9d\x00\x8e\xf9\x0e[2]J\xfc\xc0\xa8\x1c/\xb5m\xb5\xd31\xf6\x1f\xa3\xe1\xc9\xd3XZ%\xb1\xf9\xc6X\x94\xa3\xa3\x11\x01n!Z\x0bA\x89\xbc\xc3\xe5\xa7 \xda\x90.q8(\x1b\xa9s\x1a~\xcc3\x95a\r\xde\xb2_\xdc\xa35^2}R\'\x0e$\xe0\x87e9\xac\xe8+\x1b/z.)\x93\xdd\xe0X\xc1Z\x93bW\x0f\xa7mQ\xf0\x1d\xb9J\xe6\x91\x800\xb2l\xb9NBG\t\xf5\x12\xd2\x82"XT\x88{\x91a\xc0\xef+VF\x15N\xecR\x8a\xc5"j\xc9\xe7:\x12\xe2\x9b\x07\xc6MsK\xd1>\x1c+\xde\x05o_\x14\x06\x02\xf9\xc4=\xd4\x82D\xfck\x18\xbc\x85\x15\xfd"\x06\x890\x92?f\x02\x86\x15\x90\x1amu\xe5I\xecN\xddwy\x8b\xbd\n+\xda\xecH\xff\xa2\x86\x8cW\x08\xe5\x1bM\x81\xff@\xb3\xa4\xe6\x05\x0b|[\xe8,\xbb\t\xe0\x8a`3N\xf1\x86\x97F\xdc\xac\x17\xc1\x0fg}\xd5\xd3\xc7\xe6)\xc0<[\xab\xfe\xa5\x95}\xfb\xf2t\x16\xb1\t\x89s8.\xac\xebt\n%\xf0<\xfec.U\'\xa3\xf2,\xe2\xed\xf3\x11\xb4\x03\xe9\x81Y\x9ef\xc9\xfd\xa9\x06\x8a\xd2c\x07\'a\xd3\'\x88\xf2\xe1\x8cD\x166A\x13h\x1a0P\xf0+\xdc\nV\\\x96\xaf\x02\xbc\xe4\x90IDj3\xd541+@\xba;t\x1f\x86\x88\x9clK\x04\xaf\x89\xba\xd2MB\xfb\xc7`6\xae\xedT\xcc\xcc\xc2x\xf0\x84\xea\xd2\xd7\xe0C\x1e{\xc5\xf9\xb3+\x96S\xd4\xb8\xf5\x1c\xae[\xd22\xb2\x19\xf5\xd0z7\xc3\x11\xd0G\xe1\x1eL7l.\xd4#):\xef\x89\xda\x87?V}\x83\xfe\x82\x98$\x03\xaf13\x906\xefn\xd3\x88\x95!\x13\xbc\xa1\xab\x81\x9a\t\xc5`n\xab\xf2\x87IqJ\xf5\x076\xf9\xd0\xc3B\x1fE8\x95\xfd\xc0\\\xcd\x93\xe2\x08\'J\xcd\x13\tG\r\x1eh\x9a\x1e\xfa*\x908vS\xdbOde?:\x00\xb8\xd5\x80\xb9\xdf\xd3GP\xeb\x88{J\x82\t\xa8\x91`s\xcb\xd2\xf7\x8b\x8f\x83^1\xa9\xaa\xff\xb0NS\x8b\x9f\xbe\x90\xf0\xe6\xc2\xee[\xd1\xcd\xb8\x06\xe3MF5t/\n\xb3\xab\xfct\xd29BX\xce\x7f\x10y^\xfc5+o\xe7\xa3\xb2\x06\xc8E\xf0\x99\xaa\xf1|aKsQ\xb2\x9bm\x82\xf3\xdc\xb3Z;\xfe"\xed\x12.\xd5\xf2\xed\x81\xbbd\x1e\x98\x11\x8bx\xfa\xc2\x04\xb8\xb2;\x8db\x8f\x7f\x868\x01(g\xc3)\x95\x02a\xcc\x97^\xe1\xbb\xf7\xce\xaf)\xb7\x04\x8f\xcaa\x06\xfb\x89\xe8\x873]Hw)4\xcc\x7f\t4\x1aA\xd5:7R\x1eK\xa5|\x980\xbc\xa1\xb3Ze\xa7_\x80\xe5+(\xbd\xe5;\x0e\x00\x89\x00\x82\x19z\x8a\x01\xc3\xcd\x02\n\xde\x9f\xc1\xe3\xfa ni\x84\x89\x08\xe5\xc3\xbaPt]\x1eY|\x8ek\xdd\x08\xfb\x89\xa1\xba\x0f\x1e\xe8\xd5\xbd\x9c\x1f\xfa\x17\x13Gl\xb8n\xde\xa1\xbd9\n\xcf\xd3\x84\xb4t\xb5\nZ\x04d\xedz\xb6\x7fI\x83o\xf7\xdd\x1f(\x07\xea\xe9\xf9\x18\xe6\x0e\x13\xcd\xb9}\xf0\x7f\xfe\x16\x1a\x17\xd6\xa7\xaaTg\x95^\x10\x10#\xda\xf9\xd9\x1ed\x11\xc8\x9bg\xa2\xbe\x9fF\xda\x84\xb4\xb5\xaf\x99\xea\xecJ\x83\x82\x95x\xcc\xd2i\x03\xbc\x1eY\xb0\xd8\xc6\xec|L+|\xd8\xa9\x1b\xcd\xef\x97/\xd0RYbXs?\xb3\xcc%\x93\xd6P\xbf\xac9\x07\xed@>\xdd\x93\xf2\xf1\x10\x90\x15}\x82\xb0`\x8e\x1eG\xba\xd7V\xb8\x9a*b\xa4/\x91\xca\xbc\xb84_!\x8eF\xcdK\xd7\xf2M\xd0\x04o#\x96\xaf\xeb\xad\x9b\xf6\x0b"\xf2\xf4\xc0\x0c\x81\x16\xce\x94\xa3\xf9#\xcfd\xd1\x0b\xf5s\xeb\x05\x12\x08C\xf5H\x85}\xab_\xcey\x98\xfc\x807\xdbCW\xb2\x00t\xcd\xd4\x1a\xc5b\\\x81(\xf2U\xae\x930\x18/[\x05\x9e\xb9\x9b\xf1W\xc4/\xe2\xb8\xaa"\xbbK\xfa\xfe\x1a\xefBr+\xb6\xa1A\xf4\x8e\x8b,\xd2\x9f\x81\x8eb\xc1\xe7.\xd7\x93rg\xb7\xe13\xe34\xdc\xc0\xb6\xddO\x1e3\x07}\xd9\x10\x8bnt:\x16\x05\x1d\xaa\xb9x\xaf\xe3\x1a\'\x02\xafC90\xba\n\xe3\x0fV\xb1s\x8cP\xa5\xc4\xe4\'\xa3EO\xcd\xc7\xedU){S\xa7\xd4\x7f\x9d.a\xc4V\xb9\xc8f\x9a\xabW-\x95D\x8f\xdaBD\xa6X\x19\x03\x98g9`\xdb \xa8\x14\xb6\xb8\x91\xd9\x17\xff\x89\x0e\x98v\xb4A1\x1eP\x82\x90\xbfo\xcb7\xa0`v]W\x88z\x80\xc9\xef2\x05\xfe,D\xef\x82\x8f\x01\xea\\\x08\x1cF\xef\xee\x12NR*\x14:\x04<[a\xe0N\xb4\xb8W\xfc\xfa\xe3\xb6\xe2\x99\x9b\x1b\xb3\xdc\xe7t\xb0\xf0\x96\x8c\\\xbf\xc4\xf8\x85\xeb\xbf\xeb\x96\xdc\xb2\x13u\xb5\x94\x9d\x12\xb4\x02\xaap\xc5\xf2\x9d\x99G\xca[\xbe>\xfe\x92Q\xf3\x93\xa9\x8a\x90P\xd5\xa8\xb4\xcd\x8c\x8a\xcc\xfe\x07\xf4\x8d\x9e{\x06\x13\xa9\xd7)\xa9\x89\xc3\xce\xccW\x99\xc1\xad1\xba\n\xfb\x8b\x01\xf0\xe8:\xca\xba\x8b\xda\x1f\x93\x0c\x17\xc2\x8fs\x96v\xab\x1e\tG{\xc4kwp\x0b\xb53\xa5\xd9\xdes\xf8\xd8S\x92\x8e\xf9\xf3\xc4O\xe5\x1d\x8c\xf5u\xd8\xc2\xce\xb6\n\xdd\xae\x91\xa1,4\xe8p\xf03u3+h\xb4l\x99\xfdQ:Y\x8bje9?\xcb\xe3!\x85\xbah\x00\x02\x10\xba6[\x04\xa8\xd1n\x0b\xc0E\x94C&y\xb2\x88T\xe3\xbd\xbb\xa7%\x03\x0c3\xcf\xa1xA\xb4*y\x88E\xa1\xebA\xa9F+\xf4\x1cO,\xc0\xccfs\x9aw\x97\xb7\xe2\xde\x85nG\x9f|\x1eQE\t"\x01)\xf8O(\x04`LK\xaf\x8c\x04{\x01\xac\'M\xfb\xbd\xa9Qjn\xf8\xd2\xeb\xefp\xa2\xe6\x10\xcf"\xcd\xc2i+gd\x0fP\x8dBQ\xd1\xd2\x92\'\x98\x9bEWY\xcd\x9b\xed|\xb2L4m\xa8\x05\xd8\xb9\xe6\x17\xcb\xe8\\\x87\x8eR\x8b\x1c\xb2\x1f\xc5\x85\xe7\xdeB7\x895\x8ct\x07X,\xfb\xa2?o\x0c]]&j`\x0cp>\x0b5\x96\x88\x1d\xc3\xc9Z(R \xa5\xe7\xa7-~\xcd\xab\xe8\n\xd5\xa2(\x00\x91Bx\x88\'En6\xe4\xf0Jb]\xa9<|r\xf3\xd5\x9f\xb6b\xf4H*\xeab\x88f\xf0\xd1wB$\xed!\x1e\xd1\x80Pr\xb2/\x01\x1b\xaa\xf36\x84\xe3\xcd6\xe6\x96\xcf\x81\x10\xa2f0O\xa3\xa3\xc8\xb0~\xda\xb6\x90`\xe7\xcd\xddCx\xf0p]\xd3\x1c\x06\xfaP\xf4\x84\x9c\xcd^}\x14\x04\x17\xbfdQ@UT\x07\xc9s\x15\x90\x89\x8a\xf2\x84\x9f-\xd8\x86"\x182\x81v\x0bu\x10\xfc\xdb\x88\x87\x04q\x82)\x03\xa4\xb9\xdeq\xf5\xda\xddP\xee\xf4\xf5\xcf\x1a\xce\x8b\xdf\xc2\xeb\xc2S\\\x98\xf4\xfe{\xa4\x9fj\x19\xac\xe4\x82\xb5M\x82\x0f\xf4\xe2vQ\xff\xae48}P\xb8k\x97\x0c_\xee\xadb\xb9@KG\xa5\x0b3\xd6\x16\xc3\ni{&\xe8\xf3\xb1\xe6\x9bk\xa4\xc3\xac\xd3\x00\x8dL\x87\xaf\xda=\xc4v\xc1\x1b\xcd\x81\x8aY\x9ew\x9f\xf0[z\xd6\x98\x14\x86\xcfV\x83\xf42]\xc4E]J\x00\xeaL\xb5\x89$\xa4v\x80)!/c\xbb\xb9\x8a\'\xba3\x88-\xf9\x90c\x00t\xa2\xe0\x14n\x96\x01\x88\xea)!\xc1\x89O\x87\x14$I\xc8\xbf\xb3\x9e\x00P4\xb7P\x0e\x89+\xa32#\xc5\x18\x90\xb1\xef\xb4u\xf3\\3\xe9\xa2\x98\x85\xbbf\x86]~o\x0bg\x9a6\xf4\x87\xabq\xe9\x02\xdd\x18\xb4J\xddK\xfb\xecg\xbcX\xc1&\xce-6\xef1\xe3\xbe\x92\xee\xcf\x15\x9f\x96\xc1\x1e\xd4\xa1XFt\x0b\xff\x81\xbf\xd5"&\xb3\xbe\xed\xb0\x0e\x89\xee\xb8\xf3,\x92R\x94X8\xeb\x9b\xd3\x8bA\xed\xed*\xddGu\xf6\xba"\\\x93\xc6\xbd\xa4\xe5\xb9^\xac~\\\xceM\xb5\x14]\x0eM5\xc0\x91\xc7?\xd2\xbd\xee\xdc\xb6A\x9e\x0c\xc8\x9f#\x17Pe\x1aQ\xd4H\x1c3\x83\x19)!Yu\xd9\x9b\xd1Y\xa9\xfd\xc95\xcf\xdb\xb2tr\x19\xdbL\xf6\xfez\xa0\x96{\x9ci5\xca\xc7)\xec\xd9\xb0S\xd80\x84X\xbe1\xd2\x8em\xd6Q\xbc\xf9olk8\x11{\x15\xf74Hn\x00\x13r\x8d\x7fjz\x86\xf2\\\x16\xbc\x84\xee\xe4\x9b\xba0\xb9\x1cqQ.{\n\xda\x13u\x8a\r\x1fMl8\x99+\xf5q\nfNqAe\xfe\x03{n\x96\xb8Wr\x1d\x12d\x12\xa3@,\xdf\xa39\x97\\\xe9S/L4X\xe9N8x3\xcc\xf7\xd2p\xea\x17\xaf\'\xea\xd9\xad(/\x0e\xf76\x10Q\xcb\n\x89g\xcel\x0c\xf0\x95\xa2\xeb\xee\xa0X\x84\xa6Yk\xe0\xc8\x18\xd0[\x87\x07\xf0\xc3\x0e\xff7pw\x13O\xfc?\x1eBF\xcc\x19;\xd3\xf8\xecL0\xc6\x8e\xc0)qL\xb0\x0b2>\x1e<\xf2\xfd4\x88hK\x11\xe2o\x0e\x04\x9e\xfe\x16\x8ch\xc2=\xb9(\x19exPP:\xc8"\x9c7\xa4yko\x1b4\xca\xc8 \xbf\xad\x84~h\xe7Y\xc4\xb1h\x196\x82j_\x18\xf2\xe30\xdb\xff m]\xdc\xa8\x08+q\xbf\xef\xed\x02=\xcd3\x9f\x81\x8c\xed\xdf.\xd4/v\xd9\x81X\xc0\x13p\xbcDQY\xd6\xb2\xab\x8b\xaf\xfaA\x02d\x92\xa6&\xc3\xf5|\xad\xc9\xae\xdb\xc3\x92\xf5\xd4<\x17\x80=\xec\xdcQMc\xd1M\x8b\xa4\xb0\xb4\xd0\xf4<\x18xd(\xbb^/\xeb\x92\x07\xad\x86\xc8\xd1zGLf\xba\xc6\x8a\xbe\x13l\xe5\x16\xf9Bn\x82\x97\xbcG;\xf5\xa8\xfa\x00Y\x8d`\xc6\x90\x86-\x82\x162\xef\xe8\xb8^h\xbd\xc8\x92_\xc1]\xe4\x8b\xd4\x93\x9a\x80_\xb7g\x81\xb0^\x98\xd7\x17\xf6\xad\xc4!tl{Y\xfc[\xbc\xec\xd8\xac\xfd\xc1.\x0b\xd9\xb8(H<\x8bt#\xda4r\xc1i(\xb5\xa6\xc7z\xa2\xa2\xa6\x9b\xb5P\xcc}\xf7\x06M\x8e\x1f\x81\xc7 \xa6\x14/\xb4\x82\xd1\x14\x83b\xf8\xb4O\xbf\xcd\xe6YE\xbc\xb8\xb8\xd9n\xefx\xc4;,z]\xbb\xcd\xf2\xe0$b\xfe\xf7+\xf0\xf8l\\\x0f]V\xc2\x9d\x03\xabX\xaa\xa6.\x1e\xf9]\xd9\r1\x1eA\xa8%\xd1\xe7=\xf4\x99\xe0\xaaO<@D\xe4R\xb0T\x8d"7K\x91\xc8\xc6\x0clH)\xd2\xf1\x7f\x92q94\xe7e\n\xe0\x19\xfaD\xe5\xd6\x0eAsVN1\xa2\xa6\xf2[\xfcxS-n\xec\xcf\x07I\x95U\xb0]\x91\xe9w_\xf6\x02\xfb\x16\xf0-\xbd#\xbe\x01RK\xfe\x0e\xe0\xc7"(y\x9dU\xbcV.\xf3\xce\xd4\x05bX\xd2\x10\xfcs\xe1\xacD\x1d"\x8e\xaa\xdfr(\xea|\xc7z\xbbfd\xc7S\x0e\x7f\x84Q\x1f\x83N\x19\x19\x83\xdcFu\x80%3\xedJ\xa58\xec\xb5h\xa9\x02z\x0c!t\xa6\xcaR\x019j\xe2\x1f\x7f\x03\x95\xf7>.\xc3w:\xf0\xd2\xbfJ\x0f\x90\xa4-|;S\xe5\tD\xf6\xe0S4\x9a2!\xd2\xa5\\\x7f\xa9\xbf\xd9)\xdcy \x02\xc2\x97xb\xb9p\xd4\xad\x03\x86\x0f\x04\x11W\n\x8d\xdb{-\xd2\x91\x10k%2kU\xedC\x9b\'\xe9m\xab\xb1pQ\xb4H$`\xba\xe3c\xae4q\x99\\\xcd\xbb\x1c\xad\x99<5\xfe\x05}\xde\xe6\xc4A\x8dNf\xdb\x97/\x8d\xde9\x86U:e\x9f\xc2?\xd5VuV\x8bL\xf9!\xb7\xb0/\x84a\xd8\x99 \xf8\xcc\x97*\x04o\'\xed\xa5+\xba\x0f\xdb\x1b\xdf\xfc\x0c\x04\xc3 \xe7V5\x1c\xb7\xe3\xc7Q\x88I\xca\xe6\xe5O!nO\xfd\x11\xb2T\xa2\x98\x93i\xb8\xb3BeW\x19\xe1\x9a_R\xf7\xc0\x1b\xb5\x12\xa1/\xd8\x95\x88\xfe\xad\x0f\x18\x90\r\x8e\xe65,y\x9c\xc8\x8d5UR\xcd4\x9dk\xd3\xa5\xb8\xfc\xb1\xf7\x93F\x17z\xba{\xb2,\xaa\x80\x19\xbdG\xf3)\xaa\xd8\x8c\xe4-\xcd\xaf\xa8\r\xec\xb7\xec\xa1\xf7\x1d\x12\xb7\x8br\x96s\x91Q\xe5\x8f\xeb\x0cp\x84\xd6\x00\xeb0GrFC\xa4\xc0N\x89p\xa6d\x18\xa2\x00p\xc4X\x91\xc8\xe3\x06\x1a\xaan\x8e\xdc,\xfa>\xb6\xba\xcaA85\xa8\x81G\xed\x1b\x00\x13#?\xb8\x07\xc8\xf63\xfa\x8e9;\xe9\xaa\xb2:\x131\x8dp>G\x93\xeb\xa4\xcf\xd8O\xe0\xd6\xc3\xddbE]\xf2T\xcb\x8b\x8e\x02\x06\xbdR\xe3\x98\x83E\xf1\x90\xad6\x85\xd2e\xd3\xf8\xd0\xee\x06\xe0\xde\x85x\xa3\xf9\xf8\x8c\x10\xed\x17i\x85t\x98!\xb8O\x95O7\x1a\xe7\xf0E\x16\t*\xba\xa4\xa5\xc2\xd5\xbdh\x0c\xbf\xc3\xed\x8b\x1b\x80\xe5vo\x99\x8bZA\x8a\xe4A6\n:\xb1\xa6\xad\x92 \xd6\x02M\x97\xc0\x8a\xc3\xe6\x8e\xa2\xa8$z\x10/\x17\xab\x02h\x1d\x10\xb2\xc4\x1810@\xb2zv\xc8\x91\x91\xfb\x88A\n\xe6Yn.\xa1\xfa\xf4\xd8\x86\x8c-\xc6\xcf\xe4b\xb6\xcc\xc1\xd9\x1b\x9d\xe3 uy\x86R\x84\xfb\xa5\x15h\\\xdf\xc7\xf5x\x0c\x82\x0ce\xc9=e"]\xe3\xd37\x7f\xf0\x0e\xd6\x0e\xdaL\xd0\xb6&\xb8\xdazc\xbaC\x8c`\xb8\x92\xdc5\xeec]7\xc9\x95\xb3^\xb6fa\xcdE\xf2AI\xc5\xc4\xd5\x02Q\xff^M9\xe1INn\xb3\x83\xfe\x13\xea\x83\x80\x1eZ\xe5\xca\xea\r\x07^{\x92\x1fj\x9c\x9b\xaf1\x9f\xf3\xadmPw\x8c\x02jq\xac[g\x1d\x10c\x02\x1a\x8f\xde\x85~\xb6C\xed\x02\x8d\xf9\xc2j\x02\xf6`c\x99\xcb\xab\xfb\xcf\x03\xc4q\xc0\xe0\x83n-\xca2\x12/\xdeD\x87+\x90\xf8Y\xb7\x9a\xc1,\n<\x11\xec\xb2\x96\xc7\x9c\x02u-\x1a\xa6M\xf0#^.\n.\xdc\xd80\xce\xfc\xb6\xc4\x8a\\\x9eP~?\xf7\xbchN\x06\x8aF\xda\x0b\xcb\xb2\x9aPf\xfc\x0c\xdbS\xe5\x02~[TL\xdb?t*J1\xa5\xb6\xbc\x0e\x1c4{\xe1\xd8\xfd\xcf\xfd\xe8\x14\x80a\xadw\x843\x00\x91[\x93\x86\xe1<\xce\xa5\x992\x97'
|
|
|
|
|
|
2024-12-14 17:54:48.612179 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 386
|
|
id = 15361
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8a1d
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505881770
|
|
ack = 2364269497
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x28
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xa3\xd4-\xc7\xc4\xe1\x97\xe0\xcfK\x96\xacf\x81\x12!\xe6+(\x8fdi\x1d\x901\xa4\x08\xd3\xba\x0f\x0b\xc1\xca\xb8\xe5 \x91\x1d\xebvl\xb6%n\xda\xa9\xd6\nMO\x01\xf3\xe7\xfc]m$)\x880a\xbd\x14A\x19\xbb~\xc3\xeb\xf8*e\x18\xfc6\\\xa5\x9aAy\xe8\x9f\x12\xa8\xc3g~I}HN~\xb1\xf7J\x9d(ym\'1C\x84\xcf\xd3\x19\x00J\xec\xb0%qU\x89\tpL&\xb7\x04\xcb\xb5\xb3c\x14S\xf8\xd6\xa4Z3T\x8dsQ7[\xa3\xbd\x82\x8dJ\xeb\x8dz\xf0F\xfdU\xb5\xdb~\x9e\xfe\x1cT!<\xbc\x06_\xb9\x0b\xd6\xca;6Q\x91\x00\xfb\x1d\xdd\x97?\xef`\xa0\xde\xc9\x9e\xd9y\xbb\xb2\x13\xedI%\xeb$2;B\x17\xe4K\xff\xa4\x14wQ\xb3G\xe0\x04\x94Y\xc8\xc6\x04&:\xec\x1f\x01\x98"\xb2\x8eJy\xe6\xcd\x89*h\xe0O\xd5\x8f0u}Ow\'\x05\r\x1e\xadi\xdb\xb8{\x990-:QF_\xb6\x17W\xaeN\xbc\xaf(\r\xc0,\x85C\xa7\xf6\x9d\x95\x82\x88$_e\x8c\xd8U\xf2[Uk*m\\\x01\xc2\xa0e-\xc4\x19\x95K_\x12\xbd\x8d15\xa0a;\xe6\xd4\x1ah\x0f\xc6\x13S$:T\xbc\x04\xb1c\xd5\xd9\xb5\x88{\xdf\xa1\x84W\xec\x12\xd5?;p\xcd\xef\xe6\r\x80\x82\xebN\xd5\xc4\xaa\xd2\xdf\x1c'
|
|
|
|
|
|
2024-12-14 17:54:48.614674 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 45338
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269528
|
|
ack = 3505864366
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8072
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.617406 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 45339
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269528
|
|
ack = 3505865710
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 508
|
|
chksum = 0x8072
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.619950 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 45340
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269528
|
|
ack = 3505881770
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8072
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.621943 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 45341
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269528
|
|
ack = 3505882116
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x8072
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.624678 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 15362
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8b57
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505882116
|
|
ack = 2364269497
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x30b3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1a0U\x1d)\x0e\x1c\xfa\x880\x10\x83\x8f\x8c\xc0\x88\xc3$f\xc9W\xa4\xde\x99Os.'
|
|
|
|
|
|
2024-12-14 17:54:48.629352 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1308
|
|
id = 15363
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8681
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505882147
|
|
ack = 2364269497
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x91d4
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x04\xefLgZ\x1a\x11\xdfv\xc9a\xa9\xfc\xc4j>\x0c\x81\xa1\xd6wq\x8d\xcb>\x15Mj\xd7\x12\xf4\xd6\x94\xa8\xd2\\\xc21\xbd\xdb\x81\xef8\x1c>\x9a6\x94\x8ch\xf3^s\xea\xc0^\xc3\x11\x83\xca+-\x97\xee\x99\xa3tF)\x1b\xafj\xbc\x9e]T\xb3\xd2\xc3TJ\x92\xbe\x00Nzq\xffq\xc5\xc5\xe0\xcd>\t\xf0cm\x8f5qO\xa2p\xcd\xa6\xc3&\xb9k\x99\xd0$Y\x93\xfe\xb3`GQKs`\xc0\x92\xcc\x8coN\xdcO\xb1\xce\xfb\x1d\xbf\xb1\x8f\t\x02\xeb\xc6\xdb\xb4F\xc0{\x832\x8e\x1e|\xee\xff.\x7f\xd0\xa3\xbfj\xca\xbe\\[\x89p\xee\x1a\xf9\xa5\xeba\x17sC}pA\x02@\xfdnAl&\xff\xa8\xe1\xa6\xcf\x17\xe2\xa5\x07\x9a\xff~\x11\x1a\x85\xf2\xbf\x07\xcb\xdc\xa8#Cw,\xbe\xc5\x80\xb4c\xe2\x05v\xa8V\x96i\xde=\xde\xd7\xd2Y\xce\xf2|\xed?\xedA\x83\xc9n\x9f \xbf\x8d\xa9\x06E\xb0\xa6\xd6DU\x1fS\xcd\xb8W\x0f\xfc\xd7l%8ox\xbb\xca\x18\xc4]\xa5\xf5\xf9Xj\x8d\xec\x17\x980\xf4\x81\x06\xc0|\xec"\xbc\xbc\x0b\x1ep\x048\x06\xef\xc0\x8dtz\x1c\xc6\x9e\xf3f\xdc\xde$\xa2\xb1\x931G\xd5\x1d\xc1\x12\x8chNN\xb2\xdc\x11\xf7\xc1$\x8b DJ\xe2r\xc52\xa5\x12\xb9p\xbb\x96\xbfX\xab\x15\xd6\x1bLS\xf8e\xa9Yq\xab\xea\x13w\x13\x06\x0fx\x19$\xa9\xba\xa9\x15]\xc6\x0b\xef=\xb6\x811\x1d\x89z\'2\xd3v\xb1F;\xd5k\x17:A\xcb\xa4}>i\nSK\x0b\'2,\xed\xa5y@\xb6\x1a\xd6\xd5\xcea\xc5,\xd95\xc3\x93hsq\xd1\x9f3AE\xedUW\xfaSf)1\x84Kvy\x85\x9c$\xc4F}\x9c\x8b\xdc\xf7\xef4\x90\xe9\xc8\x87\x874\xc8\xb7p\xa5\xb14\xd8\xab\xbd\x1b\xf7\xc9\x1e\xf6\x9b\x04\x87\xeb\xa0\x81\x9a\xb3.O@\xfb\x10\x13W\xd8\x07C\x13\xc8\xad\x0b<~XVL\x1e\xbc\x90\xbeJ&z\xfd\xec\xea(w\x0b\xe6\xe0\xca#\x92Jy\n[\x96{{$\x7fG\x10H\x81\xa9j3\x99z\x0e\xccQ\x02\xd3\x1b\r\xf6\xae\x0cG=\xa1\xeb\xf1\xd2\x02Y\t\xec\xder\xa5\x98! \xddX\xa4v\xa86\xc2\xad\x14\x9d\xe2\xba\x7f>\x9c0\xa8X\x8aI5\x1dy(Y7p7Z\x9c\xdb\xcf|\x00\xa2\xdeG6]g\xf8\xda\x8ej\xbew\xe5\xac;\xa9\xa35\xb6\xd5\xea*LK{K\xd89\xaa\x1f\x05f?\x92\x9e\xf7S\x10nn\xbc0\xc3\xc9(\xee\xcbE\xe9o\x8fK\x8f\n\x1fI\xf3\x1a\x03\xe7\xc1\xe7Q\xc4\x08\xb6kd\\\xbf\x89\xc5\xd2\xa3\x04{~\xf3\xa1\xda\xfe5\x06\x1a9\x1c+\x07d\xd8\xb7\xe9\xcaO\x0c]\x0c\xc4\x86"\xea\xdb\xf5nk\xa9]\xdcp\x05\xf6\xcc\x123I\xd4F\xfa\x1ad}4y"0\xb1)+\xedLc$\xb9U&\xa5{\xba\xee6\x98\xa5\xb3M\xab.(2\xb9\x9d\x11\x069\x8f\\\xbby\xa48O\xa5\xdb\x8b\x0f\x8d\x92\x02\xf6\xd7_7\x08\xa8\xc0\x164@L\r\xe0\xa3p\x19:\xae\xe6\xd8\xaa\x82\xc3g\xfbm\x8d]\xf5\xbb\xc3\x9b\x91b\x93\xc7\x0ej\x0c\x90\x01\xb0\x10\xdc\x8b7pWh\x0e\xb6\x10\x8e\x05D\xd8\xb4\x85N+\xcd\xf5\xa6\xa4\x88L\xec\xeere\x0f\x87\x1c\x1e\xee\xaf_RM\xc7\xb62\xe2k\xa3&\xc7\xc7E\x1a\xe2P\xb6\'\x802\xfb^\x7f\xa9F\xa62#\x82|\x9f\xd5\xf9\xf16<\xa8v\x85\x01\xa8U\xdb0\x82`\x81\x05\xec\xbe\x13\xe4\x1a\xee\xbf\x9c)\x1a\xf9/\xff N1\xb7\xb2\xe3\xe4T\x8f\x07\x1b=F.D\xa9\x065\xfcFI\xb5\xeb\xd4\x1f\xac\xa8\x99\x80\x0e-\xf0\xf7]\xf1\xf0$AE7Xr\x14\x8d8\xc7\x12\xbf\xd8s\x0c2\x81`j\xab\xd4Y\xa0A[E\x01\xef*\xe7\x87;\x03\xce\xd2\x01y\x8d\xd2n\x04\\h\xe5h\x8e\x1e8\xd8Gb\x804T\xad\xc4\xb3\x9b\x91Y\xc5W\x08\xa2\x19\x17\x8b\xce\xf1\x94\xcfz\x86{\x95\xca\x14_r\\\x05)\xfe\nM$J\x83\xc9CA\xfd%\x80,>\x93^\xa9\xfcZ\xd6\xf8}\n\x16\xbd\xcbT\xcb!\xdd\xc8Q\x82\xb4\x8f{ {\x05\xf2\xd1\xb2j\xde\xa2{tf\xb5J6\xc7\x9ci\x13\xa2\x83\x9d\xeb\xd0_A\x1c\x10\x0fL\xa8\x1d\xc3\xb3\x07\x80\xc9\xe5\xe5h\x96\xb8\x8f\x10\xb5\xce\x8bx9Y\xd5\x99\x13}uC2\xd6~\xdc\xe3\x97\x8b\xc2S\x1d\xd6\xc7\xa6\x06h\x99ZV@C\xd6\xe8!\x0f\xe1\xdf\xda\x1eNK?\xb7;\xa4\x8c\xb3o\xaf\xde\x19\x03\xb2\xa2R\xc8*e\xaeH\xac\xde{\x85\xb5>\xaa\x9e\xcb+.\xb17?H\'q\x94\x88a\\H\xef\x94D7\x99&\xe9\x0b\x98f(\xb5oH\x91\xe8\xe7\xb3O\xf0\xd7\xa3\x7f\xf1\xd0#\xb4\xe0\xdc\xa5p\x80b\x07x\xe4]\xc9\xca&\xac\xf6i\x9b/\n\x7f\xa5,\x9e\x1cT\xafa7\xcfz4\xc7\xc4g\xc7<\xebp!\x1f\xef\x8e\x98\xef<\x0bw\xb2\xf2\xbfB1\xaegD\x1a\xb5\x7f\'q\xf1'
|
|
|
|
|
|
2024-12-14 17:54:48.631643 - Ether / IP / TCP 192.168.1.11:40847 > 2.18.188.146:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 45342
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.146
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40847
|
|
dport = https
|
|
seq = 2364269528
|
|
ack = 3505883415
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8072
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.634165 - Ether / IP / TCP 192.168.1.11:40845 > 2.18.188.131:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 25573
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40845
|
|
dport = https
|
|
seq = 1299534588
|
|
ack = 3808890008
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x8063
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:48.637057 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40821 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 123
|
|
id = 17093
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x3b32
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40821
|
|
seq = 2746219178
|
|
ack = 373750560
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1019
|
|
chksum = 0x3458
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00N\xfe#\xd4\x1a\xd2OB\xce\xd6\xc9\xf3I7[\n+\xb0\xb3VD\t\x05\xa1\xd2WQ*m\xd5C[\x96\x83R\xd9\x00t\xcf\x83m=)\xe0\xe2\x91\x15|FA\xfe\xe0\xcb\xadr\xca\xdb\xc7n\xc5\x18\xaa\x1e\xb4\xff\xb1\xde\xc7D\xb7\xf9dIz/\x8dH\xb0\x03'
|
|
|
|
|
|
2024-12-14 17:54:48.639548 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:52783 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d31
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52783
|
|
len = 32
|
|
chksum = 0x3994
|
|
###[ Raw ]###
|
|
load = b'C\xee\xe2\x1bC\xcaj\xa9Q\xe2\xe6\x8e\xaf\x89\x84\x05\xbe\xfe[\x0e\xe8h\xed\xb2'
|
|
|
|
|
|
2024-12-14 17:54:48.642441 - Ether / IP / TCP 192.168.1.11:40821 > 35.186.224.24:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 30931
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40821
|
|
dport = https
|
|
seq = 373750560
|
|
ack = 2746219261
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc5c7
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\xbf\xbdF\xed\xe3\xe9\xb1\x81\xae*\xfe\x8d\xca\xfe\x18\xab\x82K\x1d\xa1s\xf2\x1e\xee\x99\x97\xb3\xb7s\xe6\xfa\xc7\xf3\x8b'
|
|
|
|
|
|
2024-12-14 17:54:48.644786 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:40821 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 17094
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x3b84
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40821
|
|
seq = 2746219261
|
|
ack = 373750599
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1019
|
|
chksum = 0x94e7
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:48.647217 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d33
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 32
|
|
chksum = 0xcf05
|
|
###[ Raw ]###
|
|
load = b'EQ@\xf4L46\xc2Ks\xeeZ\x97\x98\x08\x07\xdaY\xf7\x06\xda\x04\xe8O'
|
|
|
|
|
|
2024-12-14 17:54:48.649166 - Ether / IP / TCP 2.18.188.146:https > 192.168.1.11:40847 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 15364
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x8b74
|
|
src = 2.18.188.146
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40847
|
|
seq = 3505883415
|
|
ack = 2364269528
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0xc169
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:48.652850 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 951
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x79b0
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 931
|
|
chksum = 0xa0b
|
|
###[ Raw ]###
|
|
load = b'E\x9e\xa8I\r\xd1\xa2\x88\xd1i9\xac\xf5\xaa\x0cd\xe9\x97q\x03\xf9\xe0T\xb6.\xf6\xd2yP=3\xabk\x88,\x08\x0b~PJ\xac\xaddY?\x1b6\x06\xc4\xcc\xf2\xc6\x85O\xe9D\x11\x98;\xbf\x01\xb9j\xeb\xf6 \x0c\xfex\xfb\xe2\xca\'\xa2p#\xe9\xe2\xc9\x89\xfc\xfe\x9d\xad\xe9\x903\xfb\xf8\xc4\x0bo\xbf\x94\xbbMtR\xff<\xa8^\x0b\x9b\xe8\x88f\x02\x90\xaf\xf5\xda**\x8e\x0e\x819\xe5\xcc\xa0QMI\xdb|/\xd9\xcb\xca-\xd4\xe0\xb6\xae\x0b\xd6+@g\xafpn\xc1"\t\x97\xd2\xbd\xd3\xd2\x89O\xe7\xbd\xe6\xdd\x89\x82\xfa\x884\xa26`\xc9\xb5c\xed\xfe\x00!\xc0`\xb7\xa5yXp\x0cC\xc0Z\x06\xf9\x18\xab/\x88(d\xe1\xd3D\x12\x9d\xd4c\x98u4{\xa1 \xfcd\x8e\xe2/\xf7\t\x04\xf6\xba\xe9\xfaO\xe4W\rr\xda\x83\x07Fa\xd3.\x9d-82\xcb\x9e\x14\xd0<]vW\xca\x8a\xfai\x07Q\xf1\xd1N\xe6\xe1\xd5\x0c1\xb7\xeeu$\xd0.\xd3J#/\xb3\xa8\xf9O\x83\xfe\x1f\xaa\xdc8@\xd1\xa1\xce\xa8\x86%\xa2d\x8d\x19\xe1\xa7\xc6\x0e\x8b_x]\xbf\xbf\xd01c1\xbc\n\xd9Y\xd6S\x89*\xc9(\x8c\x83_\xba\xd7\x0c\x9c\xefX\xd1\r.\xcd\xcd]t\xacpaF`\x04\x94\x18\xdb\xd3\xd4\xa1\xbe\x95V\xb9\xb3(%k{.\xbc\x80\x9d\xe4\x10y\x82\x88\x837\x1b\xfb\x8bE\xfaS\xd6\x85\xab\xb7\xba\xdd\\\\\x1f\xf5\xbeq\xf2\x82\xff\x9ba\xd81\xcd\xdbU\x97\x1f\xc2\xf6\xc3Kd\x18b#G\xc9\xfa;s\xf8N\x03\xc8\x9f \x89\xd5\x8e\x8e\xe5\xbc\x1b\x1a\xce\x11#\x89m\xa7\xb1\x88\x9b\x11\x94|@\n\xbaE\x1d\xb3\xc8\xea\x920r\xe6\xb3\x02%\x02u\xe7N\x85\x1dPD\x9c\xc6\x8e\xb5\x90\xcd\xa5\xd07y\xca\xc7+\xb4\xb2\xf7d\xe2\xdd\xf8\xb4\xa9\xcb\x7fc\x9d\xa8x\x90t\xef\xfb\xb9\x95\x8au\x8ciEI\x1c?\xbc\xffB\xe5?N\xbdcY\xd5\xe0\xc9\xc8\xba\xa8dp\xa7\x08 \xac\xb1\\~\xcc\x97^\x12\n\xed]5\xa9O\xc1\x8a\xd9x\xfe\xca\xdf\x1c\x92\xbaY\x96\x862\x9a\xf2\xd70\xaes\xaa\x02^\x06\xbd\xb2\x9f"\x91\x80>\xf3w\xffsh\t\x97\\\xabh:r>\xce_V\x00s\xff\xf4\xe0~~=\xd8V\xd8\xa7\xea\xeeG\x89\x02\xec,\xc4\xbbq[\x97\x18:\x1eK\xb8\x18\r`\n\xebw\x91U\x1e\t\xeet\x82\x91\xe8\x8b.\xc5.\xd5\xef\xba\xc7\xbf\xbdo\xa4\x0f\xd3\x92\xf1KS\x0b0\xec\xaaw,j\x14\x01\x8cK;\xa5o\x0c+\xf4@]\xa6\xbeL}P\x0c\xedP\x91sJ\x1a8s\xc6\x8c\xad\xf6JT\xf2\xb1q\xda\x965\xe7\x9f+E\x85\x85\xb8l\xc7>W\xef!\xf9\xed\xe7\x06\x9bL\\-\x84io\x15\x9f\x1e\x87o\xd2hy\x0c6T9\x97\x14Eq?y\xe9\xa84\xa2]M j\x19_\xd2d\xa0\x8f\x14\xe6\xde\xb45\xf92\x85\x0e&\x946\xd9\x10e\xee\x18\x0c\t4{\x01aK.\x9f\xf4^ Q$\xf7\xfa\x9e\xe0\x08\x82\xafy=q\xce\xfd\x07\x18Z\t\x9e\xb0l\xcc\x0bh\xc2\x01*\xdc\x8d\xda\xa3\xd1\xe7j\x92\x99r\xc4\xecU\xde\xddB\xc1\x83Z\xf7m\xc2\x88 y\x9c\xa8\xbc^\xe0\x84\x89+\xeb\xd7\rT\xf2\r\x9b\x0eP\xd2l\xbf\xdc\x85\xdaA\xa3\xa1\xa6\xf7\xb1\xff\x1a\xbfiS~\x05\x8br\xe9\x91\'\x16\xc3\x08\x8c\xab+\x83b/j\xfa\x16b\x0c2\n\xbf\xc4\x0b;\xf8\xc9\\4\xd6$3\xe0v \xa4+\x9e\r&\xafZ\xbcVp\xf7\x87\x86\xda\x11\xcc\x9a\xf9\x88\xd5;g8\xaeB|\x89\xd1\x02u\x83\xd1N7\xe5W'
|
|
|
|
|
|
2024-12-14 17:54:48.655932 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 859
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7a0c
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 839
|
|
chksum = 0x4777
|
|
###[ Raw ]###
|
|
load = b'X(\x1c\xba\x80\x1c\x14\x8eg\xc8\xed\xa6\xc7\xff\x7fI\xa1\r\xcc\x12\x86\xe1\xe9\xe6\xce-\xa4h\x01\xe2o\xd8\x8d\xf2\xb5w\xa4_\x03U\x07pAi_\xa6\x99N)w\xc3\\\xf9\'\xa6\x86:\xbd9\x81~\xac\x84\xecj\xe5\x87i\xfa\xabF\x12\xec\xbcr\xd9`\xd6\xdd\'\x11\xdd\xcc]Nf\x9f"\x83\x11\xeaU\xa9\xf3Q\xe6p$\'\\&\x1e\x80j\x08\xf4^\x1d\\\x100#\xf1\x97\xdd\x10\xf9\xc4\xe1\xbd\xfa\xb41\x8e\xe6\x08\xef\x82\xd1%Z\x10\xef\xa6\x9c\xfa\xea\xd1\xa3M\xc4g\xa7\x14\x19\x11\xc4\x9b\x86\x00\xc6\xc9\x98=m\xd8\xebK\xb48\xbf\xe1k,\xcf\xef@:\xe3z\x08\xbbT\x10> \x86`\x9c\xea\xe7\x05\x1e\t\x8a\xb2\xdf\x85#b\xa8\xfa\xb6\x0b\xab\xf4\x9fdS\x90\xde\xed\xf7\xc05\x9d\x83\xfa\x8c\x1dJy\x88Kj\xefl\xaf\x8a\x1a>\x08\xb1-\x82\xf7\xbe9\x9bW\rl\xe3\xd4\xebw\x0b \x160\xa1cQ\xf2\xfaDC\xc5cJ\xab\xb1\xafD\x93\x1aJ\x861\x82\x1a\x11\xe2!\xab^\x0e\xb2I|\x9bC\x0f\x19\nB/Q\xc2\xe4\x8a|n\xdb\x9aF\x14\x7f/N:\xc1\xf3B\xdak\xac\xb0\xbc\x03v\x82c\xf7\xc4\x920!UM\xf1u\x8d\xd7\xde@U^\x8f\xff\xd3`\x86\x92r\xb2\xa6}??\xa4\xcaQ@\xd1\xd6\xc4\xf2\xb4\x89\x03\x1ei\xe8\xf7\xb1|\x83\x9eb\xb7\xe8\xbfl\xaa\xf6R\xa3W\x16\xa5\xb7\x11\xba\x13\x12T\xeaW\x03g\xe6F"7\xbd\xae\xaef\xad\x94\xd0\xf4\x8a\xc0+BY\rNj\xe6\x80\xac\xa0i\x93\x9a\xd7\xf3lV|\x1b\xb3\xe3\xa9<\x8f\xca\x87\xa0\x94\x136\xd2F\x04\x8c\xf1=\xe1\x9f\xbfb\xc1\x16\xc7/\xf8\xdc\x0c&"1\x0e\x0b\xe9T\xf0V\x8e&P\xa1\x10q$\xd3\x0e\xea\xf7\xc2f\xbe\xe2id\xfc*\x93\xd1E\x8ee\x8f!\x7f\xb3\x96\xa93\xbfDd\xcen\xd5\xed\x805\x9b;\xe4nK{\xe2\x85\xd9\x1b\xa5\xfeS\x91\xf8\x93\x1cJn\x9c\xe1 \xd4o\xa2\xd5\xf4\xfb\x87\x127\x0e\xb8]k\'-P\xcf|\xc9MFmh\xea\t\xabKv\xc8\x9c(\xb8j\x8a7\xe89\xb2\xbf\xd4\xf2\xaa\xa1\x07=\x89\xdc\xf7\x1ddSh\x1eS5\xe1y\xbfK\x05\x1a\x96G\xfe"\x86\x8e\xba\xde\xc5\x93\x01\xf9\x12\xaci\xe8sCm\x0c\xab\xb6\xabz@\x0f\xe72\r\xdc\x05E\xa9\xf0\x99\xd8\xb0,^\xa1\xf8[\xb2\xa4\xb8.w\xec\xe5\xf8\x16\xa1\xeb\xac\'3\xee3\xb4\xc9:\x965\x7f\x96\x9cv\x16U\x00^|d5\x1b\x18`C\x9e\x0f\xf0\xe9,U\n\xe2\xea\x9dj,\xe0\xc4\xd3\x8d\xd0\x93g8x4}\x03\xf0\x08T\xcf\x19\x8e\xd2)\x82!\xa1\xe5\x8c\xd8\x7f\x8c2\xd7\x1a\x13\xecXo\xca\xc3j\xd5\x00\x9b"\x137\xca\xd3H\xfcU9pk\x11\xd4n\xc9\xb7\xdc\x8fh\xf7\x00\xf1.\xb4\x0e\xea\x0fU\xe8\xfa\xc9\x00F\x08\xc2\xfe\x17\x9a\xe1\xb0\x062rXr\xe7\x8d\x7f\xff\xa0\x06\xb2H\x8b\x9b\x1a..\xf0\xa1\x1b\x02@&\x0b\x85\xf2W\xad\xb6S<\xb1W\x13\xe4g\xd43\xaa\xfbA\xe0\x9eq\x18\xa6M0\xc0\xc8z\xb7\x92\x96\x89\x99\xc7B\' )\xbd \xa1\xca\xad\x90\xfd\x814h\xf0\x15~\x05\x87 \xa4\x83-\x0c\x83Q\xe6[q\xa0\xd3^\n\x81j&\xba*'
|
|
|
|
|
|
2024-12-14 17:54:48.658442 - Ether / IP / UDP 192.168.1.11:62215 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 65
|
|
id = 30932
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 62215
|
|
dport = https
|
|
len = 45
|
|
chksum = 0xc5c4
|
|
###[ Raw ]###
|
|
load = b'[\xea\xa4\xfd\xe9\x04\xea\xaf`n\x1dFQ\xd2\x92\xed\xb0\xeaJ\xd3}\xb7\xc9mW\xe5\xf7\x19S\t\xc1\x92\x15\xc8k\xb8H'
|
|
|
|
|
|
2024-12-14 17:54:48.660920 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:62215 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d33
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 62215
|
|
len = 32
|
|
chksum = 0x250e
|
|
###[ Raw ]###
|
|
load = b'Su\xdb\x94hbg\xd5W\xcb$\x0e\x9bg\x9e\xc5\xe4*\x0f\x12\x19B^\x8f'
|
|
|
|
|
|
2024-12-14 17:54:50.213233 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 57
|
|
id = 53861
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 37
|
|
chksum = 0x8ef
|
|
###[ Raw ]###
|
|
load = b'U\xf3wB\xde\xaf\xa6\xa7\xe04\xeb\xe1\x8d\xff\xf5\xfe\xd9\xbc\xc6Xi\x82\xb7\xf4N\x0f\xc0\xcb\xbe'
|
|
|
|
|
|
2024-12-14 17:54:50.241604 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 54
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3aff
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 34
|
|
chksum = 0xfd80
|
|
###[ Raw ]###
|
|
load = b'@\xd3\xb0\xde\x1b\xe2D\xdd\x01\xc1\x902\x00\xbc\x1eVy-P$\x7f\xce\xb8\x1a\xf6\xbe'
|
|
|
|
|
|
2024-12-14 17:54:50.450264 - Ether / IP / TCP 192.168.1.11:39688 > 162.159.136.234:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 94
|
|
id = 3084
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.136.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39688
|
|
dport = https
|
|
seq = 3211592045
|
|
ack = 414049505
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 511
|
|
chksum = 0xed8d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x001\xf99\xb8\x1a\x84\xce\xf9\xc8\xc7o\xa5\xae<\t\xfa\x93|1/\xb3\xe2Qw\\\xf1\x1a3\x87\x07)-\\\xa4\x92\xf6\xa9\xb2\x0b\xc1!\x95\x84\xc255\x8f\xab\x9a\x1d'
|
|
|
|
|
|
2024-12-14 17:54:50.472788 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 443
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x55d8
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414049505
|
|
ack = 3211592099
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 8
|
|
chksum = 0x672c
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\xab\xd7\x8c7'
|
|
|
|
|
|
2024-12-14 17:54:50.564044 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 77
|
|
id = 444
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x55b2
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414049505
|
|
ack = 3211592099
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xf796
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00 \xe0\xb5\xbb\xbe\xe6\xde\xfct\xddT&\xe0\x19\xc8\x10\xba\x85\xeb\xc7W\x8d)\x83\x8c\xd6\xbaA\x86\xfciD\x11'
|
|
|
|
|
|
2024-12-14 17:54:50.605063 - Ether / IP / UDP 192.168.1.11:57621 > 192.168.1.255:57621 / Raw
|
|
###[ Ethernet ]###
|
|
dst = ff:ff:ff:ff:ff:ff
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 48711
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.255
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 57621
|
|
dport = 57621
|
|
len = 52
|
|
chksum = 0x9f
|
|
###[ Raw ]###
|
|
load = b'SpotUdp0\x977M\xb3\xe9=C\xf2\x00\x01\x00\x04H\x95\xc2\x03\xb3}cPK\xb7\xed\x7fT~\x1d\x0f\xd7\x01\x15-#vA\xf6'
|
|
|
|
|
|
2024-12-14 17:54:50.621099 - Ether / IP / TCP 192.168.1.11:39688 > 162.159.136.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3085
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.136.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39688
|
|
dport = https
|
|
seq = 3211592099
|
|
ack = 414049542
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0xed57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:50.631999 - Ether / IP / TCP 192.168.1.11:40820 > 142.250.200.131:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 16929
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.200.131
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40820
|
|
dport = https
|
|
seq = 1064348429
|
|
ack = 3535858572
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x194d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 17:54:50.637289 - Ether / IP / TCP 142.250.200.131:https > 192.168.1.11:40820 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 5890
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x1491
|
|
src = 142.250.200.131
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40820
|
|
seq = 3535858572
|
|
ack = 1064348430
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1018
|
|
chksum = 0x3d99
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (1064348429, 1064348430))]
|
|
|
|
|
|
2024-12-14 17:54:51.972579 - Ether / IP / UDP / DNS Qry b'gew1-spclient.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 31679
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55391
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 20473
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'gew1-spclient.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:51.981002 - Ether / IP / UDP / DNS Qry b'gew1-spclient.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 31680
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52969
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 13941
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'gew1-spclient.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:51.988281 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 417
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc5a8
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 397
|
|
chksum = 0xc02c
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: upnp:rootdevice\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::upnp:rootdevice\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:51.997741 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 489
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc560
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 469
|
|
chksum = 0x502d
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.005305 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x83e4
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.012747 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 485
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc564
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 465
|
|
chksum = 0x7632
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.019487 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8392
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.028008 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 465
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc578
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 445
|
|
chksum = 0x8a6f
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:device:WANDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.037924 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8394
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.045064 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 497
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc558
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 477
|
|
chksum = 0x3a9
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.053903 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 479
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc56a
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 459
|
|
chksum = 0x81a1
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANIPConnection:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:service:WANIPConnection:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.059874 - Ether / IP / UDP / DNS Ans b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 136
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb708
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 55391
|
|
len = 116
|
|
chksum = 0x8738
|
|
###[ DNS ]###
|
|
id = 20473
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 2
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'gew1-spclient.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'gew1-spclient.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 178
|
|
| rdlen = None
|
|
| rdata = b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 32
|
|
| rdlen = None
|
|
| rdata = 35.186.224.26
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:52.068077 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 45706
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdb51
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412657040
|
|
ack = 1692640772
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x47b2
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00\xd4\x02\x0c\\\xd5\xfe\x16\x89\xe5\xb0U#\x91\xee\xed\xf6\x918\x15\xcd\xad\xbcYVH\xc6P\xa8\xeb\xe5\xf0\x1f.\xde\x1eVS\xaf\xd9-\xd4\xe8\xbe\x19i\x06\x02\xfb\x0c\xddL\xd5A\x88\x1dk\x9a6\xb8+u\x11\xbf\x9aa\xa4\xa8\xfb\x7fVA\xdb\x99\xbb\x1a\x1b\xddTg\xcayrs\xe1\xb9o\xee\xe7\x9eE\xd3u\x95\x01\xe53\xc9\x8d.\xdf?\xa5\xe99\xc8l\xa3m\xa4\\\xb4b\\\xa0\xec\xef\x1b\xb7\xbb\xdaE\x80+k\x81+\x87ex\xcf\xd7\xc4\xcb\r\x12a&\xbd\x91'\x1d\x06\xa0\x95-\x95\xfe\xbb\xa2E\xe3\xd2\xfd\xe4\x94T.\xb5\xbf\xc41\x9b~\x1a<\x1d\xb6\\\x9a\x95/8+\xaa\x15\x06\xa3sn\xa8\x1d\x87\xe75\x07\xbd\x01\xebi\x93tc;\xf8\x08\x14\x03X\x90\xb4\x15\x07\xeb\xbc\xf01\x00nnOM\xfbi"
|
|
|
|
|
|
2024-12-14 17:54:52.073751 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 49796
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcb57
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030874682
|
|
ack = 17610682
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1517
|
|
chksum = 0xa6ee
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\xfcn\x9cR\xab\xfda`\xad\xb7\xb3\x96\x84\xac\xc6\xe4\xe3QY\xc8\xe7*\xe4D|b`\x1a3z\x12\xf6\xc3\x95S\xd1\xb3d\x85\xb4\x97p\xd6s\xc0\xdb\x03a\xe1\xc5\x89K\x89\xeb\x08l\xc7\xa5(\xe2\xe8\xdd\x1c\x93]:l\x7f\x1b\xc2B\x9c\xd7\xe6T5\xa7\xeaI\x84=\xfe\x17{i\x99\x90<\xf7\xda\xc4x\x1d\xa0\xb8\xd6\xa1P\x08&\x19\xee\xaer\x86\xb8v\'\xbf\xa2\xc3\x14\xa1\xa2\xd4\x12"_^\\\x88N\xbe\x0f\x8f\x11\x03\xf2\x17D\x02\x0f\xb2\'\x0bkRpY\x85\xa0m\xaaWC,\x98\x06\xe2\x8c%;\xa39\xdc\x94\x8a<\xee\xe8\x83\x07O(\x88]\xd6\xf8\nPnPW\x80\xe8\x0e\xac\x9c\x08\xde\x1d\x1c&a\xab\xfc\xfa,\x05\x9b\x03)\x9ev\x15\x1e\xd6\x9a$\x08a\xdd\xa5\xe4\xe7)\xe2T\xba,\x9b\x14'
|
|
|
|
|
|
2024-12-14 17:54:52.085383 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 1588
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca83
|
|
###[ Raw ]###
|
|
load = b'\xc5\x00\x00\x00\x01\x08\xf0\xe0\x0fd\x16\xe2\xe8/\x00@F\x00\xb8\x8e\xca\xda\xd3\x01\xfa\xf04\xb6\xcd\xfb\xc9w\x1c\xa7n )\xd5\x951ET\x9e\x02\xa9a\xf8<\x10\x1bp-\xa1\xa1\xfe\t\xeeB\xf5r:\x07\x0bpa\xf2\xa4\xdf\x82mR\x8ex\xf6\xbe\x7f\xb1\x11Bs\xe4Y\xc4\x94,\x00ID\x89\xe7.J\x14C\xbd_S\xf8]s\xa4\x10\x91\xb4\xdf\x87mA\xa0\xd1\xe5\x81K\x8b_\xd1\x0f\x1fp\xb3\xf6\xbd\x874\xec\x97\xccBC\xe0\\\xa5_\x8b\xbb\x7f\xcc\xc0\xf3\x03\x05\xa9I\x8cT\x05\x13\x14\x0bu\x94\xa4\xe9w\x90\xebTC$\xb0+\xa0\x1f\x9b\x86\x86\x91\x00\xd8\x11\x8b\'b\xf1\xf1@\xf2h\xd5\xac\x83\x94\xc2L\xe8\xe4\x10\xaa\x9b\xf7\x02n-\x0e\x8f\xe2\xd4\x16_-\xd9\xa2\xb1\x1e\xffk\xf7G\xa7\x83\x19\xc5\x9d\x05VF\xc6|"e\xce\x17\x85\xdcCUJ\x1d#\xa4MdV\x86gv\x07\xe7\x16{\xdd\x88]\xde\x19\xb2{6\xe7\x02\xab\x88\xfa~\r\x10B\x9b9\xd8\x90\xe4|j\xa8a\x82\xb3\x8c\x95\xa2_\x13\xed\x0et^\xedO!\xd9Wb\x94\xd4\xee\x1fj\xf3f\x7f\x91r}UL\xf5\xe8\x8b\xf5g\xf2\x8f\xe1\xe80\xb2\r^ \x91\xee\x01l*\xba\xfc\x8d\xa9\x9f\xa5\xa131\xb6J>\xcb\x82Bg\xa1\xdf\xf3\xd1\xa5\xde\xb8\x08\xf1\x15f\x07(\x82\xa3\xa3\xd8\xd2\x1bZA\x16\xf0:D\xed\xe4-\x04\x9fX\xcb~on\x10Q\x97\n\xddy\xfc\xb4U\xf2q)\xfei\x82\xa3$\xbc\x03_\xf1\x16\xe4\x96[\xf6\xee\x17\xf8\xd4Hs\xe8\xf29Q\xb4\x13d\x832\x16\x19t\\\x90O\x0c{\x13\xb3\xc5\x91\xb26p\xa5\xd7\x1ar9H\xed\xcc\xb2H\x99\xef\xdfk \x8a\xbf\xc9f\x94Q\xbc\x96\xf0V\x96p\xf5(\xc5\xe9\xe2\xbc?\xc6\xe8\xfd\xf3\xc2\xa70\xc8z^\x89\xa9\x03\xb9bsj\xd1\xf7\x19Z\xc2\r\x94\xf0\x07)KF"q"\x7fG;[a\xfb\x116\xdaL3\xb9\xcb~\xcf#\x0b\x17\x8a\xddw\xe2\xcd\xdeX\x7f\xdb\xdf\xd1;+\xdf\xder\x82\x02F_\xf2V\x7fX\x00(\x14\x11.sN\xea\xc6+0o\xcf\x8d\xf8"\x9cl\x0c\xbb\xe8\xf1\xd9\x80\xf7\xe0\x17\xc8\xd0\xd0\x85\xfd\xa6\xd2\x9b-\xfe\xb1\xbd?\xc5\n!5\x16L\xf2i\xef<\x9f\xfd\x8em\xb0\xfd\x93\xe5\r\xcfX\xa4\xd5\x87\x1dW~\xb0]\x8e\xf2\xa7,0\x9d1\xd5#\xdaB\xcd\xf8s\x02\xe8\x15\xdc\xc6+s\x08\x02\xf4\xf1xF\x81)\xe2f3@\xe9\x1c\xbd\xffg\x10\x96\xe0\xbc\xcc\x8e/\xa5\x1b\xbf\x03\xc0Ij\r\x87mrl\xee\xc5KV\x8e\xfd\xbe\x13\xa7\xd7\xd3\xbb?\xdd\xe9\x05E\x97\xed& \x87r\xf3\x05\xf3a\xf3;\x075\xb7\xfd\xa6Q\xa5#R\xe8\xb5\xfa\xac\tAL\xdf\xd2\xdb@qJ#\xae\x14\x08{3\x0c\xf2\xdb\x86@\x0f\xbf\x80\x00\xccG\xbd_\xf7%\xc4xz\xa8\x90\x87J-u\xda\xae\x7f#\xde\xb8\xfc\x1a&\x88\x93\x9e\xe1v\xd8wV\xfc,\xd2\xb4\x99h#\xc8*\x13l\xe6\x1f\xb6w\x92\xd6\xbdgw\xb1g\x141k\xfd\xb5E\xcbh\xa4Q\xa01\xee\xdd2rOK\xa1\xc7%\x84?\x1aO\xbcU\x9cC9\xb2I?S\xdbO\x1b-,\xe1\x13\xd0\x1c\x82\x81g\x87\x90i\x99D\xe9\x0bZ\xd9\n\xbb\xef\xa3\xd7\x02\x14\xd5GlH\x10\x8d\xa6\x174i=\x9e\xbc1\xe6|!\x93\x862\xb3\x17O\xa9\xec\x08\xa9I\xd6\xe62*\xc6)5\x0f\xa5\'^\xf6\x9b\xc8\x7fxEQ,\xa9_+\xeaJ.j\xd3JKwb`\x7f\x10\xcc\xdfO\x8cz\x9b\xbeS\xf6\xda3\xb7\x1d\x98I\xe1>k\x1d\x9d\x17\x81s4\xa2\xd2Q\xd2c\xf1$,\xcc\xffJ^~\x0b\xf0\xa8\x9c\xdf\t\x07\x8c)\'\x9b\xc2\xcdIG\xf2\xc2\xe1]*8\r7\n\xadpK\xae&f\xbd\xe3\xf0\x81~\xb9\xd13\xec\xed\x8d\\\x80\xdf\x06\xce\x84\x83\x98\x89\xbcA{*\xb6\x89\x1e\\\xb0\x0c\x01/\xf8\xe9\xe6Xs,(~o\x08\xc5\x81\xde\xb5\xee\x03\xa9)xj\x90\x9a\xb1\xc6\xcc\xd6\xc0`\x9a\xc8\x8f\xc8\xa6I\xfb\xbf\x95\xb2o\x0e8\xc6\xe8\xf1\xe4q\xf6\xec\xd9\xd3Ci\xc9@\xf2\xac\xc8\xcb\xafx\xd7\xf1}\x94\xd8\xc1\x93d\xe1\x18Et:\\\xb7\xb0\xfaK\xe4X\x0b\x1c_7\xb6\xb6\xdcR\xca&\xe9\x82.B\x89\x95\x84\xa4~7@\xb9\x0e\x9a\xa8\xcb\xee\x9e\x0c\xadRF\xb0\x06%\x15\xbf\x83_\x87\x1e\x19i\x9cv\x17YEeZ\xc3O*XNUhO\xaf3\xc5_\x99\x91c&w\x1e\x01\x8cXG\xb4\xcd\x1dv(\x00\x19\xe6;*\x11S\x97\x9c\xc9\x88\xb2X\x1d\xc6\xdf\x16\xa7F^\xcb\xf5KH,\xa9j\x08\x04Q\xd0\xa0oLk\x08\xe7O\xfa\xd3\x02\xcb}f\x01\xf1zd\x1ax; \x17\xc1G\x01+"T\x18\xd7p\n\xac\x88&fT_\xa6\x16~\xc6\x85\'K],\xe5$$\tt=Z\x03%\xc0\x8b,\xa45B\xcf'
|
|
|
|
|
|
2024-12-14 17:54:52.094161 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 1589
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca83
|
|
###[ Raw ]###
|
|
load = b'\xce\x00\x00\x00\x01\x08\xf0\xe0\x0fd\x16\xe2\xe8/\x00@F\x00\xb8\x8e\xca\xda\xd3\x01\xfa\xf04\xb6\xcd\xfb\xc9w\x1c\xa7n )\xd5\x951ET\x9e\x02\xa9a\xf8<\x10\x1bp-\xa1\xa1\xfe\t\xeeB\xf5r:\x07\x0bpa\xf2\xa4\xdf\x82mR\x8ex\xf6\xbe\x7f\xb1\x11Bs\xe4Y\xc4\x94,\x00ID\x89a\x08Z\xb6W\x84\x81\xd9\xd9;D\xd3\xd1\xbeL\xa7\x01\xc6#\xec\x17\xa7\x98(\x1f1\x82]\x12\xa6\xb0s7/EpD\x16\xc1Z:\xdag\x00\xe6 \xb4R6\x174\x17>\xf5C\x8c\xd3\xb2\x84.og\xa2\xe7s\xf0q\x9c\xdc\xab\t\xe4u\xa6\xb0\xe2"\x0c\x0b\xe5\xfc\x00\xad\x9c\x97\x90]\xcb\xa5E\xc8e>\xa4qp\xe5\xab\xf7]\xc8\xff:\xd4\xb9\xd5V:\xb9\x07;\x17\x19=\x90\xfa\xb1_\x10d\x1e,R\x16+\xc6\xc8p)\x01\xbb\xd0<%\xfeUf\x91\xf7\x18\xe0\x94\xf4\xc8\n\x1br0\x1a\xda\x99\x9a\xf4u\xd9Sh\xf7/t\x93l4E?h:T\xf2y\x9e\r\x1d\xf8\x0f\x96\x95A\x1e\x85\xbe\xb4\x124\x92\x14\xc2\xd7\x1b|\x0f\xb2\x1d\xbe3;\\\xa7 t\x95i\x98\x9f\x95\x1b\x0ep\x8e+\x0e\x8d?\x94\xb2\x80\x19\xf9pG\xbe^\xc1+\xd9\xdef\xbb\xde\x98\x81F%hz\x99\x89+\x9d\xfd\n\\\xca\xde\x91.\xf3F\xbaX\x8f\xddh\xfe\xe1\xcf\xeaV\xa6F\xae\x0fk]\xfe\xa7-\xb8\x7fFC\x96\xb5\xf9\xddQ,\xad\xd3\xf4i\xf9\xa7\x98$X\xf4;a\x82\xed\xd8\x07cr\xb5\xa7\xcd\x98\xda\x17\x837\x01\x97Z\x8doF,\x03\xe3\x82\xf7\xecN\x81\t\xb5\xfe\x98\x8c\x8d\xaar_#{0dv@\x04\xd7G\x8a\xa2Mg\x1d\xd6&\xac\xdb\xe4/\xd5\xd9B8u\x03#?\xef\xe4\x85*\xe0o\xc0^)\xc1\xc1\x93\\)l\xa6\x90\xe2\x9a\xd0\x0b\xe6ih\xf8)5\xf6Jh+Y\xee\xa9\xb4\x1f\xaf\xef\xb4\x15xd\xc7\x9b\x07}%`\xf75\x10\xe4\x1d\x02\xb5~\xb8\x01\xdbZ\xb1\x0e\x184M\xde\xdf\xd7\x1e\x96\xd6d\xdd\xd3\xd67d\xd4 6\xbaG\x01\xb2\xfc\xdd\x86\xf9\x1a\xf1_F!\x8b\x85\xc4\x8bA\xcbD\x95\x1d\x04\xdc)WPB\xa5\x0b\xe0\xa1P\x8e.A\x03\xbd\x85K\x88\xe6!<\xce\x82\x00^\xeb\xd6 \x8a\xd8L\xc6\xc1\xbdr\xcb\x96\xfb\xfd|\xbd\xec\xde\xf7\x10\\\xeb\xd2\x81\x1a\xb5T\x88P"R\xc0\x04\xed\x06\x084\x9f\xe9\xa8\x1a\xc3.\x1f\xc0\xec@\x1d\xf0pH\x0b\xeda\xdf\xd9dq\xb6d\x04A\xa9\xba\xc4\x9d6d\x16@\x96\'\xe3M!&{/\x17i\xe5\xcb\x8d\x81f\x11I\xc4w\xb23\xba\xf4u\xb7\x0b\xad\x95\x16\xbcf\xa7*\x81\xcbw5\xea\xf3o[xT\x18{\xbeF\xfa\xb6q\xd6\xfdJ\xf2\xa5\xaejxOl\t)\xd4\x99]m\x99\xd1\x1d\xd6K\xe4\x0f\x16\x89\xc16\xc6C\xdf\xedt\xbe\x91\xaaI0]\xbbc-\xc4\x0fz\xe9\xdb\x90#\xe7\x8b!\xe8p\n\xd0\x99\xf5x\xea!\x83\xc9\xfbm\x10Ju0\x040j\xf2\xaaV\x90M\x07`\x9f<\xaa\x93\xd3\x857{\xd5\x7f\x0fX\xe8\xac\xf0\xc8\x98\xa8\xc4~\x14\x9fl\x12\x93\xe6\x1c\xa7=\xd4\xaa\xd2~\xe6\xcfH\x8b\xb6~[\xa7\xd7._B. fB\xf8\xe5\xaf\xdb\xe7\xd0E\xb7\t\xbd\xdb\x90]V\xf2\xc7b\x84(&|>\xc4\xc2H!\xd5-i\xeeX\xd4\xccN_j;\x10d\xea\xd9\xf6@\xf8\x03\x19\x07\xacP\x80\xb1\x84\xad\x10\x8a\r\x9dQ\xc3R\xf7\xc7NSd\tV;\xc5\xe5\xd7\x13\xbe.\x9e\x85\xaf\xd3A\xf3+g\x8e\x03\xa0qsY\x02\t\xae;]Q[\xb7ziV\x0f\xdd_d\x04\xd2C\xa2\xf7-oXZ?\xc0Ro\xba\xee\xd0\xcf\x03\x92\xca\xa9q|-\xcc\xcf\xa6|\x0b\xe0\xc4}\x9b\x02\x88\xf5o1=\x843\xb0\xf4\x9c\x8e\xef\x110u\x86\x8caP\x92\nU\xb2\xde\x9fRU\xea\x918Gu\x19\x8f\x0b\x154\x9cX\xaa\xaa\x05\x9e\xe9+\xc8\x9as}\xdc\xa666\xdc\x10.\xe3s/\xf4y\xf2\xa6\x1e\xc7\xb4\xe6\xfa9{\x96\xae\xdc\x07Z\xe1\xfbd)?U*\xb7I\xd1\xa1\x9a\x87\x01\xfc\xdf9\x8eL\x83\x86\x88\xb6\xc3iAo%\x89]=4\xd8VM\x16\xf9\x15\xd5\xf2\xe1\xaf\xf7fi\xfaqG)G\rI\x99\x1c\xb2#\xea\xafI\x0c!y^\xd4\x07\x96\xcc\xc0\x9c\x15\xf9\x9b\xcf\xc6\x18\xc9$Vys\x83\x1e\x90\xf5\x17\xbb \xad\x989ThAT\xd1G\x7f\xff\x9d\xb9\x9d\x1fe\x05\xd1\xb4\xa67\x1ay\x91k\x11\x16\xf9}\xd6\x05 \x08\x11\x87\x82\xb5[\x84\xaa\xe7\xa1\xf1!\x99*\x8e\xd8d\xb1\x14\x13\xaa\x89\xfe@\xeaq\x1c\x1f\xe2\xc6\x1bXi\xf4AA\xf0-\x17\x10\xca\xc9\x1c?\xa9\x1a&a\xbb\x03\x854\xeeB\xae\xc8C\xc0\x06\xdbb\xbbRBj\xed\xf4\x89\n\x8f\xb3>`\xf2\xd2\x12\xb5\xa3\xf3\xaah\x8f>x%\x12\xf9*\xa3\xbc\xc2qF\xca\xa6>k\\omx'
|
|
|
|
|
|
2024-12-14 17:54:52.101722 - Ether / IP / TCP 192.168.1.11:40827 > 35.186.224.26:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1041
|
|
id = 1590
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40827
|
|
dport = https
|
|
seq = 3115727526
|
|
ack = 1569492755
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xc98b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x03\xe4\xf7=\xc0\xfd\xba){\xb9\xe4);\xc0\xff\x9a\x15\x86t\x07\xc3\xcd\x1c\xcb\xfa\xd5\x1b}W\x0c\rZVg\xa6\x03\xd3\x8b\xea\x8aI|j2(\x14\xfb\x03+w\xa6+\xd2"\x92-j1\x15z-\x85\x08\x16\x97\x12 L\xa4?\xf6\xe0^T\xb7|\xac\xe8\xfa\xd6|\x10\xe6\'\x9f\xb0\xba\x97\xf6\xed\xf4h,j\xaa>\x90t\xc7\xd1\\\xae\xf8\xfd\x93\xf9I69\xdf\xaf\x1ew\xfa\x1d\xfe\x8d\x98\xecY\x151\xb6\xdf\x96\xde\xdc<\xb9G)S`n\xf5qsO\xf7\x021[I\x86\xefU<\x8d\xe0a,\xe9\xa3\xbb>\xa5\x8e\x12\x07\xdbV]\x93\xf6\xc4\x19&0\xdb@+\xa10\x98U<\x9f\xd52@\x039 3@4\xfd\xdf{nB~n\x0b|\xc7\xec\xe7\x89g\x94\x94`\xc1\xd0\xeb\x13\xd2Z\xb7\x05\xb9<\r\'j\x8b\xe9,\x0eNv3|\xf9>\xed6\x15\xd7)6\x8f\xf4\x15\xc9A\x9e\xbf\xde?\x90\xec\x1a\xadyF\xc65\x0e\x0f\xd3]\xdbj\xe8G)\xd5]\x90\xff\x19Q\xee\x0b\x93\x84\xda\xb6\xb9q\xef\xbaQ\x94\x9fb@\x1a.(\xe1Js\x81\',\xf4\xf8\xe26\x90\xc3\xf2\xcf\x0c b\x97\xba\x15\xa7\xea5\x88\xd6q\x00\xfcM\x9f\xcf\xcb\xc5\x1d\xcc\xd0.s\x08\xe2\xc5\xa4\xfa\xc6\xbe\xebE\x91KgHz\xa6\x90/1\xe3U\xd9e\xba\xe1\x10\x0f\xb1_\xa9\xf7A\x96\xccH,!\xc6\xcf\x08a\x16P\xd8\xf53M\x10\x05\x19\x9b\xce\xea\x18\x03\xdf.\xe0X\x0fEV\x06iV\xbd[\x1f\xb0\xa1*\xf5\x06c\xe6s`\xde%)\xb8)\xde_\xf2;\xf0.z\xf7\xe31hZ\x84f\x99\x8a\x9d\x19\xa2\xb5\xd1\x15*\xe1\xf0v\xe2\xf7\x18\xc3tj\xe3/\x02mi\xa06}CXa\x8c\xa4\x07\x8c\xd1\xf2\x85\xc5T\x9a\x84\x92\xd0n\x08\x82\x9b!D\xca\x17\xa2\x8cJt\x1e\x8a \x7f\x84\x19uL2\x9e#s8\xffqm\x8e\x86\xd6\x90\x1e\xf3o\xe1\xf2x\x99a\x8c\xef\x1f\xb9\x89\x07\x9d\x01\xa4\xb2AL\x9d\xb7.\xc9\x98\xc6\x1fMPY\xce\x19\xa3\xfd\xf3\x0f\xca&\xdaV\xb6\x03\xc3*:Z\x8f\xfb\x8d\xf8\x01\xf6sf\x88\xaa\xbd\xb9\xa1\x97\xfc\x171\xb8\x9a\x82\xa4x}l\xe1\x9e\xc6\xcb\xd0\xc4b\xb7\x1by\xc0t\xe2\x07\x9d\\(\xa6\xfe\xb1\\*MK\x9a#x UKXO6\xd8\x8dH\x9bY>lg\xea\x03\x9d\\N\x0e\x03\x9a\xc8v\xf7\xadE\x88\xa8\xf1\x13\xfcW\xf6o\x18\xf5\xaf\xd52\xf7\xf7a\xe5?\xa6\xac\xc8\xf9\x0c:\xf56\x9d*\x97\n\xb0\x96\xc0g\x87\xb4\xa0\xb5\x11\x95\'j^\xaaC\xc7\xb6/\x9a\xb6B#\x8d}e\xa1\xe7\x00Q\x7f\x8a\x9a\x08l\xa4\x83,Q\xbf+P\xe2m\xdd\xe5\x8d\x13\xd1JU\xa9w\x82\x8ce}\xb3A\xbe\xaa\xaa\x86w\x034\xffj\x8f\xebw\xae\xc2\xc5wlQ8\xbe\xe4\x8do\x83\xa9\x9c\x0cZ\xbd\x1e\xcay9\x16\xf6Q~\x87\x96\xda_\xed\x03\xb1\x94\xa7{\xca\xe4O\x03\xb2\xb9\x96\x01\xdb\xa0\xd3J\xea\x90\x9d\xf1\x91P\xabk\xf6\xe2\xd5\xb2\x1c\xdee\xe1\xbb\x1f4/^D\x8dcc\xef\x92rH\xc6\x93\xf6\x06\xb1\xba\xc6\\Z\x13\xe8\xfcx=B\\X\xe8\x8a\x80{\xae\xdb-\x8a\xf8}\x1f\xcbg\x9b\x8c;\x18\xd0eR\xc2$\x98a\xb7\x17\x83\xc8\x84\xd0\xda^|<v\xa7\xb3\xdc0&\xa6\x1b\xbev\xc0\xc19\xf9\x98\xf2\xa1\xda*[\xf4E;\x7f%\xf2Kb]tu\x90\t\xf74\xb9e\x83\x0eJo\xe5\r\xd0\x07\x0c\xb9\xa0i\xbb\xf6YA\xa1~\x90\xd96\x8b+\xd3\xb8\x1c\xa9-\x92\xda\x1f\\\t/\x86$\xe2\x8b\x14\xf7\xda\xbd\xed>u\x86\x87\x13m\x9eS\xce\x93\xc3\x15\xf52\x05\x8b\xf6\xbdS\x08\x05\xb0uu\xa6\xfc\x7f\x0f\xe4\x17\x0c\xb1d\xca\x86p\xa0\xf3\xff\xd6\xb2\xfb-f\xe5\xc6\xb6\x0c\xa8\x8a\x048L\x87\x11\xbd\xf9\xae\xca\x98\xa7\\V\x8c\x82\x1d\xf9\xe2\xa5\xf9\x06K\x91:Z\x18L>'
|
|
|
|
|
|
2024-12-14 17:54:52.107373 - Ether / IP / TCP 192.168.1.11:40827 > 35.186.224.26:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 1591
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40827
|
|
dport = https
|
|
seq = 3115728527
|
|
ack = 1569492755
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xc5c9
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"&\x1at\x83ayGQ\x90\xf9\x1a\x9e\xeb\x14^\xdc\x9e\xe9\x9f\x01\xcaf\xbevP\xc1E\xcd\xefOI\xa1\xfa\x87'
|
|
|
|
|
|
2024-12-14 17:54:52.114621 - Ether / IP / TCP 192.168.1.11:40827 > 35.186.224.26:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 1592
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40827
|
|
dport = https
|
|
seq = 3115728566
|
|
ack = 1569492755
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xcb26
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x11\xe1\xfc\xda\x93\xc8\'\xea\xca\x9a\x92\x07\x80\xd6\xb3\xf0T\xd2\xcf:$W\xb4\xf9]AQZ\xbc[\x1e\xe3X\x12\xba[\x11\xb2o\xa4\x15XH\xb6\t\xed\xbb\xf4\x11\x9d\xcd\xa7-\x84e\x81\x05\x9c?$:(W\xd71\xcd\xc0\x9be\xd8B5\x7f\xd0\xe34}\xcf\x01\x03K\x06\x8d\xfb\xf7\x11\xca\xdf:\x0cCn\xe8\x9b\x11\x95\xb9s.<P\xe6\x80\x1e\xddc\xb8\xc51\xd1!\x0b!\xa5\xde\xdcf\x81R\xfc\xa5\xb4\xb9\xceJ\xa6\xda\x88\x06\x8e;\xcd^\xe2H&v\x8e\xf5\xbb<\xd7NE\xc4\xc7\xd1\x83\x82\xf6\xc3\xd1\xd1j\x01\xe0Zn\xbf\xe9\xf6\xfe\x15\xa7\x90\xc4f\\o\xd1\xf7\x06\x89\x995C\xef"5j\x87\x05T\xa4U\x8d\xbd\x18\xbah\xea\xba\xb1\x8f\\\xa3\xe2[\xd8\x14\x89\xe1@\xc2\xa9\xc4\xc40\xba\xbc$\xbe\x93\x926\x18\xa7\xef\xed\x91&\xfb\xae\xe0wb\xd1LV\xf8\xa7\xe0\xba\xd0Z\xcbe\x05oF\xba\xab\x8d\x07\xf1_\xcd\xf7%;\x97\xbaN\xf4EZ\xa2%\xb3\xe2LQ\x80\xa5h1\xfaz\x14\xb7\xf8\x91jh\x05 \x08Y\x0c\xf6K=\xda\xfa\x93\xee\x85\xbfU\x94\xad\x90\xd4XV\xbe\xab\x002\xc7s\xba\x10\x8a~\xe6\x05\x9d\x82bdG\']\xca\x179f\xd9\xb7U\x12xz\xb5\x1d`\x05Dawd\xf4\x04=R\xd8?\xf6\xc0&|y\xa5?a\xd1\xbd\xaer\xf7r\xe5\x7fh\xe2k\xb9,\xd3{\xc2T \x0fQ\x000\xfbt\x8a#f\x8e\x9c=\xd0\x7f\x0e}\xd5\xc4}\xf3A]\xbc\x97\xc2\xb7\xb7\xebH\x08\xbf\x1dc\xd5\x83}s\xac\xc0+\xf5\xdfJ\'\xeaN\xe9\x1f[du\xb0\xb3\x98\xf3\x92S\x161q\x00\xaa\xfa\x84\x9eqZc\x03 \xbc\x13\x05\xdf\xb3;\xef\xe9G\xf6\xde\xcd\xf7\x18e9K\xf2\x199YDZb\xec\xddZ_\x88m\x8dB\xec\x02\xabh\xe1\x965\x88\xea\x9d\xbeX\xac\xea\x1c\xd7\xd1\xbb\x13[j\x9c\x17)!87\x93\xd7\xd9\xf6?\xc5\x0eY\x89\xb9wL\xa4\xa5\xb6\xcay\xe1\xcb.\xa6i\xc3\xf5\x9fX\xae\xfb\t\xed\r\x7f\xdbII\xa6\xcbZI\xb8\xcd\xa50\xf5\xa1\xc7\x1c\xa0R\x966\x04d-P\x9d\xb1-\x08h@\x14\xab\xab\x1d\x98\x1b\xdd\xbdQ`OnQ^\xb6{R\xdc\xad\xc2 \x82_\x0co\x0c\x96\x8a\x7f^\xe9*e\xba\x85\xa4Rdb\xf1/\x95\x06\xd9\x1cl\xe7w\xa3\xaf\x12\xce\x10\x86-\x0f$3h/\xe0(\xa9\x9aY\x19\n\x83\xa5\x8bv\xcb\xcb\x1b\x04\x96q2\x18dG\xd3\x18G\x95)w}\xc9ll\x19t\xcfA\xb3Fgq\xc3\xf2 \x95\xc6\xfc\xebl/\xa3z\xab\x1a\xe4\xeb\xed\xde!\xc2\xf0\xeae\x1a\xbb\x15\xf0F\xfb\xf5\xd2\x9e\xa5_\xaf|Wi6\xff\xe2\xf7c\xd5\xb2\xa7\xc0\x98\xda\xa1\xcb\xb7\xf9\xa5\x11E\xac\x02\x9a\xc5\xb3\xe5\xc2u\x1d5\xc1|\xe3\x90\x0b\xdf!\x02\xb1\x9b\xad\xe9\x14BT\xe3\x90\xef\x07\xdc\xde\x12\x0f\x04D\xb4c\xb6\xe5\xfek\x11\x96\xf4\x87H\xb0\xf0U\x96\xda;[<%Lc\xf3+>M\x9f\x94M\xe9\x9c\xd4u\x90k\xd7\xad\xe7\xcct\xcd\xbb\xf6W\x03\xf2\xed\xb1\x17\x1fmTp\xe8ZHB\xbdCz\xc8v\xd3\x94h\xffj`\x98k\xd3\x885p\xfb\xc8\xd1\xb1"V\x15\x8c\xac\xfec\xa6A\x18\xb82\xb8{\xba\xeb\xa5\xa2\xca\x08F=\n\xf0s\x8b\x04\xdcw\x86sW\xd0\xf0\xdf\x1e\xa6\xb6\x00\xeb\x13\xe0-\xa2\x9e\xfbv\xbd\xaf\x0e\xdd\xd3\xad\xa6m\x00\t\x9a\x1c\x8d\xeb\xbd\xca^}\xf32@O\xa0\xe6\x85\xcc\xd83\x8f~\xdf\x08\xf0\xb9\xf2\xd7Y8\x00\xd3\xac\x11gP\x9c\xcdZ\xecsb\xe1\xd8U\x1eQ\xd2\x02\xd4~\xaf:-a\x8b:\xd0C\x87\x88\xf5\xb8\xf4\xa6\xb2\xbc\x89\x91{\xd3\x90\x0b4\xb9\xac\xc7\xa0p+\x07\xe1\x8f\xd0P\xee!1\xd9\x8a\x9f\x01\x12\x0e!f\xde\x8b/\x89\xae\x81\xdf\xecG\x8b\xa1@\x80\xfcj\xa2\xefg\x1e\x1a\xcd\x14\xcb\xe0g\x1c\x0b\t*\\\xaa\xeb<\x912\xe3cd\xce\xf2|Ska\xb4m\x80\xd9~\xdb\xfb\xa5\x0bDFlqY\x94\xe8\xe6-o;\xdc\xab/x\xc2\xec\x8aj\xa9\x19\\\\\xae\xb1"\xea\xae\x92j%)\xe3sM"\xc9Rii\x02EO@D\x89\xf0\xfb1\xc0S\xd5zU8Zv\xc5\xcdy\xb3\x99\xcc\xd8\x15\xa5f\xdc\xa8\x1dr\x91b^\xac\x9f\x01\xac\xa7\x0b\x07\xa7\xab\x8f\x96\x0f\x91b\xea\xffb<\xc4\xb6\xbc_^\x0e\xee\xbah\x08\xb3-\x01\xe9t\xd9\xdd\xbd\x07\xc7d\xed*\x84\xf5\xd2\x86\xee\xb3[\x8c\xf4\x88\x8d\xb8k\xd7Q\x112\xbdk\x0cM \xa7G\xea\x93\x8e\xf9\xc8\xb1\xf3\xccc\xad\x188\x89\x1aR^\x9dZ\xd2\x17\xfc\xbbH\x8e\xaf\x04l\xda\xb4\x895\xed\'b\xea0\xbb\x00\xc9\xc4\xa0u\xb4}KT\xf8\xaf\rk)\xceB\xb1\xcf\xa3\x9b\xe1Q\x154\x97\xa5$I\xce\x88M\xca\x92m\xc3#\xadJ\xc9L\x15\xa16<\xaa7\x8c2\x17\xb6\x01&<\xf0\x96\x9a\x00!]\xd2\xdc\x8d\xfe\x0e/l\x9f\xf7\x0fg\xfc\x91}\ty\x15\xd3?\x94\r\x9bud\xf0\xd7\x8a\xfc\xbd\x9e\xb0\xb9m\x05\xa3\xaa\x9eu\x0e\xfa\x1d \x02\x13r\x14\x1b\x8c\xca\x89\xceN\x99\x82I\xc9g\x00\x03\xdc+\xb2@K>\x1f\xd8uIe\xc7\xc1T\x19\t\\\xf8\xc6\x89\x86\x98\x8eL\x17\xbc2\x15\xe8\x87t!\xce\xa5t\xdcI\xba\xf0OU\xe0\xb9\xbdN`\xe1=\xf2\xc7I%v^\x8a5L\xda\xca\xbeZ\x1c_\xbb\xe4\xb4N\xaffXc\x96\xb1_\x1e\x92\xd9>\xcb*l\xd7\x13\xb0=\x8d\x81\xa6}@'
|
|
|
|
|
|
2024-12-14 17:54:52.123463 - Ether / IP / TCP 192.168.1.11:40827 > 35.186.224.26:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 1593
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40827
|
|
dport = https
|
|
seq = 3115729978
|
|
ack = 1569492755
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xcb26
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xbe\x7f\x9d\xea\xe7:\x0e\xb4\xee\x08\x9d\xfcx%qw!Pz\xfc4\x81b\xd8Z@\x04\x01U\xf2=z\x8b\x13\xb4sSNn\xbdr\x0f\x02\x90N\x7f\xdc\xc8l\'W\x7f\xb4\xcf\x0c@\x08\xdd\xb6\xed\xcf\xed9\x9e\xce\x8f{~\x009\xad\x1d\x19\x0cb\xc8j]\xbd\xb4\xedr\x88\xc7\xc1A\x88X\x9ca\xb2N$\xc5=\x8c\nN\x93\x14\xe5`\xbbK\x8c\x85 J\xf35\xefH-\x8c\xfe\x0c\x18\',!\x9e[\x9b\xdef\xc8u\xbb\x7fjt\xf9\r\xefO\xdcf;\xd7\x8b\xb1\xb0\\\x1e\xbb\x11!\xd7\x04-\x8a8p\x15\xe8\xa5\x1c\xe3\xe4d"\x83\xc8\x19t4\xe2\xdc\xdf\xab\xc0\x9d\x08p\tm\xec\xa7\x0c\xae\xbd\xbc\xc7~\x98\xf7gY\xb8oo\xda\xbd\xcej\x96\x80u#\xfd\xae(Q\xa7!\xb6\xb4!\xd8\x98\\\xb8\xe7\xa3U\t\x1a\xdcL\x84\xb9\x1b\xb0\xee\x100\x88\x10U\x85\xc0\x89R\x1b;R\x11s=\xa0&l\xffU\x7f\xb6\xa1\x83\xc1\xc3\xc3ZkC{\x12\x9a\xebo\xc1\x98\xa1U\xf8\xe6\x08?\x0eA\x95\xed/8\x94\xda\x82\x01{\x12\x0f\xa5\xaeO\x82\xd8\x99\x91\xc7\xcf\xed\xfa\x9b\xfb\xbe7\x84\xa5&%\xe23V\x0c\xa5K\xa0\xe7\xfe\xc9\x8c\xcf\xb3I(\xae2\x12\xd1\x0e5\xf6\xea\xebx\xbf\xad\x88\xd3(`\xf1\xec#\xccM\xb2\xf5r\x9db\xb0\xbe\x87F\x8fz\xc2\x07{\xaf\x99\x7f\x85\xc7`\xf2\t\xa3e\xda\xe5\xfeX\x16\xbeBx\xda\xb3QA\x1b\xb0\x93>\xbc\x16Uv\xd2\xed\x8b\xcc8{\xc0\xb0\x98\x8f\xf5\xb4\xb1\xd7\x88:[\x81\t\x14H\x8e-\xaa\xf8\x81\x81\xcd6\x1c\xf7\xcbi^\xf8q\x7fM\xe8G\xef\xb2W\xb8A\x8d\x04\x17e\xac7\x19\xd9\x92\xb9?1F\xb2zl/\xe8\xc3}\xcd\x89\xe2\xf2\x15\xeeX\xc8r:\r\xe3\x10\x97\xafg\xfe\xab\x89\xdd\xa3\x80ht\n$\xd6\xda\x1a\xd4\x0e\xfe\x8c\xb5\xeb\xd0\x89\xa6\xe1\xe4\x81\xf1\x00x\xce3\x943\xdd\xbcY\xe4\x17D\xe2\x1dNI\rM\xce1 \xbfW\x08\xa1\xe8t\xff\x88\xc3\xdd\xbf\xe2\xaf\xd2\xd5\xdc\x9c\xb9=\xa8\xed\xcf\xcf\xe6T\xb5\xeeo\xf9\x08\xd4\x08\x95\xd3\x97\x93\x86\xf6\xb7\\\xaa@\xc4\xa4\xa4\xa6\x0e\xecH%C\x81\x96\xb7\x8b\xd6\xab\xd8F\xf1\x97\x1cl\xc5\xf3\xefL\xd0r\x86\xe5O\x0c\x18\xddb\xd7D.\xb7\xeb\xe2\x8c~i\x1bj\xfe\xbd\xfa\xe6\x1et}Zc\t\x8b\x1b-5\xa4\t\xb7\xb5\x15WU\xb0\xf5s\xb5_D\x0b\xbb\xa25\x1a?\x0c\xc4\x06\xabv\xe6e\xc4\xe3\x85\xde\xc6}\x8f\xa03\x8e\xf0\xf3S2\xa4\x93i\xaa\x1f\x9a:91\xf8\x0e\xeb_\xbaF\xa4I\xdf\xb8?\xd7\xe9\x87\xeayg\xb9o6*X\xfd\x05W/.$\xfaV}\xa7\x8b@` w:7s\r#\xec7^7\xa7\xfd8\xc2\x1a(|\x1a\x94\xe4\xf8\n\x9cr?\'*\\3\xb0L\xae\xea+\xfaSDs\xe34|k\x1d\xf4\x83\xe7\x89y\xdfm\x1f\xfb\xcb\xf5\xbc\x15\xb3m\xea\x83\r\x963\xa3tB\xb6iU\xc1F\xa0+\xfc\xfd\x1f\x96\xc2V\xf1\xce\xf1\x93^\x02\x89\xaad\x1e4;o,\x1c\xb5\x01\xb9Q\xd3\xbc\xf6\x99\x939\xdc\x03?\xe1\xc1\'\x90\xf83\x06\xaefU\x80R\x85*\x7fG\xd5\xd45\xb5\xcd\xcfQR\xdd\xaa{\xab\xd0\xd2\xfe\x14\xf0\x83<)\xbc\xb6\x9dG\xc04\t,iP\xd1\xa8\x0f\xa0\x9f\xc4Tw$\x97\xf4u4&\xfb\xed\xd3\x87\x8eN\xe4\xa6p\x0b\xb3\x88\xd4\xd6\x94J\xe0[\xcb\xeb\x8a\xe8\x8d\x1b?e\xd0\xa2\xbd6E\x8dI\x90\xc8\xb2x\xa9,\x92~\xce\x11/\xb7Ol2F=\x82\xa7\xff@\xd1\xf2"\x15\xeb\xb8\x9c\xff\xd2)V.\x9c\xb6\xac~\xf1\x83Wr(\xca\xac\xb8\xb5\xb1q\x8c\x0c\xa9\xf2\xf7,\xc0e\x97\x16\x81\xa3\xea#g\x10\xc0L\x15\x0c\x15\xe3b_\xf1;\xe7\xc6\xdaf\ni\xd1\xf1\xf6\x0c#AO\x11\x01\xc8\xb6CeC\xbf!\xc5\xa7h\xcf\xe1\xd4B\x1a\xae\x8e\xefh\xfa*\x82\xcb\x0e\x0c\x0f^\x8a_\xfd%S.\x04\xc9\xed\t8\x9f\x95z\x9c)8\xc8c\x15\xc9\xc7\x97$_\xa3N+\x9e\xd0\xd9\xc1\xf7\xad\x93=\xf2f\xa7[\x15\x0f\xbd\x06\x19^\xd0\x16"\x10\x8aE_\xabP\x05\x9b\xca-x)\xc0\r\x0c\xe12C|P\x1a\xd6m\xa0\xad`\xa1\xde1"\xa9Hs\xea\xf5*]\x1a\x97\xd1\xf2\x19\x12x\xa2\xf4r|\x8e\xd3gA\t6\xea\xf2/9\xf0\x1aZ\x86K\x1bs\x979\xa9=\xa3\xb5\x85\t\x9c\x8a\xb12\xea\xce\xa7iJ\x07)5\x95\x87\x0f\xd9\xc7\xbf\xcc\x97\x0f\x08\xe1\xa2\xd9\xd9\x87\x86\xb3E\xe5O\xb3\xa6\xd3G\x05\xae\x8bH>\x01"\x11\xa2=J\xd5]\xe6\xbf\xfc\xc9\xa5?\xecPWS\xf6\xf1!\xb9\xaa4\xf0\xaca\xf6\x01=\xcfq\x9a\xedR\xb5\x0cN\xfc?\x10(\xb1`\xf3Y8\xd6c\xb4\xfb\xa7ey!E\xebI$\xea\x80\xb9G\xde\x8a-\xe4e\x02\x1e\xaf\xebg\xc1\x9f\xcbg\r3\xe1\x96\xddn\xb8\xfd\xf7\xb8\x8a\x1f\xf5\xcd\xaf\nU\xd6"\xb0\xd7\xd7\xcd\x10K7\xadm\x0b.\xc1x@\xd3\xa5\x8d\xe1U\x9d\xc2Q\x10\xd6\xca\xe6\x18FLs\xef\x17\xc0\xc2s\xcb\xe1\x7f\xb8\xd9\'\xde\xbcc\xe6\xaf\xd8G\xe2DQ[\x88\xf5\x1b\xc2\xa5L\xeb\xdfJ}\xc4\xf9:\'q\x05\x00,p\x08"\x1f1X\xd8\xb9u\xb1*+\xe2+\xfbi\xdb\xcd\xabC\xd5\xeb\xf2\xf4\xb5\x9f\xc6*\xb5\xd6\xb8\x96\xb64\xaeo\x80>\x9d\xa2\xe5\x1e\x8bX\xe8"k\x89\x04\xe0h\xe9Bs\'J\xe1\x92\xd0\xd5\xde(\xce(\xd5\x83\x9b\xa4\xa9Pw\xe2\xac'
|
|
|
|
|
|
2024-12-14 17:54:52.130020 - Ether / IP / TCP 192.168.1.11:40827 > 35.186.224.26:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 1594
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40827
|
|
dport = https
|
|
seq = 3115731390
|
|
ack = 1569492755
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xcb26
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x8b2\xe3\xa7\x96%B\x98x=VK\xb6\xf0\xd1\xfe\xbc\x92\xce2\x18\xbf\x91Z\x85\xe7\xef\x9d\xff\x0b`\xa4\x0c\xe3\xf9\xe0\xca>\xe0\x8b\x8c5\x91\x80+\xd5\xe1\xc2\xeb\x16\x8b\x97\xed<\xa4\x187\xaaB;`\xcf\xfd\xd4\xb9v\xd0\x85\xb3\xc0Z\tbL\xfbu\xbe\x9c+\x86\xabF\xa6\xb3\xb5\xae\x8caIP\xd3h]\xd0:VX\x95\xd7\x0b/=p\x8f9\xaf\x1f\x0b\xaez\x9c\xb4\x91S\x08\x1f\xc7\xb7@\xfc\xeb,\xa5E\xb9$\xad\x0f\x9b\xb8\xf9\x85f\xde\xc5\x1cX+\x9d\xbaFy\x8c\xb4{\xce\x1bQ\xc4\x12n\xce*9\xfamo\xcb\x9a\x9e\xc4bw!\x7fQ\x00\x98\x84\xa0K\x7f\x067\xa6\x90\xfb\x9f+\x10R\x0e\xf4\xfaWF\xf9\x14\xcf\xa2\xd2C\x8d^B\x0e\xdd\xeb\x03A\xd3\xdd\xf9\x8f.RT\x9b\x1f\xfeu\xe0\xe2\xe5\xb0\'m\x01\xa5\xb7\x94\x8f\xf5\xacj\x01\xbe\xadK\x98\x88\xdbo-t@abKFY\x8d\xfb\xd7\xd3B\x06\xd8\xa5g\xde\xba\xaa\xf2\t\xa5/a\xc1\xf8-\xa7\x17\xdf\xf5@*B\x04F\xa64:\xdc6O6\x9fe\x08\x86\x1f!R\xe6x\x9a\x9c\x94J\xdf\xbe\xbdNM\xf3\x05qv:\xf4\xf8\n\xfc\x01\\\xd8\xb4cR\xe3\xa5y\x9fU\xfc\x10\xd8l\xbf\xd8NXZ\xd3z\x08\xfe\xa7\x88Nr\xcd\xfa-\xd8(\x12\x19g]\x93SDA\x89!\xe15?\xbd]?\x94\x94\xcaE_\xe8\xd1yE\x14 !f\x8b\xc5\x90\x1aS\x02DY\xe5\xec\xcc\xd3\x85\xc53\x137\x03A\x08\xaa\xec\x98_\x9a\xf32L\x81\xd1\x0ba\xc8\x83\xd9\xc0E\xce\x82\xd4<"D\xd8\xbaah\xa7\x9a\x95\xfc\x9b1:\xb8\x02Dj\xb2\xa5\xa1\x1f\xa8\x19\x1a^\x8eI\x01\xb5\xd0\x1e\xd6\x18\xa7\xf0\xf0+\x84+\x9f\x86\x9dk\xa4\xf5\xfd\'\xebQ\xc5\x05k\x97\xac\xa2\xf0K\xb3(Rk\xf2\x93KK\xc1\xd0\x0c\x96\xb6\xe0\xdb\x01\xe3\xfd\xe2R\xb1\x8f(\'\xea\xbad\xda\xfa$\x07\xd3\r\x19\xa4I4m\x8f@\x1cy\xc9\xde\xbeg\x06l\xc6\xb3\r-\xfa\x01\xbc\x07|\x07\x99\xf8\xd2\x9c\xc4\x1a\x81<\x9f\x83cR%:.\xab\xc1\xdd\x8c\x07\xdb\xe8\x05\xa5\x08\xe9Sb\x96\xe5[\xb9\xfc\xed\xac\x8az:k\xdf\xff\xe9G{6E\x0b\xc1\xdfU\x94f\x8c\xd4~O\xe0\xa8\xeb\x1f4\xb7\x07\xbd\xcf\xb0S\xa7\x97\x83\xb1\xf6\x16\xa0L\xe8\xe3\x11\xd4x\x19l\xc8p\xdc\xaa\xcb\x07\xcb\xc2\x1bk\xae\x9f\xf8\x83\x1a\x12\xf4\xc4\x82\x19\xab\xe9\xe5?m\xd6\xa0\'4\x9fi\x1f8\x90{+\x15\xd7B\xf3\xc7\xbd"\xd9\x03\x17\xbeg]\xe8(4\xc7\x83\xa1\xf2\xa5\xea\n0W\xae\xd8M](]\x903gg\xc2G\xa14\xe9\xf0\x99)\xfe\xb8k\x818r\xca5\xae\xc08\xb0\xbc\x16\x9f\xef\x9a\xfd\xcc\xce\x16\xfe6\xa2\x15\xba\xf7*rJq\xb1\xbf\x93\xd9\xd1\n\xd4\x1d\x82\x13\r\x05"$\x10\x8a@\x14\xef\xfe\nF7\x8ei\x8eq\x85\x8eP\xb2\x99\xb2\xff|\xdfj|n\xbb\x13\xe4|\xd1\xe2\x80\xe5\x15\xaeejl\xb6*\x83\xa1}2=\xe4\xbf^Q&\xfco\x82\xdas\xf1]\xb5|\x06\xb6\xb7\x13\x8e\xf3\xe2:\xc7\xfc\xbbl\xe3\xf4\xd9\xf2\xf4\xdd\xcc%\xf6\xbc\xd7\xfc\xe8\x0c\x02U\x1b\xe3\xc0\x90\xf9\x9d\x9a^{\x82\x1a@\x18\xee\xb3\x81\xcf4)\xf8\x86\x8d\xd4#\xe3\xf7$\xbf!fa\xa0\xb9\xb7DM\x89\x94\x8a\xb0\xc8\x1ae\xd5\x7fn\xb6\x8f\x7f\xae\xc5\x952>/\x801*\xad\x1c\x0e\xac#\xdd;\x9cG\xa08\xa4\xf7Iy\xfb\xfc+\xd9\x02K7\x81V\xc2\xb5\x96ZmR\xbe\x08\xdf\xb5\xd1d\xf60\xee\xc4\x9a`,\xfc\xf3\xbf\x8d\x8c_\xc6$\x14*c\x1e\x11\x90U}\x1d\xbf\x93\xc8~w\x9d\x19\xc8Q\xac|h\x03\xb9\x93\x9e\xc1\xe6M4v\xafx\xc6\x12\xd35g\xd8\xef\xc1\xad\x08\xd6\xbe\xde\x03\xdb\x83k\xe5\x1a\x88\x86\xab\xdb\x13\xed\xf1/A\x84\xfdm5<4\xfb\xe0 \x11W\xdd\xc3<\n\x9bItN\xc3P\xdb@%\xa0EATk8\xca\xa7\xc3\xf3\xf4/\x01\x147\xbe\xba\x1d\x16yt\xcd\xe2\xbfX\x86\xda\xea\xdf\xecje,#\x1a\xfbf!\x96O=\x01\x8c\xe4\x95\xad[\xa4i#\x8cZY\xc1I\x1c\xdb\xf0\x06~\xe8\xf0\x89th\xec\x8e\x02\xee\xa5{H~\x8f\x9a\xda\xd8\x00\xb3\x1ap\xf07\xa1\x88#\xa1\xbfp(\x9a\xc1\x0bT \x89~\x80QN\xb9O\x1e\xb8\xcd\x08\x1b\xbc\xd2u_\xcd\xd5\x12\xea\x81j\x9a\xda\x05h\xa7\x88\x1bq/\xf4G\x98,\xb1g\xa9\xc5\xbb\xa8\x0b\xa9\xe0u9\x9d\xf7=\x7f\xd6\xdd\x8b\x0f\x13\x8f\xf7zY&\xbc6<\xc0"\xea\xf0\x0c\xabx@\xc5\x052\xb8!\x14\xfe\xaf\xd23\xb5b\x83\xf2!4\x06\x96\xeeX\xc4\xa6\xdf\x85\x87<jrN\xb7nuZ_H\x14p\xf6?\xf4}\x85\xaf\xc30^\xa8\x07\xac\x1a\xbb-V\xf7\xc0\x17_\xde\xeaF\xf7_\xf3d\x88;\x8c\xb9\xd4JL\x9c\x02\xbd\x99\xd2\x14\x1cVL\x03\x06\xeb\xab\x8f\x8f\xe1\xea~\xab\xff\xd3\\\xb9s\x145\x88_\xbf\xea\xc4\x16\xbe\x17+\xf1\x89?\xfdL\xd7\x1a\x00\xb4\r\xea\xa9_\x85\xb4\x97\x0c\xed_M6\xdf\xe2\xf7\x93\x98\x98\xbfn\xb6\x0c\xaf\xed\x82\xba\x82\xf2v\xee\xbb\xba\xd6\xe5$\xe1\xca\xb9\x8b\xd9\xed#S\xdd\x01\xc6\xb2\x87k\xb9\x84}\x88\x1d\xa2\x81\xb0\xe79\xa6\xdfm\xa1\x1e%\xa7\xe7\x87\xb2\x177\xcb\xd4\xd3e\x96]\xbe\xfedZ\x81\xaf\xf9\xb7\x97I\xdcw\xe8&\r\xb35dV\xa7\xb1t\x9f(\xd9\x14\x1f\xad\x87\x8c\xf2\xe48b\x9a\xd2\x19<\x1a\xc6\xd3Zd\xfbZ\x9c'
|
|
|
|
|
|
2024-12-14 17:54:52.134178 - Ether / IP / TCP 192.168.1.11:40827 > 35.186.224.26:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 386
|
|
id = 1595
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40827
|
|
dport = https
|
|
seq = 3115732802
|
|
ack = 1569492755
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xc6fc
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xf3\xa3\xe5r;J\x1fF>\xdb\xc8M\x91\xb0_\xc3\xf7G\xcc\xac\xbf\x84T:\x0e\x11\x1d\x851n\xb1\x0c\x91\x00\x98\xd5Q\xe0\x94N\xfd?e\xf9j\x1e\xae\xea\xc1\x9a(3tC\xea\xa4\x16$\xfe\xd8\xce_\xfa\xd9\xf3I\xbf\xadO\xff\xbc\x00y\x12\xa6\xd6\x10\x1e\x86:+~;\xa8\x96Y \xdb\xdc>\xaa4\xac\x85\x10N\x9a\x02Z\xa3\x15[\x1c\xfc\xefG\xcd_\x07\x16L\x1bW\xbc\xe3\x92bC\xe9\x8fM\xd1k8W\x871\x9bb\x95\x0c\xef\x17\xea\xde\xf3\\x)t\xcbal\x12\x82+)\xa7\xc2\xebr\xbddq\xc9\xfe\x1b\xad\x9e\x8c\xa4\xc4C\xaf\x11w/B\xa7fd\x8a&xv\xd4\x97\xb3N\x07`\xe8O[\x1e\xd3\xe9N\x02\xdb\xaeC,s\x82N\x035\x1b\xb7\xf9\xda\x98\xee\xc37\x00T\xa1bI\x1e\x8d\xfb\xeeo_lyG?\xcd\x8b`Z\xa0H\xb5T\xcew0\x01\xa8\x9b\xd2\xd4\xfb\xbf\x8a\xa4\xccj\x166>\x8e\xe2\x1f\xdcY@z\xcfta\xde\xdd\xe8\x05\x98\xf2p\xf7\xc5\xbb\x03\xc4\xbf\xe9\x84&\xd3dX\xdb\x1fq\t\x99\x06\xae\xff\xac\xba\x1d\xab\xea\xe6\t\xde\xc2\xc9&\xfda\xef\xe0\xda\x1c\xa7\x8f5\xfe\xf0\xe2\x8ahn\xfa.i\r\xb8 \xa9As\xd3H[\xf2\x12\xc3\x9c\xbb6\x1eW\xa0i\xb5o8@\x81s:w\x9f\xd3\xcd2\x9b9\x85'
|
|
|
|
|
|
2024-12-14 17:54:52.138114 - Ether / IP / UDP / DNS Ans b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 174
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb6e2
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52969
|
|
len = 154
|
|
chksum = 0xeed9
|
|
###[ DNS ]###
|
|
id = 13941
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 1
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'gew1-spclient.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'gew1-spclient.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 178
|
|
| rdlen = None
|
|
| rdata = b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
\ns \
|
|
|###[ DNS SOA Resource Record ]###
|
|
| rrname = b'dual-gslb.spotify.com.'
|
|
| type = SOA
|
|
| rclass = IN
|
|
| ttl = 464
|
|
| rdlen = None
|
|
| mname = b'dns1.p05.nsone.net.'
|
|
| rname = b'hostmaster.nsone.net.'
|
|
| serial = 1647020872
|
|
| refresh = 43200
|
|
| retry = 7200
|
|
| expire = 1209600
|
|
| minimum = 3600
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:54:52.142861 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7e21
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 48
|
|
chksum = 0x244f
|
|
###[ Raw ]###
|
|
load = b'\xc9\x00\x00\x00\x01\x00\x08\xf0\xe0\x0fd\x16\xe2\xe8/\x00@\x16\xde\xf3\x02\x8d3\xc2$\x01\xc2A\xe2\xe2\xfbN\xeb\x15\x10\xa5\xaa}M\xff'
|
|
|
|
|
|
2024-12-14 17:54:52.150010 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7967
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 1258
|
|
chksum = 0x8e7a
|
|
###[ Raw ]###
|
|
load = b'\xcb\x00\x00\x00\x01\x00\x08\xf0\xe0\x0fd\x16\xe2\xe8/\x00D\xd0h\x0b`\x18\n\x9b\xad\x98Q\xc2\x90\xed\x81A\x16x\xa5\x8d\x91r\xd4\x8e\xc64\xd7\xc8\xe4\xc1\xc7\x9c\xdcX\x01\x1d\x0by\x8d\x14\x11W\xe9\x123\xf6Fo#\xca\xec\xe4i\x9e\xe2\xc0\x8a\xce\x05.\xab\xc3\xa5\xe7\xcf\xa8N\xc0\xaeI\xfe\xd3\xca\x05\xf1$\xa3[1\xa2\x05@~iZW\x98\xafL\xb4\xe3\xef=vz\x80\xac\xc21\xcdc!\xd3\x97+NlI\xfd\x89mU\xfb\x06$\xe2\xdf`r\x8b"\x17w\xf8\x86_\x19\x13\xc9\x92\xad\xa2*\xcd\xde?\x1f\x82\xcc\xe6\xff&\xd6b\xef6\x12\xbdBQ\xf5I$\x15\xed~Hjw\xe5\x87\xf6\xfa%f,HU^\xfd\xaa\x00P\x0c\x14\xe7\xbeW\xd3\xb4\xcd\xe5;\xe64Z9\xd5\xaf)\xe1^\x8e\xde\xd0]g*\xf6\xba\xc4\xcb\xe6\xe2\xc8\xd7^t\xbd]\xfe\x1e\x03\x81-0\x99\xe5\xbfa\xad\xd9\x99\xb1$=\xfb\xda\x1c\xe3\xd5a\x12\xeb\x85p\xa6\xcf\x07\xda{\x9f\xf6\xd9\x0bs\x9c\xa6\xed\x0c\xf9\x89\x12\r\xaf%T\xb1\xd7\xfa\xdf#\x05&pQ\x9bqY\xb7\xe8g\x9a\xfbG0\x8f\x82,\x1f\xcb\x01\xa1l\xc9&\x1d\r9|[\xcfEw\xf8_\x07&\xbf\x8d\xb6\xac\xe5\x9dDJ\xeb\x99\xd7\x04,\x0b\xa2\x03\xa0\x80\xb3\xe5S/\x85\x84\xf2ixG*O1\x85\x02\xd4\x9fm\x02\x82AcZSXc\xd6v\xd9\x8b\x98\xc2\xd4\x92IQl\xdd\xcd\xac\x95\xe8\x1b\xdb\x8c\xbe&\xb3&J\xf7R\x12\xe9\x18F\xf0Q=\x9cv(\xe1\x0b\xb1\xbacX\xd9i\xd8\xb0k\xe8\xb3\xb2#\r\x96\x8a\xb4Z\xc4\xff\xa0\x8b4\xe8\xe4L\x15\xcb\x87\x8e~2\x04K\x13\xbe\x16\xd2\x81"\x06\x10\xe3\x181\x08\x03\xf4v\x7fB\x99\r.)\x12\xd9Y\x86@><\xc6\xda\x80\x8b\x15KOC\xb2\x07\\26\x12\x1e6M\x88Y\xa2T\x9e0l\xd2\xfe\xa3\xa1\xba\x9b#-Z\r0!\xd5]5s\xd0\x92\x9f\xfc\xc2g\xb6\xd9\xad\xc9\x8a\x04G\xc8\x92)^;E\xb2\xbb\x94\xcd\xe8\x9e\x7f\x08\xfd\xb8OJ\xbe^\xb2\xbf\xfa:\xb3q!>\'\x13*z\x17\xcd\xd6jFM\xa39G\xe0\x1eDi\xbe\x10\xef\xe1\xd3\x16a\x17\xe5\x82X\xbc\xb7\x14\xab\xa7\'\xed\x8e7#\x98b\xd4\x18\xb7b\xea\xf1]\x83\x96\xf2\x1e\x9f7\x8f]\xddo\x96\'\xe0F\x12\x14_}\xee\x0f\xa3X7\xfd\xb6I\xa8\xd9\xd5\xda\x08\x11\xe1\xfb\xcf\xf09e\xbe\x9d\xad\xfc<\x1f\xca\x8a\xa5MV\xcc\x927\x81\x16\xb8v\x9d\xfc\x1en\xe9Q\xe2\xab\x97A\xbe\xdd\x9d\x97zv\x07\x81\xbd\x1e?n\xef<\x05\x11\xb6\x08(\xa6\x85\xd8|(\xb4\xff\xe5@\xf2\x8f\xe6R\xfds\xf1\x93\x94\xe49\xe2\x13\x19fDI\x9b\xc5+\x94\xf8\x97#\x0b\xdb]\xb3\xb8\xc3o\xe0\x10\xccG^I\x1e\x13\xd2\x92\xbb\xb3\x9e\xa2\x0f\xf5Sko\xbc\xb9\xa5\x1d\xbd\xb9\xfcV\x037\x8dt\x90,\x0f\xe6\xb3({\xd56\xf2o\xa3N\xf2\xe6\x0f\xedm&\xa4jnP\x88\x8dE\xad6\x9f\xc1\xfa\xb5$\nQ6\xd3:E\xb2\xff\xbc\x1a\x95]\xf5\xc7\x81\xb4\\\xc8R\x0c\xefE\x08\xb5\xcf:\xfa\xaay,\xdb\xed\xd7_\x85\x14\x95b\x1aK\x8cE\xe4a\x06k\x1a\x9a^4bi\x13\xf5B\xabt\xc5O\xc6\xe2C\x05\xe9\xfd\x08))>`\xbf\xcf\x12\r=\xd8\xc9\xe6\xdb`\xbbX\x06\xcc\x91Y)&a\x85\xe4Z\xfb}=\xb0B9\xa2a0*\xc1\xd8\xbep\xb9\xbaM\xcbI$\xb8\x84\x81\xb0\xd8\xe5\xe2\xbbk\x13\x082\xfc\x94\xe8\xae\xb6\xcc\xc3k\x90\xc4B[*\x93\xdd|@\xdf\xf1\xf4\x9d\xce\xdcD\xeb\x1a\xee\xfaM_\xbb\x0f\n\x80r\x810\xc8\xbf\x06\x08\xc2\xbe\xeaj\x9cOwp\x1aU_\xd2rr\x8c\x1f\xaf\xef\xe12\x9aC\xb0\xed\xd0\x91\x1e\xe6\xdf\xe0L\x9a\x1f7\xfd\xe8\xa8\xb0\xa3\xebrF\xb8\x16\xee\xb3\xca=&\xcfe+c\x0bj\xf3\xea3\x0e\x9a)\xb0\xda\x11\x83\xa7\x12\x95\xd4\x87\xc6\xe2\x81\xf8\x13z\xd1\xd6o2\x8aN\xf4\xb7\xf0\xa2\xb0\xb3\x13\xbfc\xb8RA\xf4\xae$\xd7\xfa=\xfcG\xf5\x9fE`\x1cR\xf4\x18\xcb\x08\xb8\xfc\r)5\xc6\xd8q\xce\xdf\x9f\xd6\x1a\x08#?g\xf3;6\xf8jr\x97]J8\xcc\'\x86D+\xaa\xb8B\x13l&\xf7\xb79) \xb3\xe9\xdf\xadf\x10\xe7\xd9\x15\x19{1 \xd1\x81\xce\xa1\x9f*\x8d6\xbfn\xa2QVg\xfa\xad\xdfU"6|\xbf\xe0\xb7\xcb\xe1\x1d=+\x9dq\xee\xb0\'\x8a\xe2`\xd3\x88/\xeeDt\xeb1Y\xc1\xf0\xb1\x82\xf7\xa4\xefb\x04\n\x89\xc7F\xfa\x11\x87+\xd9\xad\x8fP\xa5\x8c\x85\xf7\xfc.2\xf1\x0f\xfa\xfd`1\xb2\x1fK!\x9cuN\xf9x\x0f\x93k\xb2\x1c\xb9\x8e\xc5\xaf\xc7\xac\xad7[\x9f\xaf\x1c\xa6\xb3Sf\xdf\xd2\x1d\x1aWh\xe4,d\xe2\x99\x88\xa0,(\xf0\xfc\xdd,\x93\xa5\xcb\xd0\xc8+h\x96\x95\'\xf2c\xc9'
|
|
|
|
|
|
2024-12-14 17:54:52.153169 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40827 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 2038
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x7752
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40827
|
|
seq = 1569492755
|
|
ack = 3115728527
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1043
|
|
chksum = 0x601d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\xab\x84z\x97\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:52.156148 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40827 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 2039
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x7751
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40827
|
|
seq = 1569492755
|
|
ack = 3115728566
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1043
|
|
chksum = 0x5ff6
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\xf21\x88e\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:52.159795 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40827 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 2040
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x7750
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40827
|
|
seq = 1569492755
|
|
ack = 3115729978
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1038
|
|
chksum = 0x5a77
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x9a\xc0O\xd4\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:52.162923 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40827 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 2041
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x7743
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40827
|
|
seq = 1569492755
|
|
ack = 3115729978
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1038
|
|
chksum = 0x1114
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (3115732802, 3115733148))]
|
|
|
|
|
|
2024-12-14 17:54:52.166252 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40827 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 2042
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x774e
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40827
|
|
seq = 1569492755
|
|
ack = 3115733148
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1026
|
|
chksum = 0x4e21
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\xd6)\x10\xd6\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:52.168914 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40827 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 2043
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x7726
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40827
|
|
seq = 1569492755
|
|
ack = 3115733148
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1026
|
|
chksum = 0x660c
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"8\x89E\xdd\xc5\xbdn\x9b\x984\xcf\x8c\xc8Bs\x0b\xf4\x1b .\xe18Sf\xdb\xf5\x8452\x8c\xabd\x05\xd7'
|
|
|
|
|
|
2024-12-14 17:54:52.171117 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16604
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692640772
|
|
ack = 3412657257
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2068
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:52.173058 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16605
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17610682
|
|
ack = 2030874899
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4138
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:52.178223 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7967
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 1258
|
|
chksum = 0xe273
|
|
###[ Raw ]###
|
|
load = b'\xc4\x00\x00\x00\x01\x00\x08\xf0\xe0\x0fd\x16\xe2\xe8/\x00@o\xf0\x06A\x96\xde(XB*@\xdfr\x87!.\xbeb\x14&(\xc3(\xe4g\x91L\xe1\xfb\x04I:\xb3<\xa4\x00?N\x1c\xae\xd3\x1e\x84\xeb\x8a?\x11:\x9a\x12R^"\x18\xd6\x15\xe8L\xd7\x06Vx\xdaw\n\xdf\xaf\xaa_\xeaUZ\xd6\x04\xa3Qc\xabO\xfc\xfb1{S\x81\xe4u\xc7#\xbe\xb0\x84\x14\xc2\x03\xdaZx\x8d\r\rh\xe5\x1cG\xc2\x11u\xd6E4~\xee\x00\x00\x00\x01\x00\x08\xf0\xe0\x0fd\x16\xe2\xe8/DP\xc5\xc6\x96\x8c%\xf1\x1c!V \xd5G\x92T\'\r\x8c\xd2\x08\xa6\x13\xa4+\x84\x99:\xcd\x08+&:Y,-v`\xa1\xfb\x80w\xf4F,\x08\'\x936 \xf0\xc8\xf2l\xa9\x15\x97\x1ag\xe6\xdd\x88\xe9\xdb\x97;\xc8\x1a\xec\x08\x81\xedm\x85\xe8\xacD\xb0\xcah];\xa2}\xda\xad\x94\x9f5\xde\x1e\x9f3\x95y\xe4\xadL\x96\x0eK\xc8\x95\xba\xa27\xc7z`\xd1\x02=j\x95\xac\xc0\x952I\xa4\xe6\x01^\xbd\xda\x15\xff \xe8l\n\xde\xee\x19\xbe\xb98\xac\xe2\x0f\xbb\xc0W}\xb2\xb9\xc8Y>\x11k\x16[S\xd8,_=\x9a\xbd\xd1\xd9\x96\xf4\xed\xb4Q\x01C\x8a\xfe\xe6\xba@\xe1\xfft/\xa7\xfdx\x12\xe0}{\x9b\x9a \xd6\xb3\xc3!\x9d\xa97\xf8\xa9e\x1c\xb1\xae\xd1b\x93\x9eU\x0c\x02\xe3e~\xd1\xcc\n\xd7\xc4}\x94\xf7\x9b\x1d\x00k\xc0\xf9T\xbd\x81\x93W\x05W=\xd9\xf5@\xc8\x9f{\x90\xa35W\x81g\xf8\x8ek\xb4\xf2E\xe6\xc29\x13\xa8\x9d\xde\x1a,O;\xe6\x92c\x973L\r\xb5\x0f7\x9e\x81F\x9c\x9b\x82U\xaf$\xeb\xa4\x91\xf1\'\x93\xa6\x12\xa2+\x99\xa9\xe6!\x9e\xc5.4@\xd3sa\x1ewZ\xac5\x0f\xff$E\xe1\xa3\x86\xdc`\x99\xc8w\xd5\x81\x88\xa1\x13L`\x82\x01$NJ:\x87!]n)\xbc\x04\x17gi\xc1~\xff\x00\x1c\x99\xb6P\xd1\xf7B:\xcb\x84;m3\x93\xa9\'\x11\x1a\xaf\xc3%\xf4rQ\x8e+\xae4Tp\x82\x9e@M\xd9\x0b\xd82\xab\xa60w\xdft;\x1b\x876dT\xdd\xd08\x89\xa4N\xd5%\x87\xbf\x8fg\xef\xb8rV\x17\xfd\x0fI\xd2\xd8\xf9s\x9e\xfc\x0f(zy\x95\x7f\x82\xff\x84P\xb3r\xd0\xb0\xcaFVF\xd7\xb2Cv\xb6\xa0\xfb\x17\xe7kVG\xb1\xa7j!\x91\xa7\x14OUI\xac\x18\xca\x9c/s)VZ\x16\xb5\xcf%\x04\x17\x11\xab]\xca\xc2%c\x7f\x9b\x0b\xe7\xe2\xfc\xe2;nJ\x80E8\xe1\xfd\x0b\x84\x07\xf2\x89\x06]q$Pr_y\xf3g<\x8d\x9f\xcbd\xd0\x0f_\xeb\xe8\x01\xebAHk\x05\x8d\x82\x12Ci\x84|\xb5gB\xe6\x1e\x0bl\xa18-\x8ec=\xd2<\x9b\xf1\xb4dE\xa0\x9a\xc8\x04%\xb1\xca:\x02)\xfe\xb6M\xcf\xfa(n\xcd\x83\x91;3D\\,\xc8R1\n\xd2k\x02\xf1\x076\x85\t}\xe1\xbe\x98\xf4\xff\x15\xa3\x00Q\xb5\xe4X\x0fv\xac\x9e\xb8\x8c\x1c\xca\xea\xfb@f\'\x91\xc5\x802\x82\xc7j\xf2h\xe23s\x05ds?wV%\x93o\xb7\xac9\x0b\xe9\xda\xae6a\xfe\xc5\xda@\x97\x85G\x02jO\x9bz#\xef\xbeQ\xfc7\xcf\xc0o\x11\t\x11\x03\x938\xa8\x1cr\x82\xf6u\xa3_\x06\x19"\xe9-z\x85\x17\xdc\x07/>\x12\x1dfl+\xf4x\x05_\xdf\xfc\xcbvg\n\x81\xef50I\xfd\xe0Y71(\xb6\xdaH\xe4\x81\xdd\t\xd6\x0e8\xef\xd8E\xe0`\xf3\xd5E\xe4_d+\xfdc\xde\x95\xc8\xa6\xd1\xdd\xe6m\xa5\xb2\xb0\xde\xb8\xdfi\xfa@UB,\xcdL\x96\xf5\t42\x02y\x054\x97"\xe4\xbc\x87\xbdXG\xfa\x87~N\xf3\xb3s\xaa\xeb\x93H\xb2\xeaV\x99c\xdc?o\xab\xae\x8a\xf1\xe1\x18\xde\xea\xbb4\xe2\xd8\xbeq\xc0\x06\xbc\xe8F\xe67\x9e\xcfUz\xa0\x7f\xbc\xa8\xf4\xad1\x19\xf3\xb6^\xcf\x91^U\xbe\xd8\xea1\xc3\xd7Z\x86\x8e\x84e#\xea\x8b\xa7.\xc0\x02\xeb\x91\x15s\x08ES\x16\xfb_\x17\xe2?oE5\xd0\x86\xa5vW6\x8e\x937)\x1fr\xb5/]{\xd0AO\x96\xf4~R\x1fv\xf8\n=\xe3\xfd\xe5\xa3n\xa8A\x8a\x8bqy\xff\xdb\x04\x1bQ\xb6\xfd\x15;\x897IH\xbd)\xf4 J\x1bX\xe00\x05\xdea\xe8\xd0s\x01*\x86\xd9z^so\xc3<\xf4)\xb9m\xa4\x1ac,\x9b\x0fs\x01\x93\xc0\x0c}RL\x80\xb0\x1d\xcf\xea\xa2\xa8uF\xd2\xe0\x9aD`\xa9\x18\xb4\x06k\xb4\xd4[\xdf\x11>\xfc\xb5\xa0\x1c\x10\xd1\x0e\xf8C2\x8e\xabK\xee\x966\xd8\xc5{&\x97t"\xafO\xfe\x96\xcd\xc4"\x8d\xb4\xad>"\xd6!f\x1f\x19X"\xa0\xe7H?\xac\xf7\xbc&\x1b\x9a\xdb^\xaa\xac\x93A\x1c$>\x9cE\xf8\'\x8b\x87\xa5\xa6u\x00\x86\xbe\xfc\x16\xa1[{\xc7\xba\xf5\xb0\x1e\x16\xf083\xb6\x00w\x10\xf7\xa5\x92\x9dl\xa2\xfbh\xc1\xf9\xf8a\xda\x11\x02'
|
|
|
|
|
|
2024-12-14 17:54:52.182510 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7967
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 1258
|
|
chksum = 0x7de9
|
|
###[ Raw ]###
|
|
load = b'\xee\x00\x00\x00\x01\x00\x08\xf0\xe0\x0fd\x16\xe2\xe8/D\xd1\xdcql\xa8\x84\x0e7J\x14\xb6\xc4e{_ \x9c#\xe8\x19\t\xaa\x83\x15\x93\xe0\xb2Z-\xfd\xa3\xa8\xbcV\x021$E+\x05u\xbd;0\xf08\x92E\x1a o\x84\xf2\x87\xcc\x06\x1b\xa8\x84\xdb\xad\xbda\xa2:\xfe\x12\x14\x10\xe8\xb4\x87\xc8W\xcar\xcd\xc7\x89 \x9f\x106\xea\xe6\xb7#\xc9\x0b\x92\x85\xf3M\xe0\xf1\x1c\x02*94\x1a\xafV\xa9\xd3\xd4sz(\xda\xf6\xc5-@M\xe1/\xcb~\xd7\xb6/\xaeQ\xbb\x05\xc55\x1d.FG\xe5(\x97m\xef`\x01\xdda\xc4\tF\xf5Ax&c\x1f\xe9`S6\xbf}Y7h[vfK\xff\xd7\xdd\x0c0{\xe1\x81\xec\x8f\xf7\x81\xd7\x8d\xdf\xa7\x1eE\x06\xc5~\xc8w\xc6\x94\xc3\x8e\x98\xc7\x10\x10\xb9(\xf7\\\xc9\x871\xbc\xa9\xe4\xaev\x90\xd4D\x83rEp\xceS(\x01`\x9b\xe9\x00\x9f\xcd\xb9\xdc\xf2\xa7\xad\xc1A`]\x9fB\xcf\x08o&\x9a\xbdC\x9d$\xf0\xa4^\x16\x85(\x90o\xa6\x1aP\xc5K\xac(1\x806\xb9\xf9\xd8\xa7\x95dl\xd5b\xf4\x94%\x87\xe0\x95\xe2\xc1\x0c&\xcd\xc9\xfazd&\n)\x99\xe6H\x1b\xdc\x8b\xf2\xa1\xaf\xbc\xab\xdf\r\n\xa1\xdf\x7f\xf5X+\x928\xec\x7f\rB\x17\xa3\x99\x0f\x7f\x80\x90\xf5\'\x12e\x8cA\x04\xef\xdf\xbd\xcf2x\xf1~\xd2\xe1\x82\xd1\x1f\xaeq\x89\xb9~\xc5y\xe8/\xf9\xf5b]\r w3-\xb3\x9b\x8dR\x9e\x8d\xeb\x88\xc178\x81\x8e@\x8c\x07\x981\x1cA\x01\xac\x0c\xe6I\xbf\x12`\x03kf\x99\xda\xe3\x9b\xcd\xbf\xc0\x8fj\xd1\xba\x10c%Z\xbd\xab\xbbW\xeei\'/\xe0\xf1\x18\xf0\xfd\x99sR\xf0Ke\xbe~\xa0c\x96\xa1Ii\xc8\x18\xa8\xd9fA\xb60\x8c`\xeb,\xceC\xb8\xf6\xc1R`Q,\xc0\x9a\x85}\xb9\xb4\x02\xfd-\xb0\x0e\xe1\xc35d\xc0\x9b{4u#7_P\xc7\xe2\xd4\xf4\xee\xd58/\xb2\xb0N\rR\xd3(aM+\x85\xedp\x1fR\xfe\x8c\x13\xb4\x92\xef}\xb9\xf5=+\x90\x89\xe7\xac\x94\xed\x91\xd3\xd6\xff\x88\xd6f8\t3\xf3\xc1y\xa5A\xf3~\xdf\x92\x00\x83U~\xd9#\xa4\xa4\x067\xf7\x93\xca\xac\x19\x8f\xe0N"4\xe5=en&y\xaf\x1fp\xa2N\xb5wd\xf0\xce\xde\xda\xf1\xfd\xe0\x19\xc3\x8d\x04\x80nk\x9dmCw3\x92\xf8\xdd\x19\xa0\xc2\xe9\x90\x05\xd10\xae(\x8a\xc6\x01\xa4?0\xd3\xc34\xe2\xb9\x95\xf8\x82\xfb\x8bt \xce \xddA\xdd\xddq\xc5=jZ\x1e\x89U\xc5<V\xa0\xfeU\xb9\xd8*4\x1cM\xee\xcd\xe2\x8ai6=\xb16\xf8\x9e)\xcd\x159z\xb1y0\xf2\x95R\xde9\xf2#\xc4\x94Hs\x0c\x8b|\\\x85M\xe3R\xf8Z\xc8Qi\x88W\xef\xa9L\x07%\xe0\xbc\x85\xd2\x16\xfa\xd9\x8b.\x0c\xfcI\x95},5$~ar0V\xd4\xae\xf4e7\xb0\xd4\xc2\x8a;b\x84si\xa9\xe0Ot*\xdb\x90\x86qO}\x19\xac\xbdj-\x04\xb0LHcih\xaba\xd1Y\x17@0I\x8b}\xcf<\xd7\xd1\xaaE\x87\x12W\xdb\x98\xb1\xf1\xe6d\x9d\xea\x1b\x7f\xa9g\xe1\x97\xe0\xa3\xb9\xcf\xef\x1c\xe6u\x1dG\xa5\xb4\x93\xee,\xc9\x12\xe6x5\xa9du`\xd6\xb6**\xcd\x8e\xa7}\x85\xd1\xcb93^i\xb3{Y\x81\xb4\x1d\x94\xd75\xf1i\xa5\xa7\xfai\x878\x0b\x8a\x98\x97\x04\xfaCQC\r\x9b\x10\xf6\xb7UX\xf9#\x9f\x1bzH\xb4\\jy\x9a\x83d\xa3\x1a\x04x\xbfXb\xaeA\xf1Tc\xb3\x04i\xf8\xcfpy\xdc\xa3\x16\xd7A\x06\xca\xfdu\xf9\x95\x14\xff;Pq1_\x1b\x83\x81\xf9\xca\xe9\x127\xb4FOI\xf1\x939\xa1\x0b\xfa\xc7"\x0f@\xf3\x9d\xe9\xa3\x8dG5\xd8R\xec\x93\xff\x17\x92\\\xd4\xceS\xd2\xf7\x02\xe7S\x9d\xbf\x18\x07\xf3\x80\x82\x13V\x11\x93\xc3@\x83\xda\xe5\xb7\xe5\xcb /W\x1bhOB\tYxKX\x14\xcf\xd8\xa9\x0c\x84\x1a\x156E\xbd\x07\xe8\x91\xc3?\x8a&\x8f\x8f\xdfc\x0c7\xde\x05\xc3\xb1\x90\xdbT<\x83\xc5\x85Ij\xfd\x19-\xa0h3jp\xc21\xb6\xd6U\x8e\xf0\xa4\x10Z\xd1\x98kB\xea%ow`\x88j\xeaF\xeaz\x12\xbfE@\xed(\x81\xe6\x16\xa2\x18*\x9d\xf7\xcb\xbe\x9c$\x85\xb5\xe3K\x0e\x86\xe6\xbe\xd4}/U\x1f\n\xf1-\xe8]\xd1\x1by\n\xfd\xdc\xc0\xf8\xc8\xc2\x91\x13\x99\xd3uc\x99\xd2I\xbb\xe7\xfb\xd9\xc3\x02\r\xae\xc3QHz\xeaG\x7f\xfd\xb3\x1c\xb1r+\r\xbbn\xb0\xd2\x1a\\\xe0A\xe4\xdd*}\xce#\xbd\x02\r\x13\x99-N\x02\xf0^\x13G\x13\xd3\xf6\x99\x93o\xed\xcc)W\x13L\xdeT\x8d\xd3s\xb2\xa15\xb3\xe8\x0f~B\x87V\x95\x0b\xc3\x90q9V\x05\xe0~\xe5\x80Z$\xd8`\x81_K"7\x05\x8b\xcd\x8d\xc8\xdc\x15\xd5\x93\x1dF,\xf9\xcf\x0c\xe4V\xe0y\xfd\xbe\x9fU\\\xe9}n'
|
|
|
|
|
|
2024-12-14 17:54:52.185146 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 532
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7c51
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 512
|
|
chksum = 0x7628
|
|
###[ Raw ]###
|
|
load = b'\xe9\x00\x00\x00\x01\x00\x08\xf0\xe0\x0fd\x16\xe2\xe8/A\xa3\xf8\xa0\xdd\xcf\x8bm\xc6v\xb31\x80\xef\x91\xc9\xad<\x04q*\r\xa80j\xe9\xb6d\x08a\x0c\xa5\xa4\xa3\x0e\xd9r\xf3qI\xe3\x9aw\xf0sx\xbaV\x86\xbd\x05I\xb4H\x19I\x94\xeeJ2E\x15K\xb3\xaf\xf4H\x173\t\xd9\xd3\xeb\x99Qc\xb6\xb0\x83)\xac\xc8\x16#\xec\\+\xbb\xf5\xd5j0\xa1=\x16\x96\xaf\x80\xa9f:\xf0\x84\xfc\x80\xd6\x92m?\xaa\xd5q|\x92N\x80\xe9\xa8\xa0\xc8\xd8V\r\xbfF\x88\x82U\xc1\xf6\xed\x16\xec\xf5N=\xd3a\xfe\\\xd8\x1f\xd1\x02\xb6]\xa2\x87a\x8c&\xfb\xf0\xeeG\xdc)\xf0T\x9b\x16n\x84?\x04\xcb\x87\x0br\x88\t\xb5\xf3\xa0\x11W\x1cg0\x1c\xff\xc7\xcf*\xd7\x86/\xa89\x0e\xdd92\x0f\xe4\xcc\x06\xf2\xec[\x11%ib\x90\xe9Zcs\x1cge\xe0\xc0+\x033\x04\xfb\xc7\x88\x93\x8c+\xd3\x12\x1e\x7f\x1aR\x1d\x86\xfa\xe6b\xdc\xb47\x1e\x19\xe4.\xdeV\xbd~\xf2\xe5\x0e#\xa1\xff\xd6\x06\xd7\xe1\xd6\xe2\xfc,!\x0c\xf7^\x84*o\x945I\xb6b\xdbE\x14\x821\xb3QA\xcf\\\xe4N\x8di\x9d\xad\xaa\x9f\x84\xa1\x0f.\x1d\xd6\xa99\\r\xec\x8b\xea\xa4\xd18\x82\x19s\xc8\x16\rt\xed\x04\xa7\x8b\xf5\xb1\'\x85\xaf\x8f;\x10[9-\xaa\xd0\xe0^\x85\xa7\xbe\xa5x\xbeR"\x91\xf2r\xda\xdf\xf4\r\x85\x10Z\xd7\xab~\xfay=m\xfcE\x9d\x01#T\'\x9bJ\t\x12\x07\x19zm\x9113p5\xf0\x9f\x93\x81|\xb6\r\x18\xbd\xd1\xa9\x9cs\xf8\xd8\x0e\x02\xbci\x0e#\xc4\xa3\x01U\xa3\x8f\x00\xe6\x8fY\x06\xd7Cfs\xe9\xd9\xcb\xa9\x0c\xd5Q\x99H\x1dF\xdc\xaf\x0b\xca=\xb4)\xc8\xddod{\x02\xfb\x15\xd4\x9f\x01\xc7!%\xa9\x04hQ\xaa\xbc\xc2\x12\xad\x85\x03\xb83>\xae\x18\xd0\xef\x19M\x97,r\xdb\xb4ktCEl\xdb\xaca\xd2\x97\x1e\xdeu#\xa0<\x10Rx'
|
|
|
|
|
|
2024-12-14 17:54:52.187562 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 67
|
|
id = 1596
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 47
|
|
chksum = 0xc5c8
|
|
###[ Raw ]###
|
|
load = b'\xef\x00\x00\x00\x01\x08\xf0\xe0\x0fd\x16\xe2\xe8/\x00@\x16\x9b\xffn\xf0}\x91b_\xa2\xce\x91\xc5\x1a\x19K\x9e\xd4\x1et\xfc\xbd\x84'
|
|
|
|
|
|
2024-12-14 17:54:52.190189 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 193
|
|
id = 1597
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 173
|
|
chksum = 0xc646
|
|
###[ Raw ]###
|
|
load = b'\xe2\x00\x00\x00\x01\x08\xf0\xe0\x0fd\x16\xe2\xe8/\x00@Gc\x82f\x89y\xc1)\xcd\xc4S\xb8\x04\x0bY\x8a\xab>-C\xf3\xe1\x10\x97\xbc\xaa\xf9\x8a\x87\x99\xb8\xc2\x81\xd4\x12l\xbb\x05\x90\x98c\xf9gz\x14KmQl\x07nz\xb7\xca\xaa9L\xb63\x88\x80wp\xeac\xf3\xa7\xa0\xc6\xa6\xdf%Z\xf0\xe0\x0fd\x16\xe2\xe8/\x1c\x10\xdd\x7f\x82\x05t\xc7v2\x9a\xd9\x04\x84\xa4\x84\xefaU\x03 1k\xbckj$\x8a#.[\x8a\x85\x1cJ}Ga\x94\x15\xe3\xcc\xc2X\x80\x15\xbd:\xe7\xea.\xa1P\x84L\x83\x99\xf66\xf8`0V\x85\xe3\xf7\xde!'
|
|
|
|
|
|
2024-12-14 17:54:52.194409 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 546
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7c43
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 526
|
|
chksum = 0x6b0c
|
|
###[ Raw ]###
|
|
load = b'T\xfcb2\x1d\xf6\xcd\xaf\xa0\x03dy\xb6\xad\x9fGL@{\xf8\xf1\xc0\xc63Jx\x1d\xfc"\x15\xc7A=\x9e(\xaa.\x1f\xb5\xf2qK\xa9r\xde\xf6\x8f\x9a\x176\x17)\x02+\xf7\xfb/\x0e\x08\xb0`\x0f\xe4\x1b\x94q\xed\x1c\xcbc\rM\xe1\x04\xed\x10\xe5\x18\x8fk~k\x8b[\xa0\x12\xcc\xd0\xcbm\xad#\x08\x9e\x9bP\r\x7f\x92U\xc6\x8c/"|\xb7h9K\xe7\xeb\xf0\x0b\xde(\xc9\x8bL\xc3\xad\x11\xabz\x8a0\x00V\x86\xb65\xbc\x93\xff\xa8\x06\xa7\x85\xf6$\x11\xd7\xe9\xef\xb53)5\xd1\xff1\x0c\xcd\xe5\xde\xec\xbdY\x1d\xca@\xd5\xb5S$\x01?\xd3d\xe0N_B\xa7\xf8\xc2\xdaCR:6[\xac\x04V\x92\xd4\x17i\x03L\x8d\\\xa7n\xda\xd1s\x08D\x10}\xe6\xc8B`(CX\x0e\x87\x1e;D\xa01cP^\xb5\xb5\xfbW\xece\xa7\x9ej:i\x9d\xc8r\x95\xc10\xf9\r~\xea\xd6\xb3\xa6A+n[3\x82\xcdLA{t\xe6\x11\xcaH9\x9c\x8b\x19\x90\x97\xce\xf9f\xb8t\x9a\x0f\xa4\xd0C,C$=\x8c\x88\xc77\xea`\xcc\xe3\x1dZ\x91f\xf9;d\xa2\xfd&\x0f\xf3\x89R\xf2\n\x18(\x03\xf4M\x0b\xaa\xf4\x976\x88\xa8u\xd8\x95\xc7;\x97\xb4H\xd4f\xa1U\xd0\xdd\xae\xce\x94\x8ar\x8c\xd5\x99\xca\xf3\xa6\x1d\x02\xd1\x15\xd2{?\x14\xbe\xf2\x1by\xe2\x81\x0c\xec\xfbZ\xbd\xb6GZ\xdc\xe4\x15\xd5\x08ShM\x8bX\x07\x8f\xc6W\xb4s\xb3\xd3\xfdY\x1b}\xba\xe0\xa2\xc9H\xa7\x0bt\x99\xee\xab\x9c\x9d\xa7\xe9\xd1\xa1\xc1\xb6\x83\xf5\x9e\xdev\xf3\x92/\x153\xd5\x84\xd5)j\xce\xbb\x80\x86<\x14S\xf4CJ\xd7\x0b\x94\xb8\xb0-}\x9b\xb4\xa1\x96\xe0\xa7O\x16\xce\x85\xb0F]\x03\xf8\x01\xef\x93Ky\x1f\xa0\x07F\xb0\x95\xc8{.-\xc1\xef\xdc \x03b\xfe[\x19\x8bQs^gdA\x94\xdf\x9b\xfd\x16\x91N]N\xe3C\xe0u\xd5h$>\xed\xc0|\xbc\xd5FC\xf2\xc5\xd6\x03%R\x84-:\x80\x18[\xdd\x1c\xaa'
|
|
|
|
|
|
2024-12-14 17:54:52.197735 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 149
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7dd0
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 129
|
|
chksum = 0x4cac
|
|
###[ Raw ]###
|
|
load = b'N\x1d\xb5u\xfaep0w\x86\x9b\xf2uJ\xaf/\x9c\n\xaa\xc9E\xc3\x02\xe9/\xaa9\xb6\xa9\x0f/;K"\xa0\x81n\xf1\x0e\x0e\x1a\xab\x96\xb8\x1b\\\xccJ\x17\xd1l\xb8\x05\x87\x16\xc0\x02\xe2^\xf4?\x06\xa00\xbd\nQ\x8106\x8e\x07\xefy\x9b\x9b\xb0..\rj\xe8$$\xf4g\xb1d\xact%\x80\xe5\x0c\x94\xa1m\x86\x14\x93\xe7Ds\xe7\x04\x08\xfd1h8J\xb2Rj\x11\xbe\x17\x99$n\xcb'
|
|
|
|
|
|
2024-12-14 17:54:52.200550 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 59
|
|
id = 1598
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 39
|
|
chksum = 0xc5c0
|
|
###[ Raw ]###
|
|
load = b'N\xf0\xe0\x0fd\x16\xe2\xe8/D\x85M\x118\x1e\xefL\xe3\xa4\xf1\xd2\xdb+\x9a\x0en0\xa7\xe9\xe3w'
|
|
|
|
|
|
2024-12-14 17:54:52.203323 - Ether / IP / TCP 192.168.1.11:40827 > 35.186.224.26:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 1599
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40827
|
|
dport = https
|
|
seq = 3115733148
|
|
ack = 1569492794
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xc5a2
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:52.206069 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40827 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 291
|
|
id = 2044
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x7651
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40827
|
|
seq = 1569492794
|
|
ack = 3115733148
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1026
|
|
chksum = 0xddbb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xf6Zb\xcbTt\xee\xc5\xce\x8ax{\xd6:\xab\xe6_l\xbd\xb1j/\xa3y\x13"k\xace\xea&\x10r~\xa1M\x92+\xa0M\xef\xb3\xdc\xd2\t\xb4\xd9\xaaL\x87\'\xa7\x1d\xe0\xa1:`\x8b\x18\xa7\xaf\x08\xd8@\xa2)\xe1\xf6\xf2\xcb\xbah\x8c\xb0\xa6\xf9d\xa3\x86\xc3,\x9a\xfb2VqN\xb7\x9d\xca\xf9)\x00\xc5;\xdc\xdd\x05U\x9d\xc9\xda\x8c\xe2\x82\x1a\x0f\xeeGQ\xb1\xee\xcf\x0et\x84+\xb9\x82[\x07\xfd\x1c\xb5\x10\x0f\xad\xbf\x1d\xed\x03*\x8e\xdb\xa7\x97\x0bw=\xbb\x14\x0eN$f\x0e\xf0K\x92\xf9\xbc\xc8\xe4\x836\x9cm[\xbb\xb7\xcf\x83\xc5\xd9\xa7\xd0\x9e\x022\xd56\xa7\x98\x0e\x8d\x07\xbcS\xdd\xf5;\xea\xab\xf8\xf1(\xb9\x8c\xec+\x1a\x14^\x1c\x8e\x0c?P\xc5\t\x88\xc6\x84"\xb6\x1d\xafu\x063\x83\xe1\xcb\xf1\x16\n\x17Un6\x90\xaf\xde\x01)E\xe6\xd4K\xf0\x88C]\xe8j\x07~\xd3T\xda\x7f\xf6j\x96\x9b\x81c'
|
|
|
|
|
|
2024-12-14 17:54:52.209858 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40827 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 318
|
|
id = 2045
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x7635
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40827
|
|
seq = 1569493045
|
|
ack = 3115733148
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1026
|
|
chksum = 0xe395
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\x11\x0c\x95A+Z-\xb0Q\xae*\xf2\x9c=\x91\x009\xedGvo\x99\x13=<\xd7{&"\xb4\xbb\x94\x92\xffMN\xc9\xa8\xbaS\xf8\xad\xb1"\xff\xde\x1c\x85\xa0Z\x06u_n\r0B\xa1\xe6\x19\xb5~\x9d@\xbc\x00\xbcH\x85\xf8\xe4\xdc${/.\xed.}\x93\x88\x8cR\xca\xf1\xbe\x93\xbc|\xbe\xd1X/@\xa8\x9c\x06>f@\x93h\xce+b\xcd\x19\x89\x8aw\xbbz\x86\x15\x83\xe8\x06\xb0\xd1\x91gzo[0\xe1\x9c\x19US0q\x97+=\xceX[\xea\x1d.k\xbc\xe5;#\xbcY\x8f\xa2\x88^\xc8\x9e\x12}\x85^o\xc0\x99\xc3\x1a\xaem\xd1\x1c\x00\xe8u4s0\xb4\xcd\xa7>\xd8\xd5\xbc\x16x\x1dy\xa7\xcbR\xe6"\x99e\x0buz\xa0\xcbe\xc4\xe9\xb7u\x0b\xac\xb9\x94\xc7\xda\xa7L\x9fE \xf5\x89\x18A\xad\x9a(\xdc\xcf\xd1 \xa7S]\xf5\x0c+\xd0\x03X;\x04\xf1P\xe6\xd8\x95?\x18B\x82,\x9a~\xe8\x85\xc9]\xb5\xa8\x81\x19\x9f\xbb!W\xeb\r\xcf\x1e\x15$\xcd\xd3\xa3\t\xd4\xc8\x99\x05{\xb0'
|
|
|
|
|
|
2024-12-14 17:54:52.212245 - Ether / IP / TCP 192.168.1.11:40827 > 35.186.224.26:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 1600
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40827
|
|
dport = https
|
|
seq = 3115733148
|
|
ack = 1569493323
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xc5a2
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:52.214829 - Ether / IP / TCP 192.168.1.11:40827 > 35.186.224.26:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 1601
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40827
|
|
dport = https
|
|
seq = 3115733148
|
|
ack = 1569493323
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc5c5
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xfc\x0c+Iz\xf5\x00\x1a+\xcb\xd8\x07\xea\xb8\xda\x01J\xfc\xb5\r$q*\xc8\x9f\x07z\xe1\xbd\xdb'
|
|
|
|
|
|
2024-12-14 17:54:52.217486 - Ether / IP / TCP 192.168.1.11:40827 > 35.186.224.26:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 1602
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40827
|
|
dport = https
|
|
seq = 3115733183
|
|
ack = 1569493323
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc5c9
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\x1c\x0b\x89\xe1\xdf\xda\xeb\x12\x08\x03\x800\xe3\xf9\xb6\xc9\x85\x96\xb8\xf1\xaf~\x1aA\x08\xf9\xab\xe4\xf6V\xa6\xd4g)'
|
|
|
|
|
|
2024-12-14 17:54:52.219675 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7e31
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 32
|
|
chksum = 0xc423
|
|
###[ Raw ]###
|
|
load = b'O\xb8qo\xf3\x1e\xe1\x10\xf9\xf8>\x06\xa8\xaf\x1f\xde.\xcd\xce\xa3S\x98\xb0c'
|
|
|
|
|
|
2024-12-14 17:54:52.222453 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 479
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc56a
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 459
|
|
chksum = 0x81a1
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANIPConnection:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:service:WANIPConnection:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.227227 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 497
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc558
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 477
|
|
chksum = 0x3a9
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.231557 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8394
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.234858 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 465
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc578
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 445
|
|
chksum = 0x8a6f
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:device:WANDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.237805 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8392
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.241485 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 485
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc564
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 465
|
|
chksum = 0x7632
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.244900 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x83e4
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.248432 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 489
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc560
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 469
|
|
chksum = 0x502d
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.251536 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 417
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc5a8
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 397
|
|
chksum = 0xc02c
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: upnp:rootdevice\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::upnp:rootdevice\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 17:54:52.253609 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:40827 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 2046
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x774a
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40827
|
|
seq = 1569493323
|
|
ack = 3115733222
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1026
|
|
chksum = 0x4b9f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\xfe\xf6bn\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:52.444691 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40578 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 204
|
|
id = 58757
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x44ae
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40578
|
|
seq = 1061751474
|
|
ack = 3654923801
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 922
|
|
chksum = 0x4bf1
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x9f-z\xc6/jb\xa1\x1aaJ\xb48Jl\r\xebe\x8dTk.\xc8\xe2\xbd\xb9+%\xb83tC\x05\xba\xcf\x15\xc4b\xd8\xd5\x8e=K\x8bh6<\xbfEW\xb2\xbaD\xca\xfd\'\xff\n\x952\x18\x87\x95\x9e\n\xc7\xa9q0\xe8\xa2\x84U\xf5\x9cYT\x9c\xe4\xcf\xdej\x0f\xca\xf7\xff\xe6\xe2\xdc\x9e\x03U>J\x87\x15\x9en\x92\xa3\x06\xeb\x83?\x1aK%>R\x0bX\xa8\xe1\xc2"\x03\x95\xb4}\xd2\xc6j8?6f=\xfaV\xc6\x86\xd8~d\xf5\xd7\x7f\x84\n\xb6&\xd6\xa6p\xf7\xc5Qu =\x9d$\x00\xe7\x10"\xf7\xfe\xbe\x19'
|
|
|
|
|
|
2024-12-14 17:54:52.462220 - Ether / IP / TCP 192.168.1.11:40578 > 142.250.201.74:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 42378
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40578
|
|
dport = https
|
|
seq = 3654923801
|
|
ack = 1061751638
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0x1a36
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xf6W{GDc\xef\x83/\xc8t\xe0!$g7\x915K\xfc\n\xb02\x14\xf9n\xa6$^J'
|
|
|
|
|
|
2024-12-14 17:54:52.473339 - Ether / IP / TCP 192.168.1.11:40578 > 142.250.201.74:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 42379
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40578
|
|
dport = https
|
|
seq = 3654923836
|
|
ack = 1061751638
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0x1a36
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e|\xdd\x95\x05\x93\xb0\xf6O!\r]\xb8\xa0\xf3T765\xdf\x8c(\x88\x1b^\x1c\x84\x96\x80n\x93'
|
|
|
|
|
|
2024-12-14 17:54:52.483527 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40578 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 58758
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x4551
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40578
|
|
seq = 1061751638
|
|
ack = 3654923836
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 922
|
|
chksum = 0x174f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:52.488997 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40578 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 58759
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x4550
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40578
|
|
seq = 1061751638
|
|
ack = 3654923871
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 922
|
|
chksum = 0x172c
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:53.364795 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 66
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3af3
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 46
|
|
chksum = 0x1bc
|
|
###[ Raw ]###
|
|
load = b'T\x11\xd4=\x1b\t=\xd8\x84\x02\xa6\n\x9eFv\nX\x02\xc49\xd8\xe79\xed\xc5{}\xa0\x84\xb20#|\x8e\xc7\xcc\xcc0'
|
|
|
|
|
|
2024-12-14 17:54:53.376671 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 61
|
|
id = 53862
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 41
|
|
chksum = 0x8f3
|
|
###[ Raw ]###
|
|
load = b'G\xf3wB\xde\xaf\xa6\xa7\xe0]XxDr\xe8.h\x88P.7\xe5B\xc9\x80\xb9g\x92\xa6\xb8Xxt'
|
|
|
|
|
|
2024-12-14 17:54:53.386690 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 66
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3af3
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 46
|
|
chksum = 0xa80b
|
|
###[ Raw ]###
|
|
load = b'\\\x99\x19%\xbbB~\xc9-\xbb)\xee\x1e\xf3\xff+\xae\xd2{\xa6\x9e\x8b\x1e\xe4y\xda\x11\xba\xccV&\x00\xbe0\xe7\x93\x1f\xa2'
|
|
|
|
|
|
2024-12-14 17:54:53.391061 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 62
|
|
id = 53863
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 42
|
|
chksum = 0x8f4
|
|
###[ Raw ]###
|
|
load = b'O\xf3wB\xde\xaf\xa6\xa7\xe0\xd2M\x84\x8es\xce\xc71\x8dw\xef\x8b\x10u\xeb\xd5\xcdnp\xdc>\x96\xa4\x0e\xe8'
|
|
|
|
|
|
2024-12-14 17:54:53.578246 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 57
|
|
id = 53864
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 37
|
|
chksum = 0x8ef
|
|
###[ Raw ]###
|
|
load = b'Y\xf3wB\xde\xaf\xa6\xa7\xe0\x1a\xf1r\xbcO\xe2|\xe9\xf2^\xca\xf9?\xb4\x9a\x85\xa9\x1e\x11\x13'
|
|
|
|
|
|
2024-12-14 17:54:53.585384 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 45707
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdb50
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412657257
|
|
ack = 1692640772
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0xb014
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\xfb\x1c\xc79\x8f\xaa\xedD\xee\xde\x98j\xec\x1b\xa8\xae\xfeN\xd4\x8fi\xef\n\xf7\x88\xb9(\\\xd1\xf4\xedl\xd0w\x12}\xaa\xfaYP\xd0\x0b\xe4\x99\n&\xbe\xe7_\r=\xd2l8\x91\xe4\x9a\x1a: \xc3kB1\xa6\xc4\xbb\x80\x13{S2\x03\xc5\xef\xf3\xaeS\xcb\xd9\xee\x1e\xe2/bsy\xfb\xf5\xad\xf2\x95\x90\x9a\x1e\x80\xe5\x91D2\xf1\xd5\xfa\x13[\xf6Ie[\xcct\xe6\xb9`\xa9.F3\xa9\xab!\xfd\xe2\x9d\xa0\xda\xaccG*J\xa0w\x11s>\xc4hc\xf9ZB\xe7\x92\xf4\xf7\xaev\xd8\xeeWA\x15\xb2\xe3\xe6G\x1f\xee(\xfa\xbc+\xc9\xdc]0\xecN\xa0\xfc\x05\xc4YX\xd10\xbam\xd37,\xee\x90\xc6<\x82\x1f\xe3;\x13!\x83\n\xb0\xfdT=r\xfc\x1d\xf3\x82\r&\xaaI.\xea*\x1dH'
|
|
|
|
|
|
2024-12-14 17:54:53.591612 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 49797
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcb56
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030874899
|
|
ack = 17610682
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1517
|
|
chksum = 0xd5b5
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\x90<B\x9c\xcd\x96\xac.\xd4\xec \x89\x8a9\x87x\xe2\x14_\xa6\xff\xb1@j\xab\x84\xf1\xdf4\xd3\xf5\xa1b\x83\xc8\xa9\x9aYR:l\x12S@\xea\xb75\x88\x8a\xda\x9f\xf2W"\x15\xdd\xc0\xa9\xc1*\\\xce\xfc\xca\xa0\xfe\x05\x0c\xea"\xf9\xb2\xc3\xf5:\x1a0\xae\xb9x\xab\xb8\xc2\x18\xa5#\xe9\xc6,(\xea\xff\xf5D|\xd7BD\xa4\x06\xcb\xbac\xa8D\xf1\x84\x8e\xc0f\x92\xa5c\x85\x98}\'pB\xb2\xf9\x00\x91_\x93~H\xf6\xa9\x98\xfe>\xb8[\nq\x17=E\xd4\xfc\xd5\x8f5\x99\xb31\'\xa3\x9ak\xb6\x05\xdc\xb9\x0e\xd95\x00t\xb7\xd8\x94\xe4\x96\x90\xcf\xa8{\xe7\xd9\xa5s\xda\xce\xc0\xb6\xf7\x9e\xdaD\xf7\x14\x08\xc4E\x19\xbfl\x82\x1a\xae\x95I6\xc1\xbd\r\x17\x9a\xa0e\xf6q|J\x95\xbc\x84\x95Z\x0c'
|
|
|
|
|
|
2024-12-14 17:54:53.609037 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0x1caa
|
|
###[ Raw ]###
|
|
load = b'V\x8c\x0c[!\x9d\x83#\xc0gW\xdb\xc2\xce\xe6_E\xf6\xde\xbaT\x00\xbe}\xdc'
|
|
|
|
|
|
2024-12-14 17:54:53.639805 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16606
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692640772
|
|
ack = 3412657474
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2067
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:53.646516 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16607
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17610682
|
|
ack = 2030875116
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4137
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:53.811501 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 57
|
|
id = 53865
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 37
|
|
chksum = 0x8ef
|
|
###[ Raw ]###
|
|
load = b'V\xf3wB\xde\xaf\xa6\xa7\xe0\x8d\xcbw\x95l\xfb7\xf4H9\xbe\xb2\x8f\xe3\xf3\x83\xe8\xedy\xb8'
|
|
|
|
|
|
2024-12-14 17:54:53.819595 - Ether / IP / TCP 142.250.200.106:https > 192.168.1.11:40573 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 125
|
|
id = 34088
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xa53a
|
|
src = 142.250.200.106
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40573
|
|
seq = 991711716
|
|
ack = 1062958736
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 941
|
|
chksum = 0xc7db
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00P\xfa\xf5_h\x02\x88\xa0\x01?a\x18\xc6\x14\xe4\xf4\x0b\x02\xb8\xc7\xa8\x80y#\xed\x01\x8e*"7h%\xf0T~/<\x1e|p|\x86\r\xf7g\xc0\xf3!\x11\xff=\xbd\xb1\x07@/hW\x95&\x8f>\xa5\x94d\xbb\xfb<\xdc\xea\x0e\xe4`"i\x8cV5f\xf6L'
|
|
|
|
|
|
2024-12-14 17:54:53.828372 - Ether / IP / TCP 192.168.1.11:40573 > 142.250.200.106:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 60585
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.200.106
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40573
|
|
dport = https
|
|
seq = 1062958736
|
|
ack = 991711801
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 508
|
|
chksum = 0x1956
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xcdU\xc9\xfd\x9bz\xe78v\xf9\xe0\x83\x82l\xb4\x95\x1bk\x91\xbe,N\xf8\x89\xdb\xb0\xeb\xf8\xde9'
|
|
|
|
|
|
2024-12-14 17:54:53.835757 - Ether / IP / TCP 192.168.1.11:40573 > 142.250.200.106:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 60586
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.200.106
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40573
|
|
dport = https
|
|
seq = 1062958771
|
|
ack = 991711801
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 508
|
|
chksum = 0x1956
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xe1\xc4\xf6\xb1\xad!z\xbe9\xbf"\x19\xb7\x1e\x9e<\x8e\xa1eH\\p\xb4\x920f\xea\xf8\xfeF'
|
|
|
|
|
|
2024-12-14 17:54:53.842443 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0x72ce
|
|
###[ Raw ]###
|
|
load = b'Q\x8frO\xb9p\x9aP\x1a(\xeb\xc3P\xf3\xb2\x15\x02\xea\x84\x16\x94\x1c\xd9rq'
|
|
|
|
|
|
2024-12-14 17:54:53.849964 - Ether / IP / TCP 142.250.200.106:https > 192.168.1.11:40573 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 34089
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xa58e
|
|
src = 142.250.200.106
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40573
|
|
seq = 991711801
|
|
ack = 1062958771
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 941
|
|
chksum = 0xaf72
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x8c\xa4\x9d\xea\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:53.856743 - Ether / IP / TCP 142.250.200.106:https > 192.168.1.11:40573 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 34090
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xa58d
|
|
src = 142.250.200.106
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40573
|
|
seq = 991711801
|
|
ack = 1062958806
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 941
|
|
chksum = 0xaf4f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'O\xe7\x95<\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:53.924128 - Ether / IP / TCP 172.65.236.181:https > 192.168.1.11:40740 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 41091
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x49a2
|
|
src = 172.65.236.181
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40740
|
|
seq = 3095617723
|
|
ack = 3402305305
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 8
|
|
chksum = 0xc11e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00_\x9e0\x10'
|
|
|
|
|
|
2024-12-14 17:54:53.930206 - Ether / IP / TCP 192.168.1.11:40740 > 172.65.236.181:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 49634
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 172.65.236.181
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40740
|
|
dport = https
|
|
seq = 3402305305
|
|
ack = 3095617724
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0x5ac5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:54.017184 - Ether / IP / TCP 172.65.202.201:https > 192.168.1.11:40741 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 41540
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x69cd
|
|
src = 172.65.202.201
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40741
|
|
seq = 1086778143
|
|
ack = 2364320777
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 9
|
|
chksum = 0x7150
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\xfd\xd3\xdf\xbf'
|
|
|
|
|
|
2024-12-14 17:54:54.021707 - Ether / IP / TCP 192.168.1.11:40741 > 172.65.202.201:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 44950
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 172.65.202.201
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40741
|
|
dport = https
|
|
seq = 2364320777
|
|
ack = 1086778144
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 510
|
|
chksum = 0x38d9
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:54.044348 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 57
|
|
id = 53866
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 37
|
|
chksum = 0x8ef
|
|
###[ Raw ]###
|
|
load = b'Y\xf3wB\xde\xaf\xa6\xa7\xe0\x0eI\xa7\xe6\x9d\xa0C\x86ba\x9b0V\xf4g<Q\xe4\x1eY'
|
|
|
|
|
|
2024-12-14 17:54:54.066274 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0xe534
|
|
###[ Raw ]###
|
|
load = b'G\xcf\xdd\t\x8a\xe8\x8d}Z\xe9\xe1\x1aWxBH\x92B\xb3\x8b\xc2?\xc4\xac4'
|
|
|
|
|
|
2024-12-14 17:54:54.084699 - Ether / IP / TCP 172.65.208.22:https > 192.168.1.11:40739 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 5377
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf1c3
|
|
src = 172.65.208.22
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40739
|
|
seq = 2490404189
|
|
ack = 3087247988
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 9
|
|
chksum = 0x4c9b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\xcb\x8f\xf2*'
|
|
|
|
|
|
2024-12-14 17:54:54.088678 - Ether / IP / TCP 192.168.1.11:40739 > 172.65.208.22:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 32628
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 172.65.208.22
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40739
|
|
dport = https
|
|
seq = 3087247988
|
|
ack = 2490404190
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0x3e26
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:54.180584 - Ether / IP / TCP 172.65.240.166:https > 192.168.1.11:40744 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 105
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xe5cb
|
|
src = 172.65.240.166
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40744
|
|
seq = 2989982210
|
|
ack = 2215829312
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 9
|
|
chksum = 0x18bf
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\xc6\xce\x03\xf9'
|
|
|
|
|
|
2024-12-14 17:54:54.187633 - Ether / IP / TCP 192.168.1.11:40744 > 172.65.240.166:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 39717
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 172.65.240.166
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40744
|
|
dport = https
|
|
seq = 2215829312
|
|
ack = 2989982211
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 508
|
|
chksum = 0x5eb6
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:54.203558 - Ether / IP / TCP 172.65.198.159:https > 192.168.1.11:40743 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43337
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x66f2
|
|
src = 172.65.198.159
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40743
|
|
seq = 3154762007
|
|
ack = 1892183454
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 8
|
|
chksum = 0x66cd
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00k\x1a\xe0\xcd'
|
|
|
|
|
|
2024-12-14 17:54:54.208103 - Ether / IP / TCP 192.168.1.11:40743 > 172.65.198.159:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 56750
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 172.65.198.159
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40743
|
|
dport = https
|
|
seq = 1892183454
|
|
ack = 3154762008
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x34af
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:54.281027 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 57
|
|
id = 53867
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 37
|
|
chksum = 0x8ef
|
|
###[ Raw ]###
|
|
load = b'^\xf3wB\xde\xaf\xa6\xa7\xe0}\x92\xc4\xf5\xf3\x8f\xbew\x14X\x8d\xbb8T\xe4\x1a\x1c;\xd7\xf2'
|
|
|
|
|
|
2024-12-14 17:54:54.292819 - Ether / IP / TCP 172.65.238.60:https > 192.168.1.11:40742 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 9950
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xc1c0
|
|
src = 172.65.238.60
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40742
|
|
seq = 2282652292
|
|
ack = 2490636353
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 9
|
|
chksum = 0xfb6f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x10\x08M\x81'
|
|
|
|
|
|
2024-12-14 17:54:54.299740 - Ether / IP / TCP 192.168.1.11:40742 > 172.65.238.60:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 14875
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 172.65.238.60
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40742
|
|
dport = https
|
|
seq = 2490636353
|
|
ack = 2282652293
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0x5c4c
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:54.305715 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0xed3a
|
|
###[ Raw ]###
|
|
load = b'^\x90\xe8\xb6(\x8d\x10\xb2\xa5\x97\xae[4\xb6\xae\xba\xd51\xe7\xe2`N\x0bk+'
|
|
|
|
|
|
2024-12-14 17:54:54.537966 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0x8d5a
|
|
###[ Raw ]###
|
|
load = b'RJ\x8c\xf1\xc5>\x1b\xa2%a\xb2\xa8\x16\x97\xae\xaa\x86\x07\xf9\xc69)\xe38r'
|
|
|
|
|
|
2024-12-14 17:54:54.744906 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 57
|
|
id = 53869
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 37
|
|
chksum = 0x8ef
|
|
###[ Raw ]###
|
|
load = b'L\xf3wB\xde\xaf\xa6\xa7\xe0\x80$\xa0\x11J8\\\x07y:\xfd\xff\x1f0`\x92\xa4<\xb1\x06'
|
|
|
|
|
|
2024-12-14 17:54:54.774062 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0x68e5
|
|
###[ Raw ]###
|
|
load = b'QY\xe9\x89\x16\xfc%v\xbe\xe0&\xc5\xad\x8b;\xcd\xab\xc2E\xe5U\xbc\xe3U\x1f'
|
|
|
|
|
|
2024-12-14 17:54:55.008084 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 45708
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdb4f
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412657474
|
|
ack = 1692640772
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0xedeb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\xac&i\x9b\xf1\x90pd\xefl\xe5\xbfC4J\n\xcbT\xa3\x18\xac\x1b\xc0\xd7\xbe\xcc\nl\xca6\x85\xcd\x83\xb6\xb1\xcaH\xf73\xaby\xb3\x8c\x00\x9d\x15z\n\xaf\x9c\xf8\xed\xee)\x9a4\xaeu\xb5\x1e\x01\xcd\xd1\x80}\xf51\x05s\x0f%)\x9ffZTX\x81\r\xfatJ\t\xc5\xfb\xe3\xa8P`6\xb8\xa2R\xad[\x95,\x9dJ3\x1b\x0btD\r\xae\xb0\xb7Q\xd0c\xb4g\xbe\x04\xca\xf9?\xea\xe8\xc5y\x87\x83\x80\x01CP6r\x93,\xfeN@\x1f\xee \\\xd4\xd6r.p\xd5\xd8\x88UKU@KKW\xbc\xfe\xf5\x11\xe2f""\xc7g\x11\xbc}\x88\x82\xd8\xe5\xf4\xcbt\xc0\xd6x\x0e3\xcd7\xee~\x914l\x993\\\xb1\xe8P%`}\xf2\x01J\xd3y\xab\x84\x1cV1h\x87\xed\xd4\xf7> '
|
|
|
|
|
|
2024-12-14 17:54:55.017029 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 49798
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcb55
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030875116
|
|
ack = 17610682
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1517
|
|
chksum = 0x1b7f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\xa9\xa2|\xa9\x8d\x1bo\xcb\xd6\xd0<~31\x89W\x7f,@\x86r\xa5\xc0E\xa4a\xcd1\n\xbc\xc7\x11\xbbD\x1c\xba\x8b\x07\xeaM5\xd70T\\mF\xaehEo\xb3\xe8\xbbe\x8f\xccGF\xc7\xb2\xac \x12\x12\xa5\x17\xb7\xb3\xd4{\xb5b\xc4\x81\xb7\x0f\xf2\xf1\xfc<Ri\xd2?\xd2\x7fz\xb45:$\x85\x88^\xf3\r\x02\x07\x8d?\x8e\x96\xcf\xec\xfd=`\xf8\x12\x0bDr\x19\xaa\xfdN\xc0>\xe9>)^\xc5\xadc\x14\x1e\xc4\x92\t\xa0b\xaaJ\x18\xb4t\xdbo\x04\x14\x16\xea\x17\x96 \x04PrG\xe4\xf8\xfc\x1c\xf6\xfe\x93\xdc\xbd\x9b\xe3\xaa:J;X\x1d\x89\xb2*\xd1\x1d\x8b\xfd\xcb\xdc\xb1\xe25\rDB\x1fV\n\xact\xf4F_#d\x1dE\x043\xb3H\xa0\x87F\xf1\xbc\x89\xb6\xc5/iU*|'
|
|
|
|
|
|
2024-12-14 17:54:55.055479 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16608
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692640772
|
|
ack = 3412657691
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2066
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:55.060023 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16609
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17610682
|
|
ack = 2030875333
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4136
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:55.165086 - Ether / IP / TCP 192.168.1.11:37795 > 20.54.37.64:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 83
|
|
id = 26849
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.54.37.64
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 37795
|
|
dport = https
|
|
seq = 2419269640
|
|
ack = 837223361
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 514
|
|
chksum = 0xfb6e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00&\x00\x00\x00\x00\x00\x00\x00\x0e''\xfc\x9fw5\xfbg@#\x9e\x9dV\x02m\x8f\x8b>v\xd17\x8e\x1f\n\xe0\xd6A\x86\x96i"
|
|
|
|
|
|
2024-12-14 17:54:55.180459 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 57
|
|
id = 53870
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 37
|
|
chksum = 0x8ef
|
|
###[ Raw ]###
|
|
load = b'R\xf3wB\xde\xaf\xa6\xa7\xe0\xd2\xf6\xe7\x80+R@j^\x86P\x87\x99\xd6\x8d0\xac\xe7\xc6\xf8'
|
|
|
|
|
|
2024-12-14 17:54:55.200997 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0x8835
|
|
###[ Raw ]###
|
|
load = b'ESR8_Bd\x9d\xbd\xd4\xa2\x92\x0f\x9f\x84\x0b\xe8\x9b\xe1\xb7\x06\xd5t\x17\xdc'
|
|
|
|
|
|
2024-12-14 17:54:55.216470 - Ether / IP / TCP 20.54.37.64:https > 192.168.1.11:37795 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 214
|
|
id = 58696
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 107
|
|
proto = tcp
|
|
chksum = 0x2eb0
|
|
src = 20.54.37.64
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 37795
|
|
seq = 837223361
|
|
ack = 2419269683
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 7682
|
|
chksum = 0x3c28
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xa9\x00\x00\x00\x00\x00\x00\x00\x0f\xfb\x15\x18\xa8\x1f\xed\xba\x98$A\xe8\x0c\xbe\x10\n\xc5\x98\x1a\xba!(y\xd6\xe8\xc8\xa8^t$f\x8e\x13\r\x12\x17\xf1\xbf\xbd@v7yu\x8b6\x17\x17\xb8\xf1P\xba\x04\x9b\x0b\x7fX(!\xb8\xda0T\xab\xc0\xc7\xd2)\xca"\'\xac\xec\xff\xb2_oJ\\\xfdG\xb0m\xeb9"__{\x04k\x98t\x8d\x93\xc9\xb3\xc4\xec\xfe\xa6\xe3\x9a\x02\xf9\x9f\x88\x83\x91\x84~\xad+\xb4\x03\x03\x8c\xc1\xce\xe1\x10C\xcce\x02\xb4!\xd6\xa4\xbb\xfd\xbb\\\xc6@O3r\x85c \xa0C\xa8C\xeb\\\x16#\xb4o.\xa0\x9e_.TY\xaf\x0c\x9a\x00'
|
|
|
|
|
|
2024-12-14 17:54:55.254497 - Ether / IP / TCP 192.168.1.11:37795 > 20.54.37.64:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 26850
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.54.37.64
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 37795
|
|
dport = https
|
|
seq = 2419269683
|
|
ack = 837223535
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 514
|
|
chksum = 0xfb43
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:56.031782 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0x3755
|
|
###[ Raw ]###
|
|
load = b'S\xe5oW\x11W=\x9cyg\x12\xb0;\xef=\xf1yR\xb5\xc2\xac\xeb\x18u\xb5'
|
|
|
|
|
|
2024-12-14 17:54:56.070115 - Ether / IP / TCP 192.168.1.11:39454 > 52.84.66.19:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 16610
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39454
|
|
dport = https
|
|
seq = 20247212
|
|
ack = 1095416445
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 515
|
|
chksum = 0x3855
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00\x1b\x11\x91q\xa2\x82E\xf6\x0e\xdf\xa9'\x8fF`Vd\xdd\xa1\x89!\xad\x17/h\x1c\x8d<"
|
|
|
|
|
|
2024-12-14 17:54:56.074779 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 90
|
|
id = 16611
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692640772
|
|
ack = 3412657691
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 2066
|
|
chksum = 0x3867
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00-\x8d\xe5\xdb\xf5\xca%\xaa\xbc\xf5!\xa1\x99\x9d\xd6\xf66i\xc5\xc7\x0f\x03\xfe\xe5\xcc\xd6E\x9a\x98\xc5?rc\xc6\x9b-\x9ax(\x1f\xf5A\xd8G\x8b+'
|
|
|
|
|
|
2024-12-14 17:54:56.079109 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 90
|
|
id = 16612
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17610682
|
|
ack = 2030875333
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4136
|
|
chksum = 0x3867
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00-\xd4\x10V\xb4\x05\x8b\xe0\xc2\xad\xa3?\xae\xb9\xfa\xb9\xae\xb5\xfa\xc7\xf4\xf2PJ\x08B\xb1\xfeH+\xef\xf1\xee-\xb7Q"\xae\x8a\xb5\xf7:\x91\x90\x00\xe1'
|
|
|
|
|
|
2024-12-14 17:54:56.084108 - Ether / IP / TCP 192.168.1.11:39492 > 52.84.66.19:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 16613
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39492
|
|
dport = https
|
|
seq = 394882544
|
|
ack = 3877224638
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0x3855
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1bY\xd8a\xbeq\x04\x1a8J4\xd6\x10\x0e\xb7\r\xa1NZp\xc4\xac\x82.\xf8\xf5\xe0\x13'
|
|
|
|
|
|
2024-12-14 17:54:56.091891 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 61832
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158781427
|
|
ack = 3359208130
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4098
|
|
chksum = 0x8fb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x0cY\x8a\xf7\x02\x02x~Ihk\xc0\xff\xcb\xb6y\xc7V~w\xf7\xca\xea\x85\xc77\n\x82\xf63\x12X\x10u\xc8\r7{\xb8\x89L\xfbU\x8eo`\n{\xdd\xd6\x91\xc1S\xd5\xea\xde\x05e\x00\xea\x1e\xec\x8d\x8a\xe7\xd8G\xe7ht`#\x07\xdf\xe4\x9f\xf1:\x89\x085\xf9\xd0S\x19=M\x82\x99\xe5\x1bA\xd7\xba\x80\xb7\x04\xe1\x1aCS\x1c\xf0v\x8c\tVNCP\xaa\xec(\xd0\x1b\x19\x14\xba\x8b\xc3\xda\x9d\x02\xa9\xd4\xf8\x99I\xe0S\x88\xe1\xc47%Q\x12/]\xa7I\xe1\x0c\xb1c3r\x17\x11(\x07\xeecjT\x12\x93\x94}\x03\xed\xeeL\xc0;.\xad\xac\xb3\xe6\x117p\xe8\x95\xffZ?\xfa\x9e\xf8\xf5\x7fE\xc9\xbe\xc9)\xb4\xfdJQV\xe4\xab\xfcs\xbe\x9f<\xd7E2\xa5\xe7yU|w\xfe\xa0&YT\xce\xdbG\xb0\xaaP\xafM>d\x9d\x01%Y\xc7\xca\xd1\xb6\x07Qu\xa5Q(<\x84\xaa=\x86zD7ln-\xd6ws\xca\xf7]\xdd]]U\x83\x17\xd0\xf5Dh\xa6\xf0#\xe6\xb2:\x07\xbeN$\xbbyc_3\xd1\xb8\x0b<X\xcd(\xc7\x0e\x05\x16\xb0Y\x92z\xd9\x96\xb0\x8a\x9b\xc6\x02.t\xafM\xe5\x9a\xff}\x05\xde\x8eou\xc7\x13__}\x9e\xf3R\xc1\xefH\xb0$\x86\xcf\xdf\x9d\x93\xc3\xee`\x97`\x80/1\t\\\n\x14\xdc\x92\xd8v/\x80)^\x17\x03\xa9\xff\xe8\xed\x15\x99[v\x12\x9f \x00R\xa5\x07.\xa3\xf7\x7f\xed\xad\xb4\xe69v\xc9U\xeb\x95\xb3\x85\xb9\xca\x88\xf6~\xff\xfc\xd5\xde|\xa0OI~\xa3\xfa"\x9b\xe0\xc4\xc2;\xbf\x8a\x82q\x01\x02\x02\x0c7`\xa4[\x8fE2\xd4t:zi\x05\x1aX\xdc\x17\xc9}c\xc9\x80\xf7ju\x0c\xc5\'w\\\xdc_Kv`\x0b"?6\xcf\x95\x1d\xfb\x16`\xee]D\x1a\x14\xcf\x86\n\x96\x83tjc\xe9l\x06\x13\x00m5S\x8fZq\x93\xdfWJ=\x15\t\xcb\xa0\thE\xd6\xa5C-\xdd=e\xc1\x80\xec\x9c\xe7C\xa7!\x06\nK(\xe4\xd4\xf5\xe8Ug\x95\x8f\xe6\xe4\xd0\x83\x85\xf05\xdd`\xc8\xe7\xa4\xc2A\xf6\xa8!\x8e\xb0\xff\xa8#\xca\xc4R\xb5Z\xd3S9A\xef\xb3\x80\xfd\xe5\xa4\xbc;\x8a\xbc\xd5\r\xcbk\x895g0;e\xfe`\x14\xd7\xdc\xab\x0cQ\x84#\\m\x07\x90\xc7\xe155\xebA*\x04\x82\t\x87\xfdS\xa5\x0e\xb3\x1fa\xc7\x92\n\x96\x89H_\xa1\xf5\xb4z\xfa\xcb\xc9\x0e\xbb\x7f\xdf\x8b\xb6\x8e\x1c\xb6\x8eh\xbf!\xa9\xf5\xc3\xc9(\xa4\xd3\x07\x8f\xa8\x14\'\xb2k\x18\x8b\xfe\x10\x8c\xdcR\xec2\x92W-\xe0\xa6\xbb\x12G#\n1\x8dI\xeb:\xf9\x94\xa6\x87~Z\x9f\xd3J\xbb~JVr<<\x1cNGD\xb5\x06\xfc\x90\nGC\r\x80\xe5\xba\xca\x859k\xd2\xb4\xd7\xa0 Z\xdbon\xcd\x98\x8c\xb28\xfe\xc8\x0e\xad}\x8e\xe1"\x1d\xfe\xdfvsl\xc8\x01\xf9oo/\x99\x1b\xcb\x8a\xbfi\xea\x8c\x05\xb7\xeb\xa7p\xe4\xf9x\x08\x92\x82\r\x9d\xa5\xackU\x18hx\xf2\xd6K\xbb\xda\xaf\x10}\x05\x02\xeb\xab\x1b\xed\x1b\x80\x1aP\xcc\x94\xb5@\x1c\x04\x11,\xac\x17C\xad\xd2&\x1b\xc1\xadz\xfa{\xbf\x0cL\r\x8aW\xd4\xdf\xf0{\xb0\xc05\x05\x9bN#\x9b\x04K \xd6#S\xed\xb4\xccEuk\nc\x84\xde\xa9\xab~)\x83\xc0\xabe\xb2f\xf5\xbc\x96\x9c\x14i\xc3\xe3\xd4\x10\xe21\x9e\xc5-\x17}4\x87\xc8\xcfLe\xe4=\xc1\xdb=\xdc\xac\xa0\x89\x19\r\x14\xca\xf5\xe1g\xfd\xfe\x04\xc4~7}z\x84aK\x19\rP\xac\x15C\xa52\xf4\xa7\xe6\xbd\xb9\x18\xb7_\x91<\x07\x1e\x99\xf8-\xe3\x08\x9e}\x99OT\x1e\x14\x9eV\xafO\xf12\xf0\xd3X\xcc\xaa\xc4?5\xd4\xa7\xc2L\x03\xdd\'\xc61:L\x91\x127\xdc\xb7\x7f\xd9\xdb\x86\x84\xee\xd5\x01\x93)\xdd^\xc8B\xe8\xb3\x04\xed\xad\xba\x98k$\xe4\x17(z\xc2\x94\x97hU\x9a\x0e/\xfb\xfa\x9a\x89\xa7\xb1\x80/\xedn\x15y\xf0\xa3\xdau\xfc\xdb\xc4G\xba\xcfg\xf3\xe2\xec\x03 \xf3\x99?1\xb7B\xf8\x98\x04\xb1\x05\x1cb\xdf\xac\xab\xcb3\xf3\x8b\xda\xe1\x19\xdf\xd2\xae\x14\xee\x83\x8e\x04\x08\x8bF\x0f\xde\x9e\xf2LMg\xc2g\xae\xf6\xc8~\xb9\xc2\xdd-\xc2\x9f\xc7\xd7\xf8\xf6r\xcc\xa1W\xb8\xcb|\xee\x0e\xfft\xa3v\xd6\xd7ag\xfb\x986\x1e\t\x91O\xb6\xfa\x7f\xac\xed\xbf\xfa.\xaf;i\xf3\x9d\xad\x8c\x91S\xbd\xb2$\xc5k\xfb\x87\x85fe\xcf#\xd6U&u\x11)\x9f\xad\xa5\xd1\xd6E\x90\x86\xf3\xbe\xe95\x03\xf3\xd8\xec\xe6\xf1\x08.M\x8d\xaa.\x05\x9dfY;\x8b\x1bw\x03\x8b\xa8I\xf0r\xaa\x1d\xa6\x01\xaf\x07\x9aXG\x8c\xa6\xb5\n\xf0]\x08\x89\xe9\xa0\x98\xc1I*\xee\x94 \xa2\xd8T\x9dr>`\xf4\xf5\xd4\xe5\x1a\xce\x8b\xaeN\xff\x0c"\x8a\xdd\xca\'\xb7\nK\xb1q\xf9\xd6_a\xca\x98\x15#\xcb\'=#\x89lH\xbc\xd4\xa9\xb3\x8e\x05K \x1bj\x7fg\xfbh\xb4\x92i\xa9\xd7>\xb2\xe5\x0f_\x9d9`v\xc5\xd2\x98\x81\xf8\x1aC\xb0{O\x04\xb7\xff\xee\xa6x\x8d\x9e\xc6\x9d\x17\xf0\x92w\x1d\xd0\x1dEN\x05]\xbcbNR\x99(>q,H\xc3\xdbMy\xcb2\x16A=M\xf7\xac{D$Y\xb7\x157?$n\xfdV\xf5\xdaf6\xbcy\xc13t\xf2\x1e\xa7\xaa\xb9v<\xb6\x02\xd3]q3G\xed\xd4\xa0S\\\xc4?\x8b\x07\xcfM\xd8\x00\xd7S\xa8\xf0\xf9Y\x02\xcew\x1c/\xc55\xbf\xaf-\x86\xb2o\xe82\xe7\xb6\x89\xc1,\x8a)y2H'
|
|
|
|
|
|
2024-12-14 17:54:56.099506 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 61833
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158782839
|
|
ack = 3359208130
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4098
|
|
chksum = 0x8fb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'_\r\x7f\x17\xed\xa3M\xc5\xacgo>\xdd\xb0?\xb8\xc2\x8e\x92\xeb\xfb\xa8\xd3\xb2\x00\x9b\xfa-\xc7\r\x8b\x8b\xfbV\xd5\xf1\xa0\xf0\xa2\xc4\x1d\x97\xc1\xc3\x0e\x05ZD\xd9w\x90>i\xc1\x86J}v1D\x00O\xd7x\xdc\x01<f\x15\x91\xder\x10\x9ax\\\xb0IS=\t\xe1\xbaz\x05M{-Y\xd9\xe8\x8by\xa7\xe0\x7f\x93[X\x9cnV\xbdI\x0b;\xdd(3w\x81\xfb\xbf\x82\xca\x08\xa9D\xf2\x1c\x14\x04C-\xea\x9f\\\x0c\xdc\xd9\x1a\x97\xd2P\x82"c\xf5\xe9\xd05\xa7H\x01\xdbE)\x17X\x88\x13^H\xf0J\xe7\xd8\xaf\xd0\x07jc\x9a\x916@\xb7M\x06\xaa\xa1IA\x84jj\xf0H\xf2\x15$\x04_(A\xe0\x90\x11\xf2\x95\xe4fj\x94\xf5[q\xc4~I\x9cz\xfa\xef\x8c\x0c\x1e\xf0\x8c\x95\x9b\x18c\x9e\xea{\xbc\xb5\xf8\xb5\xa3\x8f\x1c7\x17\x97bD\xb6\xbc\x15\xc6\xe0GVh\x84\xa8WL\xf2\x05h\xd3(u\x91\xe5\xe3~W\xeaLa\x98X\x06\xda\xd2\xce\xbb\x17R8\xa5\xd6\xa7\xd7\xb3\t\xfa\x14\x87\x0emy\xc72\xe8j\xb5\xd0\x96\xe6V\'Gh\xef\ti\xcb\x803ef6\x9b|\xa1n\x9a\x8am\xa2\x97\x9c\x01\xa7\x8e\xf1\xc2\xd1o\x8f\x17B\xf1\xe9\xf8\x86\xealJ\x11d!\xeb\xda\x16\xb9\xe0k9\x84Q\x19\xec\xd4\x14\x17\xfc\x94\xafL\x85\xb1a\x97o\xfd\xfaK\x1d-\x06\x15\xe5\xf2\xaf\xa2-\xb7\xf7{\xd9\xcc\x84E\xf7WL\xc5{[d\xd0*\x9d\xd4\xf3\x89\xbb\xbb?\xe2\xe7\xcb\xbd\x14Ere\xf5n-\x93\x92\xdfi\xb0\xedj\xc0\x08\xef5\x7f\xceI\x1c9DH\xe7\xceJ\x93\xe0\xee\x95\xfcx\xbb"\xfb\xf4p\x8d\xc0\xb7\x05\xff\x1d\x97\xbd\x1c\xce\xa8c\xc4cRU\x11\xd7\xea\xf6\x7f}-\x83\x9e_44\xb6A\x9c%,\x8f1\xef\xb0\xdd\xf7*\xad\xcc\x08\x98nt"*\xed8\xaf\x04\xdctF\xa6\x1b2\x82z\xa93M`Rt\x9b\xc6\xf6M}\x01I#\xcdt\xc3.\xcd\xae\x90D\xf0A/<<\x94\xd3vj\xfd)v\x91z\x00b\xc1,\x11:\xa5Q\xf3S\xabb\x06\t\xd1P\xa4\x95\x8djt\x81r\x0bfX\xd1\x87\x05Z\xc5OL\xce\x01/\x83\xa7uU\x83\xf4}$"\r-W\xf9&\xdb\x1c\xe5\xd9\xf5Q7*o{V\xafR?\x00\xc6L\xa5\xbe\xdbU D\xc0\xd4rS\xe7\x10\xe7T\xfa6ls\xd2\xc0Q\x1d\x17\xb9\xf3\xfcsh*\xe1anr\xcdWk\x9e\xe5\x1d^\xc1\x0c\xf7\x19\x82\xe1\x85\xec\xc0x\xf1\x9f\xcb\x10\x98z^dl\xb6\xdc\x16C\xb3\xdf_\xe0TK\xc0F\xfaTp\\7v\xc5x\xad:\xf5;\n\xec\xa7\x9b\xc7\xf9\x04F\xe5\xaf\x1f\xedt\xf4\x99j\x1f\x8d\xaeS;\xac\xad\x92lnM~\x83CN\xab\xc7\x84C\xe9\xe5|n\xf3T\x0bR\xf5\xf5\xe3\x03\xe1\x18\xafF\x04\xbc%\x8a\x1e\xad\xe3?\x8f\xb6\xcd\xff\xf1\xd7\xbf\xd4\xbb\xad)\xab\xca\x0c\x9aq\x009x\x87\x1b\xe0\xc8B:\xd3\xd11)\x1f\xbc1>\xadl$\xb0\x8dv\xf8\xf4\xe2V\xe5\xe8\xdb\xa63\xf0\x98\t\x93\x08\xeb\x7f\xb1Y\x8d\t\xfe\xe7\xd4)\xb0"\xcf_\xbe\xe1\xaf"\x7f\x1a\xcb\xed\xc9\xf3\xb1\x13\xf9M\x12\xe0\xba\x1e\xe4\xc8\xd6E\x82\xddV\xdf\xd5\x03\x11ij\x1c"\xe0sQP#\xf2\xa1qF\xf4yB\x86X\x9f=\xb3\xce\xa5%I\xce\x8e\x10C\xa9\x15\xfa\x8bS\xdd4,\xd0\x92\xfd\xb2V\xf8Z\xf3{\xa3\x08\xfa\x8c\xf0\x96u\xa3\xa0\x8aK/\xe4\xec\xd4\xcc\xd1\xa2\x9f\xb1\xf9\x8bg\x9eXN\xd3,9\x879\x9d\xe2]\xa7F\xadc\xc3\xcfD\x15\xe8\x81,\xdc\xc7{\x0c\xe8\xf7\xb9\x01X:\\`\x0f\xed.\xee\x8b\xbcE\xb9&?\xc1g6+\'\x9e\x17\x94\xad\xedCG\xb4>\xb0\xf6Kj\xa9\xfe\x96\x96\xab\x95C\xfb\x88m\xd9\xc886u\xb5\x97\xbbbG\xe6\xcd\x9aBUF\xed\x06(\x06\x18\xe7\x88\x9c\xd5\xd29\xd8\xbf\x13\x0f\xa5#\xba9i\xa0\xfd)\xb3\xba\xe8\xec/\x9c\xbeSF\xab\xc2\xa5\xefm\xeeA,nR\x08\xca\xdb\x0e\xf9\x0f9\xc6\xfa\n\xcdAs\xb9\x18\xf6\xb5<jA\xac\x1c;@r\xa4#C\x0e\xcb\xd2\xffs\x813\xf4\x94K\xeb\nrL"%\xe6\xea5<\xd7\xcd:\xbc\x96\x83\x94\xd0M\x02\xc2\x16\xab\x8a\xa3\x1b\xe9]%\x7f\xcct\xad\xfdc\x8d1&\x93FC\xc7\x16e$\x8c\x93X*T\x0f4\xfd\xa4\xcf\xfbaHX\xf1\xa6\x99\xc8\xd5\xb4\x89\n>\x17\x83RInrw1\xc2\xcd\x7f\xcb\xfa\xac\x8d\xa4\xa3\x87\x95`\xb7\xac\xa0\xed:\xb0\xed1\x13\x1c\xc6\x00\xcb\x19\xfc\x11 \xd1NCY\xf2\x1f!\xb17E\xe6J2L\xd3\xecf\x9c\x97\x1b\xff\xed\rX@"2\x93\x0f\xc9\xdcz\xa2\xb1\xc7\xcd\x17\xbd\x19{]Y\x13<g\'\xeae\xc02\x9b\xc8T\x10\xbf\xb2\x01\xeb\x1e\xcb\x14}1\xc4X\xe0\xe6o\x84\x101,\x13\xbc\x93\x9fqp7\x1f\xb1\xd5\xf7|w\xe1\x8abD\xd7\xa3\xa6\xdc\x92)\xf47\x9d\xca$S\x92`;g\xbd\x90\x85\xe7\x83\x0f\xdf\xe1\xd0\xfdN{\xa5d\x7f\xe3d\x7fAN\xdb50\xa3_\xf0/\xf9B\x07z\xa0r\xf3M\xbc\x9e\xbbt\xb2\x83\x11\x85\x0e8\x80\xad\x8bc\x8a\xf4\x1f\xa2\x9d\xc0\xa1\xc0M\xddG\xdf\xab>\xd3\x84A\x96\xc1\xe4\xc3\x91\xd4;d)\xd7\xe8\x88d\x11\x01UY\x08\xae\xc8\xbd\x014\xc9\xb8\xde\xbc\xf5\xb7\xb3\x05\x1bi\xe3\xe6\xbfN\x81\xd1\xb4\xf6\x01mQ\xd6\x0bs\xefB\xa2\xd7\xb5_\xf8Q\x90\xcf$\xf5\x9aE\x8f\x9b\xd7@\xcb\x0f\x00\xd8\xce'
|
|
|
|
|
|
2024-12-14 17:54:56.106321 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 382
|
|
id = 61834
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158784251
|
|
ack = 3359208130
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4098
|
|
chksum = 0x4cd
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x11@Z\xa9\xb4\xaci\xa9f\n\xce\xf4\xd9\x8f\xa4g\x8e\t3\xb6sn\xc3\xf05\x86\xd6{\xb3T2\x8e\xe6k\x84\x1f\xcb\x93\xe4\xe12L\xf9\x84\\N\xdb<\x0bd\xe0V\x8f\x83\xc2[_l`\xe8\xf9\xa3\n\xa9H1\xf4q\xf2\xf1?h\xbd\x86\xdcRz\xbe\xadvG\xd6\xea)]\xf8\x90\xc7\x92\xed\x0e~A\x15U\xd3\xa8xs\x18\xed\x0c\x98R@*\xb1`Tq\xa5\xa6\x038\xe05\xfa5\xa7i\x06\xbc}5M\x18\xfe\xe7\xd7e\x80\x03\x00\xc4\xc4\xb3\xf3x\x82\x88`\xd8c\xa3\x18\xbd\x86\xe1\xa4\nw!\x1cq\xb2\xac.\x92\x0fK\xf3\x9ao\x8dJx\xa3\x15\xd9H\xac[\xae\xdd9\x93o\xf5\xf1\x0e\x84\xeb\xbf~\xdbC\xd6\xd7J\xc9S\r\xad"\xc0\xce\x13\xf1\xe0\x8a9\x83\xa1%k\xf4"dU0\xc6\x81\xb6\xb2.\x01\xf9\xd7/bI\xfc\x9a\xd9\x90\x83 FA\x8c\xd1\x9b\xcc\xbe|\xc2\xc5*\x8d\xb1\xcf\xe7QS\x90B\xad\x8bj\xa5\xb1icI\xf9\xff\xd2\xc1\xb5\xdcd\xe0\x1byu\x1f;m\xb49\x9a4\x99z\x97q=\x1d\x9fgG\xc9n\xa8\xec:\xab\xe8\x8f\xdf\x14\x1a\xc4.\x84TB\x1d\x19\x1e\xd4G\xb5.\xc3~\x80\xdd\x0eK\xc8\xc6\xb0\xee\x11\xc4\xdd[h/+\xc3\xfe]\x1a\xaa\xc1\xfd?t\xb5\x87\x87\x8f\xa82\xc2\x0b\xa3\n\x9b\x8e'
|
|
|
|
|
|
2024-12-14 17:54:56.112783 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 163
|
|
id = 61835
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158784593
|
|
ack = 3359208130
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4098
|
|
chksum = 0x3f2
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00vW`\xd7N&\xf6\xbch\x1fX@\xe4\xb86\xbd\x80S\xb5\x87\x8a\x8b\xe4\xc3\xa3w\x974f\x0f\xd7\x1bp\xd1C\x90\x04\x1avna\x8e]h\xa2\x06\x0bw\x94\xd72\xeb\x17\x15\x05O\x1f\x91B'\x03T\xa8_\x89\xae\x12\xd1\xdcZ\xdaF\xbe.\xa6uf\xa2\x9b\xa0\x0f\x9f[#\xf4\xa6\xb8\xb0?\xca#Q\xd6S\xd8\tq0\x81\n\xe9\xad\x0e>\xb1f48?\xb0\x98.\x9d\x02\xaeb\xad\x96\xcf"
|
|
|
|
|
|
2024-12-14 17:54:56.117283 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39454 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 49855
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcbf5
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39454
|
|
seq = 1095416445
|
|
ack = 20247244
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 149
|
|
chksum = 0xeb82
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\xcf\xd3u\x7f\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:56.121508 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 45709
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdc27
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412657691
|
|
ack = 1692640822
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1022
|
|
chksum = 0xfb47
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'@\xc4q\xc5\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:56.126292 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 49799
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcc2d
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030875333
|
|
ack = 17610732
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1517
|
|
chksum = 0xf103
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'6\xe5\x12:\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:56.132081 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39492 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 7623
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0x70ee
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39492
|
|
seq = 3877224638
|
|
ack = 394882576
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 149
|
|
chksum = 0xadb3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'un+\xcd\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:56.137900 - Ether / IP / TCP 192.168.1.11:40566 > 142.250.201.67:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 140
|
|
id = 12164
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.67
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40566
|
|
dport = https
|
|
seq = 2571310693
|
|
ack = 1308406513
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0x1a70
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00_\xcb\x1eFo\xaa\x84\x0e\t\xe9\xfe@\x9dr\xca\r\xffB\xb9\xba\x01y\xddu\x87\xf0\x93G\xe4\xe0dZ\x1dQ\xff\x83m\x05\xdf\xaa!\xc8\xa5\xc0\xccbbdZ\x11"2\xe9F\x17F\x07\xa7!M\x1c\xc3\xbd\x0bG\xbcww\xd1\xf5\xa2\xabv\xdcy\x88\x8b3\xf2\xa8\\\x8bh%&\xa9^"\x86\xdf\xf4\xdc\xc2\x15<X'
|
|
|
|
|
|
2024-12-14 17:54:56.143490 - Ether / IP / TCP 192.168.1.11:40566 > 142.250.201.67:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 12165
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.67
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40566
|
|
dport = https
|
|
seq = 2571310793
|
|
ack = 1308406513
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0x1a33
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"p\xcf\xe5\xd4\x89\xe7\xc3Q\x05"\xcc\x83y\xae\xcc\xbc\xd5\xd2S\x19&f\x93\xa3h\x05r\x99a\xef\x90\xeaN.'
|
|
|
|
|
|
2024-12-14 17:54:56.147951 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43649
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95f2
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208130
|
|
ack = 158782839
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2980
|
|
chksum = 0xe6bc
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:56.151628 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 43650
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95e5
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208130
|
|
ack = 158782839
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 2980
|
|
chksum = 0xe66b
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (158784251, 158784593))]
|
|
|
|
|
|
2024-12-14 17:54:56.156859 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 43651
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95e4
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208130
|
|
ack = 158782839
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 2991
|
|
chksum = 0xe5e5
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (158784251, 158784716))]
|
|
|
|
|
|
2024-12-14 17:54:56.161697 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43652
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95ef
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208130
|
|
ack = 158784716
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 3002
|
|
chksum = 0xdf51
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:56.168748 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40566 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 484
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x28fb
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40566
|
|
seq = 1308406513
|
|
ack = 2571310793
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1041
|
|
chksum = 0x40a6
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'&\xbdT\x99\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:56.174343 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40566 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 485
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x28fa
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40566
|
|
seq = 1308406513
|
|
ack = 2571310832
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1041
|
|
chksum = 0x407f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x9cV\x7f\xec\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:56.179172 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40566 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 486
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x28d2
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40566
|
|
seq = 1308406513
|
|
ack = 2571310832
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1041
|
|
chksum = 0xbf8d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\xca\xbf1tS\x1e\xd7\xca\x8ab\xc0a\xff\xee\x9c\xd1\xa7\xdee\xb5|>\xd0\xb9a`y\x13\xa2\x12N\xed\x8a\xa2'
|
|
|
|
|
|
2024-12-14 17:54:56.184506 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40566 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 112
|
|
id = 487
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x28b0
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40566
|
|
seq = 1308406552
|
|
ack = 2571310832
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1041
|
|
chksum = 0x4e31
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00C\x8b\x0c\xfa\x85z8f\xff\xbf\x88\x11u)\xab\x14\xf7L\xb9\xfe\xab@\xba\xeeo\xd2\x89~\xaa\x83#i\xc4m\x8aSd8I9;\xaal\xcfh$\xe5\xab\xaaX\x92W\x035\xf8g\xa7\xe2\x00\xdd\xf4\x8c>"!r\x1a\xfa'
|
|
|
|
|
|
2024-12-14 17:54:56.189629 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40566 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 140
|
|
id = 488
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x2893
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40566
|
|
seq = 1308406624
|
|
ack = 2571310832
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1041
|
|
chksum = 0x8275
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00_\xc1\r\xc8\xb5\xb2\xe1C\x93O\x8a\xab\x95Y\xe4_\xa4\x14N\xd5\x9b\x11\x83\'[Z/\x86\x06M \x1a\xd4\xea\xab@"\xe2Q\xc3\xb8LK\xcf|oe?dU\xf3k\x8cu\x03\x87 \x8aF\xecG\xbc\xc5\x85x/h \x0f\xa4\xd1\xf0\xbd]\x9dty\x8aM\xb9\'\xc1\xc9%\xdf\x88\xee\xf6\x8e{[p}\xbb\x02q'
|
|
|
|
|
|
2024-12-14 17:54:56.193560 - Ether / IP / TCP 192.168.1.11:40566 > 142.250.201.67:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 12166
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.67
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40566
|
|
dport = https
|
|
seq = 2571310832
|
|
ack = 1308406624
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 510
|
|
chksum = 0x1a0c
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:56.198944 - Ether / IP / TCP 192.168.1.11:40566 > 142.250.201.67:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 12167
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.67
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40566
|
|
dport = https
|
|
seq = 2571310832
|
|
ack = 1308406724
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0x1a2f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\x1a\xb6G\xe4\xbf\x89\xf4\x18_\xfa\x93\x04\xa9\xa7\xae\xc0\x8bM?v\x8f\x8e\x9a?\xf1\xd4\x8f\xe7\x8d\xa0'
|
|
|
|
|
|
2024-12-14 17:54:56.203931 - Ether / IP / TCP 192.168.1.11:40566 > 142.250.201.67:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 12168
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.67
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40566
|
|
dport = https
|
|
seq = 2571310867
|
|
ack = 1308406724
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0x1a33
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\x12\xe80\x99M\x059\xe4gh\xd6I\xc3\x8d!\xb5z\x1a\xec\xabe\xba\x85\x8e\xaa\xdc\x98\xa0\x13\x97\x9c\xc1\x08b'
|
|
|
|
|
|
2024-12-14 17:54:56.208813 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40566 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 489
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x28f6
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40566
|
|
seq = 1308406724
|
|
ack = 2571310906
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1041
|
|
chksum = 0x3f62
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b"\xfa'\xed\x1f\x00\x00"
|
|
|
|
|
|
2024-12-14 17:54:56.231879 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 108
|
|
id = 43653
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95aa
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208130
|
|
ack = 158784716
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 3002
|
|
chksum = 0x63c9
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00?ZZvlbF\x95q\xfc\xa7\x02:\x029C\x08\x9c\xcfZE\x15\x98\xe9\xe0\x02\x95\x8a?\r\xb4\x92\xdfo_\x85\xe2i\xa2\xfcdYp\xb7\x8dH\x9c\xe69\x14\xa8(\x07v\x18w\x9bS\xbd\xce\xdd\xf2m.'
|
|
|
|
|
|
2024-12-14 17:54:56.237913 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 219
|
|
id = 43654
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x953a
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208198
|
|
ack = 158784716
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 3002
|
|
chksum = 0xa7eb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xae\x18\xc5\x10I\xfb\xbc\xe9\xb9h\x84\xfb\x02Go\xfcw \xb6\xe3\n\x88\xc5#X>/\x95\x00?#I\xe1o\xf0P\x12D5\xa4\x8e\x0bIn\x9c\xdbx\xc8\xc7G\xd2\xeb\xednS\xa8\x94&\x96nB\x7fvJ\xf5\x11\x91\x83%\xd8\x8a2\x91X\xd1M\x13\xe8*HV\xcf\x10\xe61C\xaf\xdcW\x12\x1c$\x04dZ[\x8f\x97\x08l\xbb\xe4\xaa\\\x84\xca\xeb\xcao\x8f\x8c\xb0I\xb9\x1f\xf5\xdfDx\x90m\xab\xdbJV\x0e\nh\x19q\xb8F\x14tt_\xac\x7f_H\x93\x83?\x8b\xed\xc8dx\x18\xc8\xc3C\x89\xc34U\xaf9\x15\n\x96\xd2\xc7\xda\xe5JqEdoF\xdbiP\x07'
|
|
|
|
|
|
2024-12-14 17:54:56.243107 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 88
|
|
id = 43655
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95bc
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208377
|
|
ack = 158784716
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 3002
|
|
chksum = 0xd818
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00+U\r\x90\x04\xd4\xe1\x18>~\x8f\xc3\xbbq\xcd\x87i\xdel-(/|\x8cof\xc7\xbd\x19\xfa\xedu\xcc\xc9\xaft\xc8B|\x0e\x9fB\\\xcb'
|
|
|
|
|
|
2024-12-14 17:54:56.247569 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 61836
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158784716
|
|
ack = 3359208377
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4103
|
|
chksum = 0x377
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:56.252384 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 61837
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158784716
|
|
ack = 3359208425
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4103
|
|
chksum = 0x39a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e{\xee3\xb0YD\x15\xa2,M\x02&n\xceA(\xd3U\x08\xf4\xc7! .\xba\xef\xb8I\xa2\xe7'
|
|
|
|
|
|
2024-12-14 17:54:56.257057 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 61838
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158784751
|
|
ack = 3359208425
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4103
|
|
chksum = 0x39e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\xb9"\x1c\xad\\\xe8\x00\x1aU\x96\xa8\x15{-\x0c=7\xa2\x11\xf9\x88\xe8\xc06\x96s\xe5\xf7f\x93\x8f\x13\xfb\xe4'
|
|
|
|
|
|
2024-12-14 17:54:56.262963 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39454 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 49856
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcbd8
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39454
|
|
seq = 1095416445
|
|
ack = 20247244
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 149
|
|
chksum = 0x7720
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x17\x12ee!\x91\xedC\xe4x\xf0\xb9\xb0\xf3\x1ao!f){\x07Z\xdc\x1d'
|
|
|
|
|
|
2024-12-14 17:54:56.267182 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 85
|
|
id = 45710
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdbf9
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412657691
|
|
ack = 1692640822
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x5805
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00(\x83q0,\xf8\xf9h\x1f\x00/\xbe\xcc\xada\xabv\xfd\xdfx\xd4\xe3\x1d\x08WA\xed\xc1\xfa|\xe2\xaa@\xb9\x8e\xe2\x0e\xf2b\xc2\xa0'
|
|
|
|
|
|
2024-12-14 17:54:56.271195 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 85
|
|
id = 49800
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcbff
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030875333
|
|
ack = 17610732
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1517
|
|
chksum = 0xa3e8
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00(K\xb0\xc6\xde\xa9\xf6\xb8\xf9\x9e8\x060\xf9\x1d\xd86\xbc\x07\x8b\x96\x90\x9dHf\xdb\xae\xc0\x8b\xee\xa6\xf3\x83\x9d\xc8B\x84\xaa\xe3\xcd\x95'
|
|
|
|
|
|
2024-12-14 17:54:56.276371 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39492 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 7624
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0x70d1
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39492
|
|
seq = 3877224638
|
|
ack = 394882576
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 149
|
|
chksum = 0xaf54
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x17\x14P#\xc9w\xce\xf3\x94\x13\xc2n\x12$\xf9X\xc4\xf8\x15\xde\xa7>\x00\x80'
|
|
|
|
|
|
2024-12-14 17:54:56.280714 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43656
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95eb
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208425
|
|
ack = 158784751
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 3002
|
|
chksum = 0xde07
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:56.284034 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43657
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x95ea
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359208425
|
|
ack = 158784790
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 3002
|
|
chksum = 0xdde0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:56.287985 - Ether / IP / TCP 192.168.1.11:39454 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16614
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39454
|
|
dport = https
|
|
seq = 20247244
|
|
ack = 1095416473
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 515
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:56.291268 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16615
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692640822
|
|
ack = 3412657736
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2066
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:56.295502 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16616
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17610732
|
|
ack = 2030875378
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4136
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:56.298081 - Ether / IP / TCP 192.168.1.11:39492 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16617
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39492
|
|
dport = https
|
|
seq = 394882576
|
|
ack = 3877224666
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:56.726642 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1274
|
|
id = 1603
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 1254
|
|
chksum = 0xca7f
|
|
###[ Raw ]###
|
|
load = b'^\xf0\xe0\x0fd\x16\xe2\xe8/\xac\xd5\x05\'\xa7`\xc3\xa2un\xa4uo\xb5\xa6pK2\xda\xbc\x8epy\tE\xce\xd5\x16\xa0J\r\xa4\xeb%4\xa7s\x9a\x19`k\xad>\x06\xa8%\xe5\xd7\xf4\x8fZ\xd0\'\xbc\xa8\xd0\xffH\xa4_\xd2w\x99-&\xdfDt\xb9\x93\xf9\x00\xf9\xbc9\xfd\xa1q|HuH,\x1c\xe1))U\xb2\xeb\x1e\x03/:\xe4\xc9}%\x17X\x15ovc(\x13\xc3\xcet\xed.\xc8S|\x89\x9c\x85Q\xa4f\xb7\xd3N\xd9|\xedH\xb2v\xc9\xe1\xf3\xb1{\x9c\x1c\x98\xa0.\xe9\xcf\x1a0\xa2)\xb5\x07\x99\x99$\x95\xe4\xd9\xd4hJv\x1f\x99\x1e\xc8\x15\xa19\xe3\x9f\xb1\\u\xe9\x9c\x01\x87\xe45\x18\xf0\x15\xb4\x0b\xf4\xcc?\x92\xb4\xb2`\x1f\x95 \x93\x19t\x9aX\xe0\x8c\xc5z]\x9a\xb4\xe3\xc0\xec\x8c\x18\x07\xe9\xbe\x1f\x11\xbaA\xf22?+\xe3\xab\xbf\xa4\xe6~\x15\xdc\xd5\t\xb4G\xd1)\x91\x0e\x98\x00\x806\x98 \x19?\x994\xaf\xab\x9e\xe4j\x91\xa6\xfd\x1d6\xffP\x95\xfbf\xe1\x9f\xae\x99<\xdc\xe7\xb2\x1b\xf5\xf0\xee\xfb\xf5\x85lc\xb4\xa5\x0fb<\xbb\r\xa1v\xd2\x87\xc7\x14\x96\x87\xc8b\tH\xbf#v0\xda\xfa\xca\x80\x9c\xd70cI\xea\xbfrw\xd0u\xe3\x0f\xf1W\xc1\x01.\xb2\x00\x8a\xa5\x0b\x8c\xb4\xf1\x9b\x1d\xe9\x1aM\x8d\x95#\xe1\xa6\xc8\xb8\x139\xe8\xa3\x06\xdab\xab\x1e\xcaem\xec\xb1\x98\xa1wZ|\x06\x0851\xfc\x1f\xcf\x8au\xce\x0f,\x98\xb1n}\x18\xc2\xde\xb9\xc6\x144\xb3\x833\xc5\xdc;\xcd\xab\\\xc1\xc1\xf1\x1f\xd4\x98\xe3\xc8\xf9\x03%D#\xb0\xcb\xb7\xde\xee\xe3\xa5\xfb\x9c2A[\xbe~\x19\xfc\xdfD\xcb9W\xa7\x7f&D\xa0\xd3?qf\xcc\xcd\xb9\xd9n\x03\xc8^\xe6*>_:z\x9e\x0e\xef2lM\x88\xd0\xe1\xfc\xe2\xc9O\\\x96\xc2\x91\rIL+e\xa0\x8eN\xfe\x86\xa3\x1e\xd4\x06\x15\xd6\x18\x96B<m\x95\x9ek\x85\xd8)\xab\x15\t\xad`\x8eNpO\xef\xbb?Z\xa6\xa3p\xa1\x9aL\x99~-\xb6\xc4\xa1\x99\xe0-+?\x82\tf\xe6\x14\xca\xb5K%W\xe8\xc1-\xd5\x1b\xd4\xd3\xf1\xf9\x08a\xa9\xc4K\xa4O\xc7\x0f\x94m\xefg\x1e\x0c\x12\xef\x7f\xfa\xedc,\xa3C\xf6\xa8E\x92\xd4\xf7\xa9\xb2%\x1c[\x89\x06\x9cG\xb0\x96U\xd8:[\x90H\x96\xb1\x93\xb3\x80\xde\xf7<\x04\xb4\x99\x99\'\x89\xba\xaf\xaaP\x89:\xd6\xc8]\x95lD\xd3\xbb\xbeu\xf9\x9b:\x16\xfe\xc0\xfc\xe4@\xeb\xdd6\x81z\xe2\x07\xb9\x05\xf3\xa4\x1b\x1a\xa1\xcfU\xedh\xb8Q\x08M\x1a\x01\x9d\xcb<\xc0\xcakm\x90\x16\x02\xbe\xa7R|\x02#\x8f\xa3Zt\x94\x1c\xc1\xd5\xe3\x0e\xd9n\xc1\xe4\xdbp.\x0f$\xf0(\x0f\xf5\xeb@\xdf\xe2\x9d\x96Ex\xd5|\xd6rz\x05\xcb\xf2;\xac,\xfa\xf01\xa9\x08\xfb\xc5>\xad\x83\xc76\xe3~b\xca\xa3(\\\xa5\xbe [/Z\x8aNW,\x1d3\x15\x14Lt\xb01+\xe0\x8d\x8f\xef79\xc8\xe2TM\x13\xebE\xdf1\x10\xbf\x96e#\xd9\x11\x99a\x88\xf8\x88\x90\x85\x89\x00s\xd93\xd8\xe9r\x96C\xffV\xc9\xa1\xe4\x85\xe0\xfdV\x12\x990y\xdc\xbc\xb1_\xee\xff&\xc5\xcc\xbf\x1cm\x9dRj\x1a\xc2\xf1\t\xb0\x9f\xac\x98\xe5\xd0\x941c\x9eq\x95?8\xecG\x96\x0b\x15b\x0e\x8c\r\xb4\xd1s\xf7\x0e\xcb\xaf\x9f\xf6\\\xa4\x08\x80f\xd9mO0A\x12\xb3\xd7\x8b~\xccj\xd69\xdc<;\x13\xa9.\xdd\xc4\x80\xb4\x0f\xb6\x06\xe7\xc2\xd8\xfa\x98-\xbc\xbd\xd4\xd0\xb8\xccI\x96t?\x93\x08G\x85E\xcd\xf8\x05\xc4\x92\xd5\x1e\xdb|\xe5\xc8\x9f\x80\xd4\xe2\xb7\xd3M{\xa7\x91\xf9\r\x8bN\t\x00\x86\xcdE_p)0a\xaf\xdf\x90\xfe\xb00\xcb\xd5\xd9\xfd\t\xba\x02\x83\xf4\xbel\xe8[|\x93\x88 \x02\xf0\xc5\x06\xaaG\x9d\x86\x19\x12\x83\x01M/6,{&XGb\xab\x1c.\x98\xb5]\xa7\x03\xee\xc8\x9fx\x91H\x8f\x19\xc2\x9a\x9b\x04<\x15\x90\x83\xach\xba\x81\x1c\x8c\x0f\tD?y\xc8Ob7\x89[}\xf3\xcf\x82\xb1\xf3\xd8\xb3\xf4{\xd9k\xe1\x02\xe3?\xd2\xef\xcd\x0f\xa4\x90\x9c"P\x9a\xadg\xe9\xbbM\x93\x97`\x82\xc7*\x9b\x07?c\xbdro\x01\xd6c\x80m\xd4~\xc0\xd5p\n\xbcV06\xab\xf7\xec\x93y{\xa7\xbf]:\xfd\xa4}@A\x8e\xe7\xa0E@:\x9avQ\xf5+\xdf^z\xfez\x99\xd9\x9a\x80"\xea\xb3}\xe7\xec-\x1d\xa7\t\xd7\xbakGx]RF\x0b+\xa5\xbf\xaa\x0f\xe8\xf0\x18)u\x10J\xa21\x1d-2\xd2\x8b\xe8\x148\xda*;<Yz41\xadsG\xdc\xb0\x9emlu\xc3\x1a#\x9a\xdf\xb3\x95\xd2Z\xfa\x8a\xcc\x12\x03\xaf<\x1aK\xbd\x82t\xaf\n*\x98\x08}f\xa2A\xacZ\xe1\xdbO\xcd\xca;\x1c\xa8\xe3\x83\xfbI\xe6Z\x05\xed\xd4V\xa9\x91Q3\xa4E\xba\x1bZ\xeeE'
|
|
|
|
|
|
2024-12-14 17:54:56.736249 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 1604
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca83
|
|
###[ Raw ]###
|
|
load = b'H\xf0\xe0\x0fd\x16\xe2\xe8/\x0b"\xdcY\xb0\x1cc\x85\x81\xc1\xbc\xd0\x98gY&\xce\xd3\xc7~\xcf\xc2s;yc!\x86\xa3\xd0?\x02\x87aK\xe0p\xde\xbaHE?\xf1\xe7ds\xd5\x9d\xf1f|\xb2v\xd2+\xee\xe9,\xad\x95V\xca\xed\xdb\x8dS\xb5\x9c\xb2P\x1alv\xd6\x88\xd2O\x11\t\x1as\xf2\xefb\xed\xbc\xbd\xdd\xe0[86tudo\x88\x96\x9e q[\xd0\xbeW\xdb\x90\xa8\x17c\x9a\xaa\x01\xd6\xa6\xc3\xe7\x06I\xffa7{i\x9d\x99\xdcG\x85#\xfb>\xc97\x07%\x89\xc4\x89\x8aF\xbb\x15b\x00\xd0\\\xb7\x00\x13\xccO\xed\xbe\xba(\x18\xd7i\x08\xe2Z\xcaT5y\xe0\x94\xd4\xbdeD\x90!va\x83""C~\x8e\xbb3]\x16\x05~\x12\xfbA<\x19\xe3\x15\x84\x8f\x06\xce\xe4\xaeT:\xd4MO\xecL\xda\xfb\xd7&K\xc9\xc97\xde\x98\x8f\xcf\x02]k\x94\x1f\x92\x15\xfb\xb0\xcd\x93\xf7k\xa8\\Kra\x95\xaf\x9d\xc4|NE\xce\xf6`5\x96\x16c\x02\x06fo\xca\xb3m\x81pZ\x17\xfc6\xb3\x1cW\xfb\x17\xbf>A\xd8m\xd5T\x10\x86@\xdf\xd1}\n\x18\\\x91\'\xb0\xcd!4|+\xcc\x94d\xf4k\xd8?\xaa\x17B0\xaa\xc6-\xc2\x80\x87j%\xa0\x90\xe4d\x86>\x0c\xccO\x7f`\x87\xaalD\x8c\xee\x92\xc8Yo\x89A\x17\xe9\x93\xb4<m`[$\xb1\r\x95S\xbf\xd3\xb7\xdar\xe9\xff\xdaO\x995\x83OL`\x12"\t\xb6\xef\xa0\x05u\xcd\x16\xd2\xdar\xba\x0cN\xffy\x96z,Ft\xe6\xc8`\xd1\xabds\n\r]\xfcS\xabm\xf0\x87\xc2u\xf8\xe0\x90\xeb;\x1b\xa7\xe7\xb8\xa1o0\xe8gM\xf8\xb6\xe7\xa7\xbam\xde\xa9\xb8\xf4\xbf"6\x0eH\xcds\t\xfb\x8cs\xc1\n\xaa\xce\x91mp\xc4^0\x84\x10?\x94\x84:q\xb4\x80c\x0e\x82\x9d\x8c\x91.\xb57\x81\xdc2e\xa1t\xf4g)%tg\xce\x8f\xf4\xa0\xe2 \xbd$\xe5\x86\r<\x1a\xd6\x01\xb1\x89/3!\x1b$\xc1h\x14\x96\xdc\xe3w\xe0\xa8\x90dfz\x15\xcb\xfco7+*#e\x965\xb8_\xfau\xdb\x9cY\xbdvm\xc0t?\x0c\xa2\x16\r\xf9Xi\x0e@\xb0\xbdM\xf4_T\xe3\x83\nc\x9b\xf4\x0b\x8ejF\xbe\xd7\xa7\x89v\x0c\x0e\xb1\x07\x19Q!\'\xb6C\xc0\x14\x88\xfa%\xab!\xa0\x94\xca?c\xc3<\x0b\xa2\x8d\x06\xec\xaf(\xde}\x98\x02\x84AX\xfc`>\x91!Z\xdfM\xb0\x90\x12_\x0f\xcb\xe4\xc2\xc3;\xd0\x90\x9b\xc9ek\n}\x84\xfbGD\xf7\xa9tp\x8e\xa7#Q\x88\x1f;\xba_\x86\xdeXr\xe1L[R&~?\x8cb\xd2\xa3\x1b\xde\xfc\x98\xc4\xfc\x9bW\x8c\x86\x16R\xcf\x9d\x8c/\xeb\x89\xf5d*\xfb\xfd\x1d[OaS\x8b\xf5\xda\x01\x1a\x11\xb5\xf7\x97\xf2\n+@\xc5\x90\x01=\x15#\xbcn/\xe1\x88WLq\xe5\xdd\x9b\x0e+\x90\xfb\xd0\xe2~\x89\x01X\xf2\x1c:\xb2\xd82^\x1f\xcd>\x07\x14\xdd\xe9x\x94\xc5\xdd\x9el\xd8\x1f\xd2\x9b\x9b\xe4pc<\xb6\xa7^\x81\x9c8\xbc\xdcop\xcac\xce\xf5\xccX\x16\xed%\nY\x80!8\x05\xae\x14\x19\x83\x83\x10\xc9@\xfdw\xcd%\x93f\xab\xe1}|X\xbbe\xc6@\xbdWz\x1c\x8a8\xd1i.\xdehz\xf6\x96\x15\xa6\xbdh\xf0\xa3f\xfc\x81\x1aH\x9e\'k[\x1db4\x04\xd2z\x88\xfeQ\xe0\\\xea\xf3m\x91\x90\x8ee\xb2\xfe\xcc\x00\xd6R\xd0\xc5\x8c\xe5\x7f\x05t\xfaE\xeb,Z\x8bB*_I_/\x93\x8a\xd0\x97G\xc8R\xf8:\x18^\xce\xe3\x14\x1b\x0f\xcf\x8f\xa1Br\x9d\xce\x87\xbb/k\x05\xe4\xf2\x14[\xcfQ\x8e\xb9\x9c\x9b.\xd1Q\xa8D`M\xa8\xc8\x8a\xae\x9f\xbe\xd0Y\xbf\n3\xf2\xbc^\x8c\xf6\x90\x07%\x9f\xa1C\x8e\x93\xac\xea\x05\x1d\x85\xea\x9d#\xee:\xa2\n\xf9\xa0\xc4\xff\x91tR\x7fy\x18\xfd\xa8hrlC\xd9\x90\\\xdc\x90\x10\x13\xafJC\x7f\xe3jq\xf1\xc0\x15\x08\xb2Vn\xa0\xa1\xa9h\xd8S\xde\x0c\x02\xcbv\xae5\xf6\x14+\x07\x94\x80)\xd1W"j\xb6\xe6\xa38\xafJ\xe2z2\xbd\xa3\xe2\xd2DL\xf1dW\xe8\x8fT\xceT\xfc\x8e\xafhD\xb89\x96j\xb0J\xac\\\x1b\xdb\xa5\xeeR\x91G\xc2\x84\xf3\xf3z\xfa\xb9\xfd\xa4\xf5B!\'V\x1c3\x90\xc1B\xd7\xe4\xdb_\x82&"\x10\xde\xaf\x91\xb5y\xb9\xf1\x1d\xe9\x19a\r \x82I\xca\xe64oV\x02\x83J\x12\xc2k\xb3\xbc\xba\x19Z(\x95$`^\x84\x02N7\xa7\xd6\xe8\x18\xdfV<\xcb\xcc?\xdaY\x91\xae]O:_\xfa\xf0\xc6\x14\x8f\xdb\x981}r\xcb\xd3\x0c\xd6\x8a\xa3L\xef)5\x12\xd6\xe2\x80\x85f\x92@e\xdcm90R\xfd\x0cDe\x1f\x96^/\x14\x86\x84\xd7\x81\x12\xb5\x82\xc3\xa5\xdb\xc9\xa3\xdbb\xa1vc\x1c\xfc\xde\xea\xa9\xb5\xf6\x93\xb1M\x1f\xe2\xf3\xdc\xb1+2\x08\xa79w\x13\xc6n\x9f\x04\xa9I'
|
|
|
|
|
|
2024-12-14 17:54:56.747776 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 1605
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca83
|
|
###[ Raw ]###
|
|
load = b'U\xf0\xe0\x0fd\x16\xe2\xe8/!>I\xc8\xfc\xbb]i\x95Xk\x08\xb6\x9c\xf8\xf8K(\x94\x95\x05\xe5cv\x08bu\x07\x9c\xc0\xf6D7\xfe\xe7\x17\x7f<EjU6\xd7\x0b\xc6\x7f\x1a\xdeGC\x9bi\xfd\x1dx\x14\x1d\xc7\x108\xab\xbc\xa8\xcec\x84\xe4v_9,k_\xac\x9e\xa2\xef?\xdb\xda\xde_\xb3Q\xcf[lI\x0f[\x0f\xf1\xde\xec\xddG<\x14\x14\xea9\xae\xcd\xa04aZ\xcc\xcfN\xe7\xe7\x1dXP:p\xeb\x83\xafX\xf3i)\x89cWfn\xde\x882\x99\xe5\xa1\x03\xc9\xed\x8d\xe2\xc5)q\xf6_\xc9\xac\xcf@\x13\xb1ys\xd8n\x95o\x11J\xc2\xa5\xbf#\xb1\x84]q\x01\xea\xa1\xa2\xae \xe2`\x8c\x8e\xa2\xaawN]\xab\xf2W\x1d\xdb5\xebH\x9c#\xcaVdf\xecW\xa5\xb5C\x0b-\xcb\x7f\x1f<7$\xfc1\x9f\xbddk\x9c\x00\xf6\x86P\xd2L\xe9o\xcb0\xa1\x17|<fj\xd8\xb9\xb9\x98k&\x03\x8e\xaeg\x01\xe9\n\x0c9\x0epkeM_\xd0\xcb\x0e\x1a\x87\xb9\x05\x84\xf5\xde\xed\x86,&\xb8R\xfe\x14\x0c\n\xb6d\x10\x9c\x19c3P$\xcaP%<>\xe2\xb0\xd7\xc4\x9b\xeb-Z\xea\xd2\xad\xdfn\x87MxcA\xfd\xcd\xfd\xcc\xf5\xbcV\x95\x84\x03\xb1n\xbb\x03^\xd9\xd92|\xcb\xc1\xa2\xb95up\xb1\xcasvf\xcd\xa3\xb4q\xe1Y:%\x12\x9c\xef\xbev\x04\xf5L\x0e\xc3\xa3tjx\x05\xe5\xfd\xeb\xb8a\xff\xf1a%\x1d\x1b\xb9\xee[\x86\x15\xea\xe1\x7fY\xc9\xd9\x95\xf6\x00+k\xe5\xeaY\xf9FV\x96\xb5&\x04\x93\x7f\x0c@\x8c\xd7y}\x1e\xb7*\x19\xd4d\x8a\x86\xc9"V}27\x06\x85\xf5Kr\x90\xc6\x87\x87z\xef\xa5P\x89\x9d\xd7nU\x03\xa9\xb5~\x16\x1f\xd3\xc9Y\xf6#\xaa0\xa8 \xf8\xc9\xce$4\n\xe4n\x97@\xba2\xca\xf2\x89\xa3\xf4\xa4S\xdaV\xe3\xea\xc7\x1e\xf9\xabF\xc4\xcb\x9b.\x0b)\xcd\xa1\xec\x91\x7f\xc5\xbe\xc3\x8al\xebxv\x05\x9b2[0\x82F\xa1\xa4\xc6\xa9\xb0\xba\x85q\xb0?&\xe9\x14\xc7\xdaK:\xbf\x91}\x96Iv\x89GmD6p\xf5\xebjt\xdb\xc7\xfeQ\xd8u&:(\x95\xa7\xc0\xd5[|r\xcd\x1bn\xb9n\xcd\xbe\xc7]\xd5\x18\x80\xaa:\x1c\xabb{\xe4R^~H\\#\xb3t\x16\xach\xbd\x1c%\xd8-\x16^\xcf\x10\xea\x10[\x1e\xd2\xcc\xf8/\x99-\xb2b\x93`\x99\xf0H\xad\xec\xfe\x8b\xf0\x9a\x92\x85\xe9.\x91\xff?,\tSd\xd0\x12EY\x85G\x1c\xc6%\x8a\x85_\xd0\x8e\x8f\x1b,A<.B\xdd\xcdi\xd8.\x0f\n,3\x1a\xae\x03):cx\xa5b\xef3\x8d\xe7iE\x8b\x0e\xf6\x9c\xcc#F;v<\xbf\xea\x07\xc9X\x83N\xf4u\xd4\x81v\xbf!\xec\xae\x15\x9a\xcd\xe0\xf1\x1f\xe2Q\xdb\xc6\xb5\r\xf8^\x18\x07a\x11\xb3\x8e\xf1\x0c\xba\x92\xbe/m\xa8&8\xc1\xe8\xc4V\xb88U\xc0W#\xb5\xb6\x13P\xf2\x1d[\x85\x9c\x85\xac[\xca\n\x9f\xd4x\xa4\xbe\xb1#C\xc7g\xc0v\xac\x18s\xd0\x9a#\x9e\x9c;\x05Y\xa3\xe9\xc6\xd6\xd89 \x1dG\xbc\xcbmj\xa6<\x81A\xc9\xf7F7\\\x11{\xe4r\x97U\x85\xfe^\xf7!\xe0a\xb1\xb5w*1\\\xd5$u\x93tPr\xa1\'\x16\xf7#\xd9\xe51K\xd0t\x87\xaa/,\x0b\xdb\xa6E\x14\xd7\xccOE\xa61\xb7\xd7z\x03*\xbed\xe9\xf1\x85\x06.\x98\x15`\xf31\xd9\xe7\xd9\xbf\xac\x07\xc1\x18\xc2\xdcf\xc74W\xf7\x0c%\xfd\x90\xed\xaa\xc2\x0e\x9e?\xfc+\xcd\xc7l\xbf\x9f\xc4\xab\x1a\xdd[\xd3R\x03$\xfesk\xc2x\x83D\xff\xa1\xbe\x85\x8ei\xa4\xad\x0f[m@\xff\x01\xb8\x08\xd3\xdf\xca\x12\xee\x89\xb6\xd4uh\xa7r\xb6\xb2T:?\xd6\x9c\xbc\xc8\xd9\xd87z\x07K\xe8\x1d\xab\xde\xdd"\xddK2\xc3$\xbd\x9c\x87U\xd1\x16\x91\x9e\xca\xe74\xc8E\xa5o\x91\xa4F\xbb\x1b\xee6n\x89(B\x14Y\xaf\xf5\x89\x8f\x0c\x81\xe5\xcdr\xaaP\xe77\xee\x13S\xea\n\xbe\xe7\x1b\x99\x9c9\xb5>Qz\xb3\x9d\x9e\\T\xc2Tg\x94\x15\xe8Az\x0b\xca\x02\xcc\xa3D\xbb\xcaC\xb1d\xe2\xe7)\xb6\x97\xfeJe\x94\x10\xf9\xe8O\x93\xc5\xcf\xe7\x82\x88{\xc5\xb1*@T\x17[\x0e\xe9\x1e|\xe3\x05\xa4\xa9\xf0\xd6\x06P|<\xff\xd4\x98h\xff\xce\xfa5B\x8a\xac\xfa\xaf\xcd/\x9d\xbe\xeb\xfb%\xa5\xb8\xa2V\xe9\xcb\x03\xb6\xa4\xf1\xac\x056\xfd\xf4\xb3\x81u\xf6DN\x88\xc4\xed\x8dT-\xa7\x1d\x88\xb8i\xb2\xfa\xc1\xa7\x9f\xcd\x8c\xe5\xc7G\xaa\x9bt7\xcd,\xc1\xd9\xa78{\x85\xb2\xd9\xa5qp\x07\xb7\xdf?\xd2\xcb\xbe\xd1OvN4\x0b\n\xfc\x07\xec\xb6\xa26\t\xe9\xa0\x18\x0f\xe3,<\xab\xedJ\x17\xb6\x1d\x0c\x7f\xf2\x03;c_\xf7\x18\xad\x19\x04\xb9\xc0D\xde\x10\xad\xd1\x17\xcd\xa3:\xed\xb0\xcd\xe6G\xbd\x88C\xb8\xb4\x12\x1e\xba\xfb\xd2\x11'
|
|
|
|
|
|
2024-12-14 17:54:56.753774 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 330
|
|
id = 1606
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 310
|
|
chksum = 0xc6cf
|
|
###[ Raw ]###
|
|
load = b'F\xf0\xe0\x0fd\x16\xe2\xe8/\xf0U\xf7\x91hmO\x80\xdf\xd7\xad\x0b*\xfe2j\x15\xd1\x91\xd3\x17H\xd8\xb8\x05R\x03\x9a)\xd0-\x87\xa6\x80\xe1Q\xa9\xec\xb7\xe5\x11\\>\x0bH\x9c\x96\xec\xc5\x93\xc5\xcfq\xda3\xbe\xf7\xa0\xc1S\xc0\xaa\xf2\x11XX\xd0\x1d\x8eo\x93/[\xc3\xc0\x1a\xe0ZV\x8a\x8fP\x81\xea\xd1\x19\x90\xec.{\x03u%\xec\x0c\xd3.\xff\xb8\x941i\xf8g:UI\xcbK%\xb8h"n#C\xb2\x0cu\xbc\xa6\x8b\xfc\x1b\x93\x9a\xcb\xab\xf5\x85\x94\xdd\x04l_}\x16<\x17\xe5/\x8cO\x86\xb7\x87\xcd\x9bZ\x91\xd5[\x17K\xde\xcf/5\xc0\xa7_\xdfT\xba\x9bt\xc1a5U\xd3\xa8\x8d\xab\xb2\xdd\xfc\xa9]4\\\xa5;v\\E\xa1\x07\xc7\xe7\xf0\x1cb\x0b\x88L\x9b\x0c\x1f\xb6\x8cg\x85\xed-\xe5M\xfe\x13N~\xd0\xa1\xae\xf9\xaa\xf7\xe7\x1f\xe5\xbd\x90! =\xe9\xa9\xb2Y(\x85\x95w?\xaa,\xf4\xe1\xef\x04MH\xce5\xb6\x1f^\xe2\xd1\x18^\xfa\x8f9\xfd\xe8b\xe5\xb5\xe7\x7f\xba\xa86\xafw\xe3#\x86\x7f\x91\x8c\x04\xcal\x00\x0c\xa1 \xc7$\x9a\x08\xe3}\xb4[\x90fx\xcf\x8e\x93'
|
|
|
|
|
|
2024-12-14 17:54:56.758991 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 55
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d2e
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 35
|
|
chksum = 0x4ef3
|
|
###[ Raw ]###
|
|
load = b'W\x9a\x0c=e\x16\xd9\xac\x05\x1a75CX\xe6\xe0\xe8\x9f\xba/30\xe1\x94E\xc4\x06'
|
|
|
|
|
|
2024-12-14 17:54:56.765232 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 51
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d32
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 31
|
|
chksum = 0x9e40
|
|
###[ Raw ]###
|
|
load = b'B\xa3\xa8\xb3\xa4\xa7\x8d\x101\xa90q\x9f?\xf9?V\x19\x1e\x85\xce\xeeb'
|
|
|
|
|
|
2024-12-14 17:54:56.778387 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 60
|
|
id = 1607
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 40
|
|
chksum = 0xc5c1
|
|
###[ Raw ]###
|
|
load = b'S\xf0\xe0\x0fd\x16\xe2\xe8/\xcd\x7f\xa5\xfd\x0e]\xee\xc4T\xddQ\x13Z\xed\xc6\xfb8V\x95$K\xe7['
|
|
|
|
|
|
2024-12-14 17:54:56.795250 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 386
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7ce3
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 366
|
|
chksum = 0xc047
|
|
###[ Raw ]###
|
|
load = b'Q\x9d\x96\xda\xd0\xea"j\xa91=f_\xd7q\xe4\xa5\x1c&\xfc\xa3ro\x91\xb7S\x91\x93\x19\x7fj\xf6/\xf1\x18\xf1\x82\xb1L\x10\x11\xb5\x81\xf7sb\x99\x88\x97\xab\xda\x80\xb97p\xa2\xf1\x86\x9c\xf9\xd8\x97\x81\xf4j\x14\x01\xf8dE\x10\xe4\xb2S\xf2\xa5\x19s\x06S\xc3\xd5\xbe\x93>t\xbe\xbc\xc7\x02\x1a\x85>\xc6EI)\xcbv\xb5\xa4\x0c\xd2c\xc4\xf0p\x8eu\xd5\xf3rr\xa0u\xf8\x0e\xb42n\xecK$SE\xcaS\xdbTC\x945xor3\xff\xb5\xcfI\x17\x16\xff\xcd\xb7\xae#a^y[\x05\x9e\xc8\xe7\x1e\xe3\x9d\x9a\xee\x81\xa2\xe5\xc0\xe6\xf1U\xcd\xb85\x9aP\xb5\xab\x0cQ\xdc4%\x8f\x99\xbb\xf8\x19\xb6C\xac>\xc7\xfe\xf8+w$\xc6m\xfc\x80\xfa-l\xe94\xdcmt-\x91\xec\xb1P\x97B1y\x93*\x9a:\x027Nm#\xd2`\x90~\xfc\xc7\x04\xf9>\x1c\xa3\xb5!\x02\x91\xf5<\xb4\xf0+\xe9\x96\x9d;\xefE\xf2M\xb52\x90\xb9\xff\xb7\x1cA\xf0&\xf9\xcd\xb2\xd7\x8d\xd2\xc3Z(\xab\xa69x\xe5s\x83\xc6\xf9\x1f\xad\xffl\xf8\x93\xb6\x9fe\x9f\x07\xec\x84/\xaf\xf41\x17\xccIu\x18.\t\xeco\xf7\x06\xbc>\xde-\n\xa9\x12\xf2z\xb5\xe9V\xc6\xce7E\xb3\x93\xa2!\xd1\xc0\xeel\xf6\xa8\xe2\x06\x88\xe7\xccP\xbf\t\xcb\xf7g\\m#\x84\x0c>\x87}\x9f\x82\xe9\xfcP'
|
|
|
|
|
|
2024-12-14 17:54:56.826927 - Ether / IP / UDP 192.168.1.11:56565 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 64
|
|
id = 1608
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56565
|
|
dport = https
|
|
len = 44
|
|
chksum = 0xc5c5
|
|
###[ Raw ]###
|
|
load = b'P\xf0\xe0\x0fd\x16\xe2\xe8/\x120,$\xcc\xac\xdc\x94\x90\xcf\xf7>\xe1FY\x85\xa9CB\xae\x89\x80\xd3\x97\x86\x1f\xdf'
|
|
|
|
|
|
2024-12-14 17:54:56.865794 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:56565 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7e31
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 56565
|
|
len = 32
|
|
chksum = 0x7a74
|
|
###[ Raw ]###
|
|
load = b'Mc\xcb\xb7\xcd\xde\xf8Ep0;~\x19\x1dv\rj4\xc6V?0W,'
|
|
|
|
|
|
2024-12-14 17:54:57.672752 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0x271
|
|
###[ Raw ]###
|
|
load = b'P\x85\xd0d\x89\xa1:\x02\x8bs)\xf9\xd1B\xa3\xdc8&\x8ez\xbc\xb0\x86\x16\xde'
|
|
|
|
|
|
2024-12-14 17:54:57.693136 - Ether / IP / TCP 192.168.1.11:40570 > 142.250.200.106:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 60587
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.200.106
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40570
|
|
dport = https
|
|
seq = 1307131834
|
|
ack = 3946161319
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0x1934
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 17:54:57.704024 - Ether / IP / TCP 142.250.200.106:https > 192.168.1.11:40570 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 14748
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xf20f
|
|
src = 142.250.200.106
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40570
|
|
seq = 3946161319
|
|
ack = 1307131835
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1044
|
|
chksum = 0x8391
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (1307131834, 1307131835))]
|
|
|
|
|
|
2024-12-14 17:54:59.159137 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 45711
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdb4c
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412657736
|
|
ack = 1692640822
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x83ea
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4J\xce\x17\xe8v\x9e\xcb\x15\xf4(b_o\x8b\x13\xf6i\xe6\x05z\x9e\x06\xcf\x19\x01w\xac*b>\xe5\x05\x88\xd5\x91n\xe2\xbb\xfe\x06Pi\xb9\xbc{\xe0\xbe\x93\xadG\x04\xaa3\x15\xf9\x98\xd1\xfdS5\xa7\xe7\xf4\nO\xe7\xc0\x10,8\x13\xde\xc1\x0c\x91\xf9\xcd3\x9f\ryFu\xb6\t:\x98\xd9\x16N\x9d\x03\xb3_.\xe3\xd4\x82\x80\xf4\x98m&\x07\xcc\xe8\xca\xb7Re\xaa\xba\xa2\xdb\x13\xa9\xc4\xfb\xe4\xd4*\x00\xedT\xea\xcb\xc4F%M\xdc\xdc\x15!v`\x8b\xd3\xdbI+\xbdX\x986\xff\xc3\x82\xbc\xf1\xfb\x0c\xce\x07\x1b\xf6\x9a\x8b(\xc8\xce\x11\xe942\xf2i\xe1\xd4Xn\xf20H\x9e!\x84\x05\xbc%H\x18C\x8dLc\xdc\x93\x8c(:\x8f\xe8K\x1625\xd8.\x86\x9c\x8ch\x99sH\x88#\xec\xab\xcc\x86'
|
|
|
|
|
|
2024-12-14 17:54:59.195346 - Ether / IP / TCP 18.154.48.18:https > 192.168.1.11:40668 R / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 246
|
|
proto = tcp
|
|
chksum = 0x8070
|
|
src = 18.154.48.18
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40668
|
|
seq = 3731708429
|
|
ack = 0
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = R
|
|
window = 0
|
|
chksum = 0xd26e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:54:59.209264 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16618
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692640822
|
|
ack = 3412657953
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2065
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:54:59.216511 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16619
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17610732
|
|
ack = 2030875595
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4135
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:55:00.901453 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0x2a52
|
|
###[ Raw ]###
|
|
load = b'^A\xec\x1e1\xf15N & y\xacg1?z\xd7\x1b\xa4Q\\\xee\xe3('
|
|
|
|
|
|
2024-12-14 17:55:01.080132 - Ether / IP / UDP / DNS Qry b'mobile.events.data.microsoft.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 78
|
|
id = 31681
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 61167
|
|
dport = domain
|
|
len = 58
|
|
chksum = 0x83a8
|
|
###[ DNS ]###
|
|
id = 31305
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'mobile.events.data.microsoft.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:55:01.083961 - Ether / IP / UDP / DNS Qry b'mobile.events.data.microsoft.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 78
|
|
id = 31682
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64376
|
|
dport = domain
|
|
len = 58
|
|
chksum = 0x83a8
|
|
###[ DNS ]###
|
|
id = 56870
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'mobile.events.data.microsoft.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:55:01.087518 - Ether / IP / TCP 192.168.1.11:40825 > 20.42.73.30:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 158
|
|
id = 58369
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.73.30
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40825
|
|
dport = https
|
|
seq = 2481014104
|
|
ack = 3769517311
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 514
|
|
chksum = 0x1f8c
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00qT]\xf0U\xa5\xcb\xa2\x06*w\xacS\xe5\xe4RE_Y\xaaE0\x9f\x7f\xa6;\xe0\xd4\xfb\x92\xa81\xf8\xc6@!\xeeh\xab\xc8`\xbb[\n\x17\r\xdc\xba|N\x15D\xc7\xe1\xb9\x12v]!\x99\x07\x95\xa7n`\n-#R\xf6\x8cn\xb72\xcb\xff\xed\xae\xc3P\xa0\xcd\xa9\x94\xd0yi^\x17\x96\xb5\xe4\xd9q\xf3p\x8c\x95\xc6H\x05\x12x\x96\x0f\xb0\xa6\xa3DK\xf08\xdb\x81'
|
|
|
|
|
|
2024-12-14 17:55:01.092892 - Ether / IP / TCP 192.168.1.11:40825 > 20.42.73.30:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 58370
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.73.30
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40825
|
|
dport = https
|
|
seq = 2481014222
|
|
ack = 3769517311
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 514
|
|
chksum = 0x1f3d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\xc7\xa2\x8aa\xd2\xcdt9\xc0#\xe6\x9e\xab\xee\x96\xc4{i\xc0\xa5R\x9c\x9e\xbd\x85<\x11\x1a\xe1\xed\x1d\x0c\xda\x92'
|
|
|
|
|
|
2024-12-14 17:55:01.099572 - Ether / IP / TCP 192.168.1.11:40825 > 20.42.73.30:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1480
|
|
id = 58371
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.73.30
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40825
|
|
dport = https
|
|
seq = 2481014261
|
|
ack = 3769517311
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 514
|
|
chksum = 0x24b6
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x08T\xfe*\x08\x9f6\x94\x13\xf7\xae\xcc\xba\xec\x12\xe5\t\xcc\x14}\x97\x94\xf0\xaam\xcd[\x0b\xb3,\xff\'\xb3buEi\xed_}a\xbc\xa9\x96\xb8Q\xc2\xf3yr\xd7\xe8{\x982\x86\xed\x0b\xdc\xfda(8\xe8S\x8f,\xd3^\xc3C31h\xc2N\xd1\xd7\xa6\xd0>\xda\x94<]@E\xa5\r]g\xf3\x00\xa4\xc0\x94\xa2\xe8\x99\xcc\xefP\xa0\xd2\xa4!\x9cZ\x0eJ\xee\xb6\x98/\x98\xe1\x15\xc1\xf5\xb0\xef]\x80D;\x8b\x93\xf3\x12\xbc\x9b\x01\x89\xf4\x11!Lp\x13\t\xc6MM\xff\x16x\xc8w5\xc2\xec\xa9\xb7Rf\xd2L\xff\xe4\x97\xb5D\t\'8\x98\xf0H\x88\x039\xf9F\xb6\xaby/8\x9aU\xa9B\xb0\xde\x9b\xa8}5=\x829b\xcf\xba\xb7,Z\xfbT\xa9Ob\xd1\xda\xa1b\x84\x1a\xfa\'\xb311\x16\x90\xb4b\xe6\xbb\x1e\x11\x19\x1b\x18\xf0\xa5?\x8bB\xe8\xfcf\xbb\x1e\x17~\x05\xeeq\xf8\xffw\x9a\xcf:\x15\xd9\xf43\x9b\xf6\xb93\xddq\x99\x86bx\xf1\x9dW\x88\xe8\xdc\x9a\xbf\x19\r`\xb8u\xab\xd6\x7f\xacC\xef\xdc\x18d\x1e\'\x90\xe2$/\x15Dl\xc2N\x83R\xf3\xd8\x14\x15>x|\x9a\xf3\xb1)\xd9\xb1\x19Pj.EsQ\x82\xb9K76\xb2w\x92g\x90\xeaJ\xc3\x1d!\xf4\xc9Ut\xa4\x94\x8a\xec[\x8ec\x8e[-@\x9b\x1aq\xd45#\xdf\x13\x12>J\x87|\x14r\x82\xa7Gj\xa9kg}QpW\xc1\xc3\x07\x97\x14\xff\xc7W\x10\'\x08$9n\xc0!\x1f\xecXM\x04|0\x11q]%*\xf9\x896\x8c\xdb\x05\xb4wE|\xd2\x9a\x83GCWr\x1c\xf7~\x9f\xee\xe8\x01J\\\x8a\x85\x8e=P\x8f$\x01"%\xbf*y4\xf1\x17\xb2\xb0+\x80\xad\x0e#\xb6\xa5\xad\x11c\xfaS\x02J\xfcz8\xe0Se\x103\xb8H%~c9\xa5\xde$\xf5w\xb7\x0bX\n\xd8\xb2\\\xa4\xe4\x07\xc9\x9e\xf7\xe1c\x9eC!\x07\x92Q\xbc\x9b\xef\x08+\xd7\x92+\x02{x\x9a`6\x1d\xc7Z\xd3^\xf7X\xf0\x92\xab8Ak\x04lM\x02\xbcr\xb9\xd0\xaeE\xf7#\xec\xcej\x98\x8a\'\x148\x9bD\xf9\xc9\xbff\xc9Ad\xe1gZ\x05G\xf1A}\xfe?\xba\x8a\xcb[0e\xae-t%o_C,\xa6\xe5\x97&s\r\xc2y\xfe{\xa2\xf5\xf6\x12rg\xae\xc3,a\x82\x9a\x8btE\x8cTt\x9b\xba\x0f\x89*\xc1\xef~\xce\xea\xa5J\xb7\x8dQ\xe7C\xbd\xcc\xff9D\xe7\x08\xf5\x96R\x95Q\x90\x08E$\x06S\xf54\x9e\xff\xcdF\x16>W\xb5A\x8d\xef?\x1am\x93n\x05\x05O\xdd\x8e\xd7\x159\xf4,W\x9a\xd3>1\xf1\x02\xf3\x9e>\xd6\xbd_\xae{\t\xa2\xba\x11F_%\xb7X\xa2`of\x04\x16jQ\xde\x15H\x00\xaa\xb5\xc4\xccv\xb6\xff\xbf\xf6Fo|\xd8\xabX\xab~\xd5a\xbeIdZ\xe7\x1c\xe1\xca\x8f\xe1\x11\xa6h\xf6\xc0Y\xab\x83\xfa\x02\x14\xf6\x0c\x03\x83\xa8\x9c\xab\xcb2\x98:\xe3\x1dF\x8f\x19\x14zb\xf6\x04"\xa8\xc9\x06\x85\xa2\x88?\x1b\xe4\xd9bo\xe6\x02\x94\x9fxy\xcd\xaf3\xb4\xab\'\xbf:\x0e*\x02\xad\xeeK\x17\xeb\x86h\x18\xa5\xe4{\x9a(\x11\x8cQ\xc3y\xed\x1cD"Q\x17\x85O\x9c\x80\x14J\xc5\x1cr\xf5\x8f:\x91\xb9\x81z`\xdek\x91\xdb\xedV/\x8b*\x1f\x08\xee\xb6\xa5v\xe1\xc5d&\xf2\xaa\xabU\x90\xdb\xfa\xd7\xe1M dt\xc6\xf7\xa5\xe1rJ\xdf8V\xba \'W\x15\xe5Pn\xcapPvXh)\x10\x83O\x13\xb1\xbf\xc5\x8d.\xad\xfehRpA\x13>O\xc1\xb7K\x95`\xfa\x0f,\x12!\x94\xb9[\xbbak\xb06\xff\x02\x8b\xb3\xa8j\xcfJ\xf5@\xb3\xb3\xb6\x81\xbdxW\xce\xdf|}\x06\xa9\xb4 \xc8\xe6r\x03\x1a\x7f\x03\xea\xac\xe60\x8140H+\xfc\x0fCP/9\x9c\xe1\xa0<\xee\xa3\xbc9\x15"\x81 {\x81\xa9\xd8\xb5L|\xd4^\r\xae\xdb\x04\xac\x9d\xfb\xa8\xb5\xb8\x97\x05\xad"\xbd\xc6\xc7\x0e\x00\x12+\xe6B\xf6\x99\xa9?p*\xcc\x88 \x82;~2\\\x9d\x04\xa2\x80SE\x94\x92\x98\xb8\xd4\xd2j\x90\x04\x19\xc3\xa4\xf7.\xcf1\x05\xa6\x7f\xa1.\xa2\xf9\xb50\xa6%-\x93\xed\xb1\xb7D\x7f\x95h\xe5\xc4\x1d\x88\x18$\x92e,\x1d\xc1A\x9dZJ\xe0,\x04\xb0P\xf3\xf6\xeb\xc2\x16\x94\xcf\xf0\xe6d\xa2\'\xc3\xc5x\xfeg*7\x80\xea\x0f!k\xe5E\xd10\xfd\xfa\xa66\xbdhb\xef\x83\x93%\xb4"14b\xf3\xab"D\x04\x1a\xba^\xe1\xeb\xa6Sx(aW\x15\xady:9II\x07(\x96[\xb6\xba\xd0\xef\x86 \x98\xbe\xb2\xc72\xa2\xd4l\xb9\x06Im\xbb\xaf$\xc8\x8c\xc0\xba\n\x9b\xb6G\xcc\xc7\xd067\x1b\xf7\xe4\x1dd7\xd8\x83\x15@\xb5\xf8m\xfdw\x00\x87\xea\xc7^`\xe1&\xa7[\xcckE\xdd\xfe\xed\x13~[N\x03F\x8cn\xfa\xd4\xa5\x8fm\x85\xc8\xb4\x98\x99\x82\x15\xc9\xd8\xb9g\xb8\x90G>w\xca\xd4ep\xd5\x8c\xd4\xde\x9c>&\n\xc2\x12\xff\xd8|6\xc6\xc5\x85\xf5p\xdf\x19\xf6oJ\xc3\'\xcfd8\x97+\xcc\xc0lD{\x9c\xb5f\xb0\x97\x8d\x0e\x01\x13\x05\x9a\x19\xf9\x08\x89~\xa3=Q\x1f+D\x17\xe4\x86:\x0c\xca\xfeV\xe0\xc2`p-:[Zu\xb5P\x14\xa1\x1b\xa6\xf9U\xfe\x89!\x01:\x82\x1b0\xc2\x97P\xac\x96\xd6\\+u\xd1n5\xdfE^\x04D\xdc\xa8H\x87\xf2\xf8p\xf0\xc0b\\\\mwNj\x07\x9cd\x00B\xe3ah\x83\xea\x94u\x99\xbb\xb4\x87\xce\xee^\x84\'\xf5\x95\x81y\x8e\x8b\xc4\x98\xdb\xa6\x87\xca\xaf\x82\x95\x83\x8a\xa0w\xb2E\xd5\x9d\xd6:\x8b\xcb3|'
|
|
|
|
|
|
2024-12-14 17:55:01.104187 - Ether / IP / TCP 192.168.1.11:40825 > 20.42.73.30:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 737
|
|
id = 58372
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.73.30
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40825
|
|
dport = https
|
|
seq = 2481015701
|
|
ack = 3769517311
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 514
|
|
chksum = 0x21cf
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'3\x01r\x07\x0e|\x0b\xa1{/\xc5\x82 \xd6\xa9(\xcb\xe0\xdc\x85\x11\xd8;\xec\x0cc9\xa7\x99\x94\xb7\xef\x03\x1a\x8e\xa6\xc8\xbdr\x84w\x07\x0f\xe7\x9b7%\xfb)G+\xc4K\x9a\x86\xd2\x1b\x96\t\x83C\xbc\x8e\x84\xbd\x17\xbb\xd5\x95H\'\xc7\x11HR\x7f\xfa\x102\x9f\xd9\x8f\xa1g`\x9b\xac\x06\x110\xd1\xb7\xfe\x94\x9f\xd05\xda\x81y\'\xae\x8d\x01e\xba+]\x13G\x91X\x0f}(;\xe3\xd5%{K\xbf\xffQ2\x84\xbd\x0bv\x91\xc0:\xdcb\x87e\x1a%Dy\xf4\xd9\xe2\xd2p\xf2\x7fD\x8c\x01[\xb6R\x85\xd7\x92\xe0[\x13Ph&u\t\r\xfe5\x10Q\xde\xaba\xddA\xd5\x1b\x1d\x92\\\x1e\xca\x87C\x03\x95\xc9:$:\xda\nr\x17:\xd0\xf0@i4q*\xfd55\xb7\x82d\xd1\x82\x7f\x9d\x1e\xeb?}>8#\xab\x89\x8e\xa4\x03\xd9\xa3\x94\xc2>\x7f\x93\'e\xa0\xf6\xf7\x92\x95\x19TN\\\xf2$]\xf5F?"\xff\xcavbI?\x0b\xf0q\xe7\xfa\xf7\xe6\x00\x83\xb8c\xf2\xc4\xec\x05\xdb\n\x15\x81!\xe4\xade\x9d\xeezB\xa7\xf8\xa4\xf4@\xddx\xc7u\x1c\xd8\xde\x8c\xef\x0f\xbc\x99\'G\xf3\x7f\x8e;l\xa7_U\xbb;\x9c\xe9s\xe8\xecJ\x7f\x10\x15\xd0WF\xe3\x0c\t\xec\xa6D\xc9I\x91\x8d\x95\x14Z\xc4\xf3f\xbei\xed\x1f\x0b\xb6\xa6,\x93qr\xa47\xe4\x06\xf2\xb3\xec\x1d\x92\xcbUe\x7f`W\x1e\xd7\xc0b\x8c\xb6H\xdc\xa1\x19o\x8b\x91$/x\xde\xf9\'\xaa\\\xfd\xdf\xe2N\x9aDC\x9d\xf1-G\xfc~\xcao\\\xb0Y\xa3QD\xa6\x82\x8c\xd7\xe7kd"\xf0mG.\xb4\xf23\xde2\xf5$//\xda\xea`\x9d\x91-\xd7\xc2\xf5\xd8T\xd4\xb7\x9b\xcb\x06\x86\xbdcY\x94\x0e\xe2\r\xeaq\xcd\x83\x82\x02\xcc5\xd3\xc1@\xdar\x80\x85\xf1\xf7\xc9\x93\x90=\x0cM\xe4 oo\xc7Sh\xa5\xaaq\x14\xe0\x13Xyw\x01\xc2\x11\x0c\x08\xcc\xba\\k\xd0\xdc\xa8\xe5o|\x90\x86\xfb/\x8e\xfaz\t\xc1\xda\xfbq\xb51\x9d\xc8\xba\xac}\x1c{\x999m\xd0\r!\x8evL>O\xd07\x83\xd1{\xbd\x8c\xba\xc8\xf2)\xd5\x0b\xee\xe5E&\'\xaf\x9a\xedB7\x8dP\xcf"\xd6\xa2\r\x17\x1e\xd4\xc8\x96\xe4\xc5b\xdf\xac\xf9\xacU\xcbn\xf3C~Z+\x18\xd5\x96\x89\x82y\x81\x07\x04\x0e\xae9\xc4~\xbb\xbcs\xd80m$-\x84L\x03\xd9\xb5S\x8e\x9e\x0f\x95\xf80+\x98\xb3\x0e;^\xf1\x94\xb0F\x1d\xe6R\xff\x1ac\x90+Y(\xb2\x95zY\xae\\\x06\xc6T4/!\x07\xd3\xeb\xb5\xa0\x80k/\xe7TL7\x8d\xe6\xb5\xc05\x83{z1\x8f*\x17\xa1"kR,\x84UA>\x00\xc1\x8fc\xf6G\xf5\x92\xaf~`'
|
|
|
|
|
|
2024-12-14 17:55:01.109716 - Ether / IP / UDP / DNS Ans b'mobile.events.data.trafficmanager.net.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 198
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb6ca
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 61167
|
|
len = 178
|
|
chksum = 0x4bac
|
|
###[ DNS ]###
|
|
id = 31305
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 3
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'mobile.events.data.microsoft.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'mobile.events.data.microsoft.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 27
|
|
| rdlen = None
|
|
| rdata = b'mobile.events.data.trafficmanager.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'mobile.events.data.trafficmanager.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 21
|
|
| rdlen = None
|
|
| rdata = b'onedscolprdeus16.eastus.cloudapp.azure.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'onedscolprdeus16.eastus.cloudapp.azure.com.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 7
|
|
| rdlen = None
|
|
| rdata = 52.168.117.171
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:55:01.115271 - Ether / IP / UDP / DNS Ans b'mobile.events.data.trafficmanager.net.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 247
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb699
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 64376
|
|
len = 227
|
|
chksum = 0x9804
|
|
###[ DNS ]###
|
|
id = 56870
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 2
|
|
nscount = 1
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'mobile.events.data.microsoft.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'mobile.events.data.microsoft.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 15
|
|
| rdlen = None
|
|
| rdata = b'mobile.events.data.trafficmanager.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'mobile.events.data.trafficmanager.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9
|
|
| rdlen = None
|
|
| rdata = b'onedscolprdweu03.westeurope.cloudapp.azure.com.'
|
|
\ns \
|
|
|###[ DNS SOA Resource Record ]###
|
|
| rrname = b'westeurope.cloudapp.azure.com.'
|
|
| type = SOA
|
|
| rclass = IN
|
|
| ttl = 23
|
|
| rdlen = None
|
|
| mname = b'ns1-201.azure-dns.com.'
|
|
| rname = b'msnhst.microsoft.com.'
|
|
| serial = 10001
|
|
| refresh = 900
|
|
| retry = 300
|
|
| expire = 604800
|
|
| minimum = 60
|
|
\ar \
|
|
|
|
|
|
2024-12-14 17:55:01.180296 - Ether / IP / TCP 20.42.73.30:https > 192.168.1.11:40825 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 7392
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xd2f4
|
|
src = 20.42.73.30
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40825
|
|
seq = 3769517311
|
|
ack = 2481014261
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 16384
|
|
chksum = 0xb01f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:55:01.185951 - Ether / IP / TCP 20.42.73.30:https > 192.168.1.11:40825 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 7393
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xd2cc
|
|
src = 20.42.73.30
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40825
|
|
seq = 3769517311
|
|
ack = 2481014261
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 16384
|
|
chksum = 0x96ce
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"b&6\xd2|%V\xc6\x18P\x03g:3\xbe\xa6\xba\x96\x16\x95T\x82\x11S\xa2\xac\xb2a\xb9\xf8\xf4\xdac\x84'
|
|
|
|
|
|
2024-12-14 17:55:01.191120 - Ether / IP / TCP 20.42.73.30:https > 192.168.1.11:40825 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 7394
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xd2f2
|
|
src = 20.42.73.30
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40825
|
|
seq = 3769517350
|
|
ack = 2481016398
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 16385
|
|
chksum = 0xa79e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:55:01.233687 - Ether / IP / TCP 192.168.1.11:40825 > 20.42.73.30:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 58373
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.73.30
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40825
|
|
dport = https
|
|
seq = 2481016398
|
|
ack = 3769517350
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 514
|
|
chksum = 0x1f16
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 17:55:01.350141 - Ether / IP / TCP 20.42.73.30:https > 192.168.1.11:40825 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 139
|
|
id = 7395
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xd28e
|
|
src = 20.42.73.30
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40825
|
|
seq = 3769517350
|
|
ack = 2481016398
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 16385
|
|
chksum = 0x61b6
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00^\x99\xd7\x1aZ\xd4\xe3\x1c\xe7\xc8\xe0\x19\x8a\x07\xb4\xff\x08\xd9XL\xb1J\xfe\x13b=Y\xad=\xaa\xdd\xea\x96\x1f\xa2\xf5\xb6\xb3\xf4\xb3\xcfYO\xaa!J\xae\xd6\x0esh\xac\x83...vTD7\xaf\x03:\xc1\x98\xdcA*\xe6>\xf2b\x18&\xa3\xdb\xe5\xe8]-F\xa0C\tc\xbc\xb3\xcbd\x08\x8f\xf8\xa4\x84='
|
|
|
|
|
|
2024-12-14 17:55:01.356071 - Ether / IP / TCP 192.168.1.11:40825 > 20.42.73.30:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 58374
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.73.30
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40825
|
|
dport = https
|
|
seq = 2481016398
|
|
ack = 3769517449
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 513
|
|
chksum = 0x1f39
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xba\xb0W\xe0\xef\xe8\xc4\xe2\xc8\x13\x0e\xe4\xe9=\x0f\xccI\xa5*\x02y\x88\xf4c\xb9\xd59\xf5\xf6\xc7'
|
|
|
|
|
|
2024-12-14 17:55:01.555404 - Ether / IP / TCP 20.42.73.30:https > 192.168.1.11:40825 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 7396
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xd2f0
|
|
src = 20.42.73.30
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40825
|
|
seq = 3769517449
|
|
ack = 2481016433
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 16384
|
|
chksum = 0xa719
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 17:55:02.174588 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 97
|
|
id = 445
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x559d
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414049542
|
|
ack = 3211592099
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xe125
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x004\xd6\xb8\xd0\x1b\xa4\x0ft\x08x\x92\x8e\xdcY\x19k.\x8c\xee"\\\xaff\xed\xb8\xdc\x93\x11\xb4c\x90\xc3:\xefM\x19M\xf6\x1ey)\xb7\xf4\xd3b\xa3\x93\x16\xd6\xbe\xa54\xcc'
|
|
|
|
|
|
2024-12-14 17:55:02.225028 - Ether / IP / TCP 192.168.1.11:39688 > 162.159.136.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3086
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.136.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39688
|
|
dport = https
|
|
seq = 3211592099
|
|
ack = 414049599
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0xed57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:08:38.123796 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 325
|
|
id = 44094
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x9318
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359255185
|
|
ack = 158953102
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4403
|
|
chksum = 0xdc20
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\x18`\x1eB\xa6G\xe3\xa2\x14\x826Bs:\x1f\x846\xcd(ho\xde\xd7 r\xf0\xb3\xb8\x13\x8eo\xf1%\x15dr\x14\xa9)d\x9434\xf0\xe2\xd5+\xbc\xd3\xb0D}&?%\xa8FY\xff\xf2Bq\x07e\xefVT\x94\xa5o\x97\x87E"\x81\x9e\x1a}sq\xf7\t\x85\xc6F\xcb\x8e@\x9aez\xe3\x8c\x19}c\xf3\'\x8e\xee\xe1\xe4&\xab\xb3\xc3\xb3\xb7\xac:\x90\xe8\x7f\xadO\xf4\xf2\x8a\xa1nO\x9eO\xcd\x1bt\r\xc3\xa1\x9d\x8d\xdd\x0f\x89\x9b3c\xc53oY4\xe7\x93\x16\x196\x98\xec\x0f\xb8W\x15\x91p1\xd8\x08\x1a\xbca\x10N&\xf8s\x13\xb0,\x11\x14C6\x85\x01\xe6\x83\x86\x06\x973T\r\xd7\x81\xbb\xbaI%\x91\x8d\xe1\x15\x16V\x92|\xa3xl\x05m\xa4\xa1\xba\xe7] \xe1p\x93\xa7\xac\x92hQ;\xc2SX]\xd8\xaf\x88L6\xa9T\xfe*%B\x88U\x0e\xaf\x18N\xdc\x88\xb7\xf1\xd1\xcau\xdc\xb7\x10\xffV\xbfP:\xb0\x9d^\x96\xea\xa1\xc7\xa9[\x01C\x0c\x06\n\x08\xe9\xc5\xf6\x93mP\xe1y\x97s\x1b1T'
|
|
|
|
|
|
2024-12-14 18:08:38.452197 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 62247
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158953102
|
|
ack = 3359255470
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4102
|
|
chksum = 0x39a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xf67\xf6\xd5m\xb1\x91f\xfd6\xa3\xdc|\xd3|~\x89\xee\x8f"\xf1\x89)\xb9!,e2C\xae'
|
|
|
|
|
|
2024-12-14 18:08:38.454789 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 44095
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x9434
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359255470
|
|
ack = 158953137
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4403
|
|
chksum = 0x8f04
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 18:08:38.517458 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 85
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3ae0
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 65
|
|
chksum = 0x378
|
|
###[ Raw ]###
|
|
load = b'G\xfc\xeaL\x9b\xb9\xf9\xf5\xe1\x01}x:\xa2\xaf\xcd~\x10C\x04\x8c\x1c\xddIz\xda])3\xbb%\x08\x18@T\xb7-\x18\x1d!F1\xeaH\r\x90\x94)@Zd\x93g\x12\xdc\xb1\x17'
|
|
|
|
|
|
2024-12-14 18:08:38.527815 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 213
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3a60
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 193
|
|
chksum = 0x6825
|
|
###[ Raw ]###
|
|
load = b'Q\xa6\xd2@\xc8\x1a\xea\xf0>\xb5\x9d\x9bX\xbe]z,:Hc\x05IJ\x99*\x9c\xdc\xf3r\x11\x892\xad\x88@:\xeb\xde\x9a\x18\xce\xa7S\xa4\xe86\xf6\xd6\xb3\xef\x9b\x99H\xb7\xa8>\xa6Q\xbaW\xda|\x8b"\x83\x05\xfd\x8f\x03]\x15F_\xd9\x8a\xec\xd4\x13%Y\n\xbb\xe4\xbd{g\x95V\x88\xf4\x8a\xc5\xbbs\x143\t\\\x94\xe7\xcb~\x8cO\xd2A\x84F%\xdbp5\xe5\xae\xb7j8\x85\xbc\xbc\x93\x06\xc2u)B\xca\xaa\xccq\x8b\x19\xee\x871\x00\xb6\xd2CK\xc89E"J\x94\xee/\x8e\xe1\xd3\x8frw\xf11F%.\x02h\xd3\xa4$,;\x04\xcc\x12\xd1P~\xc8\x89\x04\xc47\x8d\xaf\xc2.\x08^\xe5\xef'
|
|
|
|
|
|
2024-12-14 18:08:38.996510 - Ether / IP / TCP 192.168.1.11:37662 > 74.125.133.188:5228 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 38432
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 74.125.133.188
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 37662
|
|
dport = 5228
|
|
seq = 938547355
|
|
ack = 2945028465
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0x9208
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:08:39.038540 - Ether / IP / TCP 74.125.133.188:5228 > 192.168.1.11:37662 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 58143
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xceb7
|
|
src = 74.125.133.188
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 5228
|
|
dport = 37662
|
|
seq = 2945028465
|
|
ack = 938547356
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1046
|
|
chksum = 0x98e
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (938547355, 938547356))]
|
|
|
|
|
|
2024-12-14 18:08:41.249132 - Ether / IP / TCP 192.168.1.11:39454 > 52.84.66.19:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 16988
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39454
|
|
dport = https
|
|
seq = 20247659
|
|
ack = 1095416837
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x3836
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:08:41.264524 - Ether / IP / TCP 192.168.1.11:39492 > 52.84.66.19:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 16989
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39492
|
|
dport = https
|
|
seq = 394882991
|
|
ack = 3877225030
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 516
|
|
chksum = 0x3836
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:08:41.270029 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39454 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 49896
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcbc0
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39454
|
|
seq = 1095416837
|
|
ack = 20247660
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 149
|
|
chksum = 0xc702
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (20247659, 20247660))]
|
|
|
|
|
|
2024-12-14 18:08:41.278765 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39492 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 7664
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0x70b9
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39492
|
|
seq = 3877225030
|
|
ack = 394882992
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 149
|
|
chksum = 0x6602
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (394882991, 394882992))]
|
|
|
|
|
|
2024-12-14 18:08:41.717337 - Ether / IP / UDP / DNS Qry b'safebrowsing.googleapis.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 73
|
|
id = 31902
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53934
|
|
dport = domain
|
|
len = 53
|
|
chksum = 0x83a3
|
|
###[ DNS ]###
|
|
id = 40109
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'safebrowsing.googleapis.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:08:41.723263 - Ether / IP / UDP / DNS Qry b'safebrowsing.googleapis.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 73
|
|
id = 31903
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60719
|
|
dport = domain
|
|
len = 53
|
|
chksum = 0x83a3
|
|
###[ DNS ]###
|
|
id = 19311
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'safebrowsing.googleapis.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:08:41.730561 - Ether / IP / UDP / DNS Ans 142.250.200.138
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 89
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb737
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53934
|
|
len = 69
|
|
chksum = 0xd153
|
|
###[ DNS ]###
|
|
id = 40109
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'safebrowsing.googleapis.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'safebrowsing.googleapis.com.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 17
|
|
| rdlen = None
|
|
| rdata = 142.250.200.138
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:08:41.739754 - Ether / IP / UDP / DNS Ans
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 130
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb70e
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 60719
|
|
len = 110
|
|
chksum = 0x8bca
|
|
###[ DNS ]###
|
|
id = 19311
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 1
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'safebrowsing.googleapis.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
|###[ DNS SOA Resource Record ]###
|
|
| rrname = b'googleapis.com.'
|
|
| type = SOA
|
|
| rclass = IN
|
|
| ttl = 32
|
|
| rdlen = None
|
|
| mname = b'ns1.google.com.'
|
|
| rname = b'dns-admin.google.com.'
|
|
| serial = 705849533
|
|
| refresh = 900
|
|
| retry = 900
|
|
| expire = 1800
|
|
| minimum = 60
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:08:41.744832 - Ether / IP / UDP 192.168.1.11:55981 > 142.250.200.138:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 11671
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.200.138
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55981
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0x1e34
|
|
###[ Raw ]###
|
|
load = b'\xc5\x00\x00\x00\x01\x08U\xa2t1\x1c\xc0\xd64\x00\x00D\xd0\xa4Q@\x86\xac#\x11I\xa2\x80\x06\x88#\xacRB\xed{2\xe3SV\x85\x89\xf4\xed\x00S%\x98+ \x04;}\xc3\x92\xe9\xb2\xe5I\xa7\x93Q\xb2\xdaU\xe5\x12\xc2_\xb0dGP\x08\x06=#&\xceJ\xaeAA\xcd\xc6\xf4o\x85\xd7c\x14\x83\x0cX\xb4\x9a\xa3\xd91\x97\xbe\xd0\xe3\x19\xde\x0e\xd6\xb8S\xf6\xba_\xff\x88\x99\xe0\x15\xf4iOd9l,|J\xecc\x17\xc5zr8\xb1/\x9d\xe5@\xe3\xe9>\x8aH\x1ai,\x1c\xe0\xae=\xe3\xedU\x01\x9a\xd6\x0f\xfd\x83\xb3\xc4\x7f\xb1\xdea\x1b\xdfD]\x95\x92\xbb\x8fs\xd9l\x9bt\x9ak\xc4!\xe0\xc6\xdc`\xc4!\x9b?|\xd2M\x14\x04\xe5o\x95L\x0f:\x0b\x92\xec\x9fT.>\xe8M\x19\xc2!$\x83]\xb9\xc2\xdd\x1e\xc4\xfdQ\xb3\x07\xfeC0\xdd\x10"\x15-\xb7\xa3\xe8\xb7\xd9\xc0\n\xa2\xd8U\x8e\xcfI8\xc4Zx\xedc\xd7Hw\x1b\xbb]i\xf9\xa2\x90\xf7{\xaa~X\xc4\xb9D\xeaD^\x8a\x96t\xde\xad8\xa6\xa3\xa0\xf1p\xff\xcduB\xa8\x17\xdd\x01\xf3|\xa6*\x8a\xcdR\xfe\xaa\xbfz\xb1\xad%lH!3\xe47\x93\xae\x8cx\xf8\x05\xfd\x05\x18\x02\x97Hf\x87\\\x16\x9f\x97\x8c\x893\xe1f\x89FF(\xe1\xf9\xd4F~1L\xc5\xeb\xb8d\x86\xa0\x17\xdf@d\xe8V"\xf4Y\xde\x81\xf1\xe7D\x07bA\xa13\x08\xcc!A_\x13\xac9\x9f\x99\xa1\\\xf8\x89\x94\xd8AdB~q\xcb9+\xd5Z\x82\x82\x87\xba\xe2\x08\x1cY\x00\x9fX\r\xd8\xb1\x8e\xf3\x1e\xd91\xdd\x97h\x18\xd0\x8b\x817\x1ek\xbe\xef\x1f\x08O\\\'\x8aJY\xeeo.\x9dkOu\x02\xa9\xb4\x92\x0e\xbbj\xb2pP\xb51\x93\xf7\x1e&\xa5\xb7V\xc3"\xd5\x8a\xac\x8f\xe4\xa4x`j5\xa4\xbb\xbd\x7f\x1cb\xbf\t\xa9\x0b\tA\x14\xaa\xa0\x15\x1e\x0fa\xf9\xcc\xdbp)}v\xe0\xcfX\xac\x99\x07\x88\xd0\xac"Rt\xcc\xfa\xaa\xdf\xc5\xc3|\xdf\x8c\xaeS\x85w=\xaf\xfbTe\x81\xda\x9a9\xe0S\xe7\xc9\x15]\x93\x1a6hG\x16i\xea\xef\xa9\xe4\x05\xf6\xb3U\xbb7PG\x15\x8e\x81\x94\xb2\xedbv\x81\xd5<m\x11\xde\xff1\xe1(j.\xa2[\xf7&(\x98`h\r\xcaT\x05\x85\x13m\xbc\xb8(\x93\xdf:bx>\x97j\xb8\x10\xc1\x1f\x12Iv\x07\x85S\r~\xd2\x11\xdf\xd7@\xa8\xd0."\xe6oE\r"Dr\x8e\x94$tS%]\xa0\xe2\xa4\xa6a\no\xca\xee%st1\x1a\x1b\x06:}:5\xda\xb4h\x87\x1f\x8c\xc8\xc9&\xdb>\xb3\x1f\xb5Q\xed\x17\xc0\xb53\xe2\x87\tYCj\xf9\x03\x96\xb9!R7]K\xe8\xbat<\x13\xbc\xa4\xe4Q\xd4\xd1\xdd\x14\xd6\xd8m\xe2"\xb2\x99\xa0\xb9\xe9\x0f-~\xfa\x13\xc4\x04\xfc\x87G\xfa\xe5K\xda\x08\t\xa8"\x11\xbfl\xa2x\x18r\xdd\x93\xe4\x9f\xa6\xdb\x83C\xce\xbd\x03\x95\x90\x10\xd14\x14\xd8{r\x9c\xe2\x0f\x1a\xaey\x99\xb0\xb9\x9d)\x8aN\xf8\xc8#eI\x02\xe8\x01s\xba\xb0\xd5\x90\xe2\x1a\xf1\x82\x00M\xbc\x16\xaf\x8d\xb4X\x1b\xfft\xa2\x02\x15c>\xe0\xcd+nR\x82ek\x07t\r\xf7\xe1Q.\xe6\x8f\x93CN\x8a,\xbe\xb1Se\x90\xb3S\xffxSMT\xe3\xbdO\x9e\xc3\xfa\x98\xdc\'\xea\x7fon/\xc2\x11\xb9*\xba\xfa\x97u\x97\xd9T\x0b\xe2\xda\x97v\x0e\x06\xa0\xa5\xb4gl\x01\xfd\xff\xfdp\xe5\xf8(\xe7\xd8I\xb5\xff\x02\x12\x9b\r\xe3~)|8]QI\\\x83\\\xaa\x05P\x8b\xde\xed\xa77P4\xa0\x9cI\xdd34\x8b8g\xdc\xa7a;\t\x03se*+\xe7\xa4\xd9\xf8.^\xf6\xc5\xb2\x8e\xc1\xb5\x07\xd1\x9e\x86\xbd\x14@\x9f\xb8\xaft@\xd5\xd5\xad\xebOB\xbfe\x06\x87\x93B7\x0e<\xe35\x9c;\xb2m\xc6\x16\xc3n\xfa\x03\x17\xf9\xdd\x8f\xeeE\x08\xd3o\x19\xbe\x1d\xe0\x9c\x1a\x85\xa8\x1dmc\xd4\xcb\x87\xecQm\x0e\x1e;\x8c\xe7\x00\xe5\x04"=ZL%\xc4U_\x85\x0bz\xe9\x8e\x89\x85\xd8as\x95\xde\xa67n\x89\x0c#\x0e\'\x93\xc6\xb2l\r\xe9\xdf\x9bU\\f\\-\x98\x06\x99\x1fM\xfe\x00Px<\xf4\x8f\xbc\xe8\xd3\xea\xba2\xd2\x02\xff0\xda\xf8s\xe9V\xce8\x01P\xfe\xd0\x01N8\xaa\x13\xd8\xb5V\xaas(\xbe\x139I2\xd5\x1f\xfd\xd5\xbe\xde\x82\x87?\x0b\x8c\x1c]=\xfb\x9d\tL\xa5\xecn\x87\x84\xca\x9aG\xe6YXSc)\xad\xdbC\x9cE\xef\x0e\x9a\x14\x93F\x10\x10\x0e\xb8\xe5\xc3\xb1\x1f\x1e\xcd\xc4\x12\xfb\x9f\xd7\xf7Z\xf9\x97\xbe;M\x15\xe1\xb6\xd6@\x17\x0f\t\xcf\xa2\x0f\xd9\xb4\x13]\x8fV\xa0&\x14\x86\x1b\x82y\xca\x1d+\xcb\x83y\x84\x95\xfb7\xea^\xed\x06y<\xa02\xf8\x94\xa4\xde\xff\xae\x1c\xf4I%\xfdhL\x95s\xdf\x96\xbc\xabz\xc5\x1e-s\x00[\x8f\xben\x8fH'
|
|
|
|
|
|
2024-12-14 18:08:41.893403 - Ether / IP / UDP 192.168.1.11:55981 > 142.250.200.138:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 11672
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.200.138
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55981
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0x1e34
|
|
###[ Raw ]###
|
|
load = b'\xc9\x00\x00\x00\x01\x08U\xa2t1\x1c\xc0\xd64\x00\x00D\xd0\xf2\xc4V\\>\x81\x8e\x9c&3\xa0Z\xa9_x\x83c\xa3?\xe2\xd5_\x05\xb3\t\xe5\x9a\x023\x07+]\x9fz\x86\x17\xad\xa5\x8b"Z\x0b\xfe:/Y\x12\xb2|A\x89\xebW\x980\xf6{]\xca\xdd\x16q\n\x91\xd5i1\xdb7y\x0b)\xf7\xb38\x81\xfcGk\xf1\r\x9b\xde\x15\xf7\xb4\r6\x9d\x04\xecI\xff\x972 \xc2\xf4\xfa7\x83u\xfc\xb4C\xdcu\xf7\x8dN\x0c\xd9f\xd8\xae\x05\xc6\xe4\x12H\xa5[z\xb5c\xb5\x82\xfcW\xdf\xceS\xbb\n\\\xae\xe1\x16F\xb1/p\xc9T#\xb0N\xae\xb6\x9c\x7f\xbcm%\xa1::[\x99\x96#\x92\xddM\x91-]d,W\x80\x88\xa0\x19\xcfr<a\x08\xd0#\xa3\x12+\xc9\x049A\x89\xfc\x85\xe9\x19\x01\xa5\xf4\x83\xb0v\xcb\xbb\xed~e\xa7\xb3\xf3\xe0\x16\x96\x93\xe7x\x90h\xf7W\x11P\x02\xa3~88^\x1d\xafI\x88$\xc2\xa6P\\\'\xf9\x8d=\xa1u]f*\x91\x1e\xf4(_\xc9\x8e$\x9b\x19\xa9\x91\xfaB@c\xc6\x15 \x89R\xe7\x0b\xef\x8d\'\xd8\xba\xaa\xa0\x10(0Gk\x99$\t\xe4\xa0\xaa\xc0\x17\x12\xc1)K?_\xe24\xb9\x07GN\x04I\x08\x05r\xc1Vo\xdb\xb8;s\xe8\xd2\x9b\xc3\xa8\xd4>\xe3\xa4\xa7w\xc9A\xd5a\xe4\xd3\x87S\xdegO\xf6\xc1\x1f!\xcf\x0f7\x03\xb2\xe26\xe8ID\xc2\xb8\xb8\xcf@\xf8\xceviW\xfeki\xfa\xb5\x9d\xca\xa4\x8a)\xc3\xe1>\x17\x87\xc7h_Z\xd94\xf9\x05+\xb0 BH\xda\xd3\xa3\xb6\x93D\xa1\xcbZO\x8d\xda;\xc2\xfdqj\xd79\xe5\t\x0f\xeac T\x10{\xe1\xbf\xbc.m\xe25\xe6\x97\xdb\xe2\xea\xc75\xe1\x877\xea\xdb|\xb1`\xfa\xa35\x98\x92q\xa0D\x11\xd4\xd5kK\xa0\xda\xdbq\xfd\xb0\xf6\xa9\x7f2J<F\xf1\x923*\x7f\xb9\xbeY9\x9e?\xd0?\xb7)Y\xf1\xd4\x91Y\xce\x7f\xad#\xf7\x88\xeb\xb0\xb2\x8a\x06vU\xc4\xe4C\x8f\\\xa9\x0f(\xf7\xed\x1a\x857\xff\x1e8\x9ah\xa7\xab\x19\x0f\xcb1\x11\xa7\xcd\x1e\xfd\xad2\xfe\xe3\xffZ\xf4\xfc..j\xe7D@\x86\x08\xe4\xd3K8~\x96\xe3\xd6D\xd3i\x8f\x0c)\xd8\x95\x16!\xae\xbfMSU\x96\xdb\xd7\xc1s\xfbG\xd4G\xb8H#Q\xb9\xaa\x14?\xde<\xaa\xb2\x08e\xf4@\x14\xb7\xadZ\x9cb\x8a_\x9d\x0e\x1c\xaa\xcd<+\x08\xd8\x8dR\x94\x070\x01+dH\xabi\xbd|\xa3\xe6\xba"\xa7L\xcf\x86-\x19\x0b\xe7\x8c\xb5b\xca\xd8q=zMW\x82\xaf\xf8pL\xd2y\x8ex\x1f\x94\xd9}\xab\xf1\x97\x18\x07\xc0\x13\xb3\x9b`(\x1b\x19\x15s\xa7\x8c\x0f\x14o\xe17\xcc\xdf\x83\x079,\x9d\x93&S\xefn\x8f\xcc\xb5\xc2\t\xe9\x1cC\x1cN\x16\x05\xf0w\x89Ft\xd6\x90\x8a\xf8^\xf0\x05\xf8\xa7\x86rmFj\xb0\xa7\x92<i\x0b\xc9\xb4l\xfbG\xdf\xcf\xeb\xb9g\x1e\xff\xe2\x7f\xc0]-@\xd9\xf8T\xf0Z\x0f\x06p\xca\xdaxy>p\x95\xde\t7\x84OV\'\xb3\x8e\xd3\x80\xea\xcd\xb8\xc3*\xdegU\xb6\x97CGC+\xa5\x00\xf5\x98\xf8%\x90,\xc1\xd2\x1e\xf7\x85\x7fB\x1a\\\\M\xf8\x12E\xe0\xe9p/\x1f\xc72\xe3Yp\xa6N\x1a\xa4\xff\xc8\xa6e{n\x0bE\x19\r?\x92W{|",\xd5\xa0\xe72\xd2[\x0f\xd0\xac\x87\x88\xec\x8f\xefYf\xcf|\xbb\x1fn\xe7\x14\x96\xb4\x8a\xba\xe7\xb8:`\xf2S;7dq\x05\x03\xe5\xf6\x1d\xff\xb1\x88\x91\x13\x85\x01\xeb4\x05\xd2P\xf5\x83\x11F\xc3Jn5\xef\xed.x)\x11\xa2\xa5\xa1\xd85P\x05\x9d5\xc3\xec\xb3\x97Z\x84\xd3\xfb\xc7\xc1\xd76r\xc1?\xec\x95\x01`\xb6\x15 :\xf8:9\xdcm\xabaY\x97$\xed9\x0cP \x9f\x94h5\xa07\xba\xff$\xd9z\xcb\xaf\xf3\xd2"R\xd2\xe1\xdb\xcd\xd0\x87\x0b8\xe9\xdcs\x16\xb7\xde\xbf>:+\x93K\xdf\xf5&\xeb\x9c\x81UC\xf0\x8a\xceY\x17\x95\xbe\xf1^.7t\x056\xd4\xb5\xef\xea\xa5\xc0\xbe\x91\x7f\xf6\xd6\xbc\xe5\xb8"\x17t\xe6\xa0\x0cW\xdb\x80\xa8\xc6 \x97J\xfc\xf9\xea`R\xf8\xc3\xce\xb7w\xda\xe8\xc2\\*\r\x1c\x8f\xe0\xff\xe0\xaf\x04_\xc7\xe3U\xe9\xf1\xeb\x84\xa1_@5\xf0\xe7\x01\xdcn\x01\xb7\n\x1c\xa1(\xd4\x80\xe7sX\xb8\x83@<\x17S\xbc\x86\x83\xf0\xa7xi)\xa8N\x02\xbb\xe8\x94\xed\xdf0-\x93\xb6\xfc0}\x9c\x01I\x0cw9BE\xc4\xe8\xd4\x16\xe2]\xd4"\x08d\xc7\xd0\xc0$\xc1G\x7f\x95\x97f\xf5>\x84D\xdeX5\x14\xe8\xb9|\x81A\xf9\xed\xcdf\xe9\x8bX\xb2]\xcb\xe7\x89\x91\x98\xfbo\xbaJ\xa0\xd4q\n}x\x9a\xe8\xa7\xb5\xec\xde(z\x02~A\x12\xda\x8fE\xd3\xa3\x8f\x80\xd6B\x8eyP\x94\x96\xb3\x05aQh\xc0jS\xe0\x05\xeb\x1d$\x1f\x0c\xc8V\x82\xab_\x7fB\xb3\x90`\xd9'
|
|
|
|
|
|
2024-12-14 18:08:45.789012 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 45857
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdaba
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412684230
|
|
ack = 1692641472
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0xa4a7
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\x15\xdc/n\xaa\xda\xdd\xf6\x1c,\x95]\x86\xdf\x7f\x1b5\x8bc\xab\x14C\x9a\xe4\x0e\xc5\x89\xf2\x95\xed]\xa4p\x01W\xef:\xb8\x1234\xf9zr\x86\xdd$\xd0\x1b}\x87\xa0o\x19%\x92\xe8oLt\xc4`\xff\x98\xbd\xec\x80\x8f{2\'\x16\x0c7\x8fy\xaa\xec\x0e\xaaHx\xa6\x8f\x03\xc6\xf9b\xf8\xd6\xdb{nT#\x1caf\x93\xaf\xcf\x91\x02\x81\xff\xb4+\xbe\xe5\xa4\xf3\xc5\x83%\x8c\x1e\xab\xdbD\xa5\x1d\xea\x1d\xf6r\xd8a\xad\xdemt\x07\xe5\xf0v\xc4\xa5~\n]\x8c>q\xd0E\xbe\x1e\x9e\xdc\x11\x84V\x14\xcd\x98\xf7\x10\xce\xc8,Qt\xdd\xb5\xd8-\x04\xa6\xffE\xfb\x91\xff\xc4\x8a\xbb\xcd\x9fj-\x93\xa2\xdf!K?\xdf\x88\xc8*h\x85Y\xce\xba\xa8\x93\xe9E\x9fU73\xf9E9}\xe8\x83")w'
|
|
|
|
|
|
2024-12-14 18:08:45.841478 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 49947
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcac0
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030901872
|
|
ack = 17611382
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1517
|
|
chksum = 0x5cfb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\x1c\x97g"\xf4\xcb5\x0c\xdc\x1d\x8d\xb3\\\xaa\x8c.\xc0|\xd2\xda\xc7\x81fs\xd6\xf1o\xfe\xacR*\x8b\x1d\nq\x8d\xcc2f\x9dV\xc6\x86%Z(L\xc7\xb5:\xd6\xfb\x11("\xfc\x0b\xee1#\x89\xa5Q\xb7+\x8b\xb8\x1c\x82\xfcsb\xff\x1c\x194\xb9\xca}\x0b\xd8e8C<\x96\xff_\x84\xe8\xcc\xc7\xca\xfb\x80\xe9\xa0\xf7u\xaf\xbe\xa3\xb3\xbb\xc83p\xcfxi>\x7f\xc1)\xa83\x96_B\xe5\x12\x83\xef=\xc8\xa9\xb8d\x8f\x00\x89L20\x0fV\x81\xea\x06\xd8\x95\xd9\xd39:ff\xd2L@\x85D\x99\xeb\x85\xecp\xacW\xb8\xd0i\xa9\x7f,7\xf3d\xcb\x15rp\x1b\x19\x95Bq-r\x93\xd4\xc9\x8fHS\xc3\xef\x03\x8b4\x91\x08\xe9\xf1W\xa7\xd3U\xcbN^P&e,\x110\x11F\xc7\xc2P'
|
|
|
|
|
|
2024-12-14 18:08:45.908991 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16990
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692641472
|
|
ack = 3412684447
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2065
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:08:45.939509 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16991
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17611382
|
|
ack = 2030902089
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4135
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:08:46.197864 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 45858
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdab9
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412684447
|
|
ack = 1692641472
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x47ee
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4p\x9bic\xa3:\xe7\x97\xc9\xac\x0c\x01\xfe\xf6\x16\x0f\x0f\xcee\x8a\xeaB\\\x93h\xd3i\xe5\xb9e_\xa4o\xec\x98v\x98\xf5\t>\xe3c\x08@y\xf0\x9f\xc7\xa58\x07\x82\xe9\xec\xde\x8e\x08\xa4\x94\xb1\xce\xa9\xcc\xf9D\x93\xa6\x92\xc3H\x15\x19\x03\xd1+\xf6,\x03\xd8\xaf\xda\xc7\x94~\xdcD>\xdb\xb5p\x1ag\xa8\x0f\x80\xad\xc2I5\xae\xc8u\xe7\xc4\x01\x9d\xbd"\x8cei\x9f(i\xe0\xf4\xc7\xbe\x1d\xa3,\xd3F8\xd5\x7f\xe6\xf1\xf5*#\x92\xe9\xac\x040#\xb85\xcc\xe0\xc8X\x06\x84\xa8\x15\xab\xfb\xfaON\xfb\t\xd0H\xf4\xea\x16\xa4\x00\\\xda&R\xa1\xc5wR\xbc\xf4\xabpA\xe1\xa7\x9aZ\xf0\xddV\xc9\x9e\x82\rH\\\xbe\xba\xab,&\xb8W\xcd\x08k\x87\x95D\x8d\x1e\xe0\xd6u\xcfB\x03\xed\xe8\xcd\xf9'
|
|
|
|
|
|
2024-12-14 18:08:46.238840 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 49948
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcabf
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030902089
|
|
ack = 17611382
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1517
|
|
chksum = 0x51cc
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\xacj\xff3^\xa5\xbe&\x98\xb3I\x10\x90S\x13C\x83\x06\xaa\x12Mf\xa5\xf7\x9c\x9a\xeau!\x88\x84\x94\xdf{Z\xa8:\xf7g\x07\x08H\xcd\xe8q{/v\xd4\xe38\xa1\x8e\xc6\xe5\x97\x9f\xfbZ\xdb\x9ew]\xe1\xb9j\xa5|k\x9e\xf8\x88[\xc0\xda\xdf\x0f}\x84\x17U\x9e\x86\xe8\x04\x9aD@\xe4*\x8d\xd4\xb6\xcb\x8b\n\xadD\xbd\xfe\xd7\x13\x9c\xacU\xae\xc1\xf9\xd4+\xb3\xb1\x01|\x16U\x08\xdc\x12/\x0c\x86\xa0\r\xfa6;\x83\xc2\x1f\x18\xf4\xa0\xa6\xcb\x1a\x913\xc8UW\x100\xc4^z\xb5\xf3\xad\xd4\x91\xa0_\x14\xc4/\xc9\xc0\x95\x8dY\x88\x9d\xa5\xa3\xa40\xe7\xd3b\xda#\xf5p\xf2a\xb9\x91Nlr\x92\xf4)m\xe8a&\x1c\xe44wG\x01oL\x82\xcf}\x9e,\x0f:\x0b\xbe\xd7\xe0\x1c\xf0\x91G\x17'
|
|
|
|
|
|
2024-12-14 18:08:46.264222 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16992
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692641472
|
|
ack = 3412684664
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2064
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:08:46.273986 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 16993
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17611382
|
|
ack = 2030902306
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4134
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:08:47.017435 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40578 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 204
|
|
id = 58980
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x43cf
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40578
|
|
seq = 1061769788
|
|
ack = 3654989682
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 701
|
|
chksum = 0x7db2
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x9f\xf8%\'\x17\x81?\xb4>\xa6\x855\xdb\xdeK:\x06\xf0\xc0\x12R\xa7\xd7\xef\x95\x12tUA.\xc43\xc7!I\xd3\x07t\xce\x04\x07YQ\x01\xde*\xefy\x0b\x80\xcaZ\x14h\xad\xff2\xf8\xa8:o\x17\x19\xd1\xdf\x14\xcf\xac\x89\x9dQ\xcf\xb6\x8dX\xc4\x12\x8b\xedXe\xd3&\xb4\xbd\x19\xd7!kp"\x89\x1a\xdb_.\x13d\xcfT#\xb1\xa7\xeb+w\xa5Y}A\x83\xe9M/6\xcaN~l\x9c\x9d\x87\x8d\x1a\x9c\x9eK\n\xe8\xa8Q\xa6\xe9R\xc4z\xb1\xa6\xbc\xfd\x07\xdd\xca\x07J\xb19\xd3\xb1K\xb6\xe6\x85\xa0gLp\xc4 J'
|
|
|
|
|
|
2024-12-14 18:08:47.056765 - Ether / IP / TCP 192.168.1.11:40578 > 142.250.201.74:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 42654
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40578
|
|
dport = https
|
|
seq = 3654989682
|
|
ack = 1061769952
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 511
|
|
chksum = 0x1a36
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xca\x14\xa3\x80\x84\xc5J\x16\xda\x10\xb0Y\xabA\xd0\x14\xad\t\xd9X\xbb\xa6\xe5\x9e\xd9$$3\xca\xb8'
|
|
|
|
|
|
2024-12-14 18:08:47.073136 - Ether / IP / TCP 192.168.1.11:40578 > 142.250.201.74:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 42655
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40578
|
|
dport = https
|
|
seq = 3654989717
|
|
ack = 1061769952
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 511
|
|
chksum = 0x1a36
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e/\x9b\xfd\x08(:\xbc\xf8\xf7\xd5\xa1\xbe\x86\x1e#\xd9H\x19jj\xf9\xa0\xb4\xe5\xa6c\xad.\xec%'
|
|
|
|
|
|
2024-12-14 18:08:47.084096 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40578 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 58981
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x4472
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40578
|
|
seq = 1061769952
|
|
ack = 3654989752
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 701
|
|
chksum = 0xcf24
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:16.611414 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 45867
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdab0
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412686011
|
|
ack = 1692641522
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0xb53
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00\xd4\r\x9f\x928/\xeb`\xcb\xb0\x1fS\x1f\xd81uE>\x02\xb5Im\x81\xf8\xadTH1\xcc#\x05\xc4\xe8A\r4\xc4\xad\x02\xd7\x938\x97E\x00_B\xe8\xb2\xee\xd57,n\xa5\xd1\xef&)w\x88b\xdf\x8d\xe8\xc9'\xf0n\x0e\xa4*\xec\x82\xb4\xc5\xc8\xbd\xc7\x12\x0f\xcd\x19s1\xab4\xa8\x99:\x17\xde8\xd9\x968\xb3V\x18\xf8\xb9\xf26\xa4(\x10\x1e\xe8\x8d Q\xcc\x82\xa3\xecY1\xad\xa4\xf7w\xe8)7\xbd\\\x9eL\xab\x01}+%\xd3\x19\x12\xd3\x8d\xefcy\xc5/\\\xbc\xb2\xf7)^\x17\x88p\x1e\x96\xe6qt\xf1\xc7\xc6\xd6\xeb\xad\xf7H}5S\x99\x08\x04\xf4-\xd3\xc2\x85\xaa\x00\xdf\xf1~a\xbb\xd4b\xdb\xcb\xd8PN\xbc\x060\x06\x8f\x9b\xb5\x99eS\x19\xf3\x04w\xf8\x03o\xd2\xffu\xca\xe9\xbc"
|
|
|
|
|
|
2024-12-14 18:09:16.636913 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 49957
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcab6
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030903653
|
|
ack = 17611432
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1517
|
|
chksum = 0xcb8d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00\xd4L\xa7S\x12g<O\xf7\x8f\xec5\x90O?&w\xf4\xfa\x10\xb2o& \xbe1\xc5\x8e\xa2\xeew\xac\xa1\xd7\xed\xa0[\xc7\x0c\x0eV\xb6\x08\xe0\xc3'\x9dbG\x80w\xc8i\xf3{\xbf\xe5%\xc4\x8a\x1a\x8c\x0b\xaa.\xbe\x88;\x1f\xc8\x06\x8f\xe9\xf5\x10V\xfc\xec\x98\xcf\xc6\x7f\xccG\xea\xbc\xa3\xca7\x05\xe2(\x94\xc1\x1e\xd2\x0c\x0e\x8cYh:\x02\x0b\xf8\x1b<X\xbb\xe2N\xd9\xa1\x06\xccM\xd0Y0\xd7\xf4\xfc&\xf3\xf9\xdaG\xca\xd3\xfcV\x03\xb0\x12:@u\x89\xf3\xbe\x882\x8e\xa9\x17\x06\xe7\xcf\xa7>\xae?\xcfx^\nON\xe9\xddu\x91\x03\xb3?\xa1\x89\xb0\x18\xc5\xef\xa4Xk\x1e\xdc\x9b1\x83,4L\xf0l\xad\xc2e\x07v^\x16\x8bn\xf0|D\xb4\x9e\xd5z\xeb\x82\x82\x9cF\x84\xe1$\xd6PV\x08q"
|
|
|
|
|
|
2024-12-14 18:09:16.664472 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 17014
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692641522
|
|
ack = 3412686228
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2064
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:16.673750 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 17015
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17611432
|
|
ack = 2030903870
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4134
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:16.696078 - Ether / IP / TCP 192.168.1.11:39688 > 162.159.136.234:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 94
|
|
id = 3271
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.136.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39688
|
|
dport = https
|
|
seq = 3211593179
|
|
ack = 414067568
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0xed8d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x001\xa0mp8\x13\x82U$\xa5\x11\xe3\xef\x03@\x99\xb1\xe8\x11\xae\x0c\x1b\xff\x0f\xa5G\xack\xc6:8f`\xf75\xb3\xec\xb1yp\xed\xf5Z\xe9\xa1\x00\xd9\xd6\x86f'
|
|
|
|
|
|
2024-12-14 18:09:16.723535 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 669
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x54f6
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414067568
|
|
ack = 3211593233
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 8
|
|
chksum = 0x1c2f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x05z\xdaI'
|
|
|
|
|
|
2024-12-14 18:09:16.816953 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 670
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x54ce
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414067568
|
|
ack = 3211593233
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x68c4
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\x9d\xee%\x05\xf7\x10\xc1\x11a\xa8M+*;\xba\xf3\xda\xd3O\x11^\xde=\x0b\x06PX6\xfc\xd6\xcaZ=\xd7'
|
|
|
|
|
|
2024-12-14 18:09:16.868202 - Ether / IP / TCP 192.168.1.11:39688 > 162.159.136.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3272
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.136.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39688
|
|
dport = https
|
|
seq = 3211593233
|
|
ack = 414067607
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 510
|
|
chksum = 0xed57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:16.913292 - Ether / 192.168.1.11 > 239.255.255.250 2 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:7f:ff:fa
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 6
|
|
tos = 0x0
|
|
len = 32
|
|
id = 60801
|
|
flags =
|
|
frag = 0
|
|
ttl = 1
|
|
proto = 2
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 239.255.255.250
|
|
\options \
|
|
|###[ IP Option Router Alert ]###
|
|
| copy_flag = 1
|
|
| optclass = control
|
|
| option = router_alert
|
|
| length = 4
|
|
| alert = router_shall_examine_packet
|
|
###[ Raw ]###
|
|
load = b'\x16\x00\xfa\x04\xef\xff\xff\xfa'
|
|
|
|
|
|
2024-12-14 18:09:17.532848 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 169
|
|
id = 671
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x5473
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414067607
|
|
ack = 3211593233
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x124e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00|\xb4\x14:\xf4\x81\xf4\xf6&\x0c\xd0\x10v!\xca(\xdcn3*]z*IR\xfa|\xc4\x9a;%\xcf3l\x07@\\t\x9d\x18\x87]Tw5B"\xb2\'\xef\x97G\xb5v\xb3o\x06\xec\xe4\xcc\x82\x96\xdc\x1fJ\xb07bc|\xaf\x18\xf8mt\xdc\xe9\xd2\x05b\xc8\x8a\xe9\x03\x94\tcj\xac\xa9\xa4\n\x9e\xd6.\xae\xb5\x110\xb6\xdb\xbb\x8a\xbd\x9a\xeb\x96\x1d\xaa\x8a\xab\x95Mk\x1dVr\xee\x95\xbe\xd4\xa1\xea\xcb~'
|
|
|
|
|
|
2024-12-14 18:09:17.581559 - Ether / IP / TCP 192.168.1.11:39688 > 162.159.136.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3273
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.136.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39688
|
|
dport = https
|
|
seq = 3211593233
|
|
ack = 414067736
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 510
|
|
chksum = 0xed57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:19.178528 - Ether / 192.168.1.27 > 224.0.0.251 2 / Raw / Padding
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 2c:93:fb:9c:dc:c0
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 6
|
|
tos = 0xc0
|
|
len = 32
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = 2
|
|
chksum = 0x4159
|
|
src = 192.168.1.27
|
|
dst = 224.0.0.251
|
|
\options \
|
|
|###[ IP Option Router Alert ]###
|
|
| copy_flag = 1
|
|
| optclass = control
|
|
| option = router_alert
|
|
| length = 4
|
|
| alert = router_shall_examine_packet
|
|
###[ Raw ]###
|
|
load = b'\x16\x00\t\x04\xe0\x00\x00\xfb'
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:19.990420 - Ether / 192.168.1.62 > 239.255.255.250 2 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 6
|
|
tos = 0xc0
|
|
len = 32
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = 2
|
|
chksum = 0x3237
|
|
src = 192.168.1.62
|
|
dst = 239.255.255.250
|
|
\options \
|
|
|###[ IP Option Router Alert ]###
|
|
| copy_flag = 1
|
|
| optclass = control
|
|
| option = router_alert
|
|
| length = 4
|
|
| alert = router_shall_examine_packet
|
|
###[ Raw ]###
|
|
load = b'\x16\x00\xfa\x04\xef\xff\xff\xfa'
|
|
|
|
|
|
2024-12-14 18:09:20.016340 - Ether / IP / TCP 192.168.1.11:40825 > 20.42.73.30:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 58966
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.42.73.30
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40825
|
|
dport = https
|
|
seq = 2481585275
|
|
ack = 3769523708
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x1f17
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:09:20.122916 - Ether / IP / TCP 20.42.73.30:https > 192.168.1.11:40825 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 7748
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xd184
|
|
src = 20.42.73.30
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40825
|
|
seq = 3769523708
|
|
ack = 2481585276
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 16384
|
|
chksum = 0x89af
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (2481585275, 2481585276))]
|
|
|
|
|
|
2024-12-14 18:09:20.604134 - Ether / IP / UDP / mDNS Qry b'_adb._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 2c:93:fb:9c:dc:c0
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 154
|
|
id = 62535
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0xe44b
|
|
src = 192.168.1.27
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 134
|
|
chksum = 0x4338
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 2
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_adb._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_amzn-wplay._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'_amzn-wplay._tcp.local.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:09:20.809586 - Ether / IP / UDP / mDNS Ans 192.168.1.62
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 350
|
|
id = 6706
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = udp
|
|
chksum = 0xbb7b
|
|
src = 192.168.1.62
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 330
|
|
chksum = 0x26d8
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 0
|
|
ancount = 3
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'192-168-1-62.local.'
|
|
| type = A
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3599
|
|
| rdlen = None
|
|
| rdata = 192.168.1.62
|
|
|###[ DNS SRV Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
| type = SRV
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3599
|
|
| rdlen = None
|
|
| priority = 0
|
|
| weight = 0
|
|
| port = 35948
|
|
| target = b'192-168-1-62.local.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
| type = TXT
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3599
|
|
| rdlen = None
|
|
| rdata = [b'a=0', b'c=36:af:b3:ac:fc:17', b'ad=A31DTMEEVDDOIV', b'pv=1', b'f=0', b'mv=2', b'dpv=1', b'n=FireTVStick de fabiola', b'at=TyK0zfSnV9zr', b's=0', b't=2', b'u=77A58D33A6B0B8794D57457DEBC2CE4D', b'v=2', b'sp=36805', b'tr=tcp']
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:09:21.628555 - Ether / IP / UDP / mDNS Qry b'_adb._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 2c:93:fb:9c:dc:c0
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 154
|
|
id = 62920
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0xe2ca
|
|
src = 192.168.1.27
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 134
|
|
chksum = 0x4338
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 2
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_adb._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_amzn-wplay._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'_amzn-wplay._tcp.local.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:09:21.833812 - Ether / IP / UDP / mDNS Ans 192.168.1.62
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 350
|
|
id = 6768
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = udp
|
|
chksum = 0xbb3d
|
|
src = 192.168.1.62
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 330
|
|
chksum = 0x26d5
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 0
|
|
ancount = 3
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'192-168-1-62.local.'
|
|
| type = A
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = 192.168.1.62
|
|
|###[ DNS SRV Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
| type = SRV
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| priority = 0
|
|
| weight = 0
|
|
| port = 35948
|
|
| target = b'192-168-1-62.local.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
| type = TXT
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = [b'a=0', b'c=36:af:b3:ac:fc:17', b'ad=A31DTMEEVDDOIV', b'pv=1', b'f=0', b'mv=2', b'dpv=1', b'n=FireTVStick de fabiola', b'at=TyK0zfSnV9zr', b's=0', b't=2', b'u=77A58D33A6B0B8794D57457DEBC2CE4D', b'v=2', b'sp=36805', b'tr=tcp']
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:09:22.346397 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 417
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc5a8
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 397
|
|
chksum = 0xc02c
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: upnp:rootdevice\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::upnp:rootdevice\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.351364 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 489
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc560
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 469
|
|
chksum = 0x502d
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.364184 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x83e4
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.373978 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 485
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc564
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 465
|
|
chksum = 0x7632
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.384325 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8392
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.395741 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 465
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc578
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 445
|
|
chksum = 0x8a6f
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:device:WANDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.403758 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8394
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.415812 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 497
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc558
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 477
|
|
chksum = 0x3a9
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.423392 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 479
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc56a
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 459
|
|
chksum = 0x81a1
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANIPConnection:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:service:WANIPConnection:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.442925 - Ether / IP / TCP 192.168.1.11:49517 > 20.54.37.73:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 1801
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.54.37.73
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 49517
|
|
dport = https
|
|
seq = 3022298396
|
|
ack = 3222002737
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 516
|
|
chksum = 0xfb4d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:09:22.490564 - Ether / IP / TCP 20.54.37.73:https > 192.168.1.11:49517 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 15644
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0xd675
|
|
src = 20.54.37.73
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 49517
|
|
seq = 3222002737
|
|
ack = 3022298397
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 7168
|
|
chksum = 0xf5f
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (3022298396, 3022298397))]
|
|
|
|
|
|
2024-12-14 18:09:22.523988 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 479
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc56a
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 459
|
|
chksum = 0x81a1
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANIPConnection:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:service:WANIPConnection:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.530105 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 497
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc558
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 477
|
|
chksum = 0x3a9
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.546504 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8394
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.556843 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 465
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc578
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 445
|
|
chksum = 0x8a6f
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:device:WANDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.568579 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8392
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.578077 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 485
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc564
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 465
|
|
chksum = 0x7632
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.587120 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x83e4
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.595607 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 489
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc560
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 469
|
|
chksum = 0x502d
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.608634 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 417
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc5a8
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 397
|
|
chksum = 0xc02c
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: upnp:rootdevice\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::upnp:rootdevice\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 18:09:22.909429 - Ether / IP / TCP 192.168.1.11:40768 > 104.199.65.9:4070 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x98
|
|
len = 51
|
|
id = 2614
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 104.199.65.9
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40768
|
|
dport = 4070
|
|
seq = 998635232
|
|
ack = 3458560761
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0xf701
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xa0M\xf1d\x11\xd9\xb7}@\x88\x8d'
|
|
|
|
|
|
2024-12-14 18:09:22.953032 - Ether / IP / TCP 104.199.65.9:4070 > 192.168.1.11:40768 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 51
|
|
id = 14962
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x9ecf
|
|
src = 104.199.65.9
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 4070
|
|
dport = 40768
|
|
seq = 3458560761
|
|
ack = 998635243
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 6
|
|
chksum = 0x7473
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x1de\xc5\xbb\x04\xe2.\x8c\xdb}\xbb'
|
|
|
|
|
|
2024-12-14 18:09:23.000082 - Ether / IP / TCP 192.168.1.11:40768 > 104.199.65.9:4070 A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x98
|
|
len = 40
|
|
id = 2615
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 104.199.65.9
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40768
|
|
dport = 4070
|
|
seq = 998635243
|
|
ack = 3458560772
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 510
|
|
chksum = 0x1f91
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:23.435506 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 57
|
|
id = 54380
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 37
|
|
chksum = 0x8ef
|
|
###[ Raw ]###
|
|
load = b'O\xf3wB\xde\xaf\xa6\xa7\xe0\xff\x94\xf2O\x1cm;\x06ys2\xacb\x12{H\xda\xc6\xb9\xa4'
|
|
|
|
|
|
2024-12-14 18:09:23.444351 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 170
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3a8b
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 150
|
|
chksum = 0xf0b0
|
|
###[ Raw ]###
|
|
load = b'\\\xa5\xf9\xf5\xb0\xd4hW|\xef~\xeaN\xb0t\xb8J\xb20\\\xd0O?\x97\xe4\xcf\xbe\xa7 \x00\x02\x84\xe10\x89\x0bj\xf1\xa4\xd6\x8c&\xfc(\xed\x0c\x7f\xe6B[w\xbb\x0c\xe6\x03\x0e%*t\xee\xa104\x99\xe59b\xd2\xd2\t;\nK\x8c\x92\xafK\xe2@\x0c\x06<eh\x82\\\xcd\x01\xd7\xa3\x9ci\x81\xa8j\xec\xb2XWR2\x91\x9e\xaa\r\xa3\x92a{\x9c_n\x07\xa5\x93VA\xbb\x02\xad\xe4\xf5\x0f\xa7\xf5\x8dr\xd6\x88\x85\x83_\x18\xf4\xe8\xf0\xcf\xe8\xd5\xcf\xbdZ'
|
|
|
|
|
|
2024-12-14 18:09:23.457946 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 61
|
|
id = 54381
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 41
|
|
chksum = 0x8f3
|
|
###[ Raw ]###
|
|
load = b'K\xf3wB\xde\xaf\xa6\xa7\xe0&\xd5\xc3_?\x0c\xe8\x93D\xc9\x83\xc3\x94\x01z\xcau\xb2\xab\x88\xd7S\x86 '
|
|
|
|
|
|
2024-12-14 18:09:23.468211 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0xdfd6
|
|
###[ Raw ]###
|
|
load = b'S\xa8\xe5A\xc3\xbdk\x18\xcf\x85z \xdc\xe0\x00\x95~\xdb\xfa\r\xbe\xc9z\x8c\xd8'
|
|
|
|
|
|
2024-12-14 18:09:23.676349 - Ether / IP / UDP / mDNS Qry b'_adb._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 2c:93:fb:9c:dc:c0
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 154
|
|
id = 63438
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0xe0c4
|
|
src = 192.168.1.27
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 134
|
|
chksum = 0x4338
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 2
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_adb._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_amzn-wplay._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'_amzn-wplay._tcp.local.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:09:24.045163 - Ether / IP / TCP 192.168.1.11:37662 > 74.125.133.188:5228 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 38433
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 74.125.133.188
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 37662
|
|
dport = 5228
|
|
seq = 938547355
|
|
ack = 2945028465
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0x9208
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:09:24.085813 - Ether / IP / UDP / mDNS Ans 192.168.1.62
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 350
|
|
id = 6908
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = udp
|
|
chksum = 0xbab1
|
|
src = 192.168.1.62
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 330
|
|
chksum = 0x26d5
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 0
|
|
ancount = 3
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'192-168-1-62.local.'
|
|
| type = A
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = 192.168.1.62
|
|
|###[ DNS SRV Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
| type = SRV
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| priority = 0
|
|
| weight = 0
|
|
| port = 35948
|
|
| target = b'192-168-1-62.local.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
| type = TXT
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = [b'a=0', b'c=36:af:b3:ac:fc:17', b'ad=A31DTMEEVDDOIV', b'pv=1', b'f=0', b'mv=2', b'dpv=1', b'n=FireTVStick de fabiola', b'at=TyK0zfSnV9zr', b's=0', b't=2', b'u=77A58D33A6B0B8794D57457DEBC2CE4D', b'v=2', b'sp=36805', b'tr=tcp']
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:09:24.093574 - Ether / IP / TCP 74.125.133.188:5228 > 192.168.1.11:37662 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 58144
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xcfb6
|
|
src = 74.125.133.188
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 5228
|
|
dport = 37662
|
|
seq = 2945028465
|
|
ack = 938547356
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1046
|
|
chksum = 0x98e
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (938547355, 938547356))]
|
|
|
|
|
|
2024-12-14 18:09:26.050269 - Ether / IP / UDP 192.168.1.11:57621 > 192.168.1.255:57621 / Raw
|
|
###[ Ethernet ]###
|
|
dst = ff:ff:ff:ff:ff:ff
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 48748
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.255
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 57621
|
|
dport = 57621
|
|
len = 52
|
|
chksum = 0x9f
|
|
###[ Raw ]###
|
|
load = b'SpotUdp0\x977M\xb3\xe9=C\xf2\x00\x01\x00\x04H\x95\xc2\x03\xb3}cPK\xb7\xed\x7fT~\x1d\x0f\xd7\x01\x15-#vA\xf6'
|
|
|
|
|
|
2024-12-14 18:09:26.871244 - Ether / IP / TCP 192.168.1.11:41004 > 142.250.200.138:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 11687
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.200.138
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 41004
|
|
dport = https
|
|
seq = 1910279478
|
|
ack = 2964521239
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0x1954
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:09:26.895638 - Ether / IP / TCP 142.250.200.138:https > 192.168.1.11:41004 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 43736
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x80b3
|
|
src = 142.250.200.138
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 41004
|
|
seq = 2964521239
|
|
ack = 1910279479
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1045
|
|
chksum = 0xb83
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (1910279478, 1910279479))]
|
|
|
|
|
|
2024-12-14 18:09:27.568573 - Ether / IP / UDP / mDNS Qry b'_adb._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 2c:93:fb:9c:dc:c0
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 154
|
|
id = 63692
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0xdfc6
|
|
src = 192.168.1.27
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 134
|
|
chksum = 0x4338
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 2
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_adb._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_amzn-wplay._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'_amzn-wplay._tcp.local.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:09:27.575271 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 49958
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcab5
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030903870
|
|
ack = 17611432
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1517
|
|
chksum = 0xbba9
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00\xd4f6\xd3\xba\x90\xb0#\xff\x8c]\x0e\xacse\xa5\x07CC\xc3\x84\x06M\xe6.3\xb6\xb0\xee\xf8\xdc\x95\x9cn3\x80C\xa1V\xd1\xcb\xc0\xc2\x07g%C\xc7\x9chE\x0e\xbb\xbe=*\t\x9d\x000\x84\xe8\x9fKObJ\xbb$:\x7f\x95xE\xcb\xf6&M\xfb\xb3\x99\x8at\xba2\xf6/!\xc8\x04\xbc\x92\xce\x0f\xb8\xf3\x04\x14w\xa4\xd9\xfd\xfc \x17\x99\xfc\xd1<\xd0\xbe\xc8\x97\xe6:\x07T)\xd6\xea\xcb\xb4+\x82\xc6\x7ft\xa1T\x97\xc2C\x8c\xbf\xedL?\xeb\x80\xf6!\xf1\x8b\xc7\xc7f\xf3|I\xb2W\x11\xdb\x15\xb2'3\x1e\xb4y\xf7\x9a\xa3bOSi\x92\xd7!}\xc3\xa33\xfc\xdd\x15\xff\xb1P\xe6\xc1\x1e4}\x86\xb0u\xd80G\xa2\xe4I\xb3\x9a\xb1|\x83\xeb\xfab.?\x89\xd6\xa7\xaf\xe66\x0f\xceI"
|
|
|
|
|
|
2024-12-14 18:09:27.584729 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 45868
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdaaf
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412686228
|
|
ack = 1692641522
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x9017
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00\xd4\xdb\xdb\xbdb\x03@d\xf3(\x9c3\xdbp\xa1\xce\xadN\xe2\xd4\x1d9\x18\x7f\xd0\xc9\xfd\x1a\xa4\xc7\xb0\x8fv\xf6\x03\xf5L\xda\xc0\xc2\xd4\xf1(\xde\x0c\x1b\xf3\xbb\xc2\xa3\t#(\xb6RidC\x7f\x04\x97\xd0\x19p\x04\x89\xccnk*\xf7%\xfc>\xf2eU4e\xdd\x1a\xfb\x15\xff8\x05\x86\xcb\x1d\xe1L\xdeA\xc0\x18xV\xa1@\x02\xeb\xbd\t\x93(\xd3\\w\x8b\t\xf7\x9d\xdf$\xe9\xdd\xd8p<\xc0\t\xbd\xa6\x86\x13\xd1\xc5\xcdb\xb8\x1d\xcd\xdd\x8b\x18\x1ex\xa5\xabx\xf4\xfc\x02\xe3\xaa\x11T\xfd\xdf-,\xf7\x97\xc3\xa1`\x18\x16\xed\xcfm\xc6\xbfH5\x85VP\xa3k\x80(\x8a\x16;1=\xe7\xec\x80\xb1\x1d\xe1\x8by\xb02\xa5*\x13\xb8n\xd3W\xc6\x83\n\xe5t590z>\x9d\xf4\xf7\xead)'\x80\xee"
|
|
|
|
|
|
2024-12-14 18:09:27.773078 - Ether / IP / UDP / mDNS Ans 192.168.1.62
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 350
|
|
id = 7034
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = udp
|
|
chksum = 0xba33
|
|
src = 192.168.1.62
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 330
|
|
chksum = 0x26d5
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 0
|
|
ancount = 3
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'192-168-1-62.local.'
|
|
| type = A
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = 192.168.1.62
|
|
|###[ DNS SRV Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
| type = SRV
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| priority = 0
|
|
| weight = 0
|
|
| port = 35948
|
|
| target = b'192-168-1-62.local.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
| type = TXT
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = [b'a=0', b'c=36:af:b3:ac:fc:17', b'ad=A31DTMEEVDDOIV', b'pv=1', b'f=0', b'mv=2', b'dpv=1', b'n=FireTVStick de fabiola', b'at=TyK0zfSnV9zr', b's=0', b't=2', b'u=77A58D33A6B0B8794D57457DEBC2CE4D', b'v=2', b'sp=36805', b'tr=tcp']
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:09:28.182986 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40578 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 230
|
|
id = 58984
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x43b1
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40578
|
|
seq = 1061770116
|
|
ack = 3654989822
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 701
|
|
chksum = 0xed0d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xb9<`\x10\xa5\xa9A\xf4\xd0Da\xe5\xac}\xbf\xa0M\x02\xda6\xef\x8e\xc4\xae\x86o\\\xe1iO-\xe86m\xcfA\x9b\n\xa9hY"\xde\xdf\xa1x\xd0P\x12\xbbiT\x08\xb5\xe9\x9b\x1d\'\x17\xc3\xe4\x8fj\xbd\xb0\xeeV\xe4\xfa\x19\x1c\xef\xc7"p9l\xce>u|\xdc?.\xdc\x0f\xc2\x07N\xde|aly\xc9\xc0M,GJ\xd1\xbe\x10\xd0\xaa$\xccLg\xa9\xa5\xc2\x11\xc7|qR\x05\xa0\x0e(\x84D\x1ci\xe8\xabz\xe9\x07\xf1\xcbMQ\x8d\xbd5\x88x\xf6H\xa7\xe1\x02\x0fVL\xf0\xbcR_\xa9\xe26\xdc$\xfd\x9f\x89\xe4\x03\xb2\x0cy\xf55\xc2\xe7\x07\xfb\xde\x99\xdc\xffii\xb1#R\xc2\x8d\x07Y,d\xd0'
|
|
|
|
|
|
2024-12-14 18:09:28.195612 - Ether / IP / TCP 192.168.1.11:40578 > 142.250.201.74:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 42659
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40578
|
|
dport = https
|
|
seq = 3654989822
|
|
ack = 1061770306
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0x1a36
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\x13\x8f\x8b\xef\xd4\xbc\xfd\xe3Z~\xc9"go\xc0\xdc\x15\xbf\xe7\x9cWT$\xfaC\x97\xd4\xb4\x83\x9d'
|
|
|
|
|
|
2024-12-14 18:09:28.206339 - Ether / IP / TCP 192.168.1.11:40578 > 142.250.201.74:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 42660
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40578
|
|
dport = https
|
|
seq = 3654989857
|
|
ack = 1061770306
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0x1a3a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\xa5\x9b\x0e\x14N,\x87y\xfb\x8b\xfa^\xbe\xe4\xfdq\xfe\x18\xa6\xaa\xa3\x87\x8d\xc1Z\xea0 \x0e\xf0ka{\xb4'
|
|
|
|
|
|
2024-12-14 18:09:28.213552 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40578 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 58985
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x446e
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40578
|
|
seq = 1061770306
|
|
ack = 3654989896
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 701
|
|
chksum = 0xcd32
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:28.218394 - Ether / IP / TCP 192.168.1.11:40577 > 142.250.201.74:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 269
|
|
id = 42661
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40577
|
|
dport = https
|
|
seq = 3290738374
|
|
ack = 413172483
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 507
|
|
chksum = 0x1af8
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xe0\xa7g\xcaM\x0eT\x97\xdet\xee\x93\x05.n\xa36\x93`$\xd5s\xfc\x03F\xf4\xfe\xa1L\xd5\xe9\x895\x8c\x98G\x8f\xff_\xf1\n\x91\x17\xac\xb2\xf9\xb1\x1c\x99\xb0Mg\xd8-J[\xb2\xfa[\xb8\xfeU\xeeL\xf1\x18\x9b\xb8\xda\x04\x1b\xa6\xa8\x19\xe8\r\x90-_J\x12:\x17\x82\x04\xecO\xa4/\xf5\\upL`n\xa3\x84\xe1\xfa0\xf0\x9a\xa0F\x9fn$\xb7>\x8a\x07\x90\x11\x12l\xa5\xdc\xab+\x98\xf5B\xc5`m\x93\xf6L\xa7:\xc6\\\x95Zj\xe5\xa2\x8ce\x08\xb5\xa0\xb7\xdf\xd8%6\xc2BO\xd7k\x86\xc9>\x03=)\x15\x85\xa9BHd;3b\xde\xbd7\x9b\x95\x05"\xff\xd4\xa9\xb6\xf6\x13\x89\x101-\xb2D\xf6}\x0e\x9d\x81\x90\xc6\xf2\xd2\x86\x06/\xc611\x9e\x7fZ\x7f\xd582\xe3\x16\xb9\xb4{\xe4\xec\xb2\xa6v\xe4=?\xfa\xebb'
|
|
|
|
|
|
2024-12-14 18:09:28.259086 - Ether / IP / TCP 192.168.1.11:40577 > 142.250.201.74:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 42662
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40577
|
|
dport = https
|
|
seq = 3290738603
|
|
ack = 413172483
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 507
|
|
chksum = 0x1a3a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"(\xdd\xbc6e\xce"\x0c\xb0\xc6Yp\xd8g\xdfBlt\xacp8\xcb2OU\xbbMEJ\xbb\xdah\xcc\x07'
|
|
|
|
|
|
2024-12-14 18:09:28.272371 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40577 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28974
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xb9a9
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40577
|
|
seq = 413172483
|
|
ack = 3290738603
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1042
|
|
chksum = 0xe219
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\xaeSX\xe0\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:28.283027 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40577 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28975
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xb9a8
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40577
|
|
seq = 413172483
|
|
ack = 3290738642
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1042
|
|
chksum = 0xe1f2
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\xf3\xfd\xacs\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:28.292947 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40577 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 28976
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xb980
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40577
|
|
seq = 413172483
|
|
ack = 3290738642
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1042
|
|
chksum = 0x4dfc
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\xe0[9\xafE\x7f\xdc\x1e\x95x\x1e\xfe)\x00\xa7\xd9.M\x0e\xa3\x12\x98\xc5\x1f\x85b\x8e\xfa]\x8d\x80q\xfcY'
|
|
|
|
|
|
2024-12-14 18:09:28.299126 - Ether / IP / TCP 192.168.1.11:40577 > 142.250.201.74:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 42663
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40577
|
|
dport = https
|
|
seq = 3290738642
|
|
ack = 413172522
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 507
|
|
chksum = 0x1a13
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:28.363071 - Ether / IP / TCP 142.250.201.74:https > 192.168.1.11:40577 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 28977
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xb961
|
|
src = 142.250.201.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40577
|
|
seq = 413172522
|
|
ack = 3290738642
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1042
|
|
chksum = 0xe4cb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00@l\x8a\xdd\xef\xfe{\xa94#\xd2B\xaf\xe4\xba\xac\xaa\x90\r.%\x8e\xe1\x10\xef\\\x05\x87\xa9t\x14U\x84\xdbu\xb8\x11\xb1'\x17\xe0\xcb\x84\xf2g\x1a&\xa7\n\x00\xc4\xad\xfe\xa0\x7f>E\xc9\xf9\x06|\x0c\x02t\x99"
|
|
|
|
|
|
2024-12-14 18:09:28.371321 - Ether / IP / TCP 192.168.1.11:40578 > 142.250.201.74:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 42664
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40578
|
|
dport = https
|
|
seq = 3654989896
|
|
ack = 1061770306
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 510
|
|
chksum = 0x1f97
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\tzFU)\xde\x18%R\xea\x8b\x037J\xad\xf3\xa28\x00\x04\xf5\xbd\x0f\x10\x9bp\xac!\xb5D\x99\xed\x9e\xceH\xd4\xc22\xde(!\x0c\x16\x0b\x8b\xd5\xd5\x02\xbd-\x1eV\x12D\xab\r\xdc\x1eS3-\xe0c\xac\x01Q\xdc\xe3\x1d\xb5Y\xb8\x85\xbe\xd1\xca\xb8\xc2\xbc\x92\x8a\x80\xf2bIr\xc1\xf7\xb4\xc0x.wi\xdajU\x81\nE\nI\xdf\x1e \xae\xf5\xb8\x0f\x01\x89?\xcb4\xfb\x17\x1bH\x16\x1f\xba\xe0\x15\x184y\x9a^r/\xc0r1b\xd8j\xcb\xa2\xa0\xe8\x15\x88\xd9\x02\x90\xff\x1e\xc7u[\xa1\xa7\xc6\x82~\xe3\xe1[\x16\xc5\x92\xf5H[FUhLb]\x7f}\xad.\xa7D\x18O\xed\x17\x99*\xb4\xad\xf4\xd9[mZ\xfeLv\xd7\x8al\xe8\xac3\xee\xac\xf4v\xd7\xaeGeD\xc5i\xd4\xbf\x01\x7f?\xa8n\x02i\xdae\xe5 ;mE\xd8}\xc16/\n\xca\xcf7\x0b\xa2@\x80\xb5\x13\x18\xda\xbc\xde\x1a\x1eC\x94\xa7\xca]\x07f\xa6\xdd\xafP\xaf\x9a\x8a|-\xd5\xb4\xd0\xed\xd9\xc4\x1f\xc3B\xca\xdew\x0f\xae\xe9\x85\x02>\x18k\xc7\xa7\xb7\x11\xf1\xe4\x7f\x00rD\xb6\x8a\xbe4\x10$a\'\x03[\xb9\xb2W\xb3\xa8RrO\x95\x87\xabG\xf2S`\xb3\x01\xa1c\x8b\x94@JG\xdd\xaem\x96*\xfb\xf6\xbdx\x86\xcd`R\tu\t\x88H\xed\xa0\xfeb\xb8\xe5\x0f\xad40\xcb`_q\xb1\x9a=\xf3P\x92\x9bH\xc1\xce\xa6\xc4\xee`dJ\xf5!\xc2\xf0\x1a\x84~\x06\x91\to\xb0<:l\x1d\x18\xdb\xaa\xb7\x85D8\xe2\xf1\xb4\xccG\xb1\x98\xc5\x02\xa8\xcf\xc6\xe0\xa1\x84\xab\xf7vsh\xcb\xb6\xeb\n\xe5:&\xf2\xe1\xdd\xb2l9D\x88\xe3\x9b\xea\x98\xa9\xa2\x86\xb9\xfd\x18\x10\xc94\x94\x14\x85\xa7\x0f\xa4\xbd\xe6a%]\xe1\xdb\xb72\x8d\x95G*%B\x03\xd8\xeb\xbb[\xf6Z\xcePE\x1d=\xe5S+\x8ff.;\xe0zRk4\x89\xf8\xf7\x83`\x9e-F ,\xe5M\xf3\xe6\r\xd3\x8e\xfewm.\xc7;w\xf7g1\xc6(\xc1\xda\xe3.\xba\x8a\xab\x06cO h\xba\x19;\xd7\xab\xdbh\x8cF\xdf\xa6E\xafI\r\xabA{\xc1u\nAirT\xfa\x80\x8b\x80\x1d5w\x99$\xabR\x8a\xac\xfd\tP\x8d\x8a>\x01\x1c\xae\xab\xee\xc1|^\xf5\xf1\x96\xd4h\xda\xd6\xbf\x95*T\xccW\x1b=^\x1a\x9d.H\x98\x8c9\xea\xb4C\xce@\xdf\x13\xcexL\xa9\x91{\x98\x882\xf0\xef\x9c\xea2w8\xf2\xad\xb9\x1e\xc1A\xf2\xa5\xce\x055\xf9{\n\xe9\xa82\xcf?$7\x08\x92\xb6S\xc7N\xd7\x15CH2\x9c\xfc\xfa\x14\xf3\x06\x80;$E7\x13\x99\xcfP\xd3;\xd0\xaf\rp\xb2,\x07\xab\xa9\r\xe5~\xbfV\x9e\n\xd0}\xb9 >!/a\x15\x95\xfe\x9f\xfcN\x99\x8f\x18h\x07\xc4\xff\xf8\x80s3c\xff]\xec\n\xe5E\x00\x88\xfe\xff\x88<\xca7\x02\x95\x9f\xb6\xf7\xc8\xa9\xf2s\xf0\x1f\x06_\xca%\xeam}\xd405)wZ\xad\x1b%c\xaf\n\xec\xc4\xc4\x8c\xaf\x00[\x98\xeb\x13\xd0\x87H\x05\xa8\xae3\xc1\xc8<\xcd\xf5\xcf\xa8\xbf\xd5e\xd5i\xd2_p\xd0}{?\x8f.\xcb\xba\nX5\xc4\xb90\xf3\xf6\xdb*n\xf5\xea\xd0\xaa7\x06,8"\xa0\x01\x96\x0b]\xf9A\x84\xc0\xe1\xa7\x95\xc7\xec:\xba\x8f\xce,*\x04\x9dv\xad9\xf4\xd4\x1a\xde\xa8\x1d\x04\x91\x15\'"5f\x1b\x93\x1c\xd1.Z-\xe6\x83\x0e%\xb9\x1b\xf7\xc3\xaa\xc8\x91\x10T\xcb\x17\xf6\x16 \xc1E\xeb\xf8\xadN\xd1\x03\xbd\xc9c\x98\xc7\xf9\xb5\xcb\x0c\x0c,\x97\xc6JS\x9e\xec\xc9\xb7\xc7\x1bP9Z\xc4I\xf0?\xa6\xbe\xd6\xff\xd0\x16\xda\xa0\x19\x9aW\xac\x8c\xeaW\xe4\xb6\xcc09\\\xe3B\x818\x89pp<\x1c\x81\x02\xa1%\xe7rw\x9b\xf3\xef\xa0\xbdH\x0b\xc6%V\xe1\xbe\xb7\xcc\xf7\xda\xc0D\xab\x87\xef\xd7(\xd4?\xab\xc3\xa9\xfe\xfc;H\xc5\xc6\xe8\xc3\xefa\x18\xaev\xa9.-\x1c\xd28u\x1c\x16G\xe4\xdeze[\x81\xbds\x19Fw\xa7\x07\x1fzI\t\x07\xee\xd1\xfb\xbf\xe6Zv#c\x92\xfb\x98\x1a_\x8b\xc1>&\xf5\xd0\xffg!\xb4\x1c_A\x92\x14\xa6\x0b\xdfF \x85$\xdfi`\xf6\xc3\xe3\x81@\xe1k\x03\xd4\xf3h\xd6\xf4\xe6J\xc3+(8\x9d\xc2c\x10p\x9a\'\xd3\x14_\xa1\xe6\x1b\xbfr\x036\x87|\x04Q\xc3K\xf3\xf0\xb8\x81\x8f\xa1\x0c\x90#\xb2\xc8\x88\x83\x0e\xe0\xc0\x87\x0c\x01\xe9\x01\xff\x9b\xd7V\x1d\xca\x9e\xf9\xa8\xc78\x1e\x85\'\xb8\x15\xb96;\x03\x1d-\x92\xf3\xbfw7i\xed\xcfI8\xbb\x07\x98\'d\x06\xbcb\xed\xad\x1e^2)F\xa6f\x89\x11\x9c\x8f\xab\x1bZ\xbb\x8d\x00\xba\xd6\xf3\xac\xaf\x92\xda\xb9\xf1"\xf7\xb9\xfe\n\xdc\xa7\xca\xd9\x98/\xb1\xdauI\xa6\xed3\xbf1\xc8\xe3m{y\xc0\xaec\x8f~^\x16\xc2\x02\xf1\x90\xec\x8a2\xd7\x99*c\xa9\xcd\x94^\xd7\x88\xd5\xbf\x8bk\xc7\x9b\x1e\x01\xe4%%4H\x04\x03\x94s)\xb5ut\xae\xd0ZSc\xfb\x01H\x86IX\\I\x0fy7\x84\xd5j)\xc5\xf5\xab\xb9\x97\xd1\x1aU\xb0-\x13\xe8Q\x91)\xd4H\xaa\xd5:9O*\xa0\xb7>m\xf9+\xf4\xa4q\xf7\xf1|j\xc4\xcc9\xfe\x9a\xed\xd5}\xeb\xf8\xc6U\x94l\x85\x08\xf8\xd0\xb8\xba\xdeY\x81\xae\xbel\xea\x9bW\x15Y\xaa\x173\xb1CAB\xda\xc6J#@\x9d\xe6\xb1\xa8\x97uUt\x8d\xd7\xcd\x82\xd1\x94\xc7\x0f\xa7\xfdh\x7f\\\xf7>^\x849\xa6\xfe\\\xdbvB\x9fRA\xd5K&\xb6\xaep'
|
|
|
|
|
|
2024-12-14 18:09:28.573636 - Ether / IP / TCP 192.168.1.11:40578 > 142.250.201.74:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1059
|
|
id = 42665
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.74
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40578
|
|
dport = https
|
|
seq = 3654991308
|
|
ack = 1061770306
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0x1e0e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'`\xc6\xb1f\xf4\x1a\xde\x8c\x85\xb5\x0c\x1c\xc6gh\xab`\xb1bu\x89\xc3\x08\x00\xa3J0z\xb8\xb4\xb2\x94\xa9A\x8e\xd3-X\xd3\x01}\xc0\x8aW\x08G\xd5J\xb5\xf0Z9Id\x97\xfe\xcbYCQnJB\x13;jK\x99T\xd1irH\x93\xe7\xd3@)\x11\xc0\xe3\xbb_\xe0\xfa6e=\x88\x9a?U\xfb!\xf5H\xc7\xd1\x0fGErJ,\xc6\xf0\x13\x18\x82\x90J\x04y\x84\x8d\xe9\xd1\xf8\xbcS\xb2\xb4\x11\xa4\x1d\x04<\x98\xf5\xf1\xb8\xd7\x9b+\x0f\x0fy\x98\xcfjX\x84\xd7;\xfd\x82&\x0c\xce\x92\xf0d\x1d\xb67\'\x9by\x11rw\x11C>\x91\xb2#\xc9\xed\x87\x95\xdc\xed\x9d\xf2\x13%!e+\xb7\x87e\x1e\x9e\xe1\x84\xdf\x8a\x92\xc0oA\\S\xd9\x96\xfc\x87\xb7\x9b\xc8W\xb9"o\xe0\x98V:Q\x85\x865W\x84\xb0\xa7\xa5\xac\'\x9e/\xa53\xe1W~\xcc\x84n\x14\xd7y\x12D\x0e\x92\xf3\x91\xc1\xf6.c]#P\xa2\xb3\x1c\x9d\x91/\xeb\xbc\xb3\xe3V\xb2\xf8t1\xf0!P\xc7\xed\xb0N\xe8"\xa7,\x00"\r\x85\xd5B#\xa2\xe1c\n+m\xees\xb4\xe8\x14\xe5\xa4U(\xae6\x03\xda\xdek\x88\x8c\xd2\x00{\x99\x8c\xb4\x8d\xb0\xe2\x9a\'}\x1d\x85P\xa4%\x942\xa5\x81&\xf8\xef$\xe3\xa5\x99\xa5F\xbbC\xe0?g\xa0\xcf\x0c\xd5\x12H8\x16Z\x10\xae\xd5\xb5\x99\xc4c\x19-?\xf1@Q\x03\xf4\xf3\xb8F-\x99\x15|\xe2\xd8\xf3{\xaa\x86\xf705-\xf1c\xf0\xcf\xe6H\xf3\x0f\xfa\xcb\t\xce\xb6EA\xe7\xd9^\xb3\x19\xce\xbdV\xb4e\xf8V\xcf\xa1\xb5*\x0f6\x82\x96\'\xf5\xfe\xd0\x8b+t\xb0\xb1+P\xd7\x08\x9b\x94\xee\x05\xcee\xc5\x9c\xe0V\xb7\xf8k\xff\xc8\xb4Y\xd3\\G#\x81$y%\xc0\xb5\x81)\xe2\x1c\x85E\x01R\xec\xd8\xc6\xc4`\x85l\x19\xe8\xcf\xe7!\xa1\xde(X\xf6\xf3,\x8a4\xea\x98\xba\x9d\x10\x0b!7\nU\xf8D&\xc0\x1a\xc3\xf1\xd7\xab\x0c\xad\xbe\x816uH\xed\xf4>\x19m\x1cjw\x19\x91\xd6\xaa^\x0cy\xaf\x8a\x9f\x9b\xaf\x1e\xc1\xea\xf7\xcc^.\xdcX\x14\x1d\xbfH<\xc27~\x93i>\xf4s\xf2\x87\xb0B\'<\xf9\'\x12\xe63\xe1\xdfJ}\x85!\r\xe5\xd4\xfe\x81\x1e\xb8\x12\x80\xc6\x11\xa9\xad\xd8\t\xe3\x9f\xc0\xae*\xfe\xa0\x14\x12\x8f\x12\xaeI\x19\x9c\xcayB\xd1ls2\x16C\xe4\x16#\x18\xd9\x1b\xc5;\xf7/l\xc9\xb7L\xa1\xe6\xb9\x94gV2\x9c\x92\xd1\xd9V\xf0\xd7\x9eV\xac\xcbT\xfbU\xd0\x93\xda|\xde\xbb+]\xcbE\xea\xf2*\xc5\xde\xa7\xfel\xf8\xb850N\xc1P_\xdf\xd7|\xd4\xd2d\x176\xfe\xdb\xf7q&\xdc"e\xdaT\xc8\x07,\xdf\xab/Bk\xce\\\xcb\'\xf2U\xc3\xc7\xd7\xcfy\xf3\x0f\xe8\x87\xcc\xd3\x89\x14\x94\x87wE\x16\x03\xc8\xe4\xb8@\x9b\xca\xf5m\x12\xdd\xec)\x8f&?\xe7]H\xbb\x16e\xfc)\xc5\\\xf5(h\xe0\',\x91\x9d\x9f@&\xa3\x7fRD\xb0\x99?\x17\xf6x\x8d\x82\xd4tq\x06\xe4\xc6kh\x1a\xc2J\xa7\xeb\xb5u\xa7\\\xbcts\x04\xa7\x1f\x9b\xa9\x07\x0e\xc9\x9d\xcf\xde\x18`m\xbd[]q5\r+rS\x91M\x97\xb8"\xeeI\x0c\x1c\xcc\t\xb9\x9c\xba\x9a\x8f\xba\xd9)L\x80\xbf \xd0\xcf\x17\xe6_\x12<E \xe4\x11\x94P \xaaC\r\xa3\xdd\xf8\xeaA\xa3\xe2\x1f\xdd\x9b\x0c\x1e\xbdB\x04\xcef\xf6\xdd$\xf5}/A\x129\x88\x1d\xc40\x92\x82\xbf\x17\xd7"j\xe4\xefB\x11\xd2\xa7?\xdf\xd8\xdd\xc1[\xe9\x03\x0e\x7fw\xeb\xb6\r\xb8Y5\xcf4 I\xaf\xba\x03\xb6E\x89\xfee\x07\x85"\x9a\xa0\xd2.\xf1@\x9e\n\x86(\xfe0\x80\x0c\xad99\xc3k}\xb6\x8bN)\x8f\x95\xaa}\xe8\xa1X\\\x85\x94\x9f\x03.z\xba\xe2]\xa3\xc7\x96f\xdc\xc5\\\x8b\x02Q\x07\xf8m\x9d)\xd8\x93\xc3\xfe\x1c\xd3\xadtlIO\xad\x88i\xc7\xcb"\x98\x9f\xb3\xe6\xcd\x86\x85\x19\x02b\xfe;\xce\xb7\xa7\xe6KQ3\x8a\xee'
|
|
|
|
|
|
2024-12-14 18:09:33.199838 - Ether / IP / TCP 142.250.200.106:https > 192.168.1.11:40573 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 125
|
|
id = 34330
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xa448
|
|
src = 142.250.200.106
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40573
|
|
seq = 991722330
|
|
ack = 1063011440
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 763
|
|
chksum = 0xfd76
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00P\xca\xb8\xb4H@\xb0v\x7f6\xca\x97\x05c\xc8Sd\t\xa2x\xe6X-{\xc3~tpHL\x06?\x96\xf3\x88=\x9fU\xfa\xfbAr\x12#\xb9QczaS\xc4O\xc6\xab\xa5\x12\x7f\x94\xef\r\x0co!\xae\xa5\x01Rc\xe4\xcf$6?\x98\x05}\x0eOn\r\xcd'
|
|
|
|
|
|
2024-12-14 18:09:33.233477 - Ether / IP / TCP 192.168.1.11:40573 > 142.250.200.106:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 60854
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.200.106
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40573
|
|
dport = https
|
|
seq = 1063011440
|
|
ack = 991722415
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 508
|
|
chksum = 0x1956
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e2P\xdeG3\x8e&\x86\xa3\x89\xbd?\xaa\x1d\xf8\xcf\x83\x91\xc6\xad\xdc%\xed\xc5\x8c\xbd\x920\xe4\xbe'
|
|
|
|
|
|
2024-12-14 18:09:33.251468 - Ether / IP / TCP 192.168.1.11:40573 > 142.250.200.106:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 60855
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.200.106
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40573
|
|
dport = https
|
|
seq = 1063011475
|
|
ack = 991722415
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 508
|
|
chksum = 0x1956
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\x1f\xa1G\x9f\x14\xc0\xde\xce\x0f,jd\xd7\x8f5\n\xd79\xee\x06\xf0\xfd\x8b\xd3\x8d\xee\x15\xe1\xc1a'
|
|
|
|
|
|
2024-12-14 18:09:33.272087 - Ether / IP / TCP 142.250.200.106:https > 192.168.1.11:40573 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 34331
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xa49c
|
|
src = 142.250.200.106
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40573
|
|
seq = 991722415
|
|
ack = 1063011475
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 763
|
|
chksum = 0xb8cd
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x17\xb0\xe2o\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:33.279541 - Ether / IP / TCP 142.250.200.106:https > 192.168.1.11:40573 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 34332
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xa49b
|
|
src = 142.250.200.106
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40573
|
|
seq = 991722415
|
|
ack = 1063011510
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 763
|
|
chksum = 0xb8aa
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x95\x89\xce;\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:34.096106 - Ether / IP / TCP 192.168.1.11:40788 > 35.186.224.41:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 7262
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40788
|
|
dport = https
|
|
seq = 948629424
|
|
ack = 1994418507
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xc5cd
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x17\xe8\x92DH\xeb\x81\xe6NHv\xeb{k+\xe7\xa9\xa5\xe7\xa7\x98\xfaU\xb2'
|
|
|
|
|
|
2024-12-14 18:09:34.119812 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:40788 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 49490
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xbde6
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40788
|
|
seq = 1994418507
|
|
ack = 948629452
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1051
|
|
chksum = 0x3c90
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:35.065452 - Ether / IP / TCP 192.168.1.11:40790 > 35.186.224.41:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 83
|
|
id = 7263
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40790
|
|
dport = https
|
|
seq = 3089470489
|
|
ack = 915346319
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xc5dc
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00&R(zCe\xbfd\xef\xa5#T\xa5\xd36\xdd\xfb\x85\x90U8\xe7R\xb9\t\xee\x19-<OP\xd9\xf1\xbd4\xc1\xc6\x16\xe6'
|
|
|
|
|
|
2024-12-14 18:09:35.093122 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:40790 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 14744
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x44a1
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40790
|
|
seq = 915346319
|
|
ack = 3089470532
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1043
|
|
chksum = 0xae90
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\xb3`\x07\xa4\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:35.117425 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:40790 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 80
|
|
id = 14745
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x4478
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40790
|
|
seq = 915346319
|
|
ack = 3089470532
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1043
|
|
chksum = 0x40b3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00#\x87\x93JRv^\x8e\xb41\xea\x016\xffZ\xf7X\xb9\xe1\x92n\xd85\x97\xd8\xad\x89\xb7Z\xcc]e\xc2a\xff\xf4'
|
|
|
|
|
|
2024-12-14 18:09:35.171198 - Ether / IP / TCP 192.168.1.11:40790 > 35.186.224.41:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 7264
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40790
|
|
dport = https
|
|
seq = 3089470532
|
|
ack = 915346359
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xc5b1
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:35.441160 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39450 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 45869
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xdaae
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39450
|
|
seq = 3412686445
|
|
ack = 1692641522
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x4a89
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xd4\xc8\xba\'\xc6\xfc\nK\x92\x1a\xb9G\xa2\x0f\x17\xa8\x9f\x10\xfd\xb05\xc6gba)\x84%\x87\xeaQ\xb5\xceI\xa6\xd1\x1f\xe9\xcd\tIC\x8a~*\x8c\x8a\xdd\xc9\xc0-\xfc\xd91{\xfc>\x82\xc7&\xa8\xac\x96\xcd\xeef.%\x9at\xf3*~5\xd4\xdd6\x97d\xb2\xde\x9fr\rtm\xc7]"\xc9\xceuS\x0e2w\xed\xb4\xc1\x9b\xab\xa8!\x9ba\xc0\x8bl\xads\x1f\xcagZ\xd7\xacR\xda\xa3\xad\x99:\x18N\xdd\xf5\x95\xa4\x94~\x80\xc98\x03\xac\x13@\x86Uyl\x1a\x88*L\xaa\xdc\x86_-7>M\x1eZI\x8c\x18=\x1bv\xc8\xfa\xb6%v\xdbL\xc9:R\xb1ipr\'\xb1\x0c\x9e*\xb4\xa7\x7f\xc8\xec\x91\xbc\xc5\xaf\xcc\xc4\xa2z\xed\x0e\xab\x16\xed\xb7\xb2\xc8\xf2\xf6\xff\xcb?#x\xac\xcdP\x1fW'
|
|
|
|
|
|
2024-12-14 18:09:35.484163 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39491 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 257
|
|
id = 49959
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcab4
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39491
|
|
seq = 2030904087
|
|
ack = 17611432
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1517
|
|
chksum = 0xda68
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00\xd4C\x91F\xfe\x85\x85s\x91U\xa8\xfd\xf6T\x81\xe0a\x92\x0f_\xc7\xaf\x81G\xc2\x8b;\tD\x18\xb5\xb3\xce\x02C|\x93V\xf9\xf42BF\xa5J\x98\x95T\xab\xd5\x8fu\xdbs\xbb\x19\x7f\xb3\x98N\xdc\xe7\x15\xd0\x96\xb2\x15V\xaek$\x03w\xfd\x8a\xc7rb+\x834J\x98,\x7fF\x91\x89%\xf0\xfd\xb4\xd6\xb0c\x8dK\x81P0\x0c\x1e\xd1\xaeA1,\xcfO\x80t\xcd\x1c\xe7\xb0\xa1\x07[\x05\xa3\xf9\x047\xb3\xa1\xdc\x8a\x05\t#iXE\xe1i\xa3\xfeF\xe6\xe9p0\xfb\x08>\x88X\x13\xa3\xd8\xba\x9e\x00\xb5\xc6\x0b\xafBX\x96,vK8\xc3{\x00\x080\xe4U\xd3\x85K\xac\xeeD\x96E\xc2\xe2}\x08\xb4c\xad\xff\x10\xc7\xc9\xf8\xa9\x8c\xec\x11\x15\xe4\xbf\xfd\x0c\xdb\xd4\x9f\xc1nd\x1d\xc2@;*'u"
|
|
|
|
|
|
2024-12-14 18:09:35.528739 - Ether / IP / TCP 192.168.1.11:39450 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 17018
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39450
|
|
dport = https
|
|
seq = 1692641522
|
|
ack = 3412686662
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 2069
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:35.552502 - Ether / IP / TCP 192.168.1.11:39491 > 52.84.66.19:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 17019
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39491
|
|
dport = https
|
|
seq = 17611432
|
|
ack = 2030904304
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4139
|
|
chksum = 0x3835
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:35.570380 - Ether / IP / UDP / mDNS Qry b'_adb._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 2c:93:fb:9c:dc:c0
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 154
|
|
id = 3616
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0xca73
|
|
src = 192.168.1.27
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 134
|
|
chksum = 0x4338
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 2
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_adb._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_amzn-wplay._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'_amzn-wplay._tcp.local.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:09:35.965334 - Ether / IP / UDP / mDNS Ans 192.168.1.62
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 350
|
|
id = 7520
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = udp
|
|
chksum = 0xb84d
|
|
src = 192.168.1.62
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 330
|
|
chksum = 0x26d6
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 0
|
|
ancount = 3
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'192-168-1-62.local.'
|
|
| type = A
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3599
|
|
| rdlen = None
|
|
| rdata = 192.168.1.62
|
|
|###[ DNS SRV Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
| type = SRV
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| priority = 0
|
|
| weight = 0
|
|
| port = 35948
|
|
| target = b'192-168-1-62.local.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:990237._amzn-wplay._tcp.local.'
|
|
| type = TXT
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3600
|
|
| rdlen = None
|
|
| rdata = [b'a=0', b'c=36:af:b3:ac:fc:17', b'ad=A31DTMEEVDDOIV', b'pv=1', b'f=0', b'mv=2', b'dpv=1', b'n=FireTVStick de fabiola', b'at=TyK0zfSnV9zr', b's=0', b't=2', b'u=77A58D33A6B0B8794D57457DEBC2CE4D', b'v=2', b'sp=36805', b'tr=tcp']
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 18:09:37.076350 - Ether / IP / TCP 192.168.1.11:40564 > 142.250.201.67:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 136
|
|
id = 12425
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.67
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40564
|
|
dport = https
|
|
seq = 769059478
|
|
ack = 668934003
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0x1a6c
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00[8\xb3\xb3<\x9c\x8fq0\xb8\x8esa\x83\xbe\xbe\x05@\xf4\xbf\xc7N\x05\xe48\xe8)\xda\xac\xc5.\x8f\x88X\xbb\xfaZ\x99\xdf\xd4@\xb3q\x00\xd4\xe4\x9d\xb6\xc8!f\x98\xbd1c\xbe\xfe\xd0p9a\t\xce\xd8\x82\x0b\x14+"a4f/\x10\xa2Q\x02l\xcf\x8bE\x97\x85\xfb\xa9\x13\x08@\x88\xb1\x81\x02'
|
|
|
|
|
|
2024-12-14 18:09:37.085387 - Ether / IP / TCP 192.168.1.11:40564 > 142.250.201.67:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 12426
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.67
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40564
|
|
dport = https
|
|
seq = 769059574
|
|
ack = 668934003
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0x1a33
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"e\xcb\x16=B\x17\x9e\xc6\xe5\n\xf6\xd3\xc4!\xf20\t>\x18K\x96\x1bN9gk\x98j|\x82\'\x99>\x1f'
|
|
|
|
|
|
2024-12-14 18:09:37.095774 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40564 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 20175
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xdc0f
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40564
|
|
seq = 668934003
|
|
ack = 769059613
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1042
|
|
chksum = 0x915b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x0fs\x9fR\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:37.106889 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40564 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 20176
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xdbe7
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40564
|
|
seq = 668934003
|
|
ack = 769059613
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1042
|
|
chksum = 0x749e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"^\xd9\xd1\x05:\xce\xf9q\xca\xc1\xe3\x14=\xea\x859\xc4\xc6\xb6\xc82r\xaf\xffI~\xad\xaa/\xe9\xfbk5G'
|
|
|
|
|
|
2024-12-14 18:09:37.124800 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40564 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 136
|
|
id = 20177
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xdbad
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40564
|
|
seq = 668934042
|
|
ack = 769059613
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1042
|
|
chksum = 0x2e56
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00[\xdb(\x07\x90\x10\xf6\xc6\xd6?\x94\x85\xc2\xd3\x84\xc5\x1e\xd3_\xd4\xeeB\x11S\x04\xfa]\xac|\x8c\xb8\x96bg\x1b\x87\x88n\xfd\xf7.\x97\x8ee\x00\x1du\xad\xf2\x9a\xdb\xb6/\xa9~s\xbdf\x8f\x8a\n\x95#_\x8b:\x0f\xa6\tM\xaaj\r\xa4\xe4\xb1\xa3C4\xfb\xb4\x08\xe6\xd3H\x0e\x95\n\xa5\x9f\x10!'
|
|
|
|
|
|
2024-12-14 18:09:37.131777 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40564 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 131
|
|
id = 20178
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xdbb1
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40564
|
|
seq = 668934138
|
|
ack = 769059613
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1042
|
|
chksum = 0x4c7a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00V\xef\xabVj0C\xf4\xa8\r\xd0\x9bA\xc9\xe2Pos6\x9a\x98-a\xcaf\x18&\x05\xda\xaeC\x18\xd1\x07\xec\xeb9\x0ce\x00\xa9\x9fa\xcb\n\xd5\x8e&\t\x14\xb5[\xfe\x84C0Z\x02q9\xf6x\xc9y\xbb\xf3\x88\xf3"Q\xd2"@uRU\xf8<2\xd8\x1aI)\x82p\x1a\\'
|
|
|
|
|
|
2024-12-14 18:09:37.137425 - Ether / IP / TCP 192.168.1.11:40564 > 142.250.201.67:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 12427
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.67
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40564
|
|
dport = https
|
|
seq = 769059613
|
|
ack = 668934138
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x1a0c
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:37.148142 - Ether / IP / TCP 192.168.1.11:40564 > 142.250.201.67:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 12428
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.67
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40564
|
|
dport = https
|
|
seq = 769059613
|
|
ack = 668934229
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 511
|
|
chksum = 0x1a2f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\x13\x15\x9e\xac=B\x9d\x18\x1c\xa9\x91\x8d\x80&\xddg\x02\xbe\xc1J\x9f\x83h\xe0[\x10\xd1\xcf\x94\x08'
|
|
|
|
|
|
2024-12-14 18:09:37.154584 - Ether / IP / TCP 192.168.1.11:40564 > 142.250.201.67:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 12429
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.67
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40564
|
|
dport = https
|
|
seq = 769059648
|
|
ack = 668934229
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 511
|
|
chksum = 0x1a33
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\x837\xea\xe1\xa4i\xcfk\xf9\x11\x0c%\xceW\xa6\x8c\xea\xe6\xaaZ\x8f\x9f\xcd\x8dT,\xc5G\x15\x9f\x1bSb\xc3'
|
|
|
|
|
|
2024-12-14 18:09:37.161511 - Ether / IP / TCP 142.250.201.67:https > 192.168.1.11:40564 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 20179
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xdc0b
|
|
src = 142.250.201.67
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40564
|
|
seq = 668934229
|
|
ack = 769059687
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1042
|
|
chksum = 0x902f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'9\xdc\xa4\x8c\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:37.207042 - Ether / IP / TCP 192.168.1.11:40570 > 142.250.200.106:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 60856
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.200.106
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40570
|
|
dport = https
|
|
seq = 1307136675
|
|
ack = 3946163776
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 507
|
|
chksum = 0x1934
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:09:37.245521 - Ether / IP / TCP 142.250.200.106:https > 192.168.1.11:40570 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 14857
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xf1a2
|
|
src = 142.250.200.106
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40570
|
|
seq = 3946163776
|
|
ack = 1307136676
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1044
|
|
chksum = 0x413d
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (1307136675, 1307136676))]
|
|
|
|
|
|
2024-12-14 18:09:37.500745 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 116
|
|
id = 672
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x54a7
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414067736
|
|
ack = 3211593233
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xee51
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00GQ\xd1\x91\x7fD\xc6\x13\xab\xd9p\xa2g\x8f\xc3\xa2\xa3\xccJY%\x0f\x10Tm\x97\xa5q\xd9\xad0\xea.V)\xa3mFSp\xe2\x04\x12D\r\xfdF\xa7\x92\x17\xf42:\xe2\nWoROS\xed\xf0\x06\xe3d\rBk\xeb!\xb9\x94'
|
|
|
|
|
|
2024-12-14 18:09:37.507528 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 102
|
|
id = 673
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x54b4
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414067812
|
|
ack = 3211593233
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xb6d5
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x009\x08x\xf8\xf8\x99\xa6j\xfa\xda\x13Ms%C\xe0\t\x81\xd8\xfe\x11\xcc\xa9.vV\x17v\xe0\xf7\xe0\xd8\x96P\xc6\xd6\n?\xc5\xf2\xf3k\x188\xab6PZ\xc0$\xdf\xd8s\x87\x99+e\x92'
|
|
|
|
|
|
2024-12-14 18:09:37.523142 - Ether / IP / TCP 192.168.1.11:39688 > 162.159.136.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3274
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.136.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39688
|
|
dport = https
|
|
seq = 3211593233
|
|
ack = 414067874
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xed57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:38.013097 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 207
|
|
id = 44116
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x9378
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359257249
|
|
ack = 158962679
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4491
|
|
chksum = 0x8e96
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xa2\x8cO9\x86\xb8ye^\x85\xed\xb6\xcd\xa2\x19\x0c;\xf1\xf5f\x86\x87\xaa\xa1nX\xccx\x05\xe0\xb2\x12\x0bhT\x1b\x89\xeb\xc5\xc1\xe9\xa4\xf9\x94*\x1cc\xaf\x1f\x01v\xa7\xec\x17\x15\xa59>\\\x99\x81m\xef\xe7\xe1_%\x9dq>\xd4G=}H\xbe$\x98a\xc6\xdc\xb5tv\xe1\xf6\xb7\x8f^\x162a\x0e\x8f\xf5\xa5\xb7<\xb9\xb7e\xafN0\x1a\x02\x12\x10\xb9\xa9M\xe2`ZA|\twB:\x87w\xbeF\x06p\xb6\xeaZ\xb2\x16&\x8c\xe6\xf9\xd50\x9f\x8b \xe1\xea#\xb5\xc3\x1d\x1c\xf0\xff\x1b7\xa6\x9b,\xa0\x87!\x87jJ9r\x8e'
|
|
|
|
|
|
2024-12-14 18:09:38.025648 - Ether / IP / TCP 204.79.197.239:https > 192.168.1.11:40987 RA / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 4652
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x9eb1
|
|
src = 204.79.197.239
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40987
|
|
seq = 2317587216
|
|
ack = 3107864498
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = RA
|
|
window = 0
|
|
chksum = 0xa3e2
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:38.034997 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 62269
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158962679
|
|
ack = 3359257416
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4102
|
|
chksum = 0x39a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xa6\x86=x\x93\xc2\x89&\xf8\xa3\x05O\xc7\xbc\xe9\x15%Vq\x9d\xcaFO\xd8\x95.\xff_\xbe\x8d'
|
|
|
|
|
|
2024-12-14 18:09:38.042436 - Ether / IP / TCP 192.168.1.11:40562 > 142.250.178.174:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 62270
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.178.174
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40562
|
|
dport = https
|
|
seq = 158962714
|
|
ack = 3359257416
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 4102
|
|
chksum = 0x39a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xbcAR:\xf8D\x9f\x88\x14\xbf\x15\x0b^\xfa\x90\xa2\x8e4n\xf2\x11\xddH\x87pY\x1fp\xd5\xce'
|
|
|
|
|
|
2024-12-14 18:09:38.049883 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 44117
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x941e
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359257416
|
|
ack = 158962714
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4491
|
|
chksum = 0x61a9
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:38.054999 - Ether / IP / TCP 142.250.178.174:https > 192.168.1.11:40562 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 44118
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x941d
|
|
src = 142.250.178.174
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40562
|
|
seq = 3359257416
|
|
ack = 158962749
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 4491
|
|
chksum = 0x6186
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 18:09:38.438565 - Ether / IP / UDP 192.168.1.11:64580 > 142.250.184.10:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 57
|
|
id = 54382
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.10
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64580
|
|
dport = https
|
|
len = 37
|
|
chksum = 0x8ef
|
|
###[ Raw ]###
|
|
load = b'C\xf3wB\xde\xaf\xa6\xa7\xe0G\xa4\x15\x91\xe5\xd6\xd5\xe1\x86\xafTA\x9ep()\x00\xddS\x03'
|
|
|
|
|
|
2024-12-14 18:09:38.468215 - Ether / IP / UDP 142.250.184.10:https > 192.168.1.11:64580 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x3b00
|
|
src = 142.250.184.10
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 64580
|
|
len = 33
|
|
chksum = 0x54e
|
|
###[ Raw ]###
|
|
load = b'BM\x95x\xc85\xfc\x80\x7f\xd5\x06\x00\x88\x19\x96\x94r\xbc\x8a+N\xf2\xa7\xca\xbf'
|
|
|
|
|
|
2024-12-14 18:09:39.864284 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 148
|
|
id = 674
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x5485
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414067874
|
|
ack = 3211593233
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x3717
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00gF\x0b\xfc\xf10\x02i<\xc8$\xd4c\x85\x84\xca\xf3|\xf3Y\x83\xdf\xdb\x88\xea\x92>j\xf6\xf7\xfdy\x16VA\x9f8\xc6\x1cT\xed\x92t\x13\xf3\xe8\x95M0}\x17\xca\x89/\xa4w\xd2Z\xb5\xad{Q\x7fpN\xe0\xcd\x98\xd4a9=\xdd\x0c\xe8\xc3\x96\xc0\xcae{J2+6\x17S\xbb\xd1\x16\xaeKK18\x8b\x93\xf6\x8a\x1aQw)S'
|
|
|
|
|
|
2024-12-14 18:09:39.909537 - Ether / IP / TCP 192.168.1.11:39688 > 162.159.136.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3275
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.136.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39688
|
|
dport = https
|
|
seq = 3211593233
|
|
ack = 414067982
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xed57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 18:09:41.265288 - Ether / IP / TCP 192.168.1.11:39454 > 52.84.66.19:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 17020
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39454
|
|
dport = https
|
|
seq = 20247691
|
|
ack = 1095416865
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x3836
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:09:41.282819 - Ether / IP / TCP 192.168.1.11:39492 > 52.84.66.19:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 17021
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.84.66.19
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39492
|
|
dport = https
|
|
seq = 394883023
|
|
ack = 3877225058
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 516
|
|
chksum = 0x3836
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:09:41.302370 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39454 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 49899
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0xcbbd
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39454
|
|
seq = 1095416865
|
|
ack = 20247692
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 149
|
|
chksum = 0xc686
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (20247691, 20247692))]
|
|
|
|
|
|
2024-12-14 18:09:41.307414 - Ether / IP / TCP 52.84.66.19:https > 192.168.1.11:39492 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 7667
|
|
flags =
|
|
frag = 0
|
|
ttl = 244
|
|
proto = tcp
|
|
chksum = 0x70b6
|
|
src = 52.84.66.19
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39492
|
|
seq = 3877225058
|
|
ack = 394883024
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 149
|
|
chksum = 0x6586
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (394883023, 394883024))]
|
|
|
|
|
|
2024-12-14 18:09:47.240404 - Ether / IP / TCP 192.168.1.11:40908 > 172.64.155.209:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 44937
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 172.64.155.209
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40908
|
|
dport = https
|
|
seq = 1626614240
|
|
ack = 1229880709
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 510
|
|
chksum = 0x9e1
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 18:09:47.295952 - Ether / IP / TCP 172.64.155.209:https > 192.168.1.11:40908 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 33286
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xb8f8
|
|
src = 172.64.155.209
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40908
|
|
seq = 1229880709
|
|
ack = 1626614241
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 30
|
|
chksum = 0x66ff
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (1626614240, 1626614241))]
|
|
|
|
|
|
2024-12-14 18:09:47.536262 - Ether / IP / TCP 162.159.136.234:https > 192.168.1.11:39688 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 145
|
|
id = 676
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x5486
|
|
src = 162.159.136.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 39688
|
|
seq = 414068098
|
|
ack = 3211593233
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xc14f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00d#8ib\xfc\x8a\xc8\xaa\xf4J;\x13\xc2\r\x19=\xad\x90\xc4\x1dh \x0b\xd6\xc6\x93k\x8b\xf8iI!3\xeb\xe4\xc9\xb9\x0b\xae\r\x16\x88\xb2\t\xb5\xcf\xed\xd3\x99\x1e-,\x0b\xca\x83\\\n\xc4\xdb\x16_~\x81\xb7\xec\x04\xa3@t\xb3\xd2!@!|\xd7\x1e(\xd1\xc5\xc7\xae\x84Z\xe7\x07\xe0h=\xe3\xa4\x00OoJ\xfar\x04\x15\xbe'
|
|
|
|
|
|
2024-12-14 18:09:47.584115 - Ether / IP / TCP 192.168.1.11:39688 > 162.159.136.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 3277
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.136.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 39688
|
|
dport = https
|
|
seq = 3211593233
|
|
ack = 414068203
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 514
|
|
chksum = 0xed57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:34:56.452493 - Ether / IP / TCP 192.168.1.11:42733 > 151.101.135.42:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 18202
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 151.101.135.42
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42733
|
|
dport = https
|
|
seq = 2796051337
|
|
ack = 1613279978
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 507
|
|
chksum = 0xe05e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:34:56.470253 - Ether / IP / TCP 151.101.135.42:https > 192.168.1.11:42733 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 22165
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = tcp
|
|
chksum = 0xcec
|
|
src = 151.101.135.42
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42733
|
|
seq = 1613279978
|
|
ack = 2796051338
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 306
|
|
chksum = 0xd5f4
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (2796051337, 2796051338))]
|
|
|
|
|
|
2024-12-14 20:34:56.498713 - Ether / IP / UDP / mDNS Qry b'_233637DE._sub._googlecast._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 86:1e:7e:31:2b:c4
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 89
|
|
id = 52922
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0xa06
|
|
src = 192.168.1.47
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 69
|
|
chksum = 0x3293
|
|
###[ DNS ]###
|
|
id = 6
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 2
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_233637DE._sub._googlecast._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_googlecast._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:34:58.137226 - Ether / IP / TCP 188.114.96.5:https > 192.168.1.11:42259 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 84
|
|
id = 43050
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xbe4e
|
|
src = 188.114.96.5
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42259
|
|
seq = 2693639149
|
|
ack = 4062860535
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 9
|
|
chksum = 0xb7b0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00'n\xd7)\xe5\xf4\x05(\xee\xf4\xd2\xd2-\x9cH3Hg:\x00)\x98\x04\xfdh_Y\x04$/\xa7v\xed\xed\xa7\xd1\xd6#\xfa\x16"
|
|
|
|
|
|
2024-12-14 20:34:58.148264 - Ether / IP / TCP 192.168.1.11:42259 > 188.114.96.5:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 49546
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 188.114.96.5
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42259
|
|
dport = https
|
|
seq = 4062860535
|
|
ack = 2693639193
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xde68
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xc8|^ \xa0qs\x84{EQ\xfe\x82U\xd2\xb9\xb5z\xa1\xd2\x9c\xa0dl%&\x15\xe2\xc1\xbf'
|
|
|
|
|
|
2024-12-14 20:34:58.150744 - Ether / IP / TCP 192.168.1.11:42259 > 188.114.96.5:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 49547
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 188.114.96.5
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42259
|
|
dport = https
|
|
seq = 4062860570
|
|
ack = 2693639193
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xde68
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e-\xf9ZN\x88 \xcca\x89\xad\x1e\x89E\xc1c\xff\x01\xb9\x12\x90]Il\x8a4[\x06_#P'
|
|
|
|
|
|
2024-12-14 20:34:58.175100 - Ether / IP / TCP 188.114.96.5:https > 192.168.1.11:42259 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43051
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xbe79
|
|
src = 188.114.96.5
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42259
|
|
seq = 2693639193
|
|
ack = 4062860570
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 9
|
|
chksum = 0x96e5
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\xf2\xffM\xf3'
|
|
|
|
|
|
2024-12-14 20:34:58.177529 - Ether / IP / TCP 188.114.96.5:https > 192.168.1.11:42259 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43052
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xbe78
|
|
src = 188.114.96.5
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42259
|
|
seq = 2693639193
|
|
ack = 4062860605
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 9
|
|
chksum = 0x96c2
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\xa7YK\t'
|
|
|
|
|
|
2024-12-14 20:34:58.928822 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 108
|
|
id = 26759
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf1c7
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995229985
|
|
ack = 212489189
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xb1ea
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00?\xf8tQ2\xd1\x17f\x86\x99Ov\xbdU\xber\xe3`\x12~\xa9\xd3\x807=\xed\x0f\x1d\xd1\xc1\xc2\x86\xce\x03\x1by\x86\x02\x15\xe2\x81K\x12C\x1dJ\xd3\x03^Y2d >\x1a\xb9\xe8\xe7\x06\xa5OYNp'
|
|
|
|
|
|
2024-12-14 20:34:58.932866 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 99
|
|
id = 26760
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf1cf
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995230053
|
|
ack = 212489189
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xa150
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x006D\xf0SjP\x0f\x1d\xf8\xaa\xa2$\xa2\x88\x97\xd7k\xd4\xd4\x91\xd7YZ\x9a\xc6\xb0\x1c\xbbD\x8c\x99;\xdc`\xe9Yu\xef\x99+\xb9\xbdZ\xf5\xc4\xf8\x1d\xe4\xf4\x94\x01\xe8\xdc\x97|'
|
|
|
|
|
|
2024-12-14 20:34:59.019913 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 37100
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489189
|
|
ack = 995230112
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0xea57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:34:59.022196 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 81
|
|
id = 26761
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf1e0
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995230112
|
|
ack = 212489189
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xaea1
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00$|r\xddb\x8c\xfc7\x1a\x9c6\xbdF\xc8\xdc\xe53\xbb"h-\x1c65\x7fqm\xe0\x01\xee\x06h\xb2\xad\x0f\xd4\xda'
|
|
|
|
|
|
2024-12-14 20:34:59.023750 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 37101
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489189
|
|
ack = 995230153
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0xea57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:01.424738 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 941
|
|
id = 26762
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xee83
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995230153
|
|
ack = 212489189
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xb72a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x03\x80\xed\x91\x1f\xa9D\xbb\x7f1\x8a0\xa0"\xc0s0\xf8\xce+\xc7\x911\xa1\xd9\x97\xea\xa9=\xc3\x98\xe0\x06\'l\x8b\xf8\x0e\xc2\x1b\xd0\xbf<\x1f\x10\x8d|\xb7\x19\xba\xa9\xa6Ah\xe3\xd2\x9e\xf0\x9f2Hioj\x9czy\x8fF\xa4\xc9M\x05\'\\DV\xac\x91E\x84r\xf5\xc0\x8c\xc4]\x1e4C_\x85\xb4\xf6\x1b\xe6}\xfe\xe9\xbc\xe4\x11q\xd4e\xb6*`h\xe7\xe4(VjN\x84\x9e\xb7V \x97L\x03\x83\xf4\xff\\\xb3\x1c\x14\xa4\t$\xdb|\xb0\x04\xa6\x8f\x9d\x02\x8b\x13c\xc25\xb6e\x9e\xca:\x00m%\xaf-]A\xa9\xdd\xa8\xf7\xf6\xb6\xe8,`\xe63\xf45\xdc\xf6R\xb0\xa9\x9c!\xd6!#\x19\x80y\x03F\x04\x81\xa3\xd2Hs^\x8c\x03\x9e\xa1:A\x07\xe0w\x0fw\xb4\xecR\xd2\xc4`so\xf5T+p\x04\x0f,\x1a\x13\xdd\xc5\x1eb\x9e\x1c^~0\xe9\xf7\xb7\x1aU|\x08\x16\xb1\x15NL\x8d9Ivo\xf4a\xb8Hk\xeb\x90\xae\xff\xcae\t\x8b}\xee\x0b\x1b\xf5\x0b\xd36\xfc\x80\xf29@\xb2\xee\x02\xf1\x1cw\xad)\x0b\x97\xdc\xf3o\xb3\xaa\xd7\x8a\xa6\xd40\x1ed\xa1d\xd4\xeb)x8]4tn\xfc\x96\xfb\xdf\x847f-\x91\x81W\x05\xf7\xe1\xdf\xd6X]\x9ce\xa6\\\xff_\x1b\x9a\xbd\xea%d<\xb8\x1e\xc0\x03\x80\x91\xa0yS\xbfWx\x86\x1f\x81\xf63\xac\x19^\xf1\xa6\x1az\xcd\x88\xe7\xa6C\t\xad\xc0\xa1\xca|\xeempL\xd4\xccr\x8c#U>\xcf\x97\xbf\xdaj\\\x185_\xbdF\x89t8o~Y\x84\xd6\x9eF\xc5<q\xc4\x17\x97\x8c\n\x9f\xb1\x90\xf6\xde\xe6h\xd7\xb3S\x80\xde\x08\x19A\x7fcU\xa9BU\x1b\xcb\xe0"\x08\x17\xc7\xfe\x12\x87E\xa7r\x85\xb9x\x17\xb5r\xa2\x1e\x8e\xba\xf2.\x16\xf34\xads\xc97\xa9\xcceK\\Mw\x9c{`\xc7\xbb\x98\xabB=\xe9\x11\x91\x0f\n\x8d\xf3\xcf>*GH%C7R\xacq\xb1\n\x8e\x02_\xcc\xa9\xa37\xd1\x8b\x1499\xa6\xa6=\x08!\xc7j+[[Q9@\xf1\xd7\xaa\x9b_/\x90{\x1e\xadg\xf1\x18^\xa3lyO)\x1d\xd1RS+\xa1\x0f\x07\xe6\xed\xc9\xc1\xc0d\xfe\xbf\x94\x18B\x1avIv\xca\x93Ok\xa4\x0b\xed`\x19$\xea\x1b"?\x9a%Q\x9c\x90\xe1Ru\xd4\xfew\xd3C\xa9=\xc9\x01\x16\xbb\xe9bN\xf4v\x1bB\xa2\x13HQv\x01\x02s\xa3\x15bB\x8f>\x8c%\x97\n)$\xbc\x07&KeE\xfb\x04+\xd0zT\x18\xd7\x8c\xd7\xb3\x1f\xb0e\xdb\x13\xa6mJ\x08:VN{]\x97#\x14\x16j\xf0Z]\xcd\xd2\x95"(\xe0%:\xd8\xde*\xba\r\xf4\xeb\x9b\x0b\xf4\xbdA\x00j\'\xd5\x95O\x97O\x11\xf6cs\xe3\xdaJ\x1fP\x8d\x04Q\xc1HE\xa1\x01\xcd"\xc4\x96PY\xb1`\xb0\xd2\xd1\xff\xf6\x0c\xe7_\x06\xa1\x83\x9a\x081z\xca\x9c\\\xe3\x836\xa3\xf8\\\xc0\xfc\xe3\x82/\x9d\xd5\xe1rh\xd1\x10\xe7\xcbIw\xbe\xf0i=$\x82\xce\xae\x1e\xe8\xcf\xf9\xb1\xa6\xef\xbf\xbf\xc0\xbd\xc1\xc2 \xff\xc0\x87\xc5\r\x86\x01\xb6\xcc\xd6\xdc\xc7\xb0W&\xad\xc7\x1dR\xdb\xd9\xacj\xfd&.\xc3O\'\xb7\xda\x1a]\x8b\xe0&:\x7f\xaez\x0e{> \xadV\xa6(5\xea\x1aF\x88\xf4\x9f\xdbt\xe7\x0f\x85\xaf.\x15\x0c\xce[\xac\xfaCq5YH\xbd\xccR\xe0\xdc\xda\xb6#\x086J\xac\xbeCN\xc3\xd5\x19\x9d\xe4\xc0\xd3B\xd9\xe6\xd7\x88\xab\xec\x07\x05\xac\x19Tex:t\xc8z\x11\xc2\x01'
|
|
|
|
|
|
2024-12-14 20:35:01.611792 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 37102
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489189
|
|
ack = 995231054
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 514
|
|
chksum = 0xea57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:03.775055 - Ether / 192.168.1.1 > 224.0.0.1 2 / Raw / Padding
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:01
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 6
|
|
tos = 0x80
|
|
len = 32
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = 2
|
|
chksum = 0x42ad
|
|
src = 192.168.1.1
|
|
dst = 224.0.0.1
|
|
\options \
|
|
|###[ IP Option Router Alert ]###
|
|
| copy_flag = 1
|
|
| optclass = control
|
|
| option = router_alert
|
|
| length = 4
|
|
| alert = router_shall_examine_packet
|
|
###[ Raw ]###
|
|
load = b'\x11d\xee\x9b\x00\x00\x00\x00'
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:03.921634 - Ether / 192.168.1.11 > 224.0.0.251 2 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 6
|
|
tos = 0x0
|
|
len = 32
|
|
id = 41287
|
|
flags =
|
|
frag = 0
|
|
ttl = 1
|
|
proto = 2
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 224.0.0.251
|
|
\options \
|
|
|###[ IP Option Router Alert ]###
|
|
| copy_flag = 1
|
|
| optclass = control
|
|
| option = router_alert
|
|
| length = 4
|
|
| alert = router_shall_examine_packet
|
|
###[ Raw ]###
|
|
load = b'\x16\x00\t\x04\xe0\x00\x00\xfb'
|
|
|
|
|
|
2024-12-14 20:35:05.547177 - Ether / IP / UDP / mDNS Qry b'_spotify-connect._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 73
|
|
id = 41288
|
|
flags =
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 53
|
|
chksum = 0xbc4
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_spotify-connect._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.265622 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34184
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58348
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 60017
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.268283 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34185
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58349
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 60018
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.270425 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34186
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58348
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 60019
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.271999 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34187
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58349
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 60020
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.273862 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34188
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58348
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 60021
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.276847 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58348
|
|
len = 76
|
|
chksum = 0x67a7
|
|
###[ DNS ]###
|
|
id = 60017
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.279148 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58349
|
|
len = 89
|
|
chksum = 0xfa1e
|
|
###[ DNS ]###
|
|
id = 60018
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.281417 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58348
|
|
len = 90
|
|
chksum = 0x6044
|
|
###[ DNS ]###
|
|
id = 60019
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.283508 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58348
|
|
len = 81
|
|
chksum = 0x1b97
|
|
###[ DNS ]###
|
|
id = 60021
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.285431 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58349
|
|
len = 51
|
|
chksum = 0xae4e
|
|
###[ DNS ]###
|
|
id = 60020
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.294141 - Ether / 192.168.1.62 > 239.255.255.250 2 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 6
|
|
tos = 0xc0
|
|
len = 32
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = 2
|
|
chksum = 0x3237
|
|
src = 192.168.1.62
|
|
dst = 239.255.255.250
|
|
\options \
|
|
|###[ IP Option Router Alert ]###
|
|
| copy_flag = 1
|
|
| optclass = control
|
|
| option = router_alert
|
|
| length = 4
|
|
| alert = router_shall_examine_packet
|
|
###[ Raw ]###
|
|
load = b'\x16\x00\xfa\x04\xef\xff\xff\xfa'
|
|
|
|
|
|
2024-12-14 20:35:06.307304 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34189
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58350
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 60022
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.310229 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58350
|
|
len = 81
|
|
chksum = 0x357e
|
|
###[ DNS ]###
|
|
id = 60022
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:06.337452 - Ether / IP / TCP 192.168.1.11:42720 > 35.186.224.24:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 35859
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42720
|
|
dport = https
|
|
seq = 516658157
|
|
ack = 1765306794
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xc5a1
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:06.350797 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:42720 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 6672
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x652e
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42720
|
|
seq = 1765306794
|
|
ack = 516658158
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1046
|
|
chksum = 0x1477
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (516658157, 516658158))]
|
|
|
|
|
|
2024-12-14 20:35:06.816937 - Ether / IP / TCP 192.168.1.11:40768 > 104.199.65.9:4070 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x98
|
|
len = 51
|
|
id = 2864
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 104.199.65.9
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40768
|
|
dport = 4070
|
|
seq = 998644514
|
|
ack = 3458563027
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 513
|
|
chksum = 0xd241
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xa6CWb\xc1er\xd1\x98UV'
|
|
|
|
|
|
2024-12-14 20:35:06.854191 - Ether / IP / TCP 104.199.65.9:4070 > 192.168.1.11:40768 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 51
|
|
id = 15137
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x9e20
|
|
src = 104.199.65.9
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 4070
|
|
dport = 40768
|
|
seq = 3458563027
|
|
ack = 998644525
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 6
|
|
chksum = 0x1fe0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xfd\xd1<\xbfm\xc5#\xe7oF\x99'
|
|
|
|
|
|
2024-12-14 20:35:06.909382 - Ether / IP / TCP 192.168.1.11:40768 > 104.199.65.9:4070 A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x98
|
|
len = 40
|
|
id = 2865
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 104.199.65.9
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40768
|
|
dport = 4070
|
|
seq = 998644525
|
|
ack = 3458563038
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xf272
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:07.062651 - Ether / IP / TCP 192.168.1.11:41595 > 35.186.224.41:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 83
|
|
id = 8639
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 41595
|
|
dport = https
|
|
seq = 3242435546
|
|
ack = 2961047309
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xc5dc
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00&\xa2\xdd\x8c\xb7Z\xeb\x97\xfd\xa7\x94\x8e\xb5\xf1\x91\xca$\xa7\xeb\xd7\x96\x08M!|\x9d\xb2D4\xab\x9cXO \xc6\xf6+yT'
|
|
|
|
|
|
2024-12-14 20:35:07.080841 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:41595 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 54077
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xabfb
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 41595
|
|
seq = 2961047309
|
|
ack = 3242435589
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1036
|
|
chksum = 0x2d26
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\xc9\x12\x19\xf4\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:07.101480 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:41595 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 80
|
|
id = 54078
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xabd2
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 41595
|
|
seq = 2961047309
|
|
ack = 3242435589
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1036
|
|
chksum = 0xc07f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00#\x99e^\xa6\xa0\xb0g*Nb\xbb\x94\rm\x89o#\xd51\xc6[\xef\x0c\xe0\xb8\xd1:\xcfc\xb1\x82\xe7\xb6\xcf\x83'
|
|
|
|
|
|
2024-12-14 20:35:07.155195 - Ether / IP / TCP 192.168.1.11:41595 > 35.186.224.41:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 8640
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 41595
|
|
dport = https
|
|
seq = 3242435589
|
|
ack = 2961047349
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xc5b1
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:07.309233 - Ether / IP / UDP / mDNS Qry b'_adb._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 2c:93:fb:9c:dc:c0
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 216
|
|
id = 42232
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0x335d
|
|
src = 192.168.1.27
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 196
|
|
chksum = 0x4862
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 4
|
|
ancount = 2
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_adb._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_spotify-connect._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_amzn-wplay._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_dosvc._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'_dosvc._tcp.local.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 4500
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte._dosvc._tcp.local.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'_amzn-wplay._tcp.local.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 3599
|
|
| rdlen = None
|
|
| rdata = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:963520._amzn-wplay._tcp.local.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:07.311704 - Ether / IP / UDP / mDNS Ans b'KevinOlarte._dosvc._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 467
|
|
id = 41289
|
|
flags =
|
|
frag = 0
|
|
ttl = 1
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 447
|
|
chksum = 0x764b
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 0
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 4
|
|
\qd \
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'_dosvc._tcp.local.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 4500
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte._dosvc._tcp.local.'
|
|
\ns \
|
|
\ar \
|
|
|###[ DNS SRV Resource Record ]###
|
|
| rrname = b'KevinOlarte._dosvc._tcp.local.'
|
|
| type = SRV
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 120
|
|
| rdlen = None
|
|
| priority = 0
|
|
| weight = 0
|
|
| port = 7680
|
|
| target = b'KevinOlarte.local.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'KevinOlarte._dosvc._tcp.local.'
|
|
| type = TXT
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 4500
|
|
| rdlen = None
|
|
| rdata = [b'P=65280', b'SH00=BY0IkhqixvwPdwUC', b'SH01=IY1Az2JlW4gNUFfP', b'SH02=QxgYBZvgGvJpvx+l', b'SH03=U/nE/sNFwdOWjUpT', b'SH04=WfRgRM7MmfcBgXS/', b'SH05=fRahcZmnWAMmCnGG', b'SH06=jlhdKrHZsU9GUe9A', b'SH07=nL0DpLuiZxeevzrQ', b'SH08=wztLJ2cZiu42pp/7', b'SH09=6ck1lzbylEaU9x5e']
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'KevinOlarte.local.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 60
|
|
| rdlen = None
|
|
| rdata = 192.168.1.11
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'KevinOlarte.local.'
|
|
| type = AAAA
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 60
|
|
| rdlen = None
|
|
| rdata = fe80::2466:ce0f:a572:3c19
|
|
|
|
|
|
2024-12-14 20:35:07.465674 - Ether / IP / UDP / mDNS Ans 192.168.1.62
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 350
|
|
id = 19922
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = udp
|
|
chksum = 0x87db
|
|
src = 192.168.1.62
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 330
|
|
chksum = 0x1b34
|
|
###[ DNS ]###
|
|
id = 0
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 0
|
|
ancount = 3
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'192-168-1-62.local.'
|
|
| type = A
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3599
|
|
| rdlen = None
|
|
| rdata = 192.168.1.62
|
|
|###[ DNS SRV Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:963520._amzn-wplay._tcp.local.'
|
|
| type = SRV
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3599
|
|
| rdlen = None
|
|
| priority = 0
|
|
| weight = 0
|
|
| port = 42246
|
|
| target = b'192-168-1-62.local.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'amzn.dmgr:77A58D33A6B0B8794D57457DEBC2CE4D:LqxtozVpbE:963520._amzn-wplay._tcp.local.'
|
|
| type = TXT
|
|
| cacheflush= 1
|
|
| rclass = IN
|
|
| ttl = 3599
|
|
| rdlen = None
|
|
| rdata = [b'a=0', b'c=36:af:b3:ac:fc:17', b'ad=A31DTMEEVDDOIV', b'pv=1', b'f=0', b'mv=2', b'dpv=1', b'n=FireTVStick de fabiola', b'at=TyK0zfSnV9zr', b's=0', b't=2', b'u=77A58D33A6B0B8794D57457DEBC2CE4D', b'v=2', b'sp=35592', b'tr=tcp']
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:08.226179 - Ether / IP / UDP 192.168.1.11:49670 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:7f:ff:fa
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 153
|
|
id = 61192
|
|
flags =
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 49670
|
|
dport = ssdp
|
|
len = 133
|
|
chksum = 0x563a
|
|
###[ Raw ]###
|
|
load = b'M-SEARCH * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nMAN: "ssdp:discover"\r\nMX: 1\r\nST: urn:dial-multiscreen-org:service:dial:1\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:08.231694 - Ether / IP / UDP 192.168.1.62:ssdp > 192.168.1.11:49670 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 365
|
|
id = 34338
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0x2fc4
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = ssdp
|
|
dport = 49670
|
|
len = 345
|
|
chksum = 0xf2a2
|
|
###[ Raw ]###
|
|
load = b'HTTP/1.1 200 OK\r\nLOCATION: http://192.168.1.62:60000/dd.xml\r\nCACHE-CONTROL: max-age=1800\r\nEXT:\r\nBOOTID.UPNP.ORG: 1\r\nSERVER: Linux/2.6 UPnP/1.1 quick_ssdp/1.1\r\nST: urn:dial-multiscreen-org:service:dial:1\r\nUSN: uuid:01e9554e-4aef-36f8-a143-fc0328f08d08::urn:dial-multiscreen-org:service:dial:1\r\nWAKEUP: MAC=34:af:b3:ac:fc:17;Timeout=20\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:08.233721 - Ether / IP / TCP 192.168.1.11:42765 > 192.168.1.62:60000 S
|
|
###[ Ethernet ]###
|
|
dst = 34:af:b3:ac:fc:17
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 61803
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.62
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42765
|
|
dport = 60000
|
|
seq = 887331385
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 64240
|
|
chksum = 0x83c0
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 20:35:08.236955 - Ether / IP / TCP 192.168.1.62:60000 > 192.168.1.11:42765 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = tcp
|
|
chksum = 0xb72a
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 60000
|
|
dport = 42765
|
|
seq = 2274683729
|
|
ack = 887331386
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 65535
|
|
chksum = 0x17f6
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('NOP', None), ('SAckOK', b''), ('NOP', None), ('WScale', 6)]
|
|
|
|
|
|
2024-12-14 20:35:08.238775 - Ether / IP / TCP 192.168.1.11:42765 > 192.168.1.62:60000 A
|
|
###[ Ethernet ]###
|
|
dst = 34:af:b3:ac:fc:17
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 61804
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.62
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42765
|
|
dport = 60000
|
|
seq = 887331386
|
|
ack = 2274683730
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x83b4
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:08.240647 - Ether / IP / TCP 192.168.1.11:42765 > 192.168.1.62:60000 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 34:af:b3:ac:fc:17
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 210
|
|
id = 61805
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.62
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42765
|
|
dport = 60000
|
|
seq = 887331386
|
|
ack = 2274683730
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 513
|
|
chksum = 0x845e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'GET /dd.xml HTTP/1.1\r\nUser-Agent: Spotify/125200442 Win32_x86_64/0 (PC laptop)\r\nHost: 192.168.1.62:60000\r\nKeep-Alive: 0\r\nAccept-Encoding: gzip\r\nConnection: keep-alive\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:08.242192 - Ether / IP / TCP 192.168.1.62:60000 > 192.168.1.11:42765 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 4829
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = tcp
|
|
chksum = 0xa459
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 60000
|
|
dport = 42765
|
|
seq = 2274683730
|
|
ack = 887331556
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1369
|
|
chksum = 0x52c4
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:08.243571 - Ether / IP / TCP 192.168.1.62:60000 > 192.168.1.11:42765 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 132
|
|
id = 4830
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = tcp
|
|
chksum = 0xa3fc
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 60000
|
|
dport = 42765
|
|
seq = 2274683730
|
|
ack = 887331556
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1369
|
|
chksum = 0x6562
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'HTTP/1.1 200 OK\r\nContent-Type: text/xml\r\nApplication-URL: http://192.168.1.62:8009/apps/\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:08.283545 - Ether / IP / TCP 192.168.1.11:42765 > 192.168.1.62:60000 A
|
|
###[ Ethernet ]###
|
|
dst = 34:af:b3:ac:fc:17
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 61806
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.62
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42765
|
|
dport = 60000
|
|
seq = 887331556
|
|
ack = 2274683822
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x83b4
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:08.306971 - Ether / IP / TCP 192.168.1.62:60000 > 192.168.1.11:42765 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 475
|
|
id = 4831
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = tcp
|
|
chksum = 0xa2a4
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 60000
|
|
dport = 42765
|
|
seq = 2274683822
|
|
ack = 887331556
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1369
|
|
chksum = 0xc7ab
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'<?xml version="1.0"?><root xmlns="urn:schemas-upnp-org:device-1-0" xmlns:r="urn:restful-tv-org:schemas:upnp-dd"> <specVersion> <major>1</major> <minor>0</minor> </specVersion> <device> <deviceType>urn:schemas-upnp-org:device:tvdevice:1</deviceType> <friendlyName>FireTVStick de fabiola</friendlyName> <manufacturer>Amazon</manufacturer> <modelName>AFTSS</modelName> <UDN>uuid:01e9554e-4aef-36f8-a143-fc0328f08d08</UDN> </device></root>'
|
|
|
|
|
|
2024-12-14 20:35:08.314989 - Ether / IP / TCP 192.168.1.62:60000 > 192.168.1.11:42765 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 11108
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = tcp
|
|
chksum = 0x8bd2
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 60000
|
|
dport = 42765
|
|
seq = 2274684258
|
|
ack = 887331557
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1369
|
|
chksum = 0x50b3
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:08.516093 - Ether / IP / TCP 192.168.1.11:42766 > 192.168.1.62:8009 S
|
|
###[ Ethernet ]###
|
|
dst = 34:af:b3:ac:fc:17
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 61809
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.62
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42766
|
|
dport = 8009
|
|
seq = 7898511
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 64240
|
|
chksum = 0x83c0
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 20:35:08.525039 - Ether / IP / TCP 192.168.1.62:8009 > 192.168.1.11:42766 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = tcp
|
|
chksum = 0xb72a
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 8009
|
|
dport = 42766
|
|
seq = 1206795741
|
|
ack = 7898512
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 42340
|
|
chksum = 0x73d8
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('NOP', None), ('SAckOK', b''), ('NOP', None), ('WScale', 6)]
|
|
|
|
|
|
2024-12-14 20:35:08.527394 - Ether / IP / TCP 192.168.1.11:42766 > 192.168.1.62:8009 A
|
|
###[ Ethernet ]###
|
|
dst = 34:af:b3:ac:fc:17
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 61810
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.62
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42766
|
|
dport = 8009
|
|
seq = 7898512
|
|
ack = 1206795742
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0x83b4
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:08.529188 - Ether / IP / TCP 192.168.1.11:42766 > 192.168.1.62:8009 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 34:af:b3:ac:fc:17
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 232
|
|
id = 61811
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.62
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42766
|
|
dport = 8009
|
|
seq = 7898512
|
|
ack = 1206795742
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 513
|
|
chksum = 0x8474
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'GET /apps/com.spotify.Spotify.TVv2 HTTP/1.1\r\nUser-Agent: Spotify/125200442 Win32_x86_64/0 (PC laptop)\r\nHost: 192.168.1.62:8009\r\nKeep-Alive: 0\r\nAccept-Encoding: gzip\r\nConnection: keep-alive\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:08.530530 - Ether / IP / TCP 192.168.1.62:8009 > 192.168.1.11:42766 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 50290
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = tcp
|
|
chksum = 0xf2c3
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 8009
|
|
dport = 42766
|
|
seq = 1206795742
|
|
ack = 7898704
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 679
|
|
chksum = 0x56a7
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:08.675405 - Ether / IP / TCP 192.168.1.62:8009 > 192.168.1.11:42766 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 131
|
|
id = 50291
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = tcp
|
|
chksum = 0xf267
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 8009
|
|
dport = 42766
|
|
seq = 1206795742
|
|
ack = 7898704
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 679
|
|
chksum = 0x3103
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'HTTP/1.1 404 Not Found\r\nContent-Type: text/plain\r\nContent-Length: 30\r\nConnection: close\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:08.678349 - Ether / IP / TCP 192.168.1.62:8009 > 192.168.1.11:42766 FPA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 50292
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = tcp
|
|
chksum = 0xf2a3
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 8009
|
|
dport = 42766
|
|
seq = 1206795833
|
|
ack = 7898704
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FPA
|
|
window = 679
|
|
chksum = 0xbdf3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'Error 404: Not Found\nNot Found'
|
|
|
|
|
|
2024-12-14 20:35:08.680128 - Ether / IP / TCP 192.168.1.11:42766 > 192.168.1.62:8009 A
|
|
###[ Ethernet ]###
|
|
dst = 34:af:b3:ac:fc:17
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 61812
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.62
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42766
|
|
dport = 8009
|
|
seq = 7898704
|
|
ack = 1206795864
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x83b4
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:08.681852 - Ether / IP / TCP 192.168.1.11:42766 > 192.168.1.62:8009 FA
|
|
###[ Ethernet ]###
|
|
dst = 34:af:b3:ac:fc:17
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 61813
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.62
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42766
|
|
dport = 8009
|
|
seq = 7898704
|
|
ack = 1206795864
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FA
|
|
window = 512
|
|
chksum = 0x83b4
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:08.683332 - Ether / IP / TCP 192.168.1.62:8009 > 192.168.1.11:42766 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 34:af:b3:ac:fc:17
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 11129
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = tcp
|
|
chksum = 0x8bbd
|
|
src = 192.168.1.62
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 8009
|
|
dport = 42766
|
|
seq = 1206795864
|
|
ack = 7898705
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 679
|
|
chksum = 0x562c
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:10.340486 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34190
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58714
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 9998
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.343121 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34191
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58715
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 9999
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.345900 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34192
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58714
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 10000
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.348974 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34193
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58715
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 10001
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.351580 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34194
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58714
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 10002
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.354572 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58714
|
|
len = 76
|
|
chksum = 0x299d
|
|
###[ DNS ]###
|
|
id = 9998
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.361117 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58715
|
|
len = 89
|
|
chksum = 0xbc14
|
|
###[ DNS ]###
|
|
id = 9999
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.364887 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58714
|
|
len = 90
|
|
chksum = 0x223a
|
|
###[ DNS ]###
|
|
id = 10000
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.371784 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58714
|
|
len = 81
|
|
chksum = 0xdd8c
|
|
###[ DNS ]###
|
|
id = 10002
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.374217 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58715
|
|
len = 51
|
|
chksum = 0x7044
|
|
###[ DNS ]###
|
|
id = 10001
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.381789 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34195
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58716
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 10003
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:10.384705 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58716
|
|
len = 81
|
|
chksum = 0xf773
|
|
###[ DNS ]###
|
|
id = 10003
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:11.198254 - Ether / IP / TCP 192.168.1.11:42690 > 142.250.201.78:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 22706
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.78
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42690
|
|
dport = https
|
|
seq = 912712043
|
|
ack = 2800351769
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0x1a18
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:11.221671 - Ether / IP / TCP 142.250.201.78:https > 192.168.1.11:42690 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 32052
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xac93
|
|
src = 142.250.201.78
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42690
|
|
seq = 2800351769
|
|
ack = 912712044
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 999
|
|
chksum = 0xcae0
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (912712043, 912712044))]
|
|
|
|
|
|
2024-12-14 20:35:11.915016 - Ether / 192.168.1.11 > 224.0.0.252 2 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fc
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 6
|
|
tos = 0x0
|
|
len = 32
|
|
id = 30465
|
|
flags =
|
|
frag = 0
|
|
ttl = 1
|
|
proto = 2
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 224.0.0.252
|
|
\options \
|
|
|###[ IP Option Router Alert ]###
|
|
| copy_flag = 1
|
|
| optclass = control
|
|
| option = router_alert
|
|
| length = 4
|
|
| alert = router_shall_examine_packet
|
|
###[ Raw ]###
|
|
load = b'\x16\x00\t\x03\xe0\x00\x00\xfc'
|
|
|
|
|
|
2024-12-14 20:35:12.508730 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34196
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58978
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 45064
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:12.511291 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34197
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58979
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 45065
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:12.512854 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34198
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58978
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 45066
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:12.514313 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34199
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58979
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 45067
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:12.515809 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58978
|
|
len = 76
|
|
chksum = 0x9f9a
|
|
###[ DNS ]###
|
|
id = 45064
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:12.517374 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58979
|
|
len = 89
|
|
chksum = 0x3212
|
|
###[ DNS ]###
|
|
id = 45065
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:12.519580 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58979
|
|
len = 81
|
|
chksum = 0x538a
|
|
###[ DNS ]###
|
|
id = 45067
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:12.527633 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58978
|
|
len = 51
|
|
chksum = 0xe643
|
|
###[ DNS ]###
|
|
id = 45066
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:12.549185 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34200
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 58980
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 45068
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:12.553158 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 58980
|
|
len = 81
|
|
chksum = 0x6d72
|
|
###[ DNS ]###
|
|
id = 45068
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:13.075465 - Ether / IP / UDP 192.168.1.11:57621 > 192.168.1.255:57621 / Raw
|
|
###[ Ethernet ]###
|
|
dst = ff:ff:ff:ff:ff:ff
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 49060
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.255
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 57621
|
|
dport = 57621
|
|
len = 52
|
|
chksum = 0x9f
|
|
###[ Raw ]###
|
|
load = b'SpotUdp0\x977M\xb3\xe9=C\xf2\x00\x01\x00\x04H\x95\xc2\x03\xb3}cPK\xb7\xed\x7fT~\x1d\x0f\xd7\x01\x15-#vA\xf6'
|
|
|
|
|
|
2024-12-14 20:35:14.064119 - Ether / IP / TCP 192.168.1.11:40790 > 35.186.224.41:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 83
|
|
id = 8641
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40790
|
|
dport = https
|
|
seq = 3089482615
|
|
ack = 915357599
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0xc5dc
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00&\xabh\xb4\x80\x8b\xb8L\xc0\x18\x12\xc6\xe8$1\xc8\x8fb\x00\x87\xc1BIwx\xf3\\I\x8a\xf5\xf3\x89\xbd\xa9U\xd8F.\t'
|
|
|
|
|
|
2024-12-14 20:35:14.086834 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:40790 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 15310
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x426b
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40790
|
|
seq = 915357599
|
|
ack = 3089482658
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1043
|
|
chksum = 0x5322
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'=\xc3X\xc1\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:14.102389 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:40790 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 80
|
|
id = 15311
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x4242
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40790
|
|
seq = 915357599
|
|
ack = 3089482658
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1043
|
|
chksum = 0x965b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00#\x03\xa9\x9eR\x1f\xae[\x81V:\x8cZ5\xc1Y\xe3\xe7\x9fQ\x1a\xaa\x9b\xa7\x97\x06\x06\xe1\x96\x11\xc2NPW}\xda'
|
|
|
|
|
|
2024-12-14 20:35:14.156541 - Ether / IP / TCP 192.168.1.11:40790 > 35.186.224.41:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 8642
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40790
|
|
dport = https
|
|
seq = 3089482658
|
|
ack = 915357639
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xc5b1
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:14.926438 - Ether / IP / UDP / mDNS Qry b'_233637DE._sub._googlecast._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 6c:f7:84:e4:d7:de
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 89
|
|
id = 57037
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0xfa05
|
|
src = 192.168.1.28
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 69
|
|
chksum = 0x32a8
|
|
###[ DNS ]###
|
|
id = 4
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 2
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_233637DE._sub._googlecast._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_googlecast._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.887965 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34201
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 59238
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 56796
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.889945 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34202
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 59239
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 56797
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.892610 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34203
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 59238
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 56798
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.894678 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34204
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 59239
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 56799
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.896140 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34205
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 59238
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 56800
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.897707 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 59238
|
|
len = 76
|
|
chksum = 0x70c2
|
|
###[ DNS ]###
|
|
id = 56796
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.899479 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 59239
|
|
len = 89
|
|
chksum = 0x33a
|
|
###[ DNS ]###
|
|
id = 56797
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.902525 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 59238
|
|
len = 90
|
|
chksum = 0x695f
|
|
###[ DNS ]###
|
|
id = 56798
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.906490 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 59238
|
|
len = 81
|
|
chksum = 0x24b2
|
|
###[ DNS ]###
|
|
id = 56800
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.908658 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 59239
|
|
len = 51
|
|
chksum = 0xb769
|
|
###[ DNS ]###
|
|
id = 56799
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.924906 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34206
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 59240
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 56801
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:15.927849 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 59240
|
|
len = 81
|
|
chksum = 0x3e99
|
|
###[ DNS ]###
|
|
id = 56801
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:16.569629 - Ether / IP / UDP / mDNS Qry b'_233637DE._sub._googlecast._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 86:1e:7e:31:2b:c4
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 89
|
|
id = 54492
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0x3e4
|
|
src = 192.168.1.47
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 69
|
|
chksum = 0x3292
|
|
###[ DNS ]###
|
|
id = 7
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 2
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_233637DE._sub._googlecast._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_googlecast._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:19.237679 - Ether / IP / TCP 192.168.1.11:42699 > 52.168.117.171:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 51199
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 52.168.117.171
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42699
|
|
dport = https
|
|
seq = 3947335681
|
|
ack = 3150555719
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x6c22
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:19.356077 - Ether / IP / TCP 52.168.117.171:https > 192.168.1.11:42699 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 9543
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 108
|
|
proto = tcp
|
|
chksum = 0x7d76
|
|
src = 52.168.117.171
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42699
|
|
seq = 3150555719
|
|
ack = 3947335682
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 16385
|
|
chksum = 0x4d3f
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (3947335681, 3947335682))]
|
|
|
|
|
|
2024-12-14 20:35:20.419605 - Ether / IP / UDP / DNS Qry b'safebrowsing.googleapis.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 73
|
|
id = 34207
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64667
|
|
dport = domain
|
|
len = 53
|
|
chksum = 0x83a3
|
|
###[ DNS ]###
|
|
id = 12833
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'safebrowsing.googleapis.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:20.436966 - Ether / IP / UDP / DNS Ans 216.58.213.74
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 89
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb737
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 64667
|
|
len = 69
|
|
chksum = 0xb39c
|
|
###[ DNS ]###
|
|
id = 12833
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'safebrowsing.googleapis.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'safebrowsing.googleapis.com.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 111
|
|
| rdlen = None
|
|
| rdata = 216.58.213.74
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:20.440184 - Ether / IP / UDP 192.168.1.11:55785 > 216.58.213.74:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 5258
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 216.58.213.74
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55785
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0x7434
|
|
###[ Raw ]###
|
|
load = b'\xc4\x00\x00\x00\x01\x08\xfa\xbe\xc6\x1c\x11\xd6<\xa9\x00@F\x00J\xa2\xc3Pq\x08\x02\xdd\x02\x12\xf5\x94EF\x02A\x01\x0b\xff[M\xa5\xcbVV\xfd\x96\x14\x9dl\xac\xb4Dgs\xaf\xe3\xd2\xed\xd5\xef\xcaJ\xef#\xb3,\x8b&\x9a\x84\x13\xd6\xf3k\x1c%.&&\xd0y\x1a\x00\x1c\x92L\x1f\xf7D\x89=.\x8f\xdc\x94H\x00\x90\xb2,\x04\xd3o\xe5r\x8e\xc3^\xef\xd22k\xbc\xe85\xda\x94H\xf7\x9d\x12\xe5\x8d\t>e>"\xd2;=\xbd\xd5\xa4\x1b\x1d\xa9\x81\xfd\x82\x18\xdfIx,{\xc9\xeb\xdd\x19#E\xcbG\x04\xca\xe1v\x97\xb49\xb8 \xe8\xa3\xfa\xfb\xaf\x8c\x1a\xe9\xc0\xd6\xe2G\x1d\xe3\x0eq\x0e\xff,t)\xeb|\x06\xe4\x9c[\xc8\x10\xf0m\xab\x95\t\x03\x11\x14\x1b\x0cf\x87\r;\xfdi\r\xb1*KC\xab\x0f\xec\xc6\xde\xf5\x83%\xfb\x8b\xd4\xa2\xba\xa2\x03G\x840r\xa2\x1b\xc5m\xcf\xc7\nR\xb6\xdd.\xc3\xd4W\x13\xf6Hi\xaa\xa1;\xcc\xa7q\xd0"\x90\xcb\xd1-=\x8fP\xebCf\xcc\xecgfVq\x06\xfaM\xc1\x9aw\xb7#\xfe\xd6\x1a$\xd6v\x17\xa7\x18\xa3\x16}\xd8\xa6a\xd02\xf1\xce\xc5\\\xd1Z\xf0\x0e\x97Y\x0f6\x8c\x84\x1a\xcd\x89\xac.!\xaf&\xaa\x89\xa1*\xc5\xc3\x13\xb1H\xa4\xa0e\x92\xcd\xc7%KXv\xdc@%\x9e\xe4\x8e\xbe\x0bj\xcdU<\xc1\xa2\x04:C\xabz\xbb\xb2S\x0b\x89\x7fA\xcbo\xa0&k\xb2\xf9g\xf3\xea\x84\xe7\xb80\x04\xb4\xd3\xf3H\xaf\x14i\xfe\n{4\xeb\xfe\xadr\xb6\xa9\xabW\xd0z\x88\xb3\xb8\xe8\xa8[}\x8f\x94a\xed\xc9\xbc\xbd[\x87\x89\xd4\xd3\xae$\x00\x8dre\xdc\x9eW\xc6kx\x1d{\x8d)b\xe3\xcb\xec\xee\x18\x1a\x8c\x84\x0c\x0f\xc5\x03c+\xc2\xbc\xbePY]\x8eg\xd0\xf1\x8f\xc9\x7f)i\x18\xb6w\xaeBq\x13\x91s\x12h\xd7\r[\xee\xfe\x85\xcf~\x8d\x92z!\x04inIb\x82v3\x07\xa4\xa6\xca H\x8d\x19\x88c/\x03\xedM\x9d\x9cqk\x98\xac\x84oSU\xc2\xacq\x90\x87\x97*\xa5y\xe5\xc6\xad\x06\xe9\x17\xaeI\xf1\xfa>T\xf0\x02\xe6y{G@\xa5l\xa6x&H\xba\r\xacd\x03\x19Z\x917\xaf\x06\xf6\xc2\x99\x97\xc9\x16F\x93\x0b\xd3r\xaa\xdb\xbat\xbbRHV\xc0N\x92c\x03\xbb9\xf5\xb4\xb2oh\xa2\xeb\xb7E\x16w\x91\x9d\x8a<\xb0Kb\x95\x84\t3\x03\xa1\x04\xe6\xd7A\xb5M\xfa\xed\x06\xbcn40\xfd\xaeC\xc0\x1a\xbb\xdb\xc0\xd6\xf1\xd3%\x0c{B\xe2\xebx\x02W\x02\x81g\xa1\xab\x1c5 \x99\x0c\x8a\x83\xb1q\x03,d\xf2\xe56\xaa\xd9 \xbf\xdbi\x1a\x1c\x8e\xef\x94\x92\x08|\xc80C$=\xaeo\xc3\xd2\xb9\x82\xe6\xbf\xccLj\xc0\x16=\xe4n\\\xd7\t+n\xc5\xa2\x85\xa3\x91\xf6(\x96\x04\x00\xc4\xa4u\xfb\xab\x04\x96\x92\x94\xe55\x05\xf3\xa6\xab\x18G\xfb\x1c%\xb2\x05\xc5\xc7"\x9cO\xa09kQ\x1e8\xdftok:\x99\x15\xa0[j6\x9an\xb6\xf8O\xfd\xa1H{\x83aPC\xb8\x9e1\xe3\x168\x81\x9e\xab_?Q\xbf\xe3\x8a\xcd\r\x97\xa9\xc4\xdbE\x1e\xc5~\xeeQ\x02w\x0e\xd7G\x91\xf0\x8el{\xbfM\xb1\x9dr\xee\x8b\xb7{\xd8<s\xb1{\x97\xc3\xcf\x8d@]\xf0n\xf1@F;\x0c\x89.A\xe1\x97,<\xc8\xad\xef\\\x80d\xdb\xf6\x91\xdd\x08\xb2VlH{\xe7\xd8\x01\x02\xee\x1c\xe5M\xb2\xaa\xfc\x7f Q\xec0\xad\x89\xe8:\xf5<\x1e\x9a\xfal\xac9r\x1d\xd39\x87\xef.\xdf\x08\xa4}^\xe8<~\xaf\xe5\xa2\xe5b\x8e:\xbb\xac@\x029\x92\xd0\xd6\xa0\x8c\x93|\xefw\x7f\x9b\x97wW\x95\ru\x08\x96\xa2\xd7\xa8\xf7\x8b\xc2\xa5\x97\x0f\xa8qW\x97u\xe4\xca\x97\x1d\xa1%\x91\xd6f\x8cQ\xad]H\xaf\xa1\x0b\xb5\xcal\x0e7+G\x026\xc0|\xd3\x17ed\xae\xc3xV\x97\xdaI\xe9<\xdfr\xd0\xea-\xc2s\x04k\x0e\xde9\xe7\\\x0c\xb0\x01\xf1nQ\xe49g\'^b\xb09\xeb\xddH\x94\x1f-!H\xcb\xc0\xa5\xb0\x9c\x90\x1a\xe1\x1f7x\xe2\x19G\x1a\x0e\xf5y\xa1\xfb\x1cc`\x1d\x1bM\x0b\xa8)\xc6\xfd$\x90G\x81\x8dp{\xe4\xc9T c\x0b\xac\xa6\xec\xa0\xe0\x7f\xdc\xb5\x92O\x92\x90\xc8\tg\xfc?\x01\x99\xe4\x8f\'\xd2\xab)\x18\x7f\xb9wo\xa0\xdb\xc4\xe3<L\xceML\xba\n\xde\xf6\x990\x8ei1\xe7\xed\xa8\xe9\x93\x81\t\xb6DBd\xc0,<;5\xf2\xed:\xca\xf7\x93K&K\x9e\xe0L\x85\xb2\x12l\r$D\x9f!$\xd9\x85\x8e\x0e\xe1\x9aP\xef\xdb\xeea\xeb\x99AL\x14w\xf2?\xc4"\xa9\xde\x8f[0\x87\xd6\xb8}D\x19\xc1M\x85\x98\xa7D4\xe9\x02\x80L\xcdu\r\x03\xc5\xdf-e\x8e\x8c\x98\xff\xb2\x8d\xf0{\xa8\xfb\xcf\x8aZ\xe3\x10\xcc0\xb2(B\xf2^\x99l\xff\x18\xdb\x1c8\x96\xb8\xf2\xf2\xadX\xf4O^\x1f\xf6\x99'
|
|
|
|
|
|
2024-12-14 20:35:20.522096 - Ether / IP / UDP 192.168.1.11:55785 > 216.58.213.74:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 5259
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 216.58.213.74
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55785
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0x7434
|
|
###[ Raw ]###
|
|
load = b'\xc7\x00\x00\x00\x01\x08\xfa\xbe\xc6\x1c\x11\xd6<\xa9\x00@F\x00J\xa2\xc3Pq\x08\x02\xdd\x02\x12\xf5\x94EF\x02A\x01\x0b\xff[M\xa5\xcbVV\xfd\x96\x14\x9dl\xac\xb4Dgs\xaf\xe3\xd2\xed\xd5\xef\xcaJ\xef#\xb3,\x8b&\x9a\x84\x13\xd6\xf3k\x1c%.&&\xd0y\x1a\x00\x1c\x92L\x1f\xf7D\x89>\xf9\xd0\x80_\x9dx\t\xf1\\\xae\xc4g\xd2\xae\x97")\n\\\x9bj\x87tSq\xb2L\xe8wI\x13N\x8e\xffyU\x0bRm\xc9\xf6\x96\x91\x85FV\x9c\xb4\xaba\xe6h\xb8R\xd8\xcbT\xb8L\xa3\x17T\xff0m\x8e+\x91t\x9cO\xd7i\x02\x02X\x1d\x1d\xb0H\xd4\xc6<\xd9\x8dL\\|\x9b\xe4\x8ec\xa9\x13I\x94z\x9b\xe8+\xfaWc\x86\xaa\x9fY\x07dt\xf7o\x08\xa8E\xca\xc5\xb9g\xd7m\xc6I\xaa\xe8\x9d\x14\xda(\xaf\xa9\x9a\x11\xd6\x91\x0eB\xf6?v\xd8\xab\x95@\xcbJ\xe1\x84e\xe81\x17^\xaej\xe4\x9b0\xaa\x92\x9f`\x84P\xec\x08\x86/\xe5,\xda\t\xceR\xc4\xb9WJ\xf9\xa0`b\xa8\xd2\xed\xda\x8f\xa1\xea\x98\xad\x95p\xd2\xd6,\xbb\x0c\xa2\xf5\xa2B\xc8\xa6\xd9\x8b\xfdP\xf0\xca\x08\x95\xc3\xde\xaa\x1e7\xac\xca\xed_\x10\xe5\x9d\xe4\xd0\x84.hu\\\x94d#\xddj\xd3,-\xff\xde6\xd6\x9e\x13\xbd\x1a8\xa1\x18~\x067K\x9e\xf4\x8d/\x7ft\xd1\x7f\x11a6\xbf\xd0\xf7\xd6\xbb\x16|y\xa3\xd2)uh\x16\xba\xb64\x05$\xa4\xfc\nM,,\xd8\x14/\xcc\xf1Z\x05\xa0\xd7\x192\xd94\xa76\xac\x17\xb8\x9c;cn\x9e\xc4\x9dz~\xaa\xd1\x97\xb9\x0b\xca/%\xd0\xd9Q\xea4\xf8\x8b\x95\x10\x0e\xd6\xdd(zA\x06\x11\x0e3\xc7\xb5fl\xeeS\xb6\x16T\xc4\xa1Z\xaa\xa7P\xc5[\r\xc7{ 7\x02D=\xe0]}\xc5\x9b\xde\x93|\x18i(\xd3\xf6\xa9\xf9\x04n\xec\xbaB34\xf5{\x98\x9af\xc0\xab\x83\x93\x19\xf5\xc93\x8d\x02\xce\xb9;\x13g\x930\xcb\x9d\xf0`5\xe6N\x81\xfe\xb7\xb2L\x99\t\x1d=\rM\xbfC5j\x04\xc5\xec\xb5\xa4\xdb\x16\xe2/N\xd8\xa3\x98\x18\xd3\x16\xa4\xad\x98\xad\xc3a\x1c\xaeJ\x80Z\x9b\xd0\xd8i{\xdf\xb7D\xdd5]aW4\xdd\xe1k\xdb*\xd3\xb4-\xf0y\xc9\x95\x8a\x7fa\xcf3\xfc\x08\x11`\xfd\xbf\x89\xb3b\xf7\xd8\xf0\xc9E\x80\xb2\x1d\xe8\xb8O \x1c\x18\xcc\xed\x8b@u\xf3\x05\xd7\xf4\x00\x15jD\xd2qS\xde\xcb}6\xd3\xae\xd3\xf2<w\x033\x92\x8f\x83\xd2\xd8SQ\x07;%!P\x80SX\xb2\x88\x9e\x00\xb8\xb6St\x93\xbb\x00J\x85\xcd\x93\xe1\x85\x9f\xef\xc2\xfao\xc5\xdd\xce\x1d6f\xb8i\xbd\xb2\rN\xe7%\x86\x16\xdcLELV\xcb\xdfV\xb9\x12\xb241\x80^\xc9$B\xa1\xb5Ze}`\x06\xdbs:\xb2N\xa7\xf3\x1e\x1anJ\x17\xd5\xee7V\xab\x06?\x84\xa8v\xd1\xb1\x12\x08{\xac\x91\xbbc\xfd\x06\xa95JOf\xbf\xe8;\x00\xbbpd\x02R\x1d\x1b\x81o\xd8\x8b.\x8b\xe6Np\x10\xc6\tr\xfbB\xa5I\x13\xea\x86\xc3\x06\xc9\x19V\x9b`E,\x04\xd1P\x0f"\x0e\xe7\xe3\xda\xd9\xbc\x08:y\xbb\x98\x10s2\xfd\x8a\x03C\xc2\xeaG\x93!\xe0Z*\x01IrF\xcf\xf1A\x9a\xd7#tO\xf39r\xba\x9e.\xd0\x03j\xb3\x01%\xfbX\x06\x98l\xb6\x9b`\xfc\x92/\x08wW\x8c\x9e\xf0Cb\x8c\x10\xcf>\xf0\xb7\xdf\xd1\xefk\x8d\xed\xcd\xe6\xda\xd6\x95\xe01\xb9\xd5\x91\x88\x8du~\x05\x7f\xaa6\xe3\xa9\x19\x80\x88e\x0e\x91u\xa7\'\xf7z\r+\xd0\x8bjW\xae\xd7\x1fhN\x0b-\xe2\xd4\'\xb8\xa1\x9c\x06\x1b\xe9sr\xd4+\x7fh\x1cO\xef\xf8\xfc{\xad0\xc20*\x17\x0bl\x03\x11\x89?\xd7\x82\xff\xe2\x81t\xf9\xf9\xb9j\xddF\xf0\xdb\xc2Z\xb6\xf2\xc5\xdf\x8b%6\xbbU}\xd8v\x8d\x00\x1e`.;\x8f\xdb\x01;\xa1\xb6\xa9\x18\xc4\xe5v\xe4\xa9\x8d\'\xaa\xb1\x01\x95\xa6-\xb0\x16\xf4\xaf\xfe@\xe1\x1b]\xa6\x97\r"\x14\x96\xbf\x84\x01*u9\x03\xb1\xe9\x8d\x19\xc1\xc9\x81\xdb\xf6y\x85H\xad>\x98p^\xfb\xef\xfc\xc4\x03\x06d\xbe[\xbd\xdd\xbb\xa0d\x9b\xa3\x021\x1b\xbe\x86\x08\xe4\xd8,\x84\xbb$\xc8\x97\xfaE\xf2\x18\x04);\xd8\xabm\xdb\xf7\xbcZ\x08\x17yL\xf4\x8c\x95#\x1an\x8e\xf7\x1cz\xb0)\xf4\x15\xb4\xa6W\xaf\xf8\xb3\t\x893KW\x13M\x87b\xc3\xee\xaa\xeb\xa8\xdd\xa3\x87\xfb\xcbVj\xad\'\xaa\xe3,K\x82j\x16ms\xa5w.J\xdf\xd98uO\xd1\x95\xa0Z\xe3zU\xc3I\x198i\x01\xc9\xfd\xc8=\xc8\xc7V\x0b\x1e{\xd5\xe6\xe6N\xc0[\xc3\x86\xaf\x8d\x11I\xc7\x96\x97!\x95sq\x9f\x96\x1d4\xf3Em\xcc\xc6\xf0N\xe8\xde\xef+vm%\x0b\xde\xc3\x85{\x131<\xc0\x1b\x9d\x0fC3L\x91\r\x14:\xa6\x9cK\x7f\\W\xc2\xc1\x9d\xed\x009\xdb\x16`'
|
|
|
|
|
|
2024-12-14 20:35:20.612899 - Ether / IP / UDP 192.168.1.11:55785 > 216.58.213.74:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 5260
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 216.58.213.74
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55785
|
|
dport = https
|
|
len = 89
|
|
chksum = 0x6fa3
|
|
###[ Raw ]###
|
|
load = b'\xd4\x00\x00\x00\x01\x08\xfa\xbe\xc6\x1c\x11\xd6<\xa9\x00@@\xdb\xcb\xbf\xd6\xeb\x16\xe2!\x16g\x9d\xa5\x13\x82G\x14~\xe7\x8a\xefL\xad\x9c\xd7=xAs\x1a>\x86\xe7\x8c\x8c\xf1\xc7=b\x95\x90\x82p\x86&\xc6\xde\xdd\xcaP\x93\xa2\xf9\xb2\xb3+u\xee\xd7\xb2!\xd2\x17C\x1e'
|
|
|
|
|
|
2024-12-14 20:35:20.636823 - Ether / IP / UDP 192.168.1.11:55785 > 216.58.213.74:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 943
|
|
id = 5261
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 216.58.213.74
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55785
|
|
dport = https
|
|
len = 923
|
|
chksum = 0x72e5
|
|
###[ Raw ]###
|
|
load = b'\xd1\x00\x00\x00\x01\x08\xfa\xbe\xc6\x1c\x11\xd6<\xa9\x00C\x82\x9d\x06\x82\rV\x99\xe8\xc1\xdcF\x1c(\x96|\xbe\x1a\xcb\xc5\xf2\xc2P\xe0\x8cv\x01\xfdm\xe0\xc4\xc5\x91\x0f\nW\x17[\xe5,q\xe8\x90\x9db\x1f\xbb\x94~ A73\x0fBz\xbe\xffs\xe4\x0e\x89\xd3\xc119\x06\xa0C\xdb\x01\x84\x94\x9b\x1a\xdf\x1a\xce1\xaa\xd3\x17\x17\x90MUj\xf7,>"\x7f\x1d\xba1k\x89\x06x\xb0kY\x15\xdb\x8e\xfe\xa9\xd4\x1cm\xffk\x90\xb5\xfd\x98\x91\xec"bb\x12<zU\x8e\xf2b\x83\x16\xbdjI\xa8Q]\x8d\xe3Q\x8ba\xce\x95\x8a\x12\xb3=\xeb/*\xb8?\xb3\xea\xcd\xbe\x12\xf0)_\xcf6\xf7\x9d$@\xc9\x8e\xfd\t0%\xd3\x12\x0eY\x89\x18\x19\xc1\x0b\xf0\xe9\x92\x87A=\x9f\x07)\x18\x01\x9d\xa2\xb8\x8e0~\xc0\x13v\xd3\xb9\xd6\x05\xb0]p\x9d\x8a\xb7\xe4\x16\x89>t\'\xccn:\x1b~\xfbN,4\xba~E\xbe%F\x8ei)\x98\x1a\xdb\xb8qY0\x1a\xdd\x14\xf4A\xbb\x8c[rLZ>\xf1\x1a\x80u\x02\xe7\xcf\xefh\x99\xce\xd2\xddi<!\xf8Z\xb0\x19\x1c\xefl\xeb\xff\xb8\xe9\x80\x93\xbd\xcf~\xccX\x84\xc3\xa6\x0f\xf1\xa8\xa7gghY\x04v\xb2\xf2\x14\xce\xccbe\xed\x8f\x11\xa1\x96\'s\xac\xa6V\xbe\xd0\x1f\x96}u\xbe\xda\xd2\xd3a\x16\x12\xd0\xe5H\xee\xea_\x07\xccf>\xcd6_\xc1\x07O\x07ML\xb5\xe6K0\\\xe9S<\xce\x0bdL\xc6\x12\x13\x83"Ip\xb0\xe9\xfd\xa3\x9f\xf3\xd4\x11\xc7M\xf0\xc3*<\x92\x99\xa1\xc0\x18\x82\xffL\x8a6\xb5\xa9\x0b\xea1\xbc\xba\xbeK\x15z\xbeoL\x88\x0c\x15\x9e_\xed\x06e\x1b-]\xd7\xdf\x87/\x1c9\xba\xd6\x95\xe8p\x8ap\xffk\x8f\x0b\x1c\x08u.\x8b\x8b\xd8(\x14\xbb\xc0\xac\x83\x0fn\xa6\xc5 \x85\x87x&\xdc\x13\xd5aD\xde%\xe7\xae\xdf\xddJ7\xe6\x12\x8e\x85\xb3b[\xd2Z\xbf\xb3I\xc1\xe2\x1d\xc2\xc6\xb3\xfa\xfe\x01\x85\x98]\xc8\xea\xb3\xe7\xc06\xe3\xa8\x802\xf9C\x9eI\xb9N\xef!\x9d\xd7^\xc3\x14LVo\xfe\xd0\x9a.|^\x00aY/\x01\x91S+)\xa2&hu\x14v\x96\xb7aK\xf9\xb1\x87\x9b\x15{\xb39Ae\xe1\xbfu\x8b>\xcbj\x15]\xe6P\x9a\x1b\xf4X\x8f\x12f\xfe\xe1\xf6(S4\xf0{0\x8fFD\xef}\x8f\x94\xb27"y\xfd\xb1\x9d87\x00@Ug\t\xcc\x1f=E\x05#\'\xa4sE8\xc5M\xad\xcc\xca\x07\xf1\x9b\xa0t\xc1\xd0\xb8f\x04\xf0\xa0DV\xc6\x1a;\xab\x0c\x14\x91PVo\xc1Eaf\'\x9d\xf4\x191\x14\xc0\xdeB\x9d\xa9\x14~~m\xe8\x10\x0eF\x0b\x9a/\x13;\xb3\x9b\x00\xa3ow\xb4%M\xc2"\x12bH\x9eNelH\x11\\\x83C\x93\xaf\x8e\x1cS\xf2g\x95\xd9\xfb}\xb9\ns_\xb0\xcdI\xad\x1f\x1dRB\xa7]\x10\x01G\xeb\x99\xb9dK4<\xf4\x92\t\xda\x8f$\xcc\xd3\x83\x95\x8e\x14=Bk\x07\tQ\xca\xa1k\xa1\xef\x04!\xcb\x9d\x1b\xcdU\x97\xf2\xb5y\xab\xbe\x90\xbb\xe5\xab\xba[\x02&\xa8\xe1\xa27;\xd9\x9e|L?RyF\xc8\x847\x1c\xa1,\xff\xef\xd0\x8d(\xd0}\xd7\xbf\xd3\xa9\xb8\x19\xb0@@\x9b9u\xcd\xf4\x10\xb88,\xbf\xdc\r\x92\xfcC\n\xefq\x17\xe1Y\x84\xe5\x14\xfb\xc8d\xff\xd7\x96\xd8\x8f\x97\x90\x10\xedE\xa1\xb4J\xeb\xd5\xc4\xc6a\xa8,\x81\x8e\xf7\x95\x86.\x9ci\xbb\x94x\xa7\x14\x88\x13Y\xc5\x8d\xf9$\xc0\x11\x1b\xbfRf\xfc\n\x9f\xf0\xef\xd0(\xab\xac=|\xc6hc\xb2\xea.\x06\xe6'
|
|
|
|
|
|
2024-12-14 20:35:20.700137 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xd470
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 48
|
|
chksum = 0xa929
|
|
###[ Raw ]###
|
|
load = b'\xce\x00\x00\x00\x01\x00\x08\xfa\xbe\xc6\x1c\x11\xd6<\xa9\x00@\x16LGV\x04\xc3XN\xea\x00\xf6\xa7n2\xc3\x10\xbc\xfc7)\xc2\xd2\xf3'
|
|
|
|
|
|
2024-12-14 20:35:20.707944 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xcfb6
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 1258
|
|
chksum = 0x3811
|
|
###[ Raw ]###
|
|
load = b'\xc8\x00\x00\x00\x01\x00\x08\xfa\xbe\xc6\x1c\x11\xd6<\xa9\x00D\xd0O\xce\xe3C\xb80\x1b\xa7\x13\x16\xb2y\x7fH[\x93#\xf5\x1c\'BNS)w\x8a\xf6#\x11\x8a\x89n\xb8\xf3\x8f\x92\x07\x17W\x91\x87\xfbl\xd4\xc20\xb1\x08\xcbn&\x8b\xdaR{E/.z\x87M\x04\xf0\xd1d\xde|\x0b\xb8\xcbXh6\xd7\x97\x80\x8b\xcd\x82q!v\xc4\xb7E7\xe1)\x97h\x81\x0f\xd3B4\x02\x87\xea\x13\x8f\x06%2<GR\xf3L\xe0\xd7H}[\x92\x01t\xa3\x1f\xf2\x026\x9f\x1b\x0e\x0e\xf6\x99\xa4\xd1s\x88_\xca\xae\xdf\x9d\xeb;\xd0\tY\x83\x0f\x87\x19\xa3>\x16I\x86\xd8\x1a&\x13U\x9d\xc3\xd6RD/\x13\x1d\x1a\xa1\x02\x89\xecD\r\x08W\x9cpk\xb7\xb4\xed\x1bw\xdb\x8d_\x1c\xa2>6E\xc1\x80\xc2U2\x81\xa8O0\xa59\xfb"\xb9\x9cq\xa4\xeb\xc8i\xf6\xe2\xf8\x8b\x0c\x7f\xda\xff\x11\xb8c\x89\xc8\xcat\xb5\x80"\xefte\x85z\xe3\xfc\xe2\x1d\\\x0f\xd7\xf1\xe1\'\x89\xf6;_\x05\x08\xf6\xa4\x99T\x1a\xcdG\xe7\x15\xa6 ~HV~\x04\xb5ss\xc4\x9b\xc5oaC\x93\x94$\x86\xcf\x05!"g+1\xba\xed\xd99\xf3C\xaa\xb9\xf6\xed\x12\xf4\xce$)\xf5\xfcm\x94\xaefK\xb1\x1f;\x9c\xfd` \xf8\x07\xc0\xfbF\xfa\xec\xd0\xbf\xa9\xee\xcb\x08\xa8{\x07\xc2\xecD:\xd2\x15l@\x90\x7f\xf7\xca\xa0_\x809\xa7\x86{\x95C\x16Ya\xe7Y\x99"2\xa51\xea\xd1\r\x1c\x00\x17m\xec\xae\xac\xa88M\xac\xe6\xe6\xbf\xcfsj\x9dDP\xef\x01 \x18.\xc9\xa7>\x16%\xc5.x\x0b\xe3+\x8e\xbca\xbc+\x9c\x90H4\xdbB\xfb\xea\xee\x8bZ\xd6;,Hy\xfc\x06\x88o\xde\xf8wp\xd0\x1bLG\xbac\xc7n\x1e\xb7%B\x11\xe9*\x90\xab2\xd2\x95\x908I\xc6\x82)1\x0f\x83M\xbc\xcdP\x8e\x89\xd8\xa5\xe8\x83\xbf\x9a\\\xc9\xaa\x9c\x87\x91\xd8\x1c:\x18\xe0\xc0\x1b\x05"\xa7A\xa9\x13\xf4\xdb\x03H\xdbnN\xd6swQ\x8f\xaf\x05\xc2_?y\xe81\xd4D\xec7\xac>\xd9~\xe9|m\'6*\x0bi\xa5\xc4\xae[\xb0K\x8d::\x03\x87\x04\xe4\x14v\x00\x1c\x8fe\x878:\x00G\xad\x9b\xd4V\x1f\xfd\xbc4\x06{\xed< \xc6d\xbf\x02\x8d\xed\x0f\x8d\x98\xd9\x8b\x86\x10VdofbZ>\xcet\x87\x04b\x05!\xca< \x02\xc3\xae\xe1\x0b\xcf\x0f\xeeR\x1aW\x8d\xf0e\xe4E\x0e0O\xe7\x91\x80{(It\xa9\xd2\xdb1\xa9\xc6\x9e\xf8\x94)\x96\x93Ff\xfb\xa6\xfd_-\xf6J\xfe\x81\xb4G\xf5\xcb\xe5\x1ei\x93\x82\xca\xf37-\x82\x93\xd9\xc8\xcbu\x0b\x10\x1f}\x00\xe4h\xe1U\x02\xa9\x8a\xdd\xc4\xa7\x04v\xdf[\x9f\xf9\xc6)W\xe3\rF\xc4q`\xda\xe0&\x85\xc8r@h\xd6G\x1e\xa1\x0e\xc1\x13\xb0\x1d\x98\xad\x0e,\xce\xd4\xda\xa4\xa6@|\x8b\x9dr\x92\xe4\x03\xf6_r<\x9f[\xf08K<7\xcc\x95\xe4\x1b\xae\xb4`\x16\xba\xa40\xb6|\xa1&s\x0c\xf7\xc0"\xb9\xea\xeb\x16\xbd\nC\xde\xfa$\x06\x82\x02m\x02\xcaen\xd3\xa0$\xd5\xe7)\x11P\xf77r\xf6\xa7\xb7O\xb3\xb5\xe5\x99\x18Z\xe9V\xf0(\x04\xe6]0z\xf7\xb9\xd9\xdd\x05"\x88k\xb2sa\n\xd2E\xb6R[\\\x1b\xc7\xb9?\xcd"\x12\xe0\xe9\r\xbe\x92Q\xb5\x17V\x0c\xb9t\x14\xa0W\xea\xfd?\x028\\\xd1\x88\xc4\xe0\xbf\x9b\xe6\xf8\x1e\xf9\n\xc2\xd1\xf7<\xc2\xbf\x80\xd1\x8e\xe8\xf59\nYE\xdbjBmn}\xefrDmU\xd3\t\xe1[8\xd1\xfd\x10e\xf9\xae}\x8fg\x0e\xae\xdc/\x86\xca\xd4\xbb\xf0\xe4#q\xe3g\xd0\xe1O\xf55\xd5n\xac"\xf9i\xec!\xc0Xl`\x1e\x8f7\xac\x8e\xb5\xde\x80\xc0t\x83ETt\xbb\xe5<\xf1\xf4m\xa4\xc4\xa0\xe2z\xd2\x8f`4>\xe0T\xdeA\xf6\x166\xfa\x06\rA\xd9\x06\x0e\xa6+\x13\xe9w\xae\xb5M\x0f\x16\xf0\x0ew3\x0b}6\xf9\xad\xae,\xc4\xd4Q\xca\xee\x8e\xd2L\xc3\xdd\x9a\xe8\xa4\xf9\x84\xb6\xcf#\xe3)H\\]\xe9\xed\xe0\x9aWz6\x00\xb2"\xb4\x00\xf45\x99U\x8b6\xdc\x96\n\xe8\xd9h\xfce\xd8\xe5T/Z\x05\xa9^\xecW\xd3v\xe7q\xc8\x84\xfe\xc6\xe2R\x07kO\xfd\xe2\x85\x12\xb3eu\xc3\xb0\xc8\xfd\xd9\xc4\x9f9s\x01^\xf1\xfcm\xa9fL\x7f\xa8\xadd\x90\xdbw\x1f\xfa\xda\x19\xc0\xc2\x0f\xd7\x07f\xe1\xce\xe5\x93?\x02g%g\x90\xb1L\x8a\x15\n\x8c\xab,I|m\x85#P&\xf0\xfe\t\x9d\x82\xbe"\x98\xab-q.\x05O\xf6\xddc\x86\xd4\xb5\xe3=~\x0f\x1e,\xfeL\xee$\x04\xb4\xbc\xc0\xbc\xbf\xc8H\xcb\x19\xff\xcc\x1b\xcc\xdd\xe9\x0eB[\x94\xf9y\xa1]\x8f\x15\xe8\x937e\xa1\xf8D\x8f\xb9\x05!\xd3\xd5N2\\\xc7\x87\xbbl@d8\x9c\x1d0G#\x03\xee\xd1\xb5SM\xc4\xfco\x08\x8f\xceZ\xd7v+'
|
|
|
|
|
|
2024-12-14 20:35:20.754669 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xcfb6
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 1258
|
|
chksum = 0x6a87
|
|
###[ Raw ]###
|
|
load = b'\xc1\x00\x00\x00\x01\x00\x08\xfa\xbe\xc6\x1c\x11\xd6<\xa9\x00D\xd0\\\xbci\x1e\x94\xd2\xfe\x1b\x84\x05\xc5r\xe0\xa1D\x9a;\x97G\xd4P\xa1\xf9FG@\xf0\x98\xc0\x97\x07\xb8\xfb\xa4\xb7\xac\x8e\x85\xcf\x05j\x19\x1cGh\xd2\x11\x99\xa2\xf7\n#\xd9lK)\xec7\x85\x94\x1f\x7f\xd0\xa3\x18\xc1\xfb\xf8\x04\x93\x9b\xd6\x158\x8a;\x1e\xb5\xc4\\\xc9`\x13D\xe8R\xd68\xba\x9a\x84\xe3\x80\x98lQ\x19\x05s\xb0\xe9\xc6\n\xf3gYl%\xb0\xb5\x95\xe6\x8fr@ |\x8dh\x0e\xbaf\xd7\xa0_WlL~;ED\x962\xd7\x04|\'\xb60\xfa\xaf\x03\x13\xb9Qha\x95\x88F]4\x161\x82\x8bU\xc1\x0e\x8d\xc9\xba6\xa5\xb4\r\x1f\xd7\x9eacb\x87\xbc\x1f\x8f\xb6\xab\xc3\x9dp\x81Y7G\xeaN\x98,\x9cy\x15\xf7\x8e\x010\x92k\xab1\xf5\x11;\xe9\xf0\xaa\xc9\xa5\xfa\xddbA+M\x94\xc7V_\xf7\xf5\x8f\xda4\xbdF\xa7>\x94Xfr\x0eh"L\xbb\xb2N\x90\xa0\xfd\xf0P\\\xcb2\xba{\x1f\xc4\xf7Z\xba\x91pQ\xf5\xac\x88\xef0_`\x9a\x0b\xa7\x8a\xca\xa5v/y\x1d-\x00\x9d\x84\xe6B\xa5Vn\xf6\xaa\xea\t5\x1a\xfdD\x982C\x80h\xd1\x82\x8f\xa7\xe9\x01(F\x90\xfe\xe1\x91\x8b!\xbfH\x8d&Y\xcb\xfe\xb5>^fM\x1a\xf0q\x97\x98EV\xe6\xda\xd0\xd9`\t\xd6N\x9b\n\x8a\xb61\xbe5\xb2\xec\xac\x04D\xfe\x15\xdb>\xfcq-\xc2\xd7\'\xe2G\x80)\xe2\x00\xbeOO\x0f\\V\x8a\x80\x1b\xba(\x0bm\xeay/\xbf\x98\xa1E\xc2\x0c\xc2\x909\x99\xe7\xf3x\xb4\xa5\x8c\xb0o\\l\x8e"gq\xa8\xa4\x11\xa0\x15\x04\xe0.V\xc2Ka\x1cY\xdc(\xc2\xac\x812Y\xa7\xa6\xb3H\xc8)\x1f\xf2\x86\xb3\x048\xd3\x80\xe9q1\x8d\xf37c\xff 2Y\xffn\\KW\x9fe\'\xe9`\xabvW\xe9Y\x04i\x91\xeay-\x01%\xe9\xd1F\x1d\xd0\x94\xbe{A\x89\xcfD|\x9d\xd6\xeb"^P\xf3\x19\xca1\r\xb5i\xe9\xa4\x86\xdc\xaf\x1c\xe4Jmd\xeeX\xa4a\x92\xd80\xe5\xe2\x14O\x97v\xd4I\xf0\x91K\x92\xfbB\x04\xea\xcf\xc5\x95\x89\xf0\x83\x8a\x89\x15<p\xab\x96\xd4,\x07\xf5e\xd3\xc8\xa4\xa4\x8e\xccc\xcc\xf2\xc6=\x1a"W\xfb\xa7\x84\xa6b\x0c)\x8bR\xa09\x14\xe8\xe8\x0e\x1c:+\x8fuv\xce#`\xecl;1\xcbuq\xc7\xc4\x12\xbf\x04\x8a\xdeh\nq/\xabx\x07\xdbH\x1c\xb4\x07>\x16>|\xee\xd1\xbe\x01\xfe\xef6\x101\x8a6q\xc6\xaauc\xd8\xec\x1dt\xd9\xaeHG2\x9e\n\xe8\x9aB\xff\x98\xe2\xdd\xf0\xb9on\xae\xcej\x94\xb7\x90Gx\x0e\xc7\x7f\xf3\x8c\x1e\xa8\x1c\x1bs\xf1\x9a\x92_\x18\'\xcd[\xdd\x82\xb6\xe4\x97_\x85\xae x>\x95MJ3\x10\t\\\x17cj\xfcy*\xb4\xa2\x05?z\x86ysb~\x8e\nG\xdfh\x15\x9cK\x1dk\xfeW\xcc\x8b3d\xcb:\xf8\x86\x9fA\x15\xd9`B\x1c\x8a\x1d*\x9c\xb0"L_\'#1\xcf\x8a\x928\x18d0\xfcS\xe4\':\xb9T\xcd\x17\xa4\'\x80\x1d\x9b\xb5[Mn@+\xa4\xce\xb0\xd7\xdc\x83epi\x06\xcc\xc7\x19\xee]\xa0\xc0\xf8+W7\x98W1\xcd%=\x9c\xff\x9cZ\x9e\xcb\xde\x05>\xfe5\xa4\xfb.\xafV7\xb4M#\xd8\x18\x10\xe2\xa9\xe3\x18\x83\x93}|\x92\x08v\x1aS\x1e\xe1\xd6h\xe5zI!\xe9:\x94\xe9\xc8\xb5\xf9\x93D3\xd2\xd0\xd9\xfd\x05`\xa9Q\x1d\x0e\xb2\xe8\xbf\xe4\xee\x8cp\x89\x14X\t\x19\xb6\x10\xe6\xe4\x8d\xd2\xb1:I`\xd6E*?\x0b\xba\xae\xcb\x9d\\\x13\x1a\xa0\xac\xfc^\xa6\xed\xbaw\x93r\xec\x931\xc1p\xd1?\xbab\t\r\xb9$~I\xa0r\xe5y=\x15D\xb6yk\xc2\x1d\xfa\xfd\xd1\xd9\xc8\xb9\x8a\xc6\n\xf0\xfd \xf6)\xf2\x1b{N$+\x86\x92\x96.I\x0e\x9c\x88\xffZ\x95\xaf\xbdU\x91\xbb\x18\xc8\xf9\x17\xfd.\x89\x96\xa3\xa7\x18\xf6\x8a\xf5\x18\xdc\xe4\xef\x92\xb9\x99\x9d\xfd\xd1\xaa\xc7\x85\x141\x88Mr\x97\xac\x100<+\xe9\xce\x8e!\x01u\xdc\xfc\xab\x81\xd7SD1\x9e\xaa\xe8[%\xff+O\x1b\xc5/;k8\xd4y\xc4\xcf\x0c? \x0fQ\xef\xe7r\xb37\xad\x17\x80<\xbbo}\xcdv\xb1K\xff-\x96\xda\xce\xa1\xd7n\x19\x82z\x90{b\xb5a\x16\xf6|+\xf8\xfa\xdd\xfeq2\xa8*\x98dD\xd7\xcc\xecI\x84\tl\n\x8b\x9dt\x01s\x85\xff\xc2\xa1\xc0\xa8\x0e\x86\x90\xc2d\x1b\x14h\xe9\x0b\x96\xd0;`\t\x08\xcd/\x91l\x9b\xd6\xd5\xd9\xadv\x91\xed\x07\xeb=6D\xb2\x8e\xe2\xc1\x0c\x82\xc6\xd4\x1bv~\xfa\xd95\xdf\x08\x06\xae\xb7\xf8\x02\xb6\x90\x02\xca\xf4\x1d[\xc6Z6\xf4\xf6*2\xb7\x8b\xe5\xcb\xa8\x19|\x02e&>\x80L\xa6\x06\xa9\x12\xbda\'\nY\x9a\x97hzH\xd4\xebv\xc6w\x82E0F\x1e\x89~\x8a\xaa\xfe\x81'
|
|
|
|
|
|
2024-12-14 20:35:20.807443 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 334
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xd366
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 314
|
|
chksum = 0x53f0
|
|
###[ Raw ]###
|
|
load = b'\xea\x00\x00\x00\x01\x00\x08\xfa\xbe\xc6\x1c\x11\xd6<\xa9@\xdd \x9cMQ\x80X\xe9DZ\x94\xd4\xc6\xd5\x16yO\xb5\x90C\xe1\xc5\xac\xe9\xed\x88\x1d\x11\x91\x00F\x80 \xcb\x89\x8e \x8d6\xa6:\x19\xd6\x99\x03\x103fn\\\x10\xbc\xd6\xda\xec\x16\xb9\xfe)\xf3\xc4\x0c\xd2\xb4\xb2/\x14\xc3p\x8c\x1c_\xb6\x0f\xc1?\xd3XGC\xa1\xfb\xad\x9e\xcf<A\xd6\xb7\xdf\xc7\xe7\x90\x0b\xe1\xa7\x86\xce\xbb\x181\xe9\x1b\xec\x98W7\x03\xe5\xed\rD\x8b\xab\x87\x19q\x1d\xf1\x87\x96\x7f\xd3\xdde\x82\xcb\xce\xf9\xe85;\xb1\xd9\xf8(\xc5"\xd6\xe8HY\xdd\xd3\xb3\x1d\x08\xb6\x8a\xe8"\x1b\xddf\xc4\x80\xff\xd7@\xad6\xfe\xa6Kmd\xca\x99\xa9\x9a\xc5\xc9\xadl\xc0\x93M\xc7\xda"}5\x9e\xbaI$!z\xfaC\xcb\xaaa\xf8\x12fj\xa7\xad\xab\xa9x+\xa3\x06uY%1\x06\x91\x97\x9b\x18\x90\xb4\x1d\xca\x7fSY&O\xb1u\xcc\xbc\x7f\xad\x9e\xbc\xe6\xcd\x9c\xa5Z\xefu7(T\xf1\xebs<\xbc\xc0V\x1d\n\x19~k\x90t\x94\x13\x88bl\xe6\x08\x857\x1727$y\xbd1\x16\xd5\x1cZ\x18}\xe9\x01\xf0\xec\xbe\x17\x04\x8975\x1e*\xe7'
|
|
|
|
|
|
2024-12-14 20:35:20.824028 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 972
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xd0e8
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 952
|
|
chksum = 0xceec
|
|
###[ Raw ]###
|
|
load = b'K\x96\xad\x10\x98\xf4}{*\x03\x91\xbb\xb9Z\xcbu\x1ak\xef\xc8\x8f.\x89\x93\xbf\xcdZ\xad\x92\xddv,\xba\x1b\xcf\xa0\xc5\x14J\xc9ZI\xe7\xd59\x07Z\xf3\xca\xde\xef\xc8\x12\x17\xd3\xcc\xc1vs\x0cfL\xb9\x87\xe5f\xd7\xfb\xc5\xd6\xec8\xca\xd9\xfaI\xf1.\xa4v\x97R\x9a\xd9\x9d\x8c\xb2\xeb\xfe\x18\x84\xf8\xc2/\xd3j\x08\xc9\x96l\xf2f\x91\xfek,\xc8\xc7\xb7\x1aN\x94O\xe2\xc7\xf1\x8f\xa7h\xf7\xf9\x93Kz\'8\x18_-\\\xcf\x0c\xeb3\xb8\xeb!]u\xe2\xb7\xd5\'\r\xcew~\rU(\xd2\x15t\xf0/\x83CR#\x81\xac?A|\xad\x08\xa7\x1e\xc1\xf1\x03\x9c\x0e\xcb\x87\xbdds\xf4\xb35BN\xf7\xa7\x82\x00\xa0\\\ru\xbf\x7f{\x193h\xec<\x88\xaf=\x97\x81\xc86?v\x1e\x02\xfd\xa2"\xca\xc6V\xc53\x9c\xddKW\x95$\xe3-Au\x86A\xc7R\xa1\x0b\\+&\x8d\xf5\xf7s\x7f[\xf8\xf9\xb7\x02l\x91M\x8b\x04\x94sq\x87\xf5\xdfy\xbbJ\x8dywS\x19\xf0\x8ag\x14g\x95)\x1c.\x84\x96\x05\x8e\xe23\xcee\xe20\xbc\xbc\x8e\xc8EY\xca\x9f\xb8\xae\x98\x99\x0c\x94c\n\x7f\x94\x0e\xe7@\xe20\xc7\t\x02Hi|mM\x82\nJ\x81\xc7.W\xfc2\xb5\x99\xcb\xf3(\xef\x03\xde\xa4.j!\xe4{po\xf6\x87D\x06\xd6\x9b\xe7\xef\x91by\xf8E\n\'\x9fh,\xd0\x96\x87\xfdY\xe77__,\xb4\x15\x88\xc0\xd3\xf2Nu\xf8\xb0\xce\x0be\xc3\xf1\x99U_\x8f\x7f\xd9TJ|f&gA\xb3K\xe7t\xe2\xefi#:\\\x91EV&\xf7\xbeTY~\xb5J\x9e\x9b\xec\xc7\xf9\xb4\xbciwm\xef\xb9\x03\xfb\x1a\x8cs\xff\x82\x07\x0f\xcb\xd6\x1e)[\xa5\xb5Dd-\xd5,\x8d&V\xcb[2\xaf\xb5m\xb7\x18\xff\x8a\xda\xab|)cB5\x9c\x96\xfa\xd0(\x80\x98\xc2\x05[Bt\xac\xfb\xd4\xbb\xde\x17\x16r\xab#\xe2a\x00#\xf8\x11\xadV\xc9\xed\xc3\xe0\xd3#\xeda\x1e\xd9$\xc1\xa6\xdfH_\x902\x19\xba\xbd\xc1\xc7\x92\x03\r\x0e\xacKm\xa0L\x1e\x1e\x88K\xac\xea\x84\xc9\x001\x02\xf34\x9a\x1c\xd7\xed\x83m\x1b\xeb\xf1\xe9\xd4\x1e/\x1c\x9c\xaa;\xca\xc6D{%n\xab\xa5K\xbd\x14\xd9V\xe3\x13\xcafk\xe9\x92\x8a\xbe}\nb\xd6\xdf\xed*f\x19b\xc5\xf4\x89T=\x89TF+w\xaf\xd7\xf3\x82\xe4\x9e9\xda\xa5 h\xea`\xbb\xc1V\x90q\x90U\xe7\x03\xef\x14\xca(C\x1d\x08\x0f\x0f\xe2\xc0p\x00@\xc6\x88\xd3\xd4\x0b\xf1\x01\x84ti5\xd0.(\x8b\xde\xa4\x9c\x95\xfc!\x8e\xa9K\xd4@>k\xa6\x98uj\xd2\x14\x9cw"\\\x8f\xf3\x89\xd9\x15\x87\xbe:\x0b\x86\xad\xe7\x94\xc7d\xdb!|\xca\x01\x88b\xe1\xdb!M\xf1\xebb\x8f\'\xe9\x892F\xc1\x04\xe0\xc3H\x0f\xe3\xd0q\xcdQ\xa4\xc6$3\x8e\x1a\xa3\xeb#r\x87\x0f9\xc8\xc8`:\xfb\xfd\xc7\x94\x82q]\x008j\xc5\x1e\xc3\x83w{\x04&\x0fk\xefU\x1f\xa6(\x9a\x8dc\xd4F\xa8\xf8\xb4\xd5\xbc\xbb\xba\xd6\xf9\xc1\xbf\xa9\xc1\x8e\xb8\xf7\xc5\xe2[\x1b\xf4\x94\x1c\xb9)\x05\xadh8BF\x86\xb0\xa9\x81g\x96M\xe1\x8a\xe6pK;\xe2\x81\xb7"\x02-{\x12m\xe7\x8f\x8f\xf5\x83\xe3\x1a\x0614\xf9\x1cY\xec\x9a\xf0\x07\xa4\x05\xd8\xbe\xb5\xfb\x80j\xfd\x0ec\x82\x0f*\x87\xcd\xfe5\xfac\x93\x92A`u0\x94\xe2c\xba\xc1L\xe8\xf2\x8d\x9df\xd4\xf25~\xe6y\xc73:a5\xa4\x8e\x19\xc5\xda\xfe\xba2\xe6K\x891\xf7\xac\xb0B\xa1\xea#\xbf=x\x90\xbc\x7f\x82\xde\x0b\'\x95\x9b\x8df%\xca\xcd\xa1\xd6\x17v\xfd}\xa6\xb4\xa7\xe3\x96j\x8fB\xd6\xe0H\x8b'
|
|
|
|
|
|
2024-12-14 20:35:20.894859 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xd469
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 55
|
|
chksum = 0x5f27
|
|
###[ Raw ]###
|
|
load = b'Y\x06\xacv/V\xe3Q\xf4\xc1\x00,\xe8\xab\x80Y\x9d"\x86{\x05\xc5-\xc1&\xd4\xcaERy\xcb\x12\xf5\xd2\xee\xa0\xc6K9\x1f\x9casc\xd4\xf3\xb1'
|
|
|
|
|
|
2024-12-14 20:35:20.920082 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xd480
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 32
|
|
chksum = 0x7da5
|
|
###[ Raw ]###
|
|
load = b']\xd4Q\x8a\xb8\xb1kP:\xc5\xce<\xcf~\x14\xf0\x86\xf1#\xaa\xaeq\x1dL'
|
|
|
|
|
|
2024-12-14 20:35:20.939690 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1274
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xcfba
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 1254
|
|
chksum = 0x67f3
|
|
###[ Raw ]###
|
|
load = b'G9$\xca\x1e\xf1\xc3NR\xb8\xd1\x80\xac\x05@\x18@\x13\x01\xcd\x99\xf1\xc8F\xc4\xaf\x95\xaa\xf6\x96\xc7\x9b\x06=/\xcf\x03\x97\x92\x9aD\x02)iw\x99YEa\x81\ncp\x1fy;\xec\xbc$\xb5Z?\xb8C\x1av n\xf4\xc3\x10\x11e\x9b\xab*\xf1\xd8D~\x06\xb4RN\xf6\x9a\xbf\x1c\x08\x04D8}\x0f3 \xb30\x10\xae\xbfl>H\x85Fu;\xd0<\xf1E\xe1H\xd5\xf7\x1c\xec\xd1\xcd\x0e<\x02\x1b\x91\x8af\x03\x9f\xc5\xfa\x7f\x82\xed\x1f\xbfY\xd3\xde1\x18\xe2\xb2\xf6R\x06c\xab\xd1\xb6\xc9\xff\x08\xe5tl\xa6\xd7\x9a\xb1g\xe5\xba\x86\xe1,\xef\x93\xcb\x98\xad\x18\xd2)\x8aA<\xad\xe0\n\xaf7\x8f\x9cL\xcc7*\x87\x9c!+I\x13Qs\xc8~\x80\x880\xc5=\xb6\xefU.\x86\xb2\xbf9\x03\x07Oj\x9c\xd74\x90\xbc\xfd\xd6\xc7!\xe1\x9eP7\x98\x14\xae}\x82\x96EoG\x11\xa9p9\xc9\xb5\x19$\x7f\x0b/\xa9\xbf\xad\x96\x80\xb7\xb6\xfc$\xc2\x18o\xe1s\x11Y2\x97e\xbe\x95\xdd\xafM;\'=\xe4u\xf4\x10\xf9\xd9\xa6\x81\xa0W\xe3V\x93\x8f8\x82\xc1}\xe0A\n\xd8\xaat\xd1\xecC\xa7\x96`\xf4r{\xc1\xd3\xe9$\xea\xe8\xd9\x0bI\xab\xd5\xdf\xb0\x02\x7f!\xfc8\\\xe1\x8f\x022\x9d\xc2M\xae\x14s\xaaY\xa6<\'\xba<a\xa6\xa7r\x16\xa3\x9fd\xf8\x01jg\xb3$\xf9\x82=\x81\x0e~`]\x15\xa5j\xa2\x8b-\xc1\x1eI\x98\xff\x8b*\x83G\xc2\x10\x06~\x96\xf6k[W\x91\x0btF\xd8p\x9c\x85\xd8\x98\\\xd1\xd3\xfa\xb4\xaa\x93a{NQ\x86\xb8(!\x92\xe5a\xfbXt5\xf8_mN\xa7\xfc\x07\xa2\xb4\x98\x88g\xf0\xe5\xdb\xdd\xaf7\xaa|\x02\x82-/n\xb3\xe0t\xba\xd6f\xf8ME#w[]\x13l\x11\xe1\xb1\x90g\x98lc\xd9o\xebp\xd2\x9b7\x87\xb5\xe8\xb2\xbeo\xcd\x19]\x16\xa4\xdekG8\xf7\xb3\xcf\xc4\xaf\xf4\xd7d~\x90t%\xef\x16F\xd3(\xf1\x87\xc8\xb2b<{QX\xef\x9c\r\x04\xcd\xc1\xfb\x9c\xc0=\xae\x93\xa4O[\xa6;\xe8\xd3eeY\x10:Exb;\xcd\xb3H\xb3!\xf4\x01\xe8\xdb/\xcd\xf7\x9f[Fm3\xec1^\x05)YE\xcc\xd0\xf6>\xf5}{\xa3\x90\xd1\xa7"\x81\xb8\x8b\xacQ\xeb&\xca:\x1e^\xceW\x84$wflm\x14\xd6:\x93\x1e\x84g\xb3\xc5\xa6\xba\x7f\xa8D\xe0a\xef\xbf\xd7\xe4\xb2\xfb\xe1\x8e\x14\x94\x11VJ\x0b\xa8\xe1$e\xc3\x15\xe2\xd8iL<\x1eN\xcf;\x1e\x9e~O\xab\x0f\xef\xd2DC8rO\xe4\xf9=\xd4\xeb\xceRja\x8c\xcf\x04\xd6;\xc5}\xab\xfd\x98ny\xc1\xd1K#w<]\xc21\xa1^x\xb0J\xbe\x98fm\xc4\x13b\xfc\x9f\x82&\x1b\xfe\xe26\xf4\xdb\xe1;f\xaa[1\xf7R\xf7\x04\xc2\xc0\x1e\\\x17\xe15\xd9\x97\xe7\xc1=\xd3\x8d\xdd\xec\xf9\xe1\xe5?\xf0U\xc8\x16{\x89!\x84\x98\x92d\xed\x07\xa5T\xc2\xfa\xd5\x83A7*H\xe6\xb55.\xd2\xfd\x11\n\xc2\xfaA\x12R\xcdY)\x84\xd0a\xbf\x9e}\r]\xe5\xb9\xaa\x8f\x8bZ\x02(*7N\xe30\x0e\xe7\xcf\x97H\xe0\xbb0B\xca\xeb\xb4P\x15 \xc3\x9d\xaf0\x8f\xa9\x9b\xf8\x06\x15\xf4JZ\xb3&e\xe0@\t"\xdb\x99\xff\x80\xea:I\xf5eF\xf9Ka*a\xd4\x19E1\x19\xb6\xbbT{*\xe9\xdd\x84\r\xdd"\x8e\xe4\xe7\x12R\xe8\x97\xe1c\xa6\x0c\xdc\t\x8az>\x9d\x18\xaa\n\xb6]\xe2s\xc48\xe3\xaa\xe1\xf8L4\xb2\x18\xe1\xbd\x89^\x91\xd9*\x89\x11G\xe5\xcfN\xb5\xd1\xc3\xdft\x1ccco3\x89\xe5sy9\xd4n\x80\x0b\x8f\x13L^\xcd\x909&\x0f\xcb\xa3T\xa6\xc5\xe3\xd9\x10\xdd\'\xee\xf4M\xa9^8<\xbdc\x1fU\xa0\xa5#S&d\xde6\xb6/\xa59\xad<\x023>\xcc,Ne\x14\x87\x15I\x01\x17\xb0C\x19[_d\x0e`\x0f;\xfb\x8a\xd0i\xf0\x1df\xb3\xad\x7f\xb6T\xc9U|\xa2\xe9\xda\xeb\x1f\xb4B|\x87\x8e@\xdbW\xe6\x1aJ\xb6 }\xb7\x19m\xe0\xc9\x0f\xec\xc4\t\xf4\xf1\xd0\x07\xa6\xe1\x1b\xd7+\x9e\xb0\xd2!1\xbcgQ:\x00(\xd8\xa6\xba\x02\xa8\xfb\x83\xa0\xb7\x97\xb2\xd4\x9a\x14B\x83|r[C\xde\x82&\xcd\xfa\x1c\'\xa9{\xd6SwU\xbf\xcai\x1a8\x88I<\xb4Ll\x16\x90L+a\x98\x12\x0c\xbb_h\x9d\xe3\xc0\xf1Eg\xe7z;\xd0\xb0\xf2-\xf3,\x93O\r\xe5\xe1\x8f_:\xb6\xeeo\xdb\xa3&\xc8\r\x06\xc1\x81\xd6\x97\xccO[J\xba\xc4m\xd7\x07\xf5\xe3\x86\r\xf9H\xfd\x87\xa0\xe2hD\xf4\xee\xa6\xced\xaa\xd0\r?+\xef\x9b\xc2!\xe0r}\xf0\xca\\h1\xad\x83\xbd\xcc\xa0\x84IP\xber\xc5\xab\xcd\xac\xbb\x1d\x1f\xe5R\x01\x13\xb8d\x17h\x90\xb9\x1b\x17^\xcb\xc8\x11\xc7\xe6\x0b\xe3\xd3a`\xcc\xf0m(/\x82\xc8\x81?'
|
|
|
|
|
|
2024-12-14 20:35:21.022683 - Ether / IP / UDP 192.168.1.11:55785 > 216.58.213.74:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 106
|
|
id = 5262
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 216.58.213.74
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55785
|
|
dport = https
|
|
len = 86
|
|
chksum = 0x6fa0
|
|
###[ Raw ]###
|
|
load = b'\xe9\x00\x00\x00\x01\x08\xfa\xbe\xc6\x1c\x11\xd6<\xa9\x00@=\x1bi"B\xce\xb8x\xd9\x0f\xcc\xdemM\x80\xcfe\xee\xbc)D\x9b\xa5s\xf7\x01A\x0c\xd6\xb6Y\x16\x05\x8e\xc3\x06|\x97t\x0f\xfe\xe1\x0cf\xe4\xe0\x11\xca\xc0sE\xfbY\xe4N\xe6\xbe{;\xa29D'
|
|
|
|
|
|
2024-12-14 20:35:21.050805 - Ether / IP / UDP 192.168.1.11:55785 > 216.58.213.74:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 59
|
|
id = 5263
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 216.58.213.74
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55785
|
|
dport = https
|
|
len = 39
|
|
chksum = 0x6f71
|
|
###[ Raw ]###
|
|
load = b'F\xfa\xbe\xc6\x1c\x11\xd6<\xa9\x04a4\xc8\xc2\xe1\xe8=\xf1 ZoeKhh\xbf\xdc\xf4\xda\x82U'
|
|
|
|
|
|
2024-12-14 20:35:21.071662 - Ether / IP / UDP 192.168.1.11:55785 > 216.58.213.74:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 63
|
|
id = 5264
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 216.58.213.74
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55785
|
|
dport = https
|
|
len = 43
|
|
chksum = 0x6f75
|
|
###[ Raw ]###
|
|
load = b'P\xfa\xbe\xc6\x1c\x11\xd6<\xa9\xef\xc1\xe5U\r\xd0\x04\xf3\xfc-\xa4\x90\xc5\xb4\xb7\xd5\x02\x0fm\xb5\xd0\xb8\x8bC\xb0\xe0'
|
|
|
|
|
|
2024-12-14 20:35:21.089879 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xcfb6
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 1258
|
|
chksum = 0x685a
|
|
###[ Raw ]###
|
|
load = b'O\xd6\x1d\x94\x02\xcby\xbcD\xe7o/\xef\xd2\n\xb6YOvn"\xbc\xdb\x845\xa0\x1e \xbf\xbb\xfc\xbc)^\xc9\x82\x14A\xb8C\x14\xf7Z\xd5\xbb\xf7\x8e3W\xd7.\xdb\x08n\xb5)\xaaJ\xebP\xbfc\x98\xb5}~\x86a"\xeew\x11Q\xd2i9\x9b^\xba\xd0:\xd1\x84;\xd2\x02\xdfq\x01\xfb\xf8r6\xa1\t\xc9\xe5\x8f\x0f\xd1\x92\xe1t\x14!\xf0q\xc4e\xdd?;u9\xe6\xb6tVN\xc5\xa9\xc7\x08\xecf\xb7\x87\xb3\xf6|`\'g\xe9\x04\xf3\xe9\xe8r\x9f\x93H\xcal\xe4\xd0\xfc\x88\xfb\xde\xd4\x83\x97m\xd8,RU\x8c\xe3I\xb5\xb4\x148j\xd4u.\xc2\x15\xb4\xce\xed\xbd vV\xcdrA\xf1d\xd0\xa8\xc1\xd3\x8c\xf82\xf5\xd1\x8eb\xea\x1b\xf2\x11A\x7f\xcf\x05-\x12Z\xb4\xf4\x96f\x19\xaca\xbb\xedi\xd4\xd3\xea\x1f\xab\xfen\x150\x1ak\xf9\xa2c=\xa4\xd9\x7f2]\n\x1e\xc1.{T\xa8\x89Y%\x1b\xbc\x01\xeb%E\xcc\xb9u\x16\x01Or#\xde\x8bK\x8b\xb0|\xb7\x9c\x82\xc6Y\xc3\x9f@I\xde\xc5\xdb\xcf\xfal\xe7{\xfdW\x11\x03\xf9QU\xd4p\x1d;\xf2ld\xc6\xbaK\xf3\x1f{\xbc\xcf]\x08\x12S\xc4ey\x100\xedI;Z\xed\xa4\x8a\xbaN\x0b\x08&/ANN\xb0\xc5\xcby\x97\x0f\x93\xb3\x1f\x9b?>\xe6\xe7\x0b\xfd\x17\xfc\x17No\x87(\xf7\\W\x92\xecz{\xe6\xf7O\xe3\xd3\xd2\x17f\xd2{J\xc6\x99:z\x01\t8}@d\xdf#E\x82:\xa8-\xad\xcc\x80J\xe6\x99\xf1k2\xab\x8e\x9b\xb6<4&\x12\xae\xc2\xe5\x84\x92\x10\xc5\x9e\xb0er:E-O\x0b\xd3[\x17\xfb\xb9x\xe5\x0f8_:\xf9\xa4\xcb\xe9\x1e\xf4{%\xbd\x15"2\xc8\x97\x9c\x13J\xc2\x8c"i\xc5M6\x1a\x95\x86+\x95H*\xc6\xaeO\xear\xa5\x95\x02\x8f\xe15\x83\xa2\xe5\x8c\xc4\xce\x1a\xae\x8d\xf1Y\x15:\x8f\xd8\x13\x13\x98\xd5)S8\xc0]\x96\xac\xd9\x02\x15\x9c\x9e\xf4$8\x02\xb2F\x14\xdd\xfb\xfaZ\xc9^\xbf\xfe^\x8a\xd1:\xc45\xa4\x84\xc8\x00u\xff\x8c\tS\x90\xf9\x1ba_\xc7G\xda\xdeO\x17\xce\xd9\xd8\xdc\x86\xb4\xbc\r\xb1T\xc5\x15L\x81h;\xcd&m&\x11\xa9\x07\xd3y\xe7\x12\xb4\xe0\xe5\xe2\x91\xfe*b\xd5\x91B\xf4}\xa6\xa9\xaeB\x19<\xc4\xed\x08\xb5\x07y\x08\xd8\x02v\x03\x8c\xb7\x05.\xbd\x10\xff\xc4\x81\xceH\x9f\xcd\x1e\x99\x80\xb6\xda\n\xb3\xb0\xbb\xaeG\xb7\xac\xc5\x9f\t\xd3\xea\x97\xdb\x1c\x1c\xef,K-\x07\x8fr\x8a\xb6\xa2{\xd7\x1a\xd4\xfeg\x1e\xa3\x10\xbf\x05\x9e\xa8\x04\xb9\r\x03\xd4{\xf1\xfek\xec;\r\x17\xc1\xba\xe1C\xe4_\x07D:\x85]\xa4\x03\x15\xec\x88\x08si\xe2=k\xe8\xfb\xdc\x10\x12j\xcc\x93L+\x89\x19\xf8\x8e\xc9-\xc8}\xa8O\xc6:Fg)\xe8\xf6?\xfe\xf4\xeb*j\xfc\x7f\x95\xa1\xff4\x98\x99\xa9\xef\x1c\xa4$M\xb6k\xf4\xad3\x0c\x8a\xa1\xc4\x80g#\xc9\xa8\xe7sj\xeb\x94\x9e?\x19ua\x88\x9a\x8b\xaf\x1b_\x14\xf5\xfa^\x94:@\xc2\x1b1:\x8d\xe3Q\x08\x03X?>-\xfd\xab\xd0$\xb8\xf4 \x0f\t;\x15{C\xcah\x13|(e\x85\x1c\x89\x88\xf9y\x82F\xf5\xe7\xfbf\x95\xed\xdaj\xb7\xe1\x95\xfa\x91\xad\xc9\xec#0@T\xf6$\t\x86\x87\xd7n\xc6\xfc`b\x16\x17\x91\xef\x9e\xad\xed\xbe_\x7f_\xed\n\x0e\x8cq\x1d\xae\xe4\xe5\xcf\x83\xdc\xf7\\,B\xc8\xbd\xed\x05l\xe6\x98\xc0\x92\x81}\xa0\x90d~\xdb\x93\x0b#\xec-W\xb7\xab[\xcb{2\x8b\xde\xbc\xa7L\xe6m\xeb\x9b\x8b\\-)3?\xd3\xb8\xd2\xba\xa0\xf6vCEk)\xad\xb4*rXU\xce\xa7\xa5\xbaU=\xe8\xfd\x95\xc1\xa4\xe5\xe5\x83\xf9#\xec\xe5\x89\xcfiPpk=\x9b\n<-9\xd8D\x94 \x85FJ^\xb6\xfa\xc4]\x807.\xa7\xd1\x1f\x9d\x04\xd7&X\xe6\xc6\xdczo\xfb\xbb\xca\x91\x99\xe4\xa5\xb4p\xed\xc0\xc7\x9de3\xe6<O\x10\xd5\xd4\xf1\x93\xa5\x0c\x7f\x9e\xb1 \x96\xb8\xe2p\x1c>\x1d\xfe\x897c!N\x9c\x1f\x02%\xe1\xff\x1e\xea\x1e\xa3\xe2\xb4\x8dX\x8b\\\x98?%r\xaf\xbb\\\x06\x91\x9f\xee\xb6\xc8\xa5\xa80:\x02\xda\xeb\x97\xad\xfc^\xb4\xdf\x9f$E\xea\xd6d\xef\x0e~[\xd3\xcf\xc6\xa3\xe4(\xcc\xceK\x92\x89\x80\xfa\xb9\'r\x1c\x1d\xeb|\x10\xf5[\x14eG\xac\xc1\xd9_%\xab\xc5\x0c\x98\x96\xc4v{\xd8\xe5@\xfd\xfce\xe0\xb0\x83\x93\xbcX\xcf\x02\x88\xa7\xd6\xdc\xa0%\xdb$5a\x80\x83\x80\xbd\x86q\xb6>\xe8\xc9\xc2\xc3\xea\xfa\xa6ap>\xde\xb0\x8ek\xc61e\xdc\x0eK\xa1\xea\x84\xd2\xdc\xb8\xd7\xbc\xc7\x85\xfd\x1em\xc7\x17\xb9\x00%\xda\x0f\x15\xd9\xad\x1a\x1f\xe8\xb7\x96B\xf3O\x04\x00\x01\x07B\xd2\xe5A\xa3o\xb7sN\xe1[\x1b\x80~\x90\x8e)\xd1\xa8e\xffs\x05\xb8\x1b\xb0\x02V\xc8I\xff/=\xdf\xde'
|
|
|
|
|
|
2024-12-14 20:35:21.164502 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 270
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xd3a6
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 250
|
|
chksum = 0xdb13
|
|
###[ Raw ]###
|
|
load = b'P`\xb0\x93\xd2\xed\x8aFZ\x8e\x879\x1d\xe6\xb8\x05\xf1J@\x11\xeb]\x11\xf7\xf7lo\x02\xddP\xb3\xb4\x90\x83F!!\x994\xe1\x11\xacT_\xbdj\x8d\x84\xd06S\x81\xb9<\xc7\x98\x93\xd7\xb5\xa7\x1ck\xa3on\xbf\xb3Y;\xe5\xca\xfc\xa6\xfe\x02L\x9by\xa5\xf8\xb4\xd1_\xf1\xec#\x11\xbc/\xe54\xb5\x17whMC\xd4\xbfC\x97f\xda\n}VS\xda\xca\xda\xca\x0f\r\xe6\x14\xbb*<\x01\xcd\x8a\xd2\xbd"\x9d ;\x9b\xf8\xb0\xb3\x83q\xff7\x01t\xddR\xc0(\x1a\xc7\xc1\x80\xbbB\x1b\xca3\xefN\xad\x7f\x85\xbe\x8eJ8H}\xea{\xd4A\xefO\xccF\x12\xb2\x80\xfb\xfe\x97i|\xbe\n\xa9M,\xd3\xb4\x1c\\ \xbd}\xa6\xc8\x80"\xb0_\xad\xb3\xb2\xc1\xd1\xbb\x9f\xbda\xc2\x963\x94\x15\xf6\xc1\x8d\xe1k\xee\xfeL\x11\xb5X>c\x86Y\x9b7\xc8\x8f\x11\xdb\n}B4\xfd\xa1\x80\xb1N\xac\x90\xfa'
|
|
|
|
|
|
2024-12-14 20:35:21.177578 - Ether / IP / UDP 192.168.1.11:55785 > 216.58.213.74:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 59
|
|
id = 5265
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 216.58.213.74
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55785
|
|
dport = https
|
|
len = 39
|
|
chksum = 0x6f71
|
|
###[ Raw ]###
|
|
load = b'@\xfa\xbe\xc6\x1c\x11\xd6<\xa9^\xa5.\xe7f\xdc\xc7\xb7\xed07\x03d\xc6v<\x07\xb7\x1eju\xce'
|
|
|
|
|
|
2024-12-14 20:35:21.185625 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 148
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xd420
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 128
|
|
chksum = 0xef81
|
|
###[ Raw ]###
|
|
load = b']\xc8\xd1\x0f\x04<\x82Ifu\xf4\xc6\x02\x05\xe5\xd0\xf9\x1a\xc3\xf5\xfaK-yvJq\x1b3\x9f\xadZ;c\x96\xd9nx\x17`\xc5\xdb\xd6H\xba\x11\xb5\x04\xf2vq4\xfd\xaen\x8b4*\x1c\x82\xf8\xcf\xb1\xd7\xdc\x01s\x8b\xc2\x9ej\xd7y\xd1\xf7\xe6\x11>\xd8\xd6\xe1\xd9\x80\xfa\xd5@\xd2\xeb\x91\x96\xd4\x92\x8a\xfeVe]\xea\x14\xc1\xc6`\xc3\x03\x8a"$\x80\xd2\xce\x06\xdc\xfe8\xa8\xca\x84\x84\x15\x1a'
|
|
|
|
|
|
2024-12-14 20:35:21.188879 - Ether / IP / UDP 216.58.213.74:https > 192.168.1.11:55785 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 53
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0xd47f
|
|
src = 216.58.213.74
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 55785
|
|
len = 33
|
|
chksum = 0xb658
|
|
###[ Raw ]###
|
|
load = b'[\xe7\xdd?\x9c\xb4\x9d\x9cb\xf5\xa4\xc6w\xfa\xa1\xb7\xa7\xbb1\xc4\xd9\xb8&V\x90'
|
|
|
|
|
|
2024-12-14 20:35:21.191560 - Ether / IP / UDP 192.168.1.11:55785 > 216.58.213.74:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 60
|
|
id = 5266
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 216.58.213.74
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55785
|
|
dport = https
|
|
len = 40
|
|
chksum = 0x6f72
|
|
###[ Raw ]###
|
|
load = b'C\xfa\xbe\xc6\x1c\x11\xd6<\xa9\x0c\xdf\xef(o\xc1u\xe0\xd4\x9e\xef\xd1C\xe0W\xf5\x08=P;D\xc6g'
|
|
|
|
|
|
2024-12-14 20:35:21.194906 - Ether / IP / TCP 192.168.1.11:40788 > 35.186.224.41:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 8643
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40788
|
|
dport = https
|
|
seq = 948637544
|
|
ack = 1994427668
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc5cd
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x17c\x018)\x1aG\x0c\x08n?\xea\x0c\xf7jj\x94\xe8\x88\xc6\xa7\x8e?K'
|
|
|
|
|
|
2024-12-14 20:35:21.196944 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:40788 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 49790
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xbcba
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40788
|
|
seq = 1994427668
|
|
ack = 948637572
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1051
|
|
chksum = 0xf90e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:23.164253 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 417
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc5a8
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 397
|
|
chksum = 0xc02c
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: upnp:rootdevice\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::upnp:rootdevice\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.167244 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 489
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc560
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 469
|
|
chksum = 0x502d
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.168966 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x83e4
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.170471 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 485
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc564
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 465
|
|
chksum = 0x7632
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.171947 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8392
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.173238 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 465
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc578
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 445
|
|
chksum = 0x8a6f
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:device:WANDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.175309 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8394
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.176761 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 497
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc558
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 477
|
|
chksum = 0x3a9
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.178156 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 479
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc56a
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 459
|
|
chksum = 0x81a1
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANIPConnection:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:service:WANIPConnection:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.198208 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34208
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55786
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 41437
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.201526 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34209
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55787
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 41438
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.203288 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34210
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55786
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 41439
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.207620 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34211
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55787
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 41440
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.209208 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34212
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55786
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 41441
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.211541 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 55786
|
|
len = 76
|
|
chksum = 0xba3d
|
|
###[ DNS ]###
|
|
id = 41437
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.213124 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 55787
|
|
len = 89
|
|
chksum = 0x4cb5
|
|
###[ DNS ]###
|
|
id = 41438
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.214941 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 55786
|
|
len = 90
|
|
chksum = 0xb2da
|
|
###[ DNS ]###
|
|
id = 41439
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.218427 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 55786
|
|
len = 81
|
|
chksum = 0x6e2d
|
|
###[ DNS ]###
|
|
id = 41441
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.219842 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 55787
|
|
len = 51
|
|
chksum = 0xe5
|
|
###[ DNS ]###
|
|
id = 41440
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.241158 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34213
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 55788
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 41442
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.244047 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 55788
|
|
len = 81
|
|
chksum = 0x8814
|
|
###[ DNS ]###
|
|
id = 41442
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:23.420360 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 479
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc56a
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 459
|
|
chksum = 0x81a1
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANIPConnection:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:service:WANIPConnection:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.422104 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 497
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc558
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 477
|
|
chksum = 0x3a9
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.423601 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8394
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.425281 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 465
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc578
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 445
|
|
chksum = 0x8a6f
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:device:WANDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.426649 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8392
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.428176 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 485
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc564
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 465
|
|
chksum = 0x7632
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.429509 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x83e4
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.430742 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 489
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc560
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 469
|
|
chksum = 0x502d
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:23.432111 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 417
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc5a8
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 397
|
|
chksum = 0xc02c
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: upnp:rootdevice\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::upnp:rootdevice\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:24.193633 - Ether / IP / TCP 192.168.1.11:41802 > 172.64.155.209:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 48035
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 172.64.155.209
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 41802
|
|
dport = https
|
|
seq = 437917378
|
|
ack = 116824022
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0x9e1
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:24.212142 - Ether / IP / TCP 172.64.155.209:https > 192.168.1.11:41802 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 28155
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xcd03
|
|
src = 172.64.155.209
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 41802
|
|
seq = 116824022
|
|
ack = 437917379
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 162
|
|
chksum = 0x98ed
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (437917378, 437917379))]
|
|
|
|
|
|
2024-12-14 20:35:25.549488 - Ether / IP / UDP 192.168.1.28:40175 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = 6c:f7:84:e4:d7:de
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 153
|
|
id = 33478
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 1
|
|
proto = udp
|
|
chksum = 0x44cf
|
|
src = 192.168.1.28
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 40175
|
|
dport = ssdp
|
|
len = 133
|
|
chksum = 0x7b40
|
|
###[ Raw ]###
|
|
load = b'M-SEARCH * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nMAN: "ssdp:discover"\r\nMX: 1\r\nST: urn:dial-multiscreen-org:service:dial:1\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:26.184234 - Ether / IP / TCP 192.168.1.11:42631 > 35.186.224.26:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 5434
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42631
|
|
dport = https
|
|
seq = 20160527
|
|
ack = 44088017
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 510
|
|
chksum = 0xc5a3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:26.197638 - Ether / IP / TCP 35.186.224.26:https > 192.168.1.11:42631 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 54938
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xa8a1
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42631
|
|
seq = 44088017
|
|
ack = 20160528
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1022
|
|
chksum = 0x66b9
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (20160527, 20160528))]
|
|
|
|
|
|
2024-12-14 20:35:26.252166 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34214
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56046
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 1014
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:26.253990 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34215
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56047
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 1015
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:26.255413 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34216
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56046
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 1016
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:26.256783 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34217
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56047
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 1017
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:26.259146 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56046
|
|
len = 76
|
|
chksum = 0x5721
|
|
###[ DNS ]###
|
|
id = 1014
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:26.261140 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56047
|
|
len = 89
|
|
chksum = 0xe998
|
|
###[ DNS ]###
|
|
id = 1015
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:26.262764 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56047
|
|
len = 81
|
|
chksum = 0xb11
|
|
###[ DNS ]###
|
|
id = 1017
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:26.272133 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56046
|
|
len = 51
|
|
chksum = 0x9dca
|
|
###[ DNS ]###
|
|
id = 1016
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:26.294633 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34218
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56048
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 1018
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:26.297943 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56048
|
|
len = 81
|
|
chksum = 0x24f9
|
|
###[ DNS ]###
|
|
id = 1018
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:28.070531 - Ether / IP / TCP 188.114.96.5:https > 192.168.1.11:42259 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 84
|
|
id = 43053
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xbe4b
|
|
src = 188.114.96.5
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42259
|
|
seq = 2693639193
|
|
ack = 4062860605
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 9
|
|
chksum = 0x68b1
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00'U\xe8\xc2\x14p\xb7fPy\t/\x1e\xbf\x9a\xbf^\xa4'\xe6 \xffx2 \x92/_\x86\xd5\x0c\xbaM)u\xb9H\x90\x16\x14"
|
|
|
|
|
|
2024-12-14 20:35:28.080118 - Ether / IP / TCP 192.168.1.11:42259 > 188.114.96.5:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 49548
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 188.114.96.5
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42259
|
|
dport = https
|
|
seq = 4062860605
|
|
ack = 2693639237
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xde68
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xee\xe0\xd0\xe4\xdb-\xfd)=Q\xd7\xa2\t\xe3\xb5!\xddn\x87Mo\x966U\xd7*R\xec\x14\xb6'
|
|
|
|
|
|
2024-12-14 20:35:28.082470 - Ether / IP / TCP 192.168.1.11:42259 > 188.114.96.5:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 49549
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 188.114.96.5
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42259
|
|
dport = https
|
|
seq = 4062860640
|
|
ack = 2693639237
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xde68
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xd5m\tefS\x85\xcbU\xf5\x12\xca;\x8c\x01\xf9\x16\xd7\xc9#\xdfDN=\xd8\x15W\x9c\xa5\xa3'
|
|
|
|
|
|
2024-12-14 20:35:28.097574 - Ether / IP / TCP 188.114.96.5:https > 192.168.1.11:42259 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43054
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xbe76
|
|
src = 188.114.96.5
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42259
|
|
seq = 2693639237
|
|
ack = 4062860640
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 9
|
|
chksum = 0x9673
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\xf0\xb4\xe1r'
|
|
|
|
|
|
2024-12-14 20:35:28.099788 - Ether / IP / TCP 188.114.96.5:https > 192.168.1.11:42259 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43055
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xbe75
|
|
src = 188.114.96.5
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42259
|
|
seq = 2693639237
|
|
ack = 4062860675
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 9
|
|
chksum = 0x9650
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\xe6B\xdc\xe6'
|
|
|
|
|
|
2024-12-14 20:35:28.221124 - Ether / IP / TCP 192.168.1.11:42760 > 20.50.88.242:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 701
|
|
id = 28822
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.50.88.242
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42760
|
|
dport = https
|
|
seq = 2716058156
|
|
ack = 996188136
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 515
|
|
chksum = 0x3187
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x02\x90\xe3\x1bE\xda\x03G\xd8\xce)\xb1\xbd\x92?py\x13lp\x11E\xe7\xa4\xf9\xe4\xcbt\xfb\xf3-\xce\xa0\xc5\xf9T{M\xee\xc1\xdaOf\xccb\xc3\x05A\x03\xe7$\x8f\x06\x87\xf7$\xca\xbb7\r\xfd\x88)t\xbc\xa6\'\xe1<\xe1\xabD\xa9\xa81~\xe6\xa3\xd6\xb1\xf4\xe8\x97@F-q\xfb\xd7+,\x9f^\xc0\x89y\x8a\xc58\xb6\xaa\xe6Q\n\xce\x0c\xaf\x12\x12\'\xaerj6G\xb7\xcaE\xe8It M\x8c\xa2o\xad\xc1\xaa\xc7\x80\x9b\x1fyK\x88)`\x8b\x9e*R\xb9\x8a\xef\xfcR\x16\x9d>\xd2\x19\xbf\xdfgF\xc38\x97c\x01\xb0\x94\x96\xcf\xa9\xf9/\xaf\x10\x06q\xb3\xb2\x9d\xb4W\xe9\x96C.\xb4\x97^5\x9f\x0cq\xa2SJ\xc1#\xeb.\x07u\xa7P\xb6H\x9fo{.\x0f32\xc9\xfa%\xa0\xb1\xd9\x85\xa2|\x06k~u\xe2\xdb\xff\x9f\xedU\x9b\x13*\x19\xd1#\xd2\x8c\x02\x05iC/\xa3\xbe5\xaa\xb8\xbd\xcdv\x01\x93\xa3\x18\x81\xd4\xfe\t\x05\x8c\x943\x81\xdb\xa8;\x145\xa4\xae _O\xf0\xa5\xdc\x94\x83\xa5\xfaU\x11\xc4\xa0UY\x18L*uv\x9b9SX\x87\xea\xe4\xccU\x80\xa4\xa1\xdd\xdd\xcc\xdb\xe3\x01\xda\xf4X\xe0~\xc5O\x9e\xce*\x82\x18k#\x83/\x9c\xd3\x8a\xf5\xd7\xa9b\\t\t\xfc\xade\xdf@\x1b&\xecV\x06\x0bu\xc6\x1b\xe0\x0b<\x05J\x93\t7\x98,\xe8\x8c6aB\x1e~\x01p\x9e9\xa8\x8a\x9dly\xe9\x86\x8b\xce!\xc9k\xfe\x0f\n\'\xf2\xe9\xcf\xcd\xf5`a\xc4N^68@\x91\xb8i\xc4\x10\xea\xed\x92n\xc9\x03/X\xb3\xfb\xcb\xc6\xfcT}\x83\xcb \x9a\x99\xd9\x1c\xc9\xbc\xa0<\xb7X\xf9\x0b\xfc\xe2\xe5\xd0\xf9\x8e\x17N\x0f\x03"j%w\x07\xd1\xe4:.n\x04#/\xe5#1\xf4b\xb3\xb7c\xeb}\xce\x83\x91\r8\xf2\r\xfaQ\xe8\x15;Q\xa0\xa1CF\xceY\x89\x85\xdc\xd8\x99B\x82\x02\xedC\x9225\x16`\x0e\xc6\x1c\x8e\x9a*\xa4X\xeeoj7\x16\xfc\xb9\xf8?tL$\x9a`\x99V\x92\xb6\xbf\xac\xaa9\xf3\x01"\x9at\xa0\x94\x1c\xc5\xcc\x8f_\xfb\x11\x0f\xe0\n\xc28\x8axO\xc4\x91\x820bX\x8f\xb2xL\xad\x95[\x88<yN\xd2\x01A\xef\x9d\xb6\x04\x84\x02\xbfb\x13\xa7\xd7\xcf_\xa40\xd5d\xa2T\xba\xd4#R2\xa7\x1d\x87\xd7w\x02\xcc\x94x\x7f\xb6f\x14\xdd\x06R\tk\xfe\x1f\x1b\xfb\xb42\x8b\x92\xae\x1c\xab\x1c\x13\x93K\xf5\xb9\xb9\xf6U\xc4\xb2\x9b\xde\x8ej\x01Wc\xb6Xa\x001\xcf\xe2<\xda\xb1\xb0\x08~\xf5bw'
|
|
|
|
|
|
2024-12-14 20:35:28.301535 - Ether / IP / TCP 20.50.88.242:https > 192.168.1.11:42760 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 42876
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 106
|
|
proto = tcp
|
|
chksum = 0x3a7c
|
|
src = 20.50.88.242
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42760
|
|
seq = 996188136
|
|
ack = 2716058817
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 16382
|
|
chksum = 0x564d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:28.340693 - Ether / IP / TCP 20.50.88.242:https > 192.168.1.11:42760 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 370
|
|
id = 42877
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 106
|
|
proto = tcp
|
|
chksum = 0x3931
|
|
src = 20.50.88.242
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42760
|
|
seq = 996188136
|
|
ack = 2716058817
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 16382
|
|
chksum = 0x4f28
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01E7\x93\xac\xcc\xb2=\xb5G\x96\xa8\x0f\xe8\xd9AdJ.:\x83U\xe1-\xbbR\xab[\xdc\x9a`\xd9\x1a\x81+\xe3*\xad\x84e\x91z1\xfav\x9b\xe7\xa6\xb5\xb1\x82\xdb\xe0T\xb9\xfd\xc6m\x19\t\x16\xe1\x04\xbd4\x17N\x88\xf4|\xda\xeb^\x13\x84f\x0f8\xfd\x1c\xf4\x82\xce\xe8\x9b\xe6p\xc5m]\x9bY\x93\x15\x9bs\x9a?\x82\x84\x92\xf8\x11@\xde\xff\x03\xd4\xea\xff\xb0\xfbM}\r\x81\xa3\x93GC\xcf\xecU\x1f-o\xa1h<\xee\xab\xb5AL,\x86\xccBtg\xc1\xfb\x87\x86\r\xc9\xda\xbe\x98\xa1,j\xca\x16\x93$\'\x90\x86\x10\x96c\xb7\xe7\xcc;\x83iwoQu\x87\xc3\x8c\xd6\xe3\xff28uUI\x08\x1a\x196]\x05\xf1\xe8\x9f\x9c\xdf\xc7\x92sc\xd2\xe0n8\xe5\x9f\x18\xe2\x1b\xa5#\xc4\x93\xee\xb5\x03\x9d\x81\x8e\xd3\xb3 \xc6\xd3\xd1"-\xa6zt\xa6]\xe1\x0e\x01\xd8\r\xde(\rE\x83\x94/6WI\xcd\xca\xf1\xc7\xae\xa1\xbc\xae\x118\xd9\xd7\xfb\xf8M\xa1\xdb@\x96.\x8aA^Ay#\x11\xf7g]\x15wz\x95\x03\xa7\x14\xda\x1f\x07l\xf1\\\x18\xdf\xe9bL\xc0\xd5\xe3OEo\xe2\xa9F\xd2Q\xa3\xbd.\xa5\xc7\x1a^\x9b\xd4\xce&T\x17@+\'\xde*56zX '
|
|
|
|
|
|
2024-12-14 20:35:28.364154 - Ether / IP / TCP 20.50.88.242:https > 192.168.1.11:42760 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 67
|
|
id = 42878
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 106
|
|
proto = tcp
|
|
chksum = 0x3a5f
|
|
src = 20.50.88.242
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42760
|
|
seq = 996188466
|
|
ack = 2716058817
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 16382
|
|
chksum = 0xee5c
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x16*M\xb9\xb9m\xc2\r#x\x14;!m\x8a\x0c\x10\x06&\xd5\xfa\x18Y'
|
|
|
|
|
|
2024-12-14 20:35:28.367261 - Ether / IP / TCP 192.168.1.11:42760 > 20.50.88.242:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28823
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 20.50.88.242
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42760
|
|
dport = https
|
|
seq = 2716058817
|
|
ack = 996188493
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 514
|
|
chksum = 0x2ef2
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:29.569843 - Ether / IP / TCP 192.168.1.11:41801 > 104.18.32.47:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 6512
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 104.18.32.47
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 41801
|
|
dport = https
|
|
seq = 3989790058
|
|
ack = 3388882222
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x4a10
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:29.586445 - Ether / IP / TCP 104.18.32.47:https > 192.168.1.11:41801 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 21935
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xa520
|
|
src = 104.18.32.47
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 41801
|
|
seq = 3388882222
|
|
ack = 3989790059
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 156
|
|
chksum = 0xa14a
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (3989790058, 3989790059))]
|
|
|
|
|
|
2024-12-14 20:35:29.588999 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 216
|
|
id = 26763
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf157
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995231054
|
|
ack = 212489189
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x4ebf
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\xab\x83\xe3\x9de!\x82\xfc\xdcs\xb2jm\xdf\x91\xc47\xf8\x1d\x1e\x0e\xa9\xddO\xcc\x1c\x08IDwW\xf3+$\xe6\x8f\x16\xb3\x0b\xfd)\x04\xe8\x8cj\x19c\xd0\x83\xba\x02-\x13mi\xc4{\xc5\x13\xdb\x9b\x1ay\x0b\xc1\x14\xba\xd6\xaeq}z\xf4`\xe8\xae\x8f\xf2\xe1\xa0<\xb9\xf5a\xd4\xfe\x8c\xf0Q\xb8\xf1\x86\r\xe4\xff\xcf\x96Q\xa37\x1a\x8d5\xf7AE\x19\x80\xba\xad\xb0Ha\x01\xbb\x89m#\x9ft\xd0H\xa5w\xa02\x80\n\xd9\x81[k\xad\x0e\x0fA\x0f\xe3\xf0\xec>\xfa\xc8A\xa1\x1d\xef\xeb\x02\xb0#L\xeaa\x9bx\xeaVh\x97\x1a\xf3\xfdSi\x04W `\x0b\xf4\x1f'
|
|
|
|
|
|
2024-12-14 20:35:29.601041 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 81
|
|
id = 26764
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf1dd
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995231230
|
|
ack = 212489189
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x9647
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00$\x85F\xc4\xaa\xf7\xf2\x87\xbe\x8c,:\xcc\x93\xf21\x8c4Z\xf8f@\x005\xaf^i>\xaa\x1fE\x10\xef\xbd$=\xaf'
|
|
|
|
|
|
2024-12-14 20:35:29.603512 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 37103
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489189
|
|
ack = 995231271
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0xea57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:29.605690 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 81
|
|
id = 26765
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf1dc
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995231271
|
|
ack = 212489189
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x5b81
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00$\xdd\x8c\xfe\x0c\t\x99[li6\x04\x8f\xf6\xf4\x0b\x1d\xfc"\xb7\xd0l\x9f/\x7f\x0e\'\xf7I\x003\xd4Yt\x1b\x0f?'
|
|
|
|
|
|
2024-12-14 20:35:29.646036 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 37104
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489189
|
|
ack = 995231312
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0xea57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:30.466569 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 139
|
|
id = 26766
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf1a1
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995231312
|
|
ack = 212489189
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x9511
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00^\xb2\x9c\x0eV?rn\xd1\n\r\x0ea\xf8dk~\xb8m9\xf4/\x9cS\xce\xe6\xc5\ntVGc\x80\xb7\x90k\xa9\x0c\xed\x9cG\xee\xf18\xfd\xef\x89\xb3\xf8\\\x97)\xab\x82\xc1|T\\\xa9\xf3\x8a\x81X\xc8\xddh\x99\x0f)\x98\x16JC\x88\xf5i\x93$5\xf6\xe3r*2\x80"\xda\x9cN\xfd\xb8b\x02{&'
|
|
|
|
|
|
2024-12-14 20:35:30.507067 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 37105
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489189
|
|
ack = 995231411
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xea57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:30.653913 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34219
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56306
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 45275
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.655688 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34220
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56307
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 45276
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.657967 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34221
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56306
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 45277
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.660238 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34222
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56307
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 45278
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.662018 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34223
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56306
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 45279
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.664182 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56306
|
|
len = 76
|
|
chksum = 0xa937
|
|
###[ DNS ]###
|
|
id = 45275
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.666366 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56307
|
|
len = 89
|
|
chksum = 0x3baf
|
|
###[ DNS ]###
|
|
id = 45276
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.668820 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56306
|
|
len = 90
|
|
chksum = 0xa1d4
|
|
###[ DNS ]###
|
|
id = 45277
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.670849 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56306
|
|
len = 81
|
|
chksum = 0x5d27
|
|
###[ DNS ]###
|
|
id = 45279
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.678664 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56307
|
|
len = 51
|
|
chksum = 0xefde
|
|
###[ DNS ]###
|
|
id = 45278
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.701581 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34224
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 56308
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 45280
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:30.704535 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 56308
|
|
len = 81
|
|
chksum = 0x770e
|
|
###[ DNS ]###
|
|
id = 45280
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:31.590259 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 94
|
|
id = 37106
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489189
|
|
ack = 995231411
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xea8d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x001a#/\xc2\xa6\xbe\xc9k\xd5\x1a\x89\x01\xc0\xc0b\xba|\xd2\x91\xd1\xf0{\xa0\x8c\x81\xde26dQs7\xf3\x99\x89\xcf\x83\xc5\xba\xfbW\x86S)\x9d\x8b\xe5Y\x0e'
|
|
|
|
|
|
2024-12-14 20:35:31.603082 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 26767
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf203
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995231411
|
|
ack = 212489243
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 8
|
|
chksum = 0x7a51
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x90\x90\xab\xf4'
|
|
|
|
|
|
2024-12-14 20:35:31.694117 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 80
|
|
id = 26768
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf1da
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995231411
|
|
ack = 212489243
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xb3e1
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00#\x16\xe1\x12\xb3\xa7D\xe28h\x8eB\xdbd\xca]\xfa\xd8g\x95)\x18\x05\xe45\xb5D|\\"\xbc3\xf0\xe6.C'
|
|
|
|
|
|
2024-12-14 20:35:31.746383 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 37107
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489243
|
|
ack = 995231451
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xea57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:33.574494 - Ether / IP / TCP 192.168.1.11:42764 > 172.217.17.4:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 2091
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 172.217.17.4
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42764
|
|
dport = https
|
|
seq = 640425001
|
|
ack = 4143681656
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 508
|
|
chksum = 0x7fac
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:33.613749 - Ether / IP / TCP 172.217.17.4:https > 192.168.1.11:42764 R / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x843f
|
|
src = 172.217.17.4
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42764
|
|
seq = 4143681656
|
|
ack = 0
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = R
|
|
window = 0
|
|
chksum = 0x14
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:35.832586 - Ether / IP / TCP 192.168.1.11:42750 > 148.251.1.246:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 19700
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 148.251.1.246
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42750
|
|
dport = https
|
|
seq = 497605335
|
|
ack = 3189985791
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x58c0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:35.878965 - Ether / IP / TCP 148.251.1.246:https > 192.168.1.11:42750 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 25491
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x888c
|
|
src = 148.251.1.246
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42750
|
|
seq = 3189985791
|
|
ack = 497605336
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0x7cc5
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (497605335, 497605336))]
|
|
|
|
|
|
2024-12-14 20:35:36.003297 - Ether / IP / TCP 192.168.1.11:42729 > 142.250.184.14:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 33706
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.14
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42729
|
|
dport = https
|
|
seq = 3790787412
|
|
ack = 2391708146
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x8d8
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:36.020522 - Ether / IP / TCP 142.250.184.14:https > 192.168.1.11:42729 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 11440
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xf58
|
|
src = 142.250.184.14
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42729
|
|
seq = 2391708146
|
|
ack = 3790787413
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1042
|
|
chksum = 0x83f0
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (3790787412, 3790787413))]
|
|
|
|
|
|
2024-12-14 20:35:36.074568 - Ether / IP / UDP / DNS Qry b'spclient.wg.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 69
|
|
id = 34225
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 50392
|
|
dport = domain
|
|
len = 49
|
|
chksum = 0x839f
|
|
###[ DNS ]###
|
|
id = 48800
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:36.076624 - Ether / IP / UDP / DNS Qry b'spclient.wg.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 69
|
|
id = 34226
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 51731
|
|
dport = domain
|
|
len = 49
|
|
chksum = 0x839f
|
|
###[ DNS ]###
|
|
id = 3631
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:36.102619 - Ether / IP / UDP / DNS Ans b'edge-web.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 192
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb6d0
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 51731
|
|
len = 172
|
|
chksum = 0xcba6
|
|
###[ DNS ]###
|
|
id = 3631
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 1
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = HTTPS
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'spclient.wg.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 167
|
|
| rdlen = None
|
|
| rdata = b'edge-web.dual-gslb.spotify.com.'
|
|
\ns \
|
|
|###[ DNS SOA Resource Record ]###
|
|
| rrname = b'dual-gslb.spotify.com.'
|
|
| type = SOA
|
|
| rclass = IN
|
|
| ttl = 100
|
|
| rdlen = None
|
|
| mname = b'ns-cloud-d1.googledomains.com.'
|
|
| rname = b'cloud-dns-hostmaster.google.com.'
|
|
| serial = 1
|
|
| refresh = 21600
|
|
| retry = 3600
|
|
| expire = 259200
|
|
| minimum = 300
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:36.105253 - Ether / IP / UDP / DNS Ans b'edge-web.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 118
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb71a
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 50392
|
|
len = 98
|
|
chksum = 0x561e
|
|
###[ DNS ]###
|
|
id = 48800
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 2
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'spclient.wg.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'spclient.wg.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 88
|
|
| rdlen = None
|
|
| rdata = b'edge-web.dual-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'edge-web.dual-gslb.spotify.com.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 115
|
|
| rdlen = None
|
|
| rdata = 35.186.224.24
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:36.107096 - Ether / IP / UDP 192.168.1.11:52702 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 35860
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52702
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca81
|
|
###[ Raw ]###
|
|
load = b'\xce\x00\x00\x00\x01\x08\xf7\ri\xbf\xab\xe9\xb0\xd9\x00@F\x00\xb4*\xcf\xdcie\xdc\xe6E\xd4\x1c\x93\xda.\x06oK\xff\xc5\x1dC\xd1g\xa4\xe8\r\xe3/\xa4\xfc\xcb\x0eC\x1d\xe9\xe4\xde,\x9f\x1e\xc8"\xaa\xbc\xc6\x12~\xa74\xc3\x11\x90JB&m\xd7t\x0c\t\xd2\n0\x9e]vG\xeb\x8cD\x89"\xd7\xfa\xb8\x89fx\xbe\xf1\xa1\x91i\xbeg\x91\x83\x15\x8d\x14\xe0\x91\x01o\xf4\x1a\x8b\x10\xa5\x8e2\xcb\xe8\x82\x86\xfc=\xdc\xd2 jWm\xdb\xdc\\,p\x92\x15\xa1\rbK"\xf1A\xcf/b\xa0\x08CR\xb3\x9d&\xea1\x96\xb0B\x00\xee8\xc7\xe9dl\x0f\x96u\xd9\xad\x16\x1f\xce\x9a\x90{_\xfe\xbe\x11\xc6`\xa3Yj\x1e\xe3iX\x00u`\xca\xd92 \xf5~\xee\xaa\x1e}n\xbb\xeb\x86\x8eHs$\x87\x9c\x1a\'\xd8 \xfa~\xad9\x10\xcd\x99\x89\xfd\xb0Z\xdc<\x82\x1d\x8cW\x0e7:\xe0u\xe9\xab\xc6\xdf7\x8cam\xe7\xbf\x88}\xdc\x15\xca_\'4^\x0f\xa1p\xe7\x17+\xd0M@\xee2\xfa\xbdj\xe2n\xef\x10\x14\xf5[\x11\xff\x06\t\xc8\xa3\x18V\xfd\x04\xc0O\xb9\x1e\xf8\x8c,\x01\xc1\xe0&\x06\'\xc7\xce;\xeeI\xcfm,\x11\x0c\x8e\x14/0\xab}\xa5]\xfeZ\xed\xca\xad\xcc\x836d$K5=\x06\xb2\x1d\x8f\xe2\xc1\x97.\x10\xdexP}H\x02\x8c\xca\r]\xbf\xba\xf3<\x89\xeb\x08\rU\xaf[\xc5\x1b\xff\xaf}<2\xd1\xf6.L\xc9Ispm\xc8\xa4\x82DU\xe3Pu\x19\xa2\xb12S\xbd\x1dw\xff[\x80@\x1d\xc5\xf6\xaa\x87\x9d\xf7%\xd5\xa5\xd7\x9d\x00\xb1\r\x06\xe7\x19\xb5\xc9\x8d\r\x17\xfe\xbf\xdd\xad]\x8e\xc6\xa8N\x87\xd3\x11<\xf0\x7fW\x88\x881/\xb5\xd9\xad\x1f\xd2\xefAd\xbe+\xab\xc4\xa3\xc8D\x03\xb3^+\xbb\xe1\xd2\x9dq\x12\x02\xedw1$Z\xe2\\\x01\xf0\xb7J\xe7\x10{\xb0\xc4\xab\x08T\xf8Y\x92\xb2N\x10s\tR5_\xb3\xa1n\xde<\xb95\xb7\xf1Z\x16t\x8c\xdf\x16~\xd0\xa0?\xae\xe8\xb4\x9d\x02119\xdaz\x1f\xb8\x8f\x96\xefk)dn\x90\x8dvvk\xb2\x08z#\x05\xb5\xb5\x98\x01\xd3r7[\x16r\xa1\xd1\x886"\xdc0\x04F\x81\x9d.\xdf\x0b\xfe\xe0x!_\rizf\x1a<$\xc9\xa3\xed\xa4\x16\x85\xbc\xe0\xe5\x07\x15\xaa" g|i\xdf\xd6\xa6cf Bfg\xb0m\x87\x89\x96\xa6\x82\x80fg<7\xa8\xa0I\xc1\xc3\xa7\x1do\xdf\xa9\xf0\x96v\xc2\xce9\xfa\xa3\xda7\x1f\xc7]\xf9\x88x?\xfa\x98\x0c\x84\x8e\xb8\x8a\xbeg\xc7\x07L\x13\x88\xb0\xb4K\x82\xb5\x96\x81\xc1\x8a<}\x9f\x82\xa8\x0e>\x8e;\x8emO\xae\xff\x16fW\xef\xd7\x04\xcaR\xf1\xdb\xf1\xd6Zd\x80\xfc\x0f\x9b\xfcUk\x0b\xc2\xf2/L{\xfbK\xdf\xb6\xb93Q\x9e\xe6\x00.S\xf1,\x9a1\xf5R7\x04d\xf8\x10\x11\xeb\xc1\xce\x17\x91e#\xc5]\xac\x90\xa1\xf7M\x08\x99!,;\xb2*\x89K\xa2\x0b\xe6_\xd6Cm\'\t\xdb\xb5\n~o\xb3%.BG\xd8`\x03-R\x0e=\xbc\x13\x84\x9b\xc3\x9c\xc9!?\xe8\x01\xcaMU5X [z\xa1.\xd4\\\x88\xf95@8$\x0e\xa9\x99\x10-\x89\xaax\xed\xce\xc8\xaf<\x1f\x86\xb4\xbf\x9f\x1b s,3\xb6\xa9"UO\x15\t\xb0\xb2\x81`\xa2x\xb9P\x1cT\xb0\x07\xbd\xbb\xe1\xb1\xf9\n\xba\xf9\xd0R\x17ui\xfe\x9a\xe2\x10\xc7O\xe1!p\xf0\xb2P\xb5\x97\x1ej\x08p\xaev\xbf\xe9\xfe_pI\x98\xccAS\x87dZ\xb4\xd5\x84]\xc5[\x9fA9\xed&\xbf\x94DA\xcf\xf4\xe6\x10g\xf2I?t\xe3\r\xfb\xb3\xdf*i\x84\xe8/\x8c\xb9\x94;7\\:\x0e\xbe\xf6\x1dXM\r\xbd\x8f6\xebX\x0e\xd3\x97\xe1\x85\x89\xcdH|\x9b\xb5\xbcc\'\xca[_\xe3\xf5\x1d\xe3\xd1\x8b\x12\xca\xef\'@\xf0\x81\n\x07\x8c\xe2\x99\xee}8\xec\x9c\xd5N\xf4B?\x8fT\x00\x1f\x9aDe)@a\xed&\xb4M\xdd\x92\x92_N\xbb\xfev\xf5\xe4&v\x07\xc4\x9aco\xb6\x10R\xbc\n\x98\xa9\xda`\x12 \xa6\xe5\xf1\xd1\xfc\xacq\xef\xf4a\xa1\xf7\xb3\xfd\x81\xc1\xc3\xc11\x86\x9a+w\xdc\x95\x94(0\xe1\xb3\xfb\x8b@\n\x1d\xf3w\xd39\x05\x89\xf5\xd3Z\x81ws\x0fM\xc6\x8e\xd2\xdc5(\xd0~K<u\x0e\x12\x89\x1dd\xc6eR\x87\xef\xe0\x1d\xf9\xaf}\xda}\xb9q\x8a\xf8H\x01Ich\xf4\xea\xc7\x86G\x1a\x03\x10\xbd\x90\'\xf6q~\xf7\x13\xfb\x11\x1d>o\x84r\t\x8b\xc2\xa4h\x11\xcd)\xe0\x0f\xcc]\x9d\x87\xf1\x1c}\xfa\x8f\xe2\xf3\x8b%\'\xfe\x8axc\xafN\x14\x87^\xfcX\x8ci\xe7\xac\xda\xa4\x0e\xd9}&\x08\x0e\xcdI<+\xd4\xbc\xf1\xeeO\xf0ZAc\xaf\x06\x8c\xfc\xbaHz\xf4\tT\x1c\xa27\xf3\x8e\x95\xc5\x1b\x0c#\x87\xf0k\xddh\n\xf6\xf7\xd5\xb8*\xa8\xe6\x8eA\r\t\xcb\x19'
|
|
|
|
|
|
2024-12-14 20:35:36.141480 - Ether / IP / UDP 192.168.1.11:52702 > 35.186.224.24:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 35861
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52702
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca81
|
|
###[ Raw ]###
|
|
load = b'\xc1\x00\x00\x00\x01\x08\xf7\ri\xbf\xab\xe9\xb0\xd9\x00@F\x00\xb4*\xcf\xdcie\xdc\xe6E\xd4\x1c\x93\xda.\x06oK\xff\xc5\x1dC\xd1g\xa4\xe8\r\xe3/\xa4\xfc\xcb\x0eC\x1d\xe9\xe4\xde,\x9f\x1e\xc8"\xaa\xbc\xc6\x12~\xa74\xc3\x11\x90JB&m\xd7t\x0c\t\xd2\n0\x9e]vG\xeb\x8cD\x89\x83/fc\xb0\xdac\x81\t\xf3\xe9\x04w\x05-m\xb4.\x96\x04\xb1L\x94o\xc6\xe11\xe0\x8d\xa4u\xac4=\x1e\xbct\xe6\xc1"\xf2\x96\x83e\xa2\x15D\xa3R\xc2\x96\x18~`\xd8\x8b\x87g\xd6qEYl\xd3NjB\xb3,h\xa8\xe8\n)\xd6/W\x14]\xf3\x88-B\xc2\x92\xd6\x8a\x82C\x91ph`\xe5O\xf65\xf9\xea\xabM\x10\xd9dGl\xb5\xfc\xdb\x15z<\xf9\xbb\xac\x0b\\\x97\xae\xfecu\xd4\x93-\x1bj\xcaTY\xa9_\x98\x1e\x0e\xad\xa4\xe2\x9e\xb3\xbc\xf7J\\\xfa\xdb\xaa\x82%\x1d\xf9uW9Yp(7a]0!\x1a:\x8b\xe7\xdf\x0b\x92\xe4\x8cf\x8e\xcb\xc3\x87\xe89A\xd4\xf9\x9da\xcf\x9f\x91\x8e\xc4\x80\xd7W\xe5|\xa4RJ\x90\xa1Y\x07\x0f4\x90I\xc2\xe64\r\\P\x08\xc2qYb\t\x15\xe0v\xa9\xef\xe7\xcc2\x13\x93\x813;\xff\x16\xac\'$\xf5\r\xcbv\xe0\xb2k\x1dp5b\x12*\x1eC\xdci\x7fv#/\xbd\xa7\xce\xf3m}\xcb_^\xfcT\r\xd0J\xc9\xd3\x95Bp\xda\xee\xe6\xd9\x08\x7fE\xeey!\xc8\xa8\x00\x83\xf6~|\xe2a{\x08X\x8e|}\xedb\x00([\xf0\xb6\xb8\x1f\xca\x9c\x87\xe5j\xab\xd1\x19\x82\xb6\xda\x1a\xe0."]\xb8\xb5W\xb0\x7fX=\xcd\xa9vv\x98/\xc1\x87\x1e\xaa\xecy\xfe\x0e\xf7\x95w]4\x89P`2\xd7V\xcc\xc1`\x91\xa0M\xc5f\xad\xdf\xf2\xeb\x8d\xea\xc2\xbap\x90\xa7\x85t\x07\xacK\xb7\xaa\x89\xc6\xfd\x04\x87&\xbc\x9f\xacU<0\xb2\xc1\xb6BA\xab\xa6?\xa1Al&\x8f\xeb\xcd2~p\xe6d\xc6\xa2v9w\x08\xe0\x83\x11\xceV\xecch\xb7pG\x8f\xe9%\xae\xb4c9\xcb\x81\xe6\x89\\j\xb31>\x9994\xce\x98\xfeO\x9b\xc4Kl\xf6+\xfbM6\x0b\xd0\xcc\x91x\xa0\x91A\xaf\xfc\xc2\x96bA9\xa8\xd0\x94m&N\xee\xf5\xdbP\xe4h\x1c\xc2\xde\xed\xf40P)\x1f\xd3\x07\xea\x8d\xf7\xf7,\xa7\xed\xca\xcd\xd2c\x8bS\xae1K\x81\xb5_=\xc3\x96\xd3\xa3\\\n\x8c\xf8_\x92\xb1\x82m\x9b\x90\xef\xbf\xe7ZL\xa0\xb4\xf9\x8c\x8f\xb7\x021\x0b2\xb3b-\xe99\xc2/p\x87\x03\x1b`_\x17\xa34\x8b\xe1\xb1\xae\x1f\xac\xe4s\x0bLAs\x03\xac0\x96\xeb\xf1\x01\xb5\x03\x8ag\xc9\x14\xe9\x07\xa8>^\xd3F\x06G\xd7)\x93\x8e\xe7$\x8c0\xc4\xab\xe8\xe0\x95e\x1e\x1b\xe4\x85j\xb6\\M^\x0c!\xaf\xeeEg\xe6\xd5\x860\x91\x83\x02\x83\xb5<%S\xab\xf3\xebN9\xfe\x85\xd89\xeb\xa7,\xc1=\x1cj\x14}\xee\xe7\xf8\x90\x97J\xed\xe4./\x19V\x02\x8d{\xa7<\xc5\x93\xca\x9bz\xd5\xf6W\x83w\x88\x1at\x02\xe3\x08\x96<\xd4\xf8\x14\x9d\x04\x8d~\xa6\x85\xbf\xf3\x1e"\x99\xc6Q\x9d\xf8,\xf8@\xd6\x96\xc0\x07\xe3S\xc7(*%\xea;W\x83\x83\xa3\xf7\xdc\xa9\xb9\xb3\x80\xe8\xcb\xbdUB\x99tV\x0e\x7f1z\xea\xcb\xbf\x16F\x9dub\x97\r\x93\xab\xadK^\xf0\x055b\xedY\xcd\'\x8b\x08\x19\xfb\xdb\x15!\xc1K\xc8O#S\x07\xf8\xa7\x7fS;\x943\xd3\xf2|\x02\xabo\x88\xc9\xaf\xb2\x10!\x06\xdcO8\\\xc3\xb1\x1fQq\x15j/\xa1\xb4k\x95\x96\xdd\xad\xe4\xc0\x0e\xde8\x91\xc8\xf4\xa6\x84\xad\xc1\xe4\xd59\x03\x99\xf3\x8c\xb8\xcc\x19F1\xad\xa8\xf1z\xe6\xf5\x92\x12 \xe5\xbe\x11^hu_\xc0\xc6\xe0(!h\xfb@\xe4U\x84\x86\xa1c\xe1\x80D?PT\xc8P\x110\xd2}\xf7\x8bk8X\xadE^-5@\xde\xa9\xfc\xbe\x01u\xc8\xe2\xf0\xde\xab\x97\xc2\x9d\xa4\xe2\xdad]\x17U@,\xce\x03\xb3\x9b\xa3\x14=\r\xa6#\x0b<\xef\xc57*\xa1eF=\xedf&\x89\xb8Ub\x94\xc9\xde\xabF\x0f\xcfi\xd1\x9c\xe0%q\x887\xebz=\x08\xc0w\x0e\x02\x82F\x15\xf1h\xe3\x93\xb9Pc D\x07\x99t6\x84k%?\xd8M\x15\xe0n@\x14\x1ap\x87q8\'g5\x9b[\x9d\x08#m\xd9V^4\xc0\x15\xac\\\xfd\xfao\x9c\xb7b<\x9d\x07\xafle\xa1*\xbe\x06\xba\xcc:Y\x8f\xb4\xa0#\xfd\x1f\xb3\xd0\x18\xec)S\xd9v\xcc\xd6\xc8\xd8\x7f\x8af\xa9$/V\x1dY\xd3\xd6n\xc3\xc7Z\xb5\x12BP4NvQ\x8a\xf8`+\xaf\xcc464\xfa\xaeukvq\x02\x9e\xb6Z\xaf\xdf-C!\xf6x\xc2\xad\xd4Z\xf2\x84\x95\xfb!\xd5u\x0b\xf5\xf3\x04\xc6\xae\x02\xb1,Eu\x8c\xa8\xaeb\x0e\xbc\x81_\xda\x98\x062t\xbaI\xaf\xd0\xc8L\xe4Ih\xd0\x02\x1a\x9b\x1d'
|
|
|
|
|
|
2024-12-14 20:35:36.212579 - Ether / IP / TCP 192.168.1.11:42720 > 35.186.224.24:https FA
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 35862
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42720
|
|
dport = https
|
|
seq = 516658158
|
|
ack = 1765306794
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FA
|
|
window = 509
|
|
chksum = 0xc5a0
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:36.243933 - Ether / IP / TCP 192.168.1.11:42767 > 35.186.224.24:https S
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 35863
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42767
|
|
dport = https
|
|
seq = 2178914231
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 64240
|
|
chksum = 0xc5ac
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 20:35:36.267374 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:52702 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7d23
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52702
|
|
len = 48
|
|
chksum = 0x7649
|
|
###[ Raw ]###
|
|
load = b'\xcb\x00\x00\x00\x01\x00\x08\xf7\ri\xbf\xab\xe9\xb0\xd9\x00@\x16"\xa2[B\x14(\x11U\x8b\xb2\x12\xc1\x18\xbd\xa6\xdd\x1cJP\xc0\xe0\xd5'
|
|
|
|
|
|
2024-12-14 20:35:36.281931 - Ether / IP / UDP 35.186.224.24:https > 192.168.1.11:52702 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 56
|
|
proto = udp
|
|
chksum = 0x7869
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 52702
|
|
len = 1258
|
|
chksum = 0xbe07
|
|
###[ Raw ]###
|
|
load = b'\xc2\x00\x00\x00\x01\x00\x08\xf7\ri\xbf\xab\xe9\xb0\xd9\x00D\xd0r\xc5\xbc3\xf8\xfa\xa3\xa8\x99\x1e\xea\xa9\xaa\x80\xa4\x1c\xa7]-\xb8;w0/\x08U\x8e\xfdB\x9a\xb6\x98L\xd4\x17\xcf?\x18\x1d)\x89\x8f\x05T%J\x1dd\x1cLL\x04\x93\x0b\x8cG\xdbW\xd7p\xf5\x8c\x828t\x1fT\xc36\x10\xfe\xe8UQqsl\xe6\xe4\x98I,\xbbg\xf5\xee\x1dlFZ\xae\xbc\x84B\x1dT\x1a\x84\xfd\xb7H\x91>X\xd8\x99X6\xed,\xe1\x8f\xdbId\xea\x95z\xa5\xf4,\x06\xb3\xe2?8_\xdf\x10\xc04\xa8\xd9\xb6\x88i\xf3\xe5\xfe\x80\x99(\x01\xa6\x19\x7f\xc8n\xcc\x1a\x90\xe3Z~\x9e\xd8o\x84\xcbg\xe0,\xdc8\x96c\xc7b\x8a]\x81\x92\x92sr\xf90\xd7\xb6\xe5<\xfc\xac\xf0\xb1\xec?\xe0\xb9\xb4\xf6\x8f-\x9c8s\xe1h\xa5\xa5\xde\xafW\x827nI\xbf\xff{\xcb\xf7(\xd2q\xfb\x0e\n\xf3b\xca\xd7\x19c\xc63\xab\x9ax\n\x81$\x967\x9d\x92\x9f_\xf5\xae\x89\x9au\xa7\x9ds\xd5m\xfd\xba\x84\x12e\xc5P\x8a"\xfc\x0c\xfc\x9a\x9d\xd3\xd5\xca\xb9\xac\xac\xf9b\x05R\xba\xf4\x94e\xc7\xb4\xfd\xb3%7\xae\xbbe\xb0\xfa\xa5\x13\x1b\x1d\x87\xb5g\x10\\]\'\xb5\x81*\x97\xec\tt|Yg\xe4p\xeaO?\xae\xc6(\x14K\xb3\xa3f\xa2E\xc7\xd9L7\'\x1c\x1f\xef!_;\xa5\x84\xcd\xb5\xbd\x9a\xc3.^\x1c\x14T\x81;,:N\x9eU\xd8u\xabw\x15c\xb3\xafZ\x81\xc9\xa1\x8c\x89*\x06\x1c\xd4\xac=\xd0\x97\x84\xaa\x99\xb4A{\t\xe5P\x89+\xcf\x98"Ow\x9f\'ApNy\x05\xd9\xbb\xcdHV\xba/bO\xf7\xe0\xd4\xaf\x11\xa7y\x9e\xd7{\xca<\xaa\x1d\xafd\x04i\x15&zV\x8b\x94\x06\x99h/\xe9f\x8c\rf\xbaR\xc7\x8d\xc4\'o\x83\x8a\xe2>\xf3/\x850R\x03\xd4\xcc\xc0\x9aH\x84\xa3"7l\xb1GN\x1e\x93\\\xfe\x8a\xcf\xac\xf8f,\x9a;\xf3\xf1}.V\x9eL\xe6>\xa7\\\xdf\xc4\xc8\x0e\x8a\xb3\x0f\x155\xec\xd9.T\xadG\xa8g\xff\xca\xfd\xe7ZA\x9b\\\xc8Q;8\x9aK\xb7\x91\xa9\x88\x90ciHPm\xdd@\xff\xc7\x80z\x92\xee\xda\xaf\x84\x01\x1c\xf9R\x8dHG\xb1\\\xda\xf4\xd9=#F\xc2\x861v%\x88\xdc\xd7\xff\x13\x18\x90#\xac\x01\xe4\xf0\xb7T\x8b\x88\x8e\x93Ta)\xf2\xc9\x99\xcd\xca\x9f\x04\x92\xd2%q\xbf\xe0B\x87\x1f\x98\xe0\xec\x8e\xcdU\xd0iS\xcd\xf0\x07\xab\xad\xbb\xd6\xe3;\xc6\xfep!j\xbd\x10n\x98+\xab\xec*\xa9\xee\x93k\xb7\xa4\xbb\xba\x13\x04\xf7ge?|O7N\xd9\x88\xda\xb5I\x81\xf4Z\x87\xb9\xb3\x12\x94%y\x9c\x89\xfa7\x05\xb1\xc1\x9a\x8dh|\xef\xf9a\xd4k\x13)\xc2\x88\xe0\x11\xef\xd8r\xc6\xff\xc5\xc1:\xcb\xab\xd3\xfa\x83G\xb6GfF(g\xdeo\xe2\x822\x14\x0cp\xb8\xcaC\xb6\x8fQr\xdb\xd4\x04}\x06\x9e\xd0\xc5J\xd2>.\xac^\x9b\xce\xfaB\x96`\x1cj5\'p\x03\x01J\xdf\xb6M\x84\xf8\xcf!\x8b\xa4\x116^\xd2\xf3\xbc\xd2\x9d\x98\xad\x10e\xd2lO\x1e\x1eGP\x0c=\xb8Q\xef\x1f\xd3\x03\xd7\x07\x16\x7f\xf2\x95*\xb8\rib\xc4\xfa\t\x05\xdc\xc3\xa28\x19V\x1cDf\x08w\x158W\xf4\x84\xdfw\xe5\xed\xfa9S\xc6\xca\x1d\nUqj\xd4\x1a\x83~\xc7\x0chDkxT\x0b\x87\xbe\xe7\x00rL\xd0\x83\xa1\xbd\xa7L\x18\x08\xcc\x7f\xf5,\x8cj\x12\x9c\xe4\xfe$\x0b\x13\xd1h\xfeT\xddD6Y\xe6Z\x82\x14\x0f\xc8\x82p\x1fNcb\x02b\x8d#\xb1\xdc<\xbc\xdb\xc1\xeb5\xd0;\'\xbf\xc7J\xa5\xbc\x13q2\xea\xa8\xec\x17f1W\x80\x840Y\xf1\xd8\xf9\t\xa6\xe0\xa3\x8b^\xfd\x8a [jc\x1ax\xcd\xf6\xb4 \xdeV\x0fN\x14Db\x822t\x8aB\x1a\xbds}r-_\xa80\xf3\xa0\xb0\xb0\x83\xe6w\xa8\xd9\x9e\x1c\xa4\x00\xc0\x8e\xaaq\x0bH\xc3\xec\'\x83\xe8;\xec%\xc4w->c\x83\xa9\x96\x8a\x06\xb4\xae\x9f\x16\xda\xdf\x99o\n\xff\x0e,X\xc6\x1eP\x1b+5y\xd2\xad\xed8\x0f\xac\xd1\xaaU\x05S\xa4\r\xb4\x8b\xa2\xb8\x08v\xb2\x95\xe0Xz\xabj\x0eh\xc3\x1f!#?";%[\x08\xbe\xdd\x18\xfes\xb96(\x8a\xba\x8dq\xcf\xccm\x9e\x9ei\xc4\x9d\x8e\xfcg\xe4\xcaFf\xcb`4@\xcb\xf6\xb5f\xae\x02\x7f\xfe\xc9\x10.\xf6\xdf\xa7\xee\xbb\x9b\x1a\x83\x88\xf1.\x99s\x99\x10\x87T\xfe"l\xbdG\x1d^\x8a\xcd(3\xe0"\xdf\xd8\x1f\xb87\xfa\xc9h\xa8\xb3\xbaV\xber\xe8\ng\x926w\xf2\xec\xdf\xca\xebx\xa2\x94\x92rb\xf6\x9a\r\x82m/T\xb5\xad\xf0\xe1/l\xde\xd0\xd7]\xd0\xf0\xc3d4\xbd\xc0\xd7\xac\xd1\xf0\x96~\x99\x00\xc2\xe3\xeb\xd3\xaa\xb9n\x83ZoE\xc6\xe6\x0b\x91z\x80\x9ag!4\xaak\xe3\xcdCR\xbd\xb3\x0cWn9\x91B'
|
|
|
|
|
|
2024-12-14 20:35:36.349105 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:42720 FA / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 6673
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x6539
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42720
|
|
seq = 1765306794
|
|
ack = 516658159
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FA
|
|
window = 1046
|
|
chksum = 0xaffe
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:36.362022 - Ether / IP / TCP 35.186.224.24:https > 192.168.1.11:42767 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x3f3e
|
|
src = 35.186.224.24
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42767
|
|
seq = 3054360900
|
|
ack = 2178914232
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 65535
|
|
chksum = 0x57f5
|
|
urgptr = 0
|
|
options = [('MSS', 1412), ('NOP', None), ('NOP', None), ('SAckOK', b''), ('NOP', None), ('WScale', 8)]
|
|
|
|
|
|
2024-12-14 20:35:36.384048 - Ether / IP / TCP 192.168.1.11:42720 > 35.186.224.24:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 35864
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42720
|
|
dport = https
|
|
seq = 516658159
|
|
ack = 1765306795
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xc5a0
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:36.401820 - Ether / IP / TCP 192.168.1.11:42767 > 35.186.224.24:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 35865
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42767
|
|
dport = https
|
|
seq = 2178914232
|
|
ack = 3054360901
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xc5a0
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:36.403665 - Ether / IP / TCP 192.168.1.11:42767 > 35.186.224.24:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 35866
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.24
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42767
|
|
dport = https
|
|
seq = 2178914232
|
|
ack = 3054360901
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xcb24
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x01\x084\x01\x00\x080\x03\x03\xc1\x9f\r\x18\xfc `)\xea\x83\xdd\x8d\x8f\xb73\x82\x1b\x82\xc5\x91\x85Y+ aI\xfbJ=\xee]\xcb X\xe3DI\xc2\x00\x80u\x8c\x9a\x0c\x1a\xa0\xf4\xfe\r\xf8io\x9f\xf5\xad\xc4\xe5\xb3\xc4\xf9b\xd65\xa1!\x00 \xba\xba\x13\x01\x13\x02\x13\x03\xc0+\xc0/\xc0,\xc00\xcc\xa9\xcc\xa8\xc0\x13\xc0\x14\x00\x9c\x00\x9d\x00/\x005\x01\x00\x07\xc7ZZ\x00\x00\x00\x0b\x00\x02\x01\x00\x00\x17\x00\x00\x00-\x00\x02\x01\x01\x00\x05\x00\x05\x01\x00\x00\x00\x00\x00\x00\x00\x1c\x00\x1a\x00\x00\x17spclient.wg.spotify.com\xfe\r\x01\x1a\x00\x00\x01\x00\x01\x17\x00 \xf4[\xf6\xe6\xd8\x91KF\xb3rY\xc7\'b\xd5E\xebt&\xeas\x8d\xe7S\xf2wLy\xfd\x10\xd39\x00\xf0\x80w\xcc\xcc]R\x92\xcb\xd2j\xe7\xe6\xe9\xff\xeafw\xd8\xe84\xef\xdeg\xfd\x05;\x05\x9a\x98\xa9\xebf\xb7bg(R\xd8N\x8b\x96Q\x11+\x04\x0f\xc6\xff\x80\x98\x88P\xfdb\xb4\x87\x97\x18DH\x8c\xc5\x82G\x17\xb2\xfd\x943.\x1f\x80\xa03\xb7~\x94\xddy\xa4\x18\x82h\x05\xc2\xb7\x8dSX\x9d\xd0\xcc1\xcd\x1f\xf6\x0c\xaa\x11\xae\x7f"\xf8$)\x06el\xa3\xf2<)\x95zd\x97]4\xa9s\x81h\x0b4G\xad\xd3\xda\x96\xdd1\xa4\xf5\na\xad-V\xc6\xc2\xca+\x99\xf8\x0b\xc8\xed\xbe6\xe9\xbb-1\x92\x8d\x12 \x83\xd60\xc3\xe8~\xcf\xdc\xa8\x98\x10\x06\xd43$r\x85\xd76\xe9N\xd7x\x85\xe8\xfe\xa7\xdb\xb4\xccd<Z\x19\x1b\xc6:|\xdf\x9ai\x95\xb4M\xf6\x887\x95q\x93\xc3\xe3\x05\t3>J\x1e\xf3\x13-\xf9\xbeb\xa4n\x9b7=k\xa5w\x8a\x08-\tzr\x14*\x84\xee)\x00\x1b\x00\x03\x02\x00\x02\x003\x04\xef\x04\xed\xba\xba\x00\x01\x00c\x99\x04\xc0t`\xee\xb4xL\xfe\xf0m\xffP\x00\r\x1dbAV\x00P\xe1\x94\xd7a\x8e\xdf\x85\xcd\xefkC\xb8z\xe3\x18=\x8c,/\xb6KQo\xf0\x83\x1c\x90\xc5\x9fx>d[\x84\xb0z\x07\x8a\x17$\x0b#\xc9\xdaz;\x86\xa2\x7fl\xbb(\x0c\xe3!\xc7\xfcDx\x890\x00P\x84\x06\xb9\xc2\xe8)<=\xf8&l\x91.\xe8\xc4u\x054<\x19\xfb\x90e\x87\xb2\x87QE\x84$\x98\xd0\xe7h\x8d\xe0\xc7\xf9\tv\xf7\'\x9a"h\xb1P\x8c\x8d\x89+\xcap\x81!oU#X\x81!\x18\xf3\xb4Wt\x1c\xf9\xc9\xb4$\xa4\x84\xea\x05\'\xd8\x92\x17\xec\x96b\xdb\xf2\xb6/\xe7\x07\xe6l~{\xcc\x7f\\R)Kw\x11G\xc7R\xf2\xf7\xc4m\xe7Pl\x93\xc3\xe3\xa7\x02\xc7:e\xda\xbb\x11\xa8\x96\x163\x8b}\xf7X\x91\xae\xb3\x1fcV\xbe\xd4+w\x9c&\xa3\xee\xf5L\xac`A42\xbc\xa2ZR\xa43\x11f\xa5~^\x08pw\xf3\xa1\xee<D\xa2\xcb4\xf1\xd4\xb4\xbd2\xa0LG@\xca\xcb\xb0\x18\xbc\xb7\x1d\xf5\xc5\xe3)[\xa4\xfc+]D;\x8a\xc1Z\xaf\x18n\x06WG\xa7\xa6\x05\x9aZ\xa1\xd8\'.yxyfaW\xfb1rF\xab$\xfei\x02\x14\x14c\xef\x91\x19\xa0\xc3Y\xe8[f\x83\xb5>w\xb6\xc2\xd5\xdb\xa8\xba\\\xce\x13\x80\x9e\x89\xd0\x98\xe0\x8cR\x14\x0c\x05H\x98\x82nPkN\x1al&\\v\xd6\x9a\xb9j\xd6\'\xe4\xb1M\x8c\xe1\xac\x98,\x92\xf4\x08\x9e\xd2\xe2-\x127\x03\x1a\xe6\x13Q\xa2\x06\x9e\x8b^b`9\x95\x04\x0f\xb6\xf0\x97\x9c\xf8@\x8c\x1c%Y|\x00\xb7s})\xe6\x1e\xeb\x11\xbbDw\x80g\x198\x9c,9\x0eh\xc1>Y\x93R\xfa\xc7\x99\n-\xb4\xa5\x80nX\x03_$,\xf8\xab\'\x91[\xbfOC;\x86\x05\xa0\x12#\x92\x9bSb\xa6\xb2\x83\xe2\x082)\xbbT\x8d\xf0T)C\x1c\xfd\xb1\x13\x8b\x006@\xcb\x98\x80\xa3\x94\r\xca\xab\x10\xc8\xc6p\x88h\xefr\x13\xaf\xb5b\x01\x80z1\x89d\xb5\xac~#r\t\xcd3\x13\xe4u\x9c\x91\x8a<\xa4Y+kVm\xad\xd8\x189\x16\xc7\xa6\xe1\x81\x1b\xac\xb8\xb9\xc8|\x9b\x94\xceHg\xab\xcf\xc1\xa8\xe9\xfa\x88\xabP1d\xacz\xb6D#\x12R|\x03\xfa\xc3\xd3\xd3}\x0e\x88\x05u\xeag\xe1\xb0;p\x03;"\x9c-\xe9\xb2^z\x10\x03\xe4\xc3$&\x18v\xda\x95K\x9d\x80\xc1(gg[\x11\x04\xb6bG\xb1\xa1Ldv\xa9\x8c\xb1\x87\x92\x05\x86\xc5P\x0f\x8d\x95\xb6&\xf3tX\xa1VS\xf9\x8d\xb6\x9bh\x83\x1a,\xb7\xf5\'S\x06\xb9f\xe5\xb4L#<\xa9\xf3\x90\xa7\xd2\t`iiG\x89\x9b\xb8\xdc~?\x99\xba3s"\xe1W\x92\xfc5\x9a,!\xb7%Q\x06\x08\xf6\xa6\xcb\n\xc9\xd5\xd8\xc4) \n\xda\xe5\xb1\xc0U\xb8\xddF}\x10\x1a\x1fUG^2B\x16m\x89k+k\x07Z\x9c\xa0\xea\x84\xb4\x06\xe8)\xdc\xe5\x04\xa4sY\xd5\xc8\xbdb\x0b\xb5\xb7\xe9|\\\x84@\x1a\x98\x13\x87\xf6P\xf2S:\xb6\x1c\x82\xfe+~\xcc\x1bd-GBA4\x89\xcf\x10q\xac\x0cZt\xc7eIcd\'\x8b\xc2p\x9b \x98X\xca,\xd3fL\x81\xbf\xc7*\x89\x93f\xb0++\x18\x93\xccb\x07\xe7\x17\xac\x02\xccj\xf7i\rZ\x02a\xd0O=\x05\x19\\\x19\xa3i\x84\x8aj\x87Ov\xa6\xbc\x1d4\\\xbc7\x19\x93w~\x1f\xe7\t\xd9\x1c\xc8KfO\xdc\xd1\x86G\xf5Ij{{e\x93\xb6\x95\x07\r\xb2 Mow\xc0\xceG^\x922"\xa9\xa3P\x9f)g\x17\xf6wY\x1c!\xc8@\xa0\xd1\x02\xa4W1\xba3#\xad'
|
|
|
|
|
|
2024-12-14 20:35:36.562735 - Ether / IP / TCP 192.168.1.11:42730 > 142.250.184.14:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 33707
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.14
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42730
|
|
dport = https
|
|
seq = 1636439969
|
|
ack = 1816494065
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x8d8
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:36.601199 - Ether / IP / TCP 142.250.184.14:https > 192.168.1.11:42730 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 58134
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x58f1
|
|
src = 142.250.184.14
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42730
|
|
seq = 1816494065
|
|
ack = 1636439970
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1030
|
|
chksum = 0x6c9a
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (1636439969, 1636439970))]
|
|
|
|
|
|
2024-12-14 20:35:37.192757 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34227
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52703
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 39044
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.201009 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34228
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52704
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 39045
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.203229 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34229
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52703
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 39046
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.204607 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34230
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52704
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 39047
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.206311 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34231
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52703
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 39048
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.208468 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52703
|
|
len = 76
|
|
chksum = 0xcfa1
|
|
###[ DNS ]###
|
|
id = 39044
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.210181 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52704
|
|
len = 89
|
|
chksum = 0x6219
|
|
###[ DNS ]###
|
|
id = 39045
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.212312 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52703
|
|
len = 90
|
|
chksum = 0xc83e
|
|
###[ DNS ]###
|
|
id = 39046
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.214013 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52703
|
|
len = 81
|
|
chksum = 0x8391
|
|
###[ DNS ]###
|
|
id = 39048
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.218226 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52704
|
|
len = 51
|
|
chksum = 0x1649
|
|
###[ DNS ]###
|
|
id = 39047
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.240118 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34232
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52705
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 39049
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:37.244614 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52705
|
|
len = 81
|
|
chksum = 0x9d78
|
|
###[ DNS ]###
|
|
id = 39049
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:38.072224 - Ether / IP / TCP 192.168.1.11:41595 > 35.186.224.41:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 83
|
|
id = 8644
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 41595
|
|
dport = https
|
|
seq = 3242435589
|
|
ack = 2961047349
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xc5dc
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00&P\xaf}SA\xd2\xb0u\xd9\xba\xa8\xb3\xf8\xb3\x0e\xb0\x16\x98\x88=Cgq\xc0Y\x00\xf4\x16\xf3*\x1f\x96,\\\x8d\xcc\x96\xdb'
|
|
|
|
|
|
2024-12-14 20:35:38.096976 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:41595 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 54079
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xabf9
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 41595
|
|
seq = 2961047349
|
|
ack = 3242435632
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1036
|
|
chksum = 0x2cd3
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'm\x9eI\xc9\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:38.116016 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:41595 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 80
|
|
id = 54080
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xabd0
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 41595
|
|
seq = 2961047349
|
|
ack = 3242435632
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1036
|
|
chksum = 0x5ea6
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00#\xac\xfe\x1e\xb9\xdd\x00\xcb\xbd\xe3\x1e\x19Q\xfe\x15\x9en{d"\x1d\xb1\xdf9\xb2\x8a\x87\xae\x9aa\xe4\x88\xc1\xc3I|'
|
|
|
|
|
|
2024-12-14 20:35:38.162413 - Ether / IP / TCP 192.168.1.11:41595 > 35.186.224.41:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 8645
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 41595
|
|
dport = https
|
|
seq = 3242435632
|
|
ack = 2961047389
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 508
|
|
chksum = 0xc5b1
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:39.816212 - Ether / IP / UDP / DNS Qry b'ipwho.is.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 54
|
|
id = 34233
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64667
|
|
dport = domain
|
|
len = 34
|
|
chksum = 0x8390
|
|
###[ DNS ]###
|
|
id = 61640
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'ipwho.is.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:39.834084 - Ether / IP / UDP / DNS Ans 195.201.57.90
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb74a
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 64667
|
|
len = 50
|
|
chksum = 0xfbe2
|
|
###[ DNS ]###
|
|
id = 61640
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'ipwho.is.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'ipwho.is.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 60
|
|
| rdlen = None
|
|
| rdata = 195.201.57.90
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:39.846296 - Ether / IP / TCP 192.168.1.11:42768 > 195.201.57.90:http S
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 57668
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 195.201.57.90
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42768
|
|
dport = http
|
|
seq = 1867829416
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 64240
|
|
chksum = 0xbefd
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 20:35:39.880841 - Ether / IP / TCP 195.201.57.90:http > 192.168.1.11:42768 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x85ed
|
|
src = 195.201.57.90
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = http
|
|
dport = 42768
|
|
seq = 3819389530
|
|
ack = 1867829417
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 29200
|
|
chksum = 0x30b7
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('NOP', None), ('SAckOK', b''), ('NOP', None), ('WScale', 9)]
|
|
|
|
|
|
2024-12-14 20:35:39.883466 - Ether / IP / TCP 192.168.1.11:42768 > 195.201.57.90:http A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 57669
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 195.201.57.90
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42768
|
|
dport = http
|
|
seq = 1867829417
|
|
ack = 3819389531
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 513
|
|
chksum = 0xbef1
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:39.885561 - Ether / IP / TCP 192.168.1.11:42768 > 195.201.57.90:http PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 191
|
|
id = 57670
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 195.201.57.90
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42768
|
|
dport = http
|
|
seq = 1867829417
|
|
ack = 3819389531
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 513
|
|
chksum = 0xbf88
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'GET /192.168.1.62 HTTP/1.1\r\nHost: ipwho.is\r\nUser-Agent: python-requests/2.32.3\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:39.928427 - Ether / IP / TCP 195.201.57.90:http > 192.168.1.11:42768 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 12494
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x552b
|
|
src = 195.201.57.90
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = http
|
|
dport = 42768
|
|
seq = 3819389531
|
|
ack = 1867829568
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 60
|
|
chksum = 0xe2c8
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:39.932825 - Ether / IP / TCP 195.201.57.90:http > 192.168.1.11:42768 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 343
|
|
id = 12495
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x53fb
|
|
src = 195.201.57.90
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = http
|
|
dport = 42768
|
|
seq = 3819389531
|
|
ack = 1867829568
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 60
|
|
chksum = 0x5edb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'HTTP/1.1 200 OK\r\nDate: Sat, 14 Dec 2024 19:35:40 GMT\r\nContent-Type: application/json; charset=utf-8\r\nTransfer-Encoding: chunked\r\nConnection: keep-alive\r\nServer: ipwhois\r\nAccess-Control-Allow-Headers: *\r\nX-Robots-Tag: noindex\r\n\r\n40\r\n{"ip":"192.168.1.62","success":false,"message":"Reserved range"}\r\n0\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:39.938108 - Ether / IP / TCP 192.168.1.11:42768 > 195.201.57.90:http FA
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 57671
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 195.201.57.90
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42768
|
|
dport = http
|
|
seq = 1867829568
|
|
ack = 3819389834
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FA
|
|
window = 512
|
|
chksum = 0xbef1
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:39.975841 - Ether / IP / TCP 195.201.57.90:http > 192.168.1.11:42768 FA / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 12496
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0x5529
|
|
src = 195.201.57.90
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = http
|
|
dport = 42768
|
|
seq = 3819389834
|
|
ack = 1867829569
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FA
|
|
window = 60
|
|
chksum = 0xe197
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:39.978318 - Ether / IP / TCP 192.168.1.11:42768 > 195.201.57.90:http A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 57672
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 195.201.57.90
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42768
|
|
dport = http
|
|
seq = 1867829569
|
|
ack = 3819389835
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0xbef1
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:40.312394 - Ether / IP / TCP 192.168.1.11:37662 > 74.125.133.188:5228 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 38637
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 74.125.133.188
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 37662
|
|
dport = 5228
|
|
seq = 938547589
|
|
ack = 2945028699
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 508
|
|
chksum = 0x9208
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:40.351175 - Ether / IP / TCP 74.125.133.188:5228 > 192.168.1.11:37662 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 58348
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xcdea
|
|
src = 74.125.133.188
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 5228
|
|
dport = 37662
|
|
seq = 2945028699
|
|
ack = 938547590
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 1046
|
|
chksum = 0x5e6
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (938547589, 938547590))]
|
|
|
|
|
|
2024-12-14 20:35:40.895628 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34234
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52963
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 59939
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.898002 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34235
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52964
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 59940
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.900439 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34236
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52963
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 59941
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.901900 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34237
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52964
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 59942
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.903251 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34238
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52963
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 59943
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.905652 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52963
|
|
len = 76
|
|
chksum = 0x7cfe
|
|
###[ DNS ]###
|
|
id = 59939
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.907507 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52964
|
|
len = 89
|
|
chksum = 0xf76
|
|
###[ DNS ]###
|
|
id = 59940
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.909631 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52963
|
|
len = 90
|
|
chksum = 0x759b
|
|
###[ DNS ]###
|
|
id = 59941
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.911163 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52963
|
|
len = 81
|
|
chksum = 0x30ee
|
|
###[ DNS ]###
|
|
id = 59943
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.913750 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52964
|
|
len = 51
|
|
chksum = 0xc3a5
|
|
###[ DNS ]###
|
|
id = 59942
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.935494 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34239
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 52965
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 59944
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:40.940138 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 52965
|
|
len = 81
|
|
chksum = 0x4ad5
|
|
###[ DNS ]###
|
|
id = 59944
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:41.476730 - Ether / IP / TCP 192.168.1.11:42733 > 151.101.135.42:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 41
|
|
id = 18203
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 151.101.135.42
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42733
|
|
dport = https
|
|
seq = 2796051337
|
|
ack = 1613279978
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 507
|
|
chksum = 0xe05e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x00'
|
|
|
|
|
|
2024-12-14 20:35:41.493372 - Ether / IP / TCP 151.101.135.42:https > 192.168.1.11:42733 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 22166
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = tcp
|
|
chksum = 0xceb
|
|
src = 151.101.135.42
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42733
|
|
seq = 1613279978
|
|
ack = 2796051338
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 306
|
|
chksum = 0xd5f4
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (2796051337, 2796051338))]
|
|
|
|
|
|
2024-12-14 20:35:43.083296 - Ether / IP / UDP 192.168.1.11:57621 > 192.168.1.255:57621 / Raw
|
|
###[ Ethernet ]###
|
|
dst = ff:ff:ff:ff:ff:ff
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 49061
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.255
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 57621
|
|
dport = 57621
|
|
len = 52
|
|
chksum = 0x9f
|
|
###[ Raw ]###
|
|
load = b'SpotUdp0\x977M\xb3\xe9=C\xf2\x00\x01\x00\x04H\x95\xc2\x03\xb3}cPK\xb7\xed\x7fT~\x1d\x0f\xd7\x01\x15-#vA\xf6'
|
|
|
|
|
|
2024-12-14 20:35:45.062723 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 280
|
|
id = 26769
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf111
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995231451
|
|
ack = 212489243
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x35fb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00\xeb\x8a\x930\xcc/\x99\x86\x00W\xe7Y\xf8\x86\xb0\x7f\r\xfb\xd7\xf6\xe6h7\x1d\xe4\x87\xa2\x19\xe6\x90s\x05\xf6\x9fT{G\x8e\x0e\x1c\xd8\x8f\xd8\xa5\x04\x9arR\xfdzh)\xc1\xb9nu{i\xdd\xc5;(F\xb8|\xb7H\xa08\x12d\xaey\xef|\xa1\xc6 \x076\r\xb5w\xac\xc1'\xed\xa8wI\t`\xb7H\xf5\xcf]0n\xb1\x9bQiE\xcf6\xe4\x13\xc1\x8f\xd9\xfedM\x96.\xcaT\xa9B\xc9\xc8\xa0u\xb0\xb1\xedEKJk\xee\x1eC9\x8b\x00\x0b\x0cSb\x1dSY\xdbR\xa4\x8b\xa6I\x83[\xee\x94V\xdfq\x84.\xdaD\x1f\xc3e<{\xcc\x16\xf5\xe5\x80\xc1E1 \xba\x03e\xf3\x1e\x0e`\xf5c\\q\xa6\x02\x01\x80!+h^\x1a&|\xd5\x88\xf97d\xfb\xd1\x12\x9d\x0cy\xf8\xd3\x963\xe1{\xb6`\x94\x9b?~\xf8\x06\xd6X\x930\x86\x19\xe4\xf2\x8f\xa8r\xf1g\xe6"
|
|
|
|
|
|
2024-12-14 20:35:45.087565 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 81
|
|
id = 26770
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf1d7
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995231691
|
|
ack = 212489243
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x3ca4
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00$\xd4v}\x89\xfa ]\xff\x07\t\x06\xed\x95\x1b\x19\xdc9\x12\xa2\x8a\x897\x0b\xda\\\x949\xdd\x11\xe2d\xb0\x13\xb3h\x8a'
|
|
|
|
|
|
2024-12-14 20:35:45.094637 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 37108
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489243
|
|
ack = 995231732
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0xea57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:45.103892 - Ether / IP / TCP 192.168.1.11:40790 > 35.186.224.41:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 83
|
|
id = 8646
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40790
|
|
dport = https
|
|
seq = 3089482658
|
|
ack = 915357639
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xc5dc
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00&\xc4\xc8\x11zA,\xa4b\x05\xd3\xa0|\x11\x8c\xa9\xa6\x08\x8c\xd2\xfa2\xc2ML\xbe\xe3\xd9\xd4\xb0\xab\xcd\x8d\xfc\x14\x1eU\x92<'
|
|
|
|
|
|
2024-12-14 20:35:45.119852 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 81
|
|
id = 26771
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf1d6
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995231732
|
|
ack = 212489243
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0x3e28
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00$\xc7\x19\xd2=\xde]\x97v\x1b\xcd\xfc{\xd0\x99\xe6xP\xeb\xa2s}\xe5q\xd1\xe0j\xa2\xba:\x808\xf7H\x90\xb31'
|
|
|
|
|
|
2024-12-14 20:35:45.121875 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:40790 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 15312
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x4269
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40790
|
|
seq = 915357639
|
|
ack = 3089482701
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1043
|
|
chksum = 0x52cf
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x0b\x1a\x97\n\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:45.123889 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:40790 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 80
|
|
id = 15313
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0x4240
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40790
|
|
seq = 915357639
|
|
ack = 3089482701
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1043
|
|
chksum = 0x406
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00#\xaf\x9eW\x96\xf1\xf2v\xf2\xba\xfa%f\x06\x15\xad\x15\x90\xf4\xc6\xfe\x91x\x91\xf5'\xbeD|\xc4\xc6r]h\xab\x0b"
|
|
|
|
|
|
2024-12-14 20:35:45.125441 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 37109
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489243
|
|
ack = 995231773
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 511
|
|
chksum = 0xea57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:45.165069 - Ether / IP / TCP 192.168.1.11:40790 > 35.186.224.41:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 8647
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40790
|
|
dport = https
|
|
seq = 3089482701
|
|
ack = 915357679
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xc5b1
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:47.546371 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34240
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53276
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 19031
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.548587 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34241
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53277
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 19032
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.550535 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34242
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53276
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 19033
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.551970 - Ether / IP / UDP / DNS Qry b'47.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34243
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53277
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 19034
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'47.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.553739 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34244
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53276
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 19035
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.555666 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34245
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53277
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 19036
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.557717 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53276
|
|
len = 76
|
|
chksum = 0x1b92
|
|
###[ DNS ]###
|
|
id = 19031
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.559452 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53277
|
|
len = 89
|
|
chksum = 0xae09
|
|
###[ DNS ]###
|
|
id = 19032
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.561400 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53276
|
|
len = 90
|
|
chksum = 0x142f
|
|
###[ DNS ]###
|
|
id = 19033
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.563096 - Ether / IP / UDP / DNS Ans b'S22-Ultra-de-Adrian.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53277
|
|
len = 89
|
|
chksum = 0xd15e
|
|
###[ DNS ]###
|
|
id = 19034
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'47.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'47.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'S22-Ultra-de-Adrian.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.564739 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53277
|
|
len = 81
|
|
chksum = 0xcf7f
|
|
###[ DNS ]###
|
|
id = 19036
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.567253 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53276
|
|
len = 51
|
|
chksum = 0x6239
|
|
###[ DNS ]###
|
|
id = 19035
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.588247 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34246
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53278
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 19037
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:47.591754 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53278
|
|
len = 81
|
|
chksum = 0xe967
|
|
###[ DNS ]###
|
|
id = 19037
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:50.811561 - Ether / IP / TCP 192.168.1.11:40788 > 35.186.224.41:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 8648
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.41
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 40788
|
|
dport = https
|
|
seq = 948637572
|
|
ack = 1994427668
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 512
|
|
chksum = 0xc5cd
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x17\xc3\xe9\xcd\xc7\xb9vdU\xc9\xf5\x16e\xd45\xfc\xf1\x10\xde\xc5XF<\xb3'
|
|
|
|
|
|
2024-12-14 20:35:50.831474 - Ether / IP / TCP 35.186.224.41:https > 192.168.1.11:40788 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 49791
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xbcb9
|
|
src = 35.186.224.41
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 40788
|
|
seq = 1994427668
|
|
ack = 948637600
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1051
|
|
chksum = 0xf8f2
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:50.883536 - Ether / IP / TCP 142.250.184.14:https > 192.168.1.11:42729 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 113
|
|
id = 11441
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xf1a
|
|
src = 142.250.184.14
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42729
|
|
seq = 2391708146
|
|
ack = 3790787413
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1042
|
|
chksum = 0x7d5f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00DqP\xbf\x867\xf1o\xf8\xed\xb5\x83r\x85\xb2\x08\xe0\xfa\x89\xc7\xa1\x97\xc2B\x13\xa15\xear\xba\x14\xe36M\xed\x97\x7f\xdc\x88\xcb%J\xedQ*\xa1\x97%\x9c\xa0\x94\xb1\x9c\x84\xe4\xa8&\xa0\xc8sj\x14\xcd\x8bFN`\xd4\x8c'
|
|
|
|
|
|
2024-12-14 20:35:50.885909 - Ether / IP / TCP 192.168.1.11:42729 > 142.250.184.14:https FA
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 33708
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.14
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42729
|
|
dport = https
|
|
seq = 3790787413
|
|
ack = 2391708219
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FA
|
|
window = 512
|
|
chksum = 0x8d7
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:50.905583 - Ether / IP / TCP 142.250.184.14:https > 192.168.1.11:42729 FA / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 11442
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0xf62
|
|
src = 142.250.184.14
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42729
|
|
seq = 2391708219
|
|
ack = 3790787414
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FA
|
|
window = 1042
|
|
chksum = 0x244d
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:50.908546 - Ether / IP / TCP 192.168.1.11:42729 > 142.250.184.14:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 33709
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.14
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42729
|
|
dport = https
|
|
seq = 3790787414
|
|
ack = 2391708220
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x8d7
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:51.330562 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34247
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53536
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 53179
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.332467 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34248
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53537
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 53180
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.333944 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34249
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53536
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 53181
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.335439 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34250
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53537
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 53182
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.337224 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34251
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53536
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 53183
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.339301 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53536
|
|
len = 76
|
|
chksum = 0x9529
|
|
###[ DNS ]###
|
|
id = 53179
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.341296 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53537
|
|
len = 89
|
|
chksum = 0x27a1
|
|
###[ DNS ]###
|
|
id = 53180
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.343236 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53536
|
|
len = 90
|
|
chksum = 0x8dc6
|
|
###[ DNS ]###
|
|
id = 53181
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.344772 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53536
|
|
len = 81
|
|
chksum = 0x4919
|
|
###[ DNS ]###
|
|
id = 53183
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.348556 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53537
|
|
len = 51
|
|
chksum = 0xdbd0
|
|
###[ DNS ]###
|
|
id = 53182
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.371750 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34252
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53538
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 53184
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.375466 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53538
|
|
len = 81
|
|
chksum = 0x6300
|
|
###[ DNS ]###
|
|
id = 53184
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:51.442243 - Ether / IP / TCP 142.250.184.14:https > 192.168.1.11:42730 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 113
|
|
id = 58135
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x58b3
|
|
src = 142.250.184.14
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42730
|
|
seq = 1816494065
|
|
ack = 1636439970
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1030
|
|
chksum = 0xf074
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00DU\xaf\x9dv\xf3A\tZ\x93\x18\x1b\xb0\x0f\xe0m\x84\xa4{\xfdj\x8f'\xe3p\xbd\xa5\x08\x89u\xd5T\xdce8\x01\x03q\xf2/U\x91U\xa9P\xe7$\x18\x8f\x88h\x18\xb8n\x7f\xc2\\\xdcv\x17\xe3\xe9\xac\xf6w\xa3\xc2\xf2\xdb"
|
|
|
|
|
|
2024-12-14 20:35:51.444442 - Ether / IP / TCP 192.168.1.11:42730 > 142.250.184.14:https FA
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 33710
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.14
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42730
|
|
dport = https
|
|
seq = 1636439970
|
|
ack = 1816494138
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FA
|
|
window = 512
|
|
chksum = 0x8d7
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:51.460246 - Ether / IP / TCP 142.250.184.14:https > 192.168.1.11:42730 FA / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 58136
|
|
flags =
|
|
frag = 0
|
|
ttl = 118
|
|
proto = tcp
|
|
chksum = 0x58fb
|
|
src = 142.250.184.14
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42730
|
|
seq = 1816494138
|
|
ack = 1636439971
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = FA
|
|
window = 1030
|
|
chksum = 0x94be
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x00\x00\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:51.461916 - Ether / IP / TCP 192.168.1.11:42730 > 142.250.184.14:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 33711
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.184.14
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42730
|
|
dport = https
|
|
seq = 1636439971
|
|
ack = 1816494139
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x8d7
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:53.192316 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 417
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc5a8
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 397
|
|
chksum = 0xc02c
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: upnp:rootdevice\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::upnp:rootdevice\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.194937 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 489
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc560
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 469
|
|
chksum = 0x502d
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.196496 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x83e4
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.198195 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 485
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc564
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 465
|
|
chksum = 0x7632
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.199696 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8392
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.201029 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 465
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc578
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 445
|
|
chksum = 0x8a6f
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:device:WANDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.203482 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8394
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.204986 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 497
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc558
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 477
|
|
chksum = 0x3a9
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.207612 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 479
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc56a
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 459
|
|
chksum = 0x81a1
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANIPConnection:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:service:WANIPConnection:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.473478 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 479
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc56a
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 459
|
|
chksum = 0x81a1
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANIPConnection:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:service:WANIPConnection:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.475493 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 497
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc558
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 477
|
|
chksum = 0x3a9
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:service:WANCommonInterfaceConfig:1\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.477797 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8394
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.480672 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 465
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc578
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 445
|
|
chksum = 0x8a6f
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842ba::urn:schemas-upnp-org:device:WANDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.482649 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x8392
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.484608 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 485
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc564
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 465
|
|
chksum = 0x7632
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842bb::urn:schemas-upnp-org:device:WANConnectionDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.486489 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 426
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc59f
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 406
|
|
chksum = 0x83e4
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.488245 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 489
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc560
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 469
|
|
chksum = 0x502d
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::urn:schemas-upnp-org:device:InternetGatewayDevice:2\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.489993 - Ether / IP / UDP 192.168.1.1:60364 > 239.255.255.250:ssdp / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 417
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 2
|
|
proto = udp
|
|
chksum = 0xc5a8
|
|
src = 192.168.1.1
|
|
dst = 239.255.255.250
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60364
|
|
dport = ssdp
|
|
len = 397
|
|
chksum = 0xc02c
|
|
###[ Raw ]###
|
|
load = b'NOTIFY * HTTP/1.1\r\nHOST: 239.255.255.250:1900\r\nCACHE-CONTROL: max-age=1800\r\nLOCATION: http://192.168.1.1:64920/d15f795f/rootDesc.xml\r\nSERVER: Linux/3.4.11 UPnP/1.0 MiniUPnPd/1.9\r\nNT: upnp:rootdevice\r\nUSN: uuid:d15f795f-9d12-458e-874b-cb38ba3842b9::upnp:rootdevice\r\nNTS: ssdp:alive\r\nOPT: "http://schemas.upnp.org/upnp/1/0/"; ns=01\r\n01-NLS: 1\r\nBOOTID.UPNP.ORG: 1\r\nCONFIGID.UPNP.ORG: 1337\r\n\r\n'
|
|
|
|
|
|
2024-12-14 20:35:53.883534 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34253
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53796
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 43406
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.885687 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34254
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53797
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 43407
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.887914 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34255
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53796
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 43408
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.889685 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34256
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53797
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 43409
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.891075 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34257
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53796
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 43410
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.915214 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53796
|
|
len = 76
|
|
chksum = 0xba52
|
|
###[ DNS ]###
|
|
id = 43406
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.917332 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53797
|
|
len = 89
|
|
chksum = 0x4cca
|
|
###[ DNS ]###
|
|
id = 43407
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.919918 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53796
|
|
len = 90
|
|
chksum = 0xb2ef
|
|
###[ DNS ]###
|
|
id = 43408
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.921880 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53796
|
|
len = 81
|
|
chksum = 0x6e42
|
|
###[ DNS ]###
|
|
id = 43410
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.924301 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53797
|
|
len = 51
|
|
chksum = 0xfa
|
|
###[ DNS ]###
|
|
id = 43409
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.938612 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34258
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53798
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 43411
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:53.941821 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 53798
|
|
len = 81
|
|
chksum = 0x8829
|
|
###[ DNS ]###
|
|
id = 43411
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:54.939890 - Ether / IP / UDP / mDNS Qry b'_233637DE._sub._googlecast._tcp.local.'
|
|
###[ Ethernet ]###
|
|
dst = 01:00:5e:00:00:fb
|
|
src = 6c:f7:84:e4:d7:de
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 89
|
|
id = 65519
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 255
|
|
proto = udp
|
|
chksum = 0xd8e3
|
|
src = 192.168.1.28
|
|
dst = 224.0.0.251
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 5353
|
|
dport = 5353
|
|
len = 69
|
|
chksum = 0x32a6
|
|
###[ DNS ]###
|
|
id = 6
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 0
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 2
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_233637DE._sub._googlecast._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'_googlecast._tcp.local.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:56.103861 - Ether / IP / UDP / DNS Qry b'gew1-spclient.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34259
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64667
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 21332
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'gew1-spclient.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:56.107739 - Ether / IP / UDP / DNS Ans b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 136
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb708
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 64667
|
|
len = 116
|
|
chksum = 0x86ba
|
|
###[ DNS ]###
|
|
id = 21332
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 2
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'gew1-spclient.spotify.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'gew1-spclient.spotify.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 139
|
|
| rdlen = None
|
|
| rdata = b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'edge-web-gew1.dual-gslb.spotify.com.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 7
|
|
| rdlen = None
|
|
| rdata = 35.186.224.26
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:56.110724 - Ether / IP / UDP 192.168.1.11:53339 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 5435
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53339
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca83
|
|
###[ Raw ]###
|
|
load = b'\xc4\x00\x00\x00\x01\x08\xc2\xc0\x97\x0f\xf5\xc4?@\x00@F\x00\xe2=[4\x96\'\x15z\x1blM8H\xd5\xa0\xa9a\x8d|\xa5\xc9\xe5[QK\x82i\xfc\x96\x02"\xea\xbb\xd7\xda\xd7\xbb\xe3\x01\xdc\xeeC\x83\xc9\xb0N\x87\x85&a\x07\x1dL\xb9\x17\x90\xda\xcbfh\x8e\xd5)\xb0\xc65\xd1\xcf*D\x89\xbb\x86\x94G\xee\x90\\:\xd4d\x18\x98\xdf\xefH\xc7\x85N~\xff;\xb4 \xf2\x04N\xddM\xe1\x0b1`Q&\xab\x00O-u\xaa\xe5\x1d\xf0-i\xbc\xc2\x97\x9e\xd7"\xba\x7f\xf7\xf2\xd2\xf9\xfc\x8b\xea\xd5\x949\xc6\x84&\x18\x18\x07\xb7\xad\x98\xafr&\xcd\xe2\xc2U#a\x00\xfac\xfd\xba\xe0\x14\xce\xcc?u\x1f\xbf\x99\x9a\xf9\xf8\xe9\xa0%\xe5\xa6\xbb$\xfbs\xd5\xa7\x8d\xeb\r\xdc\xf1\xba.\x9fvi\x04 #\xb1\xb6*\x1b\xf0)6q\x87#\x10\xb1\x82B\xed^3\xebF\x9e\xe8Q\xa8R{(\x01t3\xd1H\x86\x8a\xb8\x89S=\xd9R\xf5!\xe6\xbf\xbc\xa4e[\x96~`\x03t\x9e\x9f\xf5\x0b{\xd4\xf9\xe1\x1c;\xee\x8d\xa5B\xea\x12u\\}\xe4\\7D*%j/\x97\x86\xa4ff\x97\x1f\x9b\x0eE\xd0\xb3\xa0\xb8H\xbb\xd2%\xd5\'`\xd5\xb1"g\x7f\x1a?\x08\x12\x16`\xe6\x04\x9ffz\xa2(@xD95\xae\x18\xb0)\xf3\x1b\xfdw\xd8\xab\x90\xd9\xd6\xe2"\xae\x8d\x98\xc4h\xc1\x9b\xadc\x8c\xceUzY\xbcSV\x86\xce\x84\x8b\x87c\x80\xd6:\xcc\xee\xd7 d\xce\xac\xb4g\x80\xcd\x11\xbf\x0e\xc0[\xfcJ;\xf3\x8a\xc0\xc5\xa8\xff\xfcW\xc1\x1c\xc0\xbe\xc4GG\xd7\xf6\x84el\xc2J\\\x16\xcb9\xf5H*\x00le#\xe5\x02\xde\xd1\xadG\x06\x03\xe1\xe8D\x0eN\xd8\x84\x81L\x11?\x84?\x84\xe7<n\xdb\x06@\x8e&\xe0j\x83\x9a\x87\xddC\xcb\xc8\x02g\xa2\xd8\xb9s\xad\x1e\x1d\xba\xa6#\xc7\x81\xb7\xf6\x0fZ\xe49>\xe6R?\x83\xd2i,\xa6y\xfc\xb22\x8f\xda\xca\xaa\x0b\xac.\x8eV\x89/\xdd\x04\'\xc9\x0ffx\xc6\xf2c\xcem\x9dIgi\xf45\x1e\x92\xf1\xc1\x07\xab\x18\x89\xef\x81\xe1\xc1L\xa1\x0e[\xe3jb\xd5a]\x8b\x80\xc9\xbe\xebT]<\xd5\x80b\xa6c\x1a7\x0e\xaf\xdcS\xe7!\xe9\x94cP\x14\xcf\x00\xbf\xaa\xe2R\x19\xbd\xd0\x8d\xf8.\xb7C\xd4=&8\xc3A\xef\x05\x83lv].\xa1\xfd\x19\xa7\xf9\xfb\x8a\xb4\xc8_\xc5\x85a\xd2xvd\x1cP\x951iD\xdd\xb8#\t\x9f\xccm\'\x9c\x1d\r\x00\xb0\x89hF\xb5\x85\xbf\x94\xb4^\x8d<TQ6G\\\xfd\x9f\xe4\xa2\x1b\x17\xbcJQ\xea\r\xd9\xb3\xf9\x18"\x02\x960\x90\x91\xd0\xaeomH?\xfbch\xf3\n\x88\x1a\x03\xb1Hnr\x0f!\xa4\x9b\xe7\x8f\x86\x01oCre\xa9\x95]\xef\xf7\xc80\x15\xd2\xcfvQ(\x80]\xc9+l\xc5\x88,\x82\x84\x81,|\x04\xf5z^\xbb\xe6(\xd9\xf6\xe1\xb7P~\xab\xaa\xda\x15\xcd\x11\xcd,\xd8]\xee\xe7Dl\xde)\x19\xb1k\xea\xd3\xa5\x07I_{_\x06gF\r5\x88\xdf\xa2\x1c,9\xfcd1\xe8\x86\xba\x89\xc1\x82\x986\x03\xb9[G\xa9\x1a\xeeg\x8a^r\xa4\x15&\x8c\x9b&\x96\xee|\xf0\xce\x0eW\x9a\xdd\x8e\xc9\xa5\xfb\x9e\x16\x9emu\x0b4_G\x84\x10\xbf\xd5\n\xb9\xd3\x8d\xa3|A\x82\xf6\xd3?\xe7WV\x92`\xa8L\\&L3\x84\x7f\xf4>s}\x16\xa8g\xa9\x97\xf6\xf8\xf0\xc7\xc5\x92do\xcbe~\x83\'\x05\xb7\x88\xa8\xef(\xd7\x05\x07>\x8f\x99j,\xe7\xca\'\xee\xd24\xc4\xdck\xc9k\xa9i\xdd\x9ar\xa74\xffh$w\x0cN\xc6S\x88\xa9\xa2\x08\xab8\x99k\x91\x11\xc3\xc7\xb5\x13R\x8d\xb7\x89YI\x83\xfbR\xdb\x89\xa8m`*]\x14\x1b\xcbP<\x16\xda9\xa0\xd9\x13\x90\x85\xf8\xcc)\x1a\xc94f\x98\xca\x18\xb0\xa1\xaa\xe6k\x8a\xc8\x13\xaa\x9e\x85\x15\xf4\x01\x00\xb0\x063\x87\xce\xfcj\x98\x01\x1df\xb0\xd3\x14\x06\xfe9\xde@\xf6qLi\xafQ\xa7\xf4#U\xac\x08\x92\xb0\x94\x19\xfb\xef\xf5<\x80\xcc\xd1b6@\x80\x8e\x91\xdf}\x99\x91|{\xd4\x8a\xfd3\xb7\\q\xa0\x80\x17N\xe3o\xa8\x93\xe0:\x1c2T\x056\xa6rT\xafJ\xe9\x89\x1dH\x02#\xe1\x1a]\xe8LSX\xcbz\x15\n\xdd\xfa\xda\x96\xe4\x17FG?\x02\xaaE\xca1\xc9ZR\x9dg\xe7\xa4n\xe3V\x96\xa1\x85\xaa\xfe\xcb\x8d(I\x9b\xa0\xd1p\x8e\x94R\xa1\xe0\x8bFn)\x97u\x96\x14\x93\\xB\x80c\xd3\xdeu!\n\xd62\xf3\x8f}\x009\xfc\xff\x1a\xc4\x9d)\xc4s\xa1\xef-\x9e\xe0\xe7`N\xe9\xb6\xa4\x12\x98\x8d\x97\xc4\x9bGt\xd0Mp\x88\xb9\xbc0I\xb2\xa9\xcdv\xba\xeabT\xe7\xdc\x13\x89\xdb\xbe\x96\x08~\x0c\x93>&"\xbao\xd7c\x13\xfd\xd5q\x1czK\x8f?\xad\xac~z\x83j6\xd6\x93\x81\x85\xe1\x11\x94 \xa6\xdb\x9fmP\xaf\x9e\xee'
|
|
|
|
|
|
2024-12-14 20:35:56.236109 - Ether / IP / UDP 192.168.1.11:53339 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 5436
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53339
|
|
dport = https
|
|
len = 1258
|
|
chksum = 0xca83
|
|
###[ Raw ]###
|
|
load = b'\xcc\x00\x00\x00\x01\x08\xc2\xc0\x97\x0f\xf5\xc4?@\x00@F\x00\xe2=[4\x96\'\x15z\x1blM8H\xd5\xa0\xa9a\x8d|\xa5\xc9\xe5[QK\x82i\xfc\x96\x02"\xea\xbb\xd7\xda\xd7\xbb\xe3\x01\xdc\xeeC\x83\xc9\xb0N\x87\x85&a\x07\x1dL\xb9\x17\x90\xda\xcbfh\x8e\xd5)\xb0\xc65\xd1\xcf*D\x89\xf7\xd74E\xac\xa5\x92:\xe7\'\xb2\xae,{\xd6\x9ei\x17\xf5bG\x0fR\xd1E\xe7Fr\x8bA\x88[\xa6q\x0f\xc6\x01\xbc\xd2E\xb5j5\x9d\xf9]=\xad\xe4\xcd$\x16\xfe)<\xaeB)F\x84oM\xd95>\xbe\x83\x8bQx<KW\xb8D\xe7\xe1\x9a\x9b\\}\x1d\xd2m\xd7\xf6\x86\xbf"\x9cn\xa2\x1d\xc2z\xe0-\x9d=&\xe5\xeb\x8a\x88\xb3\xbdI%o\xf4d\x8a\x1f\xde5\xe2\xf7\xcb\xd5dz\xce\xa3M\x17\x89\xff\xdeTU\xf1\x9b\x0f\xc5\xfd\xf4\xb5\xc9\x14\xcf\xf1\xadc\xa7?_gtU^\x9b9s\x16\t\xc7\\W\xea\xd6\xcf\xfd\x04\x11C\xc4O\xe2J\x15=:\x1eM\x1f\xb7\xed.\xe0\x02\x13>\x87e\xfb\xd4L7\xed]\xd0\xf4\xcc\xe9L\x1fL[P \xbf\x82\xa0.\xb9\xc1Q\xdc\xff\x89\xf0$8\x90;\'\x80\x8dk\xd9\xca\x8eX\x00\xc2\xf8\xe4W\x91\xbc\xc7\xa9\xb7\xceG\xa4:\xdeV\xf7\x94\xf0\xd5\xe5I\xf02\xea\\\x12{\x00 \xc9\xbfCZA\xeehB\xf4Hf\nh*s3\xc0\x81;NG\xa71\xa0x|g6\xa3\xe96\xdb\xdc\x06\xb4\xb6\xe1\xe2Qk4t\x17\xd6s\x01]w\xcbM\xeb\xf9\x03\x99>\xb0\xbd\xba}Y\xa9\xc5\xff\xda\xb1p\xb8\x97\xaf\x89y\xcb\xdd\x8c\x9f\x15^\xa4h\xd5\xd6\xbb\x9eLR\xba\x96\x1d5T\xefi7\xe2uHBc\x7f\x07[P\x0f\x87\xef\x0cR \xc7\x01\x83\xa8xB&QP\xdb\xc0\xc6\x97ES\xa6?\x96\xaf\xcb6\xf5luP\xc1\x1d\x10\xb23\xd9\xbf.\xa8\xdc\x8d\xae\xf5l\xa6\xa2^ \xe9\xa5\xcb\x15\x84\xad\xf2\xe6\xd1\xa5\xe8\'\xb8ar\x80\x0b\x10u\x8b\xfe\xdc\x95\xe4_\x1b\xa1\xea\xa3\xd2\x03\xe5&\xe1\xd5\xcb\xbc$\xc4\x1f\xca\xcfR\x0e\x89&\xa4\xa13\xfah\x1e\xf9\xb6\x05\x1a\x84\x13\xd1\x11\x91+\xc4\x1a5\r\x17\xb4\x99;\xd2\xe9\x93"~w\xbbQ\x83YI\xdd\xc3\xec\x1f\xe2l\xfc1a\x1e\xb5\xbfR\xdcFP\xb5wb\xba\xcc\xde\xf4\xb0\xce\x90G\xf9\x84.\xb35\xf2\x0e\xc0\x16\x1c\x94\x80\xfc\xc8\x85d\x07\x98h\xbe@\x80Zo\x86\xb3tc\xbfP\x8c\xd3$g\xf0\x1e\x84\x94\xd3\t\x94\x0f\xa5\xeb*\x1cR\xd2\xb7\xbb|\xd4m\xdf\x99L\x81\xcc{\xcc\x03\xe4]\x0bjc3\xd4\xc30;\x04\xae\x03\xc2\xe2J\x81\x19\xd5\x9f\x04\x00:L{\x94U\xd5\xa2\xc8\xd8\xff\x14\xecqJ\xc0\xa0R\x06\xf9\xe8\x87\xcaw\xe6\xf0v\xb5,\x08 \x14\xcf0)\x83~2\x99\xba\x86\x83X\xd0\xd2\x99\xcf\xdd\xe0\x9a\xb6\xf8\xe0p\x9d[Y\xfcF\xf3\xad\xcb\xd1\xca\x188\xf4ZM\xe0\x9b-\xb2\x93f\x89`\x184\xf7\xb2X\x94\x10\xe0\xa8~\x93Ge\x0e\xb4\xb6\x9c\x9as\xf99\r\xe6\x97\xe6\xa8\x08\nl\xbfl,V\xe2\xa9D\xc00K7\xa6\x1d\x81%\\5\xe3t\xe2\xdcn\x00\x93\xb9\xa6\x97H&2\n\x94c\xf7Qs\x04\x07\x02\xa6\x15\x1f\x8d\x11 \xcb\\\xf9"*\xd1\xc0j\xf20\x95\x90\xc9p)\xc6\x1b\xdb|\xe4\xec?YX\xea]\xa7N\x9f\r6\x9d.\x04\x90\xf7\xa934\x93\x95e\xdf"\x86\x91\xf5\x02i\xd9\x15r\xadT\xe3\xbd\xb9\x07\x9c\xce\x87WR\n\\\xb8[\x94,\xf90\xf1\xe1\xd4\xc3^\xaa\xeb\xee\xeb\x0bXZ\xc9\xb9\x15\xbe\xff\x16\x0f\xe6\xe9 \x81\xcd\xad+\x95S\x04v`\xad\xf1\xc2\x8e\x80\xca\xf5\xe9\xee\xc1\x8f0\xaf/)f\xfe\xa4\xac\x8e)\x99\tH\x07\xb6\xb0%@1i-\x8d\x04~z\xf8\x1a\xd9\x04\x1c\x02)\x05\xaa\xe2~mm.\x0c^H\xb3\x9dY\xe1\x96u\xe1Q\xbb\x05\xe1\x03H\x89\x07K\x1fkv\xe9l\xb6\xfe\xffH\xd4\xa2\x85\x86\x03\x9fHG\xe2\xef\x7f\xde\x95L$\xc6\xf76\xb9\x98\xab\xedV.\x1c\xe5\x8dP\x9a\x91\xa0T\xe7\xb1k\x8f\x14\xcd\x00\xb0\xdb\xbb\xefZ\x15W\x9d\xde3\xb1V \x03\x94\xdb\xae\xdd\xd0\x84\xa6\x13\xed\xd1Hw-\xca\x91\xe0\xfe\x1b\xb8\x8d\xc21\x12ZX=L!\xdb\x86\xdf\xaa\xde\xcf\xae\xea@,!3\x0b\xec\xa2*\xf5^\x14\xb1\x90\xf2Q\xdd"\xc0\xa3\x02KF\xbc\xdf\xa6\x86\x02\xbaN\xeb\x99\xf0K@\x80\xb7\xc8\xfcF\xc3\x8b\xf2V!g\xc2n\x1f\xc4\x9e\x1d\xa8\x91|\xc2E\xcb\xf6\xa4U\x8e\x9c\n\xf7Cy\xda\x0b^\xd6\xc1\xbcV\xcc\x9c(\x06\\=\xb8\xc6p\xc2t_ .j\x0b!W\x04\xa0\xfd\xf6{\xf8\xcc\xbcw\x8c\x98\xbd\xdc"[\xb7\xc9\xc1(\xf6\x15\x14\x95\xb98\xf5\xe7\\\xd3\xa9\x0f\xf1\x07bbX\x93\xb5\xa8\xdd\xb9\x81\x9frlZ&\xbb\xd5\x88\xeb\xea(\xe1\x1c4'
|
|
|
|
|
|
2024-12-14 20:35:56.292856 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:53339 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 68
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7e21
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 53339
|
|
len = 48
|
|
chksum = 0xd678
|
|
###[ Raw ]###
|
|
load = b'\xc7\x00\x00\x00\x01\x00\x08\xe2\xc0\x97\x0f\xf5\xc4?@\x00@\x16\xce-\x16\x83\xa3\xc9\x1e45\xf4?[\x9e\x9dmnKL\xce\xf3if'
|
|
|
|
|
|
2024-12-14 20:35:56.310565 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:53339 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7967
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 53339
|
|
len = 1258
|
|
chksum = 0x8f2e
|
|
###[ Raw ]###
|
|
load = b'\xc9\x00\x00\x00\x01\x00\x08\xe2\xc0\x97\x0f\xf5\xc4?@\x00D\xd0\x98$\xcc_\x980\xa0\xa6T\x93Aw\xbd\xd1\xbc\xccy>&\x173\x19\n.\xecp\xd6\xf5\xe5\xdc\\g\xf2\xe5[\xd4\x18\xdc\x92J\x103A\x08\xc3\x14\xa6\xc2\xb1+\xa9\xd4P\x85\xf0,\xaf\x16~\xcf\xec\xa3+\x9eHc\n9\t\xfd1^{\x13d7\x18\x948^3\xd4\xffs\xf4\xfe:\x9a\x8f\xcd`u|\x10\xc1\xc0\xc4\xe5Y\xe2\xc7\xd6K\xda\xdf\xd96\xe4\xc0IR\xc6\'\xf4?\xa15J\x84\xa8\x9d\x13\xe9-\xab\xd4\xaa\xf1\x97\xa7\xad.\x81\x03\xcfo\xfa\xccPo\xd3\x9f\x8d\x87K=\xd4o\xa67\xcfBv\xe0LM\x95\x8b8\x95\x08\x07\xd9\xeb\x8f\xdb\xfd\xd6\x9e\xee\x12\xd2\x86\x81j\xa0\x06\x9c\xf6\xef\xd8\x91\x9e\xaf\x8fwS\x16\xfc\xe4\x140?\x0f*|\xe4\x12\x90@\xcf\xc4AT\xb6A\xb1\xbaM\xb7\x82\x1e\xc7@\xb19\x1c\x08\xfa\x9e\xb7il\x0c\x84\xc6\x06#\x85\xdbO\xf4\x8f:\xae\xf7\'V,\x86d\x9ck\xebnNF\x90\x07\xc0\xe0\x0b\x99\x02\x8d\xee\xb6~-\xeb8\xf2.\xaeZ2\xacP\x1f\xd3\x8eLjx/\x86\x83s\xe3\xa9|\xc9\xb6\x8a\xc3\xa4\x9e\xc1Ts\xc0\x10\xad\x12\x03Z\x1d\x81\x07LM\xa6\x947/5<^\xe7\x8e\xd6\r\xd2:\xf2\x01y\xd1\xc6QQ\xcce2\x00W\x1d\xff\xa4\xd2\x87\x9a\x91\xca\x82\x9b\x9a\xe2\xea$\xa7\xa2)\x94\xce@\xbb\x99f\xbc\x034\xce\x12\xf0\xcfvx\xae\xeaEl\xcbVC\xd13\xca\x1fNs\xc4\x16\t\x98\xfdw\x16\x9f5\xd0\xbe\xac\xc6\xce&N\xef\xd9\x08N\x01\xaa\xb9\xe5i\xbb\xcc\x01B\x16h\x82P\xf9j\xb5\xdb\x0f\x10\xd4\\\x0e\x98\xf6@\xd1)\xa1\x9f\xbdJ\xd07\xe3\x9c\x1f\xafs\xeb\xdd\xfc\x12J\x938\xea\xde\x84\xbe}^\x07n\xeeM\x7fi<|%\xe7\xfaZX\xd5[\xed\xb5&\x89@\xd8\xed\xe2o_g\xf8\x13\x86+\xdb\xbf\xc4\xdb:\xf1{\xfc\x04\x1b\x14\x1bb\xcd\x91\x9dn\xfe\x15\x15-\x07e\xc3\xda]\x89c~$\xc9\xaf\xcdi\xa0\xa5\x89S\x1e0\xc5\xa5,\xe2\xd8\xb5)\x83\xa9\xb0\x83"\xc4\xf4\x03\xe3\t|\x0f\xb2\xadb\xc4\xa3tF\x15\xe8\xdb\xe39l\xf5\x7f\x15\x8c\xab\xfa\x86\x0b\xf3f?\xb0\xb5+\xe9\n\x8a\xfd\x8e\xe0Dg+\x8a\\\x1b+LOApK\x17\xb9\x01\xaa\\A\xea\t0\x82?\xef\xd5!\x8c/\xc9v\x13\x10xp\xa80r\x03\x1c\xc7\xe3\xa1\x1bn\xb6<\xb5&2X\x16U\x99\xc9\x7f\xce\xddt\x02\xbdw\xc1\xdb\xa1\xcc\xc2`\xe6\xe3\\\xd0\x06\xac\x10v\x19\x8e\x12\xe4\xfc,\xad\xffa;\x97\xfb\x8bL5\xc0\xd8\x03[\xc9\xae}k\x9b\xb1lo\x91\x08\x8e;b\xb0\xfa\xfa\xe7Q \x13^\x93P\xed~\x8bD\xda,\x90\xb9_A\xb2I\xa67Aq\x1e\xc5\x86\x8e%i3\xcc\xdca;\xc4\x84\xe3\xb6\xa5N\xb8\xb4%U\xfc\x13?X/\xdc\xad\xdb\xf4,\x7f@\xaf\xf73M\xff\x17\xa0\x04\x9f#@\xdeS\xbbc\xaa\x07\xb8\xbb\xb3=\xa9\x1a\xef\xc4\xd1w\xe4\x88x#\x12S\x1ao\xea\x97\x12\x11\xc1\xa5\xa0\xdb\xea\x1eI\xce\x11E$\x83\x13\x85\xc5;_\x06\x7f\xeeI1\xf2\xae\x86\xb3\x16,\xeaD\x13:\x8d\t\xff\xa7\xdd\xe4\x88%\x11x\xfa\x96\xe2\xf7\xa2\xcd\x83\'\xea\x88\x9dl\x9ae\xacC\xacx\xfd\xfc\x98\xc0\x8d\x9abH\x18tnU\xc6\x03\xca\xb9\xa4i\xff\xf7\x82\x81\xcdp\xe2\xe9s\x8eE\xdc?\xd9%\xf3\xd67/}\xeb\x14\xc2\x87\xda\x0c\x1d\xd2\xf9s\x979\x9dl\xc0\x1f\xd0\xbb\x9d7\r\xe6\xae\xf4\x80\xb0R\x17\xf6\xc2bc\xb2\xde%\xcf\xe4X\\\xf2\xb8\xdf{V\xf8BbR\xa4\xc1\xf9|\xfa\xe1m\xaf\x05\xf2y\xce\\l)/\x9dha\x9d\x93\xe4\x07\xa4\xca\x98\xb2I\xb2\xca\x05[\xc1\xc9\x8c+\x8dP\rb\xdd|[!\x9c\x16M\xb1\\)\x93U\xc5\xfc\xb4\xa4\xc4C#{\x88\xd7\x11\xf6t\xdfd\x8a}\x0b\x87\rg\xe9\x1b\xfb\xb2\x84\xc5\xaa\x9cz,\xc9\xe7\xfa\xfa4\x7f\xb0\xed\xa0\xf7\xd4]\xaeE\x93\xf1X\xa9\xb6\xc6p\xad\x9dO\xbe\x1f\x1e_\x80\xe4\xfc\xc7\x071\n)v\xc5u\xf6\x9dDb\xb4\x88\xb8\x8e\x97u\x9baj\xd1i\xd1&\x88\x19\xe1G\xc9\xa7m\x9ax\x91\xdd\x14\x0b\x02\xac\xa1n\'\xec\xe5@$\x94\x92S/\xe7Vt\xf6\xef\xe2\xf9\xeb~\xce\x1e\x9c\x7f\x13\xe1?\xd0\xb2\xda\x04\xef\x9b\x97,\x14\x1e\xb6\xfc\x07%\x8a1\x9a\xacr<\xc1\x98\xa4T\tky\xaf \xb7I=~E\x16E\xba\xd3\xa7\xaf\xd0\xf6\xdd\x0ed\xdd\xfa\xfcQ\xa6\x92\xddn%\xd8p\x18\xf0\xed\x7f\x00\xc7\x90\xf3O\xa6\xe1\xb2jS\x80\xa1IF\x0e\x0eo\xca}\xc8\x08\xb4 \x12\x88l\x06\xad\xa0\xa2kw\x1f!\xe6\xe98\xc0\xf8WC;\xbc7h\x07\xab\xa2\xb7\x00\x11\xafe3\xca\x9e\x98W\x13>\xbeY\x1d`=\xb6i\x1e\xb9\xf4\x96= \xa7\x82%'
|
|
|
|
|
|
2024-12-14 20:35:56.395627 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:53339 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7967
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 53339
|
|
len = 1258
|
|
chksum = 0x1233
|
|
###[ Raw ]###
|
|
load = b'\xc4\x00\x00\x00\x01\x00\x08\xe2\xc0\x97\x0f\xf5\xc4?@\x00C\x9f\x83\xe6\x03\xee\x96\xbd,,\x90\xa2\x0b@\x9f\x152\xfa\xd02Z\xedC\x99\xc6\x94\xba\xa6\x94\xb6at\xcd\xb1F\x9c\xeeGL\n\x96\xc3\xd1>\xaf\xb6\x82z\x15\xd9\xbbi\xc3*\xbfi\xb1\xce-\xaeo\x0c\xef;\xc8k\xa3\x83\x96\x85S%dv\xf5\xacq\xc9\xf2\xdb\xa3\x85\xf3\xfe\x89\xb0R\xb7\xdd\xbf4\x7fs>&C\xbf\x8a!H}\x85\x17\xd0\xcf\xf3\x14\xc9j\x0bY\x96\xec\x16\'\x96;\x97\xfb\xde\x97\xff\xc9\xc2\xf5\x17\xe6\xd41\xf9\xd7\xee\x97!\xce\xa7Hh\xa6\xd8\xb0\xfa+\x98\x92\xc6\x06\xe5\x1c\'\xe9\x12\x92J\xf5f\x8bov\xc4\xde\x93\x91T\x87\x15\x93\xb6\x12\xe5I\xa4I\xdc\x0b\xda\x9b\x08\n\xb5\x84&_\xbafo\x1a\x93\xa3]P\x8d0\xd07\xf06\x8a\x078\xd8\x022\xfd)\xdd\x8dC\xd4\x8a*;\x0b\x12i\xd48\x05\nE\xcb\xe1|vB\xb0\x9b\xfd\xff\t\xdbX\xa9=\xe8\x8e@YO\x8cC>\xc6\xb8\x93\xb9)\xe5to\xce1\'+\x80\x80M\xb4&\xad\xc8\xbd\x1f\x0f\xc9\xe1\x14\xeaKa\xb7[\x80\xda5\x83\x12\x86\x9d\xc6\x18\xe8\x92\xf0\xe0`\xa9*\xde\xfc\xf9\x7fF/\x9eL\x96\xca\xcd\xb7\xf0\xa7T9kT2\x1d\xee\xba\xea\x9aO\xe7\x1d\xaa\x1a\xb1{\x1a\xbd\x03\xbb\x15\x95\xed\x14W\xb6\xfe\xcfX\x89%\x9e/\x08\x9c\x04x\xf6\xee\xbc\xb3a\x82\xa7f\xae\\\xa0\x15\x18\xd3\xdc\x97\x13\xd8X6\x83\xfb\xdaFzK\x1d\xd5\xcaHsI0\xbb\xc9\xd2\xf1*\x98\xec93T\xbfqJ\t\x19\x8a\xc7\xb0\xb4\xfe\tj\xe3L\xf8\x98\x03\x98\x82\x16\x8c\x9f\xf7^\xe3\x10\xfcS\xeb\x1a\x0c\x0f<!MrM\x10>68\xc3+W\x95\xab\xef=k\xc7\x04\x99\x80\x17\xfa\xe1\xc6\x11\xaf\xc0\x05\xcbI?6m\xa8\x8eU{X\x06\xaa~ \xae\xb8G\x1e\xcbh\x8f1\xe1I\x8b\xc6\x98*\x94r\x90>V\x19\xac\xa4\xb009E2\'\xdeO\x1b\x9fzf\x08\x16&\x83L\x84e\xac\x92Gk\'\x9c~\xab\x1e\xd6\x0b\x0c\xf6\x1b\\@\xb85\xcbWWl\xe8\xd3\x05-\x83#[\x01K\xef\x1f]x\x1cP\x8d\xce\x8eU\xf5\x84\xeb]\xd1$\xbe\xd7\x1cAK\x8e\xfc\xc0l\x95=\xe9\xd0\td\xc3\x82\xc4\xd4\xfd\xd5\x05VB\x82L#/[Kb\xaf\x19\xd5~\xb6\xd4%\x86M\xf0\x9a\x91\xff\x0e\xd8l\n\n$\xea\xd8\xad\x03\xe0\x844\xc9\x82\x92\x13\xbc\xcb\xd6\xe4\'\xc2\xe1\x18t\xcbe\xa21\x89z\x14\x88y\xa3:\x10\x95\x95\x86,\xbc-\xd4Jz\xe3\x93\x0c\\\xd82\x16\xa2{h>\xb9\x9em\x91\xd6\xb9\x0b\xb9\x19[\xc7\x98`\x92\xf2\x90xq\xb6\xc1\xefekcK\x820\x94\xa4\xc1\xa1I.\xeed\x91\xd5\x85D-\x04\xa5\xc5\x96\x96\x9dir\x88\xb1\xb9\x8e\x82b\\\x1c\t!\'`\xf1\xb7\x10\x1f\xacM\x0c\xe4)\xaf\xf1`{\x82/\x8b \xb7\xe7\xbd[\xd2\x93\x9e`\xb5Gw\xe6\x1aY\xd9X@\x16\xcb\xeey\x18\xdf\x06\xe8\xb9\xa4\x9d\xd2\xad\xb2[\xd6g\x8a\xb1\xc8\x0c>\x13x\x02\x05c\xdc\xdf\xbfZR\x1d\xb5\x02\x0em\xae$\x82~\r\xe0\xe3\xf0FK\x8e[\xfe.\xde:\x01\x9c2\xdeWs~\xf9\xcd\xb4\xc4\xae\x87\x1c\xc92\x16\xa4[\xd6D\x0c\xd4\xd4\xc7o\xb9\\\xcfl\xe2\x05G\x89\xba\xf3\xd0\xdb;\xdem\x14`\xafU0\xee\xa4mX\xb1\xbal\xed\x13\xfe\x11r\xb7\xbc<J\xf1\xb1\x0fL\x84\xf5\xe0/\x19\x91\xcd\x89Sl6\xa3\xcf\xd8\xcd\xd9P\x04W\x19\x81\xd5\xba\xb81T\xd6o13\xd4G\x92,k\x02\xae\x7f\rE\xda\x19\xee\xf5"\x00g\xfb\x9ai\xfb\xc8\x0e\xa5UGM\xe6l\xab8\xbe\x04-\t\xa9\x85R\xe4\x00\x00\x00\x01\x00\x08\xe2\xc0\x97\x0f\xf5\xc4?@@\xdc\xccl&\xaa\xc0\xe1GJe\xc3q\xc8\xa4l\x167HW\xb8k\x84\xb3h\x18\x01\xc6\x15\xa6j\x9f1&\xe9$\x873}\x01\n\xba\xdf?W8\xfc\x02z\x04\xe7\x9a\x91\xf5\xbf\xff\x88\xfd\x02\xca\nB\xba\xf7xW\xcd\xabQ\x10\x0c\x9a\x15l\xf8\x84%\xfc\xb1R\xe6\x9ev!\xe9\x16\x04\xf9\xc7\xb6\xb2\\\x17\x0f\xe3\xa2\x02\x05wZ\x00\xc7_\x9c#\xa9\x04\xd0\xde\xf8G\r\x10%\xa3\xbd\xb6/\xd3\xdf\xcd\x0cb{\xa6N\x1c\xdc\xefLF\x14\x1e\xa9\xb2\xb79\xb1\x02ZdV*\xf2\x81\x87\x94\xc5s\x1b\xa2\xd2+\xa7\xf6\xd0B6w\xa4\xcd\xf1\xdc)\xa0\r\xe0\xd6\x91\xc5\xd0O!?\xd7g\xe3\x97n\xaea\x1d\x98\x94z@\x94\xc2\x9bzvi\xe6.\xa0Jl\xc4\x94w\x92\xeb\x07*\x9e\x0c(\x1cz\xbb\xe5\xf7\xef\x1a^\t\x86\xc5\xb4B\xb7\xe8U\x7fH%\x00\xf4\xd0\xcc\x1b\xc4$\x19\xd28\x96]8\xad\x80\x0ck\x9ci\x15\xe6\xfa\x9e\xbfY\xd2\xa0x \xd4\xb3c"L\xf1\x1b 9\xc8\x84\x12b\ng\xf6\xf7\xf1\xcb!\xff\x8f\xfb-\x9f\xe6\xe8\xae\xd6tb\x14\xb8\xfa\xb2'
|
|
|
|
|
|
2024-12-14 20:35:56.460327 - Ether / IP / UDP 192.168.1.11:53339 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 194
|
|
id = 5437
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53339
|
|
dport = https
|
|
len = 174
|
|
chksum = 0xc647
|
|
###[ Raw ]###
|
|
load = b'\xef\x00\x00\x00\x01\x08\xe2\xc0\x97\x0f\xf5\xc4?@\x00@Gl\x9f\xf6\x81\xb5\n@\xcf\x83ln\xca$\xad=\xc7\xf2\xab\xa5Fy*.A\xec/"#b{D\x19]\xbf(\n\xc8\xd8A\x8a\x94j\xbb\xdce\xa1\x10^Z\x1d\xae\xfa!V7;\x133\x027\xbf\xbeiY7\xcfQ\xc9\xc2\xc5\xfaH\xe2\xc0\x97\x0f\xf5\xc4?@\x9bz\xfa[\xcd\xaa\x98W\xd4\xf52\x84\xd7D9qd\xa5\xce\xc1\xe6{\x1f"\x82\xfbM"\x12b\xcf\x8a6\xcf\xeaV\x85I\tZ>\xdb{\x00\xfeZ\xbb^\xaa\xe1d\xd0@wk\x7f\x9bc\xa0\x93Y\xfa\x8aU\x82E\xde\xaf\x89'
|
|
|
|
|
|
2024-12-14 20:35:56.480792 - Ether / IP / TCP 192.168.1.11:42769 > 35.186.224.26:https S
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 5438
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42769
|
|
dport = https
|
|
seq = 4043067409
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 64240
|
|
chksum = 0xc5ae
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 20:35:56.496523 - Ether / IP / UDP 192.168.1.11:53339 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1274
|
|
id = 5439
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53339
|
|
dport = https
|
|
len = 1254
|
|
chksum = 0xca7f
|
|
###[ Raw ]###
|
|
load = b'E\xe2\xc0\x97\x0f\xf5\xc4?@\xd1\x01C<$v\x90\xf7>y\r\xc8\x1a\x82\xd0\x9d^\xa5\x94\x01\x19qz\xa3\xdb\xa9\x85\xb4\xb6\x9c\xa2\xf3\xd3\x98\x87!=Y\x13\xc2\x0b\xb0n\xfa\xb7+tCk\xc2\xeeF\xe8\xe3\xa7\x8c\xbaoq\x97s\x94w9\xd4\x06k\x0b\n6\x82\x1d$%\xe2\xa6\xfd\x1f\xbaGg\x04$\xc5f\x08\xff\xc7\x1c\xdc\\\xf1\xa4.u\xf5OS\x1a\xb2\xea\xd5H\xaa^\xecn\\\x12\xf6\xd6N2\xab\xa9~\xc4.b\xcb\n]i#\xff\xa2\xadt\xf2SY\xc8E\x1aj\xf5\xd2\x19HF\x16DgU\x8c\xcd\x95\xb6w\xdd\x80\xd8)\x0e\xe1\xa8\xbb\xd6\xd5/6[\xdc\xef\x1e{\xd3T\xe9/\xcf\xb3\xa9$\xab&!@\xef\xd0\x88\x82v(\xc9\xcf~\xa4\x83\x8b\xb6p\'\x93T\xc5pVp\xe9\xb1\x86\xee\xfa\xaf\xe2\xa4E \x9b\x91\xb84<\x92\xb8F\xd0+w\x97\xfcB\x04S\x0bF5x\xcd\x11\xfb\xa8>\xf2WL\x07f\xc2q\xf3\xba\x8f\xb0\x91\x0f\x9a\xdb\x15\xcd\xcdhd\x08u\x84\xe4\x89<\x1f\x863\xb7\x19V\xfd\xa5\xd2\xad.*\xa3|\x9di\x16\xe5L\xff\xe30\xdfU\xb9?l\x14\xf5\n<.\xc27\x81\x81\xd2\x0f\x0f\xad\xcc\xd8\x1c\xe6\xa2\x82\xbdi\x8a`\xee\xa2p.Nc\x05H{\xb9\x1c\xc5\xfc\xb8\xd8\x13\xe8M\x8e:*\xe1\x1b\xc2\xcdc\xda\x102f\xfc[\x8a\xaf\xf0X"\xe3\x0e\x7f\x7f,\x02\x02N\n\xba\xc5\xe7l\x12Ch\x1c\xd7\x91\xb0\xdf2\xa2E\xe8\xb0\xf1qr\x06\xf0\xf3\x08\xcd\x05\xe7v\xd8j\x19&\x80\xcd\xb1\x85\x82\xbf\xae\xe9\xc0\x11\xf9\x0c\xba\xbd\x7f\xe7T\x9fd\x83.\xf3\xcd\xcb\xacIUE\x93mI\t\xc0X\xae\x03\xfc\x97\x10\xf7:\xf8q\xde\xc0\xd2\xb6\xb0}2\x1e\xfc\xfb\t\xd2\xdb\xe9\xe7\xc5\x81\xc5L\x80\x17\xf8G^\xf6\xf0F\xf7\xecD8\xcc\xc0\x18,&Y\x8fg\xe4\x8a\xd5\xb8\xc9&\xcbe\xe9t\x85\xf1\xa7C\xaf\xe3\x96e\x85N\xf6~\x1d%\x06,{t2"\rB\xea,\xb2\x9f\xd9\xd3\xfd\x12\x13\xd7l\xd8,\xf0X\x01\x8b\xf1\xd0vz\xef\x92\xd7$\r\xf2\xb3=\x9b\xe9\xa1\x08\xfal\x95v\xa9\xd9\x0fX\xc4\xf4W\xdb\x16\xf33\xa3n\xf2\x89PBS\xa3\xf9\xa1\x89N\x08\xfeiT\xb4\x0e*\xd4ro\x01\xcf\x13ctT(\x98\xe8\xa8v\xf7\xb62\x1f\x1b\xb7\xba\xe7\x98\x7f\xd75\x07@\x85\xa5\xbc\x10\xdc\x84/\xfbZ\x16\xb7\xb0\xb7\xf2?`\xb5\xbb\x08\x1d\x1fG\xd4\xb9\xb8\xcb\x88\xc34KZ_\xd8\xa8\x9c\x0eI\x01{g\x1a>Q\x9e\\\xa3\xb8V\xc0\xd3\tW\x12c\r\x13\x1e\x16xi\xa4\n\x05\xbf|\x81?\xb8\xc6\x9f0\xb3q\xf2\xe3\x1c\x0f \xd4\xa4WZ|F\xd5\xd4\xf4\x06D\xd4\xcd!`\xc2\r\xe89k>\x85\xbb_\x93{9\x8d\xbf\xcf*\xbf `\xff\x15"J\x92\x1a\x85\xe1T\x17\xefw\x07AF\xc0\xb96\x1e\x0c\x8bW\xe6L^\xa4\x82\xb12?\xe9 t\xf1\xf5\xc1\xd4\xf3\x96z\xff\xc2\x8a%\xdd\xc1~\xccc3Y\xab\xfa\xf4\xbb\x17\x81;`n\xcd\xe1pQ\xab\xa7\xf6:hna\x96\x16\x9f\xf3jk\x08\x8b6\x00\xad\xc7\x95\x82\xc3\xda\xd4]^\x9e\x8e\xf1o#W"\x032\x16J\xe6\xecU\x0f>\xab\xc3T\x90(\x9b3L\x160LRtY\x97\x98)\x1e\x85\xc1\xf4\xcc(\xaa\xca\x173A\xad\x9fA\x93{D\x87o\xf9\x9e\xea\xba\xa7\xa2\xa3\x8e\x93\xf3|\xbc\xd4q\\\xc8R_\xad\xef\xcd\xf1\x88#\x05\xf6P\x7f\xe5%\xbc\x11{\xd9\x99\xd7\xa3A\x9e\x9dp\xa9\xb9\xd1\x9eo\n\xd6w\x88`\x03\x95\xbf\x1e\xb2\xdb\xc5\xa3\xb4\xaa\xd0\xbb,\xc2\xe5\xac\xcd\xb2}\x93\xf9\x02\x87\xaf\\\xd4#p\xec\xeb\xbb\xaf\xc93\xca/\xc74\xf6\xd4\xb7\xab\xf3\x14\x9c\x8b\x19\xab\xeb\xd9\x9dL\xd6\xadiz\x90\xc8\xb6\xd5?hP`N[\xf2\x93\xe3m\xa7f}\x83S\x0e\xd7\xc4\xff,6\x06\xeeN`Bq\x1e\xda\x814 \x9ek\xfa{\x17 u\x00\xd7e\x1aLJ)\xd0\xfe\'\xf1\x02\xa6\xbc\xdcE]d\x89%\xb4\xc7!\x7f\xae\xaf9\xb0*\x9e\xc3dp~C:\x12\x05\n`\xda\xe2a\x0em\x03\xe5\x8dSd\x1ck\x13\xa6\xff\xda\xfdBI\x17\xab\x98\xb9\x0f]\xbay\xc7Z>\xf6\x17O\x9b,\xbe\xf5\xdd\xa5\x1a\xcfe1\xa6&8`l&\x0e\xa2\xad\x9f\xa6\xdaw\xb5\x9b\x04V^?\x17\xb5I\x12qP\x96I\x1fj\xd6\xdat\xa7\xee5\xc9\xcf\x85\xfe\xca)\xd2"\x1b\x1dQ\x9fl\x01\x89\x04d\xf4\xd38\xc0t\x83u\x15\x07\xf7\x01\xae\x00\xba\xf1?h\x93\xfc\x9by\xb0\xdb4\x9f+P\xa1\x89\xc0MdA\x83\x96PL)\\+\xc3.\x1bz\x82.Y\x15\xc8\xfe/_\x16\xc7\xd7k\xdf\x94:c$?\xb6\xcbP3A\xff\x8c\x16M5dz\xefsBl\x0b\x0cO\xb8\xa6\xfa\x18\xfd\x9dU|:~\x1c\xe5\xd3\xc1\xf8\xa5T)\xf6\x80'
|
|
|
|
|
|
2024-12-14 20:35:56.556666 - Ether / IP / UDP 192.168.1.11:53339 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 893
|
|
id = 5440
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53339
|
|
dport = https
|
|
len = 873
|
|
chksum = 0xc902
|
|
###[ Raw ]###
|
|
load = b'L\xe2\xc0\x97\x0f\xf5\xc4?@\x0f\xe5\x02JYu\x8e!\xd0\xd5~\x9a\x05\xb6f\xe8*\x82\x87\xf74\xf7\x82\xba\x1b\xc4d\xf3\x90R&\x901\xa7z\xf6K\x08\xf56\x94\xfb\xde)8\xe8\xc1\xa5\x05\xa0\xa2:V\xe2\x9b\xfd6h\x8fO&^X\xaf\x97xH\x91\xe7\x97\x87\x02\xc3\xc3\xb8\x1f\xe9\xeabB\xc8\xad\x96\xf3~\xe1\x10\xc2\x81sG\x1c\xef\xe5\xd6\xce\xac\r\x85\xa2C\xcb\xd3bP\xcb\xee\xfdT?r\xb3\x05\xe2\xb9;IW?\x07\xdf{6!e{\xd46\x1eG\xc0\xa4\x9b-?\xd4\x0ej\xe5\xed\x84\xf2\x7f\xb7\x04cC\xab\x92S{\xf1\xabY\xb5\xa7\xff\x06\xffm\x90\xc4\x8d\xcep:\x15^\x04\x8e\x06jl\x1a\xc4uBv\xf1\x94\x18g\xda\x80TUD\xe0\xa2\x81\x08\x0f7\xb0\xacL\x95\xdd\xc7\xd5j\x10\x97e\xf17\xb28\x06\xc0\xe0\xc0\x1d\xe7\x1c\x9b!O"\xdb\xdf\xa3\x8cy&\xe8}cpy\xd5\xa4\x13.\x88\xba\xc0\xc3\xae\xfa\x15\xf5J_Q\xcd\x1eKhs\x11\xd1\xba<\xac\xb4u\xeb\x0e4a3\xa1\xb5X/*c\x9ev\x94\x80QG\xc6\xf5\xea\x1d\xc8;\xbb\xd6\xa338\x1cJ\x18\x01\xc5\x10\x97j\xf7MY\x18AJ\xda>\xa0p\xa0(O\xfcD\x11w/\xa1\x14+v\xe0\x8fa\xf3\xd0g\x1e\xff\xfe(V\xea\xa1n\xe57g`Db\xaf\x8d\xfc\x80\xdf\x0f\x05\xe5\xbc1\xf1\x1e\xc3\xa0\xcb\n\x97p\x85\xb0\xe6HZ(\r\xf9\xe3\x1a\x9c\xbe\xec@\xc8\x7fc\xee\xc9~\x0b5g\xd4b\xcbJv\xf1\xe1\x153\x1a9\x10\x9b\x14I\xdft[\xbd\x90\x82\xea\x9c\x96\xf5\xb4\x9f\x99\\\n6\x82Z\xaeK3\xc7\x85\xc0i3,u\xed\xc5WZ\x0b\x86\xd3R:\xc7b\xb2jw> \x8c\xed\x1a\x9e\x98\xf6x\xcc\xe2HV\x13\x99>\xf0\xa3\xa8\x14\xb6B\x99\xc2@\x7f\xf3\xc0\x947\xe7T\xe1I\x0e\x9e)\xbe\xca<\xc4f\x14\x979\xb4\xdf\xc6\xd4\x07#\t\xb01\xc3\x05O*\xd2\xc7X;i\x15w\xa3xm3\xe9l\x1b\xe5\x87\xcb&\xc8$`\xce7\xf7\x9b\xa6~\x95\xec\xfd\xf7\xf2\xffI\xb4\xafr5\xa6\xf7l\xc4\x95\x96\xbbFd?KBC\xc8\x072\xe2s\xea\xce\xe7\x0f%+\x1e<\xaa\x1e[\xf6\x99\xed7\xdc\xfc\xf5\xfe\xb0~\x98\xe3\x15\xbc\xa3\x07\x0bK[u%\x80#+LIy\x90C\x9b\xe0A\xcf>\xfd[\xcfS\xdek\xcfH\xd8g\xbf\xfe\xf8\x92\xcd<\x96\xba\xa8\xff9\xc1\x9f"\xee\xdf\xd7?B\x91\x8c/\x99\xa6o\xcc\x8e\xcc\x0c\xfa9\x0f\x7fr\x1a\x16\x92\x17\x9b\xce\xe6x[O\x96uq\xd4\x82\\\xf2\x8c\xa3\xe6\xbd\xc42\xf2\xe4\x8c\xc3\x8a\xde\xc8[\x14\xdb\xa4\x9a\x06\xaf\x83\x1f\x1a_-\x81g\x90\x19\x8cse\xcb4<\xdf\xb4\x9f\xd6\x1b8m\xd8\xe2\x8aZg\xc9C\x1d;\xa8\x95oAj9\x17\x05\xd8\xa8CA\x85\x8f\x1f\xe9{M\xd51\xc7=\xed\x0c\x9e\xc7x\x1a\x8fj\xb1\xd3\xb6\x10x\xe6\xcaD/@\x82Z(Tl\xac\xb4oF\x04\xe6\x1a\x91t\x9c\x98\xa6\x14\xb6\xc2\xb63d\x8e\x90\xb67GH9\xbe]\xb1\xd5a\xce@\xf5.\xa1AO\x89&\xc5\x91HZo\xeb\xfa\xf9:\xa91\x0b\xce<\x87\xdf\x87kz*\xf0\xcc\xaf\xb4\xcb\xc9\x87\xa0\xdd\x98\xd0l9#\x1c\x04\xfb\x10\x0c8Tb\xd2^\x08\xd9B\x9f\x95\x8d\x08\n\xadS\x17T\xe7\x08\xd5b\xc9\x95\x93\x7f\xd9\x81\xe0\x07'
|
|
|
|
|
|
2024-12-14 20:35:56.615379 - Ether / IP / UDP 192.168.1.11:53339 > 35.186.224.26:https / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1267
|
|
id = 5441
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 35.186.224.26
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 53339
|
|
dport = https
|
|
len = 1247
|
|
chksum = 0xca78
|
|
###[ Raw ]###
|
|
load = b'B\xe2\xc0\x97\x0f\xf5\xc4?@\xa4\xafFy\x01)\x99b\xf4\xca\x95\xb2\xf0\x1d\x03\xa9\xf1\x11]\xb4G\x14\xe0p\xb4$\x08D\x92\xb7]r\xf6\xf9\x1eF\xca!\x16\xa2\x8d\n\xe2\x08\x8b3)DoF5\tf\xe0\x04i\xb5\x8f\xc7\xc5\x00w\x06\n\xcb\x07[\xb9\x7f\xec\xbb\xc4\xec\xca\xd8\x1d\xfc\xe9e\x9arC\x19+\x93\xfc\x05\xc1\x05\x1b\xdf\xae\xcbK\x90\x91\xae\xdaU\xc4\xbf\x07{\xe9\xfc\x81R\xe6T\'I\xa5\xe7\x00\xb0\xeeP\xfb\xe6\xdc\xe0\x12\x87\x80\xba_\x13\x02\x9cy-w\t\xc9\xdd@\x0e\xbe\x91\xefg\xcb\xa8f\x03?\x8b\xe6\xf6A\x99`"Y4\xcc\xde\x1eK\x92\x1dm4\xbe\xe5\xaf\x92\xf8\xaeg{\x89X\xbeV\xc5o\x93)\xa3t\xfb\x18\x96\xf1U?\x83\x04\x14/\xb0\xee\xa3\t\x1d\x90\x0e~\xfdK\x9f\x02N~\xb7\r\x1b\x81\x82\'\xd3R\xb0e\xbcD\xa8n!\xd4\x12\xa9\xb4\xbf\xc3\xe6\xdb\xc6\x05\\\xeav\xd4\xe9uI2\xfe0\xf7\xa4\xff\xda\x83\xa5\xf8og\x90\x07\xed\xbd\x8c\xd7x\x1d\x1ef\xe1P8\xf5&\x15\x8f[&\xd3s\x83\xc8>\xec\x92\xf9\x9e\xed\xcdd\'k+\x85\xeb\x8a7\x9b\x94A\xe7\x06\x9f\xb0\xf1|CF\x84\xc5\xc1<b\xeb\x84|d\xc8\xcd7\x83\xa7V\xde\xfdjq\xc6\x8c\x9cv\xc6\x98\x83E\x94\xc7\x10\xa5\xf4\xc1\x90\xda\xd3y\x9f\x8d\x1f\xaft\xd1\x96\x87E\xf3\x1bs\xfe\xe1\x94\xf0\xa5\x00\xb6\x9dO\x8b\xa4A\xc5\xdb\xa3\xd4+a\x83b`\x01\xc8\xc9\xa9)EE0\x7fH\xe9\xdf\xa1\x08Y!\xb5;\x11$\x83T\xa0\xcd:Ae[\x1f\xfa\xfa\xc3\xe3q\x96\xc0\xe7\x94l,\xc1\xd6\xc0\x80v-\x03Pt\xb9\x00\xc8a\xc7\xb03\xad\x87hL\xa7\x87\x86\xefw\xd8+\x17PAYs6gPg\xb6K\x9b\xb0J\x8b\x8b\x86o`\xfa]$7\xa3]\xd0\xcc\xd5\xdb\xd7\xe4N\x806v\x19\x97\xaa8\x0c\x81zd\xa5\xc9\x00R\xfd\x87\xc4w\t\xd0\xf4\xfb\xf7\x04\xc4\x84\x8d\xdb\xebA\x0f\xa4~\t\x16\x8fe\x03\xc4\xb0\x8c\xeb\xd5\xfe\t#\xe0\xd7\xbf\x06"\xd29\xdf!IH\xf4\x16\x88\x05\xd2\xc4\x86S{\x1e\xb8)\xce~\xf1+\xc6\xaa\xa1O\xe3\r\xfc\xff\x01\xe5\xe5*\xf4],Q\xa9\xe3?\x8c\xa7B\x86\x85\x0fH{\x9b\x9d\xea\x88\xcd\xc2x\xfc5-]\xbe\xc9\xafZ\xdf\xd5\x15\x85y\xf4\xf9\xf6\xdb\x90e\xabO\xee*\xb4\x8f\x1e\xc6M<\x10*sSJo\x92<\x83\x8f\xb9#A\x8eh(B\xf8\xaa\xa4\x94\xaa\x7f\xae~ \x95\x076\x0e\xedG\xd8\x9cb\\\xc9\xea\xce\xb7V\xe0\xc3p\xe2.\n,-\x8c\x11\xab\xc6#\x1e\xb9\xdd\x8e\xe2KG4n\xfbKU\x0e\x0f5\x9f\xc2\xd4\t\xf2@\x85\xb4\x84\xc0\xff0\x00\xb8\x91\x94m:\xe3gD,\x19\x0cMYl\x98\xdfW\xd8\x04\xe2}8\xd8Q\xeaiI}\xde\xe2\x13\xd7\x85\xe7W7\xfa\x9c\xe6K\x0b\x03m7w\n\xd2\xd9M\x01\xf3B\xfa\xcaOZg\xa56\xe1I\xedj\xf3|q\xde\x13\x8fWd\xaet\x0b;x\x9eY\x08\xab\xebxQN\x9e\xfeJ\xcf<\x86\xec\xbc\x94\xd0Fx\xefA\x13\xcbM\x83\xac\xb7\x91\xf4%\x7f*\xe2\xa0h![\xbf|-\xab\\\xa3\xa3\x04p\x88<Oz\xd2/\xbc\xab\xf4$f\r \x91|\x8d\xc3\x04\xcb1\x08\xd0\xf3\xdb6\xa0\xc6\xb59\xfd\xd1\xbb\xb2C\xdb\x0bx\xe9\xdb2-\x1f\xdb\xaf\xffl\xee\x86b\x95\xfb\xe9Q\xf8\xe1\xc5\x10\xcd\xc1\x16a|\x92HY\xa1!\xb9sw\xbf$\x03t\xb2\xcfo:hrj]\xd3\xf8&0\xd8\xf9h\xe2\x17\xbe\xe5F\xfd\x9d\x15\xea0\xae6\xd4;*\x0e\x04\x155\xb1\xaf\xbb\x98\xd5\xac\xa0\xa3\xb0\x07\x84\xb2sjt\xe8cj5~\xba|!\'\xba.\xd4\xb0o\xc2\xb0\xe1*\xf3\x8c\xb4\x9dt\xf2~\x1a\x83\xf6:&\x85\xd5\x1d\x99\x16\x9c\xe7\xc1\xa8\xf2\xa2*\x95W\x85Q\xbf\xa9\xd2q\xdbN^\xc5\xec(s\x9b6\x1flp\xf79\x8e\x7fg\xe8{\x85\xe3\xbc\xa9A\xd4\x96/\x11br\x00\xe3\xdb\x18\xdab\xde\xdd\xb8\x02K\xa2\x9c\xa3\xf6\xab|j\xb3\xb7\xec\x94\xde\x97\xa7\xc4m\x87\x1f\x8b\xcf8\xe2\xd2V\xb6\xd4G\x89\xf4\x97,j\xad4""\x11f\x16\x88\x03\x0bz\xf5 <\x89!uA\x8d@\xa7?\xa4\xd7\xcb>Y&\xf0&g\x9a\xad\xfd\x9c"\xc9\xe2T\x88\xad\xff\\\xd1\x90\t\xec\xb9A\xe0\xc6\xce\x9f\xb2\xd4\xcd\x8cK#\x86\xabRLk\xa8y\xa4&\xde\x04\xcc\x15\xb8U^\xd3\xe9qo\xc6s\x0e\xd3\xb4\x93\xba\xdd\xa1\x1a.\x83\xe2\xdd\xed{\xcb\xdf\x01Sc\xba\xc8C&p\xb1\xf9\x1b\x9a\xaf\xf6\x01\xd6\x12]\x139\xecHe;\xe2\x9b\x18vG\xcc\xe7\x8e_\xf5Ew\x91vb\x12\x16\x88\xa70l\x83\x14\x9d\x06\x83\x02\x07O\xd8@\xad\xf1\xfbR\xfd\x01\xcc&C\xd2\x99\x99\xbc\xed\x9d<\xef\xf4\xb6B\x92\x9e9'
|
|
|
|
|
|
2024-12-14 20:35:56.670594 - Ether / IP / UDP 35.186.224.26:https > 192.168.1.11:53339 / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 612
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 55
|
|
proto = udp
|
|
chksum = 0x7c01
|
|
src = 35.186.224.26
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = https
|
|
dport = 53339
|
|
len = 592
|
|
chksum = 0xc32a
|
|
###[ Raw ]###
|
|
load = b'X\x18\xcdf}\xae#\xbb\x8a&\xc2\x84\x9c\xf3\xef\xee\xec\x14R\xe9\x19\x0b\xacx#\xc0\x90\x88\xf2\xac\x88I\xe1\x8a\n!\xdc\x17/\x8c\xcda\xc2l\xe3\xa3\xf0o\xb1\x8fA\xdb5\xcew\x83g\x11e\xbe\x973\x94\x8f\xec=\xb1\xc9\xe2}t\xf5x\xc3\xb9\xbd\t\xda>\xbf\xb6\x03\x08\x82\xae\xba\xd7\xce\xa2Ys\xc5\xdc\xe4\x1aT\xa8\xb1O\xcf\x88\x85.\xfd\x17\x9f\xb0\xfb\xb9\x8b\xf4)\xf11A\xc3\xf1\x86TmhR\\H\x05\xaf\xf66\x04!3\xe46mV\xa5\xa8\x01\xb4\x82\x14\xf0\xc4_\x02\xc3\xf6o2 \xffoI\x9f`\xda\x16@\xe4\xa4\x90\x03\xd3\xaca\x12X\x19\xe0\xf8\xad\x85a\x02J\xea\xb4C\xfa/\xbc\xc9\x89\x95\xfb\x80\xe5\xe0\xf9\xbd\x9b0\xfb\x8d\xec\x0c\xef\x91m\xa8\x0e:\xadg\x82S\xb8R\xbd\xec\xb0\xd2\xff\xf9\xeasLyi\\\xb6k\x9cu\x81\x91S\x85\x14\xcf\xb4\x18"\xee\x07\xb8\xff\x1e\xae\xcf\x8a\xc4\xcf\xc7\xf7\x7fh\xf3`\xf8\xfb\xa8b\xcb\xab\x99i\x82\xaf=\xe9\xad\x03\x10Jy\x10t1\xa8\xbc\xf3\xd65!\x8a&\x9d\xc3~\xed<r\x08\x0c\x98b\xbd\xc7_=9{\x8e\x89\xdeE\n^\x82U\x93^\xc8\xcfk\x83\x1ej3|\x94o\x9c\xf9\xba\xda\xc6\xf9p\xf6\xfa\xb4\xfbM\xccaN[\xc1g2F\x07\x90\xef\x83!VDl\x9f\xc5\xb9\x82\xe8\xec\x07\x03\xff\xbe\xca\xabY\xcen\x11\x12\x9b\xe5\x90\xcc`!\xac\xfd\xfd\xc1\x16\xbaV\x9e\xc8=\xc6\xb4\xefT*\t\xa5\x12\xa4oP\xa1\xa8\x7f\xfc^)?\xe89\xe7\xe0q\xe2r\xd9g\xc6\xca\xfb\xa7i\x8b\xfd\xff1\xb4D\xb8\xc4\xeelr\xc9\x9a7\xa2\x84\xdcH\x83\x12\t\xb0\xa5h\'v\x19M\x95\xd1\x1d\x05\xccj>\xed\x15nn\x10n\x1c\xda\x9c*M\x1d\xa7?\x06Yf\x84GGPA\xab\x94!\xd7\x84YqZ|\xbe\xe4\xe1\xa4\xf5\xf9gU\x03\xb1Z\xc2\xed8\xda\xa1&@yB\xdd\x9d\x8fi\xd8WM\xde\xef\x7f,_\x9f\x95\x11!\xd7Y\xb2\xc5\xf3\xea\xe3\x1eh\xe4\xfa\xa5;U\xe46;\xd9\x92\x9c\xd41\x83)_c\xb84\x89uV\x8b\x9e\xc2\xf7\xcd\xa0\xc9\xa2\xa9p\x89\n\x7f\xf9+\x07+`\xc6\xd0\xb6\x95\xe2\xd7LM\x17\x08\xd6\xe0Iz\xb8\xd9\x03Y\xaa\xa09\x05 P\xe3\xa3\xca'
|
|
|
|
|
|
2024-12-14 20:35:57.477724 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34261
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60937
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 9188
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.494228 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34262
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60938
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 9189
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.505682 - Ether / IP / UDP / DNS Qry b'47.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34263
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60937
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 9190
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'47.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.509617 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34264
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60938
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 9191
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.511882 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34265
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60937
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 9192
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.513884 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 60937
|
|
len = 76
|
|
chksum = 0x2418
|
|
###[ DNS ]###
|
|
id = 9188
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.516451 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 60938
|
|
len = 89
|
|
chksum = 0xb68f
|
|
###[ DNS ]###
|
|
id = 9189
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.518660 - Ether / IP / UDP / DNS Ans b'S22-Ultra-de-Adrian.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 60937
|
|
len = 89
|
|
chksum = 0xd9e6
|
|
###[ DNS ]###
|
|
id = 9190
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'47.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'47.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'S22-Ultra-de-Adrian.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.520618 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 60937
|
|
len = 81
|
|
chksum = 0xd807
|
|
###[ DNS ]###
|
|
id = 9192
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.522348 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 60938
|
|
len = 51
|
|
chksum = 0x6abf
|
|
###[ DNS ]###
|
|
id = 9191
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.524135 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34266
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 60939
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 9193
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:57.526567 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 60939
|
|
len = 81
|
|
chksum = 0xf1ee
|
|
###[ DNS ]###
|
|
id = 9193
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:58.071015 - Ether / IP / TCP 188.114.96.5:https > 192.168.1.11:42259 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 84
|
|
id = 43056
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xbe48
|
|
src = 188.114.96.5
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42259
|
|
seq = 2693639237
|
|
ack = 4062860675
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 9
|
|
chksum = 0x56c7
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00'yW\x02?\xdc\xfb\xe4\xd6\xfb\x9bA\xf7\x98\x90\xe8\x1e(u\xb7\x98\x1b\xbc'*\x9e\x12\xc8:\x8b\x81\xb3\x1a\xc5\xd9=\xb5\xf7\xe4\x93"
|
|
|
|
|
|
2024-12-14 20:35:58.076674 - Ether / IP / TCP 192.168.1.11:42259 > 188.114.96.5:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 49550
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 188.114.96.5
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42259
|
|
dport = https
|
|
seq = 4062860675
|
|
ack = 2693639281
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xde68
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x00\x1e\x0bb\x96\x8b'\xba\xae\xff\xdf;\x87\x0c\x1e\x16\xf8$d\xe1\xe1o=\xe7c\xba*\xf3\xd9\x0e\xa2F"
|
|
|
|
|
|
2024-12-14 20:35:58.080892 - Ether / IP / TCP 192.168.1.11:42259 > 188.114.96.5:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 49551
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 188.114.96.5
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42259
|
|
dport = https
|
|
seq = 4062860710
|
|
ack = 2693639281
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0xde68
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e\xefa\xd0,\xfe\xc6|\xb0\xa9\xa9\xb7_\xef\xcb\tb^\xb4\xee\x13\xc4\xc2\xf4\xecQ\x8b4\x05\xce\xa6'
|
|
|
|
|
|
2024-12-14 20:35:58.095921 - Ether / IP / TCP 188.114.96.5:https > 192.168.1.11:42259 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43057
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xbe73
|
|
src = 188.114.96.5
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42259
|
|
seq = 2693639281
|
|
ack = 4062860710
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 9
|
|
chksum = 0x9601
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x1b\x1d(E'
|
|
|
|
|
|
2024-12-14 20:35:58.098812 - Ether / IP / TCP 188.114.96.5:https > 192.168.1.11:42259 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 43058
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xbe72
|
|
src = 188.114.96.5
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42259
|
|
seq = 2693639281
|
|
ack = 4062860745
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 9
|
|
chksum = 0x95de
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x00\x00\x80\xfd\xe3T'
|
|
|
|
|
|
2024-12-14 20:35:59.119707 - Ether / IP / TCP 192.168.1.11:42690 > 142.250.201.78:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 22708
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.78
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42690
|
|
dport = https
|
|
seq = 912712044
|
|
ack = 2800351769
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0x1f9b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\t\xbcf\xc9g\'\xbf\x9fT\xad\xe9!z\xedC\x01\x1f\xf2\x05\x95\x8d1\xe2\x15hwr\x05\x12{@\x8d\xe4M,M\xc9\xd9&M\xc16\xe5a\x1f\x0c\xdey\xc1\xc2M\xe2Wg\x11$\xebCX\'\xc2\xb5\x05\xc9\xdbtk$t!\x1d\xdb+.6m\x10\x06>\x8c\xacw\xb4\xbd\xe35\xd4Hp|k\xa6\xd0\xba\x9dv\xa0=a0i\x89\xdd\xa1\x0e\xa8\xa3\xe8\x1fX`G\x8e/9\xfb#3Vm8\xda\x02)\x01\xe3V\x8f\t\x0f\xa6i\xf0ZZs?\xf1\x15,\xaa\xe9\'\xcf\xd5@\xea\xd944\xf5@6*$\xa7\xe6\xael\x18w\x9d\xa0\xb7\x1c1\xd4\x1a#\t\xe4\x9e\x1c\xe1\xb2y\xbd\xc7\xd0\xa2\xcbP\xa2;\x13O\xb9\x97uv5\xd9F\xc4\x0c\xd5\xc3\xce\x9ap\x1a.g\xdb\x92\xbe\x89\xd18\x13\xdb\x12\x80\rx\x973W\x05\x95\x84_\x93o\xea\xe3\t\x08\x8d\xcc\xd2\xf3\x9f\xbd\xd0OWG%\xfec\xe7\xc1\x07:\xba.\xd8l\x9d~\x14\x80\xa3\x05\xb6\xc2W\x8f@\xf8\xb8\x03\x91FW0\xeb\x0c\x88\xd5t\xe3\x9d^ ;\x17\xcb,{\xdbE\xbd\xaf\x0f\x01\x00A\xd2\x13\x0f\xd4cw(\xb9\xc68\xfa\x86\x8a1\xd3\x18T\x8dC\x01\xca\xb8\xc4r\xcbk\xea3\x04!\xd2`\x8d^\xbf\x0e\xc6\xe3O/:F/A&\xcc\xed!\x82@S\'>G3\x199\xfb"\xe2\xa0D\x83=\xe1\xf6$&\xd4E\x85fx2\x04\xe8\xef\xabR\x00\xdeSF\x08R\xc9p2\x9b\x85w\x07\xd5\xc3\xc0\x1f\x83\xce\xb4\x9a\x02\x1a\xa2\xe0\xcdM\x01\xb4\x87\xd2\x8aZ\xf3\xcc\xaf\xcf\x0e\x0b\xcd\x01\x03\xcf\xd5\xdc\xfb\x911\xe7\xeb\'\x9c\xfa\xb7l\xe5X\x91\xbc&8\xd9\xbcu\xc0z)7\xff\xee\x8d\xcc\xba_\xbb\xcf\xabkH\x10\x11W\xc4\xd5\xf6Yr\x98c\x88R\xccI|\xb77q\xa2\x10~\x13\x96ED\x13\x07\xf0\xf9\xee,\x84\xbc\\\xb9\x00`K\x9f\xafB\x82\x12\xd1C\xab\xe4\xa7\xfe\x99|\xd4\x13\xc0\x0c2\x83\x17\xfd\x81\x1d\xfb\x88\xf1\xb52\x8a\x88\xd1\xde}\x0fOG\xb1\x10\x05\x8bQ\x03\x9eO\xd3Wc\xfa\xcbd\x06w\xa9v\t\x00\xd1w\x11\xfdXw\x0b\x9c\xa0\xe4\x17\x1b\x88J\x8c\xe6\xe3\xacR/\xd8e\xdc5\xfd\xf9\x99\xea\xa1K,\x1b2\n\xaa6K\xe5\x1dR\x11]\xac\xb0\xa7\xf4\xe0\x13/\xb7\x0b\xbb\xd3\xea3f/B<\x8d\xe1\x05ri<\xd3\x83\xe7\x8a\xe9\xcd0\x8f8\x82kX\x08\xd5Kr\xcd&\xd2\x1f\xcdPM\xfd#\xf8\xd6\x9f\xfcF\xb9#I\x11D\xf1\xee\xcb\x88\xed\x9c\xe4\x86\xf3\x05\xff\x1d\xc2d|5$\x11\xfb\xeb\xeaiFs\x0b\x93\xf9\xef\xf6\xbe\xa7\x11|5\xbd\x91\xc0\xf2\xc9\x8ef\xba\x86\xfeF\xd5D<\x10\xd5{\xbd\xd4\xfe\xa1\x12M~|Q4\xec\xec\xdd\x1eMP\'\xcd\xfeK\x80\xd9\xec\xb7\xa0\xdbX\xcb\x15\xc3\xf2\x10s\x1d\xf3\x98\xda\x02\xbe\x83b\xddJ\x9f\xfb8y1\xab\x02\x90#\xee\xd2\x0c\x9du+9P&w\x9f\'\xa0\t\xb1\xf5\xe3\xd0K,\xca\x8a\x95=<\x0e\xc4\xd6t\xd6\x85\xed\xa1\x9f\xc7\xc2m\xaf\x07\xe9\xd8\xbcF\x19\x9f\x13\r\x89\xb0\xd2\xee\xdf\x84\xa2-\x1e\xdaH\xb6\x91yy\xc2\xbc# 0\xfdy\xd7\x7f\x8b\x0f\r\x9a\x08\xadU\x1b)\xc9T\x8bU\xf9\xff*\x8a\x1fS\x946\x11f;\xb9\xd1\xaa4V)\x8d\xc2\xe6]\xa8\xd1\xc9\xc2n\xe9\xd9\xa6\x9e\x95\xf1\x08*\xb8&\xc6\xd3G"*\xe0\x8d\x9b\xef{\x8e\xde}hJ\xbc\xb4m1\x98\x95s\r\xfb\xdcLNA\xbd\xec\xf7\x07\xa3\x0813\xa3M7\x04\xee\x7fZ\xf7\xc6\xff*\x80G\xfaP\xf9[\xf2z\x99\xa5\x1a\x80\\\xe5\x9a\x16\xc8\x0f\xe0\xf3/\x06\xb0\x1d\xff\xedj\x92\x0b!h}\x7fe\x8b\x88pL\xa1\x9e\xd7\xe8\x14\xd0\x1a\xd7*\xa9\xed\xdbTq\xb8\xc3\xc8\x1a\xce\xb4\xadqj?\xb62\xda\xba\xc9\x8f\xbd\xab\xfd\xef\xf2Fs\xe7\xa7\x98\x00n\xf4UX\xbc\xd6~}c\xd5>\x81\x83\x9b9\xca\x8e\xe9D\xa5~i\xe3?\xfb\xe9\xcbQ\x1c)\xbd\x98\xdej\xf2\xcdN\xa72\xdf92q\xe8\x173\xd0p\x08\xa6(\x0cQ\x9f\x1a\xef\x9b\x8ee\xec\x9f\xfb\x1d\xeb\x1f`\xf0T\x884Q\xa0\x08h\xe4bW\xe4_\t\x8e]\x8e2.\x7f\x1a"\xb0\xc9\xf6~\x88\t5&>\x1a\x92\x90\xf7\x03\x81\xe3\xe7\n\xec-\xf8\xb2\xaaFk|R\xc8\xeaJ\x85\xaa\x9a\x11e\xb2E\xb7\xa1\xe4\xa6\xb7\x13X<\xcf\xed\xadz\x88?\xb6\xac\x9a1\xf6\xbb\x1a\xd6-\x99b}b\xbc \x02\xc8\xbc\x1e\xac\xae\x17\xea\xd7_\xad\x08\xf7Hz[A&\xed\x18\xf4G\xd2D\x8690\xee\xc2\xbdN\xed7-\xb3`\xe5\xf6\x07w\x82\xca\x07\xef\x9c#\xc5\x89+<\t\x8c\xb4X8\x7f\xa2\x96,\xe5\x99^L\xa4*\x17\xbd\x94K\xceu%\xa1(\x9d\xfa\xb0\xe3\x93$\xfe\x85<\xcf\xf2\xe1\xf1`/l0E\xb8{w\x13\x8a\x96\xce\xd8Q\xbd\xad\xea\x1f\xb9\x17\x00\xef\xf5"\xeb\x10%\t\x8d\x8f\x84N`\x04w9\xea\xcf^\x91k\xfe\xb8,\xf0\x0c\xe9B\xae\xccy+\x18\xbb\xa5\xb7\xed\xb6\xef\xe5Y\xe6\x1cE\xc4\xb0f\x83\xfe\xdf\xdcmr\xe6\x1e\x1eu\xa5\xec\x8eJ\xf9\x15\x05x?ro\xf0a\x86\x88K\xb56V\xd20\xe7\x9d~\xcb\xd8,\xfe\x12\x10p\xe8Y,\xbe\x15\xf6\xc2\x8c\xbd\xbc~!\xb8\x1cA/]WU\x18X\xfd\xb2%\x0bp\xa1c\x87\r\xcc8\xf1S\xdcq\xd8\xb6\x9fv\xf8\xf1\x9dZ*\xf4\xf1\xbd\x9f\xb5C\x9a\xd6\x926\r\xf4\xe0\xd4\x86\x93\x07\xa8t<A\x87\xa7\xc9B'
|
|
|
|
|
|
2024-12-14 20:35:59.191076 - Ether / IP / TCP 192.168.1.11:42690 > 142.250.201.78:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1125
|
|
id = 22709
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.78
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42690
|
|
dport = https
|
|
seq = 912713456
|
|
ack = 2800351769
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0x1e54
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'8\xca\x0c\xaa\xda=Q\xda\xb7\xb5(?\xa20\xb3G\'c\xb7\xd8\x8e\x80s\xdes\xe2\x0b\x8e\x13\x9f\xc20\t\t\xb3\xbd\x89\x07\xda\x12\x13W\xee\x1a@?\x07\xec\x04\x1a\xa3\xa9\xd4Nm<\xba\xd1\xc9\xbc\x1f\x81\xf6\xe1\x1d{f\xc4\x9e\x10s\x85\xde\xd0\xce\x90\x99\x17\xfc\xc6\x82\xc0\x86\x01#\xf5NV\x97dH\xe3jW./\x96\x95\x07\xdeL\xf5\x0b\xf7+V`gSe\xc6L\xb9\xe1p_H\r8\n\xb2=\x01\x87U-\x94\xbdzD\xbd\xb2M\xa8\xeb\x82W\x1cz\xdf\x87<$\xcbX\xc6wm\x89\xc18\x1d\xed\xf9T\x8f\xdb\xe1\x90\x1b\x05\xb0,\x1a+\xcb\x08\x0eR\xcfhj)\x08\x85\xb3\x16\x12\x16c\x8d.\x12\x18\x01\xd4TI\x93\xd6\x04\xa5\xe8\x84V\xc3I($\x04\xa15\xbfM&\xa9/\'\x92\x9e\x10\xb4\x9d\xc4\x84\xec\xbe\x1a\xc2\x9a\x8a\x99\x18\x92\x8e\x19k\xa2\xdc\xdcDf\xce\xb1_xR\x81\xc1ecal{W\xd8\x05\xdbw6+\xcb\xfa\xacNe\xee\xd3\xb5@:\xfe\xdc\x8fN\xd9\xe8\xa2\xb7oo\x9b%\xb7Y\xe4\xae\xd1\x15\x9al\x9fo\xaa\xfeF\xa7\xfa\xd7\xcb\xd9\x06\x82\'Y}\xbd\x13m\x1aR\xe4xX\x18|\x15\xea\xb3\xaa\xf0(\x9d\x91\x1d\x99py,\xff\xaboB\xe1\xee\xfe<\xbe\xe2+%\x9f:\xa1\xabL\xa97c\x8f~\x82\xe2*\x8c\xa1\x05\xd3"a\xe1\xe8,<\x85\x14\xd8PR\xc9\xff%\xa1\xd7Y\xf1[Pq\x87\xe3\xab\xc4T\xac\x82\x0e\xb9h\xf9\xf4\x10/.*\xb6Dz\x0bhs\x9c\xc21l\xe5\'\xa5\xb1E\x85\x8aN&\xa2\xbdd+z(\n\xd0\xa1u&\xad\xb0\xed\xb7\x1b\xf72,BV\x1e\xc3\xd7e\tJ\xd6\xc1i\x00\xd9\x05Y\x11\xa2\xe9VQ\t\x07\xec\x00\x83\xef\rx\xf6b\x98\\j\xaf\xc1ER\xe3D\x96\x90\x96\xf8}\xc4\x13\xbc\xc1\xf6\xed\x88\xec\xe2=[\xdb\xd93b \xd1\x03\x0e\xb8\x8f\x90\x0f\xc3\xa2\xd2\x9d*\xa1\x03\xf2}\x0fD\xcb\xba-\xe3\xb0G\xff~G3\xd8\xdc\xcf\x8e\x1fjN\x85\xb1g\x95|@\xb5\x0c\x85\xb6n\xcb\x0c2\xed\xa3\x8a\xbb\x8cz\x7f">\xf0\xb4_\x7f\xcb\xd7\xad\x87\x9c\x96\xe7\x9biF\x88\xde(\xd1\xa2&\xd6\x05 &`\xe0z\x18\x02\xba\xeb\xe6t\x93\xe0\xfevX\xaf>\xcb\xdc\xa7\xd8(\xacg\xfc\xcd\x1c\xf1\x8b\xee\xbb?\x9fq\x02\xf6L\xb9\x0b\xe5m\xe1\x86WnS\xdf\x93F\xce\xff@\xd0\x87\x97\x98\xeb\xd7s\xf0\xe6\x85\x84{{\x8d\xb5\xf5v\xbb\x81\xb0\xe3\xf1\xfb\xb9O\xb2\xe9\xcf\xf6L\x83\xa4\x07\xf3\xe6cT\xee\x81\xf2\xbf=0\xec\xea\x9br\xd8\xde\xffQ\x06\xc6$\xbf\r\x8e[\x88LH#\x04\xc1!WQ\x89)7ySY\xc3\x03\x9b\xc4\xa5do\xef\x8b\xaa>\xc2xR4\xda<s\x9dJ\xfb\xd4Q(\xc3\x8a\x9bq\x7f\xb6D\n\x9b\x0e\xdc&\x1e\xaeQ&yX\xcd\x8d\xb4~\xb2\x82 Q\xd4)\x16\x88\'\x05>\xa6t\x96\x97\x1c\xf2\xd0\x84\xb1\xe2\xfa\xef^h\xe6K]\x0b\x96\xc5\xa8\xc0\x81\xc9T<\xf6\xb76\x1e\xab\xcb\xbe\xe2\x0c\xb3\xa5\x8aS\x19}89\x0f\x0cBj\xcfn\xc7G|K\x8d\xeb\x0cx/a\xdd6\x19\xce\xb6\xbdB\xb3<\x99\x83\x9f\xdb+\xb4\x10Iv\xf2\xf3\xbc\x8a)N\x12^\n\x9b\xb12\x03\xfb\x0by,\xf9)Y\xe2\xd4\x8b\x93^\'\xd5A|S\x02\xc1\x83\x18P\x137\xbe{[\xdaS\xef\x8f\x12\x86\x85\xaa\xd8^\xd4F\xe6\xcel\x07?\xbaS\x9c\x1aX\xcc\xfa\xc4\x1d\nf\xec\x8b\x91\xd9Yt\x12R\x06\xef\xc1c\x92;aL\x13\xcf\xf0\x16\n\xed\xd9\xb0\xf4\xc9\xc2\xaa\xda\x14<\x93\n\x15\x8cDB\xf0\x18\x88\xe1\x11\xb7\x188#\xaf\x01\xc2\xa1d\x9bH\x9dK6\x7f(\xe3\x94\n\x00a:\xe5+\xf7\xf0\xdc.\x88\x84A\xb6\x8dv \xe1\xdb\xd7\xf6\xd8\xee\xe9Z\xfb\x8d\xea\xff\xff\xa3v.m9\xd1\xbc\x1c\x8c\x8b\xec\x1e\xc2\n\xdaJL\xaal!\x1ac\xd1\xa9\x00m\x81[\xc5\xef\xab\xef\\\xb6\xaaj2\n2\xbbTH$\x86\xe9\xaac\xbc\x1d\x0b\xbd\x89\xf1\x00`A_\xe9\xb1mK\xe3\x12\xe4v\x12\xed\xc9\xc7\x1c\x18<G+\xf6\xf5X1\x81D\xe6\x7fY\xfd+\x93wG\xab\xf2"\x94\xe588\x7f\xf0]j\xe6m\xba\r1'
|
|
|
|
|
|
2024-12-14 20:35:59.254166 - Ether / IP / TCP 192.168.1.11:42690 > 142.250.201.78:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 22710
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.78
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42690
|
|
dport = https
|
|
seq = 912714541
|
|
ack = 2800351769
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0x1a3e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"6\xcef%\x80\xde\x845\xfc[\x13~\xa4\xdc4q\xbf_\xe1!\x8a\x051L\xa3\xe1\x9d\x06\x7f\x94;\xbe\x02\xa6'
|
|
|
|
|
|
2024-12-14 20:35:59.271906 - Ether / IP / TCP 192.168.1.11:42690 > 142.250.201.78:https A / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1452
|
|
id = 22711
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.78
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42690
|
|
dport = https
|
|
seq = 912714580
|
|
ack = 2800351769
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0x1f9b
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x06\xd6K\xc8_\x047\xa2\xd4\x05Z\xd3=\xa4\xa3+\xef\xc1\xde\xdd\x1efr^X\xe5a\x91K\xcb\x96\xfa\xa3\xf8\x84\xe7He\xde\x94\x97\xe4\x83\t>\xe30F\xbe\x99\xa7\x81\x02\x13\xcet*\x11\x94}\xd2\x82\x97p\xd4\xb6\r\x08.\xe5\xbc\xbfh\xb0\x82\xb56\x8f\xa5\x02A\xa8xDq6!\x93\xff\x1d)\x8d\x8cig\x11\xb0\xbc!\x10_8\xddq\\\xd5=e\xdf,\xe90_U\xe4\xc0x\xa0+-0\x13\x8d\x1d\xb9\xe9\x0b||e\xea\x8dn\'\xf5\x1b\xc6\xb4P\x0c<\x0bz\xa9[\x8d\x8a\xc2HUF\x84\x8d1\xa7\xf5Y>\x96bj\xd5\x9d\x84GU\xf0\xd21\\r\x98\x9b\xe4\xb0NFu\x8f0\xbc\xc4U"\xe9N\xfc\xf3\xca\xbb+\xec\xcbE\xb1\xd0\xa2\xc7e\x80~\x9a\x89\x97\xceR\xb0WI\x0cF\xdb\xe0\xe2E\xb3\\\x02s\xf9\xb2\xc0gXq(\xed\xc8\xec\xf3Q\x14\xaa\xc0\x89\x1dg\x0bb\xee\x80y/g\xb9\xa3\x9c\x94\xf1\xea\xdf\x83\xe1_{\xaeP\x9aHjDb\xad\x86Z0\xbd\xdfz\xde\x17\xfe-\xe9\xa7\x8fw\xbb\xc4`\x11\xa8Q\xb5\x978\xa9:\xbd\r\xbd\xb9\xf6\xe7!\xe3\x8b&\xaa&\xb0%]\x95!/\xe7\xc0j\xb4\xa1\x17\n\x93\xed#f\xe3\xd2\xcbQL6(\x19\xb8\xfe)\x00\x12\x1fmz\xd3\xe0\xcb\xf1B\x88\x9a\xb1E\xee\xbb\xe9\x03:\xe7cC\x17\x8c\xb6\xc6\xc4\xa5\t\xdc\xbbL\x15\xdc1\xf8V\xa9\xe3\xfc\x86\x0bS\xbb+y\xa9\x9e\xab =\x9a\xb07\x85\xf8\xa5F\xfa$\x95\xd9\xe1\x91\x0cB\xac\xe5\x8f\xbe\x88]_x?\xb4\xc9\x13\xf2\x87\xd5\xfa.YyZ?l\x01\xd0\xca(\xc2\xa1\x11\xa9\x07\xd1G\x86\xe1\x88\xd8;\xdd\t\xceW\xd3\x9bB\xfct\x1e\xb5\xce-<\x82\xf6\xb3\xe7L\x13\x8f\x8cPj_#\xe9Cq\x04\xb8\xd5]2\xe9\x12Q\x1b\x18#/\\lQ/Z$"\x1f\xc7\xd7\xd5|v\xd7\x1f?\xc6\xcdt%*r!\xa1q\xe1\x19C\xaf\xac\x9b\x86)D\xc2\x89\x9b\xc0\xe1\xbd\xc5\xe0\xf0\xbc\xd2\xa3TF$\xd6\x18\x94y\x96q\xaa1+\x88\xe7;\xb6m\xfe`\x9e\x9d\xad\xff\xe2]\xd8\xfb\xe1%\x1d\xba\xe8\xfb\x7f\xba\x9e-\xe7\xb3m\xdc\x96\xc4\x1fB\xa4\x97\xf46\xe0\xa8,\xbe\\\r\xd6\x8c\x8c<\x8f\xe5v\xd2m\x90\x855]\x1f\x99\xcc\xb5^\xca\xaal\x9bM\x87G\x02\xe2\xcc9Ca\x94\x08&n\x9eI\xffm\xa5LbLx\x06\x97\x8b\x1f\x02Fx\x81S4.\xfb\xd5\x867#\xd7:\xfa\xbcFt}\xfcW\xa8fa\x1b\xf8o7\x13\xc1\xfc3\xf2\xebf\x13H\xc8\xab\x0e\xc5\x0c\xb1\xb3\x0b\x8b\xa3L\x82kQP8`b,\xf6;\xc4\xe6\xbc\x15cMs(\xcbD\xb3\x9a\xc1\x1c\xaade)\xd5\x18P}\xee\xd3\xda\xbc\xdb\xa84!3\r\xb4#\x82\x10\xae\xcfW\'3\xa9%\x1d\xb6_HV\xae\xac\x8b\xe1?\xf7\x10\xc8\x06\x13\xbd\xbam\x8f\x08UBK{\x87s9W\x88"\xbdPa\x85\x00\x01\xe2\xda\xce\xc7\xb0!\xf5\xd4\r\xb0\xca\xb1\xa0}27;\x17\x01\xe9\xa6\x86y8\x01\x01\xd7\xde\x92-\x10\x1fw\xf39a. \xe77!\xe4\x1e=\xc9g\x05\xf2\xfe\xbaK8R_\x9c\x96\xaby\x84\xcf\xb3\x11(N\x97\x981f\xc2\xc6\x05\xe7\xed\xfc5\xa9}e\xe7\x17\xf2i\xa74\x06eq\xa8\xafw\x97OK\xe4W\xd6\x06\xa6-w\x1b\xeb\xc3\xf4g\xf1\xd9-\xfbB\x07\x9e\xe9\x112\xdd{\x94\x1dO\x0fY\x95\x98\xd6x\xa4\xa3\xd3md\xd0\xdf\xbc<\xff\r\xb9G\xf0\x97\xad\xc7\x93#\x81\xe8p\xe1ad%\x0b\x7f\xb6\xc0[\x1d\xb24\xd9\x1d\x02\x92\xf3\x0f\x89\xc3{\x95\\,\xf0yPKP;\xfd\xe9?r)\x12\xe5\x02z\\\x1b\xbb7,{7\xb0\x8a\xd7\xe3\xfe\xe3o\xf8a\xb2l/\xc6\xeb\xdaq\xf6\xca\x90\x90P\xfb\xf6A\x82\xc80gBT}E\x9d\xb7=\xdd\xa1\xd0\xa5DN\x1a(\x08\x0fX\xbcH\xc7\xa9[\x1a\xcc\xbe\xd3 \x9fJ\xf8\xd7\xe2\'$8\x9b\x15\x1d\xdc\x8a\xaf\xfb\x0b\xb9~\xac@\x19f\x91\x1f\xffu\xa2\xcd\xb1\xc5\xaa\x8bHq\x0f\xbf`\xfc\x0e\xf2T\x15r\xb3\x8fo\xdb\x98\x8a\xc0V\xb5\x19=x\x03\x9e\x1b\xb5\x86f\xef|P\xc0\xab\xb27;;\x81\xf2\xba\xea\x90\x81hU\xb7x~\xb3S\xee\xa0\xe9C\xbb\xa1\x97\xdaq\xb3b\x13\'\xa2\x1e`\xc60#\xa1\x89\x13\xa2\x8d\xc3\x97\xb3\x91\x9a\xd2\x8e/aQ\xdb#GB\xd5\xd3\xe2Q\x9d=e\xec\xcc\x80\xb4\xd2\x13\x07\xfa\x840\xf6\x16\xba2\xe6\x9a\x89\xd6\x18(\x14\xd6\xb8v\xf9\x8f=O\xd9pHv[\xa88\xbb\x9a/\xb3\x08\xf1L\x81<@\xbedA\xd3^\xe8\x13#\xb7\x16*\xfa\xd2a]\x89\x1a$\x8f\xb81,\xcc\xb4wl\xc7Z\xado\\\xf3l\x93\xb4\xb3\xef\xd5b\xf7\x87\xfd\x0f88\xc2\xda\xb1\xc5\x85\x1b{;\xb3Lk\xf3\xb0\x1e\x80\x03\xe0$u\xed\xb1\x08*\xe75\xbcKA`\xbd4O\x98\xf0\xb8\x8fKZ\x872\xbf\x9c\x90\x8f\n\x01\xc9\xd2\xca\xc2\x90\xae&\xdf_A^\x96\xec\x885\xdf\x1f\r\x97:hK\x99\x8e\xa5\x9be\xae\xe0\xb0j\xb7\x88\x8e\x94\x86\x1b\x16<\x06^:(:8G\x97\x15<\xba;*B3\x94{\xad\xd47X\xebQ\x17f\n\xb8\xbc\xa6\xeaV</\x8f\xa9\t(!R\x9a%`\x05\x83\x81V\x1bg/\x12\x06.\x9b[< \xbd\xd5\xf6\xc6\x7f\xff\x07N\xce,\x98\xdd\x8b\xd6V\xccLpc\xcasJ!\x07F6\x1b\xa7.o\x15A\xcb\xc3"\x87\x17\x82\x7f\xc3w'
|
|
|
|
|
|
2024-12-14 20:35:59.354347 - Ether / IP / TCP 192.168.1.11:42690 > 142.250.201.78:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 383
|
|
id = 22712
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.78
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42690
|
|
dport = https
|
|
seq = 912715992
|
|
ack = 2800351769
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 509
|
|
chksum = 0x1b6e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'P\xa5\xec\xaaV\xb2\x06.\xda@\xad\xd5\xcd\xb6<\x90\x86\xfe\x9b2\\\xdb|\x11\x19@d\xf1H<}\xd3\x1c\xf7v|\xba\xda\xcf\x80\xe0\xf5C6!J\xdc\xe9\xdf\xf1G\x16\x1e\x90\xcd\xd3|\xc3~\x87\xc7"3\x0b\xe5dO\xfd\x90\xab\xb0\x8c\x8a|\xdd\xf0\x02\x177\x04\x80\xd8yvk\xf9/\xad?\xff]\x97l\xf3~\xd6r\xc3\x81\x82&\xaf\xd9`\x9c\xe5\xf1T\xd5v\xa0\xa1\xbd\x81\x8e\xc8\xdf\xef9\'\xd16f\xb7\xea\t\xb1\xda\x11\xd3\xa6r\xa2\x8d\xa5P\xa2k\xbd\x85\xd3\xebR\x93\xe0\x8f<\xfc\x07\x044\xaaH\xbesBdR\x06\x1f|\xd0k\xf5\x1c+\x8b\x10\xf1H\xb2H\x03\xe1\xe5\x9aG\'!\xfa\xed,\x98\xa1{u\x17\xdc\xd5\x00\x03\x8e\x91\xe7\xe6\xbfW4j\x8e\xf7\x03\x9b_~\x83\xa1\xfe\\\xd2\xf9\x1c\x86\'\x9c\x8f\x01\xa1\x03\x80\xc8b\x15\xb4\xb6{-e\x80\x98\xda\xb3\x80\x05;\xad\x98\xdb\x80\xf0\xce3\xa6\xaer\xf8B\x80F[T\x91 \xc5\x1a\xaf\xcd~\xfb\xe3\xdb\xafH\xbc\xc7\xbff\xeb\xf5\x87S\xdahEw\xd6\x076\x840\xd4\xe0\xdd\xb7\xe6i\xef\xcf\x08\x15bD\x17\xcd\x92\x91\xfd9?Q\xa1\x84\x10^\xf2?;\x12\x8b\x93\xb8\x12C\xeb\x1cyLL\xfa\xf2-W1:d\xae*\xc0\xee\x12\xb2|\\u\x1a$>\xc5\xc2\xf3\xe7!\xa3'
|
|
|
|
|
|
2024-12-14 20:35:59.405687 - Ether / IP / TCP 142.250.201.78:https > 192.168.1.11:42690 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 32054
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xac9d
|
|
src = 142.250.201.78
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42690
|
|
seq = 2800351769
|
|
ack = 912713456
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 994
|
|
chksum = 0x2b1e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'\x8e\xe5\x80\xb3\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:59.460343 - Ether / IP / TCP 142.250.201.78:https > 192.168.1.11:42690 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 32055
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xac9c
|
|
src = 142.250.201.78
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42690
|
|
seq = 2800351769
|
|
ack = 912714541
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 990
|
|
chksum = 0x26e5
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b')_\xc9\x91\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:59.505999 - Ether / IP / TCP 142.250.201.78:https > 192.168.1.11:42690 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 32056
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xac9b
|
|
src = 142.250.201.78
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42690
|
|
seq = 2800351769
|
|
ack = 912714580
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 990
|
|
chksum = 0x26be
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'PK`\r\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:59.519277 - Ether / IP / TCP 142.250.201.78:https > 192.168.1.11:42690 A
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 32057
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xac8e
|
|
src = 142.250.201.78
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42690
|
|
seq = 2800351769
|
|
ack = 912714580
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = A
|
|
window = 990
|
|
chksum = 0xa0d1
|
|
urgptr = 0
|
|
options = [('NOP', None), ('NOP', None), ('SAck', (912715992, 912716335))]
|
|
|
|
|
|
2024-12-14 20:35:59.526018 - Ether / IP / TCP 142.250.201.78:https > 192.168.1.11:42690 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 32058
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xac99
|
|
src = 142.250.201.78
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42690
|
|
seq = 2800351769
|
|
ack = 912716335
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 984
|
|
chksum = 0x1fe9
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b')c\xd8:\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:59.527906 - Ether / IP / TCP 142.250.201.78:https > 192.168.1.11:42690 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 32059
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xac71
|
|
src = 142.250.201.78
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42690
|
|
seq = 2800351769
|
|
ack = 912716335
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 984
|
|
chksum = 0xa540
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\x82\xf9\xc0+Rt\xdf\xc5\xe4\xf8\xf5\x10\xef\xe2S3O\xdbl\x15\x93_7\xbd\xf5\x8b\xbbZ\xfcA\xe7\xa6\xc7\xe1'
|
|
|
|
|
|
2024-12-14 20:35:59.534239 - Ether / IP / TCP 142.250.201.78:https > 192.168.1.11:42690 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 586
|
|
id = 32060
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xaa75
|
|
src = 142.250.201.78
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42690
|
|
seq = 2800351808
|
|
ack = 912716335
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 984
|
|
chksum = 0x77f0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x02\x1d\x98\xea9\x1e$\x14\x98\xacI\xc2O\xc3\xb2u\xb5\xa6\x04bxU\xee\xf4\x1f\x88\x90\xa4B\x0b\x07\x00I\xcf\xef\x14\x04\xae\xb20yf\xc6\x9b\x1d\xa5\xa9qh-\xe3{\x85\n\xa2Y\x89Z\xdf\x98\x96\xef\xdf\t\x9e\xa6\x93\xbc\xfbH\x122\x16\x8c~]\xf6\xb1r:S\xb0\xc9\x04\xc3r\x0e\xa2\xe0MEB^zDKI?\xdb\xa54\x16\xaa\x8d!\xc7\x99\xcd\xdc\xa9\n\xde\xa5PzGLP\xdd\xf5\x1d\xfdJ\xad\xafe\xa5\xf1S\xc6+\xb1\xb2y\x83N\xbfs\x91\x84*5\x04\xa3\xbdL\x85\xe8\xa3\xd3^\x03F\xbb^\t\x84\xadK\xa0i\xdcmt\xe5\xc7&&\'[\x9f\xa6)v<\x13@\nw\xf6\x00A\xa1\xa2GO}fv\xb2}\xf6A\xe6\xafL@\xf9\n\xe4\x0b\x7fyd<\xcc\xd4\x8a\xe1]\xce\x94\xa7\xcby;n!i\x00\xd5G\xac5\x19\x14\x8a:H\xf0\xe4g\xdc|[\x81[p\xd0\xe2\xef\x08\xe3\xd6\xbe\xda\xdeV\xfe#\xf9tyM\x97<\xdf*\rl\x1f\x7f\x16\x0e\xb7\xc7\x9bCq\xfb\xae\xdb\xca\xadp\xc66\xdd~*\xc2\xf7w\xa1\xe0\xc6\xe8\xd9\xfc\x0b\x9ct\xf9\xf5\xec\xc9\xc5}\x93\x1e\xd8\xbfn\xda\xe5\x87N\xfa\xaf\x85\xa6~\x1c\xab\xa9\xa5\xa3\x85\x93\xff\xb7\xdf\xc1A#\xe7\xc7\xb6\xc9\xa1N\xfd8Ei4\xf4S\xc4\xd1\xa2\xc4)l\xa8$\xc8B\xba\x17\xac3\xeb\xd8\t?\x9a\xd0\xe4L\x06\x84g\xb4\xf2U\xa25\xf4\x92\x04\x86LNm\x032\xe0\xa9\xe9?\x9e\xc5\x8e#8"\x81\x00\x14F\'\x98\xe4Am\xa2\xf1\xebB\x92\xf5T\xe6\xadyZ\x06\x9e\x8cgS|\xf4\xc8pJ\xb2\xf6nhg-4\xe7N\xd6,\x8cN\x93\xfb\xcf:+=\x89*7\x87\xc2[\xfb\xad\x880\xddR\xee\t\xc9\x18\xcc\x89\x91D\x8b# Y)\x97<\xc1\xe9\xfb\xb7\x86\x1a2\x88\xbf3\xef\x1e\xb9\xa9\xd75\x1d\xf6\xed\xbd\x0e\xe2\xea\x15E%\xa1\xfa\xbb\x8d\xee\x86L\xfd\x8a\xd6\x1c\xd2\x0e\xf0\xcf\x0f\xd9}\xbc\x8e#\n\xa4L\x138\x03\x9d\xf4\x0c\x13\xd7\x91Z\xe0>a\x03\x15\x0c!*0\x95\x02\x8c-M\x19@\xd0\xd4\x8c\xf3'
|
|
|
|
|
|
2024-12-14 20:35:59.543302 - Ether / IP / TCP 142.250.201.78:https > 192.168.1.11:42690 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 744
|
|
id = 32061
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xa9d6
|
|
src = 142.250.201.78
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42690
|
|
seq = 2800352354
|
|
ack = 912716335
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 984
|
|
chksum = 0xa1a5
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x02\xbbS\x86\xc8D\x0b\xf8\xcd\xac:C\xdc\x9b\x8a6\x90a\xd2\xa5|\xcbhg\xd8\xe5\xd7\xd9\xb9n\xcd\x88,\x1aM9\x12\xb8\xfa\x8e%>\xa0t\x04\xf6\xd6\xd1\xb1\xae\xe3\xe5\xb7ih\x16\xa2\xe9\xcc\xaf\xa5\x0f8\xa0b\xf5\xb2e\rv\xb0,\xda8\x9c\x8e~\xa2\x10\xa1\xaa\x1f\xf0Y\x9c%\xebq\xeb\xd2\xdf\xeel*\xce\xa1\xb6\xe1\xea$?\xc4\x08zN\x00\xc1\t\xd7\t\x8b\x0c>l\xeeT\x03\xfb>?\xf5\xb3\xd5S\x1dyi\x1f\xe3\xa6(\xfa\xf8r\x9dz\xacKED\xd1\x1bF\xccw\xf2\x9d\x0f\xdf\x1bjn\x93\xf4V.z\xbe\xa4\xea\xfd$\xd2:"h2\xdd\x1b<z\x82\xb5x\xbc\x18\xeb\xd9\r1\x13\xc8\x1e["g\xdfB\x91\x94t\x0ftNXd]\x87s\xa5-45OCY\xda\x1b\xb5zi0\x8fX\xebu\xe3?L]\xb1%Y\xab\xe0\x9a\xc6\xda1\xe1\xb61\x8b\xd3\xe2\x96\xd1\xe0k\x11*\x96\xe8M_\x10\x98\xf3\x19A\xab"vW\xcdR\x82\x86\x9bq\xaf\xdd\xeb\xb6\xc3\x1a|\xf6\x0f\xe3\xd2K\x9d\xfa\xc2K\xd2\x8e$hf\xafM\xdc\xb3b\x88\xdc\x80|\x83-H\xde\xd6%\x8a<Gq\xd5\xa3\xd3W}D\xe9B\xe3x\xfd\t\xd3\xc4\x009\xdfX7;\xb0\x86\xf12\xcc\xe9\x12\x0cg\x8f\xeb\xf3\xe4\xa6R\x99\x84;f\t\x93\x12\x1b5\x0b\xd6\xa8F\xd1\x9f\x0c`\x05\xeb\xe4\xf2\xf2f\x92\xcd\x7f\x955\x07Xw\xb8Y\x810\x10\t\xf1-9\xdd\xbc\xe7\x93!j\xba~\xa1\xda8\x8d\xfb\xb9{2\xa1f\xe0]\xd3_*\t\xbd0\xcb\x04\x7f6\x82M\x0c,\xb2\x15\x8b\xcae\x8f\x98t\xf2\xee\xe7\xc4\xd1\xba\xb0\x0e\n\x17\xa8\x1f6\x84z\xe4\x1fv\x80\xdaO\'\xa5B\xb6\xbe\xf5\xff\xb2C\x92\xc1p%\xd4O\xc5\x06@"\xc6\xcc\xde\xd4\xbf/\x82\xe1T\xab\xc7E\xcad_Os\xa9\x08\x15\x1e:\xd71\xcdj\xa0\xdf\xd2\xf6\xc2kbdV2f\xd4\xcb\xb1\x0b\xb5\x0e\xae\x17\x7f\x87x\x98Gb\xb0\xf1\'u\x96\xef\xc6\xc9Kq\xa3\x96\x08&\x1f\xa6%\xc0\xafx\x16?`\x05\xc1\xf2\xad\x9bG\xfb\\ \x0bI\x94\xd1\xa9>\x0f?\xde5c$\xf1\xc4\xf9p\x19\x90\x80\xe454\x8e\xf0I\xa9\x89UD-F\x84\x1c\xa7\xd3g2\x07W\xda\x99P\x832T\x08\xec\xe8L\x02\xa2k\xdf\x9c!\x8a\xfb8\x7f\x16\xd5c\x19\xfc\xb9\x8aSm\x8b5-=Jx\x1bZUf\x94C\x7f\xefa\x11\xc6l\xb9\x80\xafD>\xbf5.2\xc7\xb0\xac\x96~\xa1p\xa7S\xc0c9\xe2#nw\xd6EU\xa5\xf0\x14Jk\xa5q\xd7\x01\xd0E\xe8\xee\xebT\xf7\xb2\xc0.\x12\xef<-\xbcM*>\x83\x0e\xf5s\x10\xc5\xd9\xaa;V@\xa1 \xe2\xdcS\'A\xa0\xf2'
|
|
|
|
|
|
2024-12-14 20:35:59.578542 - Ether / IP / TCP 192.168.1.11:42690 > 142.250.201.78:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 22713
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.78
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42690
|
|
dport = https
|
|
seq = 912716335
|
|
ack = 2800352354
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 512
|
|
chksum = 0x1a17
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:35:59.612853 - Ether / IP / TCP 192.168.1.11:42690 > 142.250.201.78:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 75
|
|
id = 22714
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.78
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42690
|
|
dport = https
|
|
seq = 912716335
|
|
ack = 2800353058
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0x1a3a
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00\x1e[\x12\xd4(\xc4\xd6h\xd3\xc0.\xa51\xc0Z\xd1\xc6*1}J\xd25\xa1\x81\xbev\x0c{\xb1\x07'
|
|
|
|
|
|
2024-12-14 20:35:59.621470 - Ether / IP / TCP 192.168.1.11:42690 > 142.250.201.78:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 79
|
|
id = 22715
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 142.250.201.78
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42690
|
|
dport = https
|
|
seq = 912716370
|
|
ack = 2800353058
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 510
|
|
chksum = 0x1a3e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x00"\xe4=V\xed\xa8w.J\xab_41NF\xb7\x9dN\xedV\xf4\xefJ\xde\xff\x976\xf3\xc8\xdc\xe5\x9a\xb2n\xf6'
|
|
|
|
|
|
2024-12-14 20:35:59.638132 - Ether / IP / TCP 142.250.201.78:https > 192.168.1.11:42690 A / Padding
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 32062
|
|
flags =
|
|
frag = 0
|
|
ttl = 119
|
|
proto = tcp
|
|
chksum = 0xac95
|
|
src = 142.250.201.78
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42690
|
|
seq = 2800353058
|
|
ack = 912716409
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 984
|
|
chksum = 0x1a96
|
|
urgptr = 0
|
|
options = []
|
|
###[ Padding ]###
|
|
load = b'i\x97\xbc\x85\x00\x00'
|
|
|
|
|
|
2024-12-14 20:35:59.820297 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34267
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63629
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 25795
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:59.822139 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34268
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63630
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 25796
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:59.823927 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34269
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63629
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 25797
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:59.826197 - Ether / IP / UDP / DNS Qry b'101.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 72
|
|
id = 34270
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63630
|
|
dport = domain
|
|
len = 52
|
|
chksum = 0x83a2
|
|
###[ DNS ]###
|
|
id = 25798
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:59.835030 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63629
|
|
len = 76
|
|
chksum = 0xd8b4
|
|
###[ DNS ]###
|
|
id = 25795
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:59.837055 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63630
|
|
len = 89
|
|
chksum = 0x6b2c
|
|
###[ DNS ]###
|
|
id = 25796
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:59.839082 - Ether / IP / UDP / DNS Ans b'Galaxy-A51.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63630
|
|
len = 81
|
|
chksum = 0x8ca4
|
|
###[ DNS ]###
|
|
id = 25798
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'101.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'101.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Galaxy-A51.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:59.849237 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63629
|
|
len = 51
|
|
chksum = 0x1f5e
|
|
###[ DNS ]###
|
|
id = 25797
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:59.871336 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34271
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63631
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 25799
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:35:59.877431 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63631
|
|
len = 81
|
|
chksum = 0xa68c
|
|
###[ DNS ]###
|
|
id = 25799
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:00.279301 - Ether / IP / UDP / DNS Qry b'assets.msn.com.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 60
|
|
id = 34272
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 64667
|
|
dport = domain
|
|
len = 40
|
|
chksum = 0x8396
|
|
###[ DNS ]###
|
|
id = 18300
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'assets.msn.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:00.301393 - Ether / IP / UDP / DNS Ans b'assets.msn.com.edgekey.net.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 278
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb67a
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 64667
|
|
len = 258
|
|
chksum = 0x249d
|
|
###[ DNS ]###
|
|
id = 18300
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 11
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'assets.msn.com.'
|
|
| qtype = A
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'assets.msn.com.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 20714
|
|
| rdlen = None
|
|
| rdata = b'assets.msn.com.edgekey.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'assets.msn.com.edgekey.net.'
|
|
| type = CNAME
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 215
|
|
| rdlen = None
|
|
| rdata = b'e28578.d.akamaiedge.net.'
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'e28578.d.akamaiedge.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9
|
|
| rdlen = None
|
|
| rdata = 2.18.188.21
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'e28578.d.akamaiedge.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9
|
|
| rdlen = None
|
|
| rdata = 2.18.188.2
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'e28578.d.akamaiedge.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9
|
|
| rdlen = None
|
|
| rdata = 2.18.188.17
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'e28578.d.akamaiedge.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9
|
|
| rdlen = None
|
|
| rdata = 2.18.188.20
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'e28578.d.akamaiedge.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9
|
|
| rdlen = None
|
|
| rdata = 2.18.188.4
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'e28578.d.akamaiedge.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9
|
|
| rdlen = None
|
|
| rdata = 2.18.188.3
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'e28578.d.akamaiedge.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9
|
|
| rdlen = None
|
|
| rdata = 2.18.188.30
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'e28578.d.akamaiedge.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9
|
|
| rdlen = None
|
|
| rdata = 2.18.188.8
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'e28578.d.akamaiedge.net.'
|
|
| type = A
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 9
|
|
| rdlen = None
|
|
| rdata = 2.18.188.19
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:00.304939 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https S
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 28333
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308730996
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 65535
|
|
chksum = 0x8001
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 20:36:00.312520 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https S
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 28332
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156341888
|
|
ack = 0
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = S
|
|
window = 65535
|
|
chksum = 0x8001
|
|
urgptr = 0
|
|
options = [('MSS', 1460), ('NOP', None), ('WScale', 8), ('NOP', None), ('NOP', None), ('SAckOK', b'')]
|
|
|
|
|
|
2024-12-14 20:36:00.321533 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42770 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xc7e9
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42770
|
|
seq = 959589876
|
|
ack = 3308730997
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 64240
|
|
chksum = 0xe4e0
|
|
urgptr = 0
|
|
options = [('MSS', 1384), ('NOP', None), ('NOP', None), ('SAckOK', b''), ('NOP', None), ('WScale', 7)]
|
|
|
|
|
|
2024-12-14 20:36:00.330622 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28334
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308730997
|
|
ack = 959589877
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1024
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:00.335030 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 603
|
|
id = 28335
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308730997
|
|
ack = 959589877
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1024
|
|
chksum = 0x8228
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x01\x02.\x01\x00\x02*\x03\x03<:\x93I{^"\x00N\xe72)\x15\xa4\x8fp\xdd\xe3%\x04\x83\xc2\x14\xb3;@j\x90\x13\xf6\xa9\x1e \xee\xae\xbcj\xc8\x82b\xc65\x83\xc9D"\xcfJ\x0e)\xbc"\x0b\xba\x01\xfd\xa9\xe9\xea\xc4\x99\xc9\xbb?y\x00(\x13\x02\x13\x01\xc0,\xc0+\xc00\xc0/\xc0$\xc0#\xc0(\xc0\'\xc0\n\xc0\t\xc0\x14\xc0\x13\x00\x9d\x00\x9c\x00=\x00<\x005\x00/\x01\x00\x01\xb9\x00\x00\x00\x13\x00\x11\x00\x00\x0eassets.msn.com\x00\x05\x00\x05\x01\x00\x00\x00\x00\x00+\x00\x05\x04\x03\x04\x03\x03\x00\r\x00\x1a\x00\x18\x08\x04\x08\x05\x08\x06\x04\x01\x05\x01\x02\x01\x04\x03\x05\x03\x02\x03\x02\x02\x06\x01\x06\x03\x00#\x00\x00\x00\n\x00\x08\x00\x06\x00\x1d\x00\x17\x00\x18\x00\x0b\x00\x02\x01\x00\x003\x00&\x00$\x00\x1d\x00 \x04\xf6^\xcd\xe9\xe2?J\x17\xb3\xc0\x84\x8d\xc4\xfe\xe4\xe4\xc6\xe0\x8f\x13y-9\x8f\xd0\xd9}\xd3\xf1.\x03\x001\x00\x00\x00\x17\x00\x00\xff\x01\x00\x01\x00\x00-\x00\x02\x01\x01\x00)\x01\x1b\x00\xe6\x00\xe0\x00\x00o\xa20X\xa5\xbb6\xea$\r\x81\xa1\xadb\x89\xf6\xcf\x82\x87\xc5G#"\x97\x1d\x9a\xdf?^bv\xa5\xef\x00h\xcc\xd2Wp\xfe\xe9\xa1H\x15|\xdf\xcc\xb4)r:\xa8\x0e\xfc1\xe9\x9f\x95\xea\xee\xd2\x84\x8f\xee\x18d\xd0\xfd\x94WJ\x81\x06\x0e\xe4t\x0cL\xf7\x95j\xc2\x8e\xac]\xddW`\xa5\x91\xf8\x1f\x02\xea\x84b\xb2l\x97\xf9\xf3b\x0f\xf9\x83\xd4t\xb3\xff\xdaQT\x9b."s-\x8c\x83\xa9\xf0x\xce\x8dhA\xb8\xfamox\xed4N)\xc3\xe1M\x05\x1aC\x0f.\xfc5\x8e)\xb1\x15p\x92XO\xf7I\x8f\xc9\xb1\xd2<\xb3\xedZE\xdc\xae\x94[U\xadj%F\x14[Y\x99I-\xed\xd9\x07\xed\xdfhA\x0b\x1e\xd4\t\x97p\x88\x17\xbb\x85\xe3\x0c\x96.--\xec\xd1\xe6\x03\xe9\x1f\xdc\xbcm\xe31\x10\xaf\x14\x7f\x98\xf9g\x8a"\xb4\xff\x90\x93\x0010\x82E\x81\x14\xfd"Ir\xd2H\x87\xea\xafj\xaf\x8e\'`D\x1a\x8f\x905cz9\xf1n9\xbd;\xb1\xd8\xfa[z\x80\xffO\xbd\x89]\xb1N\x15\xf8\xf8-'
|
|
|
|
|
|
2024-12-14 20:36:00.360081 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42771 SA
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 52
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xc7e9
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42771
|
|
seq = 2767126959
|
|
ack = 4156341889
|
|
dataofs = 8
|
|
reserved = 0
|
|
flags = SA
|
|
window = 64240
|
|
chksum = 0xeed5
|
|
urgptr = 0
|
|
options = [('MSS', 1384), ('NOP', None), ('NOP', None), ('SAckOK', b''), ('NOP', None), ('WScale', 7)]
|
|
|
|
|
|
2024-12-14 20:36:00.367628 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28336
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156341889
|
|
ack = 2767126960
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1024
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:00.372212 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 316
|
|
id = 28337
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156341889
|
|
ack = 2767126960
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1024
|
|
chksum = 0x8109
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x16\x03\x01\x01\x0f\x01\x00\x01\x0b\x03\x03\x06hZ\xec\x17\xd7\x8eM\xa0\x98\xdb:\xf5^\x10A\xd8}q&\xae\r\x84\nu\xc8\x9c\xc5FO\x8f\x11 \xa7\x1fN\xd3\xb0\xf1\x03\x7fmn\x8c\xdb\x8dM\x1d8\xfdS\x06_!\x0f\xf8B\x1e\xedJ\xe5?\xaf\x9d\xe6\x00(\x13\x02\x13\x01\xc0,\xc0+\xc00\xc0/\xc0$\xc0#\xc0(\xc0'\xc0\n\xc0\t\xc0\x14\xc0\x13\x00\x9d\x00\x9c\x00=\x00<\x005\x00/\x01\x00\x00\x9a\x00\x00\x00\x13\x00\x11\x00\x00\x0eassets.msn.com\x00\x05\x00\x05\x01\x00\x00\x00\x00\x00+\x00\x05\x04\x03\x04\x03\x03\x00\r\x00\x1a\x00\x18\x08\x04\x08\x05\x08\x06\x04\x01\x05\x01\x02\x01\x04\x03\x05\x03\x02\x03\x02\x02\x06\x01\x06\x03\x00#\x00\x00\x00\n\x00\x08\x00\x06\x00\x1d\x00\x17\x00\x18\x00\x0b\x00\x02\x01\x00\x003\x00&\x00$\x00\x1d\x00 \xbc\x1d\xb7bd\xb2D\x0fW<?\xfe\xffW\xb7^\x1f\xc8i1\x1a\xe4\xe3G)\x89z?\x0f\n\xf6j\x001\x00\x00\x00\x17\x00\x00\xff\x01\x00\x01\x00\x00-\x00\x02\x01\x01"
|
|
|
|
|
|
2024-12-14 20:36:00.396119 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42770 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 295
|
|
id = 54866
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xf0a3
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42770
|
|
seq = 959589877
|
|
ack = 3308731560
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xe9c6
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x03\x00\x80\x02\x00\x00|\x03\x03]\xfa\xfc\xad`\xaa\x80\x1d\x96\xf8B\xfb\xd8\x9b\x94e\xb7T\x15wT\xe6\xa5\xd2\x80/\xc5m\xdb\xafO\x08 \xee\xae\xbcj\xc8\x82b\xc65\x83\xc9D"\xcfJ\x0e)\xbc"\x0b\xba\x01\xfd\xa9\xe9\xea\xc4\x99\xc9\xbb?y\x13\x02\x00\x004\x00+\x00\x02\x03\x04\x003\x00$\x00\x1d\x00 \x85\xc7\x17\xb5|\xc0\x82np\xc5\xd9W[n\xb3\xf1\xde\xd3\r\xf7 \x04\xea.\x1a\xdc:\x0e,$9 \x00)\x00\x02\x00\x00\x14\x03\x03\x00\x01\x01\x17\x03\x03\x00%O\x8azvy%\x14e\x05\x99\xbc7Wq\xe5\xfb\xdb2?MA\xb5\x9b\x0c`\x08\x14]\xe5)7\x87\x84}^dI\x17\x03\x03\x00EF\xdd\x1ca\x01\xb4P9h@r\x0c\xc5_C\xee\x87\xcb\xe9\xb4\xb1\xa9\x90<w\x0ea\x10\xc07j$\xd5"K\x1b\x91\xc1Y\xc7v(Qs\xc9b\x13\xcb> \x11\xc5\xbc\xebc\xf7\xf7 \x87\x12\x01\x97\xab\xb3\xe0_\xfa\x01\xc4'
|
|
|
|
|
|
2024-12-14 20:36:00.415855 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28338
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308731560
|
|
ack = 959590132
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1023
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:00.433745 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 120
|
|
id = 28339
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308731560
|
|
ack = 959590132
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1023
|
|
chksum = 0x8045
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x14\x03\x03\x00\x01\x01\x17\x03\x03\x00Ek+\x10O>\x8e\x0e|\xef\xc9\x9cp\xeek,\x80\xc3\xc1*z\xfc{\xecQ\xf3z\xb6\'\xaa\xba\xfeu\x9b\x9b-\x08\xd2Os\x9a\x83\x0f\xf8i\x87"t\x05\x00\xa9\xe8\x17\x07m\xf6\xc3\xc2\x12\xdfJ\x10[\xbc\xfbX\xf7\x8f\xde\xa0'
|
|
|
|
|
|
2024-12-14 20:36:00.447026 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 433
|
|
id = 28340
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308731640
|
|
ack = 959590132
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1023
|
|
chksum = 0x817e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\x84@\xe1 \xe3I?\xfc\xd9\x01\x9c9\xc2\x90J\xc2-\r\xc7U+\x86\x9cN\xfc\xd8\xa9\n\xb8\xaf\x9dw\xee\x07\xb0"+\xd9\xd1\xfc\xdd\x0c1\xbe\xfd\x08\xa9\x84\xe96\xeb/\xa6\x04\xc9#l&\xce\x9cM\xbc\x0c \xd72\xc9\x08\xc3M+\xd43\xbfq\xb3\xc5\xda\xbd\xf0?2V\x96\xf4\xc8\xc6\x1c\x8b\xf3\x8a\x8b\xe0\x19\xc4\x8d\xb4\xfe\xc9\x11\xbf\x93\xcb\x94\'\xe4|w\x1a\x0b\xc4mT(\x0f\xd1x\x8e\xb8\xd5\xb9\xaeEL\r\n\x02\x11~\xf7<\x15\x98u\xcej3\xf7\xb1@\xdef\xf3\x1b\xe5\xe6_\xbc?\xaf[>c\xca\x12/\xc40\xb8\x96\x1dAi\x8d\xaf2\xf1\xa5Q\x9d\xda\xd5\x04\xe6\xce\xe81\xcbO\xce\x8a\xbf\x1c\xf6B\t\xe9\x10\x1c\x1fs\xd8\x7f\xbc`\xfci9\xae|l\xd1\xa5\x99\xb4z4;Y\xca\xff\xbe\xd2\xd9\x99\xe9\xdaAV)\xf3\x12M\xc2\xdaKB,bw\x01\xd9\x18\xf0W\x11\n:\xd1\xa0\xf5\xb9\xcf,\xf6\x12c\x90\xb9\xa0\xfbk\xf9\xb0*\xc4`\xb4\xec\xf9\xfcQ\xd8\x07h\xbbDs\x0c:n\x11\xee\x1c\xe98\xcc\x99%\xf6=\xd0\xf2\x1c\xdc\xee\xebG\xd0\xe8\x142\x1a\xfb\xa0\x87\x00M)\x9a\xde\x13\xec@<\x95\xdaY$rzM\xe6\x8d\x05\x1e\xf9\x0e/su<\x1d\x87\x0b\x8e\x13\xff\xaa\xcd\xcc\xac\xdc\xa5\xa7\x04\'THD\xe4I0\x85\x1d`R\xe6\xa2\x88\x91jyf\x0eK\xab#\x86\x96t\x88z=\x97u10\x12\xba\xd1\x80\xacd\xe5\xe1\x11\x05\xf9J9@f0l\xc3\xf0\xea\xe5'
|
|
|
|
|
|
2024-12-14 20:36:00.454530 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42771 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 2960
|
|
id = 37712
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x293d
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42771
|
|
seq = 2767126960
|
|
ack = 4156342165
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x0
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x16\x03\x03\x00z\x02\x00\x00v\x03\x03\xbf\xf1\xbfg\xc0\xb3\xad\xf3\xb2\x15Y\x9e\x8f\xd4H\xfb`\xaa_\x9b\xbb\x9c*\xe5\x92*\xc9\xdegK\xc2\xd1 \xa7\x1fN\xd3\xb0\xf1\x03\x7fmn\x8c\xdb\x8dM\x1d8\xfdS\x06_!\x0f\xf8B\x1e\xedJ\xe5?\xaf\x9d\xe6\x13\x02\x00\x00.\x00+\x00\x02\x03\x04\x003\x00$\x00\x1d\x00 \xbe\x9b\xaa\xc3\xe1\x0f\xed\xc7e\x96\x992p\xb5\x92\xf1/-\xf3\xba2\x05\x7f\xda6\x81\x97$\x8fJ\x8b=\x14\x03\x03\x00\x01\x01\x17\x03\x03\x00%\xf9j\xe0\x0e\x98J\xa5\x8f8[\x9b\x12Ib\x11\xbf\x9b\x83\xa5\x8e\x86L\x8d=\x93w\x98Wk\x01\x04Z\x81Vt\xe7\xe9\x17\x03\x03\r\xafo\xbc\xd5\x0c\xab\xff\x00\t\x1e\x95\x1d\xfd\xa5*B\xb5\xb8#+\x1e\x8dp\xa4\x98z\x7fi\xcc\xcd\xf6\x7f!\xae\x8bN\x96|\x96\x18\x1a19I\xc6\xedo\xa0\x1b#\xa5\xecL\x06\xac\xbe\xfa\x82\t\x80\xee\xcb_\xc4{^\x1f?\x8c1\xc7\x19(Pvm\xa8~\xb0u\xc4SV\xbb\x90\x04\xf5\xc5\r\xa8I\xb4\x1c\xc6}b\x8b\x96\x17\x11\x93\x01\x98\xce\x83\xa9\x00{\xcd\xc1\n\x19\xfe\x0f7+\xfc\x80\x1c\xe1\xec\xc8pv\x10\x9d\x1d\x13/o\xd8k\xa8\xdf\xeb\xba\xcce\xf5\xb3\xda,\x0f\x8e\x98h\xb2\xc7\x15\xa6\x85/`J\xd7\xcfz`\x19\xcfr\x99\x07Yj\xee\xa2\x14g\xbc\xeb\xb7Z\x92\xafpp\xfcnx\xdb\xdf\x12!\x08}p\x10\xeeZW\xb6B\xb4P\xc6QK\xf1\xbe\xdb<\xbc\x0cW\xe3\x98\x8b\x96\xd8\x112\xa2b\xad\xd6\xe2%k\xc3\xfaz\xdb\xb1\x10&\xcf\x98\xd6_\xe8\x1c\x86\xf3Z\x11\x9e\x96)\xd6e\xc7\x96\x02\x8a]_TJ\xf2\x95\xb2F\x86]\xdfu\xd3\xf4i\xb9\xfe\x04\x98\xad[e\x1d1\xec\x19\x05\xa8\xa86u\x99JcS\xbav2\x10\x05rMZ\x07\xe1\xfa\xd4zk\x83\x17\xd6W\xfb\xba\xa8M\t;\xe8\tf\xb5\xe7z\xb4\xe0x:\xc0\xcb\xb4>87\x92\x11\x1a\x97\x82f\x126I>q\xa4\xcb\nv\xad\xdb6RA\xd9\xfco\xcdWg@\x81\x82\x1c8E\xde\x0f\xeb\xd4\xaei\x15\xe8\xe7\xc4\xbbW\xd1\x0c^\xe6\xc8\xb9u\x96\xc2\xbe\xd3\xf3\xe4\xd2s\xa6\xf4*w\xdbpD\xfaIR\xbd\xd2\xbc\xb0\xd4l\xbaJ-\xfd\x93\x9fdC\xb9\xb7\xa9\x96\x8b\'Hsr\x85\xe9*\x87@6P\t\x88h\xea\x01\xc5\x82\xf9w\xf1\xb6\xf1\xe4\xafVv\x98\xe25\x9eN\xe2\xe2\xb3X\x99G\xb8\x0bI\x93\xaa\x1b\xae\\ A.\xf9\x16\x00\xeb\x19\xae8\xa5\x078\xde\x7f\xa4\xe3[\x07m\\\x91\xde]n\x1b\xe3\xea\xc1E\xf9\xde\xd5\x16)\x92Q\x8ft,Ew\'\x1eb\x94\xb7\xbe\xab\xf5\xeb%\x8c\x96\x85\x0b]\x1e/\x11\xd7M\xa3\xda\x9f\x94\xef\xb1\xd2\x91c\xa8\xc1anXf\xc6g\x1ejA.\xa3\xf4R\xc0\xd6\xcd\x94"\xecz^P\xae\xdc\xf3\x1e\x8d\xeb(=\x19N\xfdq\xa20\xe5\x98\x18MH\x1d\x17\xbb\xb9\xa2+\x1c\x89R\xca\x89\xee\xd9\xbd\xc9\x02\n\x94\x99\x9bB\xf3\xc6\x15_m,\x93o\xe1=\x9d\xbc\xb0\x1d>\xb5\xfa\xb4\xf7q\x14\x19\xab7\x9b\xc2*\xc6\xd7\x1e~\x8dO\x10D\x92\x85\x07\x19\x12\xd1\xb5\x9d.\xfdb\x07\xf0(\x03\xb6\xc4\x07,.\x890\xd1Y\x93Q$@\x15\xf8\xb0B-\x11\xab\x9c\xfd\xc0\xfaA\xedK\x15\xc5\xe2\xd2\xdb\xd9\x85 .\x80\xffS\x01\xa1ir\xb3QhD\t\x8a\x18>\xeaSQ\\9\xdb\xfd<X\xe5\xba\xe86\xcd\xcb\xa5\xb6@\x04Q\xfer\xec3\xda*\x10\xfdp\n\x02I\xc3\x16\xdf\x9f\x9fW\xfd\x05\xaaK\xd3Inf\xdf\xcc\xb4Y\xab\xcbi(g\xc2\xfe\xfd\x87\x8d\xa3\xbe\x12w\xdd\xecq\xc8\xe5\xc3\xa6\x07\x1b\xe8e\x99\x0e\xdc5"\xb0\x98\n\x082\x9f%\n\x06YQ\xcab\'\xfdEk\xec>}<[\xe15\xe5\x83n\xde\x8b\xf8{\xccAN{j\xe0\xc7\x18\xb3\x02+\xa3A0f\xe3e\xce\xc7\xcd\x10V+\x8b\x92;\xd8 8\xab\xf4\xf7]\\\xba\x1b\xad\x92\x12-\x04+{\xa7\xb2H\x8eBt\xd3\x19\x17\x9a\xc6\xe3\x84s\x19\x92\xe01\x95\xc3\xf4\xbd\x99\xc4\xb6DK\xa3\x06i(K\x94\x12\xe8\x9a\xdb\x0e\x08\xc2\x82\xbd\x00)\xf7-4\x03\x80\x12\xdb0m\xcc\x8c(\x98\xafo\xfc\x1f\x0e\x1d\x85\x17h}\xaa\xff\xf7\x98/J\xaaR1V<\xe4b\xd2]\xaf6\xf6\xa6}\xa6\xb6~y~^\xbe5\xc2\xd7\xca\x1d\xd08D\x85"O\xfcM:-\x89\xe4\x9d%m\x9bVP\xd5Md\x02R\x1f\xaf\xd6N\x06l\xd7\x90\xdf\x81,\x02\xfaW\x96\x1e<\xf20~=vw\xeb\xc3\xdcj\x8c}\xef\x0e\xed\x84\xbe\xb1\xfcN\x9fvw\x13\x85\xb5\xda \x05\xf6\x08\x9f\x95\xa8\xb1#E\xbeJ\x97\xa4\xf3\xd52\x0f\xae{\xbd0 \xf9Q\xee\xbf\x8b\xeb\x1cqa~1\xa6|\x93\x0c/\x9d\xb7\x0b\xda@6\x1f\xbbyz\xbe\x1c\x00 ~\xd3\x1b\x1ds\xba\x06\x84Z\xc2\x84\xb3\x1dk}\xbd\xe1\xe3\xab\x7f\xbaZ&\xde\x1b\xc5Bl\xa7\xa6\xfe\xf6\x81\xae\xcb\xe7&\x96\x91\xeae\xa7\xa25SL\xc0Vc !hHPb\x96 UR\xff\xb6\x87\xf9V\xa6*\xdc\xe2\x98l]\xe3\xf7\xd8kB\x99v\xb2{7\x96D\x8b\x1e6\xa8\xf1r\x08=>7\xd6\xe2\xfc\xda\xfdu\xa4\x04\x89\x10\xa6\x89%\xbdlc\xf1\xe1Yr\x88\x02R\x11X\x1c\xb3+\xae$7\x0f\xe56\x18F\xe5\xa6.p<?P\xba\xc8a\x9a\xe0\xa4\x19\x86\xdd\xd6\xb3|\x8d-f\xe2\x93\xda\xf1+\xec\xe8p\xb1\xfe\xeaZ\xf5\xa0\x80\x81\xbf\xa2\xbe\x9c\x12\x9b\xddMC\xd1W{\x038\x90\xb8B`\xb7F\xfd\x1a\xa9\xe6\xebi\xf4\xc8\xe4\xb6\x96Z\x9aYs\xe6\xc9\x15\xb3\x0c*\xa95\xf0\x0ec\xd8\xfd\x92\xb0\x0b\x0e\xff-t\xe1M\x96\x1a\n\xe4\xaa\xeca\xe1\xc5\x13X\xc0\xc5O\xdb%&\x13\xd3V\x04)%\xbb\x03n5\x9b\xa8$\x98\x04A\x8e\xd1\xc0w}\x00\xc6\x11;Y\x16\'\xa1s\xb1\xbe-i\xbd(\xf5\xfb\xcc\xed\xb5\x15\xd7ru\xc7\x0f!/4\x8cmd\x8e\xda\xe6\xd6\xe5\xf9\x81\xd2dS\xac\xa5\xee\x14}\x80\x95\xfc\xb9\xa7k\x9d\x86T\xbez(\x18\x00\xdb\xd0\xdbS\xad\xf0\xeb\'\xef\x9d\xa1\xd9YI\xb9\n\xa46k\xaeh\x9a\xa7l"-!\xf2I?\xa9I\xe6\xd8\xb0D\x9eS\x04\xc4\x17\xed\xa3\x85V[\xdd\xed\xf40\xc3Y\xde{o0B\xeb{\xa7\x14\x19^\x83\x06\x0f\x8a\x81\xa5 \x158\xd5\xf3\xeeW.\xd6\x08P]&\x83 \xe2\xf4\xc5\xb0!7\xf8k\xa2\x02+e\xd71N\xfe\xc8\x12\xed\x1f\x02\x12\xa5\x82\x07-\xea\x93q`\xafj\xa8\xbd\xa6\x0c\xaf\xb2\x84W\xc8\xfb\xbc\x1a\x00)z\x81\x88jv\xbc#\xf4\xf5\x02\xbbP\x12\xd1L\xd1M\x1e\xffy\xe2i\xf7\xba\xc2W\xd9\xa2\x8a\x15z_\x9e\x0e\xac\x01T- ,,EqnGhB\xf1\xcf\xe6\x9ek\xa5\xad\xf0\xf2\xe4#\xcc\xd5*`\xd6\xd1\x93\x0c\x1b;@$\xa1\xf5\x81i\x11S5\xa8\xff\x8bvH\x91rfg\xde\x11\x11B\xc6K"N\xbd\xc7s\x93\xbc\x7fyW\x03g\xe3n\x87\x86\xa8\x06F\xda\xbb^O\x95\xf0T\x0f\xb2\xb3\xc6\x15\xefx\xc6W\xcc\xd2]\x94\x03\xaf\xaa\xfc\xe7\xa9/,\xb37z2\xb3\xedj\xaeo\xa3\xe6Nj\x9e\xf3RB\xdd\x18u{\xfc\t\xc7\x9bv\xe0\x85\x8a\xce)\xe9f\xe3\x8f\xb2fx\xe5\x0e\xb4.\n\xe8*\x03X5\xbf\xe8O\xc7}\xd8\xf3\xac\xe8\xc3\x1e\xda\xc6\ndow\x85\x06\x91\t\x08A\xcb\xdd\xf8\xf5\xcfN\xdc\x1f\x94\xe1\xa1\xccR\xb9\x06K\xfa\xa3\xf3R\xfb\xa8c\xbac\x01\xda\xd7>o:\xf0\x88\xcc\x11\xfc<\xae\x83\\>\\\xdd\xdc\x0b\x8a\xbaT\xc7\x98;\xde\xd1B;q\x11\xf5E\x928\xc0\x0cR\xce\x9e,\x90\x9dV\x0e\xdc#\x07m\x80\xa6+\xa7\xc4\xcc\xc5(\x83y\x9e\t\xf4\x13\xe7k\xc5\xa6\x8fr\xb7\x0b\xf2\x0e\xe7\xd3\xfd#R%\x8c\x83\xb3\xea\x90\x93V\x98\xbcVi\xba]\xd2_7gH\x14VO\x8d\x7f\x90g:\xcc\xf2\xb1\x15\xb5\x18\xc8\xc1\xeeS\x1dLf\xf8\xf4\xf2\xd8\xd9!\xb0\xe47l\x9c\x07\xf0\x1bK\xcc\x1d\x94\xd7\x81\xb3)\xd1x2\xe8v\xcb\xd6u\xf2\xde}u\xd1H\x86\xe8@#\xf4"\x90\x17\x85\xc7\x19\xbe\x0b\xea\xff4_\x95t3\xde\x1a\x10\xff\xa4\x16HE\xc3\xa6\x1d\xca\xa3x\xa4\xfc\xbb\x15\x08w\xb6\xd7M*\xba\xc6O`\xf9\xc8\xf7\x01.\xe2\xd7Eb\xa57I,\x9d\xd6\x1a\x92\x1a\xc5\xb4\x14YT\xe2\x85+6\x1a-7n|\xd7\x00\xcff\xe8\xcbu\x1ep@\xbc\xe7\x04\x13T\xdb\xff%&\xf9=c\xc9\x91\xfe\x81\xd8\x08\xfd\xfd2.x\t@\xae\x8e#\xc4\xff\'\xa9\xb8\xfa\xc4A\xf0\t\xa3x\x17\xf4,(M_\x9d\xab\x8b\xde\xb7\x8b\xe9\x91\xe8\x145~-\xf2\xb0o\x17\x84\xff\xc2\xf8\x08C\xffT\x03\x9c\xc1\xa9\xdb+\x80\xfb\xfc"\xfb|\xbb\x16\xa7\xb6\xea\x87\xb4\x05c\xa7\xd1\n\xaf\xbc\xff\xca\xdc\xbb\xd2\x94\x94@\xc8\xe8\xab\x94\x86\xe1^\xc9\xbb\x81\xe1g\xf9(E!b\x19\x89\xbe\xcb\x8e\xaf\xdd\xefD\xa3\xb0\xbd\xe4\xc3qCv\x7fb\x9cl\xde_\xac\xc1\xb9\xa6wY\r\x9b\xedr\x87Jnf\x8e]\x1aE#!P\xc2\n8\xd0x5\xa4\x05\xc7\x97\xe1\x9b\xf7\x1a\xd1C\xd34\xe6#e\x1e\xce\x00\xbbhN\xd7\x13\x93\x02\xf9Bxk\xf4\x98\xe2/W\x89\xb0\x15\x10ouo\xb9\x02\x14\xdd\xfe<\xffb\xdd\xfc\x7fKx\x02.\xef:\x92\t\x90\xb6ElQ\xd3\xce\xeb\xc7FZ?w\xeb-\x05\x8b\n\xde\xcf\x8c\x7f\xb6\xcb|\x1ai\x0eK~\xb8\xc8\x86\x1c\x8du\xe9\xa1\xeb\x1ft*X\x9d\xb8h\x95Y\xefO\xda\x9e\xba?\xa4\xec\xca#\x1f\xd0\xaf\xb44u\x8a|}E\x91L\x19t\'\n\x97a\xacoKY\xb6i\xbdY-S\xd0"\xac\xff\x1d\xce[\x9d\xb1Kw\xb0\x8a\xf2\x07\xd6O\x1c\x17\xb1\x92 L\x84\xe2\xacG\x9fN\xcb\x84\xad\xe1\x90\xa1\xf4\xc7\xf47\xa2\x14\x99s\x8c0o \xcb\xbd\xaf+\xeb\xa8C\x08gh\xf9\xca; \xd8\x8d\xc5\x03\x8c\x07\x8a\x84\xb0\xd1\xab\x181\x9f1G\x01\xcdV\x1e]\xb5V\x85V-\x1a\x86\xa0}\xa0z\x95~\xf8l\xb18\xc9\xbaW\x81&\xe4\x9b\xfb\x90\x18\x7f\x0c\x83\xfa"\xb3\xe07\xbck\xc65\x1a\xb8\xbd`:J#\xde\xddw\x97C.\xf0\xc3\x1a\xe30\xde\xf5k\x80/\xe60\xe3\x7f\xb3Uf\x18\x941\x0e\xd2\xbc\x81\xe9!g5\xeb\xa4\xc2\x96\xee\xd5\x93\x87\xb5\xfd\xacJ&n\x90\x0b\xa6\xde\xaf\xc8\x1d\xf8r\x0bZm\x1e\x0e\xc6\xbf%(\xc3\xe9\xf76\xf3\xa2v(\x14\xd5x\x91\xec\xe0?`\xb1M\x1e\n\xa9\xe8\xb5\xc2\xde\x84\x8a\x82\x83\xd6\x900\xb0\xde\xb8\x13bIV\x9bu\xce<B\xe4\x07\x954\xafW\xea\x99\xcd}p\xcdN\xe8\xb9\xfa\x8a\x17\x1b\x9f\xbe\xc2\xb498;?f\xd2\xa6$\xf4\x08\x82\xadI\x93\x9eY\x9e\xf5\x0b\x10\xe1I#\x05\xc3\x04\x1e\x13\x97qVO\x8e \xfc\x02\x1e\xbd\xc7\x12\xa8\xc5\x97\xdc\x83\xb7QN\xa5\xddU\xe2\x08\xa1orj\xfd&\x9a\x7fU\x9b\xfa]\x9eb\xd1\xd7bJ\x95\xc4\x01\x8e\x88+.6}H\xbbp\xaa\xfe\xfb\xcf\xa7\xc8\xbc\x16\x86\xda6\x91\x99I\x14\xb9\xc1hb\xaa@\xd6\x8f\xe0\x8c=D:\x1cmq\x93\xe3\xe1\xa75\xbe\x94\x87C^\xc2H\x9du\xa3\xaa|D\x8e\x8f7\xf9.E\xeeqs+\x0b\x02n]v\xdb\xe2\xde;W\x9a\x9cT\xc9?r\x12^\xfa3\xa2\xd2\xaa2'
|
|
|
|
|
|
2024-12-14 20:36:00.570139 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42771 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 978
|
|
id = 37714
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x30f9
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42771
|
|
seq = 2767129880
|
|
ack = 4156342165
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x2aed
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\'\x99_\x84d\xc3|OcV\x98:m\x81\x8e\xb7Pb\xe7\x06\x17C\xee\n6me\xe0\x81a)\xdf^\xbdt\\E"\x1b\x03J@N\xd3\xdf\x1e`\xa1\xd0{q\x14^S\x00\xaf\xaa\xaf1n\x19\x074\x930\xb9\xba\xc5\x8e\x8fb\xf6\x00\x9fr\xe1[<J\xca9\xca>\xa2E\x1c\xaf\xbf\xd4\x85\xd0\xb0\xda\xdf\xe2r\x14\xea\xf0\x88)I\xdd\xc0\xc4zA2MQ{1\xed7\xa0}\xae\xf4\x1a\xa5\x0cE1\x1e\x1d}8Ry\xc3\xf3?\xf0\x0b\xfe\xfa\x0c\x08A.\xf5]\x89\xebmQ\x8c4fG\xcd\xd6H\xc5\xaaLov\x0f$\x16L\xb2i$\xde\x0b\x95\x08\x12\\\x03[\xde&\xf4"\ty\x92S\xd8\x03\xe2\x00#js\xdb\x11\x1a#_A\xbd\xbb\x15\x81\xc6\x07\xba\xb3\xade\xc8\x10\xa7\x9d\xcdD\xcaxc\x14h\x11"\xa0>\xc9\xff\xb6\x14c\x0e$\xf2NG\x1b\xc1\xf1\x91\xaft2\xe4\xac,\xdb\xf5j\xe1y\xb6\xb0\xd8\x9b\xa1\x14Y2\x8b\\6\xc5\xda\xd1\xee\xed\xeb\xd0D\xda\xe4\r\xc2u\xb0\x10HV\xa7\x83\xfd\x93\xceZ<^I\x81#`E\xab\x9d\x9d\x15\xaa\xecB\x19B\x1eo|\xf0\xd8\x81\xd9\x02"\x86\x9e\xdd7\x1b,\xc3\x14\xa4Wl|\xb4K\xd3ox\n>\xeb\x1a\xc5\x98\xec\xaf\x19L\x8e\xe9\xcc4\x97\x07\tE\xf6\xa1\x1c\xa1\xc6\xfb\x06$J\x00\x15\x08\x90k\x14\xbaN\x01\xa8\x8f\xe6\xdf|c\xb0Vy\x0e\x98\x01H"O\xff\x0c\xbc\xc0\xefh\xae4\xd6(\x13\xcb\xc4\x17s\xa5&{\xfe\xa3\xd8o\x8c8\xa6\x03\xb5\xda>\xd4\xae\xc7\xdd\xf9f\xd8D\xbc\xd8K\xe5\xeb\xd7\xedQ\x9c\xa3-g\x99[C\x14\xa4n\xe8\x1b\xd3\xf2\x0fG\xea\x8e\x8b(\xa8IMS\xf7\x0e VFcP(\x15Wt\n\x05Rl\xfe\x9b\xfd\x1cJ\xc3[\xee\xf9\x1f\xf9~4\xce`\x1f\x89>\x05-q-1\xc4\x15R\xe9?\xd0\x8c\x96,nW\t\x87K\xcey\x14\xa3\xb4y\xb5\xad\xa4\x06\x8d8\x13\x9e\x05\xa8.=_\xe4\x1e(\xf7\xb1\x07\xa0\x8f\x97\x9a6\x0b\xf7\xe7\xbf\xbf\xc2miV\xf6>\x02\xaf2kL"\xb1\xac\t\x94\xb3\x19\xe5\x80\xf2\x1c\xff\x03\xd4\xf6\xad4\xba{j\xa9\xbe\x7f\xd9\xcb2\xcd\xa4(i\xa9b\xec1\x87\x9fF\x9e\xc9\xd6\xb2\xa4\xf5\x85t\xb7\x98\x0cR\xdb\x91\xaf\xbf\r,J\xee\xdc\xed\xcd\xd0b\xeb\xee\xc8\xd0O\xd5\xa5\x0f\xd5\xe9Sq\xe6\x98\x8c\xd92\n\x9e\xee\x8e\xc6\x85\xd46(~MSk\xf8+\x12\xd5\x89J\xade\x96%\xc4\x8d\xcb\xdd\xb1\xd6\xfa\x1d\xc1\xe24\x02x\xd3~"\xd2\x84\xca\x1b\xde5\x927\x17G\x96k\x10G/7\x94\x8c\xba\x93\xa2nq\xf9\xc7\x8a\xdf:"\xda\xf8\xd7F~\xee\xc4\xe6\x8eh~3q\xfd\xc9M?,\x02\x9fi<\xcceF\\:\x99vQ\xac\xc5\xf6XKn\xa6\x924\x8fr5x!{\xa2/omq\xeb\x88\x0e\x9e\xcf\xa5\xdfZ{~fLtY>\x8f\x1f\x95M\x0cl\xcf\xfd\xc2p\x82\xed\xb8\x17\x03\x03\x00`X\x07?"\x916\x80\xd1w\x98x\xb1\xf1w\xe0\\\x06|t\xb4fr\x05\t\'\xb3)\xd5\xcbZ\x18\xc4\x8cB\x86\xcda\xb4\xd9\x8dr\xf1\x97\xff\x9d\xd0\xb4\x963/\nr\xa4D\xb5l,\xfcQ6\xdb_\xd1\x86-\xd5\x15\x0e\xbbv\x11\xb4\x11\x08\x96\xeeKJ\xb1?\xd9iT\xd1pN\xae\x170(\x0b\xa3\xce\xfaa\x10\x17\x03\x03\x00E\x8e\xae\xe7q\x1e\xc9c\xba\x8di=E\xffr\x95\x1c\xad\xbe\xca\x81\xd7\xd7\x04M\xf0\xbc\xaa\x8dC\t\x8e\x1d\xbd\xa1)\n\xb3\x1e\xd6\x08,B\x97\x13\x13\xeb1"\xd3\xfa\xb1\x15~\x88Cs1\x01\xd0\xe2\r\xf0\x92h\xf3\xdf\x95\xda\xc4'
|
|
|
|
|
|
2024-12-14 20:36:00.661468 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28341
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156342165
|
|
ack = 2767129880
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1024
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:00.696240 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28342
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156342165
|
|
ack = 2767130818
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1020
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:00.721588 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 120
|
|
id = 28343
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156342165
|
|
ack = 2767130818
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1020
|
|
chksum = 0x8045
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x14\x03\x03\x00\x01\x01\x17\x03\x03\x00E\r9(\tpMf\xda\xee\xb4hzc/\xbc\x9d\xf8\xf6\xec\x8c\x03\x91\x12\x01H\xbe\x9dS\xf1\x8b8\xa6\x93\x082\x00-\xdd5~B\xd25\x1e\xb4?\x9e\x89M)Z\xcb\xb2\xc5\x97$\x01\x19\xd0\xb4\xfdA\x8f\x1f\x7fl\x87iZ'
|
|
|
|
|
|
2024-12-14 20:36:00.731806 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 433
|
|
id = 28344
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156342245
|
|
ack = 2767130818
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1020
|
|
chksum = 0x817e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\x84\x93d^\x9b[\xc1}wD[<\x120\x1e\x96\xa0@\xf9\xf5d\x10\xab\x86\xb5\x93\x0c0\x7f\x94.\xbau\xad\t\xf6\xfeH\x8bw8\xdc\x91\x87\xf2\xd1\xd1\xf3nD\x0c\x96_\xa1\xf2\xab\xe7o\x80\xf8\xa3\x8dV\xfb\x8c\xcd\x02\x8e\xce\xecQ\x15=\x82k\xa7n/\x11\xec\xcf\xe9\xe3\x971\xfd\r\xc7\x1eZ\xec\x89\xeev\xf7T\x9c\x82L\xae\xfb\xbeY,\xcf)U:\xb1\x11\x89"\x8d\x1e\x99\x9bR\x16\xc7\x96\x84\x8d\x9f\xec\xb4Y?\xf7\xb2\x97m\x90\x1b\xaa\xcd\xafV\xfb\xffH\xdd\r\xa6j\xff\xfbJ\x08c\xb9\x1c\xd6\x83\xfd\xf9\xdd\xb6\x97\x97\x02\xf6Vwl\xba\x84\xdbv\x1f{N\x96\x986\xfea\xf4I!\xe6\x8c$\xf86\x86\x17R\x90\xbb\x8f\xe0\x97\x1d\xf8\xe5\x9f\xffF\x84\xbe\x17\xd4v\xf5\xa5\x96fS\x10\xf9\xea\xdeQPOb5T\xc4\xd5\xea!\xcc\x0c\xc3\xefRz1\xb8\xdd\xe7cnq\x181\xff%\x8bN\x07\xcc\xb3\xfd\xa1\xfc\x8c7\\\x99\x07x*\xe4i\xa38r\x95\xab\x00\x8d\xfb\xac\xfe\x8df\xf0cx\x06P\xf8\xee\x05\xf3\x1a\xf7\xeeQ\xff\xdc\xeb=\xd1\xe3\xd1\xb0\x97\xa38\xf7\xaa_\xef;!9\xf7\x02\xd30\xf8\x8f\xa2\x10.w\xd8\'O\xe5\xa4&\xfc\x87\xe7\xec\xfe\xcfM\xe4\x16\xea\x0f\xd8&h\xa8\x82K\x8a\xb4bc\xbe\xd7\xb8\xd9xk\x82\xd1\xc6\x89\xff\xbd\x80\xa8\x0b\xa7\x13\x96B$\xc7\xdd\xa3 \xf6U\xc6\x1a\xb6\xfdq\x92JJ\x96\xdf+cS\xfd\xa0E\x0bk>\xdb*h8F\xc2\xc9\xe5'
|
|
|
|
|
|
2024-12-14 20:36:00.776186 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42770 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1500
|
|
id = 54905
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xebc7
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42770
|
|
seq = 959622314
|
|
ack = 3308738714
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0xabcb
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x07W?\x0b\xab\xad}7 .y[\xe2~\xb7\x17 \x88\xcci\xf2e\x1b\xdf\xa8LHt\xc6>\x11\x030\x02\x0c\x04\xa8\x04\x9f\xce\x1d\x89\xd9\xbd__=\\\xa8\xf3+\x8b\x15\xbf\x82.\xae\xd0\xaf\xdf\xde\'\xb1T \xa0\xc5\x85<\xde\xc1\xba.n\xff\x1b\x15\xfe\xc3\xc8TKy\x18\'&o\xfa\x1d\x8fY\x8c\x10\xf6,\xb5*\x957 \xb6\x16\xd2q;\x17\xaa\xcb\x88j\x1e\x05*Z\xbd\xb4\xb1\x938\xb6\xf5\x01\xab\xd8\x12<\xf0\xc30\x03\xd7\xcf\x06\x9b\xbc\xdf\xa5\x0c\xd2\xbd\x93\xb4r\xc1\x91t\xb6\xd9=9z\xebao\x90C\x15\x08\x19\xc3W\xdcIm\xd6j\xf0\x8d\xa1\x11\xad1Gf\xeb\xe3\xe6t\x91\xc8\x10\xc0\x8b\r\x8b8BI\xdb\x7f)\xd7\xe1^\xbb\xd0\xa6\t\x1f\xe6\xeb\x87h{\xde\xce\x1d\xb9\xa39Jt/01C\x0fA\xfdq\xd3\x9f\x17\x12$\xe8\xe6\x00\x83\x15Z9\xe5p4\x00G\xe9<-\xc5\n\xde9Z\xa8\x18\xe5\xa7\xf0\x9e\xf4\x9b\r\x8a\xa8Ff\x91\xf4\x1c\xf1\xe6\xaa\x1f\xb1\xcf\x1d&\xae\x1a{2\xf1\xa2\xcc\x1e\xff\xfa$U:^\xed\xfb\x04\xcd1\x02\x07^\x9c\x8e4\x85F\xe8&w$X\x88\x80O\x81:\xd2E\x9d\x9f+(\xab*\x9b\x80V\xf1!\xc0\xef\x93\x10\xe4^\xe0ub\xb0,\xf3\x84\x8b\xa2\xfa\r\x8e\xb4M\xda\xa2\xb1\x11\xda\xc8\x03\xf8\xa4.\x94@\xf6q\xd2\x15\x86\x86\x19\xf2\x13\xae\xe2/\xba\x90r\x85\x97\xa1\xa0\x99k\xdd\xf1\xe4\x9a\x19\xbd\x9d\x86\x0c\x7fu:\x86[\x8b7\xb9t\xabF\x19\x1f, U\x85\x9cDP\t%z\xe6\x16v\x05\n\xe5&\xa14\x0c\xb2\x8e\xf5\xb0G\x1d6\xac\x05\x8fj\xd3MSW4T\x81\xb3t/"\x0f*\x040\xf1\x9d\xf1\xe8Z\xe8\x96\xe0\xd4\x19\x1cj\xf8\x82\xcd\xd6\x13\xb8\xcc}j\xbb\xb4\xe0\xd2U\x11e\xf3\xf6r\x13\xb6k<\xff\xb2\x12nA\x1cR\xf6\x9a\xbb.\x9d\x8c*\xf3\'^J\xa8\x8665\xec\x14\xd1\xd9\xf6\x82\x9fn\xcc\xefi\xa6\xd3\x8d\xe8tP\xa9\xec`\xc5Jm\xc8\xc7S\x0e\xc5%\x0e\xb9\xfc\xc1\x81\xa4<a\xb0\xec\x05\xf1V\xf4E\x1c\x8d\xb0\xad\xefO\x1c\xcb\x96\xea\xd0;[\xc4X|\xd4s\x03\x00n\xc1r\xd3DV\xdb\xaf\xb8\xbd9\xc4d\x9a;H\x99\xd4\xb9\xc4\x80\xf1F\xc3j\x8c\xa7\xae\xc7C\x85I\xf4\xf8]\\\x1aL\xe9\xdc5\xaa>\xa4D\x06|>i|\x8c\x13\x82\x93d!\xf0\x9c\xa1\xe0\x07H\x94s\xcfc_\xdd!\n\x96\x89\xbd\x02\xa6\xef\xf9\xf3\xec\xafg_\xc1\xe0>\x9bx\x87x-+\x80x#\x91\x1c6u\xb2\xe8=\xa36\x11\xf9\xbd\x92\x96\x08\xe4\x91\xca]`|\xf5m\xc3\x12F\xb1\x18\x1b\x01\xfa\xcb\x10\xbe\xac\x86m\xd5\xf8\xd9\x8cw.\xb7\xb6\xc1S\x10\xa1o\xe7\xa7\xe8\xf3%\x01\x1d\xdf\xc1\n\xa9p\\\xaf2\xc7\xee\xdc\xb2\xbe\x8b\x8b\xcc/\x9626\xa2\x80\x01\xd2\xc7[k\x803\x07w\x9dTM8\xc3M5\xd6|\xc1\xdb\xb3 ~\x8bkQ\xe6\xa2ek^\xc0\xe8\xd3\xf6\x9f\xc6\x0c\xce\xff\xf6\x0b"F\x88\xd6\x99\xe9[\x83>\x92\x8d\xb9\x7fWb}5,\xea\xc5\x1a\x9d\xdf\x86(d\xb2\x7f\xcf\xac\x9a)\xa3\xf0\x8f\xee\xde1l\xa52{f\xb3|\x01\x0b\xf7\xddK\xcb\xc0<[\xed\xfb\xebz\x95\xe3=\\E!z\x1f\xa9\x94\xda\x1a\xd8\xd6K\xed\x0fK\xa8R\xe9\xd5\x84\xd8\xca\x1c^\x95I0\x05\xe2Z\xd8$\x0b\xc8\xf1\xc6\x0b\xc3\x89\xe04\x98U8{\x8d\x06\xca|<\x7f]\x19\x1f\x98\x922@ \xedCq\x1f\x9e%\xf9{r\x80\x89\x8bQ\xc6\xcei\x96\x0e`Y\xfbe :\xe8ia\xc6Y\x10\xc6\x136=G\x8f\x8b\'\xc17\xb9\x840\xdf\x07\xd0b+\x9b\x895x"Y\xdac\x1d\xa2&l6\xf4\xe4%\x00]%\xf1QC\xe3\xfeX\x8b\x8bk/\x87o\x1c\xb6O\xb2\x0ev\x97\x86\x93\xe2#,Ab\xb7\xe1\xfaL\xc2BbD9>\xa0S\x8c\xc0\x1a\x1c\xe9\x10\xe3K\xee\x9eR\x1b\xf5\xe9\x11\xf9f\xe19\x9d\x0f\x111\xc2\x96\x85\x92v\x80\xd2\x13\x0f^PNp\'\xd9\xe5\xee:z\xc9\xef\n3\xed\xae\x00A4\xfa/}\xbb7\xab\x80\x87\x90\xe4\x93\x97\xaa\nq"`\xe7\'S\x87\x92n\xe4D*\x91\x9bn.\xd4\xdd\xaa\xc4\xfd\xa6\x13\xa4\xe0 f3\x83\xfb\x04]H.\xc1\xa5ci\xa0\xcd7\xc44\xb0\xe3q-\xd5\xe1\x9bC\xe5Y\xab\x1a~\x9aw\xd9\xfc\xedX\xe7\xe8\xb6\xbf\xc8,\x08\xba\x8a\xc9L \xbaH`%,\xfb\x88?\x8cp\x13o\x9c\xbf\xd2\xf7\xfa}&\xd9l\x0f\xa0}\xf3*s\xd1\xa36gb\xee\xbeMKX\xb7\xa9k\x9dc\xba\x9e\x14\xc3\x8a\xf5\xdc\x98Y\xa9\xf1,\xfe\xf0\x1e\xc7%\xc7\x18N\x80\xab\x84\x91\xb8>\x18\xb7\x91\x0e\xba$\x1c\x9dr\x01\x02\xcf\x98RO/o\xf5^Q\xa0\x1cgs\xf3\xc0\xbd]\x0bI\xf6\r\xc5\xe1\xe7\x91=\xbd\x89~\xbb\xfeu\x84U \xc4\x8a/\x9dZT\xe4\x92-\x19\xbde\xf2\x99F\xc4\x0e\xe3X\xa2\x1c\xfd\x92\xae\x10UmkF>t\xd9.M\xfe\x06\x9b\xa0\x1d$8\x98\x08.\x06\xd1\xf2\xb2\xe5\xa4\xc0\xb0\xbb{\xdf\xde\xd3Q\xc6d\xec\xa7R?\xa9\x8d\xa6\x19mY\x92j!\x84\t\x19\xbf\x9dK|T\xd3#\x08\x8bM\xf1LDnhw\x8fJ\xccE\x9b\x9ahx\x9e\xd8eOs\x08\xf5?!\xb7%\x0c\xf0\xa8C\xf1c Gh\xb2N\xd56\xe0\xdc\x10\x08.x\x99\x1d\x81\x9a{\xfe\xc4\x8b\x02\xc4\x872;\x87UkWN\x9f!VLe\xa5kC{Kw\xb2K\x03\x99\xffX\xaa\xe7mp]\xd8\xa4$A\x1e\tX\xfa\xf1\x04\x98\xca0\x07\xac\xde\x08\xa5\x80\x01\'b\xa0G\'\xb0\xe3\x14\xa4\xc9\xef1\xca'
|
|
|
|
|
|
2024-12-14 20:36:00.847963 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42770 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 464
|
|
id = 54906
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xefd2
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42770
|
|
seq = 959623774
|
|
ack = 3308738714
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xbb4f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'm\xc1\xc3\xdc\x8fN\x1d\xdd\xb7M\\\x83>\x10k\x83\xe5n\xedH\xea\x88R\x8b\x94?\xf1[\x19\x87\xa9\x1c\xf8x\xd2\'LR\x1dx\x07.\xb7\x04\xdb\x16\xc0X\xb8\xca\x14\xfd\xb7d2V\xa2\x06 \xb29X\x84#\x96UK\x85\xe4\xae\xa8\xf3\xa1\xae\x1aa\xe9\x8e7\x93\xbf\x18a\xa1\xb7R\xb6\xb8.~\xf7\x83\x85T\xea\x9a\xf0\xe2\xa7\x9c\xb4\x1f\x16\xef\x9f\xae\x89^\xa9u\x08\xfa/\xf8t\xact\'\x16\x06U.a\x0b\x9b\xf6\xfaU\x89(\xa7ZXo\xc0\xca\xa1\xa0\xb9R\xe8w\x06[\xbf\x1abp4\x0b\x00\x93\xcb\xde\xc32\xde\x08OKv\xe7\xd6SB\x95\xedf"\xb8\xcd+\x08c\x12\xe9t\xcf\xd2=SI\x1c\x0fc\xe4\xe8\x824\xd9\x1a&HX\x85I}#+\x13\'>\xea\xed\xe03\xe5\x8e\x8f0\x07Q\x02\xd1\x96\x90\xf2\x0b\xa8!D\xc7bv\xd7C\xb8\xc2\xd1N\x9e-\xf6\xfc\xe0\x02\xa8\x82\xc6\x9c\xef[vW\xc9\xb6dU\x83\xea\x831\x80\x08\x05V\x8fC\xf4=\xfe.K\\\xf6\xeb\x9a\x8f\x13\xe5\x85\xb0\x03HX\xff\xc18X\xc66s\x8bS\xca\xa4\x94*\x9f\xb0\x04\x03\xe9\xe0\xea\xd7\xdb\x11\nh\\\x80\xb0!\xf1\x99X\x08\xb6\x96\x07\x8eX\xb8\xd0H\x1dr\xdfV\x81\n\xf4rF\x02_\xcc\xcbA]\x975\xe2\x9b\xda\xcc\xff\x1dr\x02\xe3\xfe\xe9\x8a\x88]\xadk\xd3G+\xa2\x89\xb5q\x03_T\xc4j\xb3\x8d\xf4\xf2\xc8\xc8\xa4\xbb\x0fD\xbf\xf1ZJT\xaf\x1a$\xe57SS\xaa)\x0b>f\xb3A\xf2\xfc\xd2\xd2\x04\x8b\xce\xca~9\xe4\xe8\x17\xacg\xd4q3+\x1e\x97E\x14\xa6\xd0h\x1a\x9a\x06f\x86\x92\x1a\x05'
|
|
|
|
|
|
2024-12-14 20:36:00.922357 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28437
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308738714
|
|
ack = 959623774
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1024
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:00.954422 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28438
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308738714
|
|
ack = 959624198
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1022
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:00.957852 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 433
|
|
id = 28439
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308738714
|
|
ack = 959624198
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x817e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\x84\xed2\xd913\x1f\xff\xf0\xd8\x83\xe9\x9cNa\xad\x8e\x8cx\x99~\xefj\xfc(P\xa4\xf3&\x867\xa0)\xfc,\x0e\x03\xfc6D\x83d\x7fz\x87(\xaa\xb6S\'o<\'\xbd\x89\xa6zO\\\xfcG\xf3eE\x08\xcf\x02\\\x8a}\xb4mF1kox\x12a\xa4\x9d\x9eA[\x00\xcc\xc43\x10vE`\x1f\xce\xcbG\x81\\t,\x05\xf2\xa3e\x1a\xd7l\xa2\x9eN\xcc\x018u\xff\xc1\xaf\xb7\xb0p%\x80z\x1d\x1e\x826\x88\xc6\xb0es\xfaq\x8b\xe5\x11bZ\xe7h<\x03\xaf\xae\xcbD\xacn8\xb9\xaa=q/\x97L\x98\xa3r\x9a\x99\x90a\x1f\x11\xd6\xc6\xd5\xc1d\xd9Op\xf2\x18\x87\xd6,\xf5\xac&\xfdR\xd0\x00\xe2R\xf5\x10\xf2\x00%\xe2\x01\xbfS\xc6\x04\xd29\xed\xc8\xa3\xd9d\xc66\x1e@x\xaeh\xbd{\xe4\xca\x9dU\xc0d\xf3c\x8d\xcb\xc3\x06\x83\xfe=\xb3\xbe\x03:\x867\x1e,\x95\xb5\x92"\xc6}<XC\xb9\xeb\xa2\x1d\xb1\':\x8e\x9a\xce\xe7X\xb5\xcc\x17 \x00\xae\xb6\xd2z\x7f\xef`\x16\x04I\xee\xf9\xe9/\x86S\xbb\x97K\x9fn!\xfc\xe0\xdf1\xe4,\xb3Qw\x9e\xd0\xff_ B\xef!\xaf2\xec\xe6\x9d0\xc9\xcd\x9da\xfe\xa5xN\x12YS\x9d\xc4\\f\t\x86\xcdt\xf9H\xed\x90\xde\xfe\x15\xd1\x1c\x12\xb4\x91\xb9\xa8\xae\x05\xc9\x81\xbb\x98r)\xb0\x0fn\xcc\xaf\xc2\x1c\xed\xc8\x9c\xd8-\xa4\x01\xc84\xd9J\x0b\x96\xb5iYv\xb5\x00\x14\xe1\xb6\x16\xe6\x87\x9d?\xbe\xa2\xf8\xc7\xde'
|
|
|
|
|
|
2024-12-14 20:36:01.007270 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42771 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1500
|
|
id = 37745
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x2ed0
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42771
|
|
seq = 2767155766
|
|
ack = 4156347747
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0xd91e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x07X\x0c\x93`\x91b\x8fi\xe4\nx\xf2o\xde\xab\xd7\x0bv>\xf6\xd5>\x12w\x95\xf4\xb6\x89\x89\xb2\xc8\x98`,jz\'\x00\xa8\xdf\x08\x85)\xc6Ke\xd0f=\x0c#Ou\xbda\x1b\x80fa\xf3\xfc[\xd2w\xfd\xcf+\xde\xed\xeba}\xf5\x05U\x1a\xa8\xaf\x13\x13\xd4\xe4^!\xa2\x0b>\xcf\xfa\xadK\x92\xcao\x98F\xc7\xf0\xd2\r\xab\xde\xcc\xdf\xf9\x97?\xf5\xd2M\xf2C\xe9NJ\xcc\xa0r\x94M\x82X5\xdf/6\x83r\x90\xf8,\xf0Q\x9d>\xf7`\xe5\x10zY\xe1\xe1\xc7\xf9\xd2\xd5\xa1\'\xab\x94\x07\x1d\xea\xabL\xad)T]JGR%$\xb3\xa7k\xb5RjbX&X\x17\xe4\xd5\xc6\x1fT\xe3 u\x08J\x9c\x8f\xd8\xb7\xde\xfe*t\x80\xaep\xeb\xcdOO\xbd\'7\x8bL\xac0\xafQ\x98\x00W\xad\x8b\xfa\xb3G\t\x9a\xb0\xb0\xbd\xc4xMaJH\r{+F\xab\xf6\xbb\x12\x99j9\x92\x8d^C\xb1\x14[\xfb\xef\xb0\x17Gj\xa2\xfe\x0b>\xd60Ne\xae\xc3\x00\x92\xe1\xc7\nO;\xc4\xbekW\xc9E\xf6\\P\xf0\x1b\xa0\xdclN\xa5\x1f\xb5scPUo*\xfd\xe8\x99\x03:lDX\xc0\x92\xead\x975%\xb3\x7f(\xae\x8eLV\xce@\xd8\x0e\xff\'E\x04f|\x88 \x8a\x05n\xa7g!\x99\xcf\x97\x0c\xbdq\xb3`\x82\xdb\x9aA\xdf\xcb\xa7A\x81\xcd[2p\x86\xfe]<#\xd0\x82\x9d\xa1\xe6v\xe1\xc6a\xba\x95$\x0em\xdb\xaf\xdc\xe0\xa9B(\xdd\xd2I\x95\xb3\x9b\xbf\xf1\xbf\xcf\x86C\x9f\xb6\xb0\x1a\xe8\xa3\xa4\x16:\xd5e*\x01\x93\x8f\x06\xb9\x17\xae\xdd\x86_\x05\xbb\xf8\xa6\\\xeb\xb6:\xf0\x88\x0c_\xa0\xc0\xd3\xf6E\x0fk\x81\xda9\xf3RB\xf7\xb1/\xcf\xce\xda\xe2\xc2\x92P\xedx\xfe+S\x96\x82x\xab4\x16+\x93\xf2\x897\xeb\x01\xa41\xe8\t\x05j\xf4\xe0<\x87\xa3\x0e\xb0h3\x8d\'\xe1j\x8e\xd9\xfd%\xa40v7\xf9+\x97\xb6\xc4\x1e\x1dO5\x18%r\xde1\xda\x99\xe3\xf9W\x01\x01]O)\xd5\x1b\xb5\xa05Z\x1b\xb6\x1f\xd4\nA\x8b\xb3\xfa\x04J\x19Cn4\xfd\x9ei|C\xdc\xaa\xf9%\xc7\xf7\xfb\xf5<\xc8\x16\xe6!o\xf3}S\x1d\xc2m\r\x86\\\xa1M\xe8\r\x96\xd4gp_=\xeb\xc3\x18\xc3\x17\xe9R\xf7\xe4\xa4j\x12\xc3$\xe0\x992\xb6\x9bp\r\x8c\x9e \xa8\x164\xe7\x0bx\xbf\xfas\x84\xe2\xe1$\xaa\xfd-\xb0#X\xf3\\U\xa9\xaf\xeaiR\xc4\x80\x1b ;\x08\x9e\\\x8f|\xc1^KE\xf5\x9cB\xb0\x99\xc6=e\xd6`?\x06\xb1\xedK\xc2$\xd7\x8a\x8b\xa2{*\xdf\xc7\xd8\xc3u\xd2\xb5g\x1d\xa9Ka\xf4G\xd0\xf0\xbbCL\x94\xc1#N\x9doV\x97g\xab\x8a\xc3\xb0\xe2\x19\xc6\xcdm\xd1\x0bE\x82u\xee\x84\x8bj\xe2\x92\x8c\xa3\x17\xe6r\x07\xf2\xde6\xaf\xce\xe9\xdb\xa4V\xe8W\xa1NobP{\x9b"\xe4j\xc6\'\x97\xd4P\x13\x04,\x01\xe0\xe0:\x1e\x8d\xa5\x8fZ\xf2\x94\xf4oM\xe5\xd1\xc8RkS\xf3\x0c\n\x04\xe0\xb8;l\x92D\xc3\xd8-n\xe5@BNb\x99C\x08\xc1\xba\x1f\x91b\xa1\x0bD\xb7\xe5n\x1f\xd3\xca_\xed\xe0\xa9\xf8+\xa8wGF\x8c/\x8eXA\xf7\xf8\xdb\x0c#\x91\x92\xba\x0f\x99f\x14\xc2\x97\x90\xb1\xd9\xcf6`y\x10i\x1cM\x0e]QS-\xdd1\xca\xe1$V\xf8\xa1\x1b\x901\xb6\x8dQ\xbavJ/R\xfc\xdf\x1a\xee\xb4\x89N^\xb3\xcb\xea\xbe\xb7^.&_\x86\x1b\nxn\xd9!\xf4\x1a5sA\x82% \xa4\x1fpm\xe4\x96\xf1q\x9fB\x87 c\xfe\x87cs\xf9\x15=\xcc\xbc\x0e\xb3\xc7\xf3\xc6\x17o\x96\x89"\nv\xed\xacx\xd9Y\xaa\x18S&\x18\xe2xRw\xe0\xc0u\xc3\x7f\x8d\xe3\x16\tMJ\xa6\xdc\xaf\x93\ro%\'\x18\x8a\x96\x184\xed\xee\x136\xad6\x1f\xff\x08\x00n\xfe\xcd\xef\xed@d\xbe\xcd\x05\xd4\xdb\xcaH\xfd\t\xbc\xf2\xda\x08\x15\xc3l&\xa3W\x03\x9b\xd0\xe6\x97\xb6\xc2\x18\xeeBF\x90H\xf7a\xa0j\xb1\xd1]\xa4\x8d\xf7\x07\xa8<V5I\xdcHo^B\xb3\xc3R<\x00[\xb1e\x05\xa7\x90\x12i\xdc\xa99\xf13\xc6\x10\x92\xfc\x82y\xbe\rm\x0f=\x8a\x8a\xa4\x10\xe1A\xc3\x85\x08ok\xb4\x05x\xa2\xb7\x0f\xda\xaa%X\x7fk\x94\x10\\\x0e\xfb\x8c\x1c\xc2]\x8f\xc2Z\xa8\x9d{ \xe7}\xda.\xf8Ml\x97\xc7G\r\xdfU\xaf#\x00\x0fu=\xe87\x922\x82\xe6\xec\xd8\x10me\x18\x8aV\xd0\xa0-\xbf\x80.\xa5-\xfe)E]\x1c\xa5\x8a\xe6\x1cBt\xb9X=\x080M\xec\x88\xf8\xf5\rk\xd8\x83\xe4\x8f\xe4\xec\xc4\xfa5\xe2\x0fx\xc8\xe1u\xc0>&\xfd\x1c\x94D\xe1p\x9f\x80\xe0\xb2m\x80]\xe3\'^\xb8Ys\xda\xad4\x1e\\\x07?\xb54\xa7\xbb4\x1e\xb3=\xe2\xa3\xbe\xb8\x94\x16\xc1\xbb\x8d\xa7\xe6\xe6\xd3\xe8\x96\xf3\x92\xcdu;*\xa9a3\xc5\xdf\x19\x01\x7fD4w5e\xc7\xd6\xef;:\x11U\xfa7g\xbe\x17Ev\x96\xb7b\x08\xa3\xd3\xa0\xcc\x08\x87\x9d\xd9\xf9\x95\xe4\x9b7\t~\x03\x07\x11;\xd9\x06\x16\xd3\x17l\x1en\xe3\x8c\\\xb3\xa9\xb1%7H\x9a\x9a\x8d[ \xc6\x0f\xdd-#\xea7#;,~BW\xa8\x89]\xc6T\xd4\xdd\xd1Uf\xd9\xae\xaa\x17T\xfa\'\xdc\xb6\x96\xfd\x80|4\xe8-\xe0q\x9e\x9bx\x9ci\x0e\xdd\xb61\xf4j\x9e\x13\x84\xfe\x8d\xa7\xf8\xc4\x03\xc8[T|;\x92\xa7\x99\xc6\xd8\x102Hr\xfc\xd4pW^\xdd\x03.\xa2@]\xad\xfaA\x8c}\xe7_\x9e\xb8/\xfe\x1fX\xc8O\xdb\xe2\xa0\xa38\xb6\xcb\xe7\xb0c\x9c\xf2\xb0\x84M\x9a\xfe\xefgO\xad\x03\xa6q\x1f\x90\'7\x8b\xd3#\xf5\x87\xad\xde'
|
|
|
|
|
|
2024-12-14 20:36:01.077933 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42771 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 465
|
|
id = 37746
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x32da
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42771
|
|
seq = 2767157226
|
|
ack = 4156347747
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x644f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"c\x93\xdc\xb6|\xf3\xc3c\x07\xb0\xbf2\xe9\xe3E\x7f\xbbD\x81\xae\xf0\x14\x8d\x8b\xe7\xb0\xb3\x06\r\x93\xdf\xd7Af(\xbe4\x80s\xc4\xa6\xddY\x0f*\xf8\xfe\xc4\x99\x0e\xd3\x83\xfdg\x9dv\xf7\xe7\xf9\x06\x00\x11\xd0\x97\x8b\x05\x02r\x89\xc6\xe7\x9a\x06\xa6|!\xfc#\x8e\xea(\xdd\xe7M\xbc\x96\xb0k\xc3\x1b3\xe8\xde\x85\r\xb6\xebr\xba\xf8N\xae\x87\xc6g\xf1\xf8\xd0\x85\xfd\xce\xc8\xa5d\xb73\xb8\xfcG\xdc\x02\xe1\xf8\x88\x01\xe9R\x05\xfcX/\x94\xfd`!\x9em\x07\xddFx\xf9*\xf1Y9:\x90\xbf$\xb9Jc\xd3\xe4\xb3\xaf\x02\xbb\xc0/\xce5\xfb0DL\x16\xc1\xa2\xb4z\x87\xd2\xbd;=\xe6(\x1f\x8c^\xd6\x9bL\x1cD\n\xa6.y\x92\x1d\xbfW\xea<g|\x00\xd6\x9b\xed\x1d\x82\xbd\xe1\xa9\xe6\xa5\xadx\x08\xabI\x0c\x8e\x95\x89K\x19\r\xcb\xc5\xbd\xe4@\x05K-\xfeF\xf3\xb2\n\xbeM\x96T\xabq\xcd[\xc3\x9et\xfe1\x04`\xd1s\xc6\xf8-U\x1f8c$Y\xae'`\x14\xdaK\xce\x02\xee\xd4\x81G\x8f\xfe;x\x9a2H\xa5-A\xfe[)\xf1u\xa9F]\x01x\xa8\x05\xc4\xec\xect\x18\xabi\xc9\x84\xe2P\xb3~V'\xf6V\xe9Z\x14\xe9\xb3\xe7\xe9fVBc\x06#c\xcc\x86_A|M7e\x162\r,&\xd2\x87\xd0\xf8\xf0G\xdaB\xfdE\xcfq\xa5\x8f\x1d\x89\xb9\x01U\xe9\xdd\xd13PY|.\xed\x85D\xb4\x81\xab\x0b\xaf\x8as\xa9\xad\xa7@h+?\x07\x96<SnyA\x80\xeb%9\xdb\xcd;\xe1\xa1\xac:Q\xe8\xd9f\xe1\x8crr\xa9\xf4\xaa#\x03\xf2\xcf\x80Fj\x9b\x15`\x04\xfd\x85"
|
|
|
|
|
|
2024-12-14 20:36:01.148229 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28440
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156347747
|
|
ack = 2767157226
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1024
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:01.185899 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28441
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156347747
|
|
ack = 2767157651
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1022
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:01.204624 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 433
|
|
id = 28442
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156347747
|
|
ack = 2767157651
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x817e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x01\x84$\xf8\xe4c\xb3c\xdc\x10cA\xeb\x96o\xcf\xac\n\xdd\xa3\x82:\xb6>\xa1\xcc=LG\x07\xae!\xb0ql\xca\x04\x99!\\\xbe<Ck\xa4\x9c\xcb|\x8a\xa0\x8e\x11<\x8b\xb7}\xd9\x7f\x18\x1f\xfds\x80\xa3\x15;\xe9\x0b<C\xd7!\xed\xb9\xa7\xc29+\x85i\xa7\xc3\xb8\xca\xff/\xfeFn\xdfz\t\x83\xce9\xa1l\xd5\xf5\xdbn<G\xed\x954'\xd6\x8e\xe6C\x02\x85]\xd9f\xc2\x93\xe8\x16\xea}]\r\x9ay^\xef=fp\xe3\x12\xb9;c\xce\x9ew6\x88\x0f\x1b\x13\x04\xde\xc9\xea\x83\xc8\xd4\x95B[\xc55\x8a\xbez\x1d\xc5:)Y\xbc\xc3\xc1\xdc\xfa>-\xfbq\xd1\x96\x00\x80\x89(\xcc\xe8$\x06c\xab?\xd5\x87U\x1di\xb5\x0bIE9b\x8c\x0c\xca\x06g\x83\x17\xb7\x0e3\xaa\xba\xf1U\xe1w4T\x8a6c\x03qy&\xca\xaa\x9cw!0bDI\xa0\x0eg:E~s\xf5\xe5\xdf\x98\xe1\xeaij\xa9\xaa\xa0\xb4\xaa\xc3\x12\x8aY\xbc\xc7\x8f\x96\x82e\xb9\xd6ez\xdf\x83\xf4\x80\xd4\x8c\x9f\xe5'T\xdb^\xb6\x00F\x9c\xb0=\x16U\x91\x80\xe5\xb6\x068\xec/\xf8\xd9\xdbp\x8aux\xb1(z\x92{$\x01f4\xafl\xa7\xfd\x0b\x89\xb3\xdf\xdc\x95\xc3\x91\xda\\\x01!;\x98\x902w\xe3\x14`\xa9-\x0b1@rC\x02\xb3\x90\xf4%\xb1\xf02\xf7(\xf6\x9c,\xf2\x08\xffs\xc4\xc64\xe0\xed\xa2\xc1\x95\x85{_U\x06\x10th+\x8e{\xf0\x1fx\xca0\xb8\xc93aq6\x1c\x1aW"
|
|
|
|
|
|
2024-12-14 20:36:01.229451 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42770 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1500
|
|
id = 54907
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xebc5
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42770
|
|
seq = 959624198
|
|
ack = 3308739107
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0x53a7
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x07R4\xb5\xe1?"\xf5\xf2Q\xbe\xd8\x150\xf1\x13h\xaf\xbd/\x8e\x7fG\xe7\xa5\x12w\xbb\xbb1z#&KRdL\x13{4\x8bU\xa0\x82\xb8\'\xa0+\xbeP\xac8*k\x83|\xce\xda\xc7i\xa0\xe3gmkf\xe8o\xe9Kd\xb2\x8e\x0c\x1bh~\x01f\xb5J\xbc\xdcj\x0c,\x0b\xe5w\x1c|\xf2\xda\xfd\x0f\xcb\x99S@|\x89$/\xea`tY\xc7\x08z\xd0\xa4\x18\x07O5\xd2\xc2\x8f\x03\xcek\x80\x0es]\x8c\xc6\xef\xbf\xd0\xd6C\x06\xfd\x1e]\x05\xf3\xa89\xf21\xc3R\x9c\x00L\xbc\xbd\xdde`\x97K\xc7\xbc\xb1\x88\xf5\xae\xd5{\xa4\xf3~\xe8\x1f\xb3\x0c\xe2k\x99u\xbciLT:6\xb5\x18\xfe\\*\xbaz\xb5_<\x93\x92A\x968\x04\x06\xf5W\xbc\x85\x16pM\x1dDYYy\xa81\x83\xccHoY\xde\x02K/\x13\xean\x04\xfd&\x99\x0e\xf5\x18\xf9\xf9\xbd\xe7\x91\xbf\x8b&.\xd2n\xebMuS\xb2\xcf\x08eK2\x91/\xdf\x84\xcb\xd30\x8c\xe8]\xceJ\x01\x88V\xba\xbd\xb4Ehu5\x84\xb0\x02\x08\xa1j\xb9\xd9}\xce\xd9\x0f\xa7u%\x0f\xc3\xf9\xc1\x89\xbc\xe2%V\x94\x17\x04 \xeb\x12\xbc\xfd\x0eKkrq`\xa1|&Z\xc2\x85W\xbd\xe5\x0f\x89\xc7\xf3NE"9Y\xd0/\x07\xc3\xb2zZL\xc2\xbf`&W\xab\xd1\x0bw+q\xfct0\xedZ\x01\xab\xa6\x93VH|M_DfT\x1f\xb4\xea\rw}\x88\xe8O\x14Y\x95\x9ch\xa0\x9d\x93\xc3+\xeb\xbc}t\x8f\xeb/\xde\x15\x0c\xb6j\x0b\xdb\x8egw\x0f\xa2\xc6\x9b\xca&\x87/\xb4\xa5\x063\x00\x02\xd4s\x83*\x07\xa39$s\x82\xc8\x17\x9bx\xd4\x12\x90\xea\x87\xa7e\xeet\xbd\x97$\xd6\x06l@\xe9Q\xb3\xf3[U\x00TS\x85\xf3\x9b\x13\xef\x8f\x00]\xaf\xb5\xddSR\x01U\xa7S\x8b\xa8\xa3\x8c\xb4\xd8\xed*\x1c\x9b\x80\xf2\x08\x8da6\x91O\x80x\xe9\x06>~\xfbdKd\x03*\xcb\x01\x1a\x91c\x1dA\x82Y\xdc\xb5AW\xb0K\xe6&\xd9\xc2\x8ak4Odd>\x85b\xe2\x1b7U\xc4\xcd\xe2\x8cOE\xd9\x0f\x84C\x83;\x0f)\xa4\xa7\x94l\xa8\x01\xc2\xf9f\xb6\xd6\xb5i\xcd\xdbT4\xcb\xefc\x11\x1e\xf4\x1eRAG\x91J\x99\xfa,}:\xfd\xb6\xdbMFX\xf2\xf7l\xde\x85\xdaB\x8e8\x80/+\xc6=5gXd\xb1\xa0F\xd2Q\xd5!\xbc.c\xc2+\x9dpW\x172A0\x81\x01\xd9|\x1fi8\xe0*\xbe\xf9}\xbf\xd1?\xcc\x1d\xdb\xcf\x10\xd4i\xa1\xc0T\x0c\xe1\xdb\x07\xa0g2DX\xf2\xb0\x9f\xa2W8a\x0f\xedT\x15\xa8\xb2\x9azN<\x00\xc6%\xa7\xafy\xbdWK\xc5[(uv\xbf\xd4U\x8f?\x0e\xbb.\x94\xd3\x1a\xce\xf4\x815\x8f\xa8\xf9q\x8e\xc7\xb2\t$A\xc7\xb0\xc8\xe9\x8d\x00:t#\xa3\xb6G\xd0\xf6\x88\x05\x8d\x01~\xc7\xe9D\xb5\x06C\x96~\xac\xa0\xff\xe5.\xedu\xa8\x14\xc0\xe0\x95:\x99bg\x8a\x07*\x85\t\xb0\xfd_\xa2/\x10\n\xff\xc3\xbb\x7f&T\xcd\xbc\xfeX\xc1]\x9c\xb8\xa7a\xf9w\x15V\xfe\x94d$\x90J\xf9\xc2\xe9(\xec\x90\x86\xb2\x95c\xa7\xa2\x166\xb6\x80\x82F\x161\xeeJ\xf5\xae\xb7\xb9\x84\x01\x8a\xde\xcc<a\xc5n\xfb\xa1\xb4O\xf0\x9fnI\x9e\x12\x01--\xfbl\xf9\x94\x00D\xc7\xaf\x8b\xd8a\x93r\tV:\xdc\x8b\xb3\xd0\x06\xa4\x9b\xc6,\xcd;-\xd6"\x15\x190{\xdc\x05\x83\x90\xec|\xeb\x00\xe4\'\xe8c\r\xf5\xff\xcf\xd8\xeaY!\xf8\xe1\xe4\x1d\xd6\xd0\xc9\xd2\x1b\xba\xc9\t\x14.Et\xfb\xbe\x15(\xb7\xa5\xa8\xec\xeam2\x9aJ\x19\xc1\x00!\x80C/\xd4&M(\xc9Hg\xb4~\xd1=\x12\xd28)\x82?\x1d-\x11\xa4X\x82\x80/\r\x7f\x9bW\xd6&\xf9h\x8a\x0fH\x00\xd3)\n\xf4\xf5\x86\x01\x11$\xdb\x8d,cS\x1d\xdc\xcb\xf7\xf6\x8f\x18mkp\xc7.\x98\x83`Wc\x01\xe5\xd3b\x80\xcc\xdfQ\xc1%\x1c\x9ec0\xff\xe9\x8b\xfc\xe2\xe5\xa1\xd1\xad\xc2\xf7\xd1\xbf\xa5\x14-\x8c9T[\x1a\x9e\x00\x89a\x05W\xcc\x1e\xe2o\xff\x1b\x7f\xc1\xd3\xcf\x1f\x98G\xdf\xe0s\x81\x02\xee\x87\xc6\x86)\xea\xb3<\x0b\xbc\xa3\xbe$.\x1f\n\xbe\xec\xbd\x7f\xa2\x15:c\x9d\xdd\xb9<\x98\x8f\xf7\x9azj\xa5\\\xaa\x92\xf7\xc4?\xb2\x85\xb8\x0e\xa6\xc9d\x08\x91\x8f6\xd2\x1f\xfc\x83e[\xba\xf5\x00\x19\xea4\xa5G\x10;\x8c\x10\x8b\xa4\xad\x95\xaf>SC"E\x99a\xc1\xd0\xc7Bt\xdf\xca\x17\x9f\x02\x03\x99\x00\xf4\xe4\x1fj\x95\x05E\xdb\xbc\xbe\x82\xa6"\xd9\xa1b\x0b+(\xdc\xb0\x19\xaf\xbf\x9dp\xe9\xcf\x17\xcc\xc8{Oi\xf2\x85\xa0\x11\x082>\\\xa5I\x90\x02\x1b\xb9\x16+\x82\xc3\xcb\xc1\x99\xa9\x910\xbf&\x14\xfa\x82\x95yY`\xbe\xa8H\x950W\'^\xb7\xd0\xba&wG$\x93\xcaS0\xfe\xbf\xa6\xd1"\x07\xa4\xa33v\xd5\x06\xd4\xfd\xb3\xe0\xc1\x12i\xd4l]\x84\x9e\x862S,\xacr\n\x90\xb0\'\xa2\xf0\xb0\xe2VP\xa3%\xd7\xff1V\x7f\xf2\x1f\xfc* \xb9<\x8e\r}\xc7f\xb7\xda\x08\xd5\x98:\xcbH\xa0\xa8.S<n\x1a\xf2\x84n}\x06\xe4*\x07\x9c\xab\xdf\xbb\x10S\x99\x96\xf3\xd1\xad\\\xf7\xf7\xeb<\x03\xcf\xc9\xc7\x13\x1b\x8e\xafj\xf8\x05\x04\x9b\xfe\x00\x81\x81\xaenq_\xf8\xa5\xc1\xa2k\xab\xe3\t\x90\xda4\xd8\xd4\x95\x96L$Tg\n\xe1\xd9}\x94\x04??\xa0\x8cv-\xe0\xab\xfbkb\x97\xe8\x84V\xe6\xbf\xb6P\xab\xc7\x87\x08\xb7@\x8c\xe4\x87H\x9d\xd6;\x84<\xa5\xb5i\xf0`f\xc1\x962AAN6\x94\xd7\xa6\x94l,\xce\xe57\xde\x8c\x8d\xf4\x901,\xa6yb\xe0\x8a\xa1\x80\xa6"'
|
|
|
|
|
|
2024-12-14 20:36:01.306440 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42770 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 459
|
|
id = 54908
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xefd5
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42770
|
|
seq = 959625658
|
|
ack = 3308739107
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0xb9a8
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\xc0\x8a\xe2\x84\x13\x01\x88\xe7\xb2Q\x8c\xf6\x96@\xae\x95dn\xe4V\xd4\xef\xbc\x16\xb7\x94\x82\xfa\xa3l\xae\xf8\x87\xa4\xc3\xd2B\x8d\xfa\xe2\xact^\x1d\xce\xd2\xaa\x7f\xb4]\xdft6w\xe9\x9c\xeb\xc6;\xce\x81h\xa9h8T`\x99\x1c\xeb\xc3\xb5(\x9cu\x90!\xfe\x8f}\xe3\x1eB\x06Ow\x0e\xfe\xd2\x1f\\\xde\xde2\xff\xda>q,l\xef\xdb\xd9t\xbavY\x1d\xf0\n\x98\xa8ng\t\xe7Fs$*c\x980\xb2\xcb\xe1ftUJ\xc3\xb0\x9d\x893\xd2\xa8\x0fe\xb8\x03\xb8\xefC\x10\x89N\xb3\xf8\x98\xe7G\x11ro\xf2{\x02\xd1\x84\xca\xa8\xc4\xbf<\x91U \xa8{\x81\xc0#c\x87\xa4-?\x10b\xec98\x95\n\xbc\xe3\xf3\xd8\xa3"\x89R "\xd6?\xbb*\x9cq\xd9T\xd7\xf4\xabN\x02=\xc3>7\x98>\x8dQ\x97\x00\x8b\x9a\x14\xc43l\xb4\x8e\x1a\xf36f\xe5\xdc\xe6\xe2\xa0\xf3o.\x92\x00:\xd4ltf\x9cK\xa0\x0f\xdf\'\xc6Fcjf\x08\xdf\xc6\x98\x1b\x90`\xdd\xad;\x99z\xcb:\x00\xfdI\xde;\xa8cp\x94\xe6\xd41X\x89\xe0C8&Ri\xcbjJ\xd6\xebZ\'\x0e\xa8+)_)\x91\xc8\xf6C8\xf4\xda\x05\x93!\xb7\xd7\xf2\x8d\xda\xac\x9aql\x18r\xcf\xa1>x\x14\xd3c\xfa\xc8m7\xcdnO\x9d\xf1\x05\xaa\x05\xad\xd26\x04\xd0b\xc2&w\xca\x12M\xd1>H\x95\xb7F\x14]\xd4Bk|z\xf4)\x8c;\xf59i\'\xdd\xff7\xf7\x9b1\xc8~\xbd=\xed\x05\xc6SQc\xa1R\xf6\x1b\xb4\xd6r{l\xfc\xf4\x11\x1dY\xe8R(Q\xdb\xcb\x87\xd0\x00k\xa3\xaf\xa6'
|
|
|
|
|
|
2024-12-14 20:36:01.369228 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28443
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308739107
|
|
ack = 959625658
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1024
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:01.432465 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28444
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308739107
|
|
ack = 959626077
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1022
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:01.453229 - Ether / IP / TCP 192.168.1.11:42770 > 2.18.188.21:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 433
|
|
id = 28445
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42770
|
|
dport = https
|
|
seq = 3308739107
|
|
ack = 959626077
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x817e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x01\x84\xd3\x18x\xe1(\\/'.\x9c\x9e\x93\xb9H\xbb\x07\t\xa8D\x1a\xf2\x81@\\\xb3\x13$]\x1d\xa0\xdc\xb3\xf3\xebV\xbaXL DU\x04j\xd643e\x92\xc4\xc2\xed&\\\xab=\xb7Z@ux:\xbbN\xf6\x0e\x9c\xe0\xdd\xfc\x01\x11\x92\x8a\x15\x90\xe0\xb1\x96\xd1jo\xa8Y\xcf\xda\xe6\x1d5\xa5N\xb4T\xca\xfc\x11\x11\xf0\xb9\xfb&n\xd2\xa6V\x8bi\xec\xa0\xc4\xc7m\xca\xecO\x0b\x02\xba\x87\x9f\x97\xfb\r0\xcei=\xfaM\xdf\x00\x9e \x06\xdbi[5\xa6O\x0c\x1dg\x12\xe1\x7f\xf6\xf1h\xc3y\x0f@M{C\xd1\xd0\xa7\xd8\x05\xa0fd\x9a\xe3\xf0kI\x12\x9b\x03\xed&p\xaa\x06\x96e\x8b\xed\x17\xa2\xf7\x14b34\x16\x91h\xb1\x06\x7fND\xa4g!x\xd0\x88LO\x15\xd9\xb1@u\xbd\x1f\x92m\xecO4\xd1\xcd\x19\x9d2\x9d\x86\xb3T5\xdf\x9e\x17\x1a\xbf\x9a\xc5\xbf\xa8yC\xdbA\xaeP\xf8D[\xa9F4\x80\xe336X\x0f\xf4C\x0b\x11,\xae\xfe\xcav\xf1\xb2\xd4k7m\xd12u\x84b%z\x95M\xbb\t\xdf\x86\xb3\x92\xc7)IhlX\xac\xa0`Wzc\xd4\\R\xb6\x7ff\xca\xae\xdb\xda\xb4:\x99\x91\x10\rceu\x1faTR\x7f `-z\x99T\xd9^\x81J}\xa7CT\x9bd\xf0\xe0BR\xf3\xb0\x0b^\xef\xb88g\xfa\x95\xc0\xf8\x19\xc3~\x959\xf8\xff\x83t4]a\x92\xf7F\xd2\xe1\xee\xb3\x16\xc8\x1d\x1fWv\xf2\x898\x8b\xb7\x9bX\x9b\x97\x1aF\x85\x13"
|
|
|
|
|
|
2024-12-14 20:36:01.496760 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42771 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1500
|
|
id = 37747
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x2ece
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42771
|
|
seq = 2767157651
|
|
ack = 4156348140
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0x17a5
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x07MX\x18BW5#\xaa_\xf1\xdf\x92"*\xedy\xd8\xe4\x86\xe7\xacr\x04SO\rm\xc3B/\xa0\x03P\xdf\xfe\x7f\x1alnq\x8c\x16\x8f\xbcL\x86\xb0\xb6+\x88\xb4$\xb3.\xca\x96\xd1[\xde\x91\xee?]\xfc\xfd\x83\xf5\x9c\x98/;\x0f\x97W\xaf3v\xf1\xd3\x86\x89\x1f\x92V\x90P9cCY\xf9\xa01uo\xbb@\xd8f\x19\xf3\xb7p<\x14\x1c\x17\xbb\xd1K\xea\x83\xa3_V \xa4\xc1\xfaj\xebu\x88>\x89\x85\xb8KU\x97@km\x88/#C\xa5\x95\tK\xfd\x84\xde\xa3\xef\xa2\xb6\x1c\xad\xbc\xfc\x80\xe9\xa6\xd9\x05\xbc\xcc\x1fOd\xcc\xfc\xbcZ\'\xd9do4*\xeb\x0e&r_z@\xc3\xff\x0e\x8aS\x85\xc1v"S\x84\xe1P]\xd8\xe4\x1d\xe2\x9eM"\x95T\x9f\xb0U\xcb\xe1\xe0:\xf4\x84\xa4F\xbf\xdf\xd0\xa43\xd6\xc9\xa1\xcc\x17\xce\xf9\xbf\x1e_\xf5\xc6\\\xb7=z\x17*\xdb\x7f\xf4\x98@\x89+\x8dc\xcf\xcd:\xb8\x98\x15z;FI\xa1)\x06k\x13\xcbG)\x10\x8dr.D\x86\xd0{/\x1c\x9e\xd2\xb1a)0\xe3,G\xcf\xff\xa4V\xc0\xdc\xb4\xf6\x8aSG\xbd\x0fk6lwPLv\x00;\x9d\x02\xfb\x17\xa8gs#}\xf5\x9a\xae\t\xd9_\x9e\x84\x06\x83\xe1\xdbC\x02\xba\r2\x9c\x1c0\xd5\xc5|74zo\x8a\xfb\x13/\xc6\x0b\x82\xfd\xa1\x15\x8b\xcb\xc0c,\xf3\x1d\xfaD\xd9\x14\xba\xb2j\x0f\x8f\xe5WN\x0b\'\xbd9\x9e\xecB\x84\x1ex\xeb\xca\xeb\xf9\x9e\x0c\xee\x1a\x9e\xf6~\x1b\xc1OT}\x9f\xbeH\x8c_\xbc\xa3\xccj =\x04d$\x89\xdfD\xa9\xad\xf5:\xe3\xafv4\xc0\x08\x06i\x82\x1e\xe7\xcfb\xf9\t\xae\xfe\x14\xbf\t8i)H\xe9\xcc\x17\x8b+S\xaa\xf7G\x0c\x1b\xa3\xc9yh~\xfa\xfc\xf6\xb4\x88\xd5\x04\xec_\xaf\x81\xe6\x14\xbc\x95zR\xe0\xba#\xb9|7!\xbb\xd2kyZ\xf2\xd9?\x1a6\x1fj\x99\x00\x0f\x81b\xd5\xe7M2\x96\xf3K\x1d\xbe*\xac\xb9N|!\x94\xed`1Q\xc1\xaa h\xc3\xf1}\\\x92\x83G\xe4?\xf3p\x93\x83kMM\xd2\xa2\x8d\xde\xb1\x91g\xc0)\x8fg\xea\xed\x8c\xa5Y\x0f\xd6%\x92@\xd4l\x06\xc9AB\xfc-\xd9\xf8\x15`G\x14\xef\xda\xd5\xbf\xcb\x111d\xdb\xd9\xdf\xfe\x80\xe4Y\x0b\x82\xc7h\x8c6\xc9i,\x0f\xe8r\xd0\xec!\x8c# %7+r\x12\x0e\x06`\xfd\xe1\x89jO\x90c\xb2\x1c\xe9\xbe\x92`\xe3\x84\x15\xed`\x08[\x00~\xa8\xc6\x9c\x04o\xc0\xa0\xc9|\xa7\xe7\x927C\xe1cl\xc1:h5>\\\x03I8:\xa6\tS[\xf1&RlV\xab`\xfc\x1d\x88\x05\x98\xe4\xdbM\xf4\xb6C\x88\xff\xb2y\xd6Swh}DW\x97l\x8di+\x89\xc0\xbc\xd0\xb7\xa6\x87\x98\x1c\x13\xc44?Op*D\xb5w0\xfd\\L\xb3\x8dk\x9f\x92k\xb9\xe0y\xe0\r\x19\x9d!\x1b$\xe1\xcd\xba\x12\x12\x9d\x19\xcb^< \x17\x1f\xdeN\xf8\x8f\xda*M\xcag#\xf6\xfa\x1b\t\x85\x8f>d\xa2w\xbc\x94\xdd\xe8\xb1\xccT\xec\x965I.1\x1e\x04 \xe9\xbf\xa9n(\x07\x1f\x1e=\xb1\xb7)n\xf6\xc0\xe3\xbe\x9dS\xfarE\xf9l\x8a\xfa\xe4\xa3\xa8\xe3H$_\x9dB,I\x1f=\xf1}\xddyb~.\xad\xb0\xf7\x0b:R\x99f5\xf5>\xcfrL>@y=\xb7G56Z\xf8\xad\xf5\x13\x81\xce\xce\xbdX\xd5\x18A<;\xcb\x96"Q\xcd\xc7\x90"\xaf\xe9\xd9gM\x19\xcf\xec*q\x9e\xd7\x1f\x85\xaa\x1b\xa2\x8aR\xf12\x1f\xbd\xf2\xfa\x83\xdf\xdc@\x96\xea\xd5\xd5\x9f\xc7\xcd\x16\x85E8\xde\x92\xb1:\xb8\x8f?\xc2>f\x1f\xfeQ\x1f\xf9\rs\xf8\x8a\xc3\xf5b\'\xca\xc6\x9c\x1e0\xe1J\xef\xb8\r\x97\xdf\x1b\xc7\xf0d\xf5\xd5\x1d\x7f\x14\x9e\xa33B\x05\xcf\t\xd4\x86G\xe88B\xcfI\xc6*E\xfe\xa2\xe0\x84\xb3\x00Lj\x1c\x0f\xd59B\xe1%\x8d\xee\xd1X\x1dM\x11\xdf\x87s9<P\x9e4\xd8\xf9,s|\x164\xba\xdb\x15+E\xa5\x8aE\xeef5\x07\xe6\r\xc9\xa54\x94Cx\'\xb2\x19\xde\xb9\xd2\xbc\xf9C\x0f\xc6\xd1aG\x90\xa0.\xdb\xb9\xd9*z\x88<D"e\xa4*\xb7\xcda$\xf71\x060\x84\x18\xe1\x05\x87|\xd5\xe3E\x12\xf38\xda(\x06\xabr.\x99>#G\x8d%\x1e\x14?\xc1\xe1`\x9d#\xf1\x9c\xdab\\KM3\x83\x9c\x1b\x8f\xa9\x120F\xde\x96\x9a\x1bP\xf2c]\x90\xadImE$Y(\xb5\xbf\x0e\xb3\xac#9\x80\xacc\x16D,D\xa3\xdfX\x0f\x7f\xe3\xa1a\x06\x0bJC\x13\xa2\x96\xc0\xe6\xaa7\x98\xb2\xde\x0c\xf7D\xd71\x89k\xc3\xba\x08oe\x89\xed|U\x19\xfd\xfb*\x84\xd8\x90j\x7fz\xf9\xf4\xab\xfa\xd1`d\x12\xfc=K\xf0\xe1\xe1\xbbT\x868@\x1a%\xa2\x1d\xca_\x07\xd5\x9aq:^\r\x1e\x82\xb1`<\xca\x8c#F\x92\xe8\xe760\x88\xd1\x9exQO\xb7\\P\x17\x84pcC\x9f?\xceo\xfb\xfc;\x92[\xf3\xee$\xea\xe6\xe6\xf8%4\xaf\x9f|\x82\xb9\xb4\xbf\n\x84r\x1d\xba\x8b\xbe\x07\xa5\x04\xc4\xd5x\xf3AJa\x86\x9f?\xc6\x97\xa1\xe12\xda\xd0\xe4L\xe5k\xb2\xd7\x16\xfdfx\xd4\xdd\x85\xfb\xcbUn\x06!\x89\xf5\x8bHJ\xb4~\r5\xa0\x80\xf67)\xff\xf4KH\x82nd\xaeh\x19[A\x03\xbb\xaa\t,3\xa1s%\x9d/\xff\xeb\xa6\x9f\x8f\xc6\xb8\xcbJGs_\xd3{\xca\x82\xebR\x8a\xef3y\xf4\x97\xbbF\xab\xf4\xf3\x02\xe5\xef\x9c\xdb\xb6\x1d\xd9^R\xdf\x18\x05A\xe5\x04j\x9f\xde\xac\x98\x04{k\x93`\xd9\x13\xb9\xf0\xb7\xf0\xcb\xf9\x10\xf7\xbb5\xbc\xc8xW:\xbc \x95v\\x\x8f\xd2\xd0J\xc5L\x85\xc5\xf2'
|
|
|
|
|
|
2024-12-14 20:36:01.581654 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42771 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 454
|
|
id = 37748
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0x32e3
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42771
|
|
seq = 2767159111
|
|
ack = 4156348140
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 501
|
|
chksum = 0x7ecd
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'K]f\xc4R\x93\xc1-\xb6+\xc2\xb06,z\xf1\xbc1\x81\xe0\x01_\xfa\xd1`K\xe3l#o\xb3\x17\xaa\xc0\xa1C~s\xa0\x93\xb7\xeb/~"\xfb3g\x17r\xd1d\x88\x1d\x97\x11q\xa9\x07\x97pi{]\x07\x83\xcf\x19\xc3W\xebw\xcf!\xb8\xf1\x88W\x14\x81\xba\xacSR\xb9GV\x8d]\x941\xceD^M\xd8\xe0\xee\xe4ig\xedZ\x03\xbb8a\x1bO%!(\xbc\x95K\x1a\xa2B\xa4^\x00\xcf])\x00\x1c\x1b\xeaa\x03F\xbe\xc5\x7f\xb3\xec\x96\tW]\x83\x1a\xd6C\xf4|<\xad\x82g\x0cB\t\xbc\x94\xea\xd5$\xd8\xcd\xd2T\xc0`\xdb\x8f\xae\x805\xfaL\xdc\xfa\xcdL\xd2T%\x11\x82K\x11!\xc4&j\xf9>S3\x85\x13bs\x9en\xcb\x049\xcf\x8f06H-g\xf0\x9f\x9a\xb0\xe8\xe5:\xcbaS^\xa0\xac\xd5T\xc6b\xff\xeb\xd8r\xf7\xdb\x9dB\xc5\x8cZX\xfb]4\xb3H\x11\x8aI\x87\xc6wpw\x0f\xc9\xd2\xee\x0bja\xfd\xe9b\xefm\xdfk\x88L\x8e"\x88\xefZ\x92\xa6\x12R@\x80\r0\x98\xc2\xb9\x8b p\x84\xc9\xdc\xb8\xf8(AP\x89\xf9\xc5#GJ\'\xc7!\x02\x97\xc1\xfd\xfc:kIEp\x8eW\x82rl\x89k\n+\x13\x86\x1d=\xf0\xeb\xd2\n\x1a\xcd.\x90;v\x86C,\xd54\xb4\xd2~o\xdb|+\x9c&\xe6\x0f\xb4>%-\x0e\x92\x01\xd5\x9bW\xa6p8\x1e"%\xf7\x89=\xc4q6\xa1\xfd:\t \x99BH}\x1f\x86\xb0\xf5p7\xc9:U0\xd1\x03\xc4\xcb\xea\xbdL,\x80\x95\xa8\xdbJ\x1d\xf4\x13\xe6\xd6\x91\xdd\xf4L~\xdd'
|
|
|
|
|
|
2024-12-14 20:36:01.649504 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28446
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156348140
|
|
ack = 2767159111
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1024
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:01.673769 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 28447
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156348140
|
|
ack = 2767159525
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 1022
|
|
chksum = 0x7ff5
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|
|
2024-12-14 20:36:01.697469 - Ether / IP / TCP 192.168.1.11:42771 > 2.18.188.21:https PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 433
|
|
id = 28448
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 2.18.188.21
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42771
|
|
dport = https
|
|
seq = 4156348140
|
|
ack = 2767159525
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 1022
|
|
chksum = 0x817e
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x01\x84k]\x99\xbb\xfb\xd4+^b\xd0nA\x95\xb0\x83n\x8f6\x14\x91\xd3C\xa4\xb7\r<b\xef\xd6G2\x86)\x9b\xa6\xb9\x04T\xce2\xe7\x8c1\xf1=\xeb,\xdc\xc89\xf8\xa2\x16\xec\x167<|\xe2\xf7\xedFm\xe4.\xedse*\xf6\xfd\x15\x84\xca\x05p\x15i\x8f\x1bk2\x07\xb1W\x96\xd4\x91h\x92\x8a\x11OG\x9d6\x04< \xed\x07\x1cQ\xdc\x9c\xceK\xa3T\x880\xd2\xe20\x1b\xf1":\xbb\xe3^=\x1e_\x8bdunL\x9b1\x10\xe5\xa0\xf3\r8\x98Z#Y\xdf\xde3\x8c\x91\xe6e\xa0\xe1\xbbE\xccF\xb1\xd4)\xa1Q\xce7%\xda\xeb\xd5\x10\x7f\x0b\xde\x0cF\xac#\xca\x89\xc3\x00$\x13\x9c\xb6kt\x1c\x0e\xe1\x1ey\x9c\xea\x00\xeaD\x82I*\xed{\x1b\\\xe1\x06\x90d\x1a?\xc6\xcb\x05}\xf5x\xaf~,\t7#o;\xcb6\x19P\xa1_\x96Q9\x9f\xb5\xb3\x05=R<KFx\xd7\xefu\xb07\xb6\xe6\xe5e+\xa4\x07\x9b\xd6\xfe\x08\x1d\x15\x1e\xf7Z\xbaY\xc4m-r\xe0A\x8fIA\xb8\xf6^\xf3\xb6b\x92\x98\xb8\xa3\xb5\x1b\x93m\xbeH\x872\xedME0#\xfe\xe1\xa1[\xd4?c`[\xad&W\xc28ne\x1aC\x06<\t@\xd7\xed\xdfo\xd5Au\xfe:$\xfa\xae\xa0\x8f-#\xa5\xea\xe3\x95HN#\xd2\xff\xcdMy!u\xfeVJ\xfapk\xffL\xd0^A\xc0\xd0\xd1\x18v=\x7f\xd0C\xa2A\x13Rf\x99\xd1_\xcb\x911\xb2K\xd6M\x7f\xe2\xc7\xed\x8d\x08\x85'
|
|
|
|
|
|
2024-12-14 20:36:01.705384 - Ether / IP / TCP 2.18.188.21:https > 192.168.1.11:42770 A / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 1500
|
|
id = 54909
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 51
|
|
proto = tcp
|
|
chksum = 0xebc3
|
|
src = 2.18.188.21
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42770
|
|
seq = 959626077
|
|
ack = 3308739500
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 501
|
|
chksum = 0x15
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b'\x17\x03\x03\x07L\xad\x03F\x1a\xc9\x9e\xdb\xc2\xa4\xf3\x85\xf85\x8d{\xdd C-m\xaa\xc1S\xb3$\xecX\xcf\r"\xb6]\xd2\xf0\xb1\xb3\xa7\xfa\n\xfd\x8d\x13\x1d)\x8a\xf1\x96VPvD\xe7\x06\xaf\x1c\xa1\x04\xd2\x07\xb3\\\xd8\xbf\\\x81\xcaL\xeaak"\xba\xc0\xcaN\x04h\x0b8K\xf9G\x1c\x8c$\x8c\xe0K\xa5\x81O\xd2p\xbb&\x0b\x8d:B\xe4\xdb\x8a\xef=\xa5\x12\xaa\x1d\xceX\x1cK\x0e\xe5\xda\xd8\x9b;H\xf2\xf7\xb8a+\x84\xd0\x9f(\xb0\xb8\xa4h\x8f]\x18\xdc\x0b\x97)\x83\xdf\x01\x0eOj\xdf\r\xf4\xee.\xf5\r\xfe\xb4f\x81\x00\x9c\xf4F\x9c\xaa\x18\xa6\xc34y\xc5\x85\x7f\x12<\xf8"\x95\xac\xb5\xa4\x94I.ma7\xb2\xb4\xe1^#t\x80O\xe4\x8f\xa2\x0cL\x7f^\x90_\x15\xc4\xe0yy\x02\xd9\xf7\x8b|\xac\xa8:\xcas.\xbd\xdd2\x8e\x07\xf6\x07\xb4\xfc\x9a\xc8&\xb6\xe8y\xc9\x90\xb4\xe23\x15|\x87\x94\xbae\xb6&z\xe30=\x8f\x0b\x1e\x0f\x97dSq\xcd\xaf\xeb\\/\xd9r\xed\x84e\xb1RN\xa9\xce\xd9J$\xbd\xe7A5\xc1u9u\xdd\xd8\x95\x8d;\xf7\xc3\xaf\xb1\x9bnc\xdf\x84W\x19u\xce\xd0\xe1\x84-\x949\x0c\xb9sp\x0f.\xca<\xf1\xcc%\xf1\xa6\xd8\xf3R\xdf\x91\xf0\xb4\x03o\x8f\xe5\xf4\xe9)l)\xf7Q\xb1\x8b;\xa6\xd7\xd4\xa3\x8b+5\xa1j\x1f\xc4\x86\xd4\xfc`\x17\xa7H)\xa1\xd3\xce\xa9\xc7\xfd\'\x0c\x86\xbft\x99[\xbd\xadx\x05e\xba0\xdf\xa0\xee\x85\xd9\xce\xf4\x8dTF\x0f\x9e\xcc\xe5\x7fut(\xcf\xf5i\x86\xb7\x15\xc2\xfd\xb2\x1b;\x83\xbb\xe3\'Z6\xb6\xd1\x0f\xf4F\xba\xf37\xaa\x1a\x96;\xe3oY.\xa3\x82\xb3\x05\xfa\xc5\x12|\xbfss\xff}&[\xe0\x80X\x1df8\x97\x9aa\x12w\xaa\x02<\xf5\xda\x84\xc5\xa2\xc8\xe9\xa3\x9d9\xb7\xf7\x9f\xaeM\x01\xa8\xb3V\x1e#\x91g\x17\xd6\xee\x1f\xf6d\xea\x02H\xb6J\xa4\xf4z\x8c\x85S&\xe9_.\xb16txpS\x05\xf9\x9a\x7fv\x15(\x01\xa3\x9d0\xe7\xbf\xc07\xd4\x80g\xbd\xa0,\xcc\xb8!\xf0Q\xac\xea \xb0G\x1e%\x96\x04\x95O\x1d\xc0\x06yu\xd5^zx\x1c6\xe9\x15\xaa`/k\xbf\x13\xb60\xcfQ\xfe\xd3\x0e\x8a\x9f0\x98\xaa\x1e\xb0\xdcl&\xec\xc8D>\xff\xc0R\x0e\t\xe9\x1d0\xe9H\xcb\t\x97\x83Y\xf1\xe3\xd3Z\xa7!B\xc2\x98\x85\x9c\x19\xee\xad\xa3\xbf\xe8s\x98\xf3x\xc3$\xa8\xe0\xa8\xa9\xe9N\r\xfeG!\xe1=\xa1P\xad\xf8\'\xad\xdb\xe1]\xad\xecU\x01\xa5\xaf\x9dH\x03E\t\x89 \xb0\xca\xa6\xb4\x05\xcc\xcd/\x1e\xdb\xd0\xa1\xae\xa9R\xd8\x9c\xf8\xad\xf5\xf7\xbf\xc8l\xca\xe7\x0c\x1f\\\xf5\x82\x86\xd4\x83cfk\x9ec"X}da\x0e\xf6*\xeeC\x10\xdc\xdcj\xf5Rcp\x0c\x91CM\xf2\xc8^h\xf1,\x8f\xf1\x9cL"\xf6@\nvK\x8e\x94U\x85{\xc8b\xf2\x8a\xfe\\.\xa6\x06p\r\x9a[~\'#\xf9\x01T\xc2\xe8\x02\xd83\x84\x14T}\x17\x0f\xc9\x0e\x19\x0c\xfdj"L\x88Q\x8c\x16\x94\xfa\xeb\xef\xd7\xb0\xa3\xc5\x02`\x81\xb6-t"\xa9\xa6\xa5~\xa0F \x83\xf6\xa2\xf8Xm;N\xbdH\x87\xde\xf6B%\xca\xc7M\xe6\x9d:rg\x1dut\x94&\x16\xe3m[1\xca\xfepIC\xd3\xf3\xbf\x91\xf89\x01\xc7#S\xd1\x01w#\xbf\x97\x98\x9e\x00F\xa6\xf1\x1e\x08\xa63Gz\xf6\x07js\x9fV\xa5o\xba\x84=y\xc6\xd7\x01\x12Y{@\x93c\xc9\x13\xf8p\xacf\x84\xf9\xcf\x85\xc4\xfe\xb8Y\xc2\xc8.\x8e,\x7fzQ\nmm\xbe\xdes\x17\xf5=S\x96+\xc3%\xe2e\xbd\x8a\x15lp\x076\x0f-\x98\xdfX\x1dI\xb4\x1e,\x06\x90\xa4\x98*\x9a\xd2\xca)x\xa9\xf4\x8a-\x1a\x9d\x0f\x98\xe6CSG\x8e\xa3_I\x86\xbcR\x96y\x0by\xf72w\x07\x88\xee\x0f\xfd}m\xe4\xf3\xb4L\xd6P(}tnw9Y\x0c\xaa\xb8\xff_\xab\r\xb9\xfbce\xeb\x15\x12\x85E\xea\xcf\xed\x11h\xcb\xe4\x98@\xc1\xba\xc3\xf3*\r`_3)+\x9c\xc2\xf2\xd2\xf2F2\x10gV\x97l\xba\xa1\x07vq#6\xef\xe7\xc8q\xf3\xa8\x81\x80\x87IPF\x93\x0b\x8c\x83\x18Ps\xfc\xefI\xd2\xc8a1\xc1\x90\xe8\xa3\xc1Z\x1d\x0f\xee\xf3Bu\xa7\x99\xdfC\xcc\t2\x9c\xf1:\x8d\xda6\x1a(\x94\x12\x19\xd9\x1e@z\x1a\xec\xf1R\x02p\xc2\xd7\x910\xa7\xe9\x80\x11#\xec\x1b\xd3i@\xb1V\xdb\xd9FUQ\xb7\x87C\xdc\x19\x07\xfc\x16g\x1d\xee\xc5\xac]\x8b%\x05\xbb\xc8\x87(T"\xe4\xd4\xecs\xf3\x07\x93\x11\xe0\xec,\xfa\x0b\xe8h\x84\x90\xe7\x15Y\xceA\x8e7a\x981\x9d\xdd\x00\xef3s\xca\x88\x08\x12M\xfby6\xfc\xf7\xb8 \xf6\xa4\xf0\xd6B\xddk9\x94\xec\xf7\x04\xd9\x008\xe4\xd8W\x1c\xb3)\xf3\xdd\x99a)C7\x14\xb2|\xd9\x8a\t\xcd\t}\'\xd2\r\xc7\'\xa9\x1a\xd7l\x06\x88\xb2F\x8a\x7flub\xc4Y@\xe9z\xd6:!\xdc\xc7\xde\x84\x9d\xf9\x88\x0b\xf5\x15c\x8di\xaa\x1c\x82\xc0\xa3\x82\xfa\xf5\x0c\xa0W\x9e\xdc\x1dx\xff\x7f\xd9\x03d\x98\xfb"\\\xd5\x80T\x9f\xf6\xd2|\xf050>B\xe0\x08\xce\xb2H\xe4E\xd1\x9b\xa6\x16L\x82\xd3\xedxa/\xcf@\xff\'B\xa4\x80\xb2\x08k\xa9s\x8f\xfd\xcb<\xe1\xeeR\xeco\xa3&h\x93T\xdf\xddD\x803\xce05\xce\xfa\xa8s`#\xa2\xb0\'9u2\r\xef5\xd4\x08\xd0\xa6\xb9\xde\x9b\x9dj\r\x8c#\xb2\xb0\xae\x1a_\x03\xee\x94\xdf\x93\xf0\xfb\xae\n\x83\xae\xfb\x81\x8d\xa1\xd3\x8d\x00\xb1\x06\x04\x8d\xe0\x96\xd0\x10\xd6\xa7m\x1f\x19\xfa\x06h\x89a\xd1\xd3\xa7H\xe7\xec\x80\x98\xe9\xa7'
|
|
|
|
|
|
2024-12-14 20:36:02.169513 - Ether / IP / UDP / DNS Qry b'1.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 70
|
|
id = 34273
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63889
|
|
dport = domain
|
|
len = 50
|
|
chksum = 0x83a0
|
|
###[ DNS ]###
|
|
id = 14652
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:02.186889 - Ether / IP / UDP / DNS Qry b'27.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34274
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63890
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 14653
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:02.202672 - Ether / IP / UDP / DNS Qry b'28.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34275
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63889
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 14654
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:02.222181 - Ether / IP / UDP / DNS Qry b'62.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34276
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63890
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 14655
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:02.225155 - Ether / IP / UDP / DNS Ans b'liveboxfibra.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 96
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb730
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63889
|
|
len = 76
|
|
chksum = 0x338
|
|
###[ DNS ]###
|
|
id = 14652
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'1.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'1.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'liveboxfibra.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:02.227483 - Ether / IP / UDP / DNS Ans b'repetidorwifi6-DCC0.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 109
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb723
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63890
|
|
len = 89
|
|
chksum = 0x95af
|
|
###[ DNS ]###
|
|
id = 14653
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'27.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'27.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'repetidorwifi6-DCC0.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:02.229160 - Ether / IP / UDP / DNS Ans b'Redmi-Note-11-Pro-5G.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 110
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb722
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63889
|
|
len = 90
|
|
chksum = 0xfbd4
|
|
###[ DNS ]###
|
|
id = 14654
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'28.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'28.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'Redmi-Note-11-Pro-5G.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:02.230864 - Ether / IP / UDP / DNS Ans name-error
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb749
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63890
|
|
len = 51
|
|
chksum = 0x49df
|
|
###[ DNS ]###
|
|
id = 14655
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = name-error
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'62.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:02.232855 - Ether / IP / UDP / DNS Qry b'11.1.168.192.in-addr.arpa.'
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 71
|
|
id = 34277
|
|
flags =
|
|
frag = 0
|
|
ttl = 128
|
|
proto = udp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 192.168.1.1
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = 63891
|
|
dport = domain
|
|
len = 51
|
|
chksum = 0x83a1
|
|
###[ DNS ]###
|
|
id = 14656
|
|
qr = 0
|
|
opcode = QUERY
|
|
aa = 0
|
|
tc = 0
|
|
rd = 1
|
|
ra = 0
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 0
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:02.236381 - Ether / IP / UDP / DNS Ans b'KevinOlarte.home.'
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 101
|
|
id = 0
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 64
|
|
proto = udp
|
|
chksum = 0xb72b
|
|
src = 192.168.1.1
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ UDP ]###
|
|
sport = domain
|
|
dport = 63891
|
|
len = 81
|
|
chksum = 0xd10f
|
|
###[ DNS ]###
|
|
id = 14656
|
|
qr = 1
|
|
opcode = QUERY
|
|
aa = 1
|
|
tc = 0
|
|
rd = 1
|
|
ra = 1
|
|
z = 0
|
|
ad = 0
|
|
cd = 0
|
|
rcode = ok
|
|
qdcount = 1
|
|
ancount = 1
|
|
nscount = 0
|
|
arcount = 0
|
|
\qd \
|
|
|###[ DNS Question Record ]###
|
|
| qname = b'11.1.168.192.in-addr.arpa.'
|
|
| qtype = PTR
|
|
| unicastresponse= 0
|
|
| qclass = IN
|
|
\an \
|
|
|###[ DNS Resource Record ]###
|
|
| rrname = b'11.1.168.192.in-addr.arpa.'
|
|
| type = PTR
|
|
| cacheflush= 0
|
|
| rclass = IN
|
|
| ttl = 0
|
|
| rdlen = None
|
|
| rdata = b'KevinOlarte.home.'
|
|
\ns \
|
|
\ar \
|
|
|
|
|
|
2024-12-14 20:36:03.669793 - Ether / IP / TCP 162.159.133.234:https > 192.168.1.11:42680 PA / Raw
|
|
###[ Ethernet ]###
|
|
dst = 6c:2f:80:f3:9a:99
|
|
src = ec:f4:51:54:2f:0c
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 417
|
|
id = 26772
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 54
|
|
proto = tcp
|
|
chksum = 0xf085
|
|
src = 162.159.133.234
|
|
dst = 192.168.1.11
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = https
|
|
dport = 42680
|
|
seq = 995231773
|
|
ack = 212489243
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = PA
|
|
window = 8
|
|
chksum = 0xad6f
|
|
urgptr = 0
|
|
options = []
|
|
###[ Raw ]###
|
|
load = b"\x17\x03\x03\x01tG;\xb0\xe7\x8d\xa4\xb5>\x1f\xd1\xca\x9a\xc4\x92\x8e\xc6\xa3\xa4w>\xc4\xd8\xdb\x06Pp\xdb\xa1\xa7\xa2\xe0D\xf7B\xf7\x08>\xc7\xbc\xe7\xb0\xdf\xf5\x833J\x8bbts\xf3n\x9b\xe0\xa3\xbeHQ\xf3\xd2\xb4Mg8t\xd7\x08\x14\xc1\xfaW\xcd\x8f\xab\xa7\xc9\x8b\x1c\xb4\x16\x15\xa7,\xd4\xfa\xe1\xf1Px\xde@\xd9\x9f\xe0n\xf5\t\x8c\xc5EP\x06K\xac#0\xd1\x8aj)@\x06\xcc\xcc\xb8\x85\xaam\xc7-\x99\xc0\xde\x82\xec\x8f\xf9\xd9B\xd9\x81\x0bG\xd3.\x02\x1e\x1a\x14]\xfeWa\x16*.3\x8f\\\x01h\x8d\xf9f\xad\xd5*\xe0\xe3W\xaa(\xaf\x12&\xd3\x10\x94\xec\x00\x9a\xbe\xb6\xd1\x05\xf5\x10\xdb\x94\xc5`M\x1c}Z\x08\xbd\xc2\xe5\xcdw\xa7\xd7\xac90`Mk\xc9b\x06b\xa4[K\x0e\xcb\x901`P6v\xc3\xdd\x87\x921\xb4\x84V\xfa\xfcS',\x9d-|8\x86\x19\xd0Q\xd1\xf7\xedy\x914x.\xc6_e\x83\x86\xdb\x93\xe5\xdb\xaf\x80Dr\xc8\xce\x87\\A\x8a\x9c[\xfe z\x87\x94\xe6(A\x17\xc2}\x02\xd5\xc4\x15\x01r\x97\x18_\xe7X\xa4\x8b\xe3\x0bJ\xcbZ\x87\xb3\xe8\xa0\xbb\x96\xca\xbf\xdb\x82\xaa\xb2\xa0\xc5\xd0\xd8\x936T6O8\xac\xfb\xd7\x8c\xacK\xc9\xae\xff\xf6\xe4\x98)\r5\xe4\xf4y\xd0c< lH\x87\xc1\xd6t\xa2jX\x1f/\x8e?\xf0sW6g\xcb\xe7{\xc4\xf5\x9e0\xb6\xdb/\xc0\x93\x01zL.S"
|
|
|
|
|
|
2024-12-14 20:36:03.710090 - Ether / IP / TCP 192.168.1.11:42680 > 162.159.133.234:https A
|
|
###[ Ethernet ]###
|
|
dst = ec:f4:51:54:2f:0c
|
|
src = 6c:2f:80:f3:9a:99
|
|
type = IPv4
|
|
###[ IP ]###
|
|
version = 4
|
|
ihl = 5
|
|
tos = 0x0
|
|
len = 40
|
|
id = 37110
|
|
flags = DF
|
|
frag = 0
|
|
ttl = 128
|
|
proto = tcp
|
|
chksum = 0x0
|
|
src = 192.168.1.11
|
|
dst = 162.159.133.234
|
|
\options \
|
|
###[ TCP ]###
|
|
sport = 42680
|
|
dport = https
|
|
seq = 212489243
|
|
ack = 995232150
|
|
dataofs = 5
|
|
reserved = 0
|
|
flags = A
|
|
window = 509
|
|
chksum = 0xea57
|
|
urgptr = 0
|
|
options = []
|
|
|
|
|