1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
| 00:06:50.852967 IP machine.local.45991 > 192.168.9.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
00:06:50.857126 IP machine.local.57557 > 192.168.1.254.domain: 21722+ PTR? 255.9.168.192.in-addr.arpa. (44)
00:06:50.879368 IP 192.168.1.254.domain > machine.local.57557: 21722 NXDomain* 0/1/0 (94)
00:06:50.981548 IP machine.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 255.9.168.192.in-addr.arpa. (44)
00:06:51.129572 IP machine.local.45991 > 192.168.9.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
00:06:51.404574 IP machine.local.45991 > 192.168.9.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
00:06:51.682268 IP machine.local.47651 > 192.168.1.254.domain: 30213+ A? nu.nl. (23)
00:06:51.704245 IP 192.168.1.254.domain > machine.local.47651: 30213 2/3/3 A 62.69.184.230, A[|domain]
00:06:51.704575 IP machine.local.42710 > 62.69.184.230.www: S 2358109473:2358109473(0) win 5840 <mss 1460,sackOK,timestamp 100474 0,nop,wscale 7>
00:06:51.729988 IP 62.69.184.230.www > machine.local.42710: S 2282370406:2282370406(0) ack 2358109474 win 57344 <mss 1460,nop,wscale 0,nop,nop,timestamp 362470012 100474,nop,nop,sackOK>
00:06:51.730051 IP machine.local.42710 > 62.69.184.230.www: . ack 1 win 46 <nop,nop,timestamp 100481 362470012>
00:06:51.730176 IP machine.local.42710 > 62.69.184.230.www: P 1:549(548) ack 1 win 46 <nop,nop,timestamp 100481 362470012>
00:06:51.758477 IP 62.69.184.230.www > machine.local.42710: P 1:489(488) ack 549 win 56796 <nop,nop,timestamp 362470015 100481>
00:06:51.758508 IP machine.local.42710 > 62.69.184.230.www: . ack 489 win 54 <nop,nop,timestamp 100488 362470015>
00:06:51.759470 IP 62.69.184.230.www > machine.local.42710: . 489:1937(1448) ack 549 win 56796 <nop,nop,timestamp 362470015 100481>
00:06:51.759482 IP machine.local.42710 > 62.69.184.230.www: . ack 1937 win 77 <nop,nop,timestamp 100488 362470015>
00:06:51.760468 IP 62.69.184.230.www > machine.local.42710: . 1937:3385(1448) ack 549 win 56796 <nop,nop,timestamp 362470015 100481>
00:06:51.760478 IP machine.local.42710 > 62.69.184.230.www: . ack 3385 win 100 <nop,nop,timestamp 100489 362470015>
00:06:51.782896 IP machine.local.42711 > 62.69.184.230.www: S 2354839147:2354839147(0) win 5840 <mss 1460,sackOK,timestamp 100494 0,nop,wscale 7>
00:06:51.783710 IP 62.69.184.230.www > machine.local.42710: . 3385:4833(1448) ack 549 win 56796 <nop,nop,timestamp 362470017 100488>
00:06:51.783730 IP machine.local.42710 > 62.69.184.230.www: . ack 4833 win 122 <nop,nop,timestamp 100494 362470017>
00:06:51.784208 IP 62.69.184.230.www > machine.local.42710: . 4833:6281(1448) ack 549 win 56796 <nop,nop,timestamp 362470017 100488>
00:06:51.784219 IP machine.local.42710 > 62.69.184.230.www: . ack 6281 win 145 <nop,nop,timestamp 100494 362470017>
00:06:51.787210 IP 62.69.184.230.www > machine.local.42710: . 6281:7729(1448) ack 549 win 56796 <nop,nop,timestamp 362470017 100488>
00:06:51.787235 IP machine.local.42710 > 62.69.184.230.www: . ack 7729 win 168 <nop,nop,timestamp 100495 362470017>
00:06:51.787458 IP 62.69.184.230.www > machine.local.42710: . 7729:9177(1448) ack 549 win 56796 <nop,nop,timestamp 362470017 100488>
00:06:51.787475 IP machine.local.42710 > 62.69.184.230.www: . ack 9177 win 190 <nop,nop,timestamp 100495 362470017>
00:06:51.787706 IP 62.69.184.230.www > machine.local.42710: P 9177:10351(1174) ack 549 win 56796 <nop,nop,timestamp 362470017 100489>
00:06:51.787720 IP machine.local.42710 > 62.69.184.230.www: . ack 10351 win 213 <nop,nop,timestamp 100495 362470017>
00:06:51.791920 IP machine.local.42710 > 62.69.184.230.www: P 549:1071(522) ack 10351 win 213 <nop,nop,timestamp 100496 362470017>
00:06:51.807707 IP 62.69.184.230.www > machine.local.42711: S 571261335:571261335(0) ack 2354839148 win 57344 <mss 1460,nop,wscale 0,nop,nop,timestamp 362470020 100494,nop,nop,sackOK>
00:06:51.807761 IP machine.local.42711 > 62.69.184.230.www: . ack 1 win 46 <nop,nop,timestamp 100500 362470020>
00:06:51.808029 IP machine.local.42711 > 62.69.184.230.www: P 1:536(535) ack 1 win 46 <nop,nop,timestamp 100500 362470020>
00:06:51.820449 IP 62.69.184.230.www > machine.local.42710: P 10351:10853(502) ack 1071 win 56274 <nop,nop,timestamp 362470021 100496>
00:06:51.821191 IP 62.69.184.230.www > machine.local.42710: P 10853:11643(790) ack 1071 win 56274 <nop,nop,timestamp 362470021 100496>
00:06:51.821237 IP machine.local.42710 > 62.69.184.230.www: . ack 11643 win 258 <nop,nop,timestamp 100504 362470021>
00:06:51.836694 IP 62.69.184.230.www > machine.local.42711: P 1:488(487) ack 536 win 56809 <nop,nop,timestamp 362470022 100500>
00:06:51.836756 IP machine.local.42711 > 62.69.184.230.www: . ack 488 win 54 <nop,nop,timestamp 100508 362470022>
00:06:51.837935 IP 62.69.184.230.www > machine.local.42711: . 488:1936(1448) ack 536 win 56809 <nop,nop,timestamp 362470022 100500>
00:06:51.837949 IP machine.local.42711 > 62.69.184.230.www: . ack 1936 win 77 <nop,nop,timestamp 100508 362470022>
00:06:51.838434 IP 62.69.184.230.www > machine.local.42711: P 1936:2998(1062) ack 536 win 56809 <nop,nop,timestamp 362470022 100500>
00:06:51.838448 IP machine.local.42711 > 62.69.184.230.www: . ack 2998 win 100 <nop,nop,timestamp 100508 362470022>
00:06:51.859175 IP machine.local.42710 > 62.69.184.230.www: P 1071:1591(520) ack 11643 win 258 <nop,nop,timestamp 100513 362470021>
00:06:51.887670 IP 62.69.184.230.www > machine.local.42710: P 11643:12145(502) ack 1591 win 55754 <nop,nop,timestamp 362470027 100513>
00:06:51.887715 IP 62.69.184.230.www > machine.local.42710: P 12145:12275(130) ack 1591 win 55754 <nop,nop,timestamp 362470027 100513>
00:06:51.888637 IP machine.local.42710 > 62.69.184.230.www: . ack 12275 win 303 <nop,nop,timestamp 100520 362470027>
00:06:51.892540 IP machine.local.42711 > 62.69.184.230.www: P 536:1062(526) ack 2998 win 100 <nop,nop,timestamp 100521 362470022>
00:06:51.920659 IP 62.69.184.230.www > machine.local.42711: P 2998:3500(502) ack 1062 win 56283 <nop,nop,timestamp 362470031 100521>
00:06:51.920707 IP machine.local.42711 > 62.69.184.230.www: . ack 3500 win 122 <nop,nop,timestamp 100529 362470031>
00:06:51.921145 IP 62.69.184.230.www > machine.local.42711: P 3500:4422(922) ack 1062 win 56283 <nop,nop,timestamp 362470031 100521>
00:06:51.921156 IP machine.local.42711 > 62.69.184.230.www: . ack 4422 win 145 <nop,nop,timestamp 100529 362470031>
00:06:51.927557 IP machine.local.42710 > 62.69.184.230.www: P 1591:2151(560) ack 12275 win 303 <nop,nop,timestamp 100530 362470027>
00:06:51.928937 IP machine.local.42711 > 62.69.184.230.www: P 1062:1627(565) ack 4422 win 145 <nop,nop,timestamp 100530 362470031>
00:06:51.930399 IP machine.local.42712 > 62.69.184.230.www: S 2348208605:2348208605(0) win 5840 <mss 1460,sackOK,timestamp 100531 0,nop,wscale 7>
00:06:51.931803 IP machine.local.42713 > 62.69.184.230.www: S 2349008011:2349008011(0) win 5840 <mss 1460,sackOK,timestamp 100531 0,nop,wscale 7>
00:06:51.933302 IP machine.local.42714 > 62.69.184.230.www: S 2362020854:2362020854(0) win 5840 <mss 1460,sackOK,timestamp 100531 0,nop,wscale 7>
00:06:51.936840 IP machine.local.46050 > 192.168.9.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
00:06:51.956387 IP 62.69.184.230.www > machine.local.42710: P 12275:12700(425) ack 2151 win 55194 <nop,nop,timestamp 362470034 100530>
00:06:51.956630 IP 62.69.184.230.www > machine.local.42710: P 12700:13022(322) ack 2151 win 55194 <nop,nop,timestamp 362470034 100530>
00:06:51.956668 IP machine.local.42710 > 62.69.184.230.www: . ack 13022 win 349 <nop,nop,timestamp 100537 362470034>
00:06:51.962378 IP 62.69.184.230.www > machine.local.42711: P 4422:4847(425) ack 1627 win 55718 <nop,nop,timestamp 362470035 100530>
00:06:51.962629 IP 62.69.184.230.www > machine.local.42711: P 4847:4980(133) ack 1627 win 55718 <nop,nop,timestamp 362470035 100530>
00:06:51.962666 IP machine.local.42711 > 62.69.184.230.www: . ack 4980 win 190 <nop,nop,timestamp 100539 362470035>
00:06:51.963378 IP 62.69.184.230.www > machine.local.42712: S 2976428021:2976428021(0) ack 2348208606 win 57344 <mss 1460,nop,wscale 0,nop,nop,timestamp 362470035 100531,nop,nop,sackOK>
00:06:51.963400 IP machine.local.42712 > 62.69.184.230.www: . ack 1 win 46 <nop,nop,timestamp 100539 362470035>
00:06:51.963457 IP machine.local.42712 > 62.69.184.230.www: P 1:561(560) ack 1 win 46 <nop,nop,timestamp 100539 362470035>
00:06:51.963629 IP 62.69.184.230.www > machine.local.42713: S 63585268:63585268(0) ack 2349008012 win 57344 <mss 1460,nop,wscale 0,nop,nop,timestamp 362470035 100531,nop,nop,sackOK>
00:06:51.963644 IP machine.local.42713 > 62.69.184.230.www: . ack 1 win 46 <nop,nop,timestamp 100539 362470035>
00:06:51.963688 IP machine.local.42713 > 62.69.184.230.www: P 1:569(568) ack 1 win 46 <nop,nop,timestamp 100539 362470035>
00:06:51.964377 IP 62.69.184.230.www > machine.local.42714: S 1272769817:1272769817(0) ack 2362020855 win 57344 <mss 1460,nop,wscale 0,nop,nop,timestamp 362470035 100531,nop,nop,sackOK>
00:06:51.964393 IP machine.local.42714 > 62.69.184.230.www: . ack 1 win 46 <nop,nop,timestamp 100539 362470035>
00:06:51.964433 IP machine.local.42714 > 62.69.184.230.www: P 1:564(563) ack 1 win 46 <nop,nop,timestamp 100539 362470035>
00:06:51.985476 IP machine.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 255.9.168.192.in-addr.arpa. (44)
00:06:51.994368 IP 62.69.184.230.www > machine.local.42712: P 1:426(425) ack 561 win 56784 <nop,nop,timestamp 362470038 100539>
00:06:51.994420 IP machine.local.42712 > 62.69.184.230.www: . ack 426 win 54 <nop,nop,timestamp 100547 362470038>
00:06:51.994615 IP 62.69.184.230.www > machine.local.42712: P 426:965(539) ack 561 win 56784 <nop,nop,timestamp 362470038 100539>
00:06:51.994635 IP machine.local.42712 > 62.69.184.230.www: . ack 965 win 63 <nop,nop,timestamp 100547 362470038>
00:06:51.999362 IP 62.69.184.230.www > machine.local.42713: P 1:426(425) ack 569 win 56776 <nop,nop,timestamp 362470039 100539>
00:06:51.999380 IP machine.local.42713 > 62.69.184.230.www: . ack 426 win 54 <nop,nop,timestamp 100548 362470039>
00:06:51.999616 IP 62.69.184.230.www > machine.local.42713: P 426:545(119) ack 569 win 56776 <nop,nop,timestamp 362470039 100539>
00:06:51.999627 IP machine.local.42713 > 62.69.184.230.www: . ack 545 win 54 <nop,nop,timestamp 100548 362470039>
00:06:52.005610 IP 62.69.184.230.www > machine.local.42714: P 1:427(426) ack 564 win 56781 <nop,nop,timestamp 362470039 100539>
00:06:52.005629 IP machine.local.42714 > 62.69.184.230.www: . ack 427 win 54 <nop,nop,timestamp 100550 362470039>
00:06:52.006357 IP 62.69.184.230.www > machine.local.42714: P 427:1589(1162) ack 564 win 56781 <nop,nop,timestamp 362470039 100539>
00:06:52.006372 IP machine.local.42714 > 62.69.184.230.www: . ack 1589 win 73 <nop,nop,timestamp 100550 362470039>
00:06:52.209620 IP machine.local.46050 > 192.168.9.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
00:06:52.484555 IP machine.local.46050 > 192.168.9.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
00:06:52.760604 IP machine.local.40484 > 192.168.1.254.domain: 30605+ A? ad.nl.doubleclick.net. (39)
00:06:52.783520 IP 192.168.1.254.domain > machine.local.40484: 30605 3/4/4 CNAME[|domain]
00:06:52.783868 IP machine.local.54749 > frmegaadvip1.doubleclick.net.www: S 2373341785:2373341785(0) win 5840 <mss 1460,sackOK,timestamp 100744 0,nop,wscale 7>
00:06:52.822999 IP frmegaadvip1.doubleclick.net.www > machine.local.54749: S 2085106215:2085106215(0) ack 2373341786 win 16384 <mss 1460,nop,wscale 0,nop,nop,timestamp 0 0,nop,nop,sackOK>
00:06:52.823029 IP machine.local.54749 > frmegaadvip1.doubleclick.net.www: . ack 1 win 46 <nop,nop,timestamp 100754 0>
00:06:52.823096 IP machine.local.54749 > frmegaadvip1.doubleclick.net.www: P 1:420(419) ack 1 win 46 <nop,nop,timestamp 100754 0>
00:06:52.864981 IP frmegaadvip1.doubleclick.net.www > machine.local.54749: FP 1:264(263) ack 420 win 65116 <nop,nop,timestamp 793377 100754>
00:06:52.865089 IP machine.local.54749 > frmegaadvip1.doubleclick.net.www: F 420:420(0) ack 265 win 54 <nop,nop,timestamp 100765 793377>
00:06:52.879181 IP machine.local.42710 > 62.69.184.230.www: P 2151:2707(556) ack 13022 win 349 <nop,nop,timestamp 100768 362470034>
00:06:52.879928 IP machine.local.42711 > 62.69.184.230.www: P 1627:2184(557) ack 4980 win 190 <nop,nop,timestamp 100768 362470035>
00:06:52.883169 IP machine.local.54750 > frmegaadvip1.doubleclick.net.www: S 2371928027:2371928027(0) win 5840 <mss 1460,sackOK,timestamp 100769 0,nop,wscale 7>
00:06:52.884971 IP machine.local.42712 > 62.69.184.230.www: P 561:1129(568) ack 965 win 63 <nop,nop,timestamp 100769 362470038>
00:06:52.903215 IP frmegaadvip1.doubleclick.net.www > machine.local.54749: . ack 421 win 65116 <nop,nop,timestamp 793378 100765>
00:06:52.908456 IP 62.69.184.230.www > machine.local.42710: P 13022:13446(424) ack 2707 win 54638 <nop,nop,timestamp 362470129 100768>
00:06:52.908706 IP 62.69.184.230.www > machine.local.42710: P 13446:13491(45) ack 2707 win 54638 <nop,nop,timestamp 362470129 100768>
00:06:52.908735 IP machine.local.42710 > 62.69.184.230.www: . ack 13491 win 371 <nop,nop,timestamp 100775 362470129>
00:06:52.913954 IP 62.69.184.230.www > machine.local.42711: P 4980:5405(425) ack 2184 win 55161 <nop,nop,timestamp 362470130 100768>
00:06:52.914205 IP 62.69.184.230.www > machine.local.42711: P 5405:5568(163) ack 2184 win 55161 <nop,nop,timestamp 362470130 100768>
00:06:52.914225 IP machine.local.42711 > 62.69.184.230.www: . ack 5568 win 235 <nop,nop,timestamp 100777 362470130>
00:06:52.919451 IP 62.69.184.230.www > machine.local.42712: P 965:1392(427) ack 1129 win 56216 <nop,nop,timestamp 362470131 100769>
00:06:52.919462 IP machine.local.42712 > 62.69.184.230.www: . ack 1392 win 71 <nop,nop,timestamp 100778 362470131>
00:06:52.920451 IP 62.69.184.230.www > machine.local.42712: . 1392:2840(1448) ack 1129 win 56216 <nop,nop,timestamp 362470131 100769>
00:06:52.920461 IP machine.local.42712 > 62.69.184.230.www: . ack 2840 win 94 <nop,nop,timestamp 100778 362470131>
00:06:52.921450 IP 62.69.184.230.www > machine.local.42712: . 2840:4288(1448) ack 1129 win 56216 <nop,nop,timestamp 362470131 100769>
00:06:52.921456 IP machine.local.42712 > 62.69.184.230.www: . ack 4288 win 117 <nop,nop,timestamp 100779 362470131>
00:06:52.921462 IP 62.69.184.230.www > machine.local.42712: P 4288:4369(81) ack 1129 win 56216 <nop,nop,timestamp 362470131 100769>
00:06:52.921466 IP machine.local.42712 > 62.69.184.230.www: . ack 4369 win 117 <nop,nop,timestamp 100779 362470131>
00:06:52.928199 IP frmegaadvip1.doubleclick.net.www > machine.local.54750: S 2318370353:2318370353(0) ack 2371928028 win 16384 <mss 1460,nop,wscale 0,nop,nop,timestamp 0 0,nop,nop,sackOK>
00:06:52.928213 IP machine.local.54750 > frmegaadvip1.doubleclick.net.www: . ack 1 win 46 <nop,nop,timestamp 100780 0>
00:06:52.928250 IP machine.local.54750 > frmegaadvip1.doubleclick.net.www: P 1:421(420) ack 1 win 46 <nop,nop,timestamp 100780 0>
00:06:52.971433 IP frmegaadvip1.doubleclick.net.www > machine.local.54750: FP 1:454(453) ack 421 win 65115 <nop,nop,timestamp 793378 100780>
00:06:52.971587 IP machine.local.54750 > frmegaadvip1.doubleclick.net.www: F 421:421(0) ack 455 win 54 <nop,nop,timestamp 100791 793378>
00:06:52.977583 IP machine.local.44770 > 192.168.9.255.netbios-ns: NBT UDP PACKET(137): QUERY; REQUEST; BROADCAST
00:06:52.987822 IP machine.local.42717 > 62.69.184.230.www: S 2372542060:2372542060(0) win 5840 <mss 1460,sackOK,timestamp 100795 0,nop,wscale 7>
00:06:53.007916 IP frmegaadvip1.doubleclick.net.www > machine.local.54750: . ack 422 win 65115 <nop,nop,timestamp 793379 100791>
00:06:55.903734 IP machine.local.50358 > 192.168.1.254.domain: 62920+ PTR? 254.1.168.192.in-addr.arpa. (44)
00:07:00.929894 IP machine.local.52368 > 192.168.1.254.domain: 4369+ PTR? 251.0.0.224.in-addr.arpa. (42)
00:07:00.953131 IP 192.168.1.254.domain > machine.local.52368: 4369 NXDomain 0/1/0 (100)
00:07:05.957855 IP machine.local.39914 > 192.168.1.254.domain: 5113+ PTR? 230.184.69.62.in-addr.arpa. (44)
00:07:05.986141 IP 192.168.1.254.domain > machine.local.39914: 5113 NXDomain 0/1/0 (112)
00:07:06.089468 IP machine.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 230.184.69.62.in-addr.arpa. (44)
00:07:07.093454 IP machine.local.mdns > 224.0.0.251.mdns: 0 PTR (QM)? 230.184.69.62.in-addr.arpa. (44)
00:07:11.001106 IP machine.local.60218 > 192.168.1.254.domain: 15048+ PTR? 57.179.62.209.in-addr.arpa. (44)
00:07:11.022898 IP 192.168.1.254.domain > machine.local.60218: 15048 1/4/4 (222) |