* 'ntp-rewrite' of https://github.com/mauropalumbo75/zeek: (25 commits)
  update tests baseline
  Apply requested changes: - file dpd.sig and TODO comments for signature protocol detection removed - missing doc field filled in events.bif - rename OpCode and ReqCode fields into op_code and req_code respectively - removed unnecessary child method in NTP.h/.cc - main.zeek and ntp-protocol.pac reformatted
  minor changes in the documentation
  fix some initializations
  fix wrong assignment of control key_id/crypto_checksum
  code clean up
  add extension fields parsing
  add extended mac field with 20 byte digest (+4 byte key id)
  update tests and add a new one for key_id and mac
  fix auth field (key_id and mac) in standard and control msg
  remove old NTP record in init-bare.zeek
  fix key_id and digest (WIP)
  fix wrong Assign with reference_id
  add tests for ntp protocol (finished)
  add tests for ntp protocol (WIP)
  fix problem with time vals
  add ntp records to init-bare.zeek
  update ntp analyzer to val_mgr
  extend and refact script-side of NTP analyzer
  extend and refactor several fields
  ...
This commit is contained in:
Jon Siwek 2019-06-15 19:09:03 -07:00
commit e2dc0092f3
53 changed files with 1729 additions and 711 deletions

View file

@ -0,0 +1,35 @@
ntp_message 192.168.43.118 -> 80.211.52.109:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028229, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246818.058351, rec_time=1559246818.079217, xmt_time=1559246885.027449, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 80.211.52.109:123 [version=4, mode=4, std_msg=[stratum=4, poll=64.0, precision=0, root_delay=0.048843, root_disp=0.075409, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=105.237.207.28, ref_time=1559245852.721794, org_time=1559246885.027449, rec_time=1559246885.069212, xmt_time=1559246885.069247, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 212.45.144.88:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028259, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246820.060608, rec_time=1559246820.081498, xmt_time=1559246887.027425, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 212.45.144.88:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.003799, root_disp=0.037018, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=193.204.114.233, ref_time=1559245541.537424, org_time=1559246887.027425, rec_time=1559246887.050758, xmt_time=1559246887.050774, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 31.14.131.188:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028275, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246819.064014, rec_time=1559246819.079147, xmt_time=1559246888.027454, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 185.19.184.35:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028275, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246822.050275, rec_time=1559246822.064562, xmt_time=1559246888.030021, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 185.19.184.35:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0.000008, root_delay=0.003235, root_disp=0.000565, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=193.204.114.233, ref_time=1559246481.481997, org_time=1559246888.030021, rec_time=1559246888.22033, xmt_time=1559246888.220401, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 31.14.131.188:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.040375, root_disp=0.001236, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=195.113.144.238, ref_time=1559246882.967102, org_time=1559246888.027454, rec_time=1559246888.234035, xmt_time=1559246888.234061, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 212.45.144.3:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.02829, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246822.05809, rec_time=1559246822.069097, xmt_time=1559246889.027449, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 212.45.144.3:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0.000001, root_delay=0.00351, root_disp=0.040573, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=193.204.114.232, ref_time=1559245278.44239, org_time=1559246889.027449, rec_time=1559246889.061203, xmt_time=1559246889.06122, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 85.199.214.99:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028305, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246824.073855, rec_time=1559246824.095227, xmt_time=1559246890.027469, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 31.14.133.122:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028305, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246821.052836, rec_time=1559246821.069165, xmt_time=1559246890.027512, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 188.213.165.209:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028305, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246823.12395, rec_time=1559246823.295751, xmt_time=1559246890.027523, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 188.213.165.209:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.013596, root_disp=0.025208, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=193.204.114.232, ref_time=1559246828.086879, org_time=1559246890.027523, rec_time=1559246890.060644, xmt_time=1559246890.060687, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 31.14.133.122:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.01091, root_disp=0.037491, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=193.204.114.233, ref_time=1559245577.265702, org_time=1559246890.027512, rec_time=1559246890.069012, xmt_time=1559246890.069048, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 85.199.214.99:123 [version=4, mode=4, std_msg=[stratum=1, poll=16.0, precision=0, root_delay=0.0, root_disp=0.0, kiss_code=<uninitialized>, ref_id=GPS\x00, ref_addr=<uninitialized>, ref_time=1559246890.0, org_time=1559246890.027469, rec_time=1559246890.070262, xmt_time=1559246890.070268, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 93.41.196.243:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.02832, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246822.05173, rec_time=1559246822.067161, xmt_time=1559246891.027395, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 94.177.187.22:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.02832, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246825.052045, rec_time=1559246825.066358, xmt_time=1559246891.029953, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 93.41.196.243:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.025391, root_disp=0.015671, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=193.204.114.233, ref_time=1559246412.455332, org_time=1559246891.027395, rec_time=1559246891.051818, xmt_time=1559246891.051827, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 94.177.187.22:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.013657, root_disp=0.025818, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=193.204.114.233, ref_time=1559246788.670839, org_time=1559246891.029953, rec_time=1559246891.061992, xmt_time=1559246891.062023, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 212.45.144.206:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028336, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246824.061335, rec_time=1559246824.08282, xmt_time=1559246892.027401, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 212.45.144.206:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0.000002, root_delay=0.00351, root_disp=0.042603, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=193.204.114.232, ref_time=1559245178.020777, org_time=1559246892.027401, rec_time=1559246892.05139, xmt_time=1559246892.051436, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 147.135.207.214:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028366, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246825.064608, rec_time=1559246825.074985, xmt_time=1559246894.027491, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 147.135.207.214:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0.000008, root_delay=0.042236, root_disp=0.041504, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=212.7.1.132, ref_time=1559245356.576177, org_time=1559246894.027491, rec_time=1559246894.059304, xmt_time=1559246894.05938, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 80.211.88.132:123 [version=3, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028427, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246829.060691, rec_time=1559246829.079018, xmt_time=1559246898.027403, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 80.211.171.177:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028427, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246830.0714, rec_time=1559246830.08971, xmt_time=1559246898.029953, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 80.211.88.132:123 [version=3, mode=4, std_msg=[stratum=3, poll=64.0, precision=0.000001, root_delay=0.011917, root_disp=0.000565, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=185.19.184.35, ref_time=1559246667.219303, org_time=1559246898.027403, rec_time=1559246898.077958, xmt_time=1559246898.078029, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 80.211.171.177:123 [version=4, mode=4, std_msg=[stratum=4, poll=64.0, precision=0, root_delay=0.036819, root_disp=0.050842, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=73.98.4.223, ref_time=1559246822.40751, org_time=1559246898.029953, rec_time=1559246898.078347, xmt_time=1559246898.07843, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 147.135.207.213:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028458, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246833.067975, rec_time=1559246833.07965, xmt_time=1559246900.027439, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 80.211.155.206:123 [version=4, mode=3, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.04628, root_disp=0.028458, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=85.199.214.99, ref_time=1559246556.073681, org_time=1559246831.053954, rec_time=1559246831.069547, xmt_time=1559246900.030036, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 80.211.155.206:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0, root_delay=0.013535, root_disp=0.029602, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=193.204.114.232, ref_time=1559246283.180069, org_time=1559246900.030036, rec_time=1559246900.08881, xmt_time=1559246900.088844, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 147.135.207.213:123 [version=4, mode=4, std_msg=[stratum=2, poll=64.0, precision=0.000008, root_delay=0.042236, root_disp=0.041595, kiss_code=<uninitialized>, ref_id=<uninitialized>, ref_addr=212.7.1.132, ref_time=1559245356.576177, org_time=1559246900.027439, rec_time=1559246900.103765, xmt_time=1559246900.103887, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 193.204.114.232:123 [version=4, mode=3, std_msg=[stratum=0, poll=16.0, precision=0.015625, root_delay=1.0, root_disp=1.0, kiss_code=\x00\x00\x00\x00, ref_id=<uninitialized>, ref_addr=<uninitialized>, ref_time=0.0, org_time=0.0, rec_time=0.0, xmt_time=1101309131.444112, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 193.204.114.232:123 [version=4, mode=4, std_msg=[stratum=1, poll=16.0, precision=0, root_delay=0.0, root_disp=0.000122, kiss_code=<uninitialized>, ref_id=CTD\x00, ref_addr=<uninitialized>, ref_time=1559246910.937978, org_time=1101309131.444112, rec_time=1559246940.281161, xmt_time=1559246940.281191, key_id=<uninitialized>, digest=<uninitialized>, num_exts=0], control_msg=<uninitialized>, mode7_msg=<uninitialized>]
ntp_message 192.168.43.118 -> 193.204.114.232:123 [version=2, mode=7, std_msg=<uninitialized>, control_msg=<uninitialized>, mode7_msg=[req_code=42, auth_bit=F, sequence=0, implementation=3, err=0, data=<uninitialized>]]

View file

@ -0,0 +1,43 @@
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path ntp
#open 2019-06-16-00-59-58
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p version mode stratum poll precision root_delay root_disp ref_id ref_time org_time rec_time xmt_time num_exts
#types time string addr port addr port count count count interval interval interval interval string time time time time count
1559246885.027478 CHhAvVGS1DHFjwGM9 192.168.43.118 123 80.211.52.109 123 4 3 2 64.000000 0.000000 0.046280 0.028229 85.199.214.99 1559246556.073681 1559246818.058351 1559246818.079217 1559246885.027449 0
1559246885.088815 CHhAvVGS1DHFjwGM9 192.168.43.118 123 80.211.52.109 123 4 4 4 64.000000 0.000000 0.048843 0.075409 105.237.207.28 1559245852.721794 1559246885.027449 1559246885.069212 1559246885.069247 0
1559246887.027467 ClEkJM2Vm5giqnMf4h 192.168.43.118 123 212.45.144.88 123 4 3 2 64.000000 0.000000 0.046280 0.028259 85.199.214.99 1559246556.073681 1559246820.060608 1559246820.081498 1559246887.027425 0
1559246887.060766 ClEkJM2Vm5giqnMf4h 192.168.43.118 123 212.45.144.88 123 4 4 2 64.000000 0.000000 0.003799 0.037018 193.204.114.233 1559245541.537424 1559246887.027425 1559246887.050758 1559246887.050774 0
1559246888.027489 C4J4Th3PJpwUYZZ6gc 192.168.43.118 123 31.14.131.188 123 4 3 2 64.000000 0.000000 0.046280 0.028275 85.199.214.99 1559246556.073681 1559246819.064014 1559246819.079147 1559246888.027454 0
1559246888.030028 CtPZjS20MLrsMUOJi2 192.168.43.118 123 185.19.184.35 123 4 3 2 64.000000 0.000000 0.046280 0.028275 85.199.214.99 1559246556.073681 1559246822.050275 1559246822.064562 1559246888.030021 0
1559246888.422200 CtPZjS20MLrsMUOJi2 192.168.43.118 123 185.19.184.35 123 4 4 2 64.000000 0.000008 0.003235 0.000565 193.204.114.233 1559246481.481997 1559246888.030021 1559246888.220330 1559246888.220401 0
1559246888.422229 C4J4Th3PJpwUYZZ6gc 192.168.43.118 123 31.14.131.188 123 4 4 2 64.000000 0.000000 0.040375 0.001236 195.113.144.238 1559246882.967102 1559246888.027454 1559246888.234035 1559246888.234061 0
1559246889.027482 CUM0KZ3MLUfNB0cl11 192.168.43.118 123 212.45.144.3 123 4 3 2 64.000000 0.000000 0.046280 0.028290 85.199.214.99 1559246556.073681 1559246822.058090 1559246822.069097 1559246889.027449 0
1559246889.075261 CUM0KZ3MLUfNB0cl11 192.168.43.118 123 212.45.144.3 123 4 4 2 64.000000 0.000001 0.003510 0.040573 193.204.114.232 1559245278.442390 1559246889.027449 1559246889.061203 1559246889.061220 0
1559246890.027493 CmES5u32sYpV7JYN 192.168.43.118 123 85.199.214.99 123 4 3 2 64.000000 0.000000 0.046280 0.028305 85.199.214.99 1559246556.073681 1559246824.073855 1559246824.095227 1559246890.027469 0
1559246890.027517 CP5puj4I8PtEU4qzYg 192.168.43.118 123 31.14.133.122 123 4 3 2 64.000000 0.000000 0.046280 0.028305 85.199.214.99 1559246556.073681 1559246821.052836 1559246821.069165 1559246890.027512 0
1559246890.027528 C37jN32gN3y3AZzyf6 192.168.43.118 123 188.213.165.209 123 4 3 2 64.000000 0.000000 0.046280 0.028305 85.199.214.99 1559246556.073681 1559246823.123950 1559246823.295751 1559246890.027523 0
1559246890.076319 C37jN32gN3y3AZzyf6 192.168.43.118 123 188.213.165.209 123 4 4 2 64.000000 0.000000 0.013596 0.025208 193.204.114.232 1559246828.086879 1559246890.027523 1559246890.060644 1559246890.060687 0
1559246890.082370 CP5puj4I8PtEU4qzYg 192.168.43.118 123 31.14.133.122 123 4 4 2 64.000000 0.000000 0.010910 0.037491 193.204.114.233 1559245577.265702 1559246890.027512 1559246890.069012 1559246890.069048 0
1559246890.094824 CmES5u32sYpV7JYN 192.168.43.118 123 85.199.214.99 123 4 4 1 16.000000 0.000000 0.000000 0.000000 GPS\x00 1559246890.000000 1559246890.027469 1559246890.070262 1559246890.070268 0
1559246891.027431 C3eiCBGOLw3VtHfOj 192.168.43.118 123 93.41.196.243 123 4 3 2 64.000000 0.000000 0.046280 0.028320 85.199.214.99 1559246556.073681 1559246822.051730 1559246822.067161 1559246891.027395 0
1559246891.029967 CwjjYJ2WqgTbAqiHl6 192.168.43.118 123 94.177.187.22 123 4 3 2 64.000000 0.000000 0.046280 0.028320 85.199.214.99 1559246556.073681 1559246825.052045 1559246825.066358 1559246891.029953 0
1559246891.068733 C3eiCBGOLw3VtHfOj 192.168.43.118 123 93.41.196.243 123 4 4 2 64.000000 0.000000 0.025391 0.015671 193.204.114.233 1559246412.455332 1559246891.027395 1559246891.051818 1559246891.051827 0
1559246891.075965 CwjjYJ2WqgTbAqiHl6 192.168.43.118 123 94.177.187.22 123 4 4 2 64.000000 0.000000 0.013657 0.025818 193.204.114.233 1559246788.670839 1559246891.029953 1559246891.061992 1559246891.062023 0
1559246892.027415 C0LAHyvtKSQHyJxIl 192.168.43.118 123 212.45.144.206 123 4 3 2 64.000000 0.000000 0.046280 0.028336 85.199.214.99 1559246556.073681 1559246824.061335 1559246824.082820 1559246892.027401 0
1559246892.077560 C0LAHyvtKSQHyJxIl 192.168.43.118 123 212.45.144.206 123 4 4 2 64.000000 0.000002 0.003510 0.042603 193.204.114.232 1559245178.020777 1559246892.027401 1559246892.051390 1559246892.051436 0
1559246894.027523 CFLRIC3zaTU1loLGxh 192.168.43.118 123 147.135.207.214 123 4 3 2 64.000000 0.000000 0.046280 0.028366 85.199.214.99 1559246556.073681 1559246825.064608 1559246825.074985 1559246894.027491 0
1559246894.070325 CFLRIC3zaTU1loLGxh 192.168.43.118 123 147.135.207.214 123 4 4 2 64.000000 0.000008 0.042236 0.041504 212.7.1.132 1559245356.576177 1559246894.027491 1559246894.059304 1559246894.059380 0
1559246898.027422 C9rXSW3KSpTYvPrlI1 192.168.43.118 123 80.211.88.132 123 3 3 2 64.000000 0.000000 0.046280 0.028427 85.199.214.99 1559246556.073681 1559246829.060691 1559246829.079018 1559246898.027403 0
1559246898.029960 Ck51lg1bScffFj34Ri 192.168.43.118 123 80.211.171.177 123 4 3 2 64.000000 0.000000 0.046280 0.028427 85.199.214.99 1559246556.073681 1559246830.071400 1559246830.089710 1559246898.029953 0
1559246898.094782 C9rXSW3KSpTYvPrlI1 192.168.43.118 123 80.211.88.132 123 3 4 3 64.000000 0.000001 0.011917 0.000565 185.19.184.35 1559246667.219303 1559246898.027403 1559246898.077958 1559246898.078029 0
1559246898.094827 Ck51lg1bScffFj34Ri 192.168.43.118 123 80.211.171.177 123 4 4 4 64.000000 0.000000 0.036819 0.050842 73.98.4.223 1559246822.407510 1559246898.029953 1559246898.078347 1559246898.078430 0
1559246900.027467 C9mvWx3ezztgzcexV7 192.168.43.118 123 147.135.207.213 123 4 3 2 64.000000 0.000000 0.046280 0.028458 85.199.214.99 1559246556.073681 1559246833.067975 1559246833.079650 1559246900.027439 0
1559246900.030051 CNnMIj2QSd84NKf7U3 192.168.43.118 123 80.211.155.206 123 4 3 2 64.000000 0.000000 0.046280 0.028458 85.199.214.99 1559246556.073681 1559246831.053954 1559246831.069547 1559246900.030036 0
1559246900.102991 CNnMIj2QSd84NKf7U3 192.168.43.118 123 80.211.155.206 123 4 4 2 64.000000 0.000000 0.013535 0.029602 193.204.114.232 1559246283.180069 1559246900.030036 1559246900.088810 1559246900.088844 0
1559246900.111834 C9mvWx3ezztgzcexV7 192.168.43.118 123 147.135.207.213 123 4 4 2 64.000000 0.000008 0.042236 0.041595 212.7.1.132 1559245356.576177 1559246900.027439 1559246900.103765 1559246900.103887 0
1559246940.262220 C7fIlMZDuRiqjpYbb 192.168.43.118 58229 193.204.114.232 123 4 3 0 16.000000 0.015625 1.000000 1.000000 \x00\x00\x00\x00 0.000000 0.000000 0.000000 1101309131.444112 0
1559246940.304152 C7fIlMZDuRiqjpYbb 192.168.43.118 58229 193.204.114.232 123 4 4 1 16.000000 0.000000 0.000000 0.000122 CTD\x00 1559246910.937978 1101309131.444112 1559246940.281161 1559246940.281191 0
#close 2019-06-16-00-59-58