Frame 8017: Packet, 452 bytes on wire (3616 bits), 452 bytes captured (3616 bits) Encapsulation type: Ethernet (1) Arrival Time: Oct 21, 2017 05:02:29.704396000 UTC UTC Arrival Time: Oct 21, 2017 05:02:29.704396000 UTC Epoch Arrival Time: 1508562149.704396000 [Time shift for this packet: 0.000000000 seconds] [Time delta from previous captured frame: 5.000 microseconds] [Time since reference or first frame: 10 minutes, 36.390893000 seconds] Frame Number: 8017 Frame Length: 452 bytes (3616 bits) Capture Length: 452 bytes (3616 bits) [Frame is marked: False] [Frame is ignored: False] [Protocols in frame: eth:ethertype:ip:tcp:http:png] Character encoding: ASCII (0) Ethernet II, Src: LinksysGroup_f8:1a:ac (00:04:5a:f8:1a:ac), Dst: ASUSTekCOMPU_6a:b2:1f (60:a4:4c:6a:b2:1f) Destination: ASUSTekCOMPU_6a:b2:1f (60:a4:4c:6a:b2:1f) .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) Source: LinksysGroup_f8:1a:ac (00:04:5a:f8:1a:ac) .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) Type: IPv4 (0x0800) [Stream index: 1] Internet Protocol Version 4, Src: 34.206.190.189, Dst: 10.0.1.95 0100 .... = Version: 4 .... 0101 = Header Length: 20 bytes (5) Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT) 0000 00.. = Differentiated Services Codepoint: Default (0) .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0) Total Length: 438 Identification: 0x25ff (9727) 000. .... = Flags: 0x0 0... .... = Reserved bit: Not set .0.. .... = Don't fragment: Not set ..0. .... = More fragments: Not set ...0 0000 0000 0000 = Fragment Offset: 0 Time to Live: 128 Protocol: TCP (6) Header Checksum: 0x2659 [validation disabled] [Header checksum status: Unverified] Source Address: 34.206.190.189 Destination Address: 10.0.1.95 [Source GeoIP: Ashburn, US] [Source GeoIP City: Ashburn] [Source or Destination GeoIP City: Ashburn] [Source GeoIP Country: United States] [Source or Destination GeoIP Country: United States] [Source GeoIP ISO Two Letter Country Code: US] [Source or Destination GeoIP ISO Two Letter Country Code: US] [Source GeoIP Latitude: 39.0481] [Source or Destination GeoIP Latitude: 39.0481] [Source GeoIP Longitude: -77.4728] [Source or Destination GeoIP Longitude: -77.4728] [Stream index: 62] Transmission Control Protocol, Src Port: 80, Dst Port: 61279, Seq: 1, Ack: 899, Len: 398 Source Port: 80 Destination Port: 61279 [Stream index: 246] [Stream Packet Number: 6] [Conversation completeness: Incomplete, DATA (15)] ..0. .... = RST: Absent ...0 .... = FIN: Absent .... 1... = Data: Present .... .1.. = ACK: Present .... ..1. = SYN-ACK: Present .... ...1 = SYN: Present [Completeness Flags: ··DASS] [TCP Segment Len: 398] Sequence Number: 1 (relative sequence number) Sequence Number (raw): 3236515672 [Next Sequence Number: 399 (relative sequence number)] Acknowledgment Number: 899 (relative ack number) Acknowledgment number (raw): 1443971662 0101 .... = Header Length: 20 bytes (5) Flags: 0x018 (PSH, ACK) 000. .... .... = Reserved: Not set ...0 .... .... = Accurate ECN: Not set .... 0... .... = Congestion Window Reduced: Not set .... .0.. .... = ECN-Echo: Not set .... ..0. .... = Urgent: Not set .... ...1 .... = Acknowledgment: Set .... .... 1... = Push: Set .... .... .0.. = Reset: Not set .... .... ..0. = Syn: Not set .... .... ...0 = Fin: Not set [TCP Flags: ·······AP···] Window: 64240 [Calculated window size: 64240] [Window size scaling factor: -2 (no window scaling used)] Checksum: 0x5a64 [unverified] [Checksum Status: Unverified] Urgent Pointer: 0 [Timestamps] [Time since first frame in this TCP stream: 169.782000 milliseconds] [Time since previous frame in this TCP stream: 83.347000 milliseconds] [SEQ/ACK analysis] [iRTT: 85.613000 milliseconds] [Bytes in flight: 398] [Bytes sent since last PSH flag: 398] [Client Contiguous Streams: 1] [Server Contiguous Streams: 1] TCP payload (398 bytes) Hypertext Transfer Protocol, has 2 chunks (including last chunk) HTTP/1.1 200 OK\r\n Response Version: HTTP/1.1 Status Code: 200 [Status Code Description: OK] Response Phrase: OK Date: Sat, 21 Oct 2017 05:02:31 GMT\r\n Content-Type: image/gif\r\n Transfer-Encoding: chunked\r\n Connection: keep-alive\r\n X-Powered-By: Express\r\n Access-Control-Allow-Origin: *\r\n Access-Control-Allow-Methods: GET,PUT,POST,DELETE\r\n Access-Control-Allow-Headers: Origin, X-Requested-With, Content-Type, Accept\r\n \r\n [Request in frame: 7997] [Time since request: 83.846000 milliseconds] [Request URI […]: /ptmd?t=%7B%22status%22%3A22%2C%22za%22%3A1%2C%22env%22%3A%22p%22%2C%22gh%22%3A%2215085621488801074183180%22%2C%22ts%22%3A%221429807462558%22%2C%22vs%22%3A%226.0.102%22%2C%22al%22%3A3%2C%22fc%22%3A-1%2C%22ea%22%3A%22e35f] [Full request URI […]: http://dt.clnmde.com/ptmd?t=%7B%22status%22%3A22%2C%22za%22%3A1%2C%22env%22%3A%22p%22%2C%22gh%22%3A%2215085621488801074183180%22%2C%22ts%22%3A%221429807462558%22%2C%22vs%22%3A%226.0.102%22%2C%22al%22%3A3%2C%22fc%22%] HTTP chunked response Data chunk (70 octets) Chunk size: 70 octets Chunk data: 89504e470d0a1a0a0000000d49484452000000010000000108060000001f15c4890000000d4944415478da63fccfc0500f000485018084a98c210000000049454e44ae426082 Chunk boundary: 0d0a End of chunked encoding Chunk size: 0 octets \r\n File Data: 70 bytes [Expert Info (Note/Malformed): HTTP body subdissector failed, trying heuristic subdissector] [HTTP body subdissector failed, trying heuristic subdissector] [Severity level: Note] [Group: Malformed] Portable Network Graphics PNG Signature: 89504e470d0a1a0a Image Header (IHDR) Len: 13 Type: IHDR ..0. .... .... .... .... .... .... .... = Ancillary: This is a CRITICAL chunk .... .... ..0. .... .... .... .... .... = Private: This is a PUBLIC chunk .... .... .... .... .... .... ..0. .... = Safe To Copy: This chunk is NOT safe to copy Width: 1 Height: 1 Bit Depth: 8 Colour Type: Truecolour with alpha (6) Compression Method: Deflate (0) Filter Method: Adaptive (0) Interlace Method: No interlace (0) CRC: 0x1f15c489 Image data chunk (IDAT) Len: 13 Type: IDAT ..0. .... .... .... .... .... .... .... = Ancillary: This is a CRITICAL chunk .... .... ..0. .... .... .... .... .... = Private: This is a PUBLIC chunk .... .... .... .... .... .... ..0. .... = Safe To Copy: This chunk is NOT safe to copy Data CRC: 0x84a98c21 Image Trailer (IEND) Len: 0 Type: IEND ..0. .... .... .... .... .... .... .... = Ancillary: This is a CRITICAL chunk .... .... ..0. .... .... .... .... .... = Private: This is a PUBLIC chunk .... .... .... .... .... .... ..0. .... = Safe To Copy: This chunk is NOT safe to copy CRC: 0xae426082