Frame 6401: Packet, 181 bytes on wire (1448 bits), 181 bytes captured (1448 bits) Encapsulation type: Ethernet (1) Arrival Time: Mar 19, 2019 02:31:39.520895000 UTC UTC Arrival Time: Mar 19, 2019 02:31:39.520895000 UTC Epoch Arrival Time: 1552962699.520895000 [Time shift for this packet: 0.000000000 seconds] [Time delta from previous captured frame: 546.000 microseconds] [Time since reference or first frame: 46 minutes, 43.884129000 seconds] Frame Number: 6401 Frame Length: 181 bytes (1448 bits) Capture Length: 181 bytes (1448 bits) [Frame is marked: False] [Frame is ignored: False] [Protocols in frame: eth:ethertype:ip:tcp:tls] Character encoding: ASCII (0) Ethernet II, Src: Intel_57:2b:42 (64:32:a8:57:2b:42), Dst: Netgear_b6:93:f1 (20:e5:2a:b6:93:f1) Destination: Netgear_b6:93:f1 (20:e5:2a:b6:93:f1) .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) Source: Intel_57:2b:42 (64:32:a8:57:2b:42) .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) Type: IPv4 (0x0800) [Stream index: 4] Internet Protocol Version 4, Src: 10.0.90.215, Dst: 203.45.1.75 0100 .... = Version: 4 .... 0101 = Header Length: 20 bytes (5) Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT) 0000 00.. = Differentiated Services Codepoint: Default (0) .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0) Total Length: 167 Identification: 0x097a (2426) 010. .... = Flags: 0x2, Don't fragment 0... .... = Reserved bit: Not set .1.. .... = Don't fragment: Set ..0. .... = More fragments: Not set ...0 0000 0000 0000 = Fragment Offset: 0 Time to Live: 128 Protocol: TCP (6) Header Checksum: 0x05d4 [validation disabled] [Header checksum status: Unverified] Source Address: 10.0.90.215 Destination Address: 203.45.1.75 [Destination GeoIP: Melbourne, AU] [Destination GeoIP City: Melbourne] [Source or Destination GeoIP City: Melbourne] [Destination GeoIP Country: Australia] [Source or Destination GeoIP Country: Australia] [Destination GeoIP ISO Two Letter Country Code: AU] [Source or Destination GeoIP ISO Two Letter Country Code: AU] [Destination GeoIP Latitude: -37.8159] [Source or Destination GeoIP Latitude: -37.8159] [Destination GeoIP Longitude: 144.9669] [Source or Destination GeoIP Longitude: 144.9669] [Stream index: 13] Transmission Control Protocol, Src Port: 49237, Dst Port: 443, Seq: 1, Ack: 1, Len: 127 Source Port: 49237 Destination Port: 443 [Stream index: 81] [Stream Packet Number: 4] [Conversation completeness: Incomplete, ESTABLISHED (7)] ..0. .... = RST: Absent ...0 .... = FIN: Absent .... 0... = Data: Absent .... .1.. = ACK: Present .... ..1. = SYN-ACK: Present .... ...1 = SYN: Present [Completeness Flags: ···ASS] [TCP Segment Len: 127] Sequence Number: 1 (relative sequence number) Sequence Number (raw): 2476752076 [Next Sequence Number: 128 (relative sequence number)] Acknowledgment Number: 1 (relative ack number) Acknowledgment number (raw): 644767513 0101 .... = Header Length: 20 bytes (5) Flags: 0x018 (PSH, ACK) 000. .... .... = Reserved: Not set ...0 .... .... = Accurate ECN: Not set .... 0... .... = Congestion Window Reduced: Not set .... .0.. .... = ECN-Echo: Not set .... ..0. .... = Urgent: Not set .... ...1 .... = Acknowledgment: Set .... .... 1... = Push: Set .... .... .0.. = Reset: Not set .... .... ..0. = Syn: Not set .... .... ...0 = Fin: Not set [TCP Flags: ·······AP···] Window: 64240 [Calculated window size: 64240] [Window size scaling factor: -2 (no window scaling used)] Checksum: 0x23e0 [unverified] [Checksum Status: Unverified] Urgent Pointer: 0 [Timestamps] [Time since first frame in this TCP stream: 224.232000 milliseconds] [Time since previous frame in this TCP stream: 546.000 microseconds] [SEQ/ACK analysis] [iRTT: 223.686000 milliseconds] [Bytes in flight: 127] [Bytes sent since last PSH flag: 127] [Client Contiguous Streams: 1] [Server Contiguous Streams: 1] TCP payload (127 bytes) Transport Layer Security [Stream index: 19] TLSv1 Record Layer: Handshake Protocol: Client Hello Content Type: Handshake (22) Version: TLS 1.0 (0x0301) Length: 122 Handshake Protocol: Client Hello Handshake Type: Client Hello (1) Length: 118 Version: TLS 1.0 (0x0301) Random: 5c905486fd7e6470f251bcc6cc13cac1ccb02d59506bf5bdab5a3e6511593399 GMT Unix Time: Mar 19, 2019 02:31:34.000000000 UTC Random Bytes: fd7e6470f251bcc6cc13cac1ccb02d59506bf5bdab5a3e6511593399 Session ID Length: 32 Session ID: 46067fac1c14a8f9f5bd912ba56e069783d7e20f7cc89319f15ec5df3a433527 Cipher Suites Length: 24 Cipher Suites (12 suites) Cipher Suite: TLS_RSA_WITH_AES_128_CBC_SHA (0x002f) Cipher Suite: TLS_RSA_WITH_AES_256_CBC_SHA (0x0035) Cipher Suite: TLS_RSA_WITH_RC4_128_SHA (0x0005) Cipher Suite: TLS_RSA_WITH_3DES_EDE_CBC_SHA (0x000a) Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013) Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014) Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (0xc009) Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (0xc00a) Cipher Suite: TLS_DHE_DSS_WITH_AES_128_CBC_SHA (0x0032) Cipher Suite: TLS_DHE_DSS_WITH_AES_256_CBC_SHA (0x0038) Cipher Suite: TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA (0x0013) Cipher Suite: TLS_RSA_WITH_RC4_128_MD5 (0x0004) Compression Methods Length: 1 Compression Methods (1 method) Compression Method: null (0) Extensions Length: 21 Extension: renegotiation_info (len=1) Type: renegotiation_info (65281) Length: 1 Renegotiation Info extension Renegotiation info extension length: 0 Extension: supported_groups (len=6) Type: supported_groups (10) Length: 6 Supported Groups List Length: 4 Supported Groups (2 groups) Supported Group: secp256r1 (0x0017) Supported Group: secp384r1 (0x0018) Extension: ec_point_formats (len=2) Type: ec_point_formats (11) Length: 2 EC point formats Length: 1 Elliptic curves point formats (1) EC point format: uncompressed (0) [JA4: t10i120300_d94e65cdb899_f8ec56bc740a] [JA4_r: t10i120300_0004,0005,000a,0013,002f,0032,0035,0038,c009,c00a,c013,c014_000a,000b,ff01] [JA3 Fullstring: 769,47-53-5-10-49171-49172-49161-49162-50-56-19-4,65281-10-11,23-24,0] [JA3: 6734f37431670b3ab4292b8f60f29984]