Frame 754: 362 bytes on wire (2896 bits), 362 bytes captured (2896 bits) Encapsulation type: Ethernet (1) Arrival Time: Mar 19, 2019 01:47:04.599220000 UTC UTC Arrival Time: Mar 19, 2019 01:47:04.599220000 UTC Epoch Arrival Time: 1552960024.599220000 [Time shift for this packet: 0.000000000 seconds] [Time delta from previous captured frame: 0.000255000 seconds] [Time delta from previous displayed frame: 0.000000000 seconds] [Time since reference or first frame: 128.962454000 seconds] Frame Number: 754 Frame Length: 362 bytes (2896 bits) Capture Length: 362 bytes (2896 bits) [Frame is marked: False] [Frame is ignored: False] [Protocols in frame: eth:ethertype:ip:tcp:http] Ethernet II, Src: Intel_57:2b:42 (64:32:a8:57:2b:42), Dst: Netgear_b6:93:f1 (20:e5:2a:b6:93:f1) Destination: Netgear_b6:93:f1 (20:e5:2a:b6:93:f1) .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) Source: Intel_57:2b:42 (64:32:a8:57:2b:42) .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) Type: IPv4 (0x0800) [Stream index: 4] Internet Protocol Version 4, Src: 10.0.90.215, Dst: 209.141.34.8 0100 .... = Version: 4 .... 0101 = Header Length: 20 bytes (5) Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT) 0000 00.. = Differentiated Services Codepoint: Default (0) .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0) Total Length: 348 Identification: 0x01a5 (421) 010. .... = Flags: 0x2, Don't fragment 0... .... = Reserved bit: Not set .1.. .... = Don't fragment: Set ..0. .... = More fragments: Not set ...0 0000 0000 0000 = Fragment Offset: 0 Time to Live: 128 Protocol: TCP (6) Header Checksum: 0xe5d6 [validation disabled] [Header checksum status: Unverified] Source Address: 10.0.90.215 Destination Address: 209.141.34.8 [Destination GeoIP: Las Vegas, US, ASN 53667, PONYNET] [Destination GeoIP City: Las Vegas] [Source or Destination GeoIP City: Las Vegas] [Destination GeoIP Country: United States] [Source or Destination GeoIP Country: United States] [Destination GeoIP ISO Two Letter Country Code: US] [Source or Destination GeoIP ISO Two Letter Country Code: US] [Destination GeoIP AS Number: 53667] [Source or Destination GeoIP AS Number: 53667] [Destination GeoIP AS Organization: PONYNET] [Source or Destination GeoIP AS Organization: PONYNET] [Destination GeoIP Latitude: 36.102] [Source or Destination GeoIP Latitude: 36.102] [Destination GeoIP Longitude: -115.1447] [Source or Destination GeoIP Longitude: -115.1447] [Stream index: 7] Transmission Control Protocol, Src Port: 49204, Dst Port: 80, Seq: 1, Ack: 1, Len: 308 Source Port: 49204 Destination Port: 80 [Stream index: 48] [Stream Packet Number: 4] [Conversation completeness: Incomplete, ESTABLISHED (7)] ..0. .... = RST: Absent ...0 .... = FIN: Absent .... 0... = Data: Absent .... .1.. = ACK: Present .... ..1. = SYN-ACK: Present .... ...1 = SYN: Present [Completeness Flags: ···ASS] [TCP Segment Len: 308] Sequence Number: 1 (relative sequence number) Sequence Number (raw): 2938185605 [Next Sequence Number: 309 (relative sequence number)] Acknowledgment Number: 1 (relative ack number) Acknowledgment number (raw): 1203208075 0101 .... = Header Length: 20 bytes (5) Flags: 0x018 (PSH, ACK) 000. .... .... = Reserved: Not set ...0 .... .... = Accurate ECN: Not set .... 0... .... = Congestion Window Reduced: Not set .... .0.. .... = ECN-Echo: Not set .... ..0. .... = Urgent: Not set .... ...1 .... = Acknowledgment: Set .... .... 1... = Push: Set .... .... .0.. = Reset: Not set .... .... ..0. = Syn: Not set .... .... ...0 = Fin: Not set [TCP Flags: ·······AP···] Window: 64240 [Calculated window size: 64240] [Window size scaling factor: -2 (no window scaling used)] Checksum: 0xbe3b [unverified] [Checksum Status: Unverified] Urgent Pointer: 0 [Timestamps] [Time since first frame in this TCP stream: 0.040331000 seconds] [Time since previous frame in this TCP stream: 0.000255000 seconds] [SEQ/ACK analysis] [iRTT: 0.040076000 seconds] [Bytes in flight: 308] [Bytes sent since last PSH flag: 308] TCP payload (308 bytes) Hypertext Transfer Protocol GET /test1.exe HTTP/1.1\r\n Request Method: GET Request URI: /test1.exe Request Version: HTTP/1.1 Accept: */*\r\n Accept-Encoding: gzip, deflate\r\n User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)\r\n Host: 209.141.34.8\r\n Connection: Keep-Alive\r\n \r\n [Full request URI: http://209.141.34.8/test1.exe]