-----------------------------------------------------------------------------------------
ps vind iemand anders deze packetdump niet vreemd?
GetLogicalDrives, CreateFile

? komt van de UPC brain....

-----------------------------------------------------------------------------------------
File Version : 5.0.2195.6616
File Description : IP Network Address Translator (ipnat.sys)
File Path : C:\WINNT\system32\drivers\ipnat.sys
Process ID : 0xFA0 (Heximal) 4000 (Decimal)
Connection origin : remote initiated
Protocol : TCP
Local Address : xxx.xxx.xxx.xxx
Local Port : 3729
Remote Name :
Remote Address : 212.142.33.157
Remote Port : 80
Ethernet packet details:
Ethernet II (Packet Length: 1514)
Destination: xx-xx-xx-xx-xx-xx
Source: 00-09-b6-68-ec-71
Type: IP (0x0800)
Internet Protocol
Version: 4
Header Length: 20 bytes
Flags:
.1.. = Don't fragment: Set
..0. = More fragments: Not set
Fragment offset:0
Time to live: 61
Protocol: 0x6 (TCP - Transmission Control Protocol)
Header checksum: 0xbd3a (Correct)
Source: 212.142.33.157
Destination: xxx.xxx.xxx.xxx
Transmission Control Protocol (TCP)
Source port: 80
Destination port: 3729
Sequence number: 2630422729
Acknowledgment number: 1210750030
Header length: 20
Flags:
0... .... = Congestion Window Reduce (CWR): Not set
.0.. .... = ECN-Echo: Not set
..0. .... = Urgent: Not set
...1 .... = Acknowledgment: Set
.... 0... = Push: Not set
.... .0.. = Reset: Not set
.... ..0. = Syn: Not set
.... ...0 = Fin: Not set
Checksum: 0x5a33 (Correct)
Data (1460 Bytes)
Binary dump of the packet:
0000: 00 50 DA 3E 25 9D 00 09 : B6 68 EC 71 08 00 45 00 | .P.>%....h.q..E.
0010: 05 DC 87 36 40 00 3D 06 : 3A BD D4 8E 21 9D 18 84 | ...6@.=.:...!...
0020: 67 79 00 50 0E 91 9C C9 : 10 C9 48 2A 94 4E 50 10 | gy.P......H*.NP.
0030: 60 F4 33 5A 00 00 00 00 : 00 F2 3E 02 00 D4 3E 02 | `.3Z......>...>.
0040: 00 BE 3E 02 00 9E 3E 02 : 00 AC 3E 02 00 00 00 00 | ..>...>...>.....
0050: 00 AC 3A 02 00 54 3A 02 : 00 66 3A 02 00 8C 3A 02 | ..:..T:..f:...:.
0060: 00 00 3A 02 00 EE 39 02 : 00 E2 39 02 00 D4 39 02 | ..:...9...9...9.
0070: 00 78 3A 02 00 C6 3B 02 : 00 0C 3A 02 00 B6 3B 02 | .x:...;...:...;.
0080: 00 3C 3C 02 00 D2 3B 02 : 00 E0 3B 02 00 F0 3B 02 | .<<...;...;...;.
0090: 00 FC 3B 02 00 0E 3C 02 : 00 20 3C 02 00 30 3C 02 | ..;...<.. <..0<.
00A0: 00 9A 3A 02 00 4E 3C 02 : 00 5A 3C 02 00 C6 3D 02 | ..:..N<..Z<...=.
00B0: 00 B4 3D 02 00 A0 3D 02 : 00 92 3D 02 00 7A 3D 02 | ..=...=...=..z=.
00C0: 00 68 3D 02 00 54 3D 02 : 00 44 3D 02 00 BA 3A 02 | .h=..T=..D=...:.
00D0: 00 C8 3A 02 00 D4 3A 02 : 00 E4 3A 02 00 F2 3A 02 | ..:...:...:...:.
00E0: 00 04 3B 02 00 14 3B 02 : 00 26 3B 02 00 38 3B 02 | ..;...;..&;..8;.
00F0: 00 48 3B 02 00 5E 3B 02 : 00 6E 3B 02 00 80 3B 02 | .H;..^;..n;...;.
0100: 00 92 3B 02 00 A4 3B 02 : 00 0A 3D 02 00 2E 3D 02 | ..;...;...=...=.
0110: 00 F0 3C 02 00 E2 3C 02 : 00 D0 3C 02 00 BE 3C 02 | ..<...<...<...<.
0120: 00 AC 3C 02 00 9C 3C 02 : 00 8C 3C 02 00 22 3A 02 | ..<...<...<..":.
0130: 00 7C 3C 02 00 68 3C 02 : 00 46 3A 02 00 34 3A 02 | .|<..h<..F:..4:.
0140: 00 1C 3D 02 00 00 00 00 : 00 00 3E 02 00 00 00 00 | ..=.......>.....
0150: 00 20 3F 02 00 0E 3F 02 : 00 00 00 00 00 1E 3E 02 | . ?...?.......>.
0160: 00 32 3E 02 00 42 3E 02 : 00 50 3E 02 00 60 3E 02 | .2>..B>..P>..`>.
0170: 00 70 3E 02 00 80 3E 02 : 00 00 00 00 00 E4 3D 02 | .p>...>.......=.
0180: 00 00 00 00 00 D2 37 02 : 00 E6 37 02 00 F0 37 02 | ......7...7...7.
0190: 00 02 38 02 00 10 38 02 : 00 24 38 02 00 32 38 02 | ..8...8..$8..28.
01A0: 00 46 38 02 00 56 38 02 : 00 62 38 02 00 6E 38 02 | .F8..V8..b8..n8.
01B0: 00 7E 38 02 00 90 38 02 : 00 B6 38 02 00 CC 38 02 | .~8...8...8...8.
01C0: 00 E6 38 02 00 FE 38 02 : 00 0C 39 02 00 24 39 02 | ..8...8...9..$9.
01D0: 00 3E 39 02 00 4C 39 02 : 00 5E 39 02 00 70 39 02 | .>9..L9..^9..p9.
01E0: 00 80 39 02 00 8C 39 02 : 00 A4 39 02 00 B4 39 02 | ..9...9...9...9.
01F0: 00 BC 37 02 00 AE 37 02 : 00 92 37 02 00 7E 37 02 | ..7...7...7..~7.
0200: 00 6A 37 02 00 52 37 02 : 00 3A 37 02 00 2C 37 02 | .j7..R7..:7..,7.
0210: 00 1E 37 02 00 0E 37 02 : 00 02 37 02 00 EC 36 02 | ..7...7...7...6.
0220: 00 D8 36 02 00 C4 36 02 : 00 B8 36 02 00 A8 36 02 | ..6...6...6...6.
0230: 00 90 36 02 00 7E 36 02 : 00 68 36 02 00 5C 36 02 | ..6..~6..h6..\6.
0240: 00 46 36 02 00 30 36 02 : 00 A6 38 02 00 84 40 02 | .F6..06...8...@.
0250: 00 66 40 02 00 58 40 02 : 00 46 40 02 00 34 40 02 |
[email protected]@
[email protected]@.
0260: 00 24 40 02 00 14 40 02 : 00 04 40 02 00 F6 3F 02 | .$@...@...@...?.
0270: 00 72 40 02 00 98 40 02 : 00 E8 3F 02 00 D6 3F 02 | .r@...@...?...?.
0280: 00 CA 3F 02 00 BA 3F 02 : 00 AA 3F 02 00 90 3F 02 | ..?...?...?...?.
0290: 00 7C 3F 02 00 6E 3F 02 : 00 60 3F 02 00 54 3F 02 | .|?..n?..`?..T?.
02A0: 00 1C 36 02 00 6C 41 02 : 00 B4 40 02 00 CE 40 02 | ..6..lA...@...@.
02B0: 00 E8 40 02 00 00 41 02 : 00 1A 41 02 00 26 41 02 |
[email protected]..&A.
02C0: 00 30 41 02 00 3C 41 02 : 00 48 41 02 00 5A 41 02 | .0A..<A..HA..ZA.
02D0: 00 48 3F 02 00 7C 41 02 : 00 8E 41 02 00 A0 41 02 | .H?..|A...A...A.
02E0: 00 BA 41 02 00 00 00 00 : 00 00 00 00 00 F2 3E 02 | ..A...........>.
02F0: 00 D4 3E 02 00 BE 3E 02 : 00 9E 3E 02 00 AC 3E 02 | ..>...>...>...>.
0300: 00 00 00 00 00 AC 3A 02 : 00 54 3A 02 00 66 3A 02 | ......:..T:..f:.
0310: 00 8C 3A 02 00 00 3A 02 : 00 EE 39 02 00 E2 39 02 | ..:...:...9...9.
0320: 00 D4 39 02 00 78 3A 02 : 00 C6 3B 02 00 0C 3A 02 | ..9..x:...;...:.
0330: 00 B6 3B 02 00 3C 3C 02 : 00 D2 3B 02 00 E0 3B 02 | ..;..<<...;...;.
0340: 00 F0 3B 02 00 FC 3B 02 : 00 0E 3C 02 00 20 3C 02 | ..;...;...<.. <.
0350: 00 30 3C 02 00 9A 3A 02 : 00 4E 3C 02 00 5A 3C 02 | .0<...:..N<..Z<.
0360: 00 C6 3D 02 00 B4 3D 02 : 00 A0 3D 02 00 92 3D 02 | ..=...=...=...=.
0370: 00 7A 3D 02 00 68 3D 02 : 00 54 3D 02 00 44 3D 02 | .z=..h=..T=..D=.
0380: 00 BA 3A 02 00 C8 3A 02 : 00 D4 3A 02 00 E4 3A 02 | ..:...:...:...:.
0390: 00 F2 3A 02 00 04 3B 02 : 00 14 3B 02 00 26 3B 02 | ..:...;...;..&;.
03A0: 00 38 3B 02 00 48 3B 02 : 00 5E 3B 02 00 6E 3B 02 | .8;..H;..^;..n;.
03B0: 00 80 3B 02 00 92 3B 02 : 00 A4 3B 02 00 0A 3D 02 | ..;...;...;...=.
03C0: 00 2E 3D 02 00 F0 3C 02 : 00 E2 3C 02 00 D0 3C 02 | ..=...<...<...<.
03D0: 00 BE 3C 02 00 AC 3C 02 : 00 9C 3C 02 00 8C 3C 02 | ..<...<...<...<.
03E0: 00 22 3A 02 00 7C 3C 02 : 00 68 3C 02 00 46 3A 02 | .":..|<..h<..F:.
03F0: 00 34 3A 02 00 1C 3D 02 : 00 00 00 00 00 00 3E 02 | .4:...=.......>.
0400: 00 00 00 00 00 20 3F 02 : 00 0E 3F 02 00 00 00 00 | ..... ?...?.....
0410: 00 FA 00 47 65 74 4C 6F : 67 69 63 61 6C 44 72 69 | ...GetLogicalDri
0420: 76 65 73 00 00 FC 00 47 : 65 74 4D 6F 64 75 6C 65 | ves....GetModule
0430: 46 69 6C 65 4E 61 6D 65 : 41 00 00 6E 02 57 69 64 | FileNameA..n.Wid
0440: 65 43 68 61 72 54 6F 4D : 75 6C 74 69 42 79 74 65 | eCharToMultiByte
0450: 00 9B 02 6C 73 74 72 63 : 70 79 41 00 00 D6 00 47 | ...lstrcpyA....G
0460: 65 74 43 75 72 72 65 6E : 74 54 68 72 65 61 64 49 | etCurrentThreadI
0470: 64 00 00 AA 00 47 65 74 : 43 6F 6D 6D 61 6E 64 4C | d....GetCommandL
0480: 69 6E 65 41 00 0C 02 53 : 65 74 43 75 72 72 65 6E | ineA...SetCurren
0490: 74 44 69 72 65 63 74 6F : 72 79 41 00 00 3D 01 47 | tDirectoryA..=.G
04A0: 65 74 54 65 6D 70 50 61 : 74 68 41 00 00 92 02 6C | etTempPathA....l
04B0: 73 74 72 63 61 74 41 00 : 00 F0 00 47 65 74 46 75 | strcatA....GetFu
04C0: 6C 6C 50 61 74 68 4E 61 : 6D 65 41 00 00 DB 00 47 | llPathNameA....G
04D0: 65 74 44 69 73 6B 46 72 : 65 65 53 70 61 63 65 41 | etDiskFreeSpaceA
04E0: 00 AB 01 4D 75 6C 74 69 : 42 79 74 65 54 6F 57 69 | ...MultiByteToWi
04F0: 64 65 43 68 61 72 00 A1 : 02 6C 73 74 72 6C 65 6E | deChar...lstrlen
0500: 41 00 00 F4 00 47 65 74 : 4C 61 73 74 45 72 72 6F | A....GetLastErro
0510: 72 00 00 18 00 43 6C 6F : 73 65 48 61 6E 64 6C 65 | r....CloseHandle
0520: 00 31 00 43 72 65 61 74 : 65 46 69 6C 65 41 00 8F | .1.CreateFileA..
0530: 01 4C 65 61 76 65 43 72 : 69 74 69 63 61 6C 53 65 | .LeaveCriticalSe
0540: 63 74 69 6F 6E 00 00 58 : 00 45 6E 74 65 72 43 72 | ction..X.EnterCr
0550: 69 74 69 63 61 6C 53 65 : 63 74 69 6F 6E 00 00 FE | iticalSection...
0560: 00 47 65 74 4D 6F 64 75 : 6C 65 48 61 6E 64 6C 65 | .GetModuleHandle
0570: 41 00 00 D3 00 47 65 74 : 43 75 72 72 65 6E 74 50 | A....GetCurrentP
0580: 72 6F 63 65 73 73 00 79 : 01 49 6E 69 74 69 61 6C | rocess.y.Initial
0590: 69 7A 65 43 72 69 74 69 : 63 61 6C 53 65 63 74 69 | izeCriticalSecti
05A0: 6F 6E 00 6C 01 48 65 61 : 70 44 65 73 74 72 6F 79 | on.l.HeapDestroy
05B0: 00 86 02 57 72 69 74 65 : 50 72 6F 66 69 6C 65 53 | ...WriteProfileS
05C0: 74 72 69 6E 67 41 00 26 : 01 47 65 74 53 68 6F 72 | tringA.&.GetShor
05D0: 74 50 61 74 68 4E 61 6D : 65 41 00 6F 02 57 69 6E | tPathNameA.o.Win
05E0: 45 78 65 63 00 50 00 44 : 65 76 | Exec.P.Dev
===========================================================================
IP Address : [212.142.33.157] test.net.upc.nl
IP Location: Netherlands Netherlands [NL]
% This is the RIPE Whois query server #1.
% The objects are in RPSL format.
%
% Note: the default output of the RIPE Whois server
% is changed. Your tools may need to be adjusted. See
% https://www.ripe.net/db/news/abuse-proposal-20050331.html
% for more details.
%
% Rights restricted by copyright.
% See https://www.ripe.net/db/copyright.html
% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to '212.142.33.0 - 212.142.33.255'
inetnum: 212.142.33.0 - 212.142.33.255
netname: UPC-BRAIN-2
descr: Brain IP access Amsterdam
country: NL
admin-c: UCR1-RIPE
tech-c: UCR1-RIPE
status: ASSIGNED PA
mnt-by: UPCNL-MNT
source: RIPE # Filtered
role: UPC-NL Contact Role
address: Galvanistraat 12-2
address: 6716 AE Ede
address: The Netherlands
phone: +31 318 695505
fax-no: +31 318 695515
e-mail:
[email protected]
admin-c: RIHU1-RIPE
admin-c: RC482-RIPE
tech-c: RIHU1-RIPE
tech-c: EJ21-RIPE
tech-c: RC482-RIPE
nic-hdl: UCR1-RIPE
remarks: complaints about spam and other net-abuse:
[email protected]
mnt-by: UPCNL-MNT
source: RIPE # Filtered
% Information related to 'UCR1-RIPE'
route: 212.142.32.0/19
descr: UPC.nl Network Services
descr: Priority Telecom Business Customers
descr: The Netherlands
origin: AS8209
mnt-by: UPCNL-MNT
source: RIPE # Filtered