Advertisement
Guest User

Untitled

a guest
Aug 7th, 2019
202
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 13.31 KB | None | 0 0
  1. [
  2. {
  3. "_index": "packets-2019-08-07",
  4. "_type": "pcap_file",
  5. "_score": null,
  6. "_source": {
  7. "layers": {
  8. "frame": {
  9. "frame.encap_type": "25",
  10. "frame.time": "Aug 7, 2019 16:51:49.912308000 Hora de Ver\u00c3\u00a3o de GMT",
  11. "frame.offset_shift": "0.000000000",
  12. "frame.time_epoch": "1565193109.912308000",
  13. "frame.time_delta": "0.035752000",
  14. "frame.time_delta_displayed": "0.000000000",
  15. "frame.time_relative": "34.138096000",
  16. "frame.number": "585",
  17. "frame.len": "1505",
  18. "frame.cap_len": "1505",
  19. "frame.marked": "0",
  20. "frame.ignored": "0",
  21. "frame.protocols": "sll:ethertype:ip:udp:sip:mime_multipart:sdp:isup",
  22. "frame.coloring_rule.name": "UDP",
  23. "frame.coloring_rule.string": "udp"
  24. },
  25. "sll": {
  26. "sll.pkttype": "0",
  27. "sll.hatype": "1",
  28. "sll.halen": "6",
  29. "sll.src.eth": "6c:3b:6b:fe:5b:2f",
  30. "sll.unused": "00:00",
  31. "sll.etype": "0x00000800"
  32. },
  33. "ip": {
  34. "ip.version": "4",
  35. "ip.hdr_len": "20",
  36. "ip.dsfield": "0x000000b8",
  37. "ip.dsfield_tree": {
  38. "ip.dsfield.dscp": "46",
  39. "ip.dsfield.ecn": "0"
  40. },
  41. "ip.len": "1489",
  42. "ip.id": "0x000086e2",
  43. "ip.flags": "0x00000000",
  44. "ip.flags_tree": {
  45. "ip.flags.rb": "0",
  46. "ip.flags.df": "0",
  47. "ip.flags.mf": "0"
  48. },
  49. "ip.frag_offset": "0",
  50. "ip.ttl": "63",
  51. "ip.proto": "17",
  52. "ip.checksum": "0x0000f6f7",
  53. "ip.checksum.status": "2",
  54. "ip.src": "212.13.38.147",
  55. "ip.addr": "212.13.38.147",
  56. "ip.src_host": "212.13.38.147",
  57. "ip.host": "212.13.38.147",
  58. "ip.dst": "212.13.40.220",
  59. "ip.addr": "212.13.40.220",
  60. "ip.dst_host": "212.13.40.220",
  61. "ip.host": "212.13.40.220",
  62. "Source GeoIP: Unknown": "",
  63. "Destination GeoIP: Unknown": ""
  64. },
  65. "udp": {
  66. "udp.srcport": "5060",
  67. "udp.dstport": "5060",
  68. "udp.port": "5060",
  69. "udp.port": "5060",
  70. "udp.length": "1469",
  71. "udp.checksum": "0x00006d60",
  72. "udp.checksum.status": "2",
  73. "udp.stream": "2"
  74. },
  75. "sip": {
  76. "sip.Status-Line": "SIP\/2.0 180 Ringing",
  77. "sip.Status-Line_tree": {
  78. "sip.Status-Code": "180",
  79. "sip.resend": "0",
  80. "sip.response-request": "531",
  81. "sip.response-time": "3853"
  82. },
  83. "sip.msg_hdr": "Content-Type:multipart\/mixed;boundary=unique-boundary-1\r\nContact: <sip:[email protected]:5060>\r\nAllow:INVITE,ACK,OPTIONS,BYE,CANCEL,REGISTER,INFO,PRACK,REFER,SUBSCRIBE,NOTIFY\r\nDate:Wed, 07 Aug 2019 14:07:01 GMT\r\nFrom:<sip:[email protected]>;tag=3970176878\r\nTo:<sip:[email protected]>;tag=1E8B303037363131022A4E1D\r\nCall-ID:[email protected]\r\nCSeq:83 INVITE\r\nRecord-Route:<sip:212.13.40.220;r2=on;lr;ftag=3970176878;tbk_i=10_10_N;tbk_o=1_2_Y;vsf=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA;vst=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD;did=f48.285>\r\nRecord-Route:<sip:212.13.40.223;r2=on;lr;ftag=3970176878;tbk_i=10_10_N;tbk_o=1_2_Y;vsf=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA;vst=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD;did=f48.285>\r\nServer:TB007611\r\nVia:SIP\/2.0\/UDP 212.13.40.220;branch=z9hG4bKe876.299389693c8ed69def7a656c2628033c.0;received=212.13.40.220;rport=5060\r\nVia:SIP\/2.0\/UDP 192.168.24.86:5060;branch=z9hG4bK00158fed98b7e9118b3c4da50ae2ed72;rport;tbk_i=10_10_N;tbk_o=1_2_Y;received=212.13.35.221;rport=5060\r\nContent-Length:342\r\n\r\n--unique-boundary-1\r\nContent-Type:application\/sdp\r\n\r\nv=0\r\no=- 2989269303 1 IN IP4 212.13.38.147\r\ns=-\r\nc=IN IP4 212.13.38.147\r\nt=0 0\r\nm=audio 26710 RTP\/AVP 8\r\na=direction:passive\r\n\r\n--unique-boundary-1\r\nContent-Type:application\/ISUP;base=itu-t92+;version=itu-t\r\nContent-Disposition:signal;handling=required\r\n\r\n,\u0001\u0001\u0011\u0002\u00164",
  84. "sip.msg_hdr_tree": {
  85. "sip.Content-Type": "multipart\/mixed;boundary=unique-boundary-1",
  86. "sip.Contact": "<sip:[email protected]:5060>",
  87. "sip.Contact_tree": {
  88. "sip.contact.uri": "sip:[email protected]:5060",
  89. "sip.contact.uri_tree": {
  90. "sip.contact.user": "351925934244",
  91. "sip.contact.host": "212.13.38.147",
  92. "sip.contact.port": "5060"
  93. }
  94. },
  95. "sip.Allow": "INVITE,ACK,OPTIONS,BYE,CANCEL,REGISTER,INFO,PRACK,REFER,SUBSCRIBE,NOTIFY",
  96. "sip.Date": "Wed, 07 Aug 2019 14:07:01 GMT",
  97. "sip.From": "<sip:[email protected]>;tag=3970176878",
  98. "sip.From_tree": {
  99. "sip.from.addr": "sip:[email protected]",
  100. "sip.from.addr_tree": {
  101. "sip.from.user": "351211450160",
  102. "sip.from.host": "212.13.40.223"
  103. },
  104. "sip.from.tag": "3970176878",
  105. "sip.tag": "3970176878"
  106. },
  107. "sip.To": "<sip:[email protected]>;tag=1E8B303037363131022A4E1D",
  108. "sip.To_tree": {
  109. "sip.to.addr": "sip:[email protected]",
  110. "sip.to.addr_tree": {
  111. "sip.to.user": "351925934244",
  112. "sip.to.host": "212.13.40.220"
  113. },
  114. "sip.to.tag": "1E8B303037363131022A4E1D",
  115. "sip.tag": "1E8B303037363131022A4E1D"
  116. },
  117. "sip.Call-ID": "[email protected]",
  118. "sip.CSeq": "83 INVITE",
  119. "sip.CSeq_tree": {
  120. "sip.CSeq.seq": "83",
  121. "sip.CSeq.method": "INVITE"
  122. },
  123. "sip.Record-Route": "<sip:212.13.40.220;r2=on;lr;ftag=3970176878;tbk_i=10_10_N;tbk_o=1_2_Y;vsf=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA;vst=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD;did=f48.285>",
  124. "sip.Record-Route_tree": {
  125. "sip.Record-Route.uri": "sip:212.13.40.220;r2=on;lr;ftag=3970176878;tbk_i=10_10_N;tbk_o=1_2_Y;vsf=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA;vst=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD;did=f48.285",
  126. "sip.Record-Route.uri_tree": {
  127. "sip.Record-Route.host": "212.13.40.220",
  128. "sip.Record-Route.param": "r2=on",
  129. "sip.Record-Route.param": "lr",
  130. "sip.Record-Route.param": "ftag=3970176878",
  131. "sip.Record-Route.param": "tbk_i=10_10_N",
  132. "sip.Record-Route.param": "tbk_o=1_2_Y",
  133. "sip.Record-Route.param": "vsf=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA",
  134. "sip.Record-Route.param": "vst=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD",
  135. "sip.Record-Route.param": "did=f48.285"
  136. }
  137. },
  138. "sip.Record-Route": "<sip:212.13.40.223;r2=on;lr;ftag=3970176878;tbk_i=10_10_N;tbk_o=1_2_Y;vsf=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA;vst=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD;did=f48.285>",
  139. "sip.Record-Route_tree": {
  140. "sip.Record-Route.uri": "sip:212.13.40.223;r2=on;lr;ftag=3970176878;tbk_i=10_10_N;tbk_o=1_2_Y;vsf=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA;vst=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD;did=f48.285",
  141. "sip.Record-Route.uri_tree": {
  142. "sip.Record-Route.host": "212.13.40.223",
  143. "sip.Record-Route.param": "r2=on",
  144. "sip.Record-Route.param": "lr",
  145. "sip.Record-Route.param": "ftag=3970176878",
  146. "sip.Record-Route.param": "tbk_i=10_10_N",
  147. "sip.Record-Route.param": "tbk_o=1_2_Y",
  148. "sip.Record-Route.param": "vsf=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA",
  149. "sip.Record-Route.param": "vst=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD",
  150. "sip.Record-Route.param": "did=f48.285"
  151. }
  152. },
  153. "sip.Server": "TB007611",
  154. "sip.Via": "SIP\/2.0\/UDP 212.13.40.220;branch=z9hG4bKe876.299389693c8ed69def7a656c2628033c.0;received=212.13.40.220;rport=5060",
  155. "sip.Via_tree": {
  156. "sip.Via.transport": "UDP",
  157. "sip.Via.sent-by.address": "212.13.40.220",
  158. "sip.Via.branch": "z9hG4bKe876.299389693c8ed69def7a656c2628033c.0",
  159. "sip.Via.received": "212.13.40.220",
  160. "sip.Via.rport": "5060"
  161. },
  162. "sip.Via": "SIP\/2.0\/UDP 192.168.24.86:5060;branch=z9hG4bK00158fed98b7e9118b3c4da50ae2ed72;rport;tbk_i=10_10_N;tbk_o=1_2_Y;received=212.13.35.221;rport=5060",
  163. "sip.Via_tree": {
  164. "sip.Via.transport": "UDP",
  165. "sip.Via.sent-by.address": "192.168.24.86",
  166. "sip.Via.sent-by.port": "5060",
  167. "sip.Via.branch": "z9hG4bK00158fed98b7e9118b3c4da50ae2ed72",
  168. "sip.Via.rport": "rport",
  169. "tbk_i=10_10_N": "",
  170. "tbk_o=1_2_Y": "",
  171. "sip.Via.received": "212.13.35.221",
  172. "sip.Via.rport": "5060"
  173. },
  174. "sip.Content-Length": "342"
  175. },
  176. "sip.msg_body": {
  177. "mime_multipart": {
  178. "mime_multipart.type": "multipart\/mixed",
  179. "mime_multipart.first_boundary": "--unique-boundary-1\r\n",
  180. "mime_multipart.part": "",
  181. "mime_multipart.part_tree": {
  182. "mime_multipart.header.content-type": "application\/sdp",
  183. "sdp": {
  184. "sdp.version": "0",
  185. "sdp.owner": "- 2989269303 1 IN IP4 212.13.38.147",
  186. "sdp.owner_tree": {
  187. "sdp.owner.username": "-",
  188. "sdp.owner.sessionid": "2989269303",
  189. "sdp.owner.version": "1",
  190. "sdp.owner.network_type": "IN",
  191. "sdp.owner.address_type": "IP4",
  192. "sdp.owner.address": "212.13.38.147"
  193. },
  194. "sdp.session_name": "-",
  195. "sdp.connection_info": "IN IP4 212.13.38.147",
  196. "sdp.connection_info_tree": {
  197. "sdp.connection_info.network_type": "IN",
  198. "sdp.connection_info.address_type": "IP4",
  199. "sdp.connection_info.address": "212.13.38.147"
  200. },
  201. "sdp.time": "0 0",
  202. "sdp.time_tree": {
  203. "sdp.time.start": "0",
  204. "sdp.time.stop": "0"
  205. },
  206. "sdp.media": "audio 26710 RTP\/AVP 8",
  207. "sdp.media_tree": {
  208. "sdp.media.media": "audio",
  209. "sdp.media.port_string": "26710",
  210. "sdp.media.port": "26710",
  211. "sdp.media.proto": "RTP\/AVP",
  212. "sdp.media.format": "ITU-T G.711 PCMA"
  213. },
  214. "sdp.media_attr": "direction:passive",
  215. "sdp.media_attr_tree": {
  216. "sdp.media_attribute.field": "direction",
  217. "sdp.media_attribute.value": "passive"
  218. }
  219. }
  220. },
  221. "mime_multipart.boundary": "\r\n--unique-boundary-1\r\n",
  222. "mime_multipart.part": "",
  223. "mime_multipart.part_tree": {
  224. "mime_multipart.header.content-type": "application\/ISUP;base=itu-t92+;version=itu-t",
  225. "mime_multipart.header.content-disposition": "signal;handling=required",
  226. "isup": {
  227. "isup.message_type": "44",
  228. "Event information : ALERTING (1)": {
  229. "isup.parameter_type": "36",
  230. "isup.event_ind": "1",
  231. "isup.event_presentation_restr_ind": "0"
  232. },
  233. "isup.optional_parameter_part_pointer": "1",
  234. "Parameter: (t=17, l=2) Backward call indicators: Backward call indicators : 0x1634": {
  235. "isup.parameter_type": "17",
  236. "isup.parameter_length": "2",
  237. "isup.charge_indicator": "0x00000002",
  238. "isup.called_partys_status_indicator": "0x00000001",
  239. "isup.called_partys_category_indicator": "0x00000001",
  240. "isup.backw_call_end_to_end_method_indicator": "0x00000000",
  241. "isup.backw_call_interworking_indicator": "0",
  242. "isup.backw_call_end_to_end_information_indicator": "0",
  243. "isup.backw_call_isdn_user_part_indicator": "1",
  244. "isup.backw_call_holding_indicator": "0",
  245. "isup.backw_call_isdn_access_indicator": "1",
  246. "isup.backw_call_echo_control_device_indicator": "1",
  247. "isup.backw_call_sccp_method_indicator": "0x00000000"
  248. },
  249. "isup.parameter_type": "0"
  250. }
  251. },
  252. "mime_multipart.last_boundary": "\r\n--unique-boundary-1--\r\n"
  253. }
  254. }
  255. }
  256. }
  257. }
  258. }
  259. ]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement