File Version :
File Description : C:\WINDOWS\system32\Sygate.exe
File Path : C:\WINDOWS\system32\Sygate.exe
Process ID : 0x400 (Heximal) 1024 (Decimal)
Connection origin : remote initiated
Protocol : TCP
Local Address : xx.xx.xx.xxx
Local Port : 1058 (NIM - nim)
Remote Name :
Remote Address : 200.203.xx.xxx
Remote Port : 6667
Ethernet packet details:
Ethernet II (Packet Length: 116)
Destination: 00-00-01-00-00-00
Source: 04-3a-20-00-01-00
Type: IP (0x0800)
Internet Protocol
Version: 4
Header Length: 20 bytes
Flags:
.1.. = Don't fragment: Set
..0. = More fragments: Not set
Fragment offset:0
Time to live: 48
Protocol: 0x6 (TCP - Transmission Control Protocol)
Header checksum: 0x5ba1 (Correct)
Source: 200.203.54.213
Destination: 82.48.15.187
Transmission Control Protocol (TCP)
Source port: 6667
Destination port: 1058
Sequence number: 2764482380
Acknowledgment number: 1733889075
Header length: 20
Flags:
0... .... = Congestion Window Reduce (CWR): Not set
.0.. .... = ECN-Echo: Not set
..0. .... = Urgent: Not set
...1 .... = Acknowledgment: Set
.... 1... = Push: Set
.... .0.. = Reset: Not set
.... ..0. = Syn: Not set
.... ...0 = Fin: Not set
Checksum: 0xcf38 (Correct)
Data (62 Bytes)
Binary dump of the packet:
0000: 00 00 01 00 00 00 04 3A : 20 00 01 00 08 00 45 00 | .......: .....E.
0010: 00 66 47 AB 40 00 30 06 : A1 5B C8 CB 36 D5 52 30 |
[email protected]..[..6.R0
0020: 0F BB 1A 0B 04 22 A4 C6 : A7 4C 67 59 0C 33 50 18 | ....."...LgY.3P.
0030: 16 D0 38 CF 00 00 3A 49 : 54 41 7C 38 32 38 32 34 | ..8...:ITA|82824
0040: 36 21 74 6D 67 72 63 74 : 40 35 31 44 36 34 36 36 | 6!tmgrct@51D6466
0050: 33 2E 39 32 41 31 38 44 : 33 46 2E 36 46 41 35 31 | 3.92A18D3F.6FA51
0060: 32 41 30 2E 49 50 20 4A : 4F 49 4E 20 3A 23 72 30 | 2A0.IP JOIN :#r0
0070: 78 78 0D 0A : | xx..