Frame 9533: 259 bytes on wire (2072 bits), 259 bytes captured (2072 bits) Encapsulation type: Ethernet (1) Arrival Time: Oct 21, 2017 05:03:26.098046000 UTC [Time shift for this packet: 0.000000000 seconds] Epoch Time: 1508562206.098046000 seconds [Time delta from previous captured frame: 0.000002000 seconds] [Time delta from previous displayed frame: 0.000000000 seconds] [Time since reference or first frame: 692.784543000 seconds] Frame Number: 9533 Frame Length: 259 bytes (2072 bits) Capture Length: 259 bytes (2072 bits) [Frame is marked: False] [Frame is ignored: False] [Protocols in frame: eth:ethertype:ip:tcp:http:data] Ethernet II, Src: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac), Dst: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f) Destination: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f) Address: ASUSTekC_6a:b2:1f (60:a4:4c:6a:b2:1f) .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) Source: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac) Address: LinksysG_f8:1a:ac (00:04:5a:f8:1a:ac) .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default) .... ...0 .... .... .... .... = IG bit: Individual address (unicast) Type: IPv4 (0x0800) Internet Protocol Version 4, Src: 162.244.35.36, Dst: 10.0.1.95 0100 .... = Version: 4 .... 0101 = Header Length: 20 bytes (5) Differentiated Services Field: 0x00 (DSCP: CS0, ECN: Not-ECT) 0000 00.. = Differentiated Services Codepoint: Default (0) .... ..00 = Explicit Congestion Notification: Not ECN-Capable Transport (0) Total Length: 245 Identification: 0x298a (10634) Flags: 0x00 0... .... = Reserved bit: Not set .0.. .... = Don't fragment: Not set ..0. .... = More fragments: Not set ...0 0000 0000 0000 = Fragment Offset: 0 Time to Live: 128 Protocol: TCP (6) Header Checksum: 0x3f02 [validation disabled] [Header checksum status: Unverified] Source Address: 162.244.35.36 Destination Address: 10.0.1.95 [Source GeoIP: Santa Clara, US, ASN 14576, HOSTING-SOLUTIONS] [Source GeoIP City: Santa Clara] [Source or Destination GeoIP City: Santa Clara] [Source GeoIP Country: United States] [Source or Destination GeoIP Country: United States] [Source GeoIP ISO Two Letter Country Code: US] [Source or Destination GeoIP ISO Two Letter Country Code: US] [Source GeoIP AS Number: 14576] [Source or Destination GeoIP AS Number: 14576] [Source GeoIP AS Organization: HOSTING-SOLUTIONS] [Source or Destination GeoIP AS Organization: HOSTING-SOLUTIONS] [Source GeoIP Latitude: 37.353] [Source or Destination GeoIP Latitude: 37.353] [Source GeoIP Longitude: -121.9543] [Source or Destination GeoIP Longitude: -121.9543] Transmission Control Protocol, Src Port: 80, Dst Port: 61356, Seq: 4381, Ack: 282, Len: 205 Source Port: 80 Destination Port: 61356 [Stream index: 321] [Conversation completeness: Incomplete, DATA (15)] [TCP Segment Len: 205] Sequence Number: 4381 (relative sequence number) Sequence Number (raw): 291916032 [Next Sequence Number: 4586 (relative sequence number)] Acknowledgment Number: 282 (relative ack number) Acknowledgment number (raw): 3380249083 0101 .... = Header Length: 20 bytes (5) Flags: 0x018 (PSH, ACK) 000. .... .... = Reserved: Not set ...0 .... .... = Nonce: Not set .... 0... .... = Congestion Window Reduced (CWR): Not set .... .0.. .... = ECN-Echo: Not set .... ..0. .... = Urgent: Not set .... ...1 .... = Acknowledgment: Set .... .... 1... = Push: Set .... .... .0.. = Reset: Not set .... .... ..0. = Syn: Not set .... .... ...0 = Fin: Not set [TCP Flags: ·······AP···] Window: 64240 [Calculated window size: 64240] [Window size scaling factor: -2 (no window scaling used)] Checksum: 0x04b9 [unverified] [Checksum Status: Unverified] Urgent Pointer: 0 [Timestamps] [Time since first frame in this TCP stream: 0.371721000 seconds] [Time since previous frame in this TCP stream: 0.000002000 seconds] [SEQ/ACK analysis] [iRTT: 0.080817000 seconds] [Bytes in flight: 4585] [Bytes sent since last PSH flag: 4585] TCP payload (205 bytes) Hypertext Transfer Protocol File Data: 205 bytes Data (205 bytes) 0000 20 74 65 78 74 29 7d 2c 66 61 6c 73 65 29 7d 65 text)},false)}e 0010 6c 73 65 20 7b 64 6f 63 75 6d 65 6e 74 5b 5f 30 lse {document[_0 0020 78 62 33 63 39 5b 32 5d 5d 5b 5f 30 78 62 33 63 xb3c9[2]][_0xb3c 0030 39 5b 35 5d 5d 28 5f 30 78 62 33 63 39 5b 34 5d 9[5]](_0xb3c9[4] 0040 2c 66 75 6e 63 74 69 6f 6e 28 5f 30 78 63 36 38 ,function(_0xc68 0050 36 78 31 29 7b 61 6c 65 72 74 28 5f 30 78 62 33 6x1){alert(_0xb3 0060 63 39 5b 30 5d 2b 20 74 65 78 74 29 7d 29 7d 3b c9[0]+ text)})}; 0070 77 69 6e 64 6f 77 5b 5f 30 78 62 33 63 39 5b 36 window[_0xb3c9[6 0080 5d 5d 3d 20 66 75 6e 63 74 69 6f 6e 28 29 7b 72 ]]= function(){r 0090 65 74 75 72 6e 20 74 65 78 74 5f 73 68 6f 72 74 eturn text_short 00a0 7d 0d 0a 20 20 20 20 3c 2f 73 63 72 69 70 74 3e }.. 00b0 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d ..........0.... Data: 2074657874297d2c66616c7365297d656c7365207b646f63756d656e745b5f3078623363… [Length: 205]