Link to home
Start Free TrialLog in
Avatar of dalva
dalva

asked on

What does this packet capture between PC and Exchange server mean?

Recently while using ethereal we came across this conversation between a user PC with XP and our Exchange server.  I am looking to understand what the conversation is about.  This is only a sampling of 100 lines in the order they occurred.  I would like to hear from someone who is knowledgeable in these matters and not just guessing what might be going on.  This capture took place when the user was not using their PC.  Feel free to request more information.

Source          Destination      Protocol Info
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190688 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190688 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190688 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190688 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190689 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190689 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190689 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190689 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190690 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190690 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190690 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190690 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190691 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190691 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190691 ctx_id: 0
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [ACK] Seq=937973971 Ack=1945378387 Win=8488 Len=1460
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [ACK] Seq=937975431 Ack=1945378387 Win=8488 Len=1460
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [PSH, ACK] Seq=937976891 Ack=1945378387 Win=8488 Len=1460
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190691 ctx_id: 0
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [PSH, ACK] Seq=937979811 Ack=1945378387 Win=8488 Len=124
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190691 ctx_id: 0
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [ACK] Seq=937973971 Ack=1945378387 Win=8488 Len=1460
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [ACK] Seq=937975431 Ack=1945378387 Win=8488 Len=1460
XXX.46.32.215   XX.5.80.40       TCP      1936 > 1060 [ACK] Seq=1945378387 Ack=937975431 Win=64512 Len=0
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [PSH, ACK] Seq=937976891 Ack=1945378387 Win=8488 Len=1460
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190691 ctx_id: 0
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [PSH, ACK] Seq=937979811 Ack=1945378387 Win=8488 Len=124
XXX.46.32.215   XX.5.80.40       TCP      1936 > 1060 [ACK] Seq=1945378387 Ack=937975431 Win=64512 Len=0
XXX.46.32.215   XX.5.80.40       TCP      1936 > 1060 [ACK] Seq=1945378387 Ack=937978351 Win=64512 Len=0
XXX.46.32.215   XX.5.80.40       TCP      1936 > 1060 [ACK] Seq=1945378387 Ack=937979935 Win=64512 Len=0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190692 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       TCP      1936 > 1060 [ACK] Seq=1945378387 Ack=937978351 Win=64512 Len=0
XXX.46.32.215   XX.5.80.40       TCP      1936 > 1060 [ACK] Seq=1945378387 Ack=937979935 Win=64512 Len=0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190692 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190692 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190692 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190693 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190693 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190693 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190693 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190694 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190694 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190694 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190694 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190695 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190695 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190695 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190695 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 33679 opnum: 7 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 33679 opnum: 7 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 33679 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 33679 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 33680 opnum: 9 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 33680 opnum: 9 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 33680 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 33680 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190696 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190696 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190696 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190696 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190697 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190697 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190697 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190697 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190698 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190698 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190698 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190698 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190699 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190699 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190699 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190699 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190700 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190700 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190700 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190700 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190701 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190701 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190701 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190701 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190702 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190702 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190702 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190702 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190703 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190703 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190703 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190703 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190704 opnum: 2 ctx_id: 0
XXX.46.32.215   XX.5.80.40       DCERPC   Request: call_id: 190704 opnum: 2 ctx_id: 0
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190704 ctx_id: 0
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [ACK] Seq=937983155 Ack=1945379939 Win=8472 Len=1460
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [ACK] Seq=937984615 Ack=1945379939 Win=8472 Len=1460
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [PSH, ACK] Seq=937986075 Ack=1945379939 Win=8472 Len=1460
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190704 ctx_id: 0
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [ACK] Seq=937988995 Ack=1945379939 Win=8472 Len=1460
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [ACK] Seq=937990455 Ack=1945379939 Win=8472 Len=1460
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [PSH, ACK] Seq=937991915 Ack=1945379939 Win=8472 Len=1460
XX.5.80.40      XXX.46.32.215    DCERPC   Response: call_id: 190704 ctx_id: 0
XX.5.80.40      XXX.46.32.215    TCP      1060 > 1936 [ACK] Seq=937994835 Ack=1945379939 Win=8472 Len=1460
ASKER CERTIFIED SOLUTION
Avatar of marc_nivens
marc_nivens

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of dalva
dalva

ASKER

This capture was done from a location which would capture all conversations between the server and many other PCs.  The disturbing part is this PC consistently has much more traffic than any other PC.  I thought the PC might be a spam zombie.  I will wait a few days before closing out.  Any other perspectives out there?
A few explanations I can think of are:

- Other clients are in cached mode, this one is not
- Free/Busy update interval is lower on this client
- This client gets more mail than other users