
Hi, MoleRat, Uneek, thanks for your replies, the unknown packets were sent repeatedly using 3 kinds of length, 596 bytes, 724 byte, and 1172 bytes, these packets came from 6 devices to 1 devices simultaneously, within 1 minutes almost 1 MB were captured. Here's the sample packets. Is it some kind of attack?
No. Time Source Destination Protocol Info
467 30.509368 C-Com_02:03:b5 C-Com_05:00:9a 0xffe2 Ethernet II
Frame 467 (596 bytes on wire, 596 bytes captured)
Arrival Time: Feb 17, 2005 06:45:29.407635000
Time delta from previous packet: 0.021643000 seconds
Time since reference or first frame: 30.509368000 seconds
Frame Number: 467
Packet Length: 596 bytes
Capture Length: 596 bytes
Ethernet II, Src: 00:01:eb:02:03:b5, Dst: 00:01:eb:05:00:9a
Destination: 00:01:eb:05:00:9a (C-Com_05:00:9a)
Source: 00:01:eb:02:03:b5 (C-Com_02:03:b5)
Type: Unknown (0xffe2)
Data (582 bytes)
0000 00 01 eb 05 00 9a 00 01 eb 02 03 b5 ff e2 44 02 ..............D.
0010 00 00 06 10 c4 00 01 00 52 ac 36 04 52 ac 36 04 ........R.6.R.6.
0020 00 00 00 00 91 00 00 00 52 ac 36 04 52 ac 36 04 ........R.6.R.6.
0030 01 00 00 00 00 00 00 00 c6 00 02 00 0f c0 27 02 ..............'.
0040 0f c0 27 02 00 00 00 00 93 0a 00 00 0f c0 27 02 ..'...........'.
0050 0f c0 27 02 04 00 00 00 04 00 00 00 00 00 03 00 ..'.............
0060 0e cc 36 04 0e cc 36 04 00 00 00 00 02 00 00 00 ..6...6.........
0070 0e cc 36 04 0e cc 36 04 00 00 00 00 00 00 00 00 ..6...6.........
0080 63 ed 04 00 81 09 08 01 81 09 08 01 00 00 00 00 c...............
0090 19 26 00 00 81 09 08 01 81 09 08 01 12 00 00 00 .&..............
00a0 1c 00 00 00 00 00 05 00 35 23 25 00 35 23 25 00 ........5#%.5#%.
00b0 00 00 00 00 ce 0a 00 00 35 23 25 00 35 23 25 00 ........5#%.5#%.
00c0 03 00 00 00 05 00 00 00 3d 00 06 00 4d ce b9 00 ........=...M...
00d0 4d ce b9 00 00 00 00 00 0f 05 00 00 4d ce b9 00 M...........M...
00e0 4d ce b9 00 04 00 00 00 02 00 00 00 00 00 07 00 M...............
00f0 a4 1f f5 02 a4 1f f5 02 00 00 00 00 21 14 00 00 ............!...
0100 a4 1f f5 02 a4 1f f5 02 06 00 00 00 08 00 00 00 ................
0110 70 cf 08 00 e3 26 55 00 67 07 55 00 4c 4f 00 00 p....&U.g.U.LO..
0120 79 08 00 00 67 07 55 00 e3 26 55 00 06 00 00 00 y...g.U..&U.....
0130 07 00 00 00 00 00 09 00 5f 9a 02 00 5f 9a 02 00 ........_..._...
0140 00 00 00 00 8b 01 00 00 5f 9a 02 00 5f 9a 02 00 ........_..._...
0150 01 00 00 00 0f 02 00 00 9f a7 0a 00 27 58 27 01 ............'X'.
0160 27 58 27 01 00 00 00 00 7c 0e 00 00 27 58 27 01 'X'.....|...'X'.
0170 27 58 27 01 09 00 00 00 bb 00 00 00 0e 00 0b 00 'X'.............
0180 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0190 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
01a0 de 23 0c 00 d4 d6 5c 00 d4 d6 5c 00 00 00 00 00 .#....\...\.....
01b0 6b 01 00 00 d4 d6 5c 00 d4 d6 5c 00 00 00 00 00 k.....\...\.....
01c0 00 00 00 00 00 00 0d 00 00 00 00 00 00 00 00 00 ................
01d0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
01e0 00 00 00 00 00 00 00 00 d6 72 0e 00 9a 7b 9c 00 .........r...{..
01f0 9a 7b 9c 00 00 00 00 00 ce 0c 00 00 9a 7b 9c 00 .{...........{..
0200 9a 7b 9c 00 0a 00 00 00 05 00 00 00 6b 22 0f 00 .{..........k"..
0210 9a f9 7c 00 9a f9 7c 00 00 00 00 00 90 00 00 00 ..|...|.........
0220 9a f9 7c 00 9a f9 7c 00 00 00 00 00 00 00 00 00 ..|...|.........
0230 f3 d7 10 00 cc b4 48 00 cc b4 48 00 00 00 00 00 ......H...H.....
0240 e9 11 00 00 cc b4 48 00 cc b4 48 00 06 00 00 00 ......H...H.....
0250 0c 00 00 00 ....
No. Time Source Destination Protocol Info
468 30.535633 C-Com_02:03:b5 C-Com_05:00:9a 0xffe2 Ethernet II
Frame 468 (724 bytes on wire, 724 bytes captured)
Arrival Time: Feb 17, 2005 06:45:29.433900000
Time delta from previous packet: 0.026265000 seconds
Time since reference or first frame: 30.535633000 seconds
Frame Number: 468
Packet Length: 724 bytes
Capture Length: 724 bytes
Ethernet II, Src: 00:01:eb:02:03:b5, Dst: 00:01:eb:05:00:9a
Destination: 00:01:eb:05:00:9a (C-Com_05:00:9a)
Source: 00:01:eb:02:03:b5 (C-Com_02:03:b5)
Type: Unknown (0xffe2)
Data (710 bytes)
0000 00 01 eb 05 00 9a 00 01 eb 02 03 b5 ff e2 c4 02 ................
0010 00 00 06 10 c5 00 01 00 04 00 00 00 01 00 00 00 ................
0020 00 00 00 00 c4 2c 5b 00 05 0a a9 00 00 00 00 00 .....,[.........
0030 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0040 0f c0 02 00 4e 00 00 00 08 00 00 00 00 00 00 00 ....N...........
0050 8a f5 b8 00 c4 20 18 01 00 00 00 00 00 00 00 00 ..... ..........
0060 3b c7 36 04 00 00 00 00 00 00 00 00 02 00 03 00 ;.6.............
0070 00 00 00 00 00 00 00 00 00 00 00 00 0c a7 4f 00 ..............O.
0080 6a 4b 2a 01 00 00 00 00 00 00 00 00 00 00 00 00 jK*.............
0090 00 00 00 00 00 00 00 00 81 09 04 00 be 00 00 00 ................
00a0 15 00 00 00 00 00 00 00 6d 4f 19 00 9a 76 30 00 ........mO...v0.
00b0 00 00 00 00 00 00 00 00 35 23 25 00 00 00 00 00 ........5#%.....
00c0 00 00 00 00 05 00 05 00 35 00 00 00 06 00 00 00 ........5.......
00d0 00 00 00 00 30 a4 08 00 60 00 30 00 00 00 00 00 ....0...`.0.....
00e0 00 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 ................
00f0 d1 1a 06 00 10 00 00 00 01 00 00 00 00 00 00 00 ................
0100 06 8b 0d 00 84 40 2b 00 00 00 00 00 00 00 00 00 .....@+.........
0110 5b cf 08 00 00 00 00 00 00 00 00 00 4c 4f 07 00 [...........LO..
0120 64 00 00 00 07 00 00 00 00 00 00 00 e0 ac 4d 04 d.............M.
0130 10 d3 5e 04 00 00 00 00 00 00 00 00 5f 9a 02 00 ..^........._...
0140 00 00 00 00 00 00 00 00 5f 9a 08 00 57 00 00 00 ........_...W...
0150 04 00 00 00 00 00 00 00 fa 82 00 00 13 c1 01 00 ................
0160 00 00 00 00 00 00 00 00 7c 0e 00 00 00 00 00 00 ........|.......
0170 00 00 00 00 09 00 09 00 21 00 00 00 0e 00 00 00 ........!.......
0180 00 00 00 00 55 13 01 00 92 83 02 00 00 00 00 00 ....U...........
0190 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
01a0 de 23 0a 00 65 00 00 00 06 00 00 00 00 00 00 00 .#..e...........
01b0 3c 28 0e 00 3d 60 18 00 00 00 00 00 00 00 00 00 <(..=`..........
01c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0b 00 ................
01d0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
01e0 00 00 00 00 00 00 00 00 00 00 00 00 9a 7b 9c 00 .............{..
01f0 00 00 00 00 00 00 00 00 ce 0c 0c 00 06 00 00 00 ................
0200 00 00 00 00 00 00 00 00 20 35 00 00 6b 22 01 00 ........ 5..k"..
0210 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0220 00 00 00 00 9a f9 0d 00 00 00 00 00 00 00 00 00 ................
0230 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0240 00 00 00 00 cc b4 48 00 00 00 00 00 00 00 00 00 ......H.........
0250 0c 00 0e 00 46 00 00 00 07 00 00 00 00 00 00 00 ....F...........
0260 4c de 0a 00 f0 5b a0 00 00 00 00 00 00 00 00 00 L....[..........
0270 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0f 00 ................
0280 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0290 0d d3 00 00 00 00 00 00 00 00 00 00 00 00 0a 00 ................
02a0 00 00 00 00 00 00 00 00 18 00 10 00 5b 00 00 00 ............[...
02b0 09 00 00 00 00 00 00 00 dd f9 13 00 e7 54 c8 00 .............T..
02c0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
02d0 00 00 00 00 ....