Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-07-24 01:59:31.424 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35466 10 6438 1 2025-07-24 02:00:31.837 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:44482 10 6438 1 2025-07-24 01:57:01.540 00:05:00.474 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-07-24 02:01:32.249 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:44062 10 6438 1 2025-07-24 01:58:01.542 00:05:00.485 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-07-24 02:02:39.525 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:02:39.697 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:02:39.857 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:02:39.703 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:02:39.786 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:02:32.608 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:60620 10 6438 1 2025-07-24 02:03:33.025 00:00:10.348 TCP 1.101.0.1:3000 -> 23.104.0.1:58102 10 6438 1 2025-07-24 02:04:33.432 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:60934 10 6438 1 2025-07-24 02:05:33.840 00:00:10.352 TCP 1.101.0.1:3000 -> 23.104.0.1:46948 10 6438 1 2025-07-24 02:06:34.229 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:47852 10 6438 1 2025-07-24 02:03:01.542 00:05:00.493 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-07-24 02:07:39.949 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:07:39.754 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:07:39.866 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:07:40.095 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:07:40.045 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:07:34.639 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57614 10 6438 1 2025-07-24 02:04:01.542 00:05:00.488 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-07-24 02:08:35.056 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:45470 10 6438 1 2025-07-24 02:09:35.468 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:60806 10 6438 1 2025-07-24 02:10:35.871 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:38826 10 6438 1 2025-07-24 02:11:36.280 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:52076 10 6438 1 2025-07-24 02:12:39.912 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:12:39.827 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:12:39.552 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:12:39.736 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:12:39.819 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:12:36.683 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:43842 10 6438 1 2025-07-24 02:09:01.543 00:05:00.492 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-07-24 02:13:37.104 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:33926 10 6438 1 2025-07-24 02:10:01.544 00:05:00.487 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-07-24 02:14:37.515 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:35794 10 6438 1 2025-07-24 02:15:37.912 00:00:10.334 TCP 1.101.0.1:3000 -> 23.104.0.1:45714 10 6438 1 2025-07-24 02:16:38.287 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55630 10 6438 1 2025-07-24 02:17:39.858 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:17:39.869 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:17:39.943 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:17:39.690 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:17:39.774 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:17:38.695 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47326 10 6438 1 2025-07-24 02:18:39.112 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:53504 10 6438 1 2025-07-24 02:15:01.543 00:05:00.493 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-07-24 02:19:39.515 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:53636 10 6438 1 2025-07-24 02:16:01.546 00:05:00.488 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-07-24 02:20:39.920 00:00:10.981 TCP 1.101.0.1:3000 -> 23.104.0.1:49658 10 6438 1 2025-07-24 02:21:40.965 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44450 10 6438 1 2025-07-24 02:22:39.945 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:22:40.154 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:22:40.006 00:00:00.045 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:22:40.146 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:22:40.230 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:22:41.368 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:38902 10 6438 1 2025-07-24 02:23:41.773 00:00:10.466 TCP 1.101.0.1:3000 -> 23.104.0.1:58598 12 10350 1 2025-07-24 02:24:42.265 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:47756 10 6438 1 2025-07-24 02:21:01.544 00:05:00.501 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-07-24 02:25:42.670 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:36858 10 6438 1 2025-07-24 02:22:01.548 00:05:00.495 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-07-24 02:26:43.094 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:55784 10 6438 1 2025-07-24 02:27:39.863 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:27:40.286 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:27:39.985 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:27:40.191 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:27:40.202 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:27:43.500 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:48748 10 6438 1 2025-07-24 02:28:43.864 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:48442 10 6438 1 2025-07-24 02:29:44.276 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:49422 10 6438 1 2025-07-24 02:30:44.682 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:41352 10 6438 1 2025-07-24 02:27:01.548 00:05:00.499 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-07-24 02:31:45.110 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:41202 10 6438 1 2025-07-24 02:28:01.555 00:05:00.489 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-07-24 02:32:40.270 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:32:40.370 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:32:40.433 00:00:00.030 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:32:40.484 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:32:40.518 00:00:00.029 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:32:45.511 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46974 10 6438 1 2025-07-24 02:33:45.914 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:32868 10 6438 1 2025-07-24 02:34:46.315 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:39262 10 6438 1 2025-07-24 02:35:46.719 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:58234 10 6438 1 2025-07-24 02:36:47.133 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:44130 10 6438 1 2025-07-24 02:33:01.549 00:05:00.500 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-07-24 02:37:40.328 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:37:40.357 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:37:40.233 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:37:40.317 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:37:40.318 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:37:47.498 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:54422 10 6438 1 2025-07-24 02:34:01.551 00:05:00.500 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-07-24 02:38:47.900 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:44394 12 6542 1 2025-07-24 02:39:48.303 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:36294 10 6438 1 2025-07-24 02:40:48.716 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:60950 10 6438 1 2025-07-24 02:41:49.132 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:36258 10 6438 1 2025-07-24 02:42:40.495 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:42:40.416 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:42:40.551 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:42:40.385 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:42:40.411 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:42:49.494 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:46422 10 6438 1 2025-07-24 02:39:01.549 00:05:00.505 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-07-24 02:40:01.552 00:05:00.500 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-07-24 02:43:49.855 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:53870 10 6438 1 2025-07-24 02:44:50.278 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:49140 10 6438 1 2025-07-24 02:45:50.642 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54136 10 6438 1 2025-07-24 02:46:51.052 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:48346 10 6438 1 2025-07-24 02:47:40.356 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:47:40.574 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:47:40.463 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:47:40.551 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:47:40.440 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:47:51.422 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39518 10 6438 1 2025-07-24 02:45:01.549 00:05:00.505 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-07-24 02:48:51.828 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58710 10 6438 1 2025-07-24 02:46:01.552 00:05:00.501 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-07-24 02:49:52.237 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:43418 10 6438 1 2025-07-24 02:50:52.644 00:00:10.342 TCP 1.101.0.1:3000 -> 23.104.0.1:40216 10 6438 1 2025-07-24 02:51:53.026 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52442 10 6438 1 2025-07-24 02:52:40.615 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:52:40.626 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:52:40.720 00:00:00.026 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:52:40.532 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:52:40.698 00:00:00.028 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:52:53.437 00:00:10.437 TCP 1.101.0.1:3000 -> 23.104.0.1:42584 12 10352 1 2025-07-24 02:53:53.919 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:36506 10 6438 1 2025-07-24 02:51:01.551 00:05:00.509 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-07-24 02:54:54.327 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:34506 10 6438 1 2025-07-24 02:52:01.553 00:05:00.505 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-07-24 02:55:54.731 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:45874 10 6438 1 2025-07-24 02:56:55.140 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:60982 10 6438 1 2025-07-24 02:57:40.885 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-07-24 02:57:40.808 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-07-24 02:57:40.744 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-07-24 02:57:40.824 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:57:40.803 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-07-24 02:57:55.505 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56404 10 6438 1 Summary: total flows: 139, total bytes: 417652, total packets: 1016, avg bps: 911, avg pps: 0, avg bpp: 411 Time window: 2025-07-24 01:57:01 - 2025-07-24 02:58:05 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0024s User: 0.0016s Wall: 0.0020s flows/second: 69257.3 Runtime: 0.0020s