Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-14 09:59:35.773 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:58754 10 6452 1 2025-10-14 09:55:44.477 00:06:00.004 TCP 179.21.23.21:38570 -> 179.21.23.23:179 13 809 1 2025-10-14 09:59:44.043 00:01:00.442 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-14 10:00:36.188 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:57498 10 6452 1 2025-10-14 10:01:36.548 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:38476 10 6452 1 2025-10-14 10:02:24.968 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:02:24.906 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:02:25.106 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:02:25.115 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:02:25.191 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:02:36.908 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:38846 10 6452 1 2025-10-14 10:03:37.309 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:40076 10 6452 1 2025-10-14 10:04:37.710 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41656 10 6452 1 2025-10-14 10:01:44.043 00:04:00.442 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-10-14 10:05:38.138 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:51074 10 6452 1 2025-10-14 10:06:38.505 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55038 10 6452 1 2025-10-14 10:07:25.340 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:07:25.405 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:07:25.462 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:07:25.361 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:07:25.422 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:02:44.046 00:06:00.437 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-14 10:07:38.908 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:46566 10 6452 1 2025-10-14 10:08:39.274 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:40676 10 6452 1 2025-10-14 10:09:39.636 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:50114 10 6452 1 2025-10-14 10:10:40.035 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:48768 10 6452 1 2025-10-14 10:06:44.044 00:06:00.442 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-14 10:11:40.440 00:00:10.440 TCP 1.101.0.1:3000 -> 23.104.0.1:43440 12 10369 1 2025-10-14 10:12:25.527 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:12:25.369 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:12:25.265 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:12:25.197 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:12:25.445 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:12:40.918 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:40066 10 6452 1 2025-10-14 10:13:41.283 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58620 10 6452 1 2025-10-14 10:09:44.046 00:06:00.438 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-14 10:14:41.689 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60152 10 6452 1 2025-10-14 10:15:42.112 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54984 10 6452 1 2025-10-14 10:16:42.513 00:00:10.483 TCP 1.101.0.1:3000 -> 23.104.0.1:50002 10 6452 1 2025-10-14 10:17:25.286 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:17:25.242 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:17:25.290 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:17:25.070 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:17:25.373 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:17:43.037 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:37402 10 6452 1 2025-10-14 10:13:44.046 00:06:00.001 TCP 179.21.23.23:179 -> 179.21.23.21:38570 13 809 1 2025-10-14 10:18:43.418 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:38016 10 6452 1 2025-10-14 10:19:43.823 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:54740 10 6452 1 2025-10-14 10:16:44.050 00:04:00.436 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-10-14 10:20:44.191 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:53128 10 6452 1 2025-10-14 10:21:44.550 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:52940 10 6452 1 2025-10-14 10:22:25.274 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:22:25.552 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:22:25.425 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:22:25.550 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:22:25.634 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:22:44.947 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:36844 10 6452 1 2025-10-14 10:23:45.364 00:00:10.415 TCP 1.101.0.1:3000 -> 23.104.0.1:54966 11 6504 1 2025-10-14 10:19:44.488 00:06:00.001 TCP 179.21.23.23:179 -> 179.21.23.21:38570 13 790 1 2025-10-14 10:24:45.820 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:33890 10 6452 1 2025-10-14 10:21:44.054 00:04:00.433 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-10-14 10:25:46.229 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:44574 10 6452 1 2025-10-14 10:26:46.640 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:35822 10 6452 1 2025-10-14 10:27:25.548 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:27:25.942 00:00:00.026 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:27:25.476 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:27:25.616 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:27:25.698 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:26:44.050 00:01:00.439 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-14 10:27:47.056 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:35452 10 6452 1 2025-10-14 10:28:47.461 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48190 10 6452 1 2025-10-14 10:29:47.861 00:00:10.346 TCP 1.101.0.1:3000 -> 23.104.0.1:38932 10 6452 1 2025-10-14 10:30:48.243 00:00:10.733 TCP 1.101.0.1:3000 -> 23.104.0.1:35194 10 6452 1 2025-10-14 10:26:44.053 00:06:00.435 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-14 10:31:49.011 00:00:10.315 TCP 1.101.0.1:3000 -> 23.104.0.1:34110 10 6452 1 2025-10-14 10:32:25.752 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:32:25.676 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:32:25.672 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:32:25.961 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:32:26.044 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:28:44.053 00:04:00.440 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-10-14 10:32:49.364 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:53232 10 6452 1 2025-10-14 10:33:49.763 00:00:11.157 TCP 1.101.0.1:3000 -> 23.104.0.1:59542 10 6452 1 2025-10-14 10:34:50.959 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:56058 10 6452 1 2025-10-14 10:35:51.359 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:37542 10 6452 1 2025-10-14 10:36:51.764 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:60724 10 6452 1 2025-10-14 10:37:25.781 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:37:25.701 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:37:25.783 00:00:00.026 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:37:25.712 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:37:25.795 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:33:44.052 00:04:00.440 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-10-14 10:37:52.184 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:57482 10 6452 1 2025-10-14 10:33:44.055 00:06:00.004 TCP 179.21.23.21:38570 -> 179.21.23.23:179 13 790 1 2025-10-14 10:38:52.596 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:60344 10 6452 1 2025-10-14 10:39:52.952 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:49872 10 6452 1 2025-10-14 10:40:53.364 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:38180 10 6452 1 2025-10-14 10:41:53.765 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:60322 10 6452 1 2025-10-14 10:42:25.874 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:42:25.634 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:42:25.634 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:42:25.910 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:42:25.718 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:42:54.169 00:00:10.649 TCP 1.101.0.1:3000 -> 23.104.0.1:56914 10 6452 1 2025-10-14 10:38:44.056 00:06:00.002 TCP 179.21.23.23:179 -> 179.21.23.21:38570 13 809 1 2025-10-14 10:43:54.849 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:55464 10 6452 1 2025-10-14 10:39:44.490 00:06:00.007 TCP 179.21.23.21:38570 -> 179.21.23.23:179 13 809 1 2025-10-14 10:44:55.267 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:56548 10 6452 1 2025-10-14 10:45:55.675 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:49912 10 6452 1 2025-10-14 10:46:56.097 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:41888 10 6452 1 2025-10-14 10:47:25.999 00:00:00.043 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:47:25.948 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:47:25.825 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:47:25.945 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:47:26.027 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:47:56.498 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:47400 10 6452 1 2025-10-14 10:48:56.903 00:00:10.723 TCP 1.101.0.1:3000 -> 23.104.0.1:40786 12 6556 1 2025-10-14 10:44:44.501 00:06:00.002 TCP 179.21.23.23:179 -> 179.21.23.21:38570 13 790 1 2025-10-14 10:49:57.663 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:50066 10 6452 1 2025-10-14 10:50:58.093 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:58926 10 6452 1 2025-10-14 10:46:44.060 00:06:00.438 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-14 10:51:58.507 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:34128 10 6452 1 2025-10-14 10:52:26.246 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:52:26.146 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:52:26.114 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:52:26.087 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:52:26.171 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:52:58.911 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46436 10 6452 1 2025-10-14 10:53:59.315 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49382 10 6452 1 2025-10-14 10:54:59.720 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:60806 10 6452 1 2025-10-14 10:56:00.146 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:52344 10 6452 1 2025-10-14 10:51:44.061 00:06:00.443 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-14 10:57:00.547 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58382 10 6452 1 2025-10-14 10:57:26.271 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-14 10:57:26.273 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-14 10:57:26.165 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:57:26.230 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-14 10:57:26.313 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-14 10:53:44.063 00:04:00.438 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-10-14 10:58:00.972 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:41650 10 6452 1 Summary: total flows: 140, total bytes: 414815, total packets: 1018, avg bps: 885, avg pps: 0, avg bpp: 407 Time window: 2025-10-14 09:55:44 - 2025-10-14 10:58:11 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0048s User: 0.0010s Wall: 0.0020s flows/second: 68566.4 Runtime: 0.0021s