Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-16 19:59:22.421 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:39866 10 6452 1 2025-10-16 19:54:45.287 00:06:00.353 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-16 20:00:22.784 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:42460 10 6452 1 2025-10-16 19:55:45.285 00:06:00.358 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-16 20:01:23.189 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:48936 10 6452 1 2025-10-16 20:02:23.596 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:39832 10 6452 1 2025-10-16 20:03:34.904 00:00:00.026 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:03:34.757 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:03:23.966 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:43482 10 6452 1 2025-10-16 20:03:34.828 00:00:00.025 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:03:34.797 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:03:34.822 00:00:00.025 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:04:24.368 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:51132 10 6452 1 2025-10-16 20:05:24.775 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:49418 10 6452 1 2025-10-16 20:06:25.196 00:00:10.356 TCP 1.101.0.1:3000 -> 23.104.0.1:41522 10 6452 1 2025-10-16 20:01:45.288 00:06:00.354 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-16 20:07:25.592 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:38750 10 6452 1 2025-10-16 20:02:45.285 00:06:00.359 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-16 20:08:34.915 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:08:34.930 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:08:34.828 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:08:34.911 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:08:35.055 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:08:25.997 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:33190 11 6504 1 2025-10-16 20:09:26.414 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:55188 10 6452 1 2025-10-16 20:10:26.778 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58014 10 6452 1 2025-10-16 20:11:27.189 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:55028 10 6452 1 2025-10-16 20:12:27.612 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:33764 10 6452 1 2025-10-16 20:13:34.953 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:13:34.928 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:13:35.170 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:13:35.094 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:13:27.975 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:40558 10 6452 1 2025-10-16 20:13:35.088 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:08:45.290 00:06:00.354 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-16 20:14:28.390 00:00:11.041 TCP 1.101.0.1:3000 -> 23.104.0.1:54680 10 6452 1 2025-10-16 20:09:45.288 00:06:00.359 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-16 20:15:29.471 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:55922 10 6452 1 2025-10-16 20:16:29.875 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59988 10 6452 1 2025-10-16 20:17:30.279 00:00:10.868 TCP 1.101.0.1:3000 -> 23.104.0.1:59338 10 6452 1 2025-10-16 20:18:35.086 00:00:00.051 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:18:35.005 00:00:00.042 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:18:35.134 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:18:35.058 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:18:35.004 00:00:00.050 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:18:31.179 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:60116 10 6452 1 2025-10-16 20:19:31.580 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:44430 10 6452 1 2025-10-16 20:20:31.942 00:00:10.741 TCP 1.101.0.1:3000 -> 23.104.0.1:44912 10 6452 1 2025-10-16 20:15:45.291 00:06:00.355 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-16 20:21:32.722 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:33516 10 6452 1 2025-10-16 20:16:45.289 00:06:00.360 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-16 20:22:33.138 00:00:10.398 TCP 1.101.0.1:3000 -> 23.104.0.1:42880 12 10375 1 2025-10-16 20:23:35.429 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:23:35.256 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:23:34.991 00:00:00.054 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:23:35.258 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:23:35.342 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:23:33.583 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36510 10 6452 1 2025-10-16 20:24:33.986 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:59074 10 6452 1 2025-10-16 20:25:34.403 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:48032 10 6452 1 2025-10-16 20:26:34.773 00:00:10.892 TCP 1.101.0.1:3000 -> 23.104.0.1:56654 10 6452 1 2025-10-16 20:22:45.293 00:06:00.356 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-16 20:27:35.707 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:52116 10 6452 1 2025-10-16 20:28:35.550 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:28:35.689 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:28:35.371 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:28:35.642 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:28:35.724 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:28:36.113 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:48012 10 6452 1 2025-10-16 20:23:45.291 00:06:00.361 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-16 20:29:36.547 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41396 10 6452 1 2025-10-16 20:30:36.948 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:44712 10 6452 1 2025-10-16 20:31:37.361 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:52144 10 6452 1 2025-10-16 20:32:37.767 00:00:10.344 TCP 1.101.0.1:3000 -> 23.104.0.1:60398 10 6452 1 2025-10-16 20:33:35.396 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:33:35.530 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:33:35.584 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:33:35.582 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:33:35.613 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:33:38.149 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:51170 10 6452 1 2025-10-16 20:29:45.296 00:06:00.360 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-16 20:34:38.556 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:39092 10 6452 1 2025-10-16 20:35:38.961 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36564 10 6452 1 2025-10-16 20:30:45.293 00:06:00.365 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-16 20:36:39.364 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46304 10 6452 1 2025-10-16 20:37:39.771 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:43144 10 6452 1 2025-10-16 20:38:35.519 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:38:35.574 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:38:35.522 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:38:35.516 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:38:35.599 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:38:40.185 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:56150 10 6452 1 2025-10-16 20:39:40.595 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:35684 10 6452 1 2025-10-16 20:40:41.005 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:44946 10 6452 1 2025-10-16 20:36:45.305 00:06:00.352 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-16 20:41:41.410 00:00:10.915 TCP 1.101.0.1:3000 -> 23.104.0.1:38516 14 14286 1 2025-10-16 20:37:45.302 00:06:00.357 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-16 20:42:42.366 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:49380 10 6452 1 2025-10-16 20:43:35.643 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:43:35.544 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:43:35.448 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:43:35.719 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:43:35.803 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:43:42.769 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:52672 10 6452 1 2025-10-16 20:44:43.186 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:54696 10 6452 1 2025-10-16 20:45:43.590 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37256 10 6452 1 2025-10-16 20:46:43.990 00:00:10.633 TCP 1.101.0.1:3000 -> 23.104.0.1:51112 10 6452 1 2025-10-16 20:47:44.668 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:59350 10 6452 1 2025-10-16 20:48:35.844 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:48:35.772 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:48:35.899 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:48:35.775 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:48:35.858 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:43:45.307 00:06:00.353 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-16 20:48:45.031 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56510 10 6452 1 2025-10-16 20:44:45.304 00:06:00.358 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-16 20:49:45.436 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:45310 10 6452 1 2025-10-16 20:50:45.841 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:39176 10 6452 1 2025-10-16 20:51:46.255 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49712 10 6452 1 2025-10-16 20:52:46.660 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:52488 10 6452 1 2025-10-16 20:53:35.787 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:53:35.865 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:53:35.457 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:53:35.948 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:53:36.031 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-16 20:53:47.070 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:41946 10 6452 1 2025-10-16 20:54:47.432 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:38506 10 6452 1 2025-10-16 20:50:45.309 00:06:00.353 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-16 20:55:47.833 00:00:10.345 TCP 1.101.0.1:3000 -> 23.104.0.1:54872 10 6452 1 2025-10-16 20:51:45.306 00:06:00.357 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-16 20:56:48.215 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56738 10 6452 1 2025-10-16 20:57:48.620 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:57860 10 6452 1 2025-10-16 20:58:35.723 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-16 20:58:35.935 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-16 20:58:36.104 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:58:36.094 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-16 20:58:36.178 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 Summary: total flows: 137, total bytes: 423095, total packets: 1029, avg bps: 883, avg pps: 0, avg bpp: 411 Time window: 2025-10-16 19:54:45 - 2025-10-16 20:58:36 Total flows processed: 137, passed: 137, Blocks skipped: 0, Bytes read: 14312 Sys: 0.0031s User: 0.0015s Wall: 0.0020s flows/second: 68841.5 Runtime: 0.0020s