Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-18 11:58:58.897 00:00:10.392 TCP 1.101.0.1:3000 -> 23.104.0.1:40156 10 6452 1 2025-10-18 11:59:23.028 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 11:59:22.777 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 11:59:22.881 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 11:59:22.639 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 11:59:22.945 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 11:59:59.321 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:45368 10 6452 1 2025-10-18 12:00:59.724 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:47350 10 6452 1 2025-10-18 11:56:46.189 00:06:00.285 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-18 12:02:00.141 00:00:10.637 TCP 1.101.0.1:3000 -> 23.104.0.1:59512 10 6452 1 2025-10-18 12:03:00.812 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:49754 10 6452 1 2025-10-18 12:04:01.214 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47154 10 6452 1 2025-10-18 12:04:23.451 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:04:23.282 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:04:23.071 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:04:23.371 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:04:23.282 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 11:59:46.190 00:06:00.287 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-18 12:05:01.620 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:40564 10 6452 1 2025-10-18 12:06:02.022 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:33820 10 6452 1 2025-10-18 12:07:02.421 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:46712 10 6452 1 2025-10-18 12:08:02.830 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54490 10 6452 1 2025-10-18 12:03:46.192 00:06:00.284 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-18 12:09:03.230 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:58294 10 6452 1 2025-10-18 12:09:23.091 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 12:09:23.084 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:09:22.859 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:09:22.966 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:09:23.048 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:10:03.598 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:51330 10 6452 1 2025-10-18 12:11:04.022 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:58500 10 6452 1 2025-10-18 12:06:46.191 00:06:00.287 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-18 12:12:04.427 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:38258 10 6452 1 2025-10-18 12:13:04.842 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:56954 10 6452 1 2025-10-18 12:14:23.141 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:14:05.273 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52418 10 6452 1 2025-10-18 12:14:23.249 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 12:14:23.246 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:14:23.174 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:14:23.059 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:15:05.681 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:48654 10 6452 1 2025-10-18 12:10:46.194 00:06:00.282 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-18 12:16:06.068 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:34136 10 6452 1 2025-10-18 12:17:06.471 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:48170 10 6452 1 2025-10-18 12:18:06.887 00:00:10.353 TCP 1.101.0.1:3000 -> 23.104.0.1:34942 10 6452 1 2025-10-18 12:13:46.191 00:06:00.287 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-18 12:19:23.398 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:19:07.275 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:40144 10 6452 1 2025-10-18 12:19:23.442 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 12:19:23.314 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:19:23.336 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:19:23.315 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:20:07.646 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:58480 10 6452 1 2025-10-18 12:21:08.006 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:50378 10 6452 1 2025-10-18 12:22:08.407 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:42244 10 6452 1 2025-10-18 12:17:46.198 00:06:00.281 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-18 12:23:08.813 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:58894 10 6452 1 2025-10-18 12:24:09.227 00:00:10.392 TCP 1.101.0.1:3000 -> 23.104.0.1:34828 10 6452 1 2025-10-18 12:24:23.595 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:24:23.514 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:24:23.434 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 12:24:23.642 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:24:23.200 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:25:09.640 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:44516 10 6452 1 2025-10-18 12:20:46.198 00:06:00.283 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-18 12:26:10.041 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:49650 10 6452 1 2025-10-18 12:27:10.450 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:36364 10 6452 1 2025-10-18 12:28:10.856 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:38320 10 6452 1 2025-10-18 12:29:23.921 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 12:29:11.272 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:32950 10 6452 1 2025-10-18 12:29:23.785 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:29:23.370 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:29:23.852 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:29:23.935 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:24:46.202 00:06:00.277 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-18 12:30:11.671 00:00:10.986 TCP 1.101.0.1:3000 -> 23.104.0.1:56704 10 6452 1 2025-10-18 12:31:12.697 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:38636 10 6452 1 2025-10-18 12:32:13.067 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55620 10 6452 1 2025-10-18 12:27:46.200 00:06:00.285 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-18 12:33:13.471 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:53708 10 6452 1 2025-10-18 12:34:23.698 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 12:34:23.767 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:34:23.543 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:34:23.771 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:34:13.837 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:41524 10 6452 1 2025-10-18 12:34:23.854 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:35:14.233 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:56202 10 6452 1 2025-10-18 12:36:14.597 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:38748 10 6452 1 2025-10-18 12:31:46.204 00:06:00.279 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-18 12:37:14.958 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50480 10 6452 1 2025-10-18 12:38:15.368 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:47712 10 6452 1 2025-10-18 12:39:23.884 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:39:23.802 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:39:23.795 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 12:39:23.851 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:39:23.745 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:39:15.774 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:55324 10 6452 1 2025-10-18 12:34:46.202 00:06:00.284 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-18 12:40:16.187 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:43418 10 6452 1 2025-10-18 12:41:16.588 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:43506 10 6452 1 2025-10-18 12:42:16.998 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:37180 10 6452 1 2025-10-18 12:43:17.401 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:50514 10 6452 1 2025-10-18 12:38:46.204 00:06:00.280 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-18 12:44:23.732 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:44:23.909 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 12:44:23.649 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:44:23.965 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:44:23.649 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:44:17.798 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39214 12 6556 1 2025-10-18 12:45:18.208 00:00:11.086 TCP 1.101.0.1:3000 -> 23.104.0.1:59710 10 6452 1 2025-10-18 12:46:19.337 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:59930 10 6452 1 2025-10-18 12:41:46.205 00:06:00.282 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-18 12:47:19.749 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:39590 10 6452 1 2025-10-18 12:48:20.116 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:59936 10 6452 1 2025-10-18 12:49:24.295 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:49:23.861 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 12:49:23.865 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:49:23.899 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:49:24.211 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:49:20.529 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:41468 10 6452 1 2025-10-18 12:50:20.931 00:00:10.341 TCP 1.101.0.1:3000 -> 23.104.0.1:55250 10 6452 1 2025-10-18 12:45:46.209 00:06:00.276 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-18 12:51:21.311 00:00:11.046 TCP 1.101.0.1:3000 -> 23.104.0.1:54280 10 6452 1 2025-10-18 12:52:22.410 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:58176 10 6452 1 2025-10-18 12:53:22.812 00:00:10.337 TCP 1.101.0.1:3000 -> 23.104.0.1:42386 10 6452 1 2025-10-18 12:48:46.211 00:06:00.278 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-18 12:54:24.225 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-18 12:54:24.277 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-18 12:54:23.944 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:54:24.043 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-18 12:54:24.126 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-18 12:54:23.187 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:60240 10 6452 1 2025-10-18 12:55:23.596 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:33806 10 6452 1 2025-10-18 12:56:23.995 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:45796 10 6452 1 2025-10-18 12:57:24.360 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:56100 10 6452 1 2025-10-18 12:52:46.215 00:06:00.272 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-18 12:58:24.758 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:51976 10 6452 1 Summary: total flows: 137, total bytes: 416981, total packets: 1020, avg bps: 896, avg pps: 0, avg bpp: 408 Time window: 2025-10-18 11:56:46 - 2025-10-18 12:58:46 Total flows processed: 137, passed: 137, Blocks skipped: 0, Bytes read: 14312 Sys: 0.0028s User: 0.0019s Wall: 0.0021s flows/second: 66177.5 Runtime: 0.0021s