Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-20 02:59:00.842 00:00:21.676 TCP 1.101.0.1:3000 -> 23.104.0.1:54802 10 6452 1 2025-10-20 03:00:09.847 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:00:09.879 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:00:09.753 00:00:00.030 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:00:09.836 00:00:00.029 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:00:10.076 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:00:12.577 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:39078 10 6452 1 2025-10-20 02:56:46.983 00:05:00.246 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-20 03:01:12.982 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58766 10 6452 1 2025-10-20 02:57:46.982 00:05:00.251 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-20 03:02:13.389 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:44740 10 6452 1 2025-10-20 03:03:13.756 00:00:10.459 TCP 1.101.0.1:3000 -> 23.104.0.1:53834 12 10375 1 2025-10-20 03:04:14.257 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:51118 10 6452 1 2025-10-20 03:05:09.600 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:05:10.090 00:00:00.035 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:05:10.008 00:00:00.035 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:05:10.012 00:00:00.029 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:05:10.131 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:05:14.621 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:34700 10 6452 1 2025-10-20 03:06:15.020 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56200 10 6452 1 2025-10-20 03:02:46.991 00:05:00.240 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-20 03:07:15.425 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:55396 10 6452 1 2025-10-20 03:03:46.989 00:05:00.244 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-20 03:08:15.842 00:00:10.388 TCP 1.101.0.1:3000 -> 23.104.0.1:43536 10 6452 1 2025-10-20 03:09:16.268 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:38390 10 6452 1 2025-10-20 03:10:10.121 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:10:10.285 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:10:10.146 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:10:10.322 00:00:00.026 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:10:10.405 00:00:00.026 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:10:16.631 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:43482 10 6452 1 2025-10-20 03:11:17.051 00:00:10.356 TCP 1.101.0.1:3000 -> 23.104.0.1:55584 10 6452 1 2025-10-20 03:12:17.449 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:51470 10 6452 1 2025-10-20 03:08:46.991 00:05:00.242 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-20 03:13:17.852 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:49558 10 6452 1 2025-10-20 03:09:46.990 00:05:00.247 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-20 03:14:18.270 00:00:10.903 TCP 1.101.0.1:3000 -> 23.104.0.1:59614 10 6452 1 2025-10-20 03:15:09.929 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:15:10.244 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:15:10.303 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:15:10.054 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:15:10.160 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:15:19.210 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41676 10 6452 1 2025-10-20 03:16:19.618 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:37154 12 6556 1 2025-10-20 03:17:20.024 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:58916 10 6452 1 2025-10-20 03:18:20.423 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:60878 10 6452 1 2025-10-20 03:14:46.992 00:05:00.244 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-20 03:19:20.833 00:00:10.391 TCP 1.101.0.1:3000 -> 23.104.0.1:59996 10 6452 1 2025-10-20 03:15:46.993 00:05:00.252 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-20 03:20:10.339 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:20:10.263 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:20:10.399 00:00:00.030 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:20:10.373 00:00:00.030 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:20:10.460 00:00:00.026 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:20:21.266 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:38560 10 6452 1 2025-10-20 03:21:21.669 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:32854 10 6452 1 2025-10-20 03:22:22.119 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:52946 10 6452 1 2025-10-20 03:23:22.498 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53542 10 6452 1 2025-10-20 03:24:22.900 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:38228 12 6556 1 2025-10-20 03:20:46.998 00:05:00.244 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-20 03:25:10.473 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:25:10.307 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:25:10.494 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:25:10.469 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:25:10.552 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:25:23.319 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39036 10 6452 1 2025-10-20 03:21:46.994 00:05:00.249 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-20 03:26:23.727 00:00:11.886 TCP 1.101.0.1:3000 -> 23.104.0.1:45464 10 6452 1 2025-10-20 03:27:25.656 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:44654 10 6452 1 2025-10-20 03:28:26.074 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:50990 10 6452 1 2025-10-20 03:29:26.482 00:00:10.865 TCP 1.101.0.1:3000 -> 23.104.0.1:35440 10 6452 1 2025-10-20 03:30:10.862 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:30:10.734 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:30:10.812 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:30:10.521 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:30:10.779 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:30:27.381 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:60502 10 6452 1 2025-10-20 03:31:27.785 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48550 10 6452 1 2025-10-20 03:27:46.997 00:05:00.247 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-20 03:26:47.001 00:06:00.241 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-20 03:32:28.193 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:37626 10 6452 1 2025-10-20 03:33:28.555 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:42804 10 6452 1 2025-10-20 03:34:28.957 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:43836 10 6452 1 2025-10-20 03:35:10.598 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:35:10.884 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:35:10.530 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:35:10.756 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:35:10.839 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:35:29.320 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:44416 10 6452 1 2025-10-20 03:36:29.723 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:50418 10 6452 1 2025-10-20 03:37:30.112 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:42026 10 6452 1 2025-10-20 03:33:47.037 00:06:00.210 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-20 03:38:30.527 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:41552 10 6452 1 2025-10-20 03:33:47.041 00:06:00.206 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-20 03:39:30.927 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:42188 10 6452 1 2025-10-20 03:40:10.655 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:40:10.833 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:40:10.662 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:40:10.424 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:40:10.573 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:40:31.338 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:52722 10 6452 1 2025-10-20 03:41:31.741 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:37634 10 6452 1 2025-10-20 03:42:32.107 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39544 10 6452 1 2025-10-20 03:43:32.510 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:41728 10 6452 1 2025-10-20 03:44:32.915 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:37302 10 6452 1 2025-10-20 03:45:10.926 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:45:10.803 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:45:10.799 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:45:10.753 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:45:10.845 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:45:33.322 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:35374 10 6452 1 2025-10-20 03:40:47.039 00:06:00.209 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-20 03:40:47.043 00:06:00.204 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-20 03:46:33.722 00:00:10.317 TCP 1.101.0.1:3000 -> 23.104.0.1:35052 10 6452 1 2025-10-20 03:47:34.107 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:58812 10 6452 1 2025-10-20 03:48:34.505 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:48480 10 6452 1 2025-10-20 03:49:34.908 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:59538 10 6452 1 2025-10-20 03:50:12.641 00:00:00.039 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:50:11.879 00:00:00.032 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:50:12.050 00:00:00.025 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:50:11.992 00:00:00.029 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:50:12.076 00:00:00.028 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:50:35.334 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:35286 10 6452 1 2025-10-20 03:51:35.742 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:52694 10 6452 1 2025-10-20 03:47:47.044 00:06:00.206 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-20 03:52:36.151 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:38496 10 6452 1 2025-10-20 03:47:47.041 00:06:00.211 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-20 03:53:36.516 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:33612 10 6452 1 2025-10-20 03:54:36.917 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:34886 10 6452 1 2025-10-20 03:55:11.057 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-20 03:55:11.114 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-20 03:55:10.819 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:55:10.950 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-20 03:55:11.032 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-20 03:55:37.315 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:45140 10 6452 1 2025-10-20 03:56:37.690 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:48144 10 6452 1 2025-10-20 03:57:38.056 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57496 10 6452 1 2025-10-20 03:58:38.458 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:53264 11 6504 1 Summary: total flows: 138, total bytes: 420568, total packets: 1017, avg bps: 903, avg pps: 0, avg bpp: 413 Time window: 2025-10-20 02:56:46 - 2025-10-20 03:58:48 Total flows processed: 138, passed: 138, Blocks skipped: 0, Bytes read: 14416 Sys: 0.0042s User: 0.0017s Wall: 0.0039s flows/second: 35052.0 Runtime: 0.0040s