Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-28 16:53:51.458 00:06:00.324 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-28 16:59:18.422 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 16:59:18.340 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 16:59:18.330 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 16:59:05.787 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:48266 10 6452 1 2025-10-28 16:59:18.400 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 16:59:18.272 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:00:06.214 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:47020 10 6452 1 2025-10-28 17:01:06.634 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:38494 10 6452 1 2025-10-28 17:02:06.996 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:56374 10 6452 1 2025-10-28 16:57:51.461 00:06:00.320 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-28 17:03:07.405 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:49956 10 6452 1 2025-10-28 17:04:18.303 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:04:18.222 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:04:18.077 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:04:07.814 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:42270 10 6452 1 2025-10-28 17:04:18.299 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:04:18.384 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:05:08.216 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:44402 10 6452 1 2025-10-28 17:00:51.460 00:06:00.327 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-28 17:06:08.622 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:51612 10 6452 1 2025-10-28 17:07:09.028 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54472 10 6452 1 2025-10-28 17:08:09.434 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:60798 10 6452 1 2025-10-28 17:09:18.314 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:09:17.873 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:09:18.085 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:09:18.397 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:09:18.169 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:09:09.841 00:00:10.351 TCP 1.101.0.1:3000 -> 23.104.0.1:41358 10 6452 1 2025-10-28 17:04:51.465 00:06:00.322 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-28 17:10:10.233 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:59530 10 6452 1 2025-10-28 17:11:10.641 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:51220 10 6452 1 2025-10-28 17:12:11.059 00:00:10.531 TCP 1.101.0.1:3000 -> 23.104.0.1:51176 10 6452 1 2025-10-28 17:07:51.462 00:06:00.328 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-28 17:13:11.626 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:58194 10 6452 1 2025-10-28 17:14:18.411 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:14:18.408 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:14:18.270 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:14:18.328 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:14:18.410 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:14:11.985 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:41672 10 6452 1 2025-10-28 17:15:12.390 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:49916 10 6452 1 2025-10-28 17:16:12.791 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35142 10 6452 1 2025-10-28 17:11:51.466 00:06:00.324 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-28 17:17:13.193 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:59906 10 6452 1 2025-10-28 17:18:13.559 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:38270 10 6452 1 2025-10-28 17:19:18.293 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:19:18.538 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:19:18.359 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:19:18.735 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:19:18.818 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:19:13.924 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:59376 10 6452 1 2025-10-28 17:14:51.464 00:06:00.328 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-28 17:20:14.341 00:00:10.675 TCP 1.101.0.1:3000 -> 23.104.0.1:33456 10 6452 1 2025-10-28 17:21:15.066 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:33018 10 6452 1 2025-10-28 17:22:15.474 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:34952 10 6452 1 2025-10-28 17:23:15.878 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:56236 10 6452 1 2025-10-28 17:18:51.467 00:06:00.325 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-28 17:24:18.458 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:24:18.401 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:24:19.112 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:24:18.633 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:24:19.196 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:24:16.245 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:37622 10 6452 1 2025-10-28 17:25:16.666 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58236 10 6452 1 2025-10-28 17:26:17.102 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:34460 10 6452 1 2025-10-28 17:21:51.464 00:06:00.333 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-28 17:27:17.531 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47350 10 6452 1 2025-10-28 17:28:17.930 00:00:10.390 TCP 1.101.0.1:3000 -> 23.104.0.1:53986 10 6452 1 2025-10-28 17:29:18.730 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:29:18.727 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:29:18.686 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:29:18.771 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:29:18.854 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:29:18.358 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:34134 10 6452 1 2025-10-28 17:30:18.714 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:47168 10 6452 1 2025-10-28 17:25:51.467 00:06:00.328 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-28 17:31:19.115 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:42232 10 6452 1 2025-10-28 17:32:19.481 00:00:10.474 TCP 1.101.0.1:3000 -> 23.104.0.1:38322 14 14292 1 2025-10-28 17:33:19.993 00:00:10.538 TCP 1.101.0.1:3000 -> 23.104.0.1:42172 10 6452 1 2025-10-28 17:28:51.465 00:06:00.334 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-28 17:34:18.951 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:34:18.863 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:34:18.706 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:34:18.628 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:34:18.868 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:34:20.572 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36572 10 6452 1 2025-10-28 17:35:20.977 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:57068 10 6452 1 2025-10-28 17:36:21.383 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:53858 10 6452 1 2025-10-28 17:37:21.784 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40812 10 6452 1 2025-10-28 17:32:51.469 00:06:00.328 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-28 17:38:22.184 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41914 10 6452 1 2025-10-28 17:39:18.994 00:00:00.046 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:39:18.736 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:39:18.748 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:39:18.731 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:39:18.813 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:39:22.587 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:60952 10 6452 1 2025-10-28 17:40:22.989 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:39806 10 6452 1 2025-10-28 17:35:51.469 00:06:00.335 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-28 17:41:23.398 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:45242 10 6452 1 2025-10-28 17:42:23.814 00:00:10.444 TCP 1.101.0.1:3000 -> 23.104.0.1:41006 12 10369 1 2025-10-28 17:43:24.297 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:42622 10 6452 1 2025-10-28 17:44:19.370 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:44:19.230 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:44:19.402 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:44:19.224 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:44:19.288 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:44:24.701 00:00:10.583 TCP 1.101.0.1:3000 -> 23.104.0.1:33854 10 6452 1 2025-10-28 17:39:51.472 00:06:00.328 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-28 17:45:25.322 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47036 10 6452 1 2025-10-28 17:46:25.723 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:52096 10 6452 1 2025-10-28 17:47:26.112 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:42136 10 6452 1 2025-10-28 17:42:51.471 00:06:00.336 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-28 17:48:26.515 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:43478 10 6452 1 2025-10-28 17:49:19.338 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:49:18.796 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:49:19.255 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:49:19.386 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:49:19.094 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:49:26.919 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:33604 10 6452 1 2025-10-28 17:50:27.312 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:33502 10 6452 1 2025-10-28 17:51:27.738 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:52464 10 6452 1 2025-10-28 17:46:51.474 00:06:00.331 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-28 17:52:28.159 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:53330 10 6452 1 2025-10-28 17:53:28.563 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:40032 10 6452 1 2025-10-28 17:54:19.135 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-28 17:54:19.233 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-28 17:54:19.154 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:54:18.987 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-28 17:54:19.069 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-28 17:54:28.964 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:59154 10 6452 1 2025-10-28 17:49:51.472 00:06:00.336 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-28 17:55:29.365 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:47486 10 6452 1 2025-10-28 17:56:29.781 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:41048 10 6452 1 2025-10-28 17:57:30.147 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37046 10 6452 1 2025-10-28 17:58:30.552 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:48534 10 6452 1 Summary: total flows: 137, total bytes: 428634, total packets: 1024, avg bps: 881, avg pps: 0, avg bpp: 418 Time window: 2025-10-28 16:53:51 - 2025-10-28 17:58:40 Total flows processed: 137, passed: 137, Blocks skipped: 0, Bytes read: 14312 Sys: 0.0057s User: 0.0000s Wall: 0.0019s flows/second: 72370.2 Runtime: 0.0019s