Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-30 21:53:52.482 00:06:00.387 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 21:58:49.929 00:00:10.345 TCP 1.101.0.1:3000 -> 23.104.0.1:50280 10 6452 1 2025-10-30 21:59:50.318 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:41930 10 6452 1 2025-10-30 22:00:21.921 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:00:21.863 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:00:21.890 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:00:21.973 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:00:22.055 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:00:50.720 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:55518 10 6452 1 2025-10-30 22:01:51.109 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:54212 10 6452 1 2025-10-30 22:02:51.508 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60006 10 6452 1 2025-10-30 21:58:52.482 00:06:00.391 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 22:03:51.920 00:00:10.438 TCP 1.101.0.1:3000 -> 23.104.0.1:46322 12 10375 1 2025-10-30 22:04:52.392 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:59340 10 6452 1 2025-10-30 22:05:21.939 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:05:22.093 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:05:21.868 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:05:21.941 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:05:22.024 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:00:52.485 00:06:00.386 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 22:05:52.793 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37262 10 6452 1 2025-10-30 22:06:53.196 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:43626 10 6452 1 2025-10-30 22:07:53.595 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:56682 10 6452 1 2025-10-30 22:08:53.995 00:00:10.679 TCP 1.101.0.1:3000 -> 23.104.0.1:60714 10 6452 1 2025-10-30 22:09:54.713 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52344 10 6452 1 2025-10-30 22:10:21.961 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:10:22.097 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:10:22.109 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:10:21.879 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:10:21.995 00:00:00.046 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:05:52.488 00:06:00.386 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 22:10:55.123 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:34322 10 6452 1 2025-10-30 22:11:55.531 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:59146 10 6452 1 2025-10-30 22:07:52.488 00:06:00.385 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 22:12:55.930 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:51598 10 6452 1 2025-10-30 22:13:56.353 00:00:10.357 TCP 1.101.0.1:3000 -> 23.104.0.1:44648 10 6452 1 2025-10-30 22:14:56.750 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:53486 10 6452 1 2025-10-30 22:15:22.217 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:15:22.207 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:15:22.227 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:15:22.254 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:15:22.336 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:15:57.156 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:52764 10 6452 1 2025-10-30 22:16:57.566 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:38496 10 6452 1 2025-10-30 22:12:52.487 00:06:00.390 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 22:17:57.972 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:44672 10 6452 1 2025-10-30 22:18:58.399 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:46696 10 6452 1 2025-10-30 22:14:52.493 00:06:00.383 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 22:19:58.807 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:54502 10 6452 1 2025-10-30 22:20:22.291 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:20:22.357 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:20:22.256 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:20:22.232 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:20:22.316 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:20:59.214 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:54534 10 6452 1 2025-10-30 22:21:59.575 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:53868 10 6452 1 2025-10-30 22:22:59.976 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:38862 10 6452 1 2025-10-30 22:24:00.394 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:50700 10 6452 1 2025-10-30 22:19:52.491 00:06:00.389 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 22:25:00.795 00:00:10.342 TCP 1.101.0.1:3000 -> 23.104.0.1:39692 10 6452 1 2025-10-30 22:25:22.436 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:25:22.430 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:25:22.494 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:25:22.358 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:25:22.443 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:26:01.174 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35524 10 6452 1 2025-10-30 22:21:52.494 00:06:00.384 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 22:27:01.578 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:49910 10 6452 1 2025-10-30 22:28:01.995 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:51324 10 6452 1 2025-10-30 22:29:02.405 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:55222 10 6452 1 2025-10-30 22:30:02.812 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:37956 10 6452 1 2025-10-30 22:30:23.441 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:30:23.493 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:30:23.498 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:30:23.437 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:30:23.519 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:31:03.189 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:42854 10 6452 1 2025-10-30 22:26:52.493 00:06:00.393 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 22:32:03.596 00:00:21.853 TCP 1.101.0.1:3000 -> 23.104.0.1:45476 10 6452 1 2025-10-30 22:33:15.491 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:38028 10 6452 1 2025-10-30 22:28:52.495 00:06:00.388 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 22:34:15.893 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:38136 10 6452 1 2025-10-30 22:35:22.654 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:35:22.546 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:35:22.756 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:35:22.654 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:35:22.838 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:35:16.296 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36158 10 6452 1 2025-10-30 22:36:16.696 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39372 10 6452 1 2025-10-30 22:37:17.110 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48990 10 6452 1 2025-10-30 22:38:17.516 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:47980 10 6452 1 2025-10-30 22:33:52.511 00:06:00.378 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 22:39:17.920 00:00:11.183 TCP 1.101.0.1:3000 -> 23.104.0.1:40896 10 6452 1 2025-10-30 22:40:22.815 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:40:22.583 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:40:22.733 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:40:22.650 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:40:22.656 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:40:19.144 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:38406 10 6452 1 2025-10-30 22:35:52.514 00:06:00.372 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 22:41:19.549 00:00:10.357 TCP 1.101.0.1:3000 -> 23.104.0.1:58420 10 6452 1 2025-10-30 22:42:19.946 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:48866 10 6452 1 2025-10-30 22:43:20.354 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:34856 10 6452 1 2025-10-30 22:44:20.757 00:00:10.394 TCP 1.101.0.1:3000 -> 23.104.0.1:34420 11 6504 1 2025-10-30 22:45:22.859 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:45:22.557 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:45:22.813 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:45:22.815 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:45:22.896 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:45:21.190 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:52792 10 6452 1 2025-10-30 22:40:52.510 00:06:00.379 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 22:46:21.587 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:52724 10 6452 1 2025-10-30 22:47:21.990 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:54902 10 6452 1 2025-10-30 22:42:52.513 00:06:00.374 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 22:48:22.399 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:41414 10 6452 1 2025-10-30 22:49:22.800 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58310 10 6452 1 2025-10-30 22:50:22.987 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:50:22.846 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:50:22.988 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:50:22.903 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:50:23.070 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:50:23.205 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:33686 10 6452 1 2025-10-30 22:51:23.603 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:55596 10 6452 1 2025-10-30 22:52:24.005 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:41516 10 6452 1 2025-10-30 22:47:52.513 00:06:00.379 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 22:53:24.374 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:40396 10 6452 1 2025-10-30 22:54:24.789 00:00:10.350 TCP 1.101.0.1:3000 -> 23.104.0.1:58406 10 6452 1 2025-10-30 22:49:52.516 00:06:00.372 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 22:55:23.275 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 22:55:23.191 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:55:22.987 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 22:55:23.149 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 22:55:22.733 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 22:55:25.179 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:56842 10 6452 1 2025-10-30 22:56:25.582 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:55552 10 6452 1 2025-10-30 22:57:25.990 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:37876 10 6452 1 2025-10-30 22:58:26.395 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:39140 10 6452 1 Summary: total flows: 137, total bytes: 420852, total packets: 1021, avg bps: 866, avg pps: 0, avg bpp: 412 Time window: 2025-10-30 21:53:52 - 2025-10-30 22:58:36 Total flows processed: 137, passed: 137, Blocks skipped: 0, Bytes read: 14312 Sys: 0.0053s User: 0.0021s Wall: 0.0021s flows/second: 66445.4 Runtime: 0.0021s