Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-12 04:59:33.418 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47210 10 6452 1 2025-11-12 05:00:33.821 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48756 10 6452 1 2025-11-12 04:58:59.396 00:02:00.161 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 04:58:59.394 00:02:00.167 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:01:17.209 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:01:17.190 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:01:16.970 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:01:16.757 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:01:17.126 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:01:34.224 00:00:10.795 TCP 1.101.0.1:3000 -> 23.104.0.1:48598 10 6452 1 2025-11-12 05:02:35.069 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56040 10 6452 1 2025-11-12 05:01:59.397 00:01:00.161 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:01:59.395 00:01:00.166 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:03:35.473 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:51780 10 6452 1 2025-11-12 05:04:35.879 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:42396 10 6452 1 2025-11-12 05:05:36.288 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:54144 10 6452 1 2025-11-12 05:03:59.398 00:02:00.160 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 05:03:59.395 00:02:00.166 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:06:17.168 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:06:17.071 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:06:17.071 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:06:17.139 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:06:17.252 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:06:36.701 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:50630 10 6452 1 2025-11-12 05:06:59.396 00:01:00.165 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:06:59.398 00:01:00.160 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:07:37.067 00:00:19.072 TCP 1.101.0.1:3000 -> 23.104.0.1:52112 10 6452 1 2025-11-12 05:08:46.179 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:40794 10 6452 1 2025-11-12 05:09:46.580 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:33066 10 6452 1 2025-11-12 05:08:59.398 00:02:00.160 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 05:10:46.990 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:38720 10 6452 1 2025-11-12 05:08:59.396 00:02:00.165 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:11:17.449 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:11:17.336 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:11:17.172 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:11:17.408 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:11:17.490 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:11:47.398 00:00:10.676 TCP 1.101.0.1:3000 -> 23.104.0.1:49998 10 6452 1 2025-11-12 05:11:59.398 00:01:00.165 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:11:59.400 00:01:00.160 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:12:48.124 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:45206 10 6452 1 2025-11-12 05:13:48.524 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54368 10 6452 1 2025-11-12 05:14:48.925 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:54728 10 6452 1 2025-11-12 05:13:59.397 00:02:00.166 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:15:49.344 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:38314 10 6452 1 2025-11-12 05:13:59.402 00:02:00.161 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 05:16:17.700 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:16:17.611 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:16:17.617 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:16:17.634 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:16:17.620 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:16:49.743 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:43118 10 6452 1 2025-11-12 05:16:59.401 00:01:00.160 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:16:59.398 00:01:00.165 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:17:50.144 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:47420 10 6452 1 2025-11-12 05:18:50.545 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:50894 10 6452 1 2025-11-12 05:19:50.947 00:00:10.394 TCP 1.101.0.1:3000 -> 23.104.0.1:49668 10 6452 1 2025-11-12 05:18:59.401 00:02:00.164 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:18:59.402 00:02:00.160 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 05:20:51.387 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39100 10 6452 1 2025-11-12 05:21:17.383 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:21:17.228 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:21:17.298 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:21:17.011 00:00:00.034 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:21:17.301 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:21:51.785 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:53580 10 6452 1 2025-11-12 05:21:59.401 00:01:00.164 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:21:59.403 00:01:00.159 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:22:52.193 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53390 10 6452 1 2025-11-12 05:23:52.597 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33584 10 6452 1 2025-11-12 05:24:53.005 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:57568 10 6452 1 2025-11-12 05:23:59.404 00:02:00.159 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 05:23:59.401 00:02:00.165 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:25:53.421 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:50132 10 6452 1 2025-11-12 05:26:17.465 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:26:17.474 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:26:17.314 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:26:17.471 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:26:17.554 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:26:53.791 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:41976 10 6452 1 2025-11-12 05:26:59.401 00:01:00.164 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:26:59.403 00:01:00.160 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:27:54.193 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:45310 10 6452 1 2025-11-12 05:28:54.593 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60460 10 6452 1 2025-11-12 05:28:59.405 00:01:00.159 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:28:59.402 00:01:00.164 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:29:54.996 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:35052 10 6452 1 2025-11-12 05:30:55.400 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:57092 10 6452 1 2025-11-12 05:31:17.651 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:31:17.551 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:31:17.174 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:31:17.592 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:31:17.676 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:31:55.764 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:38292 10 6452 1 2025-11-12 05:30:59.406 00:02:00.159 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 05:30:59.403 00:02:00.164 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:32:56.178 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:54026 10 6452 1 2025-11-12 05:33:56.583 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:46794 10 6452 1 2025-11-12 05:33:59.406 00:01:00.160 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:33:59.404 00:01:00.165 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:34:56.989 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:41258 10 6452 1 2025-11-12 05:35:57.357 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59128 10 6452 1 2025-11-12 05:36:17.439 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:36:17.623 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:36:17.647 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:36:17.438 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:36:17.521 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:36:57.761 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:56184 10 6452 1 2025-11-12 05:35:59.408 00:02:00.161 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:35:59.410 00:02:00.156 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 05:37:58.181 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41026 10 6452 1 2025-11-12 05:38:58.586 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33954 10 6452 1 2025-11-12 05:38:59.411 00:01:00.157 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:38:59.408 00:01:00.162 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:39:58.990 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:38152 10 6452 1 2025-11-12 05:40:59.399 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:51776 10 6452 1 2025-11-12 05:41:17.918 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:41:17.957 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:41:18.193 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:41:17.749 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:41:17.835 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:41:59.765 00:00:10.340 TCP 1.101.0.1:3000 -> 23.104.0.1:47000 10 6452 1 2025-11-12 05:40:59.421 00:02:00.149 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 05:40:59.418 00:02:00.154 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:43:00.144 00:00:10.946 TCP 1.101.0.1:3000 -> 23.104.0.1:52470 10 6452 1 2025-11-12 05:44:01.124 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:59516 10 6452 1 2025-11-12 05:43:59.417 00:01:00.154 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:43:59.420 00:01:00.149 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:45:01.530 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:47858 10 6452 1 2025-11-12 05:46:01.924 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:48334 10 6452 1 2025-11-12 05:46:17.977 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:46:17.895 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:46:17.825 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:46:17.699 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:46:17.894 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:47:02.347 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:42400 10 6452 1 2025-11-12 05:45:59.418 00:02:00.154 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:45:59.420 00:02:00.149 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 05:48:02.753 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:38562 10 6452 1 2025-11-12 05:49:03.156 00:00:10.337 TCP 1.101.0.1:3000 -> 23.104.0.1:37970 10 6452 1 2025-11-12 05:48:59.422 00:01:00.148 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:48:59.419 00:01:00.153 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:50:03.528 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:45046 10 6452 1 2025-11-12 05:51:03.930 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:56768 10 6452 1 2025-11-12 05:51:17.901 00:00:00.026 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:51:17.754 00:00:00.025 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:51:17.983 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:51:17.909 00:00:00.028 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:51:18.066 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:52:04.353 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:42966 10 6452 1 2025-11-12 05:50:59.423 00:02:00.147 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-12 05:50:59.420 00:02:00.152 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-12 05:53:04.719 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:44242 10 6452 1 2025-11-12 05:54:05.144 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:38990 10 6452 1 2025-11-12 05:53:59.425 00:01:00.145 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:53:59.424 00:01:00.150 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:55:05.548 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:35856 10 6452 1 2025-11-12 05:56:18.009 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 05:56:17.924 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 05:56:18.111 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 05:56:17.946 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:56:17.926 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 05:56:05.962 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:51106 10 6452 1 2025-11-12 05:55:59.424 00:01:00.151 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-12 05:55:59.427 00:01:00.145 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-12 05:57:06.319 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:46728 10 6452 1 2025-11-12 05:57:59.425 00:00:00.148 TCP 179.21.23.23:179 -> 179.21.23.21:38570 2 123 1 2025-11-12 05:57:59.427 00:00:00.144 TCP 179.21.23.21:38570 -> 179.21.23.23:179 2 123 1 2025-11-12 05:58:06.724 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:42998 10 6452 1 Summary: total flows: 169, total bytes: 410548, total packets: 1010, avg bps: 923, avg pps: 0, avg bpp: 406 Time window: 2025-11-12 04:58:59 - 2025-11-12 05:58:17 Total flows processed: 169, passed: 169, Blocks skipped: 0, Bytes read: 17640 Sys: 0.0040s User: 0.0020s Wall: 0.0024s flows/second: 71275.8 Runtime: 0.0024s