Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-15 00:59:33.758 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:44954 10 6452 1 2025-11-15 00:55:00.835 00:06:00.138 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 01:00:34.134 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:45900 10 6452 1 2025-11-15 01:01:34.551 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:60760 10 6452 1 2025-11-15 01:02:38.963 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:02:38.882 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:02:38.923 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:02:38.878 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:02:38.655 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:02:34.917 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:55202 10 6452 1 2025-11-15 01:03:35.317 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:52302 10 6452 1 2025-11-15 00:59:00.835 00:06:00.145 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 01:04:35.718 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:35032 10 6452 1 2025-11-15 01:05:36.136 00:00:10.392 TCP 1.101.0.1:3000 -> 23.104.0.1:35260 12 10369 1 2025-11-15 01:06:36.571 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:48626 10 6452 1 2025-11-15 01:02:00.838 00:06:00.139 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 01:07:38.829 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:07:38.834 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:07:38.947 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:07:38.736 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:07:38.819 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:07:36.975 00:00:10.556 TCP 1.101.0.1:3000 -> 23.104.0.1:52440 10 6452 1 2025-11-15 01:08:37.571 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:49322 10 6452 1 2025-11-15 01:09:37.973 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:43572 10 6452 1 2025-11-15 01:10:38.376 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:40938 10 6452 1 2025-11-15 01:06:00.837 00:06:00.145 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 01:11:38.780 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:59854 10 6452 1 2025-11-15 01:12:38.866 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:12:38.788 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:12:38.834 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:12:38.641 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:12:38.783 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:12:39.189 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:56280 10 6452 1 2025-11-15 01:13:39.550 00:00:10.446 TCP 1.101.0.1:3000 -> 23.104.0.1:37214 10 6452 1 2025-11-15 01:09:00.839 00:06:00.140 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 01:14:40.031 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:55420 10 6452 1 2025-11-15 01:15:40.427 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:45906 10 6452 1 2025-11-15 01:16:40.835 00:00:10.348 TCP 1.101.0.1:3000 -> 23.104.0.1:37306 10 6452 1 2025-11-15 01:17:38.959 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:17:38.785 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:17:38.716 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:17:38.871 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:17:38.956 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:17:41.222 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39248 10 6452 1 2025-11-15 01:13:00.838 00:06:00.144 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 01:18:41.626 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:32860 10 6452 1 2025-11-15 01:19:42.027 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:38082 10 6452 1 2025-11-15 01:20:42.391 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:44606 10 6452 1 2025-11-15 01:16:00.842 00:06:00.141 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 01:21:42.791 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:53068 10 6452 1 2025-11-15 01:22:39.235 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:22:39.124 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:22:38.937 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:22:39.084 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:22:39.167 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:22:43.199 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:59954 10 6452 1 2025-11-15 01:23:43.602 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:60776 10 6452 1 2025-11-15 01:24:43.965 00:00:15.587 TCP 1.101.0.1:3000 -> 23.104.0.1:49650 10 6452 1 2025-11-15 01:20:00.840 00:06:00.149 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 01:25:49.594 00:00:15.628 TCP 1.101.0.1:3000 -> 23.104.0.1:33078 10 6452 1 2025-11-15 01:26:55.281 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:48418 10 6452 1 2025-11-15 01:27:39.675 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:27:39.585 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:27:39.679 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:27:39.593 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:27:39.676 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:23:00.845 00:06:00.141 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 01:27:55.683 00:00:11.041 TCP 1.101.0.1:3000 -> 23.104.0.1:51004 10 6452 1 2025-11-15 01:28:56.757 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:46940 10 6452 1 2025-11-15 01:29:57.125 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:40008 10 6452 1 2025-11-15 01:30:57.532 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:57874 10 6452 1 2025-11-15 01:27:00.843 00:06:00.147 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 01:31:57.935 00:00:10.392 TCP 1.101.0.1:3000 -> 23.104.0.1:57194 10 6452 1 2025-11-15 01:32:39.323 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:32:39.975 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:32:39.118 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:32:39.439 00:00:00.029 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:32:39.522 00:00:00.029 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:32:58.360 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:49126 10 6452 1 2025-11-15 01:33:58.763 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:33250 10 6452 1 2025-11-15 01:30:00.846 00:06:00.142 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 01:34:59.135 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:45466 10 6452 1 2025-11-15 01:35:59.538 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:46398 10 6452 1 2025-11-15 01:36:59.937 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:33988 10 6452 1 2025-11-15 01:37:39.344 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:37:39.336 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:37:39.319 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:37:39.460 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:37:39.543 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:38:00.354 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:59308 10 6452 1 2025-11-15 01:34:00.844 00:06:00.147 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 01:39:00.762 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:52454 10 6452 1 2025-11-15 01:40:01.171 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:60076 10 6452 1 2025-11-15 01:41:01.576 00:00:10.436 TCP 1.101.0.1:3000 -> 23.104.0.1:45414 12 10369 1 2025-11-15 01:37:00.847 00:06:00.142 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 01:42:02.065 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:36032 10 6452 1 2025-11-15 01:42:39.320 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:42:39.550 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:42:39.470 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:42:39.501 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:42:39.584 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:43:02.466 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:36196 10 6452 1 2025-11-15 01:44:02.864 00:00:10.337 TCP 1.101.0.1:3000 -> 23.104.0.1:33516 10 6452 1 2025-11-15 01:45:03.243 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:56256 10 6452 1 2025-11-15 01:41:00.847 00:06:00.148 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 01:46:03.652 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:46818 10 6452 1 2025-11-15 01:47:04.073 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:47142 10 6452 1 2025-11-15 01:47:39.807 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:47:39.923 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:47:40.075 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:47:39.993 00:00:00.037 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:47:40.006 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:48:04.448 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:46022 10 6452 1 2025-11-15 01:44:00.849 00:06:00.143 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 01:49:04.853 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:36336 10 6452 1 2025-11-15 01:50:05.277 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:45884 10 6452 1 2025-11-15 01:51:05.635 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:52944 10 6452 1 2025-11-15 01:52:06.054 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52384 10 6452 1 2025-11-15 01:52:39.825 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:52:39.632 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:52:39.637 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:52:39.764 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:52:39.740 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:48:00.849 00:06:00.146 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 01:53:06.461 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:56120 10 6452 1 2025-11-15 01:54:06.825 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:58570 10 6452 1 2025-11-15 01:55:07.223 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:38056 10 6452 1 2025-11-15 01:51:00.852 00:06:00.141 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 01:56:07.587 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56342 10 6452 1 2025-11-15 01:57:07.995 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:57942 10 6452 1 2025-11-15 01:57:39.831 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 01:57:39.638 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 01:57:39.853 00:00:00.027 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:57:39.899 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 01:57:39.981 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 01:58:08.400 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:41760 10 6452 1 Summary: total flows: 136, total bytes: 418259, total packets: 1012, avg bps: 881, avg pps: 0, avg bpp: 413 Time window: 2025-11-15 00:55:00 - 2025-11-15 01:58:18 Total flows processed: 136, passed: 136, Blocks skipped: 0, Bytes read: 14208 Sys: 0.0042s User: 0.0008s Wall: 0.0022s flows/second: 62587.8 Runtime: 0.0022s