Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-17 01:54:01.865 00:06:00.124 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-17 01:58:57.785 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41718 10 6452 1 2025-11-17 01:59:58.187 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:40412 10 6452 1 2025-11-17 02:00:58.589 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:49796 10 6452 1 2025-11-17 02:01:58.997 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:39068 10 6452 1 2025-11-17 02:02:59.405 00:00:10.589 TCP 1.101.0.1:3000 -> 23.104.0.1:43522 10 6452 1 2025-11-17 02:03:37.929 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:03:37.942 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:03:37.932 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:03:37.982 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:03:38.016 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 01:59:01.867 00:06:00.121 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-17 02:04:00.037 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:54998 10 6452 1 2025-11-17 02:05:00.400 00:00:14.221 TCP 1.101.0.1:3000 -> 23.104.0.1:41234 10 6452 1 2025-11-17 02:01:01.865 00:06:00.128 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-17 02:06:04.676 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:41534 10 6452 1 2025-11-17 02:07:05.108 00:00:10.772 TCP 1.101.0.1:3000 -> 23.104.0.1:35178 10 6452 1 2025-11-17 02:08:05.915 00:00:10.334 TCP 1.101.0.1:3000 -> 23.104.0.1:37370 10 6452 1 2025-11-17 02:08:37.791 00:00:00.030 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:08:37.713 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:08:37.870 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:08:37.606 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:08:37.690 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:09:06.285 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39376 10 6452 1 2025-11-17 02:10:06.692 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:54976 10 6452 1 2025-11-17 02:06:01.869 00:06:00.122 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-17 02:11:07.065 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39424 10 6452 1 2025-11-17 02:12:07.477 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:41670 10 6452 1 2025-11-17 02:08:01.865 00:06:00.128 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-17 02:13:07.883 00:00:10.343 TCP 1.101.0.1:3000 -> 23.104.0.1:51868 10 6452 1 2025-11-17 02:13:37.847 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:13:37.770 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:13:37.703 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:13:37.993 00:00:00.036 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:13:38.077 00:00:00.035 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:14:08.266 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:53642 10 6452 1 2025-11-17 02:15:08.626 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:36942 10 6452 1 2025-11-17 02:16:08.990 00:00:14.978 TCP 1.101.0.1:3000 -> 23.104.0.1:44336 10 6452 1 2025-11-17 02:17:14.024 00:00:10.445 TCP 1.101.0.1:3000 -> 23.104.0.1:38332 12 10375 1 2025-11-17 02:13:01.876 00:06:00.117 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-17 02:18:14.505 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:42156 10 6452 1 2025-11-17 02:18:38.006 00:00:00.027 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:18:37.848 00:00:00.030 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:18:37.867 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:18:37.772 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:18:37.856 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:19:14.906 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:36000 10 6452 1 2025-11-17 02:15:01.872 00:06:00.123 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-17 02:20:15.316 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:38688 10 6452 1 2025-11-17 02:21:15.682 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:43574 10 6452 1 2025-11-17 02:22:16.109 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:54884 10 6452 1 2025-11-17 02:23:16.516 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:37788 10 6452 1 2025-11-17 02:23:38.271 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:23:38.006 00:00:00.046 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:23:38.131 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:23:37.895 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:23:38.188 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:24:16.876 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57030 10 6452 1 2025-11-17 02:20:01.878 00:06:00.117 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-17 02:25:17.279 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51064 10 6452 1 2025-11-17 02:26:17.686 00:00:10.704 TCP 1.101.0.1:3000 -> 23.104.0.1:44944 10 6452 1 2025-11-17 02:22:01.876 00:06:00.123 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-17 02:27:18.430 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:59560 10 6452 1 2025-11-17 02:28:18.832 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:43198 10 6452 1 2025-11-17 02:28:38.028 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:28:38.086 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:28:38.169 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:28:37.964 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:28:37.945 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:29:19.256 00:00:10.596 TCP 1.101.0.1:3000 -> 23.104.0.1:53328 12 6556 1 2025-11-17 02:30:19.885 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:56942 10 6452 1 2025-11-17 02:31:20.312 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:41750 10 6452 1 2025-11-17 02:27:01.878 00:06:00.119 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-17 02:32:20.715 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:34632 10 6452 1 2025-11-17 02:29:01.876 00:05:00.125 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-17 02:33:21.120 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:58280 10 6452 1 2025-11-17 02:33:38.228 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:33:38.245 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:33:38.174 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:33:38.303 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:33:38.385 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:34:21.530 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:49568 10 6452 1 2025-11-17 02:35:21.942 00:00:10.341 TCP 1.101.0.1:3000 -> 23.104.0.1:55550 10 6452 1 2025-11-17 02:36:22.325 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:36222 10 6452 1 2025-11-17 02:37:22.736 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:49798 10 6452 1 2025-11-17 02:38:23.112 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:43422 10 6452 1 2025-11-17 02:38:38.205 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:38:38.443 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:38:38.293 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:38:38.302 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:38:38.378 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:34:01.888 00:06:00.110 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-17 02:35:01.886 00:05:00.115 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-17 02:39:23.518 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:36774 10 6452 1 2025-11-17 02:40:23.903 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:33256 12 6556 1 2025-11-17 02:41:24.341 00:00:15.387 TCP 1.101.0.1:3000 -> 23.104.0.1:50612 10 6452 1 2025-11-17 02:42:29.789 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:44858 10 6452 1 2025-11-17 02:43:38.406 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:43:38.517 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:43:38.443 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:43:38.514 00:00:00.026 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:43:38.597 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:43:30.151 00:00:10.739 TCP 1.101.0.1:3000 -> 23.104.0.1:35320 10 6452 1 2025-11-17 02:44:30.928 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:59076 10 6452 1 2025-11-17 02:41:01.892 00:05:00.109 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-17 02:41:01.889 00:05:00.115 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-17 02:45:31.338 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:35374 10 6452 1 2025-11-17 02:46:31.744 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:53478 10 6452 1 2025-11-17 02:47:32.149 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:49426 10 6452 1 2025-11-17 02:48:38.493 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:48:38.416 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:48:38.516 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:48:38.529 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:48:38.409 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:48:32.549 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:45206 10 6452 1 2025-11-17 02:49:32.949 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:54144 10 6452 1 2025-11-17 02:50:33.353 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:33162 10 6452 1 2025-11-17 02:47:01.892 00:05:00.131 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-17 02:47:01.890 00:05:00.135 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-17 02:51:33.757 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:58212 10 6452 1 2025-11-17 02:52:34.173 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:38040 10 6452 1 2025-11-17 02:53:38.646 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:53:38.641 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:53:38.658 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:53:38.795 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:53:38.876 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:53:34.578 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:49972 10 6452 1 2025-11-17 02:54:34.991 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:51116 10 6452 1 2025-11-17 02:55:35.395 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:40166 10 6452 1 2025-11-17 02:56:35.796 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:40196 10 6452 1 2025-11-17 02:53:01.895 00:05:00.132 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-17 02:53:01.891 00:05:00.136 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-17 02:57:36.173 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:34930 10 6452 1 2025-11-17 02:58:38.820 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-17 02:58:38.558 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:58:38.505 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-17 02:58:38.689 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-17 02:58:38.587 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-17 02:58:36.581 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:52000 10 6452 1 Summary: total flows: 139, total bytes: 421746, total packets: 1036, avg bps: 868, avg pps: 0, avg bpp: 407 Time window: 2025-11-17 01:54:01 - 2025-11-17 02:58:46 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0029s User: 0.0019s Wall: 0.0025s flows/second: 54876.5 Runtime: 0.0026s