Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-20 04:59:03.675 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55726 10 6452 1 2025-11-20 05:00:08.001 00:00:00.036 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:00:07.831 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:00:07.821 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:00:07.895 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:00:07.906 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:00:04.107 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:42900 10 6452 1 2025-11-20 04:56:03.403 00:06:00.249 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 04:56:03.399 00:06:00.255 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 05:01:04.505 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50034 10 6452 1 2025-11-20 05:02:04.906 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:57268 12 6556 1 2025-11-20 05:03:05.313 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:40346 10 6452 1 2025-11-20 05:04:05.720 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:52098 10 6452 1 2025-11-20 05:05:07.833 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:05:07.914 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:05:07.799 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:05:08.044 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:05:08.126 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:05:06.140 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:55874 10 6452 1 2025-11-20 05:06:06.541 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:38630 10 6452 1 2025-11-20 05:07:06.968 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:54530 10 6452 1 2025-11-20 05:03:03.406 00:06:00.248 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 05:03:03.403 00:06:00.253 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 05:08:07.392 00:00:10.510 TCP 1.101.0.1:3000 -> 23.104.0.1:58546 10 6452 1 2025-11-20 05:09:07.957 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:59712 10 6452 1 2025-11-20 05:10:07.898 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:10:07.996 00:00:00.034 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:10:08.044 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:10:07.996 00:00:00.044 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:10:08.079 00:00:00.044 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:10:08.326 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:60232 10 6452 1 2025-11-20 05:11:08.737 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:36678 10 6452 1 2025-11-20 05:12:09.112 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:41284 10 6452 1 2025-11-20 05:13:09.519 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:42230 10 6452 1 2025-11-20 05:14:09.924 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:50856 10 6452 1 2025-11-20 05:10:03.409 00:06:00.246 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 05:10:03.407 00:06:00.251 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 05:15:08.173 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:15:08.183 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:15:07.917 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:15:08.182 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:15:08.265 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:15:10.332 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54304 10 6452 1 2025-11-20 05:16:10.736 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:53074 10 6452 1 2025-11-20 05:17:11.149 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:43032 10 6452 1 2025-11-20 05:18:11.559 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48812 10 6452 1 2025-11-20 05:19:11.960 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46624 10 6452 1 2025-11-20 05:20:08.491 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:20:08.492 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:20:08.200 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:20:08.705 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:20:08.787 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:20:12.367 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:44338 10 6452 1 2025-11-20 05:21:12.779 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:38932 12 6556 1 2025-11-20 05:17:03.410 00:06:00.257 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 05:17:03.412 00:06:00.252 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 05:22:13.192 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:37490 10 6452 1 2025-11-20 05:23:13.594 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:33882 10 6452 1 2025-11-20 05:24:13.995 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:41786 10 6452 1 2025-11-20 05:25:08.529 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:25:08.422 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:25:08.380 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:25:08.287 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:25:08.462 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:25:14.398 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:49770 10 6452 1 2025-11-20 05:26:14.808 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:58012 10 6452 1 2025-11-20 05:27:15.216 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:60800 10 6452 1 2025-11-20 05:28:15.582 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:57808 10 6452 1 2025-11-20 05:24:03.413 00:06:00.251 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 05:24:03.411 00:06:00.256 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 05:29:15.990 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:32968 10 6452 1 2025-11-20 05:30:08.613 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:30:08.616 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:30:08.538 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:30:08.425 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:30:08.509 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:30:16.398 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:51506 10 6452 1 2025-11-20 05:31:16.799 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:46966 10 6452 1 2025-11-20 05:32:17.211 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:51804 10 6452 1 2025-11-20 05:33:17.615 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54110 10 6452 1 2025-11-20 05:34:18.020 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:42430 10 6452 1 2025-11-20 05:35:08.944 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:35:08.423 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:35:08.762 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:35:08.745 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:35:08.861 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:35:18.380 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:45788 10 6452 1 2025-11-20 05:31:03.414 00:06:00.252 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 05:31:03.412 00:06:00.257 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 05:36:18.779 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:52612 10 6452 1 2025-11-20 05:37:19.187 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:50712 10 6452 1 2025-11-20 05:38:19.602 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39616 10 6452 1 2025-11-20 05:39:20.012 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:51470 10 6452 1 2025-11-20 05:40:08.827 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:40:08.667 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:40:08.671 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:40:08.721 00:00:00.015 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:40:08.744 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:40:20.423 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:50474 10 6452 1 2025-11-20 05:41:20.839 00:00:10.391 TCP 1.101.0.1:3000 -> 23.104.0.1:37600 10 6452 1 2025-11-20 05:42:21.276 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:55392 10 6452 1 2025-11-20 05:38:03.416 00:06:00.252 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 05:38:03.415 00:06:00.256 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 05:43:21.675 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:57650 10 6452 1 2025-11-20 05:44:22.094 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:39200 10 6452 1 2025-11-20 05:45:08.548 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:45:08.909 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:45:08.598 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:45:08.833 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:45:08.915 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:45:22.457 00:00:10.340 TCP 1.101.0.1:3000 -> 23.104.0.1:49660 10 6452 1 2025-11-20 05:46:22.835 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:40952 10 6452 1 2025-11-20 05:47:23.252 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:42394 10 6452 1 2025-11-20 05:48:23.612 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46350 10 6452 1 2025-11-20 05:49:24.020 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53936 10 6452 1 2025-11-20 05:45:03.416 00:06:00.256 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 05:45:03.418 00:06:00.252 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 05:50:09.292 00:00:00.019 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:50:09.200 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:50:09.093 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:50:08.810 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:50:09.206 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:50:24.425 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:54830 10 6452 1 2025-11-20 05:51:24.830 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:60742 10 6452 1 2025-11-20 05:52:25.249 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:51330 10 6452 1 2025-11-20 05:53:25.651 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:59530 10 6452 1 2025-11-20 05:54:26.017 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:47062 10 6452 1 2025-11-20 05:55:09.151 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 05:55:08.843 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:55:09.070 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 05:55:09.062 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 05:55:09.181 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 05:55:26.427 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:39380 10 6452 1 2025-11-20 05:56:26.828 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:47934 10 6452 1 2025-11-20 05:52:03.421 00:06:00.253 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 05:52:03.418 00:06:00.259 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 05:57:27.242 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:51872 12 10375 1 2025-11-20 05:58:27.722 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:34680 10 6452 1 Summary: total flows: 138, total bytes: 421869, total packets: 1038, avg bps: 898, avg pps: 0, avg bpp: 406 Time window: 2025-11-20 04:56:03 - 2025-11-20 05:58:38 Total flows processed: 138, passed: 138, Blocks skipped: 0, Bytes read: 14416 Sys: 0.0041s User: 0.0021s Wall: 0.0020s flows/second: 67484.4 Runtime: 0.0021s