Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-20 05:59:28.137 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:39128 10 6452 1 2025-11-20 06:00:09.413 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:00:09.359 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:00:09.360 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:00:09.186 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:00:09.497 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:00:28.537 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:50092 10 6452 1 2025-11-20 06:01:28.889 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:41110 12 6556 1 2025-11-20 06:02:29.313 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:52022 10 6452 1 2025-11-20 06:03:29.718 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:49624 10 6452 1 2025-11-20 05:59:03.425 00:06:00.252 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 05:59:03.422 00:06:00.258 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 06:04:30.132 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41638 10 6452 1 2025-11-20 06:05:09.220 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:05:09.192 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:05:09.011 00:00:00.042 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:05:08.951 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:05:09.137 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:05:30.544 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:34898 10 6452 1 2025-11-20 06:06:30.943 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:45984 10 6452 1 2025-11-20 06:07:31.315 00:00:10.883 TCP 1.101.0.1:3000 -> 23.104.0.1:59166 10 6452 1 2025-11-20 06:08:32.233 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:48214 10 6452 1 2025-11-20 06:09:32.644 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:40612 12 6556 1 2025-11-20 06:10:09.253 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:10:09.320 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:10:09.110 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:10:09.186 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:10:09.269 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:10:33.123 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:34514 10 6452 1 2025-11-20 06:06:03.431 00:06:00.252 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 06:06:03.428 00:06:00.257 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 06:11:33.523 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:54618 10 6452 1 2025-11-20 06:12:33.930 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:42228 10 6452 1 2025-11-20 06:13:34.346 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:54980 10 6452 1 2025-11-20 06:14:34.754 00:00:23.991 TCP 1.101.0.1:3000 -> 23.104.0.1:52302 10 6452 1 2025-11-20 06:15:09.223 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:15:09.489 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:15:09.381 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:15:09.397 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:15:09.479 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:15:48.810 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:47272 10 6452 1 2025-11-20 06:16:49.214 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:33224 10 6452 1 2025-11-20 06:17:49.618 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:57510 10 6452 1 2025-11-20 06:13:03.432 00:06:00.255 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 06:13:03.436 00:06:00.249 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 06:18:50.023 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:47322 10 6452 1 2025-11-20 06:19:50.429 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:52406 10 6452 1 2025-11-20 06:20:09.281 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:20:09.554 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:20:09.394 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:20:09.397 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:20:09.637 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:20:50.832 00:00:10.354 TCP 1.101.0.1:3000 -> 23.104.0.1:42340 10 6452 1 2025-11-20 06:21:51.225 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52040 10 6452 1 2025-11-20 06:22:51.631 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:34508 10 6452 1 2025-11-20 06:23:52.035 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:45972 10 6452 1 2025-11-20 06:20:03.438 00:06:00.248 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 06:24:52.438 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:36874 10 6452 1 2025-11-20 06:20:03.434 00:06:00.253 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 06:25:09.929 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:25:09.881 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:25:09.612 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:25:09.936 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:25:10.019 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:25:52.831 00:00:15.831 TCP 1.101.0.1:3000 -> 23.104.0.1:57456 10 6452 1 2025-11-20 06:26:58.704 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:52382 10 6452 1 2025-11-20 06:27:59.110 00:00:10.438 TCP 1.101.0.1:3000 -> 23.104.0.1:54560 12 10375 1 2025-11-20 06:28:59.589 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:33164 10 6452 1 2025-11-20 06:30:09.716 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:30:09.713 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:30:09.628 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:30:09.594 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:30:09.677 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:29:59.994 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:33624 10 6452 1 2025-11-20 06:31:00.396 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:47240 10 6452 1 2025-11-20 06:27:03.436 00:06:00.257 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 06:27:03.438 00:06:00.251 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 06:32:00.809 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:51022 10 6452 1 2025-11-20 06:33:01.222 00:00:10.438 TCP 1.101.0.1:3000 -> 23.104.0.1:56384 12 10375 1 2025-11-20 06:34:01.703 00:00:11.109 TCP 1.101.0.1:3000 -> 23.104.0.1:41758 10 6452 1 2025-11-20 06:35:09.899 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:35:09.813 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:35:09.725 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:35:09.751 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:35:09.817 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:35:02.852 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:38252 10 6452 1 2025-11-20 06:36:03.273 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47238 10 6452 1 2025-11-20 06:37:03.677 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:51234 10 6452 1 2025-11-20 06:38:04.041 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:50148 10 6452 1 2025-11-20 06:34:03.439 00:06:00.255 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 06:34:03.436 00:06:00.260 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 06:39:04.449 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:54436 10 6452 1 2025-11-20 06:40:09.924 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:40:09.880 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:40:09.927 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:40:10.010 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:40:10.155 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:40:04.855 00:00:10.340 TCP 1.101.0.1:3000 -> 23.104.0.1:58854 10 6452 1 2025-11-20 06:41:05.235 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:59104 10 6452 1 2025-11-20 06:42:05.639 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:49046 10 6452 1 2025-11-20 06:43:06.056 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:37844 10 6452 1 2025-11-20 06:44:06.423 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37352 10 6452 1 2025-11-20 06:45:10.130 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:45:09.866 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:45:09.660 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:45:10.049 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:45:10.047 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:45:06.828 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:57222 10 6452 1 2025-11-20 06:41:03.440 00:06:00.259 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 06:41:03.443 00:06:00.255 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 06:46:07.227 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:43280 10 6452 1 2025-11-20 06:47:07.591 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:54348 10 6452 1 2025-11-20 06:48:07.961 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52146 10 6452 1 2025-11-20 06:49:08.368 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:46586 10 6452 1 2025-11-20 06:50:09.956 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:50:09.874 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:50:10.163 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:50:10.191 00:00:00.026 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:50:10.064 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:50:08.769 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:50934 10 6452 1 2025-11-20 06:51:09.178 00:00:10.397 TCP 1.101.0.1:3000 -> 23.104.0.1:33268 10 6452 1 2025-11-20 06:52:09.612 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:60144 10 6452 1 2025-11-20 06:48:03.445 00:06:00.255 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 06:48:03.442 00:06:00.260 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 06:53:09.975 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:59398 10 6452 1 2025-11-20 06:54:10.385 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:55962 10 6452 1 2025-11-20 06:55:10.189 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 06:55:10.097 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:55:10.342 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 06:55:10.255 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 06:55:10.426 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 06:55:10.795 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:48422 10 6452 1 2025-11-20 06:56:11.205 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:34686 10 6452 1 2025-11-20 06:57:11.621 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:46586 10 6452 1 2025-11-20 06:58:12.026 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:43004 10 6452 1 Summary: total flows: 135, total bytes: 417618, total packets: 1002, avg bps: 938, avg pps: 0, avg bpp: 416 Time window: 2025-11-20 05:59:03 - 2025-11-20 06:58:22 Total flows processed: 135, passed: 135, Blocks skipped: 0, Bytes read: 14104 Sys: 0.0044s User: 0.0018s Wall: 0.0019s flows/second: 70938.5 Runtime: 0.0020s