Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-20 12:59:02.517 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:55842 10 6452 1 2025-11-20 13:00:02.890 00:00:10.352 TCP 1.101.0.1:3000 -> 23.104.0.1:41588 10 6452 1 2025-11-20 13:00:19.135 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:00:19.026 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:00:19.370 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:00:19.184 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:00:19.052 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 12:56:03.579 00:06:00.269 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 13:01:03.305 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:60672 10 6452 1 2025-11-20 13:02:03.715 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:33290 10 6452 1 2025-11-20 13:03:04.101 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:50354 10 6452 1 2025-11-20 12:59:03.579 00:06:00.275 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 13:04:04.462 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:38776 10 6452 1 2025-11-20 13:05:19.371 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:05:19.309 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:05:19.337 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:05:04.870 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:39950 10 6452 1 2025-11-20 13:05:19.370 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:05:19.453 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:06:05.279 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37214 10 6452 1 2025-11-20 13:07:05.688 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:42638 10 6452 1 2025-11-20 13:03:03.581 00:06:00.270 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 13:08:06.112 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:45162 10 6452 1 2025-11-20 13:09:06.518 00:00:10.701 TCP 1.101.0.1:3000 -> 23.104.0.1:57528 10 6452 1 2025-11-20 13:10:19.343 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:10:19.554 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:10:19.266 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:10:07.255 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:50926 10 6452 1 2025-11-20 13:10:19.495 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:10:19.578 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:06:03.580 00:06:00.297 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 13:11:07.665 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:39712 10 6452 1 2025-11-20 13:12:08.101 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:57016 10 6452 1 2025-11-20 13:13:08.501 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:46104 10 6452 1 2025-11-20 13:14:08.912 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:60916 10 6452 1 2025-11-20 13:10:03.583 00:06:00.291 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 13:15:19.575 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:15:19.569 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:15:19.441 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:15:19.572 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:15:09.293 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:35768 10 6452 1 2025-11-20 13:15:19.653 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:16:09.698 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:52664 10 6452 1 2025-11-20 13:17:10.121 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:58884 10 6452 1 2025-11-20 13:13:03.581 00:06:00.296 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 13:18:10.489 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:49184 10 6452 1 2025-11-20 13:19:10.908 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:39698 10 6452 1 2025-11-20 13:20:19.604 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:20:19.655 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:20:19.492 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:20:19.720 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:20:19.803 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:20:11.310 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:48682 10 6452 1 2025-11-20 13:21:11.710 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58368 10 6452 1 2025-11-20 13:17:03.584 00:06:00.290 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 13:22:12.123 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:33658 10 6452 1 2025-11-20 13:23:12.532 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:38906 10 6452 1 2025-11-20 13:24:12.931 00:00:10.390 TCP 1.101.0.1:3000 -> 23.104.0.1:52658 10 6452 1 2025-11-20 13:20:03.582 00:06:00.298 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 13:25:19.774 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:25:19.692 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:25:19.696 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:25:19.480 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:25:19.715 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:25:13.358 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:35868 10 6452 1 2025-11-20 13:26:13.767 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:35008 10 6452 1 2025-11-20 13:27:14.190 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:39386 10 6452 1 2025-11-20 13:28:14.587 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46138 10 6452 1 2025-11-20 13:24:03.584 00:06:00.293 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 13:29:14.987 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36032 10 6452 1 2025-11-20 13:30:19.668 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:30:19.757 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:30:19.560 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:30:20.093 00:00:00.034 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:30:20.011 00:00:00.032 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:30:15.391 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:36308 10 6452 1 2025-11-20 13:31:15.794 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:33732 10 6452 1 2025-11-20 13:27:03.583 00:06:00.298 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 13:32:16.202 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:44232 10 6452 1 2025-11-20 13:33:16.604 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:38398 10 6452 1 2025-11-20 13:34:16.967 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:57288 10 6452 1 2025-11-20 13:35:19.949 00:00:00.026 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:35:19.887 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:35:19.947 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:35:20.031 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:35:20.144 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:35:17.394 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:38422 10 6452 1 2025-11-20 13:31:03.586 00:06:00.293 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 13:36:17.814 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:56912 10 6452 1 2025-11-20 13:37:18.214 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:47682 10 6452 1 2025-11-20 13:38:18.577 00:00:10.846 TCP 1.101.0.1:3000 -> 23.104.0.1:57548 10 6452 1 2025-11-20 13:34:03.584 00:06:00.298 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 13:39:19.465 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:52594 10 6452 1 2025-11-20 13:40:20.344 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:40:19.791 00:00:00.026 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:40:20.263 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:40:20.265 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:40:20.261 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:40:19.862 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:52648 10 6452 1 2025-11-20 13:41:20.274 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:50858 10 6452 1 2025-11-20 13:42:20.633 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:38244 10 6452 1 2025-11-20 13:38:03.588 00:06:00.293 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 13:43:21.032 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:54126 10 6452 1 2025-11-20 13:44:21.435 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:57106 10 6452 1 2025-11-20 13:45:20.179 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:45:20.260 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:45:20.160 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:45:20.182 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:45:20.265 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:45:21.806 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37130 10 6452 1 2025-11-20 13:41:03.586 00:06:00.297 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 13:46:22.214 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:37422 10 6452 1 2025-11-20 13:47:22.618 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:35642 10 6452 1 2025-11-20 13:48:23.017 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:47024 10 6452 1 2025-11-20 13:49:23.377 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:42366 10 6452 1 2025-11-20 13:45:03.590 00:06:00.291 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 13:50:19.862 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:50:20.137 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:50:20.377 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:50:20.283 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:50:20.054 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:50:23.785 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:35790 10 6452 1 2025-11-20 13:51:24.156 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:52652 10 6452 1 2025-11-20 13:52:24.563 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:60994 10 6452 1 2025-11-20 13:48:03.588 00:06:00.298 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 13:53:24.967 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:36462 10 6452 1 2025-11-20 13:54:25.373 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36864 10 6452 1 2025-11-20 13:55:20.644 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 13:55:20.292 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:55:20.562 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 13:55:20.349 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 13:55:20.155 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 13:55:25.775 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:52138 10 6452 1 2025-11-20 13:56:26.184 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:45664 10 6452 1 2025-11-20 13:52:03.591 00:06:00.291 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 13:57:26.585 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:59746 10 6452 1 2025-11-20 13:58:26.987 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:35296 10 6452 1 Summary: total flows: 137, total bytes: 416877, total packets: 1018, avg bps: 888, avg pps: 0, avg bpp: 409 Time window: 2025-11-20 12:56:03 - 2025-11-20 13:58:37 Total flows processed: 137, passed: 137, Blocks skipped: 0, Bytes read: 14312 Sys: 0.0047s User: 0.0019s Wall: 0.0022s flows/second: 61933.6 Runtime: 0.0022s