Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-20 22:59:04.751 00:00:10.338 TCP 1.101.0.1:3000 -> 23.104.0.1:39274 10 6452 1 2025-11-20 23:00:05.126 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53014 10 6452 1 2025-11-20 23:00:31.269 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:00:31.253 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:00:31.197 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:00:31.256 00:00:00.025 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:00:31.340 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:57:03.784 00:05:00.310 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 23:01:05.527 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:39046 10 6452 1 2025-11-20 23:02:05.937 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:36384 10 6452 1 2025-11-20 22:59:03.780 00:05:00.316 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 23:03:06.359 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:37472 10 6452 1 2025-11-20 23:04:06.766 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:56704 10 6452 1 2025-11-20 23:05:07.179 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:40892 10 6452 1 2025-11-20 23:05:31.272 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:05:31.367 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:05:31.355 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:05:31.424 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:05:31.191 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:06:07.579 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:56230 10 6452 1 2025-11-20 23:03:03.789 00:05:00.306 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 23:07:07.983 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:37530 10 6452 1 2025-11-20 23:08:08.395 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:33516 10 6452 1 2025-11-20 23:05:03.785 00:05:00.313 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 23:09:08.753 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:56448 10 6452 1 2025-11-20 23:10:09.166 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:58450 10 6452 1 2025-11-20 23:10:31.476 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:10:31.481 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:10:31.387 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:10:31.559 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:10:31.642 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:11:09.532 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:45410 10 6452 1 2025-11-20 23:12:09.935 00:00:21.127 TCP 1.101.0.1:3000 -> 23.104.0.1:55486 10 6452 1 2025-11-20 23:09:03.789 00:05:00.308 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 23:13:21.106 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:39760 10 6452 1 2025-11-20 23:14:21.503 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:58848 10 6452 1 2025-11-20 23:11:03.786 00:05:00.313 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 23:15:31.817 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:15:31.841 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:15:31.521 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:15:21.860 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:51858 10 6452 1 2025-11-20 23:15:31.735 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:15:31.905 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:16:22.268 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:38062 10 6452 1 2025-11-20 23:17:22.672 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:39590 10 6452 1 2025-11-20 23:18:23.096 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54622 10 6452 1 2025-11-20 23:15:03.788 00:05:00.308 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 23:19:23.499 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:55924 10 6452 1 2025-11-20 23:20:31.745 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:20:31.820 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:20:23.899 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:50886 10 6452 1 2025-11-20 23:20:31.684 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:20:31.748 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:20:31.831 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:17:03.786 00:05:00.313 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 23:21:24.312 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:42254 10 6452 1 2025-11-20 23:22:24.717 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:39824 10 6452 1 2025-11-20 23:23:25.121 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39996 10 6452 1 2025-11-20 23:24:25.527 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:53958 10 6452 1 2025-11-20 23:21:03.789 00:05:00.309 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 23:25:31.767 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:25:31.670 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:25:31.777 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:25:31.718 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:25:31.859 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:25:25.891 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:58334 10 6452 1 2025-11-20 23:26:26.315 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:51682 10 6452 1 2025-11-20 23:23:03.788 00:05:00.313 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 23:27:26.682 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:40424 10 6452 1 2025-11-20 23:28:27.112 00:00:10.985 TCP 1.101.0.1:3000 -> 23.104.0.1:36994 10 6452 1 2025-11-20 23:29:28.133 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:60834 10 6452 1 2025-11-20 23:30:31.741 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:30:31.745 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:30:31.817 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:30:31.521 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:30:31.823 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:30:28.535 00:00:10.532 TCP 1.101.0.1:3000 -> 23.104.0.1:49144 10 6452 1 2025-11-20 23:27:03.791 00:05:00.308 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 23:31:29.114 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:60330 10 6452 1 2025-11-20 23:32:29.496 00:00:10.508 TCP 1.101.0.1:3000 -> 23.104.0.1:35580 10 6452 1 2025-11-20 23:29:03.790 00:05:00.312 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 23:33:30.052 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:60158 10 6452 1 2025-11-20 23:34:30.457 00:00:15.522 TCP 1.101.0.1:3000 -> 23.104.0.1:33580 10 6452 1 2025-11-20 23:35:31.998 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:35:31.968 00:00:00.027 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:35:31.830 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:35:31.662 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:35:31.915 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:35:36.021 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:39754 10 6452 1 2025-11-20 23:36:36.421 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:51938 10 6452 1 2025-11-20 23:33:03.793 00:05:00.310 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 23:37:36.820 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:59622 10 6452 1 2025-11-20 23:38:37.220 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:39426 10 6452 1 2025-11-20 23:35:03.790 00:05:00.315 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 23:39:37.585 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:33204 10 6452 1 2025-11-20 23:40:31.930 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:40:31.834 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:40:31.952 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:40:31.935 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:40:32.018 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:40:37.983 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:52510 10 6452 1 2025-11-20 23:41:38.404 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:55710 10 6452 1 2025-11-20 23:42:38.804 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:39794 10 6452 1 2025-11-20 23:39:03.794 00:05:00.309 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 23:43:39.213 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:40896 10 6452 1 2025-11-20 23:44:39.608 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:57378 10 6452 1 2025-11-20 23:41:03.791 00:05:00.315 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 23:45:32.059 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:45:32.197 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:45:31.956 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:45:32.188 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:45:32.270 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:45:40.008 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:42592 10 6452 1 2025-11-20 23:46:40.410 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:41508 10 6452 1 2025-11-20 23:47:40.814 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39132 10 6452 1 2025-11-20 23:48:41.219 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:58992 10 6452 1 2025-11-20 23:45:03.795 00:05:00.310 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 23:49:41.621 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:46750 10 6452 1 2025-11-20 23:50:32.343 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:50:32.102 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:50:32.210 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:50:32.083 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:50:32.166 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:50:42.030 00:00:11.117 TCP 1.101.0.1:3000 -> 23.104.0.1:53916 10 6452 1 2025-11-20 23:47:03.794 00:05:00.315 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 23:51:43.186 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:46340 10 6452 1 2025-11-20 23:52:43.586 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:33132 10 6452 1 2025-11-20 23:53:43.945 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:52722 10 6452 1 2025-11-20 23:54:44.355 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:58210 10 6452 1 2025-11-20 23:51:03.799 00:05:00.307 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 23:55:32.427 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 23:55:32.149 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:55:32.314 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 23:55:32.241 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 23:55:32.397 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 23:55:44.760 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:49756 10 6452 1 2025-11-20 23:56:45.178 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:57686 10 6452 1 2025-11-20 23:53:03.797 00:05:00.314 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 23:57:45.546 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:45056 10 6452 1 Summary: total flows: 139, total bytes: 410548, total packets: 1010, avg bps: 897, avg pps: 0, avg bpp: 406 Time window: 2025-11-20 22:57:03 - 2025-11-20 23:58:04 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0042s User: 0.0008s Wall: 0.0022s flows/second: 62081.6 Runtime: 0.0023s