Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-23 15:58:47.720 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:37720 10 6452 1 2025-11-23 15:59:48.137 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:37166 10 6452 1 2025-11-23 16:00:48.537 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:45966 10 6452 1 2025-11-23 16:01:49.539 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:01:49.652 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:01:49.530 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:01:49.172 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:01:49.457 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:01:48.943 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:40306 10 6452 1 2025-11-23 16:02:49.357 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:60002 10 6452 1 2025-11-23 16:03:49.756 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:35614 10 6452 1 2025-11-23 15:59:05.113 00:06:00.873 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-23 15:59:05.115 00:06:00.868 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-23 16:04:50.182 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:51000 10 6452 1 2025-11-23 16:05:50.579 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:47922 10 6452 1 2025-11-23 16:06:49.843 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:06:49.970 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:06:49.966 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:06:49.395 00:00:00.025 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:06:49.760 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:06:50.998 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:53498 10 6452 1 2025-11-23 16:07:51.364 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:38208 10 6452 1 2025-11-23 16:08:51.770 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:55338 10 6452 1 2025-11-23 16:09:52.183 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:53902 10 6452 1 2025-11-23 16:10:52.590 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:37962 10 6452 1 2025-11-23 16:06:05.115 00:06:00.875 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-23 16:06:05.118 00:06:00.870 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-23 16:11:49.547 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:11:49.546 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:11:49.709 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:11:49.687 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:11:49.770 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:11:52.950 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:45524 10 6452 1 2025-11-23 16:12:53.370 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:58302 10 6452 1 2025-11-23 16:13:53.770 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:41266 10 6452 1 2025-11-23 16:14:54.137 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36818 10 6452 1 2025-11-23 16:15:54.542 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:33116 10 6452 1 2025-11-23 16:16:49.633 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:16:49.727 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:16:49.566 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:16:49.733 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:16:49.816 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:16:54.939 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:42418 10 6452 1 2025-11-23 16:13:05.119 00:06:00.872 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-23 16:17:55.358 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:37914 10 6452 1 2025-11-23 16:13:05.116 00:06:00.877 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-23 16:18:55.766 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:45746 10 6452 1 2025-11-23 16:19:56.141 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58624 10 6452 1 2025-11-23 16:20:56.546 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:54360 10 6452 1 2025-11-23 16:21:49.961 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:21:49.878 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:21:49.788 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:21:49.880 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:21:49.877 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:21:56.946 00:00:10.341 TCP 1.101.0.1:3000 -> 23.104.0.1:35744 10 6452 1 2025-11-23 16:22:57.322 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:47620 10 6452 1 2025-11-23 16:23:57.726 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:55076 10 6452 1 2025-11-23 16:20:05.120 00:06:00.874 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-23 16:24:58.134 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:50932 10 6452 1 2025-11-23 16:20:05.117 00:06:00.880 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-23 16:25:58.533 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:49654 10 6452 1 2025-11-23 16:26:49.832 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:26:50.208 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:26:50.361 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:26:50.361 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:26:50.445 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:26:58.934 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:53158 10 6452 1 2025-11-23 16:27:59.354 00:00:12.039 TCP 1.101.0.1:3000 -> 23.104.0.1:50384 10 6452 1 2025-11-23 16:29:01.461 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:45490 10 6452 1 2025-11-23 16:30:01.824 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48600 10 6452 1 2025-11-23 16:31:02.226 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:36452 10 6452 1 2025-11-23 16:31:50.220 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:31:50.236 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:31:50.237 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:31:50.137 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:31:50.194 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:27:05.120 00:06:00.877 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-23 16:27:05.122 00:06:00.873 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-23 16:32:02.589 00:00:10.415 TCP 1.101.0.1:3000 -> 23.104.0.1:59806 10 6452 1 2025-11-23 16:33:03.037 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:37748 10 6452 1 2025-11-23 16:34:03.443 00:00:11.050 TCP 1.101.0.1:3000 -> 23.104.0.1:47682 10 6452 1 2025-11-23 16:35:04.528 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:59676 10 6452 1 2025-11-23 16:36:04.929 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:60036 10 6452 1 2025-11-23 16:36:50.221 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:36:50.221 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:36:50.243 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:36:50.385 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:36:50.469 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:37:05.353 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:54108 10 6452 1 2025-11-23 16:34:05.123 00:05:00.877 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-23 16:38:05.718 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:46424 10 6452 1 2025-11-23 16:34:05.125 00:06:00.872 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-23 16:39:06.148 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:55752 10 6452 1 2025-11-23 16:40:06.551 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:46110 10 6452 1 2025-11-23 16:41:06.960 00:00:10.451 TCP 1.101.0.1:3000 -> 23.104.0.1:50516 12 10369 1 2025-11-23 16:41:50.367 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:41:50.289 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:41:50.291 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:41:50.300 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:41:50.449 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:42:07.448 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:45668 10 6452 1 2025-11-23 16:43:07.856 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:53544 10 6452 1 2025-11-23 16:40:05.124 00:05:00.901 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-23 16:44:08.276 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:46806 10 6452 1 2025-11-23 16:41:05.127 00:05:00.877 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-23 16:45:08.639 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:57784 10 6452 1 2025-11-23 16:46:09.015 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:35380 10 6452 1 2025-11-23 16:46:50.556 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:46:50.362 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:46:50.576 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:46:50.623 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:46:50.708 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:47:09.418 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54022 10 6452 1 2025-11-23 16:48:09.822 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:37106 10 6452 1 2025-11-23 16:49:10.190 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:33130 10 6452 1 2025-11-23 16:46:05.125 00:05:00.911 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-23 16:50:10.592 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:45800 10 6452 1 2025-11-23 16:47:05.128 00:05:00.908 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-23 16:51:10.960 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:54282 10 6452 1 2025-11-23 16:51:50.801 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:51:50.651 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:51:50.788 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:51:50.389 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:51:50.719 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:52:11.364 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40270 10 6452 1 2025-11-23 16:53:11.770 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:40872 10 6452 1 2025-11-23 16:54:12.137 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44670 10 6452 1 2025-11-23 16:55:12.537 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:60452 10 6452 1 2025-11-23 16:52:05.129 00:05:00.911 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-23 16:56:12.932 00:00:10.461 TCP 1.101.0.1:3000 -> 23.104.0.1:47932 12 10375 1 2025-11-23 16:56:50.604 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-23 16:56:50.585 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-23 16:56:50.332 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:56:50.549 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-23 16:56:50.632 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-23 16:53:05.131 00:05:00.906 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-23 16:57:13.433 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:32946 10 6452 1 2025-11-23 16:58:13.849 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:53104 10 6452 1 Summary: total flows: 138, total bytes: 424717, total packets: 1022, avg bps: 950, avg pps: 0, avg bpp: 415 Time window: 2025-11-23 15:58:47 - 2025-11-23 16:58:24 Total flows processed: 138, passed: 138, Blocks skipped: 0, Bytes read: 14416 Sys: 0.0024s User: 0.0024s Wall: 0.0018s flows/second: 75005.0 Runtime: 0.0019s