Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-25 18:59:20.054 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:38530 10 6452 1 2025-11-25 19:00:20.451 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47828 10 6452 1 2025-11-25 19:01:20.857 00:00:10.341 TCP 1.101.0.1:3000 -> 23.104.0.1:46074 10 6452 1 2025-11-25 18:58:06.218 00:05:01.341 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:02:21.234 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:36500 10 6452 1 2025-11-25 19:02:50.860 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:02:50.775 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:02:50.885 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:02:50.712 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:02:50.778 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 18:59:06.221 00:05:01.336 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:03:21.634 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:57818 10 6452 1 2025-11-25 19:04:22.057 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:55154 10 6452 1 2025-11-25 19:05:22.461 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:39980 10 6452 1 2025-11-25 19:06:22.871 00:00:10.402 TCP 1.101.0.1:3000 -> 23.104.0.1:46328 10 6452 1 2025-11-25 19:07:23.308 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44864 10 6452 1 2025-11-25 19:07:51.398 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:07:51.271 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:07:51.141 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:07:51.274 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:07:51.357 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:04:06.221 00:05:01.344 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:08:23.711 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:36608 10 6452 1 2025-11-25 19:05:06.223 00:05:01.340 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:09:24.119 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:53976 10 6452 1 2025-11-25 19:10:24.543 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58686 10 6452 1 2025-11-25 19:11:24.944 00:00:10.407 TCP 1.101.0.1:3000 -> 23.104.0.1:43068 10 6452 1 2025-11-25 19:12:25.351 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:53150 10 6452 1 2025-11-25 19:12:51.200 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:12:51.240 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:12:50.817 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:12:51.002 00:00:00.048 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:12:51.084 00:00:00.049 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:13:25.728 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:46628 10 6452 1 2025-11-25 19:10:06.221 00:05:01.345 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:14:26.143 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:42512 10 6452 1 2025-11-25 19:11:06.223 00:05:01.340 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:15:26.546 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53524 10 6452 1 2025-11-25 19:16:26.952 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54874 10 6452 1 2025-11-25 19:17:27.356 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:57200 10 6452 1 2025-11-25 19:17:51.279 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:17:51.180 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:17:51.136 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:17:51.326 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:17:51.409 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:18:27.770 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:50724 10 6452 1 2025-11-25 19:19:28.185 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:49372 10 6452 1 2025-11-25 19:16:06.223 00:05:01.344 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:20:28.593 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37052 10 6452 1 2025-11-25 19:17:06.225 00:05:01.339 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:21:28.995 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:44930 10 6452 1 2025-11-25 19:22:29.367 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56568 10 6452 1 2025-11-25 19:22:51.256 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:22:51.346 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:22:50.891 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:22:51.256 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:22:51.339 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:23:29.773 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:50014 10 6452 1 2025-11-25 19:24:30.139 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:37898 10 6452 1 2025-11-25 19:25:30.541 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:37426 10 6452 1 2025-11-25 19:22:06.227 00:05:01.346 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:26:30.939 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:48468 10 6452 1 2025-11-25 19:23:06.230 00:05:01.341 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:27:31.314 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:57956 10 6452 1 2025-11-25 19:27:51.431 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:27:51.519 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:27:51.132 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:27:51.348 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:27:51.263 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:28:31.685 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:44644 10 6452 1 2025-11-25 19:29:32.066 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:55474 10 6452 1 2025-11-25 19:30:32.471 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:45550 10 6452 1 2025-11-25 19:31:32.838 00:00:10.424 TCP 1.101.0.1:3000 -> 23.104.0.1:48298 12 10375 1 2025-11-25 19:28:06.228 00:05:01.349 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:32:33.301 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:33164 10 6452 1 2025-11-25 19:32:51.682 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:32:51.601 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:32:51.650 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:32:51.649 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:32:51.350 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:29:06.230 00:05:01.344 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:33:33.666 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:56438 10 6452 1 2025-11-25 19:34:34.102 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:44744 10 6452 1 2025-11-25 19:35:34.504 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:37912 10 6452 1 2025-11-25 19:36:34.870 00:00:10.449 TCP 1.101.0.1:3000 -> 23.104.0.1:48378 12 10369 1 2025-11-25 19:37:35.363 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:49778 10 6452 1 2025-11-25 19:37:51.777 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:37:51.652 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:37:51.623 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:37:51.603 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:37:51.685 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:34:06.232 00:05:01.348 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:38:35.761 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:38498 10 6452 1 2025-11-25 19:35:06.233 00:05:01.343 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:39:36.175 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:52858 10 6452 1 2025-11-25 19:40:36.582 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:55396 10 6452 1 2025-11-25 19:41:36.987 00:00:10.342 TCP 1.101.0.1:3000 -> 23.104.0.1:33392 10 6452 1 2025-11-25 19:42:37.371 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:38752 10 6452 1 2025-11-25 19:42:51.696 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:42:51.751 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:42:51.711 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:42:51.625 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:42:51.708 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:43:37.780 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56426 10 6452 1 2025-11-25 19:40:06.232 00:05:01.368 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:44:38.187 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57276 10 6452 1 2025-11-25 19:41:06.236 00:05:01.363 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:45:38.596 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:54360 10 6452 1 2025-11-25 19:46:38.996 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:56262 10 6452 1 2025-11-25 19:47:39.360 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37354 10 6452 1 2025-11-25 19:47:51.634 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:47:51.717 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:47:51.667 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:47:51.633 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:47:51.716 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:48:39.773 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:44202 10 6452 1 2025-11-25 19:49:40.192 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:49958 10 6452 1 2025-11-25 19:46:06.236 00:05:01.368 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:50:40.611 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:57178 10 6452 1 2025-11-25 19:47:06.238 00:05:01.364 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:51:41.008 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:49118 10 6452 1 2025-11-25 19:52:52.054 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:52:52.058 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:52:51.959 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:52:52.220 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:52:41.415 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:49260 10 6452 1 2025-11-25 19:52:52.303 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:53:41.827 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:53888 10 6452 1 2025-11-25 19:54:42.190 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:34654 10 6452 1 2025-11-25 19:55:42.602 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:60100 10 6452 1 2025-11-25 19:52:06.238 00:05:01.367 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:56:42.989 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:43690 10 6452 1 2025-11-25 19:53:06.240 00:05:01.362 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:57:52.197 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:57:52.227 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:57:52.159 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:57:43.390 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:55632 10 6452 1 2025-11-25 19:57:52.085 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:57:52.168 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 Summary: total flows: 139, total bytes: 418388, total packets: 1014, avg bps: 929, avg pps: 0, avg bpp: 412 Time window: 2025-11-25 18:58:06 - 2025-11-25 19:58:07 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0035s User: 0.0017s Wall: 0.0020s flows/second: 68076.6 Runtime: 0.0021s