Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-26 07:58:51.559 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:48362 10 6870 1 2025-11-26 07:59:51.960 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:35854 10 6870 1 2025-11-26 08:00:52.328 00:00:10.984 TCP 1.101.0.1:3000 -> 23.104.0.1:38714 10 6870 1 2025-11-26 08:01:53.352 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49916 10 6870 1 2025-11-26 07:58:06.443 00:05:01.537 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:02:53.753 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:39600 10 6870 1 2025-11-26 08:03:06.568 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:03:06.405 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 07:59:06.445 00:05:01.532 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:03:06.478 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:03:06.245 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:03:06.486 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:03:54.115 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58540 10 6870 1 2025-11-26 08:04:54.525 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:58026 10 6870 1 2025-11-26 08:05:54.936 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:41818 10 6870 1 2025-11-26 08:06:55.364 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:58158 10 6870 1 2025-11-26 08:08:06.868 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:07:55.760 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:54810 10 6870 1 2025-11-26 08:08:06.665 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:08:06.755 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:08:06.956 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:04:06.444 00:05:01.539 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:08:07.039 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:08:56.174 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:52884 10 6870 1 2025-11-26 08:05:06.447 00:05:01.533 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:09:56.584 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54074 10 6870 1 2025-11-26 08:10:57.006 00:00:10.317 TCP 1.101.0.1:3000 -> 23.104.0.1:48664 10 6870 1 2025-11-26 08:11:57.367 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:35260 10 6870 1 2025-11-26 08:13:06.803 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:13:06.721 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:13:06.724 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:13:06.296 00:00:00.037 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:13:06.719 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:12:57.777 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:57394 10 6870 1 2025-11-26 08:13:58.179 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:50824 10 6870 1 2025-11-26 08:10:06.445 00:05:01.538 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:14:58.578 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:56948 10 6870 1 2025-11-26 08:11:06.448 00:05:01.538 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:15:58.978 00:00:10.441 TCP 1.101.0.1:3000 -> 23.104.0.1:57616 12 10369 1 2025-11-26 08:16:59.462 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51838 10 6452 1 2025-11-26 08:18:06.867 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:18:06.940 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:18:06.953 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:18:06.867 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:18:06.950 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:17:59.861 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:34120 10 6452 1 2025-11-26 08:19:00.275 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:55334 10 6452 1 2025-11-26 08:16:06.451 00:05:01.535 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:20:00.680 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:56128 10 6452 1 2025-11-26 08:17:06.454 00:05:01.532 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:21:01.110 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46916 10 6452 1 2025-11-26 08:22:01.514 00:00:10.342 TCP 1.101.0.1:3000 -> 23.104.0.1:41704 10 6452 1 2025-11-26 08:23:06.943 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:23:06.922 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:23:06.919 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:23:06.989 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:23:06.859 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:23:01.892 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:49836 10 6452 1 2025-11-26 08:24:02.260 00:00:10.653 TCP 1.101.0.1:3000 -> 23.104.0.1:34588 10 6452 1 2025-11-26 08:25:02.963 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:53834 10 6452 1 2025-11-26 08:22:06.453 00:05:01.537 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:26:03.369 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:38542 10 6452 1 2025-11-26 08:23:06.455 00:05:01.532 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:27:03.777 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:37922 10 6452 1 2025-11-26 08:28:06.927 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:28:07.012 00:00:00.043 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:28:07.112 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:28:06.927 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:28:07.011 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:28:04.186 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:45758 10 6452 1 2025-11-26 08:29:04.597 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37872 10 6452 1 2025-11-26 08:30:05.002 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51344 10 6452 1 2025-11-26 08:31:05.401 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47558 10 6452 1 2025-11-26 08:28:06.461 00:05:01.532 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:32:05.812 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59948 10 6452 1 2025-11-26 08:33:07.255 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:33:07.214 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:29:06.465 00:05:01.524 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:33:07.172 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:33:07.078 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:33:07.171 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:33:06.213 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:43764 10 6452 1 2025-11-26 08:34:06.622 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47642 10 6452 1 2025-11-26 08:35:07.029 00:00:10.413 TCP 1.101.0.1:3000 -> 23.104.0.1:46944 11 6504 1 2025-11-26 08:36:07.487 00:00:10.442 TCP 1.101.0.1:3000 -> 23.104.0.1:36056 12 10578 1 2025-11-26 08:37:07.965 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:50324 10 6661 1 2025-11-26 08:38:07.607 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:34:06.463 00:05:01.529 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:38:07.583 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:38:07.532 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:38:07.453 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:38:07.525 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:38:08.330 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:50954 10 6661 1 2025-11-26 08:35:06.466 00:05:01.524 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:39:08.768 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:55876 10 6661 1 2025-11-26 08:40:09.179 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:42512 10 6661 1 2025-11-26 08:41:09.565 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:46060 10 6661 1 2025-11-26 08:42:09.926 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:57016 10 6661 1 2025-11-26 08:43:07.439 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:43:07.351 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:43:07.453 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:43:07.283 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:43:07.357 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:43:10.305 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:41886 10 6661 1 2025-11-26 08:40:06.465 00:05:01.531 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:44:10.704 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:40862 10 6661 1 2025-11-26 08:41:06.468 00:05:01.527 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:45:11.126 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59402 10 6661 1 2025-11-26 08:46:11.535 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:41738 10 6661 1 2025-11-26 08:47:11.905 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:45936 10 6661 1 2025-11-26 08:48:07.386 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:48:07.382 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:48:07.271 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:48:07.380 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:48:07.465 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:48:12.310 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:44474 10 6661 1 2025-11-26 08:49:12.679 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:54296 11 6713 1 2025-11-26 08:46:06.467 00:05:01.532 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:50:13.116 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:60776 10 6661 1 2025-11-26 08:47:06.469 00:05:01.527 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:51:13.479 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:35084 10 6661 1 2025-11-26 08:52:13.841 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:46008 10 6661 1 2025-11-26 08:53:07.633 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:53:07.591 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:53:07.608 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:53:07.631 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:53:07.713 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:53:14.258 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35212 10 6661 1 2025-11-26 08:54:14.661 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39896 10 6661 1 2025-11-26 08:55:15.089 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44396 10 6661 1 2025-11-26 08:52:06.467 00:05:01.533 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:56:15.492 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:44924 12 10787 1 2025-11-26 08:53:06.470 00:05:01.527 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:57:15.975 00:00:10.982 TCP 1.101.0.1:3000 -> 23.104.0.1:42652 10 6870 1 2025-11-26 08:58:07.567 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:58:07.792 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:58:07.592 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:58:07.582 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:58:07.675 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:58:16.997 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:36368 10 6870 1 Summary: total flows: 140, total bytes: 441395, total packets: 1028, avg bps: 975, avg pps: 0, avg bpp: 429 Time window: 2025-11-26 07:58:06 - 2025-11-26 08:58:27 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0038s User: 0.0019s Wall: 0.0020s flows/second: 70391.1 Runtime: 0.0020s