Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-01 03:59:09.979 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50720 10 6452 1 2025-12-01 04:00:10.384 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:56926 10 6452 1 2025-12-01 04:00:26.156 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:00:26.109 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:00:25.850 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:00:26.221 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:00:26.306 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:01:10.791 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:45782 10 6452 1 2025-12-01 03:58:08.931 00:05:02.196 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 03:58:08.934 00:05:02.191 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 04:02:11.157 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49194 10 6452 1 2025-12-01 04:03:11.559 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:38474 10 6452 1 2025-12-01 04:04:11.917 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:47692 10 6452 1 2025-12-01 04:05:12.321 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:38674 10 6452 1 2025-12-01 04:05:26.303 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:05:26.355 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:05:26.303 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:05:26.223 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:05:26.385 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:06:12.689 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:33170 10 6452 1 2025-12-01 04:07:13.115 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41164 10 6452 1 2025-12-01 04:04:08.935 00:05:02.191 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 04:04:08.933 00:05:02.195 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 04:08:13.516 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:54848 10 6452 1 2025-12-01 04:09:13.926 00:00:10.349 TCP 1.101.0.1:3000 -> 23.104.0.1:41466 10 6452 1 2025-12-01 04:10:14.315 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:43248 10 6452 1 2025-12-01 04:10:26.303 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:10:26.317 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:10:26.327 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:10:26.306 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:10:26.389 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:11:14.678 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:49614 10 6452 1 2025-12-01 04:12:15.107 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41834 10 6452 1 2025-12-01 04:13:15.515 00:00:10.544 TCP 1.101.0.1:3000 -> 23.104.0.1:37876 10 6452 1 2025-12-01 04:10:08.938 00:05:02.193 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 04:10:08.935 00:05:02.198 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 04:14:16.111 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:34980 10 6452 1 2025-12-01 04:15:26.875 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:15:26.671 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:15:26.706 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:15:26.519 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:15:16.516 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:58580 10 6452 1 2025-12-01 04:15:26.792 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:16:16.876 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:57082 10 6452 1 2025-12-01 04:17:17.284 00:00:10.521 TCP 1.101.0.1:3000 -> 23.104.0.1:38388 14 14292 1 2025-12-01 04:18:17.837 00:00:15.812 TCP 1.101.0.1:3000 -> 23.104.0.1:53362 10 6452 1 2025-12-01 04:19:23.710 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:33738 10 6452 1 2025-12-01 04:16:08.942 00:05:02.192 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 04:16:08.940 00:05:02.198 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 04:20:26.418 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:20:26.452 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:20:26.457 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:20:26.450 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:20:26.336 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:20:24.113 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55638 10 6452 1 2025-12-01 04:21:24.517 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:40974 10 6452 1 2025-12-01 04:22:24.917 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:47960 10 6452 1 2025-12-01 04:23:25.325 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39500 10 6452 1 2025-12-01 04:24:25.730 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:57532 10 6452 1 2025-12-01 04:25:26.732 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:25:26.582 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:25:26.595 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:25:26.604 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:25:26.650 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:25:26.108 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:55418 10 6452 1 2025-12-01 04:22:08.940 00:05:02.201 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 04:22:08.942 00:05:02.196 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 04:26:26.508 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:58412 10 6452 1 2025-12-01 04:27:26.916 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:53204 10 6452 1 2025-12-01 04:28:27.318 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:49288 10 6452 1 2025-12-01 04:29:27.720 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:38464 10 6452 1 2025-12-01 04:30:26.793 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:30:26.786 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:30:26.691 00:00:00.026 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:30:27.006 00:00:00.041 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:30:27.088 00:00:00.042 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:30:28.135 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:50152 10 6452 1 2025-12-01 04:31:28.508 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:56980 10 6452 1 2025-12-01 04:28:08.941 00:05:02.202 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 04:28:08.944 00:05:02.196 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 04:32:28.912 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:52492 10 6452 1 2025-12-01 04:33:29.322 00:00:10.334 TCP 1.101.0.1:3000 -> 23.104.0.1:60114 10 6452 1 2025-12-01 04:34:29.696 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:42354 10 6452 1 2025-12-01 04:35:26.923 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:35:26.872 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:35:26.512 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:35:26.916 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:35:27.002 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:35:30.113 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:37530 10 6452 1 2025-12-01 04:36:30.487 00:00:10.540 TCP 1.101.0.1:3000 -> 23.104.0.1:58276 10 6452 1 2025-12-01 04:37:31.095 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:47610 10 6452 1 2025-12-01 04:34:08.942 00:05:02.203 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 04:34:08.945 00:05:02.198 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 04:38:31.493 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37444 10 6452 1 2025-12-01 04:39:31.895 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:45534 10 6452 1 2025-12-01 04:40:26.858 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:40:26.857 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:40:26.813 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:40:26.774 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:40:26.857 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:40:32.301 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:37778 10 6452 1 2025-12-01 04:41:32.662 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:59622 10 6452 1 2025-12-01 04:42:33.030 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:35518 10 6452 1 2025-12-01 04:43:33.433 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:54282 10 6452 1 2025-12-01 04:40:08.948 00:05:02.196 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 04:40:08.946 00:05:02.201 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 04:44:33.834 00:00:10.394 TCP 1.101.0.1:3000 -> 23.104.0.1:34046 10 6452 1 2025-12-01 04:45:27.141 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:45:26.982 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:45:27.056 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:45:26.995 00:00:00.034 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:45:27.058 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:45:34.268 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:49116 10 6452 1 2025-12-01 04:46:34.674 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:54272 10 6452 1 2025-12-01 04:47:35.056 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:41516 10 6452 1 2025-12-01 04:48:35.458 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:51498 10 6452 1 2025-12-01 04:49:35.858 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:42808 10 6452 1 2025-12-01 04:46:08.949 00:05:02.197 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 04:46:08.946 00:05:02.202 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 04:50:26.953 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:50:26.871 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:50:26.969 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:50:27.071 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:50:27.154 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:50:36.228 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:40306 10 6452 1 2025-12-01 04:51:36.635 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:38884 10 6452 1 2025-12-01 04:52:37.042 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:54220 10 6452 1 2025-12-01 04:53:37.446 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:42950 10 6452 1 2025-12-01 04:54:37.861 00:00:11.558 TCP 1.101.0.1:3000 -> 23.104.0.1:41982 10 6452 1 2025-12-01 04:55:27.298 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 04:55:27.266 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 04:55:27.056 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 04:55:27.106 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:55:27.214 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 04:55:39.460 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:53640 10 6452 1 2025-12-01 04:52:08.949 00:05:02.200 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 04:52:08.952 00:05:02.195 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 04:56:39.861 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:55624 10 6452 1 2025-12-01 04:57:40.278 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:48902 10 6452 1 Summary: total flows: 139, total bytes: 418388, total packets: 1014, avg bps: 934, avg pps: 0, avg bpp: 412 Time window: 2025-12-01 03:58:08 - 2025-12-01 04:57:50 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0043s User: 0.0011s Wall: 0.0023s flows/second: 59992.6 Runtime: 0.0023s