Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-01 07:58:56.201 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:37400 10 6452 1 2025-12-01 07:59:56.567 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:34046 10 6452 1 2025-12-01 08:00:31.069 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:00:31.070 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:00:30.497 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:00:30.922 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:00:31.005 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:00:56.972 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:52688 10 6452 1 2025-12-01 07:57:11.213 00:05:57.839 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 07:57:11.210 00:05:57.844 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:01:57.405 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:41092 10 6452 1 2025-12-01 08:02:57.826 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:59112 10 6452 1 2025-12-01 08:03:58.228 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:35288 10 6452 1 2025-12-01 08:04:58.632 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:57754 10 6452 1 2025-12-01 08:05:30.895 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:05:31.077 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:05:30.947 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:05:31.179 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:05:31.262 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:05:58.999 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54806 10 6452 1 2025-12-01 08:06:59.405 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46736 10 6452 1 2025-12-01 08:03:11.211 00:05:57.843 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:07:59.809 00:00:10.459 TCP 1.101.0.1:3000 -> 23.104.0.1:59178 10 6452 1 2025-12-01 08:03:11.214 00:06:00.001 TCP 179.21.23.23:179 -> 179.21.23.21:38570 13 790 1 2025-12-01 08:09:00.324 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47956 10 6452 1 2025-12-01 08:10:00.732 00:00:10.611 TCP 1.101.0.1:3000 -> 23.104.0.1:38444 10 6452 1 2025-12-01 08:10:31.407 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:10:31.095 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:10:30.977 00:00:00.025 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:10:31.119 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:10:31.325 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:11:01.383 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58588 10 6452 1 2025-12-01 08:12:01.787 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:56920 10 6452 1 2025-12-01 08:13:02.190 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:40806 10 6452 1 2025-12-01 08:10:09.052 00:05:02.164 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:09:11.213 00:05:57.845 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:14:02.603 00:00:11.020 TCP 1.101.0.1:3000 -> 23.104.0.1:39970 10 6452 1 2025-12-01 08:15:03.674 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:56700 10 6452 1 2025-12-01 08:15:31.482 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:15:31.329 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:15:31.351 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:15:31.357 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:15:31.400 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:16:04.032 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:38334 10 6452 1 2025-12-01 08:17:04.433 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51972 10 6452 1 2025-12-01 08:18:04.837 00:00:10.458 TCP 1.101.0.1:3000 -> 23.104.0.1:40594 12 10375 1 2025-12-01 08:19:05.333 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47494 10 6452 1 2025-12-01 08:15:11.214 00:05:57.845 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:16:09.055 00:05:02.163 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:20:05.731 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:51166 10 6452 1 2025-12-01 08:20:31.476 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:20:31.158 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:20:31.385 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:20:31.182 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:20:31.394 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:21:06.147 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:35168 10 6452 1 2025-12-01 08:22:06.553 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:36694 12 6556 1 2025-12-01 08:23:06.965 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:40930 10 6452 1 2025-12-01 08:24:07.331 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:42032 10 6452 1 2025-12-01 08:25:07.741 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:42098 10 6452 1 2025-12-01 08:25:31.698 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:25:31.540 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:25:31.411 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:25:31.219 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:25:31.616 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:21:11.216 00:05:57.844 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:22:09.056 00:05:02.165 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:26:08.147 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37480 10 6452 1 2025-12-01 08:27:08.549 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:49796 10 6452 1 2025-12-01 08:28:08.952 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:42534 10 6452 1 2025-12-01 08:29:09.367 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:57298 10 6452 1 2025-12-01 08:30:09.766 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:40018 10 6452 1 2025-12-01 08:30:31.558 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:30:31.621 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:30:31.498 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:30:31.552 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:30:31.635 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:31:10.178 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:46664 10 6452 1 2025-12-01 08:27:11.219 00:05:57.843 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:28:09.059 00:05:02.165 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:32:10.545 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54418 10 6452 1 2025-12-01 08:33:10.943 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:50080 10 6452 1 2025-12-01 08:34:11.365 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47694 10 6452 1 2025-12-01 08:35:11.767 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:52064 10 6452 1 2025-12-01 08:35:31.682 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:35:31.838 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:35:31.751 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:35:31.676 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:35:31.759 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:36:12.189 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:59376 10 6452 1 2025-12-01 08:37:12.597 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:49252 10 6452 1 2025-12-01 08:33:11.222 00:05:57.845 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:34:09.059 00:05:02.166 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:38:13.014 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:46594 10 6452 1 2025-12-01 08:39:13.439 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:60726 10 6452 1 2025-12-01 08:40:13.845 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:37562 10 6452 1 2025-12-01 08:40:31.793 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:40:31.666 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:40:31.512 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:40:31.826 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:40:31.909 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:41:14.271 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:41618 10 6452 1 2025-12-01 08:42:14.677 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:51772 10 6452 1 2025-12-01 08:43:15.117 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:40970 10 6452 1 2025-12-01 08:40:09.063 00:05:02.166 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:39:11.223 00:06:00.004 TCP 179.21.23.21:38570 -> 179.21.23.23:179 13 809 1 2025-12-01 08:44:15.486 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:35640 10 6452 1 2025-12-01 08:45:15.852 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:52932 10 6452 1 2025-12-01 08:45:31.821 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:45:31.739 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:45:31.911 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:45:31.815 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:45:31.764 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:46:16.281 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36926 10 6452 1 2025-12-01 08:47:16.685 00:00:10.450 TCP 1.101.0.1:3000 -> 23.104.0.1:56780 12 10369 1 2025-12-01 08:48:17.179 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:36468 10 6452 1 2025-12-01 08:49:17.579 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:59080 10 6452 1 2025-12-01 08:46:09.067 00:05:02.161 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:46:09.064 00:05:02.166 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:50:17.995 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:47448 10 6452 1 2025-12-01 08:50:31.958 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:50:32.042 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:50:31.923 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:50:31.816 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:50:31.866 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:51:18.362 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:56346 10 6452 1 2025-12-01 08:52:18.761 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:32988 10 6452 1 2025-12-01 08:53:19.181 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:52640 10 6452 1 2025-12-01 08:54:19.582 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40080 10 6452 1 2025-12-01 08:55:32.521 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:55:32.518 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:55:32.220 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:55:32.164 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:55:19.986 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:50216 10 6452 1 2025-12-01 08:55:32.437 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:52:09.068 00:05:02.161 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:52:09.067 00:05:02.166 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:56:20.397 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52022 10 6452 1 2025-12-01 08:57:20.799 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:56938 10 6452 1 2025-12-01 08:58:21.204 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39778 10 6452 1 Summary: total flows: 140, total bytes: 425067, total packets: 1028, avg bps: 923, avg pps: 0, avg bpp: 413 Time window: 2025-12-01 07:57:11 - 2025-12-01 08:58:31 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0050s User: 0.0020s Wall: 0.0022s flows/second: 63406.0 Runtime: 0.0022s