Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-01 08:59:21.613 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50940 10 6452 1 2025-12-01 09:00:32.146 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:00:22.014 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:52900 10 6452 1 2025-12-01 09:00:32.083 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:00:31.931 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:00:31.951 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:00:32.035 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:01:22.418 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48212 10 6452 1 2025-12-01 08:58:09.071 00:05:02.164 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:58:09.069 00:05:02.168 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:02:22.822 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:38004 10 6452 1 2025-12-01 09:03:23.183 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:52416 10 6452 1 2025-12-01 09:04:23.586 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37636 10 6452 1 2025-12-01 09:05:32.246 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:05:32.179 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:05:32.285 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:05:32.222 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:05:32.164 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:05:23.990 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:34800 10 6452 1 2025-12-01 09:06:24.397 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:33086 10 6452 1 2025-12-01 09:07:24.806 00:00:10.413 TCP 1.101.0.1:3000 -> 23.104.0.1:55168 11 6504 1 2025-12-01 09:04:09.068 00:05:02.170 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:04:09.071 00:05:02.164 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:08:25.257 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:49184 10 6452 1 2025-12-01 09:09:25.623 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:57088 10 6452 1 2025-12-01 09:10:32.297 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:10:32.227 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:10:32.399 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:10:32.228 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:10:32.311 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:10:25.987 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:52894 10 6452 1 2025-12-01 09:11:26.395 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60844 10 6452 1 2025-12-01 09:12:26.802 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:52254 10 6452 1 2025-12-01 09:13:27.207 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:35866 10 6452 1 2025-12-01 09:10:09.072 00:05:02.164 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:10:09.071 00:05:02.168 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:14:27.572 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41740 10 6452 1 2025-12-01 09:15:32.841 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:15:32.704 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:15:32.557 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:15:32.724 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:15:32.759 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:15:27.977 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:43222 10 6452 1 2025-12-01 09:16:28.391 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:49080 10 6452 1 2025-12-01 09:17:28.757 00:00:10.390 TCP 1.101.0.1:3000 -> 23.104.0.1:39862 10 6452 1 2025-12-01 09:18:29.187 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:34622 10 6452 1 2025-12-01 09:19:29.547 00:00:10.436 TCP 1.101.0.1:3000 -> 23.104.0.1:33176 10 6452 1 2025-12-01 09:16:09.076 00:05:02.162 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:16:09.074 00:05:02.167 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:20:32.630 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:20:32.485 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:20:32.479 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:20:32.496 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:20:32.547 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:20:30.018 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:35688 10 6452 1 2025-12-01 09:21:30.417 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:58664 10 6452 1 2025-12-01 09:22:30.823 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:42034 10 6452 1 2025-12-01 09:23:31.232 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:56252 10 6452 1 2025-12-01 09:24:31.639 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:57720 10 6452 1 2025-12-01 09:25:32.550 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:25:32.562 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:25:32.560 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:25:32.634 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:25:32.468 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:25:32.040 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56274 10 6452 1 2025-12-01 09:22:09.075 00:05:02.168 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:22:09.078 00:05:02.163 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:26:32.444 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:52190 10 6452 1 2025-12-01 09:27:32.810 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:42332 10 6452 1 2025-12-01 09:28:33.217 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:38930 10 6452 1 2025-12-01 09:29:33.622 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:41726 10 6452 1 2025-12-01 09:30:32.848 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:30:32.633 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:30:32.636 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:30:32.374 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:30:32.764 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:30:34.026 00:00:11.080 TCP 1.101.0.1:3000 -> 23.104.0.1:43082 10 6452 1 2025-12-01 09:31:35.145 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56214 10 6452 1 2025-12-01 09:28:09.077 00:05:02.166 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:28:09.075 00:05:02.171 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:32:35.546 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:42908 10 6452 1 2025-12-01 09:33:35.945 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:46856 10 6452 1 2025-12-01 09:34:36.351 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:53564 10 6452 1 2025-12-01 09:35:32.750 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:35:32.642 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:35:32.820 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:35:32.778 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:35:32.832 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:35:36.753 00:00:16.078 TCP 1.101.0.1:3000 -> 23.104.0.1:33034 10 6452 1 2025-12-01 09:36:42.884 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39314 10 6452 1 2025-12-01 09:37:43.294 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:45604 10 6452 1 2025-12-01 09:34:09.078 00:05:02.166 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:34:09.077 00:05:02.171 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:38:43.701 00:00:10.583 TCP 1.101.0.1:3000 -> 23.104.0.1:46328 10 6452 1 2025-12-01 09:39:44.325 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:58014 10 6452 1 2025-12-01 09:40:33.057 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:40:32.933 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:40:32.983 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:40:32.745 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:40:32.833 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:40:44.722 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:54734 12 6556 1 2025-12-01 09:41:45.144 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47882 11 6492 1 2025-12-01 09:42:45.550 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:45142 10 6452 1 2025-12-01 09:43:45.954 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51012 10 6452 1 2025-12-01 09:40:09.076 00:05:02.172 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:40:09.080 00:05:02.167 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:44:46.359 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:59848 10 6452 1 2025-12-01 09:45:33.165 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:45:33.061 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:45:32.959 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:45:32.966 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:45:33.144 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:45:46.767 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:50794 10 6452 1 2025-12-01 09:46:47.186 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:58078 10 6452 1 2025-12-01 09:47:47.587 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57422 10 6452 1 2025-12-01 09:48:47.992 00:00:10.344 TCP 1.101.0.1:3000 -> 23.104.0.1:53346 10 6452 1 2025-12-01 09:49:48.384 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:46404 10 6452 1 2025-12-01 09:46:09.081 00:05:02.176 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:46:09.077 00:05:02.181 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:50:33.585 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:50:33.502 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:50:33.157 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:50:33.271 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:50:33.194 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:50:48.788 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:50356 10 6452 1 2025-12-01 09:51:49.187 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:47682 10 6452 1 2025-12-01 09:52:49.588 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:48154 10 6452 1 2025-12-01 09:53:49.959 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:32822 10 6452 1 2025-12-01 09:54:50.360 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:46114 10 6452 1 2025-12-01 09:55:33.077 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:55:33.096 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:55:33.124 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:55:33.350 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:55:33.432 00:00:00.027 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:55:50.764 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:50580 10 6452 1 2025-12-01 09:52:09.080 00:05:02.173 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:52:09.083 00:05:02.167 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:56:51.130 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:36004 10 6452 1 2025-12-01 09:57:51.542 00:00:10.351 TCP 1.101.0.1:3000 -> 23.104.0.1:50382 10 6452 1 Summary: total flows: 139, total bytes: 410744, total packets: 1014, avg bps: 914, avg pps: 0, avg bpp: 405 Time window: 2025-12-01 08:58:09 - 2025-12-01 09:58:01 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0043s User: 0.0011s Wall: 0.0022s flows/second: 62387.2 Runtime: 0.0022s