Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-01 15:58:43.029 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:35900 10 6452 1 2025-12-01 15:59:43.434 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:34060 10 6452 1 2025-12-01 16:00:40.472 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:00:40.600 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:00:40.445 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:00:40.598 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:00:40.680 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:00:43.853 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:38360 10 6452 1 2025-12-01 16:01:44.268 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:41114 10 6452 1 2025-12-01 15:58:09.199 00:05:02.175 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 15:58:09.198 00:05:02.180 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 16:02:44.638 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:36940 10 6452 1 2025-12-01 16:03:45.040 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:33660 10 6452 1 2025-12-01 16:04:45.446 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:35024 10 6452 1 2025-12-01 16:05:40.685 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:05:40.595 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:05:40.593 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:05:40.414 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:05:40.602 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:05:45.851 00:00:10.388 TCP 1.101.0.1:3000 -> 23.104.0.1:37076 10 6452 1 2025-12-01 16:06:46.272 00:00:10.405 TCP 1.101.0.1:3000 -> 23.104.0.1:54418 10 6452 1 2025-12-01 16:07:46.714 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:52916 10 6452 1 2025-12-01 16:04:09.199 00:05:02.180 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 16:04:09.201 00:05:02.176 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 16:08:47.135 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39496 10 6452 1 2025-12-01 16:09:47.536 00:00:10.388 TCP 1.101.0.1:3000 -> 23.104.0.1:42588 10 6452 1 2025-12-01 16:10:40.893 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:10:40.775 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:10:40.772 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:10:40.743 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:10:40.811 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:10:47.961 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:37630 10 6452 1 2025-12-01 16:11:48.322 00:00:11.134 TCP 1.101.0.1:3000 -> 23.104.0.1:39986 10 6452 1 2025-12-01 16:12:49.496 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37488 10 6452 1 2025-12-01 16:13:49.907 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:41656 10 6452 1 2025-12-01 16:10:09.203 00:05:02.177 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 16:10:09.200 00:05:02.182 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 16:14:50.312 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:32958 10 6452 1 2025-12-01 16:15:40.894 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:15:41.072 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:15:40.843 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:15:40.812 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:15:41.140 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:15:50.710 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:44738 10 6452 1 2025-12-01 16:16:51.096 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:39614 10 6452 1 2025-12-01 16:17:51.507 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37894 10 6452 1 2025-12-01 16:18:51.907 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:46228 10 6452 1 2025-12-01 16:19:52.311 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35726 10 6452 1 2025-12-01 16:16:09.207 00:05:02.174 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 16:16:09.205 00:05:02.179 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 16:20:41.093 00:00:00.031 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:20:40.823 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:20:41.127 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:20:40.850 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:20:41.011 00:00:00.031 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:20:52.710 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:45136 10 6452 1 2025-12-01 16:21:53.104 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:38760 10 6452 1 2025-12-01 16:22:53.484 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:49526 10 6452 1 2025-12-01 16:23:53.849 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:58138 10 6452 1 2025-12-01 16:24:54.253 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:59542 10 6452 1 2025-12-01 16:25:40.969 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:25:40.970 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:25:41.144 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:25:40.926 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:25:40.887 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:25:54.659 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:33344 10 6452 1 2025-12-01 16:22:09.204 00:05:02.181 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 16:22:09.207 00:05:02.176 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 16:26:55.017 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58174 10 6452 1 2025-12-01 16:27:55.425 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:52050 10 6452 1 2025-12-01 16:28:55.837 00:00:10.344 TCP 1.101.0.1:3000 -> 23.104.0.1:60318 10 6452 1 2025-12-01 16:29:56.217 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:39232 10 6452 1 2025-12-01 16:30:41.139 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:30:41.061 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:30:41.101 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:30:40.945 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:30:41.029 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:30:56.579 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:46818 10 6452 1 2025-12-01 16:31:56.979 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:50948 10 6452 1 2025-12-01 16:28:09.208 00:05:02.175 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 16:28:09.206 00:05:02.180 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 16:32:57.383 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:33212 10 6452 1 2025-12-01 16:33:57.785 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:53700 10 6452 1 2025-12-01 16:34:58.190 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:59278 10 6452 1 2025-12-01 16:35:41.351 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:35:41.112 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:35:41.211 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:35:41.315 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:35:41.268 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:35:58.586 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:49146 10 6452 1 2025-12-01 16:36:58.987 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:58946 10 6452 1 2025-12-01 16:37:59.389 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:47490 10 6452 1 2025-12-01 16:34:09.213 00:05:02.173 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 16:34:09.210 00:05:02.178 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 16:38:59.748 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52682 10 6452 1 2025-12-01 16:40:00.154 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:56788 10 6452 1 2025-12-01 16:40:41.630 00:00:00.036 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:40:41.308 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:40:41.480 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:40:41.348 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:40:41.547 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:41:00.561 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:50138 10 6452 1 2025-12-01 16:42:00.963 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:56552 10 6452 1 2025-12-01 16:43:01.363 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39252 10 6452 1 2025-12-01 16:40:09.214 00:05:02.175 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 16:40:09.216 00:05:02.170 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 16:44:01.770 00:00:10.705 TCP 1.101.0.1:3000 -> 23.104.0.1:43934 10 6452 1 2025-12-01 16:45:02.513 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:44602 10 6452 1 2025-12-01 16:45:41.396 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:45:41.520 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:45:41.463 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:45:41.355 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:45:41.313 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:46:02.917 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:37878 10 6452 1 2025-12-01 16:47:03.327 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58816 10 6452 1 2025-12-01 16:48:03.736 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:49694 10 6452 1 2025-12-01 16:49:04.144 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54720 10 6452 1 2025-12-01 16:46:09.216 00:05:02.175 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 16:46:09.217 00:05:02.170 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 16:50:04.556 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:45654 10 6452 1 2025-12-01 16:50:41.737 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:50:41.578 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:50:41.652 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:50:41.724 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:50:41.656 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:51:04.920 00:00:10.403 TCP 1.101.0.1:3000 -> 23.104.0.1:41796 10 6452 1 2025-12-01 16:52:05.360 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:43340 10 6452 1 2025-12-01 16:53:05.722 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:51812 10 6452 1 2025-12-01 16:54:06.132 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:51134 10 6452 1 2025-12-01 16:55:06.529 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:47248 10 6452 1 2025-12-01 16:55:42.066 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 16:55:41.655 00:00:00.027 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 16:55:41.684 00:00:00.025 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 16:55:41.862 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:55:41.984 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 16:52:09.224 00:05:02.165 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 16:52:09.221 00:05:02.170 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 16:56:06.929 00:00:10.395 TCP 1.101.0.1:3000 -> 23.104.0.1:59516 10 6452 1 2025-12-01 16:57:07.363 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:42122 10 6452 1 2025-12-01 16:58:07.726 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60360 10 6452 1 Summary: total flows: 140, total bytes: 417000, total packets: 1020, avg bps: 924, avg pps: 0, avg bpp: 408 Time window: 2025-12-01 15:58:09 - 2025-12-01 16:58:18 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0031s User: 0.0021s Wall: 0.0020s flows/second: 69788.8 Runtime: 0.0020s