Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-02 01:59:01.140 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:34058 10 6452 1 2025-12-02 02:00:01.550 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:53456 10 6452 1 2025-12-02 02:00:52.831 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:00:52.787 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:00:52.674 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:00:52.747 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:00:52.845 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:01:01.948 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:46608 10 6452 1 2025-12-02 01:58:09.428 00:05:02.170 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 01:58:09.432 00:05:02.165 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:02:02.362 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:50954 10 6452 1 2025-12-02 02:03:02.769 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:60116 10 6452 1 2025-12-02 02:04:03.182 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:56770 10 6452 1 2025-12-02 02:05:03.583 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:50932 10 6452 1 2025-12-02 02:05:52.628 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:05:52.731 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:05:52.548 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:05:52.533 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:05:52.545 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:06:03.942 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:49212 10 6452 1 2025-12-02 02:07:04.369 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:43398 10 6452 1 2025-12-02 02:04:09.431 00:05:02.169 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:04:09.435 00:05:02.163 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:08:04.772 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:58346 10 6452 1 2025-12-02 02:09:05.179 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:58550 10 6452 1 2025-12-02 02:10:05.548 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:55636 10 6452 1 2025-12-02 02:10:52.819 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:10:52.896 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:10:52.857 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:10:52.560 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:10:52.737 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:11:05.913 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:57780 10 6452 1 2025-12-02 02:12:06.315 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:37620 10 6452 1 2025-12-02 02:13:06.716 00:00:10.474 TCP 1.101.0.1:3000 -> 23.104.0.1:40842 14 14298 1 2025-12-02 02:10:09.436 00:05:02.165 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:10:09.439 00:05:02.159 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:14:07.228 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:57234 10 6452 1 2025-12-02 02:15:07.635 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60088 10 6452 1 2025-12-02 02:15:52.985 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:15:52.982 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:15:52.910 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:15:53.093 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:15:52.903 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:16:08.042 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50806 10 6452 1 2025-12-02 02:17:08.449 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:59884 10 6452 1 2025-12-02 02:18:08.847 00:00:10.707 TCP 1.101.0.1:3000 -> 23.104.0.1:59532 10 6452 1 2025-12-02 02:19:09.594 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:56280 10 6452 1 2025-12-02 02:16:09.440 00:05:02.164 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:16:09.436 00:05:02.170 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:20:09.960 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54756 10 6452 1 2025-12-02 02:20:52.867 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:20:52.774 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:20:52.784 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:20:52.957 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:20:52.785 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:21:10.361 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:46538 10 6452 1 2025-12-02 02:22:10.765 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:59664 10 6452 1 2025-12-02 02:23:11.188 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:60974 10 6452 1 2025-12-02 02:24:11.586 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:59264 10 6452 1 2025-12-02 02:25:11.997 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:34054 10 6452 1 2025-12-02 02:25:53.299 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:25:53.164 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:25:53.302 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:25:53.105 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:25:53.382 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:22:09.440 00:05:02.164 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:22:09.438 00:05:02.169 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:26:12.397 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:53400 10 6452 1 2025-12-02 02:27:12.796 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:43398 10 6452 1 2025-12-02 02:28:13.212 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:39582 10 6452 1 2025-12-02 02:29:13.576 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:39750 10 6452 1 2025-12-02 02:30:13.941 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:56816 10 6452 1 2025-12-02 02:30:53.186 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:30:53.106 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:30:52.966 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:30:53.047 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:30:53.104 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:31:14.312 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:52140 10 6452 1 2025-12-02 02:28:09.441 00:05:02.165 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:28:09.439 00:05:02.170 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:32:14.735 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:35220 11 6492 1 2025-12-02 02:33:15.144 00:00:10.417 TCP 1.101.0.1:3000 -> 23.104.0.1:49006 11 6504 1 2025-12-02 02:34:15.601 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:43440 10 6452 1 2025-12-02 02:35:16.012 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:53498 10 6452 1 2025-12-02 02:35:53.342 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:35:53.407 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:35:53.373 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:35:53.190 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:35:53.273 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:36:16.413 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33004 10 6452 1 2025-12-02 02:37:16.818 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:33166 10 6452 1 2025-12-02 02:34:09.443 00:05:02.164 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:34:09.440 00:05:02.168 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:38:17.228 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:36892 10 6452 1 2025-12-02 02:39:17.627 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:35182 10 6452 1 2025-12-02 02:40:18.041 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:38346 10 6452 1 2025-12-02 02:40:53.482 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:40:53.354 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:40:53.355 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:40:53.411 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:40:53.493 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:41:18.444 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:40544 10 6452 1 2025-12-02 02:42:18.844 00:00:10.395 TCP 1.101.0.1:3000 -> 23.104.0.1:37036 10 6452 1 2025-12-02 02:43:19.277 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58412 10 6452 1 2025-12-02 02:40:09.444 00:05:02.165 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:40:09.441 00:05:02.169 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:44:19.682 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:57366 10 6452 1 2025-12-02 02:45:20.108 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:34932 10 6452 1 2025-12-02 02:45:53.553 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:45:53.553 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:45:53.452 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:45:53.495 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:45:53.579 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:46:20.507 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:45296 10 6452 1 2025-12-02 02:47:20.920 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:37140 10 6452 1 2025-12-02 02:48:21.327 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:38110 10 6452 1 2025-12-02 02:49:21.736 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:40178 10 6452 1 2025-12-02 02:46:09.441 00:05:02.170 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:46:09.445 00:05:02.165 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:50:22.145 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46470 10 6452 1 2025-12-02 02:50:53.542 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:50:53.547 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:50:53.658 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:50:53.538 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:50:53.619 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:51:22.552 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59232 10 6452 1 2025-12-02 02:52:22.962 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:33020 10 6452 1 2025-12-02 02:53:23.324 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35654 10 6452 1 2025-12-02 02:54:23.727 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:40338 10 6452 1 2025-12-02 02:55:24.140 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:41312 10 6452 1 2025-12-02 02:55:53.701 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:55:53.516 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:55:53.733 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:55:53.628 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:55:53.619 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:52:09.445 00:05:02.164 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:52:09.443 00:05:02.169 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:56:24.508 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:48534 10 6452 1 2025-12-02 02:57:24.912 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:36972 10 6452 1 2025-12-02 02:58:25.318 00:00:10.411 TCP 1.101.0.1:3000 -> 23.104.0.1:49796 11 6504 1 Summary: total flows: 140, total bytes: 424990, total packets: 1027, avg bps: 937, avg pps: 0, avg bpp: 413 Time window: 2025-12-02 01:58:09 - 2025-12-02 02:58:35 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0042s User: 0.0017s Wall: 0.0024s flows/second: 57349.6 Runtime: 0.0025s