Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-04 03:59:35.286 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:50858 10 6661 1 2025-12-04 04:00:35.692 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:36368 10 6661 1 2025-12-04 04:01:36.109 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:39662 10 6661 1 2025-12-04 04:01:52.993 00:00:00.042 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:01:52.994 00:00:00.043 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:01:52.740 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:01:52.846 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:01:52.929 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 03:58:10.476 00:05:02.172 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 03:58:10.475 00:05:02.177 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 04:02:36.474 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37820 10 6661 1 2025-12-04 04:03:36.876 00:00:10.787 TCP 1.101.0.1:3000 -> 23.104.0.1:38582 10 6661 1 2025-12-04 04:04:37.701 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:39164 10 6661 1 2025-12-04 04:05:38.101 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:57972 10 6661 1 2025-12-04 04:06:38.496 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:48954 10 6661 1 2025-12-04 04:06:52.886 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:06:52.878 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:06:52.812 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:06:52.815 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:06:52.804 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:07:38.863 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:59370 10 6661 1 2025-12-04 04:04:10.475 00:05:02.178 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 04:04:10.478 00:05:02.172 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 04:08:39.280 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:49834 10 6661 1 2025-12-04 04:09:39.693 00:00:10.342 TCP 1.101.0.1:3000 -> 23.104.0.1:38390 10 6661 1 2025-12-04 04:10:40.103 00:00:10.417 TCP 1.101.0.1:3000 -> 23.104.0.1:40628 11 6713 1 2025-12-04 04:11:52.900 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:11:52.726 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:11:53.011 00:00:00.032 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:11:52.796 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:11:40.563 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:49292 10 6661 1 2025-12-04 04:11:53.092 00:00:00.034 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:12:40.924 00:00:10.390 TCP 1.101.0.1:3000 -> 23.104.0.1:59402 10 6661 1 2025-12-04 04:13:41.355 00:00:10.888 TCP 1.101.0.1:3000 -> 23.104.0.1:51152 10 6661 1 2025-12-04 04:10:10.480 00:05:02.171 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 04:10:10.479 00:05:02.176 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 04:14:42.280 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:46110 10 6661 1 2025-12-04 04:15:42.681 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:47054 10 6661 1 2025-12-04 04:16:53.242 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:16:52.869 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:16:53.082 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:16:52.993 00:00:00.039 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:16:43.051 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:41564 10 6661 1 2025-12-04 04:16:53.159 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:17:43.452 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:36760 10 6661 1 2025-12-04 04:18:43.855 00:00:10.453 TCP 1.101.0.1:3000 -> 23.104.0.1:54116 12 10369 1 2025-12-04 04:19:44.350 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:42126 10 6452 1 2025-12-04 04:16:10.481 00:05:02.171 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 04:16:10.479 00:05:02.177 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 04:20:44.765 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:52814 10 6452 1 2025-12-04 04:21:53.249 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:21:53.337 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:21:53.268 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:21:52.964 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:21:53.420 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:21:45.189 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:56822 10 6452 1 2025-12-04 04:22:45.595 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:33108 10 6452 1 2025-12-04 04:23:45.964 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:41964 10 6452 1 2025-12-04 04:24:46.331 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:43442 10 6452 1 2025-12-04 04:25:46.731 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:55068 10 6452 1 2025-12-04 04:22:10.486 00:05:02.169 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 04:22:10.484 00:05:02.174 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 04:26:53.455 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:26:53.438 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:26:53.379 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:26:53.432 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:26:53.373 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:26:47.112 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:36718 10 6452 1 2025-12-04 04:27:47.479 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55480 10 6452 1 2025-12-04 04:28:47.890 00:00:10.341 TCP 1.101.0.1:3000 -> 23.104.0.1:44958 10 6452 1 2025-12-04 04:29:48.270 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:42118 10 6452 1 2025-12-04 04:30:48.674 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:33102 10 6452 1 2025-12-04 04:31:53.302 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:31:53.218 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:31:53.289 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:31:53.366 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:31:53.387 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:31:49.105 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:42532 10 6452 1 2025-12-04 04:28:10.487 00:05:02.170 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 04:28:10.485 00:05:02.174 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 04:32:49.506 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:39168 12 6556 1 2025-12-04 04:33:49.908 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40290 10 6452 1 2025-12-04 04:34:50.310 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:56594 10 6452 1 2025-12-04 04:35:50.723 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:38484 10 6452 1 2025-12-04 04:36:53.468 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:36:53.139 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:36:53.470 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:36:53.474 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:36:53.553 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:36:51.136 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51436 10 6452 1 2025-12-04 04:37:51.541 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:44974 10 6452 1 2025-12-04 04:34:10.491 00:05:02.170 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 04:34:10.492 00:05:02.166 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 04:38:51.959 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:38998 10 6452 1 2025-12-04 04:39:52.376 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:40228 10 6452 1 2025-12-04 04:40:52.785 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:44876 10 6452 1 2025-12-04 04:41:53.509 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:41:53.393 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:41:53.376 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:41:53.784 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:41:53.867 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:41:53.207 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:36046 10 6452 1 2025-12-04 04:42:53.572 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:47768 10 6452 1 2025-12-04 04:43:53.968 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:60846 10 6452 1 2025-12-04 04:40:10.493 00:05:02.166 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 04:40:10.491 00:05:02.170 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 04:44:54.384 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:40524 10 6452 1 2025-12-04 04:45:54.792 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:48342 10 6452 1 2025-12-04 04:46:53.723 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:46:53.609 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:46:53.683 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:46:53.730 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:46:53.812 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:46:55.205 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35472 10 6452 1 2025-12-04 04:47:55.606 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:50924 10 6452 1 2025-12-04 04:48:56.011 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:53864 10 6452 1 2025-12-04 04:49:56.424 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56486 10 6452 1 2025-12-04 04:46:10.495 00:05:02.166 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 04:46:10.492 00:05:02.171 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 04:50:56.826 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:34828 10 6452 1 2025-12-04 04:51:53.954 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:51:53.499 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:51:53.871 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:51:53.815 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:51:53.664 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:51:57.230 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:38680 10 6452 1 2025-12-04 04:52:57.632 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:50310 10 6452 1 2025-12-04 04:53:58.049 00:00:14.586 TCP 1.101.0.1:3000 -> 23.104.0.1:57958 10 6452 1 2025-12-04 04:55:02.670 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:33024 10 6452 1 2025-12-04 04:52:10.494 00:05:02.167 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 04:56:03.101 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:60754 10 6452 1 2025-12-04 04:52:10.493 00:05:02.172 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 04:56:53.756 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 04:56:53.858 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 04:56:53.872 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:56:53.754 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 04:56:53.837 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 04:57:03.499 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:56958 10 6452 1 2025-12-04 04:58:03.905 00:00:10.443 TCP 1.101.0.1:3000 -> 23.104.0.1:42768 12 6556 1 Summary: total flows: 139, total bytes: 418696, total packets: 1017, avg bps: 929, avg pps: 0, avg bpp: 411 Time window: 2025-12-04 03:58:10 - 2025-12-04 04:58:14 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0024s User: 0.0016s Wall: 0.0013s flows/second: 103041.4 Runtime: 0.0014s