Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-08 03:59:38.218 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:57634 11 6504 1 2025-12-08 04:00:38.637 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46250 10 6452 1 2025-12-08 04:01:39.039 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:57002 10 6452 1 2025-12-08 03:58:12.522 00:05:02.391 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-08 03:58:12.525 00:05:02.387 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-08 04:02:39.443 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:44238 10 6452 1 2025-12-08 04:03:48.569 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:03:48.253 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:03:48.437 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:03:48.067 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:03:48.486 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:03:39.807 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:37216 10 6452 1 2025-12-08 04:04:40.210 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:39148 10 6452 1 2025-12-08 04:05:40.612 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:37320 10 6452 1 2025-12-08 04:06:41.021 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:50684 10 6452 1 2025-12-08 04:07:41.428 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:56164 10 6452 1 2025-12-08 04:04:12.527 00:05:02.387 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-08 04:04:12.525 00:05:02.392 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-08 04:08:48.466 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:08:48.527 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:08:48.551 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:08:48.462 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:08:48.549 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:08:41.838 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:43094 10 6452 1 2025-12-08 04:09:42.261 00:00:17.295 TCP 1.101.0.1:3000 -> 23.104.0.1:51060 10 6452 1 2025-12-08 04:10:49.596 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:49658 10 6452 1 2025-12-08 04:11:49.999 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:54312 10 6452 1 2025-12-08 04:12:50.402 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:57204 10 6452 1 2025-12-08 04:13:48.754 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:13:48.585 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:13:48.721 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:13:48.590 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:13:48.672 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:13:50.759 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:44202 10 6452 1 2025-12-08 04:10:12.525 00:05:02.393 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-08 04:10:12.529 00:05:02.388 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-08 04:14:51.170 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:34902 10 6452 1 2025-12-08 04:15:51.574 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:45236 10 6452 1 2025-12-08 04:16:51.971 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:45542 10 6452 1 2025-12-08 04:17:52.380 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:47398 10 6452 1 2025-12-08 04:18:48.974 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:18:48.974 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:18:49.194 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:18:48.977 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:18:49.060 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:18:52.746 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:33534 10 6452 1 2025-12-08 04:19:53.148 00:00:10.627 TCP 1.101.0.1:3000 -> 23.104.0.1:59174 10 6452 1 2025-12-08 04:16:12.532 00:05:02.391 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-08 04:16:12.528 00:05:02.396 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-08 04:20:53.831 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:57532 10 6452 1 2025-12-08 04:21:54.251 00:00:10.396 TCP 1.101.0.1:3000 -> 23.104.0.1:41616 10 6452 1 2025-12-08 04:22:54.701 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:43260 10 6452 1 2025-12-08 04:23:48.877 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:23:48.688 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:23:48.859 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:23:48.819 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:23:48.795 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:23:55.068 00:00:10.645 TCP 1.101.0.1:3000 -> 23.104.0.1:35436 10 6452 1 2025-12-08 04:24:55.754 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:59888 10 6452 1 2025-12-08 04:25:56.123 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:51724 10 6452 1 2025-12-08 04:22:12.532 00:05:02.410 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-08 04:22:12.530 00:05:02.415 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-08 04:26:56.487 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:51592 10 6452 1 2025-12-08 04:27:56.908 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:55772 12 6556 1 2025-12-08 04:28:49.056 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:28:48.970 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:28:48.836 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:28:48.935 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:28:48.974 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:28:57.310 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:34128 10 6452 1 2025-12-08 04:29:57.712 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59230 10 6452 1 2025-12-08 04:30:58.114 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:38342 10 6452 1 2025-12-08 04:31:58.524 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44266 10 6452 1 2025-12-08 04:28:12.532 00:05:02.414 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-08 04:28:12.535 00:05:02.409 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-08 04:32:58.921 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:54720 10 6452 1 2025-12-08 04:33:49.098 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:33:48.965 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:33:49.015 00:00:00.041 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:33:49.188 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:33:49.270 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:33:59.329 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:58948 10 6452 1 2025-12-08 04:34:59.726 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:58774 10 6452 1 2025-12-08 04:36:00.141 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:55516 10 6452 1 2025-12-08 04:37:00.542 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:56438 10 6452 1 2025-12-08 04:38:00.906 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59712 10 6452 1 2025-12-08 04:34:12.533 00:05:02.413 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-08 04:34:12.537 00:05:02.408 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-08 04:38:49.584 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:38:49.502 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:38:49.294 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:38:49.284 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:38:49.067 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:39:01.312 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:48380 10 6452 1 2025-12-08 04:40:01.704 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:34924 10 6452 1 2025-12-08 04:41:02.112 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:55992 10 6452 1 2025-12-08 04:42:02.512 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:52928 10 6452 1 2025-12-08 04:43:02.917 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:54998 10 6452 1 2025-12-08 04:43:49.164 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:43:49.280 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:43:48.913 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:43:49.163 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:43:49.246 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:44:03.341 00:00:10.445 TCP 1.101.0.1:3000 -> 23.104.0.1:50392 12 10375 1 2025-12-08 04:40:12.539 00:05:02.410 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-08 04:40:12.537 00:05:02.415 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-08 04:45:03.828 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:44724 10 6452 1 2025-12-08 04:46:04.234 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:60708 10 6452 1 2025-12-08 04:47:04.593 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:45604 10 6452 1 2025-12-08 04:48:04.991 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:45232 10 6452 1 2025-12-08 04:48:49.196 00:00:00.025 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:48:49.350 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:48:49.203 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:48:49.197 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:48:49.287 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:49:05.409 00:00:10.355 TCP 1.101.0.1:3000 -> 23.104.0.1:50388 10 6452 1 2025-12-08 04:50:05.798 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:47826 10 6452 1 2025-12-08 04:46:12.540 00:05:02.409 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-08 04:46:12.537 00:05:02.415 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-08 04:51:06.201 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53344 10 6452 1 2025-12-08 04:52:06.608 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:47458 10 6452 1 2025-12-08 04:53:07.037 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39372 10 6452 1 2025-12-08 04:53:49.485 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:53:49.431 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:53:49.261 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:53:49.432 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:53:49.515 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:54:07.439 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:58960 10 6452 1 2025-12-08 04:55:07.809 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:43166 12 6556 1 2025-12-08 04:52:12.538 00:05:02.416 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-08 04:56:08.240 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:41438 10 6452 1 2025-12-08 04:52:12.540 00:05:02.411 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-08 04:57:08.656 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:43782 10 6452 1 2025-12-08 04:58:09.022 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:40146 10 6452 1 2025-12-08 04:58:49.805 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-08 04:58:49.679 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-08 04:58:49.626 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-08 04:58:49.288 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-08 04:58:49.724 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 Summary: total flows: 139, total bytes: 414731, total packets: 1017, avg bps: 912, avg pps: 0, avg bpp: 407 Time window: 2025-12-08 03:58:12 - 2025-12-08 04:58:49 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0027s User: 0.0027s Wall: 0.0021s flows/second: 67438.8 Runtime: 0.0021s