Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-13 08:58:54.618 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39670 10 6452 1 2025-12-13 08:59:55.026 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37896 10 6452 1 2025-12-13 09:00:55.430 00:00:10.420 TCP 1.101.0.1:3000 -> 23.104.0.1:53514 11 6504 1 2025-12-13 09:01:18.778 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 08:57:15.324 00:05:02.397 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-13 09:01:18.786 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:01:18.631 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:01:18.778 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:01:18.862 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 08:57:15.322 00:05:02.402 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-13 09:01:55.886 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:40012 12 6556 1 2025-12-13 09:02:56.310 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:40922 10 6452 1 2025-12-13 09:03:56.713 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48086 10 6452 1 2025-12-13 09:04:57.114 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:40916 10 6452 1 2025-12-13 09:05:57.525 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:42048 10 6452 1 2025-12-13 09:06:19.352 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:06:19.397 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:06:19.296 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:06:19.295 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:06:19.379 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:06:57.932 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:55996 10 6452 1 2025-12-13 09:03:15.322 00:05:02.403 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-13 09:03:15.326 00:05:02.398 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-13 09:07:58.362 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:57114 10 6452 1 2025-12-13 09:08:58.758 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:44838 10 6452 1 2025-12-13 09:09:59.167 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:37640 10 6452 1 2025-12-13 09:10:59.570 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:51192 10 6452 1 2025-12-13 09:11:19.046 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:11:18.858 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:11:18.890 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:11:19.040 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:11:19.123 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:11:59.982 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:48316 10 6452 1 2025-12-13 09:13:00.390 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:42474 10 6452 1 2025-12-13 09:09:15.333 00:05:02.409 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-13 09:09:15.335 00:05:02.405 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-13 09:14:00.793 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:54976 10 6452 1 2025-12-13 09:15:01.227 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:43566 10 6452 1 2025-12-13 09:16:01.638 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47700 10 6452 1 2025-12-13 09:16:18.926 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:16:19.109 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:16:19.102 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:16:18.788 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:16:18.844 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:17:02.052 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:36522 10 6452 1 2025-12-13 09:18:02.450 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49162 10 6452 1 2025-12-13 09:19:02.852 00:00:10.348 TCP 1.101.0.1:3000 -> 23.104.0.1:39026 10 6452 1 2025-12-13 09:15:15.336 00:05:02.406 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-13 09:15:15.332 00:05:02.412 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-13 09:20:03.242 00:00:10.702 TCP 1.101.0.1:3000 -> 23.104.0.1:59640 10 6452 1 2025-12-13 09:21:03.981 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:40938 10 6452 1 2025-12-13 09:21:19.223 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:21:19.171 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:21:19.225 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:21:19.224 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:21:19.307 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:22:04.386 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:58622 10 6452 1 2025-12-13 09:23:04.750 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:60088 10 6452 1 2025-12-13 09:24:05.166 00:00:10.356 TCP 1.101.0.1:3000 -> 23.104.0.1:33716 10 6452 1 2025-12-13 09:21:15.338 00:05:02.405 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-13 09:21:15.340 00:05:02.400 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-13 09:25:05.561 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:46074 10 6452 1 2025-12-13 09:26:19.303 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:26:05.965 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:51598 10 6452 1 2025-12-13 09:26:19.292 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:26:19.212 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:26:19.151 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:26:19.387 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:27:06.337 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:59432 10 6452 1 2025-12-13 09:28:06.735 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:47692 10 6452 1 2025-12-13 09:29:07.144 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:43142 10 6452 1 2025-12-13 09:30:07.551 00:00:10.487 TCP 1.101.0.1:3000 -> 23.104.0.1:37832 10 6452 1 2025-12-13 09:31:19.097 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:31:19.201 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:31:08.104 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:47786 10 6452 1 2025-12-13 09:31:19.367 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:27:15.342 00:05:02.400 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-13 09:31:19.369 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:31:19.285 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:27:15.340 00:05:02.405 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-13 09:32:08.472 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:38632 10 6452 1 2025-12-13 09:33:08.838 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:46564 10 6452 1 2025-12-13 09:34:09.267 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:45688 10 6452 1 2025-12-13 09:35:09.676 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:47304 10 6452 1 2025-12-13 09:36:19.414 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:36:19.327 00:00:00.027 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:36:19.491 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:36:19.448 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:36:19.331 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:36:10.051 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:40478 10 6452 1 2025-12-13 09:33:15.349 00:05:02.395 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-13 09:33:15.347 00:05:02.401 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-13 09:37:10.490 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:45574 10 6452 1 2025-12-13 09:38:10.893 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:32950 10 6452 1 2025-12-13 09:39:11.318 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:45894 10 6452 1 2025-12-13 09:40:11.718 00:00:10.390 TCP 1.101.0.1:3000 -> 23.104.0.1:44606 10 6452 1 2025-12-13 09:41:19.705 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:41:19.532 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:41:19.536 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:41:19.584 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:41:19.622 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:41:12.141 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:57820 10 6452 1 2025-12-13 09:42:12.537 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:52474 10 6452 1 2025-12-13 09:39:15.350 00:05:02.404 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-13 09:39:15.347 00:05:02.409 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-13 09:43:12.947 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:35748 10 6452 1 2025-12-13 09:44:13.360 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:44452 10 6452 1 2025-12-13 09:45:13.760 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:45408 10 6452 1 2025-12-13 09:46:19.530 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:46:19.678 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:46:19.679 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:46:19.648 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:46:19.447 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:46:14.172 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:46562 10 6452 1 2025-12-13 09:47:14.576 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:33296 10 6452 1 2025-12-13 09:48:14.982 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44918 10 6452 1 2025-12-13 09:45:15.351 00:05:02.405 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-13 09:45:15.349 00:05:02.410 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-13 09:49:15.389 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:43672 10 6452 1 2025-12-13 09:50:15.787 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:46322 10 6452 1 2025-12-13 09:51:19.879 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:51:19.825 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:51:19.455 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:51:19.915 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:51:19.998 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:51:16.190 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58460 10 6452 1 2025-12-13 09:52:16.595 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:34250 10 6452 1 2025-12-13 09:53:17.001 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:41546 10 6452 1 2025-12-13 09:54:17.401 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52316 10 6452 1 2025-12-13 09:51:15.352 00:05:02.404 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-13 09:51:15.350 00:05:02.409 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-13 09:55:17.804 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:53004 10 6452 1 2025-12-13 09:56:19.771 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:56:19.920 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-13 09:56:19.826 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-13 09:56:19.882 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-13 09:56:20.005 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-13 09:56:18.211 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:40098 10 6452 1 2025-12-13 09:57:18.616 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:39186 10 6452 1 2025-12-13 09:58:19.022 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:44110 10 6452 1 Summary: total flows: 140, total bytes: 417156, total packets: 1023, avg bps: 908, avg pps: 0, avg bpp: 407 Time window: 2025-12-13 08:57:15 - 2025-12-13 09:58:29 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0034s User: 0.0017s Wall: 0.0029s flows/second: 48986.6 Runtime: 0.0029s