Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-20 03:59:11.116 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:49206 10 6452 1 2025-10-20 03:59:38.869 00:00:10.369 TCP 23.104.0.1:60220 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:00:11.507 00:00:00.094 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:00:11.692 00:00:00.017 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:00:11.337 00:00:10.230 TCP 1.101.0.1:3000 -> 22.102.0.1:33344 10 6452 1 2025-10-20 04:00:39.277 00:00:10.362 TCP 23.104.0.1:33676 -> 1.101.0.1:3000 11 1507 1 2025-10-20 03:56:44.884 00:05:02.647 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-20 03:56:44.882 00:05:02.651 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-20 04:01:11.610 00:00:10.138 TCP 1.101.0.1:3000 -> 22.102.0.1:57108 10 6452 1 2025-10-20 04:01:39.679 00:00:10.382 TCP 23.104.0.1:37028 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:02:11.788 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:49104 10 6452 1 2025-10-20 04:02:40.107 00:00:10.366 TCP 23.104.0.1:38864 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:03:12.006 00:00:10.186 TCP 1.101.0.1:3000 -> 22.102.0.1:51874 10 6452 1 2025-10-20 04:03:40.513 00:00:10.369 TCP 23.104.0.1:41742 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:04:12.233 00:00:10.609 TCP 1.101.0.1:3000 -> 22.102.0.1:58062 10 6452 1 2025-10-20 04:04:40.921 00:00:10.378 TCP 23.104.0.1:37548 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:05:11.359 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:05:11.359 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:05:12.884 00:00:10.147 TCP 1.101.0.1:3000 -> 22.102.0.1:55292 10 6452 1 2025-10-20 04:05:41.337 00:00:10.372 TCP 23.104.0.1:33158 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:06:13.085 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:39126 10 6452 1 2025-10-20 04:02:44.892 00:05:02.644 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-20 04:02:44.889 00:05:02.650 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-20 04:06:41.744 00:00:10.364 TCP 23.104.0.1:50100 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:07:13.297 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:57980 10 6452 1 2025-10-20 04:07:42.145 00:00:10.364 TCP 23.104.0.1:41236 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:08:13.507 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:44310 10 6452 1 2025-10-20 04:08:42.550 00:00:10.370 TCP 23.104.0.1:39478 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:09:13.718 00:00:10.144 TCP 1.101.0.1:3000 -> 22.102.0.1:51428 10 6452 1 2025-10-20 04:09:42.956 00:00:10.370 TCP 23.104.0.1:39234 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:10:11.258 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:10:11.312 00:00:00.028 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:10:13.899 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:39282 10 6452 1 2025-10-20 04:10:43.367 00:00:10.321 TCP 23.104.0.1:34618 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:11:14.120 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:60430 10 6452 1 2025-10-20 04:11:43.720 00:00:10.372 TCP 23.104.0.1:48762 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:12:14.341 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:56084 10 6452 1 2025-10-20 04:08:44.897 00:05:02.640 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-20 04:08:44.895 00:05:02.645 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-20 04:12:44.130 00:00:10.323 TCP 23.104.0.1:48848 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:13:14.558 00:00:10.186 TCP 1.101.0.1:3000 -> 22.102.0.1:46304 10 6452 1 2025-10-20 04:13:44.494 00:00:10.363 TCP 23.104.0.1:40606 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:14:14.787 00:00:15.127 TCP 1.101.0.1:3000 -> 22.102.0.1:60282 10 6452 1 2025-10-20 04:14:44.894 00:00:10.340 TCP 23.104.0.1:48858 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:15:11.409 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:15:11.557 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:15:19.955 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:52940 10 6452 1 2025-10-20 04:15:45.271 00:00:10.322 TCP 23.104.0.1:53586 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:16:20.182 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:57418 10 6452 1 2025-10-20 04:16:45.631 00:00:10.374 TCP 23.104.0.1:59262 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:17:20.397 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:43676 10 6452 1 2025-10-20 04:17:46.062 00:00:10.376 TCP 23.104.0.1:50022 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:18:20.614 00:00:10.610 TCP 1.101.0.1:3000 -> 22.102.0.1:57194 10 6452 1 2025-10-20 04:14:44.901 00:05:02.637 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-20 04:14:44.897 00:05:02.643 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-20 04:18:46.469 00:00:10.363 TCP 23.104.0.1:53832 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:19:21.260 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:37450 10 6452 1 2025-10-20 04:19:46.866 00:00:10.365 TCP 23.104.0.1:55690 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:20:11.904 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:20:11.862 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:20:21.470 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:54060 10 6452 1 2025-10-20 04:20:47.267 00:00:10.326 TCP 23.104.0.1:37910 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:21:21.691 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:45714 10 6452 1 2025-10-20 04:21:47.632 00:00:10.378 TCP 23.104.0.1:40270 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:22:21.920 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:44544 10 6452 1 2025-10-20 04:22:48.058 00:00:10.363 TCP 23.104.0.1:53194 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:23:22.136 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:48646 10 6452 1 2025-10-20 04:23:48.461 00:00:10.362 TCP 23.104.0.1:40902 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:24:22.352 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:39948 10 6452 1 2025-10-20 04:20:44.900 00:05:02.642 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-20 04:20:44.903 00:05:02.636 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-20 04:24:48.861 00:00:10.373 TCP 23.104.0.1:49060 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:25:11.578 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:25:11.726 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:25:22.580 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:43354 10 6452 1 2025-10-20 04:25:49.275 00:00:10.337 TCP 23.104.0.1:40762 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:26:22.812 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:35898 10 6452 1 2025-10-20 04:26:49.659 00:00:10.365 TCP 23.104.0.1:44924 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:27:23.027 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:52844 10 6452 1 2025-10-20 04:27:50.074 00:00:10.373 TCP 23.104.0.1:56394 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:28:23.236 00:00:10.186 TCP 1.101.0.1:3000 -> 22.102.0.1:41420 10 6452 1 2025-10-20 04:28:50.505 00:00:10.365 TCP 23.104.0.1:34200 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:29:23.457 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:59370 10 6452 1 2025-10-20 04:29:50.912 00:00:10.365 TCP 23.104.0.1:50014 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:30:11.520 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:30:11.823 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:30:23.685 00:00:10.194 TCP 1.101.0.1:3000 -> 22.102.0.1:40582 10 6452 1 2025-10-20 04:26:44.902 00:05:02.642 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-20 04:26:44.905 00:05:02.638 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-20 04:30:51.318 00:00:10.367 TCP 23.104.0.1:36590 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:31:23.915 00:00:10.193 TCP 1.101.0.1:3000 -> 22.102.0.1:58070 10 6452 1 2025-10-20 04:31:51.724 00:00:10.375 TCP 23.104.0.1:50038 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:32:24.149 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:58930 10 6452 1 2025-10-20 04:32:52.139 00:00:10.377 TCP 23.104.0.1:52192 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:33:24.366 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:57026 10 6452 1 2025-10-20 04:33:52.561 00:00:10.366 TCP 23.104.0.1:38090 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:34:24.539 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:44090 10 6452 1 2025-10-20 04:34:52.968 00:00:10.367 TCP 23.104.0.1:51434 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:35:11.708 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:35:11.727 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:35:24.767 00:00:10.234 TCP 1.101.0.1:3000 -> 22.102.0.1:49142 10 6452 1 2025-10-20 04:35:53.378 00:00:10.362 TCP 23.104.0.1:56110 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:36:25.056 00:00:10.141 TCP 1.101.0.1:3000 -> 22.102.0.1:41902 10 6452 1 2025-10-20 04:32:44.906 00:05:02.637 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-20 04:32:44.903 00:05:02.642 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-20 04:36:53.777 00:00:10.367 TCP 23.104.0.1:49910 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:37:25.235 00:00:10.138 TCP 1.101.0.1:3000 -> 22.102.0.1:43970 10 6452 1 2025-10-20 04:37:54.187 00:00:10.365 TCP 23.104.0.1:40200 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:38:25.415 00:00:10.233 TCP 1.101.0.1:3000 -> 22.102.0.1:41270 10 6452 1 2025-10-20 04:38:54.590 00:00:10.370 TCP 23.104.0.1:60492 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:39:25.692 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:55512 10 6452 1 2025-10-20 04:39:55.002 00:00:10.373 TCP 23.104.0.1:50708 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:40:11.682 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:40:11.994 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:40:25.908 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:56136 10 6452 1 2025-10-20 04:40:55.402 00:00:10.363 TCP 23.104.0.1:40844 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:41:26.128 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:45844 10 6452 1 2025-10-20 04:41:55.806 00:00:10.346 TCP 23.104.0.1:37002 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:42:26.339 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:54202 10 6452 1 2025-10-20 04:38:44.906 00:05:02.637 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-20 04:38:44.904 00:05:02.642 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-20 04:42:56.181 00:00:10.366 TCP 23.104.0.1:55860 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:43:26.550 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:47980 10 6452 1 2025-10-20 04:43:56.585 00:00:10.368 TCP 23.104.0.1:42826 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:44:26.768 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:43646 10 6452 1 2025-10-20 04:44:56.985 00:00:10.372 TCP 23.104.0.1:33450 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:45:12.115 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:45:12.167 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:45:26.993 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:36870 10 6452 1 2025-10-20 04:45:57.388 00:00:10.378 TCP 23.104.0.1:47490 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:46:27.217 00:00:10.143 TCP 1.101.0.1:3000 -> 22.102.0.1:60634 10 6452 1 2025-10-20 04:46:57.807 00:00:10.363 TCP 23.104.0.1:47894 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:47:27.395 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:41680 10 6452 1 2025-10-20 04:47:58.208 00:00:10.363 TCP 23.104.0.1:37950 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:48:27.619 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:57958 10 6452 1 2025-10-20 04:44:44.905 00:05:02.644 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-20 04:44:44.909 00:05:02.639 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-20 04:48:58.610 00:00:10.364 TCP 23.104.0.1:54916 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:49:27.834 00:00:10.189 TCP 1.101.0.1:3000 -> 22.102.0.1:39810 10 6452 1 2025-10-20 04:49:59.011 00:00:10.428 TCP 23.104.0.1:49208 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:50:12.166 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:50:11.995 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:50:28.077 00:00:10.146 TCP 1.101.0.1:3000 -> 22.102.0.1:54122 10 6452 1 2025-10-20 04:50:59.474 00:00:10.376 TCP 23.104.0.1:39880 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:51:28.258 00:00:10.140 TCP 1.101.0.1:3000 -> 22.102.0.1:50346 10 6452 1 2025-10-20 04:51:59.890 00:00:10.377 TCP 23.104.0.1:57552 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:52:28.439 00:00:10.465 TCP 1.101.0.1:3000 -> 22.102.0.1:36190 10 6452 1 2025-10-20 04:53:00.315 00:00:10.371 TCP 23.104.0.1:45906 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:53:28.939 00:00:10.192 TCP 1.101.0.1:3000 -> 22.102.0.1:46586 10 6452 1 2025-10-20 04:54:00.728 00:00:10.378 TCP 23.104.0.1:42474 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:54:29.168 00:00:10.168 TCP 1.101.0.1:3000 -> 22.102.0.1:47170 10 6452 1 2025-10-20 04:50:44.908 00:05:02.639 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-20 04:50:44.908 00:05:02.644 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-20 04:55:01.143 00:00:10.376 TCP 23.104.0.1:39198 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:55:12.215 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-20 04:55:12.398 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-20 04:55:29.379 00:00:10.136 TCP 1.101.0.1:3000 -> 22.102.0.1:52176 10 6452 1 2025-10-20 04:56:01.555 00:00:10.369 TCP 23.104.0.1:36840 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:56:29.555 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:33680 10 6452 1 2025-10-20 04:57:01.963 00:00:10.335 TCP 23.104.0.1:43420 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:57:29.788 00:00:10.370 TCP 1.101.0.1:3000 -> 22.102.0.1:46816 10 6452 1 2025-10-20 04:58:02.336 00:00:10.366 TCP 23.104.0.1:52180 -> 1.101.0.1:3000 11 1507 1 2025-10-20 04:58:30.223 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:49366 10 6452 1 Summary: total flows: 163, total bytes: 496841, total packets: 1561, avg bps: 1069, avg pps: 0, avg bpp: 318 Time window: 2025-10-20 03:56:44 - 2025-10-20 04:58:40 Total flows processed: 163, passed: 163, Blocks skipped: 0, Bytes read: 17016 Sys: 0.0031s User: 0.0021s Wall: 0.0023s flows/second: 69394.2 Runtime: 0.0024s