Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-05 08:54:52.832 00:05:03.202 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-05 08:58:53.110 00:00:10.364 TCP 23.104.0.1:42304 -> 1.101.0.1:3000 11 1507 1 2025-11-05 08:59:23.312 00:00:10.137 TCP 1.101.0.1:3000 -> 22.102.0.1:48560 10 6452 1 2025-11-05 08:55:52.835 00:05:03.197 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-05 08:59:53.515 00:00:10.367 TCP 23.104.0.1:41868 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:00:23.488 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:49890 10 6452 1 2025-11-05 09:00:53.926 00:00:17.439 TCP 23.104.0.1:44288 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:01:23.706 00:00:10.198 TCP 1.101.0.1:3000 -> 22.102.0.1:55140 10 6452 1 2025-11-05 09:02:01.403 00:00:10.363 TCP 23.104.0.1:38156 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:02:23.944 00:00:10.191 TCP 1.101.0.1:3000 -> 22.102.0.1:50992 10 6452 1 2025-11-05 09:02:59.638 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:02:59.488 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:03:01.801 00:00:10.363 TCP 23.104.0.1:34402 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:03:24.175 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:43196 10 6452 1 2025-11-05 09:04:02.210 00:00:10.364 TCP 23.104.0.1:42702 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:04:24.393 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:51514 10 6452 1 2025-11-05 09:00:52.833 00:05:03.202 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-05 09:05:02.613 00:00:10.324 TCP 23.104.0.1:43580 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:05:24.611 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:52724 10 6452 1 2025-11-05 09:01:52.836 00:05:03.197 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-05 09:06:02.980 00:00:10.331 TCP 23.104.0.1:33088 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:06:24.829 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:56478 10 6452 1 2025-11-05 09:07:03.354 00:00:10.326 TCP 23.104.0.1:51578 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:07:25.072 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:59984 10 6452 1 2025-11-05 09:07:59.597 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:07:59.663 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:08:03.720 00:00:10.371 TCP 23.104.0.1:44344 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:08:25.241 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:48070 10 6452 1 2025-11-05 09:09:04.133 00:00:10.362 TCP 23.104.0.1:35808 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:09:25.456 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:36018 10 6452 1 2025-11-05 09:10:04.539 00:00:10.366 TCP 23.104.0.1:57940 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:10:25.672 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:46186 10 6452 1 2025-11-05 09:06:52.835 00:05:03.202 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-05 09:11:04.944 00:00:10.376 TCP 23.104.0.1:58398 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:11:25.883 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:56330 10 6452 1 2025-11-05 09:07:52.839 00:05:03.196 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-05 09:12:05.362 00:00:10.367 TCP 23.104.0.1:55904 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:12:26.109 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:39464 10 6452 1 2025-11-05 09:12:59.877 00:00:00.025 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:12:59.828 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:13:05.766 00:00:10.669 TCP 23.104.0.1:53846 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:13:26.323 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:52982 10 6452 1 2025-11-05 09:14:06.480 00:00:10.374 TCP 23.104.0.1:53412 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:14:26.551 00:00:10.186 TCP 1.101.0.1:3000 -> 22.102.0.1:36732 10 6452 1 2025-11-05 09:15:06.891 00:00:10.375 TCP 23.104.0.1:33356 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:15:26.774 00:00:10.146 TCP 1.101.0.1:3000 -> 22.102.0.1:46296 10 6452 1 2025-11-05 09:16:07.303 00:00:10.364 TCP 23.104.0.1:56552 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:16:26.957 00:00:10.153 TCP 1.101.0.1:3000 -> 22.102.0.1:52688 10 6452 1 2025-11-05 09:12:52.836 00:05:03.201 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-05 09:17:07.709 00:00:10.368 TCP 23.104.0.1:42894 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:17:27.147 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:49106 10 6452 1 2025-11-05 09:13:52.839 00:05:03.195 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-05 09:17:59.858 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:17:59.807 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:18:08.117 00:00:10.365 TCP 23.104.0.1:35214 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:18:27.365 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:34794 10 6452 1 2025-11-05 09:19:08.519 00:00:10.366 TCP 23.104.0.1:44368 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:19:27.580 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:49468 10 6452 1 2025-11-05 09:20:08.923 00:00:10.371 TCP 23.104.0.1:33924 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:20:27.794 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:41296 10 6452 1 2025-11-05 09:21:09.332 00:00:10.362 TCP 23.104.0.1:45492 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:21:28.009 00:00:10.466 TCP 1.101.0.1:3000 -> 22.102.0.1:39358 10 6452 1 2025-11-05 09:22:09.735 00:00:10.367 TCP 23.104.0.1:47682 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:22:28.515 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:56612 10 6452 1 2025-11-05 09:23:00.093 00:00:00.045 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:18:52.837 00:05:03.201 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-05 09:23:00.079 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:23:10.131 00:00:10.381 TCP 23.104.0.1:33178 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:23:28.738 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:41596 10 6452 1 2025-11-05 09:19:52.840 00:05:03.196 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-05 09:24:10.549 00:00:10.374 TCP 23.104.0.1:47104 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:24:28.963 00:00:10.840 TCP 1.101.0.1:3000 -> 22.102.0.1:34192 12 6556 1 2025-11-05 09:25:10.962 00:00:10.368 TCP 23.104.0.1:49566 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:25:29.841 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:46044 10 6452 1 2025-11-05 09:26:11.367 00:00:12.259 TCP 23.104.0.1:59510 -> 1.101.0.1:3000 13 1611 1 2025-11-05 09:26:30.085 00:00:10.184 TCP 1.101.0.1:3000 -> 22.102.0.1:37104 10 6452 1 2025-11-05 09:27:13.666 00:00:10.323 TCP 23.104.0.1:42408 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:27:30.304 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:39176 10 6452 1 2025-11-05 09:28:00.246 00:00:00.024 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:28:00.132 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:28:14.030 00:00:10.365 TCP 23.104.0.1:36924 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:28:30.516 00:00:10.139 TCP 1.101.0.1:3000 -> 22.102.0.1:41724 10 6452 1 2025-11-05 09:24:52.839 00:05:03.204 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-05 09:29:14.431 00:00:10.363 TCP 23.104.0.1:46154 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:29:30.692 00:00:10.193 TCP 1.101.0.1:3000 -> 22.102.0.1:49248 10 6452 1 2025-11-05 09:25:52.840 00:05:03.199 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-05 09:30:14.832 00:00:10.385 TCP 23.104.0.1:36778 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:30:30.937 00:00:10.193 TCP 1.101.0.1:3000 -> 22.102.0.1:60366 10 6452 1 2025-11-05 09:31:15.259 00:00:10.370 TCP 23.104.0.1:37364 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:31:31.172 00:00:10.168 TCP 1.101.0.1:3000 -> 22.102.0.1:42440 10 6452 1 2025-11-05 09:32:15.670 00:00:10.329 TCP 23.104.0.1:56514 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:32:31.379 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:49920 10 6452 1 2025-11-05 09:33:00.265 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:33:00.271 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:33:16.031 00:00:20.071 TCP 23.104.0.1:51522 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:33:31.591 00:00:10.141 TCP 1.101.0.1:3000 -> 22.102.0.1:38166 10 6452 1 2025-11-05 09:34:26.171 00:00:10.320 TCP 23.104.0.1:34718 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:34:31.767 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:47024 10 6452 1 2025-11-05 09:30:52.840 00:05:03.204 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-05 09:35:26.531 00:00:10.371 TCP 23.104.0.1:49870 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:35:31.996 00:00:10.252 TCP 1.101.0.1:3000 -> 22.102.0.1:45780 13 6608 1 2025-11-05 09:31:52.844 00:05:03.199 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-05 09:36:26.937 00:00:10.373 TCP 23.104.0.1:38376 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:36:32.318 00:00:10.136 TCP 1.101.0.1:3000 -> 22.102.0.1:36842 10 6452 1 2025-11-05 09:37:27.348 00:00:10.363 TCP 23.104.0.1:49190 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:37:32.492 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:50152 10 6452 1 2025-11-05 09:38:00.459 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:38:00.374 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:38:27.750 00:00:10.374 TCP 23.104.0.1:53644 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:38:32.715 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:45512 10 6452 1 2025-11-05 09:39:28.158 00:00:10.321 TCP 23.104.0.1:49228 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:39:32.905 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:45168 10 6452 1 2025-11-05 09:40:28.521 00:00:10.368 TCP 23.104.0.1:51260 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:40:33.118 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:46950 10 6452 1 2025-11-05 09:36:52.842 00:05:03.205 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-05 09:41:28.927 00:00:10.754 TCP 23.104.0.1:38044 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:41:33.331 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:44524 10 6452 1 2025-11-05 09:37:52.844 00:05:03.200 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-05 09:42:29.719 00:00:10.377 TCP 23.104.0.1:32934 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:42:33.547 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:47722 10 6452 1 2025-11-05 09:43:00.174 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:43:00.520 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:43:30.134 00:00:10.357 TCP 23.104.0.1:34468 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:43:33.757 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:42574 10 6452 1 2025-11-05 09:44:30.534 00:00:10.385 TCP 23.104.0.1:44670 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:44:33.984 00:00:10.202 TCP 1.101.0.1:3000 -> 22.102.0.1:57270 10 6452 1 2025-11-05 09:45:30.971 00:00:10.373 TCP 23.104.0.1:37216 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:45:34.220 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:50750 10 6452 1 2025-11-05 09:46:31.384 00:00:11.423 TCP 23.104.0.1:53820 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:46:34.441 00:00:10.196 TCP 1.101.0.1:3000 -> 22.102.0.1:40208 10 6452 1 2025-11-05 09:42:52.842 00:05:03.206 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-05 09:47:32.841 00:00:10.395 TCP 23.104.0.1:35588 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:47:34.688 00:00:10.189 TCP 1.101.0.1:3000 -> 22.102.0.1:47798 10 6452 1 2025-11-05 09:43:52.846 00:05:03.200 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-05 09:48:00.620 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:48:00.547 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:48:33.271 00:00:10.329 TCP 23.104.0.1:43492 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:48:34.913 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:38366 10 6452 1 2025-11-05 09:49:33.636 00:00:10.369 TCP 23.104.0.1:52408 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:49:35.128 00:00:10.140 TCP 1.101.0.1:3000 -> 22.102.0.1:48668 10 6452 1 2025-11-05 09:50:34.048 00:00:18.182 TCP 23.104.0.1:51202 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:50:35.299 00:00:16.895 TCP 1.101.0.1:3000 -> 22.102.0.1:53748 10 6452 1 2025-11-05 09:51:42.243 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:38880 10 6452 1 2025-11-05 09:51:42.330 00:00:10.362 TCP 23.104.0.1:47032 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:52:42.455 00:00:10.135 TCP 1.101.0.1:3000 -> 22.102.0.1:54536 10 6452 1 2025-11-05 09:48:52.844 00:05:03.206 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-05 09:52:42.731 00:00:10.366 TCP 23.104.0.1:44012 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:53:00.653 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-05 09:53:00.732 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:49:52.847 00:05:03.201 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-05 09:53:43.137 00:00:10.365 TCP 23.104.0.1:52636 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:53:42.630 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:56052 10 6452 1 2025-11-05 09:54:43.541 00:00:10.368 TCP 23.104.0.1:37024 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:54:42.840 00:00:10.192 TCP 1.101.0.1:3000 -> 22.102.0.1:59368 10 6452 1 2025-11-05 09:55:43.080 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:49324 10 6452 1 2025-11-05 09:55:43.945 00:00:10.375 TCP 23.104.0.1:58932 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:56:44.357 00:00:10.441 TCP 23.104.0.1:35566 -> 1.101.0.1:3000 15 1926 1 2025-11-05 09:56:43.294 00:00:10.165 TCP 1.101.0.1:3000 -> 22.102.0.1:57008 12 10375 1 2025-11-05 09:57:44.841 00:00:10.386 TCP 23.104.0.1:38740 -> 1.101.0.1:3000 11 1507 1 2025-11-05 09:57:43.498 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:37428 10 6452 1 2025-11-05 09:58:00.837 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-05 09:58:00.794 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 Summary: total flows: 162, total bytes: 495095, total packets: 1564, avg bps: 1045, avg pps: 0, avg bpp: 316 Time window: 2025-11-05 08:54:52 - 2025-11-05 09:58:00 Total flows processed: 162, passed: 162, Blocks skipped: 0, Bytes read: 16912 Sys: 0.0036s User: 0.0018s Wall: 0.0023s flows/second: 69977.1 Runtime: 0.0023s