Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-08 01:53:57.376 00:05:56.829 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-08 01:59:06.647 00:00:10.133 TCP 1.101.0.1:3000 -> 22.102.0.1:53438 10 6452 1 2025-11-08 01:59:17.766 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 01:59:17.713 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 01:59:35.761 00:00:10.381 TCP 23.104.0.1:43002 -> 1.101.0.1:3000 11 1507 1 2025-11-08 01:54:57.373 00:05:56.834 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-08 02:00:06.815 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:40540 10 6452 1 2025-11-08 02:00:36.177 00:00:10.374 TCP 23.104.0.1:57168 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:01:07.039 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:41598 10 6452 1 2025-11-08 02:01:36.586 00:00:10.368 TCP 23.104.0.1:42802 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:02:07.251 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:60766 10 6452 1 2025-11-08 02:02:36.985 00:00:10.382 TCP 23.104.0.1:47702 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:03:07.475 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:47378 10 6452 1 2025-11-08 02:03:37.411 00:00:10.335 TCP 23.104.0.1:39238 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:04:17.785 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:04:17.843 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:04:07.690 00:00:10.186 TCP 1.101.0.1:3000 -> 22.102.0.1:38354 10 6452 1 2025-11-08 02:04:37.784 00:00:10.367 TCP 23.104.0.1:49710 -> 1.101.0.1:3000 11 1507 1 2025-11-08 01:59:57.377 00:05:56.832 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-08 02:05:07.917 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:55748 10 6452 1 2025-11-08 02:05:38.187 00:00:10.331 TCP 23.104.0.1:42106 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:00:57.375 00:05:56.836 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-08 02:06:08.143 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:38934 10 6452 1 2025-11-08 02:06:38.553 00:00:10.364 TCP 23.104.0.1:37350 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:07:08.310 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:51498 10 6452 1 2025-11-08 02:07:38.953 00:00:10.726 TCP 23.104.0.1:56994 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:08:08.523 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:50600 10 6452 1 2025-11-08 02:08:39.719 00:00:10.374 TCP 23.104.0.1:34394 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:09:18.074 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:09:08.739 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:48966 10 6452 1 2025-11-08 02:09:17.595 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:09:40.131 00:00:10.327 TCP 23.104.0.1:33292 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:10:08.952 00:00:10.198 TCP 1.101.0.1:3000 -> 22.102.0.1:51646 12 6556 1 2025-11-08 02:10:40.494 00:00:10.329 TCP 23.104.0.1:49042 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:05:57.382 00:05:56.827 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-08 02:11:09.190 00:00:10.141 TCP 1.101.0.1:3000 -> 22.102.0.1:50670 10 6452 1 2025-11-08 02:11:40.855 00:00:10.493 TCP 23.104.0.1:59652 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:06:57.381 00:05:56.832 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-08 02:12:09.373 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:60850 10 6452 1 2025-11-08 02:12:41.385 00:00:10.322 TCP 23.104.0.1:36216 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:13:09.587 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:46964 10 6452 1 2025-11-08 02:13:41.751 00:00:10.366 TCP 23.104.0.1:35470 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:14:17.959 00:00:00.024 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:14:17.895 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:14:09.808 00:00:10.136 TCP 1.101.0.1:3000 -> 22.102.0.1:39198 10 6452 1 2025-11-08 02:14:42.161 00:00:10.363 TCP 23.104.0.1:52254 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:15:09.986 00:00:10.192 TCP 1.101.0.1:3000 -> 22.102.0.1:49548 10 6452 1 2025-11-08 02:15:42.561 00:00:10.358 TCP 23.104.0.1:38602 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:16:10.214 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:56460 12 6556 1 2025-11-08 02:11:57.384 00:05:56.830 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-08 02:16:42.966 00:00:10.327 TCP 23.104.0.1:46990 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:17:10.425 00:00:10.159 TCP 1.101.0.1:3000 -> 22.102.0.1:47920 12 10375 1 2025-11-08 02:17:43.331 00:00:10.439 TCP 23.104.0.1:48692 -> 1.101.0.1:3000 15 1926 1 2025-11-08 02:12:57.381 00:05:56.834 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-08 02:18:10.625 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:59502 10 6452 1 2025-11-08 02:18:43.814 00:00:10.365 TCP 23.104.0.1:47332 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:19:10.834 00:00:10.512 TCP 1.101.0.1:3000 -> 22.102.0.1:50520 10 6452 1 2025-11-08 02:19:17.806 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:19:18.046 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:19:44.216 00:00:10.364 TCP 23.104.0.1:40412 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:20:11.384 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:57172 10 6452 1 2025-11-08 02:20:44.618 00:00:10.321 TCP 23.104.0.1:33828 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:21:11.611 00:00:10.186 TCP 1.101.0.1:3000 -> 22.102.0.1:56936 10 6452 1 2025-11-08 02:21:44.980 00:00:10.329 TCP 23.104.0.1:36888 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:22:11.856 00:00:10.131 TCP 1.101.0.1:3000 -> 22.102.0.1:56806 10 6452 1 2025-11-08 02:17:57.384 00:05:56.830 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-08 02:22:45.348 00:00:10.367 TCP 23.104.0.1:40332 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:23:12.034 00:00:10.166 TCP 1.101.0.1:3000 -> 22.102.0.1:54986 10 6452 1 2025-11-08 02:23:45.753 00:00:10.390 TCP 23.104.0.1:39640 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:18:57.382 00:05:56.834 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-08 02:24:18.267 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:24:18.332 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:24:12.237 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:33442 10 6452 1 2025-11-08 02:24:46.179 00:00:10.366 TCP 23.104.0.1:49672 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:25:12.408 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:42548 10 6452 1 2025-11-08 02:25:46.585 00:00:10.365 TCP 23.104.0.1:43560 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:26:12.626 00:00:10.143 TCP 1.101.0.1:3000 -> 22.102.0.1:58328 10 6452 1 2025-11-08 02:26:46.990 00:00:10.372 TCP 23.104.0.1:43450 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:27:12.808 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:48290 10 6452 1 2025-11-08 02:27:47.398 00:00:10.365 TCP 23.104.0.1:46814 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:28:13.020 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:47246 10 6452 1 2025-11-08 02:23:57.386 00:05:56.830 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-08 02:28:47.797 00:00:10.366 TCP 23.104.0.1:51544 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:29:18.574 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:29:18.630 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:29:13.231 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:56116 10 6452 1 2025-11-08 02:24:57.382 00:05:56.835 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-08 02:29:48.203 00:00:10.844 TCP 23.104.0.1:49140 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:30:13.444 00:00:10.135 TCP 1.101.0.1:3000 -> 22.102.0.1:49464 10 6452 1 2025-11-08 02:30:49.103 00:00:10.362 TCP 23.104.0.1:52398 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:31:13.616 00:00:10.137 TCP 1.101.0.1:3000 -> 22.102.0.1:48630 10 6452 1 2025-11-08 02:31:49.505 00:00:10.366 TCP 23.104.0.1:35418 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:32:13.790 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:54446 10 6452 1 2025-11-08 02:32:49.907 00:00:10.914 TCP 23.104.0.1:48264 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:33:14.001 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:53312 10 6452 1 2025-11-08 02:33:50.858 00:00:10.370 TCP 23.104.0.1:42422 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:34:18.138 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:34:18.339 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:34:14.219 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:53298 10 6452 1 2025-11-08 02:29:57.388 00:05:56.832 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-08 02:34:51.267 00:00:10.366 TCP 23.104.0.1:46128 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:35:14.441 00:00:10.135 TCP 1.101.0.1:3000 -> 22.102.0.1:52810 10 6452 1 2025-11-08 02:30:57.384 00:05:56.838 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-08 02:35:51.673 00:00:10.369 TCP 23.104.0.1:60934 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:36:14.615 00:00:10.169 TCP 1.101.0.1:3000 -> 22.102.0.1:39390 10 6452 1 2025-11-08 02:36:52.096 00:00:10.366 TCP 23.104.0.1:34142 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:37:14.823 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:50634 10 6452 1 2025-11-08 02:37:52.496 00:00:10.368 TCP 23.104.0.1:39198 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:38:15.066 00:00:10.167 TCP 1.101.0.1:3000 -> 22.102.0.1:53840 10 6452 1 2025-11-08 02:38:52.900 00:00:10.331 TCP 23.104.0.1:40460 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:39:18.557 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:39:18.643 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:39:15.272 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:45670 10 6452 1 2025-11-08 02:39:53.270 00:00:10.364 TCP 23.104.0.1:44256 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:40:15.481 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:50456 10 6452 1 2025-11-08 02:35:57.390 00:05:56.831 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-08 02:40:53.672 00:00:10.363 TCP 23.104.0.1:52256 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:41:15.694 00:00:10.169 TCP 1.101.0.1:3000 -> 22.102.0.1:53844 10 6452 1 2025-11-08 02:36:57.386 00:05:56.836 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-08 02:41:54.096 00:00:10.322 TCP 23.104.0.1:43580 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:42:15.899 00:00:10.137 TCP 1.101.0.1:3000 -> 22.102.0.1:43978 10 6452 1 2025-11-08 02:42:54.456 00:00:10.368 TCP 23.104.0.1:48318 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:43:16.081 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:44620 10 6452 1 2025-11-08 02:43:54.858 00:00:10.373 TCP 23.104.0.1:58558 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:44:18.751 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:44:18.403 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:44:16.286 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:34534 10 6452 1 2025-11-08 02:44:55.269 00:00:10.324 TCP 23.104.0.1:37262 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:45:16.507 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:46518 10 6452 1 2025-11-08 02:45:55.632 00:00:10.364 TCP 23.104.0.1:34994 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:46:16.719 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:36122 10 6452 1 2025-11-08 02:41:57.390 00:05:56.831 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-08 02:46:56.035 00:00:10.325 TCP 23.104.0.1:34312 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:47:16.936 00:00:10.227 TCP 1.101.0.1:3000 -> 22.102.0.1:55790 12 10375 1 2025-11-08 02:42:57.387 00:05:56.837 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-08 02:47:56.397 00:00:10.440 TCP 23.104.0.1:58338 -> 1.101.0.1:3000 15 1926 1 2025-11-08 02:48:17.200 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:33940 10 6452 1 2025-11-08 02:48:56.876 00:00:10.369 TCP 23.104.0.1:33296 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:49:18.948 00:00:00.024 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:49:19.026 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:49:17.417 00:00:10.144 TCP 1.101.0.1:3000 -> 22.102.0.1:37042 10 6452 1 2025-11-08 02:49:57.288 00:00:10.365 TCP 23.104.0.1:36398 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:50:17.609 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:57740 10 6452 1 2025-11-08 02:50:57.688 00:00:10.364 TCP 23.104.0.1:47814 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:51:17.822 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:48512 10 6452 1 2025-11-08 02:51:58.105 00:00:10.326 TCP 23.104.0.1:48430 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:52:18.062 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:55176 10 6452 1 2025-11-08 02:47:57.392 00:05:56.830 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-08 02:52:58.472 00:00:10.366 TCP 23.104.0.1:38678 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:53:18.272 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:53896 10 6452 1 2025-11-08 02:48:57.391 00:05:56.834 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-08 02:53:58.877 00:00:10.623 TCP 23.104.0.1:43106 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:54:18.936 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-08 02:54:18.800 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-08 02:54:18.484 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:52256 10 6452 1 2025-11-08 02:54:59.547 00:00:10.365 TCP 23.104.0.1:38388 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:55:18.700 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:53494 10 6452 1 2025-11-08 02:55:59.949 00:00:10.370 TCP 23.104.0.1:52448 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:56:18.911 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:54286 10 6452 1 2025-11-08 02:57:00.359 00:00:10.961 TCP 23.104.0.1:40096 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:57:19.125 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:48262 10 6452 1 2025-11-08 02:58:01.360 00:00:10.367 TCP 23.104.0.1:44578 -> 1.101.0.1:3000 11 1507 1 2025-11-08 02:58:19.335 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:47024 10 6452 1 Summary: total flows: 163, total bytes: 505733, total packets: 1577, avg bps: 1044, avg pps: 0, avg bpp: 320 Time window: 2025-11-08 01:53:57 - 2025-11-08 02:58:29 Total flows processed: 163, passed: 163, Blocks skipped: 0, Bytes read: 17016 Sys: 0.0041s User: 0.0020s Wall: 0.0027s flows/second: 60663.0 Runtime: 0.0027s