Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-15 13:58:48.220 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:42462 10 6452 1 2025-11-15 13:59:16.350 00:00:10.361 TCP 23.104.0.1:55668 -> 1.101.0.1:3000 11 1507 1 2025-11-15 13:59:48.442 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:43420 10 6452 1 2025-11-15 14:00:16.757 00:00:10.381 TCP 23.104.0.1:59816 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:00:48.654 00:00:11.243 TCP 1.101.0.1:3000 -> 22.102.0.1:58046 10 6452 1 2025-11-15 14:01:17.176 00:00:10.374 TCP 23.104.0.1:60084 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:01:49.928 00:00:10.152 TCP 1.101.0.1:3000 -> 22.102.0.1:59488 10 6452 1 2025-11-15 14:02:17.586 00:00:10.366 TCP 23.104.0.1:45372 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:02:54.413 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:02:54.337 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:02:50.116 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:60434 10 6452 1 2025-11-15 14:03:17.992 00:00:10.371 TCP 23.104.0.1:36096 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:03:50.327 00:00:10.719 TCP 1.101.0.1:3000 -> 22.102.0.1:39852 11 6504 1 2025-11-15 13:59:57.507 00:05:04.648 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-15 13:59:57.506 00:05:04.652 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-15 14:04:18.405 00:00:10.365 TCP 23.104.0.1:42336 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:04:51.088 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:56728 10 6452 1 2025-11-15 14:05:18.810 00:00:10.367 TCP 23.104.0.1:59364 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:05:51.301 00:00:10.136 TCP 1.101.0.1:3000 -> 22.102.0.1:44758 10 6452 1 2025-11-15 14:06:19.217 00:00:10.443 TCP 23.104.0.1:40542 -> 1.101.0.1:3000 15 1926 1 2025-11-15 14:06:51.475 00:00:10.201 TCP 1.101.0.1:3000 -> 22.102.0.1:46400 12 10375 1 2025-11-15 14:07:19.703 00:00:10.329 TCP 23.104.0.1:50050 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:07:54.602 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:07:54.666 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:07:51.712 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:41260 10 6452 1 2025-11-15 14:08:20.110 00:00:10.364 TCP 23.104.0.1:37558 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:08:51.934 00:00:10.191 TCP 1.101.0.1:3000 -> 22.102.0.1:48228 10 6452 1 2025-11-15 14:09:20.515 00:00:10.328 TCP 23.104.0.1:37310 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:05:57.510 00:05:04.647 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-15 14:09:52.177 00:00:10.137 TCP 1.101.0.1:3000 -> 22.102.0.1:60304 10 6452 1 2025-11-15 14:05:57.508 00:05:04.652 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-15 14:10:20.878 00:00:10.345 TCP 23.104.0.1:51352 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:10:52.347 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:39934 10 6452 1 2025-11-15 14:11:21.263 00:00:10.368 TCP 23.104.0.1:37406 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:11:52.558 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:57992 10 6452 1 2025-11-15 14:12:21.670 00:00:10.329 TCP 23.104.0.1:53092 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:12:54.719 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:12:54.569 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:12:52.772 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:56706 10 6452 1 2025-11-15 14:13:22.036 00:00:10.363 TCP 23.104.0.1:48746 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:13:52.982 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:53782 10 6452 1 2025-11-15 14:14:22.438 00:00:10.364 TCP 23.104.0.1:55576 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:14:53.207 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:60646 10 6452 1 2025-11-15 14:15:22.836 00:00:10.389 TCP 23.104.0.1:51706 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:11:57.512 00:05:04.646 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-15 14:11:57.511 00:05:04.651 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-15 14:15:53.437 00:00:10.189 TCP 1.101.0.1:3000 -> 22.102.0.1:49176 10 6452 1 2025-11-15 14:16:23.264 00:00:10.344 TCP 23.104.0.1:56592 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:16:53.659 00:00:10.145 TCP 1.101.0.1:3000 -> 22.102.0.1:44308 10 6452 1 2025-11-15 14:17:23.650 00:00:10.368 TCP 23.104.0.1:38048 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:17:54.496 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:17:54.645 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:17:53.846 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:42610 10 6452 1 2025-11-15 14:18:24.063 00:00:10.368 TCP 23.104.0.1:35624 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:18:54.077 00:00:10.149 TCP 1.101.0.1:3000 -> 22.102.0.1:54660 10 6452 1 2025-11-15 14:19:24.467 00:00:10.370 TCP 23.104.0.1:57836 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:19:54.273 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:57564 10 6452 1 2025-11-15 14:20:24.889 00:00:10.345 TCP 23.104.0.1:51888 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:20:54.490 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:37346 10 6452 1 2025-11-15 14:21:25.270 00:00:10.368 TCP 23.104.0.1:52348 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:17:57.515 00:05:04.651 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-15 14:21:54.701 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:34450 10 6452 1 2025-11-15 14:17:57.512 00:05:04.657 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-15 14:22:25.674 00:00:10.322 TCP 23.104.0.1:55622 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:22:54.889 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:22:54.808 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:22:54.916 00:00:10.169 TCP 1.101.0.1:3000 -> 22.102.0.1:47776 10 6452 1 2025-11-15 14:23:26.029 00:00:10.363 TCP 23.104.0.1:59248 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:23:55.124 00:00:10.227 TCP 1.101.0.1:3000 -> 22.102.0.1:54448 10 6452 1 2025-11-15 14:24:26.430 00:00:10.363 TCP 23.104.0.1:38718 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:24:55.397 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:48312 10 6452 1 2025-11-15 14:25:26.833 00:00:10.385 TCP 23.104.0.1:47634 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:25:55.627 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:49808 10 6452 1 2025-11-15 14:26:27.251 00:00:10.367 TCP 23.104.0.1:51658 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:26:55.839 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:34552 10 6452 1 2025-11-15 14:27:27.654 00:00:10.329 TCP 23.104.0.1:56044 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:27:54.860 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:27:54.769 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:23:57.515 00:05:04.652 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-15 14:27:56.075 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:56060 10 6452 1 2025-11-15 14:23:57.512 00:05:04.657 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-15 14:28:28.025 00:00:10.368 TCP 23.104.0.1:54354 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:28:56.291 00:00:10.137 TCP 1.101.0.1:3000 -> 22.102.0.1:49602 10 6452 1 2025-11-15 14:29:28.431 00:00:10.332 TCP 23.104.0.1:38486 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:29:56.468 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:34970 10 6452 1 2025-11-15 14:30:28.798 00:00:10.377 TCP 23.104.0.1:37892 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:30:56.673 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:39314 10 6452 1 2025-11-15 14:31:29.214 00:00:10.325 TCP 23.104.0.1:33264 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:31:56.888 00:00:10.133 TCP 1.101.0.1:3000 -> 22.102.0.1:42394 10 6452 1 2025-11-15 14:32:29.577 00:00:10.367 TCP 23.104.0.1:58098 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:32:55.010 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:32:55.119 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:32:57.081 00:00:10.169 TCP 1.101.0.1:3000 -> 22.102.0.1:43886 10 6452 1 2025-11-15 14:33:29.980 00:00:10.365 TCP 23.104.0.1:42480 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:29:57.515 00:05:04.653 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-15 14:29:57.512 00:05:04.659 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-15 14:33:57.287 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:37424 10 6452 1 2025-11-15 14:34:30.381 00:00:10.370 TCP 23.104.0.1:59356 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:34:57.514 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:53760 10 6452 1 2025-11-15 14:35:30.792 00:00:11.016 TCP 23.104.0.1:50466 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:35:57.737 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:51580 10 6452 1 2025-11-15 14:36:31.851 00:00:10.375 TCP 23.104.0.1:35346 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:36:57.910 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:43188 10 6452 1 2025-11-15 14:37:32.270 00:00:10.360 TCP 23.104.0.1:57580 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:37:55.277 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:37:55.216 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:37:58.122 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:42312 10 6452 1 2025-11-15 14:38:32.670 00:00:10.372 TCP 23.104.0.1:46448 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:38:58.343 00:00:10.130 TCP 1.101.0.1:3000 -> 22.102.0.1:51032 10 6452 1 2025-11-15 14:39:33.105 00:00:10.336 TCP 23.104.0.1:38436 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:35:57.515 00:05:04.657 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-15 14:35:57.517 00:05:04.652 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-15 14:39:58.521 00:00:10.741 TCP 1.101.0.1:3000 -> 22.102.0.1:54906 10 6452 1 2025-11-15 14:40:33.483 00:00:10.362 TCP 23.104.0.1:50642 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:40:59.300 00:00:10.186 TCP 1.101.0.1:3000 -> 22.102.0.1:56420 10 6452 1 2025-11-15 14:41:33.888 00:00:10.343 TCP 23.104.0.1:58960 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:41:59.528 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:45252 10 6452 1 2025-11-15 14:42:34.267 00:00:10.370 TCP 23.104.0.1:38368 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:42:55.214 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:42:55.065 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:42:59.756 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:53452 10 6452 1 2025-11-15 14:43:34.683 00:00:10.362 TCP 23.104.0.1:53062 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:43:59.977 00:00:10.192 TCP 1.101.0.1:3000 -> 22.102.0.1:57680 10 6452 1 2025-11-15 14:44:35.108 00:00:10.329 TCP 23.104.0.1:47462 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:45:00.214 00:00:10.162 TCP 1.101.0.1:3000 -> 22.102.0.1:46926 10 6452 1 2025-11-15 14:45:35.469 00:00:10.376 TCP 23.104.0.1:58378 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:41:57.518 00:05:04.659 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-15 14:41:57.516 00:05:04.665 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-15 14:46:00.415 00:00:10.136 TCP 1.101.0.1:3000 -> 22.102.0.1:56582 10 6452 1 2025-11-15 14:46:35.877 00:00:10.321 TCP 23.104.0.1:36594 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:47:00.592 00:00:10.186 TCP 1.101.0.1:3000 -> 22.102.0.1:57960 10 6452 1 2025-11-15 14:47:36.235 00:00:10.365 TCP 23.104.0.1:56168 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:47:55.227 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:47:55.354 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:48:00.818 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:54760 10 6452 1 2025-11-15 14:48:36.635 00:00:10.362 TCP 23.104.0.1:42330 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:49:01.052 00:00:10.167 TCP 1.101.0.1:3000 -> 22.102.0.1:48174 10 6452 1 2025-11-15 14:49:37.036 00:00:10.360 TCP 23.104.0.1:48214 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:50:01.262 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:55410 10 6452 1 2025-11-15 14:50:37.437 00:00:10.329 TCP 23.104.0.1:54406 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:51:01.474 00:00:10.141 TCP 1.101.0.1:3000 -> 22.102.0.1:37198 10 6452 1 2025-11-15 14:51:37.804 00:00:10.327 TCP 23.104.0.1:60322 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:47:57.522 00:05:04.660 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-15 14:47:57.518 00:05:04.666 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-15 14:52:01.649 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:55116 10 6452 1 2025-11-15 14:52:38.168 00:00:13.446 TCP 23.104.0.1:58148 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:52:55.519 00:00:00.025 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:52:55.464 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:53:01.864 00:00:10.184 TCP 1.101.0.1:3000 -> 22.102.0.1:47576 10 6452 1 2025-11-15 14:53:41.661 00:00:10.324 TCP 23.104.0.1:60606 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:54:02.090 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:42902 10 6452 1 2025-11-15 14:54:42.026 00:00:10.363 TCP 23.104.0.1:32956 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:55:02.303 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:39508 10 6452 1 2025-11-15 14:55:42.429 00:00:10.367 TCP 23.104.0.1:51596 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:56:02.523 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:50128 10 6452 1 2025-11-15 14:56:42.835 00:00:10.388 TCP 23.104.0.1:37588 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:57:02.739 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:53594 10 6452 1 2025-11-15 14:57:55.559 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-15 14:57:55.292 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-15 14:57:43.270 00:00:10.368 TCP 23.104.0.1:39238 -> 1.101.0.1:3000 11 1507 1 2025-11-15 14:53:57.522 00:05:04.660 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-15 14:53:57.520 00:05:04.666 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-15 14:58:02.962 00:00:10.200 TCP 1.101.0.1:3000 -> 22.102.0.1:57022 10 6452 1 Summary: total flows: 163, total bytes: 501235, total packets: 1568, avg bps: 1109, avg pps: 0, avg bpp: 319 Time window: 2025-11-15 13:58:48 - 2025-11-15 14:59:02 Total flows processed: 163, passed: 163, Blocks skipped: 0, Bytes read: 17016 Sys: 0.0054s User: 0.0011s Wall: 0.0030s flows/second: 54152.2 Runtime: 0.0030s