Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-25 07:59:04.789 00:00:10.195 TCP 1.101.0.1:3000 -> 22.102.0.1:42220 10 6452 1 2025-11-25 07:59:26.762 00:00:10.375 TCP 23.104.0.1:56296 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:00:05.038 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:41220 10 6452 1 2025-11-25 08:00:27.169 00:00:10.327 TCP 23.104.0.1:54320 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:01:05.256 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:44846 10 6452 1 2025-11-25 08:01:27.541 00:00:10.363 TCP 23.104.0.1:46172 -> 1.101.0.1:3000 11 1507 1 2025-11-25 07:57:07.805 00:05:55.697 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 07:57:07.809 00:05:55.692 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 08:02:05.471 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:58384 10 6452 1 2025-11-25 08:02:37.715 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:02:27.945 00:00:10.372 TCP 23.104.0.1:56588 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:02:37.686 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:03:05.691 00:00:10.219 TCP 1.101.0.1:3000 -> 22.102.0.1:57948 11 6504 1 2025-11-25 08:03:28.355 00:00:10.362 TCP 23.104.0.1:49144 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:04:05.952 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:51936 10 6452 1 2025-11-25 08:04:28.756 00:00:10.374 TCP 23.104.0.1:41344 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:05:06.184 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:48382 10 6452 1 2025-11-25 08:05:29.170 00:00:10.321 TCP 23.104.0.1:36020 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:06:06.393 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:35724 10 6452 1 2025-11-25 08:06:29.532 00:00:10.329 TCP 23.104.0.1:39768 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:07:06.606 00:00:10.143 TCP 1.101.0.1:3000 -> 22.102.0.1:56640 10 6452 1 2025-11-25 08:07:37.858 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:07:29.898 00:00:10.375 TCP 23.104.0.1:40770 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:07:37.963 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:03:07.809 00:05:55.693 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 08:03:07.806 00:05:55.699 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 08:08:06.795 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:50944 10 6452 1 2025-11-25 08:08:30.308 00:00:10.327 TCP 23.104.0.1:36976 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:09:07.009 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:52448 10 6452 1 2025-11-25 08:09:30.670 00:00:10.364 TCP 23.104.0.1:58934 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:10:07.234 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:39464 10 6452 1 2025-11-25 08:10:31.103 00:00:10.369 TCP 23.104.0.1:57130 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:11:07.447 00:00:10.203 TCP 1.101.0.1:3000 -> 22.102.0.1:38226 12 10375 1 2025-11-25 08:11:31.503 00:00:10.399 TCP 23.104.0.1:43490 -> 1.101.0.1:3000 15 1926 1 2025-11-25 08:12:07.686 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:38100 10 6452 1 2025-11-25 08:12:37.923 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:12:37.946 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:12:31.942 00:00:10.392 TCP 23.104.0.1:52048 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:13:07.903 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:59788 10 6452 1 2025-11-25 08:13:32.361 00:00:10.371 TCP 23.104.0.1:32912 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:09:07.809 00:05:55.694 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 08:09:07.808 00:05:55.700 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 08:14:08.120 00:00:10.130 TCP 1.101.0.1:3000 -> 22.102.0.1:40102 10 6452 1 2025-11-25 08:14:32.772 00:00:10.371 TCP 23.104.0.1:57492 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:15:08.290 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:51468 10 6452 1 2025-11-25 08:15:33.180 00:00:10.364 TCP 23.104.0.1:54334 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:16:08.512 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:39682 10 6452 1 2025-11-25 08:16:33.575 00:00:10.318 TCP 23.104.0.1:42504 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:17:08.730 00:00:18.162 TCP 1.101.0.1:3000 -> 22.102.0.1:34142 10 6452 1 2025-11-25 08:17:37.926 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:17:37.892 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:17:33.932 00:00:10.337 TCP 23.104.0.1:44838 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:18:16.929 00:00:10.209 TCP 1.101.0.1:3000 -> 22.102.0.1:37746 10 6452 1 2025-11-25 08:18:34.313 00:00:10.363 TCP 23.104.0.1:58282 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:19:17.184 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:36912 10 6452 1 2025-11-25 08:19:34.709 00:00:10.365 TCP 23.104.0.1:54712 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:15:07.807 00:05:55.701 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 08:15:07.811 00:05:55.695 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 08:20:17.396 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:52500 10 6452 1 2025-11-25 08:20:35.112 00:00:10.364 TCP 23.104.0.1:43904 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:21:17.608 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:59716 10 6452 1 2025-11-25 08:21:35.509 00:00:10.367 TCP 23.104.0.1:59048 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:22:17.824 00:00:10.131 TCP 1.101.0.1:3000 -> 22.102.0.1:54862 10 6452 1 2025-11-25 08:22:38.090 00:00:00.043 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:22:37.955 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:22:35.914 00:00:10.374 TCP 23.104.0.1:54178 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:23:18.000 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:33102 10 6452 1 2025-11-25 08:23:36.327 00:00:10.365 TCP 23.104.0.1:43970 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:24:18.217 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:34544 10 6452 1 2025-11-25 08:24:36.727 00:00:10.380 TCP 23.104.0.1:55686 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:25:18.433 00:00:10.137 TCP 1.101.0.1:3000 -> 22.102.0.1:50992 10 6452 1 2025-11-25 08:25:37.173 00:00:10.364 TCP 23.104.0.1:58328 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:21:07.813 00:05:55.694 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 08:21:07.810 00:05:55.700 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 08:26:18.607 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:48324 10 6452 1 2025-11-25 08:26:37.577 00:00:10.363 TCP 23.104.0.1:42926 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:27:18.822 00:00:10.130 TCP 1.101.0.1:3000 -> 22.102.0.1:43738 10 6452 1 2025-11-25 08:27:38.283 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:27:38.240 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:27:37.979 00:00:10.383 TCP 23.104.0.1:59434 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:28:18.993 00:00:10.192 TCP 1.101.0.1:3000 -> 22.102.0.1:35006 10 6452 1 2025-11-25 08:28:38.399 00:00:10.366 TCP 23.104.0.1:57880 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:29:19.223 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:36738 10 6452 1 2025-11-25 08:29:38.813 00:00:10.368 TCP 23.104.0.1:40418 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:30:19.447 00:00:10.130 TCP 1.101.0.1:3000 -> 22.102.0.1:51598 10 6452 1 2025-11-25 08:30:39.219 00:00:10.374 TCP 23.104.0.1:41014 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:31:19.617 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:52592 10 6452 1 2025-11-25 08:31:39.631 00:00:10.365 TCP 23.104.0.1:58452 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:27:07.816 00:05:55.695 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 08:27:07.813 00:05:55.700 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 08:32:19.835 00:00:10.283 TCP 1.101.0.1:3000 -> 22.102.0.1:44312 10 6452 1 2025-11-25 08:32:38.263 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:32:38.099 00:00:00.041 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:32:40.044 00:00:10.363 TCP 23.104.0.1:44350 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:33:20.159 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:36084 10 6452 1 2025-11-25 08:33:40.446 00:00:10.365 TCP 23.104.0.1:43092 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:34:20.330 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:45240 10 6452 1 2025-11-25 08:34:40.850 00:00:10.384 TCP 23.104.0.1:40472 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:35:20.543 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:45122 10 6452 1 2025-11-25 08:35:41.273 00:00:10.366 TCP 23.104.0.1:56218 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:36:20.755 00:00:11.100 TCP 1.101.0.1:3000 -> 22.102.0.1:33138 10 6452 1 2025-11-25 08:36:41.680 00:00:10.365 TCP 23.104.0.1:41470 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:37:21.894 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:40050 10 6452 1 2025-11-25 08:37:38.378 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:37:38.382 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:37:42.101 00:00:10.364 TCP 23.104.0.1:52996 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:33:07.813 00:05:55.700 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 08:33:07.816 00:05:55.695 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 08:38:22.123 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:35050 10 6452 1 2025-11-25 08:38:42.519 00:00:10.366 TCP 23.104.0.1:54602 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:39:22.351 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:39942 10 6452 1 2025-11-25 08:39:42.923 00:00:10.381 TCP 23.104.0.1:36696 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:40:22.565 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:34258 10 6452 1 2025-11-25 08:40:43.344 00:00:10.365 TCP 23.104.0.1:49684 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:41:22.793 00:00:10.128 TCP 1.101.0.1:3000 -> 22.102.0.1:36238 10 6452 1 2025-11-25 08:41:43.746 00:00:10.365 TCP 23.104.0.1:52704 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:42:22.961 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:43558 10 6452 1 2025-11-25 08:42:38.482 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:42:38.318 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:42:44.147 00:00:10.326 TCP 23.104.0.1:47716 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:43:23.181 00:00:10.168 TCP 1.101.0.1:3000 -> 22.102.0.1:53588 10 6452 1 2025-11-25 08:43:44.509 00:00:10.363 TCP 23.104.0.1:45194 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:39:07.815 00:05:55.700 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 08:39:07.817 00:05:55.695 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 08:44:23.390 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:50692 10 6452 1 2025-11-25 08:44:44.910 00:00:10.324 TCP 23.104.0.1:42684 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:45:23.597 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:51244 10 6452 1 2025-11-25 08:45:45.275 00:00:10.364 TCP 23.104.0.1:47024 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:46:23.763 00:00:10.294 TCP 1.101.0.1:3000 -> 22.102.0.1:54876 10 6452 1 2025-11-25 08:46:45.684 00:00:10.362 TCP 23.104.0.1:37590 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:47:24.093 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:32974 10 6452 1 2025-11-25 08:47:38.624 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:47:38.608 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:47:46.105 00:00:10.363 TCP 23.104.0.1:55500 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:48:24.310 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:48576 10 6452 1 2025-11-25 08:48:46.505 00:00:10.366 TCP 23.104.0.1:52510 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:49:24.528 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:47848 10 6452 1 2025-11-25 08:49:46.910 00:00:10.325 TCP 23.104.0.1:58420 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:45:07.817 00:05:55.699 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 08:45:07.818 00:05:55.695 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 08:50:24.742 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:36216 10 6452 1 2025-11-25 08:50:47.275 00:00:10.371 TCP 23.104.0.1:45076 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:51:24.968 00:00:10.184 TCP 1.101.0.1:3000 -> 22.102.0.1:51014 10 6452 1 2025-11-25 08:51:47.680 00:00:10.366 TCP 23.104.0.1:38526 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:52:25.190 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:38132 10 6452 1 2025-11-25 08:52:38.589 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:52:38.710 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:52:48.107 00:00:10.368 TCP 23.104.0.1:57682 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:53:25.405 00:00:11.000 TCP 1.101.0.1:3000 -> 22.102.0.1:51062 10 6452 1 2025-11-25 08:53:48.515 00:00:10.367 TCP 23.104.0.1:46326 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:54:26.441 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:50686 10 6452 1 2025-11-25 08:54:48.919 00:00:10.371 TCP 23.104.0.1:38268 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:55:26.650 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:47318 10 6452 1 2025-11-25 08:55:49.331 00:00:10.373 TCP 23.104.0.1:41402 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:51:07.818 00:05:55.698 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 08:51:07.821 00:05:55.693 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 08:56:26.870 00:00:10.195 TCP 1.101.0.1:3000 -> 22.102.0.1:53482 10 6452 1 2025-11-25 08:56:49.747 00:00:10.370 TCP 23.104.0.1:51650 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:57:38.774 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 08:57:27.098 00:00:10.149 TCP 1.101.0.1:3000 -> 22.102.0.1:40088 10 6452 1 2025-11-25 08:57:38.684 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 08:57:50.159 00:00:10.368 TCP 23.104.0.1:59932 -> 1.101.0.1:3000 11 1507 1 2025-11-25 08:58:27.286 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:36084 10 6452 1 Summary: total flows: 163, total bytes: 501235, total packets: 1568, avg bps: 1086, avg pps: 0, avg bpp: 319 Time window: 2025-11-25 07:57:07 - 2025-11-25 08:58:37 Total flows processed: 163, passed: 163, Blocks skipped: 0, Bytes read: 17016 Sys: 0.0048s User: 0.0010s Wall: 0.0020s flows/second: 82789.0 Runtime: 0.0020s