Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-25 18:58:56.935 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:36360 10 6452 1 2025-11-25 18:59:20.048 00:00:10.361 TCP 23.104.0.1:38530 -> 1.101.0.1:3000 11 1507 1 2025-11-25 18:59:57.147 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:35586 10 6452 1 2025-11-25 19:00:20.446 00:00:10.368 TCP 23.104.0.1:47828 -> 1.101.0.1:3000 11 1507 1 2025-11-25 18:57:03.698 00:05:04.338 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 19:00:57.367 00:00:10.126 TCP 1.101.0.1:3000 -> 22.102.0.1:41096 10 6452 1 2025-11-25 18:57:03.702 00:05:04.333 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 19:01:20.851 00:00:10.341 TCP 23.104.0.1:46074 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:01:57.539 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:34968 10 6452 1 2025-11-25 19:02:21.228 00:00:10.364 TCP 23.104.0.1:36500 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:02:50.808 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:02:50.936 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:02:57.751 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:44208 10 6452 1 2025-11-25 19:03:21.629 00:00:10.366 TCP 23.104.0.1:57818 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:03:57.963 00:00:10.222 TCP 1.101.0.1:3000 -> 22.102.0.1:57894 10 6452 1 2025-11-25 19:04:22.052 00:00:10.364 TCP 23.104.0.1:55154 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:04:58.221 00:00:10.135 TCP 1.101.0.1:3000 -> 22.102.0.1:44838 10 6452 1 2025-11-25 19:05:22.456 00:00:10.371 TCP 23.104.0.1:39980 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:05:58.397 00:00:10.184 TCP 1.101.0.1:3000 -> 22.102.0.1:46478 10 6452 1 2025-11-25 19:06:22.866 00:00:10.401 TCP 23.104.0.1:46328 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:03:03.701 00:05:04.336 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 19:06:58.618 00:00:10.184 TCP 1.101.0.1:3000 -> 22.102.0.1:51560 10 6452 1 2025-11-25 19:03:03.700 00:05:04.341 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 19:07:23.303 00:00:10.364 TCP 23.104.0.1:44864 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:07:51.239 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:07:51.064 00:00:00.039 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:07:58.840 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:58720 10 6452 1 2025-11-25 19:08:23.705 00:00:10.369 TCP 23.104.0.1:36608 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:08:59.077 00:00:10.194 TCP 1.101.0.1:3000 -> 22.102.0.1:42458 10 6452 1 2025-11-25 19:09:24.113 00:00:10.373 TCP 23.104.0.1:53976 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:09:59.309 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:52798 10 6452 1 2025-11-25 19:10:24.539 00:00:10.365 TCP 23.104.0.1:58686 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:10:59.482 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:52212 10 6452 1 2025-11-25 19:11:24.939 00:00:10.407 TCP 23.104.0.1:43068 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:11:59.693 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:40442 10 6452 1 2025-11-25 19:12:25.346 00:00:10.331 TCP 23.104.0.1:53150 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:12:50.915 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:12:51.051 00:00:00.046 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:12:59.914 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:50748 10 6452 1 2025-11-25 19:09:03.705 00:05:04.337 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 19:09:03.708 00:05:04.331 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 19:13:25.724 00:00:10.376 TCP 23.104.0.1:46628 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:14:00.130 00:00:10.199 TCP 1.101.0.1:3000 -> 22.102.0.1:53078 10 6452 1 2025-11-25 19:14:26.137 00:00:10.366 TCP 23.104.0.1:42512 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:15:00.373 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:47954 10 6452 1 2025-11-25 19:15:26.539 00:00:10.367 TCP 23.104.0.1:53524 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:16:00.582 00:00:10.169 TCP 1.101.0.1:3000 -> 22.102.0.1:53786 10 6452 1 2025-11-25 19:16:26.946 00:00:10.366 TCP 23.104.0.1:54874 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:17:00.799 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:36958 10 6452 1 2025-11-25 19:17:27.353 00:00:10.373 TCP 23.104.0.1:57200 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:17:51.340 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:17:51.233 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:18:01.027 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:34406 10 6452 1 2025-11-25 19:18:27.765 00:00:10.373 TCP 23.104.0.1:50724 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:15:03.708 00:05:04.338 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 19:19:01.251 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:57448 10 6452 1 2025-11-25 19:15:03.711 00:05:04.333 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 19:19:28.180 00:00:10.372 TCP 23.104.0.1:49372 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:20:01.471 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:32868 10 6452 1 2025-11-25 19:20:28.589 00:00:10.366 TCP 23.104.0.1:37052 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:21:01.687 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:48214 10 6452 1 2025-11-25 19:21:28.991 00:00:10.326 TCP 23.104.0.1:44930 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:22:01.904 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:41978 10 6452 1 2025-11-25 19:22:29.361 00:00:10.368 TCP 23.104.0.1:56568 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:22:51.311 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:22:50.989 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:23:02.123 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:56542 10 6452 1 2025-11-25 19:23:29.768 00:00:10.327 TCP 23.104.0.1:50014 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:24:02.343 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:47294 10 6452 1 2025-11-25 19:24:30.135 00:00:10.361 TCP 23.104.0.1:37898 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:21:03.709 00:05:04.340 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 19:21:03.713 00:05:04.334 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 19:25:02.564 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:40128 10 6452 1 2025-11-25 19:25:30.536 00:00:10.359 TCP 23.104.0.1:37426 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:26:02.791 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:36426 10 6452 1 2025-11-25 19:26:30.934 00:00:10.336 TCP 23.104.0.1:48468 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:27:03.010 00:00:11.189 TCP 1.101.0.1:3000 -> 22.102.0.1:51234 10 6452 1 2025-11-25 19:27:31.310 00:00:10.322 TCP 23.104.0.1:57956 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:27:51.229 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:27:51.460 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:28:04.236 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:55738 10 6452 1 2025-11-25 19:28:31.680 00:00:10.329 TCP 23.104.0.1:44644 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:29:04.446 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:49794 10 6452 1 2025-11-25 19:29:32.063 00:00:10.365 TCP 23.104.0.1:55474 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:30:04.662 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:58522 10 6452 1 2025-11-25 19:30:32.467 00:00:10.339 TCP 23.104.0.1:45550 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:27:03.711 00:05:04.340 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 19:27:03.713 00:05:04.335 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 19:31:04.884 00:00:10.216 TCP 1.101.0.1:3000 -> 22.102.0.1:51630 12 10375 1 2025-11-25 19:31:32.832 00:00:10.424 TCP 23.104.0.1:48298 -> 1.101.0.1:3000 15 1926 1 2025-11-25 19:32:05.135 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:38768 10 6452 1 2025-11-25 19:32:33.295 00:00:10.322 TCP 23.104.0.1:33164 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:32:51.447 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:32:51.470 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:33:05.357 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:47314 10 6452 1 2025-11-25 19:33:33.661 00:00:10.366 TCP 23.104.0.1:56438 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:34:05.579 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:47408 10 6452 1 2025-11-25 19:34:34.096 00:00:10.367 TCP 23.104.0.1:44744 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:35:05.798 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:53044 10 6452 1 2025-11-25 19:35:34.499 00:00:10.321 TCP 23.104.0.1:37912 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:36:06.006 00:00:10.209 TCP 1.101.0.1:3000 -> 22.102.0.1:46828 12 10369 1 2025-11-25 19:36:34.864 00:00:10.450 TCP 23.104.0.1:48378 -> 1.101.0.1:3000 15 1926 1 2025-11-25 19:33:03.715 00:05:04.335 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 19:33:03.714 00:05:04.340 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 19:37:06.260 00:00:10.218 TCP 1.101.0.1:3000 -> 22.102.0.1:56452 10 6452 1 2025-11-25 19:37:35.358 00:00:10.360 TCP 23.104.0.1:49778 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:37:51.720 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:37:51.677 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:38:06.517 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:56604 10 6452 1 2025-11-25 19:38:35.756 00:00:10.374 TCP 23.104.0.1:38498 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:39:06.732 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:40466 10 6452 1 2025-11-25 19:39:36.170 00:00:10.366 TCP 23.104.0.1:52858 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:40:06.945 00:00:10.189 TCP 1.101.0.1:3000 -> 22.102.0.1:58024 10 6452 1 2025-11-25 19:40:36.576 00:00:10.368 TCP 23.104.0.1:55396 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:41:07.179 00:00:10.137 TCP 1.101.0.1:3000 -> 22.102.0.1:55130 10 6452 1 2025-11-25 19:41:36.983 00:00:10.341 TCP 23.104.0.1:33392 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:42:07.353 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:58106 10 6452 1 2025-11-25 19:42:51.704 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:42:51.808 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:42:37.366 00:00:10.370 TCP 23.104.0.1:38752 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:39:03.716 00:05:04.340 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 19:39:03.718 00:05:04.334 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 19:43:07.567 00:00:10.143 TCP 1.101.0.1:3000 -> 22.102.0.1:42574 10 6452 1 2025-11-25 19:43:37.775 00:00:10.368 TCP 23.104.0.1:56426 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:44:07.750 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:47952 10 6452 1 2025-11-25 19:44:38.182 00:00:10.364 TCP 23.104.0.1:57276 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:45:07.965 00:00:10.199 TCP 1.101.0.1:3000 -> 22.102.0.1:39902 10 6452 1 2025-11-25 19:45:38.591 00:00:10.361 TCP 23.104.0.1:54360 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:46:08.202 00:00:10.138 TCP 1.101.0.1:3000 -> 22.102.0.1:53504 10 6452 1 2025-11-25 19:46:38.990 00:00:10.331 TCP 23.104.0.1:56262 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:47:08.381 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:54578 10 6452 1 2025-11-25 19:47:51.765 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:47:39.355 00:00:10.366 TCP 23.104.0.1:37354 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:47:51.859 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:48:08.600 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:58298 10 6452 1 2025-11-25 19:48:39.767 00:00:10.382 TCP 23.104.0.1:44202 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:45:03.719 00:05:04.335 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 19:45:03.716 00:05:04.341 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 19:49:08.822 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:41472 10 6452 1 2025-11-25 19:49:40.186 00:00:10.379 TCP 23.104.0.1:49958 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:50:09.070 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:51280 10 6452 1 2025-11-25 19:50:40.604 00:00:10.360 TCP 23.104.0.1:57178 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:51:09.287 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:43772 10 6452 1 2025-11-25 19:51:41.003 00:00:10.367 TCP 23.104.0.1:49118 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:52:09.501 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:46586 10 6452 1 2025-11-25 19:52:51.776 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:52:41.410 00:00:10.372 TCP 23.104.0.1:49260 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:52:52.058 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:53:09.713 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:53794 10 6452 1 2025-11-25 19:53:41.822 00:00:10.321 TCP 23.104.0.1:53888 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:54:09.926 00:00:10.202 TCP 1.101.0.1:3000 -> 22.102.0.1:51036 10 6452 1 2025-11-25 19:54:42.186 00:00:10.375 TCP 23.104.0.1:34654 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:51:03.720 00:05:04.337 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-25 19:51:03.718 00:05:04.342 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-25 19:55:10.169 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:60654 10 6452 1 2025-11-25 19:55:42.598 00:00:10.332 TCP 23.104.0.1:60100 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:56:10.386 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:45378 10 6452 1 2025-11-25 19:56:42.983 00:00:10.363 TCP 23.104.0.1:43690 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:57:10.598 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:54996 10 6452 1 2025-11-25 19:57:52.116 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-25 19:57:52.258 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-25 19:57:43.386 00:00:10.371 TCP 23.104.0.1:55632 -> 1.101.0.1:3000 11 1507 1 2025-11-25 19:58:10.816 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:38040 10 6452 1 Summary: total flows: 163, total bytes: 505519, total packets: 1573, avg bps: 1099, avg pps: 0, avg bpp: 321 Time window: 2025-11-25 18:57:03 - 2025-11-25 19:58:20 Total flows processed: 163, passed: 163, Blocks skipped: 0, Bytes read: 17016 Sys: 0.0041s User: 0.0031s Wall: 0.0030s flows/second: 55085.9 Runtime: 0.0030s