Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-27 15:59:29.345 00:00:10.365 TCP 23.104.0.1:50774 -> 1.101.0.1:3000 11 1507 1 2025-11-27 15:59:33.389 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:53940 10 6452 1 2025-11-27 15:56:04.555 00:05:04.517 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-27 15:56:04.558 00:05:04.511 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-27 16:00:29.752 00:00:10.381 TCP 23.104.0.1:58274 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:00:33.562 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:56718 10 6452 1 2025-11-27 16:01:30.178 00:00:10.366 TCP 23.104.0.1:46466 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:01:33.774 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:52338 10 6452 1 2025-11-27 16:02:30.572 00:00:10.370 TCP 23.104.0.1:59366 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:02:33.990 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:37452 10 6452 1 2025-11-27 16:03:30.978 00:00:10.376 TCP 23.104.0.1:46248 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:03:45.081 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:03:34.220 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:34262 10 6452 1 2025-11-27 16:03:44.930 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:04:31.390 00:00:10.363 TCP 23.104.0.1:57194 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:04:34.438 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:34670 10 6452 1 2025-11-27 16:05:34.653 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:47898 10 6452 1 2025-11-27 16:05:31.792 00:00:10.369 TCP 23.104.0.1:49992 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:02:04.560 00:05:04.513 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-27 16:02:04.562 00:05:04.508 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-27 16:06:34.872 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:52372 10 6452 1 2025-11-27 16:06:32.195 00:00:10.370 TCP 23.104.0.1:48420 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:07:32.597 00:00:10.365 TCP 23.104.0.1:54332 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:07:35.113 00:00:10.135 TCP 1.101.0.1:3000 -> 22.102.0.1:43298 10 6452 1 2025-11-27 16:08:35.284 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:50992 10 6452 1 2025-11-27 16:08:45.188 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:08:45.207 00:00:00.035 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:08:33.003 00:00:12.404 TCP 23.104.0.1:45552 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:09:35.444 00:00:10.365 TCP 23.104.0.1:45496 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:09:35.499 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:38382 10 6452 1 2025-11-27 16:10:35.849 00:00:10.385 TCP 23.104.0.1:45592 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:10:35.674 00:00:10.184 TCP 1.101.0.1:3000 -> 22.102.0.1:44828 10 6452 1 2025-11-27 16:11:35.899 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:48446 10 6452 1 2025-11-27 16:11:36.271 00:00:10.330 TCP 23.104.0.1:52752 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:08:04.566 00:05:04.506 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-27 16:08:04.563 00:05:04.512 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-27 16:12:36.115 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:56346 10 6452 1 2025-11-27 16:12:36.642 00:00:10.371 TCP 23.104.0.1:53538 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:13:36.334 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:59030 10 6452 1 2025-11-27 16:13:45.464 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:13:45.504 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:13:37.052 00:00:10.375 TCP 23.104.0.1:55146 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:14:36.546 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:34630 10 6452 1 2025-11-27 16:14:37.460 00:00:10.365 TCP 23.104.0.1:36722 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:15:36.768 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:37620 10 6452 1 2025-11-27 16:15:37.859 00:00:10.375 TCP 23.104.0.1:44644 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:16:37.003 00:00:10.194 TCP 1.101.0.1:3000 -> 22.102.0.1:49702 12 10369 1 2025-11-27 16:16:38.276 00:00:10.400 TCP 23.104.0.1:54568 -> 1.101.0.1:3000 15 1926 1 2025-11-27 16:17:37.239 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:38352 10 6452 1 2025-11-27 16:17:38.720 00:00:10.378 TCP 23.104.0.1:37676 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:14:04.565 00:05:04.511 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-27 16:14:04.567 00:05:04.506 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-27 16:18:45.286 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:18:37.463 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:60018 10 6452 1 2025-11-27 16:18:45.107 00:00:00.043 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:18:39.152 00:00:10.368 TCP 23.104.0.1:41840 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:19:37.676 00:00:12.392 TCP 1.101.0.1:3000 -> 22.102.0.1:53612 10 6452 1 2025-11-27 16:19:39.562 00:00:10.582 TCP 23.104.0.1:35168 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:20:40.183 00:00:10.366 TCP 23.104.0.1:55848 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:20:40.115 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:54840 10 6452 1 2025-11-27 16:21:40.326 00:00:10.135 TCP 1.101.0.1:3000 -> 22.102.0.1:45610 10 6452 1 2025-11-27 16:21:40.585 00:00:10.360 TCP 23.104.0.1:40990 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:22:40.499 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:48404 10 6452 1 2025-11-27 16:22:40.986 00:00:10.369 TCP 23.104.0.1:43106 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:23:45.907 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:23:45.340 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:23:40.713 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:48080 10 6452 1 2025-11-27 16:23:41.392 00:00:10.364 TCP 23.104.0.1:54584 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:20:04.568 00:05:04.506 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-27 16:20:04.567 00:05:04.511 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-27 16:24:40.926 00:00:10.194 TCP 1.101.0.1:3000 -> 22.102.0.1:42528 10 6452 1 2025-11-27 16:24:41.793 00:00:10.366 TCP 23.104.0.1:34836 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:25:41.159 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:45246 10 6452 1 2025-11-27 16:25:42.197 00:00:10.361 TCP 23.104.0.1:57120 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:26:41.370 00:00:10.776 TCP 1.101.0.1:3000 -> 22.102.0.1:42122 10 6452 1 2025-11-27 16:26:42.597 00:00:10.370 TCP 23.104.0.1:36570 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:27:42.179 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:33216 10 6452 1 2025-11-27 16:27:43.006 00:00:10.366 TCP 23.104.0.1:60992 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:28:45.562 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:28:45.616 00:00:00.024 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:28:42.347 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:56176 10 6452 1 2025-11-27 16:28:43.410 00:00:10.365 TCP 23.104.0.1:41518 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:29:42.553 00:00:10.133 TCP 1.101.0.1:3000 -> 22.102.0.1:33380 10 6452 1 2025-11-27 16:29:43.814 00:00:10.360 TCP 23.104.0.1:50268 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:26:04.566 00:05:04.514 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-27 16:26:04.570 00:05:04.509 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-27 16:30:44.212 00:00:10.366 TCP 23.104.0.1:60538 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:30:42.724 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:52442 10 6452 1 2025-11-27 16:31:44.628 00:00:10.364 TCP 23.104.0.1:51248 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:31:42.931 00:00:10.204 TCP 1.101.0.1:3000 -> 22.102.0.1:46496 10 6452 1 2025-11-27 16:32:45.030 00:00:10.363 TCP 23.104.0.1:36732 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:32:43.176 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:51116 10 6452 1 2025-11-27 16:33:45.718 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:33:45.553 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:33:45.430 00:00:10.364 TCP 23.104.0.1:36988 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:33:43.391 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:51874 10 6452 1 2025-11-27 16:34:43.604 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:50328 10 6452 1 2025-11-27 16:34:45.836 00:00:10.350 TCP 23.104.0.1:57894 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:35:46.225 00:00:10.374 TCP 23.104.0.1:48846 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:35:43.821 00:00:10.803 TCP 1.101.0.1:3000 -> 22.102.0.1:42788 10 6452 1 2025-11-27 16:32:04.567 00:05:04.513 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-27 16:32:04.570 00:05:04.508 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-27 16:36:44.666 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:54552 10 6452 1 2025-11-27 16:36:46.665 00:00:10.362 TCP 23.104.0.1:47434 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:37:44.876 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:45298 10 6452 1 2025-11-27 16:37:47.089 00:00:10.358 TCP 23.104.0.1:39684 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:38:45.873 00:00:00.031 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:38:45.794 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:38:45.095 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:32978 10 6452 1 2025-11-27 16:38:47.486 00:00:10.366 TCP 23.104.0.1:48080 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:39:45.311 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:57898 10 6452 1 2025-11-27 16:39:47.894 00:00:10.375 TCP 23.104.0.1:40116 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:40:45.524 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:39582 10 6452 1 2025-11-27 16:40:48.333 00:00:10.328 TCP 23.104.0.1:47372 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:41:45.743 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:46076 10 6452 1 2025-11-27 16:41:48.697 00:00:10.366 TCP 23.104.0.1:42064 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:38:04.572 00:05:04.514 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-27 16:38:04.575 00:05:04.510 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-27 16:42:45.971 00:00:10.149 TCP 1.101.0.1:3000 -> 22.102.0.1:36752 10 6452 1 2025-11-27 16:42:49.112 00:00:10.368 TCP 23.104.0.1:53756 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:43:46.233 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:43:46.225 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:43:46.163 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:56804 10 6452 1 2025-11-27 16:43:49.533 00:00:10.326 TCP 23.104.0.1:48964 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:44:46.385 00:00:10.169 TCP 1.101.0.1:3000 -> 22.102.0.1:40366 10 6452 1 2025-11-27 16:44:49.901 00:00:10.329 TCP 23.104.0.1:57004 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:45:46.592 00:00:10.136 TCP 1.101.0.1:3000 -> 22.102.0.1:42012 10 6452 1 2025-11-27 16:45:50.270 00:00:10.364 TCP 23.104.0.1:35586 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:46:46.769 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:47032 10 6452 1 2025-11-27 16:46:50.672 00:00:10.372 TCP 23.104.0.1:57960 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:47:46.983 00:00:10.194 TCP 1.101.0.1:3000 -> 22.102.0.1:33108 10 6452 1 2025-11-27 16:47:51.107 00:00:10.324 TCP 23.104.0.1:47446 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:44:04.575 00:05:04.510 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-27 16:44:04.574 00:05:04.515 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-27 16:48:46.022 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:48:45.910 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:48:47.213 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:45116 10 6452 1 2025-11-27 16:48:51.463 00:00:10.379 TCP 23.104.0.1:43724 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:49:47.428 00:00:10.131 TCP 1.101.0.1:3000 -> 22.102.0.1:56376 10 6452 1 2025-11-27 16:49:51.876 00:00:10.417 TCP 23.104.0.1:45246 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:50:47.598 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:36900 10 6452 1 2025-11-27 16:50:52.329 00:00:10.376 TCP 23.104.0.1:45676 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:51:47.770 00:00:10.127 TCP 1.101.0.1:3000 -> 22.102.0.1:35096 10 6452 1 2025-11-27 16:51:52.738 00:00:10.370 TCP 23.104.0.1:34116 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:52:47.936 00:00:10.159 TCP 1.101.0.1:3000 -> 22.102.0.1:49766 10 6452 1 2025-11-27 16:52:53.144 00:00:10.368 TCP 23.104.0.1:52508 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:53:46.147 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:53:46.026 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-27 16:53:48.137 00:00:10.136 TCP 1.101.0.1:3000 -> 22.102.0.1:33676 10 6452 1 2025-11-27 16:53:53.550 00:00:10.359 TCP 23.104.0.1:54064 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:50:04.578 00:05:04.508 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-27 16:50:04.575 00:05:04.514 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-27 16:54:48.311 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:45586 10 6452 1 2025-11-27 16:54:53.947 00:00:10.373 TCP 23.104.0.1:49504 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:55:48.485 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:35062 10 6452 1 2025-11-27 16:55:54.356 00:00:10.378 TCP 23.104.0.1:48922 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:56:48.694 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:58638 10 6452 1 2025-11-27 16:56:54.769 00:00:10.330 TCP 23.104.0.1:52764 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:57:48.908 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:46498 10 6452 1 2025-11-27 16:57:55.139 00:00:10.336 TCP 23.104.0.1:51776 -> 1.101.0.1:3000 11 1507 1 2025-11-27 16:58:46.049 00:00:00.025 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-27 16:58:46.011 00:00:00.028 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 Summary: total flows: 162, total bytes: 494725, total packets: 1557, avg bps: 1052, avg pps: 0, avg bpp: 317 Time window: 2025-11-27 15:56:04 - 2025-11-27 16:58:46 Total flows processed: 162, passed: 162, Blocks skipped: 0, Bytes read: 16912 Sys: 0.0043s User: 0.0014s Wall: 0.0065s flows/second: 24771.3 Runtime: 0.0066s