Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-05 08:58:42.714 00:00:10.397 TCP 23.104.0.1:48616 -> 1.101.0.1:3000 15 1926 1 2025-12-05 08:55:07.923 00:05:04.916 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-12-05 08:55:07.912 00:05:04.929 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-12-05 08:59:13.060 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:38710 10 6452 1 2025-12-05 08:59:43.150 00:00:10.365 TCP 23.104.0.1:33274 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:00:13.270 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:47570 10 6452 1 2025-12-05 09:00:43.558 00:00:10.320 TCP 23.104.0.1:41634 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:01:13.484 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:37984 10 6452 1 2025-12-05 09:01:43.916 00:00:10.381 TCP 23.104.0.1:35416 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:02:27.899 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:02:13.701 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:45206 10 6452 1 2025-12-05 09:02:27.882 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:02:44.338 00:00:10.369 TCP 23.104.0.1:41234 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:03:13.913 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:54444 10 6452 1 2025-12-05 09:03:44.744 00:00:10.364 TCP 23.104.0.1:41554 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:04:14.130 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:43160 10 6452 1 2025-12-05 09:04:45.147 00:00:10.362 TCP 23.104.0.1:52480 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:01:07.915 00:05:04.928 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-12-05 09:01:07.916 00:05:04.923 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-12-05 09:05:14.337 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:49658 10 6452 1 2025-12-05 09:05:45.553 00:00:10.359 TCP 23.104.0.1:37140 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:06:14.511 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:55442 10 6452 1 2025-12-05 09:06:45.953 00:00:10.369 TCP 23.104.0.1:39528 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:07:14.724 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:55622 10 6452 1 2025-12-05 09:07:27.912 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:07:28.007 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:07:46.369 00:00:10.362 TCP 23.104.0.1:48982 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:08:14.933 00:00:10.152 TCP 1.101.0.1:3000 -> 22.102.0.1:44426 10 6452 1 2025-12-05 09:08:46.773 00:00:10.366 TCP 23.104.0.1:57386 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:09:15.120 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:33358 10 6452 1 2025-12-05 09:09:47.179 00:00:10.364 TCP 23.104.0.1:37318 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:10:15.344 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:40288 10 6452 1 2025-12-05 09:10:47.583 00:00:10.369 TCP 23.104.0.1:52654 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:07:07.916 00:05:04.929 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-12-05 09:07:07.918 00:05:04.924 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-12-05 09:11:15.561 00:00:10.393 TCP 1.101.0.1:3000 -> 22.102.0.1:60566 10 6452 1 2025-12-05 09:11:47.991 00:00:10.369 TCP 23.104.0.1:54996 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:12:27.785 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:12:15.995 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:58082 10 6452 1 2025-12-05 09:12:27.942 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:12:48.396 00:00:10.323 TCP 23.104.0.1:41030 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:13:16.221 00:00:10.196 TCP 1.101.0.1:3000 -> 22.102.0.1:48812 12 10369 1 2025-12-05 09:13:48.755 00:00:10.454 TCP 23.104.0.1:59116 -> 1.101.0.1:3000 15 1926 1 2025-12-05 09:14:16.455 00:00:10.131 TCP 1.101.0.1:3000 -> 22.102.0.1:48428 10 6452 1 2025-12-05 09:14:49.247 00:00:10.365 TCP 23.104.0.1:59070 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:15:16.626 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:56432 10 6452 1 2025-12-05 09:15:49.654 00:00:10.442 TCP 23.104.0.1:35684 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:16:16.835 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:45502 10 6452 1 2025-12-05 09:16:50.136 00:00:10.360 TCP 23.104.0.1:44440 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:13:07.917 00:05:04.929 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-12-05 09:13:07.920 00:05:04.923 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-12-05 09:17:27.977 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:17:28.045 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:17:17.074 00:00:10.184 TCP 1.101.0.1:3000 -> 22.102.0.1:59382 10 6452 1 2025-12-05 09:17:50.535 00:00:10.365 TCP 23.104.0.1:49228 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:18:17.304 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:38384 10 6452 1 2025-12-05 09:18:50.949 00:00:10.370 TCP 23.104.0.1:42274 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:19:17.519 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:43514 10 6452 1 2025-12-05 09:19:51.364 00:00:10.369 TCP 23.104.0.1:38788 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:20:17.732 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:46402 10 6452 1 2025-12-05 09:20:51.771 00:00:10.372 TCP 23.104.0.1:51328 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:21:17.967 00:00:10.194 TCP 1.101.0.1:3000 -> 22.102.0.1:39278 12 6556 1 2025-12-05 09:21:52.180 00:00:10.368 TCP 23.104.0.1:58460 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:22:28.780 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:22:18.195 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:45812 10 6452 1 2025-12-05 09:22:29.133 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:22:52.587 00:00:10.367 TCP 23.104.0.1:47720 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:19:07.921 00:05:04.924 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-12-05 09:19:07.920 00:05:04.929 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-12-05 09:23:18.402 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:43938 10 6452 1 2025-12-05 09:23:52.989 00:00:10.331 TCP 23.104.0.1:45008 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:24:18.621 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:57938 10 6452 1 2025-12-05 09:24:53.358 00:00:10.694 TCP 23.104.0.1:34730 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:25:18.839 00:00:10.191 TCP 1.101.0.1:3000 -> 22.102.0.1:34230 10 6452 1 2025-12-05 09:25:54.101 00:00:10.373 TCP 23.104.0.1:38362 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:26:19.080 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:48364 10 6452 1 2025-12-05 09:26:54.510 00:00:10.323 TCP 23.104.0.1:36286 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:27:19.288 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:52280 10 6452 1 2025-12-05 09:27:28.189 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:27:27.998 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:27:54.877 00:00:10.329 TCP 23.104.0.1:60900 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:28:19.508 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:43344 10 6452 1 2025-12-05 09:28:55.242 00:00:10.786 TCP 23.104.0.1:36728 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:25:07.922 00:05:04.930 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-12-05 09:25:07.919 00:05:04.935 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-12-05 09:29:19.723 00:00:10.130 TCP 1.101.0.1:3000 -> 22.102.0.1:42930 10 6452 1 2025-12-05 09:29:56.097 00:00:10.361 TCP 23.104.0.1:54964 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:30:19.893 00:00:10.231 TCP 1.101.0.1:3000 -> 22.102.0.1:57934 11 6504 1 2025-12-05 09:30:56.499 00:00:10.364 TCP 23.104.0.1:50626 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:31:20.167 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:33286 10 6452 1 2025-12-05 09:31:56.913 00:00:10.361 TCP 23.104.0.1:41282 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:32:20.392 00:00:10.184 TCP 1.101.0.1:3000 -> 22.102.0.1:55178 10 6452 1 2025-12-05 09:32:28.107 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:32:28.346 00:00:00.020 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:32:57.314 00:00:10.361 TCP 23.104.0.1:45048 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:33:20.614 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:44262 10 6452 1 2025-12-05 09:33:57.715 00:00:10.373 TCP 23.104.0.1:58484 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:34:20.835 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:37446 10 6452 1 2025-12-05 09:34:58.127 00:00:10.364 TCP 23.104.0.1:59952 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:31:07.922 00:05:04.931 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-12-05 09:31:07.921 00:05:04.936 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-12-05 09:35:21.083 00:00:10.126 TCP 1.101.0.1:3000 -> 22.102.0.1:34176 10 6452 1 2025-12-05 09:35:58.533 00:00:10.362 TCP 23.104.0.1:50786 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:36:21.250 00:00:10.413 TCP 1.101.0.1:3000 -> 22.102.0.1:39316 10 6452 1 2025-12-05 09:36:58.934 00:00:10.337 TCP 23.104.0.1:39282 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:37:28.055 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:37:21.697 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:33822 10 6452 1 2025-12-05 09:37:28.371 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:37:59.309 00:00:10.361 TCP 23.104.0.1:52698 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:38:21.912 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:51504 10 6452 1 2025-12-05 09:38:59.713 00:00:10.377 TCP 23.104.0.1:59274 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:39:22.148 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:52694 10 6452 1 2025-12-05 09:40:00.132 00:00:10.710 TCP 23.104.0.1:57898 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:40:22.363 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:39272 10 6452 1 2025-12-05 09:41:00.875 00:00:10.324 TCP 23.104.0.1:50812 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:37:07.922 00:05:04.935 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-12-05 09:37:07.925 00:05:04.929 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-12-05 09:41:22.577 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:55064 10 6452 1 2025-12-05 09:42:01.236 00:00:10.366 TCP 23.104.0.1:59554 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:42:28.572 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:42:28.890 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:42:22.787 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:54326 10 6452 1 2025-12-05 09:43:01.639 00:00:10.367 TCP 23.104.0.1:57700 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:43:22.996 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:43702 12 6556 1 2025-12-05 09:44:02.050 00:00:10.324 TCP 23.104.0.1:44882 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:44:23.220 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:60250 10 6452 1 2025-12-05 09:45:02.414 00:00:10.364 TCP 23.104.0.1:33694 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:45:23.435 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:33530 10 6452 1 2025-12-05 09:46:02.816 00:00:10.367 TCP 23.104.0.1:37784 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:46:23.656 00:00:10.168 TCP 1.101.0.1:3000 -> 22.102.0.1:58504 10 6452 1 2025-12-05 09:43:07.957 00:05:04.903 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-12-05 09:43:07.960 00:05:04.897 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-12-05 09:47:03.224 00:00:10.366 TCP 23.104.0.1:48986 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:47:28.204 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:47:28.474 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:47:23.863 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:50920 10 6452 1 2025-12-05 09:48:03.634 00:00:10.371 TCP 23.104.0.1:35578 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:48:24.084 00:00:10.135 TCP 1.101.0.1:3000 -> 22.102.0.1:43440 10 6452 1 2025-12-05 09:49:04.056 00:00:10.324 TCP 23.104.0.1:55400 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:49:24.256 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:52886 10 6452 1 2025-12-05 09:50:04.420 00:00:10.366 TCP 23.104.0.1:51526 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:50:24.474 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:53768 10 6452 1 2025-12-05 09:51:04.825 00:00:10.395 TCP 23.104.0.1:47632 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:51:24.649 00:00:11.665 TCP 1.101.0.1:3000 -> 22.102.0.1:42386 10 6452 1 2025-12-05 09:52:05.261 00:00:10.363 TCP 23.104.0.1:50598 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:52:28.517 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:52:28.494 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:52:26.353 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:58514 10 6452 1 2025-12-05 09:49:07.959 00:05:04.899 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-12-05 09:53:05.665 00:00:10.440 TCP 23.104.0.1:58524 -> 1.101.0.1:3000 15 1926 1 2025-12-05 09:49:07.957 00:05:04.904 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-12-05 09:53:26.575 00:00:10.209 TCP 1.101.0.1:3000 -> 22.102.0.1:33498 12 10375 1 2025-12-05 09:54:06.143 00:00:10.364 TCP 23.104.0.1:58326 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:54:26.823 00:00:10.141 TCP 1.101.0.1:3000 -> 22.102.0.1:32840 10 6452 1 2025-12-05 09:55:06.547 00:00:10.371 TCP 23.104.0.1:43556 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:55:27.009 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:39164 10 6452 1 2025-12-05 09:56:06.961 00:00:10.328 TCP 23.104.0.1:45516 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:56:27.220 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:33550 10 6452 1 2025-12-05 09:57:07.330 00:00:10.324 TCP 23.104.0.1:52590 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:57:28.815 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-12-05 09:57:28.808 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-12-05 09:57:27.435 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:58406 10 6452 1 2025-12-05 09:58:07.694 00:00:10.369 TCP 23.104.0.1:53910 -> 1.101.0.1:3000 11 1507 1 2025-12-05 09:58:27.662 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:55210 10 6452 1 Summary: total flows: 164, total bytes: 507705, total packets: 1593, avg bps: 1066, avg pps: 0, avg bpp: 318 Time window: 2025-12-05 08:55:07 - 2025-12-05 09:58:37 Total flows processed: 164, passed: 164, Blocks skipped: 0, Bytes read: 17120 Sys: 0.0024s User: 0.0032s Wall: 0.0030s flows/second: 55272.5 Runtime: 0.0030s