Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-04 04:59:06.997 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:37332 10 6452 1 2025-10-04 04:55:38.911 00:05:00.381 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-04 05:00:07.357 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48254 10 6452 1 2025-10-04 05:01:07.756 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:45650 10 6452 1 2025-10-04 05:02:08.172 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48384 10 6452 1 2025-10-04 05:02:30.530 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:02:30.166 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:02:30.563 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:02:30.429 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:02:30.645 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:03:08.576 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:55006 10 6452 1 2025-10-04 04:59:38.914 00:05:00.376 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-04 05:04:08.974 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:41434 10 6452 1 2025-10-04 05:05:09.344 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47228 10 6452 1 2025-10-04 05:01:38.912 00:05:00.380 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-04 05:06:09.750 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:60082 10 6452 1 2025-10-04 05:07:10.155 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:37076 10 6452 1 2025-10-04 05:07:30.495 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:07:30.680 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:07:30.222 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:07:30.413 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:07:30.517 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:08:10.521 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:37320 10 6452 1 2025-10-04 05:09:10.882 00:00:10.344 TCP 1.101.0.1:3000 -> 23.104.0.1:40720 10 6452 1 2025-10-04 05:05:38.916 00:05:00.375 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-04 05:10:11.267 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:44468 10 6452 1 2025-10-04 05:11:11.631 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41808 10 6452 1 2025-10-04 05:07:38.914 00:05:00.379 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-04 05:12:12.037 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:36786 10 6452 1 2025-10-04 05:12:30.833 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:12:30.755 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:12:30.848 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:12:30.750 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:12:30.889 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:13:12.439 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:48214 10 6452 1 2025-10-04 05:14:12.853 00:00:10.392 TCP 1.101.0.1:3000 -> 23.104.0.1:37302 10 6452 1 2025-10-04 05:15:13.289 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52814 10 6452 1 2025-10-04 05:11:38.916 00:05:00.376 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-04 05:16:13.693 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:39372 10 6452 1 2025-10-04 05:17:14.110 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55534 10 6452 1 2025-10-04 05:17:30.579 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:17:30.497 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:17:30.652 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:17:30.655 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:17:30.735 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:13:38.915 00:05:00.379 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-04 05:18:14.514 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:32848 10 6452 1 2025-10-04 05:19:14.923 00:00:10.357 TCP 1.101.0.1:3000 -> 23.104.0.1:54240 10 6452 1 2025-10-04 05:20:15.317 00:00:16.396 TCP 1.101.0.1:3000 -> 23.104.0.1:60378 10 6452 1 2025-10-04 05:21:21.760 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:56784 10 6452 1 2025-10-04 05:17:38.918 00:05:00.375 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-04 05:22:30.735 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:22:30.657 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:22:30.788 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:22:30.794 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:22:30.870 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:22:22.167 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:46808 10 6452 1 2025-10-04 05:23:22.563 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:55550 10 6452 1 2025-10-04 05:19:38.915 00:05:00.380 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-04 05:24:22.978 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:37834 10 6452 1 2025-10-04 05:25:23.387 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:59516 10 6452 1 2025-10-04 05:26:23.788 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:36418 10 6452 1 2025-10-04 05:27:30.906 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:27:30.571 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:27:30.823 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:27:30.890 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:27:24.191 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:52194 10 6452 1 2025-10-04 05:27:31.051 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:23:38.920 00:05:00.375 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-04 05:28:24.592 00:00:10.334 TCP 1.101.0.1:3000 -> 23.104.0.1:59240 10 6452 1 2025-10-04 05:29:24.973 00:00:10.338 TCP 1.101.0.1:3000 -> 23.104.0.1:54478 10 6452 1 2025-10-04 05:25:38.917 00:05:00.380 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-04 05:30:25.350 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:45146 10 6452 1 2025-10-04 05:31:25.748 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:57724 10 6452 1 2025-10-04 05:32:30.861 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:32:30.914 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:32:31.110 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:32:31.078 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:32:31.161 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:32:26.150 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40042 10 6452 1 2025-10-04 05:33:26.554 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:41188 10 6452 1 2025-10-04 05:29:38.921 00:05:00.375 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-04 05:34:26.954 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:55618 10 6452 1 2025-10-04 05:35:27.356 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:42898 10 6452 1 2025-10-04 05:31:38.920 00:05:00.379 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-04 05:36:27.759 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:50790 10 6452 1 2025-10-04 05:37:30.915 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:37:31.070 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:37:31.069 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:37:31.184 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:37:31.152 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:37:28.132 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37182 10 6452 1 2025-10-04 05:38:28.541 00:00:10.471 TCP 1.101.0.1:3000 -> 23.104.0.1:40958 12 10369 1 2025-10-04 05:39:29.090 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:34578 10 6452 1 2025-10-04 05:35:38.923 00:05:00.374 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-04 05:40:29.495 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:59838 10 6452 1 2025-10-04 05:37:38.921 00:05:00.379 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-04 05:41:29.860 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:55294 10 6452 1 2025-10-04 05:42:31.453 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:42:31.271 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:42:31.159 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:42:31.370 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:42:31.275 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:42:30.277 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54038 10 6452 1 2025-10-04 05:43:30.684 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58648 10 6452 1 2025-10-04 05:44:31.118 00:00:10.396 TCP 1.101.0.1:3000 -> 23.104.0.1:54834 10 6452 1 2025-10-04 05:41:38.924 00:05:00.375 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-04 05:45:31.557 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:33534 10 6452 1 2025-10-04 05:46:31.916 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:60692 10 6452 1 2025-10-04 05:47:31.387 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:47:31.288 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:47:31.341 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:47:31.342 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:47:31.423 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:43:38.922 00:05:00.380 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-04 05:47:32.281 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:44984 10 6452 1 2025-10-04 05:48:32.685 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:57408 10 6452 1 2025-10-04 05:49:33.109 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:59260 10 6452 1 2025-10-04 05:50:33.526 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:40636 10 6452 1 2025-10-04 05:47:38.924 00:05:00.377 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-04 05:51:33.931 00:00:10.348 TCP 1.101.0.1:3000 -> 23.104.0.1:45652 10 6452 1 2025-10-04 05:52:31.538 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:52:31.448 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:52:31.292 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:52:31.455 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:52:31.450 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:52:34.315 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:35136 10 6452 1 2025-10-04 05:49:38.922 00:05:00.382 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-04 05:53:34.717 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:59556 10 6452 1 2025-10-04 05:54:35.123 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:41366 10 6452 1 2025-10-04 05:55:35.525 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:35396 10 6452 1 2025-10-04 05:56:35.934 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:60936 10 6452 1 2025-10-04 05:57:31.416 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-04 05:57:31.334 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-04 05:57:31.358 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:57:31.332 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-04 05:57:31.327 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-04 05:53:38.925 00:05:00.378 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-04 05:57:36.356 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:43272 10 6452 1 2025-10-04 05:58:36.755 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:55308 10 6452 1 Summary: total flows: 140, total bytes: 420917, total packets: 1022, avg bps: 888, avg pps: 0, avg bpp: 411 Time window: 2025-10-04 04:55:38 - 2025-10-04 05:58:47 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0028s User: 0.0014s Wall: 0.0039s flows/second: 35461.2 Runtime: 0.0040s