Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-25 01:59:29.634 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:40760 10 6452 1 2025-10-25 02:00:30.037 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:56506 10 6452 1 2025-10-25 01:55:49.564 00:06:00.232 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-25 02:01:30.441 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:36278 10 6452 1 2025-10-25 02:02:33.805 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:02:33.494 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:02:33.424 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:02:33.722 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:02:33.499 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:02:30.811 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:51106 10 6452 1 2025-10-25 02:03:31.230 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:53750 10 6452 1 2025-10-25 02:04:31.631 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41784 10 6452 1 2025-10-25 01:59:49.568 00:06:00.231 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-25 02:05:32.033 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:50722 10 6452 1 2025-10-25 02:06:32.443 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36388 10 6452 1 2025-10-25 02:07:33.686 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:07:33.336 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:07:33.783 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:07:33.738 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:07:33.866 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:07:32.844 00:00:10.344 TCP 1.101.0.1:3000 -> 23.104.0.1:35334 10 6452 1 2025-10-25 02:02:49.565 00:06:00.233 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-25 02:08:33.232 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:38700 10 6452 1 2025-10-25 02:09:33.650 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:34392 10 6452 1 2025-10-25 02:10:34.054 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:54052 10 6452 1 2025-10-25 02:11:34.458 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:41064 10 6452 1 2025-10-25 02:06:49.568 00:06:00.228 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-25 02:12:33.937 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:12:33.657 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:12:33.851 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:12:33.975 00:00:00.025 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:12:33.934 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:12:34.858 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:54306 10 6452 1 2025-10-25 02:13:35.273 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:53002 10 6452 1 2025-10-25 02:14:35.692 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:57218 10 6452 1 2025-10-25 02:09:49.568 00:06:00.231 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-25 02:15:36.062 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:60032 10 6452 1 2025-10-25 02:16:36.459 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:57664 10 6452 1 2025-10-25 02:17:33.694 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:17:33.825 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:17:33.862 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:17:33.872 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:17:33.946 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:17:36.820 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:41932 10 6452 1 2025-10-25 02:18:37.189 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37122 10 6452 1 2025-10-25 02:13:49.571 00:06:00.227 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-25 02:19:37.591 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:48992 10 6452 1 2025-10-25 02:20:37.947 00:00:11.564 TCP 1.101.0.1:3000 -> 23.104.0.1:45108 10 6452 1 2025-10-25 02:16:49.568 00:06:00.234 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-25 02:21:39.549 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:39492 10 6452 1 2025-10-25 02:22:33.970 00:00:00.031 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:22:33.978 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:22:34.221 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:22:33.888 00:00:00.030 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:22:34.185 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:22:39.946 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:43776 10 6452 1 2025-10-25 02:23:40.357 00:00:11.303 TCP 1.101.0.1:3000 -> 23.104.0.1:39370 11 6504 1 2025-10-25 02:24:41.703 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:33276 10 6452 1 2025-10-25 02:20:49.576 00:06:00.224 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-25 02:25:42.115 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:32842 10 6452 1 2025-10-25 02:26:42.518 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:58272 10 6452 1 2025-10-25 02:27:34.198 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:27:34.118 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:27:34.202 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:27:34.115 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:27:34.171 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:27:42.920 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:48772 10 6452 1 2025-10-25 02:23:49.571 00:06:00.231 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-25 02:28:43.334 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:56000 10 6452 1 2025-10-25 02:29:43.736 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:41280 10 6452 1 2025-10-25 02:30:44.139 00:00:10.340 TCP 1.101.0.1:3000 -> 23.104.0.1:37584 10 6452 1 2025-10-25 02:31:44.531 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:35780 10 6452 1 2025-10-25 02:32:34.224 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:32:34.002 00:00:00.038 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:32:34.144 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:32:34.329 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:32:34.226 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:27:49.574 00:06:00.227 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-25 02:32:44.935 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:57174 10 6452 1 2025-10-25 02:33:45.309 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:48740 10 6452 1 2025-10-25 02:34:45.736 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:47848 10 6452 1 2025-10-25 02:30:49.572 00:06:00.233 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-25 02:35:46.108 00:00:10.931 TCP 1.101.0.1:3000 -> 23.104.0.1:33540 10 6452 1 2025-10-25 02:36:47.094 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46944 10 6452 1 2025-10-25 02:37:34.450 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:37:34.368 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:37:34.061 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:37:34.368 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:37:34.243 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:37:47.498 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:34488 10 6452 1 2025-10-25 02:38:47.864 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:54922 10 6452 1 2025-10-25 02:34:49.578 00:06:00.224 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-25 02:39:48.273 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:49310 10 6452 1 2025-10-25 02:40:48.672 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58068 10 6452 1 2025-10-25 02:41:49.105 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54294 10 6452 1 2025-10-25 02:42:34.491 00:00:00.027 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:42:34.419 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:42:34.495 00:00:00.045 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:42:34.205 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:42:34.584 00:00:00.040 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:37:49.576 00:06:00.230 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-25 02:42:49.511 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:53412 10 6452 1 2025-10-25 02:43:49.927 00:00:10.391 TCP 1.101.0.1:3000 -> 23.104.0.1:39940 10 6452 1 2025-10-25 02:44:50.360 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58936 10 6452 1 2025-10-25 02:45:50.763 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:53378 10 6452 1 2025-10-25 02:41:49.578 00:06:00.228 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-25 02:46:51.185 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58900 10 6452 1 2025-10-25 02:47:34.673 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:47:34.337 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:47:34.586 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:47:34.528 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:47:34.671 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:47:51.588 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:47816 10 6452 1 2025-10-25 02:48:51.995 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:51442 10 6452 1 2025-10-25 02:44:49.579 00:06:00.230 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-25 02:49:52.360 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:38376 10 6452 1 2025-10-25 02:50:52.719 00:00:10.441 TCP 1.101.0.1:3000 -> 23.104.0.1:33494 12 10369 1 2025-10-25 02:51:53.201 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:43258 10 6452 1 2025-10-25 02:52:34.766 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:52:34.518 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:52:34.725 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:52:34.684 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:52:34.516 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:52:53.607 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:55162 10 6452 1 2025-10-25 02:48:49.582 00:06:00.226 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-25 02:53:54.010 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:59922 10 6452 1 2025-10-25 02:54:54.409 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59678 10 6452 1 2025-10-25 02:55:54.821 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40002 10 6452 1 2025-10-25 02:51:49.580 00:06:00.231 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-25 02:56:55.230 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:38156 10 6452 1 2025-10-25 02:57:34.663 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:57:34.644 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 02:57:34.845 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 02:57:34.716 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 02:57:34.725 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 02:57:55.594 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:57944 10 6452 1 Summary: total flows: 136, total bytes: 414394, total packets: 1011, avg bps: 887, avg pps: 0, avg bpp: 409 Time window: 2025-10-25 01:55:49 - 2025-10-25 02:58:05 Total flows processed: 136, passed: 136, Blocks skipped: 0, Bytes read: 14208 Sys: 0.0060s User: 0.0000s Wall: 0.0022s flows/second: 60690.0 Runtime: 0.0023s