Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-25 14:59:27.003 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:50656 10 6870 1 2025-10-25 15:00:27.405 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:53226 10 6870 1 2025-10-25 15:01:27.819 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:49900 10 6870 1 2025-10-25 14:57:49.866 00:05:00.283 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-25 15:02:28.225 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:52058 10 6870 1 2025-10-25 14:58:49.862 00:05:00.288 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-25 15:02:49.229 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:02:49.272 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:02:49.179 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:02:49.147 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:02:49.270 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:03:28.637 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36046 10 6870 1 2025-10-25 15:04:29.042 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:43968 10 6870 1 2025-10-25 15:05:29.443 00:00:10.447 TCP 1.101.0.1:3000 -> 23.104.0.1:37310 12 10793 1 2025-10-25 15:06:29.930 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:46620 10 6870 1 2025-10-25 15:07:30.346 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:32938 10 6870 1 2025-10-25 15:07:49.515 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:07:49.467 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:07:49.366 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:07:49.519 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:03:49.867 00:05:00.284 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-25 15:07:49.449 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:08:30.752 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:35720 10 6870 1 2025-10-25 15:04:49.864 00:05:00.290 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-25 15:09:31.119 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56232 10 6870 1 2025-10-25 15:10:31.523 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:46312 10 6870 1 2025-10-25 15:11:31.931 00:00:10.347 TCP 1.101.0.1:3000 -> 23.104.0.1:54630 10 6870 1 2025-10-25 15:12:32.319 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:39894 10 6870 1 2025-10-25 15:12:49.527 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:12:49.554 00:00:00.020 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:12:49.462 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:12:49.529 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:12:49.549 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:13:32.727 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:49354 10 6870 1 2025-10-25 15:09:49.870 00:05:00.281 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-25 15:14:33.139 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:43830 10 6870 1 2025-10-25 15:10:49.868 00:05:00.285 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-25 15:15:33.542 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39672 10 6870 1 2025-10-25 15:16:33.947 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:37214 10 6870 1 2025-10-25 15:17:34.367 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:56494 10 6870 1 2025-10-25 15:17:49.398 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:17:49.497 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:17:49.601 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:17:49.593 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:17:49.685 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:18:34.769 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:47538 10 6870 1 2025-10-25 15:19:35.183 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:38266 10 6870 1 2025-10-25 15:15:49.875 00:05:00.278 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-25 15:20:35.587 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:38494 10 6870 1 2025-10-25 15:16:49.873 00:05:00.282 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-25 15:21:35.993 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52468 10 6870 1 2025-10-25 15:22:49.722 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:22:36.395 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:33922 10 6870 1 2025-10-25 15:22:49.644 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:22:49.575 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:22:49.639 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:22:49.825 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:23:36.755 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:58314 10 6870 1 2025-10-25 15:24:37.183 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:51440 10 6870 1 2025-10-25 15:25:37.587 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:34952 10 6870 1 2025-10-25 15:21:49.879 00:05:00.275 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-25 15:22:49.876 00:05:00.299 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-25 15:26:37.991 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:37612 10 6870 1 2025-10-25 15:27:49.666 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:27:49.826 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:27:49.617 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:27:49.583 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:27:49.679 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:27:38.393 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49756 10 6870 1 2025-10-25 15:28:38.797 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:37494 10 6870 1 2025-10-25 15:29:39.196 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:42652 10 6870 1 2025-10-25 15:30:39.606 00:00:10.751 TCP 1.101.0.1:3000 -> 23.104.0.1:43954 10 6870 1 2025-10-25 15:31:40.397 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:58192 10 6870 1 2025-10-25 15:27:49.885 00:05:00.270 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-25 15:28:49.882 00:05:00.279 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-25 15:32:49.870 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:32:49.864 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:32:49.896 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:32:49.787 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:32:49.669 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:32:40.773 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:43574 10 6870 1 2025-10-25 15:33:41.183 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:38390 10 6870 1 2025-10-25 15:34:41.592 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:34142 10 6870 1 2025-10-25 15:35:41.995 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54368 10 6870 1 2025-10-25 15:36:42.400 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46474 10 6870 1 2025-10-25 15:37:49.847 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:37:49.793 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:37:49.847 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:37:49.917 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:33:49.886 00:05:00.273 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-25 15:37:49.931 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:37:42.804 00:00:10.334 TCP 1.101.0.1:3000 -> 23.104.0.1:50258 10 6870 1 2025-10-25 15:34:49.884 00:05:00.279 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-25 15:38:43.178 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:42232 10 6870 1 2025-10-25 15:39:43.549 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:44830 10 6870 1 2025-10-25 15:40:43.949 00:00:10.446 TCP 1.101.0.1:3000 -> 23.104.0.1:35426 12 10369 1 2025-10-25 15:41:44.434 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:53336 10 6452 1 2025-10-25 15:42:49.928 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:42:50.104 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:42:49.602 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:42:49.847 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:42:50.007 00:00:00.034 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:42:44.797 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:51880 10 6452 1 2025-10-25 15:43:45.202 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:49226 10 6452 1 2025-10-25 15:39:49.888 00:05:00.280 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-25 15:40:49.886 00:05:00.285 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-25 15:44:45.597 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:56746 10 6452 1 2025-10-25 15:45:45.961 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:50718 10 6452 1 2025-10-25 15:46:46.376 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48962 10 6452 1 2025-10-25 15:47:50.333 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:47:50.347 00:00:00.025 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:47:50.206 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:47:50.203 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:47:50.289 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:47:46.782 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:60942 10 6452 1 2025-10-25 15:48:47.187 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:46800 10 6452 1 2025-10-25 15:45:49.891 00:05:00.277 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-25 15:49:47.592 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:42708 10 6452 1 2025-10-25 15:46:49.889 00:05:00.282 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-25 15:50:47.958 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:37052 10 6452 1 2025-10-25 15:51:48.373 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:59884 10 6452 1 2025-10-25 15:52:50.525 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:52:50.219 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:52:50.142 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:52:50.442 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:52:50.324 00:00:00.014 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:52:48.733 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:39186 10 6452 1 2025-10-25 15:53:49.147 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:39404 10 6452 1 2025-10-25 15:54:49.556 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:33218 10 6452 1 2025-10-25 15:51:49.895 00:05:00.274 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-10-25 15:55:49.956 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:47004 10 6452 1 2025-10-25 15:52:49.892 00:05:00.279 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-10-25 15:56:50.366 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:51642 10 6452 1 2025-10-25 15:57:50.499 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-25 15:57:50.291 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-25 15:57:50.054 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:57:50.416 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-25 15:57:50.372 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-25 15:57:50.726 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:36510 10 6452 1 Summary: total flows: 139, total bytes: 435526, total packets: 1014, avg bps: 964, avg pps: 0, avg bpp: 429 Time window: 2025-10-25 14:57:49 - 2025-10-25 15:58:01 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0042s User: 0.0017s Wall: 0.0019s flows/second: 74927.2 Runtime: 0.0019s