Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-26 12:59:10.518 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39414 10 6452 1 2025-10-26 13:00:10.924 00:00:10.347 TCP 1.101.0.1:3000 -> 23.104.0.1:53032 10 6452 1 2025-10-26 12:59:50.394 00:01:00.225 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 12:59:50.396 00:01:00.220 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:01:11.321 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:47894 10 6452 1 2025-10-26 13:02:11.736 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:50320 10 6452 1 2025-10-26 13:03:15.778 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:03:15.742 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:03:15.521 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:03:15.695 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:03:15.743 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:03:12.113 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:53508 10 6452 1 2025-10-26 13:01:50.394 00:02:00.242 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-10-26 13:01:50.396 00:02:00.237 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-10-26 13:04:12.473 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:59528 10 6452 1 2025-10-26 13:05:12.877 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36728 10 6452 1 2025-10-26 13:04:50.396 00:01:00.221 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:04:50.394 00:01:00.225 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:06:13.282 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:55798 10 6452 1 2025-10-26 13:07:13.683 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:40676 10 6452 1 2025-10-26 13:06:50.395 00:01:00.224 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:08:15.753 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:08:15.671 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:08:15.836 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:08:15.671 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:08:15.752 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:08:14.065 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:51696 10 6452 1 2025-10-26 13:06:50.399 00:02:00.220 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-10-26 13:09:14.478 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:56724 10 6452 1 2025-10-26 13:10:14.883 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:41034 10 6452 1 2025-10-26 13:08:50.396 00:02:00.224 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-10-26 13:09:50.399 00:01:00.219 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:11:15.289 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50328 10 6452 1 2025-10-26 13:12:15.702 00:00:10.417 TCP 1.101.0.1:3000 -> 23.104.0.1:50670 11 6504 1 2025-10-26 13:11:50.397 00:01:00.224 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:13:15.964 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:13:15.878 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:13:15.881 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:13:15.883 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:13:15.813 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:13:16.158 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:40738 10 6452 1 2025-10-26 13:11:50.399 00:02:00.220 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-10-26 13:14:16.555 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:36984 10 6452 1 2025-10-26 13:15:16.953 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:51266 10 6452 1 2025-10-26 13:13:50.398 00:02:00.224 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-10-26 13:14:50.400 00:01:00.219 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:16:17.361 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44576 10 6452 1 2025-10-26 13:17:17.764 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:55654 10 6452 1 2025-10-26 13:16:50.399 00:01:00.222 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:16:50.401 00:01:00.217 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:18:15.935 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:18:16.269 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:18:16.122 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:18:16.125 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:18:16.206 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:18:18.139 00:00:10.422 TCP 1.101.0.1:3000 -> 23.104.0.1:55028 11 6504 1 2025-10-26 13:19:18.603 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:35156 10 6452 1 2025-10-26 13:20:19.025 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:60800 10 6452 1 2025-10-26 13:18:50.401 00:02:00.219 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-10-26 13:18:50.399 00:02:00.223 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-10-26 13:21:19.427 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:38258 10 6452 1 2025-10-26 13:22:19.827 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:45940 10 6452 1 2025-10-26 13:21:50.401 00:01:00.222 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:21:50.403 00:01:00.217 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:23:15.724 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:23:15.927 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:23:15.928 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:23:15.926 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:23:16.012 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:23:20.190 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:58128 10 6452 1 2025-10-26 13:24:20.592 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:60744 10 6452 1 2025-10-26 13:25:20.961 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:34684 10 6452 1 2025-10-26 13:23:50.407 00:02:00.213 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-10-26 13:23:50.404 00:02:00.218 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-10-26 13:26:21.329 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:41956 10 6452 1 2025-10-26 13:27:21.736 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:59062 10 6452 1 2025-10-26 13:26:50.409 00:01:00.215 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:26:50.406 00:01:00.220 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:28:16.061 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:28:16.151 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:28:16.060 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:28:16.186 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:28:16.142 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:28:22.149 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:57754 10 6452 1 2025-10-26 13:29:22.553 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:45900 10 6452 1 2025-10-26 13:30:22.955 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:33980 10 6452 1 2025-10-26 13:28:50.407 00:02:00.220 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-10-26 13:28:50.411 00:02:00.215 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-10-26 13:31:23.357 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:49976 10 6452 1 2025-10-26 13:32:23.766 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:39584 10 6452 1 2025-10-26 13:31:50.410 00:01:00.215 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:31:50.410 00:01:00.220 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:33:16.450 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:33:16.089 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:33:16.419 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:33:16.347 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:33:16.501 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:33:24.182 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54320 10 6452 1 2025-10-26 13:34:24.583 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:38238 10 6452 1 2025-10-26 13:35:24.984 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:34188 10 6452 1 2025-10-26 13:33:50.408 00:02:00.220 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-10-26 13:33:50.413 00:02:00.215 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-10-26 13:36:25.353 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:59474 10 6452 1 2025-10-26 13:37:25.763 00:00:10.392 TCP 1.101.0.1:3000 -> 23.104.0.1:46022 10 6452 1 2025-10-26 13:36:50.411 00:01:00.219 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:36:50.414 00:01:00.214 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:38:16.476 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:38:16.329 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:38:16.208 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:38:16.394 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:38:16.337 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:38:26.215 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:52382 10 6452 1 2025-10-26 13:39:26.617 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:47380 10 6452 1 2025-10-26 13:38:50.411 00:01:00.219 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:40:26.984 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:55668 10 6452 1 2025-10-26 13:38:50.414 00:02:00.214 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-10-26 13:40:50.411 00:00:00.218 TCP 179.21.23.23:179 -> 179.21.23.21:38570 2 123 1 2025-10-26 13:41:27.439 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:41782 10 6452 1 2025-10-26 13:42:27.795 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:53880 10 6452 1 2025-10-26 13:41:50.412 00:01:00.219 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:41:50.415 00:01:00.214 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:43:16.591 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:43:16.396 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:43:16.419 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:43:16.508 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:43:16.463 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:43:28.200 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:48944 10 6452 1 2025-10-26 13:44:28.687 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:52436 10 6452 1 2025-10-26 13:43:50.412 00:01:00.218 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:45:29.109 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37410 10 6452 1 2025-10-26 13:43:50.414 00:02:00.214 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-10-26 13:46:29.514 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:59312 10 6452 1 2025-10-26 13:47:29.912 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:56346 10 6452 1 2025-10-26 13:46:50.415 00:01:00.213 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:45:50.412 00:02:00.219 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-10-26 13:48:16.550 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:48:16.583 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:48:16.330 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:48:16.332 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:48:16.414 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:48:30.280 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59744 10 6452 1 2025-10-26 13:48:50.413 00:01:00.219 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:49:30.686 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:39186 10 6452 1 2025-10-26 13:48:50.415 00:01:00.214 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:50:31.104 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53964 10 6452 1 2025-10-26 13:50:50.415 00:00:00.214 TCP 179.21.23.21:38570 -> 179.21.23.23:179 2 123 1 2025-10-26 13:51:31.502 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:41426 10 6452 1 2025-10-26 13:52:31.918 00:00:10.354 TCP 1.101.0.1:3000 -> 23.104.0.1:51400 10 6452 1 2025-10-26 13:50:50.413 00:02:00.222 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-10-26 13:51:50.416 00:01:00.216 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:53:16.613 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:53:16.616 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:53:16.696 00:00:00.029 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:53:16.794 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:53:16.780 00:00:00.029 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:53:32.309 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:38902 10 6452 1 2025-10-26 13:54:32.712 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:50916 10 6452 1 2025-10-26 13:53:50.415 00:01:00.215 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-10-26 13:53:50.415 00:01:00.220 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-10-26 13:55:33.112 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:52702 10 6452 1 2025-10-26 13:56:33.517 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:56400 10 6452 1 2025-10-26 13:55:50.414 00:02:00.220 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-10-26 13:57:33.916 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46506 10 6452 1 2025-10-26 13:55:50.415 00:02:00.216 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-10-26 13:58:16.797 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-26 13:58:16.675 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:58:16.797 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-26 13:58:16.741 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-26 13:58:16.880 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-26 13:58:34.319 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59662 10 6452 1 Summary: total flows: 170, total bytes: 416858, total packets: 1018, avg bps: 933, avg pps: 0, avg bpp: 409 Time window: 2025-10-26 12:59:10 - 2025-10-26 13:58:44 Total flows processed: 170, passed: 170, Blocks skipped: 0, Bytes read: 17744 Sys: 0.0040s User: 0.0016s Wall: 0.0021s flows/second: 80605.0 Runtime: 0.0021s