Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-30 11:53:52.273 00:06:00.407 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 11:59:06.568 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:54192 10 6452 1 2025-10-30 11:54:52.270 00:06:00.412 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 12:00:09.950 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:00:09.871 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:00:09.547 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:00:09.868 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:00:09.876 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:00:06.970 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:45202 10 6452 1 2025-10-30 12:01:07.344 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:58296 10 6452 1 2025-10-30 12:02:07.741 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:50704 10 6452 1 2025-10-30 12:03:08.145 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56782 10 6452 1 2025-10-30 12:04:08.547 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:55458 10 6452 1 2025-10-30 12:05:10.170 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:05:10.179 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:05:09.867 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:05:10.087 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:05:09.994 00:00:00.048 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:05:08.945 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:49740 10 6452 1 2025-10-30 12:00:52.278 00:06:00.405 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 12:06:09.354 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:47138 10 6452 1 2025-10-30 12:01:52.275 00:06:00.408 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 12:07:09.760 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:58414 10 6452 1 2025-10-30 12:08:10.170 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:49718 10 6452 1 2025-10-30 12:09:10.530 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:45756 10 6452 1 2025-10-30 12:10:10.434 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:10:10.094 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:10:09.824 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:10:10.351 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:10:10.352 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:10:10.893 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:48714 10 6452 1 2025-10-30 12:11:11.305 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:45578 10 6452 1 2025-10-30 12:12:11.724 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:51172 10 6452 1 2025-10-30 12:07:52.280 00:06:00.402 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 12:13:12.137 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:46892 10 6452 1 2025-10-30 12:08:52.278 00:06:00.408 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 12:14:12.501 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:46350 10 6452 1 2025-10-30 12:15:10.373 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:15:10.218 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:15:10.136 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:15:10.291 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:15:09.875 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:15:12.923 00:00:10.391 TCP 1.101.0.1:3000 -> 23.104.0.1:41876 10 6452 1 2025-10-30 12:16:13.362 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:43052 10 6452 1 2025-10-30 12:17:13.752 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:46534 10 6452 1 2025-10-30 12:18:14.159 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:56918 10 6452 1 2025-10-30 12:19:14.562 00:00:22.990 TCP 1.101.0.1:3000 -> 23.104.0.1:48574 10 6452 1 2025-10-30 12:14:52.283 00:06:00.401 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 12:20:10.199 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:20:10.223 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:20:09.898 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:20:10.117 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:20:10.344 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:20:27.615 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:37564 10 6452 1 2025-10-30 12:15:52.282 00:06:00.406 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 12:21:28.015 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:42938 10 6452 1 2025-10-30 12:22:28.378 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:51228 10 6452 1 2025-10-30 12:23:28.735 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:57900 10 6452 1 2025-10-30 12:24:29.142 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:48736 10 6452 1 2025-10-30 12:25:10.623 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:25:10.674 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:25:10.477 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:25:10.541 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:25:10.442 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:25:29.505 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:42182 10 6452 1 2025-10-30 12:26:29.908 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:60604 12 6556 1 2025-10-30 12:21:52.285 00:06:00.401 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 12:27:30.316 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49268 10 6452 1 2025-10-30 12:22:52.283 00:06:00.406 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 12:28:30.720 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:45440 10 6452 1 2025-10-30 12:29:31.132 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:34764 10 6452 1 2025-10-30 12:30:10.582 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:30:10.415 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:30:10.541 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:30:10.548 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:30:10.624 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:30:31.529 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47062 10 6452 1 2025-10-30 12:31:31.934 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:38406 10 6452 1 2025-10-30 12:32:32.348 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:48628 10 6452 1 2025-10-30 12:33:32.756 00:00:10.391 TCP 1.101.0.1:3000 -> 23.104.0.1:41382 10 6452 1 2025-10-30 12:28:52.285 00:06:00.401 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 12:34:33.200 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:60646 10 6452 1 2025-10-30 12:29:52.283 00:06:00.407 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 12:35:10.326 00:00:00.025 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:35:10.634 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:35:10.541 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:35:10.585 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:35:10.668 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:35:33.612 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:53292 10 6452 1 2025-10-30 12:36:34.020 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:42628 10 6452 1 2025-10-30 12:37:34.388 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40858 10 6452 1 2025-10-30 12:38:34.793 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:37154 12 6556 1 2025-10-30 12:39:35.208 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:55836 10 6452 1 2025-10-30 12:40:10.411 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:40:10.255 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:40:10.353 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:40:10.384 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:40:10.436 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:40:35.615 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:42704 10 6452 1 2025-10-30 12:35:52.287 00:06:00.402 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 12:41:35.976 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50190 10 6452 1 2025-10-30 12:36:52.285 00:06:00.407 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 12:42:36.388 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:33212 10 6452 1 2025-10-30 12:43:36.786 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:50620 10 6452 1 2025-10-30 12:44:37.194 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:34104 10 6452 1 2025-10-30 12:45:10.743 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:45:10.731 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:45:10.644 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:45:10.902 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:45:10.727 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:45:37.593 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:44992 10 6452 1 2025-10-30 12:46:38.003 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:36374 10 6452 1 2025-10-30 12:47:38.400 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:43154 10 6452 1 2025-10-30 12:42:52.289 00:06:00.403 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 12:48:38.803 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54624 10 6452 1 2025-10-30 12:43:52.289 00:06:00.404 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 12:49:39.211 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:59576 10 6452 1 2025-10-30 12:50:10.923 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:50:10.892 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:50:10.631 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:50:10.840 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:50:10.922 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:50:39.611 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39080 10 6452 1 2025-10-30 12:51:40.011 00:00:10.356 TCP 1.101.0.1:3000 -> 23.104.0.1:34156 10 6452 1 2025-10-30 12:52:40.405 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59320 10 6452 1 2025-10-30 12:53:40.804 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:54686 10 6452 1 2025-10-30 12:54:41.210 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:35884 10 6452 1 2025-10-30 12:49:52.294 00:06:00.399 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-10-30 12:55:10.802 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:55:10.970 00:00:00.025 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-10-30 12:55:10.970 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-10-30 12:55:11.052 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-10-30 12:55:11.117 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-10-30 12:50:52.291 00:06:00.403 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-10-30 12:55:41.572 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:43366 10 6452 1 2025-10-30 12:56:41.974 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:33532 10 6452 1 2025-10-30 12:57:42.386 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:49014 12 6556 1 Summary: total flows: 137, total bytes: 411598, total packets: 1028, avg bps: 857, avg pps: 0, avg bpp: 400 Time window: 2025-10-30 11:53:52 - 2025-10-30 12:57:52 Total flows processed: 137, passed: 137, Blocks skipped: 0, Bytes read: 14312 Sys: 0.0027s User: 0.0018s Wall: 0.0023s flows/second: 58724.5 Runtime: 0.0023s