Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-02 10:54:53.976 00:05:00.368 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-02 10:59:38.229 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:35000 10 6452 1 2025-11-02 10:55:53.980 00:05:00.364 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-02 11:00:38.628 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:34310 10 6452 1 2025-11-02 11:01:35.517 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:01:35.112 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:01:35.202 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:01:35.449 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:01:35.284 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:01:39.031 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:55890 10 6452 1 2025-11-02 11:02:39.436 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:56252 10 6452 1 2025-11-02 11:03:39.798 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47016 10 6452 1 2025-11-02 11:04:40.204 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:40704 10 6452 1 2025-11-02 11:00:53.981 00:05:00.365 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-02 11:05:40.605 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:50884 10 6452 1 2025-11-02 11:01:53.982 00:05:00.362 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-02 11:06:35.689 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:06:35.694 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:06:35.312 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:06:35.608 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:06:35.524 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:06:41.009 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54698 10 6452 1 2025-11-02 11:07:41.413 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:44116 10 6452 1 2025-11-02 11:08:41.779 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:58736 10 6452 1 2025-11-02 11:09:42.144 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:50384 10 6452 1 2025-11-02 11:10:42.553 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:48698 10 6452 1 2025-11-02 11:06:53.981 00:05:00.367 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-02 11:11:35.791 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:11:35.712 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:11:35.400 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:11:35.708 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:11:35.902 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:07:53.985 00:05:00.363 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-02 11:11:42.957 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:60230 10 6452 1 2025-11-02 11:12:43.367 00:00:16.412 TCP 1.101.0.1:3000 -> 23.104.0.1:58466 10 6452 1 2025-11-02 11:13:49.848 00:00:10.392 TCP 1.101.0.1:3000 -> 23.104.0.1:56946 10 6452 1 2025-11-02 11:14:50.276 00:00:10.490 TCP 1.101.0.1:3000 -> 23.104.0.1:56728 13 10427 1 2025-11-02 11:15:50.806 00:00:16.553 TCP 1.101.0.1:3000 -> 23.104.0.1:41612 10 6452 1 2025-11-02 11:16:35.954 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:16:35.949 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:16:36.082 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:16:36.090 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:16:36.164 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:12:53.982 00:05:00.368 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-02 11:16:57.412 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:55570 10 6452 1 2025-11-02 11:13:53.986 00:05:00.362 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-02 11:17:57.780 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:38404 10 6452 1 2025-11-02 11:18:58.144 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:32988 10 6452 1 2025-11-02 11:19:58.544 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:47590 10 6452 1 2025-11-02 11:20:58.957 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:44552 10 6452 1 2025-11-02 11:21:35.893 00:00:00.014 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:21:36.209 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:21:36.236 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:21:36.127 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:21:36.187 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:21:59.360 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:41036 10 6452 1 2025-11-02 11:18:53.983 00:05:00.368 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-02 11:22:59.762 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:47034 10 6452 1 2025-11-02 11:19:53.987 00:05:00.362 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-02 11:24:00.133 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:41092 10 6452 1 2025-11-02 11:25:00.498 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:46976 10 6452 1 2025-11-02 11:26:00.863 00:00:21.939 TCP 1.101.0.1:3000 -> 23.104.0.1:41622 10 6452 1 2025-11-02 11:26:35.966 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:26:35.805 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:26:35.562 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:26:35.883 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:26:35.807 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:27:12.842 00:00:10.338 TCP 1.101.0.1:3000 -> 23.104.0.1:33880 10 6452 1 2025-11-02 11:28:13.218 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:57614 10 6452 1 2025-11-02 11:24:53.985 00:05:00.366 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-02 11:29:13.622 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:34102 10 6452 1 2025-11-02 11:25:53.988 00:05:00.362 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-02 11:30:14.028 00:00:10.399 TCP 1.101.0.1:3000 -> 23.104.0.1:33300 12 10369 1 2025-11-02 11:31:14.470 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:38816 10 6452 1 2025-11-02 11:31:35.889 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:31:35.923 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:31:35.835 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:31:35.993 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:31:36.006 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:32:14.876 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:44118 10 6452 1 2025-11-02 11:33:15.283 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:51680 10 6452 1 2025-11-02 11:34:15.685 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:56734 10 6452 1 2025-11-02 11:30:53.989 00:05:00.362 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-02 11:35:16.064 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:43014 10 6452 1 2025-11-02 11:31:53.993 00:05:00.357 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-02 11:36:16.457 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:42504 10 6452 1 2025-11-02 11:36:35.982 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:36:36.103 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:36:36.096 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:36:35.993 00:00:00.047 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:36:36.181 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:37:16.864 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:49060 10 6452 1 2025-11-02 11:38:17.283 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33672 10 6452 1 2025-11-02 11:39:17.687 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:47618 10 6452 1 2025-11-02 11:40:18.113 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:56186 10 6452 1 2025-11-02 11:36:53.991 00:05:00.362 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-02 11:41:18.515 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:53162 10 6452 1 2025-11-02 11:41:36.689 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:41:36.603 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:41:36.468 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:41:36.606 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:41:36.691 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:37:53.995 00:05:00.356 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-02 11:42:18.918 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:57360 10 6452 1 2025-11-02 11:43:19.282 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:38240 10 6452 1 2025-11-02 11:44:19.685 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51576 10 6452 1 2025-11-02 11:45:20.114 00:00:11.126 TCP 1.101.0.1:3000 -> 23.104.0.1:47882 10 6452 1 2025-11-02 11:46:36.309 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:46:21.277 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:38812 10 6452 1 2025-11-02 11:46:36.293 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:46:36.044 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:46:36.226 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:46:36.358 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:42:53.992 00:05:00.362 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-02 11:47:21.652 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:44116 10 6452 1 2025-11-02 11:43:53.995 00:05:00.358 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-02 11:48:22.070 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:36694 10 6452 1 2025-11-02 11:49:22.473 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:38828 10 6452 1 2025-11-02 11:50:22.876 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41140 10 6452 1 2025-11-02 11:51:23.276 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:40478 10 6452 1 2025-11-02 11:51:36.724 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:51:36.582 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:51:36.670 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:51:36.621 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:51:36.754 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:52:23.642 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:52734 10 6452 1 2025-11-02 11:48:53.993 00:05:00.364 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-02 11:53:24.058 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:52970 10 6452 1 2025-11-02 11:49:53.995 00:05:00.359 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-02 11:54:24.427 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:33768 10 6452 1 2025-11-02 11:55:24.830 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37914 10 6452 1 2025-11-02 11:56:25.234 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:35946 10 6452 1 2025-11-02 11:56:36.633 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-02 11:56:36.643 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-02 11:56:36.553 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:56:36.550 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-02 11:56:36.552 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-02 11:57:25.634 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:35074 10 6452 1 2025-11-02 11:58:26.038 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:42510 10 6452 1 Summary: total flows: 139, total bytes: 418440, total packets: 1015, avg bps: 875, avg pps: 0, avg bpp: 412 Time window: 2025-11-02 10:54:53 - 2025-11-02 11:58:36 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0029s User: 0.0019s Wall: 0.0023s flows/second: 59248.8 Runtime: 0.0024s