Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-04 01:59:23.718 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:59862 10 6452 1 2025-11-04 02:00:24.103 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:60786 10 6452 1 2025-11-04 01:56:54.822 00:05:00.396 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-04 02:01:24.504 00:00:10.601 TCP 1.101.0.1:3000 -> 23.104.0.1:35500 10 6452 1 2025-11-04 02:02:22.516 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:02:22.186 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:02:22.689 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:02:22.392 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:02:22.772 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:02:25.143 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:53544 10 6452 1 2025-11-04 01:58:54.824 00:05:00.392 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-04 02:03:25.512 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:49872 10 6452 1 2025-11-04 02:04:25.885 00:00:10.399 TCP 1.101.0.1:3000 -> 23.104.0.1:49396 12 6556 1 2025-11-04 02:05:26.316 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:42424 10 6452 1 2025-11-04 02:06:26.681 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:44856 12 10375 1 2025-11-04 02:02:54.830 00:05:00.391 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-04 02:07:22.522 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:07:22.329 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:07:22.441 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:07:22.371 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:07:22.366 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:07:27.154 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:40442 10 6452 1 2025-11-04 02:08:27.568 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:45992 10 6452 1 2025-11-04 02:04:54.825 00:05:00.394 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-04 02:09:27.930 00:00:10.395 TCP 1.101.0.1:3000 -> 23.104.0.1:33696 10 6452 1 2025-11-04 02:10:28.361 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:44550 10 6452 1 2025-11-04 02:11:28.763 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:59520 10 6452 1 2025-11-04 02:12:23.336 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:12:23.227 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:12:22.691 00:00:00.025 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:12:23.254 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:12:23.259 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:12:29.188 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:48228 10 6452 1 2025-11-04 02:08:54.825 00:05:00.398 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-04 02:13:29.592 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:59312 10 6452 1 2025-11-04 02:14:30.010 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:54968 10 6452 1 2025-11-04 02:10:54.829 00:05:00.393 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-04 02:15:30.415 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:35626 10 6452 1 2025-11-04 02:16:30.824 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:47024 10 6452 1 2025-11-04 02:17:22.726 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:17:22.528 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:17:22.592 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:17:22.505 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:17:22.675 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:17:31.185 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:56872 10 6452 1 2025-11-04 02:18:31.594 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:33636 10 6452 1 2025-11-04 02:14:54.826 00:05:00.397 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-04 02:19:32.036 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:57078 10 6452 1 2025-11-04 02:20:32.438 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:53738 10 6452 1 2025-11-04 02:16:54.829 00:05:00.392 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-04 02:21:32.843 00:00:10.348 TCP 1.101.0.1:3000 -> 23.104.0.1:37288 10 6452 1 2025-11-04 02:22:22.789 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:22:22.731 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:22:22.831 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:22:22.729 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:22:22.914 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:22:33.228 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37304 10 6452 1 2025-11-04 02:23:33.632 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:47828 10 6452 1 2025-11-04 02:24:34.034 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:41180 10 6452 1 2025-11-04 02:20:54.829 00:05:00.396 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-04 02:25:34.440 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53388 10 6452 1 2025-11-04 02:26:34.845 00:00:10.392 TCP 1.101.0.1:3000 -> 23.104.0.1:37310 10 6452 1 2025-11-04 02:22:54.833 00:05:00.389 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-04 02:27:22.985 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:27:22.904 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:27:22.810 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:27:22.903 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:27:22.913 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:27:35.274 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:37958 10 6452 1 2025-11-04 02:28:35.635 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:54594 10 6452 1 2025-11-04 02:29:36.053 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:35068 10 6452 1 2025-11-04 02:30:36.457 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:59290 10 6452 1 2025-11-04 02:26:54.831 00:05:00.395 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-04 02:31:36.822 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:37610 10 6452 1 2025-11-04 02:32:23.104 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:32:23.103 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:32:23.168 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:32:23.044 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:32:23.186 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:32:37.231 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:60366 10 6452 1 2025-11-04 02:28:54.834 00:05:00.389 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-04 02:33:37.634 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:47684 10 6452 1 2025-11-04 02:34:38.035 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:35770 10 6452 1 2025-11-04 02:35:38.434 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:42190 10 6452 1 2025-11-04 02:36:38.841 00:00:10.351 TCP 1.101.0.1:3000 -> 23.104.0.1:58204 10 6452 1 2025-11-04 02:32:54.832 00:05:00.395 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-04 02:37:23.095 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:37:22.923 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:37:23.098 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:37:22.901 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:37:23.181 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:37:39.224 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40064 10 6452 1 2025-11-04 02:38:39.628 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:44204 10 6452 1 2025-11-04 02:34:54.837 00:05:00.389 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-04 02:39:39.994 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:58612 10 6452 1 2025-11-04 02:40:40.399 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36794 10 6452 1 2025-11-04 02:41:40.806 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54604 10 6452 1 2025-11-04 02:42:23.100 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:42:22.974 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:42:23.107 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:42:23.101 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:42:23.192 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:42:41.213 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39008 10 6452 1 2025-11-04 02:38:54.834 00:05:00.395 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-04 02:43:41.612 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:42772 10 6452 1 2025-11-04 02:44:41.976 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:35224 10 6452 1 2025-11-04 02:40:54.837 00:05:00.391 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-04 02:45:42.387 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59506 10 6452 1 2025-11-04 02:46:42.789 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:54404 10 6452 1 2025-11-04 02:47:23.340 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:47:23.207 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:47:23.078 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:47:23.254 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:47:23.298 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:47:43.200 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:54290 10 6452 1 2025-11-04 02:44:54.836 00:05:00.395 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-04 02:48:43.642 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:51396 10 6452 1 2025-11-04 02:49:44.066 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:46968 10 6452 1 2025-11-04 02:50:44.474 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:35642 10 6452 1 2025-11-04 02:46:54.841 00:05:00.389 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-04 02:51:44.881 00:00:10.347 TCP 1.101.0.1:3000 -> 23.104.0.1:40386 10 6452 1 2025-11-04 02:52:23.235 00:00:00.043 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:52:22.989 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:52:23.235 00:00:00.027 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:52:23.795 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:52:23.319 00:00:00.026 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:52:45.269 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:42342 10 6452 1 2025-11-04 02:53:45.671 00:00:10.898 TCP 1.101.0.1:3000 -> 23.104.0.1:51426 10 6452 1 2025-11-04 02:50:54.839 00:05:00.393 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-04 02:54:46.609 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47718 10 6452 1 2025-11-04 02:55:47.015 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:60066 10 6452 1 2025-11-04 02:52:54.839 00:05:00.392 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-04 02:56:47.415 00:00:25.041 TCP 1.101.0.1:3000 -> 23.104.0.1:34642 10 6452 1 2025-11-04 02:57:23.505 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-04 02:57:23.608 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-04 02:57:23.421 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:57:23.423 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-04 02:57:23.433 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-04 02:58:02.547 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47838 10 6452 1 Summary: total flows: 139, total bytes: 414575, total packets: 1014, avg bps: 901, avg pps: 0, avg bpp: 408 Time window: 2025-11-04 01:56:54 - 2025-11-04 02:58:12 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0037s User: 0.0009s Wall: 0.0020s flows/second: 70420.1 Runtime: 0.0020s