Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-08 15:53:57.269 00:06:00.115 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 15:59:11.329 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:60140 10 6452 1 2025-11-08 15:59:34.501 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 15:59:34.566 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 15:59:34.501 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 15:59:34.557 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 15:59:34.584 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 15:54:57.268 00:06:00.120 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 16:00:11.723 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:41226 10 6452 1 2025-11-08 16:01:12.134 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:32950 10 6452 1 2025-11-08 16:02:12.543 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:57658 10 6452 1 2025-11-08 16:03:12.945 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:41238 10 6452 1 2025-11-08 16:04:13.366 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59764 10 6452 1 2025-11-08 16:04:34.625 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:04:34.453 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:04:34.625 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:04:34.620 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:04:34.709 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:05:13.768 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:41058 10 6452 1 2025-11-08 16:00:57.272 00:06:00.114 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 16:06:14.181 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:51430 10 6452 1 2025-11-08 16:01:57.270 00:06:00.119 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 16:07:14.591 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48830 10 6452 1 2025-11-08 16:08:14.993 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:44334 10 6452 1 2025-11-08 16:09:15.350 00:00:17.946 TCP 1.101.0.1:3000 -> 23.104.0.1:39766 10 6452 1 2025-11-08 16:09:34.723 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:09:34.642 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:09:34.815 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:09:34.816 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:09:34.898 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:10:23.337 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:49764 10 6452 1 2025-11-08 16:11:23.699 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:52284 10 6452 1 2025-11-08 16:12:24.107 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:34638 10 6452 1 2025-11-08 16:07:57.275 00:06:00.112 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 16:13:24.509 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:44196 10 6452 1 2025-11-08 16:08:57.273 00:06:00.117 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 16:14:34.923 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:14:24.917 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54644 10 6452 1 2025-11-08 16:14:34.922 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:14:34.804 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:14:34.840 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:14:34.849 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:15:25.320 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:43296 10 6452 1 2025-11-08 16:16:25.682 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56912 10 6452 1 2025-11-08 16:17:26.110 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:52758 10 6452 1 2025-11-08 16:18:26.519 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:55340 10 6452 1 2025-11-08 16:19:35.079 00:00:00.032 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:19:35.127 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:19:34.692 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:19:34.995 00:00:00.033 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:19:34.876 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:19:26.921 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:54438 10 6452 1 2025-11-08 16:14:57.276 00:06:00.112 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 16:20:27.283 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:48588 10 6452 1 2025-11-08 16:15:57.274 00:06:00.118 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 16:21:27.646 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:34964 10 6452 1 2025-11-08 16:22:28.011 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:57562 10 6452 1 2025-11-08 16:23:28.405 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:39158 10 6452 1 2025-11-08 16:24:35.160 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:24:35.078 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:24:35.119 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:24:35.062 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:24:35.202 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:24:28.809 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:35170 10 6452 1 2025-11-08 16:25:29.216 00:00:10.657 TCP 1.101.0.1:3000 -> 23.104.0.1:57008 10 6452 1 2025-11-08 16:26:29.910 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:51614 10 6452 1 2025-11-08 16:21:57.279 00:06:00.112 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 16:27:30.317 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:39188 12 10369 1 2025-11-08 16:22:57.276 00:06:00.117 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 16:28:30.791 00:00:10.348 TCP 1.101.0.1:3000 -> 23.104.0.1:55226 10 6452 1 2025-11-08 16:29:35.406 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:29:35.218 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:29:34.831 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:29:35.323 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:29:35.273 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:29:31.177 00:00:10.634 TCP 1.101.0.1:3000 -> 23.104.0.1:57322 10 6452 1 2025-11-08 16:30:31.857 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:40684 10 6452 1 2025-11-08 16:31:32.268 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:44496 10 6452 1 2025-11-08 16:32:32.670 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:34686 10 6452 1 2025-11-08 16:33:33.106 00:00:10.644 TCP 1.101.0.1:3000 -> 23.104.0.1:46140 10 6452 1 2025-11-08 16:28:57.282 00:06:00.110 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 16:34:35.614 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:34:35.225 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:34:35.614 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:34:34.951 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:34:35.698 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:34:33.805 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:56498 10 6452 1 2025-11-08 16:29:57.279 00:06:00.116 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 16:35:34.205 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:33974 10 6452 1 2025-11-08 16:36:34.625 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:53056 10 6452 1 2025-11-08 16:37:35.025 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:43122 12 6556 1 2025-11-08 16:38:35.429 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:41902 11 6504 1 2025-11-08 16:39:35.468 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:39:35.084 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:39:35.523 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:39:35.519 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:39:35.606 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:39:35.838 00:00:10.391 TCP 1.101.0.1:3000 -> 23.104.0.1:41672 10 6452 1 2025-11-08 16:40:36.271 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55492 10 6452 1 2025-11-08 16:35:57.280 00:06:00.113 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 16:41:36.675 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:60396 10 6452 1 2025-11-08 16:36:57.278 00:06:00.118 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 16:42:37.097 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:60714 10 6452 1 2025-11-08 16:43:37.493 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44278 10 6452 1 2025-11-08 16:44:35.538 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:44:35.347 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:44:35.546 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:44:35.455 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:44:35.536 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:44:37.901 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:39884 10 6452 1 2025-11-08 16:45:38.318 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:42170 10 6452 1 2025-11-08 16:46:38.722 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:46426 10 6452 1 2025-11-08 16:47:39.132 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35598 10 6452 1 2025-11-08 16:42:57.286 00:06:00.109 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 16:48:39.537 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:35864 10 6452 1 2025-11-08 16:43:57.282 00:06:00.115 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 16:49:36.561 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:49:36.433 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:49:36.270 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:49:36.300 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:49:36.353 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:49:39.946 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:59992 11 6492 1 2025-11-08 16:50:40.375 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:59980 10 6452 1 2025-11-08 16:51:40.751 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:52868 10 6452 1 2025-11-08 16:52:41.156 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:49004 10 6452 1 2025-11-08 16:53:41.584 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:34704 10 6452 1 2025-11-08 16:54:35.899 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:54:36.047 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 16:54:36.165 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 16:54:36.013 00:00:00.042 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 16:54:36.249 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 16:54:41.987 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:38666 10 6452 1 2025-11-08 16:49:57.293 00:06:00.105 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 16:55:42.354 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:44684 10 6452 1 2025-11-08 16:50:57.289 00:06:00.110 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 16:56:42.764 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:60564 10 6452 1 2025-11-08 16:57:43.174 00:00:10.435 TCP 1.101.0.1:3000 -> 23.104.0.1:48234 12 10375 1 Summary: total flows: 137, total bytes: 419322, total packets: 1030, avg bps: 874, avg pps: 0, avg bpp: 407 Time window: 2025-11-08 15:53:57 - 2025-11-08 16:57:53 Total flows processed: 137, passed: 137, Blocks skipped: 0, Bytes read: 14312 Sys: 0.0036s User: 0.0018s Wall: 0.0029s flows/second: 47158.0 Runtime: 0.0029s