Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-08 22:58:37.597 00:00:21.164 TCP 1.101.0.1:3000 -> 23.104.0.1:42280 10 6452 1 2025-11-08 22:53:57.420 00:06:00.095 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 22:59:42.973 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 22:59:42.912 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 22:59:42.880 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 22:59:43.130 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 22:59:42.962 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 22:59:48.816 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:40404 10 6452 1 2025-11-08 22:54:57.417 00:06:00.101 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 23:00:49.227 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:38630 10 6452 1 2025-11-08 23:01:49.590 00:00:11.218 TCP 1.101.0.1:3000 -> 23.104.0.1:46724 10 6452 1 2025-11-08 23:02:50.845 00:00:10.351 TCP 1.101.0.1:3000 -> 23.104.0.1:44764 10 6452 1 2025-11-08 23:03:51.233 00:00:10.357 TCP 1.101.0.1:3000 -> 23.104.0.1:41600 10 6452 1 2025-11-08 23:04:43.001 00:00:00.046 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:04:43.136 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:04:43.057 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:04:43.110 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:04:43.142 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:04:51.630 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37788 10 6452 1 2025-11-08 23:00:57.422 00:06:00.095 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 23:05:52.033 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:51670 10 6452 1 2025-11-08 23:01:57.418 00:06:00.100 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 23:06:52.433 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:46238 10 6452 1 2025-11-08 23:07:52.842 00:00:10.395 TCP 1.101.0.1:3000 -> 23.104.0.1:47506 10 6452 1 2025-11-08 23:08:53.275 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:53158 10 6452 1 2025-11-08 23:09:43.257 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:09:43.191 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:09:43.258 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:09:43.175 00:00:00.025 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:09:43.181 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:09:53.677 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:40108 10 6452 1 2025-11-08 23:10:54.040 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:37296 10 6452 1 2025-11-08 23:11:54.442 00:00:16.176 TCP 1.101.0.1:3000 -> 23.104.0.1:47414 10 6452 1 2025-11-08 23:07:57.423 00:06:00.093 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 23:13:00.659 00:00:10.440 TCP 1.101.0.1:3000 -> 23.104.0.1:37368 12 10375 1 2025-11-08 23:08:57.421 00:06:00.099 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 23:14:01.136 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:51418 10 6452 1 2025-11-08 23:14:43.461 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:14:43.664 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:14:43.723 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:14:43.809 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:14:43.805 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:15:01.539 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58998 10 6452 1 2025-11-08 23:16:01.943 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:51538 10 6452 1 2025-11-08 23:17:02.354 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37346 10 6452 1 2025-11-08 23:18:02.754 00:00:10.436 TCP 1.101.0.1:3000 -> 23.104.0.1:44536 12 10375 1 2025-11-08 23:19:03.228 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:48552 10 6452 1 2025-11-08 23:19:43.317 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:19:43.405 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:19:43.309 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:19:43.313 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:19:43.393 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:14:57.425 00:06:00.095 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 23:20:03.624 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:60712 10 6452 1 2025-11-08 23:15:57.423 00:06:00.099 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 23:21:04.034 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:55716 10 6452 1 2025-11-08 23:22:04.445 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:46484 10 6452 1 2025-11-08 23:23:04.847 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:55450 10 6452 1 2025-11-08 23:24:05.269 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:38536 10 6452 1 2025-11-08 23:24:43.602 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:24:43.405 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:24:43.501 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:24:43.500 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:24:43.584 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:25:05.630 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55026 10 6452 1 2025-11-08 23:26:06.036 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41030 10 6452 1 2025-11-08 23:21:57.430 00:06:00.096 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 23:27:06.442 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:55606 10 6452 1 2025-11-08 23:22:57.431 00:06:00.098 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 23:28:06.843 00:00:10.399 TCP 1.101.0.1:3000 -> 23.104.0.1:36038 10 6452 1 2025-11-08 23:29:07.332 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48388 10 6452 1 2025-11-08 23:29:44.130 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:29:43.888 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:29:44.127 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:29:44.090 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:29:44.209 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:30:07.738 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:32972 10 6452 1 2025-11-08 23:31:08.144 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:33540 10 6452 1 2025-11-08 23:32:08.541 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:57734 10 6452 1 2025-11-08 23:33:08.946 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:58238 10 6452 1 2025-11-08 23:28:57.431 00:06:00.098 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 23:34:09.353 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39768 10 6452 1 2025-11-08 23:34:43.652 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:34:43.517 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:34:43.788 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:34:43.653 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:34:43.871 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:29:57.429 00:06:00.103 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 23:35:09.750 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:60510 10 6452 1 2025-11-08 23:36:10.112 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:45750 10 6452 1 2025-11-08 23:37:10.510 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44288 10 6452 1 2025-11-08 23:38:10.910 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:53324 10 6452 1 2025-11-08 23:39:11.316 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:50398 10 6452 1 2025-11-08 23:39:43.800 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:39:43.608 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:39:43.649 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:39:43.717 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:39:43.894 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:40:11.715 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:37530 11 6492 1 2025-11-08 23:35:57.436 00:06:00.094 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 23:41:12.123 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:56994 10 6452 1 2025-11-08 23:36:57.433 00:06:00.100 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 23:42:12.487 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40930 10 6452 1 2025-11-08 23:43:12.890 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:55648 10 6452 1 2025-11-08 23:44:13.316 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:40162 10 6452 1 2025-11-08 23:44:43.861 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:44:43.703 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:44:43.745 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:44:43.778 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:44:43.787 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:45:13.677 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:57440 10 6452 1 2025-11-08 23:46:14.039 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:57806 10 6452 1 2025-11-08 23:47:14.446 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35504 10 6452 1 2025-11-08 23:42:57.439 00:06:00.092 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 23:48:14.863 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:43646 10 6452 1 2025-11-08 23:43:57.438 00:06:00.095 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 23:49:15.289 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:57224 10 6452 1 2025-11-08 23:49:44.385 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:49:44.053 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:49:44.211 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:49:44.209 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:49:44.294 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:50:15.654 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60604 10 6452 1 2025-11-08 23:51:16.068 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:38744 10 6452 1 2025-11-08 23:52:16.433 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:44602 10 6452 1 2025-11-08 23:53:16.803 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:51256 10 6452 1 2025-11-08 23:54:17.217 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:60710 10 6452 1 2025-11-08 23:54:44.118 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-08 23:54:43.952 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:54:44.248 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-08 23:54:44.117 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-08 23:54:44.332 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-08 23:49:57.441 00:06:00.091 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-08 23:55:17.618 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:56212 10 6452 1 2025-11-08 23:50:57.440 00:06:00.095 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-08 23:56:18.066 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:33028 10 6452 1 2025-11-08 23:57:18.436 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:42310 10 6452 1 2025-11-08 23:58:18.839 00:00:10.464 TCP 1.101.0.1:3000 -> 23.104.0.1:45312 12 10369 1 Summary: total flows: 138, total bytes: 429541, total packets: 1039, avg bps: 887, avg pps: 0, avg bpp: 413 Time window: 2025-11-08 22:53:57 - 2025-11-08 23:58:29 Total flows processed: 138, passed: 138, Blocks skipped: 0, Bytes read: 14416 Sys: 0.0022s User: 0.0022s Wall: 0.0016s flows/second: 84969.8 Runtime: 0.0016s