Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-12 15:53:59.632 00:06:00.186 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-12 15:59:22.288 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:42138 10 6452 1 2025-11-12 16:00:22.685 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:52234 10 6452 1 2025-11-12 16:01:30.009 00:00:00.038 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:01:29.843 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:01:29.913 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:01:30.052 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:01:29.995 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:01:23.059 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:45220 10 6452 1 2025-11-12 16:02:23.464 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:45836 10 6452 1 2025-11-12 16:03:23.827 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:50612 10 6452 1 2025-11-12 16:04:24.225 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:50540 10 6452 1 2025-11-12 15:59:59.632 00:06:00.194 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-12 16:05:24.632 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:56800 10 6452 1 2025-11-12 16:00:59.635 00:06:00.188 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-12 16:06:30.129 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:06:30.246 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:06:30.392 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:06:30.128 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:06:30.475 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:06:25.035 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60148 10 6452 1 2025-11-12 16:07:25.441 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:52120 10 6452 1 2025-11-12 16:08:25.845 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:59926 10 6452 1 2025-11-12 16:09:26.272 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:51400 10 6452 1 2025-11-12 16:10:26.680 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:36612 10 6452 1 2025-11-12 16:11:30.306 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:11:30.185 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:11:30.271 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:11:30.184 00:00:00.027 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:11:30.267 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:11:27.119 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:50972 10 6452 1 2025-11-12 16:06:59.632 00:06:00.196 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-12 16:12:27.525 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:59924 10 6452 1 2025-11-12 16:07:59.634 00:06:00.190 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-12 16:13:27.922 00:00:10.808 TCP 1.101.0.1:3000 -> 23.104.0.1:49656 10 6452 1 2025-11-12 16:14:28.764 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:50594 10 6452 1 2025-11-12 16:15:29.188 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:44212 10 6452 1 2025-11-12 16:16:30.599 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:16:30.324 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:16:30.359 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:16:30.465 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:16:30.442 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:16:29.588 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:49308 10 6452 1 2025-11-12 16:17:29.955 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:46452 10 6452 1 2025-11-12 16:18:30.362 00:00:11.982 TCP 1.101.0.1:3000 -> 23.104.0.1:51270 10 6452 1 2025-11-12 16:13:59.632 00:06:00.196 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-12 16:19:32.386 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:34134 10 6452 1 2025-11-12 16:14:59.635 00:06:00.191 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-12 16:20:32.793 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:37552 10 6452 1 2025-11-12 16:21:30.486 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:21:30.482 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:21:30.551 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:21:30.484 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:21:30.568 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:21:33.202 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40378 10 6452 1 2025-11-12 16:22:33.605 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:33194 10 6452 1 2025-11-12 16:23:34.012 00:00:10.514 TCP 1.101.0.1:3000 -> 23.104.0.1:57912 14 14292 1 2025-11-12 16:24:34.562 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:60006 10 6452 1 2025-11-12 16:25:34.968 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:56514 10 6452 1 2025-11-12 16:20:59.633 00:06:00.197 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-12 16:26:31.710 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:26:31.514 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:26:31.779 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:26:31.578 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:26:31.861 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:26:35.364 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:51000 10 6452 1 2025-11-12 16:21:59.636 00:06:00.192 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-12 16:27:35.770 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:34490 10 6452 1 2025-11-12 16:28:36.183 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:57116 12 10369 1 2025-11-12 16:29:36.661 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:40708 10 6452 1 2025-11-12 16:30:37.024 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:37860 10 6452 1 2025-11-12 16:31:30.682 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:31:30.723 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:31:30.814 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:31:30.766 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:31:30.898 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:31:37.421 00:00:11.575 TCP 1.101.0.1:3000 -> 23.104.0.1:34878 10 6452 1 2025-11-12 16:32:39.034 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:55796 10 6452 1 2025-11-12 16:27:59.635 00:06:00.199 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-12 16:33:39.435 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:60706 10 6452 1 2025-11-12 16:28:59.637 00:06:00.193 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-12 16:34:39.838 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:54482 10 6452 1 2025-11-12 16:35:40.259 00:00:10.854 TCP 1.101.0.1:3000 -> 23.104.0.1:37894 10 6452 1 2025-11-12 16:36:30.925 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:36:30.726 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:36:30.875 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:36:30.812 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:36:30.959 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:36:41.151 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:60074 10 6452 1 2025-11-12 16:37:41.562 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39366 10 6452 1 2025-11-12 16:38:41.970 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:49650 10 6452 1 2025-11-12 16:39:42.356 00:00:10.738 TCP 1.101.0.1:3000 -> 23.104.0.1:38508 10 6452 1 2025-11-12 16:34:59.642 00:06:00.193 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-12 16:40:43.133 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:44694 10 6452 1 2025-11-12 16:35:59.644 00:06:00.191 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-12 16:41:30.758 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:41:30.566 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:41:30.967 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:41:30.969 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:41:31.050 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:41:43.537 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:42738 10 6452 1 2025-11-12 16:42:43.941 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:58222 10 6452 1 2025-11-12 16:43:44.318 00:00:10.774 TCP 1.101.0.1:3000 -> 23.104.0.1:35958 10 6452 1 2025-11-12 16:44:45.138 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:50488 10 6452 1 2025-11-12 16:45:45.555 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47432 10 6452 1 2025-11-12 16:46:31.173 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:46:31.000 00:00:00.040 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:46:31.060 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:46:31.091 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:46:31.086 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:46:45.956 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:50066 10 6452 1 2025-11-12 16:41:59.643 00:06:00.193 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-12 16:42:59.647 00:06:00.188 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-12 16:47:46.321 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47242 10 6452 1 2025-11-12 16:48:46.724 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:41954 10 6452 1 2025-11-12 16:49:47.144 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59568 10 6452 1 2025-11-12 16:50:47.550 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:56970 10 6452 1 2025-11-12 16:51:31.435 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:51:31.433 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:51:31.383 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:51:31.353 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:51:31.503 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:51:47.949 00:00:10.989 TCP 1.101.0.1:3000 -> 23.104.0.1:54464 10 6452 1 2025-11-12 16:52:48.976 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:36222 10 6452 1 2025-11-12 16:48:59.644 00:06:00.195 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-12 16:53:49.386 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:50248 10 6452 1 2025-11-12 16:54:49.781 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:43862 10 6452 1 2025-11-12 16:49:59.647 00:06:00.190 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-12 16:55:50.146 00:00:10.651 TCP 1.101.0.1:3000 -> 23.104.0.1:59870 10 6452 1 2025-11-12 16:56:31.214 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-12 16:56:31.172 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:56:31.295 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-12 16:56:31.033 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-12 16:56:31.378 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-12 16:56:50.838 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:55970 10 6452 1 2025-11-12 16:57:51.268 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:52924 10 6452 1 Summary: total flows: 136, total bytes: 422182, total packets: 1014, avg bps: 879, avg pps: 0, avg bpp: 416 Time window: 2025-11-12 15:53:59 - 2025-11-12 16:58:01 Total flows processed: 136, passed: 136, Blocks skipped: 0, Bytes read: 14208 Sys: 0.0037s User: 0.0019s Wall: 0.0021s flows/second: 64578.9 Runtime: 0.0021s