Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-13 04:58:52.932 00:00:10.396 TCP 1.101.0.1:3000 -> 23.104.0.1:53778 11 6504 1 2025-11-13 04:55:59.876 00:05:00.254 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-13 04:59:53.372 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:55104 10 6452 1 2025-11-13 05:00:53.777 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:45598 10 6452 1 2025-11-13 05:01:45.619 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:01:45.563 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:01:45.895 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:01:45.784 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:01:45.977 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 04:57:59.871 00:05:00.260 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-13 05:01:54.183 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:58930 10 6452 1 2025-11-13 05:02:54.588 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57118 10 6452 1 2025-11-13 05:03:54.994 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:50906 10 6452 1 2025-11-13 05:04:55.403 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:57648 10 6452 1 2025-11-13 05:01:59.876 00:05:00.253 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-13 05:05:55.821 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53404 10 6452 1 2025-11-13 05:06:45.794 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:06:45.963 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:06:45.873 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:06:45.701 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:06:45.957 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:06:56.223 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:36602 10 6452 1 2025-11-13 05:03:59.874 00:05:00.260 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-13 05:07:56.628 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:57052 10 6452 1 2025-11-13 05:08:57.030 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:53850 10 6452 1 2025-11-13 05:09:57.434 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:33684 10 6452 1 2025-11-13 05:10:57.846 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:32948 10 6452 1 2025-11-13 05:11:45.849 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:11:46.337 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:11:46.300 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:11:46.254 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:11:46.200 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:07:59.877 00:05:00.255 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-13 05:11:58.272 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:58026 10 6452 1 2025-11-13 05:12:58.670 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:51548 10 6452 1 2025-11-13 05:09:59.875 00:05:00.259 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-13 05:13:59.093 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:54306 10 6452 1 2025-11-13 05:14:59.492 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:33226 10 6452 1 2025-11-13 05:15:59.851 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:47486 10 6452 1 2025-11-13 05:16:45.830 00:00:00.026 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:16:45.947 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:16:46.184 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:16:46.183 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:16:46.030 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:17:00.270 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39626 10 6452 1 2025-11-13 05:13:59.878 00:05:00.256 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-13 05:18:00.673 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:55068 10 6452 1 2025-11-13 05:19:01.106 00:00:10.395 TCP 1.101.0.1:3000 -> 23.104.0.1:53196 10 6452 1 2025-11-13 05:15:59.875 00:05:00.260 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-13 05:20:01.540 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:51318 10 6452 1 2025-11-13 05:21:01.942 00:00:10.344 TCP 1.101.0.1:3000 -> 23.104.0.1:49008 10 6452 1 2025-11-13 05:21:46.152 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:21:46.180 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:21:46.330 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:21:46.151 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:21:46.414 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:22:02.323 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:56192 10 6452 1 2025-11-13 05:23:02.740 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:52782 10 6452 1 2025-11-13 05:19:59.885 00:05:00.251 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-13 05:24:03.109 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:57150 10 6452 1 2025-11-13 05:25:03.475 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:51256 10 6452 1 2025-11-13 05:21:59.881 00:05:00.258 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-13 05:26:03.880 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:50886 10 6452 1 2025-11-13 05:26:47.326 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:26:46.991 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:26:47.247 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:26:47.161 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:26:47.330 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:27:04.288 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:59656 10 6452 1 2025-11-13 05:28:04.693 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:55230 10 6452 1 2025-11-13 05:29:05.109 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57124 10 6452 1 2025-11-13 05:25:59.885 00:05:00.251 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-13 05:30:05.508 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:35306 10 6452 1 2025-11-13 05:31:05.916 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:49350 10 6452 1 2025-11-13 05:31:46.278 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:31:46.274 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:31:46.189 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:31:46.518 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:31:46.272 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:27:59.884 00:05:00.256 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-13 05:32:06.278 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:41734 10 6452 1 2025-11-13 05:33:06.676 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:37158 10 6452 1 2025-11-13 05:34:07.104 00:00:10.440 TCP 1.101.0.1:3000 -> 23.104.0.1:39192 12 10375 1 2025-11-13 05:35:07.583 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:51010 10 6452 1 2025-11-13 05:31:59.887 00:05:00.252 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-13 05:36:07.948 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:50480 10 6452 1 2025-11-13 05:36:46.614 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:36:46.448 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:36:46.497 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:36:46.500 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:36:46.580 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:37:08.363 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:47326 10 6452 1 2025-11-13 05:33:59.885 00:05:00.257 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-13 05:38:08.772 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:35564 10 6452 1 2025-11-13 05:39:09.141 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:35172 10 6452 1 2025-11-13 05:40:09.545 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:39090 10 6452 1 2025-11-13 05:41:09.947 00:00:10.423 TCP 1.101.0.1:3000 -> 23.104.0.1:40458 11 6504 1 2025-11-13 05:41:46.640 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:41:46.567 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:41:46.875 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:41:46.818 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:41:46.959 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:37:59.891 00:05:00.248 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-13 05:42:10.403 00:00:10.577 TCP 1.101.0.1:3000 -> 23.104.0.1:58350 10 6452 1 2025-11-13 05:43:11.021 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52546 10 6452 1 2025-11-13 05:39:59.888 00:05:00.253 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-13 05:44:11.425 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:35186 10 6452 1 2025-11-13 05:45:11.829 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:40554 10 6452 1 2025-11-13 05:46:12.237 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:34702 10 6452 1 2025-11-13 05:46:46.863 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:46:46.465 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:46:46.811 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:46:46.774 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:46:46.893 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:47:12.643 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36048 10 6452 1 2025-11-13 05:43:59.891 00:05:00.248 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-13 05:48:13.042 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52414 10 6452 1 2025-11-13 05:49:13.446 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:51882 10 6452 1 2025-11-13 05:45:59.892 00:05:00.252 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-13 05:50:13.851 00:00:10.340 TCP 1.101.0.1:3000 -> 23.104.0.1:33640 10 6452 1 2025-11-13 05:51:14.225 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:46762 10 6452 1 2025-11-13 05:51:46.934 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:51:46.852 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:51:46.803 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:51:46.852 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:51:46.898 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:52:14.580 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:37708 10 6452 1 2025-11-13 05:53:14.952 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:54362 10 6452 1 2025-11-13 05:49:59.897 00:05:00.244 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-13 05:54:15.396 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:34390 10 6452 1 2025-11-13 05:55:15.808 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:58734 10 6452 1 2025-11-13 05:51:59.896 00:05:00.247 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-13 05:56:16.206 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:45028 10 6452 1 2025-11-13 05:56:46.761 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 05:56:46.618 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:56:46.917 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 05:56:46.750 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 05:56:47.002 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 05:57:16.604 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:46300 10 6452 1 2025-11-13 05:58:17.007 00:00:11.024 TCP 1.101.0.1:3000 -> 23.104.0.1:57374 10 6452 1 Summary: total flows: 140, total bytes: 421027, total packets: 1024, avg bps: 898, avg pps: 0, avg bpp: 411 Time window: 2025-11-13 04:55:59 - 2025-11-13 05:58:28 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0036s User: 0.0018s Wall: 0.0029s flows/second: 47585.3 Runtime: 0.0030s