Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-13 21:59:27.990 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:56384 10 6452 1 2025-11-13 22:00:28.399 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:56782 10 6452 1 2025-11-13 22:01:28.809 00:00:10.510 TCP 1.101.0.1:3000 -> 23.104.0.1:45776 10 6452 1 2025-11-13 21:58:00.244 00:04:00.221 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-11-13 21:58:00.242 00:04:00.226 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-11-13 22:02:05.964 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:02:06.394 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:02:06.165 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:02:06.147 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:02:06.248 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:02:29.355 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:60148 10 6452 1 2025-11-13 22:03:29.715 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:57216 10 6452 1 2025-11-13 22:03:00.247 00:01:00.218 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-13 22:03:00.245 00:01:00.223 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-13 22:04:30.122 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:57892 10 6452 1 2025-11-13 22:05:30.526 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:48670 10 6452 1 2025-11-13 22:06:30.934 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:60350 10 6452 1 2025-11-13 22:05:00.246 00:02:00.219 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-13 22:05:00.244 00:02:00.223 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-13 22:07:06.406 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:07:06.164 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:07:06.287 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:07:06.282 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:07:06.370 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:07:31.356 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:58398 10 6452 1 2025-11-13 22:08:31.754 00:00:10.434 TCP 1.101.0.1:3000 -> 23.104.0.1:33440 11 6504 1 2025-11-13 22:08:00.247 00:01:00.219 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-13 22:08:00.245 00:01:00.224 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-13 22:09:32.224 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:33498 10 6452 1 2025-11-13 22:10:32.624 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58528 10 6452 1 2025-11-13 22:11:33.031 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:53212 10 6452 1 2025-11-13 22:10:00.248 00:02:00.218 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-13 22:10:00.246 00:02:00.222 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-13 22:12:06.437 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:12:06.417 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:12:06.180 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:12:06.353 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:12:06.248 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:12:33.435 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:35138 10 6452 1 2025-11-13 22:13:33.795 00:00:10.340 TCP 1.101.0.1:3000 -> 23.104.0.1:55262 10 6452 1 2025-11-13 22:13:00.248 00:01:00.217 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-13 22:13:00.246 00:01:00.223 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-13 22:14:34.176 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37596 10 6452 1 2025-11-13 22:15:34.582 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33726 12 6556 1 2025-11-13 22:16:34.982 00:00:11.772 TCP 1.101.0.1:3000 -> 23.104.0.1:36126 10 6452 1 2025-11-13 22:17:06.685 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:17:06.556 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:17:06.359 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:17:06.604 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:17:06.682 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:17:36.786 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39770 10 6452 1 2025-11-13 22:18:37.189 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50550 10 6452 1 2025-11-13 22:15:00.249 00:04:00.222 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-11-13 22:15:00.246 00:04:00.227 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-11-13 22:19:37.593 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:32832 10 6452 1 2025-11-13 22:20:37.991 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59000 10 6452 1 2025-11-13 22:21:38.396 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:33474 10 6452 1 2025-11-13 22:22:06.559 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:22:06.585 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:22:06.615 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:22:06.546 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:22:06.698 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:22:38.801 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:33002 10 6452 1 2025-11-13 22:23:39.197 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:42038 10 6452 1 2025-11-13 22:20:00.250 00:04:00.222 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-11-13 22:20:00.247 00:04:00.227 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-11-13 22:24:39.562 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:60634 10 6452 1 2025-11-13 22:25:39.928 00:00:10.403 TCP 1.101.0.1:3000 -> 23.104.0.1:50258 10 6452 1 2025-11-13 22:26:40.370 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:58066 10 6452 1 2025-11-13 22:27:06.823 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:27:06.773 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:27:06.882 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:27:06.758 00:00:00.026 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:27:06.966 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:27:40.772 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:37344 10 6452 1 2025-11-13 22:28:41.191 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:49452 10 6452 1 2025-11-13 22:25:00.253 00:04:00.220 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-11-13 22:25:00.251 00:04:00.225 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-11-13 22:29:41.596 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56112 10 6452 1 2025-11-13 22:30:41.997 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:44190 10 6452 1 2025-11-13 22:31:42.401 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:37650 10 6452 1 2025-11-13 22:32:06.940 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:32:06.715 00:00:00.030 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:32:07.231 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:32:06.943 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:32:07.320 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:32:42.806 00:00:10.533 TCP 1.101.0.1:3000 -> 23.104.0.1:37900 10 6452 1 2025-11-13 22:33:43.379 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:48992 10 6452 1 2025-11-13 22:30:00.250 00:04:00.227 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-11-13 22:30:00.253 00:04:00.221 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-11-13 22:34:43.778 00:00:14.662 TCP 1.101.0.1:3000 -> 23.104.0.1:37528 10 6452 1 2025-11-13 22:35:48.524 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39410 10 6452 1 2025-11-13 22:36:48.929 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:49744 10 6452 1 2025-11-13 22:37:07.210 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:37:06.804 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:37:06.727 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:37:07.128 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:37:06.904 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:37:49.363 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:36980 10 6452 1 2025-11-13 22:38:49.767 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:54840 10 6452 1 2025-11-13 22:35:00.254 00:04:00.221 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-11-13 22:35:00.252 00:04:00.226 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-11-13 22:39:50.175 00:00:10.440 TCP 1.101.0.1:3000 -> 23.104.0.1:50388 12 10375 1 2025-11-13 22:40:00.255 00:01:00.220 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-13 22:40:00.252 00:01:00.225 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-13 22:40:50.654 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:56364 10 6452 1 2025-11-13 22:41:51.079 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:35624 10 6452 1 2025-11-13 22:42:06.813 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:42:06.706 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:42:06.764 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:42:06.767 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:42:06.847 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:42:51.499 00:00:10.394 TCP 1.101.0.1:3000 -> 23.104.0.1:37178 10 6452 1 2025-11-13 22:42:00.256 00:02:00.221 TCP 179.21.23.21:38570 -> 179.21.23.23:179 6 369 1 2025-11-13 22:42:00.253 00:02:00.226 TCP 179.21.23.23:179 -> 179.21.23.21:38570 6 369 1 2025-11-13 22:43:51.931 00:00:10.391 TCP 1.101.0.1:3000 -> 23.104.0.1:32946 10 6452 1 2025-11-13 22:44:52.362 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:32870 10 6452 1 2025-11-13 22:45:00.254 00:01:00.226 TCP 179.21.23.23:179 -> 179.21.23.21:38570 4 246 1 2025-11-13 22:45:00.256 00:01:00.221 TCP 179.21.23.21:38570 -> 179.21.23.23:179 4 246 1 2025-11-13 22:45:52.771 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:35726 10 6452 1 2025-11-13 22:46:53.137 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:59822 10 6452 1 2025-11-13 22:47:07.165 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:47:06.992 00:00:00.047 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:47:07.267 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:47:07.091 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:47:07.350 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:47:53.543 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:45306 10 6452 1 2025-11-13 22:48:53.951 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55326 10 6452 1 2025-11-13 22:49:54.355 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54030 10 6452 1 2025-11-13 22:47:00.254 00:04:00.226 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-11-13 22:47:00.256 00:04:00.222 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-11-13 22:50:54.754 00:00:10.393 TCP 1.101.0.1:3000 -> 23.104.0.1:43714 10 6452 1 2025-11-13 22:51:55.188 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:45424 10 6452 1 2025-11-13 22:52:07.562 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:52:07.512 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:52:07.187 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:52:07.480 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:52:07.414 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:52:55.592 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:43330 10 6452 1 2025-11-13 22:53:55.991 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:60330 10 6452 1 2025-11-13 22:54:56.403 00:00:10.399 TCP 1.101.0.1:3000 -> 23.104.0.1:55530 12 10369 1 2025-11-13 22:52:00.255 00:04:00.226 TCP 179.21.23.23:179 -> 179.21.23.21:38570 10 615 1 2025-11-13 22:52:00.259 00:04:00.220 TCP 179.21.23.21:38570 -> 179.21.23.23:179 10 615 1 2025-11-13 22:55:56.839 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:49164 10 6452 1 2025-11-13 22:57:07.472 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-13 22:57:07.387 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-13 22:57:07.202 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:56:57.256 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:45916 10 6452 1 2025-11-13 22:57:07.389 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-13 22:57:07.535 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-13 22:57:57.663 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:46298 10 6452 1 Summary: total flows: 151, total bytes: 418298, total packets: 1013, avg bps: 927, avg pps: 0, avg bpp: 412 Time window: 2025-11-13 21:58:00 - 2025-11-13 22:58:07 Total flows processed: 151, passed: 151, Blocks skipped: 0, Bytes read: 15768 Sys: 0.0020s User: 0.0031s Wall: 0.0028s flows/second: 54256.8 Runtime: 0.0028s