Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-15 11:54:01.135 00:06:00.093 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 11:59:26.150 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41580 10 6452 1 2025-11-15 11:55:01.131 00:06:00.098 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 12:00:26.551 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:43468 10 6452 1 2025-11-15 12:01:26.956 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:49732 10 6452 1 2025-11-15 12:02:27.349 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48002 10 6452 1 2025-11-15 12:02:51.939 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:02:52.071 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:02:51.879 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:02:51.857 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:02:51.940 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:03:27.755 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:49834 10 6452 1 2025-11-15 12:04:28.128 00:00:10.394 TCP 1.101.0.1:3000 -> 23.104.0.1:35838 10 6452 1 2025-11-15 12:05:28.529 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:52334 10 6452 1 2025-11-15 12:01:01.136 00:06:00.092 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 12:06:28.933 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:43348 10 6452 1 2025-11-15 12:02:01.133 00:06:00.097 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 12:07:29.357 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:44106 10 6452 1 2025-11-15 12:07:52.011 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:07:51.876 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:07:51.929 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:07:52.003 00:00:00.036 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:07:51.935 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:08:29.761 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:58450 10 6452 1 2025-11-15 12:09:30.132 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:57210 10 6452 1 2025-11-15 12:10:30.537 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:59746 10 6452 1 2025-11-15 12:11:30.940 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:40378 10 6452 1 2025-11-15 12:12:31.352 00:00:10.410 TCP 1.101.0.1:3000 -> 23.104.0.1:52872 11 6504 1 2025-11-15 12:12:52.416 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:12:52.567 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:12:52.121 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:12:52.334 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:12:52.403 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:08:01.144 00:06:00.084 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 12:13:31.800 00:00:10.340 TCP 1.101.0.1:3000 -> 23.104.0.1:47432 10 6452 1 2025-11-15 12:09:01.142 00:06:00.090 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 12:14:32.175 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:42280 10 6452 1 2025-11-15 12:15:32.587 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:59628 10 6452 1 2025-11-15 12:16:32.988 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:42104 10 6452 1 2025-11-15 12:17:33.388 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:44204 10 6452 1 2025-11-15 12:17:52.168 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:17:52.279 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:17:52.058 00:00:00.033 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:17:52.058 00:00:00.033 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:17:52.141 00:00:00.033 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:18:33.803 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39726 10 6452 1 2025-11-15 12:19:34.205 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:52026 10 6452 1 2025-11-15 12:15:01.145 00:06:00.086 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 12:20:34.608 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:54736 10 6452 1 2025-11-15 12:16:01.143 00:06:00.091 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 12:21:34.968 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:55060 10 6452 1 2025-11-15 12:22:35.373 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:58070 10 6452 1 2025-11-15 12:22:52.313 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:22:51.955 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:22:52.420 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:22:52.246 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:22:52.504 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:23:35.768 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:48938 10 6452 1 2025-11-15 12:24:36.179 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:35390 10 6452 1 2025-11-15 12:25:36.579 00:00:11.483 TCP 1.101.0.1:3000 -> 23.104.0.1:47284 10 6452 1 2025-11-15 12:26:38.111 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:44056 10 6452 1 2025-11-15 12:22:01.148 00:06:00.085 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 12:27:52.420 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:27:38.516 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39380 10 6452 1 2025-11-15 12:27:52.254 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:27:52.297 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:27:52.337 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:27:52.425 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:23:01.145 00:06:00.091 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 12:28:38.922 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36902 10 6452 1 2025-11-15 12:29:39.322 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:55082 10 6452 1 2025-11-15 12:30:39.727 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:55366 10 6452 1 2025-11-15 12:31:40.133 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:35374 10 6452 1 2025-11-15 12:32:40.541 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:55662 10 6452 1 2025-11-15 12:32:52.622 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:32:52.263 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:32:52.621 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:32:52.622 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:32:52.704 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:33:40.953 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:37892 10 6452 1 2025-11-15 12:29:01.152 00:06:00.082 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 12:34:41.359 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:54012 10 6452 1 2025-11-15 12:30:01.149 00:06:00.087 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 12:35:41.779 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:42596 10 6452 1 2025-11-15 12:36:42.194 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:37762 10 6452 1 2025-11-15 12:37:52.665 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:37:52.468 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:37:52.586 00:00:00.025 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:37:52.586 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:37:42.613 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:58700 10 6452 1 2025-11-15 12:37:52.670 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:38:43.017 00:00:10.412 TCP 1.101.0.1:3000 -> 23.104.0.1:50802 11 6504 1 2025-11-15 12:39:43.467 00:00:10.427 TCP 1.101.0.1:3000 -> 23.104.0.1:44936 10 6452 1 2025-11-15 12:40:43.930 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:40654 10 6452 1 2025-11-15 12:36:01.153 00:06:00.082 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 12:41:44.352 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:57896 10 6452 1 2025-11-15 12:37:01.150 00:06:00.088 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 12:42:52.690 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:42:52.738 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:42:52.694 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:42:52.855 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:42:44.754 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:55300 10 6452 1 2025-11-15 12:42:52.776 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:43:45.155 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:42528 10 6452 1 2025-11-15 12:44:45.555 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:49034 10 6452 1 2025-11-15 12:45:45.963 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48166 10 6452 1 2025-11-15 12:46:46.366 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:51644 10 6452 1 2025-11-15 12:47:52.920 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:47:52.933 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:47:52.893 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:47:52.837 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:47:52.836 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:47:46.733 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:37280 10 6452 1 2025-11-15 12:43:01.154 00:06:00.085 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 12:48:47.117 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:42630 10 6452 1 2025-11-15 12:44:01.152 00:06:00.087 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 12:49:47.541 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:55102 10 6452 1 2025-11-15 12:50:47.943 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:55928 10 6452 1 2025-11-15 12:51:48.357 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47152 12 6556 1 2025-11-15 12:52:53.090 00:00:00.027 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:52:53.199 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:52:52.948 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:52:53.008 00:00:00.025 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:52:52.885 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:52:48.764 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:42148 10 6452 1 2025-11-15 12:53:49.141 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:49710 10 6452 1 2025-11-15 12:54:49.539 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:56300 10 6452 1 2025-11-15 12:50:01.156 00:06:00.084 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-15 12:55:49.940 00:00:10.780 TCP 1.101.0.1:3000 -> 23.104.0.1:59858 10 6452 1 2025-11-15 12:51:01.154 00:06:00.087 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-15 12:56:50.763 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:49282 10 6452 1 2025-11-15 12:57:53.028 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-15 12:57:52.948 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-15 12:57:52.880 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:57:52.944 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-15 12:57:53.065 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-15 12:57:51.181 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:51776 10 6452 1 Summary: total flows: 137, total bytes: 411494, total packets: 1026, avg bps: 857, avg pps: 0, avg bpp: 401 Time window: 2025-11-15 11:54:01 - 2025-11-15 12:58:01 Total flows processed: 137, passed: 137, Blocks skipped: 0, Bytes read: 14312 Sys: 0.0022s User: 0.0032s Wall: 0.0020s flows/second: 68603.1 Runtime: 0.0020s