Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-16 18:58:59.914 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:40414 10 6452 1 2025-11-16 19:00:00.319 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39672 10 6452 1 2025-11-16 18:56:01.730 00:06:00.109 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-16 19:01:00.722 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:34688 10 6452 1 2025-11-16 18:57:01.728 00:06:00.115 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-16 19:02:01.109 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:44106 10 6452 1 2025-11-16 19:03:01.478 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:46312 10 6452 1 2025-11-16 19:03:29.207 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:03:29.222 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:03:29.273 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:03:29.351 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:03:29.355 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:04:01.873 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:53962 10 6452 1 2025-11-16 19:05:02.277 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:53418 10 6452 1 2025-11-16 19:06:02.692 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48222 10 6452 1 2025-11-16 19:07:03.110 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37640 10 6452 1 2025-11-16 19:03:01.734 00:06:00.109 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-16 19:08:03.513 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:36828 10 6452 1 2025-11-16 19:08:29.490 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:08:29.313 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:08:29.506 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:08:29.408 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:08:29.561 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:04:01.731 00:06:00.115 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-16 19:09:03.918 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:40102 10 6452 1 2025-11-16 19:10:04.320 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58424 10 6452 1 2025-11-16 19:11:04.725 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:57674 10 6452 1 2025-11-16 19:12:05.141 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:53462 10 6452 1 2025-11-16 19:13:05.504 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59752 10 6452 1 2025-11-16 19:13:29.487 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:13:29.426 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:13:29.614 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:13:29.559 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:13:29.696 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:14:05.907 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:33130 10 6452 1 2025-11-16 19:10:01.734 00:06:00.111 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-16 19:15:06.327 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60368 10 6452 1 2025-11-16 19:11:01.731 00:06:00.117 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-16 19:16:06.736 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58530 10 6452 1 2025-11-16 19:17:07.139 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:53766 10 6452 1 2025-11-16 19:18:07.501 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51934 10 6452 1 2025-11-16 19:18:29.490 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:18:29.694 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:18:29.426 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:18:29.409 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:18:29.697 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:19:07.905 00:00:10.337 TCP 1.101.0.1:3000 -> 23.104.0.1:46200 10 6452 1 2025-11-16 19:20:08.272 00:00:10.341 TCP 1.101.0.1:3000 -> 23.104.0.1:35346 10 6452 1 2025-11-16 19:21:08.662 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:41084 10 6452 1 2025-11-16 19:17:01.737 00:06:00.111 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-16 19:22:09.087 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:55816 10 6452 1 2025-11-16 19:18:01.733 00:06:00.117 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-16 19:23:09.454 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60146 10 6452 1 2025-11-16 19:23:29.554 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:23:29.673 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:23:29.637 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:23:29.465 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:23:29.612 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:24:09.862 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:48848 10 6452 1 2025-11-16 19:25:10.278 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:40396 10 6452 1 2025-11-16 19:26:10.685 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:36322 10 6452 1 2025-11-16 19:27:11.063 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:34588 10 6452 1 2025-11-16 19:28:29.605 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:28:11.475 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:47092 10 6452 1 2025-11-16 19:28:29.634 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:28:29.658 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:28:29.524 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:28:29.526 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:24:01.739 00:06:00.110 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-16 19:29:11.881 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47118 10 6452 1 2025-11-16 19:25:01.737 00:06:00.115 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-16 19:30:12.285 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:51962 10 6452 1 2025-11-16 19:31:12.693 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:43942 10 6452 1 2025-11-16 19:32:13.065 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59332 10 6452 1 2025-11-16 19:33:30.285 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:33:13.471 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:41722 10 6452 1 2025-11-16 19:33:30.106 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:33:30.304 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:33:30.202 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:33:30.260 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:34:13.868 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:42504 10 6452 1 2025-11-16 19:35:14.283 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35410 10 6452 1 2025-11-16 19:31:01.740 00:06:00.112 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-16 19:36:14.685 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52718 10 6452 1 2025-11-16 19:32:01.737 00:06:00.118 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-16 19:37:15.107 00:00:10.356 TCP 1.101.0.1:3000 -> 23.104.0.1:53630 10 6452 1 2025-11-16 19:38:15.504 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:53242 10 6452 1 2025-11-16 19:38:30.013 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:38:29.662 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:38:29.945 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:38:29.929 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:38:29.979 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:39:15.911 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54530 10 6452 1 2025-11-16 19:40:16.321 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:51752 10 6452 1 2025-11-16 19:41:16.689 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:55738 10 6452 1 2025-11-16 19:42:17.062 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:40920 10 6452 1 2025-11-16 19:38:01.742 00:06:00.112 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-16 19:43:30.385 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:43:30.062 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:43:17.457 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:53858 10 6452 1 2025-11-16 19:43:30.303 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:43:29.980 00:00:00.025 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:43:30.245 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:39:01.739 00:06:00.118 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-16 19:44:17.823 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:39748 10 6452 1 2025-11-16 19:45:18.231 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:50846 10 6452 1 2025-11-16 19:46:18.638 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:48162 10 6452 1 2025-11-16 19:47:18.999 00:00:10.337 TCP 1.101.0.1:3000 -> 23.104.0.1:38654 10 6452 1 2025-11-16 19:48:30.302 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:48:19.380 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:41002 10 6452 1 2025-11-16 19:48:30.151 00:00:00.025 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:48:30.446 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:48:30.220 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:48:30.530 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:49:19.749 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:38684 10 6452 1 2025-11-16 19:45:01.742 00:06:00.114 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-16 19:50:20.161 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:57246 10 6452 1 2025-11-16 19:46:01.740 00:06:00.119 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-16 19:51:20.567 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:42830 10 6452 1 2025-11-16 19:52:20.973 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58506 10 6452 1 2025-11-16 19:53:30.233 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:53:30.207 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:53:30.205 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:53:30.340 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:53:30.291 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:53:21.376 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:49580 10 6452 1 2025-11-16 19:54:21.776 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:48338 10 6452 1 2025-11-16 19:55:22.137 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:40844 10 6452 1 2025-11-16 19:56:22.502 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:42830 10 6452 1 2025-11-16 19:52:01.749 00:06:00.111 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-16 19:57:22.903 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:40508 12 6556 1 2025-11-16 19:53:01.744 00:06:00.116 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-16 19:58:30.345 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-16 19:58:30.262 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:58:30.526 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-16 19:58:30.216 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-16 19:58:30.610 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-16 19:58:23.314 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:58360 10 6452 1 Summary: total flows: 138, total bytes: 417842, total packets: 1034, avg bps: 884, avg pps: 0, avg bpp: 404 Time window: 2025-11-16 18:56:01 - 2025-11-16 19:59:01 Total flows processed: 138, passed: 138, Blocks skipped: 0, Bytes read: 14416 Sys: 0.0018s User: 0.0046s Wall: 0.0021s flows/second: 65093.8 Runtime: 0.0021s