Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-20 13:59:27.400 00:00:13.199 TCP 1.101.0.1:3000 -> 23.104.0.1:55984 10 6452 1 2025-11-20 13:55:03.595 00:06:00.290 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 14:00:20.402 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:00:20.273 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:00:20.403 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:00:20.376 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:00:20.485 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:00:30.638 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:36722 10 6452 1 2025-11-20 14:01:31.051 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:36376 10 6452 1 2025-11-20 14:02:31.405 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:46696 10 6452 1 2025-11-20 13:58:03.591 00:06:00.295 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 14:03:31.810 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:45052 10 6452 1 2025-11-20 14:04:32.215 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:35992 10 6452 1 2025-11-20 14:05:20.591 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:05:20.411 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:05:20.516 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:05:20.660 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:05:20.598 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:05:32.617 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:38060 10 6452 1 2025-11-20 14:06:33.024 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59488 10 6452 1 2025-11-20 14:02:03.594 00:06:00.290 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 14:07:33.428 00:00:10.723 TCP 1.101.0.1:3000 -> 23.104.0.1:48724 10 6452 1 2025-11-20 14:08:34.197 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59800 10 6452 1 2025-11-20 14:09:34.598 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:58838 10 6452 1 2025-11-20 14:05:03.594 00:06:00.299 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 14:10:20.670 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:10:20.564 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:10:20.397 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:10:20.587 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:10:20.713 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:10:35.005 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:56044 10 6452 1 2025-11-20 14:11:35.376 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:43598 10 6452 1 2025-11-20 14:12:35.780 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48710 10 6452 1 2025-11-20 14:13:36.181 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44602 10 6452 1 2025-11-20 14:09:03.596 00:06:00.295 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 14:14:36.581 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:43146 10 6452 1 2025-11-20 14:15:20.634 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:15:20.655 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:15:20.592 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:15:20.552 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:15:20.727 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:15:37.002 00:00:10.414 TCP 1.101.0.1:3000 -> 23.104.0.1:36858 10 6452 1 2025-11-20 14:16:37.462 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:56182 10 6452 1 2025-11-20 14:12:03.597 00:06:00.298 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 14:17:37.871 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:51080 10 6452 1 2025-11-20 14:18:38.291 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39182 10 6452 1 2025-11-20 14:19:38.688 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58090 12 6556 1 2025-11-20 14:20:20.896 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:20:20.861 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:20:20.875 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:20:20.812 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:20:20.719 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:20:39.111 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:56194 10 6452 1 2025-11-20 14:16:03.601 00:06:00.291 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 14:21:39.513 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:34232 10 6452 1 2025-11-20 14:22:39.921 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:33622 10 6452 1 2025-11-20 14:23:40.332 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:52108 10 6452 1 2025-11-20 14:19:03.598 00:06:00.297 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 14:24:40.693 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:37512 10 6452 1 2025-11-20 14:25:20.795 00:00:00.031 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:25:21.183 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:25:21.323 00:00:00.025 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:25:21.183 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:25:21.406 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:25:41.060 00:00:10.887 TCP 1.101.0.1:3000 -> 23.104.0.1:41806 10 6452 1 2025-11-20 14:26:41.993 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:34920 10 6452 1 2025-11-20 14:27:42.400 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:55746 10 6452 1 2025-11-20 14:23:03.601 00:06:00.292 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 14:28:42.760 00:00:10.394 TCP 1.101.0.1:3000 -> 23.104.0.1:52848 10 6452 1 2025-11-20 14:29:43.193 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:56696 10 6452 1 2025-11-20 14:30:20.775 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:30:20.945 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:30:20.829 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:30:21.028 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:30:21.006 00:00:00.040 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:30:43.597 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:47236 10 6452 1 2025-11-20 14:26:03.599 00:06:00.298 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 14:31:43.997 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48078 10 6452 1 2025-11-20 14:32:44.403 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:47252 10 6452 1 2025-11-20 14:33:44.810 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:50946 10 6452 1 2025-11-20 14:34:45.213 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:54006 10 6452 1 2025-11-20 14:30:03.603 00:06:00.292 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 14:35:21.154 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:35:21.001 00:00:00.028 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:35:21.152 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:35:21.004 00:00:00.045 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:35:21.234 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:35:45.618 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:52434 10 6452 1 2025-11-20 14:36:46.062 00:00:10.397 TCP 1.101.0.1:3000 -> 23.104.0.1:50260 10 6452 1 2025-11-20 14:37:46.510 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:37726 10 6452 1 2025-11-20 14:33:03.608 00:06:00.291 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 14:38:46.879 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:42658 10 6452 1 2025-11-20 14:39:47.284 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:58972 10 6452 1 2025-11-20 14:40:21.260 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:40:21.033 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:40:21.133 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:40:21.069 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:40:21.343 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:40:47.693 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:59938 10 6452 1 2025-11-20 14:41:48.111 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:55908 10 6452 1 2025-11-20 14:37:03.606 00:06:00.292 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 14:42:48.510 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:35608 10 6452 1 2025-11-20 14:43:48.871 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60224 10 6452 1 2025-11-20 14:44:49.283 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:45498 10 6452 1 2025-11-20 14:40:03.603 00:06:00.298 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 14:45:21.198 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:45:21.149 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:45:21.332 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:45:21.211 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:45:21.413 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:45:49.682 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:49374 10 6452 1 2025-11-20 14:46:50.108 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:46922 10 6452 1 2025-11-20 14:47:50.510 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:43432 10 6452 1 2025-11-20 14:48:50.913 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:36266 10 6452 1 2025-11-20 14:44:03.608 00:06:00.292 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 14:49:51.280 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:45234 10 6452 1 2025-11-20 14:50:21.517 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:50:21.399 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:50:21.402 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:50:21.486 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:50:21.599 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:50:51.649 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46802 10 6452 1 2025-11-20 14:47:03.605 00:06:00.298 TCP 179.21.23.23:179 -> 179.21.23.21:38570 14 861 1 2025-11-20 14:51:52.069 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:37200 10 6452 1 2025-11-20 14:52:52.472 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:36062 10 6452 1 2025-11-20 14:53:52.899 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:32916 10 6452 1 2025-11-20 14:54:53.311 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:53596 10 6452 1 2025-11-20 14:55:21.790 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 14:55:21.537 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:55:21.457 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 14:55:21.723 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 14:55:21.539 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 14:51:03.610 00:06:00.293 TCP 179.21.23.21:38570 -> 179.21.23.23:179 14 861 1 2025-11-20 14:55:53.713 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:51136 10 6452 1 2025-11-20 14:56:54.119 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:33148 10 6452 1 2025-11-20 14:57:54.485 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:51118 10 6452 1 Summary: total flows: 136, total bytes: 410529, total packets: 1010, avg bps: 868, avg pps: 0, avg bpp: 406 Time window: 2025-11-20 13:55:03 - 2025-11-20 14:58:04 Total flows processed: 136, passed: 136, Blocks skipped: 0, Bytes read: 14208 Sys: 0.0038s User: 0.0009s Wall: 0.0019s flows/second: 72804.8 Runtime: 0.0019s