Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-20 21:59:37.839 00:00:10.351 TCP 1.101.0.1:3000 -> 23.104.0.1:46078 10 6452 1 2025-11-20 21:56:03.759 00:05:00.320 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 22:00:30.020 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:00:30.038 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:00:30.109 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:00:29.937 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:00:30.053 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:00:38.227 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:37456 10 6452 1 2025-11-20 22:01:38.633 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:47336 10 6452 1 2025-11-20 22:02:39.037 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:60012 10 6452 1 2025-11-20 22:03:39.444 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:38246 10 6452 1 2025-11-20 22:00:03.764 00:05:00.313 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 22:04:39.808 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:44016 10 6452 1 2025-11-20 22:05:30.079 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:05:29.965 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:05:30.157 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:05:30.231 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:05:30.240 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:05:40.211 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:51494 10 6452 1 2025-11-20 22:02:03.761 00:05:00.319 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 22:06:40.576 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:32818 10 6452 1 2025-11-20 22:07:40.985 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47962 10 6452 1 2025-11-20 22:08:41.392 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:59350 10 6452 1 2025-11-20 22:09:41.796 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:39828 10 6452 1 2025-11-20 22:06:03.767 00:05:00.312 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 22:10:30.551 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:10:30.340 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:10:30.304 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:10:30.468 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:10:30.336 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:10:42.165 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:53008 10 6452 1 2025-11-20 22:11:42.572 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:41626 10 6452 1 2025-11-20 22:08:03.764 00:05:00.318 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 22:12:42.975 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:50636 10 6452 1 2025-11-20 22:13:43.387 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39792 10 6452 1 2025-11-20 22:14:43.792 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:57946 10 6452 1 2025-11-20 22:15:30.154 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:15:30.495 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:15:30.300 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:15:30.295 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:15:30.578 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:15:44.201 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:53678 10 6452 1 2025-11-20 22:12:03.768 00:05:00.313 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 22:16:44.604 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:33410 10 6452 1 2025-11-20 22:17:45.008 00:00:10.423 TCP 1.101.0.1:3000 -> 23.104.0.1:40834 11 6504 1 2025-11-20 22:14:03.766 00:05:00.318 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 22:18:45.473 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:34748 10 6452 1 2025-11-20 22:19:45.834 00:00:10.393 TCP 1.101.0.1:3000 -> 23.104.0.1:58400 10 6452 1 2025-11-20 22:20:30.371 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:20:30.410 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:20:30.275 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:20:30.362 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:20:30.359 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:20:46.266 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:51384 10 6452 1 2025-11-20 22:21:46.697 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:46910 10 6452 1 2025-11-20 22:18:03.769 00:05:00.313 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 22:22:47.117 00:00:10.446 TCP 1.101.0.1:3000 -> 23.104.0.1:37926 12 10375 1 2025-11-20 22:23:47.605 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:47174 10 6452 1 2025-11-20 22:20:03.769 00:05:00.317 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 22:24:47.964 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36746 10 6452 1 2025-11-20 22:25:30.446 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:25:30.364 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:25:30.371 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:25:30.471 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:25:30.478 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:25:48.368 00:00:13.370 TCP 1.101.0.1:3000 -> 23.104.0.1:38402 11 6492 1 2025-11-20 22:26:51.818 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:43000 10 6452 1 2025-11-20 22:27:52.221 00:00:10.438 TCP 1.101.0.1:3000 -> 23.104.0.1:56186 12 10375 1 2025-11-20 22:24:03.772 00:05:00.312 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 22:28:52.695 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33822 10 6452 1 2025-11-20 22:26:03.773 00:05:00.312 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 22:29:53.108 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:33212 10 6452 1 2025-11-20 22:30:30.776 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:30:30.350 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:30:30.789 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:30:30.561 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:30:30.870 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:30:53.465 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:56530 10 6452 1 2025-11-20 22:31:53.826 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41696 10 6452 1 2025-11-20 22:32:54.229 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:47608 10 6452 1 2025-11-20 22:33:54.627 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44146 10 6452 1 2025-11-20 22:30:03.774 00:05:00.314 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 22:34:55.030 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:33174 10 6452 1 2025-11-20 22:35:30.770 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:35:30.712 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:35:30.815 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:35:30.861 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:35:30.897 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:35:55.445 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:40878 10 6452 1 2025-11-20 22:32:03.772 00:05:00.319 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 22:36:55.850 00:00:10.353 TCP 1.101.0.1:3000 -> 23.104.0.1:55674 10 6452 1 2025-11-20 22:37:56.240 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:43960 10 6452 1 2025-11-20 22:38:56.634 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:42006 10 6452 1 2025-11-20 22:36:03.775 00:05:00.313 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 22:39:57.042 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:38944 10 6452 1 2025-11-20 22:40:30.766 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:40:30.945 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:40:30.940 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:40:31.149 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:40:31.028 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:40:57.450 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:49384 10 6452 1 2025-11-20 22:38:03.772 00:05:00.320 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 22:41:57.875 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:38078 10 6452 1 2025-11-20 22:42:58.234 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:56794 10 6452 1 2025-11-20 22:43:58.638 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:57190 10 6452 1 2025-11-20 22:44:59.065 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54960 10 6452 1 2025-11-20 22:45:30.929 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:45:30.852 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:45:30.931 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:45:30.719 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:45:31.014 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:42:03.777 00:05:00.315 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 22:45:59.470 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:40314 10 6452 1 2025-11-20 22:46:59.873 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:48348 10 6452 1 2025-11-20 22:44:03.774 00:05:00.320 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 22:48:00.281 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:57090 10 6452 1 2025-11-20 22:49:00.680 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:45704 10 6452 1 2025-11-20 22:50:01.059 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49092 10 6452 1 2025-11-20 22:50:31.271 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:50:30.924 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:50:30.975 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:50:31.114 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:50:31.189 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:51:01.460 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:39526 10 6452 1 2025-11-20 22:48:03.781 00:05:00.312 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 22:52:01.869 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:32970 10 6452 1 2025-11-20 22:53:02.236 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:33384 10 6452 1 2025-11-20 22:50:03.778 00:05:00.319 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-20 22:54:02.666 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:45464 10 6452 1 2025-11-20 22:55:03.108 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:51286 10 6452 1 2025-11-20 22:55:31.339 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-20 22:55:31.261 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-20 22:55:31.002 00:00:00.043 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:55:31.258 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-20 22:55:31.099 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-20 22:56:03.478 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:35968 10 6452 1 2025-11-20 22:57:03.896 00:00:10.337 TCP 1.101.0.1:3000 -> 23.104.0.1:41450 10 6452 1 2025-11-20 22:54:03.781 00:05:00.311 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-20 22:58:04.271 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:50330 12 10369 1 Summary: total flows: 139, total bytes: 422403, total packets: 1018, avg bps: 893, avg pps: 0, avg bpp: 414 Time window: 2025-11-20 21:56:03 - 2025-11-20 22:59:04 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0045s User: 0.0009s Wall: 0.0018s flows/second: 76752.0 Runtime: 0.0018s