Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-22 16:59:26.931 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:40146 10 6452 1 2025-11-22 17:00:27.355 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37760 10 6452 1 2025-11-22 17:01:21.760 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:01:21.712 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:01:21.688 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:01:21.702 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:01:21.770 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:01:27.757 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:35844 10 6452 1 2025-11-22 17:02:28.134 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48830 10 6452 1 2025-11-22 16:59:04.636 00:05:00.499 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-22 16:59:04.639 00:05:00.494 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-22 17:03:28.537 00:00:10.491 TCP 1.101.0.1:3000 -> 23.104.0.1:46438 10 6452 1 2025-11-22 17:04:29.080 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:49396 10 6452 1 2025-11-22 17:05:29.479 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58768 10 6452 1 2025-11-22 17:06:21.922 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:06:21.960 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:06:21.781 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:06:21.841 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:06:21.957 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:06:29.877 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:56532 10 6452 1 2025-11-22 17:07:30.278 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53978 10 6452 1 2025-11-22 17:08:30.684 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:34952 10 6452 1 2025-11-22 17:05:04.642 00:05:00.495 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-22 17:05:04.640 00:05:00.500 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-22 17:09:31.102 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:47950 10 6452 1 2025-11-22 17:10:31.496 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:35162 10 6452 1 2025-11-22 17:11:22.463 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:11:22.375 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:11:22.387 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:11:22.381 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:11:22.373 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:11:31.904 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:41384 12 6556 1 2025-11-22 17:12:32.314 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:36244 10 6452 1 2025-11-22 17:13:32.716 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:58744 10 6452 1 2025-11-22 17:14:33.130 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:45800 10 6452 1 2025-11-22 17:11:04.642 00:05:00.495 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-22 17:11:04.640 00:05:00.500 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-22 17:15:33.526 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:60984 10 6452 1 2025-11-22 17:16:22.269 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:16:22.235 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:16:22.173 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:16:22.187 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:16:22.114 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:16:33.897 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:45962 12 6556 1 2025-11-22 17:17:34.318 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:60872 10 6452 1 2025-11-22 17:18:34.721 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:42966 10 6452 1 2025-11-22 17:19:35.121 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46930 10 6452 1 2025-11-22 17:20:35.521 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:39070 10 6452 1 2025-11-22 17:17:04.641 00:05:00.499 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-22 17:17:04.644 00:05:00.494 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-22 17:21:22.079 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:21:22.118 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:21:22.142 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:21:22.140 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:21:22.225 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:21:35.957 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:38880 10 6452 1 2025-11-22 17:22:36.323 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:39764 10 6452 1 2025-11-22 17:23:36.731 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:52348 10 6452 1 2025-11-22 17:24:37.146 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:57992 10 6452 1 2025-11-22 17:25:37.553 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:50306 10 6452 1 2025-11-22 17:26:22.191 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:26:22.202 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:26:22.108 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:26:22.119 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:26:22.272 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:26:37.992 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:45804 10 6452 1 2025-11-22 17:23:04.650 00:05:00.494 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-22 17:23:04.647 00:05:00.500 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-22 17:27:38.404 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:39744 10 6452 1 2025-11-22 17:28:38.812 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:49508 10 6452 1 2025-11-22 17:29:39.227 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:54746 10 6452 1 2025-11-22 17:30:39.590 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:43528 10 6452 1 2025-11-22 17:31:22.329 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:31:22.583 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:31:22.280 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:31:22.248 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:31:22.455 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:31:39.994 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:38222 10 6452 1 2025-11-22 17:32:40.410 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:51808 10 6452 1 2025-11-22 17:29:04.651 00:05:00.495 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-22 17:29:04.649 00:05:00.499 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-22 17:33:40.813 00:00:10.891 TCP 1.101.0.1:3000 -> 23.104.0.1:38298 10 6452 1 2025-11-22 17:34:41.751 00:00:10.441 TCP 1.101.0.1:3000 -> 23.104.0.1:46712 14 10479 1 2025-11-22 17:35:42.231 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:45898 10 6452 1 2025-11-22 17:36:22.464 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:36:22.214 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:36:22.576 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:36:22.531 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:36:22.659 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:36:42.630 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:46440 10 6452 1 2025-11-22 17:37:42.994 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:40562 10 6452 1 2025-11-22 17:38:43.401 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:45998 10 6452 1 2025-11-22 17:35:04.654 00:05:00.494 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-22 17:35:04.651 00:05:00.500 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-22 17:39:43.814 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:40336 10 6452 1 2025-11-22 17:40:44.217 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:51580 10 6452 1 2025-11-22 17:41:22.640 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:41:22.608 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:41:22.394 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:41:22.558 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:41:22.487 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:41:44.622 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:60148 10 6452 1 2025-11-22 17:42:45.032 00:00:10.422 TCP 1.101.0.1:3000 -> 23.104.0.1:46780 10 6452 1 2025-11-22 17:43:45.491 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:53212 10 6452 1 2025-11-22 17:44:45.853 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:52436 10 6452 1 2025-11-22 17:41:04.652 00:05:00.500 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-22 17:41:04.654 00:05:00.495 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-22 17:45:46.274 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33402 10 6452 1 2025-11-22 17:46:23.209 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:46:23.075 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:46:23.059 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:46:23.054 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:46:23.143 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:46:46.680 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41236 10 6452 1 2025-11-22 17:47:47.109 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:34628 10 6452 1 2025-11-22 17:48:47.521 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59284 10 6452 1 2025-11-22 17:49:47.927 00:00:10.343 TCP 1.101.0.1:3000 -> 23.104.0.1:58900 10 6452 1 2025-11-22 17:50:48.311 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:41466 10 6452 1 2025-11-22 17:47:04.653 00:05:00.499 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-22 17:47:04.656 00:05:00.494 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-22 17:51:22.541 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:51:22.833 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:51:22.955 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:51:22.833 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:51:22.917 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:51:48.719 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:53112 10 6452 1 2025-11-22 17:52:49.138 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49214 10 6452 1 2025-11-22 17:53:49.544 00:00:10.337 TCP 1.101.0.1:3000 -> 23.104.0.1:56438 10 6452 1 2025-11-22 17:54:49.924 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:60314 10 6452 1 2025-11-22 17:55:50.340 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:49380 10 6452 1 2025-11-22 17:56:22.805 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-22 17:56:22.893 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:56:22.936 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-22 17:56:22.786 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-22 17:56:23.018 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-22 17:53:04.659 00:05:00.497 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-22 17:56:50.752 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:57268 10 6452 1 2025-11-22 17:53:04.656 00:05:00.503 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-22 17:57:51.155 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:40586 10 6452 1 Summary: total flows: 139, total bytes: 414783, total packets: 1018, avg bps: 937, avg pps: 0, avg bpp: 407 Time window: 2025-11-22 16:59:04 - 2025-11-22 17:58:05 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0042s User: 0.0000s Wall: 0.0021s flows/second: 67571.7 Runtime: 0.0021s