Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-24 04:58:52.792 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:37530 10 6661 1 2025-11-24 04:59:53.202 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35100 10 6661 1 2025-11-24 05:00:53.602 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:58200 10 6661 1 2025-11-24 05:01:53.971 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:58686 10 6661 1 2025-11-24 05:02:05.600 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:02:05.383 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:02:05.532 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:02:05.222 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 04:58:05.402 00:05:00.964 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 05:02:05.617 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 04:58:05.401 00:05:00.969 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 05:02:54.389 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:48770 10 6661 1 2025-11-24 05:03:54.787 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:35376 10 6661 1 2025-11-24 05:04:55.195 00:00:10.357 TCP 1.101.0.1:3000 -> 23.104.0.1:36534 10 6661 1 2025-11-24 05:05:55.590 00:00:18.639 TCP 1.101.0.1:3000 -> 23.104.0.1:45262 10 6661 1 2025-11-24 05:07:05.272 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:07:05.249 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:07:05.147 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:07:05.190 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:07:05.178 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:07:04.268 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:60632 12 6765 1 2025-11-24 05:04:05.402 00:05:00.968 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 05:04:05.404 00:05:00.963 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 05:08:04.674 00:00:10.953 TCP 1.101.0.1:3000 -> 23.104.0.1:53202 10 6661 1 2025-11-24 05:09:05.664 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:59610 10 6661 1 2025-11-24 05:10:06.091 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:51162 10 6661 1 2025-11-24 05:11:06.492 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:40476 10 6661 1 2025-11-24 05:12:05.338 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:12:05.310 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:12:05.333 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:12:05.427 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:12:05.416 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:12:06.892 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:39548 10 6661 1 2025-11-24 05:13:07.308 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:60492 10 6661 1 2025-11-24 05:10:05.409 00:05:00.959 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 05:10:05.407 00:05:00.964 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 05:14:07.712 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:52892 10 6661 1 2025-11-24 05:15:08.102 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:59150 10 6661 1 2025-11-24 05:16:08.511 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:45796 10 6661 1 2025-11-24 05:17:05.384 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:17:05.325 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:17:05.331 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:17:05.461 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:17:05.408 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:17:08.874 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:43988 10 6661 1 2025-11-24 05:18:09.286 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:37118 10 6661 1 2025-11-24 05:19:09.657 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:56626 10 6661 1 2025-11-24 05:16:05.407 00:05:00.965 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 05:16:05.409 00:05:00.960 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 05:20:10.063 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:34432 10 6661 1 2025-11-24 05:21:10.461 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:56358 10 6661 1 2025-11-24 05:22:05.414 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:22:05.356 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:22:05.206 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:22:05.482 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:22:05.288 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:22:10.862 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:60104 10 6661 1 2025-11-24 05:23:11.275 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49088 10 6661 1 2025-11-24 05:24:11.678 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:34368 10 6661 1 2025-11-24 05:25:12.105 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:53102 10 6661 1 2025-11-24 05:22:05.408 00:05:00.965 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 05:22:05.412 00:05:00.959 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 05:26:12.524 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:56882 10 6661 1 2025-11-24 05:27:06.142 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:27:06.072 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:27:06.268 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:27:06.077 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:27:06.351 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:27:12.925 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:34208 10 6661 1 2025-11-24 05:28:13.344 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:52030 10 6661 1 2025-11-24 05:29:13.744 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:43284 10 6661 1 2025-11-24 05:30:14.150 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:53600 10 6661 1 2025-11-24 05:31:14.554 00:00:10.451 TCP 1.101.0.1:3000 -> 23.104.0.1:49454 12 10369 1 2025-11-24 05:32:05.779 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:28:05.410 00:05:00.964 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 05:32:05.828 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:32:05.343 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:32:05.696 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:32:05.597 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:28:05.413 00:05:00.959 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 05:32:15.051 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:43268 10 6452 1 2025-11-24 05:33:15.453 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:37338 10 6452 1 2025-11-24 05:34:15.864 00:00:10.409 TCP 1.101.0.1:3000 -> 23.104.0.1:41240 10 6452 1 2025-11-24 05:35:16.274 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:45272 10 6452 1 2025-11-24 05:36:16.681 00:00:10.802 TCP 1.101.0.1:3000 -> 23.104.0.1:44144 10 6452 1 2025-11-24 05:37:05.899 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:37:05.681 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:37:05.740 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:37:05.811 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:37:05.824 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:37:17.532 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:39200 10 6452 1 2025-11-24 05:34:05.414 00:05:00.959 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 05:34:05.411 00:05:00.964 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 05:38:17.932 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:45598 11 6492 1 2025-11-24 05:39:18.351 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:59396 10 6452 1 2025-11-24 05:40:18.755 00:00:10.454 TCP 1.101.0.1:3000 -> 23.104.0.1:43378 10 6452 1 2025-11-24 05:41:19.250 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:38902 10 6452 1 2025-11-24 05:42:05.922 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:42:05.972 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:42:05.506 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:42:05.838 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:42:06.050 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:42:19.652 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54612 10 6452 1 2025-11-24 05:43:20.066 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:54262 10 6452 1 2025-11-24 05:40:05.417 00:05:00.957 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 05:40:05.414 00:05:00.961 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 05:44:20.471 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:37936 10 6452 1 2025-11-24 05:45:20.875 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35342 10 6452 1 2025-11-24 05:46:21.286 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:43800 10 6452 1 2025-11-24 05:47:06.347 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:47:06.100 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:47:06.231 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:47:06.265 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:47:06.198 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:47:21.692 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:36688 10 6452 1 2025-11-24 05:48:22.108 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:40770 10 6452 1 2025-11-24 05:49:22.503 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:38698 10 6452 1 2025-11-24 05:46:05.419 00:05:00.954 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 05:46:05.417 00:05:00.960 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 05:50:22.910 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:59122 12 6556 1 2025-11-24 05:51:23.326 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:43646 10 6452 1 2025-11-24 05:52:05.902 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:52:05.819 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:52:06.111 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:52:06.066 00:00:00.030 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:52:06.161 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:52:23.731 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:58656 10 6452 1 2025-11-24 05:53:24.142 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:56458 10 6452 1 2025-11-24 05:54:24.545 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:51910 10 6452 1 2025-11-24 05:55:24.949 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:45398 10 6452 1 2025-11-24 05:52:05.418 00:05:00.960 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 05:52:05.421 00:05:00.955 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 05:56:25.359 00:00:10.586 TCP 1.101.0.1:3000 -> 23.104.0.1:56062 10 6452 1 2025-11-24 05:57:05.937 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:57:06.132 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 05:57:06.229 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 05:57:06.141 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 05:57:06.229 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 05:57:25.986 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:33854 10 6452 1 2025-11-24 05:58:26.390 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:48636 10 6452 1 Summary: total flows: 140, total bytes: 427853, total packets: 1027, avg bps: 942, avg pps: 0, avg bpp: 416 Time window: 2025-11-24 04:58:05 - 2025-11-24 05:58:36 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0050s User: 0.0010s Wall: 0.0020s flows/second: 70038.5 Runtime: 0.0020s