Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-24 21:59:04.598 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:34268 10 6452 1 2025-11-24 22:00:04.996 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48738 10 6452 1 2025-11-24 22:01:05.397 00:00:10.572 TCP 1.101.0.1:3000 -> 23.104.0.1:42886 12 10375 1 2025-11-24 21:58:05.773 00:05:01.046 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 21:58:05.775 00:05:01.042 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 22:02:06.012 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33860 10 6452 1 2025-11-24 22:02:25.482 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:02:25.477 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:02:25.607 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:02:25.484 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:02:25.689 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:03:06.417 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:46474 10 6452 1 2025-11-24 22:04:06.834 00:00:10.417 TCP 1.101.0.1:3000 -> 23.104.0.1:37720 10 6452 1 2025-11-24 22:05:07.285 00:00:10.341 TCP 1.101.0.1:3000 -> 23.104.0.1:42566 10 6452 1 2025-11-24 22:06:07.666 00:00:10.442 TCP 1.101.0.1:3000 -> 23.104.0.1:45674 12 10584 1 2025-11-24 22:07:08.150 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:39226 10 6661 1 2025-11-24 22:07:25.664 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:07:25.445 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:07:25.603 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:07:25.600 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:07:25.687 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:04:05.775 00:05:01.045 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 22:04:05.778 00:05:01.041 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 22:08:08.560 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:54976 10 6661 1 2025-11-24 22:09:08.970 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:48468 10 6661 1 2025-11-24 22:10:09.376 00:00:10.771 TCP 1.101.0.1:3000 -> 23.104.0.1:55362 10 6661 1 2025-11-24 22:11:10.190 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:52038 10 6661 1 2025-11-24 22:12:10.602 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:34446 10 6661 1 2025-11-24 22:12:25.553 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:12:25.697 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:12:25.782 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:12:25.471 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:12:25.857 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:13:10.966 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:43848 10 6661 1 2025-11-24 22:10:05.776 00:05:01.046 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 22:10:05.777 00:05:01.042 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 22:14:11.370 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:48330 10 6661 1 2025-11-24 22:15:11.768 00:00:10.436 TCP 1.101.0.1:3000 -> 23.104.0.1:44356 11 6713 1 2025-11-24 22:16:12.244 00:00:10.446 TCP 1.101.0.1:3000 -> 23.104.0.1:42686 12 10793 1 2025-11-24 22:17:12.737 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35804 10 6870 1 2025-11-24 22:17:25.970 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:17:26.054 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:17:26.108 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:17:26.054 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:17:26.189 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:18:13.139 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:35686 10 6870 1 2025-11-24 22:19:13.511 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:40148 10 6870 1 2025-11-24 22:16:05.780 00:05:01.041 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 22:16:05.779 00:05:01.045 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 22:20:13.919 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:55518 10 6870 1 2025-11-24 22:21:14.318 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:60378 10 6870 1 2025-11-24 22:22:25.892 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:22:14.711 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:54658 10 6870 1 2025-11-24 22:22:26.275 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:22:26.059 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:22:26.193 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:22:26.001 00:00:00.028 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:23:15.107 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:40320 10 6870 1 2025-11-24 22:24:15.524 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:40274 10 6870 1 2025-11-24 22:25:15.924 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:36694 10 6870 1 2025-11-24 22:22:05.782 00:05:01.043 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 22:22:05.784 00:05:01.038 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 22:26:16.350 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:58322 10 6870 1 2025-11-24 22:27:26.313 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:27:16.761 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:54072 10 6870 1 2025-11-24 22:27:26.030 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:27:26.105 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:27:26.230 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:27:26.010 00:00:00.036 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:28:17.138 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:47688 10 6870 1 2025-11-24 22:29:17.545 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46806 10 6870 1 2025-11-24 22:30:17.950 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:43504 10 6870 1 2025-11-24 22:31:18.358 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:34310 10 6870 1 2025-11-24 22:28:05.788 00:05:01.035 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 22:28:05.786 00:05:01.040 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 22:32:26.264 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:32:26.182 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:32:26.148 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:32:18.765 00:00:10.388 TCP 1.101.0.1:3000 -> 23.104.0.1:40718 10 6870 1 2025-11-24 22:32:26.182 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:32:26.101 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:33:19.187 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:57050 10 6870 1 2025-11-24 22:34:19.550 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:48536 10 6870 1 2025-11-24 22:35:19.909 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:55814 10 6870 1 2025-11-24 22:36:20.317 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48486 10 6870 1 2025-11-24 22:37:26.310 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:37:26.311 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:37:26.075 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:37:26.229 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:37:26.299 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:37:20.738 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:55388 10 6870 1 2025-11-24 22:34:05.788 00:05:01.035 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 22:34:05.786 00:05:01.041 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 22:38:21.153 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40572 10 6870 1 2025-11-24 22:39:21.572 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:55750 10 6870 1 2025-11-24 22:40:21.982 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:59826 10 6870 1 2025-11-24 22:41:22.398 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:55312 10 6870 1 2025-11-24 22:42:26.328 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:42:26.433 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:42:26.412 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:42:26.419 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:42:26.517 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:42:22.799 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:59826 10 6870 1 2025-11-24 22:43:23.209 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:50822 10 6870 1 2025-11-24 22:40:05.789 00:05:01.040 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 22:40:05.791 00:05:01.035 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 22:44:23.612 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:40690 10 6870 1 2025-11-24 22:45:24.021 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:49684 10 6870 1 2025-11-24 22:46:24.431 00:00:10.437 TCP 1.101.0.1:3000 -> 23.104.0.1:33848 12 10787 1 2025-11-24 22:47:26.416 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:47:26.510 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:47:26.564 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:47:26.253 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:47:26.498 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:47:24.911 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:53206 10 6870 1 2025-11-24 22:48:25.316 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:57804 10 6870 1 2025-11-24 22:49:25.723 00:00:11.046 TCP 1.101.0.1:3000 -> 23.104.0.1:44656 10 6870 1 2025-11-24 22:46:05.794 00:05:01.035 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 22:46:05.792 00:05:01.040 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 22:50:26.808 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:56838 10 6870 1 2025-11-24 22:51:27.218 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:36432 10 6870 1 2025-11-24 22:52:26.742 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:52:26.490 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:52:26.321 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:52:26.659 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:52:26.569 00:00:00.032 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:52:27.622 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:41902 10 6870 1 2025-11-24 22:53:28.029 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:34508 10 6870 1 2025-11-24 22:54:28.434 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:34704 10 6870 1 2025-11-24 22:55:28.798 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40822 10 6870 1 2025-11-24 22:52:05.794 00:05:01.037 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-24 22:52:05.791 00:05:01.043 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-24 22:56:29.205 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:32860 10 6870 1 2025-11-24 22:57:26.599 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:57:26.758 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-24 22:57:26.600 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-24 22:57:26.631 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-24 22:57:26.682 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-24 22:57:29.573 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:57306 10 6870 1 2025-11-24 22:58:29.977 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:45460 10 6870 1 Summary: total flows: 140, total bytes: 452802, total packets: 1029, avg bps: 996, avg pps: 0, avg bpp: 440 Time window: 2025-11-24 21:58:05 - 2025-11-24 22:58:40 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0053s User: 0.0009s Wall: 0.0036s flows/second: 39401.6 Runtime: 0.0036s