Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-25 00:59:22.421 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:46052 10 6452 1 2025-11-25 01:00:22.826 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:58264 10 6452 1 2025-11-25 01:01:23.229 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:34904 10 6452 1 2025-11-25 00:58:05.835 00:05:01.066 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 00:58:05.833 00:05:01.071 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 01:02:29.370 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:02:29.059 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:02:29.541 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:02:29.576 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:02:29.624 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:02:23.588 00:00:10.748 TCP 1.101.0.1:3000 -> 23.104.0.1:58556 10 6452 1 2025-11-25 01:03:24.374 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:37266 10 6452 1 2025-11-25 01:04:24.778 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:55022 10 6452 1 2025-11-25 01:05:25.144 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:46782 10 6452 1 2025-11-25 01:06:25.542 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:42472 10 6452 1 2025-11-25 01:07:28.998 00:00:00.047 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:07:28.946 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:07:29.008 00:00:00.039 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:07:28.897 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:07:29.090 00:00:00.040 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:07:25.907 00:00:18.805 TCP 1.101.0.1:3000 -> 23.104.0.1:55724 10 6452 1 2025-11-25 01:04:05.837 00:05:01.068 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 01:04:05.835 00:05:01.073 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 01:08:34.749 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:40476 10 6452 1 2025-11-25 01:09:35.152 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:32880 10 6452 1 2025-11-25 01:10:35.552 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46394 10 6452 1 2025-11-25 01:11:35.957 00:00:10.446 TCP 1.101.0.1:3000 -> 23.104.0.1:50554 12 10375 1 2025-11-25 01:12:29.403 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:12:29.318 00:00:00.031 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:12:29.368 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:12:29.321 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:12:29.482 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:12:36.446 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:56378 10 6452 1 2025-11-25 01:13:36.848 00:00:10.404 TCP 1.101.0.1:3000 -> 23.104.0.1:35042 10 6452 1 2025-11-25 01:10:05.839 00:05:01.067 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 01:10:05.835 00:05:01.073 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 01:14:37.274 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:43118 10 6452 1 2025-11-25 01:15:37.680 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:38464 10 6452 1 2025-11-25 01:16:38.052 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:40872 10 6452 1 2025-11-25 01:17:29.532 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:17:29.467 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:17:29.413 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:17:29.406 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:17:29.496 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:17:38.418 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:54150 10 6452 1 2025-11-25 01:18:38.823 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:36780 10 6452 1 2025-11-25 01:19:39.226 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:54928 10 6452 1 2025-11-25 01:16:05.838 00:05:01.072 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 01:16:05.842 00:05:01.066 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 01:20:39.630 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:47002 10 6452 1 2025-11-25 01:21:40.028 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:33954 10 6452 1 2025-11-25 01:22:29.918 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:22:29.776 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:22:29.836 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:22:29.919 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:22:29.920 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:22:40.387 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:54416 10 6452 1 2025-11-25 01:23:40.785 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:54040 10 6452 1 2025-11-25 01:24:41.191 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58302 10 6452 1 2025-11-25 01:25:41.592 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:57520 10 6452 1 2025-11-25 01:22:05.840 00:05:01.083 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 01:22:05.842 00:05:01.077 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 01:26:41.997 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:52468 10 6452 1 2025-11-25 01:27:29.557 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:27:29.646 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:27:29.658 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:27:29.475 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:27:29.757 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:27:42.398 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:37792 10 6452 1 2025-11-25 01:28:42.805 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:57158 10 6452 1 2025-11-25 01:29:43.227 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:33574 10 6452 1 2025-11-25 01:30:43.627 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:48046 10 6452 1 2025-11-25 01:31:43.988 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:34424 10 6452 1 2025-11-25 01:28:05.840 00:05:01.081 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 01:28:05.845 00:05:01.075 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 01:32:29.920 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:32:29.744 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:32:29.921 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:32:29.837 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:32:29.836 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:32:44.398 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:58950 10 6452 1 2025-11-25 01:33:44.817 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:57980 10 6452 1 2025-11-25 01:34:45.249 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:55418 10 6452 1 2025-11-25 01:35:45.653 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:39430 10 6452 1 2025-11-25 01:36:46.068 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:47448 10 6452 1 2025-11-25 01:37:29.833 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:37:29.876 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:37:29.753 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:37:29.682 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:37:29.836 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:37:46.476 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36980 10 6452 1 2025-11-25 01:34:05.842 00:05:01.082 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 01:34:05.844 00:05:01.077 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 01:38:46.892 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:57982 12 6556 1 2025-11-25 01:39:47.307 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:45826 10 6452 1 2025-11-25 01:40:47.707 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:41910 10 6452 1 2025-11-25 01:41:48.113 00:00:10.318 TCP 1.101.0.1:3000 -> 23.104.0.1:34526 10 6452 1 2025-11-25 01:42:30.157 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:42:30.313 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:42:30.342 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:42:30.260 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:42:30.425 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:42:48.469 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:46300 10 6452 1 2025-11-25 01:43:48.867 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:51382 10 6452 1 2025-11-25 01:40:05.842 00:05:01.083 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 01:40:05.845 00:05:01.078 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 01:44:49.277 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:38074 10 6452 1 2025-11-25 01:45:49.680 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:39516 10 6452 1 2025-11-25 01:46:50.048 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:34354 10 6452 1 2025-11-25 01:47:29.860 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:47:30.076 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:47:30.043 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:47:30.160 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:47:30.124 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:47:50.410 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:44468 10 6452 1 2025-11-25 01:48:50.775 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:54978 10 6452 1 2025-11-25 01:49:51.175 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:56316 10 6452 1 2025-11-25 01:46:05.847 00:05:01.076 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 01:46:05.844 00:05:01.081 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 01:50:51.535 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:52100 10 6452 1 2025-11-25 01:51:51.944 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:36284 10 6452 1 2025-11-25 01:52:30.245 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:52:30.302 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:52:30.193 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:52:30.162 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:52:30.270 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:52:52.357 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52612 10 6452 1 2025-11-25 01:53:52.763 00:00:10.534 TCP 1.101.0.1:3000 -> 23.104.0.1:49884 12 6556 1 2025-11-25 01:54:53.338 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:42344 10 6452 1 2025-11-25 01:55:53.744 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:33296 10 6452 1 2025-11-25 01:52:05.846 00:05:01.081 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 01:52:05.850 00:05:01.076 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 01:56:54.149 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53778 10 6452 1 2025-11-25 01:57:30.387 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 01:57:30.307 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 01:57:30.165 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:57:30.303 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 01:57:30.104 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 01:57:54.548 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:35184 10 6452 1 Summary: total flows: 139, total bytes: 414679, total packets: 1016, avg bps: 921, avg pps: 0, avg bpp: 408 Time window: 2025-11-25 00:58:05 - 2025-11-25 01:58:04 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0053s User: 0.0011s Wall: 0.0024s flows/second: 57866.8 Runtime: 0.0024s