Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-25 09:59:15.386 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:52104 10 6452 1 2025-11-25 10:00:15.747 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:43278 10 6452 1 2025-11-25 10:01:16.151 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:44172 10 6452 1 2025-11-25 09:58:06.051 00:05:01.175 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 09:58:06.054 00:05:01.170 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:02:16.554 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:53066 10 6452 1 2025-11-25 10:02:40.041 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:02:40.074 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:02:39.968 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:02:39.958 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:02:40.069 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:03:16.960 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:49306 10 6452 1 2025-11-25 10:04:17.388 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:50050 10 6452 1 2025-11-25 10:05:17.769 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:46706 10 6452 1 2025-11-25 10:06:18.175 00:00:10.523 TCP 1.101.0.1:3000 -> 23.104.0.1:42374 10 6452 1 2025-11-25 10:07:18.737 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:36504 10 6452 1 2025-11-25 10:07:40.110 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:07:40.115 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:07:40.171 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:07:40.246 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:07:40.255 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:04:06.059 00:05:01.166 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:04:06.057 00:05:01.171 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 10:08:19.148 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:43932 10 6452 1 2025-11-25 10:09:19.552 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47390 10 6452 1 2025-11-25 10:10:19.953 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:44086 10 6452 1 2025-11-25 10:11:20.359 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:35496 10 6452 1 2025-11-25 10:12:20.764 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:43892 10 6452 1 2025-11-25 10:12:40.444 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:12:40.517 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:12:40.505 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:12:40.391 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:12:40.587 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:13:21.130 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:50388 10 6452 1 2025-11-25 10:10:06.058 00:05:01.176 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 10:10:06.060 00:05:01.172 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:14:21.543 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:39176 10 6452 1 2025-11-25 10:15:21.903 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:46736 10 6452 1 2025-11-25 10:16:22.274 00:00:10.451 TCP 1.101.0.1:3000 -> 23.104.0.1:41692 12 10369 1 2025-11-25 10:17:22.770 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:51330 10 6452 1 2025-11-25 10:17:40.100 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:17:40.266 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:17:40.351 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:17:40.420 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:17:40.434 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:18:23.174 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:57476 10 6452 1 2025-11-25 10:19:23.576 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:42548 10 6452 1 2025-11-25 10:16:06.065 00:05:01.171 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:16:06.062 00:05:01.177 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 10:20:23.978 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:36112 10 6452 1 2025-11-25 10:21:24.382 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:57588 10 6452 1 2025-11-25 10:22:24.791 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39822 10 6452 1 2025-11-25 10:22:40.588 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:22:40.500 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:22:40.228 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:22:40.502 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:22:40.281 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:23:25.189 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:50074 10 6452 1 2025-11-25 10:24:25.592 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54828 10 6452 1 2025-11-25 10:25:25.992 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:40002 10 6452 1 2025-11-25 10:22:06.067 00:05:01.171 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:22:06.066 00:05:01.176 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 10:26:26.427 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:38232 10 6452 1 2025-11-25 10:27:40.557 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:27:40.513 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:27:40.554 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:27:40.618 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:27:26.834 00:00:10.438 TCP 1.101.0.1:3000 -> 23.104.0.1:55026 11 6504 1 2025-11-25 10:27:40.637 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:28:27.315 00:00:11.056 TCP 1.101.0.1:3000 -> 23.104.0.1:59714 10 6452 1 2025-11-25 10:29:28.407 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:34850 10 6452 1 2025-11-25 10:30:28.809 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54370 10 6452 1 2025-11-25 10:31:29.208 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:38270 10 6452 1 2025-11-25 10:28:06.070 00:05:01.172 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:28:06.066 00:05:01.177 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 10:32:40.753 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:32:40.751 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:32:40.635 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:32:40.669 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:32:40.507 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:32:29.566 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:44202 10 6452 1 2025-11-25 10:33:29.969 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:40278 10 6452 1 2025-11-25 10:34:30.395 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:37804 10 6452 1 2025-11-25 10:35:30.770 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:60330 10 6452 1 2025-11-25 10:36:31.177 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:52182 10 6452 1 2025-11-25 10:37:40.839 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:37:40.749 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:37:40.499 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:37:40.758 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:37:40.684 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:37:31.581 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:54528 10 6452 1 2025-11-25 10:34:06.071 00:05:01.172 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:34:06.069 00:05:01.176 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 10:38:31.992 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48540 10 6452 1 2025-11-25 10:39:32.397 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:39830 10 6452 1 2025-11-25 10:40:32.801 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39574 10 6452 1 2025-11-25 10:41:33.201 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48136 10 6452 1 2025-11-25 10:42:40.842 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:42:40.781 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:42:40.893 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:42:40.774 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:42:40.977 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:42:33.604 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37368 10 6452 1 2025-11-25 10:43:34.013 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:33204 10 6452 1 2025-11-25 10:40:06.073 00:05:01.170 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:40:06.070 00:05:01.175 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 10:44:34.371 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:51588 10 6452 1 2025-11-25 10:45:34.771 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:45206 10 6452 1 2025-11-25 10:46:35.183 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:46390 10 6452 1 2025-11-25 10:47:40.835 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:47:40.658 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:47:40.929 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:47:40.973 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:47:41.012 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:47:35.578 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:46040 10 6452 1 2025-11-25 10:48:35.978 00:00:10.909 TCP 1.101.0.1:3000 -> 23.104.0.1:47478 10 6452 1 2025-11-25 10:49:36.931 00:00:10.398 TCP 1.101.0.1:3000 -> 23.104.0.1:49074 10 6452 1 2025-11-25 10:46:06.072 00:05:01.181 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 10:46:06.075 00:05:01.177 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:50:37.378 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40274 10 6452 1 2025-11-25 10:51:37.780 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:60928 10 6452 1 2025-11-25 10:52:40.984 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:52:41.133 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:52:41.138 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:52:41.134 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:52:41.220 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:52:38.188 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:59598 10 6452 1 2025-11-25 10:53:38.590 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:39064 10 6452 1 2025-11-25 10:54:38.998 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:40642 10 6452 1 2025-11-25 10:55:39.401 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:54896 10 6452 1 2025-11-25 10:52:06.076 00:05:01.176 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:52:06.076 00:05:01.181 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 10:56:39.765 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:42078 10 6452 1 2025-11-25 10:57:41.403 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 10:57:41.179 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:57:41.281 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 10:57:41.278 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 10:57:41.364 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 10:57:40.179 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:59496 10 6452 1 2025-11-25 10:58:40.561 00:00:10.341 TCP 1.101.0.1:3000 -> 23.104.0.1:60184 10 6452 1 Summary: total flows: 140, total bytes: 420969, total packets: 1023, avg bps: 923, avg pps: 0, avg bpp: 411 Time window: 2025-11-25 09:58:06 - 2025-11-25 10:58:50 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0032s User: 0.0022s Wall: 0.0019s flows/second: 74907.8 Runtime: 0.0019s