Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-25 10:59:40.946 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:49870 10 6452 1 2025-11-25 11:00:41.361 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:42842 10 6452 1 2025-11-25 11:01:41.731 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:53300 10 6452 1 2025-11-25 10:58:06.078 00:05:01.176 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 10:58:06.076 00:05:01.181 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 11:02:41.333 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:02:41.249 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:02:41.116 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:02:41.287 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:02:41.174 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:02:42.139 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:38048 10 6452 1 2025-11-25 11:03:42.542 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:33944 10 6452 1 2025-11-25 11:04:42.947 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:40806 10 6452 1 2025-11-25 11:05:43.351 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:35478 10 6452 1 2025-11-25 11:06:43.758 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:42912 10 6452 1 2025-11-25 11:07:41.317 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:07:41.131 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:07:41.309 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:07:41.303 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:07:41.391 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:07:44.182 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:36110 10 6452 1 2025-11-25 11:04:06.083 00:05:01.172 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 11:04:06.080 00:05:01.178 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 11:08:44.541 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:44090 10 6452 1 2025-11-25 11:09:44.947 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:52834 10 6452 1 2025-11-25 11:10:45.364 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:43182 10 6452 1 2025-11-25 11:11:45.763 00:00:10.455 TCP 1.101.0.1:3000 -> 23.104.0.1:41274 12 10375 1 2025-11-25 11:12:41.527 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:12:41.444 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:12:41.405 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:12:41.446 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:12:41.365 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:12:46.259 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:46628 10 6452 1 2025-11-25 11:13:46.618 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:41256 10 6452 1 2025-11-25 11:10:06.083 00:05:01.179 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 11:10:06.081 00:05:01.184 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 11:14:46.982 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:43746 10 6452 1 2025-11-25 11:15:47.385 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:49082 10 6452 1 2025-11-25 11:16:47.790 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:51918 10 6452 1 2025-11-25 11:17:41.414 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:17:41.245 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:17:41.570 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:17:41.538 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:17:41.654 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:17:48.195 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39826 10 6452 1 2025-11-25 11:18:48.602 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:44722 10 6452 1 2025-11-25 11:19:49.016 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37596 10 6452 1 2025-11-25 11:16:06.085 00:05:01.179 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 11:16:06.082 00:05:01.184 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 11:20:49.421 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:59802 10 6452 1 2025-11-25 11:21:49.818 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:56000 10 6452 1 2025-11-25 11:22:41.480 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:22:41.763 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:22:41.729 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:22:41.397 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:22:41.697 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:22:50.225 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:33194 10 6452 1 2025-11-25 11:23:50.626 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:45818 10 6452 1 2025-11-25 11:24:51.033 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:33796 10 6452 1 2025-11-25 11:25:51.434 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:37936 10 6452 1 2025-11-25 11:22:06.088 00:05:01.178 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 11:22:06.086 00:05:01.182 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 11:26:51.832 00:00:10.350 TCP 1.101.0.1:3000 -> 23.104.0.1:54060 10 6452 1 2025-11-25 11:27:41.815 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:27:41.372 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:27:41.811 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:27:41.808 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:27:41.893 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:27:52.225 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:43234 10 6452 1 2025-11-25 11:28:52.644 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:53198 10 6452 1 2025-11-25 11:29:53.063 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:42972 10 6452 1 2025-11-25 11:30:53.466 00:00:10.428 TCP 1.101.0.1:3000 -> 23.104.0.1:34296 12 6556 1 2025-11-25 11:31:53.931 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:55438 10 6452 1 2025-11-25 11:28:06.089 00:05:01.180 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 11:28:06.087 00:05:01.185 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 11:32:41.867 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:32:41.834 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:32:41.794 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:32:41.784 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:32:41.838 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:32:54.350 00:00:10.357 TCP 1.101.0.1:3000 -> 23.104.0.1:49034 10 6452 1 2025-11-25 11:33:54.745 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:60556 10 6452 1 2025-11-25 11:34:55.146 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:51048 10 6452 1 2025-11-25 11:35:55.510 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:44960 10 6452 1 2025-11-25 11:36:55.910 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33044 10 6452 1 2025-11-25 11:37:41.758 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:37:41.981 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:37:41.737 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:37:41.767 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:37:41.822 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:34:06.088 00:05:01.185 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 11:37:56.317 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:35950 10 6452 1 2025-11-25 11:34:06.090 00:05:01.180 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 11:38:56.720 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:45304 10 6452 1 2025-11-25 11:39:57.134 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:44618 10 6452 1 2025-11-25 11:40:57.540 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:54276 10 6452 1 2025-11-25 11:41:57.911 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:37794 10 6452 1 2025-11-25 11:42:41.930 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:42:41.943 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:42:41.848 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:42:42.144 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:42:42.273 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:42:58.322 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:50354 10 6452 1 2025-11-25 11:40:06.089 00:05:01.185 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 11:43:58.725 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:39002 10 6452 1 2025-11-25 11:40:06.092 00:05:01.180 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 11:44:59.134 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:40404 10 6452 1 2025-11-25 11:45:59.504 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:50644 10 6452 1 2025-11-25 11:46:59.908 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:51236 10 6452 1 2025-11-25 11:47:42.249 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:47:41.948 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:47:41.763 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:47:42.166 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:47:42.268 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:48:00.274 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:48138 12 6556 1 2025-11-25 11:49:00.681 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:50738 10 6452 1 2025-11-25 11:46:06.090 00:05:01.187 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 11:46:06.092 00:05:01.183 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 11:50:01.046 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46726 10 6452 1 2025-11-25 11:51:01.453 00:00:10.434 TCP 1.101.0.1:3000 -> 23.104.0.1:40426 12 10369 1 2025-11-25 11:52:01.922 00:00:10.393 TCP 1.101.0.1:3000 -> 23.104.0.1:60198 10 6452 1 2025-11-25 11:52:42.326 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:52:41.985 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:52:42.100 00:00:00.031 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:52:42.363 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:52:42.183 00:00:00.031 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:53:02.354 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:44066 10 6452 1 2025-11-25 11:54:02.755 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:40888 10 6452 1 2025-11-25 11:55:03.120 00:00:10.347 TCP 1.101.0.1:3000 -> 23.104.0.1:49406 10 6452 1 2025-11-25 11:52:06.093 00:05:01.185 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 11:52:06.095 00:05:01.180 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 11:56:03.519 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:46362 10 6452 1 2025-11-25 11:57:03.922 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:39016 10 6452 1 2025-11-25 11:57:42.523 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 11:57:42.312 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 11:57:42.418 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:57:42.440 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 11:57:42.385 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 11:58:04.294 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:46280 10 6452 1 Summary: total flows: 139, total bytes: 418596, total packets: 1018, avg bps: 928, avg pps: 0, avg bpp: 411 Time window: 2025-11-25 10:58:06 - 2025-11-25 11:58:14 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0036s User: 0.0018s Wall: 0.0024s flows/second: 57626.6 Runtime: 0.0024s