Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-25 11:59:04.690 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:51438 10 6452 1 2025-11-25 12:00:05.108 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:50154 10 6452 1 2025-11-25 12:01:05.513 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:53834 10 6452 1 2025-11-25 11:58:06.098 00:05:01.181 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 11:58:06.096 00:05:01.187 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 12:02:05.922 00:00:10.344 TCP 1.101.0.1:3000 -> 23.104.0.1:35588 10 6452 1 2025-11-25 12:02:42.387 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:02:42.517 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:02:42.210 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:02:42.305 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:02:42.380 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:03:06.304 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:47740 10 6452 1 2025-11-25 12:04:06.702 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:45890 10 6452 1 2025-11-25 12:05:07.071 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:60786 10 6452 1 2025-11-25 12:06:07.431 00:00:10.402 TCP 1.101.0.1:3000 -> 23.104.0.1:52278 12 10375 1 2025-11-25 12:07:07.869 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:58858 10 6452 1 2025-11-25 12:07:42.640 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:07:42.573 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:07:42.629 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:07:42.633 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:07:42.712 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:04:06.099 00:05:01.182 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 12:04:06.097 00:05:01.187 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 12:08:08.297 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:52072 10 6452 1 2025-11-25 12:09:08.703 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:42040 10 6452 1 2025-11-25 12:10:09.113 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:46030 10 6452 1 2025-11-25 12:11:09.480 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:33880 10 6452 1 2025-11-25 12:12:09.893 00:00:11.290 TCP 1.101.0.1:3000 -> 23.104.0.1:35338 12 6556 1 2025-11-25 12:12:42.779 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:12:42.742 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:12:42.575 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:12:42.696 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:12:42.741 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:13:11.220 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:53046 10 6452 1 2025-11-25 12:10:06.097 00:05:01.187 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 12:10:06.099 00:05:01.183 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 12:14:11.621 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:50366 10 6452 1 2025-11-25 12:15:12.029 00:00:10.342 TCP 1.101.0.1:3000 -> 23.104.0.1:48678 10 6452 1 2025-11-25 12:16:12.402 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39180 10 6452 1 2025-11-25 12:17:12.798 00:00:10.342 TCP 1.101.0.1:3000 -> 23.104.0.1:58936 10 6452 1 2025-11-25 12:17:42.854 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:17:42.706 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:17:42.549 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:17:42.772 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:17:42.770 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:18:13.177 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:47808 10 6452 1 2025-11-25 12:19:13.579 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:46046 10 6452 1 2025-11-25 12:16:06.101 00:05:01.182 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 12:16:06.099 00:05:01.187 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 12:20:13.980 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:34138 10 6452 1 2025-11-25 12:21:14.387 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:40174 10 6452 1 2025-11-25 12:22:14.791 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:38832 10 6452 1 2025-11-25 12:22:43.111 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:22:42.890 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:22:43.174 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:22:43.117 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:22:43.258 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:23:15.200 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:53314 10 6452 1 2025-11-25 12:24:15.564 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39078 10 6452 1 2025-11-25 12:25:15.965 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:51074 10 6452 1 2025-11-25 12:22:06.100 00:05:01.187 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 12:22:06.102 00:05:01.182 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 12:26:16.364 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36178 10 6452 1 2025-11-25 12:27:16.772 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:53852 10 6452 1 2025-11-25 12:27:43.032 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:27:42.961 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:27:42.976 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:27:42.949 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:27:42.958 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:28:17.195 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:41570 10 6452 1 2025-11-25 12:29:17.598 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:58062 10 6452 1 2025-11-25 12:30:18.001 00:00:10.887 TCP 1.101.0.1:3000 -> 23.104.0.1:37496 10 6452 1 2025-11-25 12:31:18.930 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:55664 10 6452 1 2025-11-25 12:28:06.103 00:05:01.182 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 12:28:06.102 00:05:01.187 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 12:32:19.356 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59574 10 6452 1 2025-11-25 12:32:43.136 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:32:43.133 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:32:42.954 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:32:43.088 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:32:43.039 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:33:19.762 00:00:10.692 TCP 1.101.0.1:3000 -> 23.104.0.1:53264 10 6452 1 2025-11-25 12:34:20.500 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58770 10 6452 1 2025-11-25 12:35:20.904 00:00:10.727 TCP 1.101.0.1:3000 -> 23.104.0.1:57750 12 6556 1 2025-11-25 12:36:21.669 00:00:10.452 TCP 1.101.0.1:3000 -> 23.104.0.1:53370 12 10375 1 2025-11-25 12:37:22.160 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:37486 10 6452 1 2025-11-25 12:37:43.297 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:37:42.931 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:37:43.257 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:37:43.247 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:37:43.339 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:34:06.107 00:05:01.184 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 12:34:06.106 00:05:01.190 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 12:38:22.560 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:33692 10 6452 1 2025-11-25 12:39:22.955 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:51720 10 6452 1 2025-11-25 12:40:23.366 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:42646 10 6452 1 2025-11-25 12:41:23.770 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:38952 10 6452 1 2025-11-25 12:42:24.181 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:46776 10 6452 1 2025-11-25 12:42:43.278 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:42:43.257 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:42:43.201 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:42:43.195 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:42:42.976 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:43:24.566 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:38016 10 6452 1 2025-11-25 12:40:06.105 00:05:01.190 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 12:40:06.108 00:05:01.185 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 12:44:24.974 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:52132 10 6452 1 2025-11-25 12:45:25.382 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59556 10 6452 1 2025-11-25 12:46:25.780 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:47404 10 6452 1 2025-11-25 12:47:26.196 00:00:10.355 TCP 1.101.0.1:3000 -> 23.104.0.1:45128 10 6452 1 2025-11-25 12:47:43.411 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:47:43.447 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:47:43.673 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:47:43.493 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:47:43.756 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:48:26.557 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:43062 10 6452 1 2025-11-25 12:49:26.962 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:54406 10 6452 1 2025-11-25 12:46:06.111 00:05:01.187 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 12:46:06.108 00:05:01.192 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 12:50:27.326 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40990 10 6452 1 2025-11-25 12:51:27.727 00:00:11.033 TCP 1.101.0.1:3000 -> 23.104.0.1:52980 10 6452 1 2025-11-25 12:52:28.799 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54648 10 6452 1 2025-11-25 12:52:43.513 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:52:43.448 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:52:43.352 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:52:43.355 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:52:43.433 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:53:29.206 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:59094 10 6452 1 2025-11-25 12:54:29.609 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:38466 10 6452 1 2025-11-25 12:55:29.982 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:51164 10 6452 1 2025-11-25 12:52:06.110 00:05:01.190 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 12:52:06.108 00:05:01.195 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 12:56:30.386 00:00:10.431 TCP 1.101.0.1:3000 -> 23.104.0.1:46878 12 10375 1 2025-11-25 12:57:43.619 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 12:57:43.385 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:57:30.860 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:51260 10 6452 1 2025-11-25 12:57:43.538 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 12:57:43.618 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 12:57:43.620 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 12:58:31.273 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:60538 10 6452 1 Summary: total flows: 140, total bytes: 428977, total packets: 1030, avg bps: 943, avg pps: 0, avg bpp: 416 Time window: 2025-11-25 11:58:06 - 2025-11-25 12:58:41 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0050s User: 0.0000s Wall: 0.0020s flows/second: 68598.4 Runtime: 0.0021s