Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-25 13:58:55.834 00:00:10.354 TCP 1.101.0.1:3000 -> 23.104.0.1:45038 10 6452 1 2025-11-25 13:59:56.233 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:44550 10 6452 1 2025-11-25 14:00:56.631 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:49102 10 6452 1 2025-11-25 14:01:57.031 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:53750 11 6492 1 2025-11-25 13:58:06.129 00:05:01.237 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 13:58:06.127 00:05:01.242 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 14:02:44.879 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:02:44.598 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:02:44.916 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:02:44.653 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:02:45.000 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:02:57.445 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:44604 10 6452 1 2025-11-25 14:03:57.813 00:00:10.338 TCP 1.101.0.1:3000 -> 23.104.0.1:51742 10 6452 1 2025-11-25 14:04:58.187 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:45128 10 6452 1 2025-11-25 14:05:58.586 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:32782 10 6452 1 2025-11-25 14:06:58.992 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:59628 10 6452 1 2025-11-25 14:07:44.823 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:07:44.861 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:07:44.900 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:07:44.836 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:07:44.984 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:04:06.129 00:05:01.244 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 14:04:06.132 00:05:01.238 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 14:07:59.404 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44710 10 6452 1 2025-11-25 14:08:59.806 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:56028 10 6452 1 2025-11-25 14:10:00.219 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:44548 10 6452 1 2025-11-25 14:11:00.577 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:50200 10 6452 1 2025-11-25 14:12:00.985 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:34596 10 6452 1 2025-11-25 14:12:45.141 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:12:45.107 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:12:44.942 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:12:45.059 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:12:45.058 00:00:00.025 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:13:01.396 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:32790 10 6452 1 2025-11-25 14:10:06.132 00:05:01.238 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 14:10:06.129 00:05:01.243 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 14:14:01.757 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:50502 10 6452 1 2025-11-25 14:15:02.182 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:53752 10 6452 1 2025-11-25 14:16:02.579 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:58284 10 6452 1 2025-11-25 14:17:02.948 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:55650 10 6452 1 2025-11-25 14:17:45.309 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:17:45.226 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:17:45.167 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:17:45.226 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:17:45.203 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:18:03.360 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:43732 10 6452 1 2025-11-25 14:19:03.760 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:45300 10 6452 1 2025-11-25 14:16:06.133 00:05:01.247 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 14:16:06.131 00:05:01.252 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 14:20:04.128 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:37810 10 6452 1 2025-11-25 14:21:04.492 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:56274 10 6452 1 2025-11-25 14:22:04.856 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:59854 10 6452 1 2025-11-25 14:22:45.424 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:22:45.154 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:22:45.290 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:22:45.341 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:22:45.339 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:23:05.275 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39512 10 6452 1 2025-11-25 14:24:05.682 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50114 10 6452 1 2025-11-25 14:25:06.105 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50632 10 6452 1 2025-11-25 14:22:06.132 00:05:01.257 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 14:22:06.134 00:05:01.252 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 14:26:06.515 00:00:10.401 TCP 1.101.0.1:3000 -> 23.104.0.1:33720 12 10375 1 2025-11-25 14:27:06.958 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:54148 10 6452 1 2025-11-25 14:27:45.362 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:27:45.349 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:27:45.388 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:27:45.279 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:27:45.277 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:28:07.377 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:47326 10 6452 1 2025-11-25 14:29:07.780 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:60888 10 6452 1 2025-11-25 14:30:08.190 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:55460 10 6452 1 2025-11-25 14:31:08.590 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51916 10 6452 1 2025-11-25 14:28:06.135 00:05:01.252 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 14:28:06.133 00:05:01.257 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 14:32:09.001 00:00:10.862 TCP 1.101.0.1:3000 -> 23.104.0.1:40544 10 6452 1 2025-11-25 14:32:45.406 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:32:45.147 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:32:45.583 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:32:45.499 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:32:45.667 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:33:09.912 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:47428 10 6452 1 2025-11-25 14:34:10.316 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:57878 10 6452 1 2025-11-25 14:35:10.719 00:00:10.337 TCP 1.101.0.1:3000 -> 23.104.0.1:36612 10 6452 1 2025-11-25 14:36:11.103 00:00:10.432 TCP 1.101.0.1:3000 -> 23.104.0.1:57422 10 6452 1 2025-11-25 14:37:11.610 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37194 10 6452 1 2025-11-25 14:37:45.703 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:37:45.721 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:37:45.642 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:37:45.556 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:37:45.726 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:34:06.134 00:05:01.257 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 14:34:06.136 00:05:01.252 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 14:38:12.018 00:00:10.357 TCP 1.101.0.1:3000 -> 23.104.0.1:60046 10 6452 1 2025-11-25 14:39:12.418 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:55328 10 6452 1 2025-11-25 14:40:12.784 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:37460 10 6452 1 2025-11-25 14:41:13.192 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:44366 10 6452 1 2025-11-25 14:42:13.598 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:42350 10 6452 1 2025-11-25 14:42:45.607 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:42:45.328 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:42:45.743 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:42:45.781 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:42:45.827 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:43:13.958 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:37796 10 6452 1 2025-11-25 14:40:06.135 00:05:01.258 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 14:40:06.137 00:05:01.253 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 14:44:14.371 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41584 10 6452 1 2025-11-25 14:45:14.777 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:42988 10 6452 1 2025-11-25 14:46:15.189 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41368 10 6452 1 2025-11-25 14:47:15.608 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:59174 10 6452 1 2025-11-25 14:47:45.718 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:47:45.635 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:47:45.766 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:47:45.635 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:47:45.799 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:48:16.036 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:36670 10 6452 1 2025-11-25 14:49:16.440 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:56280 10 6452 1 2025-11-25 14:46:06.139 00:05:01.253 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 14:46:06.136 00:05:01.259 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 14:50:16.846 00:00:10.393 TCP 1.101.0.1:3000 -> 23.104.0.1:59856 10 6452 1 2025-11-25 14:51:17.279 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:38684 10 6452 1 2025-11-25 14:52:17.680 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51342 10 6452 1 2025-11-25 14:52:45.762 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:52:45.880 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:52:45.768 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:52:45.955 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:52:45.851 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:53:18.107 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:57468 10 6452 1 2025-11-25 14:54:18.515 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:40082 10 6452 1 2025-11-25 14:55:18.875 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:39414 10 6452 1 2025-11-25 14:52:06.138 00:05:01.258 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 14:52:06.141 00:05:01.253 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 14:56:19.239 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59470 10 6452 1 2025-11-25 14:57:19.645 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:43376 10 6452 1 2025-11-25 14:57:45.957 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:57:45.760 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 14:57:46.113 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 14:57:45.984 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 14:57:46.196 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 14:58:20.062 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:46244 10 6452 1 Summary: total flows: 140, total bytes: 420963, total packets: 1023, avg bps: 929, avg pps: 0, avg bpp: 411 Time window: 2025-11-25 13:58:06 - 2025-11-25 14:58:30 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0031s User: 0.0031s Wall: 0.0018s flows/second: 79459.1 Runtime: 0.0018s