Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-25 18:59:20.054 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:38530 10 6452 1 2025-11-25 19:00:20.451 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47828 10 6452 1 2025-11-25 19:01:20.856 00:00:10.341 TCP 1.101.0.1:3000 -> 23.104.0.1:46074 10 6452 1 2025-11-25 18:58:06.219 00:05:01.341 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 18:58:06.222 00:05:01.336 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:02:21.234 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36500 10 6452 1 2025-11-25 19:02:50.773 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:02:50.710 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:02:50.776 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:02:50.883 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:02:50.859 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:03:21.634 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:57818 10 6452 1 2025-11-25 19:04:22.058 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:55154 10 6452 1 2025-11-25 19:05:22.462 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:39980 10 6452 1 2025-11-25 19:06:22.871 00:00:10.401 TCP 1.101.0.1:3000 -> 23.104.0.1:46328 10 6452 1 2025-11-25 19:07:23.308 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44864 10 6452 1 2025-11-25 19:07:51.357 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:07:51.397 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:07:51.140 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:07:51.273 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:07:51.270 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:04:06.221 00:05:01.344 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:04:06.224 00:05:01.339 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:08:23.710 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:36608 10 6452 1 2025-11-25 19:09:24.118 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:53976 10 6452 1 2025-11-25 19:10:24.543 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58686 10 6452 1 2025-11-25 19:11:24.945 00:00:10.407 TCP 1.101.0.1:3000 -> 23.104.0.1:43068 10 6452 1 2025-11-25 19:12:25.352 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:53150 10 6452 1 2025-11-25 19:12:50.818 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:12:51.083 00:00:00.049 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:12:51.200 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:12:51.002 00:00:00.047 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:12:51.240 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:13:25.729 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:46628 10 6452 1 2025-11-25 19:10:06.223 00:05:01.340 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:10:06.221 00:05:01.344 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:14:26.143 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:42512 10 6452 1 2025-11-25 19:15:26.543 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:53524 10 6452 1 2025-11-25 19:16:26.951 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54874 10 6452 1 2025-11-25 19:17:27.356 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:57200 10 6452 1 2025-11-25 19:17:51.408 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:17:51.278 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:17:51.136 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:17:51.326 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:17:51.180 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:18:27.770 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:50724 10 6452 1 2025-11-25 19:19:28.184 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:49372 10 6452 1 2025-11-25 19:16:06.222 00:05:01.344 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:16:06.225 00:05:01.339 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:20:28.595 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37052 10 6452 1 2025-11-25 19:21:28.996 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:44930 10 6452 1 2025-11-25 19:22:29.366 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56568 10 6452 1 2025-11-25 19:22:50.890 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:22:51.339 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:22:51.256 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:22:51.256 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:22:51.346 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:23:29.773 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:50014 10 6452 1 2025-11-25 19:24:30.139 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:37898 10 6452 1 2025-11-25 19:25:30.539 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:37426 10 6452 1 2025-11-25 19:22:06.229 00:05:01.341 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:22:06.226 00:05:01.346 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:26:30.938 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:48468 10 6452 1 2025-11-25 19:27:31.316 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:57956 10 6452 1 2025-11-25 19:27:51.430 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:27:51.263 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:27:51.133 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:27:51.349 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:27:51.519 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:28:31.686 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:44644 10 6452 1 2025-11-25 19:29:32.066 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:55474 10 6452 1 2025-11-25 19:30:32.470 00:00:10.340 TCP 1.101.0.1:3000 -> 23.104.0.1:45550 10 6452 1 2025-11-25 19:31:32.838 00:00:10.425 TCP 1.101.0.1:3000 -> 23.104.0.1:48298 12 10375 1 2025-11-25 19:28:06.232 00:05:01.343 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:28:06.229 00:05:01.349 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:32:33.301 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:33164 10 6452 1 2025-11-25 19:32:51.682 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:32:51.650 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:32:51.350 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:32:51.601 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:32:51.649 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:33:33.666 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:56438 10 6452 1 2025-11-25 19:34:34.102 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:44744 10 6452 1 2025-11-25 19:35:34.503 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:37912 10 6452 1 2025-11-25 19:36:34.869 00:00:10.450 TCP 1.101.0.1:3000 -> 23.104.0.1:48378 12 10369 1 2025-11-25 19:37:35.364 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:49778 10 6452 1 2025-11-25 19:37:51.685 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:37:51.778 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:37:51.624 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:37:51.603 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:37:51.652 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:34:06.231 00:05:01.348 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:34:06.234 00:05:01.343 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:38:35.762 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:38498 10 6452 1 2025-11-25 19:39:36.175 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52858 10 6452 1 2025-11-25 19:40:36.581 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:55396 10 6452 1 2025-11-25 19:41:36.988 00:00:10.342 TCP 1.101.0.1:3000 -> 23.104.0.1:33392 10 6452 1 2025-11-25 19:42:37.371 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:38752 10 6452 1 2025-11-25 19:42:51.708 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:42:51.695 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:42:51.711 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:42:51.624 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:42:51.751 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:43:37.780 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56426 10 6452 1 2025-11-25 19:40:06.233 00:05:01.368 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:40:06.236 00:05:01.362 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:44:38.187 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57276 10 6452 1 2025-11-25 19:45:38.596 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:54360 10 6452 1 2025-11-25 19:46:38.995 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:56262 10 6452 1 2025-11-25 19:47:39.359 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37354 10 6452 1 2025-11-25 19:47:51.633 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:47:51.667 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:47:51.632 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:47:51.716 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:47:51.716 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:48:39.773 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:44202 10 6452 1 2025-11-25 19:49:40.192 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:49958 10 6452 1 2025-11-25 19:46:06.237 00:05:01.363 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:46:06.236 00:05:01.368 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:50:40.611 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:57178 10 6452 1 2025-11-25 19:51:41.008 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:49118 10 6452 1 2025-11-25 19:52:52.303 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:52:52.221 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:52:52.059 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:52:52.055 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:52:51.960 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:52:41.416 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:49260 10 6452 1 2025-11-25 19:53:41.826 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:53888 10 6452 1 2025-11-25 19:54:42.189 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:34654 10 6452 1 2025-11-25 19:55:42.603 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:60100 10 6452 1 2025-11-25 19:52:06.237 00:05:01.367 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-25 19:52:06.239 00:05:01.362 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-25 19:56:42.990 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:43690 10 6452 1 2025-11-25 19:57:52.169 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-25 19:57:52.197 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-25 19:57:52.159 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:57:52.085 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-25 19:57:52.227 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-25 19:57:43.390 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:55632 10 6452 1 Summary: total flows: 139, total bytes: 418388, total packets: 1014, avg bps: 932, avg pps: 0, avg bpp: 412 Time window: 2025-11-25 18:58:06 - 2025-11-25 19:57:53 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0041s User: 0.0000s Wall: 0.0021s flows/second: 66828.1 Runtime: 0.0021s