Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-26 03:59:12.693 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:46770 10 6452 1 2025-11-26 04:00:13.112 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:54378 10 6452 1 2025-11-26 04:01:13.519 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:53426 10 6452 1 2025-11-26 03:58:06.369 00:05:01.513 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 03:58:06.374 00:05:01.508 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 04:02:13.916 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:40676 10 6452 1 2025-11-26 04:03:02.124 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:03:01.497 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:03:01.338 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:03:02.042 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:03:01.968 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:03:14.323 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:56676 10 6452 1 2025-11-26 04:04:14.724 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46566 10 6452 1 2025-11-26 04:05:15.138 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:44698 10 6452 1 2025-11-26 04:06:15.498 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:54868 10 6452 1 2025-11-26 04:07:15.901 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:35928 10 6452 1 2025-11-26 04:08:01.776 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:08:01.708 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:08:01.746 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:08:01.693 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:08:01.778 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:04:06.375 00:05:01.507 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 04:04:06.372 00:05:01.512 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 04:08:16.322 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:47450 10 6452 1 2025-11-26 04:09:16.723 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:38860 10 6452 1 2025-11-26 04:10:17.139 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:51708 10 6452 1 2025-11-26 04:11:17.546 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:50442 10 6452 1 2025-11-26 04:12:17.950 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:58526 10 6452 1 2025-11-26 04:13:01.705 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:13:01.655 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:13:01.935 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:13:01.815 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:13:02.018 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:13:18.373 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:46712 12 6556 1 2025-11-26 04:10:06.375 00:05:01.509 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 04:10:06.373 00:05:01.514 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 04:14:18.775 00:00:10.417 TCP 1.101.0.1:3000 -> 23.104.0.1:46318 11 6504 1 2025-11-26 04:15:19.234 00:00:10.416 TCP 1.101.0.1:3000 -> 23.104.0.1:59368 11 6504 1 2025-11-26 04:16:19.690 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:59572 10 6452 1 2025-11-26 04:17:20.055 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:51298 10 6452 1 2025-11-26 04:18:01.947 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:18:01.830 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:18:02.006 00:00:00.042 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:18:01.962 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:18:02.088 00:00:00.043 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:18:20.458 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:59086 10 6452 1 2025-11-26 04:19:20.821 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:43802 10 6452 1 2025-11-26 04:16:06.376 00:05:01.512 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 04:16:06.379 00:05:01.507 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 04:20:21.227 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:44938 10 6452 1 2025-11-26 04:21:21.636 00:00:10.399 TCP 1.101.0.1:3000 -> 23.104.0.1:44654 12 10369 1 2025-11-26 04:22:22.102 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:43884 10 6452 1 2025-11-26 04:23:02.109 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:23:01.904 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:23:02.167 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:23:01.956 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:23:02.193 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:23:22.509 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:58026 10 6452 1 2025-11-26 04:24:22.884 00:00:10.351 TCP 1.101.0.1:3000 -> 23.104.0.1:37174 10 6452 1 2025-11-26 04:25:23.294 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:35454 10 6452 1 2025-11-26 04:22:06.379 00:05:01.509 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 04:22:06.377 00:05:01.514 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 04:26:23.666 00:00:10.409 TCP 1.101.0.1:3000 -> 23.104.0.1:52156 10 6452 1 2025-11-26 04:27:24.116 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:40788 10 6452 1 2025-11-26 04:28:02.227 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:28:02.394 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:28:02.407 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:28:02.505 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:28:02.478 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:28:24.477 00:00:10.357 TCP 1.101.0.1:3000 -> 23.104.0.1:54124 10 6452 1 2025-11-26 04:29:24.873 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56628 10 6452 1 2025-11-26 04:30:25.276 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:46548 10 6452 1 2025-11-26 04:31:25.675 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:33638 10 6452 1 2025-11-26 04:28:06.381 00:05:01.510 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 04:28:06.383 00:05:01.505 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 04:32:26.108 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:46848 10 6452 1 2025-11-26 04:33:02.514 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:33:02.189 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:33:01.963 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:33:02.432 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:33:02.280 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:33:26.474 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:60754 10 6452 1 2025-11-26 04:34:26.874 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:57510 10 6452 1 2025-11-26 04:35:27.281 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:42022 10 6452 1 2025-11-26 04:36:27.681 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:46378 10 6452 1 2025-11-26 04:37:28.131 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:44810 10 6452 1 2025-11-26 04:38:02.337 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:38:02.356 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:38:02.334 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:38:02.354 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:38:02.416 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:34:06.389 00:05:01.503 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 04:34:06.387 00:05:01.508 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 04:38:28.493 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:33272 10 6452 1 2025-11-26 04:39:28.894 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:55818 12 6556 1 2025-11-26 04:40:29.311 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47832 10 6452 1 2025-11-26 04:41:29.719 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:52340 10 6452 1 2025-11-26 04:42:30.131 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:57694 10 6452 1 2025-11-26 04:43:02.701 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:43:02.622 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:43:02.230 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:43:02.617 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:43:02.389 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:43:30.485 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:51918 10 6452 1 2025-11-26 04:40:06.389 00:05:01.507 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 04:40:06.391 00:05:01.502 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 04:44:30.888 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:54170 12 6556 1 2025-11-26 04:45:31.303 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:45514 10 6452 1 2025-11-26 04:46:31.707 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:45010 10 6452 1 2025-11-26 04:47:32.104 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:52992 10 6452 1 2025-11-26 04:48:02.787 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:48:02.604 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:48:02.858 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:48:02.785 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:48:02.942 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:48:32.503 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:59188 10 6452 1 2025-11-26 04:49:32.925 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:49124 10 6452 1 2025-11-26 04:46:06.391 00:05:01.514 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 04:46:06.393 00:05:01.509 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 04:50:33.287 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:47618 10 6452 1 2025-11-26 04:51:33.690 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:52558 10 6452 1 2025-11-26 04:52:34.115 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:58256 10 6452 1 2025-11-26 04:53:02.854 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:53:02.769 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:53:02.378 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:53:02.771 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:53:02.860 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:53:34.481 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:47074 10 6452 1 2025-11-26 04:54:34.891 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:56758 10 6452 1 2025-11-26 04:55:35.298 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36398 10 6452 1 2025-11-26 04:52:06.397 00:05:01.507 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 04:52:06.394 00:05:01.513 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 04:56:35.696 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:51954 10 6452 1 2025-11-26 04:57:36.111 00:00:10.882 TCP 1.101.0.1:3000 -> 23.104.0.1:49074 10 6452 1 2025-11-26 04:58:02.797 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 04:58:02.596 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:58:02.803 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 04:58:02.734 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 04:58:02.886 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 04:58:37.031 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:48224 10 6452 1 Summary: total flows: 140, total bytes: 421333, total packets: 1030, avg bps: 925, avg pps: 0, avg bpp: 409 Time window: 2025-11-26 03:58:06 - 2025-11-26 04:58:47 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0052s User: 0.0013s Wall: 0.0023s flows/second: 61461.4 Runtime: 0.0023s