Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-26 07:58:51.559 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:48362 10 6870 1 2025-11-26 07:59:51.959 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:35854 10 6870 1 2025-11-26 08:00:52.329 00:00:10.984 TCP 1.101.0.1:3000 -> 23.104.0.1:38714 10 6870 1 2025-11-26 08:01:53.353 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49916 10 6870 1 2025-11-26 07:58:06.444 00:05:01.532 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 07:58:06.443 00:05:01.537 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:02:53.753 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:39600 10 6870 1 2025-11-26 08:03:06.405 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:03:06.245 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:03:06.487 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:03:06.479 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:03:06.570 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:03:54.115 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58540 10 6870 1 2025-11-26 08:04:54.525 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:58026 10 6870 1 2025-11-26 08:05:54.937 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:41818 10 6870 1 2025-11-26 08:06:55.364 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:58158 10 6870 1 2025-11-26 08:07:55.760 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:54810 10 6870 1 2025-11-26 08:08:06.868 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:08:06.755 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:08:06.957 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:08:06.665 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:04:06.447 00:05:01.534 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:04:06.445 00:05:01.539 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:08:07.040 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:08:56.175 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:52884 10 6870 1 2025-11-26 08:09:56.584 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54074 10 6870 1 2025-11-26 08:10:57.006 00:00:10.317 TCP 1.101.0.1:3000 -> 23.104.0.1:48664 10 6870 1 2025-11-26 08:11:57.367 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:35260 10 6870 1 2025-11-26 08:13:06.802 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:13:06.721 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:13:06.296 00:00:00.037 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:13:06.719 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:13:06.724 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:12:57.777 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:57394 10 6870 1 2025-11-26 08:10:06.445 00:05:01.539 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:10:06.448 00:05:01.534 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:13:58.179 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:50824 10 6870 1 2025-11-26 08:14:58.578 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:56948 10 6870 1 2025-11-26 08:15:58.979 00:00:10.441 TCP 1.101.0.1:3000 -> 23.104.0.1:57616 12 10369 1 2025-11-26 08:16:59.461 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51838 10 6452 1 2025-11-26 08:18:06.950 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:18:06.868 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:18:06.941 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:18:06.868 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:18:06.955 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:17:59.862 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:34120 10 6452 1 2025-11-26 08:19:00.275 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:55334 10 6452 1 2025-11-26 08:16:06.451 00:05:01.536 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:16:06.454 00:05:01.531 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:20:00.681 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:56128 10 6452 1 2025-11-26 08:21:01.110 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46916 10 6452 1 2025-11-26 08:22:01.514 00:00:10.341 TCP 1.101.0.1:3000 -> 23.104.0.1:41704 10 6452 1 2025-11-26 08:23:06.942 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:23:06.922 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:23:06.989 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:23:06.859 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:23:06.919 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:23:01.894 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:49836 10 6452 1 2025-11-26 08:24:02.260 00:00:10.653 TCP 1.101.0.1:3000 -> 23.104.0.1:34588 10 6452 1 2025-11-26 08:25:02.963 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:53834 10 6452 1 2025-11-26 08:22:06.455 00:05:01.532 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:22:06.452 00:05:01.537 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:26:03.369 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:38542 10 6452 1 2025-11-26 08:27:03.778 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:37922 10 6452 1 2025-11-26 08:28:06.926 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:28:07.112 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:28:06.926 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:28:07.011 00:00:00.043 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:28:07.010 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:28:04.186 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:45758 10 6452 1 2025-11-26 08:29:04.597 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37872 10 6452 1 2025-11-26 08:30:05.002 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51344 10 6452 1 2025-11-26 08:31:05.401 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47558 10 6452 1 2025-11-26 08:28:06.462 00:05:01.527 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:28:06.460 00:05:01.532 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:32:05.811 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59948 10 6452 1 2025-11-26 08:33:07.213 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:33:07.077 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:33:07.171 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:33:07.172 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:33:07.254 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:33:06.214 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:43764 10 6452 1 2025-11-26 08:34:06.622 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47642 10 6452 1 2025-11-26 08:35:07.031 00:00:10.412 TCP 1.101.0.1:3000 -> 23.104.0.1:46944 11 6504 1 2025-11-26 08:36:07.486 00:00:10.443 TCP 1.101.0.1:3000 -> 23.104.0.1:36056 12 10578 1 2025-11-26 08:37:07.964 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:50324 10 6661 1 2025-11-26 08:38:07.584 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:38:07.454 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:38:07.526 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:38:07.532 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:34:06.466 00:05:01.524 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:34:06.463 00:05:01.529 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:38:07.608 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:38:08.331 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:50954 10 6661 1 2025-11-26 08:39:08.767 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:55876 10 6661 1 2025-11-26 08:40:09.179 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:42512 10 6661 1 2025-11-26 08:41:09.565 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:46060 10 6661 1 2025-11-26 08:42:09.927 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:57016 10 6661 1 2025-11-26 08:43:07.357 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:43:07.452 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:43:07.350 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:43:07.282 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:43:07.439 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:43:10.303 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41886 10 6661 1 2025-11-26 08:40:06.468 00:05:01.526 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:40:06.464 00:05:01.532 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:44:10.704 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:40862 10 6661 1 2025-11-26 08:45:11.125 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59402 10 6661 1 2025-11-26 08:46:11.534 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:41738 10 6661 1 2025-11-26 08:47:11.904 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:45936 10 6661 1 2025-11-26 08:48:07.387 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:48:07.272 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:48:07.382 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:48:07.384 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:48:07.464 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:48:12.311 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:44474 10 6661 1 2025-11-26 08:49:12.679 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:54296 11 6713 1 2025-11-26 08:46:06.469 00:05:01.527 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:46:06.466 00:05:01.532 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:50:13.115 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:60776 10 6661 1 2025-11-26 08:51:13.479 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:35084 10 6661 1 2025-11-26 08:52:13.839 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:46008 10 6661 1 2025-11-26 08:53:07.713 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:53:07.633 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:53:07.608 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:53:07.631 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:53:07.591 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:53:14.258 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35212 10 6661 1 2025-11-26 08:54:14.661 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:39896 10 6661 1 2025-11-26 08:55:15.089 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:44396 10 6661 1 2025-11-26 08:52:06.466 00:05:01.534 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-26 08:52:06.470 00:05:01.527 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-26 08:56:15.492 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:44924 12 10787 1 2025-11-26 08:57:15.975 00:00:10.982 TCP 1.101.0.1:3000 -> 23.104.0.1:42652 10 6870 1 2025-11-26 08:58:07.675 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-26 08:58:07.582 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-26 08:58:07.791 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:58:07.592 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-26 08:58:07.567 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-26 08:58:16.997 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:36368 10 6870 1 Summary: total flows: 140, total bytes: 441395, total packets: 1028, avg bps: 975, avg pps: 0, avg bpp: 429 Time window: 2025-11-26 07:58:06 - 2025-11-26 08:58:27 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0028s User: 0.0028s Wall: 0.0020s flows/second: 69172.2 Runtime: 0.0020s