Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-29 06:59:02.843 00:00:10.401 TCP 1.101.0.1:3000 -> 23.104.0.1:37594 10 6452 1 2025-11-29 06:59:31.875 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 06:59:31.789 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 06:59:31.534 00:00:00.025 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 06:59:31.792 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 06:59:31.796 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:00:03.278 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:56720 10 6452 1 2025-11-29 07:01:03.655 00:00:11.143 TCP 1.101.0.1:3000 -> 23.104.0.1:58026 10 6452 1 2025-11-29 06:58:07.961 00:05:02.141 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 06:58:07.958 00:05:02.146 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 07:02:04.840 00:00:10.391 TCP 1.101.0.1:3000 -> 23.104.0.1:40700 10 6452 1 2025-11-29 07:03:05.272 00:00:10.351 TCP 1.101.0.1:3000 -> 23.104.0.1:47210 10 6452 1 2025-11-29 07:04:05.641 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:38202 10 6452 1 2025-11-29 07:04:32.138 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:04:31.968 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:04:31.842 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:04:32.054 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:04:31.968 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:05:06.060 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:34910 10 6452 1 2025-11-29 07:06:06.475 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:43306 10 6452 1 2025-11-29 07:07:06.870 00:00:10.406 TCP 1.101.0.1:3000 -> 23.104.0.1:52522 12 10375 1 2025-11-29 07:04:07.960 00:05:02.147 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 07:04:07.963 00:05:02.142 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 07:08:07.314 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:60548 10 6452 1 2025-11-29 07:09:07.721 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:54282 10 6452 1 2025-11-29 07:09:32.160 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:09:32.080 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:09:32.163 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:09:32.074 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:09:31.999 00:00:00.044 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:10:08.100 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:40854 10 6452 1 2025-11-29 07:11:08.504 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:60060 10 6452 1 2025-11-29 07:12:08.911 00:00:10.440 TCP 1.101.0.1:3000 -> 23.104.0.1:58218 12 10375 1 2025-11-29 07:13:09.391 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:35946 10 6452 1 2025-11-29 07:10:07.962 00:05:02.145 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 07:10:07.965 00:05:02.140 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 07:14:09.799 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:35696 10 6452 1 2025-11-29 07:14:32.182 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:14:32.266 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:14:32.216 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:14:32.097 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:14:32.089 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:15:10.210 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37260 10 6452 1 2025-11-29 07:16:10.612 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:38580 10 6452 1 2025-11-29 07:17:11.037 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:50714 10 6452 1 2025-11-29 07:18:11.401 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46244 10 6452 1 2025-11-29 07:19:11.807 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:33604 10 6452 1 2025-11-29 07:19:32.201 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:19:32.106 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:19:32.181 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:19:32.182 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:19:32.265 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:16:07.969 00:05:02.145 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 07:16:07.966 00:05:02.150 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 07:20:12.178 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:35114 10 6452 1 2025-11-29 07:21:12.546 00:00:10.393 TCP 1.101.0.1:3000 -> 23.104.0.1:39336 10 6452 1 2025-11-29 07:22:13.008 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:54412 10 6452 1 2025-11-29 07:23:13.413 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:47376 10 6452 1 2025-11-29 07:24:13.819 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:48694 10 6452 1 2025-11-29 07:24:32.388 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:24:32.315 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:24:32.369 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:24:32.478 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:24:32.452 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:25:14.229 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:33376 10 6452 1 2025-11-29 07:22:07.968 00:05:02.150 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 07:22:07.970 00:05:02.145 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 07:26:14.649 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:35336 10 6452 1 2025-11-29 07:27:15.011 00:00:10.395 TCP 1.101.0.1:3000 -> 23.104.0.1:50580 12 10375 1 2025-11-29 07:28:15.442 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:41156 10 6452 1 2025-11-29 07:29:15.849 00:00:11.000 TCP 1.101.0.1:3000 -> 23.104.0.1:44504 10 6452 1 2025-11-29 07:29:32.502 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:29:32.373 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:29:32.508 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:29:32.550 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:29:32.592 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:30:16.886 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:39820 10 6452 1 2025-11-29 07:31:17.299 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35724 12 6556 1 2025-11-29 07:28:07.971 00:05:02.146 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 07:28:07.968 00:05:02.151 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 07:32:17.701 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:39402 10 6452 1 2025-11-29 07:33:18.113 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:59860 10 6452 1 2025-11-29 07:34:18.478 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:39122 10 6452 1 2025-11-29 07:34:32.975 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:34:32.893 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:34:32.894 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:34:32.893 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:34:32.961 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:35:18.886 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:41722 10 6452 1 2025-11-29 07:36:19.247 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:43678 10 6452 1 2025-11-29 07:37:19.655 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56576 10 6452 1 2025-11-29 07:34:07.971 00:05:02.151 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 07:34:07.972 00:05:02.146 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 07:38:20.070 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:33326 10 6452 1 2025-11-29 07:39:20.475 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:43602 10 6452 1 2025-11-29 07:39:33.096 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:39:33.129 00:00:00.025 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:39:33.094 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:39:33.091 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:39:33.180 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:40:20.880 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:37820 10 6452 1 2025-11-29 07:41:21.292 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:56150 10 6452 1 2025-11-29 07:42:21.657 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:60892 10 6452 1 2025-11-29 07:43:22.017 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56898 10 6452 1 2025-11-29 07:40:07.973 00:05:02.149 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 07:40:07.972 00:05:02.153 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 07:44:32.890 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:44:32.705 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:44:32.919 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:44:32.884 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:44:22.422 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:57384 10 6452 1 2025-11-29 07:44:33.002 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:45:22.831 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:51884 10 6452 1 2025-11-29 07:46:23.233 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:35786 10 6452 1 2025-11-29 07:47:23.642 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:55396 10 6452 1 2025-11-29 07:48:24.065 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48386 10 6452 1 2025-11-29 07:49:32.977 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:49:32.895 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:49:32.841 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:49:24.467 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:34746 10 6452 1 2025-11-29 07:49:32.832 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:49:32.857 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:46:07.974 00:05:02.149 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 07:46:07.972 00:05:02.154 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 07:50:24.871 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:33862 10 6452 1 2025-11-29 07:51:25.281 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:35646 10 6452 1 2025-11-29 07:52:25.714 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:36774 10 6452 1 2025-11-29 07:53:26.115 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:49984 10 6452 1 2025-11-29 07:54:32.943 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 07:54:32.965 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:54:32.949 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 07:54:32.950 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 07:54:33.031 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 07:54:26.484 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:45490 10 6452 1 2025-11-29 07:55:26.893 00:00:10.934 TCP 1.101.0.1:3000 -> 23.104.0.1:47022 10 6452 1 2025-11-29 07:52:07.976 00:05:02.149 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 07:52:07.973 00:05:02.154 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 07:56:27.875 00:00:10.400 TCP 1.101.0.1:3000 -> 23.104.0.1:53316 12 6556 1 2025-11-29 07:57:28.317 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54130 10 6452 1 2025-11-29 07:58:28.718 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:59138 10 6452 1 Summary: total flows: 140, total bytes: 428977, total packets: 1030, avg bps: 945, avg pps: 0, avg bpp: 416 Time window: 2025-11-29 06:58:07 - 2025-11-29 07:58:39 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0049s User: 0.0010s Wall: 0.0017s flows/second: 80692.9 Runtime: 0.0018s