Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-29 08:58:56.794 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47576 10 6452 1 2025-11-29 08:59:34.182 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 08:59:34.236 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 08:59:34.278 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 08:59:34.075 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 08:59:34.360 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 08:59:57.203 00:00:10.354 TCP 1.101.0.1:3000 -> 23.104.0.1:50690 10 6452 1 2025-11-29 09:00:57.597 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:37920 10 6452 1 2025-11-29 08:58:07.998 00:05:02.155 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 09:01:58.000 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:51588 10 6452 1 2025-11-29 08:58:08.002 00:05:02.149 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 09:02:58.407 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:56150 10 6452 1 2025-11-29 09:03:58.810 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:40864 10 6452 1 2025-11-29 09:04:34.376 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:04:34.299 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:04:34.286 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:04:34.292 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:04:34.370 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:04:59.183 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:48246 10 6452 1 2025-11-29 09:05:59.589 00:00:11.041 TCP 1.101.0.1:3000 -> 23.104.0.1:54322 10 6452 1 2025-11-29 09:07:00.665 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:38798 10 6452 1 2025-11-29 09:04:08.002 00:05:02.149 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 09:08:01.084 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:52584 10 6452 1 2025-11-29 09:04:07.999 00:05:02.154 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 09:09:01.484 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:52646 10 6452 1 2025-11-29 09:09:34.492 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:09:34.356 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:09:34.605 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:09:34.488 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:09:34.687 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:10:01.885 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:57134 10 6452 1 2025-11-29 09:11:02.300 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:46056 10 6452 1 2025-11-29 09:12:02.705 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:55868 12 10369 1 2025-11-29 09:13:03.199 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:38118 10 6452 1 2025-11-29 09:10:08.001 00:05:02.156 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 09:14:03.563 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:54776 10 6452 1 2025-11-29 09:10:08.004 00:05:02.150 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 09:14:35.169 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:14:34.685 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:14:34.631 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:14:35.085 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:14:34.538 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:15:03.961 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:60376 10 6452 1 2025-11-29 09:16:04.369 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:36310 10 6452 1 2025-11-29 09:17:04.734 00:00:10.450 TCP 1.101.0.1:3000 -> 23.104.0.1:34392 12 10375 1 2025-11-29 09:18:05.230 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:55412 10 6452 1 2025-11-29 09:19:05.585 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:38308 10 6452 1 2025-11-29 09:19:34.927 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:19:34.687 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:19:34.790 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:19:34.844 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:19:34.877 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:16:08.015 00:05:02.144 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 09:16:08.017 00:05:02.139 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 09:20:05.972 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58862 10 6452 1 2025-11-29 09:21:06.378 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:58376 10 6452 1 2025-11-29 09:22:06.787 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:36764 10 6452 1 2025-11-29 09:23:07.188 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:50534 10 6452 1 2025-11-29 09:24:07.595 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:44582 10 6452 1 2025-11-29 09:24:34.738 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:24:34.681 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:24:34.798 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:24:34.811 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:24:34.882 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:25:07.970 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:58598 10 6452 1 2025-11-29 09:22:08.033 00:05:02.126 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 09:22:08.036 00:05:02.121 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 09:26:08.378 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:34598 10 6452 1 2025-11-29 09:27:08.782 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:37320 10 6452 1 2025-11-29 09:28:09.144 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:34520 10 6452 1 2025-11-29 09:29:09.551 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:59378 10 6452 1 2025-11-29 09:29:35.134 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:29:35.053 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:29:34.813 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:29:35.052 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:29:34.909 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:30:09.954 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:60120 10 6452 1 2025-11-29 09:31:10.368 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:46854 10 6452 1 2025-11-29 09:28:08.038 00:05:02.119 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 09:28:08.036 00:05:02.124 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 09:32:10.770 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:36790 10 6452 1 2025-11-29 09:33:11.184 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:34214 10 6452 1 2025-11-29 09:34:11.594 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:51454 10 6452 1 2025-11-29 09:34:34.929 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:34:34.836 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:34:35.009 00:00:00.050 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:34:34.878 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:34:35.011 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:35:11.954 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:42708 10 6452 1 2025-11-29 09:36:12.353 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:57716 10 6452 1 2025-11-29 09:37:12.761 00:00:11.491 TCP 1.101.0.1:3000 -> 23.104.0.1:60548 10 6452 1 2025-11-29 09:34:08.037 00:05:02.124 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 09:34:08.040 00:05:02.119 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 09:38:14.289 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:53406 10 6452 1 2025-11-29 09:39:14.691 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:46608 10 6452 1 2025-11-29 09:39:35.189 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:39:35.224 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:39:35.247 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:39:35.106 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:39:35.217 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:40:15.071 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:55866 10 6452 1 2025-11-29 09:41:15.477 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:48124 10 6452 1 2025-11-29 09:42:15.878 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:46998 10 6452 1 2025-11-29 09:43:16.283 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:38414 10 6452 1 2025-11-29 09:40:08.043 00:05:02.120 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 09:40:08.044 00:05:02.115 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 09:44:16.689 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:38862 10 6452 1 2025-11-29 09:44:35.160 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:44:35.254 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:44:35.199 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:44:35.078 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:44:35.185 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:45:17.108 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:39188 10 6452 1 2025-11-29 09:46:17.507 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:47302 10 6452 1 2025-11-29 09:47:17.889 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:39316 10 6452 1 2025-11-29 09:48:18.291 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:43540 10 6452 1 2025-11-29 09:49:18.661 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:50762 10 6452 1 2025-11-29 09:49:35.088 00:00:00.038 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:49:35.329 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:49:35.300 00:00:00.025 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:49:35.006 00:00:00.036 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:49:35.144 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:46:08.051 00:05:02.112 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 09:46:08.048 00:05:02.118 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 09:50:19.098 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:36760 10 6452 1 2025-11-29 09:51:19.508 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:57136 10 6452 1 2025-11-29 09:52:19.874 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:54710 10 6452 1 2025-11-29 09:53:20.234 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:35108 10 6452 1 2025-11-29 09:54:20.637 00:00:10.340 TCP 1.101.0.1:3000 -> 23.104.0.1:39330 10 6452 1 2025-11-29 09:54:35.461 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 09:54:35.277 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 09:54:35.428 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:54:35.380 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 09:54:35.564 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 09:55:21.002 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:40050 10 6452 1 2025-11-29 09:52:08.049 00:05:02.117 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 09:52:08.052 00:05:02.112 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 09:56:21.402 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:58908 10 6452 1 2025-11-29 09:57:21.767 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:35952 10 6452 1 2025-11-29 09:58:22.132 00:00:19.303 TCP 1.101.0.1:3000 -> 23.104.0.1:56602 10 6452 1 Summary: total flows: 140, total bytes: 424840, total packets: 1024, avg bps: 935, avg pps: 0, avg bpp: 414 Time window: 2025-11-29 08:58:07 - 2025-11-29 09:58:41 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0031s User: 0.0021s Wall: 0.0019s flows/second: 74310.6 Runtime: 0.0019s