Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-29 12:58:45.269 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:49436 10 6452 1 2025-11-29 12:59:39.256 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 12:59:39.172 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 12:59:39.064 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 12:59:39.172 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 12:59:38.938 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 12:59:45.675 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:55654 10 6452 1 2025-11-29 13:00:46.105 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:40542 10 6452 1 2025-11-29 13:01:46.503 00:00:10.672 TCP 1.101.0.1:3000 -> 23.104.0.1:52666 10 6452 1 2025-11-29 12:58:08.117 00:05:02.098 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 12:58:08.115 00:05:02.103 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 13:02:47.209 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46420 10 6452 1 2025-11-29 13:03:47.619 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:54588 10 6452 1 2025-11-29 13:04:39.405 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:04:39.324 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:04:39.358 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:04:39.259 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:04:39.125 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:04:48.023 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:43350 10 6452 1 2025-11-29 13:05:48.424 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:41280 10 6452 1 2025-11-29 13:06:48.833 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:50834 10 6452 1 2025-11-29 13:07:49.257 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:47748 10 6452 1 2025-11-29 13:04:08.116 00:05:02.101 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 13:04:08.119 00:05:02.097 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 13:08:49.659 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48506 10 6452 1 2025-11-29 13:09:39.356 00:00:00.030 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:09:39.497 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:09:39.496 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:09:39.356 00:00:00.030 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:09:39.578 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:09:50.068 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48968 10 6452 1 2025-11-29 13:10:50.476 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:36660 10 6452 1 2025-11-29 13:11:50.873 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:47162 10 6452 1 2025-11-29 13:12:51.243 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:47690 10 6452 1 2025-11-29 13:10:08.118 00:05:02.101 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 13:13:51.645 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:36060 10 6452 1 2025-11-29 13:10:08.121 00:05:02.097 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 13:14:39.717 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:14:39.434 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:14:39.586 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:14:39.635 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:14:39.450 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:14:52.057 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:46214 10 6452 1 2025-11-29 13:15:52.459 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:34940 10 6452 1 2025-11-29 13:16:52.862 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:37568 10 6452 1 2025-11-29 13:17:53.275 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46658 10 6452 1 2025-11-29 13:18:53.678 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:52824 10 6452 1 2025-11-29 13:19:39.548 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:19:39.548 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:19:39.548 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:19:39.312 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:19:39.630 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:19:54.108 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39186 10 6452 1 2025-11-29 13:16:08.122 00:05:02.096 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 13:16:08.119 00:05:02.100 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 13:20:54.516 00:00:12.408 TCP 1.101.0.1:3000 -> 23.104.0.1:55424 10 6452 1 2025-11-29 13:21:57.031 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:52702 10 6452 1 2025-11-29 13:22:57.430 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:36444 10 6452 1 2025-11-29 13:23:57.832 00:00:10.350 TCP 1.101.0.1:3000 -> 23.104.0.1:54772 10 6452 1 2025-11-29 13:24:39.573 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:24:39.584 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:24:39.715 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:24:39.655 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:24:39.799 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:24:58.217 00:00:10.976 TCP 1.101.0.1:3000 -> 23.104.0.1:44394 10 6452 1 2025-11-29 13:22:08.119 00:05:02.102 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 13:25:59.228 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:51664 10 6452 1 2025-11-29 13:22:08.123 00:05:02.097 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 13:26:59.635 00:00:10.437 TCP 1.101.0.1:3000 -> 23.104.0.1:54630 12 10369 1 2025-11-29 13:28:00.115 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:53668 10 6452 1 2025-11-29 13:29:00.512 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:60292 10 6452 1 2025-11-29 13:29:39.882 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:29:39.809 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:29:39.523 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:29:39.800 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:29:39.678 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:30:00.929 00:00:10.390 TCP 1.101.0.1:3000 -> 23.104.0.1:33908 10 6452 1 2025-11-29 13:31:01.355 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:57898 10 6452 1 2025-11-29 13:28:08.120 00:05:02.103 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 13:28:08.124 00:05:02.098 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 13:32:01.754 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:35968 10 6452 1 2025-11-29 13:33:02.117 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:41132 10 6452 1 2025-11-29 13:34:02.523 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:34088 10 6452 1 2025-11-29 13:34:39.854 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:34:39.747 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:34:39.750 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:34:39.813 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:34:39.832 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:35:02.925 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:37052 10 6452 1 2025-11-29 13:36:03.353 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:52176 10 6452 1 2025-11-29 13:37:03.757 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:49658 10 6452 1 2025-11-29 13:34:08.125 00:05:02.097 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 13:34:08.122 00:05:02.103 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 13:38:04.181 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:40026 12 6556 1 2025-11-29 13:39:04.596 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:49424 10 6452 1 2025-11-29 13:39:39.869 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:39:39.631 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:39:39.869 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:39:39.869 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:39:39.952 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:40:05.006 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:45450 10 6452 1 2025-11-29 13:41:05.410 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:57642 10 6452 1 2025-11-29 13:42:05.814 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:40046 10 6452 1 2025-11-29 13:43:06.201 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:40056 10 6452 1 2025-11-29 13:40:08.125 00:05:02.098 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 13:40:08.123 00:05:02.103 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 13:44:06.601 00:00:10.670 TCP 1.101.0.1:3000 -> 23.104.0.1:56884 10 6452 1 2025-11-29 13:44:40.239 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:44:39.874 00:00:00.034 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:44:40.214 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:44:40.402 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:44:40.297 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:45:07.320 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:56454 10 6452 1 2025-11-29 13:46:07.713 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:57744 10 6452 1 2025-11-29 13:47:08.118 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:36734 10 6452 1 2025-11-29 13:48:08.515 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:35786 10 6452 1 2025-11-29 13:49:08.916 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:51778 10 6452 1 2025-11-29 13:49:40.153 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:49:40.116 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:49:39.937 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:49:39.945 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:49:40.021 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:46:08.125 00:05:02.107 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 13:46:08.128 00:05:02.101 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 13:50:09.321 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39750 10 6452 1 2025-11-29 13:51:09.728 00:00:10.425 TCP 1.101.0.1:3000 -> 23.104.0.1:49588 10 6452 1 2025-11-29 13:52:10.187 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:34782 10 6452 1 2025-11-29 13:53:10.605 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:34896 10 6452 1 2025-11-29 13:54:10.960 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:51290 10 6452 1 2025-11-29 13:54:40.202 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-29 13:54:40.095 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:54:40.279 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-29 13:54:40.288 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-29 13:54:40.363 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-29 13:55:11.362 00:00:11.499 TCP 1.101.0.1:3000 -> 23.104.0.1:37384 10 6452 1 2025-11-29 13:52:08.128 00:05:02.104 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-29 13:52:08.125 00:05:02.109 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-29 13:56:12.898 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:34812 10 6452 1 2025-11-29 13:57:13.306 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:58312 10 6452 1 2025-11-29 13:58:13.709 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:54524 10 6452 1 Summary: total flows: 140, total bytes: 421021, total packets: 1024, avg bps: 931, avg pps: 0, avg bpp: 411 Time window: 2025-11-29 12:58:08 - 2025-11-29 13:58:24 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0025s User: 0.0025s Wall: 0.0024s flows/second: 58092.9 Runtime: 0.0024s