Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-30 02:58:57.387 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:36274 10 6452 1 2025-11-30 02:59:55.951 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 02:59:55.848 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 02:59:55.942 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 02:59:56.047 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 02:59:56.130 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 02:59:57.796 00:00:10.350 TCP 1.101.0.1:3000 -> 23.104.0.1:49598 10 6452 1 2025-11-30 03:00:58.197 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41102 10 6452 1 2025-11-30 03:01:58.601 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:58610 10 6452 1 2025-11-30 02:58:08.474 00:05:02.067 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 02:58:08.472 00:05:02.072 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 03:02:58.973 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:43788 10 6452 1 2025-11-30 03:03:59.387 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52670 10 6452 1 2025-11-30 03:04:55.908 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:04:55.967 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:04:56.050 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:04:56.092 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:04:56.179 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:04:59.790 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:42844 10 6452 1 2025-11-30 03:06:00.194 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44234 10 6452 1 2025-11-30 03:07:00.598 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:33352 10 6452 1 2025-11-30 03:04:08.472 00:05:02.072 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 03:08:00.971 00:00:10.478 TCP 1.101.0.1:3000 -> 23.104.0.1:51114 10 6452 1 2025-11-30 03:04:08.474 00:05:02.067 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 03:09:01.484 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:41286 10 6452 1 2025-11-30 03:09:55.936 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:09:56.262 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:09:56.201 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:09:56.201 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:09:56.021 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:10:01.850 00:00:10.343 TCP 1.101.0.1:3000 -> 23.104.0.1:35454 10 6452 1 2025-11-30 03:11:02.235 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:55196 10 6452 1 2025-11-30 03:12:02.648 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:42420 10 6452 1 2025-11-30 03:13:03.063 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:56358 10 6452 1 2025-11-30 03:10:08.474 00:05:02.069 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 03:14:03.469 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:47860 10 6452 1 2025-11-30 03:10:08.472 00:05:02.074 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 03:14:56.510 00:00:00.030 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:14:56.607 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:14:56.406 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:14:56.594 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:14:56.488 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:15:03.836 00:00:10.390 TCP 1.101.0.1:3000 -> 23.104.0.1:49402 10 6452 1 2025-11-30 03:16:04.265 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:57606 10 6452 1 2025-11-30 03:17:04.669 00:00:10.398 TCP 1.101.0.1:3000 -> 23.104.0.1:55932 12 10375 1 2025-11-30 03:18:05.111 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:45364 10 6452 1 2025-11-30 03:19:05.515 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:54498 10 6452 1 2025-11-30 03:19:56.469 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:19:56.275 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:19:55.995 00:00:00.056 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:19:56.385 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:19:56.385 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:16:08.474 00:05:02.077 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 03:16:08.477 00:05:02.072 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 03:20:05.918 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:44842 10 6452 1 2025-11-30 03:21:06.322 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:56098 10 6452 1 2025-11-30 03:22:06.687 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:44844 10 6452 1 2025-11-30 03:23:07.113 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:34600 10 6452 1 2025-11-30 03:24:07.533 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:40492 10 6452 1 2025-11-30 03:24:56.552 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:24:56.630 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:24:56.504 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:24:56.471 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:24:56.595 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:25:07.941 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:54874 10 6452 1 2025-11-30 03:22:08.477 00:05:02.072 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 03:22:08.475 00:05:02.077 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 03:26:08.360 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:49510 10 6452 1 2025-11-30 03:27:08.767 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:42884 10 6452 1 2025-11-30 03:28:09.189 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:44142 10 6452 1 2025-11-30 03:29:09.594 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:32974 10 6452 1 2025-11-30 03:29:56.710 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:29:56.707 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:29:56.516 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:29:56.627 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:29:56.706 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:30:10.012 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:59408 10 6452 1 2025-11-30 03:31:10.419 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37314 10 6452 1 2025-11-30 03:28:08.478 00:05:02.073 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 03:28:08.474 00:05:02.079 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 03:32:10.823 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52286 10 6452 1 2025-11-30 03:33:11.235 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:47378 10 6452 1 2025-11-30 03:34:11.633 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:37032 10 6452 1 2025-11-30 03:34:56.952 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:34:56.829 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:34:56.571 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:34:56.871 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:34:56.780 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:35:11.992 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:46306 10 6452 1 2025-11-30 03:36:12.397 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:46552 10 6452 1 2025-11-30 03:37:12.764 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:40506 10 6452 1 2025-11-30 03:34:08.476 00:05:02.083 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 03:34:08.479 00:05:02.077 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 03:38:13.168 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:34302 10 6452 1 2025-11-30 03:39:13.569 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:50692 10 6452 1 2025-11-30 03:39:56.782 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:39:56.624 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:39:56.770 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:39:56.909 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:39:56.853 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:40:13.969 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:48522 10 6452 1 2025-11-30 03:41:14.389 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:50898 10 6452 1 2025-11-30 03:42:14.789 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:33964 10 6452 1 2025-11-30 03:43:15.151 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:39792 10 6452 1 2025-11-30 03:40:08.479 00:05:02.079 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 03:40:08.479 00:05:02.084 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 03:44:15.562 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:38766 10 6452 1 2025-11-30 03:44:56.857 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:44:56.915 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:44:56.979 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:44:56.742 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:44:56.940 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:45:15.963 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:54204 10 6452 1 2025-11-30 03:46:16.366 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:46856 10 6452 1 2025-11-30 03:47:16.723 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:60428 10 6452 1 2025-11-30 03:48:17.103 00:00:14.573 TCP 1.101.0.1:3000 -> 23.104.0.1:59768 10 6452 1 2025-11-30 03:49:21.712 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:59024 10 6452 1 2025-11-30 03:49:57.003 00:00:00.049 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:49:57.102 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:49:56.797 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:49:57.001 00:00:00.031 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:49:56.881 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:46:08.481 00:05:02.079 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 03:46:08.479 00:05:02.084 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 03:50:22.111 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:41222 10 6452 1 2025-11-30 03:51:22.510 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:58690 10 6452 1 2025-11-30 03:52:22.917 00:00:10.441 TCP 1.101.0.1:3000 -> 23.104.0.1:36686 12 10375 1 2025-11-30 03:53:23.399 00:00:11.086 TCP 1.101.0.1:3000 -> 23.104.0.1:53554 10 6452 1 2025-11-30 03:54:24.521 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:35520 10 6452 1 2025-11-30 03:54:57.209 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 03:54:56.944 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 03:54:56.890 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:54:57.126 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 03:54:57.270 00:00:00.028 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 03:55:24.929 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:37798 10 6452 1 2025-11-30 03:52:08.483 00:05:02.081 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 03:52:08.481 00:05:02.085 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 03:56:25.352 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:55548 10 6452 1 2025-11-30 03:57:25.719 00:00:11.877 TCP 1.101.0.1:3000 -> 23.104.0.1:60792 10 6452 1 2025-11-30 03:58:27.635 00:00:10.391 TCP 1.101.0.1:3000 -> 23.104.0.1:40404 10 6452 1 Summary: total flows: 140, total bytes: 424846, total packets: 1024, avg bps: 936, avg pps: 0, avg bpp: 414 Time window: 2025-11-30 02:58:08 - 2025-11-30 03:58:38 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0048s User: 0.0008s Wall: 0.0016s flows/second: 85003.3 Runtime: 0.0017s