Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-30 08:58:49.299 00:00:11.141 TCP 1.101.0.1:3000 -> 23.104.0.1:60888 10 6452 1 2025-11-30 08:59:50.481 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:45064 10 6452 1 2025-11-30 09:00:03.206 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:00:03.240 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:00:03.216 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:00:03.124 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:00:02.998 00:00:00.029 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:00:50.880 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:59042 10 6452 1 2025-11-30 09:01:51.305 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:44116 10 6452 1 2025-11-30 08:58:08.580 00:05:02.087 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 08:58:08.582 00:05:02.082 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 09:02:51.707 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39682 10 6452 1 2025-11-30 09:03:52.117 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60042 10 6452 1 2025-11-30 09:05:03.549 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:05:03.289 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:05:03.232 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:05:03.467 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:05:03.429 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:04:52.522 00:00:10.902 TCP 1.101.0.1:3000 -> 23.104.0.1:39576 10 6452 1 2025-11-30 09:05:53.460 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:59848 10 6452 1 2025-11-30 09:06:53.862 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:60220 10 6452 1 2025-11-30 09:07:54.276 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:40932 10 6452 1 2025-11-30 09:04:08.584 00:05:02.082 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 09:04:08.582 00:05:02.086 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 09:08:54.647 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:54530 10 6452 1 2025-11-30 09:10:03.394 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:09:55.058 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:42108 10 6452 1 2025-11-30 09:10:03.401 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:10:03.552 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:10:03.311 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:10:03.197 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:10:55.459 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:45818 10 6452 1 2025-11-30 09:11:55.857 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:54802 10 6452 1 2025-11-30 09:12:56.233 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:35738 10 6452 1 2025-11-30 09:13:56.641 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48698 10 6452 1 2025-11-30 09:10:08.589 00:05:02.077 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 09:10:08.587 00:05:02.082 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 09:15:03.548 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:15:03.425 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:15:03.545 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:15:03.494 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:15:03.629 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:14:57.052 00:00:10.357 TCP 1.101.0.1:3000 -> 23.104.0.1:46394 10 6452 1 2025-11-30 09:15:57.452 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:47558 10 6452 1 2025-11-30 09:16:57.853 00:00:10.337 TCP 1.101.0.1:3000 -> 23.104.0.1:36254 10 6452 1 2025-11-30 09:17:58.232 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:35754 10 6452 1 2025-11-30 09:18:58.638 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:35210 10 6452 1 2025-11-30 09:20:03.780 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:20:03.651 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:20:03.505 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:20:03.698 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:20:03.653 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:16:08.590 00:05:02.080 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 09:16:08.592 00:05:02.075 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 09:19:59.003 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:34848 10 6452 1 2025-11-30 09:20:59.367 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:41424 10 6452 1 2025-11-30 09:21:59.730 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:43028 10 6452 1 2025-11-30 09:23:00.109 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:50368 10 6452 1 2025-11-30 09:24:00.489 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:59070 10 6452 1 2025-11-30 09:25:04.052 00:00:00.027 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:25:04.082 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:25:03.974 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:25:03.777 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:25:04.135 00:00:00.027 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:25:00.851 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:51844 10 6452 1 2025-11-30 09:22:08.593 00:05:02.078 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 09:26:01.271 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:50606 10 6452 1 2025-11-30 09:22:08.595 00:05:02.073 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 09:27:01.669 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:56436 10 6452 1 2025-11-30 09:28:02.102 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:42138 10 6452 1 2025-11-30 09:29:02.514 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:39214 10 6452 1 2025-11-30 09:30:03.956 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:30:03.703 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:30:03.758 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:30:03.874 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:30:03.979 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:30:02.878 00:00:10.394 TCP 1.101.0.1:3000 -> 23.104.0.1:35540 10 6452 1 2025-11-30 09:31:03.296 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:51984 10 6452 1 2025-11-30 09:28:08.597 00:05:02.076 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 09:32:03.662 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:39458 10 6452 1 2025-11-30 09:28:08.599 00:05:02.071 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 09:33:04.109 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:47704 10 6452 1 2025-11-30 09:34:04.477 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:38392 10 6452 1 2025-11-30 09:35:04.266 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:35:04.229 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:35:04.429 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:35:03.880 00:00:00.025 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:35:04.513 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:35:04.899 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:52010 10 6452 1 2025-11-30 09:36:05.315 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44710 10 6452 1 2025-11-30 09:37:05.715 00:00:10.453 TCP 1.101.0.1:3000 -> 23.104.0.1:58042 12 10369 1 2025-11-30 09:34:08.605 00:05:02.066 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 09:34:08.602 00:05:02.072 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 09:38:06.223 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:51966 10 6452 1 2025-11-30 09:39:06.622 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:39332 10 6452 1 2025-11-30 09:40:04.124 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:40:03.770 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:40:03.952 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:40:04.083 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:40:04.033 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:40:06.992 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:35052 10 6452 1 2025-11-30 09:41:07.402 00:00:10.923 TCP 1.101.0.1:3000 -> 23.104.0.1:35418 10 6452 1 2025-11-30 09:42:08.366 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:52820 10 6452 1 2025-11-30 09:43:08.768 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54148 10 6452 1 2025-11-30 09:40:08.603 00:05:02.077 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 09:40:08.606 00:05:02.071 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 09:44:09.172 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:39070 10 6452 1 2025-11-30 09:45:03.944 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:45:04.066 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:45:04.111 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:45:03.944 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:45:04.197 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:45:09.576 00:00:10.680 TCP 1.101.0.1:3000 -> 23.104.0.1:40824 10 6452 1 2025-11-30 09:46:10.302 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:40538 10 6452 1 2025-11-30 09:47:10.705 00:00:10.438 TCP 1.101.0.1:3000 -> 23.104.0.1:33432 12 10371 1 2025-11-30 09:48:11.188 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:48786 10 6452 1 2025-11-30 09:49:11.587 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:54662 10 6452 1 2025-11-30 09:50:04.411 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:50:04.284 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:50:04.295 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:50:04.328 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:50:04.285 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:46:08.607 00:05:02.071 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 09:46:08.604 00:05:02.076 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 09:50:11.995 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:40848 10 6452 1 2025-11-30 09:51:12.354 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:46974 10 6452 1 2025-11-30 09:52:12.755 00:00:10.392 TCP 1.101.0.1:3000 -> 23.104.0.1:49944 10 6452 1 2025-11-30 09:53:13.186 00:00:10.628 TCP 1.101.0.1:3000 -> 23.104.0.1:56452 10 6452 1 2025-11-30 09:54:13.889 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:38500 10 6452 1 2025-11-30 09:55:04.288 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 09:55:04.420 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:55:04.543 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 09:55:04.543 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 09:55:04.627 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 09:55:14.298 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:57458 11 6492 1 2025-11-30 09:52:08.609 00:05:02.069 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 09:52:08.607 00:05:02.074 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 09:56:14.709 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:52036 10 6452 1 2025-11-30 09:57:15.100 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52592 10 6452 1 2025-11-30 09:58:15.508 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:49164 10 6452 1 Summary: total flows: 140, total bytes: 424876, total packets: 1025, avg bps: 939, avg pps: 0, avg bpp: 414 Time window: 2025-11-30 08:58:08 - 2025-11-30 09:58:25 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0052s User: 0.0017s Wall: 0.0029s flows/second: 47712.9 Runtime: 0.0030s