Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-30 18:59:21.899 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:45918 10 6452 1 2025-11-30 19:00:15.928 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:00:15.657 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:00:15.732 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:00:16.070 00:00:00.040 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:00:15.988 00:00:00.040 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:00:22.305 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:42046 10 6452 1 2025-11-30 19:01:22.712 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:49928 10 6452 1 2025-11-30 18:58:08.777 00:05:02.107 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 18:58:08.774 00:05:02.111 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 19:02:23.118 00:00:10.435 TCP 1.101.0.1:3000 -> 23.104.0.1:56046 12 10375 1 2025-11-30 19:03:23.597 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49828 10 6452 1 2025-11-30 19:04:24.001 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:57494 10 6452 1 2025-11-30 19:05:15.465 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:05:15.041 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:05:15.408 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:05:15.408 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:05:15.491 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:05:24.401 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:49500 10 6452 1 2025-11-30 19:06:24.809 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:34214 10 6452 1 2025-11-30 19:07:25.244 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:36346 10 6452 1 2025-11-30 19:04:08.779 00:05:02.105 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 19:04:08.777 00:05:02.110 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 19:08:25.647 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:60756 10 6452 1 2025-11-30 19:09:26.088 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:59994 10 6452 1 2025-11-30 19:10:15.588 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:10:15.438 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:10:15.389 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:10:15.505 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:10:15.601 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:10:26.463 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46536 10 6452 1 2025-11-30 19:11:26.865 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:52954 10 6452 1 2025-11-30 19:12:27.277 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:60500 10 6452 1 2025-11-30 19:13:27.644 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57308 10 6452 1 2025-11-30 19:10:08.777 00:05:02.119 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 19:10:08.779 00:05:02.114 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 19:14:28.053 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37100 10 6452 1 2025-11-30 19:15:15.712 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:15:15.631 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:15:15.685 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:15:15.563 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:15:15.589 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:15:28.463 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:54758 10 6452 1 2025-11-30 19:16:28.865 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:56188 10 6452 1 2025-11-30 19:17:29.272 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:54662 10 6452 1 2025-11-30 19:18:29.677 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:36508 10 6452 1 2025-11-30 19:19:30.111 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:55514 10 6452 1 2025-11-30 19:20:15.933 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:20:15.933 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:16:08.782 00:05:02.115 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 19:20:15.858 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:20:15.795 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:16:08.778 00:05:02.121 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 19:20:16.016 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:20:30.476 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33104 12 6556 1 2025-11-30 19:21:30.877 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:50368 10 6452 1 2025-11-30 19:22:31.279 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:34424 10 6452 1 2025-11-30 19:23:31.644 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39684 10 6452 1 2025-11-30 19:24:32.074 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:33378 10 6452 1 2025-11-30 19:25:15.710 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:25:15.857 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:25:15.915 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:25:15.940 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:25:16.100 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:25:32.481 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:34936 10 6452 1 2025-11-30 19:22:08.783 00:05:02.116 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 19:22:08.779 00:05:02.122 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 19:26:32.881 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:35780 10 6452 1 2025-11-30 19:27:33.282 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:56960 10 6452 1 2025-11-30 19:28:33.685 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:32994 10 6452 1 2025-11-30 19:29:34.107 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:44258 10 6452 1 2025-11-30 19:30:15.711 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:30:15.891 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:30:16.058 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:30:16.002 00:00:00.038 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:30:16.141 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:30:34.508 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:33004 10 6452 1 2025-11-30 19:31:34.915 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:51010 10 6452 1 2025-11-30 19:28:08.780 00:05:02.123 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 19:28:08.784 00:05:02.117 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 19:32:35.279 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:46034 10 6452 1 2025-11-30 19:33:35.681 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:40894 10 6452 1 2025-11-30 19:34:36.099 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:58786 10 6452 1 2025-11-30 19:35:15.867 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:35:15.859 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:35:15.776 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:35:15.615 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:35:15.949 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:35:36.469 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37076 10 6452 1 2025-11-30 19:36:36.876 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:54644 10 6452 1 2025-11-30 19:37:37.289 00:00:10.396 TCP 1.101.0.1:3000 -> 23.104.0.1:44486 12 10369 1 2025-11-30 19:34:08.781 00:05:02.123 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 19:34:08.785 00:05:02.118 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 19:38:37.727 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:53532 10 6452 1 2025-11-30 19:39:38.144 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:37948 10 6452 1 2025-11-30 19:40:16.322 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:40:16.089 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:40:16.277 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:40:16.277 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:40:16.360 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:40:38.553 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:38098 10 6452 1 2025-11-30 19:41:38.962 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:45154 10 6452 1 2025-11-30 19:42:39.373 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:55376 10 6452 1 2025-11-30 19:43:39.737 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:47034 10 6452 1 2025-11-30 19:40:08.787 00:05:02.117 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 19:40:08.785 00:05:02.123 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 19:44:40.110 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:39318 10 6452 1 2025-11-30 19:45:16.539 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:45:16.405 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:45:16.312 00:00:00.026 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:45:16.314 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:45:16.395 00:00:00.026 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:45:40.519 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:42542 10 6452 1 2025-11-30 19:46:40.929 00:00:10.356 TCP 1.101.0.1:3000 -> 23.104.0.1:46630 10 6452 1 2025-11-30 19:47:41.320 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:51410 10 6452 1 2025-11-30 19:48:41.717 00:00:10.402 TCP 1.101.0.1:3000 -> 23.104.0.1:55080 10 6452 1 2025-11-30 19:49:42.158 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41246 10 6452 1 2025-11-30 19:46:08.788 00:05:02.121 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 19:46:08.785 00:05:02.126 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 19:50:16.448 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:50:16.173 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:50:16.394 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:50:16.365 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:50:16.080 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:50:42.566 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:36454 10 6452 1 2025-11-30 19:51:42.965 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:47648 10 6452 1 2025-11-30 19:52:43.364 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:43968 10 6452 1 2025-11-30 19:53:43.765 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:37446 10 6452 1 2025-11-30 19:54:44.182 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56386 10 6452 1 2025-11-30 19:55:16.476 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-11-30 19:55:16.393 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:55:16.135 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-11-30 19:55:16.130 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-11-30 19:55:16.348 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-11-30 19:55:44.593 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:57476 10 6452 1 2025-11-30 19:52:08.787 00:05:02.127 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-11-30 19:52:08.789 00:05:02.123 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-11-30 19:56:45.003 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:55536 10 6452 1 2025-11-30 19:57:45.408 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:48882 10 6452 1 Summary: total flows: 139, total bytes: 418492, total packets: 1016, avg bps: 933, avg pps: 0, avg bpp: 411 Time window: 2025-11-30 18:58:08 - 2025-11-30 19:57:55 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0039s User: 0.0008s Wall: 0.0021s flows/second: 66599.1 Runtime: 0.0021s