Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-01 01:59:17.146 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58348 10 6452 1 2025-12-01 02:00:23.896 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:00:23.551 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:00:23.550 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:00:23.814 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:00:23.887 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:00:17.553 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:37780 10 6452 1 2025-12-01 02:01:17.910 00:00:10.413 TCP 1.101.0.1:3000 -> 23.104.0.1:45990 10 6452 1 2025-12-01 01:58:08.892 00:05:02.188 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 01:58:08.896 00:05:02.183 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 02:02:18.364 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:51670 10 6452 1 2025-12-01 02:03:18.731 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:58658 12 6556 1 2025-12-01 02:04:19.144 00:00:10.319 TCP 1.101.0.1:3000 -> 23.104.0.1:38326 10 6452 1 2025-12-01 02:05:23.993 00:00:00.025 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:05:23.860 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:05:23.734 00:00:00.034 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:05:23.911 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:05:23.789 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:05:19.504 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48958 10 6452 1 2025-12-01 02:06:19.906 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:58406 10 6452 1 2025-12-01 02:07:20.329 00:00:10.683 TCP 1.101.0.1:3000 -> 23.104.0.1:42662 10 6452 1 2025-12-01 02:04:08.896 00:05:02.186 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 02:04:08.899 00:05:02.181 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 02:08:21.055 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:39804 10 6452 1 2025-12-01 02:09:21.460 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:43632 10 6452 1 2025-12-01 02:10:23.839 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:10:23.920 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:10:23.948 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:10:23.634 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:10:24.031 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:10:21.863 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:59776 10 6452 1 2025-12-01 02:11:22.282 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:57490 10 6452 1 2025-12-01 02:12:22.689 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:36912 10 6452 1 2025-12-01 02:13:23.101 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:59116 10 6452 1 2025-12-01 02:10:08.899 00:05:02.187 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 02:10:08.902 00:05:02.182 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 02:14:23.504 00:00:12.013 TCP 1.101.0.1:3000 -> 23.104.0.1:45664 10 6452 1 2025-12-01 02:15:23.885 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:15:23.896 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:15:23.834 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:15:23.804 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:15:24.146 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:15:25.559 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:34786 10 6452 1 2025-12-01 02:16:25.959 00:00:10.623 TCP 1.101.0.1:3000 -> 23.104.0.1:59468 10 6452 1 2025-12-01 02:17:26.620 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:45324 10 6452 1 2025-12-01 02:18:26.985 00:00:11.893 TCP 1.101.0.1:3000 -> 23.104.0.1:50442 10 6452 1 2025-12-01 02:19:28.918 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52712 10 6452 1 2025-12-01 02:16:08.900 00:05:02.188 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 02:16:08.903 00:05:02.182 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 02:20:24.244 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:20:24.135 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:20:24.205 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:20:24.118 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:20:24.288 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:20:29.321 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47842 10 6452 1 2025-12-01 02:21:29.727 00:00:10.388 TCP 1.101.0.1:3000 -> 23.104.0.1:42058 10 6452 1 2025-12-01 02:22:30.142 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37552 10 6452 1 2025-12-01 02:23:30.549 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49998 10 6452 1 2025-12-01 02:24:30.951 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39682 10 6452 1 2025-12-01 02:25:24.375 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:25:24.413 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:25:24.152 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:25:24.293 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:25:24.168 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:25:31.357 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:54904 10 6452 1 2025-12-01 02:22:08.905 00:05:02.182 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 02:22:08.902 00:05:02.187 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 02:26:31.753 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:42232 10 6452 1 2025-12-01 02:27:32.158 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:53354 10 6452 1 2025-12-01 02:28:32.573 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39860 10 6452 1 2025-12-01 02:29:32.979 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:44586 10 6452 1 2025-12-01 02:30:24.607 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:30:24.545 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:30:24.432 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:30:24.525 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:30:24.531 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:30:33.385 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:60492 10 6452 1 2025-12-01 02:31:33.795 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:56102 10 6452 1 2025-12-01 02:28:08.904 00:05:02.195 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 02:28:08.906 00:05:02.190 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 02:32:34.211 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41392 10 6452 1 2025-12-01 02:33:34.608 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41900 10 6452 1 2025-12-01 02:34:35.012 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37522 10 6452 1 2025-12-01 02:35:24.521 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:35:24.517 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:35:24.395 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:35:24.439 00:00:00.025 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:35:24.560 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:35:35.415 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:48686 10 6452 1 2025-12-01 02:36:35.779 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:45548 10 6452 1 2025-12-01 02:37:36.143 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:59146 10 6452 1 2025-12-01 02:34:08.908 00:05:02.192 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 02:34:08.905 00:05:02.197 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 02:38:36.544 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:40994 10 6452 1 2025-12-01 02:39:36.962 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:59932 10 6452 1 2025-12-01 02:40:24.583 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:40:24.390 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:40:24.526 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:40:24.628 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:40:24.610 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:40:37.366 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:37074 10 6452 1 2025-12-01 02:41:37.741 00:00:10.514 TCP 1.101.0.1:3000 -> 23.104.0.1:48100 10 6452 1 2025-12-01 02:42:38.292 00:00:10.416 TCP 1.101.0.1:3000 -> 23.104.0.1:44370 11 6504 1 2025-12-01 02:43:38.750 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:35174 10 6452 1 2025-12-01 02:40:08.910 00:05:02.193 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 02:40:08.914 00:05:02.188 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 02:44:39.150 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:56400 10 6452 1 2025-12-01 02:45:24.698 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:45:24.545 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:45:24.445 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:45:24.616 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:45:24.425 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:45:39.560 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:51658 10 6452 1 2025-12-01 02:46:39.963 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:50500 10 6452 1 2025-12-01 02:47:40.364 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:40726 10 6452 1 2025-12-01 02:48:40.772 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:54630 10 6452 1 2025-12-01 02:49:41.181 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:35084 10 6452 1 2025-12-01 02:46:08.912 00:05:02.192 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 02:46:08.915 00:05:02.187 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 02:50:24.819 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:50:24.823 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:50:24.746 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:50:24.779 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:50:24.862 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:50:41.583 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:58256 10 6452 1 2025-12-01 02:51:41.985 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:44146 10 6452 1 2025-12-01 02:52:42.386 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:55958 10 6452 1 2025-12-01 02:53:42.766 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:58734 10 6452 1 2025-12-01 02:54:43.140 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:36252 10 6452 1 2025-12-01 02:55:24.863 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 02:55:24.842 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 02:55:24.420 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:55:24.782 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 02:55:24.841 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 02:55:43.543 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56454 10 6452 1 2025-12-01 02:52:08.916 00:05:02.188 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 02:52:08.912 00:05:02.193 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 02:56:43.954 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51734 10 6452 1 2025-12-01 02:57:44.358 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52914 10 6452 1 Summary: total flows: 139, total bytes: 410704, total packets: 1013, avg bps: 916, avg pps: 0, avg bpp: 405 Time window: 2025-12-01 01:58:08 - 2025-12-01 02:57:54 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0045s User: 0.0009s Wall: 0.0019s flows/second: 71940.8 Runtime: 0.0019s