Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-01 07:58:56.201 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:37400 10 6452 1 2025-12-01 07:59:56.567 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:34046 10 6452 1 2025-12-01 08:00:30.497 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:00:30.922 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:00:31.006 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:00:31.070 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:00:31.071 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:00:56.972 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:52688 10 6452 1 2025-12-01 07:57:11.213 00:05:57.839 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:01:57.405 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:41092 10 6452 1 2025-12-01 07:57:11.210 00:05:57.845 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:02:57.827 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:59112 10 6452 1 2025-12-01 08:03:58.228 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:35288 10 6452 1 2025-12-01 08:04:58.631 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:57754 10 6452 1 2025-12-01 08:05:30.895 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:05:30.947 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:05:31.262 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:05:31.180 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:05:31.078 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:05:59.000 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54806 10 6452 1 2025-12-01 08:06:59.406 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:46736 10 6452 1 2025-12-01 08:03:11.211 00:05:57.843 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:07:59.809 00:00:10.459 TCP 1.101.0.1:3000 -> 23.104.0.1:59178 10 6452 1 2025-12-01 08:03:11.214 00:05:57.838 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:09:00.325 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47956 10 6452 1 2025-12-01 08:10:00.732 00:00:10.611 TCP 1.101.0.1:3000 -> 23.104.0.1:38444 10 6452 1 2025-12-01 08:10:31.406 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:10:31.094 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:10:31.118 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:10:31.324 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:10:30.976 00:00:00.025 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:11:01.384 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58588 10 6452 1 2025-12-01 08:12:01.789 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:56920 10 6452 1 2025-12-01 08:13:02.191 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:40806 10 6452 1 2025-12-01 08:09:11.216 00:05:57.839 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:09:11.213 00:05:57.845 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:14:02.604 00:00:11.020 TCP 1.101.0.1:3000 -> 23.104.0.1:39970 10 6452 1 2025-12-01 08:15:03.674 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:56700 10 6452 1 2025-12-01 08:15:31.329 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:15:31.358 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:15:31.400 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:15:31.351 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:15:31.482 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:16:04.033 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:38334 10 6452 1 2025-12-01 08:17:04.435 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:51972 10 6452 1 2025-12-01 08:18:04.837 00:00:10.458 TCP 1.101.0.1:3000 -> 23.104.0.1:40594 12 10375 1 2025-12-01 08:19:05.333 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:47494 10 6452 1 2025-12-01 08:15:11.216 00:05:57.840 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:15:11.214 00:05:57.845 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:20:05.732 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:51166 10 6452 1 2025-12-01 08:20:31.478 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:20:31.158 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:20:31.182 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:20:31.393 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:20:31.385 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:21:06.146 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35168 10 6452 1 2025-12-01 08:22:06.552 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36694 12 6556 1 2025-12-01 08:23:06.963 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:40930 10 6452 1 2025-12-01 08:24:07.330 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:42032 10 6452 1 2025-12-01 08:25:07.742 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:42098 10 6452 1 2025-12-01 08:25:31.700 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:25:31.539 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:25:31.219 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:25:31.616 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:25:31.411 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:21:11.218 00:05:57.839 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:21:11.215 00:05:57.844 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:26:08.147 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:37480 10 6452 1 2025-12-01 08:27:08.548 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:49796 10 6452 1 2025-12-01 08:28:08.952 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:42534 10 6452 1 2025-12-01 08:29:09.368 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:57298 10 6452 1 2025-12-01 08:30:09.765 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:40018 10 6452 1 2025-12-01 08:30:31.558 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:30:31.498 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:30:31.552 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:30:31.621 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:30:31.635 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:31:10.178 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:46664 10 6452 1 2025-12-01 08:27:11.219 00:05:57.843 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:27:11.221 00:05:57.838 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:32:10.545 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54418 10 6452 1 2025-12-01 08:33:10.944 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:50080 10 6452 1 2025-12-01 08:34:11.365 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47694 10 6452 1 2025-12-01 08:35:11.768 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:52064 10 6452 1 2025-12-01 08:35:31.682 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:35:31.751 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:35:31.676 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:35:31.838 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:35:31.760 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:36:12.189 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:59376 10 6452 1 2025-12-01 08:37:12.597 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:49252 10 6452 1 2025-12-01 08:33:11.223 00:05:57.841 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:33:11.222 00:05:57.845 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:38:13.014 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:46594 10 6452 1 2025-12-01 08:39:13.439 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:60726 10 6452 1 2025-12-01 08:40:13.845 00:00:10.388 TCP 1.101.0.1:3000 -> 23.104.0.1:37562 10 6452 1 2025-12-01 08:40:31.793 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:40:31.512 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:40:31.826 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:40:31.666 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:40:31.909 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:41:14.271 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:41618 10 6452 1 2025-12-01 08:42:14.676 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:51772 10 6452 1 2025-12-01 08:43:15.116 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:40970 10 6452 1 2025-12-01 08:39:11.225 00:05:57.839 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:39:11.223 00:05:57.843 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:44:15.487 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:35640 10 6452 1 2025-12-01 08:45:15.850 00:00:10.388 TCP 1.101.0.1:3000 -> 23.104.0.1:52932 10 6452 1 2025-12-01 08:45:31.821 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:45:31.740 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:45:31.816 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:45:31.912 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:45:31.765 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:46:16.279 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36926 10 6452 1 2025-12-01 08:47:16.684 00:00:10.450 TCP 1.101.0.1:3000 -> 23.104.0.1:56780 12 10369 1 2025-12-01 08:48:17.179 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:36468 10 6452 1 2025-12-01 08:49:17.578 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:59080 10 6452 1 2025-12-01 08:45:11.227 00:05:57.841 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:45:11.229 00:05:57.836 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:50:17.996 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:47448 10 6452 1 2025-12-01 08:50:31.959 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:50:32.043 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:50:31.817 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:50:31.866 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:50:31.923 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:51:18.362 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:56346 10 6452 1 2025-12-01 08:52:18.760 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:32988 10 6452 1 2025-12-01 08:53:19.181 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:52640 10 6452 1 2025-12-01 08:54:19.581 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:40080 10 6452 1 2025-12-01 08:55:32.520 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 08:55:19.987 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:50216 10 6452 1 2025-12-01 08:55:32.519 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 08:55:32.165 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:55:32.439 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 08:55:32.221 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 08:51:11.227 00:05:57.843 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 08:51:11.230 00:05:57.838 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:56:20.396 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:52022 10 6452 1 2025-12-01 08:57:20.799 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:56938 10 6452 1 2025-12-01 08:58:21.205 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39778 10 6452 1 Summary: total flows: 140, total bytes: 424944, total packets: 1026, avg bps: 923, avg pps: 0, avg bpp: 414 Time window: 2025-12-01 07:57:11 - 2025-12-01 08:58:31 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0046s User: 0.0023s Wall: 0.0020s flows/second: 70424.9 Runtime: 0.0020s