Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-01 08:59:21.612 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50940 10 6452 1 2025-12-01 09:00:32.147 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:00:31.932 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:00:22.015 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:52900 10 6452 1 2025-12-01 09:00:31.952 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:00:32.084 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:00:32.036 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:01:22.418 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48212 10 6452 1 2025-12-01 08:57:11.233 00:05:57.836 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 08:57:11.230 00:05:57.841 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:02:22.821 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:38004 10 6452 1 2025-12-01 09:03:23.184 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:52416 10 6452 1 2025-12-01 09:04:23.587 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:37636 10 6452 1 2025-12-01 09:05:32.246 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:05:32.178 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:05:32.221 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:05:32.162 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:05:32.284 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:05:23.988 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:34800 10 6452 1 2025-12-01 09:06:24.397 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:33086 10 6452 1 2025-12-01 09:07:24.806 00:00:10.413 TCP 1.101.0.1:3000 -> 23.104.0.1:55168 11 6504 1 2025-12-01 09:03:11.235 00:05:57.839 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:03:11.237 00:05:57.834 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:08:25.257 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:49184 10 6452 1 2025-12-01 09:09:25.622 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:57088 10 6452 1 2025-12-01 09:10:32.310 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:10:32.299 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:10:32.400 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:10:32.229 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:10:32.228 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:10:25.987 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:52894 10 6452 1 2025-12-01 09:11:26.395 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:60844 10 6452 1 2025-12-01 09:12:26.803 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:52254 10 6452 1 2025-12-01 09:13:27.208 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:35866 10 6452 1 2025-12-01 09:09:11.237 00:05:57.836 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:09:11.235 00:05:57.841 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:14:27.571 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:41740 10 6452 1 2025-12-01 09:15:32.704 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:15:32.725 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:15:32.760 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:15:32.557 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:15:32.842 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:15:27.976 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:43222 10 6452 1 2025-12-01 09:16:28.391 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:49080 10 6452 1 2025-12-01 09:17:28.756 00:00:10.390 TCP 1.101.0.1:3000 -> 23.104.0.1:39862 10 6452 1 2025-12-01 09:18:29.187 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:34622 10 6452 1 2025-12-01 09:19:29.547 00:00:10.436 TCP 1.101.0.1:3000 -> 23.104.0.1:33176 10 6452 1 2025-12-01 09:15:11.236 00:05:57.841 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:15:11.239 00:05:57.835 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:20:32.629 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:20:32.485 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:20:32.496 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:20:32.546 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:20:32.479 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:20:30.019 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:35688 10 6452 1 2025-12-01 09:21:30.416 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:58664 10 6452 1 2025-12-01 09:22:30.824 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:42034 10 6452 1 2025-12-01 09:23:31.232 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:56252 10 6452 1 2025-12-01 09:24:31.638 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:57720 10 6452 1 2025-12-01 09:25:32.551 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:25:32.562 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:25:32.635 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:25:32.468 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:25:32.560 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:25:32.039 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56274 10 6452 1 2025-12-01 09:21:11.240 00:05:57.834 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:21:11.239 00:05:57.839 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:26:32.444 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:52190 10 6452 1 2025-12-01 09:27:32.809 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:42332 10 6452 1 2025-12-01 09:28:33.217 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:38930 10 6452 1 2025-12-01 09:29:33.621 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:41726 10 6452 1 2025-12-01 09:30:32.634 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:30:32.375 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:30:32.764 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:30:32.637 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:30:32.847 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:30:34.026 00:00:11.080 TCP 1.101.0.1:3000 -> 23.104.0.1:43082 10 6452 1 2025-12-01 09:31:35.146 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56214 10 6452 1 2025-12-01 09:27:11.243 00:05:57.833 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:27:11.241 00:05:57.838 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:32:35.547 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:42908 10 6452 1 2025-12-01 09:33:35.946 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:46856 10 6452 1 2025-12-01 09:34:36.350 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:53564 10 6452 1 2025-12-01 09:35:32.643 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:35:32.779 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:35:32.750 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:35:32.821 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:35:32.834 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:35:36.753 00:00:16.077 TCP 1.101.0.1:3000 -> 23.104.0.1:33034 10 6452 1 2025-12-01 09:36:42.885 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39314 10 6452 1 2025-12-01 09:37:43.295 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:45604 10 6452 1 2025-12-01 09:33:11.244 00:05:57.836 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:33:11.247 00:05:57.830 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:38:43.701 00:00:10.584 TCP 1.101.0.1:3000 -> 23.104.0.1:46328 10 6452 1 2025-12-01 09:39:44.324 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:58014 10 6452 1 2025-12-01 09:40:32.831 00:00:00.020 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:40:33.058 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:40:32.984 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:40:32.746 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:40:32.934 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:40:44.721 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:54734 12 6556 1 2025-12-01 09:41:45.144 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47882 11 6492 1 2025-12-01 09:42:45.550 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:45142 10 6452 1 2025-12-01 09:43:45.953 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51012 10 6452 1 2025-12-01 09:39:11.247 00:05:57.830 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:39:11.244 00:05:57.835 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:44:46.360 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:59848 10 6452 1 2025-12-01 09:45:33.143 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:45:32.958 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:45:33.164 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:45:33.060 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:45:32.965 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:45:46.768 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:50794 10 6452 1 2025-12-01 09:46:47.186 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:58078 10 6452 1 2025-12-01 09:47:47.588 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57422 10 6452 1 2025-12-01 09:48:47.993 00:00:10.344 TCP 1.101.0.1:3000 -> 23.104.0.1:53346 10 6452 1 2025-12-01 09:49:48.384 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:46404 10 6452 1 2025-12-01 09:45:11.246 00:05:57.837 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:45:11.249 00:05:57.832 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:50:33.586 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:50:33.157 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:50:33.194 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:50:33.502 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:50:33.270 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:50:48.788 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:50356 10 6452 1 2025-12-01 09:51:49.188 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:47682 10 6452 1 2025-12-01 09:52:49.588 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:48154 10 6452 1 2025-12-01 09:53:49.959 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:32822 10 6452 1 2025-12-01 09:54:50.360 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:46114 10 6452 1 2025-12-01 09:55:33.433 00:00:00.027 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 09:55:33.077 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 09:55:33.124 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:55:33.349 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 09:55:33.096 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 09:55:50.765 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:50580 10 6452 1 2025-12-01 09:51:11.257 00:05:57.827 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 09:51:11.259 00:05:57.822 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 09:56:51.129 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36004 10 6452 1 2025-12-01 09:57:51.541 00:00:10.351 TCP 1.101.0.1:3000 -> 23.104.0.1:50382 10 6452 1 Summary: total flows: 139, total bytes: 410744, total packets: 1014, avg bps: 900, avg pps: 0, avg bpp: 405 Time window: 2025-12-01 08:57:11 - 2025-12-01 09:58:01 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0050s User: 0.0008s Wall: 0.0024s flows/second: 58576.1 Runtime: 0.0024s