Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-01 12:59:13.068 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:50706 10 6452 1 2025-12-01 13:00:13.476 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:59968 10 6452 1 2025-12-01 13:00:36.851 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:00:36.989 00:00:00.049 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:00:36.961 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:00:36.767 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:00:36.850 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:01:13.879 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:51580 10 6452 1 2025-12-01 12:57:11.309 00:05:57.822 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 12:57:11.307 00:05:57.827 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 13:02:14.294 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:35522 10 6452 1 2025-12-01 13:03:14.690 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:54036 10 6452 1 2025-12-01 13:04:15.116 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:35098 10 6452 1 2025-12-01 13:05:15.518 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:45792 10 6452 1 2025-12-01 13:05:37.148 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:05:37.082 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:05:36.744 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:05:37.064 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:05:37.078 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:06:15.882 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:57162 10 6452 1 2025-12-01 13:07:16.251 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:47362 10 6452 1 2025-12-01 13:03:11.310 00:05:57.821 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 13:03:11.310 00:05:57.826 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 13:08:16.655 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:40162 10 6452 1 2025-12-01 13:09:17.070 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:37584 10 6452 1 2025-12-01 13:10:17.432 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:33528 10 6452 1 2025-12-01 13:10:37.137 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:10:37.052 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:10:37.152 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:10:37.054 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:10:37.317 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:11:17.832 00:00:10.395 TCP 1.101.0.1:3000 -> 23.104.0.1:39602 10 6452 1 2025-12-01 13:12:18.270 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54686 10 6452 1 2025-12-01 13:13:18.675 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:58590 10 6452 1 2025-12-01 13:09:11.311 00:05:57.821 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 13:09:11.308 00:05:57.826 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 13:14:19.115 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:39932 10 6452 1 2025-12-01 13:15:19.516 00:00:11.851 TCP 1.101.0.1:3000 -> 23.104.0.1:35428 10 6452 1 2025-12-01 13:15:37.266 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:15:37.295 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:15:37.229 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:15:37.182 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:15:37.192 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:16:21.420 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:51198 10 6452 1 2025-12-01 13:17:21.822 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:42302 10 6452 1 2025-12-01 13:18:22.186 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:50824 10 6452 1 2025-12-01 13:19:22.593 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:38134 10 6452 1 2025-12-01 13:15:11.314 00:05:57.822 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 13:15:11.312 00:05:57.827 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 13:20:37.257 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:20:23.002 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:32836 10 6452 1 2025-12-01 13:20:37.354 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:20:37.409 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:20:37.174 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:20:37.405 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:21:23.371 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36030 10 6452 1 2025-12-01 13:22:23.772 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:43804 10 6452 1 2025-12-01 13:23:24.182 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:59966 10 6452 1 2025-12-01 13:24:24.579 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:59736 10 6452 1 2025-12-01 13:25:24.982 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:42592 10 6452 1 2025-12-01 13:25:37.766 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:25:37.884 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:25:37.894 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:25:37.682 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:25:37.766 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:21:11.312 00:05:57.835 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 13:21:11.314 00:05:57.830 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 13:26:25.393 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:41718 10 6452 1 2025-12-01 13:27:25.754 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:46570 12 10375 1 2025-12-01 13:28:26.229 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:56702 10 6452 1 2025-12-01 13:29:26.634 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:34098 10 6452 1 2025-12-01 13:30:27.059 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:52894 10 6452 1 2025-12-01 13:30:37.635 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:30:37.418 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:30:37.540 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:30:37.385 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:30:37.623 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:31:27.421 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:42272 10 6452 1 2025-12-01 13:27:11.315 00:05:57.831 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 13:27:11.312 00:05:57.836 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 13:32:27.829 00:00:13.640 TCP 1.101.0.1:3000 -> 23.104.0.1:39712 10 6452 1 2025-12-01 13:33:31.540 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:58494 10 6452 1 2025-12-01 13:34:31.945 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:40166 10 6452 1 2025-12-01 13:35:37.979 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:35:37.640 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:35:37.458 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:35:37.896 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:35:37.437 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:35:32.352 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:45060 10 6452 1 2025-12-01 13:36:32.712 00:00:10.388 TCP 1.101.0.1:3000 -> 23.104.0.1:57696 10 6452 1 2025-12-01 13:37:33.137 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:53548 10 6452 1 2025-12-01 13:33:11.318 00:05:57.830 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 13:33:11.314 00:05:57.835 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 13:38:33.549 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:33318 10 6452 1 2025-12-01 13:39:33.954 00:00:10.581 TCP 1.101.0.1:3000 -> 23.104.0.1:33020 10 6452 1 2025-12-01 13:40:37.733 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:40:37.576 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:40:37.731 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:40:37.869 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:40:37.815 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:40:34.573 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:39214 10 6452 1 2025-12-01 13:41:34.975 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:33398 10 6452 1 2025-12-01 13:42:35.350 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:39150 10 6452 1 2025-12-01 13:43:35.754 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:43596 10 6452 1 2025-12-01 13:39:11.319 00:05:57.831 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 13:39:11.316 00:05:57.836 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 13:44:36.150 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:40716 10 6452 1 2025-12-01 13:45:37.860 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:45:37.472 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:45:37.852 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:45:37.955 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:45:37.935 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:45:36.507 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:45638 10 6452 1 2025-12-01 13:46:36.912 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:34144 10 6452 1 2025-12-01 13:47:37.324 00:00:10.399 TCP 1.101.0.1:3000 -> 23.104.0.1:48134 12 10375 1 2025-12-01 13:48:37.763 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:50678 10 6452 1 2025-12-01 13:49:38.187 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:41546 10 6452 1 2025-12-01 13:45:11.320 00:05:57.832 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 13:45:11.317 00:05:57.838 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 13:50:37.941 00:00:00.027 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:50:37.797 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:50:37.968 00:00:00.016 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:50:37.923 00:00:00.032 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:50:38.050 00:00:00.016 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:50:38.567 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:38270 10 6452 1 2025-12-01 13:51:38.977 00:00:10.344 TCP 1.101.0.1:3000 -> 23.104.0.1:56786 10 6452 1 2025-12-01 13:52:39.361 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:57110 10 6452 1 2025-12-01 13:53:39.717 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:35442 10 6452 1 2025-12-01 13:54:40.111 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:49336 10 6452 1 2025-12-01 13:55:38.050 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-01 13:55:37.984 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:55:37.938 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-01 13:55:37.864 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-01 13:55:38.022 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-01 13:55:40.507 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:56208 10 6452 1 2025-12-01 13:51:11.320 00:05:57.832 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-01 13:51:11.319 00:05:57.837 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-01 13:56:40.908 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:39842 10 6452 1 2025-12-01 13:57:41.324 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:57134 10 6452 1 Summary: total flows: 139, total bytes: 418394, total packets: 1014, avg bps: 919, avg pps: 0, avg bpp: 412 Time window: 2025-12-01 12:57:11 - 2025-12-01 13:57:51 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0039s User: 0.0023s Wall: 0.0021s flows/second: 66828.1 Runtime: 0.0021s