Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-02 01:59:01.141 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:34058 10 6452 1 2025-12-02 02:00:01.550 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:53456 10 6452 1 2025-12-02 02:00:52.830 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:00:52.846 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:00:52.675 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:00:52.748 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:00:52.788 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:01:01.949 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:46608 10 6452 1 2025-12-02 01:57:11.593 00:05:57.841 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 01:57:11.595 00:05:57.835 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:02:02.361 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:50954 10 6452 1 2025-12-02 02:03:02.769 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:60116 10 6452 1 2025-12-02 02:04:03.182 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:56770 10 6452 1 2025-12-02 02:05:03.584 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:50932 10 6452 1 2025-12-02 02:05:52.628 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:05:52.731 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:05:52.533 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:05:52.546 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:05:52.548 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:06:03.943 00:00:10.388 TCP 1.101.0.1:3000 -> 23.104.0.1:49212 10 6452 1 2025-12-02 02:07:04.369 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:43398 10 6452 1 2025-12-02 02:03:11.598 00:05:57.834 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:03:11.596 00:05:57.839 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:08:04.770 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:58346 10 6452 1 2025-12-02 02:09:05.178 00:00:10.336 TCP 1.101.0.1:3000 -> 23.104.0.1:58550 10 6452 1 2025-12-02 02:10:05.548 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:55636 10 6452 1 2025-12-02 02:10:52.819 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:10:52.896 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:10:52.559 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:10:52.736 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:10:52.856 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:11:05.913 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:57780 10 6452 1 2025-12-02 02:12:06.315 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:37620 10 6452 1 2025-12-02 02:13:06.715 00:00:10.474 TCP 1.101.0.1:3000 -> 23.104.0.1:40842 14 14298 1 2025-12-02 02:09:11.596 00:05:57.842 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:09:11.599 00:05:57.837 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:14:07.227 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:57234 10 6452 1 2025-12-02 02:15:07.633 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:60088 10 6452 1 2025-12-02 02:15:52.982 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:15:53.093 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:15:52.903 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:15:52.910 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:15:52.985 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:16:08.040 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:50806 10 6452 1 2025-12-02 02:17:08.450 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:59884 10 6452 1 2025-12-02 02:18:08.847 00:00:10.707 TCP 1.101.0.1:3000 -> 23.104.0.1:59532 10 6452 1 2025-12-02 02:19:09.595 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:56280 10 6452 1 2025-12-02 02:15:11.597 00:05:57.842 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:15:11.601 00:05:57.837 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:20:09.961 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:54756 10 6452 1 2025-12-02 02:20:52.774 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:20:52.957 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:20:52.785 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:20:52.784 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:20:52.867 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:21:10.362 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:46538 10 6452 1 2025-12-02 02:22:10.765 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:59664 10 6452 1 2025-12-02 02:23:11.189 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:60974 10 6452 1 2025-12-02 02:24:11.588 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:59264 10 6452 1 2025-12-02 02:25:11.997 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:34054 10 6452 1 2025-12-02 02:25:53.381 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:25:53.164 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:25:53.105 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:25:53.299 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:25:53.302 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:21:11.607 00:05:57.832 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:21:11.604 00:05:57.837 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:26:12.397 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:53400 10 6452 1 2025-12-02 02:27:12.796 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:43398 10 6452 1 2025-12-02 02:28:13.212 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:39582 10 6452 1 2025-12-02 02:29:13.575 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:39750 10 6452 1 2025-12-02 02:30:13.941 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:56816 10 6452 1 2025-12-02 02:30:53.105 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:30:53.046 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:30:53.103 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:30:52.965 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:30:53.186 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:31:14.312 00:00:10.376 TCP 1.101.0.1:3000 -> 23.104.0.1:52140 10 6452 1 2025-12-02 02:27:11.607 00:05:57.833 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:27:11.604 00:05:57.838 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:32:14.737 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:35220 11 6492 1 2025-12-02 02:33:15.144 00:00:10.417 TCP 1.101.0.1:3000 -> 23.104.0.1:49006 11 6504 1 2025-12-02 02:34:15.600 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:43440 10 6452 1 2025-12-02 02:35:16.012 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:53498 10 6452 1 2025-12-02 02:35:53.273 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:35:53.342 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:35:53.373 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:35:53.190 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:35:53.408 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:36:16.412 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33004 10 6452 1 2025-12-02 02:37:16.819 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:33166 10 6452 1 2025-12-02 02:33:11.605 00:05:57.837 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:33:11.609 00:05:57.832 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:38:17.227 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36892 10 6452 1 2025-12-02 02:39:17.627 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:35182 10 6452 1 2025-12-02 02:40:18.040 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:38346 10 6452 1 2025-12-02 02:40:53.493 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:40:53.481 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:40:53.355 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:40:53.411 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:40:53.353 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:41:18.444 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:40544 10 6452 1 2025-12-02 02:42:18.844 00:00:10.396 TCP 1.101.0.1:3000 -> 23.104.0.1:37036 10 6452 1 2025-12-02 02:43:19.278 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58412 10 6452 1 2025-12-02 02:39:11.609 00:05:57.832 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:39:11.606 00:05:57.838 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:44:19.682 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:57366 10 6452 1 2025-12-02 02:45:20.108 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:34932 10 6452 1 2025-12-02 02:45:53.579 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:45:53.554 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:45:53.453 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:45:53.496 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:45:53.554 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:46:20.508 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:45296 10 6452 1 2025-12-02 02:47:20.920 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:37140 10 6452 1 2025-12-02 02:48:21.328 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:38110 10 6452 1 2025-12-02 02:49:21.736 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:40178 10 6452 1 2025-12-02 02:45:11.611 00:05:57.832 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:45:11.608 00:05:57.837 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:50:22.145 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:46470 10 6452 1 2025-12-02 02:50:53.537 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:50:53.545 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:50:53.541 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:50:53.657 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:50:53.621 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:51:22.552 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59232 10 6452 1 2025-12-02 02:52:22.962 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:33020 10 6452 1 2025-12-02 02:53:23.323 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35654 10 6452 1 2025-12-02 02:54:23.727 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:40338 10 6452 1 2025-12-02 02:55:24.139 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:41312 10 6452 1 2025-12-02 02:55:53.701 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 02:55:53.515 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 02:55:53.627 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:55:53.618 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 02:55:53.732 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 02:51:11.611 00:05:57.832 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 02:51:11.608 00:05:57.838 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 02:56:24.508 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:48534 10 6452 1 2025-12-02 02:57:24.912 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:36972 10 6452 1 2025-12-02 02:58:25.316 00:00:10.411 TCP 1.101.0.1:3000 -> 23.104.0.1:49796 11 6504 1 Summary: total flows: 140, total bytes: 424990, total packets: 1027, avg bps: 922, avg pps: 0, avg bpp: 413 Time window: 2025-12-02 01:57:11 - 2025-12-02 02:58:35 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0034s User: 0.0014s Wall: 0.0030s flows/second: 46404.5 Runtime: 0.0030s