Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-02 09:59:31.711 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:44178 10 6452 1 2025-12-02 10:00:32.114 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:50350 10 6452 1 2025-12-02 10:01:02.057 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:01:01.975 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:01:01.874 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:01:02.184 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:01:01.931 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:01:32.529 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:54658 10 6452 1 2025-12-02 09:57:11.765 00:05:57.887 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 09:57:11.762 00:05:57.893 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 10:02:32.936 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:36398 10 6452 1 2025-12-02 10:03:33.357 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:38854 10 6452 1 2025-12-02 10:04:33.755 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:49306 10 6452 1 2025-12-02 10:05:34.115 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:51474 10 6452 1 2025-12-02 10:06:02.299 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:06:02.251 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:06:02.207 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:06:02.297 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:06:02.289 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:06:34.477 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:56512 10 6452 1 2025-12-02 10:07:34.879 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35156 10 6452 1 2025-12-02 10:03:11.764 00:05:57.892 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 10:03:11.767 00:05:57.887 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 10:08:35.287 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:49648 10 6452 1 2025-12-02 10:09:35.688 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:36470 10 6452 1 2025-12-02 10:10:36.056 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:59962 10 6452 1 2025-12-02 10:11:02.521 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:11:02.335 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:11:02.165 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:11:02.438 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:11:02.442 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:11:36.417 00:00:15.692 TCP 1.101.0.1:3000 -> 23.104.0.1:59856 10 6452 1 2025-12-02 10:12:42.147 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:41832 10 6452 1 2025-12-02 10:13:42.549 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:55234 10 6452 1 2025-12-02 10:09:11.766 00:05:57.894 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 10:09:11.768 00:05:57.888 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 10:14:42.948 00:00:10.378 TCP 1.101.0.1:3000 -> 23.104.0.1:57102 10 6452 1 2025-12-02 10:15:43.362 00:00:13.469 TCP 1.101.0.1:3000 -> 23.104.0.1:33524 10 6452 1 2025-12-02 10:16:02.825 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:16:02.420 00:00:00.032 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:16:02.885 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:16:02.895 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:16:02.967 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:16:46.868 00:00:10.396 TCP 1.101.0.1:3000 -> 23.104.0.1:39628 10 6452 1 2025-12-02 10:17:47.305 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:51252 10 6452 1 2025-12-02 10:18:47.674 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:37950 10 6452 1 2025-12-02 10:19:48.037 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:57648 10 6452 1 2025-12-02 10:15:11.768 00:05:57.892 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 10:15:11.770 00:05:57.888 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 10:20:48.449 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:48724 10 6452 1 2025-12-02 10:21:02.609 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:21:02.533 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:21:02.356 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:21:02.527 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:21:02.733 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:21:48.849 00:00:10.393 TCP 1.101.0.1:3000 -> 23.104.0.1:50184 10 6452 1 2025-12-02 10:22:49.279 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:56032 12 10369 1 2025-12-02 10:23:49.758 00:00:10.316 TCP 1.101.0.1:3000 -> 23.104.0.1:42056 10 6452 1 2025-12-02 10:24:50.114 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:47876 10 6452 1 2025-12-02 10:25:50.524 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:41232 10 6452 1 2025-12-02 10:26:02.516 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:26:02.767 00:00:00.029 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:26:02.464 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:26:02.433 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:26:02.543 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:21:11.771 00:05:57.891 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 10:21:11.768 00:05:57.897 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 10:26:50.896 00:00:10.339 TCP 1.101.0.1:3000 -> 23.104.0.1:44178 10 6452 1 2025-12-02 10:27:51.278 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:39714 10 6452 1 2025-12-02 10:28:51.679 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:58450 10 6452 1 2025-12-02 10:29:52.103 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:40036 10 6452 1 2025-12-02 10:30:52.536 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:51120 10 6452 1 2025-12-02 10:31:02.781 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:31:02.721 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:31:02.790 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:31:02.785 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:31:02.872 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:27:11.772 00:05:57.892 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 10:31:52.941 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:40758 10 6452 1 2025-12-02 10:27:11.770 00:05:57.896 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 10:32:53.354 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40840 10 6452 1 2025-12-02 10:33:53.773 00:00:10.381 TCP 1.101.0.1:3000 -> 23.104.0.1:49056 10 6452 1 2025-12-02 10:34:54.206 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:38814 10 6452 1 2025-12-02 10:36:02.848 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:36:02.880 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:35:54.612 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:34214 10 6452 1 2025-12-02 10:36:02.644 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:36:02.848 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:36:02.727 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:36:55.014 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:41350 10 6452 1 2025-12-02 10:37:55.377 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48358 10 6452 1 2025-12-02 10:33:11.773 00:05:57.894 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 10:33:11.776 00:05:57.889 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 10:38:55.783 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:49824 10 6452 1 2025-12-02 10:39:56.193 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:59442 10 6452 1 2025-12-02 10:41:03.151 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:41:03.085 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:41:02.995 00:00:00.049 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:41:03.074 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:41:03.078 00:00:00.049 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:40:56.599 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:40804 10 6452 1 2025-12-02 10:41:56.999 00:00:10.356 TCP 1.101.0.1:3000 -> 23.104.0.1:43150 10 6452 1 2025-12-02 10:42:57.393 00:00:10.436 TCP 1.101.0.1:3000 -> 23.104.0.1:34702 12 10369 1 2025-12-02 10:39:11.778 00:05:57.891 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 10:43:57.864 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:33614 10 6452 1 2025-12-02 10:39:11.775 00:05:57.896 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 10:44:58.235 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:58722 10 6452 1 2025-12-02 10:46:02.921 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:46:02.889 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:46:03.116 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:46:03.009 00:00:00.036 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:46:03.198 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:45:58.598 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:46580 10 6452 1 2025-12-02 10:46:59.006 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:37296 10 6452 1 2025-12-02 10:47:59.417 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:46010 10 6452 1 2025-12-02 10:48:59.814 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:60370 10 6452 1 2025-12-02 10:45:11.779 00:05:57.892 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 10:50:00.223 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:42418 10 6452 1 2025-12-02 10:45:11.776 00:05:57.897 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 10:51:03.222 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:51:03.223 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:51:03.342 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:51:03.221 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:51:03.425 00:00:00.039 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:51:00.584 00:00:10.419 TCP 1.101.0.1:3000 -> 23.104.0.1:43584 11 6504 1 2025-12-02 10:52:01.048 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:52234 10 6452 1 2025-12-02 10:53:01.451 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:60370 10 6452 1 2025-12-02 10:54:01.853 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:43958 10 6452 1 2025-12-02 10:55:02.277 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:54196 10 6452 1 2025-12-02 10:56:03.303 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-02 10:56:03.221 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:56:03.350 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-02 10:56:03.401 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-02 10:56:03.433 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-02 10:51:11.782 00:05:57.891 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-02 10:51:11.779 00:05:57.897 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-02 10:56:02.685 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:45050 10 6452 1 2025-12-02 10:57:03.110 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:48730 10 6452 1 2025-12-02 10:58:03.519 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:51044 10 6452 1 Summary: total flows: 139, total bytes: 418434, total packets: 1015, avg bps: 914, avg pps: 0, avg bpp: 412 Time window: 2025-12-02 09:57:11 - 2025-12-02 10:58:13 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0051s User: 0.0010s Wall: 0.0023s flows/second: 60939.5 Runtime: 0.0023s