Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-03 09:59:09.430 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:59082 10 6452 1 2025-12-03 10:00:09.800 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:37460 10 6452 1 2025-12-03 09:57:10.121 00:05:02.179 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-03 09:57:10.124 00:05:02.173 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-03 10:01:10.205 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:49660 10 6452 1 2025-12-03 10:01:30.893 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:01:30.889 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:01:30.976 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:01:31.010 00:00:00.038 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:01:30.998 00:00:00.043 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:02:10.606 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:49782 10 6452 1 2025-12-03 10:03:11.011 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:37006 10 6452 1 2025-12-03 10:04:11.417 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:38048 10 6452 1 2025-12-03 10:05:11.826 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:53442 10 6452 1 2025-12-03 10:06:12.230 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:59862 10 6452 1 2025-12-03 10:06:31.471 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:06:31.127 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:06:31.163 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:06:31.389 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:06:31.223 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:03:10.122 00:05:02.179 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-03 10:03:10.125 00:05:02.174 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-03 10:07:12.634 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:34134 10 6452 1 2025-12-03 10:08:13.005 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:57056 10 6452 1 2025-12-03 10:09:13.406 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:50896 10 6452 1 2025-12-03 10:10:13.812 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:43662 10 6452 1 2025-12-03 10:11:14.217 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:56346 10 6452 1 2025-12-03 10:11:31.397 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:11:31.105 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:11:31.516 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:11:31.519 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:11:31.599 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:12:14.614 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:58194 10 6452 1 2025-12-03 10:09:10.125 00:05:02.175 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-03 10:09:10.122 00:05:02.180 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-03 10:13:15.022 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55092 10 6452 1 2025-12-03 10:14:15.428 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58846 10 6452 1 2025-12-03 10:15:15.836 00:00:10.380 TCP 1.101.0.1:3000 -> 23.104.0.1:44866 10 6452 1 2025-12-03 10:16:16.251 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:51728 10 6452 1 2025-12-03 10:16:31.510 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:16:31.353 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:16:31.470 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:16:31.428 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:16:31.450 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:17:16.611 00:00:10.930 TCP 1.101.0.1:3000 -> 23.104.0.1:53930 10 6452 1 2025-12-03 10:18:17.574 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36126 10 6452 1 2025-12-03 10:15:10.127 00:05:02.175 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-03 10:15:10.125 00:05:02.180 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-03 10:19:17.981 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:44534 10 6452 1 2025-12-03 10:20:18.390 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:42084 10 6452 1 2025-12-03 10:21:31.612 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:21:18.792 00:00:10.667 TCP 1.101.0.1:3000 -> 23.104.0.1:43070 10 6452 1 2025-12-03 10:21:31.603 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:21:31.284 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:21:31.529 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:21:31.442 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:22:19.511 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:55160 10 6452 1 2025-12-03 10:23:19.915 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:42006 10 6452 1 2025-12-03 10:24:20.323 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:45106 10 6452 1 2025-12-03 10:21:10.127 00:05:02.175 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-03 10:21:10.125 00:05:02.180 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-03 10:25:20.724 00:00:10.353 TCP 1.101.0.1:3000 -> 23.104.0.1:50802 10 6452 1 2025-12-03 10:26:31.559 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:26:31.559 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:26:21.109 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:38386 10 6452 1 2025-12-03 10:26:31.688 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:26:31.543 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:26:31.640 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:27:21.514 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:48848 10 6452 1 2025-12-03 10:28:21.915 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:41472 10 6452 1 2025-12-03 10:29:22.318 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:58688 10 6452 1 2025-12-03 10:30:22.727 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:43098 10 6452 1 2025-12-03 10:27:10.128 00:05:02.175 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-03 10:27:10.126 00:05:02.180 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-03 10:31:31.890 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:31:23.103 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:40826 10 6452 1 2025-12-03 10:31:31.765 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:31:31.363 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:31:31.806 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:31:31.566 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:32:23.467 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:34742 10 6452 1 2025-12-03 10:33:23.872 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:50438 10 6452 1 2025-12-03 10:34:24.239 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:47528 10 6452 1 2025-12-03 10:35:24.646 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:33942 10 6452 1 2025-12-03 10:36:32.028 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:36:25.049 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:53572 10 6452 1 2025-12-03 10:36:31.809 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:36:31.557 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:36:31.943 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:36:31.861 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:33:10.129 00:05:02.176 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-03 10:33:10.127 00:05:02.181 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-03 10:37:25.454 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:46448 10 6452 1 2025-12-03 10:38:25.863 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:38326 10 6452 1 2025-12-03 10:39:26.280 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:33946 10 6452 1 2025-12-03 10:40:26.681 00:00:10.355 TCP 1.101.0.1:3000 -> 23.104.0.1:41238 10 6452 1 2025-12-03 10:41:31.775 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:41:31.931 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:41:31.631 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:41:31.692 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:41:31.931 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:41:27.107 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:53352 10 6452 1 2025-12-03 10:42:27.469 00:00:15.326 TCP 1.101.0.1:3000 -> 23.104.0.1:45402 10 6452 1 2025-12-03 10:39:10.128 00:05:02.190 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-03 10:39:10.131 00:05:02.186 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-03 10:43:32.837 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:58290 10 6452 1 2025-12-03 10:44:33.245 00:00:11.805 TCP 1.101.0.1:3000 -> 23.104.0.1:52254 10 6452 1 2025-12-03 10:45:35.116 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:38736 10 6452 1 2025-12-03 10:46:32.087 00:00:00.031 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:46:31.909 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:46:31.862 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:46:32.005 00:00:00.030 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:46:31.955 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:46:35.517 00:00:10.358 TCP 1.101.0.1:3000 -> 23.104.0.1:49712 10 6452 1 2025-12-03 10:47:35.915 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:41832 10 6452 1 2025-12-03 10:48:36.321 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39082 10 6452 1 2025-12-03 10:45:10.135 00:05:02.176 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-03 10:45:10.138 00:05:02.171 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-03 10:49:36.723 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:44100 10 6452 1 2025-12-03 10:50:37.102 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:33094 10 6452 1 2025-12-03 10:51:32.237 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:51:32.087 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:51:31.859 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:51:32.155 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:51:32.008 00:00:00.031 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:51:37.511 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:48630 10 6452 1 2025-12-03 10:52:37.914 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:43444 10 6452 1 2025-12-03 10:53:38.277 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:34170 10 6452 1 2025-12-03 10:54:38.704 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39430 10 6452 1 2025-12-03 10:51:10.136 00:05:02.176 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-03 10:51:10.139 00:05:02.171 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-03 10:55:39.114 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:52032 10 6452 1 2025-12-03 10:56:32.140 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-03 10:56:32.244 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-03 10:56:32.006 00:00:00.047 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:56:32.058 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-03 10:56:32.381 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-03 10:56:39.519 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:55922 10 6452 1 2025-12-03 10:57:39.927 00:00:10.448 TCP 1.101.0.1:3000 -> 23.104.0.1:43694 12 10369 1 2025-12-03 10:58:40.414 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:44788 10 6452 1 Summary: total flows: 140, total bytes: 420917, total packets: 1022, avg bps: 909, avg pps: 0, avg bpp: 411 Time window: 2025-12-03 09:57:10 - 2025-12-03 10:58:50 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0038s User: 0.0019s Wall: 0.0019s flows/second: 71943.5 Runtime: 0.0020s