Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-04 21:59:31.773 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:42410 10 6452 1 2025-12-04 22:00:32.180 00:00:10.334 TCP 1.101.0.1:3000 -> 23.104.0.1:46594 10 6452 1 2025-12-04 21:57:10.861 00:05:02.234 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 21:57:10.864 00:05:02.228 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 22:01:32.548 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:38726 10 6452 1 2025-12-04 22:02:14.520 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:02:14.530 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:02:14.191 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:02:14.437 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:02:14.435 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:02:32.911 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46000 10 6452 1 2025-12-04 22:03:33.317 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:38258 10 6452 1 2025-12-04 22:04:33.728 00:00:10.372 TCP 1.101.0.1:3000 -> 23.104.0.1:44396 10 6452 1 2025-12-04 22:05:34.142 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:46458 10 6452 1 2025-12-04 22:06:34.541 00:00:11.179 TCP 1.101.0.1:3000 -> 23.104.0.1:37872 10 6452 1 2025-12-04 22:03:10.862 00:05:02.233 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 22:07:14.479 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:07:14.838 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:07:14.730 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:07:14.397 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:07:14.800 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:03:10.866 00:05:02.228 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 22:07:35.740 00:00:10.335 TCP 1.101.0.1:3000 -> 23.104.0.1:49314 10 6452 1 2025-12-04 22:08:36.118 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:49336 10 6452 1 2025-12-04 22:09:36.526 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:58238 10 6452 1 2025-12-04 22:10:36.929 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:54228 10 6452 1 2025-12-04 22:11:37.332 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:39666 10 6452 1 2025-12-04 22:12:14.560 00:00:00.026 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:12:14.452 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:12:14.748 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:12:14.478 00:00:00.025 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:12:14.607 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:12:37.733 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:47630 10 6452 1 2025-12-04 22:09:10.869 00:05:02.228 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 22:09:10.871 00:05:02.223 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 22:13:38.148 00:00:10.434 TCP 1.101.0.1:3000 -> 23.104.0.1:39720 12 10375 1 2025-12-04 22:14:38.625 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:60066 10 6452 1 2025-12-04 22:15:38.985 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:58712 10 6452 1 2025-12-04 22:16:39.347 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:48094 10 6452 1 2025-12-04 22:17:14.826 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:17:14.629 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:17:14.608 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:17:14.743 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:17:14.502 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:17:39.746 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:41196 10 6452 1 2025-12-04 22:18:40.160 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:42998 10 6452 1 2025-12-04 22:15:10.874 00:05:02.226 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 22:15:10.877 00:05:02.220 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 22:19:40.566 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:36498 10 6452 1 2025-12-04 22:20:40.969 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:60400 10 6452 1 2025-12-04 22:21:41.379 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:45034 10 6452 1 2025-12-04 22:22:14.884 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:22:14.554 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:22:14.840 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:22:14.602 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:22:14.969 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:22:41.782 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:44356 10 6452 1 2025-12-04 22:23:42.149 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:59770 10 6452 1 2025-12-04 22:24:42.512 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:36504 10 6452 1 2025-12-04 22:21:10.877 00:05:02.221 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 22:21:10.875 00:05:02.226 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 22:25:42.877 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:47584 10 6452 1 2025-12-04 22:26:43.279 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:47890 10 6452 1 2025-12-04 22:27:14.864 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:27:14.689 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:27:14.683 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:27:14.859 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:27:14.766 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:27:43.682 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:46340 10 6452 1 2025-12-04 22:28:44.113 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:58158 10 6452 1 2025-12-04 22:29:44.518 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46112 10 6452 1 2025-12-04 22:30:44.921 00:00:10.388 TCP 1.101.0.1:3000 -> 23.104.0.1:37416 10 6452 1 2025-12-04 22:27:10.876 00:05:02.226 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 22:27:10.879 00:05:02.222 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 22:31:45.356 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:53784 10 6452 1 2025-12-04 22:32:15.337 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:32:15.241 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:32:14.929 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:32:15.254 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:32:15.298 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:32:45.772 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:57120 10 6452 1 2025-12-04 22:33:46.181 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:36042 10 6452 1 2025-12-04 22:34:46.594 00:00:10.771 TCP 1.101.0.1:3000 -> 23.104.0.1:38314 10 6452 1 2025-12-04 22:35:47.404 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:36546 10 6452 1 2025-12-04 22:36:47.813 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:46528 10 6452 1 2025-12-04 22:33:10.877 00:05:02.226 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 22:37:15.130 00:00:00.030 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:37:15.048 00:00:00.029 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:37:14.882 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:37:15.048 00:00:00.029 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:37:14.949 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:33:10.880 00:05:02.221 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 22:37:48.194 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:49790 10 6452 1 2025-12-04 22:38:48.597 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:37100 10 6452 1 2025-12-04 22:39:48.995 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:36916 10 6452 1 2025-12-04 22:40:49.414 00:00:10.384 TCP 1.101.0.1:3000 -> 23.104.0.1:52724 10 6452 1 2025-12-04 22:41:49.836 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:52830 10 6452 1 2025-12-04 22:42:15.968 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:42:16.103 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:42:16.081 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:42:16.093 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:42:16.175 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:42:50.263 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:55294 10 6452 1 2025-12-04 22:39:10.880 00:05:02.221 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 22:39:10.879 00:05:02.225 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 22:43:50.666 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:59608 10 6452 1 2025-12-04 22:44:51.033 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:44130 10 6452 1 2025-12-04 22:45:51.442 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:51230 10 6452 1 2025-12-04 22:47:15.159 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:46:51.846 00:00:19.225 TCP 1.101.0.1:3000 -> 23.104.0.1:41442 10 6452 1 2025-12-04 22:47:15.185 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:47:15.224 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:47:15.230 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:47:15.305 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:48:01.120 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:35516 10 6452 1 2025-12-04 22:49:01.521 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:38996 10 6452 1 2025-12-04 22:45:10.896 00:05:02.208 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 22:45:10.894 00:05:02.213 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 22:50:01.921 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:46720 10 6452 1 2025-12-04 22:51:02.339 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:33584 10 6452 1 2025-12-04 22:52:02.702 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:34566 10 6452 1 2025-12-04 22:52:15.194 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:52:15.140 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:52:15.463 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:52:15.424 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:52:15.547 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:53:03.114 00:00:10.395 TCP 1.101.0.1:3000 -> 23.104.0.1:42198 12 10375 1 2025-12-04 22:54:03.553 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:36236 10 6452 1 2025-12-04 22:51:10.895 00:05:02.213 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-04 22:55:03.955 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:50106 10 6452 1 2025-12-04 22:51:10.899 00:05:02.208 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-04 22:56:04.326 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:47590 10 6452 1 2025-12-04 22:57:15.148 00:00:00.028 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-04 22:57:15.470 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:57:04.731 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:45988 10 6452 1 2025-12-04 22:57:15.323 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-04 22:57:15.557 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-04 22:57:15.405 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-04 22:58:05.108 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:54572 12 10375 1 Summary: total flows: 139, total bytes: 422317, total packets: 1016, avg bps: 921, avg pps: 0, avg bpp: 415 Time window: 2025-12-04 21:57:10 - 2025-12-04 22:58:15 Total flows processed: 139, passed: 139, Blocks skipped: 0, Bytes read: 14520 Sys: 0.0043s User: 0.0011s Wall: 0.0020s flows/second: 70275.8 Runtime: 0.0020s