Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-05 06:58:47.919 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:37042 10 6452 1 2025-12-05 06:59:48.329 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:53024 10 6452 1 2025-12-05 07:00:48.691 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:53976 10 6452 1 2025-12-05 06:57:11.100 00:05:02.188 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 06:57:11.097 00:05:02.193 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 07:01:49.106 00:00:10.373 TCP 1.101.0.1:3000 -> 23.104.0.1:54698 10 6452 1 2025-12-05 07:02:25.369 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:02:25.193 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:02:25.361 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:02:25.309 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:02:25.443 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:02:49.531 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:35050 10 6452 1 2025-12-05 07:03:49.933 00:00:10.466 TCP 1.101.0.1:3000 -> 23.104.0.1:43354 12 10375 1 2025-12-05 07:04:50.441 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:35428 10 6452 1 2025-12-05 07:05:50.843 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:48148 10 6452 1 2025-12-05 07:06:51.264 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:41918 10 6452 1 2025-12-05 07:03:11.098 00:05:02.194 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 07:03:11.102 00:05:02.189 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 07:07:25.399 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:07:25.364 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:07:25.012 00:00:00.038 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:07:25.317 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:07:25.257 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:07:51.668 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:48870 10 6452 1 2025-12-05 07:08:52.093 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:37832 10 6452 1 2025-12-05 07:09:52.452 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55028 10 6452 1 2025-12-05 07:10:52.858 00:00:10.333 TCP 1.101.0.1:3000 -> 23.104.0.1:58414 10 6452 1 2025-12-05 07:11:53.235 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:49538 10 6452 1 2025-12-05 07:12:25.506 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:12:25.346 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:12:25.286 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:12:25.424 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:12:25.345 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:12:53.608 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:38636 10 6452 1 2025-12-05 07:09:11.101 00:05:02.195 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 07:09:11.102 00:05:02.190 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 07:13:54.017 00:00:10.403 TCP 1.101.0.1:3000 -> 23.104.0.1:46864 12 10375 1 2025-12-05 07:14:54.457 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:41928 10 6452 1 2025-12-05 07:15:54.830 00:00:10.386 TCP 1.101.0.1:3000 -> 23.104.0.1:57148 10 6452 1 2025-12-05 07:16:55.258 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:43646 10 6452 1 2025-12-05 07:17:25.425 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:17:25.438 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:17:25.411 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:17:25.343 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:17:25.329 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:17:55.673 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:37414 10 6452 1 2025-12-05 07:18:56.110 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:57650 10 6452 1 2025-12-05 07:15:11.103 00:05:02.193 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 07:15:11.100 00:05:02.198 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 07:19:56.510 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:33900 10 6452 1 2025-12-05 07:20:56.911 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:54234 10 6452 1 2025-12-05 07:21:57.318 00:00:10.331 TCP 1.101.0.1:3000 -> 23.104.0.1:49892 10 6452 1 2025-12-05 07:22:25.775 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:22:25.542 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:22:25.711 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:22:25.692 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:22:25.696 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:22:57.682 00:00:10.330 TCP 1.101.0.1:3000 -> 23.104.0.1:34752 10 6452 1 2025-12-05 07:23:58.065 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:60366 10 6452 1 2025-12-05 07:24:58.428 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37228 10 6452 1 2025-12-05 07:21:11.106 00:05:02.190 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 07:21:11.104 00:05:02.195 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 07:25:58.833 00:00:10.405 TCP 1.101.0.1:3000 -> 23.104.0.1:43364 10 6452 1 2025-12-05 07:26:59.281 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:54636 10 6452 1 2025-12-05 07:27:25.655 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:27:25.683 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:27:25.699 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:27:25.572 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:27:25.680 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:27:59.682 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:37564 10 6452 1 2025-12-05 07:29:00.107 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:48502 10 6452 1 2025-12-05 07:30:00.507 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:40666 10 6452 1 2025-12-05 07:31:00.917 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:46430 10 6452 1 2025-12-05 07:27:11.107 00:05:02.199 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 07:27:11.105 00:05:02.204 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 07:32:01.325 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:46036 10 6452 1 2025-12-05 07:32:25.882 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:32:25.795 00:00:00.024 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:32:25.755 00:00:00.024 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:32:25.800 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:32:25.735 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:33:01.731 00:00:10.374 TCP 1.101.0.1:3000 -> 23.104.0.1:47820 10 6452 1 2025-12-05 07:34:02.140 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:54840 10 6452 1 2025-12-05 07:35:02.545 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:43410 10 6452 1 2025-12-05 07:36:02.954 00:00:10.385 TCP 1.101.0.1:3000 -> 23.104.0.1:43508 10 6452 1 2025-12-05 07:37:03.375 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:50164 10 6452 1 2025-12-05 07:33:11.108 00:05:02.199 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 07:33:11.107 00:05:02.205 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 07:37:25.713 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:37:25.638 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:37:25.814 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:37:25.873 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:37:25.898 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:38:03.776 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:49872 10 6452 1 2025-12-05 07:39:04.189 00:00:10.328 TCP 1.101.0.1:3000 -> 23.104.0.1:57608 10 6452 1 2025-12-05 07:40:04.552 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:48868 10 6452 1 2025-12-05 07:41:04.955 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:36876 10 6452 1 2025-12-05 07:42:05.319 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:40930 10 6452 1 2025-12-05 07:42:25.884 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:42:26.070 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:42:26.074 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:42:26.229 00:00:00.031 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:42:26.156 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:39:11.106 00:05:02.205 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 07:39:11.110 00:05:02.200 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 07:43:05.678 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:50256 10 6452 1 2025-12-05 07:44:06.098 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:52192 10 6452 1 2025-12-05 07:45:06.507 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:43514 10 6452 1 2025-12-05 07:46:06.917 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:44894 10 6452 1 2025-12-05 07:47:07.328 00:00:10.360 TCP 1.101.0.1:3000 -> 23.104.0.1:60934 10 6452 1 2025-12-05 07:47:25.829 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:47:26.252 00:00:00.010 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:47:26.091 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:47:26.147 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:47:26.218 00:00:00.031 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:48:07.728 00:00:14.641 TCP 1.101.0.1:3000 -> 23.104.0.1:59022 10 6452 1 2025-12-05 07:45:11.111 00:05:02.200 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 07:45:11.109 00:05:02.205 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 07:49:12.410 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:52976 10 6452 1 2025-12-05 07:50:12.781 00:00:11.491 TCP 1.101.0.1:3000 -> 23.104.0.1:60672 10 6452 1 2025-12-05 07:51:14.312 00:00:10.320 TCP 1.101.0.1:3000 -> 23.104.0.1:34712 10 6452 1 2025-12-05 07:52:14.674 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:58922 10 6452 1 2025-12-05 07:52:26.243 00:00:00.027 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:52:26.252 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:52:26.238 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:52:26.034 00:00:00.021 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:52:26.320 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:53:15.114 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:49600 10 6452 1 2025-12-05 07:54:15.516 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:32874 10 6452 1 2025-12-05 07:51:11.109 00:05:02.206 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 07:51:11.113 00:05:02.200 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 07:55:15.925 00:00:10.382 TCP 1.101.0.1:3000 -> 23.104.0.1:49094 10 6452 1 2025-12-05 07:56:16.345 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:38608 10 6452 1 2025-12-05 07:57:26.124 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 07:57:26.370 00:00:00.021 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 07:57:26.264 00:00:00.028 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:57:26.041 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 07:57:26.246 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 07:57:16.752 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:38624 10 6452 1 2025-12-05 07:58:17.157 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:36714 10 6452 1 Summary: total flows: 140, total bytes: 424846, total packets: 1024, avg bps: 924, avg pps: 0, avg bpp: 414 Time window: 2025-12-05 06:57:11 - 2025-12-05 07:58:27 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0044s User: 0.0009s Wall: 0.0019s flows/second: 74660.2 Runtime: 0.0019s