Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-12-05 13:58:56.952 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:34124 10 6452 1 2025-12-05 13:59:57.315 00:00:10.322 TCP 1.101.0.1:3000 -> 23.104.0.1:38632 10 6452 1 2025-12-05 14:00:57.677 00:00:10.395 TCP 1.101.0.1:3000 -> 23.104.0.1:47990 10 6452 1 2025-12-05 13:57:11.234 00:05:02.247 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 13:57:11.237 00:05:02.242 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 14:01:58.100 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:57090 10 6452 1 2025-12-05 14:02:33.577 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:02:33.653 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:02:33.668 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:02:33.664 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:02:33.750 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:02:58.462 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:49262 10 6452 1 2025-12-05 14:03:58.861 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:36608 10 6452 1 2025-12-05 14:04:59.276 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:37146 10 6452 1 2025-12-05 14:05:59.677 00:00:10.383 TCP 1.101.0.1:3000 -> 23.104.0.1:40540 10 6452 1 2025-12-05 14:03:11.235 00:05:02.248 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 14:07:00.111 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:34132 10 6452 1 2025-12-05 14:03:11.238 00:05:02.243 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 14:07:33.934 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:07:33.589 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:07:33.764 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:07:33.852 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:07:33.846 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:08:00.512 00:00:10.366 TCP 1.101.0.1:3000 -> 23.104.0.1:55038 10 6452 1 2025-12-05 14:09:00.913 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:38006 10 6452 1 2025-12-05 14:10:01.316 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:44914 10 6452 1 2025-12-05 14:11:01.683 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:50028 10 6452 1 2025-12-05 14:12:02.115 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:41334 10 6452 1 2025-12-05 14:12:33.996 00:00:00.047 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:12:33.953 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:12:34.157 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:12:34.003 00:00:00.040 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:12:34.239 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:13:02.479 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:39442 10 6452 1 2025-12-05 14:09:11.239 00:05:02.241 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 14:09:11.236 00:05:02.246 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 14:14:02.897 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:43144 10 6452 1 2025-12-05 14:15:03.314 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:43418 10 6452 1 2025-12-05 14:16:03.717 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:52670 10 6452 1 2025-12-05 14:17:04.148 00:00:10.375 TCP 1.101.0.1:3000 -> 23.104.0.1:41102 10 6452 1 2025-12-05 14:17:34.192 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:17:34.123 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:17:34.177 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:17:34.259 00:00:00.024 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:17:34.261 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:18:04.569 00:00:10.440 TCP 1.101.0.1:3000 -> 23.104.0.1:51858 12 10369 1 2025-12-05 14:15:11.240 00:05:02.244 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 14:19:05.055 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:55466 10 6452 1 2025-12-05 14:15:11.243 00:05:02.239 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 14:20:05.465 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:51790 10 6452 1 2025-12-05 14:21:05.876 00:00:10.367 TCP 1.101.0.1:3000 -> 23.104.0.1:41956 10 6452 1 2025-12-05 14:22:06.284 00:00:10.324 TCP 1.101.0.1:3000 -> 23.104.0.1:40544 10 6452 1 2025-12-05 14:22:34.054 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:22:33.981 00:00:00.025 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:22:34.004 00:00:00.032 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:22:33.971 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:22:33.829 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:23:06.645 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:49178 10 6452 1 2025-12-05 14:24:07.062 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:55240 10 6452 1 2025-12-05 14:21:11.244 00:05:02.242 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 14:21:11.246 00:05:02.237 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 14:25:07.428 00:00:10.332 TCP 1.101.0.1:3000 -> 23.104.0.1:48284 10 6452 1 2025-12-05 14:26:07.794 00:00:10.379 TCP 1.101.0.1:3000 -> 23.104.0.1:47088 10 6452 1 2025-12-05 14:27:08.202 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:34930 10 6452 1 2025-12-05 14:27:34.229 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:27:33.959 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:27:34.261 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:27:34.180 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:27:34.345 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:28:08.606 00:00:10.446 TCP 1.101.0.1:3000 -> 23.104.0.1:41766 12 10369 1 2025-12-05 14:29:09.107 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:35730 10 6452 1 2025-12-05 14:30:09.507 00:00:10.389 TCP 1.101.0.1:3000 -> 23.104.0.1:51182 10 6452 1 2025-12-05 14:27:11.248 00:05:02.237 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 14:27:11.245 00:05:02.242 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 14:31:09.923 00:00:10.321 TCP 1.101.0.1:3000 -> 23.104.0.1:38678 10 6452 1 2025-12-05 14:32:10.286 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:53884 10 6452 1 2025-12-05 14:32:34.210 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:32:34.236 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:32:34.353 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:32:34.128 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:32:34.235 00:00:00.023 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:33:10.693 00:00:10.323 TCP 1.101.0.1:3000 -> 23.104.0.1:47358 10 6452 1 2025-12-05 14:34:11.055 00:00:11.080 TCP 1.101.0.1:3000 -> 23.104.0.1:53992 10 6452 1 2025-12-05 14:35:12.181 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:37580 10 6452 1 2025-12-05 14:36:12.579 00:00:10.361 TCP 1.101.0.1:3000 -> 23.104.0.1:59974 12 6556 1 2025-12-05 14:33:11.247 00:05:02.245 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 14:33:11.249 00:05:02.240 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 14:37:12.981 00:00:10.329 TCP 1.101.0.1:3000 -> 23.104.0.1:45898 10 6452 1 2025-12-05 14:37:34.555 00:00:00.023 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:37:34.311 00:00:00.022 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:37:34.468 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:37:34.473 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:37:34.538 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:38:13.343 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:58640 10 6452 1 2025-12-05 14:39:13.746 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:48366 10 6452 1 2025-12-05 14:40:14.150 00:00:10.327 TCP 1.101.0.1:3000 -> 23.104.0.1:57036 10 6452 1 2025-12-05 14:41:14.521 00:00:10.326 TCP 1.101.0.1:3000 -> 23.104.0.1:47454 10 6452 1 2025-12-05 14:42:14.888 00:00:10.394 TCP 1.101.0.1:3000 -> 23.104.0.1:38844 12 6556 1 2025-12-05 14:42:34.539 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:42:34.451 00:00:00.022 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:42:34.542 00:00:00.022 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:42:34.544 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:42:34.625 00:00:00.022 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:39:11.252 00:05:02.239 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 14:39:11.249 00:05:02.243 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 14:43:15.322 00:00:10.362 TCP 1.101.0.1:3000 -> 23.104.0.1:55394 10 6452 1 2025-12-05 14:44:15.724 00:00:10.370 TCP 1.101.0.1:3000 -> 23.104.0.1:37156 10 6452 1 2025-12-05 14:45:16.134 00:00:10.349 TCP 1.101.0.1:3000 -> 23.104.0.1:53196 10 6452 1 2025-12-05 14:46:16.517 00:00:10.371 TCP 1.101.0.1:3000 -> 23.104.0.1:57400 10 6452 1 2025-12-05 14:47:16.938 00:00:10.387 TCP 1.101.0.1:3000 -> 23.104.0.1:40044 10 6452 1 2025-12-05 14:47:34.487 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:47:34.416 00:00:00.021 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:47:34.550 00:00:00.023 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:47:34.550 00:00:00.020 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:47:34.632 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:48:17.388 00:00:10.359 TCP 1.101.0.1:3000 -> 23.104.0.1:52338 10 6452 1 2025-12-05 14:45:11.254 00:05:02.237 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 14:45:11.251 00:05:02.242 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 14:49:17.787 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:50368 10 6452 1 2025-12-05 14:50:18.195 00:00:10.368 TCP 1.101.0.1:3000 -> 23.104.0.1:54054 10 6452 1 2025-12-05 14:51:18.601 00:00:10.369 TCP 1.101.0.1:3000 -> 23.104.0.1:39768 10 6452 1 2025-12-05 14:52:19.013 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:53770 10 6452 1 2025-12-05 14:52:34.725 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:52:34.671 00:00:00.023 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:52:34.773 00:00:00.021 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:52:34.590 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:52:34.856 00:00:00.021 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:53:19.412 00:00:10.377 TCP 1.101.0.1:3000 -> 23.104.0.1:45716 10 6452 1 2025-12-05 14:54:19.826 00:00:10.325 TCP 1.101.0.1:3000 -> 23.104.0.1:58778 10 6452 1 2025-12-05 14:51:11.256 00:05:02.238 TCP 179.21.23.21:38570 -> 179.21.23.23:179 12 738 1 2025-12-05 14:51:11.253 00:05:02.243 TCP 179.21.23.23:179 -> 179.21.23.21:38570 12 738 1 2025-12-05 14:55:20.186 00:00:10.363 TCP 1.101.0.1:3000 -> 23.104.0.1:47234 10 6452 1 2025-12-05 14:56:20.591 00:00:10.364 TCP 1.101.0.1:3000 -> 23.104.0.1:57238 10 6452 1 2025-12-05 14:57:35.032 00:00:00.024 ICMP 23.107.0.1:0 -> 21.0.198.2:0.0 3 252 1 2025-12-05 14:57:35.234 00:00:00.023 ICMP 21.0.198.2:0 -> 27.107.0.1:8.0 3 252 1 2025-12-05 14:57:34.450 00:00:00.029 ICMP 1.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:57:34.950 00:00:00.024 ICMP 21.0.198.2:0 -> 23.107.0.1:8.0 3 252 1 2025-12-05 14:57:35.218 00:00:00.022 ICMP 21.0.198.2:0 -> 32.102.0.1:8.0 3 252 1 2025-12-05 14:57:20.991 00:00:10.365 TCP 1.101.0.1:3000 -> 23.104.0.1:59998 10 6452 1 2025-12-05 14:58:21.407 00:00:10.439 TCP 1.101.0.1:3000 -> 23.104.0.1:50986 12 10375 1 Summary: total flows: 140, total bytes: 428965, total packets: 1030, avg bps: 932, avg pps: 0, avg bpp: 416 Time window: 2025-12-05 13:57:11 - 2025-12-05 14:58:31 Total flows processed: 140, passed: 140, Blocks skipped: 0, Bytes read: 14624 Sys: 0.0050s User: 0.0025s Wall: 0.0023s flows/second: 60605.1 Runtime: 0.0023s