PDA

View Full Version : Bizarre Activity on Router/Network? DOS?



Limited
June 15th, 2011, 05:10 PM
Okay, so my internet connection has been a bit weird lately, having it cut out and what not, we think its because the router is overheating and we've put the box vertical which has helped.

I was checking the router settings page just to see if I could find the attenuation section and clicked on the log. At the time the log states the UDP packets were received (with the [DOS] tags), I was watching tv and I believe my mum was on the laptop. I turned the router on and off again at 20:06 to get it to reset (as she had difficulties connecting).

Heres what we know:
0*:**:29:*A:23:CA <- My computer MAC address, set to 192.168.0.2

1*:**:D6:*D:DD:D6 <- pretty sure this is my dads laptop mac address, set to 192.168.0.3

My xbox 360 IP is 192.168.0.10, I network bridge this to my pc (192.168.0.3).
I also have a firewall exception on port 3047 (the port that has packets sent to it) for xbox service on IP 192.168.0.10

My computer was on, xbox was turned off, and my dads laptop was on at the time of UDP packets coming in.

The log from my router admin page, I've removed parts of mac addresses just in case :D


Sat, 2000-01-01 00:00:47 - Initialize LCP.
Sat, 2000-01-01 00:00:47 - LCP is allowed to come up.
Sat, 2000-01-01 00:01:14 - DHCP IP: 192.168.0.2 to MAC address 1*:**:D6:*D:DD:D6
Sat, 2000-01-01 00:01:20 - LCP is allowed to come up.
Sat, 2000-01-01 00:01:24 - CHAP authentication success
Sat, 2000-01-01 00:01:25 - [Internet connected] IP address 87.**12.**01.217 ** IP I mostly get given
Sat, 2000-01-01 00:01:27 - Send out NTP request to time-g.netgear.com
Wed, 2011-06-15 20:07:49 - Receive NTP Reply from time-g.netgear.com
Wed, 2011-06-15 20:07:51 - DHCP IP: 192.168.0.3 to MAC address 0*:**:29:*A:23:CA
Wed, 2011-06-15 20:06:21 - Router start up ******* I REBOOTED IT MANUALLY ************
Wed, 2011-06-15 20:16:36 - UDP Packet - Source:24.109.242.166,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:36 - UDP Packet - Source:89.241.9.56,20054 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:37 - UDP Packet - Source:80.192.206.39,3143 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:37 - UDP Packet - Source:216.26.222.116,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:37 - UDP Packet - Source:24.109.242.166,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:37 - UDP Packet - Source:90.203.49.239,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:37 - UDP Packet - Source:89.241.9.56,20054 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:38 - UDP Packet - Source:98.18.98.40,2154 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:38 - UDP Packet - Source:216.26.222.116,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:38 - UDP Packet - Source:24.109.242.166,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:38 - UDP Packet - Source:75.91.43.184,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:38 - UDP Packet - Source:90.203.49.239,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:38 - UDP Packet - Source:89.241.9.56,20054 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:39 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:39 - UDP Packet - Source:81.135.105.201,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:39 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:39 - UDP Packet - Source:80.192.206.39,3143 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:39 - UDP Packet - Source:86.146.143.181,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:39 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:40 - UDP Packet - Source:86.146.143.181,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:40 - UDP Packet - Source:80.192.206.39,3143 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:40 - UDP Packet - Source:216.26.222.116,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:40 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:40 - UDP Packet - Source:209.170.122.204,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:41 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:41 - UDP Packet - Source:81.135.105.201,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:41 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:41 - UDP Packet - Source:86.146.143.181,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:41 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:42 - UDP Packet - Source:75.91.43.184,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:42 - UDP Packet - Source:78.144.184.249,18815 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:42 - UDP Packet - Source:216.26.222.116,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:42 - UDP Packet - Source:98.18.98.40,2154 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:42 - UDP Packet - Source:90.203.49.239,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:42 - UDP Packet - Source:89.241.9.56,20054 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:42 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:42 - UDP Packet - Source:78.144.184.249,18815 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:43 - UDP Packet - Source:216.26.222.116,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:43 - UDP Packet - Source:98.18.98.40,2154 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:43 - UDP Packet - Source:24.109.242.166,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:43 - UDP Packet - Source:90.203.49.239,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:43 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:43 - UDP Packet - Source:80.192.206.39,3143 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:43 - UDP Packet - Source:78.144.184.249,18815 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:43 - UDP Packet - Source:216.26.222.116,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:43 - UDP Packet - Source:24.109.242.166,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:44 - UDP Packet - Source:90.203.49.239,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:44 - UDP Packet - Source:89.241.9.56,20054 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:44 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:44 - UDP Packet - Source:79.200.62.76,62643 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:44 - UDP Packet - Source:216.26.222.116,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:44 - UDP Packet - Source:98.18.98.40,2154 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:44 - UDP Packet - Source:81.135.105.201,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:44 - UDP Packet - Source:24.109.242.166,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:44 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:45 - UDP Packet - Source:79.200.62.76,62643 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:49 - UDP Packet - Source:217.229.201.149,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:50 - UDP Packet - Source:216.26.222.116,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:16:51 - UDP Packet - Source:86.146.143.181,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:31:38 - DHCP IP: 192.168.0.2 to MAC address 1*:**:D6:*D:DD:D6
Wed, 2011-06-15 20:31:44 - DHCP IP: 192.168.0.2 to MAC address 1*:**:D6:*D:DD:D6
Wed, 2011-06-15 20:31:55 - DHCP IP: 192.168.0.3 to MAC address 0*:**:29:*A:23:CA
Wed, 2011-06-15 20:31:57 - DHCP IP: 192.168.0.2 to MAC address 1*:**:D6:*D:DD:D6
Wed, 2011-06-15 20:32:24 - DHCP IP: 192.168.0.2 to MAC address 1*:**:D6:*D:DD:D6
Wed, 2011-06-15 20:33:11 - DHCP IP: 192.168.0.2 to MAC address 1*:**:D6:*D:DD:D6
Wed, 2011-06-15 20:33:15 - DHCP IP: 192.168.0.2 to MAC address 1*:**:D6:*D:DD:D6
Wed, 2011-06-15 20:33:21 - DHCP IP: 192.168.0.3 to MAC address 0*:**:29:*A:23:CA
Wed, 2011-06-15 20:48:47 - UDP Packet - Source:86.197.22.156,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:48 - UDP Packet - Source:91.138.77.149,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:48 - UDP Packet - Source:84.193.4.212,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:48 - UDP Packet - Source:85.192.244.69,3076 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:48 - UDP Packet - Source:86.197.22.156,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:48 - UDP Packet - Source:85.246.61.181,50671 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:49 - UDP Packet - Source:84.193.4.212,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:49 - UDP Packet - Source:86.197.22.156,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:49 - UDP Packet - Source:85.192.244.69,3076 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:49 - UDP Packet - Source:85.246.61.181,50671 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:50 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:52 - UDP Packet - Source:86.197.22.156,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:52 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:53 - UDP Packet - Source:86.197.22.156,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:53 - UDP Packet - Source:91.138.77.149,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:53 - UDP Packet - Source:85.192.244.69,3076 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:53 - UDP Packet - Source:85.246.61.181,50671 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:54 - UDP Packet - Source:86.197.22.156,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:54 - UDP Packet - Source:85.192.244.69,3076 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:54 - UDP Packet - Source:85.246.61.181,50671 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:55 - UDP Packet - Source:84.193.4.212,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:55 - UDP Packet - Source:85.192.244.69,3076 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:55 - UDP Packet - Source:91.138.77.149,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:55 - UDP Packet - Source:85.246.61.181,50671 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:55 - UDP Packet - Source:91.138.77.149,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:55 - UDP Packet - Source:85.192.244.69,3076 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:48:56 - UDP Packet - Source:85.246.61.181,50671 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 20:51:44 - DHCP IP: 192.168.0.4 to MAC address 0*:25:4*:F2:12:93 ****** DONT RECOGNISE THIS MAC ADDRESS.
Wed, 2011-06-15 21:13:55 - UDP Packet - Source:95.19.177.201,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:13:55 - UDP Packet - Source:86.157.57.247,50305 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:13:56 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:13:56 - UDP Packet - Source:86.8.112.160,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:13:57 - UDP Packet - Source:86.157.57.247,50305 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:13:57 - UDP Packet - Source:209.170.124.113,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:13:59 - UDP Packet - Source:81.184.106.226,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:13:59 - UDP Packet - Source:81.141.195.123,17917 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:13:59 - UDP Packet - Source:86.157.57.247,50305 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:14:00 - UDP Packet - Source:95.19.177.201,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:14:00 - UDP Packet - Source:81.141.195.123,17917 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:14:01 - UDP Packet - Source:95.19.177.201,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:14:01 - UDP Packet - Source:81.141.195.123,17917 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:14:02 - UDP Packet - Source:81.184.106.226,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:14:02 - UDP Packet - Source:95.19.177.201,3074 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:14:02 - UDP Packet - Source:81.141.195.123,17917 Destination:192.168.0.10,3074 - [DOS]
Wed, 2011-06-15 21:41:31 - Administrator login successful - IP:192.168.0.3 ** this is me logging into router ***
Wed, 2011-06-15 21:42:05 - LCP down.
Wed, 2011-06-15 21:42:07 - [Internet disconnected]
Wed, 2011-06-15 21:42:08 - Initialize LCP.
Wed, 2011-06-15 21:42:08 - LCP is allowed to come up.
Wed, 2011-06-15 21:42:13 - CHAP authentication success
Wed, 2011-06-15 21:42:14 - [Internet connected] IP address 9*.1*5.*6.172 ** MY IP **


Anyone think this could be malicious?

Patrickssj6
June 16th, 2011, 11:50 AM
Run PeerBlock and see who is trying to read your comp...probably some crawlers, university stats blabla