Mar 24 01:17:30 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.231.167:19756 to 192.168.1.101:80 Mar 24 01:18:52 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:2203 to 60.241.205.167:1433 Mar 24 01:27:20 user alert kernel: Intrusion -> TCP packet from [ppp0] 173.245.53.167:15017 to 192.168.1.101:80 Mar 24 01:37:43 user alert kernel: Intrusion -> TCP packet from [ppp0] 195.198.236.88:63620 to 60.241.205.167:8443 Mar 24 01:38:09 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.222.208:22112 to 192.168.1.101:80 Mar 24 01:38:14 syslog info -- MARK -- Mar 24 01:38:59 user alert kernel: Intrusion -> TCP packet from [ppp0] 118.244.137.10:6000 to 60.241.205.167:1433 Mar 24 01:45:32 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:3716 to 60.241.205.167:1433 Mar 24 01:47:48 user alert kernel: Intrusion -> TCP packet from [ppp0] 141.101.98.40:15618 to 192.168.1.101:80 Mar 24 01:57:18 user alert kernel: Intrusion -> TCP packet from [ppp0] 103.22.200.192:53097 to 192.168.1.101:80 Mar 24 02:00:03 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:4263 to 60.241.205.167:1433 Mar 24 02:05:52 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:3224 to 60.241.205.167:1433 Mar 24 02:07:24 user alert kernel: Intrusion -> TCP packet from [ppp0] 103.22.200.243:49486 to 192.168.1.101:80 Mar 24 02:18:17 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.6:47100 to 192.168.1.101:80 Mar 24 02:21:46 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:2180 to 60.241.205.167:1433 Mar 24 02:28:06 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:4018 to 60.241.205.167:1433 Mar 24 02:28:53 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.231.151:46499 to 192.168.1.101:80 Mar 24 02:37:25 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.222.208:47595 to 192.168.1.101:80 Mar 24 02:38:14 syslog info -- MARK -- Mar 24 02:41:15 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:1503 to 60.241.205.167:1433 Mar 24 02:45:49 user alert kernel: Intrusion -> TCP packet from [ppp0] 41.232.14.126:2259 to 60.241.205.167:23 Mar 24 02:47:33 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.222.208:36876 to 192.168.1.101:80 Mar 24 02:52:54 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.203.90:2987 to 60.241.205.167:1433 Mar 24 02:57:31 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.168:9840 to 192.168.1.101:80 Mar 24 03:05:22 user alert kernel: Intrusion -> TCP packet from [ppp0] 116.247.118.204:6000 to 60.241.205.167:1433 Mar 24 03:07:49 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.225.156:37746 to 192.168.1.101:80 Mar 24 03:14:10 user alert kernel: Intrusion -> TCP packet from [ppp0] 180.186.27.68:6000 to 60.241.205.167:1433 Mar 24 03:18:46 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.222.208:64273 to 192.168.1.101:80 Mar 24 03:27:36 user alert kernel: Intrusion -> TCP packet from [ppp0] 173.245.51.220:18119 to 192.168.1.101:80 Mar 24 03:37:18 user alert kernel: Intrusion -> TCP packet from [ppp0] 103.22.200.237:51387 to 192.168.1.101:80 Mar 24 03:38:14 syslog info -- MARK -- Mar 24 03:38:23 user alert kernel: Intrusion -> TCP packet from [ppp0] 218.28.35.100:1244 to 60.241.205.167:3389 Mar 24 03:40:37 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:4555 to 60.241.205.167:1433 Mar 24 03:47:32 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.222.208:14908 to 192.168.1.101:80 Mar 24 03:51:43 user alert kernel: Intrusion -> TCP packet from [ppp0] 42.96.164.226:6000 to 60.241.205.167:1433 Mar 24 03:54:24 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:2876 to 60.241.205.167:1433 Mar 24 03:58:16 user alert kernel: Intrusion -> TCP packet from [ppp0] 103.22.200.197:47305 to 192.168.1.101:80 Mar 24 04:08:50 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.169:40480 to 192.168.1.101:80 Mar 24 04:17:56 user alert kernel: Intrusion -> TCP packet from [ppp0] 173.245.51.168:30372 to 192.168.1.101:80 Mar 24 04:18:52 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:4680 to 60.241.205.167:1433 Mar 24 04:20:45 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:4849 to 60.241.205.167:1433 Mar 24 04:27:54 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.6:22818 to 192.168.1.101:80 Mar 24 04:29:59 user alert kernel: Intrusion -> TCP packet from [ppp0] 219.140.162.172:28127 to 60.241.205.167:65500 Mar 24 04:37:34 user alert kernel: Intrusion -> TCP packet from [ppp0] 141.101.98.41:10220 to 192.168.1.101:80 Mar 24 04:38:14 syslog info -- MARK -- Mar 24 04:39:15 user alert kernel: Intrusion -> TCP packet from [ppp0] 183.245.76.134:6000 to 60.241.205.167:8909 Mar 24 04:39:23 daemon info DHCP SERVER: DHCP request from 24:77:03:22:80:d8 Mar 24 04:39:23 daemon info DHCP SERVER: DHCP ack to 24:77:03:22:80:d8 Mar 24 04:42:08 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:1215 to 60.241.205.167:1433 Mar 24 04:47:30 user alert kernel: Intrusion -> TCP packet from [ppp0] 173.245.53.208:45135 to 192.168.1.101:80 Mar 24 04:54:42 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:3231 to 60.241.205.167:1433 Mar 24 04:57:33 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.225:49576 to 192.168.1.101:80 Mar 24 05:07:25 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:2609 to 60.241.205.167:1433 Mar 24 05:07:58 user alert kernel: Intrusion -> TCP packet from [ppp0] 173.245.55.163:22204 to 192.168.1.101:80 Mar 24 05:08:15 daemon info DHCP SERVER: DHCP request from 14:da:e9:23:d5:9f Mar 24 05:08:15 daemon info DHCP SERVER: DHCP ack to 14:da:e9:23:d5:9f Mar 24 05:12:45 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.203.90:3957 to 60.241.205.167:1433 Mar 24 05:17:27 user alert kernel: Intrusion -> TCP packet from [ppp0] 173.245.49.207:45667 to 192.168.1.101:80 Mar 24 05:26:51 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:3376 to 60.241.205.167:1433 Mar 24 05:27:23 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.169:40473 to 192.168.1.101:80 Mar 24 05:33:20 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:4574 to 60.241.205.167:1433 Mar 24 05:38:14 syslog info -- MARK -- Mar 24 05:39:43 user alert kernel: Intrusion -> TCP packet from [ppp0] 173.245.62.207:40229 to 192.168.1.101:80 Mar 24 05:47:54 user alert kernel: Intrusion -> TCP packet from [ppp0] 173.245.49.206:10507 to 192.168.1.101:80 Mar 24 05:51:11 user alert kernel: Intrusion -> TCP packet from [ppp0] 202.195.79.121:6000 to 60.241.205.167:3306 Mar 24 05:54:44 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:2462 to 60.241.205.167:1433 Mar 24 05:59:05 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.8:22899 to 192.168.1.101:80 Mar 24 06:07:44 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.222.208:54809 to 192.168.1.101:80 Mar 24 06:09:15 user alert kernel: Intrusion -> TCP packet from [ppp0] 218.188.2.198:3763 to 60.241.205.167:139 Mar 24 06:14:55 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.203.90:2457 to 60.241.205.167:1433 Mar 24 06:17:32 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.169:18485 to 192.168.1.101:80 Mar 24 06:19:26 daemon info DHCP SERVER: DHCP request from 44:1e:a1:3b:75:31 Mar 24 06:19:26 daemon info DHCP SERVER: DHCP ack to 44:1e:a1:3b:75:31 Mar 24 06:28:17 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.222.208:50207 to 192.168.1.101:80 Mar 24 06:33:50 user alert kernel: Intrusion -> TCP packet from [ppp0] 88.190.43.117:19051 to 60.241.205.167:8332 Mar 24 06:36:00 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:3880 to 60.241.205.167:1433 Mar 24 06:38:14 syslog info -- MARK -- Mar 24 06:38:31 user alert kernel: Intrusion -> TCP packet from [ppp0] 103.22.200.197:16300 to 192.168.1.101:80 Mar 24 06:47:57 user alert kernel: Intrusion -> TCP packet from [ppp0] 78.47.45.156:31093 to 60.241.205.167:5900 Mar 24 06:48:18 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.225:61014 to 192.168.1.101:80 Mar 24 06:54:09 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:3836 to 60.241.205.167:1433 Mar 24 06:58:20 user alert kernel: Intrusion -> TCP packet from [ppp0] 103.22.200.193:60445 to 192.168.1.101:80 Mar 24 07:08:12 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.245.143:35284 to 192.168.1.101:80 Mar 24 07:11:57 user alert kernel: Intrusion -> TCP packet from [ppp0] 103.1.210.16:6000 to 60.241.205.167:1433 Mar 24 07:12:28 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:3803 to 60.241.205.167:1433 Mar 24 07:19:04 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.6:30509 to 192.168.1.101:80 Mar 24 07:22:07 user alert kernel: Intrusion -> TCP packet from [ppp0] 221.10.226.83:62222 to 60.241.205.167:21111 Mar 24 07:30:10 user alert kernel: Intrusion -> TCP packet from [ppp0] 199.27.128.199:36944 to 192.168.1.101:80 Mar 24 07:34:58 user alert kernel: Intrusion -> TCP packet from [ppp0] 118.244.137.10:6000 to 60.241.205.167:1433 Mar 24 07:37:17 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.222.208:23205 to 192.168.1.101:80 Mar 24 07:38:14 syslog info -- MARK -- Mar 24 07:46:42 user alert kernel: Intrusion -> TCP packet from [ppp0] 58.221.60.155:6000 to 60.241.205.167:1433 Mar 24 07:47:57 user alert kernel: Intrusion -> TCP packet from [ppp0] 202.46.48.27:10922 to 192.168.1.101:80 Mar 24 07:50:19 daemon info DHCP SERVER: DHCP request from 00:a0:96:e9:a7:a3 Mar 24 07:50:19 daemon info DHCP SERVER: DHCP ack to 00:a0:96:e9:a7:a3 Mar 24 08:00:37 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.6:10106 to 192.168.1.101:80 Mar 24 08:04:13 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:1550 to 60.241.205.167:1433 Mar 24 08:06:56 user alert kernel: Intrusion -> TCP packet from [ppp0] 202.103.36.43:65023 to 60.241.205.167:22 Mar 24 08:07:59 user alert kernel: Intrusion -> TCP packet from [ppp0] 103.22.200.243:17892 to 192.168.1.101:80 Mar 24 08:17:23 user alert kernel: Intrusion -> TCP packet from [ppp0] 66.249.74.163:60716 to 192.168.1.101:80 Mar 24 08:20:43 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.203.90:2912 to 60.241.205.167:1433 Mar 24 08:27:26 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.231.156:11076 to 192.168.1.101:80 Mar 24 08:28:42 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:4988 to 60.241.205.167:1433 Mar 24 08:32:10 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:4647 to 60.241.205.167:1433 Mar 24 08:37:22 user alert kernel: Intrusion -> TCP packet from [ppp0] 141.101.98.40:15414 to 192.168.1.101:80 Mar 24 08:38:14 syslog info -- MARK -- Mar 24 08:48:33 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.229.214:61902 to 192.168.1.101:80 Mar 24 08:48:40 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:3945 to 60.241.205.167:1433 Mar 24 08:53:49 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:4862 to 60.241.205.167:1433 Mar 24 08:57:30 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.225:15244 to 192.168.1.101:80 Mar 24 09:07:52 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.221.169:19464 to 192.168.1.101:80 Mar 24 09:08:52 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:1916 to 60.241.205.167:1433 Mar 24 09:12:35 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:3275 to 60.241.205.167:1433 Mar 24 09:17:37 user alert kernel: Intrusion -> TCP packet from [ppp0] 141.101.99.37:39356 to 192.168.1.101:80 Mar 24 09:24:40 user alert kernel: Intrusion -> TCP packet from [ppp0] 121.166.215.214:6000 to 60.241.205.167:1433 Mar 24 09:28:16 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.224:20218 to 192.168.1.101:80 Mar 24 09:32:17 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:4167 to 60.241.205.167:1433 Mar 24 09:38:14 syslog info -- MARK -- Mar 24 09:38:38 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.229.162:26694 to 192.168.1.101:80 Mar 24 09:48:32 user alert kernel: Intrusion -> TCP packet from [ppp0] 119.63.193.195:35013 to 192.168.1.101:80 Mar 24 09:49:51 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:1869 to 60.241.205.167:1433 Mar 24 09:57:56 user alert kernel: Intrusion -> TCP packet from [ppp0] 69.60.181.12:4198 to 60.241.205.167:23 Mar 24 09:57:59 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.212.237:26235 to 192.168.1.101:80 Mar 24 10:08:12 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.246.143:11698 to 192.168.1.101:80 Mar 24 10:11:26 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:1752 to 60.241.205.167:1433 Mar 24 10:17:29 user alert kernel: Intrusion -> TCP packet from [ppp0] 103.22.200.193:52787 to 192.168.1.101:80 Mar 24 10:19:21 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:1975 to 60.241.205.167:1433 Mar 24 10:27:36 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.186.150.195:60209 to 60.241.205.167:23 Mar 24 10:29:47 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.226.168:56349 to 192.168.1.101:80 Mar 24 10:32:31 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.203.90:4407 to 60.241.205.167:1433 Mar 24 10:38:14 syslog info -- MARK -- Mar 24 10:39:04 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.222.208:65317 to 192.168.1.101:80 Mar 24 10:47:59 user alert kernel: Intrusion -> TCP packet from [ppp0] 108.162.212.121:44336 to 192.168.1.101:80 Mar 24 10:53:05 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.222.202:4544 to 60.241.205.167:1433 Mar 24 10:54:34 user alert kernel: Intrusion -> TCP packet from [ppp0] 118.244.137.10:6000 to 60.241.205.167:1433 Mar 24 10:59:20 user alert kernel: Intrusion -> TCP packet from [ppp0] 173.245.62.207:62818 to 192.168.1.101:80 Mar 24 11:05:01 user alert kernel: Intrusion -> TCP packet from [ppp0] 60.241.208.211:4996 to 60.241.205.167:1433