I hope u can help

Data54

Honorable
Feb 6, 2014
2
0
10,510
Im wondering what this is all about???
I looked into my log on SMC 8014wn and found this happening:

2/1/14 01:06:11) Send Discover
(2/1/14 01:06:11) Receive Offer from 64.59.168.40
(2/1/14 01:06:11) Send Request, Request ip = 24.71.227.201
(2/1/14 01:06:11) Receive Ack
(2/1/14 14:47:20) Send Request, Request ip = 24.71.227.201
(2/1/14 14:47:20) Receive Ack
(2/1/14 16:08:20) 192.168.0.24 cusadmin login
(2/1/14 16:10:53) 192.168.0.24 cusadmin logout
Attack name:Chargen scan, 2/1/14 22:34:47 ~ 2/1/14 22:34:47
Attack name:Chargen scan, 2/1/14 23:00:00 ~ 2/1/14 23:00:00
(2/2/14 14:47:36) Send Request, Request ip = 24.71.227.201
(2/2/14 14:47:36) Receive Ack
(2/3/14 14:47:50) Send Request, Request ip = 24.71.227.201
(2/3/14 14:47:50) Receive Ack
(2/3/14 17:06:04) Send Release
(2/3/14 17:06:44) Send Discover
(2/3/14 17:06:44) Receive Offer from 64.59.168.40
(2/3/14 17:06:44) Send Request, Request ip = 24.71.227.201
(2/3/14 17:06:44) Receive Ack
Attack name:Chargen scan, 2/3/14 19:55:34 ~ 2/3/14 19:55:34
(2/3/14 23:40:26) Source:192.168.0.60, Destination:134.249.40.174, Name:
(2/3/14 23:40:26) Source:192.168.0.60, Destination:134.249.40.174, Name:
(2/3/14 23:45:34) Source:192.168.0.60, Destination:37.201.224.159, Name:
(2/3/14 23:45:46) Source:192.168.0.60, Destination:149.5.45.7, Name:
(2/3/14 23:48:28) Source:192.168.0.60, Destination:91.190.216.105, Name:
(2/3/14 23:55:36) Source:192.168.0.60, Destination:108.181.82.113, Name:
(2/3/14 23:55:39) Source:192.168.0.60, Destination:108.181.82.113, Name:
(2/3/14 23:57:45) Source:192.168.0.60, Destination:85.65.50.42, Name:
(2/3/14 23:57:45) Source:192.168.0.60, Destination:85.65.50.42, Name:
(2/4/14 00:06:26) Source:192.168.0.60, Destination:108.181.82.113, Name:NT:urn:schemas-upnp-orgservicÃLayer3Fo
(2/4/14 15:57:58) Send Request, Request ip = 24.71.227.201
(2/4/14 15:57:58) Receive Ack
Attack name:Chargen scan, 2/5/14 06:03:58 ~ 2/5/14 06:03:58
Attack name:Chargen scan, 2/5/14 11:22:16 ~ 2/5/14 11:22:16
Attack name:Chargen scan, 2/5/14 11:22:22 ~ 2/5/14 11:22:22
Attack name:Chargen scan, 2/5/14 11:28:47 ~ 2/5/14 11:28:47
Attack name:Chargen scan, 2/5/14 11:36:58 ~ 2/5/14 11:36:58
Attack name:Chargen scan, 2/5/14 11:47:02 ~ 2/5/14 11:47:02
(2/5/14 15:58:11) Send Request, Request ip = 24.71.227.201
(2/5/14 15:58:11) Receive Ack
Attack name:Chargen scan, 2/5/14 19:02:10 ~ 2/5/14 19:02:10
(2/6/14 15:58:24) Send Request, Request ip = 24.71.227.201
(2/6/14 15:58:24) Receive Ack
(2/6/14 17:47:45) 192.168.0.112 cusadmin login
(2/6/14 22:07:17) 192.168.0.42 cusadmin login
Thanks Mike
 
Solution
All the daily send/ack stuff is just DHCP.

The chargen thing is the only suspicious thing.
The firewall is blocking something it beleives to be dodgy coming from the PC which has the ip address ending.60.
it could be a false alarm but the only thing that is commonly known to use that port/service is crappy malware, make sure you scan that pc with something like avg free, and id recommend a free software firewall like comodo too.

Also try going to start/run (windows key + r), and type services.msc, see if there is a service runing called "chargen". If it is runing stop it.

You could dig deeper with wire-shark but i wouldn't recommend it unless you are a total boffin.
If the scans come back ok I wouldnt worry.

Urumiko

Distinguished
Dec 28, 2013
505
0
19,160
All the daily send/ack stuff is just DHCP.

The chargen thing is the only suspicious thing.
The firewall is blocking something it beleives to be dodgy coming from the PC which has the ip address ending.60.
it could be a false alarm but the only thing that is commonly known to use that port/service is crappy malware, make sure you scan that pc with something like avg free, and id recommend a free software firewall like comodo too.

Also try going to start/run (windows key + r), and type services.msc, see if there is a service runing called "chargen". If it is runing stop it.

You could dig deeper with wire-shark but i wouldn't recommend it unless you are a total boffin.
If the scans come back ok I wouldnt worry.
 
Solution