Been DDOS with possible evidence

Solidsnake07

Distinguished
Aug 25, 2013
86
0
18,640
Hi all

Before i start explaining why i think my internet is been dossed i wanna let everyone know Ive had technicians check my internet line, replaced cables and even tried a friends router. The only thing i can think off is that im been dossed so today i got a friends help and it seems so. I dont know why this is happening to me and i cant think of any personal reasons why someone would do this.

During this i had wireshark open and had found that my router was been slammed with large amounts of information despite the internet not been used at all this causes my router to crash and restart. I run one pc on my network via Ethernet cable and my WiFi is disabled including my wps. I'm using a Belkin n300 surf wireless router.

I had a friend tell me to run "netstat" in cmd as i know what i run and do on my pc i saw some unusual readings. He then told me to run a trace on the ip address to which every time i repeated the process it slightly changed the origin ip. I found through research that i was connecting to spam servers in nanjing china or rather been spammed by.

http://www.ip-adress.com/ip_tracer/58.215.171.46

http://www.dolphinwave.org/spam/CHINANET-GD.txt

I may have all this completely misunderstood as my router event log seems ok but then again i dont know what im reading or dealing with. The large X's are where my ip should be ive removed them deliberately. My internet keeps dropping out every 5mins or so. I live 1km from my exchanged and my internet has been fine till recently.

System Log
03/22/2014 02:13:14 192.168.2.12 login success
03/22/2014 01:56:01 If(PPPoE1) PPP connection ok !
03/22/2014 01:56:00 PPPoE1 get IP:XXXXXXX
03/22/2014 01:55:59 PPPoE1 start PPP
03/22/2014 01:55:59 PPPoE receive PADS
03/22/2014 01:55:59 PPPoE send PADR
03/22/2014 01:55:59 PPPoE receive PADO
03/22/2014 01:55:59 PPPoE send PADI
03/22/2014 01:55:59 ADSL Media Up !
03/22/2014 01:55:12 PPPoE stop
03/22/2014 01:55:12 PPPoE1 stop PPP
03/22/2014 01:55:12 ADSL Media Down !
03/22/2014 01:54:59 If(PPPoE1) PPP connection ok !
03/22/2014 01:54:58 PPPoE1 get IP:XXXXXXXX
03/22/2014 01:54:58 PPPoE1 start PPP
03/22/2014 01:54:58 PPPoE receive PADS
03/22/2014 01:54:58 PPPoE send PADR
03/22/2014 01:54:58 PPPoE receive PADO
03/22/2014 01:54:57 PPPoE send PADI
03/22/2014 01:54:54 Delay 3 second before PADI retry.
03/22/2014 01:54:49 PPPoE send PADI
03/22/2014 01:54:46 Delay 3 second before PADI retry.
03/22/2014 01:54:41 PPPoE send PADR
03/22/2014 01:54:41 PPPoE receive PADO
03/22/2014 01:54:41 PPPoE send PADI
03/22/2014 01:54:41 ADSL Media Up !
03/22/2014 01:53:56 PPPoE stop
03/22/2014 01:53:56 PPPoE1 stop PPP
03/22/2014 01:53:56 ADSL Media Down !
03/22/2014 01:53:39 If(PPPoE1) PPP connection ok !
03/22/2014 01:53:38 PPPoE1 get IP:XXXXXXXXX
03/22/2014 01:53:37 PPPoE1 start PPP
03/22/2014 01:53:37 PPPoE receive PADS
03/22/2014 01:53:37 PPPoE send PADR
03/22/2014 01:53:37 PPPoE receive PADO
03/22/2014 01:53:37 PPPoE send PADI
03/22/2014 01:53:37 ADSL Media Up !
03/22/2014 01:52:52 PPPoE stop
03/22/2014 01:52:52 PPPoE1 stop PPP
03/22/2014 01:52:51 ADSL Media Down !
03/22/2014 01:41:23 sending ACK to 192.168.2.12
03/22/2014 01:31:29 If(PPPoE1) PPP connection ok !
03/22/2014 01:31:28 PPPoE1 get IP:XXXXXXXXX
03/22/2014 01:31:27 PPPoE1 start PPP
03/22/2014 01:31:27 PPPoE receive PADS
03/22/2014 01:31:27 PPPoE send PADR
03/22/2014 01:31:27 PPPoE receive PADO
03/22/2014 01:31:27 PPPoE send PADI
03/22/2014 01:31:24 Delay 3 second before PADI retry.
03/22/2014 01:31:19 PPPoE send PADR
03/22/2014 01:31:19 PPPoE receive PADO
03/22/2014 01:31:19 PPPoE send PADI
03/22/2014 01:31:19 ADSL Media Up !
03/22/2014 01:30:56 PPPoE stop
03/22/2014 01:30:56 PPPoE1 stop PPP
03/22/2014 01:30:56 ADSL Media Down !
03/22/2014 01:29:23 If(PPPoE1) PPP connection ok !
03/22/2014 01:29:22 PPPoE1 get IP:XXXXXXXXXX
03/22/2014 01:29:22 PPPoE1 start PPP
03/22/2014 01:29:22 PPPoE receive PADS

 

Solidsnake07

Distinguished
Aug 25, 2013
86
0
18,640
Ok this is going to sound really unusual i opened my phone line adapter the one use by home phone and internet and found a large amount of dust everywhere and a redback spider living inside...i used a compressed air can to clean it. I found a black and red cable inside had been cut but two blues and a white cable connected. After cleaning this i noticed for the first time in a long time that my noise margin and attenuation levels are stable. It is 3am here so i dont wanna count my chicken before they hatch, i feel dumb asking this but can dust cause a issue plus spiderwebs?
 

Solidsnake07

Distinguished
Aug 25, 2013
86
0
18,640
I dont know to do that how is it done? I found the evidence of the ip behind it.

Firewall Log
03/25/2014 20:11:43 **Ping of Death/Tear Drop** 74.125.109.72, 443->> 192.168.2.12, 58250 (from PPPoE1 Inbound)
03/25/2014 20:07:14 **Ping of Death/Tear Drop** 74.125.109.120, 443->> 192.168.2.12, 57977 (from PPPoE1 Inbound)
03/25/2014 19:32:14 **Ping of Death/Tear Drop** 74.125.109.120, 443->> 192.168.2.12, 56053 (from PPPoE1 Inbound)
03/25/2014 19:23:38 **Ping of Death/Tear Drop** 74.125.109.71, 443->> 192.168.2.12, 55655 (from PPPoE1 Inbound)
03/25/2014 17:19:44 **UDP Loop** 184.105.139.78, 41594->> XXXXXXXXXXX (from PPPoE1 Inbound)
03/25/2014 13:00:18 **TCP FIN Scan** 122.148.3.242, 80->> 192.168.2.12, 50862 (from PPPoE1 Inbound)
03/25/2014 06:36:01 **TCP FIN Scan** 74.125.237.139, 80->> 192.168.2.12, 57742 (from PPPoE1 Inbound)

http://www.ip-adress.com/ip_tracer/74.125.109.72 i think it maybe coming from free airport wifi?