Strange traffic - 100% link utilization
-
Hello,
From last few days I got strange issue with pf 2.0-RELEASE (i386) built on Tue Sep 13 17:28:43 EDT 2011, router establishes the connection with the specified address below on port 80 and collects huge amounts of data (since Tuesday almost ~ 140 Gb), it's strange because none of the LAN computers are not trying to connect to these hosts, LAN disconnected, moreover, for the moment and the traffic remained. SNORT is installed but does not show any threats from these hosts. It looks like router itself has established connection on port 80 and retrieve something….
tcp “router”:41605 -> 94.245.70.68:80 ESTABLISHED:ESTABLISHED
4.23.44.0/24
4.23.55.0/24
4.23.60.0/24
4.27.4.0/24
4.27.5.0/24
4.27.6.0/24
8.12.192.0/24
8.12.193.0/24
8.12.212.0/24
62.121.78.0/24
94.245.58.0/24
94.245.68.0/24
94.245.70.0/24
198.78.222.0/24
207.123.55.0/24
-
Could it be a compromised router and a DoS?
I suggest having a look at the traffic exchanged with these hosts via wireshark or something similar to better understand what is going on.