- 15:43:22.888373 ARP, Request who-has 45.154.108.220 tell 45.154.108.1, length 42
- 15:43:22.890340 IP router-dus-a.ipv4.xidns.net > router-dus-b.ipv4.xidns.net: ESP(spi=0xc6b47071,seq=0x593), length 280
- 15:43:22.890751 IP r1-waw.e-utp.net > as56662.vserver.site: GREv0, length 597: IP6 r1-waw.vyo.tu36.core.pl.ipv6.e-utp.net.44557 > r0-dus.vyo.tu36.core.de.ipv6.e-utp.net.bgp: Flags [P.], seq 1333757856:1333758377, ack 846592345, win 24576, options [nop,nop,TS val 3226691876 ecr 532649021], length 521: BGP
- 15:43:22.890879 IP router-dus-a.ipv4.xidns.net > router-dus-b.ipv4.xidns.net: ESP(spi=0xc6b47071,seq=0x594), length 264
- 15:43:22.891651 ARP, Request who-has 45.154.109.98 tell 45.154.109.1, length 42
- 15:43:22.892232 IP i2shost02.import2shop.de.mysql > 103.158.223.136.45490: Flags [P.], seq 489312951:489313283, ack 1408171128, win 1452, options [nop,nop,TS val 1725111002 ecr 3961725694], length 332
- 15:43:22.892236 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 84
- 15:43:22.892237 ARP, Request who-has 45.154.109.206 tell 45.154.109.1, length 42
- 15:43:22.892680 ARP, Request who-has 45.154.109.28 tell 45.154.109.1, length 42
- 15:43:22.892744 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 116
- 15:43:22.893027 ARP, Request who-has 103.158.223.234 tell 103.158.223.254, length 46
- 15:43:22.896911 ARP, Request who-has powered.by.rdp.sh tell powered.by.rdp.sh, length 46
- 15:43:22.899794 IP router-dus-a.ipv4.xidns.net > router-dus-b.ipv4.xidns.net: ESP(spi=0xc6b47071,seq=0x595), length 104
- 15:43:22.902354 IP6 fe80::a05:e200:11f:fe74 > ff02::1:ff00:1: ICMP6, neighbor solicitation, who has rtr-dus.trasec.net, length 32
- 15:43:22.905123 IP i2shost02.import2shop.de.mysql > 103.158.223.136.45490: Flags [P.], seq 332:904, ack 358, win 1452, options [nop,nop,TS val 1725111005 ecr 3961725704], length 572
- 15:43:22.905127 IP6 fe80::a05:e200:11f:fe74 > ff02::1:ff00:231: ICMP6, neighbor solicitation, who has 2a0f:5707:aa80:103::231, length 32
- 15:43:22.905133 ARP, Request who-has 45.154.109.177 tell 45.154.109.1, length 42
- 15:43:22.906007 IP hostcsr.com.35601 > 103.158.223.70.46878: Flags [.], ack 3905866050, win 6146, options [nop,nop,TS val 2762974492 ecr 3707928836], length 0
- 15:43:22.911390 ARP, Request who-has 103.158.223.212 tell _gateway, length 46
- 15:43:22.913074 IP i2shost02.import2shop.de.mysql > 103.158.223.136.45490: Flags [P.], seq 904:1426, ack 685, win 1452, options [nop,nop,TS val 1725111008 ecr 3961725715], length 522
- 15:43:22.919082 IP r0-fra.e-utp.net > as56662.vserver.site: IP6 r0-fra.vyo.tu30.core.de.ipv6.e-utp.net.bgp > r0-dus.vyo.tu30.core.de.ipv6.e-utp.net.42621: Flags [.], ack 44984286, win 7241, options [nop,nop,TS val 4215027375 ecr 516549905], length 0
- 15:43:22.920275 IP r1-fra.e-utp.net > as56662.vserver.site: IP6 r1-fra.vyo.tu40.core.de.ipv6.e-utp.net.bgp > r0-dus.vyo.tu40.core.de.ipv6.e-utp.net.37827: Flags [.], ack 2940396282, win 3403, options [nop,nop,TS val 2366925103 ecr 4252424011], length 0
- 15:43:22.920399 ARP, Request who-has 45.154.108.179 tell 45.154.108.1, length 42
- 15:43:22.922328 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as208059.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 2103
- ARP, Request who-has bb6a3800.virtua.com.br tell 100.66.181.14, length 28
- 15:43:22.922619 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as56662.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 1942
- ARP, Request who-has bb6a3800.virtua.com.br tell 100.66.181.14, length 28
- 15:43:22.922622 ARP, Request who-has 45.14.69.168 tell cr03.dus.vps.hosting, length 46
- 15:43:22.922632 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 116
- 15:43:22.923144 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as208059.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 2103
- ARP, Request who-has 100.98.0.86 tell 100.66.181.14, length 28
- 15:43:22.923261 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as56662.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 1942
- ARP, Request who-has 100.98.0.86 tell 100.66.181.14, length 28
- 15:43:22.923266 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 116
- 15:43:22.924762 ARP, Request who-has 185.244.27.44 tell 185.244.27.254, length 46
- 15:43:22.924788 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as208059.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 2103
- ARP, Request who-has 192.168.0.227 tell 100.66.181.14, length 28
- 15:43:22.924791 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as56662.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 1942
- ARP, Request who-has 192.168.0.227 tell 100.66.181.14, length 28
- 15:43:22.924798 ARP, Request who-has 185.244.27.218 tell 185.244.27.254, length 46
- 15:43:22.924803 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 84
- 15:43:22.924811 IP i2shost02.import2shop.de.mysql > 103.158.223.136.45490: Flags [P.], seq 1426:3017, ack 1641, win 1452, options [nop,nop,TS val 1725111010 ecr 3961725726], length 1591
- 15:43:22.924815 ARP, Request who-has 103.158.223.245 tell 103.158.223.254, length 46
- 15:43:22.925142 ARP, Request who-has 45.14.69.99 tell cr03.dus.vps.hosting, length 46
- 15:43:22.926494 ARP, Request who-has 45.154.109.137 tell 45.154.109.1, length 42
- 15:43:22.928058 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as56662.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 1942
- ARP, Request who-has 104.194.8.134 tell 100.66.43.254, length 28
- 15:43:22.928063 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as208059.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 2103
- ARP, Request who-has 104.194.8.134 tell 100.66.43.254, length 28
- 15:43:22.928066 ARP, Request who-has 185.244.27.30 tell 185.244.27.254, length 46
- 15:43:22.928077 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as56662.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 1942
- ARP, Request who-has root-mia-01.zerotier.com tell 100.66.43.254, length 28
- 15:43:22.928080 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as208059.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 2103
- ARP, Request who-has root-mia-01.zerotier.com tell 100.66.43.254, length 28
- 15:43:22.928082 ARP, Request who-has 45.152.125.185 tell 45.152.125.254, length 46
- 15:43:22.928383 ARP, Request who-has 45.14.69.201 tell cr03.dus.vps.hosting, length 46
- 15:43:22.928773 ARP, Request who-has 185.244.27.64 tell 185.244.27.254, length 46
- 15:43:22.929181 ARP, Request who-has 103.158.223.19 tell 103.158.223.254, length 46
- 15:43:22.929864 ARP, Request who-has 185.244.27.221 tell 185.244.27.254, length 46
- 15:43:22.930053 IP 150.109.50.44.6474 > 185.244.27.181.domain: 4674 AAAA? casino-cs.eu. (30)
- 15:43:22.930310 ARP, Request who-has 185.244.27.32 tell 185.244.27.254, length 46
- 15:43:22.930801 ARP, Request who-has ae0-1020.metro.mx204-dus6-02.vserver.site tell 45.152.125.254, length 46
- 15:43:22.931262 ARP, Request who-has as205591.vserver.site tell cr03.dus.vps.hosting, length 46
- 15:43:22.931276 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as208059.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 2103
- ARP, Request who-has root-zrh-01.zerotier.com tell 100.66.183.254, length 28
- 15:43:22.931587 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as56662.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 1942
- ARP, Request who-has root-zrh-01.zerotier.com tell 100.66.183.254, length 28
- 15:43:22.931921 ARP, Request who-has ti10-2.cr2.dus.vserver.site tell cr03.dus.vps.hosting, length 46
- 15:43:22.931932 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as208059.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 2103
- ARP, Request who-has root-sgp-01.zerotier.com tell 100.66.183.254, length 28
- 15:43:22.932087 IP ip-194-28-99-186.v4.isp.servpersosystems.net.37337 > as56662.vserver.site.vxlan: VXLAN, flags [I] (0x08), vni 1942
- ARP, Request who-has root-sgp-01.zerotier.com tell 100.66.183.254, length 28
- 15:43:22.932513 ARP, Request who-has 103.158.223.170 tell 103.158.223.254, length 46
- 15:43:22.932935 ARP, Request who-has 45.14.69.7 tell cr03.dus.vps.hosting, length 46
- 15:43:22.933393 ARP, Request who-has 185.244.27.49 tell 185.244.27.254, length 46
- 15:43:22.933798 ARP, Request who-has 45.154.108.63 tell 45.154.108.1, length 42
- 15:43:22.934215 ARP, Request who-has 45.154.109.148 tell 45.154.109.1, length 42
- 15:43:22.934678 ARP, Request who-has 45.154.108.201 tell 45.154.108.1, length 42
- 15:43:22.934768 IP i2shost02.import2shop.de.mysql > 103.158.223.136.45490: Flags [.], seq 3017:5913, ack 2878, win 1452, options [nop,nop,TS val 1725111013 ecr 3961725737], length 2896
- 15:43:22.936057 IP ip176.ip-5-196-203.eu.55287 > voip.leviscop.net.42019: Flags [S], seq 2650319036, win 1024, length 0
- 15:43:22.936066 IP r1-waw.e-utp.net > as56662.vserver.site: GREv0, length 76: IP6 r1-waw.vyo.tu36.core.pl.ipv6.e-utp.net.44557 > r0-dus.vyo.tu36.core.de.ipv6.e-utp.net.bgp: Flags [.], ack 490, win 24573, options [nop,nop,TS val 3226691921 ecr 532649116], length 0
- 15:43:22.936212 IP i2shost02.import2shop.de.mysql > 103.158.223.136.45490: Flags [P.], seq 5913:6863, ack 2878, win 1452, options [nop,nop,TS val 1725111013 ecr 3961725737], length 950
- 15:43:22.937094 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 116
- 15:43:22.938628 IP router-dus-a.ipv4.xidns.net > router-dus-b.ipv4.xidns.net: ESP(spi=0xc6b47071,seq=0x596), length 104
- 15:43:22.942962 ARP, Request who-has dev.rozak.net tell xe-vl306.core05.dus6.vserver.site, length 46
- 15:43:22.945245 IP wk5-5.hetrixtools.com > vs2.bo4.fr: ICMP echo request, id 10912, seq 3, length 64
- 15:43:22.946613 IP i2shost02.import2shop.de.mysql > 103.158.223.136.45490: Flags [P.], seq 6863:7537, ack 3294, win 1452, options [nop,nop,TS val 1725111016 ecr 3961725748], length 674
- 15:43:22.946854 ARP, Request who-has usedworkclothes.com tell 45.152.125.254, length 46
- 15:43:22.950983 IP ip-190-226.4vendeta.com.39298 > one.amadija.de.5980: Flags [.], ack 2431472780, win 229, options [nop,nop,TS val 1520063253 ecr 1146869441], length 0
- 15:43:22.954565 IP r1-fra.e-utp.net > as56662.vserver.site: IP6 svc.e-utp.net.59774 > inferno.e-utp.net.zabbix-agent: Flags [S], seq 443312765, win 65136, options [mss 1416,sackOK,TS val 4198685638 ecr 0,nop,wscale 7], length 0
- 15:43:22.954958 ARP, Request who-has 45.154.109.40 tell 45.154.109.1, length 42
- 15:43:22.955441 ARP, Request who-has 45.154.109.223 tell 45.154.109.1, length 42
- 15:43:22.956157 IP i2shost02.import2shop.de.mysql > 103.158.223.136.45490: Flags [P.], seq 7537:8163, ack 3648, win 1452, options [nop,nop,TS val 1725111018 ecr 3961725758], length 626
- 15:43:22.971999 IP 194.50.94.249 > router-dus-b.ipv4.xidns.net: GREv0, length 313: IP 100.122.1.13.bgp > 100.122.1.14.34395: Flags [P.], seq 3074447319:3074447576, ack 1091991331, win 581, options [nop,nop,TS val 82099595 ecr 3912671891], length 257: BGP
- 15:43:22.972998 IP 194.50.94.249 > router-dus-b.ipv4.xidns.net: GREv0, length 590: IP 100.122.1.13.bgp > 100.122.1.14.34395: Flags [P.], seq 257:791, ack 1, win 581, options [nop,nop,TS val 82099597 ecr 3912672103], length 534: BGP
- 15:43:22.974524 ARP, Request who-has 45.154.108.75 tell 45.154.108.1, length 42
- 15:43:22.975246 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 84
- 15:43:22.975896 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 116
- 15:43:22.976305 ARP, Request who-has 45.154.109.8 tell 45.154.109.1, length 42
- 15:43:22.976578 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 116
- 15:43:22.977240 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 116
- 15:43:22.979182 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 116
- 15:43:22.983480 ARP, Request who-has 45.152.125.154 tell 45.152.125.254, length 46
- 15:43:22.986578 IP r1-waw.e-utp.net > as56662.vserver.site: GREv0, length 581: IP6 r1-waw.vyo.tu36.core.pl.ipv6.e-utp.net.44557 > r0-dus.vyo.tu36.core.de.ipv6.e-utp.net.bgp: Flags [P.], seq 521:1026, ack 490, win 24576, options [nop,nop,TS val 3226691972 ecr 532649116], length 505: BGP
- 15:43:22.987042 ARP, Request who-has 45.154.109.169 tell 45.154.109.1, length 42
- 15:43:22.987460 ARP, Request who-has 103.158.223.162 tell _gateway, length 46
- 15:43:22.988002 IP r1-fra.e-utp.net > as56662.vserver.site: IP6 svc.e-utp.net.59774 > inferno.e-utp.net.zabbix-agent: Flags [.], ack 1181636727, win 509, options [nop,nop,TS val 4198685671 ecr 2479557928], length 0
- 15:43:22.988007 ARP, Request who-has 45.14.69.151 tell ae0.vrrp.mx204-dus6-01.vserver.site, length 46
- 15:43:22.988588 IP r1-fra.e-utp.net > as56662.vserver.site: IP6 svc.e-utp.net.59774 > inferno.e-utp.net.zabbix-agent: Flags [P.], seq 0:21, ack 1, win 509, options [nop,nop,TS val 4198685671 ecr 2479557928], length 21
- 15:43:22.989017 ARP, Request who-has 45.14.69.93 tell ae0.vrrp.mx204-dus6-01.vserver.site, length 46
- 15:43:22.990391 ARP, Request who-has 45.14.69.141 tell ae0.vrrp.mx204-dus6-01.vserver.site, length 46
- 15:43:22.990410 IP 194.50.94.249 > router-dus-b.ipv4.xidns.net: GREv0, length 324: IP 100.122.1.13.bgp > 100.122.1.14.34395: Flags [P.], seq 791:1059, ack 1, win 581, options [nop,nop,TS val 82099612 ecr 3912672104], length 268: BGP
- 15:43:22.990415 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 132
- 15:43:22.990772 IP 194.50.94.249 > router-dus-b.ipv4.xidns.net: GREv0, length 324: IP 100.122.1.13.bgp > 100.122.1.14.34395: Flags [P.], seq 1059:1327, ack 1, win 581, options [nop,nop,TS val 82099614 ecr 3912672121], length 268: BGP
- 15:43:22.990775 IP security.criminalip.com.36903 > voip.leviscop.net.49163: Flags [S], seq 3931982293, win 65535, length 0
- 15:43:22.994606 IP 194.50.94.249 > router-dus-b.ipv4.xidns.net: GREv0, length 962: IP 100.122.1.13.bgp > 100.122.1.14.34395: Flags [P.], seq 1327:2233, ack 1, win 581, options [nop,nop,TS val 82099618 ecr 3912672122], length 906: BGP
- 15:43:22.995421 IP r1-waw.e-utp.net > as56662.vserver.site: GREv0, length 124: IP6 dnscache-node.ipv6.e-utp.net.45740 > dns11.quad9.net.domain: 21399+% [1au] A? region1.analytics.google.com. (72)
- 15:43:22.996078 IP 0-131-44-64.reverse-dns.tinc > middle.bardridista.com.tinc: UDP, length 116
- 15:43:22.998225 IP at2.phix-it.com.tinc > 185.244.27.141.tinc: UDP, length 180
- 15:43:22.999251 IP ip176.ip-5-196-203.eu.55287 > voip.leviscop.net.29210: Flags [S], seq 4111270447, win 1024, length 0
- 15:43:22.999262 IP 185.245.96.165.60622 > 185.244.27.141.targus-getdata: Flags [P.], seq 901227605:901227717, ack 526097893, win 501, options [nop,nop,TS val 286617187 ecr 3476438960], length 112
- 15:43:22.999950 IP at2.phix-it.com.tinc > 185.244.27.141.tinc: UDP, length 1348
- 15:43:23.002369 IP i2shost02.import2shop.de.mysql > 103.158.223.136.45490: Flags [P.], seq 8163:12842, ack 3747, win 1452, options [nop,nop,TS val 1725111030 ecr 3961725804], length 4679
- 15:43:23.004346 IP 185.245.96.165.60326 > 185.244.27.141.targus-getdata: Flags [.], ack 160012574, win 501, options [nop,nop,TS val 286617190 ecr 3476439009], length 0
- 15:43:23.004355 IP 185.245.96.165.60326 > 185.244.27.141.targus-getdata: Flags [P.], seq 0:38, ack 1, win 501, options [nop,nop,TS val 286617191 ecr 3476439009], length 38
- 15:43:23.006665 IP null-249-148-193.fra.ifog.li.40030 > as208059.vserver.site.otv: OTV, flags [I] (0x08), overlay 0, instance 89
- IP6 core01-fra.as208059.net.bgp > edge.dus3.dus.as208059.net.49505: Flags [P.], seq 1202714901:1202715006, ack 842212047, win 944, options [nop,nop,TS val 3065691544 ecr 2321882892], length 105: BGP
