MAC Cloning Linksys EA6900

Ximerous

Reputable
Mar 12, 2014
511
0
5,060
ISP: Cox Cable
Router: EA6900

Hi, I think I am under a ddos attack( I am very sure but it could be something else?) , not a very bad one, just slows down my network a bit. But it's annoying as shit. I tried mac cloning and it sort of worked, I looked up my IP it was different, on google but after like 5 second it no longer let me connect to the internet. I tried to do it again or restart modem/router, didn't work. So just wondering how to properly do this because cox wants me to turn my modem off for 24 hours so the server automatically resets my IP however I cannot do this for business reasons and it would just be annoying.

Router log

Incoming log
Source IP address | Destination port number
95.211.212.198 48864
79.175.84.212 48864
98.157.215.115 48864
68.146.183.38 48864
14.219.194.149 48864
189.122.114.120 48864
98.232.190.38 48864
109.153.100.60 48864
197.237.157.188 48864
177.243.200.93 48864
108.162.139.99 48864
31.63.83.41 48864
116.234.99.113 48864
122.87.153.227 48864
90.231.77.155 48864
72.198.185.108 48864
23.113.102.114 48864
116.25.103.115 48864
203.109.175.140 48864
78.241.142.232 48864
49.83.199.132 48864
196.210.70.45 48864
126.65.151.62 48864
79.143.174.224 48864
118.211.12.192 48864
220.233.108.195 48864
190.73.44.48 48864
14.201.73.83 48864
39.32.38.120 48864
93.163.233.251 48864
191.250.214.225 48864
46.166.191.14 48864
183.252.52.250 48864
142.68.49.158 48864
183.157.160.35 48864
110.175.171.121 48864
119.247.151.186 48864
92.108.89.107 48864
110.55.2.21 48864
181.31.49.107 48864
188.17.192.82 48864
79.130.118.179 48864
And many more
If I refresh every second there are usually 3-5 more a second.
 
It could be a random attack they happen all the time and you just get unlucky. Other than use a bit of your bandwidth they have no bad effect because your router is blocking them and your pc never sees the traffic. A real DDoS and you would get thousands in one second.

Just guessing this almost looks like skype traffic. Skype is constantly send junk to random bad addresses.
 
3 packets per second is not a denial of serice attack, and I doubt you would notice any impact. It's a bit strange that different addresses are trying to connect to the same port. Do you ever use Skype or torrent clients?
 
Alright, yea, because it's always a different Ip I figured it was an ametuer ddos, idk what else to call it, because it it just makes loading times a bit slower. I do use Skype but it was still happening when all computers were shut down. Also tell me if I should make a new thread about this or not but... One of my computers (and only one) has super slow load times at first, around five min. So here's a example. Computer starts, I open a browser, I goto any site, takes around 5 minutes, it's loaded, I goto a new tab then a website, it loads instantly. If I close all instances of that browser and start it back up and goto a page it takes 5 min again. When connecting to a game it takes a very long time as well, but once I am in I don't lag. Oh and google chrome just crashes when I start it (I have re installed) this problem started happening when the lag did then I went to the logs ... I did hard reset router and the problem stayed. I'm guessing there connected not sure if my pc is the problem but, the night before I had no issues than the next morning this problem started when I booted my pc.