Mon May 27 01:14:00 2019 local5.info geoip-daemon[7900]: verdict 1 1048576 Mon May 27 01:14:01 2019 local5.info geoip-daemon[7900]: {"t":117382198,"ip":-1807177319,"category":"wd","distance":830, "lat": 50, "lng": 8, "rtt": 0, "islan2wan": true } Mon May 27 01:14:01 2019 local5.info geoip-daemon[7900]: verdict 1 524288 Mon May 27 01:14:19 2019 kern.info kernel: [117400.632000] recv: nf_ct_get failed Mon May 27 01:14:19 2019 kern.info kernel: [117400.632000] send: nf_ct_get failed Mon May 27 01:14:23 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:14:23 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:14:23 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:14:23 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:14:34 2019 local5.info geoip-daemon[7900]: {"t":117415208,"ip":1605618708,"category":"wd","distance":302, "lat": 51, "lng": 0, "rtt": 0, "islan2wan": true } Mon May 27 01:14:34 2019 local5.info geoip-daemon[7900]: verdict 1 524288 Mon May 27 01:14:34 2019 local5.info geoip-daemon[7900]: {"t":117415212,"ip":1605618708,"category":"wd","distance":302, "lat": 51, "lng": 0, "rtt": 0, "islan2wan": true } Mon May 27 01:14:34 2019 local5.info geoip-daemon[7900]: verdict 1 524288 Mon May 27 01:14:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:14:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:14:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:15:23 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:15:23 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:15:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:17:57 2019 daemon.info hostapd: wlan0: STA 28:24:ff:8e:0d:9a WPA: group key handshake completed (RSN) Mon May 27 01:17:59 2019 daemon.info hostapd: wlan0: STA a4:93:3f:e5:e7:91 WPA: group key handshake completed (RSN) Mon May 27 01:18:34 2019 kern.info kernel: [117655.672000] recv: nf_ct_get failed Mon May 27 01:18:34 2019 kern.info kernel: [117655.672000] send: nf_ct_get failed Mon May 27 01:19:23 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:19:28 2019 daemon.warn odhcpd[739]: Failed to send to ff02::1%br-lan (Operation not permitted) Mon May 27 01:20:59 2019 kern.info kernel: [117799.924000] recv: nf_ct_get failed Mon May 27 01:20:59 2019 kern.info kernel: [117799.924000] send: nf_ct_get failed Mon May 27 01:21:37 2019 kern.info kernel: [117838.224000] recv: nf_ct_get failed Mon May 27 01:21:37 2019 kern.info kernel: [117838.224000] send: nf_ct_get failed Mon May 27 01:21:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:21:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:22:23 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:22:23 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:22:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:22:58 2019 kern.info kernel: [117918.936000] recv: nf_ct_get failed Mon May 27 01:22:58 2019 kern.info kernel: [117918.936000] send: nf_ct_get failed Mon May 27 01:22:58 2019 kern.info kernel: [117919.708000] recv: nf_ct_get failed Mon May 27 01:22:58 2019 kern.info kernel: [117919.708000] send: nf_ct_get failed Mon May 27 01:22:59 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-c45a5c.sjc02.hls.ttvnw.net Mon May 27 01:23:01 2019 kern.info kernel: [117922.000000] recv: nf_ct_get failed Mon May 27 01:23:01 2019 kern.info kernel: [117922.000000] send: nf_ct_get failed Mon May 27 01:23:01 2019 kern.info kernel: [117922.000000] recv: nf_ct_get failed Mon May 27 01:23:01 2019 kern.info kernel: [117922.000000] send: nf_ct_get failed Mon May 27 01:23:01 2019 kern.info kernel: [117922.000000] recv: nf_ct_get failed Mon May 27 01:23:01 2019 kern.info kernel: [117922.000000] send: nf_ct_get failed Mon May 27 01:23:01 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: clients4.google.com Mon May 27 01:23:01 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: clients4.google.com Mon May 27 01:23:01 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: clients4.google.com Mon May 27 01:23:02 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: api.branch.io Mon May 27 01:23:02 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: api.branch.io Mon May 27 01:23:04 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-c45a5c.sjc02.hls.ttvnw.net Mon May 27 01:23:06 2019 daemon.info hostapd: wlan0: STA a4:93:3f:e5:e7:91 IEEE 802.11: disassociated Mon May 27 01:23:07 2019 daemon.info hostapd: wlan0: STA a4:93:3f:e5:e7:91 IEEE 802.11: deauthenticated due to inactivity (timer DEAUTH/REMOVE) Mon May 27 01:23:07 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-weaver.lhr03.hls.ttvnw.net Mon May 27 01:23:07 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-c68834.lhr03.abs.hls.ttvnw.net Mon May 27 01:23:08 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: client.wns.windows.com Mon May 27 01:23:08 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:09 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-c45a5c.sjc02.hls.ttvnw.net Mon May 27 01:23:09 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:10 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: gateway.discord.gg Mon May 27 01:23:10 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:11 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:11 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:12 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:12 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:12 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:12 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:12 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:13 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:13 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:14 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:14 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-c45a5c.sjc02.hls.ttvnw.net Mon May 27 01:23:14 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-weaver.lhr03.hls.ttvnw.net Mon May 27 01:23:15 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:15 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:15 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: dns.msftncsi.com Mon May 27 01:23:16 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: gateway.discord.gg Mon May 27 01:23:18 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:18 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: streamapi.majorleaguegaming.com Mon May 27 01:23:19 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-c45a5c.sjc02.hls.ttvnw.net Mon May 27 01:23:19 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:19 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-c68834.lhr03.abs.hls.ttvnw.net Mon May 27 01:23:21 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.google.com Mon May 27 01:23:21 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: secure-dcr.imrworldwide.com Mon May 27 01:23:21 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: safebrowsing.googleapis.com Mon May 27 01:23:21 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: s2.googleusercontent.com Mon May 27 01:23:21 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:21 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: fonts.gstatic.com Mon May 27 01:23:22 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:22 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: streamapi.majorleaguegaming.com Mon May 27 01:23:22 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: pipes-prod-glutton.public.aws.demonware.net Mon May 27 01:23:23 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: streamapi.majorleaguegaming.com Mon May 27 01:23:23 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: api.spotify.com Mon May 27 01:23:23 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: dealer.spotify.com Mon May 27 01:23:23 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: streamapi.majorleaguegaming.com Mon May 27 01:23:23 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:23 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-c45a5c.sjc02.hls.ttvnw.net Mon May 27 01:23:24 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: clients4.google.com Mon May 27 01:23:24 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: dumaos.com Mon May 27 01:23:24 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: forum.netduma.com Mon May 27 01:23:24 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: netduma.com Mon May 27 01:23:24 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: support.netduma.com Mon May 27 01:23:24 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:25 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: client.wns.windows.com Mon May 27 01:23:25 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-27187d.sjc02.hls.ttvnw.net Mon May 27 01:23:25 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: sentinel.twitchsvc.net Mon May 27 01:23:26 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:27 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: asm.np.community.playstation.net Mon May 27 01:23:27 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: asm.np.community.playstation.net Mon May 27 01:23:27 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:28 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: gateway.discord.gg Mon May 27 01:23:28 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:29 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-c45a5c.sjc02.hls.ttvnw.net Mon May 27 01:23:29 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: video-edge-c45a5c.sjc02.hls.ttvnw.net Mon May 27 01:23:29 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: client.wns.windows.com Mon May 27 01:23:29 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:29 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:29 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:29 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:30 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:30 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: dns.msftncsi.com Mon May 27 01:23:30 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: pipes-prod-glutton.public.aws.demonware.net Mon May 27 01:23:31 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: clients1.google.com Mon May 27 01:23:33 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: speedtest.net Mon May 27 01:23:34 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: netdumasoftware.com Mon May 27 01:23:36 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:37 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: clients1.google.com Mon May 27 01:23:38 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: sb.scorecardresearch.com Mon May 27 01:23:39 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:42 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:42 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: clients1.google.com Mon May 27 01:23:43 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:45 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: feedr.search.sky.com Mon May 27 01:23:45 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: feedr.search.sky.com Mon May 27 01:23:45 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: feedr.search.sky.com Mon May 27 01:23:45 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: feedr.sky.com Mon May 27 01:23:45 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: feedr.sky.com Mon May 27 01:23:45 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: feedr.sky.com Mon May 27 01:23:47 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: gateway.discord.gg Mon May 27 01:23:47 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: asm.np.community.playstation.net Mon May 27 01:23:47 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: clients1.google.com Mon May 27 01:23:49 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: gql.twitch.tv Mon May 27 01:23:49 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: api.spotify.com Mon May 27 01:23:49 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: dealer.spotify.com Mon May 27 01:23:49 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: client.wns.windows.com Mon May 27 01:23:49 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: client-event-reporter.twitch.tv Mon May 27 01:23:52 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: a26m9qrmiux96c.iot.eu-west-1.amazonaws.com Mon May 27 01:23:53 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:23:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:23:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:23:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:23:53 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:23:53 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:53 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:53 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:54 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: www.msftconnecttest.com Mon May 27 01:23:54 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: clients1.google.com Mon May 27 01:23:54 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: dns.msftncsi.com Mon May 27 01:23:54 2019 daemon.warn dnsmasq[14283]: possible DNS-rebind attack detected: dns.msftncsi.com Mon May 27 01:24:01 2019 kern.info kernel: [117982.532000] recv: nf_ct_get failed Mon May 27 01:24:01 2019 kern.info kernel: [117982.532000] send: nf_ct_get failed Mon May 27 01:24:10 2019 kern.info kernel: [117990.924000] recv: nf_ct_get failed Mon May 27 01:24:10 2019 kern.info kernel: [117990.924000] send: nf_ct_get failed Mon May 27 01:24:23 2019 kern.info dpiclass-daemon: Kill flow due to timeout Mon May 27 01:24:32 2019 kern.info kernel: [118012.940000] recv: nf_ct_get failed Mon May 27 01:24:32 2019 kern.info kernel: [118012.940000] send: nf_ct_get failed