when,ip,message 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=32723 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=50363 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=242 ID=42034 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=242 ID=277 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=242 ID=57727 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=242 ID=51087 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=10719 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=8990 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=242 ID=36204 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=242 ID=9455 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=31945 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=16036 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:06,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=5646 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:37,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=239 ID=22132 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:24:37,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=239 ID=17983 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 06:25:05,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=13233 PROTO=TCP SPT=46607 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 08:05:07,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=49842 PROTO=TCP SPT=52689 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 08:05:07,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=57454 PROTO=TCP SPT=52689 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 08:05:07,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=49189 PROTO=TCP SPT=52689 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 08:05:07,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=28457 PROTO=TCP SPT=52689 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 08:05:07,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=33856 PROTO=TCP SPT=52689 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-29 08:05:07,149.28.46.201,SRC=149.28.46.201 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=242 ID=38730 PROTO=TCP SPT=52689 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-31 11:24:35,149.28.46.201,SRC=149.28.46.201 DST=162.213.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=30287 PROTO=TCP SPT=57436 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-31 11:24:35,149.28.46.201,SRC=149.28.46.201 DST=162.213.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=18467 PROTO=TCP SPT=57436 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0