when,ip,message 2018-10-09 01:34:05,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=21396 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 01:44:06,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=6452 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 03:06:16,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=42305 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 03:13:05,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=21058 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 05:58:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=13563 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 06:00:07,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=59367 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 06:01:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=26968 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 06:05:06,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=14078 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 09:17:58,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=46328 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 12:45:59,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=56317 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 13:17:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=23597 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 13:19:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=53592 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 13:28:11,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=38332 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 13:30:12,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=52059 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 13:34:04,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=61518 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 13:35:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=24005 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 14:28:04,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=4210 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 14:37:05,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=19779 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 16:14:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=41431 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 16:17:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=31624 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 17:10:05,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=11909 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 17:10:05,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=8775 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 17:11:06,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=18500 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 17:15:05,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=25738 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 17:16:07,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=16531 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 17:20:05,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=34872 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 19:06:08,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=63566 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 19:08:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=22659 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 19:15:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=30123 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 19:16:07,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=45729 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 19:18:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=41427 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 19:20:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=55134 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 19:20:05,204.152.209.106,SRC=204.152.209.106 DST=23.227.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=10859 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 21:35:00,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=9473 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 21:57:05,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=4367 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-09 22:42:59,204.152.209.106,SRC=204.152.209.106 DST=23.29.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=247 ID=34594 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-10 00:39:05,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=24038 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 2018-10-10 01:58:05,204.152.209.106,SRC=204.152.209.106 DST=107.155.*.* LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=42000 PROTO=TCP SPT=44653 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0