I found out that during these spikes my httpd.exe (apache) is taking up the resources for outbound traffic. I checked the ip, and it corresponded to the ip in the router log.
I double checked during another spike, my httpd.exe was hogging the resources again to a different IP this time, and sure enough, it was the same new IP as in the server log.
To my knowledge, I think my server has been compromised by a botnet and is now used for ddos attacks.
My modem doesn't have a built in router. Connection is fiberoptics.
Latest firmware: 1.23WW
I also get incoming "attacks" altho not so severe on ports 27960 and 27962, but they were more serious a few days before my outbound traffic started spiking.
Is it possible that during this attack on ports 27960 and 27962 the router couldn't coup and something might have gone through the firewall? And then infecting the server?
What measurements should I take to stop this from happening (again?).
1) Disconnect the server from the internet
2) Reinstall the server
3) Change router pw
4) If possible, change the static IP?
Thanks in advance,
Crytiqal