My internet has been blocked by our provider because they have detected botnet activity in their routine check. I am now trying to find out which device in our network causes this because. Alle devices are scanned and found clean.
I'm using a DIR-655 with the latest firmware (2012)
Ik would think that something must be visible in the log of the botnet activity. But it all looks fairly normal. The parts in the log that i don't understand are:
Jul 28 00:06:46 info UDHCPD sending OFFER of 192.168.0.111
Jul 28 00:06:46 debug UDHCPD sendOffer : client is in lease/offered table
Jul 28 00:06:46 info UDHCPD sendOffer : device_lan_ip=192.168.0.1 , device_lan_subnet_mask=255.255.255.0
the part below names ip adresses from our provider so i think this is their check session
Jul 27 19:17:30 info using nameserver 62.238.255.69#53
Jul 27 19:17:30 info using nameserver 212.115.192.100#53
Jul 27 19:17:30 info reading /etc/resolv.conf
Jul 27 19:17:29 debug No DHCP ACK with option DHCP_STATIC_ROUTE
Jul 27 19:17:29 info Lease of 213.34.238.239 obtained, lease time 86400