Woke up this morning, and noticed this on my snort log:
Code:
01/10-02:40:01.134740 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-02:40:01.134740 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-02:40:01.158133 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.147 -> 192.168.1.93
01/10-03:00:01.165371 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.99
01/10-03:00:01.165371 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.99
01/10-03:00:01.195549 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.99 -> 192.168.1.93
01/10-03:30:01.649273 [**] [1:254:8] DNS SPOOF query response with TTL of 1 min. and no authority [**] [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 192.168.1.1:53 -> 192.168.1.93:52355
01/10-03:40:01.558799 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.103
01/10-03:40:01.558799 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.103
01/10-03:40:01.580171 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.103 -> 192.168.1.93
01/10-04:00:01.598586 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-04:00:01.598586 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-04:00:01.618159 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.147 -> 192.168.1.93
01/10-04:30:01.751074 [**] [1:254:8] DNS SPOOF query response with TTL of 1 min. and no authority [**] [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 192.168.1.1:53 -> 192.168.1.93:48739
01/10-04:40:01.710521 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.103
01/10-04:40:01.710521 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.103
01/10-04:40:01.733354 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.103 -> 192.168.1.93
01/10-05:00:01.990355 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.104
01/10-05:00:01.990355 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.104
01/10-05:00:02.009411 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.104 -> 192.168.1.93
01/10-05:30:01.624738 [**] [1:254:8] DNS SPOOF query response with TTL of 1 min. and no authority [**] [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 192.168.1.1:53 -> 192.168.1.93:60029
01/10-05:40:01.528183 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.99
01/10-05:40:01.528183 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.99
01/10-05:40:01.553644 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.99 -> 192.168.1.93
01/10-06:00:01.815023 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.103
01/10-06:00:01.815023 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.103
01/10-06:00:01.842012 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.103 -> 192.168.1.93
01/10-06:30:02.202950 [**] [1:254:8] DNS SPOOF query response with TTL of 1 min. and no authority [**] [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 192.168.1.1:53 -> 192.168.1.93:51519
01/10-06:40:01.118694 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-06:40:01.118694 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-06:40:01.138599 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.147 -> 192.168.1.93
01/10-07:00:01.969456 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-07:00:01.969456 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-07:00:01.992475 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.147 -> 192.168.1.93
01/10-07:10:54.801073 [**] [129:5:1] Bad segment, adjusted size <= 0 [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 192.168.1.93:37592 -> 72.14.204.19:443
01/10-07:30:01.800999 [**] [1:254:8] DNS SPOOF query response with TTL of 1 min. and no authority [**] [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 192.168.1.1:53 -> 192.168.1.93:48761
01/10-07:40:01.692999 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.103
01/10-07:40:01.692999 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.103
01/10-07:40:01.715607 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.103 -> 192.168.1.93
01/10-08:00:01.936271 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.103
01/10-08:00:01.936271 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.103
01/10-08:00:01.958371 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.103 -> 192.168.1.93
01/10-08:17:38.308569 [**] [129:16:1] FIN number is greater than prior FIN [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 193.28.235.40:80 -> 192.168.1.93:40013
01/10-08:20:11.595172 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-08:20:11.595172 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-08:20:11.615827 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.147 -> 192.168.1.93
01/10-08:20:12.596534 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-08:20:12.596534 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-08:20:12.616478 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.147 -> 192.168.1.93
01/10-08:20:43.431954 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-08:20:43.431954 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-08:20:43.455986 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.147 -> 192.168.1.93
01/10-08:20:44.433707 [**] [1:366:7] ICMP PING *NIX [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-08:20:44.433707 [**] [1:384:5] ICMP PING [**] [Classification: Misc activity] [Priority: 3] {ICMP} 192.168.1.93 -> 72.14.204.147
01/10-08:20:44.456289 [**] [1:408:5] ICMP Echo Reply [**] [Classification: Misc activity] [Priority: 3] {ICMP} 72.14.204.147 -> 192.168.1.93
It traces back to google's server (iad04s01-in-f147.1e100.net).... Has anybody else ever gotten anything like this? What's weird is that it happened every 30 minutes or so, on the dot, and I'm behind my NAT enabled router.....
Edit - Mods, move it.... my bad, wrong area.