
Bear in mind, when reading this, that there is absolutely no other traffic on this LAN. The LAN is effectively in honeypot mode.
202.176.209.3 seems to be using DNS to map the network. I've seen this before where the attacker floods the outer router with unsolicited DNS replies. When an inner Router realizes it has
no ability to make DNS requests via DNS relay, it is referred by the next router on the outbound side to it's DNS providers...and the hacker is outside watching.
...

