Source IP 1.12.168.192
I have an image of the packet details but I can't upload as of now.
It is a ICMP type 9 packet with these addresses:
-Source IP 1.12.168.192
-Destination IP 224.0.0.1
-Router IP 192.168.12.1
It doesn't seem to make any sense.
Why would you have a multicast within your local network with a global source IP 1.12.168.192 but the router IP 192.168.12.1?
Would this be a DoS packet because whenever this packet shows up, Wireshark is flooded with bad TCP packets and it then just makes loading pages very slow?
Any ideas why that is and where the source IP 1.12.168.192 is coming from?
Is IP 1.12.168.192 coming from the router or maliciously spoofed from outside?
You can share either the capture (which is much more useful for diagnosis) or a screenshot on a public share and then post a link to it back here.
https://imgur.com/07wNwv2 is the image.