2) Assuming the logs are completely truthful, no. If it reaches the ESTABLISHED or TIME_WAIT phases, it couldn't have been spoofed.
again, ephi could've falsified this, but occams razor,
(response to item 1)
, and
Hammer is saying he did not do it and it was most likely malware.
all suggest that my ideas are bullstuff
yeah, i'm pretty convinced pacnet or hammer did it.
it's still technically within ephi's power to do it, and
I'm not a big fan of thishe's literally admitting to a crime. like seriously.
anyway, pacnet, hammer, or ephi are the three people who had the power to do this