I spent a lot of time searching of an answer of how this is possible but i didnt find anything. I know that there is an attack named ICMP tunneling but i dont think that there is some tunneling in this case. Here is some other pictures: https://ibb.co/TvmZS6Y
A week ago, after opening wireshark, i was surprised by seing a storm of ICMP packets from different IP addresses. While deep analysing of thoses packets, i noticed that <strong>those ICMP packets contains IPv4 headers and UDP/TCP headers.</strong> It seems like port scanning.