I'm most curious though, can anyone hazard a guess as to what this may be?
My current stab in the dark is a glitch (or hack) in helstra's monitoring system, could someone be stealling bandwidth/throughput from bigpong?

'Curious Captain...'

I get unrequested traffic terminating at my network all the time. Typically I've found it to be

* Attempts to relay mail through my mail server
* Attempts to subvert my webserver
* Random other attempts to find security holes, scan ports, ping, etc.

If the user owns a class C domain then it's also likely they're getting a lot of traffic from random scans of all the addresses in that domain. But that's probably unlikely in this case, as there aren't many people around with their own large range of IP's. (Unless of course someone used to use that particular IP address for something else...)

Is it possible the BigPond traffic logs are updated sometime during the evening, leading to the big jump?

It's also possible there are some folks doing nasty denial-of-service stuff.

One possibility is installing HenWen and Snort or running a packet sniffer to see what's coming down the line. Of course it's possible it's blocked at their router, but you still get charged for it.

Have fun,
Shay
--
=========================== Shay  Telfer ================================
 Perth, Western Australia   Technomancer        Chronopolis Quiz Day
 Opinions for hire              [POQ]      Sun. March 14, Hyde Park Hotel
 [EMAIL PROTECTED]         fnord     <http://chronopolis.sf.org.au/>