My log file told me that a couple of exploits(LSASS and DCOM exploits) were tried on my system's one of the VM (windows xp2) from the following IPs

10.8.240.93
10.8.154.135

But how is this possible, since these addresse are in the reserved RFC 1918 address range and should never appear on public internet.
Any clues ?