Have you automatic check for updates activated ? That would also be a valid reason.
EDIT: just checked. When I manually go checking for updates, I see in that same range address 159.148.147.204 appearing in the connections list.
So it could be something as simple as that.
Really strange then.
If it really is such a problem: add firewall rule to drop everything going to that IP address (and log for later inspection) and see what stops working.
Maybe someone else can give better ideas to determine what’s causing this but I don’t see any other way.
Other option:
drop your config here (terminal: /export hide-sensitive file=anynameyouwish)
Maybe something IS causing this which you are not seeing right now.
Internet
WAN interfaces that can reach cloud.mikrotik.com using UDP protocol port 30000 can obtain this state. Reachability is checked every minute. If a cloud is not reached for 3 minutes, the state falls back to WAN.