• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Alerts from "Signal Android App"!

Scheduled Pinned Locked Moved IDS/IPS
7 Posts 2 Posters 805 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    denis_ju
    last edited by Mar 16, 2021, 4:20 PM

    hi everybody,

    while on a phone call today, saw some messages in snort from an android signal app.

    Screenshot from 2021-03-16 17-09-53.png Screenshot from 2021-03-16 17-08-44.png Screenshot from 2021-03-16 17-04-52.png

    Anybody know if those alerts are false positive and have to ignore it?

    N D 2 Replies Last reply Mar 17, 2021, 1:36 AM Reply Quote 0
    • N
      NollipfSense @denis_ju
      last edited by Mar 17, 2021, 1:36 AM

      @denis_ju I would guess false positive; however, as admin for your network only you can determine ... have you looked up each IP to see whether they're associated with Signal or Android?

      pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
      pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

      D 1 Reply Last reply Mar 17, 2021, 8:51 AM Reply Quote 0
      • D
        denis_ju @denis_ju
        last edited by Mar 17, 2021, 8:15 AM

        Again warnings for the next call to Signal App.

        @denis_ju Screenshot from 2021-03-17 09-10-30.png

        1 Reply Last reply Reply Quote 0
        • D
          denis_ju @NollipfSense
          last edited by Mar 17, 2021, 8:51 AM

          @nollipfsense I did a live monitoring before and during the conversation with Signal App on Android phone.

          IP's are changing every time on every conversation, even if i try to change from a voice call to video call. And the warnings continue.

          Mostly IP's until now come from "amazona ws", "vodafone albania", "ProXad/Free SAS, France".

          N 1 Reply Last reply Mar 17, 2021, 8:43 PM Reply Quote 0
          • N
            NollipfSense @denis_ju
            last edited by Mar 17, 2021, 8:43 PM

            @denis_ju Android and Google have many different IPs so you'll continue to receive different ones. Are you or the other party using Vodaphone and is in France or Albania? Signal is very robust and that's what I use as well.

            pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
            pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

            D 1 Reply Last reply Mar 18, 2021, 12:29 PM Reply Quote 0
            • D
              denis_ju @NollipfSense
              last edited by Mar 18, 2021, 12:29 PM

              @nollipfsense Neither me nor the other side uses vodafone.
              I spoke for Vodafone Albania not in France.

              Do I have to deactivate these "Conficker Rules"?

              Screenshot from 2021-03-18 13-20-44.png Screenshot from 2021-03-18 13-19-58.png

              N 1 Reply Last reply Mar 23, 2021, 4:39 AM Reply Quote 0
              • N
                NollipfSense @denis_ju
                last edited by Mar 23, 2021, 4:39 AM

                @denis_ju said in Alerts from "Signal Android App"!:

                I spoke for Vodafone Albania not in France.

                I do not understand this statement after reading your first. I would check out all destination IPs in the above image before disabling ... do a whois and reverse IP ... you can use Google to look up each ET Trojan above ... welcome to IDS/IPS.

                pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                1 Reply Last reply Reply Quote 0
                7 out of 7
                • First post
                  7/7
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                  This community forum collects and processes your personal information.
                  consent.not_received