Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is this a Hack Bot that Suricata Found?

    Scheduled Pinned Locked Moved IDS/IPS
    17 Posts 3 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      weirdpolice Banned
      last edited by weirdpolice

      Just tried going to ARP Table but it's not loading.. after a couple minutes it started loading:

      WAN 192.168.1.101 00:26:*** Permanent ethernet

      It basically has the same stats as the 192.168.1.1 except it says Permanent

      SMH... there are a bunch of MAC addresses/192.168.1.x addresses but I only connected 1 computer to pfSense's LAN

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        Do you have another router conneced between the Internet and your pfSense WAN interface.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        W 1 Reply Last reply Reply Quote 1
        • W
          weirdpolice Banned @NogBadTheBad
          last edited by weirdpolice

          @NogBadTheBad Yes, I do. Internet -> Router -> Router's LAN -> pfSense -> Single Computer

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by

            Well its a device connected to that other router then, either by ethernet or WiFi.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 1
            • W
              weirdpolice Banned
              last edited by

              Yeah, I figured that... I'm just curious how it knew to start scanning and then dropped silent all of a sudden

              M 1 Reply Last reply Reply Quote 0
              • NogBadTheBadN
                NogBadTheBad
                last edited by

                @ProfessorManhattan said in Is this a Hack Bot that Suricata Found?:

                Here are the logs (Note: I had to remove a massive sum of the malicious logs because Stack does not allow that many characters... I left in the parts that show the Network Trojan and Scanning of the pfSense Router (IP address: 192.168.1.101):

                Can you switch the upstream router to modem mode ?

                If you can it would be better as you'll have a non rfc1918 IP address on the pfSense WAN interface and you won't have a double NAT occurring.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                W 1 Reply Last reply Reply Quote 1
                • M
                  msf2000 @weirdpolice
                  last edited by

                  @ProfessorManhattan
                  You have an active malware infection. It's certainly capable of knowing what network its on, changing its own IP address, and then "hiding" itself to fall silent until called upon by its master.

                  1 Reply Last reply Reply Quote 1
                  • W
                    weirdpolice Banned @NogBadTheBad
                    last edited by weirdpolice

                    @NogBadTheBad @msf2000 This post is the truth and partially for my own protection:

                    ok, do you think I should reinstall pfSense? Or if they can hack my router I'm supposed to let them have their way with my set up? I experienced some extremely high level hacks in the past so I'm not sure what I should do (you would not believe --- I tracerouted at one point and saw my traffic going through countries on the other side of the world... also I logged into my cell phones manufacturer menu and saw someone changed the Cellular SSID to the name of one of my research projects -- Radiation TDR.. then sh*t got gnostic)... on one hand, I (POSSIBLY still) have this unknown group that's capable of doing extremely high level hacks on my system (I believe they actually fixed up some settings last time they hacked me) and on the other hand I live with a bunch of computer n00bs who prolly click virus.exe like its candy..

                    I'm not sure I want to even "protect" myself from the high level group -- I wouldn't want to cause some guy in the NSA to be like, "Shit, they know our IP block now" But on the other hand, I want to keep the script kiddies out.

                    Any recommendations on what to do? Is this malware capable of infecting the rest of the LAN? There is some sensitive information on the network PLUS BTW IN CASE I POSTED IPs... HIGHLY DO NOT RECOMMEND HACKING THIS NETWORK --- just read this post which doesn't even scratch the surface

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      msf2000 @weirdpolice
                      last edited by msf2000

                      @ProfessorManhattan

                      It just looks like DNS queries on weird ports... Mostly reconnaisance-type connections. I would just the host/client device. I don't see any evidence that your pfSense box is hacked...

                      Also, connections all over the world are not necessarily a sign of compromise... something as simple as getting the current time (NTP) from a Russian timeserver can be benign and even routine.

                      In any event, we're off topic. Suricata helps you detect malware/reconnaisance, and it's doing its job as far as I can see.

                      1 Reply Last reply Reply Quote 1
                      • NogBadTheBadN
                        NogBadTheBad
                        last edited by

                        No it's not a pfSense issue.

                        It's an issue with the hosts.

                        By default pfSense blocks anything hitting the WAN interface.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        W 1 Reply Last reply Reply Quote 1
                        • W
                          weirdpolice Banned @NogBadTheBad
                          last edited by weirdpolice

                          @NogBadTheBad Thank you for the re-assurance. I can take off my tin foil hat as you say and not waste a month compulsively re-installing pfSense which probably would be from a source with a mismatching checksum anyway.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.