Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Alerts from "Signal Android App"!

    Scheduled Pinned Locked Moved IDS/IPS
    7 Posts 2 Posters 840 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      denis_ju
      last edited by

      hi everybody,

      while on a phone call today, saw some messages in snort from an android signal app.

      Screenshot from 2021-03-16 17-09-53.png Screenshot from 2021-03-16 17-08-44.png Screenshot from 2021-03-16 17-04-52.png

      Anybody know if those alerts are false positive and have to ignore it?

      NollipfSenseN D 2 Replies Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense @denis_ju
        last edited by

        @denis_ju I would guess false positive; however, as admin for your network only you can determine ... have you looked up each IP to see whether they're associated with Signal or Android?

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        D 1 Reply Last reply Reply Quote 0
        • D
          denis_ju @denis_ju
          last edited by

          Again warnings for the next call to Signal App.

          @denis_ju Screenshot from 2021-03-17 09-10-30.png

          1 Reply Last reply Reply Quote 0
          • D
            denis_ju @NollipfSense
            last edited by

            @nollipfsense I did a live monitoring before and during the conversation with Signal App on Android phone.

            IP's are changing every time on every conversation, even if i try to change from a voice call to video call. And the warnings continue.

            Mostly IP's until now come from "amazona ws", "vodafone albania", "ProXad/Free SAS, France".

            NollipfSenseN 1 Reply Last reply Reply Quote 0
            • NollipfSenseN
              NollipfSense @denis_ju
              last edited by

              @denis_ju Android and Google have many different IPs so you'll continue to receive different ones. Are you or the other party using Vodaphone and is in France or Albania? Signal is very robust and that's what I use as well.

              pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
              pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

              D 1 Reply Last reply Reply Quote 0
              • D
                denis_ju @NollipfSense
                last edited by

                @nollipfsense Neither me nor the other side uses vodafone.
                I spoke for Vodafone Albania not in France.

                Do I have to deactivate these "Conficker Rules"?

                Screenshot from 2021-03-18 13-20-44.png Screenshot from 2021-03-18 13-19-58.png

                NollipfSenseN 1 Reply Last reply Reply Quote 0
                • NollipfSenseN
                  NollipfSense @denis_ju
                  last edited by

                  @denis_ju said in Alerts from "Signal Android App"!:

                  I spoke for Vodafone Albania not in France.

                  I do not understand this statement after reading your first. I would check out all destination IPs in the above image before disabling ... do a whois and reverse IP ... you can use Google to look up each ET Trojan above ... welcome to IDS/IPS.

                  pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                  pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.