Suspected Remote Access Trojan (RAT) On Router

Page 2 of 3 FirstFirst 123 LastLast

  1. Posts : 295
    Windows 10 Pro
       #11

    YouTube creators have sure made the word "RAT" a household name.

    If your router is infected (very real possibility) it's not called a RAT. I don't remember the name off hand but it's like a backdoor/stepping stone. What a hacker will do is that if you have a port open (usually due to the dumb ISP) they can scan it and see if it's vulnerable to new firmware code. I think it's small and in the bootloader.

    Turn off UPnP.
    Don't use port forwarding. Instead, use a service like ZeroTier One and the likes.
    If you need port forwarding, learn how to use pfSense or OPNsense.
    Change the default router username and password to something else.
    Stay abreast of any and all router firmware updates. Many people pay homage to the Microsoft patch Tuesday god and never pay attention to the one big machine: a router or modem.
    If you know how, use a third-party router firmware like Asus Merlin, DD-WRT and the likes. Keep it updated.


    If you wanna help know if perhaps your router is infected, then take your external WAN IP and search at the following three websites. If Shodan or Census shows an open port you may have issues. But it is common for some ISPs to have an open port on their equipment. But then again, that open port can be used to infect your router if it's vulnerable.

    Shodan Search Engine

    Censys.io.

    GreyNoise Visualizer (If you see activity here with your IP, contact your ISP and let them know ASAP)

    (Same with the website) AlienVault - Open Threat Exchange

    All in all, if you're that concerned about it, reflash the router per manufacturer's instructions. Or use that new router you talked about and keep its firmware updated.

    And another. See anything here with your IP, contact your ISP ASAP. AbuseIPDB - IP address abuse reports - Making the Internet safer, one IP at a time
      My Computer


  2. Posts : 295
    Windows 10 Pro
       #12

    Edit-

    All those "scanners" won't find jack. It's snake oil... You would need to dump the RAM as an image and study it...
      My Computer


  3. Posts : 295
    Windows 10 Pro
       #13

    bro67 said:
    None of these tools are going to do anything with network hardware. As for your computer hardware, it is obvious that there is nothing nefarious going on.
    I think this is the right assumption at this point.
      My Computer


  4. Posts : 352
    Windows 11 Home (x64) Version 23H2
       #14

    I sure am glad you Malware expert program readers know more about these programs than i do after using them for 25 yrs !! Just saying ............. But what if they did find something !
      My Computer


  5. Posts : 295
    Windows 10 Pro
       #15

    You need to understand that sophisticated malware will not be detected by your run-of-the-mill anti-virus software. Especially if it's polymorphic.
      My Computer


  6. Posts : 352
    Windows 11 Home (x64) Version 23H2
       #16

    You can run the Farbar program & the other Malware removal programs & send the reports to my email if you want, i use this email for computer clients that i clean who want their info kept quiet ! flashh4@hotmail.com
      My Computer


  7. Posts : 1,770
    Windows 10 Pro (+ Windows 10 Home VMs for testing)
       #17

    flashh4 said:
    You can run the Farbar program & the other Malware removal programs & send the reports to my email if you want, i use this email for computer clients that i clean who want their info kept quiet ! flashh4@hotmail.com
    IMO, suggestions to take discussions outside the forum is frowned upon... as is self-promotion, particularly when you denigrate other forum contributors.

    Hope this helps....
      My Computer


  8. Posts : 352
    Windows 11 Home (x64) Version 23H2
       #18

    I have discussed this with Brink & if the file/reports are to big they can be emailed or posted at another source so i can have access to them ! If you would do your research on me you would find this is legit ! Done !!
      My Computer


  9. Posts : 295
    Windows 10 Pro
       #19

    It's called pastebin and the likes...
      My Computer


  10. Posts : 241
    Windows 10
    Thread Starter
       #20

    Original poster here.
    I got my new router but havn't used it yet. I will make sure UPNP is disabled and no port forwarding.
    I find the programme Livetcpudpwatch useful this sometimes show connections to port 1900 are being made. Port 1900 is known for vulnerabilities and of no use to an average home user who just uses the computer for browsing etc.
    The attached pic is from a 10 minute session

    Suspected Remote Access Trojan (RAT) On Router-clipboard01cv.jpg
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 05:50.
Find Us




Windows 10 Forums