Hello;
I've got the GT-AX6000 setup with the latest merlin firmware on my sisters house. I have enabled AiProtect which I had thought would stop outbound "attacks".
However since last week we've been getting email from the ISP say we are the source of abuse.
This is what the email says:
How can I use the features of this router to help determine the machine responsible?
Any help would be appreciated as they say they are going to terminate our account as this problem is affecting the network.
Thanks
I've got the GT-AX6000 setup with the latest merlin firmware on my sisters house. I have enabled AiProtect which I had thought would stop outbound "attacks".
However since last week we've been getting email from the ISP say we are the source of abuse.
This is what the email says:
Code:
IP x.x.x.x
data: SOURCE TIME: 2024-06-15 00:35:02Z
IP: x.x.x.x
ASN: 812
AS NAME: ROGERS-COMMUNICATIONS, CA
MALWARE FAMILY: 911-socks5-proxy
TYPE: malware infection
DESCRIPTION: This host is most likely infected with malware.
DESTINATION IP: 5.79.71.225
DESTINATION PORT: 443
PORT: 58905
HTTP REQUEST: POST /api/node HTTP/1.1
USER AGENT: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
UUID
: bd8df903-4f54-4263-956d-6fb0568c895e
How can I use the features of this router to help determine the machine responsible?
Any help would be appreciated as they say they are going to terminate our account as this problem is affecting the network.
Thanks