Jump to content

Antivirus Software to find Botnet Activity?

m0k

I just received a lengthy email from my ISP. this was the key info:

Unwanted and or Abusive Web Requests:
Offending/Source IP:  174.XXX.XXX.XX
       - Issue: Source has attempted the following botnet activity: WordPress Login Brute Force
       - Block Type: New Ban
       - Time: 2016-10-02 19:16:15-07:00
       - Port: 80
       - Service: http
       - Report ID: d3ddaca4-13df-4650-810f-cccd38abd4bb
       - Bot Fingerprint: ecfeb55593d60e18bcb90450dacca9dd
       - Bot Information: https://www.webiron.com/bot_lookup/ecfeb55593d60e18bcb90450dacca9dd
       - Bot Node Feed: https://www.webiron.com/bot_feed/ecfeb55593d60e18bcb90450dacca9dd
       - Abused Range: 5.133.182.0/24
       - Requested URI: /wp-login.php
       - User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1
       - GET/POST Arguments Sent: pwd, wp-submit, testcookie, log

       - Issue: Source has attempted the following botnet activity: WordPress Login Brute Force
       - Block Type: Banned IP
       - Time: 2016-10-02 19:16:15-07:00
       - Port: 80
       - Service: http
       - Report ID: 935dbdb4-4782-4909-88e2-e681faae3db5
       - Bot Fingerprint: 78c5e7c8e2bf89b015688ee6cb512412
       - Bot Information: https://www.webiron.com/bot_lookup/78c5e7c8e2bf89b015688ee6cb512412
       - Bot Node Feed: https://www.webiron.com/bot_feed/78c5e7c8e2bf89b015688ee6cb512412
       - Abused Range: 5.133.182.0/24
       - Requested URI: /wp-login.php
       - User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101  

 

I called tech support and they confirmed that this is logged on their system and is infact a real threat (i thought it could have been spam)
I have already scanned 4 of my computers with Windows Defender, Malwarebytes, Spybot Search & Destroy, and Sophos and all four have come up empty/clean
My last remaining computer on the network belongs to the basement tenant who uses our Guest WIFI network

 

Now just to be safe im going to purchase a proper Antivirus Software, But i dont know which one would effectively find something as malicious as this botnet activity.


Can you guys give recommendations on one? I'm currently looking at ESET and Kaspersky (for 5 devices)

Photography / Finance / Gaming

Link to comment
Share on other sites

Link to post
Share on other sites

edit: can someone also confirm if the "user-agent" is saying that it was done through a mozilla browser?  or does that mean something else (this is important to me because none of my 4 computers use mozilla, and would point towards my tenant)

Photography / Finance / Gaming

Link to comment
Share on other sites

Link to post
Share on other sites

BitDefender and Norton are the only ones I would recommend. As for the user/agent line, I can't help you.

CPU: Intel Core i9-10900K  MOBO: ROG MAXIMUS XII FORMULA GPU: 2080ti Hall of Fame 10th anniversary limited edition  PSU: Asus ROG THOR 1200W  COOLER: Optimus foundation black acetal RADS: 3x EKWB CoolStream PE 360  LOOP: EKWB torque HDC fittings / EKWB ZMT 15,9/9,5mm / EKWB CryoFuel Clear MONITOR: Acer predator X34

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, mok said:

(this is important to me because none of my 4 computers use mozilla, and would point towards my tenant)

Step one: scan your tenant's computers with all the things.

We have a NEW and GLORIOUSER-ER-ER PSU Tier List Now. (dammit @LukeSavenije stop coming up with new ones)

You can check out the old one that gave joy to so many across the land here

 

Computer having a hard time powering on? Troubleshoot it with this guide. (Currently looking for suggestions to update it into the context of <current year> and make it its own thread)

Computer Specs:

Spoiler

Mathresolvermajig: Intel Xeon E3 1240 (Sandy Bridge i7 equivalent)

Chillinmachine: Noctua NH-C14S
Framepainting-inator: EVGA GTX 1080 Ti SC2 Hybrid

Attachcorethingy: Gigabyte H61M-S2V-B3

Infoholdstick: Corsair 2x4GB DDR3 1333

Computerarmor: Silverstone RL06 "Lookalike"

Rememberdoogle: 1TB HDD + 120GB TR150 + 240 SSD Plus + 1TB MX500

AdditionalPylons: Phanteks AMP! 550W (based on Seasonic GX-550)

Letterpad: Rosewill Apollo 9100 (Cherry MX Red)

Buttonrodent: Razer Viper Mini + Huion H430P drawing Tablet

Auralnterface: Sennheiser HD 6xx

Liquidrectangles: LG 27UK850-W 4K HDR

 

Link to comment
Share on other sites

Link to post
Share on other sites

I wouldnt recommend norton. They have a good database but their anti virus software misses lots of malware. Its really difficult to find an anti virus that will block malware that i have resorted to manually removing malware and using a configurable firewall to block suspicious behaviour based on how one would define it. Although upon doing it i find that google, facebook and other sites do get blocked as they attempt to track you.

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, System Error Message said:

I wouldnt recommend norton. They have a good database but their anti virus software misses lots of malware. Its really difficult to find an anti virus that will block malware that i have resorted to manually removing malware and using a configurable firewall to block suspicious behaviour based on how one would define it. Although upon doing it i find that google, facebook and other sites do get blocked as they attempt to track you.

I hate Norton, it was never an option 
Did a more detailed scan with Sophos and Malwarebytes, was able to find one malware on my sister's computer. 

as for trackers i use Ghostery extension on chrome, it disables trackers

Photography / Finance / Gaming

Link to comment
Share on other sites

Link to post
Share on other sites

I recommend Kaspersky myself as it's always been great to me.

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×