What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

AIProtection-Infected Device Prevention and Blocking

joe scian

Very Senior Member
Hi All
I received 9 threat entries on my AC5300 running 384.5 this morning.
Threat - C&C Server ( comand and control server ) on 2 Iphones 6 and 7 running latest versions of IOS. The destination on all 9 entries was www.google.kg.

Not sure whether I should be concerned - any thoughts or feedback welcome.
 
Update signature, check your DNS settings. Do a DNS query manually and see if the IP returned is a known Google IP.

Maybe look into more secure DNS options like DNSSEC, dnscrypt, or DNS-over-{TLS,HTTP} as a preventative measure.
 
Thanks for feedback - I have DNSSEC enabled and running dnscrypt on router - i am using latest CA cert on router and on Iphone. Maybe it was a false positive. www.google.kg is Googles home page for Kyrgyzstan,
 
Thanks for feedback - I have DNSSEC enabled and running dnscrypt on router - i am using latest CA cert on router and on Iphone. Maybe it was a false positive. www.google.kg is Googles home page for Kyrgyzstan,

If you have all that set up I doubt it was some DNS issue then, probably just false alarm AiProtection. Have you updated the signatures?

Also you mention couple iPhones but on latest iOS, so I assume they’re not jailbroken?
 
yes correct no jailbreak mod
 
  • Like
Reactions: kfp
Thank you
 
Could be a bad url being used or simply an e-mail that was opened up. If it keeps happening, you need to look into it more closely.
 
yes i have a feeling i may have opened a phishing text message on one of the phones. Will keep a watchful eye on it . Thank you
 
Hi All
I received 9 threat entries on my AC5300 running 384.5 this morning.
Threat - C&C Server ( comand and control server ) on 2 Iphones 6 and 7 running latest versions of IOS. The destination on all 9 entries was www.google.kg.

Not sure whether I should be concerned - any thoughts or feedback welcome.

I also had 7 hits (a second apart), on Wednesday for that site on my wife's iPhone. A website I found after some google searching alerted me to turn on security notification in her Whats APP in case things were being hijacked. Just going to keep an eye on it for now.
 
I also had 7 hits (a second apart), on Wednesday for that site on my wife's iPhone. A website I found after some google searching alerted me to turn on security notification in her Whats APP in case things were being hijacked. Just going to keep an eye on it for now.

The URL you linked to does not contain anything related to google.kg, I fail to see the relevance here.

Moreover, the malware seems to be spreading with fake APK (Android file format) so I don’t think it’s related to your wife’s iPhone at all.
 

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top