NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Wildguns84's avatar
Oct 27, 2017

Nighthawk C7000 AC1900 DoS attack with speed slowdowns

Hello everyone!

I have tried going through my ISP but they see nothing wrong with modem health or my connection on their end. I have a Nighthawk C7000 AC1900 firmware version v1.01.23, with Windows 10 and in a home environment. 

 

I'm a streamer and frequently watch other streamers to show support. I noticed the stream I was watching kept freezing. So after checking other streamers and seeing the same results, I did multiple speed test. The speed I pay for is 100/10 and I was getting between 3/11 to 50/11. The download speed is never consistant and at times the dial will shoot up to 100+ but then drop right away during the testing.

 

I'll provide the logs below. All of this started on 10/25/17 and has continued every day. I have done a factory reset several times with no fixes. Please see partial logs below (including the event log too because of critical errors).

 

Any help would be greatly appreciate. I'm not great with the networking side of things and have no clue what I'm looking at.

 

Thank You

 

[DoS attack: Ping Of Death] from 212.9.9.0, port 011Fri Oct 27 07:24:31 201712.250.195.76:0212.9.9.0:0
[DoS attack: Illegal Fragments] from 212.9.9.0, port 01Fri Oct 27 07:23:32 201712.250.195.76:0212.9.9.0:0
[DoS attack: Ping Of Death] from 212.9.9.0, port 03Fri Oct 27 07:16:04 201712.250.195.76:0212.9.9.0:0
[DoS attack: Illegal Fragments] from 212.9.9.0, port 05Fri Oct 27 07:12:02 201712.250.195.76:0212.9.9.0:0
[DoS attack: Ping Of Death] from 212.9.9.0, port 01Fri Oct 27 07:12:01 201712.250.195.76:0212.9.9.0:0
[DoS attack: Teardrop or derivative] from 212.9.9.0, port 02Fri Oct 27 07:12:01 201712.250.195.76:0212.9.9.0:0
[DoS attack: Ping Of Death] from 212.9.9.0, port 01Fri Oct 27 06:53:32 201712.250.195.76:0212.9.9.0:0
[DoS attack: Illegal Fragments] from 212.9.9.0, port 02Fri Oct 27 06:53:32 201712.250.195.76:0212.9.9.0:0
[DoS attack: Ping Of Death] from 212.9.9.0, port 03Fri Oct 27 06:43:59 201712.250.195.76:0212.9.9.0:0
[DoS attack: Illegal Fragments] from 212.9.9.0, port 01Fri Oct 27 06:40:28 201712.250.195.76:0212.9.9.0:0
[DoS attack: Teardrop or derivative] from 212.9.9.0, port 02Fri Oct 27 06:40:28 201712.250.195.76:0212.9.9.0:0

5 Replies

  • Here is some of the event log.

     

    [DoS attack: Ping Of Death] from 212.9.9.0, port 011Fri Oct 27 07:24:31 201712.250.195.76:0212.9.9.0:0
    [DoS attack: Illegal Fragments] from 212.9.9.0, port 01Fri Oct 27 07:23:32 201712.250.195.76:0212.9.9.0:0
    [DoS attack: Ping Of Death] from 212.9.9.0, port 03Fri Oct 27 07:16:04 201712.250.195.76:0212.9.9.0:0
    [DoS attack: Illegal Fragments] from 212.9.9.0, port 05Fri Oct 27 07:12:02 201712.250.195.76:0212.9.9.0:0
    [DoS attack: Ping Of Death] from 212.9.9.0, port 01Fri Oct 27 07:12:01 201712.250.195.76:0212.9.9.0:0
    [DoS attack: Teardrop or derivative] from 212.9.9.0, port 02Fri Oct 27 07:12:01 201712.250.195.76:0212.9.9.0:0
    [DoS attack: Ping Of Death] from 212.9.9.0, port 01Fri Oct 27 06:53:32 201712.250.195.76:0212.9.9.0:0
    [DoS attack: Illegal Fragments] from 212.9.9.0, port 02Fri Oct 27 06:53:32 201712.250.195.76:0212.9.9.0:0
    [DoS attack: Ping Of Death] from 212.9.9.0, port 03Fri Oct 27 06:43:59 201712.250.195.76:0212.9.9.0:0
    [DoS attack: Illegal Fragments] from 212.9.9.0, port 01Fri Oct 27 06:40:28 201712.250.195.76:0212.9.9.0:0
    [DoS attack: Teardrop or derivative] from 212.9.9.0, port 02Fri Oct 27 06:40:28 201712.250.195.76:0212.9.9.0:0
    • DarrenM's avatar
      DarrenM
      Sr. NETGEAR Moderator

      It seems to be coming from the same IP tried to remove your phone or tablet from the network one by one it could be some app causing the issues it will help you find if its coming from one of your own devices.

       

      DarrenM

      • Wildguns84's avatar
        Wildguns84
        Tutor

        Thank you for the reply!

         

        So none of my devices are connected to my network. I switched to an ISP provided modem and the issues continue. Here is the event log and my signal levels from that modem.

         DCIDFreqPowerSNRModulationOctetsCorrectedsUncorrectables
        Downstream 131759.00 MHz-8.30 dBmV37.64 dB256QAM10174456403773531
        Downstream 211639.00 MHz-3.80 dBmV35.78 dB256QAM903956398615482542074
        Downstream 312645.00 MHz-3.80 dBmV37.64 dB256QAM937542605618668873
        Downstream 413651.00 MHz-4.50 dBmV38.61 dB256QAM1115742665713984776
        Downstream 519687.00 MHz-5.40 dBmV38.61 dB256QAM108409855879804759
        Downstream 620693.00 MHz-4.60 dBmV38.98 dB256QAM95735652196821233
        Downstream 721699.00 MHz-6.80 dBmV37.36 dB256QAM76473582179843294
        Downstream 822705.00 MHz-8.60 dBmV37.64 dB256QAM825247209814474147
        Downstream 923711.00 MHz-6.50 dBmV37.36 dB256QAM811041751223359375
        Downstream 1025723.00 MHz-5.20 dBmV38.98 dB256QAM938250045410141140
        Downstream 1126729.00 MHz-5.10 dBmV38.61 dB256QAM1134509179318788097
        Downstream 1227735.00 MHz-5.80 dBmV37.36 dB256QAM739188281711133751
        Downstream 1328741.00 MHz-6.00 dBmV35.78 dB256QAM8140687219156131333
        Downstream 1429747.00 MHz-6.70 dBmV31.69 dB256QAM10875684659165655211821278
        Downstream 1530753.00 MHz-8.40 dBmV30.05 dB256QAM5827894160191058622282938
        Downstream 1632765.00 MHz-8.30 dBmV37.64 dB256QAM88347128488951338
        Reset FEC Counters

        Upstream

         UCIDFreqPowerChannel TypeSymbol RateModulation
        Upstream 14224.20 MHz43.50 dBmVDOCSIS2.0 (ATDMA)5120 kSym/s64QAM
        Upstream 24437.00 MHz46.00 dBmVDOCSIS2.0 (ATDMA)2560 kSym/s64QAM
        Upstream 34330.60 MHz44.25 dBmVDOCSIS2.0 (ATDMA)5120 kSym/s64QAM
        Upstream 44119.40 MHz42.50 dBmVDOCSIS1.x (TDMA)2560 kSym/s16QAM

         

         Status
        System Uptime:4 d: 0 h: 56 m
        Computers Detected:staticCPE(1), dynamicCPE(2)
        CM Status:OPERATIONAL
        Time and Date:Wed 2017-11-01 17:17:08

         

         Interface Parameters
        Interface NameProvisionedStateSpeed (Mbps)MAC address
        LAN Port 1EnabledUp1000(Full)AC:EC:80:F4:30:F1
        LAN Port 2EnabledDown-----AC:EC:80:F4:30:F1
        LAN Port 3EnabledDown-----AC:EC:80:F4:30:F1
        LAN Port 4EnabledDown-----AC:EC:80:F4:30:F1
        CABLEEnabledUp-----AC:EC:80:F4:30:F2
        MTANotInitiatedDown-----AC:EC:80:F4:30:F3
        Date TimeEvent IDEvent LevelDescription
        11/1/2017 18:03840202005Lost MDD Timeout;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:03840007005RCS Partial Service;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:03840202005Lost MDD Timeout;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:03840007005RCS Partial Service;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:03840202005Lost MDD Timeout;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:03840007005RCS Partial Service;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:04840202005Lost MDD Timeout;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:04840007005RCS Partial Service;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:04840202005Lost MDD Timeout;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:04840007005RCS Partial Service;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:04840202005Lost MDD Timeout;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:04840007005RCS Partial Service;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:05840202005Lost MDD Timeout;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:05840007005RCS Partial Service;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:05840202005Lost MDD Timeout;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:05840007005RCS Partial Service;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:06840202005Lost MDD Timeout;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:06840007005RCS Partial Service;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:06840202005Lost MDD Timeout;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;
        11/1/2017 18:06840007005RCS Partial Service;CM-MAC=ac:ec:80:f4:30:f2;CMTS-MAC=00:01:5c:77:6c:57;CM-QOS=1.1;CM-VER=3.0;

         

         PacketCable(MTA) Events

         

        Date TimeEvent IDDescription
        10/12/2017 12:2414Power Supply Telemetry Log - BATTERY MISSING
        10/12/2017 12:2416MTA TFTP: Successful
        10/12/2017 12:2426MTA PROV: Successful!
        10/12/2017 12:243Voice Line State Change, Line Number = 1, Prev State = OOS, New State = IS
        10/12/2017 12:243Voice Line State Change, Line Number = 2, Prev State = OOS, New State = IS
        10/12/2017 12:253Voice Line State Change, Line Number = 1, Prev State = IS, New State = OOS
        10/12/2017 12:253Voice Line State Change, Line Number = 2, Prev State = IS, New State = OOS
        10/12/2017 12:2616MTA TFTP: Successful
        10/12/2017 12:2626MTA PROV: Successful!
        10/12/2017 12:263Voice Line State Change, Line Number = 1, Prev State = OOS, New State = IS
        10/12/2017 12:263Voice Line State Change, Line Number = 2, Prev State = OOS, New State = IS
        10/12/2017 12:2614Power Supply Telemetry Log - BATTERY MISSING