× Introducing the Orbi 970 Series Mesh System with WiFi 7 technology. For more information visit the NETGEAR Press Room.
Orbi WiFi 7 RBE973
Reply

Re: DDOS ATTACKS!!! COPS CAME!!! PLEASE HELP!!!

sev_kouva
Aspirant

DDOS ATTACKS!!! COPS CAME!!! PLEASE HELP!!!

Hello everyone,

 

I'm going through an odd problem here and I really don't know what else I have to do and try.

So, a month ago cops randomly showed up to our house like 8 of them and they told us someone with your ip address was at VETERANS CHAT ROOM and he was threatening to commit a suicide and it links back to your house. In our house no one is going through this and the problem is I'm the only one using the internet 80% of the times.

 

3 weeks passes by and the exact same thing happens and they show up once again, same story and everything, They search the house and see everything is OK, we try to login to the ROUTER and the secret questions don't work anymore. They leave and I reset the router to factory settings and just buy a brand new one which is this one R9000 with a brand new SPECTRUM Modem.

 

I setup the router with complicated passwords and everything with secret answers that don't even make sense... on purpose.

I login to the router settings and check my logs and I notice constant DDOS attacks and the internet just goes down completely. It's constant everyday thing, it happens every other hour.

 

I called Spectrum my internet company and they don't even know what to do and told me your IP address is DYNAMIC and it keeps changing, nothing to worry about. If it's dynamic how is it possible for this person to constantly attack my ip address and take it down?

So, they didn't even know what to do and just send a regular tech who barely knew anything about ip addresses and basic troubleshooting stuff. 

 

The Next day I called my Router company Netgear and explained to them what's going on and they were shocked and told me they've never heard of this and they don't know what to do,besides recommending me to USE a VPN, which slows down my internet and I already have 2 of them.

How am I suppose to get rid of this attacker? is there anyway I can change my default router ip address from 192.168.1 to something else? the other day I tried it and it completely went down and I couldn't bring it back on again.

 

Here are some of the logs.

[DoS Attack: SYN/ACK Scan] from source: 141.105.66.244, port 443, Friday, May 24, 2019 00:29:24

[DoS Attack: RST Scan] from source: 74.125.197.109, port 993, Friday, May 24, 2019 00:07:43
[DoS Attack: RST Scan] from source: 74.125.197.108, port 993, Friday, May 24, 2019 00:07:43
[DoS Attack: ACK Scan] from source: 52.201.182.69, port 443, Friday, May 24, 2019 00:07:28
[DoS Attack: ACK Scan] from source: 205.185.216.42, port 443, Friday, May 24, 2019 00:07:12
[DoS Attack: ACK Scan] from source: 20.36.246.152, port 443, Friday, May 24, 2019 00:07:07
[DoS Attack: ACK Scan] from source: 74.125.197.108, port 993, Friday, May 24, 2019 00:07:00
[DoS Attack: ACK Scan] from source: 52.201.182.69, port 443, Friday, May 24, 2019 00:06:51
[DoS Attack: SYN/ACK Scan] from source: 52.86.194.88, port 443, Friday, May 24, 2019 00:06:50
[DoS Attack: SYN/ACK Scan] from source: 216.58.193.198, port 443, Friday, May 24, 2019 00:05:58
[DoS Attack: SYN/ACK Scan] from source: 52.114.76.34, port 443, Friday, May 24, 2019 00:05:53
[DoS Attack: SYN/ACK Scan] from source: 54.70.55.114, port 443, Friday, May 24, 2019 00:05:51
[DoS Attack: SYN/ACK Scan] from source: 52.35.46.249, port 443, Friday, May 24, 2019 00:05:51
[DoS Attack: SYN/ACK Scan] from source: 216.58.193.198, port 443, Friday, May 24, 2019 00:05:50
[DoS Attack: ACK Scan] from source: 52.230.222.68, port 443, Friday, May 24, 2019 00:05:44
[DoS Attack: SYN/ACK Scan] from source: 52.39.55.138, port 443, Friday, May 24, 2019 00:05:44
[DoS Attack: SYN/ACK Scan] from source: 54.70.55.114, port 443, Friday, May 24, 2019 00:05:44
[DoS Attack: SYN/ACK Scan] from source: 52.39.55.138, port 443, Friday, May 24, 2019 00:05:44
[DoS Attack: SYN/ACK Scan] from source: 52.35.46.249, port 443, Friday, May 24, 2019 00:05:44
[DoS Attack: SYN/ACK Scan] from source: 216.58.193.198, port 443, Friday, May 24, 2019 00:05:44

[DoS Attack: SYN/ACK Scan] from source: 203.107.43.207, port 80, Thursday, May 23, 2019 23:59:18

 

Can anyone please help me out and suggest me what to do and how I can get rid of this attacker?

Router firmware is updated to latest settings. 

 

Please help me out someone!

Really appreciate it, thanks!

Model: R9000|Nighthawk X10 AD7200 Smart WiFi Router
Message 1 of 3
Netduma_Alex
NetDuma Partner

Re: DDOS ATTACKS!!! COPS CAME!!! PLEASE HELP!!!

Wow this is really interesting, I can't wait to see how it turns out.

 

However, this is the wrong forum! Sorry...

 

I think this is the forum you want: https://community.netgear.com/t5/Nighthawk-WiFi-Routers/bd-p/home-wifi-routers-nighthawk

Message 2 of 3
FURRYe38
Guru

Re: DDOS ATTACKS!!! COPS CAME!!! PLEASE HELP!!!

Yes post in the NH forum. 

 

Also contact your ISP and have them give you a new WAN IP address. 


@sev_kouva wrote:

Hello everyone,

 

I'm going through an odd problem here and I really don't know what else I have to do and try.

So, a month ago cops randomly showed up to our house like 8 of them and they told us someone with your ip address was at VETERANS CHAT ROOM and he was threatening to commit a suicide and it links back to your house. In our house no one is going through this and the problem is I'm the only one using the internet 80% of the times.

 

3 weeks passes by and the exact same thing happens and they show up once again, same story and everything, They search the house and see everything is OK, we try to login to the ROUTER and the secret questions don't work anymore. They leave and I reset the router to factory settings and just buy a brand new one which is this one R9000 with a brand new SPECTRUM Modem.

 

I setup the router with complicated passwords and everything with secret answers that don't even make sense... on purpose.

I login to the router settings and check my logs and I notice constant DDOS attacks and the internet just goes down completely. It's constant everyday thing, it happens every other hour.

 

I called Spectrum my internet company and they don't even know what to do and told me your IP address is DYNAMIC and it keeps changing, nothing to worry about. If it's dynamic how is it possible for this person to constantly attack my ip address and take it down?

So, they didn't even know what to do and just send a regular tech who barely knew anything about ip addresses and basic troubleshooting stuff. 

 

The Next day I called my Router company Netgear and explained to them what's going on and they were shocked and told me they've never heard of this and they don't know what to do,besides recommending me to USE a VPN, which slows down my internet and I already have 2 of them.

How am I suppose to get rid of this attacker? is there anyway I can change my default router ip address from 192.168.1 to something else? the other day I tried it and it completely went down and I couldn't bring it back on again.

 

Message 3 of 3
Discussion stats
  • 2 replies
  • 2116 views
  • 0 kudos
  • 3 in conversation
Announcements

Orbi WiFi 7