Orbi WiFi 7 RBE973
Reply

[Lan access from Remote]... Someone played audio through my computer speaker and said my name

jvgaeta
Follower

[Lan access from Remote]... Someone played audio through my computer speaker and said my name

Hello!

 

A couple of days ago, I was having a conversation with my SO in my home office. Suddenly, a man's voice was coming through my computer speakers and said my name twice. It sounded like something that was pre-recorded as their was also music spliced in. What was scarier is that the topic the speaker was fixated on was relevant to our conversation. I've since disabled UPnP, changed password of router and my accounts since I'm worried they had a key logger. I also ran multiple scans that didn't yield much of anything. So, I took a look at the router logs and voila remote access from an external ip to an apparently open tcp port. The IP addresses look very suspicious to as they appear to be proxies in various countries outside of my own (Brazil, China, Japan etc). The firewall was disabled on the pc I was using without me realizing it, so I imagine that's how they were able to get in. Likely by just scanning for open ports. Any explanation for how they were able to play audio / listen to me? I'm creeped out 😕

 

This is a small sample of the logs.

 

[LAN access from remote] from 178.162.194.147:45154 to 192.168.0.17:38908 1 Wed Sep 01 14:05:09 2021 192.168.0.17:38908 178.162.194.147:45154
[LAN access from remote] from 185.225.234.25:15546 to 192.168.0.17:38908 1 Wed Sep 01 14:05:08 2021 192.168.0.17:38908 185.225.234.25:15546
[LAN access from remote] from 213.136.79.7:51475 to 192.168.0.17:38908 1 Wed Sep 01 14:05:08 2021 192.168.0.17:38908 213.136.79.7:51475
[LAN access from remote] from 121.165.75.172:40954 to 192.168.0.17:38908 1 Wed Sep 01 14:05:07 2021 192.168.0.17:38908 121.165.75.172:40954
[LAN access from remote] from 124.246.85.176:1403 to 192.168.0.17:38908 1 Wed Sep 01 14:05:06 2021 192.168.0.17:38908 124.246.85.176:1403
[LAN access from remote] from 183.237.146.195:20490 to 192.168.0.17:38908 1 Wed Sep 01 14:05:04 2021 192.168.0.17:38908 183.237.146.195:20490
[LAN access from remote] from 116.49.55.189:17175 to 192.168.0.17:38908 1 Wed Sep 01 14:05:03 2021 192.168.0.17:38908 116.49.55.189:17175
[LAN access from remote] from 111.251.95.105:22427 to 192.168.0.17:38908 1 Wed Sep 01 14:05:01 2021 192.168.0.17:38908 111.251.95.105:22427
[LAN access from remote] from 123.18.31.150:6881 to 192.168.0.17:38908 1 Wed Sep 01 14:05:01 2021 192.168.0.17:38908 123.18.31.150:6881
[LAN access from remote] from 157.45.13.245:63800 to 192.168.0.17:38908 1 Wed Sep 01 14:05:01 2021 192.168.0.17:38908 157.45.13.245:63800
[LAN access from remote] from 175.140.110.234:25813 to 192.168.0.17:38908 1 Wed Sep 01 14:05:00 2021 192.168.0.17:38908 175.140.110.234:25813
[LAN access from remote] from 182.56.206.154:34988 to 192.168.0.17:38908 1 Wed Sep 01 14:05:00 2021 192.168.0.17:38908 182.56.206.154:34988
[LAN access from remote] from 68.119.24.47:49155 to 192.168.0.17:38908 1 Wed Sep 01 14:05:00 2021 192.168.0.17:38908 68.119.24.47:49155
[LAN access from remote] from 83.44.89.215:59695 to 192.168.0.17:38908 1 Wed Sep 01 14:05:00 2021 192.168.0.17:38908 83.44.89.215:59695
[LAN access from remote] from 82.209.131.4:31490 to 192.168.0.17:38908 1 Wed Sep 01 14:04:59 2021 192.168.0.17:38908 82.209.131.4:31490
[LAN access from remote] from 119.39.248.126:7800 to 192.168.0.17:38908 1 Wed Sep 01 14:04:59 2021 192.168.0.17:38908 119.39.248.126:7800
[LAN access from remote] from 5.189.157.90:9905 to 192.168.0.17:38908 1 Wed Sep 01 14:04:58 2021 192.168.0.17:38908 5.189.157.90:9905
[LAN access from remote] from 60.156.246.59:26469 to 192.168.0.17:38908 1 Wed Sep 01 14:04:58 2021 192.168.0.17:38908 60.156.246.59:26469
[LAN access from remote] from 1.165.117.227:37159 to 192.168.0.17:38908 1 Wed Sep 01 14:04:58 2021 192.168.0.17:38908 1.165.117.227:37159
[LAN access from remote] from 89.161.47.96:26360 to 192.168.0.17:38908 1 Wed Sep 01 14:04:58 2021 192.168.0.17:38908 89.161.47.96:26360
[LAN access from remote] from 109.252.90.153:17579 to 192.168.0.17:38908 1 Wed Sep 01 14:04:58 2021 192.168.0.17:38908 109.252.90.153:17579
[LAN access from remote] from 82.215.98.134:21668 to 192.168.0.17:38908 1 Wed Sep 01 14:04:57 2021 192.168.0.17:38908 82.215.98.134:21668
[LAN access from remote] from 179.61.240.100:59144 to 192.168.0.17:38908 1 Wed Sep 01 14:04:57 2021 192.168.0.17:38908 179.61.240.100:59144
[LAN access from remote] from 78.83.96.240:18200 to 192.168.0.17:38908 1 Wed Sep 01 14:04:57 2021 192.168.0.17:38908 78.83.96.240:18200
[LAN access from remote] from 190.115.65.46:14747 to 192.168.0.17:38908 1 Wed Sep 01 14:04:56 2021 192.168.0.17:38908 190.115.65.46:14747
[LAN access from remote] from 197.221.89.182:17067 to 192.168.0.17:38908 1 Wed Sep 01 14:04:54 2021 192.168.0.17:38908 197.221.89.182:17067
[LAN access from remote] from 91.39.241.148:39684 to 192.168.0.17:38908 1 Wed Sep 01 14:04:54 2021 192.168.0.17:38908 91.39.241.148:39684
[LAN access from remote] from 36.226.167.192:27683 to 192.168.0.17:38908 1 Wed Sep 01 14:04:54 2021 192.168.0.17:38908 36.226.167.192:27683
[LAN access from remote] from 86.38.158.101:2753 to 192.168.0.17:38908 1 Wed Sep 01 14:04:53 2021 192.168.0.17:38908 86.38.158.101:2753
[LAN access from remote] from 84.236.36.158:57294 to 192.168.0.17:38908 1 Wed Sep 01 14:04:53 2021 192.168.0.17:38908 84.236.36.158:57294
[LAN access from remote] from 151.254.205.229:5526 to 192.168.0.17:38908 1 Wed Sep 01 14:04:49 2021 192.168.0.17:38908 151.254.205.229:5526
[LAN access from remote] from 223.16.117.206:53999 to 192.168.0.17:38908 1 Wed Sep 01 14:04:49 2021 192.168.0.17:38908 223.16.117.206:53999
[LAN access from remote] from 212.91.160.177:16873 to 192.168.0.17:38908 1 Wed Sep 01 14:04:49 2021 192.168.0.17:38908 212.91.160.177:16873
[LAN access from remote] from 207.180.192.205:6915 to 192.168.0.17:38908 1 Wed Sep 01 14:04:49 2021 192.168.0.17:38908 207.180.192.205:6915

.

.

Model: C7000|Nighthawk - AC1900 WiFi Cable Modem Router
Message 1 of 2
FURRYe38
Guru

Re: [Lan access from Remote]... Someone played audio through my computer speaker and said my name

Any progress on this? 

Message 2 of 2
Discussion stats
  • 1 reply
  • 497 views
  • 0 kudos
  • 2 in conversation
Announcements

Orbi WiFi 7