Ring Security Cameras

Browse posts, comment, and join in the discussion about Ring’s indoor and outdoor cameras.

J
Ring Device accessing a DNS server in Austria designated as a C&C risk
cs-support
wireless-security-cameras
network

I have four Ring security cams. Just recently the stick-up cam has begun trying to reach a DNS server in Austria. According to my firewall security, the server in question poses a C2/Generic-A security threat.This has just started happening within the last week. ulogd[20523]: id="2022" severity="info" sys="SecureNet" sub="packetfilter" name="Packet dropped (ATP)" action="drop" fwrule="63001" initf="eth1" **threatname="C2/Generic-A"** srcmac="xx:xx:xx:xx:48:72" dstmac="00:13:3b:11:25:19" srcip="192.168.5.160" dstip="185.121.177.177" proto="17" length="60" tos="0x00" prec="0x00" ttl="255" srcport="32091" dstport="53" the registered name for the server is "Silent Ghost", which is rather ominous-sounding.I performed a factory reset on the device and assigned it a different IP address but the problem is now being flagged on the new address. None of my other cameras are doing this. (Nor any of my other devices or computers.)You can find out more about this threat at https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/C2~Generic-A.aspxHas anyone had a similar experience? Thankfully my firewall blocks this behavior but I'm concerned that the ring cam firmware may be compromised.

2805

0

0

06-06-2021 18:53:28

Loading...
Loading...
Loading...Loading...Loading...Loading...Loading...Loading...Loading...
Loading...
Loading...Loading...Loading...Loading...Loading...Loading...Loading...
Loading...
Loading...Loading...Loading...Loading...Loading...Loading...Loading...

Didn't find an answer ?

Log in or create your Ring account to post a question and join in the on the conversation.

Most Helpful Members