Windows 10: I have a firewall keeps popping up a blocked set of packets from ransomware called "conti"...

Discus and support I have a firewall keeps popping up a blocked set of packets from ransomware called "conti"... in AntiVirus, Firewalls and System Security to solve the problem; Hello, I have a Cisco Meraki Firewall AMP, which has started blocking packets from what it things are an infection of ransomwhere called "Conti"... Discussion in 'AntiVirus, Firewalls and System Security' started by bed1m, Jul 26, 2022.

  1. bed1m Win User

    I have a firewall keeps popping up a blocked set of packets from ransomware called "conti"...


    Hello, I have a Cisco Meraki Firewall AMP, which has started blocking packets from what it things are an infection of ransomwhere called "Conti" Variant. The packest certainly look suspicious, but this is a ServerCore 2022 HyperV hypervisor and the only 3rd party software is communication softare from APC for shutting down the machine in case of UPS failure. the Built in firewall and Defender stuff is running and up to date and turns up nothing and I ran MSERT and it too turned up nothing. The packets are sent out only saturday and sunday and appear to be going to my management workstati

    :)
     
    bed1m, Jul 26, 2022
    #1
  2. zebal Win User

    What in the firewall is blocking my app? UPDATE

    One easy way to figure out which executable is being blocked is to use process monitor:
    https://docs.microsoft.com/en-us/sys...nloads/procmon

    Download it and run as Administrator.

    Next step is to configure filtering in process monitor to show only dropped connections, here is a link to customized setting for this task:
    ProcmonConfiguration.pmc

    Download it to your desktop, then in process monitor click on File -> Import configuration and locate downloaded configuration.

    Next step is to clear accumulated data by pressing following button marked in green in process monitor:

    I have a firewall keeps popping up a blocked set of packets from ransomware called "conti"... [​IMG]


    Now go ahead and try to reproduce your problem with Arduino IDE.
    Within process monitor all dropped TCP connections and closed TCP connections will be marked with Cyan color as soon as there is dropped data.

    Not all of this cyan lines are drops, but it should give you some picture.
    If you want to be 100% sure, click on filter to enable showing received TCP data as follows, click on red marked button:

    I have a firewall keeps popping up a blocked set of packets from ransomware called "conti"... [​IMG]


    Here when filter opens up uncheck options that says
    Operation is TCP receive


    I have a firewall keeps popping up a blocked set of packets from ransomware called "conti"... [​IMG]


    Click OK and now you can investigate which of the cyan lines are dropped packets and which ones are normal TCP close.
    For example if you see cyan lines without matching TCP receive then you know these lines are representing firewall problem with outbound traffic (not inbound!)

    Your next step is to investigate if within firewall there are block rules that contribute to dropping packets.
    If not, next step see if default outbound is set to block in firewall, and if so create allow rule for dropped packets.
     
    zebal, Jul 26, 2022
    #2
  3. bencrutz Win User
    Blocking Torrenting

    to effectively block torrent, you need to define fire-walling rules that are based on layer 7 pattern and packet content matching - which i doubt that your switch is capable of.

    consider a mikrotik or any powerful router to get it done.

    shall you deploy a mikrotik, all you need to do is add this rules to firewall:
    • drop packet that are matching to a L7 pattern of torrents packet (use built in feature: p2p=all-p2p) - this will keep classic - non secure - torrents connection out
    • block outgoing DHT from your network (packets containing "d1:ad2:id20:" with packet size from 95 to 190 and in a udp protocol)
    • block outgoing torrent announce (packets containing "info_hash" in a tcp protocol format)
     
    bencrutz, Jul 26, 2022
    #3
  4. Smeed Win User

    I have a firewall keeps popping up a blocked set of packets from ransomware called "conti"...

    Smeed, Jul 26, 2022
    #4
Thema:

I have a firewall keeps popping up a blocked set of packets from ransomware called "conti"...

Loading...
  1. I have a firewall keeps popping up a blocked set of packets from ransomware called "conti"... - Similar Threads - firewall keeps popping

  2. Pop-up Ransomware Warning

    in AntiVirus, Firewalls and System Security
    Pop-up Ransomware Warning: The other day, I clicked on a link for an interesting article. I was pinged with a supposed ransomware attack. Knowing everything that I know about computers, I immediately clicked CTRL ALT DEL together to bring up Task Manager and ended the task. You will not be able to...
  3. Ransomware Protection keeps blocking svchost.exe

    in AntiVirus, Firewalls and System Security
    Ransomware Protection keeps blocking svchost.exe: Recently for whatever reason my Ransomware Protection has started to block svchost.exe from %userprofile%\videos? This happens every time I turn on my PC, I also very odd to because last I checked svchost.exe is legitimate host process and this has just started happening out...
  4. Getting pop-ups that "There is a ransomware detected".

    in AntiVirus, Firewalls and System Security
    Getting pop-ups that "There is a ransomware detected".: As you can see that in screen shot one it scanned risky worm on drive D, But there is no D drive on my device. And I also removed this virus so many times through M.S Defender, but it shows same Pop-Up again and again. After that I run MS Safety Scanner, but it says there no...
  5. Windows Firewall blocked some features of this app keeps popping up

    in AntiVirus, Firewalls and System Security
    Windows Firewall blocked some features of this app keeps popping up: I get this popup with Plex Media Sever, Plex Media Player, and Calibre. All three apps are in the pass list for both Bullguard and Windows Defender Firewall. Why does this happen and how can I stop it? I have tried just about every proposed fix I can find on the net. 157051
  6. block pop ups

    in Windows 10 Customization
    block pop ups: how do I stop pop up ads https://answers.microsoft.com/en-us/windows/forum/all/block-pop-ups/a35a6c30-ca14-4dc2-8c1c-2efaef511f05
  7. Pop up block

    in Windows 10 BSOD Crashes and Debugging
    Pop up block: Windows 10 problem started yesterday. When I attempt to open an attachment (Facebook "view")…... Response says block-up stops opening. I have gone to block-up in the control panel.....and it is not turned on. Any ideas Ed B...
  8. blocking pop ups

    in AntiVirus, Firewalls and System Security
    blocking pop ups: I am unable to click on trusted links in my emails. I keep getting this message "Could not open window.If you have a pop-up blocker installed, please make sure it is disabled." This has only started recently so I'm assuming it's from a resent update. Help please....
  9. Windows firewall not logging packets

    in Windows 10 Network and Sharing
    Windows firewall not logging packets: I need to troubleshoot firewall but it doesn't generate logs. I use firewall policy from local group policy and logging is enabled there. things I tried so far: change log file path to E:/logs/firewall_log.txt create file manually 120065
  10. Pop up Block

    in Browsers and Email
    Pop up Block: Hello All, I am trying to open a link on my companies web site from my home computer. It tells me I cant because a pop up blocker is on, and I have checked that it isn't. Any pointers please ? 60820