Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Notification of unknown phone connected but MAC is for one of my pcs


  • Please log in to reply
7 replies to this topic

#1 sean7200

sean7200

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 15 March 2024 - 12:37 PM

I am trying to figure out if this was some sort of breach or some other issue. For my Nighthawk XR1000 router with firmware 1.0.0.64:
Last night, my Internet connection stopped, though the network and the internet didn't show as disconnected (Win 11).
I received a Nighthawk app notification:
  • Armor detected a new device, AG Mobile ULTRA phone. View Details. MAC [address]
In the device list, the MAC address shown was for a wired PC and said online, wired connection, and had an IPv4 address allocated. The PC was off but Ethernet cable plugged in.
There was a dual entry in the device list for the same computer name that had a different MAC address, connection type also wired, but with offline status.
This morning, two more notifications:
  • Suspicious connection blocked: Armor has detected and blocked a suspicious connection on Synology NAS. (I do have a Synology NAS, Ethernet cable.)
  • New Device: Armor detected a new device, Intel computer. View Details. MAC [another-address]
I do have Armor subscription. Nighthawk repeatedly said no firmware update available. Today, found, manually downloaded and installed v. 68 and then v. 72.
 
I have posted in Netgear's Reddit, but it doesn't look very active. Do you have any suggestions or ideas on seeing whether this was a inaccurate notification or a security breach?

 



BC AdBot (Login to Remove)

 


#2 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:49 AM

Posted 15 March 2024 - 02:01 PM

Can you show both mac addresses? These are not personally identifiable information.

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#3 sean7200

sean7200
  • Topic Starter

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 15 March 2024 - 03:13 PM

Yes

 

04:42:1A:EB:1C:79 - the MAC of the PC

00:FF:58:55:B6:D3

 

ipconfig /all gives the second address as

 

NETGEAR-VPN  :  TAP-Windows Adapter V9

 

I have been using the NETGEAR VPN to provide access to a floating license to an employee.



#4 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:49 AM

Posted 15 March 2024 - 03:30 PM

Your second MAC doesn't exist at all https://maclookup.app/search/result?mac=00:FF:58:55:B6:D3

Your second Mac is for Asus Tek

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#5 sean7200

sean7200
  • Topic Starter

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 15 March 2024 - 03:46 PM

I did not realize that this was the VPN address until I looked it up for you.  It must be one that is unallocated and used for other purposes.  My Netgear XR1000 router has a VPN option that assigns that MAC.
 
VPN Service

OpenVPN configuration package download

For Windows For non-Windows For Smart Phone

OpenVPN client setup instruction      Windows      Mac OSX       iPhone/iPad       Android

Advanced Configurations

TUN Mode Service Type  UDP   TCP 

TUN Mode Service Port *****

TAP Mode Service Type  UDP   TCP

TAP Mode Service Port *****

Clients will use this VPN connection to access       All sites on the Internet & Home Network             Home Network only               Auto



#6 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:49 AM

Posted 15 March 2024 - 04:02 PM

Does it show that in the manual?

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra


#7 sean7200

sean7200
  • Topic Starter

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:01:49 AM

Posted 15 March 2024 - 04:14 PM

Thank you, yes. Chapter 13 in here:

 

https://www.downloads.netgear.com/files/GDC/XR1000/XR1000_UM_EN.pdf



#8 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 34,434 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:49 AM

Posted 15 March 2024 - 04:55 PM

Awesome glad you provided the manual reference it may help others out.

US Navy Veteran from 2002 to 2006

Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015

Arch Desktop - https://termbin.com/epij

Arch Laptop - https://www.termbin.com/dnwk

Ubuntu Server - https://termbin.com/zvra





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users