Hello + Network attacks-HELP me plz

Campbelltown2016

Beta member
Messages
0
Location
Australia
Hi Guys, I am a self learner when it comes to pc stuff. I am not a novice but I am far far away from knowing much either. I presently need help about NETWORK ATTACKS as my antivirus stop hundreds each days since I started using Purevpn...
Hi guys,
I am turning to you because purevpn tech prodigees won't really help me about NETWORK ATTACKS happening when I use their VPN.
I have use Bullguard antivirus for the last 2 years without issue and with same settings. I was previously using easy-hide-ip as VPN but changed to pureVPN end of last year and that is when bullguard started to send me notification about “blocked NETWORK ATACKS”. Initially that was only few per days but it quickly evolve to several hundred a day.
If I do not use purevpn, I do not experience those “NETWORK ATTACKS”, but as soon as I connect…it s non stop these days, one attack after the other is being blocked.
I asked purevpn what was happening and initially was told those were not real attacks, but just over sensitive setting from my antivirus. I contacted Bullguard staff and after providing them with logs etc…they concluded the attacks being real but told me not to worry their software will continue to blocks them all! Re-assuring, isn't it ! Well NO! it ll take only one attack to succeed to do damages to devices in my network! So I am worried! 3 years ao we lost 3 laptop in the family within a week as damages were so important tech shop could not fix them…all this after a network intrusion was detected but ignored!
Anyway pure vpn allegedly investigated further and provided me with free firewall setting and said that will now stop everything …it only slow down the attacks for few hours only then back to non stop! They are now saying they are not real. So I sent them bullguard tech guys results saying they are indeed real attacks!
I have copies of logs and took pic of notifications. It shows that attacks are having the same MAC address for several attacks but the IP change with each attacks.
I have asked purevpn for help and a solution…
Please see below the conversation with purevpn tech guys and also part of the one with bullguard tech guys:
[FONT=&quot]Re: Network attacks [/FONT]

[LIST]
[*][FONT=&quot]4/1/16 at 4:32 AM More Information [/FONT]
[/LIST]
[FONT=&quot]From:[/FONT]
[FONT=&quot]PureVPN Support [/FONT]

[LIST]
[*][FONT=&quot]To:[/FONT]
[/LIST]
[FONT=&quot]V....... M....... [/FONT]

[FONT=&quot]Hi,[/FONT]
[FONT=&quot]Thanks for your reply. Your email has been viewed and forwarded to the concerned department and you will be updated shortly.[/FONT]


[FONT=&quot]Thanks,[/FONT]
[FONT=&quot]Hummer[/FONT]
[FONT=&quot]PureVPN Support Team.[/FONT]
[FONT=&quot]
[/FONT]
[FONT=&quot]***** We apologize for the delay, might cause in replying your email. We are experiencing an excessive load, unexpectedly, due to customer interest in the services. Our 24/7 live chat is available to assist you on immediate basis.*****[/FONT]

[FONT=&quot]On Thu, Mar 31, 2016 at 3:33 AM, V....... M....... wrote:[/FONT]
[FONT=&quot]Hi Guys, thank for your reply and assistance on the matter.[/FONT]
[FONT=&quot]I've turned bullguard internet security off and of course I am not getting any attacks notifications because the bullguard firewall is not working! This doesn't mean they don't occur.[/FONT]

[FONT=&quot]So what can be done to stop those attacks?[/FONT]

[FONT=&quot]Can I go online in forums and chat about it?[/FONT]

[FONT=&quot]Prior to contact you, I contacted the tech support from bullguard and they asked me to provide some screen shots and logs copies , and they told me the attacks are real![/FONT]
[FONT=&quot]please read part transcript of live chat with bullguard tech support:[/FONT]
[FONT=&quot]" [/FONT]
[I][COLOR=maroon][FONT=&quot]Mihai: Hello, welcome to BullGuard Live Support! I am sorry if there might be a bit of waiting time. Please hold and I will be back with you in a few minutes.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: Hi, I keep getting "single port scan: network attack" notification with attacker IP & MAC and time stamp....am I being attacked for real? someday I can get up to 200 other days just a dozen.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: Please provide me with the attacker IP address.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: it changes with every attacks ...thelast one was 71.6.158.166 ([URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=http%3A%2F%2Fubuntu14158166.aspadmin.net"][COLOR=blue]ubuntu14158166.aspadmin.net[/COLOR][/URL][/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: the previous one209.126.102.181[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: others:[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: The two IP address do not belong to your local network.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: 69.25.7.66 / 68.67.15.218 /[URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=http%3A%2F%2F85.25.218.201%2F185.104.29.16"][COLOR=blue]85.25.218.201/185.104.29.16[/COLOR][/URL][/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: They seem to be hosting servers, therefore I suspect these are genuine attacks.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: what does this mean?[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: You should let BullGuard block them.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: holly ****![/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: can I find out who is behind?[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: how can I make sure they don't suceed?[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: is that mean they have already infiltrated my router?[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: Keep BullGuard active all the time, and it will continue blocking them.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: You can also ban the attackers if you wish, but that might not help if the IP address keeps changing.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: yeah for each attack they change their IP[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: And no, the attacks are coming from other IP addresses, not from your router.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: so that mean they have already access to my router, isn't it?[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: ho ok thanks[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: I am using VPN , that should make it difficult for them to attack..unless they have a point of reference or access to the router isn't it?[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: If you are using a VPN, the attacks might be coming from the servers you are using for your internet connection.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: But there is no reason to take any action, if this does not affect your activity.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: Anyting I can do with bullguard to stop the attacks [/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: BullGuard blocks the attacks automatically. [/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: any suggestion how I could fight back or track them? is there any such software?[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]Mihai: There is not much you can do, except blocking them.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: Bullguard is the best software and the ONLY one who got the attacks and stop them[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: ok then , I guess I let you go to elp someone else.[/FONT][/COLOR][/I]
[I][COLOR=maroon][FONT=&quot]VM: thank you for your help, expertise & time today, have a good day/night[/FONT][/COLOR][/I]


[FONT=&quot]Regards[/FONT]

[FONT=&quot]V.M[/FONT]
[B][FONT=&quot]Sent:[/FONT][/B][FONT=&quot] Friday, March 25, 2016 at 9:01 PM
[B]From:[/B] "PureVPN Support" <[URL="https://3c-lxa.mail.com/mail/client/mail/mailto;jsessionid=0CC3923EDF4BDBF2BE20548A49D2B43E-n1.lxa06b?to=enquiry%40purevpn.com"][COLOR=blue]enquiry@purevpn.com[/COLOR][/URL]>
[B]To:[/B] "V....... M......." <[I][COLOR=maroon] VM[/COLOR][/I] >
[B]Subject:[/B] Re: Fw: Re: NETWORK ATTACKS & traceable IP ![/FONT]
[FONT=&quot]Hi, [/FONT]

[FONT=&quot]Thanks for your patience. It seems that your antivirus is giving wrong alerts because we have checked and all incoming ports are blocked in your account so there is no chance to get further attacks. You are requested to disable Bullguard then reconnect VPN and check and also share the result with us.[/FONT]

[FONT=&quot]Feel free to contact us for further assistance.[/FONT]

[FONT=&quot]Regards[/FONT]
[FONT=&quot]Albert[/FONT]
[FONT=&quot]PureVPN Support Team[/FONT]

[FONT=&quot]***** We apologize for the delay, might cause in replying your email. We are experiencing an excessive load, unexpectedly, due to customer interest in the services. Our 24/7 live chat is available to assist you on immediate basis.*****[/FONT]

[FONT=&quot]On Fri, Mar 25, 2016 at 6:22 AM, V....... M....... <[I][COLOR=maroon] VM[/COLOR][/I] > wrote: [/FONT]
[FONT=&quot]Hi guys , any progress in solving those network attacks?[/FONT]
[FONT=&quot]thanks[/FONT]
[I][COLOR=maroon][FONT=&quot]VM[/FONT][/COLOR][/I]

[B][FONT=&quot]Sent:[/FONT][/B][FONT=&quot] Tuesday, March 22, 2016 at 7:41 PM
[B]From:[/B] [I][COLOR=maroon]VM[/COLOR][/I]
[B]To:[/B] "PureVPN Support" <enquiry@purevpn.com>
[B]Subject:[/B] Re: NETWORK ATTACKS & traceable IP ![/FONT]
[FONT=&quot]Hi guys as per your last email. I have tried again ...total waste of time, the attacks are coming even faster now! Please see results attached (sorry previous results still there). [/FONT]
[FONT=&quot]Hi I thought that by using your service, my Ip will be hidden and nobody could find it! so why this is not the case![/FONT]
[FONT=&quot]In addition of getting network attacks when using pureVPN, now my Ip is not even hidden! What are my chance of getting a full refund? please advise[/FONT]
[FONT=&quot]Regards[/FONT]

[I][COLOR=maroon][FONT=&quot]VM[/FONT][/COLOR][/I]
[FONT=&quot][URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=https%3A%2F%2Fderef-mail.com%2Fmail%2Fclient%2Fdereferrer%2F%3FredirectUrl%3Dhttps%253A%252F%252Fdiafygi.github.io%252Fwebrtc-ips%252F"][COLOR=blue]https://diafygi.github.io/webrtc-ips/[/COLOR][/URL][/FONT]
[FONT=&quot][URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=https%3A%2F%2Fderef-mail.com%2Fmail%2Fclient%2Fdereferrer%2F%3FredirectUrl%3Dhttp%253A%252F%252Fwww.lifehacker.com.au%252F2015%252F02%252Fhow-to-see-if-your-vpn-is-leaking-your-ip-address-and-how-to-stop-it%252F"][COLOR=blue]http://www.lifehacker.com.au/2015/02/how-to-see-if-your-vpn-is-leaking-your-ip-address-and-how-to-stop-it/[/COLOR][/URL][/FONT]
[FONT=&quot]PLEASE CONSIDER THE ENVIRONMENT BEFORE PRINTING THIS EMAIL.

NB: This email has been sent to the mentioned recipient(s) and its content and/or any attachment(s) is/are or may be confidential and subject to copyrights. This email is also subject to copyright. No part of it should be reproduced, adapted or communicated without the written consent of the copyright owner. Any personal information in this email must be handled in accordance with the Privacy Act 1988 (Cth).[/FONT]


[B][FONT=&quot]Sent:[/FONT][/B][FONT=&quot] Tuesday, March 22, 2016 at 6:19 PM
[B]From:[/B] "PureVPN Support" <enquiry@purevpn.com>
[B]To:[/B] [I][COLOR=maroon]VM[/COLOR][/I]
[B]Subject:[/B] Re: NETWORK ATTACKS[/FONT]
[FONT=&quot]Hi, [/FONT]

[FONT=&quot]Thank you for your patience, you are requested to try now, as we have added NAT firewall (Free) into your account, you are requested to try now, and share a result with us, so we may proceed it accordingly.[/FONT]

[FONT=&quot]Feel free to contact us for further assistance.[/FONT]

[FONT=&quot]Regards[/FONT]
[FONT=&quot]Andrew[/FONT]
[FONT=&quot]PureVPN Support Team[/FONT]


[FONT=&quot]***** We apologize for the delay, might cause in replying your email. We are experiencing an excessive load, unexpectedly, due to customer interest in the services. Our 24/7 live chat is available to assist you on immediate basis.*****[/FONT]

[FONT=&quot]On Tue, Mar 22, 2016 at 5:00 AM, <[I][COLOR=maroon] VM[/COLOR][/I] > wrote: [/FONT]
[FONT=&quot]As per attachments. [/FONT]
[B][FONT=&quot]Sent:[/FONT][/B][FONT=&quot] Tuesday, March 22, 2016 at 1:23 AM
[B]From:[/B] "PureVPN Support" <enquiry@purevpn.com>
[B]To:[/B] [I][COLOR=maroon]VM[/COLOR][/I]
[B]Subject:[/B] Re: Enquiry Form[/FONT]
[FONT=&quot]Hi, [/FONT]

[FONT=&quot]Thanks for your reply. You are requested to do following tests and share the result with us.[/FONT]

[FONT=&quot]1- Connect VPN with Australian server first then once you receive an attack please check the VPN assigned IP and share with us.[COLOR=red]DONE[/COLOR][/FONT]
[FONT=&quot]2- Connect VPN with Brunei, Germany or Netherlands Server and let us know if you receive same behavior. [COLOR=red]DONE[/COLOR][/FONT]
[FONT=&quot]3- Go to your firewall settings and block all incoming connections on your public network.[COLOR=red]DONE. it was already blocked[/COLOR][/FONT]

[FONT=&quot]Feel free to contact us for further assistance.[/FONT]

[FONT=&quot]Regards[/FONT]
[FONT=&quot]Albert[/FONT]
[FONT=&quot]PureVPN Support Team[/FONT]

[FONT=&quot]***** We apologize for the delay, might cause in replying your email. We are experiencing an excessive load, unexpectedly, due to customer interest in the services. Our 24/7 live chat is available to assist you on immediate basis.*****[/FONT]

[FONT=&quot]On Mon, Mar 21, 2016 at 1:51 AM, <[I][COLOR=maroon] VM[/COLOR][/I] > wrote: [/FONT]
[FONT=&quot]Hi,[/FONT]
[FONT=&quot]to include purevpn in the firewall exception I needthe ip address in format such as:[/FONT]
[FONT=&quot]IPv4 , IPV6, IPv4 & IPv6[/FONT]
[FONT=&quot]as well as subnet:[/FONT]
[FONT=&quot]IPv6 (max 128)[/FONT]
[FONT=&quot]IPv4 (max 32)[/FONT]
[FONT=&quot]dot IPv4 (255.255.255.0)[/FONT]
[FONT=&quot]But by doing so (list in exception) will only stop the notifications of attacks but the attacks will still occur.[/FONT]
[FONT=&quot]1- How do you plan to stop/block them?[/FONT]
[FONT=&quot]2- why are those coming up to my devices?[/FONT]
[FONT=&quot]3- Are my device at risk?[/FONT]
[FONT=&quot]4- Are those attacks from outside purevpn ?[/FONT]
[FONT=&quot]5- Are those atacks from purevpn?[/FONT]
[FONT=&quot]...I must say I was surprised as after I reported it to you online chat, attacks stopped for several hours until I disconnect and reconnect purevpn....VERY strange indeed![/FONT]
[FONT=&quot]Looking forward to hear from you before I start spending my free time...I am home bound due to spinal injury, so I have indeed plenty of time to chat online in forums, blogs and share my experience and thoughts on the matter....[/FONT]

[FONT=&quot]Regards[/FONT]

[I][COLOR=maroon][FONT=&quot]VM[/FONT][/COLOR][/I]
[FONT=&quot]PLEASE CONSIDER THE ENVIRONMENT BEFORE PRINTING THIS EMAIL.

NB: This email has been sent to the mentioned recipient(s) and its content and/or any attachment(s) is/are or may be confidential and subject to copyrights. This email is also subject to copyright. No part of it should be reproduced, adapted or communicated without the written consent of the copyright owner. Any personal information in this email must be handled in accordance with the Privacy Act 1988 (Cth).[/FONT]


[B][FONT=&quot]Sent:[/FONT][/B][FONT=&quot] Sunday, March 20, 2016 at 9:42 PM
[B]From:[/B] "PureVPN Support" <[URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=http%3A%2F%2Fenquiry%40purevpn.com"][COLOR=blue]enquiry@purevpn.com[/COLOR][/URL]>
[B]To:[/B] [I][COLOR=maroon]VM[/COLOR][/I]
[B]Subject:[/B] Re: Enquiry Form[/FONT]
[FONT=&quot]Hi, [/FONT]

[FONT=&quot]Thank you for contacting us, you are requested to add pure vpn in an exception of your antivirus, and share a result with us, so we may proceed it accordingly.[/FONT]

[FONT=&quot]Feel free to contact us for further assistance.[/FONT]

[FONT=&quot]Regards[/FONT]
[FONT=&quot]Andrew[/FONT]
[FONT=&quot]PureVPN Support Team[/FONT]

[FONT=&quot]***** We apologize for the delay, might cause in replying your email. We are experiencing an excessive load, unexpectedly, due to customer interest in the services. Our 24/7 live chat is available to assist you on immediate basis.*****[/FONT]

[FONT=&quot]On Sun, Mar 20, 2016 at 3:55 AM, PureVPN <[URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=http%3A%2F%2Fenquiry%40purevpn.com"][COLOR=blue]enquiry@purevpn.com[/COLOR][/URL]> wrote: [/FONT]
[FONT=&quot]Dear Admin,
Contact Form has been received.
[/FONT]
[FONT=&quot]Name:[/FONT]
[I][COLOR=maroon][FONT=&quot]VM[/FONT][/COLOR][/I]
[FONT=&quot]Email:[/FONT]
[I][COLOR=maroon][FONT=&quot]VM[/FONT][/COLOR][/I]
[FONT=&quot]Country:[/FONT]
[FONT=&quot]Australia[/FONT]
[FONT=&quot]Phone No:[/FONT]
[I][COLOR=maroon][FONT=&quot]VM[/FONT][/COLOR][/I]
[FONT=&quot]Feedback:[/FONT]
[FONT=&quot]Hi Guys since I have used your servicesI am getting some notification from my BULLGUARD interet protection saying I have "NETWORK ATTACK". Those attacks are listed as "single port attack"...last 7 attacks details : Attacker IP: a- 79.121.55.50 ([URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=http%3A%2F%2Fhost-79-121-55-50.kabelnet.hu"][COLOR=blue]host-79-121-55-50.kabelnet.hu[/COLOR][/URL]) b- 183.33.185.214 c- 88.15.131.249 ([URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=http%3A%2F%2F249.red-88-15-131.dynamicip.rima-tde.net"][COLOR=blue]249.red-88-15-131.dynamicip.rima-tde.net[/COLOR][/URL]) d- 60.2.76.50 e- 180.65.201.84 f- 83.45.194.244 ([URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=http%3A%2F%2F244.red-83-45-194.dynamicip.rima-tde.net"][COLOR=blue]244.red-83-45-194.dynamicip.rima-tde.net[/COLOR][/URL]) g- 91.122.44.238 ([URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=http%3A%2F%2Fppp91-122-44-238.pppoe.avangarddsl.ru"][COLOR=blue]ppp91-122-44-238.pppoe.avangarddsl.ru[/COLOR][/URL]) h- 41.182.53.244 ([URL="https://deref-mail.com/mail/client/dereferrer/?redirectUrl=http%3A%2F%2Fwhk-br02-41-182-53-244.ipb.na"][COLOR=blue]whk-br02-41-182-53-244.ipb.na[/COLOR][/URL]) Attacker MAC: a- 96-87-20-00-01-00 b- 96-87-20-00-01-00 c- 96-87-20-00-01-00 d- 96-87-20-00-01-00 e- 96-87-20-00-01-00 f- 96-87-20-00-01-00 g- 96-87-20-00-01-00 h- 96-87-20-00-01-00 it started with few a day to several hundreds a day now....doesn't matter if I change the "location". If I close pureVPN the attack stop! I did have thise with easy hide ip! Please explain what's going on! each attack has a different IP address but usually has the same MAC address for several attack then changing too.presently I have an attack notificationevery 4 to 5 seconds.[/FONT]
[FONT=&quot]

Country: Australia
IP Address: [I][COLOR=maroon]VM[/COLOR][/I]
Date: 19, Mar, 2016 - 11:04 pm[/FONT]
 
Last edited by a moderator:
Hi Guys, I am a self learner when it comes to pc stuff. I am not a novice but I am far far away from knowing much either. I presently need help about NETWORK ATTACKS as my antivirus stop hundreds each days since I started using Purevpn...
Hi guys,
I am turning to you because purevpn tech prodigees won't really help me about NETWORK ATTACKS happening when I use their VPN.
I have use Bullguard antivirus for the last 2 years without issue and with same settings. I was previously using easy-hide-ip as VPN but changed to pureVPN end of last year and that is when bullguard started to send me notification about “blocked NETWORK ATACKS”. Initially that was only few per days but it quickly evolve to several hundred a day.
If I do not use purevpn, I do not experience those “NETWORK ATTACKS”, but as soon as I connect…it s non stop these days, one attack after the other is being blocked.
I asked purevpn what was happening and initially was told those were not real attacks, but just over sensitive setting from my antivirus. I contacted Bullguard staff and after providing them with logs etc…they concluded the attacks being real but told me not to worry their software will continue to blocks them all! Re-assuring, isn't it ! Well NO!
Easiest solution? Ditch them. Get rid of PureVPN choose another service - there's plenty out there. Personally I recommend PrivateInternetAccess. I've been using it for about 2 years now without issue.

it ll take only one attack to succeed to do damages to devices in my network! So I am worried! 3 years ao we lost 3 laptop in the family within a week as damages were so important tech shop could not fix them…all this after a network intrusion was detected but ignored!
Sounds like those "techs" didn't know what they were doing then...a malware attack won't physically harm a device. So replacing 3 entire laptops was not necessary at all (let me guess, you bought new devices from the same shop that said they couldn't fix your old ones?). A simple reinstall would have solved that issue.

I didn't read the rest of your reply in regards to the email conversations you mentioned because it's so jumbled with broken BB code that it makes it difficult to read.
 
Holy wall of text...

I stopped about four lines into the code... I can't keep up with all of that right now. It sounds like you need to get rid of the VPN and, in addition, run some malware scans. Those attacks sound reminiscent of malware. I'm also presuming, from Carnage's response, that somebody said you had an infection and to replace the laptops, but I'm not sure.
 
Back
Top Bottom