Wednesday, November 2, 2016

Blocking viruses port in mikrotik



/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1-2 comment="Socks Des Troie, Death"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=31 comment="Agent 31, Hacker's Paradise"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=37 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=41 comment="Deep Throat"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=58 comment="DM Setup"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=69-70 comment="W32.Evala.Worm"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=79 comment="Firehotcker"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=81 comment="Beagle.S"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=85-90 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=99 comment="Common Port for phishing scam sites"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=113 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=119 comment="Happy99"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=121 comment="Jammer Killah"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=129 comment="Password Generator Protocol"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=135-139 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=146 comment="Infector 1.3"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=382 comment="W32.Rotor"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=420 comment="W32.kibuv.b"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=421 comment="tcp Wrappers"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=445 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=456 comment="Hacker's Paradise"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=530 comment="W32.kibuv.worm"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=531 comment="Rasmin"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=555 comment="Stealth Spy, Phaze, 7-11 Trojan"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=559 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=587 comment="Sober worm Variants"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=593 comment="W.32.Sasser worm"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=666 comment="Attack FTP"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=777-778 comment="BackDoor.Netcrack.B"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=880 comment="Common Port for phishing scam sites"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=901-902 comment="Backdoor.Devil"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=911 comment="Dark Shadow"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=999-1001 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1011-1015 comment="Doly Trojan"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1024-1025 comment="Backdoor.lingosky"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1033-1034 comment="NetSpy"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1042 comment="Bla"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1045 comment="Rasmin"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1080-1081 comment="Backdoor.Zagaban"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1111 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1218 comment="Backdoor.Sazo"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1234 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1243 comment="Sub Seven"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1245 comment="VooDoo Doll"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1269 comment="Maverick's Matrix"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1394 comment="GoFriller, Backdoor G-1"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1433 comment="w32.spybot.ofn"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1492 comment="FTP99CMP"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1505 comment="FunkProxy "/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1509 comment="Psyber Streaming server"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1533-1534 comment="Backdoor.Miffice"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1534 comment="Bizex.Worm"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1600 comment="Shivka-Burka"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1604 comment="ICA Browser"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1751 comment="Loxbot.d"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1772 comment="Backdoor.NetControle"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1807 comment="SpySender"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1863 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1981 comment="Shockrave"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=1999-2005 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2023 comment="Ripper"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2041 comment="W32.korgo.a"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2080 comment="Backdoor.TJServ"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2090 comment="Backdoor.Expjan"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2115 comment="Bugs"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2140 comment="Deep Throat"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2155 comment="Illusion Mailer"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2283 comment="Dumaru.Y"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2322 comment="backdoor.shellbot"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2333-2335 comment="backdoor.shellbot, Eyeveg.worm.c"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2414 comment="vbs.shania"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2556 comment="Beagle.N"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2565 comment="Striker"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2583 comment="WinCrash"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2716 comment="The Prayer 1.2 -1.3"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2721 comment="Phase Zero"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2745 comment="Beagle.J"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2766 comment="W32.hllw.deadhat.b"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2801 comment="Phineas Phucker"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=2989 comment="Backdoor.Brador.A"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3024 comment="WinCrash"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3028 comment="Backdoor.Wortbot"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3030 comment="W32.Mytob.cz@mm"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3067 comment="W32.korgo.a"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3127-3198 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3256 comment="W32.HLLW.Dax"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3306 comment="Backdoor.Nemog.D"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3332 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3385 comment="w32.Mytob.kp@MM"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3410 comment="W32.mockbot.a.worm"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3456 comment="Backdoor.Fearic"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3459 comment="Eclipse 2000"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3547 comment="Backdoor.Amitis.B"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3700 comment="Portal of Doom"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3737 comment="Backdoor.helios"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=3791 comment="Eclypse"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4001 comment="Backdoor.OptixPro.13.C"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4092 comment="WinCrash"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4128 comment="Backdoor.rcserv"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4242 comment="Backdoor.Nemog.D"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4300 comment="Backdoor.smokodoor"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4387 comment="Phatbot"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4444 comment="More than 3 known worms and trojans use this port"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4512 comment="W32.mytob.db"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4567 comment="File Nail"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4590 comment="ICQ Trojan"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4646 comment="Backdoor.Nemog.D"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4661 comment="Backdoor.Nemog.D"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4751 comment="Beagle.U"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4820 comment="Backdoor.tuxder"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4888 comment="W32.Opanki"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4899 comment="W32.RaHack"/ip firewall filter add chain=viruses protocol= tcp action=drop dst-port=4903 comment="Common Port for phishing scam sites"

No comments: