So I think I have (or had) malware on my network on some device.
I can see on my FreePBX phone server a pile of failed logins at 11:09 April 19.
Now when I logged into Winbox today and opened the terminal (I was going to do some VLAN stuff) I see it pops up and showed several failed login attempts for mikrotik router.
apr/19/2023 11:08:28 system,error,critical login failure for user admin from 192.1 68.88.34 via ftp apr/19/2023 11:08:29 system,error,critical login failure for user guest from 192.1 68.88.34 via ftp apr/19/2023 11:08:30 system,error,critical login failure for user root from 192.16 8.88.34 via ftp apr/19/2023 11:08:31 system,error,critical login failure for user admin from 192.1 68.88.34 via ftp apr/19/2023 11:08:33 system,error,critical login failure for user root from 192.16 8.88.34 via ftp apr/19/2023 11:08:34 system,error,critical login failure for user admin from 192.1 68.88.34 via ftp apr/19/2023 11:08:35 system,error,critical login failure for user admin from 192.1 68.88.34 via ftp apr/20/2023 10:16:47 system,error,critical login failure for user admin from 192.1 68.88.250 via winbox
Thank you.
EDIT: The last entry (IP address 192.168.88.250) was me I think, but all the 192.168.88.34 ftp attempts were not. And yes I have changed the admin account to a new named one, 'admin' is disabled now