Jump to content

Recommended Posts


I recently had a pop-up appear while browsing that requested my login credentials to my browser (192.168.xxx).  The curious thing is that the pop-up was a carbon copy of my router's administrator login page, right down to the make and model number and color scheme.  Everything was the same, except for the site address, which belonged to "pix1.payswithservers", and was attached with "Main_Login.asp" at the end (I use an Asus router).

Googling this did not yield many results.

I ran multiple AVs including Malwarebytes, all of which came back negative.  My router firmware has been up to date.  DNS settings for my router were unchanged (automatic), and remote management via WAN was turned off.

I've encountered pop-ups before, all of which were more or less similar.  This pop-up however was different because of the aforementioned details.

Have malicious pop-ups been known to phish for login credentials to routers?  And so specifically at that.  I asked around and it seems router make / model information is available to the public, though these particular pop-ups don't seem to be typical (I have been unable to find anyone with a case similar to mine).

Any help would be much appreciated.

Link to post
Share on other sites

It's a Phish site. 

All you can do is make sure you changed the default Router password, disable management from the Internet POV and make sure the Router password is a Strong Password.

If you had the fully qualified URL, it can be submitted to be blocked by Malwarebytes' products.  This is done in;  Newest IP or URL Threats after reading  READ ME: Purpose of this forum

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.