Malwarebytes picked up bambulab traffic as RAT (Remote Access Tool)

Got an alert today from Malwarebytes when I opened the Bambulab app on my windows desktop.

It said that traffic being sent to 173.234.28.82 from bambulab was blocked as it is potentially RAT traffic (Remote Access Tool).

Port was 3478

By “app” you mean Bambu Studio? Well, the A/V is not wrong. Not saying the traffic to/from BL cloud is malicious, but it is remote access to a program on your computer, which in turn has access to whatever is allowed by current OS security settings for that program/process. And even though Studio is open source, the network agent (“plugin”) BL uses for communications with cloud/printer is not, and that agent also runs in the security context of Studio.

-Max

Yes, Bambu Studio.

If you google the IP address, it seems to be sketchy.

This will be much to do about nothing yet make one ugly thread as well.

Looks like a server collocation facility: 173.234.28.82 | Chicago, AS63018, & VPN Not Detected - IPinfo.io

Port 3478 is commonly used for STUN traffic, which is a simple protocol used to establish communication through a NAT router. It’s explicitly listed in BL’s wiki as one of the ports they use:

Most likely it’s just doing its routine phoning home to Bambu’s US servers. I wouldn’t worry about it.

2 Likes

Yeah, they already know everything about you. :rofl:

1 Like