Jump to content

Malwarebytes

False Positive Website


1 reply to this topic

#1
marzie

    New Member

  • Members
  • Pip
  • 1 posts
cghub.com is being tagged as a positive by Malwarebytes.
80.77.95.51 is what Malwarebytes listed when attempting to access the site.

I believe this to be a false positive, as I was able to access it with Malwarebytes on my computer just last week.

#2
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,991 posts
  • Gender:Male
  • Location:Tyneside, UK
80.77.95.50 and 80.77.95.51 belong to cghub.com itself, and their NS1 and NS2 nameservers (previously lived at 184.173.238.10, the same IP cghub.com itself lived at until July 7th) at the time of writing this, which itself is unusual (sites should never be using their NS server IPs to house their sites, that's just bad practice).

An initial check, shows they switched to these IPs, and changed NS on July 7th from soft-com.biz (which is why you're only recently seeing it being blocked), which means it is likely they've only just moved to this IP at the same time as the NS was changed. Puzzled as to why they chose this range, given its history.

Never the less, this will be unblocked on the next update.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us