Jump to content

Malwarebytes

False Positive IP 128.204.195.105


5 replies to this topic

#1
LucyI

    New Member

  • Members
  • Pip
  • 2 posts
The domain is www.markhamstra.com and I believe it's safe.

#2
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,992 posts
  • Gender:Male
  • Location:Tyneside, UK
It is indeed safe, unfortunately however, it's so far, the only "safe" site on the entire range, that I've come across. The rest of them, are an entirely different story and so far, there's been no response from the host.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
LucyI

    New Member

  • Members
  • Pip
  • 2 posts
Thank you so much for taking the time to investigate this! Can you give details on what you've found on the other domains?

#4
markhamstra

    New Member

  • Members
  • Pip
  • 1 posts
I recently (ie. last weekend) moved my site from AltusHost (which in retrospect was a really bad choice) to a new VPS hosted by Inception Hosting, which is a company my server guys are very happy with and have been hosting with for ages.

Looking back I can totally get that the AltusHost server would have been blacklisted (and them not responding sounds pretty accurate too), but are you saying the server we migrated to is just as bad? Couldn't it be that the server migration away from Altus somehow confused the IP blacklisting feature where it kept the record assigned to my domain name and auto-blacklisted the new IP as well as the DNS changes kicked in saturday/sunday?

#5
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,992 posts
  • Gender:Male
  • Location:Tyneside, UK

View Postmarkhamstra, on 21 February 2012 - 08:46 AM, said:

I recently (ie. last weekend) moved my site from AltusHost (which in retrospect was a really bad choice) to a new VPS hosted by Inception Hosting, which is a company my server guys are very happy with and have been hosting with for ages.

Looking back I can totally get that the AltusHost server would have been blacklisted (and them not responding sounds pretty accurate too), but are you saying the server we migrated to is just as bad? Couldn't it be that the server migration away from Altus somehow confused the IP blacklisting feature where it kept the record assigned to my domain name and auto-blacklisted the new IP as well as the DNS changes kicked in saturday/sunday?

The blacklisting isn't automatic (your domain was never the cause of any blocks), but sadly yes, Shiryo is just as bad.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#6
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,992 posts
  • Gender:Male
  • Location:Tyneside, UK

View PostLucyI, on 21 February 2012 - 08:21 AM, said:

Thank you so much for taking the time to investigate this! Can you give details on what you've found on the other domains?

The major problems and cause of the block, has been exploits, drive-by's and trojans (minor issues have been counterfeit sites, but these wouldn't usually cause a block unless a more major issue was found)
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us