Jump to content

Malwarebytes

False Positive on URL (?)


3 replies to this topic

#1
yarl

    New Member

  • Members
  • Pip
  • 16 posts
Hi MB,

Could you double check that www.ice2012.org is a dangerous site and should be blocked? MB is blocking it but the conference organizers have a different opinion.

Thanks!

E

#2
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,992 posts
  • Gender:Male
  • Location:Tyneside, UK
That domain resolves to 110.45.146.30, which we don't actually block.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
yarl

    New Member

  • Members
  • Pip
  • 16 posts
Would you mind checking again? It does resolve to 110.45.146.30 but the log below shows what MB does:

Thanks for your help!

2012/04/30 07:32:00 -0700 PW52 eb MESSAGE Executing scheduled scan: Quick Scan | Daily | Silent | -remove | -terminate | -reboot | -log
2012/04/30 07:32:00 -0700 PW52 eb MESSAGE Scheduled scan executed successfully
2012/04/30 08:16:31 -0700 PW52 eb IP-BLOCK 173.192.183.195 (Type: outgoing, Port: 53585, Process: firefox.exe)
2012/04/30 08:16:31 -0700 PW52 eb IP-BLOCK 173.192.183.195 (Type: outgoing, Port: 53592, Process: firefox.exe)
2012/04/30 08:16:39 -0700 PW52 eb IP-BLOCK 173.192.183.195 (Type: outgoing, Port: 53606, Process: firefox.exe)
2012/04/30 09:38:37 -0700 PW52 eb IP-BLOCK 173.192.183.196 (Type: outgoing, Port: 56483, Process: firefox.exe)
2012/04/30 09:38:37 -0700 PW52 eb IP-BLOCK 173.192.183.196 (Type: outgoing, Port: 56489, Process: firefox.exe)

#4
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,992 posts
  • Gender:Male
  • Location:Tyneside, UK
Can you e-mail me a Fiddler (www.fiddlertool.com) and Wireshark (www.wireshark.org) capture please?
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us