Jump to content

Malwarebytes

IP False NEGATIVE?


3 replies to this topic

#1
centralkong

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 101 posts
  • Gender:Male
  • Location:A mason in Archades
Hi to all,

Today I mistyped an address on Google Chrome,
www.localstrike.com/foros/
, when I meant the same address but with .com.ar.

(Luckily) MBAM blocked the access attempt displaying the usual notification bubble. But I did not stay there, and I went to hosts-file.net just to know what I was going to deal with.

And localstrike. com (208.73.210.27) resolved back to "parkinglot.informa tion.com" (208.73.210.27), but this domain's reverse IP gives the very previous address (208.73.210.26).

Maybe MBAM should directly block the whole IP range?

Greetings,
DominumDS

P/S: Oh God, you really should... RobTex logs for .26 stink with domain names that are very suspicious...

#2
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,233 posts
  • Gender:Male
  • Location:Tyneside, UK
The entire range is already blocked :(
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
Blottedisk

    Trusted Advisor

  • Trusted Advisors
  • Pip
  • 32 posts
  • Gender:Male
  • Location:Argentina
Centralkong? Itīs a small world! Itīs good to see you here.


MysteryFCM, Iīm part of LocalStrike.com.ar staff, and really appretiate you look after blocking the IPīs range that belongs to these non-legit servers in order to protect our members. It seems the IP Protection Module is working fine :(


Best regards

#4
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,233 posts
  • Gender:Male
  • Location:Tyneside, UK
My pleasure :(
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us