Jump to content

Malwarebytes

IP protection detecting infection from evilterritory.com/Evilrtcw2.com


18 replies to this topic

#1
derrick90

    New Member

  • Members
  • Pip
  • 7 posts
I was just browsing Youtube and got a "Malwarebytes' Anti-Malware IP Protection: Infection detected: 209.44.99.178" notice.

I'm not sure if Youtube has anything to do with it since I googled the IP and found out it belongs to Evilrtcw2.com and also evilterritory.com and warcraft-source.com.

Is this a threat or just a common false positive?

Thanks for your support.

#2
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
It looks like a legit IP, but I'm not an expert. See here
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#3
derrick90

    New Member

  • Members
  • Pip
  • 7 posts

View Postswagger, on Sep 4 2009, 11:32 PM, said:

It looks like a legit IP, but I'm not an expert. See here

Well, it's not listed on hosts-file.net's database.

Do you (or anyone else viewing this thread) get the same message when you visit evilterritory.com or any of the other sites that I mentioned?

Also, how reliable is hosts-file.net as a threat identifier?

#4
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
It isn't blocked on 1.41 beta which may further back the evidence for a false positive as there is a bug in 1.40 that blocks legitimate IPs.

I've seen most of the experts refer to http://hosts-file.net when dealing with IPs since this new feature has been introduced. I think with that being said, it's pretty reliable :(
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#5
derrick90

    New Member

  • Members
  • Pip
  • 7 posts

View Postswagger, on Sep 4 2009, 11:47 PM, said:

It isn't blocked on 1.41 beta which may further back the evidence for a false positive as there is a bug in 1.40 that blocks legitimate IPs.

I've seen most of the experts refer to <a href="http://hosts-file.net" target="_blank">http://hosts-file.net</a> when dealing with IPs since this new feature has been introduced. I think with that being said, it's pretty reliable :(

Thanks for your insight but I'd like an expert (you said you are not one) to answer my question, no offense intended.

And thanks for the info about hosts-file.net

#6
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
No offense taken at all. You have your rights :( I hope one helps you soon
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#7
derrick90

    New Member

  • Members
  • Pip
  • 7 posts
A little update: IP Protection just detected 200.98.197.7. This site is listed on hosts-file.net and is considered to be threatening.

The only reason that I found it necessary to make this thread is because I don't usually get warnings like this regularly from MBAM. I am getting these warnings while browsing sites that I commonly visit. It's just at this moment that I am getting an unreasonable amount of warnings which makes me suspect something harmful. I don't have a p2p program open so I know it's not a false positive from some random person.

Any ideas as to what might be going on?

#8
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina
You're right, according to hosts-file.net it does seem to be malicious. I tried pinging the IP from my desktop running version 1.41 beta and I was able to reach the IP. This could be due to the fact that the definitions for the beta don't include this IP... We aren't allowed to update from the beta because it's still being tested.

Do you have any IM software? What are the sites that you browse if you don't mind me asking? Maybe there's an ad on the page that is trying to load from that IP.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#9
mountaintree16

    music is <3

  • Honorary Members
  • PipPipPipPipPipPip
  • 6,559 posts
  • Gender:Not Telling
  • Location:USA

Quote

@ Derrick90

I might be mistaken, but, I think that P2P's could potentially cause this to happen even if they aren't actually open. Do you have any P2P programs?


#10
derrick90

    New Member

  • Members
  • Pip
  • 7 posts

View Postswagger, on Sep 5 2009, 02:23 AM, said:

You're right, according to hosts-file.net it does seem to be malicious. I tried pinging the IP from my desktop running version 1.41 beta and I was able to reach the IP. This could be due to the fact that the definitions for the beta don't include this IP... We aren't allowed to update from the beta because it's still being tested.

Do you have any IM software? What are the sites that you browse if you don't mind me asking? Maybe there's an ad on the page that is trying to load from that IP.

When you say "IM software" you mean instant messaging right? If so, then no, although I have previously installed a few of them, which are now uninstalled (properly I hope).

The sites that I have been browsing include youtube, google, yahoo and other similar sites. Just general popular sites like this. I actually got the 200.98.197.7 warning while I was using the google search engine... These warnings may have had nothing to do with the sites that I was browsing, I just listed some of them as I thought it might be relevant.

#11
derrick90

    New Member

  • Members
  • Pip
  • 7 posts
Yes, I use uTorrent and I have never had any problems using utorrent and MBAM in sync. I usually turn off IP protection while using utorrent to avoid the constant false positives.

I have never encountered this problem while utorrent was inactive.

#12
mountaintree16

    music is <3

  • Honorary Members
  • PipPipPipPipPipPip
  • 6,559 posts
  • Gender:Not Telling
  • Location:USA

Quote

@ Derrick90

Hmm I'm out of ideas then. Hopefully an expert on this can jump in here and hopefully will be able to tell you whats going on or what might be going on.


#13
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
Apologies for taking so long to notice this thread. To answer your questions;

209.44.99.178

This IP is on a Netelligent IP range, who are known for housing criminals, which is why it is blocked.

200.98.197.7

The IP itself seems fine, I can't identify any malicious activity thus far, however, the rest of the range does presently house malicious activity, because of this, the range itself was blocked, rather than just the IP's.

/edit

For clarity by the way, hpHosts is actually run by me.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#14
derrick90

    New Member

  • Members
  • Pip
  • 7 posts

View PostMysteryFCM, on Sep 5 2009, 03:12 AM, said:

Apologies for taking so long to notice this thread. To answer your questions;

209.44.99.178

This IP is on a Netelligent IP range, who are known for housing criminals, which is why it is blocked.

200.98.197.7

The IP itself seems fine, I can't identify any malicious activity thus far, however, the rest of the range does presently house malicious activity, because of this, the range itself was blocked, rather than just the IP's.

/edit

For clarity by the way, hpHosts is actually run by me.

Thanks for the info.

The "attacks" seem to have subsided for now. I will update this thread if I encounter any more threats.

Thanks again.

#15
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
No problem :(
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#16
swagger

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 887 posts
  • Gender:Male
  • Location:South Carolina

View PostMysteryFCM, on Sep 4 2009, 10:12 PM, said:

For clarity by the way, hpHosts is actually run by me.

;) I did not know this, but it makes perfect sense now. Thanks for a very informative site and helpful HOSTS file :D Thanks for helping out derrick90 also, I'm sure you've eased his concerns.
Desktop ----- AMD Athlon 3700+ (2.64Ghz), 2GB DDR 400, ASUS A8N-SLI Premium, 500GB HD, Windows XP Pro SP3, Avira Antivir Personal, MBAM Pro
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal

#17
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
No problem ;)
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#18
Emma

    New Member

  • Members
  • Pip
  • 1 posts
I have a question and I'm not sure this is the place to post it -- but when I am browsing and I get a warning that Malwarebytes has identified an infection - do they quarantine or disinfect automatically? Each time I get this warning I immediately do a full scan and no malicious objects are detected?

#19
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
It's not actually an infection per-se, it's a known malicious IP, so it will actually prevent the site from infecting you to begin with.

For details, please see;

http://www.malwareby...showtopic=21076
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us