Jump to content

Malwarebytes

False positive? at Ancestry.co.uk


3 replies to this topic

#1
simonpg

    New Member

  • Members
  • Pip
  • 2 posts
Ancestry is the largest genealogy database company on the internet and entirely respectable. They digitize data from The National Archives of England and the USA.

When I am logged in to "www.ancestry.co.uk", and do a search, and then when the search list is displayed, and then select "View images", the malicious warning pops up with blocked IP: 308.73.210.27

The image still is displayed, but I then cannot navigate forward or backward between the preceding or following images, presumably because of this blocking.

Simon

#2
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,233 posts
  • Gender:Male
  • Location:Tyneside, UK
Sorry for taking so long to reply.

308.* is not a valid IP. Could you double check it please, and if possible, provide the direct URL that this issue occurs on (i.e. the direct URL to the search you are using, with the search term included)
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
simonpg

    New Member

  • Members
  • Pip
  • 2 posts
308.* is not a valid IP.

Sorry, typo mistake , should be 208.73.210.27

A screen shot is attached.

'ancestry.co.uk' is part of the very large 'ancestry.com' group. Such is the current interest in genealogy and online records this company has recently floated on the Nasdaq :-
Ancestry.com

It is a well established company since the mid 1990's and used by most people tracing their family history in USA or Europe.

The pages causing me problems are subscription access only requiring login, and only when images are displayed.

Thanks
Simon

:)

Attached Files



#4
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,233 posts
  • Gender:Male
  • Location:Tyneside, UK
This is definately not an F/P. There's absolutely no reason they should be contacting information.com servers;

http://hosts-file.net/?s=208.73.210.27

It appears, from your screenshot, to be being caused by the following domain;

http://hosts-file.ne...creativedev.com

Given this IP is a parking server, I can see no reason why they should be accessing it.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us