MalwareBytes is blocking an attempted outbound connection several times a day coming from an IIS worker process on my web server. The server is running Windows Server 2012 R2.
This is being categorized as RiskWare, and I've been unable to find out much information at all about this domain/IP on the web.
Does anybody have any information about why MalwareBytes blocks this? What is the particular risk and where does this outbound request typically originate from?
Thanks in advance.
Protection Event Date: 9/30/19
Protection Event Time: 1:41 PM
Log File: 8971163a-e3a9-11e9-9874-005056b9b9ae.json
Components Version: 1.0.627
Update Package Version: 1.0.12709
OS: Windows Server 2012 R2
File System: NTFS
-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0
IP Address: 22.214.171.124