Hello!
At irregular intervals, Malwarebytes blocks outbound powershell connections in category 'Riskware' going to 'imonews.net', with the IP-address: 172.67.190.202 on port: 443.
It also blocks outbound powershell connections in category 'Riskware' going to the IP-address: 135.181.231.130 on port: 80.
This has been going on for a few months now, but neither Malwarebytes nor Symantec Endpoint Protection (14.3 RU9) find anything when doing a full scan of the computer. Both apps are updated to the latest version.
At one time, Symantec Endpoint Protection also terminated a powershell process with the risk name: 'CL.Downloader!gen96'.
I'm on a Windows 11 23H2 PC, and I've tried to disable powershell as outlined here: https://www.thewindowsclub.com/how-to-disable-powershell-windows-10, but it did not fix the problem. FYI, I've enabled powershell in the OS again.
Can someone please help me look into and hopefully solve this?