This is oneview on multiple client computers (businesses), and they are running Malwarebytes Nebula Agent.
What we keep getting up is:
As requested, we’re notifying you of a detection event on your Malwarebytes account <removed>. Here are the details:
OS release name: Microsoft Windows 11 Pro
OS platform: Windows
Category: Website
Type: OutboundConnection
Location: eu.rollserver.xyz(157.90.33.71:443)
Action taken: Blocked
Scan time: November 16th 2022, 17:13:22 UTC
Report time: November 16th 2022, 17:13:24 UTC
Threat name: Malvertising
Endpoint name: <removed>
Endpoint IP address/CIDR: <removed>
Public endpoint IP: <removed>
Group name: Default Group
Policy name: Default Policy
Below is for the same computer:
However the alerts seem to have died down in the last few days, unknown for what reason. I think this must be related to something that the users are surfing on in Chrome.
Today we just have 3 alerts so far, so it is no big deal. I think we can close this case as something that was intermittent.