Jump to content

IP Block - False Positive?


rpstone

Recommended Posts

I have recently had a website blocked due to its being "potentially malicious". This occurs when I try to open the site manually via IE, both on my laptop and desktop. My McAfee Total Protection lists this as "secure" and a scan by MBAM is clear. The log is as follows:

2013/05/09 09:49:07 +1000 PETER-PC Peter IP-BLOCK 195.42.103.57 (Type: outgoing, Port: 63162, Process: iexplore.exe)

The website is "movavi.com", a software company which I have used for many years for my video editing. I also note that I have had the Pro vesrion of MBAM on my laptop for some time without this recent notification.

I have conducted the "start/deveoper" scan, with the following log.

Is there a problem with this site or can I report it as a false/positive and filter it from my MBAM?

Regards

Malwarebytes Anti-Malware (PRO) 1.75.0.1300

www.malwarebytes.org

Database version: v2013.05.07.09

Windows 7 Service Pack 1 x86 NTFS

Internet Explorer 9.0.8112.16421

Peter :: PETER-PC [administrator]

Protection: Enabled

9/05/2013 10:04:40 AM

mbam-log-2013-05-09 (10-04-40).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 229825

Time elapsed: 8 minute(s), 45 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Link to post
Share on other sites

  • 4 weeks later...

I experienced the same blocking of the website as the original poster. Why has no one responded to this post? I've just emailed the information below:

When I try to go to a well known software site called:

http://www.movavi.com/,

a message appears that says Malwarebytes is blocking access to a malicious website with an IP address of

195.42.103.57

I just ran movavi.com through several online scanners and they say it's clean:

http://www.urlvoid.com/scan/movavi.com/

http://sitecheck.sucuri.net/results/movavi.com

http://scanurl.net/?u=movavi.com&uesb=Check+This+URL#results

Is this a false positive and if so, why hasn't it been corrected in several weeks. From what I can gather, reviews for this software around the web aren't that good, but I would just like to know why the IP address for the url is being blockedby MBAM and no other program,

Link to post
Share on other sites

Sorry for missing this.

It's not an F/P, no. Whilst this specific site may be perfectly fine, the same can not be said for any other IP on the entire /24. However, as there's no open cases on this IP at present, I'll get an exception made for it.

Link to post
Share on other sites

Sorry for missing this. It's not an F/P, no. Whilst this specific site may be perfectly fine, the same can not be said for any other IP on the entire /24

I'm not sure what you mean by "entire 24". Are you referring to 24 numbers after 195.42.103.xx that might be associated with Movavi.com?

Link to post
Share on other sites

  • Staff

It's not about movavi.com but the /24 that it uses which is being blocked. Sadly legitimate sites suffer when other sites on the same /24 do dirty things :( MysteryFCM has said he will make an exception for this site. Give him a reminder if you see no change in 24-48 hours.

Link to post
Share on other sites

It's not about movavi.com but the /24 that it uses which is being blocked. Sadly legitimate sites suffer when other sites on the same /24 do dirty things :( MysteryFCM has said he will make an exception for this site. Give him a reminder if you see no change in 24-48 hours.

It's the /24 I didn't understand and had to read this to try to make head or tail out of it:

http://www.ripe.net/internet-coordination/press-centre/understanding-ip-addressing

I'm pretty good with hardware and security, but this is slightly above my pay grade right now.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.