Jump to content

False positive?


SeanO

Recommended Posts

Thanks - I had read this before posting and understood it as this...

I find that significant parts of the website appear blocked, suggesting that MW regards the site itself as infected.

I would be surprised if that site had an issue lasting about a week so wondered if there is sometihng else for me to explore....

Different IP lookup searches gave me 'contradictory' results - one said the IP address was 'blocked / private', the other said 'local'

I want to be fairly ceetain before telling my children to ignore any warning message.

Link to post
Share on other sites

The IP being blocked is actually 94.75.216.155. 192.168.*.* IP's are internal non-routable (NRIP) IP's (something a website should NEVER be calling).

The 94.75.216.155 IP is on a Leaseweb range that is known for malware, which is why it is blocked;

http://hosts-file.net/?s=94.75.216.155

Specifically, exploits;

http://hosts-file.net/?s=94.75.216.155&view=matches

Sadly, I couldn't track down which part of the site was loading the malicious content as the IP notitification only appeared once, suggesting it only loads the content once per IP (don't have access to proxies or test machines at present).

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.