Jump to content

111.67.21.187 being blocked


JasonManfred
Go to solution Solved by JPopovic,

Recommended Posts

I represent bunburymotel.com.au which is being blocked by Malwarebytes due to "a trojan". We're not blacklisted by anyone else I'm aware of and I don't know what it's detecting as "a trojan". Log details below, basically the same whether HTTP or HTTPS except for port, different browsers don't matter, different computers same result too. Server IP is a pretty standard Aussie web hosting one (https://hostopia.com.au/).

-Log Details-
Protection Event Date: 12/23/20
Protection Event Time: 12:55 PM

-Software Information-
Version: 4.2.3.96
Components Version: 1.0.1122
Update Package Version: 1.0.34647
License: Premium

-System Information-
OS: Windows 10 (Build 19041.685)
CPU: x64
File System: NTFS
User: System

-Blocked Website Details-
Malicious Website: 1
, C:\Program Files\Mozilla Firefox\firefox.exe, Blocked, -1, -1, 0.0.0, ,

-Website Data-
Category: Trojan
Domain:
IP Address: 111.67.21.187
Port: 443
Type: Outbound
File: C:\Program Files\Mozilla Firefox\firefox.exe

 

Link to post
Share on other sites

  • Staff
  • Solution

Hello,

There are some potentially malicious files related to this IP address.

One of them:

 http://111.67.21.187/~cancalc/order/invoice_74645.jar 

VT detection:

https://www.virustotal.com/gui/file/caed7828ba15c4c9b0d90c1e7f0d308c26ee32a17433e2492da349eafe7ee400/detection

 

Link to another one:

 http://111.67.21.187/~cancalc/order/un1.jar 

VT detection:

https://www.virustotal.com/gui/file/46336d11c0a510e9565055772daf977a18e4179a7ec744dfc6d8a6f2094b0cb0/detection

 

One more:

 http://111.67.21.187/~cancalc/order/invoice_34315R18.jar 

VirusTotal detection:

https://www.virustotal.com/gui/file/c65d3ff20b9a591b41d0b575e70167ebd8963e003f619652660d0fa7adf84c9d/detection

 

Unfortunately, we still wouldn't be able to remove the block from this IP address.

One IP address can have several different domains on it. Even if your domain is not malicious, many other can make some trouble and that is the reason we block complete IP address.

Thank you for your understanding!

Link to post
Share on other sites

  • Dashke locked this topic
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.