BODIS Posted March 31, 2021 ID:1448068 Share Posted March 31, 2021 Malwarebytes is currently blocking millions of domains hosted on IP 199.59.242.153 , for reason 'Trojan'. Can you urgently look into, and resolve this matter and advise how to prevent this from happening again. Link to post Share on other sites More sharing options...
BODIS Posted March 31, 2021 Author ID:1448071 Share Posted March 31, 2021 If you have any questions, please do feel to contact me directly. I would like to thank you in advance for your assistance in this matter and hope we can resolve this issue soon. Link to post Share on other sites More sharing options...
Staff Solution Dashke Posted March 31, 2021 Staff Solution ID:1448072 Share Posted March 31, 2021 The IP has been added because of the brute-force attacks. You can also check the reports here - https://www.abuseipdb.com/check/199.59.242.153 Link to post Share on other sites More sharing options...
BODIS Posted March 31, 2021 Author ID:1448079 Share Posted March 31, 2021 Hi Dashke, Thankyou for your reply. As a domain monetization provider, we are partnered with only the largest and most trust worthy advertising partners in the world. The CPC ads we show and as can be seen on PropertyTraders.co.uk are the same ads you see when you perform a search in the most popular search engine, in fact if Malware bytes advertises using CPC advertising, we also serve your ads. The domains on our platform are typically expired and tens of thousands of new domains are added to our system each day, the majority of these domains are expired, meaning they were previously owned by an individual or business and the previous owners failed to renew the domains. I can only imagine that the false positives detected and otherwise reported come from previous domain usage cases . I would be happy to provide lists of tens of thousands of other domains if you wish, to help you better understand our business. Scans using VirusTotal etc. also do not highlight any issues. Would could we change on PropetyTraders.co.uk to become compliant? Link to post Share on other sites More sharing options...
BODIS Posted March 31, 2021 Author ID:1448081 Share Posted March 31, 2021 Addressing the reports on: https://www.abuseipdb.com/check/199.59.242.153 Of the 9 cases reported this month out of the millions of domains we monetise this month. Let me address a few: keznews.com, this is reported twice. When you visit this page, you will note that the domain is advertised as for sale. slkjfdf.net, doesnt resolve 1 report is a false positive, highlighting the block by Malware Bytes 1 lists, visiting samsung.com. They are an advertiser. 1 calling us "another coronavirus infected low life scum." The rest seem to be people clicking every possible option and submitting these complaints with no evidence given. We are happy to work with Malware Bytes if you show us examples and we will immediately take action. Link to post Share on other sites More sharing options...
BODIS Posted March 31, 2021 Author ID:1448084 Share Posted March 31, 2021 Please find attached a few more domains which show a false positive. I can provide tens of thousands, even hundreds of thousands of domains if you wish, but they will all show a similar landing page. few examples.txt Link to post Share on other sites More sharing options...
BODIS Posted March 31, 2021 Author ID:1448086 Share Posted March 31, 2021 Also, as we ourselves don't host the ads (our advertising partners do), there is simply no way we can be responsible for the brute force attacks. @Dashke If you wish I can put you in touch with our developer and dev op team? Then any checks you wish to carry out, you are welcome to do so. How does that sound? Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now