andyseubert Posted September 17, 2021 ID:1480365 Share Posted September 17, 2021 IP address: 199.233.255.65 Excerpt of the protection log 09/17/21 " 08:52:14.139" 41478406 12e4 267c INFO MwacControllerImpl mb::mwaccontrollerimpl::MwacControllerImpl::InvokeBlockNotificationCallback "mwaccontrollerimplhelper.cpp" 2639 "Block notification callback: url='www.eci-nw.com', ipAddr='199.233.255.65', processPath='C:\Program Files (x86)\Google\Chrome\Application\chrome.exe', category='Trojan'" 09/17/21 " 08:52:14.139" 41478406 12e4 267c INFO MwacControllerImpl mb::mwaccontrollerimpl::MwacControllerImpl::InvokeBlockNotificationCallback "mwaccontrollerimplhelper.cpp" 2640 "AppDetectionNotification=F, BlockNotification=T" 09/17/21 " 08:52:14.153" 41478421 12e4 267c INFO MWACControllerCOM CMWACController::WebsiteBlockedNotificationCallback "mwaccontroller.cpp" 1424 "Malicious Website Protection, domainblocklist, 199.233.255.65, www.eci-nw.com, 443, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" 09/17/21 " 08:52:14.154" 41478421 12e4 267c INFO CleanControllerImpl mb::cleanctlrimpl::whitelist::WhiteListManager::LogWhiteListStatus "whitelistmanager.cpp" 302 "White list status: IpDomain '199.233.255.65 www.eci-nw.com' 77A7CF9D77983EA6372638FB87C38E66 3F6605EDF25A902A5C9EA9A4ED47EF9A => None:Unknown" 09/17/21 " 08:52:14.155" 41478421 12e4 267c INFO MwacLib NetworkEventHandler::connectionRedirected "networkeventhandler.cpp" 260 "Connection redirected: ProcessId=16336 (C:\Program Files (x86)\Google\Chrome\Application\chrome.exe) RemoteAddress=199.233.255.65:443 LocalAddress=0.0.0.0:7084 Protocol=TCP" 09/17/21 " 08:52:14.157" 41478421 12e4 25e4 INFO MwacControllerImpl mb::mwaccontrollerimpl::MwacControllerImpl::GetDetectedFileDetails "mwaccontrollerimplhelper.cpp" 2726 "White list disposition (0) for 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe'" Hostname/URL: www.eci-nw.com Link to post Share on other sites More sharing options...
andyseubert Posted September 17, 2021 Author ID:1480366 Share Posted September 17, 2021 I also ran the URL through virustotal nothing bad detected hxxps://www.virustotal.com/gui/url/c38a847792a6cf3bbe5f21ceda8e30d98772aa755e8c4c4d7fc45f012d6f1e28/detection Link to post Share on other sites More sharing options...
Staff Solution Zynthesist Posted September 17, 2021 Staff Solution ID:1480369 Share Posted September 17, 2021 Hello, Domain appears cleaned up so block will be removed. Link to post Share on other sites More sharing options...
Recommended Posts