Jump to content

85.118.59.189 / oreliance.com


GPL-Nico
Go to solution Solved by JPopovic,

Recommended Posts

Hello,

The ORELIANCE.COM site, which we administer, is identified as potentially dangerous "TROJAN" in the "Malwarebytes" solution.
 
85.118.59.189
hxxps://oreliance.com
 
 
======
Malwarebytes
www.malwarebytes.com

-Détails du journal-
Date de l'événement de protection: 23/08/2022
Heure de l'événement de protection: 02:03
Fichier journal: 713583f2-22c2-11ed-a2b9-080027e6e559.json

-Informations du logiciel-
Version: 4.5.13.208
Version de composants: 1.0.1740
Version de pack de mise à jour: 1.0.59001
Licence: Essai

-Informations système-
Système d'exploitation: Windows 10 (Build 17763.437)
Processeur: x64
Système de fichiers: NTFS
Utilisateur: System

-Détails du site Web bloqué-
Site Web malveillant: 1
, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe, Bloqué, -1, -1, 0.0.0, ,

-Données du site Web-
Catégorie: Cheval de Troie
Domaine: oreliance.com
Adresse IP: 85.118.59.189
Port : 443
Type: En sortie
Fichier: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(end)
===
 

After much research we have not identified any reason.

The site is up to date.


We use the following security solutions :


CLAMAV

RKHUNTER

iThemes Security https://fr.wordpress.org/plugins/better-wp-security/


We also searched with :

https://fr.wordpress.org/plugins/gotmls/

https://fr.wordpress.org/plugins/wordfence/


VIrustotal : (Result) https://www.virustotal.com/gui/url/4b23649ae431777339bd8bf46954bf1e44b0ab579def2901d22ecf2e79603a8b


So it seems to us that this is possibly a false positive.

Could you help us please ?

Export.txt

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.