Jump to content

Why are these sites being blocked?


dtsolutions

Recommended Posts


Is there a reason why Malwarebytes is blocking these 2 sites, or is it some mistake and they should be unblocked?

-Website Data-
Category: Trojan
Domain: nj-a.thetadata.us
IP Address: 131.226.212.246
Port: 0
(No malicious items detected)
Type: Outbound
File: System


-Website Data-
Category: Trojan
Domain: nj-b.thetadata.us
IP Address: 131.226.212.246
Port: 0
(No malicious items detected)
Type: Outbound
File: System
 

Link to post
Share on other sites

  • Staff
37 minutes ago, dtsolutions said:


Is there a reason why Malwarebytes is blocking these 2 sites, or is it some mistake and they should be unblocked?

-Website Data-
Category: Trojan
Domain: nj-a.thetadata.us
IP Address: 131.226.212.246
Port: 0
(No malicious items detected)
Type: Outbound
File: System


-Website Data-
Category: Trojan
Domain: nj-b.thetadata.us
IP Address: 131.226.212.246
Port: 0
(No malicious items detected)
Type: Outbound
File: System
 

Hello- this is a valid IP block based on the following data from VirusTotal: VirusTotal - IP address - 131.226.212.246

This IPV4 is used as a CnC by DEIMOS. Deimos implant, initially reported in 2020, is a sophisticated form of malware under continuous development. It operates as a remote access tool and employs multiple layers of complex obfuscation and encryption techniques to evade detection. Its advanced defensive measures encompass convincing lure files and digitally signed installation executables, making analysis and identification challenging. Deimos serves for initial access, persistence, and C2 functions, making it a potent tool for various tasks requiring remote access.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.