Avast WEBforum

Other => Viruses and worms => Topic started by: polonus on November 19, 2023, 03:07:39 PM

Title: Why this search.exe IP is flagged by AbuseIPDB?
Post by: polonus on November 19, 2023, 03:07:39 PM
See: https://www.abuseipdb.com/check/204.79.197.200  was found in their database.
Also see: https://www.shodan.io/host/204.79.197.200

See also: https://cleantalk.org/blacklists/204.79.197.200 Detected as spam source (and other attacks).

Low risk according to crowdsourced content-> https://www.virustotal.com/gui/url/7225ba05f003e03d4b126246e348ce92080a6dd25f3b507fc27a082f38c1ce2f
4 vendors give the IP address as malicious.

File analysis gives it the all green here: https://www.virustotal.com/gui/file/c987ec90685c19d24d0fa92a03e3d8675089fe1b14f16eb4228f9062ea75fc40?nocache=1

Also see: https://www.virustotal.com/gui/url/d1bc71de7ce1902d402517eb9da782086ffe5c1230b314ad83befba9f4d8e699

IP is being abused for port-probing, phishing, router scanning and bot activity,

But insecure connection to: -https://a-0001.a-msedge.net/ -> (index):1540 crbug/1173575, non-JS module files deprecated.
Site cannot be reached ....

polonus