Author Topic: Cloudflare-dns Threat Secured  (Read 1124 times)

0 Members and 1 Guest are viewing this topic.

Offline edungarian

  • Newbie
  • *
  • Posts: 12
Cloudflare-dns Threat Secured
« on: February 06, 2024, 12:46:56 PM »
I just got 3 threat secured messages in a row in a matter of seconds that all say "Avast aborted connection on chrome.cloudflare-dns.com because it was infected with URL:Phishing" The URL for the threat was "http://chrome.cloudflare-dns.com/dns-query" and the process was listed as "C:\Program Files(x86)\Google\Chrome\Application\chrome.exe" The alert ID for the first one was "ef005ef34ff8/2024-02-06T11:33:06.381Z" Anyone know what that was all about? A false positive, or some random link on Youtube triggering it?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37598
  • Not a avast user
Re: Cloudflare-dns Threat Secured
« Reply #1 on: February 06, 2024, 04:20:48 PM »
Quote
A false positive, or some random link on Youtube triggering it?
Possible blacklisted ad`s


Offline edungarian

  • Newbie
  • *
  • Posts: 12
Re: Cloudflare-dns Threat Secured
« Reply #2 on: February 06, 2024, 10:33:01 PM »
That is what I would figure as well. I use an adblocker on that site so I don't see any ads at all, but I guess they still exist in the background process and that could have triggered the threat reaction.

Offline polonus

  • Avast √úberevangelist
  • Probably Bot
  • *****
  • Posts: 33927
  • malware fighter
Re: Cloudflare-dns Threat Secured
« Reply #3 on: February 07, 2024, 12:29:28 AM »
The IP of that link has been reported because of abuse three times: https://www.abuseipdb.com/check/162.159.61.3
Peculiar as this CloudFlare IP address comes whitelisted by abuseipdb dot com.

Moreover the site address kicks up a 400 error. So it cannot be reached, as it is a CloudFlare Reverse Proxy.

polonus
« Last Edit: February 08, 2024, 12:38:12 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!