Author Topic: Botnet:Blacklist  (Read 1992 times)

0 Members and 2 Guests are viewing this topic.

Offline Paul Blueberry

  • Jr. Member
  • **
  • Posts: 41
Botnet:Blacklist
« on: August 16, 2024, 03:25:14 PM »
Today I got this alert 5 times in an hour. The Process varies.
  • Threat name: Botnet:Blacklist.
  • URL: tcp://40.127.240.158:443 (VirusTotal links: IP, HTTPS)
  • Process: C:\Windows\System32\svchost.exe, C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe, C:\Windows\System32\taskhostw.exe
  • Detected by: Web Shield
  • Status: Connection aborted
How to get rid of this?



Visiting https://40.127.240.158 gives a certificate error. The certificate is not issued to this domain name, but to settings.data.microsoft.com. Pinging this pings several IP addresses. Sometimes it is the IP address in question. Examples (each line is the first line of the output of ping settings.data.microsoft.com):

Code: [Select]
Pinging settings-prod-neu-1.northeurope.cloudapp.azure.com [40.127.240.158] with 32 bytes of data:
Pinging settings-prod-neu-2.northeurope.cloudapp.azure.com [51.104.136.2] with 32 bytes of data:
Pinging settings-prod-neu-3.northeurope.cloudapp.azure.com [4.231.128.59] with 32 bytes of data:
« Last Edit: August 16, 2024, 08:18:02 PM by Paul Blueberry »

Offline chris...

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3040
Re: Botnet:Blacklist
« Reply #1 on: August 16, 2024, 11:33:00 PM »
It would appear that avast has recently detected a botnet threat on several (legitimate) Windows executables.
in french forum:
https://forum.avast.com/index.php?topic=328364.0
Try sending these executables to avast to check whether they are false positives:
https://www.avast.com/report-false-positive#pc

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: Botnet:Blacklist
« Reply #2 on: August 17, 2024, 12:22:30 AM »
This wouldn't be the first time that svchost.exe has been misused in this way.  Being a system file, commonly it will get through because of it being a signed system file.

I have to wonder what it is that is misusing the svchost.exe file in this way.

That said the IP given by the 'Paul Blueberry' is for Microsoft Azure in Dublin, Leinster, D02, Ireland. according to an IP check.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline chris...

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3040
Re: Botnet:Blacklist
« Reply #3 on: August 17, 2024, 02:08:12 PM »
.... The Process varies....
The alert isn't just for the svchost.exe process, but for loads of other Windows processes (devicecensus, taskhostx, ruximics, etc.), all more or less linked to MS telemetry and/or datalogging.
These false positives? (avast/avg) are the subject of numerous comments on Reddit.


I'm thinking more of a problem with the monthly Windows update last Tuesday, it wouldn't be the first time that avast has had problems just after the Windows update.
« Last Edit: August 17, 2024, 02:11:04 PM by chris... »

Offline Paul Blueberry

  • Jr. Member
  • **
  • Posts: 41
Re: Botnet:Blacklist
« Reply #4 on: August 17, 2024, 09:53:58 PM »
I got only those 5 alerts yesterday. Fortunately no more.

Anyhow, is there a way to filter them? Say, if Threat name = Botnet:Blacklist and URL = tcp://40.127.240.158:443, then don't alert me.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: Botnet:Blacklist
« Reply #5 on: August 18, 2024, 01:16:02 AM »
Adding an exclusion would leave you at risk (if this isn't legit) and possibly not what you are seeking. 
As  chris... mentions there are legit uses for svchost.exe connecting the internet, you could report it as a possible false positive.

However as I said that IP is located in Dublin, Leinster, D02, Ireland. It is assigned to the ISP Microsoft Azure.

Given the connection is initiated by svchost.exe would wonder why it is connecting to that IP, would you have any ms software that might be using Microsoft Azure  ?
Quote from: TCP protocol
What is TCP? Transmission Control Protocol (TCP) is a communications standard that enables application programs and computing devices to exchange messages over a network. It is designed to send packets across the internet and ensure the successful delivery of data and messages over networks.

Does that ring any bells e.g. delivery/exchange of data/messages.
Quote from: Azure
Azure, also known as Microsoft Azure, is a cloud computing platform and a suite of cloud services offered by Microsoft. It provides a wide range of cloud-based services and solutions that enable organizations to build, deploy, and manage applications and services through Microsoft's global network of data centers.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Paul Blueberry

  • Jr. Member
  • **
  • Posts: 41
Re: Botnet:Blacklist
« Reply #6 on: August 18, 2024, 03:10:33 PM »
Suppose, I accept the risk. Will I get an answer?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: Botnet:Blacklist
« Reply #7 on: August 18, 2024, 06:15:58 PM »
Suppose, I accept the risk. Will I get an answer? ?

An answer from whom ?
If your only action is to set an exclusion you won't get anything - have you reported it as a possible false positive as suggested by chris... reply #1 ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Paul Blueberry

  • Jr. Member
  • **
  • Posts: 41
Re: Botnet:Blacklist
« Reply #8 on: August 18, 2024, 10:41:02 PM »
I think, this means no, you won't answer it. Maybe someone else?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: Botnet:Blacklist
« Reply #9 on: August 19, 2024, 01:13:05 AM »
I think, this means no, you won't answer it. Maybe someone else?

You weren't specific on where you were hoping to get an answer, or if you had sought it out.

The answer is already in the topic, "Adding an exclusion would leave you at risk (if this isn't legit) and possibly not what you are seeking."
If 'you accept the risk' by adding an exclusion.


Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Paul Blueberry

  • Jr. Member
  • **
  • Posts: 41
Re: Botnet:Blacklist
« Reply #10 on: August 19, 2024, 05:33:20 PM »
Your post can be easily misunderstood. My question was "is there a way to filter them?". You answered "Adding an exclusion would leave you at risk", which sounds like you ignored my question, focused on the context of it (it's a good idea to filter them) and replied to that (it's a bad idea, don't do that, it's risky). You didn't answer, whether there is a way to filter them or not. My understanding of your answer was that you don't know, but you also don't care, whether they can be filtered or not, anyway I should accept, that it would be a bad idea to filter them, and since it's a bad idea, the question "how to filter?" can be ignored.

Subsequently, I stressed, that I don't want the question be ignored based on invalidating the context of it. You didn't want to answer again.

Then I turned to other people in a new topic, dedicated to this question only. They answered it, without digressing to related topics, like is it good or bad.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: Botnet:Blacklist
« Reply #11 on: August 19, 2024, 06:05:25 PM »
Adding an exclusion as mentioned is one way to exclude/filter, the other topic confirms that, within Avast there is no other way and it isn't without risk.

On a publicly available forum any advise given should always mention the risk involved of adding an exclusion.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline chris...

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3040
Re: Botnet:Blacklist
« Reply #12 on: August 19, 2024, 10:07:19 PM »
I think you've got the wrong end of the stick.
As I said on the other subject, Paul Blueberry wasn't so much waiting to know what to do, but how to do it, i.e. to obtain a FAQ on the procedure for placing a file under exclusion ... now that he knows the risks, he's free to do what he wants.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: Botnet:Blacklist
« Reply #13 on: August 19, 2024, 10:37:19 PM »
I have only responded to what has been directly asked (which hasn't always been clear) - and that still amounts to adding an exclusion - which isn't rocket science.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Paul Blueberry

  • Jr. Member
  • **
  • Posts: 41
Re: Botnet:Blacklist
« Reply #14 on: August 20, 2024, 04:03:35 PM »
No, you didn't answer directly. You ignored the question and digressed. Let's clarify. Saying "Adding an exclusion would leave you at risk" (link) doesn't mean to me, that there is a way to add exclusions (which you forget to mention, how, despite that was the question), when I'm asking whether there is a way to add exclusions.

It was very hard to communicate with you. Please, mind your English. Look carefully, what's been written.

As for the rocket science. I just looked at the bad place in the app, didn't find it there, and thought I'll ask it on the forum. Getting information from Google is sometimes easy, sometimes hard. I had the wrong term on mind. Google for Avast filter alerts gives you nothing, whereas searching for Avast exceptions directs you to the answer in the first result.

Anyway, thank you all for your help. It's sad, that Avast can't set the filters/rules I desired. Fortunately, the need for them ended soon.
« Last Edit: August 20, 2024, 04:16:38 PM by Paul Blueberry »