Skip to content

Malwarebytes reports Trojan every 4 hours #574

Description

@Compunologist

Malwarebytes reports a Trojan with dnscrypt-proxy trying to reach two IP numbers. This seems to occur every 4 hours.

Trojan_Screenshot 2024-09-08 100108
Website blocked due to Trojan

Detection History_Screenshot 2024-09-07 232154
Detection occurs every 4 hours

Malwarebytes Website Blocked Report 2024-09-07 231828.txt
ba26ca1a-6d5e-11ef-ab1f-dc4546c03275.json

Simple DNSCrypt v0.7.1 (x64) [dnscrypt-proxy 2.0.42]
Malwarebytes v5.1.9.124
OS: Windows 11 Pro (Build 22631.4037) v23H2

Activity

  1. jedisct1 commented on Sep 8, 2024

    @jedisct1
    Member

    Why didn't you report this to Malwarebytes instead?

  2. Compunologist commented on Sep 13, 2024

    @Compunologist
    Author

    I created a support ticket at Malwarebytes and they responded that after having reviewed the IP's it was confirmed there were no active threats remaining and the block has been removed. These IP's are part of the public DNSCrypt resolvers list and apparently at some point the IP's may have contained malware prior to being used by DNSCrypt.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions