Malwarebytes flagging Thumbsnap as a malicious site
Malwarebytes flagging Thumbsnap as a malicious site
Author
Discussion

Funk

Original Poster:

27,322 posts

232 months

Wednesday 20th February 2019
quotequote all
FYI, Malwarebytes has started blocking all connections to Thumbsnap as malicious:


tirolo_

280 posts

132 months

Wednesday 20th February 2019
quotequote all
does Malwarebytes provide you with any info as of why it believes it's malware? Also, are you able to share the actual blocked urls?

Bullett

11,131 posts

207 months

Wednesday 20th February 2019
quotequote all
Came to report this.

It just says;

Trojan
thumbsnap.com
104.31.7.178
Port 59976 (but various)
Outbound connection
Chrome.exe

Ozone

3,072 posts

210 months

Wednesday 20th February 2019
quotequote all
Virus total shows that Malwarebyres says Thumbsnap URL is clean but your ip address doesn't match theirs with 104.31.7.178

https://www.virustotal.com/#/url/1c8265e24c57b794b...

Edited by Ozone on Wednesday 20th February 22:21

tirolo_

280 posts

132 months

Thursday 21st February 2019
quotequote all
Ozone said:
Virus total shows that Malwarebyres says Thumbsnap URL is clean but your ip address doesn't match theirs with 104.31.7.178

https://www.virustotal.com/#/url/1c8265e24c57b794b...

Edited by Ozone on Wednesday 20th February 22:21
dns resolution happens on the client side so we would need to figure why your machine is resolving thumbsnap.com to 104.31.7.178 whereas virustotal resolves it to 104.31.6.178... I would guess it's based on load/availability zone balance? Depending on the route out to the server your request is chosen to take it would eventually hit the same ip as virustotal.... one option would be to force it through hosts file to test it out... let me know how it goes...

TonyRPH

13,460 posts

191 months

Thursday 21st February 2019
quotequote all
The IP address thing is harmless.

104.31.7.178 and 104.31.6.178 are CloudFlare IPs.

CloudFlare provide CDN (content delivery network) services amongst other things.

This is perfectly normal.


MrOnTheRopes

1,573 posts

269 months

Thursday 21st February 2019
quotequote all
Yeah I noticed the same. Started a few days ago. Even popped up when I hit 'reply' to this topic.


Funk

Original Poster:

27,322 posts

232 months

Saturday 23rd February 2019
quotequote all
TonyRPH said:
The IP address thing is harmless.

104.31.7.178 and 104.31.6.178 are CloudFlare IPs.

CloudFlare provide CDN (content delivery network) services amongst other things.

This is perfectly normal.
Yep. Cloudflare's 1.1.1.1 is my default DNS.

The irony is Thumbsnap is st anyway - any site that watermarks embedded pics can fk off; the problem is that all PH pics from Thumbsnap now just show as a broken link.


Fore Left

1,601 posts

205 months

Saturday 23rd February 2019
quotequote all
Same here. I assumed thumbsnap is OK so added an exclusion to Malwarebytes.

aeropilot

39,682 posts

250 months

Monday 25th February 2019
quotequote all
MrOnTheRopes said:
Yeah I noticed the same. Started a few days ago. Even popped up when I hit 'reply' to this topic.
I get the same as well, as you say, started around middle of last week.


wolfracesonic

8,842 posts

150 months

Monday 25th February 2019
quotequote all
Fore Left said:
Same here. I assumed thumbsnap is OK so added an exclusion to Malwarebytes.
I'm having problems with Thumbsnap and Malwarebytes; what exclusion do I add, is it pistonheads.com, thumbsnap.com or something else? Help appreciatedsmile

MrOnTheRopes

1,573 posts

269 months

Monday 25th February 2019
quotequote all
wolfracesonic said:
Fore Left said:
Same here. I assumed thumbsnap is OK so added an exclusion to Malwarebytes.
I'm having problems with Thumbsnap and Malwarebytes; what exclusion do I add, is it pistonheads.com, thumbsnap.com or something else? Help appreciatedsmile
Just thumbsnap.com will do it smile

wolfracesonic

8,842 posts

150 months

Monday 25th February 2019
quotequote all
thumbup