Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Tripped website firewall- is someone attacking through my computer?


  • Please log in to reply
7 replies to this topic

#1 cactus37

cactus37

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:22 AM

Posted 18 December 2023 - 07:20 PM

Hi there,

I was browsing the web and I visited a certain website. (A rescue non-profit for wildcats. I like big cats. Anyways.) I clicked on a link on the page- not an external link, but supposedly a link to another page on the same site- and I was redirected to an error screen from Sucuri Website Firewall (screenshot attached.) It said that the firewall had detected an obfuscated attack payload coming from my device.

On my word, I was not trying to attack the website. Just browsing. So what could cause my computer to trip a website's firewall like this? Is it possible that someone was using my device through a backdoor to orchestrate an attack? Or is this more likely a false positive? I haven't used the internet on that computer since getting this message. Any advice appreciated.

Im using Windows 11 Home, v. 22H2
OS build 22621.2283, 64-bit
HP OMEN 16-b0xxx
My browser was Firefox 118.0 (unfortunately I can't remember if I was using my VPN at the time. Trying to confirm as we speak by comparing ip addresses)

If needed, I can post the full address of the blocked webpage

Thank you!

Attached Files


Edited by cactus37, 18 December 2023 - 07:26 PM.


BC AdBot (Login to Remove)

 


#2 0lds0d

0lds0d

  •  Avatar image
  • Members
  • 4,645 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:11:22 PM

Posted 18 December 2023 - 07:59 PM

No attack from your device - firewall just blocked an attempt from that url going to your device.

 

Best advice - first clean the browser cache, then run the Windows Disk cleaner,  and then scan with your resident antivirus/antimalware scanners. You should be clean.


un2yad-6.png


#3 Porthos

Porthos

  •  Avatar image
  • Members
  • 1,093 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:22 PM

Posted 18 December 2023 - 09:27 PM

 

I can't remember if I was using my VPN at the time.

A VPN can cause this at times.



#4 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 4,816 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:06:22 AM

Posted 19 December 2023 - 04:19 AM

Please update Mozilla Firefox to version 121.0.

Good luck! :)

Edited by midimusicman79, 19 December 2023 - 02:09 PM.

Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), SUMo Free. I have 28.5 Years of PC Experience.


#5 cactus37

cactus37
  • Topic Starter

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:22 AM

Posted 04 January 2024 - 03:54 PM

firewall just blocked an attempt from that url going to your device.


Thank you all so far. Just to be clear, I don't have Securi Website Firewall running on my device- the block came from the website itself. Why would the site stop my computer from accessing that url?

Edited by cactus37, 04 January 2024 - 04:00 PM.


#6 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 4,816 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:06:22 AM

Posted 05 January 2024 - 04:30 AM

You are welcome, cactus37! :)

It would be interesting if you please could upload the full address of the blocked webpage to VirusTotal and share the resulting link here.

Good luck! :)

Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), SUMo Free. I have 28.5 Years of PC Experience.


#7 cactus37

cactus37
  • Topic Starter

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:22 AM

Posted 20 February 2024 - 01:32 PM

Thanks for your advice earlier. (Took me a while to get around to fixing it- life happened.) I cleared the cache, ran Disk Cleanup, and scanned with Malwarebytes free, then Windows Defender. (I did a full scan, then an offline scan.) I also updated everything- Defender, Malwarebytes, Windows Update- since the internet on the macchine had been turned off for several months.

I also checked the url of the blocked page and linked the results here. The page itself (1st link) came up clean. Interestingly though, when I checked the address of the main domain (bigcatrescue.org), it was flagged under 'Relations' as communicating with malicious files (2nd link). Should this have any bearing on the results of the first page?

https://www.virustotal.com/gui/url/ba06e85a751a4f85f1301a93bc17daa47a5ffab6d567fb65dbfaf2cf368835ad

https://www.virustotal.com/gui/domain/bigcatrescue.org/relations

As for the scans, they all came up clean. However, I read the log for the offline scan and errors occured- the scan couldn't open a registry hive.( I don't know if that would affect its capacity to detect something.) There are also some events in my Windows security log that look concering, odd behavior coming from my Desktop Windows Manager, and a CMOS checksum error that's coincided with all this.

TLDR- the scans all say it's fine, but there are still concerning things going on. I don't know if I'm looking at normal behavior or not. I'm wondering if I should start a new thread to address some of these issues.

#8 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 4,816 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:06:22 AM

Posted 20 February 2024 - 08:23 PM

You are welcome, cactus37! :)

You can start a new topic in the Virus, Trojan, Spyware, and Malware Removal Help Forum, for assistance by the Malware Response Team.

And to do that, please follow the instructions in the Malware Removal and Log Section Preparation Guide.

Good luck! :)

Edited by midimusicman79, 20 February 2024 - 08:25 PM.

Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 4 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis CPHOE (DI), SUMo Free. I have 28.5 Years of PC Experience.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users