Malaware bytes keeps blocking something weird...


Recommended Posts

Malware bytes has told me it has blocked this twice now anyone know what it is? :

IP-BLOCK 83.128.74.152 (Type: incoming, Port: 10167, Process: skype.exe)

EDIT: I also find it especially weird the IP is in the netherlands.... 152-074-128-083.dynamic.caiway.nlnew-window.gifdns-ok.gif Country : Netherlands nl.png

I think it's this:

http://www.iss.net/security_center/reference/vuln/PortalOfDoom.htm

that's a known port it uses. I wasn't aware it could/would get in through Skype, though. Not 100% sure but I'd guess that's why Malwarebytes doesn't like it.

Skype uses a bunch of really nasty techniques and some that it relies on - like the P2P directory, my guess would be it's that.

Or someone on your friends / contacts has contracted something nasty and is bombing that particular port.

so how is port 10167 even open to your machine? Are you not behind a nat router? Or did the process open up that port via UPnP on your router? Is it tcp or udp?

https://support.skype.com/en-us/faq/FA148/Which-ports-need-to-be-open-to-use-Skype

What port do you have setup for skype to use? See the above link.

I get this ALL the time.

Taken from the Malwarebytes website

Which was also the first result in a google search for "Malwarebytes skype"

Skype is a Peer-to-Peer (P2P) application. This means that it connects to a wide variety of IP addresses dynamically in order to establish a connection from one point to another.

Because of this, Skype may sometimes connect to IP addresses that are also known for hosting malicious content such as malware. For this reason, Malwarebytes Anti-Malware may block such connections, though this should not affect your usage of Skype or the quality of communication through Skype itself.

If the notifications occur frequently and you wish to disable them while still allowing Malwarebytes Anti-Malware to continue protecting your PC by blocking the malicious websites, then you may do the following:

  1. Open Malwarebytes Anti-Malware and access the Protection tab
  2. Uncheck the box next to Show tooltip balloon when malicious website is blocked.
  3. Click the Exit button

http://helpdesk.malw...are-block-skype

"I just let it set the ports I didn't change anything.."

Well then it prob is using that port.. And then opened on your router via UPnP? Do you have that enabled?

No unsolicited traffic should even get to your machine from behind a nat router. So either the traffic is an answer to your initiated traffic, or you have the port open via a forward or a UPnP some software opened it up. for example not setting a port on skype to use, and letting it use UpnP.

WW seems to have the answer to what the traffic is -- not some old trojan/backdoor.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Just for anyone reading, AdGuard (the free, standalone MV3 extension) is quite good now, a direct competitor to uBlock Origin Lite and much more built-out than it.
    • Microsoft Edge 149.0.4022.62 by Razvan Serea Microsoft Edge is a super fast and secure web browser from Microsoft. It works on almost any device, including PCs, iPhones and Androids. It keeps you safe online, protects your privacy, and lets you browse the web quickly. You can even use it on all your devices and keep your browsing history and favorites synced up. Built on the same technology as Chrome, Microsoft Edge has additional built-in features like Startup boost and Sleeping tabs, which boost your browsing experience with world class performance and speed that are optimized to work best with Windows. Microsoft Edge security and privacy features such as Microsoft Defender SmartScreen, Password Monitor, InPrivate search, and Kids Mode help keep you and your loved ones protected and secure online. Microsoft Edge has features to keep both you and your family protected. Enable content filters and access activity reports with your Microsoft Family Safety account and experience a kid-friendly web with Kids Mode. The new Microsoft Edge is now compatible with your favorite extensions, so it’s easy to personalize your browsing experience. Download: Microsoft Edge (64-bit) | 193.0 MB (Freeware) Download: Microsoft Edge (32-bit) | 170.0 MB Download: Microsoft Edge (ARM64) | 188.0 MB View: Microsoft Edge Website | Release History Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Yeah, when I saw that, I wanted to find the nearest nose. You can't find a good nose these days when you need one.
    • Anthropic launches Claude Fable 5, a state-of-the-art AI model that beats OpenAI's GPT-5.5 by Pradeep Viswanathan Back in April, Anthropic announced Claude Mythos Preview, a frontier model with state-of-the-art coding capabilities. Due to the cybersecurity implications that would occur due to the availability of such a powerful model, Anthropic made it available to only a select set of companies around the world. The company's plan was to prepare appropriate guardrails before releasing such a powerful model to everyone. Now, after nearly two months, Anthropic announced Claude Fable 5, its most capable AI model yet for general users. The company also announced Claude Mythos 5, the same underlying model as Fable 5, but with safeguards lifted, making it more suitable for selected cybersecurity and biology use cases. Claude Fable 5 sits a tier above its Opus models and it beats most other generally available models across areas including software engineering, knowledge work, vision, scientific research, and long-running autonomous tasks. To prevent model misuse, when Claude Fable 5 detects certain requests related to cybersecurity, biology, chemistry, or model distillation, the request will be routed to the Claude Opus 4.8 model. Anthropic claims that these safeguards trigger in less than 5% of sessions on average. However, for large organizations working on critical software, Claude Mythos 5 can be availed through Project Glasswing. Later, Anthropic has plans to expand access through a broader trusted access program. As you can notice in the benchmarks above, Fable 5 and Mythos 5 are state-of-the-art on most key AI benchmarks and they are well ahead of OpenAI's frontier model, GPT-5.5. For example, Fable 5 is the new state-of-the-art model for vision tasks. Also, Mythos 5 has the strongest cybersecurity capabilities of any model in the world. Claude Fable 5 and Claude Mythos 5 are priced at $10 per million input tokens and $50 per million output tokens, which is less than half the price of Claude Mythos Preview. Another big change is that Anthropic is making a change to the way they handle business customer data for both Fable 5 and Mythos 5 models. The company will now require 30-day retention for all traffic on both first- and third-party surfaces. Anthropic promises that it won't use the data to train Claude models, instead it will use it against complex and novel attacks. Claude Fable 5 is available today on the Claude API and consumption-based Enterprise plans. It is also included at no extra cost for Pro, Max, Team, and seat-based Enterprise customers from today through June 22. After that, users on those plans will need usage credits to continue using Fable 5, unless Anthropic extends the included access window based on capacity. Developers can access Fable 5 through the Claude API using the claude-fable-5 model name.
  • Recent Achievements

    • Week One Done
      rubentuben8 earned a badge
      Week One Done
    • Week One Done
      ARaclen earned a badge
      Week One Done
    • One Year In
      jojodbn earned a badge
      One Year In
    • One Month Later
      jojodbn earned a badge
      One Month Later
    • Week One Done
      jojodbn earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      525
    2. 2
      PsYcHoKiLLa
      232
    3. 3
      +Edouard
      124
    4. 4
      ATLien_0
      88
    5. 5
      Steven P.
      83
  • Tell a friend

    Love Neowin? Tell a friend!