URL:Phishing-false positives

WeChat communication was intercepted by Avast, resulting in inability to receive information
http://14.215.158.100/mmtls/00006ca6

Hi HVM,

See detection: https://www.virustotal.com/gui/url/6119e326831e37cc01c17d86f8c87691374a100037bd89d757918011e9a7dcf2/detection
Consider: https://www.abuseipdb.com/check/14.215.158.100 MITRE Attacks taking place from that IP address,
info credits go to Pondus. :wink:
Read also here: https://hybrid-analysis.com/sample/53968792f45be660089633c1a28e81289fb942bf6586d012b79cf963ce3b57f9?environmentId=100

Try to take this issue up with the China Telecom Group → https://www.shodan.io/host/14.215.158.100
https://ip.cha127.com/14.215.158.100.html (site uses Beijing DNS, pol)

Also consider: https://webbkoll.dataskydd.net/en/results?url=http%3A%2F%2Fip.cha127.com (24 hrs scan result).

Wait for a final verdict from an avast team member, because they are the only ones to come and unblock.

We here are just volunteers with relevant knowledge in the field of website security and website error-hunting.
Hope your chat-service will soon continue and return to you again :slight_smile: wish you loads of success.

Cached page view: https://aw-snap.info/file-viewer/?protocol=secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=W3AuXmh8MTI3Ll5dbWAxNC4yMTUuMTU4LjEwMC5odG1s~enc
See also: https://sitereport.netcraft.com/?url=+https%3A%2F%2Fip.cha127.com%2F14.215.158.100.html

最好的祝福

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)