# Malwarebytes flagging Plex as Trojan?

**URL:** <https://forums.plex.tv/t/malwarebytes-flagging-plex-as-trojan/848093>\
**Category:** Plex Media Server\
**Tags:** server-docker\
**Created:** [July 22, 2023, 2:09pm UTC](https://forums.plex.tv/t/malwarebytes-flagging-plex-as-trojan/848093 "2023-07-22T14:09:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![RxBrad](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/rxbrad/32/204436_2.png) [@RxBrad](https://forums.plex.tv/u/RxBrad)\
**Post date:** [July 22, 2023, 2:09pm UTC](https://forums.plex.tv/t/malwarebytes-flagging-plex-as-trojan/848093/1 "2023-07-22T14:09:40Z")

</div>

Server Version#: 1.32.5.7328 (via official Docker)  
Player Version#: Plex Web Version 4.111.1

Is MalwareBytes having a bout of false positives with Plex this morning, or do I have a busy weekend ahead of me?

![image](https://global.discourse-cdn.com/plex/original/4X/3/3/0/330f69808ea7e22980ef7ed907a32ded8735ff5c.png)

Some additional – potentially related info… I tunnel Plex through Packetriot due to CGNAT on T-Mobile Home Internet. ([via their tutorial](https://packetriot.com/tutorials/posts/setting-up-plex/))

This morning, Packetriot’s US East servers were having issues with TCP tunneling, so I reconfigured my tunnel to use their US South server. I did not see any of these Trojan Malwarebytes alerts prior to my issues with Packetriot this morning. The screenshot-redacted IP address being flagged every time I view my Plex Home tab is either my T-Mobile IP, or the Packetriot public-facing server IP.

---

<div class="post-metadata">

**Author:** ![RxBrad](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/rxbrad/32/204436_2.png) [@RxBrad](https://forums.plex.tv/u/RxBrad)\
**Post date:** [July 22, 2023, 6:02pm UTC](https://forums.plex.tv/t/malwarebytes-flagging-plex-as-trojan/848093/2 "2023-07-22T18:02:52Z")

</div>

So, I think the issue was that my current T-Mobile CGNAT’ted IP address was on some naughty lists.

Since I’m tunnelling my connection out to Packetriot, I just went ahead and disabled remote access, so the responsible 172.58.x.x IP stopped getting parsed into the \*.plex.direct URLs. That seems to have fixed my issue.

![image](https://global.discourse-cdn.com/plex/original/4X/4/5/0/4503a851326a56eafd0a6276c74bb455b30af4af.png)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/plex/original/3X/2/a/2acb9765406f63293d357b4ec509ec39aa28f2ad.png) [@system](https://forums.plex.tv/u/system)\
**Post date:** [October 20, 2023, 6:03pm UTC](https://forums.plex.tv/t/malwarebytes-flagging-plex-as-trojan/848093/3 "2023-10-20T18:03:18Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
