MalwareBytes rejects IP 89.248.168.197






The file name is connected to you. I don’t know how to do further research. IF the site 89.248.168.197 is connected to you and is OK I can let Malwarebytes accept it.
(I uploaded Trojan_004 twice - sorry)
None of the Tags seemed appropriate

Looks more like one of your friends that tries to stream from you?

Looks like a scanner of some sort.

IP Address Information

Analysis Date 2022-04-22 15:51:10
Elapsed Time 7 seconds
IP Address 89[.]248[.]168[.]197
Reverse DNS scanner.openportstats.com
ASN Owner IP Volume inc
ISP IP Volume inc
Continent Europe
City Amsterdam
Region North Holland

I’d just block the IP on your router if it doesn’t belong to one of your users.

Yep, port scanner.

Really common actually.

Check the IP with your users though but I get these scanning 32400 daily, mostly Chinese IPs. Sometimes Russian.

I no longer use 32400 as the WAN port number. Doesn’t help with security but stops your server showing up as a Plex server on the usual 32400 WAN. That way, if there is a Plex exploit, your server won’t be on the hackers lists as likely as if you just used the well known 32400.

Anyone using Plex with remote enabled should have software like MWB in place - that is also what I use (premium). I don’t block these IPs in my router as the list would be massive. Whack a mole.

Thanks, but happens to users who aren’t catching/blocking thjis?

They will never see the port scans.

Unless an exploit is found in Plex, nothing will happen.

However, exploits do happen in commercial software so being aware is the first step in security.