Media server connection being detected by Malwarebytes as a phish

For the last little while Malwarebytes has been detecting a possible phish with one of the URLs it keeps trying to access about five times a week. I wanted to double-check before whitelisting it to make sure that it was okay:

-Log Details-
Protection Event Date: 5/8/21
Protection Event Time: 3:55 AM
Log File: dddebadc-afeb-11eb-9b01-2cf05d3b2a32.json

-Software Information-
Version: 4.3.0.98
Components Version: 1.0.1273
Update Package Version: 1.0.40230
License: Premium

-System Information-
OS: Windows 10 (Build 19041.928)
CPU: x64
File System: NTFS
User: System

-Blocked Website Details-
Malicious Website: 1
, C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe, Blocked, -1, -1, 0.0.0, ,

-Log Details-
Protection Event Date: 5/8/21
Protection Event Time: 3:55 AM
Log File: dddebadc-afeb-11eb-9b01-2cf05d3b2a32.json

-Software Information-
Version: 4.3.0.98
Components Version: 1.0.1273
Update Package Version: 1.0.40230
License: Premium

-System Information-
OS: Windows 10 (Build 19041.928)
CPU: x64
File System: NTFS
User: System

-Blocked Website Details-
Malicious Website: 1
, C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe, Blocked, -1, -1, 0.0.0, ,

-Website Data-
Category: Phishing
Domain: ia902800.us.archive.org
IP Address: 207.241.232.100
Port: 443
Type: Outbound
File: C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe

Any confirmation or help would be appreciated.

Server Version#: 1.21.3.4346-3c1c83ba4
Player Version#: N/A

It seems Malwarebytes have generally blacklisted the Internet Archive as they are not selective about what pages they move to their archive (note from the malwarebytes forums). In consequence there appear to be some pages that were targeting users in phishing attacks.

From what I can find, some of the agents/sources used by Plex use information from archive.org for certain metadata (e.g. musicbrainz is linking/sourcing/storing their covers on coverartarchive.org which is part of archive.org).

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.