473,606 Members | 3,113 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

Microsoft site 131.107.115.28 blocked as known malware site, why?

I was building a "hello world" application in ASP.NET and during the
construction of the same it attempted to access the above site, owned
by Microsoft. Webroot Spy Sweeper, which resides on my system,
blocked the connection and lists the site as a known malware site.

Why is this and has anybody else had this happen? Ordinarily Webroot
is very reliable.

RL

WHOIS Search Results
Your WHOIS Search Results

131.107.115.28
Record Type: IP Address

OrgName: Microsoft Corp
OrgID: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US

NetRange: 131.107.0.0 - 131.107.255.255
CIDR: 131.107.0.0/16
NetName: MICROSOFT
NetHandle: NET-131-107-0-0-1
Parent: NET-131-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.MSFT.NET
NameServer: NS5.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
Comment:
RegDate: 1988-11-11
Updated: 2004-12-09

Aug 26 '08 #1
7 2386
On Tue, 26 Aug 2008 03:32:29 -0700 (PDT), raylopez99 wrote:
I was building a "hello world" application in ASP.NET and during the
construction of the same it attempted to access the above site, owned
by Microsoft. Webroot Spy Sweeper, which resides on my system,
blocked the connection and lists the site as a known malware site.

Why is this and has anybody else had this happen? Ordinarily Webroot
is very reliable.

RL

WHOIS Search Results
Your WHOIS Search Results

131.107.115.28
Record Type: IP Address

OrgName: Microsoft Corp
OrgID: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US

NetRange: 131.107.0.0 - 131.107.255.255
CIDR: 131.107.0.0/16
NetName: MICROSOFT
NetHandle: NET-131-107-0-0-1
Parent: NET-131-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.MSFT.NET
NameServer: NS5.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
Comment:
RegDate: 1988-11-11
Updated: 2004-12-09
I believe that site has something to do with the search function in
Windows.
IOW when you do a Find it connects to that site for some reason.

I'd block the pig if I were you....

--
Moshe Goldfarb
Collector of soaps from around the globe.
Please visit The Hall of Linux Idiots:
http://linuxidiots.blogspot.com/
Aug 26 '08 #2
In comp.os.linux.a dvocacy, raylopez99
<ra********@yah oo.com>
wrote
on Tue, 26 Aug 2008 03:32:29 -0700 (PDT)
<5e************ *************** *******@r66g200 0hsg.googlegrou ps.com>:
I was building a "hello world" application in ASP.NET and during the
construction of the same it attempted to access the above site, owned
by Microsoft. Webroot Spy Sweeper, which resides on my system,
blocked the connection and lists the site as a known malware site.

Why is this and has anybody else had this happen? Ordinarily Webroot
is very reliable.

RL

WHOIS Search Results
Your WHOIS Search Results

131.107.115.28
Record Type: IP Address

OrgName: Microsoft Corp
OrgID: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US

NetRange: 131.107.0.0 - 131.107.255.255
CIDR: 131.107.0.0/16
NetName: MICROSOFT
NetHandle: NET-131-107-0-0-1
Parent: NET-131-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.MSFT.NET
NameServer: NS5.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
Comment:
RegDate: 1988-11-11
Updated: 2004-12-09
[1] Someone got cute and submitted this address to Webroot.
Talk to Webroot.

[2] Someone got *real* cute and infected crl.microsoft.c om.
Talk to Microsoft.

--
#191, ew****@earthlin k.net
Linux makes one use one's mind.
Windows just messes with one's head.
** Posted from http://www.teranews.com **
Aug 26 '08 #3
In comp.os.linux.a dvocacy, Moshe Goldfarb.
<br***********@ gmail.com>
wrote
on Tue, 26 Aug 2008 10:39:07 -0400
<u5************ *************** **@40tude.net>:
On Tue, 26 Aug 2008 03:32:29 -0700 (PDT), raylopez99 wrote:
>I was building a "hello world" application in ASP.NET and during the
construction of the same it attempted to access the above site, owned
by Microsoft. Webroot Spy Sweeper, which resides on my system,
blocked the connection and lists the site as a known malware site.

Why is this and has anybody else had this happen? Ordinarily Webroot
is very reliable.

RL

WHOIS Search Results
Your WHOIS Search Results

131.107.115. 28
Record Type: IP Address

OrgName: Microsoft Corp
OrgID: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US

NetRange: 131.107.0.0 - 131.107.255.255
CIDR: 131.107.0.0/16
NetName: MICROSOFT
NetHandle: NET-131-107-0-0-1
Parent: NET-131-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.MSFT.NET
NameServer: NS5.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
Comment:
RegDate: 1988-11-11
Updated: 2004-12-09

I believe that site has something to do with the search function in
Windows.
IOW when you do a Find it connects to that site for some reason.

I'd block the pig if I were you....
The given address backresolves to crl.microsoft.c om.
The web server is active, though directory listing access
is denied, and none of index.html nor index.htm
nor index.asp exist. index.aspx generates a server error;
interestingly, the error page is different.

wget returns

Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322

Without more info I can't do much more.

--
#191, ew****@earthlin k.net
Linux makes one use one's mind.
Windows just messes with one's head.
** Posted from http://www.teranews.com **
Aug 26 '08 #4
On Aug 26, 11:22*am, The Ghost In The Machine
<ew...@sirius.t g00suus7038.net wrote:
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322

Without more info I can't do much more.
I would not be surprised if it's some backdoor portal to record "user
experiences" by MSFT for new users of Visual Studio 2008 (which is
what I'm using), of which I own a legal but academic copy.

RL

Aug 26 '08 #5
raylopez99 wrote:
I was building a "hello world" application in ASP.NET and during the
construction of the same it attempted to access the above site, owned
by Microsoft. Webroot Spy Sweeper, which resides on my system,
blocked the connection and lists the site as a known malware site.

Why is this and has anybody else had this happen? Ordinarily Webroot
is very reliable.

RL

WHOIS Search Results
Your WHOIS Search Results

131.107.115.28
I routinely blocks these as well:

127.0.0.1 genuine.microso ft.com
127.0.0.1 mpa.one.microso ft.com
127.0.0.1 wustat.windows. com
127.0.0.1 sa.windows.com
127.0.0.1 ie.search.msn.c om
127.0.0.1 se.windows.com
127.0.0.1 wutrack.windows .com


--

Jerry McBride (jm******@mail-on.us)
Aug 26 '08 #6
On Aug 26, 6:32*am, raylopez99 <raylope...@yah oo.comwrote:
I was building a "hello world" application in ASP.NET and during the
construction of the same it attempted to access the above site, owned
by Microsoft. *Webroot Spy Sweeper, which resides on my system,
blocked the connection and lists the site as a known malware site.
[snip details]

Think about it. You compiled an application, put it to the site, and
then were able to access and execute it.

If you can do it, so can malware hackers.

You know exactly where your page is supposed to be. But a malware
hacker could generate the bogus page, then send a link which would be
loaded when the e-mail is previewed. You don't even have to open the
e-mail, just preview it.

Because the infecting site would be a Microsoft site, it would be
nearly impossible to trace the perpetrator back to it's source.

Aug 27 '08 #7
It happened to me while accessing the help icon under the snipper tool, which
appeared on my XP machine after the SP3 upgrade

"The Ghost In The Machine" wrote:
In comp.os.linux.a dvocacy, Moshe Goldfarb.
<br***********@ gmail.com>
wrote
on Tue, 26 Aug 2008 10:39:07 -0400
<u5************ *************** **@40tude.net>:
On Tue, 26 Aug 2008 03:32:29 -0700 (PDT), raylopez99 wrote:
I was building a "hello world" application in ASP.NET and during the
construction of the same it attempted to access the above site, owned
by Microsoft. Webroot Spy Sweeper, which resides on my system,
blocked the connection and lists the site as a known malware site.

Why is this and has anybody else had this happen? Ordinarily Webroot
is very reliable.

RL

WHOIS Search Results
Your WHOIS Search Results

131.107.115.28
Record Type: IP Address

OrgName: Microsoft Corp
OrgID: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US

NetRange: 131.107.0.0 - 131.107.255.255
CIDR: 131.107.0.0/16
NetName: MICROSOFT
NetHandle: NET-131-107-0-0-1
Parent: NET-131-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.MSFT.NET
NameServer: NS5.MSFT.NET
NameServer: NS2.MSFT.NET
NameServer: NS3.MSFT.NET
NameServer: NS4.MSFT.NET
Comment:
RegDate: 1988-11-11
Updated: 2004-12-09
I believe that site has something to do with the search function in
Windows.
IOW when you do a Find it connects to that site for some reason.

I'd block the pig if I were you....

The given address backresolves to crl.microsoft.c om.
The web server is active, though directory listing access
is denied, and none of index.html nor index.htm
nor index.asp exist. index.aspx generates a server error;
interestingly, the error page is different.

wget returns

Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 1.1.4322

Without more info I can't do much more.

--
#191, ew****@earthlin k.net
Linux makes one use one's mind.
Windows just messes with one's head.
** Posted from http://www.teranews.com **
Aug 27 '08 #8

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

3
1736
by: chausan | last post by:
Hi, In these 2 days I received many e-mail requesting me for doing upgrade with various microsoft components (examples below). But from what I know microsoft will generally not asking normal users (my e-mail account is just a free one among the millions others) to do this. Will those e-mail contain trojan horse programs or virus ? Where can I report the case (I need one concrete e-mail address) to if so ? Thanks!
0
1710
by: chausan | last post by:
Update ++++++ All attchment scanned with norton anti-virus w/ yahoo mail service and they all reported infected with virus Worm.Automat.AHB. ======================================== From: chausanwong@yahoo.com.hk (chausan) Newsgroups: microsoft.public.dotnet.general
383
12038
by: John Bailo | last post by:
The war of the OSes was won a long time ago. Unix has always been, and will continue to be, the Server OS in the form of Linux. Microsoft struggled mightily to win that battle -- creating a poor man's DBMS, a broken email server and various other /application/ servers to try and crack the Internet and IS markets. In the case where they didn't spend their own money to get companies to
6
2635
by: Keith Smith | last post by:
How can I invoke a popup that is not blocked? I know it can be done because I have seen it. My goal is to pop up an image that has a BLACK background color (not white - otherwise I could just directly link to the picture file).
87
5298
by: Sony Music CDs install Malware | last post by:
Whether you are a web surfer or a C++ developer, if you use Windows be cautioned about SONY music CDs. They contain 'viewer' type software that is actually a trojan horse for a "rootkit". The licence agreement gives no indication whatsoever that the 'viewer' software contains the implementation of a nasty near-impossible to remove rootkit software. http://www.sysinternals.com/blog/2005/10/sony-rootkits-and-digital-rights.html ...
4
3267
by: dd | last post by:
I have a scenario where my popups are being blocked by IE6+ and Firefox. The problem is that although the popup is a direct result of the user clicking on the link (meaning that they WANT the popup), when it comes to opening it, I'm doing it via a JavaScript function and by the time the popup is opened the browser doesn't know it was as a result of that click. The link between click and popup open attempt is broken. The reason for this...
4
1243
by: =?Utf-8?B?TWljaGFlbEFmcm9tTkM=?= | last post by:
I recently found myself in a position that I had to reload XP Home, SP2 on two different computers. Right now, I connect to the Internet via a wireless ISP and connect through my laptop. I have Internet Connection Sharing running on the laptop. I have to add, that because of this wireless, I cannot use my Router and I am running a Crossover Cable between the two machines. My problem here is that although the computer connected to my laptop...
64
6035
by: Mika | last post by:
Hello, we understand you guys may be able to help. We have a page which has been working great for over a year and gets many hits. However recently something got changed that we cannot seem to find, and now *sometimes* if you refresh the page (generally while it is still loading) in IE7, we get the popup window error: Internet Explorer cannot open the Internet site... Operation aborted
0
8036
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However, people are often confused as to whether an ONU can Work As a Router. In this blog post, we’ll explore What is ONU, What Is Router, ONU & Router’s main usage, and What is the difference between ONU and Router. Let’s take a closer look ! Part I. Meaning of...
0
8461
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers, it seems that the internal comparison operator "<=>" tries to promote arguments from unsigned to signed. This is as boiled down as I can make it. Here is my compilation command: g++-12 -std=c++20 -Wnarrowing bit_field.cpp Here is the code in...
0
8448
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven tapestry of website design and digital marketing. It's not merely about having a website; it's about crafting an immersive digital experience that captivates audiences and drives business growth. The Art of Business Website Design Your website is...
0
8317
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each protocol has its own unique characteristics and advantages, but as a user who is planning to build a smart home system, I am a bit confused by the choice of these technologies. I'm particularly interested in Zigbee because I've heard it does some...
0
6796
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing, and deployment—without human intervention. Imagine an AI that can take a project description, break it down, write the code, debug it, and then launch it, all on its own.... Now, this would greatly impact the work of software developers. The idea...
1
5987
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new presenter, Adolph Dupré who will be discussing some powerful techniques for using class modules. He will explain when you may want to use classes instead of User Defined Types (UDT). For example, to manage the data in unbound forms. Adolph will...
0
5470
by: conductexam | last post by:
I have .net C# application in which I am extracting data from word file and save it in database particularly. To store word all data as it is I am converting the whole word file firstly in HTML and then checking html paragraph one by one. At the time of converting from word file to html my equations which are in the word document file was convert into image. Globals.ThisAddIn.Application.ActiveDocument.Select();...
0
3948
by: TSSRALBI | last post by:
Hello I'm a network technician in training and I need your help. I am currently learning how to create and manage the different types of VPNs and I have a question about LAN-to-LAN VPNs. The last exercise I practiced was to create a LAN-to-LAN VPN between two Pfsense firewalls, by using IPSEC protocols. I succeeded, with both firewalls in the same network. But I'm wondering if it's possible to do the same thing, with 2 Pfsense firewalls...
1
1572
muto222
by: muto222 | last post by:
How can i add a mobile payment intergratation into php mysql website.

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.