<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lots of Traffic to 4 IP Addresses in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85245#M17163</link>
    <description>&lt;P&gt;Agree on the blocking. Those IP's go back to adsafeprotected which is associated with both adware and malware.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-05-14_9-02-24.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6077i29F496BC1FF260D6/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-05-14_9-02-24.jpg" alt="2020-05-14_9-02-24.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You can see the relationships to a lot of Android and other exe files here:&amp;nbsp;&lt;A href="https://www.virustotal.com/graph/http%253A%252F%252Fdaldt.adsafeprotected.com%252F" target="_blank"&gt;https://www.virustotal.com/graph/http%253A%252F%252Fdaldt.adsafeprotected.com%252F&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-05-14_9-14-05.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6078iFADF837529328497/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-05-14_9-14-05.jpg" alt="2020-05-14_9-14-05.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Apparently there was a binary PUP with the same name (ADSAFEPROTECTED) at one point, so check for that. It could be they have moved to pure hosted. I would give them the benefit of the doubt that maybe they are protecting ads, but as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; points out their "website seems pretty vague" and that is a lot of traffic.&lt;/P&gt;&lt;P&gt;&lt;A href="https://greatis.com/blog/howto/remove-adsafeprotected-forever.htm" target="_blank"&gt;https://greatis.com/blog/howto/remove-adsafeprotected-forever.htm&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 May 2020 13:22:09 GMT</pubDate>
    <dc:creator>MartinZ</dc:creator>
    <dc:date>2020-05-14T13:22:09Z</dc:date>
    <item>
      <title>Lots of Traffic to 4 IP Addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85228#M17159</link>
      <description>&lt;P&gt;I am curious as to whether anyone else is seeing a great deal of traffic to 4 ip addresses....&lt;/P&gt;&lt;P&gt;104.244.xx.20 with the xx being either 36, 37, 38 or 39&lt;/P&gt;&lt;P&gt;We have ~3000 pc's on our network and I am seeing ~100 logs in an hour for each one. (first thing this morning I had 24,431 logs, not everyone is in yet)&lt;/P&gt;&lt;P&gt;I have googled these addresses and some sites say it is malware, some say it is good, but I can't find a reliable source to let me know what it is. The site name is &amp;lt;daldt or amidt&amp;gt; .adsafeprotected.com. When I go to their www site it does not look malicious (but I know that is not an indicator that the site is ok). I have all the traffic blocked right now and nothing is breaking. The traffic is coming from all the PC's on our network, including mine, and it must be behind the scenes stuff because I am not going there intentionally.&lt;/P&gt;&lt;P&gt;We have recently switched to Chrome as our default browser, but I can't find anything associating the IP's with Chrome either.&lt;/P&gt;&lt;P&gt;Any assistance is appreciated,&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;terri&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 12:09:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85228#M17159</guid>
      <dc:creator>Terri_Hawkins</dc:creator>
      <dc:date>2020-05-14T12:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: Lots of Traffic to 4 IP Addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85233#M17160</link>
      <description>&lt;P&gt;ARIN.net says it is "Integral Ad Science" (integralads.com) whose website seems pretty vague about about what they actually do, so I'm assuming they are tracking user data and shoveling ads.&amp;nbsp; In my opinion, block 'em.&lt;/P&gt;
&lt;DIV class="card-header"&gt;
&lt;H2 class="card-title"&gt;Network: NET-104-244-36-0-1&lt;/H2&gt;
&lt;/DIV&gt;
&lt;DIV class="card-body"&gt;
&lt;DL class="row"&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Source Registry&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12"&gt;ARIN&lt;/DD&gt;
&lt;/DL&gt;
&lt;DL class="row secondary"&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Net Range&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12"&gt;104.244.36.0 - 104.244.39.255&lt;/DD&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;CIDR&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12"&gt;104.244.36.0/22&lt;/DD&gt;
&lt;DD class="col-md-8 col-sm-12"&gt;
&lt;DL class="row"&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Source Registry&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12"&gt;ARIN&lt;/DD&gt;
&lt;/DL&gt;
&lt;DL class="row secondary"&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Kind&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12 preserve-whitespace"&gt;Org&lt;/DD&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Full Name&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12 preserve-whitespace"&gt;Integral Ad Science, Inc.&lt;/DD&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Handle&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12"&gt;&lt;A href="https://search.arin.net/rdap?query=ASML-5&amp;amp;searchFilter=entity" target="_blank"&gt;ASML-5&lt;/A&gt;&lt;/DD&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;&lt;/DT&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Email&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12 preserve-whitespace"&gt;network@integralads.com&lt;/DD&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Address&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12 preserve-whitespace"&gt;95 Morton St 8th Floor New York NY 10014 United States&lt;/DD&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Roles&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12"&gt;Registrant&lt;/DD&gt;
&lt;/DL&gt;
&lt;DL class="row secondary"&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Registration&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12"&gt;Thu, 02 Aug 2012 13:38:40 GMT (Thu Aug 02 2012 local time)&lt;/DD&gt;
&lt;DT class="col-md-4 col-sm-12"&gt;Last Changed&lt;/DT&gt;
&lt;DD class="col-md-8 col-sm-12"&gt;Wed, 22 Jun 2016 14:14:23 GMT (Wed Jun 22 2016 local time)&lt;/DD&gt;
&lt;/DL&gt;
&lt;/DD&gt;
&lt;/DL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 14 May 2020 12:35:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85233#M17160</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-05-14T12:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Lots of Traffic to 4 IP Addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85245#M17163</link>
      <description>&lt;P&gt;Agree on the blocking. Those IP's go back to adsafeprotected which is associated with both adware and malware.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-05-14_9-02-24.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6077i29F496BC1FF260D6/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-05-14_9-02-24.jpg" alt="2020-05-14_9-02-24.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You can see the relationships to a lot of Android and other exe files here:&amp;nbsp;&lt;A href="https://www.virustotal.com/graph/http%253A%252F%252Fdaldt.adsafeprotected.com%252F" target="_blank"&gt;https://www.virustotal.com/graph/http%253A%252F%252Fdaldt.adsafeprotected.com%252F&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-05-14_9-14-05.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6078iFADF837529328497/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-05-14_9-14-05.jpg" alt="2020-05-14_9-14-05.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Apparently there was a binary PUP with the same name (ADSAFEPROTECTED) at one point, so check for that. It could be they have moved to pure hosted. I would give them the benefit of the doubt that maybe they are protecting ads, but as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; points out their "website seems pretty vague" and that is a lot of traffic.&lt;/P&gt;&lt;P&gt;&lt;A href="https://greatis.com/blog/howto/remove-adsafeprotected-forever.htm" target="_blank"&gt;https://greatis.com/blog/howto/remove-adsafeprotected-forever.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 13:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85245#M17163</guid>
      <dc:creator>MartinZ</dc:creator>
      <dc:date>2020-05-14T13:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Lots of Traffic to 4 IP Addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85263#M17165</link>
      <description>&lt;P&gt;Great analysis, given that extra info I'd say block the whole 104.244.36.0/22 netblock outright, not just the .20 host addresses as I'm sure they will shift host addresses around inside their netblock at some point to avoid existing blocks.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 14:34:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85263#M17165</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-05-14T14:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: Lots of Traffic to 4 IP Addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85300#M17173</link>
      <description>&lt;DIV id="tinyMceEditorWolfgang_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;from Check Point categorization:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Bildschirmfoto 2020-05-14 um 17.38.50.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6079i01CB4D61DC1533E4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bildschirmfoto 2020-05-14 um 17.38.50.png" alt="Bildschirmfoto 2020-05-14 um 17.38.50.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As all other guys recommend,&amp;nbsp;block them.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 15:41:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85300#M17173</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-05-14T15:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Lots of Traffic to 4 IP Addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85301#M17174</link>
      <description>&lt;P&gt;Thank you all for your input! I will block the traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 15:48:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Lots-of-Traffic-to-4-IP-Addresses/m-p/85301#M17174</guid>
      <dc:creator>Terri_Hawkins</dc:creator>
      <dc:date>2020-05-14T15:48:30Z</dc:date>
    </item>
  </channel>
</rss>

