Jump to content

Event type: Dangerous link blocked


Go to solution Solved by Danila T.,

Recommended Posts

Hello.

 

I had recieve a lot of alerts how below:

 

Event "Dangerous link blocked" has occurred on device  in Windows domain on quarta-feira, 24 de março de 2021 08:51:46 (GMT-03:00)

Event type:     Dangerous link blocked

Application:     Host Process for Windows Services

Application\Name:     svchost.exe

Application\Path:     C:\Windows\System32\

Application\Process ID:     1056

User:     vasconcelos (Active user)

Component:     Web Threat Protection

Result\Description:     Blocked

Result\Type:     Malicious link

Result\Name:    "http://185.38.111.1/wpad.dat"

Result\Threat level:     High

Result\Precision:     Exactly

Object:     "http://185.38.111.1/wpad.dat"

Object\Type:     Web page

Object\Path:    "http://185.38.111.1/wpad.dat"

Object\Name:     wpad.dat

Reason:     Automatic analysis

Database release date:     24/03/2021 02:10:00

 

How can I solve this alert? I can´t just disable the alert, I need solve the problem.

 

I appreciate the help.

Link to comment
Share on other sites

Thank you Berny .

1- how to stop these alert messages? 
2- Is it an outgoing malicious link ? in that case there is a malware in the PC?

3- Or is it someone trying to attack the PC from outside?

 

Link to comment
Share on other sites

Facing same problem for last  two to three months. This keeps on popping :

 

Event :    Access denied
User :    XXXXX-PC\XXXXX
User type :    Active user
Application name :    svchost.exe
Application path :    C:\Windows\System32
Component :    Web Anti-Virus
Result description :    Blocked
Type :    Malicious link
Name :    http://185.38.111.1/wpad.dat
Precision :    Exactly
Threat level :    High
Object type :    Web page
Object name :    wpad.dat
Object path :    http://185.38.111.1
Reason :    Databases
Databases release date :    Yesterday, 03-04-2021 12:03:00

Link to comment
Share on other sites

  • 2 weeks later...

Hello, I also had this problem recently and resolved it.  My new router set the name of my home network to “domain.name” by default and the website that Kaspersky is blocking for everyone here was created to exploit routers which do so.  This article explains everything and further solutions for Windows users can be found in the comment section:  https://nakedsecurity.sophos.com/2016/05/25/when-domain-names-attack-the-wpad-name-collision-vulnerability/.

Cheers!

Link to comment
Share on other sites

Good day everyone.

 

Is there any optionon how to remove the alert at least, since we know Kaspersky has blocked the transmission.


If you are not going to deal with the root of the problem, you can probably mask the alert by creating a “block” rule in “Security Controls | Web Control” for this URL.

Link to comment
Share on other sites

Should have put this in my original post but for those who don’t want to read the article I linked above or don’t care to understand the exploit and just want a solution: 

“ahmadmbaghdadi 

April 7, 2021 at 3:07 pm

The following steps work for Windows 10:

Click the Windows logo on the bottom left corner and select Settings.
Select Network & Internet.
Select Proxy from the list on the left.
Make sure “Automatically Detect Settings” is disabled.


The following steps work for Windows XP, Windows Vista and Windows 7:

Click Start or the Windows logo and then find Control Panel.
In the control panel select Network & Internet and then Internet Options.
Go to the Connections tab and select LAN Settings.
Make sure “Automatically detect settings” is disabled.”

 

Alternatively/additionally you can rename your domain name to something other than “domain.name” in your router’s settings.  (Run Ipconfig /all from a command prompt and you’ll see it listed as the DNS suffix.)

Link to comment
Share on other sites

  • 4 weeks later...
Guest
This topic is now closed to further replies.


×
×
  • Create New...