Norton states IP address of Denon receiver as Malicious

My Denon Home Entertainment receiver, connected to my local network with IP-address 192.168.1.44 (local address) has a Network interface, which can be called by it's IP-address.

When the menu of the receiver is displayed in the Firefox browser, this local address is identified as Malicious by Norton Safe Web, caused by a  : Drive by dowload - Malicious Site: Malicious Domain Request 2.

 

Can somebody explain, why a local address in the first place is identified this way and how to correct this situation?

Hi hvgsel,

 

That is peculiar.  Malicious Site: Malicious Domain Request 2 is an outbound detection.  Is the private IP address showing in the alert as the destination address or is there an internet address showing in the alert somewhere as well?

Hi SendOfJive,

 

No there is not an internet address and no specific alert in the History section. It only shows up in the browser toolbar with an exclamation mark (see screenshot). When i click the exclamation mark and then ask a full report, it sends me to Norton's Safe Web site and there it states that this IP-adress has the before mentioned threat.

The only alert which shows up for this IP-address in History is an SSDP warning, which relates to the IP-address of my laptop (see second screenshot), which i can imagine because i manage the receiver from there.

 

I think it's an error in the Safeweb site's database, which makes the error too general for only a private/local address.

 

BTW : The receiver makes, once a day, a connection with Denon's website to check if there are firmware updates. A normal operation, I think.

 

Regards, Hugo

 

 

The Denon menu with the Safe Web warning :

 

Denon Receiver Menu.JPG

 

Norton's History log alert :

Denon Receiver Alert.JPG.

 

 

 


hvgsel wrote:

No there is not an internet address and no specific alert in the History section. It only shows up in the browser toolbar with an exclamation mark (see screenshot). When i click the exclamation mark and then ask a full report, it sends me to Norton's Safe Web site and there it states that this IP-adress has the before mentioned threat.


Yeah, I see what you mean.  There is no way that Norton Safe Web could actually crawl that address, let alone find a threat.  Very strange.

 

Hi hvgsel,

We have manually analyzed the sites '192.168.1.44' and '192.168.1.31' and found it to be clean so we have changed its rating to green.

http://safeweb.norton.com/report/show?url=192.168.1.44

http://safeweb.norton.com/report/show?url=192.168.1.31



Cops

 

So, that's solved then; still weird that local/private IP addresses show up in Safeweb. Any idea why??

 

 


hvgsel wrote:

So, that's solved then; still weird that local/private IP addresses show up in Safeweb. Any idea why??


Yeah, I'd like to know how those got listed in Safe Web, too.  Those aren't websites.  They aren't even internet (WAN) addresses.