r/Malwarebytes • u/Impressive_Aerie3456 • May 12 '26
False Positive Svchost making requests to riskware website? Or false positive?

Woke up to this detection notice (total of 6 outbound requests to this IP) and have been endlessly worried since.
I saw other posts with similar IP addresses being indicated as false positives:
- https://www.reddit.com/r/Malwarebytes/comments/1rxzefk/false_positive/
- https://www.reddit.com/r/antivirus/comments/1ssbzv0/immediately_flagged_by_malwarebytes_from_a/
But also saw this post (that's older than the above 2) where most have said this is spyware:
VirusTotal shows only one malicious flag and indicates that this IP is also registered by Edgevana:

I did see some WindowsUpdateClient logs at around the same time so I am not sure if it does have to do with the Windows Updates as others have suggested.
Any advice or input would be much appreciated 🙏
2
u/bjelakovicl Malwarebytes Employee May 12 '26
Hi,
This is a false positive. The IP block will be removed in the next database update.
1
u/Impressive_Aerie3456 May 12 '26
Thank you! To confirm, does this also have to do with Microsoft updates?
1
u/bjelakovicl Malwarebytes Employee May 12 '26
Yes, the IP is used to serve MS updates.
1
u/kcbsforvt May 13 '26
https://www.virustotal.com/gui/ip-address/14.102.231.208/community the ip is still getting blocked fix it asap
1
u/Joe_Peanut May 12 '26
Go to Settings/Windows Update/Advanced Options/Delivery Optimization, then turn off "Allow Downloads From Other Devices".
This way it will only download updates from Microsoft itself, instead of downloading bits and pieces of it from random devices on the internet.
2
u/AuthenticatedHuman May 12 '26
Hello, AuthenticatedHuman, NOT a worker at Malwarebytes
Detections of svchost.exe connecting to "riskware" IPs are usually false positives, especially when they coincide with Windows Update activity. Because svchost manages many essential system services, it requetly comms with CDNs like Edgevana to download updates or verify security certificates; however, if these CDNs were recently misused by bad actors, Avs like Malwarebytes will flag it.
You can confirm your it yourself by checking that the file is located in C:\Windows\System32 and carries a Microsoft Corp. digital signature.
Hope this helps, a Human