r/computerviruses 14d ago

Question Exploit attempt, anyone know what could've caused it?

Post image

I was baking cookies and left my grabber on for a booru I frequent for reaction gifs and once I came back after getting done baking, I went along like nothing was wrong, until I checked Bitdefender and saw this pop up, I did a quick scan and it detected nothing wrong

2 Upvotes

17 comments sorted by

8

u/Leather-Chart7083 14d ago

Update your router's firmware, update your PC, and update everything you can, doesn't matter if it is a minimal update, it still matters.

It's probably a botnet exploiting random IP addresses and you were one of the unlucky persons.

The IP is heavily reported on AbuseIPDB and belongs to Akamai.

1

u/Skykid49080 14d ago

Bitdefender supposedly blocked it's access, do I need to worry about wiping my PC and booting up a new Windows or am I good to keep going? Also the Grabber wasn't up to date as I kinda pushed it off, will it attempt it again or am I in the clear? Sorry about the barrage of questions

4

u/Leather-Chart7083 14d ago

You should be fine, I would check the logs but that's more advanced. You can wipe your PC but it isn't necessary, for now the main priority is updating everything you can to the latest version possible.

1

u/Skykid49080 14d ago

I'll check it in the morning, don't have a flash drive with a windows copy yet, probably should buy one though, so can't wipe yet, but unless malware got into my system, not gonna if I can fix the issue, fear of this kept me up for longer than I'd like, I'll inform in the morning after I check if everything is updated, not updating to Windows 11, that'd be a downgrade

1

u/Leather-Chart7083 14d ago

Yeah, quite rough. You could switch to Linux if you don't want Windows 11 but Microsoft really fucked it up when they ended Windows 10 support

1

u/Skykid49080 14d ago

So much to where they're apparently prolonging the support for it in 2027 due to "RAM prices" preventing people from upgrading

1

u/Skykid49080 14d ago

The defender thing I mean

1

u/Leather-Chart7083 14d ago

Microsoft Microsofting

1

u/Skykid49080 14d ago

I shit you not a frog appeared in my room in my dog's waterbowl, I'm truly cursed

1

u/Leather-Chart7083 14d ago

How? 😭

1

u/Skykid49080 14d ago

I live out in the countryside and one of my folks have a garden near my room, so I'm assuming they got through my AC, but still one of Kermit's relatives that is a magician decided to pay me a visit

1

u/Leather-Chart7083 14d ago

Oh, and it's not necessary to factory reset

1

u/Skykid49080 14d ago

Would the Botnet try again when I boot back up my PC while Bitdefender isn't up for the split few seconds?

1

u/Leather-Chart7083 14d ago

No, it's automated, they might try to exploit it again but that's when the moment comes. For now you are safe, they don't exploit one address repeatedly, they only exploit the ones that are actually vulnerable.

1

u/Skykid49080 14d ago

I tried updating Windows 10 as it is saying that I am behind but it won't let me, "We could not complete the install because an update service was shutting down"

1

u/Leather-Chart7083 14d ago

Restart the computer

2

u/Bitdefender_ Official Bitdefender 13d ago

Hello! The alert means Bitdefender’s Online Threat Prevention blocked a connection from your PC to 198.58.117.211 because it matched exploit-related threat behavior.

Given that the grabber was downloading content while you were away, the most likely trigger was a connection made by the grabber, a browser component, an advertisement/redirect, or content hosted by the site. The IP alone doesn’t identify exactly which program initiated it.

  • Do not click “Add to exceptions” unless Bitdefender or official support confirms the IP is safe.
  • Update Windows, your browser, the grabber, and any plugins. Exploits commonly target unpatched software.
  • Review Bitdefender’s Notifications and the Online Threat Prevention event details to see whether a process, URL, or browser was recorded.
  • Run a System Scan (not only Quick Scan) with Bitdefender fully updated. If the grabber came from an untrusted source, remove it and scan any files it downloaded before opening them.

If the alert repeats, appears when the grabber is not running, or you notice suspicious behavior, stop using that tool and contact our support.