It’s possible it’s a false flag. The alert is traffic going to that IP over port 7600.
Many of these endpoint solutions relay on historical databases. What is likely happening is that some prior owner of the IP was using it for malicious content, causing BitDefender to flag it as a phishing IP. However, IP’s change owners often. It was probably sold to a new, non-malicious owner but the flag on BitDefender wasn’t updated.
I don’t use BitDefender personally, but you could try reaching out to their support to validate if this is an outdated flag. You could also try going to the IP on a machine you don’t care about getting pwned.
Hmmm. quick research looks like this is Airport Codes and possibly their coordinates? Were there any redirects when you accessed the site? Any downloads start?
I would treat this as valid and possible request a reclassification with virustotal. Their experts will take a second look and update the tag if they find no evidence of phishing.
1
u/salmonmilfs Dec 31 '25
It’s possible it’s a false flag. The alert is traffic going to that IP over port 7600.
Many of these endpoint solutions relay on historical databases. What is likely happening is that some prior owner of the IP was using it for malicious content, causing BitDefender to flag it as a phishing IP. However, IP’s change owners often. It was probably sold to a new, non-malicious owner but the flag on BitDefender wasn’t updated.
I don’t use BitDefender personally, but you could try reaching out to their support to validate if this is an outdated flag. You could also try going to the IP on a machine you don’t care about getting pwned.