45.148.10.122

ThreatDown is now the name of the Malwarebytes line of business products. References to Malwarebytes below reflect the amazing technology used to first identify the threat.

Short bio

The IP address 45.148.10.122 was blocked by Malwarebytes because one or more systems at this IP have beenĀ compromised. Systems at this IP are used to scan your system.

Malicious behavior

This range of IP addresses have been found to be involved in RDP probes or attacks. This is a block of incoming traffic ā€“ meaning the IP address being blocked is scanning and/or attempting to force its way into your machine via different ports. These attacks can last anywhere from a few hours, days, to a week. IP ranges will be probed by the compromised systems followed by an attempt to brute force their way into machines in order to infect them with ransomware.

The most common method of accessing machines is via Windows Remote Desktop Protocol (RDP). We recommend you check to see if you have the Remote Desktop enabled and if so, disable it. For more information, see How to use Remote Desktop. If you need to use Remote Desktop, see our Malwarebytes Labs article How to protect RDP on how best to lock it down.

Protection

Malwarebytes blocks the IP 45.148.10.122 because it has been compromised.

Malwarebytes blocks 45.148.10.122

What you can do

Given that Malwarebytes is blocking the attackers, you do not need to worry and no further action is required.
If the block alerts are interfering too much with your daily work, it may help if you add the IP address you see in our Alert to the Windows Firewall.
To view the IP address in our alert:

  • Open Malwarebytes for Windows > click the Detection History card.
  • Click the History tab.
  • Under the Event column, open the Real-Time Protection detection report.

Add an exclusion

Should users wish to visit a blocked IP Address and exclude it from being blocked, they can add it to the exclusions list. Hereā€™s how to do it.

  • Open Malwarebytes for Windows.
  • Click theĀ Detection History
  • Click theĀ Allow List
  • To add an item to theĀ Allow List, clickĀ Add.
  • SelectĀ Allow a website.
  • SelectĀ Add an IP addressĀ and enter the IP address that you wish to exclude.
  • Click onĀ DoneĀ and the IP address should appear in yourĀ Allow List.

Please note that allowing these inbound scans could lead to an infection of your system.