Malwarebytes reports Trojan every 4 hours

Open
#574 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
20/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Stale
Tech stack
csharp

Research direction

Start by reviewing the attached Malwarebytes blocked report and JSON, then compare their details with Simple DNSCrypt v0.7.1 and dnscrypt-proxy 2.0.42 on Windows 11. Determine whether the reported connections originate from the tool and whether the four-hour recurrence can be explained or reproduced; done requires a confirmed cause or a documented finding.

Written by the indexing model from the issue text.

Description

Malwarebytes reports a Trojan with dnscrypt-proxy trying to reach two IP numbers. This seems to occur every 4 hours.

Trojan_Screenshot 2024-09-08 100108
Website blocked due to Trojan

Detection History_Screenshot 2024-09-07 232154
Detection occurs every 4 hours

Malwarebytes Website Blocked Report 2024-09-07 231828.txt
ba26ca1a-6d5e-11ef-ab1f-dc4546c03275.json

Simple DNSCrypt v0.7.1 (x64) [dnscrypt-proxy 2.0.42]
Malwarebytes v5.1.9.124
OS: Windows 11 Pro (Build 22631.4037) v23H2

Dominant language
C#
Stars
2.5k
Forks
249
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from DNSCrypt/SimpleDnsCrypt

All issues in DNSCrypt/SimpleDnsCrypt

Similar issues

More C# issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.