blocking issue

Sree 1,971 Reputation points
2021-10-02T16:51:57.58+00:00

I wish to know if the flagging of this address is a false positive from MS side or whether the entire CDN is truly malicious.

Issue can be reproduced on any box with network protection in block mode. Open browser, attempt to navigate to https[:]//cdn.js7k.com.

suddenly started getting a large number of Network Protection alerts related to cdn.js7k.com in M365.
like to know if this is a false positive or whether blocking the entire CDN is truly what is intended.
I am unsure if end users are noticing any impact, as I do not how they are actually ending up visiting that site. It appears to be related to Ad delivery, so it could be that the users are sitting on an entirely unrelated page and touching the site via Ads.

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,168 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,339 questions
{count} votes

Accepted answer
  1. Rocky254 76 Reputation points
    2021-10-05T01:46:21.097+00:00

    I see there is no content on the website https[:]//cdn.js7k.com and might be difficult to confirm whether the Alerts are FP or not, with out analyzing the actual content on the website.

    I think if you can provide more information regarding the website, like - what content it used to host etc.. that might help Microsoft to investigate further.(not sure, these are my thoughts)

    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Paul Gerloff 16 Reputation points
    2021-10-04T02:23:27.973+00:00

    We started getting the same behavior over the weekend, I've had one of my team submit a support case to ask what the root cause determination was. Will reply with whatever they come back with

    2 people found this answer helpful.

  2. AC Gel 1 Reputation point
    2021-10-04T13:25:11.8+00:00

    Hello folks, did anyone got an answer from Microsoft? i got a lot of alerts about suspicious connection to that url.
    Thanks


  3. Paul Gerloff 16 Reputation points
    2021-10-05T01:58:10.503+00:00

    @Rocky254 It's a CDN so the content will be unlikely to be static, a single CDN user could have triggered blocking or the CDN itself is suspect, or of course FP. Still no word from MSFT on our ticket

    0 comments No comments