Community


Avast Botnet warning on Remote Utilities server IP 198.147.28.34

Support level: Free or trial
Hi everyone,

I noticed that rutview.exe connects to 198.147.28.34:5655. Avast Web Shield blocks this IP and reports it as Botnet.

I checked the IP on VirusTotal. The vast majority of security vendors classify it as clean, but a few reputation providers currently flag it:
Malicious/Malware: CRDF, Fortinet, Lumu, SOCRadar
Suspicious: alphaMountain.ai, Gridinsoft

I also found older discussions mentioning that Avast/AVG had previously flagged parts of the Remote Utilities infrastructure, so I was wondering if this is a known issue.
Could a moderator or someone from the Remote Utilities team please confirm whether 198.147.28.34 is an official Internet-ID relay server?

If it is, are you aware that Avast is currently blocking this IP? If so, are there any plans to have the IP removed from Avast's blacklist, or to stop using this IP if its reputation cannot be restored?

I'm not suggesting the server is malicious—I'm simply trying to verify whether this is a false positive and whether the issue is already being addressed.

Thank you.

* Website time zone: America/New_York (UTC -4)