Q-Feeds flagging xxx.xxx.xxx.xxx as suspicious: likely false positive

Started by dinguz, July 22, 2026, 07:21:36 PM

Previous topic - Next topic
I've noticed xxx.xxx.xxx.xxx is flagged as suspicious in Q-Feeds.

On top of that, the OPNsense GUI doesn't currently offer a way to whitelist an IP address for either the firewall blocklist or the Unbound blocklist. Combined with the free tier's 24-hour update frequency, this leaves me with two unappealing options: run a manual override at the firewall rule or Unbound config level, or disable Q-Feeds altogether until the update has propagated to my system. Neither feels like the right tool for what should be a simple exception case.

Edit: redacted because this has been resolved through a report in the Q-Feeds portal.
Note: This post may have been lightly edited by AI for spelling and minor readability improvements. The content and findings are entirely my own.

Even as a free tier user you probably have an account, so log in to their portal and use the False Positive Reports form:

https://tip.qfeeds.com/views/support/my_false_positives.php

The OPNsense forum is definitely not the place for that.

HTH,
Patrick
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

You could go to "Firewall: Diagnostics: Aliases", select "__qfeeds_malware_ip" from the drop-down list, search for the IP and delete it.

But this probably only lasts a day till the next Q-Feeds update.

Or use the False Positives Report Form 🙄
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

Obviously sorry for the inconvenience. But the only way to get this solved in the future within an hour (and often sooner) is indeed to let us know via our false positive reporting in the TIP.

Your Threat Intelligence Partner  qfeeds.com