Help fixing 'erroneous' Q-Feeds Block

Started by Taunt9930, August 08, 2026, 02:17:29 PM

Previous topic - Next topic
August 08, 2026, 02:17:29 PM Last Edit: August 08, 2026, 02:41:55 PM by Taunt9930
Hi All,

I am not sure if this is a Q-feeds issue, OPNSense Firewall Issue, or a me issue.

After working for some time, I noticed the other day that my Aqara presence sensors can no longer be controlled by the Aqara app. Upon looking at the OPNSense firewall live log, it appears that connections from those devices into the firewall/out to the internet is suddenly being blocked by my Qfeeds rule blocking connections to the qfeeds created malware-ip feed.

EDIT: The event is also shown in the Qfeeds events pane.

When I search for the IP on the TIP, nothing comes up - no IOC's.

This (happily) appears to be the only connection being blocked by this rule - connection to this IP from the two Aqara Device IP's.

EDIT: If I go to firewall > Diagnostics > aliases and select the qfeeds malware alias in the dropdown, and search for the IP, it does not appear to be in the list. Why is it being blocked? What can I do to work out why this is suddenly being blocked. If I disable the qfeeds rule, all is well.

The IP in question is 43.131.7.8

Thanks - I appreciate any help anyone can give!

I searched the qfeeds block file and 43.131.7.8 isn't contained there.

virustotal.com also shows zero reported security issues wirh that ip

Vendors Analysis:
No security vendors flagged this URL as malicious
Final URL:
http://43.131.7.8/
Domain:
43.131.7.8

Look at your logs to see why it's being blocked for you?

Quote from: vk2him on Today at 12:14:10 AMI searched the qfeeds block file and 43.131.7.8 isn't contained there.

virustotal.com also shows zero reported security issues wirh that ip

Vendors Analysis:
No security vendors flagged this URL as malicious
Final URL:
http://43.131.7.8/
Domain:
43.131.7.8

Look at your logs to see why it's being blocked for you?

All of that is in my original post.

It is being blocked by the qfeeds rule - as indicated by the firewall log, and as indicated by being in the qfeeds event list - despite, as I said above, not being on the IOC list, or the qfeeds alias list on the device itself.

Disabling the qfeeds rule resolves the problem.

Are you using Q-Feeds Plus or Premium? That would explain why you have the IP in the list but vk2him doesn't.

I noticed that the IP is on the Spamhaus ZEN blacklist, you can check it here: https://mxtoolbox.com/blacklists.aspx

Quote from: Taunt9930 on August 08, 2026, 02:17:29 PMEDIT: If I go to firewall > Diagnostics > aliases and select the qfeeds malware alias in the dropdown, and search for the IP, it does not appear to be in the list. Why is it being blocked? What can I do to work out why this is suddenly being blocked. If I disable the qfeeds rule, all is well.

The IP in question is 43.131.7.8

It is in there and caught by a CIDR entry - search for 43.131.0.0.


Quote from: vpx23 on Today at 07:16:44 PMSpamhaus ZEN blacklist

It's in ZEN because it's listed in their PBL. Unless the node at this address is attempting to deliver e-mail's directly, it isn't a problem.

AHH, brilliant - thanks both - I missed that. Didn't think to search for 43.131.0.0. (Yes, I'm on plus).

What's the best way to whitelist/bypass for that single address? I notice you can add domain whitelist in qfeeds, but not sure you can add an IP?

They have a false positive reporting form in your TIP.
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)