84.17.46.49 and 84.17.46.53 are both IP addresses that seem to facilitate a downloader, trying to collect data from our network/PCs.
Our threat analysis software indicates: “The connection from [SYSTEM-XYZ to 84.17.46[.]49 has been blocked for security reasons(Malicious).”
Funny thing is, after manually blocking these particular IPs in our firewall, the website https://xstore.8theme.com/ becomes unreachable. When deactivating the block, your website pops up again, looking normal.
For some reason, your contents are linked to these IP addresses.
Are you using CDN from Datacamp? (https://ipinfo.io/AS60068/84.17.46.0/23)