Author Topic: Clean web sites in blacklist  (Read 2987 times)

0 Members and 1 Guest are viewing this topic.


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: Clean web sites in blacklist
« Reply #1 on: May 07, 2012, 07:30:18 PM »
Nothing on http://sitecheck.sucuri.net/results/www.kit-iphone.ru/ nor http://sitecheck.sucuri.net/results/www.svoj-dom.ru/ for the sites.

Since they are both hosted on the same IP address it is more likely the IP that is blocked rather than the domains as such. It may be that there are other domains that are hosted on this IP address and it could be that they are the problem or the actual host.

####
- There is an on-line contact form, http://www.avast.com/contact-form.php?loadStyles for:  * Sales inquiries; Technical issues; Website issues; Report false virus alert in file; Report false virus alert on website; Undetected Malware; Press (Media), issues.

- If you are reporting an FP, then you get another input field open, click Browse button and navigate to the file or enter the web URL for the site you wish to submit for review (network shield - IP address), etc. A link to this topic also wouldn't hurt.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Clean web sites in blacklist
« Reply #2 on: May 07, 2012, 07:42:26 PM »
The only minor hick-ups I see are the following - as DavidR says: ....IP address has been identified as risky by one/more sources....
Malware (i.e. riskware)  from that IP like  Skodna.ArchSMS.P, Win32:Malware-gen and unknown_html malware have been since closed
or is no longer responsive (dead)!

Given as suspicious here: htxp://zulu.zscaler.com/submission/show/1f714da6809d9b6e7fa5160ec580db2b-1336410803
and this link: hxtp://zulu.zscaler.com/submission/show/4751f19d60d403f1f5896a659a62d89f-1336411127
Issue here: wXw.svoj-dom.ru/engine/classes/js/jquery.js benign
[nothing detected] (script) wXw.svoj-dom.ru/engine/classes/js/jquery.js
     status: (referer=wXw.svoj-dom.ru/)saved 93868 bytes 9eb9ac595e9b5544e2dc79fff7cd2d0b4b5ef71f
     info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
     info: [decodingLevel=0] found JavaScript
     suspicious
See:  htxp://zulu.zscaler.com/submission/show/e7df941958a9b152601a823082ec9bf5-1336411852

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

kubecj

  • Guest
Re: Clean web sites in blacklist
« Reply #3 on: May 07, 2012, 08:26:29 PM »
The hosting server got killed because it distributes malware. I temporarily removed it from the block, but I'll kill it again in any other case of malware.

chertenok

  • Guest
Re: Clean web sites in blacklist
« Reply #4 on: May 08, 2012, 11:42:57 AM »
Thanks to all.  It is necessary to change a hosting provider? My sites are blocked because another's sites on the same IP address are distribute viruses?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Clean web sites in blacklist
« Reply #5 on: May 08, 2012, 03:35:17 PM »
Hi chertenok,

The now closed malware came from IP 176.9.118.22, also hosting hxtp://load-rar2.ru/ via which domain malware has been launched. Skodna.ArchSMS.P stayed active for 159.8 hrs before it was killed, and  Win32:Malware-gen stayed on for 74.8 hrs.
Your site seems to be secure. You could remove the "X-Powered-By" HTTP Header, which gives away that content is being generated dynamically.

Spamcheck and Safebrowsing secure. Web rep: http://www.webutation.net/go/review/kit-iphone.ru

If you experience new blocks because of the hosting server being abused,
you could reconsider hosting your site somewhere else, but that is up to you.
The AS has 3098 blacklisted URLs, re: http://sitevet.com/db/asn/AS24940
From your side on everything seems hunky-dory,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

chertenok

  • Guest
Re: Clean web sites in blacklist
« Reply #6 on: May 08, 2012, 10:09:19 PM »
 Thank you very much for the operative help.