Author Topic: Wah: Avast's Blacklisting a Clean site  (Read 4844 times)

0 Members and 1 Guest are viewing this topic.

ser123

  • Guest
Wah: Avast's Blacklisting a Clean site
« on: June 26, 2011, 07:28:37 PM »
The site I'm talking about had a problem some time ago, it was cleaned quickly but is still suffering being in the blacklist.

Could you exclude the site from avast's blacklist?
The site is http://wahackpokemon.com

G-Data send me this info:
Quote
I just received word from one of our analysts that this was indeed a false positive detection, the reason being that back in March 2011 a variant of the ZEUS Trojan was parked there. That has been removed by now but for some reason the website was still blacklisted.
 
This blacklist entry is now scheduled for removal – the website should be available again within the next few hours.

It's clean in http://www.urlvoid.com
In virusTotal is also clean, (except for websense who until now didnt give any support all this time)
In unmaskparasites : This page seems to be <clean>
« Last Edit: June 26, 2011, 07:33:06 PM by ser123 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Wah: Avast's Blacklisting a Clean site
« Reply #1 on: June 26, 2011, 09:57:59 PM »
Sucuri Scanner say infected
http://sucuri.net/malware/malware-entry-mwdefaced01

Malware found in the URL: hxxp://wahackpokemon.com/es/mirage-space
Malware found in the URL: hxxp://wahackpokemon.com/es/lightplatinum-space

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Wah: Avast's Blacklisting a Clean site
« Reply #2 on: June 26, 2011, 11:04:53 PM »
Hi ser123,

Make that link non-click through like -http://wahackpokemon.com/ or like Pondus did hxxp://wahackpokemon.com/
We have to re-evaluate...

WOT has questions on the vendor reliability and privacy scores of the site:
http://www.mywot.com/en/scorecard/wahackpokemon.com
The link to -www.megaupload.com is flagged by unmasked parasites
and also the link here: http://www.google.com/safebrowsing/diagnostic?site=www.mediafire.com

Do not know about the actuality of these defacements as mentioned by sucuri ?
Cannot trace them now when I visited site via a proxy just a minute ago..
SOSWebScan says: Your site URL -http://wahackpokemon.com/ has been successfully scanned. And No Malware or badwares found.

Anyway the server there gives away too much information about installed version etc., specific header information about dynamically generated content should not be given away, and the site uses Flash with the danger of local shared object cookies,

polonus
« Last Edit: June 26, 2011, 11:18:10 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Wah: Avast's Blacklisting a Clean site
« Reply #3 on: June 27, 2011, 08:37:18 AM »
NORMAN analysis say infected

Quote
wahackpokemon.com.htm : Processed - HTML/Agent.MV

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Wah: Avast's Blacklisting a Clean site
« Reply #4 on: June 27, 2011, 08:59:08 AM »
urlvoid, avg and others say "can't find the location", "can't scan" and such things as I write this.

Name of the site doesn't sound trustfull to me.

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Wah: Avast's Blacklisting a Clean site
« Reply #5 on: June 27, 2011, 12:40:29 PM »
I really doubt if this site is clean.
Unfortunately,i can see this site listed here(10 before the end of the list) as rogue site, http://www.freepcsecurity.co.uk/2010/10/04/malicious-sites-october-04/. In addition,in the past this site was listed by Zeustracker.

Urlvoid can't scan this site since the domain "does not exist or is unaccessible".Refence to your post(It's clean in http://www.urlvoid.com).
« Last Edit: June 27, 2011, 12:42:51 PM by Left123 »
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Sirmer

  • Avast team
  • Sr. Member
  • *
  • Posts: 324
Re: Wah: Avast's Blacklisting a Clean site
« Reply #6 on: June 27, 2011, 01:44:16 PM »
Hello,
i checked this site and it is clear now, and it was removed from Zeustracker. It will be removed from our black list in next VPS.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Wah: Avast's Blacklisting a Clean site
« Reply #7 on: July 05, 2011, 02:16:36 PM »
I got a feeling it is clear for as long as it lasts. Which will be not be long.