Author Topic: MY Website blocked bv Avast with the Infection: URL:Mal message  (Read 3342 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
MY Website blocked bv Avast with the Infection: URL:Mal message
« on: January 17, 2016, 08:31:10 PM »
Hi all,

Many users started to inform us that they cannot access our website because Avast was telling them that the website is infected: URL:Mal

Could you help me with this? Thank you for your interest.
« Last Edit: January 17, 2016, 11:47:30 PM by msaxar »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
URL:Mal = IP and/or domain is blocked.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
One vulnerable library detected: http://retire.insecurity.today/#!/scan/003ffb412db036dcfe106dd4b64ab2f022897a8a638ed7afc1e2172f9c1b3daf

http://quttera.com/detailed_report/www.e-data.com.tr

Also you may want to update Windows Server as OS when Server 2016 is out next year, should help in security, please take use of its new security features.

Other scanners give a clean sheet on the site.

You may want to add Incapsule to get some better protection: https://www.incapsula.com/
CloudFlare can be gone around pretty quickly.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
« Last Edit: January 17, 2016, 09:59:46 PM by Pondus »

REDACTED

  • Guest
Dear Pondus,

Thank you for your interest ,so only Avast doesnt like our website :P "Avast   JS:ScriptIP-inf [Trj]   20160117"

So in order to make available our website for Avast users we should do this?

"
any domain hosted on afraid.org can be used by other persons for dns hosting without your control. It happened for your/client's domain, it was misused for malicious purposes - in that case, when nobody has control on subdomains of domain (DNS hijacking), we block the whole domain in order to protect our users. For you/client, the solution is most probably only changing the dns hosting and letting us know later.
"

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Since it is a companies website, I say :

- Get a decent host
- Use a dedicated server
- Hire someone who keep everything (especially security related things) up-to-date

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Hi msaxar,

Yes for Avast Team Members to unblock just steer away from afraid dot org and the unblocking could often come as soon as with an upcoming update of the software definitions. We cannot do this for you as we are volunteers with relevant knowledge, and unblocking can only be performed by Avast Team Members.
There is no malware at that website per se, no cloaking, all same status codes, no spammy looking links, no iframes, no blacklists, exept than for that afraid dot org issue.

The other recommendations in this thread are also worth looking into. to make the website more secure. The real situation with the server security can only be known to whom administrates the website. Remember excessive server header info proliferation is a misconfiguration, never let your server software or your CMS talk to loudly for that matter.

See one fail and two warnings here: https://asafaweb.com/Scan?Url=www.e-data.com.tr

Have a peaceful day,

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Thank you so much Dear Polonus.  :)

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: MY Website blocked bv Avast with the Infection: URL:Mal message
« Reply #8 on: January 18, 2016, 10:00:12 AM »
Please do note that just being hosted at afraid.org does not result in blocking - only when there are malicious subdomains being created. We spotted these URLs active in the past 24 hours:

hxxp://1.totalhelp.e-data.com.tr
hxxp://utid.iteby.e-data.com.tr

Both pointing to blocked IPs. This is the reason of blocking, and it can be resolved by changing hosting or using the premium account at afraid.org (setting called "stealth").

Please post a reply when you resolved the issue and I will unblock it after confirming.
Honza