Avast WEBforum

Other => General Topics => Topic started by: REDACTED on July 03, 2015, 04:43:58 PM

Title: Domain and IP blocked by Avast
Post by: REDACTED on July 03, 2015, 04:43:58 PM
Hello,
I hope this is the right forum to post about a possible false positive.

Since few days, my company website trucchislotmachine.com has been blocked by avast, it says URL:MAL

I have analyzed the website and the server and I don't see any problem with it. Could you please check if it's a false positive? I already sent a request through the contact form but I didn't receive any reply.
Title: Re: Domain and IP blocked by Avast
Post by: Eddy on July 03, 2015, 05:04:44 PM
IP and domain are blacklisted:
http://zulu.zscaler.com/submission/show/b9f38f30563a1d084a85a6e764b4d78b-1435935053
http://www.siteadvisor.com/sites/trucchislotmachine.com


https://www.virustotal.com/en/url/6faca9b68c2eb1d22c3bac63f674c760120f2f177ea82ae38882d237f9fc9c07/analysis/1435935088/
http://trafficlight.bitdefender.com/info?url=http://trucchislotmachine.com
http://urlquery.net/report.php?id=1435935290882
http://urlquery.net/report.php?id=1435935311410
http://quttera.com/detailed_report/trucchislotmachine.com

Outdated software:
https://sitecheck.sucuri.net/results/trucchislotmachine.com

server is vulnerable to the POODLE attack, expired certificate, certificate name mismatch :
https://www.ssllabs.com/ssltest/analyze.html?d=trucchislotmachine.com
Title: Re: Domain and IP blocked by Avast
Post by: polonus on July 03, 2015, 06:11:54 PM
Flagged here: https://www.virustotal.com/nl/domain/trucchislotmachine.com/information/
Potentially Suspicious files:
Detected unconditional redirection to external web resource in 17 instances.
[[<meta HTTP-EQUIV="REFRESH" content="0; url=htxp://resources.32red.com/redirect.aspx?pid=10399%26bid=2607">]]
[[<meta HTTP-EQUIV="REFRESH" content="0; url=https://mediaserver.bwinpartypartners.it/renderBanner.do?zoneId=1657529">]] etc. etc.
Web application version:
Joomla Version 2.5.20 for: htxp://trucchislotmachine.com/media/media/js/mediamanager.js
Joomla Version 2.5.20 for: htxp://trucchislotmachine.com/language/en-GB/en-GB.ini
Joomla version outdated: Upgrade required.
Outdated Joomla Found: Joomla under 2.5.26 or 3.3.5
Outdated Web Server Apache Found: Apache/2.2.15  (has been mitigated?)

See: http://www.domxssscanner.com/scan?url=http%3A%2F%2Ftrucchislotmachine.com%2Fmedia%2Fmedia%2Fjs%2Fmediamanager.js

External malware link: htxp://js.users.51.la/17675171.js -> https://www.virustotal.com/nl/url/8a976a1485f7a38701566af9a0253ae095f74f84faf574ab4b87bf50662ffe40/analysis/1435939856/

PHP vulnerable: ftp://ftp.netbsd.org/pub/pkgsrc/current/pkgsrc/lang/php54/README.html

polonus (volunteer website security analyst and website error-hunter)
Title: Re: Domain and IP blocked by Avast
Post by: Para-Noid on July 03, 2015, 06:16:49 PM
Multiple blacklists http://multirbl.valli.org/lookup/188.121.50.243.html

Not a safe site at all.
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on July 06, 2015, 11:40:44 AM
Thank you for your support,
some issues are not real at all (e.g: meta HTTP-EQUIV="REFRESH" which are affiliate redirects to 100% safe websites), I'm going to fix remaining ones and let you know.
Title: Re: Domain and IP blocked by Avast
Post by: Eddy on July 06, 2015, 11:56:30 AM
The refresh issue is real and is considered as malicious behavior.
Title: Re: Domain and IP blocked by Avast
Post by: polonus on July 06, 2015, 02:08:03 PM
Eddy is right, flagged by Malware Script Detector v.2.0. detected Malware Customized XSS Malware in source:
https://s0.wp.com/_static/?? etc. etc. This is the Meta Tag "HTTP-EQUIV "REFRESH" - the client has to resolve: expound-v2.css?ver=2013-02-15s2.wp.com/wp-content/blog-plugins/wor…   0   B
https://s0.wp.com/_static/??-eJx9kdFO…   50.3   kB
Quote
Basic Principle: Never attribute to malice what you can attribute to incompetence. The first place to look is for a problem on the page itself.
Quote Info credits - Bob Trower.

polonus
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on July 07, 2015, 12:07:26 AM
Polonus I don't understand your post.

I don't get if you're saying META REFRESH are bad in general, or if my website has one ore more malicious meta refresh.

Eddy is right, flagged by Malware Script Detector v.2.0. detected Malware Customized XSS Malware in source:
https://s0.wp.com/_static/?? etc. etc. This is the Meta Tag "HTTP-EQUIV "REFRESH" - the client has to resolve: expound-v2.css?ver=2013-02-15s2.wp.com/wp-content/blog-plugins/wor…   0   B
https://s0.wp.com/_static/??-eJx9kdFO…   50.3   kB
Quote
Basic Principle: Never attribute to malice what you can attribute to incompetence. The first place to look is for a problem on the page itself.
Quote Info credits - Bob Trower.

polonus
Title: Re: Domain and IP blocked by Avast
Post by: polonus on July 07, 2015, 12:30:04 AM
Hi Matteo45,

I mean as general it isn't an elegant solution, a 301 isn't.
These test however were passed succesfully: http://mobilefriendlytest.website/index.php
Mind the advice there. The refresh gets carried through resolving in multiple alert boxes.
If there were a malicious Meta Tag it would not be visible for the public (visitors).
In that case the easiest and safest fix is to completely wipe your public server space and DB,
then reinstall from a known clean backup.

polonus
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on July 13, 2015, 10:21:42 PM
I'm a bit curious in knowing how avast decides wether blocking a site or not.
I requested to get out of siteadvisor blacklist, few minutes ago site was removed and now avast is not blocking trucchislotmachine.com anymore. So it just checks mcafee blacklist? COOL!
I'm glad I don't use MS win...
Title: Re: Domain and IP blocked by Avast
Post by: polonus on July 13, 2015, 11:02:09 PM
The website - trucchislotmachine.com is still being blocked by Avast Webshield as with URL:Mal
One of these domains on the same IP can also be responsible for the blocking:
http://sameid.net/ip -> http://sameid.net/ip/188.121.50.243/
What should be done is that the server shouldn't give out excessive server version info: Apache/2.2.15 (CentOS) to the world and attackers.
This could be easily mended by settings in the server configuration, so we get Apache period.
While even with CentOS 6.3 apache/2.2.15 (centos) is not vulnerabe to exploits, just turn off the Apache and PHP versions in the headers and miraculously you might get a clean bill of health....

polonus
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on July 16, 2015, 10:30:25 PM
Hi polonus,
thank you for your support.
I've hidden Apache and PHP version info in http header and all the previous issues, except:
- email blacklists: most of them are automatic and/or distribuited and I cannot find out how to submit site for review
- https://sitecheck.sucuri.net/results/trucchislotmachine.com => forced a rescan but it incorrectly sees website blacklisted on siteadvisor
- meta refresh: I understand your concerns about unconditional redirects but unfortunately I cannot move to other solutions like php header redirect

Matteo
Title: Re: Domain and IP blocked by Avast
Post by: polonus on July 16, 2015, 10:46:05 PM
Hi Matteo,

Report to virus@avast.com and ask for an exclusion (refer to this thread here). They could consider that, I cannot as unblocking websites is only reserved for avast team members, I am just a volunteer here with relevant knowledge. Anyway you considerably improved your website security by reporting here. Stay secure with Avast!

Damian

P.S. Joomla scan OK: https://hackertarget.com/joomla-security-scan/
Note that this site: -http://www.open-society-kz.org/modules/mod_roknavmenu/themes/basic/code.php
had  a threat identified as: Exploit.HTML.IFrame-6

pol
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on July 24, 2015, 03:17:07 PM
I sent an email 5 days ago, no reply and no action. Website trucchislotmachine.com (http://trucchislotmachine.com/) is still blocked by avast.
Title: Re: Domain and IP blocked by Avast
Post by: Eddy on July 24, 2015, 03:34:36 PM
A email?
You need to submit a ticket.
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on July 25, 2015, 12:58:05 AM
Report to virus@avast.com and ask for an exclusion (refer to this thread here). They could consider that, I cannot as unblocking websites is only reserved for avast team members, I am just a volunteer here with relevant knowledge. Anyway you considerably improved your website security by reporting here. Stay secure with Avast!

That's why I sent an email.

Where should I submit a ticket? I think I already did it, but I need to double check.

Matteo
Title: Re: Domain and IP blocked by Avast
Post by: Asyn on July 25, 2015, 07:33:35 AM
Where should I submit a ticket? I think I already did it, but I need to double check.

Matteo
-> https://support.avast.com/Tickets/Submit
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on August 12, 2015, 10:51:55 AM
Asyn,
I submitted a ticked some weeks ago, I received an automatic reply and nothing else.
Domain is still blocked, I don't understand why.

Do you think this is fair? My website is losing about 40-50 customers per day, I'm losing lot of money and Avast is not taking care of this false positive.

Someone please help me in contacting Avast.
Title: Re: Domain and IP blocked by Avast
Post by: Asyn on August 12, 2015, 10:53:21 AM
Post your ticket-ID.
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on August 16, 2015, 10:44:15 AM
Ticket ID: #IST-853-68707

Quote from: Kalivoda
The website is exploited by Angler ExploitKit. They need to clean all malware files on their hosting, change all their passwords and update all the systems.

Could you please give more details? Do you mean webserver tries to attack and exploit target pc installing angler exploit kit?

Thank you for your help.

Matteo
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on August 16, 2015, 10:11:09 PM
I used another pc with a new ip address to access the website, and I logged every communication with wireshark network analyzer.

I went through every single packet and I didn't notice anything suspicious.

Do you have more details about infected files? Maybe there are some injected javascript functions I don't see.
Title: Re: Domain and IP blocked by Avast
Post by: jefferson sant on August 16, 2015, 10:24:00 PM
I used another pc with a new ip address to access the website, and I logged every communication with wireshark network analyzer.

I went through every single packet and I didn't notice anything suspicious.

Do you have more details about infected files? Maybe there are some injected javascript functions I don't see.

Hello

I will check again there was a small problem on support
there was a response of duplicity, maybe tomorrow I can return feedback.
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on August 19, 2015, 09:40:15 AM
Thank you,
I'll wait for some more info.

Matteo
Title: Re: Domain and IP blocked by Avast
Post by: jefferson sant on August 19, 2015, 11:30:01 PM
Thank you,
I'll wait for some more info.
Matteo

It was sent to the analysts
Because there was no answer at least to get or delays resolution of issues support.
verification requested  ID ticket has progress.
Title: Re: Domain and IP blocked by Avast
Post by: jefferson sant on August 20, 2015, 01:13:44 PM
Thank you,
I'll wait for some more info.
Matteo

virus specialists informed me que website hxxp://trucchislotmachine.com/ is exploited by Angler ExploitKit as well.

Quote from: kalivoda
Please let the owner of the website que know there is need to clean the website, update all the systems and change all passwords Their.
Title: Re: Domain and IP blocked by Avast
Post by: HonzaZ on August 20, 2015, 10:05:00 PM
Hi,
You still didn't confirm that you changed passwords - if you didn't, please do so immediately. I am unblocking the domain now. ;)
Honza
Title: Re: Domain and IP blocked by Avast
Post by: REDACTED on August 21, 2015, 10:05:52 AM
I changed Joomla passwords, hosting passwords, mysql passwords 2 weeks ago and I have changed again few minutes ago.

Matteo
Title: Re: Domain and IP blocked by Avast
Post by: jefferson sant on August 22, 2015, 03:21:50 AM
I changed Joomla passwords, hosting passwords, mysql passwords 2 weeks ago and I have changed again few minutes ago.

Matteo

OK.
Site has been Unblocked.