Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: KingEdward on June 22, 2021, 12:43:20 AM

Title: Website Blocked - False Positive
Post by: KingEdward on June 22, 2021, 12:43:20 AM
Hi,

A website I mange has been taken offline, the site is GrabFreeRobux.com - It's a simple site that DOES NOT PHISH at all.

Please feel free to check it out for yourself, a user simply enters their username and completes actions to earn Points.

We are completely transparent with the way we work, explaining that we get paid a percentage for users completing actions and then reward them with points that can be converted to Robux gift cards.

Please could you get this removed as my traffic has seriously dropped since this was placed.

Thank you.
Title: Re: Website Blocked - False Positive
Post by: DavidR on June 22, 2021, 01:31:18 AM
This check reports the site as a Medium Security Risk - https://sitecheck.sucuri.net/results/GrabFreeRobux.com
This check reports a number of out of date software on the site - https://awesometechstack.com/analysis/website/grabfreerobux.com/
The check fails - https://webhint.io/scanner/5658831c-ec91-462b-b048-e4cc19057982

I don't know if these could contribute to the avast alert, but out of date software on the site could make it vulnerable to exploit.

Interesting 1 - I went for a check on the GrabFreeRobux.com to see what Avast was alerting on - to my surprise I was blocked by Firefox, it didn't like it either, see attached image 1.

Interesting 2 - Whilst trying to get a screenshot of the Firefox warning, Avast alerted, and it was complaining that my screen capture software (SnagIt) was some how touching the favicon.ico on your site, see attached image 2. 
So I would suggest checking that favicon.ico.

EDIT: Forgot to include this:
Reporting Possible False Positive File or Website - https://www.avast.com/false-positive-file-form.php (https://www.avast.com/false-positive-file-form.php).
Title: Re: Website Blocked - False Positive
Post by: garrodshelly on June 22, 2021, 04:13:32 AM
Dear Avast Team,
I am having trouble getting onto the web site https://www.shortstorylovers.com. Every time I try a threat pops up stating a URL Phishing has been detected. So I am blocked from getting to this site.
I hope you can fix the issue for me.
Thank you in advance,
Shelly
Title: Re: Website Blocked - False Positive
Post by: DavidR on June 22, 2021, 12:05:55 PM
Dear Avast Team,
I am having trouble getting onto the web site shortstorylovers.com. Every time I try a threat pops up stating a URL Phishing has been detected. So I am blocked from getting to this site.
I hope you can fix the issue for me.
Thank you in advance,
Shelly

Please read the post before yours, it gives a link to report it.

Also break suspect links to avoid accidental exposure as I have done in the quoted post.

You could also check your site for issues using the other sites in the post above yours.
Title: Re: Website Blocked - False Positive
Post by: KingEdward on June 22, 2021, 05:42:52 PM
Thank you I will replace the favicon.ico, not sure why its reporting as that.

I literally have no idea but going to try my best to resolve this!

Thanks guys, I have also submitted a false positive report, hopefully I can get this resolved.

Have a great day guys.
Title: Re: Website Blocked - False Positive
Post by: KingEdward on June 22, 2021, 05:56:47 PM
Hi,

After checking the favicon is fine, if you look above it says phishing as the issue.

And we all know an image cant physically phish your details.

So I beleive avast is just tagging anything that comes from grabfreerobux.com as phishing, so if i can get this removed all will be well.

I am now setting up a new SSL which should fix a few of the issues =)

Thank you communuity.
Title: Re: Website Blocked - False Positive
Post by: DavidR on June 22, 2021, 06:44:54 PM
In the old days of the internet the favicon.ico was used maliciously as the link doesn't/didn't necessarily have to be the actual favicon.ico image.
Title: Re: Website Blocked - False Positive
Post by: KingEdward on June 22, 2021, 06:48:54 PM
I see, yeah I would understand if it was showing as an actual virus but flagging an image as phishing is unlikely in my opinion.

I also ran a test of my site on AV SCANNER - https://www.virustotal.com/gui/url/6a74f11045c3a08edf54bf5048e4912eb82c3d2ae4798426238f4785447d99dc/detection

DETECTIONS - 0/70.
Title: Re: Website Blocked - False Positive
Post by: KingEdward on June 22, 2021, 07:30:29 PM
Just added the SSL and tested works great.

Also removed and replaced favicon.ico just to be safe, ran a full Virus scan on website all seems fine, just hoping someone from avast can look over the site and remove the false positive asap :)
Title: Re: Website Blocked - False Positive
Post by: DavidR on June 22, 2021, 07:33:20 PM
VirusTotal doesn't actually do a site scan as such, just checks blacklists, etc.  Hence why you don't see Avast or AVG in the supposed lost of scans.

The three links that I first posted actually do site checks looking at vulnerabilities/weaknesses that could be exploited.  As I said this could result in Avast alerting, but avast doesn't do these kind of checks, it is simply looking for malware/phishing, etc.

What I say holds no sway as to why avast may be alerting on your site, which is why I also gave you a link to report it as a possible false positive.