Avast WEBforum

Other => Viruses and worms => Topic started by: KDibble on May 18, 2022, 05:59:18 PM

Title: False Positive on a New York State Goverment Website
Post by: KDibble on May 18, 2022, 05:59:18 PM
I've filed a false positive report with Avast on this. I'm posting it here in case anyone is able to help speed up their response.

These websites:

hxtps://www.nytrainingservices.com/
hxtps://www.nytrainingservices.com/healthassistors

are official New York State training websites for people who operate under New York State Department of Health contracts to help people purchase health insurance.

A recent VirusTotal scan finds no issues (a scan from a year ago had one vendor reporting an issue but that vendor now reports the website as clean).

Avast Business Pro is blocking these sites as "URL:Phishing".

This is a website that many of our employees use frequently, and so it is important to correct this issue quickly.

Thanks for your support.
Title: Re: False Positive on a New York State Goverment Website
Post by: polonus on May 19, 2022, 01:21:09 PM
Hi KDibble,

Probably the reason was Scamvertising on basis of IP abuse reports:
https://www.abuseipdb.com/check/198.49.23.145

Here it was not flagged: https://quttera.com/detailed_report/www.nytrainingservices.com

A mere 4% of content being blocked for me at this site. Trend Micro gives it the all green.

Wait for a final verdict from an avast team member, as avast team are the only ones to come and unblock,
we here are just volunteers with relative knowledge in the field of 3rd party cold recon website security and error-hunting,

polonus
Title: Re: False Positive on a New York State Goverment Website
Post by: DavidR on May 19, 2022, 08:45:44 PM
@ KDibble
If you mean the - Reporting a possible Malicious sample File or Website link - then you should get a response in a day or  two.
Title: Re: False Positive on a New York State Goverment Website
Post by: polonus on May 19, 2022, 11:21:52 PM
Hi KDibble,

In the light of what DavidR added, can you share with us here what was avast team's final verdict.

Website has a self-referencing canonical. No CSP detected.
Javascript resources seem all OK.


polonus