Author Topic: False positive detection on domain by avast  (Read 4189 times)

0 Members and 1 Guest are viewing this topic.

seidweise

  • Guest
False positive detection on domain by avast
« on: July 23, 2013, 07:24:13 PM »
Hi,
I submitted a report however to maybe speed things up I am also posting here.

Just bought a new dedicated server and moved a few sites to it.
It seems its ip/range was previously blacklisted by an offending domain by avast.

The domain currently being falsely blocked is: haruhichan.com
A large percentage of the site's userbase are avast users and the situation is infuriating them.
If you can please sort this situation out asap that would be great, many thanks

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: False positive detection on domain by avast
« Reply #1 on: July 23, 2013, 07:48:27 PM »
I have just visited the home page using firefox 22.0 and no alert.

I also did a quick browse of the menu bar and no alerts, ensure you have the latest avast virus definitions/streaming updates.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: False positive detection on domain by avast
« Reply #2 on: July 23, 2013, 07:54:57 PM »
your IP has one block here  http://whatismyipaddress.com/blacklist-check

http://www.apews.org/?

Quote
Oooops 108.162.199.175 is currently listed in APEWS :-(


--------------------------------------------------------------------------------
Entry matching your Query: E-631057
108.162.0.0/16
--------------------------------------------------------------------------------
CASE: C-131
Unallocated CIDR, no traffic until allocated,
or allocated to bad reputation provider
or allocated but dynamic / generically named IPs,
or bogons, see www.cidr-report.org,
or orphaned IP / CIDR in routing table
--------------------------------------------------------------------------------
History:
Entry created 2013-06-05

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: False positive detection on domain by avast
« Reply #3 on: July 23, 2013, 08:00:38 PM »
Hi DavidR,

Thanks, Pondus, also what I can concluse from this info.
I indeed get an alert there for URL:Mal for wxw.haruhichan.com  Could be because of these results for that IP: https://www.virustotal.com/en/ip-address/217.23.12.104/information/  -> http://urlquery.net/report.php?id=3960634
Maybe because of this on same IP: http://urlquery.net/report.php?id=19306
Also see: http://support.clean-mx.de/clean-mx/viruses.php?netname=WORLDSTREAM&sort=first%20desc&response=alive

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

seidweise

  • Guest
Re: False positive detection on domain by avast
« Reply #4 on: July 23, 2013, 08:05:37 PM »
just turned on cloudflare cdn to evade this issue at the moment

The ip address is 217.23.12.104
This is a brand new dedicated server

seidweise

  • Guest
Re: False positive detection on domain by avast
« Reply #5 on: July 23, 2013, 08:14:46 PM »
http://direct.haruhichan.com <- dns to the ip directly

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: False positive detection on domain by avast
« Reply #6 on: July 23, 2013, 08:19:58 PM »
Same results, these issues demand some time to elapse before everything comes unblocked.
Either ask for an exclusion for the domain at virus AT avast dot com or start sending de-listing requests for the initial IP block,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: False positive detection on domain by avast
« Reply #7 on: July 23, 2013, 09:07:00 PM »
Hi seidweise,

No problems from my side.

I enjoy your site and would like to see the issue resolved ASAP.

~!Donovan
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: False positive detection on domain by avast
« Reply #8 on: July 23, 2013, 11:20:41 PM »
hXXp://direct.haruhichan.com <- dns to the ip directly

Interesting on this direct url I get 12 alerts, best to change the http to hXXp to break the link.

However, I still don't get any alert on haruhichan.com.
I connect to that by highlighting the haruhichan.com text and have firefox open it in a new tab.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: False positive detection on domain by avast
« Reply #9 on: July 23, 2013, 11:48:52 PM »
Hi DavidR,

Exactly, with www etc. alerted as URL:Mal by avast!NetworkShield as I reported.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: False positive detection on domain by avast
« Reply #10 on: July 24, 2013, 01:40:54 AM »
But as I have said the two connections (as outlined in my last posts) not going to the direct.haruhichan.com link I don't get any alerts at all by the web shield or network shield.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security