Author Topic: URL:Mal false positive  (Read 3283 times)

0 Members and 1 Guest are viewing this topic.

dominator

  • Guest
URL:Mal false positive
« on: February 26, 2014, 09:12:39 AM »
Avast Web Shield is giving me URL:Mal pop-up everytime I enter teen-o-rama.com. When I enter this adress directly into browser (newest firefox) I get popup and connection is blocked/reset. Even .jpg files associated with this site ( f/e http://www.teen-o-rama.com/thumbs/motherless.jpg ) are being blocked (therefor when entering motherless.com i get URL:Mal aswell, although website itself is not blocked).

I was reporting this obvious false positive already, so get your s**t together and fix this pls.

also: http://onlinelinkscan.com/results/teen-o-rama-com/
https://www.virustotal.com/nl/url/3f3245d8c927e0b3478e4c32c3cf84616dacb6867929ea63ba727999fbad34a8/analysis/1393402945/
« Last Edit: February 26, 2014, 09:24:03 AM by dominator »

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: URL:Mal false positive
« Reply #1 on: February 26, 2014, 09:37:40 AM »
I do not recommend visiting this site. Not long ago, users were redirected from
hxxp://teen-o-rama.com/category/55/Mom/ctr/1/?4x3x379997
to
hxxp://goyxtcxs.pornofreak.biz/azgmstle.php
which then tried to download Urausy malware.

Another suspicious thing about this domain is that we were never contacted by the admin, whereas in other cases, they respond fairly quickly.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: URL:Mal false positive
« Reply #2 on: February 26, 2014, 09:41:21 AM »
URL:mal means url or ip is on a blacklist for whatever reason

No surprise since it is a pornsite....


dominator

  • Guest
Re: URL:Mal false positive
« Reply #3 on: February 26, 2014, 10:49:03 AM »
I do not recommend visiting this site. Not long ago, users were redirected from
hxxp://teen-o-rama.com/category/55/Mom/ctr/1/?4x3x379997
to
hxxp://goyxtcxs.pornofreak.biz/azgmstle.php
which then tried to download Urausy malware.

Another suspicious thing about this domain is that we were never contacted by the admin, whereas in other cases, they respond fairly quickly.

Thank you for this reply, thats more than enough to give me a second thought.