Author Topic: Avast has blocked our commercial business domain and JavaScript  (Read 5684 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Avast has blocked our commercial business domain and JavaScript
« on: December 09, 2014, 01:21:30 AM »
Avast has blocked our core domain where we host our business assets:  lkqd.net 
We run mobile video ads for thousands of website so this has huge implications.
The only thing I can think of that would cause a flag is our JavaScript, but it does nothing other than render ads and has a perfect score according to multiple scanners:  https://www.virustotal.com/en/url/635696e638bef3b90215c3c0e16cf2714d2d5c2cce545dfdba64413dc41a7b59/analysis/1418083290/

We uglify the JavaScript, but do not use any other form of code manipulation.  There is some base64 logic in the JavaScript which is the only thing I can think of that would cause this to be flagged. 

Has anyone else experienced this?  Here is the JavaScript file:  http://ad.lkqd.net/serve/pure.js

Any help would be greatly appreciated.

Thanks everyone!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Avast has blocked our commercial business domain and JavaScript
« Reply #2 on: December 09, 2014, 07:51:30 AM »
Thank you for advising!

We did try to report the false positive, but did not hear back.  We will try again.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Avast has blocked our commercial business domain and JavaScript
« Reply #3 on: December 09, 2014, 07:55:55 AM »
You're welcome.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Avast has blocked our commercial business domain and JavaScript
« Reply #4 on: December 09, 2014, 03:25:34 PM »
I will flag Milos to this thread. He controls blacklists.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Avast has blocked our commercial business domain and JavaScript
« Reply #5 on: December 09, 2014, 03:58:25 PM »
If anything I think it could be a general IP block as malware is being spread via domains on that IP and I see IDS alerts for "ET SHELLCODE Possible Call with No Offset TCP Shellcode", a buffer overflow shellcode issue (this from an additonal IP via another domain widgets.getsitecontrol.com/ on that same IP server your domain shares).
So if anything I would suggest you ask avast team members for a domain exclusion.
I cannot do that because I am a volunteer website security analyzer and error-hunter with relevant knowledge,
but I am not an avast team member.

For the pure.js code you mention remember that
Quote
gzip-js is a pure JavaScript implementation of the GZIP file format.
It uses the DEFLATE algorithm for compressing data.*

Please note that since this is a pure JavaScript implementation, it should NOT be used on the server for production code. It also does not comply 100% with the standard, yet.

The main goal of this project is to bring GZIP compression to the browser.
Quote Info by T. Jameson Little

* Be aware of leakage attacks via malicious shell scripts.
Code external link: htxp://ad.lkqd.net/serve/corp_site_vast.xml -> htxp://googleads4.g.doubleclick.net/pagead/adview?ai= blurred out by me pol. Registered from within here: htxp://doam.com/50228?ckattempt=1

So let us wait for Milos's reaction,

polonus

P.S. Consider the insecurities detected here: access violarion writing location non-mutable tree-return vuln. [/size]
& injecting content from one window into a target window....etc.

And for the code you gave:
http://www.domxssscanner.com/scan?url=http%3A%2F%2Fad.lkqd.net%2Fserve%2Fpure.js
goin' to htxp://wXw.pretoriabusinessforsale.co.za etc.

D
« Last Edit: December 09, 2014, 04:48:16 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Avast has blocked our commercial business domain and JavaScript
« Reply #6 on: December 09, 2014, 04:49:06 PM »
IP is blacklisted:
http://zulu.zscaler.com/submission/show/24e4dea91674ff9e26c20391d37f7781-1418139813
Quote
No IP address of the DNS lookup for s3-website-us-east-1.amazonaws.com matches the original IP
http://multirbl.valli.org/lookup/54.231.17.60.html

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Avast has blocked our commercial business domain and JavaScript
« Reply #7 on: December 09, 2014, 05:14:48 PM »
Hi Eddy,

What you think of this domain on that IP: https://www.mywot.com/en/scorecard/facefetti.com?utm_source=addon&utm_content=rw-viewsc
-> http://sitecheck.sucuri.net/results/facefetti.com#blacklist-status  given that IP now at 174.129.25.170
Re: http://www.dnsinspect.com/facefetti.com/1418143738
this a so-called naked domain redirect via SSL for the cloud: http://wwwizer.com/naked-domain-redirect -no secure protocols supported here;
but zulu Zscaler resolves to 54.231.64.28 -> http://zulu.zscaler.com/submission/show/75949a04212a54eca2dd91fb61048c34-1418141520
Re: http://sameid.net/ip/54.231.17.60/ (the www address has the one IP, the naked domain address the other!).

D
« Last Edit: December 09, 2014, 05:50:37 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Avast has blocked our commercial business domain and JavaScript
« Reply #8 on: December 10, 2014, 10:38:03 AM »
Hi,
lkqd.net was unblocked yesterday 10AM CET. However, there is at least one IP that lkqd resolves to, 54.68.70.118, which right now is blocked and will remain blocked due to other malicious domains on that IP.