Author Topic: Website False Positive?  (Read 2581 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Website False Positive?
« on: September 04, 2015, 08:54:25 PM »
I visited this web site (http://blogs.channel4.com/factcheck/factcheck-europes-migration-crisis/21469) and had mulitple warnings come up and a file called "28510" which was located in "C:\Users\[user name]\AppData\Local\Mozilla\Firefox\Profiles\[String of numbers and letters].default\cache2\doomed" moved to the virus vault with virus "HTML:Iframe-inf", yet scanning the site on Virus Total says it is clean: https://www.virustotal.com/en/url/2ab62faa3a2987bf489e30964f98870058c642325524086a9b4d8bf62cf55790/analysis/1441392162/

Is this a false positive?

EDIT: According to the pop-up the issues was http://blogs.channel4.com/factcheck/factcheck-europes-migration-crisis/21469|{gzip} but Virus Total also says there is no issue: https://www.virustotal.com/en/url/de7d659ea440fdc9190e46b4540122ca47306b790e0fda234af3a72626103aee/analysis/1441393670/
« Last Edit: September 04, 2015, 09:09:58 PM by Avq2315 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Website False Positive?
« Reply #1 on: September 04, 2015, 09:31:06 PM »
Virustotal URL scan does not scan for infections, it is a blacklist check

html only detected by avast
https://www.virustotal.com/nb/file/779800c18328bd4ab618e2b9de36096e4264e761ff0ea067c4fcd683dda2f3c3/analysis/1441396800/


« Last Edit: September 04, 2015, 10:01:29 PM by Pondus »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Website False Positive?
« Reply #2 on: September 04, 2015, 09:32:56 PM »
Zulu scaler says benign

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6669
  • volunteer
Re: Website False Positive?
« Reply #3 on: September 04, 2015, 09:35:51 PM »
I see here avast blocks the following iframe
links to  redirects this site is blocked as URL:Mal

Code: [Select]
< p> <  if​rame  src=hxxp://static.data.c4news.com/9cf25/index.html" frameborder="0" allowtransparency="true" allowfullscreen="allowfullscreen" webkitallowfullscreen="webkitallowfullscreen" mozallowfullscreen="mozallowfullscreen" oallowfullscreen="oallowfullscreen"
 msallowfullscreen="msallowfullscreen" width="100%" height="400" data-preserve-height="true"> < / if​rame > < /p>

Humm is suspect,Error 404 File not found,try to clean.
« Last Edit: September 04, 2015, 10:01:39 PM by jefferson sant »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Website False Positive?
« Reply #4 on: September 04, 2015, 10:57:14 PM »
This is what F-secure lab say

==================================================
The file is not malicious. The links used in the iframe are clean.
==================================================


REDACTED

  • Guest
Re: Website False Positive?
« Reply #5 on: September 04, 2015, 11:09:32 PM »
Ok, thank you for the replies.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Website False Positive?
« Reply #6 on: September 04, 2015, 11:23:51 PM »
Jefferson Sant stumbled upon something that Avast (AOS) flags: https://www.virustotal.com/nl/ip-address/212.227.30.237/information/  (see last detected urls), so it is -static.data.c4news.com/9cf25/index.htm
that is being blocked in chrome.exe as URL:Mal. Even the Google cache of for instance: htxp://static.data.c4news.com/HuWKG/index.html. is being flagged and blocked.
Received data:
1. HTTP/1.1 403 Forbidden\r\n
Date: Fri, 04 Sep 2015 21:20:25 GMT\r\n
Server: Apache\r\n
Content-Length: 9\r\n
Content-Type: text/html; charset=iso-8859-1\r\n
\r\n
Forbidden -> http://toolbar.netcraft.com/site_report?url=+http%3A%2F%2Fwww.static.data.c4news.com

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Website False Positive?
« Reply #7 on: September 07, 2015, 10:05:26 AM »
Avast indeed complains about iframes leading to c4news.com, which we have been blocking since February. I am now unblocking c4news.com, so there should be no more warnings ;-)!