Author Topic: I'm sure this is just a false alert. Just wanted to talk about it.  (Read 3813 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
I bought a new Razer headset today. They told me to download a surround sound program from their official site: www.razerzone.com/surround/ . So I downloaded and tried to install it... then Avast popup comes and tells me that it's a malware. I already sent a report about it. It should be false alarm but now Avast won't let me install it. I have attached a picture of that Avast popup.
« Last Edit: May 25, 2016, 07:13:04 PM by kz91 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37623
  • Not a avast user
Re: I'm sure this is just a false alert. Just wanted to talk about it.
« Reply #1 on: May 25, 2016, 07:50:09 PM »
The popup show a bloked URL not program

URL:Mal = Blacklisted URL or IP

websites seems to be infected or have leftover script from a removed infection? >>  https://sitecheck.sucuri.net/results/www.razerzone.com

Zulu URL Risk Analyzer
http://zulu.zscaler.com/submission/show/875ee6ae1287acceb1507aa837eeb7d3-1464200050


« Last Edit: May 25, 2016, 08:19:14 PM by Pondus »

REDACTED

  • Guest
Re: I'm sure this is just a false alert. Just wanted to talk about it.
« Reply #2 on: May 25, 2016, 08:16:17 PM »
Oh I see...Actually that popup came up when the installer started to update or something. Even big company like Razer can get their sites infected? Damn. Oh I guess I have to wait until they clean up their site.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37623
  • Not a avast user
Re: I'm sure this is just a false alert. Just wanted to talk about it.
« Reply #3 on: May 25, 2016, 08:18:30 PM »
Quote
Actually that popup came up when the installer started to update or something
Seems it try to contact a blacklisted URL

Have notified avast, check back for a reply tomorrow


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33938
  • malware fighter
Re: I'm sure this is just a false alert. Just wanted to talk about it.
« Reply #4 on: May 25, 2016, 11:36:46 PM »
Hi kz91 and Pondus,

Whatever the outcome, they have some code to mitigate and retire anyway (zip file for later reference):
-http://www.razerzone.com
Detected libraries:
jquery - 2.1.4 : (active1) -https://ajax.googleapis.com/ajax/libs/jquery/2.1.4/jquery.min.js *
Info: Severity: medium
https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
jquery - 1.6.4 : -http://cdn.optimizely.com/js/529790331.js  **
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
(active) - the library was also found to be active by running code
2 vulnerable libraries detected

This external script ** has questionable web rep as tracking script: https://www.mywot.com/en/scorecard/cdn.optimizely.com?utm_source=addon&utm_content=rw-viewsc

That there are some isssues with external third party scripts is shown from these test results:
https://sritest.io/#report/5d8d737a-2884-4781-b311-0c0ad575fd95
3 Stylesheet issues and 3 Script issues with missing SRI hashes.
<script src="https://ajax.googleapis.com/ajax/libs/jquery/2.1.4/jquery.min.js"></script>    Missing SRI hash   *
<script src="http://assets.razerzone.com/eeimages/assets/v4/tether.min.js"></script>    Missing SRI hash
<script src="http://assets.razerzone.com/eeimages/assets/v4/bootstrap.min.js"></script>    Missing SRI hash

Wonder whether it is these iFrames ***: Any iframes? Yes there are, they are:

<iframe src="//www.googletagmanager.com/ns.html?id=GTM-6ZK3" height="0" width="0" style="display:none;visibility:hidden"></iframe>
<iframe src="//www.googletagmanager.com/ns.html?id=GTM-M6JKNF" height="0" width="0" style="display:none;visibility:hidden"></iframe>
Normally wXw.googletagmanager.com  comes blocked by adblockers ***

But wait for the final verdict from Avast Team Member,

polonus (volunteer website security analyst and website error-hunter)
« Last Edit: May 25, 2016, 11:45:51 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: I'm sure this is just a false alert. Just wanted to talk about it.
« Reply #5 on: May 25, 2016, 11:41:35 PM »
Hi, we blocked cfbeta.razersynapse.com/1457950589rzrmodrazer_common_config_v2.57.301.6_v2.exe
because we have spotted malware being downloaded from it: https://www.virustotal.com/en/file/ec54dc73a6283b5a460b12d4af55f8f0a6704917223ad69e9622e8f275f3e391/analysis/1399286599/

Most likely this was an infection on the user's end, and not a threat to all users.
I have unblocked the URL, and will alter the rule so it does not block the URL when the file has been infected on the way.
Thanks for reporting it!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33938
  • malware fighter
Re: I'm sure this is just a false alert. Just wanted to talk about it.
« Reply #6 on: May 25, 2016, 11:52:46 PM »
Thanks, HonzaZ,

Thanks for reporting that  there is no real immediate malware threat.
Seems now they only have to retire whatever script  has been flagged,
and also generate the missing SRI hashes,
whenever these could be implemented without causing issues elsewhere,
while hxtp://cdn.optimizely.com/js/529790331.js  will stay a bit of a controversial item there.
Oh and I'd rather block this running: htxp://i.kissmetrics.com/i.js (online tracker)
and htxp://doug1izaerwt3.cloudfront.net as another ad- and tracking server (found in adblocker's easylist).

polonus
« Last Edit: May 26, 2016, 12:03:31 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: I'm sure this is just a false alert. Just wanted to talk about it.
« Reply #7 on: May 26, 2016, 02:48:33 PM »
So what now? Is this my problem or Razer's? I didn't properly understand your replies  ;D . Should I also tell Razer about this or?

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: I'm sure this is just a false alert. Just wanted to talk about it.
« Reply #8 on: May 26, 2016, 02:55:12 PM »
Not yours, not Razer's, but ours... Everything should be fixed already :)

REDACTED

  • Guest
Re: I'm sure this is just a false alert. Just wanted to talk about it.
« Reply #9 on: May 26, 2016, 03:01:27 PM »
So...it was a false alert after all? Avast just thought it's bad URL?

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: I'm sure this is just a false alert. Just wanted to talk about it.
« Reply #10 on: May 26, 2016, 03:09:09 PM »
Precisely. We have spotted a user with a totally malicious file that came from that domain, but what most likely happened was that the file was infected on the way, and there is no reason to block the domain because of that.