Author Topic: False Positive on want2race.co.uk  (Read 3739 times)

0 Members and 1 Guest are viewing this topic.

brainstormdesign

  • Guest
False Positive on want2race.co.uk
« on: April 25, 2014, 04:37:18 PM »
Hi,

Can you please check to see if there is a false positive on the following URL / Server:
http://www.want2race.co.uk / 185.17.181.14

We don't seem to have issues with some of our other domains on the same server.

Thanks

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: False Positive on want2race.co.uk
« Reply #1 on: April 25, 2014, 04:58:04 PM »
The problem seems to be with cutwel-tools.co.uk

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6669
  • volunteer
Re: False Positive on want2race.co.uk
« Reply #2 on: April 25, 2014, 05:48:59 PM »


Mcafee This link is suspicious

http://www.siteadvisor.com/sites/want2race.co.uk

 ip in blacklist

http://www.ipvoid.com/scan/78.129.250.40/

http://support.clean-mx.de/clean-mx/viruses.php

it seems like"hxxp://want2race.co.uk/ebaca1bbdbc21f3da9e1cda26c0b83fb/q.php"   blackhole exploit kit

can you confirm that this clean ?
« Last Edit: April 25, 2014, 05:52:51 PM by jefferson santiag »

brainstormdesign

  • Guest
Re: False Positive on want2race.co.uk
« Reply #3 on: April 25, 2014, 06:05:52 PM »
The problem seems to be with cutwel-tools.co.uk

Sorry, I'm not sure what this means?

brainstormdesign

  • Guest
Re: False Positive on want2race.co.uk
« Reply #4 on: April 25, 2014, 06:15:34 PM »


Mcafee This link is suspicious

http://www.siteadvisor.com/sites/want2race.co.uk

 ip in blacklist

http://www.ipvoid.com/scan/78.129.250.40/

http://support.clean-mx.de/clean-mx/viruses.php

it seems like"hxxp://want2race.co.uk/ebaca1bbdbc21f3da9e1cda26c0b83fb/q.php"   blackhole exploit kit

can you confirm that this clean ?

The /q.php definitely doesn't exist.
The IP Address on ipvoid is also wrong, the IP is:
Address lookup
canonical name    want2race.co.uk.
aliases    
addresses    185.17.181.14

I'll check the McAfee thing and get that sorted.

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6669
  • volunteer
Re: False Positive on want2race.co.uk
« Reply #5 on: April 25, 2014, 06:35:03 PM »

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6669
  • volunteer
Re: False Positive on want2race.co.uk
« Reply #6 on: April 26, 2014, 04:09:27 PM »
Hi,

Can you please check to see if there is a false positive on the following URL / Server:
http://www.want2race.co.uk / 185.17.181.14

We don't seem to have issues with some of our other domains on the same server.

Thanks

The URL was unblocked in update VPS 140426-0.

« Last Edit: April 28, 2014, 12:28:13 AM by jefferson santiag »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: False Positive on want2race.co.uk
« Reply #7 on: April 26, 2014, 04:34:25 PM »
Hi 185.17.181.14 is not flagged at urlquery dot net -> http://urlquery.net/report.php?id=1398521749908
Badness history of IP: https://www.virustotal.com/nl/ip-address/185.17.181.14/information/
When I scan the site I get a server redirect status: Code: 404,  Content cannot be read!
Extensive header ifo spread: apache/2.2.25 (unix) mod_ssl/2.2.25 openssl/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 frontpage/5.0.2.2635
-> Unable to properly scan your site. Site returning error (40x): HTTP/1.1 404 Not Found

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6669
  • volunteer
Re: False Positive on want2race.co.uk
« Reply #8 on: April 28, 2014, 12:28:34 AM »
Looks like it was not cleaned  not  is clean server
will remain blocked until you solve

Reporting for vírus analyst

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: False Positive on want2race.co.uk
« Reply #9 on: April 28, 2014, 01:16:56 AM »
This was the vulnerability that was exploited on mentioned site: http://security.stackexchange.com/questions/44705/is-requestid-vulnerable-to-sql-injection
info credits go to zer0fl4g, bobnince & HamZa,
I gave the vulnerable script as an  attached image.

pol

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!