Author Topic: My Website Is Reporting A False Positive URL:Mal  (Read 5309 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
My Website Is Reporting A False Positive URL:Mal
« on: December 03, 2014, 09:46:19 PM »
Hello,
Anytime that anyone visits  our website with Avast installed, they get the following error:

Avast Web Shield has blocked a harmful webpage or file.
Object: http://www.sliptalk.com/
Infection: URL:Mal
Process: c:\.....

Our website is www.sliptalk.com is clean according to https://www.virustotal.com/en/url/7b0e5633fea9e32dfd86d5f91cd3ef0fb4946999abfd531ba69531232ee4ec5a/analysis/.

Please let me know what we can do to unblock our site.

Thank you.

Dan
« Last Edit: December 03, 2014, 10:07:46 PM by dan55 »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37697
  • F-Secure user
Re: My Website Is Reporting A False Negative URL:Mal
« Reply #1 on: December 03, 2014, 09:59:52 PM »
Quote
Our website is sliptalk.com is clean according to
Virustotal does not scan the site for infections, it check URL against blacklists

URL:Mal means URL or IP is blacklisted for whatever reason, there can be many......

if you think it is wrong, report it to avast lab here  https://support.avast.com


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31073
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: My Website Is Reporting A False Negative URL:Mal
« Reply #2 on: December 03, 2014, 10:06:04 PM »
http://sitecheck.sucuri.net/
Unable to properly scan your site. Site returning error (40x): HTTP/1.1 403 Forbidden

https://www.webhostinghero.com/who-is-hosting/
Nameservers: n/a

http://multirbl.valli.org/lookup/104.20.27.80.html
IP is blacklisted

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37697
  • F-Secure user
Re: My Website Is Reporting A False Negative URL:Mal
« Reply #3 on: December 03, 2014, 10:06:17 PM »
Quote
My Website Is Reporting A False Negative
and it is called False Poitive if a clean file is detected as malware ..... False Negative is a malware file not detected


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37697
  • F-Secure user
Re: My Website Is Reporting A False Negative URL:Mal
« Reply #4 on: December 03, 2014, 10:08:08 PM »
Quote
http://sitecheck.sucuri.net/
Unable to properly scan your site. Site returning error (40x): HTTP/1.1 403 Forbidden
works fine here Eddy  http://sitecheck.sucuri.net/results/www.sliptalk.com/


Quote
http://multirbl.valli.org/lookup/104.20.27.80.html
IP is blacklisted
wrong IP ... the one given by VT is  104.20.25.80    http://multirbl.valli.org/lookup/104.20.25.80.html


« Last Edit: December 03, 2014, 10:10:53 PM by Pondus »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31073
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: My Website Is Reporting A False Positive URL:Mal
« Reply #5 on: December 03, 2014, 10:20:27 PM »
IP seems to keep changing.
Now Zulu says: 104.20.26.80

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37697
  • F-Secure user
Re: My Website Is Reporting A False Positive URL:Mal
« Reply #6 on: December 03, 2014, 10:25:43 PM »
IP seems to keep changing.
Now Zulu says: 104.20.26.80
Yea.....now VT give the same?....click additional information
https://www.virustotal.com/en/url/7b0e5633fea9e32dfd86d5f91cd3ef0fb4946999abfd531ba69531232ee4ec5a/analysis/1417641798/

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34039
  • malware fighter
Re: My Website Is Reporting A False Positive URL:Mal
« Reply #7 on: December 03, 2014, 11:05:55 PM »
See Javascript check: Suspicious

It is a multiple IP site. wXw.sliptalk.com,104.20.28.80,,Multiple IPs,
:none}.ngfb-buttons iframe{max-width:none}.ngfb-buttons>div{display:inline-block;vertical-align:bottom;text-align:left;line-height:20px;padd
See changing IP: 104.20.28.80 -> 100 different results here: https://www.robtex.com/q/x1?q=www.sliptalk.com%2F&l=go
Resolution failed: http://hosts-file.net/default.asp?s=www.sliptalk.com%2F -> issues: http://www.dnsinspect.com/sliptalk.com/1417643646
Web rep external link: cdn.taboola dot com -> https://www.mywot.com/en/scorecard/taboola.com?utm_source=addon&utm_content=popup
error in CDN Plug-in: cdn-cgi/styles/cf.errors.ie.css
Here again we have 190.93.250.192 is hosted on a dedicated server -> P History   32 changes on 21 unique IP addresses over 9 years
> http://whois.domaintools.com/sliptalk.com -> reported as open proxy: http://www.liveipmap.com/190.93.250.192
-> http://network-tools.com/default.asp?prog=express&host=www.sliptalk.com/
Jarida plug-in exploitable: http://nakedsecurity.com/exploit/226894.htm & http://www.exploit4arab.net/exploits/1044
Vuln. -> -http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.sliptalk.com
Blocked by extension external code-link to: htxps://cas.criteo.com/delivery/ajs.php?

polonus
« Last Edit: December 04, 2014, 12:11:19 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2297
Re: My Website Is Reporting A False Positive URL:Mal
« Reply #8 on: December 04, 2014, 08:49:24 AM »
Hello,
domain will be unblocked in next stream update.

Milos

REDACTED

  • Guest
Re: My Website Is Reporting A False Positive URL:Mal
« Reply #9 on: December 04, 2014, 02:41:03 PM »
Thanks Milos,
Do you know when the next stream update will happen?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76017
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: My Website Is Reporting A False Positive URL:Mal
« Reply #10 on: December 04, 2014, 02:42:18 PM »
Stream updates happen every few minutes.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0