Author Topic: False positive website blocked  (Read 2036 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
False positive website blocked
« on: April 20, 2016, 07:54:14 PM »
Please check www.marciomarinho.com.br for false positive avast block.
This is a simple made website made by me and avast keep blocking it.
Thank you!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: False positive website blocked
« Reply #1 on: April 20, 2016, 08:14:08 PM »
well, Bitdefender dont like it
https://virustotal.com/en/url/fd18408a59215af558ba9ea0e0aa33c85b1aa97f2a699d193c79ddaa7da4b426/analysis/1461175985/

IP history is bad, multiple domains (enormus amount) and many are blacklisted
https://virustotal.com/en/ip-address/191.252.4.11/information/
click more button under list(s) for more info


« Last Edit: April 20, 2016, 08:25:26 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: False positive website blocked
« Reply #2 on: April 20, 2016, 08:36:25 PM »
Insecurity custom errors- Fail: https://asafaweb.com/Scan?Url=www.marciomarinho.com.br
and 2 warnings. Nameserver DROWn vulnerable: https://test.drownattack.com/?site=ns1.locaweb.com.br
This should not be online accessible: http://orion02.locaweb.com.br/
This is an IP block because of the IP badness history: https://www.virustotal.com/nl/ip-address/191.252.4.11/information/
Insecurity in jQuery code: -http://www.marciomarinho.com.br
Detected libraries:
jquery - 1.8.3 : -http://musecdn2.businesscatalyst.com/scripts/4.0/jquery-1.8.3.min.js
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
Info: Severity: medium
https://github.com/jquery/jquery/issues/2432
http://blog.jquery.com/2016/01/08/jquery-2-2-and-1-12-released/
1 vulnerable library detected

Error: Domain has no A records

Server address has bad WOT web rep: https://www.mywot.com/en/scorecard/ns1.locaweb.com.br?utm_source=addon&utm_content=rw-viewsc

Flagged for Spamming: reported as
Quote
12-02-2013
FedEx Identity Theft Scam
Unsolicited Spam Originating From: Poland (91.213.96.32)
Originating Network(s): telvinet.pl
Date Received: 2/12/2013
Click Link: -http://www.oncocentro.com/tmp/bkhi71.php?receipt_print=825_693766498
Responding IP: 187.45.193.158
Name Servers: -ns1.locaweb.com.br, -ns2.locaweb.com.br
Contents of Spam:
Reply-To: "Manager

polonus
« Last Edit: April 20, 2016, 09:25:21 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: False positive website blocked
« Reply #3 on: April 22, 2016, 12:25:51 PM »
Unblocked ;)

BTW, it was blocked more than 3 years ago :)