Author Topic: my site is denied  (Read 2435 times)

0 Members and 1 Guest are viewing this topic.

lucio

  • Guest
my site is denied
« on: June 25, 2012, 09:35:07 PM »
Help me my site is denied for avast mfcp.homelinux.com

Infection Details
URL:   hxtp://mfcp.homelinux.com/
Process:   C:\Archivos de programa\Mozilla Firefox\...
Infection:   URL:Mal

I can not access, maintenance had a script that made my domain is blocked ..

 help to unlock my users can not enter.
« Last Edit: June 25, 2012, 11:22:26 PM by Milos »

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5666
  • Spartan Warrior
Re: my site is denied
« Reply #1 on: June 25, 2012, 10:49:57 PM »
Hi lucio,

urlquery here:  http://urlquery.net/report.php?id=75459  Screenshot in upper right is actual url page.  Says page is working properly but has yet to be configured.  Shows Fedora server page.

zulu here:  http://zulu.zscaler.com/submission/show/f8b7943673eb2c66fa4e1ed61c1e1ee3-1340655779  Suspicious link found in domain history.

urlvoid here:  http://www.urlvoid.com/scan/mfcp.homelinux.com/  avg threat labs here:  http://www.avgthreatlabs.com/sitereports/domain/mfcp.homelinux.com/

securi site check here:  http://sitecheck.sucuri.net/results/mfcp.homelinux.com/

Please make url non-clickable as in wXw or hxxp: to protect innocent users here.

« Last Edit: June 25, 2012, 10:51:36 PM by mchain »
Windows 10 Home 64-bit 22H2 Microsoft Windows Defender - Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.4.6112 (build 24.4.9067.762) UI version 1.0.803

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: my site is denied
« Reply #2 on: June 25, 2012, 11:20:18 PM »
Hi mchain,

Thanks for that extensive check. Your contributions are very welcome here, and mutually inspiring.
Therefore  I like this corner of the forums, I really do. How much insight it has already brought us all.

Just two additional remarks on a side note for what you report here, my friend:

1. Originally this was flagged by Norton Safe Web for "uklatt.homelinux dot com", and so all of homelinux dot com came under suspicion.
The link to  hxtp://fedoraproject.org/  recently resulted in the infection with two worms according to Google's Safebrowsing, 

2.
Quote
Also /sbin/init  on fedora is has been reported as infected with the Suckit rootkit but this could not be proven either
and could well be a false positive or false negative rather,
Quote
(quote tahen from a report by Beartooth on fedura's user-list june 7 2012),

polonus

« Last Edit: June 25, 2012, 11:23:59 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: my site is denied
« Reply #3 on: June 25, 2012, 11:33:05 PM »
I am shown a record that malware was live on this site for 0.1 hours 2012-06-25 22:36:15.

Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33921
  • malware fighter
Re: my site is denied
« Reply #4 on: June 25, 2012, 11:50:21 PM »
Hi !Donovan,

Right you are, my friend,  and sites for that domain has been spreading the following flaws of malware: unknown html and unknown executable malware, Trojan.Generic.KD.17597, PHP/BackDoor.AR,  Virus.PHP.Small!IK, 5 instances of Win32.SuspectCrc!IK, now all response dead, various IP sites for that domain were being taken down as well. So it could well have been a general domain block.

Sitevet report for the AS for that IP:
AS Name: Uninet S.A. de C.V.
IPs allocated: 12955024
Blacklisted URLs: 23

Hosts...
...malicious URLs? Yes 
...badware? Yes 
...Current Events? Yes 

If despite of all this you might feel your website is secure, then there is an on-line contact form, http://www.avast.com/contact-form.php?loadStyles for:  * Sales inquiries; Technical issues; Website issues; Report false virus alert in file; Report false virus alert on website; Undetected Malware; Press (Media), issues.

polonus
« Last Edit: June 25, 2012, 11:54:53 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!