Author Topic: false alarm on domain  (Read 6560 times)

0 Members and 2 Guests are viewing this topic.

idreams

  • Guest
false alarm on domain
« on: July 05, 2012, 03:41:27 PM »
hello good afternoon all,

i need a big help.. i dont why but avast is treating our website like "malicious url blocked" even i have changed the hosting to another server
tried with out any files

when ever i type the domain in the browser it is giving me the warning.. this is happening only with avast

this is the url of our company website www.eximlinks.in

thanks

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: false alarm on domain
« Reply #1 on: July 05, 2012, 04:19:44 PM »
welcome to the forum. i suggest you write to the avast support and send them a ticket about this problem.
http://www.avast.com/contact-form.php?loadStyles

according virustotal scan it shows to be clean. but if avast is reporting it to be malware it could be something in the code.
https://www.virustotal.com/url/0dd06c44e8b0212bacb0b4514331f7796e373d7b671c0617915fc046215e1354/analysis/1341497690/
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: false alarm on domain
« Reply #2 on: July 05, 2012, 04:24:26 PM »
according to WOT it was/is listed at phishtank.com

http://www.urlvoid.com/scan/eximlinks.in/


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: false alarm on domain
« Reply #3 on: July 05, 2012, 04:36:38 PM »
Hi Pondus,

Nothing on Phis Tank, and nothing on Sucuri.
But I found site with 'searchmagnified.com' d='manual category browser Hijacker
Searchmagnified.com Hijacker is classified as an invasive browser hijacker which adjusts your homepage, search page and favorites to hxtp://Searchmagnified.com and various unwanted sites. It is able to get into your operating system without your concert.
Content returned: 1: test

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

idreams

  • Guest
Re: false alarm on domain
« Reply #4 on: July 05, 2012, 06:21:28 PM »
should i contact avast support team or what should i do know ?
the replies are confusing.. and i am not so sure about what does this mean
MyWOT   05-07-2012, 12:01:25    DETECTED

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: false alarm on domain
« Reply #5 on: July 05, 2012, 06:24:38 PM »
There is an on-line contact form, http://www.avast.com/contact-form.php?loadStyles for:  * Sales inquiries; Technical issues; Website issues; Report false virus alert in file; Report false virus alert on website; Undetected Malware; Press (Media), issues.

- If you are reporting an FP, then you get another input field open, enter the web URL for the site you wish to submit for review (Network Shield), etc. A link to this topic also wouldn't hurt.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: false alarm on domain
« Reply #6 on: July 05, 2012, 06:33:10 PM »
When avast receives your report and the site indeed seems secure, they are known to solve these issues rather quickly, sometimes with a coming update.
So just report as DavidR told you how to and wait,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

idreams

  • Guest
Re: false alarm on domain
« Reply #7 on: July 05, 2012, 06:35:39 PM »
thank you so much guys. i have sent a request for review to the support team

lets see what they have to say..

really appreciate your help in this matter. never saw this much pro active community..

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: false alarm on domain
« Reply #8 on: July 05, 2012, 07:16:07 PM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

idreams

  • Guest
Re: false alarm on domain
« Reply #9 on: July 06, 2012, 04:39:22 PM »
i guess the problem has been solved.
can anyone please check our domain and confirm it please www.eximlinks.in

thanks

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: false alarm on domain
« Reply #10 on: July 06, 2012, 05:05:03 PM »
Well it isn't alerting, but there isn't a whole lot there just a test page 'literally,' see image.

But since this was a Network Shield alert on a malicious site, that looks to have been corrected.

However WOT still needs to be sorted as it has historical data giving the site a bad Rep, see http://www.mywot.com/en/scorecard/eximlinks.in, so you might need to contact them also.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: false alarm on domain
« Reply #11 on: July 06, 2012, 06:42:17 PM »
Nothing much I can see: http://urlquery.net/report.php?id=83053
Content returned by request for: htxp://www.eximlinks.in/
1: test

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

true indian

  • Guest
Re: false alarm on domain
« Reply #12 on: July 06, 2012, 06:55:22 PM »
Hi all,

the IP to the site eximlinks.in is 184.173.229.96 which gives no alert on URLQuery so pol is correct..

However there is a bad boy on: 184.173.0.171

see: http://urlquery.net/report.php?id=83890

this is a IP block for 184.173.xxx [xxx=any ransom numbers]...this will need analysis from a virus analyst to examine
« Last Edit: July 06, 2012, 06:57:47 PM by true indian »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: false alarm on domain
« Reply #13 on: July 06, 2012, 07:01:27 PM »
Hi true indian,

That one is actually being reported in the Blackhole URL thread here...http://forum.avast.com/index.php?topic=100591.msg806005#msg806005
A sheer coincidence or the reason for the initial IP block, who will tell?
Arrticle author Fraser Howard did a write up about this particular one here in a Sophos Technical Paper:
http://nakedsecurity.sophos.com/exploring-the-blackhole-exploit-kit-6/   I mean the "main.php?page= " Blackhole detection variant....
Checked against realtime lists the IP is not being blocked by any now (or going under the radar)..

polonus
« Last Edit: July 06, 2012, 07:37:15 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

idreams

  • Guest
Re: false alarm on domain
« Reply #14 on: July 06, 2012, 10:30:29 PM »
how can we contact WOT
i dont see any contact us form in their website