Author Topic: Is this site really URL Mal infected?  (Read 4899 times)

0 Members and 1 Guest are viewing this topic.

wisteria

  • Guest
Is this site really URL Mal infected?
« on: December 05, 2012, 07:54:12 PM »
Hello all,

Apologies if this question has already been asked, but whenever I try to visit the following website, I receive the URL Mal warning.  Friends who have computers protected with other anti virus software such as AVG are not receiving this warning and say there is nothing wrong with the site and that Avast is over-reacting.

wxw.bigtoyswarehouse.co.uk

Any information about this would be very welcome as I'm not especially computer literate.

Thanks.   
« Last Edit: December 06, 2012, 11:44:56 AM by Milos »

Offline midnight

  • Massive Poster
  • ****
  • Posts: 2473
Re: Is this site really URL Mal infected?
« Reply #1 on: December 05, 2012, 08:05:11 PM »
I just clicked on the link and got the red pop up, saying the site was malicious, clicked on more details and showed that I had just dodged a bullet.  Did you read the details?
« Last Edit: December 05, 2012, 08:12:04 PM by -midnight »
.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Is this site really URL Mal infected?
« Reply #2 on: December 05, 2012, 08:11:49 PM »
URL:mal means the URL is on a blocklist

if you think this is wrong, you can report it here   http://www.avast.com/contact-form.php?


urlquery - IDS alert by sucuricata _ FILEMAGIC Macromedia Flash data (compressed),
http://urlquery.net/report.php?id=317682
« Last Edit: December 05, 2012, 08:20:19 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: Is this site really URL Mal infected?
« Reply #3 on: December 05, 2012, 10:40:07 PM »
No alerts here: http://urlquery.net/report.php?id=318597
Some code hick-ups found up by Quttera's heuristic scanner in the following 4 files.
This does not mean that these should be malicious per se, only have anomalities to make them stand out from the rest of the files there...

all-include.js
File size[byte]:    173286
Threat type:   Potentially Suspicious
Details:    Detected potentially suspicious content.
Reason:    Detected potentially suspicious initialization of function pointer to JavaScript method writeln <code> __tmpvar1699510875 = writeln; <code/>
MD5:   54D6DF7CB5DAC605790C363683027FB8

/include/js/DD_roundies_0.0.2a-min.js
File size[byte]:    8429
Threat type:   Potentially Suspicious
Details:    Detected potentially suspicious content.
Reason:    Detected potentially suspicious initialization of function pointer to JavaScript method writeln <code> __tmpvar183615581 = writeln; <code/>
MD5:   B8B9F888948D72009322CFD0FEE48E0E

chatserver.comm100 dot com/js/LiveChat.js?siteId=128909&planId=2104&partnerId=-1  (web rep four greens)
File size[byte]:    26398
Threat type:   Potentially Suspicious
Details:    Detected hidden reference to external web resource.
Reason:    Detected generation of hidden DOM element [iframe].
MD5:   8584A6F23E4FC7454E18CFF2237DAF67
Scan duration[sec]:    0.777000
s7.addthis dot com/js/250/addthis_widget.js#pubid=ra-4ec907345df988e1
File size[byte]:    6721
Threat type:   Potentially Suspicious
Details:    Detected hidden reference to external web resource.
Reason:    Detected generation of hidden DOM element [iframe].
MD5:   9ADEDD301F5AA4594680A852630E56AB

source: Quttera's scan data

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

wisteria

  • Guest
Re: Is this site really URL Mal infected?
« Reply #4 on: December 06, 2012, 12:25:51 AM »
Thank you for your insight guys!  I didn't read the explanation offered by Avast regarding the nature of URL Mal, but will do so.  I was simply puzzled that the issue wasn't coming up in other anti virus software. 

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Is this site really URL Mal infected?
« Reply #5 on: December 06, 2012, 12:34:17 AM »
I just clicked on the link and got the red pop up, saying the site was malicious, clicked on more details and showed that I had just dodged a bullet.  Did you read the details?

The information on that page is more generic and not very helpful if you are looking for a detailed analysis. That requires the use of other analysis tools.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: Is this site really URL Mal infected?
« Reply #6 on: December 07, 2012, 01:13:19 PM »
Here you see now that the site has been migrated to another IP without the IDS alerts that were previous given for the former IP location: http://urlquery.net/report.php?id=317682
So I think the site has been cleansed, however the IP migrated to has instances of  HTML:Script-inf malware for other domains there, which avast should detect because it has a very good reputation on detection of thes types of malware: https://www.virustotal.com/file/17650ad4d4808528ab176a6765aae1eb5ba3e73288d7885f984467c878240771/analysis/
Some malware from that IP is long overdue and has been on for more than 1042.3 hrs... JS/Agent.ebz, JS/iFrame.BO.1,  JS/iFrame.czo,  JS/iFrame.XA.1, HTML/Rce.Gen3 etc......


polonus
« Last Edit: December 09, 2012, 12:34:00 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!