Author Topic: Site blocked - MAL:Url - but can't find any infection  (Read 15276 times)

0 Members and 1 Guest are viewing this topic.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89168
  • No support PMs thanks
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #15 on: July 15, 2013, 03:31:44 PM »
Having switched host, it may take a little time before all DNS servers reflect your new IP address - Strange that it is still present on a .php file that you can't find. I would check your php templates and see if there isn't something in there inserting and running the q.php file on page creation.

I visited the site and got a network shield alert, but if I disable the network shield I get an alert on the home page, so there is something present and not just a block on IP address. No reference to the file you mentioned.

I captured and uploaded the element that avast was alerting on to virustotal, VT Results, only avast alerting. But it is a script injection it shows and I can't see any script tags on that page which appear to be pointing at malicious sites of calling a .php page.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #16 on: July 15, 2013, 03:55:28 PM »
Hi nicholosophy,

This should not appear in your code:  - wp-admin/admin-ajax.php?action=wordfence_logHuman&hid=EB7BA865DC8DC9C09DCEB364AE8F48F1
You may want to create a robots.txt file that blocks access to /wp-admin/ so Google doesn’t index these and other internal URL

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

nicholosophy

  • Guest
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #17 on: July 16, 2013, 03:09:19 AM »
Thanks. robots.txt added.

Feel like I'm hitting my head against a wall. If anyone else spots anything I'll do whatever I need to do to clean the site/server.

Last thing I want is an infected server or site.

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6674
  • volunteer

nicholosophy

  • Guest
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #19 on: July 16, 2013, 03:47:11 AM »
Site is listed as suspicious by mcafee

http://www.siteadvisor.com/sites/fancyladyindustries.com

Blackhole Exploit Kit

http://www.avgthreatlabs.com/website-safety-reports/domain/fancyladyindustries.com/

Thanks. Asked Mcafee to review and avg says it is clean now but wasn't 16 days ago. So that's something...

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #20 on: July 16, 2013, 01:47:54 PM »
Site has been unblocked by avast I assume, because I do not see any alerts now,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

nicholosophy

  • Guest
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #21 on: July 16, 2013, 01:52:57 PM »
Site has been unblocked by avast I assume, because I do not see any alerts now,

polonus

Can I ask what version db update you have? I'm still getting alerts with 130716-0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #22 on: July 16, 2013, 02:04:36 PM »
Same, you are right it is still being blocked...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #23 on: July 16, 2013, 05:12:46 PM »
Has anything been done to solve the issue with q.php?
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

nicholosophy

  • Guest
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #24 on: July 16, 2013, 05:51:03 PM »
Has anything been done to solve the issue with q.php?

I've replaced core, theme and plugin files with fresh downloaded versions; scanned the site with clamav, maldet, wordfence and others; moved from shared server to one I control and locked down the firewall; checked the database for suspicious code.

If there is malware on the site, I don't know of it and I'm happy to be pointed to it. And if there is something, some tips on how to clean it up would be useful too.

The thing now is that since the server is blacklisted, not just the domain, clean-mx lists another domain as infected. I've taken the same steps as noted above for that site so it should be clean as well.

It's frustrating because I want it clean and I want it secure. I appreciate the advice I've been given so far.
« Last Edit: July 16, 2013, 05:53:12 PM by nicholosophy »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89168
  • No support PMs thanks
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #25 on: July 16, 2013, 06:28:02 PM »
Have you checked all of the script tags, as I still get an alert by the web shield (if the network shield is disabled) and it is the same alert HTML:Script-inf which is a suspect script, that avast thinks was injected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #26 on: July 16, 2013, 06:49:36 PM »
See here: IP block for http://www.urlvoid.com/ip/176.31.248.63 e.g. http://www.urlvoid.com/ip/176.31.248.63 on that IP
australianfatshion dot com
Even this is flagged by avast! Web Shield: http://global.sitesafety.trendmicro.com/result.php for australianfatshion dot com
as infected by JS:ScriptIP-Inf[Trj]
JS:ScriptIP-Inf is through web server infection. It exploits security faults on target host and installs the harmful script. It is designed to run automatically once it senses a visitor and instantly infects the Internet browser. There are no reports however that JS:ScriptIP-Inf can spread on local and network computers.
This scan of your site is clean: http://evuln.com/tools/malware-scanner/www.fancyladyindustries.com/rescan/
This is a code hick up I see with jsunpack:
wXw.fancyladyindustries.com/wp-content/themes/mystile/includes/js/third-party.js?ver=3.5.2 benign
[nothing detected] (script) wXw.fancyladyindustries.com/wp-content/themes/mystile/includes/js/third-party.js?ver=3.5.2
     status: (referer=wXw.fancyladyindustries.com/)saved 4392 bytes 63a630d7b1f2453844862334ebfd23797273bbcf
     info: [decodingLevel=0] found JavaScript
     error: undefined variable jQuery
     error: undefined variable a.fn
     error: line:1: SyntaxError: missing ; before statement:
          error: line:1: var a.fn = 1;
          error: line:1: ....^
     suspicious:

polonus
« Last Edit: July 16, 2013, 07:11:28 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

nicholosophy

  • Guest
Re: Site blocked - MAL:Url - but can't find any infection
« Reply #27 on: July 17, 2013, 12:01:49 AM »
Even this is flagged by avast! Web Shield: http://global.sitesafety.trendmicro.com/result.php for australianfatshion dot com
as infected by JS:ScriptIP-Inf[Trj]
JS:ScriptIP-Inf is through web server infection. It exploits security faults on target host and installs the harmful script. It is designed to run automatically once it senses a visitor and instantly infects the Internet browser. There are no reports however that JS:ScriptIP-Inf can spread on local and network computers.

Not sure how  the fact that trendmicro's site comes uip as infected is relevant. When I disable the network scan and use only web scan I get the URL:Mal on all sites on the server, so I'm guessing IP Block.

Also scanned the other site and it is clean:

http://evuln.com/tools/malware-scanner/www.australianfatshion.com/rescan/