Author Topic: False Positive on a website  (Read 2926 times)

0 Members and 1 Guest are viewing this topic.

earth_grinder

  • Guest
False Positive on a website
« on: November 16, 2013, 03:09:15 AM »
Avast would not let me access a perfectly safe website called importantpics.com http://importantpics.com/1950DCPhotos/?tag=suitland-tractor-company  How can that be corrected?

avastreally?

  • Guest
Re: False Positive on a website
« Reply #1 on: November 16, 2013, 03:14:42 AM »
There is a possibility the site is hosted on malicious server
also backlisted by WOT
http://www.ipvoid.com/scan/72.167.183.42/

earth_grinder

  • Guest
Re: False Positive on a website
« Reply #2 on: November 16, 2013, 03:25:11 AM »
So, because AVG said there was malware Avast blocked the site.  Well, I had AVG and a virus or malware got through and that is why I have Avast.  So as long as I have Avast I won't be able to access that site without turning Avast off?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: False Positive on a website
« Reply #3 on: November 16, 2013, 03:36:42 AM »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: False Positive on a website
« Reply #4 on: November 16, 2013, 01:52:43 PM »
If it's a false positive,as you claim, report it to avast!.
If it's found to be clean then it will be corrected.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

earth_grinder

  • Guest
Re: False Positive on a website
« Reply #5 on: November 16, 2013, 02:57:41 PM »
Thank you for your reply.  I reported it to Avast.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: False Positive on a website
« Reply #6 on: November 16, 2013, 03:06:39 PM »
It shows the hideme redirect

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: False Positive on a website
« Reply #7 on: November 16, 2013, 04:02:54 PM »
There is also this suspicious file:
/index.html
Severity:    Potentially Suspicious
Reason:    Detected unconditional redirection to external web resource.
Details:   <meta http-equiv="refresh" content="6;URL=htxp://www.fsmphoto.com">
Threat dump:   View code
File size[byte]:    2081
File type:    ASCII
MD5:    05DC439D88CF3B93EBE5CAE426DCA120
Scan duration[sec]:    0.002000

This is also given as a code hick-up there:
suspicious: maxruntime exceeded 10 seconds (incomplete) 0 bytes
s0.wp dot com/wp-content/js/devicepx-jetpack.js?ver=201346 benign
[nothing detected] (script) s0.wp dot com/wp-content/js/devicepx-jetpack.js?ver=201346
     status: (referer=importantpics.com/1950DCPhotos/?tag=suitland-tractor-company)saved 9153 bytes 2e2eeb3b5db8c4955a7786324c70a7c6cb559afd
     info: [decodingLevel=0] found JavaScript
     error: undefined variable document.body.style
     error: line:1: SyntaxError: missing ; before statement:
          error: line:1: var document.body.style = 1; (Expected '.')
          error: line:1: ....^
     suspicious:

The hide-me malcode resides in Decoded Files
30dc/175bb951d094ca784643da8f311db5f89b1d from importantpics dot com/1950DCPhotos/?tag=suitland-tractor-company (20815 bytes, 449 hidden) download

PHP vuln. for site: http://www.cvedetails.com/vulnerability-list/vendor_id-74/product_id-128/version_id-36749/PHP-PHP-5.1.6.html
(local file inclusion exploit)

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!