Author Topic: Why is the website harmful?  (Read 8856 times)

0 Members and 1 Guest are viewing this topic.

Matthew_Wai

  • Guest
Why is the website harmful?
« on: April 26, 2014, 01:58:36 PM »
http://60.210.11.231/
The Web Shield deems it harmful, do you know what it is?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Why is the website harmful?
« Reply #2 on: April 26, 2014, 02:08:44 PM »
« Last Edit: April 26, 2014, 02:12:53 PM by Pondus »

Matthew_Wai

  • Guest
Re: Why is the website harmful?
« Reply #3 on: April 26, 2014, 02:20:04 PM »
http://60.210.11.231/lvs/banner_1.jpg  quoted from the Web Shield report
Perhaps this file exists.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Why is the website harmful?
« Reply #4 on: April 26, 2014, 02:23:03 PM »
it does....pic of a nice girl.  ;)     http://www.urlquery.net/report.php?id=1398515062630



« Last Edit: April 26, 2014, 02:24:38 PM by Pondus »

Matthew_Wai

  • Guest
Re: Why is the website harmful?
« Reply #5 on: April 26, 2014, 02:24:41 PM »
But it is not a banner at all!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Why is the website harmful?
« Reply #6 on: April 26, 2014, 02:27:42 PM »

Matthew_Wai

  • Guest
Re: Why is the website harmful?
« Reply #7 on: April 26, 2014, 02:31:59 PM »
It is an advertisement for express delivery of documents, the words are in Chinese.
Do you think it is false positive?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Why is the website harmful?
« Reply #8 on: April 26, 2014, 02:41:50 PM »
see my first post... from the IP ban blacklist, it seem it may have to do with spam


Matthew_Wai

  • Guest
Re: Why is the website harmful?
« Reply #9 on: April 26, 2014, 02:44:40 PM »
What do you think will happen if I visit the URL after disabling the Web Shield?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: Why is the website harmful?
« Reply #10 on: April 26, 2014, 02:55:01 PM »
What do you think will happen if I visit the URL after disabling the Web Shield?
nada i guess.... and the pic file is clean according to VT.... 5 month old scan
but dont come back complaining if i am wrong.   



https://www.virustotal.com/en/url/7426cdaf3b4e6b40da0504bb800af974cf7918f233c256d5f6d0eb6177de85d1/analysis/

https://www.virustotal.com/en/file/2bb3608eab1a013999a13b80e704606bc7793b56669354380989b66232ac5aa1/analysis/1385649338/



Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33916
  • malware fighter
Re: Why is the website harmful?
« Reply #11 on: April 26, 2014, 03:35:32 PM »
See all threats here: http://threatstop.com/checkip -> 23 minutes ago threats MODIFIED ITAR, ITAR, CHINA threat level 1.
See: Up(nil):      APNIC   CN      60.210.11.231    to 60.210.11.231   60.210.11.231   
See: http://toolbar.netcraft.com/site_report?url=60.210.11.231%2Flvs%2Fbanner_1.jpg  (Risk rate 10 out of 10 RED)
htxp://60.210.11.231/file/MDAwMDAwMDGSJcByiJiZn3rq0LglSSlmpMcl_EJPHghyPvUhjxW-2w../209c2a443f46eb26807ff78378f7ad8d17d786cd/10958773-vxd-UG&  -> https://www.virustotal.com/nl/url/486f4c473bf280bd41c5cc62f02f4272e424f7c7211f583249061b3fe93e2668/analysis/1398518686/
url after redirect: htxp://60.210.11.231/lvs/redirect.html?kne=&d=0823C937 (flagged by avast! Webshield as URL:Mal).
-> http://urlquery.net/report.php?id=1398515062630
Trying to redirects to:  htxp://www.dbank.com/ping.php?js=all?v=1.26.23"%3B  -> htxp://www.dbank.com/ping.php?js=base
Emisoft is the only one to flag next to avast! shield.

pol

P.S. Everybody should be aware of the banner abuse by Zeus: http://www.gfi.com/blog/beware-malware-banner/
link article author = Mohammed Ali  (actually old info from 2011, then new but now still actual)

D
« Last Edit: April 26, 2014, 03:40:30 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Matthew_Wai

  • Guest
Re: Why is the website harmful?
« Reply #12 on: May 07, 2014, 01:35:45 PM »
After disabling "Block malware URLs" I could download and save the banner on http://60.210.11.231/lvs/banner_1.jpg
It read "NO THREAT FOUND" after manual scanning
The URL might have been blacklisted mistakenly.

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Why is the website harmful?
« Reply #13 on: May 07, 2014, 01:54:51 PM »
Hi,
This IP was blocked 21. June 2013, 11:38 because of this file we spotted:
hxxp://60.210.11.231/file/mdawmdawmdhmzntt3gw_6vm8w34pwr1wsbqbat_3thhkqpgcslagnq../ba97b7fbf4ab948d7ceb62df1626d016fbc97/%e9%97%ae%e9%97%ae%e5%ad%a6%e5%a0%82%e8%87%aa%e5%8a%a8%e7%ad%94%e9%a2%98%e5%99%a8beta%203.85.rar?key=aaabqfhcyxi8vv6i&p=&a=4022865-af11
I hope the infection has been cleared already, so I am unblocking the IP now;-).
Honza

Matthew_Wai

  • Guest
Re: Why is the website harmful?
« Reply #14 on: May 07, 2014, 01:58:39 PM »
Do you mean avast will block a whole site just because a single file is infected?