Author Topic: My sites do not contain a virus, please delete it from the blacklist!  (Read 4489 times)

0 Members and 1 Guest are viewing this topic.

Offline Асхаб

  • Newbie
  • *
  • Posts: 3
My sites www.softmaster95.ru and kvktravel.ru do not contain a virus, please delete it from the blacklist!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37105
« Last Edit: December 28, 2015, 02:07:50 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33320
  • malware fighter
Re: My sites do not contain a virus, please delete it from the blacklist!
« Reply #2 on: December 28, 2015, 02:03:30 PM »
Sucuri has another view: https://sitecheck.sucuri.net/results/www.softmaster95.ru/
Known javascript malware. Details: http://sucuri.net/malware/entry/MW:JS:GEN2?web.js.malware.fake_jquery.001
Vulnerable code to be retired: -http://www.softmaster95.ru/
Detected libraries:
jquery - 1.10.1 : (active1) -http://code.jquery.com/jquery-1.10.1.min.js?ver=1.10.1
jquery.prettyPhoto - 3.1.4 : (active1) -http://www.softmaster95.ru/wp-content/themes/invert-lite1/js/jquery.prettyPhoto.js?ver=1
Info: Severity: high
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6837&cid=3
Info: Severity: high
https://github.com/scaron/prettyphoto/issues/149
https://blog.anantshri.info/forgotten_disclosure_dom_xss_prettyphoto
jquery - 2.1.1 : -http://widgets.livetex.ru/js/app3.js?1.0.7
jquery - 2.1.4 : -http://widgets.livetex.ru/widget-ui-3.js
(active) - the library was also found to be active by running code
1 vulnerable library detected

WP update plug-in:    jquery-colorbox 4.6   latest release (4.6.1) Update required
http://www.techotronic.de/plugins/jquery-colorbox/
Warning User Enumeration is possible  :o User -Admin

blocked by Scriptblocker for me: -http://cs15.livetex.ru/js/client.js

Site given as clean here: https://urlquery.net/report.php?id=1451307343723

We cannot unblock as we are volunteers with relevant knowledge, ask for it here https://www.avast.com/contacts


polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!


Offline Асхаб

  • Newbie
  • *
  • Posts: 3

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37105
Re: My sites do not contain a virus, please delete it from the blacklist!
« Reply #5 on: December 28, 2015, 02:36:15 PM »
Virustotal does not scan website for infections, it is a blacklist check


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33320
  • malware fighter
Re: My sites do not contain a virus, please delete it from the blacklist!
« Reply #6 on: December 28, 2015, 02:40:46 PM »
That is not an active real life scan, it is a collective of scan results and may change with every update and detection.
While the site may not be immedeately malicious as such there vulnerable code should be retired for security reasons (take down zip for later reference) e.g. -http://kvktravel.ru
Detected libraries:
jquery-migrate - 1.2.1 : -http://kvktravel.ru/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
Info: Severity: medium
http://bugs.jquery.com/ticket/11290
http://research.insecurelabs.org/jquery/test/
1 vulnerable library detected
Site flagged here: https://sitecheck.sucuri.net/results/kvktravel.ru  (Is that actual or cleansed?).
Site clean: http://killmalware.com/kvktravel.ru/

Ask for a second opinion from Avast Team Members here: https://www.avast.com/contacts

Mitigate the found vulnerabilities and Avast Team may eventually unblock when they see that as fit.
When site is being unblocked that could be with a coming update.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37105
Re: My sites do not contain a virus, please delete it from the blacklist!
« Reply #7 on: December 28, 2015, 02:51:35 PM »
Quote
Site flagged here: https://sitecheck.sucuri.net/results/kvktravel.ru  (Is that actual or cleansed?).
@Polonus, your question should be answered by my html  scan above


Offline Асхаб

  • Newbie
  • *
  • Posts: 3
Re: My sites do not contain a virus, please delete it from the blacklist!
« Reply #8 on: December 28, 2015, 02:57:54 PM »
Sites exist a few years, and I do not admit that there was an attack. If there is a virus detected, then it is a mistake

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31302
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: My sites do not contain a virus, please delete it from the blacklist!
« Reply #9 on: December 28, 2015, 03:00:21 PM »
It doesn't matter how long a website exists.
It can be infected any time, any moment and within a second.

The detection is not a mistake as our scans show.
You need to fix all the problems or more and more anti-malware software will gonna block the site.

If you don't know how, hire someone who does know how to run and maintain a website.
« Last Edit: December 28, 2015, 04:28:31 PM by Eddy »

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1126
Re: My sites do not contain a virus, please delete it from the blacklist!
« Reply #10 on: December 28, 2015, 04:25:08 PM »
The site is not on a blacklist, but there is an active infection right now. That is what Avast is complaining about.
You can find more info about this specific threat for example here: https://blog.sucuri.net/2015/11/jquery-min-php-malware-affects-thousands-of-websites.html
Once you remove the malicious code, Avast will stop flagging your domain. No action is necessary on our side.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31302
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: My sites do not contain a virus, please delete it from the blacklist!
« Reply #11 on: December 28, 2015, 04:35:00 PM »
Quote
That is what Avast is complaining about.
avast isn't complaining. It is doing what it is supposed to do. Protecting the users systems. :D

Асхаб
several problems can be avoided by using a dedicated server instead of a shared one.
If there is a malicious website on a shared server and the IP gets blacklisted/blocked, it will mean that your website also will be blocked, even when it is clean.

As said before, cleanup your site to solve at least one of the problems.