Author Topic: Why our domain is blocked by avast  (Read 1883 times)

0 Members and 1 Guest are viewing this topic.


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Why our domain is blocked by avast
« Reply #1 on: September 06, 2016, 03:01:42 PM »
Here is a good reason why it is blocked :
https://sitecheck.sucuri.net/results/www.promety.net

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Why our domain is blocked by avast
« Reply #2 on: September 06, 2016, 04:19:00 PM »
There is a redirect on that page:
URLs that redirect found in: -http://www.promety.net/

1: -http://www.primiti.com/script/primiti.js ->-http://www.primiti.com/script/primiti.js?rc=.asp
This page cannot be found? code 302 - Carrefour Internet -> https://asafaweb.com/Scan?Url=www.primiti.com
Also Fail and warnings.

See: https://asafaweb.com/Scan?Url=www.promety.net%2Fweblg.asp%3Fi_id%3D7659
Fial and warnings.

Check code -https://aw-snap.info/file-viewer/?tgt=http%3A%2F%2Fwww.promety.net&ref_sel=GSP2&ua_sel=ff&fs=1

Unblock for researchers and developers that know how to evalute the report from redleg's fileviewer only!

Consider -http://www.domxssscanner.com/scan?url=http%3A%2F%2Fwww.promety.net%2Fweblg.asp%3Fi_id%3D7659
landing at: -http://ban-ex.primiti.com/initredir.asp?s=11535
http://toolbar.netcraft.com/site_report?url=http://ban-ex.primiti.com 
A kind of website traffic-doubler?

polonus
« Last Edit: September 06, 2016, 04:28:35 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Why our domain is blocked by avast
« Reply #3 on: September 06, 2016, 04:32:25 PM »
We spotted this URL being accessed in our userbase: tpiron.promety[.]net/counter/?ad=1dp41llefwctxmrzjoawlhndgvyhhhkqtz&id=tzua9rmqgd7og0nmilcmed06-a1oxtzdapwqri-shndfznh5vknssfpomht9frlre5lihosicv0&rnd=21
Looks like Locky to me.

REDACTED

  • Guest
Re: Why our domain is blocked by avast
« Reply #4 on: September 06, 2016, 11:16:10 PM »
Hi,
we deleted this site :

tpiron.promety[.]net/counte

Can you reactivate promety.net ?

Thanks

Michel Morin

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Why our domain is blocked by avast
« Reply #5 on: September 07, 2016, 12:20:40 PM »
Hi,
We have seen traffic to tpiron.promety[.]net even today, though not to /counter/.
I am unblocking promety[.]net right now, but please do take security seriously, or the whole domain might be blocked again in the future.