Author Topic: URL Blocked by webshield  (Read 2213 times)

0 Members and 1 Guest are viewing this topic.

Offline neorosis

  • Newbie
  • *
  • Posts: 2
URL Blocked by webshield
« on: December 01, 2019, 12:54:23 PM »
From today I am getting Popups saying URL blocked by Avast. The process is svchost.exe
The URL is to the domain http://referently.club

The exact full URL is:
http://referently.club:8080/?tr=tNVOV1rk5ydiaEu13_PF8B--aW5ilgWxnFISE1x5BQyC3aqNhxyAt9gQd9BhNjLHX4z27xeBnN1kwL9BcYJEyDp7O3x5VF2s-hWBoSDQmQbAU-X_8esQE2A4olPcC_KEOuex7OlkUryd5ilUOsBlTPQxuzG5KkG2vKGuAlfaveTN0TwkDbkzm4jzf6QFC84j8TxV99zTXCnSuXnp7OVoqg0sdzVR1W0cU3r

Now I have tried to look for some process piggy banking on svchost.exe but not found any suspicious program or service. Boot time scan is clean. Malwarebytes scan is clean. Nothing suspicious at autorun or services list.

I disabled Avast for a few seconds and pasted this URL in browser which downloads a file named file.dat which Avast detects as generic malware. Virustotal analysis:
https://www.virustotal.com/gui/file/87cc748c326a03e6bbacbe486409d2964113fb33a410692b30465207bee8baba/detection

Google doesn't throw up any similar domain.

Will be glad to know where to look to eliminate what I suspect is well hidden trojan downloader.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76036
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: URL Blocked by webshield
« Reply #1 on: December 01, 2019, 01:08:55 PM »
Start a topic in V&W and post your logs there: https://forum.avast.com/index.php?action=post;board=4
Instructions (basic diagnostic logs): https://forum.avast.com/index.php?topic=194892.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline neorosis

  • Newbie
  • *
  • Posts: 2
Re: URL Blocked by webshield
« Reply #2 on: December 01, 2019, 01:38:18 PM »
OK Doing that shortly thanks.