Author Topic: Avast marked my webpage as a dangerous site. FALSE POSITIVE  (Read 2053 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Avast marked my webpage as a dangerous site. FALSE POSITIVE
« on: April 25, 2017, 04:31:13 PM »
Hello, we are having some trouble with our webpage.
Yesterday my website got wrongly marked as fraudulent by Google, but today they unmarked my website, the problem is that users still can't access unless they deactivate Avast shields.
I've already run scans at virustotal.com and https://sitecheck.sucuri.net/results/sproactiva.cl/intranet. They don't report any problems concerning being blacklisted nor infected.

Any ideas?
Thanks in advance!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Avast marked my webpage as a dangerous site. FALSE POSITIVE
« Reply #1 on: April 25, 2017, 04:35:24 PM »
What does the avast message say?  .... you may post a screenshot



REDACTED

  • Guest
Re: Avast marked my webpage as a dangerous site. FALSE POSITIVE
« Reply #3 on: April 25, 2017, 05:03:58 PM »
Thanks a lot.
We are very surprised with the ammount of domains pointing to our IP. We have no absolutely no relation to those domains.
What can we do?

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Avast marked my webpage as a dangerous site. FALSE POSITIVE
« Reply #4 on: April 25, 2017, 05:05:06 PM »
Get dedicated hosting instead of shared hosting.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Avast marked my webpage as a dangerous site. FALSE POSITIVE
« Reply #5 on: April 25, 2017, 06:24:43 PM »
Another presentation of just the issues Eddy mentions:
Quote
Search results for -sproactiva.cl/intranet.
Total number observed artifacts in database: URLs, HTTP cookies, Flash cookies, HTML5 localStorage cookies, sessionStorage cookies and SSL/TLS checks. Recents scans from a few hours back are listed below.
-http://intranet.com/ 3rd-party 1 Persistent 3 Session 0 Score ?
-http://interact-intranet.com/ 3rd-party 4 Persistent 9 Session 4 Score ?
-http://proactive-internet.com/ 3rd-party 0 Persistent 4 Session 1 Score ?
See: -https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=sproactiva.cl%2Fintranet&ref_sel=GSP2&ua_sel=ff&fs=1
and https://urlscan.io/result/65fc6ffb-407b-44ae-8270-9ecbe0f9afd0#summary

And you are never alone on these BigData domains: http://domainbigdata.com/50.87.144.108
So when there is abuse on that same IP, you can reap the consequences of that as well,

Also consider the results from scanning URL: -http://sproactiva.cl/intranet/javascript/tapmodo-Jcrop-1902fbc/js/jquery.Jcrop.js
Number of sources found: 109
Number of sinks found: 88

jQuery bug with this expression in that very code for that hash was patched
Quote
quickExpr = /^(?:[^#<]*(<[\w\W]+>)[^>]*$|#([\w\-]*)$
The quick patch by jQuery is:
Quote
-       quickExpr = /^(?:[^<]*(<[\w\W]+>)[^>]*$|#([\w\-]*)$)/,
           +       quickExpr = /^(?:[^#<]*(<[\w\W]+>)[^>]*$|#([\w\-]*)$)/,

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: Avast marked my webpage as a dangerous site. FALSE POSITIVE
« Reply #6 on: April 26, 2017, 09:10:22 AM »
I am removing sproactiva[.]cl from our blacklist ;)