Author Topic: URL:Mal false positive detection report  (Read 3000 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
URL:Mal false positive detection report
« on: June 28, 2017, 11:21:27 AM »
Hi,
We have a client reporting a URL:Mal infection threat detection from code on their website hosted on one of our domains:
lmknjb1[.]com

This is hosted via a global webfarms with endpoint IP's: 23.96.83.107, 138.91.156.9, 104.40.215.103
None of the domain or IP's have been blacklisted on any available blacklist I can find.

Please can this detection be reviewed, and any false positive(s) removed.

Regards
Rich
« Last Edit: June 29, 2017, 09:06:44 AM by HonzaZ »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: URL:Mal false positive detection report
« Reply #1 on: June 28, 2017, 11:23:35 AM »
You can report a URL here: https://www.avast.com/report-a-url.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0


REDACTED

  • Guest
Re: URL:Mal false positive detection report
« Reply #3 on: June 28, 2017, 05:26:09 PM »
I've already contact Fortinet for the domain that has been flagged as Malware on the IP listed.
I've also got an active ticket open with Securi.

The wordpress issues I'm in discussions with our website developers on.


.....
None of these however explain why Avast has blacklisted the domain lmknjb1[.]com
« Last Edit: June 29, 2017, 09:06:56 AM by HonzaZ »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: URL:Mal false positive detection report
« Reply #4 on: June 28, 2017, 06:45:59 PM »
On same IP there is malware here: http://urlquery.net/report.php?id=1497984002929
Custom errors: Fail

Requested URL: hxtp://www.lmknjb1.com/< | Response URL: hxtp://www.lmknjb1.com/< | Page title: Runtime Error | HTTP status code: 400 (Bad request) | Response size: 3,420 bytes | Duration: 19 ms
Overview
Custom errors are used to ensure that internal error messages are not exposed to end users. Instead, a custom error message should be returned which provides a friendlier user experience and keeps potentially sensitive internal implementation information away from public view.

Result
It looks like custom errors are not correctly configured as the requested URL contains the heading "Server Error in".

Custom errors are easy to enable, just configure the web.config to ensure the mode is either "On" or "RemoteOnly" and ensure there is a valid "defaultRedirect" defined for a custom error page as follows:

<customErrors mode="RemoteOnly" defaultRedirect="~/Error" /> -> https://urlscan.io/result/8601ee12-be43-44e1-8a10-1fe6b64ebbf9/dom/  http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) -  Potentially risky methods: TRACE
nameserver salt.master salt.minion using master DNS: zone.easydns.com. . No excessive server info proliferation found.  ;)
Consider PulseSecure for Barracuda.... :-X

Certificate error: Wrong certificate installed. 8)
The domain name does not match the certificate common name or SAN.
RC4
Your server's encryption settings are vulnerable. This server uses the RC4 cipher algorithm which is not secure.
Go Daddy Secure Certificate Authority - G2
This server is vulnerable to a Poodle (SSLv3) attack  :'(

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: URL:Mal false positive detection report
« Reply #5 on: June 29, 2017, 09:11:07 AM »
I have unblocked lmknjb1[.]com. It might have been because the domains seems randomly-generated (as are 90 % of the domains on the 3 IPs you mentioned). This is usually a sign of maliciousness, and I strongly advise against it.