Author Topic: False positive site blacklisted as phishing  (Read 9612 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
False positive site blacklisted as phishing
« on: September 22, 2018, 04:00:27 PM »
We have our site blacklisted as phishing info.santander.com.uy, properly called from the main site www.santander.com.uy.

Can you please clarify the reasons behind this decision and how to unblock it please?

Thanks!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: False positive site blacklisted as phishing
« Reply #1 on: September 22, 2018, 04:31:46 PM »
Not there: -https://www.santander.com.uy
Consider on reverse DNS: Invalid URL
The requested URL "[no URL]", is invalid.
Reference #9.af8e7b5c.1537626237.158db467
Also: https://www.virustotal.com/#/ip-address/104.82.201.165
VT responds
Quote
Oops, I know nothing about this item.
Hi there, my name is Win32.Helpware.VT... certain antivirus labs also call me W32.eHeur.BadNews.GAFE, I guess it is because every time I appear they get very upset. It looks like you found a hole in my malware net...

IP address "104.82.201.165" not found
Re: https://toolbar.netcraft.com/site_report?url=https%3A%2F%2Fwww.santander.com.uy
and https://aw-snap.info/file-viewer/?protocol=not-secure&ref_sel=GSP2&ua_sel=ff&chk-cache=&fs=1&tgt=d3d3LnN8bnR8biN7fS5eXW0udXlg~enc

See domain search results here: https://www.virustotal.com/#/domain/www.santander.com.uy
CLean MX alerts PHISHING: https://www.virustotal.com/#/url/28a15f42b9e6b0f6a5d65dcf69e7ac145a7e14c0999653c448c228e1bbaa8b72/detection

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: False positive site blacklisted as phishing
« Reply #2 on: September 22, 2018, 04:37:42 PM »
Hi polonus, thanks for your reply.

I've already checked all the usual sites for anomaly detection and found nothing so far indicating a problem.

VirusTotal reports no problem against www.santander.com.uy nor against info.santander.com.uy (the flagged domain). NetCraft also reports no problems.

Also the info site es going through CloudFlare on ip 104.20.249.118, so I don't think that's a problem either.

Do you have any insight as of the reasons Avast has for flagging a domain? Since it's not clear at all for us what may be wrong.

Thanks,
G.-

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: False positive site blacklisted as phishing
« Reply #4 on: September 22, 2018, 05:05:04 PM »
Hi, thanks for your reply!

I already reported the problem on that url, but I don't know there's someone there today.

So I'm trying to understand WHY the site was flagged in an attempt to fix it ASAP.

Certainly there's no phishing on that domain nor was it compromised by any means, so there's something about our domain that the avast algorithm didn't like.

New site went live yesterday and we have no real timeframe to wait until monday until someone from avast reviews the complain.

Any insights about what may be are really appreciated.

Thanks again,
G.-


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positive site blacklisted as phishing
« Reply #5 on: September 22, 2018, 05:10:28 PM »
I already reported the problem on that url, but I don't know there's someone there today.
The guys from threat lab are also working on weekend.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: False positive site blacklisted as phishing
« Reply #6 on: September 22, 2018, 05:41:04 PM »
Do you know how long does it usually take to fix a problem like this? Or if a support account exists?



Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positive site blacklisted as phishing
« Reply #7 on: September 22, 2018, 05:43:28 PM »
Usually a few hours.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: False positive site blacklisted as phishing
« Reply #8 on: September 22, 2018, 07:02:33 PM »
Website is insecure in this respect according to Tracker SSL:
Quote
Website is insecure by default
100% of the trackers on this site could be protecting you from NSA snooping. Tell -santander.com.uy to fix it.

Identifiers | All Trackers
 Insecure Identifiers
Unique IDs about your web browsing habits have been insecurely sent to third parties.

dafa79a834b798f7ce114bcba5e116ee41537635149 info dot santander dot com dot uy __cfduid
Legend

 Tracking IDs could be sent safely if this site was secure.

Furthermore consider the  9 security errors here: https://webhint.io/scanner/4c67feca-5580-4371-8555-b2c0039417a7

4 vulnerable retirable jQuery libraries found: https://retire.insecurity.today/#!/scan/022399493f4b1d01b69cf4428cf2223cd8866a2f8f8711f3d8eee311375093af

polonus (volunteer website security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: False positive site blacklisted as phishing
« Reply #9 on: September 22, 2018, 07:15:58 PM »
Hi polonus, thanks for your pointers.

I've already checked most of the sites, and besides some recommendations and best practices that could be followed, none of that justifies Avast to classify the santander.com.uy domain as phishing.

The main questions here are:

Why Avast is classifying as phishing a site which obviously isn't.

Why does it take so long on their part to respond, given that there are customers complaining online about it for hours.(see attached image)

This is is really damaging on many ends, not justifiable on an outdated jquery library.




REDACTED

  • Guest
Re: False positive site blacklisted as phishing
« Reply #10 on: September 23, 2018, 03:00:48 PM »
We have received no response so far from Avast, does someone know a better way to report the issue?

We've been having problems all weekend because of the misclassification.

Thanks

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positive site blacklisted as phishing
« Reply #11 on: September 23, 2018, 03:13:37 PM »
Hi, I'll forward it for you.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positive site blacklisted as phishing
« Reply #12 on: September 23, 2018, 03:21:28 PM »
Info: It will be fixed in next VPS update.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: False positive site blacklisted as phishing
« Reply #13 on: September 23, 2018, 04:27:51 PM »
@Asyn, thanks for your reply!

Do you know when is the next VPS update scheduled?


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: False positive site blacklisted as phishing
« Reply #14 on: September 23, 2018, 04:32:26 PM »
You're welcome. (Nope, but most probably later today...)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0