Author Topic: Avast blocking site (phishing) but site is clean  (Read 2628 times)

0 Members and 1 Guest are viewing this topic.

Offline LotusMan

  • Newbie
  • *
  • Posts: 2
Avast blocking site (phishing) but site is clean
« on: January 29, 2019, 04:06:04 PM »
Avast is blocking access to the website  app.jumpsend.com saying it is infected with URL:Phishing.
Brought it to the attention of the website and they checked and have assured me that is is clear and clean of any infection.

Sucuri also indicates that the site is clean.     https://sitecheck.sucuri.net/results/app.jumpsend.com

How do we get Avast to stop blocking this site?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: Avast blocking site (phishing) but site is clean
« Reply #1 on: January 29, 2019, 04:24:43 PM »
Reporting Possible False Positive File or Website - https://www.avast.com/false-positive-file-form.php.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline LotusMan

  • Newbie
  • *
  • Posts: 2
Re: Avast blocking site (phishing) but site is clean
« Reply #2 on: January 29, 2019, 04:36:56 PM »
thanks.  Hopefully that will solve the problem.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Avast blocking site (phishing) but site is clean
« Reply #3 on: January 29, 2019, 04:39:39 PM »
Could be a IP problem as it have bad history ... seems it containe lots of porn sites and .xyz domains

IP History  https://www.virustotal.com/#/ip-address/104.27.182.125
Click more button to extend list, click listed items for details


xyz domain info:
 
https://www.symantec.com/connect/blogs/exploring-xyz-another-shady-tld-report

https://dnsr.com/2015/08/21/xyz-domain-scam/



« Last Edit: January 29, 2019, 04:45:54 PM by Pondus »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89053
  • No support PMs thanks
Re: Avast blocking site (phishing) but site is clean
« Reply #4 on: January 29, 2019, 04:40:08 PM »
thanks.  Hopefully that will solve the problem.

You're welcome, hopefully so.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Avast blocking site (phishing) but site is clean
« Reply #5 on: January 29, 2019, 04:46:16 PM »
Detection is for PHISHING on deals: https://www.virustotal.com/#/url/c729aec9c20a055ff0ebef75acd2165ae6690d3c738c7688696851019d99dddb/detection
PHISHCheck also sees it as a PHISH: {"sid": 175097, "is_success": true}

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37529
  • Not a avast user
Re: Avast blocking site (phishing) but site is clean
« Reply #6 on: January 29, 2019, 04:57:47 PM »
Detection is for PHISHING on deals: https://www.virustotal.com/#/url/c729aec9c20a055ff0ebef75acd2165ae6690d3c738c7688696851019d99dddb/detection
PHISHCheck also sees it as a PHISH: {"sid": 175097, "is_success": true}

polonus
Did have, but not with fresh scan   ;)

always check scan date ..... yea i know i am a nag   ;D



Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Avast blocking site (phishing) but site is clean
« Reply #7 on: February 19, 2019, 03:48:03 PM »
That actual domain might not been PHISHING, the address however has seen 275 times of it in last 30 days:
https://checkphish.ai/ip/104.27.183.125 Cloudflare abuse.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!