Author Topic: URL: Phishing false positive - HELP?  (Read 5044 times)

0 Members and 1 Guest are viewing this topic.

Offline tym3

  • Newbie
  • *
  • Posts: 1
URL: Phishing false positive - HELP?
« on: August 01, 2019, 09:01:20 PM »
One of my clients' sites is throwing what I believe is a false positive, URL:Phishing.

The site in question is emcsecurity.com. Their google ads are coming back clean, so we're at a loss if it's not a false positive.


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6677
  • volunteer
Re: URL: Phishing false positive - HELP?
« Reply #2 on: August 06, 2019, 11:18:46 PM »
Detection has been removed 06.08.2019 at 07:54 AM.

Quote from: Avast
Our virus specialists have been working on this problem and it has been resolved. The provided website isn't detected by Avast anymore.
« Last Edit: August 06, 2019, 11:21:10 PM by jefferson sant »

Offline Surzycki

  • Newbie
  • *
  • Posts: 1
Re: URL: Phishing false positive - HELP?
« Reply #3 on: August 07, 2019, 03:34:05 PM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: URL: Phishing false positive - HELP?
« Reply #4 on: August 07, 2019, 03:56:59 PM »
Quote
How can I figure out why this is happening ? 
Report it to avast lab

Offline jefferson sant

  • Starting Graphoman
  • *
  • Posts: 6677
  • volunteer
Re: URL: Phishing false positive - HELP?
« Reply #5 on: August 07, 2019, 11:07:10 PM »
« Last Edit: August 07, 2019, 11:09:18 PM by jefferson sant »

Offline Sakamoto

  • CDN IT Maintenance Engineer
  • Newbie
  • *
  • Posts: 3
    • 坂本Sakamoto.blog
Re: URL: Phishing false positive - HELP?
« Reply #6 on: August 12, 2019, 05:15:34 PM »
Hello, I am a IT maintenance engineer. I am falsely reported as a phishing website on this website ( https://www.myhair.asia/ ), please help detect? Can I lift the ban?

https://sitecheck.sucuri.net/results/www.myhair.asia

https://www.virustotal.com/gui/url/8c1101e483cf9cb0b3a74ca76e07fb371fcf44e60ee1de1a5f5ecf6e08238ff3/detection

many thanks
Hello, i am a simple creature.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: URL: Phishing false positive - HELP?
« Reply #7 on: August 12, 2019, 08:04:47 PM »
You can report a suspected FP (File/Website) here: https://www.avast.com/false-positive-file-form.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Sakamoto

  • CDN IT Maintenance Engineer
  • Newbie
  • *
  • Posts: 3
    • 坂本Sakamoto.blog
Re: URL: Phishing false positive - HELP?
« Reply #8 on: August 13, 2019, 02:37:23 AM »
You can report a suspected FP (File/Website) here: https://www.avast.com/false-positive-file-form.php

Hi, I have Report a suspected false positive, but I am still waiting for reply.

many thanks
« Last Edit: August 13, 2019, 02:54:51 AM by Sakamoto »
Hello, i am a simple creature.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: URL: Phishing false positive - HELP?
« Reply #9 on: August 14, 2019, 08:23:19 AM »
Website is no longer being flagged by avast's.

However check: ReferenceError: ga is not defined
 /:20  and jquery   1.12.4   Found in -https://myhair.sakacdn.com/wp-includes/js/jquery/jquery.js?ver=1.12.4-wp
Vulnerability info:
Medium   2432 3rd party CORS request may execute CVE-2015-9251   
Medium   CVE-2015-9251 11974 parseHTML() executes scripts in event handlers   1
Medium   CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Sakamoto

  • CDN IT Maintenance Engineer
  • Newbie
  • *
  • Posts: 3
    • 坂本Sakamoto.blog
Re: URL: Phishing false positive - HELP?
« Reply #10 on: August 14, 2019, 05:41:01 PM »
Website is no longer being flagged by avast's.

However check: ReferenceError: ga is not defined
 /:20  and jquery   1.12.4   Found in -https://myhair.sakacdn.com/wp-includes/js/jquery/jquery.js?ver=1.12.4-wp
Vulnerability info:
Medium   2432 3rd party CORS request may execute CVE-2015-9251   
Medium   CVE-2015-9251 11974 parseHTML() executes scripts in event handlers   1
Medium   CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution

polonus

Hi, this problem has been fixed so far, should it be ok?

https://www.virustotal.com/gui/file/8c7ee0238fa5cd80a02ef9870a7fff498ef52097181cb73edb9219dc022fd919/detection

many thanks
Hello, i am a simple creature.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: URL: Phishing false positive - HELP?
« Reply #11 on: August 14, 2019, 08:32:21 PM »
Hi Sakamoto,

That retirable jQuery library had nothing to do with the avast FP detection, now elevated.
More with the minified js code of the regular expression in: 
https://myhair.sakacdn.com/wp-includes/js/jquery/jquery.js?ver=1.12.4-wp
read on that particular subject here: https://github.com/SnakeskinTpl/Snakeskin/issues/69
just meant for hardening your security there,

一切都很好  all's well that ends well, a.k.a everything is fine,

polonus (volunteer 3rd party cold recon website security analyst & website error-hunter)

unminify -code at https://unminify.com/ (pol)


« Last Edit: August 14, 2019, 09:16:20 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: URL: Phishing false positive - HELP?
« Reply #12 on: June 27, 2020, 12:24:12 PM »
Hi nadim221mia,

Why you attach this to a report for a site, that is not even online anymore?
Are you the developer of Unminify JS? Hope this was not intentional then?

De-minifying is only for CSS min.js script, you can detect such scripts for instance while using the SRC extension in the browser, a.k.a. Quick Source Viewer, an extension to help website developers and also those into website security analysis.
Falls in the realm of scripts like Retire.JS and the likes.

I am just looking at a newly reported suspicious PHISH: -burency.io
(something with cryptocurrency for the Middle East, USA excluded).
Re: https://www.phishtank.com/phish_detail.php?phish_id=6651116&frame=details
Checked at Zonemaster: https://www.zonemaster.net/domain_check

Just have the following script run at the unminifyer:
-> -https://cdn.jsdelivr.net/npm/vanilla-lazyload@12.4.0/dist/lazyload.min.js
lands at  -http://burency.io/js/bioPopupView.js (no DOM-XSS sources & sinks)...

polonus (volunteer 3rd party cold recon website security anlayst and website error-hunter)
« Last Edit: June 27, 2020, 02:14:00 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!