Author Topic: False Positive for Modern Chess website  (Read 2663 times)

0 Members and 1 Guest are viewing this topic.

Offline nikola.obreshkov

  • Newbie
  • *
  • Posts: 4
False Positive for Modern Chess website
« on: October 08, 2021, 09:58:34 PM »
Please, remove https://www.modern-chess.com/ from the blacklist. For the last couple of days Avast web protection has blocked our website with the message URL: Botnet. However, the hosting security detector and several online scanners all say that the website is clear. It could be related with the Facebook outage making our website to load slowly because of the not working FB Pixel integration. I have reported the website here:
https://www.avast.com/false-positive-file-form.php
Thank you!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88895
  • No support PMs thanks
Re: False Positive for Modern Chess website
« Reply #1 on: October 08, 2021, 10:24:02 PM »
Nothing found here - https://www.virustotal.com/gui/url/9e3c98dd7aaa120c40888fe7873bc46ef0dc1e2da8e07cc7ed8fd2edd5042157
Low Security Risk here - https://sitecheck.sucuri.net/results/modern-chess.com - but some hardening points to consider.
Out of date software found here - https://awesometechstack.com/analysis/website/modern-chess.com/
-  This may or may not be what Avast is alerting for - but you should certainly address this.

You should get a response from Avast in a day or two.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.2.6105 (build 24.2.8918.824) UI 1.0.799/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33891
  • malware fighter
Re: False Positive for Modern Chess website
« Reply #2 on: October 08, 2021, 11:19:20 PM »
This is the external link that is being flagged twice as malware by VT (an Amazon S3 bucket):
htxps://chimpstatic.com/mcjs-connected/js/users/e267209b8766c50c52ffd5128/b71817e0756f15d07c1db5ec2.js

See: https://www.virustotal.com/gui/url/46d164ae94989316abc2440f5d45828d0600507bd63b88382fafdbd416ca5660?nocache=1

polonus
« Last Edit: October 08, 2021, 11:22:48 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline nikola.obreshkov

  • Newbie
  • *
  • Posts: 4
Re: False Positive for Modern Chess website
« Reply #3 on: October 08, 2021, 11:40:15 PM »
Dear DavidR and polonus,

thank you for your replies. I looks like that the most dangerous thing is the chimpstatic js script which is part of the MailChip integration. But then every site that uses MailChimp should be flagged as infected as well.

Regards!


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88895
  • No support PMs thanks
Re: False Positive for Modern Chess website
« Reply #4 on: October 09, 2021, 12:50:02 AM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.2.6105 (build 24.2.8918.824) UI 1.0.799/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33891
  • malware fighter
Re: False Positive for Modern Chess website
« Reply #5 on: October 09, 2021, 05:40:24 PM »
Hi nikola.obreshkov,

It is not exactly as you put it. Hackers are abusing mailchimp to spread malware,
that is why using it means taking a risk in the case it is being abused.

Read online about this abuse: https://www.libraesva.com/hackers-using-mailchimp-spread-malware/

So there were users because of such malware that moved away from using mailchimp.

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline nikola.obreshkov

  • Newbie
  • *
  • Posts: 4
Re: False Positive for Modern Chess website
« Reply #6 on: October 09, 2021, 09:28:06 PM »
I will gladly switch to another newsletter service if Avast confirms that this is the issue. So far there is no word from them.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88895
  • No support PMs thanks
Re: False Positive for Modern Chess website
« Reply #7 on: October 09, 2021, 11:46:59 PM »
Unfortunately it is still being detected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.2.6105 (build 24.2.8918.824) UI 1.0.799/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline nikola.obreshkov

  • Newbie
  • *
  • Posts: 4
Re: False Positive for Modern Chess website
« Reply #8 on: October 10, 2021, 09:12:26 PM »
Now it should be gone. This tool:
https://www.virustotal.com/gui/domain/modern-chess.com
give all Clean.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88895
  • No support PMs thanks
Re: False Positive for Modern Chess website
« Reply #9 on: October 11, 2021, 12:25:24 AM »
Now it should be gone. This tool:
https://www.virustotal.com/gui/domain/modern-chess.com
give all Clean.

It's not that great as it doesn't actually do a live scan of websites (only of uploaded files), it is just checking various lists.  You should notice that Avast isn't on the list for URL checks, only file scans.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.2.6105 (build 24.2.8918.824) UI 1.0.799/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security