Author Topic: Avast flagging JPG files as phishing on my website  (Read 2778 times)

0 Members and 1 Guest are viewing this topic.

Offline tony379

  • Newbie
  • *
  • Posts: 2
Avast flagging JPG files as phishing on my website
« on: December 17, 2019, 07:25:39 AM »
Avast is flagging several (but not all) JPG files as phishing. Website is hxtps://mybookcave.com. Seems to have started this morning. Why are those files flagged as phishing? They are book covers, nothing there that could make someone divulge confidential information. How do I get my website delisted?
« Last Edit: December 19, 2019, 10:25:37 AM by Milos »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Avast flagging JPG files as phishing on my website
« Reply #2 on: December 17, 2019, 12:00:14 PM »
CMS configuration issues: User Enumeration
  The first two user ID's were tested to determine if user enumeration is possible.

ID   User   Login
1   0x0049   jordan
2   Rachel Ann Nunes   rachel
It is recommended to rename the admin user account to reduce the chance of brute force attacks occurring. As this will reduce the chance of automated password attackers gaining access. However it is important to understand that if the author archives are enabled it is usually possible to enumerate all users within a WordPress installation.

Recommendations to improve website and website security, found through linting:
https://webhint.io/scanner/103802ac-5a0f-4b62-996d-168c5b4abf05

Wait for a final verdict of an avast team member as they are the only ones to come and unblock,
we are just volunteers with relative knowledge of 3rd party cold recon website security analysis and error-hunting.

See
Quote
Detected jQuery libraries to be retired:
jquery   1.11.1   Found in https://ajax.googleapis.com/ajax/libs/jquery/1.11.1/jquery.min.js
Vulnerability info:
Medium   2432 3rd party CORS request may execute CVE-2015-9251   
Medium   CVE-2015-9251 11974 parseHTML() executes scripts in event handlers   
Low   CVE-2019-11358 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution

I do not see the website being blocked by avast's at the moment.  ;)

polonus (volunteer 3rd party cold recon website security analyzer and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline tony379

  • Newbie
  • *
  • Posts: 2
Re: Avast flagging JPG files as phishing on my website
« Reply #3 on: December 19, 2019, 01:00:29 AM »
Thank you for those links. And for pointing out the user enumeration issue--I was not aware that this was even possible. I'll be working on these as time permits.

Offline Hector J

  • Newbie
  • *
  • Posts: 2
Re: Avast flagging JPG files as phishing on my website
« Reply #4 on: December 16, 2022, 12:38:32 AM »
Hello, my website is also having this same issue of muy clean site getting flagged all over the place for phishing by avast web shield.   I have run multiple malware checks and wordfence cleanups and all looks ok.

The site is haciendaeltriangulo.com

Any suggestions? thank you.
« Last Edit: December 16, 2022, 02:56:01 AM by Hector J »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: Avast flagging JPG files as phishing on my website
« Reply #5 on: December 16, 2022, 01:56:05 AM »
Hello, my website is also having this same issue of muy clean site getting flagged all over the place for phishing by avast web shield.   I have run multiple malware checks and wordfence cleanups and all looks ok.

The site is haciendaeltriangulo.com

Any suggestions? thank you.

First of all modify the link so it isn't active (as I have in the quoted text) to avoid accidental exposure to a suspect site.

I don't see anything about jpg files as the detection is on the domain, see attached image.

Avast Isn't alone in detecting your site:
https://www.virustotal.com/gui/url/3a2a0cd8465de39c5fb6aea91b03a9a0d250acab6aeeef5d02f53498d056491a?nocache=1

Security issues reported here - https://en.internet.nl/site/haciendaeltriangulo.com/1826062/

Further issues - Webpage Security Score  F
https://snyk.io/test/website-scanner/?test=221216_BiDcWT_DE&utm_medium=referral&utm_source=webpagetest&utm_campaign=website-scanner
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Hector J

  • Newbie
  • *
  • Posts: 2
Re: Avast flagging JPG files as phishing on my website
« Reply #6 on: December 16, 2022, 02:58:42 AM »
Woah! Was not expecting all of that.   Thanks for the help, I'll start trying to fix all of those issues one by one :)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: Avast flagging JPG files as phishing on my website
« Reply #7 on: December 16, 2022, 12:05:26 PM »
You're welcome.

When you have some progress you can use this:
Reporting a Possible False Positive File or Website - https://www.avast.com/false-positive-file-form.php.
You should get a response in a day or two.

As and Avast user, I can only point you in the right direction, to remove it only the Avast virus labs team can do that.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Avast flagging JPG files as phishing on my website
« Reply #8 on: December 18, 2022, 01:47:46 PM »
Still flagged by avast's,
A word press security scan fails (time-out to target wp-includes), also see: https://sitecheck.sucuri.net/results/haciendaeltriangulo.com

Then there is this info on the IP address:
https://www.malwareurl.com/ns_listing.php?ip=51.254.238.160

Flu & Qack-bot infested, and with scam & spam abuse.

polonus (volunteer 3rd party cold recon website security analyst and website error-hunter)
« Last Edit: December 18, 2022, 02:24:09 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!