Author Topic: Avast is blocking my website  (Read 2802 times)

0 Members and 1 Guest are viewing this topic.

Offline NTSS

  • Newbie
  • *
  • Posts: 8
Avast is blocking my website
« on: December 22, 2022, 12:53:40 PM »
Hello

I received several messages from different users telling me Avast has started blocking my website - link is https://fearlessrevolution.com and for life of me I can’t figure out why!!!

I also checked virustotal and as expected site is A-clean because it’s a free useful site that is loved by its users.

Can I at least get a reason why Avast all of a sudden is causing issues for my users. If it’s a false positive then can it be removed?

First time I am actually hearing antiviruses blocking sites, I thought they only scanned exes.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37531
  • Not a avast user
« Last Edit: December 22, 2022, 05:25:07 PM by Pondus »

Offline NTSS

  • Newbie
  • *
  • Posts: 8
Re: Avast is blocking my website
« Reply #2 on: December 23, 2022, 02:48:24 AM »
https://sitecheck.sucuri.net/results/https/fearlessrevolution.com

https://unmask.sucuri.net/security-report/?page=fearlessrevolution.com


Note that virustotal does not scan the website but check URL against blacklists


https://forum.avast.com/index.php?topic=14433.msg1289438#msg1289438

Huh so as expected the url is clean which makes Avast blocking it really weird. Also that suspicious inline script is from Cloudflare for bot fights. And of course sucuri can’t access the memberlist or search pages, bots are blocked they were eating up server resources. But neither of these things should cause a url block??.

I have submitted to the report false positive url but got a response that they couldn’t find any detection? But my users are complaining still. This is so stressful

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Avast is blocking my website
« Reply #3 on: December 24, 2022, 02:15:43 PM »
Somewhere there is a problem with the hosting of that website,
by the way never enter live links here.

See: https://sitecheck.sucuri.net/results/https/fearlessrevolution.com

Although Quttera gives it as suspicious: https://www.virustotal.com/gui/url/3436a186e7983b4e0a0d209287dc5a0d8781e780a7074a871b155146fa772d3f

Re: https://quttera.com/detailed_report/fearlessrevolution.com

Quote
/assets/javascript/core.js?assets_version=307
Severity:   Potentially Suspicious
Threat:   PS.JS.Obfuscantion.gen
Reason:   Too low entropy detected in string [['Ctable class="not-responsive colour-palette vertical-palette" style="width: auto;"ECtd style="backgr']] of length 13681 which may point to obfuscation or shellcode.
Details:   Detected procedure that is commonly used in suspicious activity.
Line:   78
Offset:   38
Threat dump:   View code (not given for obvious reasons)
Threat dump MD5:   C8E84DE76947F13AC59BBA15C7B63E7B
File size[byte]:   27839
File type:   ASCII
Page/File MD5:   306683526ADD20506793AC5E9D0A0135
Scan duration[sec]:   1.646

Also consider this report: https://tuad.btarena.com/report/fearlessrevolution.com

polonus (volunteer 3rd party cold recon website security-analyst and website error-hunter)

« Last Edit: December 24, 2022, 02:24:06 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast is blocking my website
« Reply #4 on: December 24, 2022, 02:19:25 PM »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Avast is blocking my website
« Reply #5 on: December 24, 2022, 02:34:30 PM »
Hi bob3160,

It is already being blocked by avast's. They could only give another final verdict.

We will find a lot of links now added on regular websites with suspicious shell code (-lked.ru for example etc.).

Average end-users aren't always aware of particular scam-ad campaigns etc. on what further may be domains to be fully trusted and will get infested.

These our days are cybercriminal hey-days, and so one should be twice shy to click at such links.

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast is blocking my website
« Reply #6 on: December 24, 2022, 02:47:38 PM »
Hi bob3160,

It is already being blocked by avast's. They could only give another final verdict.

We will find a lot of links now added on regular websites with suspicious shell code (-lked.ru for example etc.).

Average end-users aren't always aware of particular scam-ad campaigns etc. on what further may be domains to be fully trusted and will get infested.

These our days are cybercriminal hey-days, and so one should be twice shy to click at such links.

pol
Reporting it to Avast (unless that's already been done, will make them take another look at the site if the owner has made corrections.
As you know, there are times sites are blocked because they wound up on some ones list.
The makes Avast Review the site.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline NTSS

  • Newbie
  • *
  • Posts: 8
Re: Avast is blocking my website
« Reply #7 on: December 25, 2022, 07:23:24 AM »
Somewhere there is a problem with the hosting of that website,
by the way never enter live links here.

See: https://sitecheck.sucuri.net/results/https/fearlessrevolution.com

Although Quttera gives it as suspicious: https://www.virustotal.com/gui/url/3436a186e7983b4e0a0d209287dc5a0d8781e780a7074a871b155146fa772d3f

Re: https://quttera.com/detailed_report/fearlessrevolution.com

Quote
/assets/javascript/core.js?assets_version=307
Severity:   Potentially Suspicious
Threat:   PS.JS.Obfuscantion.gen
Reason:   Too low entropy detected in string [['Ctable class="not-responsive colour-palette vertical-palette" style="width: auto;"ECtd style="backgr']] of length 13681 which may point to obfuscation or shellcode.
Details:   Detected procedure that is commonly used in suspicious activity.
Line:   78
Offset:   38
Threat dump:   View code (not given for obvious reasons)
Threat dump MD5:   C8E84DE76947F13AC59BBA15C7B63E7B
File size[byte]:   27839
File type:   ASCII
Page/File MD5:   306683526ADD20506793AC5E9D0A0135
Scan duration[sec]:   1.646

Also consider this report: https://tuad.btarena.com/report/fearlessrevolution.com

polonus (volunteer 3rd party cold recon website security-analyst and website error-hunter)

As I explained before, bots are blocked from accessing memberlist and search pages, these bad bots eat precious server resources. There is nothing wrong with the hosting.

What kind of crap is quttera? All these sites are pretty terrible if you ask my opinion. Let’s see what that js file is

https://fearlessrevolution.com/assets/javascript/core.js?assets_version=307

It is a simple phpbb js script, minified by Cloudflare and then cached. Am I supposed to turn off Cloudflare now, increase my hosting bills than they already are, make myself vulnerable to DDOS attacks because some crap site called quttera thinks a minified phpbb js script is a threat that will wipe out users BIOS and create a zombienet?? Is this a joke?

I don’t code in JavaScript but even I can see and read it isn’t obfuscated. What does low entropy in string means? And how is it dangerous that it will warrant a block?

Here is some information, I have had to deal with serious DDOS attacks just this year alone and what saved me was Cloudflare and aggressive blocking of bad bots adding to demise of my server (crap like quttera bots). When you run a big site that isn’t mommy daddy blogs, every byte every request counts. It is absolutely criminal that “quttera” and these crap bots are marking my site as malicious for Cloudflare scripts, to please them I have to make myself vulnerable to people who want to harm my site???

Avast removed the detection and I hope they don’t rely on these crap automated bots to run their AV on because oh my God, I can’t even begin to explain how this would be bad. My whole week was wasted and my time is precious, I could’ve spent that time earning money and with my family instead it was spent analysing Cloudflare minified assets and Cloudflare bot fighting scripts.

« Last Edit: December 25, 2022, 07:25:13 AM by NTSS »

Offline NTSS

  • Newbie
  • *
  • Posts: 8
Re: Avast is blocking my website
« Reply #8 on: December 25, 2022, 07:41:07 AM »
Hi bob3160,

It is already being blocked by avast's. They could only give another final verdict.

We will find a lot of links now added on regular websites with suspicious shell code (-lked.ru for example etc.).

Average end-users aren't always aware of particular scam-ad campaigns etc. on what further may be domains to be fully trusted and will get infested.

These our days are cybercriminal hey-days, and so one should be twice shy to click at such links.

pol

No offence but this is just paranoia. Fact is it is very hard to get infected these days. First you have Google itself blocking any exes from being hosted or every browser blocks the site. You have Adblock plus, unlock origin and noscript extensions that blocks even necessary scripts. You have virustotal now. You have VMWare etc. It is very hard for bad sites to exist just cause browsers have become so advanced. I am on my IPhone and it has an adblocker and anti tracker built in.

I also worry about the legitimacy of those shell code that you say is found on sites because for my site, the supposed malware is Cloudflare minified js scripts and bad bots fighting script.
 
You know what the irony is? Google/Facebook are malicious data miners using trackers etc but they are given free hand just because they’re big tech.

Sorry but it’s paranoia. It was bad in 2006 and before that and you had to be computer savvy, these days it’s very hard to get infected. I could go on and on but meh, what’s the point. You’re even afraid of a minified js script lol anything slightly bad you will think is going to destroy your computer.

Offline NTSS

  • Newbie
  • *
  • Posts: 8
Re: Avast is blocking my website
« Reply #9 on: December 25, 2022, 09:33:12 AM »
I checked this quttera site further and the business model is pretty transparent. They prey on the fears of average computer user who doesn’t know anything (oooh scary unknown virus my website is infected). Look at the attached image

https://cdn.discordapp.com/attachments/1056215831744364644/1056488527359127622/IMG_2222.png

179$! Just unbelievable, that’s what it is asking me to protect my website!! Along with my personal information

This is downright predatory behaviour because if you don’t pay them, they will keep marking your site as suspicious and cause troubles for you with AV companies. If I was an average user who didn’t know this crap site was calling Cloudflare minified js as malware, I would pay them 179$, their representative would probably prey on my lack of computer knowledge, ask for my server access, then silently remove the detection on their site and tell me my site is all clean now.

I am going to investigate further to understand how I fell into this security extortion mafia because I have run sites for two decades now and I never heard of these crap sites until now. Maybe some of my site haters reported me, I don’t know what triggered it.

The tragedy is on a well respected antivirus like Avast, users are sent to this mafiaso type extortion site. What do you suggest? I pay 179$ to quttera? I remove Cloudflare js minification feature? The real malware, the real adscam is quttera. I am shocked there are poor computer newbies who pay quttera 179$ and you tell me it’s cyber criminal heyday , well yeah when you pass around quttera as a legit site then it’s no surprise. You are helping quttera scam.

Maybe I need to quit my day job and start a quttera site myself. Because even if I extort 100 customers with 179$, ooh baby, that’s overnight rich. And I can extort them further with BS fears, it’s not even that infeasible a target. I imagine quttera must have thousands of victims by now. No surprise you have a million “security” sites now telling you your site is suspicious and pay me hundreds of dollars.

What a joke, I really need to get my hands into security field but I don’t know if I can run these scammy practices.

Sorry for the rant but not really. You surely must have sent many users to this quttera who are computer ignorant who might have paid them 179$. It is criminal, I work day and night honestly in a stressful job just for 100$ and they get 179$ from one victim running this scam and get recommended on Avast site….just wow. Mind blowing