Author Topic: False positive? Site blocked - URL:Blacklist with embedded video player  (Read 1075 times)

0 Members and 1 Guest are viewing this topic.

Offline Owen10

  • Newbie
  • *
  • Posts: 1
Hi folks,

I get the following 'threat secured' message every time I open a webpage with our embedded video player from Castr:

Alert ID: 9374789d9038/2023-06-18T10:43:27.466Z
hXXps://cdn.dna-delivery.com/dna-client/6.5.1/peer-agent.js infected with URL:Blacklist
https://postimg.cc/3WrKDvV9

This is meant to launch as a paid product, so I need to find out what the issue is before we launch.

The pop-up can be on any webpage - including Castr's own backend. I've personally tried it on the following sites:

hXXps://monument-cycling.ghost.io/lincoln-grand-prix-highlights/
hXXps://www.monumentcycling.com/player-test
hXXps://castr.com/app/dynamic/647f93d5c0bc02728590b943

All of the sites seem to come back clean when I check with things like Sucuri, even with the player on the page, but Avast pops up with it every time. I've alerted the team at Castr, and they don't think their site or player is infected with anything.

Some hopefully useful information:
- The embedded player is an iFrame widget for switching between livestreaming and video on demand
- Other companies' embedded iFrame widgets don't get flagged on Avast.
- I've turned off all my Chrome extensions when checking.

Can you help me understand what's happening here and what's triggering the threat message?

Many thanks,

Owen
« Last Edit: June 18, 2023, 01:30:19 PM by Owen10 »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
2 flag it here: https://www.virustotal.com/gui/url/ad736e82083ebc258fa18a91c03f75649b354ee4917ce492f55ae18d7e06bb9a/details
On IP: https://urlscan.io/ip/157.245.65.101
Also flagged here: https://www.urlvoid.com/scan/cdn.dna-delivery.com/

Wait for a final from avast team, whether this is not agent - Container malware?
 
The domain name 'Cdn.dna-delivery.com' is well known to violate our detection criteria.

Internal ID: 37824653
Detection category: Malicious:URL
Date and hour: about 2 months ago
Advert domain: No


polonus
« Last Edit: June 18, 2023, 07:54:33 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!