Author Topic: False positive for our company's website tag  (Read 1757 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
False positive for our company's website tag
« on: September 30, 2014, 09:48:18 PM »
We recently started getting complaints that our website tag was leading to AVAST security notices.  I'm not sure this is the correct channel but we'd like to resolve this as quickly as possible so it doesn't impact our business, customers or their audience.



Thanks,
Tom

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: False positive for our company's website tag
« Reply #1 on: September 30, 2014, 09:56:54 PM »
False positive?
No it is not, the IP is blacklisted.

Blacklisted and yellow listed:
http://multirbl.valli.org/lookup/162.159.242.219.html

Blacklisted:
http://zulu.zscaler.com/submission/show/f11bd2c514838cb0fdc65cda3e4f5021-1412106587


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: False positive for our company's website tag
« Reply #2 on: September 30, 2014, 10:44:44 PM »
Hi Tom55,

Benign and reputable sites in a malicious environment form the main reason for false positives as you will all understand.
The avast! blocking comes more than likely from that general IP block. But here it is based on the interpretation of a
conditional redirect.

See for badness history: https://www.virustotal.com/nl/ip-address/162.159.242.219/information/
Look here: /report.php?id=1412106896679

De-blocking can only be done by avast! team members, we here are not.
I am just a voluntary website analyst with some relevant knowledge and training.
So send a request and contact avast! via www.avast.com/contact-form.php

But I see the site redirects  to wXw.trueanthem.com and that is what avast is blocking in the browser.

See for uri: http://linkeddata.informatik.hu-berlin.de/uridbg/index.php?url=http%3A%2F%2Ftru.am%2F&useragentheader=&acceptheader=

What they, TrueAnthem, do in theor own words: https://www.ghostery.com/fr/apps/trueanthem

Your company's site has DNS SOA issues:
Could not find reverse address for 74.125.205.27 (27.205.125.74.in-addr.arpa.).

PTR record(s) for the address could not be found in the .arpa-zone. (ip6.arpa. for IPv6 addresses and in-addr.arpa. for IPv4).

Could not find reverse address for 2607:f8b0:4003:c06:0:0:0:1a (a.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.6.0.c.0.3.0.0.4.0.b.8.f.7.0.6.2.ip6.arpa.).

PTR record(s) for the address could not be found in the .arpa-zone. (ip6.arpa. for IPv6 addresses and in-addr.arpa. for IPv4).

Could not find reverse address for 2607:f8b0:4003:c06:0:0:0:1a (a.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.6.0.c.0.3.0.0.4.0.b.8.f.7.0.6.2.ip6.arpa.).

PTR record(s) for the address could not be found in the .arpa-zone. (ip6.arpa. for IPv6 addresses and in-addr.arpa. for IPv4).

Stay safe and secure both offline and online,
all the best,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!