Author Topic: Blocks site esthus.in (favicon.ico)  (Read 8467 times)

0 Members and 1 Guest are viewing this topic.

BloodySoul

  • Guest
Blocks site esthus.in (favicon.ico)
« on: September 10, 2011, 11:40:59 AM »
Good day.

More recently, there was a problem, avast blocking site http://esthus.in cursing at favicon.ico
What caused this?
How can I fix this situation?

Sorry for my bad English.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Blocks site esthus.in (favicon.ico)
« Reply #1 on: September 10, 2011, 12:01:40 PM »
Only detected by avast!  no detection on other web scanners....

VirusTotal - HTML scan
http://www.virustotal.com/file-scan/report.html?id=97c55f9f649cde9377d52c30c0057ba5d3fb247adb41bdc118185b05e63237b0-1315648545

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Blocks site esthus.in (favicon.ico)
« Reply #2 on: September 10, 2011, 12:03:53 PM »
Also clean on Sucuri and URLVoid.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

BloodySoul

  • Guest
Re: Blocks site esthus.in (favicon.ico)
« Reply #3 on: September 10, 2011, 12:48:46 PM »
Thank you for your answers.
Who can fix this?
Many clients use Avast. They have to unplug it so visit the site: (

BloodySoul

  • Guest
Re: Blocks site esthus.in (favicon.ico)
« Reply #4 on: September 10, 2011, 01:08:11 PM »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Blocks site esthus.in (favicon.ico)
« Reply #5 on: September 10, 2011, 01:22:12 PM »
Quote
Who can fix this?
If it is False Positive... avast!

you can report it here   http://www.avast.com/en-no/contact-form.php?loadStyles&subject=SALES

see dropp down menu > Report False Virus Alert On Website

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: Blocks site esthus.in (favicon.ico)
« Reply #6 on: September 10, 2011, 02:26:35 PM »
Hi BloodySoul,

Here it is given clean: Checking with DrWeb's URL checker:
-http://esthus.in/js/jquery.min.js
File size: 78.33 KB
File MD5: 272d1908ee08e2dca212fc3bb634182c

-http://esthus.in/js/jquery.min.js - Ok
esthus.in/js/jquery.min.js benign (checked with unpacker)
Checking: -http://esthus.in/
Engine version: 5.0.2.3300
Total virus-finding records: 2572207
File size: 23.05 KB
File MD5: c58452b2cbc6fde4f0e346777af9f3de

-http://esthus.in/ - archive HTML
>-http://esthus.in//Script.0 - Ok
>-http://esthus.in//Script.1 - Ok
>-http://esthus.in//Script.2 - Ok
>-http://esthus.in//Script.3 - Ok
-http://esthus.in/ - Ok

Given clean here: http://www.urlvoid.com/scan/esthus.in
Safe: http://siteinspector.comodo.com/public/reports/328673
No alerts detected: http://urlquery.net/report.php?id=2763
This outbound link had issues: http://www.google.com/safebrowsing/diagnostic?site=vkontakte.ru
with 5 scripting exploit, 1 exploit
Another outbound link, see: http://www.urlvoid.com/scan/liveinternet.ru
(suspicious)
The block could however have been because of malware from here (now dead:
-http://update.esthus.su/Esthus-Updater.exe, see: http://xml.ssdsandbox.net/view/12cdc9e2df89887d14c82e57e9270579 )
AS Name: ESERVER eServer.ru - hosting operator
IPs allocated: 5376
Blacklisted URLs: 4

I see no further immediate issues here,

polonus


« Last Edit: September 10, 2011, 02:35:26 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89706
  • No support PMs thanks
Re: Blocks site esthus.in (favicon.ico)
« Reply #7 on: September 10, 2011, 02:37:02 PM »
Well the Network Shield blocks the site (image1) due to the frequency of alerts from the Web Shield (as you mention on the favicon.ico file). This file is one of the most frequently hacked as it is displayed/loaded for all pages, so check the contents of this file, it may have script inside it.

If the networks shield is taken out of the equation, then the Web Shield alerts (image2) as there appears to be a compressed {gzip} obfuscated script file loaded with the index/home page, see image extract of the contents of this file (image3).
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

BloodySoul

  • Guest
Re: Blocks site esthus.in (favicon.ico)
« Reply #8 on: September 10, 2011, 02:41:36 PM »
What should I do?

BloodySoul

  • Guest
Re: Blocks site esthus.in (favicon.ico)
« Reply #9 on: September 10, 2011, 03:06:06 PM »
It's all because of back links to http://vkontakte.ru and http://liveinternet.ru ?
It's a well-known services :(
Help, how now?
« Last Edit: September 10, 2011, 03:08:47 PM by BloodySoul »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: Blocks site esthus.in (favicon.ico)
« Reply #10 on: September 10, 2011, 03:17:59 PM »
What is important is the source of the favicon. So open your AV log file and see where the .ico is sourced. If the icon comes from a website and you can trust that site, you can assume it is safe. If it comes from a source unknown to you, consider it to be malicious. There is also a possibility it could be a FP.
Check the IP here, it is new: http://hosts-file.net/?s=liveinternet.ru
This is flagged there as EMD, so called high risk site,
On the other hand vkontakte.ru is given an all green,
see: http://hosts-file.net/default.asp?s=vkontakte.ru
and http://www.urlvoid.com/scan/vkontakte.ru

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

BloodySoul

  • Guest
Re: Blocks site esthus.in (favicon.ico)
« Reply #11 on: September 10, 2011, 03:38:56 PM »
Quote
If the icon comes from a website and you can trust that site, you can assume it is safe.
favicon.ico is taken from my site, http://esthus.in/favicon.ico


Quote
There is also a possibility it could be a FP.
Please explain what is FP?

Sorry for my bad English.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: Blocks site esthus.in (favicon.ico)
« Reply #12 on: September 10, 2011, 03:52:18 PM »
Hi BloodySoul,

This malware possibly has been flagged: -http://www.liveinternet.ru/favicon.ico
That should not be there now  because the unknown malware is now dead.
http://www.virustotal.com/file-scan/report.html?id=13bea65aa11d1a0b141f15922caf9f5dcae9c458f195c9f655845c5052d6a9e4-1315662138
see: http://urlquery.net/queued.php?id=2764  No alerts detected - image-x-icon
Maybe trying to get it outbound gets it flagged by avast, then it is a false positive.
FP means false positive detection ложных срабатываний обнаружения
So you should report that to avast, and see if they agree,

приветствовать,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

BloodySoul

  • Guest
Re: Blocks site esthus.in (favicon.ico)
« Reply #13 on: September 10, 2011, 04:11:26 PM »
I've already written a letter.
Ie I expect that my site will be removed from the database and it will work?


Thx polonus.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34067
  • malware fighter
Re: Blocks site esthus.in (favicon.ico)
« Reply #14 on: September 10, 2011, 04:14:40 PM »
Hi BloodySoul,

Until then users can leave avast installed can still visit your site here: via http://www.idoproxy.com ,and this without any ill effects,

polonus
« Last Edit: September 10, 2011, 04:17:14 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!