Author Topic: [SOLVED] Strange URL:Mal detections...  (Read 6217 times)

0 Members and 1 Guest are viewing this topic.

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5496
  • Whatever will be, will be.
[SOLVED] Strange URL:Mal detections...
« on: January 07, 2012, 10:00:31 AM »
I got an strange URL detected as URL:Mal only sometimes.
Sometimes I can access that page, sometimes (minutes after?) that page got blocked by Network Shield.
No update was coming during this test.
Some other images also blocked sometimes.

Here is the URL:
hxxp://tabakonomi.web.fc2.com/i/seven_samurais.jpg

Any ideas about this?
« Last Edit: January 11, 2012, 12:15:18 PM by NON »
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Strange URL:Mal detections...
« Reply #1 on: January 07, 2012, 04:54:18 PM »
Well it isn't the image that is the problem (clean on avast and VT) as the Network Shield is the one alerting and it is either the domain (Red) or one of the sub-domain (Green) or (Blue) tabakonomi.web.fc2.com/i/seven_samurais.jpg

Personally I find it strange when the network shield names a file rather than the domain alone. I would report as a possible false positive (network shield) it using the load styles contact page, http://www.avast.com/contact-form.php?loadStyles for further investigation.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Strange URL:Mal detections...
« Reply #2 on: January 07, 2012, 05:02:50 PM »
Hi NON and DavidR,

Site is not listed at hpHosts. Given safe here: http://urlquery.net/report.php?id=15044
and here: https://new.virustotal.com/url/9adef545171b9fcd5c628ca5385ea9000c7399e6af93d48f88c2d54b40893b0a/analysis/1325950934/
But there is something out there and avast Network shield seems to flag that...
Possibly suspicious code resides here: -static.fc2.com/share/fc2parts/js/jquery.js suspicious
[suspicious:2] (ipaddr:208.111.161.254) (script) -static.fc2.com/share/fc2parts/js/jquery.js
     status: (referer=-tabakonomi.web.fc2.com/i/samurais.jpg)saved 57272 bytes fd09a826a62fc6f5809d0a67bf0f80b3b76ca894
     info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
     info: [decodingLevel=0] found JavaScript
     error: line:3: SyntaxError: invalid flag after regular expression:
          error: line:3: filter(function(){return this.name&&!this.disabled&&(this.checked||/select|textarea/i.test(this.nodeName)||/text|hidden|password|search/i.test(this.type))}).map(function(E,F){var G=o(this).val();return G==null?null:o.isArray(G)?o.map(G,function(I,H){retur
          error: line:3: ^
     error: undefined function T.insertBefore
     error: undefined variable T
     suspicious:
Also a redirect to -http://error.fc2.com/web/403.html Cpan perl code...
The IP has a history of IE redirect virus and was in the  bothunter activity listing,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5496
  • Whatever will be, will be.
Re: Strange URL:Mal detections...
« Reply #3 on: January 08, 2012, 05:55:09 AM »
Hello DavidR and polonus,

So this detection could be a remnant of old infection.
I'll report this as a false positive and see results.

Thanks for answering.
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Strange URL:Mal detections...
« Reply #4 on: January 08, 2012, 12:39:56 PM »
You're welcome.

Well old/previous infections (or hacked site), if they have subsequently had a lot of alerts on the web shield from other avast users, that 'could possibly' have added it to the network shield malicious sites list, via the CommunityIQ feature.

But yes it needs further investigation.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5496
  • Whatever will be, will be.
Re: Strange URL:Mal detections...
« Reply #5 on: January 08, 2012, 01:54:06 PM »
I found this FC2 web hosting service shares one server (one IP) among several domains, and all of them are blocked.

Does network shield block per IP address, not domain names?

Many innocent domains get involved in this detection.
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Strange URL:Mal detections...
« Reply #6 on: January 08, 2012, 03:04:47 PM »
Well there is nothing published on exactly what is covered by the blocking (otherwise those seeking to exploit would have useful info). It rather depends on how widespread infections might be, but as far as I'm aware they try to block at the lower level, it used to be domain level so all sub-domains would be covered. I'm not sure it is IP based blocking as that is server based and may well cover many sub-domains, again nothing published.

Many of these quasi hosting sites have the host providing the integrated software SQL, wordpress, etc. so if that were the case then any vulnerability in it would extend to the sub-domains.

Which is why it needs further investigation by avast.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline NON

  • Japanese User
  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5496
  • Whatever will be, will be.
Re: Strange URL:Mal detections...
« Reply #7 on: January 11, 2012, 12:14:57 PM »
False positive seems resolved. :)

Thanks everyone!
Desktop: Win10 Pro 22H2 64bit / Core i5-7400 3.0GHz / 32GB RAM / Avast 23 Premium Beta(Icarus) / Comodo Firewall
Notebook: Win10 Pro 22H2 64bit / Core i5-3340M 2.7GHz / 12GB RAM / Avast 23 Free / Windows Firewall Control
Server: Win11 Pro 23H2 64bit / Core i3-4010U 1.7GHz / 12GB RAM / Avast One 23 Essential

Avast の設定について解説しています。よろしければご覧ください。

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: [SOLVED] Strange URL:Mal detections...
« Reply #8 on: January 11, 2012, 01:47:05 PM »
You're welcome, thanks for the feedback.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security