Author Topic: Possible FP on web site scan  (Read 7932 times)

0 Members and 4 Guests are viewing this topic.

AU4U

  • Guest
Possible FP on web site scan
« on: February 21, 2012, 04:00:14 AM »
Virustotal site scan: https://www.virustotal.com/url/f3e9f9af364f7306a92738af330b806fc5fb8001aacbe9eb7c5240e4434c1856/analysis/1329792028/
Website in question: http://www (dot) flipmytext (dot) com/tattoos/

avast! reports: Infection:js:Redirector-NK [Trj]

Would someone please respond as to the safety of this site and links?
TY
« Last Edit: February 21, 2012, 04:31:49 AM by MichaelT. »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Possible FP on web site scan
« Reply #1 on: February 21, 2012, 06:37:17 AM »
INFECTEDhttp://sitecheck.sucuri.net/results/http://www.flipmytext.com/tattoos/
OBS: you may get a avast warning if you enter this site, since the malware code is displayed there


Malware info:  http://sucuri.net/malware/malware-entry-mwjs159

AU4U

  • Guest
Re: Possible FP on web site scan
« Reply #2 on: February 21, 2012, 07:01:43 AM »
So whats with the VT scan showing nothing? 0/19????
And what happens from here, is the site owner or the host notified of this?
I would sure like to have this resolved, I would like to use there services again.
« Last Edit: February 21, 2012, 07:03:34 AM by MichaelT. »

Gargamel360

  • Guest
Re: Possible FP on web site scan
« Reply #3 on: February 21, 2012, 07:21:45 AM »
So whats with the VT scan showing nothing? 0/19????
And what happens from here, is the site owner or the host notified of this?
I would sure like to have this resolved, I would like to use there services again.
The VT "scan" isn't a scan at all, it just checks the url against blacklists.  Blacklists always lag behind infections when it comes to legit sites. 

By all means, report it to the sites webmaster if you wish.  Someone might have done it already, if you start getting virus alerts on your site, it usually does not take long for someone to inform you.  But it couldn't hurt to let him know, just in case.

AU4U

  • Guest
Re: Possible FP on web site scan
« Reply #4 on: February 21, 2012, 07:47:11 AM »
Holy Crap Batman!
VT site scans are from Blacklists?!?!?!?!?!?! :-\

Don't tell me the File Scans are the same, I might just poop myself!

Gargamel360

  • Guest
Re: Possible FP on web site scan
« Reply #5 on: February 21, 2012, 08:14:58 AM »
Don't tell me the File Scans are the same, I might just poop myself!
No, not at all.   File scans are run against  x-amount of scanners

Also, you can scan a site with VT.....you have to save the site itself to your PC, then upload it to VT, if I remember correctly.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Possible FP on web site scan
« Reply #6 on: February 21, 2012, 08:21:06 AM »
to scan at VT for the infection you need to download the html and upload that to VT. Sonething i can not do froom my Nokia phone......but if you wait 8 hours to after work..,

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Possible FP on web site scan
« Reply #7 on: February 21, 2012, 09:06:51 AM »
i think URlVoid.com have a webinfection scanner. I think you find the link at the bottom, somethin like 'scan url for infection'

AU4U

  • Guest
Re: Possible FP on web site scan
« Reply #8 on: February 21, 2012, 05:29:47 PM »
OOOOOH, Bad news Pondus   ???
Your recommended site, URLVoid.com, came up with a 0/9.   :P  And one of them was avast!
URLVoid.com SCAN RESULTS: http://vscan.urlvoid.com/analysis/05fe8195bc1997b8a9bee8ae5243b15c/dGF0dG9vcw==/
So, does URLLink do the same as VT on the site scans and use the blacklists?

EDIT
So, I found this at the VT site, for the full article, this LINK: https://www.virustotal.com/faq/#url-scans


« Last Edit: February 21, 2012, 06:09:21 PM by MichaelT. »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Possible FP on web site scan
« Reply #9 on: February 21, 2012, 06:07:46 PM »
It depends what scan at URLVoid you use   ;)    the one you used  NO

But URLVoid also have a web rebutation scanner.......it is the one you see when you enter urlvoid.com


and here is one more  http://urlquery.net/report.php?id=23587 
this one will also display any malware reported on that url, if any......see "Alerts"



OBS: and the old VT did download the html file and scan it when scanning a URL...the new does not do that....yet



« Last Edit: February 21, 2012, 06:13:52 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Possible FP on web site scan
« Reply #10 on: February 21, 2012, 06:08:53 PM »
Next to the avast flagged issue with images/spacer.gif [Spyman malware], the following code at the site also deserves attention: -pagead2.googlesyndication.com/pagead/ads.js suspicious
[suspicious:2] (ipaddr:74.125.227.26) (script) -pagead2.googlesyndication dot com/pagead/ads.js
     status: (referer=wXw.flipmytext.com/tattoos/)saved 11642 bytes 801d92f3f23999c4778ddcdae56f305e0fd84bbc
     info: [decodingLevel=0] found JavaScript
     suspicious:
See also: http://urlquery.net/report.php?id=23583

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Possible FP on web site scan
« Reply #11 on: February 21, 2012, 06:17:57 PM »
at the moment it seems no AV is detecting this....or the Sucuri detection is wrong/not malicious ?

flipmytext.com.htm
https://www.virustotal.com/file/3054d52bca75a61157866f070c05c879e0b25fad73c9d1df21fd4327bc056cbe/analysis/1329844502/

tattoos.htm
https://www.virustotal.com/file/3717577639c67774b3c02463bb5ac1c1aa77b842f699d630fdbea6c04b95fb84/analysis/1329844596/



have uploaded to Sophos / Avira / Norman lab.... will post the result when i have it 

« Last Edit: February 21, 2012, 06:21:55 PM by Pondus »

AU4U

  • Guest
Re: Possible FP on web site scan
« Reply #12 on: February 21, 2012, 06:31:58 PM »
Oddly enough, the site has new owners as of July last year.
1st time I've had any problems with this type of thing.



Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Possible FP on web site scan
« Reply #13 on: February 21, 2012, 06:33:46 PM »
could you attach a screen shot of the avast warning you get ?

AU4U

  • Guest
Re: Possible FP on web site scan
« Reply #14 on: February 21, 2012, 06:53:42 PM »

« Last Edit: February 21, 2012, 07:01:09 PM by MichaelT. »