Author Topic: (goldie_) URL:mal block my site  (Read 5554 times)

0 Members and 1 Guest are viewing this topic.

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
(goldie_) URL:mal block my site
« on: April 04, 2012, 11:15:19 PM »
Re: http://forum.avast.com/index.php?topic=96334.msg771597#msg771597

I have the same problem with my website hXXp://www.chillout.rs/. I have scaned everything and didn't find any viruses or trojans.

It's somehow ridiculous for me to use Avast when it blocks my own website.

Avast is not alone. More sites that report blacklisting:
https://www.virustotal.com/url/2c559f2d4c5665b3c30bf316fad8981f5925f9e98a56e8182482962e4c931cd3/analysis/1333570085/
http://www.urlvoid.com/scan/chillout.rs/

Suspicious Patterns Found:
http://zulu.zscaler.com/submission/show/2e2420e5849643a096fc8447c2dc1cd2-1333570124

Unknown Reputation:
http://urlquery.net/report.php?id=38255

Avast! alerts an infected script:
https://www.virustotal.com/file/0b58701937ace49c9583a136033bfc8320b50d253b88d594f62136f0d8097ffc/analysis/1333573551/


However, a Wepawnet report shows clean:
http://wepawet.iseclab.org/view.php?hash=2307f168ba17273b356e1b234a745b0d&t=1333573784&type=js

Because you are the only one with that IP site, I suspect that the site HAS hosted malware recently.


To get your site whitelisted from avast, you can report your site here: http://www.avast.com/contact-form.php?loadStyles
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37526
  • Not a avast user
Re: (goldie_) URL:mal block my site
« Reply #1 on: April 04, 2012, 11:18:57 PM »
Sucuri report:  WordPress version outdated: Upgrade required.

URLVoid   http://www.urlvoid.com/scan/chillout.rs/
« Last Edit: April 04, 2012, 11:20:48 PM by Pondus »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33895
  • malware fighter
Re: (goldie_) URL:mal block my site
« Reply #2 on: April 04, 2012, 11:42:16 PM »
At some time the IP had  TR/Graftor.162 on it a.k.a. P2P-Worm.Win32.Palevo.dulw,
therefore could be an overdue IP ban.
Because that malware was here: htxp://chillout.rs/facebook-pic-#####-JPEG
Has been closed since: 2011-10-20 02:30:36
The WP software should be updated, else there is chance for the site to be re-infected.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

goldie_

  • Guest
Re: (goldie_) URL:mal block my site
« Reply #3 on: April 05, 2012, 05:01:09 PM »
Hi everybody and thanks for quick answer.

It's true that the website was infected long time ago but it was at the beginning of 2010. Virus was removed successfully in a short period and everything worked normaly after that.
Suddenly on 20th October 2011 Avast started to block that website even though the files on the server remained the same. Since then I'm using MAC OS for browsing that website. I have also used other PCs with other antivirus programs and i could browse the website without any problems.

There is no any *facebook*.* file on the server for a long time. I have also downloaded all files from server, scanned them with Avast and I didn't found anything suspicious.

I have already reported site here http://www.avast.com/contact-form.php?loadStyles few weeks ago but nothing happened since then.

Thanks once again for your help.

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: (goldie_) URL:mal block my site
« Reply #4 on: April 05, 2012, 06:00:03 PM »
I have already reported site here http://www.avast.com/contact-form.php?loadStyles few weeks ago but nothing happened since then.
Try reporting again and give a link to this topic. ;)
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

goldie_

  • Guest
Re: (goldie_) URL:mal block my site
« Reply #5 on: April 18, 2012, 10:56:11 AM »
More than 10 days since I sent an e-mail including the link to this topic and still nothing  :)
In the meantime Trend Micro changed its status about http://www.chillout.rs/ "The latest tests indicate that this website contains no malicious software and shows no signs of fraud."
http://global.sitesafety.trendmicro.com/

goldie_

  • Guest
Re: (goldie_) URL:mal block my site
« Reply #6 on: May 10, 2012, 01:50:30 PM »
more than a month  ;)

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: (goldie_) URL:mal block my site
« Reply #7 on: May 10, 2012, 11:12:03 PM »
Maybe the avast! team has something to say..? ???
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."