Author Topic: Need Someone to Test This Site Sandboxed.  (Read 2908 times)

0 Members and 1 Guest are viewing this topic.

Jack 1000

  • Guest
Need Someone to Test This Site Sandboxed.
« on: May 12, 2012, 07:43:00 PM »
Dear Avast,

Please sandbox and test ghostvillage.com.  About two years ago, Avast warned of a virus there, and a few weeks ago, I got a report from an Avast user who said that he/she went to the site and got a virus warning.  However, checks with Virus Total, URLVoid, and Brightcloud show a clean site.  Is this a FP that was not cleared?

Jack

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Need Someone to Test This Site Sandboxed.
« Reply #1 on: May 12, 2012, 07:55:23 PM »
Two years and a few weeks ago are ancient history in terms of infected sites as the avast web shield is doing a live scan. So you can't chase possible FPs on old results.

No alert by avast on the site when I just visited it using firefox 12.0.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Need Someone to Test This Site Sandboxed.
« Reply #2 on: May 12, 2012, 08:27:53 PM »

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Need Someone to Test This Site Sandboxed.
« Reply #3 on: May 12, 2012, 09:21:50 PM »
http://urlvoid.com/scan/ghostvillage.com/


No other site with the IP of 67.227.172.79. :-\
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Need Someone to Test This Site Sandboxed.
« Reply #4 on: May 12, 2012, 11:33:30 PM »
Hi !Donovan & Jack 1000,

I see a misused or defaced server history for that IP range. So there must be server issues for domains on that range have been defaced.
 Let us see; server gives away to the world and hackers all of the version and also via the system info under certain circumstances
see: htxp://sitecheck.sucuri.net/results/ghostvillage.com/  under system details -  safersite.de does not give this for the scan...
(this could be easily remedied: http://nixcraft.com/getting-started-tutorials/746-apache-php-web-server-security-hiding-version-information.html  (link author = Nixcraft)). OK here: htxp://urlquery.net/report.php?id=54520
One code hick-up flagged: pagead2.googlesyndication dot com/pagead/ads.js benign
[nothing detected] (script) pagead2.googlesyndication dot com/pagead/ads.js
     status: (referer=wXw.ghostvillage.com/)saved 10516 bytes ce5e416db4e9b7dbd24e979fefe8d7e9bea43dc3
     info: [decodingLevel=0] found JavaScript
     suspicious,

polonus
« Last Edit: May 12, 2012, 11:35:10 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Jack 1000

  • Guest
Re: Need Someone to Test This Site Sandboxed.
« Reply #5 on: May 13, 2012, 12:36:23 AM »
Hi !Donovan & Jack 1000,

I see a misused or defaced server history for that IP range. So there must be server issues for domains on that range have been defaced.
 Let us see; server gives away to the world and hackers all of the version and also via the system info under certain circumstances
see: htxp://sitecheck.sucuri.net/results/ghostvillage.com/  under system details -  safersite.de does not give this for the scan...
(this could be easily remedied: http://nixcraft.com/getting-started-tutorials/746-apache-php-web-server-security-hiding-version-information.html  (link author = Nixcraft)). OK here: htxp://urlquery.net/report.php?id=54520
One code hick-up flagged: pagead2.googlesyndication dot com/pagead/ads.js benign
[nothing detected] (script) pagead2.googlesyndication dot com/pagead/ads.js
     status: (referer=wXw.ghostvillage.com/)saved 10516 bytes ce5e416db4e9b7dbd24e979fefe8d7e9bea43dc3
     info: [decodingLevel=0] found JavaScript
     suspicious,

polonus

Thanks much Polonus!

This site should be watched IMO based on this new information.

Jack