Avast alert on Paypal link

My customers are reporting issues when going to Paypal from a link on my site.

I’m able to see it on my own computer as well when using a pay button link, but if I go directly to Paypal there is no problem.

I have had my computer scanned twice and my website scanned by my hosting provider. All scans are clean.

error is https://www.palpal.com/webapps/hermes/token

Infection is: HTML:Paypal-B [Phish]

This is done using the Chrome browser.

Is this a false positive? What can I do about it?

I’m losing customers.

Any help appreciated.

Kerry

A good start would be fixing the certificate problems.
https://www.ssllabs.com/ssltest/analyze.html?d=www.palpal.com

I don’t get as far as an avast alert as Firefox blocks it and gives its own ‘Your connection is not secure’ message for that link.

Indeed, browsers already blocking it/giving a alert.

But there is more going on there that make the site not secure :
http://urlquery.net/report.php?id=1497977867329
https://www.virustotal.com/en/ip-address/66.96.149.17/information/

I made a typo in the URL : should be:

https://www.paypal.com/webapps/hermes/token

Cannot GET /webapps/hermes/token
gives a " Cannot GET /webapps/hermes/token"

That URL if you had made the error on your site, would certainly look very like a phishing (typo squatting) attempt.
https://www.palpal.com/webapps/hermes/token

Using that palpal URL typo and the correct URL I now get a different firefox error - Cannot GET /webapps/hermes/token.

Get that same error using Chrome, etc.

http://allanstudios.ca/avast-error.jpg

The URL still isn’t right. It’s just all I can see from the error msg.

Here is a screen shot of the Avast error.

Kerry

Have a look in the Web Shield log file, it should have the full path.
C:\Documents and Settings\All Users\Application Data\AVAST Software\Avast\report\WebShield.txt (XP location)
C:\ProgramData\AVAST Software\Avast\report\WebShield.txt (win7 & later location).

When you post the URL break it so it isn’t active, drop the https and www element and post the rest.
e.g. palpal.com/webapps/hermes/token....rest of url…

paypal[.]com/webapps/hermes?token=7D872073KA021964G&useraction=commit&rm=2&mfid=1497894243890_4502ce827ce69

This error appears several times in that file. Each time it has a different token value:

token=9B334303VA4368538&useraction=commit&rm=2&mfid=1497966802638_75b6d21a2b854
token=75H33843LP067150L&useraction=commit&rm=2&mfid=1497971813778_97b2ced264393
token=3PB623340P818991F&useraction=commit&rm=2&mfid=1497971982973_36afdcc28c887

Kerry

Detection has been already fixed. Should be fine with new VPS update.

I also have this issue with Avast / Paypal - and I am unable to pay important invoices that are due !! Please help!

I updated Avast Virus definitions and program engine - but still not working. What do you mean by "should be fine with the new vps update?? What do I need to update?

I get “threat blocked” when accessing a paynow button from a provider - it goes to

https://www.paypal.com/webapps/hermes?token=

Then I get the same popup as mentioned in the above https://forum.avast.com/index.php?topic=204295.msg1402669#msg1402669

I am running Virus definitions 170620-2 and Program v 17.4.2294

I am still getting the same error so I’m not sure what needs to be updated

Kerry

As Savcin said, you need to update the VPS.

But as it looks avast still need to roll out the new VPS.
If I look at the time Savcin posted it should be something like 170521-0 but that isn’t rolled out yet.

Yep :slight_smile:

Some users don’t realise that 170620-2 means : ( year ) 17 (month ) 06 ( day ) 20 - ( update ) 2.
So that is yesterdays update.

Greetz, Red.

I believe that the -2 at the end of the VPS version is actually the 3rd of the day, -0 being the first of the day. Slightly confusing but I believe correct.

Indeed, they start with -0

Strange though that the latest still is 170620-2
There should have been at least one update today.

Sorry to be dumb…but what is the VPS?

Kerry

https://www.avast.com/faq.php?article=AVKB22