I contact you because approximately a half hour ago, I had to use Paypal to send some money to a friend, on Firefox and I was using Private Browsing, and AVAST suddenly blocked Paypal, I got a message saying “infected by HTML:PhishingPP-DH[Phish]”
I tried with Chrome and Internet Explorer, impossible to reach Paypal, like if Paypal was blocking it.
I tried again a few minutes later on Firefox (Private Browsing again), and it perfectly worked, I sent the money to my friend. I tested on Chrome and Internet Explorer too again, the Paypal site was reachable again.
Was it a false positive and it was fixed between my tries or is there a problem ?
I am using Paypal almost every day, it is the first time AVAST did that.
Yes, I have found a few topics here but the names are not exactly the same, so I preferred to ask, in case it was a real phishing and not a false positive.
Thanks
edit : well, I just tested again, and AVAST blocks Paypal again. 2 hours ago it worked after a few minutes, now it happens again
This is known, when genuine, as a so-called “supply chain attack”,
Aliases: Trojan-PWS.HTML.Phish (Ikarus) Trojan-Spy.HTML.Fraud.ix (Kaspersky).
We have observed these phishing pages using the following page names to steal your information:
Account Verification.html
Account.html
PP-658-119-347.htm after filling out the form,
redirects to hxxp://95.154.192.201/~review/cgi-bin/www.paypal.com.php
It is a webpage posing as itself as a legitimate PayPal webpage.
Above Info credits go to Microsoft’s Analysis by Patrik Vicol.
If all of the above is not there, we have a FP.
polonus (volunteer website security analyst and website error-hunter)
It is still happening. But if I log in, it is the real Paypal, I can send some money to my friend. I checked the microsoft link you posted, in the symptoms I read :
"The following may indicate the presence of this malware:
-An email inviting or requesting you to fill in your online banking or credit card details
-The display of the following pages, or ones similar, that ask you to fill out your PayPal, online banking or credit card details: .... "
I don’t see anything like this.
I scanned with AVAST and Malwarebyte’s Antimalware, no infection detected on my computer.
It is difficult to say that all of the above is not there, because AVAST antivirus says that it blocks the element infected by the phishing, so after logging in, nothing of the above is there. If AVAST antivirus didn’t block the element, maybe all of the above would be there ?
I contacted Paypal on Twitter through their help account @askpaypal, I will see what they will answer.
Even if I find weird that other antiviruses find it too.
The problem still occurs today.
(edit) : I contacted Paypal on twitter yesterday, they just replied, they asked me my email address and they forwarded my message to the technical service of Paypal, so someone from the technical service will email me soon. At least they will check their site and if they find anything wrong, they will do what it needs to remove it.