Avast srabyvaet falsely on my website, writes that by un address is sites infected with viruses.
We checked your server with five anti-virus.
Not one anti-virus does not work, including Avast!
But when you try to go to the site, it says that on the avast site allegedly viruses.
Avast triggered by un address 5.254.100.170.
By un address apparently were previously infected sites, now un address 5,254,100,170 is one domain reywood.ru.
Domain reywood.ru 3 months is on the un address 5.254.100.170.
We have already created a ticket. on your system: Open ticket: # RHX-614-27853
https://support.avast.com/Default/Tickets/Ticket/View/RHX-614-27853
But for some reason considered a ticket a week.
And do not answer that ticket be accepted for processing!
How can we be?
What is your website URL ?
And what is the message from avast?
IP 5.254.100.170 is blacklisted by apews.org
Entry matching your Query: E-1227094 5.192.0.0/10 CASE: C-131 Unallocated CIDR, no traffic until allocated, or allocated to bad reputation provider or allocated but dynamic / generically named IPs, or bogons, see www.cidr-report.org, or orphaned IP / CIDR in routing table History: Entry created 2014-03-10
Website url http://reywood.ru/
IP 5.254.100.170 is blacklisted by apews.org QuoteEntry matching your Query: E-1227094 5.192.0.0/10 CASE: C-131 Unallocated CIDR, no traffic until allocated, or allocated to bad reputation provider or allocated but dynamic / generically named IPs, or bogons, see www.cidr-report.org, or orphaned IP / CIDR in routing table History: Entry created 2014-03-10</blockquote>What is it?
The situation is now such.
Reywood.ru site is on un address 5.254.100.170.
By un address 5.254.100.170 is the only site reywood.ru
Check IP blacklisting here http://whatismyipaddress.com/blacklist-check
If you think this is wrong…
You can upload files and report issues to avast here : http://www.avast.com/contact-form.php (select subject according to Your case)
Well here is that IP’s address badness history: https://www.virustotal.com/en/ip-address/5.254.100.170/information/
There was a complaint for that IP: http://www.liveipmap.com/5.254.100.170
If the detection is IP related and your website is clean, you should ask for an exclusion via
http://www.avast.com/contact-form.php
polonus
Possible before 5.254.100.170 owner un addresses used it for personal gain.
Now ip address 5.254.100.170 given to me by this site eeee.
IP address is in my 6 months and only you using for this site reywood.ru.
Website reywood.ru not what harm does not.
Use third-party base of gray IP addresses that are not updated, it’s bad.
These two domains on same IP had or have malware: https://www.virustotal.com/en/url/7a9613316b6bf0f7d97030d01ff5beafcab9118971c24dab81941d9323804977/analysis/
and
https://www.virustotal.com/en/url/e8d10616130ade07f48eb8155db227401d33ec40281332cb48dcd04c8c0c72a7/analysis/
polonus
These domains are not mine.
interesting!
Now will communicate with the host.
I see so, many domains located on the ip address.
http://www.ip-ping.ru/siteip/
Найдено сайтов: 1
reywood.ru
Hoster said that these domains (d-ranka.net.ua,i-zyskat.net.ua) were used to address this un (5.254.100.170).
After see the owner domains (d-ranka.net.ua,i-zyskat.net.ua) refused to host.
And hoster gave me this ip address (5.254.100.170).
http://multirbl.valli.org/lookup/5.254.100.169.html
IP is blacklisted by Apews, but that is nothing to worry about since they do not update their databse.
http://zulu.zscaler.com/submission/show/e8b51821a44f7e025fbe51994336a848-1404217107
Netblocksize is risky.
Ask you host to change it.
Quttera is reporting the site (1 file) as suspicious:
http://quttera.com/detailed_report/reywood.ru
Looks to me other than the above mentioned, the site can be deblocked.
If you haven’t done so already, please use the contact form to ask avast to allow the website.
hello
URL was unblocked
nothing this being blocked by Avast.
URL still blocked by Trend Micro, reported via the block page to review it ![]()
try scan. http://mcshield.net with Trend Micro. ![]()
Also blocked.
Also sent for review ![]()
MCShield team have reported it to trend a million times … they will not listen
If you have MCS on a computer with Trend you cant download updates
the page is based on votes from users like
rather than analyze the detection mechanism
not clearly trust the results of trend micro having seen detection rates of false positive.