Pondus
8
If the site is on the list of "known malware distribution" , seems to be logical that Avast! knows which malware is being distributed. (other wise why put the site on the list????)
So, if the malware is known, should be detected by the file shield.
At least this seems to be a logical chain of events…
Today they may distribute a known malware tomorrow they may distribute a complete new not known yet … also when loaction URL/IP is blocked by many or taken down they start up at new not blocked location and the arms race continue
https://www.zscaler.com/blogs/research/top-exploit-kit-activity-roundup-spring-2017