Domain and IP blocked by Avast

Hello,
I hope this is the right forum to post about a possible false positive.

Since few days, my company website trucchislotmachine.com has been blocked by avast, it says URL:MAL

I have analyzed the website and the server and I don’t see any problem with it. Could you please check if it’s a false positive? I already sent a request through the contact form but I didn’t receive any reply.

IP and domain are blacklisted:
http://zulu.zscaler.com/submission/show/b9f38f30563a1d084a85a6e764b4d78b-1435935053
http://www.siteadvisor.com/sites/trucchislotmachine.com

https://www.virustotal.com/en/url/6faca9b68c2eb1d22c3bac63f674c760120f2f177ea82ae38882d237f9fc9c07/analysis/1435935088/
http://trafficlight.bitdefender.com/info?url=http://trucchislotmachine.com
http://urlquery.net/report.php?id=1435935290882
http://urlquery.net/report.php?id=1435935311410
http://quttera.com/detailed_report/trucchislotmachine.com

Outdated software:
https://sitecheck.sucuri.net/results/trucchislotmachine.com

server is vulnerable to the POODLE attack, expired certificate, certificate name mismatch :
https://www.ssllabs.com/ssltest/analyze.html?d=trucchislotmachine.com

Flagged here: https://www.virustotal.com/nl/domain/trucchislotmachine.com/information/
Potentially Suspicious files:
Detected unconditional redirection to external web resource in 17 instances.
[[]]
[[]] etc. etc.
Web application version:
Joomla Version 2.5.20 for: htxp://trucchislotmachine.com/media/media/js/mediamanager.js
Joomla Version 2.5.20 for: htxp://trucchislotmachine.com/language/en-GB/en-GB.ini
Joomla version outdated: Upgrade required.
Outdated Joomla Found: Joomla under 2.5.26 or 3.3.5
Outdated Web Server Apache Found: Apache/2.2.15 (has been mitigated?)

See: http://www.domxssscanner.com/scan?url=http%3A%2F%2Ftrucchislotmachine.com%2Fmedia%2Fmedia%2Fjs%2Fmediamanager.js

External malware link: htxp://js.users.51.la/17675171.js → https://www.virustotal.com/nl/url/8a976a1485f7a38701566af9a0253ae095f74f84faf574ab4b87bf50662ffe40/analysis/1435939856/

PHP vulnerable: ftp://ftp.netbsd.org/pub/pkgsrc/current/pkgsrc/lang/php54/README.html

polonus (volunteer website security analyst and website error-hunter)

Multiple blacklists http://multirbl.valli.org/lookup/188.121.50.243.html

Not a safe site at all.

Thank you for your support,
some issues are not real at all (e.g: meta HTTP-EQUIV=“REFRESH” which are affiliate redirects to 100% safe websites), I’m going to fix remaining ones and let you know.

The refresh issue is real and is considered as malicious behavior.

Eddy is right, flagged by Malware Script Detector v.2.0. detected Malware Customized XSS Malware in source:
https://s0.wp.com/_static/?? etc. etc. This is the Meta Tag "HTTP-EQUIV “REFRESH” - the client has to resolve: expound-v2.css?ver=2013-02-15s2.wp.com/wp-content/blog-plugins/wor… 0 B
https://s0.wp.com/_static/??-eJx9kdFO… 50.3 kB

[i]Basic Principle: Never attribute to malice what you can attribute to incompetence. The first place to look is for a problem on the page itself[/i].
Quote Info credits - Bob Trower.

polonus

Polonus I don’t understand your post.

I don’t get if you’re saying META REFRESH are bad in general, or if my website has one ore more malicious meta refresh.

Hi Matteo45,

I mean as general it isn’t an elegant solution, a 301 isn’t.
These test however were passed succesfully: http://mobilefriendlytest.website/index.php
Mind the advice there. The refresh gets carried through resolving in multiple alert boxes.
If there were a malicious Meta Tag it would not be visible for the public (visitors).
In that case the easiest and safest fix is to completely wipe your public server space and DB,
then reinstall from a known clean backup.

polonus

I’m a bit curious in knowing how avast decides wether blocking a site or not.
I requested to get out of siteadvisor blacklist, few minutes ago site was removed and now avast is not blocking trucchislotmachine.com anymore. So it just checks mcafee blacklist? COOL!
I’m glad I don’t use MS win…

The website - trucchislotmachine.com is still being blocked by Avast Webshield as with URL:Mal
One of these domains on the same IP can also be responsible for the blocking:
http://sameid.net/iphttp://sameid.net/ip/188.121.50.243/
What should be done is that the server shouldn’t give out excessive server version info: Apache/2.2.15 (CentOS) to the world and attackers.
This could be easily mended by settings in the server configuration, so we get Apache period.
While even with CentOS 6.3 apache/2.2.15 (centos) is not vulnerabe to exploits, just turn off the Apache and PHP versions in the headers and miraculously you might get a clean bill of health…

polonus

Hi polonus,
thank you for your support.
I’ve hidden Apache and PHP version info in http header and all the previous issues, except:

  • email blacklists: most of them are automatic and/or distribuited and I cannot find out how to submit site for review
  • https://sitecheck.sucuri.net/results/trucchislotmachine.com => forced a rescan but it incorrectly sees website blacklisted on siteadvisor
  • meta refresh: I understand your concerns about unconditional redirects but unfortunately I cannot move to other solutions like php header redirect

Matteo

Hi Matteo,

Report to virus@avast.com and ask for an exclusion (refer to this thread here). They could consider that, I cannot as unblocking websites is only reserved for avast team members, I am just a volunteer here with relevant knowledge. Anyway you considerably improved your website security by reporting here. Stay secure with Avast!

Damian

P.S. Joomla scan OK: https://hackertarget.com/joomla-security-scan/
Note that this site: -http://www.open-society-kz.org/modules/mod_roknavmenu/themes/basic/code.php
had a threat identified as: Exploit.HTML.IFrame-6

pol

I sent an email 5 days ago, no reply and no action. Website trucchislotmachine.com is still blocked by avast.

A email?
You need to submit a ticket.

That’s why I sent an email.

Where should I submit a ticket? I think I already did it, but I need to double check.

Matteo

https://support.avast.com/Tickets/Submit

Asyn,
I submitted a ticked some weeks ago, I received an automatic reply and nothing else.
Domain is still blocked, I don’t understand why.

Do you think this is fair? My website is losing about 40-50 customers per day, I’m losing lot of money and Avast is not taking care of this false positive.

Someone please help me in contacting Avast.

Post your ticket-ID.

Ticket ID: #IST-853-68707

Could you please give more details? Do you mean webserver tries to attack and exploit target pc installing angler exploit kit?

Thank you for your help.

Matteo