Fake or positive malware?

Everytime I try to enter Taig’s site (for jaibreakers) (This is the site) I get a pop up for Malware but no one reported this problem… Searched in Google and nothing… So can it be fake report? I am with free version and I have the extension for Mozilla browser.

and what does avast say?

i guess it say URL:mal … it means URL or IP is blacklisted for whatever reason, there can be many

Virustotal URL blacklist check
https://www.virustotal.com/en/url/b4a01880227d6333ccaf72c67810867507778d7ef8fa2a36b80e0827e778c040/analysis/1420420291/

IP history: multiple domains on same IP and many are blacklisted
https://www.virustotal.com/en/ip-address/61.160.224.229/information/ click more button under list(s) for more info

urlvoid http://www.urlvoid.com/ip/61.160.224.229

[b]IP ADDRESS: 61.160.224.229[/b]

We have found in our database of already analyzed websites that there are 38 websites hosted in the same web server with IP address 61.160.224.229. Remember that it is not good to have too many websites located in the same web server because if a website gets infected by malware, it can easily affect the online reputation of the IP address and also of all the other websites.

so from this info it seems like a IP block

Yes. Infection: URL: Mal
http://imgbox.com/abQEaiWG
This is what I get when I try to enter. But I think the site is safe.

http://zulu.zscaler.com/submission/show/f2620a46524e4b162c7441617e5b1055-1420419661
http://urlquery.net/report.php?id=1420419790594
http://urlquery.net/report.php?id=1420419938022
https://www.ssllabs.com/ssltest/analyze.html?d=taig.com
http://multirbl.valli.org/lookup/61.160.224.229.html
http://dnscheck.sidn.nl/?time=1420420906&id=1789222&view=basic&test=standard

Suspicious javascripts and external links:
http://www.websicherheit.at/en/website-security-check/

Blacklisted for spamming:
http://mxtoolbox.com/SuperTool.aspx?action=blacklist%3Awww.taig.com&run=toolpage#

493 error:
http://fetch.scritch.org/%2Bfetch/?url=www.taig.com&useragent=Fetch+useragent&accept_encoding=

And when you look at the picture/message,
you can see that it tries to open another website then the one you are thinking to visit.

Yes but when I disabled the Avast for 10 mins just to enter the site and download the jailbreak it opened only the site, no pop ups or redirection… :slight_smile:

It proves not every solution detects AdChief malcode!

polonus

About the AdThief threat: http://www.iphonehacks.com/2014/08/adthief-malware-jailbroken-ios-devices.html

polonus

Hello

avast block a redirects

sc​ript  type="text/javascript"> 
69:  var _bdhmProtocol = (("https:" == document.location.protocol) ? " https://" : " http://");
70:   doc​ument.write (un​escape ("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3F62cd6b3cb717418dcf69fe06c7f14677' type='text/javascript'%3E%3C/ sc​ript %3E"));
71:  < / sc​ript > 

https://urlquery.net/report.php?id=1420765709005