false alarm Or not?

is this site infected?[suspicious] :P[/suspicious]

xxx.gladiator-antivirus.com

http://zulu.zscaler.com/submission/show/99dad8aaf79375c02ee9b87385cf940c-1356801611

Infection Details

URL: xxx.gladiator-antivirus.com/
Process: C:\Program Files (x86)\Google\Chrome\App…
Infection: URL:Mal

Given as benign here: http://zulu.zscaler.com/submission/show/99dad8aaf79375c02ee9b87385cf940c-1356801909
on line 10 This domain has just been registered for one of our customers!
Subversion going on behind a DAV proxy, avast detects: http://silmor.de/proxysvn.php (link article author = webmaster AT silmor DOT de)
The domain is blacklisted in http://hosts-file.net/?s=www.gladiator-antivirus.com.
See: http://vurldissect.co.uk/?url=1735750

polonus

Please ‘modify’ your post change the URL from http to hXXp, as you did with the first URL (but not the infection details) to break the link and avoid accidental exposure to suspect sites, thanks.

Nothing on sucuri.net or urlvoid.com, urlquery.net (http://urlquery.net/report.php?id=549088) shows an image of the page that indicates that this domain has recently been registered, so it is possible that you may have inherited a problem from a previous site on that IP address.

There is an on-line contact form, http://www.avast.com/contact-form.php?loadStyles for: * Sales inquiries; Technical issues; Website issues; Report false virus alert in file; Report false virus alert on website; Undetected Malware; Press (Media), issues.

  • If you are reporting an FP, then you get another input field open, click Browse button and navigate to the file or enter the web URL for the site you wish to submit for review (Network Shield), etc. A link to this topic also wouldn’t hurt.

As this is an IP block (URL:Mal) this could be as DavidR said a block for malware previously launched from that IP,

polonus