Help with blacklisted URL from a customer (URL:Mal)

Hello.

I’m one of the customer support reps of a LMS (Learning Management System) and I’m wondering if anyone can help us out with this situation.

Since last Sunday one of our customers has reported that one specific website URL (URL/script) has been preventing their users from accessing one of the files from our system showing the message “URL:Mal” to users that have Avast and the Avast plugin in their browsers.

Not all parts (scripts) from their website are blocked though, only a specific one which allows users to “open” or “save” files from the LMS. The specific URL that is showing this alert from Avast is this one in particular: https://ulp.untrefvirtual.edu.ar/location.cgi

To be able to access it though you need to be an authenticated user, that’s why I can’t find a way to verify it with the different websites that I saw on this forum that checks whether a url is blacklisted or not. I’m pretty sure it is because it only shows this behaviour for users with Avast and if you completely disable it, it works, or if you don’t have an antivirus installed. Also, according to other posts “URL:Mal” means exactly that it was blacklisted.

We don’t know how this happened mainly because the LMS and that particular URL to the cgi script (https://ulp.untrefvirtual.edu.ar/location.cgi) was working fine before Sunday for all users, and we would really like to know why it was blacklisted so we can take steps to prevent it from happening again.

We sent a request to get it removed from the blacklist yesterday but we haven’t received a reply. We’ve checked today and it’s still blacklisted. This is affecting thousands of students and teachers who use this system and use Avast as so many do.

Could someone help us out? I can provide any information you need but we’re completely clueless as to why it was blacklisted in the first place. We really need to get it removed from that blacklist as it’s becoming a big inconvenience to the user base.

Thanks in advance.

Romina

Hello,
where did you sent the request to get it removed? Was it https://www.avast.com/false-positive-file-form.php ?

Milos

Hi,
I have removed ulp.untrefvirtual[.]edu[.]ar/location.cgi from our blacklist. It was blocked because a malicious PDF was downloaded from this URL.

Hi Milos! Yes, I sent it through that form. We don’t know how long it usually takes for each request to be analysed or if once it’s analysed we were going to get a reply, so I thought it best to write a post here just in case, specially considering that it was blocking an important feature in our system.

Thank you so much HonzaZ! If you have the name of the file that would help. Otherwise, I’m going to run a antivirus check in our backups and see if I can find that malicious PDF that caused this.

Thank you all so much for your quick response to this matter. We’ll be implementing some measures to try prevent this from happening again.

Regards,
Romina