HTML:RedirME-inf [Trj] detection

Hello,

I reported it 2 weeks ago, didn’t get an answer and today our website is still blocked by Avast (HTML:RedirME-inf [Trj]).

As far as I know we were never compromised so I’m not sure why Avast is blacklisting www.drillscan.com

Any clue?

https://www.virustotal.com/en/url/9bcc0c276cd42f5210803b40141dde70a1680b1e0279b555a5cee7d8da87cfa2/analysis/1454502993/
http://www.web-malware-removal.com/website-malware-virus-scanner/?url=www.drillscan.com
http://www.urlvoid.com/scan/drillscan.com/
http://trafficlight.bitdefender.com/info?url=http://drillscan.com

http://retire.insecurity.today/#!/scan/2972f022d798b44648f13c0309bdb60f26eba45a3eabb1420861ddbb7a93dc5a

post screenshot of the avast block message

html scan
https://www.virustotal.com/en/file/d543209b3f55685122f43ec45ceadfc2046f08ac44afb124efe7aa47e6af079a/analysis/1454503907/

Hi,
It was blocked due to: drillscan.com/copilot%20host%20555%20741%20572%20435.exe
I am now unblocking the domain :wink:

Thanks.

However the executable you listed was digitally signed and not infected so I’m not sure why this trigerred the blacklist.

Could have just had low prevalence, or triggered suspicious behaviour in sandboxed environment… possibilities are endless. Digitally signing a PE file doesn’t make it automatically clean to Avast :-).