system
August 26, 2016, 8:33am
1
Hello,
Could you help me to remove my site from your blacklist?
http://www.aplusoassociates.com/ was infected, but it’s all clean now.
Scaned by virustotal.com :
This URL was last analysed by VirusTotal on 2016-08-02 16:34:31 UTC
Detection ratio: 0/68
Unblock it, please.
Thank you!
Eddy
August 26, 2016, 8:46am
2
Hoster insecurety: Name Servers Versions
WARNING: Name servers software versions are exposed:
192.241.152.201: “9.8.2rc1-RedHat-9.8.2-0.23.rc1.el6_5.1”
95.85.28.55: “9.8.2rc1-RedHat-9.8.2-0.30.rc1.el6_6.3”
Exposing name server’s versions may be risky, when a new vulnerability is found your name servers may be automatically exploited by script kiddies until you patch the system. Learn how to hide version.
Malicious phishing from IP. Moziila Observatory Scan: https://observatory.mozilla.org/analyze.html?host=www.aplusoassociates.com
meagre F-status.
pol
system
August 26, 2016, 3:30pm
4
system
August 26, 2016, 3:34pm
5
Hoster insecurety: Name Servers Versions
WARNING: Name servers software versions are exposed:
192.241.152.201: “9.8.2rc1-RedHat-9.8.2-0.23.rc1.el6_5.1”
95.85.28.55: “9.8.2rc1-RedHat-9.8.2-0.30.rc1.el6_6.3”
Exposing name server’s versions may be risky, when a new vulnerability is found your name servers may be automatically exploited by script kiddies until you patch the system. Learn how to hide version.
This server configuration, and I can not change them
https://observatory.mozilla.org/analyze.html?host=www.aplusoassociates.com - this general information on the standard of safety, there is no evidence that the site has a virus.
system
August 26, 2016, 3:38pm
6
http://www.aplusoassociates.com/ This site has been cleaned by the web security company.
They have removed all malicious code on the site.
Re-scan and delete it from your blacklist please.
Eddy
August 26, 2016, 3:53pm
7
https://www.virustotal.com/en/ip-address/138.201.31.212/information/ - this report is old and does not contain any relevant information Guess you haven't looked at the date of the detections. Latest one is 2016-08-26 08:11:51
These two libraries are contained in the original version of wordpress and do not contain malicious code It still need to be fixed.
If you don't, the site will be vulnerable to infections/abuse.
http://urlquery.net/report.php?id=1472201470880 - this link is not malicious scripts loadable It very clearly shows that malware is present on that IP/ASN.
HonzaZ
August 29, 2016, 7:50am
8
aplusoassociates[.]com was indeed infected, most probably by nuclear EK. I am unblocking it now , but please do pay attention to insecurities/vulnerabilities others pointed out, or your domain might be blocked again in the future.