URL: Mal error on our website - please remove site from your blacklist

Hi,

I manage the website for our company - www.forthcapital.com
My colleague (who uses Avast Premier) brought this to my attention - he cannot visit our website with Avast installed on his system.
Disabling Avast allows him to visit the website just fine. This is reported for only our website and on all browsers.

I tested by installing both Avast Premier and Free on a freshly formatted system - same URL: Mal error on IE, FF and Chrome.
I can assure you we have clean systems - We use Symantec Endpoint Cloud protection for the company systems and we’re networked behind hardware Firewalls.

I saw similar posts on Google and Avast forums where users are recommended to do a 3rd party scan and post data for remedial actions. The test system is fully clean - fully wiped for fresh OS reinstall, no chance of malware.

Our site is hosted with Godaddy and we log on to the hosting Control Panel every day to check for issues. I’ve done online AV scans on the website, no problems found.

Can you please help remove our website from your blacklist.

Many thanks. Mohammed.

You can report a URL here: https://www.avast.com/report-a-url.php

URL:Mal = IP and/or domain is blocked.
It doesn’t mean by default that the website is infected/malicious although it can be ofcourse.

Vulnarable libraries :
http://retire.insecurity.today/#!/scan/1de3abb8955700c4f1cc8aa6ff68abd9b02ed348d3775b37a6ead4a8ea8b1fff

Many blacklisted domains on that ASN :
http://sitevet.com/db/asn/AS26496

Blacklisted IP :
http://multirbl.valli.org/lookup/107.180.54.210.html

Advise :
1] replace the vulnerable libraries
2] get dedicated hosting

The site used to work fine on my colleague’s system a few days ago. I think 5-7 days ago, this URL Mal error started.
We didn’t change anything on the site.

Also, more than 90% websites used shared hosting.
If one site out of thousands starts acting up (due to no fault of ours), we get blacklisted due to server IP? All the websites on the shared server? What is the logic behind this?

We don’t have any issues with any other AV programs.

Did you report (Reply #1) the URL yet…!?

If one site out of thousands starts acting up (due to no fault of ours), we get blacklisted due to server IP? All the websites on the shared server? What is the logic behind this?
If a IP block is set or a domain block, depends on several things. Amongst them are (not limited to) : - What is detected (spam, phising, malware etc) - How many domains on that IP are malicious - If the server itself is infected - What part of the detection tool(s) is detecting something

The logic is to protect peoples systems from getting infected.

Welcome mohammed60,

When this site does not spread malcode, it could become excluded from blocking by an Avast Team Member.
You then should wait for one to come and react here in the thread.

We cannot exclude your domain as that only can be performed by Avast Team Members .
We are just forum-volunteers with years of experience and relevant knowledge in website security.

Consider this script that should be retired: http://www.domxssscanner.com/scan?url=http%3A%2F%2Fcdnjs.cloudflare.com%2Fajax%2Flibs%2Fjquery%2F2.2.0%2Fjquery.min.js
Number of sources found: 33
Number of sinks found: 10

Consider whether your cloud security is in good hands with bulk hosting services like GoDaddy/CloudFlare?
Security is often not their first priority, isn’t it?
E.g.: prod.iad2.secureserver.net has bad WOT web rep.

A meagre F-Status here: https://observatory.mozilla.org/analyze.html?host=www.forthcapital.com

The site could be non-malicious per se,
but it cannot stand a full vulnerability scan against “Musa’s rod and Suleiman’s ring”.
Keep that in mind.

Have a nice day,

polonus (volunteer website security analyst and website error-hunter)

Yes this was reported to Avast team. I was advised this is being analysed by Virus Lab now.

Thanks Polonus. That was very helpful.
I’ll try and fix jquery.

OK, now wait for their verdict. :wink:

Avast Virus Labs team have removed my URL from their blacklist. Problem solved.

Thanks everyone for your input. Much appreciated.

You’re welcome.