Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > Other ESET Home Products
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 26th, 2011, 07:57 AM
loyukfai loyukfai is offline
Regular Poster
 
Join Date: May 2008
Posts: 104
Default Reporting A False-Positive Website

Greetings.

There's a website (hxxp://www.cm2g.org) which I believe has been marked as a false positive by ESET. Tried using http://kb.eset.com/esetkb/index?page=content&id=SOLN141 and also wrote to them (samples at eset.com) a few days before, but no response thus far.

What do you think I could do to get ESET's attention?

Thanks in advance.

Note: urlvoid.com and AVG says the site is clean. But NOD32 says there is a JS/Kryptik.BN trojan

Snipped: URL obfuscated to prevent infection when clicking on it unwittingly.

Last edited by Marcos : September 27th, 2011 at 05:08 AM.
  #2  
Old September 26th, 2011, 08:40 AM
dmaasland's Avatar
dmaasland dmaasland is offline
Frequent Poster
 
Join Date: Nov 2010
Posts: 468
Default Re: Reporting A False-Positive Website

Are you sure it's clean? There's a very suspicious, obfuscated piece of JavaScript at the bottom of the HTML, and it does some weird active X things..
Attached Thumbnails
Click image for larger version

Name:	js.kryptik.png
Views:	11
Size:	16.3 KB
ID:	229456  

Attached Images
 
  #3  
Old September 27th, 2011, 03:31 AM
loyukfai loyukfai is offline
Regular Poster
 
Join Date: May 2008
Posts: 104
Default Re: Reporting A False-Positive Website

No. Other than the fact that urlvold.com and AVG say so.

Do you have a better idea to make sure of it...?

Cheers.

P.S. Just tried http://www.virustotal.com/ and http://siteinspector.comodo.com/, no suspicious things reported.
  #4  
Old September 27th, 2011, 03:32 AM
dmaasland's Avatar
dmaasland dmaasland is offline
Frequent Poster
 
Join Date: Nov 2010
Posts: 468
Default Re: Reporting A False-Positive Website

Well i'm pretty sure that code isn't doing anything to help the site. I'd contact the site's admin.
  #5  
Old September 27th, 2011, 04:01 AM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,656
Default Re: Reporting A False-Positive Website

Check this out: -http://vscan.urlvoid.com/analysis/84f1eb67e4de67183ec1325d8ed08589/Y20yZy1vcmc=/
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-
  #6  
Old September 27th, 2011, 04:54 AM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,656
Default Re: Reporting A False-Positive Website

Quote:
Originally Posted by loyukfai
P.S. Just tried http://www.virustotal.com/ and http://siteinspector.comodo.com/, no suspicious things reported.
I suggest you try VT again.

Make a search on Virustotal with this MD5: 84f1eb67e4de67183ec1325d8ed08589

And you will see this result 25/44!
So I really doubt that this is an FP!
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-

Last edited by SweX : September 27th, 2011 at 05:44 AM.
  #7  
Old September 28th, 2011, 10:02 AM
loyukfai loyukfai is offline
Regular Poster
 
Join Date: May 2008
Posts: 104
Default Re: Reporting A False-Positive Website

Ahhh.... Thanks for the heads-up, I'll contact the site admin about it...

But how come it showed up clean before...? Did I do something wrong...?

Last edited by loyukfai : September 28th, 2011 at 10:08 AM.
  #8  
Old September 29th, 2011, 09:12 AM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,656
Default Re: Reporting A False-Positive Website

Quote:
Originally Posted by loyukfai
Ahhh.... Thanks for the heads-up, I'll contact the site admin about it...


Quote:
But how come it showed up clean before...? Did I do something wrong...?
Not sure. Idk how you did it though
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-
  #9  
Old October 1st, 2011, 09:58 PM
loyukfai loyukfai is offline
Regular Poster
 
Join Date: May 2008
Posts: 104
Default Re: Reporting A False-Positive Website

The site admin told me he re-uploaded the index page, which doesn't have that obfuscated piece of code, but NOD32 is still giving me the prompt.

Could it be a transparent proxy? Or the webserver itself was compromised?

It's strange that the prompt only shows up on the index page, for the rest it seems to be fine. Maybe it's because the rest have .php suffix?

Cheers.
  #10  
Old October 1st, 2011, 10:25 PM
J_L's Avatar
J_L J_L is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 4,833
Default Re: Reporting A False-Positive Website

Quote:
Originally Posted by SweX
Check this out: -http://vscan.urlvoid.com/analysis/84f1eb67e4de67183ec1325d8ed08589/Y20yZy1vcmc=/
Never knew that was separate. Why didn't they integrate the 2 services?
__________________
  #11  
Old October 2nd, 2011, 01:00 PM
loyukfai loyukfai is offline
Regular Poster
 
Join Date: May 2008
Posts: 104
Default Re: Reporting A False-Positive Website

@J_L: What 2 services are you talking about...?

BTW, used Bing IP search to look for other hosts on the same server, but they seem to be fine, can I rule out compromised server as a possibility...?

Cheers.
  #12  
Old October 2nd, 2011, 01:06 PM
dmaasland's Avatar
dmaasland dmaasland is offline
Frequent Poster
 
Join Date: Nov 2010
Posts: 468
Default Re: Reporting A False-Positive Website

Quote:
Originally Posted by loyukfai
The site admin told me he re-uploaded the index page, which doesn't have that obfuscated piece of code, but NOD32 is still giving me the prompt.

Could it be a transparent proxy? Or the webserver itself was compromised?

It's strange that the prompt only shows up on the index page, for the rest it seems to be fine. Maybe it's because the rest have .php suffix?

Cheers.

Not sure what he did, but the JS is still there. It sounds like someone has access to the server, or someone is able to use something like XSS to modify files.
  #13  
Old October 2nd, 2011, 02:09 PM
SweX SweX is offline
Massive Poster
 
Join Date: Apr 2007
Location: Sweden
Posts: 3,656
Default Re: Reporting A False-Positive Website

FYI. Here's an IP Scan: -http://www.ipvoid.com/scan/64.29.151.221

Detections: 3/26
Status: Dangerous
__________________
OpenDNS ESET Smart Security
-A Heavy product is not the same as a Bloated product and vice versa-

Last edited by SweX : October 2nd, 2011 at 02:22 PM.
  #14  
Old October 2nd, 2011, 09:17 PM
J_L's Avatar
J_L J_L is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 4,833
Default Re: Reporting A False-Positive Website

Quote:
Originally Posted by loyukfai
@J_L: What 2 services are you talking about...?
That and urlvoid.com of course.
__________________
  #15  
Old October 4th, 2011, 11:01 AM
loyukfai loyukfai is offline
Regular Poster
 
Join Date: May 2008
Posts: 104
Default Re: Reporting A False-Positive Website

Oh you meant urlvoid.com and virus.urlvoid.com?

P.S. Got rid of the virus at last, it's in the webpage.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > Other ESET Home Products « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:13 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums