Avast blocks site but VT is all green.

Status
Not open for further replies.

nclr11111

Level 6
Thread author
Verified
Well-known
Feb 25, 2011
277
So i ran across a website in hunt for a new wallpaper in google images. The site (***.ryylxjw.com) was instantly blocked by Avast as infectious.
As far as i can tell Avast blocks 15 items on the site and refuse to open it. Seen in retroperspective i should have noticed that the url was, lets say, a bit odd but i didn´t check at the time since i was clicking on an image.
You can see what image i was clicking on in the upladed image.

Anyway, i went to VT and scanned the url and the scan says 0/68. So now i´m a bit lost to what Avast is protecting me from?
Is it a real threat or a FP???

Not sure if this is the correct forum but i had a hard time finding a place for this question.
1.JPG
 

askmark

Level 12
Verified
Top Poster
Well-known
Aug 31, 2016
578
My gut feeling would be Avast didn't like the domain name. It looks like random characters strung together which would probaby break a rule that Avast uses to determine if a site is safe or not.

I ran the site through a couple of online checkers and it came up clean overall, but the odd domain name was flagged as a potential risk.
 
Last edited:

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
Just that domain name in itself , screams a warning.
But hey, if you want to play there, at least you can get to know TwinHeadedEagle :p
And it could be that the sites name has been associated with nefarious actions in the past too.
 

nclr11111

Level 6
Thread author
Verified
Well-known
Feb 25, 2011
277
It's better to stay away from that site. :) Sometimes being curious can get you in trouble. :p

Ahh, but you never learn if you're not curious and ask questions! Just have to take precautions and be ready to take the consequences. :p
Just that domain name in itself , screams a warning.
But hey, if you want to play there, at least you can get to know TwinHeadedEagle :p
And it could be that the sites name has been associated with nefarious actions in the past too.

I think I'm a bit slow but what's the "TwinHeadedEagle"??
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
Ahh, but you never learn if you're not curious and ask questions! Just have to take precautions and be ready to take the consequences. :p


I think I'm a bit slow but what's the "TwinHeadedEagle"??
Keep getting wallpapers there and you will see :p
hes our resident Malware removal expert rofl
And Zemana Staff member
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
And seeing you were hunting for wallpapers, weather you were sandboxed or not, you obviously
planned on keeping the images, the images can contain code too, i'm sure you knew this, but what happens when
your not sandboxed and that image code gets executed ? I hope you deleted any images. Investigating the link
out of curiosity is cool, having any images from there may cost you. Just a Heads Up
 

askmark

Level 12
Verified
Top Poster
Well-known
Aug 31, 2016
578
And seeing you were hunting for wallpapers, weather you were sandboxed or not, you obviously
planned on keeping the images, the images can contain code too, i'm sure you knew this, but what happens when
your not sandboxed and that image code gets executed ? I hope you deleted any images. Investigating the link
out of curiosity is cool, having any images from there may cost you. Just a Heads Up
You make a very valid point, which I wouldnt have considered myself. Thanks.
 

nclr11111

Level 6
Thread author
Verified
Well-known
Feb 25, 2011
277
Keep getting wallpapers there and you will see :p
hes our resident Malware removal expert rofl
And Zemana Staff member

Time to take a walk in the hall of shame.... Really need to spend more time here at MT! :D
And seeing you were hunting for wallpapers, weather you were sandboxed or not, you obviously
planned on keeping the images, the images can contain code too, i'm sure you knew this, but what happens when
your not sandboxed and that image code gets executed ? I hope you deleted any images. Investigating the link
out of curiosity is cool, having any images from there may cost you. Just a Heads Up
Def a valid point! But I can honestly say I've never came across anything like this when hunting for wallpaper. Usually I use Alphacoders HP but this was the exception and a learning experience it was! :rolleyes:
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Seek second opinion siteadvisor or verify by reporting it to the Avast itself, since the information will provide much clearer when you request it.

In such typical browsing, Google Searches have no guarantee to filter out those bad sites however having siteadvisor tool can give you ratings without worries.
 
R

Ramona

The main issue is that you use custom settings and you set the sensibility to high. It's a FP so don't worry about it :)
 
  • Like
Reactions: askmark
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top