Can virustotal be trustable? well read

nissimezra

Level 25
Thread author
Verified
Apr 3, 2014
1,460
Hi everyone

I wanted to share something with you.

One day at work we had a fishing attack, someone jailbreak the boss email and sent a link to a fishing site.

well the first thing I did with the link is to scanning it with virus total, the first scan showed the site is clean only chrome detected it as a malware site later on bitdefender was added so a total of 2.

long short, a day latter ESET detected the site as a fishing site and MSE detected an HTML file as dangerous.
fishing.png

I reported the site to microsoft and 4 days latter it was blocked as a fishing site.

the site has been changed since then

well happy me went to virustotal to reanalyze the and i was surprised to see that the result are the same, I uploaded the html file and it showed me clean. I double checked the the link the file and virus total and it's still the same. ESET is blocking the site, but when I scanned it in virustotal este show clean. chrom was the first that detect it as fishing.

well today I browswer to this link
http://windows7themes.net/en-us/set-internet-explorer-cache-size-via-ie-registry-or-group-policy/
ESET blocked it so i went to scan it and again it is showing me that eset clean site
https://www.virustotal.com/he/url/d...2a1f6b0e20a4147793dac09a/analysis/1397307760/

now to the old story of the fishging that was confirmed. here is the email that was sent, it was a month a go and the site was changed since then

Email
Here is the Document I uploaded it via Google Drive.

Read or Download Here it's very important.

Thank you.

No virus found in this incoming message.
Checked by AVG - www.avg.com
Version: 8.5.339 / Virus Database: 270.12.50/2150 - Release Date: 01/01/14 06:47:00

End

The date of AVG is not correct since it was sent on march 15, smart but.....

the site has been changed since then and no longer the
for some resume eset and chrome no longer blocking it
 
Last edited:
  • Like
Reactions: Cats-4_Owners-2

nissimezra

Level 25
Thread author
Verified
Apr 3, 2014
1,460
Thanks

Now none of the anti viruses detecting it, chrom, eset mse, and avast.
it used to be bloked
 

Mateotis

Level 10
Verified
Well-known
Mar 28, 2014
497
It is possible that an AV doesn't block the malicious website, but it blocks the payload, which is more important.

Also, if you really want to let your vendors know about it, here's a great article about how you can submit samples to any AV/AM vendor.
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Have you considered the threat (*.htm page) has been eliminated from the site?

Google SafeBrowsing Report
http://www.google.com/safebrowsing/diagnostic?site=windows7themes.net
This site is not currently listed as suspicious.

Of the 411 pages we tested on the site over the past 90 days, 0 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2014-04-12, and the last time suspicious content was found on this site was on 2014-02-18.

Malicious software includes 1 trojan(s).

URLVoid.com (Combined results from various sources)
http://www.urlvoid.com/scan/windows7themes.net/
Flagged by 2 vendors; Scumware and DrWeb

VirusTotal.com Results (Combined results from various sources)
https://www.virustotal.com/en/url/d...2a1f6b0e20a4147793dac09a/analysis/1397318209/
Flagged by 1 vendor; DrWeb

Comodo Web Inspector
http://app.webinspector.com/public/reports/21227505
> Nothing detected

Bitdefender TrafflicLight
http://trafficlight.bitdefender.com/info?url=windows7themes.net
> No suspicious activity
 

MalwareDetective

Level 9
Verified
Well-known
Dec 16, 2013
429
Thanks

Now none of the anti viruses detecting it, chrom, eset mse, and avast.
it used to be bloked
What are you scanning? You are probably not scan the URL because avast and MSE is not an engine there. scanning HTML files is not the same as scanning URL. HTML files detection and URL detection is not the same.
To see the malicious sites AV blocking you should enter the Phishing site here:
ZnLAi0B.png
 

nissimezra

Level 25
Thread author
Verified
Apr 3, 2014
1,460
hi all

the site has been change since then and no longer direct to fishing

I did scan the URL in virustotal, and then it showed me that only chrome found it unsafe which was true at the time
at the evening that day ESET blocked the URL as fishing site, after 2 days avast chrome blocked it and mse detected the html file and the didn't load.
around five days after I received the email MSE blocked the website when I used IE 11 up to date, I don't have a photo to prove it and I was surprised my self that MSE blocked the site completely with red warning the the web page is phishing, that was the first time i seen mse blocking web pages and as far as i know it doesn't have this option but it did.
now i am suprised to see that non of the above blocking the site anymore even that they did 2 weeks ago.
 

MalwareDetective

Level 9
Verified
Well-known
Dec 16, 2013
429
@nissimezra If the site the site is no longer redirct to Phishing than the site was probably hacked or compromised but now he got cleaned (the phishing code had been removed). If so - there is no reason for detection. Can you share Virustotal report or URL here or in PM? I can check him.
 
Last edited:

nissimezra

Level 25
Thread author
Verified
Apr 3, 2014
1,460
thanks @MalwareDetective

I dont have any thing left of it, all i had shared here
I might have logs from eset I'll need to look for

bitdefender is still blocking the site.

best regards
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top