False positives and exploits which are undetected

Only blocked by Google Safeweb. :stuck_out_tongue:
This time the malware is activated. >:-D
Always Thank You~ :-*

PS.: Comodo’s Proactive Protection is best :-TU beautiful :-TU

[attachment deleted by admin]

Only detected by Google Safeweb. :stuck_out_tongue:
Now, Malware is activated. ;D

[attachment deleted by admin]

Hi~
Only detected by google safeweb.
This time, malware is activated.
Thank you~ :-*

[attachment deleted by admin]

Thanks for your feedback, Gaige!
Could you please send environment of your pc ? I’m interesting in java version, flash version etc. I’ll try to get infected with your’s version of software. To protect your privacy you can pm me.

Siteinspector didn’t find it.
I think mal download server is blocked by Gov-secure-center.

Thank you.
ps. The samples are submited. :a0
ps2. Doesn’t Siteinspector have ‘Behavior Detection System’? ;D

[attachment deleted by admin]

Only detected by Google safeweb.
This time. The exploits&Drive-by-download are activated. >:-D

ps. Mal urls are always changed. :stuck_out_tongue:

[attachment deleted by admin]

Hello~

This time. Malware is activated. 88)
Always Thank you~ ;D

ps. The malware has been removed by Comodo cloud scanning(Behavior Blocker). :-TU :-TU :-TU :-TU :-TU :-TU
But Site-inspector didn’t detect it. ???

[attachment deleted by admin]

gesomoon.com = Normal Safe Website.
gesomoon.co.kr = Fake Phishing Website => Malware is Activated.

Only detected by Google Safeweb.

[attachment deleted by admin]

Many thanks Gaige for all those feedbacks :-TU

Hello~ ;D

  • This time, Drive-by-Downloads is activated.
  • Site_inspector didn’t detect it.

Thank you~ ;D

Full link:
h :stuck_out_tongue: :stuck_out_tongue: p://dvdprime.donga.com/bbs/view.asp?major=MD&minor=D1&master_id=23&bbsfword_id=&master_sel=&fword_sel=&SortMethod=&SearchCondition=&SearchConditionTxt=&bbslist_id=2358082&page=1

[attachment deleted by admin]

Hi. ;D

Siteinspector Result:

Full link:
hxxp://dvdprime.donga.com/bbs/view.asp?major=MD&minor=D1&master_id=23&bbsfword_id=&master_sel=&fword_sel=&SortMethod=&SearchCondition=&SearchConditionTxt=&bbslist_id=2360879&page=1

This time, Malware is activated.
Thank you~ ;D

ps. The exploit removes my iE-temp-folders. :stuck_out_tongue: :stuck_out_tongue: :stuck_out_tongue: :stuck_out_tongue: :stuck_out_tongue: :stuck_out_tongue: :stuck_out_tongue:

[attachment deleted by admin]

Hi ;D

(currently time)

Siteinspector always doesn’t detect these. ;D
And… The exploits&malwares don’t work in Virtualmachines. :o
After the malware deletes self.
So ‘Behavior Blocker’ can’t submit(auto) these malware samples. ;D
‘Comodo Behavior Blocker’ needs improve that strong grab/catch the malwares. (for auto-submit samples) >:-D

ps. My english is bad. sorry. :cry:

[attachment deleted by admin]

Thanks again for your feedback, Gaige! Your English level is enough to understand you. :-TU Yes, we know, that some malware use different tricks to catch and escape virtual environment. I guess this is one of those :cry: . And yes, it would be great to auto-upload malware samples and links they come from. CIS is a different product so I can’t make promises here. We’ll check this link with our internal tools. Stay tuned…

Dear Sirs,

I have repeatedly send E-mail enquiries regarding false positives in your Site Inspector to your sales@comodo.com E-mail address.

But so far I have not received any response from you.

My website has for a long period of time been listed on the Virustotal.com site inspection list as “malware”.

Now since I am the website owner and also the owner of the software that is being sold via that website, I know the there is absolutely nothing malicious about neither the website, nor the sofware that is available from the website.

I have hundres of satisfied customers each year and I have the documentation to prove it as well (my sales numbers on Paypal alone would make it evident that people have no problems with my trial software and so purchase the full version).

I again urge you to re-review my website and fix this false positive since your disclosure of this information may hurt my business.

Below you can see a copy of the Virustotal scan list, and as you can see Comodo is the only scanner which rates my site as malicious:

Webadresse Skanner Resultat
ADMINUSLabs Clean site
AlienVault Clean site
Antiy-AVL Clean site
Avira Clean site
BitDefender Clean site
C-SIRT Clean site
CLEAN MX Clean site
Comodo Site Inspector Malware site
CyberCrime Unrated site
Dr.Web Clean site
ESET Clean site
Fortinet Unrated site
Google Safebrowsing Clean site
K7AntiVirus Clean site
Kaspersky Clean site
Malc0de Database Clean site
Malekal Clean site
MalwareDomainList Clean site
MalwarePatrol Clean site
Minotaur Clean site
Netcraft Unrated site
Opera Clean site
ParetoLogic Clean site
Phishtank Clean site
Quttera Clean site
SCUMWARE.org Clean site
SecureBrain Unrated site
Sophos Unrated site
SpyEyeTracker Clean site
Sucuri SiteCheck Clean site
URLQuery Unrated site
VX Vault Clean site
Websense ThreatSeeker Clean site
Wepawet Unrated site
Yandex Safebrowsing Clean site
ZDB Zeus Clean site
ZeusTracker Clean site
zvelo Clean site

Please tell me what information or actions is required to fix this issue.

Thank you.

Could you post the url to the CSI report of your website here? To get the report start at http://app.webinspector.com/ ,fill in your site and wait for the report. Then publish the link.

Hello

Could you please provide name of your website? We need it to research this question.

malicious (virustotal and urlvoid detection)

http://www.urlvoid.com/scan/h4420.com/

http://www.urlvoid.com/scan/sunksexiestlocals4you.com/

Hello, kitmub!
Thanks for your reply. Updated report for hxxp://h4420.com/ here Website Malware Scanner | Online Website Virus and Malware Scanner.

Second link has adult contert :P0l and javascript “stopper” when living page but can’t be approved as malicious.

Here is a site that is trying to steal your paypal info not detected.

Hello, kidx86!
Thanks for your attention, here is updated report Website Malware Scanner | Online Website Virus and Malware Scanner