Warning Messages from Virus Protection Software When Coming to AzB Website

ctyhntr

RIP Kelly
Silver Member
If you know how, check to see if Anti-Virus definitions are up to date. You may have a different version of AV definition from your brother's machine.

Norton, Symantec, and others have occasionally been known to goof up and put false positives. They usually catch on, and send a corrected AV definition later.

No problem on my laptop but is being blocked and warned on my brother's computer...we both have Norton...
 

Pushout

AzB Silver Member
Silver Member
What Internet browser are you using (Internet Explorer, Firefox, Chrome, Safari are the big four) and what operating system (Windows, Mac, ChromeOS/Linux).

The warning below is referring to 32-bit Chrome running on Windows 64-bit (likely7,8,9, or 10). If you're not running Windows, and have Chrome browser installed, it could be a fake alert trying to get you to install malware.

Server side:
I checked netcraft, and AZ is running linux, likely apache or nginx. AZ staff can confirm that they're not hosted on Windows server. Outside of major corporations (traditional microsoft shops), linux variations are preferred server hosts.

I'm using Chrome, 64 bit on Windows 10. Haven't seen anything.
 

ctyhntr

RIP Kelly
Silver Member
Well, according to other news reports, Kaspersky was a hacking tool for the Israelis, our only democratic ally in the middle east. The Israelis were watching the Russians 'hack' in real time and they were the ones who tipped us off.

I think we dropped the ball by making one of the biggest faux pas in intelligence, revealing our sources. So whatever backdoor the Israelis had in, is now likely patched and Russians have no qualms killing people to prevent another opportunity for intrusion. More importantly we now lost a source of intelligence gathering on the Russians, and our ally may think twice before sharing intelligence with us in the future.

https://www.washingtonpost.com/worl...bdd1236be5d_story.html?utm_term=.63a2101ec822

Too bad they are a hacking tool for the Russian goverment.
 

Fenwick

AzB Silver Member
Silver Member
Yikes! That is scary. Food for thought. I just renewed Norton on 3 computers for $59. I hope I didn't make a mistake.:eek:

Maybe I'll switch to McAfee next year. :)

I've been using Bask for several years now. Morton and McAfee gave me nothing but problems. Just my expersnce.
 

JAM

AzB Silver Member
Silver Member

Attachments

  • Copy of P6036604[1]-HALLOWEEN.jpg
    Copy of P6036604[1]-HALLOWEEN.jpg
    25.3 KB · Views: 281

AlexandruM

AzB Silver Member
Silver Member
Enter the site using an Android smartphone, and Chrome browser. I got a message that my phone antivirus (360) crashed and I have to send more details, including IMEI to fix the problem. It's the first time I got such a message, I'm using same phone and antivirus for almost 3 years.
 

One Pocket John

AzB Silver Member
Silver Member
Is anybody getting warning messages from their virus protection when they come to AzBilliards-dot-com? This morning, I have gotten two of them. I can't remember the name of the first one, but my Norton blocked.

Just now, I got one called "Coinminer Download 6." Norton says it's a trojan.

Is it just my computer, or has anybody else encountered this on AzBilliards?

For my work, I go on hundreds of websites all day long for research, and I am not getting warning messages on those. Just AzBilliards. :frown:

I'm getting a message from Malwarebytes that says it is blocking this website using Chrome and that I can add IP address 38.134.106.126 to my list of blocking exclusions. I don't get the message when using Internet Explorer.
Is anyone familiar with the above IP address?

Thanks
John
 
Last edited:

ctyhntr

RIP Kelly
Silver Member
I installed Chrome and added the Malwarebytes extension, then browsed forums.azbilliards.com to try to replicate the issue, and nothing lit up.

JS Miner:
Quick google search indicates this is a name for a family of Java Script for Coinhive, a cryptocurrency miner (think bitcoin). Java Script runs inside your web browser, usually to provide video, audio or in this case to mine cryptocurrency.

My educated guess is the script isn't coming from AZ, but one of the ad sites is infected, which is likely hosted on IP 38.134.106.64. So, this could explain why some of us are seeing it, and not everyone. One possible tell is if loading pages takes longer than usual. If one of the advertisers pages are compromised, AZ staff can simply block it, if they haven't already done so.

:IP 38.134.106.64
rwhois V-1.5:0010b0:00 rwhois.cogentco.com (CGNT rwhoisd 0.0.0)
network:ID:NET4-26866A401A
network:Network-Name:NET4-26866A401A
network:IP-Network:38.134.106.64/26
network:Org-Name: Danidin LLC
network:Street-Address:9651 Hornbaker Road
network:City:Manassas
network:postal-Code:20109
network:Tech-Contact:ZC108-ARIN
network:Updated:2016-08-09 14:32:18
%ok

This is a web hosting service, likely hosting on of the AZ sponsor banners, which could be infected with JS Miner.

I'm getting a message from Malwarebytes that says it is blocking this website using Chrome and that I can add IP address 38.134.106.126 to my list of blocking exclusions. I don't get the message when using Internet Explorer.
Is anyone familiar with the above IP address?

Thanks
John
 
Last edited:
  • Like
Reactions: JAM

JAM

AzB Silver Member
Silver Member
I installed Chrome and added the Malwarebytes extension, then browsed forums.azbilliards.com to try to replicate the issue, and nothing lit up.

JS Miner:
Quick google search indicates this is a name for a family of Java Script for Coinhive, a cryptocurrency miner (think bitcoin). Java Script runs inside your web browser, usually to provide video, audio or in this case to mine cryptocurrency.

My educated guess is the script isn't coming from AZ, but one of the ad sites is infected, which is likely hosted on IP 38.134.106.64. So, this could explain why some of us are seeing it, and not everyone. One possible tell is if loading pages takes longer than usual. If one of the advertisers pages are compromised, AZ staff can simply block it, if they haven't already done so.

:IP 38.134.106.64
rwhois V-1.5:0010b0:00 rwhois.cogentco.com (CGNT rwhoisd 0.0.0)
network:ID:NET4-26866A401A
network:Network-Name:NET4-26866A401A
network:IP-Network:38.134.106.64/26
network:Org-Name: Danidin LLC
network:Street-Address:9651 Hornbaker Road
network:City:Manassas
network:postal-Code:20109
network:Tech-Contact:ZC108-ARIN
network:Updated:2016-08-09 14:32:18
%ok

This is a web hosting service, likely hosting on of the AZ sponsor banners, which could be infected with JS Miner.

Thanks for great info. :smile:
 

Snooker Theory

AzB Silver Member
Silver Member
Oddly only some of the forum threads produce the warning, most don't ?
I get a warning when trying to visit the the thread below, I have been browsing the forums most the morning. When I previously got the warning, it was just on one particular thread as well. Sorry I don't remember which it was.
I have malwarebytes, and windows 10. my flatmate also gets warning when trying to visit the link below on a different computer with different antivirus.


Does anyone else get this warning?
Hope that helps you guys in diagnosing the issue.

https://forums.azbilliards.com/showthread.php?t=351101
Y0h0I57.jpg
 

mjkeil62

AzB Silver Member
Silver Member
Oddly only some of the forum threads produce the warning, most don't ?
I get a warning when trying to visit the the thread below, I have been browsing the forums most the morning. When I previously got the warning, it was just on one particular thread as well. Sorry I don't remember which it was.
I have malwarebytes, and windows 10. my flatmate also gets warning when trying to visit the link below on a different computer with different antivirus.


Does anyone else get this warning?
Hope that helps you guys in diagnosing the issue.

https://forums.azbilliards.com/showthread.php?t=351101
Y0h0I57.jpg



I just tried it and am also getting that warning. I've checked out dozens of other threads and it doesn't happen. I am also using Windows 10, not sure what security is on this computer since it is my companies but I'm sure it's pretty decent.
 
Last edited:

ctyhntr

RIP Kelly
Silver Member
AFAIK, AZ has not enabled this browser communication protocol (https), so you will get that warning on az or any site that has not enable https.

In layman's, imagine this was World War II and HTTPS is Navajo. You're asking azbilliards to talk to your in Navajo. AZ doesn't have Navajo speaker.

There is another thread on pushing AZ to go https. https is just one tool in security. Just like playing the ghost only measure your offensive skill.

If AZ were to go this route, they would also need to shop for a SSL certificate and do their homework. An SSL certificate vouches for AZ identity. Not unlike looking up a person's in Mike Page's fargogate database, to vouch for the skill range.
 
Top