Register Free Newsletter Plus Membership
  • Home
    • Newsletters/Alerts
    • Forums
    • About
    • MS-DEFCON System
    • Master Patch List
    • Register
    • Login
Microsoft Patch Defense Condition level 2 Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it.
SIGN IN Not a member? REGISTER PLUS MEMBERSHIP
  • Security threat on Askwoody

    Home » Forums » Frequently asked questions, feedback, suggestions » Suggestions about improving the Forum » Security threat on Askwoody

    • This topic has 8 replies, 4 voices, and was last updated 3 years, 5 months ago.
    Author
    Topic
    New Reply
    Berserker79
    AskWoody Lounger
    December 30, 2021 at 3:24 am #2409406

    Just thought to report this to be on the safe side, hopefully I’m on the proper forum for this.

    Today I began receiving threat warnings from Kaspersky Internet Security when visiting askwoody. This did not happen before and everything was fine yesterday. It appears the warning is sent every time I access askwoody.com by typing the URL directly or through a link, but not when I browse through the site’s pages. As far as I can tell, an object embedded somewhere on the site is triggering the following warning from KIS:

    Event: Access denied
    User: ****
    User type: Active user
    Application name: firefox.exe
    Application path: C:\Program Files (x86)\Mozilla Firefox
    Component: Web Anti-Virus
    Result description: Blocked
    Type: Threat of data loss
    Name: https://app.box.com/public/static/hzuah4febg4wivrem6a788p4148v0lnm.jpg
    Precision: Exactly
    Threat level: High
    Object type: Web page
    Object name: hzuah4febg4wivrem6a788p4148v0lnm.jpg
    Object path: https://app.box.com/public/static
    Reason: Cloud Protection

    Is it just me? Or a “false positive” from KIS?

    BTW, I’m on Windows 10 20H2 Home updated with December patches, running Firefox 95.0.2 (latest version) and KIS version 21.3.10.391 (g) with latest antivirus definitions.

    Reply | Quote
    Viewing 3 reply threads
    Author
    Replies
    • Alex5723
      AskWoody Plus
      December 30, 2021 at 4:33 am #2409412
      Berserker79 wrote:

      Is it just me? Or a “false positive” from KIS?

      I use Kaspersky 21.3.10.391 (G) and Chrome and never got any warnings.
      No warnings using Firefox 91.4.1esr.

      The alert is for E Pericoloso Sporgersi’s avatar jpg.

      Just visited one of his posts at:

      https://www.askwoody.com/forums/topic/avast-free-tries-to-increase-foothold/

      No alert.

      1 user thanked author for this post.
      Berserker79
      Reply | Quote
      • Berserker79
        AskWoody Lounger
        December 30, 2021 at 4:50 am #2409413

        Thanks Alex, that’s helpful to know. I’m no longer receiving that warning from KIS at the moment, but I’ve got a feeling it might be a false positive from KIS and nothing to worry about. After reading your reply I ran an online scan in VirusTotal of the “suspicious” URL flagged by KIS and the report came back with a “1 [out of 93] security vendor flagged this URL as malicious” and that one vendor is Kaspersky.

        According to the info in the VirusTotal report, Kaspersky flags the URL as “Phishing“, but the other 92 security vendors report it “Clean“. The details in the report state the following:

        Categories
        Forcepoint ThreatSeeker personal network storage and backup
        Sophos personal network storage
        BitDefender business

        The report details contain some additional data that maybe can be useful if anyone needs to look further into this.

        EDIT: I do receive the warning again after the link to the post with E Pericoloso Sporgersi’s avatar jpg was included in your post above. Odd, but no reason to worry. Thanks again for your reply.

        Reply | Quote
    • Susan Bradley
      Manager
      December 30, 2021 at 8:52 am #2409435

      Susan here:  I edited the title because it was causing the forum format to break.  I’ve scanned the site and don’t see anything?

      Susan Bradley Patch Lady/Prudent patcher

      Reply | Quote
      • Berserker79
        AskWoody Lounger
        December 30, 2021 at 12:28 pm #2409483
        Susan Bradley wrote:

        Susan here: I edited the title because it was causing the forum format to break. I’ve scanned the site and don’t see anything?

        Thanks for taking the time to check this out Susan. The URL which seems to be the cause of the problem according to Kaspersky is this one: https://app.box.c*m/public/static/hzuah4febg4wivrem6a788p4148v0lnm.jpg (I put an asterisk in there myself just to be on the safe side)

        According to Alex above “The alert is for E Pericoloso Sporgersi’s avatar jpg.“: maybe he can share additional input on how he came to that conclusion.

        Also, maybe you can run a scan of that URL on VirusTotal and see if the details of the report there make any sense to you.

        Reply | Quote
    • Alex5723
      AskWoody Plus
      December 30, 2021 at 1:14 pm #2409488
      Berserker79 wrote:

      According to Alex above “The alert is for E Pericoloso Sporgersi’s avatar jpg.“: maybe he can share additional input on how he came to that conclusion.

      Clarification : it is not the jpg file that has been flagged its the app.box.com.. URL/site that has been flagged by your KIS (but not on my KAV)
      Kaspersky is not on the list of A/Vs checked by virustotal.

      Reply | Quote
      • Bob99
        AskWoody MVP
        December 30, 2021 at 1:43 pm #2409493

        Kaspersky is not on the list of A/Vs checked by virustotal.

        Then why is it listed at the top of the list in the following URL?:

        https://www.virustotal.com/gui/url/004b379e21019f1dadfd8b10869953b42f93ff536dff29994e8f35c58f1b41cc/detection

        Granted, the name does say Kaspersky, but does not elaborate as to which product/engine is used in the detection scheme.

        Additional info that I found while digging to see just how far this “detection” goes. As @Alex5723 points out just above, the detection is positive for the SITE, but only to the https://app.box.com/public/static level and no higher. In other words, going to just the app.box.com/public site results in no positive results, and there are no positive results for the plain site of app.box.com. It’s only when you go to that particular sub-directory of /static, or beyond that sub-directory to the exact .jpg file mentioned in other quotes above that Kaspersky gives the positive result in the list.

        Since there’s a positive result just for a plain sub-directory on the app.box.com site, it would be nice to know exactly what Kaspersky doesn’t like about that individual sub-directory!

        Could there have been some phishing material in the not too distant past that Kaspersky traced back to that particular sub-directory, but that isn’t there now, that caused them to flag the entire sub-directory as malicious?


        @Berserker79
        –

        Since @Alex5723 uses Chrome and has reportedly not experienced issues as you have using FF, try loading the AskWoody site in Edge or another chromium-based browser to see if it triggers the aforementioned issue with Kaspersky. BTW, I also use FF95.0.2 and have noticed that FF has blocked third party cookies from the app.box.com site and from the (possibly related) dl3.boxcloud.com site.

        One final note: Per the Page Info utility built into Firefox, the allegedly “offending” image/.jpg is actually the image at the bottom of all of E Pericoloso Sporgersi’s posts, NOT the avatar image listed above the name. In other words, the image is actually the signature, not the avatar portraying a senior, distinguished individual.

        • This reply was modified 3 years, 5 months ago by Bob99.
        1 user thanked author for this post.
        Berserker79
        Reply | Quote
        • Berserker79
          AskWoody Lounger
          December 31, 2021 at 3:13 am #2409573
          Bob99 wrote:

          Since Alex5723 uses Chrome and has reportedly not experienced issues as you have using FF, try loading the AskWoody site in Edge or another chromium-based browser to see if it triggers the aforementioned issue with Kaspersky. BTW, I also use FF95.0.2 and have noticed that FF has blocked third party cookies from the app.box.com site and from the (possibly related) dl3.boxcloud.com site.

          Thanks for your reply @Bob99 – I loaded this thread in (Chr)Edge and it triggered the same warning in KIS, except that the offending URL has changed to the following (below I replaced the “com” domain with some *** just to be on the safe side):

          https://dl3.boxcloud.***/d/1/a1!CMi-sbG0z9EkLPL_5YWU5XsEDkgkeJAX8PpcdG0Le-ew7CmVxYLeNoSAWS11RvgexTo_IDefDrkUBZxhUHavSzpzgLkHLmAafRncnkSyM6AGPFo3n9B1ud_RJ6sdy9UacaohCEDEv5LrH89UlyHo9tylwPnRiOiQpO4n7fOB8nEEhrWpLrdDEhECrLE-D3SOGoy0DuTIlnPlIDKEBu6I0sWWWanWcZd-IkcBp5plR77BBTXoiBvMRPPHA21Mtr_C7pQnyxCkRKW-0PkglKoZvdtiYg7xw9cwF2kDkjvK8orH9mEi-DfbktcsiYrtAB0TetEqzXjT0FVBBepmZLIYmVPnSzTwPIIQk1es7JMF0PFlJmT3g7YLSCdJzt1Idnzq2XaKfZrgHMmoyQ5nvuqfXuyu5t0carBF8jLUqeClb2Mg6Dii8I9eQk7C9SAmNaguZxb6QlgP6ykr7su8hUMDUPQ-AG_q1e7yePEV0GQSsk03GW-kaT9SmbSul8-Uw3WOTq7Pnlfo97snXWCAGPLUuhUksHwmZQpRP9yrd4fXeEfWvd5UuQGCl_a0ZVRf8u3coxWPJdf3dDVjE0oxh3QZ1I1mh_xkDaYrLLjYuqJICGageh738iRAaQeitreX02-ztLQPRanq7nEZyTtSCd8YRa0u6XxuRb0P_K_rEeWqwl3b1pgugHYSQQBT0eZ47CgOg79PQ-rpi2oe0Xx6X1zjWSh4qp72Cv7xe6Q5r9cLJN_1MM40vdAwvgFg6xwgPqZU-69FWiHvb04c2fnVi98XZetY7TiIsSVHilX_CcX_4YeR7RpifJwLMDwAMoVYJU4mJ3ITLXQMXGRJlK4RnZBkLRs70DsYBliAPmFoLXelp6heDcZ1b11rhqRTAiilSNt7_N8nSu_8GVtDCOj0PJcEFTWVnk0GkFlveq87s3nhlf3UlYb4CaO-bzNwwEUyd0prhTTlU-mvNKlewDAXcSOK6DpbdlFipUlItdkl6Xq7WT9GgcJC_5ouY5NP0ByKEb8ORaqptkuu6L_IZ87q5tHXzVzteh1ybpDzi8oGErZJ9k5gXPYDWlywCIA6B-E4YEWXAgH8V8lUQ9XsYRabGwasnVcPt2S1yVBJWzg3hftmf9X7Y9U_Dzo8HxvcLfouuaVS8jB5GkDt3biMCm-w_ZlbcK0cFX1Dq01HeioR4Vxg86M_YgfFU9-0MXE0w5gaZkrqXcXO4jyfHgDRfFyWyhcL7xtfwpS_VltvI_dCttu8hHGrlXKjuDsTbTzqPHDhbA7olN-Bld_1kZegV3UP1zp34oi0uOOTAUMbVaJUmPo1Bzf1nnEZPT8VOZyVWNyw4fhUCtTRow_wCWuASBMeXxYK4lj4U4jyITVl9VrgxzJTxoFuiw5yBIe2nAZiX8_dHv9pn5xyBKFzZWtVoh5dpQ../download

          Interestingly, when submitted to VirusTotal the above URL is reported to be “clean” by all security vendors, Kaspersky included, but the URL pointing to the jpg file is still flagged as “phishing” by Kaspersky when scanned on VirusTotal.

          I don’t have another Chromium-based browser installed on my system atm, but I can install one if you think it might be helpful to check this out in a further browser. I’ve got a feeling this issue is related to KIS rather than to the browser I’m using, but it’s odd that Alex using a different Kaspersky product has no problem.

          Reply | Quote
    • Alex5723
      AskWoody Plus
      December 30, 2021 at 2:52 pm #2409501
      Bob99 wrote:

      Then why is it listed at the top of the list in the following URL?:

      My bad. I missed that 🙁

      Reply | Quote
    Viewing 3 reply threads
    Reply To: Reply #2409573 in Security threat on Askwoody

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information:




     
    Cancel
DON'T MISS OUT!
Subscribe to the Free Newsletter
We promise not to spam you. Unsubscribe at any time.
Invalid email address
Thanks for subscribing!

Register
Lost your password?

Plus Membership

Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.

AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.


Get Plus!

Welcome to our unique respite from the madness.

It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.

Search Newsletters

Search Forums

Advanced Search

View the Forum

  • Recent Replies
  • My Replies
  • My Active Topics
  • New Posts in the Last day
  • Private Messages
  • Knowledge Base
  • How to use the Forums
  • All Forums
  • Search for Topics

    • Most popular topics
    • Topics with no replies
    • Recently active topics
    • New posts: Last day
    • New posts: Last three days
    • New posts: Last week
    • New posts: Last month
    • Topics with most replies
    • Latest topics

    Recent Topics

    • End of support for Windows 10 by Old enough to know better
      13 minutes ago
    • What goes on inside an LLM by Michael Covington
      2 hours, 21 minutes ago
    • The risk of remote access by Susan Bradley
      3 hours, 52 minutes ago
    • The cruelest month for many Office users by Peter Deegan
      46 minutes ago
    • Tracking protection and trade-offs in Edge by Mary Branscombe
      3 hours, 55 minutes ago
    • Supreme Court grants DOGE access to confidential Social Security records by Alex5723
      3 hours, 56 minutes ago
    • EaseUS Partition Master free 19.6 by Alex5723
      4 hours, 54 minutes ago
    • Microsoft : Edge is better than Chrome by Alex5723
      17 hours, 13 minutes ago
    • The EU launched DNS4EU by Alex5723
      1 day, 5 hours ago
    • Cell Phone vs. Traditional Touchtone Phone over POTS by 280park
      20 hours, 15 minutes ago
    • Lost access to all my networked drives (shares) listed in My Computer by lwerman
      1 day, 11 hours ago
    • Set default size for pasted photo to word by Cyn
      1 day, 17 hours ago
    • Dedoimedo tries 24H2… by Cybertooth
      1 day, 5 hours ago
    • Windows 11 Insider Preview build 27871 released to Canary by joep517
      2 days, 16 hours ago
    • Windows 11 ad from Campaign Manager in Windows 10 by Jim McKenna
      9 hours, 7 minutes ago
    • Small desktops by Susan Bradley
      8 hours, 13 minutes ago
    • Totally disable Bitlocker by CWBillow
      1 day, 9 hours ago
    • Phishers extract Millions from HMRC accounts.. by Microfix
      2 days, 13 hours ago
    • Windows 10 22H2 Update today (5 June) says up-to-date but last was 2025-04 by Alan_uk
      3 days, 20 hours ago
    • Thoughts on Malwarebytes Scam Guard for Mobile? by opti1
      1 day, 15 hours ago
    • Mystical Desktop by CWBillow
      3 days, 23 hours ago
    • Meta and Yandex secretly tracked billions of Android users by Alex5723
      3 days, 4 hours ago
    • MS-DEFCON 2: Do you need that update? by Susan Bradley
      16 hours, 12 minutes ago
    • CD/DVD drive is no longer recognized by WSCape Sand
      4 days, 14 hours ago
    • Windows 11 24H2 Default Apps stuck on Edge and Adobe Photoshop by MikeBravo
      4 days, 17 hours ago
    • North Face and Cartier customer data stolen in cyber attacks by Alex5723
      4 days, 15 hours ago
    • What is wrong with simple approach? by WSSpoke36
      2 days, 13 hours ago
    • Microsoft-Backed Builder.ai Set for Bankruptcy After Cash Seized by Alex5723
      5 days, 3 hours ago
    • Location, location, location by Susan Bradley
      3 days, 17 hours ago
    • Cannot get a task to run a restore point by CWBillow
      5 days, 4 hours ago

    Recent blog posts

    • What goes on inside an LLM
    • The risk of remote access
    • The cruelest month for many Office users
    • Tracking protection and trade-offs in Edge
    • Small desktops
    • MS-DEFCON 2: Do you need that update?
    • Location, location, location
    • June 2025 Office non-Security Updates

    My Profile

    Login and Registration

    • Log In
    • Register

    Key Links

    • > Computerworld's The Microsoft Patch Lady
    • > Computerworld's Woody on Windows
    • AskWoody Knowledge Base index
    • BlockaPatch tools
    • Gift subscription for Ask Woody Newsletter
    • Microsoft Answers Forum
    • Tasks for the Weekend YouTube Channel
    June 2025
    S M T W T F S
    1234567
    891011121314
    15161718192021
    22232425262728
    2930  
    « May    

    Remembering Woody

     

    Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.

    Mastodon profile for DefConPatch
    Mastodon profile for AskWoody

     

    Home • About • FAQ • Posts & Privacy • Forums • My Account
    Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts

    Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.

    Insert/edit link

    Enter the destination URL

    Or link to existing content

      No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.

        Notifications

        #