Blacklists and McAfee Site Advisor

I’ve received complaints that sites hosted are getting blocked or coming up with omnious messages about malware, trojans, and viruses:

[INDENT]McAfee Site Advisor:
This link might be dangerous. We tested it and found security risks. Beware.
[/INDENT]
Going through their checks they report the server Web15.MyHsphere.biz ( 173.0.129.56 ) is on the CBL black list (just to be clear, the site the list is NOT mine or under my reseller account):
[INDENT]
IP Address 173.0.129.56 is listed in the CBL. It shows signs of being infected with a spam sending trojan, malicious link or some other form of botnet.

It was last detected at 2016-02-23 20:00 GMT (+/- 30 minutes), approximately 1 hours ago.

StealRat Infection
We have detected that this IP is NATting for, or is infected itself, with the “StealRat” malware. StealRat is usually found on UNIX or xxxBSD web servers running the Drupal, Wordpress or Joomla Content Management Systems (CMS).

In short, you have to:

Secure the computer against further reinfection - which means making sure that all CMS installations on the computer are up-to-date and kept up to date. Almost all Stealrat infections are via security holes in stale CMS software.
Find the StealRat infection and remove it.
The stealrat infection appears to be affiliated with the hostname phillytowing.com. If this domain is hosted on this IP address, this is the virtual host that is infected, and this information will help guide mitigate the security breach. If this domain isn’t familiar to you, it is co-hosted on the same IP address, and only your administrator can fix it.[/INDENT]

I see I can request a “de-list” but it’s pretty clear that without cleaning the problems eventually we won’t be able to de-list automatically.

Is this something I just submit via a ticket? It seems to be a server level issue, not an account issues, so I don’t want to confuse things by requesting this since it’s not literally on my account.

We have scanned this domain phillytowing.com and also other user accounts.You can raise
support ticket for any further query.

It isn’t a server level issue, it is that domain level issue :wink:

Just to be clear on that, it is a php proxy app, thats running because people think you can make a site on an open source, or even closed source CMS, and never update it again.

Sorry for the late reply - lots of stuff going on!

In the original post I had several domains getting a warning by clients running McAfee Site Advisor - following up with McAfee (now Intel?) they pointed me to the black list:

[INDENT]Web15.MyHsphere.biz ( 173.0.129.56 ) is on the CBL black list
[/INDENT]
The black list didn’t report any of my sites, but it did show:

[INDENT]The stealrat infection appears to be affiliated with the hostname phillytowing.com[/INDENT]

That domain wasn’t on my account, so I don’t have any clue about “phillytowing.com

This hacking thing is REALLY getting to be a nightmare (for me) - I can’t even imagine everything Jodo must have to deal with…

Domain phillytowing.com was was cleaned up. Please check the same at-
http://www.mcafee.com/threat-intelligence/site/default.aspx?url=http://phillytowing.com/