# Un rapporto sul malware

**URL:** https://meta.discourse.org/t/a-malware-report/115991
**Category:** WordPress
**Created:** [25 Aprile 2019, 6:30pm UTC](https://meta.discourse.org/t/a-malware-report/115991 "2019-04-25T18:30:36Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [25 Aprile 2019, 6:30pm UTC](https://meta.discourse.org/t/a-malware-report/115991/1 "2019-04-25T18:30:36Z")

</div>

So this is strange.

I’ve recently started posting my Discourse comments on my webcomic site using WP-Discourse. A [reader commented](https://webcomics.yaoi911.com/typ3/doublecross-ch1-page-21/#comment-4437179181) on my site (Wordpress install) that he got a Hijack report from his anti-virus software (Malwarebytes) when visiting [my most current page](https://webcomics.yaoi911.com/typ3/doublecross-ch1-page-21/).

He copy-pasted the report. It was in Polish, but I recognized the Digital Ocean IP address of my Discourse forum.

I had my assistant download the Malwarebytes software, and she got this report:

 ![Malwarebytes%20Pop%20up](https://global.discourse-cdn.com/meta/original/3X/0/0/005a6cbaeeda8c9aee2da9c9e6b3945b6cf94d91.jpeg)

I literally just upgraded my Discourse site and all the plugins when I got the Discourse update email yesterday afternoon—a couple hours before getting that comment from my reader. I have (what I think is) a fairly vanilla install of Discourse—no themes, and just with these (I think all official) plugins installed:

 ![2019-04-25_11-23-40](https://global.discourse-cdn.com/meta/original/3X/e/1/e1b6ae280c7cbde7bdaa1819dfd1fc9a29ae25e8.png)

I know Discourse is super on-top-of security. I did a search on malware here on this forum, and only found [one post](https://meta.discourse.org/t/sucuri-reports-a-malware-infection/45161) from 2016 that seemed like it could have been a false positive.

I’m not sure what to do here. Malwarebytes seems like a legit company that’s been around for ten years. If it’s blocking my Wordpress webcomic site for all its users because of the Discourse comments, I obviously need to figure this out. Especially if this _isn’t_ a false positive.

Any help would be greatly appreciated. Thanks!

---

<div class="post-metadata">

### Author: ![simon](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/simon/32/339122_2.png) [@simon](https://meta.discourse.org/u/simon)
#### Post date: [25 Aprile 2019, 7:02pm UTC](https://meta.discourse.org/t/a-malware-report/115991/2 "2019-04-25T19:02:58Z")

</div>

I’m not sure what’s going on with this. When I scan either [https://webcomics.yaoi911.com](https://webcomics.yaoi911.com/) or [https://community.amwcomics.com](https://community.amwcomics.com/) with Securi, no malware is being detected: [https://sitecheck.sucuri.net/results/community.amwcomics.com](https://sitecheck.sucuri.net/results/community.amwcomics.com).

Does the report from Malwarebytes tell you the page they are finding the problem on?

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [25 Aprile 2019, 7:04pm UTC](https://meta.discourse.org/t/a-malware-report/115991/3 "2019-04-25T19:04:09Z")

</div>

That doesn’t mean discourse itself was the source of malware, just that something served from that URL triggered an alert.

It could have arrived through the browser via a piece of JavaScript in your theme, or something even simpler such as an attachment.

---

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [25 Aprile 2019, 7:08pm UTC](https://meta.discourse.org/t/a-malware-report/115991/4 "2019-04-25T19:08:18Z")

</div>

> [@simon](#):
>
> Does the report from Malwarebytes tell you the page they are finding the problem on?

Both the commenter and my assistant looked at the current page:

> **[The Young Protectors: Double-Cross Chapter One—Page 21 - Young Protectors...](https://youngprotectors.com/typ3/doublecross-ch1-page-21/)**
>
> Flyboy moves to attack the evil magic users in the 21st page of Alex Woolfson's 3rd gay superhero comic The Young Protectors: Double-Cross.

(I just tested it with Securi. Seems ok according to them…)

> [@Stephen](#):
>
> That doesn’t mean discourse itself was the source of malware, just that something served from that URL triggered an alert.

OK. So what do you think is the best way to proceed and get the answer to this. Download Malwarebytes myself, disable the Discourse comments and see if I get the same error? I haven’t done that yet in case y’all needed to look at it yourself.

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [25 Aprile 2019, 7:12pm UTC](https://meta.discourse.org/t/a-malware-report/115991/5 "2019-04-25T19:12:18Z")

</div>

I would reach out to MalwareBytes Support and ask for more information on the block, they’ve wrongly blocked websites ‘due to hijack’ in the past for simple stuff like shared IPs.

---

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [25 Aprile 2019, 7:13pm UTC](https://meta.discourse.org/t/a-malware-report/115991/6 "2019-04-25T19:13:29Z")

</div>

OK. I’ll do that right now.

When this has happened in the past, do you know if Malwarebytes has been responsive?

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [25 Aprile 2019, 7:16pm UTC](https://meta.discourse.org/t/a-malware-report/115991/7 "2019-04-25T19:16:52Z")

</div>

In the case of the shared IP it took an update on their side to resolve. In one other case the user reporting the issue hadn’t noticed that their local DNS settings had been hijacked, hence traffic wasn’t going where it was expected.

It certainly can’t hurt to ask.

Does the same user still see that message?

---

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [25 Aprile 2019, 7:21pm UTC](https://meta.discourse.org/t/a-malware-report/115991/8 "2019-04-25T19:21:58Z")

</div>

> [@Stephen](#):
>
> Does the same user still see that message?

I’ll ask him to check. And I’ll have my assistant check again when she starts her shift this evening.

I’m not sure if Digital Ocean uses shared IPs, but it could be [a potential trigger](https://forums.malwarebytes.com/topic/21076-info-malicious-website-blocking/).

In the meantime, I’m filling out the [False Report post](https://support.malwarebytes.com/docs/DOC-1413) on their site. I think that’s the correct procedure here.

We’ll see what they say. Thanks! 🙂

EDITED TO ADD: [Here’s what I posted](https://forums.malwarebytes.com/topic/246524-hijack-warning-on-my-site/) on their support forum. I’ll keep y’all posted here.

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [25 Aprile 2019, 9:05pm UTC](https://meta.discourse.org/t/a-malware-report/115991/9 "2019-04-25T21:05:01Z")

</div>

Looks like it has been taken care of:

> Hello,
> 
> IP block will be removed.

---

<div class="post-metadata">

### Author: ![alexwoolfson](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alexwoolfson/32/99119_2.png) [@alexwoolfson](https://meta.discourse.org/u/alexwoolfson)
#### Post date: [26 Aprile 2019, 1:19am UTC](https://meta.discourse.org/t/a-malware-report/115991/10 "2019-04-26T01:19:55Z")

</div>

Yep! Looks like we are all set.

Thank you for your help with this. Hopefully these posts can also guide others if they run into the same issue with Malwarebytes. 🙂

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [14 Dicembre 2022, 3:49pm UTC](https://meta.discourse.org/t/a-malware-report/115991/11 "2022-12-14T15:49:41Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
