Skip to main content

Abuse / Malware Classifications, February 2014

This week, we're seeing a small flood of reports about abuse / malware classifications, involving various blogs.

Some blogs are being classified as an apparently intensified effort to block a long recognised malware source - and others because of a newly detected problem.

For a while, we've been noting problem reports discussing blogs with gadgets provided by "abu-farhan". Some hijacks would lead to simple spam displays (of possibly objectionable content), while others led to active malware distribution. The latter, in turn, generated more problem reports here - by people reporting their blogs now under the control of other people, who were not the original blog owners.

This week, we see reports that Google has taken action against the "abu-farhan" domain. Blogger now appears to be actively classifying blogs, which contain accessories provided from "abu-farhan", as malicious content hosts - pending review, on a blog by blog basis.

Along with the action against "Abu Farhan", we also see reports of problems with "MadAdsMedia". Google appears to be taking similar action, against blogs containing material from the "madadsmedia" domain.

Use of either "Abu Farhan" or "MadAdsMedia" supplied material appears to lead to action against blogs containing the material - and against blogs that link to other blogs containing the material.

If your blog is now locked as a malware host, and you're unable to find any material from either "Abu Farhan" or "MadAdsMedia", then it's possible that you have linked to one or more blogs containing such material.

A Google Safe Browsing diagnosis, for your blog, may offer a clue where your problem lies. You generate a Safe Browsing diagnosis directly from a URL, containing the published blog URL.

Since this blog is published as "blogging.nitecruzr.net", the Safe Browsing diagnosis URL for this blog is
www.google.com/safebrowsing/diagnostic?site=blogging.nitecruzr.net
The diagnosis URL, for your blog, will be similar.

If the problem with your blog involves content on another blog / website, you have two choices.
  1. Contact the owner of the blog / website which actively contains malicious material, and suggest cleanup and review.
  2. Remove the link to the blog / website in question.

If your blog is now locked as a malware host, and you're able to find material from either "abu-farhan" or "madadsmedia", you'll simply need to remove the malicious material.

Having removed all problem content and links from your blog, you'll next use Google Webmaster Tools, and request review of your blog. Right now, Blogger Support advises us that review can take up to 2 business days, to complete. Considering the volume of problem reports, I'm not optimistic that reviews are likely to take any less time.

When you visit Webmaster Tools, look in the menu for your blog. The menu entry for "Security Issues", or Webmasters help for hacked sites, may provide some guidance.

Be thorough, and search both your blog, and any linked blogs and websites, before requesting review. Requesting review, when your blog (or any linked blogs) has cleanup action pending, may be a problem for you.

If you are here because your blog is locked as a malware host, and you have not yet provided details about your problem, please help us to help you and provide your details, in the forum discussion, "[Problem Rollup] Blogs locked as malware hosts, with mention of "Abu Farhan" or "MadAdsMedia"" Please keep your post brief, responsive, and relevant, so we can best help you.

And in the future, be more selective about content and links, that you add to your blog.

>> Top

Comments

Dr Sonia S V said…
Thank you so much for this write up.Though I am not a computer expert and I was very tempted by the abufarhan gadget I was uncomfortable seeing the link in the gadget so luckily did not install.
I have a crafting hobby blog and like most blogs in that niche tend to link to several other craft blogs. Will making the links "no follow" help prevent link induced malware label problems ?
Blog Co-Author said…
My blog Malware was resolved already by google webmaster and I am sure that there's no more malware on my site that came from madadsmedia, How long will be my site to be unlocked?

the diagnosis is here:http://www.google.com/safebrowsing/diagnostic?site=theblogservices.net

and my site is now clear with my webmaster, hope you can take action to unlocked my site.

This article is really infomative.
Nitecruzr said…
Sonia,

Malware links are followed by people, because the payload of malware involves infection of computers used by people. The "no follow" attribute is for search engine bots, not people.

So in this case, I hope that "no follow" would have no effect on the malware bots run by Google. Remember that "no follow" and "no index" are advisory only, not authoritative.
Nitecruzr said…
Frank,

Blogger Support advised us that "up to 2 business days" may be required for review - and that was stated early last week, well before the current flood of problem reports started.

Considering the volume of problem reports seen this weekend, I'm not betting my paycheck that any less than "2 business days" will be involved, for many blogs.
Blog Co-Author said…
My site is already up, it was unlocked after 12hrs waiting, thanks for the information.
Dr Sonia S V said…
Thank you Chuck.

Popular posts from this blog

Adding A Link To Your Blog Post

Occasionally, you see a very odd, cryptic complaint I just added a link in my blog, but the link vanished! No, it wasn't your imagination.

Embedded Comments And Main Page View

The option to display comments, embedded below the post, was made a blog option relatively recently. This was a long requested feature - and many bloggers added it to their blogs, as soon as the option was presented to us. Some blog owners like this feature so much, that they request it to be visible when the blog is opened, in main page view. I would like all comments, and the comment form, to be shown underneath the relevant post, automatically, for everyone to read without clicking on the number of comments link. And this is not how embedded comments work.

What's The URL Of My Blog?

We see the plea for help, periodically I need the URL of my blog, so I can give it to my friends. Help! Who's buried in Grant's Tomb, after all? No Chuck, be polite. OK, OK. The title of this blog is "The Real Blogger Status", and the title of this post is "What's The URL Of My Blog?".