[Solved] Antivirus says a connection is infected by URL:Phishing

Issues with installing under all versions of MS Windows
Post Reply
keneso
Posts: 51
Joined: Sun Nov 10, 2013 10:58 pm

[Solved] Antivirus says a connection is infected by URL:Phishing

Post by keneso »

Not sure if it's the right place to ask this, anyhow, this is the issue.

Lately when using OpenOffice the antivirus reports a threat:
to be safe I put (dot) instead of the . in the below link
"connection to aoo-pdf-import.apache-extras.org.codespot.com has been interrupted cause it is infected by URL:Phishing"
URL:
http://aoo-pdf-import(dot)apache-extras(dot)org(dot)codespot(dot)com/git/update/windows_x86-update(dot)xml
Process:
C:\Program Files (x86)\OpenOffice4\program\soffice.bin
Is the soffice.bin the infected file?
If yes do you think if I uninstall, and reinstall OpenOffice it'll fix it?

 Edit: Changed subject, was infection 
Make your post understandable by others 
-- MrProgrammer, forum moderator 
Last edited by MrProgrammer on Fri Feb 24, 2023 6:38 pm, edited 1 time in total.
Reason: Tagged ✓ [Solved] Q: Is soffice.bin infected? A: Probably not -- MrProgrammer, forum moderator
OpenOffice 4.1.1 - Win 8.1
User avatar
Hagar Delest
Moderator
Posts: 33357
Joined: Sun Oct 07, 2007 9:07 pm
Location: France

Re: Antivirus says a connection is infected by URL:Phishing

Post by Hagar Delest »

Rather strange.
You can check the hash of the installation files before reinstalling. Have you downloaded it from the SourceForge servers?
LibreOffice 25.2 on Linux Mint Debian Edition (LMDE Faye) and 24.8 portable on Windows 11.
keneso
Posts: 51
Joined: Sun Nov 10, 2013 10:58 pm

Re: Antivirus says a connection is infected by URL:Phishing

Post by keneso »

Thank you.

I downloaded it years back from openoffice.org (following the download path), and the issue is recent (a month or so).
Running the antivirus on C:\Program Files (x86)\OpenOffice4 reports no infection, it's only when using OpenOffice that it ntoifies on a blocked threat.
OpenOffice 4.1.1 - Win 8.1
elfmmf
Posts: 1
Joined: Fri Feb 17, 2023 3:19 pm

Re: Antivirus says a connection is infected by URL:Phishing

Post by elfmmf »

Having same problem. Just started within the past month. Have you tried reinstalling? I would like to know if that helped too!
Open Office 4.1.1 Windows 10
User avatar
MrProgrammer
Moderator
Posts: 5264
Joined: Fri Jun 04, 2010 7:57 pm
Location: Wisconsin, USA

Re: Antivirus says a connection is infected by URL:Phishing

Post by MrProgrammer »

keneso wrote: Wed Jan 25, 2023 9:09 pm Is the soffice.bin the infected file?
Probably not. Let's say you use your web browser to open a page, say https://www.foo.bar. That page has a link to aoo-pdf-import.apache-extras.org.codespot.com. When you click on the link, your anti-virus software says that may be URL:Phishing. Why? The real site is codespot.org, not codespot.com. The page is trying to trick you to visit the wrong site. (My "links" in grey are not real and won't respond if clicked. Only the link in blue can be opened.)

What program (process) tried to open the site? Your web browser. But is your web browser infected? No, the page is infected.

You seem to have the same situation here. If you open a naughty Writer document with OpenOffice which contains a hyperlink to aoo-pdf-import.apache-extras.org.codespot.com and you click it, your anti-virus will issue a warning. Is OpenOffice infected? No, it's the document that's infected.

Or let's say you have a macro written for OpenOffice. The macro came from somewhere else, and is not part of the OpenOffice installation. If the naughty macro connects to to aoo-pdf-import.apache-extras.org.codespot.com your anti-virus will issue a warning. Is OpenOffice infected? No, it's the macro that's infected.

It may be difficult for your anti-virus software to determine exactly what is infected — a web page, a Writer document, a macro — so it just reports the name of the program (process) that was running, which for you was soffice.bin.

keneso wrote: Wed Jan 25, 2023 9:09 pm Lately when using OpenOffice the antivirus reports a threat:
elfmmf wrote: Fri Feb 17, 2023 3:21 pm Having same problem.
Others reading this post will want to know exactly which anti-virus software you're using. Both of you. The difficulty may be specific to a particular anti-virus product.

keneso wrote: Thu Jan 26, 2023 11:48 am the issue is recent (a month or so)
elfmmf wrote: Fri Feb 17, 2023 3:21 pm Just started within the past month.
OK, your anti-virus product updated its diagnostic rules recently. Good anti-virus products update their rules often, perhaps even daily, as new threats emerge. The rules are dynamically loaded from the internet, not when the anti-virus software is installed or updated.

Hagar Delest wrote: Wed Jan 25, 2023 10:32 pm You can check the hash of the installation files before reinstalling. Have you downloaded it from the SourceForge servers?
Agreed. To be safe only download via the ⬇︎OpenOffice link at the bottom right of this page. For additional security, you can check the hash yourself as explained in the How to Verify the Download link inside the second box on that page.

keneso wrote: Wed Jan 25, 2023 9:09 pm do you think if I uninstall, and reinstall OpenOffice it'll fix it?
Not if the real culprit is a naughty document, macro, etc.
 Edit: 2023-03-08: Not if the real culprit is an obsolete non-OpenOffice extension
If this solved your problem please go to your first post use the Edit button and add [Solved] to the start of the Subject field. Select the green checkmark icon at the same time.
Mr. Programmer
AOO 4.1.7 Build 9800, MacOS 13.7.5, iMac Intel.   The locale for any menus or Calc formulas in my posts is English (USA).
User avatar
Mr.Dandy
Posts: 461
Joined: Tue Dec 11, 2012 4:22 pm

Re: Antivirus says a connection is infected by URL:Phishing

Post by Mr.Dandy »

Believing that free antiviruses are the panacea is nonsense :)
OpenOffice 4.1.12 - Windows 10
Post Reply