Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FALSE-POSITIVE] #868

Open
sucuriteamarc opened this issue Apr 18, 2024 · 3 comments
Open

[FALSE-POSITIVE] #868

sucuriteamarc opened this issue Apr 18, 2024 · 3 comments
Assignees
Labels
false positive Should not be listed

Comments

@sucuriteamarc
Copy link

Domains or links
Please list any domains and links listed here which you believe are a false positive.

More Information
How did you discover your web site or domain was listed here?

  1. Virus Total (https://www.virustotal.com/gui/url/8e0fa3032b90dc6b38f7b805c431ef699c445227f4bae3ce35b6cead4b11c6dd?nocache=1)
  2. Site was infected by malware.

Have you requested removal from other sources?
Please include all relevant links to your existing removals / whitelistings.

E-mailed Antiy: support@antiy.cn [undefined:support@antiy.cn]
E-mailed SOCRadar: info@socradar.io
E-mailed Cluster25: threatintel@cluster25.io
E-mailed CyRadar: contact@cyradar.com [undefined:contact@cyradar.com
E-mailed Phishtank:
https://submit.gdatasoftware.com/privacy
https://safetoopen.com/contact
https://www.criminalip.io/contact-us
https://www.alphamountain.ai/
https://www.avira.com/en/analysis/submit-url
https://www.bitdefender.com/consumer/support/answer/29358/
https://www.brightcloud.com/tools/change-request.php#
https://helpdesk.vipre.com/hc/en-us/requests/new
https://www.brightcloud.com/tools/change-request.php
https://www.phishtank.com/phish_detail.php?phish_id=8451615

Additional context
We've scanned the site and remove all malicious content.

Sucuri Team

We understand being listed on a Phishing Database like this can be frustrating and embarrassing for many web site owners. The first step is to remain calm. The second step is to rest assured one of our maintainers will address your issue as soon as possible. Please make sure you have provided as much information as possible to help speed up the process.

Send a Pull Request for faster removal
Users who understand github and creating Pull Requests can assist us with faster removals by sending a PR to mitchellkrogza/phishing repository, on the falsepositive.list file

https://github.com/mitchellkrogza/phishing/blob/main/falsepositive.list
Please include the same above information to help speed up the whitelisting process.

@emidaniel
Copy link

emidaniel commented Apr 18, 2024

We've scanned the site and remove all malicious content.

When you see someone from this "suckuri team" complaining, it almost always means that the page is not removed:
https://urlscan.io/result/e8994c9e-324c-40a4-801b-8a8a4d43dc67/

I bet they just launched some "website malware scanner" to delete few scripts/files it considers malicious, then submit these requests and don't care to check even once whether phishing pages actually got deleted.

urlscan.io - Website scanner for suspicious and malicious URLs

@sucuriteamarc
Copy link
Author

sucuriteamarc commented Apr 18, 2024 via email

@emidaniel
Copy link

bishopberrian.com/fitnessbase looks removed now.

We made sure to remove the suspicious redirects. I have already cleared the cache from the Firewall.

Why couldn't you do this before sending these requests?

I've also found that the site is also serving malware:

http://bishopberrian.com/22.exe -> http://bishopberrian.com/1.exe

https://app.any.run/tasks/91ed7f5f-970a-42b2-a7bb-b97c66104095

How come you missed this too? Shouldn't be too hard to find when you have full access to files list.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
false positive Should not be listed
Projects
None yet
Development

No branches or pull requests

4 participants