Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | sibalogtv.com #972

Closed
Fernandof28 opened this issue Dec 26, 2024 · 8 comments
Closed

False Positive | sibalogtv.com #972

Fernandof28 opened this issue Dec 26, 2024 · 8 comments
Assignees
Labels
false positive Should not be listed

Comments

@Fernandof28
Copy link

What are the subjects of the false-positive (domains, URLs, or IPs)?

https://sibalogtv.com/Fundacion
https://sibalogtv.com/Scotiabank
https://sibalogtv.com/hsbc)

Why do you believe this is a false-positive?

This Domain www.sibalogtv.com is for Ecommerce B2B, we verified the site is clean, we check malware and the team of Quttera verified the site is clean

The domain is in your blacklist, please help me testing again the URL

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

I discovered this false-positive by...

Have you requested a review from other sources?

The team of Quttera and Sucuri, check the site and is clean

Do you have a screenshot?

Screenshot ![image](https://github.com/user-attachments/assets/212bf595-8d43-4588-87ed-31bb53ae4458)

Additional Information or Context

I have also noticed that...

@spirillen
Copy link
Contributor

Can't help you, as you are denying the public access to the domain

image

@spirillen
Copy link
Contributor

https://www.sibalogtv.com/scotiabank
https://www.sibalogtv.com/scotiabank/index24.php
http://www.sibalogtv.com/scotiabank

@Fernandof28
Copy link
Author

Hi,

The site is working, but you are trying to access a File don´t exist (Index24.php)

Checking the server, I see that there are no Blocked IP's, the screen you send me is of the application Firewall that is activated in the event of suspicious activity, could you share your IP with me to investigate with the Quttera and Sucuri team why your computer is blocked when doing URL validation

image

@g0d33p3rsec
Copy link

Can't help you, as you are denying the public access to the domain

image

urlscan shows 404s for that URI which matches @Fernandof28's statement. I was not previously aware that GoDaddy offered a WAF, interesting.
image

@spirillen
Copy link
Contributor

GoDaddy offered a WAF, interesting.

Can tell you it blocks out about every one, especially when you use tor network, for privacy = Gofloffy are not into freedom and democracy 😒 just like Putin and trump

could you share your IP

Nope, rotate constantly, thanks to Tor 👍🏻

investigate with the Quttera and Sucuri

Could be nice if you tell them, you are loosing bunch of legit visitors as they are blocking the white-net/Light-net of Tor, while allowing the Evil net 😉

@g0d33p3rsec are you adding this one to the whitelist? I'm on my way out

@g0d33p3rsec
Copy link

@g0d33p3rsec are you adding this one to the whitelist? I'm on my way out

Sure, I'll take care of that right now. I like to have at least one other set of eyes on a domain I didn't make the initial report for.

@g0d33p3rsec
Copy link

@g0d33p3rsec are you adding this one to the whitelist? I'm on my way out

It should be addressed in Phishing-Database/phishing#557. Can you or one of the other maintainers verify that it is on the appropriate list before I merge it?

@g0d33p3rsec
Copy link

@Fernandof28 I added the domain in Phishing-Database/phishing#557 and requested a review from the other maintainers.

It may take a little while for the results to propagate once merged.

@github-project-automation github-project-automation bot moved this from 🆕 New to ✅ Done in Phishing Database Backlog Dec 27, 2024
@g0d33p3rsec g0d33p3rsec added the false positive Should not be listed label Dec 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
false positive Should not be listed
Projects
Status: ✅ Done
Development

No branches or pull requests

5 participants