mitchellkrogza / Phishing.Database

Phishing Domains, urls websites and threats database. We use the PyFunceble testing tool to validate the status of all known Phishing domains and provide stats to reveal how many unique domains used for Phishing are still active.
MIT License
1.13k stars 257 forks source link

[FALSE-POSITIVE] #781

Closed DenMurphy closed 9 months ago

DenMurphy commented 9 months ago

Domains or links Please list any domains and links listed here which you believe are a false positive.

parkhavengarden.com.au

More Information How did you discover your web site or domain was listed here?

  1. Website was hacked
  2. Incorrectly marked as Phishing on Phishtank or OpenPhish?

The previous web developers managing the website were uploading Native Word files for their clients instead of PDF versions. I have taken over hosting and management of the website, moved to my hosting (Flywheel) and have removed all Word Documents. I had discovered their website flagged via VirusTotal as Malware. I have so far managed to get 2 of 4 flags removed, I have two remaining, CyRadar and from this database.

Have you requested removal from other sources? Please include all relevant links to your existing removals / whitelistings.

I have requested Cyradar remove the website via a Contact Email address.

Additional context Add any other context about the problem here.

:exclamation:

We understand being listed on a Phishing Database like this can be frustrating and embarrassing for many web site owners. The first step is to remain calm. The second step is to rest assured one of our maintainers will address your issue as soon as possible. Please make sure you have provided as much information as possible to help speed up the process.

Send a Pull Request for faster removal Users who understand github and creating Pull Requests can assist us with faster removals by sending a PR to mitchellkrogza/phishing repository, on the falsepositive.list file

https://github.com/mitchellkrogza/phishing/blob/main/falsepositive.list Please include the same above information to help speed up the whitelisting process.

spirillen commented 9 months ago

How did you discover your web site or domain was listed here?

DenMurphy commented 9 months ago

Adding to the above, when I used VirusTotal to scan the site, SOCradar appeared in the results. When I went to the SOCradar.io site and used the IOC radar tool to scan the URL, the name mitchellkrogza appeared as a Feed Source the URL was flagged on.

I have just rescanned today on VirusTotal and now the site does not appear on any vendors lists. This ticket can be closed.