mitchellkrogza / Phishing.Database

Phishing Domains, urls websites and threats database. We use the PyFunceble testing tool to validate the status of all known Phishing domains and provide stats to reveal how many unique domains used for Phishing are still active.
MIT License
1.1k stars 254 forks source link

[FALSE-POSITIVE] #898

Open thechakmasaju opened 1 month ago

thechakmasaju commented 1 month ago

Domains or links https://gontop.app

More Information How did you discover your web site or domain was listed here?

  1. Website was hacked
  2. Incorrectly marked as Phishing on Phishtank or OpenPhish

These both. I have installed GPL plugin in my woocomerce site which added virus in my site. Now I have removed the folder of that site & created my site newly. But virustotal still showing virus in my site.

Have you requested removal from other sources? Please include all relevant links to your existing removals / whitelistings.

Additional context I am writing to address an important concern regarding the URL and files associated with https://gontop.app. Our site is completely free of viruses, malware, or any phishing activities. However, it has come to our attention that several URL-checking sites are incorrectly flagging our site as a potential threat. This information is categorically false. We have thoroughly checked our site and all associated files, ensuring they are secure and safe for users. We request a re-evaluation to rectify these false positives and reflect the true nature of our site's security. Thank you for your attention to this matter.

:exclamation:

We understand being listed on a Phishing Database like this can be frustrating and embarrassing for many web site owners. The first step is to remain calm. The second step is to rest assured one of our maintainers will address your issue as soon as possible. Please make sure you have provided as much information as possible to help speed up the process.

Send a Pull Request for faster removal Users who understand github and creating Pull Requests can assist us with faster removals by sending a PR to mitchellkrogza/phishing repository, on the falsepositive.list file

https://github.com/mitchellkrogza/phishing/blob/main/falsepositive.list Please include the same above information to help speed up the whitelisting process.

spirillen commented 1 month ago

I'm not convinced this domain have solved it's issues...

image

spirillen commented 1 month ago
Logger output | | | | | | | | | |:--- |:--- |:--- |:--- |:--- |:--- |:--- |:--- | | +17 | | | gontop.app | 1 | get | doc | `https://gontop.app/` | | +17 | | | behind-the-scene | 0,3 | get | xhr | `https://[ff00::]/nscl/moz-extension://7f5a4c01-d385-48df-9101-326bb6e1c065/syncMessage?id=e69e2cd70f.9838%2Chttps%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26sol%3DMjA6MTcyMDk1NzE2ODo0NDhhNzQ1YTpmMDdhODVmYmNlMmQ5YzVhM2QwNDBjZjY3ZDM1ODcwODcxZTZiZWMxY2NjNGI0YmZkMGU1ZTRkNWQ3NmRlZmIyOgEZguU%253D%26s%3D1783%3A1098514&url=https%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26sol%3DMjA6MTcyMDk1NzE2ODo0NDhhNzQ1YTpmMDdhODVmYmNlMmQ5YzVhM2QwNDBjZjY3ZDM1ODcwODcxZTZiZWMxY2NjNGI0YmZkMGU1ZTRkNWQ3NmRlZmIyOgEZguU%253D%26s%3D1783%3A1098514&top=true&msg=%7B%22id%22%3A%22fetchChildPolicy%22%2C%22url%22%3A%22https%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26sol%3DMjA6MTcyMDk1NzE2ODo0NDhhNzQ1YTpmMDdhODVmYmNlMmQ5YzVhM2QwNDBjZjY3ZDM1ODcwODcxZTZiZWMxY2NjNGI0YmZkMGU1ZTRkNWQ3NmRlZmIyOgEZguU%253D%26s%3D1783%3A1098514%22%7D` | | +16 | | | gontop.app | 1 | get | doc | `https://gontop.app/.well-known/sgcaptcha/?r=%2F&sol=MjA6MTcyMDk1NzE2ODo0NDhhNzQ1YTpmMDdhODVmYmNlMmQ5YzVhM2QwNDBjZjY3ZDM1ODcwODcxZTZiZWMxY2NjNGI0YmZkMGU1ZTRkNWQ3NmRlZmIyOgEZguU%3D&s=1783:1098514` | | +13 | | | behind-the-scene | 0,3 | get | xhr | `https://[ff00::]/nscl/moz-extension://7f5a4c01-d385-48df-9101-326bb6e1c065/syncMessage?id=1056b9d181d.05e%2Chttps%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26y%3Dipr%3A94.177.106.55%3A1720957167.845&url=https%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26y%3Dipr%3A94.177.106.55%3A1720957167.845&top=true&msg=%7B%22id%22%3A%22fetchChildPolicy%22%2C%22url%22%3A%22https%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26y%3Dipr%3A94.177.106.55%3A1720957167.845%22%7D` | | +13 | | | gontop.app | 3 | get | image | `https://d1rozh26tys225.cloudfront.net/loader.svg` | | +13 | | | gontop.app | 3 | get | image | `https://d1rozh26tys225.cloudfront.net/robot-suspicion.svg` | | +12 | | | gontop.app | 1 | get | doc | `https://gontop.app/.well-known/sgcaptcha/?r=%2F&y=ipr:94.177.106.55:1720957167.845` | | +12 | | | behind-the-scene | 0,3 | get | xhr | `https://[ff00::]/nscl/moz-extension://7f5a4c01-d385-48df-9101-326bb6e1c065/syncMessage?id=29d11657d0.a126%2Chttps%3A%2F%2Fgontop.app%2F&url=https%3A%2F%2Fgontop.app%2F&top=true&msg=%7B%22id%22%3A%22fetchChildPolicy%22%2C%22url%22%3A%22https%3A%2F%2Fgontop.app%2F%22%7D` | | +0 | | | gontop.app | 1 | get | doc | `https://gontop.app/` |
thechakmasaju commented 1 month ago

Kindly Check now please. The site is live now.

On Sun, Jul 14, 2024, 5:43 PM spirillen @.***> wrote:

Logger output +17 gontop.app 1 get doc https://gontop.app/ +17 behind-the-scene 0,3 get xhr https:// [ff00::]/nscl/moz-extension://7f5a4c01-d385-48df-9101-326bb6e1c065/syncMessage?id=e69e2cd70f.9838%2Chttps%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26sol%3DMjA6MTcyMDk1NzE2ODo0NDhhNzQ1YTpmMDdhODVmYmNlMmQ5YzVhM2QwNDBjZjY3ZDM1ODcwODcxZTZiZWMxY2NjNGI0YmZkMGU1ZTRkNWQ3NmRlZmIyOgEZguU%253D%26s%3D1783%3A1098514&url=https%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26sol%3DMjA6MTcyMDk1NzE2ODo0NDhhNzQ1YTpmMDdhODVmYmNlMmQ5YzVhM2QwNDBjZjY3ZDM1ODcwODcxZTZiZWMxY2NjNGI0YmZkMGU1ZTRkNWQ3NmRlZmIyOgEZguU%253D%26s%3D1783%3A1098514&top=true&msg=%7B%22id%22%3A%22fetchChildPolicy%22%2C%22url%22%3A%22https%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26sol%3DMjA6MTcyMDk1NzE2ODo0NDhhNzQ1YTpmMDdhODVmYmNlMmQ5YzVhM2QwNDBjZjY3ZDM1ODcwODcxZTZiZWMxY2NjNGI0YmZkMGU1ZTRkNWQ3NmRlZmIyOgEZguU%253D%26s%3D1783%3A1098514%22%7D +16 gontop.app 1 get doc https://gontop.app/.well-known/sgcaptcha/?r=%2F&sol=MjA6MTcyMDk1NzE2ODo0NDhhNzQ1YTpmMDdhODVmYmNlMmQ5YzVhM2QwNDBjZjY3ZDM1ODcwODcxZTZiZWMxY2NjNGI0YmZkMGU1ZTRkNWQ3NmRlZmIyOgEZguU%3D&s=1783:1098514 +13 behind-the-scene 0,3 get xhr https:// [ff00::]/nscl/moz-extension://7f5a4c01-d385-48df-9101-326bb6e1c065/syncMessage?id=1056b9d181d.05e%2Chttps%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26y%3Dipr%3A94.177.106.55%3A1720957167.845&url=https%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26y%3Dipr%3A94.177.106.55%3A1720957167.845&top=true&msg=%7B%22id%22%3A%22fetchChildPolicy%22%2C%22url%22%3A%22https%3A%2F%2Fgontop.app%2F.well-known%2Fsgcaptcha%2F%3Fr%3D%252F%26y%3Dipr%3A94.177.106.55%3A1720957167.845%22%7D +13 gontop.app 3 get image https://d1rozh26tys225.cloudfront.net/loader.svg +13 gontop.app 3 get image https://d1rozh26tys225.cloudfront.net/robot-suspicion.svg +12 gontop.app 1 get doc https://gontop.app/.well-known/sgcaptcha/?r=%2F&y=ipr:94.177.106.55:1720957167.845 +12 behind-the-scene 0,3 get xhr https:// [ff00::]/nscl/moz-extension://7f5a4c01-d385-48df-9101-326bb6e1c065/syncMessage?id=29d11657d0.a126%2Chttps%3A%2F%2Fgontop.app%2F&url=https%3A%2F%2Fgontop.app%2F&top=true&msg=%7B%22id%22%3A%22fetchChildPolicy%22%2C%22url%22%3A%22https%3A%2F%2Fgontop.app%2F%22%7D +0 gontop.app 1 get doc https://gontop.app/

— Reply to this email directly, view it on GitHub https://github.com/mitchellkrogza/Phishing.Database/issues/898#issuecomment-2227315191, or unsubscribe https://github.com/notifications/unsubscribe-auth/AZJ3Q4YATFV7USFVIFT4SGTZMJP5FAVCNFSM6AAAAABK3A7ET6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDEMRXGMYTKMJZGE . You are receiving this because you authored the thread.Message ID: @.***>

spirillen commented 1 month ago

and is it cleaned for for your fingerprinter? and opened for the public domain to visit? last time you used fingerprinter from cloudflare to prohibit the public internet to access your site and only allow members of the walled garden, which are limiting the number of people who can/will visit your site in the first place and you are loosing costumers.

/.well-known/sgcaptcha/?r=%2F&y=ipr:94.177.106.55:1720957167.845
thechakmasaju commented 1 month ago

Site was on development. There wew virus because of using GPL plugin in wordpress site. Now its all clear

On Mon, Jul 15, 2024, 6:24 PM spirillen @.***> wrote:

and is it cleaned for for your fingerprinter? and opened for the public domain to visit? last time you used fingerprinter from cloudflare to prohibit the public internet to access your site and only allow members of the walled garden, which are limiting the number of people who can/will visit your site in the first place and you are loosing costumers.

/.well-known/sgcaptcha/?r=%2F&y=ipr:94.177.106.55:1720957167.845

— Reply to this email directly, view it on GitHub https://github.com/mitchellkrogza/Phishing.Database/issues/898#issuecomment-2228381649, or unsubscribe https://github.com/notifications/unsubscribe-auth/AZJ3Q433ENNTDK3EKQL4HG3ZMO5RLAVCNFSM6AAAAABK3A7ET6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDEMRYGM4DCNRUHE . You are receiving this because you authored the thread.Message ID: @.***>

spirillen commented 1 month ago

Your domain is still not on the open web and controlled by cloudflare.

image

I (@spirillen) can not help you in https://github.com/mitchellkrogza/phishing/ unless you release the site to the public. As public declared, I no longer accessing the walled garden https://matrix.rocks/notes/9vkszovs0v

GitHub
GitHub - mitchellkrogza/phishing: Central Repository for Adding Domains / Links to the Phishing.Database project - https://github.com/mitchellkrogza/Phishing.Database/
Central Repository for Adding Domains / Links to the Phishing.Database project - https://github.com/mitchellkrogza/Phishing.Database/ - mitchellkrogza/phishing
Matrix Rocks
Jerry Mouse (@jerry)
Feels god no longer to be slaving for propertarian OS, that Ubuntu have turned into, withheld update for ransom. This gives the meaning of #ransomeware a new twist of meaning. Yes, this gives me back a good feeling in my stomachs, knowing I'm back on FOSS OS form #Debian, even tho a lot of package are outdated and need personal actions to get up to date, such as the unbound v1.17 with a lot of security issues which isn't addressed and fixed until version 1.20, but that one is still held in the testing (former SID) repo, rather than getting it released. And this makes me wondering on how they determine which Alpha releases should be force down to the stable repo, such as wayland, that can't recover `displey:0` from the sleep state, unless you reboot the system, while stable releases like unbound are withheld. This would make the first time experience of Debian as a buggy and not properly maintained distro, making people running away screaming, only to never come back. Yes, it took me a couple of days to notice the dropdown on the #SDDM login screen, allowing me to switch back to good old stable #x11 window system. Please Debian-devs, set X11 as default windows engine and leave waylands to the experimental group running on the testing releases. The rest of us have chosen Debian for stability not a endless counts of total brake downs, while actually doing literally nothing... IF you are using Debian stable, please share your stories. This said, I've become rather firmly determined that no more packages/apps/programs that gets in touch with the walled Garden/big5/BigTech surveillance network, will be installed on my network anymore, this includes and is not limited to Element (Chat client) using matrix.org network as primary network, this in running over cloudflare. A few exception would be vsCode and my sponsored IDE's from jetbrains's opensource license. Have a nice wet/sunny summer depending on your current location... (Can see it looks a tad moist somewhere this summer https://matrix.rocks/notes/9vkrkl6g8z) #debian #ubuntu #wayland #x11 #internetsecurety #dnsbomb #walledgarden #cloudflare #big5 #bigtech #anime #rain (📎1)
thechakmasaju commented 1 month ago

No. I am not using cloudflare cdn in my site. Its working for me.

On Mon, Jul 15, 2024, 7:39 PM spirillen @.***> wrote:

Your domain is still not on the open web and controlled by cloudflare.

image.png (view on web) https://github.com/user-attachments/assets/98366db3-18f2-4acb-b343-76eb664ceaee

I @.*** https://github.com/spirillen) can help you in https://github.com/mitchellkrogza/phishing/ unless you release the site to the public. As public declared, I no longer accessing the walled garden https://matrix.rocks/notes/9vkszovs0v

https://camo.githubusercontent.com/c358b90e1310b7bb95f9941a48eb200df3c6ebe50887431d473f0e167ddd01b5/68747470733a2f2f6f70656e67726170682e6769746875626173736574732e636f6d2f326662383837306461643537353036646364353735616330376535646563316338383062626664336662643537396236623232313236366261616665373131362f6d69746368656c6c6b726f677a612f7068697368696e67

https://camo.githubusercontent.com/95e35b1ddbd18e9680ef4876f3544fdf46e2116b5fefc3f6a48e1e427ea75b59/68747470733a2f2f6769746875622e6769746875626173736574732e636f6d2f66617669636f6e732f66617669636f6e2e737667 GitHub GitHub - mitchellkrogza/phishing: Central Repository for Adding Domains / Links to the Phishing.Database project - https://github.com/mitchellkrogza/Phishing.Database/ https://github.com/mitchellkrogza/phishing Central Repository for Adding Domains / Links to the Phishing.Database project - https://github.com/mitchellkrogza/Phishing.Database/ - mitchellkrogza/phishing

https://camo.githubusercontent.com/6898d8f5894916b38982fc9a8f27ae5138b43d9ac3c9ca3b61a2322577a34811/68747470733a2f2f6d61747269782e726f636b732f66696c65732f38383563623138372d653464322d343032612d616433622d316437643230626639616534

https://camo.githubusercontent.com/6e43990b657b6dfd316be6c92cdc4321489b0fa85d6bf45ebce68b119070376c/68747470733a2f2f6d61747269782e726f636b732f66696c65732f30303539316536342d633135312d346138652d383530312d333138373633313332363666 Matrix Rocks *Jerry Mouse @.**) https://matrix.rocks/notes/9vkszovs0v Feels god no longer to be slaving for propertarian OS, that Ubuntu have turned into, withheld update for ransom. This gives the meaning of

ransomeware a new twist of meaning.

Yes, this gives me back a good feeling in my stomachs, knowing I'm back on FOSS OS form #Debian, even tho a lot of package are outdated and need personal actions to get up to date, such as the unbound v1.17 with a lot of security issues which isn't addressed and fixed until version 1.20, but that one is still held in the testing (former SID) repo, rather than getting it released.

And this makes me wondering on how they determine which Alpha releases should be force down to the stable repo, such as wayland, that can't recover displey:0 from the sleep state, unless you reboot the system, while stable releases like unbound are withheld. This would make the first time experience of Debian as a buggy and not properly maintained distro, making people running away screaming, only to never come back. Yes, it took me a couple of days to notice the dropdown on the #SDDM login screen, allowing me to switch back to good old stable #x11 window system.

Please Debian-devs, set X11 as default windows engine and leave waylands to the experimental group running on the testing releases. The rest of us have chosen Debian for stability not a endless counts of total brake downs, while actually doing literally nothing...

IF you are using Debian stable, please share your stories.

This said, I've become rather firmly determined that no more packages/apps/programs that gets in touch with the walled Garden/big5/BigTech surveillance network, will be installed on my network anymore, this includes and is not limited to Element (Chat client) using matrix.org network as primary network, this in running over cloudflare.

A few exception would be vsCode and my sponsored IDE's from jetbrains's opensource license.

Have a nice wet/sunny summer depending on your current location... (Can see it looks a tad moist somewhere this summer https://matrix.rocks/notes/9vkrkl6g8z)

debian #ubuntu #wayland #x11 #internetsecurety #dnsbomb #walledgarden

cloudflare #big5 #bigtech #anime #rain (📎1)

— Reply to this email directly, view it on GitHub https://github.com/mitchellkrogza/Phishing.Database/issues/898#issuecomment-2228530574, or unsubscribe https://github.com/notifications/unsubscribe-auth/AZJ3Q45ZI4GJ4EAFIF5A6LTZMPGHPAVCNFSM6AAAAABK3A7ET6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDEMRYGUZTANJXGQ . You are receiving this because you authored the thread.Message ID: @.***>

thechakmasaju commented 1 month ago

Also users are ordering product continuously.

On Mon, Jul 15, 2024, 7:48 PM Saju Chakma @.***> wrote:

No. I am not using cloudflare cdn in my site. Its working for me.

On Mon, Jul 15, 2024, 7:39 PM spirillen @.***> wrote:

Your domain is still not on the open web and controlled by cloudflare.

image.png (view on web) https://github.com/user-attachments/assets/98366db3-18f2-4acb-b343-76eb664ceaee

I @.*** https://github.com/spirillen) can help you in https://github.com/mitchellkrogza/phishing/ unless you release the site to the public. As public declared, I no longer accessing the walled garden https://matrix.rocks/notes/9vkszovs0v

https://camo.githubusercontent.com/c358b90e1310b7bb95f9941a48eb200df3c6ebe50887431d473f0e167ddd01b5/68747470733a2f2f6f70656e67726170682e6769746875626173736574732e636f6d2f326662383837306461643537353036646364353735616330376535646563316338383062626664336662643537396236623232313236366261616665373131362f6d69746368656c6c6b726f677a612f7068697368696e67

https://camo.githubusercontent.com/95e35b1ddbd18e9680ef4876f3544fdf46e2116b5fefc3f6a48e1e427ea75b59/68747470733a2f2f6769746875622e6769746875626173736574732e636f6d2f66617669636f6e732f66617669636f6e2e737667 GitHub GitHub - mitchellkrogza/phishing: Central Repository for Adding Domains / Links to the Phishing.Database project - https://github.com/mitchellkrogza/Phishing.Database/ https://github.com/mitchellkrogza/phishing Central Repository for Adding Domains / Links to the Phishing.Database project - https://github.com/mitchellkrogza/Phishing.Database/ - mitchellkrogza/phishing

https://camo.githubusercontent.com/6898d8f5894916b38982fc9a8f27ae5138b43d9ac3c9ca3b61a2322577a34811/68747470733a2f2f6d61747269782e726f636b732f66696c65732f38383563623138372d653464322d343032612d616433622d316437643230626639616534

https://camo.githubusercontent.com/6e43990b657b6dfd316be6c92cdc4321489b0fa85d6bf45ebce68b119070376c/68747470733a2f2f6d61747269782e726f636b732f66696c65732f30303539316536342d633135312d346138652d383530312d333138373633313332363666 Matrix Rocks *Jerry Mouse @.**) https://matrix.rocks/notes/9vkszovs0v Feels god no longer to be slaving for propertarian OS, that Ubuntu have turned into, withheld update for ransom. This gives the meaning of

ransomeware a new twist of meaning.

Yes, this gives me back a good feeling in my stomachs, knowing I'm back on FOSS OS form #Debian, even tho a lot of package are outdated and need personal actions to get up to date, such as the unbound v1.17 with a lot of security issues which isn't addressed and fixed until version 1.20, but that one is still held in the testing (former SID) repo, rather than getting it released.

And this makes me wondering on how they determine which Alpha releases should be force down to the stable repo, such as wayland, that can't recover displey:0 from the sleep state, unless you reboot the system, while stable releases like unbound are withheld. This would make the first time experience of Debian as a buggy and not properly maintained distro, making people running away screaming, only to never come back. Yes, it took me a couple of days to notice the dropdown on the #SDDM login screen, allowing me to switch back to good old stable #x11 window system.

Please Debian-devs, set X11 as default windows engine and leave waylands to the experimental group running on the testing releases. The rest of us have chosen Debian for stability not a endless counts of total brake downs, while actually doing literally nothing...

IF you are using Debian stable, please share your stories.

This said, I've become rather firmly determined that no more packages/apps/programs that gets in touch with the walled Garden/big5/BigTech surveillance network, will be installed on my network anymore, this includes and is not limited to Element (Chat client) using matrix.org network as primary network, this in running over cloudflare.

A few exception would be vsCode and my sponsored IDE's from jetbrains's opensource license.

Have a nice wet/sunny summer depending on your current location... (Can see it looks a tad moist somewhere this summer https://matrix.rocks/notes/9vkrkl6g8z)

debian #ubuntu #wayland #x11 #internetsecurety #dnsbomb #walledgarden

cloudflare #big5 #bigtech #anime #rain (📎1)

— Reply to this email directly, view it on GitHub https://github.com/mitchellkrogza/Phishing.Database/issues/898#issuecomment-2228530574, or unsubscribe https://github.com/notifications/unsubscribe-auth/AZJ3Q45ZI4GJ4EAFIF5A6LTZMPGHPAVCNFSM6AAAAABK3A7ET6VHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDEMRYGUZTANJXGQ . You are receiving this because you authored the thread.Message ID: @.***>