Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | https://workforcebrokers.com/ #1019

Open
mbte opened this issue Jan 14, 2025 · 9 comments
Open

False Positive | https://workforcebrokers.com/ #1019

mbte opened this issue Jan 14, 2025 · 9 comments
Assignees
Labels
duplicate This issue or pull request already exists

Comments

@mbte
Copy link

mbte commented Jan 14, 2025

What are the subjects of the false-positive (domains, URLs, or IPs)?

Why do you believe this is a false-positive?

Workforcebrokers.com had a cyber security incident, my company resolved this issue for them. They are still on the blacklist on Virustotal.com and need to be removed, please!

How did you discover this false-positive(s)?

Other (Please fill out the next box)

Where did you find this false-positive if not listed above?

My company was contracted for the malware removal and remediation of this incident.

Have you requested a review from other sources?

Trolleye Security did the review and the remediation. This wordpress site is now monitored by Sucuri along with their WAF

Do you have a screenshot?

Screenshot

Additional Information or Context

I have also noticed that...

@phishing-database-bot
Copy link
Member

Verification Required

@mbte, thank you for submitting a false positive report! To help us verify your ownership of the affected domain(s), please complete the following steps:

  1. Set a DNS TXT record for the domain(s) listed in this issue with the following details:

    • Record Name: _phishingdb
    • Record Value: antiphish-ee1e8b09ee423144f28569222e25411317451af9

    Your Verification ID: antiphish-ee1e8b09ee423144f28569222e25411317451af9

  2. Wait for DNS propagation (this may take a few minutes to a few hours).

  3. Reply to this issue once the TXT record has been set.

Important Notes

  • Verification does not guarantee whitelisting. The Phishing.Database team will review your report after verifying ownership, but the decision to whitelist depends on further investigation and analysis.
  • If the record cannot be set or you need alternative methods of verification, please contact us at [email protected] - preferably from the domain's official email address.

How to Check the TXT Record ?

You can verify that the TXT record is properly set using:

Thank you for your cooperation! We will address your issue as soon as possible after verification.

The Phishing.Database Project Team.

@mbte
Copy link
Author

mbte commented Jan 15, 2025

This record was just added!

@spirillen
Copy link
Contributor

Duplicate of #993

@spirillen spirillen marked this as a duplicate of #993 Jan 15, 2025
@github-project-automation github-project-automation bot moved this from 🆕 New to ✅ Done in Phishing Database Backlog Jan 15, 2025
@mbte
Copy link
Author

mbte commented Jan 16, 2025

this still needs to be resolved, the last issue was closed because the site was not public.

@spirillen
Copy link
Contributor

this still needs to be resolved, the last issue was closed because the site was not public.

and still isn't, so you need to resolve that at first. I'm still blocked, locked out what ever you will call it, and without access to the site, we can't handle any request as we can't test, control etc.

Make the domain public available or stay on the list.

@mbte
Copy link
Author

mbte commented Jan 16, 2025

Image

https://workforcebrokers.com/

It is public, I am confused about why you cannot access this.

@mbte
Copy link
Author

mbte commented Jan 16, 2025

We have strict geoblocking and rules in place using Wordfence, I do not want to disable any of the rules we have in place.

@spirillen
Copy link
Contributor

I reopen it, but I'm not the one wasting more time of this intranet site, that's not what I wont to waste my free time at.

@spirillen spirillen reopened this Jan 16, 2025
@github-project-automation github-project-automation bot moved this from ✅ Done to 📋 Backlog in Phishing Database Backlog Jan 16, 2025
@spirillen spirillen moved this from 📋 Backlog to 🆕 New in Phishing Database Backlog Jan 16, 2025
@spirillen spirillen added the duplicate This issue or pull request already exists label Jan 16, 2025
@spirillen spirillen removed their assignment Jan 16, 2025
@mbte
Copy link
Author

mbte commented Jan 16, 2025

This is not an intranet site.
From the original ticket you were blocked by Wordfence, which I just explained has geoblocking in place.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
duplicate This issue or pull request already exists
Projects
Status: 🆕 New
Development

No branches or pull requests

6 participants