Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | macdiarmidlegal.com.au #658

Closed
jcfbeardsley opened this issue Jan 8, 2025 · 4 comments · Fixed by #663
Closed

False Positive | macdiarmidlegal.com.au #658

jcfbeardsley opened this issue Jan 8, 2025 · 4 comments · Fixed by #663
Assignees
Labels
False Positive This domain have been block by mistake

Comments

@jcfbeardsley
Copy link

What are the subjects of the false-positive (domains, URLs, or IPs)?

Why do you believe this is a false-positive?

I believe this is a false-positive because...
This website was previously compromised by a malicious actor, but the domain has since been transferred to a new registrar and connected to a different web host. A brand new (clean) website has now been built for this domain, so the address should be re-assessed.

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

I discovered this false-positive by...
https://www.virustotal.com/gui/domain/macdiarmidlegal.com.au

Have you requested a review from other sources?

No response

Do you have a screenshot?

No response

Additional Information or Context

No response

@spirillen spirillen moved this from 🆕 New to 👀 In review in Phishing Database Backlog Jan 8, 2025
@spirillen spirillen added the False Positive This domain have been block by mistake label Jan 8, 2025
@spirillen
Copy link
Contributor

Sorry for the delay, I did see this issue, right before I entered my special comfort zone 🛌🏻

I understand the annoyance I'm going to tell you as of right now... and your gonna hate me, I'm sorry.

I do find rather resent links to the domain, and since I (Github) doesn't know you, I'm gonna request for a verification of your relation to this domain.

Also I only see that your site in under construction.

image

Please make the DNS check, then I'll guess @g0d33p3rsec can take over the case as I leaving for many hours.

@spirillen
Copy link
Contributor

This is the single record in the db, and is insufficient to test for phishing https://macdiarmidlegal.com.au/comnet

@spirillen spirillen moved this from 👀 In review to 🚫 Blocked / Waiting in Phishing Database Backlog Jan 8, 2025
@g0d33p3rsec
Copy link
Contributor

This is the single record in the db, and is insufficient to test for phishing https://macdiarmidlegal.com.au/comnet

It looks like there was a lure targeting Commonwealth Bank hosted there in the period around January 22nd 2023
https://urlscan.io/result/f0028d61-e59c-473c-b09d-37a87ec75206/
f0028d61-e59c-473c-b09d-37a87ec75206

The same URI now 404s
image

I have no objection to delisting if you're okay with it @spirillen

@g0d33p3rsec
Copy link
Contributor

@jcfbeardsley I just rescanned www.macdiarmidlegal.com.au and we are not returning a positive result for the subdomain.
image

#663 should address the parent domain.

@github-project-automation github-project-automation bot moved this from 🚫 Blocked / Waiting to ✅ Done in Phishing Database Backlog Jan 14, 2025
@g0d33p3rsec g0d33p3rsec removed the WIP label Jan 14, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
False Positive This domain have been block by mistake
Projects
Status: ✅ Done
Development

Successfully merging a pull request may close this issue.

5 participants