Skip to content

False Positive | su.vc #976

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wardhache opened this issue Dec 27, 2024 · 5 comments
Closed

False Positive | su.vc #976

wardhache opened this issue Dec 27, 2024 · 5 comments
Assignees
Labels
false positive Should not be listed

Comments

@wardhache
Copy link

What are the subjects of the false-positive (domains, URLs, or IPs)?

  • su.vc

Why do you believe this is a false-positive?

As the Lead Developer of Pointerpro, I want to address the blacklisting of our short domain, su.vc, in the Phishing-Database. This domain is integral to our platform, which provides secure and professional services for creating and distributing online assessments and surveys.

Pointerpro is a reputable company serving numerous clients worldwide. The su.vc domain is used exclusively for these clients to generate a short link to their assessment. It has a valid HTTPS connection, ensuring security and trustworthiness. It also immediately redirects to s.pointerpro.com. We also offer white-labeling to ensure our clients' branding is reflected through their surveys and emails. As part of this service, emails sent from the platform may use the su.vc domain.

I believe this blacklisting is a false positive, likely stemming from the nature of survey distribution, which is occasionally misinterpreted as phishing activity. However, I can assure you that su.vc is not involved in any malicious or deceptive practices. Its sole purpose is to facilitate the sharing of legitimate surveys for our platform users.

We take security and compliance very seriously and are confident in the integrity of our domain and its use. I kindly request that you review this case and remove su.vc from the blacklist.

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

We have an automated cronjob using the API of virustotal.com

Have you requested a review from other sources?

No response

Do you have a screenshot?

No response

Additional Information or Context

No response

@g0d33p3rsec
Copy link

The link that was in our db https://su.vc/rjapaohd has been removed.

197ca988-7be4-4e2f-862f-0f2b7b8bbfec

When reviewing the domain history, I came across another phishing lure that has since been removed.
https://urlscan.io/result/9c7c8714-eef9-4b2f-8e17-9d29ea3fad6d/

9c7c8714-eef9-4b2f-8e17-9d29ea3fad6d

When looking at that result, my primary concern is a lack of a reporting mechanism on the generated form. If I look at other forms on your service, I can see that you can add your corporate watermark so a link to report abuse shouldn't be an unreasonable ask.

1844c4b4-4cc3-4d43-9b85-ae6f82e865d3

@spirillen
Copy link
Contributor

I agree the link (Record) in the database, no longer are active.

But whitelisting the domain as such, raises the same question as regarding any url_shortners like funilrys/PyFunceble#412 (comment), #971 and #970

@wardhache Are you open for the possibility to return HTTP code 410 on removed links?, or any other HTTP code uniq for disabled URI's, then I'm open for adding a MR to add a special rule to PyFunceble for your domain.

Touches funilrys/PyFunceble#409

@g0d33p3rsec g0d33p3rsec added the false positive Should not be listed label Dec 28, 2024
spirillen added a commit to Phishing-Database/phishing that referenced this issue Jan 4, 2025
@spirillen
Copy link
Contributor

Solved in Phishing-Database/phishing@62307bc

@wardhache
Copy link
Author

@spirillen Thanks for going forward with this. We will look into the possibility to return HTTP Code 410 on removed links.

@spirillen
Copy link
Contributor

Sounds eminent, Looking forward to receive news on the implementation.

If you need more private chat channel, you are welcome to use https://www.mypdns.org/contact @g0d33p3rsec have access to the system as well

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
false positive Should not be listed
Projects
Archived in project
Development

No branches or pull requests

5 participants