Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | corp.bnpparibasbank.ru #974

Closed
R4inbowD4sh opened this issue Dec 27, 2024 · 6 comments
Closed

False Positive | corp.bnpparibasbank.ru #974

R4inbowD4sh opened this issue Dec 27, 2024 · 6 comments
Assignees
Labels
false positive Should not be listed

Comments

@R4inbowD4sh
Copy link

What are the subjects of the false-positive (domains, URLs, or IPs)?

https://corp.bnpparibasbank.ru/
corp.bnpparibasbank.ru

Why do you believe this is a false-positive?

BNP Paribas russia E-banking site corp.bnpparibasbank.ru is reported as Malicious on VirusTotal .
It is a false positive detection. Some other vendors have already reclassified the site as Clean.

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

https://www.virustotal.com/gui/domain/corp.bnpparibasbank.ru

Have you requested a review from other sources?

No response

Do you have a screenshot?

No response

Additional Information or Context

No response

@g0d33p3rsec
Copy link

Someone else will need to address this issue, I'm not comfortable touching it due to the geopolitical conflict of interest and risk of legal jeopardy as a U.S. citizen.

@g0d33p3rsec g0d33p3rsec added the false positive Should not be listed label Dec 28, 2024
@spirillen
Copy link
Contributor

And I'm not touching it for the same reason as neighbor to Sweden, Finland, Germany ETC as I lives next to the Baltic Sea, And I do not support warmongers, or any other country that keeps attacking peaceful countries, Ukraine, Finland, Estonia etc.

EU also have an 100% war embargo against Russia, So it is illegal for anyone at this project to touch this issue. with exception for people living in South Africa, who stands by and training military with Putin.

@R4inbowD4sh
Copy link
Author

Understanding and respecting the USA and EU "embargo" regulations against Russia is crucial.
However, addressing this false positive detection is essential to ensure accurate threat intelligence and avoid any negative impact on legitimate services.
Phishing Database is now one of the only VirusTotal vendors to classify the site as "Phishing". Other vendors, including US-based ones like Forcepoint, have corrected their classification and marked the site as "Clean".

@g0d33p3rsec g0d33p3rsec removed their assignment Jan 4, 2025
@funilrys funilrys added false positive Should not be listed and removed false positive Should not be listed labels Jan 7, 2025
@phishing-database-bot
Copy link
Member

Verification Required

@R4inbowD4sh, thank you for submitting a false positive report! To help us verify your ownership of the affected domain(s), please complete the following steps:

  1. Set a DNS TXT record for the domain(s) listed in this issue with the following details:

    • Record Name: _phishingdb
    • Record Value: antiphish-d1e8b513b127ed59087e0d08ec402eda9c48550c

    Your Verification ID: antiphish-d1e8b513b127ed59087e0d08ec402eda9c48550c

  2. Wait for DNS propagation (this may take a few minutes to a few hours).

  3. Reply to this issue once the TXT record has been set.

Important Notes

  • Verification does not guarantee whitelisting. The Phishing.Database team will review your report after verifying ownership, but the decision to whitelist depends on further investigation and analysis.
  • If the record cannot be set or you need alternative methods of verification, please contact us at [email protected] - preferably from the domain's official email address.

How to Check the TXT Record ?

You can verify that the TXT record is properly set using:

Thank you for your cooperation! We will address your issue as soon as possible after verification.

The Phishing.Database Project Team.

@funilrys
Copy link
Contributor

funilrys commented Jan 7, 2025

@R4inbowD4sh, please comply with the comment above.

Thank your for your patience.

@funilrys funilrys moved this from 🆕 New to 🚫 Blocked / Waiting in Phishing Database Backlog Jan 7, 2025
@github-project-automation github-project-automation bot moved this from 🚫 Blocked / Waiting to ✅ Done in Phishing Database Backlog Jan 9, 2025
@mitchellkrogza
Copy link
Contributor

@funilrys personal request received all domains check out okay for me

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
false positive Should not be listed
Projects
Archived in project
Development

No branches or pull requests

6 participants