Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | banking-oberbank.at #768

Open
DS3-IT opened this issue Feb 27, 2025 · 3 comments
Open

False Positive | banking-oberbank.at #768

DS3-IT opened this issue Feb 27, 2025 · 3 comments
Assignees
Labels
verification The label to use to request verification.

Comments

@DS3-IT
Copy link

DS3-IT commented Feb 27, 2025

What are the subjects of the false-positive (domains, URLs, or IPs)?

banking-oberbank.at

Why do you believe this is a false-positive?

I believe this is a false-positive because this website is owned by 3 Banken IT, the IT service provider of Oberbank
https://urlscan.io/result/a565d6bf-363b-4a44-8f08-6e9782750e19/

How did you discover this false-positive(s)?

Other (Please fill out the next box)

Where did you find this false-positive if not listed above?

Brand Mentions on Github

Have you requested a review from other sources?

No

Do you have a screenshot?

Screenshot

Additional Information or Context

https://urlscan.io/result/a565d6bf-363b-4a44-8f08-6e9782750e19/

@spirillen
Copy link
Contributor

This is weird,,, I do not find the domain in my latest ALL-phishing-links.csv(1 minutes old)

While it is listed within hosts-sources project (1 hour since last update)

Conclusion

Putting on hold

@spirillen spirillen changed the title False Positive | banking-oberbank.at False Positive | banking-oberbank.at (Paused until 19:00 CEST) Feb 27, 2025
@spirillen spirillen moved this from 🆕 New to 🚫 Blocked / Waiting in Phishing Database Backlog Feb 27, 2025
@DS3-IT
Copy link
Author

DS3-IT commented Feb 27, 2025

Hello, it´s in phishing-domains-ACTIVE.adblock on repo Phishing.Database

@spirillen spirillen changed the title False Positive | banking-oberbank.at (Paused until 19:00 CEST) False Positive | banking-oberbank.at Feb 28, 2025
@spirillen spirillen added the verification The label to use to request verification. label Feb 28, 2025
@spirillen
Copy link
Contributor

spirillen commented Feb 28, 2025

Hello, it´s in phishing-domains-ACTIVE.adblock on repo Phishing.Database

That ain't a valid resource, only chose listed on https://github.com/Phishing-Database#-download-data are considered valid

Now I see it in the link list. Taking it from here

Hmmm haven't you been validating your relation to the domain by adding a TXT record??


Please add the following TXT to the domain. This is a security check to limit the risk of interacting with the phisher.

Verification Required

Thank you for submitting a false positive report! To help us verify your ownership of the affected domain(s), please complete the following steps:

  1. Set a DNS TXT record for the domain(s) listed in this issue with the following details:

    • Record Name: _phishingdb
    • Record Value: antiphish-0a9405626d32073d896a0439e80766b91119ca56

    Your Verification ID:

    antiphish-0a9405626d32073d896a0439e80766b91119ca56
    
  2. Wait for DNS propagation (this may take a few minutes to a few hours).

  3. Reply to this issue once the TXT record has been set.

Important Notes

* **Verification does not guarantee whitelisting**. The Phishing.Database team will review your report after verifying ownership, but the decision to whitelist depends on further investigation and analysis.

* If the record cannot be set or you need alternative methods of verification, please contact us at [[email protected]](mailto:[email protected]) - preferably from the domain's official email address.

How to Check the TXT Record ?

You can verify that the TXT record is properly set using:

* The command line:
  ```
  dig TXT _phishingdb.example.com
  ```

Thank you for your cooperation! We will address your issue as soon as possible after verification.

The Phishing.Database Project Team.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
verification The label to use to request verification.
Projects
Status: 🚫 Blocked / Waiting
Development

No branches or pull requests

5 participants