Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | storage.googleapis.com #701

Open
Somebodyisnobody opened this issue Oct 16, 2024 · 5 comments
Open

False Positive | storage.googleapis.com #701

Somebodyisnobody opened this issue Oct 16, 2024 · 5 comments
Assignees

Comments

@Somebodyisnobody
Copy link
Member

What are the subjects of the false-positive (domains or URLS)?

  • storage.googleapis.com (from Phishing.Database)

Why do you believe this is a false-positive?

I believe this is a false-positive because the domain is used for too many legit services beside phishing sites.

How did you discover this false-positive(s)?

I discovered this false-positive by trying to upload a file on a website which uses storage.googleapis.com

Have you requested a review from other sources?

I don't know who is operating Phishing.Database

Additional Information or Context

@spirillen
Copy link
Contributor

Hey friend, where in the phishing DB have you seen this record? it's not among my search results

Search result from External Hosts-Sources

@mypdns's External Hosts-Sources can be found here

data/ShadowWhispererBloat.csv:os-u.storage.googleapis.com
data/ShadowWhispererTracking.csv:bluestacks-cloud-appplayer-logs.storage.googleapis.com
data/ShadowWhispererTracking.csv:geofilter-compress.storage.googleapis.com
data/ShadowWhispererTracking.csv:geofilter.storage.googleapis.com
data/Ultimate.Hosts.Blacklist2.csv:storage.googleapis.com

Sorted result

bluestacks-cloud-appplayer-logs.storage.googleapis.com
geofilter-compress.storage.googleapis.com
geofilter.storage.googleapis.com
os-u.storage.googleapis.com

Search result from easylist

easylist/easylist_specific_block.txt:||storage.googleapis.com/cdn.newsfirst.lk/advertisements/$domain=newsfirst.lk
easylist/easylist_thirdparty.txt:||storage.googleapis.com/admaxvaluemedia/
easylist/easylist_thirdparty.txt:||storage.googleapis.com/adtags/
easylist/easylist_thirdparty.txt:||storage.googleapis.com/ba_utils/stab.js
easylist_cookie/easylist_cookie_international_specific_block.txt:||storage.googleapis.com/om-gravito-cmp/$script
easyprivacy/easyprivacy_specific.txt:||storage.googleapis.com/t3n-de/assets/t3n/2018/scripts/msodrq.js
easyprivacy/easyprivacy_thirdparty.txt:||storage.googleapis.com/afs-prod/tags
easyprivacy/easyprivacy_thirdparty.txt:||storage.googleapis.com/nchq-dj-nid/prod/sp_v1.js
easyprivacy/easyprivacy_thirdparty.txt:||storage.googleapis.com/snowplow-cto-office-tracker-bucket/
easyprivacy/easyprivacy_thirdparty.txt:||storage.googleapis.com/tm-frend-graffiti/
easyprivacy/easyprivacy_thirdparty_international.txt:||storage.googleapis.com/rasin/*/hm.js
fanboy-addon/fanboy_chatapps_third-party.txt:||storage.googleapis.com/code.snapengage.com/

Search in Matrix

Search results from Matrix blacklist project

source/adware/domains.list:storage.googleapis.com
source/phishing/domains.list:storage.googleapis.com
source/tracking/domains.list:gadasource.storage.googleapis.com
source/tracking/wildcard.list:gadasource.storage.googleapis.com

Found these RPZ records from My Privacy DNS

id      domain records  type    content
21292524        storage.googleapis.com.phishing.mypdns.cloud    CNAME   .
21284298        *.gadasource.storage.googleapis.com.tracking.mypdns.cloud       CNAME   .
21284297        gadasource.storage.googleapis.com.tracking.mypdns.cloud CNAME   .
24819736        gadasource.storage.googleapis.com.adware.mypdns.cloud   CNAME   .
24804302        storage.googleapis.com.adware.mypdns.cloud      CNAME   .

Any known matrix issues?

+ We did not find any existing issues for the domain in Matrix

+++++++++++++++++++++++++++++++++++++++
+ Thanks to My Privacy DNS for this knowledge +
+++++++++++++++++++++++++++++++++++++++

@spirillen
Copy link
Contributor

@mitchellkrogza, @funilrys

image

And only if I do not get the cert error

@Somebodyisnobody
Copy link
Member Author

@mitchellkrogza, @funilrys

image

And only if I do not get the cert error

I was unsure if the app still exists. It wasn't working for me either

@Somebodyisnobody
Copy link
Member Author

@spirillen
Copy link
Contributor

That seems to be related to mitchellkrogza/phishing#395, regarding the phishing relation

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Development

No branches or pull requests

5 participants