Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | shorter.gg #1105

Closed
NodeAdmins-com opened this issue Feb 6, 2025 · 4 comments
Closed

False Positive | shorter.gg #1105

NodeAdmins-com opened this issue Feb 6, 2025 · 4 comments
Assignees
Labels
wontfix This will not be worked on

Comments

@NodeAdmins-com
Copy link

What are the subjects of the false-positive (domains, URLs, or IPs)?

shorter.gg

Why do you believe this is a false-positive?

Dear Phishing Database

I hope this message finds you well. I am reaching out regarding our domain, shorter.gg, which appears to have been flagged and blacklisted by your system.

Shorter.gg is a reputable URL shortening service that prioritizes user safety. We actively monitor our platform for any malicious activity, and any harmful content is promptly removed upon detection or being reported.

We believe this flagging is a false positive and would greatly appreciate it if you could review our case. If there are specific issues or criteria we need to address to resolve this, please let us know so we can take the necessary steps.

Thank you for your time and support. We look forward to your response.

Best regards, shorter.gg support team.

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

I discovered this false-positive by...

Have you requested a review from other sources?

I have requested a review from...

Do you have a screenshot?

Screenshot

Additional Information or Context

I have also noticed that...

@phishing-database-bot
Copy link
Member

Verification Required

@NodeAdmins-com, thank you for submitting a false positive report! To help us verify your ownership of the affected domain(s), please complete the following steps:

  1. Set a DNS TXT record for the domain(s) listed in this issue with the following details:

    • Record Name: _phishingdb
    • Record Value: antiphish-29ef02b6dfc532e01d5cb630b556ea1de4b65d8a

    Your Verification ID: antiphish-29ef02b6dfc532e01d5cb630b556ea1de4b65d8a

  2. Wait for DNS propagation (this may take a few minutes to a few hours).

  3. Reply to this issue once the TXT record has been set.

Important Notes

  • Verification does not guarantee whitelisting. The Phishing.Database team will review your report after verifying ownership, but the decision to whitelist depends on further investigation and analysis.
  • If the record cannot be set or you need alternative methods of verification, please contact us at [email protected] - preferably from the domain's official email address.

How to Check the TXT Record ?

You can verify that the TXT record is properly set using:

Thank you for your cooperation! We will address your issue as soon as possible after verification.

The Phishing.Database Project Team.

@NodeAdmins-com
Copy link
Author

TXT record added

@spirillen
Copy link
Contributor

Search results

Lookup provided by My Privacy DNS

Hosts-Sources

External Hosts-Sources can be found here

phishing_database/ALL-phishing-links.csv:www.shorter.gg
phishing_database/phishing.database/domain.csv:shorter.gg

Sorted result

www.shorter.gg

EasyList

Matrix blacklist project

redirector/wildcard:shorter.gg
tracking/wildcard:shorter.gg

Matrix blacklist project, Filtered

Response Policy Zone - RPZ

Found these RPZ records in My Privacy DNS

Domain records Type content
*.shorter.gg.redirector.mypdns.cloud CNAME .
shorter.gg.redirector.mypdns.cloud CNAME .
*.shorter.gg.tracking.mypdns.cloud CNAME .
shorter.gg.tracking.mypdns.cloud CNAME .

Known Issues

DNS lookup

dante.ns.cloudflare.com.
kenia.ns.cloudflare.com.

HTTP header

HTTP response, click to expand
HTTP/2 200 
date: Thu, 06 Feb 2025 08:47:47 GMT
content-type: text/html; charset=UTF-8
x-powered-by: PHP/8.2.26
set-cookie: PHPSESSID=69699ae08b6e5699f33f66850203fa0d; path=/
expires: Thu, 19 Nov 1981 08:52:00 GMT
cache-control: no-store, no-cache, must-revalidate
pragma: no-cache
cf-cache-status: DYNAMIC
report-to: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Z3FKetC%2BPmnx%2FNNGUxyYcD5EeB9Pa3XWeY5lcqAioYArhCsFXBl%2BnHY1qp%2BnZxf114we1XT87npTcZmkaSSkDDSHM%2B9f0rOW1BvQq8qQHxVm1nZvKcY3bHw74avP"}],"group":"cf-nel","max_age":604800}
nel: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
strict-transport-security: max-age=15552000; includeSubDomains; preload
x-content-type-options: nosniff
server: cloudflare
cf-ray: 90d9e09eb9ff3875-AMS
alt-svc: h3=":443"; ma=86400
server-timing: cfL4;desc="?proto=TCP&rtt=937&min_rtt=886&rtt_var=223&sent=5&recv=8&lost=0&retrans=0&sent_bytes=3423&recv_bytes=844&delivery_rate=3022964&cwnd=253&unsent_bytes=0&cid=51b5d34c81584453&ts=1211&x=0"

@spirillen
Copy link
Contributor

ptcheck shorter.gg antiphish-29ef02b6dfc532e01d5cb630b556ea1de4b65d8a
The test value matches the DNS TXT record.

Thanks for using my tools.
Please consider a sponsor ship at https://www.mypdns.org/donate

sd shorter.gg
http://www.shorter.gg/NVJOVL

HTTP/2 410 👍🏻 👍🏻

However, all URL shorteners seem to be managed through @PeterDaveHello's URL lists. You need to submit a request to have your link included in his project.

@github-project-automation github-project-automation bot moved this from 🆕 New to ✅ Done in Phishing Database Backlog Feb 6, 2025
@spirillen spirillen added the wontfix This will not be worked on label Feb 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
wontfix This will not be worked on
Projects
Archived in project
Development

No branches or pull requests

6 participants