Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | l1nq.com #766

Open
patrikbell opened this issue Feb 26, 2025 · 14 comments
Open

False Positive | l1nq.com #766

patrikbell opened this issue Feb 26, 2025 · 14 comments
Assignees
Labels
False Positive This domain have been block by mistake

Comments

@patrikbell
Copy link

patrikbell commented Feb 26, 2025

What are the subjects of the false-positive (domains, URLs, or IPs)?

https://l1nq.com/ftZOx

Why do you believe this is a false-positive?

Hello, I hired a LinkedIn marketing agency (advisorappointments.com) to handle the marketing for my business. They adapted a tiny URL from a legitimate partner website and somehow it directed traffic to another site which is the justifiable reason why I got tagged and suspended. After reaching out to LI corporate, I received a message from Selina who is one of their Executive Escalations Case Managers to contact you. In the meantime, I have released Advisor Appointments from helping me. I would respectfully like to have my account reinstated and will promise to double check all links in the future.

I believe this is a false-positive because it was it originally went to a legitimate web page but this link no longer goes anywhere.

Thank you,
Patrick

How did you discover this false-positive(s)?

Other (Please fill out the next box)

Where did you find this false-positive if not listed above?

I discovered this false-positive by being contacted by LinkedIn corporate.

Have you requested a review from other sources?

I have requested a review from CRDF Labs and they removed the false positive. Here is their email:
Hello,

False Positive Reference #20250226837032

You receive this confirmation after your request for a URL that is a false positive.
We are pleased to inform you that the domain name "l1nq.com" have been removed from our database.

Thank you kindly note that the spread of the new corrected database may take some time (about 4 hours).

If you need to notify us of other domain names or if the application does not correspond to your expectations, thank you to send a request to https://threatcenter.crdf.fr/false_positive.html.

In any case, thank you kindly note that we take very seriously the reports that you send us the false positive and we thank you.
If you have any questions, please consult our FAQ accessible at the following address: https://threatcenter.crdf.fr/faq.html


Satisfied with our response? Feel free to leave us a feedback on:
https://threatcenter.crdf.fr/feedback.php?ref=67bf0243c51445.89142507

Regards,
CRDF Labs,

Do you have a screenshot?

Screenshot

Image

Additional Information or Context

Your help is so very appreciated. Thank you.

@spirillen spirillen changed the title False Positive | https://l1nq.com/ftZOx False Positive | l1nq.com Feb 27, 2025
@spirillen
Copy link
Contributor

Where do you expect this domain to redirect to?? and is it yours domain, and what is it purpose??

@g0d33p3rsec do you understand this issue, as a native speaking?

https://l1nq.com/ftZOx

@patrikbell
Copy link
Author

patrikbell commented Feb 27, 2025 via email

@spirillen
Copy link
Contributor

Have you inadvertently selected the False Positive report, when in fact, you intended to report the link as Phishing, given that the destination URL is https://www.encurtador.dev/redirecionamento/ftZOx rather than the expected repeatable.ai?

spirillen added a commit to mypdns/matrix that referenced this issue Feb 27, 2025
Fix #866

MTX-203600 Added ad company #MTX-203600 FIXED

Rel Phishing-Database/phishing#766
spirillen added a commit to mypdns/matrix that referenced this issue Feb 27, 2025
Fix #121070

MTX-203600 Added ad company #MTX-203600 FIXED

Rel Phishing-Database/phishing#766
@patrikbell
Copy link
Author

patrikbell commented Feb 27, 2025 via email

@g0d33p3rsec
Copy link
Contributor

do you understand this issue, as a native speaking?

Not really. I'm still unsure of which domains the reporting party actually has control of. From what I can gather, the first of the two link shorteners, which is the domain listed in this report, is included in our dataset. LinkedIn uses VirusTotal to scan links used on their platform and a post with the shortened link led to the reporter's account being restricted.

Have you inadvertently selected the False Positive report, when in fact, you intended to report the link as Phishing, given that the destination URL is https://www.encurtador.dev/redirecionamento/ftZOx rather than the expected repeatable.ai?

https://urlscan.io/result/51a42cc4-b2af-43ae-b099-f92ce391f27d/

Image

Additionally, I see https://l1nq.com/KJ0L0 in our dataset, which also redirects to www.encurtador.dev.
Image
https://app.any.run/tasks/29c7d97a-617a-41cf-bbc9-3b4f2d49ff7e
Image

https://www.virustotal.com/gui/domain/encurtador.dev/
Image
Image

Checking repeatable.ai on VirusTotal returns clean results from all engines. @patrikbell am I correct in understanding you have no relation to encurtador.dev and your only relation to l1nq.com was through advisorappointments.com? From what I can see, both the shortener and the target are true positives.

You can see that the "anti-malware" checks were turning blue... before moving me on to this page: https://repeatable.ai/repeatable-session-page?affiliate_code=7111

The same "anti-malware" tracker that can't even bother to include the right domain name in the header?

Image

@spirillen
Copy link
Contributor

@patrikbell do you understand the concept of what a False Positive is?

@patrikbell
Copy link
Author

patrikbell commented Feb 28, 2025 via email

@spirillen
Copy link
Contributor

Alright, so if I’ve understood you correctly, you would like to request that they be added as phishing, as they link to harmful webpages, but at the same time, you want them removed from the Phishing Database so that you can have your trapped in Metasheep account released? Am I getting closer to grasping your request?

@patrikbell
Copy link
Author

patrikbell commented Mar 1, 2025 via email

@spirillen
Copy link
Contributor

Meta sheep:

  1. Meta as in Metadata: In the context of online privacy, "meta" often refers to metadata, which is data that provides information about other data. For example, metadata can include details about when a file was created, who created it, and how it has been modified. A "Meta sheep" could refer to individuals who are unaware of how their metadata is being collected and used, essentially following the herd without understanding the implications for their privacy.

  2. Social Media Context: If "Meta" refers to Meta Platforms, Inc. (formerly Facebook), a "Meta sheep" might describe users who passively accept the privacy practices of social media platforms without questioning or understanding the potential risks to their personal information. This could imply a lack of critical engagement with privacy settings and data sharing practices.

  3. General Conformity: More broadly, the term could symbolize people who conform to online behaviors and practices without considering the privacy implications, similar to how sheep follow a flock.

In any case, the concept highlights the importance of being aware of privacy issues and understanding how personal data is collected, used, and shared (abused) in the digital landscape. It encourages individuals to take an active role in managing their online privacy rather than passively accepting the status quo.

@spirillen
Copy link
Contributor

is it l1nq.com you want whitelisted?

@patrikbell
Copy link
Author

patrikbell commented Mar 3, 2025 via email

@spirillen
Copy link
Contributor

Yes please and thank you.

Super, This issue should be solved by @PeterDaveHello as this is a url_shortner, and for some reasons they are not included into this project?? 🤷🏻 ¯_(ツ)_/¯

@spirillen spirillen added the False Positive This domain have been block by mistake label Mar 3, 2025
@spirillen spirillen moved this from 🆕 New to 🔖 Ready in Phishing Database Backlog Mar 3, 2025
@patrikbell
Copy link
Author

patrikbell commented Mar 3, 2025 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
False Positive This domain have been block by mistake
Projects
Status: 🔖 Ready
Development

No branches or pull requests

6 participants