-
-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
False Positive | digitaloceanspaces.com and associated regional endpoints #1048
Comments
Verification Required@tjdawson, thank you for submitting a false positive report! To help us verify your ownership of the affected domain(s), please complete the following steps:
Important Notes
How to Check the TXT Record ?You can verify that the TXT record is properly set using:
Thank you for your cooperation! We will address your issue as soon as possible after verification. The Phishing.Database Project Team. |
Hello, The TXT record has been added:
|
TXT record verified
@tjdawson I am at school at the moment and would like to give @mitchellkrogza, @funilrys, and @spirillen a chance to review this so that we can try to address the root cause of the false positives. Additionally, I tend to focus on adding threats and prefer a second opinion for these sorts of calls. I can appreciate your situation and the challenges that come with trying to ensure compliance as a cloud provider. On the other hand, here are the DO related entries I currently see in our dataset, to offer a sense of the volume: List of DO associated URIs, click to expand.
To be fair, I do recognize that the nature of your platform attracts a lot of users with limited experience in systems administration or security and besides malicious users there are also likely many comprised domains included in the above mentioned links.
I would be interested in learning more about this option. I tend to communitcate behind the scenes with other stakeholders, such as the various state SOC's and ISPs, after adding entries here. |
Hi Tim @tjdawson First of, my official free time spend helping you, cost the same as your "open source" project, and is available for 10 Bitcoins https://github.com/tjdawson/duck-dojo-bot Can be send over https://www.mypdns,org/donate Second to that, I can see you have no less than 1286 records in the DB, I do not have a tool to scan all these, and I'm not going to spend all my time on this for free, while you are spinning coins, so unless you can provide evidence, that all of these urls are dead or clean, I'm going to pass this one on to the next in line. |
What are the subjects of the false-positive (domains, URLs, or IPs)?
digitaloceanspaces.com
nyc3.digitaloceanspaces.com
ams3.digitaloceanspaces.com
sfo2.digitaloceanspaces.com
sfo3.digitaloceanspaces.com
sgp1.digitaloceanspaces.com
lon1.digitaloceanspaces.com
fra1.digitaloceanspaces.com
tor1.digitaloceanspaces.com
blr1.digitaloceanspaces.com
syd1.digitaloceanspaces.com
Why do you believe this is a false-positive?
Hello,
My name is Tim Dawson, and I work on the Security team at DigitalOcean. It was recently brought to our attention that several of our regional endpoints for our S3-compatible Object Storage product, Spaces (https://www.digitalocean.com/products/spaces), are listed as Suspicious or Malicious on VirusTotal. I'm contacting vendors who have any of the following URLs listed in order to:
We would like to reiterate DigitalOcean’s commitment to keeping our platform free of abuse. As part of this process, we would be happy to review and expedite the removal of any specific Spaces URLs currently listed in your system that are actively engaged in abusive behavior. You can find our Terms of Service and Acceptable Use Policy on the following pages:
https://www.digitalocean.com/legal/terms-of-service-agreement
https://www.digitalocean.com/legal/acceptable-use-policy
Additionally, we operate an API which provides privileged actions for trusted reporters. Reports submitted via this API will be actioned via an automated system and drastically reduce time to takedown for URLs submitted by verified reporters. If you are interested in being onboarded for access to this, please let me know and I would be happy to provide more information.
Please let me know if you have any questions or concerns. We look forward to hearing from you.
How did you discover this false-positive(s)?
VirusTotal
Where did you find this false-positive if not listed above?
Via VirusTotal and customer reports.
Have you requested a review from other sources?
Yes, we are requesting review from all other vendors who currently have these URLs listed.
Do you have a screenshot?
No applicable screenshots to provide.
Additional Information or Context
To summarize: these URLs are only the regional gateway endpoints for our S3 service, and should not be classified as malicious. We will take swift action on any reports for specific Spaces URLs hosting malicious content.
The text was updated successfully, but these errors were encountered: