Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

False Positive | mobilephotokiosk.app #1058

Open
idformats opened this issue Jan 24, 2025 · 18 comments
Open

False Positive | mobilephotokiosk.app #1058

idformats opened this issue Jan 24, 2025 · 18 comments
Assignees
Labels
bug Something isn't working

Comments

@idformats
Copy link

What are the subjects of the false-positive (domains, URLs, or IPs)?

admin.mobilephotokiosk.app
mobilephotokiosk.app

Why do you believe this is a false-positive?

We - Pixel-Tech (www.pixel-tech.eu) - are the owner of this domain. Mobile Photo Kiosk is our main solution provided all around the world. You can contact us: [email protected]

How did you discover this false-positive(s)?

Other (Please fill out the next box)

Where did you find this false-positive if not listed above?

I discovered this false-positive by searching virustotal.com

Have you requested a review from other sources?

No response

Do you have a screenshot?

No response

Additional Information or Context

No response

@phishing-database-bot
Copy link
Member

Verification Required

@idformats, thank you for submitting a false positive report! To help us verify your ownership of the affected domain(s), please complete the following steps:

  1. Set a DNS TXT record for the domain(s) listed in this issue with the following details:

    • Record Name: _phishingdb
    • Record Value: antiphish-2eb080aee8b01009f0c916e44b2cfcde301497f7

    Your Verification ID: antiphish-2eb080aee8b01009f0c916e44b2cfcde301497f7

  2. Wait for DNS propagation (this may take a few minutes to a few hours).

  3. Reply to this issue once the TXT record has been set.

Important Notes

  • Verification does not guarantee whitelisting. The Phishing.Database team will review your report after verifying ownership, but the decision to whitelist depends on further investigation and analysis.
  • If the record cannot be set or you need alternative methods of verification, please contact us at [email protected] - preferably from the domain's official email address.

How to Check the TXT Record ?

You can verify that the TXT record is properly set using:

Thank you for your cooperation! We will address your issue as soon as possible after verification.

The Phishing.Database Project Team.

@idformats
Copy link
Author

Hello, the TXT record has been set. Best regards

@idformats
Copy link
Author

Dear Support, any news about the false report? Sorry for the rush but this situation is really problematic on our side. Our major customers are having a hard time accessing their store platform on Mobile Photo Kiosk. We are recording significant losses because of this.

Could I ask where did you get the report that the site is unsafe? On the Mobile Photo Kiosk website, customers do not have to provide any data, we do not use analytics, there is no possibility to save credit card data (the service does not have such functionality).

Best regards, Edyta Dziubek.

@drego85
Copy link

drego85 commented Jan 29, 2025

@mitchellkrogza, can you please remove “mobilephotokiosk.app” from the list? It is a false positive.
On Phishing Army it has already been removed and also by PhishTank.
🙏 thanks!

@spirillen
Copy link
Contributor

I doubt this issue is regarding example.com, please solve the issue to match the template

@idformats
Copy link
Author

Hello, any news for us about removing mobilephotokiosk.app from your list? It seems that another vendor doesn't want to remove us from its list, because we are still on your list.

Furthermore, could I ask where did you get the report that the site is unsafe? On the Mobile Photo Kiosk website, customers do not have to provide any data, we do not use analytics, there is no possibility to save credit card data (the service does not have such functionality).

It's just strange that we end up with such a list for no apparent reason, and other vendors just copy it - without any basis, without checking.

Best regards

Edyta Dziubek

@drego85
Copy link

drego85 commented Feb 3, 2025

Hi @idformats, please correct the initial message by following @idformats's indication (fix example.com from title).

@idformats idformats changed the title False Positive | example.com False Positive | mobilephotokiosk.app Feb 3, 2025
@idformats
Copy link
Author

Hi @drego85 , done

@drego85
Copy link

drego85 commented Feb 3, 2025

Well, I'm not an admin or maintainer of this repository. I hope that soon those in authority will resolve your false positive!

@idformats
Copy link
Author

Yes, I know. Thanks for pointing out that I should correct the topic - I hadn't noticed that before.

@idformats
Copy link
Author

idformats commented Feb 3, 2025

@spirillen > I doubt this issue is regarding example.com, please solve the issue to match the template

Something more we need to correct to solve this issue?

@spirillen
Copy link
Contributor

@spirillen > I doubt this issue is regarding example.com, please solve the issue to match the template

Something more we need to correct to solve this issue?

Well this one solves, so let's move forward to do some lookup, testing and a lot of fancy words, to make sounds like I'm doing something and not just on the can, which I am... I'll be back to Terminate this issue

ptcheck mobilephotokiosk.app antiphish-2eb080aee8b01009f0c916e44b2cfcde301497f7
The test value matches the DNS TXT record.

Thanks for using my tools.
Please consider a sponsor ship at https://www.mypdns.org/donate

spirillen added a commit to Phishing-Database/phishing that referenced this issue Feb 3, 2025
@spirillen
Copy link
Contributor

spirillen commented Feb 3, 2025

I don't see why you should have been listed, the uri seems fine, however It could be related to the play stores, I don't know

https://urlscan.io/result/634085b9-d330-46c4-9ff0-660cf087a655/ | https://urlscan.io/search/#page.domain%3Amobilephotokiosk.app

Image

whitelisted in Phishing-Database/phishing@932c3ca

@github-project-automation github-project-automation bot moved this from 🆕 New to ✅ Done in Phishing Database Backlog Feb 3, 2025
@idformats
Copy link
Author

Hi @spirillen , hope I'm finding you well. Could you check one more time? Because mobilephotokiosk.app is still listed as Phishing.

BTW another our domain has been listed too: mobilephotokiosk.com -> should I create a new issue or you can handle it within this one?

Best regards

Edyta Dziubek

@spirillen
Copy link
Contributor

BTW another our domain has been listed too: mobilephotokiosk.com -> should I create a new issue or you can handle it within this one

please do, My personal prefs says one domain = one issue as you that way can keep the threat clean, concise and relevant for that one domain

Could you check one more time?

It is still listed here Phishing-Database/phishing@932c3ca, I can't do more about it, and yet I still see you in the db,,,

sd mobilephotokiosk.app
https://mobilephotokiosk.app:443/view/1337

@funilrys Huston we have Apolla 13 sized issues here

@spirillen spirillen reopened this Feb 5, 2025
@github-project-automation github-project-automation bot moved this from ✅ Done to 📋 Backlog in Phishing Database Backlog Feb 5, 2025
@spirillen spirillen added the bug Something isn't working label Feb 5, 2025
@spirillen spirillen moved this from 📋 Backlog to 🏗 In progress in Phishing Database Backlog Feb 5, 2025
@idformats
Copy link
Author

BTW another our domain has been listed too: mobilephotokiosk.com -> should I create a new issue or you can handle it within this one

please do, My personal prefs says one domain = one issue as you that way can keep the threat clean, concise and relevant for that one domain

Could you check one more time?

It is still listed here Phishing-Database/phishing@932c3ca, I can't do more about it, and yet I still see you in the db,,,

sd mobilephotokiosk.app
https://mobilephotokiosk.app:443/view/1337

@funilrys Huston we have Apolla 13 sized issues here

Noted - just created another one for mobilephotokiosk.com

@funilrys and @spirillen I believe your hands are full of work but we need a little help here ;) It seems that because you and gridinsoft blacklisted us (still visible at VirusTotal too) we have a really big problem in Poland with one of the main mobile operator which is called Orange...and as a result we have thousands of angry customers on our backs :D I know I know - not your problem really but aprreciate any help.

Edyta Dziubek

@spirillen
Copy link
Contributor

Hi @idformats

Thank you for mentioning me, but this matter is now beyond my control. I do not have access to their infrastructure, and it has never been in their interests. My only capability is to merge on https://github.com/Phishing-Database/Phishing.

@idformats
Copy link
Author

Hi @funilrys any news about the bug? Why are we still listed on https://github.com/Phishing-Database/Phishing?

Edyta

@spirillen spirillen assigned funilrys and unassigned spirillen and g0d33p3rsec Feb 6, 2025
@spirillen spirillen moved this from 🏗 In progress to 🚫 Blocked / Waiting in Phishing Database Backlog Feb 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
Status: 🚫 Blocked / Waiting
Development

No branches or pull requests

7 participants