Author Topic: URL:Phishing on ocsps.ssl.com  (Read 147 times)

0 Members and 1 Guest are viewing this topic.

Offline chris...

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3041
URL:Phishing on ocsps.ssl.com
« on: Yesterday at 01:07:18 AM »
hi
I've just had an alert involving certificate authorities oscps.ssl, but I don't know what site I was visiting that triggered the alert.
It seems strange to me, what should I think?
On the other hand, while searching on the net, I came across a similar subject with an alert at about the same time as my alert, but with AVG (same engine as avast).
It's in Turkish, so I'm not sure of my translation.
Here's the link:
hxxps://www.technopat.net/sosyal/konu/avg-phishing-uyarisi-veriyor.3432586/

Could it be a false positive following the latest VPS update "240919-8"?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34053
  • malware fighter
Re: URL:Phishing on ocsps.ssl.com
« Reply #1 on: Yesterday at 11:36:53 PM »
VT does not alert this. The site is hosted on CloudFlare, so probably also been whitelisted.

But consider the site issue on that site mentioned here: https://sitecheck.sucuri.net/results/https/static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015

Our automated scan found an issue on some pages of your website. There is always a possibility of a hack.
So we can state it could be qualified as "suspicious.

Consider this from the VT community: e.g. Joe Sandbox Analysis:

Verdict: SUS
Score: 23/100
Domain: -static.cloudflareinsights.com
Host: 104.16.79.73 (for abuse there, see: https://www.abuseipdb.com/check/104.16.79.73).

HTML Report: https://www.joesandbox.com/analysis/1485878/0/html
PDF Report: https://www.joesandbox.com/analysis/1485878/0/pdf
Executive Report: https://www.joesandbox.com/analysis/1485878/0/executive
Incident Report: https://www.joesandbox.com/analysis/1485878/0/irxml
IOCs: https://www.joesandbox.com/analysis/1485878?idtype=analysisid

polonus (volunteer 3rd-party cold reconnaissance website-security analyst and website error-hunter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!