Skip to content

False Positive | go.skimlinks.com #969

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
obyg11770 opened this issue Dec 24, 2024 · 25 comments
Closed

False Positive | go.skimlinks.com #969

obyg11770 opened this issue Dec 24, 2024 · 25 comments
Assignees
Labels
false positive Should not be listed question Further information is requested

Comments

@obyg11770
Copy link

What are the subjects of the false-positive (domains, URLs, or IPs)?

https://go.skimresources.com/
go.skimresources.com

Why do you believe this is a false-positive?

I believe this is a false-positive because this is a legitimate advertising network that is used by thousands of websites to drive
$6m+ in sales daily across 48,500 merchants worldwide

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

I discovered this false-positive by...

Have you requested a review from other sources?

I have requested a review from...
virus total but they sent me to you

Do you have a screenshot?

Screenshot
![VirusTotal-URL-12-19-2024_09_56_AM](https://github.com/user-attachments/assets/326b1254-0f36-4bf8-bb43-1cde230862be) ![VirusTotal-URL-12-19-2024_09_56_AM](https://github.com/user-attachments/assets/947f9cb0-2e28-441d-b997-91c0514de505)

Additional Information or Context

this is the second time i have reached out to you with no response.

@spirillen
Copy link
Contributor

spirillen commented Dec 25, 2024

@funilrys @mitchellkrogza I'm missing the power to edit OP msg. In this case I would like to add the ``` to the urls + fixing the image line

@obyg11770

I can see there are lots of spookier destination links in the list, and as my VM are not turned on, I'm not the one checking any of these out.

Leaving for other to test and judge

wget -qO- "https://phish.co.za/latest/ALL-phishing-links.lst" | grep -i '\.skimresources\.com'
http://hsn.app.link/3p?$3p=e_et&$original_url=https://go.skimresources.com/?id=129857X1600501&url=https://p.dtns.me/t/61f00be30628bf732c052b1c?r=https://secure.adnxs.com/seg?redir=http://amorlowzba36.haztedigital.cl/ct/new/css/?email=3mail@b.c
https://go.skimresources.com/?id=126006X1587360&xs=1&isjs=1&url=https://furnimart.in/BT329685/dGl0bGV1bml0MUBjdHQuY29t
https://go.skimresources.com/?id=126006X1587360&xs=1&isjs=1&url=https://furnimart.in/BT329685/dGl0bGV1bml0MUBjdHQuY29t&xguid=01FF0J812A714ZCD82XKBYR97N&persistence=1&checksum=ee353b273cd133198aec87cc3ba4f45c985039243cec1770acdac2d39b8a3a7a
https://go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fmeadow-tiny-month.glitch.me/56bh7c4e.html
https://go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fnewworldenclosures.com/wp-includes/js/Wellsv2
https://go.skimresources.com/?id=129857X1600601&url=https://bafkreig2ox6scs3dco5umljsr6seap2bj7jcwsw7zxavxxvrczordwajfu.ipfs.dweb.link
https://go.skimresources.com/?id=209867X1689872&&url=https://s.free.fr/4TFQugKa
https://hsn.app.link/3p?$3p=e_et&$original_url=https://go.skimresources.com/?id=129857X1600501&url=https://p.dtns.me/t/61f00be30628bf732c052b1c?r=https://secure.adnxs.com/seg?redir=http://amorlowzba36.haztedigital.cl/ct/new/css/?email=3mail@b.c
https://www.skimresources.com/?id=92X363&xcust=trdpro_us_1541938487208509200&xs=1&url=https://lovenestfamily.org/yiivkfxc/webmail-RD127/index.html

@g0d33p3rsec
Copy link

g0d33p3rsec commented Dec 25, 2024

https://go.skimresources.com/?id=126006X1587360&xs=1&isjs=1&url=https://furnimart.in/BT329685/dGl0bGV1bml0MUBjdHQuY29t

oddly, redirects to a safe browsing lookup
https://app.any.run/tasks/ded1b21a-f0d1-4a3b-9163-400d2faf4717

https://go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fnewworldenclosures.com/wp-includes/js/Wellsv2

another safe browsing lookup
https://app.any.run/tasks/23425e7c-ffae-4881-8c7e-194483773695

https://go.skimresources.com/?id=209867X1689872&&url=https://s.free.fr/4TFQugKa

safe browsing lookup
https://app.any.run/tasks/b3da24c1-655b-43a8-a605-3c0822f1b084

https://hsn.app.link/3p?$3p=e_et&$original_url=https://go.skimresources.com/?id=129857X1600501&url=https://p.dtns.me/t/61f00be30628bf732c052b1c?r=https://secure.adnxs.com/seg?redir=http://amorlowzba36.haztedigital.cl/ct/new/css/?email=<REDACTED>

redirects to hsn.com
https://app.any.run/tasks/6e4e1244-67cf-4a12-887f-4055cb2fa790

the other URIs are returning 404s and 410s

@g0d33p3rsec
Copy link

g0d33p3rsec commented Dec 27, 2024

I see multiple instances of your service redirecting to malicious content on the free host jimdosite.com, which then redirects to https://www.primechoicefinance.com.au/dykjj.php?.... The final target appears to have been removed as now it just returns a wordpress placeholder suggesting a site that had been previously compromised.

https://go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fys-law-firm.jimdosite.com -> https://ys-law-firm.jimdosite.com/
https://urlscan.io/result/acd3f99a-e5f7-401a-a522-226c846e99c5/
acd3f99a-e5f7-401a-a522-226c846e99c5

https://go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fnanua-and-ioffe-lawyers.jimdosite.com -> https://nanua-and-ioffe-lawyers.jimdosite.com/
https://urlscan.io/result/703553f4-f084-4323-8c32-30dc71d8db45/
703553f4-f084-4323-8c32-30dc71d8db45

https://go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fark-fire-protection.jimdosite.com ->https://ark-fire-protection.jimdosite.com/
https://urlscan.io/result/2636ea2f-3c26-497b-8077-96f2310b3a82/
2636ea2f-3c26-497b-8077-96f2310b3a82

https://go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fkinver-business.jimdosite.com -> https://kinver-business.jimdosite.com/
https://urlscan.io/result/3c02ad65-ddd8-4f47-822c-281bb84e7c96/#summary
3c02ad65-ddd8-4f47-822c-281bb84e7c96

https://go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fabaco-international-loss-adjusters.jimdosite.com -> https://abaco-international-loss-adjusters.jimdosite.com/
https://urlscan.io/result/b3072e8c-0b51-45df-935d-269494ac466b/
b3072e8c-0b51-45df-935d-269494ac466b

http://go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fswiss-hospitality-and-partners.jimdosite.com -> https://swiss-hospitality-and-partners.jimdosite.com/
https://urlscan.io/result/d1cee180-6d66-4101-bc57-90ea09faa7ff/
d1cee180-6d66-4101-bc57-90ea09faa7ff

https://go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fjbs-expedite-ltd.jimdosite.com -> https://jbs-expedite-ltd.jimdosite.com/
https://urlscan.io/result/619e43c0-c071-49ca-b7ec-b2d979fb9523/#summary
619e43c0-c071-49ca-b7ec-b2d979fb9523

image
image
image

https://urlscan.io/result/f2ce8f71-5325-4098-9e88-20d7508b2b8a/
f2ce8f71-5325-4098-9e88-20d7508b2b8a

scan of https://www.primechoicefinance.com.au/dykjj.php?... from November 2, 2024
https://urlscan.io/result/2f4afe26-bd63-4598-9132-22fdb424ec7e/
2f4afe26-bd63-4598-9132-22fdb424ec7e

@g0d33p3rsec
Copy link

I believe this is a false-positive because this is a legitimate advertising network that is used by thousands of websites to drive
$6m+ in sales daily across 48,500 merchants worldwide

true positives confirmed, the ad-tech pitch does nothing to mitigate the threats

@g0d33p3rsec g0d33p3rsec added the false positive Should not be listed label Dec 28, 2024
@spirillen spirillen moved this from 🆕 New to 🚫 Blocked / Waiting in Phishing Database Backlog Jan 4, 2025
@spirillen
Copy link
Contributor

Moved this issue to the blocked projects list, as it seems stalled from OP.

@g0d33p3rsec g0d33p3rsec removed the false positive Should not be listed label Jan 4, 2025
@g0d33p3rsec g0d33p3rsec added the question Further information is requested label Jan 4, 2025
@g0d33p3rsec
Copy link

@obyg11770 please see also the question @funilrys recently asked in your duplicate thread #944 (comment)

@g0d33p3rsec
Copy link

@obyg11770 I see that you replied to the other thread via email so tagging you again to this thread so that we can limit your issue to a single thread instead of scattering the information throughout the repo.

@spirillen
Copy link
Contributor

I suggest we add these lines to a "onetime" whitelist, especially because the reporter @obyg11770 isn't related to the domain.

https: //go.skimresources.com/?id=126006X1587360&xs=1&isjs=1&url=https://furnimart.in/BT329685/dGl0bGV1bml0MUBjdHQuY29t
https: //go.skimresources.com/?id=126006X1587360&xs=1&isjs=1&url=https://furnimart.in/BT329685/dGl0bGV1bml0MUBjdHQuY29t&xguid=01FF0J812A714ZCD82XKBYR97N&persistence=1&checksum=ee353b273cd133198aec87cc3ba4f45c985039243cec1770acdac2d39b8a3a7a
https: //go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fmeadow-tiny-month.glitch.me/56bh7c4e.html
https: //go.skimresources.com/?id=129857X1600501&url=https%3A%2F%2Fnewworldenclosures.com/wp-includes/js/Wellsv2
https: //go.skimresources.com/?id=129857X1600601&url=https://bafkreig2ox6scs3dco5umljsr6seap2bj7jcwsw7zxavxxvrczordwajfu.ipfs.dweb.link
https: //go.skimresources.com/?id=209867X1689872&&url=https://s.free.fr/4TFQugKa
https: //www.skimresources.com/?id=92X363&xcust=trdpro_us_1541938487208509200&xs=1&url=https://lovenestfamily.org/yiivkfxc/webmail-RD127/index.html

@Phishing-Database/contributors Should we make a list for removal of records, but not permanent whitelist?

@g0d33p3rsec
Copy link

@Phishing-Database/contributors Should we make a list for removal of records, but not permanent whitelist?

I think that could be useful and generally safer than a whitelist for domains that may change hands in the future. A risk with the whitelist approach is that it is susceptible to domain hijacking if the owner moves on and allows their control of the domain to expire.

@obyg11770
Copy link
Author

obyg11770 commented Jan 13, 2025 via email

@spirillen
Copy link
Contributor

Please see #988 (comment) by admin

@obyg11770
Copy link
Author

obyg11770 commented Jan 14, 2025 via email

@spirillen
Copy link
Contributor

I do not understand these comments as I am not a developer.

AFAIK, we are whitelisting URL shortener already. @megaworldai if you can be listed in @PeterDaveHello's list https://github.com/PeterDaveHello/url-shorteners/ , it will be removed automatically from our project.

Are go.skimlinks.com not used for redirecting traffic and collecting PII data?

@obyg11770
Copy link
Author

obyg11770 commented Jan 14, 2025 via email

@g0d33p3rsec
Copy link

I am concerned about go.skimlinks.com not @megaworldai. this is the original tickte #944 skimlinks does not collect PII. PLease read the ticket linked above. go.skimlinks is an advertising network redirect link that is used for tracking sales conversions and managing payouts to publishers across. the world.

since you also seem to struggle with basic reading comprehension, the relevant part of the referenced comment is:

if you can be listed in @PeterDaveHello's list https://github.com/PeterDaveHello/url-shorteners/ , it will be removed automatically from our project.

TL;DR, you need to address the root cause and have the site delisted from the upstream source feeding into our database

@obyg11770
Copy link
Author

obyg11770 commented Jan 25, 2025 via email

@g0d33p3rsec g0d33p3rsec removed their assignment Jan 26, 2025
@spirillen
Copy link
Contributor

@obyg11770

I understand your frustration. To resolve this, please open an issue in the @PeterDaveHello url_shortner repository and request to have your domain added to the project. Thank you for your patience. https://github.com/PeterDaveHello/url-shorteners/issues/new?template=Blank+issue&title=go.skimresources.com

@obyg11770
Copy link
Author

obyg11770 commented Jan 29, 2025 via email

@spirillen
Copy link
Contributor

@PeterDaveHello ?? can you review this one, to see if you can solve it?

@obyg11770
Copy link
Author

obyg11770 commented Feb 12, 2025 via email

@spirillen
Copy link
Contributor

English

Have you opened an issue in the @PeterDaveHello Project as we asked you to?

Spanish

¿Has abierto un problema en el proyecto @PeterDaveHello como te pedimos?

French

Avez-vous ouvert un problème dans le projet @PeterDaveHello comme nous vous l'avons demandé?

German

Hast du ein Problem im @PeterDaveHello-Projekt eröffnet, wie wir dich gebeten haben?

Italian

Hai aperto un problema nel progetto @PeterDaveHello come ti abbiamo chiesto?

Chinese (Simplified)

你是否按照我们的要求在@PeterDaveHello项目中打开了一个问题?

Danish

Har du åbnet et issue i @PeterDaveHello projekt, som vi bad dig om?

@PeterDaveHello
Copy link
Member

If you need anything, please open issues or submit pull requests at the right place: https://github.com/PeterDaveHello/url-shorteners. I'm currently overwhelmed by the mentioning notifications, and they are not helpful.

@obyg11770
Copy link
Author

obyg11770 commented Feb 13, 2025 via email

@spirillen
Copy link
Contributor

@PeterDaveHello are you maintaining the url shortner lists actively??

PeterDaveHello/url-shorteners#124

Image

@phishing-database-bot
Copy link
Member

Closing.

Domain(s) or IP(s) not found in the Phishing.Database project: go.skimresources.com, go.skimlinks.com.

-- We appreciate your help in refining this. Please let us know if anything seems incorrect.

@github-project-automation github-project-automation bot moved this from 🚫 Blocked / Waiting to ✅ Done in Phishing Database Backlog May 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
false positive Should not be listed question Further information is requested
Projects
Status: ✅ Done
Development

No branches or pull requests

7 participants