AlexWoods Posted July 7, 2022 ID:1523879 Share Posted July 7, 2022 Hey Malwarebytes team! I work for a website hosting company, Makeswift. We had a user create malicious content using our platform — they uploaded malicious HTML files. As soon as we discovered them, we banned them and even blocked all HTML file uploads. We did an audit as well on all existing HTML files, and deleted any we deemed malicious. Because of this, Malwarebytes blacklisted our domain for files, s.mkswft.com. That was appealed, and we showed the issue isn't present anymore. Last week we were temporarily blacklisted (I appealed again, and it was accepted), and it wasn't clear why. Each time we're blacklisted it affects all of our customers and creates a serious threat to our business. So the question is — what can we do to prevent our domain from getting blacklisted? Is there a whitelist we can apply for as a hosting company? (If individual URLs are blacklisted, that's totally fine. But our whole domain being blacklisted is not good.) Preventing all phishing activity on our platform is a near impossibility — we take it down as soon as we find it, but scammers are creative. We just want the .001% of bad users to not be able to affect the 99.99% who are using our platform for their businesses. Link to post Share on other sites More sharing options...
Staff TeMerc Posted July 7, 2022 Staff ID:1523883 Share Posted July 7, 2022 16 minutes ago, AlexWoods said: Hey Malwarebytes team! I work for a website hosting company, Makeswift. We had a user create malicious content using our platform — they uploaded malicious HTML files. As soon as we discovered them, we banned them and even blocked all HTML file uploads. We did an audit as well on all existing HTML files, and deleted any we deemed malicious. Because of this, Malwarebytes blacklisted our domain for files, s.mkswft.com. That was appealed, and we showed the issue isn't present anymore. Last week we were temporarily blacklisted (I appealed again, and it was accepted), and it wasn't clear why. Each time we're blacklisted it affects all of our customers and creates a serious threat to our business. So the question is — what can we do to prevent our domain from getting blacklisted? Is there a whitelist we can apply for as a hosting company? (If individual URLs are blacklisted, that's totally fine. But our whole domain being blacklisted is not good.) Preventing all phishing activity on our platform is a near impossibility — we take it down as soon as we find it, but scammers are creative. We just want the .001% of bad users to not be able to affect the 99.99% who are using our platform for their businesses. Hello- Your domain is not currently blocked. We block when and if we find evidence of a threat and disable the block when the threats are removed. Link to post Share on other sites More sharing options...
AlexWoods Posted August 1, 2022 Author ID:1527105 Share Posted August 1, 2022 Hey Malwarebytes team, We are being flagged again. Is there some phishing site that you've identified? If not, can you please unblock s.mkswft.com? This is the 3rd or 4th time this has happened. Link to post Share on other sites More sharing options...
Porthos Posted August 1, 2022 ID:1527120 Share Posted August 1, 2022 1 hour ago, AlexWoods said: We are being flagged again. Do you have a log or screenshot of this block? Link to post Share on other sites More sharing options...
AlexWoods Posted August 1, 2022 Author ID:1527124 Share Posted August 1, 2022 Here is one of our customer's sites. It's flagging the favicon Link to post Share on other sites More sharing options...
AlexWoods Posted August 1, 2022 Author ID:1527126 Share Posted August 1, 2022 Our home page is perhaps an even better example — https://www.makeswift.com/ Link to post Share on other sites More sharing options...
Solution gonzo Posted August 1, 2022 Solution ID:1527144 Share Posted August 1, 2022 I have added mkswft.com to two different whitelists to prevent this from happening again in the future. Please allow 15-30 minutes for changes to take effect. 1 Link to post Share on other sites More sharing options...
AlexWoods Posted August 1, 2022 Author ID:1527183 Share Posted August 1, 2022 Thank you! I am still seeing the flag on our home page — would you mind adding s.mkswft.com specifically? Link to post Share on other sites More sharing options...
gonzo Posted August 1, 2022 ID:1527197 Share Posted August 1, 2022 Please dump your browser cache. I am NOT seeing any evidence of a continued block, using either of the sites you have previously referenced. Link to post Share on other sites More sharing options...
AlexWoods Posted August 2, 2022 Author ID:1527238 Share Posted August 2, 2022 Ah, I think I know what it is — on some of our sites, I've explicitly clicked "Allow" in the browser extension, and it remembers that. When I went to sites where I haven't done that, I don't see anything. Thank you so much! Link to post Share on other sites More sharing options...
Recommended Posts