Jump to content

concierge.totalwine.com false positive


ebrandt

Recommended Posts

Hi,

https://concierge.totalwine.com

 is being blocked by malwarebytes with a warning about malware.

I am helping host the website, so don't have any logs myself for the issue. We don't host any downloads on this site so I am not sure where what would be causing the warning. Any pointers on what the false positive is stemming from would be greatly appreciated.

Thanks
Elliot

Edited by TeMerc
Disabled link
Link to post
Share on other sites

Log for staff.

 

-Website Data-
Category: Malware
Domain: concierge.totalwine.com
IP Address: 18.160.156.61
Port: 443
Type: Outbound
File: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe

 

Also, your other domain is also blocked.

 

-Website Data-
Category: RiskWare
Domain: ultracommerce.co
IP Address: 104.196.189.107
Port: 443
Type: Outbound
File: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe

 

 

 

Link to post
Share on other sites

  • Staff
1 hour ago, Porthos said:

Log for staff.

 

-Website Data-
Category: Malware
Domain: concierge.totalwine.com
IP Address: 18.160.156.61
Port: 443
Type: Outbound
File: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe

 

Also, your other domain is also blocked.

 

-Website Data-
Category: RiskWare
Domain: ultracommerce.co
IP Address: 104.196.189.107
Port: 443
Type: Outbound
File: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe

 

 

 

This was the only block I can find on the database and it's appearing to be valid: VirusTotal - Domain - training.ultracommerce.coimage.thumb.png.16678b8fe6d1224995c81d1098c7e94b.png

Link to post
Share on other sites

Hi @TeMerc,

We have gotten in touch with our WordPress hosting provider and cleared out the bad files that were present on the training.ultracommerce.co site. Issues were previously reported on https://sitecheck.sucuri.net/results/https/training.ultracommerce.co but it is now showing up clean.

Moving forward from here, are you able to re-evaluate this URL as well as concierge.totalwine.com?

Additionally, am I correct that concierge.totalwine.com is being blocked because it is CNAMEd to totalwineconcierge.uc-prod.ultracommerce.co, and therefore is "related" to training.ultracommerce.co?

Thanks
Elliot

Link to post
Share on other sites

  • Staff
23 hours ago, ebrandt said:

Hi @TeMerc,

We have gotten in touch with our WordPress hosting provider and cleared out the bad files that were present on the training.ultracommerce.co site. Issues were previously reported on https://sitecheck.sucuri.net/results/https/training.ultracommerce.co but it is now showing up clean.

Moving forward from here, are you able to re-evaluate this URL as well as concierge.totalwine.com?

Additionally, am I correct that concierge.totalwine.com is being blocked because it is CNAMEd to totalwineconcierge.uc-prod.ultracommerce.co, and therefore is "related" to training.ultracommerce.co?

Thanks
Elliot

Hello, thanks for the updated info. We've reviewed the data from the site again and have determined it no longer warrants being blocked so we've disabled the block in our database. 

Removal should be reflected in the next database update going out in a few hours or so.

  • Like 1
Link to post
Share on other sites

  • TeMerc locked this topic
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.