Jump to content

False Positive Trojan Risk


Recommended Posts

Earlier today a number of our customers using Malwarebytes began reporting problems accessing our site.  I've included a screenshot below.  I think our domain (kickfin.com) or a subdomain of it (apiv2.kickfin.com) is being treated as a trojan risk.  I believe this is a false positive.  We run daily scans using tenable and everything seems clean.  Can you remove this or tell us why you are flagging this as a trojan risk?


Thank you for your assistance.

Screenshot 2024-08-25 at 4.55.33 PM.png

Link to post
Share on other sites

  • Staff

Hi, mikesyahoo,

Your website has been identified as part of a malicious Gootloader campaign. Could you please check your server logs for any connections or requests from suspicious IP addresses or unusual user agents (e.g., 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36')? If nothing suspicious is found, we can proceed with removing the block.

Link to post
Share on other sites

Thanks for getting back to us.  We've reviewed this on our side checking all of the various platforms that make use of that domain.  We don't see any signs that the platforms were compromised.  We also ran security scans with several different tools and all appear clean.  We are confident that the systems are secure and would request that you remove the block.  Thanks!

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.