Skip to content

False Positive | redherring.sdcoe.net #1110

@RCsandoval

Description

@RCsandoval

What are the subjects of the false-positive (domains, URLs, or IPs)?

Why do you believe this is a false-positive?

Greetings,
The referenced websites are owned by and redirect to redherring.sdcoe.net, which is an authorized simulated phishing awareness platform used to promote cybersecurity awareness among employees. Please review and decategorize them as Malicious.

  • Red Herring landing pages are not indexed by search engines.
  • The app collects only the necessary information such as the target user's email address and name to send simulated phishing emails.
  • Interaction telemetry with the simulated phishing emails is collected and secured against unauthorized access.
  • Text inputted into form fields on landing pages is registered, but no actual data entered is collected or recorded

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

I discovered this false-positive by checking virustotal.com

Have you requested a review from other sources?

I have requested a review from multiple threat databases.

Do you have a screenshot?

N/A

Additional Information or Context

N/A

Metadata

Metadata

Assignees

No one assigned

    Labels

    bot:check-false-positiveInforms our bots that they should check for the possible false-positive.bot:verify-dnsInforms our bots that they should check for the DNS verification.false-positive-reportA False-Positive report that has to be verified.

    Type

    No type

    Projects

    Status

    ✅ Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions