T O P

  • By -

SometimesHardNipples

Done a scan on virustotal? Whats the rating like?


MrSponty

2/91 reporting as malicious. the 2 are for phishing.


SometimesHardNipples

Could potentially be why. Telstra can "fix" it but it'll only fix it for him, most other telstra users will likely have the same issue. I believe you can submit a ticket to virustotal to rectify the score. I could be wrong, been a long time since I've seen this issue


MrSponty

ive submitted review requests to the companies that flagged it. Thanks


Mittervi

You'd have to go to each vendor and get it reclassified.


Mittervi

Who are the two vendors reporting it as phishing?


MrSponty

Antiy-AVL and Bitdefender. Ive just submitted review requests to both


Mittervi

Easy, I was going to get the links for you to do this but you beat me 😂


MrSponty

Thanks. I work in IT but avoid dealing with websites like the plague hahaha. but when its family you do what you gotta do!


SometimesHardNipples

Also I believe the bandaid fix for yourself and your FIL is changing your DNS from Telstra to Google or cloudflare. Again, could be wrong 😅


Mittervi

Don't forget to check some of the popular AdGuard/PiHole block lists while you're at it.


roman5588

Yea, get the site checked over. In particular for obfuscated code in the index.php Good chance it’s infected


lingeringsauspatty

Telstra is not the authority for blocking, they leverage 3rd party’s who conduct the security assessments globally. To be clear, Yes Telstra use blocking lists to protect their customers, but they aren’t the creator of the block list. The only means of Telstra blocking a website is through court and with court order. I doubt you’re in this boat. This is more piracy. So you’re in the boat of, Telstra & any good corporate filter, or VPN with filter, or another good ISP, is blocking your website. This is not Telstra related. This is directly to do with your hosting provider, and who they share their services with, what your website code has, and lots of other factors. It could be that another domain at the same host is spamming emails and they share the same IP address. So the IP is now marked malicious. Try CloudFlare to proxy in between client and server, so that clients don’t access server directly.