False Positive 'Phishing' on Commercial Website

Hello,
Our commercial end user package tracking website has been flagged as Phishing - https://consumer.onsend.com

Not sure why, we don’t even collect any information - other than your preferred delivery date, and show the progress of tracked packages.

Threat: URL: Phishing

URL example:
https://consumer.onsend.com/confirmation/NL47313?sastoken=[BASE64 Encoded Token]

This is our main website here…

https://www.onsend.com

consumer.onsend.com” is for end-user package tracking and confirmation.

The error was reported on Avast Security for Mac Version 15.2 (Free)

Reporting a possible Malicious sample File or Website - https://www.avast.com/report-malicious-file.php.

Hi,
Thanks.
We’ve done that (reporting a False Positive) a few hours ago and had no response as yet.

You should get a reply within 48 hours.

I gave you the wrong URL (just after 1am local), so I don’t know if it would be handled as a possible FP (but it could well be as it goes to the virus labs also).

This is what I should have given you first off.
Reporting a Possible False Positive File or Website - https://www.avast.com/false-positive-file-form.php.
You should get a response in a day or two.

Thank you,

We submitted a ‘false positive’ phishing report via the url https://www.avast.com/false-positive-file-form.php and got a reply within about 12 hours.

You’re welcome, a positive one I hope :slight_smile: