CriticalPathSecurity/Zeek-Intelligence-Feeds

False positive

Closed this issue · 5 comments

We have identified a false positive in this threat feed:

http://4-11-1.uniswap-uncensored.eth.limo/ Intel::URL OPENPHISH F Phishing-URLS
@Patrick-Kelley

Please kindly remove it per the evidence below:


Our service, eth.limo is a gateway proxy for accessing user-generated content from the Ethereum Name Service. We do not directly host or sponsor any of the content that can be retrieved via our gateway.

We have reviewed 4-11-1.uniswap-uncensored.eth.limo (ENS domain) and determined that it does not qualify as phishing. To our knowledge this user created site is a simple fork of Uniswap, as evidenced by this tweet: https://twitter.com/MicahZoltu/status/1560653264554958848

We believe this is an automated system incorrectly filing abuse reports. Please see the additional information below that might be useful in handling this in the future:

Uniswap has many open source repositories containing front end code as well as EVM contract code. Some power users fork these repositories and deploy custom front-ends that either add or remove features contained within the original Uniswap front end code. In the case of this abuse report, a well known crypto developer on Twitter announced his intention to develop and deploy a Uniswap compatible fork that removed some controversial data mining features:

Uniswap repos: https://github.com/Uniswap

Forked repo: https://github.com/MicahZoltu/uniswap-frontend

Announcement and explanations of the Uniswap fork: https://twitter.com/MicahZoltu/status/1560652867811561473

https://twitter.com/MicahZoltu/status/1560653264554958848

Please let us know if we can provide you with any additional information.

I'm more than willing to remove the entry, but it was added by the upstream provider "OPENPHISH".

Having it removed from OpenPhish would remove it from all feeds, including ours.

contact@openphish.com is their contact address.

I'm more than willing to remove the entry, but it was added by the upstream provider "OPENPHISH".

Having it removed from OpenPhish would remove it from all feeds, including ours.

contact@openphish.com is their contact address.

Thank you! I'll let them know.

Outstanding!

@Patrick-Kelley we're all good now. OpenPhish removed our entry!