cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2607
Views
0
Helpful
5
Replies

Web Reputation Flagged Untrusted/Poor by only Talos

thom.chris
Level 1
Level 1

My company's website was suddenly flagged by Talos as a "Malware Site". I submitted a ticket yesterday to have it resolved and it was but I was provided no information other than "Resolved".  My question and concern is how was my website flagged as malware or who specifically submitted the complaint? Can anyone submit a website as untrusted and Talos just automatically flags the website without verifying? I looked up my domain on VirusTotal and other similar sites and it came back as clean/good at the same time Talos had mine flagged.

Some transparency would be nice.

5 Replies 5

Udupi Krishna.
Cisco Employee
Cisco Employee

There's definitely thorough verification process followed before flagging a website. This could based on a complaint, but to gather additional information on why it was flagged in the 1st place, TAC would be a good first step.

What is the verification process? No one has explained anything to me. I do not have the ability to submit a TAC case. This has been the closest attempt at someone talking to me about what actually happened.

My company is a cyber security firm, there is no reason there would be malware on our site. I would like to see the info on who submitted the complaint and the evidence you allegedly gathered. It's been weeks and nothing. 

I don't have the capability to submit a tac case. Can you do that for me? I
would like to find the root cause of this issue.

Thanks,
Crud

I cannot guarantee it, but provide me the URL/domain and i will try to look around

Libin Varghese
Cisco Employee
Cisco Employee

Talos cannot disclose details on the verification process undertaken and where submissions came from since those are data internal for them to use and protect. So if any information is to be shared would be a decision taken by them.

 

For customers with a support contract, TAC would be the team who can co-ordinate with Talos to get any information possible for such false positive instances from Talos.

Without a support contract you would need to rely on information made available through talosintelligence.com dispute cases.

 

Regards,

Libin