I am part of the IT security team at GLWA that owns the URL "itservicedesk.glwater.org". According to your site, Avira has classified this URL as a source of phishing, please see here:
This URL (itservicedesk.glwater.org) is an alias (DNS CNAME) to glwa.cherwellondemand.com:
> dig itservicedesk.glwater.org. @8.8.8.8
; <<>> DiG 9.9.7 <<>> itservicedesk.glwater.org. @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 22846
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;itservicedesk.glwater.org. IN A
;; ANSWER SECTION:
itservicedesk.glwater.org. 300 IN CNAME glwa.cherwellondemand.com.
glwa.cherwellondemand.com. 300 IN A 162.159.138.37
glwa.cherwellondemand.com. 300 IN A 162.159.137.37
;; Query time: 41 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Wed Jul 13 14:24:44 Eastern Daylight Time 2022
;; MSG SIZE rcvd: 125
We use Cherwell's IT Service Management SaaS solution:
I note that glwa.cherwellondemand.com is clean according to your database/Virus Total, please see here:
The content on these sites is identical - both are hosted by Cloudflare using their Web Application Firewall service. itservicedesk.glwater.org is merely an alias so our users see this under a GLWA domain as opposed to a 3rd party domain. Could you please let me know how can I address any issues and get our URL removed as a phishing site? If you have any security issues with itservicedesk.glwater.org could you please let me know and I will take your concerns back to Cherwell/Ivanti and Cloudflare and make sure they are addressed.
Please note that I've already tried the following:
* Submit suspicious URL, suspected false positive - tried multiple times, no acknowledgement or effect so far (it's been several days)
* Contact Avira support - Home support - need a licensed product, so can't do; OEM support - can't get it to work (can't get form to submit)
* Call them via contact us page, (800) 403-5207 is always busy when I call
* OEM Interest form - so far no response
Thank you for your time,
--Jim
Kommentare
0 Kommentare