Jump to content

Possible False Positive


Recommended Posts

Hello,  we have been notified by two Eset users that https://pilotshq.com is being blocked for an alleged spy.banker.lq Trojan.

multiple scans including those from google and Shopify show clean results.  I have additionally ran a scan that was used in the forums for other users.

https://sitecheck.sucuri.net/results/Pilotshq.com

Link to comment
Share on other sites

Additionally, I have downloaded all these files and have zero references to "blob("  or "atob(" in the source code.  If this exists then it is within a third party app that we need to identify.

Link to comment
Share on other sites

  • Administrators

Have you found and removed the malware in the mean time? I'm not getting any detection from ESET now.

Link to comment
Share on other sites

No, please remove the site from any blacklist.  If you would like I can post the results that came from the Shopify help desk.  I have already posted results from the tool you use for scanning.

We recently installed an addon that allows for “make an offer” which is a paid app that charges for successful transactions.  I was thinking maybe it was thier tracking code causing the issue, but if we are clean then 👍

Link to comment
Share on other sites

  • Administrators

The website is not blacklisted. If the detection still occurs, the website is still infected.

From the telemetry it's obvious that the malware was there:

image.png

Now the Google Tag Manager JS is clean:

image.png

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...