How competitors can easily block your website

Recently, we encountered a situation where several antivirus programs (Kaspersky, Quttera, McAfee, Norton Safe Web, Bitdefender, and a few lesser-known ones) began blocking our website. Investigating the situation led me to realize that getting on a blacklist is quite easy; it only takes a few complaints (even without justification). I will describe the problem in more detail later.

The issue is quite serious, as almost every user now has an antivirus or firewall installed. A website being blocked by a major antivirus like Kaspersky can make it inaccessible to a large number of users. I would like to draw the community's attention to this problem, as it opens up vast opportunities for unscrupulous methods of competition.
How competitors can easily block your website

I will not provide a link to the website or mention the company so that it is not perceived as some form of PR. I will only state that the website operates legally, the company is commercially registered, and all data is available on the site.

Recently, we received complaints from customers that our website is being blocked by Kaspersky antivirus as a phishing site. Multiple checks on our end revealed no issues on the website. I submitted a request through the form on Kaspersky's website regarding the false positive of the antivirus. As a result, we received the following response:

We have checked the link you provided.
The information from the link poses a risk of user data loss; the false positive was not confirmed.

There was no confirmation that the site poses a threat. In further inquiries, we received the following response:

We have checked the link you provided.
This domain was added to the database due to user complaints. The link will be excluded from phishing databases, but monitoring will remain in place in case of repeat complaints.

It becomes clear that a sufficient reason for blocking is merely the existence of any complaints. Presumably, the site is blocked if there are more than a certain number of complaints, and no confirmation of the complaint is required.

In our case, malicious actors submitted a series of complaints. To our data center, several antivirus programs, and services like phishtank. The complaints on phishtank only included the link to the site and indicated that the site was phishing. And that was it; no confirmations were provided.

It is possible to block unwanted sites simply by spamming complaints. There might even be services that provide such options. If there aren't, they will clearly emerge soon, considering how easy it is to blacklist a site in the databases of some antivirus programs.

I would like to hear comments from Kaspersky representatives. Also, I would like to hear from those who have faced this problem themselves and how quickly it was resolved. Perhaps someone can recommend legal methods of influence in such situations. For us, this situation has led to reputational and financial losses, not to mention the time wasted on resolving the issue.

I would like to draw as much attention to this situation as possible, as any site is at risk.

Addition.
In the comments, a link was shared to an interesting post by HerrDirektor. habr.com/ru/post/440240/#comment_19826422 on this issue. I will quote him.

I'll tell you more — do you want to create problems for almost any site in just 10 minutes (except for large, fat, and very well-known ones)?
Welcome to phishtank.
We register 8-10 accounts (only an email is needed for confirmation), choose a site we like, and add it to the phishing database from one account (to complicate the owner’s life, you can stuff the submission form with some email advertising gay porn with dwarfs).
With the remaining accounts, we vote for phishing until we get a message saying, "This is a phishing site!"
Done. We sit and wait. Although to solidify the success, you can add both http:// and https://, with a slash at the end and without, or with two slashes. If you have plenty of time, you can also add links on the site. Why? Here’s why:

In 6-12 hours, Avast pulls the data from there. Within 24-48 hours, the data spreads to various "antivirus types" — Comodo, Bit Defender, Clean MX, CRDF, CyRadar… From where the darn VirusTotal sucks the data later.
Of course, NO ONE verifies the accuracy of the data; everyone is deeply indifferent.

As a result, most "antivirus" extensions for browsers, free antivirus programs, and other software start flagging the specified site in various ways, from red warning banners to full pages claiming that the site is extremely dangerous and visiting it is akin to death.

To clear out these Augean stables, each of these 'antivirus' programs requires you to contact support. For EVERY link! Avast responds fairly quickly, while the others simply archive the known entity.
However, even if the stars align and you manage to scrub your site from antivirus databases, the 'mega-resource' virustotal couldn't care less. Not listed in the phishtank database? No worries, you were at some point, so we will show what we have. Not in Bitdefender? No problem, we will still indicate you were.
Consequently, any software or service relying on virustotal will forever show that the site is in poor standing. You can struggle with this pathetic resource for ages, and maybe you'll get lucky and get out. But then again, you might not.

* Among those blocking the site is even the Fortinet provider. We still haven't managed to remove the site from several phishing site lists.
* This is my first post on Habrahabr. Unfortunately, I was just a reader before, but the current situation motivated me to write a post.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster