Jump to content


Photo

Spyware.Exploit.BRTS

Spyware.Exploit.BRTS

  • Please log in to reply
140 replies to this topic

#1 jbrenters

jbrenters
  • Members
  • 4 posts
  • LocationThe Netherlands

Posted 25 November 2014 - 04:04 AM

Hi,

 

Our Barracuda Web Filter is blocking Spyware.Exploit.BRTS.docuonline.nl. I see several posts about Spyware.Exploit.BRTS. Is this false positive resolved?

 

Grtz,

Joost Brenters

CNV



#2 Josh Carter

Josh Carter
  • Members
  • 1 posts

Posted 03 December 2014 - 12:07 PM

I'm seeing this same issue for our domain as well: spyware.exploit.brts.teefury.com

 

Please fix this asap.



#3 Lily Nguyen

Lily Nguyen
  • Members
  • 266 posts
  • LocationCampbell, CA

Posted 04 December 2014 - 10:51 AM

Domain docuonline.nl was tagged due to being seen in association with phishing emails in November. It has since been cleaned. The domain has been cleared. Thank you.

Domain teefury.com was a false positive and has been cleared. Thank you.



#4 Juliano Bdair

Juliano Bdair
  • Members
  • 1 posts

Posted 31 December 2014 - 12:48 PM

Hello Barracuda Support,

 

Our site xlvape.com is experiencing the same issue with spyware.exploit.brts.xlvape.com 

 

Can you please review it and let us know if this is also a false positive?

 

Thank you much and we wish you a Happy New Year!



#5 Lily Nguyen

Lily Nguyen
  • Members
  • 266 posts
  • LocationCampbell, CA

Posted 31 December 2014 - 12:50 PM

Domain xlvape.com was a false positive and has been cleared. Please allow 12-24 hours for the change to propagate throughout our system. Thank you for your patience and have a happy new year as well =)



#6 Mike

Mike
  • Members
  • 2 posts

Posted 05 January 2015 - 10:03 AM

I'm receiving the same thing with www.atwebpages.com. Is this flagging it appropriately, or is it a false-positive detection?



#7 Lily Nguyen

Lily Nguyen
  • Members
  • 266 posts
  • LocationCampbell, CA

Posted 05 January 2015 - 10:06 AM

Domain atwebpages.com was seen in association with phishing emails back in November. It seems the domain has been cleaned. I have removed the domain from our block list. Please allow 12-24 hours for the change to propagate throughout our system. Thank you for your patience.



#8 Mike

Mike
  • Members
  • 2 posts

Posted 05 January 2015 - 10:26 AM

Thank you!



#9 Jay Peery

Jay Peery
  • Members
  • 3 posts

Posted 15 January 2015 - 03:55 PM

Please check Spyware.Exploit.BRTS.eventstepandrepeat.com

It looks like a false positive.



#10 Lily Nguyen

Lily Nguyen
  • Members
  • 266 posts
  • LocationCampbell, CA

Posted 15 January 2015 - 03:58 PM

Domain eventstepandrepeat.com was a false positive and has been cleared. Please allow 12-24 hours for the change to propagate throughout our system. Thank you for your patience.



#11 Corey Stone

Corey Stone
  • Members
  • 1 posts

Posted 16 January 2015 - 03:41 PM

Please check Spyware.Exploit.BRTS.perennialparkproducts.com . I think this may be a false positive.

 

 



#12 Lily Nguyen

Lily Nguyen
  • Members
  • 266 posts
  • LocationCampbell, CA

Posted 16 January 2015 - 03:46 PM

Domain perennialparkproducts.com was a false positive and has been cleared. Please allow 12-24 hours for the change to propagate throughout our system. Thank you for your patience.



#13 David Edelman

David Edelman
  • Members
  • 1 posts

Posted 19 January 2015 - 04:25 PM

Can you please check www.flasac.org ?  It is blocked due to Spyware.Exploit.BRTS.flasac.org



#14 Lily Nguyen

Lily Nguyen
  • Members
  • 266 posts
  • LocationCampbell, CA

Posted 19 January 2015 - 04:26 PM

Domain flasac.org has been cleared. Please allow 12-24 hours for the change to propagate throughout our system. Thank you for your patience.



#15 Josh Valmas

Josh Valmas
  • Members
  • 1 posts

Posted 28 January 2015 - 10:41 AM

Hello,

 

Can you please check Spyware.Exploit.BRTS.mediaconnect360.com?  It is currently blocked.

 

Thanks



#16 Lily Nguyen

Lily Nguyen
  • Members
  • 266 posts
  • LocationCampbell, CA

Posted 28 January 2015 - 10:43 AM

Domain mediaconnect360.com is currently being seen in association with phishing viruses. Please email me at intent@barracuda.com for further information. Thank you.



#17 Michael Leary

Michael Leary
  • Members
  • 1 posts

Posted 02 February 2015 - 01:16 PM

I'm having issues with invoice2go.com (Spyware.Exploit.BRTS.2go.com) - http://account.2go.com



#18 Lily Nguyen

Lily Nguyen
  • Members
  • 266 posts
  • LocationCampbell, CA

Posted 02 February 2015 - 01:21 PM

Domain 2go.com has been cleared. Please allow 2-24 hours for the change to propagate throughout our system. Thank you for your patience.



#19 3formit

3formit
  • Members
  • 1 posts

Posted 03 February 2015 - 05:20 PM

We are getting a Spyware.Exploit.BRTS on Spyware.Exploit.BRTS.lolstatic.com and we have contacted Riot games the owners of this domain and they said they don't know why this would be blocked.  This domain has a script that is used for logging into their servers.  Is this a false positive?  Should it really be blocked?

 

thanks!



#20 Lily Nguyen

Lily Nguyen
  • Members
  • 266 posts
  • LocationCampbell, CA

Posted 04 February 2015 - 09:34 AM

Domain lolstatic.com was a false positive and has been cleared. Please allow 12-24 hours for the change to propagate throughout our system. Thank you for your patience.







Also tagged with one or more of these keywords: Spyware.Exploit.BRTS