X2.c.lencr.org flagged as compromised

Hello,

Our WatchGuard firewall is flagging x2.c.lencr.org as a compromised website.

I tested the host x2.c.lencr.org in virustotal.com and it still shows me that the host is flagged as malicious

Could you please check.

Regards,

8 Likes

Hello @ABIDI, welcome to the Let's Encrypt community. :slightly_smiling_face:

What version of the WatchGuard firewall?
Is it up-to-date?

Also please see lencr.org - Let's Encrypt

4 Likes

Also there is WatchGuard Community WatchGuard Community — WatchGuard Community which may also be helpful.

3 Likes

I've filed this as a false positive with Valkyrie, which is what shows up in VirusTotal.

Do you know if WatchGuard uses that service? If not, we'll need to follow up with them as well. Your screenshot shows it as "Bot Networks", which is likely flagged because some bot checked CRLs from that domain.

12 Likes

Hello @Bruce5051

The alert was generated by WatchGuard's Threat Detection and Response system
Should I ask WatchGuard support to verify?

8 Likes

If you could give me the information I need to fill out this form, I can follow up with them. Alternatively if you could contact Watchguard support, that would be much appreciated.

12 Likes

Hello @ABIDI please coordinate with @mcpherrinm
Thanks to both of you! :slight_smile:

4 Likes

Hello @mcpherrinm
I just submitted a support case to WatchGuard.
I will let you know as soon as I have an answer.

6 Likes

Thank you!

7 Likes

Hello @mcpherrinm @Bruce5051

I got the response from WatchGuad support :
"x2.c.lencr.org appears to have already been updated:
http://x2.c.lencr.org is categorized as Information Technology
But e1.o.lencr.org is still registered as Bot Networks:
http://e1.o.lencr.org is categorized as Bot Networks"
I just scanned the host in e1.o.lencr.org and it is still flagged as malicious
Valkyrie Verdict
VirusTotal

5 Likes

Valkyrie has confirmed in the thread they've removed x2.c.lencr.org

Thank you for pointing out e1.o.lencr.org is also flagged. I've checked the rest of our domains and found out that x1.i.lencr.org is flagged as well.

I've requested they be unflagged as well:

9 Likes

Hello @mcpherrinm
The e1.o.lencr.org host is clean again

Thanks for your collaboration

2 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.