Skip to content

False Positive | seminovos.com.br #1895

@garridez

Description

@garridez

What are the subjects of the false-positive (domains, URLs, or IPs)?

*.seminovos.com.br

Why do you believe this is a false-positive?

seminovos.com.br is a legitimate Brazilian marketplace for used vehicles that has been operating continuously for over 10 years.

The platform connects private sellers, dealerships, and buyers, and does not host phishing pages, credential harvesting, malware distribution, or deceptive redirects. The domain enforces HTTPS and follows standard security practices.

Currently, only a small number of security vendors classify the domain as phishing, while the vast majority of vendors on VirusTotal consider it clean.

In addition, BrightCloud has already reviewed and reconsidered its previous classification, confirming the domain as legitimate. This strongly indicates that the current phishing classification is a false positive, possibly caused by an outdated indicator or a misidentified subdomain.

We kindly request a review and removal of this domain from the phishing database.

How did you discover this false-positive(s)?

VirusTotal

Where did you find this false-positive if not listed above?

The false positive was identified after users reported that access to seminovos.com.br was being blocked by AdGuard DNS with a “Dangerous website” warning.

After receiving these reports, we verified the issue using VirusTotal and confirmed that a limited number of phishing intelligence providers were flagging the domain.

Have you requested a review from other sources?

Yes. We have requested reviews from other threat intelligence providers, including AlphaMountain and AdGuard DNS. BrightCloud has already reviewed the case and cleared the domain.

Do you have a screenshot?

Image

Additional Information or Context

seminovos.com.br is a long-established and well-known marketplace in Brazil. The domain has a long operational history, stable ownership, and consistent usage by consumers and automotive businesses.

We believe the phishing flag may be related to an outdated indicator, automated heuristic, or a misidentified subdomain that is no longer active. No phishing content is currently hosted on the domain.

We are available to provide any additional technical information if required.

Metadata

Metadata

Labels

bot:check-false-positiveInforms our bots that they should check for the possible false-positive.bot:check-staleInforms our bots that they should check for possible stale.bot:verify-dnsInforms our bots that they should check for the DNS verification.false-positive-reportA False-Positive report that has to be verified.

Type

No type

Projects

Status

✅ Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions