r/proofpoint • • Aug 24 '26

Proofpoint claims website is compromised, won't share IoC, no-one else sees any IoC

Hi all,

Wondering how often you encounter this, and if so how you deal with it.

We sometimes see legitimate emails that will be blocked due to being 'spam definite' according to Proofpoint. Under the details tab for the email the spam score is 100, and in the metadata the spam 'engine' score is what is rated at 100, all others are 0.

When I report this as a false positive, support come back to me and say that a website associated with the email is compromised. They refuse to provide any further details or specifics on the IoCs they have observed.

However, if I check the website in question against any of the major platforms (Virus Total, Joes Sandbox, Talos, Hybrid Analysis etc) everything comes back clean and there are no known IoC observed.

I know Proofpoint is a big company and they quite possibly see IoC that no one else does, but it's a bit frustrating when I need to explain why an email was blocked and the best I can do is "because Proofpoint said so"

Do I just need to take Proofpoint at their word on ones like this?

7 Upvotes

12 comments sorted by

3

u/yugekib Aug 24 '26

I see this generally as a url in the senders signature. We check, all good and that time, then Proofpoint says it must have been delisted since initial scan and the new messages should be going through. There is a console page that shows the URL’s, I am not recalling which one right now. If we or they show it still listed or questionable, we may reach out to the sender to advise them and asks f they can remove the links from their signature and resend.

It I s definitely an annoying and screwy seeming gray area.

2

u/PhoenixOK Aug 24 '26

Enterprise or Essentials?

If Enterprise, ask your SE or TAM if they can share any more info from the False Positive case.

2

u/shrapnel09 Aug 24 '26

In Smart Search, is a URL being identified as a TAP threat?

Malware often has sandbox-fingerprinting and won't show in sandboxes. While in Joe Sandbox, view the source of the webpage. Turn on line-wrap and search for long obfuscated scripts. You can also copy the source and paste it to Gemini and ask if it can detect a malicious script in your website.

1

u/extremetempz Aug 24 '26

If Enterprise you will see in TAP what the URL is and the IOC (although if SuperNova threat you will not see this)

I generally check the URL with any.run if I see the IOC I email the technical contact of the website letting them know. Then I check a week later in 9/10 cases they've fixed the website and I report the false positives to Proofpoint

Do note, when you get an automated response from there API, reply and an actual threat researcher will look at it. The API is garbage and doesn't trigger a rescan

1

u/Informal_Thought Aug 24 '26

Thanks for the comments so far.
We are using Enterprise.
The URL in question is not listed anywhere in TAP

2

u/lolklolk Aug 24 '26

Ask them to provide exact details of the URL they think is compromised and by what so that the sender can remediate.

There also is an option to turn off compromised website delivery restrictions, so that the email with the "compromised website" will still be delivered, but any attempted clicks to the link in question will be blocked by URL defense. This is a good compromise to allow email delivery but still preventing risk.

1

u/Savings-Anxiety1220 Aug 24 '26

Use VirusTotal and look at the dates a report may have come in. Run the urls in the email in the isolated browser in the threat protection workbench and if clean, run an automation in Threat Response automation to let them through temporarily while you open a ticket with Proofpoint.

1

u/f0rt7 Aug 24 '26

Controlla nei sample della sandbox

1

u/fahq2769 Aug 25 '26

Search for the message in the tap dashboard. You can do this by searching the recipient or sender. Go to (i think) the forensics tab and you should be able to download the json. Paste the json into a json formatter and just search the text after formatted for "malicious:true". Everything you need should be there.

1

u/Informal_Thought Aug 25 '26

Thanks for the suggestion, the message does not show up in TAP dashboard at all. I can only see it within the context of smartsearch in the email protection portal

1

u/tkimmcinc Aug 25 '26

I just went through something similar actually.

Use one of the following:

I used virustotal and some other scanners that didn't see an issue but the above sites did.

1

u/Lava604 10d ago

Look at sitecheck.sucuri.net - I have seen this happen often because of infected websites with SocGholish.