False Positive / Needs Manual Review: kawaguchiclinic(dot)net & midorihihu(dot)com

Hi bjm,

I hope you are doing well! Thanks to your great support, the previous site was successfully unblocked.

I actually manage a medical mall with several clinic websites, and I found that two other sites are experiencing the exact same “InfoStl” false positive block:

  1. kawaguchiclinic(dot)net (VirusTotal: 0/92)

  2. midorihihu(dot)com (Wordfence scan is 100% clean, though 2 minor vendors on VT are lagging behind in updating their cache)

Both sites have been completely cleaned and secured on our end. Could you please do me a huge favor and report these two URLs to the Norton Threat Labs for a manual review, just like you did last time?

I would truly appreciate your continuous support!

Submit a file or URL to Norton for review

Note: after submitting dispute and waiting 48 business hours with no change.
Please contact official Norton Support and advise support that you’ve submitted dispute and waited 48 business hours. My understanding is…once you state that you have already submitted False Positive over the submission portal and waited 48 business hours…support agent shall take the URL and detection screenshot and advance the case.

=============================================

Submission Portal: Norton Submission Portal. This system is used for tracking false positive reports.
Site Ownership: Ensure you have officially “claimed” your website within the Safe Web portal. Verified owners generally have access to a dashboard where they can see the status of their site and any pending disputes without relying solely on email notifications.
48 hours: Community suggests waiting 48 business hours. If the status of your site has not changed on the Safe Web public lookup after this time, it likely means the dispute is still in the queue or was not processed.
Norton Support: If you haven’t received an email or a status change after 48 hours, contact official Norton Support directly. Explicitly tell the agent: “I have already submitted a site dispute via the Safe Web portal more than 48 hours ago and have received no email notification or status update.” This often prompts support to escalate the ticket manually.

https://kawaguchiclinic.net



0daefb213e1a

3459d1330716/2026-05-02T22:24:38.180Z

3459d1330716/2026-05-02T22:24:38.180Z

=============================================

https://midorihihu.com



4e6f758317c1

1554f6588a02/2026-05-02T22:26:04.458Z

1554f6588a02/2026-05-02T22:26:04.458Z

Dear bjm,

Thank you so much for your incredibly fast response and for reporting the false detection to the threat labs again!

I was very surprised to see that kawaguchiclinic(dot)net was actually blocked for “FakeT” instead of “InfoStl”. Your detailed check really helped clarify the situation. I will wait for the threat labs to review the sites and update their database.

Thank you always for your amazing support!

1 Like

What “URL:Block [FakeT]” typically indicates

  • FakeT = Fake/Scam/Phishing-type site
  • It’s commonly used when a site is suspected of:
    • Impersonation (login pages, brands, services)
    • Social engineering (trying to trick users into entering info)
    • Low-reputation or newly observed domains behaving suspiciously

=============================================

What “URL:Block [InfoStl]” means

  • InfoStl = Information Stealer–related activity
  • Norton uses this when a URL is associated with:
    • Credential harvesting (logins, personal data)
    • Delivery of info-stealing malware (or redirect chains leading to it)
    • Infrastructure previously tied to data exfiltration campaigns

Hi bjm,

Great news! The Japanese chat system is working again today, and I was finally able to connect with the official Norton Chat Support.

The agent confirmed that they have manually escalated the unblock request for both sites to the Threat Labs team. With your report and the official support’s escalation, I am very hopeful!

Thank you so much again for all your help. I will wait for the Threat Labs’ review to be completed!

1 Like

Threat name: URL:Block [FakeT]
URL: kawaguchiclinic.net
Detected by: Web Shield | URL scanning
Alert ID: 5222db173804
Akert ID: 215a171fb59f/2026-05-05T19:33:11.480Z


Threat name: URL:Block [InfoStl]
URL: midorihihu.com
Detected by: Web Shield | URL scanning
Alert ID: 8335cfbb3be8
Alert ID: ecfd4db6329d/2026-05-05T19:33:56.702Z


Hi @TAKANORI

https://kawaguchiclinic.net/



=============================================

https://midorihihu.com/



Hi bjm,

I just confirmed that both kawaguchiclinic(dot)net and midorihihu(dot)com are now officially evaluated as “Safe”! I can access them normally without any warning screens.

Thank you so much for your incredible and continuous support from start to finish. Your manual reports to the Threat Labs and your detailed updates truly saved me. I couldn’t have resolved this issue for our medical mall clinics without your kind help.

Thank you again, and have a wonderful day!

1 Like