Earn up to $250 in gift cards this summer. Find out how.

ESET Antivirus Users Receiving "Potential Phishing Attempt" Warning Screen in Browsers

Issue:

  • Error: Potential Phishing Attempt warning screen in browser
  • ESET Antivirus warning about Clio Documents

Environment:

  • Clio Manage
  • FasterSuite
  • Clio Drive
  • Clio Launcher
  • ESET Antivirus

Additional Information:

  • Clio will be contacting ESET Antivirus to work on a more permanent solution. Users should use the workaround steps provided below for an immediate solution.

Cause:

  • On Wednesday, April 20, 2022, Clio was made aware of the error "Potential Phishing Attempt" being displayed for users of the antivirus software ESET while working with documents in Clio Manage. The issue is most likely caused due to ESET creating a false-positive for one of the URLs that Clio uses to serve documents. 

Workaround:

Adding the affected URL to ESET's whitelist will fix the issue, until a more permanent solution is worked out by ESET Antivirus. Follow the steps mentioned below to add to ESET Whitelist.

  1. Press F5 on your keyboard to access Advanced setup.
  2. Click Web and Email → Web access protection, expand URL Address Management and then click Edit.

    KB3100Fig3-1c.png
  3. Select List of addresses excluded from content scan and then click Edit.

    KB3100Fig3-2a.png

  4. From the Edit list window, click Add and type the URL address. The Clio URL that needs to be added to ESET Whitelist is - iris-production.s3.us-east-1.amazonaws.com
    Click OK in each of the open windows to save your changes and exit Advanced setup.

    KB3100Fig3-3a.png

  5. You will no longer receive threat notifications from your ESET product when this URL is accessed.


You can also follow ESET's official guidelines listed here to add the affected URL to whitelist here: https://support.eset.com/en/how-anti-phishing-works-in-your-eset-product#add_whitelist

The Clio URL that needs to be added to ESET Whitelist is - iris-production.s3.us-east-1.amazonaws.com

Was this article helpful?
This information is confusing or wrong
This isn't the information that I was looking for
I don't like this functionality