ShadowWhisperer / BlockLists

DNS Block Lists
260 stars 32 forks source link

entechremote.com incorrectly added to malware list? #147

Closed King-Louis-III closed 5 months ago

King-Louis-III commented 5 months ago

entechremote.com is our screen connect (connectwise control) instance. I'm curious about how it ended up on your malware list? Was it pulled from another source?

ShadowWhisperer commented 5 months ago

Flagged as "Remote support page [Generic] / Potential remote scam landing"

These lists are built using custom scripts, and manual additions. (All of my own)

Source lists are compiled from multiple top million lists, newly registered lists, my honeypots, DNS logs from networks I manage, etc.

King-Louis-III commented 5 months ago

Understood. I'm trying to figure out how this particular entry ended up on your blacklist so I can make sure our domain isn't compromised, or if it came from a different list, how it ended up on their list.

I ended up here because I found it on another list entirely, and they pointed me to your list as the source, so I'm trying to trace it back to figure out what happened.

ShadowWhisperer commented 5 months ago

Origin - Tranco list

Whitelisted

King-Louis-III commented 5 months ago

The domain was entechremote.com

Which I don't see in that Tranco list you posted. I'm not sure what the uscomputergroup.com domain is?

ShadowWhisperer commented 5 months ago

Capture