badmojr / 1Hosts

World's most advanced DNS filter-/blocklists!
https://o0.pages.dev
Mozilla Public License 2.0
1.5k stars 88 forks source link

Block `restavracije-gostilne.si` #1427

Open WebworkrNet opened 1 year ago

WebworkrNet commented 1 year ago


Submit Form

Get your issue resolved quickly! Fill in the form accurately.

Lists in use:

Client: Blokada/Android


Domains:

restavracije-gostilne.si
www.restavracije-gostilne.si


Details: restavracije-gostilne.si

Malicious, Malware, Phishing

https://www.virustotal.com/gui/domain/restavracije-gostilne.si

Screenshot_2023-05-29_21-29-15

www.restavracije-gostilne.si/banner.php?id=44&url=//norsarchos.com?MjI2OTkyNjIyPTQ4MDExJjM5MDM2Nzg9ODImMzU9Y2xpY2smMWZjb3MxZj00JmxpZD0zMjMx

Malicious, Malware, Phishing

https://www.virustotal.com/gui/url/4f7d4984aa952b0aa912585973bf25b6da417042d65ce01896677e858afeea2f?nocache=1

Screenshot_2023-05-29_21-31-16

Thank you for supporting 1Hosts.

It’s people like you who make these lists great! ❤
spirillen commented 1 year ago

For what I understand, then it is http://norsarchos.com that hosts the phish/malware not restavracije-gostilne.si

But that do not gets any hits

https://www.virustotal.com/gui/url/d026114126d2c024d9e0b304ec87ab826164653f434971cadd7337c3a0c25369?nocache=1

Logger output | | | | | | | | | |:--- |:--- |:--- |:--- |:--- |:--- |:--- |:--- | | +4 | | | norsarchos.com | 1 | get | image | `http://norsarchos.com/favicon.ico` | | +3 | no-remote-fonts: * true | -- | norsarchos.com | 1 | get | inline-font | `http://norsarchos.com/?MjI2OTkyNjIyPTQ4MDExJjM5MDM2Nzg9ODImMzU9Y2xpY2smMWZjb3MxZj00JmxpZD0zMjMxwww.restavracije-gostilne.si` | | +3 | | | norsarchos.com | 1 | get | doc | `http://norsarchos.com/?MjI2OTkyNjIyPTQ4MDExJjM5MDM2Nzg9ODImMzU9Y2xpY2smMWZjb3MxZj00JmxpZD0zMjMxwww.restavracije-gostilne.si` | | +2 | | | norsarchos.com | 1 | get | doc | `https://norsarchos.com/?MjI2OTkyNjIyPTQ4MDExJjM5MDM2Nzg9ODImMzU9Y2xpY2smMWZjb3MxZj00JmxpZD0zMjMxwww.restavracije-gostilne.si` | | +2 | | | norsarchos.com | 1 | get | doc | `http://norsarchos.com/?MjI2OTkyNjIyPTQ4MDExJjM5MDM2Nzg9ODImMzU9Y2xpY2smMWZjb3MxZj00JmxpZD0zMjMxwww.restavracije-gostilne.si` | | +2 | no-remote-fonts: * true | -- | `www.restavracije-gostilne.si` | 1 | get | inline-font | `http://www.restavracije-gostilne.si/banner.php?id=44&url=//norsarchos.com?MjI2OTkyNjIyPTQ4MDExJjM5MDM2Nzg9ODImMzU9Y2xpY2smMWZjb3MxZj00JmxpZD0zMjMxwww.restavracije-gostilne.si` | | +1 | | | `www.restavracije-gostilne.si` | 1 | get | doc | `http://www.restavracije-gostilne.si/banner.php?id=44&url=//norsarchos.com?MjI2OTkyNjIyPTQ4MDExJjM5MDM2Nzg9ODImMzU9Y2xpY2smMWZjb3MxZj00JmxpZD0zMjMxwww.restavracije-gostilne.si` | | +0 | | | `www.restavracije-gostilne.si` | 1 | get | doc | `https://www.restavracije-gostilne.si/banner.php?id=44&url=//norsarchos.com?MjI2OTkyNjIyPTQ4MDExJjM5MDM2Nzg9ODImMzU9Y2xpY2smMWZjb3MxZj00JmxpZD0zMjMxwww.restavracije-gostilne.si` | | +0 | | | `www.restavracije-gostilne.si` | 1 | get | doc | `http://www.restavracije-gostilne.si/banner.php?id=44&url=//norsarchos.com?MjI2OTkyNjIyPTQ4MDExJjM5MDM2Nzg9ODImMzU9Y2xpY2smMWZjb3MxZj00JmxpZD0zMjMxwww.restavracije-gostilne.si` |
WebworkrNet commented 1 year ago

@spirillen I had also checked norsarchos.com on Virustotal and was also surprised that this domain or URL did not return any hits.

In cases where suspicious domains do not yet get hits at VT, I am still withholding them and will report them at a later date if a source backs up my blocking request.