hagezi / dns-blocklists

DNS-Blocklists: For a better internet - keep the internet clean!
GNU General Public License v3.0
6.96k stars 230 forks source link

Whitelist cname for amazonforum.com #1006

Closed xRuffKez closed 1 year ago

xRuffKez commented 1 year ago

Which AdBlocker/DNS cloud service do you use?

Pi-hole

Other

No response

NextDNS users only

Which blocklist(s) do you use?

Multi PRO

Which domain(s) should be unblocked?

d1bd3wxsyuz0t7.cloudfront.net

Why should the domain(s) be unblocked?

Domain is cname for de.amazonforum.com

Screenshot_20230504-162748

hagezi commented 1 year ago

Reason: Blocked by Quad9 Secure-DNS, but amazonforum.com is not blocked by Q9. Despite all the flags, it seems to be a false positive domain.

grafik

Domain:
 - d1bd3wxsyuz0t7.cloudfront.net OK

Malware/Phishing/Scam:
 - Malicous?       LIKELY (2)

 - Threat?
   HaGeZi.TIF.LT   NO
   HaGeZi.TIF      YES
   HaGeZi.TIF.RAW  YES
   Quad9           YES
   OpenDNS         NO
   ThreatFox       NO
   URLhaus         NO
   ThreatView      NO
   KADHosts        YES

 - Phishing?
   Phishing.Army   NO
   PT/OP/PH        NO
   Phishing.DB     NO

Top 1M rank:
 - Umbrella:       -/-
 - Tranco:         -/-
 - Chrome:         -/-

Secure DNS:
 - CleanBrowsing   BLOCKED
 - Cloudflare      OK
 - CONTROLD.TIF    BLOCKED
 - DNS0.eu         BLOCKED
 - DNS0.eu.ZERO    BLOCKED
 - NextDNS.TIF_AI  BLOCKED
 - NRD.DGA.IDN     OK
 - OpenDNS         OK
 - Quad9           BLOCKED
 - SafeDNS         OK
 - UltraDNS        OK

Blocklists:
 - 1Hosts.Lite     OK
 - 1Hosts.Mini     OK
 - 1Hosts.Pro      BLOCKED
 - AdGuardDNS      OK
 - AhaDNS          OK
 - CONTROLD        BLOCKED
 - DNSforge.de     BLOCKED
 - EasyList        OK
 - HaGeZi.LIGHT    OK
 - HaGeZi.NORMAL   OK
 - HaGeZi.PERSONAL OK
 - HaGeZi.PRO      BLOCKED
 - HaGeZi.PRO.PLUS BLOCKED
 - HaGeZi.ULTIMATE BLOCKED
 - hBlock          BLOCKED
 - Lightswitch05   OK
 - NextDNS         BLOCKED
 - NoTracking      OK
 - OISD            OK
 - QuidsUp.NOTRACK OK
 - StevenBlack     BLOCKED

Intels:
 - Google          https://transparencyreport.google.com/safe-browsing/search?url=d1bd3wxsyuz0t7.cloudfront.net
 - VirusTotal      https://www.virustotal.com/en/domain/d1bd3wxsyuz0t7.cloudfront.net/information/
 - AlienVault      https://otx.alienvault.com/indicator/domain/d1bd3wxsyuz0t7.cloudfront.net
 - Bitdefender     https://trafficlight.bitdefender.com/info/?url=https%3A%2F%2Fd1bd3wxsyuz0t7.cloudfront.net
 - FortiGuard      https://www.fortiguard.com/webfilter?q=d1bd3wxsyuz0t7.cloudfront.net&type=&engine=1
 - Kaspersky       https://opentip.kaspersky.com/d1bd3wxsyuz0t7.cloudfront.net?tab=web
 - McAfee          https://siteadvisor.com/sitereport.html?url=d1bd3wxsyuz0t7.cloudfront.net
 - Norton          https://safeweb.norton.com/report/show?url=d1bd3wxsyuz0t7.cloudfront.net
 - OpenDNS         https://domain.opendns.com/d1bd3wxsyuz0t7.cloudfront.net
 - URLVoid         https://www.urlvoid.com/scan/d1bd3wxsyuz0t7.cloudfront.net/
 - Yandex          https://yandex.com/safety/?l10n=en&url=d1bd3wxsyuz0t7.cloudfront.net
hagezi commented 1 year ago

Whois: Amazon, will be removed: https://myip.ms/info/whois/18.244.114.45/k/3034523520/website/d1bd3wxsyuz0t7.cloudfront.net

hagezi commented 1 year ago

Also whitelisted by AlienVault:

grafik

hagezi commented 1 year ago

I have additionally requested removal from Quad9.

hagezi commented 1 year ago

@xRuffKez fixed in my lists. waiting for Quad9 ...

xRuffKez commented 1 year ago

Nice and thanks.

hagezi commented 1 year ago

Will be removed from Quad9:

grafik

iam-py-test commented 1 year ago

Off topic, but what tool did you use to get that report in https://github.com/hagezi/dns-blocklists/issues/1006#issuecomment-1534908798?

hagezi commented 1 year ago

@iam-py-test my script, based on: https://github.com/PeterDaveHello/chkdomain

iam-py-test commented 1 year ago

Cool, thanks