hagezi / dns-blocklists

DNS-Blocklists: For a better internet - keep the internet clean!
GNU General Public License v3.0
5.45k stars 184 forks source link

unblock 188.114.96.2 #2331

Closed ShiGhost closed 5 months ago

ShiGhost commented 5 months ago

Which AdBlocker/DNS cloud service do you use?

AdGuard Home

Other

No response

NextDNS users only

With which block list(s) does the problem occur?

Threat Intelligence Feeds IPs

Which domain(s) should be unblocked?

188.114.96.2

Why should the domain(s) be unblocked?

This ip address belongs to cloudflare CDN.

hagezi commented 5 months ago

@ShiGhost That doesn't look like a Cloudflare CDN to me:

https://blacklist.myip.ms/188.114.96.2 https://myip.ms/browse/sites/1/ipID/188.114.96.2/ipIDii/188.114.96.2 https://myip.ms/browse/sites_history/1/ipID/188.114.96.2/ipIDii/188.114.96.2

ShiGhost commented 5 months ago

@ShiGhost That doesn't look like a Cloudflare CDN to me:

https://blacklist.myip.ms/188.114.96.2 https://myip.ms/browse/sites/1/ipID/188.114.96.2/ipIDii/188.114.96.2 https://myip.ms/browse/sites_history/1/ipID/188.114.96.2/ipIDii/188.114.96.2

Your link says it's cloudflare. - https://myip.ms/browse/sites/1/ipID/188.114.96.2/ipIDii/188.114.96.2

изображение

hagezi commented 5 months ago

Yes, but then take a look at the malicious domains that are on the IP ...

hagezi commented 5 months ago

block reason: https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/

grafik

hagezi commented 5 months ago

https://otx.alienvault.com/indicator/ip/188.114.96.2

grafik

grafik

hagezi commented 5 months ago

@ShiGhost Which domains trigger the rule for you?

ShiGhost commented 5 months ago

@ShiGhost Which domains trigger the rule for you?

Screenshot_29

hagezi commented 5 months ago

@ShiGhost I checked the IP again via a few security services, in most of them it is whitelisted because the blocking also affects "normal" sites. I will remove it.

ShiGhost commented 5 months ago

@ShiGhost I checked the IP again via a few security services, in most of them it is whitelisted because the blocking also affects "normal" sites. I will remove it.

Thank you.