hagezi / dns-blocklists

DNS-Blocklists: For a better internet - keep the internet clean!
GNU General Public License v3.0
6.22k stars 213 forks source link

xxxxxxxx.jp ? #3036

Closed tsweet64 closed 3 months ago

tsweet64 commented 3 months ago

Which AdBlocker/DNS cloud service do you use?

uBlock

Other

No response

ControlD users

NextDNS users

With which block list(s) does the problem occur?

Multi PRO++, Threat Intelligence Feeds

Which domain(s) should be unblocked?

kinzoku.xxxxxxxx.jp

Why should the domain(s) be unblocked?

It's the site for a music group.

It's blocked because it's a subdomain of xxxxxxxx.jp . It's not entirely clear to me why that's blocked, so I can't say for certain that it shouldn't be per se. But in my quick analysis, that base site itself contains no content other than a joke about it being useless; a google search for site:xxxxxxxx.jp reveals a diverse selection of random, mostly not malicious looking content (primarily local businesses), so my guess is that it's a small hosting provider.

hagezi commented 3 months ago

If they're using a free hosting provider that is known to host crap and badware, don't be surprised that the main domain is blocked in many lists:

Blocklists:
 - 1Hosts.Lite     BLOCKED
 - 1Hosts.Mini     BLOCKED
 - 1Hosts.Pro      BLOCKED
 - AdGuardDNS      BLOCKED
 - CONTROLD.AT     BLOCKED
 - DevDansHosts    OK
 - EasyList        OK
 - GoodbyeAds      BLOCKED
 - HaGeZi.LIGHT    BLOCKED
 - HaGeZi.NORMAL   BLOCKED
 - HaGeZi.PRO      BLOCKED
 - HaGeZi.PRO.PLUS BLOCKED
 - HaGeZi.TIF      BLOCKED
 - HaGeZi.ULTIMATE BLOCKED
 - hBlock          BLOCKED
 - NextDNS.AT      OK
 - OISD.Big        OK
 - OISD.Small      OK
 - QuidsUp.NOTRACK OK
 - StevenBlack     OK

The main domain is blocked to block all possible malicious subdomains.

The domain currently has no flags, but there have been some in the past: https://www.virustotal.com/gui/domain/xxxxxxxx.jp/relations

Subdomains on top 1M lists - I have not checked which of them are malicious, especially since malicious domains rarely appear on the top 1M lists: :

0meganet2.xxxxxxxx.jp
100split.xxxxxxxx.jp
2chwatch.xxxxxxxx.jp
3dscraft.xxxxxxxx.jp
4seasons.xxxxxxxx.jp
704music.xxxxxxxx.jp
across.xxxxxxxx.jp
addict.xxxxxxxx.jp
anheling.xxxxxxxx.jp
apres.xxxxxxxx.jp
areae.xxxxxxxx.jp
asagi00.xxxxxxxx.jp
atsp.xxxxxxxx.jp
blame.xxxxxxxx.jp
bon.xxxxxxxx.jp
boogie.xxxxxxxx.jp
chemlyn.xxxxxxxx.jp
chupa.xxxxxxxx.jp
coquettish.xxxxxxxx.jp
crayoneater.xxxxxxxx.jp
cry.xxxxxxxx.jp
ct1.xxxxxxxx.jp
ct2.xxxxxxxx.jp
danoni2009summer.xxxxxxxx.jp
danoni2010winter.xxxxxxxx.jp
delusaga.xxxxxxxx.jp
denokyo.xxxxxxxx.jp
doukeshi.xxxxxxxx.jp
dowf.xxxxxxxx.jp
doxf04.xxxxxxxx.jp
everydaymasic.xxxxxxxx.jp
fdfw.xxxxxxxx.jp
fia.xxxxxxxx.jp
flamingos.xxxxxxxx.jp
flowers.xxxxxxxx.jp
fma.xxxxxxxx.jp
genom.xxxxxxxx.jp
holsters.xxxxxxxx.jp
hozo.xxxxxxxx.jp
hymn.xxxxxxxx.jp
ibe.xxxxxxxx.jp
jabajaba.xxxxxxxx.jp
janet.xxxxxxxx.jp
jesusenter.xxxxxxxx.jp
jituname.xxxxxxxx.jp
junction.xxxxxxxx.jp
keins.xxxxxxxx.jp
ksd.xxxxxxxx.jp
lachenalia.xxxxxxxx.jp
large.xxxxxxxx.jp
lilac.xxxxxxxx.jp
listanegra.xxxxxxxx.jp
longlink.xxxxxxxx.jp
lovecraft.xxxxxxxx.jp
m07.xxxxxxxx.jp
momotarosu.xxxxxxxx.jp
motelotel.xxxxxxxx.jp
musou4.empires.xxxxxxxx.jp
nagata.xxxxxxxx.jp
nhoko.xxxxxxxx.jp
noosprey.xxxxxxxx.jp
oisu.xxxxxxxx.jp
outstanding.xxxxxxxx.jp
patitcarol.xxxxxxxx.jp
pay.xxxxxxxx.jp
persons.xxxxxxxx.jp
plasticchamber.xxxxxxxx.jp
projectshion.xxxxxxxx.jp
psychic.xxxxxxxx.jp
renkoumei.xxxxxxxx.jp
rikkyoigo.xxxxxxxx.jp
rinto.xxxxxxxx.jp
rouranphantom.xxxxxxxx.jp
ruffneck.xxxxxxxx.jp
rupetbiyori.xxxxxxxx.jp
saikorock.xxxxxxxx.jp
sapphirecrown.xxxxxxxx.jp
sapuriyasan.xxxxxxxx.jp
soysause.xxxxxxxx.jp
starnet.xxxxxxxx.jp
streetlife.xxxxxxxx.jp
suisai.xxxxxxxx.jp
sundance.xxxxxxxx.jp
tatsuiti.xxxxxxxx.jp
tcgportal.xxxxxxxx.jp
teikoku.xxxxxxxx.jp
tgc.xxxxxxxx.jp
toyota.xxxxxxxx.jp
tsurumakidou.xxxxxxxx.jp
twinkles.xxxxxxxx.jp
uguisudani.xxxxxxxx.jp
unununium.xxxxxxxx.jp
valhalla.xxxxxxxx.jp
vincent.xxxxxxxx.jp
vsign.xxxxxxxx.jp
wabasyun.xxxxxxxx.jp
wavision.xxxxxxxx.jp
wirepullerorg.xxxxxxxx.jp
wirepuller.xxxxxxxx.jp
x6.xxxxxxxx.jp
x7.xxxxxxxx.jp
x8.xxxxxxxx.jp
xxxxxxxxtunnel.xxxxxxxx.jp
xxx.xxxxxxxx.jp
yakitolympic.xxxxxxxx.jp
yca.xxxxxxxx.jp
yokohamajrc.xxxxxxxx.jp
youki.xxxxxxxx.jp
zrayd.xxxxxxxx.jp

Also blocked in AdGuard DNS via the JP filter, @Alex-302 what is your opinion on this?

hagezi commented 3 months ago

This is what the page looks like when I use the unfiltered AdGuard DNS:

grafik

tsweet64 commented 3 months ago

It looks like that for me too, I think their site is just broken

hagezi commented 3 months ago

And it hasn't been updated for years. I think we can close here.