linux-malware-detect icon indicating copy to clipboard operation
linux-malware-detect copied to clipboard

adguard dns blocking rfxn.com

Open Gazoo opened this issue 5 years ago • 12 comments

Just a quick note that I noticed that adguard and adguard DNS is blocking access to rfxn.com. 2019-04-15_08h45_46

Gazoo avatar Apr 15 '19 14:04 Gazoo

Thanks for the heads up @Gazoo. I've submitted a delisting request as their self-reporting page is clean.

https://reports.adguard.com/en/rfxn.com/report.html

Will report back once I hear from them to the positive or negative on delisting.

rfxn avatar Apr 15 '19 18:04 rfxn

All set, now marked as safe: https://reports.adguard.com/en/rfxn.com/report.html

Thanks again for the heads up :)

rfxn avatar Apr 15 '19 20:04 rfxn

Unfortunately it still looks like other AV providers are blocking rfxn.com too. Virustotal reports the domain as safe so I'm not sure where these other AV providers are getting their data from. 2019-04-17_03h17_16

Gazoo avatar Apr 17 '19 09:04 Gazoo

That's dumb, thank you for report. I'll dig deeper today, some list somewhere that vendors are collectively pulling must have rfxn.com on it :|.

rfxn avatar Apr 17 '19 12:04 rfxn

Cisco scansafe (proxy) is also blocking the domain.

setupdev avatar Apr 18 '19 11:04 setupdev

Cisco Scansafe says: "Blocking connection because of a webrep named 'Reputation-Viruses'".

(Trying to get an exception for the site from IT. No idea where they take the rules from).

setupdev avatar Apr 23 '19 06:04 setupdev

Quote from IT: "Approved to unblock ... reputation dispute's been raised on Cisco side".

setupdev avatar Apr 23 '19 09:04 setupdev

Works for me now. So at least locally fixed in Cisco Scansafe.

setupdev avatar Apr 27 '19 12:04 setupdev

Thanks all for the diligence here! Going to leave this open for any other related blocks.

rfxn avatar May 06 '19 16:05 rfxn

Cisco OpenDNS (Umbrella) also blocks rfxn as a "malware" network.

linuxchuck avatar Jun 03 '19 17:06 linuxchuck

I've emailed [email protected], thanks for the report @linuxchuck

rfxn avatar Jun 03 '19 21:06 rfxn

removed from opendns "Our research team has investigated the domain rfxn[.]com and has removed the block (whitelisted the domain).

Please note, that this may take 24 hours for the changes to propagate to our servers"

rfxn avatar Jun 04 '19 12:06 rfxn