The list below lists domains, that are mostly still active for the OSX/Shlayer trojan landing and CnC domains:
https://github.com/carbonblack/tau-tools/blob/master/threat_hunting/IOCs/shlayer/domain-iocs.txt
read more about it here:
https://www.carbonblack.com/2019/02/12/tau-threat-intelligence-notification-new-macos-malware-variant-of-shlayer-osx-discovered/
Hello! Thank you for opening your first issue in this repo. It鈥檚 people like you who make these host files better!
There is just one trouble.... it seems like a stalled submission like a "one off" and it haven't been updated since Feb. 12 2019
But i'll throw it through the PyFunceble and VirusTotal, then wee see what happens
This is the list I reached, before VirusTotal was trying to load the google Spyware in my browser
Logger output
| | | | | | | |
|:--- |:--- |:--- |:--- |:--- |:--- |:--- |
| +3 | \|\|google.com^*recaptcha/$important | -- | www.virustotal.com | 3 | script | https://www.google.com/recaptcha/api.js?onload=onloadGrecaptchaCallback&render=explicit |
| +1 | google-analytics.com/analytics.js | << | www.virustotal.com | | script | https://www.google-analytics.com/analytics.js |
| +1 | \|\|google-analytics.com/analytics.js | -- | www.virustotal.com | 3 | script | https://www.google-analytics.com/analytics.js |
| +0 | | | www.virustotal.com | 3 | script | https://cdn.rawgit.com/GoogleCloudPlatform/stackdriver-errors-js/v0.4.0/dist/stackdriver-errors-concat.min.js |
Test results from VirusTotal
api.adminbuffer.com https://www.virustotal.com/gui/url/358a75e41b700836eceaa5a85f5d85e92d26a8aeb95a54fe026d9d17119dad86/detection
api.agentinput.com https://www.virustotal.com/gui/url/d2e01e66210a78d7073183a12b6259e571c547fca795911870e9c20e36e77c7a/detection
#api.algorithmmode.com https://www.virustotal.com/gui/url/6461f1a808192c28f129d35db3c01464e16ef97cfd09e6ca00df53c095b6096c/detection
api.analysercloud.com https://www.virustotal.com/gui/url/7cb774bdba6a7aea97a8b737644b91237e30883b092fdb7e6b0e3e33fdcc18aa/detection
api.analyserdesk.com https://www.virustotal.com/gui/url/5b5804ad81ab31a4159f1e2b62b837d2ccbe6ef1a8339670b1c4e9314d7520b0/detection
#api.analyserinput.com https://www.virustotal.com/gui/url/f2f923a974a1140635f6c436a7501f15c1355ac6eed2fbc7bc92176e50291565/detection
api.analyzedisplay.com https://www.virustotal.com/gui/url/dea914efa206a0c84bd2dbe666e01e7266f211f27d193c4ca1ee4e3737a88897/detection
#api.appfastplay.com https://www.virustotal.com/gui/url/d9fc7541a574f8287d75645c8ff37324d5a71e6dbb9c3d2c15a07a173d63677e/detection
#api.appmotiondaily.com https://www.virustotal.com/gui/url/b6a25e734936dc45fa68d8b0481360c4359d71c019813921ce1b77169fc6a8cd/detection
#api.appsreforoma.com https://www.virustotal.com/gui/url/66ce658a64abc8379fe7664ac1ed93ddb5ad25d96245ddba1bc8d35e26ffbfda/detection
api.archivekey.com https://www.virustotal.com/gui/url/13d8e23a11152f98a906fb823b58ddb2e68e9636eef1e7bec989ff4ff12ad591/detection
api.assistiveformat.com https://www.virustotal.com/gui/url/2a58c0a3c34fac9542c88d19f8141f3707e7907c0ba45de04bd01e78ca75eec6/detection
api.assistivehandler.com https://www.virustotal.com/gui/url/065bdde60510ad18a1d147a68fc9aea3f90a7a4d7f4373b0cccddf81879bd9b6/detection
api.assistivenet.com https://www.virustotal.com/gui/url/fb08bac797d6a7881a23b73e3b98f3a84684230e1dec63f66499c3f2287f73d0/detection
#api.assistiverotator.com https://www.virustotal.com/gui/url/fcd59da48d4a54ad2ac2aa3b9c20352be7feb19e88d953fefe4feacfd0d6715a/detection
api.assistivesmart.com https://www.virustotal.com/gui/url/83f34338aa4c4448f04b4ba1d5dfd5d1d4850c68678c7cd77075a72eb4fe5cad/detection
#api.assistivesource.com https://www.virustotal.com/gui/url/9e01fe7b8c6a9577b3735329cb0964c7a5243b93fd74fbf5b663b344577bfd67/detection
#api.assistpartition.com https://www.virustotal.com/gui/url/e5bdc79b3a5b1b9276b2ce5974ebce84771312d5c80cdcea81654dad6d24a880/detection
#api.assistremote.com https://www.virustotal.com/gui/url/75edfccb14489b19356794e9c478bd04dfc9f7d30b2bf5847afd1005a1959099/detection
api.basicinitiator.com https://www.virustotal.com/gui/url/035152694d8f6a536d7a0816b4ef89d487c2e8dc043cd662b7e1833a2eb7dab3/detection
#api.bitcoordinator.com https://www.virustotal.com/gui/url/9c9a2b12bcf85e98acd6ce2b8a2dc0974d7150723eba89493598fabc489440d1/detection
#api.bitelemnt.com https://www.virustotal.com/gui/url/c3903becfa70b604c12775bed308f99b6236522985ad8af21d82f7beb753afc3/detection
api.browsedisplay.com https://www.virustotal.com/gui/url/dfb33b75f20ec73dcc370dc524a513a33c3edc24a84c6f4fa339d840867471dd/detection
api.browserinterop.com https://www.virustotal.com/gui/url/1716f43dbb09ee3791deb52172a1f85f54c0a81c99e28f91db653bbb7d23f997/detection
api.bufferqueue.com https://www.virustotal.com/gui/url/ad0479171c11ab21682624221d6987d6888a1a8269ff35b6579ba170c14c1cf8/detection
api.cachemega.com https://www.virustotal.com/gui/url/bf625a20541ff343a3f64707e978e1d979fe5c8c5da9b7b4b2bcdc8ed4072cde/detection
#api.catchthemac.com https://www.virustotal.com/gui/url/9719655b4e9a0c0c6cfc6d2400737b0bba897c440971e20f9505950e8ef1591c/detection
#api.choiceupdate.com https://www.virustotal.com/gui/url/c05458c68c8307307e20e328d3f47f6da2ce31441f4d8383607aac193f64bb04/detection
api.cleanconfig.com https://www.virustotal.com/gui/url/0fb658558a06c7bf8aa2f0ba7823af5981e9fedf271e0954ddf1c53f121f2342/detection
#api.commonprocesser.com https://www.virustotal.com/gui/url/80551358121613fa84c117dc58e621514400de0b86c401a44817ae8d63f55458/detection
api.configentry.com https://www.virustotal.com/gui/url/3458bb821c3bc59ef7f7a598e42191ed7e2884fc24265eb013081f58469eff7b/detection
#api.contemporaryapps.com https://www.virustotal.com/gui/url/8a73c9e795af52a25ce5c4e1ff6123f5215bc21899921cafe957dceea5b3234e/detection
#api.coordinatornano.com https://www.virustotal.com/gui/url/e65ab526db0ab7e9de4deeb728cbcf9bdade82bc18f05749b9093d202aa84899/detection
api.defaultindexer.com https://www.virustotal.com/gui/url/13de50995c45e2cc2c0053951d7b58b4f284539a03c8671e8b71ef3d2fb2d493/detection
#api.dynamicmodule.com https://www.virustotal.com/gui/url/9a7abd3ecd48bba8095316260156dac531a6c5721b95581782cc906b97362cbb/detection
#api.elementarylocator.com https://www.virustotal.com/gui/url/49631e4a462ebdf4561b05ef7ec85d3395f7ee61e1023355b886991361a8da0b/detection
api.elementaryprocess.com https://www.virustotal.com/gui/url/49ac6a1a980f0b68c6df046a5c7e6f5ade7e5705ea5699b8ab69fbe86ff6d87c/detection
#api.elemnttech.com https://www.virustotal.com/gui/url/45f2cc84ef44c72cde849391694f6cc9ccd9bec9aaba36ca57fc0bf56237e108/detection
#api.essentialupdater.com https://www.virustotal.com/gui/url/a7ed78cde48e4af125e3cba86c3e0a7cb75d2b140e80e9959fa2725b5c8a83ad/detection
#api.etagarring.com https://www.virustotal.com/gui/url/1065f3906741cac51ad282b59895afc9088f28716a5af45bf6623e6f8c007b41/detection
api.executiveinterface.com https://www.virustotal.com/gui/url/582d678b4f1406a0102898dff7dd544b869b585cc0ee43b796bd7ea2b2dceec4/detection
#api.explorertask.com https://www.virustotal.com/gui/url/4f7591f6a4904bf015ce083d839203cd4cbd4eb252925ef0e2c967f7e0fd189b/detection
#api.filterapps.com https://www.virustotal.com/gui/url/bf5f286872f37040e506cc2e4f1b31c7a843c111d15a08aedc484571bbc34eac/detection
#api.filterkey.com https://www.virustotal.com/gui/url/f17c1e0af3d66f630c738c011d4598cdca608233537014b5904fc54e27b76569/detection
#api.filtermode.com https://www.virustotal.com/gui/url/b8afac7aeb9c1f81c5eda4696bc25037b7ba6c4a753d6ae06d0ecebc2f172587/detection
#api.findscheduler.com https://www.virustotal.com/gui/url/e488d9d60b8e99982a589bed31963c555a45818e704d088564f260f33df1f688/detection
#api.functioninput.com https://www.virustotal.com/gui/url/e15d2e2199344e3b0344392afda61ac7752dbc0d635be0a6118c64ab67deabac/detection
#api.functionmemory.com https://www.virustotal.com/gui/url/a1889bf0701e4fef7720ea7b7eb07a1414d462293d64d7089cd2a35ff616c487/detection
api.futuristmac.com https://www.virustotal.com/gui/url/ed378e21bc3c363c1c6c2115ac22805563f22b9ecbd2d98881950e97b9a99a71/detection
api.handlerkey.com https://www.virustotal.com/gui/url/c7a57dd1cc20dfae0206e3d9c100b123062e78242bed7273c8651b7fbb259e6a/detection
api.helperportal.com https://www.virustotal.com/gui/url/a44ad6a5766c2dce2bb7d5a468051a4558ee8b7803a1bd5c9ab95bda55d72fef/detection
api.highsecuritymac.com https://www.virustotal.com/gui/url/b54317a72e8cda6d3f5caa8b8fd7382605d5e5f9cb79da67af660bd5fd98117f/detection
api.indexereng.com https://www.virustotal.com/gui/url/16a7cca6531b0a7b0b29559b34f82f83f62a8c298f057f50d97eb1514133e5da/detection
#api.initialprocess.com https://www.virustotal.com/gui/url/0969473002872d70110ba140e3d8fb2e9e3cc83f8e7e2c74880bef6b11bf4ae5/detection
The out commented is FP (False-positives) which should not be blocked.
The vote from my point of View would be to add them into a single list of choice, but these would requires I high level of maintenance, as these may turn around quickly and therefor would have to be removed from a blocking list.
If somebody would like to continue the test, which I would be pleased to see. Then you get the rest of the list to test at VirusTotal here
Still to test
api.initiatormaster.com
api.initiatormode.com
api.insidetechmac.com
api.internetalgorithm.com
api.internetinterop.com
api.interopcache.com
api.lightthemacup.com
api.locatorbasic.com
api.locatorformat.com
api.macfantsy.com
api.macmagnificent.com
api.macsatmosphere.com
api.macsinsights.com
api.macsmoments.com
api.majorqueue.com
api.managerscalable.com
api.managerwebmoves.com
api.megaformats.com
api.megamodule.com
api.metroorigin.com
api.nanodevsource.com
api.nanoscheduler.com
api.operativdata.com
api.operativebox.com
api.operativeguides.com
api.opticalmode.com
api.opticalsample.com
api.optimalcache.com
api.originassist.com
api.originmodule.com
api.partitionnet.com
api.portalconfig.com
api.portalelemnt.com
api.portalqueue.com
api.primarymodes.com
api.primarytransaction.com
api.processbuffer.com
api.processerdev.com
api.processformat.com
api.publicanalyser.com
api.publicconfig.com
api.remocreature.com
api.resultsformat.com
api.rotatorbit.com
api.rotatorsample.com
api.servereng.com
api.servicequeue.com
api.setwireframe.com
api.sharedanalyser.com
api.sourceremote.com
api.syncindexer.com
api.syncpartition.com
api.taskupgrade.com
api.technanoproject.com
api.techsmaturity.com
api.timefornaps.com
api.trackindexer.com
api.trustedadmins.com
api.ultrabitinitiator.com
api.updateelement.com
api.updaterbasic.com
api.updaterengine.com
api.upgradehandler.com
api.upgradeinput.com
api.webmemoryagent.com
api.whywarbler.com
api.wisercomputers.com
www.apple.com-care-macbook-system.live
www.aww799.com
www.enginetransaction.com
www.logicalhandler.com
I'll see to continue testing the rest of the list later and report back
Test results of remaining URLs, all the green ones have # sign in front of it,
the others have at least one detection, sometimes
there were more engines detection malware and/or phishing.
api.initiatormaster.com https://www.virustotal.com/gui/url/73e61c450b8ac6dcbf438a808e174d4d1a33436b52ea80e621fed848297d9aa8/detection
api.initiatormode.com https://www.virustotal.com/gui/url/b82b48e4dfa03898605b7ca87db62653c85184bd233d19b079063fc0243c09ac/detection
#api.insidetechmac.com https://www.virustotal.com/gui/url/12fd8fff4b5c50de4d49f47a462c4a4dd25fb2e29907e5d3d5c403c189acd7d8/detection
api.internetalgorithm.com https://www.virustotal.com/gui/url/8956b91f534818febd783eee987211c43606fc3147294c058523fd207b67d062/detection
#api.internetinterop.com https://www.virustotal.com/gui/url/91e2fa00763feb11c8e507666a806858437e9e63a0024dca9a79039e2df95eeb/detection
api.interopcache.com https://www.virustotal.com/gui/url/5feeb9ebbf8cf4af5955e59e9578f29badb5ebaa02d973746c7fd5733d2c6232/detection
api.lightthemacup.com https://www.virustotal.com/gui/url/e9923a59cd6208ca3d1394ed8661b3b60f35da10d93f84eae769e9a10c0c1870/detection
api.locatorbasic.com https://www.virustotal.com/gui/url/47e153bf3681442fc33d0f9886cb144983d0e5fa305a179b93566933a84b0fb4/detection
api.locatorformat.com https://www.virustotal.com/gui/url/3f0ff3db7f301ce0d76a61fcd48e2c118fcf28546f47fc77ce7bbdb38289a788/detection
api.macfantsy.com https://www.virustotal.com/gui/url/23553045015e4df6ac7db7981d675c4da71669066faea2b1007fe226822e3a49/detection
#api.macmagnificent.com https://www.virustotal.com/gui/url/90b3f5506d526eb2e3841501622c3c0c93e28c3bd73b4a40334fa6c9abcd7370/detection
api.macsatmosphere.com https://www.virustotal.com/gui/url/ac3c35bc5a7df9debcd482c8bf2295c1f1866a937ebeb9658f05597ec17c119e/detection
api.macsinsights.com https://www.virustotal.com/gui/url/d22d76e32f42b6d413fc2750bf718dd2b7b786019f99c43de61a3b1bd68a7859/detection
api.macsmoments.com https://www.virustotal.com/gui/url/9a4748b3eb66773c165f8824845ad54603779e3575a7bb214d103c0b14ac45ad/detection
#api.majorqueue.com https://www.virustotal.com/gui/url/8b3d39e5187bef363141dee2c092a384a9241b3aa6b76f1b4e250aaf853c74a2/detection
api.managerscalable.com https://www.virustotal.com/gui/url/5895fb2c88172efcdbe5835fdec3269ea2b97c57508c1cb6ef24a34ad22b409c/detection
#api.managerwebmoves.com https://www.virustotal.com/gui/url/5d9b441a495af22e3bf48e0e9897c77a2b168bafe9456d2137c36a20562a13f0/detection
api.megaformats.com https://www.virustotal.com/gui/url/ef437e788bdd1e70a76b96f2a749e9921deaace7fa2f67ee007f72b2d89222f0/detection
api.megamodule.com https://www.virustotal.com/gui/url/a66dacd061d18b47842e52309809b9a5e699e636c369006d1f565775d468f4b2/detection
#api.metroorigin.com https://www.virustotal.com/gui/url/9fdc92344385a24a3ed75c7373667428e1e8c26a555479b2eefba7c22ce0f5c6/detection
api.nanodevsource.com https://www.virustotal.com/gui/url/ead64938bf99081295edc99f00562bcb65403521e7298bab84c5af4e8504ca68/detection
#api.nanoscheduler.com https://www.virustotal.com/gui/url/6791ecef9d8a594aa3480fd1f4def5cb04f84af9876c2851aec964b4fc432b03/detection
api.operativdata.com https://www.virustotal.com/gui/url/d743576a22a2a989df8651441d08047e73b1fd5790634701f829646dc0f837eb/detection
#api.operativebox.com https://www.virustotal.com/gui/url/13bfc78443300fa4f7bb88927714be92cbbe54d668bfc203839928efd948a88f/detection
api.operativeguides.com https://www.virustotal.com/gui/url/933109c95f500175bc880e81a07c42191868d11d4a1ab3adccfb18d86bda80cc/detection
api.opticalmode.com https://www.virustotal.com/gui/url/5acd19b692ed962fcf1139fbd8ce93de44094c1babb19681b6f677836aea05cb/detection
#api.opticalsample.com https://www.virustotal.com/gui/url/cadd0065e176511bbdbcb26d2fd6810a86f9e142c55e65d82cb33976f1397005/detection
#api.optimalcache.com https://www.virustotal.com/gui/url/62bc763fb2c18e8cc33dc5d758a4816df9f0bbaaf5483905bca3d84c875846cd/detection
#api.originassist.com https://www.virustotal.com/gui/url/4073b4bb8e3ad2dc0f229128305d833fd798e6513e56c0f1e36bdf53947008fe/detection
api.originmodule.com https://www.virustotal.com/gui/url/5ed99721e5984d3d529eb7b20d87315eb03a12294606c2d4f97c568dc51a0a84/detection
#api.partitionnet.com https://www.virustotal.com/gui/url/2cfd9af46691642a001c895136498fde90dcfa978fb1d9916b006fc7dd366a04/detection
api.portalconfig.com https://www.virustotal.com/gui/url/c03bfcda9ca3e72d5ee9ee07efe028591644987ff13147497f51d725af258fbf/detection
api.portalelemnt.com https://www.virustotal.com/gui/url/50e134a0f9cb84d2cf487769228ebb9b318d16fb09221e548d04bfc1fc4bdbd9/detection
#api.portalqueue.com https://www.virustotal.com/gui/url/86dd249f8a3d836b2f8011ed3bf082462c1b95cac487810cc7c1ad9773908c6b/detection
#api.primarymodes.com https://www.virustotal.com/gui/url/93b48ee6abe7c50441222e7ceb93f818d48e2f47b123009a2d758b747652097e/detection
#api.primarytransaction.com https://www.virustotal.com/gui/url/d34c91ac2c820dc1dac9767984d44ab4b6961d496db083f20f18fef6f62f2686/detection
api.processbuffer.com https://www.virustotal.com/gui/url/705ba10182257bbbfbf4e07e27c422fffc96a55a0c1f16f3ad2c39dccfcb08d9/detection
#api.processerdev.com https://www.virustotal.com/gui/url/127f64213526c8d1e4d44fd2b4adbd649ca664294ecb3fff14cd407a98d42592/detection
#api.processformat.com https://www.virustotal.com/gui/url/e2b5a1100c03122fd8ca65fffd8890b5b59016c135b06aa36de53a3f667fb017/detection
api.publicanalyser.com https://www.virustotal.com/gui/url/a5ffec456a528c32997fd3415613c07b8fb862df1e9a189d6712ab16e0565791/detection
api.publicconfig.com https://www.virustotal.com/gui/url/c95888e868c85e0739a9eac3dee00e63fbc6165bdddb4e23940ece89de3a330c/detection
#api.remocreature.com https://www.virustotal.com/gui/url/d7730dfb850ab41b2aab8bc0e24c9fad18a8b2bef315d65155ccbbba105318b1/detection
api.resultsformat.com https://www.virustotal.com/gui/url/7aed8a1f956352b582c81006f7f2131e04720b6b33f6995c82f29c70fdfefacf/detection
api.rotatorbit.com https://www.virustotal.com/gui/url/9fb9eeb561c0b365696855c4df40adf38c460f966f2eaeed6d21ceb314348e03/detection
api.rotatorsample.com https://www.virustotal.com/gui/url/2ccf8d5efb554190ba50b01afb929c07d3d5c61916a0491284cea5e2c5820f77/detection
api.servereng.com https://www.virustotal.com/gui/url/7890f2e1c296a7c50161c4351b7764fc9f5d99862c4ba005e72ed7d2d2956646/detection
api.servicequeue.com https://www.virustotal.com/gui/url/967d751839a7ed7962370f0b3ceffd25db3fc0756c13ce284386cab32d607d14/detection
api.setwireframe.com https://www.virustotal.com/gui/url/1f5fa3d34ef265fa9f6c65d50d6136d70aa5e24b7272a10a8fb08c6db1146e04/detection
api.sharedanalyser.com https://www.virustotal.com/gui/url/03cb24a49f0cfd3262296d0c279ed09fcbbdf9b86d2aa6c48bada6550ef45280/detection
#api.sourceremote.com https://www.virustotal.com/gui/url/c7da279dccd9418ad09d69646c0e16d6e254b090bf9ac6b5205f30f0e7e6b492/detection
#api.syncindexer.com https://www.virustotal.com/gui/url/bdf2a236af9b2af5cf418aeb710d2493ca752d90a0a357869729362c1f8e440a/detection
api.syncpartition.com https://www.virustotal.com/gui/url/76e75034d4a2c523d2e25d1fec60a6fec3d232c0b154de8d5a0f56cc1b750056/detection
api.taskupgrade.com https://www.virustotal.com/gui/url/fc2fa8531ad744ea095b0acc42a76c30fd39c7073f59d2079ce94ced8d2c7f61/detection
#api.technanoproject.com https://www.virustotal.com/gui/url/378dc9298d09c9ce638c8e5bc6cac4f04b79e2f566f9de6d00d30733b54008eb/detection
api.techsmaturity.com https://www.virustotal.com/gui/url/495ab4f854a0489f8508ece4f9cd418476d349ea7e32f70b8818955f01e65a36/detection
#api.timefornaps.com https://www.virustotal.com/gui/url/c45b57c0c1ee73c80f0994b1bf7c3fffdde55478d5ce00f48a3140a1e12c044d/detection
api.trackindexer.com https://www.virustotal.com/gui/url/6a1fd596332dd9b0da2af90864888f3b2f6a4cf33d3e6705b357a8742382e022/detection
#api.trustedadmins.com https://www.virustotal.com/gui/url/31daa8d57e9d4d6064e94c6c17115423e32460e5c90623770eda14705bf4f53e/detection
api.ultrabitinitiator.com https://www.virustotal.com/gui/url/e57da7a1efc272e53d46802f99dcfe124087ac5a604f0a66867e27d8bad27f04/detection
#api.updateelement.com https://www.virustotal.com/gui/url/e3a3c6d029b286f1f3ddafa29ff97e8a69b811478370f600a1269809491de2e9/detection
#api.updaterbasic.com https://www.virustotal.com/gui/url/290181569f3b33f89056a623519c718ebf80b6805419915865309ec1e76bed03/detection
api.updaterengine.com https://www.virustotal.com/gui/url/ed45540d9ef85e9077a915dde93e8ad163ce40d117499e25c97a1a88ae346f85/detection
#api.upgradehandler.com https://www.virustotal.com/gui/url/79608c6b07ae7b46a48448c3b6e3f8cc14815bae3ab525fb12bf1c6f5b040ce1/detection
#api.upgradeinput.com https://www.virustotal.com/gui/url/1dab3bcfd24c618263f76cc7d79d15dfe2d4b0faed134c4e4eb270bf41fcee40/detection
#api.webmemoryagent.com https://www.virustotal.com/gui/url/6968fb09b61da1e2178a1ebbd9546d472e241dd67fe30e4d69fbeeb90a3de921/detection
#api.whywarbler.com https://www.virustotal.com/gui/url/e8f5522b4d126092470e8ab1ce963b4e57589277fba2237fc9b78cc7c9de2fc8/detection
#api.wisercomputers.com https://www.virustotal.com/gui/url/6dea091567414ceb2853eed55102ad4549d0a9770cdc54f1600d09c757b987bb/detection
www.apple.com-care-macbook-system.live https://www.virustotal.com/gui/url/d9b6a69a3d6e6e3d7f8afacfb694cecacfadbfd9b5349849c50ba2a926a39aa6/detection
www.aww799.com https://www.virustotal.com/gui/url/c551506493153024a57b11926fadb81e0d617486bde43de7b39649eafc4dbcc7/detection
www.enginetransaction.com https://www.virustotal.com/gui/url/f78d7a9a83592f5da127b0143b3e66f730c4be9e6feb4612d25251175886f403/detection
www.logicalhandler.com https://www.virustotal.com/gui/url/fbb8f55c107f7b6b5ffcf1a93d4721a7244a9d5565f08161f083e681f046b18b/detection`
Thanks Sebastian @buzzdeee. I edited the above ^^^ for readability.
So if I understand correctly, the uncommented ones above are blockable? It's unclear what it means when you say "all the green ones have # sign in front of it.", above.
I'll pick this thread up in the morning. It's rather late here now (ETC), but thanks a lot for the contribution @buzzdeee
The "green" ones are the ones where none of the engines detected anything. For the rest, at least one engine detected this as malware or phishing.
This issue has been automatically marked as stale because it has not had recent activity. It will be closed in 14 days if no further activity occurs. Thank you for your contributions.
Closing.
Closing.