Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BLOCK] joinmassive.com #2710

Open
r2fo opened this issue Aug 29, 2024 · 2 comments
Open

[BLOCK] joinmassive.com #2710

r2fo opened this issue Aug 29, 2024 · 2 comments
Labels

Comments

@r2fo
Copy link

r2fo commented Aug 29, 2024

joinmassive.com
api.joinmassive.com
geo-network.joinmassive.com
network.joinmassive.com

Why should these domain(s) be blocked?

Massive offers monetization SDK’s to developers to put in their Android app and Windows programs. This SDK will use the user’s internet connection as a proxy, in the past it used to mine cryptocurrency on the user’s pc too.

It seems like they use several subdomains under the joinmassive.com domain for C&C, but just to be safe I think it’s better to block *.joinmassive.com.

Their site advertises these services: https://joinmassive.com

This video features a deep dive into a program which uses the Massive SDK: https://youtu.be/_Q_F04Wd23k

@StevenBlack
Copy link
Owner

Thank you for this @r2fo.

We certainly won't list the root domain unless the root domain is directly used for conveying adware, tracking, malware, or worse. We aren't in the business of judging companies, and de-platforming those companies. We just try to block their heinous vectors.

Also, hosts files don't do wild cards.

What we need are specific domain names that are used to ferry the crap.

@r2fo
Copy link
Author

r2fo commented Sep 4, 2024

Thank you for this @r2fo.

We certainly won't list the root domain unless the root domain is directly used for conveying adware, tracking, malware, or worse. We aren't in the business of judging companies, and de-platforming those companies. We just try to block their heinous vectors.

Also, hosts files don't do wild cards.

What we need are specific domain names that are used to ferry the crap.

It seems like the SDK uses these domains for reporting back to Massive and receiving tasks

api.joinmassive.com
geo-network.joinmassive.com
network.joinmassive.com

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants