Disclaimer
What an entry means, and what it does not
ClickFixReport records dated observations reported by named sources. That sentence is the whole disclaimer; everything below explains what follows from it.
What an entry asserts
An entry says: this string appeared in this report, published on this date, by this publisher, described as playing this role in this campaign. That is a statement about a document and a moment in time. It is verifiable — the source is linked, and the exact string is required by a database constraint to be present in the copy of that source text we hold privately.
What an entry does not assert
- Not that anything is malicious today. An observation from March describes March. Domains change hands, get cleaned up, expire, get re-registered by somebody innocent, and end up parked.
- Not a judgement about a person or a business. We make no claim about the intent, competence or conduct of anybody who owns a listed host.
- Not an endorsement of the source’s conclusions. Where publishers disagree, we record that they disagree. We do not adjudicate.
- Not advice for your situation. The help pages describe what people generally do after pasting a command. They are not incident response, and they are not legal, financial or professional advice.
- Not attribution. Where a source names an actor, we record that the source named it. That is a fact about the report, not a finding of ours.
Many of these hosts belong to victims
This is the most important paragraph on the page. A large share of ClickFix lure pages are served from compromised legitimate websites whose owners are themselves victims — small businesses, charities, personal sites running an out-of-date content-management system. Their presence in this dataset is evidence that somebody attacked them, not evidence that they did anything wrong.
Every host carries an ownership assessment for exactly this reason, and the assessment governs what the site does with it. Compromised sites, shared hosting platforms and shared infrastructure never enter the blocklist export. Hosts that nobody has assessed show no verdict at all. The taxonomy is set out on /methodology.
This is not a blocklist
ClickFixReport is a reference index. It is not a reputation service, not a detection product, and not a feed designed to be piped into a firewall unread.
There is a blocklist export, restricted to hosts assessed as attacker-controlled, because defenders asked for one and refusing to publish it would not stop anybody building a worse one from the same data. If you use it, you are making the blocking decision, not us. Null-routing a compromised small business turns our record of their bad week into their outage, and no export file can make that judgement on your behalf.
Accuracy, and how wrong we expect to be
Extraction is automated and reviewed. It is not perfect, and we do not claim it is. A blind weekly re-check of a random sample of already-published entries, by a human with the original assessment hidden, is defined but has not yet run; the error rate it measures is published on /methodology whatever it happens to be. If you need certainty about a specific host, go to the linked source and read it.
Dates are also imperfect in a specific, predictable way: a first-seen date is the earliest date a source reported, which is usually later than the date the activity started. Read it as a lower bound.
No warranty
The site and its data are provided as is, without warranty of any kind, express or implied, including fitness for a particular purpose. Nothing here is a guarantee that a host is safe, or that it is dangerous. Decisions you make using this data are yours. The full text is on /terms.
ClickFixReport is not affiliated with, endorsed by, or speaking for any vendor, publisher or platform named anywhere on this site. Product and company names belong to their owners and are used to credit them.
How to dispute a listing
If a page concerns something you own or operate, tell us. There is no fee, no form of proof required up front, and no lawyer needed.
- Follow the dispute process, or write to corrections@clickfixreport.com. Include the page address and what is wrong with it.
- Where the claim is that a host was compromised and has since been cleaned up, or that it was never involved, the entry is suppressed the same working day, before we check. We would rather be quiet and correct than loud and wrong.
- A person reviews it and answers you either way within 10 working days. If the change alters what a page asserts, it is logged publicly with a date and a reason on /corrections.
- If we disagree with you, we say so and explain why, in writing. Disagreement is not silence.
One thing worth saying explicitly: suppression here does not clean up the original report, which is somebody else’s document on somebody else’s site. If a vendor advisory names your domain, that is the document to take up with the vendor. We will point you at it and get out of the way.