Looking at the SR here, there are two ways something could be flagged as 'malicious"
Given that the URL provided shows up as "Low Risk" in URL Filtering, it's in Threat Prevention.
Knowing exactly what blade is blocking your domain (shown in the full log card) will help.
TAC is where customers should report false positives in either case.
Providing this information to TAC when you open the case will ensure the issue is routed promptly and thus addressed properly.
In either case, you can create an exception for your domain in your local Threat Prevention policy.
However, I've confirmed that your domain should not be flagged any longer as malicious in Threat Prevention.