I think, if both sites got hit, they almost definitely share the same bad script or copied asset.
When you used httrack, you likely copied not just the visible page but also scripts, embeds, or links that were already flagged somewhere else. Google Safe Browsing doesn’t care how the code got there only that something on the page behaves like malware, phishing, or a deceptive landing page.
Go to Google Search Console - security Issues. That tells you what Google thinks is wrong (malware, phishing, etc.).
Clean the pages:
remove all external js/scripts you didn’t write
delete iframes, trackers, or weird redirects
scan your URL using virustotal.com to see what’s being flagged.
make sure your hosting isn’t infected (check for unknown files or injected code).
Go back to Search Console and request a review.
Look into that