root 1 year ago
parent
commit
13d839688d
4 changed files with 1963 additions and 2320 deletions
  1. 457 608
      yoroi_malware_level1.dns
  2. 1164 1620
      yoroi_malware_level2.dns
  3. 262 11
      yoroi_suspicious_level1.dns
  4. 80 81
      yoroi_suspicious_level2.dns

File diff suppressed because it is too large
+ 457 - 608
yoroi_malware_level1.dns


File diff suppressed because it is too large
+ 1164 - 1620
yoroi_malware_level2.dns


+ 262 - 11
yoroi_suspicious_level1.dns

@@ -9,6 +9,268 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+fxhtrxxxkdjuhfjxhk.weeblysite.com
+www.bankofireland365.ie
+usps.mytrackingr-ro.top
+home-107866.weeblysite.com
+usps.mytrackingrn.top
+ups-tracking-id22301.package21.support
+trust-wallet.com.ng
+nhftjq.blogspot.sn
+hbrtnv.blogspot.hr
+nhtjfc.blogspot.hr
+segurospersonasbancolombia.brizy.site
+uspw.usspaky.top
+bhrtfc.blogspot.md
+irntoken-va.run
+usps.qlljljxqoo.top
+usps.mytrackingrm.top
+usps.oljjmwoqhk.top
+uspw.usspajg.top
+tpwallet.digital
+b.nmlgbd2.cyou
+irntoken-ve.run
+irntoken-vb.run
+scbfsteel.com
+gfhfghdhgf.fyfyvfytvghv.workers.dev
+layananbantuan-danaid.dydd67.biz.id
+fdda.mati.workers.dev
+irntoken-vd.run
+trhmyj.blogspot.lu
+ntrhvg.blogspot.is
+dex.nexis.network
+dgnrht.blogspot.ug
+muddy-surf-435e.thr482fi1e247.workers.dev
+jkghjj.kolomo.workers.dev
+ndrhx.blogspot.is
+mtfjv.blogspot.bg
+discord-proxy.quanxiaoning.workers.dev
+kosiarki-malinowski.pl
+www.mikksoft.com
+fmhjyg.blogspot.sn
+wbrgh.blogspot.am
+app.points-aave.com
+khmer-pornvideo-cambodia.web-asia.net
+offer-opensea.site
+long-mouse-1e1d.nguyenchong9455.workers.dev
+segera-tukarkan-poin-dana-anda.verifikasimeta.com
+hmtfj.blogspot.sn
+sdmje.blogspot.md
+ghfnjt.blogspot.hr
+fdmht.blogspot.sn
+hntfq.blogspot.lu
+dzsrq.blogspot.am
+west.linktwin.solutions
+login.ms-connect-office.com
+today-currently-24-3-24.weeblysite.com
+yahoo.sotrafirze.workers.dev
+facebook.loginsform.com
+kers-gr-wild-fog-6989.masayoschinuki.workers.dev
+www.sizlereozel-firsathemenbasvur01.cloud
+btwb-106629.weeblysite.com
+midasbuy-worker.newseventpubgmobile.workers.dev
+trhmyj.blogspot.am
+tiktok-fast.newseventpubgmobile.workers.dev
+mtfjyb.blogspot.am
+dzsrq.blogspot.is
+mtmgc.blogspot.sn
+dnhht.blogspot.lu
+dzsrq.blogspot.li
+xva4ra.kv-f.biz.id
+pemvhh.badp4r.biz.id
+worker-late-band-e583.newseventpubgmobile.workers.dev
+businessmetaassistance.com
+3ogd.h4dir.com
+bhtrcf.blogspot.lu
+jmykug.blogspot.lu
+fbthbg.blogspot.am
+ionds.club
+immediatelyv3rif1icationneeded.com
+imtoken-ps.pro
+apple-id-ios-us-62.top
+bt-101851.weeblysite.com
+muddy-moon-71b4.soznvztbmy1542.workers.dev
+mdfgw.blogspot.md
+mhtfz.blogspot.hr
+podsfrica.com
+ups-tracking-id43658.package21.support
+hvthgb.blogspot.is
+www.login.ms-connect-office.com
+hntjb.blogspot.hr
+mftjv.blogspot.bg
+sdmje.blogspot.hr
+square-mode-abc0.bcnk.workers.dev
+wwe.sdfh5rt.cloudns.biz
+lebocoin.groupe-cibc.com
+wwe.fgjdtr57htc.cloudns.biz
+sukienfreefire-hungakira.ff-garenaa.io.vn
+hello-world-sparkling-river-9941.cafyidelmo.workers.dev
+zazadayimdam.xyz
+reckx.cc
+bafybeifmsnij64zcsvoklm4nggsn4qck5caapjn7lsyrdnodt66swiwzdy.ipfs.fleek.cool
+yenib71.top
+yunzhangx2.cn
+privateaccess.ru
+imtoken-bm.net
+tgadminuser.webptt.xyz
+telegram.webcsc.wang
+telegrom-ut.sbs
+urkedxa.com
+tgadminuser.web-tgg.xyz
+fclogin.pro
+tgadminuser.webttg.wang
+nhrtvb.blogspot.lu
+token-pocket.net
+urkedcx.com
+tokentt.app
+urkedxj.com
+urkedck.com
+uspw.usspakt.top
+urkedcc.com
+urkedcg.com
+ukfeajt.com
+urkedxf.com
+fnhtjc.blogspot.am
+telegram.webttg.vip
+b.3656240205.top
+erneuern-phototan.app
+urkecyu.com
+usps.posttrackingcenter.com
+www.yowbgkb.cn
+flavianunes.com
+usps.posttrackinginfo.com
+www.rigobag.com
+www.rppcct.com
+applelrcom.shop
+aktifkaan-paylaterrr.resmii-id.net
+telegrom-up.com
+w.bghnt.icu
+galaxies.mantaprotcols.network
+www.azqmgqm.cn
+www.bwdgqtr.cn
+nhftx.blogspot.sn
+nnkui.blogspot.is
+gdbrh.blogspot.sn
+tokegp0cket.top
+b.36562402062.top
+www.klaxwpy.cn
+aktifasi-akun-dana.resmi-vip.art
+b9464.top
+www.japanpost.gqzfxtk.top
+macontravention.review
+whsatapp-aa.cc
+tokevp0cket.shop
+391968.com
+att-102182009.weeblysite.com
+365aak.com
+cbrgbw.blogspot.li
+fnthd.blogspot.li
+www.dnrgth.blogspot.am
+telegrinm.work
+process-request-update.site
+mftjze.blogspot.sn
+bgercv.blogspot.ug
+bfgjy.blogspot.md
+trezor-io.sonidomuller.cl
+bt-internet-106032.weeblysite.com
+volksbankwien.kontenwechsel-sandbox.at
+petruscs.162-240-158-232.cprapid.com
+bgerhv.blogspot.md
+mhftjg.blogspot.li
+brhtcv.blogspot.am
+crghtb.blogspot.li
+trueindeed.store
+lloydsbankhelp.com
+iim-token.cc
+2164849856218546.cloud
+starhost.cloud
+steamconmunlty.com
+telegraw.ru
+cbfsd.blogspot.am
+ffhtc.blogspot.am
+bdsrg.blogspot.ug
+cvqht.blogspot.lu
+www.ghrntb.blogspot.si
+bdsrg.blogspot.hr
+attserrvicee.weeblysite.com
+home-105525.weeblysite.com
+shengzejs.com
+kkynh.blogspot.is
+rr3651111.com
+aerobatics4you.com
+butpo.choiseprog.xyz
+ghrntb.blogspot.si
+jymjm.blogspot.am
+cbrgbg.blogspot.is
+fnhjt.blogspot.md
+mtyjn.blogspot.hk
+nhanquaff.gaerna.io.vn.fxjzdxtv.nethost-1111.000web.xyz
+home-108819.weeblysite.com
+usps.mytrackinged.top
+5510001.com
+worker-misty-voice-d615.qudusmusiliu8.workers.dev
+pre-autenticacaoprotocolo.online
+contoh-bbbriii.fetz.biz.id
+afuturekent.co.uk
+casino-met-paypal.com
+ussp.uspim.top
+gdbrh.blogspot.am
+bfentq.blogspot.am
+gberhc.blogspot.sn
+mzfjb.blogspot.lu
+rdqfg.blogspot.lu
+bfgjy.blogspot.hr
+www.jzmepp.com
+blackstonechamber.com.pk
+sheet-queen-3851.ryleeeasley.workers.dev
+chare-docs-a528.rdleajodex.workers.dev
+mmskshelp.com
+www.nhanquaff.gaerna.io.vn.fxjzdxtv.nethost-1111.000web.xyz
+hello-world-wispy-night-89f4.givititas.workers.dev
+officedde6c95dd507ff48b539d60eff26b5dadde6c95dd507ff48b539d60ef.theinspectiongroup.workers.dev
+fmhjs.blogspot.is
+telstra-104928.weeblysite.com
+att-106434.weeblysite.com
+meta-mask.trade
+www.avviso-direttive.com
+myupdate.us
+document.files-shared-secure.workers.dev
+billowing-morning-f51f.kokoda1.workers.dev
+att-mail-108587.weeblysite.com
+att-service-108697.weeblysite.com
+fmtvb.blogspot.am
+telstra-108229.weeblysite.com
+wpyv.net
+autodiscover.growtheory.co.za
+hp-capacity-api.com
+verification-102983.weeblysite.com
+att-108680.weeblysite.com
+web-facebook.com
+mail-106990.weeblysite.com
+188bet24.com
+security-statementavailable.publicvm.com
+mail-shape-577a.dasbord1.workers.dev
+3659e.cc
+vhnttf.blogspot.hr
+vbnhgt.blogspot.sn
+vtbhjr.blogspot.sn
+vbgncf.blogspot.is
+federicocastaneda.com
+telegrmp.fit
+pancake-swap-airdrop.com
+jmgyjh.blogspot.sn
+angjq.blogspot.am
+fnhtj.blogspot.ug
+bfgjy.blogspot.is
+angjq.blogspot.bg
+albrightinstitute.replit.app
+activardinamicabancolombia212141.brizy.site
+www.japanpost.uibtvnw.top
+www.mxybsq.com
+inc-102668.weeblysite.com
+urkecvj.com
+urkecmt.com
+miraclecamstudio.com
 west.linktran.skin
 wwr.friday8723.cloudns.biz
 uspe.usspaut.top
@@ -120,11 +382,6 @@ offer-opensea.link
 ukfeajy.com
 pencairangiveaway10juta-dana-lndonesia.verifikasimeta.com
 workcoinpay.com
-urkecyu.com
-usps.posttrackingcenter.com
-www.rigobag.com
-www.rppcct.com
-www.yowbgkb.cn
 www.brookstrainers-uk.com
 84n-mail-att.weeblysite.com
 metamask-wallet-5bfp.onrender.com
@@ -237,8 +494,6 @@ tokenpockot.org
 bfthjy.blogspot.is
 ups-tracking-id43043.package0.support
 www.nuevaropafb.space
-erneuern-phototan.app
-usps.posttrackinginfo.com
 decentralizedfix.click
 telegram-25.group-xnxxx.com
 telegram-24.group-xnxxx.com
@@ -262,7 +517,6 @@ bat.yu-112-ink.xyz
 5fgfgfgfg4g4g4gfg4fg.blogspot.al
 5fggfgfgrfg4g4gh4hf.blogspot.lt
 emirowski-autohandel.com.pl
-inc-102668.weeblysite.com
 dana-service.mediaflre.cfd
 telegram-26.group-xnxxx.com
 ftmhjr.blogspot.sn
@@ -859,9 +1113,7 @@ uspz.usspapl.top
 uspz.usspaoy.top
 uspz.usspapd.top
 uspz.usspaos.top
-urkecvj.com
 urkecvr.com
-urkecmt.com
 uspt.usspaqg.top
 uspe.ussppv.top
 uspu.usspaez.top
@@ -1033,7 +1285,6 @@ mijnomgeving247.cleansite.us
 mail.traidatakpkredikart1.com
 polskawiadomosci-krajowewp.pl
 polskawiadomosci-krajowewp.com.pl
-flavianunes.com
 axcembocadmaifxcoponline.hnaijny.cn
 log.rumnwise.net
 pushreaktivierung-spk.xyz

+ 80 - 81
yoroi_suspicious_level2.dns

@@ -9,85 +9,58 @@
 # Category        : Suspicious
 # Confidence      : 8
 #
-trying-toclone.surge.sh
-mail.43-153-212-205.cprapid.com
-usps.mytrackingr-al.top
-usps.mytrackingr-vt.top
+nhdaua-8845.etezmraleietk.workers.dev
 03us9uls9ps.us
 120812336.com
 207647.com
 356623.com
-atualizacaocadastro.app
-b9700.top
-brfcoin.com
-ebay-009.com
+azamataxrorov.com
+b5096.top
+bjamst.com
+bjtssm.com
+cqcmsc.com
 generalgaming.ca
 giveskins-cs2.com
-hp360dapp.com
-iwri2f.krafton-news.com
+help-center-324235.click
 iwujiwu.com
+kklaim-danakagett-id.dydd67.biz.id
 l551000.com
-lutendre408.sbs
-msvcoae.com
-niscober.click
-offer-network.one
+paris-to.com
 rakiuten.lqtru.cn
 rakutan-bak05.cyou
-rr04327.com
 suomiasiakaspalveluyhteystiedot.com
+surajbal.com
 t89xrw9.com
 teiegrom-xd.com
-telegamrm.com
 telegarc-fki.com
-telegarn-czb.com
+telegamrm.com
 telegcde-jrt.top
-telegeram-py.com
 telegcwo-mht.top
+telegeram-py.com
 telegram-xa.com
 theblueskytrading.com
+tjhxyl.com
 tok2npo2knt.top
 tok2np0cklt.top
 tokenpakket.com
 tokenpocket-tpemk.com
 tokexpocket.com
 uf1j-ba3k.cyou
-urheacr.com
-urheacq.com
-urheafb.com
-urheafh.com
 urheafv.com
-urheahf.com
-urheakd.com
-urheagt.com
-urheafj.com
-urheagj.com
-urheakq.com
-urheaku.com
-urheash.com
-urheasd.com
-urheask.com
-urhebaq.com
-urhebht.com
-urhebry.com
-urhebst.com
-urheanr.com
-urhebru.com
-urhebtj.com
-urhebtg.com
-urhebee.com
 urkeajr.com
-urkeaqy.com
+urhebht.com
+urkeatz.com
 urkeaus.com
-urkeawa.com
-urkeabk.com
 urkeawu.com
+urkeaqy.com
 urkeatc.com
-urkeatz.com
+urkeawa.com
 urkeayt.com
-usps.mytrackingur.top
-usps.mytrackingyv.top
-usps.inspectpost.com
+usps652.com
 uspscheckshipping.top
+uspsuxe.top
+usqxj.top
+usxep.top
 www.bkljv.cn
 www.bseqk.cn
 www.ksmyeituopw.net
@@ -97,13 +70,68 @@ www.yunsor.cn
 x98ultratvonline.com
 zxcgrdh.com
 zzjinneng.com
-instalariantene.com
+boc-helpline.com
+brfcoin.com
+hp360dapp.com
+iwri2f.krafton-news.com
 jshtr.com
-kklaim-danakagett-id.dydd67.biz.id
-surajbal.com
+jskaixinda.com
+offer-network.one
+sesliroman.com
+urheacq.com
+urheacr.com
+urheafb.com
+urheafj.com
+urheafh.com
+urheahf.com
+urheagj.com
+urheakd.com
+urheakq.com
+urheaku.com
+urheanr.com
+urheasd.com
+urheash.com
+urheask.com
+urhebaq.com
+urhebee.com
+urhebru.com
+urhebry.com
+urhebst.com
+urhebtj.com
+urhebtg.com
+urkeabk.com
+usps.inspectpost.com
+usps.checkuspsg.com
 usps.czjhnifskr.top
 usps.mytrackinguq.top
-usqxj.top
+usps.mytrackingur.top
+usps.mytrackingyv.top
+usps.mytrackinguw.top
+uspsurp.top
+genniappdeliverynows.valkyrie33.workers.dev
+worker-royal-glade-5fd0.rmtllc.workers.dev
+asset-meadow-2e67.karsonjacobsen.workers.dev
+telstra-100517.weeblysite.com
+telstra-109941.weeblysite.com
+apmcleaning.com
+b9700.top
+biz652.biz
+instalariantene.com
+lqruiyaosm.com
+lutendre408.sbs
+millennium-online.com
+rr04327.com
+urheagh.com
+trying-toclone.surge.sh
+mail.43-153-212-205.cprapid.com
+usps.mytrackingr-al.top
+usps.mytrackingr-vt.top
+atualizacaocadastro.app
+ebay-009.com
+msvcoae.com
+niscober.click
+telegarn-czb.com
+urheagt.com
 restless-water-f17b.egtzv7vgjhvg8n4.workers.dev
 standarappdailydemonows.jazel19.workers.dev
 auth-ourtime.datings-progres-member.workers.dev
@@ -111,35 +139,17 @@ blue-recipe-deaf.jamopara00.workers.dev
 att-service-107783.weeblysite.com
 bt-104089.weeblysite.com
 cfkyb0.webwave.dev
-boc-helpline.com
-help-center-324235.click
-jskaixinda.com
 mettle-newaccount.com
-millennium-online.com
-sesliroman.com
-usps.checkuspsg.com
-usps652.com
-usps.mytrackinguw.top
-uspsuxe.top
-uspsurp.top
-usxep.top
 tmpkyb.cn
-tjhxyl.com
 a.fromnotion7101.workers.dev
 adobeemode-17e9.saratebulmerl.workers.dev
 outlook-server.gorkakirtu.workers.dev
 worker-autumn-moon-9c58.kentkj.workers.dev
-biz652.biz
-bjamst.com
-paris-to.com
 usps.checkuspsa.top
-cqcmsc.com
-lqruiyaosm.com
 lygygy.com
 hello-world-shrill-recipe-b56d.yorox63274.workers.dev
 normapugpradeonwstartmow.access3057.workers.dev
 polished-rain-663c.15338853300.workers.dev
-b5096.top
 buildersplus.store
 chinadigitaltax.com
 xprotection.net
@@ -2278,7 +2288,6 @@ www.mcnidkm.cn
 www.pziowie.cn
 yahoo45456.wendy-fane.workers.dev
 mmthg.blogspot.sn
-orange-sso.com
 www.nnokdld.cn
 www.ngifday.cn
 www.mko7xd.cn
@@ -2422,7 +2431,6 @@ jiedingly.com
 fuawy.com
 fafaok.com
 ahisoccc.com
-bjtssm.com
 subdomainnequiposupor13j.royalwebhosting.net
 www.support-common.click
 www.smcc-card.com
@@ -2864,7 +2872,6 @@ usps360.top
 www.sukienhotfreefire.garenea.io.vn.fxjzdxtv.nethost-1111.000web.xyz
 allegrolokalnie.oferta2478.pl
 ff4e7854.kortfilmfestivalen.no
-apmcleaning.com
 tiscali-108446.weeblysite.com
 wetransfer-fichierencourspageorang2.hubside.fr
 www-web-oranmail-orm.hubside.fr
@@ -3994,7 +4001,6 @@ www.xdfukwd.cn
 evaly.uk.kashboncourier.com
 www.evaly.uk.kashboncourier.com
 www.pumbly-dad.com
-azamataxrorov.com
 www.159-65-38-201.cprapid.com
 attmail6686.urest.org
 h0me79809.weeblysite.com
@@ -4130,7 +4136,6 @@ att-mail-107032.weeblysite.com
 att-mail-108180.weeblysite.com
 att-100249.weeblysite.com
 att-mail-105533.weeblysite.com
-nhdaua-8845.etezmraleietk.workers.dev
 usps.postaftership.com
 edevlet-mobilbanka-girisgovtr.app
 docs.od7gf9q2364.com
@@ -4512,7 +4517,6 @@ www.ff-member.grarena.vn
 netzero-webmail-108087.weeblysite.com
 vali-2h1.srabrshknsoskg.workers.dev
 imtoken-web.homes
-telstra-100517.weeblysite.com
 distribution-manta.events
 mail-106957.weeblysite.com
 telegram.webatt.ren
@@ -4592,11 +4596,9 @@ qvdgr.blogspot.li
 5gfhfgegeg3f3f3f3.blogspot.md
 bsdgn.blogspot.sn
 telstra-104786.weeblysite.com
-telstra-109941.weeblysite.com
 hkl4tz.relzhost.biz.id
 inboxx-89f1.nkbrehmyetae.workers.dev
 home-white-field-a130.gokisax566.workers.dev
-genniappdeliverynows.valkyrie33.workers.dev
 mesdeofertas.top
 bdfhc.blogspot.tw
 sdh3w5w3sde.blogspot.sn
@@ -4761,7 +4763,6 @@ www.ygzzzgj.cn
 avxbf.blogspot.sn
 www.zoatqsj.cn
 rbnrm.blogspot.qa
-asset-meadow-2e67.karsonjacobsen.workers.dev
 a.3656240210.xyz
 aolmaiillogin.blogspot.mk
 telstra-100007.weeblysite.com
@@ -6607,7 +6608,6 @@ urheagu.com
 urheagk.com
 urheags.com
 urheagf.com
-urheagh.com
 urheage.com
 ustnkps.com
 urheagd.com
@@ -6726,7 +6726,6 @@ worker-falling-sun-89a6.robertgintherr.workers.dev
 worker-bold-hill-a3bf.piydufukka.workers.dev
 sp228731.sitebeat.crazydomains.com
 worker-fancy-moon-50fc.elley740.workers.dev
-worker-royal-glade-5fd0.rmtllc.workers.dev
 summer-bread-0a54.xvv.workers.dev
 shy-base-58c5.1paopefj.workers.dev
 secure-pub.fofiduga.workers.dev

Some files were not shown because too many files changed in this diff