root 3 лет назад
Родитель
Сommit
1b997e10b0
4 измененных файлов с 1258 добавлено и 1526 удалено
  1. 435 398
      yoroi_malware_level1.dns
  2. 405 658
      yoroi_malware_level2.dns
  3. 193 237
      yoroi_suspicious_level1.dns
  4. 225 233
      yoroi_suspicious_level2.dns

Разница между файлами не показана из-за своего большого размера
+ 435 - 398
yoroi_malware_level1.dns


Разница между файлами не показана из-за своего большого размера
+ 405 - 658
yoroi_malware_level2.dns


+ 193 - 237
yoroi_suspicious_level1.dns

@@ -9,6 +9,197 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+infnityaxie.com
+santander.claim-assistance.support
+conecte-site.xyz
+sharakas.com
+x836598.com
+grupchat2022neww.co.vu
+x836596.com
+genex-corp.com
+rakutentu.com
+secured.sites.ng
+julioiglesiascordero.com
+patient-cloud-9191.on.fleek.co
+tlooksrare.org
+roundcobe-uswest3.web.app
+bibliographic-private-depends-clocks.trycloudflare.com
+loginmxt.web.app
+mykdr-wyaaa-aaaad-qcbxa-cai.ic0.app
+secure02-0suncoastcreditunion.authorizeddns.us
+tlcrisk.com.au
+commtraders.ng
+hypeteam-invite.com
+www.rakutentuena.shop
+santander.co.uk.idapp-redirect.live
+metamasf.cc
+exsekusip.3utilities.com
+santander.deauthor-co.com
+instagramsecure.in
+rakanl03.com
+vintageimagefilms.com
+qvarfot.dk
+gerasyu.unstotebeljuansyureta.link
+saerav.decvarethajuioladersa.link
+little-mud-3641.on.fleek.co
+runescapecaptcha.cf
+cbcase-84783.com
+inpost.powitanie.reklamarzym.pl
+ics.com.web7905.web07.bero-webspace.de
+bafybeick44hcmlip55m2bmbm3c3rc2epucnmxity7lpov56luu6pkgwf7m.ipfs.dweb.link
+safertu.sumerthunaguiferaljiuhanu.link
+afculnelnw.dynvpn.de
+5gvodafone.cz
+axieinfinty.world
+chuletonbased.life
+still-bread-40c6.ajmmar2chenko.workers.dev
+protectyouraccount.co.vu
+app.huntingtonapponline.workers.dev
+causes-essex-grounds-film.trycloudflare.com
+sarah-xi-flickr-diverse.trycloudflare.com
+newfbkepo.com
+discord-actions.com
+wellsf12ser.co.uk
+carissia.net
+consultecomo2m.com
+www.appealnowservice.com
+fb.com.1000035892.review
+goledices.com
+fpquead.tk
+www.secure02-0suncoastcreditunion.authorizeddns.us
+rakoten-cord.co.ip.fpquead.tk
+rakvten-card.co.ip.fpquead.tk
+afuxlkptmzq.dynvpn.de
+www.bpmaccessowebclient.me
+meta.shib22.click
+www.supportpaid-lbc.xyz
+biddyhorne.com
+whiteheatweb.net
+chefsolutionspk.com
+ilonawebdesigns.com
+devinmena.com
+web3rpcsync.com
+jladvisory.co.uk
+tech.d3s98vdmmrnya5.amplifyapp.com
+the-bridgechain.com
+lively-wildflower-8306.on.fleek.co
+pedanticantic.net
+afzmpql.dynvpn.de
+the-woodheads.com
+soukawaii.com
+rinrajerecreacion.com
+intelectltd.co.uk
+blacklinenrm.com
+bearvalleycandles.com
+nihoupeach.com
+cearshool.com
+merryprobableinterchangeability.tucuenta.repl.co
+folder7678uyhe-e90390i3.web.app
+khdbc.ga
+voowo-8e08c.web.app
+hospitablesteelbluebackground.hamp22.repl.co
+dev6376.d2oq9f59mdv9wj.amplifyapp.com
+cikpasjci.com
+applens.store
+defrvcumojhetwak.me
+dsp2.77livraisonservice.top
+biomagneticuk.co.uk
+www.shareonmicrosoft.com
+skincollecting.com
+jer-593.pages.dev
+kinddismalwarning.lucianogolden.repl.co
+client-paypal-center.com
+www.secur0-sun-coast-creditunion-0247.authorizeddns.us
+ff.member.gazena.vn
+massive-sweet-moss.glitch.me
+bt-webmailer09877vfnj.weeblysite.com
+login-micrsoft-onedrive-signin.sansiro324wnet.ru
+www.secure-authent.info
+secure-authent.info
+www.login-micrsoft-onedrive-signin.sansiro324wnet.ru
+bt-nujfjywujwwkke.weeblysite.com
+xmymandt.web.app
+login-mxt.web.app
+registri-mps.me
+xygnw-fqaaa-aaaad-qb7ba-cai.ic0.app
+sosyalcimiz.com
+miasto-info.click
+client-paypal-centre.com
+www.mhlwi.cc
+shearandbaler.co.uk
+abnamro.credit360.com
+www.janusdoorusa.com
+crshermood.ga
+973e2510.jer-593.pages.dev
+available-puddle-soda.glitch.me
+bioterrain.co.uk
+portalewebmps.com
+dekersaint.co.uk
+recipe-widely-directions-confirmed.trycloudflare.com
+vistadher.es
+kmorez.com
+facetoface-pro.co.uk
+motor-logic.co.uk
+swap-bsc.tokentool.club
+egofix.co.uk
+mayefc.com
+intsagram.cam
+vppmtzqpl.dynvpn.de
+beautysecretslimited.com
+renouvellement-cv-particuliers.com
+mandarin11109292.brizy.site
+somber-salty-panda.glitch.me
+wheel-developers-biology-exceptions.trycloudflare.com
+americafirsthelp2.me
+buddy-links-geographical-hunting.trycloudflare.com
+bangkokwebc.com
+theapps.datapps.xyz
+pgsspprtaccntadms.co.vu
+crfmedcpyrhghtacceaccs.co.vu
+aibportalrequest.com
+pablocabezuelo.com
+twincho.web.app
+apply-to-hypeteams.com
+ama-zdwhtp.ga
+woodicalak.net
+xml-clovers.cf
+secure.uniformprotect.com
+paxfulbr.com
+mlbbclaim2022.gamename.net
+myscamstore.es
+wells-fargo-verify29.com
+frejdk9newd0s.co.vu
+www.jp-amazon.enp-co.top
+www.supportwhatsapp.com
+mkmui-2iaaa-aaaad-qcbua-cai.ic0.app
+a0673744.xsph.ru
+alertsensor.cleaning
+communitystandarpagesandrepairservices.co.vu
+viralnewchika.co.vu
+grupchatdesh2022.co.vu
+secure-dropbox.me
+rexsoutrageous.com
+grupbokepterbaru.001www.com
+pizjx-kyaaa-aaaad-qcb7a-cai.ic0.app
+marianoajl.com.ar
+pronotivd.hs-sites-eu1.com
+www.micard-fgh.com
+365oexc3l-fl13r-5cec.d2awsrj.workers.dev
+loglns-outlooks.3utilities.com
+papaya11102756.brizy.site
+bmcellisibb.com
+bimcellct.com
+bmcellyarenim.com
+bimcellistikll.gq
+acrobat-f9a9f.web.app
+www.santander.claim-assistance.support
+www.verificaareaprivata.live
+safereviewxsw.com
+www2.mufg.jp.nft9.cn
+bimcellwakum.com
+rosybrownunluckyscales.120522g.repl.co
+docuemebyt3783893-s88sj.web.app
+verified.capone.burtech.bm
 https.meta-pages99179553770889767455.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
 https.meta-pages53717140855504062034.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
 https.meta-pages54532735477032667657.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
@@ -93,10 +284,7 @@ www.secure-0suncoastcreditunion.authorizeddns.us
 rectifierchannel.com
 claimeventreendem.cf
 anazon.co.ip.ao4an2.shop
-academy-of-elites.com
 amaz0n.us
-mainaffixrectify.com
-xn--paypalscurite-hhb.fr
 link-grup-18-whatsaap01.ga
 x836500.com
 bafybeihv6hv4xurnqrz7443ikm7hmndogmezywkt26ex6hbhu33cdp5w7e.ipfs.dweb.link
@@ -120,7 +308,6 @@ btnewweekkk.weeblysite.com
 bmcellkampanyaa.com
 www.connexion-paiement.intelligent-gagarin.162-0-213-72.plesk.page
 vodafonepartner.online
-hospitablesteelbluebackground.hamp22.repl.co
 fatura-magazine.com
 flexible-marketing.co.uk
 snapechat.ml
@@ -207,13 +394,8 @@ web3-waletconnect.com
 colissimo-douane.fr
 vknews.org.ru
 academiasapiens.com
-docuemebyt3783893-s88sj.web.app
-rosybrownunluckyscales.120522g.repl.co
-verify-decline-transactions-help.com
-verified.capone.burtech.bm
 www.m.mstacsouz.icu
 www.m.mstaceoun.icu
-appdigitalmaiohipr.com
 olivedrabunknownscales.masdroomeim.repl.co
 meta.protection-pages40949989644786269072.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
 hospital-attempt-roots-mpegs.trycloudflare.com
@@ -287,7 +469,6 @@ ucspin3.dubya.net
 grupbkpnew.co.vu
 kinderwagen-de.xyz
 gfegejdnd9jss.co.vu
-red-base-4056.on.fleek.co
 hypesquad-mail.com
 hh87wpg8no.temp.swtest.ru
 glacierfreerewards.getrewardfree.xyz
@@ -376,12 +557,12 @@ loginmicrosoft-online.on.fleek.co
 yangsempura.co.vu
 www.hosphinxi.com
 www.amzn888.com
+hkjhifsffshgjhb.web.app
 nahidharbourontario.com
 myworkingthing.h4bd9098ayhcsascvv.workers.dev
 meta.protection-pages10173785846628136964.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
 facebooksecured.authorizeddns.org
 www.s.mstacaoun.icu
-mclarenofficiall.com
 www.s.chains-sync.live
 djkyce.com
 outlookoffice.servehttp.com
@@ -393,7 +574,6 @@ folder77ui440e87uyeh-333.web.app
 digodo-ea870.web.app
 folder7838ui389uiss-s89uis.web.app
 documet3673uyhs0s0-sis.web.app
-folder7678uyhe-e90390i3.web.app
 folder783878898s-0s87uyhj33.web.app
 luxept.com.au
 folder8989389983s-s08wuiw.web.app
@@ -405,7 +585,6 @@ owamessages-reviews-center.web.app
 labanque-postale-9fb4b.web.app
 ikeri-7d929.web.app
 discord-hypesquad-events.tk
-voowo-8e08c.web.app
 tdsecurities.web.app
 asyad-invest.com
 opensea-decentralizedwallet.com
@@ -523,8 +702,6 @@ loginaccesplus.luxlithg.tk
 apppersonass.com
 wallet-bridges.com
 dexconnetswebs.com
-fileviasharpointt5.web.app
-fileviasharpointt8.web.app
 wallet.fastgiveway.com
 www.crm-globalservicexchange-v2-apple.mystore-support-apple.com
 apakahbisagembok.1999rif.com
@@ -545,7 +722,6 @@ my.jcb.juhrkh.com
 hypesquadapply.com
 www.dappswalletvalidations.com
 sphericalmarketing.net
-khdbc.ga
 tione.hdicoin2022.cyou
 www.m.mstacaoun.icu
 allchainsvalidator.com
@@ -617,8 +793,6 @@ davvpersons.com
 crm-globalservicexchange-v2-apple.mystore-support-apple.com
 grubokep18terbaru.kelelawarcyberhost.xyz
 a0672385.fsph.ru
-bangkokbank.bangkokbnak.com
-fileviasharpointt6.web.app
 folder889383-s89s89iksw.web.app
 ronsupport-livechat.com
 beta-users.app
@@ -736,7 +910,6 @@ m-business-badgeservice.ml
 toursexplorer.com
 net-defamation.com
 www.post-luxembourg-colis.com
-business-page-appeal-1286-2129.web.app
 idenfiant.paiementsmleboncoin.com
 100001533462003-id.ml
 goggllebox-tv.pl
@@ -968,6 +1141,7 @@ ucspin.dubya.net
 collectgunskinfree.com
 hypesquad-official-form.com
 www.rakoten-co-ip.dqulkev.ga
+annuitiesusaa.com
 settinglcn.web.app
 shrill-paper-af08.minfosadu24w.workers.dev
 bnfghjghghghyuyhgghj.weeblysite.com
@@ -1052,222 +1226,4 @@ www.pubgspin3.dubya.net
 microsoftonlineoffice365mails.on.fleek.co
 www.update-wallet-trust.179-43-154-180.plesk.page
 roblox-secure-uswest.us.to
-bafybeibwteteysxljum4owlusptthmqqik3h6r3tce7sx23duelarphxgu.ipfs.nftstorage.link
-fileviasharpointt1.web.app
-approachjob.net
-yamka.dk
-transaction-whenever-hb-principal.trycloudflare.com
-motolas.dk
-looksrave.com
-reedem-hypesquad-now.com
-mainnetappsync.net
-hypesquad-events-rescue.com
-bahficohsa.com
-dark-star-2751.on.fleek.co
-suportecliente.xyz
-macu-com.com
-onlinesecuredatasharefilesv.on.fleek.co
-twilight-smoke-9344.on.fleek.co
-widegamess.com
-ggbrotq.com
-cecisport.com
-super-math-7335.on.fleek.co
-gascoignefurniture.com
-pasteleriatursquesas.com
-a0670876.xsph.ru
-fantastic-curse-fascinator.glitch.me
-amazon956.com
-app.seucartaoatacadao.com
-bafybeibghacfieb6ybxw2amgwcydgswpeyvym5ttp2i63pxvyv2ofxopqm.ipfs.dweb.link
-bonucnasberkartu.org.ru
-ingeniads.com
-bonuc-na-sberkartu.net.ru
-ingoutin.net
-ingenio-marketing.com
-ingairapt.org
-pmid-ethiopia-journals-remain.trycloudflare.com
-a0670706.xsph.ru
-crazycakes4u.com
-dimarcoceramica.com
-bafybeiedls26l5p7s2h7vdumhsmbqugr3sywhxrdfy6jopwqifghvshrta.ipfs.dweb.link
-khalvor.com
-interbanca.joserr123.repl.co
-access-request-decline.com
-sharepoint-useast2.web.app
-discord-subscribe-hypesquad.tk
-lcoksrare.live
-www.bancobpm.alcalajw.disercom.es
-cscu5-oyaaa-aaaad-qb3na-cai.raw.ic0.app
-https--apps-rackspace--com-webmail.glitch.me
-freet.tyx-wkwr.xyz
-tkj398uxxsvhnlgyv4r8fy1ztfztw-hwvvmhcp-3vwicnmqv3u.pages.dev
-bafybeibbxee6s7ecvlegrqja6s7sp7yzmlbnjnzcpv6ohcjw2r545rrf7q.ipfs.dweb.link
-www.livebadgezchats.ml
-www.instagram.com.accounts.ctfiesrafaelalberti.rocks
-terleraijanji.co.vu
-dapptool.farm
-selenatention.com
-hollybourne.net
-vslsistemas.pt
-instagram.com.accounts.ctfiesrafaelalberti.rocks
-bancobpm.alcalajw.disercom.es
-folder5667622-77uiw892.web.app
-yishopee.com
-cpcmansfield.org
-arcmarketsolutions.com
-auspiciousdesigns.co.uk
-healthaura.in
-gottagetsparked.com
-newsitem.in
-onlinesecuremessagingfileshare.on.fleek.co
-pancakeswap.finance.d-app.site
-solucoesdigital16.com
-mlbbgiftskin.forumz.info
-atelieridesign.com
-berglundsite.com
-abacusnetlink.com
-heidiflies.com
-dusmuhendisleri.com
-client-luxembourg-post.com
-carusogallery.com
-fiercesolutionsllc.com
-helpdesk.stop-addons.com
-maddogmv.com
-weathered-brook-9447.on.fleek.co
-anhbiafacebook.com
-santan-auth.user-id31.com
-bafybeicz56gb2fi54fwnthbne6n7jzo6mvk65ufme4chx47f4w73c2sede.ipfs.dweb.link
-al-defendant-use-cabin.trycloudflare.com
-lined-surprised-interviews-nam.trycloudflare.com
-fileviasharpointt17.web.app
-viral22indnew.co.vu
-wagrub2o22bctu8.co.vu
-crazytest.co.vu
-viralsexgrubb.co.vu
-httpgroupwhattsap18nextnesia.co.vu
-fregetd9kdk.co.vu
-virallterbaru.co.vu
-grupterbaruwa2022.co.vu
-microsoft-datamaturity.noisehq.nl
-grupviralhoot2022.co.vu
-grupchatnewz2022.co.vu
-grupviraltiktok2022.co.vu
-cocajobs.com
-meta-helpme.ml
-secure-server.laviewddns.com
-mainnetaccess.com
-hotspring19.com
-www.ckcsharepoint.com.acanexia.fr
-www.pro-fondsharepoint.com.mexei.fr
-sgen-espace-client.fr
-mejan.pl
-official-hypesquad-claim.com
-client-anz-centre.com
-prowizaz.pl
-nubematerace.pl
-negrifitness.pl
-trueenglish.pl
-phprojects.pl
-weselne-fotki.pl
-pubgspin111.dubya.net
-bafkreibcruawuz6oqt3xg2gce5xqvhsz2sm5aofhujxyaolpjmnmc7t5b4.ipfs.nftstorage.link
-anazon.sdodvp7ohl.cn
-purple-field-6703.on.fleek.co
-www.crossoveritsolutions.com
-getnow21.com
-sotipariedsaw.com
-mamacube.pl
-renkoontol.com
-meblo-maniak.pl
-vinonet.pl
-www.sotipariedsaw.com
-www.servizi-home.com
-www.consultform-web.com
-noderectifysyncs.com
-ilcapricciopollos.com
-morning-frost-0258.on.fleek.co
-fvgbhnjmhghjkkjhj.weeblysite.com
-www.metamasksl.com
-exams-hypesquad-program.com
-vklink.xyz
-smabrokers.pl
-silvanusertid.com
-metamask-wallet-verification.com
-opus-caredesk.com
-dry-shape-0bbc.sophia-pipefittinghtxd7833.workers.dev
-demoscript.co.vu
-www.contompsonline.com
-paiementboncoin.com
-contompsonline.com
-www.connectdexapp.com
-connectdexapp.com
-appsecurenode.com
-web7878.web07.bero-webspace.de
-habitation-reservation.com
-jenmaness.com
-cztwxqyfiv.web.app
-www.chinesedm.com
-bafybeift4bwmhe2gwzkt4aeuv4b2yz7eq7ipfm3i5ydabun72t56qh3fc4.ipfs.nftstorage.link
-fskiq5.mimo.run
-3001987315874198210157985.xyz
-7001547894612616574884170.xyz
-citi-info0023.com
-axeminfimlity.xyz
-jmnetsoft.com
-www.file-outlook-office365.com
-novametalomecanicadoseixal.pt
-domaintest.misecure.com
-vtl-montoon.tk
-formulaire-domicile.com
-bsceunms.info
-area-tutela.com
-site9606042.92.webydo.com
-www.pacnackewsap.finance
-square-pine-514a.jude-kean276628.workers.dev
-groupviral18new.co.vu
-emmeline72.temp.swtest.ru
-bancosabadelll.com
-liufucheng.xyz
-www.aisecureme.com
-development.aisecureme.com
-realistic-secured-md-gentle.trycloudflare.com
-safepointshare.com
-instgram-picture.mypi.co
-img-pictr.mypi.co
-zainali.photos
-www.domaintest.misecure.com
-ch-ase.web.app
-logan-met-coalition-hands.trycloudflare.com
-itch.help
-groupviral18.co.vu
-mediafirechikaopenbo20jt.co.vu
-shoponline.co.vu
-grupbokepterbaruu.co.vu
-groupbokep.co.vu
-tllbimyukleme.tk
-walchainall.com
-www.rakoten-update.dqulkev.ml
-wcvalidate.org
-www.opensail.app
-jadiajalag.co.vu
-viralcrotdidalamah1929.co.vu
-checkinformationofsecures.co.vu
-wallet-pollygon-technollogy.com
-mlbbgiftnow.ntdll.top
-mediafireterbaru.co.vu
-groupviral18indo.co.vu
-grupkumpulanvidioviralarachu.co.vu
-officeonedrivea3188350d116c56f4640139145cbca08a3188350d116c56f4.officepos.workers.dev
-ig-photo-copy.mypi.co
-https-waatsaap-chika.001www.com
-vkcor.ru
-www.rakoten-card.dqulkev.tk
-myfavfoods.icu
-new-register-hypersquadevents.com
-credt-agcole-fr-v.web.app
-capedeli.com
-mail-inec-gob-ec-owa-auth-logon-aspx.fundacionalgoritmo.org
-battlegroundlimited.xyz
-fileviasharpointt12.web.app
-loginn-microsoftonline.fmh-corp.org
 letsencryp.at

Разница между файлами не показана из-за своего большого размера
+ 225 - 233
yoroi_suspicious_level2.dns


Некоторые файлы не были показаны из-за большого количества измененных файлов