root преди 5 дни
родител
ревизия
1dd18565e2
променени са 6 файла, в които са добавени 17205 реда и са изтрити 13007 реда
  1. 0 1
      nethesis_level3.netset
  2. 130 130
      whitelist.global
  3. 9524 7899
      yoroi_malware_level1.dns
  4. 6436 2796
      yoroi_malware_level2.dns
  5. 67 107
      yoroi_suspicious_level1.dns
  6. 1048 2074
      yoroi_suspicious_level2.dns

+ 0 - 1
nethesis_level3.netset

@@ -9204,7 +9204,6 @@
 142.147.97.21
 142.165.181.78
 143.0.236.0/22
-143.20.185.79
 143.20.185.102
 143.20.185.201
 143.20.185.225

+ 130 - 130
whitelist.global

@@ -14,130 +14,6 @@
 62.149.128.154
 62.149.128.151
 62.149.128.160
-165.22.205.55
-178.62.240.117
-167.71.68.193
-159.223.223.100
-134.209.92.178
-188.166.95.89
-64.227.78.25
-188.166.91.196
-134.122.63.170
-159.89.16.213
-46.101.197.42
-188.166.112.196
-167.71.66.0
-167.99.217.178
-188.166.89.180
-159.223.236.108
-178.62.230.155
-104.248.137.50
-167.71.78.214
-161.35.144.29
-146.190.225.217
-146.190.238.159
-159.223.212.220
-159.223.225.41
-188.166.15.149
-159.223.215.38
-142.93.137.213
-134.209.193.225
-152.42.133.210
-167.71.8.45
-167.99.42.32
-167.71.64.103
-159.89.97.40
-188.166.91.80
-178.62.247.86
-104.248.205.106
-165.22.23.86
-161.35.155.167
-64.226.110.43
-68.183.8.80
-188.166.163.93
-188.166.23.162
-167.172.38.137
-152.42.138.25
-188.166.64.212
-167.172.38.180
-128.199.43.246
-152.42.136.190
-165.22.197.93
-167.71.10.219
-104.248.82.252
-167.99.252.173
-46.101.230.158
-46.101.208.189
-188.166.17.46
-167.172.45.223
-146.190.18.242
-161.35.148.219
-142.93.138.82
-134.122.85.110
-174.138.2.121
-159.223.7.204
-139.59.137.11
-104.248.83.139
-164.92.212.150
-188.166.11.138
-167.99.216.203
-178.62.192.199
-164.92.157.134
-161.35.95.211
-142.93.131.113
-104.248.88.58
-164.92.142.172
-178.128.244.136
-104.248.46.0
-159.223.215.77
-178.62.240.209
-188.166.105.213
-161.35.71.6
-188.166.109.135
-161.35.84.164
-159.223.0.173
-206.81.28.71
-188.166.63.108
-188.166.21.67
-167.99.211.228
-164.92.219.226
-188.166.73.117
-64.227.75.231
-159.223.214.180
-142.93.131.251
-188.166.93.86
-104.248.82.87
-188.166.77.48
-146.190.29.122
-152.42.139.15
-165.227.157.248
-167.99.43.70
-188.166.70.107
-167.71.71.43
-206.189.0.226
-146.190.234.168
-174.138.8.207
-159.223.229.75
-167.71.62.233
-104.248.32.7
-64.226.87.54
-161.35.157.15
-159.223.19.185
-157.230.26.3
-188.166.83.149
-161.35.88.180
-188.166.87.159
-68.183.15.129
-165.232.95.75
-165.22.28.7
-188.166.48.29
-134.209.94.125
-209.38.110.236
-139.59.209.243
-161.35.72.43
-188.166.116.155
-152.42.128.247
-142.93.128.221
 165.22.207.243
 143.198.131.11
 167.71.2.254
@@ -145,13 +21,13 @@
 164.90.167.204
 165.22.92.33
 188.166.72.23
+46.101.171.161
 164.90.194.17
 157.245.65.18
 167.99.219.82
 167.71.11.73
 161.35.149.158
 164.90.178.60
-46.101.171.161
 167.71.76.184
 207.154.244.91
 188.166.24.24
@@ -187,13 +63,13 @@
 167.99.210.125
 167.99.208.235
 164.92.241.115
+165.22.27.110
 164.92.152.2
 188.166.37.143
 206.189.3.65
 152.42.138.49
 188.166.125.205
 164.92.209.202
-165.22.27.110
 164.92.215.172
 188.166.85.242
 64.227.119.244
@@ -211,14 +87,14 @@
 68.183.7.251
 167.71.78.224
 209.38.237.246
+157.230.99.100
+167.99.140.13
 64.225.71.102
 159.65.198.47
 178.128.248.28
 178.62.206.20
 128.199.43.100
 188.166.9.247
-157.230.99.100
-167.99.140.13
 134.122.56.28
 159.223.237.208
 139.59.152.247
@@ -237,13 +113,13 @@
 188.166.29.153
 165.232.89.253
 206.81.18.90
+206.189.62.73
 167.99.40.250
 167.172.38.97
 142.93.230.36
 104.248.201.37
 164.92.145.142
 164.92.241.94
-206.189.62.73
 188.166.68.157
 178.62.210.100
 167.99.243.169
@@ -281,6 +157,130 @@
 104.248.194.112
 178.128.254.142
 128.199.52.246
+165.22.205.55
+178.62.240.117
+167.71.68.193
+159.223.223.100
+134.209.92.178
+188.166.95.89
+64.227.78.25
+188.166.91.196
+134.122.63.170
+159.89.16.213
+46.101.197.42
+104.248.137.50
+188.166.112.196
+167.71.66.0
+167.99.217.178
+188.166.89.180
+159.223.236.108
+178.62.230.155
+167.71.78.214
+161.35.144.29
+146.190.225.217
+146.190.238.159
+159.223.212.220
+159.223.225.41
+188.166.15.149
+159.223.215.38
+142.93.137.213
+134.209.193.225
+152.42.133.210
+167.71.8.45
+167.99.42.32
+167.71.64.103
+159.89.97.40
+68.183.8.80
+188.166.163.93
+188.166.91.80
+178.62.247.86
+104.248.205.106
+165.22.23.86
+161.35.155.167
+64.226.110.43
+152.42.136.190
+165.22.197.93
+188.166.23.162
+167.172.38.137
+152.42.138.25
+188.166.64.212
+167.172.38.180
+128.199.43.246
+167.71.10.219
+104.248.82.252
+167.99.252.173
+46.101.230.158
+46.101.208.189
+188.166.17.46
+167.172.45.223
+146.190.18.242
+161.35.148.219
+142.93.138.82
+134.122.85.110
+174.138.2.121
+159.223.7.204
+139.59.137.11
+104.248.83.139
+164.92.212.150
+188.166.11.138
+167.99.216.203
+178.62.192.199
+164.92.157.134
+161.35.95.211
+142.93.131.113
+104.248.88.58
+164.92.142.172
+178.128.244.136
+104.248.46.0
+159.223.215.77
+178.62.240.209
+188.166.105.213
+161.35.71.6
+188.166.109.135
+161.35.84.164
+159.223.0.173
+206.81.28.71
+188.166.63.108
+188.166.21.67
+167.99.211.228
+164.92.219.226
+188.166.73.117
+64.227.75.231
+159.223.214.180
+142.93.131.251
+188.166.93.86
+104.248.82.87
+188.166.77.48
+146.190.29.122
+152.42.139.15
+165.227.157.248
+167.99.43.70
+188.166.70.107
+167.71.71.43
+206.189.0.226
+146.190.234.168
+174.138.8.207
+159.223.229.75
+167.71.62.233
+104.248.32.7
+64.226.87.54
+161.35.157.15
+159.223.19.185
+157.230.26.3
+188.166.83.149
+161.35.88.180
+188.166.87.159
+68.183.15.129
+165.232.95.75
+165.22.28.7
+188.166.48.29
+134.209.94.125
+209.38.110.236
+139.59.209.243
+161.35.72.43
+188.166.116.155
+152.42.128.247
+142.93.128.221
 206.189.106.156
 161.35.146.216
 164.92.215.208
@@ -311,7 +311,7 @@
 167.99.16.60
 167.99.248.251
 174.138.107.200
-185.199.110.153
+185.199.108.153
 185.236.106.196
 188.166.103.4
 188.166.10.67

Файловите разлики са ограничени, защото са твърде много
+ 9524 - 7899
yoroi_malware_level1.dns


Файловите разлики са ограничени, защото са твърде много
+ 6436 - 2796
yoroi_malware_level2.dns


+ 67 - 107
yoroi_suspicious_level1.dns

@@ -9,49 +9,51 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+worker-summer-sun-c544.hyndmanpizzimpz-t23-6-6.workers.dev
+sddsf.qpon
+pomea.replit.app
+www.87006.xyz
+www.bet365vip5.com
+allegro.pl-oferta4186419.sbs
+allegrolokalnie.pl-84629.cfd
+www.primary-device-sec.com
+www.scsalud.closer.website
+www.tokenid-8237wf.com
+j293v.xyz
+inklivo-001-site1.qtempurl.com
+pleiartdes.com
+stxrduxt.com
+icloudconect.com
+agam168.com
+allegrolokalnie.pl-oferta6831.cfd
+noobs.locker-etape.com
+gros.locker-etape.com
+de-la-chapelle.locker-etape.com
+cocherie.locker-etape.com
+thouvenin.locker-etape.com
+morais-cardoso.locker-etape.com
+tyutrurrufurrhr.weeblysite.com
+my-site-106742-108069.weeblysite.com
+4beebf27-74d8-453a-ab60-91027114de09-00-1p6ac3ebq2i1i.janeway.replit.dev
+allegrolokalnie.pl-342492841695.cfd
+allegrolokalnie.pl-firmowe-98428.sbs
+allegrolokalnie.pl-oferta736473.cfd
+gestion-dgfip.fr
+on-netlfix.com
+twopagans.com
+info-bhd.iceiy.com
+2089224e-cdef-419e-a090-faea1494dd94-00-1smzqryixs0ga.picard.replit.dev
+www.trezor.pro
+visionfundsfindept.com
 58hde.vip
 www.87193.xyz
-www.cuentas-netlfix.com
-www.cobroalfa.com
-www.flash.jsscdz.com
-www.4shotsports.com
-www.86983.xyz
-f221i.xyz
 h88p.xyz
 w51i.xyz
-www.trezor.pro
-visionfundsfindept.com
-bank.2168970.xyz
-allegrolokalnie.pl-firmowe-28424.sbs
-eesdc.sbs
-punjaboptics.net.pk
-idekerjaumkm.net
-exciting-white-3qjtseqzpp.edgeone.dev
-amp777.dev
-www.watsicon.kz
-oateryange.serv00.net
-www.login.steamspowered.com.es
-login.steamspowered.com.es
-gmbl.sy99.de
-managetrezor.io
-86974.xyz
-ts334.co
-s1096590.ha011.t.mydomain.zone
-ersportal-test.btreeboatest.com
-cvkeo.com
-www.cvkeo.com
 allegrolokalnie.pl-oferta-549345934592929292911040504345-fast.click
-allegrolokalnie.pl-342492841695.cfd
 allegrolokalnie.babdiwowjs.sbs
-allegrolokalnie.pl-firmowe-98428.sbs
-twopagans.com
-allegrolokalnie.pl-oferta736473.cfd
 downloadapps.ghost.io
-seguridadpichincha66-h9qg.onrender.com
+www.on-netlfix.com
 bank.2168969.xyz
-bank.2167970.xyz
-bank.2167981.xyz
-leighk.com
 s100g.xyz
 www.netflixli.shop
 ebf-ods.insolvency-development.co.uk
@@ -60,11 +62,12 @@ www.grociesmrocies.com
 tiktokshop.njyjlp.com
 qyhgb.zeabur.app
 securipass3-agricole.com
-www.leighk.com
 att-107133.weeblysite.com
 christien-charriere.transitclients-sms.com
 securipass-agricole15.com
 securipass-agricole11.com
+www.fortune-cobra-crew.com
+www.bright-node-game.com
 www.m72f.xyz
 h88d.xyz
 m26z.xyz
@@ -75,13 +78,11 @@ p67c.xyz
 www.r16c.xyz
 gemini.ccdgut.com
 www.knight-panther.com
-www.fortune-cobra-crew.com
 www.fire-chain-bot.com
-www.bright-node-game.com
 allegrolokalne.conformation-1890.shop
+exodus.pagy.site
 homeripleyperupersonas.im
 hometrade-nomura.t8ur4b.top
-exodus.pagy.site
 conbascustomerservicenumber.com
 allegrolokalne.conformation-1892.shop
 hd54f.baollll2.cc
@@ -90,21 +91,8 @@ hd54f.baollll2.cc
 www.easybank-landing-page-rho.now.sh
 www.test3.wirelessfraudpreventionfcc.com
 www.87304.xyz
-e102j.xyz
-shehui.top005.com
-www.84627.xyz
-authmeta.net
-credspnivell.digital
-www.b105r.xyz
-www.h88a.xyz
-www.b102s.xyz
-www.s81z.xyz
-arabuluculukkamu.com
-whatssapp.us.cc
-www.cool-murdock.82-165-96-161.plesk.page
-84711.xyz
+allegro-lokalnie.pl-59832.sbs
 j185b.xyz
-www.86191.xyz
 acessseguro.life
 x93f.xyz
 www.netflixx.free.bg
@@ -119,6 +107,20 @@ www.8mlouf2h0nr.docuget.xyz
 www.e102p.xyz
 www.y11f.xyz
 www.a67t.xyz
+e102j.xyz
+shehui.top005.com
+www.84627.xyz
+authmeta.net
+credspnivell.digital
+www.b105r.xyz
+www.h88a.xyz
+www.b102s.xyz
+www.s81z.xyz
+arabuluculukkamu.com
+whatssapp.us.cc
+www.cool-murdock.82-165-96-161.plesk.page
+84711.xyz
+www.86191.xyz
 www.m82z.xyz
 j260y.xyz
 b237fr.xyz
@@ -130,14 +132,13 @@ p113p.xyz
 h86k.xyz
 www.p108b.xyz
 oretag-betaling_nu.keepo.bio
-allegro-lokalnie.pl-59832.sbs
-www.avertiremondial.com
 lyanan-danaid.customers.biz.id
 morline.pickupapp-packets.com
 credspnivelll.digital
+www.avertiremondial.com
 abdel.paquet-rce.com
-bancoadechileqae.top
 pancakeswap-finance.fr
+bancoadechileqae.top
 www.gestion-services.info
 www.cyber-club-dapp.com
 www.mesh-field-sphere.com
@@ -151,6 +152,14 @@ ecr-paquet.com
 82570605.ep-construction.fr
 booking.pl-oferta37139759.sbs
 allegrolokalnie.pl-8259137594261.cfd
+a.36562402074.xyz
+www.83565.xyz
+www.j256n.xyz
+www.83561.xyz
+www.83568.xyz
+www.g37p.xyz
+b236c.vip
+uphlod.ghost.io
 www.a67k.xyz
 www.j133t.xyz
 j259q.xyz
@@ -166,61 +175,12 @@ www.s99j.xyz
 x92m.xyz
 www.j133r.xyz
 www.j133p.xyz
-a.36562402074.xyz
-www.83565.xyz
-www.j256n.xyz
-www.83561.xyz
-www.83568.xyz
-www.g37p.xyz
-b236c.vip
-uphlod.ghost.io
 whaotapp.us.cc
 www.dev.admin.binance-referral.com
 m24m.xyz
+dilevry.ukit.me
+yuaohoosmainl.sbs
 www.revidfr.com
 www.apcpcpp.com
 allegro.pl-smart95781242.cfd
 allegro.pl-smart9128412.cfd
-dilevry.ukit.me
-yuaohoosmainl.sbs
-www.84690.xyz
-www.free-5520723.webadorsite.com
-www.x88f.xyz
-www.b210m.xyz
-www.h59w.xyz
-h73h.xyz
-www.x80x.xyz
-www.tikmalpe.top
-www.r34p.xyz
-legend-core.event-zones.com
-e88r.xyz
-www.p67x.xyz
-x91p.xyz
-www.r15n.xyz
-p67x.xyz
-b99c.xyz
-www.j130a.xyz
-www.p88z.xyz
-17247-microsoft.com
-nav-upheld-io.grapedrop.net
-b112g.xyz
-b233j.xyz
-b233r.xyz
-www.p113g.xyz
-www.office-tousf.com
-84755.xyz
-p113g.xyz
-84681.xyz
-84663.xyz
-www.a66f.xyz
-www.r25f.xyz
-h65m.xyz
-j28b.xyz
-b223n.xyz
-www.j117x.xyz
-j259o.xyz
-a66i.xyz
-www.j134t.xyz
-p84v.xyz
-www.j240r.xyz
-w47p.xyz

Файловите разлики са ограничени, защото са твърде много
+ 1048 - 2074
yoroi_suspicious_level2.dns


Някои файлове не бяха показани, защото твърде много файлове са промени