root 1 год назад
Родитель
Сommit
235ec8b3e4
4 измененных файлов с 5969 добавлено и 5274 удалено
  1. 1011 859
      yoroi_malware_level1.dns
  2. 4626 4373
      yoroi_malware_level2.dns
  3. 306 15
      yoroi_suspicious_level1.dns
  4. 26 27
      yoroi_suspicious_level2.dns

Разница между файлами не показана из-за своего большого размера
+ 1011 - 859
yoroi_malware_level1.dns


Разница между файлами не показана из-за своего большого размера
+ 4626 - 4373
yoroi_malware_level2.dns


+ 306 - 15
yoroi_suspicious_level1.dns

@@ -9,6 +9,308 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+dl.dir.freefiremobile.com.free.putrivpn.biz.id
+bdmingchen.com
+tokenpocket-tpoun.com
+stywsysdyszyswyhrh.blogspot.li
+srtyerywyery.blogspot.lu
+stywsysdyszyswyhrh.blogspot.ug
+srtyerywyery.blogspot.co.il
+srtyerywyery.blogspot.com.eg
+dimokilu32.blogspot.co.ke
+dimokilu32.blogspot.com.cy
+karmatechsolutions.com
+cardcoin.rewitesi.top
+attmail-109512.weeblysite.com
+okia.eudkmon.top
+secure.ercdapps.com
+dl.dir.freefiremobile.com.sg4.putrivpn.biz.id
+telegram.cbad0k.xyz
+ub-migrateconnection.icu
+dimokilu32.blogspot.co.il
+login-ourtime.apps-members.workers.dev
+dimokilu32.blogspot.com.mt
+srtyerywyery.blogspot.com.by
+uspstrack.online
+fanpagebussinesspolyci.space
+dhlclearance.com
+srtyerywyery.blogspot.sn
+srtyerywyery.blogspot.com.ng
+dl.dir.freefiremobile.com.id1.putrivpn.biz.id
+www.ayuda-telefonica.com
+dimokilu32.blogspot.md
+dimokilu32.blogspot.bg
+bet110q.com
+5885.columbiauniversityinpictures.com
+146-190-36-23.cprapid.com
+www.146-190-36-23.cprapid.com
+bergelectricinvestment.com
+mail.146-190-36-23.cprapid.com
+bt-internet-101551.weeblysite.com
+shhy315.com
+sycxe.top
+login-screen-106360.weeblysite.com
+signin.aws.21cec.com
+purple-da6462.qqu4qswu.workers.dev
+ng-wdl.com
+stywsysdyszyswyhrh.blogspot.com.eg
+www.signin.aws.21cec.com
+solicitud-de-firma-digital-20245.webnode.cr
+www.dagxyc.shop
+www.feywea.shop
+www.dzicex.shop
+www.dxhizd.shop
+www.csbtam.shop
+us-usp.com
+www.arqogz.shop
+www.cxeqgb.shop
+smbxubf.com
+pposfbyf.com
+smmcbybf.com
+usps-cn.top
+urdze.com
+urdzu.com
+urdxw.com
+urdzd.com
+urdzy.com
+urdzt.com
+usps-streo.com
+urdzw.com
+urdxq.com
+urdxk.com
+urdxg.com
+urdxc.com
+urdcr.com
+urdxb.com
+urdcp.com
+urdcu.com
+urdce.com
+uspada.top
+urdca.com
+urfqu.com
+urfqr.com
+urfqp.com
+urfqe.com
+urdzf.com
+urdza.com
+urdzr.com
+urdxv.com
+urdzp.com
+urdxz.com
+urdxm.com
+urdxh.com
+urdnw.com
+urdnr.com
+urdnp.com
+urdne.com
+urdnf.com
+urdmq.com
+urfqd.com
+urfqa.com
+urdmg.com
+uaqay.com
+uaqau.com
+uaqat.com
+uddyh.top
+uaqas.com
+uaqap.com
+www.ikd9wb.cn
+att-101151-105303.weeblysite.com
+wuyier117.pxrocgr.workers.dev
+www.hcljy.com
+limit.accountv.workers.dev
+beam-solutions.com
+ragrugtextiles.com
+impulse-owners.com
+yoga-nani.com
+potatochipping.com
+pnemetzmills.com
+equi-works.com
+royacuna.com
+xgjhq.com
+tidibar.com
+dsgrlty.com
+mmqiyi.com
+smbcc-jp.pspaaop.cn
+bristolpainter.com
+220u.cn
+pancake-swap.xyz
+sparkasse-tan2.info
+ssl3393978ssl39926241480163.searchmarketingservices.dev
+urdfd.com
+urdgq.com
+urdhj.com
+urduq.com
+urdwj.com
+urdwz.com
+ursuy.com
+pay-lah.lat
+wfsjw.com
+paylah.lat
+paymentlah.lat
+www.rufz6b.cn
+www.l1kowh.cn
+www.1u409h.cn
+dehaozhuji.com
+acicpay.com
+fsbykt.com
+wuyiba92.nzzaxatc.workers.dev
+home-103870.weeblysite.com
+vaabenefit.com
+aotopc.com
+working-on-it-102140.weeblysite.com
+webmail-boardservice-attk3rjyu0.weeblysite.com
+loginscreen-att-106354.weeblysite.com
+att-mail-104835.weeblysite.com
+bt-104370.weeblysite.com
+105574-109608.weeblysite.com
+attnet-103611.weeblysite.com
+att-2024-108020.weeblysite.com
+mail-att-109610.weeblysite.com
+home0101.weeblysite.com
+home-105470.weeblysite.com
+vjkctordgchu.weeblysite.com
+sbs-108204.weeblysite.com
+att-mail-106036.weeblysite.com
+maillerrsservers.weeblysite.com
+wuyier102.pxrocgr.workers.dev
+btmailerupdate.weeblysite.com
+my-oxixlox.weeblysite.com
+allconfsbot.website
+cs0189.com
+review-case-1000938272766.gondalprotection.com
+randomstring.copyright-review.com
+pagecheck.copyright-review.com
+copyright-review.com
+checkcontrol.copyright-review.com
+gdbuildingservices.com
+business-case-1000938272408.gdbuildingservices.com
+business-case-1000938272911.gdbuildingservices.com
+business-case-1000938272916.gdbuildingservices.com
+business-case-1000938272915.gdbuildingservices.com
+birokert.ro
+violation-remove-here.replit.app
+www.onliinebbtff.com
+xiaofangsx.com
+qujingweiba.com
+bnb-id8304.com
+business-case-1000938272446.gdbuildingservices.com
+business-case-1000938272371.gdbuildingservices.com
+business-case-1000938272978.gdbuildingservices.com
+paxfuldispute.com
+official.pubgxbest.com
+ailocation-debank.app
+sparindia.org
+adminuser.2023080031.top
+linkdanaaid.bantuandanaid.biz.id
+randomstring.alwayshkg.com
+alwayshkg.com
+cpoint.me
+support.alertcase3698.me
+galaxies-mantanetwork.app
+checkpoint.alwayshkg.com
+www.bet365ym.com
+joeycosiomercado.com
+pagecheck.alwayshkg.com
+www.microsoftoutlookonline.com
+kimpetjj.anakembok.de
+axisbankybp.online-ap1.com
+restrctnstepvrfy.us.to
+randomstring.gondalprotection.com
+www.gondalprotection.com
+porfolio-metamask.io
+site.enkido.org
+telegeram-c.org
+www.imton23.xyz
+e-mail-wiederherstellungsdienst-annot2is-mrfpk.4everland.app
+randomstring.gdbuildingservices.com
+clntdemlonlinrestro.com
+leylandsummers.kesug.com
+ariful.net
+seuschke.homes
+pay-lah.top
+dana-payleter-dana-cicil.exs.biz.id
+facebooksecurity.blogspot.dk
+wcbkst42124.com
+uspk.usspbl.top
+web-debank.com
+feedback.lquan.cfd
+cloudflare2clash.alt-cu-9ops48nl.workers.dev
+cf.ekin22188.workers.dev
+356117.com
+worker-proud-butterfly-3f4f.joan-sanderlin.workers.dev
+worker-mute-unit-5da5.438749168.workers.dev
+cloudflare01.lihom22lihom22.workers.dev
+doc.whidc.workers.dev
+grnttibsvrruum.com
+garena-ff85347.baruxxi9.biz.id
+coojp01.1gevenchen1.workers.dev
+de-cloud-cefe.lloeeainderanm.workers.dev
+cf.wangfugui-f86.workers.dev
+webmail-authuser-k5fhbe.crd.co
+d8e7.jbq.workers.dev
+cf.farsight-0f6.workers.dev
+dienstetelekom-mail.de
+ddd.chaos201501.workers.dev
+mfjp.stone37170.workers.dev
+comengineer212005gmailcom.com-engineer21.workers.dev
+dark-pine.mecayok955.workers.dev
+codt.digitasianetwork.workers.dev
+cf.huabuxiang.top
+darkness-93fd.mosso.workers.dev
+profile-click-meta-a1.replit.app
+sourcedubonheur.hubside.fr
+share-field-7570.yralecaeaghnrsn.workers.dev
+www.kaleidodark.shop
+myoutlook-alerts0.lofeze.workers.dev
+gramdao.org
+aaq.kjuhgyt.cloudns.biz
+mailo-ao1.quaryr.workers.dev
+attnet-106912.weeblysite.com
+administrative-support-101506.weeblysite.com
+att-100136.weeblysite.com
+voice-chat-e42b.gzklq0kj.workers.dev
+rhy1688.com
+365mmk.com
+att-100259.weeblysite.com
+addsnapchat.com.eslamm.a2hosted.com
+irsfed.com
+dftechtide.top
+ctt-pt-post.top
+serw.dcms.site
+ctt-post-pt.top
+paypay-pointvd.com
+paypay-infologinpointed.com
+paypay-fapoint.com
+www.zydfbj.com
+www.gxqhr.com
+www.hbfzghy.com
+paypay-finpoint.com
+paypay-pointd.com
+paypay-infopointed.com
+www.zxclbj.com
+www.dfwqw.com
+dmxvlomigg.com
+www.cxjmyz.com
+nouveaufixe.hubside.fr
+nodeservicoscxg.is-a-bulls-fan.com
+10eeb71.wcomhost.com
+gestaosecurecgdnet.com
+collect-zk-sync.io
+x8c9l68gkkpz4u6.from-ak.com
+hvg45079l28uf2h.from-ak.com
+bt-105095-109970.weeblysite.com
+my-site-107550-105034.weeblysite.com
+att-webmail201.weeblysite.com
+jdfisdjksdjk.univer.se
+att-106486-102616.weeblysite.com
+home-108687.weeblysite.com
+radiogdynia24.eu
+webmail-servicekyr7y9-update.uwu.ai
+home001.weeblysite.com
+oilxo.weeblysite.com
+sparkasse-ptan2.info
+paypay-siginpoint.com
 pass.alphatonicfored.com
 taixedatai123.blogspot.lu
 bimkilo28.blogspot.co.il
@@ -79,17 +381,7 @@ xezer.me
 replensis.com
 ojosdemoya.com
 armwoodnews.com
-www.hcljy.com
 jinrus.com
-220u.cn
-sparkasse-tan2.info
-ssl3393978ssl39926241480163.searchmarketingservices.dev
-urdfd.com
-urdhj.com
-urduq.com
-urdwj.com
-urdwz.com
-ursuy.com
 hcwhome.com
 hongyangpai.com
 shopwoh.com
@@ -127,7 +419,6 @@ home-103209.weeblysite.com
 sentinel-ai.vip
 btinternet-105431.weeblysite.com
 blank-template-0-14399.grwebsite.com
-urdgq.com
 fixemobisms.hubside.fr
 authen-montp.ukit.me
 validation-authen.ukit.me
@@ -222,6 +513,10 @@ ikea.transakcje-transferowe.com
 mail.ikea.transakcje-transferowe.com
 account-upgrade2024.weeblysite.com
 trade-paxful.offersverification.site
+home-103440.weeblysite.com
+attnet-103514.weeblysite.com
+ing.informacion-naranja.com
+paypay-vid.com
 xn--oasuhfohs-ypbd.wiki
 ne-istudio.ru
 facebook-case.100597613.help
@@ -271,7 +566,6 @@ comedy.netflix.kidsuper.tv
 www.chiclouds.com
 365f66.com
 0.0.0.0ns10.cryptonight.net
-pancake-swap.xyz
 g1.rooool.com
 led-ger.com
 login-screen-101827.weeblysite.com
@@ -591,7 +885,6 @@ jslfwl.com
 jicai18.com
 jpppost.com
 ipaigd.com
-irsfed.com
 ipv6.18-237-0-28.cprapid.com
 home-108430.weeblysite.com
 home764.weeblysite.com
@@ -1197,7 +1490,6 @@ tga.dev
 cs0102.com
 dabit.mufj-vlsa.online
 cs0546.com
-cs0189.com
 att-109171-103706.weeblysite.com
 sdxcsw.com
 jizzfiesta.com
@@ -1458,7 +1750,6 @@ t0kosp2cket.top
 account.altdlgital.in
 t0koop2cket.top
 facebooksecuritys.blogspot.is
-allconfsbot.website
 freefire-reward-garena.ru
 facebooksecurity.blogspot.sg
 botysiaa.com

+ 26 - 27
yoroi_suspicious_level2.dns

@@ -9,79 +9,85 @@
 # Category        : Suspicious
 # Confidence      : 8
 #
-ssl5359533ssl37642246719388.searchmarketingservices.dev
 2003659.com
 att-currently-29-24-2024.weeblysite.com
-b2033.top
+beneficiosbpnonline.com
 bently.freexsuit.in
-cetma.it
 cm6uda.com
+dkb-de-online.com
 fdzzw.com
 financialconsiderablewixnwy.replit.app
 frankbowles.com
-galaxies.mantasprotocol.net
 helps-center-page-number-12589365.io.vn
+hugrid.net
 iihaub.com
 imtoken-bn.biz
 imtoken-bn.rip
 imtoken-yi.top
-iofppkw.com
 ivestingsworldram.click
-jhjgfgcom.com
+j551001.com
 jilb00b.anakembok.de
-lvd186.com
+kv609.com
 metileann.com
 mkctja.com
 mycyh.com
 mystgate.net
-pubgsteam.com
+qrfqavtmsm.net
 recona-eg.net
 required.conceptforums.com
 sunflowerremote.net
 sxflash.net
 t0kenq0cket.com
-telegagc-mhp.top
 telegagc-uxv.top
+telegagc-mhp.top
 telegajn-vby.top
 telegarc-ipl.top
+telegeram-q.com
 teleghlk-qlb.top
 teleghlk-wrm.top
-telegeram-q.com
-telegorme.com
 telegpen.fit
+telegorme.com
 telegrcmc.com
 tgadminuser.webcts.top
 tokenp0ckht.one
 tokenpocket-tpern.net
-tokenpocket-tpvmu.com
 tokenpocket-tpoem.net
 tokenpockkt.top
+tokenpocket-tpvmu.com
 tokentt.app
 tpkkn.com
 unfreezingrestrictions.top
 unixcw.com
-uradw.com
 urafp.com
+uradw.com
 uragn.com
 urakj.com
-urajw.com
-urasd.com
-urasf.com
 urasw.com
-uratb.com
+urasd.com
 uraxr.com
 uraxw.com
 urayp.com
 urayr.com
+uratb.com
+urajw.com
+urasf.com
 urazp.com
 urdqu.com
 xinganxian.homes
 zimbrasummary.x24hr.com
 dhlaustai.com
-qrfqavtmsm.net
+galaxies.mantasprotocol.net
+jhjgfgcom.com
+lvd186.com
+theworldsinvesing.click
+xdywna.com
+telstra-104285.weeblysite.com
+b2033.top
+iofppkw.com
+ssl5359533ssl37642246719388.searchmarketingservices.dev
+cetma.it
+pubgsteam.com
 mail0.googgle.workers.dev
-dkb-de-online.com
-j551001.com
 self.file.seek
 www.literoved.ru
 www.australiasupplementwarehouse.com
@@ -1850,7 +1856,6 @@ willoughbysmodelcars.com
 campbelljunkremoval.com
 spacejunkie.hu
 bestrongandhealthy.com
-beneficiosbpnonline.com
 t8fn1.shop
 urptt.com
 ebaywholesale.com
@@ -2038,7 +2043,6 @@ keppninni.com
 kegongtanye.com
 jnn5kosus9v0lzx6yxjjva.tiiny.site
 igovafrica.com
-id-ddasnkee.com
 home-sites.weeblysite.com
 hn5qcb.com
 hello-world-hidden-dew-6be2.vurtasispo.workers.dev
@@ -3748,7 +3752,6 @@ pl821.com
 hiphopsol.com
 oudusm.com
 id429.com
-kv609.com
 le582.com
 kd637.com
 lk312.com
@@ -4382,7 +4385,6 @@ wzh9tg.com
 0eac93cb.7dc79c02a28e1520a86dda0e.workers.dev
 post.redeliverysu.info
 yukisushiwpg.com
-xdywna.com
 skatehorde.com
 tzlsgg.com
 sohbetz.com
@@ -5313,7 +5315,6 @@ r3fy6.shop
 imtoken-nv.top
 raiffeisenmax.icu
 imtoken-bv.biz
-telstra-104285.weeblysite.com
 r9ogn4.webwave.dev
 ajajwjw.privrendom.com
 s6pv4.shop
@@ -5573,7 +5574,6 @@ ourtime.auth-mediia.workers.dev
 hurdczx.bhyydc.workers.dev
 kynfor.com
 kynfnja.com
-hugrid.net
 humaza.net
 gwazy.net
 gusuae.net
@@ -5639,7 +5639,6 @@ e2986fab-e6b0-4af0-ba62-9597b5452993-00-yd479v4g1znm.riker.replit.dev
 rewasy-ff-garens.ru
 orangebv33.convertbuilder.com
 fakeserhelpsreivew-facesonseriengoies-16837.io.vn
-theworldsinvesing.click
 debugv2vault.xyz
 new.tollsesd.cyou
 b5046.top

Некоторые файлы не были показаны из-за большого количества измененных файлов