root 3 years ago
parent
commit
3d8db64f5c
4 changed files with 1801 additions and 1543 deletions
  1. 347 246
      yoroi_malware_level1.dns
  2. 1043 1035
      yoroi_malware_level2.dns
  3. 167 17
      yoroi_suspicious_level1.dns
  4. 244 245
      yoroi_suspicious_level2.dns

File diff suppressed because it is too large
+ 347 - 246
yoroi_malware_level1.dns


File diff suppressed because it is too large
+ 1043 - 1035
yoroi_malware_level2.dns


+ 167 - 17
yoroi_suspicious_level1.dns

@@ -9,6 +9,173 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+acikdeniz-kredi-mobil.tk
+collectpubg2022.dcxuc.com
+bmhjmhfo.net
+rakoten.co.ip.lfegvrvc.ml
+frimlbb23claims.mooo.info
+acikdeniz-kredi-mobil.ml
+ofgcsbm7bn.ofgcsbm7bn.nangalkot.tv
+exposed-itacity.ml
+steamcommiinity.com
+uidhfuegdf.weeblysite.com
+stearnmcommunity.com
+adirieneck.top
+amazonvs.shop
+www.postsonlineups.com
+mama.rpm7spin.com
+04396a8d-6785-4758-8bd2-c40e487bea9f.id.repl.co
+www.cheex.com
+bimcellatamon.net
+copia-meli.web.app
+apophissecurity.biz
+overjoyedjitteryblog.colpa06763.repl.co
+mtb0nlinebnkinngcslls.pages.dev
+updatemail-102673456.weeblysite.com
+discordstatsbot.com
+business-help-service-bf8df.web.app
+bwie-22ab7.web.app
+business-help-service-8d6e6.web.app
+eeee-f67c3.web.app
+0640f5b9-e1b1-45e9-a0be-6d09e05525d9.id.repl.co
+maggaluconsultfacial.com
+fr191102201eura.click
+rbfc.cloud
+website-resmi.biz.id
+wcsxhds.cn
+bcelll.com
+steamcomunitly.site
+acikdeniz-com.tk
+acikdenizmobilsubemv1-com.tk
+trust-wallet.uite.org
+acikmobildenizv2ka.tk
+bdsdiemphat.net
+confirma.reactivalotuyo.repl.co
+foxo.online
+gggbet365ok.com
+letxoscore.xyz
+nabhelp-au.com
+nowg.top
+secure.mynab-log.in
+twistersa.co.za
+afinaltest.com
+rbfc.buzz
+att-100876.weeblysite.com
+www.6294h.xyz
+www.acikmobilldenizsube.ml
+americfirstcu.info
+metamask.io.merge.wrench.ae
+americafirst5.com
+www.xn--devletkapsiade-egcb.com
+paylah.shop
+acikmobilldenizsube.tk
+nouwwabilet-sicaminu.web.app
+peaceifuilu.top
+dbswallets.top
+acikmobilldenizv2.tk
+anz-secure.top
+www.swiftcitizen.com
+escuelawanderlust.com
+steep-wind-2976.slimshacome.workers.dev
+acikmobilldeniz.tk
+reddidb.com
+geothermaldesigninstall.com
+konfirmasitarif.web-normal.com
+bionicwebdesign.com
+referencemarketinggroup.com
+ff-claimbundle1111692.cishop.biz.id
+ff-claimbundle1118542.cishop.biz.id
+ff-claimbundle11191128.cishop.biz.id
+grandiose-guiltless-niece.glitch.me
+ivoproject.w3spaces.com
+shining-pointed-parcel.glitch.me
+groupwarkdalia.viiral.biz.id
+groupwags0gstd.viiral.biz.id
+onedrivepdfform-sweepcorpregtr.web.app
+opan-sea.com
+bafybeieu2tjkghhnv7z2k5akzjubatumaucer2ezqa5tvrdwvh53jmcf4m.ipfs.dweb.link
+citizens-0nlinebnkcrv.pages.dev
+citizens0nlinerns1.pages.dev
+rakoten.co.ip.eiqdjdrn.tk
+www.upaidcustoms.com
+www.metafiwise.com
+ci-z.cn
+dustrious.cyou
+first-horizonsecureme.com
+g1entmedia.com
+sydcoenergy.com
+www.20-220-34-205.cprapid.com
+bayc5-live.xyz
+mail.20-220-34-205.cprapid.com
+boredapeyachtclub3-free.xyz
+dbswallets.shop
+online.baking-singaporre.com
+399.haiwaiym.top
+onedrive.goojoes.workers.dev
+site.opemsea.us
+grapefruit14471818.brizy.site
+www.rzvr.cn
+lfegvrvc.ml
+rakebicu.myhostpoint.ch
+dbstapay.top
+335166.com
+www.coinbasefortune.com
+secure-metamask.cf
+dbssg.top
+exodus.yathra-travels-promotions.com
+docshared-river-96de.fri9hlxh.workers.dev
+exodus.omborrecruitment.com
+auspost-aur.cc
+www.ammazons.xyz
+alphan.762126.repl.co
+722caa53b2c1a.granu.co.tz
+secu-info-france.fr
+simpleminioffice.com
+ccmogen.com
+auspost-aust.cc
+onedrive.killgfat.workers.dev
+dbspaylsh.shop
+dbspaylsh.top
+registro.obtenloyamismo.com
+touchngorprl15.top
+khoksher98812.co.vu
+claemacooun.co.vu
+www.xn--metmask-u3a.site
+supportteam6585123.co.vu
+supportteam65851232.co.vu
+steamcommunityvo.asia
+3kan.net
+verify281982indentity.info
+verify359382indentity.info
+accessblock-id.com
+www3.amozozhnou.co.jp.lrbnfnu.cn
+www.onebankpatag.ml
+blockchain-db0f7.web.app
+www.accessbanklnglcbc.com
+citizens-0nlinebnkcrp.pages.dev
+memberfree023.16-b.it
+att-1987943.weeblysite.com
+acikdeniz-kredi-mobil.ga
+dyno.ink
+waesrlike.cyou
+qgfy.buyive.top
+citizens-0nlinebnkcr4b.pages.dev
+maisieloe.rest
+8765417641414.hyperphp.com
+pehoebekc.bar
+krancesca.store
+bafybeigouj6azwuv3xxqltddyvvxyq6sesglt53rfy2gzkatlm67olsfhi.ipfs.cf-ipfs.com
+handsomeie.top
+zebadiahi.top
+verify28691indentity.info
+verify359281indentity.info
+verify28850indentity.info
+mtb0nlinebnkinngv6.pages.dev
+verify64882indentity.info
+logn-aol-4a26.qeury22.workers.dev
+rsfs.co.za
+bmcellsabahtarife.tk
+readingbeautysalon.co.uk
 maya.e-moneymhs.com
 supportteam665475.co.vu
 supportteam6654755.co.vu
@@ -60,7 +227,6 @@ appeal-status-10006428795.web.app
 yuio-173e9.web.app
 188bet36.com
 irewi-7a979.web.app
-rbfc.buzz
 ppxkk-567ec.web.app
 huoserieur09291.asia
 coinbase.auth-recovery.com
@@ -96,11 +262,6 @@ jp.canalslifestyle.com
 mettasmasks.com
 telus-raccoon-prod.acro.website
 bafybeias77hrdbrsalgbx6ti2fhrmq3yvwuymt4lrnvhjgdwlbl4efdrni.ipfs.cf-ipfs.com
-afinaltest.com
-twistersa.co.za
-bdsdiemphat.net
-confirma.reactivalotuyo.repl.co
-foxo.online
 pnwmetalarts.com
 ppjj-6a1f9.web.app
 www.fashionme.royalelegalgroup.com
@@ -135,7 +296,6 @@ globalindependentvaults.com
 www.3659ii.com
 nhldsrlk.ga
 dawn-2ca5.uotuvclatt0.workers.dev
-letxoscore.xyz
 decdfuiygu.weeblysite.com
 bt-coin.vip
 mail11.goggle.workers.dev
@@ -183,9 +343,6 @@ affectionate-jackson.176-113-115-105.plesk.page
 operacionesnuevas.com
 suncoast-help-desk.info
 mybtmailx.blogspot.hr
-logn-aol-4a26.qeury22.workers.dev
-secure.mynab-log.in
-nabhelp-au.com
 americafirst.serverp2p.com
 steanconmunuty.ru
 americafoirest.com
@@ -253,7 +410,6 @@ procurement-department.com
 nadas123.xyz
 att-103571-102954.weeblysite.com
 pdfdocument2-794bf.web.app
-acikmobildenizv2ka.tk
 www.aib-service-queries.com
 jpmc-unification-uat.eventfarm.com
 worldinformaticace.com
@@ -279,7 +435,6 @@ c6ea9ba085e7a.mariademattiassec.sc.tz
 cef9ce1058528.mariademattiassec.sc.tz
 netflix.shouttolearn.com
 k51qzi5uqu5dll36tqfz1vmgn6z657pmshclb3rufmemn6x3xql94pk3ofrcoi.ipns.dweb.link
-gggbet365ok.com
 agoracoletasegura.com
 20223656.net
 3659iii.net
@@ -395,7 +550,6 @@ logs.blizdricz.cyou
 user53.redirectme.net
 1bimoxcell.net
 ab.budgetblind.co
-bmcellsabahtarife.tk
 link.taubeinvestment.com
 denizdenv1acik.ml
 denlzbanikcom.tk
@@ -702,7 +856,6 @@ bafybeibhdmbgrbtpgrqbz55sxwdmzm33s6e2ww6ilwbmt3jz3fmpmbv64q.ipfs.dweb.link
 txsolut001.bitbucket.io
 steamcomnunily.ru
 bliciaju735623mb.listingas.repl.co
-secursalvirtual.welcoome.repl.co
 bafybeia5lbqhyoxsk22k2q473toiphxxhrpldwztpvnlw76qkjcs4fkhji.ipfs.dweb.link
 bafybeifuj5nalym5xn7biif3jhl3rdcdhnmpfinjmy6uhnllevyuqnbe3u.ipfs.w3s.link
 bafybeif2dlwgx2tim3wanyfcekhfacmfqcjmyqsh7xm652cymtxersnjda.ipfs.dweb.link
@@ -722,7 +875,6 @@ denizmobil-com-tr.net
 denizmobilegiris.net
 21a25b68-6231-4a53-b4fe-abe719d324c2.id.repl.co
 post.updatecom.co
-nowg.top
 yokd.top
 usaps-track.sofarm.top
 updatecom.co
@@ -802,7 +954,6 @@ gdty.foundteen.icu
 restricted7071689issueviolationbusiness.co.vu
 grupwa11114957.my-v1.ninja
 bqghdtdgh.weeblysite.com
-readingbeautysalon.co.uk
 activarpin-outlook.soporteonline00.repl.co
 hqtofs.webwave.dev
 lucas.deolaran.myretirementradio.com
@@ -847,7 +998,6 @@ tumberfourie.co.za
 seasailingadventure.co.za
 wetpumps.co.za
 rmchem.co.za
-rsfs.co.za
 ulwezi.co.za
 surgitech.co.za
 vcint.co.za

File diff suppressed because it is too large
+ 244 - 245
yoroi_suspicious_level2.dns


Some files were not shown because too many files changed in this diff