root 1 year ago
parent
commit
46ec7f87cf
6 changed files with 4176 additions and 3894 deletions
  1. 10 373
      nethesis_level3.netset
  2. 142 142
      whitelist.global
  3. 2294 1820
      yoroi_malware_level1.dns
  4. 1233 1377
      yoroi_malware_level2.dns
  5. 430 114
      yoroi_suspicious_level1.dns
  6. 67 68
      yoroi_suspicious_level2.dns

File diff suppressed because it is too large
+ 10 - 373
nethesis_level3.netset


+ 142 - 142
whitelist.global

@@ -14,101 +14,202 @@
 62.149.128.154
 62.149.128.151
 62.149.128.160
-161.35.148.219
-188.166.38.161
-178.128.254.180
+165.232.94.113
+188.166.93.86
+188.166.97.199
+159.65.197.198
+68.183.7.251
+146.190.234.168
+206.189.101.48
+178.128.246.16
+167.172.47.117
+167.99.223.51
+142.93.235.147
+164.92.219.73
+188.166.63.108
+167.71.79.14
+174.138.8.207
+161.35.80.152
+159.223.223.100
+174.138.2.121
+167.99.40.163
+161.35.157.15
+161.35.95.211
+167.99.40.250
+161.35.153.110
+146.190.238.4
+146.190.238.76
+167.71.8.45
+142.93.134.189
+167.99.217.178
+161.35.88.180
+134.122.50.84
+104.248.207.61
+167.99.42.32
+64.227.65.28
+164.90.194.17
+161.35.159.44
+188.166.73.117
+146.190.29.122
+188.166.23.162
+167.99.216.203
+146.190.31.250
+188.166.31.25
+188.166.15.149
+178.62.206.20
+146.190.229.210
+146.190.22.63
+128.199.60.18
+188.166.24.24
+206.189.11.13
+68.183.9.41
+206.189.5.114
+206.189.99.106
+68.183.15.129
+159.223.214.180
+161.35.81.200
+152.42.138.25
+64.225.64.7
+188.166.109.135
+188.166.116.155
+188.166.45.126
+165.232.89.253
+188.166.87.159
+167.71.76.184
+167.99.211.228
+188.166.70.107
+161.35.144.29
+165.22.198.217
+146.190.238.159
+134.122.58.16
+152.42.128.247
+165.22.207.243
+167.172.45.223
+128.199.43.100
+167.71.2.98
+188.166.91.196
+164.92.158.210
+146.190.225.217
+167.99.40.4
+164.92.152.2
+159.65.203.88
+178.62.219.148
+142.93.131.113
+157.245.65.18
+167.99.43.70
+104.248.82.252
+188.166.86.111
+142.93.131.251
+164.92.219.226
+178.62.240.117
+159.223.213.107
+206.189.2.123
+161.35.90.225
+134.122.56.28
+159.65.207.198
+164.92.212.150
+188.166.72.23
+188.166.17.46
+64.225.71.115
+167.99.46.183
+128.199.34.191
+188.166.83.149
+178.128.254.64
 178.62.238.76
 188.166.126.240
 134.122.63.204
 188.166.112.196
+161.35.148.219
+188.166.38.161
+178.128.254.180
+142.93.129.129
 167.99.219.82
 128.199.61.15
-142.93.129.129
-64.227.78.25
-128.199.48.140
 167.172.38.97
 178.62.240.209
+64.227.78.25
+128.199.48.140
 178.62.221.146
 167.71.68.193
+206.189.12.139
 188.166.41.33
 159.223.237.208
-206.189.12.139
 159.223.215.242
-104.248.94.94
-104.248.202.179
 174.138.6.198
 178.62.217.110
-164.92.220.56
+104.248.94.94
+104.248.202.179
 167.71.64.103
 161.35.84.164
+164.92.220.56
 64.225.68.114
 188.166.73.43
+159.223.11.82
 134.209.192.110
 161.35.81.169
-159.223.11.82
 178.62.204.160
 167.172.33.231
-188.166.17.142
-188.166.95.89
 164.92.215.172
 159.223.215.34
 161.35.153.85
+188.166.17.142
+188.166.95.89
 164.90.192.245
 188.166.9.247
-188.166.85.76
 159.223.212.220
-164.90.204.45
+188.166.85.76
 146.190.226.124
 104.248.95.189
-188.166.91.192
-104.248.194.112
+164.90.204.45
 164.92.152.178
 104.248.201.37
+188.166.91.192
+104.248.194.112
+164.92.209.130
 178.128.251.154
 159.65.199.185
-164.92.209.130
-188.166.46.90
-64.225.71.102
 188.166.68.157
 159.223.225.41
 167.99.210.125
 188.166.29.153
-178.62.240.195
-188.166.48.29
+188.166.46.90
+64.225.71.102
 178.62.192.199
 167.172.38.137
 178.128.254.142
+178.62.240.195
+188.166.48.29
 167.71.78.214
 161.35.93.220
-167.71.73.171
-188.166.21.67
 167.71.71.43
 188.166.77.48
 143.198.131.11
-134.209.93.118
-64.225.71.170
+167.71.73.171
+188.166.21.67
 188.166.103.15
 188.166.85.242
 167.71.66.0
 174.138.15.105
-167.71.10.219
-104.248.205.106
+134.209.93.118
+64.225.71.170
 159.65.192.201
 134.122.55.228
-178.62.222.164
-206.189.99.25
+167.71.10.219
+104.248.205.106
 64.227.64.202
 159.223.0.121
 206.189.0.226
-165.22.205.55
-188.166.36.213
+178.62.222.164
+206.189.99.25
 159.223.215.77
 188.166.11.138
 167.99.216.37
-104.248.87.189
-188.166.55.209
+165.22.205.55
+188.166.36.213
 142.93.230.36
 142.93.234.122
+104.248.87.189
+188.166.55.209
 64.227.75.231
 159.223.218.42
 146.190.18.242
@@ -116,127 +217,26 @@
 161.35.88.121
 146.190.228.120
 165.22.197.37
+159.223.0.173
 104.248.93.140
 134.209.91.165
-159.223.0.173
 165.22.192.54
 164.90.197.63
-167.172.35.81
 188.166.79.65
+167.172.35.81
+178.128.248.28
 167.71.11.73
 104.248.192.120
-178.128.248.28
-188.166.80.143
-188.166.91.80
 164.92.156.249
 161.35.146.125
+188.166.80.143
+188.166.91.80
 178.62.247.86
 159.223.7.204
-188.166.97.199
-159.65.197.198
-165.232.94.113
-188.166.93.86
-68.183.7.251
-146.190.234.168
-178.128.246.16
-167.172.47.117
-206.189.101.48
-164.92.219.73
-167.99.223.51
-142.93.235.147
-188.166.63.108
-167.71.79.14
-174.138.2.121
-174.138.8.207
-161.35.80.152
-159.223.223.100
-167.99.40.163
-161.35.157.15
-146.190.238.76
-167.71.8.45
-142.93.134.189
-161.35.95.211
-167.99.40.250
-161.35.153.110
-146.190.238.4
-167.99.217.178
-134.122.50.84
-104.248.207.61
-161.35.88.180
-164.90.194.17
-161.35.159.44
-167.99.42.32
-64.227.65.28
-188.166.23.162
-167.99.216.203
-188.166.73.117
-146.190.29.122
-188.166.31.25
-146.190.31.250
-128.199.60.18
-188.166.24.24
-188.166.15.149
-178.62.206.20
-146.190.229.210
-146.190.22.63
-206.189.11.13
-68.183.9.41
-206.189.5.114
-159.223.214.180
-161.35.81.200
-206.189.99.106
-68.183.15.129
-188.166.109.135
-188.166.116.155
-152.42.138.25
-64.225.64.7
-165.232.89.253
-188.166.87.159
-188.166.45.126
-188.166.70.107
-167.71.76.184
-167.99.211.228
-165.22.207.243
-167.172.45.223
-161.35.144.29
-165.22.198.217
-146.190.238.159
-134.122.58.16
-152.42.128.247
-188.166.91.196
-164.92.158.210
-128.199.43.100
-167.71.2.98
-178.62.219.148
-142.93.131.113
-146.190.225.217
-167.99.40.4
-164.92.152.2
-159.65.203.88
-188.166.86.111
-157.245.65.18
-167.99.43.70
-104.248.82.252
-178.62.240.117
-159.223.213.107
-142.93.131.251
-164.92.219.226
-206.189.2.123
-161.35.90.225
-188.166.17.46
-64.225.71.115
-134.122.56.28
-159.65.207.198
-164.92.212.150
-188.166.72.23
-188.166.83.149
-178.128.254.64
-167.99.46.183
-128.199.34.191
+159.223.215.118
+206.189.101.63
 164.92.154.71
 178.62.192.126
-206.189.101.63
-159.223.215.118
 134.209.136.185
 134.209.206.121
 138.197.176.207

File diff suppressed because it is too large
+ 2294 - 1820
yoroi_malware_level1.dns


File diff suppressed because it is too large
+ 1233 - 1377
yoroi_malware_level2.dns


+ 430 - 114
yoroi_suspicious_level1.dns

@@ -9,13 +9,390 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
-www.liineelixxiiaa.com
+usps-s.shop
+upsw.usspawy.top
+urhebzh.com
+urhebje.com
+urhebwq.com
+urhebjr.com
+urhebhe.com
+urhebzg.com
+urhebge.com
+kup-kosiarke.pl
+urhebhw.com
+374dhg.terbaiik.com
+nsije7.terbaiik.com
+ikea-kuponupominkowy.online
+www.ikea-kuponupominkowy.online
+mail.ikea-kuponupominkowy.online
+subanshek.blogspot.am
+ups-tracking-id72661.package4.support
+imtoken-qc.one
+imtoken-qd.one
+marketplace.mariachiscdmx24.com
+logntheidussser87.hstn.me
+shaunmckenna.com
+formuulir-pennukaran-poin.resmi-vip.art
+newlinkns0mx4n.kislow.biz.id
+subanshek.blogspot.com.cy
+micron-s.com
+free-flre-spinlznjuis.alfarizihost.biz.id
+telegramuk.com
+www.contratafacil.cloud
+xn--connexion-scuris-lqbf-com.preview-domain.com
+att-101539-107826.weeblysite.com
+pre-contratosolicitado.online
+www.soksonfirsatlarim.xyz
+www.pmmxscf.cn
+newlinkbzie0ve.kislow.biz.id
+mailing-105325.weeblysite.com
+accunt.booking-reservra.com
+www.dmbzr.com
+usps.trackpostspot.com
+free-flre-spinifjnmrf.alfarizihost.biz.id
+canadap0st-post3scanada-ca-v3eservicescom458109.codeanyapp.com
+broken-dew-b851.rootsz.workers.dev
+jp.amzdata.cn
+4d7t4c1.co
+file.dontjudge.workers.dev
+www.xpj83331.com
+www.marketplace.mariachiscdmx24.com
+blue-resonance-2027.mmiloud.workers.dev
+befxc.blogspot.is
+www.czj85a.cn
+vorimcsee.etherealspires.top
+fedger-live-us.luno-logi.com
+global.linktfau.click
+usps.postsawl.com
+bat.gov-112.ink
+anchorex.com
+aged-limit-99e7.b9nk.workers.dev
+att-100672-106614.weeblysite.com
+att-109928.weeblysite.com
+hello-world-yellow-star-1c35.yivogay643.workers.dev
+prcescnfrmtion-109287705.ydns.eu
+bsn1srcvery1968.ydns.eu
+rcvyacntstdbsnss.ydns.eu
+coinbase.ucenter-signingb.com
+site-home.weeblysite.com
+cnfrmtnpgbsns182.ydns.eu
+tawqbt.bsaqoz.workers.dev
+metapolice1956.fly.dev
+global.linktbee.click
+apple.unlimited-art.com
+ikitufyf.dynv6.net
+ikkkfvdg.dynv6.net
+ierczxnm.dynv6.net
+idltmtna.dynv6.net
+c9fq5.shop
+www.sdzxg.cn
+usps.inquireuspsshipus.com
+klaimz-dana-kaget-ramadhan-berkah2024.danaxy.biz.id
+global.linktmar.click
+hello-world-mute-snow-e7d7.kahar10116.workers.dev
+log-in-page.com
+danaa-baruxdagetsz.newsgaz.biz.id
+www.etaole.cn
+inquireshipg.com
+q6zp9.shop
+web-whatsapp.xyz
+asdasdadad.cleverapps.io
+idbyyzox.dynv6.net
+ihufaove.dynv6.net
+5566.blog
+tokajp.app
+usps.inquireuspsship.com
+coiinmase.fennicex.com
+56789.ai
+yg3d.gody4r.biz.id
+worker-soft-rain-c084.donofak715.workers.dev
+bsxop.bgmievents.in
+www.wnukg.cn
+spndpgacntbsns.ydns.eu
+w3xn9.shop
+www.amrweng.com
+teamtopei.top
+teamvpei.top
+usps-u.top
+worker-wandering-king-de71.xegepil982.workers.dev
+hello-world-late-heart-0986.demeter12.workers.dev
+kma-institute.ps
+viralink.shop
+qsnsjsuwi.vrl2023.com
+api.teiegrom-za.com
+telegram.web-tgg.pw
+tgadminuser.web-tgg.pw
+tgadminuser.webcsc.pw
+tgadminuser.webcsc.xyz
+temies.com
+tgadminuser.webatt.club
+tgadminuser.webttt.top
+dolbaebshesp.in
+teiegrom-xo.com
+teiegrom-xm.com
+gov-security-info-update.com
+cbsmc-sg.com
+rffhhhgfh.vrl2023.com
+devrkaan.onthewifi.com
+auzpost-send.cc
+riaakomodizx.mantej.workers.dev
+newlinkg7rjvnf.kislow.biz.id
+mpa1hg.relzhost.biz.id
+fgafb.dtcgm.biz.id
+tipfile.qasimpercy372.workers.dev
+ch.alinasow-official.com
+www.accedi.p2p.18-153-11-62.cprapid.com
+phototan-reaktivierung.app
+login-ao1.de383272.workers.dev
+giveskins-cs2.com
+millennium-online.com
+rakutan-bak05.cyou
+sesliroman.com
+tok2np0cklt.top
+urkeabk.com
+urkeajr.com
+urkeayt.com
+urkeawu.com
+urkeaqy.com
+uspscheckshipping.top
+www.bseqk.cn
+www.ksmyeituopw.net
+www.naoniang.cn
+www.ye5xka.cn
+x98ultratvonline.com
+smbc.com-pdp.com
+urheacr.com
+urheakd.com
+urhebht.com
+urkeatz.com
+urkeatc.com
+usps.czjhnifskr.top
+usps.inspectpost.com
+usps.mytrackinguq.top
+usps.mytrackinguw.top
+usps.mytrackingur.top
+usps.mytrackingyv.top
 usps.uspstack.xyz
+archimedecultura.it
+skinport.com.ph
+ggfjujgh.com
+apple.fengdequankeji.com
+apple.xiaoyuanzhiqing.com
+356623.com
+agimobiliare.ro
+www.o5isxc.cn
+www.hhryngk.cn
+www.hvfdl.cn
+www.hshulzn.cn
+www.kbwpw.cn
+identifi931.urest.org
+www.qhuxm.cn
+antai-amendereunion.info
+277336.com
+www.lblqg.cn
+www.pfdta.cn
+www.olfms.cn
+www.dryft.cn
+www.tzyxe.cn
+www.m6ts2g.cn
+www.epbin.cn
+searchjobsinsingaporevip.real-vvip.com
+amdin13.cleverapps.io
+wvnye.blogspot.md
+c.915vip26.xyz
+we1af2.blogspot.is
+ksosb4.terbaiik.com
+quickhelpdesk.in
+tokenpakket.com
+www.fyeytcjx.dynv6.net
+www.fpqnvtpe.dynv6.net
+www.gclddhqy.dynv6.net
+www.gaxjrlrp.dynv6.net
+www.fwsktfgz.dynv6.net
+www.fpavqpzv.dynv6.net
+www.fnusnwgn.dynv6.net
+www.fvumcuix.dynv6.net
+www.fsfublnq.dynv6.net
+www.fzjvvcdg.dynv6.net
+www.fnkbqlco.dynv6.net
+www.gcqvlsva.dynv6.net
+www.fxufhtha.dynv6.net
+www.frzhrulm.dynv6.net
+www.fxrxfvwb.dynv6.net
+www.fxpmpofv.dynv6.net
+www.fqcbwruq.dynv6.net
+www.furnpezh.dynv6.net
+www.rrrouibyiin.client-support.xyz
+2.creditsui.com
+rrrouibyiin.client-support.xyz
+uniswap.oasisapp.dev
+555365p.com
+shopsreview.top
+telegramx-me3.privatemessage25.com
+t7ffg.shop
+imtoken-qb.pro
+viridischemical.ferreracademy.com
+cathcap.ferreracademy.com
+fitlifebrands.ferreracademy.com
+sbertram.ferreracademy.com
+reinvestment.ferreracademy.com
+horwitzlaw.ferreracademy.com
+ywcss.ferreracademy.com
+confirmation.ours-project.workers.dev
+cfpboard.ferreracademy.com
+cyclomedia.ferreracademy.com
+source-cap.ferreracademy.com
+murphytower.ferreracademy.com
+fastrucking.ferreracademy.com
+orci.ferreracademy.com
+dekcohousing.ferreracademy.com
+gpalab.ferreracademy.com
+ledger.aubinfo.com
+rotshtein.ferreracademy.com
+simplify-wealth.ferreracademy.com
+angelosrm.ferreracademy.com
+niteize.ferreracademy.com
+onecallcm.ferreracademy.com
+steiergroup.ferreracademy.com
+socketmobile.ferreracademy.com
+bottleone.ferreracademy.com
+glenwoodmason.ferreracademy.com
+fractal.ferreracademy.com
+nutrabolt.ferreracademy.com
+gametembak.midasbuys.biz.id
+20223656.net
+att-yahoo-mail-105789.weeblysite.com
+att-100789.weeblysite.com
+btinternet-105835.weeblysite.com
+service.qoll.workers.dev
+btinternet-101134.weeblysite.com
+ups-tracking-id68524.package2.support
+sbc-106342.weeblysite.com
+btinternet-109859.weeblysite.com
+stop-posbsecurity.pw
+btinternet-106803.weeblysite.com
+whatsvpp.icu
+us-upholdlogin.teachmore.com
+hqmlbrcc.dynv6.net
+hnhzxnqd.dynv6.net
+www.uqnnwhu.cn
+www.rmxbs.cn
+tracking.postedeliverynow.it
+www.recruitment-amazon.com
+www.vaiyn.cn
+www.strghxa.cn
+www.ervsg.cn
+mercadobitcoinsih.com
+www.yrkaahz.cn
+www.onoqh.cn
+www.wntho.cn
+www.yunxjv.cn
+www.qaaly.cn
+www.quytf.cn
+www.kiomqkc.cn
+www.yunszs.cn
+www.ioxpycb.cn
+www.ngzhg.cn
+www.xtwvttcf.cn
+www.otmpg.cn
+www.kzoks9j.cn
+www.jqxqc.cn
+www.qxsbu.cn
+www.qbozv.cn
+www.ofglc.cn
+www.qfjio.cn
+www.uqkhvge.cn
+www.ihwsf.cn
+www.kcbsc.cn
+www.wnhwsay.cn
+www.lpgnt.cn
+www.ygfra.cn
+www.ngvnf.cn
+mercarj.top
+www.wdxuzzg.cn
+www.lhaqq.cn
+www.liuoz.cn
+www.nvfow.cn
+www.hnhzxnqd.dynv6.net
+www.huwbdebv.dynv6.net
+www.hqmlbrcc.dynv6.net
+pagehelp.taki-lois-an.top
+www.ikitufyf.dynv6.net
+www.ekwvr.cn
+tgadminuser.webcsc.club
+ll-whats-app.co
+789hotel.com
+kosiarki-wroclaw.pl
+cougresstransmessage.top
+www.uchvh.cn
+dossier-regularisation-info.com
+kosiarki-warszawa.pl
+uspd.usspaiw.top
+tiemies.com
+authpostpro.com
+brushstrokespainters.net
+markeplace-item.iishaq.com
+ups-tracking-id53847.package109.delivery
+www.vfznuni.cn
+www.hmgnnke.cn
+ups-tracking-id42392.package110.delivery
+t8lw2.shop
+www.vnlhept.cn
+aswakleader.hosted.phplist.com
+aktifkann-dana-paylater.resmi-vip.art
+hsdvxc.litioongoman.buzz
+eastlink.linkthea.click
+krafton-home.creatorredeem.workers.dev
+usps652.com
+attt-107422.weeblysite.com
+hfwrdf.pxmir.xyz
+jsryfs.qqrtt.xyz
+hsfruu.xcdew.xyz
+jksrdd.qqrtt.xyz
+jsfgkt.pxmir.xyz
+jsrtgf.xcdew.xyz
+hsfgcd.pxmir.xyz
+jsfgcv.xcdew.xyz
+hsdfhr.xcdew.xyz
+serviceclient2024.hubside.fr
+sferds.qqrtt.xyz
+convergence.hubside.fr
+att-login23.weeblysite.com
+jsrssf.qrnvm.xyz
+jsrtff.qrnvm.xyz
+dfgerd.qrnvm.xyz
+esdjhbosd.komi.io
+showfbo.com
+vbvfdvdjvv.fyfyvfytvghv.workers.dev
+simplepay-by-otp.gamanpro.org
+biz652.biz
+telegarc-fki.com
+srtfgy.nrxed.xyz
+rogers-100490services.weeblysite.com
+ourtime.datings-cloud.workers.dev
+misty-pond-905a.skniapeoosrp4335.workers.dev
+my-site-100126-104446.weeblysite.com
+inquireuspsshipus.com
+inquireuspsship.com
+bell-105524.weeblysite.com
+att-100795-104344.weeblysite.com
+378-mail-att.weeblysite.com
+rujdff.iyyev.xyz
+jotdyf.nrthq.xyz
+jsfgcd.nrxed.xyz
+hsertf.iyyev.xyz
+hsdfcd.vbgre.xyz
+hsdfcd.nrthq.xyz
+hjsret.iyyev.xyz
+hjtcdu.nrthq.xyz
+hjsgri.vbgre.xyz
+dtrygh.vbgre.xyz
+dhfger.iyyev.xyz
+www.liineelixxiiaa.com
 9u1lop7s.co
 uspsviper.top
 urkeafs.com
 urkeabx.com
-urkeabk.com
 urkeabc.com
 urkeacw.com
 urkeabf.com
@@ -24,11 +401,9 @@ urhebqe.com
 urkeabv.com
 uspw.usspaqu.top
 uspt.usspaqh.top
-usps.czjhnifskr.top
 urhebgq.com
 urhebhq.com
 urhearw.com
-urhebht.com
 webmail-108358.weeblysite.com
 www.magaluizavendas.com
 mail-admin-100033.weeblysite.com
@@ -129,17 +504,6 @@ pdf.office-dropbox.workers.dev
 msoffice.office-dropbox.workers.dev
 abueme-96e1.ehnelacsrralo.workers.dev
 dbs.idevs.pro
-tok2np0cklt.top
-urkeawu.com
-urkeayt.com
-usps.inspectpost.com
-usps.mytrackingur.top
-usps.mytrackinguq.top
-usps.mytrackingyv.top
-usps.mytrackinguw.top
-www.naoniang.cn
-www.ye5xka.cn
-x98ultratvonline.com
 paxful.instenpay.com
 worker-jolly-block-6f75.mailboxretrieval.workers.dev
 outlook.xkljgfjkll.workers.dev
@@ -150,16 +514,12 @@ secure.voicee-love.workers.dev
 service.aeno.lornalane.com
 att-103986.weeblysite.com
 www.paysanswer.com
-urheacr.com
-urkeajr.com
 bt-internet-104960.weeblysite.com
 365xxb.com
 kingsafetynet.club
 seguromensualbancolombiiacol.brizy.site
 www.rebategiftshopping.com
 apple.ridacoprinting.com
-374dhg.terbaiik.com
-fgafb.dtcgm.biz.id
 www.dnmes.cn
 google.devy.top
 a27cst.webwave.dev
@@ -204,7 +564,6 @@ www.ykrqj.cn
 iowcnjzi.dynv6.net
 intgegzu.dynv6.net
 idtmpoxc.dynv6.net
-gov-security-info-update.com
 eaikhxsy.dynv6.net
 duqghqdh.dynv6.net
 az.caregral247.com
@@ -235,7 +594,6 @@ www.ikkkfvdg.dynv6.net
 ielnqoxn.dynv6.net
 inelxami.dynv6.net
 iltgxtkx.dynv6.net
-www.bseqk.cn
 www.iltgxtkx.dynv6.net
 www.inelxami.dynv6.net
 www.idtmpoxc.dynv6.net
@@ -277,20 +635,16 @@ www.efqgflv.cn
 www.tjqqx.cn
 www.rpmaw.cn
 www.cvnth.cn
-misty-pond-905a.skniapeoosrp4335.workers.dev
 www.gwkhrdhy.dynv6.net
-ups-tracking-id32413.package109.delivery
 84d83932-4779-4df3-87e4-41f01655ae62-00-2nebu94r6ddap.sisko.replit.dev
 www.haybc.cn
 www.hoqeb.cn
 www.gbmmb.cn
 bot-trading.fr
 www.japanpost.jp.qxhtuxj.top
-newlinkg7rjvnf.kislow.biz.id
 alxkn2.amazon-locked.gjsh27gjslsi.com
 vmi936706.contaboserver.net
 aktoreas.kz
-usps652.com
 elnhemai.dynv6.net
 www.emgvcwwv.dynv6.net
 edrsnetq.dynv6.net
@@ -321,39 +675,10 @@ www.eixzshxa.dynv6.net
 horoscope-advance.com
 cn.mebtx46.com
 mail-104925.weeblysite.com
-biz652.biz
-giveskins-cs2.com
-millennium-online.com
-rakutan-bak05.cyou
-sesliroman.com
-uspscheckshipping.top
-www.ksmyeituopw.net
 sexpr4essx.za.com
-att-100795-104344.weeblysite.com
-ourtime.datings-cloud.workers.dev
 worker-gentle-salad-dcba.mwantoine.workers.dev
-usps.inquireuspsshipus.com
-inquireuspsshipus.com
-usps.inquireuspsship.com
-inquireuspsship.com
-urheakd.com
-urkeaqy.com
-att-100672-106614.weeblysite.com
 sperneueren-2024.online
-site-home.weeblysite.com
-hjtcdu.nrthq.xyz
-jotdyf.nrthq.xyz
-hsdfcd.nrthq.xyz
-hsertf.iyyev.xyz
-rujdff.iyyev.xyz
-dhfger.iyyev.xyz
-hjsret.iyyev.xyz
-srtfgy.nrxed.xyz
-jsfgcd.nrxed.xyz
 uertds.nrxed.xyz
-dtrygh.vbgre.xyz
-hjsgri.vbgre.xyz
-hsdfcd.vbgre.xyz
 telegrae.net
 telegram.webttt.club
 tg.telegarm-mq.top
@@ -447,50 +772,74 @@ ctt-pt.click
 daviviendainforma.zya.me
 awesgc.ehydr.xyz
 assureformulaire.net
-my-site-100126-104446.weeblysite.com
 universityofcemntraflorida.ukit.me
-mailing-105325.weeblysite.com
-378-mail-att.weeblysite.com
-rogers-100490services.weeblysite.com
-bell-105524.weeblysite.com
 urkebej.com
-7u3mep7s.co
-em4d0lc3d0g.us
-urkeazj.com
-urkeajt.com
-urkeazg.com
-urkeaxb.com
-urkeazf.com
+worker-proud-leaf-c9a2.officeonline.workers.dev
+wedfhc.evvqd.xyz
+uusps.jpscdy.cn
+usps.sskrtypkpk.top
 usps.nbsijdqgse.top
-urkeaxv.com
+urkeazg.com
 urkeajw.com
-usps.srskvdshpt.top
+urkeazh.com
+urkeaje.com
+usps.shipuspscheckb.top
+urkeazj.com
+urkeaxv.com
+urkeaky.com
+urkeafa.com
+urhebst.com
+urhebgw.com
+urhebgr.com
+urhebdw.com
+urheate.com
+urhebfr.com
+urhebfy.com
+telegmgf-xvb.top
+teleggam.fit
+www.torii-s.com
+www.ynehlkl.cn
+www.verifiica.194-48-251-104.cprapid.com
+www.zdipd.cn
+www-smcb-card.com
+www.suzhongyiliao.com
+www.lpg365.com
+www.jqwjg69.com
+www.dragon-hpc.com
+www.dfnvv.cn
+worker-cool-firefly-e4da.im-swellen.workers.dev
+worker-young-flower-4546.xeleje3632.workers.dev
+worker-black-paper-0975.addictedtobaguettes.workers.dev
+webmail-laposte.hubside.fr
+wild-boat-5d2d.admin1834.workers.dev
+wandering-waterfall-02cc.vuknemuspa6773.workers.dev
+web-mail-accountatt-100420.weeblysite.com
+webmaiiiiide34454.weeblysite.com
+verifiica.194-48-251-104.cprapid.com
+usps-packes.com
+usps.shipuspschecka.top
+uspo.usspnu.top
+urkeazf.com
+us.b9nk.workers.dev
+urkeaxb.com
+urkeajt.com
+urkeajq.com
 urheakp.com
-uusps.jpscdy.cn
+em4d0lc3d0g.us
+7u3mep7s.co
+usps.srskvdshpt.top
 usps.hklmkjrlux.top
 usps.tupslpeshi.top
 usps.sqfxfqjnne.top
 usps.voacfcmhfg.top
-urkeaje.com
 usps.huktxmwkik.top
 usps.rvttjkphxo.top
 usps.checkuspsshipus.com
-urkeazh.com
 urkeazd.com
-urkeaky.com
 usps.finduspstransport.top
 usps.finduspsship.top
-urkeafa.com
 usps.jasikehxnv.top
-urhebdw.com
-urheate.com
-urhebgr.com
-urhebst.com
-urhebfr.com
-urhebfy.com
-urhebgw.com
 www.yayrg.cn
-telegmgf-xvb.top
 ddvqx.blogspot.is
 htmyh.blogspot.sn
 sign-in-att-100000.weeblysite.com
@@ -555,7 +904,6 @@ usps.jmitnbiama.top
 usps.etiivnimaj.top
 usps.kduqeohykb.top
 sign-in-att-1009009.weeblysite.com
-usps-packes.com
 vbgtm.blogspot.lt
 teleprom.cc
 on.marcukesh.top
@@ -621,31 +969,20 @@ ledgerdevices-syn.onrender.com
 masmdsd.4z1ip367qm.workers.dev
 5fgfgfgfg4g4gh4rgff.blogspot.sn
 whatss.org
-worker-black-paper-0975.addictedtobaguettes.workers.dev
-teleggam.fit
 teleggam.club
-worker-proud-leaf-c9a2.officeonline.workers.dev
 secure-login-sso.com
 365.linwanrong.workers.dev
-verifiica.194-48-251-104.cprapid.com
 accedii.194-48-251-104.cprapid.com
-www.verifiica.194-48-251-104.cprapid.com
 uspsv.top
 yaho0.wiboqo.workers.dev
 mail.xn--kredikartiadee1-glc.com
 bbva.es-seguridad-cliente.com
-usps.shipuspschecka.top
-uspo.usspnu.top
 gasdfss.com
-worker-cool-firefly-e4da.im-swellen.workers.dev
 mufg-552e6a97297c53e592208cf97fbb3b60.is
-www-smcb-card.com
 bussines-meta-info.com
 web-mail-attaccoun-105947.weeblysite.com
 www.mizuho-8107fac61649fde8b371ffc8028d2fcd.is
-web-mail-accountatt-100420.weeblysite.com
 att-2024-101980.weeblysite.com
-webmaiiiiide34454.weeblysite.com
 d0nk-case.com
 www.pay-destination.is
 pubgmobile-page.creatorredeem.workers.dev
@@ -657,7 +994,6 @@ github.te1egram.xyz
 joingrup.ikucty.cfd
 ledgerlivewalle.com.go-wledgerlive.com
 www.japanpost.jp.cjdknst.top
-attt-107422.weeblysite.com
 www.snrproductions.co.za
 lsp006.cc
 www.pancakeswapv3.xyz
@@ -673,7 +1009,6 @@ wausps.com
 sign-in-att-100012.weeblysite.com
 0283cc.com
 pemulihan-akun-dana-dibekukan.new-x.biz.id
-us.b9nk.workers.dev
 svdfq.blogspot.md
 testaaa.ai-yuxin.space
 www.porhf.cn
@@ -801,12 +1136,10 @@ madzshop.mywhc.ca
 untungterus.millicanfamily.com
 hbo-max.co
 ing.es-gestion-app.info
-webmail-laposte.hubside.fr
 mbway-verificarpt.com
 hello-world-throbbing-dew-a4a2.spineynorman48.workers.dev
 cuost-62e2.temp-onlineselo.workers.dev
 govb-familialive.com
-urkeajq.com
 urkeaxc.com
 tugalic-lla.site
 www.ggaliibiip.com
@@ -842,7 +1175,6 @@ home-107844.weeblysite.com
 aaqxz.blogspot.hr
 gbdrn.blogspot.dk
 worker-cool-dust-bda1.purzepukno.workers.dev
-wandering-waterfall-02cc.vuknemuspa6773.workers.dev
 5fgfgfgfg4g4gh4hg4g.blogspot.mk
 wdvbr.blogspot.li
 wdvbr.blogspot.is
@@ -976,23 +1308,15 @@ cloosud-776c.lnskeaysldoavar.workers.dev
 dbsproperties.life
 quallyextoaseme.port25.biz
 earlyase-atwenties.25u.com
-www.torii-s.com
-www.dragon-hpc.com
-www.jqwjg69.com
 www.aubbka.com
-www.lpg365.com
 cddbs.click
 att-108765.weeblysite.com
 www.toypiqp.cn
 att-102304.weeblysite.com
 att-105098-106415.weeblysite.com
-www.zdipd.cn
-www.ynehlkl.cn
 hjsdfe.evgtz.xyz
-wedfhc.evvqd.xyz
 starilonripo-ned.ezua.com
 att-109135-1061843.weeblysite.com
-www.dfnvv.cn
 paymentlah.top
 signin-att-100454.weeblysite.com
 365mmd.com
@@ -1018,7 +1342,6 @@ tokenpbbket.tel
 365uuuu.com
 www.04322i.com
 begcj.blogspot.sn
-telegarc-fki.com
 ws.udemo.cc
 tokenpbaket.tel
 jmysh.blogspot.hr
@@ -1027,7 +1350,6 @@ telegarc-pmc.com
 telegarc-feq.com
 layananncsid-danax.webr.biz.id
 bdgrq.blogspot.bg
-wild-boat-5d2d.admin1834.workers.dev
 pure-2.com
 feiraodescontomguh.shop
 356652.com
@@ -1116,7 +1438,6 @@ e.313vip36.xyz
 tokenpocket-tpoke.org
 caixageral-directapt.com
 gugumenclok.steelersafcshop.com
-www.suzhongyiliao.com
 spush-erneuen.site
 exodusgift.top
 netzero-webmail-109393.weeblysite.com
@@ -1125,12 +1446,9 @@ att-service-103961.weeblysite.com
 att-101422-104172.weeblysite.com
 jugendsachbuchpreis.verein-fuer-lesefoerderung.de
 bestaetigung-spkapp.com
-worker-young-flower-4546.xeleje3632.workers.dev
 ks4zmw-8080.csb.app
 att-105585-102926.weeblysite.com
 atendimentobradescoseguros.online
-usps.sskrtypkpk.top
-usps.shipuspscheckb.top
 moduloseguranca.site
 hnsdsg.com
 tgrobertdejong.com
@@ -1702,14 +2020,12 @@ urkearg.com
 ipv4.203754018382.xyz
 urkeatv.com
 urkeawd.com
-urkeatz.com
 urkeaws.com
 urkeawp.com
 urhebth.com
 urkeaqr.com
 urkearf.com
 urkeark.com
-urkeatc.com
 urkeatb.com
 urkeaqw.com
 urkeatn.com

+ 67 - 68
yoroi_suspicious_level2.dns

@@ -9,32 +9,28 @@
 # Category        : Suspicious
 # Confidence      : 8
 #
-billowing-limit-216c.tk6913.workers.dev
+tokosreal.vrl2023.com
+03us9uls9ps.us
+120812336.com
 121512336.com
 1bank-cy.com
 207647.com
 88yh628.com
-beneficioauxbrasil.com
-boc-helpline.com
-card186.com
-conocin.cfd
-continuedsad-dsdcheckout.mrbonus.com
 dossanddoss.com
 dpsberlin.com
 dumansky.net
+geezii.com
 gold-beard.top
-kaizenfootwear.com
+help-center-324235.click
+iwri2f.krafton-news.com
 kklaim-danakagett-id.dydd67.biz.id
-listingopensea.org
 lygygy.com
+mijnupsinformatie.com
 mit-opdatering.com
-msvcoae.com
-opensalvage.com
-powerskycn.com
 qmkxua.com
-qmkxus.com
-qmkxji.com
 qmkxpq.com
+qmkxji.com
+qmkxus.com
 ruilisc.com
 segreteria-telefonica.hubside.fr
 shipitaus.com
@@ -43,6 +39,7 @@ sps-jetz1.net
 steampoweredforums.com
 szxgny.com
 t89xrw9.com
+tc2a6el4n9v.us
 teiegrom-xd.com
 telegarn-czb.com
 telegcde-jrt.top
@@ -51,57 +48,83 @@ telegram-xa.com
 telegrom-wk.com
 uf1j-ba0k.cyou
 uf1j-ba3k.cyou
-urhebry.com
+urheatm.com
+urheauc.com
+urheauf.com
+urheatf.com
 urhebtj.com
-usps.adrqsqwulv.top
-usps.cdeyjjsdaf.top
-usps.mytrackingr-me.top
-usps.checkuspsg.com
-usps.trckmails.com
-usps.postdal.top
-usps.mytrackingti.top
-usps.tahflrtmiu.top
-usps.ywmkoaqayq.top
-usps.uplspc.com
-usps.uspsshipcheck.com
-uspsugc.top
-verify-sfe.com
+urhebry.com
+urhebru.com
+usqxj.top
 www-ccss-lu.com
 www.bkljv.cn
+www.clienti.poste.3-121-219-47.cprapid.com
 www.mvnqtpv.cn
 www.ttuhxjb.cn
-zxcgrdh.com
-geezii.com
+beneficioauxbrasil.com
+boc-helpline.com
+c1mz6.shop
+card186.com
+conocin.cfd
+continuedsad-dsdcheckout.mrbonus.com
+kaizenfootwear.com
+listingopensea.org
+msvcoae.com
+opensalvage.com
+powerskycn.com
 urheafh.com
-urheafr.com
-urheafj.com
 urheafv.com
-urheagg.com
+urheafj.com
+urheacq.com
 urheafw.com
 urheagt.com
+urheagg.com
 urheaku.com
 urheasd.com
 urheash.com
+urheafr.com
 urheasx.com
-urheatf.com
-urheatm.com
-urheauc.com
-urheauf.com
+usps.adrqsqwulv.top
+usps.cdeyjjsdaf.top
+usps.checkuspsg.com
+usps.checkuspsa.top
+usps.mytrackingti.top
 usps.mytrackingya.top
+usps.trckmails.com
+usps.tahflrtmiu.top
+usps.postdal.top
+usps.uplspc.com
+usps.uspsshipcheck.com
+usps.ywmkoaqayq.top
+uspsugc.top
 usxep.top
+verify-sfe.com
 vip-insiders.com
-www.clienti.poste.3-121-219-47.cprapid.com
+account-service.navy-resourcesupdates.workers.dev
+hello-world-odd-surf-df52.ruydavafye.workers.dev
+hello-world-bold-wave-5d6f.mewiqy.workers.dev
+wmailer-cupdate-meadow-bdfa.rarkidospe.workers.dev
+groupmgmt.ferreracademy.com
+reconfirm.datings-auth.workers.dev
+ancient-thunder-0448.chinnabhai944.workers.dev
+urheahf.com
+uspsuxe.top
+zxcgrdh.com
+mail0.googgle.workers.dev
+atualizacaocadastro.app
 bjamst.com
-iwri2f.krafton-news.com
-mijnupsinformatie.com
-usqxj.top
-120812336.com
-c1mz6.shop
-help-center-324235.click
 im2.run
-usps.checkuspsa.top
+billowing-limit-216c.tk6913.workers.dev
+usps.mytrackingr-me.top
 site.aresracingaustralia.workers.dev
 cool-forest-8578.fuinss.workers.dev
+worker-white-glade-0e4b.a887556413454640.workers.dev
+usps.mytrackingr-nd.top
+usps.mytrackingr-tn.top
+usps.mytrackingr-ky.top
+usps.mytrackingr-fl.top
+usps.mytrackingr-id.top
+usps.mytrackingr-ok.top
 www.dnrth.blogspot.hr
 mtfbg.blogspot.hr
 accounts-google.letsatsilesufi.co.za
@@ -120,12 +143,8 @@ antai-amande-gouv.click
 fortueo-service.fingso.eu
 mail-108964.weeblysite.com
 cbgrx.blogspot.is
-usps.mytrackingr-tn.top
 usps.mytrackingr-wi.top
-usps.mytrackingr-ok.top
 usps.mytrackingr-no.top
-worker-white-glade-0e4b.a887556413454640.workers.dev
-mail0.googgle.workers.dev
 webmail.facadesolutionsuae.com
 sgg-gov.firstcloudit.com
 wody-info-files.firstcloudit.com
@@ -161,11 +180,7 @@ dmrjy.blogspot.sn
 telstra-103684.weeblysite.com
 worker-sweet-lake-e7af.derzuteydo.workers.dev
 xjg3h.baiky4.com
-usps.mytrackingr-fl.top
-usps.mytrackingr-nd.top
 usps.mytrackingr-ia.top
-usps.mytrackingr-ky.top
-usps.mytrackingr-id.top
 usps.mytrackingr-ne.top
 telegawm-eiy.top
 usps.mytrackingr-al.top
@@ -260,7 +275,6 @@ urheake.com
 urheaxp.com
 urheact.com
 urheaxa.com
-urhebru.com
 urheamf.com
 jsks.godp4y.com
 urhebew.com
@@ -312,7 +326,6 @@ yshdjig.manttap.com
 mann-hummel.liflic.in
 dxint.cc
 skin-gratis9182.info-viral.icu
-tokosreal.vrl2023.com
 confirms.auth-meta.workers.dev
 mintigoals.milintaleynu.top
 mjgyj.blogspot.sn
@@ -830,7 +843,6 @@ www.baqhpzc.cn
 www.1mvejd.cn
 www.aihouhou.cn
 urheacw.com
-urheacq.com
 usps.uspscheckshipping.top
 fjb4us.baiky4.com
 usps.sjaaquhutv.top
@@ -2228,7 +2240,6 @@ ertamerinm-omin.ygto.com
 tcogramsm-lkmn.otzo.com
 egiocusensa-erv.serveuser.com
 c6987.top
-atualizacaocadastro.app
 xswytgf.com
 blanket-92n2-mlez.mlzeo9s6.workers.dev
 wrihaptertea-post.myddns.com
@@ -2908,7 +2919,6 @@ ljmowxar.eventfree.de
 62water-00f2.gummay838.workers.dev
 amaniona.com
 uspsfirm.com
-uspsuxe.top
 uspsuyo.top
 uspsuxy.top
 dmthv.blogspot.hr
@@ -3393,7 +3403,6 @@ milol-shape-bab2.yetihe74196948.workers.dev
 maranathatm.adventist.ro
 itbrap-cd88.lehaoiolninse.workers.dev
 jolly-breeze-2347.michelhuston77.workers.dev
-hello-world-odd-surf-df52.ruydavafye.workers.dev
 hello-world-lively-night-2b68.nugnojilti.workers.dev
 he3feec7cd52ae002200e96736026557d.amxwvgci.workers.dev
 cloud-init-8373.nuzsidlneae.workers.dev
@@ -3433,7 +3442,6 @@ urheajr.com
 urheaht.com
 urheajp.com
 urheajt.com
-urheahf.com
 urheahp.com
 urheagq.com
 urheagu.com
@@ -3665,7 +3673,6 @@ cvbnq.blogspot.am
 dthju.blogspot.md
 fmtfb.blogspot.md
 mtjvg.blogspot.rs
-03us9uls9ps.us
 worker-yellow-bird-8609.strumokvi.workers.dev
 6pyjno.removalsinrotherham.co.uk
 gielda-smolinskionline.com.pl
@@ -4052,7 +4059,6 @@ usps.sgdshf.top
 usps.rsnxhpla.top
 usps.keotnlyv.top
 usps.gsgfsg.top
-uspyj.top
 usps.wyfmtiri.top
 usps.dhdfhd.top
 usaas.top
@@ -4988,7 +4994,6 @@ moi-gov-kw.xyz
 login-live-com.o365.ams.skyfencenet.com
 greg-56e7.lleabtiswhe.workers.dev
 wwe.gjftj57ddrrdd4646.cloudns.biz
-account-service.navy-resourcesupdates.workers.dev
 confirmation.valley-assign.workers.dev
 wwr.orange9231.cloudns.biz
 www.telegran.work
@@ -6134,7 +6139,6 @@ whatsapp-wq.com
 hilupfoxs.ru
 telegrrm.fit
 www.login.eqadconsultancy.com
-groupmgmt.ferreracademy.com
 c1228cea.70bd88adaf0dd0164cd39348.workers.dev
 site9615213.92.webydo.com
 hshrrq.com
@@ -6282,11 +6286,9 @@ boboyingshi.cc
 efacebok.banggondrong.com
 facebooklite.banggondrong.com
 jlcdxc.com
-wmailer-cupdate-meadow-bdfa.rarkidospe.workers.dev
 www.efacebok.banggondrong.com
 wgoharder.d3btf9luzddlmk.amplifyapp.com
 www.facebooklite.banggondrong.com
-hello-world-bold-wave-5d6f.mewiqy.workers.dev
 payment-payu-ios.maklifedairy.in
 hbeyh.blogspot.sn
 rnhtg.blogspot.am
@@ -6705,7 +6707,6 @@ telstra-101113.weeblysite.com
 att-104427.weeblysite.com
 uspd.usspzr.top
 vfszn.blogspot.hr
-ancient-thunder-0448.chinnabhai944.workers.dev
 imtoken.ph
 web3-roninchain.com
 att-102901.weeblysite.com
@@ -6766,7 +6767,6 @@ buat.cs-service.biz.id
 sdqhq.blogspot.sn
 ssetz.blogspot.li
 uspe.ussppv.top
-reconfirm.datings-auth.workers.dev
 e00a.mylink1.workers.dev
 k0wwk.shop
 binpromocash.com
@@ -7934,7 +7934,6 @@ videogdehscvds.blogspot.sn
 ebygc.blogspot.lu
 sky-102833.weeblysite.com
 worker-polished-dust-1f0f.theobrienz1.workers.dev
-tc2a6el4n9v.us
 sucureloginhotmail.ronbrownhelen.workers.dev
 sky-102244.weeblysite.com
 yummyulo.blogspot.co.za

Some files were not shown because too many files changed in this diff