root 2 anos atrás
pai
commit
5197416097
4 arquivos alterados com 3070 adições e 2424 exclusões
  1. 1576 1166
      yoroi_malware_level1.dns
  2. 1160 1190
      yoroi_malware_level2.dns
  3. 278 12
      yoroi_suspicious_level1.dns
  4. 56 56
      yoroi_suspicious_level2.dns

Diferenças do arquivo suprimidas por serem muito extensas
+ 1576 - 1166
yoroi_malware_level1.dns


Diferenças do arquivo suprimidas por serem muito extensas
+ 1160 - 1190
yoroi_malware_level2.dns


+ 278 - 12
yoroi_suspicious_level1.dns

@@ -9,6 +9,278 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+novbco.mobi
+mafimuz.brasscustoms.com
+coz.200boundary.com
+brasscustoms.com
+appleidmz.top
+auta-lublin.pl
+aweh.whefficil.bond
+aweb.whefficts.bond
+wee.whefficxs.bond
+aweb.whvfficei.bond
+review-page-id-106910.1458754.com
+review-page-id-486063.1458754.com
+en-gb-facebook.3058864085.com
+a81062.24houcryptowatcher.com
+d60212.24houcryptowatcher.com
+a74913.24houcryptowatcher.com
+f5620.24houcryptowatcher.com
+a3020.24houcryptowatcher.com
+att-tyeyrtr.weeblysite.com
+new90702.24houcryptowatcher.com
+versanddienst.net
+attnetservice-107738.weeblysite.com
+lnfo.poste.54-242-149-51.cprapid.com
+d37355.24houcryptowatcher.com
+a44702.24houcryptowatcher.com
+a52398.24houcryptowatcher.com
+my-attmail.pory.app
+verifymyatt.pory.app
+myattmail.pory.app
+pe-stores.top
+d41843.24houcryptowatcher.com
+d65448.24houcryptowatcher.com
+c9976.24houcryptowatcher.com
+f40305.24houcryptowatcher.com
+c75750.24houcryptowatcher.com
+d98789.24houcryptowatcher.com
+dhlapp.top
+cssozopuruhtlms-nku.alineweege.repl.co
+continuar-aqui1.x10.mx
+accedi.registrati.pt.34-228-229-217.cprapid.com
+bafybeialiihfdlc3uilj6x7pwf6nyqaptz7fjklhg7dposgro2qxstm764.ipfs.infura-ipfs.io
+creasscotias24hrs.eu5.net
+dhl.postylw.top
+onlineaccess-tdbank1.com
+grup-wadhao.terbaru-2023.com
+otpbank.adamstobbe.com
+ozopuruinyinku-egouwa.limsf.repl.co
+telegtran.club
+f35006.24houcryptowatcher.com
+telegrzn.fit
+request-submit.appeal-us.repl.co
+bafybeidb6jo7o4ms2pqycfw4apybsqkp474s3uwdi257huj2oa7lmx6kwy.ipfs.infura-ipfs.io
+versanddienst.info
+r65341.alphainvestment.co
+z3683.alphainvestment.co
+v47861.alphainvestment.co
+v68155.alphainvestment.co
+r10736.alphainvestment.co
+teluspoc.com
+m33250.alphainvestment.co
+paypay-ws.jp
+banca-virtual.banrural.gt.zya.me
+grup-wa1scd.terbaru-2023.com
+uk.royalemail.icu
+a38236.24houcryptowatcher.com
+dhl-postmx.top
+freebgmirewardstopup.servermodules.in
+b43906.24houcryptowatcher.com
+spinmaxqmtadck.terbaru-2023.com
+uspost.jiaedsadd.wiki
+eptc.com.sa
+poruka.gq
+svin.terbaiik.com
+vvhdsty.mjusy.com
+waa.whziocmjm.com
+wadasgrwv.xyz
+zg-imtoken.com
+live.kitchmethat.com
+1010bcjag.com
+reactivarsucuenta-aqui12.liveblog365.com
+allyeatesr8.sbs
+pancakeswaq.finance
+swisspasshilfeid.sviluppo.host
+ff-memberships-garena.vn
+ekira.weeblysite.com
+cash365.in
+bplbnco.com
+potsaufschlag-ch.xyz
+uiyidgdidhduj.weeblysite.com
+bt-104330.weeblysite.com
+bttellecommunication.getresponsesite.com
+www.cnkicheck.org
+ghghghghghass123123123.start.page
+server-homexx217.weeblysite.com
+fffsdsds.weeblysite.com
+www.themimsi.cloudns.nz
+info-kerjaya.com
+pages-review-59641235.help
+kobsuii.mujxk.com
+grup-wayohs.terbaru-2023.com
+www.e365095.com
+jp1.metaface.click
+imtoken-aq.moe
+xhb.qwfdg.com
+www.secureurl012-onlinesecurity.com
+www.comm-infoactivity.com
+review-page-id-722340.1548762.com
+db-integral-proposed-limitation.trycloudflare.com
+offthewallgraffiti.org
+dana-payylatters26.resmi-id.art
+telegram-aaa.cc
+authconnect.net
+xknfk.qwfdg.com
+woljko.club
+gruop-wauggxcxq.terbaru-2023.com
+viral-telegram-2023-2082.real1.biz.id
+whatsappprztfsp.icc.biz.id
+whatsappfyoftav.icc.biz.id
+whatsappiineeyc.icc.biz.id
+whatsappvtmxzzn.icc.biz.id
+viral-telegram-2023-5450.real1.biz.id
+3dmimariyapi.com
+lnfo.pt.54-81-7-74.cprapid.com
+tarif-bank-bni.wb-app.com
+viral-telegram-2023-217.real1.biz.id
+uspenw.top
+admin.napthe.vin
+jp.apidyll.cc
+telegram-help02.com
+roma-ni.pages.net.br
+whatsappgrup59687.mengunjungi-website24.cfd
+whatsappgrub74992.mengunjungi-website24.cfd
+whatsappgrub85712.mengunjungi-website24.cfd
+whatsappgrup92168.mengunjungi-website24.cfd
+whatsappgrub40066.mengunjungi-website24.cfd
+whatsappgrub99723.mengunjungi-website24.cfd
+sjbdk.godp4y.com
+www.plustemizlikmarket.com
+viral-telegram-2023-5131.rtxz.cfd
+reactivar.aqui2.liveblog365.com
+tokyo.gold
+nm-simplified-demonstrate-fiji.trycloudflare.com
+uspxnd.top
+uspnic.top
+rashformalevent.robinsonwalker1.repl.co
+www.3656xx.cc
+jdodl.terbaiik.com
+validar-usuarioscoti.eu3.biz
+wallet.lynkd.id
+numbers-tv-fit-amendment.trycloudflare.com
+freshworks-sso.com
+www.verify-device-anz.com
+scotiproceso-enlinea.hstn.me
+www.baxitzhamal.kz
+telegrwmn.club
+uspnys.top
+www.parcelstracking-be.com
+updatecli.dvrlists.com
+usps.com-ny.store
+menber.vn
+support239793999.com
+gjgjk.xyz
+appleidcu.top
+uspostso.com
+uspsmax.top
+com-ct.bond
+telegxmn.club
+www.axisbankbenefits.com
+web6access1-americafirst-on.line.pm
+dkjfo.godp4y.com
+html-css-js--fidelitycapital.repl.co
+att-login5651.weeblysite.com
+txite-100103631.weeblysite.com
+sparkasse.de-skpt.info
+mbwayverificar.com
+slogimelser.gq
+att-102765-103802.weeblysite.com
+irsinsurancesupport147.brizy.site
+bewdeselva.za.com
+irsgovupdateservicesrestriction777.brizy.site
+vveb3-ex0duse-vvallets.top
+paypay.idup-ne.jp
+bienvenibi.oliver302.repl.co
+eminenttpersonas.ayudsoporteonlin.repl.co
+indie.40-84-140-149.cprapid.com
+my-site-104239-102643.weeblysite.com
+clienteslivelo.xyz
+att-105962.weeblysite.com
+attmailservicepage1567.brizy.site
+hello-world-empty-star-819b.cajopab390.workers.dev
+any.dhrtqy.com
+2playcs.com
+any.aeonao.com
+ad65f587-7c43-4a47-83a4-a91118a34d79.id.repl.co
+any.aeonaf.com
+any.dhrtqw.com
+smbc-tywm.shop
+any.dhrtqt.com
+sitloseguro.online
+any.dhrtqr.com
+any.dhrtqe.com
+any.aeonau.com
+any.aeonaa.com
+any.dhrtqq.com
+232145--2938994.repl.co
+potsckji-ch.top
+administrative-support-101506.weeblysite.com
+vveb3-ex0duse-vvalletes.top
+smbc-uk11.shop
+smbc-jc1.shop
+smbc-buujk.shop
+verificar-cuenta--nomina1.repl.co
+stylishevilbackend--vivianacerra.repl.co
+darkvioletlankyweb--nomina1.repl.co
+jumpycostlyos--vivianacerra.repl.co
+stylishevilbackend.vivianacerra.repl.co
+darkvioletlankyweb.nomina1.repl.co
+1dc9d78e-5a9b-4630-9d20-0dfccb06c7ae.id.repl.co
+b5334bfc-64bc-4f2f-a7a5-020c67a35b14.id.repl.co
+d56d1967-0ca3-4d52-af43-78777618fecf.id.repl.co
+7ecf61e7-296e-42b9-8e46-946681732c06.id.repl.co
+jumpycostlyos.vivianacerra.repl.co
+intelligentmoralnumerator.nomina1.repl.co
+meunubank.com
+intelligentmoralnumerator--nomina1.repl.co
+9bf05fb9-2f58-468b-9761-6ee6431e379c.id.repl.co
+ee957e2f-55e4-4834-9ac1-aff0ec80d887.id.repl.co
+superiordodgerblueconference.nomina1.repl.co
+superiordodgerblueconference--nomina1.repl.co
+att-login2860.weeblysite.com
+vpassidsmbcars.cyou
+xxmaidgfh786.weeblysite.com
+smbc-aarj.shop
+smbc-jc58.shop
+smbc-jc66.shop
+in-ipost.top
+smbc-yiuj.shop
+smbc-jc11.shop
+smbc-jc59.shop
+smbc-lbuf.shop
+ii-mail-sign-att.weeblysite.com
+9876.bhdsoluciones.repl.co
+desbloquearbanca.reactivacionbhd.repl.co
+attmailmanagement001.ukit.me
+my-site-106757-101575.weeblysite.com
+bankinter-banca.com
+lightpinkunequaledwireframe-1--camet28523.repl.co
+belatedshabbyshelfware.otromas1123.repl.co
+belatedshabbyshelfware--otromas1123.repl.co
+portal-creditos-y--consumosbdb.repl.co
+cuteculturedstatistics--otromas0101.repl.co
+541318fb-095f-44b6-8418-b6292826e865.id.repl.co
+fd977fd6-6876-41d9-a8bc-dfc62b328d3f.id.repl.co
+portal-creditos-y.consumosbdb.repl.co
+cuteculturedstatistics.otromas0101.repl.co
+smbc-wwym.shop
+smbc-enhg.shop
+6bb6cff5-3269-49e9-aa8d-a7b497f11264.id.repl.co
+ingresarbdb--asesorenlinea1.repl.co
+9f91b6da-fb1c-40c1-a488-cb754fbcc6ca.id.repl.co
+iniciar-solicitud-credito-y--consumos.repl.co
+5a58d44f-6c20-4cc7-b622-dfb9fd359ce1.id.repl.co
+creditos-y--consumos.repl.co
+ingresarbdb.asesorenlinea1.repl.co
+60e06bd0-31a5-4e53-9960-8feab4c931e9.id.repl.co
+iniciar-solicitud-credito-y.consumos.repl.co
+comunicaciones-bdb--servicioalclien.repl.co
+creditos-y.consumos.repl.co
+comunicaciones-bdb.servicioalclien.repl.co
+96f150ee-e7bf-4604-9597-3976fe95991b.id.repl.co
+6271529e-dd26-48a7-9329-e77afd4a7a5c.id.repl.co
+verificar-cuenta.nomina1.repl.co
 hungary-glsgyors.on.fleek.co
 corriereglsgroup.on.fleek.co
 2222hjytja.xyz
@@ -70,7 +342,6 @@ gmail.dtech.vps-kinghost.net
 att-100559-105303-update034.weeblysite.com
 cloudflarexuyz.xyz
 corpyy.xyz
-svin.terbaiik.com
 egaweg-gregearg.pages.net.br
 grimathleticboastmachine.edificiosmonta5.repl.co
 cknfo.qwfdg.com
@@ -167,10 +438,7 @@ usesxiuneed.com
 ptonlower20.sbs
 www.eurolotauto.com
 page-recovery110970.esyadepolama.info.tr
-poruka.gq
 smbc-57jj.shop
-vvhdsty.mjusy.com
-www.cnkicheck.org
 10982nklag.com
 datacenterjournal.cn
 www.bosschenhenshuaii.cn
@@ -184,13 +452,9 @@ paypay-info.jp
 paypay-os.jp
 www1-sbcmsb.icu
 akokouka.fr
-eptc.com.sa
 turkiyeanadoluhaber.com
 viaverde-painel.com
-waa.whziocmjm.com
-wadasgrwv.xyz
 yofei.cn
-zg-imtoken.com
 how2trainer.com
 sicurezzalert.com
 view-bill.weeblysite.com
@@ -307,7 +571,6 @@ bafybeiah7updnszhp2diyj5ef72x7ohuak2ubolzym3rghxxtdram4t624.ipfs.infura-ipfs.io
 bafybeic5gx3ioqegqpm7374plgeetbjw3k7mt7vhbkeh5wpjh2dfc3njea.ipfs.infura-ipfs.io
 bafybeib3sibknqhr457idlvddorgixicw5qyqtmviiqcx44nc42qlardk4.ipfs.infura-ipfs.io
 bafybeiey3s5den4fmr43trjzu7sazsj4oa3gy2lakdrxoycn5bzpe6q33m.ipfs.infura-ipfs.io
-bafybeialiihfdlc3uilj6x7pwf6nyqaptz7fjklhg7dposgro2qxstm764.ipfs.infura-ipfs.io
 bafkreibk4fjlx4od2erfeq7onwptnjyl2fo2lblymtuan7pxugfhlwbftq.ipfs.infura-ipfs.io
 bgedsacfs.xyz
 8b3br2d.xyz
@@ -367,6 +630,12 @@ psd.194-180-48-240.cprapid.com
 login.45-12-253-248.cprapid.com
 post.userdelivery.top
 p11.45-12-253-224.cprapid.com
+ctt-ajuda.com
+message-notification.click
+bafybeigumv73eyv7d6tphuvtyxdg45e2gpmeazidu4o236m4xwklcvxcqe.ipfs.infura-ipfs.io
+bafybeiemdfekb2dgb7ncpi2nibldunzpewuhoetb33wymsbru42zecz23i.ipfs.infura-ipfs.io
+bafybeidz4usa6d2xa2pkl5tbnvyc57m7csvfh35z53uqus76zt6mncjbje.ipfs.infura-ipfs.io
+usps.parcel-shipping-tools.com
 bafkreidrup6wbvidhqueqvgv64ma6omvntyzekhk3vf6zldxb4xegzejiy.ipfs.infura-ipfs.io
 bafybeiepjabijdvqxw4kfjej4kseeyyocuzvqhklwr5b4kkv3lilj4h344.ipfs.infura-ipfs.io
 bafkreid6zmiohn5xk2zyx4scy35atnaw7a3pwv3hwvaix4dcchdzhxxkda.ipfs.infura-ipfs.io
@@ -676,7 +945,6 @@ link-bagi-saldo.zxcom.cfd
 dana-resni.zxcom.cfd
 pemulihann-akunn-dana.wb-ld.com
 hadiah-dana.yourl-id.com
-usps.viewinformationc.com
 www.update-dana-id.biz.id
 www.bantuan-danaindonesia.biz.id
 tclegram.org
@@ -700,9 +968,7 @@ any.rdthqd.com
 any.rdthqs.com
 rdthqa.com
 rdthqs.com
-usps.trckingmail.com
 gmail-login-page.brightishere.repl.co
-usps.parcel-shipping-tools.com
 forapi6.ru
 globastersioben.gq
 new-bill.weeblysite.com

+ 56 - 56
yoroi_suspicious_level2.dns

@@ -9,44 +9,69 @@
 # Category        : Suspicious
 # Confidence      : 8
 #
+asqwi.com
+b8883652.com
+bb60sy.com
+boikeno.com
+cartonajespastor.com
+diepkhuchat.my.to
+global.tencentrewards.com
+jaxboatshow.com
+jgtbchs.com
+layanan-update-tarif.efile.biz.id
+lay-dasanaxx.fy-id.com
+layanan-updatetarif-perubahan.efile.biz.id
+order-tracking02.com
+res-valorant.com
+seciure-paymentech.com
+telegram88.cc
+tels1gram.com
+tokeni.art
+uaps.jntiasms.shop
+www.applecareconnect-portal-ui-manager.com.apple-cpo-portal-online.com
+cs-so.com
 7olx0g.cn
-brandfashionplaza.com
+account.smba.jdianj.com
+artenbois.com
+clubline-chicago.com
+codashopahsdsut.terbaru-2023.com
+eurartists.com
+fbb.info.vn
+ff-memnber-garena.vn
+herbieblog.com
+jamesperdunteam.world
+s-aktiv1.net
+sparkasse-verein.de
+uniswapv4.com
+update-perubahan.efile.biz.id
+jciheist.be
+usps.com-hi.online
+adminuser.kkyuanma.xyz
+ff.member.gareaa.io.vn
+activation-coupons.fr
 csvb.shop
-d4na-idx-newcom.efiles.biz.id
+eatoncomedy.com
 ebayreviews.shop
-eurartists.com
-mgm599.com
+mobilelegends-free-skin5530.terbaru-x.social
 mosoqi.com
-ospjonav.eventmaterialfree.com
 petercorplife.world
+postal-magyar.com
+uspost-zip.shop
+www.lokadbucinesa.biz.id
+brandfashionplaza.com
+d4na-idx-newcom.efiles.biz.id
+mgm599.com
+ospjonav.eventmaterialfree.com
 smba.xnpvcdb.com
 smba.sdcxgt.com
 themommyblog.xyz
 trckingstamp.com
 uspust.top
-www.applecareconnect-portal-ui-manager.com.apple-cpo-portal-online.com
 9293w86g.com
-bb60sy.com
-boikeno.com
-diepkhuchat.my.to
-global.tencentrewards.com
-jaxboatshow.com
-mobilelegends-free-skin5530.terbaru-x.social
 naldossary.com
-order-tracking02.com
-postal-magyar.com
-telegram88.cc
-www.lokadbucinesa.biz.id
-b8883652.com
 covertina.com
-herbieblog.com
 muyagroup.com
-res-valorant.com
-seciure-paymentech.com
-sparkasse-verein.de
-uniswapv4.com
 unlockgram1.com
-update-perubahan.efile.biz.id
 www.napthepubgmobile.com
 nf.outerinfo.net
 jscloud.ink
@@ -54,42 +79,28 @@ cloudjs.live
 jscloud.biz
 jscloud.live
 jscdn.biz
-wsiltv.com-pizmwtspjcvw7csrmcb6.pizmwtspjcvw7csrmcb6.manxttrider.com
+dappermall.shop
 dischisser.com
-energygroupitalia.com
-uaps.jntiasms.shop
-cartonajespastor.com
-clubline-chicago.com
 edvsindiidaeal.com
+indirizzoipverifca.com
+imtoken-qz.pro
+smbc-ukjpn4.shop
+uspsverify.dynnamn.ru
+www.ff.member.gareza.vn
+wsiltv.com-pizmwtspjcvw7csrmcb6.pizmwtspjcvw7csrmcb6.manxttrider.com
+energygroupitalia.com
 gruop-wakxqzmww.terbaru-2023.com
 group-telegram.viral-terbaru.biz.id
-uspost-zip.shop
 workforceclientconnect.com
-account.smba.jdianj.com
 dricodavila.com
-eatoncomedy.com
-fbb.info.vn
-ff-memnber-garena.vn
-dappermall.shop
 edd-portal.0auth.info
-tokeni.art
 1videoamateur.com
 finalivante.lucysulim.com
-layanan-update-tarif.efile.biz.id
-layanan-updatetarif-perubahan.efile.biz.id
-lay-dasanaxx.fy-id.com
 myblueharborbank.com
-s-aktiv1.net
-uspsverify.dynnamn.ru
 usptracklw.top
 collectskinfree.evnzy.biz.id
-jgtbchs.com
-smbc-ukjpn4.shop
-tels1gram.com
-www.ff.member.gareza.vn
 amgsharedservices.com
 dychelawfirm.com
-imtoken-qz.pro
 latvijasrepublikamail.com
 dlg-configs.buzzrin.de
 hello-world-morning-sea-95e8.javorjamesmichael.workers.dev
@@ -97,12 +108,10 @@ ad.16-170-82-231.cprapid.com
 b-telegram.pro
 bdzdfc.com
 bgmi-rewards-clam.buzz
-codashopahsdsut.terbaru-2023.com
 telegram-ga.com
 x6x1l5f.tokenapp.download
 ceskindmejaten.gq
 5554b.xyz
-asqwi.com
 italiagls-group.on.fleek.co
 liinkdana.updateebaru.com
 steamicommuniity.ru
@@ -1344,7 +1353,6 @@ newpump.firstpeterteam.world
 officialpump.jamessoldteam.world
 newpump.leaguepeterteam.world
 newpump.jamesperdunteam.world
-jamesperdunteam.world
 jamescompany.world
 officialpump.petercompanyy.world
 newpump.goldteampeter.world
@@ -1373,7 +1381,6 @@ www.3115c.me
 vip3659w.com
 vip3659r.com
 vip3659g.com
-artenbois.com
 echomedia-adv.com
 elite-waste.com
 www.javaplayernet.com
@@ -3406,7 +3413,6 @@ vincular-pago.en-daviplata-we.repl.co
 useaglefu.cc
 useaglefedcuverify.com
 useaglefcu-secure.cc
-activation-coupons.fr
 mylbpiaccess.info
 vincular-pago.en-daviplata-pr.repl.co
 consultar-beneficio2023.ingresosoliidar.repl.co
@@ -3505,7 +3511,6 @@ www.ff-members.gaerna.io.vn
 att-100323-107984.weeblysite.com
 facebook-profile.online
 6thsense-studios.com
-ff.member.gareaa.io.vn
 protection-account8765100.jpma.org.pk
 591823.cloudaccess.host
 access.comunicacionbcp.repl.co
@@ -3513,7 +3518,6 @@ fork-www-mercadolibre-com-mx-9988998b763be07d.sitemod.io
 dashboard-uni-swaps.com
 uspsbig.com
 lnfo.bp.ptl.54-166-211-197.cprapid.com
-usps.com-hi.online
 inps.ver-29.com
 chronopost-liberer.com
 2-degrees-ref.com
@@ -3609,7 +3613,6 @@ pttpostu.xyz
 app-roma789rty.odmgpeudzj-gjy3m5vlk68q.p.temp-site.link
 next-change.pages.app.br
 microdeliver.eu.pythonanywhere.com
-jciheist.be
 rayancare.com
 applecareconnect-manager-portal.com
 viral-telegram-2023-5660.real1.biz.id
@@ -3740,7 +3743,6 @@ loginbni.saattini.biz.id
 netflixclone.deruwe.me
 www.ogloszenia-paczka.pl
 www.xorb.linkpc.net
-adminuser.kkyuanma.xyz
 accesslogpgehlprcvry.com
 operated-diabetes-theorem-bat.trycloudflare.com
 086d5709c25659d6.p22.rt3.io
@@ -3978,7 +3980,6 @@ tranbatnamojigg.gq
 omerflam.gq
 payooy-ne.jp
 rakuten-card.co.jp.service-paycascampaign.com
-indirizzoipverifca.com
 allegro-platnosc.pl
 ww6.suporteonline.info
 g6qyht.xyz
@@ -4390,7 +4391,6 @@ amvfw.top
 idpfbeldiu.ydns.eu
 zip.citrapalu.net
 sa-home.weeblysite.com
-cs-so.com
 amtfm.buzz
 amdhc.buzz
 grp01-id-rakuten-co-jp.dshsewc3332rv.cn

Alguns arquivos não foram mostrados porque muitos arquivos mudaram nesse diff