root 1 рік тому
батько
коміт
a4e59c2fd1
4 змінених файлів з 5203 додано та 4823 видалено
  1. 1825 1292
      yoroi_malware_level1.dns
  2. 3132 3504
      yoroi_malware_level2.dns
  3. 226 5
      yoroi_suspicious_level1.dns
  4. 20 22
      yoroi_suspicious_level2.dns

Різницю між файлами не показано, бо вона завелика
+ 1825 - 1292
yoroi_malware_level1.dns


Різницю між файлами не показано, бо вона завелика
+ 3132 - 3504
yoroi_malware_level2.dns


+ 226 - 5
yoroi_suspicious_level1.dns

@@ -9,6 +9,232 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+z87bkc.xyz
+telegrceam.xyz
+0s6.me
+8fd.me
+verifywalletaddress.c1.is
+berikaissss.kz
+help-case-10009282918676.grupolamda.com
+d.pp503.icu
+sharefile.cmxjnqkjdahj.workers.dev
+onlineattupdate-105523.weeblysite.com
+teiegrosm-e.com
+teiegrosm-v.com
+telegram.wed-v.org
+telegram.wed-e.org
+worker-misty-base-6a04.mrinaldi.workers.dev
+yenib280.top
+investorclubssb.com
+m-etamask.io
+metamack.live
+gocisyx2.top
+snapsgcs.xyz
+thewebtrafficactionplan.com
+signin-att-102212.weeblysite.com
+web3walletconnect.com
+bet988vip.com
+gestiondepersonasseguro.brizy.site
+fangxinjt.com
+bilzzaid-app.xyz
+telegram.run.place
+pancake.saaedal.com
+attnet-102223.weeblysite.com
+sharepoint.melaton.workers.dev
+attnet-108066.weeblysite.com
+aave.liquidity.pm
+linktxchargepayment.com
+www.az.alertsgame.ru
+telegramacn.com
+jynk8ffd53mank85387sfyrukkiokoghgfo.weeblysite.com
+www.babyfaner.com
+att-102923-106551.weeblysite.com
+signup-manta.app
+mj.zaihui.cc
+jurimer.com
+imtoken.org.cn
+cara-pembukaan-akun-dana.orgzfa.com
+vps24605.hosted-by-eurohoster.org
+5h979f.xyz
+www.btbx6y.xyz
+wailing-airline-high.on-fleek.app
+down.t0kfnpofket.biz
+36c56.131vip18.xyz
+kjzquwy3df.surge.sh
+dzdo2leyqf.surge.sh
+att-login338.weeblysite.com
+ramzzwp7nkd2je.surge.sh
+att-103452.weeblysite.com
+bt-103950.weeblysite.com
+my-site-101360-103320.weeblysite.com
+lqpadfile.click
+www.doesmyloanqualify.com
+restore-secure.click
+trezoriostart.org
+rgergesrvasrfvegsr.weeblysite.com
+8ffd53mank85387sfyrukkiokoghgfo.weeblysite.com
+toppiks.risunok-vesenniy.life
+fgrhthy345.temp.swtest.ru
+techworkdept.bubbleapps.io
+att-104045-107306.weeblysite.com
+ghfrh34rli.temp.swtest.ru
+whatsapp-web.cn
+gf34rgrgth.temp.swtest.ru
+update-att-yahoo-107948.weeblysite.com
+trezorostart.com
+www.njllqa.cc
+www.xnxjla.cc
+evdcfb.cc
+imtoken-xo.mom
+mycoinbase.vip.soupeauxpois.com
+telepgrnc.top
+vkaloka-ff-garena.ru
+www.jiaocs.com
+suite-trezor-io.owconsulting.fr
+serialslasher.com
+www.accountblizzardeu.com
+wc284.com
+chat-wasepp9jxgx13.switzerlandnesia.com
+www.whatsapp-hk.red
+office-froms.com
+enter-mantagalaxies.com
+actualizacionesban-colombia.brizy.site
+worker-noisy-base-d6b4.monicaajanusss.workers.dev
+segurogestionvirtual.brizy.site
+corp.bnpparibasbank.ru
+webmall.d1gpxwzztdvdh8.amplifyapp.com
+islem-hizmetleri-kredi-ile-guven.net
+allegroau.com
+wwe.vbnmfghret435.dns-dynamic.net
+wwr.bcxvbn443.dns-dynamic.net
+wwr.bngfxh455.dns-dynamic.net
+ledger-hardware-services.com
+youhua618.com
+sbuusujv.e-kei.pl
+entering-mantagalaxies.net
+www.pncfinc.com
+boardband.univer.se
+entering-mantagalaxies.com
+persoproespacecli.myfreesites.net
+my.dhlparcel.se
+postsikei.top
+telegramcso.com
+rumanindian.com
+ridhwandaud.com
+ledger.zenliner.com
+m.1056746.com
+mail.bgmimaterials.indianxevent.com
+www.bgmimaterials.indianxevent.com
+whstass.cc
+worker-flat-firefly-642b.lolate2347.workers.dev
+www.allegronakall.com
+0fd.me
+vesennie.vesenniy-konkurs.homes
+swisscome.blogspot.ug
+cainomoli.blogspot.bg
+facebooksecurity.blogspot.com.mt
+jylhkj.com
+swisscome.blogspot.my
+metamaskinc.blogspot.rs
+metamasskluginn.blogspot.lu
+facebooksecurity.blogspot.my
+metamask-wallett.blogspot.am
+facebooksecurity.blogspot.com.uy
+us-ledgerlive.com
+17dh04.com
+telegramef.com
+postsikai.top
+facebooksecurity.blogspot.lt
+aave.app-web3.com.co
+telegrom-aa.com
+sukienfreefire.garerana.io.vn
+lali.gercep.top
+be88835.com
+t0keep0cket.top
+e-postfinance.com
+shopee98.top
+webtelegrcm.cn
+connect-airdrop.blc.lk
+somm18.com
+wa.1gi6kn.shop
+freefiremalay.g-e-t.biz.id
+3656k8.com
+pysykkelin.kz
+emails7w7upport-104866.weeblysite.com
+tm6jkbefay.preview.infomaniak.website
+loginemail-101257.weeblysite.com
+slicashub.top
+b.3656240205.vip
+a.36562402062.xyz
+tp6.app
+imtoken-yy.top
+kb5b6b3b.xyz
+g7.sdfhg.xyz
+home-107546.weeblysite.com
+metamask-wallett.blogspot.dk
+plf2.131hd27.xyz
+frsthrizn.com-jxdx.203122.chesswing.com
+facebooksecurity.blogspot.co.ke
+facebooksecurity.blogspot.co.il
+4213a.365k240212a.xyz
+bet350k.com
+ninemozxuaisa.saki61.workers.dev
+discordjs.sanbaideng.workers.dev
+acc.gugeyxiang.top
+mmhy719.com
+bet3659986.com
+uniswap-atlas-demo.fastlane.xyz
+us.manks.workers.dev
+worker-raspy-thunder-4b40.sanwe.workers.dev
+old-credit-4e56.wwwdkz6026.workers.dev
+5365bet888.com
+telegram-r.com
+8087.yajiangguoye.com
+www.slxznhzs.com
+discord.aab123.top
+air.bnb-id8205.com
+tphuntphun.enadupratibha.com
+wa.1gi6kd.shop
+m.71zci71zci.drugsimulator.com
+ngiinsuranceuae.com
+wa.1gi6klm.shop
+euwdv.enadupratibha.com
+wa.1gi6kz.shop
+wa.1gi6ys.shop
+wwwamazonm.x3322.net
+afravirr.com
+wa.1gi6cd.shop
+wa.1gi6ke.shop
+wa.1gi6kw.shop
+wa.1gi6kl.shop
+metasupportcenter.fusionwave.click
+khrinio.columbiauniversityinpictures.com
+teminatlikredim.com
+layanan-dana.id-resmi.biz.id
+facebook.onlinelogin.pro
+recibirtransfiyabancolombia2526242.brizy.site
+dartboardsonline.com
+www.flbashu.com
+www.pdszhqkjj.com
+finance.idstar.co.id
+www.jgsxcly.com
+www.glsgongyi.com
+www.ylswdx.com
+www.dyssygz.com
+www.lywnsxx.com
+www.ycspj.com
+www.bjsjzxx.com
+att-106375-100783.weeblysite.com
+appeal-support-review-pages-issue.d2yrktduz3hnww.amplifyapp.com
+www.qdnsbzx.com
+www.kmhszhc.com
+www.shsmartus.com
+www.zfyxkf.com
+www.zpfgw.com
+www.jncqqz.com
+www.dzszhsq.com
+www.hhhtgk.com
+www.ycsqwsfw.com
 cdnheicloudeuorg-1015.iaku-1.workers.dev
 attyahoonewworker-white-art-e0ce.danelle268.workers.dev
 att-twilight-credit-b0db.lindammatthews.workers.dev
@@ -69,12 +295,7 @@ vip.sukienvip-garena.io.vn
 dogecoinx.xyz
 newoneupgrademoresercrui.kyleanthony3.workers.dev
 0s1.me
-imtoken-xo.mom
-mycoinbase.vip.soupeauxpois.com
-telepgrnc.top
 vvhatsapp.sale
-vkaloka-ff-garena.ru
-www.jiaocs.com
 white-bonus-6942.on.fleek.co
 marketplace.marcelasejas.com
 teiegeram-hk.com

+ 20 - 22
yoroi_suspicious_level2.dns

@@ -9,16 +9,21 @@
 # Category        : Suspicious
 # Confidence      : 8
 #
-bt-103163.weeblysite.com
-worker-fancy-king-4058.bepsofirde.workers.dev
+www.bet365if.com
 220u.cn
 359956.com
 allconfsbot.website
 balcao-novobanco.com
-dhlaustai.com
+bismillahengineers.com
+contact-meta-policy-here.replit.app
+coynbase-wallet.com
+couturebabyshop.com
+cs0189.com
 driedbydesign.com
 frankbowles.com
 fundolosguindos.cl
+iofpnkf.com
+iofppkw.com
 irsfed.com
 kv609.com
 led-ger.com
@@ -33,23 +38,29 @@ sgaapparel.com
 simonisbv-nl.com
 small-recipe-2788.on.fleek.co
 smbjxokw.com
+soluciones.shop
 sparkasse-tan2.info
 ssl3393978ssl39926241480163.searchmarketingservices.dev
 sxflash.net
 t0kenq0cket.com
 tokenpocket-tpenk.net
 tokenpocket-tpern.net
+tokenpocket-tpokm.org
 tokenpockqt.mom
 vnbsnowday.com
 wcbkst42124.com
 xkmaugbqnk.net
 zimbrasummary.x24hr.com
-bismillahengineers.com
-couturebabyshop.com
-cs0189.com
-iofpnkf.com
-iofppkw.com
-tokenpocket-tpokm.org
+apeapp2.vip
+tokenpocket-tpumo.net
+walletconnectmobile.dapps.im
+e.3656240125.top
+b.3656240209.xyz
+od.clsgd.workers.dev
+mute-mode-3d8f.lodani-usopuv1054.workers.dev
+bt-103163.weeblysite.com
+worker-fancy-king-4058.bepsofirde.workers.dev
+dhlaustai.com
 imtoken-qb.one
 288ysb.app
 juno-100313.weeblysite.com
@@ -121,7 +132,6 @@ bantuan-costumer-dana.resmii.biz.id
 hamzaislam.me
 hotmail-update-349c.tbtea3.workers.dev
 officialt.ru
-imtoken-pay.com
 dhl-parcel.20-240-222-99.cprapid.com
 www.ama8899.vip
 zssakuuqdestdpxmy.cifehry.cn
@@ -148,7 +158,6 @@ stywsysdyszyswyhrh.blogspot.lu
 live.start-ledger.com
 en-ledgerlive.com
 qhorse.online
-w-ledgerlive.com
 undianx-hadiahx-danax7.gett.biz.id
 investors.spotify.com.free.putrivpn.biz.id
 cardinalcommerce.com.free.putrivpn.biz.id
@@ -178,7 +187,6 @@ ebay085.shop
 worker-damp-moon-d6fa.hsprice.workers.dev
 gggg.paddlefishthebook.com
 business.verified-suite-help.me
-contact-meta-policy-here.replit.app
 yasiz02x.kzuuis.shop
 securitymailclient-1.hstn.me
 a3qy6.shop
@@ -198,7 +206,6 @@ n-wwspottrise.blogspot.com.ng
 pusat-bantuan-dana-id-ojk.program-update.com
 att-108223.weeblysite.com
 worker-tls-ws.226988.xyz
-coynbase-wallet.com
 leosmedj.ru
 floxie.ru
 mivholdings.com
@@ -2223,10 +2230,8 @@ pikorabanoko.com
 pn835.com
 psd2-aktualisierung.info
 officefb43f197ddb85244543daca790f94099fb43f197ddb85244543daca79.office2mail.workers.dev
-od.clsgd.workers.dev
 njxjfbjgs.com
 nowonlineverif.x24hr.com
-mute-mode-3d8f.lodani-usopuv1054.workers.dev
 mulfinheimergroup.sbs
 mail-103364.weeblysite.com
 meta-business.autosalesaccelerator.com
@@ -2929,7 +2934,6 @@ autoconfig.68-183-214-136.cprapid.com
 auebg-8a9e.bosrmeadeklc.workers.dev
 ppaja.com
 pqvgowj.medopay.xyz
-walletconnectmobile.dapps.im
 plum20802355.brizy.site
 swisscome.blogspot.sk
 shopee.co.id.sg1.tebel.cfd
@@ -3281,7 +3285,6 @@ hahola123.blogspot.lu
 tinhmiko.blogspot.com.eg
 drgdfhdfge54757.blogspot.com.uy
 maimai1919.blogspot.lu
-tokenpocket-tpumo.net
 edhjzswehzshzsh.blogspot.com.ee
 dgdfgd2345454.blogspot.ba
 fgjhdgdjhjtg1111.blogspot.com.cy
@@ -3637,7 +3640,6 @@ tpwallet.run
 www.38cpe.com
 locze-c726.butheonevernn.workers.dev
 reviewsamazon.xyz
-b.3656240209.xyz
 facebooksecuritys.blogspot.co.id
 3656.kjiedx.cc
 www.starfoodind.com
@@ -3843,7 +3845,6 @@ working-on-it-107048.weeblysite.com
 verify-facebookpage.hepcenter.me
 usuario23.serv00.net
 suopwutxxdyd.weeblysite.com
-soluciones.shop
 rating-cont.com
 my-site-103580-104890.weeblysite.com
 incattcurrently-104774.weeblysite.com
@@ -3892,7 +3893,6 @@ tokenpocket-tpnmb.net
 telegpam.icu
 telegrammpremiumgift.ru
 apeapp9.vip
-apeapp2.vip
 apeapp3.vip
 w9610re1b.hier-im-netz.de
 ahoramoda.com
@@ -3997,7 +3997,6 @@ yenib233.top
 maile-temp2.aolquery.workers.dev
 discord2qishuiwancom.chatgptapi98.workers.dev
 349786594.com
-www.bet365if.com
 facebooksecuritys.blogspot.dk
 www.bet365ns.com
 wp.3381811460.workers.dev
@@ -4014,7 +4013,6 @@ wallstretmemes.site
 626666554654.cloud
 bnq.telegcmn.cn
 c.3656240209.xyz
-e.3656240125.top
 acheimagallu.shop
 356615.com
 jdhqzx.com

Деякі файли не було показано, через те що забагато файлів було змінено