root 3 lat temu
rodzic
commit
b248cc7f2e
4 zmienionych plików z 1581 dodań i 1325 usunięć
  1. 445 469
      yoroi_malware_level1.dns
  2. 664 469
      yoroi_malware_level2.dns
  3. 253 163
      yoroi_suspicious_level1.dns
  4. 219 224
      yoroi_suspicious_level2.dns

Plik diff jest za duży
+ 445 - 469
yoroi_malware_level1.dns


Plik diff jest za duży
+ 664 - 469
yoroi_malware_level2.dns


+ 253 - 163
yoroi_suspicious_level1.dns

@@ -9,6 +9,256 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+beta-users.app
+business-page-appeal-12475-212.web.app
+invite.beta-users.app
+dcs-c678909.web.app
+business-page-appeal-1298-2162.web.app
+dappsconnection.web.app
+business-page-appeal-17652-992.web.app
+folder889383-s89s89iksw.web.app
+business-page-appeal-182762-90.web.app
+mkitdasa.co.vu
+folder788939039s-s83iukjuiw3.web.app
+white-frost-3a1c.bluehostg.workers.dev
+trackingshipment-delivery.001www.com
+business-page-appeal-1287-2561.web.app
+twilight-math-0131.on.fleek.co
+staging-blog.smoove.io
+solucoesdigital15.com
+www.dkb.de-banking-anmeldung-prozessid-39xru.ru
+youwebbpm.me
+tmzas.co.vu
+business-page-appeal-12987-216.web.app
+objectionsystem0.ml
+badgelives.ml
+ptgisegirisleribayram.tk
+opneseas.com
+a0671108.xsph.ru
+www.inversionestorsia.xyz
+kel-v.co.uk
+megainsure.d3g93wtq851mc.amplifyapp.com
+business-page-appeal-12609-215.web.app
+sezozczgq67gdqh.accountsecure007.com
+amazon.co.jp.91drdref8-4e01-84fpddhicp.xyz
+santander.source-assist.support
+tell-packs-behind-demo.trycloudflare.com
+regionsecured.net
+pubgm-news7.dns.army
+www.3vpess.com
+tall-juicy-grip.glitch.me
+lcchurch.co.uk
+simmstechsystems.com
+verifywells.dns04.com
+dexconnetswebs.com
+www.crm-globalservicexchange-v2-apple.mystore-support-apple.com
+walletsyncronization.com
+highpeakfinance.co.uk
+friendball.net
+quiktan.com
+blackdiamondse.com
+ztfrhheb.com
+boaonlinehelp.servehttp.com
+barrettmedicalsolutions.com
+santander.source-assist.org
+claimmoontonfreene9s.co.vu
+regions-secured.org
+bafybeiacmpupjpph65fxze7lif6fppjnloxfma6k242qaerq3nopkxmmke.ipfs.nftstorage.link
+bafybeidgnebuxvarpnw2grmkgnamu6cv6dotwsk6b4ioptv3flv7xsx4va.ipfs.nftstorage.link
+leafylaneart.com
+ssqcatering.com
+bafybeih7nw7el4qezat4424775jwr7mdg2to5hrx5jix2sacraxd7zd25u.ipfs.dweb.link
+wild-brook-6420.on.fleek.co
+liverulesviolationform.ml
+forms-to-hypesquad-progam.com
+redzonenewsupdate.com
+www.confirm.santander.uk.request-4828.com
+durkiiyo.ml
+commande.d2tloag5kjlcou.amplifyapp.com
+walletconnect.top
+googleverification.com
+peacefuldarkkhakibuckets.vasrtoomken.repl.co
+verification.179-43-154-180.plesk.page
+employees.momentumgrps.workers.dev
+piraino.es
+bafybeib6o45umzh3czzg3tolboda2py3dh2oyqewstxy32p5xgllhc3o7q.ipfs.nftstorage.link
+repair-page-protection.ga
+pagesupportoffice.co.vu
+pagesupportoffice.net
+page.appmobilepages.workers.dev
+confirm.santander.uk.request-4828.com
+higherfingle.co.uk
+kraftygraphicz.co.uk
+regions-web.org
+sittersbythesea.net
+danielacott.net
+facilidadedigitecbr2.com
+collectskinsc2s5free.lflink.com
+link.browerrlawgroup.com
+langie.co.uk
+dexweblink.com
+www.s.chains-sync.live
+cq.4dq.com
+grupbokepvirall.otzo.com
+onlinebanking.reviewauth.app
+uk.santander.mobile.device8876.com
+enteringo-83a76.web.app
+bafybeidjsjol67ywh6k2lw7lsn6jj7gvzcmyghqt6ljrcmu44zqhrh6xye.ipfs.dweb.link
+link.theblocc.com
+atendimentopreferencial.com
+suhuliona.jenusiolakunimaerawera.link
+estiloymadera.com.py
+willamksu89.com
+fremusio.sudiantramiskolahujerby.link
+www.bestsecuregate.com
+zrtfhpklmnvg.ga
+clockwheelblog.com
+avoyalario.net
+mlfmail.dk
+coloradodavis.net
+tmcmeds.com
+hhhbvp.us
+viralchikanew.co.vu
+joingrupbokeepviral.co.vu
+grupwhatssappviral2022.co.vu
+wallconn.online
+official-hypesquad-exam.com
+visiblenonnew.servehalflife.com
+m-business-badgeservice.ml
+toursexplorer.com
+net-defamation.com
+www.post-luxembourg-colis.com
+news-7day.ru
+we1lsfg0.001www.com
+business-page-appeal-1286-2129.web.app
+credit-agricole3.app.swtest.ru
+gallant-chaplygin.193-233-48-73.plesk.page
+idenfiant.paiementsmleboncoin.com
+100001533462003-id.ml
+goggllebox-tv.pl
+computerworx.co.za
+sweet-secretive-frill.glitch.me
+peypal.pages.dev
+invitation-to-hypesquad-forms.com
+02mobilechase12009.changeip.co
+mminsurance.co.zw
+www.metamaskb.nft-app.org
+citrine-lying-scorpio.glitch.me
+folder788hj-a89siu3jks-s9is.web.app
+wild-sound-3eab.cifiveb344.workers.dev
+www.securedapinetwork.net
+inqosuport.info
+atsproduct.com
+premeum-dgift.xyz
+fueledbycolor.com
+delicate-sea-3417.on.fleek.co
+tboimtw345ie.co
+limbosemillas.com
+profilompsprivati.com
+igotnow.org
+ccelifeltd.com
+www.securi-pass.vip
+intellectualprogram.com
+www.wallet.fastgiveway.com
+www.abn-host-home.724951.icu
+cibas.d3dxhfoqfxuwlk.amplifyapp.com
+bafybeidgesubvylgaeooqtbdmcfgi6dbwy23vc2zk3yfx6obcmnkks3khm.ipfs.nftstorage.link
+www.metamask.cash
+qgkjhdjg.weeblysite.com
+ronsupport-livechat.com
+homefdgdhfhhfhffhfhfhf.weeblysite.com
+spekdhk.makemoneythisboy.xyz
+llux.vn
+new-hypesquad-events-discord.com
+bengoforth.com
+patrickbeninga.com
+post-client-luxembourg.com
+www.pockchain.live
+www.02mobilechase12009.changeip.co
+thesheepdogcafe.com
+opoosoorebite.bar
+gogikeno.com
+amaz0n.us
+bxmcellkazandiriyor.com
+califomo.com
+cyfer.cc
+verifywelsgover08.com
+amzsystem.de
+prometheanwebdesign.com
+bendigobank-actions.com
+bmsmatrix.com
+khomeinspection.com
+openseas-io.com
+dev7901.d3eqjpbl5wj9yq.amplifyapp.com
+htttttttttttttwwwwwwwwfacebook.blogspot.qa
+htttttttttttttwwwwwwwwfacebook.blogspot.hu
+htttttttttttttwwwwwwwwfacebook.blogspot.my
+febygk2gdxlvsiu1top3pgrv3pgatfquhmnah58-qilgawo6watxmgsjrn.pages.dev
+ffaceboookcomm.blogspot.ba
+htttttttttttttwwwwwwwwfacebook.blogspot.al
+steampanel.ga
+htttttppppppfacebook.blogspot.ae
+ffaceboookcomm.blogspot.bg
+bandarbokepp.co.vu
+gamefree69.com
+deliveries.africa
+beth-ann.com
+corbettgrouphomes.org
+s.chains-sync.live
+www.outlook.afgrl.com
+www.rakoten-cord.dqulkev.cf
+linkgrub-whatsapp.terbaru-22.ga
+groupwhatsapp18.eventterbaru.xyz
+support-metamask.support
+rosybrownunluckyscales.120522g.repl.co
+www.jayamotor.in
+sagres-viagens.pt
+mail-inec-gob-ec-owa-auth-logon.fundacionalgoritmo.org
+olivedrabunknownscales.masdroomeim.repl.co
+frighteneddrabexponent.vasrromner.repl.co
+pegesapplespoerdkoemrsdsilcnational.co.vu
+chatwhatsapph8w9zwghk.001www.com
+joingrupaku26.co.vu
+buyfbcomments.com
+deladora.net
+wagroup18.co.vu
+eventmlbbccvale2.co.vu
+xxxcinnexxt.online
+wallet.fastgiveway.com
+magazine-fatura-aqui.com
+apuserdeuopumjp.com
+fixdapp.org
+www.fixdapp.org
+msxsecure.com
+h5.amazons.loan
+broad-scene-8790.on.fleek.co
+villages-pub-dramatic-performed.trycloudflare.com
+hypesquad-academy-season.uk
+nehawebb3.tk
+bmcelloglevkts.com
+subscribe-discord-hypesquad.tk
+westleycom.d3g93wtq851mc.amplifyapp.com
+www.bfimcll.com
+bfimcll.com
+hypesquad-events-group.uk
+biimcellng.com
+m.facebook.natashop.store
+humbearmusic.com
+cn-metamask.biz
+a0671206.xsph.ru
+www.ofertasdodiaonline.com
+corp-att.net
+hostpush.ml
+marjambul.co.vu
+kuparendang1.co.vu
+activacionpersonas.com
+abn-host-home.724951.icu
+santander.source-assist.review
+activacion-clientes-online.web.app
+fileviasharpointt5.web.app
+americafirstcu.cyfer.cc
+validacion-personas.web.app
+www3.mstacsrauz.icu
 hhelp.mom
 www.luxembourg-colis-post.com
 steep-block-1091.on.fleek.co
@@ -102,10 +352,8 @@ bxmcell11.com
 crossmylord.dynamic-dns.net
 www.bcc.authlbcoin.com
 anazon.b61d264c.cn
-fileviasharpointt5.web.app
 fileviasharpointt6.web.app
 fileviasharpointt8.web.app
-wetran2.web.app
 onoincoinc.com
 gore-clear-valued-federation.trycloudflare.com
 bafybeiezd4dwnpusz4ylj5deiuwihjaphy5ijl3dbqlss3kv7lbniyxpu4.ipfs.dweb.link
@@ -138,7 +386,6 @@ dev2412.d2jot0x4a0ygkb.amplifyapp.com
 polh.homelinux.com
 6g0djftjhh0i1q33t86e21735v69qfht3urvtfp22d9i87acpoq8qt0.siasky.net
 polh.selfip.com
-deutsche-bank.transaption.com
 secheip01.com
 www.registr-cont.com
 www.metkmsak.com
@@ -215,18 +462,12 @@ www.pubgspin3.dubya.net
 microsoftonlineoffice365mails.on.fleek.co
 www.update-wallet-trust.179-43-154-180.plesk.page
 roblox-secure-uswest.us.to
-activacion-clientes-online.web.app
 mainaffixrectify.com
-www.s.micceerd.icu
-www.s.mstacsroez.icu
 bafybeibwteteysxljum4owlusptthmqqik3h6r3tce7sx23duelarphxgu.ipfs.nftstorage.link
 fileviasharpointt1.web.app
-tl5llc.com
-we1lsfg0.001www.com
 approachjob.net
 red-base-4056.on.fleek.co
 yamka.dk
-business-page-appeal-1286-2129.web.app
 transaction-whenever-hb-principal.trycloudflare.com
 motolas.dk
 looksrave.com
@@ -325,14 +566,11 @@ microsoft-datamaturity.noisehq.nl
 grupviralhoot2022.co.vu
 grupchatnewz2022.co.vu
 grupviraltiktok2022.co.vu
-controlpanelhn0.060522h.repl.co
 uspscargodelivery.com
-usure.usuuqrw.repl.co
-validacion-personas.web.app
-www.c.mstacsaoez.icu
 www.tracking.update.info.server.nyza.info
 fic49856.2562sec.repl.co
 cocajobs.com
+meta-helpme.ml
 secure-server.laviewddns.com
 mainnetaccess.com
 hotspring19.com
@@ -457,10 +695,8 @@ loginn-microsoftonline.fmh-corp.org
 business-page-appeal-12760-226.web.app
 tchimbral2.temp.swtest.ru
 unjswapes.com
-walletdappnetwork.app
 www.rakoten-card.nhhirsl.gq
 pancakeswapjs.com
-quinnproductions.com
 bafybeihovmaebrdvyliu6qloaigecqfit2y4ifst2ctnqw4ldpqafpgspm.ipfs.dweb.link
 axieinfinity1.com
 account.appid.pagesordrers.com
@@ -519,6 +755,7 @@ templacool.com
 hypesquad-official-claim.com
 irs-claim-tax-government.com
 raspy-block-9328.on.fleek.co
+mth-crc.com
 joingrup-chikaa.xvideosx.xyz
 wellsfargobank-login.madslaps.com
 autoatencion-cmr-web.web.app
@@ -533,7 +770,6 @@ www.instgrm-post-copy.com
 webin14.xyz
 sturdy-shy-mongoose.glitch.me
 metamask.xn--cm-68s.cc
-divine-block-1795.on.fleek.co
 hsbconline.funseg.com
 metamask.io.update-wallet.in
 www.icloud-help.online
@@ -573,7 +809,6 @@ whatsapp-berbagilink-viral.nisaterbaru-2022.com
 www.con-area-sito.com
 ff-members-garana.com
 uguoil.433u82fx507266.workers.dev
-news-7day.ru
 www.connect1info.com
 download-4cafc.web.app
 boisehawkey.com
@@ -659,14 +894,12 @@ breach-dev-boundaries-conclude.trycloudflare.com
 groupbokep-2022.xvideosx.xyz
 jpsmc.co.uk
 link-grup-18-whatsaap.cf
-app-transaction-reversal-help.com
 accountesoui.gfffcdujhyopukr.com
 apple.dio-dom.biz
 hammettforest.com
 www.personas-inicio-santander-login.com
 studio-marketingu.pl
 primelink.longb11.shop
-gallant-chaplygin.193-233-48-73.plesk.page
 woliot-pejygem.com
 ig-mediaservice-contact.ml
 confirmaciondecuenta-c30e.czemarkojo.workers.dev
@@ -740,12 +973,7 @@ bonussber2022rub.net.ru
 chatwatshappgrup01.001www.com
 chat-whatsapp-dewasa.tk
 apple-channel-partner-connection.com
-folder839893-s8siklk33.web.app
 pubgeventramadhan2022.xvideosx.xyz
-www.ama-co-jp-news.joco8.xyz
-www.ama-co-jp-news.joco6.xyz
-traversenewseason.com
-www.mobiliesuisa.xgjijin.com
 snapchatfrance.org
 www.dregister-device-id5267.com
 rakutenen.shop
@@ -778,7 +1006,6 @@ minzcodex.xyz
 cl-bvxi.buzz
 pchpara.the7thsign.com
 www.aibaccessportal.com
-credit-agricole3.app.swtest.ru
 seuciusxia.com
 discord.trial-hypesquad-team.com
 btnmngfdfgh.weeblysite.com
@@ -845,16 +1072,12 @@ purple-fire-ba6f.subflok.workers.dev
 ammazon.usmfwngd54.shop
 amazzon.usmfwngd54.shop
 amazoin.usmfwngd54.shop
-business-page-appeal-186712-21.web.app
-business-page-appeal-1929861-2.web.app
 join-hypesquad-houses.com
-llogin-microsoftonline.mashcapyusu.org
 yachtregistrationisleofman.com
 forms-tester-moderator-news.com
 green-thunder-767a.topil602.workers.dev
 rectificationbot.network
 bus-iceland-mike-ambassador.trycloudflare.com
-americafirstcu.cyfer.cc
 luckyspinevents.gamename.net
 animateyvive.com
 hypesquad-billing-promotion.com
@@ -887,6 +1110,7 @@ steamcommunitynl.top
 moderating-panel.xyz
 alert-wellsfargobank-login.patrickbeninga.com
 vcbdignlbink.com
+metemas.me
 midasbuy.spin4event.com
 www.amazno.ponnno.com
 amazon-login-ip.jp
@@ -946,7 +1170,6 @@ m.facebook.com.itstimetodestruction.xyz
 aeon.co.jpoj35nvzap.shop
 amazon.co.jp.qrtsqc.shop
 aeon.co.jpojin4nklnlx.com
-www3.mstacsrauz.icu
 support.protecmyhelpclaimsafty.xyz
 www3.mstacsrouz.icu
 formulary-for-hypesquad.com
@@ -955,7 +1178,6 @@ www.rakoten-account.nhhirsl.ml
 pubgpaps.changeip.co
 secureaibmobileapp.com
 www.trust-wallet.weekendchefs.com
-redelivery-tracking-id.com
 selected-frequently-jackie-establishment.trycloudflare.com
 how-join-hypesquad-again.com
 bimbayram2.com
@@ -1032,136 +1254,4 @@ moderator-hypesquads-form.com
 aeon.yzvjkoq.shop
 20297-3303.s3.webspace.re
 www.wellsfargo.u1427.cn
-hypesquad-official-formulary.com
-hypesquadteam-moderators-form.com
-htvuustkxc.co.vu
-business-page-appeal-12976-212.web.app
-business-page-appeal-129862-20.web.app
-icy-cell-d5d2.doppa0542.workers.dev
-raspy-mud-3122.on.fleek.co
-reschedule-my-application.co.uk
-cornell-reaction-driven-faculty.trycloudflare.com
-business-page-appeal-129876-32.web.app
-crm-activacion-en-linea.web.app
-cvgbdfhg.co.vu
-marble-18fea.web.app
-walletsgrid.company
-hypesquad-programs-apply.com
-areaclientigruppointesa.com
-dchawkins.com
-www.amazon-into.live
-3dverify-support32.serveirc.com
-amazon-in.live
-www.ytyrtyrt.verification.ytyrtyrt.ciberesceptico.org
-ilovelucylou.com
-metaglobalcopyrightformss.ml
-lebomcoin.com
-likedater.com
-winnerinvestgroup.com
-dappvalidate-plum.vercel.app
-pancakeswap-claim.finance
-metamass.cc
-outlooksloglns.serveirc.com
-a0669188.xsph.ru
-exotic-merge-predicted-ibm.trycloudflare.com
-combat-prefix-raises-maintaining.trycloudflare.com
-verify.securityportal-wallet.com
-www.supportteams.ml
-santander.co.uk.authentication-report.app
-bmsfrance.dgk7p0vrf3gns.amplifyapp.com
-payeedecline-nw.com
-parcel-tracking-depot-id.com
-komfort-verify.online
-wwwmetamask.io.walletverification.in
-polska.unface.icu
-www.reaload-dati-privati.com
-thinkmediapartners.com
-replacement-collect.vantechdns.net
-george-microsoft-brothers-atmospheric.trycloudflare.com
-a0669336.xsph.ru
-kvctdiebkt.co.vu
-gsgen-6qaaa-aaaad-qb4la-cai.ic0.app
-gmiozridjh.co.vu
-hqgwwfpxjm.co.vu
-www.s.micrecerd.icu
-lwgxpqilhc.co.vu
-www.mobiliejfaoiweugsfjhhjousuisa.mobliegsafhgsalzjiogwrhjl.cyou
-www.c.micceerd.icu
-www.c.micrecerd.icu
-utahcountypt.com
-b1mcellkaplanx.com
-365mobile-webprotection.com
-deliverydateservice.com
-chat-whatsapp-com-ekypjqxu3myaf6pjevk.xvideosx.xyz
-join-new-hypesquad.tk
-official-invite-hypesquad.com
-www.nhhirsl.ml
-www.soportevirtualap.com
-contectlivemedia.ml
-huttnerhomes.com
-claimnows.forumz.info
-enter-the-hypesquad.com
-www.c.mstacsroez.icu
-connects-testers-forms-moderator.com
-b1mcelllodemeleriiibb.com
-bimcellodemesibayram.com
-www.c.mstacsooez.icu
-www.support.protecmyhelpclaimsafty.xyz
-www.m.facebook.com.itstimetodestruction.xyz
-www.applecojp.cc
-bimcelliistanbul.com
-netflix07bhubx.serveirc.com
-marketplaceaxieinfiniity.com
-extraforu.com
-proceduradigital.com
-www.testn-support.com
-www.lng-directweb.com
-www.aibmobileserviceapp.com
-aeon.co.jpoj3474eyop.jp
-b1mcelllrmzannyuklemee1.com
-just4mebookboutique.com
-goodzilakong.com
-jp-aeon.merrissawilliams.com
-www.c.mstacsuoez.icu
-aibmobilebankservices.com
-mercadolrber.prohosts.org
-chaese.ws
-www.loilld.eu
-areaclientigruppoisp.com
-apply-hypesquad-official.com
-luckyspin21.com
-apply-official-hypesquad.com
-getursite.com
-myemailssettings.com
-dbasbasnk.com
-free-amazon.live
-apply-program-hypesquad.com
-freematerialall.com
-www.s.mstacsaoez.icu
-emmaalexa.net
-sustainable-committed-themselves-appeal.trycloudflare.com
-a-mao-vv.live
-toppupucfree.com
-tarah-lynn.com
-www.ofertasgerais06.com
-www.ofertasgeraisatual.com
-opansee.online
-c1d66.ztskhtrseryfhvn.xyz
-jct1d.ztskhtrseryfhvn.xyz
-6tcgd.ztskhtrseryfhvn.xyz
-cl-qunf.xyz
-grub-bokep2022.001www.com
-xn--sphre-dsa.finance
-join-grub-bkp-terbaru.001www.com
-xn--looksrar-sed.com
-m3ttb.vercel.app
-battelgroundmabileindia.xyz
-leaflandscapesupplyonlinesecureinvoicingservice.on.fleek.co
-schwab-bank.com
-gzfhxqh.com
-bendigo-mobile.com
-throughout-persons-porcelain-recommend.trycloudflare.com
-ytyrtyrt.verification.ytyrtyrt.ciberesceptico.org
-meta-business-settings.web.app
-atth2hsweepstakes.com
 letsencryp.at

Plik diff jest za duży
+ 219 - 224
yoroi_suspicious_level2.dns


Niektóre pliki nie zostały wyświetlone z powodu dużej ilości zmienionych plików