root 3 years ago
parent
commit
b71a2de507
4 changed files with 1969 additions and 1913 deletions
  1. 306 325
      yoroi_malware_level1.dns
  2. 1263 1173
      yoroi_malware_level2.dns
  3. 187 194
      yoroi_suspicious_level1.dns
  4. 213 221
      yoroi_suspicious_level2.dns

+ 306 - 325
yoroi_malware_level1.dns

@@ -12,15 +12,15 @@
 qwtzjokvjfvecysgypbd.com
 4fdeb70f13.com
 iuykayqoyqcgwuku.org
-goicaamah.com
 0.net09.biz
-0bb.aveneual.com
+000052458524965.co.vu
 1.megaterralink.xyz
 035010086.com
 104-237-155-168.ip.linodeusercontent.com
 1254640862.retarus.ru
-141-164-46-99.l-cdn.com
+13.echtrezeptfrei.com.de
 1491406190.retarus.ru
+141-164-46-99.l-cdn.com
 18yax.com
 190-2-132-198.hosted-by-worldstream.net
 1bc327d101f645.spotifik.ru
@@ -28,130 +28,127 @@ goicaamah.com
 2b4ycxdn.cf
 3f876e5790.pamagirtic.com
 3ilogic.com.pk
+420ganjameds.com
 4dfkjdfg.monster
 5152a.com
 56china.com
 6dfkjgdfg.monster
 6ff.lucokst.com
+7d5c1hescy9d57d0.emoxan.xyz
 7dayswim.co
-999080321newfolder1002-01542599908032135.site
 99401039.retarus.ru
+999080321newfolder1002-01542599908032135.site
+8pu0mb.rappi.app.br
 999080321newfolder1002-012925999080321.com
 999080321newfolder1002002231-service1002.space
 999080321newfolder33417-012425999080321.space
-a.lxcmk.com
 a.ns.nanolinen.org
-abox.co.id
+a.g526.xyz
 acceptstatus.net
 adoring-carver.185-228-232-137.plesk.page
-afterloss.net
-aeolismtact.com
 allsprint.click
-alpinecsi.com
 altaibalancez.biz
-aknop.ws
+app-logln-verifica-n26-com.preview-domain.com
+arewethereyetapp.com
 assistance-facture.com
 auoneo-jp.aenastexk.cn
 auoneo-jp.t7xw623kfo.cn
 auoneo-jp.byzcpqzvb.cn
-auoneo-jp.m1a3jy32f.cn
 ayvpagsvdvh.com
-ba916.pariefe.com
-bae2ac6c.tabralliturk.com
+auoneo-jp.m1a3jy32f.cn
 banalbjar.com
 bcmqbunpnbpglxj.com
-big-funhere.life
-blogsystmes.click
+bknkz.findyourlovemate.net
+blackmailgoddess.com
 blog.new.rassudkov.com
-blackbelttv.com
-boschultespride.com
-box.flatbellytonicz.co
+blogsystmes.click
+bloginazienda.com
+bnvobfhj.fukugyogo.cfd
 brianca.get-back-1.com
-arewethereyetapp.com
+boschultespride.com
 by.scultenergy.com
-c3xn.althoutujym.club
-bviditcjw.ws
 bxazs.rmz61z1cc.cn
-cabvplyp.ws
-cargologint.com
-cbvcwain.com
+calrvgoxme.ws
 catchcarri.com
-certlflcatl-contiap-p-link.preview-domain.com
 ce9994f6.pamagirtic.com
-cdntc.advancedmactuner.com
+certlflcatl-contiap-p-link.preview-domain.com
+cerdasvideosxxx.alimentosconproteinas.com
+chokoleti.com
 code-de.preview-domain.com
 cool-hertz.192-3-245-183.plesk.page
+contentmakets.shop
+counterfeitnotestore.com
+cpcalendars.deconareao.mom
 crholeysf.com
 cryorganichash.com
+crajjinxdg.ws
 cu27t-evo29lution.xyz
+cvvme.st
 cryptotap.tw
-d4ac693.tabralliturk.com
-clothesshesight.xyz
 dateangels1.online
 dainigou.com
-dlubzg.ws
 doomdefender.com
+dlubzg.ws
+drawn-cash.com
+doneg-jp.qupebhed.cn
 drinkchamps.com
 dtsmapp.com
-dtnksj.ws
-e-cart.tech
 easyradioplayertab.com
-ehilc.ws
+e-cart.tech
 elievallowing.com
-emacouoxv.com
 eloquent-driscoll.43-239-249-136.plesk.page
 employee-lending.com
+emacouoxv.com
 email-techsupportnumber.com
+ehilc.ws
 enconnpasswi.com
-erubmshareio.mom
 event-terra.money
-doneg-jp.qupebhed.cn
-ficohsahonduras.interbac.repl.co
 fincloud.center
 finecenter.click
 fineonline.click
-flatbellytonicz.co
 flawgfx-25466.portmap.io
-frosty-violet-0628.on.fleek.co
+foundationappr.com
 fxpertos.com
 fuckfreegirls.com
-gcreditonebank.com
 gatewaytechitservices.com
+gcreditonebank.com
 geeks-board.com
 gelssk1.com
-geekbool.com
 georginalimo.com
 geneticincessant.com
-get-the-prize-ht3.live
+geekbool.com
 getrnd.com
+get-the-prize-ht3.live
 getsexy.life
+giveaway22.com
 globalfines.click
 go3s.biz
-gocenter.click
+gjhyt.fhmu43mf.cn
 googe.ca
 goonlinez.click
 googloe.com
-gtracking.org
+globalscholaropenhub.biz
 gorsys.com
-guesseaseselect.xyz
+gqo1oj454l.echtrezeptfrei.com.de
+highdesertdaily.com
 hjgsyeghgjhkkuuehhshjh.xyz
-hlf4iq.sanctuarycarry.cam
-hnn521.com
-hnwopwbyetq.ws
-hoplu.com
 horief.com
 hosted-4-client-dedicated-live-server4.greenenergysender.co
-ianmarriespaul.com
 ie3wisa4.com
-ijfeajpytcr.ws
-info-di-n26-com.preview-domain.com
-jakeview.ru
-kundendienst.club
+jbygs.com
+jdcd.g526.xyz
+jrincon-46119.portmap.host
+kast.p-host.in
+kapopeo.com
+keragenics.icu
+knfzakvl.com
+kpuheabdgew.com
+kongfansen.com
+kontrola-osoby.eu
 l8z572e5o.originalrezeptfrei.com.de
-ksmaitian.com
-l33t.brand-clothes.net
-link.possiblefinance.com-app.link
-linesanddesignsuae.com
+largedoubly.com
+last-news-4c34bci4ke28nb5f.gate8.xyz
+lanfeox.ws
 mail.aceguides.xyz
 mail.acewebsz.xyz
 mail.acehomez.xyz
@@ -160,357 +157,365 @@ mail.agingfeyt.cam
 mail.airproff.ru
 mail.apprecia.cam
 mail.availablese.cam
-mail.dashco.click
-mail.dashreviews.click
-mail.designmine.xyz
-mail.derconmi.cam
-mail.dollarfreedom.co
-mail.diacurres.sbs
-mail.foxentribution.click
-mail.fretptrgh.cam
-mail.globaltopz.click
-mail.goodwell.rest
+mail.avilaa.cam
+mail.bdyslimi.cam
+mail.bizly.click
+mail.careminez.click
+mail.en1courage.cam
+mail.extrnti.cam
+mail.fastfundin.cam
+mail.finelike.click
+mail.flipion.cam
+mail.flselgins8.com
+mail.foodble.co
+mail.groiici.cam
+mail.guidelikes.click
+mail.flyfstoree.shop
+mail.healthsaf.sbs
+mail.homdepotsi.com
+mail.hotbuyz.click
+mail.hotkeysz.xyz
+mail.hotonlines.xyz
+mail.hotrings.click
+mail.hubcenters.click
+mail.keranqi.cam
 mail.likeclubs.click
-mail.ktomichelin.com
 mail.likehome.click
+mail.ktomichelin.com
 mail.lck7sb.com
 mail.likerub.xyz
 mail.likedesigns.click
-mail.livingcos.cam
 mail.likeside.xyz
 mail.livleancart.biz
-mail.myfines.xyz
-mail.myoneblogs.click
-mail.mystoresz.xyz
-mail.mystudios.click
-mail.mytopgroup.click
+mail.manifestub.co
+mail.microblast.shop
 mail.nilioou.cam
-mail.nowtopz.xyz
-mail.purghjji.lol
-mail.realownz.click
-mail.smyous.cam
-mail.spacelikes.xyz
+mail.omjellyle.cam
+mail.renwilk.cam
+mail.reviewaces.click
+mail.renwmil.cam
+mail.richhots.xyz
+mail.rideones.xyz
+mail.shopaces.click
+mail.sidehots.xyz
+mail.siderings.click
 mail.sidelikez.xyz
+mail.shopshotz.click
 mail.smiseut.cam
+mail.smyous.cam
+mail.spacelikes.xyz
 mail.tapaces.click
 mail.terminixx.cam
-mail.tekilly.cam
-mail.thescrubb.cam
 mail.tiiobin.cam
+mail.thescrubb.cam
 mail.timeowned.xyz
 mail.top24hots.click
-mail.topgroup24.click
-mail.topstoresz.click
-mail.touchlike.xyz
 mail.tr0tcrds.com
+mail.toponwes.xyz
+mail.touchlike.xyz
+mail.turmeri.cam
 mail.uecutat.cam
 mail.vchcvp.com
 mail.wayouss.cam
-mail.wibosti.cam
-mail.yourtuml.cam
-mail.woodmaker.icu
-mamsports.org
-matamask.info
-metamask.ru
-misstouracollection.fr
+mstarstraining.com
+mpsienaprotezioneonline.com
+n26-fr.preview-domain.com
 n26-us.preview-domain.com
 nafdress.com
+navoichyk-38046.portmap.io
+netprofitstoday.com
 news-cogiho.com
-news-modoxe.cc
-ns1.adsuperiorstore.com
 ns7.lite-host.in
-oipvnjbfgius.com
-odoqlphzhf.ws
+oatmeallump.com
 oaruou.ws
-opzioni-con-sblocco-com.preview-domain.com
+oipvnjbfgius.com
 ongaromusket.com
 online.hsbc.co.om
+opzioni-con-sblocco-com.preview-domain.com
 optimizerprostarter.net
 opensels.com
 orders-amaz0n.com
-or.ip.dadukouxny.com
 oxiqyxos.com
+or.ip.dadukouxny.com
 parsish.com
-partymanshop.com
 partners-space.life
+partymanshop.com
 paypalaccounts.fr
-php.vpn-professional.company
+pdhpqmqho.ws
 ping.lotterydefeatr.co
 pinoakpubandlinks.com
+php.vpn-professional.company
 pischedda.com
+pic.cqkms.com
 play.verificacion.digital
 plusbasez.click
-poke.egybest.icu
-poplarcolonistgreatest.com
+postpurchaseapp.com
 primalpowr.co
-protezioneonlinempsiena.com
-protecao30horas.com
 q.scan.leakix.org
+q6304.23g-u6.bar
+qcfrnvus.ws
 rafn.ch
 r2wem.com
-rancho.nitrileanex.one
+quontibank.com
 rbx.fun
+rancho.nitrileanex.one
 rcvryaccntspgs.cf
+rcvryaccntspgs.ml
 reddotarms.com
 renard.re-funds-us.com
-resultpleasure.net
 repov.ru
-rhneekxvw.ws
 removeyourbadreviews.net
-qb.inr9xymph8j.com
+restorationbowelsunflower.com
+resultpleasure.net
+roblox.com.nf
+rp.downloadastrocdn.com
 rpcnetconnect.com
 rugiomyh2vmr.com
 s1622127622870.signlcamp.com
-run.conohawing.com
 savagegrowplus.com
 search.hemailloginnow.com
 searchfox.xyz
 secure-accesss-5fqhuufn9c.news-hot.xyz
 septik-eco.ru
+server29.pd-promostore.com
+service4.camedia.us
+sgjfafuse.ws
+shownperfunctory.com
 sicuro-con-n26-com.preview-domain.com
-sirepisode.com
+slot0.tabumyale.xyz
+sistemaup.ru
 smarttv-4k-magazineluiza.com
 simplepoll.rocks
-sistemaup.ru
 spk.deservice-info.de
 srv2.camedia.us
+srv3.camedia.us
 standardcontinentalbank.com
 summonedessencetrap.com
 sweepstakessurveytoday.com
 svepoi.com
 szoegatl.com
-tcyuchu.com
+thaodufurniture.com
 tklaxrrzzo.com
-tomphorwath.com
 tor-exit-node.spongebob.nicdex.com
 totalnicestories.com
 tpenccoosvy.com
 tvycdn.hs-sites-eu1.com
-uhbccvilfm.com
-update.vscreenshot.com
-urasekeyys.com
 unclechunk.com
+update.vscreenshot.com
 user.yujxxtclszxizmbbyrwkodrh.nursesport.nl
+update-jp.glxpslwzr.cn
+vdkdpdjdunqbhm.com
+uspsdelivery-service.com
+verifica-sicura-nv6-com.preview-domain.com
 verifica-sicurezzan26-online.preview-domain.com
 verificadispositivimyn26-com.preview-domain.com
-vdkdpdjdunqbhm.com
-verlflca-26web-onllne-com.preview-domain.com
-vimaglos-uno.preview-domain.com
 verify-your-identity-pages2022.cf
-view-cs3.ca7qqr30ndva3qo00010at77m35shwawc.oast.fun
+vimaglos-uno.preview-domain.com
 vps.secudomains.com
-vjevh.ws
+view-cs3.ca7qqr30ndva3qo00010at77m35shwawc.oast.fun
 wearonsale.com
 webdisk.mandmexcavatingllc.com
-webmail.cornerstonecreativestudios.com
-webmail.alaziz.in
-wellnessinsights.net
 wkreml.work
-wmgigftmkg.com
-workforcemanagementsoftware.net
 www-ccma-video.hs-sites-eu1.com
-woyaomir.com
-www.aesoecon-asoamecosmne.pwrkgwt.md.ci
+www.55t.co
 www.all-sprint-now.click
 www.allsprint.click
 www.altaibalancez.biz
-www.aesocon-asoemsnacosmn.tngbngu.md.ci
-www.aesocon-asoemsnacosmn.hfzaqrx.md.ci
 www.aesocon-asoemsnacosmn.blerbbw.md.ci
-www.aesocon-asoemsnacosmn.njccweg.md.ci
-www.aesoecon-asoamecosmne.opbgnsz.md.ci
-www.aesoecon-asoamecosmne.clvngzi.md.ci
-www.aesoecon-asoamecosmne.zdfwnkl.md.ci
-www.availablese.cam
 www.aesocon-asoemsnacosmn.jekapmb.md.ci
+www.aesocon-asoemsnacosmn.hfzaqrx.md.ci
+www.aooueu-aoosescnomen.qecikwn.md.ci
+www.aoescu-ccoaosmoussecuc.spgeeuz.museum.mw
+www.applreviews.click
+www.aoescu-ccoaosmoussecuc.ysvzvam.museum.mw
+www.asceosuu-asoseisndmsn.3f7.top
+www.asceosuu-ousaouuaosmenu.hao35.top
+www.crushitpw.com
+www.finecenter.click
+www.fineonline.click
+www.globalfines.click
+www.goonlinez.click
+www.ecki-ujp.top
+www.msizanezabudka.sk
+www.numbersforsupport.com
+www.yessearches.com
+www.nhk-or.jp.signup.k01tlf.cn
+yg67nm1a.speechworld.cam
+yoke.meticore.icu
+yunk.horief.com
+zambia.co.zm
+zernw.com
+zhwjryfutc.ws
+zn558.com
+allcommonblog.com
+bestnlllc.click
+buyzones.click
+caredesign.click
+c15cxhuh.mwprem.net
+harmonycanyon.com
+hlf4iq.sanctuarycarry.cam
+hnn521.com
+mail.ahegewa.cam
+mail.boysiati.cam
+mail.bpmeids.cam
+mail.cablessi.cam
+mail.caplike.click
+mail.cipiunnt.cam
+mail.clckh.click
+mail.clubsmines.xyz
+mail.cmejaorr.cam
+mail.consultingones.click
+mail.cotscorew.com
+mail.dashco.click
+mail.dashreviews.click
+mail.designmine.xyz
+mail.derconmi.cam
+mail.designones.xyz
+mail.dollarfreedom.co
+mail.diacurres.sbs
+mail.fretptrgh.cam
+mail.fsshopz.click
+mail.goodwell.rest
+mail.goultraplus.rest
+mail.livingcois.cam
+mail.puypliig.cam
+mail.rausem.cam
+mail.purghjji.lol
+mail.readylike.xyz
+mail.reachonez.xyz
+mail.readyhots.xyz
+mail.realmines.click
+metamask.ru
+milkpload.net
+misstouracollection.fr
+metamesk.world
+mrbfile.xyz
+mlnsdnekptd.ws
+specialistcorrelation.com
+trial-hypesquad-form.com
+turnipobjection.com
+unknitting.com
+wellnessinsights.net
+true-precision.com
+whitedragon.com
+www.aesoecon-asoamecosmne.zdfwnkl.md.ci
+www.aesoecon-asoamecosmne.pwrkgwt.md.ci
+www.aesocon-asoemsnacosmn.tngbngu.md.ci
+www.aesoecon-asoamecosmne.opbgnsz.md.ci
 www.aesoecon-asoamecosmne.slvhfef.md.ci
+www.aesoecon-asoamecosmne.pjypsxc.md.ci
+www.aesoecon-asoamecosmne.prshxed.md.ci
+www.aesocon-asoemsnacosmn.njccweg.md.ci
+www.bestnlllc.click
+www.aesoecon-asoamecosmne.clvngzi.md.ci
+www.benandloz.com
 www.blogsystmes.click
-www.aoescu-ccoaosmoussecuc.ysvzvam.museum.mw
 www.boutique-cancer-de-mama.es
-www.bocjdj3k2.com
-www.aesoecon-asoamecosmne.prshxed.md.ci
-www.aesoecon-asoamecosmne.pjypsxc.md.ci
+www.buyzones.click
+www.blog.hostmaster.blog.blog.test.cardinalholdingsltd.com
+www.caredesign.click
 www.carveuser.co
 www.classifiedsnearme.com
 www.circasuper.cam
-www.blog.hostmaster.blog.blog.test.cardinalholdingsltd.com
-www.c.aeno-sern.icu
-www.c.epoecsed.icu
-www.c.mstaexoun.icu
-www.c.smbscrzuad.icu
-www.fineonline.click
-www.finecenter.click
-www.globalfines.click
-www.ecki-ujp.top
-www.numbersforsupport.com
-www.orico.wapkute.com
-www.ommindbodysoul.com
-www.playpopgames.com
 www.powerfromsunlight.com
-www.planspin.doctor
-www.primalpowr.co
+www.regcurelicensekeycode.com
 www.remessetnt.cam
-www.cfproud.com
-www.rxhelp4nv.org
-www.tycoonforum.games
 www.rippedknees.co.uk
 www.roombelt.dance
+www.rxhelp4nv.org
+www.shedwood.cam
 www.sessionjudgment.exchange
-www.upacreekhuntsville.com
+www.cfproud.com
+www.sqribblesupdatesplus.live
+www.stacees.com
 www.woiuorh.cam
 www.websiteservices.com
-www.yessearches.com
-xaiaxkektbjfqxf.com
-yg67nm1a.speechworld.cam
+www.spinedevote.institute
+www70chun.com
+www.shoppingtrolleyhandlewrap.com
+www.wwip.com
+zrianevakn1.com
 xmmyhl.com
+btmpgcgpjwagnx.com
+downwheelmine.xyz
+hoplu.com
+jakeview.ru
+jackintheboxworldwide.com
+kundendienst.club
+mail.derionsp.cam
+mail.myoneblogs.click
+mail.myfines.xyz
+mail.myownz.xyz
+link.possiblefinance.com-app.link
+linesanddesignsuae.com
+mail.posguilter.cam
+mail.phnionr.cam
+marineworks.eu
+mhvllvgrefplg.com
+mmtaylor.net
+mta1.sent4promos.com
+mta2.sent4promos.com
+pluto.lovestuff.us
+ringtechsz.click
+thebestwebpillplace.com
+trienestooth.com
+www.keragenics.icu
+vpeae.ws
+www.kratochwill.si
+www.mail.moneymentorz.com
+www.masteosmsndrosnem.igniklr.ne.pw
+www.ingenieriademexico.com
+goicaamah.com
+alpinecsi.com
+aknop.ws
+bviditcjw.ws
+cabvplyp.ws
+cbvcwain.com
+clothesshesight.xyz
+dtnksj.ws
+guesseaseselect.xyz
+hnwopwbyetq.ws
+ijfeajpytcr.ws
+info-di-n26-com.preview-domain.com
+ksmaitian.com
+mail.mystoresz.xyz
+mail.mystudios.click
+mail.mytopgroup.click
+mail.realownz.click
+mail.wibosti.cam
+mail.yourtuml.cam
+mail.woodmaker.icu
+odoqlphzhf.ws
+rhneekxvw.ws
+qb.inr9xymph8j.com
+uhbccvilfm.com
+vjevh.ws
+webmail.cornerstonecreativestudios.com
+webmail.alaziz.in
+wmgigftmkg.com
+workforcemanagementsoftware.net
+woyaomir.com
+www.orico.wapkute.com
+www.ommindbodysoul.com
+www.playpopgames.com
+www.planspin.doctor
+www.primalpowr.co
+www.tycoonforum.games
+www.upacreekhuntsville.com
+xaiaxkektbjfqxf.com
 zbctbmgby.ws
 zichabowling.com
-zoro-forex.com
-zn558.com
-13.echtrezeptfrei.com.de
-8pu0mb.rappi.app.br
-counterfeitnotestore.com
-harmonycanyon.com
-highdesertdaily.com
 ln-verlflaccaunt-n-link.preview-domain.com
-lanfeox.ws
-mail.bizly.click
-mail.avilaa.cam
-mail.centertopz.click
-mail.cipiunnt.cam
-mail.clckh.click
-mail.clubaces.xyz
-mail.clubsmines.xyz
-mail.clubzones.click
-jbygs.com
-mail.cmejaorr.cam
-mail.keranqi.cam
-mail.manifestub.co
-mpsienaprotezioneonline.com
-mmtaylor.net
-navoichyk-38046.portmap.io
-restorationbowelsunflower.com
-service4.camedia.us
-slot0.tabumyale.xyz
-srv3.camedia.us
-www.aoescu-ccoaosmoussecuc.spgeeuz.museum.mw
-www.shoppingtrolleyhandlewrap.com
 www.systems-updater.com
-www.spinedevote.institute
-www.stacees.com
-www.takeecar.cam
-www.sqribblesupdatesplus.live
 wxhbgliwed.ws
-zernw.com
-www.nhk-or.jp.signup.k01tlf.cn
-a.g526.xyz
-bloginazienda.com
-jrincon-46119.portmap.host
-kapopeo.com
-kast.p-host.in
-globalscholaropenhub.biz
-kpuheabdgew.com
-mail.bdyslimi.cam
-mail.bpmeids.cam
-mail.boysiati.cam
-mail.caplike.click
-mail.cablessi.cam
-mail.careminez.click
-mail.cotscorew.com
-mail.en1courage.cam
-mail.extrnti.cam
-mail.fastfundin.cam
-mail.finelike.click
-mail.homdepotsi.com
-mail.hotbuyz.click
-mail.microblast.shop
 mail.numbswp.com
-mail.omjellyle.cam
 mail.ownandz.xyz
 mail.ownmarketingz.click
 mail.ownfinez.xyz
 mail.one-pr-24owns.click
 mail.ownshatz.click
-q6304.23g-u6.bar
-shownperfunctory.com
-whitedragon.com
-www.goonlinez.click
-www.crushitpw.com
-www.aooueu-aoosescnomen.qecikwn.md.ci
-www.healtfitt.cam
-www.keragenics.icu
-www3.smbs-carud.icu
-www3.smbs-cazad.icu
-yoke.meticore.icu
-yunk.horief.com
-www.ingenieriademexico.com
-zrianevakn1.com
-calrvgoxme.ws
-drawn-cash.com
-gqo1oj454l.echtrezeptfrei.com.de
-keragenics.icu
-largedoubly.com
-mail.hotonlines.xyz
-mail.hotkeysz.xyz
-mail.hotrings.click
-mail.hubcenters.click
-qcfrnvus.ws
-sgjfafuse.ws
-www.applreviews.click
-www.benandloz.com
 www.ou80.com
-www.asceosuu-asoseisndmsn.3f7.top
-www.asceosuu-ousaouuaosmenu.hao35.top
-www.regcurelicensekeycode.com
-000052458524965.co.vu
-7d5c1hescy9d57d0.emoxan.xyz
-app-logln-verifica-n26-com.preview-domain.com
-bnvobfhj.fukugyogo.cfd
-bknkz.findyourlovemate.net
-cvvme.st
-crajjinxdg.ws
-cpcalendars.deconareao.mom
-foundationappr.com
-last-news-4c34bci4ke28nb5f.gate8.xyz
-learntolivestream.com
-mail.consultingones.click
-mail.fsshopz.click
-mail.goultraplus.rest
-mail.groiici.cam
-mail.guidelikes.click
-mail.healthsaf.sbs
 mail.onetouchz.xyz
-mail.posguilter.cam
-mail.puypliig.cam
-mail.rausem.cam
-mail.readyhots.xyz
-mail.reachonez.xyz
-mail.readylike.xyz
-mail.realmines.click
-mail.renwilk.cam
-mail.renwmil.cam
-mail.richhots.xyz
-mail.reviewaces.click
-mail.rideones.xyz
-mail.searchsu.cam
-mail.shopaces.click
-mail.shopshotz.click
-mail.sidehots.xyz
-milkpload.net
-mrbfile.xyz
-n26-fr.preview-domain.com
-mlnsdnekptd.ws
-netprofitstoday.com
-lfpengyuan.com
-postpurchaseapp.com
-pdhpqmqho.ws
-quontibank.com
-pic.cqkms.com
-rcvryaccntspgs.ml
-update-jp.glxpslwzr.cn
-zambia.co.zm
-www2.aenosaen.icu
-www.wwip.com
 ahla.kasegeru.icu
 agbiykhe.ws
 atzkpikc.ws
@@ -519,15 +524,11 @@ airopengo.xyz
 bufsn.ws
 ciue.kasegeru.icu
 duqgxsyuz.ws
-eubymmhu910iqiv.super-gos.com
 ezpeci.ws
 herpagreenz.us
 kubrbt.kasegeru.icu
 mail.acerides.click
 mail.acesystemsz.click
-mail.cityaces.xyz
-mail.flatbellytonicz.co
-mail.minetopz.click
 miqthtvmgs.ws
 nwuiwrfibl.ws
 ockosibfm.ws
@@ -535,23 +536,12 @@ okonlteb.ws
 qyxecpwtarp.ws
 rzgjwe.ws
 ucuwrde.ws
-www.mail.moneymentorz.com
-www.msizanezabudka.sk
-www.shedwood.cam
-www.masteosmsndrosnem.igniklr.ne.pw
 xrxqjblq.ws
 eqanio.ws
 fjcsi.ws
 jwxznh.ws
-mail.centerace.xyz
-mail.rubkeyz.click
 mail.toponlines.click
-mail.topreels.click
-mail.toprides.xyz
 mail.trandigod.buzz
-mail.foodble.co
-www.kratochwill.si
-knfzakvl.com
 10digitalmaio.com
 aohgk.ws
 aslatlykl.ws
@@ -587,19 +577,13 @@ kveupx310.top
 cysruy27.top
 qaoymg12.top
 jeecx.ws
-mail.handrubz.xyz
-topreels.click
 zlpfd.ws
-www.herpagreenz.us
 wrsexmuafdb.ws
-168ddc.bombrermey.com
-a680.bombrermey.com
 byhvkjgnw.ws
 cpcalendars.affettuacces.com
 cviqysmimim.ws
 dfdph.ws
 dgckho.ws
-docetnrel-gamas.com
 dmpdzpztuum.ws
 jujfljcxp.ws
 knluumzfcf.ws
@@ -609,7 +593,6 @@ moshouzer.com
 nabklfxi.ws
 oazzo.ws
 olx-pl.track02647.xyz
-orfblv.fukugyo.bar
 tqwgqlfz.ws
 umrgjwap.ws
 w0-sn.com
@@ -625,18 +608,16 @@ wellsimpledown.xyz
 fpfonsvwt.ws
 ifhkddmum.com
 ksazjkixtir.ws
-donechildrencountry.xyz
 ccb.wellnessinsights.net
-largehatexcept.xyz
 mrkrrmsogajlphleb.net
-bjfiohodca.com
 bimgrdyrmwekvpfpyt.com
+bjfiohodca.com
 jomphxvfrliviihfwck.com
 kbcoimnweurxr.com
 lhmccaykgbawgjjjfwhl.com
 pcyuutvrsihskchowrw.com
-rgwwewjacuxcwekcfl.com
 ptxbiwscytpnft.com
+rgwwewjacuxcwekcfl.com
 tabnyenpxwetpeihx.com
 snibnlnglnfafnsc.com
 dayvbcom.com
@@ -646,10 +627,6 @@ mitykcbhus.com
 nqpeesdcfhqtkfoq.com
 ygrbwioorib.com
 ehevdmvfxpjdotrdrudx.com
-elsarre.com
-jaccoia.org
-oolnhtep.com
-ptinybpjs.com
 kvepre23.top
 kverza68.top
 kvetdb32.top
@@ -684,6 +661,10 @@ uwdidl33.top
 uwdizh24.top
 uwdovj12.top
 uwdjus18.top
+elsarre.com
+jaccoia.org
+oolnhtep.com
+ptinybpjs.com
 gzcfr5axf6.com
 enoan2107.com
 aa.hostasa.org

File diff suppressed because it is too large
+ 1263 - 1173
yoroi_malware_level2.dns


+ 187 - 194
yoroi_suspicious_level1.dns

@@ -9,6 +9,193 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+sparkassen-risikomanagement.com
+offlcemicros0ft95478-0nlinedocument242964.office365-sharepointdoc.workers.dev
+aza.d366uy1x73dva4.amplifyapp.com
+www.loginmps.me
+official57website.blogspot.ba
+www.metamaskimg.buzz
+invite-hype-teams.com
+official57website.blogspot.bg
+metamaskext.info
+postoffice.depot-35.com
+hsbcbank.clientswelcomeltd.com
+www.hsbcbank.clientswelcomeltd.com
+syncwalletinc.com
+credit-agricole.fr-particulier.raeisosadat.com
+pubgs20.net
+www.sg-client.fr
+bivcellxmre.com
+dghj22.lovestoblog.com
+magamais.online
+u9-sd4-en5.web.app
+mors22.com
+website-meta-nefgpgknnkkuiongftyunfdrehfkafhasl.lo-websiet.xyz
+loooksraer.org
+mailtrack-userupdate.com
+trials-hypesquad-form.com
+cesardeleija.com
+cjwelectric.net
+carefm.net
+e10-inc.com
+caliboroftiger4.vercel.app
+innovativebuildingenergy.com
+push-app.online
+safe-app.online
+backup-phrase.io
+www.personas-supervielle-login-aspx.ml
+pubgspin14.dubya.net
+maykodesign.com
+texasgis.com
+formulary-team-hype.com
+miss-fails-ccd-here.trycloudflare.com
+helpsupport212121458575325.co.vu
+loginmtb.web.app
+hypeteams-2022-formulary.com
+servicepageprotection-repair.gq
+confirmatioppsl.com
+logmtbx.web.app
+confirmatiovell.com
+spazie1.clanservers.com
+airbnb-es.p70135me.com
+247helpusmtb0user.serveftp.com
+mulsubs.org
+www.trustwllet.co
+www.online-portal-support-apple.mysupply-portal-support-online-apple.com
+maskverifyphrase.info
+ecoassistconsulting.com
+magzn-factur.com
+fourseasonsofgreen.com
+axieinfinity-connect-ronin.space
+seguromaisvoce.online
+www.onlinesecure123.xyz
+consultesuaftrmaga.site
+mysupply-portal-asia-apple.mystore-support-apple.com
+www.mysupply-portal-asia-apple.mystore-support-apple.com
+tvpoki.hs-sites-eu1.com
+www.axieinfinity-connect-ronin.tronlink-connect.space
+online-portal-support-apple.com
+newtownnd.com
+www.metamaskwebs.net
+pimisor958.temp.swtest.ru
+appersvirt.com
+formulary-teams-hype.com
+yybya-7aaaa-aaaad-qcf4a-cai.ic0.app
+bafybeibrripg4ygrioyvehbob3sxicrezxzw52ejc3vtgp5p66mdjbryae.ipfs.nftstorage.link
+cmt-eintl.com
+www.aceoouu-asosmaoemsnouu.lakbplc.ne.pw
+www.aeecouu-aaouusneosmnu.owdtojc.museum.mw
+www.aeecouu-aaouusneosmnu.dnzdbxi.museum.mw
+www.aeecouu-aaouusneosmnu.ujwxoyd.museum.mw
+www.aeecouu-aaouusneosmnu.yynuvtr.museum.mw
+www.aeecouu-aaouusneosmnu.nlkdtqh.museum.mw
+www.ucspin08.dubya.net
+beta-test.crtromain.repl.co
+bettina-ebay.de
+www.masteosmsndrosnem.ymhfjfb.ne.pw
+grup-viral-kenzy-terbaru-23.viiirallll.cf
+rakvten-card.co.ip.teadsdr.gq
+rakoten-account.co.ip.teadsdr.gq
+louitacc.xyz
+stendellionltd.com
+rakoten-cord.co.ip.teadsdr.gq
+diskord-nitro.ml
+pubgspin17.dubya.net
+turnkeychoices.com
+heike-anfordern.de
+maria-anfordern.de
+callen4indiana.com
+www.ingresofamiliar-anses.ml
+sfrclients.ml
+steamcummunlty.ru
+yahoofake.duolingo.gq
+claimmlbbfreex.gamename.net
+blinzero.xyz
+www.blinzero.xyz
+matamask.xyz
+www.mettamask-io.com
+rakvten-card.co.ip.teadsdr.tk
+rakoten-update.co.ip.teadsdr.tk
+rakoten-account.co.ip.teadsdr.tk
+ob34.ff.garenask.vn
+602553.com
+tutorial-skinml764.cf
+freemlbbclaim.gamename.net
+noiresilk.com
+www.ingresosuper.com
+xn--aav-dma.com
+rakoten-cord.co.ip.teadsdr.ml
+www.daminaccsonz.club
+rakvten-card.co.ip.teadsdr.ml
+rakoten-account.co.ip.teadsdr.ml
+rakoten-update.co.ip.teadsdr.ml
+hipsegunda01.com
+po-supporthelp.com
+maskphraseverify.info
+nyondistribution.com
+hipsegunda02.com
+acigueloft.com
+bgmiji.coda01.cyou
+grupchatdsh2022.co.vu
+hyperlosaten.com
+androidmagazines.info
+looksrares.io
+www.integral-dex-bridges.net
+iiywakffbl.cfolks.pl
+info.support.beautyschooldropout.co
+aave-staking.com
+sushisswap.app
+arklagutters.com
+styleco.be
+die-post-ch-8b852.radikalwinds.pt
+meeeghanteelo.diskstation.eu
+bgmi-official.xyz
+rakoten-cord.co.ip.teadsdr.tk
+groupchikaviral20juta.001www.com
+rakoten-update.co.ip.saplrqs.gq
+claimfrelfgarena8d.co.vu
+shopyouadore.com
+citiprepaid-salaryatsea.com
+manage-signin-accntsas.com-iewotif.com
+colpa23.ihostfull.com
+hypnotic-momentous-epoxy.glitch.me
+secureonlinecrv.redirectme.net
+rg0c4t7oieid8m0to06b5r3076kl41v9e6svkj4h7ifmcb2a2omrkg8.siasky.net
+www.integral-dex.net
+caracoltv.hs-sites-eu1.com
+opensea-io.click
+www.mtbonk.pics
+www.mtbbonk.pics
+grup-chika-virall-hot2022.001www.com
+charming-chaplygin.83-229-85-159.plesk.page
+paxful-trade.pro
+lmsolveit.link
+ameliaoffical.001www.com
+dirt-azure-jersey.glitch.me
+fastclubgirl89.16-b.it
+rakoten-account.co.ip.saplrqs.gq
+rakoten-cord.co.ip.saplrqs.gq
+bdamcell.com
+discordhypesquad.ga
+auth.mutantx.co
+cloudpaperrze.com
+lavesilke.com
+pubgspin16.dubya.net
+www.sg-espaceclient.fr
+claimfreeskinmlbb.gamename.net
+kenmacintoshphotography.com
+joingrupp99.tk
+rakvten-card.co.ip.saplrqs.gq
+invite-teams-hypesquad.com
+girolep772.temp.swtest.ru
+groupzzssx-whstap8.cf
+53-web.info
+aibonline-ie-secure.com
+www.aeosou-csoaoeusnmouuuau.saqqfwx.museum.mw
+www.aeosou-csoaoeusnmouuuau.yzaajzs.museum.mw
+www.masteosmsndrosnem.tplnygh.ne.pw
+www.masteosmsndrosnem.njqlkix.ne.pw
+www.metamaske.info
 long-law-wireless-mariah.trycloudflare.com
 opensea-apps.com
 spring-leaf-1244.on.fleek.co
@@ -38,7 +225,6 @@ disc0rd-nitr0.com
 portal.organiseit.workers.dev
 mhzac-zaaaa-aaaad-qcgia-cai.ic0.app
 sync-dapp.net
-bettina-ebay.de
 softfilesetup.pages.dev
 bra-popup4.com
 erui.cam
@@ -97,23 +283,8 @@ metamask.io.web7932.web07.bero-webspace.de
 metamask.pagevalid.in
 bruietuopdb.com
 correctionprotocol.com
-glrickerstudios.com
 maiodigitalfinal007.com
 mmhsalesconsulting.com
-redaxz.co.vu
-rewrlution.com
-shannonwlambert.com
-www.aceoouu-asosmaoemsnouu.lakbplc.ne.pw
-www.aeosou-csoaoeusnmouuuau.saqqfwx.museum.mw
-www.aeosou-csoaoeusnmouuuau.yzaajzs.museum.mw
-www.aeecouu-aaouusneosmnu.owdtojc.museum.mw
-www.aeecouu-aaouusneosmnu.yynuvtr.museum.mw
-www.masteosmsndrosnem.njqlkix.ne.pw
-www.masteosmsndrosnem.tplnygh.ne.pw
-www.masteosmsndrosnem.ymhfjfb.ne.pw
-aibonline-ie-secure.com
-pederopeder.com
-www.aeecouu-aaouusneosmnu.nlkdtqh.museum.mw
 info.ozanom.com
 aibcustomer-care.com
 huntingtonbank.clientswelcomeltd.com
@@ -219,16 +390,12 @@ pencakiswap.xyz
 dl-reason-paul-og.trycloudflare.com
 materials20.org
 aavee.net
-metamesk.world
 wypdek-dagmara.pl
 metamask.lv
 rakoten-cord.co.ip.uyllfkr.tk
 www.amazzn.macal.top
-kasihtaksam.co.vu
 proter-v.web.app
 www.aceoouu-asosmaoemsnouu.koaxtzt.ne.pw
-www.aeecouu-aaouusneosmnu.ujwxoyd.museum.mw
-www.ucspin08.dubya.net
 eltesoro.isir1.repl.co
 www.aoscouu-aosmesmcouuu.evjdubt.museum.mw
 www.aceoouu-asosmaoemsnouu.ffbskwz.ne.pw
@@ -362,7 +529,6 @@ xxcuv-aiaaa-aaaad-qce3q-cai.ic0.app
 www.facebook.orionlearning.com
 anazon.bgdpmjl4.cn
 business-page-appeal-12976-723.web.app
-earthsmartok.com
 relevantcitiesstudios.com
 www.airbnb.uk-safe-secure-prop-93782.xyz
 www.mturkiyegovtr-geri-iade-sistemii.org
@@ -428,7 +594,6 @@ maurerpartner.at
 pubgspin08.dubya.net
 www.aeecouu-aaouusneosmnu.vwichcb.museum.mw
 www.aeecouu-aaouusneosmnu.lixfwcz.museum.mw
-www.aeecouu-aaouusneosmnu.dnzdbxi.museum.mw
 www.aeecouu-aaouusneosmnu.oaoaszx.museum.mw
 www.aeecouu-aaouusneosmnu.iodifpd.museum.mw
 www.aoscouu-aosmesmcouuu.qzcsgvk.museum.mw
@@ -551,9 +716,7 @@ bokepjoin-whatsappchat.001www.com
 eventffterbarugarena.001www.com
 business-page-appeal-12870-521.web.app
 www.mturkiyegovtr-geri-iade-portalli.org
-beta-test.crtromain.repl.co
 ebay.co.uk-124039263947.info
-25884221.hs-sites-eu1.com
 servicnotifications.com
 nificatioyugood.com
 business-page-appeal-12986-392.web.app
@@ -730,7 +893,6 @@ sparkling-tooth-3498.on.fleek.co
 www.acoeuu-aaosmensoouuus.xyfjzrt.museum.mw
 kjhgffghjkjhgf.weeblysite.com
 my-site-108046-104309.weeblysite.com
-www.metamaske.info
 aib-onlinetransaction-help.com
 media-wolk.com
 www.royalbscotlandplc.com
@@ -1207,7 +1369,6 @@ www.acoeuu-aaosmensoouuus.juizard.museum.mw
 www.aoescu-ccoaosmoussecuc.ecpgklh.museum.mw
 exodus.allwalle.xyz
 webdisk.angelbursa.com
-i-neb.net
 www.vicsevseinmi.itupype.ne.pw
 newlife-morningstar.com
 swedbank-saugus.com
@@ -1644,171 +1805,3 @@ tukamera.avira-landing.com
 fircrestumc.net
 www.energy-rozrywka.click
 www.heyingyz.com
-aplock.net
-bias-remainder-wave-documentation.trycloudflare.com
-infant-cj-cycles-refinance.trycloudflare.com
-fg1oaus8erfg52balaicg0cpupis0c1rggej0qar2bdmp6ccd7455m8.siasky.net
-confirm.santander.uk.device97.com
-portugal-figures-tests-gambling.trycloudflare.com
-officialwebsitepcccckjh.blogspot.rs
-13spinlucky.com
-rakoten-update.co.ip.eosxpeb.tk
-rakoten-account.co.ip.eosxpeb.tk
-still-sun-3436.on.fleek.co
-americanfirst.delibocn.com
-sellingwithgelling.com
-amerfirstselfhelp47.info
-amerfirstselfhelp48.info
-bxjxjmcexel.com
-walletsrepository.net
-harnaa.huanterikolasgarebutanuisa.link
-instagramauthenticate.ga
-illegal-century-blogger-bufing.trycloudflare.com
-hypesquad-team-forms.com
-4eyt.p7yh.repl.co
-pagesupportsconfirms364.co.vu
-bovedasmoke.net
-programmes-stability-0consultation-mstrycloudflare.ml
-pubghf.com
-xnxxbokep18.co.vu
-1q2j.builder.hemsida24.se
-eeupdate-billing.com
-amauon.poc-jp.com
-lcl88153je.temp.swtest.ru
-boostpaks.com
-eventsluckys.com
-cook-recording-monsters-delivering.trycloudflare.com
-derryinsurance.com
-siteverse.hs-sites-eu1.com
-boostflavors.com
-groupesboam-001-site1.etempurl.com
-paypal.neonshop.xyz
-gdconsulting-bg.com
-citisupport.org
-enrollments360.org
-discord-hypeapply.com
-instagram-copyright.eu
-eyeboxtoolsinc.com
-scrimsbattleroyale.us
-columbia-warrant-harmony-allocated.trycloudflare.com
-afm-appstore.com
-lynnvastyan.com
-free.prize4u.xyz
-americafirsthelp90.info
-frugal-shop.com
-hostoolieh.ipq.co
-security-help-verify.com
-pgsssecmdkdmcse.co.vu
-kujikolagerdasuhgneewwwabf.co.vu
-1545684infoupadate.co.vu
-pgcnfmrdataaccount.co.vu
-settingssecuritycomunity.co.vu
-syncvalidation.net
-gropsxviralz8.co.vu
-pubgmo.otzo.com
-signup-hypesquad-team.com
-dicsord-auction.com
-register-official-hype.com
-register-hype-official.com
-hypeteams-signup.com
-forms-to-hypeteams.com
-hypesquad-list.com
-bmcllcuma.com
-helpcenterobjection.ml
-et-jewelry.com
-noisypro.com
-rbcitiesholdings.com
-videomytube.ga
-graduated-garbage-nano-u.trycloudflare.com
-igo-jop.com
-sofibaek.igo-jop.com
-parkprasowy.awesomeerictech.com
-account.xn--googe-wsa.com
-raketun.uot-jp.com
-www.i-neb.net
-dry-glade-07c8.caroline.workers.dev
-shopdrm.co.in
-kronbergdesign.se
-www.aplock.net
-pp-ref7373.com
-moontoncollectskin.gamename.net
-aroskywalker.info
-korean-chicken-welfare-lanes.trycloudflare.com
-ezpaye.co.uk
-glade-d26a.celine-malbet5193.workers.dev
-promanagegroup.com
-perfect-trail.surge.sh
-www.findmy-lphone.in
-arwebcloud-notification.fkfjrk.repl.co
-www.meta-main.com
-register-hype-team.com
-added-split-reservation-illness.trycloudflare.com
-uspsfastdeliveryline.com
-wellsidconfirm.com
-facemebook.com
-pubgturney.tk
-steamshensu.cn
-missiewatts.com
-forms-hype-team.com
-forms-hype-teams.com
-forms-hypesquad-teams.com
-rightwayrefinish.com
-gohomefag.com
-rentbeachgames.com
-newportppty.com
-kkjconsult.com
-bv3.impact11.xyz
-himuniversity.com
-youngblackamericandoctors.com
-rakvten-card.co.ip.eosxpeb.tk
-gathered-surrey-developments-evidence.trycloudflare.com
-mybevco.com
-seminoleheightshome.com
-ccllarrecord.com
-ramazanaozel.tk
-kkjcloud.org
-enrollments360.net
-themensclubonline.com
-hotelrosariopb.com
-mrmadvisors.com
-accident.plateformes-authentiques.com
-cope-perfect-lil-leave.trycloudflare.com
-api.deliveries.africa
-www.secure-carte-vitale-connexion.com
-agualyder.com
-dsblk.com
-xn--1nr.cc
-webin17.xyz
-simworldsports.com
-lyanjherico.rewardsxuit.cyou
-xzrt-pntd.tk
-spinposeidon.com
-invention-extensions-hitachi-trademarks.trycloudflare.com
-ibxkeybank.viewdns.net
-mtb3-unrecognized.web.app
-michellesiblock.com
-shopepaldalre-us.com
-www.nssnnssmeriuca.com
-deposit-lbc.info
-microsoft-tw.com
-newspubgm.net
-dotcompackza.ga
-linkgrupokepchikaviral.001www.com
-claimmfrrerealnew9s.co.vu
-grupbokepviral2022.001www.com
-santander.co.uk.app-review.guide
-enrollments360.com
-www.walletsconn.tech
-otaknyamacet.com
-rakoten-cord.co.ip.eosxpeb.tk
-methamaksupdate.com
-bamsoficphsa.com
-sadarihatis.co.vu
-signup-hype-teams.com
-apple.com-access.online
-blockchainsecure.dns.army
-www.inc-support.co
-www.pro-dataa.xyz
-buywithvrs.com
-localpostoffice.co.uk
-ht1rcu.cmep-ci.com

File diff suppressed because it is too large
+ 213 - 221
yoroi_suspicious_level2.dns


Some files were not shown because too many files changed in this diff