root 1 неделя назад
Родитель
Сommit
d45384517e
4 измененных файлов с 5759 добавлено и 5633 удалено
  1. 343 299
      yoroi_malware_level1.dns
  2. 4949 4949
      yoroi_malware_level2.dns
  3. 183 87
      yoroi_suspicious_level1.dns
  4. 284 298
      yoroi_suspicious_level2.dns

Разница между файлами не показана из-за своего большого размера
+ 343 - 299
yoroi_malware_level1.dns


Разница между файлами не показана из-за своего большого размера
+ 4949 - 4949
yoroi_malware_level2.dns


+ 183 - 87
yoroi_suspicious_level1.dns

@@ -9,48 +9,168 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+excel-documen-file.appwrite.network
+xdl-whatsapp.com
+yem-whatsapp.com
+wck-whatsapp.com
+verificarseguranca.online
+www.p365777.com
+www.fezjoane.com
+fezjoane.com
+4a4383d6-a4b1-417d-8ec3-07f9e120ccf9-00-igq30xpm21kb.worf.replit.dev
+1e11904f-1e30-438d-8c94-3b5a34df1f0d-00-200ovmjm7g7h8.worf.replit.dev
+www.sduality.cfd
+www.boltzmannbrain.cfd
+www.cocktailparty.cfd
+www.frbybitteamcin.vip
+bfxinvst.com
+logic168.com
+a87y.xyz
+moana188.com
+santstest.live
+adrenalin.win
+hghgj.icu
+komisi188.com
+salleryonlnejbhomesiiite.net
+ptfuturewebinarfrellanceeece.net
+sale-wvk.91boris.com
+m.fyqn9810la0y.com
+mpo707.com
+www.originalyugoservegod.im
+wap.fbaddadsbook.com
+instagram.williamzshih.com
+wachecks.xyz
+statut04-envoi.pro
+mdlr-perso5.pro
+mdlr-perso9.pro
+www.mdlr-perso5.pro
+mr33-transit.pro
+allegro.3288f2g0-32.sbs
+marketglobet99.pw
+qnbpromosyonburda.cfd
+gr.mycheckfanpages.sbs
+2025-2026giris.click
+server33wf.com
+immueble.us
+awazzcyzon.com
+musicsuae.icu
+purworejoku.putunesimbah.de
+tr.padisahbet-adresin.vip
+www.minion178-1.cc
+account05.partner-connect-marketing.com
+www.3436.greenfrienndlypaint.com
+0838288fh929procedure4allemployeemandatory08392928482.nassvsa.com
+www.josephsonjunction.cfd
+www.phononlaser.cfd
+www.syndromemeasurement.cfd
+fjiaobd.com
+www.kednezh.com
+www.moenaqbrw.com
+kednezh.com
+moenaqbrw.com
+www.fjiaobd.com
+locale-tri.com
+mydisney.meinkonto.com.de
+ellenorzes-netfilxhu.com
+www.locale-tri.com
+allegro.pl-oferta73951.cfd
+allegrolokalnie.06902.lat
+allegro.pl-oferta239452.sbs
+allegrolokalnie.pl-oferta73951.cfd
+allegrolokalnie.oferta638464623923763.sbs
+allegro.pl-oferta6482946.click
+allegro.pl-oferta6392638.click
+allegrolokalnie.pl-oferta6482946.click
+allegrolokalnie.pl-oferta6392638.click
+allegrolokalnie.smart-94842.cfd
+allegrolokalnie.pl-oferta7375936.click
+pagedattente.com
+instruction-suivis.com
+mrelaypickup.com
+allegrolokalnie.10278900.sbs
+allegro.pl-oferta819482.cfd
+allegrolokalnie.pl-oferta3153590.click
+allegro.pl-ogloszenia-firmowe-888232.click
+allegro.pl-oferta3153590.click
+allegro.oferta7655590.click
+allegrolokalnie.pl-ld0900700.cfd
+allegrolokalnie.pl-ld0900790.cfd
+allegrolokalnie.23492385523.cfd
+allegrolokalnie.pl-6002485.sbs
+allegro.pl-oferta6927193.click
+allegrolokalnie.oferta7655590.click
+allegrolokalnie.pl-oferta6927193.click
+allegrolokalnie.pl-oferta819482.cfd
+allegro.pzpo51251.cfd
+allegro.pl-oferta7375936.click
+allegro.x152989110.cyou
+abrbpay.com
+agricole-sms0621.com
+allegrolokainie.pl-591248129512.cyou
+allegrolokalnie.pl-oferta2508073.click
+allegrolokalnie.pl-73573684645zamowienie75477845e85789.sbs
 glad-circle-676416.framer.app
+prosperous-pattern-245063.framer.app
+allegrolokalnie.pl-83842344.lat
+allegrolokalnie.pl-43151528811929zamowienie91727228199o8172728.lat
+allegrolokalnie.pl-826262717256zamowienie7115627l782877.lat
+allegrolokalnie.pl-firmowe-94821.sbs
+allegrolokalnie.pl-65567546766zamowienie6535667735o7446633567.lat
+allegrolokalnie.pl-6002485.cfd
+bsivloqwp.com
+couverture-biometrie-sante.com
+ea0c2799-05b6-445f-b873-5bf327e10ceb-00-11pp7c9ksv5og.janeway.replit.dev
+fgjtkra.com
+juybqlm.com
+pagedinformation.com
+login.indabahealthandwellness.com
+allegrolokalnie.oferta131499-proponowane-dla-ciebie.sbs
+allegrolokalnie.oferta121459-proponowane-dla-ciebie.sbs
+allegrolokalnie.pl-oferta84794854.sbs
+allegrolokalnie.7547743864.sbs
+allegro.99r8328f230.sbs
+centre-biometrie-sante.com
+login.gregoireetmarion.com
+my-uphold-walts.created.app
+suivi-instruction-2026.com
+tyabjs.top
 mywellsconnect.com
-abrbpay.com
 www.bacroblox.store
 www.63393.xyz
 att.tyrrellanalytics.com
 sorteo-bmw.maketoprint.com
-prosperous-pattern-245063.framer.app
-allegro.pl-822718181826zamowienie272728m7162728.lat
 www.reddingpolicedept.com
 www.cnnsw.com
-login.gregoireetmarion.com
 www.lsmworks.com
-login.indabahealthandwellness.com
-moderatesalesmanen.lrchaju2024.com
 straightenconveni.liruo2024.com
+moderatesalesmanen.lrchaju2024.com
 scattergratefuln.liruocha2024.com
 allegro.pl-g05.cfd
-allegrolokalnie.pl-73573684645zamowienie75477845e85789.sbs
 allegro.pl-73573684645zamowienie75477845e85789.sbs
 allegro.pl-58791248.cyou
-allegrolokainie.pl-591248129512.cyou
 allegrolokalnie.pl-58791248.cyou
 847312-ledger.com
+allegro.pl-822718181826zamowienie272728m7162728.lat
 allegro.pl-oferta57723.click
-allegrolokalnie.pl-oferta2508073.click
+original-happen-900509.framer.app
+m.padisahabet2026.com
+mall-dey.91boris.com
+www.ehay-uk-login-secures-rcrrzwzs.name2brands.com
+account02.partner-connect-marketing.com
 member40.agency-partner-apply.com
 member43.agency-partner-apply.com
 exodushelpcenter.com
-allegrolokalnie.pl-83842344.lat
 werikcenter.online
 agricole-sms0521.com
-agricole-sms0621.com
 94050105.xyz
 wellsfrargo-server.joedesa.com
 connect.secure.wellsfrargo-server.joedesa.com
 garantiadecompra.com
 sigafreeflowdigital.it.com
 digitaldebito.com
-m.08a5157.com
 dotnotblock-pfwzl61nwt.edgeone.app
 applelocalizar.com
+m.08a5157.com
 ledger-security-online.com
 tr.ngsbahis-hemenboss.vip
 tr.galabet-2026-online.vip
@@ -61,69 +181,41 @@ galabetguncelgiris.com
 shopeedlzht.cc
 stalk-insta.info.rastreamento-entregas-oficial.org
 tr.galabet-rekorgiris.vip
-original-happen-900509.framer.app
 galabetguncel.com
-m.padisahabet2026.com
-mall-dey.91boris.com
-www.ehay-uk-login-secures-rcrrzwzs.name2brands.com
-tyabjs.top
-account02.partner-connect-marketing.com
-allegrolokalnie.oferta131499-proponowane-dla-ciebie.sbs
-generale-sms17.com
 plosrwalnamter.online
-allegrolokalnie.pl-43151528811929zamowienie91727228199o8172728.lat
-allegrolokalnie.oferta121459-proponowane-dla-ciebie.sbs
 allegro.pl-826262717256zamowienie7115627l782877.lat
 allegro.pl-43151528811929zamowienie91727228199o8172728.lat
-allegrolokalnie.pl-826262717256zamowienie7115627l782877.lat
-allegrolokalnie.pl-oferta84794854.sbs
-allegrolokalnie.7547743864.sbs
 mypurpleconnect.com
 www.juybqlm.com
 www.bsivloqwp.com
 www.centre-biometrie-sante.com
-juybqlm.com
-allegro.99r8328f230.sbs
-bsivloqwp.com
-centre-biometrie-sante.com
-allegrolokalnie.pl-firmowe-94821.sbs
-allegrolokalnie.pl-65567546766zamowienie6535667735o7446633567.lat
-suivi-instruction-2026.com
 www.suivi-instruction-2026.com
 allegrolokalnie.impls.sbs
-pagedinformation.com
-allegrolokalnie.pl-6002485.cfd
-my-uphold-walts.created.app
 www.pagedinformation.com
 www.fgjtkra.com
-fgjtkra.com
 www.couverture-biometrie-sante.com
-couverture-biometrie-sante.com
-barclays-easy.meinkundenbereich.org
+generale-sms17.com
 2641a5c4-12a4-4577-aa81-730fabb9ff5c-00-20wmleubp0mgw.picard.replit.dev
 40d63b49-fe70-4cdb-98f2-5a5183be202c-00-3n6n06v132hwl.picard.replit.dev
 3rfcu.group
-allegro.oferta965064pl.cfd
 allegrolokainie.pl-4981902470.sbs
-allegro.37761.cfd
-allegro.12739t71.sbs
-allegro.262627.pl
-allegro.oferta8735147pl.cfd
-allegrolokalnie.pl-82736357716156281zamowienie7162727y8262728.sbs
-allegrolokalnie.pl-6436346347462743743734643634.sbs
+allegrolokalnie.pl-ogloszenie987352167.sbs
 allegrolokalnie.pl-oferta6785920.lat
 allegrolokalnie.pl-oferta69362.cfd
+allegrolokalnie.pl-6436346347462743743734643634.sbs
 allegrolokalnie.g3ajs8jzad.sbs
 allegrolokalnie.pl-firmowe-4829.sbs
-allegrolokalnie.pl-92ow3m.cfd
+allegro.oferta965064pl.cfd
+allegro.262627.pl
+allegro.oferta8735147pl.cfd
 colsavnet-filx.com
-relaispickup17.com
 efinptintunnelirsgov.link
-allegrolokalnie.pl-ogloszenie987352167.sbs
-bet403.cc
-www1.bkcentral.online
-www.bet431.cc
-bet426.cc
+relaispickup17.com
+barclays-easy.meinkundenbereich.org
+allegrolokalnie.pl-82736357716156281zamowienie7162727y8262728.sbs
+allegro.37761.cfd
+allegro.12739t71.sbs
+allegrolokalnie.pl-92ow3m.cfd
 shopees-online.site
 www.mynew-project.x10.network
 rbfcvu.top
@@ -143,7 +235,11 @@ www.nucleay-ws.top
 wetransfer.appwrite.network
 f235e.xyz
 bet430.cc
+bet403.cc
+www1.bkcentral.online
 w65v.xyz
+bet426.cc
+www.bet431.cc
 gewerberegislter.de-antragsformular.com
 www.ephad-suivi.com
 www.info-suivi-mondial.com
@@ -155,7 +251,6 @@ allegro.pl-id73838392.sbs
 www.allegro.pl-4981902470.sbs
 www.allegrolokainie.pl-4981902470.sbs
 6cd1f2d2-2c73-4070-9e40-9a15f91cab19-00-2evect6l7wxt7.janeway.replit.dev
-allegrolokalnie.pl-917263682829zamowienie82727281f9262728.sbs
 allegrolokalnie.pl-id738283929.sbs
 artsy-taxonomy-582688.framer.app
 btinternethjjkkk.weeblysite.com
@@ -163,39 +258,39 @@ connect-sncf.net
 delightful-point-322947.framer.app
 effective-bookings-486180.framer.app
 exec3-webme-ktun2-bn.framer.website
-jumpy-methodologies-882270.framer.app
-lkjhfdsdfghjoiuytrertyw.framer.website
 massive-encounter-356813.framer.app
 particular-founders-665677.framer.app
 recruit-invite.com
 short-millions-408003.framer.app
 started-home.zapier.app
 tedious-beet-978789.framer.app
-xfinity-email-service-102915.weeblysite.com
 talented-listening-361596.framer.app
+xfinity-email-service-102915.weeblysite.com
+lkjhfdsdfghjoiuytrertyw.framer.website
+allegrolokalnie.pl-917263682829zamowienie82727281f9262728.sbs
+jumpy-methodologies-882270.framer.app
 accounts-25355.bubbleapps.io
 q58.ad5.mytemp.website
 u0333428.isp.regruhosting.ru
+digitaispro.store
+p207h.xyz
+s112f.xyz
 ghanapostgpsa.pics
 b47486.com
+x108g.xyz
 www.osie-whatsapp.hl.cn
 vr-reaktivierung.app
 bybitrade.com
 attassist-center.dailynewsupdate.online
 ts67811.com
 www.bet433.cc
-digitaispro.store
-p207h.xyz
-s112f.xyz
-x108g.xyz
-www.u0333428.isp.regruhosting.ru
-thegamehaus.com
 allegro.pl-oferta6482825.icu
 allegro.pl-id738283929.sbs
+www.u0333428.isp.regruhosting.ru
+thegamehaus.com
+64797d60-94fd-4385-8fd3-8498a40fe1cf-00-3fryz88hq2lkx.riker.replit.dev
 7dec9639-b949-45e2-9581-93223850397d-00-hwmb2gap300y.spock.replit.dev
 95a542b5-c4d0-487f-95d6-01f77811349f-00-h5277fwuyoho.riker.replit.dev
-9c478f88-3519-4d20-a4b1-f7bc89d94adc-00-3cfttr0fvx1ft.riker.replit.dev
-9c75c5a0-77d0-4287-9a52-6e83fe9d11fc-00-291j116g1egbi.riker.replit.dev
 b315d6df-3da2-4b93-bc0f-537fe12deb09-00-1nqi18mqrvoxo.worf.replit.dev
 bisque-hands-888029.framer.app
 complex-path-586888.framer.app
@@ -204,18 +299,32 @@ eb84f314-e8b4-4a81-a16a-5b8415ae9ab7-00-2xqz63vny9gdl.riker.replit.dev
 favorite-result-798368.framer.app
 full-circle-607510.framer.app
 grey-brand-869308.framer.app
+high-instance-167244.framer.app
 ineffable-vacation-367899.framer.app
 joyous-course-233115.framer.app
 poised-haggis-013894.framer.app
 relieved-software-706324.framer.app
 xmission-webmail.weeblysite.com
-64797d60-94fd-4385-8fd3-8498a40fe1cf-00-3fryz88hq2lkx.riker.replit.dev
-high-instance-167244.framer.app
+9c75c5a0-77d0-4287-9a52-6e83fe9d11fc-00-291j116g1egbi.riker.replit.dev
+9c478f88-3519-4d20-a4b1-f7bc89d94adc-00-3cfttr0fvx1ft.riker.replit.dev
 69fc5388-670d-4c88-8908-afdb2f107291-00-262hqjqycxqhv.picard.replit.dev
 distinct-plans-399313.framer.app
 oxico.blogdns.com
 326a8eb8-4983-45a9-850d-7684b4fde14b-00-2r2poq9hy00ir.worf.replit.dev
+voudet.com
+www.facebookstartopup.info
+stylebourg.com
+member18.partner-connect-marketing.com
+www.streamcami.net
+kukuransipitik.anakembok.de.116-193-191-4.cpanel.site
+facedook.services
+www.kukuransipitik.anakembok.de.116-193-191-4.cpanel.site
+malmekwps.buras.biz.id
+bitvovip.vip
+inter1.haynsboone.com
+fabkwads.club
 6csgnd.ccsng.com
+onedrivelmcro-sharedpointers2026.bolt.host
 dvo-a.com
 bybmarket.xyz
 nexmunatt.com
@@ -230,22 +339,9 @@ dvo-us.com
 info-signere-digitilsynet.com
 owasxwheks-mph9pg.fly.dev
 app-pancakeswap.to
-voudet.com
-www.facebookstartopup.info
-stylebourg.com
-member18.partner-connect-marketing.com
-www.streamcami.net
-kukuransipitik.anakembok.de.116-193-191-4.cpanel.site
-facedook.services
-www.kukuransipitik.anakembok.de.116-193-191-4.cpanel.site
-malmekwps.buras.biz.id
-bitvovip.vip
-inter1.haynsboone.com
-fabkwads.club
-onedrivelmcro-sharedpointers2026.bolt.host
+d7d48e11-35ad-4806-b220-e15dacb9ee16-00-2oavpvtd2rl9y.janeway.replit.dev
 19f58955-0d72-401a-98fa-5315104825f2-00-33iefp7ze55tp.worf.replit.dev
 8da87598-ea8a-4cb9-8e4b-985045c9e6ea-00-22kfspdv1yj1.riker.replit.dev
-d7d48e11-35ad-4806-b220-e15dacb9ee16-00-2oavpvtd2rl9y.janeway.replit.dev
 mon-renouvellement-securipass.com
 feiwohs.com
 whatscvpp.top
@@ -253,15 +349,15 @@ whatscvpp.top
 www.h103c.xyz
 b251j.xyz
 a85p.xyz
+pedagionlinedigital.com
 www.zktwsqwzub.my
 shop.otkhi.com
 ardimasnoedi.lokmanelporso.com
 www.betnett.sbs
 www.g87g.xyz
+www.estxkmiego.my
 shop.cdxtkp.com
 www.qruryoykgj.sbs
-pedagionlinedigital.com
-www.estxkmiego.my
 charliemanarix-facebook-login-clone-spy-edition.static.hf.space
 online-skysports.com
 www.mon-renouvellement-securipass.com
@@ -270,17 +366,17 @@ careful-store-123425.framer.app
 comfortable-info-003123.framer.app
 favorable-innovation-617006.framer.app
 inventive-psychology-650553.framer.app
+loud-one-120099.framer.app
 miedcozimramermidcoweb629220.framer.website
 numerous-days-399753.framer.app
-salmon-charts-455829.framer.app
 smooth-research-204306.framer.app
+silent-consistency-323450.framer.app
 spectrum-105814.weeblysite.com
-spicy-fade-313814.framer.app
 stale-persimmon-541650.framer.app
-submit-now-for-request-here.surge.sh
 proceed839rwucj.framer.wiki
-loud-one-120099.framer.app
-silent-consistency-323450.framer.app
+salmon-charts-455829.framer.app
+spicy-fade-313814.framer.app
+submit-now-for-request-here.surge.sh
 allegro.pl4522423.cyou
 homesingrandprairie.com
 www.kimlik-ege-edu.serv00.net

Разница между файлами не показана из-за своего большого размера
+ 284 - 298
yoroi_suspicious_level2.dns


Некоторые файлы не были показаны из-за большого количества измененных файлов