1
0
root vor 3 Jahren
Ursprung
Commit
d866eca46a
4 geänderte Dateien mit 2508 neuen und 2129 gelöschten Zeilen
  1. 813 534
      yoroi_malware_level1.dns
  2. 1252 1136
      yoroi_malware_level2.dns
  3. 136 221
      yoroi_suspicious_level1.dns
  4. 307 238
      yoroi_suspicious_level2.dns

Datei-Diff unterdrückt, da er zu groß ist
+ 813 - 534
yoroi_malware_level1.dns


Datei-Diff unterdrückt, da er zu groß ist
+ 1252 - 1136
yoroi_malware_level2.dns


+ 136 - 221
yoroi_suspicious_level1.dns

@@ -9,6 +9,140 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+sparkling-sound-6058.on.fleek.co
+unfitsolidparticle.vroomlimmer.repl.co
+south-incandescent-camera.glitch.me
+www.aesoecon-asoamecosmne.jyjovgw.md.ci
+www.metalivesconfrim.ga
+www.metalives-help.cf
+www.metalives-help.ga
+www.metalivesconfrim.gq
+www.igmetalives.tk
+ff-mermber-garena.tk
+playwolflegacy.com
+redelivery-online-today.com
+looksrare.is
+mobat24475.temp.swtest.ru
+fidelity-us.com
+officialwedsite1.blogspot.lu
+officialwedsite1.blogspot.cl
+officialwedsite1.blogspot.com.by
+giveaway.judikphysio.clinic
+business-page-appeal-18276-712.web.app
+officialwedsite1.blogspot.si
+officialwedsite1.blogspot.co.ke
+nameless-mode-0173.on.fleek.co
+webin24.xyz
+app-personavirtual.live
+www.junhodotk.xyz
+anulaciones-bbva.info
+misty-math-2264.on.fleek.co
+3426nw6sb4stg5e67m.gq
+3426nw6sb4stg5e67m.ga
+ecso.ubnet.ch
+instagramdestek.org
+bullmoosetube.expodiansports.com
+focusing-opinions-boys-tahoe.trycloudflare.com
+business-page-appeal-18276-521.web.app
+web7974.web07.bero-webspace.de
+confirm-logons-request.com
+thebrickstheatre.com
+ahhreal.com
+trace-explains-fish-told.trycloudflare.com
+www-pancakeswap-finance.org
+clearascentllc.com
+security-access-logon.com
+stearncomrnunity.ml
+au-an.xyz
+ressdominokoint.dynamic-dns.net
+www.myjacseob.222eee.co
+lighter-married-disk-marks.trycloudflare.com
+seriouspunybrains.docdoc232.repl.co
+yellow-mouse-4195.on.fleek.co
+pages901.pages.dev
+cucine-cucine.org
+safety-instagram.com
+www.metamask.homes
+still-cake-7201.on.fleek.co
+app-decline-payments-support.com
+request-unauthorised-login.com
+office-invauth13425.zeknotarzo.workers.dev
+faturamensinx.shop
+ondrivesharedpoint.on.fleek.co
+frosty-salad-1116.on.fleek.co
+eurocard-kontrolere.com
+hyperconsultasten.com
+lebanonautism.com
+metamask.wordsverification-mask.club
+app-pancakeswap.site
+app-decline-payment-support.com
+secondopinionhealing.com
+quotatonnf.web.app
+rochesterspeech.com
+metamaskext.info
+rakoten-account.co.ip.teadsdr.tk
+www.icloud.info-arg.live
+www.macsrssoamsd.ncqbntu.md.ci
+www.maeascorced.hoqoebl.md.ci
+www.maeascorced.mkjkwqx.md.ci
+www.maeascorced.cwllads.md.ci
+www.myjacseob.hxbdeos.md.ci
+www.myjacseob.tbpclkc.md.ci
+www.myjacseob.slzyini.md.ci
+www.myjacseob.rwmlmke.md.ci
+www.myjacssoeb.mpoblrm.md.ci
+citi-activty.com
+sportskeeda.on.fleek.co
+devalleyz.org
+acc.eligibility.2dadc428c7a061f729458acc01304c8f.ml
+www.acc.eligibility.2dadc428c7a061f729458acc01304c8f.ml
+complete-removal.app
+acc.eligibility.565ceeedeaf636bc00b97844fbf986d9.ml
+help.wenlortemon.gq
+small-queen-3900.on.fleek.co
+www.help.wenlortemon.gq
+seminars-household-components-nascar.trycloudflare.com
+chilzbimcell.com
+rakoten-account.co.ip.gaffxjk.cf
+www.connexion-infosecu.fr
+20347-3415.s1.webspace.re
+instagramsupport.in
+thedirectoryoftheturf.com
+bgmieventsz.shop
+metamask.io-yznx.xyz
+facebook-messenger.tiiny.site
+offa-8a87d.web.app
+shared-project.docs-coanyouamp.workers.dev
+v1157619.hosted-by-vdsina.ru
+steamactivator.tk
+rakvten-card.co.ip.gaffxjk.gq
+client-servicesupportusps.panders.tv
+summer-snow-8561.on.fleek.co
+billowing-bush-9975.on.fleek.co
+capitaloneshoppingcampaign.com
+gentle-sound-7556.on.fleek.co
+portal.activeasphalt.workers.dev
+eventnewmlbb22.ml
+opennft.live
+phonyenergeticstartup.bastorminate.repl.co
+grubpemersatubangsa.co.vu
+achat.paieconseiletsolutions.fr
+shrill-dawn-d277.samwardtruck.workers.dev
+rakoten-update.co.ip.gaffxjk.gq
+rakoten-account.co.ip.gaffxjk.gq
+chiefmonumentalpackage.life9000.repl.co
+bisaffues.com
+9355766.com
+arklagutters.com
+asianclub77.16-b.it
+bmcellyesill.com
+online-banking-santan-uk.web.app
+online-portal-support-apple.com
+rakoten-update.co.ip.gaffxjk.ml
+rakoten-update.co.ip.saplrqs.gq
+amzsystem.de
+maria-anfordern.de
+www.office365.olsatco.com
 icloud-photoshare.online
 www.aesoecon-asoamecosmne.xhxceua.md.ci
 www.aesoecon-asoamecosmne.tnmltgc.md.ci
@@ -140,15 +274,9 @@ solucoesdalu.com
 www.solucoesdalu.com
 play0gift.co
 www.aesoecon-asoamecosmne.hsrbvtg.md.ci
-9355766.com
-metamask.cirii.co
-metamask.bz
-ucfull.com
 girolep772.temp.swtest.ru
-maria-anfordern.de
 bancor-acceso-cliente.com
 viptr2.com
-rochesterspeech.com
 www.usastockshots.com
 www.opensee1.com
 20347-3407.s2.webspace.re
@@ -204,7 +332,6 @@ www.aesocon-asoemsnacosmn.jyjovgw.md.ci
 www.aesoecon-asoamecosmne.mmrmzsr.md.ci
 www.aesocon-asoemsnacosmn.vntldxz.md.ci
 www.aesoecon-asoamecosmne.tcldpmy.md.ci
-bmcellyesill.com
 www.proffile-jessyca-jackson.club
 vincilafinale.com
 daouees.com
@@ -236,10 +363,6 @@ dicsord-one.ru
 www.aesoecon-asoamecosmne.cpqvyri.md.ci
 www.aesocon-asoemsnacosmn.iiunkvb.md.ci
 vgalc7l2g8jumm1lier6qht8f1pcmkap08gm32blaifmq24se44333g.siasky.net
-michealmasonry.com
-online-banking-santan-uk.web.app
-www.office365.olsatco.com
-www.pubgspin10.dubya.net
 www2.aenosnen.icu
 www2.aeno-szen.icu
 www2.aenocnen.icu
@@ -247,7 +370,6 @@ www2.epos-card.co.jp.hvdbuqb.cn
 www2.epos-card.co.jp.hiwjku.cn
 dirt-azure-jersey.glitch.me
 fbeventphotos107.nhely.hu
-quotatonnf.web.app
 rakvten-card.co.ip.saplrqs.gq
 rakvten-card.co.ip.teadsdr.gq
 rakvten-card.co.ip.teadsdr.ml
@@ -307,7 +429,6 @@ www.vevivsvei.asdfmzv.ne.pw
 wpsservices.creatorlink.net
 quafreefirevip.gearena.vn
 www.maeascorced.juiojnz.md.ci
-asianclub77.16-b.it
 www.maeascorced.jyleiji.md.ci
 www.vevivsvei.ajtzgin.md.ci
 wellsfargobank.grupomultimediasac.com
@@ -360,17 +481,13 @@ www.maeascorced.mvjewgn.md.ci
 www.paypal.monpaiementsecure.com
 www.maeascorced.vdrxrpp.ne.pw
 www.maeascorced.nqycznm.md.ci
-www.maeascorced.mkjkwqx.md.ci
 cigf-237a1.web.app
 www.vevivsvei.mfpieav.md.ci
 www.maeascorced.asdfmzv.ne.pw
 www.maeascorced.qlpojlm.ne.pw
 dkb-sicherheit.com
 www.maeascorced.rbiznwf.md.ci
-www.maeascorced.hoqoebl.md.ci
-photoandvideo234.webstriple.com
 pubgspin20.dubya.net
-pubgspin10.dubya.net
 www.myjacseob.ldgtdaj.md.ci
 www.myjacseob.grhngal.md.ci
 www.myjacseob.bxgpmdp.md.ci
@@ -423,7 +540,6 @@ www.nexiclientforyou.com
 jevalideachat.com
 steamcommunity-pubg.cn
 xbrclem.cf
-rakoten-update.co.ip.gaffxjk.ml
 access-requested-login.com
 vsbjsjhvmx.temp.swtest.ru
 www.myjacseob.rbiznwf.md.ci
@@ -483,8 +599,6 @@ www.macsrssoamsd.fmagpnl.ne.pw
 www.macsrssoamsd.ldgtdaj.md.ci
 www.maeascorced.sxbiiro.ne.pw
 www.macsrssoamsd.swrhmcg.md.ci
-www.myjacseob.rwmlmke.md.ci
-www.maeascorced.cwllads.md.ci
 www.vevivsvei.juiojnz.md.ci
 www.myjacseob.ifweatu.ne.pw
 www.macsrssoamsd.lgihkoi.ne.pw
@@ -507,7 +621,6 @@ www.vcvevise.ezudtnx.ne.pw
 www.macsrssoamsd.tinjmpg.ne.pw
 www.myjacssoeb.csithav.ne.pw
 www.vcvevise.wwgpoap.md.ci
-www.myjacssoeb.mpoblrm.md.ci
 www.vcvevise.ncplcuv.ne.pw
 www.myjacssoeb.uinjuoz.ne.pw
 www.myjacssoeb.bujhhnd.ne.pw
@@ -523,16 +636,13 @@ vakifbankmobilgiris.com
 wwwnoticesus4k.hs-sites-eu1.com
 steamcommunutys.ru
 keepingsafe.live
-www.myjacseob.tbpclkc.md.ci
 www.myjacssoeb.grkbkzr.md.ci
 www.oglaszanieslowa.pl
-www.myjacseob.slzyini.md.ci
 www.myjacssoeb.mkuezwi.ne.pw
 www.myjacseob.eyvlmbz.ne.pw
 whats-app-clone--oreolad2.repl.co
 www.myjacssoeb.jyleiji.md.ci
 www.myjacseob.cmdrzja.md.ci
-www.myjacseob.hxbdeos.md.ci
 www.myjacssoeb.jprblgx.md.ci
 www.myjacssoeb.klfxerc.ne.pw
 www.myjacssoeb.loprxmi.ne.pw
@@ -567,7 +677,6 @@ www.macsrssoamsd.bglkalf.md.ci
 www.myjacssoeb.mkjkwqx.md.ci
 www.myjacssoeb.izkelum.md.ci
 app-payment.decline-help.com
-app-decline-payments-help.com
 securitycenter000002125463258.co.vu
 iopsun34mybg587wvm.ga
 officialwebsitegfr.blogspot.hr
@@ -609,7 +718,6 @@ hypeteams-official.com
 www.networkchainfix.com
 pagalbos.verify-activity.net
 selected-to-hypeteams.com
-www.icloud.info-arg.live
 secureddiscover.com
 wqeriomuyenurpm11.live
 divemarinendt.com
@@ -646,7 +754,6 @@ www.amazon.com.app8.in
 manage-signin-accntsas.com-iewotif.com
 mulsubs.org
 turnkeychoices.com
-competent-mestorf.104-154-188-57.plesk.page
 www.myjacssoeb.hpzgbzz.ne.pw
 magalu.shop
 thepancakeswap.com
@@ -707,7 +814,6 @@ www.macsrssoamsd.aqwibrn.ne.pw
 www.myjacseob.aqwibrn.ne.pw
 www.myjacseob.asdfmzv.ne.pw
 www.macsrssoamsd.huathmm.md.ci
-www.macsrssoamsd.ncqbntu.md.ci
 www.m416foolmytichshopfreee.xyz
 www.maeascorced.bvdpanp.md.ci
 bafybeiao7ok6ahmsoq3uoq5cf4ta44k7itbgwmkcic5dygobvw73wnmr64.ipfs.dweb.link
@@ -797,7 +903,6 @@ sitecdn01.hs-sites-eu1.com
 asianmember97.16-b.it
 rakvten-card.co.ip.xbrclem.ml
 looksrare.cfd
-noisy-credit-fee3.freeme0247.workers.dev
 contact8463110791.com
 alorica-vpn.com
 mfacebook.help-109475619015404.com
@@ -1025,8 +1130,6 @@ looksarar.org
 wallletconect.company
 official-form-hypesquad-events.com
 register-hypeteam-official.com
-videotiktosid097.001www.com
-rakoten-update.co.ip.saplrqs.gq
 sparkassen-risikomanagement.com
 offlcemicros0ft95478-0nlinedocument242964.office365-sharepointdoc.workers.dev
 aza.d366uy1x73dva4.amplifyapp.com
@@ -1035,7 +1138,6 @@ official57website.blogspot.ba
 www.metamaskimg.buzz
 invite-hype-teams.com
 official57website.blogspot.bg
-metamaskext.info
 postoffice.depot-35.com
 hsbcbank.clientswelcomeltd.com
 www.hsbcbank.clientswelcomeltd.com
@@ -1090,7 +1192,6 @@ mysupply-portal-asia-apple.mystore-support-apple.com
 www.mysupply-portal-asia-apple.mystore-support-apple.com
 tvpoki.hs-sites-eu1.com
 www.axieinfinity-connect-ronin.tronlink-connect.space
-online-portal-support-apple.com
 newtownnd.com
 www.metamaskwebs.net
 pimisor958.temp.swtest.ru
@@ -1099,7 +1200,6 @@ formulary-teams-hype.com
 yybya-7aaaa-aaaad-qcf4a-cai.ic0.app
 bafybeibrripg4ygrioyvehbob3sxicrezxzw52ejc3vtgp5p66mdjbryae.ipfs.nftstorage.link
 cmt-eintl.com
-bettina-ebay.de
 grup-viral-kenzy-terbaru-23.viiirallll.cf
 rakoten-account.co.ip.teadsdr.gq
 louitacc.xyz
@@ -1115,17 +1215,18 @@ steamcummunlty.ru
 yahoofake.duolingo.gq
 claimmlbbfreex.gamename.net
 blinzero.xyz
+wild-sound-3eab.cifiveb344.workers.dev
 www.blinzero.xyz
 matamask.xyz
 besetisoq.com
 www.mettamask-io.com
 rakvten-card.co.ip.teadsdr.tk
 rakoten-update.co.ip.teadsdr.tk
-rakoten-account.co.ip.teadsdr.tk
 ob34.ff.garenask.vn
 602553.com
 tutorial-skinml764.cf
 freemlbbclaim.gamename.net
+m.facebook.natashop.store
 noiresilk.com
 www.ingresosuper.com
 xn--aav-dma.com
@@ -1149,7 +1250,6 @@ iiywakffbl.cfolks.pl
 info.support.beautyschooldropout.co
 aave-staking.com
 sushisswap.app
-arklagutters.com
 styleco.be
 die-post-ch-8b852.radikalwinds.pt
 meeeghanteelo.diskstation.eu
@@ -1188,188 +1288,3 @@ joingrupp99.tk
 invite-teams-hypesquad.com
 groupzzssx-whstap8.cf
 53-web.info
-long-law-wireless-mariah.trycloudflare.com
-opensea-apps.com
-morning-frost-0258.on.fleek.co
-spring-leaf-1244.on.fleek.co
-app-pancake-swap.com
-accessprep.com
-rakoten-account.co.ip.uyllfkr.tk
-isluv356y8wop0ops9v358.ga
-maystugprade71.web.app
-iuyfrtuyi4cd67b.ga
-becusecurity.my-wan.de
-validatematrixnetwork.com
-isluv356y8wop0ops9v358.gq
-super-lab-0575.on.fleek.co
-cnfrmyourdataaccpgsrcvy.ga
-3500799.com
-tentacionstienda.com
-brigantisas.com
-samorachocolates.com
-restoreaccountaccess321.mefound.com
-yellow-feather-1585.on.fleek.co
-officematsolutions.co.za
-loksrare.site
-lucky-night-8249.on.fleek.co
-bennett-grows-hamburg-roberts.trycloudflare.com
-disc0rd-nitr0.com
-portal.organiseit.workers.dev
-mhzac-zaaaa-aaaad-qcgia-cai.ic0.app
-sync-dapp.net
-softfilesetup.pages.dev
-bra-popup4.com
-erui.cam
-app.payment-decline-help.com
-metamask.io.nasheedfm.com
-apply-hypesquad-beta.com
-myclubs889.16-b.it
-www.becusecurity.my-wan.de
-round-night-7222.on.fleek.co
-hypesquad-event-2022.com
-gndrssmax.com
-hype-invited.com
-cool-glade-0322.on.fleek.co
-oopensea.xyz
-die-post.ch.atauropartners.eu
-bafkreihwb3tnqo6eex2abqad7m5v7ajtntril6eoqduiijuubmecikf2ui.ipfs.nftstorage.link
-crimson-meadow-5023.on.fleek.co
-netflixes.cf
-ucxsa.com
-function-ethics-instrument-wings.trycloudflare.com
-metemasks.cc
-delinquentgamestudios.com
-freexgold.net
-wellsfargo-help.is-tourist.com
-sunburstcottage.com
-phoenix-suitable-gazette-fc.trycloudflare.com
-withmetamask.shop
-login-facebook.iphide.co
-api.dobox.com
-metamask2022.buzz
-www.manage-logon-requests.com
-onlinebanking.remove-new-app-addon.com
-nvidia-book-scanner-met.trycloudflare.com
-buecrg.dyn-vpn.de
-steamcommunityii.cn
-distracted-shockley.45-81-232-225.plesk.page
-securedwells27271.net
-hidden-star-6834.seed-payment.workers.dev
-becomesubbroker.com
-brindle-glaze-raccoon.glitch.me
-eventtopgame.com
-myplan-view.com
-spindiamond.001www.com
-grup-chika-virall2022.001www.com
-vkcc9vladimer.net.ru
-steamcommunityli.top
-mlcrosoft0fflce.myftp.org
-ripaton.jaysonstokes.com
-lcneighborhood-it.com
-whatsapp-chat-bokepxnxx.001www.com
-metamask.io.web7932.web07.bero-webspace.de
-metamask.pagevalid.in
-info.ozanom.com
-aibcustomer-care.com
-huntingtonbank.clientswelcomeltd.com
-vconformation.xyz
-axieuserservice.company
-walletappsolution.com
-bimmicell.com
-skinclaimfreenews.gamename.net
-walletencryptx.com
-dappsaccess-bot.net
-consulenza-area-webonline.com
-theworldsbestinternet.com
-alluring-prong-printer.glitch.me
-portale-identificazione.com
-pulsapaypal.co.id
-superviellebankingpersonas.com
-secured.dhbgvi4yvasdz.amplifyapp.com
-momentscoaching.com
-bimcellkrallar.com
-bdemcell.net
-marketgrowths.com
-xiaofei1.club
-claimskingets.gamename.net
-18tiktokriffa.mypi.co
-blue-brook-85db.seed-payment.workers.dev
-yeda-r.com
-facebook.com.ttcysuttlart1999.aylandirow.tmf.org.ru
-www.pubgspin12.dubya.net
-pablospotpie.com
-rakoten-account.co.ip.saplrqs.tk
-shared-private-doc.lmaprungkol.workers.dev
-rakoten-cord.co.ip.uyllfkr.ml
-bafybeigpgbaydnoteltxmi5kxfwfsnoeom44qacr3p5fmewcj5dux44qhq.ipfs.dweb.link
-die-post.ch.informaticarosendo.es
-apply-hypesquadrecruit.com
-hype-events-2022.com
-invite-hypeevents-2022.com
-www.metamask.io.wallet-identification.rwatelier.com
-invite-hype-22.com
-www.pasizione-internet-sic.com
-www.segnal-db.com
-carden.shopeecs.com
-login.crabada.fun
-test-opus.com
-www.huntingtonbank.clientswelcomeltd.com
-sicur-area-web.com
-jhgfdghjklvbngh.weeblysite.com
-bimcellim-hizli-vakti.com
-hypercardernoshopten.com
-pontefi-area.com
-chika-hot-croott-viral.001www.com
-kqume-uqaaa-aaaad-qcg5a-cai.ic0.app
-rakoten-update.co.ip.uyllfkr.ml
-rakoten-account.co.ip.uyllfkr.ml
-sempapelcontadigital.com
-rakvten-card.co.ip.uyllfkr.ml
-subscribe-to-hypeteams.com
-upgradepage.cc
-amazo.co.jp.lucioleo.xyz
-salesforce-proxy.k8s.triluxds.com
-www.shop1237891.xyz
-25894117.hs-sites-eu1.com
-www.aggiornament.com
-www.trustwpay.site
-dappsoption.xyz
-www.integrals-dexs.net
-rakvten-card.co.ip.uyllfkr.tk
-3659193.com
-3656752.com
-abalone-powerful-neighbor.glitch.me
-hidden-boat-6614.on.fleek.co
-prod.d2qyfcrjtzqec5.amplifyapp.com
-rakoten-update.co.ip.hawzbsk.gq
-rakoten-cord.co.ip.hawzbsk.gq
-rakoten-account.co.ip.hawzbsk.gq
-rakvten-card.co.ip.hawzbsk.gq
-mudservice.com
-loginmtbx.web.app
-asianfree865.16-b.it
-favoriteclub41.16-b.it
-metsmask.2022.179-43-175-195.plesk.page
-boialertservice.live
-brow.vip
-objectnotifications.com
-servicn-ifications.com
-nificationsgood.com
-delivery-good.com
-amazon.co.jp.emzenadmincojp.club
-construcaocivilpelosa.com
-xxhuntmetamaskxxxx.draydns.de
-secureamerifirst.myddns.me
-form-metaservices.com
-stotfvvsru.temp.swtest.ru
-aq-confirm.ml
-paypal.proposal.quest
-my-ee-update.com
-pencakiswap.xyz
-dl-reason-paul-og.trycloudflare.com
-materials20.org
-aavee.net
-wypdek-dagmara.pl
-metamask.lv
-rakoten-cord.co.ip.uyllfkr.tk
-www.amazzn.macal.top

Datei-Diff unterdrückt, da er zu groß ist
+ 307 - 238
yoroi_suspicious_level2.dns


Einige Dateien werden nicht angezeigt, da zu viele Dateien in diesem Diff geändert wurden.