root 3 years ago
parent
commit
f4893052d6
4 changed files with 1840 additions and 1703 deletions
  1. 885 806
      yoroi_malware_level1.dns
  2. 471 459
      yoroi_malware_level2.dns
  3. 237 190
      yoroi_suspicious_level1.dns
  4. 247 248
      yoroi_suspicious_level2.dns

File diff suppressed because it is too large
+ 885 - 806
yoroi_malware_level1.dns


File diff suppressed because it is too large
+ 471 - 459
yoroi_malware_level2.dns


+ 237 - 190
yoroi_suspicious_level1.dns

@@ -9,6 +9,240 @@
 # Category        : Suspicious
 # Confidence      : 10
 #
+i-ask332.dga.jp
+metamaskwallett.com
+theblazingcenterauthverificationloginaspx.diskstation.org
+webartel.net
+catbanking-b4927.web.app
+caravanelnoorloginaspxauthverification.diskstation.org
+pinterestloginaspxalsska.diskstation.org
+theglobeandmailauthverification.diskstation.org
+geratae.faertunuasiolanurageramu.link
+citi.ctcustomeralert.com
+cortanaassistant.com
+sportv2-promo.ru
+pagcomfirmidentitty.gq
+ddsignn.com
+alkarageets.org
+tiffanykitoure.com
+decentralizeddapps.com
+wl56a-3iaaa-aaaad-qcdca-cai.raw.ic0.app
+centraldevendasbmg.com
+rakutensg.cn
+dpd.reschedulemypackage.com
+confirmyouraccount2022.co.vu
+dkb-banking.erp.ibn-jebreen.com
+prorejectattack.me
+53-login.digital
+fs.patrickm6.cyou
+supervile-personas.com
+9appsfastdownload.info
+www.1secureloginverify0.xyz
+msappy.com
+michelleryanllc.com
+lidance.net
+attsupport.co.vu
+amazom.co.ip.5hrq8szu.com
+comprasno06.xyz
+mjmeekhof.com
+regions-secure.com
+supports-chat-help.com
+shared.protection-files.workers.dev
+confirm.santander.device84.com
+memory.ezyro.com
+confirm.santander.device48.com
+looksrarex.org
+www.u11572p133847.web0147.zxcs-klant.nl
+datachainwallets.xyz
+verify-transaction-payments-help.com
+hypesquad-official-exam.com
+18gdkvcronde.gq
+win11install.com
+push-secure.online
+u11572p133847.web0147.zxcs-klant.nl
+semurtelenom10ls.com
+holy-sky-7325.on.fleek.co
+secure-amelie.org
+pubggifts.ml
+aykutcaliskan.com
+webspeedway.com
+bluechilligames.co.uk
+cn-metamask.co
+morfemcool.com
+portale-accesso.me
+uctrue.com
+rockituk.co.uk
+loveshalo.com
+veryvenga.co.uk
+wellsfargochecking2.authorizecenter.workers.dev
+www.amazon-tax.com
+ig-badgeapplication-portal.ml
+www.fbze-online.com
+realty41izmit.com
+katlineboutique91.com
+surabayalawyer.com
+www.apps-sync.org
+green-island-0756cae10.1.azurestaticapps.net
+www.icloud.find-device.co.in
+grubviraltiktok2022.co.vu
+access-ckh.pages.dev
+gbenmoto-1e187.web.app
+mainnetauth.live
+danicortez.com
+internalvareisgodois.web.app
+pengikut-gratis.com
+sportbettingpromotions.com
+theapps.datapps.xyz
+evantrck.com
+hospitablesteelbluebackground.hamp22.repl.co
+mainnet-crosschaindefi.com
+mayefc.com
+metask.world
+nicebetgold.com
+pancakeswaps.org
+secret-box.xyz
+scure0-login-suncoast-creditunion.authorizeddns.us
+www3.smbs-carud.icu
+forms-from-hypesquad-teams.com
+www.mydefiasset.com
+zobaczteraz00001fama.awesomeerictech.com
+www.integraz-web-alt.com
+zobaczteraz00kamery24prostewiesci.awesomeerictech.com
+shy-mud-6542.on.fleek.co
+lokalnienews.awesomeerictech.com
+sign-up-hypeteams.com
+singup-for-hypesquad.com
+log-in-acess-beta.com
+labornyveri.com
+www.myemailssettings.com
+login.moderationdc.repl.co
+www.updatingmyopensea.com
+rakvten-card.co.ip.sozocqr.ml
+exam-hypesquad-new.com
+integration-on-hypesquad.com
+ucspin0.dubya.net
+www.ucspin0.dubya.net
+www.certifi-compl.com
+aibsecuritysupport.com
+francephotos.webstriple.com
+login-microsoftonline.fiorettl.com
+www.annazocon.xyz
+bgmixevent.xyz
+wanamakersecuremessagingonline.on.fleek.co
+starbusinessconsultants.com
+codashopfreeth22.gq
+quadrado.fr
+www.s.smbscrzuad.icu
+www.c.smbsnaewrad.icu
+fuckaddicts.com
+www.c.aeno-svsn.icu
+historic-automotive-drunk-inf.trycloudflare.com
+steep-brook-7620.on.fleek.co
+www.faturadigitais.com
+misty-glade-8845.on.fleek.co
+www.opensenas.com
+www.s.epoecsed.icu
+logxxmxt.web.app
+www.s.epoevsed.icu
+www.s.epoesaed.icu
+www.nft-sync.xyz
+tight-butterfly-2737.on.fleek.co
+steep-violet-8230.on.fleek.co
+muddy-sun-3955.on.fleek.co
+www1.aenoeaan.icu
+floral-sound-7829.on.fleek.co
+www1.aenoaaen.icu
+snowy-brook-6802.on.fleek.co
+www1.aenoaeen.icu
+777protokol.awesomeerictech.com
+cxvolwwgane.ga
+www2.aenoaoon.icu
+molmijaml5.temp.swtest.ru
+981726.kevinallanpetss.com
+pubgevents13.com
+walletrestorations.in
+solucoesdigital58.com
+donovandesign.net
+spectrumaerials.com
+jewelryws.com
+casamundomobili.com
+thisadvomom.com
+skyband.biz
+app-transaction-payments-help.com
+ikaunbaja.org
+sitedemo.somocyz.xyz
+chosenforbeta-apply.com
+iatrogirl.org
+breathelifeproductions.org
+withered-waterfall-9408.on.fleek.co
+www.poilld.fr
+rtytyrtry.easy.co
+apps.neffllix.workers.dev
+treasuredpicsphotography.com
+solucioneselectricassantander.com
+www.sloto4.com
+www.seguimentoskzmaxultra.online
+helpmetaserviices.com
+index.ticorentacar.com
+pagesecures.co.vu
+register-to-hypeteam.com
+nontonterbaru2020zz.net
+avoidcorona-virus.com
+certifiedrealestatepr.com
+rakoten-update.co.ip.sozocqr.ml
+themagpieknitter.com
+aibauth.com
+tlyuklemebm.tk
+oponsoe.com
+signup-live-com.office365.apps.maxsolutions.com.au
+www.vwzhnntem.cn
+sweet-recipe-2407.on.fleek.co
+rakoten-account.co.ip.sozocqr.ml
+forms-on-hypeteams.com
+appaaave.com
+amazonjp.de
+xzgroubterbaru.co.vu
+red-mouse-4414.on.fleek.co
+win11-serv4.com
+gropzviralss8.co.vu
+zenith-sepia-guan.glitch.me
+xn--pensea-2wa.net
+lilac-sweet-sodalite.glitch.me
+aggiorna-sistema-app-clienti.online
+www.aggiorna-sistema-app-clienti.online
+mellowcheerfulvirtualmemory.vastroomwin.repl.co
+www.userinquiryallrequests.toh.info
+gathered-ga-tablets-livestock.trycloudflare.com
+royelmails.com
+payment-refund001.on.fleek.co
+defiauthsync.live
+instant-meta-mask-active-nelify.live
+bimcellimsaysem.com
+bmcelliixx.com
+www.bimcellasw.com
+bimcellasw.com
+apply-on-hypeteams.com
+bimcxell.gq
+bimcellcinizzz.tk
+wells-fargo-verify-support27.com
+bmcellsiznlee.com
+barnesandnoblerloginaspxauthverification.diskstation.org
+groupswhatsappx18.co.vu
+ogxmax.xyz
+asdf.myds.me
+lxgmxt.web.app
+desbloqueio-conta.top
+business-page-appeal-1960-1268.web.app
+securecharlesschwab.serveirc.com
+anazoh.co.ip.7nauzakv3w.xyz
+930180.kevinallanpetss.com
+rerecovery.co.vu
+miicsorft.xyz
+pancakeswap-app.life
+business-page-appeal-128976891.web.app
+jambaraja.co.vu
+www.mhlwi.cc
+www.s.mstaevoun.icu
 artssitter.com
 coolgirlalert.com
 eatserioustaco.com
@@ -23,7 +257,6 @@ theweedfuckers.com
 airdrop-pancakeswap.tech
 issamove.net
 hatelfantasystar.com
-business-page-appeal-128976891.web.app
 hospicats.com
 alfasuperstore.com
 headwatersprayernetwork.org
@@ -42,7 +275,6 @@ asambrotherswallpaper.com
 toplessllc.com
 blackheartoutfitters.com
 thehousephone.com
-mainnet-crosschaindefi.com
 becauseilovehouses.net
 www.claim.fire-regalos.tk
 rachelkertz.com
@@ -53,7 +285,6 @@ rakoten.sozocqr.ga
 rakoten-account.sozocqr.ga
 rakvten-card.co.ip.sozocqr.ga
 5starfirm.com
-evantrck.com
 account987161xxxxhelpcenter.tk
 www.yamaxunz.com
 delicesegypte291021.be
@@ -71,6 +302,7 @@ commonsenseconversations.life
 aperotimes.com
 pubgmxtesla.com
 handymanfreeze.com
+milmantenimientos.es
 weareboss.co.uk
 cscscscs223.hostfree.pw
 paperrzclothing.com
@@ -93,24 +325,12 @@ grup-whatsapp-viral.kelelawarcyberhost.xyz
 steam-glftcard.com
 www.my.commbank.au.idwqw.com
 x-suitfree4.xyz
-gamepi.win
-hospitablesteelbluebackground.hamp22.repl.co
-knowwearkids.com
-metask.world
-sportbettingpromotions.com
 barclays-london.com
 bmcimcell.com
 campaignpodium.com
-internalvareisgodois.web.app
-jambaraja.co.vu
-pancakeswaps.org
-pengikut-gratis.com
 stinkybutton.com
-theapps.datapps.xyz
 track.localpostoffice.co.uk
 twincho.web.app
-www.m.mstaceoun.icu
-www.mhlwi.cc
 onlinesecuremessagepdfservice.on.fleek.co
 copyriighthelpmeta.com
 kayit.guzelalan.com
@@ -183,14 +403,10 @@ lemmensbloemen.be
 impulsotecnomedia.com
 caelen.be
 www.s.mstaexoun.icu
-www.s.mstaevoun.icu
 bcit.be
 www.c.mstaevoun.icu
 www.c.mstaexoun.icu
-secret-box.xyz
 bangkokwebc.com
-register-hypeteam.com
-scure0-login-suncoast-creditunion.authorizeddns.us
 my.meghahost.xyz
 kundendienst.club
 thestarvingrevolution.com
@@ -289,6 +505,7 @@ mipromomicole.com
 gcosenegal.com
 jitsrl.com
 5n3.co.uk
+tinhhuiz.com
 mantecaediciones.com
 pierrefrancois.fr
 uzikk.fr
@@ -361,8 +578,6 @@ minuslab.fr
 enp-co.top
 grupchikakiku.co.vu
 helpsconfrims122.co.vu
-mayefc.com
-nicebetgold.com
 man-traffic.com
 sellfast.fr
 meadowlakefurniture.com
@@ -417,8 +632,6 @@ idwqw.com
 servizioprivatimps.com
 pugliese-electric.com
 mbzal.cz
-connexion-mabanque-particulier.com
-mustemyki.com
 maiodigital009.com
 york-applied-c-louis.trycloudflare.com
 metamask-blockchain.xyz
@@ -529,7 +742,6 @@ secure3tomtb.servequake.com
 globekerer.com
 app.huntingtononline.workers.dev
 kebondalemlem.com
-gruppallvidio62.co.vu
 lokalniefakty.jornadascientificasqfb.com
 lookbemine.fr
 alyciagriffin.com
@@ -557,7 +769,6 @@ brianregandesign.com
 saligault.fr
 updateopensea.com
 proxiregie.fr
-www3.smbs-carud.icu
 zobaczteraz00kamerowaneecho.awesomeerictech.com
 idver.auterrvienl.fr
 eventreendemmlbbnew.ml
@@ -865,6 +1076,7 @@ erafonejaya2022.com
 grupbokepbocil.co.vu
 really-ambien-rugs-viewer.trycloudflare.com
 mpt05.tcp4.me
+asoares.pt
 exfy.xyz
 discord-hypemail.com
 pushhost.gq
@@ -906,7 +1118,6 @@ zablokovane-primabank.info
 btwebmailernchfjfm.weeblysite.com
 bimcell-xdtrwild.com
 bimcellipazarturkiyem.com
-register-hype-teams.com
 bimcellcumartesii.com
 bmcellkampanyalar.com
 bimcellvtn.com
@@ -1000,167 +1211,3 @@ latitudeplanning.co.nz
 web3-waletconnect.com
 colissimo-douane.fr
 vknews.org.ru
-academiasapiens.com
-meta.protection-pages40949989644786269072.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
-hospital-attempt-roots-mpegs.trycloudflare.com
-meta.protection-pages70373264842134653751.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
-meta.protection-pages19964343944432460037.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
-meta.protection-pages31929594028322184075.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
-app-hwvexnl0jd8koiyqx9w9.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
-aezebapp.com
-klaimchip1b.com
-secureserverlogin.app
-regionsecures.net
-appauthorization.com
-dft76.cf
-joingrubwhatsappviral.terbaru-id.xyz
-elated-elion.62-4-18-78.plesk.page
-www.moncompte-client.info
-contohbuateditsc.tk
-jop.amcojp.life
-instagram-supporttt.tk
-gerastui.huaweysoalhenryusagu.link
-aghuia.sortamiyabilingthuisawe.link
-https-autodiscover--mail.glitch.me
-meta.protection-pages67781555638037579561.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
-inf0.spitelretycurenhoaseratu.link
-www.s.mstacroun.icu
-secure-chase06.serveuser.com
-hypesquad-events-redeem.com
-pagerepairservice2022.co.vu
-discordsupporter.com
-material-collector.com
-poupock.com
-vk-prize.xyz
-naravie.me
-www.ucspin33.dubya.net
-creating-delivering-du-hometown.trycloudflare.com
-watermelon11071278.brizy.site
-client-space.serveftp.com
-claimmlbbskin.hicam.net
-zentroser.com
-vkiiski.net
-invite-beta-acess.app
-better-oregon-honduras-directory.trycloudflare.com
-freeskinmlbb.forumz.info
-bgmixsuit.m6materials.cyou
-www.polqyon-web.network
-otpofficial.com
-storesonuk.cummingsdesign.com
-happyspinmaterial.com
-apple-dft.live
-kickadsmedia.com
-inspire-train.com
-auchmeddan.net
-anmoznpaymentt.co.jp.sigin.club
-littlestarzgym.com
-mandhsnewfashion.com
-thesarkisians.net
-postoffice.schedule-deliveries.com
-wap.secur-my53bank.com
-hypesquad-from-selected.com
-c3sengineeringinc.com
-amazon-shopinglist-jp.xyz
-macadamangel.com
-volt-thoughts-assembly-towns.trycloudflare.com
-killlemes.com
-ensea.in
-wert.rgief.xyz
-pubg2022.exfy.xyz
-ucspin3.dubya.net
-grupbkpnew.co.vu
-kinderwagen-de.xyz
-gfegejdnd9jss.co.vu
-hypesquad-mail.com
-hh87wpg8no.temp.swtest.ru
-glacierfreerewards.getrewardfree.xyz
-www.nodevalidators.org
-www.glacierfreerewards.getrewardfree.xyz
-glacierfreerewards.xyz
-nturkiye-gov-tr-aidat-kontrol-sistemin.com
-funilicazi.com
-gcbcmn.org
-www2.aenoeuon.icu
-www2.aenoeusn.icu
-www2.aenoeusz.icu
-www.metanask.icu
-www.s.aenoeusn.icu
-www.s.aenoeuzn.icu
-williamsondesign.net
-staffinginnovations.org
-fastesmadsing.web.app
-www.s.aenoeusz.icu
-www2.aenoeuzn.icu
-psanda.co.za
-walletconnect.179-43-154-180.plesk.page
-www.s.aenoeuon.icu
-sistemadisicurezzampsiena.me
-precoveridentitysacuriritylogistic.co.vu
-meta.protection-pages10561210128468805037.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
-metsmas.com
-daasdasa.com
-sighel.at
-ludimila.net
-plelosersk.com
-5legare.com
-www.c.smbscrzuad.icu
-formulary-hypesquad-selected.com
-scourup.bar
-validate-metamask.io.home-page.in
-dsic1212.net
-metamask.twplink.com
-bertobos.spinofficial.cyou
-brianandhannah.net
-eastridgeproductions.com
-podpiskaboom.xyz
-mrna-jc-titles-build.trycloudflare.com
-matikohasuw.com
-digitaltokenswap.me
-samdal001.evadeetvous.com
-bafybeiedimy6na7fsik2kavkv3ryg5tc4vytimaibbpo242xcbr4g3andu.ipfs.dweb.link
-ficohsahonduras.usuariobm.repl.co
-atlantapromarketing.com
-antiphlshing-jp.life
-metamask.io.web7896.web07.bero-webspace.de
-control.aws8.top
-postoffice-redeliverysupport.com
-www.pdfinvoiceaccess.com
-checkupsecurityaccountscomunity.co.vu
-caifuguojitw.com
-ucbom.com
-demo-memorabilia-relatively-firewire.trycloudflare.com
-secure-chase3.serveuser.com
-pancakesvvappsi.com
-expedia-oct-word-sought.trycloudflare.com
-wvw.metamaskwalletverification.com
-opensea-tools.net
-connects-forms-events-moderators.com
-buffi.org
-offices7b6ce136c0aad19d8d3ef2d19e7d8b515989e136c0aad19d8d3ef2d1.officesgm.workers.dev
-uspps-toolssclient.com
-chatwhatsappviralxnx62.co.vu
-emanuelsalazar.com
-crrrfmedcopyrhgtaccaacc.co.vu
-communitystandardpagesandrepairservicereports.co.vu
-scrveaccntpgs.co.vu
-grupbokepgg882.co.vu
-grupchatterbaru2022.co.vu
-grupchika2022.co.vu
-servishop.net
-gregfrantz.org
-hypesquad-trial-selected.com
-pagecommunity2022.com
-hypesquad-new-forms.com
-amazon-w.xyz
-apzremnza.co.vu
-amazon-z.vip
-loginmicrosoft-online.on.fleek.co
-yangsempura.co.vu
-www.hosphinxi.com
-www.amzn888.com
-hkjhifsffshgjhb.web.app
-nahidharbourontario.com
-myworkingthing.h4bd9098ayhcsascvv.workers.dev
-meta.protection-pages10173785846628136964.m1ho2i7fmj-eqg35wpn23xn.p.runcloud.link
-facebooksecured.authorizeddns.org
-www.s.mstacaoun.icu

File diff suppressed because it is too large
+ 247 - 248
yoroi_suspicious_level2.dns


Some files were not shown because too many files changed in this diff