diff --git a/Alternate versions Anti-Malware List/AntiMalwareABP.txt b/Alternate versions Anti-Malware List/AntiMalwareABP.txt index 943264fc4..a19bfe123 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareABP.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareABP.txt @@ -1,6 +1,6 @@ [Adblock Plus 3.2] ! Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for AdBlock and Adblock Plus) -! Version: 20May2019v5-Beta +! Version: 03June2019v1-Beta ! Expires: 5 days ! Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. ! For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -22,9 +22,12 @@ ! These are topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent. ! Presumably fake loans ||.loan^ +||.agency^ ! πŸ”Ά Attempted removal of Google search result entries that lead to the above top-level domains (Advanced adblockers only) +! πŸ”Ά You know those ultra-fraudulent websites who clutter up Google searches, who have some seemingly random ".php?" values in their URLs? These entries should remove some of them. + ! πŸ”Ά For Google Mobile ! Note for Firefox on Android users: I strongly recommend the use of https://addons.mozilla.org/firefox/addon/google-search-fixer/ for use on Firefox for Android, thus the entries are written for the Chrome version of Google Mobile. @@ -105,4 +108,11 @@ drivereasy.com#?#.pakb-content li:-abp-has(a:-abp-contains(Update drivers with D ! https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/ drivereasy.com#?#.pakb-content p:-abp-contains(click Update All) +! πŸ”Ά Sites that fraudulently claim you've won a new phone +||app*.bigbigabum*.live^ +||mobile*.harddayforal*.life^ +||reward*.harddayforal*.icu^ +||reward*.whoisyourd*.icu^ +||sweeps*.whoisyourd*.live^ + ! Placeholder line for alternate list versions diff --git a/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt b/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt index c6ba07d83..43491a29b 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt @@ -1,6 +1,6 @@ [AdGuard β‰₯6] ! Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for AdGuard) -! Version: 20May2019v5-Beta +! Version: 03June2019v1-Beta ! Expires: 5 days ! Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. ! For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -22,6 +22,7 @@ ! These are topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent. ! Presumably fake loans ||.loan^$empty,important +||.agency^$empty,important ! πŸ”Ά Attempted removal of Google search result entries that lead to the above top-level domains (Advanced adblockers only) google.*##.rc:has(a[href*=".tk/"]:not([href*="coolcmd.tk"]):not([href*="budterence.tk"]):not([href*="intr0.tk"]):not([href*="google.tk"]):not([href*="transportnews.tk"]):not([href*="unicorncardlist.tk"]):not([href*="c0d3c.tk"])) @@ -30,6 +31,10 @@ google.*##.rc:has(a[href*=".ml/"]:not([href*="google.ml"])) google.*##.rc:has(a[href*=".gq/"]:not([href*="deimos.gq"])) google.*##.rc:has(a[href*=".cf/"]:not([href*="1hos.cf"]):not([href*="intr0.cf"]):not([href*="ivoid.cf"]):not([href*="domainvoider.cf"]):not([href*="google.cf"]):not([href*="rths.cf"])) google.*##.rc:has(a[href*=".loan/"]) +google.*##.rc:has(a[href*=".agency/"]) + +! πŸ”Ά You know those ultra-fraudulent websites who clutter up Google searches, who have some seemingly random ".php?" values in their URLs? These entries should remove some of them. +google.*##.rc:has(a[href*=".php?xxx="]) ! πŸ”Ά For Google Mobile ! Note for Firefox on Android users: I strongly recommend the use of https://addons.mozilla.org/firefox/addon/google-search-fixer/ for use on Firefox for Android, thus the entries are written for the Chrome version of Google Mobile. @@ -39,6 +44,8 @@ google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".ml/"]: google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".gq/"]:not([href*="deimos.gq"])) google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".cf/"]:not([href*="1hos.cf"]):not([href*="intr0.cf"]):not([href*="ivoid.cf"]):not([href*="domainvoider.cf"]):not([href*="google.cf"]):not([href*="rths.cf"])) google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".loan/"]) +google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".agency/"]) +google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".php?xxx="]) ! πŸ”Ά Dead domains that used to host lists for adblockers or "hosts" tools, but which are now either used by malware pushers, or could potentially be snapped up by them. (Also added to "uBlock Filters - Badware Risks", except for startshop.no) ||adblock.gjtech.net^$empty,important @@ -117,4 +124,11 @@ drivereasy.com#?#.pakb-content li:-abp-has(a:-abp-contains(Update drivers with D ! https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/ drivereasy.com#?#.pakb-content p:-abp-contains(click Update All) +! πŸ”Ά Sites that fraudulently claim you've won a new phone +||app*.bigbigabum*.live^$empty,important +||mobile*.harddayforal*.life^$empty,important +||reward*.harddayforal*.icu^$empty,important +||reward*.whoisyourd*.icu^$empty,important +||sweeps*.whoisyourd*.live^$empty,important + ! Placeholder line for alternate list versions diff --git a/Alternate versions Anti-Malware List/AntiMalwareHosts.txt b/Alternate versions Anti-Malware List/AntiMalwareHosts.txt index 16e8c6dc2..ab424407e 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareHosts.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareHosts.txt @@ -1,5 +1,5 @@ # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Β«hostsΒ» file version) -# Version: 20May2019v5-Alpha +# Version: 03June2019v1-Alpha # Expires: 5 days # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. # For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -22,8 +22,11 @@ # Presumably fake loans + # πŸ”Ά Attempted removal of Google search result entries that lead to the above top-level domains (Advanced adblockers only) +# πŸ”Ά You know those ultra-fraudulent websites who clutter up Google searches, who have some seemingly random ".php?" values in their URLs? These entries should remove some of them. + # πŸ”Ά For Google Mobile # Note for Firefox on Android users: I strongly recommend the use of https://addons.mozilla.org/firefox/addon/google-search-fixer/ for use on Firefox for Android, thus the entries are written for the Chrome version of Google Mobile. @@ -79,4 +82,6 @@ # https://www.drivereasy.com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/ # https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/ +# πŸ”Ά Sites that fraudulently claim you've won a new phone + diff --git a/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action b/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action index 0de03acf8..784931163 100644 --- a/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action +++ b/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action @@ -1,6 +1,6 @@ {+block} # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for Privoxy) -# Version: 20May2019v5-Alpha +# Version: 03June2019v1-Alpha # Expires: 5 days # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. # For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -24,10 +24,14 @@ # These are topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent. # Presumably fake loans .loan +.agency {+block} # πŸ”Ά Attempted removal of Google search result entries that lead to the above top-level domains (Advanced adblockers only) +{+block} +# πŸ”Ά You know those ultra-fraudulent websites who clutter up Google searches, who have some seemingly random ".php?" values in their URLs? These entries should remove some of them. + {+block} # πŸ”Ά For Google Mobile # Note for Firefox on Android users: I strongly recommend the use of https://addons.mozilla.org/firefox/addon/google-search-fixer/ for use on Firefox for Android, thus the entries are written for the Chrome version of Google Mobile. @@ -91,6 +95,14 @@ # https://www.drivereasy.com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/ # https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/ +{+block} +# πŸ”Ά Sites that fraudulently claim you've won a new phone +.app*.bigbigabum*.live +.mobile*.harddayforal*.life +.reward*.harddayforal*.icu +.reward*.whoisyourd*.icu +.sweeps*.whoisyourd*.live + {-block} # Manually updated Privoxy version of the whitelisted domains from the other versions of this list. .coolcmd.tk diff --git a/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl b/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl index af1c01646..22d8d9ca8 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl +++ b/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl @@ -1,6 +1,6 @@ msFilterList # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Internet Explorer TPL) -# Version: 20May2019v5-Beta +# Version: 03June2019v1-Beta # expires = 5 # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. # For more information, details, helpful tools, and other lists that I've made, visit https: github.com DandelionSprout adfilt blob master Wiki General-info.md#english @@ -23,8 +23,11 @@ msFilterList # Presumably fake loans + # πŸ”Ά Attempted removal of Google search result entries that lead to the above top-level domains (Advanced adblockers only) +# πŸ”Ά You know those ultra-fraudulent websites who clutter up Google searches, who have some seemingly random ".php?" values in their URLs? These entries should remove some of them. + # πŸ”Ά For Google Mobile # Note for Firefox on Android users: I strongly recommend the use of https: addons.mozilla.org firefox addon google-search-fixer for use on Firefox for Android, thus the entries are written for the Chrome version of Google Mobile. @@ -80,4 +83,11 @@ msFilterList # https: www.drivereasy.com knowledge epson-xp-420-driver-update-for-windows-7-8-and-10 # https: www.drivereasy.com knowledge solved-this-display-does-not-support-hdcp +# πŸ”Ά Sites that fraudulently claim you've won a new phone + + + + + + # Placeholder line for alternate list versions diff --git a/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py b/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py index 15035c792..7fc40eef0 100644 --- a/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py +++ b/Alternate versions Anti-Malware List/xyzAM_prepare_filters.py @@ -3,11 +3,11 @@ import re SOURCES = ['https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Dandelion%20Sprout\'s%20Anti-Malware%20List.txt'] -UNSUPPORTED_ABP = ['$document', '$important', ',important' '$redirect=', ',redirect=', +UNSUPPORTED_ABP = ['$important', ',important' '$redirect=', ',redirect=', ':style', '##+js', '.*#' , ':xpath', ':matches-css', 'dk,no##'] UNSUPPORTED_TPL = ['##', '#@#', '#?#', r'\.no\.$'] UNSUPPORTED_PRIVOXY = ['##', '#@#', '#?#', '@@', '!#'] -UNSUPPORTED_HOSTS = ['##', '#@#', '#?#', '@@', '!#', '[Adblock Plus 3.2]'] +UNSUPPORTED_HOSTS = ['##', '#@#', '#?#', '@@', '!#', '[Adblock Plus 3.2]', '*'] OUTPUT = 'xyzzyx.txt' OUTPUT_AG = 'AntiMalwareAdGuard.txt' @@ -33,7 +33,7 @@ def prepare_ag(lines) -> str: # until this is done: https://github.com/AdguardTeam/CoreLibs/issues/152 line = re.sub( - "\$document", + "\$doc", "$empty,important", line ) @@ -100,7 +100,7 @@ def prepare_abp(lines) -> str: # remove $document modifier from the rule line = re.sub( - "\$document,", + "\$doc,", "$", line ) @@ -373,6 +373,18 @@ def prepare_tpl(lines) -> str: line ) + line = re.sub( + r"^- agency$", + "", + line + ) + + line = re.sub( + r"^-d .*\*\..*", + "", + line + ) + if is_supported_tpl(line): text += line + '\r\n'