diff --git a/Alternate versions Anti-Malware List/AntiMalwareABP.txt b/Alternate versions Anti-Malware List/AntiMalwareABP.txt index 5f7632653..d64cc29e5 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareABP.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareABP.txt @@ -1,6 +1,6 @@ [Adblock Plus 3.6] ! Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for AdBlock and Adblock Plus) -! Version: 07October2021v1-Beta +! Version: 09October2021v1-Beta ! Expires: 5 days ! Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there. ! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists @@ -1856,7 +1856,190 @@ zombooru.com##a[href="http://www.hard55.com"] ||fortnitecode.online^$popup ||cd.org^ ! https://www.virustotal.com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community -||23.94.26.138^ +! https://github.com/DandelionSprout/adfilt/commit/f7f114945c83b339be5cdd848e229680d9918abb#commitcomment-57642875 +||23.94.26.138^ +||23.94.26.138^$popup +||ispco.shop^ +||ispco.shop^$popup +! https://github.com/DandelionSprout/adfilt/pull/298 +! https://www.virustotal.com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community +||205.185.126.200^ +||205.185.126.200^$popup +||medpro-131.getfoxyproxy.org^ +! https://www.virustotal.com/gui/url/337dd5e5c53558dc7d6c8910b5ebe14a7390a78e13830b367363465b85ca8dd6?nocache=1 +||trytogoi.xyz^ +||trytogoi.xyz^$popup +! https://www.virustotal.com/gui/url/0f8791a82ee4d2c229ccbe3328092cdb2135027439778c280f1d2d3b0fdba1bb +||apple-technicalsupport-icloud.com^ +||apple-technicalsupport-icloud.com^$popup +! https://www.virustotal.com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community +||185.243.56.167^ +||185.243.56.167^$popup +! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community +||123.10.224.135^ +||123.10.224.135^$popup +||59.47.187.147^ +||59.47.187.147^$popup +||39.68.172.210^ +||39.68.172.210^$popup +||122.192.177.176^ +||122.192.177.176^$popup +||112.27.124.108^ +||112.27.124.108^$popup +||123.110.176.246^ +||123.110.176.246^$popup +||219.155.105.98^ +||219.155.105.98^$popup +||171.35.161.209^ +||171.35.161.209^$popup +||60.16.255.36^ +||60.16.255.36^$popup +||112.30.4.52^ +||112.30.4.52^$popup +||182.121.191.201^ +||182.121.191.201^$popup +||121.61.48.170^ +||121.61.48.170^$popup +||39.81.68.45^ +||39.81.68.45^$popup +||27.222.220.164^ +||27.222.220.164^$popup +||113.233.215.135^ +||113.233.215.135^$popup +||151.77.100.133^ +||151.77.100.133^$popup +||125.120.13.184^ +||125.120.13.184^$popup +||120.12.138.133^ +||120.12.138.133^$popup +||27.194.115.185^ +||27.194.115.185^$popup +||104.128.199.228^ +||104.128.199.228^$popup +||183.92.123.145^ +||183.92.123.145^$popup +||110.89.8.126^ +||110.89.8.126^$popup +||125.43.211.184^ +||125.43.211.184^$popup +||1.0.218.230^ +||1.0.218.230^$popup +||221.208.4.56^ +||221.208.4.56^$popup +||60.13.60.19^ +||60.13.60.19^$popup +||171.37.29.87^ +||171.37.29.87^$popup +||124.91.237.188^ +||124.91.237.188^$popup +||115.56.137.49^ +||115.56.137.49^$popup +||115.52.240.69^ +||115.52.240.69^$popup +||112.252.132.185^ +||112.252.132.185^$popup +||117.198.240.157^ +||117.198.240.157^$popup +||42.53.240.249^ +||42.53.240.249^$popup +||116.179.138.68^ +||116.179.138.68^$popup +||110.241.119.159^ +||110.241.119.159^$popup +||115.56.31.133^ +||115.56.31.133^$popup +||103.19.128.222^ +||103.19.128.222^$popup +||202.12.80.74^ +||202.12.80.74^$popup +||61.52.8.62^ +||61.52.8.62^$popup +||182.122.252.69^ +||182.122.252.69^$popup +||219.155.26.50^ +||219.155.26.50^$popup +||120.4.141.185^ +||120.4.141.185^$popup +||119.102.7.115^ +||119.102.7.115^$popup +||72.51.127.213^ +||72.51.127.213^$popup +||111.224.199.91^ +||111.224.199.91^$popup +||119.250.236.122^ +||119.250.236.122^$popup +||112.30.110.58^ +||112.30.110.58^$popup +! https://www.virustotal.com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community +||pcae.de^ +! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community +||117.196.49.21^ +||117.196.49.21^$popup +||115.55.54.234^ +||115.55.54.234^$popup +||115.52.17.123^ +||115.52.17.123^$popup +||182.59.69.21^ +||182.59.69.21^$popup +! https://www.virustotal.com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community +||chip-secured-download.de^ +||chip-secured-download.de^$popup +! https://www.virustotal.com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb +! Domains which resolve to this (already blocked) IP - for users of HOSTs/Domains/uBlock Origin +||ujgjyjltunl.com^ +||ujgjyjltunl.com^$popup +||pvyvglaf.com^ +||pvyvglaf.com^$popup +||ecsfunhget.com^ +||ecsfunhget.com^$popup +||xemfrctctdnlhe.com^ +||xemfrctctdnlhe.com^$popup +||tgxcmcoikpgek.com^ +||tgxcmcoikpgek.com^$popup +||lghdoxzulv.com^ +||lghdoxzulv.com^$popup +||knxntpsd.com^ +||knxntpsd.com^$popup +||nctylivpwhpby.com^ +||nctylivpwhpby.com^$popup +||phhitgjxsit.com^ +||phhitgjxsit.com^$popup +! https://www.virustotal.com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1 +||saimission.org^ +||saimission.org^$popup +! https://www.virustotal.com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1 +||grub-wa-saya.duckdns.org^ +||grub-wa-saya.duckdns.org^$popup +! https://www.virustotal.com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations +||driversupport.com^ +! Copied over from URLHaus +||thehotelshowdev.bitkit.dk^ +||thehotelshowdev.bitkit.dk^$popup +! Domains related to the above +||big5constructnigeria-staging.bitkit.dk^ +||big5constructnigeria-staging.bitkit.dk^$popup +||big5-nigeria.bitkit.dk^ +||big5-nigeria.bitkit.dk^$popup +||bromic-staging.bitkit.dk^ +||bromic-staging.bitkit.dk^$popup +! A PUP +||mycleanpc.com^ +! Related domains owned by the same company and used for payment (the first is for 'tech support' scams, the second for their 'ID protection') +||ustechsupport.com^ +||mycleanid.com^ +! The main website for the MyCleanPC company +||realdefen.se^ +! Vermilion Strike +! https://www.virustotal.com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations +||160.202.163.100^ +||160.202.163.100^$popup +! https://www.virustotal.com/gui/ip-address/160.202.163.100/relations +||microsoftkernel.com^ +||microsoftkernel.com^$popup +||hksupd.com^ +||hksupd.com^$popup +||microsofthk.com^ +||microsofthk.com^$popup ! β€”β€”β€” Standard malware that I stumbled upon on my own β€”β€”β€” ! http://www.toorgle.net/results.php?q=fetishkitsch&security=666 diff --git a/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt b/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt index 277de5f9f..2c51fbf21 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt @@ -1,6 +1,6 @@ [AdGuard versions from β‰₯2019] ! Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for AdGuard) -! Version: 07October2021v1-Beta +! Version: 09October2021v1-Beta ! Expires: 5 days ! Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there. ! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists @@ -1234,7 +1234,113 @@ zombooru.com##a[href="http://www.hard55.com"] ||fortnitecode.online^$empty,important ||cd.org^$document ! https://www.virustotal.com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community +! https://github.com/DandelionSprout/adfilt/commit/f7f114945c83b339be5cdd848e229680d9918abb#commitcomment-57642875 23.94.26.138$network +||ispco.shop^$empty,important +! https://github.com/DandelionSprout/adfilt/pull/298 +! https://www.virustotal.com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community +205.185.126.200$network +||medpro-131.getfoxyproxy.org^$document +! https://www.virustotal.com/gui/url/337dd5e5c53558dc7d6c8910b5ebe14a7390a78e13830b367363465b85ca8dd6?nocache=1 +||trytogoi.xyz^$empty,important +! https://www.virustotal.com/gui/url/0f8791a82ee4d2c229ccbe3328092cdb2135027439778c280f1d2d3b0fdba1bb +||apple-technicalsupport-icloud.com^$empty,important +! https://www.virustotal.com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community +185.243.56.167$network +! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community +123.10.224.135$network +59.47.187.147$network +39.68.172.210$network +122.192.177.176$network +112.27.124.108$network +123.110.176.246$network +219.155.105.98$network +171.35.161.209$network +60.16.255.36$network +112.30.4.52$network +182.121.191.201$network +121.61.48.170$network +39.81.68.45$network +27.222.220.164$network +113.233.215.135$network +151.77.100.133$network +125.120.13.184$network +120.12.138.133$network +27.194.115.185$network +104.128.199.228$network +183.92.123.145$network +110.89.8.126$network +125.43.211.184$network +1.0.218.230$network +221.208.4.56$network +60.13.60.19$network +171.37.29.87$network +124.91.237.188$network +115.56.137.49$network +115.52.240.69$network +112.252.132.185$network +117.198.240.157$network +42.53.240.249$network +116.179.138.68$network +110.241.119.159$network +115.56.31.133$network +103.19.128.222$network +202.12.80.74$network +61.52.8.62$network +182.122.252.69$network +219.155.26.50$network +120.4.141.185$network +119.102.7.115$network +72.51.127.213$network +111.224.199.91$network +119.250.236.122$network +112.30.110.58$network +! https://www.virustotal.com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community +||pcae.de^$document +! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community +117.196.49.21$network +115.55.54.234$network +115.52.17.123$network +182.59.69.21$network +! https://www.virustotal.com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community +||chip-secured-download.de^$empty,important +! https://www.virustotal.com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb +! Domains which resolve to this (already blocked) IP - for users of HOSTs/Domains/uBlock Origin +||ujgjyjltunl.com^$empty,important +||pvyvglaf.com^$empty,important +||ecsfunhget.com^$empty,important +||xemfrctctdnlhe.com^$empty,important +||tgxcmcoikpgek.com^$empty,important +||lghdoxzulv.com^$empty,important +||knxntpsd.com^$empty,important +||nctylivpwhpby.com^$empty,important +||phhitgjxsit.com^$empty,important +! https://www.virustotal.com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1 +||saimission.org^$empty,important +! https://www.virustotal.com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1 +||grub-wa-saya.duckdns.org^$empty,important +! https://www.virustotal.com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations +||driversupport.com^$document +! Copied over from URLHaus +||thehotelshowdev.bitkit.dk^$empty,important +! Domains related to the above +||big5constructnigeria-staging.bitkit.dk^$empty,important +||big5-nigeria.bitkit.dk^$empty,important +||bromic-staging.bitkit.dk^$empty,important +! A PUP +||mycleanpc.com^$document +! Related domains owned by the same company and used for payment (the first is for 'tech support' scams, the second for their 'ID protection') +||ustechsupport.com^$document +||mycleanid.com^$document +! The main website for the MyCleanPC company +||realdefen.se^$document +! Vermilion Strike +! https://www.virustotal.com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations +160.202.163.100$network +! https://www.virustotal.com/gui/ip-address/160.202.163.100/relations +||microsoftkernel.com^$empty,important +||hksupd.com^$empty,important +||microsofthk.com^$empty,important ! β€”β€”β€” Standard malware that I stumbled upon on my own β€”β€”β€” ! http://www.toorgle.net/results.php?q=fetishkitsch&security=666 diff --git a/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt b/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt index 532e7cdba..53eb445d2 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt @@ -1,6 +1,6 @@ [Adblock Plus 3.6] ! Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for AdGuard Home, and for AdGuard for Android/Windows' DNS filtering) -! Version: 07October2021v1-Beta +! Version: 09October2021v1-Beta ! Expires: 5 days ! Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there. ! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists @@ -1151,7 +1151,113 @@ ||fortnitecode.online^ ||cd.org^ ! https://www.virustotal.com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community +! https://github.com/DandelionSprout/adfilt/commit/f7f114945c83b339be5cdd848e229680d9918abb#commitcomment-57642875 23.94.26.138 +||ispco.shop^ +! https://github.com/DandelionSprout/adfilt/pull/298 +! https://www.virustotal.com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community +205.185.126.200 +||medpro-131.getfoxyproxy.org^ +! https://www.virustotal.com/gui/url/337dd5e5c53558dc7d6c8910b5ebe14a7390a78e13830b367363465b85ca8dd6?nocache=1 +||trytogoi.xyz^ +! https://www.virustotal.com/gui/url/0f8791a82ee4d2c229ccbe3328092cdb2135027439778c280f1d2d3b0fdba1bb +||apple-technicalsupport-icloud.com^ +! https://www.virustotal.com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community +185.243.56.167 +! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community +123.10.224.135 +59.47.187.147 +39.68.172.210 +122.192.177.176 +112.27.124.108 +123.110.176.246 +219.155.105.98 +171.35.161.209 +60.16.255.36 +112.30.4.52 +182.121.191.201 +121.61.48.170 +39.81.68.45 +27.222.220.164 +113.233.215.135 +151.77.100.133 +125.120.13.184 +120.12.138.133 +27.194.115.185 +104.128.199.228 +183.92.123.145 +110.89.8.126 +125.43.211.184 +1.0.218.230 +221.208.4.56 +60.13.60.19 +171.37.29.87 +124.91.237.188 +115.56.137.49 +115.52.240.69 +112.252.132.185 +117.198.240.157 +42.53.240.249 +116.179.138.68 +110.241.119.159 +115.56.31.133 +103.19.128.222 +202.12.80.74 +61.52.8.62 +182.122.252.69 +219.155.26.50 +120.4.141.185 +119.102.7.115 +72.51.127.213 +111.224.199.91 +119.250.236.122 +112.30.110.58 +! https://www.virustotal.com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community +||pcae.de^ +! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community +117.196.49.21 +115.55.54.234 +115.52.17.123 +182.59.69.21 +! https://www.virustotal.com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community +||chip-secured-download.de^ +! https://www.virustotal.com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb +! Domains which resolve to this (already blocked) IP - for users of HOSTs/Domains/uBlock Origin +||ujgjyjltunl.com^ +||pvyvglaf.com^ +||ecsfunhget.com^ +||xemfrctctdnlhe.com^ +||tgxcmcoikpgek.com^ +||lghdoxzulv.com^ +||knxntpsd.com^ +||nctylivpwhpby.com^ +||phhitgjxsit.com^ +! https://www.virustotal.com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1 +||saimission.org^ +! https://www.virustotal.com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1 +||grub-wa-saya.duckdns.org^ +! https://www.virustotal.com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations +||driversupport.com^ +! Copied over from URLHaus +||thehotelshowdev.bitkit.dk^ +! Domains related to the above +||big5constructnigeria-staging.bitkit.dk^ +||big5-nigeria.bitkit.dk^ +||bromic-staging.bitkit.dk^ +! A PUP +||mycleanpc.com^ +! Related domains owned by the same company and used for payment (the first is for 'tech support' scams, the second for their 'ID protection') +||ustechsupport.com^ +||mycleanid.com^ +! The main website for the MyCleanPC company +||realdefen.se^ +! Vermilion Strike +! https://www.virustotal.com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations +160.202.163.100 +! https://www.virustotal.com/gui/ip-address/160.202.163.100/relations +||microsoftkernel.com^ +||hksupd.com^ +||microsofthk.com^ ! β€”β€”β€” Standard malware that I stumbled upon on my own β€”β€”β€” ! http://www.toorgle.net/results.php?q=fetishkitsch&security=666 diff --git a/Alternate versions Anti-Malware List/AntiMalwareDomains.txt b/Alternate versions Anti-Malware List/AntiMalwareDomains.txt index a864adb47..26db8ef24 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareDomains.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareDomains.txt @@ -1,5 +1,5 @@ # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Domains list version) -# Version: 07October2021v1-Beta +# Version: 09October2021v1-Beta # Expires: 5 days # Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there. @@ -962,6 +962,95 @@ starbux.fun fortnitecode.online cd.org 23.94.26.138 +ispco.shop +205.185.126.200 +medpro-131.getfoxyproxy.org +trytogoi.xyz +apple-technicalsupport-icloud.com +185.243.56.167 +123.10.224.135 +59.47.187.147 +39.68.172.210 +122.192.177.176 +112.27.124.108 +123.110.176.246 +219.155.105.98 +171.35.161.209 +60.16.255.36 +112.30.4.52 +182.121.191.201 +121.61.48.170 +39.81.68.45 +27.222.220.164 +113.233.215.135 +151.77.100.133 +125.120.13.184 +120.12.138.133 +27.194.115.185 +104.128.199.228 +183.92.123.145 +110.89.8.126 +125.43.211.184 +1.0.218.230 +221.208.4.56 +60.13.60.19 +171.37.29.87 +124.91.237.188 +115.56.137.49 +115.52.240.69 +112.252.132.185 +117.198.240.157 +42.53.240.249 +116.179.138.68 +110.241.119.159 +115.56.31.133 +103.19.128.222 +202.12.80.74 +61.52.8.62 +182.122.252.69 +219.155.26.50 +120.4.141.185 +119.102.7.115 +72.51.127.213 +111.224.199.91 +119.250.236.122 +112.30.110.58 +pcae.de +117.196.49.21 +115.55.54.234 +115.52.17.123 +182.59.69.21 +chip-secured-download.de +# Domains which resolve to this (already blocked) IP - for users of HOSTs/Domains/uBlock Origin +ujgjyjltunl.com +pvyvglaf.com +ecsfunhget.com +xemfrctctdnlhe.com +tgxcmcoikpgek.com +lghdoxzulv.com +knxntpsd.com +nctylivpwhpby.com +phhitgjxsit.com +saimission.org +driversupport.com +# Copied over from URLHaus +thehotelshowdev.bitkit.dk +# Domains related to the above +big5constructnigeria-staging.bitkit.dk +big5-nigeria.bitkit.dk +bromic-staging.bitkit.dk +# A PUP +mycleanpc.com +# Related domains owned by the same company and used for payment (the first is for 'tech support' scams, the second for their 'ID protection') +ustechsupport.com +mycleanid.com +# The main website for the MyCleanPC company +realdefen.se +# Vermilion Strike +160.202.163.100 +microsoftkernel.com +hksupd.com +microsofthk.com # β€”β€”β€” Standard malware that I stumbled upon on my own β€”β€”β€” downloadprovider.me diff --git a/Alternate versions Anti-Malware List/AntiMalwareHosts.txt b/Alternate versions Anti-Malware List/AntiMalwareHosts.txt index 9c94e4a7c..0d6fe1e7e 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareHosts.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareHosts.txt @@ -1,5 +1,5 @@ # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Β«hostsΒ» file version) -# Version: 07October2021v1-Alpha +# Version: 09October2021v1-Alpha # Expires: 5 days # Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there. @@ -962,6 +962,95 @@ 127.0.0.1 fortnitecode.online 127.0.0.1 cd.org 127.0.0.1 23.94.26.138 +127.0.0.1 ispco.shop +127.0.0.1 205.185.126.200 +127.0.0.1 medpro-131.getfoxyproxy.org +127.0.0.1 trytogoi.xyz +127.0.0.1 apple-technicalsupport-icloud.com +127.0.0.1 185.243.56.167 +127.0.0.1 123.10.224.135 +127.0.0.1 59.47.187.147 +127.0.0.1 39.68.172.210 +127.0.0.1 122.192.177.176 +127.0.0.1 112.27.124.108 +127.0.0.1 123.110.176.246 +127.0.0.1 219.155.105.98 +127.0.0.1 171.35.161.209 +127.0.0.1 60.16.255.36 +127.0.0.1 112.30.4.52 +127.0.0.1 182.121.191.201 +127.0.0.1 121.61.48.170 +127.0.0.1 39.81.68.45 +127.0.0.1 27.222.220.164 +127.0.0.1 113.233.215.135 +127.0.0.1 151.77.100.133 +127.0.0.1 125.120.13.184 +127.0.0.1 120.12.138.133 +127.0.0.1 27.194.115.185 +127.0.0.1 104.128.199.228 +127.0.0.1 183.92.123.145 +127.0.0.1 110.89.8.126 +127.0.0.1 125.43.211.184 +127.0.0.1 1.0.218.230 +127.0.0.1 221.208.4.56 +127.0.0.1 60.13.60.19 +127.0.0.1 171.37.29.87 +127.0.0.1 124.91.237.188 +127.0.0.1 115.56.137.49 +127.0.0.1 115.52.240.69 +127.0.0.1 112.252.132.185 +127.0.0.1 117.198.240.157 +127.0.0.1 42.53.240.249 +127.0.0.1 116.179.138.68 +127.0.0.1 110.241.119.159 +127.0.0.1 115.56.31.133 +127.0.0.1 103.19.128.222 +127.0.0.1 202.12.80.74 +127.0.0.1 61.52.8.62 +127.0.0.1 182.122.252.69 +127.0.0.1 219.155.26.50 +127.0.0.1 120.4.141.185 +127.0.0.1 119.102.7.115 +127.0.0.1 72.51.127.213 +127.0.0.1 111.224.199.91 +127.0.0.1 119.250.236.122 +127.0.0.1 112.30.110.58 +127.0.0.1 pcae.de +127.0.0.1 117.196.49.21 +127.0.0.1 115.55.54.234 +127.0.0.1 115.52.17.123 +127.0.0.1 182.59.69.21 +127.0.0.1 chip-secured-download.de +# Domains which resolve to this (already blocked) IP - for users of HOSTs/Domains/uBlock Origin +127.0.0.1 ujgjyjltunl.com +127.0.0.1 pvyvglaf.com +127.0.0.1 ecsfunhget.com +127.0.0.1 xemfrctctdnlhe.com +127.0.0.1 tgxcmcoikpgek.com +127.0.0.1 lghdoxzulv.com +127.0.0.1 knxntpsd.com +127.0.0.1 nctylivpwhpby.com +127.0.0.1 phhitgjxsit.com +127.0.0.1 saimission.org +127.0.0.1 driversupport.com +# Copied over from URLHaus +127.0.0.1 thehotelshowdev.bitkit.dk +# Domains related to the above +127.0.0.1 big5constructnigeria-staging.bitkit.dk +127.0.0.1 big5-nigeria.bitkit.dk +127.0.0.1 bromic-staging.bitkit.dk +# A PUP +127.0.0.1 mycleanpc.com +# Related domains owned by the same company and used for payment (the first is for 'tech support' scams, the second for their 'ID protection') +127.0.0.1 ustechsupport.com +127.0.0.1 mycleanid.com +# The main website for the MyCleanPC company +127.0.0.1 realdefen.se +# Vermilion Strike +127.0.0.1 160.202.163.100 +127.0.0.1 microsoftkernel.com +127.0.0.1 hksupd.com +127.0.0.1 microsofthk.com # β€”β€”β€” Standard malware that I stumbled upon on my own β€”β€”β€” 127.0.0.1 downloadprovider.me diff --git a/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action b/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action index 234389ac5..d4a1f6908 100644 --- a/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action +++ b/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action @@ -1,6 +1,6 @@ {+block} # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for Privoxy) -# Version: 07October2021v1-Alpha +# Version: 09October2021v1-Alpha # Expires: 5 days # Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there. @@ -990,6 +990,96 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +# Domains which resolve to this (already blocked) IP - for users of HOSTs/Domains/uBlock Origin + + + + + + + + + + + + +# Copied over from URLHaus + +# Domains related to the above + + + +# A PUP + +# Related domains owned by the same company and used for payment (the first is for 'tech support' scams, the second for their 'ID protection') + + +# The main website for the MyCleanPC company + +# Vermilion Strike + + + + + {+block} # β€”β€”β€” Standard malware that I stumbled upon on my own β€”β€”β€” diff --git a/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl b/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl index 6da6be68e..fa65b33b7 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl +++ b/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl @@ -1,6 +1,6 @@ msFilterList # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Internet Explorer TPL) -# Version: 07October2021v1-Beta +# Version: 09October2021v1-Beta : expires = 5 # Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there. # For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists @@ -1141,7 +1141,112 @@ msFilterList -d fortnitecode.online -d cd.org # https://www.virustotal.com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community +# https://github.com/DandelionSprout/adfilt/commit/f7f114945c83b339be5cdd848e229680d9918abb#commitcomment-57642875 -d 23.94.26.138 +-d ispco.shop +# https://github.com/DandelionSprout/adfilt/pull/298 +# https://www.virustotal.com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community +-d 205.185.126.200 +-d medpro-131.getfoxyproxy.org +# https://www.virustotal.com/gui/url/337dd5e5c53558dc7d6c8910b5ebe14a7390a78e13830b367363465b85ca8dd6?nocache=1 +-d trytogoi.xyz +# https://www.virustotal.com/gui/url/0f8791a82ee4d2c229ccbe3328092cdb2135027439778c280f1d2d3b0fdba1bb +-d apple-technicalsupport-icloud.com +# https://www.virustotal.com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community +-d 185.243.56.167 +# https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community +-d 123.10.224.135 +-d 59.47.187.147 +-d 39.68.172.210 +-d 122.192.177.176 +-d 112.27.124.108 +-d 123.110.176.246 +-d 219.155.105.98 +-d 171.35.161.209 +-d 60.16.255.36 +-d 112.30.4.52 +-d 182.121.191.201 +-d 121.61.48.170 +-d 39.81.68.45 +-d 27.222.220.164 +-d 113.233.215.135 +-d 151.77.100.133 +-d 125.120.13.184 +-d 120.12.138.133 +-d 27.194.115.185 +-d 104.128.199.228 +-d 183.92.123.145 +-d 110.89.8.126 +-d 125.43.211.184 +-d 1.0.218.230 +-d 221.208.4.56 +-d 60.13.60.19 +-d 171.37.29.87 +-d 124.91.237.188 +-d 115.56.137.49 +-d 115.52.240.69 +-d 112.252.132.185 +-d 117.198.240.157 +-d 42.53.240.249 +-d 116.179.138.68 +-d 110.241.119.159 +-d 115.56.31.133 +-d 103.19.128.222 +-d 202.12.80.74 +-d 61.52.8.62 +-d 182.122.252.69 +-d 219.155.26.50 +-d 120.4.141.185 +-d 119.102.7.115 +-d 72.51.127.213 +-d 111.224.199.91 +-d 119.250.236.122 +-d 112.30.110.58 +# https://www.virustotal.com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community +-d pcae.de +# https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community +-d 117.196.49.21 +-d 115.55.54.234 +-d 115.52.17.123 +-d 182.59.69.21 +# https://www.virustotal.com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community +-d chip-secured-download.de +# https://www.virustotal.com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb +# Domains which resolve to this (already blocked) IP - for users of HOSTs Domains uBlock Origin +-d ujgjyjltunl.com +-d pvyvglaf.com +-d ecsfunhget.com +-d xemfrctctdnlhe.com +-d tgxcmcoikpgek.com +-d lghdoxzulv.com +-d knxntpsd.com +-d nctylivpwhpby.com +-d phhitgjxsit.com +# https://www.virustotal.com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1 +-d saimission.org +# https://www.virustotal.com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1 +# https://www.virustotal.com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations +-d driversupport.com +# Copied over from URLHaus +-d thehotelshowdev.bitkit.dk +# Domains related to the above +-d big5constructnigeria-staging.bitkit.dk +-d big5-nigeria.bitkit.dk +-d bromic-staging.bitkit.dk +# A PUP +-d mycleanpc.com +# Related domains owned by the same company and used for payment (the first is for 'tech support' scams, the second for their 'ID protection') +-d ustechsupport.com +-d mycleanid.com +# The main website for the MyCleanPC company +-d realdefen.se +# Vermilion Strike +# https://www.virustotal.com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations +-d 160.202.163.100 +# https://www.virustotal.com/gui/ip-address/160.202.163.100/relations +-d microsoftkernel.com +-d hksupd.com +-d microsofthk.com # β€”β€”β€” Standard malware that I stumbled upon on my own β€”β€”β€” # http://www.toorgle.net/results.php?q=fetishkitsch&security=666 diff --git a/Alternate versions Anti-Malware List/Dandelion Sprout's and other adblocker lists' IPs.ipset b/Alternate versions Anti-Malware List/Dandelion Sprout's and other adblocker lists' IPs.ipset index 6e3fed480..0f0c53782 100644 --- a/Alternate versions Anti-Malware List/Dandelion Sprout's and other adblocker lists' IPs.ipset +++ b/Alternate versions Anti-Malware List/Dandelion Sprout's and other adblocker lists' IPs.ipset @@ -1,5 +1,5 @@ # Title: Dandelion Sprout's and other adblocker lists' IPs -# Version: 03October2021v1-Beta +# Version: 07October2021v1-Beta # Expires: 5 days # Description: This IP set combines IP and CIDR addresses from plentiful of major adblocker lists. It contains heavily altered content from Dandelion Sprout's Anti-Malware List, Dandelion Sprout's Nordic Filters, EasyList, uBlock Filters, uBlock Filters - Badware Risks, AdGuard Base Filter, AdGuard French Filter, EasyList Germany, ABP Anti-Circumvention Filters, RU AdList, Liste AR, and EasyList Spanish. # For more information and details about this list and other lists of mine, go to https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -86,6 +86,7 @@ 27.220.253.78 192.3.194.242 # Copied from Β«uBlock Filters - Badware RisksΒ» because it has proven to be a very good entry +23.94.26.138 192.243.59.12 192.243.59.13 192.243.59.20