From ab5c82cf8fde71dcdfa598e81a7eb4249b0d94d1 Mon Sep 17 00:00:00 2001 From: Imre Kristoffer Eilertsen Date: Wed, 24 Jul 2019 19:29:54 +0200 Subject: [PATCH] Update Dandelion Sprout's Anti-Malware List.txt --- Dandelion Sprout's Anti-Malware List.txt | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/Dandelion Sprout's Anti-Malware List.txt b/Dandelion Sprout's Anti-Malware List.txt index 810102112..0558c519c 100644 --- a/Dandelion Sprout's Anti-Malware List.txt +++ b/Dandelion Sprout's Anti-Malware List.txt @@ -1,6 +1,6 @@ [Adblock Plus 3.2] ! Title: 💊 Dandelion Sprout's Anti-Malware List -! Version: 20July2019v2-Beta +! Version: 24July2019v1-Beta ! Expires: 5 days ! Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. ! For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english @@ -23,6 +23,7 @@ ! Presumably fake loans ||.loan^$doc,domain=~ Warning displayed due to: It's a topical domain whose sites have an unusally big chance of being fraudulent. ||.agency^$doc,domain=~ Warning displayed due to: It's a topical domain whose sites have an unusally big chance of being fraudulent. +||.bid^$doc,domain=~ Warning displayed due to: Being a very frequently abused .bid in EasyList entries. ! ——— Attempted removal of Google search result entries that lead to the above top-level domains (Advanced adblockers only) ——— google.*##.rc:has(a[href*=".tk/"]:not([href*="coolcmd.tk"]):not([href*="budterence.tk"]):not([href*="intr0.tk"]):not([href*="google.tk"]):not([href*="transportnews.tk"]):not([href*="unicorncardlist.tk"]):not([href*="c0d3c.tk"]):not([href*="anonytext.tk"]):not([href*="tokelau-info.tk"]):not([href*="fakaofo.tk"]):not([href*="nukunonu.tk"])) @@ -32,6 +33,7 @@ google.*##.rc:has(a[href*=".gq/"]:not([href*="deimos.gq"]):not([href*="inege.gq" google.*##.rc:has(a[href*=".cf/"]:not([href*="1hos.cf"]):not([href*="intr0.cf"]):not([href*="ivoid.cf"]):not([href*="domainvoider.cf"]):not([href*="google.cf"]):not([href*="rths.cf"]):not([href*="voitures.cf"]):not([href*="assembleenationale-rca.cf"]):not([href*="cps-rca.cf"]):not([href*="acap.cf"])) google.*##.rc:has(a[href*=".loan/"]) google.*##.rc:has(a[href*=".agency/"]) +google.*##.rc:has(a[href*=".bid/"]) ! ——— You know those ultra-fraudulent websites who clutter up Google searches, who have some seemingly random ".php?" values in their URLs? These entries should remove some of them. ——— google.*##.rc:has(a[href*=".php?xxx="]) @@ -45,6 +47,7 @@ google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".gq/"]: google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".cf/"]:not([href*="1hos.cf"]):not([href*="intr0.cf"]):not([href*="ivoid.cf"]):not([href*="domainvoider.cf"]):not([href*="google.cf"]):not([href*="rths.cf"]):not([href*="voitures.cf"]):not([href*="assembleenationale-rca.cf"]):not([href*="cps-rca.cf"]):not([href*="acap.cf"])) google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".loan/"]) google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".agency/"]) +google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".bid/"]) google.*##div[data-hveid]:has(:scope > div > div > a[onmousedown][href*=".php?xxx="]) ! ——— Dead domains that used to host lists for adblockers or "hosts" tools, but which are now either used by malware pushers, or could potentially be snapped up by them. (Also added to "uBlock Filters - Badware Risks", except for startshop.no) ———