From c9b4308c8763c2af498357725556c210e0b6ca34 Mon Sep 17 00:00:00 2001 From: Imre Kristoffer Eilertsen Date: Mon, 8 Jun 2020 21:30:02 +0200 Subject: [PATCH] Add files via upload --- .../AntiMalwareABP.txt | 66 ++++++++++++++++--- .../AntiMalwareAdGuard.txt | 66 ++++++++++++++++--- .../AntiMalwareAdGuardHome.txt | 66 ++++++++++++++++--- .../AntiMalwareDomains.txt | 41 ++++-------- .../AntiMalwareHosts.txt | 41 ++++-------- .../AntiMalwarePrivoxy.action | 50 ++++++-------- .../AntiMalwareTPL.tpl | 20 +++--- 7 files changed, 228 insertions(+), 122 deletions(-) diff --git a/Alternate versions Anti-Malware List/AntiMalwareABP.txt b/Alternate versions Anti-Malware List/AntiMalwareABP.txt index b487f48ff..8e8d6c6b3 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareABP.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareABP.txt @@ -1,8 +1,9 @@ [Adblock Plus 3.4] ! Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for AdBlock and Adblock Plus) -! Version: 04June2020v1-Beta +! Version: 08June2020v1-Beta ! Expires: 5 days ! Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. +! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists ! For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english ! β€”β€”β€” Country domains β€”β€”β€” @@ -284,39 +285,40 @@ addons.mozilla.org#?#li.SearchResult:-abp-contains(Adblocker.Global) ! Source: desidert.no ||collectfasttracks.com^ +! β€”β€”β€” Found in random witness reports online β€”β€”β€” ! https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315 ||deviuser.com^ -! Malicious domains found in videogame manuals +! β€”β€”β€” Malicious domains found in videogame manuals β€”β€”β€” ||acclaimsports.com^ ||acclaimmaxsports.com^ ||hip-games.com^ ||thq.com.au^ ||gp32.com^ -! Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones +! β€”β€”β€” Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones β€”β€”β€” ! Most of the guides haven't even accounted for how modern phones have replaced the recovery environment with an extra boot environment, leading to very critical Fastboot commands not working and/or bricking the phone. ||unofficialtwrp.com^ ||androidweblog.com^ ||hardreset.info^ -! If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions +! β€”β€”β€” If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions β€”β€”β€” ||version.server^ -! Zero-width spaces/hyphens in lookalike domains +! β€”β€”β€” Zero-width spaces/hyphens in lookalike domains β€”β€”β€” Β­* ​* -! These DNS resolver requests lead to localhost and can't ever receive a proper request +! β€”β€”β€” These DNS resolver requests lead to localhost and can't ever receive a proper request β€”β€”β€” ! https://github.com/AdguardTeam/AdGuardHome/issues/1705 ||0.168.192.in-addr.arpa^ ||1.168.192.in-addr.arpa^ -! Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. +! β€”β€”β€” Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. β€”β€”β€” ||githubus.com^ ||githubu.com^ ||githu.com^ @@ -326,7 +328,55 @@ addons.mozilla.org#?#li.SearchResult:-abp-contains(Adblocker.Global) ||githubuser.com^ ||rgithub.com^ -! User-submitted entries +! β€”β€”β€” Usually used by various groups who buy old domains and display illicit ads on them β€”β€”β€” +://ww5. +://ww6. +://ww7. +://ww8. +://ww9. +://ww10. +://ww11. +://ww12. +://ww13. +://ww14. +://ww15. +://ww16. +://ww17. +://ww18. +://ww19. +://ww20. +://ww21. +://ww22. +://ww23. +://ww24. +://ww25. +://ww26. +://ww27. +://ww28. +://ww29. +://ww30. +://ww31. +://ww32. +://ww33. +://ww34. +://ww35. +://ww36. +://ww37. +://ww38. +://ww39. +://ww40. +://ww41. +://ww42. +://ww43. +://ww44. +://ww45. +://ww46. +://ww47. +://ww48. +://ww49. +://ww50. + +! β€”β€”β€” User-submitted entries β€”β€”β€” ! https://github.com/DandelionSprout/adfilt/issues/71 ||imgvieweriri.com^ diff --git a/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt b/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt index 01e20bad6..141f098cb 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt @@ -1,8 +1,9 @@ [AdGuard β‰₯6] ! Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for AdGuard) -! Version: 04June2020v1-Beta +! Version: 08June2020v1-Beta ! Expires: 5 days ! Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. +! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists ! For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english ! β€”β€”β€” Country domains β€”β€”β€” @@ -309,23 +310,24 @@ addons.mozilla.org#?#li.SearchResult:-abp-contains(Adblocker.Global) ! Source: desidert.no ||collectfasttracks.com^$empty,important +! β€”β€”β€” Found in random witness reports online β€”β€”β€” ! https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315 ||deviuser.com^$empty,important -! Malicious domains found in videogame manuals +! β€”β€”β€” Malicious domains found in videogame manuals β€”β€”β€” ||acclaimsports.com^$empty,important ||acclaimmaxsports.com^$empty,important ||hip-games.com^$empty,important ||thq.com.au^$empty,important ||gp32.com^$empty,important -! Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones +! β€”β€”β€” Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones β€”β€”β€” ! Most of the guides haven't even accounted for how modern phones have replaced the recovery environment with an extra boot environment, leading to very critical Fastboot commands not working and/or bricking the phone. ||unofficialtwrp.com^$empty,important ||androidweblog.com^$empty,important ||hardreset.info^$empty,important -! If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions +! β€”β€”β€” If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions β€”β€”β€” !#if !ext_ublock !#if !adguard ||version.bind^ @@ -334,16 +336,16 @@ addons.mozilla.org#?#li.SearchResult:-abp-contains(Adblocker.Global) !#endif !#endif -! Zero-width spaces/hyphens in lookalike domains +! β€”β€”β€” Zero-width spaces/hyphens in lookalike domains β€”β€”β€” Β­*$empty,important ​*$empty,important -! These DNS resolver requests lead to localhost and can't ever receive a proper request +! β€”β€”β€” These DNS resolver requests lead to localhost and can't ever receive a proper request β€”β€”β€” ! https://github.com/AdguardTeam/AdGuardHome/issues/1705 ||0.168.192.in-addr.arpa^ ||1.168.192.in-addr.arpa^ -! Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. +! β€”β€”β€” Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. β€”β€”β€” ||githubus.com^ ||githubu.com^ ||githu.com^ @@ -353,7 +355,55 @@ addons.mozilla.org#?#li.SearchResult:-abp-contains(Adblocker.Global) ||githubuser.com^ ||rgithub.com^ -! User-submitted entries +! β€”β€”β€” Usually used by various groups who buy old domains and display illicit ads on them β€”β€”β€” +://ww5.$empty,important +://ww6.$empty,important +://ww7.$empty,important +://ww8.$empty,important +://ww9.$empty,important +://ww10.$empty,important +://ww11.$empty,important +://ww12.$empty,important +://ww13.$empty,important +://ww14.$empty,important +://ww15.$empty,important +://ww16.$empty,important +://ww17.$empty,important +://ww18.$empty,important +://ww19.$empty,important +://ww20.$empty,important +://ww21.$empty,important +://ww22.$empty,important +://ww23.$empty,important +://ww24.$empty,important +://ww25.$empty,important +://ww26.$empty,important +://ww27.$empty,important +://ww28.$empty,important +://ww29.$empty,important +://ww30.$empty,important +://ww31.$empty,important +://ww32.$empty,important +://ww33.$empty,important +://ww34.$empty,important +://ww35.$empty,important +://ww36.$empty,important +://ww37.$empty,important +://ww38.$empty,important +://ww39.$empty,important +://ww40.$empty,important +://ww41.$empty,important +://ww42.$empty,important +://ww43.$empty,important +://ww44.$empty,important +://ww45.$empty,important +://ww46.$empty,important +://ww47.$empty,important +://ww48.$empty,important +://ww49.$empty,important +://ww50.$empty,important + +! β€”β€”β€” User-submitted entries β€”β€”β€” ! https://github.com/DandelionSprout/adfilt/issues/71 ||imgvieweriri.com^$empty,important diff --git a/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt b/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt index cb6972b68..5733f3c51 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt @@ -1,8 +1,9 @@ [Adblock Plus 3.4] ! Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for AdGuard Home) -! Version: 04June2020v1-Beta +! Version: 08June2020v1-Beta ! Expires: 5 days ! Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. +! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists ! For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english ! β€”β€”β€” Country domains β€”β€”β€” @@ -249,23 +250,24 @@ ! Source: desidert.no ||collectfasttracks.com^ +! β€”β€”β€” Found in random witness reports online β€”β€”β€” ! https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315 ||deviuser.com^ -! Malicious domains found in videogame manuals +! β€”β€”β€” Malicious domains found in videogame manuals β€”β€”β€” ||acclaimsports.com^ ||acclaimmaxsports.com^ ||hip-games.com^ ||thq.com.au^ ||gp32.com^ -! Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones +! β€”β€”β€” Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones β€”β€”β€” ! Most of the guides haven't even accounted for how modern phones have replaced the recovery environment with an extra boot environment, leading to very critical Fastboot commands not working and/or bricking the phone. ||unofficialtwrp.com^ ||androidweblog.com^ ||hardreset.info^ -! If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions +! β€”β€”β€” If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions β€”β€”β€” ||version.bind^ @@ -274,16 +276,16 @@ -! Zero-width spaces/hyphens in lookalike domains +! β€”β€”β€” Zero-width spaces/hyphens in lookalike domains β€”β€”β€” Β­* ​* -! These DNS resolver requests lead to localhost and can't ever receive a proper request +! β€”β€”β€” These DNS resolver requests lead to localhost and can't ever receive a proper request β€”β€”β€” ! https://github.com/AdguardTeam/AdGuardHome/issues/1705 ||0.168.192.in-addr.arpa^ ||1.168.192.in-addr.arpa^ -! Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. +! β€”β€”β€” Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. β€”β€”β€” ||githubus.com^ ||githubu.com^ ||githu.com^ @@ -293,7 +295,55 @@ ||githubuser.com^ ||rgithub.com^ -! User-submitted entries +! β€”β€”β€” Usually used by various groups who buy old domains and display illicit ads on them β€”β€”β€” +://ww5. +://ww6. +://ww7. +://ww8. +://ww9. +://ww10. +://ww11. +://ww12. +://ww13. +://ww14. +://ww15. +://ww16. +://ww17. +://ww18. +://ww19. +://ww20. +://ww21. +://ww22. +://ww23. +://ww24. +://ww25. +://ww26. +://ww27. +://ww28. +://ww29. +://ww30. +://ww31. +://ww32. +://ww33. +://ww34. +://ww35. +://ww36. +://ww37. +://ww38. +://ww39. +://ww40. +://ww41. +://ww42. +://ww43. +://ww44. +://ww45. +://ww46. +://ww47. +://ww48. +://ww49. +://ww50. + +! β€”β€”β€” User-submitted entries β€”β€”β€” ! https://github.com/DandelionSprout/adfilt/issues/71 ||imgvieweriri.com^ diff --git a/Alternate versions Anti-Malware List/AntiMalwareDomains.txt b/Alternate versions Anti-Malware List/AntiMalwareDomains.txt index 4a3c3d42c..fd4dafbfe 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareDomains.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareDomains.txt @@ -1,8 +1,7 @@ # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Domains list version) -# Version: 04June2020v1-Beta +# Version: 08June2020v1-Beta # Expires: 5 days # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. -# For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english # β€”β€”β€” Country domains β€”β€”β€” # You can expect these domains to have an overwhelming majority of malware domains that have nothing to do with the countries in question. Nevertheless, if you are in a situation where you have to do active business in any of the countries in question, then this list may not be ideal for you. @@ -33,7 +32,6 @@ # β€”β€”β€” You know those ultra-fraudulent websites who clutter up Google searches, who have some seemingly random ".php?" values in their URLs? These entries should remove some of them. β€”β€”β€” # β€”β€”β€” For Google Mobile β€”β€”β€” -# Note for Firefox on Android users: I strongly recommend the use of https://addons.mozilla.org/firefox/addon/google-search-fixer/ for use on Firefox for Android, thus the entries are written for the Chrome version of Google Mobile. # β€”β€”β€” Dead domains that used to host lists for adblockers or "hosts" tools, but which are now either used by malware pushers, or could potentially be snapped up by them. (Also added to "uBlock Filters - Badware Risks") β€”β€”β€” adblock.gjtech.net @@ -81,33 +79,18 @@ hacktolive.org mandriva.com # β€”β€”β€” ReImagePlus links (Also added to "uBlock Filters - Badware Risks") β€”β€”β€” -# https://windowsreport.com/extend-windows-laptop-battery-life/ -# https://appuals.com/fix-error-0x800701e3-on-windows-7-8-1-10/ -# https://ugetfix.com/ask/how-to-fix-windows-store-error-0x8000ffff/ -# https://www.thewindowsclub.com/fix-windows-update-error-0xc1900130-on-windows-10 -# https://www.majorgeeks.com/files/details/patch_my_pc.html -# https://www.2-spyware.com/remove-redirector-gvt1-com.html # β€”β€”β€” ScanUtilities links β€”β€”β€” -# https://www.bynarycodes.com/fix-windows-10-update-error-0x80070006/ # β€”β€”β€” Driver Easy links β€”β€”β€” -# https://www.drivereasy.com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/ -# https://www.drivereasy.com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/ -# https://www.drivereasy.com/knowledge/download-gigabyte-audio-driver/ -# https://www.drivereasy.com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/ -# https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/ # β€”β€”β€” Slimware DriverUpdate links β€”β€”β€” -# https://forums.windowscentral.com/ # β€”β€”β€” Driverpack Online links (Accidentally also fixed in EasyPrivacy and Β«AdGuard Mobile AdsΒ») β€”β€”β€” google-analytics.com # β€”β€”β€” SpyHunter links β€”β€”β€” -# https://howtoremove.guide/redirector-gvt1-com-virus-malware-chrome-removal/ -# https://www.2-spyware.com/remove-redirector-gvt1-com.html # β€”β€”β€” Sites that fraudulently claim you've won a new phone β€”β€”β€” @@ -153,7 +136,6 @@ nikey.cn witkey.com # β€”β€”β€” Truly extraordinarily cases of sites so bad that it counts as malware that directly affects human brains β€”β€”β€” -# https://www.reddit.com/r/insanepeoplefacebook/comments/czvv5i/incel_tracking_down_a_mother_of_a_murdered/ incels.co # β€”β€”β€” Browser extension store entries for notoriously poor or malicious adblocker forks β€”β€”β€” @@ -165,7 +147,6 @@ adblock.biz the1adblocker.com # β€”β€”β€” Wrong suffixes of legitimate sites β€”β€”β€” -# https://new.reddit.com/r/dwarffortress/comments/e4srco/be_sure_to_use_org_instead_of_com_when_going_to/ dwarffortresswiki.com 103.224.212.249 speedtest.com @@ -209,23 +190,23 @@ veremund-hon.com # Source: desidert.no collectfasttracks.com -# https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315 +# β€”β€”β€” Found in random witness reports online β€”β€”β€” deviuser.com -# Malicious domains found in videogame manuals +# β€”β€”β€” Malicious domains found in videogame manuals β€”β€”β€” acclaimsports.com acclaimmaxsports.com hip-games.com thq.com.au gp32.com -# Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones +# β€”β€”β€” Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones β€”β€”β€” # Most of the guides haven't even accounted for how modern phones have replaced the recovery environment with an extra boot environment, leading to very critical Fastboot commands not working and/or bricking the phone. unofficialtwrp.com androidweblog.com hardreset.info -# If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions +# β€”β€”β€” If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions β€”β€”β€” version.bind @@ -234,14 +215,13 @@ version.server -# Zero-width spaces/hyphens in lookalike domains +# β€”β€”β€” Zero-width spaces/hyphens in lookalike domains β€”β€”β€” -# These DNS resolver requests lead to localhost and can't ever receive a proper request -# https://github.com/AdguardTeam/AdGuardHome/issues/1705 +# β€”β€”β€” These DNS resolver requests lead to localhost and can't ever receive a proper request β€”β€”β€” 0.168.192.in-addr.arpa 1.168.192.in-addr.arpa -# Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. +# β€”β€”β€” Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. β€”β€”β€” githubus.com githubu.com githu.com @@ -251,8 +231,9 @@ wgithub.com githubuser.com rgithub.com -# User-submitted entries -# https://github.com/DandelionSprout/adfilt/issues/71 +# β€”β€”β€” Usually used by various groups who buy old domains and display illicit ads on them β€”β€”β€” + +# β€”β€”β€” User-submitted entries β€”β€”β€” imgvieweriri.com diff --git a/Alternate versions Anti-Malware List/AntiMalwareHosts.txt b/Alternate versions Anti-Malware List/AntiMalwareHosts.txt index 7896a87d3..75a3ce81a 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareHosts.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareHosts.txt @@ -1,8 +1,7 @@ # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Β«hostsΒ» file version) -# Version: 04June2020v1-Alpha +# Version: 08June2020v1-Alpha # Expires: 5 days # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. -# For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english # β€”β€”β€” Country domains β€”β€”β€” # You can expect these domains to have an overwhelming majority of malware domains that have nothing to do with the countries in question. Nevertheless, if you are in a situation where you have to do active business in any of the countries in question, then this list may not be ideal for you. @@ -33,7 +32,6 @@ # β€”β€”β€” You know those ultra-fraudulent websites who clutter up Google searches, who have some seemingly random ".php?" values in their URLs? These entries should remove some of them. β€”β€”β€” # β€”β€”β€” For Google Mobile β€”β€”β€” -# Note for Firefox on Android users: I strongly recommend the use of https://addons.mozilla.org/firefox/addon/google-search-fixer/ for use on Firefox for Android, thus the entries are written for the Chrome version of Google Mobile. # β€”β€”β€” Dead domains that used to host lists for adblockers or "hosts" tools, but which are now either used by malware pushers, or could potentially be snapped up by them. (Also added to "uBlock Filters - Badware Risks") β€”β€”β€” 127.0.0.1 adblock.gjtech.net @@ -81,33 +79,18 @@ 127.0.0.1 mandriva.com # β€”β€”β€” ReImagePlus links (Also added to "uBlock Filters - Badware Risks") β€”β€”β€” -# https://windowsreport.com/extend-windows-laptop-battery-life/ -# https://appuals.com/fix-error-0x800701e3-on-windows-7-8-1-10/ -# https://ugetfix.com/ask/how-to-fix-windows-store-error-0x8000ffff/ -# https://www.thewindowsclub.com/fix-windows-update-error-0xc1900130-on-windows-10 -# https://www.majorgeeks.com/files/details/patch_my_pc.html -# https://www.2-spyware.com/remove-redirector-gvt1-com.html # β€”β€”β€” ScanUtilities links β€”β€”β€” -# https://www.bynarycodes.com/fix-windows-10-update-error-0x80070006/ # β€”β€”β€” Driver Easy links β€”β€”β€” -# https://www.drivereasy.com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/ -# https://www.drivereasy.com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/ -# https://www.drivereasy.com/knowledge/download-gigabyte-audio-driver/ -# https://www.drivereasy.com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/ -# https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/ # β€”β€”β€” Slimware DriverUpdate links β€”β€”β€” -# https://forums.windowscentral.com/ # β€”β€”β€” Driverpack Online links (Accidentally also fixed in EasyPrivacy and Β«AdGuard Mobile AdsΒ») β€”β€”β€” 127.0.0.1 google-analytics.com # β€”β€”β€” SpyHunter links β€”β€”β€” -# https://howtoremove.guide/redirector-gvt1-com-virus-malware-chrome-removal/ -# https://www.2-spyware.com/remove-redirector-gvt1-com.html # β€”β€”β€” Sites that fraudulently claim you've won a new phone β€”β€”β€” @@ -153,7 +136,6 @@ 127.0.0.1 witkey.com # β€”β€”β€” Truly extraordinarily cases of sites so bad that it counts as malware that directly affects human brains β€”β€”β€” -# https://www.reddit.com/r/insanepeoplefacebook/comments/czvv5i/incel_tracking_down_a_mother_of_a_murdered/ 127.0.0.1 incels.co # β€”β€”β€” Browser extension store entries for notoriously poor or malicious adblocker forks β€”β€”β€” @@ -165,7 +147,6 @@ 127.0.0.1 the1adblocker.com # β€”β€”β€” Wrong suffixes of legitimate sites β€”β€”β€” -# https://new.reddit.com/r/dwarffortress/comments/e4srco/be_sure_to_use_org_instead_of_com_when_going_to/ 127.0.0.1 dwarffortresswiki.com 127.0.0.1 103.224.212.249 127.0.0.1 speedtest.com @@ -209,23 +190,23 @@ # Source: desidert.no 127.0.0.1 collectfasttracks.com -# https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315 +# β€”β€”β€” Found in random witness reports online β€”β€”β€” 127.0.0.1 deviuser.com -# Malicious domains found in videogame manuals +# β€”β€”β€” Malicious domains found in videogame manuals β€”β€”β€” 127.0.0.1 acclaimsports.com 127.0.0.1 acclaimmaxsports.com 127.0.0.1 hip-games.com 127.0.0.1 thq.com.au 127.0.0.1 gp32.com -# Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones +# β€”β€”β€” Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones β€”β€”β€” # Most of the guides haven't even accounted for how modern phones have replaced the recovery environment with an extra boot environment, leading to very critical Fastboot commands not working and/or bricking the phone. 127.0.0.1 unofficialtwrp.com 127.0.0.1 androidweblog.com 127.0.0.1 hardreset.info -# If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions +# β€”β€”β€” If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions β€”β€”β€” 127.0.0.1 version.bind @@ -234,14 +215,13 @@ -# Zero-width spaces/hyphens in lookalike domains +# β€”β€”β€” Zero-width spaces/hyphens in lookalike domains β€”β€”β€” -# These DNS resolver requests lead to localhost and can't ever receive a proper request -# https://github.com/AdguardTeam/AdGuardHome/issues/1705 +# β€”β€”β€” These DNS resolver requests lead to localhost and can't ever receive a proper request β€”β€”β€” 127.0.0.1 0.168.192.in-addr.arpa 127.0.0.1 1.168.192.in-addr.arpa -# Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. +# β€”β€”β€” Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. β€”β€”β€” 127.0.0.1 githubus.com 127.0.0.1 githubu.com 127.0.0.1 githu.com @@ -251,8 +231,9 @@ 127.0.0.1 githubuser.com 127.0.0.1 rgithub.com -# User-submitted entries -# https://github.com/DandelionSprout/adfilt/issues/71 +# β€”β€”β€” Usually used by various groups who buy old domains and display illicit ads on them β€”β€”β€” + +# β€”β€”β€” User-submitted entries β€”β€”β€” 127.0.0.1 imgvieweriri.com diff --git a/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action b/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action index 25930bed1..02613b7b6 100644 --- a/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action +++ b/Alternate versions Anti-Malware List/AntiMalwarePrivoxy.action @@ -1,9 +1,8 @@ {+block} # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (for Privoxy) -# Version: 04June2020v1-Alpha +# Version: 08June2020v1-Alpha # Expires: 5 days # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. -# For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english {+block} # β€”β€”β€” Country domains β€”β€”β€” @@ -39,7 +38,6 @@ {+block} # β€”β€”β€” For Google Mobile β€”β€”β€” -# Note for Firefox on Android users: I strongly recommend the use of https://addons.mozilla.org/firefox/addon/google-search-fixer/ for use on Firefox for Android, thus the entries are written for the Chrome version of Google Mobile. {+block} # β€”β€”β€” Dead domains that used to host lists for adblockers or "hosts" tools, but which are now either used by malware pushers, or could potentially be snapped up by them. (Also added to "uBlock Filters - Badware Risks") β€”β€”β€” @@ -92,29 +90,16 @@ {+block} # β€”β€”β€” ReImagePlus links (Also added to "uBlock Filters - Badware Risks") β€”β€”β€” -# https://windowsreport.com/extend-windows-laptop-battery-life/ -# https://appuals.com/fix-error-0x800701e3-on-windows-7-8-1-10/ -# https://ugetfix.com/ask/how-to-fix-windows-store-error-0x8000ffff/ -# https://www.thewindowsclub.com/fix-windows-update-error-0xc1900130-on-windows-10 -# https://www.majorgeeks.com/files/details/patch_my_pc.html .majorgeeks.com/images/icons/red_icon_18x17px.png -# https://www.2-spyware.com/remove-redirector-gvt1-com.html {+block} # β€”β€”β€” ScanUtilities links β€”β€”β€” -# https://www.bynarycodes.com/fix-windows-10-update-error-0x80070006/ {+block} # β€”β€”β€” Driver Easy links β€”β€”β€” -# https://www.drivereasy.com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/ -# https://www.drivereasy.com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/ -# https://www.drivereasy.com/knowledge/download-gigabyte-audio-driver/ -# https://www.drivereasy.com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/ -# https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/ {+block} # β€”β€”β€” Slimware DriverUpdate links β€”β€”β€” -# https://forums.windowscentral.com/ {+block} # β€”β€”β€” Driverpack Online links (Accidentally also fixed in EasyPrivacy and Β«AdGuard Mobile AdsΒ») β€”β€”β€” @@ -122,8 +107,6 @@ {+block} # β€”β€”β€” SpyHunter links β€”β€”β€” -# https://howtoremove.guide/redirector-gvt1-com-virus-malware-chrome-removal/ -# https://www.2-spyware.com/remove-redirector-gvt1-com.html {+block} # β€”β€”β€” Sites that fraudulently claim you've won a new phone β€”β€”β€” @@ -173,7 +156,6 @@ {+block} # β€”β€”β€” Truly extraordinarily cases of sites so bad that it counts as malware that directly affects human brains β€”β€”β€” -# https://www.reddit.com/r/insanepeoplefacebook/comments/czvv5i/incel_tracking_down_a_mother_of_a_murdered/ .incels.co {+block} @@ -187,7 +169,6 @@ {+block} # β€”β€”β€” Wrong suffixes of legitimate sites β€”β€”β€” -# https://new.reddit.com/r/dwarffortress/comments/e4srco/be_sure_to_use_org_instead_of_com_when_going_to/ .dwarffortresswiki.com .103.224.212.249 .speedtest.com @@ -232,23 +213,27 @@ # Source: desidert.no .collectfasttracks.com -# https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315 +{+block} +# β€”β€”β€” Found in random witness reports online β€”β€”β€” .deviuser.com -# Malicious domains found in videogame manuals +{+block} +# β€”β€”β€” Malicious domains found in videogame manuals β€”β€”β€” .acclaimsports.com .acclaimmaxsports.com .hip-games.com .thq.com.au .gp32.com -# Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones +{+block} +# β€”β€”β€” Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones β€”β€”β€” # Most of the guides haven't even accounted for how modern phones have replaced the recovery environment with an extra boot environment, leading to very critical Fastboot commands not working and/or bricking the phone. .unofficialtwrp.com .androidweblog.com .hardreset.info -# If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions +{+block} +# β€”β€”β€” If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions β€”β€”β€” # # .version.bind @@ -257,16 +242,18 @@ # # -# Zero-width spaces/hyphens in lookalike domains +{+block} +# β€”β€”β€” Zero-width spaces/hyphens in lookalike domains β€”β€”β€” Β­* ​* -# These DNS resolver requests lead to localhost and can't ever receive a proper request -# https://github.com/AdguardTeam/AdGuardHome/issues/1705 +{+block} +# β€”β€”β€” These DNS resolver requests lead to localhost and can't ever receive a proper request β€”β€”β€” .0.168.192.in-addr.arpa .1.168.192.in-addr.arpa -# Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. +{+block} +# β€”β€”β€” Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. β€”β€”β€” .githubus.com .githubu.com .githu.com @@ -276,8 +263,11 @@ .githubuser.com .rgithub.com -# User-submitted entries -# https://github.com/DandelionSprout/adfilt/issues/71 +{+block} +# β€”β€”β€” Usually used by various groups who buy old domains and display illicit ads on them β€”β€”β€” + +{+block} +# β€”β€”β€” User-submitted entries β€”β€”β€” .imgvieweriri.com {-block} diff --git a/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl b/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl index 548725bd7..ca3cb3d89 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl +++ b/Alternate versions Anti-Malware List/AntiMalwareTPL.tpl @@ -1,8 +1,9 @@ msFilterList # Title: πŸ’Š Dandelion Sprout's Anti-Malware List (Internet Explorer TPL) -# Version: 04June2020v1-Beta +# Version: 08June2020v1-Beta : expires = 5 # Description: Most anti-malware lists are pretty big and can cover a 5- or 6-digit amount of specific domains. But my list hereby claims to remove more than 25% of all known malware sites with just a 2-digit amount of entries. This is mostly done by blocking top-level domains that have become devastatingly abused by spammers, usually because they allowed for free and uncontrolled domain registrations. There's also additional categories that cover unusual malware and phishing domains that very few other lists seem to cover. +# For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists # For more information, details, helpful tools, and other lists that I've made, visit https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#english # β€”β€”β€” Country domains β€”β€”β€” @@ -249,39 +250,40 @@ msFilterList # Source: desidert.no -d collectfasttracks.com +# β€”β€”β€” Found in random witness reports online β€”β€”β€” # https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315 -d deviuser.com -# Malicious domains found in videogame manuals +# β€”β€”β€” Malicious domains found in videogame manuals β€”β€”β€” -d acclaimsports.com -d acclaimmaxsports.com -d hip-games.com -d thq.com.au -d gp32.com -# Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones +# β€”β€”β€” Gobshite copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones β€”β€”β€” # Most of the guides haven't even accounted for how modern phones have replaced the recovery environment with an extra boot environment, leading to very critical Fastboot commands not working and or bricking the phone. -d unofficialtwrp.com -d androidweblog.com -d hardreset.info -# If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions +# β€”β€”β€” If you run a webserver of any sort, and you get incoming requests to resolve these domains, that's rarely a good sign for that requestor's intentions β€”β€”β€” -d version.server -# Zero-width spaces hyphens in lookalike domains +# β€”β€”β€” Zero-width spaces hyphens in lookalike domains β€”β€”β€” Β­* ​* -# These DNS resolver requests lead to localhost and can't ever receive a proper request +# β€”β€”β€” These DNS resolver requests lead to localhost and can't ever receive a proper request β€”β€”β€” # https://github.com/AdguardTeam/AdGuardHome/issues/1705 -d 0.168.192.in-addr.arpa -d 1.168.192.in-addr.arpa -# Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. +# β€”β€”β€” Since I very, very often have to go from "raw.githubusercontent.com" to "github.com" by means of manual address bar highlighting, I feel I could need some kind of protection insurance in case I highlight 2mm off-course one day. β€”β€”β€” -d githubus.com -d githubu.com -d githu.com @@ -291,7 +293,9 @@ msFilterList -d githubuser.com -d rgithub.com -# User-submitted entries +# β€”β€”β€” Usually used by various groups who buy old domains and display illicit ads on them β€”β€”β€” + +# β€”β€”β€” User-submitted entries β€”β€”β€” # https://github.com/DandelionSprout/adfilt/issues/71 -d imgvieweriri.com