Add files via upload

This commit is contained in:
Imre Eilertsen
2024-09-17 08:30:40 +02:00
committed by GitHub
parent d10e1d2bbb
commit dfbc90688d
7 changed files with 695 additions and 663 deletions
@@ -1,9 +1,10 @@
[Adblock Plus 3.13]
! Title: 💊 Dandelion Sprout's Anti-Malware List (for Adblock Plus and AdBlock)
! Version: 20August2024v1
! Version: 17September2024v1
! Expires: 2 days
! Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists
! (Note to self, only applicable to uBO: When 1.59.1 goes stable, implement "*$ipaddress=(...),all" for the IP addresses, alongside the previous syntaxing as the case is for AdGuard Browser Extension.)
! Homepage: https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#-english
! As of June 2023, Pi-Hole FTL ≥5.22 users should rather use https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/AntiMalwareAdGuardHome.txt, which is a ||-type list version designed specifically for DNS tools.
@@ -21,7 +22,7 @@
! Palau (Put on break due to too many whitelistings being needed)
!!!||pw^$domain=~libgen.pw|~petridish.pw|~palaugov.pw|~dpc.pw|~buttercup.pw|~rezka.pw|~darkcrystal.pw|~xor.pw|~fullhdfilmizlesene.pw|~gopass.pw|~vost.pw|~core.pw|~bittor.pw|~plutonium.pw|~nitter.pw|~kge.pw
! Legitimate use is almost non-existent, but has a tiny userbase in Japan. Its extreme common-ness in malware redirections means that the entry will be kept forever.
||top^$domain=~caitlin.top|~callmebymygender.top|~corriente.top|~gdtot.top|~nicenature.top|~reminder.top|~magocoro.top|~castlevania.top|~suiten.top|~shucks.top|~1stream.top|~ambr.top|~techblog.top|~changlam10.top|~changlam11.top|~pdcdn1.top|~mastodon.top|~pressplay.top|~chillx.top|~strims.top|~thedesk.top|~audioforyou.top|~pegelinux.top|~awavenue.top|~reyhub.top
||top^$domain=~caitlin.top|~callmebymygender.top|~corriente.top|~gdtot.top|~nicenature.top|~reminder.top|~magocoro.top|~castlevania.top|~suiten.top|~shucks.top|~1stream.top|~ambr.top|~techblog.top|~changlam10.top|~changlam11.top|~pdcdn1.top|~mastodon.top|~pressplay.top|~chillx.top|~strims.top|~thedesk.top|~audioforyou.top|~pegelinux.top|~awavenue.top|~reyhub.top|~iboxs.top
! International topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent.
||loan^
!!!||agency^$domain=~battlefield.agency|~baam.agency|~robotzebra.agency|~uphotel.agency|~ws.agency (Can't remember the last time I saw it used in a redirection train.)
@@ -30,7 +31,7 @@
!!!||ooo^$domain=~toast.ooo
! (https://github.com/DandelionSprout/adfilt/issues/999)
!!!@@://oo*.ooo/
! https://bgp.he.net/AS202492#_prefixes (17/07/2022)
! https://bgp.he•net/AS202492#_prefixes (17/07/2022)
!!!||monster^$domain=~egybest.monster|~yts.monster|~cloudcdn.monster|~fedi.monster|~rollenspiel.monster|~tts.monster|~geometry.monster
! https://github.com/AdguardTeam/AdguardFilters/issues/131156
!!!||sbs^$domain=~ecopulse.sbs
@@ -178,12 +179,12 @@ play.google.com#?#div[class$=" "] > div[class*=" "][jscontroller] > *:has([href$
! ——— Links to PC "optimising" "tool" PUPs that'll most likely stuff your PC full of nagware and malware ———
! ¤¤¤ ReImagePlus (Also added to "uBlock Filters - Badware Risks") ¤¤¤
! https://windowsreport.com/extend-windows-laptop-battery-life/
! https://windowsreport•com/extend-windows-laptop-battery-life/
windowsreport.com##.code-block
! https://appuals.com/fix-error-0x800701e3-on-windows-7-8-1-10/
! https://appuals•com/fix-error-0x800701e3-on-windows-7-8-1-10/
appuals.com##.info.box
appuals.com##.appua-reimage-top
! https://ugetfix.com/ask/how-to-fix-windows-store-error-0x8000ffff/
! https://ugetfix•com/ask/how-to-fix-windows-store-error-0x8000ffff/
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es##div.attention-button-box-green
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es##.sidebar_download_inner
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es##.primary_download
@@ -193,13 +194,13 @@ ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es#?#.ga-download:has-
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es##.download-button-offer-header
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es#?#h2:has-text(/^Repair\syour\sErrors\sautomatical{2}y$/i)
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es#?#h2:has-text(/^Repair\syour\sErrors\sautomatical{2}y$/i) + p
! https://www.thewindowsclub.com/fix-windows-update-error-0xc1900130-on-windows-10
! https://www•thewindowsclub•com/fix-windows-update-error-0xc1900130-on-windows-10
thewindowsclub.com#?#.entry-content > div > strong:has-text(find & fix Windows error)
thewindowsclub.com##div[style^="float: none; margin:10px "]
! https://www.majorgeeks.com/files/details/patch_my_pc.html
! https://www•majorgeeks•com/files/details/patch_my_pc•html
majorgeeks.com#?#b:has(a[target^=reimage])
||majorgeeks.com/images/icons/red_icon_18x17px.png$image
! https://www.2-spyware.com/remove-redirector-gvt1-com.html
! https://www•2-spyware•com/remove-redirector-gvt1-com•html
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk#?#.attention-button-wrap:has-text(Reimage)
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk##.ui-content > .win
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk##.sidebar_download_inner > :not(.voting-box, .colorbg-grey)
@@ -213,38 +214,38 @@ majorgeeks.com#?#b:has(a[target^=reimage])
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk#?#a:has-text(Reimage)
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk##.quick-download-button-text
! ¤¤¤ ScanUtilities ¤¤¤
! https://www.bynarycodes.com/fix-windows-10-update-error-0x80070006/
! https://www•bynarycodes•com/fix-windows-10-update-error-0x80070006/
bynarycodes.com##div[class^=bynar-content_]
bynarycodes.com#?#.panel:has(a[href*="scanutilities.com"])
! ¤¤¤ Driver Easy ¤¤¤
! https://www.drivereasy.com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/
! https://www•drivereasy•com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/
drivereasy.com#?#.pakb-content ol:has-text(Download and install Driver Easy)
drivereasy.com#?#.pakb-content p:has-text(Driver Easy)
drivereasy.com#?#.pakb-content div.info.note:has-text(drivereasy.com)
! https://www.drivereasy.com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/
! https://www•drivereasy•com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/
drivereasy.com#?#.pakb-content img[sizes^="(max-width: 80"]
drivereasy.com#?#.pakb-content p:has-text(the FREE version)
drivereasy.com#?#.pakb-content p:has-text(the Pro version)
! https://www.drivereasy.com/knowledge/download-gigabyte-audio-driver/
! https://www•drivereasy•com/knowledge/download-gigabyte-audio-driver/
drivereasy.com#?#.pakb-content img[sizes^="(max-width: 79"]
drivereasy.com#?#.pakb-content span[id^=i-]:has-text(Automatically update your)
drivereasy.com#?#.pakb-content li:has(a[href="#automatically"])
! https://www.drivereasy.com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/
! https://www•drivereasy•com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/
drivereasy.com#?#.pakb-content span[id^=i-]:has-text(Update drivers with Driver Easy)
drivereasy.com#?#.pakb-content figcaption:has-text(for free if you like)
drivereasy.com#?#.pakb-content li:has(a:has-text(Update drivers with Driver Easy))
! https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/
! https://www•drivereasy•com/knowledge/solved-this-display-does-not-support-hdcp/
drivereasy.com#?#.pakb-content p:has-text(click Update All)
! ¤¤¤ Slimware DriverUpdate ¤¤¤
! https://forums.windowscentral.com/
! https://forums•windowscentral•com/
forums.windowscentral.com###navbar_notice_33
! ¤¤¤ Driverpack Online (Accidentally also fixed in EasyPrivacy and «AdGuard Mobile Ads») ¤¤¤
||google-analytics.com^$domain=sdi-tool.org
! ¤¤¤ SpyHunter links ¤¤¤
! https://howtoremove.guide/redirector-gvt1-com-virus-malware-chrome-removal/
! https://howtoremove•guide/redirector-gvt1-com-virus-malware-chrome-removal/
howtoremove.guide##div[style^="border:2px"]
howtoremove.guide#?#.entry-content > div:has-text(Special Offer)
! https://www.2-spyware.com/remove-redirector-gvt1-com.html
! https://www•2-spyware•com/remove-redirector-gvt1-com•html
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk##.automatic_removal_list_w > .ar_block_description
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk#?#a:has-text(SpyHunter)
guide##a[href*="download.enigmasoftware.com/spyhunter-free-download/stpl_94/SpyHunter-Installer.exe"]
@@ -256,9 +257,9 @@ virusresearch.org##.virus-before-content
virusresearch.org##.q2w3-fixed-widget-container
virusresearch.org##.virus-after-fourth-h2
virusresearch.org##.virus-after-content
! https://www.cyclonis.com/how-to-create-gmail-account-without-phone-number/
! https://www•cyclonis•com/how-to-create-gmail-account-without-phone-number/
cyclonis.com#?#div.rotatead-container:has(.download[data-params*="dl.enigmasoftware.com"])
! https://www.2-viruses.com/remove-ad-spam-press-allow-to-continue
! https://www•2-viruses•com/remove-ad-spam-press-allow-to-continue
2-viruses.com##.active.prods-win.prod-download
||2-viruses.com/downloads/spyhunter2^
||2-viruses.com/downloads/spyhunter2^$popup
@@ -269,14 +270,14 @@ cyclonis.com#?#div.rotatead-container:has(.download[data-params*="dl.enigmasoftw
||cfoc.org/spyhunter-download-and-install-instructions/^$popup
cfoc.org###top_custom_banner
cfoc.org##.custom_banner_top_btn
cfoc.org#?#tr:has([href="https://cfoc.org/go-to-spyhunter/"])
cfoc.org##*:has(> * > a[href="https://cfoc.org/spyhunter-download-and-install-instructions/"])
cfoc.org#?#tr:has([href$="ttps://cfoc.org/go-to-spyhunter/"])
cfoc.org##*:has(> * > a[href$="ttps://cfoc.org/spyhunter-download-and-install-instructions/"])
cfoc.org##*:has(> * > * > .su-button[href^="https://link.safecart.com/"])
cfoc.org#?#.widget_text.widget:has([href^="https://cfoc.org/spyhunter-"])
||cfoc.org/combocleaner-download-mac/^
cfoc.org#?#tr:has([href="https://cfoc.org/combocleaner-download-mac/"])
cfoc.org#?#tr:has([href$="ttps://cfoc.org/combocleaner-download-mac/"])
cfoc.org#?#p:has(font:has-text( could remain on your Mac if you are not careful during removal. We recommend that you download and run a scan with Combo Cleaner now to professionally clean up your Mac in ))
cfoc.org#?#font:has(center:has([href="https://cfoc.org/combocleaner-download-mac/"]))
cfoc.org#?#font:has(center:has([href$="ttps://cfoc.org/combocleaner-download-mac/"]))
||sensorstechforum.com/spyhunter-download-and-install-instructions/^
||sensorstechforum.com/spyhunter-download-and-install-instructions/^$popup
||sensorstechforum.com/spyhunter-for-mac-download-install/^
@@ -284,29 +285,29 @@ cfoc.org#?#font:has(center:has([href="https://cfoc.org/combocleaner-download-mac
||sensorstechforum.com/wp-content/uploads/2020/04/SpyHunter-Install-And-Free-Scan-$image
||youtube.com/embed/KbGF_fvsRU4^
||youtube.com/embed/KbGF_fvsRU4^$popup
sensorstechforum.com#?#tr:has([href="https://sensorstechforum.com/spyhunter-download-and-install-instructions/"])
sensorstechforum.com#?#center:has([href="https://www.enigmasoftware.com/spyhunter5-eula/"])
sensorstechforum.com##[href="https://sensorstechforum.com/spyhunter-download-and-install-instructions/"]
sensorstechforum.com#?#tr:has([href$="ttps://sensorstechforum.com/spyhunter-download-and-install-instructions/"])
sensorstechforum.com#?#center:has([href$="ttps://www.enigmasoftware.com/spyhunter5-eula/"])
sensorstechforum.com##[href$="ttps://sensorstechforum.com/spyhunter-download-and-install-instructions/"]
sensorstechforum.com##.top_banner_custom
sensorstechforum.com#?#center:has-text(Click the button below):has-text(SpyHunter for Mac)
sensorstechforum.com#?#p:has([href="https://sensorstechforum.com/spyhunter-mac-review-advanced-anti-malware/"])
sensorstechforum.com#?#p:has([href$="ttps://sensorstechforum.com/spyhunter-mac-review-advanced-anti-malware/"])
sensorstechforum.com#?#p:has([src^="https://sensorstechforum.com/wp-content/uploads/2020/04/SpyHunter-Install-And-Free-Scan-"])
sensorstechforum.com#?#center:has([title="Download SpyHunter for Mac"])
sensorstechforum.com#?#p:has([src="https://www.youtube.com/embed/KbGF_fvsRU4"])
sensorstechforum.com#?#p:has([src$="ttps://www.youtube.com/embed/KbGF_fvsRU4"])
sensorstechforum.com###win_top_new_hidden
macsecurity.net##.banner
macsecurity.net##.btn-download.btn-lg.btn
! ¤¤¤ Restoro ¤¤¤
! https://www.windowsdispatch.com/fix-system-restore-0x81000203-error-code/
! https://www•windowsdispatch•com/fix-system-restore-0x81000203-error-code/
windowsdispatch.com##strong
! https://dlldownloads.com/xlive-dll/
! https://dlldownloads•com/xlive-dll/
dlldownloads.com##.page-container > p
! https://windowsreport.com/find-remove-duplicate-files-windows-10/
! https://windowsreport•com/find-remove-duplicate-files-windows-10/
windowsreport.com##.bnr-block
! https://windowsreport.com/how-to-update-roblox/ (08/12/2022)
! https://windowsreport•com/how-to-update-roblox/ (08/12/2022)
windowsreport.com##div[class^=restoro-download] + section
windowsreport.com##div[class^=refmed]
! https://appuals.com/pr-connect-reset-error/
! https://appuals•com/pr-connect-reset-error/
appuals.com##.wptp
appuals.com#?#h3:has(+ p:has-text(Download and run Restoro ))
appuals.com#?#p:has-text(Download and run Restoro )
@@ -350,7 +351,7 @@ exefiles.com#?#.row:has(a[href*="/recommended/"])
/^https://(apps?|best|competition|game|mobile|play|prize|reward|sweeps)\d{2,8}\.[a-z-]{5,22}\d{1,8}\.(icu|life|live)/$~third-party
/^https?:\/\/((?!www)[a-z]{3,5}\.)?[-0-9a-z]{6,}\.(?:com|fun|guru|life|online|pw|site|space|top)\/\/?\?o=[0-9a-z]{7}&u=[0-9a-z]{7}/$domain=com|fun|guru|life|online|pw|site|space|top
/^https?:\/\/((?!www)[a-z]{3,5}\.)?[-0-9a-z]{6,}\.(?:com|fun|guru|life|online|pw|site|space|top)\/\/?\?u=[0-9a-z]{7}&o=[0-9a-z]{7}/$domain=com|fun|guru|life|online|pw|site|space|top
! https://github.com/AdguardTeam/AdguardFilters/issues/58737
! https://github•com/AdguardTeam/AdguardFilters/issues/58737
/^https?:\/\/(?:www\.)?[-0-9a-z]{14,}\.(?:biz|fun|live)\/[a-zA-Z]{10,}\.php$/$domain=biz|fun|live
! ——— Banner for "MSN New Tab" ———
@@ -487,10 +488,10 @@ download.cnet.com#?#.c-globalCard:has(a[href*="/AdsCleaner/"])
||discordap.com^
||discordap.com^$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
! https://github.com/DevSpen/links/blob/master/src/links.txt
/(^|\.|://)d[il]sc(or|ro)ds?-?g[il]ft[se]?[.-].*/
/(^|\.|://)d[il]sc(or|ro)ds?-?g[il]ft[se]?[.-].*/$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
/(^|\.|://)d[il]sc(or|ro)ds?-?n[il]tro[.-].*/
/(^|\.|://)d[il]sc(or|ro)ds?-?n[il]tro[.-].*/$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
/^(.*\.|.*://)?d[il]sc(or|ro)ds?-?g[il]ft[se]?[.-].*$/
/^(.*\.|.*://)?d[il]sc(or|ro)ds?-?g[il]ft[se]?[.-].*$/$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
/^(.*\.|.*://)?d[il]sc(or|ro)ds?-?n[il]tro[.-].*$/
/^(.*\.|.*://)?d[il]sc(or|ro)ds?-?n[il]tro[.-].*$/$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
||discord-nltro.
||discord-nltro.$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
||discord-app.
@@ -501,8 +502,8 @@ download.cnet.com#?#.c-globalCard:has(a[href*="/AdsCleaner/"])
||dlscord.$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
||dlscord-app.
||dlscord-app.$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
/(^|\.|://)gifts?-?discord\..*/
/(^|\.|://)gifts?-?discord\..*/$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
/^(.*\.|.*://)?gifts?-?discord\..*$/
/^(.*\.|.*://)?gifts?-?discord\..*$/$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
||steamcommin*,domain=~likely-a-fake-malware-version-of-steamcommunity.com
||steamcommm*
||steamcommm*$popup,~inline-font,domain=~fake-malware-version-of-steamcommunity.com
@@ -599,7 +600,7 @@ download.cnet.com#?#.c-globalCard:has(a[href*="/AdsCleaner/"])
||githubuser.com^$domain=~you-were-likely-looking-for-githubusercontent.com
||rgithub.com^$domain=~you-were-likely-looking-for-githubusercontent.com
||githubt.com^$domain=~you-were-likely-looking-for-githubusercontent.com
! https://scammer.info/t/discord-nitro-scam-25/87887
! https://scammer•info/t/discord-nitro-scam-25/87887
||discorde-nitre.xyz^
||discorde-nitre.xyz^$popup,~inline-font,domain=~fake-malware-version-of-discordapp.com
@@ -646,10 +647,10 @@ download.cnet.com#?#.c-globalCard:has(a[href*="/AdsCleaner/"])
||3.216.243.46^
||roamingclicks.com^
||roamingclicks.com^$popup
! Source: desidert.no
! Source: desidert•no
||collectfasttracks.com^
||collectfasttracks.com^$popup,~inline-font,domain=~malware-redirection-trains.*
! Source: vn-zoom.com
! Source: vn-zoom•com
||ttnrd.com^
||ttnrd.com^$popup
||amanda.*.com^
@@ -660,7 +661,7 @@ download.cnet.com#?#.c-globalCard:has(a[href*="/AdsCleaner/"])
||54.152.245.247^
||35.172.40.232^
||3.90.125.85^
! Various ex-affiliate links at www.zombooru.com
! Various ex-affiliate links at www•zombooru•com
||track.vcdc.com^
||track.vcdc.com^$popup,~inline-font,domain=~malware-redirection-trains.*
||track.tkbo.com^
@@ -678,9 +679,9 @@ download.cnet.com#?#.c-globalCard:has(a[href*="/AdsCleaner/"])
||144.76.0.242^
||144.76.1.130^
||195.201.92.254^
zombooru.com##a[href="http://www.boorufurry.com/"]
zombooru.com##a[href="http://www.analbooru.com/"]
zombooru.com##a[href="http://www.hard55.com"]
zombooru.com##a[href$="ttp://www.boorufurry.com/"]
zombooru.com##a[href$="ttp://www.analbooru.com/"]
zombooru.com##a[href$="ttp://www.hard55.com"]
! https://github.com/DandelionSprout/adfilt/pull/167
||forgoprokick.icu^
||forgoprokick.icu^$popup
@@ -853,8 +854,8 @@ zombooru.com##a[href="http://www.hard55.com"]
||216.21.13.14^$popup
||216.21.13.15^
||216.21.13.15^$popup
/\.(xyz|pics)/[a-zA-Z0-9]{130,}/$script,subdocument,image
/\.(cloudfront\.net|xyz|pics)/[a-zA-Z0-9]{20,}/[a-zA-Z0-9]{25,}\+[a-zA-Z0-9+]{90,}$/$script,subdocument,image
/^.*\.(xyz|pics)/[a-zA-Z0-9]{130,}$/$script,subdocument,image
/^.*\.(cloudfront\.net|xyz|pics)/[a-zA-Z0-9]{20,}/[a-zA-Z0-9]{25,}\+[a-zA-Z0-9+]{90,}$/$script,subdocument,image
||abaphosis.guru^
||abaphosis.guru^$popup
||abietichob.live^
@@ -6977,7 +6978,7 @@ zombooru.com##a[href="http://www.hard55.com"]
://192.243.59.
://192.243.61.
! https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315
! https://twitter•com/SUNgoddessOKAMI/status/1221295265195405315
||deviuser.com^
! https://github.com/AdguardTeam/AdguardFilters/issues/61838
/scan-update-and-protect-your-browser.html
@@ -7077,7 +7078,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||best202*-games-web1.com^$popup
||theonlygames.com^
||theonlygames.com^$popup
! https://maldita.es/malditobulo/2020/12/04/concurso-mercadona-ganar-tarjeta-regalo-100-euros-phishing/
! https://maldita•es/malditobulo/2020/12/04/concurso-mercadona-ganar-tarjeta-regalo-100-euros-phishing/
||notified-today.com^
||antivirus-update.com^
||new-message.cc^
@@ -7089,12 +7090,12 @@ zombooru.com##a[href="http://www.hard55.com"]
||stay-notified.com^
||stay-notified.xyz^
||167.99.249.47^
! https://maldita.es/malditobulo/2020/12/02/lidl-regala-robot-cocina-silvercrest-monsieur-cuisine-encuesta/
! https://maldita.es/malditobulo/2020/11/25/jordi-evole-el-hormiguero-bitcoin-revolution-timo-twitter/
! https://maldita•es/malditobulo/2020/12/02/lidl-regala-robot-cocina-silvercrest-monsieur-cuisine-encuesta/
! https://maldita•es/malditobulo/2020/11/25/jordi-evole-el-hormiguero-bitcoin-revolution-timo-twitter/
||moderncomputer.net^
! https://maldita.es/malditobulo/2020/11/18/gobierno-tarjeta-debito-prepagada-covid-19-phishing-whatsapp/
! https://maldita•es/malditobulo/2020/11/18/gobierno-tarjeta-debito-prepagada-covid-19-phishing-whatsapp/
||version.gratis^
! https://maldita.es/malditobulo/2020/11/18/no-no-es-cierto-que-amancio-ortega-haya-invertido-100-millones-en-bitcoin-revolution-es-una-web-falsa/
! https://maldita•es/malditobulo/2020/11/18/no-no-es-cierto-que-amancio-ortega-haya-invertido-100-millones-en-bitcoin-revolution-es-una-web-falsa/
||starpowders.github.io^
! https://github.com/AdguardTeam/AdguardFilters/issues/69611
/^http://[a-z0-9-]{30,}\..*\.elasticbeanstalk\.com(/|$)/
@@ -7185,7 +7186,7 @@ zombooru.com##a[href="http://www.hard55.com"]
! https://github.com/DandelionSprout/adfilt/issues/198
||mysecrethoookup.com^
||mysecrethoookup.com^$popup
! https://www.bleepingcomputer.com/virus-removal/ (18/06/2021)
! https://www•bleepingcomputer•com/virus-removal/ (18/06/2021)
||toksearches.xyz^
||toksearches.xyz^$popup
||smashapps.net^
@@ -7208,7 +7209,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||searchprivacyplus.com^$popup
||powersmashsearch.com^
||powersmashsearch.com^$popup
! https://www.bleepingcomputer.com/virus-removal/remove-please-allow-to-watch-the-video
! https://www•bleepingcomputer•com/virus-removal/remove-please-allow-to-watch-the-video
||1000-dollar.cash^
||1000-dollar.cash^$popup
||1000-eur.cash^
@@ -7392,10 +7393,10 @@ zombooru.com##a[href="http://www.hard55.com"]
||95.168.170.165^
||213.227.145.147^
||213.227.149.216^
! https://twitter.com/adamziaja/status/1252234957679808513
! https://twitter•com/adamziaja/status/1252234957679808513
||wow-robotics.xyz^
||wow-robotics.xyz^$popup
! https://blog.sucuri.net/2021/05/woocommerce-credit-card-skimmer.html
! https://blog•sucuri•net/2021/05/woocommerce-credit-card-skimmer•html
||deepe.icu^
||deepe.icu^$popup
||google-analytics.buzz^
@@ -7486,7 +7487,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||paymetconfirm.com^
||paymetconfirm.com^$popup
||69.49.231.244^
! https://movsb.0x0.st/users/mia
! https://movsb•0x0•st/users/mia
||vid.me^$third-party
||5starhdporn.com^$frame,third-party
! https://github.com/DandelionSprout/adfilt/issues/228
@@ -7599,17 +7600,17 @@ zombooru.com##a[href="http://www.hard55.com"]
||pc-my-protection.xyz^$popup
||beta-news.org^
! https://github.com/DandelionSprout/adfilt/pull/266
! https://www.virustotal.com/gui/domain/kirstialechulbard.space/relations
! https://www.virustotal.com/gui/ip-address/198.54.117.244/relations
! https://www•virustotal•com/gui/domain/kirstialechulbard•space/relations
! https://www•virustotal•com/gui/ip-address/198•54•117•244/relations
||dashwoodestates.com^
||dashwoodestates.com^$popup
! http://vxvault.net/ViriFiche.php?ID=44013
! https://www.virustotal.com/gui/url/8066b87ad10ddb5466bc307bb48454139572f6c8c8f80a9734275ac89cf966af/detection
! https://www.virustotal.com/gui/url/826c451929420c4da32552f967fb1cab6467405a29c65b23802aaadb6a8c7505/detection
! https://safeweb.norton.com/report/show?url=192.3.110.170
! http://vxvault•net/ViriFiche•php?ID=44013
! https://www•virustotal•com/gui/url/8066b87ad10ddb5466bc307bb48454139572f6c8c8f80a9734275ac89cf966af/detection
! https://www•virustotal•com/gui/url/826c451929420c4da32552f967fb1cab6467405a29c65b23802aaadb6a8c7505/detection
! https://safeweb•norton•com/report/show?url=192•3•110•170
||192.3.110.170^
||192.3.110.170^$popup
! https://forums.malwarebytes.com/topic/278209-removal-instructions-for-socialsearchconverter/
! https://forums•malwarebytes•com/topic/278209-removal-instructions-for-socialsearchconverter/
||socialsearchconverter.com^
||install.socialsearchconverter.com^
||install.socialsearchconverter.com^$popup
@@ -7621,7 +7622,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||notify-service.com^$popup
||install.stream-all.com^
||install.stream-all.com^$popup
! copied over from https://github.com/uBlockOrigin/uAssets/issues/9848
! Copied over from https://github.com/uBlockOrigin/uAssets/issues/9848
||gghacks.com^
||gghacks.com^$popup
||rewardsgiantusa.com^
@@ -7638,11 +7639,11 @@ zombooru.com##a[href="http://www.hard55.com"]
||d1xkyo9j4r7vnn.cloudfront.net^
||d1xkyo9j4r7vnn.cloudfront.net^$popup
||onlinepromotionsusa.com^
! https://securelist.com/apkpure-android-app-store-infected/101845/
! https://www.virustotal.com/gui/url/866a25343864f03dc5a10105fda523bfbb6ed09c486d07fd31ca2b5306440089/detection
! https://securelist•com/apkpure-android-app-store-infected/101845/
! https://www•virustotal•com/gui/url/866a25343864f03dc5a10105fda523bfbb6ed09c486d07fd31ca2b5306440089/detection
||wcf.seven1029.com^
||wcf.seven1029.com^$popup
! https://www.virustotal.com/gui/url/9c66e331e455dc5c5c9d06e1a537580c9e4db279182d2285c07783e837806a16/detection
! https://www•virustotal•com/gui/url/9c66e331e455dc5c5c9d06e1a537580c9e4db279182d2285c07783e837806a16/detection
||foodin.site^
||foodin.site^$popup
! https://github.com/AdguardTeam/AdguardFilters/issues/91506#issuecomment-904080849
@@ -7663,25 +7664,25 @@ zombooru.com##a[href="http://www.hard55.com"]
||totaladblocker.xyz^$popup
||totalwebshield.xyz^
||totalwebshield.xyz^$popup
! https://www.virustotal.com/gui/file/c683bc3da4966110b419ac54d09a54ce798efdb51be398331d9ce011e2636fa9/community
! https://www.virustotal.com/gui/url/5618023ed5a768d7f879c0d599b9ba7cff0e9171201981256eeaf5ce8eb09fdb/detection
! https://www.virustotal.com/gui/url/8cf9ca3359f17cf92b9b3e5fdab30e29be23f08e66c8c5396c9410fcb91f7c3c/detection
! https://www•virustotal•com/gui/file/c683bc3da4966110b419ac54d09a54ce798efdb51be398331d9ce011e2636fa9/community
! https://www•virustotal•com/gui/url/5618023ed5a768d7f879c0d599b9ba7cff0e9171201981256eeaf5ce8eb09fdb/detection
! https://www•virustotal•com/gui/url/8cf9ca3359f17cf92b9b3e5fdab30e29be23f08e66c8c5396c9410fcb91f7c3c/detection
||91.241.19.38^
||91.241.19.38^$popup
! https://www.virustotal.com/gui/url/46e095c35d83e2dd0b98df4b5844d3d87948de0c930a618600121020a514c801/detection
! https://safeweb.norton.com/report/show?url=telete.in
! https://www.siteadvisor.com/sitereport.html?url=telete.in
! https://www•virustotal•com/gui/url/46e095c35d83e2dd0b98df4b5844d3d87948de0c930a618600121020a514c801/detection
! https://safeweb•norton•com/report/show?url=telete•in
! https://www•siteadvisor•com/sitereport•html?url=telete•in
||telete.in^
||telete.in^$popup
! https://www.virustotal.com/gui/file/e63b2d03e3fee2d538f8bd721b61dd3641284fa941087d846dea6f15cab40308/community
! https://www.virustotal.com/gui/url/fbbc8a671bff32539bd829a76f6df9f364a21ac2279922e64e3ec494a1669dd3/detection
! https://www•virustotal•com/gui/file/e63b2d03e3fee2d538f8bd721b61dd3641284fa941087d846dea6f15cab40308/community
! https://www•virustotal•com/gui/url/fbbc8a671bff32539bd829a76f6df9f364a21ac2279922e64e3ec494a1669dd3/detection
||kiff.tech^
||kiff.tech^$popup
! https://www.virustotal.com/gui/domain/kiff.tech/relations
! https://www.virustotal.com/gui/url/dc038496b1b5358b97f89440135ec91258b406c40859a2cd95983dc7a81e0cfa/detection
! https://www•virustotal•com/gui/domain/kiff•tech/relations
! https://www•virustotal•com/gui/url/dc038496b1b5358b97f89440135ec91258b406c40859a2cd95983dc7a81e0cfa/detection
||45.90.58.90^
! https://www.virustotal.com/gui/file/e565ba89d034418fd26a5f642f6eeee4d72ee3b8dc69523419b7ca8dfd452730/community
! https://www.virustotal.com/gui/url/e3a9189a1e1256beba8e0fc3abfeab6acb09f7f8cabfd973e22be9f77bb6886f/detection
! https://www•virustotal•com/gui/file/e565ba89d034418fd26a5f642f6eeee4d72ee3b8dc69523419b7ca8dfd452730/community
! https://www•virustotal•com/gui/url/e3a9189a1e1256beba8e0fc3abfeab6acb09f7f8cabfd973e22be9f77bb6886f/detection
||95.85.89.98^
||95.85.89.98^$popup
! https://github.com/DandelionSprout/adfilt/issues/267
@@ -7705,7 +7706,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||103.169.90.205^
||103.169.90.205^$popup
! https://github.com/DandelionSprout/adfilt/pull/281
! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
! https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
||125.44.43.45^
||125.44.43.45^$popup
||182.121.8.240^
@@ -7726,10 +7727,10 @@ zombooru.com##a[href="http://www.hard55.com"]
||190.238.183.5^$popup
||27.220.253.78^
||27.220.253.78^$popup
! https://www.virustotal.com/gui/file/0374ead74fa807fb1737d8829fdb5bad6c93779f6b9eb7162eddabff7a64acff/community
! https://www•virustotal•com/gui/file/0374ead74fa807fb1737d8829fdb5bad6c93779f6b9eb7162eddabff7a64acff/community
||esetnode32-antiviru.ydns.eu^
||esetnode32-antiviru.ydns.eu^$popup
! https://www.joesandbox.com/analysis/486636/0/html#domains
! https://www•joesandbox•com/analysis/486636/0/html#domains
||aieov.com^
||aieov.com^$popup
! Relations to the original domain
@@ -7844,20 +7845,20 @@ zombooru.com##a[href="http://www.hard55.com"]
||army-glo.scrollingsystem.com^
||mcafee12.tt.omtrdc.net^
||trolleydrop.info^
! https://www.virustotal.com/gui/ip-address/70.32.1.32/relations
! https://www•virustotal•com/gui/ip-address/70•32•1•32/relations
||cd.org^
! https://www.virustotal.com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community
! https://www•virustotal•com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community
! https://github.com/DandelionSprout/adfilt/commit/f7f114945c83b339be5cdd848e229680d9918abb#commitcomment-57642875
||23.94.26.138^
||23.94.26.138^$popup
! https://github.com/DandelionSprout/adfilt/pull/298
! https://www.virustotal.com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community
! https://www•virustotal•com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community
||205.185.126.200^
||205.185.126.200^$popup
! https://www.virustotal.com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community
! https://www•virustotal•com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community
||185.243.56.167^
||185.243.56.167^$popup
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
||123.10.224.135^
||123.10.224.135^$popup
||59.47.187.147^
@@ -7952,9 +7953,9 @@ zombooru.com##a[href="http://www.hard55.com"]
||119.250.236.122^$popup
||112.30.110.58^
||112.30.110.58^$popup
! https://www.virustotal.com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community
! https://www•virustotal•com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community
||pcae.de^
! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
! https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
||117.196.49.21^
||117.196.49.21^$popup
||115.55.54.234^
@@ -7963,22 +7964,22 @@ zombooru.com##a[href="http://www.hard55.com"]
||115.52.17.123^$popup
||182.59.69.21^
||182.59.69.21^$popup
! https://www.virustotal.com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community
! https://www•virustotal•com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community
||chip-secured-download.de^
||chip-secured-download.de^$popup
! https://www.virustotal.com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb
! https://www•virustotal•com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb
! Domains which resolve to this (already blocked) IP - for users of HOSTs/Domains/uBlock Origin
||nctylivpwhpby.com^
||nctylivpwhpby.com^$popup
||phhitgjxsit.com^
||phhitgjxsit.com^$popup
! https://www.virustotal.com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1
! https://www•virustotal•com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1
||saimission.org^
||saimission.org^$popup
! https://www.virustotal.com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1
! https://www•virustotal•com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1
||grub-wa-saya.duckdns.org^
||grub-wa-saya.duckdns.org^$popup
! https://www.virustotal.com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations
! https://www•virustotal•com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations
||driversupport.com^
! A PUP and scam website
||mycleanpc.com^
@@ -7989,10 +7990,10 @@ zombooru.com##a[href="http://www.hard55.com"]
! The main website for the MyCleanPC company
||realdefen.se^
! Vermilion Strike
! https://www.virustotal.com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations
! https://www•virustotal•com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations
||160.202.163.100^
||160.202.163.100^$popup
! https://www.virustotal.com/gui/ip-address/160.202.163.100/relations
! https://www•virustotal•com/gui/ip-address/160•202•163•100/relations
||microsoftkernel.com^
||microsoftkernel.com^$popup
||microsofthk.com^
@@ -8008,13 +8009,13 @@ zombooru.com##a[href="http://www.hard55.com"]
||pushbizapi.com^
||pushbizapi.com^$popup
! https://github.com/DandelionSprout/adfilt/pull/303
! https://www.virustotal.com/gui/file/37328efa73c248b460aba605d7745b024f31ab7ab864e1af273e9a197a188f42/community
! https://www•virustotal•com/gui/file/37328efa73c248b460aba605d7745b024f31ab7ab864e1af273e9a197a188f42/community
||45.95.169.115^
||45.95.169.115^$popup
! https://www.virustotal.com/gui/file/03e4533ba8874c2f4dcdb94bd135914fa4c22ed477d7c0395dc2322b6468e249/community
! https://www•virustotal•com/gui/file/03e4533ba8874c2f4dcdb94bd135914fa4c22ed477d7c0395dc2322b6468e249/community
||45.148.120.80^
||45.148.120.80^$popup
! https://www.virustotal.com/gui/file/1a782cab036efa567c2c42b7bae9452bf735be72f0b00d68f6dcba48cea526fa/community
! https://www•virustotal•com/gui/file/1a782cab036efa567c2c42b7bae9452bf735be72f0b00d68f6dcba48cea526fa/community
||85.239.33.9^
||85.239.33.9^$popup
! Relations to the domain above
@@ -8046,13 +8047,13 @@ zombooru.com##a[href="http://www.hard55.com"]
||1log-wellsfargo.serveftp.com^$popup
||eposcardokubo.serveftp.com^
||eposcardokubo.serveftp.com^$popup
! https://www.virustotal.com/gui/file/8a39f18caa77d52e80bec05f584ec50e733a3be1e33551d8902e95b9b0bfe6c0/community
! https://www•virustotal•com/gui/file/8a39f18caa77d52e80bec05f584ec50e733a3be1e33551d8902e95b9b0bfe6c0/community
||107.173.176.183^
||107.173.176.183^$popup
! https://www.virustotal.com/gui/file/54054209c921a68f12a9b29d6e84f1b45cb417bc0b5a99356a245727e0a41e40/community
! https://www•virustotal•com/gui/file/54054209c921a68f12a9b29d6e84f1b45cb417bc0b5a99356a245727e0a41e40/community
||45.148.120.171^
||45.148.120.171^$popup
! https://twitter.com/soranker0/status/1449491402409185283
! https://twitter•com/soranker0/status/1449491402409185283
://disordgift.
://disordgift.$popup
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-950330114
@@ -8094,7 +8095,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||kokotrokot.com^$popup
!!!?next_url=,popup (https://github.com/AdguardTeam/AdguardFilters/issues/108072#issuecomment-1021534226)
?uclickhash=,popup
! https://www.upwork.com/freelance-jobs/apply/Integarte-push-notification-for-chrome_~013c73ed9282225184/
! https://www•upwork•com/freelance-jobs/apply/Integarte-push-notification-for-chrome_~013c73ed9282225184/
||mugrikees.com^
||mugrikees.com^$popup
||alpha-news.org^
@@ -8109,7 +8110,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||youutube.com^
||youutube.com^$popup
! https://github.com/DandelionSprout/adfilt/pull/348
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
||39.83.80.247^
||39.83.80.247^$popup
||68.197.33.124^
@@ -8172,7 +8173,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||103.233.216.77^$popup
||183.188.192.55^
||183.188.192.55^$popup
! https://www.virustotal.com/gui/file/3bf1b7e9bdaeaa4a5619cf26b59767637bc44193df2a0470df263b98b1fe47fe/community
! https://www•virustotal•com/gui/file/3bf1b7e9bdaeaa4a5619cf26b59767637bc44193df2a0470df263b98b1fe47fe/community
||198.23.255.14^
||198.23.255.14^$popup
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-971512075
@@ -8189,7 +8190,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||91.121.67.60^$popup
||172.67.186.189^
||172.67.186.189^$popup
! https://www.virustotal.com/gui/url/af8f443208f4e86d469549b219fccbeb43b7cae40be5f1b4c4e5083e27fc8111
! https://www•virustotal•com/gui/url/af8f443208f4e86d469549b219fccbeb43b7cae40be5f1b4c4e5083e27fc8111
||inconclusive-pyrite-grandparent.glitch.me^
||inconclusive-pyrite-grandparent.glitch.me^$popup
||delicate-tame-angora.glitch.me^
@@ -8210,10 +8211,10 @@ zombooru.com##a[href="http://www.hard55.com"]
||mature-periwinkle-advantage.glitch.me^$popup
||tough-numerous-lemur.glitch.me^
||tough-numerous-lemur.glitch.me^$popup
! https://scammer.info/t/mcafee-phish/83725
! https://scammer•info/t/mcafee-phish/83725
||securefirst.us-east-1.linodeobjects.com^
||securefirst.us-east-1.linodeobjects.com^$popup
! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
! https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
||39.65.72.211^
||39.65.72.211^$popup
||42.238.151.197^
@@ -8245,28 +8246,28 @@ zombooru.com##a[href="http://www.hard55.com"]
||t.tonightshookup.com^$popup
||yourladiefun.life^
||yourladiefun.life^$popup
! https://www.virustotal.com/gui/url/a2524bba49ae71297d2b408b30d058700d9c80b5b1154924cafe190ec3e605a6/detection
! https://www•virustotal•com/gui/url/a2524bba49ae71297d2b408b30d058700d9c80b5b1154924cafe190ec3e605a6/detection
||newrrb.bid^
||newrrb.bid^$popup
! https://www.virustotal.com/gui/file/2b2628a50d3b39b0fa2395d487bf62b00e37cdae847ff76ee58399bbe4e9f7b3/community
! https://www•virustotal•com/gui/file/2b2628a50d3b39b0fa2395d487bf62b00e37cdae847ff76ee58399bbe4e9f7b3/community
||194.87.138.20^
||194.87.138.20^$popup
! https://www.virustotal.com/gui/file/b320bc7a9151d70daca038c4356ca89bfcd4918bcd6f0f73683a27a6a72467ae/community
! https://www•virustotal•com/gui/file/b320bc7a9151d70daca038c4356ca89bfcd4918bcd6f0f73683a27a6a72467ae/community
||103.167.92.73^
||103.167.92.73^$popup
! https://www.virustotal.com/gui/file/6146dfe56dcb49e1b843624a44e204754e15625a4f94b230b59a5cafc924f618/community
! https://www•virustotal•com/gui/file/6146dfe56dcb49e1b843624a44e204754e15625a4f94b230b59a5cafc924f618/community
||bursakulis.com^
||bursakulis.com^$popup
! https://www.virustotal.com/gui/url/b333c49efa4d399e65c5e2d96a905b380acbca58a3e3052b7bd7cfcb3e0e81ee
! https://www•virustotal•com/gui/url/b333c49efa4d399e65c5e2d96a905b380acbca58a3e3052b7bd7cfcb3e0e81ee
||610418.selcdn.ru^
||610418.selcdn.ru^$popup
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-977912975
! https://www.tv2.no/nyheter/14368524/
! https://www•tv2•no/nyheter/14368524/
||alexstewartinternationalltd.rw^
||alexstewartinternationalltd.rw^$popup
||vps.re^
||vps.re^$popup
! https://www.tek.no/i/wOVv0o/
! https://www•tek•no/i/wOVv0o/
||21steditionnaturalgh.com^
||21steditionnaturalgh.com^$popup
! https://github.com/iam-py-test/investigations/blob/main/2021/11/24/1.md
@@ -8287,7 +8288,7 @@ zombooru.com##a[href="http://www.hard55.com"]
! https://github.com/uBlockOrigin/uAssets/pull/10620
||shadyclient.net^
||shadyclient.net^$popup
! https://www.virustotal.com/gui/file/d546509ab6670f9ff31783ed72875dfc0f37fa2b666bd5870eecaaed2ebea4a8/community
! https://www•virustotal•com/gui/file/d546509ab6670f9ff31783ed72875dfc0f37fa2b666bd5870eecaaed2ebea4a8/community
||58.249.74.79^
||58.249.74.79^$popup
||27.45.14.109^
@@ -8312,8 +8313,8 @@ zombooru.com##a[href="http://www.hard55.com"]
||totalnicefeed.com^$popup
! https://github.com/iam-py-test/investigations/blob/main/2021/11/28/2.md
||bestlifeoffer20.com^
! https://scammer.info/t/password-stealer/84348
! https://bazaar.abuse.ch/sample/462a689d171f543c10efa08e963996d382585b67a6b298ec40d64f924adfb47a/
! https://scammer•info/t/password-stealer/84348
! https://bazaar•abuse•ch/sample/462a689d171f543c10efa08e963996d382585b67a6b298ec40d64f924adfb47a/
||youtube.com/watch?v=8nY7SnvNxH4^
||youtube.com/watch?v=8nY7SnvNxH4^$popup
||bit.ly/3p8kN5V^
@@ -8321,7 +8322,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||mediafire.com/file/at2tvnao5x6ivdo/EngineOwning.rar/$popup
||download2264.mediafire.com/pnk44f5ci9rg/at2tvnao5x6ivdo/EngineOwning.rar^
||download2264.mediafire.com/pnk44f5ci9rg/at2tvnao5x6ivdo/EngineOwning.rar^$popup
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
||110.89.59.135^
||110.89.59.135^$popup
||113.116.89.1^
@@ -8344,22 +8345,22 @@ zombooru.com##a[href="http://www.hard55.com"]
||115.194.38.143^$popup
||61.52.79.32^
||61.52.79.32^$popup
! https://scammer.info/t/pihishing-site-claiming-to-hold-a-ups-package-that-needs-payment/84466
! https://scammer•info/t/pihishing-site-claiming-to-hold-a-ups-package-that-needs-payment/84466
://ups-dk.$denyallow=dk|nu|se|no|fo|gl|ups.com,domain=ups-dk.*
! https://www.virustotal.com/gui/url/269d374b629d7896da1f9e7449bd5afecf6284a9a564244f96a71e5192363635?nocache=1
! https://www•virustotal•com/gui/url/269d374b629d7896da1f9e7449bd5afecf6284a9a564244f96a71e5192363635?nocache=1
||lowseelan.com^
||lowseelan.com^$popup
! https://www.virustotal.com/gui/file/50fd813cf8fe981e6aee179f8ba394e5527c5128b84c328f9f8347cd994bbc42/community
! https://www•virustotal•com/gui/file/50fd813cf8fe981e6aee179f8ba394e5527c5128b84c328f9f8347cd994bbc42/community
||dl02.s3.amazonaws.com/installers/747947/oi_picasa38-setupexe.exe^
||dl02.s3.amazonaws.com/installers/747947/oi_picasa38-setupexe.exe^$popup
! https://www.virustotal.com/gui/file/2ea599605c4d65902943f12e1114a71af7a40fa7dffbf018b0ee3e7a61aaeaa3/community
! https://www•virustotal•com/gui/file/2ea599605c4d65902943f12e1114a71af7a40fa7dffbf018b0ee3e7a61aaeaa3/community
||dl02.s3.amazonaws.com/installers/424531/2gzbsoj4gxb.exe^
||dl02.s3.amazonaws.com/installers/424531/2gzbsoj4gxb.exe^$popup
! https://github.com/DandelionSprout/adfilt/pull/395
! https://www.huorong.cn/info/1531309921141.html
! https://www•huorong.cn/info/1531309921141.html
||kuaizip.com^
||kuaizip.com^$popup
! https://www.huorong.cn/info/1618397948649.html - possible malware
! https://www•huorong.cn/info/1618397948649.html - possible malware
! ||zhuangjizhuli.com^
! ||zhuangjizhuli.com^$popup
! ||zhuangjizhuli.net^
@@ -8367,22 +8368,22 @@ zombooru.com##a[href="http://www.hard55.com"]
! https://github.com/uBlockOrigin/uAssets/pull/9656
||geekotg.com^
||geekotg.com^$popup
! https://www.huorong.cn/info/1526627586130.html
! https://www•huorong.cn/info/1526627586130.html
||xiaobaixitong.com^
||xiaobaixitong.com^$popup
! https://www.huorong.cn/info/1577158839403.html
! https://www•huorong.cn/info/1577158839403.html
||daque.cn^
||daque.cn^$popup
! https://www.huorong.cn/info/1598957552515.html
! https://www•huorong.cn/info/1598957552515.html
||dabaicai.com^
||dabaicai.com^$popup
! https://www.huorong.cn/info/1617368984641.html
! https://www•huorong.cn/info/1617368984641.html
||qqfzn.com^
||qqfzn.com^$popup
! https://github.com/uBlockOrigin/uAssets/pull/10017
||flash.cn^
||flash.cn^$popup
! https://www.nrk.no/vestfoldogtelemark/1.15750360
! https://www•nrk.no/vestfoldogtelemark/1.15750360
||dundeehills.group^
||dundeehills.group^$popup
!+ NOT_OPTIMIZED
@@ -8401,8 +8402,8 @@ zombooru.com##a[href="http://www.hard55.com"]
||royyer.us/R8cWuvQjhtM^
||royyer.us/R8cWuvQjhtM^$popup
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-988127908
! https://www.tek.no/i/lVeQAe/
! https://www.nkom.no/aktuelt/ikke-trykk-pa-lenker-i-sms--for-du-er-helt-sikker/
! https://www•tek.no/i/lVeQAe/
! https://www•nkom.no/aktuelt/ikke-trykk-pa-lenker-i-sms--for-du-er-helt-sikker/
||eccolabgroup.com^
||eccolabgroup.com^$popup
||galerijajava.ba^
@@ -8419,7 +8420,7 @@ zombooru.com##a[href="http://www.hard55.com"]
! https://scammer.info/t/crypto-scammers-onceagain/85354
||business.google.com/website/billyandscapedesign^
||business.google.com/website/billyandscapedesign^$popup
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
||123.10.225.196^
||123.10.225.196^$popup
||122.192.106.84^
@@ -8498,10 +8499,10 @@ zombooru.com##a[href="http://www.hard55.com"]
! Other
||crashfixes.com^
||crashfixes.com^$popup
! https://www.virustotal.com/gui/url/c25fe34c05cc8e9136027a67c277e175a5d6e35af921ee37bad98bdfeea6a2f9/community
! https://www•virustotal•com/gui/url/c25fe34c05cc8e9136027a67c277e175a5d6e35af921ee37bad98bdfeea6a2f9/community
||splendid-fallacious-anaconda.glitch.me^
||splendid-fallacious-anaconda.glitch.me^$popup
! https://www.virustotal.com/gui/file/9d40ae0439ddc594b2cf64e21ad0fdea9bb440524298e3a6bcfcc1fb417f1ed2/relations
! https://www•virustotal•com/gui/file/9d40ae0439ddc594b2cf64e21ad0fdea9bb440524298e3a6bcfcc1fb417f1ed2/relations
||91.240.118.172^
||91.240.118.172^$popup
! "Press Allow to continue"
@@ -8518,7 +8519,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||lucymods.com^$popup
||gluegames.xyz^
||gluegames.xyz^$popup
! https://twitter.com/iam_py_test/status/1496259425493225472
! https://twitter•com/iam_py_test/status/1496259425493225472
||sites.google.com/view/groundworkssolutions/contact-us^
||sites.google.com/view/groundworkssolutions/contact-us^$popup
||sites.google.com/view/groundworkssolutions/^
@@ -8542,7 +8543,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||download2340.mediafire.com/eift3ac9qmig/y65v1rk0zy7ot4a/The__Setup__With__File.zip^$popup
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1074966240
||melding.link^
! https://twitter.com/MBThreatIntel/status/1509956416311742464
! https://twitter•com/MBThreatIntel/status/1509956416311742464
||xposednews.xyz^
||xposednews.xyz^$popup
||tomguide.xyz^
@@ -8581,7 +8582,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||top3hostngc.xyz^$popup
||198.199.120.251^
||198.199.120.251^$popup
! https://www.telia.no/kundeservice/mobil/malware-flubot-android/
! https://www•telia.no/kundeservice/mobil/malware-flubot-android/
!+ NOT_OPTIMIZED
/^https?://(www\.)?[a-z0-9-]{1,}\.[a-z]{2,17}/[a-z0-9]/\?[a-z0-9.-]{8,}$/
! A Discord conversation I had about Throneful
@@ -8623,7 +8624,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||cumpussyy.uno^$popup
||195.201.253.130^
||195.201.253.131^
! The bottom download button on https://www.sushichop.com/
! The bottom download button on https://www•sushichop•com/
||installiq.com^
||installiq.com^$popup
||specgoal.com^
@@ -8653,7 +8654,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||96.47.230.68^
||96.47.230.69^
||96.47.230.70^
! https://securitytrails.com/list/ns/ns1.fastthinkingdns.com
! https://securitytrails•com/list/ns/ns1•fastthinkingdns•com
||highercaptcha-settle.
||highercaptcha-settle.$popup
||highercaptchasettle.
@@ -8731,7 +8732,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||online-guard.com^
||online-guard.com^$popup
/mcafee-safe-browsing/?*=*&*=*&*=*&*=*&*=*&*=,popup,domain=~fake-site-with-malware.*
! https://twitter.com/iam_py_test/status/1545164642346930176
! https://twitter•com/iam_py_test/status/1545164642346930176
||amazon-security-info.lnk.to^
||amazon-security-info.lnk.to^$popup
! https://github.com/AdguardTeam/AdguardFilters/issues/123968
@@ -9344,7 +9345,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||158.247.212.220^
||165.227.168.212^
! https://www.reddit.com/r/engrish/comments/w6u4uy/received_this_text_message_yesterday_i_am_very/
! https://www•reddit.com/r/engrish/comments/w6u4uy/received_this_text_message_yesterday_i_am_very/
://162.241.115.
! https://dinside.dagbladet.no/mobil/ikke-la-deg-friste/76730599
@@ -9801,7 +9802,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||51.91.66.125^
||51.178.76.105^
||147.135.253.55^
! https://github.com/uBlockOrigin/uAssets/issues/14569 → https://www.virustotal.com/gui/url/b819586938326577d759d8024abe3e0e6de1c853d6b67824daf6f613fba0f63b/detection (https://app.any.run/tasks/5914a712-1a73-4432-b89a-ca0627a24ade)
! https://github.com/uBlockOrigin/uAssets/issues/14569 → https://www•virustotal•com/gui/url/b819586938326577d759d8024abe3e0e6de1c853d6b67824daf6f613fba0f63b/detection (https://app•any•run/tasks/5914a712-1a73-4432-b89a-ca0627a24ade)
||bnbdeal.net^
||bnbdeal.net^$popup
! https://github.com/AdguardTeam/AdguardFilters/issues/129414
@@ -17785,7 +17786,7 @@ zombooru.com##a[href="http://www.hard55.com"]
://196.245.52.
://196.245.56.
! https://www.bleepingcomputer.com/news/security/hackers-push-malware-via-google-search-ads-for-vlc-7-zip-ccleaner/
! https://www•bleepingcomputer•com/news/security/hackers-push-malware-via-google-search-ads-for-vlc-7-zip-ccleaner/
://rufus.download.$popup
://virtualbox.download.$popup
://vidiq.download.$popup
@@ -18841,7 +18842,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||yourorderupdate.com^$popup
||64.132.201.92^
||64.132.201.92^$popup
! https://www.adressa.no/nyheter/trondheim/i/BWkdkw/trodde-hun-skulle-faa-en-pakke-i-posten-ble-lurt-for-titusener
! https://www•adressa.no/nyheter/trondheim/i/BWkdkw/trodde-hun-skulle-faa-en-pakke-i-posten-ble-lurt-for-titusener
||acessmygov.online^
||acessmygov.online^$popup
||centerlinkmygov.com^
@@ -20276,7 +20277,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||54.204.83.105^
||54.204.83.105^$popup
! https://github.com/DandelionSprout/adfilt/issues/808
! https://www.mandiant.com/resources/blog/tracking-evolution-gootloader-operations (26/01/2023)
! https://www•mandiant.com/resources/blog/tracking-evolution-gootloader-operations (26/01/2023)
||jonathanbartz.com^
||jonathanbartz.com^$popup
||jp.imonitorsoft.com^
@@ -20739,7 +20740,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||zondeucearixes.com^$popup
||85.17.80.16^
||85.17.80.16^$popup
! https://www.adressa.no/nyheter/trondheim/i/Moq2wR/svindlere-kaarer-vinnere-i-konkurranser-gir-en-daarlig-foelelse-aa-forklare-at-dette-bare-er-tull
! https://www•adressa.no/nyheter/trondheim/i/Moq2wR/svindlere-kaarer-vinnere-i-konkurranser-gir-en-daarlig-foelelse-aa-forklare-at-dette-bare-er-tull
||sitey.me^
! https://github.com/AdguardTeam/AdguardFilters/issues/151479
||agazpeppily.live^
@@ -21527,7 +21528,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||usedhutsold.live^$popup
||57.128.71.215^
||57.128.71.215^$popup
/&[a-z]{1,2}=[a-zA-Z0-9]{0,}%[a-zA-Z0-9%]{1000,}$/
/^.*&[a-z]{1,2}=[a-zA-Z0-9]{0,}%[a-zA-Z0-9%]{1000,}$/
! https://github.com/AdguardTeam/AdguardFilters/issues/155936
||truanet.com^
||truanet.com^$popup
@@ -32921,7 +32922,7 @@ zombooru.com##a[href="http://www.hard55.com"]
/(//|\.|^)github\.[a-z]{2,20}(/|$)/$~third-party,domain=github.*|~com|~org|~net|~co|~blog|~community|~host|~io|~microsoft|~office|~uk|~us|~xn--fiqs8s|~dev|~archive.*
||github.sale^
||github.sale^$popup
! https://www.tv2.no/nyheter/innenriks/advarer-ikke-klikk-pa-lenken/16040614/
! https://www•tv2.no/nyheter/innenriks/advarer-ikke-klikk-pa-lenken/16040614/
||0nedr1ved0cumentonline.com^
||0nedr1ved0cumentonline.com^$popup
||88godetailsvc.com^
@@ -44658,12 +44659,12 @@ zombooru.com##a[href="http://www.hard55.com"]
! ——— Standard malware that I stumbled upon on my own ———
! http://www.toorgle.net/results.php?q=fetishkitsch&security=666
! http://www•toorgle•net/results•php?q=fetishkitsch&security=666
||downloadprovider.me^
||downloadprovider.me^$popup
##a[href*=".downloadprovider.me/"]
toorgle.net##.join
! https://www.riverbender.com/articles/details/two-charged-in-connection-of-the-stallon-drug-raid-in-wood-river-46877.cfm
! https://www•riverbender•com/articles/details/two-charged-in-connection-of-the-stallon-drug-raid-in-wood-river-46877•cfm
||cash93.com^
||cash93.com^$popup
||a4alig.com^
@@ -44688,7 +44689,7 @@ toorgle.net##.join
||slimxketo.com^$popup
||works35.com^
||works35.com^$popup
! Various ex-affiliate links at www.zombooru.com
! Various ex-affiliate links at www•zombooru•com
||allowandgo.com^
||allowandgo.com^$popup
||aksuu.ru^
@@ -44715,7 +44716,7 @@ toorgle.net##.join
||traffsend.me^$popup
||wwopenclick.club^
||wwopenclick.club^$popup
! Spam comments at https://www.accountkiller.com/en/delete-htcdev-account
! Spam comments at https://www•accountkiller•com/en/delete-htcdev-account
||azhydroxychloroquine.com^
||azhydroxychloroquine.com^$popup
||wisig.org^
@@ -44737,14 +44738,14 @@ toorgle.net##.join
! The Jerma985 Discord server
||crazycrabreedville.com^
||crazycrabreedville.com^$popup
! https://flclever.weebly.com/pixie-hollow-mini-games.html (06/05/2021)
! https://flclever.weebly•com/pixie-hollow-mini-games•html (06/05/2021)
||messium.info^
||messium.info^$popup
! Various Google searches
://hullcitytigers.com^
! Various search results for 'kelloggs tresor' in Norwegian (30/05/2021)
/pgxhtogrzm-
! https://fx-onlinee.blogspot.com/2021/06/?r=Bergens-Tidende-Flertallet-av-fastlegene-i-Trondheim-sier-nei-til-Janssen-vaksinen-Umulig-%C3%A5-ta-det-ansvaret-seo+aj
! https://fx-onlinee•blogspot•com/2021/06/?r=Bergens-Tidende-Flertallet-av-fastlegene-i-Trondheim-sier-nei-til-Janssen-vaksinen-Umulig-%C3%A5-ta-det-ansvaret-seo+aj
||blogspot.com/*/?r=*-seo+aj
! Fake security sites that think every single domain is a supervirus and which try to make you install PUP (Most commonly SpyHunter)
||malwarecleanerpro.com^
@@ -49157,8 +49158,8 @@ toorgle.net##.join
||abnegationbanquet.com^
||abnegationbanquet.com^$popup
||192.243.61.225^
! https://twitter.com/medicinehelp/status/1550250932394409985
! https://securitytrails.com/list/ip/147.135.16.27
! https://twitter•com/medicinehelp/status/1550250932394409985
! https://securitytrails•com/list/ip/147•135•16•27
||2spendless.
||acrx.online^
||acrx.org^
@@ -49214,11 +49215,11 @@ toorgle.net##.join
||medicinecoupons.xyz^
||medicinehelp.news^
||147.135.16.27^
! https://www.google.no/search?q=mlp+g5&newwindow=1&tbm=isch&oq=mlp+g5&sclient=img
! https://www•google.no/search?q=mlp+g5&newwindow=1&tbm=isch&oq=mlp+g5&sclient=img
||ingeniovirtual.com^
! Spambot posts on Tumblr (19/09/2022)
tumblr.com#?#div[data-id][tabindex="-1"]:has(a[href^="https://href.li/?https://bit.ly/"])
! https://scambiofigu.forumcommunity.net/?t=57482915
! https://scambiofigu.forumcommunity•net/?t=57482915
||scambiofigu.net^
||scambiofigu.net^$popup
! Only links to another site's (APKPure) APKs, yet tries to promote its own browser extension on the alleged download pages, which comes across as suspicious
@@ -49494,8 +49495,8 @@ cdburnerxp.se##[href*="/downloadsetup.exe"]
||ru-torproject.ru^$popup
||anapatformacion.org/modules/file/tor/tor-browser.zip^
||anapatformacion.org/modules/file/tor/tor-browser.zip^$popup
! https://forums.malwarebytes.com/topic/295588-support-scam-supportclientexe-and-screenconnectwindowsclientexe/ (account required)
! https://forums.malwarebytes.com/topic/295605-techsupport-scam/ (account required)
! https://forums•malwarebytes•com/topic/295588-support-scam-supportclientexe-and-screenconnectwindowsclientexe/ (account required)
! https://forums•malwarebytes•com/topic/295605-techsupport-scam/ (account required)
! https://app.any.run/tasks/0f8b5786-177a-45c0-a1de-32e0d68beff2
||123secure.org^
||123secure.org^$popup
@@ -49505,7 +49506,7 @@ cdburnerxp.se##[href*="/downloadsetup.exe"]
! Commonly set as a proxy on hacked devices (https://www.virustotal.com/gui/url/e610e7d09c614529cb8c64185717769946f5c86044ac5c31c6608e604995f577/detection)
||34.80.59.191^
||34.80.59.191^$popup
! Various domains on https://securitytrails.com/list/ip/72.14.178.174
! Various domains on https://securitytrails•com/list/ip/72•14•178•174
|http://www6.$domain=~often-used-in-malware-redirections.*
|http://www1.*&kw,domain=~often-used-in-malware-redirections.*
||megabooru.com^
@@ -49528,7 +49529,7 @@ cdburnerxp.se##[href*="/downloadsetup.exe"]
||96.126.123.244^
||173.255.194.134^
||198.58.118.167^
! https://hutudole.com/za-mu-%c9%93ullo-da-matakan-da-za-su-hana-al%c6%99alai-kwa%c9%97ayin-cin-hanci-ba-tinubu/
! https://hutudole•com/za-mu-%c9%93ullo-da-matakan-da-za-su-hana-al%c6%99alai-kwa%c9%97ayin-cin-hanci-ba-tinubu/
||123chance.net^
||123chance.net^$popup
||123links4u.net^
@@ -50293,7 +50294,7 @@ cdburnerxp.se##[href*="/downloadsetup.exe"]
||94.237.99.118^$popup
||139.45.197.249^
||139.45.197.249^$popup
! https://dnpedia.com/tlds/topm.php bizarrely listing "anahitagirted.uno" as the 622th most visited domain worldwide
! https://dnpedia•com/tlds/topm•php bizarrely listing "anahitagirted•uno" as the 622th most visited domain worldwide
||acorusinfield.life^
||acorusinfield.life^$popup
||acridlydebit.live^
@@ -51525,9 +51526,9 @@ facebook.com#?#div[class*=ImageBlockContent] .clearfix:has-text(0nl!ne)
$csp=upgrade-insecure-requests,domain=apache.org|gnu.org|washington.edu|nyu.edu|ufl.edu|oecd.org|bu.edu|wikidot.com|alternativenation.net
! ——— Anti-'Malware comments' (Currently Disqus-specific) ———
! https://myip.ms/info/limitexcess
! https://myip•ms/info/limitexcess
! https://myip.ms/info/memberarea/My_Account.html
! https://myip•ms/info/memberarea/My_Account•html
@@ -51541,7 +51542,7 @@ $csp=upgrade-insecure-requests,domain=apache.org|gnu.org|washington.edu|nyu.edu|
! This section covers ones that would not normally be found in EasyList or AdGuard Base, for instance McAfee WebAdvisor (which also tries to change the search engine)
||webadvisorc.rest.gti.mcafee.com^
||mip.api.mcafeewebadvisor.com^
! https://get.adobe.com/no/reader/
! https://get•adobe•com/no/reader/
get.adobe.com###offersInformationPane
! Gigabyte APP Center (which use sneaky tricks to install a Norton 360 trial period; May require «AdGuard for Windows»)
||mb.download.gigabyte.com/FileList/Swhttp/DriverUpd/ANTIVIRUS^
@@ -51874,7 +51875,7 @@ www.microsoft.com##a[data-pfns][data-pfns^="9"][data-pfns*="dev."]
www.microsoft.com##a[data-pfns][href*=pacman]
www.microsoft.com##a[data-pfns][href*=pac-men]
! https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
! https://eclypsium•com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
|http://mb.download.gigabyte.com/FileList/Swhttp/LiveUpdate4^
! (Presumably anonymous) E-mail tips
@@ -1,9 +1,10 @@
! Title: 💊 Dandelion Sprout's Anti-Malware List (for AdGuard)
! Version: 20August2024v1
! Version: 17September2024v1
! Expires: 2 days
! Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists
! (Note to self, only applicable to uBO: When 1.59.1 goes stable, implement "*$ipaddress=(...),all" for the IP addresses, alongside the previous syntaxing as the case is for AdGuard Browser Extension.)
! Homepage: https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#-english
! ——— Bad top-level domains ———
@@ -20,7 +21,7 @@
! Palau (Put on break due to too many whitelistings being needed)
!!!||pw^$document,domain=~libgen.pw|~petridish.pw|~palaugov.pw|~dpc.pw|~buttercup.pw|~rezka.pw|~darkcrystal.pw|~xor.pw|~fullhdfilmizlesene.pw|~gopass.pw|~vost.pw|~core.pw|~bittor.pw|~plutonium.pw|~nitter.pw|~kge.pw
! Legitimate use is almost non-existent, but has a tiny userbase in Japan. Its extreme common-ness in malware redirections means that the entry will be kept forever.
||top^$document,domain=~caitlin.top|~callmebymygender.top|~corriente.top|~gdtot.top|~nicenature.top|~reminder.top|~magocoro.top|~castlevania.top|~suiten.top|~shucks.top|~1stream.top|~ambr.top|~techblog.top|~changlam10.top|~changlam11.top|~pdcdn1.top|~mastodon.top|~pressplay.top|~chillx.top|~strims.top|~thedesk.top|~audioforyou.top|~pegelinux.top|~awavenue.top|~reyhub.top
||top^$document,domain=~caitlin.top|~callmebymygender.top|~corriente.top|~gdtot.top|~nicenature.top|~reminder.top|~magocoro.top|~castlevania.top|~suiten.top|~shucks.top|~1stream.top|~ambr.top|~techblog.top|~changlam10.top|~changlam11.top|~pdcdn1.top|~mastodon.top|~pressplay.top|~chillx.top|~strims.top|~thedesk.top|~audioforyou.top|~pegelinux.top|~awavenue.top|~reyhub.top|~iboxs.top
! International topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent.
||loan^$document
!!!||agency^$document,domain=~battlefield.agency|~baam.agency|~robotzebra.agency|~uphotel.agency|~ws.agency (Can't remember the last time I saw it used in a redirection train.)
@@ -29,7 +30,7 @@
!!!||ooo^$document,domain=~toast.ooo
! (https://github.com/DandelionSprout/adfilt/issues/999)
!!!@@://oo*.ooo/$document
! https://bgp.he.net/AS202492#_prefixes (17/07/2022)
! https://bgp.he•net/AS202492#_prefixes (17/07/2022)
!!!||monster^$document,domain=~egybest.monster|~yts.monster|~cloudcdn.monster|~fedi.monster|~rollenspiel.monster|~tts.monster|~geometry.monster
! https://github.com/AdguardTeam/AdguardFilters/issues/131156
!!!||sbs^$document,domain=~ecopulse.sbs
@@ -174,12 +175,12 @@ play.google.com#?#div[class$=" "] > div[class*=" "][jscontroller] > *:has([href$
! ——— Links to PC "optimising" "tool" PUPs that'll most likely stuff your PC full of nagware and malware ———
! ¤¤¤ ReImagePlus (Also added to "uBlock Filters - Badware Risks") ¤¤¤
! https://windowsreport.com/extend-windows-laptop-battery-life/
! https://windowsreport•com/extend-windows-laptop-battery-life/
windowsreport.com##.code-block
! https://appuals.com/fix-error-0x800701e3-on-windows-7-8-1-10/
! https://appuals•com/fix-error-0x800701e3-on-windows-7-8-1-10/
appuals.com##.info.box
appuals.com##.appua-reimage-top
! https://ugetfix.com/ask/how-to-fix-windows-store-error-0x8000ffff/
! https://ugetfix•com/ask/how-to-fix-windows-store-error-0x8000ffff/
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es##div.attention-button-box-green
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es##.sidebar_download_inner
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es##.primary_download
@@ -189,13 +190,13 @@ ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es#?#.ga-download:has-
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es##.download-button-offer-header
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es#?#h2:has-text(/^Repair\syour\sErrors\sautomatical{2}y$/i)
ugetfix.com,sauguspc.lt,wyleczpc.pl,sichernpc.de,pcseguro.es#?#h2:has-text(/^Repair\syour\sErrors\sautomatical{2}y$/i) + p
! https://www.thewindowsclub.com/fix-windows-update-error-0xc1900130-on-windows-10
! https://www•thewindowsclub•com/fix-windows-update-error-0xc1900130-on-windows-10
thewindowsclub.com#?#.entry-content > div > strong:has-text(find & fix Windows error)
thewindowsclub.com##div[style^="float: none; margin:10px "]
! https://www.majorgeeks.com/files/details/patch_my_pc.html
! https://www•majorgeeks•com/files/details/patch_my_pc•html
majorgeeks.com##b:has(a[target^=reimage])
||majorgeeks.com/images/icons/red_icon_18x17px.png$image
! https://www.2-spyware.com/remove-redirector-gvt1-com.html
! https://www•2-spyware•com/remove-redirector-gvt1-com•html
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk#?#.attention-button-wrap:has-text(Reimage)
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk##.ui-content > .win
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk##.sidebar_download_inner > :not(.voting-box, .colorbg-grey)
@@ -209,38 +210,38 @@ majorgeeks.com##b:has(a[target^=reimage])
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk#?#a:has-text(Reimage)
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk##.quick-download-button-text
! ¤¤¤ ScanUtilities ¤¤¤
! https://www.bynarycodes.com/fix-windows-10-update-error-0x80070006/
! https://www•bynarycodes•com/fix-windows-10-update-error-0x80070006/
bynarycodes.com##div[class^=bynar-content_]
bynarycodes.com##.panel:has(a[href*="scanutilities.com"])
! ¤¤¤ Driver Easy ¤¤¤
! https://www.drivereasy.com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/
! https://www•drivereasy•com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/
drivereasy.com#?#.pakb-content ol:has-text(Download and install Driver Easy)
drivereasy.com#?#.pakb-content p:has-text(Driver Easy)
drivereasy.com#?#.pakb-content div.info.note:has-text(drivereasy.com)
! https://www.drivereasy.com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/
! https://www•drivereasy•com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/
drivereasy.com#?#.pakb-content img[sizes^="(max-width: 80"]
drivereasy.com#?#.pakb-content p:has-text(the FREE version)
drivereasy.com#?#.pakb-content p:has-text(the Pro version)
! https://www.drivereasy.com/knowledge/download-gigabyte-audio-driver/
! https://www•drivereasy•com/knowledge/download-gigabyte-audio-driver/
drivereasy.com#?#.pakb-content img[sizes^="(max-width: 79"]
drivereasy.com#?#.pakb-content span[id^=i-]:has-text(Automatically update your)
drivereasy.com##.pakb-content li:has(a[href="#automatically"])
! https://www.drivereasy.com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/
! https://www•drivereasy•com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/
drivereasy.com#?#.pakb-content span[id^=i-]:has-text(Update drivers with Driver Easy)
drivereasy.com#?#.pakb-content figcaption:has-text(for free if you like)
drivereasy.com#?#.pakb-content li:has(a:has-text(Update drivers with Driver Easy))
! https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/
! https://www•drivereasy•com/knowledge/solved-this-display-does-not-support-hdcp/
drivereasy.com#?#.pakb-content p:has-text(click Update All)
! ¤¤¤ Slimware DriverUpdate ¤¤¤
! https://forums.windowscentral.com/
! https://forums•windowscentral•com/
forums.windowscentral.com###navbar_notice_33
! ¤¤¤ Driverpack Online (Accidentally also fixed in EasyPrivacy and «AdGuard Mobile Ads») ¤¤¤
||google-analytics.com^$domain=sdi-tool.org
! ¤¤¤ SpyHunter links ¤¤¤
! https://howtoremove.guide/redirector-gvt1-com-virus-malware-chrome-removal/
! https://howtoremove•guide/redirector-gvt1-com-virus-malware-chrome-removal/
howtoremove.guide##div[style^="border:2px"]
howtoremove.guide#?#.entry-content > div:has-text(Special Offer)
! https://www.2-spyware.com/remove-redirector-gvt1-com.html
! https://www•2-spyware•com/remove-redirector-gvt1-com•html
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk##.automatic_removal_list_w > .ar_block_description
2-spyware.com,novirus.uk,faravirus.ro,uirusu.jp,virusi.hr,wubingdu.cn,avirus.hu,ioys.gr,odstranitvirus.cz,tanpavirus.web.id,utanvirus.se,virukset.fi,losvirus.es,virusler.info.tr,semvirus.pt,lesvirus.fr,senzavirus.it,dieviren.de,viruset.no,usunwirusa.pl,zondervirus.nl,bedynet.ru,virusai.lt,virusi.bg,viirused.ee,udenvirus.dk#?#a:has-text(SpyHunter)
guide##a[href*="download.enigmasoftware.com/spyhunter-free-download/stpl_94/SpyHunter-Installer.exe"]
@@ -252,9 +253,9 @@ virusresearch.org##.virus-before-content
virusresearch.org##.q2w3-fixed-widget-container
virusresearch.org##.virus-after-fourth-h2
virusresearch.org##.virus-after-content
! https://www.cyclonis.com/how-to-create-gmail-account-without-phone-number/
! https://www•cyclonis•com/how-to-create-gmail-account-without-phone-number/
cyclonis.com##div.rotatead-container:has(.download[data-params*="dl.enigmasoftware.com"])
! https://www.2-viruses.com/remove-ad-spam-press-allow-to-continue
! https://www•2-viruses•com/remove-ad-spam-press-allow-to-continue
2-viruses.com##.active.prods-win.prod-download
||2-viruses.com/downloads/spyhunter2^$all
! https://github.com/iam-py-test/my_filters_001/issues/119
@@ -262,41 +263,41 @@ cyclonis.com##div.rotatead-container:has(.download[data-params*="dl.enigmasoftwa
||cfoc.org/spyhunter-download-and-install-instructions/^$all
cfoc.org###top_custom_banner
cfoc.org##.custom_banner_top_btn
cfoc.org##tr:has([href="https://cfoc.org/go-to-spyhunter/"])
cfoc.org##*:has(> * > a[href="https://cfoc.org/spyhunter-download-and-install-instructions/"])
cfoc.org##tr:has([href$="ttps://cfoc.org/go-to-spyhunter/"])
cfoc.org##*:has(> * > a[href$="ttps://cfoc.org/spyhunter-download-and-install-instructions/"])
cfoc.org##*:has(> * > * > .su-button[href^="https://link.safecart.com/"])
cfoc.org##.widget_text.widget:has([href^="https://cfoc.org/spyhunter-"])
||cfoc.org/combocleaner-download-mac/^$document
cfoc.org##tr:has([href="https://cfoc.org/combocleaner-download-mac/"])
cfoc.org##tr:has([href$="ttps://cfoc.org/combocleaner-download-mac/"])
cfoc.org##p:has(font:has-text( could remain on your Mac if you are not careful during removal. We recommend that you download and run a scan with Combo Cleaner now to professionally clean up your Mac in ))
cfoc.org##font:has(center:has([href="https://cfoc.org/combocleaner-download-mac/"]))
cfoc.org##font:has(center:has([href$="ttps://cfoc.org/combocleaner-download-mac/"]))
||sensorstechforum.com/spyhunter-download-and-install-instructions/^$all
||sensorstechforum.com/spyhunter-for-mac-download-install/^$all
||sensorstechforum.com/wp-content/uploads/2020/04/SpyHunter-Install-And-Free-Scan-$image
||youtube.com/embed/KbGF_fvsRU4^$all
sensorstechforum.com##tr:has([href="https://sensorstechforum.com/spyhunter-download-and-install-instructions/"])
sensorstechforum.com##center:has([href="https://www.enigmasoftware.com/spyhunter5-eula/"])
sensorstechforum.com##[href="https://sensorstechforum.com/spyhunter-download-and-install-instructions/"]
sensorstechforum.com##tr:has([href$="ttps://sensorstechforum.com/spyhunter-download-and-install-instructions/"])
sensorstechforum.com##center:has([href$="ttps://www.enigmasoftware.com/spyhunter5-eula/"])
sensorstechforum.com##[href$="ttps://sensorstechforum.com/spyhunter-download-and-install-instructions/"]
sensorstechforum.com##.top_banner_custom
sensorstechforum.com##center:has-text(Click the button below):has-text(SpyHunter for Mac)
sensorstechforum.com##p:has([href="https://sensorstechforum.com/spyhunter-mac-review-advanced-anti-malware/"])
sensorstechforum.com##p:has([href$="ttps://sensorstechforum.com/spyhunter-mac-review-advanced-anti-malware/"])
sensorstechforum.com##p:has([src^="https://sensorstechforum.com/wp-content/uploads/2020/04/SpyHunter-Install-And-Free-Scan-"])
sensorstechforum.com##center:has([title="Download SpyHunter for Mac"])
sensorstechforum.com##p:has([src="https://www.youtube.com/embed/KbGF_fvsRU4"])
sensorstechforum.com##p:has([src$="ttps://www.youtube.com/embed/KbGF_fvsRU4"])
sensorstechforum.com###win_top_new_hidden
macsecurity.net##.banner
macsecurity.net##.btn-download.btn-lg.btn
! ¤¤¤ Restoro ¤¤¤
! https://www.windowsdispatch.com/fix-system-restore-0x81000203-error-code/
! https://www•windowsdispatch•com/fix-system-restore-0x81000203-error-code/
windowsdispatch.com##strong
! https://dlldownloads.com/xlive-dll/
! https://dlldownloads•com/xlive-dll/
dlldownloads.com##.page-container > p
! https://windowsreport.com/find-remove-duplicate-files-windows-10/
! https://windowsreport•com/find-remove-duplicate-files-windows-10/
windowsreport.com##.bnr-block
! https://windowsreport.com/how-to-update-roblox/ (08/12/2022)
! https://windowsreport•com/how-to-update-roblox/ (08/12/2022)
windowsreport.com##div[class^=restoro-download] + section
windowsreport.com##div[class^=refmed]
! https://appuals.com/pr-connect-reset-error/
! https://appuals•com/pr-connect-reset-error/
appuals.com##.wptp
appuals.com#?#h3:has(+ p:has-text(Download and run Restoro ))
appuals.com#?#p:has-text(Download and run Restoro )
@@ -339,7 +340,7 @@ exefiles.com##.row:has(a[href*="/recommended/"])
/^https://(apps?|best|competition|game|mobile|play|prize|reward|sweeps)\d{2,8}\.[a-z-]{5,22}\d{1,8}\.(icu|life|live)/$~third-party,doc
/^https?:\/\/((?!www)[a-z]{3,5}\.)?[-0-9a-z]{6,}\.(?:com|fun|guru|life|online|pw|site|space|top)\/\/?\?o=[0-9a-z]{7}&u=[0-9a-z]{7}/$document,match-case,domain=com|fun|guru|life|online|pw|site|space|top
/^https?:\/\/((?!www)[a-z]{3,5}\.)?[-0-9a-z]{6,}\.(?:com|fun|guru|life|online|pw|site|space|top)\/\/?\?u=[0-9a-z]{7}&o=[0-9a-z]{7}/$document,match-case,domain=com|fun|guru|life|online|pw|site|space|top
! https://github.com/AdguardTeam/AdguardFilters/issues/58737
! https://github•com/AdguardTeam/AdguardFilters/issues/58737
/^https?:\/\/(?:www\.)?[-0-9a-z]{14,}\.(?:biz|fun|live)\/[a-zA-Z]{10,}\.php\$/$document,domain=biz|fun|live
! ——— Banner for "MSN New Tab" ———
@@ -487,14 +488,14 @@ download.cnet.com##.c-globalCard:has(a[href*="/AdsCleaner/"])
||discordapp.cam^$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
||discordap.com^$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
! https://github.com/DevSpen/links/blob/master/src/links.txt
/(^|\.|://)d[il]sc(or|ro)ds?-?g[il]ft[se]?[.-].*/$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
/(^|\.|://)d[il]sc(or|ro)ds?-?n[il]tro[.-].*/$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
/^(.*\.|.*://)?d[il]sc(or|ro)ds?-?g[il]ft[se]?[.-].*$/$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
/^(.*\.|.*://)?d[il]sc(or|ro)ds?-?n[il]tro[.-].*$/$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
||discord-nltro.$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
||discord-app.$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
||discord-promo*$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
||dlscord.$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
||dlscord-app.$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
/(^|\.|://)gifts?-?discord\..*/$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
/^(.*\.|.*://)?gifts?-?discord\..*$/$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
||steamcommin*$document,domain=~likely-a-fake-malware-version-of-steamcommunity.com
||steamcommm*$all,~inline-font,domain=~fake-malware-version-of-steamcommunity.com
||steamcommn*$all,~inline-font,domain=~fake-malware-version-of-steamcommunity.com
@@ -550,7 +551,7 @@ download.cnet.com##.c-globalCard:has(a[href*="/AdsCleaner/"])
||githubuser.com^$document,domain=~you-were-likely-looking-for-githubusercontent.com
||rgithub.com^$document,domain=~you-were-likely-looking-for-githubusercontent.com
||githubt.com^$document,domain=~you-were-likely-looking-for-githubusercontent.com
! https://scammer.info/t/discord-nitro-scam-25/87887
! https://scammer•info/t/discord-nitro-scam-25/87887
||discorde-nitre.xyz^$all,~inline-font,domain=~fake-malware-version-of-discordapp.com
! ——— Frequently used to infiltrate and maliciously redirect sites, e.g. ToonBarn ———
@@ -611,9 +612,9 @@ download.cnet.com##.c-globalCard:has(a[href*="/AdsCleaner/"])
!+ NOT_PLATFORM(windows, mac, android)
||3.216.243.46^$all
||roamingclicks.com^$all
! Source: desidert.no
! Source: desidert•no
||collectfasttracks.com^$all,~inline-font,domain=~malware-redirection-trains.*
! Source: vn-zoom.com
! Source: vn-zoom•com
||ttnrd.com^$all
||amanda.*.com^$document
||katie.*.com^$document
@@ -632,7 +633,7 @@ download.cnet.com##.c-globalCard:has(a[href*="/AdsCleaner/"])
3.90.125.85$network
!+ NOT_PLATFORM(windows, mac, android)
||3.90.125.85^$all
! Various ex-affiliate links at www.zombooru.com
! Various ex-affiliate links at www•zombooru•com
||track.vcdc.com^$all,~inline-font,domain=~malware-redirection-trains.*
||track.tkbo.com^$all,~inline-font,domain=~malware-redirection-trains.*
||track.traffic.club^$all,~inline-font,domain=~malware-redirection-trains.*
@@ -661,9 +662,9 @@ download.cnet.com##.c-globalCard:has(a[href*="/AdsCleaner/"])
195.201.92.254$network
!+ NOT_PLATFORM(windows, mac, android)
||195.201.92.254^$all
zombooru.com##a[href="http://www.boorufurry.com/"]
zombooru.com##a[href="http://www.analbooru.com/"]
zombooru.com##a[href="http://www.hard55.com"]
zombooru.com##a[href$="ttp://www.boorufurry.com/"]
zombooru.com##a[href$="ttp://www.analbooru.com/"]
zombooru.com##a[href$="ttp://www.hard55.com"]
! https://github.com/DandelionSprout/adfilt/pull/167
||forgoprokick.icu^$all
! https://github.com/AdguardTeam/AdguardFilters/issues/124611
@@ -826,8 +827,8 @@ zombooru.com##a[href="http://www.hard55.com"]
216.21.13.15$network
!+ NOT_PLATFORM(windows, mac, android)
||216.21.13.15^$all
/\.(xyz|pics)/[a-zA-Z0-9]{130,}/$document,script,subdocument,image
/\.(cloudfront\.net|xyz|pics)/[a-zA-Z0-9]{20,}/[a-zA-Z0-9]{25,}\+[a-zA-Z0-9+]{90,}\$/$document,script,subdocument,image
/^.*\.(xyz|pics)/[a-zA-Z0-9]{130,}\$/$document,script,subdocument,image
/^.*\.(cloudfront\.net|xyz|pics)/[a-zA-Z0-9]{20,}/[a-zA-Z0-9]{25,}\+[a-zA-Z0-9+]{90,}\$/$document,script,subdocument,image
||abaphosis.guru^$all
||abietichob.live^$all
||abyssusuntouch.guru^$all
@@ -3900,7 +3901,7 @@ zombooru.com##a[href="http://www.hard55.com"]
192.243.59.*$network
192.243.61.*$network
!#endif
! https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315
! https://twitter•com/SUNgoddessOKAMI/status/1221295265195405315
||deviuser.com^$document
! https://github.com/AdguardTeam/AdguardFilters/issues/61838
/scan-update-and-protect-your-browser.html$document
@@ -3976,7 +3977,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||hooligapps.com^$all
||best202*-games-web1.com^$all
||theonlygames.com^$all
! https://maldita.es/malditobulo/2020/12/04/concurso-mercadona-ganar-tarjeta-regalo-100-euros-phishing/
! https://maldita•es/malditobulo/2020/12/04/concurso-mercadona-ganar-tarjeta-regalo-100-euros-phishing/
||notified-today.com^
||antivirus-update.com^$document
||new-message.cc^$document
@@ -3991,12 +3992,12 @@ zombooru.com##a[href="http://www.hard55.com"]
167.99.249.47$network
!+ NOT_PLATFORM(windows, mac, android)
||167.99.249.47^$all
! https://maldita.es/malditobulo/2020/12/02/lidl-regala-robot-cocina-silvercrest-monsieur-cuisine-encuesta/
! https://maldita.es/malditobulo/2020/11/25/jordi-evole-el-hormiguero-bitcoin-revolution-timo-twitter/
! https://maldita•es/malditobulo/2020/12/02/lidl-regala-robot-cocina-silvercrest-monsieur-cuisine-encuesta/
! https://maldita•es/malditobulo/2020/11/25/jordi-evole-el-hormiguero-bitcoin-revolution-timo-twitter/
||moderncomputer.net^
! https://maldita.es/malditobulo/2020/11/18/gobierno-tarjeta-debito-prepagada-covid-19-phishing-whatsapp/
! https://maldita•es/malditobulo/2020/11/18/gobierno-tarjeta-debito-prepagada-covid-19-phishing-whatsapp/
||version.gratis^
! https://maldita.es/malditobulo/2020/11/18/no-no-es-cierto-que-amancio-ortega-haya-invertido-100-millones-en-bitcoin-revolution-es-una-web-falsa/
! https://maldita•es/malditobulo/2020/11/18/no-no-es-cierto-que-amancio-ortega-haya-invertido-100-millones-en-bitcoin-revolution-es-una-web-falsa/
||starpowders.github.io^
! https://github.com/AdguardTeam/AdguardFilters/issues/69611
/^http://[a-z0-9-]{30,}\..*\.elasticbeanstalk\.com(/|$)/
@@ -4106,7 +4107,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||108.170.52.156^$all
! https://github.com/DandelionSprout/adfilt/issues/198
||mysecrethoookup.com^$all
! https://www.bleepingcomputer.com/virus-removal/ (18/06/2021)
! https://www•bleepingcomputer•com/virus-removal/ (18/06/2021)
||toksearches.xyz^$all
||smashapps.net^$all
||smashappsearch.com^$all
@@ -4118,7 +4119,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||searchinggood.com^$all
||searchprivacyplus.com^$all
||powersmashsearch.com^$all
! https://www.bleepingcomputer.com/virus-removal/remove-please-allow-to-watch-the-video
! https://www•bleepingcomputer•com/virus-removal/remove-please-allow-to-watch-the-video
||1000-dollar.cash^$all
||1000-eur.cash^$all
||bokerstars.com^$all
@@ -4221,9 +4222,9 @@ zombooru.com##a[href="http://www.hard55.com"]
213.227.149.216$network
!+ NOT_PLATFORM(windows, mac, android)
||213.227.149.216^$all
! https://twitter.com/adamziaja/status/1252234957679808513
! https://twitter•com/adamziaja/status/1252234957679808513
||wow-robotics.xyz^$all
! https://blog.sucuri.net/2021/05/woocommerce-credit-card-skimmer.html
! https://blog•sucuri•net/2021/05/woocommerce-credit-card-skimmer•html
||deepe.icu^$all
||google-analytics.buzz^$all
||intr0.cyou^$all
@@ -4277,7 +4278,7 @@ zombooru.com##a[href="http://www.hard55.com"]
69.49.231.244$network
!+ NOT_PLATFORM(windows, mac, android)
||69.49.231.244^$all
! https://movsb.0x0.st/users/mia
! https://movsb•0x0•st/users/mia
||vid.me^$third-party
||5starhdporn.com^$frame,third-party
! https://github.com/DandelionSprout/adfilt/issues/228
@@ -4368,25 +4369,25 @@ zombooru.com##a[href="http://www.hard55.com"]
||pc-my-protection.xyz^$all
||beta-news.org^$document
! https://github.com/DandelionSprout/adfilt/pull/266
! https://www.virustotal.com/gui/domain/kirstialechulbard.space/relations
! https://www.virustotal.com/gui/ip-address/198.54.117.244/relations
! https://www•virustotal•com/gui/domain/kirstialechulbard•space/relations
! https://www•virustotal•com/gui/ip-address/198•54•117•244/relations
||dashwoodestates.com^$all
! http://vxvault.net/ViriFiche.php?ID=44013
! https://www.virustotal.com/gui/url/8066b87ad10ddb5466bc307bb48454139572f6c8c8f80a9734275ac89cf966af/detection
! https://www.virustotal.com/gui/url/826c451929420c4da32552f967fb1cab6467405a29c65b23802aaadb6a8c7505/detection
! https://safeweb.norton.com/report/show?url=192.3.110.170
! http://vxvault•net/ViriFiche•php?ID=44013
! https://www•virustotal•com/gui/url/8066b87ad10ddb5466bc307bb48454139572f6c8c8f80a9734275ac89cf966af/detection
! https://www•virustotal•com/gui/url/826c451929420c4da32552f967fb1cab6467405a29c65b23802aaadb6a8c7505/detection
! https://safeweb•norton•com/report/show?url=192•3•110•170
!+ PLATFORM(windows, mac, android)
192.3.110.170$network
!+ NOT_PLATFORM(windows, mac, android)
||192.3.110.170^$all
! https://forums.malwarebytes.com/topic/278209-removal-instructions-for-socialsearchconverter/
! https://forums•malwarebytes•com/topic/278209-removal-instructions-for-socialsearchconverter/
||socialsearchconverter.com^$document
||install.socialsearchconverter.com^$all
||feed.socialsearchconverter.com^$all
||api.socialsearchconverter.com^$all
||notify-service.com^$all
||install.stream-all.com^$all
! copied over from https://github.com/uBlockOrigin/uAssets/issues/9848
! Copied over from https://github.com/uBlockOrigin/uAssets/issues/9848
||gghacks.com^$all
||rewardsgiantusa.com^$document
||promotionsonlineusa.com^$all
@@ -4398,10 +4399,10 @@ zombooru.com##a[href="http://www.hard55.com"]
||mediafiire.com^$document
||d1xkyo9j4r7vnn.cloudfront.net^$all
||onlinepromotionsusa.com^$document
! https://securelist.com/apkpure-android-app-store-infected/101845/
! https://www.virustotal.com/gui/url/866a25343864f03dc5a10105fda523bfbb6ed09c486d07fd31ca2b5306440089/detection
! https://securelist•com/apkpure-android-app-store-infected/101845/
! https://www•virustotal•com/gui/url/866a25343864f03dc5a10105fda523bfbb6ed09c486d07fd31ca2b5306440089/detection
||wcf.seven1029.com^$all
! https://www.virustotal.com/gui/url/9c66e331e455dc5c5c9d06e1a537580c9e4db279182d2285c07783e837806a16/detection
! https://www•virustotal•com/gui/url/9c66e331e455dc5c5c9d06e1a537580c9e4db279182d2285c07783e837806a16/detection
||foodin.site^$all
! https://github.com/AdguardTeam/AdguardFilters/issues/91506#issuecomment-904080849
||totalav.com^$all
@@ -4413,28 +4414,28 @@ zombooru.com##a[href="http://www.hard55.com"]
||totaladblock.com^$all
||totaladblocker.xyz^$all
||totalwebshield.xyz^$all
! https://www.virustotal.com/gui/file/c683bc3da4966110b419ac54d09a54ce798efdb51be398331d9ce011e2636fa9/community
! https://www.virustotal.com/gui/url/5618023ed5a768d7f879c0d599b9ba7cff0e9171201981256eeaf5ce8eb09fdb/detection
! https://www.virustotal.com/gui/url/8cf9ca3359f17cf92b9b3e5fdab30e29be23f08e66c8c5396c9410fcb91f7c3c/detection
! https://www•virustotal•com/gui/file/c683bc3da4966110b419ac54d09a54ce798efdb51be398331d9ce011e2636fa9/community
! https://www•virustotal•com/gui/url/5618023ed5a768d7f879c0d599b9ba7cff0e9171201981256eeaf5ce8eb09fdb/detection
! https://www•virustotal•com/gui/url/8cf9ca3359f17cf92b9b3e5fdab30e29be23f08e66c8c5396c9410fcb91f7c3c/detection
!+ PLATFORM(windows, mac, android)
91.241.19.38$network
!+ NOT_PLATFORM(windows, mac, android)
||91.241.19.38^$all
! https://www.virustotal.com/gui/url/46e095c35d83e2dd0b98df4b5844d3d87948de0c930a618600121020a514c801/detection
! https://safeweb.norton.com/report/show?url=telete.in
! https://www.siteadvisor.com/sitereport.html?url=telete.in
! https://www•virustotal•com/gui/url/46e095c35d83e2dd0b98df4b5844d3d87948de0c930a618600121020a514c801/detection
! https://safeweb•norton•com/report/show?url=telete•in
! https://www•siteadvisor•com/sitereport•html?url=telete•in
||telete.in^$all
! https://www.virustotal.com/gui/file/e63b2d03e3fee2d538f8bd721b61dd3641284fa941087d846dea6f15cab40308/community
! https://www.virustotal.com/gui/url/fbbc8a671bff32539bd829a76f6df9f364a21ac2279922e64e3ec494a1669dd3/detection
! https://www•virustotal•com/gui/file/e63b2d03e3fee2d538f8bd721b61dd3641284fa941087d846dea6f15cab40308/community
! https://www•virustotal•com/gui/url/fbbc8a671bff32539bd829a76f6df9f364a21ac2279922e64e3ec494a1669dd3/detection
||kiff.tech^$all
! https://www.virustotal.com/gui/domain/kiff.tech/relations
! https://www.virustotal.com/gui/url/dc038496b1b5358b97f89440135ec91258b406c40859a2cd95983dc7a81e0cfa/detection
! https://www•virustotal•com/gui/domain/kiff•tech/relations
! https://www•virustotal•com/gui/url/dc038496b1b5358b97f89440135ec91258b406c40859a2cd95983dc7a81e0cfa/detection
!+ PLATFORM(windows, mac, android)
45.90.58.90$network
!+ NOT_PLATFORM(windows, mac, android)
||45.90.58.90^$all
! https://www.virustotal.com/gui/file/e565ba89d034418fd26a5f642f6eeee4d72ee3b8dc69523419b7ca8dfd452730/community
! https://www.virustotal.com/gui/url/e3a9189a1e1256beba8e0fc3abfeab6acb09f7f8cabfd973e22be9f77bb6886f/detection
! https://www•virustotal•com/gui/file/e565ba89d034418fd26a5f642f6eeee4d72ee3b8dc69523419b7ca8dfd452730/community
! https://www•virustotal•com/gui/url/e3a9189a1e1256beba8e0fc3abfeab6acb09f7f8cabfd973e22be9f77bb6886f/detection
!+ PLATFORM(windows, mac, android)
95.85.89.98$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -4466,7 +4467,7 @@ zombooru.com##a[href="http://www.hard55.com"]
!+ NOT_PLATFORM(windows, mac, android)
||103.169.90.205^$all
! https://github.com/DandelionSprout/adfilt/pull/281
! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
! https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
!+ PLATFORM(windows, mac, android)
125.44.43.45$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -4507,9 +4508,9 @@ zombooru.com##a[href="http://www.hard55.com"]
27.220.253.78$network
!+ NOT_PLATFORM(windows, mac, android)
||27.220.253.78^$all
! https://www.virustotal.com/gui/file/0374ead74fa807fb1737d8829fdb5bad6c93779f6b9eb7162eddabff7a64acff/community
! https://www•virustotal•com/gui/file/0374ead74fa807fb1737d8829fdb5bad6c93779f6b9eb7162eddabff7a64acff/community
||esetnode32-antiviru.ydns.eu^$all
! https://www.joesandbox.com/analysis/486636/0/html#domains
! https://www•joesandbox•com/analysis/486636/0/html#domains
||aieov.com^$all
! Relations to the original domain
!+ PLATFORM(windows, mac, android)
@@ -4586,26 +4587,26 @@ zombooru.com##a[href="http://www.hard55.com"]
||army-glo.scrollingsystem.com^$document
||mcafee12.tt.omtrdc.net^$document
||trolleydrop.info^$document
! https://www.virustotal.com/gui/ip-address/70.32.1.32/relations
! https://www•virustotal•com/gui/ip-address/70•32•1•32/relations
||cd.org^$document
! https://www.virustotal.com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community
! https://www•virustotal•com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community
! https://github.com/DandelionSprout/adfilt/commit/f7f114945c83b339be5cdd848e229680d9918abb#commitcomment-57642875
!+ PLATFORM(windows, mac, android)
23.94.26.138$network
!+ NOT_PLATFORM(windows, mac, android)
||23.94.26.138^$all
! https://github.com/DandelionSprout/adfilt/pull/298
! https://www.virustotal.com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community
! https://www•virustotal•com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community
!+ PLATFORM(windows, mac, android)
205.185.126.200$network
!+ NOT_PLATFORM(windows, mac, android)
||205.185.126.200^$all
! https://www.virustotal.com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community
! https://www•virustotal•com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community
!+ PLATFORM(windows, mac, android)
185.243.56.167$network
!+ NOT_PLATFORM(windows, mac, android)
||185.243.56.167^$all
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
!+ PLATFORM(windows, mac, android)
123.10.224.135$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -4794,9 +4795,9 @@ zombooru.com##a[href="http://www.hard55.com"]
112.30.110.58$network
!+ NOT_PLATFORM(windows, mac, android)
||112.30.110.58^$all
! https://www.virustotal.com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community
! https://www•virustotal•com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community
||pcae.de^$document
! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
! https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
!+ PLATFORM(windows, mac, android)
117.196.49.21$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -4813,17 +4814,17 @@ zombooru.com##a[href="http://www.hard55.com"]
182.59.69.21$network
!+ NOT_PLATFORM(windows, mac, android)
||182.59.69.21^$all
! https://www.virustotal.com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community
! https://www•virustotal•com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community
||chip-secured-download.de^$all
! https://www.virustotal.com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb
! https://www•virustotal•com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb
! Domains which resolve to this (already blocked) IP - for users of HOSTs/Domains/uBlock Origin
||nctylivpwhpby.com^$all
||phhitgjxsit.com^$all
! https://www.virustotal.com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1
! https://www•virustotal•com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1
||saimission.org^$all
! https://www.virustotal.com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1
! https://www•virustotal•com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1
||grub-wa-saya.duckdns.org^$all
! https://www.virustotal.com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations
! https://www•virustotal•com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations
||driversupport.com^$document
! A PUP and scam website
||mycleanpc.com^$document
@@ -4834,12 +4835,12 @@ zombooru.com##a[href="http://www.hard55.com"]
! The main website for the MyCleanPC company
||realdefen.se^$document
! Vermilion Strike
! https://www.virustotal.com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations
! https://www•virustotal•com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations
!+ PLATFORM(windows, mac, android)
160.202.163.100$network
!+ NOT_PLATFORM(windows, mac, android)
||160.202.163.100^$all
! https://www.virustotal.com/gui/ip-address/160.202.163.100/relations
! https://www•virustotal•com/gui/ip-address/160•202•163•100/relations
||microsoftkernel.com^$all
||microsofthk.com^$all
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-938167311
@@ -4850,17 +4851,17 @@ zombooru.com##a[href="http://www.hard55.com"]
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-944612753
||pushbizapi.com^$all
! https://github.com/DandelionSprout/adfilt/pull/303
! https://www.virustotal.com/gui/file/37328efa73c248b460aba605d7745b024f31ab7ab864e1af273e9a197a188f42/community
! https://www•virustotal•com/gui/file/37328efa73c248b460aba605d7745b024f31ab7ab864e1af273e9a197a188f42/community
!+ PLATFORM(windows, mac, android)
45.95.169.115$network
!+ NOT_PLATFORM(windows, mac, android)
||45.95.169.115^$all
! https://www.virustotal.com/gui/file/03e4533ba8874c2f4dcdb94bd135914fa4c22ed477d7c0395dc2322b6468e249/community
! https://www•virustotal•com/gui/file/03e4533ba8874c2f4dcdb94bd135914fa4c22ed477d7c0395dc2322b6468e249/community
!+ PLATFORM(windows, mac, android)
45.148.120.80$network
!+ NOT_PLATFORM(windows, mac, android)
||45.148.120.80^$all
! https://www.virustotal.com/gui/file/1a782cab036efa567c2c42b7bae9452bf735be72f0b00d68f6dcba48cea526fa/community
! https://www•virustotal•com/gui/file/1a782cab036efa567c2c42b7bae9452bf735be72f0b00d68f6dcba48cea526fa/community
!+ PLATFORM(windows, mac, android)
85.239.33.9$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -4880,17 +4881,17 @@ zombooru.com##a[href="http://www.hard55.com"]
||c4ase-verified9932.serveftp.com^$all
||1log-wellsfargo.serveftp.com^$all
||eposcardokubo.serveftp.com^$all
! https://www.virustotal.com/gui/file/8a39f18caa77d52e80bec05f584ec50e733a3be1e33551d8902e95b9b0bfe6c0/community
! https://www•virustotal•com/gui/file/8a39f18caa77d52e80bec05f584ec50e733a3be1e33551d8902e95b9b0bfe6c0/community
!+ PLATFORM(windows, mac, android)
107.173.176.183$network
!+ NOT_PLATFORM(windows, mac, android)
||107.173.176.183^$all
! https://www.virustotal.com/gui/file/54054209c921a68f12a9b29d6e84f1b45cb417bc0b5a99356a245727e0a41e40/community
! https://www•virustotal•com/gui/file/54054209c921a68f12a9b29d6e84f1b45cb417bc0b5a99356a245727e0a41e40/community
!+ PLATFORM(windows, mac, android)
45.148.120.171$network
!+ NOT_PLATFORM(windows, mac, android)
||45.148.120.171^$all
! https://twitter.com/soranker0/status/1449491402409185283
! https://twitter•com/soranker0/status/1449491402409185283
://disordgift.$all
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-950330114
||free-softs.net^$all
@@ -4920,7 +4921,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||kokotrokot.com^$all
!!!?next_url=$document,popup (https://github.com/AdguardTeam/AdguardFilters/issues/108072#issuecomment-1021534226)
?uclickhash=$document,popup
! https://www.upwork.com/freelance-jobs/apply/Integarte-push-notification-for-chrome_~013c73ed9282225184/
! https://www•upwork•com/freelance-jobs/apply/Integarte-push-notification-for-chrome_~013c73ed9282225184/
||mugrikees.com^$all
||alpha-news.org^$all
! https://github.com/iam-py-test/investigations/blob/main/2021/11/3/1.md
@@ -4929,7 +4930,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||youvetube.com^$all
||youutube.com^$all
! https://github.com/DandelionSprout/adfilt/pull/348
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
!+ PLATFORM(windows, mac, android)
39.83.80.247$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -5054,7 +5055,7 @@ zombooru.com##a[href="http://www.hard55.com"]
183.188.192.55$network
!+ NOT_PLATFORM(windows, mac, android)
||183.188.192.55^$all
! https://www.virustotal.com/gui/file/3bf1b7e9bdaeaa4a5619cf26b59767637bc44193df2a0470df263b98b1fe47fe/community
! https://www•virustotal•com/gui/file/3bf1b7e9bdaeaa4a5619cf26b59767637bc44193df2a0470df263b98b1fe47fe/community
!+ PLATFORM(windows, mac, android)
198.23.255.14$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -5074,7 +5075,7 @@ zombooru.com##a[href="http://www.hard55.com"]
172.67.186.189$network
!+ NOT_PLATFORM(windows, mac, android)
||172.67.186.189^$all
! https://www.virustotal.com/gui/url/af8f443208f4e86d469549b219fccbeb43b7cae40be5f1b4c4e5083e27fc8111
! https://www•virustotal•com/gui/url/af8f443208f4e86d469549b219fccbeb43b7cae40be5f1b4c4e5083e27fc8111
||inconclusive-pyrite-grandparent.glitch.me^$all
||delicate-tame-angora.glitch.me^$all
||secureinvoice.glitch.me^$all
@@ -5085,9 +5086,9 @@ zombooru.com##a[href="http://www.hard55.com"]
||aquamarine-cotton-impala.glitch.me^$all
||mature-periwinkle-advantage.glitch.me^$all
||tough-numerous-lemur.glitch.me^$all
! https://scammer.info/t/mcafee-phish/83725
! https://scammer•info/t/mcafee-phish/83725
||securefirst.us-east-1.linodeobjects.com^$all
! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
! https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
!+ PLATFORM(windows, mac, android)
39.65.72.211$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -5120,27 +5121,27 @@ zombooru.com##a[href="http://www.hard55.com"]
||members.tonightshookup.com^$all
||t.tonightshookup.com^$all
||yourladiefun.life^$all
! https://www.virustotal.com/gui/url/a2524bba49ae71297d2b408b30d058700d9c80b5b1154924cafe190ec3e605a6/detection
! https://www•virustotal•com/gui/url/a2524bba49ae71297d2b408b30d058700d9c80b5b1154924cafe190ec3e605a6/detection
! https://www.virustotal.com/gui/file/2b2628a50d3b39b0fa2395d487bf62b00e37cdae847ff76ee58399bbe4e9f7b3/community
! https://www•virustotal•com/gui/file/2b2628a50d3b39b0fa2395d487bf62b00e37cdae847ff76ee58399bbe4e9f7b3/community
!+ PLATFORM(windows, mac, android)
194.87.138.20$network
!+ NOT_PLATFORM(windows, mac, android)
||194.87.138.20^$all
! https://www.virustotal.com/gui/file/b320bc7a9151d70daca038c4356ca89bfcd4918bcd6f0f73683a27a6a72467ae/community
! https://www•virustotal•com/gui/file/b320bc7a9151d70daca038c4356ca89bfcd4918bcd6f0f73683a27a6a72467ae/community
!+ PLATFORM(windows, mac, android)
103.167.92.73$network
!+ NOT_PLATFORM(windows, mac, android)
||103.167.92.73^$all
! https://www.virustotal.com/gui/file/6146dfe56dcb49e1b843624a44e204754e15625a4f94b230b59a5cafc924f618/community
! https://www•virustotal•com/gui/file/6146dfe56dcb49e1b843624a44e204754e15625a4f94b230b59a5cafc924f618/community
||bursakulis.com^$all
! https://www.virustotal.com/gui/url/b333c49efa4d399e65c5e2d96a905b380acbca58a3e3052b7bd7cfcb3e0e81ee
! https://www•virustotal•com/gui/url/b333c49efa4d399e65c5e2d96a905b380acbca58a3e3052b7bd7cfcb3e0e81ee
||610418.selcdn.ru^$all
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-977912975
! https://www.tv2.no/nyheter/14368524/
! https://www•tv2•no/nyheter/14368524/
||alexstewartinternationalltd.rw^$all
||vps.re^$all
! https://www.tek.no/i/wOVv0o/
! https://www•tek•no/i/wOVv0o/
||21steditionnaturalgh.com^$all
! https://github.com/iam-py-test/investigations/blob/main/2021/11/24/1.md
||macsoftwarez.com^$all
@@ -5156,7 +5157,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||yunosurveys.com^$all
! https://github.com/uBlockOrigin/uAssets/pull/10620
||shadyclient.net^$all
! https://www.virustotal.com/gui/file/d546509ab6670f9ff31783ed72875dfc0f37fa2b666bd5870eecaaed2ebea4a8/community
! https://www•virustotal•com/gui/file/d546509ab6670f9ff31783ed72875dfc0f37fa2b666bd5870eecaaed2ebea4a8/community
!+ PLATFORM(windows, mac, android)
58.249.74.79$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -5196,13 +5197,13 @@ zombooru.com##a[href="http://www.hard55.com"]
||totalnicefeed.com^$all
! https://github.com/iam-py-test/investigations/blob/main/2021/11/28/2.md
||bestlifeoffer20.com^$document
! https://scammer.info/t/password-stealer/84348
! https://bazaar.abuse.ch/sample/462a689d171f543c10efa08e963996d382585b67a6b298ec40d64f924adfb47a/
! https://scammer•info/t/password-stealer/84348
! https://bazaar•abuse•ch/sample/462a689d171f543c10efa08e963996d382585b67a6b298ec40d64f924adfb47a/
||youtube.com/watch?v=8nY7SnvNxH4^$all
||bit.ly/3p8kN5V^$document
||mediafire.com/file/at2tvnao5x6ivdo/EngineOwning.rar/$all
||download2264.mediafire.com/pnk44f5ci9rg/at2tvnao5x6ivdo/EngineOwning.rar^$all
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
!+ PLATFORM(windows, mac, android)
110.89.59.135$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -5247,33 +5248,33 @@ zombooru.com##a[href="http://www.hard55.com"]
61.52.79.32$network
!+ NOT_PLATFORM(windows, mac, android)
||61.52.79.32^$all
! https://scammer.info/t/pihishing-site-claiming-to-hold-a-ups-package-that-needs-payment/84466
! https://scammer•info/t/pihishing-site-claiming-to-hold-a-ups-package-that-needs-payment/84466
://ups-dk.$document,denyallow=dk|nu|se|no|fo|gl|ups.com,domain=ups-dk.*
! https://www.virustotal.com/gui/url/269d374b629d7896da1f9e7449bd5afecf6284a9a564244f96a71e5192363635?nocache=1
! https://www•virustotal•com/gui/url/269d374b629d7896da1f9e7449bd5afecf6284a9a564244f96a71e5192363635?nocache=1
||lowseelan.com^$all
! https://www.virustotal.com/gui/file/50fd813cf8fe981e6aee179f8ba394e5527c5128b84c328f9f8347cd994bbc42/community
! https://www•virustotal•com/gui/file/50fd813cf8fe981e6aee179f8ba394e5527c5128b84c328f9f8347cd994bbc42/community
||dl02.s3.amazonaws.com/installers/747947/oi_picasa38-setupexe.exe^$all
! https://www.virustotal.com/gui/file/2ea599605c4d65902943f12e1114a71af7a40fa7dffbf018b0ee3e7a61aaeaa3/community
! https://www•virustotal•com/gui/file/2ea599605c4d65902943f12e1114a71af7a40fa7dffbf018b0ee3e7a61aaeaa3/community
||dl02.s3.amazonaws.com/installers/424531/2gzbsoj4gxb.exe^$all
! https://github.com/DandelionSprout/adfilt/pull/395
! https://www.huorong.cn/info/1531309921141.html
! https://www•huorong.cn/info/1531309921141.html
||kuaizip.com^$all
! https://www.huorong.cn/info/1618397948649.html - possible malware
! https://www•huorong.cn/info/1618397948649.html - possible malware
! ||zhuangjizhuli.com^$all
! ||zhuangjizhuli.net^$all
! https://github.com/uBlockOrigin/uAssets/pull/9656
||geekotg.com^$all
! https://www.huorong.cn/info/1526627586130.html
! https://www•huorong.cn/info/1526627586130.html
||xiaobaixitong.com^$all
! https://www.huorong.cn/info/1577158839403.html
! https://www•huorong.cn/info/1577158839403.html
||daque.cn^$all
! https://www.huorong.cn/info/1598957552515.html
! https://www•huorong.cn/info/1598957552515.html
||dabaicai.com^$all
! https://www.huorong.cn/info/1617368984641.html
! https://www•huorong.cn/info/1617368984641.html
||qqfzn.com^$all
! https://github.com/uBlockOrigin/uAssets/pull/10017
||flash.cn^$all
! https://www.nrk.no/vestfoldogtelemark/1.15750360
! https://www•nrk.no/vestfoldogtelemark/1.15750360
||dundeehills.group^$all
!+ NOT_OPTIMIZED
!+ PLATFORM(windows, mac, android)
@@ -5290,8 +5291,8 @@ zombooru.com##a[href="http://www.hard55.com"]
! https://scammer.info/t/fake-facebook-login-page/84939
||royyer.us/R8cWuvQjhtM^$all
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-988127908
! https://www.tek.no/i/lVeQAe/
! https://www.nkom.no/aktuelt/ikke-trykk-pa-lenker-i-sms--for-du-er-helt-sikker/
! https://www•tek.no/i/lVeQAe/
! https://www•nkom.no/aktuelt/ikke-trykk-pa-lenker-i-sms--for-du-er-helt-sikker/
||eccolabgroup.com^$all
||galerijajava.ba^$all
||p-stn.net^$all
@@ -5307,7 +5308,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||34.201.22.10^$all
! https://scammer.info/t/crypto-scammers-onceagain/85354
||business.google.com/website/billyandscapedesign^$all
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
!+ PLATFORM(windows, mac, android)
123.10.225.196$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -5388,9 +5389,9 @@ zombooru.com##a[href="http://www.hard55.com"]
||d13pxqgp3ixdbh.cloudfront.net^$all
! Other
||crashfixes.com^$all
! https://www.virustotal.com/gui/url/c25fe34c05cc8e9136027a67c277e175a5d6e35af921ee37bad98bdfeea6a2f9/community
! https://www•virustotal•com/gui/url/c25fe34c05cc8e9136027a67c277e175a5d6e35af921ee37bad98bdfeea6a2f9/community
||splendid-fallacious-anaconda.glitch.me^$all
! https://www.virustotal.com/gui/file/9d40ae0439ddc594b2cf64e21ad0fdea9bb440524298e3a6bcfcc1fb417f1ed2/relations
! https://www•virustotal•com/gui/file/9d40ae0439ddc594b2cf64e21ad0fdea9bb440524298e3a6bcfcc1fb417f1ed2/relations
!+ PLATFORM(windows, mac, android)
91.240.118.172$network
!+ NOT_PLATFORM(windows, mac, android)
@@ -5404,7 +5405,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||myget.org/feed/discord-nitro-hack/package/nuget/Free-discord-nitro-codes-2021^$document
||lucymods.com^$all
||gluegames.xyz^$all
! https://twitter.com/iam_py_test/status/1496259425493225472
! https://twitter•com/iam_py_test/status/1496259425493225472
||sites.google.com/view/groundworkssolutions/contact-us^$all
||sites.google.com/view/groundworkssolutions/^$all
||sites.google.com/mytv/maintenance^$all
@@ -5419,7 +5420,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||download2340.mediafire.com/eift3ac9qmig/y65v1rk0zy7ot4a/The__Setup__With__File.zip^$all
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1074966240
||melding.link^$document
! https://twitter.com/MBThreatIntel/status/1509956416311742464
! https://twitter•com/MBThreatIntel/status/1509956416311742464
||xposednews.xyz^$all
||tomguide.xyz^$all
||eronews.xyz^$all
@@ -5443,7 +5444,7 @@ zombooru.com##a[href="http://www.hard55.com"]
198.199.120.251$network
!+ NOT_PLATFORM(windows, mac, android)
||198.199.120.251^$all
! https://www.telia.no/kundeservice/mobil/malware-flubot-android/
! https://www•telia.no/kundeservice/mobil/malware-flubot-android/
!+ NOT_OPTIMIZED
/^https?://(www\.)?[a-z0-9-]{1,}\.[a-z]{2,17}/[a-z0-9]/\?[a-z0-9.-]{8,}\$/$document
! A Discord conversation I had about Throneful
@@ -5473,7 +5474,7 @@ zombooru.com##a[href="http://www.hard55.com"]
195.201.253.131$network
!+ NOT_PLATFORM(windows, mac, android)
||195.201.253.131^$all
! The bottom download button on https://www.sushichop.com/
! The bottom download button on https://www•sushichop•com/
||installiq.com^$all
||specgoal.com^$all
||sandhyapi.online^$all
@@ -5511,7 +5512,7 @@ zombooru.com##a[href="http://www.hard55.com"]
96.47.230.70$network
!+ NOT_PLATFORM(windows, mac, android)
||96.47.230.70^$all
! https://securitytrails.com/list/ns/ns1.fastthinkingdns.com
! https://securitytrails•com/list/ns/ns1•fastthinkingdns•com
||highercaptcha-settle.$all
||highercaptchasettle.$all
||ns*.fastthinkingdns.com^$all
@@ -5560,7 +5561,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||saferedirects.xyz^$all,~inline-font,domain=~malware-redirection-trains.*
||online-guard.com^$all
/mcafee-safe-browsing/?*=*&*=*&*=*&*=*&*=*&*=$document,popup,domain=~fake-site-with-malware.*
! https://twitter.com/iam_py_test/status/1545164642346930176
! https://twitter•com/iam_py_test/status/1545164642346930176
||amazon-security-info.lnk.to^$all
! https://github.com/AdguardTeam/AdguardFilters/issues/123968
! https://github.com/AdguardTeam/AdguardFilters/issues/124620
@@ -5887,7 +5888,7 @@ zombooru.com##a[href="http://www.hard55.com"]
!+ NOT_PLATFORM(windows, mac, android)
||165.227.168.212^$all
!#if !ext_ublock
! https://www.reddit.com/r/engrish/comments/w6u4uy/received_this_text_message_yesterday_i_am_very/
! https://www•reddit.com/r/engrish/comments/w6u4uy/received_this_text_message_yesterday_i_am_very/
162.241.115.*$network
!#endif
! https://dinside.dagbladet.no/mobil/ikke-la-deg-friste/76730599
@@ -6148,7 +6149,7 @@ zombooru.com##a[href="http://www.hard55.com"]
147.135.253.55$network
!+ NOT_PLATFORM(windows, mac, android)
||147.135.253.55^$all
! https://github.com/uBlockOrigin/uAssets/issues/14569 → https://www.virustotal.com/gui/url/b819586938326577d759d8024abe3e0e6de1c853d6b67824daf6f613fba0f63b/detection (https://app.any.run/tasks/5914a712-1a73-4432-b89a-ca0627a24ade)
! https://github.com/uBlockOrigin/uAssets/issues/14569 → https://www•virustotal•com/gui/url/b819586938326577d759d8024abe3e0e6de1c853d6b67824daf6f613fba0f63b/detection (https://app•any•run/tasks/5914a712-1a73-4432-b89a-ca0627a24ade)
||bnbdeal.net^$all
! https://github.com/AdguardTeam/AdguardFilters/issues/129414
!+ NOT_OPTIMIZED
@@ -10220,7 +10221,7 @@ zombooru.com##a[href="http://www.hard55.com"]
196.245.52.*$network
196.245.56.*$network
!#endif
! https://www.bleepingcomputer.com/news/security/hackers-push-malware-via-google-search-ads-for-vlc-7-zip-ccleaner/
! https://www•bleepingcomputer•com/news/security/hackers-push-malware-via-google-search-ads-for-vlc-7-zip-ccleaner/
://rufus.download.$document,popup
://virtualbox.download.$document,popup
://vidiq.download.$document,popup
@@ -10776,7 +10777,7 @@ zombooru.com##a[href="http://www.hard55.com"]
64.132.201.92$network
!+ NOT_PLATFORM(windows, mac, android)
||64.132.201.92^$all
! https://www.adressa.no/nyheter/trondheim/i/BWkdkw/trodde-hun-skulle-faa-en-pakke-i-posten-ble-lurt-for-titusener
! https://www•adressa.no/nyheter/trondheim/i/BWkdkw/trodde-hun-skulle-faa-en-pakke-i-posten-ble-lurt-for-titusener
||acessmygov.online^$all
||centerlinkmygov.com^$all
||centierssl.us^$all
@@ -11525,7 +11526,7 @@ zombooru.com##a[href="http://www.hard55.com"]
!+ NOT_PLATFORM(windows, mac, android)
||54.204.83.105^$all
! https://github.com/DandelionSprout/adfilt/issues/808
! https://www.mandiant.com/resources/blog/tracking-evolution-gootloader-operations (26/01/2023)
! https://www•mandiant.com/resources/blog/tracking-evolution-gootloader-operations (26/01/2023)
||jonathanbartz.com^$all
||jp.imonitorsoft.com^$all
||junk-bros.com^$all
@@ -11780,7 +11781,7 @@ zombooru.com##a[href="http://www.hard55.com"]
85.17.80.16$network
!+ NOT_PLATFORM(windows, mac, android)
||85.17.80.16^$all
! https://www.adressa.no/nyheter/trondheim/i/Moq2wR/svindlere-kaarer-vinnere-i-konkurranser-gir-en-daarlig-foelelse-aa-forklare-at-dette-bare-er-tull
! https://www•adressa.no/nyheter/trondheim/i/Moq2wR/svindlere-kaarer-vinnere-i-konkurranser-gir-en-daarlig-foelelse-aa-forklare-at-dette-bare-er-tull
||sitey.me^$document
! https://github.com/AdguardTeam/AdguardFilters/issues/151479
||agazpeppily.live^$all
@@ -12213,7 +12214,7 @@ zombooru.com##a[href="http://www.hard55.com"]
57.128.71.215$network
!+ NOT_PLATFORM(windows, mac, android)
||57.128.71.215^$all
/&[a-z]{1,2}=[a-zA-Z0-9]{0,}%[a-zA-Z0-9%]{1000,}\$/$document
/^.*&[a-z]{1,2}=[a-zA-Z0-9]{0,}%[a-zA-Z0-9%]{1000,}\$/$document
! https://github.com/AdguardTeam/AdguardFilters/issues/155936
||truanet.com^$all
||rumadel.com^$all
@@ -17963,7 +17964,7 @@ zombooru.com##a[href="http://www.hard55.com"]
! (https://github.com/AdguardTeam/AdguardBrowserExtension/issues/2497)
/(//|\.|^)github\.[a-z]{2,20}(/|$)/$document,match-case,~third-party,domain=github.*|~com|~org|~net|~co|~blog|~community|~host|~io|~microsoft|~office|~uk|~us|~xn--fiqs8s|~dev|~archive.*
||github.sale^$all
! https://www.tv2.no/nyheter/innenriks/advarer-ikke-klikk-pa-lenken/16040614/
! https://www•tv2.no/nyheter/innenriks/advarer-ikke-klikk-pa-lenken/16040614/
||0nedr1ved0cumentonline.com^$all
||88godetailsvc.com^$all
||amexmobileupdate.cc^$all
@@ -23973,11 +23974,11 @@ zombooru.com##a[href="http://www.hard55.com"]
!#endif
! ——— Standard malware that I stumbled upon on my own ———
! http://www.toorgle.net/results.php?q=fetishkitsch&security=666
! http://www•toorgle•net/results•php?q=fetishkitsch&security=666
||downloadprovider.me^$all
##a[href*=".downloadprovider.me/"]
toorgle.net##.join
! https://www.riverbender.com/articles/details/two-charged-in-connection-of-the-stallon-drug-raid-in-wood-river-46877.cfm
! https://www•riverbender•com/articles/details/two-charged-in-connection-of-the-stallon-drug-raid-in-wood-river-46877•cfm
||cash93.com^$all
||a4alig.com^$all
||cash03.com^$all
@@ -23990,7 +23991,7 @@ toorgle.net##.join
||netpay8.com^$all
||slimxketo.com^$all
||works35.com^$all
! Various ex-affiliate links at www.zombooru.com
! Various ex-affiliate links at www•zombooru•com
||allowandgo.com^$all
||aksuu.ru^$all
||allow-space.com^$all
@@ -24004,7 +24005,7 @@ toorgle.net##.join
||push.weo.su^$all
||traffsend.me^$all
||wwopenclick.club^$all
! Spam comments at https://www.accountkiller.com/en/delete-htcdev-account
! Spam comments at https://www•accountkiller•com/en/delete-htcdev-account
||azhydroxychloroquine.com^$all
||wisig.org^$all
||confrancisyalgomas.com^$all
@@ -24016,13 +24017,13 @@ toorgle.net##.join
||amoxycillin1st.com^$all
! The Jerma985 Discord server
||crazycrabreedville.com^$all
! https://flclever.weebly.com/pixie-hollow-mini-games.html (06/05/2021)
! https://flclever.weebly•com/pixie-hollow-mini-games•html (06/05/2021)
||messium.info^$all
! Various Google searches
://hullcitytigers.com^$document
! Various search results for 'kelloggs tresor' in Norwegian (30/05/2021)
/pgxhtogrzm-$document
! https://fx-onlinee.blogspot.com/2021/06/?r=Bergens-Tidende-Flertallet-av-fastlegene-i-Trondheim-sier-nei-til-Janssen-vaksinen-Umulig-%C3%A5-ta-det-ansvaret-seo+aj
! https://fx-onlinee•blogspot•com/2021/06/?r=Bergens-Tidende-Flertallet-av-fastlegene-i-Trondheim-sier-nei-til-Janssen-vaksinen-Umulig-%C3%A5-ta-det-ansvaret-seo+aj
||blogspot.com/*/?r=*-seo+aj$document
! Fake security sites that think every single domain is a supervirus and which try to make you install PUP (Most commonly SpyHunter)
||malwarecleanerpro.com^$document
@@ -26279,8 +26280,8 @@ toorgle.net##.join
192.243.61.225$network
!+ NOT_PLATFORM(windows, mac, android)
||192.243.61.225^$all
! https://twitter.com/medicinehelp/status/1550250932394409985
! https://securitytrails.com/list/ip/147.135.16.27
! https://twitter•com/medicinehelp/status/1550250932394409985
! https://securitytrails•com/list/ip/147•135•16•27
||2spendless.$document
||acrx.online^$document
||acrx.org^$document
@@ -26339,11 +26340,11 @@ toorgle.net##.join
147.135.16.27$network
!+ NOT_PLATFORM(windows, mac, android)
||147.135.16.27^$all
! https://www.google.no/search?q=mlp+g5&newwindow=1&tbm=isch&oq=mlp+g5&sclient=img
! https://www•google.no/search?q=mlp+g5&newwindow=1&tbm=isch&oq=mlp+g5&sclient=img
||ingeniovirtual.com^$document
! Spambot posts on Tumblr (19/09/2022)
tumblr.com##div[data-id][tabindex="-1"]:has(a[href^="https://href.li/?https://bit.ly/"])
! https://scambiofigu.forumcommunity.net/?t=57482915
! https://scambiofigu.forumcommunity•net/?t=57482915
||scambiofigu.net^$all
! Only links to another site's (APKPure) APKs, yet tries to promote its own browser extension on the alleged download pages, which comes across as suspicious
apkfab.com##.tip-extension
@@ -26518,8 +26519,8 @@ cdburnerxp.se##[href*="/downloadsetup.exe"]
! https://app.any.run/tasks/679e9afa-eb19-4414-a086-e280a779a448 and https://tria.ge/230217-xd8nksgc9x/behavioral2
||ru-torproject.ru^$all
||anapatformacion.org/modules/file/tor/tor-browser.zip^$all
! https://forums.malwarebytes.com/topic/295588-support-scam-supportclientexe-and-screenconnectwindowsclientexe/ (account required)
! https://forums.malwarebytes.com/topic/295605-techsupport-scam/ (account required)
! https://forums•malwarebytes•com/topic/295588-support-scam-supportclientexe-and-screenconnectwindowsclientexe/ (account required)
! https://forums•malwarebytes•com/topic/295605-techsupport-scam/ (account required)
! https://app.any.run/tasks/0f8b5786-177a-45c0-a1de-32e0d68beff2
||123secure.org^$all
! https://github.com/RPiList/specials/issues/948#issuecomment-1458739160
@@ -26529,7 +26530,7 @@ cdburnerxp.se##[href*="/downloadsetup.exe"]
34.80.59.191$network
!+ NOT_PLATFORM(windows, mac, android)
||34.80.59.191^$all
! Various domains on https://securitytrails.com/list/ip/72.14.178.174
! Various domains on https://securitytrails•com/list/ip/72•14•178•174
|http://www6.$document,domain=~often-used-in-malware-redirections.*
|http://www1.*&kw$document,domain=~often-used-in-malware-redirections.*
||megabooru.com^$all
@@ -26584,7 +26585,7 @@ cdburnerxp.se##[href*="/downloadsetup.exe"]
198.58.118.167$network
!+ NOT_PLATFORM(windows, mac, android)
||198.58.118.167^$all
! https://hutudole.com/za-mu-%c9%93ullo-da-matakan-da-za-su-hana-al%c6%99alai-kwa%c9%97ayin-cin-hanci-ba-tinubu/
! https://hutudole•com/za-mu-%c9%93ullo-da-matakan-da-za-su-hana-al%c6%99alai-kwa%c9%97ayin-cin-hanci-ba-tinubu/
||123chance.net^$all
||123links4u.net^$all
||123prizes.net^$all
@@ -26985,7 +26986,7 @@ cdburnerxp.se##[href*="/downloadsetup.exe"]
139.45.197.249$network
!+ NOT_PLATFORM(windows, mac, android)
||139.45.197.249^$all
! https://dnpedia.com/tlds/topm.php bizarrely listing "anahitagirted.uno" as the 622th most visited domain worldwide
! https://dnpedia•com/tlds/topm•php bizarrely listing "anahitagirted•uno" as the 622th most visited domain worldwide
||acorusinfield.life^$all
||acridlydebit.live^$all
||aeneasclosure.website^$all
@@ -27718,9 +27719,9 @@ facebook.com##div[class*=ImageBlockContent] .clearfix:has-text(0nl!ne)
$csp=upgrade-insecure-requests,domain=apache.org|gnu.org|washington.edu|nyu.edu|ufl.edu|oecd.org|bu.edu|wikidot.com|alternativenation.net
! ——— Anti-'Malware comments' (Currently Disqus-specific) ———
! https://myip.ms/info/limitexcess
! https://myip•ms/info/limitexcess
*#?#.post-list > .post-content:has-text(/^.*Best\sgirls\swebcam.*$/i)
! https://myip.ms/info/memberarea/My_Account.html
! https://myip•ms/info/memberarea/My_Account•html
*#?#script[src*=disquscdn] + #layout .post-content:has-text(Viagra)
*#?#script[src*=disquscdn] + #layout .post-content:has-text(We offer unlimited)
*#?#script[src*=disquscdn] + #layout .post-content:has-text(.com specialize)
@@ -27734,7 +27735,7 @@ $csp=upgrade-insecure-requests,domain=apache.org|gnu.org|washington.edu|nyu.edu|
! This section covers ones that would not normally be found in EasyList or AdGuard Base, for instance McAfee WebAdvisor (which also tries to change the search engine)
||webadvisorc.rest.gti.mcafee.com^
||mip.api.mcafeewebadvisor.com^
! https://get.adobe.com/no/reader/
! https://get•adobe•com/no/reader/
get.adobe.com###offersInformationPane
! Gigabyte APP Center (which use sneaky tricks to install a Norton 360 trial period; May require «AdGuard for Windows»)
||mb.download.gigabyte.com/FileList/Swhttp/DriverUpd/ANTIVIRUS^
@@ -28067,7 +28068,7 @@ www.microsoft.com##a[data-pfns][data-pfns^="9"][data-pfns*="dev."]
www.microsoft.com##a[data-pfns][href*=pacman]
www.microsoft.com##a[data-pfns][href*=pac-men]
! https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
! https://eclypsium•com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
|http://mb.download.gigabyte.com/FileList/Swhttp/LiveUpdate4^
! (Presumably anonymous) E-mail tips
@@ -1,9 +1,10 @@
[Adblock Plus 3.13]
! Title: 💊 Dandelion Sprout's Anti-Malware List (for AdGuard Home, AdGuard for Android/Windows/macOS' DNS filtering, and Pi-Hole FTL ≥5.22)
! Version: 20August2024v1
! Version: 17September2024v1
! Expires: 2 days
! Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists
! (Note to self, only applicable to uBO: When 1.59.1 goes stable, implement "*$ipaddress=(...),all" for the IP addresses, alongside the previous syntaxing as the case is for AdGuard Browser Extension.)
! Homepage: https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#-english
! ——— Bad top-level domains ———
@@ -20,7 +21,7 @@
! Palau (Put on break due to too many whitelistings being needed)
!!!||pw^$denyallow=libgen.pw|petridish.pw|palaugov.pw|dpc.pw|buttercup.pw|rezka.pw|darkcrystal.pw|xor.pw|fullhdfilmizlesene.pw|gopass.pw|vost.pw|core.pw|bittor.pw|plutonium.pw|nitter.pw|kge.pw
! Legitimate use is almost non-existent, but has a tiny userbase in Japan. Its extreme common-ness in malware redirections means that the entry will be kept forever.
||*.top^$dnstype=~CNAME,denyallow=caitlin.top|callmebymygender.top|corriente.top|gdtot.top|nicenature.top|reminder.top|magocoro.top|castlevania.top|suiten.top|shucks.top|1stream.top|ambr.top|techblog.top|changlam10.top|changlam11.top|pdcdn1.top|mastodon.top|pressplay.top|chillx.top|strims.top|thedesk.top|audioforyou.top|pegelinux.top|awavenue.top|reyhub.top
||*.top^$dnstype=~CNAME,denyallow=caitlin.top|callmebymygender.top|corriente.top|gdtot.top|nicenature.top|reminder.top|magocoro.top|castlevania.top|suiten.top|shucks.top|1stream.top|ambr.top|techblog.top|changlam10.top|changlam11.top|pdcdn1.top|mastodon.top|pressplay.top|chillx.top|strims.top|thedesk.top|audioforyou.top|pegelinux.top|awavenue.top|reyhub.top|iboxs.top
! International topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent.
||*.loan^$dnstype=~CNAME
!!!||agency^$denyallow=battlefield.agency|baam.agency|robotzebra.agency|uphotel.agency|ws.agency (Can't remember the last time I saw it used in a redirection train.)
@@ -29,7 +30,7 @@
!!!||ooo^$denyallow=toast.ooo
! (https://github.com/DandelionSprout/adfilt/issues/999)
!!!@@://oo*.ooo/
! https://bgp.he.net/AS202492#_prefixes (17/07/2022)
! https://bgp.he•net/AS202492#_prefixes (17/07/2022)
!!!||monster^$denyallow=egybest.monster|yts.monster|cloudcdn.monster|fedi.monster|rollenspiel.monster|tts.monster|geometry.monster
! https://github.com/AdguardTeam/AdguardFilters/issues/131156
!!!||sbs^$denyallow=ecopulse.sbs
@@ -123,31 +124,31 @@
! ——— Links to PC "optimising" "tool" PUPs that'll most likely stuff your PC full of nagware and malware ———
! ¤¤¤ ReImagePlus (Also added to "uBlock Filters - Badware Risks") ¤¤¤
! https://windowsreport.com/extend-windows-laptop-battery-life/
! https://appuals.com/fix-error-0x800701e3-on-windows-7-8-1-10/
! https://ugetfix.com/ask/how-to-fix-windows-store-error-0x8000ffff/
! https://www.thewindowsclub.com/fix-windows-update-error-0xc1900130-on-windows-10
! https://www.majorgeeks.com/files/details/patch_my_pc.html
! https://windowsreport•com/extend-windows-laptop-battery-life/
! https://appuals•com/fix-error-0x800701e3-on-windows-7-8-1-10/
! https://ugetfix•com/ask/how-to-fix-windows-store-error-0x8000ffff/
! https://www•thewindowsclub•com/fix-windows-update-error-0xc1900130-on-windows-10
! https://www•majorgeeks•com/files/details/patch_my_pc•html
! https://www.2-spyware.com/remove-redirector-gvt1-com.html
! https://www•2-spyware•com/remove-redirector-gvt1-com•html
! ¤¤¤ ScanUtilities ¤¤¤
! https://www.bynarycodes.com/fix-windows-10-update-error-0x80070006/
! https://www•bynarycodes•com/fix-windows-10-update-error-0x80070006/
! ¤¤¤ Driver Easy ¤¤¤
! https://www.drivereasy.com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/
! https://www.drivereasy.com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/
! https://www.drivereasy.com/knowledge/download-gigabyte-audio-driver/
! https://www.drivereasy.com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/
! https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/
! https://www•drivereasy•com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/
! https://www•drivereasy•com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/
! https://www•drivereasy•com/knowledge/download-gigabyte-audio-driver/
! https://www•drivereasy•com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/
! https://www•drivereasy•com/knowledge/solved-this-display-does-not-support-hdcp/
! ¤¤¤ Slimware DriverUpdate ¤¤¤
! https://forums.windowscentral.com/
! https://forums•windowscentral•com/
! ¤¤¤ Driverpack Online (Accidentally also fixed in EasyPrivacy and «AdGuard Mobile Ads») ¤¤¤
! ¤¤¤ SpyHunter links ¤¤¤
! https://howtoremove.guide/redirector-gvt1-com-virus-malware-chrome-removal/
! https://www.2-spyware.com/remove-redirector-gvt1-com.html
! https://howtoremove•guide/redirector-gvt1-com-virus-malware-chrome-removal/
! https://www•2-spyware•com/remove-redirector-gvt1-com•html
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-968070041
! https://www.cyclonis.com/how-to-create-gmail-account-without-phone-number/
! https://www.2-viruses.com/remove-ad-spam-press-allow-to-continue
! https://www•cyclonis•com/how-to-create-gmail-account-without-phone-number/
! https://www•2-viruses•com/remove-ad-spam-press-allow-to-continue
! https://github.com/iam-py-test/my_filters_001/issues/119
@@ -158,11 +159,11 @@
! ¤¤¤ Restoro ¤¤¤
! https://www.windowsdispatch.com/fix-system-restore-0x81000203-error-code/
! https://dlldownloads.com/xlive-dll/
! https://windowsreport.com/find-remove-duplicate-files-windows-10/
! https://windowsreport.com/how-to-update-roblox/ (08/12/2022)
! https://appuals.com/pr-connect-reset-error/
! https://www•windowsdispatch•com/fix-system-restore-0x81000203-error-code/
! https://dlldownloads•com/xlive-dll/
! https://windowsreport•com/find-remove-duplicate-files-windows-10/
! https://windowsreport•com/how-to-update-roblox/ (08/12/2022)
! https://appuals•com/pr-connect-reset-error/
! ¤¤¤ "Driver" download sites that instead download PUP tools ¤¤¤
||driver-soft.com^
! ¤¤¤ Outbyte ¤¤¤
@@ -180,7 +181,7 @@
/^https://(apps?|best|competition|game|mobile|play|prize|reward|sweeps)\d{2,8}\.[a-z-]{5,22}\d{1,8}\.(icu|life|live)/
! https://github.com/AdguardTeam/AdguardFilters/issues/58737
! https://github•com/AdguardTeam/AdguardFilters/issues/58737
/^https?:\/\/(?:www\.)?[-0-9a-z]{14,}\.(?:biz|fun|live)\/[a-zA-Z]{10,}\.php$/biz|fun|live
! ——— Banner for "MSN New Tab" ———
@@ -318,7 +319,7 @@
||githubuser.com^$denyallow=you-were-likely-looking-for-githubusercontent.com
||rgithub.com^$denyallow=you-were-likely-looking-for-githubusercontent.com
||githubt.com^$denyallow=you-were-likely-looking-for-githubusercontent.com
! https://scammer.info/t/discord-nitro-scam-25/87887
! https://scammer•info/t/discord-nitro-scam-25/87887
! ——— Frequently used to infiltrate and maliciously redirect sites, e.g. ToonBarn ———
@@ -352,9 +353,9 @@
3.226.8.132
3.216.243.46
||roamingclicks.com^
! Source: desidert.no
! Source: desidert•no
! Source: vn-zoom.com
! Source: vn-zoom•com
||ttnrd.com^
||amanda.*.com^
||katie.*.com^
@@ -364,7 +365,7 @@
54.152.245.247
35.172.40.232
3.90.125.85
! Various ex-affiliate links at www.zombooru.com
! Various ex-affiliate links at www•zombooru•com
@@ -3548,7 +3549,7 @@
://192.243.59.
://192.243.61.
! https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315
! https://twitter•com/SUNgoddessOKAMI/status/1221295265195405315
||deviuser.com^
! https://github.com/AdguardTeam/AdguardFilters/issues/61838
/scan-update-and-protect-your-browser.html
@@ -3606,7 +3607,7 @@
||hooligapps.com^
||best202*-games-web1.com^
||theonlygames.com^
! https://maldita.es/malditobulo/2020/12/04/concurso-mercadona-ganar-tarjeta-regalo-100-euros-phishing/
! https://maldita•es/malditobulo/2020/12/04/concurso-mercadona-ganar-tarjeta-regalo-100-euros-phishing/
||notified-today.com^
||antivirus-update.com^
||new-message.cc^
@@ -3618,12 +3619,12 @@
||stay-notified.com^
||stay-notified.xyz^
167.99.249.47
! https://maldita.es/malditobulo/2020/12/02/lidl-regala-robot-cocina-silvercrest-monsieur-cuisine-encuesta/
! https://maldita.es/malditobulo/2020/11/25/jordi-evole-el-hormiguero-bitcoin-revolution-timo-twitter/
! https://maldita•es/malditobulo/2020/12/02/lidl-regala-robot-cocina-silvercrest-monsieur-cuisine-encuesta/
! https://maldita•es/malditobulo/2020/11/25/jordi-evole-el-hormiguero-bitcoin-revolution-timo-twitter/
||moderncomputer.net^
! https://maldita.es/malditobulo/2020/11/18/gobierno-tarjeta-debito-prepagada-covid-19-phishing-whatsapp/
! https://maldita•es/malditobulo/2020/11/18/gobierno-tarjeta-debito-prepagada-covid-19-phishing-whatsapp/
||version.gratis^
! https://maldita.es/malditobulo/2020/11/18/no-no-es-cierto-que-amancio-ortega-haya-invertido-100-millones-en-bitcoin-revolution-es-una-web-falsa/
! https://maldita•es/malditobulo/2020/11/18/no-no-es-cierto-que-amancio-ortega-haya-invertido-100-millones-en-bitcoin-revolution-es-una-web-falsa/
||starpowders.github.io^
! https://github.com/AdguardTeam/AdguardFilters/issues/69611
/^http://[a-z0-9-]{30,}\..*\.elasticbeanstalk\.com(/|$)/
@@ -3688,7 +3689,7 @@
108.170.52.156
! https://github.com/DandelionSprout/adfilt/issues/198
||mysecrethoookup.com^
! https://www.bleepingcomputer.com/virus-removal/ (18/06/2021)
! https://www•bleepingcomputer•com/virus-removal/ (18/06/2021)
||toksearches.xyz^
||smashapps.net^
||smashappsearch.com^
@@ -3700,7 +3701,7 @@
||searchinggood.com^
||searchprivacyplus.com^
||powersmashsearch.com^
! https://www.bleepingcomputer.com/virus-removal/remove-please-allow-to-watch-the-video
! https://www•bleepingcomputer•com/virus-removal/remove-please-allow-to-watch-the-video
||1000-dollar.cash^
||1000-eur.cash^
||bokerstars.com^
@@ -3794,9 +3795,9 @@
95.168.170.165
213.227.145.147
213.227.149.216
! https://twitter.com/adamziaja/status/1252234957679808513
! https://twitter•com/adamziaja/status/1252234957679808513
||wow-robotics.xyz^
! https://blog.sucuri.net/2021/05/woocommerce-credit-card-skimmer.html
! https://blog•sucuri•net/2021/05/woocommerce-credit-card-skimmer•html
||deepe.icu^
||google-analytics.buzz^
||intr0.cyou^
@@ -3844,7 +3845,7 @@
||ssielearning.com^
||paymetconfirm.com^
69.49.231.244
! https://movsb.0x0.st/users/mia
! https://movsb•0x0•st/users/mia
||vid.me^$third-party
||5starhdporn.com^$frame,third-party
! https://github.com/DandelionSprout/adfilt/issues/228
@@ -3914,22 +3915,22 @@
||pc-my-protection.xyz^
||beta-news.org^
! https://github.com/DandelionSprout/adfilt/pull/266
! https://www.virustotal.com/gui/domain/kirstialechulbard.space/relations
! https://www.virustotal.com/gui/ip-address/198.54.117.244/relations
! https://www•virustotal•com/gui/domain/kirstialechulbard•space/relations
! https://www•virustotal•com/gui/ip-address/198•54•117•244/relations
||dashwoodestates.com^
! http://vxvault.net/ViriFiche.php?ID=44013
! https://www.virustotal.com/gui/url/8066b87ad10ddb5466bc307bb48454139572f6c8c8f80a9734275ac89cf966af/detection
! https://www.virustotal.com/gui/url/826c451929420c4da32552f967fb1cab6467405a29c65b23802aaadb6a8c7505/detection
! https://safeweb.norton.com/report/show?url=192.3.110.170
! http://vxvault•net/ViriFiche•php?ID=44013
! https://www•virustotal•com/gui/url/8066b87ad10ddb5466bc307bb48454139572f6c8c8f80a9734275ac89cf966af/detection
! https://www•virustotal•com/gui/url/826c451929420c4da32552f967fb1cab6467405a29c65b23802aaadb6a8c7505/detection
! https://safeweb•norton•com/report/show?url=192•3•110•170
192.3.110.170
! https://forums.malwarebytes.com/topic/278209-removal-instructions-for-socialsearchconverter/
! https://forums•malwarebytes•com/topic/278209-removal-instructions-for-socialsearchconverter/
||socialsearchconverter.com^
||install.socialsearchconverter.com^
||feed.socialsearchconverter.com^
||api.socialsearchconverter.com^
||notify-service.com^
||install.stream-all.com^
! copied over from https://github.com/uBlockOrigin/uAssets/issues/9848
! Copied over from https://github.com/uBlockOrigin/uAssets/issues/9848
||gghacks.com^
||rewardsgiantusa.com^
||promotionsonlineusa.com^
@@ -3941,10 +3942,10 @@
||mediafiire.com^
||d1xkyo9j4r7vnn.cloudfront.net^
||onlinepromotionsusa.com^
! https://securelist.com/apkpure-android-app-store-infected/101845/
! https://www.virustotal.com/gui/url/866a25343864f03dc5a10105fda523bfbb6ed09c486d07fd31ca2b5306440089/detection
! https://securelist•com/apkpure-android-app-store-infected/101845/
! https://www•virustotal•com/gui/url/866a25343864f03dc5a10105fda523bfbb6ed09c486d07fd31ca2b5306440089/detection
||wcf.seven1029.com^
! https://www.virustotal.com/gui/url/9c66e331e455dc5c5c9d06e1a537580c9e4db279182d2285c07783e837806a16/detection
! https://www•virustotal•com/gui/url/9c66e331e455dc5c5c9d06e1a537580c9e4db279182d2285c07783e837806a16/detection
||foodin.site^
! https://github.com/AdguardTeam/AdguardFilters/issues/91506#issuecomment-904080849
||totalav.com^
@@ -3956,22 +3957,22 @@
||totaladblock.com^
||totaladblocker.xyz^
||totalwebshield.xyz^
! https://www.virustotal.com/gui/file/c683bc3da4966110b419ac54d09a54ce798efdb51be398331d9ce011e2636fa9/community
! https://www.virustotal.com/gui/url/5618023ed5a768d7f879c0d599b9ba7cff0e9171201981256eeaf5ce8eb09fdb/detection
! https://www.virustotal.com/gui/url/8cf9ca3359f17cf92b9b3e5fdab30e29be23f08e66c8c5396c9410fcb91f7c3c/detection
! https://www•virustotal•com/gui/file/c683bc3da4966110b419ac54d09a54ce798efdb51be398331d9ce011e2636fa9/community
! https://www•virustotal•com/gui/url/5618023ed5a768d7f879c0d599b9ba7cff0e9171201981256eeaf5ce8eb09fdb/detection
! https://www•virustotal•com/gui/url/8cf9ca3359f17cf92b9b3e5fdab30e29be23f08e66c8c5396c9410fcb91f7c3c/detection
91.241.19.38
! https://www.virustotal.com/gui/url/46e095c35d83e2dd0b98df4b5844d3d87948de0c930a618600121020a514c801/detection
! https://safeweb.norton.com/report/show?url=telete.in
! https://www.siteadvisor.com/sitereport.html?url=telete.in
! https://www•virustotal•com/gui/url/46e095c35d83e2dd0b98df4b5844d3d87948de0c930a618600121020a514c801/detection
! https://safeweb•norton•com/report/show?url=telete•in
! https://www•siteadvisor•com/sitereport•html?url=telete•in
||telete.in^
! https://www.virustotal.com/gui/file/e63b2d03e3fee2d538f8bd721b61dd3641284fa941087d846dea6f15cab40308/community
! https://www.virustotal.com/gui/url/fbbc8a671bff32539bd829a76f6df9f364a21ac2279922e64e3ec494a1669dd3/detection
! https://www•virustotal•com/gui/file/e63b2d03e3fee2d538f8bd721b61dd3641284fa941087d846dea6f15cab40308/community
! https://www•virustotal•com/gui/url/fbbc8a671bff32539bd829a76f6df9f364a21ac2279922e64e3ec494a1669dd3/detection
||kiff.tech^
! https://www.virustotal.com/gui/domain/kiff.tech/relations
! https://www.virustotal.com/gui/url/dc038496b1b5358b97f89440135ec91258b406c40859a2cd95983dc7a81e0cfa/detection
! https://www•virustotal•com/gui/domain/kiff•tech/relations
! https://www•virustotal•com/gui/url/dc038496b1b5358b97f89440135ec91258b406c40859a2cd95983dc7a81e0cfa/detection
45.90.58.90
! https://www.virustotal.com/gui/file/e565ba89d034418fd26a5f642f6eeee4d72ee3b8dc69523419b7ca8dfd452730/community
! https://www.virustotal.com/gui/url/e3a9189a1e1256beba8e0fc3abfeab6acb09f7f8cabfd973e22be9f77bb6886f/detection
! https://www•virustotal•com/gui/file/e565ba89d034418fd26a5f642f6eeee4d72ee3b8dc69523419b7ca8dfd452730/community
! https://www•virustotal•com/gui/url/e3a9189a1e1256beba8e0fc3abfeab6acb09f7f8cabfd973e22be9f77bb6886f/detection
95.85.89.98
! https://github.com/DandelionSprout/adfilt/issues/267
||tekhacks.net^
@@ -3988,7 +3989,7 @@
!! https://www.virustotal.com/gui/file/9f154115fa8045aa05f15f7cd1de9623ebe32e8ea400279ecb5dfa3596952e3b/community
103.169.90.205
! https://github.com/DandelionSprout/adfilt/pull/281
! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
! https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
125.44.43.45
182.121.8.240
42.235.183.74
@@ -3999,9 +4000,9 @@
188.120.50.98
190.238.183.5
27.220.253.78
! https://www.virustotal.com/gui/file/0374ead74fa807fb1737d8829fdb5bad6c93779f6b9eb7162eddabff7a64acff/community
! https://www•virustotal•com/gui/file/0374ead74fa807fb1737d8829fdb5bad6c93779f6b9eb7162eddabff7a64acff/community
||esetnode32-antiviru.ydns.eu^
! https://www.joesandbox.com/analysis/486636/0/html#domains
! https://www•joesandbox•com/analysis/486636/0/html#domains
||aieov.com^
! Relations to the original domain
192.3.194.242
@@ -4075,17 +4076,17 @@
||army-glo.scrollingsystem.com^
||mcafee12.tt.omtrdc.net^
||trolleydrop.info^
! https://www.virustotal.com/gui/ip-address/70.32.1.32/relations
! https://www•virustotal•com/gui/ip-address/70•32•1•32/relations
||cd.org^
! https://www.virustotal.com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community
! https://www•virustotal•com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community
! https://github.com/DandelionSprout/adfilt/commit/f7f114945c83b339be5cdd848e229680d9918abb#commitcomment-57642875
23.94.26.138
! https://github.com/DandelionSprout/adfilt/pull/298
! https://www.virustotal.com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community
! https://www•virustotal•com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community
205.185.126.200
! https://www.virustotal.com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community
! https://www•virustotal•com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community
185.243.56.167
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
123.10.224.135
59.47.187.147
39.68.172.210
@@ -4133,24 +4134,24 @@
111.224.199.91
119.250.236.122
112.30.110.58
! https://www.virustotal.com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community
! https://www•virustotal•com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community
||pcae.de^
! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
! https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
117.196.49.21
115.55.54.234
115.52.17.123
182.59.69.21
! https://www.virustotal.com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community
! https://www•virustotal•com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community
||chip-secured-download.de^
! https://www.virustotal.com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb
! https://www•virustotal•com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb
! Domains which resolve to this (already blocked) IP - for users of HOSTs/Domains/uBlock Origin
||nctylivpwhpby.com^
||phhitgjxsit.com^
! https://www.virustotal.com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1
! https://www•virustotal•com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1
||saimission.org^
! https://www.virustotal.com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1
! https://www•virustotal•com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1
||grub-wa-saya.duckdns.org^
! https://www.virustotal.com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations
! https://www•virustotal•com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations
||driversupport.com^
! A PUP and scam website
||mycleanpc.com^
@@ -4161,9 +4162,9 @@
! The main website for the MyCleanPC company
||realdefen.se^
! Vermilion Strike
! https://www.virustotal.com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations
! https://www•virustotal•com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations
160.202.163.100
! https://www.virustotal.com/gui/ip-address/160.202.163.100/relations
! https://www•virustotal•com/gui/ip-address/160•202•163•100/relations
||microsoftkernel.com^
||microsofthk.com^
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-938167311
@@ -4174,11 +4175,11 @@
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-944612753
||pushbizapi.com^
! https://github.com/DandelionSprout/adfilt/pull/303
! https://www.virustotal.com/gui/file/37328efa73c248b460aba605d7745b024f31ab7ab864e1af273e9a197a188f42/community
! https://www•virustotal•com/gui/file/37328efa73c248b460aba605d7745b024f31ab7ab864e1af273e9a197a188f42/community
45.95.169.115
! https://www.virustotal.com/gui/file/03e4533ba8874c2f4dcdb94bd135914fa4c22ed477d7c0395dc2322b6468e249/community
! https://www•virustotal•com/gui/file/03e4533ba8874c2f4dcdb94bd135914fa4c22ed477d7c0395dc2322b6468e249/community
45.148.120.80
! https://www.virustotal.com/gui/file/1a782cab036efa567c2c42b7bae9452bf735be72f0b00d68f6dcba48cea526fa/community
! https://www•virustotal•com/gui/file/1a782cab036efa567c2c42b7bae9452bf735be72f0b00d68f6dcba48cea526fa/community
85.239.33.9
! Relations to the domain above
||adminsys.serveftp.com^
@@ -4195,11 +4196,11 @@
||c4ase-verified9932.serveftp.com^
||1log-wellsfargo.serveftp.com^
||eposcardokubo.serveftp.com^
! https://www.virustotal.com/gui/file/8a39f18caa77d52e80bec05f584ec50e733a3be1e33551d8902e95b9b0bfe6c0/community
! https://www•virustotal•com/gui/file/8a39f18caa77d52e80bec05f584ec50e733a3be1e33551d8902e95b9b0bfe6c0/community
107.173.176.183
! https://www.virustotal.com/gui/file/54054209c921a68f12a9b29d6e84f1b45cb417bc0b5a99356a245727e0a41e40/community
! https://www•virustotal•com/gui/file/54054209c921a68f12a9b29d6e84f1b45cb417bc0b5a99356a245727e0a41e40/community
45.148.120.171
! https://twitter.com/soranker0/status/1449491402409185283
! https://twitter•com/soranker0/status/1449491402409185283
://disordgift.
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-950330114
||free-softs.net^
@@ -4226,7 +4227,7 @@
||kokotrokot.com^
!!!?next_url=popup (https://github.com/AdguardTeam/AdguardFilters/issues/108072#issuecomment-1021534226)
! https://www.upwork.com/freelance-jobs/apply/Integarte-push-notification-for-chrome_~013c73ed9282225184/
! https://www•upwork•com/freelance-jobs/apply/Integarte-push-notification-for-chrome_~013c73ed9282225184/
||mugrikees.com^
||alpha-news.org^
! https://github.com/iam-py-test/investigations/blob/main/2021/11/3/1.md
@@ -4235,7 +4236,7 @@
||youvetube.com^
||youutube.com^
! https://github.com/DandelionSprout/adfilt/pull/348
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
39.83.80.247
68.197.33.124
219.157.21.37
@@ -4267,7 +4268,7 @@
106.86.172.194
103.233.216.77
183.188.192.55
! https://www.virustotal.com/gui/file/3bf1b7e9bdaeaa4a5619cf26b59767637bc44193df2a0470df263b98b1fe47fe/community
! https://www•virustotal•com/gui/file/3bf1b7e9bdaeaa4a5619cf26b59767637bc44193df2a0470df263b98b1fe47fe/community
198.23.255.14
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-971512075
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-971495248
@@ -4278,7 +4279,7 @@
||runmodes.com^
91.121.67.60
172.67.186.189
! https://www.virustotal.com/gui/url/af8f443208f4e86d469549b219fccbeb43b7cae40be5f1b4c4e5083e27fc8111
! https://www•virustotal•com/gui/url/af8f443208f4e86d469549b219fccbeb43b7cae40be5f1b4c4e5083e27fc8111
||inconclusive-pyrite-grandparent.glitch.me^
||delicate-tame-angora.glitch.me^
||secureinvoice.glitch.me^
@@ -4289,9 +4290,9 @@
||aquamarine-cotton-impala.glitch.me^
||mature-periwinkle-advantage.glitch.me^
||tough-numerous-lemur.glitch.me^
! https://scammer.info/t/mcafee-phish/83725
! https://scammer•info/t/mcafee-phish/83725
||securefirst.us-east-1.linodeobjects.com^
! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
! https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
39.65.72.211
42.238.151.197
27.213.60.53
@@ -4312,21 +4313,21 @@
||members.tonightshookup.com^
||t.tonightshookup.com^
||yourladiefun.life^
! https://www.virustotal.com/gui/url/a2524bba49ae71297d2b408b30d058700d9c80b5b1154924cafe190ec3e605a6/detection
! https://www•virustotal•com/gui/url/a2524bba49ae71297d2b408b30d058700d9c80b5b1154924cafe190ec3e605a6/detection
! https://www.virustotal.com/gui/file/2b2628a50d3b39b0fa2395d487bf62b00e37cdae847ff76ee58399bbe4e9f7b3/community
! https://www•virustotal•com/gui/file/2b2628a50d3b39b0fa2395d487bf62b00e37cdae847ff76ee58399bbe4e9f7b3/community
194.87.138.20
! https://www.virustotal.com/gui/file/b320bc7a9151d70daca038c4356ca89bfcd4918bcd6f0f73683a27a6a72467ae/community
! https://www•virustotal•com/gui/file/b320bc7a9151d70daca038c4356ca89bfcd4918bcd6f0f73683a27a6a72467ae/community
103.167.92.73
! https://www.virustotal.com/gui/file/6146dfe56dcb49e1b843624a44e204754e15625a4f94b230b59a5cafc924f618/community
! https://www•virustotal•com/gui/file/6146dfe56dcb49e1b843624a44e204754e15625a4f94b230b59a5cafc924f618/community
||bursakulis.com^
! https://www.virustotal.com/gui/url/b333c49efa4d399e65c5e2d96a905b380acbca58a3e3052b7bd7cfcb3e0e81ee
! https://www•virustotal•com/gui/url/b333c49efa4d399e65c5e2d96a905b380acbca58a3e3052b7bd7cfcb3e0e81ee
||610418.selcdn.ru^
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-977912975
! https://www.tv2.no/nyheter/14368524/
! https://www•tv2•no/nyheter/14368524/
||alexstewartinternationalltd.rw^
||vps.re^
! https://www.tek.no/i/wOVv0o/
! https://www•tek•no/i/wOVv0o/
||21steditionnaturalgh.com^
! https://github.com/iam-py-test/investigations/blob/main/2021/11/24/1.md
||macsoftwarez.com^
@@ -4342,7 +4343,7 @@
||yunosurveys.com^
! https://github.com/uBlockOrigin/uAssets/pull/10620
||shadyclient.net^
! https://www.virustotal.com/gui/file/d546509ab6670f9ff31783ed72875dfc0f37fa2b666bd5870eecaaed2ebea4a8/community
! https://www•virustotal•com/gui/file/d546509ab6670f9ff31783ed72875dfc0f37fa2b666bd5870eecaaed2ebea4a8/community
58.249.74.79
27.45.14.109
27.40.101.191
@@ -4358,13 +4359,13 @@
||totalnicefeed.com^
! https://github.com/iam-py-test/investigations/blob/main/2021/11/28/2.md
||bestlifeoffer20.com^
! https://scammer.info/t/password-stealer/84348
! https://bazaar.abuse.ch/sample/462a689d171f543c10efa08e963996d382585b67a6b298ec40d64f924adfb47a/
! https://scammer•info/t/password-stealer/84348
! https://bazaar•abuse•ch/sample/462a689d171f543c10efa08e963996d382585b67a6b298ec40d64f924adfb47a/
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
110.89.59.135
113.116.89.1
119.183.146.191
@@ -4376,33 +4377,33 @@
171.112.177.90
115.194.38.143
61.52.79.32
! https://scammer.info/t/pihishing-site-claiming-to-hold-a-ups-package-that-needs-payment/84466
! https://scammer•info/t/pihishing-site-claiming-to-hold-a-ups-package-that-needs-payment/84466
://ups-dk.$denyallow=dk|nu|se|no|fo|gl|ups.com,ups-dk.*
! https://www.virustotal.com/gui/url/269d374b629d7896da1f9e7449bd5afecf6284a9a564244f96a71e5192363635?nocache=1
! https://www•virustotal•com/gui/url/269d374b629d7896da1f9e7449bd5afecf6284a9a564244f96a71e5192363635?nocache=1
||lowseelan.com^
! https://www.virustotal.com/gui/file/50fd813cf8fe981e6aee179f8ba394e5527c5128b84c328f9f8347cd994bbc42/community
! https://www•virustotal•com/gui/file/50fd813cf8fe981e6aee179f8ba394e5527c5128b84c328f9f8347cd994bbc42/community
! https://www.virustotal.com/gui/file/2ea599605c4d65902943f12e1114a71af7a40fa7dffbf018b0ee3e7a61aaeaa3/community
! https://www•virustotal•com/gui/file/2ea599605c4d65902943f12e1114a71af7a40fa7dffbf018b0ee3e7a61aaeaa3/community
! https://github.com/DandelionSprout/adfilt/pull/395
! https://www.huorong.cn/info/1531309921141.html
! https://www•huorong.cn/info/1531309921141.html
||kuaizip.com^
! https://www.huorong.cn/info/1618397948649.html - possible malware
! https://www•huorong.cn/info/1618397948649.html - possible malware
! ||zhuangjizhuli.com^
! ||zhuangjizhuli.net^
! https://github.com/uBlockOrigin/uAssets/pull/9656
||geekotg.com^
! https://www.huorong.cn/info/1526627586130.html
! https://www•huorong.cn/info/1526627586130.html
||xiaobaixitong.com^
! https://www.huorong.cn/info/1577158839403.html
! https://www•huorong.cn/info/1577158839403.html
||daque.cn^
! https://www.huorong.cn/info/1598957552515.html
! https://www•huorong.cn/info/1598957552515.html
||dabaicai.com^
! https://www.huorong.cn/info/1617368984641.html
! https://www•huorong.cn/info/1617368984641.html
||qqfzn.com^
! https://github.com/uBlockOrigin/uAssets/pull/10017
||flash.cn^
! https://www.nrk.no/vestfoldogtelemark/1.15750360
! https://www•nrk.no/vestfoldogtelemark/1.15750360
||dundeehills.group^
!+ NOT_OPTIMIZED
132.148.220.142
@@ -4416,8 +4417,8 @@
! https://scammer.info/t/fake-facebook-login-page/84939
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-988127908
! https://www.tek.no/i/lVeQAe/
! https://www.nkom.no/aktuelt/ikke-trykk-pa-lenker-i-sms--for-du-er-helt-sikker/
! https://www•tek.no/i/lVeQAe/
! https://www•nkom.no/aktuelt/ikke-trykk-pa-lenker-i-sms--for-du-er-helt-sikker/
||eccolabgroup.com^
||galerijajava.ba^
||p-stn.net^
@@ -4427,7 +4428,7 @@
34.201.22.10
! https://scammer.info/t/crypto-scammers-onceagain/85354
! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
! https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
123.10.225.196
122.192.106.84
172.88.199.9
@@ -4478,9 +4479,9 @@
||d13pxqgp3ixdbh.cloudfront.net^
! Other
||crashfixes.com^
! https://www.virustotal.com/gui/url/c25fe34c05cc8e9136027a67c277e175a5d6e35af921ee37bad98bdfeea6a2f9/community
! https://www•virustotal•com/gui/url/c25fe34c05cc8e9136027a67c277e175a5d6e35af921ee37bad98bdfeea6a2f9/community
||splendid-fallacious-anaconda.glitch.me^
! https://www.virustotal.com/gui/file/9d40ae0439ddc594b2cf64e21ad0fdea9bb440524298e3a6bcfcc1fb417f1ed2/relations
! https://www•virustotal•com/gui/file/9d40ae0439ddc594b2cf64e21ad0fdea9bb440524298e3a6bcfcc1fb417f1ed2/relations
91.240.118.172
! "Press Allow to continue"
||kuyhaa-mee.com^
@@ -4491,7 +4492,7 @@
||lucymods.com^
||gluegames.xyz^
! https://twitter.com/iam_py_test/status/1496259425493225472
! https://twitter•com/iam_py_test/status/1496259425493225472
@@ -4506,7 +4507,7 @@
! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1074966240
||melding.link^
! https://twitter.com/MBThreatIntel/status/1509956416311742464
! https://twitter•com/MBThreatIntel/status/1509956416311742464
||xposednews.xyz^
||tomguide.xyz^
||eronews.xyz^
@@ -4527,7 +4528,7 @@
||freeversioncrack.com^$document
||top3hostngc.xyz^
198.199.120.251
! https://www.telia.no/kundeservice/mobil/malware-flubot-android/
! https://www•telia.no/kundeservice/mobil/malware-flubot-android/
!+ NOT_OPTIMIZED
/^https?://(www\.)?[a-z0-9-]{1,}\.[a-z]{2,17}/[a-z0-9]/\?[a-z0-9.-]{8,}$/
! A Discord conversation I had about Throneful
@@ -4551,7 +4552,7 @@
||cumpussyy.uno^
195.201.253.130
195.201.253.131
! The bottom download button on https://www.sushichop.com/
! The bottom download button on https://www•sushichop•com/
||installiq.com^
||specgoal.com^
||sandhyapi.online^
@@ -4574,7 +4575,7 @@
96.47.230.68
96.47.230.69
96.47.230.70
! https://securitytrails.com/list/ns/ns1.fastthinkingdns.com
! https://securitytrails•com/list/ns/ns1•fastthinkingdns•com
||highercaptcha-settle.
||highercaptchasettle.
||ns*.fastthinkingdns.com^
@@ -4620,7 +4621,7 @@
||online-guard.com^
! https://twitter.com/iam_py_test/status/1545164642346930176
! https://twitter•com/iam_py_test/status/1545164642346930176
||amazon-security-info.lnk.to^
! https://github.com/AdguardTeam/AdguardFilters/issues/123968
! https://github.com/AdguardTeam/AdguardFilters/issues/124620
@@ -4935,7 +4936,7 @@
158.247.212.220
165.227.168.212
! https://www.reddit.com/r/engrish/comments/w6u4uy/received_this_text_message_yesterday_i_am_very/
! https://www•reddit.com/r/engrish/comments/w6u4uy/received_this_text_message_yesterday_i_am_very/
://162.241.115.
! https://dinside.dagbladet.no/mobil/ikke-la-deg-friste/76730599
@@ -5181,7 +5182,7 @@
51.91.66.125
51.178.76.105
147.135.253.55
! https://github.com/uBlockOrigin/uAssets/issues/14569 → https://www.virustotal.com/gui/url/b819586938326577d759d8024abe3e0e6de1c853d6b67824daf6f613fba0f63b/detection (https://app.any.run/tasks/5914a712-1a73-4432-b89a-ca0627a24ade)
! https://github.com/uBlockOrigin/uAssets/issues/14569 → https://www•virustotal•com/gui/url/b819586938326577d759d8024abe3e0e6de1c853d6b67824daf6f613fba0f63b/detection (https://app•any•run/tasks/5914a712-1a73-4432-b89a-ca0627a24ade)
||bnbdeal.net^
! https://github.com/AdguardTeam/AdguardFilters/issues/129414
!+ NOT_OPTIMIZED
@@ -9211,7 +9212,7 @@
://196.245.52.
://196.245.56.
! https://www.bleepingcomputer.com/news/security/hackers-push-malware-via-google-search-ads-for-vlc-7-zip-ccleaner/
! https://www•bleepingcomputer•com/news/security/hackers-push-malware-via-google-search-ads-for-vlc-7-zip-ccleaner/
://rufus.download.popup
://virtualbox.download.popup
://vidiq.download.popup
@@ -9746,7 +9747,7 @@
||yourticketchance.com^
||yourorderupdate.com^
64.132.201.92
! https://www.adressa.no/nyheter/trondheim/i/BWkdkw/trodde-hun-skulle-faa-en-pakke-i-posten-ble-lurt-for-titusener
! https://www•adressa.no/nyheter/trondheim/i/BWkdkw/trodde-hun-skulle-faa-en-pakke-i-posten-ble-lurt-for-titusener
||acessmygov.online^
||centerlinkmygov.com^
||centierssl.us^
@@ -10471,7 +10472,7 @@
3.231.137.120
54.204.83.105
! https://github.com/DandelionSprout/adfilt/issues/808
! https://www.mandiant.com/resources/blog/tracking-evolution-gootloader-operations (26/01/2023)
! https://www•mandiant.com/resources/blog/tracking-evolution-gootloader-operations (26/01/2023)
||jonathanbartz.com^
||jp.imonitorsoft.com^
||junk-bros.com^
@@ -10705,7 +10706,7 @@
||wuruclas.co.in^
||zondeucearixes.com^
85.17.80.16
! https://www.adressa.no/nyheter/trondheim/i/Moq2wR/svindlere-kaarer-vinnere-i-konkurranser-gir-en-daarlig-foelelse-aa-forklare-at-dette-bare-er-tull
! https://www•adressa.no/nyheter/trondheim/i/Moq2wR/svindlere-kaarer-vinnere-i-konkurranser-gir-en-daarlig-foelelse-aa-forklare-at-dette-bare-er-tull
||sitey.me^
! https://github.com/AdguardTeam/AdguardFilters/issues/151479
||agazpeppily.live^
@@ -16813,7 +16814,7 @@
! (https://github.com/AdguardTeam/AdguardBrowserExtension/issues/2497)
/(//|\.|^)github\.[a-z]{2,20}(/|$)/$document,match-case,~third-party,github.*|com|org|net|co|blog|community|host|io|microsoft|office|uk|us|xn--fiqs8s|dev|archive.*
||github.sale^
! https://www.tv2.no/nyheter/innenriks/advarer-ikke-klikk-pa-lenken/16040614/
! https://www•tv2.no/nyheter/innenriks/advarer-ikke-klikk-pa-lenken/16040614/
||0nedr1ved0cumentonline.com^
||88godetailsvc.com^
||amexmobileupdate.cc^
@@ -22703,9 +22704,9 @@
! ——— Standard malware that I stumbled upon on my own ———
! http://www.toorgle.net/results.php?q=fetishkitsch&security=666
! http://www•toorgle•net/results•php?q=fetishkitsch&security=666
||downloadprovider.me^
! https://www.riverbender.com/articles/details/two-charged-in-connection-of-the-stallon-drug-raid-in-wood-river-46877.cfm
! https://www•riverbender•com/articles/details/two-charged-in-connection-of-the-stallon-drug-raid-in-wood-river-46877•cfm
||cash93.com^
||a4alig.com^
||cash03.com^
@@ -22718,7 +22719,7 @@
||netpay8.com^
||slimxketo.com^
||works35.com^
! Various ex-affiliate links at www.zombooru.com
! Various ex-affiliate links at www•zombooru•com
||allowandgo.com^
||aksuu.ru^
||allow-space.com^
@@ -22732,7 +22733,7 @@
||push.weo.su^
||traffsend.me^
||wwopenclick.club^
! Spam comments at https://www.accountkiller.com/en/delete-htcdev-account
! Spam comments at https://www•accountkiller•com/en/delete-htcdev-account
||azhydroxychloroquine.com^
||wisig.org^
||confrancisyalgomas.com^
@@ -22744,13 +22745,13 @@
||amoxycillin1st.com^
! The Jerma985 Discord server
||crazycrabreedville.com^
! https://flclever.weebly.com/pixie-hollow-mini-games.html (06/05/2021)
! https://flclever.weebly•com/pixie-hollow-mini-games•html (06/05/2021)
||messium.info^
! Various Google searches
://hullcitytigers.com^
! Various search results for 'kelloggs tresor' in Norwegian (30/05/2021)
/pgxhtogrzm-
! https://fx-onlinee.blogspot.com/2021/06/?r=Bergens-Tidende-Flertallet-av-fastlegene-i-Trondheim-sier-nei-til-Janssen-vaksinen-Umulig-%C3%A5-ta-det-ansvaret-seo+aj
! https://fx-onlinee•blogspot•com/2021/06/?r=Bergens-Tidende-Flertallet-av-fastlegene-i-Trondheim-sier-nei-til-Janssen-vaksinen-Umulig-%C3%A5-ta-det-ansvaret-seo+aj
! Fake security sites that think every single domain is a supervirus and which try to make you install PUP (Most commonly SpyHunter)
||malwarecleanerpro.com^
@@ -24983,8 +24984,8 @@
||sidenoteconcern.com^
||abnegationbanquet.com^
192.243.61.225
! https://twitter.com/medicinehelp/status/1550250932394409985
! https://securitytrails.com/list/ip/147.135.16.27
! https://twitter•com/medicinehelp/status/1550250932394409985
! https://securitytrails•com/list/ip/147•135•16•27
||2spendless.
||acrx.online^
||acrx.org^
@@ -25040,10 +25041,10 @@
||medicinecoupons.xyz^
||medicinehelp.news^
147.135.16.27
! https://www.google.no/search?q=mlp+g5&newwindow=1&tbm=isch&oq=mlp+g5&sclient=img
! https://www•google.no/search?q=mlp+g5&newwindow=1&tbm=isch&oq=mlp+g5&sclient=img
||ingeniovirtual.com^
! Spambot posts on Tumblr (19/09/2022)
! https://scambiofigu.forumcommunity.net/?t=57482915
! https://scambiofigu.forumcommunity•net/?t=57482915
||scambiofigu.net^
! Only links to another site's (APKPure) APKs, yet tries to promote its own browser extension on the alleged download pages, which comes across as suspicious
! Google results for 'Katy and Bob: Cake Café powerpc' (04/11/2022)
@@ -25189,15 +25190,15 @@
! https://app.any.run/tasks/679e9afa-eb19-4414-a086-e280a779a448 and https://tria.ge/230217-xd8nksgc9x/behavioral2
||ru-torproject.ru^
! https://forums.malwarebytes.com/topic/295588-support-scam-supportclientexe-and-screenconnectwindowsclientexe/ (account required)
! https://forums.malwarebytes.com/topic/295605-techsupport-scam/ (account required)
! https://forums•malwarebytes•com/topic/295588-support-scam-supportclientexe-and-screenconnectwindowsclientexe/ (account required)
! https://forums•malwarebytes•com/topic/295605-techsupport-scam/ (account required)
! https://app.any.run/tasks/0f8b5786-177a-45c0-a1de-32e0d68beff2
||123secure.org^
! https://github.com/RPiList/specials/issues/948#issuecomment-1458739160
||yuppdownload.com^
! Commonly set as a proxy on hacked devices (https://www.virustotal.com/gui/url/e610e7d09c614529cb8c64185717769946f5c86044ac5c31c6608e604995f577/detection)
34.80.59.191
! Various domains on https://securitytrails.com/list/ip/72.14.178.174
! Various domains on https://securitytrails•com/list/ip/72•14•178•174
|http://www6.$denyallow=often-used-in-malware-redirections.*
||megabooru.com^
@@ -25216,7 +25217,7 @@
96.126.123.244
173.255.194.134
198.58.118.167
! https://hutudole.com/za-mu-%c9%93ullo-da-matakan-da-za-su-hana-al%c6%99alai-kwa%c9%97ayin-cin-hanci-ba-tinubu/
! https://hutudole•com/za-mu-%c9%93ullo-da-matakan-da-za-su-hana-al%c6%99alai-kwa%c9%97ayin-cin-hanci-ba-tinubu/
||123chance.net^
||123links4u.net^
||123prizes.net^
@@ -25599,7 +25600,7 @@
94.237.93.242
94.237.99.118
139.45.197.249
! https://dnpedia.com/tlds/topm.php bizarrely listing "anahitagirted.uno" as the 622th most visited domain worldwide
! https://dnpedia•com/tlds/topm•php bizarrely listing "anahitagirted•uno" as the 622th most visited domain worldwide
||acorusinfield.life^
||acridlydebit.live^
||aeneasclosure.website^
@@ -26273,8 +26274,8 @@
! ——— Anti-'Malware comments' (Currently Disqus-specific) ———
! https://myip.ms/info/limitexcess
! https://myip.ms/info/memberarea/My_Account.html
! https://myip•ms/info/limitexcess
! https://myip•ms/info/memberarea/My_Account•html
! ——— Dummy entry used to give myself credit, for when this list is used in large compilation hosts-type files (Although they are fully allowed by my licence to use this list, it'd be nice for me and end-users to see where it's being used, as a few of them do not credit their sources) ———
@@ -26285,14 +26286,14 @@
! This section covers ones that would not normally be found in EasyList or AdGuard Base, for instance McAfee WebAdvisor (which also tries to change the search engine)
||webadvisorc.rest.gti.mcafee.com^
||mip.api.mcafeewebadvisor.com^
! https://get.adobe.com/no/reader/
! https://get•adobe•com/no/reader/
! Gigabyte APP Center (which use sneaky tricks to install a Norton 360 trial period; May require «AdGuard for Windows»)
! ——— Carried over from "Anti-'Asset Flip Shovelware' List" in response to Microsoft Store's non-existent quality control ———
! All legitimate Pac-Man games would use "pac-man" links with a dash
! https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
! https://eclypsium•com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
|http://mb.download.gigabyte.com/FileList/Swhttp/LiveUpdate4^
! (Presumably anonymous) E-mail tips
@@ -1,8 +1,9 @@
# Title: 💊 Dandelion Sprout's Anti-Malware List (Domains list version)
# Version: 20August2024v1
# Version: 17September2024v1
# Expires: 2 days
# Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
# Note: The very limited syntax available to raw domains lists, considering it's, well, raw, means that outright anti-MV3 measures (which'd as of February 2024 only affect Minus, a project whose name is unworthy of the uBO label; AdGuard browser extensions has no relevant support for raw domains either way) cannot be done. However, at some 20,000 entries, Team Chromium's shameful leaders aren't liking this list anyway.
# (N
# ——— Bad top-level domains ———
# You can expect these domains to have an overwhelming majority of malware domains that have nothing to do with the countries in question. Nevertheless, if you are in a situation where you have to do active business in any of the countries in question, then this list may not be ideal for you.
@@ -152,6 +153,15 @@ google-analytics.com
# ¤¤¤ Restoro ¤¤¤
# ¤¤¤ "Driver" download sites that instead download PUP tools ¤¤¤
driver-soft.com
@@ -329,14 +339,14 @@ zeroredirect5.com
3.226.8.132
3.216.243.46
roamingclicks.com
# Source: desidert.no
# Source: desidert•no
collectfasttracks.com
# Source: vn-zoom.com
# Source: vn-zoom•com
ttnrd.com
54.152.245.247
35.172.40.232
3.90.125.85
# Various ex-affiliate links at www.zombooru.com
# Various ex-affiliate links at www•zombooru•com
track.vcdc.com
track.tkbo.com
track.traffic.club
@@ -350,6 +360,9 @@ splitter.microxml.net
144.76.0.242
144.76.1.130
195.201.92.254
forgoprokick.icu
inbluson.com
@@ -22394,7 +22407,7 @@ money87.com
netpay8.com
slimxketo.com
works35.com
# Various ex-affiliate links at www.zombooru.com
# Various ex-affiliate links at www•zombooru•com
allowandgo.com
aksuu.ru
allow-space.com
@@ -2,6 +2,7 @@
# Expires: 2 days
# Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
!#if !env_mv3
# (N
# ——— Bad top-level domains ———
# You can expect these domains to have an overwhelming majority of malware domains that have nothing to do with the countries in question. Nevertheless, if you are in a situation where you have to do active business in any of the countries in question, then this list may not be ideal for you.
@@ -143,6 +144,15 @@
# ¤¤¤ Restoro ¤¤¤
# ¤¤¤ "Driver" download sites that instead download PUP tools ¤¤¤
127.0.0.1 driver-soft.com
@@ -320,14 +330,14 @@
127.0.0.1 3.226.8.132
127.0.0.1 3.216.243.46
127.0.0.1 roamingclicks.com
# Source: desidert.no
# Source: desidert•no
127.0.0.1 collectfasttracks.com
# Source: vn-zoom.com
# Source: vn-zoom•com
127.0.0.1 ttnrd.com www.ttnrd.com amanda.ttnrd.com katie.ttnrd.com briana.ttnrd.com sarah.ttnrd.com pamela.ttnrd.com
127.0.0.1 54.152.245.247
127.0.0.1 35.172.40.232
127.0.0.1 3.90.125.85
# Various ex-affiliate links at www.zombooru.com
# Various ex-affiliate links at www•zombooru•com
127.0.0.1 track.vcdc.com
127.0.0.1 track.tkbo.com
127.0.0.1 track.traffic.club
@@ -341,6 +351,9 @@
127.0.0.1 144.76.0.242
127.0.0.1 144.76.1.130
127.0.0.1 195.201.92.254
127.0.0.1 forgoprokick.icu
127.0.0.1 inbluson.com
@@ -22385,7 +22398,7 @@
127.0.0.1 netpay8.com
127.0.0.1 slimxketo.com
127.0.0.1 works35.com
# Various ex-affiliate links at www.zombooru.com
# Various ex-affiliate links at www•zombooru•com
127.0.0.1 allowandgo.com
127.0.0.1 aksuu.ru
127.0.0.1 allow-space.com
@@ -1,8 +1,9 @@
{+block}
# Title: 💊 Dandelion Sprout's Anti-Malware List (for Privoxy)
# Version: 20August2024v1-Deprecated
# Version: 17September2024v1-Deprecated
# Expires: 2 days
# Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
# (Note to self, only applicable to uBO: When 1.59.1 goes stable, implement "*
{+block}
# ——— Bad top-level domains ———
@@ -321,9 +322,9 @@
.3.226.8.132
.3.216.243.46
.roamingclicks.com
# Source: desidert.no
# Source: desidert•no
.collectfasttracks.com
# Source: vn-zoom.com
# Source: vn-zoom•com
.ttnrd.com
.amanda.*.com
.katie.*.com
@@ -333,7 +334,7 @@
.54.152.245.247
.35.172.40.232
.3.90.125.85
# Various ex-affiliate links at www.zombooru.com
# Various ex-affiliate links at www•zombooru•com
.track.vcdc.com
.track.tkbo.com
.track.traffic.club
@@ -441,8 +442,8 @@
.zeikvvbobop.com
.216.21.13.14
.216.21.13.15
/\.(xyz|pics)/[a-zA-Z0-9]{130,}/
/\.(cloudfront\.net|xyz|pics)/[a-zA-Z0-9]{20,}/[a-zA-Z0-9]{25,}\+[a-zA-Z0-9+]{90,}
/.*\.(xyz|pics)/[a-zA-Z0-9]{130,}
/.*\.(cloudfront\.net|xyz|pics)/[a-zA-Z0-9]{20,}/[a-zA-Z0-9]{25,}\+[a-zA-Z0-9+]{90,}
.abaphosis.guru
.abietichob.live
.abyssusuntouch.guru
@@ -10784,7 +10785,7 @@
.showjoinnip.live
.usedhutsold.live
.57.128.71.215
/&[a-z]{1,2}=[a-zA-Z0-9]{0,}%[a-zA-Z0-9%]{1000,}
/.*&[a-z]{1,2}=[a-zA-Z0-9]{0,}%[a-zA-Z0-9%]{1000,}
.truanet.com
.rumadel.com
#
@@ -22358,7 +22359,7 @@
.netpay8.com
.slimxketo.com
.works35.com
# Various ex-affiliate links at www.zombooru.com
# Various ex-affiliate links at www•zombooru•com
.allowandgo.com
.aksuu.ru
.allow-space.com
@@ -1,9 +1,10 @@
msFilterList
# Title: 💊 Dandelion Sprout's Anti-Malware List (Internet Explorer TPL)
# Version: 20August2024v1-Deprecated
# Version: 17September2024v1-Deprecated
: expires = 2 days
# Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
# For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists
# (Note to self, only applicable to uBO: When 1.59.1 goes stable, implement "*
# Homepage: https://github.com/DandelionSprout/adfilt/blob/master/Wiki/General-info.md#-english
# ——— Bad top-level domains ———
@@ -97,6 +98,7 @@ msFilterList
+d pegelinux.top
+d awavenue.top
+d reyhub.top
+d iboxs.top
# International topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent.
!!!||agency$doc,domain=
@@ -111,7 +113,7 @@ msFilterList
!!!||ooo
# (https://github.com/DandelionSprout/adfilt/issues/999)
!!!@@://oo*.ooo/
# https://bgp.he.net/AS202492#_prefixes/(17/07/2022)
# https://bgp.he•net/AS202492#_prefixes/(17/07/2022)
!!!||monster$doc,domain=
+d egybest.monster
+d yts.monster
@@ -214,13 +216,13 @@ msFilterList
# ——— Links to PC "optimising" "tool" PUPs that'll most likely stuff your PC full of nagware and malware ———
# ¤¤¤ ReImagePlus (Also added to "uBlock Filters - Badware Risks") ¤¤¤
# https://windowsreport.com/extend-windows-laptop-battery-life/
# https://appuals.com/fix-error-0x800701e3-on-windows-7-8-1-10/
# https://ugetfix.com/ask/how-to-fix-windows-store-error-0x8000ffff/
# https://www.thewindowsclub.com/fix-windows-update-error-0xc1900130-on-windows-10
# https://www.majorgeeks.com/files/details/patch_my_pc.html
# https://windowsreport•com/extend-windows-laptop-battery-life/
# https://appuals•com/fix-error-0x800701e3-on-windows-7-8-1-10/
# https://ugetfix•com/ask/how-to-fix-windows-store-error-0x8000ffff/
# https://www•thewindowsclub•com/fix-windows-update-error-0xc1900130-on-windows-10
# https://www•majorgeeks•com/files/details/patch_my_pc•html
-d majorgeeks.com images icons red_icon_18x17px.png
# https://www.2-spyware.com/remove-redirector-gvt1-com.html
# https://www•2-spyware•com/remove-redirector-gvt1-com•html
@@ -234,25 +236,25 @@ msFilterList
# ¤¤¤ ScanUtilities ¤¤¤
# https://www.bynarycodes.com/fix-windows-10-update-error-0x80070006/
# https://www•bynarycodes•com/fix-windows-10-update-error-0x80070006/
# ¤¤¤ Driver Easy ¤¤¤
# https://www.drivereasy.com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/
# https://www.drivereasy.com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/
# https://www.drivereasy.com/knowledge/download-gigabyte-audio-driver/
# https://www.drivereasy.com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/
# https://www.drivereasy.com/knowledge/solved-this-display-does-not-support-hdcp/
# https://www•drivereasy•com/knowledge/fix-critical-service-failed-blue-screen-error-on-windows-10/
# https://www•drivereasy•com/knowledge/fixed-how-to-fix-stop-error-0x0000001e/
# https://www•drivereasy•com/knowledge/download-gigabyte-audio-driver/
# https://www•drivereasy•com/knowledge/epson-xp-420-driver-update-for-windows-7-8-and-10/
# https://www•drivereasy•com/knowledge/solved-this-display-does-not-support-hdcp/
# ¤¤¤ Slimware DriverUpdate ¤¤¤
# https://forums.windowscentral.com/
# https://forums•windowscentral•com/
# ¤¤¤ Driverpack Online (Accidentally also fixed in EasyPrivacy and «AdGuard Mobile Ads») ¤¤¤
-d google-analytics.com
# ¤¤¤ SpyHunter links ¤¤¤
# https://howtoremove.guide/redirector-gvt1-com-virus-malware-chrome-removal/
# https://www.2-spyware.com/remove-redirector-gvt1-com.html
# https://howtoremove•guide/redirector-gvt1-com-virus-malware-chrome-removal/
# https://www•2-spyware•com/remove-redirector-gvt1-com•html
# https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-968070041
# https://www.cyclonis.com/how-to-create-gmail-account-without-phone-number/
# https://www.2-viruses.com/remove-ad-spam-press-allow-to-continue
# https://www•cyclonis•com/how-to-create-gmail-account-without-phone-number/
# https://www•2-viruses•com/remove-ad-spam-press-allow-to-continue
-d 2-viruses.com downloads spyhunter2
# https://github.com/iam-py-test/my_filters_001/issues/119
@@ -264,11 +266,11 @@ msFilterList
-d sensorstechforum.com wp-content uploads 2020 04 SpyHunter-Install-And-Free-Scan-
-d youtube.com embed KbGF_fvsRU4
# ¤¤¤ Restoro ¤¤¤
# https://www.windowsdispatch.com/fix-system-restore-0x81000203-error-code/
# https://dlldownloads.com/xlive-dll/
# https://windowsreport.com/find-remove-duplicate-files-windows-10/
# https://windowsreport.com/how-to-update-roblox/ (08/12 2022)
# https://appuals.com/pr-connect-reset-error/
# https://www•windowsdispatch•com/fix-system-restore-0x81000203-error-code/
# https://dlldownloads•com/xlive-dll/
# https://windowsreport•com/find-remove-duplicate-files-windows-10/
# https://windowsreport•com/how-to-update-roblox/ (08/12 2022)
# https://appuals•com/pr-connect-reset-error/
# ¤¤¤ "Driver" download sites that instead download PUP tools ¤¤¤
-d driver-soft.com
# ¤¤¤ Outbyte ¤¤¤
@@ -286,7 +288,7 @@ msFilterList
# https://github.com/AdguardTeam/AdguardFilters/issues/58737
# https://github•com/AdguardTeam/AdguardFilters/issues/58737
# ——— Banner for "MSN New Tab" ———
@@ -423,7 +425,7 @@ msFilterList
-d githubuser.com
-d rgithub.com
-d githubt.com
# https://scammer.info/t/discord-nitro-scam-25/87887
# https://scammer•info/t/discord-nitro-scam-25/87887
-d discorde-nitre.xyz
# ——— Frequently used to infiltrate and maliciously redirect sites, e.g. ToonBarn ———
@@ -457,9 +459,9 @@ msFilterList
-d 3.226.8.132
-d 3.216.243.46
-d roamingclicks.com
# Source: desidert.no
# Source: desidert•no
-d collectfasttracks.com
# Source: vn-zoom.com
# Source: vn-zoom•com
-d ttnrd.com
@@ -469,7 +471,7 @@ msFilterList
-d 54.152.245.247
-d 35.172.40.232
-d 3.90.125.85
# Various ex-affiliate links at www.zombooru.com
# Various ex-affiliate links at www•zombooru•com
-d track.vcdc.com
-d track.tkbo.com
-d track.traffic.club
@@ -3644,7 +3646,7 @@ msFilterList
-d zonedummy.com
# https://twitter.com/SUNgoddessOKAMI/status/1221295265195405315
# https://twitter•com/SUNgoddessOKAMI/status/1221295265195405315
-d deviuser.com
# https://github.com/AdguardTeam/AdguardFilters/issues/61838
- scan-update-and-protect-your-browser.html
@@ -3702,7 +3704,7 @@ msFilterList
-d hooligapps.com
-d best202*-games-web1.com
-d theonlygames.com
# https://maldita.es/malditobulo/2020/12/04/concurso-mercadona-ganar-tarjeta-regalo-100-euros-phishing/
# https://maldita•es/malditobulo/2020/12/04/concurso-mercadona-ganar-tarjeta-regalo-100-euros-phishing/
-d notified-today.com
-d antivirus-update.com
-d new-message.cc
@@ -3714,12 +3716,12 @@ msFilterList
-d stay-notified.com
-d stay-notified.xyz
-d 167.99.249.47
# https://maldita.es/malditobulo/2020/12/02/lidl-regala-robot-cocina-silvercrest-monsieur-cuisine-encuesta/
# https://maldita.es/malditobulo/2020/11/25/jordi-evole-el-hormiguero-bitcoin-revolution-timo-twitter/
# https://maldita•es/malditobulo/2020/12/02/lidl-regala-robot-cocina-silvercrest-monsieur-cuisine-encuesta/
# https://maldita•es/malditobulo/2020/11/25/jordi-evole-el-hormiguero-bitcoin-revolution-timo-twitter/
-d moderncomputer.net
# https://maldita.es/malditobulo/2020/11/18/gobierno-tarjeta-debito-prepagada-covid-19-phishing-whatsapp/
# https://maldita•es/malditobulo/2020/11/18/gobierno-tarjeta-debito-prepagada-covid-19-phishing-whatsapp/
-d version.gratis
# https://maldita.es/malditobulo/2020/11/18/no-no-es-cierto-que-amancio-ortega-haya-invertido-100-millones-en-bitcoin-revolution-es-una-web-falsa/
# https://maldita•es/malditobulo/2020/11/18/no-no-es-cierto-que-amancio-ortega-haya-invertido-100-millones-en-bitcoin-revolution-es-una-web-falsa/
-d starpowders.github.io
# https://github.com/AdguardTeam/AdguardFilters/issues/69611
@@ -3784,7 +3786,7 @@ msFilterList
-d 108.170.52.156
# https://github.com/DandelionSprout/adfilt/issues/198
-d mysecrethoookup.com
# https://www.bleepingcomputer.com/virus-removal/ (18/06 2021)
# https://www•bleepingcomputer•com/virus-removal/ (18/06 2021)
-d toksearches.xyz
-d smashapps.net
-d smashappsearch.com
@@ -3796,7 +3798,7 @@ msFilterList
-d searchinggood.com
-d searchprivacyplus.com
-d powersmashsearch.com
# https://www.bleepingcomputer.com/virus-removal/remove-please-allow-to-watch-the-video
# https://www•bleepingcomputer•com/virus-removal/remove-please-allow-to-watch-the-video
-d 1000-dollar.cash
-d 1000-eur.cash
-d bokerstars.com
@@ -3890,9 +3892,9 @@ msFilterList
-d 95.168.170.165
-d 213.227.145.147
-d 213.227.149.216
# https://twitter.com/adamziaja/status/1252234957679808513
# https://twitter•com/adamziaja/status/1252234957679808513
-d wow-robotics.xyz
# https://blog.sucuri.net/2021/05/woocommerce-credit-card-skimmer.html
# https://blog•sucuri•net/2021/05/woocommerce-credit-card-skimmer•html
-d deepe.icu
-d google-analytics.buzz
-d intr0.cyou
@@ -3940,7 +3942,7 @@ msFilterList
-d ssielearning.com
-d paymetconfirm.com
-d 69.49.231.244
# https://movsb.0x0.st/users/mia
# https://movsb•0x0•st/users/mia
-d vid.me
-d 5starhdporn.com
# https://github.com/DandelionSprout/adfilt/issues/228
@@ -4010,22 +4012,22 @@ msFilterList
-d pc-my-protection.xyz
-d beta-news.org
# https://github.com/DandelionSprout/adfilt/pull/266
# https://www.virustotal.com/gui/domain/kirstialechulbard.space/relations
# https://www.virustotal.com/gui/ip-address/198.54.117.244/relations
# https://www•virustotal•com/gui/domain/kirstialechulbard•space/relations
# https://www•virustotal•com/gui/ip-address/198•54•117•244/relations
-d dashwoodestates.com
# http://vxvault.net/ViriFiche.php?ID=44013
# https://www.virustotal.com/gui/url/8066b87ad10ddb5466bc307bb48454139572f6c8c8f80a9734275ac89cf966af/detection
# https://www.virustotal.com/gui/url/826c451929420c4da32552f967fb1cab6467405a29c65b23802aaadb6a8c7505/detection
# https://safeweb.norton.com/report/show?url=192.3.110.170
# http://vxvault•net/ViriFiche•php?ID=44013
# https://www•virustotal•com/gui/url/8066b87ad10ddb5466bc307bb48454139572f6c8c8f80a9734275ac89cf966af/detection
# https://www•virustotal•com/gui/url/826c451929420c4da32552f967fb1cab6467405a29c65b23802aaadb6a8c7505/detection
# https://safeweb•norton•com/report/show?url=192•3•110•170
-d 192.3.110.170
# https://forums.malwarebytes.com/topic/278209-removal-instructions-for-socialsearchconverter/
# https://forums•malwarebytes•com/topic/278209-removal-instructions-for-socialsearchconverter/
-d socialsearchconverter.com
-d install.socialsearchconverter.com
-d feed.socialsearchconverter.com
-d api.socialsearchconverter.com
-d notify-service.com
-d install.stream-all.com
# copied over from https://github.com/uBlockOrigin/uAssets/issues/9848
# Copied over from https://github.com/uBlockOrigin/uAssets/issues/9848
-d gghacks.com
-d rewardsgiantusa.com
-d promotionsonlineusa.com
@@ -4037,10 +4039,10 @@ msFilterList
-d mediafiire.com
-d d1xkyo9j4r7vnn.cloudfront.net
-d onlinepromotionsusa.com
# https://securelist.com/apkpure-android-app-store-infected/101845/
# https://www.virustotal.com/gui/url/866a25343864f03dc5a10105fda523bfbb6ed09c486d07fd31ca2b5306440089/detection
# https://securelist•com/apkpure-android-app-store-infected/101845/
# https://www•virustotal•com/gui/url/866a25343864f03dc5a10105fda523bfbb6ed09c486d07fd31ca2b5306440089/detection
-d wcf.seven1029.com
# https://www.virustotal.com/gui/url/9c66e331e455dc5c5c9d06e1a537580c9e4db279182d2285c07783e837806a16/detection
# https://www•virustotal•com/gui/url/9c66e331e455dc5c5c9d06e1a537580c9e4db279182d2285c07783e837806a16/detection
-d foodin.site
# https://github.com/AdguardTeam/AdguardFilters/issues/91506#issuecomment-904080849
-d totalav.com
@@ -4052,22 +4054,22 @@ msFilterList
-d totaladblock.com
-d totaladblocker.xyz
-d totalwebshield.xyz
# https://www.virustotal.com/gui/file/c683bc3da4966110b419ac54d09a54ce798efdb51be398331d9ce011e2636fa9/community
# https://www.virustotal.com/gui/url/5618023ed5a768d7f879c0d599b9ba7cff0e9171201981256eeaf5ce8eb09fdb/detection
# https://www.virustotal.com/gui/url/8cf9ca3359f17cf92b9b3e5fdab30e29be23f08e66c8c5396c9410fcb91f7c3c/detection
# https://www•virustotal•com/gui/file/c683bc3da4966110b419ac54d09a54ce798efdb51be398331d9ce011e2636fa9/community
# https://www•virustotal•com/gui/url/5618023ed5a768d7f879c0d599b9ba7cff0e9171201981256eeaf5ce8eb09fdb/detection
# https://www•virustotal•com/gui/url/8cf9ca3359f17cf92b9b3e5fdab30e29be23f08e66c8c5396c9410fcb91f7c3c/detection
-d 91.241.19.38
# https://www.virustotal.com/gui/url/46e095c35d83e2dd0b98df4b5844d3d87948de0c930a618600121020a514c801/detection
# https://safeweb.norton.com/report/show?url=telete.in
# https://www.siteadvisor.com/sitereport.html?url=telete.in
# https://www•virustotal•com/gui/url/46e095c35d83e2dd0b98df4b5844d3d87948de0c930a618600121020a514c801/detection
# https://safeweb•norton•com/report/show?url=telete•in
# https://www•siteadvisor•com/sitereport•html?url=telete•in
-d telete.in
# https://www.virustotal.com/gui/file/e63b2d03e3fee2d538f8bd721b61dd3641284fa941087d846dea6f15cab40308/community
# https://www.virustotal.com/gui/url/fbbc8a671bff32539bd829a76f6df9f364a21ac2279922e64e3ec494a1669dd3/detection
# https://www•virustotal•com/gui/file/e63b2d03e3fee2d538f8bd721b61dd3641284fa941087d846dea6f15cab40308/community
# https://www•virustotal•com/gui/url/fbbc8a671bff32539bd829a76f6df9f364a21ac2279922e64e3ec494a1669dd3/detection
-d kiff.tech
# https://www.virustotal.com/gui/domain/kiff.tech/relations
# https://www.virustotal.com/gui/url/dc038496b1b5358b97f89440135ec91258b406c40859a2cd95983dc7a81e0cfa/detection
# https://www•virustotal•com/gui/domain/kiff•tech/relations
# https://www•virustotal•com/gui/url/dc038496b1b5358b97f89440135ec91258b406c40859a2cd95983dc7a81e0cfa/detection
-d 45.90.58.90
# https://www.virustotal.com/gui/file/e565ba89d034418fd26a5f642f6eeee4d72ee3b8dc69523419b7ca8dfd452730/community
# https://www.virustotal.com/gui/url/e3a9189a1e1256beba8e0fc3abfeab6acb09f7f8cabfd973e22be9f77bb6886f/detection
# https://www•virustotal•com/gui/file/e565ba89d034418fd26a5f642f6eeee4d72ee3b8dc69523419b7ca8dfd452730/community
# https://www•virustotal•com/gui/url/e3a9189a1e1256beba8e0fc3abfeab6acb09f7f8cabfd973e22be9f77bb6886f/detection
-d 95.85.89.98
# https://github.com/DandelionSprout/adfilt/issues/267
-d tekhacks.net
@@ -4084,7 +4086,7 @@ msFilterList
# https://www.virustotal.com/gui/file/9f154115fa8045aa05f15f7cd1de9623ebe32e8ea400279ecb5dfa3596952e3b/community
-d 103.169.90.205
# https://github.com/DandelionSprout/adfilt/pull/281
# https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
# https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
-d 125.44.43.45
-d 182.121.8.240
-d 42.235.183.74
@@ -4095,9 +4097,9 @@ msFilterList
-d 188.120.50.98
-d 190.238.183.5
-d 27.220.253.78
# https://www.virustotal.com/gui/file/0374ead74fa807fb1737d8829fdb5bad6c93779f6b9eb7162eddabff7a64acff/community
# https://www•virustotal•com/gui/file/0374ead74fa807fb1737d8829fdb5bad6c93779f6b9eb7162eddabff7a64acff/community
-d esetnode32-antiviru.ydns.eu
# https://www.joesandbox.com/analysis/486636/0/html#domains
# https://www•joesandbox•com/analysis/486636/0/html#domains
-d aieov.com
# Relations to the original domain
-d 192.3.194.242
@@ -4171,17 +4173,17 @@ msFilterList
-d army-glo.scrollingsystem.com
-d mcafee12.tt.omtrdc.net
-d trolleydrop.info
# https://www.virustotal.com/gui/ip-address/70.32.1.32/relations
# https://www•virustotal•com/gui/ip-address/70•32•1•32/relations
-d cd.org
# https://www.virustotal.com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community
# https://www•virustotal•com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community
# https://github.com/DandelionSprout/adfilt/commit/f7f114945c83b339be5cdd848e229680d9918abb#commitcomment-57642875
-d 23.94.26.138
# https://github.com/DandelionSprout/adfilt/pull/298
# https://www.virustotal.com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community
# https://www•virustotal•com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community
-d 205.185.126.200
# https://www.virustotal.com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community
# https://www•virustotal•com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community
-d 185.243.56.167
# https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
# https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
-d 123.10.224.135
-d 59.47.187.147
-d 39.68.172.210
@@ -4229,23 +4231,23 @@ msFilterList
-d 111.224.199.91
-d 119.250.236.122
-d 112.30.110.58
# https://www.virustotal.com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community
# https://www•virustotal•com/gui/file/715eef1fb3bbf84ade848d97d4ec05d380cf8595298b51af134385de70be9d08/community
-d pcae.de
# https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
# https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
-d 117.196.49.21
-d 115.55.54.234
-d 115.52.17.123
-d 182.59.69.21
# https://www.virustotal.com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community
# https://www•virustotal•com/gui/file/3db0e385eb53a32d61a5a35908a99317868b571e4cf7079db67fd68604da662c/community
-d chip-secured-download.de
# https://www.virustotal.com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb
# https://www•virustotal•com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb
# Domains which resolve to this (already blocked) IP - for users of HOSTs Domains uBlock Origin
-d nctylivpwhpby.com
-d phhitgjxsit.com
# https://www.virustotal.com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1
# https://www•virustotal•com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1
-d saimission.org
# https://www.virustotal.com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1
# https://www.virustotal.com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations
# https://www•virustotal•com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1
# https://www•virustotal•com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations
-d driversupport.com
# A PUP and scam website
-d mycleanpc.com
@@ -4256,9 +4258,9 @@ msFilterList
# The main website for the MyCleanPC company
-d realdefen.se
# Vermilion Strike
# https://www.virustotal.com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations
# https://www•virustotal•com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations
-d 160.202.163.100
# https://www.virustotal.com/gui/ip-address/160.202.163.100/relations
# https://www•virustotal•com/gui/ip-address/160•202•163•100/relations
-d microsoftkernel.com
-d microsofthk.com
# https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-938167311
@@ -4269,11 +4271,11 @@ msFilterList
# https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-944612753
-d pushbizapi.com
# https://github.com/DandelionSprout/adfilt/pull/303
# https://www.virustotal.com/gui/file/37328efa73c248b460aba605d7745b024f31ab7ab864e1af273e9a197a188f42/community
# https://www•virustotal•com/gui/file/37328efa73c248b460aba605d7745b024f31ab7ab864e1af273e9a197a188f42/community
-d 45.95.169.115
# https://www.virustotal.com/gui/file/03e4533ba8874c2f4dcdb94bd135914fa4c22ed477d7c0395dc2322b6468e249/community
# https://www•virustotal•com/gui/file/03e4533ba8874c2f4dcdb94bd135914fa4c22ed477d7c0395dc2322b6468e249/community
-d 45.148.120.80
# https://www.virustotal.com/gui/file/1a782cab036efa567c2c42b7bae9452bf735be72f0b00d68f6dcba48cea526fa/community
# https://www•virustotal•com/gui/file/1a782cab036efa567c2c42b7bae9452bf735be72f0b00d68f6dcba48cea526fa/community
-d 85.239.33.9
# Relations to the domain above
-d adminsys.serveftp.com
@@ -4290,11 +4292,11 @@ msFilterList
-d c4ase-verified9932.serveftp.com
-d 1log-wellsfargo.serveftp.com
-d eposcardokubo.serveftp.com
# https://www.virustotal.com/gui/file/8a39f18caa77d52e80bec05f584ec50e733a3be1e33551d8902e95b9b0bfe6c0/community
# https://www•virustotal•com/gui/file/8a39f18caa77d52e80bec05f584ec50e733a3be1e33551d8902e95b9b0bfe6c0/community
-d 107.173.176.183
# https://www.virustotal.com/gui/file/54054209c921a68f12a9b29d6e84f1b45cb417bc0b5a99356a245727e0a41e40/community
# https://www•virustotal•com/gui/file/54054209c921a68f12a9b29d6e84f1b45cb417bc0b5a99356a245727e0a41e40/community
-d 45.148.120.171
# https://twitter.com/soranker0/status/1449491402409185283
# https://twitter•com/soranker0/status/1449491402409185283
# https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-950330114
-d free-softs.net
# https://github.com/iam-py-test/investigations/blob/main/2021/10 24 1.md#html-capture
@@ -4320,7 +4322,7 @@ msFilterList
-d kokotrokot.com
!!!?next_url=
# https://www.upwork.com/freelance-jobs/apply/Integarte-push-notification-for-chrome_~013c73ed9282225184/
# https://www•upwork•com/freelance-jobs/apply/Integarte-push-notification-for-chrome_~013c73ed9282225184/
-d mugrikees.com
-d alpha-news.org
# https://github.com/iam-py-test/investigations/blob/main/2021/11 3 1.md
@@ -4329,7 +4331,7 @@ msFilterList
-d youvetube.com
-d youutube.com
# https://github.com/DandelionSprout/adfilt/pull/348
# https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
# https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
-d 39.83.80.247
-d 68.197.33.124
-d 219.157.21.37
@@ -4361,7 +4363,7 @@ msFilterList
-d 106.86.172.194
-d 103.233.216.77
-d 183.188.192.55
# https://www.virustotal.com/gui/file/3bf1b7e9bdaeaa4a5619cf26b59767637bc44193df2a0470df263b98b1fe47fe/community
# https://www•virustotal•com/gui/file/3bf1b7e9bdaeaa4a5619cf26b59767637bc44193df2a0470df263b98b1fe47fe/community
-d 198.23.255.14
# https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-971512075
# https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-971495248
@@ -4372,7 +4374,7 @@ msFilterList
-d runmodes.com
-d 91.121.67.60
-d 172.67.186.189
# https://www.virustotal.com/gui/url/af8f443208f4e86d469549b219fccbeb43b7cae40be5f1b4c4e5083e27fc8111
# https://www•virustotal•com/gui/url/af8f443208f4e86d469549b219fccbeb43b7cae40be5f1b4c4e5083e27fc8111
-d inconclusive-pyrite-grandparent.glitch.me
-d delicate-tame-angora.glitch.me
-d secureinvoice.glitch.me
@@ -4383,9 +4385,9 @@ msFilterList
-d aquamarine-cotton-impala.glitch.me
-d mature-periwinkle-advantage.glitch.me
-d tough-numerous-lemur.glitch.me
# https://scammer.info/t/mcafee-phish/83725
# https://scammer•info/t/mcafee-phish/83725
-d securefirst.us-east-1.linodeobjects.com
# https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
# https://www•virustotal•com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community
-d 39.65.72.211
-d 42.238.151.197
-d 27.213.60.53
@@ -4406,21 +4408,21 @@ msFilterList
-d members.tonightshookup.com
-d t.tonightshookup.com
-d yourladiefun.life
# https://www.virustotal.com/gui/url/a2524bba49ae71297d2b408b30d058700d9c80b5b1154924cafe190ec3e605a6/detection
# https://www•virustotal•com/gui/url/a2524bba49ae71297d2b408b30d058700d9c80b5b1154924cafe190ec3e605a6/detection
-d newrrb.bid
# https://www.virustotal.com/gui/file/2b2628a50d3b39b0fa2395d487bf62b00e37cdae847ff76ee58399bbe4e9f7b3/community
# https://www•virustotal•com/gui/file/2b2628a50d3b39b0fa2395d487bf62b00e37cdae847ff76ee58399bbe4e9f7b3/community
-d 194.87.138.20
# https://www.virustotal.com/gui/file/b320bc7a9151d70daca038c4356ca89bfcd4918bcd6f0f73683a27a6a72467ae/community
# https://www•virustotal•com/gui/file/b320bc7a9151d70daca038c4356ca89bfcd4918bcd6f0f73683a27a6a72467ae/community
-d 103.167.92.73
# https://www.virustotal.com/gui/file/6146dfe56dcb49e1b843624a44e204754e15625a4f94b230b59a5cafc924f618/community
# https://www•virustotal•com/gui/file/6146dfe56dcb49e1b843624a44e204754e15625a4f94b230b59a5cafc924f618/community
-d bursakulis.com
# https://www.virustotal.com/gui/url/b333c49efa4d399e65c5e2d96a905b380acbca58a3e3052b7bd7cfcb3e0e81ee
# https://www•virustotal•com/gui/url/b333c49efa4d399e65c5e2d96a905b380acbca58a3e3052b7bd7cfcb3e0e81ee
-d 610418.selcdn.ru
# https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-977912975
# https://www.tv2.no/nyheter/14368524/
# https://www•tv2•no/nyheter/14368524/
-d alexstewartinternationalltd.rw
-d vps.re
# https://www.tek.no/i/wOVv0o/
# https://www•tek•no/i/wOVv0o/
-d 21steditionnaturalgh.com
# https://github.com/iam-py-test/investigations/blob/main/2021/11 24 1.md
-d macsoftwarez.com
@@ -4436,7 +4438,7 @@ msFilterList
-d yunosurveys.com
# https://github.com/uBlockOrigin/uAssets/pull/10620
-d shadyclient.net
# https://www.virustotal.com/gui/file/d546509ab6670f9ff31783ed72875dfc0f37fa2b666bd5870eecaaed2ebea4a8/community
# https://www•virustotal•com/gui/file/d546509ab6670f9ff31783ed72875dfc0f37fa2b666bd5870eecaaed2ebea4a8/community
-d 58.249.74.79
-d 27.45.14.109
-d 27.40.101.191
@@ -4452,13 +4454,13 @@ msFilterList
-d totalnicefeed.com
# https://github.com/iam-py-test/investigations/blob/main/2021/11 28 2.md
-d bestlifeoffer20.com
# https://scammer.info/t/password-stealer/84348
# https://bazaar.abuse.ch/sample/462a689d171f543c10efa08e963996d382585b67a6b298ec40d64f924adfb47a/
# https://scammer•info/t/password-stealer/84348
# https://bazaar•abuse•ch/sample/462a689d171f543c10efa08e963996d382585b67a6b298ec40d64f924adfb47a/
-d youtube.com watch?v=8nY7SnvNxH4
-d bit.ly 3p8kN5V
-d mediafire.com file at2tvnao5x6ivdo EngineOwning.rar
-d download2264.mediafire.com pnk44f5ci9rg at2tvnao5x6ivdo EngineOwning.rar
# https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
# https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
-d 110.89.59.135
-d 113.116.89.1
-d 119.183.146.191
@@ -4470,32 +4472,32 @@ msFilterList
-d 171.112.177.90
-d 115.194.38.143
-d 61.52.79.32
# https://scammer.info/t/pihishing-site-claiming-to-hold-a-ups-package-that-needs-payment/84466
# https://www.virustotal.com/gui/url/269d374b629d7896da1f9e7449bd5afecf6284a9a564244f96a71e5192363635?nocache=1
# https://scammer•info/t/pihishing-site-claiming-to-hold-a-ups-package-that-needs-payment/84466
# https://www•virustotal•com/gui/url/269d374b629d7896da1f9e7449bd5afecf6284a9a564244f96a71e5192363635?nocache=1
-d lowseelan.com
# https://www.virustotal.com/gui/file/50fd813cf8fe981e6aee179f8ba394e5527c5128b84c328f9f8347cd994bbc42/community
# https://www•virustotal•com/gui/file/50fd813cf8fe981e6aee179f8ba394e5527c5128b84c328f9f8347cd994bbc42/community
-d dl02.s3.amazonaws.com installers 747947 oi_picasa38-setupexe.exe
# https://www.virustotal.com/gui/file/2ea599605c4d65902943f12e1114a71af7a40fa7dffbf018b0ee3e7a61aaeaa3/community
# https://www•virustotal•com/gui/file/2ea599605c4d65902943f12e1114a71af7a40fa7dffbf018b0ee3e7a61aaeaa3/community
-d dl02.s3.amazonaws.com installers 424531 2gzbsoj4gxb.exe
# https://github.com/DandelionSprout/adfilt/pull/395
# https://www.huorong.cn/info/1531309921141.html
# https://www•huorong.cn/info/1531309921141.html
-d kuaizip.com
# https://www.huorong.cn/info/1618397948649.html/-/possible/malware
# https://www•huorong.cn/info/1618397948649.html/-/possible/malware
# ||zhuangjizhuli.com
# ||zhuangjizhuli.net
# https://github.com/uBlockOrigin/uAssets/pull/9656
-d geekotg.com
# https://www.huorong.cn/info/1526627586130.html
# https://www•huorong.cn/info/1526627586130.html
-d xiaobaixitong.com
# https://www.huorong.cn/info/1577158839403.html
# https://www•huorong.cn/info/1577158839403.html
-d daque.cn
# https://www.huorong.cn/info/1598957552515.html
# https://www•huorong.cn/info/1598957552515.html
-d dabaicai.com
# https://www.huorong.cn/info/1617368984641.html
# https://www•huorong.cn/info/1617368984641.html
-d qqfzn.com
# https://github.com/uBlockOrigin/uAssets/pull/10017
-d flash.cn
# https://www.nrk.no/vestfoldogtelemark/1.15750360
# https://www•nrk.no/vestfoldogtelemark/1.15750360
-d dundeehills.group
-d 132.148.220.142
@@ -4509,8 +4511,8 @@ msFilterList
# https://scammer.info/t/fake-facebook-login-page/84939
-d royyer.us R8cWuvQjhtM
# https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-988127908
# https://www.tek.no/i/lVeQAe/
# https://www.nkom.no/aktuelt/ikke-trykk-pa-lenker-i-sms--for-du-er-helt-sikker/
# https://www•tek.no/i/lVeQAe/
# https://www•nkom.no/aktuelt/ikke-trykk-pa-lenker-i-sms--for-du-er-helt-sikker/
-d eccolabgroup.com
-d galerijajava.ba
-d p-stn.net
@@ -4520,7 +4522,7 @@ msFilterList
-d 34.201.22.10
# https://scammer.info/t/crypto-scammers-onceagain/85354
-d business.google.com website billyandscapedesign
# https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
# https://www•virustotal•com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community
-d 123.10.225.196
-d 122.192.106.84
-d 172.88.199.9
@@ -4571,9 +4573,9 @@ msFilterList
-d d13pxqgp3ixdbh.cloudfront.net
# Other
-d crashfixes.com
# https://www.virustotal.com/gui/url/c25fe34c05cc8e9136027a67c277e175a5d6e35af921ee37bad98bdfeea6a2f9/community
# https://www•virustotal•com/gui/url/c25fe34c05cc8e9136027a67c277e175a5d6e35af921ee37bad98bdfeea6a2f9/community
-d splendid-fallacious-anaconda.glitch.me
# https://www.virustotal.com/gui/file/9d40ae0439ddc594b2cf64e21ad0fdea9bb440524298e3a6bcfcc1fb417f1ed2/relations
# https://www•virustotal•com/gui/file/9d40ae0439ddc594b2cf64e21ad0fdea9bb440524298e3a6bcfcc1fb417f1ed2/relations
-d 91.240.118.172
# "Press Allow to continue"
-d kuyhaa-mee.com
@@ -4584,7 +4586,7 @@ msFilterList
-d myget.org feed discord-nitro-hack package nuget Free-discord-nitro-codes-2021
-d lucymods.com
-d gluegames.xyz
# https://twitter.com/iam_py_test/status/1496259425493225472
# https://twitter•com/iam_py_test/status/1496259425493225472
-d sites.google.com view groundworkssolutions contact-us
-d sites.google.com view groundworkssolutions
-d sites.google.com mytv maintenance
@@ -4599,7 +4601,7 @@ msFilterList
-d download2340.mediafire.com eift3ac9qmig y65v1rk0zy7ot4a The__Setup__With__File.zip
# https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1074966240
-d melding.link
# https://twitter.com/MBThreatIntel/status/1509956416311742464
# https://twitter•com/MBThreatIntel/status/1509956416311742464
-d xposednews.xyz
-d tomguide.xyz
-d eronews.xyz
@@ -4620,7 +4622,7 @@ msFilterList
-d freeversioncrack.com
-d top3hostngc.xyz
-d 198.199.120.251
# https://www.telia.no/kundeservice/mobil/malware-flubot-android/
# https://www•telia.no/kundeservice/mobil/malware-flubot-android/
# A Discord conversation I had about Throneful
@@ -4644,7 +4646,7 @@ msFilterList
-d cumpussyy.uno
-d 195.201.253.130
-d 195.201.253.131
# The bottom download button on https://www.sushichop.com/
# The bottom download button on https://www•sushichop•com/
-d installiq.com
-d specgoal.com
-d sandhyapi.online
@@ -4667,7 +4669,7 @@ msFilterList
-d 96.47.230.68
-d 96.47.230.69
-d 96.47.230.70
# https://securitytrails.com/list/ns/ns1.fastthinkingdns.com
# https://securitytrails•com/list/ns/ns1•fastthinkingdns•com
-d highercaptcha-settle.
-d highercaptchasettle.
@@ -4709,7 +4711,7 @@ msFilterList
-d saferedirects.xyz
-d online-guard.com
# https://twitter.com/iam_py_test/status/1545164642346930176
# https://twitter•com/iam_py_test/status/1545164642346930176
-d amazon-security-info.lnk.to
# https://github.com/AdguardTeam/AdguardFilters/issues/123968
# https://github.com/AdguardTeam/AdguardFilters/issues/124620
@@ -5019,7 +5021,7 @@ msFilterList
-d 158.247.212.220
-d 165.227.168.212
# https://www.reddit.com/r/engrish/comments/w6u4uy/received_this_text_message_yesterday_i_am_very/
# https://www•reddit.com/r/engrish/comments/w6u4uy/received_this_text_message_yesterday_i_am_very/
# https://dinside.dagbladet.no/mobil/ikke-la-deg-friste/76730599
-d k-yw.com
@@ -5264,7 +5266,7 @@ msFilterList
-d 51.91.66.125
-d 51.178.76.105
-d 147.135.253.55
# https://github.com/uBlockOrigin/uAssets/issues/14569/→/https://www.virustotal.com/gui/url/b819586938326577d759d8024abe3e0e6de1c853d6b67824daf6f613fba0f63b/detection/(https://app.any.run/tasks/5914a712-1a73-4432-b89a-ca0627a24ade)
# https://github.com/uBlockOrigin/uAssets/issues/14569/→/https://www•virustotal•com/gui/url/b819586938326577d759d8024abe3e0e6de1c853d6b67824daf6f613fba0f63b/detection/(https://app•any•run/tasks/5914a712-1a73-4432-b89a-ca0627a24ade)
-d bnbdeal.net
# https://github.com/AdguardTeam/AdguardFilters/issues/129414
@@ -9284,7 +9286,7 @@ msFilterList
-d zapatillasmcqueen.com
# https://www.bleepingcomputer.com/news/security/hackers-push-malware-via-google-search-ads-for-vlc-7-zip-ccleaner/
# https://www•bleepingcomputer•com/news/security/hackers-push-malware-via-google-search-ads-for-vlc-7-zip-ccleaner/
-d blendepr.org
-d blendevr.org
-d blendesr.org
@@ -9813,7 +9815,7 @@ msFilterList
-d yourticketchance.com
-d yourorderupdate.com
-d 64.132.201.92
# https://www.adressa.no/nyheter/trondheim/i/BWkdkw/trodde-hun-skulle-faa-en-pakke-i-posten-ble-lurt-for-titusener
# https://www•adressa.no/nyheter/trondheim/i/BWkdkw/trodde-hun-skulle-faa-en-pakke-i-posten-ble-lurt-for-titusener
-d acessmygov.online
-d centerlinkmygov.com
-d centierssl.us
@@ -10536,7 +10538,7 @@ msFilterList
-d 3.231.137.120
-d 54.204.83.105
# https://github.com/DandelionSprout/adfilt/issues/808
# https://www.mandiant.com/resources/blog/tracking-evolution-gootloader-operations/(26/01/2023)
# https://www•mandiant.com/resources/blog/tracking-evolution-gootloader-operations/(26/01/2023)
-d jonathanbartz.com
-d jp.imonitorsoft.com
-d junk-bros.com
@@ -10770,7 +10772,7 @@ msFilterList
-d wuruclas.co.in
-d zondeucearixes.com
-d 85.17.80.16
# https://www.adressa.no/nyheter/trondheim/i/Moq2wR/svindlere-kaarer-vinnere-i-konkurranser-gir-en-daarlig-foelelse-aa-forklare-at-dette-bare-er-tull
# https://www•adressa.no/nyheter/trondheim/i/Moq2wR/svindlere-kaarer-vinnere-i-konkurranser-gir-en-daarlig-foelelse-aa-forklare-at-dette-bare-er-tull
-d sitey.me
# https://github.com/AdguardTeam/AdguardFilters/issues/151479
-d agazpeppily.live
@@ -16891,7 +16893,7 @@ msFilterList
+d dev
+d archive.*
-d github.sale
# https://www.tv2.no/nyheter/innenriks/advarer-ikke-klikk-pa-lenken/16040614/
# https://www•tv2.no/nyheter/innenriks/advarer-ikke-klikk-pa-lenken/16040614/
-d 0nedr1ved0cumentonline.com
-d 88godetailsvc.com
-d amexmobileupdate.cc
@@ -22772,9 +22774,9 @@ vito.www.booking.
# ——— Standard malware that I stumbled upon on my own ———
# http://www.toorgle.net/results.php?q=fetishkitsch&security=666
# http://www•toorgle•net/results•php?q=fetishkitsch&security=666
-d downloadprovider.me
# https://www.riverbender.com/articles/details/two-charged-in-connection-of-the-stallon-drug-raid-in-wood-river-46877.cfm
# https://www•riverbender•com/articles/details/two-charged-in-connection-of-the-stallon-drug-raid-in-wood-river-46877•cfm
-d cash93.com
-d a4alig.com
-d cash03.com
@@ -22787,7 +22789,7 @@ vito.www.booking.
-d netpay8.com
-d slimxketo.com
-d works35.com
# Various ex-affiliate links at www.zombooru.com
# Various ex-affiliate links at www•zombooru•com
-d allowandgo.com
-d aksuu.ru
-d allow-space.com
@@ -22801,7 +22803,7 @@ vito.www.booking.
-d push.weo.su
-d traffsend.me
-d wwopenclick.club
# Spam comments at https://www.accountkiller.com/en/delete-htcdev-account
# Spam comments at https://www•accountkiller•com/en/delete-htcdev-account
-d azhydroxychloroquine.com
-d wisig.org
-d confrancisyalgomas.com
@@ -22813,12 +22815,12 @@ vito.www.booking.
-d amoxycillin1st.com
# The Jerma985 Discord server
-d crazycrabreedville.com
# https://flclever.weebly.com/pixie-hollow-mini-games.html/(06/05/2021)
# https://flclever.weebly•com/pixie-hollow-mini-games•html/(06/05/2021)
-d messium.info
# Various Google searches
# Various search results for 'kelloggs tresor' in Norwegian (30 05 2021)
- pgxhtogrzm-
# https://fx-onlinee.blogspot.com/2021/06/?r=Bergens-Tidende-Flertallet-av-fastlegene-i-Trondheim-sier-nei-til-Janssen-vaksinen-Umulig-%C3%A5-ta-det-ansvaret-seo+aj
# https://fx-onlinee•blogspot•com/2021/06/?r=Bergens-Tidende-Flertallet-av-fastlegene-i-Trondheim-sier-nei-til-Janssen-vaksinen-Umulig-%C3%A5-ta-det-ansvaret-seo+aj
-d blogspot.com * ?r=*-seo+aj
# Fake security sites that think every single domain is a supervirus and which try to make you install PUP (Most commonly SpyHunter)
-d malwarecleanerpro.com
@@ -25040,8 +25042,8 @@ dvancedhosters.com$doc,domain=
-d sidenoteconcern.com
-d abnegationbanquet.com
-d 192.243.61.225
# https://twitter.com/medicinehelp/status/1550250932394409985
# https://securitytrails.com/list/ip/147.135.16.27
# https://twitter•com/medicinehelp/status/1550250932394409985
# https://securitytrails•com/list/ip/147•135•16•27
-d 2spendless.
-d acrx.online
-d acrx.org
@@ -25097,10 +25099,10 @@ dvancedhosters.com$doc,domain=
-d medicinecoupons.xyz
-d medicinehelp.news
-d 147.135.16.27
# https://www.google.no/search?q=mlp+g5&newwindow=1&tbm=isch&oq=mlp+g5&sclient=img
# https://www•google.no/search?q=mlp+g5&newwindow=1&tbm=isch&oq=mlp+g5&sclient=img
-d ingeniovirtual.com
# Spambot posts on Tumblr (19 09 2022)
# https://scambiofigu.forumcommunity.net/?t=57482915
# https://scambiofigu.forumcommunity•net/?t=57482915
-d scambiofigu.net
# Only links to another site's (APKPure) APKs, yet tries to promote its own browser extension on the alleged download pages, which comes across as suspicious
# Google results for 'Katy and Bob: Cake Café powerpc' (04 11 2022)
@@ -25246,15 +25248,15 @@ dvancedhosters.com$doc,domain=
# https://app.any.run/tasks/679e9afa-eb19-4414-a086-e280a779a448/and/https://tria.ge/230217-xd8nksgc9x/behavioral2
-d ru-torproject.ru
-d anapatformacion.org modules file tor tor-browser.zip
# https://forums.malwarebytes.com/topic/295588-support-scam-supportclientexe-and-screenconnectwindowsclientexe/ (account required)
# https://forums.malwarebytes.com/topic/295605-techsupport-scam/ (account required)
# https://forums•malwarebytes•com/topic/295588-support-scam-supportclientexe-and-screenconnectwindowsclientexe/ (account required)
# https://forums•malwarebytes•com/topic/295605-techsupport-scam/ (account required)
# https://app.any.run/tasks/0f8b5786-177a-45c0-a1de-32e0d68beff2
-d 123secure.org
# https://github.com/RPiList/specials/issues/948#issuecomment-1458739160
-d yuppdownload.com
# Commonly set as a proxy on hacked devices (https://www.virustotal.com/gui/url/e610e7d09c614529cb8c64185717769946f5c86044ac5c31c6608e604995f577/detection)
-d 34.80.59.191
# Various domains on https://securitytrails.com/list/ip/72.14.178.174
# Various domains on https://securitytrails•com/list/ip/72•14•178•174
-d megabooru.com
-d zombooru.com
-d kusubooru.com
@@ -25271,7 +25273,7 @@ dvancedhosters.com$doc,domain=
-d 96.126.123.244
-d 173.255.194.134
-d 198.58.118.167
# https://hutudole.com/za-mu-%c9%93ullo-da-matakan-da-za-su-hana-al%c6%99alai-kwa%c9%97ayin-cin-hanci-ba-tinubu/
# https://hutudole•com/za-mu-%c9%93ullo-da-matakan-da-za-su-hana-al%c6%99alai-kwa%c9%97ayin-cin-hanci-ba-tinubu/
-d 123chance.net
-d 123links4u.net
-d 123prizes.net
@@ -25654,7 +25656,7 @@ dvancedhosters.com$doc,domain=
-d 94.237.93.242
-d 94.237.99.118
-d 139.45.197.249
# https://dnpedia.com/tlds/topm.php/bizarrely/listing/"anahitagirted.uno"/as the 622th most visited domain worldwide
# https://dnpedia•com/tlds/topm•php/bizarrely/listing/"anahitagirted•uno"/as the 622th most visited domain worldwide
-d acorusinfield.life
-d acridlydebit.live
-d aeneasclosure.website
@@ -26280,8 +26282,8 @@ ed.br ?q=artstation-
# ——— Anti-'Malware comments' (Currently Disqus-specific) ———
# https://myip.ms/info/limitexcess
# https://myip.ms/info/memberarea/My_Account.html
# https://myip•ms/info/limitexcess
# https://myip•ms/info/memberarea/My_Account•html
# ——— Dummy entry used to give myself credit, for when this list is used in large compilation hosts-type files (Although they are fully allowed by my licence to use this list, it'd be nice for me and end-users to see where it's being used, as a few of them do not credit their sources) ———
@@ -26292,14 +26294,14 @@ ed.br ?q=artstation-
# This section covers ones that would not normally be found in EasyList or AdGuard Base, for instance McAfee WebAdvisor (which also tries to change the search engine)
-d webadvisorc.rest.gti.mcafee.com
-d mip.api.mcafeewebadvisor.com
# https://get.adobe.com/no/reader/
# https://get•adobe•com/no/reader/
# Gigabyte APP Center (which use sneaky tricks to install a Norton 360 trial period; May require «AdGuard for Windows»)
-d mb.download.gigabyte.com FileList Swhttp DriverUpd ANTIVIRUS
# ——— Carried over from "Anti-'Asset Flip Shovelware' List" in response to Microsoft Store's non-existent quality control ———
# All legitimate Pac-Man games would use "pac-man" links with a dash
# https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
# https://eclypsium•com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
-d http://mb.download.gigabyte.com/FileList/Swhttp/LiveUpdate4
# (Presumably anonymous) E-mail tips