From f0f510e4cb971f2c213eef44b0e52963dad97be4 Mon Sep 17 00:00:00 2001 From: Imre Eilertsen Date: Tue, 24 Feb 2026 15:56:29 +0100 Subject: [PATCH] Syntax improvements. --- .../AntiMalwareAdGuardHome.txt | 73 +++---------------- 1 file changed, 9 insertions(+), 64 deletions(-) diff --git a/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt b/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt index 2a40de1cf..74e6d7c49 100644 --- a/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt +++ b/Alternate versions Anti-Malware List/AntiMalwareAdGuardHome.txt @@ -1,12 +1,12 @@ [Adblock Plus 3.13] ! Title: 💊 Dandelion Sprout's Anti-Malware List (for AdGuard Home, AdGuard for Android/Windows/macOS' DNS filtering, and Pi-Hole FTL ≥5.22) -! Version: 11February2026v1 +! Version: 21February2026v1 ! Expires: 1 day ! Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks domains and domain patterns used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there. ! Note: When asking us to whitelist a site: Make sure the site has some sort of public content. Non-public sites and alias sites are usually not whitelisted. ! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists ! Legitimate use is almost non-existent, but has a tiny userbase in Japan and among upstart coding experiments. Its extreme common-ness in malware redirections means that the entry will be kept forever. -||*.top^$dnstype=~CNAME,denyallow=caitlin.top|callmebymygender.top|corriente.top|gdtot.top|nicenature.top|reminder.top|magocoro.top|castlevania.top|suiten.top|shucks.top|1stream.top|ambr.top|changlam10.top|changlam11.top|pdcdn1.top|pressplay.top|chillx.top|strims.top|thedesk.top|audioforyou.top|awavenue.top|reyhub.top|iboxs.top|adrules.top|hostingowy.top|to|yggtorrent.top|asiaon.top|voxel.top|passt.top|polar.top|rifton.top|rugaming.top|doubledouble.top +||*.top^$dnstype=~CNAME,denyallow=caitlin.top|callmebymygender.top|corriente.top|gdtot.top|nicenature.top|reminder.top|magocoro.top|castlevania.top|suiten.top|shucks.top|1stream.top|ambr.top|changlam10.top|changlam11.top|pdcdn1.top|pressplay.top|chillx.top|strims.top|thedesk.top|audioforyou.top|awavenue.top|reyhub.top|iboxs.top|adrules.top|hostingowy.top|to|yggtorrent.top|asiaon.top|voxel.top|passt.top|polar.top|rifton.top|rugaming.top|doubledouble.top|hedon-haven.top ! (Loosely inspired by https://github.com/DandelionSprout/adfilt/issues/1067) @@||masto*.top^ @@/^.*(tech|project|linux).*\.top(/[a-z0-9_-]?.*)?$/ @@ -26,7 +26,6 @@ ! Domains that used to host lists for adblockers or "hosts" tools, but which are now either used by malware pushers, or could potentially be snapped up by them. ||adblock.gjtech.net^ ||spam404bl.com^ -ipaddress=109.201.135.46 109.201.135.46 ||fredfiber.no^ ||securemecca.com^ @@ -57,7 +56,6 @@ ipaddress=109.201.135.46 ||mandriva.com^ ! Fraudulent browser extensions ||ublock.org^ -ipaddress=138.68.252.54 138.68.252.54 ||useragentswitch.com^ ||dev-nano.com^ @@ -659,9 +657,6 @@ ipaddress=138.68.252.54 ||kmip.net^ ||0redirc.com^ ||iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com^ -ipaddress=5.8.34.26 -ipaddress=5.8.47.3 -ipaddress=103.224.182.251 5.8.34.26 5.8.47.3 103.224.182.251 @@ -682,10 +677,6 @@ ipaddress=103.224.182.251 ! https://github.com/DandelionSprout/adfilt/issues/196 ||secureportal.online^ ||emiratenbduae.com^ -ipaddress=108.170.31.123 -ipaddress=108.170.52.156 -ipaddress=66.85.156.85 -ipaddress=66.85.156.86 108.170.31.123 108.170.52.156 66.85.156.85 @@ -749,13 +740,11 @@ ipaddress=66.85.156.86 ||justinstalledpanel.com^ ||albumzips.xyz^ ||aleinvest.xyz^ -ipaddress=5.188.62.36 5.188.62.36 ! https://github.com/DandelionSprout/adfilt/issues/223 ||speedupmypcfree.com^ ! https://github.com/DandelionSprout/adfilt/issues/224 ||ssielearning.com^ -ipaddress=69.49.231.244 69.49.231.244 ! https://movsb•0x0•st/users/mia ! https://github.com/DandelionSprout/adfilt/issues/228 @@ -765,7 +754,6 @@ ipaddress=69.49.231.244 ||rblxexploits.net^ ||nanorgin.ydns.eu^ ||yzsnw.com^ -ipaddress=37.34.176.37 37.34.176.37 ||pcspeedcat.com^ ||auslogics.com^ @@ -783,8 +771,6 @@ ipaddress=37.34.176.37 ||mgmgmg.com^ ||temp74.com^ ||trackwebclick.com^ -ipaddress=23.111.31.137 -ipaddress=23.111.88.207 23.111.31.137 23.111.88.207 ! https://github.com/DandelionSprout/adfilt/issues/254 @@ -840,7 +826,6 @@ ipaddress=23.111.88.207 ||kiff.tech^ ! https://www•virustotal•com/gui/domain/kiff•tech/relations ! https://www•virustotal•com/gui/url/dc038496b1b5358b97f89440135ec91258b406c40859a2cd95983dc7a81e0cfa/detection -ipaddress=45.90.58.90 45.90.58.90 ! https://www•virustotal•com/gui/file/e565ba89d034418fd26a5f642f6eeee4d72ee3b8dc69523419b7ca8dfd452730/community ! https://www•virustotal•com/gui/url/e3a9189a1e1256beba8e0fc3abfeab6acb09f7f8cabfd973e22be9f77bb6886f/detection @@ -1149,7 +1134,6 @@ ipaddress=45.90.58.90 ! https://www•nrk.no/vestfoldogtelemark/1.15750360 ||dundeehills.group^ !+ NOT_OPTIMIZED -ipaddress=132.148.220.142 132.148.220.142 ||chess-progress.ru^ ! https://scammer•info/t/there-are-things-in-the-game-that-will-interest-you-trojan/84908 @@ -1226,18 +1210,11 @@ ipaddress=132.148.220.142 ||findsexy.life^ ||findsolemate.life^ ||dating-galaxy.life^ -ipaddress=195.201.253.130 -ipaddress=195.201.253.131 195.201.253.130 195.201.253.131 ! The bottom download button on https://www•sushichop•com/ ||installiq.com^ ||cpmverdirect.com^ -ipaddress=15.197.244.48 -ipaddress=96.47.230.67 -ipaddress=96.47.230.68 -ipaddress=96.47.230.69 -ipaddress=96.47.230.70 15.197.244.48 96.47.230.67 96.47.230.68 @@ -1262,7 +1239,6 @@ ipaddress=96.47.230.70 ||kdmrqw.com^ ||kdmttk.com^ ||uuidtsinc.net^ -ipaddress=31.220.27.134 31.220.27.134 ! https://github.com/AdguardTeam/AdguardFilters/issues/122757 ://adbrbk. @@ -1398,8 +1374,6 @@ ipaddress=31.220.27.134 85.17.31.152 95.211.26.202 ! https://kommunikasjon•ntb•no/pressemelding/power-advarer-mot-sms-svindel?publisherId=17847615&releaseId=17937583 -ipaddress=158.247.212.220 -ipaddress=165.227.168.212 158.247.212.220 165.227.168.212 ! https://new•reddit•com/r/engrish/comments/w6u4uy/received_this_text_message_yesterday_i_am_very/ @@ -1422,7 +1396,6 @@ ipaddress=165.227.168.212 ||stelronsi.net^ ||tadaickaipt.com^ ||vekeltaizy.net^ -ipaddress=139.45.197.236 139.45.197.236 ! https://github.com/AdguardTeam/AdguardFilters/issues/128029 ||becovi.com^ @@ -1439,9 +1412,6 @@ ipaddress=139.45.197.236 ||tutatagliente.com^ ||potestainsula.com^ ||motherpipe.net^ -ipaddress=51.91.66.125 -ipaddress=51.178.76.105 -ipaddress=147.135.253.55 51.91.66.125 51.178.76.105 147.135.253.55 @@ -1450,8 +1420,6 @@ ipaddress=147.135.253.55 !+ NOT_OPTIMIZED !+ NOT_OPTIMIZED ! https://github.com/AdguardTeam/AdguardFilters/issues/131156 -ipaddress=146.19.169.98 -ipaddress=146.19.169.99 146.19.169.98 146.19.169.99 ! https://github.com/AdguardTeam/AdguardFilters/issues/132079 @@ -2970,7 +2938,6 @@ ipaddress=146.19.169.99 ! Random Discord servers ||newntflix- ||giveawaycord. -ipaddress=162.241.124.200 162.241.124.200 ! https://github.com/AdguardTeam/AdguardFilters/issues/135815 ||adsstar.in^ @@ -2983,7 +2950,6 @@ ipaddress=162.241.124.200 ||tnlink.in^ ||tnvalue.in^ ||webhostingtips.club^ -ipaddress=157.90.71.190 157.90.71.190 ! https://github.com/AdguardTeam/AdguardFilters/issues/135924 ||beskittyan.com^ @@ -3021,9 +2987,6 @@ ipaddress=157.90.71.190 ||uxobx.xyz^ ||vayamuegn.icu^ ||wehiqes.xyz^ -ipaddress=44.228.230.225 -ipaddress=50.112.124.170 -ipaddress=100.20.104.229 44.228.230.225 50.112.124.170 100.20.104.229 @@ -3036,10 +2999,6 @@ ipaddress=100.20.104.229 ||gsecurecontent.com^ ||pressizer.net^ ||sapino.net^ -ipaddress=44.236.213.34 -ipaddress=52.24.156.12 -ipaddress=52.25.6.134 -ipaddress=100.20.13.49 44.236.213.34 52.24.156.12 52.25.6.134 @@ -3272,7 +3231,6 @@ ipaddress=100.20.13.49 ||salomonusa* ||sauconyoutlet* ||botashunter* -||hokaoneone* ||hokaoutlet* *-factoryoutlet. *-outletfactory. @@ -3476,8 +3434,6 @@ ipaddress=100.20.13.49 ||project-obs.com^ ||studio-obs.com^ ||webull-download. -ipaddress=185.106.94.139 -ipaddress=45.90.109.196 185.106.94.139 45.90.109.196 91.229.23.200 @@ -3497,7 +3453,6 @@ ipaddress=45.90.109.196 185.155.184.98 194.110.247.242 ! https://new•reddit•com/r/engrish/comments/10zs6f6/low_budget_scam/ -ipaddress=54.219.218.169 54.219.218.169 ! https://new•reddit•com/r/engrish/comments/10z8r2u/well_you_tried/ ||0365alert.com^ @@ -10889,7 +10844,6 @@ ipaddress=54.219.218.169 ||yj-huayuan.com^ ||ynjkdl.com^ ||yuxc.xyz^ -ipaddress=103.155.214.207 103.155.214.207 ! Inspired by https://github.com/AdguardTeam/AdguardFilters/issues/197908 ||app-update.site^ @@ -12784,19 +12738,16 @@ http://secured21.*.com/| ||drugcoupons.xyz^ ||freemedicine.info^ ||medication.coupons^ -ipaddress=147.135.16.27 147.135.16.27 ! https://www•google•no/search?q=mlp+g5&newwindow=1&tbm=isch&oq=mlp+g5&sclient=img ||ingeniovirtual.com^ ! https://scambiofigu•forumcommunity•net/?t=57482915 ! Only links to another site's (APKPure) APKs, yet tries to promote its own browser extension on the alleged download pages, which comes across as suspicious ! Google results for 'Katy and Bob:Cake Café powerpc' (04/11/2022) -ipaddress=185.87.148.199 185.87.148.199 ! Google results for 'horse tales: emerald valley ranch mobygames' (05/11/2022) ||gacorhub.com^ ||zh1653.com^ -ipaddress=45.136.49.35 45.136.49.35 ! Browsing around for Tajik newssites ||etarefcity.live^ @@ -12846,18 +12797,6 @@ ipaddress=45.136.49.35 ||zombooru.com^ ||kusubooru.com^ ||wh40kart.im^ -ipaddress=45.33.2.79 -ipaddress=45.33.18.44 -ipaddress=45.33.20.235 -ipaddress=45.33.23.183 -ipaddress=45.33.30.197 -ipaddress=45.56.79.23 -ipaddress=45.79.19.196 -ipaddress=72.14.178.174 -ipaddress=72.14.185.43 -ipaddress=96.126.123.244 -ipaddress=173.255.194.134 -ipaddress=198.58.118.167 45.33.2.79 45.33.18.44 45.33.20.235 @@ -14116,7 +14055,7 @@ ipaddress=198.58.118.167 ||odintara.com^ 54.174.156.141 ! Searched for Breaking Bad Jesse memes on Qwant (29/04/2025) -://old.sermitsiaq.ag^$denyallow=subdomain_stolen_from_sermitsiaqs_owners.* +://old.sermitsiaq.ag^ 85.159.213.158 ! Seemingly mass-generated fake "marketing company" sites that seem to serve no visible purpose (12/05/2025) 23.170.252.196 @@ -15664,6 +15603,12 @@ ipaddress=198.58.118.167 ||filehost09.sbs^ ||sharehost06.sbs^ ||getdwnloadss.com^ +! https://tria.ge/260215-q8jvdaey6c/behavioral1 +||crvftgbyh.click^ +||tvgyfdtrf.pro^ +||edweasdxf.pro^ +||hubygvftc.cfd^ +||audioza.cyou^ ! ——— Horrendously bad copypasted Android rooting "guides" (often with fake titles) that bricked two of my phones ——— ! Most of the guides haven't even accounted for how modern phones have replaced the recovery environment with an extra boot environment, leading to very critical Fastboot commands not working and/or bricking the phone. ||unofficialtwrp.com^