[Adblock Plus 2.0] ! Title: The malicious website blocklist ! Homepage: https://github.com/iam-py-test/my_filters_001 ! Expires: 1 day ! Last updated: 11/5/2023 ! Version: 1152023-3 ! Description: This list aims to protect against scams, phishing, malware, and potentially unwanted programs (PUPs). It includes a version of vxvault.net's list, modified by me to work in adblockers. ! Special thanks to all of the people who have helped me maintain this list! Check out https://github.com/iam-py-test/my_filters_001/blob/main/CONTRIBUTORS.md ! Issues url: https://github.com/iam-py-test/my_filters_001/issues ! GitLab issues url (not checked as often): https://gitlab.com/iam-py-test/my_filters_001/-/issues ! Note: This list includes a version of VXVault.net's malware distribution url list, formatted for adblockers, which is at https://github.com/iam-py-test/vxvault_filter ! ----- Malware and phishing ----- ! A Facebook phishing website ! https://www.siteadvisor.com/sitereport.html?url=xn--faebook-64a.com ! https://www.fortiguard.com/webfilter?q=xn--faebook-64a.com ! https://www.virustotal.com/gui/domain/xn--faebook-64a.com/detection ! https://safeweb.norton.com/report/show?url=xn--faebook-64a.com ||xn--faebook-64a.com^$document ! https://www.virustotal.com/gui/url/ab4e55cf3a5a2c02b2e7c956fa692f06770c81cd02a4b7741793b9c4b73e7e88/detection ! https://www.joesandbox.com/analysis/422872/0/html ! https://www.siteadvisor.com/sitereport.html?url=strawberry6532210.brizy.site ! https://www.virustotal.com/gui/url/ac7399fe8dda64a75a77ffc107219fcd90dc9bf2af6bc0893bef5d63b348dfe2/detection ! https://www.virustotal.com/gui/domain/strawberry6532210.brizy.site/detection ! https://transparencyreport.google.com/safe-browsing/search?url=strawberry6532210.brizy.site ! https://www.urlvoid.com/scan/strawberry6532210.brizy.site/ ! https://www.fortiguard.com/webfilter?q=strawberry6532210.brizy.site ! https://sitecheck.sucuri.net/results/strawberry6532210.brizy.site ! https://quttera.com/detailed_report/strawberry6532210.brizy.site ! https://www.google.com/s2/favicons?domain=strawberry6532210.brizy.site ||strawberry6532210.brizy.site^$all ! https://quttera.com/detailed_report/strawberry6532210.brizy.site ! https://www.siteadvisor.com/sitereport.html?url=starlangbank.com ! https://transparencyreport.google.com/safe-browsing/search?url=starlangbank.com ! https://quttera.com/detailed_report/starlangbank.com ! https://www.fortiguard.com/webfilter?q=starlangbank.com ! https://www.virustotal.com/gui/domain/starlangbank.com/detection ||starlangbank.com^$all ! https://www.joesandbox.com/analysis/424179/0/html ! https://www.virustotal.com/gui/url/7182b03efde39bf8355a8c9e3ab40e9918a799863b51ead503e212c6b56fcbae/detection ! https://www.virustotal.com/gui/domain/aloha-news.net/detection ! https://www.siteadvisor.com/sitereport.html?url=http%3A%2F%2Faloha-news.net ! https://safeweb.norton.com/report/show?url=http%3A%2F%2Faloha-news.net ! https://sitecheck.sucuri.net/results/aloha-news.net ! https://www.urlvoid.com/scan/aloha-news.net/ ! https://www.fortiguard.com/webfilter?q=aloha-news.net ||aloha-news.net^$all ! https://cyberwarzone.com/whatsapp-phishing/ ! https://www.fortiguard.com/webfilter?q=cht-whatsappz.zzux.com ! https://www.fortiguard.com/webfilter?q=zzux.com ! https://www.mywot.com/en/scorecard/zzux.com ! https://www.urlvoid.com/scan/zzux.com/ ! https://sitecheck.sucuri.net/results/zzux.com ! https://transparencyreport.google.com/safe-browsing/search?url=zzux.com ! https://safeweb.norton.com/report/show?url=zzux.com ! https://www.virustotal.com/gui/url/993fb0a37ec2e4b3503bac3b38066dabd040f43a3f47ca99c6839df9bf5dd018/detection ! https://safeweb.norton.com/report/show?url=cht-whatsappz.zzux.com ! https://www.virustotal.com/gui/url/f89e84af4a187e413fd85b2cc7b604ef1b0b5b3e94c18f039ba1539d593eb898/detection ||cht-whatsappz.zzux.com^$all ! https://github.com/uBlockOrigin/uAssets/issues/8466 ! https://www.virustotal.com/gui/ip-address/91.241.60.117/relations ! https://www.virustotal.com/gui/url/08e979bb4cde20ad8b711920f0fa604de67911559013f0fc60560990fbbad239/detection ! https://www.siteadvisor.com/sitereport.html?url=91.241.60.117 ||91.241.60.117^$all ! https://www.virustotal.com/gui/url/f616050b625e09419d8986295aab0c338f4139d3130d5c2865362fd869eeb0b8/detection ! https://www.virustotal.com/gui/url/f6d90ea65eeccc84ea6a99477811293bc0fcd4b7b845751714b69a9fe6f43a37/community ! https://www.reddit.com/r/FreeCodeCamp/comments/6gxk09/hey_guys_i_did_some_snooping_from_a_phishing/ ! https://pastebin.com/270dCwHz ! https://www.virustotal.com/gui/url/953cfae8ac5b570128d1edbfc648d81db436355be1e614f6e96b95226964a61e/detection ! https://www.virustotal.com/gui/url/23651d7da557669781e7ae2927a20f65ac86bdf3712b407018911d974a94a68d/detection ! https://www.reddit.com/r/mildlyinfuriating/comments/nc9zpe/got_a_paypal_or_should_i_say_paypl_phishing_email/ ! https://www.virustotal.com/gui/url/c0e5466cd2843f75d522093d93cf949259ca618ca2f00aa4952e7700cbf59384/detection ||paypl.com^$all ! https://www.virustotal.com/gui/url/4531df5b01e2c58f9307fabecc9a17b03c6157bafc8e9af736b278e95c182dc5/community ||payapl.com^$all ! https://www.virustotal.com/gui/url/91aecb78868044183cbe47614fb43a7e5aecd4b4ae89294a215354bdda2c3602/detection ! https://www.fortiguard.com/webfilter?q=paypaI.com ! https://www.mywot.com/en/scorecard/paypaI.com ! https://safeweb.norton.com/report/show?url=paypaI.com ||paypaI.com^$all ! Used to infect and redirect domains ! https://labs.sucuri.net/signatures/sitecheck/malware-rks_injection/ ! https://blog.sucuri.net/2011/01/malware-update-co-cc.html ! https://www.fortiguard.com/webfilter?q=http%3A%2F%2Fgoogle-analytisc.co.cc&version=8 ! https://safeweb.norton.com/report/show?url=http%3A%2F%2Fgoogle-analytisc.co.cc ! https://www.virustotal.com/gui/url/6cc9c5dbd531e82102590df163142db0c248de81b831372a35fb281d90a6c768/detection ! https://www.urlvoid.com/scan/google-analytisc.co.cc/ ! https://www.mywot.com/en/scorecard/google-analytisc.co.cc ! https://sitecheck.sucuri.net/results/google-analytisc.co.cc ! Appears offline but per https://github.com/uBlock-LLC/uBlock/issues/1839#issuecomment-852183358 adding anyway ||google-analytisc.co.cc^$all ! https://www.virustotal.com/gui/url/b3565bedd215978dc3f0e60c82e20f600f4b404343d8a4c89dd336986c941c65/community ! https://www.fortiguard.com/webfilter?q=http%3A%2F%2Foiwdd.co.cc&version=8 ! https://safeweb.norton.com/report/show?url=http://oiwdd.co.cc ! https://www.virustotal.com/gui/url/b0ccfa7eaf148df692177674f5aafeb27792399f4b03d1a75951533f6b7e7e52/detection ! https://www.urlvoid.com/scan/oiwdd.co.cc/ ! https://www.mywot.com/scorecard/oiwdd.co.cc ||oiwdd.co.cc^$all ! https://www.fortiguard.com/webfilter?q=http%3A%2F%2Fpojdue.co.cc&version=8 ! https://www.virustotal.com/gui/url/2ba73f2605b7dff79153f65cf94aee57f68e476c92234d0b4d46e29d8c4eaa12/detection ! https://www.virustotal.com/gui/domain/pojdue.co.cc/detection ! https://www.urlvoid.com/scan/pojdue.co.cc/ ! https://www.mywot.com/scorecard/pojdue.co.cc ||pojdue.co.cc^$all ! https://labs.sucuri.net/signatures/sitecheck/malware-magento_shoplift-38-1/ ! https://www.virustotal.com/gui/domain/mcloudjs.com/detection ! https://www.virustotal.com/gui/url/01a9b775e89304d7ebce8e7e5822d730b043868e09994a17786da0a71ec49691/community ! https://www.siteadvisor.com/sitereport.html?url=mcloudjs.com ! https://www.fortiguard.com/webfilter?q=mcloudjs.com ! https://www.urlvoid.com/scan/mcloudjs.com/ ! https://safeweb.norton.com/report/show?url=mcloudjs.com ! https://sitecheck.sucuri.net/results/mcloudjs.com ! https://labs.sucuri.net/blacklist/info/?domain=mcloudjs.com ! https://transparencyreport.google.com/safe-browsing/search?url=mcloudjs.com ||mcloudjs.com^$all ! https://www.virustotal.com/gui/url/082438d5ecfe8ccb9e087475cffd979211f3a52f0db27379e5072ce5d11597e8/detection ! https://www.virustotal.com/gui/ip-address/54.227.98.220/community ! https://www.virustotal.com/gui/url/6000a64c8a7e32d0cc6f319d9149b1eba038d6fba0139ed2c6a146db36cb8b02/detection ! https://www.virustotal.com/gui/url/ceb914f42f5a81bc8ea6c79b3d274f9161f252504e7603388781711cafc9e36d/detection ! https://labs.sucuri.net/signatures/sitecheck/malware-redkit/ ! https://www.virustotal.com/gui/url/26a7a5909ca372bc57d68df966fc03b887451a7cf8ae58c5cea92639b4ce2594/detection ! https://www.virustotal.com/gui/url/78eca70299b830e87ed8f6b3d276e231f2147d5c2817a3586b1ceb5310ea89fa/detection ! https://www.virustotal.com/gui/domain/wherewedev.com/detection ! https://www.fortiguard.com/webfilter?q=wherewedev.com ! https://www.urlvoid.com/scan/wherewedev.com/ ! https://www.mywot.com/en/scorecard/wherewedev.com ! https://safeweb.norton.com/report/show?url=wherewedev.com ! https://sitecheck.sucuri.net/results/wherewedev.com ||wherewedev.com^$all ! https://www.virustotal.com/gui/url/a9e68e1b4cdd0e2f58dadf4cd5a93a9983a79b600f1423f86cc5f68b0fec729f/detection ! https://www.fortiguard.com/webfilter?q=infinitypr.in ! https://sitecheck.sucuri.net/results/infinitypr.in ||infinitypr.in^$3p ! https://www.virustotal.com/gui/url/86e9efc17750d2885c940cf6ff08820aee1bf35f23fc0faac71a05467b13c0e3/detection ! https://www.fortiguard.com/webfilter?q=integra-lernwerkstatt.de ! https://www.mywot.com/en/scorecard/integra-lernwerkstatt.de ! https://safeweb.norton.com/report/show?url=integra-lernwerkstatt.de ! https://sitecheck.sucuri.net/results/integra-lernwerkstatt.de ! https://labs.sucuri.net/blacklist/info/?domain=integra-lernwerkstatt.de ! https://labs.sucuri.net/blacklist/details/?domain=integra-lernwerkstatt.de ||integra-lernwerkstatt.de^$all ! https://www.virustotal.com/gui/url/832387cfafab7a27faeac07961e56b98af8001fb702fbb9f09821d6a3213f7c8/detection ! 8/34 URLVoid detections 4 years ago ! https://www.virustotal.com/gui/file/5e6c167fc70aee2438f92ac0391dcba5905d989a20134dbb4bc9c3c40f805e74/relations ! https://www.virustotal.com/gui/url/a0fba2a31b88b8e1d6607971bd05440ee43702327e19d93ba91c705f7189c533/detection ! https://www.virustotal.com/gui/domain/kjwre77638dfqwieuoi.info/detection ! https://www.virustotal.com/gui/url/7d1b788cd3afd004b36421ad288b17ca4f2c5ad8e37363022b4f8573c7b77e03/detection ! https://www.siteadvisor.com/sitereport.html?url=kjwre77638dfqwieuoi.info ! https://www.fortiguard.com/webfilter?q=kjwre77638dfqwieuoi.info ! https://www.urlvoid.com/scan/kjwre77638dfqwieuoi.info/ ! https://www.mywot.com/en/scorecard/kjwre77638dfqwieuoi.info ! https://safeweb.norton.com/report/show?url=kjwre77638dfqwieuoi.info ! https://sitecheck.sucuri.net/results/kjwre77638dfqwieuoi.info ! https://quttera.com/detailed_report/kjwre77638dfqwieuoi.info ||kjwre77638dfqwieuoi.info^$all ! https://www.virustotal.com/gui/domain/kjwre77638dfqwieuoi.info/detection ! https://www.virustotal.com/gui/domain/kukutrustnet777.info/detection ! https://www.siteadvisor.com/sitereport.html?url=kukutrustnet777.info ! https://www.fortiguard.com/webfilter?q=kukutrustnet777.info ! https://www.urlvoid.com/scan/kukutrustnet777.info/ ! https://www.mywot.com/en/scorecard/kukutrustnet777.info ! https://safeweb.norton.com/report/show?url=kukutrustnet777.info ! https://sitecheck.sucuri.net/results/kukutrustnet777.info ! https://quttera.com/detailed_report/kukutrustnet777.info ||kukutrustnet777.info^$all ! https://www.virustotal.com/gui/url/38e39cdaa4d595968e55e4bcaa45818c887257e81ae6020bf2cb77c34a2e55be/detection ! https://www.fortiguard.com/webfilter?q=moch.forweb.pl ! https://safeweb.norton.com/report/show?url=moch.forweb.pl ||moch.forweb.pl^$document ! https://labs.sucuri.net/signatures/sitecheck/malware-iis_injection/ ! https://blog.dynamoo.com/2011/04/alisa-cartercom-lizamooncom-and-worid.html ! https://safeweb.norton.com/report/show?url=http://nbnjkl.com ! https://www.mywot.com/scorecard/nbnjkl.com ! https://www.virustotal.com/gui/url/338e2d8fa2f879d7419ca189a07635a8af4eed707e3a44509a4a7ef497fef65b/detection ! https://www.fortiguard.com/webfilter?q=http%3A%2F%2Fnbnjkl.com&version=8 ||nbnjkl.com^$all ! https://blog.dynamoo.com/2011/04/alisa-cartercom-lizamooncom-and-worid.html ! https://safeweb.norton.com/report/show?url=lizamoon.com ! https://safeweb.norton.com/reviews?url=lizamoon.com ! https://www.mywot.com/scorecard/lizamoon.com ! https://www.virustotal.com/gui/url/4fd4a9edc47f789c4819fed8887f4b64b3cf004ca76437a250b931964a8a444c/detection ! https://sitecheck.sucuri.net/results/lizamoon.com ! https://yandex.com/safety/?url=lizamoon.com ! https://www.fortiguard.com/webfilter?q=lizamoon.com&version=8 ! https://www.siteadvisor.com/sitereport.html?url=lizamoon.com ||lizamoon.com^$all ! https://safeweb.norton.com/report/show?url=worid-of-books.com ! https://safeweb.norton.com/reviews?url=worid-of-books.com ! https://www.mywot.com/scorecard/worid-of-books.com ! https://www.virustotal.com/gui/url/0bfa343fff2fa54e5af379104ce64c9bf3057246c8e0a09fb71bba57b57f24e2/detection ! https://sitecheck.sucuri.net/results/worid-of-books.com ! https://www.fortiguard.com/webfilter?q=worid-of-books.com&version=8 ||worid-of-books.com^$all ! https://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html ! https://www.siteadvisor.com/sitereport.html?url=robint.us ! https://www.fortiguard.com/webfilter?q=robint.us ! https://www.mywot.com/en/scorecard/robint.us ! https://safeweb.norton.com/report/show?url=robint.us ! https://safeweb.norton.com/reviews?url=robint.us ! https://sitecheck.sucuri.net/results/robint.us ! https://www.virustotal.com/gui/url/e72a564873593a2755e6f4d3567c679df27ffb7ea60cbaf9089ddd8df18d0a7b/detection ||robint.us^$all ||www.robint.us^$3p ! https://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-2677-inyahoo-js.html ! https://www.virustotal.com/gui/url/f507e6a0a01f24299ff14722397af662bf0ec9cdcf111af4a378c0be9696d3ac/detection ! https://www.siteadvisor.com/sitereport.html?url=2677.in ! https://www.fortiguard.com/webfilter?q=2677.in ! https://www.urlvoid.com/scan/2677.in/ ! https://www.mywot.com/en/scorecard/2677.in ! https://safeweb.norton.com/report/show?url=2677.in ! https://sitecheck.sucuri.net/results/2677.in ! https://yandex.com/safety/?url=2677.in ||2677.in^$all ! https://www.virustotal.com/gui/ip-address/199.59.242.150/relations ! https://www.siteadvisor.com/sitereport.html?url=199.59.242.150 ! https://www.fortiguard.com/webfilter?q=199.59.242.150 ! https://safeweb.norton.com/report/show?url=199.59.242.150 ! https://www.ipvoid.com/ip-blacklist-check/ ||199.59.242.150^$all ! If you see connections to this domain, update your computer and delete any recently downloaded files ! https://github.com/hoshsadiq/adblock-nocoin-list/issues/414 ! https://www.virustotal.com/gui/url/e913b807ae25aa1e24b4e934805d0cd81be4d5aa6c491d14a9f4dc050da20f94/detection ! https://www.joesandbox.com/analysis/431924/0/html#domains ! https://www.virustotal.com/gui/url/254b1fd9f7536ece07cf5a3747aa2adeccc76e61b1f4e5994c0dc683d0a6db03/detection ! https://www.virustotal.com/gui/url/be44f0113500882e27eb730cfdad7687fe75ad56c8e9d9b2426273a0eb13e201/detection ! https://www.siteadvisor.com/sitereport.html?url=alphastand.win ! https://www.fortiguard.com/webfilter?q=alphastand.win ! https://safeweb.norton.com/report/show?url=alphastand.win ! https://sitecheck.sucuri.net/results/alphastand.win ! https://quttera.com/detailed_report/alphastand.win ||alphastand.win^$all ! https://www.siteadvisor.com/sitereport.html?url=alphastand.trade ! https://www.fortiguard.com/webfilter?q=alphastand.trade ! https://safeweb.norton.com/report/show?url=alphastand.trade ! https://sitecheck.sucuri.net/results/alphastand.trade ! https://www.virustotal.com/gui/domain/alphastand.trade/detection ||alphastand.trade^$all ! https://www.joesandbox.com/analysis/413824/0/html#domains ! https://www.virustotal.com/gui/ip-address/185.14.29.217/relations ! https://www.virustotal.com/gui/url/9c1f4fd3af06c7eff8fa0c96c0386acdea17225b7202b87044a5e7895d80f694/detection ! https://www.virustotal.com/gui/url/84a718f502c01ee926debf1097f4e0ef7593fd821cda1f5cb1a072bc4198b7d8/detection ||185.14.29.217^$all ! https://www.virustotal.com/gui/url/9c1f4fd3af06c7eff8fa0c96c0386acdea17225b7202b87044a5e7895d80f694/detection ! https://www.virustotal.com/gui/domain/saywowshow.com/detection ! https://safeweb.norton.com/report/show?url=saywowshow.com ||saywowshow.com^$all ! https://forum.mywot.com/reputation-discussions-f5/ridiculous-eth-bitcoin-giveaways-or-instant-invest-t86210.html ||btc-promo.czweb.org^$all ||eth24win.co.nf^$all ||giveaway-eth-btc.webz.cz^$all ! https://www.bleepingcomputer.com/news/security/phishing-impersonates-global-recruitment-firm-to-push-malware/ ! https://twitter.com/InQuest/status/1385324245891182592 ! https://www.virustotal.com/gui/url/81913a8a7fa758d7476a13ff03395f31f665addf973adf253c5123fbb8a4caf4/detection ! https://www.virustotal.com/gui/url/cd77c6e39b0ca34cb7bd0106e769f2a4a019b05f96d608582f4ad7693b604f6a/detection ! https://safeweb.norton.com/report/show?url=powerhousetoys.com ! https://www.siteadvisor.com/sitereport.html?url=https://powerhousetoys.com/opp.txt ||powerhousetoys.com^$all ! https://www.virustotal.com/gui/url/3174e1565216d9399308ab280793130f961a01b40cc4c2457b231cad3207ef2c/detection ! https://twitter.com/InQuest/status/1403047978185670663 ! https://www.virustotal.com/gui/ip-address/23.95.122.53/relations ! https://www.fortiguard.com/webfilter?q=23.95.122.53 ! https://safeweb.norton.com/report/show?url=23.95.122.53 ! https://www.ipvoid.com/ip-blacklist-check/ ||23.95.122.53^$all ! https://www.virustotal.com/gui/url/3961877189248724c33e9d6b0e590b9e11607d27de88cd7f130487719c2e8efd/detection ! https://www.fortiguard.com/webfilter?q=crypto-loot.com ! https://www.mywot.com/en/scorecard/crypto-loot.com ! https://safeweb.norton.com/report/show?url=crypto-loot.com ! https://quttera.com/detailed_report/crypto-loot.com ! https://sitecheck.sucuri.net/results/crypto-loot.com ||crypto-loot.com^$all ! https://www.fortiguard.com/webfilter?q=crypto-loot.org ! https://www.virustotal.com/gui/url/bed5db125302663b090d4dcf170873a5ff60bbe44d72e451801497751e5a78df/detection ! https://safeweb.norton.com/report/show?url=crypto-loot.org ! https://sitecheck.sucuri.net/results/crypto-loot.org ||crypto-loot.org^$all ! https://github.com/webcompat/web-bugs/issues/74703 ! https://www.siteadvisor.com/sitereport.html?url=mysecrethoookup.com ! https://www.fortiguard.com/webfilter?q=mysecrethoookup.com&version=8 ! https://www.virustotal.com/gui/url/ad652f0b682616bb75b6ab31ed6be38fddf4c46b2d2405ea738bbee1a80e85c7/detection ! https://safeweb.norton.com/report/show?url=mysecrethoookup.com ! https://sitecheck.sucuri.net/results/mysecrethoookup.com ||mysecrethoookup.com^$all ! Malware redirects from a hacked site listed in uBo badware ! https://sitecheck.sucuri.net/results/ludibry.tech ! https://safeweb.norton.com/report/show?url=https://js.users.51.la/20876409.js ! https://www.mywot.com/scorecard/js.users.51.la ! https://www.virustotal.com/gui/url/c838d4f72c516e88bbdd2024b58fe2b8d1e2e4516ac7d3fd50639599b6c19bd2/detection ! https://www.virustotal.com/gui/url/68151aabba9b13d3d6ff699964998d04e619718e8c3db35da421f330f6ffe596/detection ! https://www.virustotal.com/gui/domain/51.la/detection ! https://www.virustotal.com/gui/domain/sdk.51.la/detection ! https://www.virustotal.com/gui/domain/51.la/relations ! https://www.siteadvisor.com/sitereport.html?url=https://js.users.51.la/20876409.js ! https://www.mywot.com/en/scorecard/51.la ! https://safeweb.norton.com/reviews?url=51.la ! https://sitecheck.sucuri.net/results/51.la ! https://www.virustotal.com/gui/url/e99e09ab22be6aa9b05773666cb726abf7be2b1fc455d4681787224aaf88ef53/detection ||js.users.51.la^$all ! https://quttera.com/detailed_report/51.la ! https://www.virustotal.com/gui/url/6a65d86d46544d0619f4cee37b6e8b7c5e573e617da839e7dd3367c3a7cb7c1f/detection ! https://www.virustotal.com/gui/url/a0c05bd080ca05fc28c5dd14280435bc71b23737f346fa9a26062af4d6a25e84/detection ||web.51.la^$all ||ia.51.la^$all ! https://www.virustotal.com/gui/url/2bdd51215412c52f5cdf2ff0183547073896503f6a6bb707e795575ebb9ef6f8/detection ||collect-v6.51.la^$all ! https://www.virustotal.com/gui/ip-address/104.236.14.145/relations ! https://www.mywot.com/en/scorecard/blogsopt.com ! https://www.virustotal.com/gui/url/6d9e9d347f3578fe8fea973820a40a0ab760165e613af323b4a025dee339c73e/detection ||blogsopt.com^$document ! https://www.urlvoid.com/ip/103.224.212.247/ ! https://www.urlvoid.com/scan/dacenete.com/ ! https://www.mywot.com/en/scorecard/dacenete.com ! https://www.virustotal.com/gui/url/1edf1ec0e4f299ec94a3c4cdfc882795a0a0e77031c866f595e8354120bee802/community ! https://www.siteadvisor.com/sitereport.html?url=Dacenete.com ! https://www.fortiguard.com/webfilter?q=Dacenete.com ! https://safeweb.norton.com/report/show?url=Dacenete.com ! https://yandex.com/safety/?l10n=en&url=dacenete.com ! https://sitecheck.sucuri.net/results/Dacenete.com ||dacenete.com^$all ! https://www.siteadvisor.com/sitereport.html?url=Coolstats1.net ! https://www.urlvoid.com/scan/coolstats1.net/ ! https://www.fortiguard.com/webfilter?q=Coolstats1.net ! https://www.mywot.com/en/scorecard/Coolstats1.net ! https://www.virustotal.com/gui/url/44e1091f194808820ef787750737232f95e7e9ecb17d1605246715645573158e/detection ! https://sitecheck.sucuri.net/results/Coolstats1.net ||coolstats1.net^$all ! https://www.siteadvisor.com/sitereport.html?url=http://ww38.coolstats1.net/?subid1=20210616-0828-13e0-974a-e3edd89fe7ec ! https://www.virustotal.com/gui/url/4b2c524cd265adaccc0bb0a4ec10f84cbb13f1920a9138f12cc7d87c65c5ca63/detection ||ww38.coolstats1.net^$all ! https://cyberwarzone.com/netflix-phishing/ ! https://www.virustotal.com/gui/url/e769d129aec129469cef20339d3b9b88028959ad2eebfb76dc658023add5caad/detection ! https://www.virustotal.com/gui/ip-address/93.157.63.125/detection ! https://www.virustotal.com/gui/url/3555785e02438130d4878766fec548c0923407df295ee66b6e4e11620944b2ba/detection ! Most of these domains were verified, but then my computer crashed so I was forced to copypaste them ! https://securelist.com/browser-lockers-extortion-disguised-as-a-fine/101735/ ! ICOs ||tkkmobileinternetssnstop.ml^$all ! https://securelist.com/convuster-macos-adware-in-rust/101258/ ! https://www.virustotal.com/gui/url/6d390e8cf8b1687cc768c84597848b9276a87b9f43a58658904f9d05b59c75d1/detection ! https://www.virustotal.com/gui/url/b8fcbc42bb2b3bdf4e45653485b04c2fad79182480cb1df150f7d677cf32a2f0/detection ||convstats.com^$document ||post.convstats.com^$all ||update.convstats.com^$all ||trk.convstats.com^$all ! https://www.virustotal.com/gui/url/ce21cbf6e95b06e9bf7a56c9f6f144a2060567acd54fb355ab07a7823a8b4059/detection ! https://www.virustotal.com/gui/url/bcffa58ec980011a0018b9719ffa07aeeea406075c15423b6103b4c070419a09/detection ! https://www.virustotal.com/gui/ip-address/146.112.61.108/relations ! https://www.virustotal.com/gui/url/41f1e06326aa712db385e4c8b16413737c18a2007f0a68f1f602706b29f27ea2/detection ! https://www.virustotal.com/gui/url/ba8c9fcfb3d0ae2d73c02652a5576fcd330c8c1ac9e668d0c01a8ea91bf17584/detection ! https://www.virustotal.com/gui/url/f25e5122f4425bfc759c1400ecd02d43b9fea93284b418eb82cfd5be230aabab/detection ! https://www.virustotal.com/gui/url/af53cde1318036d3ddc8235c472f4f83459998bc5216ec73a56d96a84f897630/detection ! https://www.fortiguard.com/webfilter?q=ibijbdtajblkrwhlzxrttmsmwxxikhjudpty-dot-cryptic-now-290917.ey.r.appspot.com ! https://safeweb.norton.com/report/show?url=ibijbdtajblkrwhlzxrttmsmwxxikhjudpty-dot-cryptic-now-290917.ey.r.appspot.com ! https://www.virustotal.com/gui/url/4680926546c96d50bbacf5da0bcc44d988b9a44ce2fa4633f15ce1012df39aef/detection ||ibijbdtajblkrwhlzxrttmsmwxxikhjudpty-dot-cryptic-now-290917.ey.r.appspot.com^$all ! https://www.virustotal.com/gui/url/2850c0e5cc08937a8ed7fc20f9f867013a8755ece9598335a88b98b469881014/detection ! https://www.virustotal.com/gui/url/84cbb9296da91c1796d4ecdaf6857bb8d216f544ce174f09dc5ad6968f6ffc92/detection ! https://www.virustotal.com/gui/url/df3b3df7c1218253c9cea23ae4aa3ca104b3104a194281270cca4b834e790467/detection ! https://www.pcrisk.com/removal-guides/15423-adf-ly-ads ! https://www.virustotal.com/gui/url/f984d9289494b526bbac5cb57fc5b9edae210a3f980f3d784f6d1fbb80c0bcb5/detection ! https://www.virustotal.com/gui/url/300f1d4d3cf0782f029aec0af02817906ecc57d30a61e78b2c01c8e8b693f5d7/detection ! https://safeweb.norton.com/report/show?url=eyourcom.fun ! https://www.fortiguard.com/webfilter?q=eyourcom.fun ||eyourcom.fun^$all ||xcrke.eyourcom.fun^$all ! https://www.virustotal.com/gui/url/8d91b224b62e8002ab9bfa5314717fc61a2cd2c74e228f26093decdd070bfb0a/detection ! https://safeweb.norton.com/report/show?url=blastnotificationx.com ||blastnotificationx.com^$document ! https://www.virustotal.com/gui/ip-address/54.38.220.85/relations ! https://www.virustotal.com/gui/url/4bdf659c73a47303a64eda32117dad824a5f2ab3f1661e046e049138e7dd0b42/detection ||3phone5.com^$all ! https://www.virustotal.com/gui/url/71f9e1e5965a45d7d8dd89ddf4f6823671187a18981155529bead19c8393e834/detection ! https://www.siteadvisor.com/sitereport.html?url=dm.3phone5.com ! https://sitecheck.sucuri.net/results/dm.3phone5.com ||dm.3phone5.com^$all ! https://twitter.com/PhishStats/status/1406178313517813761 ! https://twitter.com/PhishStats/status/1406132910537723906 ! https://www.siteadvisor.com/sitereport.html?url=145.14.144.143 ||145.14.144.143^$all ! https://www.virustotal.com/gui/url/f645599a31b833dcebbfec890361e28a5fb14ba86e6f730d74688d11cfe7f52f/details ! https://www.joesandbox.com/analysis/436433/0/html#deviceScreen ! https://www.mywot.com/scorecard/googe.com ! https://safeweb.norton.com/reviews?url=googe.com ||googe.com^$all ! https://www.virustotal.com/gui/url/9a34eeed10b62d3aa3698efc8a128e6e87f937982bbcd3d03e50a8ab53b27da9/community ! https://www.mywot.com/scorecard/proasdf.com ! https://safeweb.norton.com/report/show_mobile?name=proasdf.com ||proasdf.com^$document ! https://forum.mywot.com/24626-whatsmyipaddress-com ! https://www.virustotal.com/gui/url/c8bc45a00aeb7be3ccc68a0cf17e4a6175db761393dee57de32a49338b77ca45/detection ! https://www.fortiguard.com/webfilter?q=appple.com&version=8 ||appple.com^$all ||ww1.appple.com^$all ! https://forums.lanik.us/viewtopic.php?f=62&t=42258&p=143707&hilit=malware#p143707 ! https://www.virustotal.com/gui/url/9b0e0440263bd9d0a8825c36edcaab05b32bc76c1bf3bc0b5ce7d5f040c39e32/detection ! https://www.virustotal.com/gui/ip-address/206.189.164.210/detection ||206.189.164.210^$all ! https://blog.sucuri.net/2021/06/wordpress-redirect-hack-via-test0-com-default7-com.html ! https://www.virustotal.com/gui/url/c9e5bfbc2ed8c090d1c10f242b95b3f161464a62ab14a76222b7e092ae0ccd4a/detection ! https://www.siteadvisor.com/sitereport.html?url=default7.com ! https://www.fortiguard.com/webfilter?q=default7.com ! https://safeweb.norton.com/reviews?url=default7.com ! https://safeweb.norton.com/report/show_mobile?name=default7.com ! https://sitecheck.sucuri.net/results/default7.com ! https://labs.sucuri.net/blacklist/info/?domain=default7.com ||default7.com^$all ! https://www.virustotal.com/gui/url/c21021e9e85a89528039106662f8dbd300b45569aa40220bed7e838368db8109/detection ! https://www.fortiguard.com/webfilter?q=test0.com ! https://safeweb.norton.com/report/show?url=test0.com ! https://sitecheck.sucuri.net/results/test0.com ! https://www.virustotal.com/gui/url/bd46f87a24ad03ef262871d19d6e4176c36d2d93591391d0ee16f6ecf9167beb/detection ||test0.com^$all ! https://blog.sucuri.net/2020/11/css-js-steganography-in-fake-flash-player-update-malware.html ! https://www.virustotal.com/gui/url/c042a2c2ed1055cb1f34f7db356d41df148f77b8176307dc86a7d76c683abf14/detection ! https://blog.malwarebytes.com/scams/2021/06/hotel-staff-bust-hermes-sms-scammer-with-suspiciously-large-number-of-cables/ ! https://blog.malwarebytes.com/scams/2021/03/royal-mail-delivery-scam-warning/ ! https://www.virustotal.com/gui/url/9f661c8200bfcc4ac5643c4c8396365dfa2e93d3a293bd5dfdd3f765b0d8e066/detection ! https://www.virustotal.com/gui/url/069eca6eb3e5355c3aaf9fdd3c6f9bdd40b454ff87c1073ca03c9e2fb7bb5908/detection ! https://twitter.com/adamziaja/status/1252234957679808513 ! https://pastebin.com/syLXAS8y ! https://www.virustotal.com/gui/url/7e4c7e29da72ce9b4da17e88b4dcb2e5b759fb360bf35eeb39c54e9a032e638f/detection ! https://blog.sucuri.net/2021/05/woocommerce-credit-card-skimmer.html ! https://blog.sucuri.net/2018/04/malicious-activities-google-tag-manager.html ! https://blog.sucuri.net/2017/09/hacked-websites-mine-crypocurrencies.html ! https://www.virustotal.com/gui/ip-address/34.98.99.30/community ! https://pastebin.com/FzHDkSW7 ! https://www.fortiguard.com/webfilter?q=albumzips.xyz ! https://safeweb.norton.com/report/show?url=albumzips.xyz ! https://sitecheck.sucuri.net/results/albumzips.xyz ! https://www.virustotal.com/gui/url/cd2a97abe31697bf1822c505ee9ad267772463230a943fe3fb680af2ba74b327/detection ||ww16.albumzips.xyz^$all ! https://sitecheck.sucuri.net/results/camillesanz.com ! https://safeweb.norton.com/report/show?url=camillesanz.com ! https://www.virustotal.com/gui/url/f542034f339f53a70bbb0c40a662d49cc37806bc112ef403bac8b4a5d1c02b03/detection ||camillesanz.com^$all ||www.camillesanz.com^$all ! https://labs.sucuri.net/blacklist/details/?domain=africangrey.top ! https://www.virustotal.com/gui/url/d3feabeb546851be8e449074eaddf2c72e687b92754693aba97f3ae27772a796/detection ! https://www.virustotal.com/gui/url/917d555cce2e2e6791704d64812cbb203c57201bac559478c334c74c8e392330/detection ! https://www.siteadvisor.com/sitereport.html?url=ribinski.us ! https://safeweb.norton.com/report/show?url=ribinski.us ! https://sitecheck.sucuri.net/results/ribinski.us ! https://labs.sucuri.net/blacklist/info/?domain=ribinski.us ||ribinski.us^$all ! https://www.virustotal.com/gui/ip-address/176.123.3.85 ||176.123.3.85^$all ! https://twitter.com/gorhill/status/1293239879887970305 ! - via https://github.com/NanoAdblocker/NanoCore/issues/362#issuecomment-704235803 ! https://www.virustotal.com/gui/url/085d0bd9451920bd97eb099fb14e42b8ceccadf79cdf70da0d29e31900262ce1/detection ! https://www.siteadvisor.com/sitereport.html?url=fly-analytics.com ! https://www.fortiguard.com/webfilter?q=fly-analytics.com ! https://safeweb.norton.com/report/show?url=fly-analytics.com ! https://sitecheck.sucuri.net/results/fly-analytics.com ||fly-analytics.com^$all ! https://www.virustotal.com/gui/user/Placebo ! https://www.virustotal.com/gui/file/3ff26dfe049d6ea2d608eaf0914e527a798ae018e3918b9d1f025ca47700cb6f/community ! https://www.virustotal.com/gui/domain/thoughtplus.in/community ! https://www.virustotal.com/gui/url/626f2608d12b9bddc0ac5148b653290b192b45a79db85c7243b04f5374cd3e67/detection ! https://www.siteadvisor.com/sitereport.html?url=thoughtplus.in ! https://www.fortiguard.com/webfilter?q=thoughtplus.in ! https://safeweb.norton.com/report/show?url=thoughtplus.in ! https://sitecheck.sucuri.net/results/thoughtplus.in ! https://transparencyreport.google.com/safe-browsing/search?url=thoughtplus.in ||thoughtplus.in^$all ! https://blog.quttera.com/post/malware-analysis-of-the-infection-injected-via-security-vulnerability-of-tagdiv-themes-and-ultimate-member-plugins/ ! https://www.virustotal.com/gui/url/3191508c3a3f2abf1e7f7ac9c1b48e5bfc0688fa07f3cfcca697c645af883222/detection ! These should help people suffering from malware infections ! https://www.bleepingcomputer.com/virus-removal/how-to-remove-the-pblock-adware-extension ! https://www.virustotal.com/gui/url/ad399479dc38922a7494fc55b183ae9799da64e8cab1a82e563bef4e04ed4596/detection ! https://www.virustotal.com/gui/url/109532c1222eec56a95b7f0bd1b37ed1a1e7b07c4806e614a46e720ef032622e/detection ! https://www.bleepingcomputer.com/virus-removal/remove-toksearches.xyz-search-redirect ! https://www.virustotal.com/gui/url/f6e174e4f27f27f27b5f8c3516fcdbea555d9128d50d6e20f6ca2ca8fbf0d37f/detection ! https://www.fortiguard.com/webfilter?q=toksearches.xyz ||toksearches.xyz^$all ! https://www.bleepingcomputer.com/virus-removal/remove-smashappsearch.com-search-redirect ! https://www.bleepingcomputer.com/virus-removal/remove-smashapps.net-search-redirect ! https://www.bleepingcomputer.com/virus-removal/remove-bipapp-chrome-extension ||smashapps.net^$document ||smashappsearch.com^$document ! https://www.bleepingcomputer.com/virus-removal/remove-please-allow-to-watch-the-video ! https://www.virustotal.com/gui/url/ef88006f1f5beab8ded6b8786870209c1651db831c19e4f49e5ef829c267cac1/detection ! https://www.siteadvisor.com/sitereport.html?url=new-message.live ! https://www.fortiguard.com/webfilter?q=new-message.live ! https://safeweb.norton.com/report/show?url=new-message.live ! https://sitecheck.sucuri.net/results/new-message.live ||new-message.live^$all ! https://www.virustotal.com/gui/url/098cc8fed90c43af3a4afb4df0d7da9c68b1b2c8a3c73fb9d4506c7f062547f1/detection ! https://www.virustotal.com/gui/ip-address/95.168.170.165/relations ! https://www.virustotal.com/gui/url/6a23b2b07941322f9ad5555d97bfd020c2681264d71b5ed6c621f0a6cad6277c/detection ! https://www.fortiguard.com/webfilter?q=private-message.live ! https://safeweb.norton.com/report/show?url=private-message.live ! https://www.mywot.com/scorecard/private-message.live ||private-message.live^$document ! https://blog.malwarebytes.com/a-week-in-security/2021/06/a-week-in-security-june-21-2021-june-27-2021/ ! https://www.virustotal.com/gui/url/d668d18f1cd3b32eea6d717af4655a7e511d5b92403ed71a66d366a4c971c826/detection ! https://therecord.media/dirtymoe-malware-has-infected-more-than-100000-windows-systems/ ! https://decoded.avast.io/martinchlumecky/dirtymoe-1/ ! https://www.siteadvisor.com/sitereport.html?url=1qw.us ! https://www.fortiguard.com/webfilter?q=1qw.us ! https://safeweb.norton.com/report/show?url=1qw.us ! https://www.virustotal.com/gui/url/8e4d54adb8cc9b6fe443f17da6b29ef8e367ca1dacae6ac2cf9b2cc665268bde/detection ||1qw.us^$all ! https://www.siteadvisor.com/sitereport.html?url=rpc.1qw.us ! https://www.fortiguard.com/webfilter?q=rpc.1qw.us ! https://safeweb.norton.com/report/show?url=rpc.1qw.us ! https://www.virustotal.com/gui/domain/rpc.1qw.us/relations ! https://www.virustotal.com/gui/url/f21b269b690aac8338399bb40408aa8cefa3591dcc9a3f84f5a911f647c8d2f7/detection ||rpc.1qw.us^$all ! https://www.proofpoint.com/us/blog/threat-insight/purple-fox-ek-adds-exploits-cve-2020-0674-and-cve-2019-1458-its-arsenal ! https://www.virustotal.com/gui/url/5769102f270c1b16ebdc663ad63010d69de2d159117b3736d562dc59944fc6dc/detection ! https://www.virustotal.com/gui/url/35e34ac62d1ac12fe3146a8a2d6d60300f7a1b97e2922fedb91154243e950cb1/detection ! https://www.virustotal.com/gui/url/e88a950b22a8582a4761c8b6a26546cd7e92b3175c16bd32d1dd8f61f45a1c58/detection ! https://www.virustotal.com/gui/url/2bb2d79e789ba930b36960a8a0fbb008ed5cb594406e89507033832da2668870/detection ! https://www.virustotal.com/gui/url/326384fb6f6e393f8fde813c9cf2be668b68780c0a036d977fc6482fd6364ca1/detection ! ||raw.githack.xyz/SdTC8df7vmDNIUuV1.jpg$all ! https://www.siteadvisor.com/sitereport.html?url=raw.githack.xyz ! https://www.fortiguard.com/webfilter?q=raw.githack.xyz ! https://safeweb.norton.com/report/show?url=raw.githack.xyz ||raw.githack.xyz^$all ! https://blog.malwarebytes.com/a-week-in-security/2021/06/a-week-in-security-june-21-2021-june-27-2021/ ! https://blogs.blackberry.com/en/2021/06/pysa-loves-chachi-a-new-golang-rat ! https://www.virustotal.com/gui/url/13e2efb9c81e4754b593303cff9326c5a529d7728f87f41ac5223b9f966ffd78/detection ! https://www.siteadvisor.com/sitereport.html?url=Englishdialoge.xyz ! https://www.fortiguard.com/webfilter?q=Englishdialoge.xyz ! https://safeweb.norton.com/report/show?url=Englishdialoge.xyz ||englishdialoge.xyz^$all ! https://www.virustotal.com/gui/url/e2fcba9ff22f3b0d82d85265b723af8b9806a6b2e6c9688b3da1878d00035487/detection ! https://www.siteadvisor.com/sitereport.html?url=starhouse.xyz ! https://www.fortiguard.com/webfilter?q=starhouse.xyz ! https://safeweb.norton.com/report/show?url=starhouse.xyz ||starhouse.xyz^$all ! https://www.virustotal.com/gui/url/b54d5c2b204c5ff423dbd76365e1877030f23edfd3f24dff10c25fce3d14669e/detection ! https://www.siteadvisor.com/sitereport.html?url=accounting-consult.xyz ! https://www.fortiguard.com/webfilter?q=accounting-consult.xyz ! https://safeweb.norton.com/report/show?url=accounting-consult.xyz ||accounting-consult.xyz^$all ! https://www.siteadvisor.com/sitereport.html?url=blitzz.best ! https://www.fortiguard.com/webfilter?q=blitzz.best ! https://safeweb.norton.com/report/show?url=blitzz.best ! https://www.virustotal.com/gui/url/add3ef9a51ff4f933bcebde7614d1402468b3794a25e42f5a01c781998bac4d4/detection ||blitzz.best^$all ! https://www.virustotal.com/gui/url/0335a1e7078b1837a6d3ef5945ee1df89ddf62cf70ccd897fb4819b223e857a3/detection ! https://www.virustotal.com/gui/url/e59517dd80595a18a28902afb0b80c53f8928947c018d7c2dcf377cb89993c7c/detection ! https://www.virustotal.com/gui/url/9b9b5c030aeb252c8f0836cda03587bf779b554212fc66b4a54f212f262e3b1b/detection ! https://www.virustotal.com/gui/url/41650b0c0e3dcaf16f8073ba84c43c6b050c37fa6a240b5354e9fb2f23b39ec6/detection ! https://www.virustotal.com/gui/url/fc867fb68e59f6b7c5cabe16117643f8b895d20db5b4b3e69d114d67e3c0fa7e/detection ! https://www.virustotal.com/gui/url/8e6bbd34f515de9309e7f5ea4b3bfdd9d94ce8fb0dd91ea305b2f8abb5b03786/detection ! https://www.siteadvisor.com/sitereport.html?url=firefox-search.xyz ! https://www.fortiguard.com/webfilter?q=firefox-search.xyz ! https://safeweb.norton.com/report/show?url=firefox-search.xyz ||firefox-search.xyz^$all ! https://www.fortinet.com/blog/threat-research/hundreds-of-urls-inside-microsoft-excel-spreads-new-dridex-trojan-variant ! https://www.virustotal.com/gui/url/8f578a02e63f8059f0e113b9a422d2f72b71956e37da9a28622e508cb7a51780/detection ! https://www.virustotal.com/gui/url/cbe2bd4f1b4dd6fe4290edafbee517b5ea0093b6df78dc8227ccf171219c379c/detection ! https://www.siteadvisor.com/sitereport.html?url=bobbydhillonfilmdirector.com ! https://www.fortiguard.com/webfilter?q=bobbydhillonfilmdirector.com ! https://safeweb.norton.com/report/show?url=bobbydhillonfilmdirector.com ! https://sitecheck.sucuri.net/results/bobbydhillonfilmdirector.com ||bobbydhillonfilmdirector.com^$all ! https://www.virustotal.com/gui/url/2b483f0a9b1236313cc8abd969350c485a034bc0a1dfe099f722f53eb75e5d2d/detection ||www.bobbydhillonfilmdirector.com^$all ! https://www.virustotal.com/gui/url/6e77a0ed12e1a70e40df99297aea6af05aea14e0cf7ab930de8658e2e89d99a3/detection ! https://www.virustotal.com/gui/url/924059a7f54b53c67550abfeb493c85a4d29eddd4ff8810dc882918a67b44dbc/detection ! https://www.siteadvisor.com/sitereport.html?url=policelifeline.in ! https://www.fortiguard.com/webfilter?q=policelifeline.in ! https://safeweb.norton.com/report/show?url=policelifeline.in ||policelifeline.in^$all ! https://github.com/hoshsadiq/adblock-nocoin-list/issues/156 ! https://www.virustotal.com/gui/url/2b097e0b8c35294d4f22e514df74b6a23f69eb59bb1cb27486d2f2e0e5f5069d/detection ! https://www.virustotal.com/gui/url/2fb97c9bb91ccad7f3dc95ce6f57be7502172d9ff5a20bd33652bf500a9d06fd/detection ! https://forums.lanik.us/viewtopic.php?f=62&t=38675&p=121250&hilit=malware+website#p121250 ! https://blog.malwarebytes.com/cybercrime/2017/05/roughted-the-anti-ad-blocker-malvertiser/ ! https://www.virustotal.com/gui/url/da83d35f3882838b650fea8062f8ac1234c9c53702f30982fcf112ff49e324c0/detection ! https://www.siteadvisor.com/sitereport.html?url=histock.info ! https://www.mywot.com/en/scorecard/histock.info ! https://safeweb.norton.com/report/show?url=histock.info ||histock.info^$all ! https://sitecheck.sucuri.net/results/histock.info ||ww25.histock.info^$all ! https://www.virustotal.com/gui/url/f7b0aa4bc0b8b5a1c44c5b3bf18d9f32e61e37edb8fa16f3a6efda2d7a69dcb3/detection ! https://www.virustotal.com/gui/url/c73877f794ad788117569f28fb832e10798f79d40d266c2514f118596f5430c7/detection ! https://www.siteadvisor.com/sitereport.html?url=greatwork.info ! https://www.fortiguard.com/webfilter?q=greatwork.info ! https://www.mywot.com/en/scorecard/greatwork.info ! https://safeweb.norton.com/report/show?url=greatwork.info ! https://sitecheck.sucuri.net/results/greatwork.info ||greatwork.info^$all ! https://www.virustotal.com/gui/url/356b0dfe692ed8173dd196949f32232b9d25450cb280eae1bce1cd3a38aaad4c/detection ! https://quttera.com/detailed_report/modescrips.info#ResultInfo ! https://www.fortiguard.com/webfilter?q=modescrips.info ! https://safeweb.norton.com/report/show?url=modescrips.info ! https://sitecheck.sucuri.net/results/modescrips.info ! https://labs.sucuri.net/blacklist/info/?domain=modescrips.info ! https://www.siteadvisor.com/sitereport.html?url=modescrips.info ||modescrips.info^$all ! https://quttera.com/detailed_report/modescrips.info#ResultInfo ! https://www.siteadvisor.com/sitereport.html?url=ww1.modescrips.info ! https://www.virustotal.com/gui/url/517692c8df999a53fa9f1067a130cbeb656b204245b9282de354c0476baca697/detection ||ww1.modescrips.info^$all ! https://www.virustotal.com/gui/user/Site.safetychecker ! https://www.virustotal.com/gui/url/7108cfe6953cab08696ae1f9ab2c777b749fb53e7beb5c003756ea522c880f17/detection ! https://www.siteadvisor.com/sitereport.html?url=yotube.com ! https://www.fortiguard.com/webfilter?q=yotube.com ! https://www.mywot.com/en/scorecard/yotube.com ! https://safeweb.norton.com/reviews?url=yotube.com ! https://sitecheck.sucuri.net/results/yotube.com ||yotube.com^$all ! https://redirectdetective.com ! https://www.virustotal.com/gui/url/82e7188109152e27f51a97c1bcb935a1cc302736ed20a41ababa6d9239c7f85d/community ! https://safeweb.norton.com/report/show?url=gloos-ves.com ||gloos-ves.com^$all ! https://www.virustotal.com/gui/ip-address/54.174.112.67/relations ! https://www.virustotal.com/gui/url/85e357a917a886c9b2791d0c08199c95cd8a50ad003340a8140c04347777ee74/detection ! https://www.fortiguard.com/webfilter?q=zeroredirect1.com ! https://www.mywot.com/en/scorecard/zeroredirect1.com ! https://safeweb.norton.com/reviews?url=zeroredirect1.com ||zeroredirect1.com^$all ! https://www.virustotal.com/gui/domain/zeroredirect1.com/relations ||postback.zeroredirect1.com^$all ||zk6.zeroredirect1.com^$all ||zr.zeroredirect1.com^$all ||zm1.zeroredirect1.com^$all ||zp.zeroredirect1.com^$all ||zt.zeroredirect1.com^$all ||zx.zeroredirect1.com^$all ||ns2.zeroredirect1.com^$all ||m.zeroredirect1.com^$all ||z2.zeroredirect1.com^$all ||zh1.zeroredirect1.com^$all ||zl.zeroredirect1.com^$all ||fw.zeroredirect1.com^$all ||de.zeroredirect1.com^$all ||tools.zeroredirect1.com^$all ||sslvpn.zeroredirect1.com^$all ||s.zeroredirect1.com^$all ||root.zeroredirect1.com^$all ||r.zeroredirect1.com^$all ||q.zeroredirect1.com^$all ||pop3.zeroredirect1.com^$all ||p.zeroredirect1.com^$all ||news.zeroredirect1.com^$all ||new.zeroredirect1.com^$all ||mta-sts.zeroredirect1.com^$all ||mx.zeroredirect1.com^$all ||mdm.zeroredirect1.com^$all ||mail.zeroredirect1.com^$all ||liveupdate.zeroredirect1.com^$all ||l.zeroredirect1.com^$all ! https://www.virustotal.com/gui/ip-address/54.174.112.67/relations ! https://www.virustotal.com/gui/url/3979fe45b8b11e752ccf2728af479fa88a9898abfd5928052205c14d404b2a45/detection ! 31/1/2023: https://www.virustotal.com/gui/url/12bcc81f9b37207bbdf0bb8bc5a5c5c9e1202cc5cdc90b3916484623127d0671/community ! (my analysis) NSFW: https://app.any.run/tasks/591ba0ed-d373-46b3-950a-2b3d0a364064 ! https://duckduckgo.com/?q=url+shortener+free&ia=web ! https://www.virustotal.com/gui/url/5dddae1ba462c1db7091185cca5d502681f2e97524278a86a297a14ee878bebc/detection ! https://www.siteadvisor.com/sitereport.html?url=f.ls ! https://www.fortiguard.com/webfilter?q=f.ls ! https://safeweb.norton.com/report/show?url=https%3A%2F%2Ff.ls%2F ||f.ls^$all ! https://www.virustotal.com/gui/url/1da28265a996329b5bfce00b2aae8222d55db3f2ed81dccd789ebdeddd2dfc7d/detection ! https://www.virustotal.com/gui/url/d4bd72283480a00bdabbcc5f35234506988584de62ec047f4ce14059811b160f/detection ! https://www.mywot.com/scorecard/itsssl.com ! https://safeweb.norton.com/report/show?url=itsssl.com ! https://sitereport.netcraft.com/?url=https://itsssl.com/ ! https://www.fortiguard.com/webfilter?q=itsssl.com ||itsssl.com^$document ! https://www.bleepingcomputer.com/news/security/trickbot-cybercrime-group-linked-to-new-diavol-ransomware/ ! https://www.fortinet.com/blog/threat-research/diavol-new-ransomware-used-by-wizard-spider ! https://www.virustotal.com/gui/url/70161337eef45e521fb05e1b4288bde5f7486a09ebfd6153236ca79a63d478e8/detection ! https://www.virustotal.com/gui/ip-address/173.232.146.118/detection ! https://www.siteadvisor.com/sitereport.html?url=173.232.146.118 ! https://www.fortiguard.com/webfilter?q=173.232.146.118 ! https://safeweb.norton.com/report/show?url=173.232.146.118 ||173.232.146.118^$all ! https://www.fortinet.com/blog/threat-research/spear-phishing-campaign-with-new-techniques-aimed-at-aviation-companies ! https://www.virustotal.com/gui/file/adf94da54bc49abc6fdb2a36523eb726f26dacd5598a0fdc64e61b8d500edad8/relations ! https://www.virustotal.com/gui/url/61d8c9ffda3a8dc704bf032b57d921b82b676d562e5c2a12796ead92c3d3c428/detection ! https://www.siteadvisor.com/sitereport.html?url=shugardaddy.ddns.net ! https://www.fortiguard.com/webfilter?q=shugardaddy.ddns.net ! https://safeweb.norton.com/report/show?url=shugardaddy.ddns.net ||shugardaddy.ddns.net^$all ! https://www.virustotal.com/gui/url/237fb4d91d9afb15853f66efb01ca0930b69678fdccb787ebb3f59da65c0cf7c/detection ! https://www.siteadvisor.com/sitereport.html?url=79.134.225.18 ! https://www.fortiguard.com/webfilter?q=79.134.225.18 ! https://safeweb.norton.com/report/show?url=79.134.225.18 ||79.134.225.18^$all ! https://www.virustotal.com/gui/ip-address/79.134.225.18/relations ! https://www.virustotal.com/gui/url/6c92f5a89b5307a36688b9e4eda3da98c75ca2ee5b67a278c3b00bc95d4de15b/detection ! https://www.bleepingcomputer.com/virus-removal/remove-power-app-chrome-extension ! https://www.virustotal.com/gui/url/6dd9e3edd772497d3db7f61fa0cbd6b81b888dc1e01f95c693edfb3e696b702e/detection ! https://www.fortiguard.com/webfilter?q=searchpowerapp.com ! https://safeweb.norton.com/report/show?url=searchpowerapp.com ||searchpowerapp.com^$document ! https://www.virustotal.com/gui/url/4cb33835d45743431d20b4c019e09dd1861953440572bf40dd4b2745cb391082/detection ! https://www.fortiguard.com/webfilter?q=lp.searchdimension.com ! https://safeweb.norton.com/report/show?url=lp.searchdimension.com ! https://www.mywot.com/en/scorecard/lp.searchdimension.com ||lp.searchdimension.com^$all ! https://www.virustotal.com/gui/url/ac7e2f7f5557d6cac58a5250eedb78e5a647b5be6814d595df6b84bf9687e934/detection ! https://www.fortiguard.com/webfilter?q=searchdimension.com ! https://www.mywot.com/en/scorecard/searchdimension.com ! https://safeweb.norton.com/report/show?url=searchdimension.com ||searchdimension.com^$document ! https://blog.malwarebytes.com/exploits-and-vulnerabilities/2020/04/copycat-criminals-abuse-malwarebytes-brand-in-malvertising-campaign/ ! https://www.virustotal.com/gui/url/8faba8050b38887c13c044743c789d9a8e1795098b2c20250bfae80f5d1d2a4f/detection ! https://www.fortiguard.com/webfilter?q=malwarebytes-free.com ! https://safeweb.norton.com/report/show?url=malwarebytes-free.com ||malwarebytes-free.com^$all ! https://www.virustotal.com/gui/url/271b3785c7ce8705bb873432544b23936e0d2cab80a0408676028b174b584335/detection ! https://www.virustotal.com/gui/ip-address/134.209.86.129 ! https://www.siteadvisor.com/sitereport.html?url=134.209.86.129 ! https://www.fortiguard.com/webfilter?q=134.209.86.129 ! https://safeweb.norton.com/report/show?url=134.209.86.129 ||134.209.86.129^$all ! https://www.virustotal.com/gui/url/c9f11efd638bd9e079f5eb4a0f4a7cd78023115b98909eb59745a91be65b6449/detection ! https://www.virustotal.com/gui/ip-address/34.89.159.33/detection ! https://www.siteadvisor.com/sitereport.html?url=34.89.159.33 ! https://safeweb.norton.com/report/show?url=34.89.159.33 ||34.89.159.33^$all ! https://www.virustotal.com/gui/domain/google.com/relations ! https://www.virustotal.com/gui/file/b9e71672b1be619c6a26ee5e6e6d6b5ff96ba6192c8741d02ca049d863ba99d4/relations ! https://www.virustotal.com/gui/url/04c53464cbd4dcf8c037b7e430ec620cab5d832df7ef7ce2bf17f5d903d61fea/detection ! https://www.siteadvisor.com/sitereport.html?url=stromoliks.com ! https://www.fortiguard.com/webfilter?q=stromoliks.com ! https://safeweb.norton.com/report/show?url=stromoliks.com ||stromoliks.com^$all ! https://us-cert.cisa.gov/ncas/alerts/aa21-148a ! https://www.virustotal.com/gui/url/6042880d2adcad721d166f7bdac731bd1f953884cc94c72cf084456a1a040d88/detection ! https://www.virustotal.com/gui/url/af657a732699aa8b956f760806722522eed6a384fe93f64fdf3e29defd458502/detection ||cdn.theyardservice.com^$all ! https://www.virustotal.com/gui/url/bb7652b7686cd4c9ac1448a86ea65e3451b3b74ae8184a389cb1761aabd79771/detection ! https://www.joesandbox.com/analysis/441367/0/html ! https://www.virustotal.com/gui/ip-address/192.99.221.77/detection ! https://www.virustotal.com/gui/url/5d424847f1cdd6349105005a336a107aca8f11fd32cecf41bc9bd8f78dc1e3bb/detection ! https://www.siteadvisor.com/sitereport.html?url=192.99.221.77 ! https://www.fortiguard.com/webfilter?q=192.99.221.77 ! https://safeweb.norton.com/report/show?url=192.99.221.77 ||192.99.221.77^$all ! https://www.youtube.com/watch?v=MxKCz0NMb2o ! https://www.virustotal.com/gui/url/a4744e87f6e9061558e94b40bc073f6a1335f7f3e0f430eadc02fcfa1bbdd069/detection ! https://www.siteadvisor.com/sitereport.html?url=contirecovery.info ! https://www.fortiguard.com/webfilter?q=contirecovery.info ! https://safeweb.norton.com/report/show?url=contirecovery.info ||contirecovery.info^$all ! https://us-cert.cisa.gov/sites/default/files/publications/AA21-131A.stix.xml ! https://www.virustotal.com/gui/url/39931bba2be7fce4c7537ea23784e88974f7e822cbfc9d5b6c8633821c9c7011/detection ! https://www.virustotal.com/gui/ip-address/185.243.214.107/detection ! https://www.siteadvisor.com/sitereport.html?url=185.243.214.107 ! https://www.fortiguard.com/webfilter?q=185.243.214.107 ! https://safeweb.norton.com/report/show?url=185.243.214.107 ||185.243.214.107^$all ! https://www.virustotal.com/gui/file/2b214bddaab130c274de6204af6dba5aeec7433da99aa950022fa306421a6d32/relations ! https://www.virustotal.com/gui/url/55ece17a8cc64a501795d24f1a7a309fda60be834370e8fdd50701dcf9582ca1/detection ! https://www.virustotal.com/gui/url/e02a4395d80bfbad41e06c0a1700ecf960f894037a68ba0d15ec80631ed697f4/detection ! https://www.virustotal.com/gui/file/0a0c225f0e5ee941a79f2b7701f1285e4975a2859eb4d025d96d9e366e81abb9/community ! https://www.joesandbox.com/analysis/393833/0/html#deviceScreen ! https://www.virustotal.com/gui/url/ae5a16e96446efbd95af18cfa127779137b32587752172c98c86d19eba2974ed/detection ! https://www.virustotal.com/gui/url/f1599e930e3da28e26fd5e26b89099eabd5bc708c30a47e84b8fc5fe2cbbf0e2/detection ! https://www.virustotal.com/gui/domain/softpussyx.us/relations ! https://www.virustotal.com/gui/ip-address/162.0.209.79/relations ! https://www.virustotal.com/gui/url/342c830002dc55939bf4ea95f1344222d248d077678da0875cb847af1fe7b9c8/detection ! https://www.virustotal.com/gui/url/486e02872948b4d18c14384d7f5fdaae50707975625db26f17cfae7475945f37/detection ! https://report.netcraft.com/submission/33GfNjGY7TOhkJmC5VZ5OkAOJHcRz5IJ ! https://www.virustotal.com/gui/url/18544ab527a827c405b06dd2470eb4122b14924c4cd21ba6a191c178912290f3/detection ! https://www.virustotal.com/gui/url/ac2e0ddf46bcbcb9b8d6051c5221bc9dca994b90cfd773c9edeb5a58469d6a6f/detection ! https://www.virustotal.com/gui/url/bb22b73d6ae8d7688193e17b92aa0d5b05e3e6e321eeefa7f6d561b50375cf93/detection ! https://www.virustotal.com/gui/url/2d4ece17204745fc52f9b9d8641854b4222882960577dc5d1d606d097d9c60e2/detection ! https://www.youtube.com/watch?v=J_bHM1NkoHs ! https://www.virustotal.com/gui/url/97f147e5e83ba58c300c4d559e429f45752965a364c88bc8c080dd81db1f5188/detection ! https://forums.malwarebytes.com/topic/276364-please-help-to-remove-jingermycom/ ! https://www.virustotal.com/gui/url/5538837550b6bf93ad0fd8be30a9061d43b8f2097dcdfb6a7d959eaebf6b92f1/detection ! https://www.fortiguard.com/webfilter?q=jingermy.com ! https://safeweb.norton.com/report/show?url=jingermy.com ||jingermy.com^$all ! https://www.virustotal.com/gui/user/joesecurity/comments ! https://www.virustotal.com/gui/file/31422b061307e009869a40d0a36aeb3a19e20a45d80ef1ce245ad0bd7267af14/relations ! https://www.virustotal.com/gui/url/435165312ee2ef983b6f08359589fb753bcb6eb72bb2ce8c0b21f16279cc80fe/detection ! https://www.virustotal.com/gui/url/8b5f51015dbd8a58c75323013ea6a85d7f78c5fabadae55c96889f563c23e8ff/detection ! https://www.virustotal.com/gui/ip-address/5.39.221.61 ||5.39.221.61^$all ! https://www.virustotal.com/gui/url/48a9e88e0b6cf59fac14588d252d9bb6b936ec2fd847e832d17fdb76322b35d3/detection ! https://www.virustotal.com/gui/file/e66db6f687eacf9852542ab583f4d77191965f3a8d6c2e726f4e6b8b83b4f390/detection ! https://www.virustotal.com/gui/file/93f1afd730eb30421d8e7cae9fc79cbee918c4b0a75d68bf64d34d2cc99d29f0/detection ! To remove, run ADWCleaner (https://malwarebytes.com/adwcleaner) and follow instructions. ||speedupmypcfree.com^$all ! https://www.virustotal.com/gui/domain/speedupmypcfree.com/relations ||mail.speedupmypcfree.com^$all ||www.speedupmypcfree.com^$all ||ftp.speedupmypcfree.com^$all ! https://www.virustotal.com/gui/file/f6a03d67c52f6d431a7500e311b09edc8835d0cae6414e09b884fdab6e608e2b/relations ! https://www.virustotal.com/gui/url/46e095c35d83e2dd0b98df4b5844d3d87948de0c930a618600121020a514c801/detection ! https://www.virustotal.com/gui/ip-address/195.201.225.248 ! https://www.virustotal.com/gui/url/e1593682978e71427f16d49523e962f2ab847341ff7cf4d0d741328b73f05ba7/detection ! https://www.siteadvisor.com/sitereport.html?url=195.201.225.248 ! https://safeweb.norton.com/report/show?url=195.201.225.248 ! https://www.fortiguard.com/webfilter?q=+195.201.225.248+&version=8 ||195.201.225.248^$all ! https://www.joesandbox.com/analysis/450654/0/html#deviceScreen ||pcclcc.knorish.com^$all ! Pretends to be a OneDrive sign in ! https://www.virustotal.com/gui/url/6564216874ea790aa743fcaae6da965d7d29900e4eae051f973888f1cd24169c/detection ! Domains found by @DandelionSprout ! https://github.com/DandelionSprout/adfilt/issues/224 ||69.49.231.244^$document ! https://github.com/TheAntiSocialEngineer/AntiSocial-BlockList-UK-Community/commit/9cd756bac651f66e5f3c63cf7ceea703db968997 ! https://www.virustotal.com/gui/url/ee0706bc3eef3eaf9d6d7d2155100d8d051dfdb61588afcd7f5f74c313ce4a21/detection ! https://www.virustotal.com/gui/user/VMRay/comments ! https://www.virustotal.com/gui/file/41b25eac5234d09d70dbcd3830a098c1b25828cfb70990e2938ebf99d31f796f/relations ! https://www.virustotal.com/gui/file/e5a2f1f92189919272d6a14bbd16934ee66464a6cb90f30f00abaf0a204e4307/relations ! https://www.virustotal.com/gui/url/e942c0dcfd4c35ead2b75de05dd80928d4189118a0fe001b685d9cca62e28a1d/detection ! https://www.virustotal.com/gui/url/2c44be10bb8d858bf74b57a285f21a213dfe3b0fd17b395ccc776ee751f54f28/detection ! https://www.virustotal.com/gui/url/16cce3ab323b58c6783f7c6eee8416c5a35f3322114a4c517076fa7ab3496685/detection ! https://www.virustotal.com/gui/ip-address/136.144.41.201/detection ! https://www.virustotal.com/gui/url/09b318a17f3ba7a4729b2bcd0b8ba02b8003693e7051097797fbc52194925e76/detection ! https://safeweb.norton.com/report/show?url=136.144.41.201 ! https://www.siteadvisor.com/sitereport.html?url=136.144.41.201 ||136.144.41.201^$all ! https://www.joesandbox.com/analysis/450822/0/html ! https://www.virustotal.com/gui/url/afdc435d6d937b8d2f6049e9a75df5a8bb1fae6a66bffa19d53b61358d8a6547/community ! Looks like https://www.joesandbox.com/analysis/450654/0/html#deviceScreen ||accessoffice365.knorish.com^$all ||00ffice354.weebly.com^$all ! https://thehackernews.com/2021/07/hackers-spread-biopass-malware-via.html ! https://www.virustotal.com/gui/url/97b4ed1e2788217aa186f26dbdd13a36544dde101e53ea3382e6a5aa1b9f4081/detection ! https://www.virustotal.com/gui/ip-address/47.57.140.149/relations ! https://www.virustotal.com/gui/url/0025d5ba5569ba2ecc29c39236a9b559a212e3ac7404b9af7be62e143175cf5f/detection ! https://www.virustotal.com/gui/url/94a7b6d048720fe4e837d6027f5019c775d20e5ea761ad03236f85070f08838a/detection ! https://www.virustotal.com/gui/url/ade8073339365eed03d142d5e57ec528d54294c40fdac08e71d5363d3ba634d0/detection ||update.flash-installer.com^$all ! https://www.virustotal.com/gui/url/98962a3086cc694e1d62667a718edd6738b233b2b348b1197c141a8ecb251336/detection ||flash-installer.com^$all ! The only domains resolving to this are malware ||47.57.140.149^$document ! https://www.virustotal.com/gui/url/7b54d6ca41a6a7483987a19ebbbe072741f69eec54d93d60e936016610e4b250/detection ! Redirect via JS ! https://www.virustotal.com/gui/url/b1ec498336a80fcdfea88ea278b8df0ceb769e0600eae7b6f3253811c8cab8ac/detection ||goetm1.com.ar^$all ! Redirect from above ! https://www.virustotal.com/gui/url/56946c6bee1518cc6fd3811c6acc142051a5c5c7cbe4001be41a0c6a0395e39b/community ! https://www.mywot.com/scorecard/2m.ma ||2m.ma^$all ! https://www.virustotal.com/gui/file/4bf58623f91ff9a19c2893061a2a14660f61b2294f976a9d80ab6b3d023c9892/relations ! https://www.virustotal.com/gui/url/a21f89ebf6c4835a504a92359d23be518b80b9b7bd5417541087d60751d41694/detection ||paymetconfirm.com^$all ! https://www.virustotal.com/gui/file/309aa6af647b1267fef90257e69cfe6be01ed03d3bbcc512dba951bbf4056916/relations ! https://safeweb.norton.com/report/show?url=212.224.105.115 ! https://www.virustotal.com/gui/url/1df63f1b4325377d41be2aa4c70de3a690f7fe6148d0892a4b3b8197ba8ea08d/detection ! https://www.siteadvisor.com/sitereport.html?url=212.224.105.115 ||212.224.105.115^$all ! https://www.virustotal.com/gui/file/84904a91de28f8aff1863d9831dddea0110e94761287579926e843b1b4046608/relations ! https://www.virustotal.com/gui/file/062f2b4bd4a156914319ca2dc069e37920a5abde742103a41736ceaf56b6fcc7/relations ! https://www.virustotal.com/gui/url/d856e86a99691541893c6f94fa8c9d775d845e24ee4f83d010219168c65fab53/detection ! https://www.virustotal.com/gui/url/05d2b17b5cd77143d45fd292ad7fd3f1b3830d3298ee047fac4b4f9a9968c657/detection ! https://www.virustotal.com/gui/ip-address/185.117.90.215/relations ! https://safeweb.norton.com/report/show?url=185.117.90.215 ||185.117.90.215^$all ! https://www.virustotal.com/gui/file/47f31bc89c7581bb0483e01e15695e1f75ee4236f00142ff720f8f8138fb93eb/relations ! https://www.virustotal.com/gui/url/52c420d6a1da7f3460e5ec35aaf0f3d4f6963eb18868f81f01dbc06b814d9db9/detection ! https://www.siteadvisor.com/sitereport.html?url=154.35.32.5 ||154.35.32.5^$all ! https://www.virustotal.com/gui/file/864b531c5f5a397b3fd2a8aa91c83f956d93300db9c986bfa7ae4744d7cb732f/relations ! https://www.virustotal.com/gui/url/289225adb72bcc214c68160e2c756201cd74db997847b186f6c5a7bdfb7b1866/detection ||185.140.53.11^$all ! https://www.virustotal.com/gui/file/004068094b6adb0e6548b6334afd2dad79312f09e94e04a1d1206874028bdda0/community ! https://www.joesandbox.com/analysis/452771/0/html#domains ! https://sitecheck.sucuri.net/results/joeboiden.com ! https://www.virustotal.com/gui/url/3a15526b6e2391894cebdf79cc481155db6adc0f1c9922418367807398b65d27/detection ! https://www.siteadvisor.com/sitereport.html?url=survey-smiles.com ! https://safeweb.norton.com/report/show?url=survey-smiles.com ! https://safeweb.norton.com/reviews/382019 ||survey-smiles.com^$all ||www.joeboiden.com^$all ! https://www.virustotal.com/gui/url/91e3902494c239a8bc784fd13d2cb4cb2815688ddd4cd18a2aa705cde09afc46/community ! https://www.virustotal.com/gui/url/0d2843d2d439d0ba2694beba2513049c4a34b1ee45c4dd35823815ea03eaa11b/detection ||119.36.68.244^$all ! https://www.bleepingcomputer.com/news/security/microsoft-seo-poisoning-used-to-backdoor-targets-with-malware/ ! https://www.bleepingcomputer.com/news/security/new-jupyter-malware-steals-browser-data-opens-backdoor/ ! https://www.virustotal.com/gui/url/69b746bae9b855c6b113247709b47d57f69682b36f6a7c2202910f1f14d147d7/detection ! https://safeweb.norton.com/report/show?url=45.146.165.222 ! https://www.siteadvisor.com/sitereport.html?url=45.146.165.222 ||45.146.165.222^$all ! https://windowsreport.com/extend-windows-laptop-battery-life/ ! https://www.hybrid-analysis.com/sample/0dd66edadbe93df04f6759e5549d3e76b5bfcb292ba6f6a6139903dd705ced6a ! Tested on VM: Removed by ADWCleaner ! Switched to document as per https://github.com/uBlockOrigin/uAssets/issues/9974 ||driverfix.com^$all ||www.driverfix.com^$all ! Tech support scammers ! https://www.youtube.com/watch?v=Ooh6bV8FwTo ! https://www.virustotal.com/gui/url/02071a7a5b71526d41e0f4547b4912368ee6a0920e7d7aaade16fd3f5ca01a87/detection ! https://safeweb.norton.com/report/show?url=systemini-com.tk ||systemini-com.tk^$all ! https://www.virustotal.com/gui/url/fb85efbc7bf81b10869ddaddd9b3b9471a916b9f8d820d2ccee48712c3e58b9e/detection ! https://www.siteadvisor.com/sitereport.html?url=micropcsupport.com ||micropcsupport.com^$all ! https://www.joesandbox.com/analysis/453639/0/html#domains ! https://www.virustotal.com/gui/url/46e095c35d83e2dd0b98df4b5844d3d87948de0c930a618600121020a514c801/detection ! https://www.virustotal.com/gui/file/17a4af006da6a025094e31bfdee13e3b2123a746d97c8c4958570f1fb9e79e3c/relations ! https://www.virustotal.com/gui/url/f20f83d77c11b8ccda12dc3e08b034104af3417cac8e31b1d8b78f492deed25d/detection ||cjto.top^$all ! https://www.virustotal.com/gui/ip-address/151.139.128.14/community ! https://www.virustotal.com/gui/url/bfe18865078c79597f2d59ae50e34477f7731e6de9c8b997dae8d363cb8d4f58/detection ||151.139.128.14^$all ! https://blog.virustotal.com/2021/05/compliant-easy-and-actionable.html ! https://www.virustotal.com/ui/widget/demo/dedicated?full=1 ! https://www.virustotal.com/gui/url/fe8935d58ff55f012e0f9d1ec7b3d087f3f7a8b0087ba8ee00895a9f7b6d3114/detection ! https://www.siteadvisor.com/sitereport.html?url=audit-citoyen.org ! https://safeweb.norton.com/report/show?url=audit-citoyen.org ||audit-citoyen.org^$all ! https://www.virustotal.com/gui/url/da7df013ab885111468928c4b3bc207d2997fd3250a7c535303cb6488f78a583/detection ! https://www.siteadvisor.com/sitereport.html?url=hg2875.com ! https://safeweb.norton.com/report/show?url=hg2875.com ! https://www.virustotal.com/gui/url/440e9f698d5ec2be4832c54c0b37c4bff775b29dba8b89e98fcb70eb679410b1/detection ||hg2875.com^$all ! https://www.virustotal.com/gui/file/3f4a6504fe8dc05ff75fe4a3bdf27eb509b2431ebaf4e189c23b9297ea300f19/relations ! https://www.virustotal.com/gui/url/5bd7df6a4ee62d8ad59e6968efa9b3bb13cdf4a1b939a6841cbc05bc6317d1c7/detection ||185.252.144.65^$all ! https://www.virustotal.com/gui/url/715cfdc439d0cee9bdba44ab697c886028a0ddcaffaed3e241b95e0fcc54e17e/detection ! https://www.siteadvisor.com/sitereport.html?url=scrawny-unleashed-kite.glitch.me ||scrawny-unleashed-kite.glitch.me^$all ! https://www.virustotal.com/gui/url/42cc97a22c7bc39d31bd6a2e14992cf5fd9f640b2d1f887b5c4c07df5fa78fb3/detection ! https://www.siteadvisor.com/sitereport.html?url=125.45.67.35 ! https://safeweb.norton.com/report/show?url=125.45.67.35 ||125.45.67.35^$all ! Browser locker ! https://www.virustotal.com/gui/url/44f957f9350dfc3d9b8ccac23074301c3c20278a787af25a28edd8e15eacb7e1/detection ! https://github.com/DandelionSprout/adfilt/issues/228 ||helooworld.us^$all ! Which redirects to ! Related ||www.helooworld.us^$all ! https://www.virustotal.com/gui/file/081618f7d9c6c92271f8d6bc65c8e13f33dfe9e5022f06aaec95664ee31fead4/relations ! https://www.virustotal.com/gui/url/efc1177d474e3efe2e9e53fcfbb012c9ae86f64467e38824f6d974d5504647f0/detection ||properlysolutionsco.com^$all ! https://www.virustotal.com/gui/url/6b2338518e68612db03784b14220013e5de2062f6bd6aa4fb7f38fe94dab2b4f/detection ! https://www.virustotal.com/gui/url/cfb47cf40734458f67af9647269065856b3995bc990197c74bb015673c864213/detection ! https://www.virustotal.com/gui/url/270da35e4e24cdca72d7391886bdb7eae2d0758923b397f09558ea42402465a3/detection ! https://www.siteadvisor.com/sitereport.html?url=58.248.145.193 ||58.248.145.193^$all ! https://www.virustotal.com/gui/file/6f236e253720a0b3cf1fdafd111f99ba84e0a2b03ff8453fd747c3d9c8973403/relations ! https://www.virustotal.com/gui/file/13e8d4557870179e70b7d4f580c9183e9a6eead777af04fc226feb70d9ce76cb/relations ! https://www.virustotal.com/gui/url/e3fb5d2d13d34c94468df0ecd5825ed28861ccee9f1a1703e4b37a01af2f7caf/detection ! https://safeweb.norton.com/report/show?url=os.telechargercdn.com ! https://www.siteadvisor.com/sitereport.html?url=os.telechargercdn.com ||os.telechargercdn.com^$all ! https://www.virustotal.com/gui/file/aee59b3208def311e9fd082182c861f9b57d73f1535905675e73bc6ceadcee2f/relations ! https://www.virustotal.com/gui/url/9f925644f317b588502dc8b781df9c45fcf062ea3ea9b3d444320f7697b36d79/detection ||readinglistforjuly7.xyz^$all ! https://www.virustotal.com/gui/url/5d7515deba91f7594ce6b6d2f644b134675d3f52b3d45da5b98f8d4d32f567d8/detection ||readinglistforjuly5.xyz^$all ! https://www.virustotal.com/gui/url/a2e3ede6e9eabf470922006ea15b89cadb0de1d6ab2524d612512f3a2c7edc64/detection ||readinglistforjuly6.xyz^$all ! https://safeweb.norton.com/report/show?url=147.124.222.75 ! https://www.siteadvisor.com/sitereport.html?url=147.124.222.75 ! https://www.virustotal.com/gui/url/1bc893616784fc8861d2f34f95955030501b846e7edf812b20d5643359c3e0fd/detection ||147.124.222.75^$all ! https://www.virustotal.com/gui/url/951fedc69389911352a4c1e5af2cbaa2d7a3b3ea45d3f99b8b2dfa9438835ec9/detection ! https://safeweb.norton.com/report/show_mobile?name=boisehosting.net ||boisehosting.net^$all ! https://www.virustotal.com/gui/file/ad5711a5bdcd7c6334389a2ed722e16e774d8f55737e85f57c71ec3e1767c63b/community ! https://www.virustotal.com/gui/url/8fafebe74722ddcd491955fe5ce5383afdb38b1f1cabfad67cf900ae86b018c6/detection ! https://safeweb.norton.com/report/show_mobile?name=google.vrthcobj.com ! https://www.siteadvisor.com/sitereport.html?url=google.vrthcobj.com ||google.vrthcobj.com^$all ! https://safeweb.norton.com/report/show_mobile?name=vrthcobj.com ! https://www.virustotal.com/gui/url/605fd458fa4574953741b5e07c05c5c54d1086ed3a6b824f8a0d963e8d5bca67/detection ||vrthcobj.com^$all ! https://www.virustotal.com/gui/file/1c65db2ba951b557c38be3177040b36f25a7f586dbabe2f62ff1383e95c450ec/community ! https://www.virustotal.com/gui/url/df09fdfc84be999d37697390c655524025e4b336d5f0c1a1e54fe03723d36139/detection ! https://www.virustotal.com/gui/url/167df4bcf9c96b4f36ff3f50f8c844b47919c3e1360cae001d36966c53d434aa/detection ! https://safeweb.norton.com/report/show?url=192.3.13.125 ! https://safeweb.norton.com/report/show?url=http%3A%2F%2F192.3.13.125%2Fgood%2Fman.exe ||192.3.13.125^$all ! https://www.virustotal.com/gui/file/57c3f64c41b69f6888aa3b92ad1c60800ea22200da375aafab7114d338893dd3/community ! https://www.virustotal.com/gui/url/6131304698e9cc7f3f976ba6bfea7a981ca06ced4a8f444d767feb5d544d75e4/detection ! https://safeweb.norton.com/report/show?url=files6.uludagbilisim.com ! https://www.siteadvisor.com/sitereport.html?url=files6.uludagbilisim.com ! https://www.virustotal.com/gui/url/d4ded6d14586e4e6e2ab4f8441ae8e5f165bad1413ddc2a6d7aa8d2aba6dbef7/detection ||files6.uludagbilisim.com^$all ! vxvault.net/ViriFiche.php?ID=43976 ! https://www.virustotal.com/gui/url/e459ee048862cee8c4fd7da28954ca3a5a5e1f11d15e665cf5cb5a6d87de5894/detection ! https://www.virustotal.com/gui/ip-address/91.142.79.180/relations ||91.142.79.180^$all ! https://www.virustotal.com/gui/url/341e91db02aea79d065bcd25c005e885e6914a584365b70d1108bbdbb68d75ac/detection ! https://safeweb.norton.com/report/show?url=ozentekstil.com ||ozentekstil.com^$all ! https://www.virustotal.com/gui/url/2af624e114a93afeee7d5e02933dacffe3d489a08d0d90832599997b853f3baa/detection ! https://safeweb.norton.com/report/show?url=lahuertasonora.com ||lahuertasonora.com^$all ! https://www.siteadvisor.com/sitereport.html?url=twcamel.com ! https://www.virustotal.com/gui/url/096f7689e6c594d5a1ec9d9a28d4f022d7ea584ca59541d2b6f9122ba8fd7e2b/detection ! https://safeweb.norton.com/report/show?url=twcamel.com ||twcamel.com^$all ! https://www.siteadvisor.com/sitereport.html?url=yzsnw.com ! https://safeweb.norton.com/report/show?url=yzsnw.com ! https://www.virustotal.com/gui/url/2b5268d891356461634f1a1cc0a398999b356b870bbe6b89313a5c9810a67c07/detection ||yzsnw.com^$all ! https://www.joesandbox.com/analysis/459765/0/html#deviceScreen ! https://www.virustotal.com/gui/url/2e6294697acd8c372b42422a23d1a50a7cddb5946adfbbffc6ba2568eb4c3bd2/detection ! https://www.virustotal.com/gui/url/9642e40be4e613689925fc9ec7aad07e1560bdd88b59bcbb7bdbfeda7371c482/detection ! https://safeweb.norton.com/report/show?url=domainvalidation.cabanova.com ||domainvalidation.cabanova.com^$all ! https://www.joesandbox.com/analysis/459760/0/html#deviceScreen ! https://www.virustotal.com/gui/url/b40942e5a79b5adf46540791136aeca70747b5996fd4af87adfd7896b536c551/detection ! https://www.virustotal.com/gui/url/2abd4d921f804921d7ae4bd4a0c4e15021a2c2e7b602487ca5ebc6e8e94f5e7d/detection ||540430.selcdn.ru^$all ! Other subdomains ! https://www.virustotal.com/gui/url/c62ca486047c55f19a07721d648291d352c6e53f7a8dee5c7dbefa4e5f34fd39/detection ! https://safeweb.norton.com/report/show?url=576420.selcdn.ru ||576420.selcdn.ru^$all ! https://www.virustotal.com/gui/url/1da1642cb0fd779e372242483a4b551eaaf347076535c53e2e38c155cf0b2357/detection ! https://safeweb.norton.com/report/show?url=536930.selcdn.ru ||536930.selcdn.ru^$all ! https://safeweb.norton.com/report/show?url=575031.selcdn.ru ! https://www.virustotal.com/gui/url/17c88f52480b17fa36e2dcc170d3a0c13ed88089a37682fbc125edf5e417940d/detection ||575031.selcdn.ru^$all ! https://www.virustotal.com/gui/url/2b03f33fe578107d67713ec1201ff2243d42f0bda0cf7bcf9050dfa64c6b2488/detection ! https://safeweb.norton.com/report/show?url=567007.selcdn.ru ||567007.selcdn.ru^$all ! https://twitter.com/malwrhunterteam/status/1422972905541996546 ! https://www.virustotal.com/gui/file/6a7b7147fea63d77368c73cef205eb75d16ef209a246b05698358a28fd16e502/community ! https://www.joesandbox.com/analysis/459710/0/html#domains ! https://www.virustotal.com/gui/url/dc008163b78ea05ae4f1b14665e95a677dceb36635b3866137dd0deeb4a6a767/detection ||mojobiden.com^$all ||www.mojobiden.com^$all ! https://www.virustotal.com/gui/domain/mojobiden.com/relations ! https://www.virustotal.com/gui/file/4ad9432cc817afa905bab2f16d4f713af42ea42f5e4fcf53e6d4b631a7d6da91/relations ! https://www.virustotal.com/gui/domain/paymenthacks.com/community ! https://www.virustotal.com/gui/url/ad323946d804982acb6f8b346d04b295c5a6b56dccec573d3ccf24d8734c0f60/detection ||paymenthacks.com^$all ||www.paymenthacks.com^$all ! https://www.virustotal.com/gui/url/cdf956d33046ff7176dfafd36c9315806bbde32935da40e2dec090c21ee3a5a1/detection ! https://safeweb.norton.com/report/show?url=humisnee.com ! https://www.siteadvisor.com/sitereport.html?url=humisnee.com ||humisnee.com^$all ! https://twitter.com/teamcymru_S2/status/1423281518034575363 ! https://www.virustotal.com/gui/url/e4ce03393aa3daa83fd41ae9fbafc91bd4038d68741d74966fcce50af2045a77/detection ! https://www.virustotal.com/gui/url/ba668d3eeb8ad7c204a8a3db34fcb86fbbe0bd7270b4f15c91850953c53127cc/detection ! https://safeweb.norton.com/report/show?url=149.248.52.61 ! https://www.siteadvisor.com/sitereport.html?url=149.248.52.61 ||149.248.52.61^$all ! https://www.virustotal.com/gui/file/6d3ca814ba07ae5c6eb34eff7263b789428b1d58bef4c083015ab664f1757e50/community ! https://www.virustotal.com/gui/url/c1ec5e67ebadafcc0e29db8985900a7b8aae995a0d002795352ee2f5a80ae27b/detection ! https://www.virustotal.com/gui/url/5ba6e1f1f05d45f26424ccfc59872352e02744e1e44b490de5949bc1829adbc0/detection ! https://safeweb.norton.com/report/show?url=37.0.11.8 ! https://www.siteadvisor.com/sitereport.html?url=37.0.11.8 ||37.0.11.8^$all ! https://www.virustotal.com/gui/file/8c8ef518239308216d06b4bf9b2771dbb70759cb1c9e6327a1cd045444f2b69a/community ! https://pastebin.com/qHHUgBNK ! https://www.virustotal.com/gui/url/c4e241d019fcd5fa5aa3a4cb0ec4be1e8cf7c8a05c6229242da2e1b6887e7aab/detection ! https://safeweb.norton.com/report/show?url=45.146.165.91 ! https://www.siteadvisor.com/sitereport.html?url=45.146.165.91 ||45.146.165.91^$all ! https://www.virustotal.com/gui/url/6b506f269997a3fbbf9ef97032f05a7abfe3337efee6f42b30e3062a91d16b64/detection ! https://safeweb.norton.com/report/show?url=2215.site ! https://www.siteadvisor.com/sitereport.html?url=2215.site ||2215.site^$all ! https://www.virustotal.com/gui/file/be852596792aba7588ba5ac5819937dbc7cb8697a4550116d927d9d0772fdf89/relations ! https://www.virustotal.com/gui/url/ba85b00fbf3dd90c32380f247e267bbde96365ae7487454a64ee3ebd268452ec/detection ! https://safeweb.norton.com/report/show?url=151.237.138.38 ! https://www.siteadvisor.com/sitereport.html?url=151.237.138.38 ||151.237.138.38^$all ! https://www.virustotal.com/gui/url/c7e23912f17656d17cfc11eaa1ce83d1f7a10f90d1f83a405b1c805e5b464d3e/detection ! https://safeweb.norton.com/report/show?url=18.223.199.234 ||18.223.199.234^$all ! https://www.virustotal.com/gui/url/92ebdca53324e381d910cd299c500a2bf26c014ff41e8973ccefdf2b16d0877b/detection ! https://www.virustotal.com/gui/ip-address/162.241.216.74/relations ! https://www.virustotal.com/gui/file/f53eb5244a34381c13af884e9c08595da9fe7d75f3c0bcc85d8cef6bd0d52130/relations ! https://www.virustotal.com/gui/url/b0658cdf07ea02437bb4fbf3ccfd4847357373f5a187ceafd6c570b649db9a8f/detection ! https://safeweb.norton.com/report/show?url=118.243.83.70 ! https://www.siteadvisor.com/sitereport.html?url=118.243.83.70 ||118.243.83.70^$all ! https://www.virustotal.com/gui/url/dba92c49df2a4137cfef61dd0f9217e5c385557d8c8eaadf928304926911a8cb/detection ! https://safeweb.norton.com/report/show?url=5.189.168.53 ! https://www.siteadvisor.com/sitereport.html?url=5.189.168.53 ||5.189.168.53^$all ! https://www.virustotal.com/gui/url/ced18aa1052239d2dec2384b3d033829976d35a6d8315e17aef27e89ba829594/detection ! https://safeweb.norton.com/report/show?url=162.214.68.171 ! https://www.siteadvisor.com/sitereport.html?url=162.214.68.171 ||162.214.68.171^$all ! https://www.virustotal.com/gui/file/e298ef044baada7fadb47e9b722197896b4dafa18313de9a40bf96755148e614/relations ! https://www.virustotal.com/gui/ip-address/83.97.20.174 ! https://safeweb.norton.com/report/show?url=83.97.20.174 ! https://www.siteadvisor.com/sitereport.html?url=83.97.20.174 ||83.97.20.174^$all ! https://www.virustotal.com/gui/file/f2ecef6972fa7be407cb5576547d0bbca6bf778cc26ce02ca5a08bb884f58d6b/community ! https://www.virustotal.com/gui/url/75efeeff1963b998a24043708fd24edc1da463519e78e59a954b90954ca9fe2e/detection ! https://www.virustotal.com/gui/url/fe15cac53b47fba353e8d7951d6664f963ce898eef0005e7b771dfd88b446733/detection ! https://safeweb.norton.com/report/show?url=37.0.8.217 ! https://www.siteadvisor.com/sitereport.html?url=37.0.8.217 ||37.0.8.217^$all ! https://www.virustotal.com/gui/ip-address/49.143.32.6/community ! https://www.virustotal.com/gui/url/3d1404dadaa15af08785dc60b858137816ba60427d46946355c92670a6589026/detection ! https://safeweb.norton.com/report/show?url=49.143.32.6 ||49.143.32.6^$all ! https://www.virustotal.com/gui/file/96c77e1d8e1a7c10ebc0fb8a006c86a252fbcbbb51507acb8420fa85153e4e74/relations ! https://www.virustotal.com/gui/url/af7f53dec13a98434170029bfe715544344e514810118bca1658600e11f968dd/detection ! https://safeweb.norton.com/report/show?url=ksandrafashion.com ! https://www.siteadvisor.com/sitereport.html?url=ksandrafashion.com ||ksandrafashion.com^$all ! https://safeweb.norton.com/report/show?url=kulppasur.com ! https://www.virustotal.com/gui/url/0e5f624158f29f88fc8f3fbab69e5cb4c5db6b428967713f33e1e63aeef98edd/detection ||kulppasur.com^$all ! https://www.virustotal.com/gui/url/5c819f89b83c51e185239d1fef7a20dcee00c2b2e6593cf12122092761aa09a8/detection ! https://safeweb.norton.com/report/show?url=ecole-saint-simon.net ! https://www.siteadvisor.com/sitereport.html?url=ecole-saint-simon.net ||ecole-saint-simon.net^$all ! https://www.virustotal.com/gui/url/c7b20da67acc61b2ce9780883d372d4daafdccb87383e92605a6f623424f9476/detection ||www.ecole-saint-simon.net^$all ! https://safeweb.norton.com/report/show?url=koonadance2.com ! https://www.siteadvisor.com/sitereport.html?url=koonadance2.com ! https://www.virustotal.com/gui/url/05574a7b7820d5607c19578cde5076760530bb1d0327cc5602d88424943fe6e7/detection ||koonadance2.com^$all ! https://safeweb.norton.com/report/show?url=lifecom24.co.cc ! https://www.virustotal.com/gui/url/38551f4cb23a05558fa695d9668412c94a070831f7f4b807a734953acee6897e/detection ||lifecom24.co.cc^$all ! https://www.virustotal.com/gui/url/c1ac338c7037af10e3d07c48bb776a749d1159d1cc304d47836de5d16923a6f0/detection ! https://safeweb.norton.com/report/show?url=206.189.61.126 ! https://www.siteadvisor.com/sitereport.html?url=206.189.61.126 ||206.189.61.126^$all ! https://www.virustotal.com/gui/file/7f8f6685f7a93e134ea22dfc002505e12e68f37ca9dce13e0ecee894aab15bb2/community ! https://www.virustotal.com/gui/url/8adb82ddb59df83fedb479d51b4d937a11a78369e34196f9ab3dc0a3030cee41/detection ! https://www.virustotal.com/gui/url/3c13fdff77ca048b118cb9ce7860f30b013fbcad2787ab3d256a44bb64a30dd2/detection ! https://safeweb.norton.com/report/show?url=45.227.253.62 ! https://www.siteadvisor.com/sitereport.html?url=45.227.253.62 ||45.227.253.62^$all ! https://github.com/DandelionSprout/adfilt/issues/244 ! The original website ||rblxexploits.net^$all ||www.rblxexploits.net^$all ! Related websites open when trying to download ! Detected by FortiGuard and Norton. FortiGuard had added the detection the day I found this ||dhafj.youneerdmo.top^$all ! Another ||lprde.youneerdmo.top^$all ||youneerdmo.top^$all ||image-find.com^$all ! Why do I need a rickroll injector to download an image? This domain is also rated CAUTION by Norton... ! Fake notifications ||usegetmarketings.com^$all ||bestappever4you.com^$all ! This was loaded by a malware extension that was installed ||thecrs.club^$all ! https://gist.github.com/iam-py-test/9eb3d355c3ec875c9991f8940eb0db5c ||45.142.214.207^$all ! https://www.virustotal.com/gui/file/aed1b51083b8a9fd66a2ff75701a4c9580d79d92abe7b7a99fe725b5041cf28b/community ! https://www.joesandbox.com/analysis/461216/0/html#domains ! https://www.virustotal.com/gui/url/b7825bad8b21c35521838ac020b07c418c9d8b110686aa837e4de6d29075ec1f/detection ! https://www.virustotal.com/gui/url/3876559b496e67a29d268a98866aa7646663ccbe4f8f3d39c4328351a28e8391/detection ! https://www.siteadvisor.com/sitereport.html?url=45.61.185.83 ! https://safeweb.norton.com/report/show_mobile?name=http://45.61.185.83/sh4 ! https://www.siteadvisor.com/sitereport.html?url=http://45.61.185.83/sh4 ||45.61.185.83^$all ! https://www.virustotal.com/gui/file/67b1a7835687bf5851cf29539b2d0ce90ab30d373edfcf9ee54237026c67df33/relations ! https://www.virustotal.com/gui/url/1912779d4b9bfd7713239cf6e2ede751c40b38541404b21adb0c595b65356c75/detection ! https://www.siteadvisor.com/sitereport.html?url=uehge4g6gh.2ihsfa.com ! https://safeweb.norton.com/report/show?url=uehge4g6gh.2ihsfa.com ! https://metadefender.opswat.com/results/domain/dWVoZ2U0ZzZnaC4yaWhzZmEuY29t/overview?lang=en ||uehge4g6gh.2ihsfa.com^$all ! https://www.virustotal.com/gui/url/faee0c9a2d3786dda120ce8b99381878ebf05ca2b4d4a4437118ab2ca8ab49bd/detection ! https://www.siteadvisor.com/sitereport.html?url=2ihsfa.com ! https://safeweb.norton.com/report/show?url=2ihsfa.com ||2ihsfa.com^$all ! https://www.virustotal.com/gui/url/5cfe3add8396356f1757449074e95fab7b77aeabc405ca0fcebab5b699198d7f/detection ! https://www.siteadvisor.com/sitereport.html?url=listincode.com ! https://safeweb.norton.com/report/show?url=listincode.com ||listincode.com^$all ! https://www.virustotal.com/gui/url/9ac802ac997e44f7daf814ce163a17884ae59e3dd99e0c39432449af195f90b6/detection ||www.listincode.com^$all ! https://www.virustotal.com/gui/url/8fa47b5ba652f82753b171abebccafe63ed9afecce66fab5b675b6a5bb45938e/detection ! https://www.siteadvisor.com/sitereport.html?url=88.99.66.31 ! https://safeweb.norton.com/report/show?url=88.99.66.31 ||88.99.66.31^$all ! https://www.virustotal.com/gui/ip-address/185.220.101.139/community ! https://www.virustotal.com/gui/url/10a084ab4c535dab869f30fc95255f9d09040ca8e5f03feccf970e24d327f6a6/detection ! https://www.siteadvisor.com/sitereport.html?url=185.220.101.139 ||185.220.101.139^$all ! vxvault.net/ViriFiche.php?ID=43910 ! https://www.virustotal.com/gui/file/8a8cc0347be5e13c27bbb82822db989e8c47896d8e23944a8f5f419f4b6989ee/community ! https://www.virustotal.com/gui/url/ee836f36a1f189fa282a11a639d3a97a30743580418af72f2c30a4cae8ea0f81/detection ! https://www.virustotal.com/gui/url/5cd1ff6f48a00e547a8bbc691ca11c0ef93dc1bfe9404b4c39a0e009881e1207/detection ! https://www.siteadvisor.com/sitereport.html?url=http://nz-prosthodontists.org.nz/ox/wir.exe ! https://safeweb.norton.com/report/show?url=nz-prosthodontists.org.nz ||nz-prosthodontists.org.nz^$all ! https://www.virustotal.com/gui/file/c90df3b3551cd7235908d201f1bd3a4c635d0a5ec2f3f0af33ee5c52b611301f/community ! https://www.virustotal.com/gui/url/795a8b1a1df27a89afe709c229d95090ba8623891d23e3e5e37c5ba87ea49667/detection ! https://www.virustotal.com/gui/url/e4a6a323120010ad451dbb7be5943364c78e3622973e198d2929bddf9220bbcb/detection ! https://www.siteadvisor.com/sitereport.html?url=http://45.61.184.168/i-5.8-6.Sakura ! https://safeweb.norton.com/report/show?url=http%3A%2F%2F45.61.184.168%2Fi-5.8-6.Sakura ||45.61.184.168^$all ! https://www.virustotal.com/gui/file/8f408002a2c7305f6eff6b076043660b1fc29e7dc265a9fff0421a86081b987a/community ! https://www.joesandbox.com/analysis/462918/0/html#domains ! https://www.virustotal.com/gui/url/cb76fad673f4d4fc1f0b8c7f6bd0293e3038f9571e0693919e48e6b4e581a403/detection ! https://www.virustotal.com/gui/ip-address/194.163.136.78/relations ||194.163.136.78^$all ! https://www.virustotal.com/gui/file/cfb4e7b08343010cf746149e718c8737e4293390d02bc5bf30d46c5e73871651/relations ! https://www.virustotal.com/gui/url/5cd50f47e7f5c1e6cf66f2b20b90401dfd8ac196ddd3c1115c7c7b72dc87f28d/detection ! https://www.virustotal.com/gui/ip-address/194.5.98.81/relations ! https://www.siteadvisor.com/sitereport.html?url=194.5.98.81 ! https://www.ipvoid.com/ip-blacklist-check/ ||194.5.98.81^$all ! vxvault.net/ViriFiche.php?ID=43984 ! https://www.virustotal.com/gui/url/f13152c3b392a4c0c1759f1b96a6b73e2d775fbc75171f7c5987fc7a67a64b54/detection ! https://www.virustotal.com/gui/url/adf5541dd1d0b77f1efa66057aaf60765274b8cc4b17d9ad1029945add705c43/detection ! https://safeweb.norton.com/report/show?url=a0568605.xsph.ru ! https://www.siteadvisor.com/sitereport.html?url=a0568605.xsph.ru ||a0568605.xsph.ru^$all ! vxvault.net/ViriFiche.php?ID=43981 ! https://www.virustotal.com/gui/file/008a112467f8f7b74845bbb9958650cd16e8be074510e8d58d28f78c1fdd0840/relations ! https://www.virustotal.com/gui/url/ef0661056b66fd787d994437346284842c4d5c10334bd9d5a73ccec31749ee2a/detection ! https://www.siteadvisor.com/sitereport.html?url=179.43.187.188 ! https://safeweb.norton.com/report/show?url=179.43.187.188 ||179.43.187.188^$all ! https://www.virustotal.com/gui/file/1753f2373b77f90cf8c6b94fbe533bdf25ec3415eebd88e5fadbe8bdc1137dab/community ! https://www.virustotal.com/gui/url/a81929c9ddbf54f472a8807ad68d653de468bbc7a2c2888018ee8f8b8adde3b3/detection ! https://www.siteadvisor.com/sitereport.html?url=trust-safe.com ||trust-safe.com^$all ||www.trust-safe.com^$all ||pop.trust-safe.com^$all ! https://www.virustotal.com/gui/file/54619b816d64d1a770ef510c94d06d4cee747ca885188c80f71fd69434d057c4/community ! https://www.joesandbox.com/analysis/464518/0/html#domains ! https://www.virustotal.com/gui/url/0315d159f091d9470be69bb9f7d6e9cd43c9d1428de44a1b3818bf08807a2a08/detection ! https://www.virustotal.com/gui/url/6f12bfe5cc02286475b8f0deebb7955f8ea1814f0ebe141b19df1fc8564080e5/detection ! https://safeweb.norton.com/report/show?url=116.203.127.162 ||116.203.127.162^$all ! https://forum.adguard.com/index.php?threads/fake-downloads.36735/ ! https://safeweb.norton.com/report/show_mobile?name=keocial.pw ! https://www.virustotal.com/gui/url/7f72a53e66c878d218e4b804624ae85c1e524c4da3d7c68bb96be725b931e083/detection ||keocial.pw^$all ! https://www.virustotal.com/gui/file/0ed83aa95f87e65e843b791c92419d0c1d34e5b01cc0be01715009f679ddc220/community ! https://www.virustotal.com/gui/url/9e4b53387b8e98d3fffaf1306c4b766255519a0252bb5a452aec48cdde8c9e93/detection ! https://www.virustotal.com/gui/url/1b65a7e0eeafa63534728b39fd2c77a7db1d58f26c0c6b618834fc95192485ed/detection ! https://urlhaus.abuse.ch/url/1533784/ ||193.142.59.119^$all ! https://www.virustotal.com/gui/file/07fbb8d2038afc0b03a2b89082693597a45a7e5f75d065c919fecf63e386c58d/relations ! https://www.virustotal.com/gui/url/fab35efbf7bb4f4b05b7cd7d4192c6c13566f3a2adedef7c6440ce26e9ed4ffb/detection ! https://www.siteadvisor.com/sitereport.html?url=185.227.139.5 ||185.227.139.5^$all ! vxvault.net/ViriFiche.php?ID=43984 ! https://www.virustotal.com/gui/file/8cbafd04f32cc48843fcac1913ae731b04e990a44d789a74b0ef50785874d5aa/community ! https://www.virustotal.com/gui/url/af6d53969e3f7317379025ee9e3e768d2fb0e7e3a2f7422eff8f927c14de8014/detection ! https://www.virustotal.com/gui/url/264ccac34f89407907dd60f628b5b35c0ff830b0d6a3381124a0093a6b028647/detection ||194.226.139.141^$all ! https://www.virustotal.com/gui/file/94ae9b29d3ea02cbe824295642c9f7a6206ebd7cca74050e697943f05d0b8407/community ! https://www.virustotal.com/gui/url/7f4bee085b9aa033b3d30f4e135ee8faf620b44a4a69f2ea70ccc817853b4dcb/detection ! https://www.virustotal.com/gui/url/d0b0c5009c8e4c1dd55cd3cd96622f33be74d8d599bfe3d4297080426e56bdb9/detection ! https://www.siteadvisor.com/sitereport.html?url=http://136.144.41.122/nigbins/fbot.x86 ! https://safeweb.norton.com/report/show?url=http://136.144.41.122/nigbins/fbot.x86 ||136.144.41.122^$all ! https://www.virustotal.com/gui/file/92cd3f7d1c4eae64f683ed81efb56c65aac4bec0a014fc26e1baa547894e1eba/detection ! https://www.virustotal.com/gui/url/2a7f5f98143a920f7c8ceee7bf4033607b660b2dee35fbcef87e32ec8eed843e/detection ! https://safeweb.norton.com/report/show?url=iyfsearch.com ||iyfsearch.com^$all ! https://www.virustotal.com/gui/file/e19738a89a329be01099695a221c0d9885a728980cae42bed7625116469b4608/community ! https://www.virustotal.com/gui/file/8af95e7b245deede697fbb9081551dd88610dfd72a0cba790c7c382c29f99ccc/detection ! https://www.virustotal.com/gui/url/bcfc144c8aaf577826fbebbefd507a7dc522a8624ce77230b1c5bdf531247c7f/detection ! https://www.virustotal.com/gui/url/ae640bf4efaa089e39788f9c94972b9ef156bfbada2acda6241a42ee4eb79817/detection ! https://safeweb.norton.com/report/show?url=104.144.69.55 ! https://www.siteadvisor.com/sitereport.html?url=104.144.69.55 ||104.144.69.55^$all ! https://www.virustotal.com/gui/file/129e52b2c93cc026192d8cc216c345ec4492e9f67e6e0a80daa3619c6857574e/community ! https://www.virustotal.com/gui/url/eeafc5bc98a34dd62e1defc8a0a9512ea3bcb8a5574f7b0a17f2069153beaa00/detection ! https://www.virustotal.com/gui/url/7a774427f6daed4ced8240319ebeb747d19f1675168badaf78d1547de3027751/detection ! https://www.siteadvisor.com/sitereport.html?url=45.137.190.197 ! https://safeweb.norton.com/report/show?url=45.137.190.197 ||45.137.190.197^$all ! https://www.virustotal.com/gui/file/129e52b2c93cc026192d8cc216c345ec4492e9f67e6e0a80daa3619c6857574e/relations ! https://www.virustotal.com/gui/file/7fd0492c4392a099342c30e79cbe0b5198855d399a1848af788fa7a808e6b484/relations ! https://www.virustotal.com/gui/url/ebb8e6f632ab14941647d83991ec53cbb626aa0992d688bc12defffc8f4d7aad/detection ! https://www.virustotal.com/gui/url/f80c60f765859f9643966680b7aa5479c367909f60efe19706ce78c9897f8f57/detection ! https://www.siteadvisor.com/sitereport.html?url=45.14.49.109 ||45.14.49.109^$all ! https://www.virustotal.com/gui/file/3c2f8ba0fcd562f8f2e8ab0e41dbf01732216514120d54df74563bbc13efa9dc/community ! https://www.virustotal.com/gui/url/1ec6dfac5c2ca7bb57a033f9b627c5a55ca92da5cd6ffcfe470bead67c1b1a0e/detection ! https://www.virustotal.com/gui/url/99d1b1f9d7c658f4e0bd3840a9799d483f2410a38b6fe98c3da9e0479352bd1d/detection ! https://www.siteadvisor.com/sitereport.html?url=195.133.40.212 ! https://safeweb.norton.com/report/show?url=195.133.40.212 ||195.133.40.212^$all ! https://www.virustotal.com/gui/url/2146da7de933f89d051483f707e5bdbe88be40191ec7685fc6c9e1dd4751698a/detection ! https://www.siteadvisor.com/sitereport.html?url=afobal.cl ! https://safeweb.norton.com/report/show?url=afobal.cl ||afobal.cl^$all ! https://feodotracker.abuse.ch/downloads/ipblocklist.csv ! https://www.virustotal.com/gui/url/00deb71c098f3156546b338f1c116d78424b0f17f60a54753b865668318837ea/detection ! https://www.siteadvisor.com/sitereport.html?url=67.213.75.205 ! https://safeweb.norton.com/report/show?url=67.213.75.205 ||67.213.75.205^$all ! https://www.virustotal.com/gui/url/821b1aee0c5e3da226d0751de56ca5b04c636085af1192c51cee06a43bd0b0b8/detection ! https://www.siteadvisor.com/sitereport.html?url=51.178.161.32 ! https://safeweb.norton.com/report/show?url=51.178.161.32 ||51.178.161.32^$all ! https://www.virustotal.com/gui/url/0ade8fac39b864f2d39756810696515581c23833da3b998d80376bcb3b2ce4d6/detection ! https://safeweb.norton.com/report/show?url=162.144.127.197 ! https://www.siteadvisor.com/sitereport.html?url=162.144.127.197 ||162.144.127.197^$all ! https://www.virustotal.com/gui/url/18ea15f711e946cb8535fed822670be08fbaaf9f55c487eb6f1a5a68709793c9/detection ! https://safeweb.norton.com/report/show?url=111.230.104.169 ! https://www.siteadvisor.com/sitereport.html?url=111.230.104.169 ||111.230.104.169^$all ! https://www.virustotal.com/gui/file/a2c0961c68aa8ec95213014e570ae11abe0ee633670c676b43914bd3c4b8ce52/relations ! https://www.virustotal.com/gui/url/e52e8b85f252dc157223cf26efeabfa6a6680dfb9223a25580404b8dbe127aa7/detection ! https://safeweb.norton.com/report/show?url=wildbleu.shop ||wildbleu.shop^$all ! https://www.virustotal.com/gui/file/b4d64792408b8cde1d71a4b607bcc1a93f37f21559c0cb672073e2031253d68b/community ! https://www.joesandbox.com/analysis/466329/0/html#domains ! https://www.virustotal.com/gui/url/fcb496b07c3ebfb475b7e9a933a7c8e915026e918f803ac76095217c45f3eb35/detection ! https://safeweb.norton.com/report/show?url=103.109.247.9 ||103.109.247.9^$all ! https://www.virustotal.com/gui/url/13c6e98d8e906c40cd8683f2cc7ed68edf0a51b36e6bd4b310f2ab6916126e7d/detection ! https://safeweb.norton.com/report/show?url=188.40.100.254 ||188.40.100.254^$all ! https://www.virustotal.com/gui/url/214e06a9bb42d6f35c29a7eecf73b8381ea2b8d6ae0ad83162e4a27bbb35bd07/detection ! https://safeweb.norton.com/report/show?url=134.209.182.12 ||134.209.182.12^$all ! https://www.virustotal.com/gui/file/87123abedeb153701208d63b3cef86d265cad5ff80df6eef27e4fb081aeb2a7f/community ! https://www.virustotal.com/gui/url/360336ed8e1613a4f8d4a344ce7105ffeeaf6ac2b82580c71fbd895bb4eae4c8/detection ! https://www.virustotal.com/gui/url/e596b06a2a5f98a24d8a0c9b73b519556c511d04c4f4c8f9e6850999e4ce4a60/detection ! https://www.virustotal.com/gui/url/a4c111a5e065b0f80f8d12a29592f4ac7d1af30c62f871a7533292b50ca288fb/detection ! https://safeweb.norton.com/report/show?url=nanorgin.ydns.eu ! https://www.siteadvisor.com/sitereport.html?url=nanorgin.ydns.eu ||nanorgin.ydns.eu^$all ! Typosquatting ! https://www.virustotal.com/gui/url/7192e189a778151b8b2ac216542c1dd4c842cc5dded479941cfecfc940e44cc8/detection ! https://www.virustotal.com/gui/file/eaffdf51b17ef1b7b7bf01ab6e8c2dce61a3dbd875b368e06a6d3b95e100c6f1/relations ! https://www.virustotal.com/gui/ip-address/37.34.176.37/relations ! https://www.virustotal.com/gui/url/af95bb533c667812c17d0899ef02c8c188161be2f6d26edd80f0ff1459a03258/detection ! https://safeweb.norton.com/report/show?url=37.34.176.37 ! https://www.siteadvisor.com/sitereport.html?url=37.34.176.37 ||37.34.176.37^$all ! https://www.virustotal.com/gui/url/77792ab281bf192d8f5a0ba16e5ab2c0199aec54df4bc7374b18944b11c854fd/detection ! https://safeweb.norton.com/report/show?url=atvcampingtrips.com ! https://www.siteadvisor.com/sitereport.html?url=atvcampingtrips.com ||atvcampingtrips.com^$all ! https://www.virustotal.com/gui/url/0563e57325ffff57e032b31a7fa419c492a4ac50d0cc0c541a31b94054593cdd/detection ! https://safeweb.norton.com/report/show?url=thegymmum.com ! https://www.siteadvisor.com/sitereport.html?url=thegymmum.com ||thegymmum.com^$all ! https://www.virustotal.com/gui/domain/account-restricted.info/relations ! https://www.virustotal.com/gui/url/aebdaf64e8d42566bebb020d84cb35c05db69d8c9061940278a7fe52d794b63a/detection ! https://www.siteadvisor.com/sitereport.html?url=185.239.243.112 ! https://safeweb.norton.com/report/show?url=185.239.243.112 ||185.239.243.112^$all ! https://www.virustotal.com/gui/file/516b8716bfbbd056ec8259f0c336e855b0fed7dbaaa6c04ec76aa1328c92ad87/relations ! https://www.virustotal.com/gui/file/8038405046898dab91340152bc515b1a85f5fd54711614a56fb7a531a56a7db9/relations ! https://www.virustotal.com/gui/url/e855aab0b2ac18ea9ae36d23e294613cf35b97fa1b1734f4cf35473ceb6e6b8f/detection ! https://safeweb.norton.com/report/show?url=eduarroma.tumblr.com ||eduarroma.tumblr.com^$all ! https://www.virustotal.com/gui/url/b480da37eeb76c5cd8f867b1f8871aef1bac0a2f37f2d8cc7953ca07f91bf7c4/detection ! https://www.siteadvisor.com/sitereport.html?url=185.215.113.15 ! https://safeweb.norton.com/report/show?url=185.215.113.15 ||185.215.113.15^$all ! https://www.virustotal.com/gui/file/ebfbb91b4d57e70a7b5b2a24a5bb78ee143a6f8f2edafe2b3c1c8dd7d61b930d/relations ! https://www.virustotal.com/gui/url/510abe9a0797fba6338250a083c7049a773dca1baa9c02d25d3e7b42ee0380cc/detection ! https://safeweb.norton.com/report/show?url=185.250.206.82 ||185.250.206.82^$all ! https://www.virustotal.com/gui/url/e05b0f4fd78208598d08aa294f5a99f11177484c87d94ca1d701cb93cbe8fdc0/detection ! https://www.virustotal.com/gui/url/cf430fc85e691d89d3984ac14eb85b3b5ea7b203aea27409d302c1a95fff8244/detection ! https://www.siteadvisor.com/sitereport.html?url=a0570895.xsph.ru ! https://safeweb.norton.com/report/show?url=a0570895.xsph.ru ||a0570895.xsph.ru^$all ! https://www.virustotal.com/gui/file/fbe16f2bac5edc34ba984eb6c7b5c05da6946a5f5394c3b06ef140fa842ca824/community ! https://www.joesandbox.com/analysis/468838/0/html#domains ! https://www.virustotal.com/gui/url/d8d5c2f4020dc9ef83a1a22756aa6904962eaf6f5a89b6a10f890ea282806422/detection ! https://safeweb.norton.com/report/show?url=mail.tccinfaes.com ||mail.tccinfaes.com^$all ! https://www.virustotal.com/gui/url/e47aa054147322005e1165d5a2dc99e7263af91e80ce1529ecd0e23ccbae3ecf/detection ! https://safeweb.norton.com/report/show?url=tccinfaes.com ||tccinfaes.com^$all ! https://www.virustotal.com/gui/file/321b8f87df4dd22bdfc9631a0d84f39b90f16cd8ea0e72f4a1f70df4b39b3468/community ! https://www.joesandbox.com/analysis/469062/0/html#domains ! https://www.virustotal.com/gui/url/f793bc9318171a55a2cf7fab32b839fafbb99eb265d929f0186e86aec9e99015/detection ! https://www.virustotal.com/gui/ip-address/95.213.224.6/relations ||95.213.224.6^$all ! https://safeweb.norton.com/report/show_mobile?name=readinglistforaugust1.site ||readinglistforaugust1.site^$all ! https://www.virustotal.com/gui/file/3a83e58f8dc0015d65374b7715f89acf15ff08c82837c8f6f66f64db21732644/community ! https://www.virustotal.com/gui/url/55dca36f52cbce64ad5e810b0654ea4b335ff1e7dbd0f064556eeeef0ca12f4f/detection ! https://safeweb.norton.com/report/show_mobile?name=135.125.172.201 ! https://www.siteadvisor.com/sitereport.html?url=135.125.172.201 ||135.125.172.201^$all ! https://www.virustotal.com/gui/file/024ec546ba44a1ed3c34d2def8df5fbc6f9d1c0ac8e69f933e65b7bd0b33a28a/community ! https://www.virustotal.com/gui/url/d0da491a170874f6da9f1354e62db26995f6fc752ade5c0ca2a0a6085c041fde/detection ! https://www.virustotal.com/gui/url/9f131288062cc79198edfbe6968fa511256a51d2ad32d7737c107e3309eb4a8c/detection ! https://safeweb.norton.com/report/show_mobile?name=http://212.192.241.72 ||212.192.241.72^$all ! https://www.virustotal.com/gui/file/86d34c8a0dac58667e0fbed519b0189d90082825cba5721e9d3575c90c47e57c/community ! https://www.virustotal.com/gui/url/78855f44c4957aeb900b3a0c27d320ac1732452127d537f55d343ec73c80326c/detection ! https://www.virustotal.com/gui/url/c6603ab0398e8a65ea9cecb50729ffc1eab52adacac035b2325ef754b4ee7142/detection ! https://www.siteadvisor.com/sitereport.html?url=194.26.29.184 ! https://safeweb.norton.com/report/show_mobile?name=194.26.29.184 ||194.26.29.184^$all ! http://vxvault.net/ViriFiche.php?ID=44008 ! https://www.virustotal.com/gui/file/aca7a7d812ac2192255aa3d47477f13b05963da0383e459d6b09d1630cd11aae/community ! https://www.virustotal.com/gui/url/d357faedc123bad300c25918a04ea6287d4ca590ecaf90f2dedcde4b9e0d559e/detection ! https://www.virustotal.com/gui/url/da1609d7885281bbca767003d5edb87623eb0d4f739535bbe9e52ea85804611a/detection ! https://www.siteadvisor.com/sitereport.html?url=37.0.10.83 ! https://safeweb.norton.com/report/show_mobile?name=37.0.10.83 ||37.0.10.83^$all ! https://www.virustotal.com/gui/file/eb521300b6ee49fdaad2d339f8389528bd676124d78b2490a238d8f439574635/community ! https://www.virustotal.com/gui/url/4c7eac459d44ff63221a5a2e4c1734952ddbbaf1c4dcac7fa16d0ec7a14ec628/detection ! https://www.virustotal.com/gui/url/df497e64dc3714452bea3a24b1bbce4093281259387efbdcc021afa92bba412e/detection ! https://safeweb.norton.com/report/show_mobile?name=http://45.138.172.28/ ! https://www.siteadvisor.com/sitereport.html?url=http://45.138.172.28/ ||45.138.172.28^$all ! https://www.virustotal.com/gui/file/be76d8099188dcd24930e143e92a6c0d0f0e8c55de5dc4c17faec4669ff39802/relations ! https://www.virustotal.com/gui/url/6fc4c5b49ff795c28b752a232f8ba8f0b6e2948e3485513969f2fb1a963a195d/detection ||uyg5wye.2ihsfa.com^$all ! https://www.virustotal.com/gui/file/109f4e911963fc423baf52a474ef505145cedf68c146a86158bfdc9b8bbcc45b/community ! https://www.virustotal.com/gui/url/4ebf505cf59496a37f006435e1bb7f22a40cfed8deab05d09e426081d78f2116/detection ! https://www.virustotal.com/gui/url/4e66dcf74b39601de17b09c482ea3f9b4c967ae91723b40f6d0fbdd72db234a2/detection ! https://www.siteadvisor.com/sitereport.html?url=http://70.36.99.109/i-5.8-6.Sakura ! https://safeweb.norton.com/report/show?url=70.36.99.109 ||70.36.99.109^$all ! https://www.virustotal.com/gui/url/d4cf43cf6ad460ea97c3e401a7ff4b5aaf03da1dd7fa71fc5c6f9136c15ab4f6/detection ! https://www.virustotal.com/gui/url/c0831fa570a3a5ed04cbb8f2ec5ae8e68a18875f0dec125710b5421ff7e815db/detection ! https://www.siteadvisor.com/sitereport.html?url=70.36.99.108 ! https://safeweb.norton.com/report/show?url=70.36.99.108 ||70.36.99.108^$all ! https://www.virustotal.com/gui/url/a4a6a2743af11dcdad071e6662498c19575d71d37554789a19df0ff9f5d69f41/detection ! https://www.virustotal.com/gui/url/f8b8050cd46b54bb89a4e808e557a67b556b263b4fa4cfd09a21a8777f112eaa/detection ! https://www.siteadvisor.com/sitereport.html?url=70.36.99.107 ! https://safeweb.norton.com/report/show?url=70.36.99.107 ||70.36.99.107^$all ! https://www.virustotal.com/gui/url/69cefb16274c163b9e80c45b8e8edad6477ef245e4e576d1e022985b78981810/detection ! https://www.virustotal.com/gui/url/b383f6aafb0dc7404603ee3f64ec2b23bd71566cfdb4b30d26d3551a8469e5d2/detection ! https://www.siteadvisor.com/sitereport.html?url=70.36.99.106 ! https://safeweb.norton.com/report/show?url=70.36.99.106 ||70.36.99.106^$all ! https://www.virustotal.com/gui/url/f9f7098d4f6531c17e85c64085b1abecdf1a3b328a42d13fcb6a578cfc676e85/detection ! https://safeweb.norton.com/report/show?url=mybetterdl.com ||mybetterdl.com^$all ! https://www.virustotal.com/gui/url/b416da61cc21892d24b5c2c3108f2b37744719bef3ef9698273d97161e2a3653/detection ||p17181.mybetterdl.com^$all ! https://www.joesecurity.org/reports/report-ddd60e9ae362def377aa70d414ed374d.html#domains ! https://www.virustotal.com/gui/url/ef9279f1929cbc0f6df0657e4a60756366d64d64307c014cb8c64068a9bd9151/detection ! https://safeweb.norton.com/report/show?url=198.54.117.199 ! https://www.siteadvisor.com/sitereport.html?url=198.54.117.199 ||198.54.117.199^$all ! https://blog.malwarebytes.com/threat-intelligence/2021/08/new-variant-of-konni-malware-used-in-campaign-targetting-russia/ ! https://www.virustotal.com/gui/url/cabda0b842c71975636fa9771fb2c1e8c1cbea3f563ccb3e7b2f7aa97ef35d5c/detection ! https://www.virustotal.com/gui/url/62c816717ba7b01990587fe85d35757e1114e1903ef53a09fb30a17ba9a2c6ca/detection ! https://www.siteadvisor.com/sitereport.html?url=taketodjnfnei898.ueuo.com ! https://safeweb.norton.com/report/show?url=taketodjnfnei898.ueuo.com ||taketodjnfnei898.ueuo.com^$all ! https://www.virustotal.com/gui/url/d22f08c107fce668a5124821e8016116aa5f760a935279b1fa72f6c0bdcf7fec/detection ! https://www.virustotal.com/gui/url/a67a153fa6085488b963ffca30885ee674df394e81a97da29a13262587eafa03/detection ! https://safeweb.norton.com/report/show?url=romanovawillkillyou.c1.biz ! https://www.siteadvisor.com/sitereport.html?url=romanovawillkillyou.c1.biz ||romanovawillkillyou.c1.biz^$all ! https://www.virustotal.com/gui/file/a22fe85b92f3244cb238a2ba0631f08b4b5a0153f7d6fae26ac91cddc2d0f059/community ! https://www.joesandbox.com/analysis/472077/0/html#domains ! https://www.virustotal.com/gui/url/0641cf3612499d9e71fdf1e16b98b8fce92ca12c4a69d745704b1851c4acb24b/detection ! https://safeweb.norton.com/report/show?url=asade.no-ip.org ! https://www.siteadvisor.com/sitereport.html?url=asade.no-ip.org ! https://www.virustotal.com/gui/url/f8751682b23dff4d87dde7f95119a3ac270c77c62657e1ecfd3c3e35e74b827f/detection ||asade.no-ip.org^$all ! https://www.virustotal.com/gui/file/f78ca72f2d4c05da410da87ebece47ec6c7ad43bf1456d866e6b8640d78e96b6/community ! https://www.joesandbox.com/analysis/472098/0/html#domains ! https://www.virustotal.com/gui/url/c0dfc5f90c7a9483db3d56aec1b257079efe5a016fec10d1d2516fd8f2ac12a7/detection ! https://safeweb.norton.com/report/show?url=uhie2020.duckdns.org ! https://www.siteadvisor.com/sitereport.html?url=uhie2020.duckdns.org ||uhie2020.duckdns.org^$all ! https://www.fortinet.com/blog/threat-research/signed-sealed-and-delivered-signed-xll-file-delivers-buer-loader ! https://www.virustotal.com/gui/url/99dda4eaaf7119536fe441b204fda5f9f35697fb71941481aec24229bd178e25/detection ! https://www.virustotal.com/gui/url/e4abc2b90524ca16a57d741f8248fe4b5d0cb6c641aeabd95e6a49c5ec1d110a/detection ! https://www.siteadvisor.com/sitereport.html?url=dmequest.com ! https://safeweb.norton.com/report/show?url=dmequest.com ||dmequest.com^$all ! https://www.virustotal.com/gui/url/581087f1d00e0710951d3fb2894365d1329408f87473c2718b10745c085f05d1/detection ! https://www.siteadvisor.com/sitereport.html?url=195.123.234.11 ! https://safeweb.norton.com/report/show?url=195.123.234.11 ||195.123.234.11^$all ! https://www.virustotal.com/gui/file/ed004a6565e727941d5649b752b77f449a9748d9c49cbe21936a634cabf1f4e8/community ! https://www.virustotal.com/gui/url/916f4b05446b3fe1cceab4ec3abd70f7224f9965e86e7f0e7701df978f9146bd/detection ! https://www.virustotal.com/gui/url/36a0aad1b7c7970d6f0e118f8e84387b377de04b8b16bc5c1753404c4d20cba4/detection ! https://www.siteadvisor.com/sitereport.html?url=31.7.62.62 ! https://www.ipvoid.com/ip-blacklist-check/ ||31.7.62.62^$all ! https://www.virustotal.com/gui/file/8344690f025846a5a0dcf5d6012a94cddcfe48ffcc06fa6d566bb4ef149e6716/relations ! https://www.virustotal.com/gui/url/e5d220a13b6cc573ca4d9e96932bfc1f1b19e6b7a07ce2043190baa9f068d8b1/detection ! https://www.siteadvisor.com/sitereport.html?url=a.uguu.se ! https://safeweb.norton.com/report/show?url=a.uguu.se ||a.uguu.se^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/91815#issuecomment-902849565 ! https://www.virustotal.com/gui/url/a0d272ce4b6c2e6cce639c8cd3bc5ad91c6c20a0876bad6359f728fcf90109eb/detection ! https://safeweb.norton.com/report/show?url=lakshmiwafered.cam ||lakshmiwafered.cam^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/88280 ! https://www.virustotal.com/gui/url/5ac4b9c907ee714f1163331bcb9840a472f85809e9730edc03dd88e9d706bcbb/detection ! https://safeweb.norton.com/report/show?url=update-portal.com ! https://www.siteadvisor.com/sitereport.html?url=update-portal.com ||update-portal.com^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/88270 ! https://safeweb.norton.com/report/show?url=tw-goldenwinner-57.com ! https://www.virustotal.com/gui/url/ddec939917a016338c34597563962b9baa10080f62ea0320d8e4b8b21156007e/detection ||tw-goldenwinner-57.com^$all ||www.tw-goldenwinner-57.com^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/80390 ! https://www.virustotal.com/gui/url/1b63e3d8a99633582446d6c095e9350b869dc60716187f714bbdb85d9f06122f/detection ! https://safeweb.norton.com/report/show?url=artebythesea.com ||artebythesea.com^$all ! https://www.virustotal.com/gui/url/16534bfc6c24e0c30dbac08ea5297ae24f9f9ae90411bc3b608659e1767317a7/detection ! https://safeweb.norton.com/report/show?url=microsoftpods.com ||microsoftpods.com^$all ! https://www.virustotal.com/gui/url/94b361a89a5c3a43d6013fb8f971e40c9bd3493042343a0ee3626375b4552267/detection ! https://safeweb.norton.com/report/show?url=nashvillegems.com ||nashvillegems.com^$all ! https://www.virustotal.com/gui/url/2dbc2cf61fa22eec22629f31b731c04eeb4cdc86d589ab36c0c7719b26e60ede/detection ! https://safeweb.norton.com/report/show?url=flawlessdrinking.com ||flawlessdrinking.com^$all ! https://www.virustotal.com/gui/url/2a213601051b43f18c3f6b6faadf5b65b8375f5c9ffe5cb9fe2c18fe13b0bd2a/detection ! https://safeweb.norton.com/report/show?url=findmyautoparts.com ||findmyautoparts.com^$all ! https://www.virustotal.com/gui/url/fcd7962a77ae7836f84789452b77d293de0e1a47e91ecfe2c2508bead500197b/detection ! https://safeweb.norton.com/report/show?url=grandpaurbanfarm.net ||grandpaurbanfarm.net^$all ! https://safeweb.norton.com/report/show?url=guide4idiots.com ! https://www.virustotal.com/gui/url/2f9dfbbc3cde41756691a0b741eb605c7ed81d55733f912dc590808f6ec2cb5e/detection ||guide4idiots.com^$all ! https://safeweb.norton.com/report/show?url=holdergear.com ! https://www.virustotal.com/gui/url/c72d699f9b6070862587733e2fbe21a59ed5b8be8e176578a0cebba6fcaf700f/detection ||holdergear.com^$all ! https://safeweb.norton.com/report/show?url=houseof2.com ! https://www.virustotal.com/gui/url/5665968f7b1a2068bc9ef61407a1dcf46b59dce51c6f8ac7c4181875d507a651/detection ||houseof2.com^$all ! https://safeweb.norton.com/report/show?url=identityofplace.com ! https://www.virustotal.com/gui/url/987c5c40192b3e6049a8c2523a7f4bba374db1ab7a1418f25dccdba7379674c6/detection ||identityofplace.com^$all ! https://www.virustotal.com/gui/url/6fb68516452024785cbdb664f5363c7e49ed6a9fd88fe0dce79a157560ec0701/detection ! https://safeweb.norton.com/report/show?url=shpwmy.com ||shpwmy.com^$all ! https://www.virustotal.com/gui/file/ca5606627e5af653647b74e407fb048aedba15dd3f20cbbcaab0aedbaaeda887/community ! https://www.joesandbox.com/analysis/473048/0/html#domains ! https://safeweb.norton.com/report/show?url=steevya.com ! https://www.siteadvisor.com/sitereport.html?url=steevya.com ! https://www.virustotal.com/gui/url/c49d09a2aad1e1755401e32e04f28f27e717662012d25a748e1262b12bd6ff69/detection ||steevya.com^$all ! https://www.virustotal.com/gui/url/c591b94d6abcfcaca97598685a45751c98fd662a0706b51155305be9f9f64705/detection ! https://www.siteadvisor.com/sitereport.html?url=192.169.69.25 ! https://safeweb.norton.com/report/show?url=192.169.69.25 ||192.169.69.25^$all ! Domains from uBlock badware (GNU General Public License v3.0) ! The code below has been modified to remove not relevent entries and correct the formatting ! https://github.com/uBlockOrigin/uAssets/blob/master/filters/badware.txt#L425 ||prizesworldcenter.com^$all ||video-adblock.com^$all ||vid-adblocker.com^$all ||multiadblock.com^$all ||rsafrwd.com^$all ||adverdirect.com^$all ||bestwinexperience.com^$all ||triumphantplace.com^$all ||traffic-go.com^$all ||wignewsee.club^$all ||bainushe.com^$all ||streamssitesearch.com^$all ||catbeardx.com^$all ||wdeliv.net^$all ! https://www.virustotal.com/gui/file/0a0c14301560d7c81cb15b5feca5b7f45bcb8679fcf773705a58f81523820da3/relations ! https://www.virustotal.com/gui/url/861f1eb8989eb8979597f355e609dc36891e0891d4303cf59c23e993c2be2382/detection ! https://www.siteadvisor.com/sitereport.html?url=a1l.no-ip.biz ! https://safeweb.norton.com/report/show?url=a1l.no-ip.biz ||a1l.no-ip.biz^$all ! vxvault.net/ViriFiche.php?ID=44012 ! https://www.virustotal.com/gui/url/b918c2e51aa20c5ae35cb609e5a3c94f10fb0d38451510c7d91dee150965e6da/detection ! https://www.virustotal.com/gui/url/bccda7a30dbe5315b5e8477875c648394b52aff7c4df888e3c6260731b04e6af/detection ! https://www.virustotal.com/gui/file/62b896e96dcf04ac6f6953b1ecea555b4ac4ac0f2c0fe484b27c54650d71c8db/relations ! https://www.virustotal.com/gui/url/4d38b0c851670a331c9580352c4eb50d55c49c2711bfa34e91537eb95ee29c5b/detection ! https://www.siteadvisor.com/sitereport.html?url=91.235.129.150 ||91.235.129.150^$all ! https://github.com/easylist/easylist/pull/6164 ! https://www.virustotal.com/gui/url/451116a1c2d7538f62afb47618950eccc69e6aaa30702e21d2e6089b458d178d/detection ! https://www.virustotal.com/gui/domain/obliteratebedblue.com/relations ! https://www.virustotal.com/gui/ip-address/192.243.59.13/community ! https://www.virustotal.com/gui/url/8dd9779c568db747c6e929ecaef0c1c6f76a719afddb43bb17a64ee1d478f2f8/detection ! https://safeweb.norton.com/report/show?url=192.243.59.13 ! https://www.siteadvisor.com/sitereport.html?url=192.243.59.13 ||192.243.59.13^$all ! https://github.com/DandelionSprout/adfilt/blob/a0f6bdcc309cab585502c76ebd70c088995a3d17/Dandelion%20Sprout's%20Anti-Malware%20List.txt#L955-L5713 ! https://www.virustotal.com/gui/url/59077166c998073d0f809f35fb035256e8ee263f2136e783c82cd6017aad4029/detection ! https://www.virustotal.com/gui/ip-address/192.243.59.12/relations ! https://www.virustotal.com/gui/url/8041adaabbd884df4712bdfa8794bdbcf37dfaa8f06164bbe6df2ba79c2eaa72/detection ! https://www.siteadvisor.com/sitereport.html?url=dustymural.com ! https://safeweb.norton.com/report/show?url=dustymural.com ||dustymural.com^$all ! https://www.virustotal.com/gui/ip-address/192.243.59.13/community ! https://www.virustotal.com/gui/url/5eca62948cb380e8b8def8a250d91210df2c7385799fcc3b9f0b0df28b1fdd1b/community ! https://www.siteadvisor.com/sitereport.html?url=disappearanceinspiredscan.com ! https://safeweb.norton.com/report/show?url=disappearanceinspiredscan.com ||disappearanceinspiredscan.com^$all ! https://securelist.com/triada-trojan-in-whatsapp-mod/103679/ ! https://www.virustotal.com/gui/url/0b120a9c2738941087d223c40ece8fa7dc55fa3a6d7c008453dfe5c91bb82a03/detection ! https://safeweb.norton.com/report/show?url=t1k22.c8xwor.com ||t1k22.c8xwor.com^$all ! https://www.virustotal.com/gui/url/2f6c66a1a35d8dd21285c682f553248e9bb684076286d3463c2bd62ff2c739cc/detection ! https://safeweb.norton.com/report/show?url=dgmxn.c8xwor.com ||dgmxn.c8xwor.com^$all ! https://www.virustotal.com/gui/file/2ae6d71d98d6324da50e8c3afc3d54fddb2ab62b139ef75dad2d20b190122c80/relations ! https://www.virustotal.com/gui/file/66d7b16d21ff17d484d2075f8aab0b1593909bd31fffb04d004fbf6c581c716d/relations ! https://www.virustotal.com/gui/url/acc176a8e973e15cb52ef54d0b39b68aab76678da2fcbf77fbbfbb5c86b52e96/detection ! https://safeweb.norton.com/report/show?url=seven1029.com ! https://www.siteadvisor.com/sitereport.html?url=seven1029.com ||dooe.seven1029.com^$all ! https://www.virustotal.com/gui/url/f10c6bbda4fb2f424a7701ab7f05b259976deb36e65f1f677eeb60d7560a91d2/detection ||seven1029.com^$all ! https://www.virustotal.com/gui/url/3f0c4103951e5b74cf32c908243c1df595bd7a02a46eb708ba6d6bfc96523578/detection ||didk.seven1029.com^$all ! https://www.virustotal.com/gui/url/44f87f9c7440a793c5c0b065d719e89aa13dcc19c3d4d3bdcd90675e951cfdb4/detection ! https://safeweb.norton.com/report/show?url=awsd.publisherhunt.com ||awsd.publisherhunt.com^$all ! https://www.virustotal.com/gui/url/460537a1001eb65e56924c17db8da0faca7043fcc5eeb699a8d44bfd5c850c56/detection ! https://safeweb.norton.com/report/show?url=log.koapkmobi.com ! https://www.siteadvisor.com/sitereport.html?url=log.koapkmobi.com ||log.koapkmobi.com^$all ! https://www.virustotal.com/gui/url/55d3178deb5151fd5c5a2f5d81b9204e06d0bc5fdf5a804991c1999493263279/detection ! https://safeweb.norton.com/report/show?url=down.dd799aa.com ! https://www.siteadvisor.com/sitereport.html?url=down.dd799aa.com ||down.dd799aa.com^$all ! https://securelist.com/apkpure-android-app-store-infected/101845/ ! https://www.virustotal.com/gui/url/866a25343864f03dc5a10105fda523bfbb6ed09c486d07fd31ca2b5306440089/detection ||wcf.seven1029.com^$all ! https://www.virustotal.com/gui/url/1636952e7dd793f4edbe0014615d76685264464aeb5cb574b580f932f0907dd9/detection ! https://www.virustotal.com/gui/url/9c66e331e455dc5c5c9d06e1a537580c9e4db279182d2285c07783e837806a16/detection ! https://safeweb.norton.com/report/show?url=foodin.site ! https://www.siteadvisor.com/sitereport.html?url=foodin.site ||foodin.site^$all ! https://forums.malwarebytes.com/topic/277965-your-system-is-infected-with-3-viruses/ ! https://github.com/DandelionSprout/adfilt/issues/262 ||lucdream.com^$all ||beastbuying.com^$all ||kokotrokot.com^$all ! contains porn ||pesoaniz.com^$all ! Fake popups ||rtb-8.novitrk1.com^$all ||cu27t-evo29lution.xyz^$all ||doneonline.xyz^$all ||possessedcrackinghart.com^$all ||typiccor.com^$all ||apsolutamente.com^$all ||time4news.net^$all ||secureleadsforever.com^$all ||pushmeup.art^$all ||eu.pushmeup.art^$all ||trc.artofads.co^$all ||pc-my-protection.xyz^$all ||beta-news.org^$all ! https://forums.malwarebytes.com/topic/278166-my-website-is-labelled-as-dangerous-by-malwarebytes/ ! https://www.virustotal.com/gui/url/68ccee4530342ae6ea690a0ef786f040a3d9a0d1bfc08c4b857af71ac8e90954/detection ! https://www.virustotal.com/gui/url/14cfdccc23aac9ffaf051675efcda240f2e83a5cd34403e412f0f2959e42a536/detection ! https://www.siteadvisor.com/sitereport.html?url=serena-west.com ||serena-west.com^$all ||www.serena-west.com^$all ! https://forums.malwarebytes.com/topic/278209-removal-instructions-for-socialsearchconverter/ ||socialsearchconverter.com^$all ||install.socialsearchconverter.com^$all ||feed.socialsearchconverter.com^$all ||api.socialsearchconverter.com^$all ||notify-service.com^$all ||install.stream-all.com^$all ||stream-all.com^$all ! https://www.virustotal.com/gui/file/eac230dd8a6ed40c405caf5e79b60cc7a4e96435873a2b28658c24bdf3550b42/community ! https://www.virustotal.com/gui/url/ed7b160ae31731f6381205c0885ea74d340dac8f94d6dfb88d8806819087678f/detection ! https://www.virustotal.com/gui/url/a112bfbb50b23254eeac7e5d323598fd2a0bb85870dc9b66bf3e3e9a73aadc66/detection ! https://safeweb.norton.com/report/show?url=91.243.44.5 ! https://www.siteadvisor.com/sitereport.html?url=91.243.44.5 ||91.243.44.5^$all ! https://www.virustotal.com/gui/file/70e670504b603ff4e7d5f2fd1d79267c36b55446e63f7c408322135f7416ca27/relations ! https://www.virustotal.com/gui/url/69966a5410b5e4986d1ef988c5a5753783d457e4e485fd65dda0e8333648aa24/detection ! https://safeweb.norton.com/report/show?url=qurl.qh-lb.com ||qurl.qh-lb.com^$all ! https://www.virustotal.com/gui/url/a39970d1ea9aa43a4905e4c7bc324be07ea910058ffceb9d1e5e07f3e71f1f13/detection ! https://safeweb.norton.com/report/show?url=104.192.108.20 ||104.192.108.20^$all ! http://vxvault.net/ViriFiche.php?ID=44013 ! https://www.virustotal.com/gui/url/8066b87ad10ddb5466bc307bb48454139572f6c8c8f80a9734275ac89cf966af/detection ! https://www.virustotal.com/gui/url/826c451929420c4da32552f967fb1cab6467405a29c65b23802aaadb6a8c7505/detection ! https://safeweb.norton.com/report/show?url=192.3.110.170 ||192.3.110.170^$all ! https://www.virustotal.com/gui/domain/kirstialechulbard.space/relations ! https://www.virustotal.com/gui/ip-address/198.54.117.244/relations ! https://www.virustotal.com/gui/url/6aab797490c49b7f009a3dedf6802cd8806251d219dd51b4f8882463464b6a8b/detection ! https://safeweb.norton.com/report/show?url=dashwoodestates.com ! https://www.siteadvisor.com/sitereport.html?url=dashwoodestates.com ||dashwoodestates.com^$all ! https://www.virustotal.com/gui/url/9409fb979b234010afd377fc3839eb775243e126063a123cbd7d46cdbda6f39a/detection ! https://safeweb.norton.com/report/show?url=vm-business.online ! https://www.siteadvisor.com/sitereport.html?url=vm-business.online ||vm-business.online^$all ! https://www.virustotal.com/gui/url/3d98488e5a056cc670da414d8edf0657b379151d8ed07689becccae1a584aa5a/detection ||voice.vm-business.online^$all ! https://www.virustotal.com/gui/file/c683bc3da4966110b419ac54d09a54ce798efdb51be398331d9ce011e2636fa9/community ! https://www.virustotal.com/gui/url/5618023ed5a768d7f879c0d599b9ba7cff0e9171201981256eeaf5ce8eb09fdb/detection ! https://www.virustotal.com/gui/url/8cf9ca3359f17cf92b9b3e5fdab30e29be23f08e66c8c5396c9410fcb91f7c3c/detection ! https://safeweb.norton.com/report/show?url=91.241.19.38 ! https://www.siteadvisor.com/sitereport.html?url=91.241.19.38 ||91.241.19.38^$all ! https://www.virustotal.com/gui/file/e63b2d03e3fee2d538f8bd721b61dd3641284fa941087d846dea6f15cab40308/community ! https://www.virustotal.com/gui/url/71c48d1b40deb972ccc2ee44ba7c196d2e8c1019d5d1a1b226f587a01083eaa7/detection ! https://www.virustotal.com/gui/url/fbbc8a671bff32539bd829a76f6df9f364a21ac2279922e64e3ec494a1669dd3/detection ! https://safeweb.norton.com/report/show?url=kiff.tech ! https://www.siteadvisor.com/sitereport.html?url=kiff.tech ||kiff.tech^$all ! https://www.virustotal.com/gui/domain/kiff.tech/relations ! https://www.virustotal.com/gui/url/dc038496b1b5358b97f89440135ec91258b406c40859a2cd95983dc7a81e0cfa/detection ! https://www.ipvoid.com/ip-blacklist-check/ ! https://safeweb.norton.com/report/show?url=45.90.58.90 ! https://www.siteadvisor.com/sitereport.html?url=45.90.58.90 ||45.90.58.90^$all ! https://www.virustotal.com/gui/file/e565ba89d034418fd26a5f642f6eeee4d72ee3b8dc69523419b7ca8dfd452730/community ! https://www.virustotal.com/gui/url/d73b984a969e4dc818058099d7f7ef3dd2970a16b9b0bc11c1a489f59006411c/detection ! https://www.virustotal.com/gui/url/e3a9189a1e1256beba8e0fc3abfeab6acb09f7f8cabfd973e22be9f77bb6886f/detection ! https://www.ipvoid.com/ip-blacklist-check/ ! https://www.siteadvisor.com/sitereport.html?url=95.85.89.98 ||95.85.89.98^$all ! Malware - see https://github.com/DandelionSprout/adfilt/issues/267 ||codedexchange.com^$all ||trkk4.com^$all ||us1.trkk4.com^$all ! https://www.youtube.com/watch?v=xOw1vct-wHg ! https://www.virustotal.com/gui/url/95f8db6ff866ba200658f9c25c8a5484ca4f771ae3ac3aba8694129a7f18ec0f/detection ! Dead ||hpprintersupportservice.com^$all ||how.hpprintersupportservice.com^$all ! Not dead yet - https://github.com/uBlockOrigin/uAssets/issues/9933 ||1redirb.com^$all ! https://github.com/uBlockOrigin/uAssets/issues/9933#issuecomment-913677276 ||greenadblocker.com^$all ! https://www.virustotal.com/gui/file/76bbdd6144d670f4b0e425238d2ec42800711bfaf882dad3ec7f47ac37f2ddd9/community ! https://www.joesandbox.com/analysis/478416/0/html#domains ! https://safeweb.norton.com/report/show?url=192.42.116.41 ! https://www.siteadvisor.com/sitereport.html?url=192.42.116.41 ! https://www.virustotal.com/gui/url/3533f84c788018487e9d61431395c7de544a4af520ddcbf5bf6a424f072644e3/detection ||192.42.116.41^$all ! https://www.virustotal.com/gui/url/bbcc2e606c042c43fdb249b34b1199aca3ec916ed041b5ee1df8da20dc0530b0/detection ! https://www.virustotal.com/gui/url/bd8d650fe454b45c35ee2995082740678c7fad50f3e440f2d53b3bfaeee0e774/detection ! https://safeweb.norton.com/report/show?url=103.91.245.36 ! https://www.siteadvisor.com/sitereport.html?url=103.91.245.36 ||103.91.245.36^$all ! https://github.com/blocklistproject/Lists/issues/456 ! https://www.virustotal.com/gui/url/383e601492df662f7612beea0e02d336a3ee39e864db40d03fe72d4f3fe4c2e4/detection ||discorcl.link^$all ! https://www.virustotal.com/gui/file/e0bcfa34b70aee7aac21a653f9e7012d9531bcda12ee4b8910d8031a0f61e456/detection ! https://www.virustotal.com/gui/url/9ecc5932f5ae18a389e92ff12271536057264ab5dce047e91614186bec236b92/detection ! https://www.virustotal.com/gui/url/c6371d78b98d90f3fd2762da13a3cc8942f69e451d15a22c56ff1e2f34cb322b/detection ||209.141.42.149^$all ! https://www.virustotal.com/gui/ip-address/209.141.42.149/relations ||atvhost.live^$all ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ! https://www.virustotal.com/gui/url/fb40521e259d30376f8434fe7c1672ce71fca1b20586ea65cc8aa598d5275206/detection ! https://www.virustotal.com/gui/url/576c867dfc2462dc645bc99f7370f4eb5634de68c37e7e6d71fb042ea41695f3/detection ||115.56.84.78^$all ! https://www.virustotal.com/gui/url/f10539623f2ab79973bfef804bd94bbef8e87bb4fa31156c1d84f0faf17f61bb/detection ! https://www.virustotal.com/gui/url/813e58535aff0b73c2e9626c7c1ef8e6402cd266d6b9ce8c70df02df4ccd774c/detection ||119.119.180.149^$all ! https://www.virustotal.com/gui/url/5c4ceaf411e896720998f80e0b65a375e299fc3232293a27879d507c960bce8b/detection ! https://www.virustotal.com/gui/url/02daf628187b42af1a2383998e7141dc5ef94f8e995e8688f786622078273e5b/detection ||42.237.253.8^$all ! https://www.virustotal.com/gui/url/da05d41f8552886888ffca8f1ac59e9e26945b00206256e162dcc7f6b3934102/detection ! https://www.virustotal.com/gui/url/3eb6da0e8185db5430344e2b4452aa3a982ae0e5b55c7ff062c2575efd5a9842/detection ||219.154.110.173^$all ! https://www.virustotal.com/gui/url/469f75fe271e3f85f2250e92992dbb00ccc8f2171f33ff3d6b9e3d6316d437ee/detection ! https://www.virustotal.com/gui/url/49b8a7cd639d9ca782a5f05b70e7f9ef8446ad3301d13a3cb919d8532e69b4db/detection ||175.174.111.246^$all ! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community ! https://www.virustotal.com/gui/url/36aa6f00fa9e6d155f806d816e6f3655ee6620d730ac184366c13f722c4658b4/detection ! https://www.virustotal.com/gui/url/340b719a8837637708579c0e972c556a37270bf0fdcac0d2263178daf6968c9f/detection ||113.173.55.113^$all ! https://www.virustotal.com/gui/url/9b876302188a3663cf7c21129c97c5355e1e5dbf833b8ac01daa80448c6c755f/detection ! https://www.virustotal.com/gui/url/b7785cfa63576f46b250ecb1b918763d9fac1760bd846491cbbbd823a8ba9fd8/detection ||27.5.37.220^$all ! https://www.virustotal.com/gui/url/5a311de5c1b80dae6389ef3e8d1d6f900d9f8f9bd3afd60eaa687c464d548eb7/detection ! https://www.virustotal.com/gui/url/d4054ebdc5092023c4aa52b817a72cbe93f457d5a5accc986aa5bdb8d9091759/detection ||115.51.107.100^$all ! https://www.virustotal.com/gui/url/acea61b0e08c865b5af0585ae3d11c0daf033eae11344b6e22c5853b6d6fbb3b/detection ! https://www.virustotal.com/gui/domain/hidusi.com/relations ! https://www.virustotal.com/gui/url/c08e14de4fa564217e43a4bc2404eafd64a5e09b70123573d3622d76acae5020/detection ! https://safeweb.norton.com/report/show?url=23.106.160.25 ! https://www.siteadvisor.com/sitereport.html?url=23.106.160.25 ! https://www.ipvoid.com/ip-blacklist-check/ ||23.106.160.25^$all ||make-hex-32332e3130362e3136302e3235-rr.1u.ms^$all ! https://www.virustotal.com/gui/file/cf069e759af3f20240bc049a2138cfa3b4cb5fc1c8ad3d75a60cfaa73660b521/community ! https://www.virustotal.com/gui/url/8ba233e5f93b09990725d4b09a32031735266e8c3b93e93ec58e87605153f019/detection ! https://www.virustotal.com/gui/url/95283afc70ba5d521a07325a3520b6d869d12506b3af94de2f66a3a265b2734f/detection ! https://safeweb.norton.com/report/show?url=103.169.90.205 ! https://www.siteadvisor.com/sitereport.html?url=103.169.90.205 ||103.169.90.205^$all ! https://www.virustotal.com/gui/file/754baa6b4007335878ec474d4347f7a8bb42a9955324e84365f8c98c0d376617/community ! https://www.virustotal.com/gui/url/79b4268ad9a44992952a4bd7f3f303b20d18505f9cb52e1280cda81dbabc6f56/detection ! https://www.virustotal.com/gui/url/dcab7126cf867de5541a32602616a4bb1791adb9f9f68a3ef9c35eca95095140/detection ! https://safeweb.norton.com/report/show?url=down.rxgif.cn ! https://www.siteadvisor.com/sitereport.html?url=down.rxgif.cn ||down.rxgif.cn^$all ! https://www.virustotal.com/gui/url/b6ce9c30e13dd43df6c8181c61b2811b25087647d0a3f806928af800bb54a042/details ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/detection ! https://urlhaus.abuse.ch/url/1613433/ ||175.175.60.215^$all ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ! https://www.virustotal.com/gui/url/4cb8d7942539113f80a3268efda9f64de9a670b62102a29f9da7deb6c13b45d2/detection ! https://www.virustotal.com/gui/url/339b21c33517908fa2d9d40e160920aa105b151987490e0677632cf4025473c3/detection ||183.190.233.129^$all ! https://www.virustotal.com/gui/file/a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3/community ! https://www.virustotal.com/gui/url/824fbea82bf60c0be698488fc8f7ffca6b63288385166aa0b8e10864da2eb390/detection ! https://www.virustotal.com/gui/url/76a1f0c0d6e18b10d4071041d790df5e79656f83b2117a83c157b46b511ed636/detection ||124.230.96.62^$all ! https://www.fortinet.com/blog/threat-research/new-dridex-variant-being-spread-by-crafted-excel-document ! https://www.virustotal.com/gui/url/decd93d11b3c229c9ed577674f76e52bb7a85f0997de3175b9392ac502f9d7e5/detection ||reportingdashboard.mobilisedev.co.uk^$all ! https://www.virustotal.com/gui/url/48777f508ff2e0d71d814a6a93350374bcee2cdd4b49678833974ad846a12d37/detection ||loans.uhuruloans.com^$all ! https://www.virustotal.com/gui/url/aaa6994965e6ecd32b9cec3ca4fe638a7ebc89f52fcda04354324030ca913bec/detection ||practice.haylawdesign.com^$all ! https://www.virustotal.com/gui/url/5463e8eb63b1dbe0fde30327cfa7ad88a245c2db7c1661dcf5d5a6cec0e16bd0/detection ||103.75.201.2^$all ! https://www.virustotal.com/gui/url/89f7b236a65351daf4fa455e356889e33f8460e9b24521a4004f57e932b3e1d3/detection ||158.223.1.108^$all ! https://www.virustotal.com/gui/url/8c32db8423bad95d01c5fb8a1ed6eefed087c66ab2973c5011f36487f40100a2/detection ||165.22.28.242^$all ! https://blog.malwarebytes.com/threat-intelligence/2021/09/the-many-tentacles-of-magecart-group-8/ ! https://www.virustotal.com/gui/url/a485ff18c6fa75d246e5126b575975dbba6d09e27bd2bd8cdb8d918db4a723ea/detection ||adaptivestyles.com^$all ! https://www.virustotal.com/gui/url/3946eec45e9748c4fd6f3719a5ed1da0ffa2ef3849c33d30d09f075da450c111/detection ||anduansury.com^$all ! https://www.virustotal.com/gui/url/23f5ab0e022c0809f116f569e65d8282bbd6ce6154b82e3ec3611fb23159d2c2/detection ! https://www.virustotal.com/gui/url/294e3ed4ac955a08ee94ea29db0aa951a1c26596a33b8b134168e0ca5e9b468d/detection ||bootstrapmag.com^$all ! https://www.virustotal.com/gui/url/d1c684e861d500e9a4906444714b83de95432d240998d04d16efde7ba80d1521/detection ||cdncontainer.com^$all ! https://www.virustotal.com/gui/url/b152f0840b773944f8d10649478a5e0b900731b65b666d8c581231d2654f37b6/detection ! https://www.virustotal.com/gui/url/f14e0141dec9d7c6b2939994de7081e9ef03001e9eb6c91f40457c7b746876b0/detection ||fileskeeper.org^$all ! https://www.virustotal.com/gui/url/00de113cc0bea8bb5578d87eac425d4d8f71bc5c31626b8eb887a86b67dfbf21/detection ||foodandcot.com^$all ! https://www.virustotal.com/gui/url/d3afeb2c8a0137ed82cbfb70a8067d4e7720c0cbb6d404bc9ceb6cde1d302707/detection ||freshdepor.com^$all ! https://www.virustotal.com/gui/url/71ee0701f19ab89e50368e336e9b3eabf660f7f74a95474987b191bc8d80fe34/detection ||hottrackcdn.com^$all ! https://www.virustotal.com/gui/url/af31cd44ec4fe90c6d88d1a0dacbe0f768a23f94cb60e1716e87c69bc293989e/detection ||hqassets.com^$all ! https://www.virustotal.com/gui/url/b840868505974ace590d2ca132e8c33434e8dba726b357f5e305351ed2306682/detection ||mechat.info^$all ! https://www.virustotal.com/gui/url/eaf35269bcb4fe4add856841d2e981a0eee357c7835b4ece24d7b166b1fc0fed/detection ||paypaypay.org^$all ! https://www.virustotal.com/gui/url/8b1bb2aa6c7ef4bee926d80b14c1c99f2febd7e5934b6cbb473f4f2b444ef3b4/detection ||scriptdesire.com^$all ! https://www.virustotal.com/gui/url/ba10ead0d37648fd38b3e366092f61efc462ae29ea78083096d440222715a80f/detection ! https://www.virustotal.com/gui/url/2f13a1f4566290252fa85d94a253450d68bdab55a083dc0481299624de2ef73d/detection ! https://www.virustotal.com/gui/url/bb71a2ac6c579e62cb347912b77a3a30afe194e88ae22316fc85d2d97290f8a1/detection ||stairany.com^$all ! https://www.virustotal.com/gui/url/d21b0a44b181ea1af33964ee18027810afc0492f2b5f505727cf065bedebd74e/detection ! https://www.virustotal.com/gui/url/53242dabbd11c63cdcf563da593b1cddd08e7670dc00c489af37809f1010b13a/detection ! https://www.virustotal.com/gui/url/bc297e7f7204db51aaca536d51001b459d378fb7af1f336417e199374192bb2c/detection ! https://www.virustotal.com/gui/url/905eff316d9e0296e41a93115777152e8ad266865a73f2bb76fb45c3384b1ee3/detection ! https://www.virustotal.com/gui/url/9d4c1c222a329bf7844aab12cb06b5af233d590483102ff93d81aa8431abf5d0/detection ||verywellfitnesse.com^$all ! https://www.virustotal.com/gui/url/ff76a8094f3aba79b59966749d6673a0b9cb85c582814244320fff05357e0334/detection ! https://www.virustotal.com/gui/url/b44775de81e9c97e08ca8d6636217944c26e1315ae81de627909035ec1dea31e/detection ||webadstracker.com^$all ! https://www.virustotal.com/gui/url/7b99f29ee9883131be40f8171609fbb34149cb8478cef1eca15cb7ba7e75dcb6/detection ! https://www.virustotal.com/gui/url/bf8ab182ae67200ea5af21c2e651183aa429263071c39e9b8ce7d6de77fc786f/detection ! https://www.virustotal.com/gui/url/878a96cd3ac82336deafffaa0eed37b328f2d6e9bfce20212c0be6236450092f/detection ! https://www.virustotal.com/gui/url/8f2416a4c90c791fdfb99741d25f1f38d3f3712598e1848cc4319fddaacc775d/detection ! https://www.virustotal.com/gui/url/c8c43c71728fd48329562a3bf20a68b96dc641e45ff9469d28a2b3fbeef633f6/detection ! https://www.virustotal.com/gui/url/a9575c1df3dd1e98bb8e643b7c0f0a970e055950d53df87a4421fd3f7d846ef6/detection ! https://www.virustotal.com/gui/url/d9e2568a8b6a18b2bf0a6d47c5200b57f62ab5033c85843ebb70a385cf8c75eb/detection ! https://www.virustotal.com/gui/url/0b039602394e771af6323451ae5d3e88dfd0e63906eda39416c7dd1ba33124c0/detection ! https://www.virustotal.com/gui/url/f95a1345061e81292a47c177e9aaf8af0b51ce6d82b2ea40cc324623ee203d43/detection ! https://www.virustotal.com/gui/url/7a308c86e497076a50c8f353e5d2a104724dfb36a6b439a98358bf4edf4833fb/detection ! https://www.virustotal.com/gui/url/db9df4312b48c2be39d221a5930744465cf7512cd991ff6f695328fbebbe4c09/detection ! https://www.virustotal.com/gui/url/f404ec1c44eb659e8f06c4306e8e09f4d37b0913bee4ef6bb0151a21a0d33093/detection ! https://www.virustotal.com/gui/url/3d93f9133a3fb1849c98f2ead58ce481de7cf0c44c248e155291722934cb9c2b/detection ! https://www.virustotal.com/gui/url/542e6fc839c26a790786a211801ad0d3143ab31c00915c0268330c79cf15b79b/detection ! https://www.virustotal.com/gui/url/025ffe441f66e1972b6087088a159a487e549c0159f2dff6a85b05646b0eea2f/detection ! https://www.virustotal.com/gui/url/9383a03c04ae3ac308ccd4e5e91ec8d83937b8794ddd42916137dd4c6c3b811d/detection ! https://www.virustotal.com/gui/url/72ae17db6d0779a2da12f211bc4d1f9bba0a74cc0f7d2fed1430742f7e06f59f/detection ! https://www.virustotal.com/gui/url/6f362a27f6dab71a6f642a1a1977a91d7828051391ad24aa94e8d071c746c4ff/detection ! https://www.virustotal.com/gui/url/0dc14d709f65a39862293619b4960152b7c9f780af06120cb93fd47f641f2880/detection ! https://www.virustotal.com/gui/url/fb556aea3842a6cda3eb95e53a1a20b2d38ed75aadd6cd70bcf2d86fed8d6222/detection ! https://www.virustotal.com/gui/url/c33de2f2d87159af84e1b99f2511c6edff096300499bcdbc8464d1d34b3866a5/detection ! https://www.virustotal.com/gui/url/0af25fcc819bda5e177b5920e83de7803fda5bbd42bc47ead8eb27a6c70910a6/detection ! https://www.virustotal.com/gui/url/818307dc1655ea9be3ab64fc225512af34740206d14dc918d4726204798317fd/detection ||gctatic.com^$all ! https://www.virustotal.com/gui/url/31c6d53dfc491391f27ba77dfaa2f13fe2165b4a99f8a155d9044724677d4a80/detection ! https://www.virustotal.com/gui/url/97dd15f688d6562742882a3b590876fdb66c41185a72a953468b8a70b84d3032/detection ! https://www.virustotal.com/gui/url/ad648a05cecd440278b30e81f20490c1353c7dff646c0e84c7afb431d4f3631d/detection ! https://www.virustotal.com/gui/url/afc9b9a20d19c9b8919ce192a45adcf120973a7f0c120debb10c788faeab7906/detection ! https://www.virustotal.com/gui/url/207ce8793a591db4259b11450c2a69d94774d75a035cb1272442e3c11cd3b7f3/detection ! https://www.virustotal.com/gui/url/fea4740608070496e9f0783ea612d410300a96ea9c332072a451e773f7ba10d9/detection ! https://www.virustotal.com/gui/url/d93cf430da35ed153ed39af82d7db3b5c20c28ddd1bfdbacb926bea8459f4a17/detection ! https://www.virustotal.com/gui/url/dc224282fa8f1a4ee1f3f27cb99072f48e27810472385c402599973e93011e7e/detection ! https://www.virustotal.com/gui/url/f54c89f54c19f0e7c3e461fd2020e0cc7faa973b2311833681e1bb8170115018/detection ! https://www.virustotal.com/gui/url/4c98e91d5885770fc997531fd7960e884935bff8d7eb61b59c0dbbe3d544e864/detection ||googletagmanages.com^$all ! https://www.virustotal.com/gui/url/56d1f827ee0481025f6afaffb6ecc2e1acf06c1ab30d40f9863cc679e9e7e50d/detection ! https://www.virustotal.com/gui/url/d0f3beccece1a7982123232f558cbee1d2f0e6143c43128e08206cdd692b38b6/detection ! https://www.virustotal.com/gui/url/395f6f3c7ae32a12d1ca1efa9aa7c4bc2cbf8d7fe2f062eb34647ab1a4e21d36/detection ! https://www.virustotal.com/gui/url/a689445532312190b1b61bf08c4fb65a193262dd74555cca389364688315635a/detection ||gstaticx.com^$all ! https://www.virustotal.com/gui/url/9ed68f799d614dd1586a8dc075e74b44f881f43c75cd1826f80edae0936bce0d/detection ! https://www.virustotal.com/gui/url/3067c0c0cb6f8b0ba7196afe3b5cdd761cd1a00780de7802e98ab145875e6fdf/detection ! https://www.virustotal.com/gui/url/280b38a0719b139e13757f200040f3bb4889358ea57b0aaeb740b4a44a2054b7/detection ! https://www.virustotal.com/gui/url/0c580403f7f5fee7e61e272de583ebc13c462b886db2a0af858be1693581c261/detection ! https://www.virustotal.com/gui/url/c217d2536fca71dee04d63aa2977424eb4bd41bfdf6d42e3107aaf1b7ff0b55c/detection ! https://www.virustotal.com/gui/url/4afa69e2ba418cf00b9a1077b7ba068698bb1728c9051e85d6f37926fc29fc8f/detection ! https://www.virustotal.com/gui/url/bba90dce422fa955d826082203f6b135e76dd2cdb07b934c103f7415574eedb0/detection ! https://www.virustotal.com/gui/url/febbe9594d25c0d1b81b4db59816a08c5021eb4eab5a803ef061149a0e93d861/detection ||validcvv.ru^$all ! https://www.virustotal.com/gui/url/b4b681701df04dfdeab6b95689e7df45efb1ceca7e2f3305a476f0999f3c4f08/detection ||176.121.14.103^$all ! https://www.virustotal.com/gui/url/74695bde3e2e0c51ac36476349504c99d4ec93cea71e6400cc91b1d02735fa98/detection ||176.121.14.143^$all ! https://www.virustotal.com/gui/url/7cece1e3a1bfd2abb808b2c9841447647c33aed7139870d134e8d31432d269ba/detection ||176.121.14.189^$all ! https://www.virustotal.com/gui/url/9f4b9325aa1ffca2f76a0e89d1d0c1f8adda5ffd93a4f621a8d7e0f70ef94364/detection ||178.33.231.184^$all ! https://www.virustotal.com/gui/url/ad663f4eaf473695742bb36f91047a7cc2fdf78040d321da4707f8f4af7994bc/detection ||194.87.144.10^$all ! Typosquat ||googletagmaneger.com^$document ||googleusescontent.com^$document ||googlutagmanager.com^$document ! https://www.virustotal.com/gui/file/17b08e4418f813543e91ad18ae2e50ecfe40692d9b5dec854e94ec0abbc92b11/relations ! https://www.virustotal.com/gui/url/b811ee21aa14f8f63e8911bfa608e81f4cb8125c8bac847b8e4eae3da81b362b/detection ! https://safeweb.norton.com/report/mobile?name=midwestamericanwoman.com ||midwestamericanwoman.com^$all ||www.midwestamericanwoman.com^$all ! https://www.virustotal.com/gui/url/2245c69a63d9303e4967c776393b92132c38437d6f7dd501bef681c796c5a835/detection ! https://www.virustotal.com/gui/url/91fc2b7b96fee98beaebda6a48e0b54881c81f42901ed2b1d64977a759512b71/detection ! https://www.virustotal.com/gui/file/543694f8b09a565a88932457d40d16cd85ac3f0b7be9ad322ef9486144379449/relations ! https://www.virustotal.com/gui/url/c26a3e1752e06b6d7fd5317ffaa118163d5f9198c49fbba033d542f26a397e30/detection ! https://www.virustotal.com/gui/url/32731a33a5e44e8dd2bf31f06659451f232e318ccc5ef378d6d19647fcb87592/detection ! https://safeweb.norton.com/report/mobile?name=megida.hopto.org ! https://www.siteadvisor.com/sitereport.html?url=megida.hopto.org ||megida.hopto.org^$all ! https://www.virustotal.com/gui/file/97ea895e92f76192010e02f12aca8ec4ffa1b667e84c9958332d280ced624402/relations ! https://www.virustotal.com/gui/url/68c29c4a05836f3b1d417b3d3e805d2b14a0e6123af93d0f7ebdeba65727d3a0/detection ||34.102.136.180^$all ! https://www.virustotal.com/gui/file/cee0080bd36926b6cd481ac8219cccd8061c6369ffd8e99579d6572f0bbf7d79/community ! https://www.virustotal.com/gui/url/4be4336012c414b1d909a33a76425c7dcc9b6faaadf4f6f2f66ba777efe9f8b4/detection ! https://www.virustotal.com/gui/url/8746852bf1bd1aaba5bf3bda572d7ab983d7f0b607f2aad8679fbd3148736b9c/detection ! https://www.siteadvisor.com/sitereport.html?url=tacos.gg ! https://safeweb.norton.com/report/show?url=tacos.gg ||tacos.gg^$all ! https://www.virustotal.com/gui/file/ed67d2958f942f4beca20ac7ac8067f5af0196500af45b596d8e241d81d5f782/community ! https://www.virustotal.com/gui/url/b8565f6d2ed4e276fa2a6b0b78c4d664733d16dba225a92abb77ebdeadfd9f55/detection ! https://www.virustotal.com/gui/url/066b788edb38d41cb37d37804d0876ce0c8b638d7413f8994f1133b3d4aca3ec/detection ! https://safeweb.norton.com/report/show?url=103.167.90.59 ! https://www.siteadvisor.com/sitereport.html?url=103.167.90.59 ||103.167.90.59^$all ! https://www.virustotal.com/gui/url/83f953236ca2db72e6b1f29124eabb108531164a886e2f4b4a4392e5fa6a31d7/detection ! https://urlhaus.abuse.ch/url/1625361/ ! https://www.virustotal.com/gui/url/9ad021dd4ce4c664275b0323ef1bebb083c7ec0b58e628a106243f533538f481/detection ! https://www.virustotal.com/gui/url/542708d203696c61a73a8f5fc63c61ec7a9bd2a35181947227355f7061ba2a46/detection ! https://www.virustotal.com/gui/file/49113451c4baac2ee6b97486bd1f57dcf68891d55ff4782daa4d578e23e78d7c/relations ! https://www.virustotal.com/gui/url/3c8a2e8d244d06ec62b070ee4886fa9011161d3c79793cadbc824644cdb53a41/detection ||194.145.227.161^$all ! https://www.virustotal.com/gui/url/770c2701451a00d72aa5a1424e50b632309921ca9f187c1ff661be65969e18df/detection ! https://www.virustotal.com/gui/url/4c5a0fc42b8374b889bde94b8189a8be9f8c7fd5bfd1107e5588410e2359a53d/detection ! https://www.virustotal.com/gui/url/50d8e148f03ea0b5e78df4443de8fee256d2d3437520d7eda0c133fd7d368aea/detection ||45.137.190.31^$all ! https://www.virustotal.com/gui/url/4004f0b5afacdd462f4612ef453a3226dcc9cfe59f17c6a397ad499951d2cc69/detection ! https://www.virustotal.com/gui/file/f5af3aadb754d10407bf013ceea95d75742db4cea8e9539db369df14577c18e1/community ! https://www.virustotal.com/gui/url/2ad4a25fd971359e6754edc69fc4093d0352aacb1d2bf4a26ac401ed39f44ddf/detection ! https://www.virustotal.com/gui/url/94a899bfdfda78f281c1a470e24fa5d105ce7d7d8653490cc09e091f22bb04d6/detection ! https://safeweb.norton.com/report/show?url=hiibs.com ! https://www.siteadvisor.com/sitereport.html?url=hiibs.com ||hiibs.com^$all ! https://www.virustotal.com/gui/file/00faaf68512770431f268aa1a1a26f8c589a3f53298db6311fd38f263fe0d474/community ! https://www.virustotal.com/gui/url/a071ccb6d559078eee866ecf571ee4e2e6cd21f9e0c15882202c56b9043946e1/detection ! https://safeweb.norton.com/report/show?url=frankohacker.strangled.net ! https://www.siteadvisor.com/sitereport.html?url=frankohacker.strangled.net ||frankohacker.strangled.net^$all ! https://www.virustotal.com/gui/file/04e98a900ca361b68ebcfbad6453ddc626d93c8afb13916c18dd0e9648187566/community ! https://www.virustotal.com/gui/url/5f7645999a4c9ab439c0c9778262e07320b9f71831a6a10bd1b747fe6570149f/detection ! https://www.virustotal.com/gui/url/419738e57727f1c69d475e3868433c7990689badec09045e737da9557801d4e7/detection ||198.12.107.117^$all ! https://www.virustotal.com/gui/file/04e98a900ca361b68ebcfbad6453ddc626d93c8afb13916c18dd0e9648187566/relations ! https://www.virustotal.com/gui/url/7fd67f827526f026471d1fed36afcd05f86a714a62ec068ccba83269e6d53c88/detection ||45.33.23.183^$all ! https://www.virustotal.com/gui/url/ad7757fdf475c2160f0ad590a49751c647a5c0971c3e75aa1078c42d6833ccb7/detection ||45.33.2.79^$all ! https://www.virustotal.com/gui/url/3a5e3ba3e48338af279942f6002ec38048f98453c59a2296f413526a4472ddbb/detection ! https://www.virustotal.com/gui/url/338b050c7a6b9d69f5b174c246ac2d126f853efd1a61f3f8ce6813e90ca840aa/detection ! https://www.virustotal.com/gui/file/6bbec289761e29f2118ce99e40cd65abb5428d53806158c5898c5db5f252af96/community ! https://www.virustotal.com/gui/url/98a0ce8f7e37e92a734ffbbcdb5f277301d0c4331c1beb8fb21ff879e30a7c8d/detection ! https://www.virustotal.com/gui/url/9b4f8a94886ee961ca2a9b2883afba958df4020255bc223a4065f9f002b4e705/detection ||192.227.158.110^$all ! https://www.virustotal.com/gui/file/0b2aa8187ec6f6435630f3652af0fa7cb74579402cf94e423f95016004465aad/community ! https://www.virustotal.com/gui/url/c202ba3abd297a905c63281a8430fe0e86e275f23c30c449c77c10db0a59cca3/detection ! https://www.virustotal.com/gui/url/5650885e7203c1359a7ad957620b63a81c513cead87ef081447d663788c3ca17/detection ||45.15.170.102^$all ! https://www.virustotal.com/gui/url/5fb2767626e0ec1f3f13581aeb0e8f7e42e4ad6e277325b63a7ebc23711d6166/detection ! https://www.virustotal.com/gui/url/7723856ebbd6e156a0d652aded8df06261a290b1484ee078768c0f64a46a4445/detection ! https://www.virustotal.com/gui/file/da75c85fe037f9ff9ebbbd0b37dd2ff154f5e70a0dc6870286e0d3df6b8f246f/community ! https://www.virustotal.com/gui/url/2d1ab3d658bc793eeb760125c15fb3792cd38bec0299e790f57cb1710336cfd5/detection ! https://www.virustotal.com/gui/url/94b3b68b325a61f8116fc6939734960ce1b6cc3d6867e0ece89328e0715e92ef/detection ||139.28.37.49^$all ! https://www.virustotal.com/gui/file/ca7072bba9d1b75b02b5d2887fdb7bcb1f86050b669ffd99a7e756e1a60095f2/relations ! https://www.virustotal.com/gui/url/3e3174e68a386d1aeaec00e64037b4e3b650164ff8e0289f56da8b7c4aaf95d9/detection ||str-master.pw^$all ! https://www.virustotal.com/gui/file/8fa3c34e462037093f430ee126f228ff245b06976d452de81f0d21575e290435/community ! https://www.virustotal.com/gui/url/f075f6666140ea57d70412c02642a945a482456d7999ffc7c03fc8d8e9d2b95a/detection ! https://www.virustotal.com/gui/url/baf9a29fedcde861fe80dbdb0d94b4a3d38e3f324424b3d6cee880d905ca65ca/detection ||117.196.29.105^$all ! https://www.virustotal.com/gui/file/d1b5143160255a56f75efe4e9331aa019919d210e5c57d47cc2f54d52aeb7042/community ! https://www.virustotal.com/gui/url/30b0804a23a89e74dd8139dfcb766783f46bbae3ff65abbd008a78c3e9371b6f/detection ! https://www.virustotal.com/gui/url/09007cfca4455f32bd57fdd3c1541f20a3b9bd9cd95252bb7bd9e26fb5f4135c/detection ||139.99.135.131^$all ! Domains that resolve to this ip ! https://www.virustotal.com/gui/file/7b603dd82cb87eca59e93b2cd9c0eb8e613339097b23ac07daa9220a2eb4a7b4/community ! https://www.virustotal.com/gui/url/fb8f88ffe062f936433c934de18d7c411ab997eb5142e0458b217c9136a0a968/detection ! https://www.virustotal.com/gui/url/7557ce70f571361276db8261d1d957499eacef0ec74c9feca8d5968288180e58/detection ||91.212.150.247^$all ! https://www.virustotal.com/gui/file/3837bd604e129244d1ca1fdd901fec0de7069f960e4c787c579811e21f2448c2/community ! https://www.virustotal.com/gui/url/75518a9adcf0a22e95319f5df2017050ec3b8e4e00ffbca628ca3e32b074fba9/detection ! https://www.virustotal.com/gui/url/240e84686f645820b6b5bdfbf391bd8a5a4371e347a02ac2d6297d9905d83787/detection ||194.145.227.159^$all ! https://www.virustotal.com/gui/url/6680fe346732105a635a0c1ad47eda07bb9fa0c430d6b69b73dd49d2e9edd52b/detection ! https://www.virustotal.com/gui/url/5961dc4e337c4aa48f2ed2945730bbb40590f9f1291a7ad65446208025153eab/detection ||justinstalledpanel.com^$all ! https://www.virustotal.com/gui/file/717bfbdba55f9c2d820fde170c04fd70c3e0f907b635c13d0f29678ff781f665/community ! https://www.virustotal.com/gui/url/c6dff51df89ba29c5469f255a0eb210b227b287323760b9db444db4576f25b3c/detection ! https://www.virustotal.com/gui/url/90ab08e26da7cfb7163220d538b58159ffcd034857a6181a53eeb33111862726/detection ! https://www.virustotal.com/gui/ip-address/35.194.188.37/relations ||35.194.188.37^$all ! https://www.virustotal.com/gui/ip-address/35.194.188.37/relations ! https://www.virustotal.com/gui/url/ffcb5058b7baf1b9b74b5910eb1c0c00ab7ca3a34e67f241511489bb7a1745ec/detection ! https://www.virustotal.com/gui/url/7063630fcc39e93d2ce281a3622fa31a7384c69c7d1b88681d6cc8080b8f85ba/detection ! https://www.virustotal.com/gui/file/d4a432f1248930343a999a11dbcf5c7790f7c0d4856200aba7d20f956455fa2e/relations ! https://www.virustotal.com/gui/url/31f594b44559268c110733c6a8eee6349b6da8d6c72808c7b1530418d53dcc85/detection ||185.225.17.248^$all ! https://www.virustotal.com/gui/file/368afeda7af69f329e896dc86e9e4187a59d2007e0e4b47af30a1c117da0d792/community ! https://www.virustotal.com/gui/url/39f51c240675face23daa0fdd02c8a16f7367d599956ca56dd78994d916ab084/detection ! https://www.virustotal.com/gui/url/edd4db01297824cdd3d9762e6c5814217762733e43806910c500cec8bb9a33dc/detection ! https://www.virustotal.com/gui/url/dfc627dd9e15042b54b52256b5c097419d3d7a9e88b1ada7e336e71a1f3918cc/detection ! https://www.virustotal.com/gui/url/786ac72a5a21d9e776f4a433628c4fe4a1b883d7b2dfd5dec70f4cc9df57d92e/detection ! https://www.virustotal.com/gui/file/368afeda7af69f329e896dc86e9e4187a59d2007e0e4b47af30a1c117da0d792/relations ! https://www.virustotal.com/gui/url/de8b6da81885ece3cadcc234a81fcaddaa6e4b4d186e232b215cb9e6baf34bef/detection ! https://www.virustotal.com/gui/url/f1e54c24e1d0a6804e1a61fe846536525413103b88f3ce319eec6359c12dcfde/detection ! https://www.virustotal.com/gui/file/c0e40a12643436cb413235e385a6a90deeb6cc13b24458368fd7facb20ac0c81/community ! https://www.virustotal.com/gui/url/2bd4684b3018b632e9b81b8804abcdc81adf4fd2f09cf9c241db3c7407a0114b/detection ! https://www.virustotal.com/gui/url/e2e0014d008dfd1fc5f76cf66e5a802be2aefb7dc81ee11dde9bf8597246d694/detection ||91.243.121.19^$all ! https://www.virustotal.com/gui/file/9f154115fa8045aa05f15f7cd1de9623ebe32e8ea400279ecb5dfa3596952e3b/community ! https://www.joesandbox.com/analysis/485747/0/html#domains ! https://www.virustotal.com/gui/url/208a2c80c056202dc8b684a4770251259c52c602a886fa241dd606809587832a/detection ! https://www.virustotal.com/gui/url/99b6358982cd5d772cb7b3a70cbd9f1ff6d731f5e58ed9c4d90580013b420769/detection ! https://www.virustotal.com/gui/file/cf2520dcf0df45be39612ab801dd1bb9923c83b21fc781be782e89e3a48e27a5/community ! https://www.virustotal.com/gui/url/56fbafd52dab63df12ac360b1eb506fa17bace95d07aae5fd2ee9f4f89e778cc/detection ! https://www.virustotal.com/gui/url/568238f692c4280eba681d4629d892166cac45d07b3bc8289f1c46623a5998bd/detection ||37.0.10.214^$all ! https://www.virustotal.com/gui/file/bd9c69a6048125674efdd529748b7f8036fedae0b1982dc761f4fb3f22ff2564/community ! https://www.virustotal.com/gui/url/faaeadfe736bcee0436023aa40e6fef111769c2a0c6f5c10f4cfb18e4c3b2ebc/detection ! https://www.virustotal.com/gui/url/24853ce5bb04b5727789d5d0ffe13a37fbc7907fa5e1ae1742452e80ca9eb553/detection ||5.199.130.247^$all ! https://www.virustotal.com/gui/file/0374ead74fa807fb1737d8829fdb5bad6c93779f6b9eb7162eddabff7a64acff/community ! https://www.virustotal.com/gui/url/6585846378d6e150084167c12bb787566b854c47d2f8a7fc25c61ddb2ad85569 ! https://www.virustotal.com/gui/url/a71b19af4d835ee9b7eef1858aa3f3473bc1655f86b6815fe464e850466d9c6c ||esetnode32-antiviru.ydns.eu^$all ! https://www.joesandbox.com/analysis/486636/0/html#domains ! https://www.virustotal.com/gui/url/385130fbc7343a5d97f3b3fcb19d1933f4525e5530d0b0d5bd365704a4efbadd ||aieov.com^$all ! https://www.virustotal.com/gui/url/3fe5043049eaf39d66f91f12f3ddfd7b2b5c11bf1fceaef9a4bb5849a5e8a6d6 ||www.aieov.com^$all ! Relations to the original domain ! https://www.virustotal.com/gui/url/1ad001f2a8b45af9ab7af5b8bc97ca301b356a4a67868043bb1d0445e83f9a2b ! https://www.ipvoid.com/ip-blacklist-check/ ||192.3.194.242^$all ! https://www.virustotal.com/gui/url/f383435c4ebc276a916fcc84b8bf9c8f96ef7469918f8cf404f6199afe99e7dd ! https://safeweb.norton.com/report/show?url=w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu ! https://www.siteadvisor.com/sitereport.html?url=w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu ! https://www.virustotal.com/gui/url/0c324af104bb3ea37074bc44245d2667f0b7bde55bcd80baf6623e8c8a4365be ||w0hsyejhnbcvzaxi8euyr6tgeya5vml09jysgav27.ydns.eu^$all ! https://www.virustotal.com/gui/url/8a54108fd6f5152bf9dc9dfa40a53c42912efd5005ac5f1c1e9193904110bb17 ||hncbeyghfsbvcuabgsbncvzgaioiuyegdbhabbbw.ydns.eu^$all ! https://www.virustotal.com/gui/url/9faee609262eb05e277affe242c05d6de476c98f50351a70bf270762aa7a59a1 ||avira-antivirus.ydns.eu^$all ! https://www.virustotal.com/gui/url/e5e1be7f0c795bd33613627bad331ab08561db2b149f084f3d864d5e1c11d6bf ! https://www.virustotal.com/gui/url/c4d679b0bf890df973383c9feafa2cdec8e9fcf7c0843683ab7e196dab9640bb ||lefteriskkokkiskikinew.ydns.eu^$all ! https://www.virustotal.com/gui/url/15a4d61ed39673084eb60449fd1763732f81193d9303c2ba4b5785f37a0bb5af ! https://www.virustotal.com/gui/url/544ea0a11142e35cc324a55590ee72b0cf47ff8a1ef121171da063f4acbadad2 ||nan.ydns.eu^$all ! https://www.virustotal.com/gui/url/e013e4826117fafad60ad880bb6f35a15670c2b83d505410b88cac9583e49467 ||hurricane.ydns.eu^$all ! https://www.virustotal.com/gui/url/1020eaaad69d1f4db073554e43287624e7489eed2432a5f68fe8bc9b29f512fc ||hjjhjkk.ydns.eu^$all ! https://www.virustotal.com/gui/file/0dc6ac9a0255d8c726ea77ff4a7298ecc14552790389259c841e9da27c46e540/relations ! https://www.virustotal.com/gui/url/869cb25b1625038c359eb44c4e2768718cfb4cb0d5e3eafed6a935904c5308c6 ! https://safeweb.norton.com/report/show?url=136.243.159.53 ! https://www.siteadvisor.com/sitereport.html?url=136.243.159.53 ||136.243.159.53^$all ! https://www.virustotal.com/gui/file/358f2a778fa197fc3b032f0b85542b882f681e38c4156881874d66fc2bf2bcb0/relations ! https://www.virustotal.com/gui/url/dcff4e6feaebcafa1154a883ed9e1f99a9c34366a38857824f90794a66c3fffd ! https://www.virustotal.com/gui/file/229a81a3b6e087abf33c1efc636c1d53f16edcc38d85a4b770eea39b89450bdf/community ! https://www.virustotal.com/gui/url/2dd1e17f56770c371eccbd9249b6ea24a19f6db0bf7a3f68390d82d5493ac764 ! https://www.virustotal.com/gui/url/17480555897004a56e48ee43332b40d248dcf212eeb040657e4820d26b10611b ! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community ! https://www.virustotal.com/gui/url/f3a89082bcd805a128c00fad66bc504738a215d67431f16a8387e158f09d9d45 ! https://www.virustotal.com/gui/url/b315f0ca42053328aa5e8a2bc163511695e604d0188fb036b8d9fb063d3e2623 ||125.44.43.45^$all ! https://www.virustotal.com/gui/url/681f6aec5b27f15fbf820f5e74dd9e6b456e960458854e7980d5c29be9391532 ! https://www.virustotal.com/gui/url/7cfc78841db9822755d0c4807b1e4dd1b90d926d40b89b92cf4a00e2150292a6 ||182.121.8.240^$all ! https://www.virustotal.com/gui/url/7f731b756c7666e26e0e408bdd1928b08bd7e5dbcc2a4684c4a88a069824284e ! https://www.virustotal.com/gui/url/2705bbddc0fe7e3eea8f210a324a2de165eda70049fdeebdd29331bca5717c10 ! https://www.siteadvisor.com/sitereport.html?url=42.235.183.74 ||42.235.183.74^$all ! https://www.virustotal.com/gui/url/0883388ea922e6ace900976e17037f2a501928bc6151592825acac2639f36f29 ! https://www.virustotal.com/gui/url/280ee2804d515a3468f65c6bc569970049ac7c78ffd9a3e7c45bf1e226b854c5 ||78.36.32.242^$all ! https://www.virustotal.com/gui/url/cf971b9c95dc52572817a00d6a34a0ae07a6763e1615b893745b0ba27f7f6b87 ! https://www.virustotal.com/gui/url/b63b56399ea13fa6b384d29b94860d030539e8995d2bc2a8eedce745c6561432 ||115.50.2.119^$all ! https://www.virustotal.com/gui/url/4d73ba8f9ebb1809fa120ceee7f74fb3c704c35407d0e1e6cdb4a04187ba6e1a ! https://www.virustotal.com/gui/url/053b573a28e20e2dd5da24cc09f55ef870dfcaf70c5ab11647a02d4d49cb6cca ||115.50.110.163^$all ! https://www.virustotal.com/gui/url/27f64604a4b72627c25c3b1320fbdccc89ce4a3e9ae994a08376fae9b6924f3e ! https://www.virustotal.com/gui/url/6fed9bf1106cccb428d284efdfb39411c0b0851fa06ae4379e2d3d5c98ae2e10 ||119.179.84.145^$all ! https://www.virustotal.com/gui/url/221c562f97367319e4a786ed6899c0a57232a374a05ad37fcb2af9b5d668e674 ! https://www.virustotal.com/gui/url/e0e1c7d9701b251ee026397b375084c17f7af2c078ec3cf3c497fde34c9e3dc5 ||188.120.50.98^$all ! https://www.virustotal.com/gui/url/b70e930dbbace18a6d4175ee4d76dc959a806c7ea929b1a633ddd33324efe11e ! https://www.virustotal.com/gui/url/cc561a8a8a9bc452a305b661a9bfe82a1337c3146f79c7689f8f30ead7da7df2 ||190.238.183.5^$all ! https://www.virustotal.com/gui/url/48a82daf6596f9fac7c08ebd4c0a1c6a431a2df2ffa57861b71cb55d2226fc2c ! https://www.virustotal.com/gui/url/6a529421eba81d903ee7fa097d4141a367884d254902189ec9730bcefe1701b8 ||27.220.253.78^$all ! https://isc.sans.edu/forums/diary/Hancitor+campaign+abusing+Microsofts+OneDrive/27838/ ! https://www.virustotal.com/gui/url/e63cf4d17b2716b95d041eb34ee11a979a9f8005112eddd221d3ce5c3d43c1c3 ! https://www.virustotal.com/gui/url/ddc1000d6d3f312b010272f412c0f550a507b94406bbbdc8d288d3889e97b4fb ! https://www.virustotal.com/gui/url/a1bbf36ec20a1662d79dde4adaf0ac4315ae836c1b3e8cbcda34061ec5772e96 ! https://www.virustotal.com/gui/url/f7d235c94eda440c1335577df536eebb972c0ce28b8a690067277cd2dfc767f1 ||149.248.34.65^$all ! https://www.virustotal.com/gui/url/eb4bea99390d6174b9cf2efae95bdc22537b6a4cec73fbb4c58dda98b5f1778d ! https://www.virustotal.com/gui/url/cc4f13cf99bb29c3d3f29110717f0eddcde7c0ee5799b74fb2f969c15572f4a9 ||tiacreation.club^$all ! https://www.virustotal.com/gui/file/ed6ecb1de00df221e31b189bd85fd9dfb1f264021efbb0d83018a2247e294d87/relations ! https://www.virustotal.com/gui/ip-address/103.155.92.211/relations ! https://www.virustotal.com/gui/url/bbefad46389e25cdf31e4aebcebb13dbe77d5fe45f9dd14e9755f2dd601653df ! https://www.virustotal.com/gui/file/5bb7ab8d474109d82d8dfa3aae223df280517fe425a54d33d16ef5d00d49fcc1/community ! https://www.virustotal.com/gui/url/52028461d168b1a88b59e92ac8f040bf3e1e3dec3376d43b80cff0278f26f039 ! https://www.virustotal.com/gui/url/06f20ca243d075ae997b8635caa6deda3d29a5177c56e068020fb7c902d5dc6b ! https://github.com/brave/brave-browser/issues/10470 ! https://www.virustotal.com/gui/url/8506229caba5b07f8bde7815d0135660479284a48bbbae7b97d7047693dc60c4/detection ||linkangood.com^$all ! https://www.virustotal.com/gui/url/cdf69791a37098dc41af2e7088c1244b4688c21d07561e724ede9547845162fd ! https://www.virustotal.com/gui/ip-address/23.111.228.4/relations ||23.111.228.4^$all ! https://www.virustotal.com/gui/ip-address/23.111.228.4/relations ! https://www.virustotal.com/gui/url/59307724555428ad251276b5267fcda8fc6c27d73a838bb0c77fba1eb890cbc0 ! https://safeweb.norton.com/report/show?url=billyjons.net ! https://www.siteadvisor.com/sitereport.html?url=billyjons.net ||billyjons.net^$all ! https://www.virustotal.com/gui/file/d838cfaf7b197d6c3379e2c5daf269cc422a09df556de6ca08fe174b4906b3b6/relations ! https://www.virustotal.com/gui/url/21dec0d2c9ef69e6d000ce22057a7dffae415d345f4e4175ec37bbd715471443 ! https://www.virustotal.com/gui/url/0f07c02840b99373669f948b57b8caac5a01012afae2b9c0f5e7fa50758eb14f ! https://www.virustotal.com/gui/file/295dd067b7f19b756d75984c9534758cb8fcb8b0b4b0bcc148633cd5d089b4e0/relations ! https://www.virustotal.com/gui/url/a648e9208b432873fe74e73f01c310f484efc996ad6bcf547aae3930ecd54f86 ! https://www.virustotal.com/gui/file/dd769290ce8c125926aa85f310f4d56a0ebe7c01c0bf95238744d36e3ed0d95d/relations ! https://www.virustotal.com/gui/url/01aadf0975deb47a2c37dcd42d788cb7dce3b9468676bf3cb796a25ba5cf568c/detection ! https://www.virustotal.com/gui/url/f8734d7fd2a2b5c62ca36c7ea0dec1c4c58d06df088f46646a80b94b8b9ff7d9?nocache=1 ! https://www.virustotal.com/gui/file/b9ffae5037308a99ca3d3aecc696089829efe8d1e442b91c9f14b39e17318f35/community ! https://www.joesandbox.com/analysis/489369/0/html#domains ! https://www.virustotal.com/gui/url/7163ef062c812b99910fdd33dd477006bd4b00b9db826b8c3b23925e231fa29e?nocache=1 ! https://www.virustotal.com/gui/url/3e28059b55911a70fb5317a84103f1d271795e07470396d2812c63046ef540b7?nocache=1 ||23.94.159.204^$all ! https://www.virustotal.com/gui/file/bf72cee251615ca0af6b861fd4abf781b007249d3b0bc8612bcb37bac0d427f5/relations ! https://www.virustotal.com/gui/url/c987fe2e41bf2e3f4902ebe366e26a3b91fadc301891ca5113fef3d42c89d85d ! https://www.virustotal.com/gui/url/6a04408bd9434747ed3d80ac80363ba0973da6793d6b360b4f9483785abda879 ! https://www.virustotal.com/gui/url/e60dc17a5db9bc36e65c5f3d563f9551097211bad8c8ae985ad943f04de2eaa3 ! https://www.trendmicro.com/en_us/research/21/i/cryptominer-z0miner-uses-newly-discovered-vulnerability-cve-2021.html ! https://www.virustotal.com/gui/url/19a7942479111194f955ba52b30d5fa422ae99ae57a306199def24833ed9750f ! https://www.virustotal.com/gui/url/69e3371d9b2d42c6a54a5cc00e0df81a792762602556205b24fa3ddc74d28a8c/detection ||209.141.40.190^$all ! https://www.virustotal.com/gui/ip-address/209.141.40.190/relations ! https://www.virustotal.com/gui/url/5f60a91483d4362d52733d3d2cdb20df613fc36a1b55c9fbdc76ee2e5c45064a ||bash.givemexyz.in^$all ! https://www.virustotal.com/gui/url/f10dc2b96d8592c18c9c437a23b7be049aaa6b9aafa87e86736a06668b4384a3 ||givemexyz.in^$all ! https://www.virustotal.com/gui/url/936040d19cceeffa1e80ecd3758b9e6e66aaaa00817e2e604b00a7ad8ab3ce5d?nocache=1 ! https://www.virustotal.com/gui/url/59ec15b3d39c6fe33f620ba1f71fd934f157e1b8b145a6b58a9de67106c2877c?nocache=1 ||27.1.1.34^$all ! https://www.virustotal.com/gui/url/d731bc107bbc6d14eb0f731da16d5faf54c20a81e2af4aa27eeaa334ea71f338 ! https://www.virustotal.com/gui/url/b619fb2387a4372f6ee4840dd8a03dc530e7bbd6611bfbaacad7061a8ba613fc?nocache=1 ||222.122.47.27^$all ! https://www.virustotal.com/gui/url/2e8a89ea4e13c4b36451432cc7671497a8924bbeb0184c56b995078cf45824c7?nocache=1 ! https://www.virustotal.com/gui/url/c256e82f2e50ae73e6de1113bd22c8d28b40e3e991964016f50a70e1c76194b5?nocache=1 ||164.52.212.196^$all ! https://www.virustotal.com/gui/url/479e9877e31cb4a7bd26dceee3f961ecb2caa6ccfa054ec21471875a2553395a?nocache=1 ! https://www.virustotal.com/gui/url/322839eb79a430b5ff134db1fe8cd5c825aae0640e08a3a67b709e3700d65185 ||66.42.117.168^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/95582 ! https://www.virustotal.com/gui/url/3323920fe31aaa6724441edc7bd395232194c52967480a95039fb35bcb3d7ac2 ! https://www.virustotal.com/gui/url/93011523cfdd4defbccbe5fff351acac2bb6fdddba6420cc69d81cc9f9dd7f61 ||discord-give.com^$all ||www.discord-give.com^$all ! https://www.virustotal.com/gui/url/14e26f474bea138e9ac57c1cf5558ab6cb78b4ead632840a2e6e6f20e150398e?nocache=1 ! https://www.siteadvisor.com/sitereport.html?url=95.181.155.109 ||95.181.155.109^$all ! https://www.virustotal.com/gui/url/145c4bdadca86dfb9560668f2cec835f75c248af41b8842687ad89dce8d2aed0?nocache=1 ||communitytradeoffer.com.ru^$all ! https://www.siteadvisor.com/sitereport.html?url=dlscord-app.info ||dlscord-app.info^$all ! https://www.virustotal.com/gui/url/51da56828b0cd9d4d4514feb74038aefb01dc4188da398f1666983766914c156?nocache=1 ||steamcommnity.com.ru^$all ! https://www.virustotal.com/gui/url/83ce8c920a22c9550591e52839fd540ee7a37b941e3419780b17e195fcfb9b28?nocache=1 ! https://www.virustotal.com/gui/url/81880d767bab8515cf71ce37ebe7b56d8448184b96999f6cc4ce70d2b6c68949 ||steamdiscord.com^$all ! https://www.virustotal.com/gui/url/0a8ea816672728b0e9869f65e4788471880746a65f3f8f2215789d0edfe278d3 ||discord-app.net^$all ! https://www.virustotal.com/gui/url/0314bd2bb4874cad7a39346c83c421d87208be4bca6c0dc2f804f0a902b18cfc ||steancommynitu.com^$all ! https://www.virustotal.com/gui/url/da1a1774168459b01568a553a8e478fd495c9faa30078233a39eea572a30cc44?nocache=1 ||95.181.163.44^$all ! Copied over from https://github.com/DandelionSprout/adfilt/commit/260f840b773b04d7397c6c40d86cf7e2887768d8 (credit to https://github.com/DandelionSprout) ||cabura.loan^$all ||csgocup.ru^$all ||discord.foundation^$all ||discrod.ru^$all ||eslpro.ru^$all ! https://www.virustotal.com/gui/file/1fd0fb9234ef0bb09d41c4c8f618576c06028b832dda8d737a01d8fd22317920/community ! https://www.virustotal.com/gui/url/a6b230718db73bc5f37c9ed29327db77e67d54f3905ab0252aadf7e856380d35?nocache=1 ! https://www.virustotal.com/gui/url/9246a0897af823045fb4afbcd08daf09e71c56f354d9352a9487dd6f58b94773?nocache=1 ||45.148.123.10^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-927151458 ! https://www.virustotal.com/gui/url/a7fb846c9f8aefecbe0ffda1aecbb6a3d257f0b31a9b922aa49d494af0f0c112 ||findyour-realsex2.com^$all ! https://www.virustotal.com/gui/url/0680f0ae763476f2aa0b844b6f64a1ca4b6c63e0c7f6880ab5f121ad406b2d2e/detection ||your-dreams-girls2.com^$all ! https://www.virustotal.com/gui/url/4047b3b1b6af03839835b31cffbc5d52eff7c6f01c23cf3330a1000c61b66c0f ! https://www.virustotal.com/gui/url/4a2cff70405ed300ad14b2294eb06c9adff5354911f70229085deecc7048637b ||yourbigexplosivewin.life^$all ! https://www.virustotal.com/gui/url/ff99d9ba468539c01896ef8b380819c07b8af40792d83beccea2d76064ebf781?nocache=1 ! https://www.virustotal.com/gui/url/134a3e4324ca33c19c529aa554ff193a96b48ae6213323a957f5752641a8014e ||bestdatinglocal1.com^$all ! https://www.virustotal.com/gui/url/385edcca4e25f51083f593a4041f834fee5c903a93f5f66eab50f65df61c811c ||sexcontact-store1.com^$all ! https://www.virustotal.com/gui/url/7574cd8789b7ac7b78e4efe778ab6228a8b8c79301740247b5738bc62f208883 ||superdatenow3.com^$all ! https://www.virustotal.com/gui/url/a7f1c2d1c02cc824bb93c1ba1d147d9fc1464bb3a4aeb937922d6bbdec84ffff?nocache=1 ||findlocalgirlnow.com^$all ! https://www.virustotal.com/gui/url/c5126c3b175c6fa50d96443ecca99b75c881420248ec020c7cd567715839410a ! https://github.com/uBlockOrigin/uAssets/issues/10075 ||the-crypto-genius.net^$all ||www.the-crypto-genius.net^$all ! Redirect ||learning-base.club^$all ! https://www.welivesecurity.com/2021/09/23/famoussparrow-suspicious-hotel-guest/#Indicators%20of%20Compromise ! https://www.virustotal.com/gui/url/ba74801a83395bf008a256d5aca561801147e526b8c48cb282ecdd80bd96bea6?nocache=1 ! https://www.virustotal.com/gui/url/b048f040c5eefaf71f54c4bf7080251213237efeb6c715d832804fba146af9fe?nocache=1 ! https://safeweb.norton.com/report/show?url=45.192.178.206 ! https://www.siteadvisor.com/sitereport.html?url=45.192.178.206 ! https://www.virustotal.com/gui/url/581dea1d4c2a4f52d39edf1b25b780e45e2cbad3a5d233883e96063949f840ab?nocache=1 ||45.192.178.206^$all ! https://www.virustotal.com/gui/url/79e4bc11d7c5dbbc357b30071da243e130f6119deb13f2f3bc26bf3d7e772938?nocache=1 ! https://safeweb.norton.com/report/show?url=27.102.113.240 ! https://www.siteadvisor.com/sitereport.html?url=27.102.113.240 ||27.102.113.240^$all ! https://www.virustotal.com/gui/file/a8e150eebb41bfbb84f75ba3c3bc0662219ca3271af960b9f37b5f532d601f71/community ! https://www.virustotal.com/gui/url/bdfd32137d8a931b5ec7111526b22720557a2171a44b980fb32046c5cb7b595d?nocache=1 ! https://www.virustotal.com/gui/file/956b823bbe87e8263f8807224b66398a504bebac2e5011762d52cb4b93620c87/community ! https://www.virustotal.com/gui/url/c3b85f94cff3a7aa11d3179763a1a738289e87c62f76700ce8cfca8578aaf729?nocache=1 ||167.114.109.203^$all ! https://www.virustotal.com/gui/file/711620f91b4409e11e714ff6ac3979168d52a5ee895e2fe7b84f78f83fdd43d0/relations ! https://www.virustotal.com/gui/url/35ed5852d27c5fa5ffddfce2f18cbb90326bcf424caa26bae3e39f6d32dad4b9?nocache=1 ! https://www.virustotal.com/gui/url/9df82ea3e35554ead64340457ded7711981030775cb2c9148c0825216903c396?nocache=1 ! https://www.virustotal.com/gui/url/e5e656f97a5b6d10b597f044e9c5138da7c78bc8b5039671bcdefc0a03c4066b?nocache=1 ||connectini.net^$all ! https://www.virustotal.com/gui/url/163b04d23a3d0c2088a3d410495ba198d031b0690f38cae8bb5f57b096ca0685 ||mugrikees.com^$all ! https://www.virustotal.com/gui/url/a8ba9cea90883412a11b41a8b8c68fd1c46cf434de8707c968972b2524edbe96 ||profitabletrustednetwork.com^$all ! https://www.virustotal.com/gui/file/dd550c3bef8f1aba9066ec2a2a4c8f48f5843f0b776c12beee247fccc213be0b/community ! https://www.virustotal.com/gui/url/39c723b5881eff899a7cdad15e19351a928205d238ca3f9393df4de0cc19c68c?nocache=1 ! https://www.virustotal.com/gui/url/d07f92b86bd4c10ca3b7479ace2a8661dac587f73b8ff8ba21c5ef6b06d98b4c/detection ||176.123.6.43^$all ! https://www.virustotal.com/gui/file/79dc17855e41c95a144280cff99422932721209dd97cd28dcd985746e339397c/relations ! https://www.virustotal.com/gui/url/b1343d5895137c740eb5d3c7ff54a8c581bafdf9fa9a825a828bf154fb48ac15 ! https://www.virustotal.com/gui/url/088c15e76cdf82fd6bc0e126277a81eb2bced818efc5601f5603c872dcad398b ! https://www.virustotal.com/gui/url/bbc218634d97a3e4ceb733c2c86d5bc0f891cc71bd2cc1db3b8e48cc27f8d5a6 ! https://www.virustotal.com/gui/url/ed8727d53a3f207de5f60ed17d3651eccce46fb4b21bcae25fcba1a503114822 ! https://www.virustotal.com/gui/url/664405743b165905efc46ec3e31756a393ccb78e6b5785e58648f89d523e704d ! https://www.virustotal.com/gui/url/f469f3826024bb2ff2077fe4a60b335009e1d4fd77f17e652939f68c651c73ed ! https://www.virustotal.com/gui/file/a4c3d60102ff72d89963df742fd50a4b7dc32a23ea3cf7a78dd3a4685397d270/community ! https://www.virustotal.com/gui/url/e7fc198fae69309fe7039577cf72e9a86715c9feb4629497256ba7b559d9fe56?nocache=1 ! https://www.virustotal.com/gui/url/c8b0e4f2d976a57edd8251ea038513483d373ec2094d0270a3216ebb76b8bf33?nocache=1 ||dz.qd388.cn^$all ! https://github.com/DandelionSprout/adfilt/issues/287#issue-1013759704 ||youtuba.com^$all ||polyhymnia-mar.com^$document ||virpropcnow.xyz^$all ||avprotectionoverview.com^$document ! https://www.virustotal.com/gui/file/2cdac05088d51a5ebb646fbba3c305ec14c950dc1ce3b3d51da5aa6584774429/relations ! https://www.virustotal.com/gui/url/f5d971136a1bdee73ef5c26273b1821a8b23cb7e2d1c4e81e8299aa7506846c7 ! https://www.virustotal.com/gui/url/ce978db4fa1566a3c37eee7b591a7065185486e2ace9c1a70447b7f39bba36cf?nocache=1 ! https://www.siteadvisor.com/sitereport.html?url=186.74.208.84 ! https://safeweb.norton.com/report/show?url=186.74.208.84 ||186.74.208.84^$all ! https://www.virustotal.com/gui/ip-address/186.74.208.84/relations ! https://www.virustotal.com/gui/url/f065d589990d04aec1d4f6b19b8c9d663206f79119154e9999e13cce992d7f31 ! https://www.virustotal.com/gui/url/0e638edf895771adede653e1ba39a733e90b7b746546c1d0fad9d228042411b8?nocache=1 ! https://www.virustotal.com/gui/url/c6a6b915883afdcdb0e0fd1a163961d4d21b5bbb9cd4b60f7152e3bb045b0334 ! https://www.virustotal.com/gui/url/8c394741286dd2b8ddc88592bef230075eca394f25684ae8a3faae1ce4ad251f?nocache=1 ! https://safeweb.norton.com/report/show?url=gmpeople.com ||gmpeople.com^$document ! https://www.virustotal.com/gui/file/fab15b7f61f816cf3128cc02c96d98d3385533087bc5afe3cd3799e7e034ce7f/relations ! https://www.virustotal.com/gui/url/6803550abaac24624762c5ee233c4787f642bd8ee8eb36cd4f868507f55dfcec ! https://www.virustotal.com/gui/url/f7dfb550983e3512c09a40b41d50e4293ed4a65f87fbb39a9e2cdf9e8b711547 ! https://safeweb.norton.com/report/show?url=193.56.146.41 ! https://www.siteadvisor.com/sitereport.html?url=193.56.146.41 ||193.56.146.41^$all ! https://www.virustotal.com/gui/file/1a309fbaa8593317bf9d3810b5584a14cb799f3bc054a61976a5e82c97427199/community ! https://www.virustotal.com/gui/url/cc4d48e4db2bee1cfd10892ee6357a34065bac67b37d736c66902520599de902?nocache=1 ! https://www.virustotal.com/gui/url/a410febe00bd62e3a869d7b7c55986861a095d8002f3fb722785979148e39b63?nocache=1 ||85.237.217.143^$all ! https://www.virustotal.com/gui/file/d4bcfc7eac31ab3310de4fe8feb66dc6e1d9555493722b50c6fab5d03c4f290d/relations ! https://www.virustotal.com/gui/url/3a606b479b0214bb3e7d9aa217a93fde5dca721b3c130566dc864f472ebdd46c?nocache=1 ! https://www.virustotal.com/gui/file/4e56f35781fc7279ed306516e2cfd700e32daa86e2f11bdcfc6e8a62a487820c/relations ! https://www.virustotal.com/gui/url/dcc9d8d8de866bf04bc7d2b1f96882943af22cdc830a668a5e08037b55888000?nocache=1 ! https://safeweb.norton.com/report/show?url=update.myiphost.com ! https://www.siteadvisor.com/sitereport.html?url=update.myiphost.com ||update.myiphost.com^$all ! https://www.virustotal.com/gui/file/0e8cfcf628f5194908892cbd2cadc68e685bef5101a6230d0d71110c88d4a9ac/relations ! https://www.virustotal.com/gui/url/a31a199e46cae063faa7f9f9e2592274b6dbbe078bd1704cd007c4c0b33cd159 ! https://www.virustotal.com/gui/url/4a394ed1aff6e7694503408ee75ffbb201e29ac5ab04cbfca7f4e1b99f92d59f ! https://www.virustotal.com/gui/file/98d9321dd873a34005bc3dfbf6c22de4f45fb2e979035c8a134001bc3b85e3d3/community ! https://www.virustotal.com/gui/url/0e921cd3130f8f73eab014d8028c31595307e795afd46d93f5aa52b1eff28bde?nocache=1 ! https://www.virustotal.com/gui/url/de3b2468cc552e0d121e9fd83d7aa02806ce749436de067eba2479061d3e59d4?nocache=1 ||5.181.80.16^$all ! https://www.virustotal.com/gui/ip-address/5.181.80.16/relations ! https://www.virustotal.com/gui/url/bbae4ee1a3a3463171e1b31ca0312049b77b69009670bc2a652b96ae686af8e5?nocache=1 ! https://www.virustotal.com/gui/url/52655c6393b71c512d25ec9d50a6081210c2d076b5337851e41daf8c3bd8c691?nocache=1 ! https://www.virustotal.com/gui/url/0b6553e55a733643cac74afe65d3a94b3bf0f693a092d5299540a0d8de572032?nocache=1 ! https://www.virustotal.com/gui/file/e7c7c7d017cc78e06708a646479e5130bde12fe63370fc104763c3e993593a45/community ! https://www.virustotal.com/gui/url/e8064c8f3b3a02087ff40b36445f87628368643901e47bbc3b371738b44b6328?nocache=1 ! https://www.virustotal.com/gui/url/720c543c2779e9102647edf10aa77d4f72cef947d47fa41b625074e0e9364d57?nocache=1 ||188.127.235.211^$all ! https://www.virustotal.com/gui/file/04bc8fb0c217312979a1217434a83d5db80400108ace1beb802cb564d5424a81/community ! https://www.virustotal.com/gui/url/4ef11e71a899cff7fd0da643e8f4cecd795c45993b4f0e61b107fa9b2a7d036c?nocache=1 ! https://www.virustotal.com/gui/url/bc88104fdb5b2d5dc147b01ae3297de84cb06b723ff5082742b78fbffbfffb4d?nocache=1 ! https://www.virustotal.com/gui/file/fd4d8a70a36460fb62abfbb47681b531b2b085456583e84918c2c3ab8603c6a7/community ! https://www.virustotal.com/gui/url/c0c2010b4a8a44569685ffd48d1b4f8b15b61e14c47407ba5bce88aaf033bd7a?nocache=1 ! https://www.virustotal.com/gui/url/09d3907db18aa0e8b00e03815ee716fbbbfc24742c0c86a6937c9fa9012607c3?nocache=1 ! https://www.virustotal.com/gui/file/21f3ee4c865d930b2c8e194a01d4eb00563752e7e04cd380996a19b969d510a1/community ! https://www.virustotal.com/gui/url/3bbc9fc1eaec39b9c3b3de277b6e7217e10dc12d361f6f247e21aa3762091d65 ! https://www.virustotal.com/gui/url/f4dec34344ec5d8998b8a41521c1b78574859da5cb7764dccc289180f89dacc1?nocache=1 ! Other subdomains of the same hosting provider ! https://www.virustotal.com/gui/url/31bdab820b394e3e93f7d22bb91ebb765886d91461997eeb009eedb95e8c57f9 ! https://www.virustotal.com/gui/url/7a58869e4f342c33f79bb0f714fe7ed2de4bd329fe89b8e91bd3c0ccfc9bc64f ! https://www.virustotal.com/gui/url/c300737ec442c6d7efbc1ace76316b33b9c135a2b8d6143a83a7b022f0086759 ||cp45362.tmweb.ru^$all ! https://www.virustotal.com/gui/url/cb7d93e3637997e9fcc6606994d30ab07636e020f88a3b163dfffd499e98cabb ! https://www.virustotal.com/gui/url/258253e4fe630a53eb5cd3eb9b3709ddde430cb8179a1fadeb6719437ce828c8 ! https://www.virustotal.com/gui/url/a58517846c0e060cd76d2834e69440a05ba6b6b96b75ab51c1d237f0eb6f2f60?nocache=1 ! https://www.virustotal.com/gui/url/ed4cd95ea990528be8fd26517661ec6ed7ed96fdafaaa249271a4a56294da491 ! https://www.virustotal.com/gui/url/bd390340baef52741ba921a7afdef46023d122e74ff007e04133b5417d457270 ! https://www.virustotal.com/gui/url/8f2114831f1286ce197982abdb2da720fce7389619ef8bcc01426b584f633560 ! https://www.virustotal.com/gui/url/0ca2cfe7ca2d38645828cc6c347e52b369454416a5163c0ce583e8102f5fd922 ||ci69056.tmweb.ru^$all ! https://www.virustotal.com/gui/url/c35d74af6b1fc7a34b881678125413a70f5a386726246250f28cbad0e1b1b270?nocache=1 ||co89927.tmweb.ru^$all ! https://www.virustotal.com/gui/url/e883cff914f661cdbe26f542159d2793567b0c713ce6497f1b8465cd8e4a7658/detection ! https://www.virustotal.com/gui/url/8b284c4cd9fb3b3c1fb620952b6e2c1097d485feee151aa561dc4746de604f47 ! https://www.virustotal.com/gui/url/fa8e0395cfa0a0d6f2c2b035943662534431b410ce7c37a3ba6753dfd3896f63 ! https://www.virustotal.com/gui/url/79fa6b8a78bdabafec9fc5c81121be14b721b408b5f1ec7ecbc330aaeefcdb7f ! https://www.virustotal.com/gui/url/33a4a7ff0fd896977f9f9f292c94e151701daa0b035dea5e78e3632b7568b32b ! https://www.virustotal.com/gui/url/2b346d37ac9ea3c081fe3dba16629672bbd1881c2b3562883e1d464020e308a2 ! https://www.virustotal.com/gui/url/aa5f4bc156a1ee1f0f0e4931869fab148b934858b644de457fe9406685b2234d ! https://safeweb.norton.com/report/show_mobile?name=cnw-offers.live ! https://www.virustotal.com/gui/url/2ba31261ba9e47d8fed7672e7dc6e93daba6c9b312aed3acbfd9b7e52c893fd4?nocache=1 ! https://www.urlvoid.com/scan/cnw-offers.live/ ! https://hybrid-analysis.com/sample/6ba6bd0315c21e272f0f0e7168cb5fcdcbee007858a19aa59283ea6ec92a4c4e ||cnw-offers.live^$all ! https://www.virustotal.com/gui/file/45658721ebbfda843579b6e9007d01a37b4083cf990a7eb02d681c11f1221afe/community ! https://www.virustotal.com/gui/url/44f3da5ce00b1fca2900f68f8df7aa16b96c73a4ffa984616628f293f4805418?nocache=1 ! https://www.virustotal.com/gui/url/4af04bab8922e30a003fde7caaa87af2fe066613f25417331cc6d7d84633339f?nocache=1 ||193.142.59.150^$all ! https://www.virustotal.com/gui/file/32ca0c18270e9c8308cc4d47ca0a023a376f4b625fe3b2fae174aeb32559a271/community ! https://www.virustotal.com/gui/url/070cf007b681408125bccc4caa8c1d7f4842842c0455deff3c981cf0e9f81bb2?nocache=1 ! https://www.virustotal.com/gui/url/f35cd8ba28ccffe6b82a40d1dc8b5182fbd6f967ac7f50d9d332eed66d4440d6?nocache=1 ||104.244.78.138^$all ! https://www.virustotal.com/gui/file/57315cddae2c029d8b29557c7f2cd049a5a96dfc2134da57ab6bc0ac84997e5f/relations ! https://www.virustotal.com/gui/url/4de94f3252e57342a6d457da9d614d1a9163047f4b5ad82d6345512e140dcf96 ! https://www.virustotal.com/gui/file/5cf788e38508a9f9dbce08142591763ff947fc590ae2fe162a5f2f1849b2c695/community ! https://www.virustotal.com/gui/url/34ca9c40f7903c046ecd75b8a09ef35b8b656e90a760ec1b8ff27f72053dfe55 ! https://www.virustotal.com/gui/url/deb26f2caa66c19edeacf327a80726384b04938e0d913d30d9b83769c1c4be37?nocache=1 ||89.223.70.202^$all ! https://github.com/uBlockOrigin/uAssets/pull/10142 ! https://www.virustotal.com/gui/file/30ac6a662fbc040f84b7cc5b940768a1ea01ed3bd8bf257c27573ba343069ecb/community ! https://www.virustotal.com/gui/url/1055992de540e1c10c0acabff8c8d1384a1af951cc0687d96accefe5e051d507?nocache=1 ! https://www.virustotal.com/gui/file/78f490e503c86eaaff5760197b9ff5308ed6e03161af13194a6c1e0cd95422de/community ! https://www.virustotal.com/gui/url/99d19655ee6442f8e9ba53bda64a2bf9a7179112e3979b22a91e7bcc3fcf41f7 ! https://www.virustotal.com/gui/url/4dc2290782b1719716b9baeefef661c9e0308f3bf26df6726239b7fadb483d7f ||23.94.26.138^$all ! https://www.virustotal.com/gui/ip-address/23.94.26.138/relations ! https://www.virustotal.com/gui/url/1a40cdf06751e1059cb93468639753d245b4c8b8dbc5401e5652ab146b738057?nocache=1 ! https://www.virustotal.com/gui/url/8a1c1dc11bea3c96ed1685368b431afe7e541aeeffd09494261293f21f113404?nocache=1 ! https://www.virustotal.com/gui/url/fc2d3355d386d3eae4f313b174c23bd0b0f35599cf222e94e034a66857ea5464?nocache=1 ! https://www.virustotal.com/gui/url/c58a2554592c21450744a41ee03fc196b098ca609bf2cac6e8b2798eccd7a80d?nocache=1 ! https://www.virustotal.com/gui/file/7ef56a82a83ab840c3dc7a517e67cf2875c76263e81dad66698de25e7a1e865e/community ! https://www.virustotal.com/gui/url/570a9fdbd5145712d82a43e08d5c1ce6c17f394e85d9c39295e780fb969a593a ! https://www.virustotal.com/gui/url/10aa65571902cf6abc9bcaf353a63ad231331591c66bf5800413aaf3068a3b36 ||180.214.239.85^$all ! https://www.virustotal.com/gui/file/cd2eaa79448009041ecc926c273b4d483bccaf7c2cd39624082c3e13d55408a1/community ! https://www.virustotal.com/gui/url/94131d10db1e09aef40743e05133692300ff2994da0ada78a3e0fb680506afa6?nocache=1 ! https://www.virustotal.com/gui/url/67c5f375a7df94bc12559dfb204ca17fff5b5b7b942b4c2734def17a20207b91?nocache=1 ||54.179.71.39^$all ! https://www.virustotal.com/gui/file/294b8db1f2702b60fb2e42fdc50c2cee6a5046112da9a5703a548a4fa50477bc/relations ! https://www.virustotal.com/gui/url/f7bcb5331617155b9f4b4941030f339d10dd0ecb4528514dc441229f175bc949 ||160.202.163.100^$all ! https://www.virustotal.com/gui/ip-address/160.202.163.100/relations ! https://www.virustotal.com/gui/url/3818bac5233b17d11c0744005712a5761596f33ac54c23565eb08b5496323d48?nocache=1 ||microsoftkernel.com^$all ||update.microsoftkernel.com^$all ! https://www.virustotal.com/gui/url/7709e9dff92c359c920e31866268a04489a67fc2e415bbc8c20cea8604387121?nocache=1 ||hksupd.com^$all ||amazon.hksupd.com^$all ! https://www.virustotal.com/gui/url/c8da0d48ea7be9444411840955f2a658c3f6fbfd3dcc87df29fe0c13a6b9b604?nocache=1 ||microsofthk.com^$all ||update.microsofthk.com^$all ! https://www.virustotal.com/gui/url/956c451fe61038377026bee53c4eeff67ab3efe69f5c4c6e22b3c1dbde10ced1?nocache=1 ! https://www.virustotal.com/gui/url/8c1e1a8a80c515d411b4e22d36ddb0535427c73f2b7c8b3ae7a672ad208c89b2?nocache=1 ! https://www.virustotal.com/gui/url/681dfdb12bcaa2facfb6eefe51d671387f111134f1661e336d63c5e6b207aa10?nocache=1 ||bilalimtyaz.co^$document ! https://www.virustotal.com/gui/url/efdaf6927a66f267f8e834a1d685e76025f3c8ad29b8d950289ceb43c18a3477 ||machinesalaver.net^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-938682090 ||eliteexteriorsystems.com^$all ! https://www.virustotal.com/gui/file/9e3dffa7e605e588d50dc9a3cb7b72edacd73c4d85c0ab63a20929098d5ffbc0 ! https://www.virustotal.com/gui/url/3bb22ede9e498fac449305f49745e12bfd41ae1e68c9c3673ea501b02b5ca2e6 ||45.132.104.217^$all ! https://www.virustotal.com/gui/file/b568614fe33d732014980f0bb083e9abf45641f2dc230571eb3d63d6bc7f10b0/community ! https://www.virustotal.com/gui/url/89c873e305305486384d53b3c99468848f5fa672f87b9d9f398b157011e1bcb4?nocache=1 ! https://www.virustotal.com/gui/url/3d94e257aef5ab448f19fb32ca4f543300a41239a6f87309633d5e31218b6d57 ||139.59.93.223^$all ! https://www.virustotal.com/gui/file/da8e8a3674bb74752cc61703310b75756db86196f957dcbb1efb64dec6f45280/community ! https://www.virustotal.com/gui/url/448da47e3e945d8ff23f94c90b37767c8901803ee7ce24cc0145f10a3f6ebc2f ! https://urlhaus.abuse.ch/url/1661195/ ! https://www.virustotal.com/gui/file/a8e1e13995a1af35365965d172b801e128f52da0afc6a6a6fc7180210614c2fc/community ! https://www.virustotal.com/gui/url/2c062edfe4bc49c0e194c953c511efbeeeb1e894394922f685ec9dc16acd5001 ! https://www.virustotal.com/gui/url/a119a996204d12ffa0314429dbece549931f3bf0135bca6a258cfef3c56658ff?nocache=1 ! https://www.virustotal.com/gui/ip-address/172.64.80.1/relations ! https://www.virustotal.com/gui/url/ebcf1fd2f7371d21cdcc9f3ccee579ed86f8afcdeafd1605337edd9263d84525 ||6c4db3c7.voag.cn^$all ! https://www.virustotal.com/gui/url/dd6d65d835a115152a569ce2956ccbd068d73b785ef819d983222fc5c888f780?nocache=1 ||voag.cn^$all ! Subdomains ||4a446163.voag.cn^$all ||680c2a7c.voag.cn^$all ||5acdae4b.voag.cn^$all ||ac4e9cca.voag.cn^$all ||2280fc13.voag.cn^$all ||5cf1fce9.voag.cn^$all ||8fde7a98.voag.cn^$all ||f7e5f8c8.voag.cn^$all ! https://www.virustotal.com/gui/url/1d6d895e31ee0309478435925e1fc0e46ac8e0f3b559b7e4a8e399a356590e00?nocache=1 ! https://www.virustotal.com/gui/url/0667143920224986a70d91f82898402058d4ad3fb3a68696b4e27e8b40c0f9c0?nocache=1 ! https://www.virustotal.com/gui/url/643c8146935a0fdfff56258dd2728fe932a045c62fe7cde7b0891245ecd0a7e5 ! https://www.virustotal.com/gui/url/7a00203cc28e3b8f3a97e7f48c8180549b3e5e8b96c5fe1527127b1451a06853?nocache=1 ! https://hybrid-analysis.com/sample/e454f5042ad548a813a0c1b6632b598402a217a1461bd7440f0e429eacccc72b ! https://www.virustotal.com/gui/url/52ce844b63b58e884bcef53d1ae4c70ddf9188869c736d6077fe3a4a4670c30f?nocache=1 ! https://www.virustotal.com/gui/url/df1a3b48d866b6a20e3e63a851b4c71fd613b81e22a4bbdfe41e1c3546017204?nocache=1 ! https://www.virustotal.com/gui/url/ea7706ee9a7caa025cdce0328ead4efd53b6329cdeb5a7664532878994061a6b?nocache=1 ! https://www.virustotal.com/gui/url/abbdf776c0429d77396488a3de15eb54028477dccbd13faf405686bb6b0339aa?nocache=1 ! https://www.virustotal.com/gui/url/c6e4e51aaafda4a149819ff6a28a2b73f3c11e844b456e0da5fbd169f5c1c88c?nocache=1 ! https://safeweb.norton.com/report/show?url=octarine.cc ! https://www.siteadvisor.com/sitereport.html?url=octarine.cc ||octarine.cc^$all ! https://www.virustotal.com/gui/url/354b22add703bce89084132b7cc6abd16caac0d35098577bf06b4103afbd8ef3?nocache=1 ||ws.octarine.cc^$all ! https://www.virustotal.com/gui/url/63cc40f11fe21e1f077686a0c5b7a0cb7b18602a8f835f5c29c3ea40ecfedac2?nocache=1 ! https://www.virustotal.com/gui/url/b5885857aceb9e5b077828d683d6484cb243ae95f4fdd79b4eac27bd7a212d31 ! https://www.virustotal.com/gui/url/b864e3e2e32b719ae3ba41ca16752fb765ac20c2e77eda8e1123168ef1270465?nocache=1 ||jom.diregame.live^$all ! https://hybrid-analysis.com/sample/4976e4d130aa052632f5b4d6150df9a050e1d5adf9ddc2612a286a854492cdce ! https://www.virustotal.com/gui/url/8c67caae75ffe7756658c4bfe1696e7eebc23eb0f723842449c3ca09be84766d?nocache=1 ! https://www.virustotal.com/gui/url/1104002040080063d7ca57d02838d161e621747032c00fa60483c3d3fe64ff58?nocache=1 ! https://safeweb.norton.com/report/show?url=moja-kapa.si ! https://www.siteadvisor.com/sitereport.html?url=moja-kapa.si ||moja-kapa.si^$all ! https://github.com/uBlockOrigin/uAssets/pull/10163 ! https://www.virustotal.com/gui/file/5a0cf59fd7743ab14b9a66b5b1e07c52858109cab2ab7b2c68c940cd0a4fa5b1/detection ! https://hybrid-analysis.com/sample/5a0cf59fd7743ab14b9a66b5b1e07c52858109cab2ab7b2c68c940cd0a4fa5b1 ! https://www.virustotal.com/gui/url/b2936e74f35940d2f09cabf4e089a0d655e62a5fc08ad32e1fae79a62683683f?nocache=1 ||saimission.org^$all ! https://www.virustotal.com/gui/url/4c2c3cf2e4f5b9ac9765eb9c58f2756d8f0f4632ec707107afe3c111f4749025?nocache=1 ||grub-wa-saya.duckdns.org^$all ! https://www.virustotal.com/gui/url/411427085af5318248b505bf1e2decdad6240bb5b8f1db7f49f6620708b47d4b ||fpgiwybtgx.duckdns.org^$all ! https://www.virustotal.com/gui/url/436718654a084939837578f580894f800eadd8dfddb5ad4ca6eb906024f74017 ||wagrubhot.duckdns.org^$all ! https://www.virustotal.com/gui/url/0c9a0747e9331f8c172700cfda3bf23fbc5bea205f7744833c0a2edb1f5d6981 ||newxporn-getxi7.duckdns.org^$all ! https://www.virustotal.com/gui/url/40b5bc0be82da405df9850f26ad80f1bd1a72b60a36f30de9918a2ecbfe602c5?nocache=1 ! https://www.virustotal.com/gui/url/67311437a681e827d4159aa5c022388c45a2097d777992de386616c9d4dc2694 ||pemersatubangsa18.duckdns.org^$all ! https://www.virustotal.com/gui/url/28761eedd41dee27148dfa1df9accc5bd0742032de3e488f0b3f0502a5679976?nocache=1 ||grup18com.duckdns.org^$all ! https://www.virustotal.com/gui/file/22dcea7dc8afc3f7cf77555d885e606260b782de2ad4faa7797e35ed23fcc428/relations ! https://www.virustotal.com/gui/url/69adfadca578dec1ae7e3007de381bc076ecbe6bcb6e95e4361ea40204a9adc3?nocache=1 ! https://www.virustotal.com/gui/file/ac5a95221b895545eb04cfea29693288d7b432ad313f6bfc9db2ddf86f085a63/community ! https://www.virustotal.com/gui/url/d5b4a8add4c074afa6887f2cacda6d07aabfc25b53728001e8de1fb85f32582e?nocache=1 ! https://www.virustotal.com/gui/url/70e9fc15c4913c13f47ce4e085a7625dc4d712770cd49cd5c86a30ca169aee29?nocache=1 ||205.185.126.200^$all ! https://www.virustotal.com/gui/url/febe7565c3ff6ba247da14f06b3ca155d1c77ac3c20e93bf196fbc8c7b943331?nocache=1 ||605b10322b729.site123.me^$all ! https://www.virustotal.com/gui/file/3ef65ce27d39b037d75bdc16b197e04f3b391f76c2da5f2f755e2ded38bb9078/community ! https://www.virustotal.com/gui/url/fb675f6f5d90598bcc792d1cbd18302ad9457aa2883dc0cfdb2c720d9de42a57?nocache=1 ! https://www.virustotal.com/gui/url/28745947521bae73bd6f6409fe5838658e998773ba8ea2cfee63b156f9fe1020?nocache=1 ||185.243.56.167^$all ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ! https://www.virustotal.com/gui/url/1b6411341db43ee0e103a6771fc278c07f1e94341782d0a38a0ebb3e7cae25bc?nocache=1 ||123.10.224.135^$all ! https://www.virustotal.com/gui/url/0bf4563b2b7edcf1cdda44386e3ab0bdcd2ba2be5316ad183865a51c2e91387b?nocache=1 ||59.47.187.147^$all ! https://www.virustotal.com/gui/url/e9680891a79909f7e63ed8a658650e8624bcdf44f3d8379566a29ecb711d145e?nocache=1 ||39.68.172.210^$all ! https://www.virustotal.com/gui/url/41a01962603b2c580a463d801bea272fbcecf493beba463fffce1213f25f20a8?nocache=1 ||122.192.177.176^$all ! https://www.virustotal.com/gui/url/d7adbacb0f2a223731a24fb9be00077f7845c6290cb4b7c7bbc73c069b456ca0 ||112.27.124.108^$all ! https://www.virustotal.com/gui/url/1b453a8e762b93a64b4321fa9b07a127a538d73ac14c19c2580c0e6cde5e4d3f ||123.110.176.246^$all ! https://www.virustotal.com/gui/url/7c81238193b7e54a14c477788dc799810356a43ff3929f722546b1cd2f65f7b9?nocache=1 ||219.155.105.98^$all ! https://www.virustotal.com/gui/url/161e345165cd1d4a9111c81afdbf61f09dc5be26e1bacc02e65823e65923fe8f?nocache=1 ||171.35.161.209^$all ! https://www.virustotal.com/gui/url/812ea2ed646160e7fd82987c6d83f6d9b2c3c9726abb76863d0c28e22f788804?nocache=1 ||60.16.255.36^$all ! https://www.virustotal.com/gui/url/4f3478f220b232c42a53d010ccfc6cad4ec5157e72e5bebcbc90359e61e62070 ||112.30.4.52^$all ! https://www.virustotal.com/gui/url/7d1fefc9db7e70a85e781cdc43b14237a35ecd7715ce7d79985884bd2971d9d4?nocache=1 ||182.121.191.201^$all ! https://www.virustotal.com/gui/url/905202f03c5595f613153cedbc1383a9183d3a3541a1e72aa9fa2c38593c54a1 ||121.61.48.170^$all ! https://www.virustotal.com/gui/url/771fc5eb172de7059e8aff24e9f6eb2632c878de0097a7ab638fa6a1ad5fc180?nocache=1 ||39.81.68.45^$all ! https://www.virustotal.com/gui/url/7429dffcbbcf47b076686c1bf9a35d90bd765513125015e4d8d0a2abedb1f481?nocache=1 ||27.222.220.164^$all ! https://www.virustotal.com/gui/url/7d70f7715954110df1eecf412c997f4cea70f0514c28aaa6c963e76223ea858b?nocache=1 ||113.233.215.135^$all ! https://www.virustotal.com/gui/url/80a1ca6449888b3f367faf2e7a764c5d8a3f79ee5f34f91c54a50c00ae849a41?nocache=1 ||151.77.100.133^$all ! https://www.virustotal.com/gui/url/134ed37a0bdc78f4813428721110f959073e57c1fa4b32eeb74b43b7d2a0d9f2?nocache=1 ||125.120.13.184^$all ! https://www.virustotal.com/gui/url/f51cb237eba408cc1d2731ef3895d3e2f387fc98f9c600ab3d5a72e575749da0 ||120.12.138.133^$all ! https://www.virustotal.com/gui/url/02cfb12ffc798aea9b0568f975c9ae1b82f695ed60fefbc5231a0877b2c5ae56 ||27.194.115.185^$all ! https://www.virustotal.com/gui/url/8291b03088a668476582f42d1eec9672d203d071c78b7ad07e29fde4b28146e4 ||104.128.199.228^$all ! https://www.virustotal.com/gui/url/a24dc8c74a775b8c3a352b44b8c65591fe4921fabdf13d18a2f1627b89022c8d?nocache=1 ||183.92.123.145^$all ! https://www.virustotal.com/gui/url/d96de4ab057406b736753dade6be42f9ac2408d522b046ba3be521446f95c623 ||110.89.8.126^$all ! https://www.virustotal.com/gui/url/eeefa4df6822f67375a24b2f246fcdadef830d92fbecea4b3a60de1ac6aca350?nocache=1 ||125.43.211.184^$all ! https://www.virustotal.com/gui/url/7712cb8a7839e638e6fc4cc8a193a6d89f6ed83e4535a33182609fb35d650d40 ||1.0.218.230^$all ! https://www.virustotal.com/gui/url/ce76086e6b1aff6d2e9c6ace79977bf55aea9334b1cb7311c33f25163acee8f1?nocache=1 ||221.208.4.56^$all ! https://www.virustotal.com/gui/url/d42b47613ea7e34544d0ecbabd4f87f9f9a3cc5e591f20792bba7d2a3939adee?nocache=1 ||60.13.60.19^$all ! https://www.virustotal.com/gui/url/b87960d538f41251aabc1af79ab9c936362fa0979df149ba785f680c04cb7340 ||171.37.29.87^$all ! https://www.virustotal.com/gui/url/a31393c5d7605fa0653dc5268a3c035753bb91af540cbc1c30b6b9a75e9746c3 ||124.91.237.188^$all ! https://www.virustotal.com/gui/url/8405e65da5a1f099f78fe3aded2d3e0de8fe9369bf8efb675408ff9b40348534?nocache=1 ||115.56.137.49^$all ! https://www.virustotal.com/gui/url/1374a7760b510ed9d60c8708f7e60dfbe1ac18dbc7e4340f4c0c20051ef8a764?nocache=1 ||115.52.240.69^$all ! https://www.virustotal.com/gui/url/367d62267e42b69a956a623099e16fd9bec3489f401cdf431adb062e79387996 ||112.252.132.185^$all ! https://www.virustotal.com/gui/url/98afd508dc7f0f26e4692dbc1b3a1414077088cb4904942eb4b6e3e11e04ad62?nocache=1 ||117.198.240.157^$all ! https://www.virustotal.com/gui/url/fc9569d79bad2491161a451618dc35e0a87074c16f68ac81389ae5111af0bfe3?nocache=1 ||42.53.240.249^$all ! https://www.virustotal.com/gui/url/ef737d552a0802076baeb00d48afdd1447a50774d57fbbab919fcca123febcae?nocache=1 ||116.179.138.68^$all ! https://www.virustotal.com/gui/url/9296057c150a79c8c99114fdb154554bc7a50bbe0c93acaa9f4261926891ab5f?nocache=1 ||110.241.119.159^$all ! https://www.virustotal.com/gui/url/e752ba00cb7dba369b633133682a2ffe8615d7bfde27a3ed4e734ad31dc15248 ||115.56.31.133^$all ! https://www.virustotal.com/gui/url/1dca00f402c94da166fee7b7ee3faf014c7b0806250e403247b0b64738771921?nocache=1 ||103.19.128.222^$all ! https://www.virustotal.com/gui/url/027a846c435be2cf82e78beeeaf3f6afd79a0abcb6234a09ddb5e3e1b6e8570e ||202.12.80.74^$all ! https://www.virustotal.com/gui/url/c0546aac84941e9e0ffa74c2de4ca427c8ae1dfa4cb7be133d7b6fc14c4917c1 ||61.52.8.62^$all ! https://www.virustotal.com/gui/url/c3879dfc346c4d95cc9a535a8dc94c15a4a19e15e85325c5fdfdadc30cd66bc1?nocache=1 ||182.122.252.69^$all ! https://www.virustotal.com/gui/url/4143195d0b3a11438b8c2d81768da73c02ab36212ba25341393574bfcb049fca?nocache=1 ||219.155.26.50^$all ! https://www.virustotal.com/gui/url/ab3c79dd959feac26208d85bffa2c31a5a62949811ec1450e731337ed5f3ae82 ||120.4.141.185^$all ! https://www.virustotal.com/gui/url/cc46e6c96f62fd5c99702737f0441c04cdd02597fe1dc631a38c1b7c0e64168f ||119.102.7.115^$all ! https://www.virustotal.com/gui/url/2d02c4d08debbbc737fee2dbedf41643834f9ac03ae8d32e49640673f33c28ea ||72.51.127.213^$all ! https://www.virustotal.com/gui/url/b549acb73dfc35046297ffab4555afb3fb9dd69babfec9324aaf416c202f1d09 ||111.224.199.91^$all ! https://www.virustotal.com/gui/url/e0175c30aabf4fdf40882ec786fc3b346a494768570ee9b2cb9dbef35fee92c1 ||119.250.236.122^$all ! https://www.virustotal.com/gui/url/3befbd0bb64cb329b2c3de1132dce951dbbb13f686475859cb3b9acdf3fe2a1e ||112.30.110.58^$all ! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community ! https://www.virustotal.com/gui/url/a73ae95ae16ccf277716f60f006ff48bb52fe173c6e5402bb3ec448494d6ad9a?nocache=1 ! https://www.virustotal.com/gui/url/a5a74aa84b015f5f0a524e2a877a27c36040cbdcb11625a103eacaa6b64a2392?nocache=1 ||117.196.49.21^$all ! https://www.virustotal.com/gui/url/0c2a562b191bde0b86d73e7aa5c4042a71451749fc8df859450167797cf9a164?nocache=1 ! https://www.virustotal.com/gui/url/2382894c49af45a11e28a4c49babe07d8ca4af8d43f104dfb8336ec11ebf613f?nocache=1 ||115.55.54.234^$all ! https://www.virustotal.com/gui/url/698af71b0e57a269e3968a2c123c4397f43705f429f1439da0225fef997d670c?nocache=1 ! https://www.virustotal.com/gui/url/2fda12c8a155eb3a41131e04f2588ca5cda0464af07291a05a46c2a7c222242e?nocache=1 ||115.52.17.123^$all ! https://www.virustotal.com/gui/url/41884e1e70730c02752d9006dc05d8728a9d0dfed0afdb2d499e232b94bc4ecc ! https://www.virustotal.com/gui/url/7d27f3643e713b15d5ab0dbd5d617d8a6ca433551812d8bf64bbcff9c381b4b9?nocache=1 ||182.59.69.21^$all ! https://safeweb.norton.com/report/show_mobile?name=rosmjbees.com ! https://www.virustotal.com/gui/url/5b1dc9b2ec70e28b5f6cbb282a598a1b2ecd4df2aebb66953ca9194fa1c9c4fb?nocache=1 ! https://safeweb.norton.com/report/show?url=216.21.13.15 ! https://www.siteadvisor.com/sitereport.html?url=216.21.13.15 ||216.21.13.15^$all ! domains which resolve to this ip ||nctylivpwhpby.com^$all ! copied over from URLHaus ! https://www.virustotal.com/gui/url/17dc2fd952fa93eb7454c0b4c28c64449cfa304698cdb548ca3eeb8bbff74ac5 ! related ! https://www.virustotal.com/gui/url/f1eea95b1481268d62d7364db652c7270ba97eefab0baf95900fe7a41f762c56?nocache=1 ||big5constructnigeria-staging.bitkit.dk^$all ! https://www.virustotal.com/gui/url/b8204dccdc491d684fa368f4d6e86c8c534d4850b6e3d4b84fc0c3258e620f6a?nocache=1 ! https://www.virustotal.com/gui/url/3845cb00bad4746c089783fd17e726b591247bbc8b1d673c48c1aeb1af1cc8b7?nocache=1 ||www.big5constructnigeria-staging.bitkit.dk^$all ! https://www.virustotal.com/gui/url/0a0ed26862fa61faae7e9f4fe22522e3a395a817f7b1f23d121d3bd7d97af5f5?nocache=1 ! https://github.com/uBlockOrigin/uAssets/pull/10169 - possibly hacked ||gesas.it^$document ||techinnsrl.com^$document ! https://www.virustotal.com/gui/url/3737397e3af4c892d182fdc420ee8467fa015bcae8837fa4c1e63ee9bd6e9f9d?nocache=1 ||185.157.160.147^$all ! https://www.virustotal.com/gui/url/98d8108b746c5bed4db858d5de5452cff0a4d17856a620da815b1e4faad92168?nocache=1 ||yz.videomarket.eu^$all ! https://www.virustotal.com/gui/url/a69553e45990e6d08196d8fd4bed972e758e185649c16bc5738fa57dc4059e1a ! https://www.virustotal.com/gui/url/c06d6fc6ac0fb7515881596dcb257b0a16edcfbc06ea8e0027becdc50a4c6ced ! https://www.virustotal.com/gui/ip-address/94.20.59.243/relations ! https://www.virustotal.com/gui/url/26be2b650afc3fe06f0c08633e766468f9327aea8512c07e655a7c79fdc62b16?nocache=1 ! https://www.virustotal.com/gui/url/ffdbd6e5d385554aaad76b50001face0b4e1dbd665d3436d74c9c81c3335829a?nocache=1 ! https://www.virustotal.com/gui/url/10e53037916cb82151c0cb7a630c45231c91a9242afc3d2acba6f11cbd8b22d2?nocache=1 ! https://www.virustotal.com/gui/ip-address/194.187.98.215/relations ! https://www.virustotal.com/gui/url/589485f2a9db8ab67314ec52809025e2086533acb1cf6f8e9ed2f2504b8a8b38?nocache=1 ||propu.sh^$all ! https://www.virustotal.com/gui/file/3631ceab9eac4c52e320c9bf9f382f1ae228c96f389489bd913da6bd7d5f8cd2/community ! https://www.virustotal.com/gui/url/a3e9fe6b8e0e0543bce87cb78e97d17cc254b6e8edfb0e94266ba88f95ec0f1e ! https://www.virustotal.com/gui/url/a6ead0c6c567d4c35a14e65da5d32329f6d44d109eb57a2ce5a9f5db2fd785b1?nocache=1 ||18.195.143.183^$all ! https://www.virustotal.com/gui/file/f0f215d26e5aa6cd749db53e3f96ad8d24c9a2f0692e6c804adf1602f6ec3147/community ! https://www.virustotal.com/gui/url/5539d655647a3dd2d40cd2aa1c03f44f1aa49539482600610710b6e71281644b ! https://www.virustotal.com/gui/url/be9615fcfca63a85c529c76b987d35adc54e29bce9657f4de638ff71ca69f920?nocache=1 ||20.69.160.69^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-940500664 ! redirect chain ||captcha-smart.top^$all ! https://safeweb.norton.com/report/show?url=pushbizapi.com ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-944619528 ! http://vxvault.net/ViriFiche.php?ID=44061 ! https://www.virustotal.com/gui/ip-address/162.0.228.116/relations ||162.0.228.116^$document ! https://www.virustotal.com/gui/file/d3fa92f89ffbc4403c0f8b95034a61d63cfb47fd11cb7d90b5a8d724250234a3/relations ! https://www.virustotal.com/gui/url/eabe924910281f89fa2be8d328ecb619a75b59fffb80dbfef27e33992485755c?nocache=1 ||75.67.192.125^$all ! https://www.virustotal.com/gui/file/2a6af0d7c17e3263b3763a8710d0c033ab0dda9db8a7d601dc386cfd21ad4b1d/relations ! https://www.virustotal.com/gui/url/67a95a8a933f171cc2ec487d8bdc0054bf2070b7c513dd887b4741deb232ef59 ||24.139.72.117^$all ! https://www.virustotal.com/gui/url/68f621df9f14206a54183b59e0cce8188591f50ef1f1a5f0a5a35ddf15434f70 ||122.148.156.131^$all ! https://www.virustotal.com/gui/url/af6e7172f42cd27e37aea6c0029c00d8e065c2d845f6360018b436cfffb760d6 ||189.210.115.207^$all ! https://www.virustotal.com/gui/url/bbc77a23f33da42c2ac05b5d7397171772e173d0808395d03c6b6409f967ed30 ||78.63.226.32^$all ! https://www.virustotal.com/gui/url/093b94726ea565527812b380ab1527666fc04350cbfeb7085e11142403544e35?nocache=1 ||71.163.222.223^$all ! https://www.virustotal.com/gui/url/f2c886fe02597886a26c3f2e7cc021d19c7098f39344c43ee6c3ef6cd8c93758 ||207.246.116.237^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-944642656 ||microsoftedge.microsoft.com/addons/detail/allblock/nkllnmjaaifdphkfbmedklkimjmnjeen$document ||allblock.net^$all ! https://www.virustotal.com/gui/file/03e4533ba8874c2f4dcdb94bd135914fa4c22ed477d7c0395dc2322b6468e249/community ! https://www.virustotal.com/gui/url/d4edc3f48404ffd820a5659189da3c82fa29f7586aecb9ee84ea6d72a2207225?nocache=1 ! https://www.virustotal.com/gui/url/af67f9f5e36ed9f29b9d336193012f8112b1fbe162c5be27fb827ad6ac9302c3?nocache=1 ||45.148.120.80^$all ! https://www.virustotal.com/gui/file/1a782cab036efa567c2c42b7bae9452bf735be72f0b00d68f6dcba48cea526fa/community ! https://www.virustotal.com/gui/url/14f96ec63d4d6fedab8fa5cc851dde8bb0fbd8f6f3135bd615ae2a2307909820 ! https://www.virustotal.com/gui/url/7e01ac924967f2f68b859c97707c72b3a2c7f0bf24e8edb656cb850b8a925f3a?nocache=1 ||85.239.33.9^$all ! https://www.virustotal.com/gui/file/8a39f18caa77d52e80bec05f584ec50e733a3be1e33551d8902e95b9b0bfe6c0/community ! https://www.virustotal.com/gui/url/2f314d9d54c50bfa06cde62d4d33bf733c3b6ce7595c3f2074aa796cc56b1eec?nocache=1 ! https://www.virustotal.com/gui/url/8e3aba17cb24e37eea6c0500962b5690abf63c63f0b0310616d46d1ab01260a5?nocache=1 ||107.173.176.183^$all ! https://www.virustotal.com/gui/file/54054209c921a68f12a9b29d6e84f1b45cb417bc0b5a99356a245727e0a41e40/community ! https://www.virustotal.com/gui/url/d24f7a50842efda2d7dca42b8d7f7361cf5561212a5a2a60eea431d78bd855f7?nocache=1 ! https://www.virustotal.com/gui/url/d6a3d432703f24b239425d6ef45b90f0890f2d2f575ac275f7bd0a46e7f37cb3?nocache=1 ||45.148.120.171^$all ! https://www.virustotal.com/gui/url/a4f1b7c097442f3aa404dd04ed5635b32462231fed4dadf2f751d3785aa45412 ! https://www.virustotal.com/gui/url/afd3b55acc8456bd313ee79d5a4afe552c27ae228e480b84f23484b3d0cee8b1?nocache=1 ! https://urlhaus.abuse.ch/url/1684798/ ! https://www.virustotal.com/gui/url/6696b04b4423dca4bce15e4cd8e95d8ffa7c0bd6006c82294c6874a4988672e9?nocache=1 ! https://www.virustotal.com/gui/url/453aa63a05f27e9c538af3debc81feed589dfafdbc4418fd8c31d9c53ae7da77?nocache=1 ||futurepreneurs.eu^$all ! https://urlhaus.abuse.ch/url/1686038/ ! https://www.virustotal.com/gui/url/eb15e29ef05a277e52ea13258c53542a459b1b311185b4529a00cdbd5bfaa8cc?nocache=1 ! https://www.virustotal.com/gui/url/31dfc298c286dfa859d8e800a6c4cc3f904e992cf7b40f886e4831cdb46394f8?nocache=1 ||music-dl-asia-003.com^$all ! https://urlhaus.abuse.ch/url/1680922/ ! https://www.virustotal.com/gui/url/aef74a6c5611a362bf2c8d37063f99be8d18df0f83165d4c06fc332514212830?nocache=1 ! https://www.virustotal.com/gui/url/5011653a6058ffd2e70982f0791cae5a6af725a9e86e1cce31f3b3f3d710cf63?nocache=1 ||212.192.241.126^$all ||secure03log.dynamic-dns.net^$all ||secure09gcf.ddns.net^$all ! https://urlhaus.abuse.ch/url/1679960/ ! https://www.virustotal.com/gui/url/f9f5a4461ff700527702d4e6491d24a4d592cdae66b80faa603b5a660bba8ddb ! https://www.virustotal.com/gui/url/5477188e526ece0b3a266ce8490f58091795a54b81576cc675b78279e86890b0?nocache=1 ||ddl7.data.hu^$all ! https://www.virustotal.com/gui/url/39fac2ac9f8aec9816d056b8385988bea46c67cbe5ac373a15d2e889b68a59ce?nocache=1 ||ddl8.data.hu^$all ! https://urlhaus.abuse.ch/url/1680924/ ! https://www.virustotal.com/gui/url/51dddb29490b0512312b74d3e767ca3f01e773fb36081325e58790c6b1f1330d ! https://www.virustotal.com/gui/url/8ab7fd033fa78b557c5651378c38d55b9f17e1deedc25ace256a381c5cf708be?nocache=1 ||kohjguj.ydns.eu^$all ! https://www.virustotal.com/gui/url/5d9f6f4b76a4dfce952e33c42b715bee464f252f28400de529be4dbcd8bc8a09 ! https://www.virustotal.com/gui/url/b79146d6867ccdccd03fe8773c6bed0722d22878a723560684834a1b57dbb30d?nocache=1 ! https://www.virustotal.com/gui/url/19800af912bfe8a7c3e21af62dfdbfdbeb6d15679689b264390db9eb5e7aff61 ||wywtrwbnmhtytrebsgwtfcvzcxgjhyegvbcnmgte.ydns.eu^$all ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ! https://www.virustotal.com/gui/url/49e10c8b02c177cb6e2d33dfdc9edec0a7029857ac6bdbba6a892b4a07382d89?nocache=1 ! https://www.virustotal.com/gui/url/5ef838314d45723bfd3a9b122b4c12ff737f460caada80444d0c61b74ffc03aa?nocache=1 ||221.1.163.134^$all ! https://www.virustotal.com/gui/url/ad0d88d926140a1a5b25e297c14a6dfdd452e49580d900584509150e2d4d259c?noc ! https://www.virustotal.com/gui/url/e5f18b0769f8e072f0dfa6ef1c6bb34fd5129d34e587e71cfb75da7e57bda5cf?nocache=1 ||58.55.175.164^$all ! https://github.com/mitchellkrogza/phishing/pull/87 ! https://www.virustotal.com/gui/ip-address/20.106.143.112/relations ! https://www.virustotal.com/gui/url/8cefce438cb87cc2005741e39dd6dd6c42b24f3558e874f7fc78a81ce2e6a0d6 ! https://www.virustotal.com/gui/url/b55e7caf0c3eb128ec44c7c528f1f7f63d209ba5c5deaa31c4e1454592f9a5ee ! https://www.virustotal.com/gui/url/7bd652f2338d6040c33569d3064ef57693684548831868db12d15b019b2908fe?nocache=1 ! https://www.virustotal.com/gui/url/473b27bb990289bcd530fd8034e21290a4660baab8634c90a8023026b9334bf6?nocache=1 ! https://www.virustotal.com/gui/url/2fc8eead5c798ba6b3e808bd53694a5374e0f3696c0730a9d5c72ee6e8907ee8?nocache=1 ! https://www.virustotal.com/gui/url/4f649d037dba81685361c482e684b1e4ff78c5d9dc3c55fb5f01da049c69adbd ! copied directly from the 'files' tab ! http://vxvault.net/ViriFiche.php?ID=44070 ! https://www.virustotal.com/gui/url/bf6d865eba3f7423017fad5f4e22e06693b2e7a5665eb428f8483207f41567f9 ! https://www.virustotal.com/gui/url/24e41c7dd7dc36f7c5f349f3db301a1aad034839e4410f2689a8ceb541976aa6 ||js-hurling.com^$all ! https://www.virustotal.com/gui/file/deb99e377238d822f514a0e3f141d0ca0d4f5ddf141b00cb23f417310ff9ab20/community ! https://www.virustotal.com/gui/url/4e795f748d91655bb80087c840aabb9e35be51339da54943cb3653cd745fcb49?nocache=1 ||reoildriend.sytes.net^$all ! https://hybrid-analysis.com/sample/691fb304c88929435950c157c1789bc7004e2163a3188cf2fff1124cfa5f00f8/60f6dbfae50e5603767b8f32 ! https://www.virustotal.com/gui/url/b141c859a1246a250183b212cea2e6ed30d90477adc5ae8f3277516f68071396?nocache=1 ! https://www.virustotal.com/gui/url/5b4dc980802a96c630e76148aab4f2cbe7a196d39ffce9a7e3c95bcdc082b64a ||micuenta01.github.io^$all ! https://www.virustotal.com/gui/domain/duckdns.org/relations ! https://www.virustotal.com/gui/url/970d887002c50829eedfbd41155d63b08f7b1fe084013224f4b19b60df3c1aab ||grup-waviral2021.duckdns.org^$all ! https://www.virustotal.com/gui/url/65fa44466d8799b73aa0de19293e679a9d2cdaf059c5d83f0e20333863bfdc35 ||ffgryvsudhh.duckdns.org^$all ! https://www.virustotal.com/gui/url/7f5ef315c5744193c43e2579d64f518a9a9cb5be98a26f74206f86f156be395f ||myamx-rewerd.duckdns.org^$all ! https://www.virustotal.com/gui/url/8bf89bebf2dc8e7c30f7f908a1b65bb357cd24668e573c675552f0e785331a96 ||netconnected.duckdns.org^$all ! https://www.virustotal.com/gui/url/81fb8a39f01958c77db4786839a37e89e2b3527d9e990dc93621fb43fa3b1b17?nocache=1 ||support-user-help.duckdns.org^$all ! https://www.virustotal.com/gui/file/ba37580a3031cbc849b8e59490acad9c028d70fb1338105acb3e1c81faa9ad2a/community ! https://www.virustotal.com/gui/url/c7dc5ef5af74b21e3920103de3605dd92d34e339bd3e43fce056e035b7081ea1 ! https://www.virustotal.com/gui/url/3e651c4851f6a26e20a6b8bdd044689e4cb399eaa592bfdc61d3ca9089511b00 ||136.144.41.117^$all ! https://www.virustotal.com/gui/file/b5cf68c7cb5bb2d21d60bf6654926f61566d95bfd7c9f9e182d032f1da5b4605/community ! https://www.virustotal.com/gui/url/5cc8c191ba6cce3c3f73c1bfa014dad885bc835af52bd7250478675a3ba67174 ! https://www.virustotal.com/gui/url/df2c29753d7b0901040e7a26ac90653cc48a03fa48139996b1ea1109fc940484 ||221.15.216.46^$all ! https://www.virustotal.com/gui/url/ae21d8e063b291b5ba4981116bb64baaa63389f269d553960ae444c5a3548fa8?nocache=1 ! https://www.virustotal.com/gui/url/18ed811ade6ae9ec8e7148a2ec64e32efa79932846699cd80f58fd7ba982993a?nocache=1 ||59.93.23.101^$all ! https://www.virustotal.com/gui/url/64babbfb323b40df5b768265183886fbed60ea92234da1a2e4b85acfdceaf0aa ! https://www.virustotal.com/gui/url/4f827d8be6d25fa88c1ebe74800b6743d7e289b0f904b6f3445486b3ccac2797?nocache=1 ||tristreamstv.com^$all ! https://blog.malwarebytes.com/threat-intelligence/2021/10/q-logger-skimmer-keeps-magecart-attacks-going/ ||cocolatest.sbs^$all ||pinokio.online^$all ||sitetraffic.site^$all ||spacecom.site^$all ! https://twitter.com/soranker0/status/1449491402409185283 ! https://www.virustotal.com/gui/url/0766604b5f6e96930bd704fa007c07984b5e2c726633727176c8190f641e1050/community ! verified using VM ! https://www.virustotal.com/gui/url/2d5f25a5a72003888f05cbbd8bb0b14e9e81c53193314dd83b6415b68a20ca70?nocache=1 ! https://www.virustotal.com/gui/url/43f91dd76b8f8216917b6ae9083136d68926c203274f85457384c97dfc0548ba?nocache=1 ||sz1sz.com^$all ! https://www.virustotal.com/gui/file/db9ac5558ca84d3a90428ddab6cbef971ca4051095438370481dbf7c28e2bc78/community ! https://www.virustotal.com/gui/url/7a40be431cf8b656f20e17256d307aeae731381b29a950e45f625f02190c0ed6?nocache=1 ! https://www.virustotal.com/gui/url/0ec73bc704f4ff831d1d38144799576bb6bebeea9f86fc3f5ec19645ebba6547 ||183.83.187.89^$all ! https://www.virustotal.com/gui/file/e15e93db3ce3a8a22adb4b18e0e37b93f39c495e4a97008f9b1a9a42e1fac2b0/community ! https://www.virustotal.com/gui/url/30176cb0ad2145d36b76db2993e6f2acbf141f580bef84d9051661b1fd31ca5e ! https://www.virustotal.com/gui/url/662fb53097807500c3abf5062ef22d68d646515e11f96715d039446d2932adce?nocache=1 ||114.239.16.227^$all ! https://twitter.com/JimBrowning11/status/1449864787953868805 ! https://www.virustotal.com/gui/file/a24784cc4bd53f7d3ca9700802dd60d01bf245128e95800ccd60841f1e1075f4/community ! https://www.virustotal.com/gui/url/bf84d1d244fe0a0d411228d638bb7f6a3375dd19e6669990742c5a624a0bfc1b ! https://www.virustotal.com/gui/url/158dc023198fd5d8e79f945d1d0870f0671a51b120605f7aab26b224e0d417a0?nocache=1 ! https://www.virustotal.com/gui/file/a56535178bb2c4e9fdaf4c5c6d26d58224b9bfac8b0c4be2b035b778e6ef6d9f/community ! https://www.joesandbox.com/analysis/507864/0/html#domains ! https://www.virustotal.com/gui/url/0dc6b3a097d135dbbd708be923fb7427a9c15ab16009f13b5905b811aeea9704/detection/u-0dc6b3a097d135dbbd708be923fb7427a9c15ab16009f13b5905b811aeea9704-1634881745 ! https://www.virustotal.com/gui/ip-address/78.155.222.151/relations ! https://www.virustotal.com/gui/url/17695b568788594c391b2e9f4c5ba1ae25865ca5ae26fa4435d02431f490d427 ! https://www.virustotal.com/gui/url/71d5f737637145ae7ec15c1e52e28be336b31a737c6f2452408a805024fccc54?nocache=1 ! https://github.com/uBlockOrigin/uAssets/issues/10171 ! https://github.com/uBlockOrigin/uAssets/issues/10181 ||nbryb.com^$all ||onemacusa.com^$all ||realnetnews.com^$all ||rogueleader.org^$all ||suggestive.com^$document ! https://www.virustotal.com/gui/file/21efc6a91a56c7948115df6ee19e1c865b95a5dc3258fb4361bee551e856cc02?nocache=1 ! https://www.virustotal.com/gui/url/32cf7e0b49d8353ffb6ee19f7d54e4b1e828cb8edaf3acee674f672f00b4a948 ! https://www.virustotal.com/gui/url/5b2132496c0a7121f510561bb47ec5b3d0a015720a40217c2e10bfe0397273cd?nocache=1 ||localwithg.com^$all ! https://www.virustotal.com/gui/file/b3d979fd0876b2d43950db136e955040858bbad86b047eecf937218be20a7171 ! https://www.virustotal.com/gui/url/9a20d028b1755374bc8379519d9af357b9f818d522573345dae25797e9c315a8?nocache=1 ! https://www.virustotal.com/gui/url/6b073e110b81dc18d9bc95df262bc93410c73789a0c5c0cc055152f8fa3a47ea?nocache=1 ||moddeeeuiewuiwehew.000webhostapp.com^$all ! relations ||td634805.000webhostapp.com^$all ||eftrenet.000webhostapp.com^$all ||kjilod.000webhostapp.com^$all ! https://www.virustotal.com/gui/file/d88640b60a99a39f22a11731d0fc886fd2c9fdfb094f42886e6ba419025e69ec/community ! https://www.virustotal.com/gui/url/abc5fea5e762b77da6a300237c5e8fc355f939b0150bde4c8b7c396f7469216d ! https://www.virustotal.com/gui/url/ecd58f7b49ef63c477bd358521b5ca0516e5c1dcf024e0b42d307445e05e87ad?nocache=1 ||185.215.113.77^$all ! copied from https://github.com/Spam404/lists which was maintained by https://spam404.com, but which appears dead ! LICENSE: https://github.com/Spam404/lists/blob/master/LICENSE.md/LICENSE.md ! modifications made: selected alive scam domains, added the domains which they redirect to ! if I have misunderstood the license conditions, please contact me via GitHub and I can remove this content ||rarshare.com^$all ||www0019876.com^$all ||megapolis-hack.com^$all ||4291g.com^$all ||cheatsbasis.com^$all ||www.cheatsbasis.com^$all ||2014tools.com^$all ||surveyvoicesresearch.com^$all ||b.surveyvoicesresearch.com^$all ||surveyvoicespaidsurveys.com^$all ||usarewardspot.com^$all ||o.usarewardspot.com^$all ||peoplesearchusa.org^$all ||www.peoplesearchusa.org^$all ||free-hack-tool.com^$all ||online-secure.free-hack-tool.com^$all ||festinus.xyz^$all ||apkhackz.com^$all ! https://www.virustotal.com/gui/file/d9b62fbea306108718fa0aff46b8fef9831c420fab644e76ea1b95abd6d837f8/community ! the password for the RAR file is 111 - the exe inside: https://www.virustotal.com/gui/file/0218dd62759681af9aa77bfbd8f43af8de695b7426bb74aecdcd9f25ee53f3da ! https://www.virustotal.com/gui/url/ba49ec05e194d21d7f903067ca99fb28ad8fe586b2fc17dbc8482d1b96b1c6f9?nocache=1 ! https://hybrid-analysis.com/sample/0218dd62759681af9aa77bfbd8f43af8de695b7426bb74aecdcd9f25ee53f3da ! https://www.welivesecurity.com/2021/10/07/fontonlake-previously-unknown-malware-family-targeting-linux/ ! https://www.virustotal.com/gui/url/f3137ce6af12221e3c89953f2365c963032695bc2187b5e0007748068397f90b?nocache=1 ||47.107.60.212^$all ||test-sumanshop.i-retail.club^$document ! https://www.virustotal.com/gui/url/965c9a701ea98f0712fa25fa1c8222d5a80c1bc06e5a7178f698145064fc61c0?nocache=1 ||47.112.197.119^$all ! https://www.virustotal.com/gui/url/493ac3289a71de77801f2fe2a9398342db20232dc61e31e9d9cdb2f2bb69aede?nocache=1 ||156.238.111.174^$all ! https://www.virustotal.com/gui/url/0e764be2148d3f2dd1a8ef83726fe30a604817b8e78141a2e637dc46323ae29a?nocache=1 ||172.96.231.69^$all ! https://www.virustotal.com/gui/url/e59ad4ec1667e5893f6ab673b3ba1459a4eb8296650ae210bd6d66501d78d339 ||ywbgrcrupasdiqxknwgceatlnbvmezti.com^$all ! https://www.virustotal.com/gui/url/dccf23cd90d0048b3ad9267199ea4b22d19016825b29f63309524805cde54ef3?nocache=1 ! https://www.virustotal.com/gui/url/c3adbd339810edafebf8ccc5819a06e0c8d1fb1c0156d816e481ba0be4c4920b ||yhgrffndvzbtoilmundkmvbaxrjtqsew.com^$all ! https://www.virustotal.com/gui/url/e467e9e449d7c375cbebf3e04f6afd9943084d79437b1043f56a8a38a41ba932 ! https://www.virustotal.com/gui/url/bdad8846cfe9cffdfe63c56d333a14a580b7e54b0fcb3e1e1faa397e7689e388 ||ruciplbrxwjscyhtapvlfskoqqgnxevw.name^$all ! https://www.virustotal.com/gui/url/7c8b73e89ec7c0c5c8daf50b6849630831213a3c86f1834964ef7143f5fa4d93 ||pdjwebrfgdyzljmwtxcoyomapxtzchvn.com^$all ! https://www.virustotal.com/gui/url/098d8f3b71612dd6820535f33d37d0ff6d5664e52bca3ceda95593414059bdbb ||nfcomizsdseqiomzqrxwvtprxbljkpgd.name^$all ! https://www.virustotal.com/gui/url/8f2988fa917c183fbd653fef765785ca442aacc536d6858edde5cb7b87a4c9c7 ||hkxpqdtgsucylodaejmzmtnkpfvojabe.com^$all ! https://www.virustotal.com/gui/url/13aa4d7c701883f00056378d3797235cb2a02ec6db92d3f05288b367a550b01a ||etzndtcvqvyxajpcgwkzsoweaubilflh.com^$all ! https://www.virustotal.com/gui/url/dab6733a9fe1a7d60c2ee530a3d4c55e854b1e27cf0d6f6eb5e780b6bb92313c ! https://www.virustotal.com/gui/url/68f784279b6138317f18fd2575e00f4789ea44bb5b6fd78329ceb182f3cd9a26 ||ekubhtlgnjndrmjbsqitdvvewcgzpacy.name^$all ! https://www.virustotal.com/gui/url/176ef35507b54fcd3ca42471e2d36625a0a9e2aea57b4df1072c9d9f6afe4237?nocache=1 ||27.102.130.63^$all ! https://www.fortinet.com/blog/threat-research/recent-attack-uses-vulnerability-on-confluence-server ! https://www.virustotal.com/gui/url/8358816d5392e0cd20312af72282f69fc431e70cd7ab318529168509e3ffd2de ||86.105.195.154^$all ! https://www.virustotal.com/gui/url/f8984604b73742cf8663b6816814981bf28136ffe47af0ad92ea3a9db2c801d3 ||86.105.195.120^$all ! https://www.virustotal.com/gui/url/4fda6271810622e366883f83badc53d629024139f733aaded9c50487f6373cec ||2.57.33.59^$all ! https://www.virustotal.com/gui/url/d4f07016b352451f5f13b9762ddde7dfbacd60e08c4bb22003ae031c82a07f1b ||141.98.83.139^$all ! https://www.virustotal.com/gui/url/ad771d59bbbb4f37fc90d9e2698c8d4ac2e6c67465fe5eae69bb361a9ee25677 ||98.239.93.20^$all ! https://www.virustotal.com/gui/url/ab2f3849b39a755cdfe0510d532b2f7d9c4f76a7fd0da564c95ce50ded470e27?nocache=1 ||209.141.50.210^$all ! found when searching for "iam-py-test" on Google - starts at hxxpx[:]//google-yandex[.]info[/]iam-py-test ! https://github.com/iam-py-test/investigations/blob/main/2021/10/24/1.md ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-950351144 ||google-yandex.info^$all ||cloud-apps.store^$all ! https://www.bleepingcomputer.com/news/security/popular-npm-library-hijacked-to-install-password-stealers-miners/ ! https://github.com/faisalman/ua-parser-js/issues/536 ! https://www.virustotal.com/gui/url/742d7241eae804d130351df3b936980e4c89d98a3c59ab98a8bd25cfe6019069 ! https://www.virustotal.com/gui/url/c8d68722a01ab94c011ecf3ae6ccbfd709f406ab985968cd977ba4b2de0d37ad?nocache=1 ||159.148.186.228^$all ! https://www.virustotal.com/gui/file/b64ab676ffe01925adc506eebcc62f6edc901e017c339af5d90f6d64292e9822/relations ||abmaxdigital.com^$all ||shpak125.tumblr.com^$all ||iplis.ru^$all ! https://www.virustotal.com/gui/file/3ae5f736bfce95b0611a36c8bcfa56bf0f13a00f69076bd9c70cdac71f6dda61/community ||persianlanguageonline.com^$all ! https://www.virustotal.com/gui/url/2e874f308e1202ce4deb4068d029675c8487bed465f3bd34aeefb4a84c6b767f ! https://www.virustotal.com/gui/url/859be64d71834dba1693b079ec85f77edcd06124031c65178838555fea31efd7 ||dliscord.com^$all ! https://github.com/blocklistproject/Lists/issues/537 ! https://github.com/blocklistproject/Lists/issues/538 ||gosuslugi.contact^$all ||gosulugl.ru^$all ||gosuslugee.ru^$all ||gosmslugi.ru^$all ||gosuslugji.ru^$all ||gosuslugi.agency^$all ||gosulgi.ru^$all ||gosoogi.com^$all ||gosulvgi.ru^$all ||gosusnugi.ru^$all ||gosuslugi-kultura.ru^$all ||ciel-goshugi.com^$all ||www-gos-uslugi.ru^$all ||gosusluslugi.ru^$all ||gosuslugi.xyz^$all ||gosushlugi.ru^$all ||vgosuslugi.ru^$all ||gos-uslug.ru^$all ||gosuslugigov.ru^$all ||gosuslugi.uk^$all ! https://www.virustotal.com/gui/file/a1123c1ba1bf3a47f43437b5c7893131c12b9a7d189e49f60839e9f8daea3662/community ! https://www.virustotal.com/gui/url/136dd3869177d63c9c99a771bd875ae77dff18a87c6b892458f5564fadd565f5?nocache=1 ! https://www.virustotal.com/gui/url/e91d248f40f31b2b3984b6d3338e676d7ab510b4ed88520366a66634fc44c359?nocache=1 ||bkbikesport.com.br^$all ! https://www.virustotal.com/gui/file/a1123c1ba1bf3a47f43437b5c7893131c12b9a7d189e49f60839e9f8daea3662/relations ! https://www.virustotal.com/gui/url/f64d35892ec14f82099472bdb320beec2953f08d2346528fe7c4e250be08b741 ||192.46.210.220^$all ! https://www.virustotal.com/gui/url/e3de026ddca2a2c35150d5fcaa404c0fbcb00526851ff7b7deb9a1eed3f0d1df ||143.244.140.214^$all ! https://www.virustotal.com/gui/url/c4cbb96c48f1330dfef8bb89d1fbe651eba51acdb7e37de6a3ee3ab4ea41c13f?nocache=1 ||185.56.219.47^$all ! https://www.virustotal.com/gui/url/fec5ac33bcfbbeb563676c5ccb9ac48d4b56c25f88424278011ae89074f26913?nocache=1 ||45.77.0.96^$all ! https://www.virustotal.com/gui/file/0a2b70617c3867acb5c762b8cb1136d2cf67b09eedfaa6d5c0c22f8adf8f68ee/community ! https://www.virustotal.com/gui/url/4af299d39303fce61705804b80e05aae005917eb659367dbe409afe54254eef9?nocache=1 ! https://blog.talosintelligence.com/2021/10/squirrelwaffle-emerges.html ||168betclub.com^$all ||abogadoaccidentedetransito.com^$all ||abogadosnegocios.co^$all ||abufarees.com^$all ||acordimobiliar.ro^$all ||acquafontana.com^$all ||acuafuego.com^$all ! https://www.virustotal.com/gui/file/711a5e2cd2dc83c0711b9995db62072da4cba477cd21a1a9a95cd5d92e6f9185/community ! https://www.virustotal.com/gui/url/1a8cfe7b5f57bb3b1a4cb40ef2627065a22b9df80d6529ccea5a9ac5dc518671?nocache=1 ! https://www.virustotal.com/gui/url/c5cb1a81d58170a6f3c77f30e3386a7139d55fac719c578acdb0dac0ec03e51b?nocache=1 ||adityasolsurf.in^$all ! https://blog.google/threat-analysis-group/phishing-campaign-targets-youtube-creators-cookie-theft-malware/ ! https://www.virustotal.com/gui/url/498cb2174736cedece47080f5f35f1ce1eb7aa759d361ddd9c106c26bb3b8a05?nocache=1 ! https://www.virustotal.com/gui/file/0e2f7af509abfb3389320e195944b5702317bf0553169f9350afaacc16529307/relations ! https://www.virustotal.com/gui/url/4ceb6da6f85c060299a5bab40880ab95f4c401c2f3bbfcca5d2ad7307c2d1289 ! https://www.virustotal.com/gui/file/cf7df6863ec2d98c6ebf48de6219956d012bb2a6dd1af9eb9502ffecd7c75b72/community ! https://www.virustotal.com/gui/url/a36b26696f762d0dee74e8b09f0599bd2e19f25955efb1071752ff5a32ffaef8 ! https://www.virustotal.com/gui/url/d87d1931dc52b602e78824d945a99d2d21b90b8e99ea2d1bcece0bf486ae282f ||192.227.228.38^$all ! https://www.virustotal.com/gui/file/fbfbc6e81fb48d1ee2de7dd6ca830b58f5f5f9c41468052c730222db6bdac7ac/community ! https://www.virustotal.com/gui/url/a4efbb166939b223c20bfdae75493607df7101ff610f3740052b863fae7a2ec7 ! https://www.virustotal.com/gui/url/b289961b3f30f83fb19c9b80a4803efe92b1ea20a65e3af8d443cbe7895e507e ||198.23.212.136^$all ! https://urlhaus.abuse.ch/url/1720702/ ! https://www.virustotal.com/gui/url/444cd0b1e10dde9a9857d4103beb627101337bb76d7adbbd27f1e02f21af4f2f ! https://www.virustotal.com/gui/url/ab8f11d7926a7a1ecc631308557ee46338a647cef52f51cd29f4c39739edd4e7 ! https://www.virustotal.com/gui/file/a5e44dd81280a7fbef17c18e528c9df4b1289144fbc107d011af282a69cc3062/relations ! https://www.virustotal.com/gui/url/da7adf6821aa64e2e6b0ec2a0997e40607a99eaea26f4cf83603f5520dd42541 ||pcandtool.com^$all ! https://www.virustotal.com/gui/url/a263cdde5304a1eb2f8391ce547200d52ce461485295644d2cfdb74d5a50bd58 ! https://www.virustotal.com/gui/file/bcf9211a247a807974edf92b8e643ce15b6701c53676e5fe59d38f80259bdbbe/community ! https://www.virustotal.com/gui/file/410dd4aecdfa74eeab45713cde39903d3f93e428c8db4ca23cf20b9c95865f71/community ! https://www.virustotal.com/gui/url/dcc99e2264983670ad434c93943c794746b467e059172e76e15f5eedcab3f95a?nocache=1 ! https://www.virustotal.com/gui/url/f1edd603816d9698c36d2786711ec9c506bbe52bfb40190ef849c1fac8dc78cb?nocache=1 ||prismarepres.com.br^$all ! https://www.virustotal.com/gui/file/fdadaa29cddfdc73c668258fea6614be64a933dcfa19072a6342024985a0a68b/relations ! https://www.virustotal.com/gui/url/64125a9f54ae4b8692db8bcaaab8ce09d1f6fe3aad667d48999c8f579b8546aa?nocache=1 ! https://www.virustotal.com/gui/url/1389bac88cdc28f7f2bf371745bbbd1860cd27ca10c208419002b3ee3ffa2acc?nocache=1 ! https://www.virustotal.com/gui/url/e83e8aabda549218a7733cb1c4f167797684af08d41e9036cf3ec423dca7b519?nocache=1 ! https://www.virustotal.com/gui/url/573b2952362b66904c602e7232b60015941ac3e025d3fe3ab90c417e96af726c ! https://www.virustotal.com/gui/file/b7ba5aa2f8f7781d408e87b2131fa2cc9b95cdf3460f9778229398c9e851772a/community ! https://www.virustotal.com/gui/url/5bd80ecef1382d6c011a3dd937aec3b3f923d77b22d718fbb994c700f6252fbc ! https://www.virustotal.com/gui/url/a276d45767249ae0949851e2350777b49e7b36c01b4be10f58e85a7cd4ff27ed?nocache=1 ||59.97.171.121^$all ! https://www.virustotal.com/gui/url/e349cc8c18bed03310d37a59a098ae1a6da72bb0fb9af6b75bb8a91b94a3d523/detection ||push2.notify-service.com^$all ! used by a VBS RAT ! https://www.virustotal.com/gui/url/b6390d7581a83521834e7b24cf1a035fffbce1ee4c7413d494da82abcb57523a?nocache=1 ! https://www.virustotal.com/gui/url/f13ade19d524d7a455485415aff7cc19a31adee25a8e463f11bbb9dc461e52b2?nocache=1 ||40.85.140.7^$all ! https://www.virustotal.com/gui/file/7e148999439b83e74d823e98f7a82e4bd75d5e259e4c6351aabbb446eb9dfcc8/community ! https://www.virustotal.com/gui/url/c729caf3eec0092349e4756fbc9f95b85ac8d76d05f6e30d8d1ca4cbb5f65faa ! https://www.virustotal.com/gui/url/486ccac29bca2afd9872f56a59738c91bd62efd036c6e1e7e58fe9899fd718da?nocache=1 ! https://www.virustotal.com/gui/file/2aaf7b39e21dc933b0f7ca5f098ae21f501369bfd08f2969ae9c08c70a3210f8/community ! https://www.virustotal.com/gui/url/9861a82096b4d008aac456e8a0d77e39ab4a2d0225c2d805a012a77e0eaaa6ff?nocache=1 ! https://www.virustotal.com/gui/url/2026f71db9a3eb1121c32f629147cc6fc417c90439d6df5b72fb709edf1922c3?nocache=1 ||59.93.20.51^$all ! https://www.virustotal.com/gui/url/4178f34010da2fb291ab3f923c239c14d5e650f434d34e41e395b3d73edcf988 ! https://www.virustotal.com/gui/url/b2824d0cb94b194d3522652f85663195d003cb1591726d9f1468e964baf57729?nocache=1 ||117.215.213.151^$all ! https://www.virustotal.com/gui/url/a78c57af75cc3841594476defdc1045c60cd775ffdaa60baee30ed0380463d8b ! https://www.virustotal.com/gui/url/e1b14c986e12ca4483ccb34d2b844f827afb844be09a6033ddad2792bc237c6d ||182.116.72.63^$all ! https://www.virustotal.com/gui/file/0fdcf75cb636fe685223c07fa8dd58f8b182278d6ea3f09be75cc83974f3fae5/relations ! https://www.virustotal.com/gui/url/cb5b1b7c38007c074213b231befeb5cc0196adcb579aa31c7933f729fa9d29c9 ! https://www.virustotal.com/gui/url/ed1da2ef1bc0ecd5139dc15c27947fd69d6bbbb93d5f4937da16084303c319b1 ||62.182.156.24^$all ! https://www.virustotal.com/gui/file/9e0a15a4318e3e788bad61398b8a40d4916d63ab27b47f3bdbe329c462193600/community ! https://www.virustotal.com/gui/url/a4a2514169ce55b76611a1bc01cea2e370ddc6cf965a84d9baf86f49ea8ff186 ||115.226.75.23^$all ! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community ! https://www.virustotal.com/gui/url/0d5a517d298d71ce47c4b2f35c5f4ccd72327deb078584364b5304c831c77e0d?nocache=1 ! https://www.virustotal.com/gui/url/c6921b8aabb732723e848f39d7aa7c32d29ae9355ac34b9720daa6e1eafb820c?nocache=1 ||61.1.12.46^$all ! https://www.virustotal.com/gui/file/cc262fd3fa1f646aff2f5bcdea33beca5ed081260028b8604d5f714dd23c03ac/relations ||mail.totallyanonymous.com^$all ||totallyanonymous.com^$all ! https://www.virustotal.com/gui/url/f658980539020cf026a334aff8071f947d0528e33c01d85aa18a250a65962f33 ! https://www.virustotal.com/gui/url/99ac6c08f09b562fb9fa69f0c73b9b4727f4276e474e9b5661107b7c2b5d6e75 ||103.171.0.220^$all ! https://www.virustotal.com/gui/file/2c9c18cd54e6e08db64b4b5e3f511624287c2ac2ac7d65693a1767424a871d1c/community ! https://www.virustotal.com/gui/url/cfd5d596ecaba5ca59d8d5d6f47d236296b7a0baad6e78e0749ef963aae6e31a ! https://www.virustotal.com/gui/url/cb7f165247e77e35cf883e04049428dec078c5d9c07f1acfbe538db115e39367 ||2.56.59.42^$all ! https://www.virustotal.com/gui/file/79418c50eaf933084740c1bae28ce89a4255a67fea556c4d46fd7e93f210e7dc/relations ! https://www.virustotal.com/gui/url/e0c7db3afe68a6147c7a853e4ef1dcdcb8104d00edd7515e151fc023db2da7ce ||63.250.40.204^$all ! https://threatpost.com/chrome-deliver-malware-as-legit-win-10-app/175884/ ! https://www.rapid7.com/blog/post/2021/10/28/sneaking-through-windows-infostealer-malware-masquerades-as-windows-application/ ||cleancrack.tech^$all ||s4.cleancrack.tech^$all ||clickmatters.biz^$all ! https://forums.malwarebytes.com/topic/280439-possible-trojan/ ||117.251.56.13^$document ! https://forums.malwarebytes.com/topic/280232-cwindowssystem32svchostexe-blocked/ ||218.247.161.230^$document ! https://forums.malwarebytes.com/topic/280266-removal-instructions-for-search-streamly/ ||search-streamly.com^$document ||feed.search-streamly.com^$all ||api.search-streamly.com^$all ! https://www.virustotal.com/gui/file/ff60f1c22471abadaf5c4536e9383e29ace6988d1d9b96a77e707d9c243573a0/community ! https://www.virustotal.com/gui/url/ce41f5e77d90a644a86b9a0d4b4a562701f66d59163c3fffdff1d92c750f1cbb ! https://www.virustotal.com/gui/url/258045d677aaf5336ceee4d1b4127c1c27b293213e265729008b4f0c124589bb?nocache=1 ||103.149.12.116^$all ! https://www.virustotal.com/gui/file/ff60f1c22471abadaf5c4536e9383e29ace6988d1d9b96a77e707d9c243573a0/relations ! https://www.virustotal.com/gui/url/2bcb0678b3319f76fdf8db9fa3f001eeb353a9dfc070181fd7ce91d5d5ea7ca2 ||secure01-redirect.net^$all ! https://www.virustotal.com/gui/file/70d511307feea8b9dc8d691fc00dba829e2e88aa1d4b13c62a77aa2062625754/community ! https://www.virustotal.com/gui/url/93fcdbe157610df4e69b3bb3b9cbedhttps://www.virustotal.com/gui/url/1020389b8482768e4e1e1de6780695d8382b381baa91eeb7779faa2869ead3fb?nocache=167f37a77ad0643844b713f34039ce0abfb?nocache=1 ! https://www.virustotal.com/gui/url/1020389b8482768e4e1e1de6780695d8382b381baa91eeb7779faa2869ead3fb?nocache=1 ||198.23.207.126^$all ! https://www.virustotal.com/gui/url/d98879ac25e9f58c9df55b8f35da4fbc1b23cc96e80084a262a3555e9f37c3f9?nocache=1 ! https://www.virustotal.com/gui/url/e3ff8e31b9cfa804da922a669adafd0aaf6975e2e0814ddf83d3b2ef166dcbfe?nocache=1 ||staffportal.uoz.edu.krd^$document ! https://www.virustotal.com/gui/file/574a56656b6cf687d912baeedeeb176f0a7e58ad15ad4ab43c3cd630d9cceab2/relations ! https://www.virustotal.com/gui/url/8cb8c13da88b7b50a7cae47233a3c385a0208f0dccf119044f775e0a464de3a2 ||telegraf.top^$all ! https://www.virustotal.com/gui/file/c370bb81149e5a41ff7207e97c2b309cb24cb8059e13185713278d054cdccab7/relations ! https://www.virustotal.com/gui/url/5360be49126e116baaadcb5ebe70068614208ea841581f1682a4925ec5b6d061 ! https://www.virustotal.com/gui/file/f2b4beda6dccd753e370df728f24ee2af38201d05ed1b408b3e262a94c8cc382/community ! https://www.virustotal.com/gui/url/ff392416c5b4c8c575d9e8f3d1c2b539b6496e1eb75a9bcf418fc0d22aaf53fd?nocache=1 ! https://www.virustotal.com/gui/url/9df619495bc131c595300712942e767f579344aebf6bcc15f9f53108f6aab7ad?nocache=1 ||194.87.138.136^$all ! https://www.virustotal.com/gui/file/11a33c1decac05e1044a2a529c1d75d80f0cb114f68c70340be1e265a05dbe07/community ! https://www.virustotal.com/gui/url/994adac1920becfb4076ba6264f09eff65f269117ac41acb561b9323bb57192d?nocache=1 ! https://www.virustotal.com/gui/url/aab4e6678fb8975e67725b8c59935557c172a58a652ae45e94c6201bb6697681?nocache=1 ||107.172.89.165^$all ! https://www.virustotal.com/gui/file/70290e7e5fa4459f8800468b3d10d87ff0fb120be77e37fda9423d4c64b74f73/community ! https://www.virustotal.com/gui/url/5836de471b76471487a1626ad1ccf3b2449c99d466b6c3a92bc37a88de4636f3 ! https://www.virustotal.com/gui/url/0f139d355be5fa5c460848f204bf6a306cdeb264534a2578ed5c96b83acb195e?nocache=1 ||95.181.152.139^$all ! https://www.virustotal.com/gui/file/6a0449a0b92dc1b17da219492487de824e86a25284f21e6e3af056fe3f4c4ec0/community ! https://www.virustotal.com/gui/url/14cd28c9d266fea72cf56bdbac2fd441f71791b3f16ecdb7bc1d28ad99c1693a?nocache=1 ! https://www.virustotal.com/gui/url/57f970b32e2880645ff5189b042a97cbd61ffadd8c5092d47e2fbbc8feb9f69b?nocache=1 ||194.5.212.190^$all ! https://www.virustotal.com/gui/file/ad226d0d0d65f6b2cf338844fad2229e5556df67303fdcd0ba079f6c0dd0345e/relations ! https://github.com/iam-py-test/investigations/blob/main/2021/11/3/1.md#domains ||youutube.com^$all ||youvetube.com^$document ||www.youvetube.com^$all ||mediadlvr.com^$document ||safejokesearch.com^$all ||www.safejokesearch.com^$all ! https://www.virustotal.com/gui/file/78275c4299a8959d17cf695e4e4cebf40a993a487b9ceba5fb51fd1108b5c55c/relations ! https://www.virustotal.com/gui/url/b44a32b57fce4b753194dbec576badb6cf98c27492aa93c4fb976dc3817e2d74 ! https://www.virustotal.com/gui/file/8021eb6cfa850b00dc489a7c12f2132c7d93d66e7232799ab70ad09e1340f625/relations ! https://www.virustotal.com/gui/url/bfe41e7ae9953fb749a76086e1e26bd0eebac2acad6e2aafcf919df5e973aa5e ||2.56.59.211^$all ! https://www.virustotal.com/gui/url/16973b168ca89e297f49805d259fe337d079f6d558408fc1a9e9ff8261a575ec ! https://www.virustotal.com/gui/url/cbde34946a1dc932fc0e602c16acfee9ed7aea4e080cc645e0ec96411b48e9f1?nocache=1 ||fuckme69.duckdns.org^$all ! https://www.virustotal.com/gui/file/8fe260a56a8e9f9d6583ba23521d3662e2c11ff7c46773900c72ba8fc8502403/community ! https://www.virustotal.com/gui/url/fa62c30e8bb130fb69f35130b03dff10e30a1688d6d42fd35ac61bd528e742cd?nocache=1 ! https://www.virustotal.com/gui/url/88b1d0f10881c78c3c33b8698e39a0e55b12a0302ccf5459f8ffec28c3febf78?nocache=1 ! https://www.virustotal.com/gui/url/b8d61e5816b78c4385440df15ba635ab6d793bc721a254aab3ea047a14bbbc9b?nocache=1 ! https://www.virustotal.com/gui/url/27c6c144d447319f978c2ce4fa8272faa15d47aa1db6b04adb4fe2749c2b70ef?nocache=1 ||capetownbodyguards.com^$all ! https://www.virustotal.com/gui/file/12c431c9695b91725092b2261e1f4d251d682fdc0784ae3c7df3a7a478f194f6/relations ! https://www.virustotal.com/gui/url/07e967f7c81456880d0ef83f0c3292496794abc11acf6537bc497606e7d0ec8d?nocache=1 ||saint444.com^$all ||www.saint444.com^$all ! https://www.virustotal.com/gui/url/6e60494210c6eb19e306a3f24e9408161aa30edb2c15bc36e9bec93d5ceb69ba ||35.186.238.101^$all ! https://www.virustotal.com/gui/file/46cf9751def425de0d2cac62f2c6c91111b6b4b102d44ce5e8aa74b48310a008/community ! https://www.virustotal.com/gui/url/c907c778931a0223604c16483a68c6101f9339b8f84f45281b46dbeb144d65d4 ! https://www.virustotal.com/gui/url/83238f741c7fb148afe4c193467d742e938e6c6baa10f123fc41f488d010f23c ! https://www.virustotal.com/gui/file/e14c7699a88132d45dacece5881b93f8e01193d3afb27ee7bf03f562003fb6f2/community ! https://www.virustotal.com/gui/url/c5cc184fdc51e791d90ea80c78630dea2ec410d9b3b9ab2b70318e77c509d7ca?nocache=1 ! https://www.virustotal.com/gui/url/4a520850b9c352313cab68a8d760ea023e0afd162b574001f2fda9b7537c294a?nocache=1 ||149.3.170.181^$all ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ! https://www.virustotal.com/gui/url/a66c7eff8e2bd31960b6a23fb66db14261805e6de5c8aa3c8c4910ff30ee2e74?nocache=1 ! https://www.virustotal.com/gui/url/618a5cf01baf03ee03c9809b81f868cd7b90dfd99a47c47a0ed17aeed8b9791a?nocache=1 ||222.140.252.209^$all ! https://www.virustotal.com/gui/url/6568d4a46f6449ad6ad89817ee382d92ae5e5558ed18a6cce1ba0301bab28a95?nocache=1 ! https://www.virustotal.com/gui/url/a9dbc0c12296bd59609a3630930e85dfb1c2fd1e6db1a5dba61278fdca1586c3?nocache=1 ||61.52.101.213^$all ! https://www.virustotal.com/gui/url/31964c557deab2f039368b969f78626a2cf899b5cd537da204d539daf472768b?nocache=1 ! https://www.virustotal.com/gui/url/883129a2a67dc5e359602ef26d90224547fc7b91d5c40fb24af756db5e480120?nocache=1 ||101.204.125.180^$all ! https://www.virustotal.com/gui/url/2a4699d144143639adbdc1a083492926f5ef7c71755e5aef0280d626094f3dd2?nocache=1 ! https://www.virustotal.com/gui/url/d94b86a67c229fcea80b86a4bdb8b88f2fe8d582311235dd48fde5799e8eb7c7 ||125.25.99.89^$all ! https://www.virustotal.com/gui/url/ab48cae57b2376732909a14522e7f681599412f028c9865343afcdc0904c194e?nocache=1 ! https://www.virustotal.com/gui/url/93fcb0932e7e1b06d47ddc431d6e6054424124c70a8e3ff12b9d1f54a166c7c8 ||116.2.125.167^$all ! https://www.virustotal.com/gui/url/da28922df298c3076e47fffef541faea41db664a3a7bb0e1aecb9d874da32c48?nocache=1 ! https://www.virustotal.com/gui/url/8a8d5b7a8af008228edbea5a2005b745595ec6b9eaef52c95abb512a3d88f9ed ||112.237.91.116^$all ! https://www.virustotal.com/gui/url/525a2974a3f0354a4faadbd48b8b315f76992a429c13f2e8e749a77767e1efec?nocache=1 ! https://www.virustotal.com/gui/url/3378aeca62100e877a0d75dc739ca2ac3c647dfbcaae03e61ca60a9090bcfa37 ||119.178.241.105^$all ! https://www.virustotal.com/gui/url/64402e4c5e5708190b18d7f13901aaa18e12f68d648c9a72a338f227e69994a9?nocache=1 ! https://www.virustotal.com/gui/url/f1c671df93d5d0978653d452b81c6dcf64732076f7c2b18edb2824233b58160d ||182.120.35.128^$all ! https://www.virustotal.com/gui/url/d723076bb1a4908c3acf8125f972b2f7327a41ff9ba306e521ad58851de991bc?nocache=1 ! https://www.virustotal.com/gui/url/df74e2a3a1eb97c2b3c15a180be087a26aa0c720ff170396625ec9fd18d876be?nocache=1 ||113.53.64.189^$all ! https://www.virustotal.com/gui/file/ca35f2e3b3f297c371f0a58398cb43e24c1d1419f08baff9b9223b9032ccf4c1/community ! https://www.virustotal.com/gui/url/3f91d9196378d0b4485333ed47050af49250e4f4721d5451e5ec0f5179948ec8?nocache=1 ! https://www.virustotal.com/gui/url/3cb7f51948f2b22ef2af50f26b7994d424b6e23d01caee841fc019fb92bd4b33?nocache=1 ||59.127.100.164^$all ! https://www.virustotal.com/gui/url/3194597d0dcfa9c71429e4184f28e0642324dce5b19ae488ba20c1f16e578967?nocache=1 ! https://www.virustotal.com/gui/url/5fb6e6ff18284bb76f99b6d73190c25a3dcd1b371001a3bd72041626fd72c7f7?nocache=1 ||121.231.131.223^$all ! https://www.virustotal.com/gui/url/46df30a155b8785e825c36be7b945be50f34eb2690de5805a02ee20685d03ce7?nocache=1 ! https://www.virustotal.com/gui/url/0fd9b5f8aa2724213016f5f1224c802b295d2e529de40154c5bd16312b0b99f8?nocache=1 ||49.89.70.101^$all ! https://blog.malwarebytes.com/threat-intelligence/2021/11/credit-card-skimmer-evades-virtual-machines/ ! https://www.virustotal.com/gui/url/229181849ae5d036ff997645e9cf708d4fe96337d6e68e780777aee382fdccf1?nocache=1 ||webflows.net^$all ||web.webflows.net^$all ||librarysetr.com^$all ||js.rawgit.net^$all ||rawgit.net^$all ||iofrontcloud.com^$all ||alligaturetrack.com^$all ||getambassador.net^$all ||st.adsrvr.biz^$all ||89.108.127.254^$all ||82.202.161.77^$all ||89.108.109.167^$all ||212.109.222.225^$all ! https://www.virustotal.com/gui/url/a9a9ac2eeb94c12ae39afb300abcc15ad2eaae12975b077f3b24a00698bfc1ab/community ! https://www.virustotal.com/gui/url/4bc2cd85dc88835634fff22f4eb754b5642cc8e92d1b81486edc0d3c43a6c9b6/community ! https://www.virustotal.com/gui/domain/aman.xyz/relations ! https://www.virustotal.com/gui/url/19a46ea93a6974edf3b59461c1c91fb38ddc8286eb58ffd71dc1db594ff96747/community ||199.59.242.153^$all ! https://www.virustotal.com/gui/file/c81515e12aadebbd63afbdcc3f469fb3ae6ac20fdee5d26af1ca23eb8a9aad30/relations ! https://www.virustotal.com/gui/file/9f62f582fc02ae7b3b5df9a8a90718a80773eed10828014cee2a938976ab056b/relations ! https://www.virustotal.com/gui/url/c96b135eb1dfc0b1b632a59bdefe553ca7f59b12995744fd050ee84afb7a722f ||supnewdmn.com^$all ! https://www.virustotal.com/gui/url/2ed66d254c6ef460f4413e12ce3102b69434b282473eda590e2988f3895a8678 ||82.112.184.197^$all ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ||182.116.73.192^$all ! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community ! https://www.virustotal.com/gui/url/835ad0ffade5f6f724b1e1c460baf064777b90bc687272f1e9e82fa40b1807ef ! https://www.virustotal.com/gui/url/fad3abb3cec6e93f82cebf924ef44621f8f377c60eafaf590df2081d7726dd8f ||115.58.71.181^$all ! https://www.virustotal.com/gui/url/ec79057500371ef6fb530f75e8701e152bdefea363178003f01fee314bba9a0b ! https://www.virustotal.com/gui/url/ac3bcc96e61fa61bc10f27784021448b8db0c1db7c5588188698adcc769de13b ||182.117.182.173^$all ! https://www.virustotal.com/gui/url/5772533fa93cc140ca683ec099307d250ae63a0a49df94136c8c8e01fc0072f1 ! https://www.virustotal.com/gui/url/c1f565264a9d658fb34f79460e2c0b6b23837c4f9d047e713439df36a57f6512 ||27.5.44.161^$all ! https://www.virustotal.com/gui/url/aabfea4f2c8a304e8c86b381c254ad8f63fb1277ea0c0d6882c8faeb9b094aea ! https://www.virustotal.com/gui/url/85f3716cb4936399e2da0c8f8e4be0176b28ac94d87b70c602ce24c19714fb26 ||42.228.217.88^$all ! https://www.virustotal.com/gui/url/b6571f86a056a911839e235d69aa420a290336bb0b3e507ca687b6f8ee028776?nocache=1 ! https://www.virustotal.com/gui/url/f114e59a0da416a3d6532bddf74d15c00a5533310b006d8796f96fb1cb1fcbef?nocache=1 ||222.141.253.195^$all ! https://www.virustotal.com/gui/url/2167bba3338a8684365db933e8284acbf5021b0d216b53f08128e7ef6569c3f8?nocache=1 ! https://www.virustotal.com/gui/url/24ac7e301e133f88c4eaca315d69b99061bcad6330bb0cd41da06837b6f2682d?nocache=1 ||123.129.135.36^$all ! https://www.virustotal.com/gui/url/d6bdbb1a9b5de9da88760145b81098b79cfaf120d13d1de89baf00651a97e6cc?nocache=1 ! https://www.virustotal.com/gui/url/3cc8721a0ec6519053c347fdf0ff71cecbcc7df4e89bc79d6c19589c846f1ad5?nocache=1 ||186.33.80.17^$all ! https://www.virustotal.com/gui/url/9f018ffe4a2425477f9ed0794d1eda1cfffa046f75caa09a4158f72d1b22134c?nocache=1 ! https://www.virustotal.com/gui/url/50dd712793c302dc0eb606b88f61fc9edc69e20f70c563060d93e2765d97fc21?nocache=1 ||117.251.56.123^$all ! https://www.virustotal.com/gui/url/5dcb1619bf1e7491972f225ef637c2d108e6373ecdce8511891c8a0aafcb9dd7 ||42.230.54.56^$all ! https://www.virustotal.com/gui/url/0a4f865af75ae6662537d2e342b2fffae128779fd1fe84da4536dce042e6a800 ||182.124.119.104^$all ! https://www.virustotal.com/gui/url/3b53b8e5f28838f4bccfed035f9181b9301111d9100792f21b968bf149cf9f72?nocache=1 ||61.52.72.104^$all ! https://www.virustotal.com/gui/url/276cf141ccfbbf5135afb2622169865da19c9b746483252819c60e5eb1c272b0?nocache=1 ||117.198.243.39^$all ! https://www.virustotal.com/gui/url/8dc7298a1c942e802c4269418862d5839b5c3677de8586c42ef3a301dbabcba3?nocache=1 ||115.50.88.238^$all ! https://www.virustotal.com/gui/url/f83f1155cdb9b7d4c56fc1ef623c7f21f6b067a54ba6dcdb4aadddbfdc9657db ||125.99.221.210^$all ! https://www.virustotal.com/gui/url/f85165b70b862c8405a89edd1856172ed512d7b1b63ed1c623c24e39e362dbd4 ||42.233.65.79^$all ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ! https://www.virustotal.com/gui/url/5d832bb6991da5effc842e01fa7158978758b53c52052fc880a15a62bf6936dc?nocache=1 ! https://www.virustotal.com/gui/url/276c03fad01179e14271f85d27354d2cb40c6427a000aa77b9aef863d506a6ba?nocache=1 ||221.201.99.18^$all ! https://www.virustotal.com/gui/url/73b326d90d17a1d36cd643968ffb5e609f6129f2c5950bb2c5b89c81298a74e6 ||116.2.163.28^$all ! https://www.virustotal.com/gui/url/2dd90668cb779fefe3c0338e7815e1866573412d4cbee83a250e71d46436dc57?nocache=1 ||123.4.169.136^$all ! https://www.virustotal.com/gui/url/2aa5d893a5df236a2d67a8c3bd8049ef88c24fb2d8135d22d67007c915e960c6?nocache=1 ||111.224.100.191^$all ! https://www.virustotal.com/gui/file/6767e885a57bdddf41a669edf9d0bdd458135481c35f738ae5b94746a09d1c22/community ||221.15.182.192^$all ! https://www.virustotal.com/gui/url/9b28631bb96437ef20a0bbb114235363414cebe725bfa5e5e617559da6575594 ||kentbay.duckdns.org^$all ! https://www.virustotal.com/gui/url/7b2ee94d54bc16b53d5bf93a58101375f09b828b14fca0d8ca1a01178e75533a ||bug-codashop-gratis2021.duckdns.org^$all ! https://www.virustotal.com/gui/url/a2e63b1ddeadfdec0ca5ea848170fe9bf2538fc8deaf3dbd4d5b8d53940df018 ||eventcoda-gratis2021.duckdns.org^$all ! https://www.virustotal.com/gui/file/4a4bd0e011a39a8830334f40e4143c5795c5264d2d8ebb96abc6bbd6582f538c/community ! https://www.virustotal.com/gui/url/6744b335c00f39226a04ad1d686722a8ea415cb02020fb7aea98c8906cd87a9b/community ! https://www.virustotal.com/gui/url/50dcb458de51ccfc404e70d43c6a66a6e8134dca2daf294d326099341de8479b?nocache=1 ||20.199.96.7^$all ! https://www.virustotal.com/gui/file/625afe9e8316b04f978213bccaf2a7157bffd271ac0fa1136c86b68bb65a2950/community ! https://www.virustotal.com/gui/url/bab548409696771c2f5fd2a8a80e7304acbf1b2ab2d33abf50997c95b9d404ac ! https://www.virustotal.com/gui/url/89574acde8ba3f0d1560914b4dd9f1d7b47396fa86993c031d6d579d7ff39410?nocache=1 ||79.124.8.133^$all ! https://www.virustotal.com/gui/url/d09e30bf2f2463f011d53dd5a7f224b1457aa98a7bdbbf44f3e75537030f426e?nocache=1 ! https://www.virustotal.com/gui/url/6efa1899bcc627dce5ab6f7d7e5c067c6a4b3fc032e6018717e87fe9bb2d30be?nocache=1 ||ded3544.inmotionhosting.com^$all ! https://www.virustotal.com/gui/file/7ebe8adf7a8bf7e8d6dbfdba87ea57f3c0df3d6336ae584931e74a08f53bf6d8/community ! https://www.virustotal.com/gui/url/40cd2119fb1fe0be776b06c9ed09aae8a0e99ad4702dc5077ad665c97afc090d ! https://www.virustotal.com/gui/url/102882d3d7c15fd151787492dacba0bf880dc0736ea490165d968410c5cea6e7?nocache=1 ||172.245.79.129^$all ! https://www.virustotal.com/gui/file/ce231785f06d7c6b33b20dded67b62f759ec23b23bee89b01fcb00953f7028c9/community ! https://www.virustotal.com/gui/url/ec79f9bb6d51b6008f66484dd0bf5a2e2aa09eb5ce35d698062d4903e99b8bc0?nocache=1 ! https://www.virustotal.com/gui/url/8b048f6a67f6c9b022a85d3a7299e08a4c7af2ddd761f065b91b5ea8cb57ebc4?nocache=1 ||95.181.152.184^$all ! https://www.virustotal.com/gui/file/13654e2fe0c25303cd4697dd2f66c5d3b228cd3fff6e97ac979257c0b0768cb8/community ! https://www.virustotal.com/gui/url/2c94b13268b3a7a515fd086d8b124d07e3ce2a1f7fe15198de3fbd44cdd7ed70?nocache=1 ! https://www.virustotal.com/gui/url/ff345268ae5cc7f8de8c9e7fa4cc21c5068364e7697ad18b763c9dfdd7ceb50c?nocache=1 ! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community ! https://www.virustotal.com/gui/url/308dd80dc677089be722012653a33bdbf0b5dff10877f8d3c5d2e80663c817e5?nocache=1 ! https://www.virustotal.com/gui/url/9dfacdb1a48855f17a446c723a88973eabb412428c69fdf721b45c8854d0ba3b?nocache=1 ||182.120.52.107^$all ! https://www.virustotal.com/gui/file/d0fb8bc2330e0886178b31c9421257d5d8d64ef554f2fe1f0f08752564e68018/community ! https://www.virustotal.com/gui/url/3d14ca260bec1755f188ba64eed9a8558e9f5ed0ae83d39af184806b243f6d68 ! https://www.virustotal.com/gui/url/fa95b98f4de4e126a13ffe2f650a7c5d14ec673acc9f6175cdb87bafe9e2fed9?nocache=1 ||198.12.107.103^$all ! http://vxvault.net/ViriFiche.php?ID=44084 ! https://www.virustotal.com/gui/url/8e67da385470de16ab81b889d4f2692b5bef3bf93bf5b3645eba0d5950c0d0a8 ! https://www.virustotal.com/gui/url/c1896ba2604c5e80231ec09e448136e71ac1721b97ada9cdb632e1c3bdce6725 ||180.214.237.39^$all ! https://scammer.info/t/chase-phishing-4/83326 ||www.rdietsch.com^$document ||rdietsch.com^$document ! https://scammer.info/t/yahoo-phishing-4/83322 ||yaahhraead.weebly.com^$document ! https://scammer.info/t/redline-malware/83121 ||45.67.228.152^$document ! https://blog.talosintelligence.com/2021/11/kimsuky-abuses-blogs-delivers-malware.html ||pcsecucheck.scienceontheweb.net^$all ||o61666ch.getenjoyment.net^$all ! https://www.virustotal.com/gui/file/bf45b415add34c4a9cfd28e2f0060a5771b452a290d4807cc66e5e0355b014c0/community ! https://www.virustotal.com/gui/url/931f06b3237b5a3146155be67490fc186ed2527b0b6b73a78d06b22aa15d35d7?nocache=1 ! https://www.virustotal.com/gui/ip-address/92.38.189.206/relations ! https://www.virustotal.com/gui/url/97ebe4817da3382f244586324c1eeb0ec39f3f466a6bf85acdae5cd4e6269fe4 ! https://www.virustotal.com/gui/file/e629334def73be9e166ecdd9d5d73d6be97ef7f7d16f05383892332acb324b73/community ! https://www.virustotal.com/gui/url/ba79121c07cef5a2e58edcf9e0a51214c17b12a3f5bc9e886fe7c9833f98b4a8?nocache=1 ! https://www.virustotal.com/gui/url/d46d28be92b5a75ee66f4a4df624e83ed3d593eef407a7c7980f5c4a5b062219 ||182.121.34.64^$all ! https://www.virustotal.com/gui/ip-address/46.242.232.202/relations ! https://www.virustotal.com/gui/url/75ea70d543f6009284e91be48b3b4d455d047380769f51bd4ba78ddf91ac5844 ! https://www.virustotal.com/gui/url/8b6e00f2a6355452de1fcd5e95360c75f1dedb1f5fc1299d530fdef3181079c2?nocache=1 ||hosting2047279.online.pro^$document ! https://www.virustotal.com/gui/url/5c3db4bc306f7e587391b493173af2bf4995d915a9675fb4dfddd68530a247ec ! https://www.virustotal.com/gui/url/7b60d15a9f6fd868fef0747607b1f13135c63fbebab0f2c243a52019e0246edd?nocache=1 ||182.119.193.35^$all ! https://www.virustotal.com/gui/ip-address/192.64.119.78/relations ! https://www.virustotal.com/gui/url/efe8aec5fee6b99bc7f3b7b0c0bca9006a982dab6feb6bbf83a6f22f2448aaa5 ! https://www.bleepingcomputer.com/news/security/windows-10-app-installer-abused-in-bazarloader-malware-attacks/ ! https://github.com/sophoslabs/IoCs/blob/master/Troj-BazarBackdoor.csv ! https://www.virustotal.com/gui/url/0cd63288d0abde5976c2a05ce371deb57b77aad544c95cad23990806adde983e ||hastrama.com^$all ! https://www.virustotal.com/gui/url/49084a6ebf5edfb36a61fd95a7f5acf47eebc6b597ac078f2b7514f4aba73d4c ||dfgerta.com^$all ! https://www.virustotal.com/gui/url/a0c4731dfc864387318b5937bb509f0d73b866c12a5f1d3058234c30cf1dcf2b ||falomana.com^$all ! https://www.virustotal.com/gui/file/7930bf3f1be9acdf429e2433aa7d0c36985d9a97e580571fee1ffe8cbc0d8f5a/community ! https://www.virustotal.com/gui/url/6496408801245ebc8e42ad93044d1ee4fbec1829641b8c844b556c0bcd9b8153 ! https://www.virustotal.com/gui/url/e4842b84c30b86572e5409fa2e7e8cf0ed661169f13517b6bbaa6da2e207690e?nocache=1 ||182.188.44.77^$all ! https://www.virustotal.com/gui/url/e1040fd6b4a0981c31e0ff7307711366ba3fe8945ed487d1761325d9838319d2?nocache=1 ||aljinternationalcorp.com^$all ||www.aljinternationalcorp.com^$all ! https://www.virustotal.com/gui/url/8bb706c85f55c2c429fe521176e46210c95742634735e1055aaa89ed9d721a71?nocache=1 ! https://www.virustotal.com/gui/url/3e957264c1152dd629abda0e1c015b067aa23fc6178bf1105d9593fbfad9c439 ! https://www.virustotal.com/gui/file/adace11a1835d8b0b768bbb451dccf8507f5baf0c49925ff103ce1c88f0e1ba3/community ! https://www.virustotal.com/gui/url/1cf1099aa38de926f266b422f4def4a5a81f8aeaac60b7fb4cc685b82701c3ed ! https://www.virustotal.com/gui/url/25a801d28d3e5988f15439e2a795570e68bd018196157e11b36ab70e7572ca7c?nocache=1 ||capraroconsulting.com^$all ! https://www.virustotal.com/gui/file/879fccdf9b4b09063a6dbf1ac2cc381a1ebcacf6e38f5b8d4889785a4ccde22a/community ! https://www.virustotal.com/gui/file/4970975b3596048497e4cd865a66e68b017afddc392ce8de6d1b071846908295/community ! https://www.virustotal.com/gui/file/48bf6b216fedcd9ad055231d5179cd419533fdd480870a1a819cb90c903e557e/relations ! https://scammer.info/t/phishing-mail-with-domain-polatemlakhaninsaat-com/83493 ||polatemlakhaninsaat.com^$document ! https://www.virustotal.com/gui/file/d281f1798378ec6233487beeee61c573d2db5be73dc86d21210e3cd565674947/community ||46.249.32.66^$all ||chingchong.xyz^$all ! https://www.virustotal.com/gui/file/597b269e4d1003c1af4ddd797f87f838be88817f2cc5b1ce24f373707d2fb40f/community ||107.172.0.199^$all ! https://www.virustotal.com/gui/file/3bf1b7e9bdaeaa4a5619cf26b59767637bc44193df2a0470df263b98b1fe47fe/community ||198.23.255.14^$all ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ||39.83.80.247^$all ||68.197.33.124^$all ||219.157.21.37^$all ||182.123.141.17^$all ||125.47.243.187^$all ||182.122.196.203^$all ||182.117.231.182^$all ||112.31.211.135^$all ||125.106.63.93^$all ||115.59.197.46^$all ||122.159.29.192^$all ||171.40.0.127^$all ||171.80.219.160^$all ||123.10.65.201^$all ||168.90.205.46^$all ||125.47.205.109^$all ||39.80.147.239^$all ||45.224.171.130^$all ||45.5.209.75^$all ||116.17.210.157^$all ||27.45.103.240^$all ||110.167.64.171^$all ||39.81.117.73^$all ||183.15.90.156^$all ||119.113.248.74^$all ||175.0.95.85^$all ||61.52.99.109^$all ||222.142.183.194^$all ||106.86.172.194^$all ||103.233.216.77^$all ||183.188.192.55^$all ! https://github.com/uBlockOrigin/uAssets/issues/10484 ||onenightfriend.com^$all ||www.onenightfriend.com^$all ! https://github.com/iam-py-test/investigations/blob/main/2021/11/15/1.md#iocs ||freedownloadfiles.org^$all ||ec2-34-213-49-207.us-west-2.compute.amazonaws.com^$all ||172.67.186.189^$all ! https://www.virustotal.com/gui/file/b346f73352f3df0ec81e2bb986205f48855d98b426693375f37a2ed5f5c530d1/relations ||querahinor.xyz^$all ||server9.trumops.com^$all ||trumops.com^$all ||runmodes.com^$all ||91.121.67.60^$all ! https://www.virustotal.com/gui/file/c821d8c0542d4c4279766890e125b3fe890f612422a94a9e90f20e66858ee209/community ! https://www.virustotal.com/gui/url/868b4d676f05ff8174d2a2e91a2b1d3f4d056d5185a0e07aa14999f8d3e6f6b0 ! https://www.virustotal.com/gui/url/b11907e2fb52c9bcf1e5afe77ca6ef0b4d52f2df93ce21317d36ea56f75600a1?nocache=1 ||107.173.219.26^$all ! https://www.virustotal.com/gui/file/0d733a15a0b9fb3792b40cc7017e480a050e5ff6504b96c610bf704c837b6cae/community ! https://www.virustotal.com/gui/file/ff77fb3fd14e94cfb7b11a8bbe815c92c15983cded98bf8189858fe9b2d5fe20/community ! https://www.virustotal.com/gui/file/24fe41b59eb305419b081bfbbd7d7bc6dd1793333244dc03cf71076fca9427a9/community ||212.193.30.219^$all ! https://www.virustotal.com/gui/file/f503079af8fc970fd2a76c6a3ff731622a3153b90adea09747d47de9146f2cd7/community ||212.193.30.129^$all ! https://www.virustotal.com/gui/file/5328c4aab99fe1a6c8d10a8735a88e4a720b544576cd7acd8b03f8a063a545b1/community ||198.46.136.245^$all ! https://www.virustotal.com/gui/url/ce69462e263f0907114076f070cad653d2c944dda105793aed2115eeab5c82a3/community ! https://www.virustotal.com/gui/url/8f26eac1984a9738a36f7794a37b5d737e62c2ba647ca594ac0721babc28040d/community ! https://www.virustotal.com/gui/file/15c04c213c3c4a5f9078d87512c7e1f951cdb540d5949cb7196df3153612ef2b/relations ! https://www.virustotal.com/gui/url/af8f443208f4e86d469549b219fccbeb43b7cae40be5f1b4c4e5083e27fc8111 ! https://www.virustotal.com/gui/url/76223ce4461cdfd32a6c2a1ff435cf4b61b02597795d0d228d5e6a9f923f40db?nocache=1 ||inconclusive-pyrite-grandparent.glitch.me^$all ! same hosting ! https://www.virustotal.com/gui/url/92dd4fe7f3dd8c44d04e38b3bf173b4bf903b01bf436e95c248a2e8a31d98a82 ||delicate-tame-angora.glitch.me^$all ||secureinvoice.glitch.me^$all ||holy-ruddy-brace.glitch.me^$all ||instagramcomphoto212paaatrk.glitch.me^$all ||instafollow.glitch.me^$all ||loving-discovered-swordfish.glitch.me^$all ||aquamarine-cotton-impala.glitch.me^$all ||mature-periwinkle-advantage.glitch.me^$all ||tough-numerous-lemur.glitch.me^$all ! https://scammer.info/t/scam-bots-are-invading-g4-tvs-discord-server/83802 ! https://github.com/avast/covid-19-ioc/commit/1539def33debd4ddbc903a26166205cae6aaedd9 ! https://www.virustotal.com/gui/file/f657dd8b99b9fa047c524f055984dfb1f9886cc97c788c8ebb9e63537f327c1a/community ! https://www.virustotal.com/gui/file/676de5f6ff737af6e73a00caf93767cc9af16e6e6bd50016b5bd03ffa097c373/community ||dl02.s3.amazonaws.com/installers/693123/oi_agree-free-dvd-ripper-platinum.exe$all ||dl02.s3.amazonaws.com/installers/852091/oi_swfdeczip.exe$all ||dl02.s3.amazonaws.com/installers/415643/m1btpwzw9bc.exe$all ||dl02.s3.amazonaws.com/installers/388327/ycf45qdlvsc.exe$all ||dl02.s3.amazonaws.com/installers/848253/InfraRecorder.exe$all ||dl02.s3.amazonaws.com/installers/630249/oi_calctime4f.exe$all ||dl02.s3.amazonaws.com/installers/790203/crazy-ball.exe$all ||dl02.s3.amazonaws.com/installers/760905/tmnttheme.exe$all ||dl02.s3.amazonaws.com/installers/$document ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ||182.114.214.24^$all ! https://www.virustotal.com/gui/ip-address/2.56.59.42/relations ||cha1se.my03.com^$document ! https://www.fortinet.com/blog/threat-research/deep-dive-into-a-fresh-variant-of-snake-keylogger-malware ! https://www.virustotal.com/gui/url/ff38d62a5ca15c1ed5e70bf156f6b09451aa0b9bf9acd7aa2a002847d87900ff ! https://www.virustotal.com/gui/url/bd76e047dcf311a28a7260636a6e8337729d6eb8ee6166616b090a925e6bbcf5?nocache=1 ||3.64.251.139^$all ! https://www.virustotal.com/gui/file/f2a443b6c4ffde6e88daa60afe095436fb42fdf8eb32b84614b4108b346b4d04/community ! https://www.virustotal.com/gui/url/96dc9372d45370278705b299d301b7176bb46f2399843a9039245ce3722e9459 ! https://www.virustotal.com/gui/url/a88d69b1df946a3da52acb69b438f909a118f1dc0ce1ddef5c8ff4e5fc22eea3?nocache=1 ||83.149.87.180^$all ! https://www.virustotal.com/gui/file/c465550320e3625e430f8745c8c8b8664a202e24dbe51ed4e5dcd0af25960420/community ||caenet.s3.amazonaws.com/apps/dexway/dexway.setup.msi^$all ! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community ||117.201.201.195^$all ||61.53.195.154^$all ||61.53.23.161^$all ||42.230.87.49^$all ||182.121.144.54^$all ||115.58.133.240^$all ||117.221.188.221^$all ||182.126.145.128^$all ||123.5.131.241^$all ||117.221.190.187^$all ||182.113.15.211^$all ||218.72.105.237^$all ||112.248.191.91^$all ||182.126.113.6^$all ||27.5.26.77^$all ||42.224.171.211^$all ||115.59.210.143^$all ||103.73.61.254^$all ||42.224.33.38^$all ||182.127.222.21^$all ||116.193.172.99^$all ! https://scammer.info/t/paypal-phishing-11/83945 ||113.161.144.143^$all ! https://www.virustotal.com/gui/file/c988a65d39f617c531454c2f15971c0a769d42ac84bea0a7a3bd89394ba3e654/community ||45.42.201.16^$all ! https://www.virustotal.com/gui/file/df7841fad13bb90a108a0861c92c565ad754528e684600ad07011cd4e83f1a63/community ! https://www.virustotal.com/gui/url/29a76a0ae74cb6cdda4abcaad46246aad99ae4b58c4d8ebeaed6a084c38efeef ||bug-codashop-diamond.duckdns.org^$all ! https://www.virustotal.com/gui/url/fb7216f8666b7d0a01d1edae657f93db65a0178727571d9480e6d0fcc5ee7e1e ||secure-infodirec350.duckdns.org^$all ! https://github.com/uBlockOrigin/uAssets/pull/10542 ! https://www.virustotal.com/gui/url/a2524bba49ae71297d2b408b30d058700d9c80b5b1154924cafe190ec3e605a6/detection ||newrrb.bid^$all ! https://www.virustotal.com/gui/file/2b2628a50d3b39b0fa2395d487bf62b00e37cdae847ff76ee58399bbe4e9f7b3/community ||194.87.138.20^$all ! https://www.virustotal.com/gui/file/b320bc7a9151d70daca038c4356ca89bfcd4918bcd6f0f73683a27a6a72467ae/community ||103.167.92.73^$all ! https://www.virustotal.com/gui/file/6146dfe56dcb49e1b843624a44e204754e15625a4f94b230b59a5cafc924f618/community ||bursakulis.com^$all ! https://www.virustotal.com/gui/url/b333c49efa4d399e65c5e2d96a905b380acbca58a3e3052b7bd7cfcb3e0e81ee ||610418.selcdn.ru^$all ! https://www.virustotal.com/gui/file/2fb97449ff00263495f3d1bd7311532b4b43d5f2bcef700fe4d593dc3fa64d68/community ! https://github.com/iam-py-test/investigations/blob/main/2021/11/24/1.md ||macsoftwarez.com^$all ||namilon.xyz^$document ||ec2-3-238-75-201.compute-1.amazonaws.com^$document ||ec2-54-177-49-112.us-west-1.compute.amazonaws.com^$document ||ec2-44-192-106-88.compute-1.amazonaws.com^$document ||ec2-52-53-211-120.us-west-1.compute.amazonaws.com^$document ! C2s ||toa.mygametoa.com^$all ||mygametoa.com^$document ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ||221.210.97.251^$all ||119.183.99.159^$all ||79.17.80.19^$all ||222.138.225.21^$all ||179.42.107.54^$all ||112.226.50.116^$all ||221.232.176.162^$all ||27.158.159.100^$all ||177.22.237.82^$all ||112.246.124.159^$all ||112.30.1.211^$all ! https://forums.malwarebytes.com/topic/281074-pup-mysearchengineco-firtefox/ ! https://www.virustotal.com/gui/ip-address/172.67.222.254/relations ! https://www.virustotal.com/gui/url/781a2d763b034c9610ab9832bdc2692aced3d86c6b7296ea72579da7b68dc073?nocache=1 ||631e69eb.ainans.com^$all ! https://www.virustotal.com/gui/url/2fb021cabd8ebdc964c11f78d634d598085eca46535bbb9d5498299d9807c6e0?nocache=1 ! https://www.virustotal.com/gui/url/c895ae811452b51cc54c5845aad820dbbc89cd3d2c963a1a28f38191c213380a?nocache=1 ! https://www.virustotal.com/gui/url/e44e62fe32d2e25405df7d18539b297b4c298ceb629e0b7edb21dba040e698e2 ! https://www.virustotal.com/gui/file/36a44bb88a9d935641882b44718c3cab933416f5b408b6c663e1f6b53cb659b9/community ||194.85.250.141^$all ! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community ||27.217.237.43^$all ||182.119.229.129^$all ||186.33.82.109^$all ||186.33.67.179^$all ||125.41.206.6^$all ||186.33.83.96^$all ||59.88.216.76^$all ||182.122.250.43^$all ||186.33.78.206^$all ||186.33.84.135^$all ||221.15.22.157^$all ||115.53.242.236^$all ||182.123.205.188^$all ||182.126.178.248^$all ||186.33.74.128^$all ||186.33.91.123^$all ||117.217.145.97^$all ||182.122.144.147^$all ||115.59.62.205^$all ||186.33.68.119^$all ||37.54.48.106^$all ||186.33.87.157^$all ||122.231.1.0^$all ||115.49.224.161^$all ||59.93.29.175^$all ||123.4.254.216^$all ||116.75.215.133^$all ||186.33.90.5^$all ||117.215.241.97^$all ||125.105.92.44^$all ||61.54.68.132^$all ||219.155.105.205^$all ||186.33.79.188^$all ||123.14.106.221^$all ||59.95.79.250^$all ||27.215.140.18^$all ||186.33.78.56^$all ||182.56.163.181^$all ||42.224.31.74^$all ||61.53.102.126^$all ||125.47.80.104^$all ||14.226.182.203^$all ! https://www.virustotal.com/gui/file/2f08f5b23a062671fba5957b98d05a728299bb1ae98695b9b5d36e75528ccab7/community ! https://www.virustotal.com/gui/file/0c6d57557120decedc9a102794ea95bcaf64529eb1f18058e4df62c34b724988/community ||103.171.1.140^$all ! https://www.virustotal.com/gui/file/ff4e17d62ce9c71164879418e7942cecf8db37b16cb66adebc6c2570840f8524/relations ! https://scammer.info/t/phising-on-crypto/84207 ! https://scammer.info/t/onedrive-phishing-5/84102 ||vgiukhnmvhjhukhj.nustadaltu.workers.dev^$all ! https://scammer.info/t/quantum-ad-blocker-trojan/84204 ||quantumadblocker.com^$document ! https://www.virustotal.com/gui/file/c5d5a28565277162bc72399c71d38bf329be3a8e5b34140447212533c06a2be2/community ! https://www.virustotal.com/gui/ip-address/212.192.241.249/relations ! https://www.virustotal.com/gui/file/d6a99ad5595b073830f571defe840abc14fba0dfb6b4d406bcb00b78b92c5fee/community ||61.3.149.176^$all ! https://www.virustotal.com/gui/url/203581d14546cb9be57ed7e8e75550805d612a49cf1cac55e149413e648890db/community ||186.33.85.112^$all ! https://www.virustotal.com/gui/file/c18cf6f2677277c4885ccb069d4e65b8c97c96c0ea72cee5d8e6a2d018d74ed0/relations ! https://www.virustotal.com/gui/file/311ac01e395d96f8017ef95dfa9ee8f00aa527e02cfcd207de371e04e5aed023/community ||194.85.248.159^$all ! https://www.virustotal.com/gui/file/d546509ab6670f9ff31783ed72875dfc0f37fa2b666bd5870eecaaed2ebea4a8/community ||58.249.74.79^$all ||27.45.14.109^$all ||27.40.101.191^$all ||27.45.119.22^$all ||27.47.73.159^$all ||115.204.119.237^$all ||163.125.31.46^$all ||163.179.168.44^$all ! https://github.com/uBlockOrigin/uAssets/pull/10620 ! https://www.virustotal.com/gui/file/cbeb4e922aabe85afb7d5d3508aa7f153b58509d76d77787ec6d640d4a6300a5/relations ! https://www.virustotal.com/gui/file/a8bfc3885f89bca5242709e290a276de03d8774cbd6c744ca3676e681fae1e49/relations ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ||110.89.59.135^$all ||113.116.89.1^$all ||119.183.146.191^$all ||153.3.3.226^$all ||182.116.104.6^$all ||60.7.133.200^$all ||122.6.254.201^$all ||110.89.11.167^$all ||171.112.177.90^$all ||115.194.38.143^$all ||61.52.79.32^$all ! https://www.virustotal.com/gui/file/2e4506802aedea2e6d53910dfb296323be6620ac08c4b799a879eace5923a7b6/community ||186.33.84.20^$all ||186.33.95.240^$all ||186.33.77.47^$all ||59.99.45.244^$all ||117.223.81.25^$all ||186.33.78.70^$all ! https://www.virustotal.com/gui/file/e997cb7bc263ee036b7e137cfe989a12d75cd6db9004c7928622cbd934fb3135/community ! https://www.virustotal.com/gui/file/dcbac25b2ab80e00cd11683435692fddf4ffb2ebdcef01983de0ce39b7fb4861/community ! https://www.virustotal.com/gui/file/1151a016d3c2a23f0538777804529c0b4be56472e48f30098fbe5501f8d0d7a0/community ! https://www.virustotal.com/gui/file/4295424bd80b9d81bb59304038e44ef4462d00a59fccbad38289e3a80eb493c7/community ||185.9.36.106^$all ! https://www.virustotal.com/gui/file/af27173ed576215bb06dab3a1526992ee1f8bd358a92d63ad0cfbc0325c70acf/relations ||51.195.57.232^$document ! https://www.virustotal.com/gui/file/ec892345779df7156691fcc7eb37deb89bb8d6d6fd925841fa1764ea93bef58f/community ! https://github.com/uBlockOrigin/uAssets/pull/10662 ||api.crm.duominuo.com^$all ||static.duominuo.com^$all ||wnl.duominuo.com^$all ||duominuo.com^$all ! https://scammer.info/t/pihishing-site-claiming-to-hold-a-ups-package-that-needs-payment/84466 ! https://www.virustotal.com/gui/url/269d374b629d7896da1f9e7449bd5afecf6284a9a564244f96a71e5192363635?nocache=1 ||lowseelan.com^$all ! https://www.virustotal.com/gui/file/50fd813cf8fe981e6aee179f8ba394e5527c5128b84c328f9f8347cd994bbc42/community ||dl02.s3.amazonaws.com/installers/747947/oi_picasa38-setupexe.exe^$all ! https://www.virustotal.com/gui/file/2ea599605c4d65902943f12e1114a71af7a40fa7dffbf018b0ee3e7a61aaeaa3/community ||dl02.s3.amazonaws.com/installers/424531/2gzbsoj4gxb.exe^$all ! https://forums.malwarebytes.com/topic/281264-malware-bytes-scam-number-1-315-996-0560/?_fromLogin=1 ||tradeford.com/us853558/malwarebytes-customer-service-1-315-996-o56o_p1049357.html^$all ! https://forums.malwarebytes.com/topic/281310-malware-sample/ ! https://www.virustotal.com/gui/file/9c3f82fc5a23181b4652cd2696bf4bdb1a27f43836ebc2b654610b61d5e6d8a7/community ! https://github.com/DandelionSprout/adfilt/pull/395 ! https://www.huorong.cn/info/1531309921141.html ||kuaizip.com^$all ! https://www.huorong.cn/info/1618397948649.html ! ||zhuangjizhuli.com^$all ! ||zhuangjizhuli.net^$all ! https://github.com/uBlockOrigin/uAssets/pull/9656 ||geekotg.com^$all ||qq789.com.cn^$all ! https://www.huorong.cn/info/1526627586130.html ||xiaobaixitong.com^$all ! https://www.huorong.cn/info/1577158839403.html ||daque.cn^$all ! https://www.huorong.cn/info/1598957552515.html ||dabaicai.com^$all ! https://www.huorong.cn/info/1617368984641.html ||qqfzn.com^$all ! https://github.com/uBlockOrigin/uAssets/pull/10017 ||flash.cn^$all ! https://www.virustotal.com/gui/file/1d29ecde092f21ea0dd05b9f42531be1ed2207d6ebb9b463517f4c9508ff24a7/community ||fire.hypersys-server.com.ar^$all ! https://www.virustotal.com/gui/file/25dc1c67a35ee480f36d1ec2590f935ec6c8d70eacbd95e96208374c402cac99/community ! https://www.virustotal.com/gui/file/611cf2be6752c173be1328ea47cc8ea736bc3bda9030da617390b23afa955b47/community ! https://www.virustotal.com/gui/file/c59a0bc3fb5029c906b4f491dfccfd5bf8aafb25db2c281dc4092e6eaa81bb53/community ||117.194.171.13^$all ||59.94.131.207^$all ! https://github.com/uBlockOrigin/uAssets/pull/10774 ! https://bbs.kafan.cn/thread-2222478-1-1.html ! https://bbs.kafan.cn/thread-2221903-1-1.html ! https://bbs.kafan.cn/thread-2221781-1-1.html ! https://bbs.kafan.cn/thread-2220230-1-1.html ||ts-group.com^$all ! https://bbs.kafan.cn/thread-2221419-1-1.html ||2345.eyunsou.com^$all ! https://www.huorong.cn/info/1627034201698.html ! https://bbs.kafan.cn/thread-2217785-1-1.html ||win.zjwhr.top^$all ! https://twitter.com/Cryptolaemus1/status/1468266929014157316 ||lartmana.com^$all ! https://github.com/blocklistproject/Lists/issues/588 ||procrackerz.org^$all ||freeprosoftz.com^$all ||pccrackbox.com^$all ||365crack.com^$all ||cracklabel.com^$all ||keystool.com^$all ||pcwarezbox.com^$all ||installcracks.com^$all ||10crack.com^$all ||reallcrack.com^$all ||hit4crack.com^$all ||crackproductkey.com^$all ||profullversion.com^$all ||vcracks.com^$all ||keysfull.net^$all ||crackswall.com^$all ||crackthere.com^$all ||crackpcsoft.net^$all ||crackserialkey.co^$all ||keygenfile.net^$all ||maliksofts.com^$all ||proappcrack.com^$all ||flstudiocrack.org^$all ||scracked.com^$all ||crackpropc.com^$all ||crackwinz.com^$all ||cyberspc.com^$all ||crackedpcs.com^$all ||ayeshapc.com^$all ||crackintopc.com^$all ||crackhomes.com^$all ||zslicensekey.com^$all ||cracksmad.com^$all ||iamactivator.com^$all ||crackproduct.com^$all ||excrack.com^$all ||mahcrack.com^$all ||get4pcs.com^$all ||genuineactivator.com^$all ||keygenwin.com^$all ||thiscrack.com^$all ||crackedroot.com^$all ||crackspro.co^$all ||topcracked.com^$all ||mycrackfree.com^$all ||crackfullpro.com^$all ||starcrack.net^$all ||procrackpc.com^$all ||crackknow.com^$all ||crackpro.org^$all ||4howcrack.com^$all ||crackshere.com^$all ||crackdj.com^$all ||cracksray.com^$all ||crackkits.com^$all ||trycracksoftware.com^$all ||fullcrackedpc.com^$all ||cracktopc.com^$all ||crackkey4u.com^$all ||rootcracks.org^$all ||idmfullcrack.info^$all ||fileserialkey.com^$all ||licensekeyup.com^$all ||thecrackbox.com^$all ||rootcracks.co^$all ||cracksway.com^$all ||clevercracks.com^$all ||shahzifpc.com^$all ||idmpatched.com^$all ||getprocrack.co^$all ||autocracking.com^$all ||macwinsofts.com^$all ||productkeyfree.org^$all ||chcracked.com^$all ||cracksdat.com^$all ||patchcracks.com^$all ||activationkeys.co^$all ||serialsofts.com^$all ||piratpc.com^$all ||prosoftlink.com^$all ||cracksole.com^$all ||finalcracked.com^$all ||activatorpros.com^$all ||organiccrack.com^$all ||zscracked.com^$all ||abbaspc.org^$all ||allsoftwarekeys.com^$all ||genuineserials.com^$all ||pfcbwp.com^$all ||softwar2crack.com^$all ||xforce-cracks.com^$all ||procracks.net^$all ||productkeyforfree.com^$all ||crackgrid.com^$all ||licensekeysfree.com^$all ||goharpc.com^$all ||crackedmod.com^$all ||crackvip.com^$all ||crackedpc.org^$all ||activatorwin.com^$all ||whitecracked.com^$all ||softwarance.com^$all ||kalicrack.com^$all ||bypassapp.com^$all ||ziapc.org^$all ||zgamespc.com^$all ||cracksoon.com^$all ||boxcracked.com^$all ||procrackkey.co^$all ||activationkey.org^$all ||newproductkey.com^$all ||protoolscrack.net^$all ||download4mac.com^$all ||serialkeypatch.org^$all ||premiumsforum.com^$all ||profreefiles.com^$all ||filespremium.com^$all ! https://github.com/uBlockOrigin/uAssets/pull/10854 ||37.1.209.213^$all ! https://www.virustotal.com/gui/file/a6c5cfe008f99e4d9bf3386d2fe6ddbe8278e62ae4253516b9740a5571559c80/community ||103.161.17.177^$all ! https://www.virustotal.com/gui/file/9512ea84d3b715a1cc88f5ce8438de0332d2e9d6cf6c2f09f7eeb80ef7b47df0/community ||23.160.193.99^$all ! https://www.virustotal.com/gui/file/3298ca1f08669a4f67cae0422b0f2292be810ecfe44516e7f23db398dc927b63/community ||65.108.81.182^$all ! https://www.virustotal.com/gui/file/4bef75aae931f4dec589397a013befac963cd48a8b1f1fd4958bd52ca3c6a52e/relations ! https://www.virustotal.com/gui/file/a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3/community ||83.43.152.54^$all ||87.8.44.207^$all ||61.84.100.80^$all ||137.101.180.83^$all ||49.158.204.118^$all ||70.49.85.35^$all ! https://github.com/iam-py-test/investigations/blob/main/2021/12/13/1.md ||haxpc.net^$all ||52.53.243.52^$all ||34.201.22.10^$all ! https://twitter.com/Max_Mal_/status/1470107440268161030 ||87.251.85.100^$all ||5.182.206.13^$all ! https://scammer.info/t/amazon-phishing-scam/85343 ! https://scammer.info/t/i-dont-need-that-bayonet-scam/85314 ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ||123.10.225.196^$all ||122.192.106.84^$all ||172.88.199.9^$all ||114.38.176.185^$all ||61.52.97.35^$all ||27.206.181.208^$all ||124.163.130.175^$all ||118.75.87.102^$all ! https://forums.malwarebytes.com/topic/281893-discord-account-stealer/ ||drive.google.com/file/d/1lvkYzenTwpcsl7vjsbds1J7MKSFxv-4D/view^$document ||doc-0s-6k-docs.googleusercontent.com/docs/securesc/rfercc3a76jeult4d0h2382iop9rvhs7/bkokfcop5q4c5nh6ab7ua8fqrvfhqbut/1639701150000/13045886741651917350/15048584419024227515Z/1lvkYzenTwpcsl7vjsbds1J7MKSFxv-4D?e=download&nonce=m87re19eg7bia&user=15048584419024227515Z&hash=e46r3l57308v862803q96485oi1sd2jp^$all ! https://twitter.com/Max_Mal_/status/1471844088265719817 ! https://forums.malwarebytes.com/topic/281936-malware-campaing-distribuition-malicious-link/ ||10dimensions.com^$all ! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community ||222.136.75.93^$all ||115.59.8.61^$all ||182.121.80.185^$all ||122.57.207.174^$all ||123.7.43.77^$all ||182.116.23.98^$all ||125.47.85.248^$all ||42.224.136.186^$all ||115.50.95.249^$all ||123.8.87.209^$all ||182.123.249.171^$all ||221.15.191.40^$all ||61.53.87.155^$all ||182.114.127.220^$all ||125.45.59.7^$all ||42.230.115.174^$all ||115.63.178.97^$all ||186.33.94.23^$all ||117.208.141.188^$all ||123.9.40.156^$all ||219.154.255.148^$all ||115.54.166.182^$all ||219.157.30.136^$all ||123.5.140.193^$all ||125.45.64.52^$all ||112.248.190.154^$all ||222.137.85.151^$all ||219.157.28.251^$all ||182.120.10.37^$all ||115.58.21.200^$all ||42.236.222.17^$all ||27.215.83.232^$all ||123.10.33.144^$all ||219.157.56.100^$all ||115.50.247.44^$all ||222.139.50.200^$all ||182.112.62.87^$all ||123.12.32.193^$all ||61.52.99.203^$all ||125.41.11.188^$all ||123.5.151.84^$all ||221.15.13.134^$all ||115.63.182.225^$all ||117.198.164.222^$all ||61.3.148.53^$all ||42.224.117.112^$all ||42.224.173.228^$all ||42.226.83.149^$all ||61.52.62.218^$all ||116.72.58.108^$all ||182.116.113.177^$all ||61.53.63.98^$all ||182.117.118.74^$all ||219.157.207.62^$all ||222.138.102.119^$all ||219.155.200.222^$all ||115.59.1.181^$all ! https://www.virustotal.com/gui/file/12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef/community ||124.93.94.5^$all ||27.211.137.251^$all ||119.179.19.44^$all ||123.8.251.184^$all ||173.90.91.124^$all ||182.121.22.147^$all ||27.198.66.169^$all ||170.244.231.162^$all ||171.38.221.28^$all ||182.112.51.205^$all ! malware - https://bazaar.abuse.ch/sample/a12d74b1756d49531e21f755fef2049ab6c83626f0834cb945c781c39d40a177/ ||crackedable.com^$all ||3.239.226.246^$all ! hxxpx[:]//crackpropc[.]com/winrar-crack/ - https://bazaar.abuse.ch/sample/4f4376563cfc35d3fb0b4f857674729727b5f959235fe39daa928a1d4a28649a/ ||wastyuioytryiuoytryiuopuytryuioewr5t678i.s3.amazonaws.com^$all ! https://github.com/uBlockOrigin/uAssets/pull/10997 ||jinshanduba.org.cn^$all ||phpstat.cntcm.com.cn/phpstat/count/abceffgh/abceffgh.js^$all ! https://bazaar.abuse.ch/sample/357226dff2f3309f8271b5a7c2cc816aa8fb779275357dce9b98b30357951210/ ||download-srvr.xyz^$all ||134.122.115.190^$all ||cybermicto768jubileejhsye6yt6543.s3.us-east-1.amazonaws.com^$all ! https://bazaar.abuse.ch/sample/932fcccda7c8e576eb914b446646883cfdb439fe4c7306905ea005555be5e2bb/ ||hopelandishomeground1098alone43jk.s3.amazonaws.com^$all ! https://github.com/uBlockOrigin/uAssets/pull/11041 ||cdn.discordapp.com/attachments/916391647955279943/*^$all ! https://bazaar.abuse.ch/sample/9dfd1e4d88c586107f341620c9682710a414f34e2086aab363661f8eb8031202/ ||gigapurbalingga.net^$all ||rigrosehostingz.xyz^$document ! https://www.virustotal.com/gui/file/e48c144e54d3200492b920895b376a8cb34a2360195b3b3f4917fd59d23b6474/community ||185.215.113.84^$all ! https://www.virustotal.com/gui/file/4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7/community ||219.155.253.210^$all ||115.49.24.255^$all ||117.208.142.95^$all ||103.120.135.7^$all ||115.49.211.138^$all ||125.40.129.199^$all ||113.161.85.21^$all ||125.45.67.146^$all ||115.49.0.243^$all ||61.3.190.7^$all ||222.141.81.58^$all ||27.215.208.235^$all ||117.207.224.231^$all ||125.43.37.212^$all ||182.126.237.139^$all ||42.238.224.204^$all ||116.74.159.230^$all ||219.157.178.48^$all ||117.251.58.193^$all ||115.56.57.233^$all ||182.121.241.159^$all ! https://www.virustotal.com/gui/file/2e4506802aedea2e6d53910dfb296323be6620ac08c4b799a879eace5923a7b6/community ||42.232.75.216^$all ||117.194.165.28^$all ||182.122.211.130^$all ||117.215.206.198^$all ||115.99.115.202^$all ||117.194.162.10^$all ||115.62.141.32^$all ||117.213.46.75^$all ||117.217.155.3^$all ||117.198.249.117^$all ! https://forums.malwarebytes.com/topic/282207-how-to-remove-pupoptionalbrowserhijack-and-pupoptionallockhomepage/ ! (20/12/2022) https://github.com/AdguardTeam/AdguardFilters/issues/137498 ||find-it.pro^$all ! fake Flash Player ||new-meet-dating.life^$document ||wellhello.com^$document ! https://github.com/blocklistproject/Lists/issues/600 ||avomas.me/rbBvg78^$all ||choicemonitor.top^$document ||hellothere.shop/a/OUevEKzLtg2P7xAs^$document ||italtrack.checkitemtt.top^$all ||checkitemtt.top^$document ||conv-alida-recapiro-com.preview-domain.com^$document ! https://forums.malwarebytes.com/topic/282353-peruvian-netflix-phishing/ ||juandfar.github.io^$all ! https://forums.malwarebytes.com/topic/282352-metamask-phishing/ ! https://github.com/uBlockOrigin/uAssets/pull/11161 ! https://bazaar.abuse.ch/sample/d696d27429f51199a8b88b7a332cfa2c05d6cf6a875a88046a8764a290bf588f/ ||slidehostdowny.xyz^$all ! https://twitter.com/TheDFIRReport/status/1477687477821489157 ||rest.healthy2fit.com^$all ||api.healthy2fit.com^$all ||rest.mcghealthcare.org^$all ||rest.neckbackpainrelief.org^$all ! https://github.com/uBlockOrigin/uAssets/issues/11157 ||sideload.net^$all ||stcverify.com^$all ||verify.stc.tools^$all ||1980s.click^$all ||0x41414141.net^$all ||yatsura.0x41414141.net^$all ||chrome.google.com/webstore/detail/ultimate-ad-eraser/hkmfdialkjnljbcnincgpollobclebaf^$document ||ultimate-eraser.com^$document ! https://www.virustotal.com/gui/url/747b8465c517261eb6c5bc1a6c4fa281dc309caecf4a283f9bfb4fe2ba795bd0 ||mailsecure-helpdesk.azurefd.net^$all ! https://www.virustotal.com/gui/file/a7ee420fd3a477e690dab56f47b264dd6c8376941101065d6645716bbf4b6333/community ! https://twitter.com/pr0xylife/status/1479004948868341760 ! https://scammer.info/t/discord-nitro-scam-26/87304 ! https://scammer.info/t/discord-nitro-scam-25/87303 ! https://scammer.info/t/discord-nitro-scam-23/87273 ||discqrdapp.com^$all ! VirusTotal typosquatt ||virusttotal.com^$document ! https://blog.malwarebytes.com/threat-intelligence/2022/01/patchwork-apt-caught-in-its-own-web/ ||bgre.kozow.com^$all ! https://blog.malwarebytes.com/web-threats/2022/01/card-skimmers-strike-sothebys-in-brightcove-supply-chain-attack/ ||cdn-imgcloud.com^$all ! https://twitter.com/MBThreatIntel/status/1480659259712884736 ! https://scammer.info/t/discord-nitro-scam-25/87887 ! https://twitter.com/pr0xylife/status/1483380330652487680 ||185.7.214.7^$all ||plus-x.xsrv.jp^$all ||senior.tims.se^$all ||mecaglobal.com^$all ||mymicrogreen.mightcode.com^$all ||ariesnetwork.co.uk^$all ||animalkingdompro.com^$all ||bitcoin-up.fomentomunivina.cl^$all ||cr.almalunatural.com^$all ! https://github.com/blocklistproject/Lists/issues/623 ! https://github.com/blocklistproject/Lists/issues/613#issuecomment-1018499340 ! https://www.virustotal.com/gui/file/cfb15322084d6292f43038a69b0e017b809f178b7c85c310f8effdb37a3eb9a3/community ||florafawnamusic.com^$all ! https://www.virustotal.com/gui/file/edddab090284f2bd22d4a30b9bbe352af5c0c357f72ab3d27154fdabf9fee51c/community ! https://www.virustotal.com/gui/file/049c51aeeb616f8b465cbe006dd1d3ad27984882578f07ec043c71148797cccf/community ||179.43.175.148^$all ! https://www.virustotal.com/gui/file/72876d8f3fec998843102c94c464720c1e4396a8ce04646f171dd7b536c9ebde/community ||198.12.127.206^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/108571 ! https://www.virustotal.com/gui/file/a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3/community ||36.228.38.96^$all ||73.245.16.190^$all ||121.133.250.192^$all ||41.59.209.155^$all ||115.77.26.74^$all ||114.35.112.180^$all ||121.205.222.107^$all ||211.54.161.58^$all ||121.152.20.166^$all ||187.250.30.0^$all ||111.241.216.187^$all ||111.253.35.172^$all ||111.179.133.179^$all ||211.75.65.95^$all ||187.200.227.124^$all ||123.110.151.230^$all ||221.159.165.11^$all ||212.179.73.183^$all ||121.121.214.89^$all ||77.228.81.248^$all ||59.0.83.244^$all ||90.84.226.16^$all ||201.41.75.69^$all ||1.34.169.117^$all ||86.164.144.181^$all ||97.123.168.21^$all ||36.229.172.49^$all ||128.106.214.238^$all ! https://www.virustotal.com/gui/file/63a46fa06e1bd31832daa958d3a706fd86fbe8f7a2897dc19e52516e4a2066d5/relations ||goyaluat.vmesh.in^$all ! https://www.virustotal.com/gui/file/3b0158eb80a4ce6aefbab643c3ca57253d265c8c82754c4a7e31dbd64b5aa48f/relations ||actividades.laforetlanguages.com^$all ||laforetlanguages.com^$document ! https://urlhaus.abuse.ch/url/2028661/ ||112.30.110.62^$all ! https://www.virustotal.com/gui/file/80b5c38471c54298259cec965619fccb435641a01ee4254a3d7c62ec47849108/relations ||111439d.com^$all ||intrasvp.com^$all ||paulbau.com^$all ||peninsularbottling.com^$all ||spoilnet.com^$all ||thebeardedbrocksblends.com^$all ||wokpy.com^$all ||www.111439d.com^$all ||www.intrasvp.com^$all ||www.paulbau.com^$all ||www.peninsularbottling.com^$all ||www.spoilnet.com^$all ||www.thebeardedbrocksblends.com^$all ||www.wokpy.com^$all ||3.65.197.215^$all ! https://www.bleepingcomputer.com/news/security/a-look-at-the-new-sugar-ransomware-demanding-low-ransoms/ ||cdn2546713.cdnmegafiles.com/data23072021_1.dat^$all ! https://www.virustotal.com/gui/file/a04ac6d98ad989312783d4fe3456c53730b212c79a426fb215708b6c6daa3de3/community ||14.104.202.76^$all ||64.53.194.165^$all ||220.132.105.96^$all ||125.227.100.174^$all ||200.233.149.106^$all ||2.155.46.3^$all ||59.127.120.208^$all ||220.134.14.181^$all ||31.13.242.34^$all ||81.40.150.158^$all ||31.176.167.197^$all ||122.117.83.6^$all ||114.32.86.193^$all ||171.231.141.107^$all ||190.72.46.4^$all ||171.112.17.161^$all ||114.35.206.42^$all ||61.65.106.44^$all ||36.81.98.204^$all ||1.173.102.238^$all ||104.189.11.61^$all ||111.235.253.81^$all ! https://github.com/uBlockOrigin/uAssets/issues/11574 ||rutracker-org.appspot.com^$all ! https://scammer.info/t/forza-discord-server-hacked/90265 ||program-moderator.com^$all ! https://www.virustotal.com/gui/url/c25fe34c05cc8e9136027a67c277e175a5d6e35af921ee37bad98bdfeea6a2f9/community ||6201375e287cc50016414168.2go.me^$all ||splendid-fallacious-anaconda.glitch.me^$all ! https://www.virustotal.com/gui/file/9d40ae0439ddc594b2cf64e21ad0fdea9bb440524298e3a6bcfcc1fb417f1ed2/relations ||91.240.118.172^$all ! https://www.virustotal.com/gui/file/568cfb6f770f6fbec1f18595bb78183e1fb5d2e7086f747230f2706ce29ed381/relations ||www.tzkaxh.com^$all ! https://www.virustotal.com/gui/file/2e4506802aedea2e6d53910dfb296323be6620ac08c4b799a879eace5923a7b6/community ||125.42.96.46^$all ||115.56.134.142^$all ||59.93.20.83^$all ! weebly domains ||trekcelestial903.weebly.com^$document ||c0xmailservice.weebly.com^$all ! https://twitter.com/malwrhunterteam/status/1491859158349537280 ! https://www.virustotal.com/gui/file/33b647a646e62b8b95a40370b3a228fa50d7ac844bf4192456213ed492d74b83/relations ! https://github.com/uBlockOrigin/uAssets/pull/11744 ||greencracks.com^$all ||procrackerz.com^$all ||crackfix.net^$all ||zcracked.com^$all ||cracksoftware.org^$all ||downloadpc.net^$all ||pcfullcrack.org^$all ||keygenpc.com^$all ||up4pc.com^$all ||hitproversion.com^$all ||cracktube.net^$all ||137.184.159.42^$all ||iplogger.org/2Acru6^$all ||yourpcnotification.com^$all ! https://blog.malwarebytes.com/threat-analysis/social-engineering-threat-analysis/2022/02/dont-let-scammers-ruin-your-valentines-day/ ||162.33.178.57^$all ! https://www.virustotal.com/gui/file/8b5acf86118df625a1a40e3fe0ba9794630d4c7ffce95bf82fc2b924e0743bab/relations ||198.46.132.195^$all ! https://twitter.com/ankit_anubhav/status/1495648193396490240 ! https://www.virustotal.com/gui/file/6411a828f023be935730023e2b3bd19843106557a4a8c7126ffb4f7b16383ffe/community ||107.175.87.164^$all ! https://www.virustotal.com/gui/url/bd46572625a7d66dac92a3674fb9b8d31ef855b3229ab8ac650e8d198981ed1e/community ||www.takiparkrb.site^$document ! https://www.virustotal.com/gui/file/e3d3a7a94a0b6d8e6b4134d79f2c994c8a182a5a95ea3b447effe1c66586d995/relations ||115.88.24.202^$all ||13.107.4.52^$document ||193.106.191.67^$all ||6vftqk5hzuoaxd4m6gspin3ro6f2oujh.h6762ca.1.0.6tpdtd56tfu7tsm2xx43yj6pb4.94yb3vv.dns0.org^$all ||q3hvyvpkoev6nvwrp6g6f6cxxl4ugf25.y3jkf4i.1.0.3lz6ptnftqnrw7bhndcebflm4m.ivwssta.dns0.org^$all ||q3hvyvpkoev6nvwrp6g6f6cxxl4ugf25.y3jkf4i.1.0.q4pgqq4iaegujt6mpszvhgvh4i.ivwssta.dns0.org^$all ||q3hvyvpkoev6nvwrp6g6f6cxxl4ugf25.y3jkf4i.1.0.6iugxidyjier3po36q3odpktma.ivwssta.dns0.org^$all ||q3hvyvpkoev6nvwrp6g6f6cxxl4ugf25.y3jkf4i.1.0.ukhwibi7qimje53kbrnuugefiq.ivwssta.dns0.org^$all ||q3hvyvpkoev6nvwrp6g6f6cxxl4ugf25.y3jkf4i.1.0.375ulyaygql2ws7cbvhblanuny.ivwssta.dns0.org^$all ||eio7hluliekppcnd6ig2dj7gcom77h2d.3gal7iq.1.0.yeju5hcinqakiiz3d7bwts6tsy.iwfqgkc.dns0.org^$all ||ykqbts2t6x4sc354mdei6j5e6qe6baro.vrvy4ai.1.0.tgiaqbuyasefat64vj3vinfd5m.4d6vd7y.dns0.org^$all ||ykqbts2t6x4sc354mdei6j5e6qe6baro.vrvy4ai.1.0.p6445pgfu5ghwhrxj5ss7n6d2e.4d6vd7y.dns0.org^$all ||ykqbts2t6x4sc354mdei6j5e6qe6baro.vrvy4ai.1.0.od6u6m3cwr3rwf22eqjtek235vawsh4god2b3si.4d6vd7y.dns0.org^$all ||uh6uml572agk2gsjnxfy6kh2rbnqfncs.g7ezefi.1.0.ebvysjyolmz7nzsl4k64fjzdfm.pl4kazi.dns0.org^$all ||q3hvyvpkoev6nvwrp6g6f6cxxl4ugf25.y3jkf4i.1.0.gwvblzfxjyhvpqjljezw6qwdju.ivwssta.dns0.org^$all ||ykqbts2t6x4sc354mdei6j5e6qe6baro.vrvy4ai.1.0.ozlnabtsgij2f5y455ywbxylg4.4d6vd7y.dns0.org^$all ||211.119.84.111^$all ||203.228.9.102^$all ! https://twitter.com/malwrhunterteam/status/1502609755868696578 ! https://github.com/uBlockOrigin/uAssets/issues/12194 ||fulptube.org^$all ! https://blog.netlab.360.com/b1txor20-use-of-dns-tunneling_en/ ||194.165.16.24^$all ! https://bazaar.abuse.ch/sample/d7308dab0110ae3bc79fd15024f5ccfcbd6e676b7c42b27a0112506e8357a6dc/ --> https://app.any.run/tasks/bc53e7a9-5fd7-4682-894d-11e48e9ea89a# ||www.pccrackworld.com^$all ||pccrackworld.com^$all ! https://twitter.com/reecdeep/status/1504732496616906756 ! https://www.virustotal.com/gui/file/f158c883db7803a14c124e29a3adb1b72cca3168d904f7cee2a6ebbbdc535ca3/relations ||winfrey2024.com^$all ||www.winfrey2024.com^$all ||bisbenefits.solutions^$all ! https://www.virustotal.com/gui/file/361805dc92fd6e036de72ba6eebb15dbf62e12e4b24462bba58b9565a56a18f3/relations ! https://www.virustotal.com/gui/file/31d61f0e8fd95c5d71954c86a35617a4449d0f872c1be00aa33ffc01518c4310/relations ||136.144.41.109^$all ! https://www.virustotal.com/gui/url/a7c6db453eaaafa9450ff12b5e85d81c8fc096912f1d9c295a908bd5c02ef3bd/community ||okra-grouper-hny2.squarespace.com^$all ! https://www.virustotal.com/gui/url/2c676a4669628763604e0c4ed6079737163385a92acc45e0eeedfed9790dbbb4/community ||thaisethalitaconfeccoes.com.br^$all ! https://www.virustotal.com/gui/url/8e6215c6207521bca9da1d1e72bfcb5256ef0f4a46201e6a041756671c1c45d5?nocache=1 ! https://www.virustotal.com/gui/url/34512642d5d361717a97c817fbf65c008d4cc903a2c7ae641820a9d1e0fca5e0?nocache=1 --> https://app.any.run/tasks/5fb54e2b-1857-45ea-9656-bb4e185d47ab ||pirate4.life^$all ! https://www.virustotal.com/gui/file/439db5f69b49091964c335c5977bc6dbf8aa41398d0240410dfeb898add7dace/relations ||891706.com^$all ||www.njgummys.com^$all ! https://www.virustotal.com/gui/url/3e045124ad9f01b098462bc0397705e565d563c708dee52aaea209f55aea86bb ||oasis-field-servant.glitch.me^$all ! https://www.virustotal.com/gui/file/cc4b90ead0e3fbb3d0a0add7ba7f38f6ab300295a55f8dd372d0edda85b4cf35/relations ||212.237.17.99^$all ||46.55.222.11^$all ||131.100.24.231^$all ! https://www.virustotal.com/gui/file/cdbcc352e90f35e330bf954fe07466bd0cf2c1cf8d9112d92e3e7fd3d04317b4/community ||212.192.246.30^$all ! https://app.any.run/tasks/72d406c1-d787-4c18-a8a6-5c5d4a07af07/ (original run by someone else) --> https://app.any.run/tasks/76f5eba8-f2e6-4800-83b7-d04ed1799253 (run by me) ||honored-yummy-cheetah.glitch.me^$all ! https://www.virustotal.com/gui/url/48fca83cbb6dc2f75f0e8a1546d4f396a5914502ead0060a0eefb2ed580a8c09 (seems down but no reason not to block it) ||vww-robiox.com^$all ! https://www.virustotal.com/gui/url/169c42480ba36ed07c5895da489593248c6da52e54a7c382748258aa798d8ee1 ||littleluxuriesshop.com^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/111970 ||a23-trk.xyz^$all ! https://www.virustotal.com/gui/file/635a5c00275d4f354e8f38c646c9210440bacc46088c45907132d82b11877783/relations ||27.147.183.45^$all ! https://bazaar.abuse.ch/sample/3fd0837381babda7ef617b810457f0db32bd7c1f7e345480e6c525050ca818fa/ ! https://www.virustotal.com/gui/ip-address/188.114.97.16/relations ! https://forums.malwarebytes.com/topic/285132-outgoing-trojan-2dodddnsnet/ ||2dod.ddns.net^$all ! https://decoded.avast.io/janrubin/parrot-tds-takes-over-web-servers-and-threatens-millions/ ||clickstat360.com^$all ||statclick.net^$all ||staticvisit.net^$all ||webcachespace.net^$all ||syncadv.com^$all ||webcachestorage.com^$all ||parmsplace.com^$all ||xomosagency.com^$all ||lawrencetravelco.com^$all ||accountablitypartner.com^$all ||codingbit.co.in^$all ||fishslayerjigco.com^$all ||avanzatechnicalsolutions.com^$all ||wholesalerandy.com^$all ||integrativehealthpartners.com^$all ||wwpcrisis.com^$all ||markbrey.com^$all ||nuwealthmedia.com^$all ||pocketstay.com^$all ||fioressence.com^$all ||drpease.com^$all ||refinedwebs.com^$all ||spillpalletonline.com^$all ||altcoinfan.com^$all ||hill-family.us^$all ||109.234.35.249^$all ||141.136.35.157^$all ||91.219.236.192^$all ||91.219.236.202^$all ||194.180.158.173^$all ||87.120.8.141^$all ||15.76.172.110^$all ||45.76.172.113^$all ||5.180.136.119^$all ||94.158.247.84^$all ||94.158.245.113^$all ||94.158.247.100^$all ||154.38.242.14^$all ||199.247.3.55^$all ! https://bazaar.abuse.ch/sample/b959fb160dac2a15b8e65c15e2b1738d356c03e13623588bc70aab825c57660a/ ||penana.com/story/89349/winrar-6-0-universal-crack-activation-key-free-download-2021-latest/issue/0^$document ||freeversioncrack.com^$document ||top3hostngc.xyz^$all ||198.199.120.251^$all ! https://app.any.run/tasks/5fcd7eda-1f8b-4e99-80f9-5429d6044d16 ||45.84.0.112^$all ||45.67.229.135^$all ! another malware website ||gamesrar.co^$all ||hiptheacro.xyz^$all ||ucedover6.xyz^$all ! https://www.virustotal.com/gui/url/5362f975d1c08851b967850f2053c2ea79e6f2687012911733d65f4cf130cfff/community ||webmail8pnme.srvrwwalker.workers.dev^$all ! https://www.virustotal.com/gui/file/82d95ff9662f05179df7fdccb7ffb7b9e9cd96fb04792aed62ca40efbadca263/relations ||103.167.92.57^$all ! https://www.virustotal.com/gui/url/e47d6ed8866072e58d28b93dd0c7b06d148e5139c1dbe219a16ba288ba14f93c/community ||nolhivaranfaruonline.com^$all ! https://www.virustotal.com/gui/url/abc995b45665ad896ef807e92a3af1f29f5b9fd06dbac888eba326b4c8e93a06/community --> https://twitter.com/ANeilan/status/1513210658166390787 ! https://twitter.com/ANeilan/status/1513203825313824773 ! https://www.virustotal.com/gui/url/3d68f17518f9d0f4bc75e9f44e7ac5b3e4f0f474362ea08efa45d6b0c4cfe6a1 ! https://www.virustotal.com/gui/url/dc7b1ff1beb61c84c6200391d3ef818f9975256f4e347795bf8ccec14a7a2a66/community ! https://www.virustotal.com/gui/url/511902d4a7801d3a8ce02ae5efcb35ff708e58bf6f2e92e44df5e346daa102af ! https://forums.malwarebytes.com/topic/285865-malwarebytes-keep-blocking-random-websites/ ! https://bazaar.abuse.ch/sample/306b5745054cab7a000edf375dd4409935c6ff704dff0860a3563a04b3fa8e66/ ||2.56.57.98^$all ! https://www.virustotal.com/gui/url/87940af669b5cb1dfe0feafd6c01ae7d1d9b8b3625f24224984fe38fdd5ccf1d/community ||sutori.com/*/story/initial-page--3Xq4D6k3uL8JGkqskxczjBGr^$document ! https://www.virustotal.com/gui/url/28590bc925cf6387239b0adb2700d16d66623310afc412e5b5d8ac0b3bab3f94/community ||acrobat.adobe.com/link/track?uri=urn:aaid:scds:US:402a12fc-278e-4136-b7e9-21ccf8f776ff^$document ||storageapi2.fleek.co/8c451350-3ebb-4bff-87d5-9e3f891de4dc-bucket/codepen.io/index.html^$all ! https://www.virustotal.com/gui/url/d9a2be341e814e16c837b215cac13b30add4aba14eec06f4b6d400d0a0409ce3/community ||ipfs.io/ipfs/QmYGtFWcS83HpCnr7zSynPutkjooXdLbkHAWYHii6NpwzW?key=dbb6c0056aea6d10954f4e761688a09d1d85eb28&url_01=https://lithsman-neuroplasty-pandectist.s3.eu-central-003.backblazeb2.com/index.html&url_02=https://anthracnosis-jackscrew-rubine.s3.eu-central-003.backblazeb2.com/index.html&url_03=https://collyrite-hurst-rencounters.s3.eu-central-003.backblazeb2.com/index.html&url_04=https://freckleproof-hymnaria-lobbying.s3.eu-central-003.backblazeb2.com/index.html&url_05=https://audiovisual-jailer-woke.s3.eu-central-003.backblazeb2.com/index.html&redirect=https://www.amazon.com^$all ||anthracnosis-jackscrew-rubine.s3.eu-central-003.backblazeb2.com^$all ! https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/ (dead but may undie) ||windows11-upgrade11.com^$all ! https://www.virustotal.com/gui/url/b56536f2753c28e251a16e85e960e503e1a0fa7460225daba497734b091ef3d6/community --> https://app.any.run/tasks/0d8b025d-ba39-4f88-b83d-db3274b62f49 ||codesbro.com^$document ! https://www.virustotal.com/gui/file/56682c4820125acfcfc901b7c478b4f3925ad0bd8cba76a43c4189c230288543/relations ! https://github.com/uBlockOrigin/uAssets/pull/12902 ! https://www.virustotal.com/gui/file/ebb5399c5cdae017dce979d25046e7cc7963eac947201a1395975c4613fc5454 --> https://www.virustotal.com/gui/url/b228c1c9c795926c58c75fe54181e675b5a8fb304c24d8b8d3a7b6f25b086399 ||isiontalents.cfd^$document ! https://forums.malwarebytes.com/topic/286125-riskware-when-doing-a-google-search/ ||flydogy.com^$all ! https://bazaar.abuse.ch/sample/a5c87433df7f9a01cd7140d0882e6f227c62076b14d92f6fd9ab3e0570b596ee/ ||portabledownloads.com^$all ||jetiparfilezho.xyz^$all ||188.166.138.48^$all ||104.248.97.164^$document ||95.217.246.15^$all ! https://app.any.run/tasks/1d3c738e-f209-457b-ae95-fc42433cafbf ! https://bazaar.abuse.ch/sample/50196dfa833bc753f0c8a4b7f17c6462ad3e7f2eee41b52943f2eadade94ce53/ --> https://app.any.run/tasks/15ce1b12-68d5-4345-8a56-c89b97839241 ||195.201.253.119^$all ! https://urlhaus.abuse.ch/url/2186985/ --> https://app.any.run/tasks/26b0ab9a-34d9-4def-902f-a371e1e2b60f ! https://forums.malwarebytes.com/topic/286435-malwarebytes-reporting-riskware-through-powershell-every-minute/ ||wmail-service.com^$all ! https://forums.malwarebytes.com/topic/292561-website-blocked-due-to-riskware/ ||counter.wmail-service.com^$all ! https://app.any.run/tasks/f0cf926b-dd19-4209-9e0c-a1ae1855a77b/ ||telegra.ph/Free-Repacks-04-30^$all ! https://app.any.run/tasks/4ff53b3b-551f-4a5f-a303-c5938d31c376 ||telegra.ph/Injector-By-Vap-04-30^$all ! reported by https://github.com/PiQuark6046 - https://app.any.run/tasks/79e5c167-4efd-487a-b5d8-c860d45ac13a ||mlxkxt.spellwomancapital.xyz^$all ||spellwomancapital.xyz^$document ! https://blog.malwarebytes.com/threat-intelligence/2022/05/custom-powershell-rat-targets-germans-seeking-information-about-the-ukraine-crisis/ --> https://app.any.run/tasks/38748b95-4658-4e8a-9ff3-43c5283c53af ! https://web.archive.org/web/20220513180448/https://forums.malwarebytes.com/topic/286567-large-red-circle-in-top-right-corner-of-mb-dock-icon-all-of-a-sudden/ ! https://forums.malwarebytes.com/topic/286715-emailed-html-file-phish-appears-is-somehow-bypassing-browserguard/ ||rickmemeoapz.firebaseapp.com/bnmyssrthsdvzxv/themes/imgs/microsoft_logo.svg^$all ||etools.page^$document ! https://bazaar.abuse.ch/sample/17f5cb1dba8dd540465e9135d6541f2a7f871caee59c8afc63cf17e820c0f22f/ ||gdyhjjdhbvxgsfe.gotdns.ch^$all ||2.58.149.219^$all ! https://bazaar.abuse.ch/sample/07a496254e53741aa86e2292f1fce40bf04690504d8cda443d000133099ca107/ ||startcrack.co^$all ||upperclassan.xyz^$all ||slamicrep.cfd^$all ||lectedacivilia.cfd^$document ! https://www.virustotal.com/gui/url/6764a8e44b5fa318bbf85df6eb6d083a20fc7090b85b0d43068b8f934ad9b2c2 --> https://www.virustotal.com/gui/file/10dbb4692e34a6f3ca1cf82668a87b1204aa1548c139d88240680d3b82473510?nocache=1 ||www.enjpc.com^$all ||enjpc.com^$all ||uploadev.org/hkoarfyqyne8^$all ||nholinolout.tk/0d94969df6099021ed5f897a4144a946wOXvweYgLQgLx-WSJE8uNrZlSB0R8yPrpXhu/-Download-E33Hwwp-QbvNGlXIoS^$all ! https://www.virustotal.com/gui/url/ea37961ff4ba03a3f50b537668b97e7e682a4d6c2a980504ed4be8d4f593fd96 --> https://bazaar.abuse.ch/sample/727a3154e9862b477a4d556940a8fb47fb7f8dd955102ef7738bc32b587076f5/ ||latestsoftz.com^$all ||cdn.discordapp.com/attachments/888545381921726544/980115418058457158/setup.7z^$all ||cdn.discordapp.com/attachments/888545381921726544/980115239888637993/setup.rar^$all ! https://twitter.com/ankit_anubhav/status/1531258779899047938 ||textbin.net/raw/2tgh7yhhzs^$all ||rick63.publicvm.com^$all ! https://twitter.com/Artilllerie/status/1534076124829036544 ||bbleepingcomputer.com^$document ||bleepingc0mputer.com^$document ||bleepingccomputer.com^$document ||bleepingcimputer.com^$document ||bleepingcmoputer.com^$document ||bleepingcmputer.com^$document ||bleepingcommputer.com^$document ||bleepingcomouter.com^$document ||bleepingcompiter.com^$document ||bleepingcompouter.com^$document ||bleepingcompputer.com^$document ||bleepingcomptuer.com^$document ||bleepingcompurer.com^$document ||bleepingcomputee.com^$document ||bleepingcomputeer.com^$document ||bleepingcomputerr.com^$document ||bleepingcomputet.com^$document ||bleepingcomputor.com^$document ||bleepingcomputre.com^$document ||bleepingcomputrr.com^$document ||bleepingcomputter.com^$document ||bleepingcomputwr.com^$document ||bleepingcompuuter.com^$document ||bleepingcompuyer.com^$document ||bleepingcompyter.com^$document ||bleepingcomupter.com^$document ||bleepingconputer.com^$document ||bleepingcoomputer.com^$document ||bleepingcopmuter.com^$document ||bleepingcoputer.com^$document ||bleepingcpmputer.com^$document ||bleepingocmputer.com^$document ||bleepingvomputer.com^$document ||bleepingxomputer.com^$document ! https://blog.malwarebytes.com/threat-intelligence/2022/06/makemoney-malvertising-campaign-adds-fake-update-template/ ||ankgomag.xyz^$all ||ankltrafficexit.xyz^$all ||clicksdeliveryserver.space^$all ||cryptosuite.pro^$all ||daiichisankyo-hc.live^$all ||gettime.xyz^$all ||hilllandings.xyz^$all ||jillstuart-floranotisjillstu.art^$all ||keitarotrafficdelivery.xyz^$all ||makemoneyeazzywith.me^$all ||makemoneywith.us^$all ||mizuno.casa^$all ||money365.xyz^$all ||nawa-store.com^$all ||nippon-mask.site^$all ||openphoto.xyz^$all ||selfadtracker1.online^$all ||traffic.selfadtracker1.online^$all ||zerocryptocard.shop^$all ||185.220.35.26^$document ||188.225.75.54^$document ||185.220.33.3^$document ||185.230.140.210^$document ||188.227.107.121^$document ||188.227.107.92^$document ! fake CCleaner Pro crack ! https://app.any.run/tasks/c98acb53-5c81-4840-b337-9eb903dc66ec ||116.202.185.47^$all ! https://twitter.com/iam_py_test/status/1538235776479113216 ! https://www.virustotal.com/graph/g22a0aa9e571c4748864e82e07d46877469dc7d43cb864e76b56b22703db70962 ||107.172.191.148^$all ! https://bazaar.abuse.ch/sample/7a1ac49143e4dc8d3e7f3d033b1b382b3120bfdebfbaf3a304ab2f086456a896/ ||telegra.ph/Install-3-06-11^$all ||mediafire.com/file/eeqo14m9t7mqvdr/Install.rar/file^$all ||download2338.mediafire.com/9j4nj1ohhgug/eeqo14m9t7mqvdr/Install.rar^$all ! https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert/ ||accdn.lpsnmedia.org^$all ||app.iofrontcloud.com^$all ||app.nomalert.org^$all ||cdn.alligaturetrack.com^$all ||cdn.base-code.org^$all ||cdn.boxsearch.org^$all ||cdn.getambassador.net^$all ||cdn.tomafood.org^$all ||common.quatserve.com^$all ||dwin1.org^$all ||epos.bayforall.biz^$all ||h.lookmind.net^$all ||hal-data.org^$all ||img.etakeawaymax.biz^$all ||js.imagero.org^$all ||lp.celebrosnlp.org^$all ||m.sleeknote.org^$all ||px.owneriq.org^$all ||sdk.moonflare.org^$all ||search.global-search.net^$all ||sjsmartcontent.org^$all ||static.clarlity.com^$all ||static.lookmetric.com^$all ||static.newrelc.net^$all ||trustedport.org^$all ||web.livechatsinc.net^$all ||web.speedstester.com^$all ||185.253.32.174^$all ||185.253.32.42^$all ||185.253.32.44^$all ||185.253.32.50^$all ||185.253.32.59^$all ||185.253.32.64^$all ||185.253.33.179^$all ||185.253.33.188^$all ||185.253.33.191^$all ||185.253.33.40^$all ||185.63.188.59^$all ||185.63.188.70^$all ||185.63.188.71^$all ||185.63.188.79^$all ||185.63.188.85^$all ||185.63.190.118^$all ||185.63.190.144^$all ||185.63.190.163^$all ||185.63.190.183^$all ||185.63.190.205^$all ||185.63.190.207^$all ||185.63.190.212^$all ||194.87.217.195^$all ||194.87.217.197^$all ||194.87.217.91^$all ||77.246.157.133^$all ||80.78.249.78^$all ||82.146.50.89^$all ||82.146.50.132^$all ||82.202.160.10^$all ||82.202.160.119^$all ||82.202.160.123^$all ||82.202.160.137^$all ||82.202.160.29^$all ||82.202.160.54^$all ||82.202.160.8^$all ||82.202.160.9^$all ||89.108.109.14^$all ||89.108.109.169^$all ||89.108.116.123^$all ||89.108.116.48^$all ||89.108.123.168^$all ||89.108.123.169^$all ||89.108.123.28^$all ||89.108.126.50^$all ||89.108.127.16^$all ! https://bazaar.abuse.ch/sample/fc03d6fa6787c0e6fee51af9c567bc1febf642bdfd6fd91ee99348b0a2cdf947/ ||goo-gl.me/C_Cleaner^$all ||mega.nz/file/qKJWHISB#zhJ0PQq_ZPMrsbWNHGrEdfCvoBCUWLdFULYAiwqX_Jg^$all ! ads ||lulachu.com^$document ||zoomstreakstream.com^$all ! https://twitter.com/malwrhunterteam/status/1539964420607971328 ||business-page-appeal-126-73125.web.app^$all ! https://scammer.info/t/phishing-my-account-will-be-blocked/100783 ||bit.do/terewebmqil^$document ||firebasestorage.googleapis.com/v0/b/vendozal-adrewebmailkd.appspot.com/o/unltd-webmailkjd892f.html?alt=media&token=a5c621d4-0c0c-46ea-bcea-bf03fb27acc0$document ! https://scammer.info/t/fake-discord-nitro-generator/99942 ! https://bazaar.abuse.ch/sample/afc4c49625b8c888e7e4958ec95cf0a79baf48736d71b0cac2bb2fc5f1c99279/ ||importadoracandy.com^$all ! https://twitter.com/malwrhunterteam/status/1541694571461201928 ! YouTube video on a probably hacked channel --> https://bazaar.abuse.ch/sample/786947bd41f7be120bc82fd563b5658ff319bcb45f8e3a35e9e4c62a03ef103e/ ||telegra.ph/Sony-Vegas-Pro-19-Crack-06-28-3^$all ||mega.nz/file/nWhSiBRQ#DfJfKPJFf6EiWI3vrVp2IvbBgbsmAqIid9l0H_e3ngE^$all ! https://www.virustotal.com/gui/url/419dcd36895e1822796c14fa169a191eeda2f03013bd8f225aef6ba2f22aad3a/community ! https://app.any.run/tasks/85e32268-b888-4dfb-bb30-c7cec084039c ! https://www.virustotal.com/gui/file/8014510ba4ca11285598396ec7f36058ce42b2fdd4fd80004c1f1c84933126f1/detection ||jodywiltjer614883.wixsite.com^$all ||byltly.com/24hrsg^$all ||sbnue.com^$document ! https://forums.malwarebytes.com/topic/287876-im-posting-a-malware-to-ask-if-anyone-know-the-type-of-this-malware/ ||cdn.adx1.com/df60634899739d9c8ce9ae33940358dd.jpeg^$all ||cdn.adx1.com/8b678aab9185cb333cc7c1bf3442adcb.jpeg^$all ||www.esoftwareplus.live^$all ||esoftwareplus.live^$document ||esoftwareplus.online^$document ||www.esoftwareplus.online^$document ||surofim.life^$all ! https://app.any.run/tasks/85cfa904-06c4-4603-82ec-7a3db8db8df9 ||tjzaj.comfortykive.xyz^$all ||comfortykive.xyz^$all ||safefastfreesmart.rest^$document ||rewards-giant.uk^$all ||www.rewards-giant.uk^$all ||bepoha.live^$all ! (14/11/2022) https://app.any.run/tasks/508eecd4-0573-433f-9888-ea4bfe10e5d5 ||fbuww.ewoverth.buzz^$all ||ewoverth.buzz^$all ||cemgf.ewoverth.buzz^$all ||paylk.ewoverth.buzz^$all ||krtbw.ewoverth.buzz^$all ||lyirs.ewoverth.buzz^$all ||stijy.ewoverth.buzz^$all ||pwazc.ewoverth.buzz^$all ||uxdpj.ewoverth.buzz^$all ||jxaox.ewoverth.buzz^$all ||fqdbx.ewoverth.buzz^$all ||qakbs.ewoverth.buzz^$all ||wfarv.ewoverth.buzz^$all ||tepmv.ewoverth.buzz^$all ||ivuvh.ewoverth.buzz^$all ||rqsyl.ewoverth.buzz^$all ||hhqdq.ewoverth.buzz^$all ||eysei.ewoverth.buzz^$all ||jdmhf.ewoverth.buzz^$all ||xdgip.ewoverth.buzz^$all ||qdudm.ewoverth.buzz^$all ||xdnpv.ewoverth.buzz^$all ||ytsiw.ewoverth.buzz^$all ||aqxzv.ewoverth.buzz^$all ||akawl.ewoverth.buzz^$all ||pvrqg.ewoverth.buzz^$all ||oyffo.ewoverth.buzz^$all ||woorz.ewoverth.buzz^$all ||whqqm.ewoverth.buzz^$all ||apgib.ewoverth.buzz^$all ||bsrhu.ewoverth.buzz^$all ||lipwq.ewoverth.buzz^$all ||yzivj.ewoverth.buzz^$all ||cgwvb.ewoverth.buzz^$all ||zijim.ewoverth.buzz^$all ||fvpki.ewoverth.buzz^$all ||deqkr.ewoverth.buzz^$all ||qtngs.ewoverth.buzz^$all ||jgdvx.ewoverth.buzz^$all ||vovle.ewoverth.buzz^$all ||oqcqa.ewoverth.buzz^$all ||nruzo.ewoverth.buzz^$all ||cnwlv.ewoverth.buzz^$all ||waneo.ewoverth.buzz^$all ||fmrdm.ewoverth.buzz^$all ||pzktf.ewoverth.buzz^$all ||uivzc.ewoverth.buzz^$all ! look-alike domains on the same IP, some with AV detections ||sweredth.buzz^$document ||reamsan.buzz^$document ||ecityalittl.buzz^$document ||toftheussi.xyz^$document ||sfriend.buzz^$document ||ewallowi.buzz^$document ! trys to install extension ||antivirushub.co^$all ! https://forums.malwarebytes.com/topic/288114-website-blocked-due-to-riskware-wmail-endpointcom-and-wmail-chatcom/ ! https://www.virustotal.com/gui/url/081c3fe5d843567d0b5a1f7b2efd6592eded82d8a6b0a4283760c53b06b9d009/community ||coinbase-buysell-cryptocurrency.yolasite.com^$all ! https://www.virustotal.com/gui/url/61f80679df71801784f03035adbd921e1a1d8e71791d2aa6e66cb01cfd7456a7/community ||636419.selcdn.ru^$all ! https://www.virustotal.com/gui/file/b7a7b969380d611b8f21f457e3d56b472cd4634fc11b016c0f5e70a15ddd2363/community ||wearenotbbystealer.nl^$document ! https://www.virustotal.com/gui/url/88c6f47ec835274fa193c5540a570dc53421fcfdc5d0408f8a8215ff9ec561bf/community ||share.getcloudapp.com/nOuXRll9^$all ||nolajaymesrealtor.com^$all ! https://www.virustotal.com/gui/url/30f2e387b6958c9c68c50ad7b36c9ff8718d73b16b4bb6530930aa6407948dd7/community ||211.141.32.89^$all ! https://bazaar.abuse.ch/sample/77c945c874a9eec07cba31323fb7dd074c22f61ca1d2c7c27c768097fe237a41/ ! https://app.any.run/tasks/811d0de5-e707-4f2d-92ae-e988a5a94832/ ! https://bazaar.abuse.ch/sample/97143ab8ca0ca0b8ff80aecb1b46ab09ee8160e8cea45ff6a6d81b4dcb028284/ ! https://www.virustotal.com/gui/url/2d025728fa1d0b8f3ac26cd87c542d86d674215cb5fc12d8d9cefa57159686c8/community ! https://www.virustotal.com/gui/url/0f08c044228d8d5cf50356deeadea492d78fd691735df5438f118c52a622267b/community ||planebux.xyz^$all ! someone shared this SMS with me --> https://twitter.com/iam_py_test/status/1545164642346930176 ||amazon-security-info.lnk.to^$all ! https://bazaar.abuse.ch/sample/b41a79633a38811e378ce4e3e05cbaf086791272ae55c87eafa845eb655994a9/ ||telegra.ph/Best-tutorial-04-30^$all ||gg.gg/11nfvn^$all ||mediafire.com/file/iqamfvx8teaq9y2/SoftwareInstaller.rar/file^$all ||download2262.mediafire.com/vuiwp8s6onyg/iqamfvx8teaq9y2/SoftwareInstaller.rar^$all ||77.91.102.23^$all ! https://bazaar.abuse.ch/sample/5c795e31f7130c2c15ed1fbcb300bea7266f64e10f68cfc9a2f139f2a25a9532/ ||crackload.net^$all ! https://www.virustotal.com/gui/url/b57caaf8abc72075c0e194177af30ec2059f57ed944d23adc2e1f925bb9b4880/community ||pegaz-paragliding.com^$all ! https://www.virustotal.com/gui/url/0d0c7e807f82b3c75bb11ecf6add5a274ffaf66586374744b69021a791c057c9/community ! http://vxvault.net/ViriFiche.php?ID=44491 ! https://app.any.run/tasks/aace491d-fd35-4e27-93e0-fbec758db2e4 ||185.17.0.52^$all ||teamfighttacticstools.info^$all ||authymysexy.info^$all ||nftmatrixed.info^$all ! https://forums.malwarebytes.com/topic/288338-trojan-and-hacktoolagents-detected-installed-and-ran-pre-initial-scan/ ||109.201.133.100^$all ||81.17.18.58^$all ||199.58.81.140^$all ! https://www.virustotal.com/gui/url/a927a3bd0b3c6e016e29bf31d4d217977e2d41bb87fc555eb92f96ecab62e7f7/community ||jinjarsoft.com^$all ! https://forums.malwarebytes.com/topic/288670-im-getting-website-blocked-due-to-trojan/ ||clayroot2016.linkpc.net^$all ! https://twitter.com/stephenlacy/status/1554697077430505473 shared by HoJeong Go ||ovz1.j19544519.pr46m.vps.myjino.ru^$all ! https://www.virustotal.com/gui/file/36d0988bbecc52a81edde05ecf40562ce878dcf4eb273691a134f825bbc16f34/detection ||telegra.ph/INSTALLER-07-22-2^$all ||bit.ly/3b39wkA^$all ||mediafire.com/file/b0shvy4kbs26yro/Installer.rar/file^$all ||download2280.mediafire.com/m6lgxju62ysg/b0shvy4kbs26yro/Installer.rar^$all ! https://www.virustotal.com/gui/file/bf7050e71da2ed976d1298a9732c78aeba04db079848da295b4ed0ec0cac4e35/community ||telegra.ph/autotune-pro-07-16^$all ||telegra.ph/file/b98cb101d9b7798329580.jpg^$all ! https://www.virustotal.com/gui/file/de78cb6a65184a6011d7dee1dc1e48a60d936208718448158f656919c29856e4 ||bit.ly/3PzDpaL^$all ||mediafire.com/file/r4fodu1r8tk0f5s/spotify_premium.rar/file^$all ||download1505.mediafire.com/ias1d2g3ou8g/r4fodu1r8tk0f5s/spotify+premium.rar^$all ! https://www.virustotal.com/gui/file/f776b6341455d570e098f76b6ca38c4e6c47603070d367885d45619795f6fe17 ||robloxscript.site^$all ! https://www.virustotal.com/gui/file/601e3b16384fcfc7fc27b76f9367316fa38681b402d62569b963490496f9f17f ||youtube.com/watch?v=_URFTXX2EEU^$all ||software-universe-pro.space^$all ||drive.google.com/uc?export=download&confirm=no_antivirus&id=1gdvS1_qYnp--dM2DPtNC3IWQr48rJjre^$all ! https://bazaar.abuse.ch/sample/6198d6e4a7def1d5b431b708a3700c24f7a9a955ab9b02040bfda4ebc3bb85be/ ! https://forums.malwarebytes.com/topic/289086-antivirus-keeps-telling-me-blocked-3523615979-and-cant-find-a-solution/ ! https://forums.malwarebytes.com/topic/289935-hijackautoconfigurlprxysvrrst-backdoorfarfli-in-registre-key/ ||35.236.159.79^$all ! https://bazaar.abuse.ch/sample/78bcb53e3e0bca3655038c80eb9339d94f4a52b614b2ae072c171925099bcca8/ ! https://www.virustotal.com/gui/file/6679a9fafa55cd95f682e35649413de7d36e81d7eb77736f888d98e5ac4ccf91 ||youtube.com/watch?v=fErPw95RDkI^$all ||telegra.ph/Download-Page-07-30^$all ||qaz.su/load/inFFaH/de367fba-5307-479f-b71f-eeee1cfc3773^$all ||qaz.su^$document ! same malware? ||youtube.com/watch?v=eKdHoJvn5j8^$document ||youtube.com/watch?v=uNToj-my3GA^$document ||youtube.com/watch?v=IFNExRloGAo^$document ||youtube.com/watch?v=2Vn-wy5JvoM^$document ||youtube.com/watch?v=w5GuyJ_0cmU^$document ||youtube.com/watch?v=rwXWuqlPOlQ^$document ||youtube.com/watch?v=bIqLd3AS-X8^$document ||youtube.com/watch?v=3f6rXl88SG0^$document ||youtube.com/watch?v=h3qvNANawP8^$document ||youtube.com/watch?v=5bj8-1BkS4w^$document ||youtube.com/watch?v=F7Qej71_D34^$document ||youtube.com/watch?v=a2khWhRVy50^$document ||youtube.com/watch?v=Qzjw_iXe4OI^$document ||youtube.com/watch?v=KqWmJDT2tF8^$document ||youtube.com/watch?v=F7820k-PkPE^$document ||youtube.com/watch?v=PXiOuBY-S5s^$document ||youtube.com/watch?v=MmviHBRiyJ0^$document ||youtube.com/watch?v=gi6TCY2UqNA^$document ||youtube.com/watch?v=-VdRb6Sn5PA^$document ||bit.ly/2THQIfs^$document ||greponozy.com/1Gcf^$document ||youtube.com/watch?v=PHGc5qm1zkg^$document ||youtube.com/watch?v=qbQYXGEMsfM^$document ||youtube.com/watch?v=bdIBX4L-VCY^$document ||youtube.com/watch?v=w_yKAcScwcI^$document ||youtube.com/watch?v=wbyl2uDabk0^$document ||youtube.com/watch?v=vOgKYV9MOw4^$document ||youtube.com/watch?v=mj7Gljnb8ac^$document ||youtube.com/watch?v=Yfqtm1VoKKs^$document ||youtube.com/watch?v=XGwoTmg2b48^$document ||youtube.com/watch?v=heaz5Fz4EKI^$document ||youtube.com/watch?v=q-g7wMLHuN4^$document ||youtube.com/watch?v=sfYOxmJiOgM^$document ||youtube.com/watch?v=pT-StSpmNok^$document ||youtube.com/watch?v=3BkvamYPEe8^$document ||youtube.com/watch?v=9KomJDPKiUs^$document ||youtube.com/watch?v=Pu3LlqSP74o^$document ||gg.gg/11t6jy^$document ||youtube.com/watch?v=tV1OUdnO_n4^$document ||youtube.com/watch?v=9Kvk9h0q3qg^$document ||youtube.com/watch?v=GsfT47e6Ozw^$document ||youtube.com/watch?v=zzC0HBVy1I4^$document ||youtube.com/watch?v=ZnNg7ORZfI4^$document ||youtube.com/watch?v=O49zoBE_PzU^$document ||youtube.com/watch?v=rk9MB-sVNl4^$document ||youtube.com/watch?v=UlUH2m09y2s^$document ||youtube.com/watch?v=Nh_kgoNrDvk^$document ||youtube.com/watch?v=yXkLUdZK_fs^$document ||youtube.com/watch?v=LNrhLKvmK-Y^$document ||youtube.com/watch?v=QlLYrBvJP0E^$document ||youtube.com/watch?v=NpBkk3rmdWY^$document ||youtube.com/watch?v=z6v1E0hapQI^$document ||youtube.com/watch?v=o0SM-fup_Kg^$document ||youtube.com/watch?v=8N8KhQkZEHM^$document ||youtube.com/watch?v=yGQDtZg7T4w^$document ||youtube.com/watch?v=09K3EZiH37A^$document ||underthfeoveu.monster^$all ||rummaringp.pics^$all ||ndandinter.hair^$all ! https://forums.malwarebytes.com/topic/289257-browser-randomly-tries-to-go-to-iluhruhruxyz/ ||iluhruhru.xyz^$all ! https://www.virustotal.com/gui/url/277ab53e753d552ec350aa812bc94345c84346ce52ca03f89979bfbe9a1ae000/community ||rb.gy/itouxx^$all ||es-sign-caieyna-b65164.ingress-florina.ewp.live^$all ! https://forums.malwarebytes.com/topic/289254-reoccuring-website-blocked-due-to-malwaretrojan-message/ ||104.155.207.188^$all ! https://forums.malwarebytes.com/topic/289146-contrapersescom-malware-popups/ ! https://forums.malwarebytes.com/topic/289555-malwarebytes-reporting-riskware-and-trojan-through-powershell-every-second/ ||45.227.254.52^$document ! https://www.virustotal.com/gui/url/8cf70fad0ee6a511ce4133266b02530a09f7f9bee7e5f1acfe2bc17c70fc0abe/community ! https://twitter.com/_JohnHammond/status/1564246090748141568 ||cdn.discordapp.com/attachments/601028724606894082/1013911373635399722/CopyrightReport.zip^$all ||65.21.195.97^$document ! https://bazaar.abuse.ch/sample/7d6ed961c659e4f884e8c61d5b837ae70828bb42f51675d6cd82bba9518442a7/ ! https://bazaar.abuse.ch/sample/370262db05f130a4cf76ac1eebbe8fd8d491abcc89fd38d2eba31d1a31d5e682/ ! https://twitter.com/malwrhunterteam/status/1565435960380243968 ||ibkrs.xyz^$all ! https://twitter.com/MBThreatIntel/status/1567604533458780160 ||hgoawa.xyz^$all ||31.44.6.123^$all ! https://www.virustotal.com/gui/url/2902824978b57daf56f9ff1070505f51d7fc2bbaaa3a1b7563b292a165cfa109/community ||rhtfssepgommildccml-z-twqhtkngaebshqnhtr-ubbwnnkispstinlnwps.glitch.me^$all ! https://www.virustotal.com/gui/url/d40409e8995dd91b3ab6c154cfa84a94c3a11013262825a88861d1611d9212c8/community <-- Dead ! https://www.virustotal.com/gui/url/52b396fc9afd28864a7c7ac91faaef4be1f001b2aa45a33ad53e0f38172fa4e3/community ||tegraokulary.pl^$all ! https://www.virustotal.com/gui/url/0e4d19822cdbcd996b5802814de71856b9c957517bf3e56a634d2e85bd03e8f5/community ||142.93.141.182^$all ! https://www.virustotal.com/gui/url/ede9ff1400c40a55acb7f9d543fc41f27f69cdf385b350330dea3631bfd67e99/community ! https://www.virustotal.com/gui/url/548de04f92a9ebfb18f55ba7717c3a23963f69d0ac1eb70af7d68f783ce41352/community ! https://forums.malwarebytes.com/topic/289986-what-is-plusclick/ ||plusclick.biz^$all ! https://www.virustotal.com/gui/url/d4c898d706383367e90f7dabe340b63ab5a3245834bfea5417406f5d16d9a1e2/community ||216.189.145.246^$document ! https://www.virustotal.com/gui/url/16134b536ddf476faedd91fe7f5f92ffefe8a9645755c33188647839fe2609cc/community ||clck.ru/sdToA^$all ! https://bazaar.abuse.ch/sample/60d3fbde28010f86727b2e42f463b32cbd734b16e07f1173ee8c8f9875bcacdb/ ! https://www.virustotal.com/gui/file/60d3fbde28010f86727b2e42f463b32cbd734b16e07f1173ee8c8f9875bcacdb/relations ! https://www.virustotal.com/gui/file/fe3f662947b072546eea1183ff626e851cb99a50a406dbe28a520078f38a84df ||youtube.com/watch?v=-dQbwMVfdP4^$all ||telegra.ph/Download-09-07-6^$all ! https://www.virustotal.com/gui/file/31172f3d213210267adccd9e625a15f9713006812a3e20538425fba996e8889a ||youtube.com/watch?v=WX1owA1dV5o^$all ||mediafire.com/file/kvp9izio4r4hqly/Roblox+Hack.zip/file^$all ||download2296.mediafire.com/2puo0ie3zvug/kvp9izio4r4hqly/Roblox+Hack.zip^$all ! https://www.virustotal.com/gui/file/85ace27ad92cbb5920913a63f34e02b4dc9191271ad35bc3ae9c902a4fb4bca2 ||youtube.com/watch?v=FFwti_C7ACQ^$all ||transfer.sh/get/4vJ531/softwareforwork.zip^$all ! https://bazaar.abuse.ch/sample/a674c8d984fe21bdbf03a9cafabe8963f0b471155655943299ef9695b836c307/ ||youtube.com/watch?v=yJtuUa7USYY^$all ||telegra.ph/Clip-Studio-Crack-Latest-Version-08-15^$all ! https://www.virustotal.com/gui/url/8324e6a0342d39a24016ca08380cbcce2c0df5ebcf5046b84bbd31dba08ebb66/community ! https://www.virustotal.com/gui/file/15da28c047f5f39733db61c779a6ebc3ee3e9beb82d01f4f65f1c5254d023cc8/community ||cdn.discordapp.com/attachments/1016433329790267502/1016803033897775174/Quiet_Forest.zip^$all ! https://twitter.com/MBThreatIntel/status/1571949584943054848 ! https://blog.sucuri.net/2022/06/analysis-massive-ndsw-ndsx-malware-campaign.html <-- old, maybe dead? ! https://www.virustotal.com/gui/url/4232ca1e457512771eeb058dce5e6acf2f0cb5b3259743cda8048cad110e4a42/community ! https://www.virustotal.com/gui/url/94532535b8591efdebf95cf3c463f4b6116c76a354320676d38ab1384d40d26f/community ||sukudoanalytica.com^$all ! https://twitter.com/UK_Daniel_Card/status/1573038624853082128 ! https://twitter.com/MBThreatIntel/status/1571949584943054848 ||parrable.com^$all ||h.parrable.com^$all ! https://twitter.com/MBThreatIntel/status/1573059941619081221 ||guyacave.fr/js/tiny_mce/themes/modern/validate.js^$all ! https://twitter.com/iam_py_test/status/1573078196010078210 ||youtube.com/watch?v=3ccLmu7BeWI^$all ||telegra.ph/An-article-on-How-To-Download-Crack-and-Hack-For-Free-08-12^$all ! https://bazaar.abuse.ch/sample/7205488fe5a1d3d05f0734af8b156d5c1603e9334b407845eb5545950e7b9acc/ (credit to https://bazaar.abuse.ch/user/1169961/) ! https://app.any.run/tasks/ed58332c-913b-4a8e-8d17-e55c4fb40b76 (my analysis) ||85.31.46.80^$document ||85.31.46.80/VVK.exe^$all ! Download URL taken down ||youtube.com/watch?v=nH-b_glNQnc^$all ! https://www.virustotal.com/gui/url/dff608d10ce1c5d441e7d3d9e848d81302e26dcce121f984f2d1c2e341852a82/community ||medijaplus.com/wp-admin/network/ATOPSpA/^$all ! https://twitter.com/iam_py_test/status/1576210230119403520 ! https://twitter.com/MBThreatIntel/status/1577039325157822464 ! https://forums.malwarebytes.com/topic/290797-drive-by-typosquat/ ||login.mimecast.cm^$document ! https://www.virustotal.com/gui/file/d04f8915ee7e77951a370e770826926ba1667eab0c3a976152d29c0a6585e439/detection ||mega.nz/file/hWN0gQoQ#jRjxLrh0v0P4ru1KkA83PMHn7Pco3quhO91JHS_1Z90^$all ! https://twitter.com/iam_py_test/status/1578112473768644611 ||youtube.com/watch?v=uf5KSftY9Xc^$all ||pastebin.com/DyG0qkdA^$document ||bit.ly/3EhFS7k^$document ! new ||bit.ly/3W5iqkk^$all ||mediafire.com/file/48babb7qlspz6dd/Adobe+Photoshop.rar/file^$all ||download1647.mediafire.com/m4jyxojvtz9g/48babb7qlspz6dd/Adobe+Photoshop.rar^$all ! https://forums.malwarebytes.com/topic/290918-blocking-trojans-from-sites-i-didnt-visit-persistant/ ! https://app.any.run/tasks/5a5e6346-9bd1-4afe-8190-956ea289e735# ! https://www.virustotal.com/gui/file/ccb4ef3fffb4661e7cdb4570fdfcac6a5e6701d6ee3602bbc0e1b5e5955951fc/detection ||5.161.120.43^$all ! https://twitter.com/malwrhunterteam/status/1579793270959636480 ||micrsoft-covid-19-login.web.app^$all ! https://forums.malwarebytes.com/topic/291124-annouing-message-every-30-sec-potential-threat-blocked-plz-help/ (and many others) ||34.80.59.191^$all ! https://twitter.com/GossiTheDog/status/1582690317886578688 ||www.garmin-download.com^$all ||garmin-download.com^$all ! https://www.virustotal.com/gui/url/d56c2ac37804bb6016c6666697b34ed0e95ad1a36ca2bd8b9db78c1e13f8ae81/community ||objectstorage.us-sanjose-1.oraclecloud.com^$all ! https://www.virustotal.com/gui/url/cf647bc81b76bd4857b34fe9a6dbec1f695b3bb8910e8cd000fa16e48d8c0c4c/community ||cgi-wscalfahostingde.bondlayer.site^$all ||i4rry-tiaaa-aaaag-aaycq-cai.ic0.app^$all ! https://twitter.com/iam_py_test/status/1584189355559907335 ||104.168.44.52^$all ! https://github.com/VernonStow/Filterlist/commit/cb04d77547497a1cd211d2eac20f8af10de01a76 (all credit to https://github.com/VernonStow for finding these domains) ! https://app.any.run/tasks/f204948b-3940-41d2-af50-b3db789d4ac3 ! https://www.virustotal.com/gui/file/e34575d69ee7a2c0231982d4c2e47edc9adbf7c9290caedd69ad7598a2ae759c (with junk data deleted) ! same file ! https://twitter.com/l205306/status/1584804864013479936 ! https://twitter.com/JAMESWT_MHT/status/1584811225720164357 ||45.15.156.81^$all ||79.137.202.36^$all ! https://www.virustotal.com/gui/url/76875c981cc7ea6120260fd9c77b5edbc4ea14cc1077b6eb8fbc834b7de62a44/community ! https://forums.malwarebytes.com/topic/291507-i-keep-getting-rtp-detection-and-trojan-blocked-website-notifications/ (todo: retest soon) ! https://www.virustotal.com/gui/url/795ab548c024258eab569f7f55e968c0ad8bad8e08de3b4ef464983ce1f14899?nocache=1 ! https://www.abuseipdb.com/check/59.153.18.93 ! https://otx.alienvault.com/indicator/ip/59.153.18.93 ||59.153.18.93^$document ! https://www.virustotal.com/gui/url/9f3a622814b880fd165ab0771d30d1099929c9c107a485ff5ac8670eaae12fa8 ! https://www.abuseipdb.com/check/197.230.46.202 ! https://otx.alienvault.com/indicator/ip/197.230.46.202 ||197.230.46.202^$all ! https://bazaar.abuse.ch/sample/9d5e04f46fc4e4340b2d4c5f2044584826e016347388ec35cc9805d36c7546f1/ ||bitbucket.org/nobodoimportante/diniasndiasnid/raw/f9296891a4af851f86f26f100be89a44da6958f3/limm.exe^$all ||bitbucket.org/nobodoimportante/diniasndiasnid/raw/f9296891a4af851f86f26f100be89a44da6958f3/route.exe^$all ||95.214.53.31^$document ! https://tria.ge/221104-xnqwhsbhfp/behavioral1 ||clipper.guru^$all ! https://forums.malwarebytes.com/topic/291771-facebook-hacked-and-suspicious-link-sent-out/ ||monkey.redirectmaster.com^$all ||xe2w.com^$all ! https://www.virustotal.com/gui/url/dd3ef709e1415894e7b12f3245e91fb3993b197b34e854a2bf58d5e4ff1a8768/community ||flyrine.com^$all ! https://www.virustotal.com/gui/url/6a1435a75c9199af6c37df495fb6b05965e57ada5b617e0651efa13e51ae746b/community ! https://www.virustotal.com/gui/url/8425e5c13e3c0ee58fc0ed21cd3695ad4ef1962a32d90f2b3d34cc280e0c248b?nocache=1 ||chungwoo.futuroinfo.co.kr^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/134355 ||2c236979-b1bb-4c7a-915c-df74dbad0d8c.s3.ap-northeast-2.amazonaws.com^$all ! https://github.com/DandelionSprout/adfilt/commit/32ea69e5a7c632bc2cd739fba4ee256e8a9e8abf (all credit to https://github.com/DandelionSprout) ||1000girl.com^$all ||1000islandsinfo.com^$all ||100blackmenkc.org^$all ||10co.biz^$all ||10woomul.com^$all ||141angel.com^$all ||168av.com^$all ||1800fdlowers.com^$all ||1800fl9owers.com^$all ||1800flowerx.com^$all ||1800tlowers.com^$all ||2d-plus.com^$all ||2m5f.com^$all ||30mercantil.com^$all ||3mvs.com^$all ||4hu59.com^$all ||99bricks.com^$all ||ab-automobile.de^$all ||abc13news.com^$all ||abcyamath.com^$all ||aboutarc.com^$all ||abuhamzahfx.com^$all ||abwkoeln.de^$all ||biosaude.co^$all ||accessdiscounts.com^$all ||accountingservice.com^$all ||accountionline.com^$all ||acethematch.com^$all ||additude.org^$all ||addyourlink.net^$all ||adminbookings.com^$all ||admindiploma.co.uk^$all ||admiralmarket.com^$all ||adriod.com^$all ||advancaauto.com^$all ||aegiscrew.com^$all ||aerepostal.com^$all ||aergerforum.de^$all ||aetnaretriedhealth.com^$all ||aetnastudentehalth.com^$all ||aetnasyudenthealth.com^$all ||afshagemstone.com^$all ||aging.realmadridlive.in^$all ||air-careductcleaning.com^$all ||aj3000.org^$all ||ajmsewing.co.uk^$all ||akintor.com^$all ||alabamamedicaid.org^$all ||alamoinsurancegroup.com^$all ||allsttae.com^$all ||alojamientogratuito.info^$all ||altesino.com^$all ||alumacarsuncity.com^$all ||alvincommunitycollege.com^$all ||amazonaus.com^$all ||amcestey.com^$all ||amecstry.com^$all ||americameagle.com^$all ||americanghostsandhauntings.com^$all ||americanlegion.net^$all ||americanwingsnorcross.com^$all ||amienmelody.com^$all ||ammica.com^$all ||anabolicalternative.com^$all ||anactor.net^$all ||anandasoftbd.com^$all ||anccestary.com^$all ||anchormotor.com^$all ||androiddp1.com^$all ||andyreinold.com^$all ||angrydl.com^$all ||anheiserbusch.com^$all ||animerunkkari.net^$all ||anningten.de^$all ||antennebayer.de^$all ||antiqueforhire.com^$all ||childrenwish.ca^$all ||anuex.com^$all ||anugrahjaya.com^$all ||aouttrader.com^$all ||appdeploy.de^$all ||appe.indainbank.in^$all ||applebees.cm^$all ||appleidpassword.com^$all ||appleisider.com^$all ||appolloprism.com^$all ||apppleseeds.com^$all ||appschoolgrid.co.uk^$all ||apqconstruction.com^$all ||apv-thermotech.de^$all ||arcanedevice.com^$all ||areopostel.com^$all ||ari-model.com^$all ||arielaudio.com^$all ||aristokraftcabinets.com^$all ||arizonadollandtoymuseum.com^$all ||arnoldmartinezgallery.com^$all ||artdesignweb.com^$all ||artediez.com^$all ||artofconway.com^$all ||asicsrunningshoe.com^$all ||askalligence.com^$all ||asperdental.com^$all ||aspspider.info^$all ||atlassion.net^$all ||aturealbum.com^$all ||audble.co.uk^$all ||audiopoisk.com^$all ||audioquartet.com^$all ||auitotrader.com^$all ||australien-embassy.de^$all ||autobk.com^$all ||babajfinserv.in^$all ||autopartsguru.com^$all ||autoscvout24.de^$all ||avanteboatsales.co.uk^$all ||avg.cm^$all ||avipreview.com^$all ||awardsdecals.com^$all ||awardswlwct.com^$all ||b5o.com^$all ||ba.upyim.co^$all ||baadhuset.com^$all ||babybud.de^$all ||bagandbow.com^$all ||baileycar.com^$all ||bananajacks.com^$all ||banankofamerica.com^$all ||bankencryption.com^$all ||barrellab.com^$all ||barrettsoutdoor.co.uk^$all ||basicware.com^$all ||bathandbodywash.com^$all ||bbletche.com^$all ||bcbsillinois.com^$all ||bccstx.com^$all ||bcins.com^$all ||beachsideboatrentals.com^$all ||beardmiller.com^$all ||beatthestreak.com^$all ||bedbedandbeyond.com^$all ||befancyhair.com^$all ||beilgries.de^$all ||bejaminbluemchen.de^$all ||benifits.org^$all ||bernslaihomes.co.uk^$all ||berwww.com^$all ||bestamericanstocks.com^$all ||bestcanadian.com^$all ||besthesda.net^$all ||bestwestner.com^$all ||bext.co.uk^$all ||bherb.com^$all ||bhojpurimovie.com^$all ||biblioteka-bg.com^$all ||bilabong.de^$all ||biosmoothpro.com^$all ||biovidasaude.com^$all ||birdscapes.com^$all ||bitsize.com^$all ||bittrex.cm^$all ||blackedram.com^$all ||blackmendigital.com^$all ||blauer-engel-koeln.de^$all ||blissmassagetherapy.com^$all ||blogesupri.patons.ca^$all ||blogs-pot.com^$all ||blurau.com^$all ||bmwsarasota.com^$all ||bnbcnews.com^$all ||boating-ed.com^$all ||bobberslive.com^$all ||bobybuilder.com^$all ||bokkinmg.com^$all ||bolivianland.net^$all ||boobking.cm^$all ||boohoi.com^$all ||bookfromnet.com^$all ||booking.pixelextended.me^$all ||booksandmarks.com^$all ||boostbobile.com^$all ||bootrep.com^$all ||boottownusa.com^$all ||bootyplanet.com^$all ||bossmovies.com^$all ||bostonterrierden.com^$all ||bothers.com^$all ||bottlecapgames.com^$all ||boxmoviez.com^$all ||boy-drive.net^$all ||bppkoing.com^$all ||braillealphabet.org^$all ||brainlly.com^$all ||brigdebase.com^$all ||briteledtech.com^$all ||brosdway.com^$all ||brotherprinter.com^$all ||bsswift.com^$all ||bt666.com^$all ||burnsidedigital.com^$all ||bwmbank.de^$all ||bzp.net^$all ||cabesp.com^$all ||calebpressley.com^$all ||calvertschool.com^$all ||cambridgeebook.com^$all ||cannel24.de^$all ||cantireu.ca^$all ||captialonedirect.com^$all ||carapowersports.com^$all ||carecredet.com^$all ||carnart.com^$all ||carolinatrustfederalcreditunion.com^$all ||carthorsemachinery.com^$all ||cartridgesshop.co.uk^$all ||casinovale77.com^$all ||casualxl.com^$all ||catharijnebioscoop.nl^$all ||cbej.com^$all ||cdlebjihad.com^$all ||cellutissue.com^$all ||centerblog.com^$all ||centerhillhouseboatrentalandcharter.com^$all ||cercoamicivip.com^$all ||charlestywritt.com^$all ||chartoulette.com^$all ||chasefreedomvisa.com^$all ||chasschwab.com^$all ||chathopper.com^$all ||chaumiereonline.com^$all ||cheapnikeshoes.com^$all ||chefsouls.com^$all ||chengsgardenct.com^$all ||childrencare.com^$all ||chinaautoparts.com^$all ||chlipfih.de^$all ||choctawwildlife.com^$all ||choicepriveleges.ca^$all ||choigame24h.net^$all ||christianbooksummaries.com^$all ||christiansocialnetwork.net^$all ||chuckychesse.com^$all ||cicda.com^$all ||cinemavf.org^$all ||citimortgage.cm^$all ||clarin.cm^$all ||clarires.com^$all ||claritta.net^$all ||clashofclanhacks.com^$all ||classmatess.com^$all ||clerverbot.com^$all ||clikurl.com^$all ||cloudbar.org^$all ||cloudmail.ontatio.ca^$all ||clubemusicas.com^$all ||clubterracan.net^$all ||cogeca.ca^$all ||collectioncentre.com^$all ||collegeoftheozarks.com^$all ||colonnialpenn.com^$all ||colordrives.com^$all ||columbusstoreeq.com^$all ||comcmast.net^$all ||comicstee.com^$all ||comkp.org^$all ||commomlit.com^$all ||comstaples.com^$all ||confusion.co.uk^$all ||consunercellular.com^$all ||continentalcredito.com^$all ||convertapdftoword.com^$all ||cookiecliker.com^$all ||coolgearing.com^$all ||correo.foot-news.co^$all ||costcobusinessphone.com^$all ||cottagechicbymargie.com^$all ||cottonflower.com^$all ||countrybros.com^$all ||countrylifegifts.com^$all ||courtreporting.com^$all ||covermania.com^$all ||covid-10.onario.ca^$all ||cps-pc.de^$all ||crackact.org^$all ||craigsdlist.com^$all ||crazynudistbeach.com^$all ||creativemindsacademyfl.com^$all ||credditonebank.com^$all ||cricket.info^$all ||crowddream.com^$all ||cruiseadventures.com^$all ||crystaldiskinfo.com^$all ||crystallinks.com^$all ||cstress.net^$all ||cumonlucy.co.uk^$all ||cumsex.com^$all ||cumsnap.com^$all ||cursodeunhasdecoradas.com^$all ||cvs.cm^$all ||cvshealthsurcey.com^$all ||cyberhostvpn.com^$all ||d25.net^$all ||dafearsoft.org^$all ||daftzex.com^$all ||dailynation.co.uk^$all ||dakofurniture.co.uk^$all ||damagedpictures.com^$all ||datingwall.com^$all ||davesandbusters.com^$all ||davidaustinroses.de^$all ||davidsonfirealarms.com^$all ||davinailsandspa.com^$all ||dealaday.com^$all ||debain.org^$all ||debide.com^$all ||defloreation.com^$all ||degowo.de^$all ||dekstophut.com^$all ||demo.europadonna.de^$all ||demo.halimcan.de^$all ||dentistfinder.com^$all ||desicorner.net^$all ||destokage.com^$all ||detailreviews.com^$all ||detroitk12.com^$all ||detroitlion.com^$all ||deutschewell.de^$all ||europadonna.de^$all ||gesundheitkatalog.de^$all ||hanseatischesweinkontor.de^$all ||hbo.cm^$all ||hypoverensbank.de^$all ||academicassociation.in^$all ||deviantaet.com^$all ||dgumarket.com^$all ||dhifaaf.com^$all ||dibujosdelos80.com^$all ||dicoverycove.com^$all ||dictionarg.com^$all ||dieaertze.de^$all ||diebahnd.de^$all ||diesimsens.de^$all ||digitaldigsads.com^$all ||dippegucker.de^$all ||directnergy.com^$all ||disany.com^$all ||discdb.com^$all ||disconcerting.com^$all ||discountrires.com^$all ||discunttire.com^$all ||disnneychannel.com^$all ||distorwatch.com^$all ||dixks.com^$all ||diycondensermics.com^$all ||djwacho.de^$all ||dkroger.com^$all ||dlv4.com^$all ||com-download-stat.us^$all ||docteach.org^$all ||documany.com^$all ||documentodoestudante.com^$all ||dofant.com^$all ||dolcegabanna.com^$all ||dollarentacar.com^$all ||dollygals.com^$all ||domionspizza.com^$all ||donaldrussel.com^$all ||donvenmuehle.com^$all ||dotcomdirectory.com^$all ||doversaddley.com^$all ||drbbble.com^$all ||drivenmotorsportsales.com^$all ||drocherway.com^$all ||droplox.com^$all ||droptv.com^$all ||drssbarn.com^$all ||ds4you.de^$all ||dsca85.com^$all ||dsneyland.com^$all ||ducusign.com^$all ||durgapurgovtcollege.org^$all ||dutchbilbs.com^$all ||dvrv.com^$all ||dyptiqueparis.com^$all ||dysma.de^$all ||dzlibrary.com^$all ||easternbikes.de^$all ||ebieomachines.com^$all ||ebookbinary.com^$all ||ecentennialcollege.ca^$all ||ecoediciones.com^$all ||ecoinspeed.com^$all ||ecread.com^$all ||edge.metropcs.co^$all ||educacionbc.com^$all ||eduparkpublishinghouse.com^$all ||eevb.com^$all ||efsll.com^$all ||einv.com^$all ||eknigu.org^$all ||elcactus.com^$all ||eletterhead.com^$all ||elevationsj.com^$all ||ellasontreeservice.com^$all ||ellisiland.org^$all ||elreydelfalafel.com^$all ||elwinpure.com^$all ||empak.de^$all ||emperorinfo.com^$all ||emulespana.net^$all ||enbto.com^$all ||energybrokerconsultants.com^$all ||enfmail.com^$all ||engineerbob.com^$all ||enigaluce.com^$all ||enyergy.com^$all ||eoonext.com^$all ||epicgamis.com^$all ||epph.com^$all ||eppicard.cm^$all ||erotic-flowers.com^$all ||erotic99.com^$all ||es-toyaqui.com^$all ||esmallbusinessgrants.net^$all ||esperiqn.com^$all ||estilosashop.com^$all ||esty.com^$all ||esuracnce.com^$all ||eternityflowercreations.com^$all ||ethioporn.com^$all ||ethtrada.com^$all ||etimology.com^$all ||euronets.com^$all ||events.compres.us^$all ||everdaycarry.com^$all ||evil-unveiled.com^$all ||evtools.info^$all ||exberian.com^$all ||excelmission.com^$all ||3daxis.co^$all ||exiperan.com^$all ||experianokta.com^$all ||expertworx.com^$all ||expieeian.com^$all ||explorors.com^$all ||expreien.com^$all ||exragazze.com^$all ||exrpessscripts.com^$all ||eyebuidirect.com^$all ||ezbiodiesel.com^$all ||ezgreatoffers.com^$all ||ezprogram.com^$all ||eztvseries.com^$all ||ezzpassmd.com^$all ||fabswiingers.com^$all ||faceb00k.com^$all ||facialsgalleries.com^$all ||facilisoft.com^$all ||faircompaines.com^$all ||fairplayhorse.com^$all ||fakehab.com^$all ||faketaxi.org^$all ||fashionchurchsuits.com^$all ||fashiondressstore.com^$all ||fashionsnetwork.com^$all ||fasilhd.com^$all ||fastcash500.com^$all ||fastlaneltd.com^$all ||fatbike-motor.com^$all ||fatwa1.com^$all ||faxsports.com^$all ||fcbs-inc.com^$all ||fedbizopps.org^$all ||feixunvpn.com^$all ||fellfootfarm.co.uk^$all ||ferel.com^$all ||fertagus.com^$all ||ffrontgate.com^$all ||fiars.com^$all ||fightmove.co.uk^$all ||filecloud.monster^$all ||filezila.com^$all ||filmfreestream.net^$all ||filmox.org^$all ||findmymobike.com^$all ||findrc.com^$all ||finleyfurst.com^$all ||fionagary.com^$all ||fireking.us^$all ||firhouse.com^$all ||firstnationalc.com^$all ||firstthirdbank.com^$all ||fivestarautomotiverepair.com^$all ||fivethirteight.com^$all ||flagstarwholesale.com^$all ||flightconsolidator.com^$all ||flightlcub.com^$all ||flipkartjob.com^$all ||flipnormals.com^$all ||flixbruns.de^$all ||floormakers.com^$all ||florida-fishingcharters.com^$all ||flowermodels.com^$all ||flugzeugsupermarkt.de^$all ||fluxrp.com^$all ||flygpoolen.com^$all ||fmhogar.com^$all ||fmword.net^$all ||fnsbsd.com^$all ||focusbangla.com^$all ||fodocuments.info^$all ||followx.com^$all ||food-stamps-apply.com^$all ||foosewheels.com^$all ||footballflags.com^$all ||forceporn.com^$all ||foreverybella.com^$all ||forexclient.com^$all ||forexengines.com^$all ||formacioncorreos.com^$all ||formaua.com^$all ||forslaebyowner.com^$all ||forstinger.de^$all ||fotobugil.com^$all ||fotoescalera.com^$all ||fotoporst.de^$all ||foyerjeansturm.com^$all ||fraigslist.com^$all ||franciscajoias.com^$all ||franklhammondiii.com^$all ||frebmd.org.uk^$all ||freddiesfinespirits.com^$all ||free-iphone6s.com^$all ||freeconferenceline.com^$all ||freedomkia.com^$all ||freefre.com^$all ||freelanceeditors.com^$all ||freemovie.com^$all ||freemovies.net^$all ||freemoviesonline.com^$all ||freenortonsecurity.com^$all ||freeplaysex.com^$all ||freeprogz.com^$all ||freeshoutbox.com^$all ||friedmanshoes.com^$all ||friendsinfo.net^$all ||fronteerair.com^$all ||frontgatd.com^$all ||fsuwebmail.com^$all ||ftrontgate.com^$all ||fuckhoes.com^$all ||fudelidade.com^$all ||fullyloadednews.com^$all ||fumformobile.com^$all ||funkysexycool.com^$all ||furnitureking.com^$all ||furukawa-cooking.com^$all ||futaplay.com^$all ||gadisbandung.com^$all ||galerievitesse.com^$all ||gallagherstudents.com^$all ||gallerialighting.com^$all ||gameartisan.com^$all ||gamesloft.com^$all ||garden-flags.com^$all ||garndinroad.com^$all ||gastrodocs.info^$all ||gautengonline.com^$all ||gaylar.com^$all ||gbbox.com^$all ||geacorn.com^$all ||geamail.com^$all ||geapplaince.com^$all ||gedichtsbilder.de^$all ||gemini-usa.com^$all ||gemvera.com^$all ||generadordememes.com^$all ||genwigs.com^$all ||geogiaboot.com^$all ||geometro.com^$all ||geoxkorea.com^$all ||gerardfashion.com^$all ||getchaselnk.com^$all ||getjeeping.com^$all ||getmsguide.com^$all ||getmypopcornnow.com^$all ||getmytranscrpit.com^$all ||gettereward.com^$all ||ggodyear.com^$all ||ghostsearch.com^$all ||gibsonrv.net^$all ||gidonline.net^$all ||giftsforunow.com^$all ||giganits.com^$all ||giphy.cm^$all ||girls-party.com^$all ||glamrockbeauty.com^$all ||glassdoir.com^$all ||glasssoor.com^$all ||glendeedogrescue.co.uk^$all ||globalifeinc.com^$all ||glomp.com^$all ||gmauo.com^$all ||gmboree.com^$all ||gmglobalconnec.com^$all ||gmsexp.com^$all ||gnctraining.com^$all ||gnet7.com^$all ||gnpschandigarh.com^$all ||go-guy.com^$all ||gobdeals.com^$all ||goldclubslot.com^$all ||gomiyashiki-osouji.com^$all ||goodcheat.com^$all ||googglemail.com^$all ||google.ssvt.se^$all ||googlecal.com^$all ||googlefish.com^$all ||googleidle.de^$all ||goole.com.vn^$all ||goopgle.com^$all ||goracertech.com^$all ||goralpolishdeli.com^$all ||gordanfoodservice.com^$all ||got-corgis.com^$all ||gottorent.ca^$all ||graberbkinds.com^$all ||grabetblinds.com^$all ||gracehillision.com^$all ||granddentalpc.com^$all ||grassrootsmeasures.com^$all ||greandhra.com^$all ||greatbulletin.com^$all ||greatlesson.com^$all ||greatrating.com^$all ||greenvaporco.com^$all ||greyhoundbuslines.com^$all ||grillsandgreens.com^$all ||grinandbakeit.com^$all ||grupograncolombia.com^$all ||grupomnemon.com^$all ||gsmatena.com^$all ||gtuts.com^$all ||guicc.com^$all ||gulfmonster.com^$all ||hack-game.net^$all ||halilou.com^$all ||hallsdawghouse.com^$all ||halys.com^$all ||hamburgschool.org^$all ||handrbloock.com^$all ||hangkhung.com^$all ||hao1131.com^$all ||harfordlife.com^$all ||harpers-property.co.uk^$all ||hatventures.net^$all ||haveringfireplaces.co.uk^$all ||hawaiianaor.com^$all ||hboow.com^$all ||hcomicbooks.com^$all ||hd-sex-videos.com^$all ||hdmedicalexams.com^$all ||hdmovi3s.com^$all ||hdsupplsolutions.com^$all ||hdwallpaperslist.com^$all ||hdww.com^$all ||healthtechni.com^$all ||healthypetstore.net^$all ||heaphotels.com^$all ||heathyliving.com^$all ||helixcharter.com^$all ||hellsangelsusa.com^$all ||hensly.com^$all ||hermesairport.com^$all ||hewittresorce.com^$all ||highcash.org^$all ||hillcountrysanmarcos.com^$all ||hiwaytractor.com^$all ||hobbylobby.cm^$all ||hobyto.com^$all ||holidayproperty.com^$all ||holidycheck.at^$all ||hollywoodmoviez.net^$all ||homescapeonline.com^$all ||hongkongsthelens.co.uk^$all ||hoopsuite.com^$all ||hosfordbrothersconcrete.com^$all ||hot-deal.co.uk^$all ||hotelcentr.com^$all ||hotelesdoux.com^$all ||hotelsit.com^$all ||hotnewhiphoo.com^$all ||hotnsil.com^$all ||hottwitterwives.com^$all ||houseofnightseries.co.uk^$all ||howisavedthousands.com^$all ||hpinstankink.co.uk^$all ||hpsupportphonenumber.com^$all ||hqjt.com^$all ||htmail.co.uk^$all ||httpexample.com^$all ||hu0.com^$all ||humaneassocofclarkcounty.com^$all ||humouron.com^$all ||hvanah.com^$all ||hxymall.com^$all ||i80auto.com^$all ||ibuycard.com^$all ||iclovd.com^$all ||ideed.ca^$all ||identtyguard.com^$all ||idlebrsin.com^$all ||idoline.org^$all ||ieltsonlineexam.com^$all ||ifetel.com^$all ||igansupport.org^$all ||iheartmandalas.com^$all ||iidcgwalior.com^$all ||imageshake.de^$all ||importadoravehicular.com^$all ||inchirieriregimhotelier.net^$all ||indonesiaigo.com^$all ||infonavid.com^$all ||infoum.com^$all ||innotech-maschinenbau.de^$all ||inrussia.org^$all ||insectflix.com^$all ||insidewireman.com^$all ||insovenz.de^$all ||inssigniaproducts.com^$all ||instantsteetview.com^$all ||investopidia.com^$all ||inwexcel.com^$all ||iphonedevtools.com^$all ||iraresource.com^$all ||irlanguge.com^$all ||ishifusion.com^$all ||islandbluecoffee.net^$all ||islandsresturants.com^$all ||isseg.com^$all ||issstenet.com^$all ||itcompraenusa.com^$all ||iteachkinder.com^$all ||itunse.com^$all ||izak.com^$all ||jackwolfkins.de^$all ||jacobsfuneralhome.com^$all ||jailbait-gallery.net^$all ||janethepsychic.co.uk^$all ||jaspe.com^$all ||jcpenmey.com^$all ||jcpenneybenefits.com^$all ||jcpenneyey.com^$all ||jd.cm^$all ||jehblue.com^$all ||jeporady.com^$all ||jerrysappliancecenter.com^$all ||jewelpak.com^$all ||jimmygaorestaurant.com^$all ||jimmysfarmtoys.com^$all ||jira.hannoverscheallgemeinezeitung.de^$all ||jkhols.com^$all ||jlibrary.org^$all ||jmxded100.net^$all ||joannamartinewoolfolk.com^$all ||joaobidu.com^$all ||joblana.com^$all ||joovideo.us^$all ||journeykids.com^$all ||jquerylenslider.com^$all ||jspecialjapan.com^$all ||juanselaverde.com^$all ||jumpstar.com^$all ||juzzbunker.com^$all ||karenmillen.se^$all ||kascarpet.net^$all ||kayoutlets.com^$all ||kbshengyi.com^$all ||kelleyservices.com^$all ||keyrug.com^$all ||keysschools.net^$all ||keystonehoops.com^$all ||keywebtracker.com^$all ||keywordadvisetoolplus.com^$all ||kholsrebates.com^$all ||kickoff.cm^$all ||kindfirls.com^$all ||kit-co2.com^$all ||kitchenmusings.com^$all ||kiwihelme.de^$all ||klana.co.uk^$all ||klaser.com^$all ||kobemo.com^$all ||kodiakproduce.com^$all ||koklsfeedback.com^$all ||komunitaspeduliumatdalung.com^$all ||koon.net^$all ||kootra.com^$all ||kpry.com^$all ||krca.net^$all ||kusakabehifuka.com^$all ||kyxc.com^$all ||kzdress.com^$all ||laarsens-basingstoke.co.uk^$all ||laguiadelocio.com^$all ||lahipitaweb.com^$all ||lakecumberlandfishingguide.com^$all ||lakeserenespa.com^$all ||landgirlscookeryschool.co.uk^$all ||landhausmitpfiff.de^$all ||lankantunes.com^$all ||lapels.org^$all ||larka.de^$all ||lasierratiresutah.com^$all ||latexanzug.com^$all ||laubergeduvieuxcrozet.com^$all ||lawh.com^$all ||leakz.net^$all ||leapinginto5thgrade.com^$all ||learn.movibaz.us^$all ||learnpack.co.uk^$all ||legavy.com^$all ||legumeloyalist.com^$all ||leipomokauppa.com^$all ||lepac.com^$all ||lesbiot.com^$all ||lezgame.com^$all ||lianasims2.de^$all ||lifellinescreening.com^$all ||lightyearapp.live^$all ||likoer43.de^$all ||linkbaru.com^$all ||linkdin.ca^$all ||linkgudangcoding.com^$all ||linuxdeal.com^$all ||liqudition.com^$all ||liscensecoach.com^$all ||livescom.com^$all ||livetvonlinefree.com^$all ||livingcomforts.com^$all ||llantaslandin.com^$all ||llivet.com^$all ||loandaministration.com^$all ||login.reserveamerica.co^$all ||loitech.de^$all ||lojabau2mao.com^$all ||lojaodoreal.com^$all ||lorenagostosa.com^$all ||losingface.com^$all ||louisvuitten.com^$all ||louisvuittin.com^$all ||loveherbal.com^$all ||loverscaughtontape.com^$all ||lowcostparceldelivery.com^$all ||lowe4s.com^$all ||lpaodata.net^$all ||lunettesde.com^$all ||lutherancommunitygrace.net^$all ||luxerycard.com^$all ||lyncdiscoverinternal.ualbera.ca^$all ||lynes-shoes.com^$all ||lyodsbank.com^$all ||m2e6.com^$all ||mabcalculo.com^$all ||maderaplasticamx.com^$all ||madereriasaltillo.com^$all ||maestriasinternacionales.org^$all ||magento.expedia.cm^$all ||magento.fanmail2u.de^$all ||magento.gibco.de^$all ||magento.trannydating.nl^$all ||magoosfurniture.com^$all ||mahabaliexpress.com^$all ||makingfreinds.com^$all ||makisushi.net^$all ||malrboro.com^$all ||maluch.com^$all ||mamapho1.com^$all ||manage.polka-dot.co^$all ||mandourpharmacy.com^$all ||maneige.ca^$all ||manheimauto.com^$all ||manitobaparks.ca^$all ||mannakbbq.com^$all ||manoffashion.com^$all ||mantrafilms.com^$all ||manytears.com^$all ||manyvidd.com^$all ||marisaodonto.com^$all ||maritimeway.com^$all ||marketpalce.com^$all ||marketplace.biosaude.co^$all ||marrottvacationclub.com^$all ||maruces.com^$all ||mascy.com^$all ||mathrubhmi.com^$all ||matomefun.net^$all ||mauriciodenassau.com^$all ||maximcolombia.co^$all ||mbenzusa.com^$all ||mbwjk.de^$all ||mcatbui.net^$all ||mceyecenter.com^$all ||mcgraww-hill.com^$all ||mcjrotc.com^$all ||mckinleyspubri.com^$all ||mdtp.us^$all ||meaganslaw.com^$all ||medherb.de^$all ||medialine.org^$all ||mediasenso.com^$all ||mediationcenter.com^$all ||medicinelodgepom.com^$all ||medigov.com^$all ||medschoolhell.com^$all ||meficare.com^$all ||mega-hookup.com^$all ||megacinemaflix.com^$all ||melbourneactingstudio.com^$all ||mellatmobile.com^$all ||meloxicamsideeffects.org^$all ||metalartsinc.com^$all ||meubelmarkt.com^$all ||meuconsorciobb.com^$all ||mic-river.com^$all ||midasbuy.co^$all ||midiuser.net^$all ||mightylayoutboys.com^$all ||migranteducation.com^$all ||mijaliscomexrestaurant.com^$all ||mijntoeslagen.com^$all ||mili010.com^$all ||minecraft2.com^$all ||minicottage.com^$all ||minnesotagoldendoodles.com^$all ||missgided.com^$all ||mitkindernwachsen.de^$all ||mixreqq.com^$all ||mlgn3usa.com^$all ||mmrafricanfashions.com^$all ||mnspeoplesystem.co.uk^$all ||mobileblitz.com^$all ||mobilehacktool.com^$all ||mobilehomepartstore.com^$all ||mobilr.com^$all ||modestogold.com^$all ||modsey.com^$all ||moenygram.com^$all ||mojsng.com^$all ||mollinsburncarsales.co.uk^$all ||momentsoflife.com^$all ||momsrings.com^$all ||monasteriodepoio.com^$all ||monesupermarket.com^$all ||monyorder.com^$all ||mortgae.com^$all ||motogris.com^$all ||motorjacket.com^$all ||motorradcenter.de^$all ||motorradpartner.com^$all ||motosu.de^$all ||mountaincrestapartments.com^$all ||mountviewchandigarh.com^$all ||moviestube10.com^$all ||mp3juicess.biz^$all ||mpcclubcard.com^$all ||mrtravelers.com^$all ||msephora.com^$all ||muisjes.com^$all ||mujerlunabella.net^$all ||muktimap.co.uk^$all ||multipicatoin.com^$all ||multiquality.tech^$all ||multuimap.co.uk^$all ||mundoftp.com^$all ||musicans-place.de^$all ||musleblaze.com^$all ||mutedvods.com^$all ||blackberry.cm^$all ||carfax.cm^$all ||myaarpmwdocare.com^$all ||myancesty.com^$all ||myanthropologie.com^$all ||myapclassroom.com^$all ||mybkexpiernce.com^$all ||mybodysoul.com^$all ||mybooing.com^$all ||mycarrer.com^$all ||mycips.com^$all ||mycreditonecard.com^$all ||mydicksportinggoods.com^$all ||myebookmaster.com^$all ||myeverydayrewards.com^$all ||myfappening.org^$all ||myfinco.com^$all ||myfirstdegree.com^$all ||myftdi.com^$all ||myhbc.com^$all ||myherbelife.com^$all ||myjobsscotland.co.uk^$all ||mykohs.com^$all ||mylacountybenefit.com^$all ||myliferouch.com^$all ||mynait.ca^$all ||myoceanictwc.com^$all ||mypaneras.com^$all ||mypayback.de^$all ||myqnascloud.com^$all ||myscence.com^$all ||mysunywcc.com^$all ||mythaistlouis.com^$all ||mytruidenity.com^$all ||myvglicredential.com^$all ||myvirtualterminal.com^$all ||myvweizon.com^$all ||myxrt.com^$all ||nactar.com^$all ||nados.co.uk^$all ||nahro.com^$all ||nalcbp.com^$all ||nanacalistar.com^$all ||nanitv.com^$all ||nanoxnutriceuticals.com^$all ||naoffroad.com^$all ||napkimcuong.com^$all ||nartube.com^$all ||nationpage.com^$all ||naturebois.com^$all ||navyfereral.org^$all ||nbkonline.com^$all ||ncscu.com^$all ||neckheavy.com^$all ||nedspipeandsteel.com^$all ||nehalembay.com^$all ||nehra.org^$all ||neipets.com^$all ||neopoets.com^$all ||nesecitountrabajo.com^$all ||nesteggtrailers.com^$all ||netflflix.com^$all ||netflifx.com^$all ||networkredundancy.com^$all ||neuropsicologiacordoba.com^$all ||nevadaspca.com^$all ||newkindofmotherhood.com^$all ||nextflex.com^$all ||nflflagfootball.com^$all ||niagaragazette.com^$all ||nichewines.com^$all ||nigerialatestnews.com^$all ||nikene.com^$all ||nissenusa.com^$all ||niuqiu.com^$all ||njtutoriales.net^$all ||noborobo.com^$all ||nodesjs.org^$all ||nomorerobocalls.com^$all ||nooder.com^$all ||northpoleicecreamshop.com^$all ||norto.com^$all ||nortofn.com^$all ||norwoodcadillac.com^$all ||novadevelooment.com^$all ||novorojencek.com^$all ||carmax.cm^$all ||skyteam.cm^$all ||pcmag.cm^$all ||nexxt.cm^$all ||tillys.cm^$all ||nuken.com^$all ||nursingsa.com^$all ||nutricroq.com^$all ||nutriksystem.com^$all ||nylottery.com^$all ||nyulangoners.com^$all ||o-shohousen.com^$all ||o2tvseriea.com^$all ||obesityonline.org^$all ||obobettermann.de^$all ||oceach.org^$all ||octupus-versand.de^$all ||odincoin-ag.com^$all ||odrivers.com^$all ! https://forums.malwarebytes.com/topic/291856-suspicious-apk/ (account required) ! https://www.virustotal.com/gui/file/9ee91462c53498b2e2f59f0beb216bcef53fd28f0d0ec0ca99a0c01b71e4a0b1/detection ! https://www.virustotal.com/gui/url/ca6883e44a103ed205b6225d866719bc51a9301aca937d336dc38610e46c7ea2/community ||58.252.203.71^$all ! https://www.virustotal.com/gui/url/9951de9e42468c39c8bc5b05f67cd6645fb945ab8ed1677607cc32571214c0f3/community (redirects to localhost, maybe geolocked?) ! a "Yahoo" email claiming I will be locked out if I don't "correct my email" ||yahooo-mail-service.webflow.io^$all ! https://app.any.run/tasks/1dafbc8d-84d8-4e42-a96a-fffdc9d644e7/ ||kmspico-official.xyz^$all ! https://forums.malwarebytes.com/topic/292016-keep-getting-outbound-website-blocked-due-to-trojan-cant-find-threats/ ||humman.art^$all ! https://www.fortinet.com/blog/threat-research/new-rapperbot-campaign-ddos-attacks ||185.216.71.149^$all ! I misspelled virtualbox's website, landed here ||virutalbox.org^$all ||get.safety-search.com^$all ||safety-search.com^$document ! https://github.com/uBlockOrigin/uAssets/issues/15650 ! https://app.any.run/tasks/2de64615-6df3-457f-bfb8-3e207b44667c ||ngxqvvpwkumowm.click^$all ||kmmd6i2bg0rs.click^$all ||mega.nz/file/2kIAhSSS#RfpDvKxaabLwA-3WA9Qm7HOsYHQg1_g3oMEykkNrZMY^$all ||mega.nz/file/2kIAhSSS^$document ||116.202.5.101^$all ! https://forums.malwarebytes.com/topic/292218-malwarebytes-says-that-vbcexe-is-a-virus-please-help/ ! https://threatfox.abuse.ch/ioc/840342/ ||193.106.191.160^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/134903 ||znakomy.club^$all ||smartlink.name^$all ! https://forums.malwarebytes.com/topic/292268-phishing-html-download-url/ (account required) ! https://app.any.run/tasks/1758a17e-86da-4472-88c2-bc21dfe25c47 ! https://app.any.run/tasks/2309c8ba-3e9f-41f2-8a5c-f15f7411ac58# ||www.sadeempc.com^$all ||sadeempc.com^$all ||iplogger.org/2AnXe7^$all ||bit.ly/Password-1234-FullSetups^$all ||iplogger.com/Sadeempcfullversins^$all ! https://www.youtube.com/watch?v=xwJJkvIsEJQ ||torrent-protection.com^$all ||downloadfilearea.com^$document ! https://app.any.run/tasks/e5ba6bf3-98ee-46bf-b9ee-406b1bbebe1f ||u8gr576y.cfd^$all ||rotf.lol/BDFG-KZTP-QAYW^$all ||88.198.106.9^$all ! https://app.any.run/tasks/89b3e663-ea70-43fe-89f0-af05c1c9af2e ||95.217.31.208^$all ! https://forums.malwarebytes.com/topic/292452-strange-malwareconnections/ ||ns1usaupload.myphotos.cc^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/135924 ! https://github.com/DandelionSprout/adfilt/commit/31a32bcef8cfef97a6403f308d64c1991c6b4e8b ! credit to https://github.com/DandelionSprout ||abazelfan.com^$all ||abburmyer.com^$all ||abyamaskor.com^$all ||acelacien.com^$all ||adsvids.com^$all ||agaenteitor.com^$all ||ajestigie.com^$all ||almareepom.com^$all ||alspearowa.com^$all ||amexcadrillon.com^$all ||amgardevoirtor.com^$all ||amoddishor.com^$all ||ardsdusknoiron.com^$all ||arrlnk.com^$all ||arswabluchan.com^$all ||arwartortleer.com^$all ||arwhismura.com^$all ||aslaironer.com^$all ||aslaprason.com^$all ||asnoibator.com^$all ||astkyureman.com^$all ||astoecia.com^$all ||atgallader.com^$all ||attrapincha.com^$all ||audmrk.com^$all ||augnolru.com^$all ||ausoafab.net^$all ||bechatotan.com^$all ||belickitungchan.com^$all ||benumelan.com^$all ||beskittyan.com^$all ||betalonflamechan.com^$all ||betimbur.com^$all ||betjoltiktor.com^$all ||betotodileon.com^$all ||bett2you.org^$all ||bigsport.today^$all ||breakingfeedz.com^$all ||businessenviron.com^$all ||byambipoman.com^$all ||cadbitff.com^$all ||chemitug.net^$all ||civadsoo.net^$all ||clicktracklink.com^$all ||comivolo.com^$all ||consoupow.com^$all ||countriesnews.com^$all ||daizoode.com^$all ||davaifoa.com^$all ||desabrator.com^$all ||dfsdkkka.com^$all ||dodurantom.com^$all ||doflygonan.com^$all ||domakuhitaor.com^$all ||dosamurottom.com^$all ||dugothitachan.com^$all ||dukirliaon.com^$all ||dulillipupan.com^$all ||duponytator.com^$all ||ewoutosh.com^$all ||eyenider.com^$all ||faestara.com^$all ||fdiirjong.com^$all ||fiinann.com^$all ||fiinnancesur.com^$all ||finance2you.org^$all ||finnnann.com^$all ||flymob.com^$all ||forlumineontor.com^$all ||forunfezanttor.com^$all ||forzigzagoonom.com^$all ||fregtrsatnt.com^$all ||funnysack.com^$all ||gdasaasnt.com^$all ||geedoovu.net^$all ||geejooji.com^$all ||getsurv2youu.com^$all ||gfsdloocn.com^$all ||ggetsurveey.com^$all ||gggtrenks.com^$all ||gillynn.com^$all ||gkjoanks.com^$all ||glersakr.com^$all ||gloaphoo.net^$all ||gloolrey.com^$all ||gloudsel.net^$all ||goomaphy.com^$all ||groguzoo.net^$all ||growebads.com^$all ||gtoonfd.com^$all ||haunigre.net^$all ||higheurest.com^$all ||hoanoola.net^$all ||hrenbjkdas.com^$all ||inabsolor.com^$all ||inboldoreer.com^$all ||incorphishor.com^$all ||inkingleran.com^$all ||inpage-push.com^$all ||interdfp.com^$all ||intorterraon.com^$all ||itemolgaer.com^$all ||itgiblean.com^$all ||itnuzleafan.com^$all ||ittorchicer.com^$all ||itzekromom.com^$all ||jeehathu.com^$all ||karsauwi.xyz^$all ||koapsuha.net^$all ||kogutcho.net^$all ||lauhoosh.net^$all ||leethalo.net^$all ||leezoama.net^$all ||loralana.com^$all ||lowdodrioon.com^$all ||lowdurantom.com^$all ||lowlatiasan.com^$all ||lowstaryur.com^$all ||mauchopt.net^$all ||meagplin.com^$all ||meet4youu.com^$all ||mekstolande.com^$all ||moakaumo.com^$all ||moksoxos.com^$all ||mygtmn.com^$all ||naisoops.net^$all ||newprofitcontrol.com^$all ||nieveni.com^$all ||oackoubs.com^$all ||oaphoace.net^$all ||offmachopor.com^$all ||omanala.com^$all ||omasatra.com^$all ||omchimcharchan.com^$all ||omnidokingon.com^$all ||onclickads.net^$all ||onclickrev.com^$all ||onclickserver.com^$all ||onelivetra.com^$all ||onwasrv.com^$all ||onxatutor.com^$all ||oodrampi.com^$all ||oopsoans.xyz^$all ||opcharizardon.com^$all ||opchikoritaan.com^$all ||opchikoritar.com^$all ||opclauncheran.com^$all ||osspalkiaom.com^$all ||ossrhydonr.com^$all ||otrwaram.com^$all ||outaipoma.com^$all ||outseylor.com^$all ||overonixa.com^$all ||overswaloton.com^$all ||overzoruaon.com^$all ||overzubatan.com^$all ||paiwhoki.com^$all ||parumal.com^$all ||pipeschannels.com^$all ||propvideo.net^$all ||psaudous.com^$all ||psoukesh.com^$all ||ptewarin.net^$all ||qarewien.com^$all ||rhendam.com^$all ||ridsilry.net^$all ||rmndme.com^$all ||rndchandelureon.com^$all ||rndmusharnar.com^$all ||roduster.com^$all ||roosteem.net^$all ||rouinfernapean.com^$all ||rtmark.net^$all ||rtrgt2.com^$all ||saimifoa.net^$all ||seevustu.xyz^$all ||serconmp.com^$all ||shoubsee.net^$all ||show-review.com^$all ||sportevents.news^$all ||staixooh.com^$all ||stastips.net^$all ||surv2you.net^$all ||survey2you.org^$all ||tauvoojo.net^$all ||teefuthe.com^$all ||thoamike.xyz^$all ||timecrom.com^$all ||toateeli.net^$all ||toglooman.com^$all ||toshelmeton.com^$all ||tosuicunea.com^$all ||totentacruelor.com^$all ||totogetica.com^$all ||touroumu.com^$all ||tovanillitechan.com^$all ||trads.io^$all ||trenhsmp.com^$all ||trewnhiok.com^$all ||ugroocuw.net^$all ||unampharostor.com^$all ||unbeedrillom.com^$all ||unexeggutorer.com^$all ||ungolbator.com^$all ||untimburra.com^$all ||uparceuson.com^$all ||uplucarioon.com^$all ||uponarticunoer.com^$all ||upregisteelon.com^$all ||urmavite.com^$all ||uwhuglup.net^$all ||vamsoupowoa.com^$all ||vethojoa.net^$all ||vuftouks.com^$all ||whaxanso.net^$all ||whizista.xyz^$all ||wumpeeps.net^$all ||wynather.com^$all ||yacurlik.com^$all ||yarlnk.com^$all ||yonabrar.com^$all ||zagtertda.com^$all ||zoawufoy.net^$all ||139.45.197.239^$all ! https://www.bleepingcomputer.com/news/security/fake-msi-afterburner-targets-windows-gamers-with-miners-info-stealers/ ! https://forums.malwarebytes.com/topic/292537-phishing-x-3/ (account required, credit to https://forums.malwarebytes.com/profile/126832-bradraynor/) ||13ee53.codesandbox.io^$document ! https://www.virustotal.com/gui/ip-address/20.126.134.116/relations ! https://forums.malwarebytes.com/topic/292570-malwarebytes-blocked-trojanexe-am-i-safe/ ! https://threatfox.abuse.ch/ioc/1024382/ ||185.234.247.238^$all ! https://forums.malwarebytes.com/topic/292568-ironmodalcom/ ||ironmodal.com^$all ! https://app.any.run/tasks/fbb04c5d-ce57-4eaa-937b-20b014ed7c19# ||rsmerchantservices.com^$all ||oolomos.com^$all ||cdn.discordapp.com/attachments/1045660833943928856/1048563018402897950/File.zip^$all ||privacy-tools-for-you-453.com^$all ||gcrpgqhhmf.com^$document ||bestsmartfind.com^$all ||77.73.133.72^$all ||31.41.244.167^$all ||163.123.143.4^$all ||45.139.105.171^$all ||107.182.129.235^$all ||45.15.156.105^$all ||135.125.27.235^$all ! https://app.any.run/tasks/df07016b-df4a-47d2-8ef4-3764547ccb7b (website) ! https://app.any.run/tasks/30bb18a1-ea92-4208-91a1-e1b964930fa5 (file) ! https://threatfox.abuse.ch/ioc/1028938/ ||youtube.com/watch?v=5BENKhxzBGI^$all ||rebrand.ly/McAfeeSecurity2022ActivateDownload^$all ||pixeldrain.com/api/file/52LgfWw8^$all ||45.15.157.132^$all ! this is totally not what online malware sandboxes are for, but ! https://tria.ge/221205-15q5dsfb9z/behavioral1#network ||ftrec.adthereis.buzz^$all ||adthereis.buzz^$all ! subdomains ||czudf.adthereis.buzz^$all ||dlaho.adthereis.buzz^$all ||uyfox.adthereis.buzz^$all ||bukwg.adthereis.buzz^$all ||vriuj.adthereis.buzz^$all ||qcfhr.adthereis.buzz^$all ||vmvyu.adthereis.buzz^$all ||sxvne.adthereis.buzz^$all ||tzoca.adthereis.buzz^$all ||vqzao.adthereis.buzz^$all ||stypo.adthereis.buzz^$all ||rzukq.adthereis.buzz^$all ||buvaf.adthereis.buzz^$all ||kmkab.adthereis.buzz^$all ||ecgax.adthereis.buzz^$all ||tfseo.adthereis.buzz^$all ||pydqn.adthereis.buzz^$all ||jspov.adthereis.buzz^$all ||xdaxi.adthereis.buzz^$all ||cxyyv.adthereis.buzz^$all ||rzhxs.adthereis.buzz^$all ||ihclh.adthereis.buzz^$all ||mzqyv.adthereis.buzz^$all ||ovanj.adthereis.buzz^$all ||nnkjm.adthereis.buzz^$all ||zcuea.adthereis.buzz^$all ||mnqre.adthereis.buzz^$all ||vnzdj.adthereis.buzz^$all ||bxauc.adthereis.buzz^$all ||drauy.adthereis.buzz^$all ||gkgfw.adthereis.buzz^$all ||ribsl.adthereis.buzz^$all ||czhif.adthereis.buzz^$all ||cupyx.adthereis.buzz^$all ||ypnjk.adthereis.buzz^$all ||agexq.adthereis.buzz^$all ||ojhjn.adthereis.buzz^$all ||mrmgk.adthereis.buzz^$all ||hwkjq.adthereis.buzz^$all ||povvx.adthereis.buzz^$all ||pkciz.adthereis.buzz^$all ||drpgq.adthereis.buzz^$all ||inrtc.adthereis.buzz^$all ||tifrl.adthereis.buzz^$all ||lqgqc.adthereis.buzz^$all ||hlrjd.adthereis.buzz^$all ||dqnib.adthereis.buzz^$all ||ydhet.adthereis.buzz^$all ||izszd.adthereis.buzz^$all ||lshph.adthereis.buzz^$all ||cclct.adthereis.buzz^$all ||mzstz.adthereis.buzz^$all ||hzuhg.adthereis.buzz^$all ||qkefc.adthereis.buzz^$all ||furbf.adthereis.buzz^$all ||aealu.adthereis.buzz^$all ||imolc.adthereis.buzz^$all ||gjzsn.adthereis.buzz^$all ||rvoko.adthereis.buzz^$all ||jfope.adthereis.buzz^$all ||kngev.adthereis.buzz^$all ||fkpbd.adthereis.buzz^$all ||atyqv.adthereis.buzz^$all ||tfkbt.adthereis.buzz^$all ||ghevg.adthereis.buzz^$all ||mtvam.adthereis.buzz^$all ||zsa0i.adthereis.buzz^$all ||pxzib.adthereis.buzz^$all ||bbpky.adthereis.buzz^$all ||xtfaq.adthereis.buzz^$all ||ggyjx.adthereis.buzz^$all ||wqweo.adthereis.buzz^$all ||ycxds.adthereis.buzz^$all ||vpemr.adthereis.buzz^$all ||updsl.adthereis.buzz^$all ||pnwut.adthereis.buzz^$all ||svgpj.adthereis.buzz^$all ||afmqv.adthereis.buzz^$all ||fcwli.adthereis.buzz^$all ||bejnh.adthereis.buzz^$all ||uzvfz.adthereis.buzz^$all ||eapmj.adthereis.buzz^$all ||hiaxn.adthereis.buzz^$all ||nglkk.adthereis.buzz^$all ||04pl0.adthereis.buzz^$all ||xbufq.adthereis.buzz^$all ||kfchx.adthereis.buzz^$all ||eqtzo.adthereis.buzz^$all ||xkrws.adthereis.buzz^$all ||rabyl.adthereis.buzz^$all ||vrrip.adthereis.buzz^$all ||yrjrq.adthereis.buzz^$all ||oimxs.adthereis.buzz^$all ||mnlnd.adthereis.buzz^$all ||lubpm.adthereis.buzz^$all ||uvcbk.adthereis.buzz^$all ||bhqgv.adthereis.buzz^$all ||jzewf.adthereis.buzz^$all ||edbek.adthereis.buzz^$all ||bmvbj.adthereis.buzz^$all ||wmsxu.adthereis.buzz^$all ||mfxzk.adthereis.buzz^$all ! https://scammer.info/t/i-made-a-game-can-you-test-play-discord-trojan/114861 ! https://tria.ge/221208-n68plshh69/behavioral1 ||mediafire.com/file/bu394h0oi025wpt/ExtremeUpdate.exe/file^$all ||download2278.mediafire.com/6kgabdluwlbg/bu394h0oi025wpt/ExtremeUpdate.exe^$all ||kqnfkpoccicxiudstqonfotuwsrhuxkwhqjjfsbjhonoubrccy.nl^$all ! https://app.any.run/tasks/82e6d95e-3fd5-4bf6-873e-3d7379d495e3 ! https://app.any.run/tasks/25665331-97a5-49a8-9381-eda377347ee5/ ||bit.ly/fitgirl-repacks-site^$all ||fitgirl-repacks-site.org^$all ||bluemediafiles.top^$all ! https://forums.malwarebytes.com/topic/292825-outgoing-connection-blocked-due-to-trojan-vbcexe/ ||na.luckpool.net^$all ! https://forums.malwarebytes.com/topic/292876-detected-trojan-windowsmicrosoftnetframeworkv4030319applaunchexe/ ||tininshassama.xyz^$all ! https://forums.malwarebytes.com/topic/292840-file-detected-windowsmicrosoftnetframeworkv4030319aspnet_compileexe/ ||line.publicvm.com^$all ||209.209.41.33^$all ||onedrive.live.com/Download?cid=8BDBA39CCF6B0487&resid=8BDBA39CCF6B0487%21115&authkey=AKzKYXDKF87dXao^$all ! https://bazaar.abuse.ch/sample/a3cafe7d2d20180460c2e581b215d63519a691de2781a66349fd57ea3e5fcfdf/ (https://bazaar.abuse.ch/user/86185858/) ||194.58.108.112^$all ! https://github.com/uBlockOrigin/uAssets/issues/15990 ||vlcdownloads.com^$all ! https://github.com/uBlockOrigin/uAssets/issues/16017 ! https://app.any.run/tasks/5474c73a-c247-4837-bfd1-a35d08332a5a ! https://app.any.run/tasks/213d5660-7bba-4da6-b9a4-9539201b213c ||t20boltmig.click^$document ||offsebike.cyou^$all ! https://www.virustotal.com/gui/url/2eeeeba08305b13c205d66f7d9cd6a853bc491688d0e91c0381613066b2566a3/community ||storageapi.fleek.co/65d6137a-aa68-4f10-9b8d-3763e277f165-bucket/fav/indexxxxxx.html^$all ! https://www.virustotal.com/gui/url/f297b1523c8c0ac766edeccbc5fb099f1c7bd031c29f837a1701e0a1f71a8651/community ||desinvca.ru^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/136390 ||glthub.org^$document ! https://forums.malwarebytes.com/topic/293043-fake-notepad-website-with-fake-installer/ (login required) ! credit to https://forums.malwarebytes.com/profile/284536-liteiton/ ||nothfnw.shop^$document ! https://www.virustotal.com/gui/url/eddc1bb4cd5e2ce587a32c445fb5a0e428388e7990692b6c6068e66421bf707d/community ! https://www.virustotal.com/gui/url/39b74b6bf53d51836fe43dedf78b6d89b4fe17b9d05e740fdfcbd700229692e6/community ! https://github.com/uBlockOrigin/uAssets/pull/16038 ||microauth.ru^$all ! https://forums.malwarebytes.com/topic/293076-google-docs-extension-malware/ ||goog.goodsearchez.com^$document ||goodsearchez.com^$document ! https://forums.malwarebytes.com/topic/293086-i-keep-getting-data-crypto-mining-trojans-in-my-chrome-extensions-folder/ ||daggerhashimoto.eu.nicehash.com^$all ! https://www.virustotal.com/gui/url/02dc78a55d22ccb88c5609813f90be62723531ba26be696df8259f9820dcae3b/community ||plazaboulevard.com.br^$all ! https://www.virustotal.com/gui/url/e932836ffec1abf152162b20f97292111a5d7c02cd6b3f2d91916c0821227ac2/community ||authentication-vmail.us-east-1.linodeobjects.com^$all ! fake "Edge update" ! https://bazaar.abuse.ch/sample/dd022ea963e777dec7fbb6c3f84893961c60a0b72fa26152416a9e75e9879c5d/ ||youtube.com/watch?v=NTrWmbbLebA^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_DownloadApp.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeLoader_All_In_One.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeSubstanceDesigner.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeSubstanceSampler.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeAcrobat.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeAftereffects.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeIllustrator.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeLightroom.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobePhotoshop.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobePremiere_Pro.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeAudition.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeXD.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeAnimate.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AdobeInDesign.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_KMS_Auto.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AutodeskSketchbook.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_WondershareFilmora.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_WondershareDataRecovery.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AnyDesk.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Winrar.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_VMware.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_FL_Studio.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Ableton_Live_11_Suite.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Bandicam.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Bluestacks.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Autocad.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AutodeskMaya.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Autodesk_Civil_3D.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Autodesk_3DS_MAX.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_SonyVegasPro.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_IObit_Driver_Booster_PRO.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Movavi_VideoEditor.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_CorelDraw.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_AffinityDesigner.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_TeamViewer.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_TradingView.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_PDF_Editor.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Proxifier.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_SketchUp_PRO.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_MicrosoftOffice.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_DaVinciResolve.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_SpotifyPremium.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Camtasia.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_WaveLab_Pro_11.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_RevoUninstallerPro.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Zbrush.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_ExpressVPN.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_CyberGhost.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_ProtonVPN.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_NordVPN.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_PlanetVPN.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_Surfshark.rar^$all ||bitbucket.org/edidervishid46/facebooker/downloads/Passw_wesoft_NortonVPN.rar^$all ||142.93.198.232^$all ||youtube.com/watch?v=sByXe6zNWQY^$all ! https://www.virustotal.com/gui/file/9108e1d22d74bc5397b8886edc4f0a84b8906436a648ef8a86f30cf7e08978dd/detection ||youtube.com/watch?v=U35v0C34ON8^$all ||bit.ly/3zKpp8y^$all ||mediafire.com/folder/bftfjxk7na4m8/Setup^$all ||mediafire.com/file/kfjdexcnso6l3uk/Installer.rar/file^$all ||download2275.mediafire.com/65rwcv0jw3jg/kfjdexcnso6l3uk/Installer.rar^$all ! https://www.virustotal.com/gui/file/8b526ce6c0637c72799d1f1944f5d77a821d896c2ffe01cd8c391ed37a175f76 ||telegra.ph/TeamViewer-11-16^$all ||gg.gg/teamviewer-prem-free^$all ||mediafire.com/file/z0mvgi2bjbotamf/TeamViewerPremium.rar/file^$all ||download1505.mediafire.com/ickhc4n6zzcg/z0mvgi2bjbotamf/TeamViewerPremium.rar^$all ! https://www.virustotal.com/gui/file/5139f90c2e9555321bcd2a13a971280226f0d514f11291419e68bae7386decd7/detection ||youtube.com/watch?v=rybiOJqXqYc^$all ||github.com/vilma683/$document ||raw.githubusercontent.com/vilma683/vilma/main/Desktop_Full.rar^$all ! https://www.virustotal.com/gui/file/1727a5f6484628f4493ac2befaf48b47d88376128992c2787959c00b306da048/detection ||youtube.com/watch?v=IlpvSYMHWO8^$all ||bit.ly/3VtsAd2^$document ||mediafire.com/file/umf43herutudu71/After+Effects.rar/file^$all ||download2355.mediafire.com/nnnv7x50jddg/umf43herutudu71/After+Effects.rar^$all ! https://github.com/DandelionSprout/adfilt/discussions/163#discussioncomment-4502840 (with no adblocker, I got an ad which downloaded https://www.virustotal.com/gui/file/7c4c570fb381176736d956ee84c5fb01b6e4638fe122e7a2e1f7335d08edb1d6/detection) ||ecomefuk.xyz^$all ! https://app.any.run/tasks/f4e39100-c15b-4cd3-9a2c-3401df4435d4 ! https://tria.ge/221227-3mk7jagg99 ||thyr65qw.cfd^$all ||5rd5tgh.cfd^$all ||116.203.121.167^$all ! https://www.hybrid-analysis.com/sample/f2e12223da0ae00323260f8dadbdd1596f7ce8fcd2e2520fde0aefc6fd19a88b ! https://tria.ge/221228-3ez1qabh74/behavioral2 ! https://www.virustotal.com/gui/file/0814d32e07768c5387774d03108ea27ff132d4aee72d3f1fc98a6d78ab74d628 ||wkcrack.com^$all ||neonhost.click^$all ||157.230.87.146^$all ||sigmarole.cyou^$all ! https://threatfox.abuse.ch/ioc/847757/ ||77.73.134.24^$all ! (recheck on 28/1/2023) https://app.any.run/tasks/acb995d6-45ba-4680-8c39-b96b7a8574d8 ||rotf.lol/2p9fmd8k^$all ||65.108.249.43^$all ! https://github.com/iam-py-test/investigations/blob/main/malware/oceanofgames.com.md ||oceanofgames.com^$all ||easy-learn-tech.info^$document ||51.68.154.128^$all ! https://www.virustotal.com/gui/url/c4c4913c27814d34be86ee1394ba7706190a2b9f59adade86eaa05126b3258fc/community ||securewebauths.com^$all ! https://www.virustotal.com/gui/url/25c1299a47deee16de446a1e984b668779afe55cd5429639a112fe8cb6509b68/community ||colorflys.com^$all ! https://app.any.run/tasks/5bdcb423-d8a6-4c4a-bee0-e4817415d96e ! https://www.virustotal.com/gui/file/f82251f78347ba9a0a0fe6efee7fdfb4a07ef133ec29d4fb816116b194c4f4a2/detection ||116.203.3.152^$all ! https://app.any.run/tasks/42060440-db32-43e2-8928-4a4dbe634b0f ! shared by https://github.com/JobcenterTycoon ||funnycrack.com^$all ! https://www.hybrid-analysis.com/sample/329ba701c991e0dcf29efc79b93c589e89e25e2b6f28b4c0f75dee01fc8f2ed7 ! https://www.virustotal.com/gui/file/329ba701c991e0dcf29efc79b93c589e89e25e2b6f28b4c0f75dee01fc8f2ed7/detection ! https://tria.ge/230103-px6pbsbd48/behavioral2 ! https://app.any.run/tasks/5f9ddba3-9d5d-45a6-8ab1-37eaca832b2a/ ! https://tria.ge/230103-s79qhsfb2z/behavioral2 ||gigapurbalinggaa.com^$all ||cutt.ly/V2fZo0l^$all ||bit.ly/3Z8fkxh^$all ||stone10.xyz^$all ||143.198.211.93^$all ||blakbooot.click^$all ||p1nkroze.click^$all ||5.75.173.242^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/139106 (credit to DandelionSprout) ||loadingnow.me^$all ||gsecurecontent.com^$all ||pressizer.net^$all ||sapino.net^$all ||44.236.213.34^$document ||52.24.156.12^$document ||52.25.6.134^$document ||100.20.13.49^$document ! https://tria.ge/230104-qdn6lsfh34/behavioral2 ! https://tria.ge/230104-qcf4lsbb81/behavioral2 ! https://www.hybrid-analysis.com/sample/a2f1e5de0f6a32a2b202a973b4deebb0f3f3fd0c16001a010594ced932b17a07 ! https://www.virustotal.com/gui/file/a2f1e5de0f6a32a2b202a973b4deebb0f3f3fd0c16001a010594ced932b17a07/detection ||1weset6y.cfd^$all ! https://threatfox.abuse.ch/ioc/1064537/ ! https://threatfox.abuse.ch/ioc/1064536/ ! https://threatfox.abuse.ch/ioc/1064660/ ||88.119.161.188^$all ||88.119.161.19^$all ! copied from ThreatFox ! https://threatfox.abuse.ch/ioc/1064519/ ! https://threatfox.abuse.ch/ioc/1053246/ ! https://threatfox.abuse.ch/ioc/1064520/ ! https://threatfox.abuse.ch/ioc/1053244/ ! https://threatfox.abuse.ch/ioc/1064521/ ! https://threatfox.abuse.ch/ioc/1064528/ ! https://threatfox.abuse.ch/ioc/1053222/ ! https://threatfox.abuse.ch/ioc/1064468/ ! https://threatfox.abuse.ch/ioc/1064472/ ! https://forums.malwarebytes.com/topic/293448-brute-force-password-attack-on-email-server-from-ip-address-9820013539/?do=findComment&comment=1547922 (account required) ! https://www.abuseipdb.com/check/68.60.77.128 ! delist once there have been no new reports in one week. Probably pointless to list in the first place ||68.60.77.128^$all ! https://app.any.run/tasks/37850881-daef-455e-a60d-7b1a11438955 (just a 7zip download???) ||fitgirlrepack.games^$document ||floppyredirect.click^$all ||losstub.icu^$document ! https://app.any.run/tasks/bdf92208-3c4b-4673-b4f4-4d59299d1201 ||fitgirl-repacks.proxy2link.com^$document ! https://app.any.run/tasks/73e0b109-7648-4d44-ac89-c2abd5c0b8f0 ||nortvpn-app.com^$document ! https://github.com/hagezi/dns-blocklists/issues/166 ||nielviok.cf^$document,popup ||kallarann.gq^$document,popup ||jandin.gq^$document,popup ||web.quoabide.top^$document,popup ||milfme.com^$document,popup ||web.zoneimage.site^$document,popup ||dylacha.tk^$document,popup ||waumari.tk^$document,popup ||web.tumbleceq.in^$document,popup ||web.squirmaccess.site^$document,popup ||track.findb.news^$document,popup ||web.zoombleat.top^$document,popup ||web.grittyago.xyz^$document,popup ||wineshasi.cf^$document,popup ||web.spywax.site^$document,popup ||xonanere.ga^$document,popup ||karindal.ga^$document,popup ||web.aeratevenal.site^$document,popup ||web.cannondate.top^$document,popup ||deugahat.gq^$document,popup ||web.acidicadorn.top^$document,popup ||leelabea.cf^$document,popup ||beladra.cf^$document,popup ||web.actgrovel.site^$document,popup ||ysiquaarac.ga^$document,popup ||web.grincanis.site^$document,popup ||web.spurtparole.top^$document,popup ||llantana.ml^$document,popup ||web.datelovetime.xyz^$document,popup ||lhamad.gq^$document,popup ||web.jazztunnel.top^$document,popup ||quinete.ga^$document,popup ||web.blandfain.site^$document,popup ||web.hanfallow.online^$document,popup ||web.groupabet.site^$document,popup ||tracking.lovematchflirt.com^$document,popup ||tracking.latedreamdate.com^$document,popup ||web.gristwattle.online^$document,popup ! https://bazaar.abuse.ch/sample/971a53dd3d17c44c1f4b21e33c0c161aed411ebb8c4d7f5a47c3cc68849340a5/ ||skynetx.com.br^$all ! https://app.any.run/tasks/45e3bc2d-8e87-47b6-b233-cf8bfecbd5b7 ||cdt2023.ddns.net^$all ! https://app.any.run/tasks/425c595f-3f93-4d54-abaf-29b7d8c78e1b# ||bit.ly/3G1xJTO^$all ||upload.ee/files/14795098/Installer.rar.html^$all ||upload.ee/download/14795098/e163e4d865031c40167f/Installer.rar^$all ! https://github.com/uBlockOrigin/uAssets/pull/16283 ||galeden.cn^$all ! https://www.virustotal.com/gui/url/ba238fade1efae3c4a22a777ea6d8e7876911ba2762a38e9068be025dae64642/community ! https://app.any.run/tasks/fc749190-7a49-4f62-bfcb-b4262ba6fe8b (my analysis) ||coda.io/d/_dgQ7smav5EW/AP_suCWI^$document ! https://www.virustotal.com/gui/url/d53cb0004ee89defa498483920b97ff3b414748e05ce7a5af65136b06b19ef6f/community ||tidy-mark.com^$all ||grethychashi.pro^$all ||www.grethychashi.pro^$all ! https://forums.malwarebytes.com/topic/293729-help-please-a-file-trojan-keeps-coming-back-when-i-reboot-my-computer/ ||phtgnx.top^$all ||cdn.phtgnx.top^$all ||progriu.top^$all ||cdn.progriu.top^$all ! https://tria.ge/230114-ra56dsch4w/behavioral2 ||er76njy.click^$all ||vghu896yh.cfd^$all ! https://threatfox.abuse.ch/ioc/1068340/ and https://threatfox.abuse.ch/ioc/1068341/ ||146.70.86.11^$all ||69.46.15.158^$all ! https://github.com/uBlockOrigin/uAssets/issues/16339 ||dgemanowhot.com.ua^$all ||onandeggsiswe.com.ua^$all ||ormoredeta.xyz^$all ! https://forums.malwarebytes.com/topic/293896-malwarebytes-keeps-blocking-domains-for-malvertising/ ! https://forums.malwarebytes.com/topic/293881-hijackautoconfigurlprxysvrrst-backdoorfarfli/ ||g.agametog.com^$all ||agametog.com^$document ! https://bazaar.abuse.ch/sample/13b4cf644bcb21bc1fe99e77bc919b8114ce44e6f0cca5872b689185c57606bc/ ! my analysis (all credit to whoever originally reported this) ! https://www.hybrid-analysis.com/sample/3e79dfe786d64834eca9f37d68c01d433ebbe90bb6f2ca58c0daaf9f8a85f059 ! https://tria.ge/230116-1vskgaeb63/behavioral2 ! https://threatfox.abuse.ch/ioc/1062895/ and https://threatfox.abuse.ch/ioc/1062522/ ||domifybot.com^$all ||79.137.206.138^$all ! https://forums.malwarebytes.com/topic/293964-facebook-ad-ultimately-serves-up-pdfexe-file-grabs-browser-passwords/ (account required) ! my analysis: ! https://tria.ge/230117-pm5paabh4x/behavioral2 ! https://www.hybrid-analysis.com/sample/e36df1e426a2da7f98bc2ed336472068335b0201a05e24ed86bac3a6ae60ef31 ||dl.dropboxusercontent.com/s/h4mwkmal6ry86y3/1%2C000%2B Social Media Content Ideas _Instagram content ideas.rar?dl=0^$all ! https://blog.sucuri.net/2023/01/finding-removing-malware-from-weebly-sites.html ||circuitingratitude.com^$all ! https://forums.malwarebytes.com/topic/294262-fake-firefox-update/ (account required) ! credit to https://forums.malwarebytes.com/profile/3800-porthos/ ||84df4578bffsd.info^$all ! https://forums.malwarebytes.com/topic/294335-repeated-blocked-website-trojan-compromised-logs/ ||dellenshop.top^$document ! https://forums.malwarebytes.com/topic/294253-infected-paranoid/#comments ||fuzionblox.com^$all ! https://forums.malwarebytes.com/topic/294374-might-have-a-virus/ ! https://forums.malwarebytes.com/topic/294372-suspicious-file/ ! https://threatfox.abuse.ch/ioc/1073271/ ! (my analysis) https://app.any.run/tasks/96fff8ad-199e-4a03-aea3-410214ed18f4 ||cdn.discordapp.com/attachments/1067911713963397223/1068274673726533743/AudioTools.zip^$all ||194.36.177.164^$all ! https://github.com/blocklistproject/Lists/issues/918 (all but one appear dead but added anyway) ||notldoy.xyz^$all ||blendepr.org^$all ||blendevr.org^$all ||blender3d-software.net^$all ! https://www.virustotal.com/gui/url/6b19b5e07a1d736934459f8bfc3db4a5f5d9055311e19a7d470173014502a6da/community ! https://github.com/uBlockOrigin/uAssets/issues/16558 ! (my analysis) https://tria.ge/230130-pl42csac69/static1 ||driveusercontent.us^$document ! https://forums.malwarebytes.com/topic/294473-malware-not-detected-in-malwarebytes/ (account required) ! (my analysis) https://app.any.run/tasks/14b9da67-7f1e-49ff-b73d-26a5d263efbf/ ||135.181.41.147^$all ! https://github.com/DesktopECHO/T95-H616-Malware ||ycxrl.com^$all ||ycxrldow.com^$all ||cbphe.com^$all ||cbpheback.com^$all ! https://bazaar.abuse.ch/sample/89da2eee6af1c267e164bd9b24866bcac56588fe67efaf3bdb9aa98afa8cf990/ ! https://bazaar.abuse.ch/sample/7df24f04c4df829cd9e643cd9be596d0996b79d1fbb9422c75a17741f10414a4/ (all credit to abusech) ||pusgpaxnddw.top^$all ||qlmhxmwlyhr.top^$all ||qmudnleqjjx.top^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/141376 ||watch-online.7oc5b1i3v4iu.top^$all ||7oc5b1i3v4iu.top^$all ! from internal discussion ! https://urlhaus.abuse.ch/url/2524904/ ||cdn.discordapp.com/attachments/1070079222170787951/1070142745336889495/BrowserNews.exe^$all ! (my analysis) https://tria.ge/230201-nxx7hsda77/behavioral2 ! https://threatfox.abuse.ch/ioc/1067729/ ||82.115.223.46^$all ! https://forums.malwarebytes.com/topic/294558-google-customer-reward-program/ ||21bustqisw2.top^$document ! from search results ||331454283.jirikrcmar-photography.cz^$all ||jirikrcmar-photography.cz^$document ||dh4jf8fjs.affiliatemarketing.news^$all ||affiliatemarketing.news^$document ! https://forums.malwarebytes.com/topic/294619-trojan-hijack-browser/ ! https://app.any.run/tasks/9cdd662f-9642-4406-8797-03f021ce6370 ! https://tria.ge/230203-pmtl1saf9t/behavioral1 ||ccleaner-download.xyz^$all ||35.181.110.225^$all ||service-domain.xyz^$all ! https://twitter.com/KesaGataMe0/status/1621321884012019712 (https://github.com/AdguardTeam/AdguardFilters/commit/cc46c1f0f0c2a71e989c697fb382cdd68621d366) ||www-biccamera-com.jycfmf.com^$all ! https://www.virustotal.com/gui/url/7edda570d0f8fae48fac53194950c93137721d5535829d88add851c9bf42a0e2 ! (my analysis) https://app.any.run/tasks/1da745f3-0a79-44b4-9490-0ce55609f1e2 ||un-titled.co/remain/DNS/index.php$document ! https://www.virustotal.com/gui/url/7aa7958a7cb1509cd70a8c935c6c3eb96c46f2fc7b05cb3862f9bd9299308627/community ! (my analysis) https://app.any.run/tasks/e795f6aa-589a-4b6f-8352-403b055bdf5d ||hotmail-107217.weeblysite.com^$all ! https://www.virustotal.com/gui/url/9f52f7e0f34c63c2f0c8de10fa003fd4d8c2e0804f7ea97e056125564a56ebc7/community ! (my analysis) https://app.any.run/tasks/3525a515-f11e-4ff1-9be0-c5640b1d5904 ! https://bazaar.abuse.ch/sample/d089b6082b4f5ecf765148ffea5885d8cd81e9e078d69bee786be9e6d60a653f/ ! NSFW: https://app.any.run/tasks/84fe2ec3-067b-4095-8a4f-e74636671351 ||message.okaynotification.com^$all ||okaynotification.com^$all ||notice.okaynotification.com^$all ||click.okaynotification.com^$all ||update.okaynotification.com^$all ||now.okaynotification.com^$all ||readnow.okaynotification.com^$all ! https://app.any.run/tasks/04b2bc07-923b-4890-8587-02e360d01ae0 ||morecash.click^$all ||gamebee.club^$document ! https://app.any.run/tasks/dc47eebe-06b8-4ea7-87c5-ecab7bd18d99 ! https://forums.malwarebytes.com/topic/294675-mygov-scamfraudpersonal-detail-theft-alert/ (account required) ! (my analysis) https://app.any.run/tasks/463e490a-12bb-4afd-a496-f5500177b794/ ||quickttax.top^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/142226 ! https://app.any.run/tasks/91ca9115-952b-479f-8f9d-360e096e558b ||qfdsq.inghesatin.com^$all ||blockadsez.info^$all ||wickedhumankindbarrel.com^$document ||videoadblockerpro.com^$all ||watchadfree.info^$all ||stop-adblocker.info^$all ||ia9j0.top^$all ||yk946.top^$all ||ayybt.top^$all ||8b947.top^$all ||yz9iy.top^$all ||9sgqi.top^$all ||pivoms.live^$all ||ys2fr.top^$all ||9elo3.top^$all ||zjvw7.top^$all ||z4r0w.top^$all ||8yqet.top^$all ||wheeshoo.net^$document ||justquiz39.pushalert.co^$all ||easyadblocker.info^$all ||wbofc.top^$all ||x435f.top^$all ||w6got.top^$all ||xk9tx.top^$all ||wiruv.top^$all ||xpdep.top^$all ||shoesauto3.xyz^$document ! https://forums.malwarebytes.com/topic/294740-trojans-will-not-disappear-and-mb-wont-stop-blocking-websites/ ! https://threatfox.abuse.ch/ioc/1078147/ ||194.87.216.194^$all ! https://www.malware-traffic-analysis.net/2023/02/03/index.html ||yes2food.com^$all ||advertising-check.ru^$all ||softs-lab.ru^$all ||62.204.41.176^$all ||176.113.115.177^$all ! https://threatfox.abuse.ch/ioc/1078856/ ! https://twitter.com/1ZRR4H/status/1623067548781539339 ||79.137.248.136^$all ||79.137.206.31^$all ||85.192.40.253^$all ||mediafire.com/file/4n5bc37ank892fh/Expert-PC_2023.rar/file^$all ||download2348.mediafire.com/ewjzz8pmn7rg/4n5bc37ank892fh/Expert-PC_2023.rar^$all ! https://github.com/uBlockOrigin/uAssets/issues/16704 ! https://app.any.run/tasks/dbfbbaca-9fd5-4466-8a29-9e0519b77589 ! https://www.virustotal.com/gui/file/f202337f99c730eef56d3be2a7fb92d74c9b5adac799fb0564bc9264f2784f5c/relations ||vserpg.ru^$all ! https://github.com/hagezi/dns-blocklists/issues/324 ||teslacar.io^$all ! https://forums.malwarebytes.com/topic/294906-tesla-crypto-scam/ (account required) ! https://app.any.run/tasks/bcd4633b-931e-4bfc-a874-24d04a136036 ||wlbss.inghesatin.com^$all ||xe5j8.inghesatin.com^$all ||ggjt8.inghesatin.com^$all ||world-games.click^$all ||bynsd.top^$all ||8eatj.top^$all ||7ya1q.top^$all ||bhnx4.top^$all ||899h3.top^$all ! https://app.any.run/tasks/53948f39-666f-4083-aa4e-bd5f215d29e2 ||dykbo.inghesatin.com^$all ||cqw59.top^$all ||ajfgq.top^$all ||8lmm7.top^$all ||ifmom.top^$all ||yhvua.top^$all ||dejig.live^$all ! https://github.com/iam-py-test/my_filters_001/issues/109 ||btc.latest-articles.com^$all ||en.firstgooal.com^$all ||en.rawafedpor.com^$all ||news.istisharaat.com^$all ||ust.aly2um.com^$all ||filestack.live^$all ||0-4.top^$all ||012.bond^$all ||5pm.am^$all ||77w.pw^$all ||7la.la^$all ||9ge.ge^$all ||b-d.bond^$all ||b-i-t-l-y.co^$all ||b-ly.link^$all ||b-y.by^$all ||bit-ly.is^$all ||bit-ly.mobi^$all ||bitly.best^$all ||bitly.email^$all ||bitly.gold^$all ||bitly.network^$all ||c-lick.click^$all ||c-you.cyou^$all ||cc-z.cz^$all ||co-o.co^$all ||cr-7.cc^$all ||cutlinks.biz^$all ||cutlinks.ca^$all ||cutlinks.mobi^$all ||cutlinks.org^$all ||cuturls.net^$all ||d-ev.dev^$all ||fco.to^$all ||fmo.fm^$all ||g-l.gl^$all ||g-y.gy^$all ||gob.co.il^$all ||gov-cn.cloud^$all ||gov.co.ve^$all ||h-air.hair^$all ||i-cu.icu^$all ||i-io.io^$all ||i-n-fo.info^$all ||i-s.is^$all ||icx.cx^$all ||ii-ii.ru^$all ||ilc.lc^$all ||isn.is^$all ||isx.sx^$all ||j-e.je^$all ||l-o.loan^$all ||l-ol.lol^$all ||lbz.bz^$all ||m-n.mn^$all ||mvc.vc^$all ||n-g.ng^$all ||n-z.nz^$all ||obz.bz^$all ||oo-o.co^$all ||oo.coffee^$all ||psu.su^$all ||qis.is^$all ||s-k.sk^$all ||s-b.sb^$all ||s-sh.sh^$all ||sy-s.systems^$all ||t-o.to^$all ||tiny-url.mobi^$all ||ufox.info^$all ||u-mu.mu^$all ||uxe.luxe^$all ||vms.ms^$all ||vv-vip.vip^$all ||vvg.vg^$all ||w-me.me^$all ||w-tw.tw^$all ||w-ws.ws^$all ||wac.ac^$all ||wci.ci^$all ||wst.st^$all ||xx-yz.xyz^$all ! https://github.com/blocklistproject/Lists/issues/933 ||jNKmS0zFuEh.click^$all ||pjljo54uk.click^$all ||v1asy4ncr.click^$all ||p5tvhrlw30h.click^$all ||8narwi309.click^$all ||sbjjzdwqg41ps.click^$all ||lrhxz60alkjtik.click^$all ||tvbxrr4ym3.click^$all ||8ebtdbsjsu.click^$all ||eicxz6jfjaw.click^$all ! https://www.virustotal.com/gui/url/90ec9d3b01d045ba7917ba09722d9063803cf318d08de907e77d421800ed1cc4/community ! (my analysis) https://app.any.run/tasks/f14b7082-e3b1-4a98-84fc-e3c5e3d3b35c ||s44-fhvb.web.app^$all ! https://app.any.run/tasks/77b6a223-4c81-4798-9dc0-a747de6e0f6d ||crackshash.com^$document ||czgovd.com^$all ||pufgilsofp.sbs^$all ||bstnwswrld.com^$document ||news-wobuda.com^$all ||ztzguv.com^$all ||thbstvd.com^$all ||notyfrom.info^$document ||flymylife.info^$all ||ms-82.flymylife.info^$all ||ms-52.flymylife.info^$all ||54trck.xyz^$all ||cxvfh.gesgloven.com^$all ||jorjfordmust.sbs^$all ! https://app.any.run/tasks/f03aaba8-7c21-4316-a6db-cbb9bdbb1db6 ! https://app.any.run/tasks/d142bf7d-0363-4bf2-9795-66423bbc9eac ||origincrack.com^$all ||uerqelim91ut.click^$all ||klwukospapf.click^$all ||9bghqk3avg2gnh.click^$all ||6t09fag307ep.click^$all ||bit.ly/3S7o1VK^$all ||mega.nz/file/5w4QWZCR#pYyDSqxzjS4LzhLW9ZYvAWzxhuM3rPGh0wl7r64tDLs^$all ||mega.nz/file/AwQghbKa#GAcaJZR9cIRl3lRWYZhD5gkHtGL8Y63fKOAnCbM-9FU^$all ! https://tria.ge/230216-sgsz3shg3w/behavioral2 ! https://threatfox.abuse.ch/ioc/1077934/ ||83.217.11.27^$all ! https://www.virustotal.com/gui/ip-address/77.73.134.35/relations ||77.73.134.35^$all ! https://twitter.com/TrackerC2Bot/status/1620944031030075392 ! https://threatfox.abuse.ch/ioc/1077935/ ||83.217.11.28^$all ! https://forums.malwarebytes.com/topic/295115-trojan-downloaders-not-detected-by-malwarebytes/ (account required) ! https://www.virustotal.com/gui/file/a0626a283b6e2cbcacfbcc06c21691aff5e3386d43a76909304b2b0bacf8f45a/relations ||176.57.150.117^$all ! fake tor browser - https://app.any.run/tasks/679e9afa-eb19-4414-a086-e280a779a448 ! https://tria.ge/230217-xd8nksgc9x/behavioral2 ||ru-torproject.ru^$all ||anapatformacion.org/modules/file/tor/tor-browser.zip^$all ! https://github.com/uBlockOrigin/uAssets/issues/17400 ! https://github.com/uBlockOrigin/uAssets/pull/16764#issuecomment-1493992669 ! https://app.any.run/tasks/15000d62-df3c-41c4-95fa-b27480049e2d# ||dwnfile.fun^$all ||mpraven.org^$document ||xfiley.me^$all ! https://github.com/uBlockOrigin/uAssets/issues/15937 ! https://github.com/uBlockOrigin/uAssets/issues/15937 ! https://www.virustotal.com/gui/url/a70d88ffc974f8d9cc5c3561938e95435d20a12a555e8c10d638d2bee5292165 ||install1nstall1.com^$all ||kochava.com^$all ||neptunclicks.com^$all ||arakusus.com^$all ||imgfil.com^$all ||urlcod.com^$all ||tiurll.com^$all ||neppe.studio^$all ||startex3download.com^$all ||gowtos.com^$all ||lomogd.com^$all ||nosnou.com^$all ! https://www.virustotal.com/gui/url/8ffac07f327a1bc605278ac9cdbc1f6a00ae2efd9d7111ad38790e6031e74072/community ! (my analysis) https://app.any.run/tasks/69b1e739-fa82-487f-92c8-5ba368b25481 ||steam.steampoweredartwork.com^$all ||steampoweredartwork.com^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/142771 ||wgreplay.fun^$all ! https://www.virustotal.com/gui/file/aaa1beed5908f05cd7e4dc405ec763deecd6177b0bf78f0faa9cd54eed14bc34/detection ||mesoftwares.vip^$all ||cdn.discordapp.com/attachments/1069292766246469732/1076118263186063481/Installer.rar^$all ||drive.google.com/uc?export=download&confirm=no_antivirus&id=11WhDE3Xy7c5AkKS24P0EzS8S8LUNjIAY^$all ! https://app.any.run/tasks/82180609-bf2b-4565-88cd-e3cb2c8e6456/ (someone else's anyrun, credit to them) ||rebrand.ly/30p0zqg^$all ||telegra.ph/Download-Link-11-24-17^$all ||mediafire.com/file/3sdq84zpxzmoio5/Setup_%2528PAS%2524_5577%2529.rar/file^$all ||95.217.14.200^$all ! https://app.any.run/tasks/1aa45c59-b90f-47a2-8fb9-7915a377055a/ ||46.48.76.120^$all ! https://www.virustotal.com/gui/url/be690a1da2bc52dcfc6d7069248b1d085237009c8fb7b45110098eedf8390024/community ! (my analysis) https://app.any.run/tasks/535ae7f2-c6dd-4b51-aee5-e80c4af11b82 ! https://forums.malwarebytes.com/topic/295202-windows-powershell-keeps-popping-up-randomly-and-closing/ ! https://www.virustotal.com/gui/file/d3c9371a1456fd7c4551e18b0c1172a597f86c97e2864bc0b1be632c48da9697/relations ||ahoravideo-blog.com^$all ||ahoravideo-cdn.com^$all ||ahoravideo-endpoint.com^$all ||ahoravideo-endpoint.xyz^$all ||ahoravideo-schnellvpn.com^$all ||ahoravideo-schnellvpn.xyz^$all ||bideo-blog.com^$all ||bideo-cdn.com^$all ||bideo-chat.com^$all ||bideo-chat.xyz^$all ||bideo-endpoint.com^$all ||bideo-endpoint.xyz^$all ||bideo-schnellvpn.com^$all ||bideo-schnellvpn.xyz^$all ||fairu-blog.com^$all ||fairu-cdn.com^$all ||fairu-chat.com^$all ||fairu-chat.xyz^$all ||fairu-endpoint.com^$all ||fairu-endpoint.xyz^$all ||fairu-schnellvpn.com^$all ||fairu-schnellvpn.xyz^$all ||privatproxy-blog.xyz^$all ||privatproxy-cdn.xyz^$all ||privatproxy-chat.com^$all ||privatproxy-endpoint.xyz^$all ||privatproxy-schnellvpn.com^$all ||wmail-blog.xyz^$all ||wmail-cdn.xyz^$all ||wmail-chat.xyz^$all ||wmail-endpoint.xyz^$all ||wmail-schnellvpn.com^$all ||wmail-schnellvpn.xyz^$all ! http://vxvault.net/ViriFiche.php?ID=44753 ||adobetmcdn.net^$all ! https://forums.malwarebytes.com/topic/295239-unsure-if-anything-has-been-done/ ||tiktok.ti3fsaa.cloud^$all ||ti3fsaa.cloud^$document ! https://app.any.run/tasks/fc4768ad-8cc8-4af7-bd44-d91f5d8c258e ||polo.thegadgetguru.club^$all ||thegadgetguru.club^$all ||setupspeedyhighlyinfo-file.info^$document ||startd0wnload22x.com^$all ||skillfactsim.com^$all ||burningpushing.info^$3p ! https://urlscan.io/result/ff16e3ca-7cc9-48aa-9028-dae2e7769419/ ||catomernsuents.com^$all ! https://www.virustotal.com/gui/url/46add8496717590d1e5eef43fb67c8d09710945f395c26d822dd8d1db6a4bb13/community ! (my analysis) https://app.any.run/tasks/f531a557-d782-45a1-ac7f-da6bbfabd172 ! https://www.virustotal.com/gui/url/954e540f3914567dfa26ae82847a085c6052436ac46db1b977deba0bf05205c9/community ! (my analysis) https://app.any.run/tasks/01951733-079f-4a8e-b3b1-5d2172f860e1/ ! https://bazaar.abuse.ch/sample/777a98db2b04de56c57e9d4485d4e8e8bae7e28cb0b276742862fcf22ce85f1a/ ! https://app.any.run/tasks/4b61f476-bb18-4bee-9ebc-0574611bfed6/ ! https://bazaar.abuse.ch/sample/533d169364edf867fafa28fb948a564c032312794a5dc01f27464be65892775b/ ! https://www.virustotal.com/gui/url/b640badf626400458c15e3574d013a02e0e50652c53b135a71e3b099d29e0956/community ! (my analysis) https://app.any.run/tasks/974fe120-a13e-4fe3-9546-64aa16ad4687 ! https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/ ||xrepositoryx.name^$all ||erdjknfweklsgwfmewfgref.com^$all ||harrysucksdick.com^$all ||heikickgn.com^$all ||frassirishiproc.com^$all ||myrepository.name^$all ||egscorp.net^$all ! https://forums.malwarebytes.com/topic/295534-rtp-outbound-connection-on-googlewikipedia/ ||eatablehelprut.com^$all ! https://github.com/hagezi/dns-blocklists/issues/585 ! https://forums.malwarebytes.com/topic/295590-malwarebyes-blocks-webite/ ||mignished-sility.com^$all ! https://forums.malwarebytes.com/topic/295626-hyjecrgernebultcom-malware-removal-disguised-as-mcafee/ ||hyjecr.gernebult.com^$document,xhr,script ! https://forums.malwarebytes.com/topic/295631-blocked-website/ ||curvyalpaca.cc^$3p ! domains farmed from adfly ||zxbfm.ooumoughtcall.com^$all ||ooumoughtcall.com^$document ||s2cp.xyz^$all ! https://github.com/RPiList/specials/issues/948#issuecomment-1458739160 ||yuppdownload.com^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/145513 ||4b34eusvcxsdublb6f.runoj.click^$all ||runoj.click^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/145513#issuecomment-1468676678 ||aesch-mko.com^$document,popup ||agapios-gla.com^$document,popup ||ahura-maz.com^$document,popup ||altwi-cha.com^$document,popup ||artax-evn.com^$document,popup ||balor-ghn.com^$document,popup ||ermin-oxj.info^$document,popup ||gargi-xba.com^$document,popup ||gloos-zus.info^$document,popup ||gronw-zis.com^$document,popup ||harib-eir.info^$document,popup ||heily-nin.com^$document,popup ||iorwe-qmf.com^$document,popup ||kuno-gae.com^$document,popup ||laurentia-kor.com^$document,popup ||menelaus-col.com^$document,popup ||nicomachus-mac.com^$document,popup ||orige-duo.com^$document,popup ||phara-gte.com^$document,popup ||quinctus-isb.com^$document,popup ||sindr-yet.com^$document,popup ||redirect.newprogrammatic.click^$document ||3.231.116.86^$document ||54.237.193.255^$document ! random malware ||moresknock.click^$document ||b7iexw24.cfd^$all ||u1500oyc.cfd^$all ||nzjal5ou.cfd^$all ||krimahoriz.click^$all ||telegra.ph/Software-2023-02-21-6^$document ||en.bestadultdatinglist-com.ru^$document ||fuckbookmobile.org^$document ||theparlornextthef.com^$document,popup ||dtsdr.theparlornextthef.com^$all ||palons.live^$all ||alertci.click^$all ||9ijgfdc4rf56.click^$all ||nbsb7nr44.cfd^$all ||pingatinga.click^$all ||srinaboglad.click^$all ||bvnie.taitlastwebegan.com^$all ||taitlastwebegan.com^$all ||162.243.164.175^$all ||jikabotlan.click^$all ||trackyouswin.com^$all ||tgbhi8i.click^$all ||justfreesetuphere.xyz^$all ||hit5k.one^$all ||zdr566yh.click^$all ||getnomadtblog.com^$all ||urhandups.xyz^$all ||qtgsr.taitlastwebegan.com^$all ||yt93231mn.click^$all ||aswedfcv6ty.click^$all ||i3edtgyu.cfd^$all ||ko04rf8.cfd^$all ||dr6ghyu7.click^$all ||entry4hide.cyou^$all ||ovhoq.nkingwitheaam.com^$all ||nkingwitheaam.com^$all ||niceelitdating.top^$document,popup ||b.niceelitdating.top^$all ||bigosext1s.com^$document ! https://github.com/DandelionSprout/adfilt/issues/808 ||jonathanbartz.com^$all ||jp.imonitorsoft.com^$all ||junk-bros.com^$all ||kepw.org^$all ||kristinee.com^$all ||lakeside-fishandchips.com^$all ||108.61.242.65^$all ||146.70.78.43^$all ||87.120.254.39^$all ||45.150.108.213^$all ||92.204.160.240^$all ! https://www.reddit.com/r/uBlockOrigin/comments/1212vbf/badware_risks_fake_tor_browser_site/ ||tor-browser-rus.ru^$all ! https://www.reddit.com/r/uBlockOrigin/comments/1204r6t/this_should_probably_be_blocked_if_i_must_say/ ||adblockers.b-cdn.net^$all ||pleasetrack.com^$all ! https://github.com/hagezi/dns-blocklists/issues/809 ||getsupport-lcloud.com^$all ! https://github.com/uBlockOrigin/uAssets/pull/17424 ||octopus-warriors.com^$all ! https://forums.malwarebytes.com/topic/296601-syswow64cmdexe-continous-alert-from-malwarebytes/ ||doorspa.shop^$all ! malware ||official-expert.org^$document ||file-uploud.site^$document ! https://github.com/uBlockOrigin/uAssets/pull/17521 ! https://github.com/durablenapkin/scamblocklist/issues/31 ||balkeryswep.online^$all ! https://github.com/durablenapkin/scamblocklist/issues/29 ||youtubee.com^$document ||youtunbe.com^$document ||twiiiter.com^$document ||twitterr.com^$document ||goglle.com^$document ||toyrube.com^$document ||yahhhoo.com^$document ! https://forums.malwarebytes.com/topic/296944-malware-blocked-when-doing-a-google-search/ ||prodfliying.com^$all ! https://threatfox.abuse.ch/ioc/1104536/ ||js.msedgeupdate.com^$all ||msedgeupdate.com^$all ! https://github.com/uBlockOrigin/uAssets/pull/17651 ! https://app.any.run/tasks/00d5d80b-3924-4421-8780-7ba796d7b825 ! https://tria.ge/230420-anfn8agb9z/behavioral1 ||github.com/MasnyBen420/Nitro-Generator-Python-2023^$all ||portalproveedores.com.mx^$all ! https://threatfox.abuse.ch/ioc/1063263/ https://threatfox.abuse.ch/ioc/1028975/ ||45.15.157.131^$all ! https://github.com/durablenapkin/scamblocklist/issues/36 ||ledgerlivewallets.com^$all ||nanoweb3-rarityledgertech.com^$all ||ledger-liveweb3app.com^$all ||shop-nanox.com^$all ||ledgerlive.mobi^$all ||ledgerlives.live^$all ||ledgers.network^$all ! https://github.com/mitchellkrogza/phishing/pull/225 ! https://blog.morphisec.com/in2al5d-p3in4er ||cv-builder.site^$all ||siamaster.com.mx^$all ||chatgptex.us^$all ||45.15.156.182^$all ||45.15.156.70^$all ||45.132.106.77^$all ||199.127.62.3^$all ||94.142.138.73^$all ||94.142.138.84^$all ||94.142.138.218^$all ||199.247.24.79^$all ||5.34.180.208^$all ! https://github.com/uBlockOrigin/uAssets/pull/17767 ! https://www.reddit.com/r/uBlockOrigin/comments/1304khl/badware_sites/ ||actionclassicgames.com^$document ||allin1convert.com^$document ||allinonedocs.com^$document ||anytimeastrology.com^$document ! https://github.com/uBlockOrigin/uAssets/blob/fc2d7bd065b3e79d945fcfdc0da73ff33f6ea089/filters/badware.txt#L3038-L3044 (hopefully I understood the license right, if not, I can delete this) ||myway.com^$all ! https://forums.malwarebytes.com/topic/297334-our-company-website-shows-riskware-from-a-different-domain/ ||life.judyfay.com^$all ||xjquery.com^$all ! https://www.virustotal.com/gui/url/f68044fcf6f1a22b4b1d06cae0dddefa4bd7282377ba16a2a6222379414a6073/community ! https://app.any.run/tasks/ea625e50-b943-4e69-ae48-03231219b07f (my analysis) ||139.224.13.184^$all ! https://www.bleepingcomputer.com/news/security/new-atomic-macos-info-stealing-malware-targets-50-crypto-wallets/ ||amos-malware.ru^$all ! https://app.any.run/tasks/5fddd235-4433-4376-9a75-39a28b018f6b ||realtorstrust.com^$all ! https://app.any.run/tasks/d40fc871-4942-4acd-8d6a-d8f4baae1f32 ||kuyhaa-me.id^$all ||omnicad.click^$all ||oppodlfile.click^$all ||bit.ly/40K0ug0^$document ||mediafire.com/file/ztx9xrm611hw3z1/NewSetup_Use_2023_Password.rar/file^$all ||37.220.87.68^$all ! https://github.com/durablenapkin/scamblocklist/issues/37 ! (my analysis) https://app.any.run/tasks/21412739-6fc1-4a9e-9b35-ad2d8224bb46 ! (my analysis) https://tria.ge/230502-nebwkaag58/behavioral1 ! (my analysis) https://www.hybrid-analysis.com/sample/d293ec55b0425e8731b17b814b5d9c9abe73b9ee10f8ae808f1ec0f4a969aebe ||youtubebplan.com^$all ||www.youtubebplan.com^$all ! https://forums.malwarebytes.com/topic/297425-annoying-outbound-443-malware/ ||87cibrsm009t2lj.buzz^$all ! https://github.com/hagezi/dns-blocklists/issues/1003 ! https://forums.malwarebytes.com/topic/297570-phishing/ (account required) ||0.drroham.ir^$all ||drroham.ir^$document ! shared by ryan ||updatefreecompletelytheproduct.vip^$all ! https://github.com/hagezi/dns-blocklists/issues/1013 ||revanced.io^$all ! https://www.reddit.com/r/uBlockOrigin/comments/139u3yf/malicious_domain_to_block_used_by_hacked_manga/ ||gdpr.web0.eu^$3p ! https://forums.malwarebytes.com/topic/297655-malware-and-popup-in-my-pc/?do=findComment&comment=1566331 ||threatdetect.org^$all ! https://www.malwarebytes.com/blog/threat-intelligence/2023/05/fake-system-update-drops-new-highly-evasive-loader ||qqtube.ru^$all ||194.58.112.173^$all ||activessd.ru^$all ||chistauyavoda.ru^$all ||xxxxxxxxxxxxxxx.ru^$all ||activehdd.ru^$all ||oled8kultra.ru^$all ||xhamster-18.ru^$all ||activessd6.ru^$all ||activedebian.ru^$all ||shluhapizdec.ru^$all ||04042023.ru^$all ||clickaineasdfer.ru^$all ||moskovpizda.ru^$all ||pochelvpizdy.ru^$all ||evatds.ru^$all ||click7adilla.ru^$all ||92.53.96.119^$all ||103.195.103.54^$all ||94.142.138.218^$all ||193.233.20.29^$document ! https://www.virustotal.com/gui/file/dd45a0f40e75b051871fefd4ddb1ce6dcf130d4e172010c0753e01c1a6523666/relations ||zexeq.com^$all ||colisumy.com^$all ! (message on OALabs server) https://discord.com/channels/885624530071085097/885624530519871541/1106068675313815662 ! https://www.virustotal.com/gui/url/4cbb55b62fe8bc2acdaa79d3c4fd3a6d33c0d5eed287bbe655fc117c6bdeb0a3/community ! (my analysis) https://app.any.run/tasks/2de7c1a5-bfe4-4b48-a1e5-b7d8c059cbd0 ! (my analysis) https://tria.ge/230512-xhsg6agd4v/static1 ||0ffice-3-6-5.ltd^$all ||87.121.221.106^$all ! https://tria.ge/230512-tj6jmadg34 ||37.220.87.66^$all ||45.9.74.99^$all ! ----- Scams ----- ! Fake websites pretending to be related to uBlock Origin - the real uBlock Origin is at https://github.com/gorhill/uBlock ! See https://github.com/gorhill/uBlock/wiki/Badware-risks#ublockorg ! Also blocked by uBlock Origin badware and DandelionSprout antimalware ||ublock.org^$document ||chrome.google.com/webstore/detail/ublock-free-ad-blocker/epcnnfbjfcgphgdmggkamkmgojdagdnn^$document ||chrome.google.com/webstore/detail/ublock/epcnnfbjfcgphgdmggkamkmgojdagdnn^$document ! Malware ! https://www.virustotal.com/gui/url/723d30dcc93ee90f8f04b5cc3c5d07492338c41f7aa62fb2723c7d8b91537338/community ! https://github.com/uBlockOrigin/uAssets/issues/5854 ||ublockerext.com^$all ! This domain has been used for typosquatting, malware, phishing, and scams (redirects to other scam/malware sites as of 17/9/2021) ! curl on 9/5/2021 shows it is still online ! https://www.siteadvisor.com/sitereport.html?url=quatrefeuillepolonaise.xyz ! https://www.virustotal.com/gui/url/7319b37aff351dc0f0e71dba194b5f21972be9ad072b955a35d27d5af359d5fa/community ! https://www.virustotal.com/gui/domain/quatrefeuillepolonaise.xyz/detection ! https://safeweb.norton.com/report/show?url=quatrefeuillepolonaise.xyz ! https://www.fortiguard.com/webfilter?q=quatrefeuillepolonaise.xyz ! https://quttera.com/detailed_report/quatrefeuillepolonaise.xyz ! https://www.urlvoid.com/scan/quatrefeuillepolonaise.xyz/ ! https://www.mywot.com/en/scorecard/quatrefeuillepolonaise.xyz ! https://github.com/DandelionSprout/adfilt/issues/188 ||quatrefeuillepolonaise.xyz^$all ! Related to above ! https://github.com/DandelionSprout/adfilt/issues/188 ! https://github.com/DandelionSprout/adfilt/commit/0af1431c8f4cf45e9c27e359edf777b0c9bfa153 ||extragifis.site^$all ||captcharesolving-universe.com^$all ||5.8.47.3^$all ||5.8.34.26^$all ! https://www.virustotal.com/gui/ip-address/5.8.34.26/relations ! https://github.com/DandelionSprout/adfilt/issues/188 ||captcharesolver.com^$all ! https://www.virustotal.com/gui/url/136909c39798eacfc82e58459684619a4b89de8d3dedbe5a3010c5152b670328/detection ! https://github.com/iam-py-test/Assets-001/blob/main/goglenet%20malware ||cpmstatsart.com^$all ! https://github.com/DandelionSprout/adfilt/issues/188#issuecomment-848834204 ||instantfwding.com^$all ||103.224.182.251^$all ||catnip.de^$all ||trafcenter.us^$all ||fwdservice.com^$all ! https://securitytrails.com/list/ip/5.8.47.3 ! https://safeweb.norton.com/report/show?url=gamesex.fun ! https://www.siteadvisor.com/sitereport.html?url=gamesex.fun ! https://www.virustotal.com/gui/url/7bedfdd70bd23869a3598186270bcca9e64870842fb95df46da9ed5519e0b41c/detection ||gamesex.fun^$all ! just redirects to another blocked domain ! https://github.com/DandelionSprout/adfilt/issues/188 ||kmip.net^$all ||iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com^$all ||204.11.56.48^$document ||goldprize.xyz^$all ! More scam stuff on 27/9/2021 ||smartcaptchasolve.top^$all ||cloud-repos.store^$document ||retailproductsusa.com^$all ||www.retailproductsusa.com^$all ! Even more scams - https://github.com/DandelionSprout/adfilt/issues/188#issuecomment-931700117 ||findanswersnow.net^$document ||two.findanswersnow.net^$document ||diabasewoodhouse.xyz^$document ||signupandturnyourscreenoffsafepowernow.date^$document ||www.signupandturnyourscreenoffsafepowernow.date^$all ||best-prizes.life^$document ||jsontdsexit.com^$document ||therewardboost.com^$all ||t.therewardboost.com^$all ||natnlconsmrctr.com^$document ||lore.deduce.com^$document ||d2m2wsoho8qq12.cloudfront.net^$document ||jpgtrk.com^$document ||pnghst.com^$document ! domains which gogle[.]net redirects to on 17/10/2021 ||positivestar.org^$all ||securysearchapp.com^$document ||www1.securysearchapp.com^$document ||mydealprotection.com^$document ||www.mydealprotection.com^$document ! on the same IP & just by looking at them, I can tell they are not legit ||intunes.com^$document ||pple.com^$document ||gimal.com^$document ! 19/11/2022: https://sitecheck.sucuri.net/results/get-the-prize-ht3.live ||get-the-prize-ht3.live^$document ! https://github.com/uBlockOrigin/uAssets/issues/9344 ! https://github.com/iam-py-test/Assets-001/tree/main/uiz.io_scam ||uiz.io^$document ! More scam domains found via redirects when clicking on the fake recaptcha ! https://www.virustotal.com/gui/url/73dae7d74bcdc9099a54b75b904cc45995d85534a313ad65fcc4d9e401b34607/detection ||rewardsavenue.net^$all ! https://www.virustotal.com/gui/url/d6745ce01da185054bd2125858e75445783976de0e5fa4a445284243830070e7/detection ||rewardsgiantusa.com^$all ! https://www.virustotal.com/gui/url/9edd33c7a370ba96bf3a7682193e67538984eab9d1b719c2f3042599a4d3d1d5/detection ||rewardgiantztesters.com^$document ! https://github.com/blocklistproject/Lists/issues/513 ||gooooooooogle.com^$all ! https://github.com/iam-py-test/investigations/blob/main/2021/10/26/1.md#domains ||p185689.mybetterdl.com^$all ||r-tb.com^$document ||feed.r-tb.com^$all ||t.r-tb.com^$all ||cdn.hoood.info^$document ||barah-flo.com^$document ||beta-one.net^$all ||ny-t.r-tb.com^$all ||pisism.com^$document ||security-scanner.xyz^$all ! https://github.com/iam-py-test/investigations/blob/main/2021/10/26/1.md#html-captures ||news-back.org^$document ||www1.news-back.org^$all ||www2.news-back.org^$all ||www3.news-back.org^$all ||www4.news-back.org^$all ||www5.news-back.org^$all ||www6.news-back.org^$all ||www7.news-back.org^$all ||www8.news-back.org^$all ||www9.news-back.org^$all ||www10.news-back.org^$all ! https://github.com/DandelionSprout/adfilt/pull/289 ||gogles.com^$all ||flexroll.online^$document ||army-glo.scrollingsystem.com^$document ! ||www.kqzyfj.com^$all ! ||kqzyfj.com^$all ! ||cj.dotomi.com^$all ||mcafee12.tt.omtrdc.net^$document ! https://www.virustotal.com/gui/ip-address/70.32.1.32/relations ||clk.rtpdn14.com^$document ||cd.org^$document ! https://github.com/uBlockOrigin/uAssets/issues/9848#issuecomment-907855092 ! https://www.virustotal.com/gui/url/1671d2b14f2baed1438176929ba9908270f26e41f7b17c0ce0a85bd5e9c20f35/detection ! https://www.virustotal.com/gui/url/0eca172b2f35f81e0f222dbdf261a100c7897f734c7ba43920b67c4cddd6f8c9/detection ||get-cracked.com^$all ! More related domains/urls ||tinyurl.com/gp84uz2^$document ||www.mediafiire.com^$all ||mediafiire.com^$document ||d1xkyo9j4r7vnn.cloudfront.net^$all ||www.onlinepromotionsusa.com^$all ||onlinepromotionsusa.com^$all ||w.promotionsonlineusa.com^$all ! https://github.com/uBlockOrigin/uBlock-issues/issues/1774 ! https://github.com/iam-py-test/investigations/blob/main/2021/10/28/1.md ||slobodapatient.me^$all ||www.slobodapatient.me^$all ||ppcnzi.xyz^$document ||www.ppcnzi.xyz^$document ||eritokyo.jp^$document ||www.cpanlyzr.co^$all ||cpanlyzr.co^$document ||rewardzoneusa.com^$all ||contact.rewardzoneusa.com^$all ||reward3spot.com^$all ||www.reward3spot.com^$all ||order-safely.com^$document ||www.order-safely.com^$document ||followlink.click^$document ||us.systemupdatecontrol.com^$all ||systemupdatecontrol.com^$all ||ryderftv.co^$document ||www.ryderftv.co^$all ||publishers.revenueuniverse.com^$document ! https://scammer.info/t/crypto-scam/82425 ||gemini-horoscope-astrologer.business.site^$all ! https://scammer.info/t/i-dont-need-that-knife-discord-scam/82776 ! https://scammer.info/t/multiple-fake-discord-websites/82773 ! https://scammer.info/t/noteit-scam/82283 ||pautils.online^$document ! https://scammer.info/t/your-computer-is-infected-scan-for-free-now-scam/81989 ! https://scammer.info/t/usps-spam/83368 ||www.wutaideng.wang^$document ! https://scammer.info/t/crypto-scam/83168 ||gemini-telephonecompany.business.site^$document ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-974886953 ||e.datingmap.top^$all ||datingmap.top^$all ||tonightshookup.com^$document ||members.tonightshookup.com^$all ||t.tonightshookup.com^$all ||yourladiefun.life^$all ! Scam and fake Roblox hacks ||gghacks.com^$all ! Scam websites opened - put in redirect order ||armanfiles.com/show.php?cl=true&l=971524&u=228373&id=23694$all ||www.rewardsgiantusa.com^$all ! Asks for personal data (name,address,birthdate,gender,email), claims you will get a "reward", never provides hack ||promotionsonlineusa.com^$all ||r.promotionsonlineusa.com^$all ! More scams ||displayoptoffers.com^$all ||www.displayoptoffers.com^$all ||www.yrxtrk.com^$document ||play.sweepstakesalerts.com^$document ||sweepstakesalerts.com^$document ||www.stash.com^$document ||www.qualityhealth.com^$document ||qualityhealth.com^$document ||consumerproductsusa.com^$document ||www.consumerproductsusa.com^$document ! https://github.com/iam-py-test/investigations/blob/main/2021/11/21/1.md ||yasir252.com^$all ||www.yasir252.com^$all ||safelink.kadal.club^$document ! https://forums.malwarebytes.com/topic/285824-malicious-disk-image-file-iso/ --> https://www.virustotal.com/gui/url/20ef8f13f6ed4f2ad0f25c4d98c5ba213223dd95d18ae31494b5df4305fc7a6c ||iclickcdn.com^$all ||bedrapiona.com^$all ||dozubatan.com^$all ||onmarshtompor.com^$all ||chultoux.com^$document ||yonhelioliskor.com^$document ||ptauxofi.net^$document ||betshucklean.com^$document ||buncoswosh.com^$document ||b58ncoa1c07f.com^$document ||t.avroute01.com^$document ||gammamkt.com^$document ||leadgentrk.com^$document ||chirkacylal.com^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/122055 ||shoksips.com^$all ! https://scammer.info/t/bank-scams-in-greece/82743 ! https://scammer.info/t/faremart/82671 ||www.faremart.com^$document,image ||faremart.com^$document ! https://scammer.info/t/please-report-these-sites/78244 ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-977912975 ! https://www.tv2.no/nyheter/14368524/ ||alexstewartinternationalltd.rw^$all ||vps.re^$all ! https://www.tek.no/i/wOVv0o/ ! https://www.youtube.com/watch?v=iQiVH533ncM ||avengeradblocker.com^$document ||poweradblocker.com^$document ! https://github.com/iam-py-test/investigations/blob/main/2021/11/25/1.md ||steamkeygiveaway.net^$all ||fasterfiles.net^$all ||inteledirect.com^$all ||turapport-strience.icu^$document ||americanwinnerscircle.com^$all ! https://github.com/uBlockOrigin/uAssets/pull/10599#issuecomment-979356358 ||yunosurveys.com^$all ! https://github.com/iam-py-test/investigations/blob/main/2021/11/28/1.md ||gospelchor.info^$document ||reykijnoac.com^$document ||totalnicefeed.com^$all ||omnatuor.com^$all ! https://github.com/iam-py-test/investigations/blob/main/2021/11/28/2.md ! same as above - hxxpx[:]//momupd[.]enuguhomes[.]com/download-winrar-crack/ ! https://scammer.info/t/youtube-bot-roblox-scam-49-gift-cards/84540 ! https://scammer.info/t/youtube-bot-roblox-scam-48-gift-cards/84539 ! https://scammer.info/t/youtube-bot-roblox-scam-47-gift-cards/84538 ! https://scammer.info/t/youtube-bot-roblox-scam-46/84537 ! https://scammer.info/t/youtube-bot-roblox-scam-45-gift-cards/84536 ! https://scammer.info/t/youtube-bot-roblox-scam-44/84535 ! https://scammer.info/t/youtube-bot-roblox-scam-43/84534 ! https://scammer.info/t/youtube-bot-roblox-scam-42/84533 ! https://scammer.info/t/youtube-bot-roblox-scam-41/84532 ! https://scammer.info/t/youtube-bot-roblox-scam-39/84530 ||freeco.xyz^$all ! https://scammer.info/t/youtube-bot-roblox-scam-38/84529 ! https://scammer.info/t/youtube-bot-roblox-scam-37/84528 ||modgjn.uno^$all ! https://scammer.info/t/youtube-bot-roblox-scam-36/84527 ! https://scammer.info/t/paypal-phishing-12/84592 ||golemgreat122.000webhostapp.com^$all ! https://scammer.info/t/microsoft-phishing-1/84589 ||aceelectricalny.com^$all ! https://scammer.info/t/discord-nitro-generator-7/84570 ||www.appninjas.xyz^$all ||appninjas.xyz^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-986306768 ||chess-progress.ru^$document ||ouhastay.net^$all ! https://forums.malwarebytes.com/topic/281514-scam-websites/ ||812138.com^$document ||dk-video.xyz^$document ||dj-video.xyz^$document ||gi-video.xyz^$document ||hj-video.xyz^$document ||havmoney.xyz^$document ! https://github.com/uBlockOrigin/uAssets/pull/10804 ! https://bbs.kafan.cn/thread-2221500-1-1.html ||88btbtt.com^$all ||musmentportal.com^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-988127908 ! https://www.tek.no/i/lVeQAe/ ! https://www.nkom.no/aktuelt/ikke-trykk-pa-lenker-i-sms--for-du-er-helt-sikker/ ||eccolabgroup.com^$all ||galerijajava.ba^$all ||p-stn.net^$all ! https://borsen.dagbladet.no/74020239/ ! scam dating sites ||casualdating.com^$document ||www.iflirts.com^$document ||iflirts.com^$document ! fake notification scams ||ourcoolstories.com^$all ||javsidblog.com^$document ||link-split.com/view/tnAhAq30D4^$document ||cagothie.net^$document ! https://github.com/iam-py-test/investigations/blob/main/2021/12/9/1.md ||0s.click^$document ||0ffer.icu^$document ||0pen.online^$document ! https://github.com/iam-py-test/investigations/blob/main/2021/12/12/1.md ||onlineenglishteacher.co^$document ||www.fling.com^$document ! either redirects to random websites or scams ||lekms.com^$document ||yourcoolfeed.com^$all ! fake MediaFire websites ||songlos.com^$document ||royaltees.co^$all ||findes.co^$document ||vitafox.findes.co^$document ||supersong.nl/upload/6277.rar^$all ||monkeyselite.tonick.co^$document ||kitago.info^$all ||herezfile400.weebly.com^$all ||hereeup447.weebly.com^$all ||yaihxj.knewdayfull.top^$all ||knewdayfull.top^$document ||4lgx4.bemobtrcks.com^$document ||hugewifesilver.top^$document ||ge6s.com^$all ||sitexchange.causeart.co^$all ||yellowmother374.weebly.com^$all ||myhayward.us^$all ||tiborola.info^$all ||artbistro.us^$all ||myhypeposts.com^$all ||onlynewstoday.com^$all ||payments4u.org^$all ||freeiphone.info^$all ||static.cdnativepush.com/contents/s/7f/95/8c/2488823c2d95d7162ff723c840/01192333514141.png^$all ||static.cdnativepush.com/contents/s/04/d8/68/c0dd305c8a79b01ae4f24672ac/01477976446043.png^$all ||flummer.geppe.us^$all ||tuckets.moanas.us^$all ||static.cdnativepush.com/contents/s/b8/4e/1d/153294973f0fff7258e8f43d7c/0647024544646.jpeg^$all ||static.cdnativepush.com/contents/s/d2/3f/93/7fe562c37a9a7a6af5df460ee7/0490618650236.png^$all ||ssp-creatives.askprivate.com/prod/images/33242825/en/69dcb41b14c0449dbc67b998ca5b0c94.jpeg^$all ||ssp-creatives.askprivate.com/prod/icons/33242825/en/8bb2cd79c7dd45eb8075d0127f8d8331.jpeg^$all ||zxzfic.weebly.com^$all ||iminna.info^$all ||bloghunter.aaguatemala.org^$all ||abated-hamate.xyz^$all ||api.pushnami.com/scripts/v2/pushnami-sw/5e4bf7d0e7585f1f723a7243^$all ||cleveradult148.weebly.com^$all ||forexever451.weebly.com^$all ||ourcoolposts.com^$all ||bitnew695.weebly.com^$all ||www.iztzo.com^$all ||iztzo.com^$all ||gomusic.info^$document ||myprotectionsurveys.com^$document ||www.myprotectionsurveys.com^$document ||ouphouch.com^$all ! https://github.com/iam-py-test/investigations/blob/main/2021/12/14/2.md ! https://github.com/iam-py-test/investigations/blob/main/2021/12/14/1.md ||onemacusa.net^$all ! random .xyz domains which just don't look legit ||cp2s.xyz^$all ||80302.xyz^$all ! https://github.com/DevSpen/links/pull/3 ||d13nu0oomnx5ti.cloudfront.net^$all ||dgu9g3a2kzqx2.cloudfront.net^$all ||d13pxqgp3ixdbh.cloudfront.net^$all ! https://scammer.info/t/important-security-message-888-498-2847/85668/2 ! https://scammer.info/t/snapchat-spam-click-link-don-t-link-investigate-please/85620 ||nvoddn.hotglrls.net^$all ||hotglrls.net^$document ||hushlove.com^$document ||jucydate.com^$document ||w17veh63m7o8s4ncihd1jq8i.people-wet.com^$document ! https://scammer.info/t/stupid-ass-scammers-lol/85601 (support[@]clickgadgets[.]club) ||bit.ly/3DWxMNv^$all ||clickgadgets.club^$all ! scam website with only fake links ||crackthisgame.com^$document ||pseepsie.com^$document ! pretty sure this is a porn scam ||www.carnalcams.com^$document ||carnalcams.com^$document ! the register form doesn't do anything after entering data, just redirect back to the start ||fbookhookups.com^$document ||fuckpal.com^$document ! seen in scam ads ||fuck-me.io^$document ! https://scammer.info/t/youtube-comment-spam/85737 ||0.acceptww.com^$all ||acceptww.com^$all ||8.acceptww.com^$all ! https://github.com/DandelionSprout/adfilt/issues/288 ||discordap.com^$all ||forwrdnow.com^$document ||7lyonline.com^$document ||get.safelyonline.net^$all ||safelyonline.net^$document ||browse-safe.net^$document ||get.browse-safe.net^$all ||btpnative.com^$document ||besty-deals.com^$all ||data-px.services^$document ||live.newsvot.com^$document ||adalgard-wol.com^$all ||secure-access-981cd52a6hqpm8e2.gate23.xyz^$document ||ny-feed.r-tb.com^$document ||clk.hosting-redirect.com^$document ! https://scammer.info/t/cyberpunk-2077-fake-generator/85772 ||groups.google.com/g/cyberpunk-steam-key-generator-working-check-now-2022?$document ||groups.google.com/g/cyberpunk-steam-key-generator-working-check-now-2022/$document ||ragamer.com^$document ! https://scammer.info/t/discord-nitro-scam-10/85771 ! https://scammer.info/t/discord-nitro-scam-1/85706 ! https://scammer.info/t/indian-kotak-mahindra-bank-scam/85760 ||raam-and-laxman98.000webhostapp.com^$all ! https://scammer.info/t/nitro-is-handed-there-for-free-scam-7-927-324-30-54/85763 ||gift-discords.com^$all ! https://scammer.info/t/discord-nitro-scam-8/85739 ! https://scammer.info/t/discord-nitro-scam-6/85710 ! https://scammer.info/t/discord-nitro-scam-7/85709 ! https://scammer.info/t/discord-nitro-3/85708 ! https://scammer.info/t/discord-nitro-scam-2/85707 ! possible Tech Support Scam ||installmysecurity.com^$document ! "press allow to continue" ||shortnewsinfo.com^$document ! https://scammer.info/t/mcafee-phish/83725 ||securefirst.us-east-1.linodeobjects.com^$all ! https://github.com/uBlockOrigin/uBlock-issues/issues/1774#issuecomment-1000722777 ||viewty.xyz^$all ||landing.marketstm.com^$document ! https://scammer.info/t/airdrop-discord-nitro-with-steam-scam-7-977-525-68-47/86156 ! https://scammer.info/t/1-month-nitro-for-free-take-it-scam/86166 ||discrode-gifte.club^$all ! https://scammer.info/t/kohlsshoppergiftopportunity-scam-e-mail/86102 ! https://github.com/DevSpen/scam-links/pull/11 ! https://forums.malwarebytes.com/topic/282206-scam-websites/ ||hu-video.xyz^$all ||bs-video.xyz^$all ||xa-video.xyz^$all ||video-cd.xyz^$all ||gm-video.xyz^$all ||iamoney.xyz^$all ||vbmoney.xyz^$all ||obmoney.xyz^$all ||kcmoney.xyz^$all ||dcmoney.xyz^$all ||lstmoney.xyz^$all ||uamoney.xyz^$all ||tbmoney.xyz^$all ||ecmoney.xyz^$all ||gcmoney.xyz^$all ||xosi.ru/shop-wallets/$document ! https://forums.malwarebytes.com/topic/282206-scam-websites/?do=findComment&comment=1494794 ||iglookup.com^$document ||www.iglookup.com^$document ! https://www.virustotal.com/gui/ip-address/172.67.210.43/relations ! 'click allow to continue' scam which redirects to random subdomains when the premission is blocked. Also redirects to TotalAV at the end ||8db3p.leadoesnotknowaboutkukuriko.xyz^$all ||leadoesnotknowaboutkukuriko.xyz^$all ! fake antivirus message ||mcafee5.www-safety.com^$all ||weledying-jessed.com^$all ! https://forums.malwarebytes.com/topic/282376-website-giving-spammy-popups/ ||tepspr.com^$all ||rplnd10.com^$all ! https://scammer.info/t/youtube-bot/86668 ||kingapp.store^$all ||downloadlocked.com^$document ||advantagecircles.com^$document ||iwin.rewardsadvisor.com^$all ||rewardsadvisor.com^$document ! found this while looking for Memz samples - https://user-images.githubusercontent.com/84232764/149638659-8e0e9e91-8d02-4fff-bd0f-af8423550777.png (hxxps://verify-me.club/2004cbf?s1=down1) ||tinyurl.com/45tkeyep^$all ||verify-me.club^$all ! still alive as of 11/11/2022 - https://app.any.run/tasks/f0474f51-6b14-432b-b1f0-98a1137e359c ||verifyme.za.com^$all ||letmik.com^$all ||c.atandmouse.com^$all ||g.atandmouse.com^$all ||atandmouse.com^$document ! "press allow to continue" popup ad ||masstech.info^$all ||windows-secureit.com^$all ! fake game cheat download buttons redirecting to "press allow to continue" and Norton ! also https://forums.malwarebytes.com/topic/287349-my-google-browser-could-be-infected-need-help-removing-it/ ||anonmods.com^$all ||freychang.fun^$all ! fake discord Nitro generator ||us.doctorpost.net^$document ! another fake Nitro generator ||pastebin.com/qwUbwYbq^$all ||richinfo.co^$all ||contact.uplevelrewards.com^$document ! fake download website ||tonxis19.amebaownd.com^$all ||hzaowj3.berilata.ru^$document ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1025251202 ! https://github.com/uBlockOrigin/uAssets/issues/11518 ||libertatea.net^$document ! fake human verification scam ! start form - reported for abuse ||q.promotionsonlineusa.com^$all ||reward4spot.com^$all ||www.reward4spot.com^$all ! fake download buttons with popups ||cracked-games.org^$all ||prksism.com^$all ! https://www.virustotal.com/gui/ip-address/18.210.201.44/relations ||antirobotsystem.com^$document ! fake 'no human verification' discord nitro generator ||huffduffer.com^$all ||issuu.com/free-discord-nitro-codes^$document ! still alive as of 11/11/2022 - https://app.any.run/tasks/c4a6e7d3-21da-4274-b262-e08dee1bb3cd ||meine.belohnung24.com^$document ||ideen.belohnung24.com^$document ||iphone.belohnung24.com^$document ! another discord Nitro scam ||linktr.ee/FreeDiscordNitroGift^$all ! https://scammer.info/t/install-required-trojan/90099 ! https://www.youtube.com/watch?v=0P4OkPQP7C4 ! "press allow to continue" ||www.kuyhaa-mee.com^$all ||kuyhaa-mee.com^$all ||waystriling.com^$all ||nze0xw.waystriling.com^$all ||581358.waystriling.com^$all ||qyt8pi.waystriling.com^$all ||xiiowt.waystriling.com^$all ||www.upload-4ever.com^$document ||upload-4ever.com^$document ||worldcoolfeed.com^$all ! Fake discord nitro (still alive as of 11/11/2022 ||myget.org/feed/discord-nitro-hack/package/nuget/Free-discord-nitro-codes-2021^$document ||lucymods.com^$all ||gluegames.xyz^$all ! another fake site ||www.aldvingomes.com^$document ||aldvingomes.com^$document ||codegen.fun^$all ! fake discord nitro ||getmecodes.xyz^$all ||filevortex.com/1029130^$all ! https://app.any.run/tasks/73236419-3190-47fa-81f0-8a31bcf48a5b ||minutewinner.com^$document ! Yet another fake discord generator ||jellycheat.com^$all ! https://scammer.info/t/paste-your-discord-nitro-scams-here/89880/2 ||discord.birth/kjqsSQDF4qs9f4sK456ds7^$document ! https://www.reddit.com/r/computerviruses/comments/swrrx8/used_a_youtube_to_mp3_downloader_today_and_these/ ||unrelered.xyz^$all ! https://twitter.com/iam_py_test/status/1496259425493225472 ||sites.google.com/view/groundworkssolutions/contact-us^$all ||sites.google.com/view/groundworkssolutions/^$all ||sites.google.com/mytv/maintenance^$all ! all the RARs just contained one zero-byte file, so just blocking the confirmed scam part of it (start URL hxxpx[://]bayanhuu[.]com/microsoft-office-2016-full-download[/] ||habitum.xyz^$all ||news-easy.org^$all ! https://github.com/uBlockOrigin/uAssets/issues/11157#issuecomment-1049093327 ||sideload.cc^$all ! survey scams ||credly.com/users/free-discord-nitro-codes/badges^$document ||psp-haxors.com^$all ||gripclicks.com^$all ! https://app.any.run/tasks/a3abdf35-fa15-4115-91fb-cfc5c1e45ff4 ||omnioffers.com^$document ! https://www.virustotal.com/gui/url/98f0186f4d20f3138a4e05f58369019cee8e88153578e3d729b716d8b57c0857/community ||k6pay.top^$document ||h6pay.top^$all ||g6pay.top^$all ||n6pay.top^$document ||c6pay.top^$all ||190.115.26.220^$document ! typical fake discord nitro generator -> survey scams ||buymeacoffee.com/GamingZonebd/free-discord-nitro-codes-generator-2022-latest-working-100^$document ||gamecodeclaim.com^$all ||www.gamecodeclaim.com^$all ! hxxpx[://]consortiumrecords[.]co/free-tools/download-microsoft-office-365-product-key-crack-updated/ ||foradream.top^$all ||h.therewardboost.com^$all ||b.therewardboost.com^$all ||i.therewardboost.com^$all ||s.therewardboost.com^$all ||c.therewardboost.com^$all ||w.therewardboost.com^$all ||z.therewardboost.com^$all ||g.therewardboost.com^$all ||o.therewardboost.com^$all ||u.therewardboost.com^$all ||v.therewardboost.com^$all ||y.therewardboost.com^$all ||m.therewardboost.com^$all ||x.therewardboost.com^$all ||d.therewardboost.com^$all ||j.therewardboost.com^$all ||p.therewardboost.com^$all ||f.therewardboost.com^$all ||a.therewardboost.com^$all ||e.therewardboost.com^$all ||r.therewardboost.com^$all ||k.therewardboost.com^$all ||n.therewardboost.com^$all ||l.therewardboost.com^$all ||q.therewardboost.com^$all ||www.therewardboost.com^$all ! porn scam? asks for personal info and gets stuck in a loop ||dream-singles.com^$document ! https://scammer.info/t/take-it-discord-gift-7-0251200521/92613 ! https://scammer.info/t/discord-has-gifted-you-nitro-for-1-month-scam-3/92326 ! even more fake "human verification" ||speedboostpc.com^$document ||unlimitedtools.website^$all ! redirects to already blocked sites ||coub.com/stories/946163-free-discord-nitro-codes-list-all-valid-with-no-human-verification^$document ! scam browser extension ||chrome.google.com/webstore/detail/discord-free-nitro-free-d/ihdnmkbgjnpbkdcammpfokdmncnicfki^$all ||unlock3r.net^$all ||nitroboostcord.blogspot.com^$all ||appbase.best/dboost^$all ! poped up while running malware ! looks very shady ||www.taixiu.bet^$document ||taixiu.bet^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/111843 ||cybop.net^$document ! https://forums.malwarebytes.com/topic/284608-crypto-giveaway-scams/ ||x2-shiba.org/shiba/giveway.php^$document ||ark-today.com/ethgiveaway.html^$document ||ark-today.com/btcgiveaway.html^$document ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1060031240 ||webcams-chat.com^$all ||mydirtytinders.com^$all ! yet another fake Discord Nitro Generator ||www.everydaywinner.com^$document ||everydaywinner.com^$document ||generatekey.xyz^$all ||e.9nl.it^$document ||www.monumented.com^$document ! looks like Fox News, to promote something which is probably a scam ||www.livingyourbestlife.co^$document ||livingyourbestlife.co^$document ||foxnewsweatherdaily.com^$document ! https://www.virustotal.com/graph/gae4b79eddfec44439142fec34bf90890609e118340984dbd855b515b1be9cfc9 ||holgerstrehlow.de/discord-nitro-code-generator-no-human-verification.html^$document ! GH? ||github.com/faisalali734/$document ! starts at hxxpx[:]//triunetech[.]co/windows-software/winrar-64-bit-for-windows-10-with-crack-free-download/ ! auto-redirect from hxxpx://createwithkrista[.]co/windows/winrar-for-windows-10-64-bit-free-download-with-crack/ ||outto.us^$document ! hxxpx://thecornermarket[.]co/free-crack/winrar-64-bit-download-crack/?utm_referrer=https%3A%2F%2Fwww.bing.com%2F ||merchd.rip^$all ! the rest is blocked ||buymeacoffee.com/getcode/discord-free-nitro-generator-no-human-verification-survey^$all ! YAFNG (Yet another fake Nitro generator) ||nitromexyz.xyz^$all ||grptrac.com^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1074966240 ! https://github.com/blocklistproject/Lists/issues/693 ! https://app.any.run/tasks/b43b04b3-b8c1-4384-b455-961f427f5379 ||h.shyflirttalks.com^$document ! Yet Another fake discord generator ||pota.site-ym.com/global_engine/download_custom.aspx?fileid=c0f7d962-63d2-4ab2-82dd-7582a79c5ba0.pdf&filename=discord2021_gu-36.pdf&blnIsPublic=2&code=blog&sub=add^$document ||gamex.codes^$all ||consumerdigitalsurvey.com^$document ! Reddit spam --> already blocked ||reddit.com/r/Viral_Nova/comments/r1nwxg/free_discord_nitro_generator_hack_no_human/^$document ! Already blocked ||myget.org/feed/hermesses/package/nuget/Free-Discord-Nitro-Hack-No-Human-Verification^$document ||d.promotionsonlineusa.com^$all ! Also blocked ||replit.com/@discordnitross^$document ! https://forums.malwarebytes.com/topic/285189-scam-warnings-of-trojansviruses-via-web-browser-service-workers/ ||yourwebshield.com^$all ! https://app.any.run/tasks/a8a589e0-2aee-43f5-9fbe-92dc9e4bfec4 ||action.miliated.xyz^$document ||undrininvereb.info^$all ! https://app.any.run/tasks/3d80ad3d-3a47-46ae-a389-c0f9122ee2e2 ! https://app.any.run/tasks/94987721-2dbd-4705-8d87-561d0fc546c4 ! https://twitter.com/MBThreatIntel/status/1509956416311742464 ! https://forums.malwarebytes.com/topic/285210-hacked-discord-account-through-malware/?do=findComment&comment=1509000 ! https://app.any.run/tasks/7bfb3be3-ba73-4db5-b739-50eb76ea0e0a ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1094359634 ||disq.us/p/2o9pztr^$document ||disq.us/p/2o9qqsl^$document ||disq.us/p/2o9pmyi^$document ||2horney-girls.life^$document ||localdates16s.com^$document ||popupchat-live.com^$document ||bhgfsfh.com^$document ! a "press allow to continue" + fake McAfee ||ultrafastultra.blogspot.com^$all ||tei.ai^$document ||forfrogadiertor.com^$all ||ourdailystories.com^$all ! Fake Discord nitro generator ||acreauburn.com/profile/kyrrwgutzctpad/profile^$document ||www.uplevelreward.com^$document ||uplevelreward.com^$all ! https://github.com/uBlockOrigin/uAssets/pull/12699 ||ziltzwebsol.online^$all ! even more fake Discord Nitro generators ||coub.com/stories/946163-free-discord-nitro-codes-list-all^$document ||t.co/5N0H4rfCgL?DiscordNitro^$all ||t.co/5N0H4rfCgL^$document ! Google Group --> Discord Nitro generator ||groups.google.com/g/discord-nitro-generator-free-2021-without-human-verification/c/1MKZDSll9uA?msclkid=7bce476ac87a11eca172b94bbb5a5692^$document ||groups.google.com/g/discord-nitro-generator-free-2021-without-human-verification/c/1MKZDSll9uA^$document ||groups.google.com/g/discord-nitro-hack-generator-no-survey-or-verification^$document ||groups.google.com/g/discord-nitro-hack-generator-no-survey-or-verification?msclkid=316e2fa7c87e11ec972f52d4d5e431fd^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/115955 ||family24rx.com^$all ||37.187.88.137^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/115960 ||onpharmvermen.com^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/115959 ||classpharmenado.com^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/115958 ||sale24-pills.com^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/115957 ||helppharmlead.com^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/115954 ||everypdnsharmacy.com^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/115953 ||happypharmproduct.com^$document ! Fake Norton screen ||static.cdnativepush.com/contents/s/69/55/b8/8c4f4e3359518f986fc7970194/0201779526711.png^$all ||static.cdnativepush.com/contents/s/6e/aa/67/726cd9cf6ea6a525bbb628cab3/0303553451413.png^$all ||littlecdn.com/apps/contents/s/e1/43/b6/8d4db17f1838a03992a72e9dbf/01412844174435.png^$all ||gapscult.com^$all ! https://blog.malwarebytes.com/web-threats/2022/05/fake-recaptcha-forms-dupe-users-via-compromised-wordpress-sites/ ! https://blog.sucuri.net/2022/05/massive-wordpress-javascript-injection-campaign-redirects-to-ads.html ! https://www.virustotal.com/gui/url/9dfce1c855c4ad3bfc6b95ec8ec80090b7eecd1cc93eab1f39e456e9cdec4496/community ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1137050700 ! https://www.tv2.no/14815077/ ! https://twitter.com/iam_py_test/status/1528858711128625152 ||supercillious.xyz^$all ! a fake MediaFire domain ||walkeryellow141.weebly.com^$all ||www.rewards-cards.org^$document ||www.dealskeeper.com^$document ||h.promotionsonlineusa.com^$document ! ads on hxxp://gestyy[.]com/es8jOv ||m.eegeeglou.com^$all ! Discord Nitro generator (fake) ||montaluce.com/profile/dybiivskjcrpe/profile^$all ||filevortex.com/show.php?cl=*&l=*&u=*&id=*^$all ||y.promotionsonlineusa.com^$document ! https://twitter.com/dubstard/status/1531883515494662144 ! ads on a site --> https://www.virustotal.com/gui/url/0871f217f945c993d8624aadd5e718e9bb740096d13fad74d58b3fc3a4fdfda0?nocache=1 ||ebaaa.xyz^$all ||uprimp.com^$document ||odaba.live^$all ! https://www.youtube.com/watch?v=se4HVtBN3bM ||postoffice-depot38.com^$document ! a random popup ||lifeimpressions.net^$popup ||d0063d.lifeimpressions.net^$document ||100800.lifeimpressions.net^$document ||fdb51a.lifeimpressions.net^$document ||3ceeb9.lifeimpressions.net^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/121544 ||trafredirtds.com^$document ! https://scammer.info/t/microsoft-popup-scam-1-888-622-9118/100449 ! https://twitter.com/iam_py_test/status/1538267982551347200 ||may8forstudents.org/free-discord-nitro-codes-list-no-human-verification/^$all ||www.easyrobuxtoday.org^$document ||robloxhackv2111.blogspot.com^$all ||appinstallcheck.com^$all ||api.pushnami.com/api/push/image/id/61f58059b94aff0015c3e03c^$all ! weird website with some Push Allow To Continue alerts - hxxpx[://]www[.]filefixation[.]com/malwarebytes-pro-crack-serial-keygen-download.html ||filefixation.com^$document ||www.filefixation.com^$document ||deal-warriors.com^$document ! yet another push-allow-to-continue scam on a YouTube downloader site ! ads ||ffe405491d.28b67b8230.com^$popup ||german0.xyz^$all ||wnprt.club^$all ||kerbians.click^$all ! redirects to scams ||sharefast572.tumblr.com^$all ||tumblr.gotohouse.top^$document ||gotohouse.top^$all ! https://www.virustotal.com/gui/ip-address/5.189.217.107/relations ! redirected to scams automatically ||loadingdead.netlify.app^$document ||down.myboxloadneed.top^$all ||myboxloadneed.top^$document ! fake download to scams ||alexisfernandez.doodlekit.com^$document ||doodlekit.gotorange.top^$document ! tech support scam - https://forums.malwarebytes.com/topic/287438-excel-macro-40-abuse-protection-prevents-opening-password-protected-files/?do=findComment&comment=1519928 ||ewebprotection.info^$document ! hxxps://iyoutubetomp4[.]com/en/ ||img.pushflow.net/creatives/11/6706/1654098151508-push-preview-img.png^$all ||img.pushflow.net/creatives/11/6706/1654098151508-push-body-img.png^$all ||img.pushflow.net/creatives/11/5543/1646745691054-push-preview-img.png^$all ||justtrck.net/run.php^$document ! https://www.virustotal.com/gui/url/d27d2c721d7ff421e35934dfc189834ae69e0a5a59712dff7dbd3a8051aa3778 ! https://app.any.run/tasks/8125703c-6fdb-49bc-a18c-918e64e83f4d ||nedaugha.buzz^$all ||jarine.co^$all ||nedukeratio.lol^$all ||lsmnz.perfordpetre.xyz^$all ||perfordpetre.xyz^$document ! Discord scam ||challonge.com/discordnitrogenerator/^$all ! https://www.virustotal.com/gui/url/ccccbdeb6be72608e84d5d566167b1264fe03a02052a2f91a2a31c389b92427c/community ! Push-Allow-To-Continue ||ptaimpeerte.com^$all ! possible tech support scam, might be dead ||vyredis.bio^$document ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1195654525 ! https://github.com/DandelionSprout/adfilt/commit/5ca8e833c7817f2d5929a4adf4792fdcbb822fc0 ||k-yw.com^$all ! McAfee-themed scam ||d3f068fvt45f1f.cloudfront.net^$all ||eastrk-dn.com^$all ! Fake giveaway ||teenmas46.tistory.com^$all ||teenymi.tistory.com^$all ||myapplesite.us^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1209782781 ! https://app.any.run/tasks/a7cc86ee-a604-4a65-968c-26c237620b2b (nsfw) ||girlluscious.com^$document ||fuckbook.tv^$document ! https://www.youtube.com/watch?v=6e7MsoThffo ||loadnova898.netlify.app^$document ||tonrino.info^$all ||new.bestageoffers2022.com^$document ||d0zi.com^$all ||rewards-cards.org^$document ||x-delivery.icu^$document ||nextsoft.icu^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1218058597 ||a2ics.eu^$all ! https://github.com/blocklistproject/Lists/issues/801, credit to https://github.com/alanjacobmathew ! https://github.com/uBlockOrigin/uAssets/issues/14569 ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1230875702 ||youtube.com/channel/UCxpXAcML6p3Ns5T9GwEK5hQ^$all ||stils-top.space^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1230939213 ||classicsgirl.com^$document ||youtube.com/channel/UCfSYzJufd7asej1mqg6NXAA^$all ! https://app.any.run/tasks/a24d7146-479f-4b90-b4d6-c9d6e73257a8 ||pogothere.xyz^$document ||czxcm.sihighlyrecom.xyz^$all ||rwanf.sihighlyrecom.xyz^$all ||zosuc.sihighlyrecom.xyz^$all ||sihighlyrecom.xyz^$document ! https://forums.malwarebytes.com/topic/290022-malware-from-acaptchalesstop/ <-- No proof, but the domain name looks sus ||captchaless.top^$document ||a.captchaless.top^$all ||pshmetrk.com^$document ! https://www.virustotal.com/gui/url/d86dda38f96243311df2857966c047be0b4097ed4541ebe28cdc0dfc9e4ff4d2/community ! https://app.any.run/tasks/3c8b1d38-de18-488a-9e3f-62b3354c17e8 ||talkweb.org.uk/cl/36889_md/4/5055/3668/710/150935^$document ||haltertrailer.info^$all ||safesecureprotect.com^$all ||trk-magnam.com^$all ||event.trk-magnam.com^$all ||push.trk-deserunt.com^$all ||subscription.trk-deserunt.com^$all ||event.trk-deserunt.com^$all ||trk-deserunt.com^$all ||core.alertsx.com^$all ||alertsx.com^$all ! https://twitter.com/iam_py_test/status/1571997052900413440 ||medialysticos.live^$all ! Porn scam ||her-cupid.com^$all ||hottieswantu.com^$document ||offers.usabangpalace.com^$document ||w86a5jeili53sd6j26lv71h0.find-singles-online.com^$all ||find-singles-online.com^$document ! https://forums.malwarebytes.com/topic/290348-fake-mcafee-site/ ! credit to https://forums.malwarebytes.com/profile/62534-chas4/ ||install-network.com^$document ! https://app.any.run/tasks/541d38e7-67d1-46a7-85c8-dfcba7e40761 ||fatededers.com^$all ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1257870944 ||netbuilding.com.ar^$document ! https://github.com/uBlockOrigin/uBOL-issues/issues/1 ! Push scam shared by https://github.com/Yuki2718 ||nextpsh.top^$all ! Scam shared by https://github.com/piquark6046 (https://app.any.run/tasks/c30445b3-cc48-4039-9b02-26289f798b2f) ||54.37.5.34^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/131156 ! redirects from a hacked website ||rx-qualityshop.com^$all ||canadatrustmed.com^$all ! domains used by adfly for notification spam ! https://github.com/DandelionSprout/adfilt/commit/f60df9e069b404ce56727cc1b734b89ba7241849 ! https://github.com/AdguardTeam/AdguardFilters/issues/132079 ||davisonbarker.pro^$document ||www64.davisonbarker.pro^$document ||www31.davisonbarker.pro^$document ||www10.davisonbarker.pro^$document ||www24.davisonbarker.pro^$document ||www62.davisonbarker.pro^$document ||www87.davisonbarker.pro^$document ||www16.davisonbarker.pro^$document ||www61.davisonbarker.pro^$document ||www50.davisonbarker.pro^$document ||www77.davisonbarker.pro^$document ||www100.davisonbarker.pro^$document ||www85.davisonbarker.pro^$document ||www76.davisonbarker.pro^$document ||www39.davisonbarker.pro^$document ||www28.davisonbarker.pro^$document ||www3.davisonbarker.pro^$document ||www75.davisonbarker.pro^$document ||www78.davisonbarker.pro^$document ||www15.davisonbarker.pro^$document ||www29.davisonbarker.pro^$document ||www70.davisonbarker.pro^$document ||www21.davisonbarker.pro^$document ||www59.davisonbarker.pro^$document ||www25.davisonbarker.pro^$document ||www17.davisonbarker.pro^$document ||www74.davisonbarker.pro^$document ||www99.davisonbarker.pro^$document ||www79.davisonbarker.pro^$document ||www22.davisonbarker.pro^$document ||www94.davisonbarker.pro^$document ||www45.davisonbarker.pro^$document ||www51.davisonbarker.pro^$document ||www98.davisonbarker.pro^$document ||www35.davisonbarker.pro^$document ||www92.davisonbarker.pro^$document ||www12.davisonbarker.pro^$document ||www37.davisonbarker.pro^$document ||www33.davisonbarker.pro^$document ||www68.davisonbarker.pro^$document ||www34.davisonbarker.pro^$document ||davisonbarker.pro/am-push-cps.js$script ||lowrihouston.pro^$document ||www53.lowrihouston.pro^$document ||www44.lowrihouston.pro^$document ||www48.lowrihouston.pro^$document ||www91.lowrihouston.pro^$document ||www57.lowrihouston.pro^$document ||www1.lowrihouston.pro^$document ||www42.lowrihouston.pro^$document ||nathanaeldan.pro^$document ||www97.nathanaeldan.pro^$document ||www61.nathanaeldan.pro^$document ||www48.nathanaeldan.pro^$document ||www4.nathanaeldan.pro^$document ||www86.nathanaeldan.pro^$document ||www84.nathanaeldan.pro^$document ||www50.nathanaeldan.pro^$document ||www39.nathanaeldan.pro^$document ||www16.nathanaeldan.pro^$document ||www44.nathanaeldan.pro^$document ||freddyoctavio.pro^$document ||www63.freddyoctavio.pro^$document ||www70.freddyoctavio.pro^$document ||www16.freddyoctavio.pro^$document ||www36.freddyoctavio.pro^$document ||www21.freddyoctavio.pro^$document ||www68.freddyoctavio.pro^$document ||www72.freddyoctavio.pro^$document ||www86.freddyoctavio.pro^$document ! various domains farmed from adfly ! https://app.any.run/tasks/e18002cc-5207-4834-9e67-08364efb5036 ||toido.arrowtoldilim.com^$all ! https://forums.malwarebytes.com/topic/291290-infected-with-chilichicytriecom/ ||chilichicytrie.com^$all ! https://app.any.run/tasks/07bb037e-3180-40cd-8f59-b7854cabd601/ ||linkedin.com/pulse/free-discord-nitro-generator-verification-maxpro-game-gadget-2022^$all ||cutt.ly/YV9jKsf^$all ||gamegadget2022.blogspot.com^$document ||easymoneysurvey.space^$all ||gifttopsurvey.top^$all ! https://app.any.run/tasks/da8a44c3-965f-4fd6-816d-b5ae16235f62 ||iphone14.winnenmetje.info^$all ||winnenmetje.info^$document ! https://forums.malwarebytes.com/topic/291785-virus-removal/ ! https://www.virustotal.com/gui/url/7b40e1b7ffc3b710640ae41c529aff18e4c8cded55391d55c34b601912c5a2a2/community ! https://app.any.run/tasks/f0a198be-f4a4-4414-94c5-21ed61ae0264 ! https://app.any.run/tasks/6600c704-20f5-4643-a9b7-322673aa7eb4 ||www.vbucks-goo.com^$all ||vbucks-goo.com^$all ||take.yunosurveys.com^$all ||www.jpnbgn.com^$document ||1263dcb80ec5.789offers.net^$all ||789offers.net^$document ! https://forums.malwarebytes.com/topic/291952-mb-keeps-finding-same-4-pups/#comment-1541507 ||a.wilycaptcha.live^$all ||wilycaptcha.live^$document ||captchasee.live^$document ||captchatotal.live^$document ! https://app.any.run/tasks/c87a34ca-0d2f-43cb-be6d-8f48506bd723 ||ftuyn.ewoverth.buzz^$all ||elooksjustli.one^$all ! https://app.any.run/tasks/6bd12a68-ef8e-4e44-9c66-9c8e82cb784c ||2.napublic.com^$all ||napublic.com^$document ||haxbyq.com^$all ||authookroop.com^$document ||dlinkrdr.com^$document ||s.viichxt.com^$document ||getsecures.com^$all ||s.viiqvmfb.com^$document ! porn-related scams ||flirtclub.life^$all ||bumble-me.com^$document ||localhookup5.com^$all ||i.placefordating.live^$all ||placefordating.live^$all ||eroticmadness.com^$document ||jtdn2.datingtopgirls.com^$all ||datingtopgirls.com^$all ||join-the-dating.com^$document ||18hot.pw^$document ! https://app.any.run/tasks/87b656b2-3fd6-4bae-9267-f918ea4189ac ||dating-hotcontacts.com^$all ! https://youtu.be/GiixWxddP_M?t=1237 ||caren.live^$document ! https://scammer.info/t/discord-nitro-scam/113648 ||132.226.203.60^$all ||www.iphonediscord.info^$all ||iphonediscord.info^$all ! popups from shady URL shorteners ||mediasama.com^$document ||nadjustifygas.com^$document ||ufacw.com^$document ||lyconery-readset.com^$document ||fralstamp-genglyric.icu^$document ||m1dnightclubx.com^$document ! https://app.any.run/tasks/a15bbdd6-64d6-4a49-8457-6fbef1d00872 ||form.run/@fortnite-v-bucks-codes-hack-generator-no-human-verification^$all ||free-fortnitevbucksgenerator.blogspot.com^$all ||belohnung24.com^$all ||techplanet1.com^$all ! https://app.any.run/tasks/5a76864c-7436-4411-afc8-5937e8d1d147# ||form.run/@free-tiktok-followers-fans-likes-generator^$all ||dwmsurhf1svv8.cloudfront.net^$document,frame ! https://app.any.run/tasks/f7cdecba-0b76-4a5f-9d19-c36a453130dc ||contact.nationalconsumerscenter.co.uk^$document ! https://forums.malwarebytes.com/topic/292511-phishing-site-for-fake-usps-shipping-validation-information/ (account required) ! https://www.virustotal.com/gui/url/fdefaa6e73e722536cd080b4e820f8b69b6678d5f0c74268de126d2435369386 ||uspftiltedt.info^$all ! https://www.virustotal.com/gui/url/fe572bb6ae200bc0c888f0a4de73039aa594451e9cea8517ab835ffed1be4bd5/community ! https://www.bleepingcomputer.com/forums/t/779953/urambledcom-just-a-nuisance-or-what/ ||urambled.com^$all ! https://tria.ge/221208-2zaqwsbg78/behavioral1 ! I got some kind of miner/adware and an adware extension! All in one run! ||manualmaestro.com^$all ||holavpninstaller.com^$document ||cdn4.holavpninstaller.com^$all ||perr.holavpninstaller.com^$document ||client.holavpninstaller.com^$document ! https://forums.malwarebytes.com/topic/292800-posiberchoncom-%C2%A0malwarebytes-please-research-and-update-your-virus-db/ ||posiberchon.com^$all ! https://app.any.run/tasks/68b82f9e-16f5-4514-8140-ac3df58a3114 ||pastebin.com/K5YfahnC^$all ||fastspeed121.xyz^$all ||track.buzz-track.com^$document ||main.smile-keeper.com^$document ! https://app.any.run/tasks/41c5f7b2-250a-4781-86be-e03e56d1a8ed ||telegra.ph/Free-Minecraft-Hacks-No-Virus-Free-Download-08-03^$all ||tlgrph.gotorange.top^$all ||gotorange.top^$all ||puredating.top^$all ! (NSFW) https://app.any.run/tasks/e5a682c3-c4a3-4bb9-abd7-4f6c1cbd22f3 ||telegra.ph/Free-Minecraft-Hacks-No-Virus-Free-Download-07-30^$all ||dating-schedule.com^$document ||onlyfucks1s.com^$all ||d.wonderfuldating.top^$all ||wonderfuldating.top^$all ||milf-book.com^$document ||www.casualdates4you.com^$document ||casualdates4you.com^$document ! an infected VM ||dreamyproducts4u.net^$document ||xorror.shop^$document ||getarrectlive.com^$all ||identitysecurecenter.online^$all ||get.securedbrowser.net^$document ||securedbrowser.net^$document ||settings.securedbrowser.net^$document ||www.securedbrowser.net^$document ||search.securedbrowser.net^$document ||microsoftedge.microsoft.com/addons/detail/gfbbhkcipmfiidllnalpchabihdgklnl^$document ||microsoftedge.microsoft.com/addons/detail/secured-browse/gfbbhkcipmfiidllnalpchabihdgklnl^$document ||kms-auto.site^$document ||phenotypeguide.com^$all ||onesocialimpactnow.com^$all ||globaledyta.com^$all ||topcontactinc.com^$all ||adsforcomputertech.com^$all ||pushuworld.com^$all ||jytibarose.xyz^$all ! https://app.any.run/tasks/67907c11-6877-4c38-932f-2cf09ee4e434 ||adblock-chrome.net^$all ! https://github.com/uBlockOrigin/uAssets/issues/16000 ! https://app.any.run/tasks/195b871c-b9cd-48f8-a7c1-6a53ea943a4b ||z83z9.com^$document ||zcelv.toftheca.buzz^$all ||toftheca.buzz^$all ||fvsuo.toftheca.buzz^$all ||videofon.space^$all ||videofen.space^$all ||video7top.com^$all ||click-videov.com^$all ||click-videot.com^$all ||click-videom.com^$all ||click-videok.com^$all ||click-videoc.com^$all ||video7top.site^$all ||videobtc.space^$all ||videoeth.space^$all ||videofun.space^$all ||videofan.space^$all ||videoton.space^$all ||videosol.space^$all ||ythjhk.com^$all ! https://app.any.run/tasks/e0266815-2e00-42cb-b646-fa7dffb4a5e5 ||myget.org/feed/roblox-generator-no-verification/package/nuget/free-robux-generator-no-verification-or-survey-2022-v5153^$all ||deine.belohnung24.com^$all ||spr.belohnung24.com^$all ||expensivesurvey.click^$all ||af.247games.mobi^$document ! a "meet local girls" scam ||easy-sexxx.com^$document ! various scams from one site ||recodetime.com^$all ||updateinfoacademy.com^$all ||updaterglobal.com^$all ||phooking-nearected.com^$all ||deten.live^$all ! https://forums.malwarebytes.com/topic/293205-alexa-support-scam/ ||twitter.com/smartdotsupport^$all ||smartdotsupport.com^$document ||privacysearching.com^$document ! probably a Tech Support scam ||bigoven.com/recipe/alexa-helpline-1-855-666-7789-alexa-customer-service-number/2897947^$all ! discord nicro scam ||discordnitrocodegeneratorfree2022nohumanverification.weebly.com^$all ||gainforfree.com^$all ! https://www.virustotal.com/gui/url/65e7a48f0f2efb758087a0d99e8482a4b3245468e959633493655754fec08f48/community ! https://app.any.run/tasks/58b76078-e35e-46c8-b15e-e187ed375be6 ||bubuxflow.com^$all ||nationalconsumerscenter.co.uk^$document ! https://www.virustotal.com/gui/url/9c7b98445c0fd303be8604f383b3c940309068ea88b37d3945f4d34bb42d6c57/community ! (nsfw) https://app.any.run/tasks/a8a191ea-0e54-439f-96fd-c04a04150b06 ||expresscommusa.com^$document ||flirtingworld.com^$document ||date.sofortdates69.com^$document ||sofortdates69.com^$document ! hxxps[://]www[.]youtube[.]com/watch?v=d2ox4EcjtQY (spam comments) ! https://forums.malwarebytes.com/topic/293293-i-clicked-on-something-and-i-got-redirected-to-malicious-website-help/ ! https://forums.malwarebytes.com/topic/293294-fake-onlyfans-website/ (account required) ! https://app.any.run/tasks/cb1a672e-c3ed-455a-bc84-4b8bc060ee68 ! https://www.hybrid-analysis.com/sample/c3190b42a350a79f2b97af529a8bb57f39b62c9b12367419e71a2d053fb4a5fe ||sexfriendfdr.freeflirtz.com^$document ||freeflirtz.com^$document ! https://app.any.run/tasks/6c4f152f-c5b2-43ab-9b9e-06ae1480c74d ||mnla.biz/resource/dynamic/blogs/20220207_071000_31161.pdf^$all ||cdn.ymaws.com/www.mnla.biz/resource/dynamic/blogs/20220207_071000_31161.pdf^$all ||cldoffers.net^$all ! https://www.virustotal.com/gui/url/5808655d76b6ad31b7cc15fc266be2acb904ff8512fc1424103a6c54443bd272/community ! https://app.any.run/tasks/f619367b-ba77-4dbb-9046-211758a7f31a (my "analysis") ||viptips4youtoday.world^$document ! typical fake "discord nitro generator" ||an1.fun^$all ||b7ax3cyzhq.com^$all ||thunderfiles.co^$document ||g.luckycashzone.com^$document ! https://forums.malwarebytes.com/topic/293412-possible-fake-malwarebytes-number/ ||isixsigma.com/members/malwarebytesmailcxsupport$document ! https://dnstwist.it/ ! https://app.any.run/tasks/015824a4-f267-48df-8dde-a7ddd78f167e ||discordt.com^$all ||wildberriessgift.pw^$all ! https://scammer.info/t/viruses-need-to-be-removed-immediately-take-emergency-measures-trojan/117241/3 ||install.sunlifestores.com^$document ! https://www.virustotal.com/gui/url/2dabab937f09b2892f26c995365f64402574c8aa3e2f9750047131ca7a8d73d6?nocache=1 ! https://tria.ge/230109-14rdrsbd6t/behavioral1 ||lootprime.com^$all ||rdr.mobiletime.net^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/139667 (credit to DandelionSprout for some of these entries) ||500654179.kilpa2017.fi^$all ||yepsimmen.live^$all ||kilpa2017.fi^$all ||51.68.87.229^$all ! resolve to 51.68.87.229 ||hillendan.live^$document ||intoobut.live^$document ||logomuado.live^$document ||laxthatpie.live^$document ||nebdanext.live^$document ||drewcorsit.live^$document ||weyeplost.live^$document ||loaditjew.live^$document ||rawsalwet.live^$document ||rugpinchi.live^$document ||tillwoonote.live^$document ||becashcode.live^$document ||absbeatsic.live^$document ||tooldidhurt.live^$document ||crypostmark.live^$document ||varyhurtback.live^$document ||toeastdue.live^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/139667#issuecomment-1383935774 ||tapwhomjay.live^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/139667#issuecomment-1387103725 ! https://www.virustotal.com/gui/url/5c74d63d19b8ec82321d352749977e29795a9d074fcdacce3f1c822da28a3bba/detection ||mindkneenay.live^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/139667#issuecomment-1398421015 ! https://github.com/AdguardTeam/AdguardFilters/issues/139667#issuecomment-1399002017 ! https://tria.ge/230120-1tlersbg8x/behavioral1 ||totalrecaptcha.top^$all ! https://github.com/DandelionSprout/adfilt/issues/747 ! https://github.com/DandelionSprout/adfilt/commit/f055f89a51e7f9b1bcc58a0013b6207f89594ebe (all credit to DandlionSprout) ||2022crucialcatch.store^$all ||adidascostarica.com^$all ||adidasencostarica.com^$all ||adidasfactoryoutlet-uk.com^$all ||adidasfactoryoutletonline.com^$all ||adsoutletusa.com^$all ||adulttoysale.top^$all ||airjordanshoes.store^$all ||airjordansneakers.store^$all ||alabamacollege.store^$all ||alabamacrimsontide.store^$all ||aldo-sale.com^$all ||aldofactoryoutletcanada.com^$all ||aldoukshoes.com^$all ||allinclearance.com^$all ||aloyogaaustria.com^$all ||aloyogacz.com^$all ||altrafactoryoutletonline.com^$all ||approachmall.com^$all ||arastockistsuk.com^$all ||arizonacollege.store^$all ||arkansascollege.store^$all ||arkansasrazorbacks.store^$all ||asiacenter.sk^$all ||asicousutlet.com^$all ||asicrunningus.com^$all ||asics-outlet-greece.com^$all ||asicscolombiaoutlet.com^$all ||asicsfalabella.com^$all ||asicsoutletnl.com^$all ||asicsoutletsireland.com^$all ||asicssgonline.com^$all ||asicsskosneakers.com^$all ||astroshat.store^$all ||astrosjersey.store^$all ||astrosworldseries.store^$all ||astroswschampions.store^$all ||atl-braves.shop^$all ||atlantabraves.store^$all ||auburncollege.store^$all ||aukarenmillenbest.net^$all ||balansukcheap.com^$all ||baseballhat.store^$all ||baseballjerseys.store^$all ||basketballshoe.store^$all ||bayaayakkabi.com^$all ||baylorbears.shop^$all ||baylorbearsncaa.store^$all ||baylorcollege.store^$all ||begaborschoenensale.com^$all ||bestsclothingsale.com^$all ||billabong-turkiye.com^$all ||billabong-us.com^$all ||billabongoutletstore.com^$all ||billabongoutletuk.com^$all ||billabongromania.com^$all ||billabonguruguay.com^$all ||blundstonefactoryoutletus.com^$all ||bogsoutletie.com^$all ||bossoutletsau.com^$all ||bosssalescheap.com^$all ||bossukcheaps.com^$all ||bossusaclearan.com^$all ||bossusaoutlet.com^$all ||bossusbest.com^$all ||bossusclearan.com^$all ||bostoncollegecollege.store^$all ||bostoncollegeeagles.store^$all ||bostonjersey.store^$all ||bravesjersey.store^$all ||bravesworldseries.shop^$all ||broncosnfl.store^$all ||buccaneersjersey.store^$all ||bucsjersey.com^$all ||bucsjersey.sale^$all ||buffalopolska.net^$all ||bugattishoessaleuk.com^$all ||butypumaoutlet.com^$all ||californiasports.shop^$all ||camperportugal.com^$all ||camperskonorge.com^$all ||camperzapatochile.com^$all ||camperzapatoschile.com^$all ||canadagoosebrasil.com^$all ||cancercatch.store^$all ||carharttfactory-store.com^$all ||cariuma-australia.com^$all ||cariumafactoryoutlet.com^$all ||celticsfan.store^$all ||celticsjersey.shop^$all ||celticsjersey.store^$all ||chacofootwearusa.com^$all ||chaconewzealand.com^$all ||chacooutletswebsite.com^$all ||chacosandalsaustralia.com^$all ||chacoshoesuk.com^$all ||cheapdiesesale.com^$all ||cheappumuk.com^$all ||cheapsclothingus.com^$all ||chgaborschuhe.com^$all ||cincinnatibearcats.shop^$all ||cincinnaticollege.store^$all ||cipomagyarorszag.com^$all ||cipooutlethungary.com^$all ||cityconnect.pro^$all ||cityconnect.shop^$all ||cityconnect.store^$all ||cityconnecthat.shop^$all ||cityconnecthat.store^$all ||cityconnectjersey.store^$all ||cityconnectmlb.store^$all ||clarkcheapuk.com^$all ||clarkclearanus.com^$all ||clarkdiscountus.com^$all ||clarks-ar.com^$all ||clarks-dk.com^$all ||clarks-pe.com^$all ||clarksirelandshop.com^$all ||clarksoutlet-philippines.com^$all ||clarksoutletecuador.com^$all ||clarkssaleturkiye.com^$all ||clarksskonorge.com^$all ||clarksuy.com^$all ||clarkusoutlets.com^$all ||clarusaoutet.com^$all ||clearanclarkusa.com^$all ||clearanlacostus.com^$all ||clearanlacostusa.com^$all ||clearanskecheusa.com^$all ||clearantumius.com^$all ||clearantumus.com^$all ||clemsoncollege.store^$all ||clemsontigers.online^$all ||clemsontigers.store^$all ||clipperton.sk^$all ||coacbestusa.com^$all ||coacoutletsusa.com^$all ||coacoutletusa.com^$all ||coausaclearan.com^$all ||collegeauburntigers.store^$all ||collegebuckeyes.shop^$all ||collegefootballshop.top^$all ||collegegameshop.com^$all ||collegejayhawks.store^$all ||collegejersey.store^$all ||collegencaa.store^$all ||collegepro.store^$all ||collegespartans.com^$all ||collegewolverines.store^$all ||coloradobuffaloes.store^$all ||coloradocollege.store^$all ||columbiafactorysusa.com^$all ||columbiaoutletco.com^$all ||columbiaoutletonlines.com^$all ||columbiasalemalaysia.com^$all ||columbisportsale.com^$all ||columoutletusa.com^$all ||columsportsale.net^$all ||columsportsusa.com^$all ||converse-finland.com^$all ||converse-malaysia.com^$all ||converseirelandshop.com^$all ||converseschweizshop.com^$all ||crucialcatch.online^$all ||crucialcatch.pro^$all ||crucialcatchhoodie.store^$all ||crucialcatchpro.store^$all ||crucialcatchshop.pro^$all ||crucialcatchstore.com^$all ||dallascowboys.sale^$all ||demonia--suomi.com^$all ||demonia-boots-australia.com^$all ||demonia-boots-uk.com^$all ||diadora-schoenen.com^$all ||dieseclothingus.com^$all ||dieselsalebests.com^$all ||dieselsalesfr.net^$all ||diesusoutlet.com^$all ||discountskecheus.com^$all ||discounttumusa.com^$all ||discountumius.com^$all ||dkgaborsneakers.com^$all ||dodgershat.shop^$all ||dodgershat.store^$all ||dodgersjersey.shop^$all ||dodgersjersey.store^$all ||drcanadaoutletstore.com^$all ||dukebluedevils.store^$all ||dukecollege.store^$all ||ecco-canadasale.com^$all ||ecco-turkiye.com^$all ||eccodanmarkwebbutik.com^$all ||eccofactoryoutlets.com^$all ||eccofactoryoutletus.com^$all ||eccofactoryoutletusa.com^$all ||eccooutletukfactory.com^$all ||eccoshoesnz.com^$all ||eccoskonorge.com^$all ||eccsaleusonline.com^$all ||ellumalls.com^$all ||elluthings.com^$all ||encompassmalls.com^$all ||enucuzuggbot.com^$all ||evolutionmalls.com^$all ||exynet.sk^$all ||fanaticsretailer.store^$all ||fanaticsshop.net^$all ||fashioninmall.com^$all ||fightingirish.shop^$all ||fightingirish.store^$all ||firstcoastthings.com^$all ||fitflop-irelandstockists.com^$all ||fitflop-philippines.com^$all ||fitflop-ukoutlet.com^$all ||fitflopfactoryoutlet.com^$all ||fjallravengreece.com^$all ||fjallravenitalia.com^$all ||fjallravenoutletpolska.com^$all ||fjallravenschweiz.com^$all ||fjallraventilbud.com^$all ||floridagators.sale^$all ||floridagators.store^$all ||floridagators.xyz^$all ||floridastatecollege.store^$all ||floridastateseminoles.store^$all ||flylondonportugal.com^$all ||footballstaple.store^$all ||fredperrylojas.com^$all ||fredperrymelbourne.com^$all ||fryefactoryoutlet.com^$all ||fryeshoescanada.com^$all ||gabor-chweiz.com^$all ||gaborbelgique.com^$all ||gaborcanadasale.com^$all ||gaborfactoryoutlets.com^$all ||gaborfactorysoutlets.com^$all ||gaborireland.com^$all ||gaborirelandsale.com^$all ||gaboroutlet-online.com^$all ||gaborpolska.com^$all ||gaborsaleireland.com^$all ||gaborschuheshop.com^$all ||gaborshoeespana.com^$all ||gaborshoesespana.com^$all ||gaborshoesireland.com^$all ||gaborshoesnz.com^$all ||gaborshoesuk.com^$all ||gaborskodanmark.com^$all ||gaborskonorge.com^$all ||gaborsneakers.com^$all ||gaborsuomi.com^$all ||gaborsverige.com^$all ||gaboruksale.com^$all ||gatorscollege.store^$all ||geacahellyhansenoutlet.com^$all ||georgiabulldogs.pro^$all ||georgiabulldogs.shop^$all ||georgiabulldogs.store^$all ||georgiacollege.store^$all ||geoxaustralia.com^$all ||geoxmalaysia.com^$all ||gheteclarksromania.com^$all ||gonzagabulldogs.store^$all ||goodr-australia.com^$all ||goodr-indonesia.com^$all ||goodrphilippines.com^$all ||goodrsingapore.com^$all ||goodrsunglassesmalaysia.com^$all ||goodrsunglassessaleus.com^$all ||goodrsunglassesuk.com^$all ||groundiesshoesuk.com^$all ||gym-shark-usa.com^$all ||gymshark-canada.com^$all ||gymshark-greece.com^$all ||gymshark-ireland.com^$all ||gymshark-southafrica.com^$all ||gymsharkaustria.com^$all ||gymsharkgreeceshop.com^$all ||gymsharksaleus.com^$all ||gymsharkunitedkingdom.com^$all ||gymsharkunitedstates.com^$all ||haglofsrea.com^$all ||haglofstilbud.com^$all ||haglofsturkiye.com^$all ||haglofsusastore.com^$all ||havenshungary.com^$all ||hellyhansencanadasale.com^$all ||hhjacketsfactoryoutlet.com^$all ||hitecayakkabi.com^$all ||hitecchaussure.com^$all ||hitecscarpe.com^$all ||hitecschoenen.com^$all ||hitecskonorge.com^$all ||hitecsouthafrica.com^$all ||hockeyfightscancer.store^$all ||hokairelandsales.com^$all ||hokashoesaustralia.com^$all ||hotsaleclearance.com^$all ||houstonastros.store^$all ||houstonastrosfan.store^$all ||hoyoufat.store^$all ||hoyoufatjersey.store^$all ||hugobossclearanuk.net^$all ||hushpuppies-uk.com^$all ||hushpuppiesshoesoutlet.com^$all ||illinoiscollege.store^$all ||illinoisfightingillini.shop^$all ||illinoisfightingillini.store^$all ||iowacollege.store^$all ||iowahawkeyes.pro^$all ||iowahawkeyes.shop^$all ||iowahawkeyes.store^$all ||iowastatecollege.store^$all ||iowastatecyclones.store^$all ||jackwolfskindubai.com^$all ||japanzarclothes.com^$all ||jayhawkscollege.store^$all ||jeweloutletshopline.com^$all ||jeweloutletshoplus.com^$all ||jewelrylimitedsr.com^$all ||jordanshoe.store^$all ||jordanshoes.store^$all ||josefseibelshoesuk.com^$all ||kamikbootsukstore.com^$all ||kankenportugal.com^$all ||kansasjayhawks.shop^$all ||kansasstatecollege.store^$all ||kansasstatewildcats.store^$all ||karenmillebestus.com^$all ||karenmillensusoutlet.com^$all ||karenmillenusbest.com^$all ||karenmillesdiscount.cheap^$all ||karenmilleusaclearan.com^$all ||karenmilleusasale.com^$all ||karenmilleusastore.com^$all ||katespusoutlet.com^$all ||keds-schuhe.com^$all ||kedsonlineshopnl.com^$all ||keen1uae.com^$all ||keenshoesfactoryoutletsuk.com^$all ||keenuae.com^$all ||kenscottshop.com^$all ||kenscottshopify.com^$all ||kentuckywildcats.shop^$all ||kentuckywildcats.store^$all ||ksgiftshopline.com^$all ||kubasketball.shop^$all ||kurtka-hhsklep.com^$all ||lachargers.store^$all ||lacostcheapuk.com^$all ||lacostclearances.net^$all ||lacostdiscountus.com^$all ||lacosteclearanusa.com^$all ||lacosteuaeonline.com^$all ||lacostsaleusa.com^$all ||lacostusabest.com^$all ||ladodgershat.shop^$all ||ladodgersjersey.store^$all ||lasport.shop^$all ||legginsmexico.com^$all ||lojashushpuppies.com^$all ||longchamp-luxembourg.com^$all ||longchamp-southafrica.com^$all ||longchampbagsonsalecanada.com^$all ||longchampfactoryoutletuk.com^$all ||longchampoutletenligne.com^$all ||longchampoutletsydney.com^$all ||longchampparissoldes.net^$all ||longchampuaedubai.com^$all ||losangelesdodgers.store^$all ||louisvillecardinals.store^$all ||louisvillecollege.store^$all ||lowa-boots-uk.com^$all ||lowakangor.com^$all ||lowaoutlet-usa.com^$all ||lowaslovensko.com^$all ||lsucollege.store^$all ||lsutigers.store^$all ||mango-pakistan.com^$all ||marmot-australia.com^$all ||marmot-schweiz.com^$all ||marylandcollege.store^$all ||marylandterrapins.store^$all ||merrell-outletfactory.com^$all ||merrell-sg.com^$all ||merrell-shoesphilippines.com^$all ||miamicollege.store^$all ||michigancollege.store^$all ||michiganstatecollege.store^$all ||michiganstatespartans.store^$all ||minnesotacollege.store^$all ||minnesotagoldengophers.store^$all ||mississippistatebulldogs.store^$all ||mississippistatecollege.store^$all ||mixedmalls.com^$all ||mizunooutletuk.com^$all ||mlballstar.net^$all ||mlballstarshop.com^$all ||mlbastros.store^$all ||mlbastrosjersey.store^$all ||mlbbaseballhat.store^$all ||mlbbraves.pro^$all ||mlbcap.net^$all ||mlbcapshop.com^$all ||mlbcityconnect.sale^$all ||mlbcityconnect.store^$all ||mlbfansjersey.store^$all ||mlbfanstore.com^$all ||mlbhat.sale^$all ||mlbhat.store^$all ||mlbhat.top^$all ||mlbhats.sale^$all ||mlbjersey.store^$all ||mlbjerseys.online^$all ||mlbjerseysale.shop^$all ||mlbjerseyshop.net^$all ||mlbprobraves.store^$all ||mlbprojersey.com^$all ||mlbraves.store^$all ||monitormalls.com^$all ||nba75.store^$all ||nba75jerseys.store^$all ||nbaallstarfan.store^$all ||nbafanjerseys.com^$all ||nbafansjersey.com^$all ||nbajerseycheap.com^$all ||nbajerseys.top^$all ||nboutletphilippines.com^$all ||ncaaalabama.store^$all ||ncaaarizona.store^$all ||ncaaauburntigers.store^$all ||ncaabasketball.store^$all ||ncaabaylor.store^$all ||ncaabaylorbears.store^$all ||ncaabears.store^$all ||ncaabluedevils.store^$all ||ncaabruins.store^$all ||ncaabuckeyes.store^$all ||ncaaclemsontigers.store^$all ||ncaacollege.store^$all ||ncaacollegejersey.store^$all ||ncaacougars.store^$all ||ncaacrimsontide.store^$all ||ncaadiablesbleus.store^$all ||ncaaducks.store^$all ||ncaaduke.store^$all ||ncaadukebluedevils.store^$all ||ncaafanshop.com^$all ||ncaafightingirish.store^$all ||ncaafightingtigers.store^$all ||ncaafootballjersey.store^$all ||ncaageorgia.store^$all ||ncaageorgiabulldogs.store^$all ||ncaahoustoncougars.store^$all ||ncaahurricanes.store^$all ||ncaaillinois.store^$all ||ncaaiowa.store^$all ||ncaajayhawks.store^$all ||ncaajersey.com^$all ||ncaajersey.pro^$all ||ncaajersey.sale^$all ||ncaajerseycollege.store^$all ||ncaajerseyfan.store^$all ||ncaajerseypro.store^$all ||ncaajerseys.store^$all ||ncaajerseysstore.com^$all ||ncaakentuckywildcats.store^$all ||ncaalonghorns.store^$all ||ncaalsu.store^$all ||ncaamiami.store^$all ||ncaamiamihurricanes.store^$all ||ncaamichigan.store^$all ||ncaamichiganwolverines.store^$all ||ncaanorthcarolina.store^$all ||ncaanotredame.store^$all ||ncaaoklahoma.store^$all ||ncaaolemiss.store^$all ||ncaaoregon.store^$all ||ncaaoregonducks.store^$all ||ncaarazorbacks.store^$all ||ncaashopjerseys.com^$all ||ncaasooners.store^$all ||ncaatarheels.store^$all ||ncaatennessee.store^$all ||ncaauclabruins.store^$all ||ncaauk.store^$all ||ncaavols.store^$all ||ncaawildcats.store^$all ||ncaawolverines.store^$all ||ncaaworldseries.store^$all ||ncaazags.store^$all ||nebraskacollege.store^$all ||nebraskacornhuskers.store^$all ||newyorksport.store^$all ||nfl49ers.store^$all ||nflbengals.store^$all ||nflbroncos.store^$all ||nflcancercatch.store^$all ||nflcardinals.store^$all ||nflchargers.store^$all ||nflchiefs.store^$all ||nflcrucialcatch.sale^$all ||nflcrucialcatch.store^$all ||nflcrucialcatch.top^$all ||nflcrucialcatchshop.com^$all ||nfldraft.shop^$all ||nfldrafthat.store^$all ||nfldraftshop.com^$all ||nfleagles.store^$all ||nflgamejersey.store^$all ||nflgamelimited.store^$all ||nflhelmet.store^$all ||nfljersey.fans^$all ||nfljersey.pro^$all ||nfljerseysale.shop^$all ||nflnikeshoes.com^$all ||nflnikeshoes.store^$all ||nflpackers.store^$all ||nflsaleshop.com^$all ||nflsalutetoservice.com^$all ||nflsalutetoservice.store^$all ||nflservice.store^$all ||nflshoe.store^$all ||nflshoes.pro^$all ||nflshoes.shop^$all ||nflshoes.store^$all ||nflshoesale.store^$all ||nflshopfan.com^$all ||nflsocks.com^$all ||nflstaple.store^$all ||nflstapleshop.top^$all ||nflstorefan.com^$all ||nflsts.com^$all ||nflstsjersey.com^$all ||nflstsjersey.store^$all ||nfltitans.store^$all ||nflzoompegasus.store^$all ||nhlallstar.pro^$all ||nhlauthenticpro.store^$all ||nhlfan.store^$all ||nhlfanjersey.store^$all ||nhlfansjersey.store^$all ||nhlfansjerseys.store^$all ||nhlfightscancer.store^$all ||nhlhockey.store^$all ||nhlhockeyjersey.store^$all ||nhljersey.sale^$all ||nhljersey.site^$all ||nhljersey.store^$all ||nhljersey.top^$all ||nhljerseyfan.store^$all ||nhljerseypro.store^$all ||nhljerseys.sale^$all ||nhljerseysale.shop^$all ||nhljerseysfan.store^$all ||nhljerseyshop.store^$all ||nhljerseyssale.store^$all ||nhlprojerseys.store^$all ||nhlsalejersey.store^$all ||nhlshopfan.com^$all ||nhlshopjersey.com^$all ||nhlstadiumseries.store^$all ||nhlwinterclassicjersey.store^$all ||nike--usa.com^$all ||nike-clearancestore.com^$all ||nikeairjordan.store^$all ||nikeairshoes.store^$all ||nikeshoesale.store^$all ||nikesneaker.store^$all ||ninewestpolska.com^$all ||ninewestusasale.com^$all ||nobull-brasil.com^$all ||northcarolinacollege.store^$all ||northcarolinashop.net^$all ||northcarolinatarheels.shop^$all ||northcarolinatarheels.store^$all ||northfaceoutletstoreus.com^$all ||notredamecollege.store^$all ||notredamefightingirish.store^$all ||off-whitecanada.com^$all ||off-whitecolombia.com^$all ||off-whitedanmark.com^$all ||off-whitedeutschland.com^$all ||off-whitegreece.com^$all ||off-whitehungary.com^$all ||off-whiteindonesia.com^$all ||off-whitemalaysia.com^$all ||off-whitemexico.com^$all ||off-whitenetherlands.com^$all ||off-whiteromania.com^$all ||off-whiteschweiz.com^$all ||off-whitesuomi.com^$all ||off-whitesverige.com^$all ||off-whiteturkey.com^$all ||ohiostatebuckeyes.online^$all ||ohiostatebuckeyes.store^$all ||ohiostatecollege.store^$all ||oklahomacollege.store^$all ||oklahomasooners.store^$all ||olemisscollege.store^$all ||olemissrebels.shop^$all ||olemissrebels.store^$all ||onlinejewelshopline.com^$all ||onlinejewelshoplus.com^$all ||onlinestoresshops.com^$all ||onlinevipshplus.com^$all ||oofos-ireland.com^$all ||oofosnorgeoutlet.com^$all ||oofosoutletcanada.com^$all ||oofosoutletmalaysia.com^$all ||oofosoutletonline.com^$all ||oofosshoeaustralia.com^$all ||oofosskorsveriges.com^$all ||operationmalls.com^$all ||oregoncollege.store^$all ||oregonducks.shop^$all ||oregonducks.store^$all ||osucowboys.shop^$all ||outletargentinacolumbia.com^$all ||outletchilecolumbia.com^$all ||outletgoodshopline.com^$all ||outletjewelshoplzza.com^$all ||outletjewelsvip.com^$all ||outletmerrellargentina.com^$all ||outletuksorel.com^$all ||outletvipshoplus.com^$all ||outletvipshopy.com^$all ||panelmalls.com^$all ||partnershipmalls.com^$all ||paulsmitfactoryus.net^$all ||pennstatecollege.store^$all ||pennstatenittanylions.store^$all ||philadelphiaeagles.store^$all ||piercemalls.com^$all ||pittpanthers.shop^$all ||pittsburghsteelersshop.com^$all ||planmalls.com^$all ||proficientmalls.com^$all ||psychobunnycolombia.com^$all ||puma-greece.com^$all ||puma-norge.co.no^$all ||puma-uy.com^$all ||pumachileoutlet.com^$all ||pumacostarica.net^$all ||pumaecuador.net^$all ||pumairelandsale.com^$all ||pumaoutletonlineportugal.com^$all ||pumaturkish.com^$all ||pumauruguay.com^$all ||pumoutletusa.com^$all ||pumsaleusa.com^$all ||pumusoutlet.com^$all ||purdueboilermakers.store^$all ||purduecollege.store^$all ||quicksilveruae.com^$all ||quiksilver-australia.com^$all ||quiksilver-canada.com^$all ||quiksilver-malaysia.com^$all ||quiksilver-philippines.com^$all ||quiksilver-southafrica.com^$all ||quiksilverfactoryoutlet.com^$all ||quiksilverindonesia.com^$all ||quiksilveroutletusa.com^$all ||quiksilveruksale.com^$all ||rebecamalls.com^$all ||reclassicsg.org^$all ||redwingbootsoutlets.com^$all ||reebok-chile.com^$all ||reebok-romania.com^$all ||reebokblackfridayoffers.com^$all ||reebokfactoryoutlet.com^$all ||riekeroutletca.com^$all ||riekershoessaleuk.com^$all ||rolltide.shop^$all ||romaniakanken.com^$all ||rothyusonline.shop^$all ||roxclothingusa.com^$all ||rritemalls.com^$all ||sacfjallravensoldes.com^$all ||saleushoka.com^$all ||salewaoutletschile.com^$all ||salezarjapan.com^$all ||salomon--portugal.com^$all ||salomon-nederland.com^$all ||salomon-nederlands.com^$all ||salomon-norge.co.no^$all ||salomon-outletsturkiye.com^$all ||salomon-portugal.com^$all ||salomonaphilippines.com^$all ||salomonashoesnz.com^$all ||salomonbootsbrisbane.com^$all ||salomonbootsoutletusa.com^$all ||salomonespanas.com^$all ||salomonfactoryoutletmadrid.com^$all ||salomonmalaysiawebsite.com^$all ||salomonoutletgreece.com^$all ||salomonoutletnl.com^$all ||salomonoutletsfactory.com^$all ||salomonoutletstoresusa.com^$all ||salomonshoesoutletusa.com^$all ||salomonxapro3d.com^$all ||samsonclearanus.com^$all ||samsondiscountus.com^$all ||sandalitevaofferta.com^$all ||sanfrancisco49ers.store^$all ||sanuksingapore.com^$all ||sapatilhasallstarbaratas.com^$all ||sapatosclarkportugal.com^$all ||saucony-australia.com^$all ||sauconyfactoryoutletsuk.com^$all ||sauconyfactoryoutletuk.com^$all ||sauconyjazzturkey.com^$all ||sauconyoutletaustralia.com^$all ||sauconyoutletuk.com^$all ||seattlekraken.sale^$all ||sebagoshoesdubai.com^$all ||shoesnike.store^$all ||shopmksus.com^$all ||shopsmithsus.com^$all ||silentmalls.com^$all ||skecheausale.com^$all ||skecheclearanceus.com^$all ||skechers-israel.com^$all ||skechers-tenisice.com^$all ||skechersarchfitromania.com^$all ||skechersfactorysoutlet.com^$all ||skechersgolfshoesusa.com^$all ||skechersoutletpraha.cz^$all ||skecherstrainers-uk.com^$all ||skecherusaclearan.com^$all ||skecheukclearan.com^$all ||skecheusoutlet.com^$all ||slovenskokanken.com^$all ||sneakersnike.store^$all ||sorelfactoryoutlet.com^$all ||southcarolinacollege.store^$all ||southcarolinagamecocks.store^$all ||spartanscollege.shop^$all ||sperroutletusa.com^$all ||sperryfactoryoutlet.com^$all ||sperryonlinesatis.com^$all ||spinmalls.com^$all ||sportgear.store^$all ||spraygoutletus.com^$all ||spraygroclearanusa.com^$all ||spraygrousoutlet.com^$all ||stanfordcardinal.store^$all ||stanfordcollege.store^$all ||storeskechesale.com^$all ||suicokeshoessale.com^$all ||suicokeuk.com^$all ||superbowllvi.shop^$all ||superbowllvi.store^$all ||superbowlstore.com^$all ||swarovskichile.com^$all ||swarovskidubai.com^$all ||swarovskifactoryoutlet.com^$all ||swarovskioutletuk.com^$all ||swarovskiphilippines.com^$all ||swarovskisaleoutlet.com^$all ||tamarisfactoryoutlet.com^$all ||tamarisgreece.com^$all ||tamarisgreecer.com^$all ||tarheelscollege.store^$all ||tbeautybeauty.com^$all ||tcucollege.store^$all ||tcuhornedfrogs.store^$all ||tenisveja-portugal.com^$all ||tennesseecollege.store^$all ||tennesseevolunteers.store^$all ||teva-nederlands.com^$all ||tevacolombia.com^$all ||tevafactoryoutletuk.com^$all ||tevagreece.com^$all ||tevaromaniasandale.com^$all ||tevaturkey.com^$all ||texasamaggies.store^$all ||texasamcollege.store^$all ||texascollege.store^$all ||texaslonghorns.online^$all ||texaslonghorns.store^$all ||texastechcollege.store^$all ||texastechredraiders.store^$all ||thegirlfriendcollectiveaustralia.com^$all ||thegirlfriendcollectivenederland.com^$all ||thegirlfriendcollectiveuk.com^$all ||thorogoodfactoryoutlets.com^$all ||tiendacolumbiachile.com^$all ||tiendaunderarmourmexico.com^$all ||tocontrolbeauty.com^$all ||tombrady.store^$all ||tombradyshop.pro^$all ||tombradystore.com^$all ||tommyhilfigerperth.com^$all ||tomssingaporesale.com^$all ||tumibeststores.com^$all ||tumicheapuk.com^$all ||tumioutletclearan.com^$all ||tumusaoutlet.com^$all ||ua-australia.com^$all ||ua-canada.com^$all ||ua-chile.com^$all ||ua-greece.com^$all ||ukclarkcheap.com^$all ||ukclarkoutlets.com^$all ||ukcollege.store^$all ||ukkarenmillencheap.com^$all ||uklacostsale.com^$all ||ukskechecheap.com^$all ||uncbasketball.store^$all ||uncjersey.shop^$all ||uncjersey.store^$all ||unctarheels.shop^$all ||unctarheels.store^$all ||underarmour-costerica.com^$all ||underarmour-israel.com^$all ||underarmour-italia.com^$all ||underarmour-nl.com^$all ||underarmour-nz.com^$all ||underarmour-saudiarabia.com^$all ||underarmourhungary.com^$all ||underarmourosterreich.com^$all ||underarmouroutlet-usa.com^$all ||underarmouroutletromania.com^$all ||underarmourromania-ro.com^$all ||underarmourshortsuk.com^$all ||undergroundmalls.com^$all ||underrmourireland.com^$all ||usccollege.store^$all ||uscolumbsportswear.com^$all ||usctrojans.online^$all ||uspumsale.com^$all ||utahcollege.store^$all ||utahutes.shop^$all ||utahutes.store^$all ||veja-froutlet.com^$all ||vejafactoryoutletusa.com^$all ||vejajapanstore.com^$all ||vejaoslo.com^$all ||vejaosterreich.com^$all ||vejaromaniaoutlet.com^$all ||vejasale-ireland.com^$all ||vejasneakers-schweiz.com^$all ||vejasuomiale.com^$all ||vejatenisice-hr.com^$all ||vibramfive-fingers.cz^$all ||vibramsk.com^$all ||vionicshoes-southafrica.com^$all ||vionicshoessingapore.com^$all ||vionicshoesuksale.com^$all ||vipgiftshopline.com^$all ||vipgiftshoppy.com^$all ||vipgoodshoppy.com^$all ||vippgiftsonline.com^$all ||virginiatechcollege.store^$all ||virginiatechhokies.store^$all ||vlone-uk.com^$all ||wakeforestcollege.store^$all ||wakeforestdemondeacons.store^$all ||warriorsjersey.store^$all ||washingtoncollege.store^$all ||washingtonhuskies.store^$all ||wellness-gym.sk^$all ||westvirginiacollege.store^$all ||westvirginiamountaineers.store^$all ||wolverineaustralias.com^$all ||xn--conversemaazalar-shc44a.com^$all ||xn--hotiayakkab-p9a38g.com^$all ||xn--vansayakkab-9zb.com^$all ||zainofjallravenkanken.com^$all ||zalesglobaljewelry.com^$all ||zamberlanireland.com^$all ||zapatillasvejacl.com^$all ||zapatosaldochile.org^$all ! https://forums.malwarebytes.com/topic/293979-recent-scamware-not-recognized-by-malwarebytes/ ||allreqdusa.com^$all ! NSFW: https://app.any.run/tasks/dff4525c-555a-479e-83ba-c5b2f2d11ab6 ||baconaces.pro^$all ||twgfw.eredhadbeen.xyz^$all ||eredhadbeen.xyz^$all ||nugans.live^$all ||chrome.google.com/webstore/detail/cats-fanpage/nkhleengjihjncmbkldpfmoankdkhahg^$document ! NSFW: https://app.any.run/tasks/10647999-b75b-42bd-ae49-c7d596f3c797 ||kdakm.eredhadbeen.xyz^$all ||qualitydating.top^$all ||a.curedating.top^$all ||curedating.top^$all ! https://www.virustotal.com/gui/ip-address/5.181.203.4/relations ||finestdating.top^$document ||goodating.top^$document ||datingpoint.top^$document ||cutiesdating.top^$document ||vipdatingtime.top^$document ! https://www.virustotal.com/gui/ip-address/195.201.253.131/relations ||sensualflirts.life^$document ||yourbestpartner.life^$document ||thebestdate.life^$document ||besttightflirts.life^$document ||timetopdatings.life^$document ||realhotmeets.life^$document ||dateflirt.life^$document ||originalspartner.life^$document ||loveclick.life^$document ||goyummdating.life^$document ||bestdatingsforyou.life^$document ||findsoulmate.life^$document ||instinctdating.life^$document ||charmingdating.life^$document ||datingarea.life^$document ||delightdatings.life^$document ||delightflirt.life^$document ||delightdating.life^$document ||bestflirtzone.life^$document ||getsexy.life^$document ||lover-finder.life^$document ||findsexy.life^$document ! (copied from DandelionSprout's list): https://github.com/DandelionSprout/adfilt/issues/748 ||adidas-budapest.com^$all ||adidas-deutschland.de^$all ||adidas-egypt.com^$all ||adidas-france.fr^$all ||adidas-philippines.com^$all ||adidas-sk.sk^$all ||adidasenpanama.com^$all ||adidasfactoryshop.co.za^$all ||adidasguatemala.com^$all ||adidashonduras.com^$all ||adidasksa.com^$all ||adidasmaroc.com^$all ||adidasnicaragua.com^$all ||adidasonlineoutlet.es^$all ||adidasonlineuksale.com^$all ||adidaspakistan.com^$all ||adidasshoesgreece.com^$all ||adidasslovensko.sk^$all ||adidasuaesale.com^$all ||aerosolesportugal.com^$all ||aerosolesuk.com^$all ||alexiawrites.com^$all ||allbirditalia.it^$all ||americantouristerfactoryoutlet.com^$all ||aplshoeuk.com^$all ||aplsneakerssale.com^$all ||argentina-adidas.com^$all ||asicsayakkabitr.com^$all ||asicscipohungary.com^$all ||asicsnederland.com^$all ||asicswinkelnederland.com^$all ||billabongfactoryoutlet.ca^$all ||billabongfrance.com^$all ||billabongitalia.com^$all ||billabongpolska.com^$all ||billabongportugal.com^$all ||billabonguk.com^$all ||bogsbootsireland.com^$all ||bogschile.com^$all ||botaswolverine.com.mx^$all ||brooksshoesstore.us^$all ||bundyslovakia.com^$all ||butywolverlne.com^$all ||canada-nike.com^$all ||cariuma-france.fr^$all ||cariuma-philippines.com^$all ||cariumashoesportugal.com^$all ||cariumashoessingapore.com^$all ||chaussurenobull.com^$all ||chaussuresnobull.com^$all ||conversesingaporeoutlets.com^$all ||danskonederland.com^$all ||danskosaldi.it^$all ||demoniachaussuresparis.fr^$all ||demoniacipő.com^$all ||demoniashopberlin.de^$all ||demoniastopankysk.sk^$all ||demoniatürkiye.com^$all ||diesel-helsinki.com^$all ||docmartens-canada.com^$all ||docsmartensslovensko.sk^$all ||docsmartensthailand.com^$all ||doctormartensmadrid.com^$all ||doctormartensnederland.com^$all ||doctormartensromanla.com^$all ||drmartensosterreich.com^$all ||drmdanmark.com^$all ||ecuador-adidas.com^$all ||fitflop-australiasale.com^$all ||footjoy-portugal.com^$all ||footjoybelgie.com^$all ||footjoyfinland.com^$all ||footjoyindonesia.com^$all ||footjoypakistan.com^$all ||footjoyuae.com^$all ||gym-sharkitalia.com^$all ||gym-sharkportugal.com^$all ||gymshark-hrvatska.com^$all ||gymsharkjp.com^$all ||gymsharks-hrvatska.com^$all ||heydudeshoessaleuk.com^$all ||hhworkwearcanada.com^$all ||hoka-canada.ca^$all ||hoka-slovensko.sk^$all ||hokacaonsale.ca^$all ||hokahungarywebshop.com^$all ||hokaschuhekaufen.de^$all ||hokashoescanadasale.com^$all ||hokaskoshop.com^$all ||hrvatska-adidas.com^$all ||indonesia-adidas.com^$all ||jakkeshopdanmark.com^$all ||jakkeshopnorge.com^$all ||lojasasicslisboa.com^$all ||lojashellyhansenportugal.com^$all ||ludan102.com^$all ||lululemonbarcelona.es^$all ||martenslovensko.com^$all ||martensslovensko.sk^$all ||martensxhrvatska.com^$all ||martensywarszawa.com^$all ||martenywarszawa.com^$all ||merrell-canada-clearance.com^$all ||merrellbutysklepy.pl^$all ||merrellportugalshop.com^$all ||mizuno-italia.com^$all ||mizuno-mexico.com.mx^$all ||mizuno-peru.com^$all ||mizuno-shoesaustralia.com^$all ||mizuno-thailand.com^$all ||mizunoblackfridaysale.com^$all ||mizunodeutschland.de^$all ||mizunofootballbootsuk.com^$all ||mizunoshoescanada.ca^$all ||mizunosshoesindia.com^$all ||nb-uae.com^$all ||nbalancechile.com^$all ||nike-factoryoutletstore.com^$all ||nikefactorystoreuk.com^$all ||nobullcrossfitscarpe.com^$all ||nobullproiectcanada.com^$all ||nobullswitzeriand.com^$all ||nobulltrainerphilippines.com^$all ||nobulltrainersslngapore.com^$all ||nobullxespana.com^$all ||nobvllshoesuk.com^$all ||norge-adidas.com^$all ||northfaceindiastore.com^$all ||northfaceoutletargentina.com^$all ||northfacexhungary.com^$all ||northfacezurich.com^$all ||northfacezurlch.com^$all ||northxfaceindiastore.com^$all ||osterreich-adidas.com^$all ||peru-adidas.com^$all ||portugal-adidas.com^$all ||psychobunnypolo.com^$all ||psychobunnytshirt.com^$all ||puma-turkey.com.tr^$all ||romaniagymshark.com^$all ||salomon-retailers.com^$all ||salomonchileoutlet.com^$all ||salomondeutschlandsale.de^$all ||salomonfactoryoutletza.com^$all ||salomonshoesonline.us^$all ||salomonshop.ca^$all ||salomonskioutletshop.com^$all ||salomonspeedcrossusa.com^$all ||salomonspikecrosscanada.com^$all ||salomonxt6outletusa.com^$all ||salomonxt6sale.com^$all ||sanuk-canada.com^$all ||saucony-clearancecanada.com^$all ||saucony-portugal.org^$all ||sauconycanadaonsale.com^$all ||sauconyclearance.us^$all ||sauconyfactoryoutlet.us^$all ||sauconyirelandoutlet.com^$all ||sauconyløbesko.com^$all ||sauconymalaysiaonline.com^$all ||sauconyrunningshoes.us^$all ||sauconyshoesfactorynz.com^$all ||sauconysingaporeonline.com^$all ||sauconysneakers.us^$all ||scarpekeenitalia.com^$all ||scarpewolverine.it^$all ||shopsalomonsouthafrica.com^$all ||skechers-south-africa.co.za^$all ||skecherscanadaonline.ca^$all ||skechersoutletnz.com^$all ||sorelbootsoutlet.com^$all ||sperryonsale.com^$all ||sperryoutletfactory.com^$all ||suomi-adidas.com^$all ||tevadanmarkshop.com^$all ||tevamalaysias.com^$all ||tevamalaysiashop.com^$all ||tevanorgeshop.com^$all ||thenorthfacenzsale.com^$all ||thenorthfacexromania.com^$all ||thursdayboothungary.com^$all ||thursdayboots-ro.com^$all ||thursdaybootschweiz.com^$all ||thursdaybootsdenmark.com^$all ||thursdaybootsdeutschiand.com^$all ||thursdaybootsdeutschland.de^$all ||thursdaybootsgreek.com^$all ||thursdaybootsmalaysla.com^$all ||thursdaybootsnorway.com^$all ||thursdaybootsportugals.com^$all ||thursdaybootsrea.com^$all ||thursdaybootsturkey.com^$all ||thursdayshoesnz.com^$all ||tiendaasicsmexico.com^$all ||tiendasadidaschile.com^$all ||tiendaskecherchile.com^$all ||tiendasnorthfacemexico.com^$all ||tnfsoldes.com^$all ||uptsejacketsale.com^$all ||wolverineayakkabi.com^$all ||wolverineboty.cz^$all ||wolverinechaussure.fr^$all ||wolverinejapan.com^$all ||wolverinelaarzen.com^$all ||wolverineportugal.com^$all ||wolverineschuhe.at^$all ||wolverineschuhes.de^$all ||wolverineskonorge.com^$all ||wolverinestovler.com^$all ||wolverlnejapan.com^$all ||zapatillassalomoncolombia.com^$all ||zapatosgolffootjoy.com^$all ||zapatoswolverine.com^$all ||thenorthfacenorge.co.no^$all ||tnooutlet.com^$all ||vansnorge.co.no^$all ||hunternorge.co^$all ||hunternorge.co.no^$all ||hunternorgeno.com^$all ||hokaslippers.com^$all ||hokaskooutlet.co.no^$all ||martenssalg.com^$all ||martensnorge.co.no^$all ||hoka-sko.com^$all ||norgeskotilbud.com^$all ||hokasnorgeno.com^$all ||adidasbratislava.sk^$all ||airsuomi.com^$all ||asicswebshopshu.com^$all ||brooksrunnersireland.com^$all ||brooksrunningindia.co.in^$all ||chaussurestoms.fr^$all ||clarks-romania.com^$all ||clarksshop-hu.com^$all ||clarkswyprzedaz.com^$all ||columbiaindiasale.com^$all ||columbianzoutlet.com^$all ||crocsacheter.fr^$all ||deeruptrunner.me^$all ||desertbootshop.com^$all ||docmartensnewzealand.com^$all ||eobuvecco.sk^$all ||falconportugalshop.me^$all ||fitflopsalenederland.com^$all ||footwearnl.com^$all ||footwearsalesg.com^$all ||hunter-danmark.com^$all ||hunter-espana.com^$all ||hurricane-outlet.co^$all ||keenscarpeitalia.it^$all ||keentürkiye.com^$all ||mammutsverige.com.se^$all ||mammutuksale.com^$all ||newvanshoes.co.in^$all ||nikehrvatska-hr.com^$all ||nikeportugal.pt^$all ||north-face-indirim.com^$all ||pumarea.com.se^$all ||pumatennaritale.com^$all ||rb-greece.com^$all ||rbingreece.com^$all ||rbshopgreece.com^$all ||ropapuma.com^$all ||runninginshop.com^$all ||salomonbutikdanmark.com^$all ||salomonslovensko.sk^$all ||schweizch.com^$all ||shoesstoregreece.com^$all ||sportsonlineuk.com^$all ||sportwebaruhaz.com^$all ||tiendadiadoramexico.com^$all ||tomosterreich.com^$all ||toms-budapest.com^$all ||toms-schweiz.com^$all ||tomscipo.com^$all ||tomsdeutschland.de^$all ||tomsitalia.it^$all ||tomsosterreich.at^$all ||ukhikingshop.com^$all ||vanscipok.com^$all ||vanssnorge.com^$all ||alo-yoga-turkey.com^$all ||aloyoga-chile.com^$all ||aloyogaespana.es^$all ||aloyogairelandstore.com^$all ||aloyogaturkey.com.tr^$all ||asicsisverige.com^$all ||asolobootsireland.com^$all ||asolocolombia.com^$all ||asolodeutschland.com^$all ||asolofrance.com^$all ||asoloitaliaoutlet.com^$all ||asolonederland.com^$all ||asoloportugal.com^$all ||asoloskonorge.com^$all ||asoloskor.com^$all ||betseyjohnsonitalia.com^$all ||bootspalladiumitalia.com^$all ||botasasolomexico.com^$all ||botasasolooutlet.com^$all ||boutiquehunterfrance.com^$all ||calvinkleinchileoutlet.com^$all ||calvinkleinportugalpt.com^$all ||conversecostaricaonline.com^$all ||converseuaeonlinestore.com^$all ||gantchile.com^$all ||gantcolombia.com^$all ||gantdenmark.com^$all ||gantdeutschland.com^$all ||ganthrvatska.com^$all ||gantisrael.com^$all ||gantitalia.com^$all ||gantromania.com^$all ||gantromanias.com^$all ||gantschweiz.com^$all ||gantsrbija.com^$all ||gantturkey.com^$all ||guesskobenhavn.com^$all ||guessoutletslovensko.com^$all ||guessoutletsuomi.com^$all ||guesssuomi.net^$all ||gymsharkoutlet.com.au^$all ||hoka-malaysia.com^$all ||hoka-polska.pl^$all ||hoka-spain.es^$all ||hokabaratas.com^$all ||hokaencolombia.com^$all ||hokagermany.de^$all ||hokaitaliaoutlet.it^$all ||hokaonenorge.com^$all ||hokaonlineturkiye.com^$all ||hokaportugallojas.com^$all ||hokaromania.ro^$all ||hokashopindia.net.in^$all ||hokasingapore.com^$all ||hokasklep.com^$all ||hokastoregr.com^$all ||hunter-boots-ireland.com^$all ||hunter-canada.ca^$all ||hunter-colombia.com.co^$all ||hunter-costarica.com^$all ||hunter-cz.com^$all ||hunter-greece.gr^$all ||hunter-jp.com^$all ||hunter-osterreich.at^$all ||hunter-osterreich.com^$all ||hunter-portugal.pt^$all ||hunter-romania.ro^$all ||hunter-sk.sk^$all ||hunter-slovenija.com^$all ||hunter-southafrica.com^$all ||hunter-srbija.com^$all ||hunter.com.se^$all ||hunterargentinabotas.com^$all ||hunteraustraliaau.com^$all ||hunterbelgium.com^$all ||hunterbelgiumsale.com^$all ||hunterbootchile.com^$all ||hunterboots-israel.com^$all ||hunterboots-newzealand.com^$all ||hunterbootsaus.com^$all ||hunterbootsdubai.com^$all ||hunterbootsnewzealand.co.nz^$all ||hunterbootsslovenija.com^$all ||hunterbootssouthafrica.co.za^$all ||huntercr.com^$all ||hunterfrankfurt.com^$all ||hunterhelsinki.com^$all ||hunterhrhrvatska.com^$all ||hunterhrvatskahr.com^$all ||hunteritaliaoutlet.com^$all ||hunterjapanjp.com^$all ||hunterkalosze-pl.com^$all ||hunterlaarzennederland.com^$all ||hunterluxembourg.com^$all ||huntermalaysiamy.com^$all ||huntermexicomx.com^$all ||hunterobchod.com^$all ||hunteronlineshop.de^$all ||hunteroutlet-canada.com^$all ||hunterphilippinesstore.com^$all ||hunterpolska-pl.com^$all ||hunterportugalpt.com^$all ||hunterrainbootsaustralia.com^$all ||hunterrainbootsie.com^$all ||hunterromania.net^$all ||huntershopromania.com^$all ||huntershopschweiz.com^$all ||huntersingaporesg.com^$all ||hunterskornjislovenija.com^$all ||hunterslovenija.com^$all ||huntersoldes.com^$all ||huntersrbija.org^$all ||huntersuomifi.com^$all ||hunterturkiyesatis.com^$all ||hunteruruguay.com^$all ||hunterwellies-australia.com^$all ||hunterwellies-nz.com^$all ||hunterwelliesdublin.com^$all ||hunterwellingtonsaustralia.com^$all ||hunterwinkelnederland.com^$all ||jordan-hrvatska.com^$all ||jordan-nederland.com^$all ||jordanakcio.com^$all ||jordanalesuomi.com^$all ||jordanargentinaonline.com^$all ||jordanbelgiesale.com^$all ||jordanbelgium.com^$all ||jordanberlin.de^$all ||jordanbogota.com^$all ||jordanbutysklep.pl^$all ||jordancapetown.com^$all ||jordancena.com^$all ||jordanchileoferta.com^$all ||jordaneshop.cz^$all ||jordanfiyat.com^$all ||jordanieftini.ro^$all ||jordanindirim.com^$all ||jordanjapansale.com^$all ||jordanlisboa.com^$all ||jordanljubljana.com^$all ||jordanmalaysias.com^$all ||jordanmexicomx.com^$all ||jordanoferta.ro^$all ||jordanonlinecanada.com^$all ||jordanonlinegreece.com^$all ||jordanottawa.com^$all ||jordanoutletgreece.com^$all ||jordanoutletnz.com^$all ||jordanpatike.com^$all ||jordanph.com^$all ||jordanphilippine.com^$all ||jordanportugalpt.com^$all ||jordanpromocje.pl^$all ||jordanretroschweiz.com^$all ||jordansaldi.com^$all ||jordansaleau.com^$all ||jordansaleie.com^$all ||jordansaleireland.com^$all ||jordanschuhesale.at^$all ||jordanserbia.com^$all ||jordanshopmalaysia.com^$all ||jordanskooslo.com^$all ||jordanslovenija.co^$all ||jordansneakersau.com^$all ||jordansovensko.sk^$all ||jordansuomiale.com^$all ||jordantilbud.com^$all ||jordantilbuddanmark.com^$all ||jordanuaesale.com^$all ||jordanwinkel.com^$all ||keengermany.de^$all ||keensandalertilbud.com^$all ||keenspain.es^$all ||lojasskechersportugal.com^$all ||mizuno-germany.de^$all ||mizunoencolombia.com^$all ||mizunoteniskysk.sk^$all ||moncler-israel.com^$all ||moncler-mexico.com^$all ||monclercanada.ca^$all ||monclerchile.com^$all ||monclercolombia.com^$all ||monclergreece-outlet.com^$all ||monclermalaysia.com^$all ||moncleromania.com^$all ||moncleroutletschweizs.com^$all ||monclerphilippines.com^$all ||monclersingapore.com^$all ||monclersouthafrica.co.za^$all ||monclersouthafrica.com^$all ||nikefactoryoutletau.com^$all ||nikemaroc.com^$all ||niketurkiyeshop.com^$all ||nobull-colombia.com.co^$all ||nobull-mexico.com.mx^$all ||nobullenargentina.com^$all ||nobullespanaoutlet.com^$all ||nobullro.ro^$all ||nobullsuomiale.com^$all ||nobulltürkiye.com^$all ||outletjordanitalia.com^$all ||palladium-chile.com^$all ||palladium-finland.com^$all ||palladium-philippines.com^$all ||palladiumaustraliaoutlet.com^$all ||palladiumbootscolombia.com^$all ||palladiumbootsnzoutlet.com^$all ||palladiumbootsromania.com^$all ||palladiumindonesia.com^$all ||palladiumnederland.com^$all ||palladiumoutletportugal.com^$all ||palladiumschuheaustria.com^$all ||palladiumschuheoutlet.de^$all ||palladiumshoesuae.com^$all ||palladiumsingaporestore.com^$all ||palladiumskobutikk.com^$all ||palladiumskodk.com^$all ||palladiumskorsverige.com^$all ||palladiumsouthafrica.co.za^$all ||quiksilver-france.fr^$all ||quiksilver-mexico.com.mx^$all ||quiksilverale.com^$all ||quiksilverangebot.com^$all ||quiksilveraustralia.com^$all ||quiksilveraustraliasale.com^$all ||quiksilverbrasillojas.com^$all ||quiksilvercanadasale.com^$all ||quiksilverchile.com^$all ||quiksilvercolombia.com^$all ||quiksilverdanmark.com^$all ||quiksilverenargentina.com^$all ||quiksilverenchile.com^$all ||quiksilverespana.com^$all ||quiksilvergreece.com^$all ||quiksilverindia.co.in^$all ||quiksilverindirim.com^$all ||quiksilverinofferta.com^$all ||quiksilveritalia.com^$all ||quiksilverlojas.com^$all ||quiksilvermalaysia.com^$all ||quiksilvermalaysiasale.com^$all ||quiksilvernederland.com^$all ||quiksilvernewzealand.com^$all ||quiksilvernorge.com^$all ||quiksilveroutletgreece.com^$all ||quiksilveroutletphilippines.com^$all ||quiksilveroutletpolska.com^$all ||quiksilveroutletsingapore.com^$all ||quiksilverphilippines.com^$all ||quiksilverportugal.com^$all ||quiksilverpraha.cz^$all ||quiksilverromania.com^$all ||quiksilverromania.ro^$all ||quiksilversaleindia.com^$all ||quiksilversalesouthafrica.co.za^$all ||quiksilversingapore.com^$all ||quiksilversklep.com^$all ||quiksilversouthafrica.com^$all ||quiksilversuomi.com^$all ||quiksilversverige.com^$all ||quiksilvertilbud.com^$all ||quiksilvervyprodej.com^$all ||quiksilverwinkel.com^$all ||salomocolombia.com^$all ||salomon-danmark.net^$all ||salomon-pt.com^$all ||salomon-spain.es^$all ||salomonencolombia.com^$all ||salomonfrancesoldes.fr^$all ||salomonhungary.net^$all ||salomonidanmark.com^$all ||salomoportugalonline.com^$all ||salomoslovenija.com^$all ||salomoslovensko.sk^$all ||saucony-dk.com^$all ||sauconygermany.de^$all ||sauconylaufschuhe.at^$all ||sauconyspain.es^$all ||sendrabootsdeutschland.com^$all ||sendrabootsireland.com^$all ||sendrabootsitalia.com^$all ||sendrafrance.com^$all ||skecherchile.com^$all ||skechers-colombia.com.co^$all ||skechers-spain.es^$all ||skechersfactoryoutletau.com^$all ||skechersmexicotienda.com^$all ||skechersshoesnzoutlet.com^$all ||teniskyvejaobuv.sk^$all ||tiendahunterchile.com^$all ||tiendahuntermadrid.com^$all ||tiendajordanargentina.com^$all ||tiendaquiksilvercolombia.com^$all ||tiendaquiksilvermexico.com^$all ||underarmourenecuador.com^$all ||vejagermany.de^$all ||vejasneakers.se^$all ||vejasneakersmexico.com.mx^$all ||moncleritalia.com^$all ||alexandermcqueenboty.cz^$all ||alexandermcqueenskor.com.se^$all ||alexandermcqueentenisce.com^$all ||alexandermcqueentenisky.sk^$all ||alexandermcqueentenls.com^$all ||axelarigato.com.se^$all ||axelarigatoboty.cz^$all ||axelarigatokobenhavn.com^$all ||axelarigatos.com.se^$all ||axelarigatosapatilhas.com^$all ||axelarigatoshoesnz.com^$all ||axelarigatoslovakia.com^$all ||axelarigatosneakersnl.com^$all ||axelarigatozagreb.com^$all ||bootsonlineindia.com^$all ||botteshunterfrance.fr^$all ||cizmeshopromania.com^$all ||demoniasjapan.com^$all ||dieseljeancolombia.com^$all ||dieseljeanscolombia.com^$all ||drmarswebshop.com^$all ||enucuzsuperdry.com^$all ||gummistiefelhunter.de^$all ||gummistøvlerhunter.com^$all ||hokalopesko.com^$all ||hokanorgeno.com^$all ||hokaonelopesko.com^$all ||huntegummistiefeloutlet.com^$all ||huntegummistiefelsale.com^$all ||hunteranbootsindia.com^$all ||hunterbootcanada.com^$all ||hunterholinky.com^$all ||hunterirelandonline.com^$all ||hunterlaarzenbelgle.com^$all ||hunterlaarzendames.com^$all ||hunteronlinesverige.com^$all ||hunteroutletireland.com^$all ||hunterstovlersalg.com^$all ||hunterwelliesirelandsale.com^$all ||lacostemagyarorszag.com^$all ||marbotysleva.cz^$all ||martenbratislava.sk^$all ||martengreece.com^$all ||martenportugal.com^$all ||martensbotysleva.cz^$all ||martenshelsinki.net^$all ||martenshrvatska.co^$all ||mcqueen-philippines.com^$all ||mcqueenauckland.com^$all ||mcqueencolombia.com^$all ||mcqueenitalian.com^$all ||mcqueenmalaysiamy.com^$all ||mcqueensouthafrica.com^$all ||mcqueensouthafrlca.com^$all ||merrellespanatiendas.com^$all ||merrellshoeaustralia.com^$all ||merrellshoesoutletus.com^$all ||merrellwanderschuhe.de^$all ||merrelshoesnzsale.com^$all ||merrelshoesuksale.com^$all ||merrelturkiyetr.com^$all ||mizunonewzealandnz.com^$all ||mizunoshoesforsale.com^$all ||mizunoshoesingapore.com^$all ||nana-vypredaj.sk^$all ||nanasuomi.com^$all ||nanavypredaj.sk^$all ||nbpolskaonline.com^$all ||neweraindlacap.com^$all ||niketrindirim.com^$all ||salomomnorgeoutlet.com^$all ||salonomaustria.com^$all ||salonomireland.com^$all ||salonomitalia.com^$all ||salonomportugal.com^$all ||salonomslovensko.com^$all ||salononfranceonline.com^$all ||salononsverige.com^$all ||stivalihuntersaldi.com^$all ||superdryfactorysg.com^$all ||tenishokaoneone.com^$all ||tevasandalehrvatska.com^$all ||vans-finland.com^$all ||martensbratislava.sk^$all ||zapatillasmcqueen.com^$all ! https://app.any.run/tasks/8ced67f6-f4e6-4fed-b634-86fd93ac4074/ ||darkinfotale.xyz^$all ||f.estivaltodayz.com^$document ||hollandcash.nl^$all ||exit.hollandcash.nl^$all ||clean-blocker.com^$all ||chrome.google.com/webstore/detail/cleanblocker/obhoainpkkkkjeegnbaobapedpfdhbdl^$all ! https://github.com/DandelionSprout/adfilt/issues/752 ||omclyzyapf.com^$all ||godpvqnszo.com^$popup ||news-mapara.com^$all ||vipdatingtoday.top^$all ||mo4ckid.click^$all ||xxxnewvideos.com^$all ||iseult-aplite.xyz^$all ||img.pushflow.net/creatives/11/5645/1649754393755-push-preview-img.png^$all ||theantivirusprotection.xyz^$all ||1.news-mapara.com^$all ||battik-bowwow.xyz^$all ||2.news-mapara.com^$all ||pshsbscapr.xyz^$all ||cdn.pncloudfl.com/pn/f83/d57/83b/f83d5783b20e21e0de65e6f7f632cde8a29b9ef6.jpg^$all ||click01.pshtrkg.com^$document ||4bd71.trknovi.com^$document ||jergocast.com^$document ||news-pelivo.com^$all ||img.pushflow.net/creatives/11/5645/1649755151938-push-preview-img.png^$all ! https://app.any.run/tasks/cc3be172-9813-4637-914b-533ac2b72299 ||getfreegem.com^$all ||gamingtoolz.club^$all ! from notification scams ||nahist.live^$all ||redins.live^$all ||carltus.click^$all ||www.carltus.click^$all ||renhadmasandbab.info^$document ||bestadultdatinglist-com.ru^$document ||findflirtpartner6.euroshoptrendingclub.ru^$document ||h.curedating.top^$all ||martoysure.live^$all ||goodgollygold.com^$document ! https://www.virustotal.com/gui/domain/beastws.com ! (my analysis) https://app.any.run/tasks/dc144216-7c8d-4a2b-963e-24b507124e81 ||beastws.com^$all ! https://github.com/no-cmyk/Search-Engine-Spam-Blocklist/issues/8 ! TODO: verify these entries, hopefully there aren't any more https://github.com/hagezi/dns-blocklists/issues/987 !#if false ||adajobs.de^$document ||appart-vermietung.de^$document ||baderus.de^$document ||bermudez-portfolio.de^$document ||carpenteriekluc.it^$document ||charlotte-wilking.de^$document ||conradlentz.de^$document ||corexonline.de^$document ||dierhagen-ostsee.de^$document ||digitalplm.de^$document ||e-dos.pl^$document ||eltruciolo.it^$document ||essen-inline-skating.de^$document ||forstbetrieb-reichel.de^$document ||fotogruppe-iserlohn.de^$document ||fw-muensing.de^$document ||honighelmut.de^$document ||hostingnetwork24.de^$document ||hunsruecker-damwild.de^$document ||hypnose-kunz.de^$document ||ilcolibri.it^$document ||lhm-as.de^$document ||lotuslebanon.com^$document ||mainradweg-service.de^$document ||massaggisensitive.it^$document ||misericordiapompei.it^$document ||molinariprotection.it^$document ||new-work-in-mv.de^$document ||nick-duschek.de^$document ||officinavettoriale.it^$document ||schnelltests-ludwigsburg.de^$document ||snehpandya.me^$document ||spiritoemateria.it^$document ||stahl-rohr-moebel.de^$document ||tipps-staedtereisen.de^$document !#endif ! https://app.any.run/tasks/e90c2a06-036f-4fff-a36f-dffd0d4048ab ||doxspb.adajobs.de^$all ||giftaward.life^$all ! https://github.com/badmojr/1Hosts/issues/1098 ||elon23.page.link^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/142492 --> https://github.com/uBlockOrigin/uAssets/commit/fca5436e3e823d73541721867f42dd0712da54a0 ||apkmirror.co^$all ||webogram.org^$all ||webogram.ru^$all ||xn--80affa3aj0al.xn--80asehdb^$all ||telegr.am/user_mgt/login$all ||tgram.ru^$all ||telegramm.site^$all ||web-telegram.net^$all ! other domains not in the uBo commit ||atm-receipts.neocities.org^$document ||apkmirror.net^$document ||github.me^$document ||yandec.ru^$document ||yandex.co^$document ! https://scammer.info/t/pop-up-888-804-8031/121011 ! a test system ||paleks.live^$all ||kempus.click^$all ||www.kempus.click^$all ||webpick-cdn.s3.amazonaws.com/2%20-%20pending%20massage.jpeg$all ! https://app.any.run/tasks/3f79c271-f68d-48a8-af16-efd001ce7be3 ||mwgtf.hintonjour.com^$all ||oqnvm.top^$all ||edkiu.top^$all ||mvv5i.top^$all ||e8tov.top^$all ||rvueo.top^$all ||up9rt.top^$all ||rx93u.top^$all ||usfo6.top^$all ||bdlj8.top^$all ||bqcqw.top^$all ! https://github.com/AdguardTeam/AdguardFilters/issues/143281 ||understatedworking.com^$all ||jatostepa.com^$all ! https://forums.malwarebytes.com/topic/295377-false-mcaffee-warning/ (account required) ||powerpcsupport.com^$document ! https://github.com/hagezi/dns-blocklists/issues/598 ||t-post.com^$all ! https://github.com/hagezi/dns-blocklists/issues/597 ||stallioncredit.com^$all ! https://github.com/hagezi/dns-blocklists/issues/596 ||www.68437w.top^$all ! https://github.com/hagezi/dns-blocklists/issues/595 ||goldtimeinvest.com^$all ! https://github.com/hagezi/dns-blocklists/issues/594 ||nirvezal.com^$all ! https://www.virustotal.com/gui/url/09440e588a0f6992de1f2b85b05eb915e3fbca4f201e151038802bdd790da2cc/community ! https://www.virustotal.com/gui/url/9100833bcdcbcf5b8c2f3b56fe9b77d02f3a574b93a736e0d73e0c83a1cbf983/community ! https://www.virustotal.com/gui/url/413da77a326371e24a4c334e749a54928b43ee6bcd27165167940456b9c14f52/community ||eg-ame.com^$all ! https://forums.malwarebytes.com/topic/295588-support-scam-supportclientexe-and-screenconnectwindowsclientexe/ (account required) ! https://forums.malwarebytes.com/topic/295605-techsupport-scam/ (account required) ! https://github.com/AdguardTeam/AdguardFilters/issues/144514 ||attractbonus.life^$all ||best-prize.life^$all ||bestbigbonus.life^$all ||bonusgift.life^$all ||bonusreward.life^$all ||bonusscore.life^$all ||gainquick.life^$all ||giftjackpot.life^$all ||greatbonushere.life^$all ||greatprizes.life^$all ||jackpotscore.life^$all ||jackpotwinning.life^$all ||keep-rewards.life^$all ||keepbonus.life^$all ||keepreward.life^$all ||mygreatprize.life^$all ||prizeaward.life^$all ||prizefast.life^$all ||prizegain.life^$all ||prizehere.life^$all ||prizerush.life^$all ||prizesenses.life^$all ||prizesure.life^$all ||realgift.life^$all ||rewardgains.life^$all ||scorereward.life^$all ||simpleprize.life^$all ||simplewin.life^$all ||taketheprizes.life^$all ||topbonusgain.life^$all ||win-bonus.life^$all ||win-prize-now.life^$all ||win-prize.life^$all ||win-touch.life^$all ||winbigdrip.life^$all ||wincorporate.life^$all ||winearth.life^$all ||winexpert.life^$all ||wingiftnow.life^$all ||winmore.life^$all ||winprizehere.life^$all ||winpulse.life^$all ||winregistry.life^$all ||winsimply.life^$all ||wintarget.life^$all ||185.155.184.98^$document ! https://www.virustotal.com/gui/url/f81cf3b28a018e74571e9287064f335fde30be757b822b1014ab24480dfcd9ad/community ! (my analysis) https://app.any.run/tasks/d7861c5a-d032-4529-98fe-42e99e077a34 ! https://github.com/uBlockOrigin/uAssets/issues/17075 ! my analysis: https://app.any.run/tasks/ed301c03-1105-47e5-88d1-66fded6a0a9b ||myspecialdates.com^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/144823 ! https://www.reddit.com/r/uBlockOrigin/comments/11s92xa/badware_risks_page_request_malware/ ||s3.amazonaws.com/extpro/speed4.html$all ||chrome.google.com/webstore/detail/speed-dial/pbclkopbecbmkiijepgjoodiidfkbchn/$document ||www.addonsearch.net^$document ! https://app.any.run/tasks/794fc4f3-e0da-49b0-b29b-304514a8bd2d ||70k-free-robux-generator-no-human-verification.statuspage.io^$all ||bettertool.xyz^$all ! elon musk crypto scam on hacked YouTube channels ! https://app.any.run/tasks/2963db56-bd87-4b82-8b24-97e6e68aef66/ ||x2-promo.net^$all ! https://tria.ge/230318-twrw1ach63/behavioral1 ||teslasend.io^$all ! https://app.any.run/tasks/4a2f1865-80be-4726-8d03-59687de38e65/ ! https://app.any.run/tasks/b8a7501d-77e5-47dc-879b-eb43625728db ! https://forums.malwarebytes.com/topic/296022-comment-spam-from-my-site/ (account required) ! (my analysis) NSFW https://app.any.run/tasks/cd2d1278-ad10-4c38-8f49-fa34fa675820 ||f.vipcooldating.top^$all ||vipcooldating.top^$all ||i.vipcooldating.top^$all ! https://github.com/durablenapkin/scamblocklist/issues/10 ||adzfree-watch.net^$document ! https://github.com/AdguardTeam/AdguardFilters/commit/57f39538070d7d5e6379da4e58bd02defffa7481 ||ikouthaupi.com^$all ||instreamersdian.com^$all ! https://app.any.run/tasks/31119ba0-9bf8-42e2-8e77-eec9045be865 ||applover.net^$all ! https://app.any.run/tasks/89a5c643-ba0f-4bb6-b953-ef08ee0213ef ||youtubgenerator.w3spaces.com^$all ! https://app.any.run/tasks/482b8fa1-0f24-461a-a4f5-a6996c46ccdc/ ||rewards24.onlinewebshop.net^$all ||locked3.com^$document ||cdn.locked3.com^$document ! https://github.com/durablenapkin/scamblocklist/issues/15 ||thuthuatxiaomi.com^$document ||petsimulator.live^$document ||rewardsgiantca.com^$document ||earnpets.com^$document ! https://github.com/durablenapkin/scamblocklist/issues/14 ! (my analysis) https://tria.ge/230404-27rdlsce3y/behavioral1 ! https://0xacab.org/my-privacy-dns/matrix/-/issues/90853 ! (my analysis) https://app.any.run/tasks/029760ea-9972-4c3a-8a7e-cca3d7777c0f ||emeraldtrking.com^$all ! https://0xacab.org/my-privacy-dns/matrix/-/issues/90813 ! (my analysis) https://app.any.run/tasks/0992866b-9af2-41ba-9b91-8fe5a2917908 ||bbxxvwb.tk^$all ! https://github.com/StevenBlack/hosts/issues/2271 ||transive.top^$document ||warehousesale.shop^$document ! https://github.com/durablenapkin/scamblocklist/issues/17 ! https://app.any.run/tasks/3137c861-185d-4037-84e9-65cc0adeba15 ||bgqcb.econsultingcoem.com^$all ||econsultingcoem.com^$document ||j4352.top^$all ||emqu4.top^$all ||kp0z3.top^$all ||kxaie.top^$all ! https://app.any.run/tasks/7626fdcc-20f1-4471-a011-23108f113eca ! https://app.any.run/tasks/4bc28a83-6a39-430a-a74b-246b30ab4ae4 ||fuwins.xyz^$all .xyz/1Sm/9.html?*&campaign_id=$document ! https://www.virustotal.com/gui/ip-address/157.230.4.182/relations ||157.230.4.182^$document ! on the same IP, I tried a few and all of them hosted the same scam page (i.e. https://app.any.run/tasks/e9fd2b7d-d8cc-40dc-aa65-daaee7bc5558) ||gedins.xyz^$document ||gemins.xyz^$document ||fofins.xyz^$document ||gekins.xyz^$document ||gegins.xyz^$document ||gecins.xyz^$document ||cebens.xyz^$document ||gifirs.xyz^$document ||cexens.xyz^$document ||buvers.xyz^$document ||lohens.xyz^$document ||lodens.xyz^$document ||luvens.xyz^$document ||busers.xyz^$document ||laxens.xyz^$document ||bumers.xyz^$document ||lazens.xyz^$document ||lufens.xyz^$document ||latens.xyz^$document ||bijers.xyz^$document ||luxens.xyz^$document ||lavens.xyz^$document ||lolens.xyz^$document ||lubens.xyz^$document ||buders.xyz^$document ||baxers.xyz^$document ||bukers.xyz^$document ||buwers.xyz^$document ||bisers.xyz^$document ||bipers.xyz^$document ||bahers.xyz^$document ||lotens.xyz^$document ||lapens.xyz^$document ||ladens.xyz^$document ||basers.xyz^$document ||bugers.xyz^$document ||loxens.xyz^$document ||lowens.xyz^$document ||baters.xyz^$document ||lafens.xyz^$document ||lutens.xyz^$document ||lasens.xyz^$document ||bupers.xyz^$document ||locens.xyz^$document ||buzers.xyz^$document ||bubers.xyz^$document ||lojens.xyz^$document ||biwers.xyz^$document ||bufers.xyz^$document ||buhers.xyz^$document ||losens.xyz^$document ||lopens.xyz^$document ||bucers.xyz^$document ||lagens.xyz^$document ||bagers.xyz^$document ||birers.xyz^$document ||lozens.xyz^$document ||lusens.xyz^$document ||biders.xyz^$document ||buters.xyz^$document ||lawens.xyz^$document ||burers.xyz^$document ||lalens.xyz^$document ||bafers.xyz^$document ||bulers.xyz^$document ||lacens.xyz^$document ||lomens.xyz^$document ||balers.xyz^$document ||luzens.xyz^$document ||lahens.xyz^$document ||bavers.xyz^$document ||lokens.xyz^$document ||baders.xyz^$document ||bawers.xyz^$document ||bihers.xyz^$document ||lulens.xyz^$document ||bacers.xyz^$document ||labens.xyz^$document ||bazers.xyz^$document ||bapers.xyz^$document ||bajers.xyz^$document ||bifers.xyz^$document ||bujers.xyz^$document ||barers.xyz^$document ||lajens.xyz^$document ||buners.xyz^$document ||babers.xyz^$document ||bigers.xyz^$document ||lobens.xyz^$document ||buxers.xyz^$document ||cevens.xyz^$document ||cetens.xyz^$document ||barins.xyz^$document ||bamins.xyz^$document ||bakins.xyz^$document ||biwins.xyz^$document ||lurens.xyz^$document ||lupens.xyz^$document ||bacins.xyz^$document ||luwens.xyz^$document ||lujens.xyz^$document ||luhens.xyz^$document ||lunens.xyz^$document ||lonens.xyz^$document ||logens.xyz^$document ||lanens.xyz^$document ||lofens.xyz^$document ||tesens.xyz^$document ||sibans.xyz^$document ||ricens.xyz^$document ||rapens.xyz^$document ||rorens.xyz^$document ||tonens.xyz^$document ||sowans.xyz^$document ||tikens.xyz^$document ||tilens.xyz^$document ||ribens.xyz^$document ||setans.xyz^$document ||rofens.xyz^$document ||simans.xyz^$document ||rarens.xyz^$document ||ronens.xyz^$document ||sefans.xyz^$document ||sonans.xyz^$document ||terens.xyz^$document ||sijans.xyz^$document ||rolens.xyz^$document ||sexans.xyz^$document ||roxens.xyz^$document ||tigens.xyz^$document ||rabens.xyz^$document ||toxens.xyz^$document ||tolens.xyz^$document ||sixans.xyz^$document ||ripens.xyz^$document ||rimens.xyz^$document ||romens.xyz^$document ||sidans.xyz^$document ||ralens.xyz^$document ||sizans.xyz^$document ||todens.xyz^$document ||sehans.xyz^$document ||rawens.xyz^$document ||tevens.xyz^$document ||rocens.xyz^$document ||tibens.xyz^$document ||sikans.xyz^$document ||rozens.xyz^$document ||rivens.xyz^$document ||tivens.xyz^$document ||rizens.xyz^$document ||tegens.xyz^$document ||sepans.xyz^$document ||rafens.xyz^$document ||rilens.xyz^$document ||ragens.xyz^$document ||sohans.xyz^$document ||tirens.xyz^$document ||rohens.xyz^$document ||tehens.xyz^$document ||rifens.xyz^$document ||selans.xyz^$document ||tixens.xyz^$document ||riwens.xyz^$document ||sirans.xyz^$document ||rakens.xyz^$document ||tofens.xyz^$document ||tipens.xyz^$document ||tepens.xyz^$document ||tocens.xyz^$document ||ratens.xyz^$document ||rihens.xyz^$document ||sorans.xyz^$document ||racens.xyz^$document ||silans.xyz^$document ||ticens.xyz^$document ||tewens.xyz^$document ||tojens.xyz^$document ||rasens.xyz^$document ||rahens.xyz^$document ||rijens.xyz^$document ||rokens.xyz^$document ||tifens.xyz^$document ||towens.xyz^$document ||tisens.xyz^$document ||raxens.xyz^$document ||serans.xyz^$document ||sihans.xyz^$document ||tizens.xyz^$document ||rikens.xyz^$document ||radens.xyz^$document ||sitans.xyz^$document ||rovens.xyz^$document ||sekans.xyz^$document ||sokans.xyz^$document ||sifans.xyz^$document ||sezans.xyz^$document ||ritens.xyz^$document ||tihens.xyz^$document ||rinens.xyz^$document ||sivans.xyz^$document ||ropens.xyz^$document ||sesans.xyz^$document ||tinens.xyz^$document ||rotens.xyz^$document ||sobans.xyz^$document ||torens.xyz^$document ||rirens.xyz^$document ||semans.xyz^$document ||temens.xyz^$document ||tovens.xyz^$document ||tebens.xyz^$document ||sigans.xyz^$document ||sisans.xyz^$document ||socans.xyz^$document ||risens.xyz^$document ||ridens.xyz^$document ||rixens.xyz^$document ||texens.xyz^$document ||sipans.xyz^$document ||siwans.xyz^$document ||tedens.xyz^$document ||rigens.xyz^$document ||tejens.xyz^$document ||senans.xyz^$document ||rowens.xyz^$document ||soxans.xyz^$document ||tecens.xyz^$document ||totens.xyz^$document ||tozens.xyz^$document ||rajens.xyz^$document ||ranens.xyz^$document ||sewans.xyz^$document ||tosens.xyz^$document ||timens.xyz^$document ||razens.xyz^$document ||somans.xyz^$document ||tezens.xyz^$document ||sogans.xyz^$document ||sozans.xyz^$document ||sicans.xyz^$document ||secans.xyz^$document ||tiwens.xyz^$document ||sinans.xyz^$document ||tohens.xyz^$document ||larens.xyz^$document ||togens.xyz^$document ||gicurs.xyz^$document ||tobens.xyz^$document ||tijens.xyz^$document ||tidens.xyz^$document ||sovans.xyz^$document ||sotans.xyz^$document ||sosans.xyz^$document ||sojans.xyz^$document ||hohers.xyz^$document ||gizurs.xyz^$document ||humers.xyz^$document ||hogers.xyz^$document ||mitans.xyz^$document ||huners.xyz^$document ||giwirs.xyz^$document ||mucans.xyz^$document ||hurers.xyz^$document ||hoders.xyz^$document ||gipirs.xyz^$document ||muxans.xyz^$document ||gipurs.xyz^$document ||movans.xyz^$document ||mubans.xyz^$document ||hicers.xyz^$document ||mixans.xyz^$document ||hipers.xyz^$document ||hibers.xyz^$document ||gibirs.xyz^$document ||huhers.xyz^$document ||monans.xyz^$document ||hisers.xyz^$document ||hozers.xyz^$document ||hujers.xyz^$document ||mizans.xyz^$document ||mopans.xyz^$document ||honers.xyz^$document ||gihurs.xyz^$document ||huders.xyz^$document ||gicirs.xyz^$document ||gikurs.xyz^$document ||molans.xyz^$document ||huters.xyz^$document ||holers.xyz^$document ||hobers.xyz^$document ||modans.xyz^$document ||gilurs.xyz^$document ||hiters.xyz^$document ||mozans.xyz^$document ||mupans.xyz^$document ||higers.xyz^$document ||hocers.xyz^$document ||mukans.xyz^$document ||musans.xyz^$document ||hizers.xyz^$document ||husers.xyz^$document ||muvans.xyz^$document ||gixurs.xyz^$document ||migans.xyz^$document ||givirs.xyz^$document ||gimurs.xyz^$document ||mufans.xyz^$document ||mipans.xyz^$document ||giwurs.xyz^$document ||ginurs.xyz^$document ||gifurs.xyz^$document ||mogans.xyz^$document ||munans.xyz^$document ||gixers.xyz^$document ||giwers.xyz^$document ||gisers.xyz^$document ||mumans.xyz^$document ||mojans.xyz^$document ||gidurs.xyz^$document ||gijers.xyz^$document ||gilers.xyz^$document ||mujans.xyz^$document ||gitirs.xyz^$document ||gifers.xyz^$document ||hijers.xyz^$document ||muwans.xyz^$document ||mohans.xyz^$document ||hiners.xyz^$document ||ginirs.xyz^$document ||moxans.xyz^$document ||hupers.xyz^$document ||huwers.xyz^$document ||gigers.xyz^$document ||gisirs.xyz^$document ||hucers.xyz^$document ||howers.xyz^$document ||hokers.xyz^$document ||gimirs.xyz^$document ||gipers.xyz^$document ||gidirs.xyz^$document ||mibans.xyz^$document ||gikirs.xyz^$document ||giners.xyz^$document ||minans.xyz^$document ||gizers.xyz^$document ||mofans.xyz^$document ||mulans.xyz^$document ||hifers.xyz^$document ||mutans.xyz^$document ||mimans.xyz^$document ||gizirs.xyz^$document ||mosans.xyz^$document ||hiwers.xyz^$document ||miwans.xyz^$document ||gihirs.xyz^$document ||mugans.xyz^$document ||muzans.xyz^$document ||gijirs.xyz^$document ||gilirs.xyz^$document ||girirs.xyz^$document ||gijurs.xyz^$document ||gimers.xyz^$document ||hirers.xyz^$document ||mudans.xyz^$document ||sopans.xyz^$document ||solans.xyz^$document ||giders.xyz^$document ||sodans.xyz^$document ||irejad.life^$document ||segans.xyz^$document ||sejans.xyz^$document ||hosers.xyz^$document ||hoxers.xyz^$document ||mijans.xyz^$document ||sebans.xyz^$document ||tetens.xyz^$document ||tekens.xyz^$document ||telens.xyz^$document ||tefens.xyz^$document ||giwens.com^$document ||sporens.com^$document ||tihens.com^$document ||tomens.xyz^$document ||givurs.xyz^$document ||giturs.xyz^$document ||bipens.xyz^$document ||bafens.xyz^$document ||bizens.xyz^$document ||biwens.xyz^$document ||hovens.xyz^$document ||huhens.xyz^$document ||guters.xyz^$document ||hucens.xyz^$document ||abirs.xyz^$document ||hakens.xyz^$document ||ahirs.xyz^$document ||bolens.xyz^$document ||botens.xyz^$document ||gojers.xyz^$document ||bagens.xyz^$document ||gozers.xyz^$document ||gulers.xyz^$document ||gujers.xyz^$document ||gomers.xyz^$document ||bahens.xyz^$document ||bixens.xyz^$document ||hirens.xyz^$document ||arirs.xyz^$document ||azirs.xyz^$document ||gohers.xyz^$document ||bapens.xyz^$document ||avors.xyz^$document ||ajirs.xyz^$document ||bisens.xyz^$document ||bopens.xyz^$document ||howens.xyz^$document ||gocers.xyz^$document ||ahors.xyz^$document ||husens.xyz^$document ||bodens.xyz^$document ||bigens.xyz^$document ||bosens.xyz^$document ||guvers.xyz^$document ||hutens.xyz^$document ||hafens.xyz^$document ||boxens.xyz^$document ||bijens.xyz^$document ||apors.xyz^$document ||axers.xyz^$document ||hoxens.xyz^$document ||babens.xyz^$document ||ajers.xyz^$document ||abers.xyz^$document ||akors.xyz^$document ||anirs.xyz^$document ||bohens.xyz^$document ||gufers.xyz^$document ||homens.xyz^$document ||awirs.xyz^$document ||huwens.xyz^$document ||bofens.xyz^$document ||adirs.xyz^$document ||anors.xyz^$document ||binens.xyz^$document ||bihens.xyz^$document ||bocens.xyz^$document ||huvens.xyz^$document ||holens.xyz^$document ||goders.xyz^$document ||hugens.xyz^$document ||awers.xyz^$document ||gugers.xyz^$document ||axors.xyz^$document ||borens.xyz^$document ||bicens.xyz^$document ||birens.xyz^$document ||higens.xyz^$document ||gurers.xyz^$document ||acors.xyz^$document ||bavens.xyz^$document ||barens.xyz^$document ||apirs.xyz^$document ||atirs.xyz^$document ||awors.xyz^$document ||guners.xyz^$document ||bibens.xyz^$document ||gumers.xyz^$document ||agirs.xyz^$document ||gupers.xyz^$document ||arors.xyz^$document ||alirs.xyz^$document ||guxers.xyz^$document ||guzers.xyz^$document ||humens.xyz^$document ||golers.xyz^$document ||hosens.xyz^$document ||hukens.xyz^$document ||bimens.xyz^$document ||hogens.xyz^$document ||goters.xyz^$document ||gokers.xyz^$document ||guwers.xyz^$document ||bamens.xyz^$document ||asirs.xyz^$document ||arers.xyz^$document ||guders.xyz^$document ||ators.xyz^$document ||bilens.xyz^$document ||asors.xyz^$document ||aders.xyz^$document ||avirs.xyz^$document ||asers.xyz^$document ||axirs.xyz^$document ||gosers.xyz^$document ||hipens.xyz^$document ||guhers.xyz^$document ||baxens.xyz^$document ||afors.xyz^$document ||bogens.xyz^$document ||gopers.xyz^$document ||bokens.xyz^$document ||goxers.xyz^$document ||huzens.xyz^$document ||gucers.xyz^$document ||akirs.xyz^$document ||amers.xyz^$document ||aters.xyz^$document ||bazens.xyz^$document ||gukers.xyz^$document ||bifens.xyz^$document ||gowers.xyz^$document ||alers.xyz^$document ||abors.xyz^$document ||gusers.xyz^$document ||gisurs.xyz^$document ||gicers.xyz^$document ||hihers.xyz^$document ||gubers.xyz^$document ||girurs.xyz^$document ||giburs.xyz^$document ||gorers.xyz^$document ||huxens.xyz^$document ||hurens.xyz^$document ||hulens.xyz^$document ||hupens.xyz^$document ||hunens.xyz^$document ||hujens.xyz^$document ||hufens.xyz^$document ||ahers.xyz^$document ||hudens.xyz^$document ||hubens.xyz^$document ||hozens.xyz^$document ||horens.xyz^$document ||bikens.xyz^$document ||hopens.xyz^$document ||honens.xyz^$document ||gawirs.xyz^$document ||gepirs.xyz^$document ||gesirs.xyz^$document ||gelirs.xyz^$document ||gazirs.xyz^$document ||disirs.xyz^$document ||gevirs.xyz^$document ||gacirs.xyz^$document ||gahirs.xyz^$document ||dovirs.xyz^$document ||dipirs.xyz^$document ||gagirs.xyz^$document ||gekirs.xyz^$document ||gajirs.xyz^$document ||dogirs.xyz^$document ||gemirs.xyz^$document ||getirs.xyz^$document ||denirs.xyz^$document ||gebirs.xyz^$document ||galirs.xyz^$document ||gatirs.xyz^$document ||gabirs.xyz^$document ||gamirs.xyz^$document ||gasirs.xyz^$document ||gonirs.xyz^$document ||garirs.xyz^$document ||gozirs.xyz^$document ||gafirs.xyz^$document ||ganirs.xyz^$document ||hawens.xyz^$document ||hibens.xyz^$document ||hocens.xyz^$document ||bajens.xyz^$document ||dozirs.xyz^$document ||doxirs.xyz^$document ||hihens.xyz^$document ||dojirs.xyz^$document ||dizirs.xyz^$document ||gowirs.xyz^$document ||hobens.xyz^$document ||hicens.xyz^$document ||dorirs.xyz^$document ||dotirs.xyz^$document ||bawens.xyz^$document ||dohirs.xyz^$document ||hilens.xyz^$document ||bacens.xyz^$document ||gecirs.xyz^$document ||himens.xyz^$document ||hikens.xyz^$document ||batens.xyz^$document ||gopirs.xyz^$document ||haxens.xyz^$document ||acirs.xyz^$document ||gehirs.xyz^$document ||bakens.xyz^$document ||hixens.xyz^$document ||hinens.xyz^$document ||hijens.xyz^$document ||dofirs.xyz^$document ||hanens.xyz^$document ||hodens.xyz^$document ||hazens.xyz^$document ||gezirs.xyz^$document ||hahens.xyz^$document ||donirs.xyz^$document ||goxirs.xyz^$document ||gobers.xyz^$document ||govirs.xyz^$document ||hofens.xyz^$document ||gosirs.xyz^$document ||dosirs.xyz^$document ||basens.xyz^$document ||gorirs.xyz^$document ||hizens.xyz^$document ||hamens.xyz^$document ||gewirs.xyz^$document ||hajens.xyz^$document ||hacens.xyz^$document ||afirs.xyz^$document ||hivens.xyz^$document ||gedirs.xyz^$document ||harens.xyz^$document ||banens.xyz^$document ||hadens.xyz^$document ||habens.xyz^$document ||hohens.xyz^$document ||hidens.xyz^$document ||hifens.xyz^$document ||afers.xyz^$document ||hiwens.xyz^$document ||gisid.live^$document ||gejirs.xyz^$document ||hokens.xyz^$document ||hojens.xyz^$document ||hisens.xyz^$document ||hatens.xyz^$document ||gotirs.xyz^$document ||badens.xyz^$document ||gerirs.xyz^$document ||hapens.xyz^$document ||hasens.xyz^$document ||dolirs.xyz^$document ||gexirs.xyz^$document ||dowirs.xyz^$document ||dokirs.xyz^$document ||dopirs.xyz^$document ||dodirs.xyz^$document ||repins.xyz^$document ||mepir.live^$document ||rajist.xyz^$document ||repis.xyz^$document ||mesir.live^$document ||ropist.xyz^$document ||rekis.xyz^$document ||rejis.xyz^$document ||tapins.xyz^$document ||mepor.live^$document ||tarins.xyz^$document ||rejins.xyz^$document ||metir.live^$document ||mefor.live^$document ||tewins.xyz^$document ||rojist.xyz^$document ||towins.xyz^$document ||rezis.xyz^$document ||meror.live^$document ||rekins.xyz^$document ||recins.xyz^$document ||mebir.live^$document ||rakist.xyz^$document ||renins.xyz^$document ||rerins.xyz^$document ||mahey.live^$document ||rewis.xyz^$document ||menor.live^$document ||radist.xyz^$document ||raxist.xyz^$document ||razist.xyz^$document ||nupges.live^$document ||rogist.xyz^$document ||retins.xyz^$document ||mexor.live^$document ||rehis.xyz^$document ||rocist.xyz^$document ||rezins.xyz^$document ||memir.live^$document ||ravist.xyz^$document ||nuhges.live^$document ||rohist.xyz^$document ||nujges.live^$document ||nuwges.live^$document ||refins.xyz^$document ||majey.live^$document ||rexins.xyz^$document ||redins.xyz^$document ||robist.xyz^$document ||relins.xyz^$document ||rugist.xyz^$document ||rewins.xyz^$document ||revins.xyz^$document ||telins.xyz^$document ||gokirs.xyz^$document ||dobirs.xyz^$document ||docirs.xyz^$document ||dicirs.xyz^$document ||demirs.xyz^$document ||rehins.xyz^$document ||togins.xyz^$document ||dexirs.xyz^$document ||dirirs.xyz^$document ||didirs.xyz^$document ||diwirs.xyz^$document ||gobirs.xyz^$document ||golirs.xyz^$document ||rusist.xyz^$document ||gadirs.xyz^$document ||gavirs.xyz^$document ||degirs.xyz^$document ||dijirs.xyz^$document ||dikirs.xyz^$document ||tevins.xyz^$document ||ditirs.xyz^$document ||rovist.xyz^$document ||romist.xyz^$document ||devirs.xyz^$document ||tojins.xyz^$document ||gapirs.xyz^$document ||ruzist.xyz^$document ||dezirs.xyz^$document ||girod.live^$document ||digirs.xyz^$document ||rudist.xyz^$document ||delirs.xyz^$document ||tonins.xyz^$document ||tofins.xyz^$document ||rupist.xyz^$document ||godirs.xyz^$document ||detirs.xyz^$document ||ruhist.xyz^$document ||gaxirs.xyz^$document ||decirs.xyz^$document ||gohirs.xyz^$document ||dilirs.xyz^$document ||rotist.xyz^$document ||gogirs.xyz^$document ||dewirs.xyz^$document ||dedirs.xyz^$document ||derirs.xyz^$document ||ruxist.xyz^$document ||defirs.xyz^$document ||dejirs.xyz^$document ||depirs.xyz^$document ||gired.live^$document ||tozins.xyz^$document ||tesins.xyz^$document ||difirs.xyz^$document ||gofirs.xyz^$document ||gakirs.xyz^$document ||dehirs.xyz^$document ||dihirs.xyz^$document ||rolist.xyz^$document ||rukist.xyz^$document ||dekirs.xyz^$document ||tovins.xyz^$document ||todins.xyz^$document ||torins.xyz^$document ||runist.xyz^$document ||ruvist.xyz^$document ||dixirs.xyz^$document ||divirs.xyz^$document ||rutist.xyz^$document ||desirs.xyz^$document ||dibirs.xyz^$document ||gomirs.xyz^$document ||gocirs.xyz^$document ||gojirs.xyz^$document ||dinirs.xyz^$document ||dimirs.xyz^$document ||regins.xyz^$document ||rebins.xyz^$document ||ruwist.xyz^$document ||debirs.xyz^$document ||totins.xyz^$document ||topins.xyz^$document ||tosins.xyz^$document ||rorist.xyz^$document ||rufist.xyz^$document ||rulist.xyz^$document ||tomins.xyz^$document ||tokins.xyz^$document ||tolins.xyz^$document ||tobins.xyz^$document ||ronist.xyz^$document ||tohins.xyz^$document ||ralist.xyz^$document ||tocins.xyz^$document ||tezins.xyz^$document ||texins.xyz^$document ||medor.live^$document ||rubist.xyz^$document ||tetins.xyz^$document ||temins.xyz^$document ||mewor.live^$document ||nudges.live^$document ||mazey.live^$document ||tefins.xyz^$document ||tacins.xyz^$document ||tavins.xyz^$document ||tejins.xyz^$document ||magey.live^$document ||tabins.xyz^$document ||tekins.xyz^$document ||mafey.live^$document ||rawist.xyz^$document ||maxey.live^$document ||tamins.xyz^$document ||roxist.xyz^$document ||ragist.xyz^$document ||rofist.xyz^$document ||tebins.xyz^$document ||makey.live^$document ||tanins.xyz^$document ||masey.live^$document ||marey.live^$document ||mevir.live^$document ||rucist.xyz^$document ||ramist.xyz^$document ||mezor.live^$document ||tenins.xyz^$document ||girid.live^$document ||tadins.xyz^$document ||terins.xyz^$document ||tawins.xyz^$document ||nutges.live^$document ||rowist.xyz^$document ||taxins.xyz^$document ||tegins.xyz^$document ||rahist.xyz^$document ||talins.xyz^$document ||tepins.xyz^$document ||rozist.xyz^$document ||tafins.xyz^$document ||melir.live^$document ||metor.live^$document ||tazins.xyz^$document ||tecins.xyz^$document ||tehins.xyz^$document ||maley.live^$document ||mapey.live^$document ||rodist.xyz^$document ||tedins.xyz^$document ||mamey.live^$document ||tasins.xyz^$document ||rafist.xyz^$document ||mezir.live^$document ||mexir.live^$document ||macey.live^$document ||mabey.live^$document ||rokist.xyz^$document ||tatins.xyz^$document ||remins.xyz^$document ||ratist.xyz^$document ||takins.xyz^$document ||tajins.xyz^$document ||nusges.live^$document ||nurges.live^$document ||ranist.xyz^$document ||tahins.xyz^$document ||tagins.xyz^$document ||nulges.live^$document ||mawey.live^$document ||mavey.live^$document ||nufges.live^$document ||maney.live^$document ||rabist.xyz^$document ||madey.live^$document ||memor.live^$document ||mekir.live^$document ||melor.live^$document ||kedel.live^$document ||gipod.live^$document ||megir.live^$document ||megor.live^$document ||mevor.live^$document ||mebor.live^$document ||mehir.live^$document ||mejir.live^$document ||medir.live^$document ||mefir.live^$document ||mewir.live^$document ||merir.live^$document ||mecor.live^$document ||menir.live^$document ||mehor.live^$document ||dixans.live^$document ||dilans.live^$document ||depans.live^$document ||demans.live^$document ||dizans.live^$document ||dekans.live^$document ||dezons.live^$document ||dezans.live^$document ||depons.live^$document ||delans.live^$document ||dihans.live^$document ||difans.live^$document ||detans.live^$document ||dejons.live^$document ||dikans.live^$document ||desans.live^$document ||diwans.live^$document ||devons.live^$document ||dibans.live^$document ||dipans.live^$document ||dehans.live^$document ||dinans.live^$document ||delons.live^$document ||dedans.live^$document ||didans.live^$document ||debans.live^$document ||derons.live^$document ||denans.live^$document ||dejans.live^$document ||divans.live^$document ||detons.live^$document ||disans.live^$document ||dekons.live^$document ||dewans.live^$document ||denons.live^$document ||dehons.live^$document ||dicans.live^$document ||degons.live^$document ||derans.live^$document ||dijans.live^$document ||dirans.live^$document ||ditans.live^$document ||desons.live^$document ||digans.live^$document ||mecir.live^$document ||dexons.live^$document ||dexans.live^$document ||devans.live^$document ||dewons.live^$document ||degans.live^$document ||defons.live^$document ||defans.live^$document ||dedons.live^$document ||decons.live^$document ||debons.live^$document ||decans.live^$document ||dakent.live^$document ||daxent.live^$document ||dapent.live^$document ||copux.live^$document ||boxis.live^$document ||coxix.live^$document ||cining.live^$document ||civens.live^$document ||cizens.live^$document ||bolis.live^$document ||bojis.live^$document ||cepans.live^$document ||cetans.live^$document ||botin.live^$document ||cagax.live^$document ||cicing.live^$document ||celans.live^$document ||cojux.live^$document ||cimens.live^$document ||cawex.live^$document ||copix.live^$document ||cowux.live^$document ||civing.live^$document ||citins.live^$document ||cefans.live^$document ||cogix.live^$document ||bosis.live^$document ||cohux.live^$document ||conix.live^$document ||cebans.live^$document ||cihins.live^$document ||cihens.live^$document ||cofux.live^$document ||cotux.live^$document ||datent.live^$document ||cekans.live^$document ||cazex.live^$document ||cozix.live^$document ||bokin.live^$document ||bowin.live^$document ||cikens.live^$document ||citeng.live^$document ||cowix.live^$document ||cokux.live^$document ||cakax.live^$document ||corux.live^$document ||bovin.live^$document ||bohis.live^$document ||cadax.live^$document ||cojix.live^$document ||cosux.live^$document ||cicens.live^$document ||cosix.live^$document ||cifens.live^$document ||botis.live^$document ||cobix.live^$document ||cibing.live^$document ||dahent.live^$document ||cazax.live^$document ||corix.live^$document ||cejans.live^$document ||cotix.live^$document ||borin.live^$document ||boxin.live^$document ||cidins.live^$document ||cipins.live^$document ||bolin.live^$document ||codux.live^$document ||cigens.live^$document ||cedans.live^$document ||ciweng.live^$document ||cixing.live^$document ||caxex.live^$document ||dadent.live^$document ||cafex.live^$document ||codix.live^$document ||colix.live^$document ||cokix.live^$document ||cogux.live^$document ||cohix.live^$document ||ciling.live^$document ||cinens.live^$document ||caxax.live^$document ||cavex.live^$document ||cawax.live^$document ||cavax.live^$document ||catex.live^$document ||covix.live^$document ||dacent.live^$document ||cehans.live^$document ||cabex.live^$document ||cezans.live^$document ||cecans.live^$document ||cerans.live^$document ||bopin.live^$document ||cevans.live^$document ||bowis.live^$document ||bocis.live^$document ||dawent.live^$document ||cibens.live^$document ||bogin.live^$document ||bokis.live^$document ||bofis.live^$document ||cilens.live^$document ||cireng.live^$document ||cirins.live^$document ||ciking.live^$document ||dasent.live^$document ||cajex.live^$document ||cexans.live^$document ||bozis.live^$document ||cegans.live^$document ||cizing.live^$document ||cisins.live^$document ||dajent.live^$document ||geront.live^$document ||gewont.live^$document ||givont.live^$document ||gizont.live^$document ||wicter.live^$document ||wedger.live^$document ||tuskel.live^$document ||tuskes.live^$document ||gijont.live^$document ||garot.live^$document ||tuskep.live^$document ||tuskeg.live^$document ||gikont.live^$document ||gorint.live^$document ||gibont.live^$document ||gowint.live^$document ||gitont.live^$document ||gigont.live^$document ||gicont.live^$document ||cewans.live^$document ||gihont.live^$document ||gesont.live^$document ||cijins.live^$document ||jedger.live^$document ||gilont.live^$document ||gexont.live^$document ||gifont.live^$document ||gedont.live^$document ||tusked.live^$document ||gisont.live^$document ||gipont.live^$document ||bogis.live^$document ||camax.live^$document ||casex.live^$document ||tusket.live^$document ||ciseng.live^$document ||cijens.live^$document ||bovis.live^$document ||dafent.live^$document ||bohin.live^$document ||dazent.live^$document ||ciwins.live^$document ||bofin.live^$document ||bodis.live^$document ||ciming.live^$document ||cenans.live^$document ||dalent.live^$document ||canax.live^$document ||bobin.live^$document ||bozin.live^$document ||bocin.live^$document ||calax.live^$document ||davent.live^$document ||casax.live^$document ||cipeng.live^$document ||capax.live^$document ||bopis.live^$document ||carax.live^$document ||cifins.live^$document ||bosin.live^$document ||cesans.live^$document ||cixens.live^$document ||cemans.live^$document ||cigins.live^$document ||cidens.live^$document ||cahax.live^$document ||cajax.live^$document ||cahex.live^$document ||cagex.live^$document ||cafax.live^$document ||cacax.live^$document ||cacex.live^$document ||cabax.live^$document ||tuskef.live^$document ||tuskeh.live^$document ||hedger.live^$document ||regems.live^$document ||gotint.live^$document ||ginont.live^$document ||gimont.live^$document ||darent.live^$document ||dabent.live^$document ||danent.live^$document ||dament.live^$document ||dagent.live^$document ||giwont.live^$document ||giront.live^$document ||tadin.live^$document ||sralk.live^$document ||slalk.live^$document ||smalk.live^$document ||tabon.live^$document ||gawont.live^$document ||gehont.live^$document ||gatot.live^$document ||gebont.live^$document ||getont.live^$document ||skalk.live^$document ||gapot.live^$document ||gecont.live^$document ||gepont.live^$document ||gevont.live^$document ||taton.live^$document ||gejont.live^$document ||tahin.live^$document ||gasont.live^$document ||sjalk.live^$document ||tacin.live^$document ||tagin.live^$document ||tazin.live^$document ||gafot.live^$document ||gadot.live^$document ||gasot.live^$document ||gawot.live^$document ||genont.live^$document ||gixont.live^$document ||gidont.live^$document ||gemont.live^$document ||gelont.live^$document ||gekont.live^$document ||gezont.live^$document ||gegont.live^$document ||gefont.live^$document ||tazon.live^$document ||tacon.live^$document ||gagot.live^$document ||gamont.live^$document ||gagont.live^$document ||droppa.live^$document ||dobbla.live^$document ||takon.live^$document ||takin.live^$document ||taxon.live^$document ||tabin.live^$document ||tajin.live^$document ||tajon.live^$document ||tahon.live^$document ||taxin.live^$document ||tafon.live^$document ||tafin.live^$document ||tadon.live^$document ||dewit.live^$document ||tawon.live^$document ||tawin.live^$document ||tavon.live^$document ||tavin.live^$document ||sozing.live^$document ||soweng.live^$document ||somong.live^$document ||soxing.live^$document ||soteng.live^$document ||soring.live^$document ||soning.live^$document ||soling.live^$document ||someng.live^$document ||soxong.live^$document ||sowing.live^$document ||sozong.live^$document ||sopeng.live^$document ||sokeng.live^$document ||soming.live^$document ||sozeng.live^$document ||soxeng.live^$document ||tatin.live^$document ||sovong.live^$document ||tarin.live^$document ||soveng.live^$document ||sojong.live^$document ||sonong.live^$document ||sogong.live^$document ||soleng.live^$document ||soreng.live^$document ||sowong.live^$document ||taron.live^$document ||tamon.live^$document ||tasin.live^$document ||soving.live^$document ||soting.live^$document ||tapon.live^$document ||tason.live^$document ||soging.live^$document ||tanon.live^$document ||talin.live^$document ||tamin.live^$document ||soking.live^$document ||sojing.live^$document ||sojeng.live^$document ||sotong.live^$document ||sohong.live^$document ||sohing.live^$document ||soheng.live^$document ||sofing.live^$document ||sofeng.live^$document ||sopong.live^$document ||soping.live^$document ||sodong.live^$document ||soding.live^$document ||gikid.live^$document ||giwod.live^$document ||gijod.live^$document ||sidid.live^$document ||sidod.live^$document ||giled.live^$document ||gined.live^$document ||sicid.live^$document ||giked.live^$document ||ginod.live^$document ||gilid.live^$document ||sigod.live^$document ||giwid.live^$document ||sibod.live^$document ||gixid.live^$document ||giped.live^$document ||gijed.live^$document ||sifod.live^$document ||ginid.live^$document ||gikod.live^$document ||gilod.live^$document ||gixod.live^$document ||gijid.live^$document ||sibed.live^$document ||sogeng.live^$document ||sobeng.live^$document ||gized.live^$document ||gixed.live^$document ||sobong.live^$document ||soceng.live^$document ||sided.live^$document ||gizod.live^$document ||sodeng.live^$document ||soneng.live^$document ||socong.live^$document ||socing.live^$document ||sobing.live^$document ||gizid.live^$document ||giwed.live^$document ||sigid.live^$document ||givod.live^$document ||givid.live^$document ||gived.live^$document ||gitod.live^$document ||siged.live^$document ||gitid.live^$document ||gited.live^$document ||gisod.live^$document ||sipid.live^$document ||sipod.live^$document ||sifid.live^$document ||sinod.live^$document ||siped.live^$document ||sinid.live^$document ||sined.live^$document ||fehons.live^$document ||grimy.live^$document ||luxan.live^$document ||moken.live^$document ||stohal.live^$document ||pibers.live^$document ||simod.live^$document ||saris.live^$document ||sawes.live^$document ||sahus.live^$document ||sapis.live^$document ||sagis.live^$document ||sares.live^$document ||sames.live^$document ||sates.live^$document ||sanus.live^$document ||safis.live^$document ||sades.live^$document ||sanis.live^$document ||saxus.live^$document ||sahes.live^$document ||sases.live^$document ||safes.live^$document ||sacus.live^$document ||sadus.live^$document ||savus.live^$document ||samus.live^$document ||sazis.live^$document ||savis.live^$document ||sahis.live^$document ||sasis.live^$document ||saves.live^$document ||sacis.live^$document ||sapus.live^$document ||sasus.live^$document ||sajes.live^$document ||sajis.live^$document ||sanes.live^$document ||sadis.live^$document ||saxis.live^$document ||saxes.live^$document ||samis.live^$document ||sagus.live^$document ||sawus.live^$document ||safus.live^$document ||sabus.live^$document ||sapes.live^$document ||sazes.live^$document ||salis.live^$document ||simid.live^$document ||silid.live^$document ||saces.live^$document ||siced.live^$document ||sijod.live^$document ||sihed.live^$document ||sakus.live^$document ||sikid.live^$document ||sijed.live^$document ||sihid.live^$document ||siked.live^$document ||sicod.live^$document ||sijid.live^$document ||simed.live^$document ||sihod.live^$document ||silod.live^$document ||afeta.live^$document ||sikod.live^$document ||siled.live^$document ||sabis.live^$document ||sakis.live^$document ||sibid.live^$document ||nised.live^$document ||sabes.live^$document ||pekog.live^$document ||gaxeh.live^$document ||gateh.live^$document ||sawis.live^$document ||renak.live^$document ||perog.live^$document ||tolfe.live^$document ||tolki.live^$document ||tolve.live^$document ||tolmi.live^$document ||tolne.live^$document ||tolze.live^$document ||tolbe.live^$document ||tolhi.live^$document ||tolji.live^$document ||tolsi.live^$document ||tolpe.live^$document ||tolti.live^$document ||tolri.live^$document ||tolte.live^$document ||tolwi.live^$document ||tolvi.live^$document ||tolde.live^$document ||tolse.live^$document ||tolzi.live^$document ||tolpi.live^$document ||tolni.live^$document ||tolke.live^$document ||tolme.live^$document ||tolre.live^$document ||tolje.live^$document ||tolhe.live^$document ||tolwe.live^$document ||tolgi.live^$document ||sazus.live^$document ||tolge.live^$document ||tolce.live^$document ||tolfi.live^$document ||toldi.live^$document ||tolci.live^$document ||sajus.live^$document ||tolbi.live^$document ||rekak.live^$document ||relak.live^$document ||rehak.live^$document ||rewag.live^$document ||renag.live^$document ||rerad.live^$document ||rerak.live^$document ||retak.live^$document ||resak.live^$document ||remad.live^$document ||rewad.live^$document ||repag.live^$document ||resad.live^$document ||rebak.live^$document ||rekag.live^$document ||revag.live^$document ||relag.live^$document ||repad.live^$document ||redak.live^$document ||rerag.live^$document ||rehad.live^$document ||redad.live^$document ||regak.live^$document ||rekad.live^$document ||relad.live^$document ||rebad.live^$document ||repak.live^$document ||retag.live^$document ||resag.live^$document ||revak.live^$document ||rejak.live^$document ||rejag.live^$document ||renad.live^$document ||rejad.live^$document ||pekot.live^$document ||revad.live^$document ||gareh.live^$document ||petog.live^$document ||pemot.live^$document ||pevog.live^$document ||pehot.live^$document ||gawet.live^$document ||pelog.live^$document ||pedot.live^$document ||pepog.live^$document ||penog.live^$document ||galeh.live^$document ||gaset.live^$document ||pelot.live^$document ||gaket.live^$document ||petot.live^$document ||pepot.live^$document ||pezot.live^$document ||pedog.live^$document ||pexog.live^$document ||regag.live^$document ||rehag.live^$document ||regad.live^$document ||pegog.live^$document ||gazet.live^$document ||pegot.live^$document ||refak.live^$document ||refag.live^$document ||astel.live^$document ||refad.live^$document ||recak.live^$document ||recag.live^$document ||pefog.live^$document ||pefot.live^$document ||gazeh.live^$document ||recad.live^$document ||gaxet.live^$document ||polik.live^$document ||pohik.live^$document ||powik.live^$document ||pofim.live^$document ||pomim.live^$document ||pofik.live^$document ||pogim.live^$document ||poxik.live^$document ||porir.live^$document ||posik.live^$document ||pocik.live^$document ||pomik.live^$document ||pogir.live^$document ||powir.live^$document ||podik.live^$document ||popim.live^$document ||ponir.live^$document ||pobir.live^$document ||posir.live^$document ||poxir.live^$document ||povim.live^$document ||poxim.live^$document ||ponik.live^$document ||pobim.live^$document ||potim.live^$document ||pojik.live^$document ||powim.live^$document ||pozir.live^$document ||pohir.live^$document ||povik.live^$document ||podir.live^$document ||posim.live^$document ||popir.live^$document ||pozim.live^$document ||popik.live^$document ||ponim.live^$document ||potir.live^$document ||pozik.live^$document ||porim.live^$document ||porik.live^$document ||polim.live^$document ||pohim.live^$document ||gaweh.live^$document ||pomir.live^$document ||pogik.live^$document ||pofir.live^$document ||gavet.live^$document ||pecot.live^$document ||polir.live^$document ||gaveh.live^$document ||podim.live^$document ||pocir.live^$document ||pocim.live^$document ||pokir.live^$document ||pecog.live^$document ||pebot.live^$document ||pojim.live^$document ||pehog.live^$document ||gatet.live^$document ||pebog.live^$document ||gaseh.live^$document ||pokim.live^$document ||pokik.live^$document ||pobik.live^$document ||pojir.live^$document ||pezog.live^$document ||pexot.live^$document ||pewot.live^$document ||pewog.live^$document ||pevot.live^$document ||becog.live^$document ||pesot.live^$document ||pejog.live^$document ||gapet.live^$document ||penot.live^$document ||pesog.live^$document ||gapeh.live^$document ||pejot.live^$document ||ganet.live^$document ||pemog.live^$document ||ganeh.live^$document ||dahig.live^$document ||gameh.live^$document ||galet.live^$document ||gakeh.live^$document ||gajeh.live^$document ||gahet.live^$document ||gafeh.live^$document ||dazig.live^$document ||dabig.live^$document ||gaget.live^$document ||gageh.live^$document ||gadeh.live^$document ||mowist.live^$document ||gaceh.live^$document ||gadet.live^$document ||gaheh.live^$document ||gafet.live^$document ||gacet.live^$document ||dabin.live^$document ||gabeh.live^$document ||grotus.live^$document ||dadin.live^$document ||dasig.live^$document ||nejirs.live^$document ||dajig.live^$document ||nenirs.live^$document ||momist.live^$document ||mokist.live^$document ||nesirs.live^$document ||dasin.live^$document ||mopist.live^$document ||movist.live^$document ||molest.live^$document ||moxist.live^$document ||netis.live^$document ||danig.live^$document ||momest.live^$document ||dadig.live^$document ||motest.live^$document ||nesis.live^$document ||dapig.live^$document ||mowest.live^$document ||nedis.live^$document ||molist.live^$document ||davig.live^$document ||damig.live^$document ||dahin.live^$document ||nekis.live^$document ||motist.live^$document ||morist.live^$document ||danin.live^$document ||dalig.live^$document ||daxin.live^$document ||nelirs.live^$document ||nepirs.live^$document ||mopest.live^$document ||dagig.live^$document ||mokest.live^$document ||nebis.live^$document ||monest.live^$document ||dazin.live^$document ||dawin.live^$document ||dafin.live^$document ||monist.live^$document ||dakig.live^$document ||daxig.live^$document ||morest.live^$document ||movest.live^$document ||nemirs.live^$document ||netirs.live^$document ||nejis.live^$document ||mozest.live^$document ||dagin.live^$document ||dafig.live^$document ||dacin.live^$document ||datig.live^$document ||mosist.live^$document ||negirs.live^$document ||dapin.live^$document ||moxest.live^$document ||nehis.live^$document ||nemis.live^$document ||mosest.live^$document ||negis.live^$document ||nekirs.live^$document ||nerirs.live^$document ||nenis.live^$document ||darig.live^$document ||nehirs.live^$document ||necis.live^$document ||nedirs.live^$document ||nefirs.live^$document ||nefis.live^$document ||mozist.live^$document ||necirs.live^$document ||nebirs.live^$document ||kodit.live^$document ||kosit.live^$document ||kolet.live^$document ||kopet.live^$document ||kofet.live^$document ||kolit.live^$document ||koret.live^$document ||kocet.live^$document ||kodet.live^$document ||konet.live^$document ||kovet.live^$document ||kotit.live^$document ||kofit.live^$document ||kokit.live^$document ||komet.live^$document ||koket.live^$document ||kovit.live^$document ||kobit.live^$document ||koget.live^$document ||korit.live^$document ||kojet.live^$document ||kotet.live^$document ||kohit.live^$document ||kowet.live^$document ||koset.live^$document ||kopit.live^$document ||kogit.live^$document ||kohet.live^$document ||konit.live^$document ||kowit.live^$document ||kojit.live^$document ||kocit.live^$document ||bovid.live^$document ||bocid.live^$document ||bojid.live^$document ||bopid.live^$document ||bokid.live^$document ||bonid.live^$document ||bosid.live^$document ||bohid.live^$document ||boxid.live^$document ||bowid.live^$document ||bofid.live^$document ||bodid.live^$document ||borid.live^$document ||bozid.live^$document ||bogid.live^$document ||bobid.live^$document ||sojid.live^$document ||socid.live^$document ||rofid.live^$document ||sobid.live^$document ||sofid.live^$document ||sohed.live^$document ||sopid.live^$document ||sobed.live^$document ||soded.live^$document ||rozed.live^$document ||roved.live^$document ||soced.live^$document ||rotid.live^$document ||rolid.live^$document ||sonid.live^$document ||sofed.live^$document ||sogid.live^$document ||roxed.live^$document ||ronid.live^$document ||sojed.live^$document ||soled.live^$document ||rozid.live^$document ||sohid.live^$document ||rowid.live^$document ||sosid.live^$document ||ropid.live^$document ||rosed.live^$document ||rojed.live^$document ||sokid.live^$document ||soked.live^$document ||sosed.live^$document ||rowed.live^$document ||somed.live^$document ||soped.live^$document ||roxid.live^$document ||rovid.live^$document ||roled.live^$document ||roped.live^$document ||roted.live^$document ||roked.live^$document ||rosid.live^$document ||rorid.live^$document ||rodid.live^$document ||roged.live^$document ||sodid.live^$document ||rohid.live^$document ||rored.live^$document ||roded.live^$document ||rofed.live^$document ||robid.live^$document ||bolid.live^$document ||rohed.live^$document ||rogid.live^$document ||rocid.live^$document ||roced.live^$document ||soged.live^$document ||soned.live^$document ||roned.live^$document ||robed.live^$document ||tijens.live^$document ||tisens.live^$document ||tikers.live^$document ||tigens.live^$document ||tilens.live^$document ||tijers.live^$document ||tiwens.live^$document ||timens.live^$document ||ticens.live^$document ||tipens.live^$document ||tifens.live^$document ||tirers.live^$document ||tihens.live^$document ||tivers.live^$document ||tibers.live^$document ||tiwers.live^$document ||tizens.live^$document ||tiners.live^$document ||tifers.live^$document ||tipers.live^$document ||tidens.live^$document ||tivens.live^$document ||tixers.live^$document ||tizers.live^$document ||tinens.live^$document ||titers.live^$document ||tirens.live^$document ||tisers.live^$document ||tixens.live^$document ||titens.live^$document ||tilers.live^$document ||tikens.live^$document ||asmer.live^$document ||tihers.live^$document ||papons.live^$document ||padons.live^$document ||roxels.live^$document ||rohels.live^$document ||rogels.live^$document ||rozeks.live^$document ||pamons.live^$document ||kered.live^$document ||roreks.live^$document ||pawons.live^$document ||pagons.live^$document ||rodels.live^$document ||kewel.live^$document ||rofeks.live^$document ||kerel.live^$document ||rojels.live^$document ||keled.live^$document ||kemed.live^$document ||keped.live^$document ||kexel.live^$document ||paxons.live^$document ||kehel.live^$document ||kemel.live^$document ||panons.live^$document ||pacons.live^$document ||kefel.live^$document ||kezed.live^$document ||rodeks.live^$document ||ketel.live^$document ||kefed.live^$document ||rozels.live^$document ||ronels.live^$document ||kened.live^$document ||rocels.live^$document ||pajons.live^$document ||kesed.live^$document ||keved.live^$document ||roheks.live^$document ||kekel.live^$document ||pabons.live^$document ||keded.live^$document ||kesel.live^$document ||pavons.live^$document ||rorels.live^$document ||kexed.live^$document ||roxeks.live^$document ||kejed.live^$document ||roteks.live^$document ||robels.live^$document ||kenel.live^$document ||rowels.live^$document ||kebed.live^$document ||rotels.live^$document ||rogeks.live^$document ||keked.live^$document ||kecel.live^$document ||ropels.live^$document ||rovels.live^$document ||kelel.live^$document ||keted.live^$document ||rolels.live^$document ||roseks.live^$document ||roweks.live^$document ||rofels.live^$document ||roceks.live^$document ||keged.live^$document ||romels.live^$document ||kewed.live^$document ||kevel.live^$document ||kepel.live^$document ||roveks.live^$document ||ropeks.live^$document ||pahons.live^$document ||kejel.live^$document ||pafons.live^$document ||kehed.live^$document ||ticers.live^$document ||tibens.live^$document ||rosels.live^$document ||pihers.live^$document ||rokels.live^$document ||tiders.live^$document ||romeks.live^$document ||roneks.live^$document ||roleks.live^$document ||pipens.live^$document ||pazons.live^$document ||rojeks.live^$document ||rokeks.live^$document ||kezel.live^$document ||krafig.live^$document ||kratig.live^$document ||krahig.live^$document ||krarig.live^$document ||kravig.live^$document ||krajig.live^$document ||krasig.live^$document ||kralig.live^$document ||kranig.live^$document ||krakig.live^$document ||krapig.live^$document ||krawig.live^$document ||kraxig.live^$document ||krazig.live^$document ||kramig.live^$document ||kragig.live^$document ||kradig.live^$document ||kracig.live^$document ||parons.live^$document ||krabig.live^$document ||ganist.live^$document ||folit.live^$document ||kiset.online^$document ||krafit.live^$document ||krajis.live^$document ||krapis.live^$document ||krasit.live^$document ||kranir.live^$document ||krawit.live^$document ||kramir.live^$document ||krawis.live^$document ||krarir.live^$document ||kradir.live^$document ||kramis.live^$document ||kraxis.live^$document ||krafis.live^$document ||kralir.live^$document ||kracir.live^$document ||kratir.live^$document ||krahir.live^$document ||kragir.live^$document ||krakit.live^$document ||krakis.live^$document ||krapit.live^$document ||kradit.live^$document ||krasis.live^$document ||kratis.live^$document ||kraxit.live^$document ||krawir.live^$document ||krazit.live^$document ||krazis.live^$document ||kravir.live^$document ||kradis.live^$document ||krajir.live^$document ||kranis.live^$document ||krasir.live^$document ||krarit.live^$document ||kratit.live^$document ||krazir.live^$document ||krafir.live^$document ||kracit.live^$document ||kracis.live^$document ||krakir.live^$document ||kraris.live^$document ||krabir.live^$document ||kraxir.live^$document ||kragis.live^$document ||krabis.live^$document ||krapir.live^$document ||kralis.live^$document ||kragit.live^$document ||patert.live^$document ||pamest.live^$document ||pajest.live^$document ||pagest.live^$document ||pasert.live^$document ||pakert.live^$document ||pahest.live^$document ||pagert.live^$document ||paxert.live^$document ||pacert.live^$document ||pakest.live^$document ||pamert.live^$document ||pajert.live^$document ||panert.live^$document ||pazert.live^$document ||pafert.live^$document ||parest.live^$document ||pahert.live^$document ||pavest.live^$document ||palert.live^$document ||pawert.live^$document ||papest.live^$document ||parert.live^$document ||pawest.live^$document ||paxest.live^$document ||pabert.live^$document ||padest.live^$document ||padert.live^$document ||pasest.live^$document ||patest.live^$document ||pavert.live^$document ||papert.live^$document ||pafest.live^$document ||kralit.live^$document ||mepis.live^$document ||krahis.live^$document ||darok.live^$document ||pimers.live^$document ||pazest.live^$document ||panest.live^$document ||palest.live^$document ||kewex.live^$document ||kexlex.live^$document ||kerex.live^$document ||ketlex.live^$document ||kepex.live^$document ||kerlex.live^$document ||kewlex.live^$document ||kebex.live^$document ||keblex.live^$document ||keklex.live^$document ||kenlex.live^$document ||kehex.live^$document ||keglex.live^$document ||kenex.live^$document ||ketex.live^$document ||kemex.live^$document ||kelex.live^$document ||kezlex.live^$document ||kefex.live^$document ||kemlex.live^$document ||kejex.live^$document ||kedlex.live^$document ||kexex.live^$document ||kevex.live^$document ||kevlex.live^$document ||keslex.live^$document ||keclex.live^$document ||kezex.live^$document ||keplex.live^$document ||pacest.live^$document ||pabest.live^$document ||jakin.live^$document ||tawigs.live^$document ||hunir.live^$document ||hulir.live^$document ||humir.live^$document ||hutir.live^$document ||huvir.live^$document ||hucer.live^$document ||huger.live^$document ||huper.live^$document ||hugir.live^$document ||huder.live^$document ||husir.live^$document ||huzir.live^$document ||huxir.live^$document ||huxer.live^$document ||hukir.live^$document ||hurer.live^$document ||hufir.live^$document ||hubir.live^$document ||huwer.live^$document ||huser.live^$document ||hupir.live^$document ||huwir.live^$document ||hurir.live^$document ||huker.live^$document ||huver.live^$document ||huter.live^$document ||huzer.live^$document ||kecex.live^$document ||huler.live^$document ||hudir.live^$document ||hucir.live^$document ||pifers.live^$document ||keflex.live^$document ||pijers.live^$document ||kedex.live^$document ||hujer.live^$document ||harex.live^$document ||kehlex.live^$document ||huner.live^$document ||hufer.live^$document ||kekex.live^$document ||drinen.live^$document ||kejlex.live^$document ||kegex.live^$document ||pewins.live^$document ||hujir.live^$document ||huhir.live^$document ||kozirs.live^$document ||kopiks.live^$document ||kohirs.live^$document ||kotiks.live^$document ||koliks.live^$document ||kowiks.live^$document ||kobirs.live^$document ||koriks.live^$document ||koxiks.live^$document ||kofiks.live^$document ||kotirs.live^$document ||kociks.live^$document ||kovirs.live^$document ||kosiks.live^$document ||kohiks.live^$document ||kowirs.live^$document ||korirs.live^$document ||kofirs.live^$document ||komirs.live^$document ||kosirs.live^$document ||konirs.live^$document ||kolirs.live^$document ||koziks.live^$document ||koxirs.live^$document ||koviks.live^$document ||kojirs.live^$document ||kokiks.live^$document ||kopirs.live^$document ||koniks.live^$document ||kogiks.live^$document ||kocirs.live^$document ||huher.live^$document ||driwer.live^$document ||molirs.live^$document ||pihens.live^$document ||kojiks.live^$document ||driber.live^$document ||driken.live^$document ||drigen.live^$document ||drizen.live^$document ||drixer.live^$document ||driler.live^$document ||drixen.live^$document ||driper.live^$document ||drisen.live^$document ||drifer.live^$document ||driger.live^$document ||dripen.live^$document ||driher.live^$document ||dricer.live^$document ||drihen.live^$document ||drider.live^$document ||driben.live^$document ||drimen.live^$document ||driden.live^$document ||drifen.live^$document ||driker.live^$document ||drimer.live^$document ||driner.live^$document ||drijer.live^$document ||driwen.live^$document ||drilen.live^$document ||drijen.live^$document ||drizer.live^$document ||driter.live^$document ||driren.live^$document ||driten.live^$document ||kokirs.live^$document ||kogirs.live^$document ||kodirs.live^$document ||pigers.live^$document ||kodiks.live^$document ||driser.live^$document ||kobiks.live^$document ||dricen.live^$document ||gifems.live^$document ||kewosi.live^$document ||intes.live^$document ||sejaks.live^$document ||pigens.live^$document ||stolal.live^$document ||antis.live^$document ||tavips.live^$document ||foxin.live^$document ||cerom.live^$document ||pikers.live^$document ||hasix.live^$document ||hamex.live^$document ||pilens.live^$document ||stofal.live^$document ||hapix.live^$document ||gusuf.online^$document ||hewet.live^$document ||kalip.live^$document ||floci.live^$document ||futil.live^$document ||agur.live^$document ||dohin.live^$document ||dogin.live^$document ||donin.live^$document ||dorin.live^$document ||dojen.live^$document ||doten.live^$document ||dosen.live^$document ||dopen.live^$document ||domen.live^$document ||dokin.live^$document ||doken.live^$document ||dodin.live^$document ||donen.live^$document ||doben.live^$document ||doden.live^$document ||dowin.live^$document ||doxin.live^$document ||dowen.live^$document ||dohen.live^$document ||dopin.live^$document ||dozin.live^$document ||doxen.live^$document ||dofen.live^$document ||dojin.live^$document ||docen.live^$document ||doren.live^$document ||pifens.live^$document ||drirer.live^$document ||dobin.live^$document ||hapex.live^$document ||dovin.live^$document ||luzar.live^$document ||tazins.live^$document ||doven.live^$document ||hanix.live^$document ||pidens.live^$document ||dotin.live^$document ||hanex.live^$document ||pijens.live^$document ||pakins.live^$document ||pinens.live^$document ||palins.live^$document ||pamims.live^$document ||pakims.live^$document ||moler.live^$document ||palims.live^$document ||pamins.live^$document ||pahins.live^$document ||pahims.live^$document ||mofer.live^$document ||pajins.live^$document ||pajims.live^$document ||momer.live^$document ||hohirs.live^$document ||hokims.live^$document ||hokins.live^$document ||hojirs.live^$document ||hojims.live^$document ||hokirs.live^$document ||hojins.live^$document ||hohins.live^$document ||tawirs.live^$document ||taxirs.live^$document ||tawins.live^$document ||taxins.live^$document ||picers.live^$document ||ladert.live^$document ||latert.live^$document ||lakert.live^$document ||lapert.live^$document ||lagest.live^$document ||ladest.live^$document ||lawert.live^$document ||lafert.live^$document ||laxert.live^$document ||lasert.live^$document ||lalest.live^$document ||lazert.live^$document ||labest.live^$document ||lahest.live^$document ||lacest.live^$document ||lavert.live^$document ||lajert.live^$document ||lanest.live^$document ||lamert.live^$document ||labert.live^$document ||lawest.live^$document ||lakest.live^$document ||laxest.live^$document ||lavest.live^$document ||lagert.live^$document ||lacert.live^$document ||lapest.live^$document ||lazest.live^$document ||lanert.live^$document ||lajest.live^$document ||lalert.live^$document ||larert.live^$document ||hamix.live^$document ||tarins.live^$document ||halex.live^$document ||havix.live^$document ||tavirs.live^$document ||lasest.live^$document ||pibens.live^$document ||havex.live^$document ||hatix.live^$document ||molen.live^$document ||larest.live^$document ||tavins.live^$document ||rokens.live^$document ||foleg.live^$document ||fobed.live^$document ||foded.live^$document ||fojeg.live^$document ||fojed.live^$document ||fomeg.live^$document ||foced.live^$document ||fogeg.live^$document ||foled.live^$document ||fodeg.live^$document ||foped.live^$document ||foged.live^$document ||fohed.live^$document ||fomer.live^$document ||fored.live^$document ||fofed.live^$document ||fozek.live^$document ||foned.live^$document ||foneg.live^$document ||fosed.live^$document ||fobeg.live^$document ||fopeg.live^$document ||foheg.live^$document ||fokeg.live^$document ||foreg.live^$document ||foceg.live^$document ||foked.live^$document ||fomed.live^$document ||fofeg.live^$document ||hatex.live^$document ||tawips.live^$document ||tatins.live^$document ||lamest.live^$document ||doloy.live^$document ||25defect.mansurdo.ru^$document ||stomal.live^$document ||tasins.live^$document ||tasirs.live^$document ||lahert.live^$document ||fanir.live^$document ||foseg.live^$document ||harix.live^$document ||tatips.live^$document ||tazips.live^$document ||bbbb.ulitron.ru^$document ||97deposit.mexv.ru^$document ||3delivered.mexv.ru^$document ||8descendant.erinaceuso.ru^$document ||enforce.interdependent23.vipertos.ru^$document ||perceive81.molotiras.ru^$document ||judgement71.nightmit.ru^$document ||73descendant.erinaceuso.ru^$document ||debts71.semashi.ru^$document ||mewed.ulitron.ru^$document ||alley.sorting88.cavalierso.ru^$document ! https://github.com/durablenapkin/scamblocklist/issues/18 ||q3i5q2r6.stackpathcdn.com^$all ! https://github.com/uBlockOrigin/uAssets/pull/17530 ||rblx.land^$all ! https://forums.malwarebytes.com/topic/296891-malwarebytes-fake-website-scam-website/#comment-1563262 (account required) ||webstore.getsecuredsetup.com^$document ||www.webstore.getsecuredsetup.com^$document ! https://github.com/durablenapkin/scamblocklist/issues/24 ! https://github.com/durablenapkin/scamblocklist/issues/25 ! https://github.com/uBlockOrigin/uAssets/issues/17602 ||allprizesforme.com^$all ! https://github.com/durablenapkin/scamblocklist/issues/26 ! https://github.com/durablenapkin/scamblocklist/issues/28 ||muskai.net^$all ||tslawill.com^$all ||xrp-give.pro^$all ! https://github.com/durablenapkin/scamblocklist/issues/32 ||spacexmusk.io^$all ! https://github.com/durablenapkin/scamblocklist/issues/30 ! https://forums.malwarebytes.com/topic/296904-cant-identify-the-source/ ! https://github.com/durablenapkin/scamblocklist/issues/33 ! https://www.reddit.com/r/uBlockOrigin/comments/12r255v/gamingnewsanalystcom_badware/ ! https://github.com/uBlockOrigin/uAssets/pull/17655 ||gamingnewsanalyst.com^$all ||gamingdebates.com^$all ! https://www.reddit.com/r/uBlockOrigin/comments/12q5o60/repost_fake_dating_site_badware/ ||flirt4free.com^$document ||entrance.flirt4free.com^$popup ! https://www.reddit.com/r/uBlockOrigin/comments/12pues7/fake_123movies_site_leading_to_redirect/ ||123moviesgo.ga^$all ! https://github.com/durablenapkin/scamblocklist/issues/35 ||tslaget.live^$all ||musk-aigpt.com^$all ! https://0xacab.org/my-privacy-dns/matrix/-/issues/121793 ||cjtrade4.xyz^$all .xyz/gift_iphone_X/?$document ! https://0xacab.org/my-privacy-dns/matrix/-/issues/121792 ||rplnd60.com^$all ||news-pewuce.com^$all ||djpjwf.com^$all ! from notifications (sandbox: ) ||totalprotection-2023.store^$all ||closingday2.xyz^$all ||s.viifogyp.com^$all ||viifogyp.com^$document ! https://0xacab.org/my-privacy-dns/matrix/-/issues/121816 ||tradersuper4.xyz^$all ! nitro scam ||tronite.xyz^$all ||locked4.com^$document ||www.locked4.com^$document ! https://www.reddit.com/r/uBlockOrigin/comments/12wqrv5/steamunlockednet_badware/ <-- have not verified sites to be malware! These are just domains ads in my analysis ! https://app.any.run/tasks/9ed7df61-f0a9-49cc-91bc-a3fcc2c59ae1/ ||antivirusgaming.com^$all ||xrlbq.aluationiamcur.com^$all ||aluationiamcur.com^$document ||awesome-blocker.com^$document ! https://app.any.run/tasks/c9657f58-f49e-4e9e-80bf-9704f0eaa32a (NSFW) ||gbcok.aluationiamcur.com^$all ||www6.renhadmasandbab.info^$popup ||mobilesecuremail.com^$document ! looks like a metamask phishing website? ! https://github.com/durablenapkin/scamblocklist/issues/38 ||miningpror.top^$all ||paypartc.top^$all ||bitcllpay.top^$all ||tdsintegrations11.online^$all ||crypto030.online^$all ! NSFW: https://app.any.run/tasks/a1a425ca-7b5d-4774-95bf-c11f8f25685a ||webpick-cdn.s3.us-west-2.amazonaws.com/getlaid.jpeg^$all ||wzzzs.uuksehinkitwkuo.com^$all ||uuksehinkitwkuo.com^$document ! https://app.any.run/tasks/d576fecb-3250-4a18-82de-eba82ac7ba6d ||click2code.xyz^$all ! https://github.com/durablenapkin/scamblocklist/issues/40 ||dischargebackhanded.com^$document ||zech-company.com^$document ||govmedcareers.com^$document ||talentmaster.bio^$document ||radiatorcrate.com^$document ||theniemannbest.com^$document ||jellyfishstat.live^$document ! https://github.com/durablenapkin/scamblocklist/issues/42 ||intgblockchain.online^$document ! https://github.com/uBlockOrigin/uAssets/issues/17947 ||pccdirect.site^$all ! youtube typosquatt I found ||you8tube.com^$all ||getluckyprize2023.com^$all /17138/iphone14.html?$document ! https://app.any.run/tasks/494077d1-478b-47e0-871c-b22788a455b6 ||pingleflavor.xyz^$all ||funprizeali.site^$all ! other notification spam ||datenow.losbestbsdating2023.com^$all ||losbestbsdating2023.com^$document ! discord nitro scam ||techsoftglobals.com^$all ! https://github.com/durablenapkin/scamblocklist/issues/43 ||555sq.com.cn^$document ||prorify.de^$document ||milgenial.uy^$document ||swuso.com^$document ||cebubestbuy.com^$document ||buyyeezy2023.com^$document ||casavec.com^$document ||kingcampoutdoors.co.jp^$document ||imlb2c.com^$document ||wareeb.pk^$document ||loepwatch.com^$document ||fiewatch.com^$document ||felara.com.do^$document ||posehee.com^$document ||beautyt.shop^$document ||lomoor.com^$document ||morlyes.com^$document ||ajcenteruss.com^$document ||bitiiy.com^$document ||storagestory.com^$document ||ihuers.com^$document ||bloomessentialsbrand.com^$document ||quitasueno.com^$document ||lifestyletrading.co.za^$document ||yyderfreap.shop^$document ||audiosg.com.sg^$document ||fujibikes.com^$document ||walmartchina.top^$document ||geldencosmeticos.com^$document ||sellfox.com^$document ||parklaneupholstemk.com^$document ||iteeus.com^$document ||monark-store.com^$document ||shapeden.com^$document ||andamente.pt^$document ||staging.zendrop.com^$document ||courier-tracking.com^$document ||yofi-yofi.com^$document ||stellara.de^$document ||innomediacreate.com^$document ||sehaleservices.com^$document ||magnite.shop^$document ||decompraschile.com^$document ||salimusic.com^$document ||open-cbd.de^$document ||onrunningshop.com^$document ||bygigi.mx^$document ||vkeys.online^$document ||teevpower.com^$document ||caraci.it^$document ||easyshopper.org^$document ||oncloudrun.shop^$document ||shopperexpress.shop^$document ||aoocib.com^$document ||7s4c.top^$document ||chandeco.com^$document ||networksfishing.com^$document ||millabay.com^$document ||mila-vica.de^$document ||ballsbags.com^$document ||vinisay.com^$document ||tinkleo.com^$document ||draxu.com^$document ||headsets4business.co.uk^$document ||kielorelief.io^$document ||olaoffer.shop^$document ||nosdaarte.com^$document ||pairmate.se^$document ||babybeddingdesign.com^$document ||coco-vip-shop.com^$document ||xunlei.it^$document ||botsuanah.com^$document ||lojaacasa.com.br^$document ||dashracegear.net^$document ||youthfy.shop^$document ||smartokids.com^$document ||pipopi.com^$document ||k-tozluxury.shop^$document ||zuozuoshoe.shop^$document ||vip-yuki-shop.com^$document ||c-tozluxury.shop^$document ||lasercutjewelry.net^$document ||sleepyfull.com^$document ||expofstore.com^$document ||watchmark.shop^$document ||carsaratek.com^$document ||xajzfwgs.com^$document ||uange.shop^$document ||imagemotorcycles.co.nz^$document ||twinsbio.com^$document ||snapchaty.com^$document ||tomfordgo.com^$document ||worthas.shop^$document ||microgull.com^$document ! https://github.com/hagezi/dns-blocklists/issues/1025 ||msmcompare.com^$all ! https://github.com/durablenapkin/scamblocklist/issues/45 ||teslatucker.com^$all ! https://www.reddit.com/r/uBlockOrigin/comments/13e53jy/badware_movie_sites/ ||filmshngjbzix.blogspot.com^$document ||mopiez.com^$all ! NSFW: https://tria.ge/230511-1g9xlada3x/behavioral1 ||lynku.mingotime.com^$document ||secret-list.yasdoodl.com^$all ||smcdsecure.com^$all ! https://github.com/durablenapkin/scamblocklist/issues/46 ||teslalive23.pro^$all ||muskbtc.io^$all ! ----- PUPs ----- ! https://www.virustotal.com/gui/url/c7e3137c4baaad64dcbbafd1938f581f264944fa1e2c1aa1ebcff77ed2959082/links ! https://safeweb.norton.com/report/show?url=https://www.totalav.com/ultra-deal?exit ! https://www.virustotal.com/gui/url/a15311f27a16908dfa87b8ce6cf0302d8c8260f32ce7171845fc73bd4d9769d2/detection ! https://www.virustotal.com/gui/url/dbc664226fd57c865f66bbaeae0d7270904c4ad735d0eb0ead4511e817392943/detection ! https://www.virustotal.com/gui/domain/www.totalav.com/detection ! https://quttera.com/detailed_report/totalav.com ! https://www.virustotal.com/gui/domain/totalav.com/community ! https://github.com/VernonStow/Filterlist/issues/3 ! https://discussions.apple.com/thread/8226797 ! https://malwaretips.com/threads/total-av-is-it-a-scam.80362/ ! https://github.com/uBlockOrigin/uAssets/issues/9355 ! https://github.com/notracking/hosts-blocklists/issues/756#issuecomment-1172973042 ! many shady ads ||totalav.com^$all ||www.totalav.com^$all ! https://www.virustotal.com/gui/file/7a75c2c9695157772541cd426d057ff382d011a2791bcc3e511d94592ab0dbb7/relations ||api.totalav.com^$all ! Subdomains ||secure.totalav.com^$all ||url.totalav.com^$all ||support.totalav.com^$all ||blog.totalav.com^$all ||track.totalav.com^$all ||ajax.totalav.com^$all ||affiliate.totalav.com^$all ||livechat.totalav.com^$all ||advertisers.totalav.com^$all ||affiliates.totalav.com^$all ||my.totalav.com^$all ||assets.totalav.com^$all ||identity.totalav.com^$all ||login.totalav.com^$all ||download.totalav.com^$all ||static.totalav.com^$all ||adblock.totalav.com^$all ||sso.totalav.com^$all ||webshield.totalav.com^$all ||resources.totalav.com^$all ||signup.totalav.com^$all ||link.totalav.com^$all ||chat.totalav.com^$all ||click.totalav.com^$all ||stats.totalav.com^$all ||search.totalav.com^$all ||aff.totalav.com^$all ||news.totalav.com^$all ||blockpage.totalav.com^$all ||ext.totalav.com^$all ||smtpmail.totalav.com^$all ||articles.totalav.com^$all ||data.totalav.com^$all ||pda.totalav.com^$all ||firmy.totalav.com^$all ||portal.totalav.com^$all ||educa.totalav.com^$all ||cp.totalav.com^$all ||images.totalav.com^$all ||p.totalav.com^$all ||gallery.totalav.com^$all ||webshop.totalav.com^$all ||new.totalav.com^$all ||sklep.totalav.com^$all ||manitoba.totalav.com^$all ||wiki.totalav.com^$all ||pei.totalav.com^$all ||dl.totalav.com^$all ||bbs.totalav.com^$all ||schools.totalav.com^$all ||ts.totalav.com^$all ||hosting.totalav.com^$all ||test.totalav.com^$all ||live.totalav.com^$all ||eng.totalav.com^$all ||forums.totalav.com^$all ||lnx.totalav.com^$all ||lib.totalav.com^$all ||galeria.totalav.com^$all ||cloud.totalav.com^$all ||appauth.totalav.com^$all ||ww.totalav.com^$all ||email.totalav.com^$all ||u002fwww.totalav.com^$all ||shield.totalav.com^$all ||comassets.totalav.com^$all ||ru.totalav.com^$all ||l.totalav.com^$all ||lyncext.totalav.com^$all ||liaoning.totalav.com^$all ||www2.totalav.com^$all ||www1.totalav.com^$all ||imap2.totalav.com^$all ||internet.totalav.com^$all ||smtps.totalav.com^$all ||a.totalav.com^$all ||gin.totalav.com^$all ||supprt.totalav.com^$all ||mailout.totalav.com^$all ||imap1.totalav.com^$all ||mta1.totalav.com^$all ||eml.totalav.com^$all ||help.totalav.com^$all ! other related ||totalwebshield.com^$all ||download.totalwebshield.com^$all ! seems to be a mirror? ! https://www.virustotal.com/gui/file/c190a676d707f290a0f6fccb60ecbc4b3b5dea5ea27d552095acd4110aff51bc/relations -> https://www.virustotal.com/gui/file/33f1e7e43ededca200bda52cc9df5b2af315505fde83cab5c25d3604bfe73294/detection -> https://duckduckgo.com/?q=ScanGuard&ia=web ! This is owned by Protected[.]net, who also is responsible for the TotalAV scam. Can not get an exe as it requires me to pay first... ||scanguard.com^$all ||www.scanguard.com^$all ||my.scanguard.com^$all ||secure.scanguard.com^$all ||download.scanguard.com^$all ! An alias for TotalAV ! https://safeweb.norton.com/report/show?url=pcprotect.com ! https://www.virustotal.com/gui/url/523e692076d4eff5dba80a52bca9c01aa77b4e1dac6598aa78574cab1297497a/community ! https://www.mywot.com/scorecard/pcprotect.com ||pcprotect.com^$all ||secure.pcprotect.com^$all ! The company behind the TotalAV scam & pcprotect[.]com ! https://www.facebook.com/protectednet - they basically admitted to it. See https://www.facebook.com/protectednet/photos/a.685704165203904/1199676053806710/?type=3&theater ! Lesson to scammers: Don't post golf balls with the name of the scam product to facebook... ||protected.net^$document ||definition.protected.net^$all ||install.protected.net^$all ||ssprotectltd.com^$document ||www.ssprotectltd.com^$document ! scammers - now hiring ||protected-net.breezy.hr^$document ! A scam adblocker (use uBlock Origin, AdGuard, or even AdBlock Plus. They are all better then TotalAdBlock) ! VirusTotal scan of Android version: https://www.virustotal.com/gui/file/24ce64dfa6937c5ede674b2ba33d6818bfa9f8bb4d36ff8da9aff39e05b8e41c/detection ! https://apps.apple.com/app/totaladblock/id1564900435 (only two reviews?) ||totaladblock.com^$all ||www.totaladblock.com^$all ||download.totaladblock.com^$all ||blockpage.totaladblock.com^$all ||stats.totaladblock.com^$all ||affiliates.totaladblock.com^$all ||affiliate.totaladblock.com^$all ||url.totaladblock.com^$all ||api.totaladblock.com^$all ||signup.totaladblock.com^$all ||track.totaladblock.com^$all ||my.totaladblock.com^$all ||support.totaladblock.com^$all ||login.totaladblock.com^$all ! https://app.any.run/tasks/eb07059f-c987-4366-9fed-8abfff016173 ||totaladblock.protected.net^$all ||extension.protected.net^$all ||totaladblocker.xyz^$document ||www.totaladblocker.xyz^$document ! https://www.virustotal.com/gui/ip-address/34.117.171.15/relations ||34.117.171.15^$document ||totalwebshield.xyz^$document ||www.totalwebshield.xyz^$document ||secure.totalwebshield.xyz^$document ||login.totalwebshield.xyz^$document ||download.totalwebshield.xyz^$document ! as per https://github.com/iam-py-test/my_filters_001/issues/105, I have unblocked the main website but still block the registry cleaner, driver updater, etc ||winzipregistryoptimizer.com^$document ||download.winzipregistryoptimizer.com^$document ! WinZip ads ! https://www.virustotal.com/gui/url/cad59b610a95e69019638d171c2df89adb7eac183968e102e37396b806fa57bd/community ||winzipdriverupdater.com^$document ||slowness.winzipdriverupdater.com^$document ! https://www.virustotal.com/gui/url/e5e8624a07064fc3a296dcab3b0b578ac0ed6d841094489e8bec989653deb93c/detection ! https://www.virustotal.com/gui/ip-address/3.222.136.53/relations ||winzipultimatepccare.com^$document ||www.winzipultimatepccare.com^$document ||winzipdisktools.com^$document ||winzipsystemtools.com^$document ! It is a very bad sign when Windows Defender blocks a file, and it is not a false positive ! https://www.virustotal.com/gui/url/b27f7a631ee2bcf759ab82fa976980c2704c787ecd21abc8b591b7fc93d96ee1/detection ! https://github.com/iam-py-test/Assets-001/tree/main/PUPs/SpeedCat ! Installer ! https://www.virustotal.com/gui/file/3f4c860c2689984f7edab62d5a5459840dc9515ec2c7a94b6fea6878481a3992/detection ! https://www.hybrid-analysis.com/sample/3f4c860c2689984f7edab62d5a5459840dc9515ec2c7a94b6fea6878481a3992 ! https://www.hybrid-analysis.com/sample/3f4c860c2689984f7edab62d5a5459840dc9515ec2c7a94b6fea6878481a3992/60f6d24211dc4473a31cd34a ! Other files and the app ! https://www.virustotal.com/gui/file/792bb2a2bd9f148d0b7dca1a98b4a310a30490c6523fc53a1f1e535e53d62389/detection ! https://www.virustotal.com/gui/file/57c40a9d2e592d968daa0f092abfa7abe2b41c47eb718adb770bd6930ec0dba4/detection ! https://www.virustotal.com/gui/file/f395839a00762a5e0428cb2cf596d80c56ba2be78cc3e6a3c89afb5c1f904db9/detection ! https://www.virustotal.com/gui/file/ff652f10ac6dbf8d4965f6624339c67e02715cf499ad8b26c1a683bd503e4136/detection ! https://quttera.com/detailed_report/pcspeedcat.com ||pcspeedcat.com^$all ! https://www.virustotal.com/gui/domain/pcspeedcat.com/relations ||cdn.pcspeedcat.com^$all ||vold.pcspeedcat.com^$all ||www.pcspeedcat.com^$all ||dev.pcspeedcat.com^$all ||access.pcspeedcat.com^$all ||vold-cdn.pcspeedcat.com^$all ||envoy.pcspeedcat.com^$all ||www-click-cf.pcspeedcat.com^$all ! Found in the shady Bing ads when searching for ADWCleaner ! Before downloading, ADWCleaner detected no adware. After downloading, ADWCleaner detected adware, which included the program. Program claims that buying the paid version (and entering private data) will fix issues with a clean VM. ! This also adds unneeded start up tasks (why would it need start up tasks?). In total, Malwarebytes detected 99 threats. ! https://www.virustotal.com/gui/url/681984dd59e84ade5ad3c7b93842dd3b8b759992e7a5f5a1a2aa8dd04f4c823e/community ||mycleanpc.com^$document ! I saw the www in the results ||www.mycleanpc.com^$document ! Found using VirusTotal ||reviews.mycleanpc.com^$document ||m.mycleanpc.com^$document ||shop.mycleanpc.com^$document ||web.mycleanpc.com^$document ||blog.mycleanpc.com^$document ||app.mycleanpc.com^$document ||get.mycleanpc.com^$document ||dev-www.mycleanpc.com^$document ! related domains owned by the company used for paying - obtained when talking to the scammer ||ustechsupport.com^$document ||www.ustechsupport.com^$popup ||mycleanid.com^$document ||www.mycleanid.com^$popup ||iolostore.com^$document ||www.iolostore.com^$popup ! the main website for the company ||realdefen.se^$document ! other 'products' which all appear to be PUPs ||getmydrivers.com^$document ||www.getmydrivers.com^$document ||app.getmydrivers.com^$document ||dev-www.getmydrivers.com^$document ||qa-www.getmydrivers.com^$document ||stopzilla.com^$document ||cyberdefender.com^$document ||www.cyberdefender.com^$popup ||virusfix.com^$document ||www.virusfix.com^$popup ! Owned by them (they admit it) ! 4/12/2022: https://app.any.run/tasks/82c340da-6ab4-4398-86bd-2bd368c018ce ||iolo.com^$document ||www.iolo.com^$document ||secure1.iolo.com^$document ! https://github.com/DandelionSprout/adfilt/compare/c3d04d61c9...4a2d9d2efa ! link on https://www.windowsdispatch.com/fix-system-restore-0x81000203-error-code/ ! https://www.virustotal.com/gui/url/41ada9c74d64537274173ea01f61fae7c7bdce2d660b64abb11546563fc6bf10/community ! The installer ! https://www.virustotal.com/gui/file/5d99408fc2f7bc85f2c4bc6dcd762008bfecd5c8dcaaacf9c9bdc2914ddd22b1/detection ! Files related to the PUP program ! https://www.virustotal.com/gui/file/fcf484d1009b4136c8655d32484babb0a284cbcb112ced7647194aea9e7688df/detection ! https://www.virustotal.com/gui/file/67252e30a59ddc58c273555bfd306343ec61e3f198a1c2d3eb30d8a93ec4fffa/detection ! https://www.virustotal.com/gui/file/5ef7eedfa7f283f180c1de80803e8d5c81fee09750ca044f018a098a94ad85c1/detection ! Malwarebytes detection - https://blog.malwarebytes.com/detections/pup-optional-restoro/ ! Screenshots from anaysis - https://github.com/iam-py-test/Assets-001/tree/main/PUPs/Restoro (VM Env: Windows 10, Windows Defender on) ||restoro.com^$all ||www.restoro.com^$all ! https://www.virustotal.com/gui/file/f019dab3172f6ce7808d45a5b5dea92354352e302219c02a84a280978f6eb166/community ||go.windowsreport.com/Restoro$document ! https://www.bleepingcomputer.com/virus-removal/page/2/ ! https://www.virustotal.com/gui/url/1a381bcdd30c4fafbe50baa12a0446c18b875e2221330ffe2adec106f14904f4/community ! https://www.virustotal.com/gui/file/50abca232390db8eb28a17b9fa5386631857c7c14d1b43d0adcdaf90178a4f7c/community ! https://www.mywot.com/scorecard/iobit.com ! https://forums.malwarebytes.com/topic/29681-iobit-steals-malwarebytes-intellectual-property/page/5/#elControls_152972_menu ! https://www.virustotal.com/gui/url/1a381bcdd30c4fafbe50baa12a0446c18b875e2221330ffe2adec106f14904f4/community ||iobit.com^$document ! Subdomains ||cdn.iobit.com^$document ||stats.iobit.com^$document ||estore.iobit.com^$document ||update.iobit.com^$document ||jp.iobit.com^$document ||store.iobit.com^$document ||download.iobit.com^$document ||www.iobit.com^$document ||clouddownload.iobit.com^$document ||ru.iobit.com^$document ||search.iobit.com^$document ||purchase.iobit.com^$document ||cloud.iobit.com^$document ||interface.iobit.com^$document ||shop.iobit.com^$document ||mobile.iobit.com^$document ||m.iobit.com^$document ||startup.iobit.com^$document ||survey.iobit.com^$document ||checkout.iobit.com^$document ||blog.iobit.com^$document ||sdupdate.iobit.com^$document ||mail.iobit.com^$document ||giveaway.iobit.com^$document ||uninstall.iobit.com^$document ||de.iobit.com^$document ||codes.iobit.com^$document ||forums.iobit.com^$document ||recorder.iobit.com^$document ! download redirects to iobit ||windowserrorfixer.com^$document ||www.windowserrorfixer.com^$document ! itop vpn seems to be made by iobit and comes with bundled installs ||itopvpn.com^$document ||update.itopvpn.com^$document ||api.itopvpn.com^$document ||stats.itopvpn.com^$document ! https://www.virustotal.com/gui/file/4efd1bc1bdc12da1bbdc597cf3f37f0c65e582f42e353cf781ac1fe422dfa68c/detection ! https://www.virustotal.com/gui/file/69d9d162a040888164707b7e44f4709059ad45296a832c077c0dc91afed89c05/detection ! https://www.virustotal.com/gui/file/fd9dbb971a9995f6d146237933fbe27f18217d3cacbb6da121de4cc9590030be/relations ! https://github.com/iam-py-test/Assets-001/tree/main/PUPs/Restoro ! https://www.virustotal.com/gui/url/16766e8681f0bf474ec3238d4b6d7f33047f5f368abef0aac13001d2be0a757d/detection ! https://blog.malwarebytes.com/detections/pup-optional-reimage/ ||2-spyware.com/reimage/download$all ||2-spyware.com/download/ReimageRepair$all ! https://www.virustotal.com/gui/url/16766e8681f0bf474ec3238d4b6d7f33047f5f368abef0aac13001d2be0a757d/detection ||reimageplus.com^$all ||cdnrep.reimageplus.com^$all ! More reimage - new name, new SHA256, new domain? ! https://www.virustotal.com/gui/url/3493793318d49332b789aba96de7937c468c5f6a20d6fdbf8da87832183c5d07/detection ! https://github.com/iam-py-test/Assets-001/tree/main/PUPs/Restoro_2 ! https://www.virustotal.com/gui/file/fd9dbb971a9995f6d146237933fbe27f18217d3cacbb6da121de4cc9590030be/relations ||reimage.org^$all ||www.reimage.org^$all ! Nobody names their legit domain after malware and then is detected on VirusTotal ! https://www.virustotal.com/gui/url/deef544081c813ee971cfa78d8145e5a050ea5eccc3d5718b033d00b64c5f9f4/detection ||reimage.com^$all ! https://www.virustotal.com/gui/file/af7b36c0f9f48f35315877e3cd5efb83c1a122a043ea9228db7da9c1c3c3120b/community ! https://github.com/iam-py-test/Assets-001/blob/main/PUPs/MediaGet/mediaget_detections.jpeg ||mediaget.com^$all ! found by @DandelionSprout in https://github.com/DandelionSprout/adfilt/issues/253 ||media-get.com^$all ||media-get.ru^$all ||mediagetplus.com^$all ||mgmgmg.com^$all ||23.111.31.137^$document ||23.111.88.207^$document ! https://www.virustotal.com/gui/file/05f052c64d192cf69a462a5ec16dda0d43ca5d0245900c9fcb9201685a2e7748/detection ! https://www.virustotal.com/gui/url/f938821627f117b561598186343cf47ce5f75b89b8d149a3efe885f9eba51942/community ! https://www.virustotal.com/gui/file/a367e0562e612bc66729f3a4676bad849e5c3c32fad8223b5ea991e11604f5fe/details ! ADWCleaner detects malware after execution. File opens webpage with generic 'your system has issues' message ||driveragent.com^$all ! https://www.joesandbox.com/analysis/237782/0/html#domains ||secure.driveragent.com^$all ||driveragent-web-126513135.us-east-1.elb.amazonaws.com^$third-party ! https://www.virustotal.com/gui/file/61ddc79c421d13052f0acdb838d1a68d98c5e4eda0058f018f72a65474135d08/detection ! https://github.com/DandelionSprout/adfilt/issues/254 ! https://blog.malwarebytes.com/detections/onesafe-software-com/ ||onesafesoftware.com^$all ||vpn.onesafesoftware.com^$all ||blog.onesafesoftware.com^$all ||drivers.onesafesoftware.com^$all ||updates.onesafesoftware.com^$all ||support.onesafesoftware.com^$all ||cdn.onesafesoftware.com^$all ||subscriptions.onesafesoftware.com^$all ||notifications.onesafesoftware.com^$all ||stats.onesafesoftware.com^$all ||www.onesafesoftware.com^$all ! https://www.virustotal.com/gui/file/a6e89d2bb1c2da1d852fb8e248f39cf7b3d4b0ea05a8d8f343d1b8e74d271d43/relations ||driversupport.com^$document ||front.driversupport.com^$document ||secure.driversupport.com^$document ||aloha.driversupport.com^$document ! "SolveIQ"? ||apps.solveiq.com^$document ||preview.solveiq.com^$document ||auth.solveiq.com^$document ! Taken from DandelionSprout's Anti-malware list - which is at https://github.com/DandelionSprout/adfilt/blob/master/Dandelion%20Sprout's%20Anti-Malware%20List.txt and which is maintained by https://github.com/DandelionSprout - and verified ||driver-soft.com^$document ! https://github.com/blocklistproject/Lists/issues/497 ||pcspeedup.en.softonic.com^$document ||tweakbit.com^$all ||static.tweakbit.com^$all ||www.tweakbit.com^$all ||debuglogs.tweakbit.com^$all ||update.tweakbit.com^$all ||dynamicdownloads.tweakbit.com^$all ||downloads.tweakbit.com^$all ||store.tweakbit.com^$all ||cdn.tweakbit.com^$all ||aff.tweakbit.com^$all ||mail.tweakbit.com^$all ! Original inspection ! disable uBlock Origin and go to https://www.google.com/search?q=clean+up+computer+to+run+faster&source=hp&ei=Y4KzYIrUL-rP0PEPqM2liAc&iflsig=AINFCbYAAAAAYLOQcwKl4vglkAEcsALPhO6XEyguHxPP&oq=clean+up+comp&gs_lcp=Cgdnd3Mtd2l6EAEYATICCAAyAggAMgIIADICCAAyBQgAEMkDMgIIADICCAAyAggAMgIIADICCAA6DgguELEDEMcBEKMCEJMCOgsILhCxAxDHARCjAjoFCAAQsQM6CAgAELEDEIMBOggILhDHARCjAjoOCC4QsQMQgwEQxwEQrwE6CAgAEOoCEI8BOggILhCxAxCDAToICC4QxwEQrwE6BQguELEDOggILhCxAxCTAjoICAAQsQMQyQM6BQgAEJIDOgsILhDHARCjAhCTAjoCCC46BQguEJMCUOUoWKCDAWDakwFoAnAAeACAAYoDiAGaFJIBCDAuMTQuMC4xmAEAoAEBqgEHZ3dzLXdperABCg&sclient=gws-wiz ! https://www.virustotal.com/gui/url/2f44cf878800c082d5fefb8326cf384fe12393ecfcca05e64903c5888f4c762c/detection ! https://www.virustotal.com/gui/url/c6290089eb08d05375650bfb7778713e1e9443ac1d8d180df44bd8ddd49124f9/detection ! https://www.virustotal.com/gui/domain/www.pchelpsoft.com/relations ! https://www.mywot.com/scorecard/pchelpsoft.com ! https://safeweb.norton.com/report/show_mobile?name=https://www.pchelpsoft.com/pc-cleaner/lp1-ms-us/?tracking=PH_EN_PP_GO_SE_PCC_US&keyword=speed%20up%20my%20pc&campaignID=ADWORDS&gclid=EAIaIQobChMIsOqVwrTx8AIV9xmtBh17swHGEAAYASAAEgLr1fD_BwE ! https://www.virustotal.com/gui/url/3cfe4ec34704092b5ad0c03b1f9566b538c11e3e0434a73991cdc2694db26582/detection ! https://www.urlvoid.com/scan/pchelpsoft.com/ ! https://sitecheck.sucuri.net/results/pchelpsoft.com ! https://www.fortiguard.com/webfilter?q=pchelpsoft.com ! Inspection on 23/7/2021 ! https://www.virustotal.com/gui/url/3cfe4ec34704092b5ad0c03b1f9566b538c11e3e0434a73991cdc2694db26582/detection ! https://safeweb.norton.com/reviews?url=pchelpsoft.com ! https://www.mywot.com/en/scorecard/pchelpsoft.com ! Setup file (installer) - https://www.virustotal.com/gui/file/7ab506784dcc49c916cdff2076132dafc881ac268e54aba39d6af2ca6ce0c775/details ! Related files ! https://www.virustotal.com/gui/file/04ef20ed8a783aaa91082865ed99c079cf2bf9f67908d536fdb9e227b19401f0/detection ! https://www.virustotal.com/gui/file/192dc080f0c52222e03c074e3a38a8b3cc5b31605457fd6acd447bf7488a89d8/relations ! https://www.virustotal.com/gui/file/40157e1981b97206658667927fbdc484c7e9615591884cfed2d6cadc9e3f1b4c/detection ! A 'driver updater' it wanted me to install - https://www.virustotal.com/gui/file/965bf402594ee539ce61d2a593c421b1c7ed6e1969369ae4a7866c17b2281a3c/detection ! https://forums.malwarebytes.com/topic/200216-removal-instructions-for-pccleaner/ ! Screenshots - https://github.com/iam-py-test/Assets-001/tree/main/PUPs/PCHelpSoft ! 19/9/2022: https://app.any.run/tasks/3c8b1d38-de18-488a-9e3f-62b3354c17e8 ! 6/11/2022: https://app.any.run/tasks/da8a44c3-965f-4fd6-816d-b5ae16235f62 (https://www.virustotal.com/gui/file/5475c9cff70482b8b5bf2c31395f9463261313991b41743686e4c8c43e53df0b/detection) ||pchelpsoft.com^$document ||www.pchelpsoft.com^$document ||cloud.pchelpsoft.com^$document ||cda.pchelpsoft.com^$document ||cdn.pchelpsoft.com^$document ||webtools.pchelpsoft.com^$document ||pchelpsoft.net^$document ||www.pchelpsoft.net^$document ! https://www.virustotal.com/gui/url/27307acb5b127114423ed0d7c63aaed0013d1833f56c158a3b049f8d1c98dcbc/detection ! Download button redirects to advancedsystemrepair.com ||pccleaner.com^$document ! The PUP from this website looks like a past one; maybe a variant or another download location ! https://github.com/iam-py-test/Assets-001/tree/main/PUPs/PCCleaner_1 ||advancedsystemrepair.com^$all ||support.advancedsystemrepair.com^$all ||secure.advancedsystemrepair.com^$all ||lp.advancedsystemrepair.com^$all ||track.advancedsystemrepair.com^$all ||www.advancedsystemrepair.com^$all ||checkout.advancedsystemrepair.com^$all ! Found this PUP on someone else's computer, so I decided to figure more about it. It does look very old; even the UI sometimes looks like Windows 7 despite the VM running 10 ! The (working) installer (from Softonic) - https://www.virustotal.com/gui/file/863adfe03c1ea35c424817274eabe4eef02fe4a2d6428f8718e61655fb8bc49c/detection ! The program (according to Malwarebytes's IOC report) - https://www.virustotal.com/gui/file/2aad06624e9b698ec0dc0276b433c606a4858d6585028cd658ae7c697358ffec/detection ! https://blog.malwarebytes.com/detections/pup-optional-slimcleanerplus/ ! All the domains seem to be related to this PUP ! https://www.virustotal.com/gui/url/f7be15d28340acb7db31f63a62a26bad1253824f2424117a816203950e86fd22/community ||slimware.com^$all ! https://www.virustotal.com/gui/url/440e39a20d7e01064269dadfc38eafd80c8534f7391f2c1ef7ac41c10d9c4e20/detection ||slimcleaner.com^$all ||www.slimcleaner.com^$all ! https://www.virustotal.com/gui/url/946a5c2295cfef547f162350af93257df55d6b2103a0ce2e84b241cf727a81f6/detection ||slimwareutilities.com^$all ! The executable from the website (https://www.virustotal.com/gui/file/d9103347f6043f0266a6480b6c794a4ee9f07800db43b6301920fe97587066d2/detection) seemed broken, but this one (maybe an older/newer mirror) works ||slimcleaner-plus.en.softonic.com^$all ! Other TLDs ||slimcleaner-plus.softonic.com.tr^$document ||slimcleaner-plus.softonic.vn^$document ! https://github.com/iam-py-test/investigations/blob/main/2021/11/5/1.md ||windowserrorhelp.com^$document ||certified.windowserrorhelp.com^$document ! Spyhunter is far from legit - and this company sues almost anyone (i.e. Bleeping Computer - https://blog.malwarebytes.com/security-world/2016/02/bleepingcomputer-defends-freedom-of-speech/, Malwarebytes - https://press.malwarebytes.com/2021/09/29/malwarebytes-wins-dismissal-of-enigma-lawsuit-in-final-ruling/) ! https://www.mywot.com/en/scorecard/enigmasoftware.com ! https://github.com/gorhill/uBlock/wiki/Software-known-to-have-uninstalled-uBlock-Origin ! https://en.wikipedia.org/wiki/SpyHunter_(software) ||enigmasoftware.com^$document ||www.enigmasoftware.com^$document ||installer.enigmasoftware.com^$document ||download.enigmasoftware.com^$document ||dl.enigmasoftware.com^$document ||instcfg.enigmasoftware.com^$document ||tt.web.enigmasoftware.com^$document ||myaccount.enigmasoftware.com^$document ||purchase.enigmasoftware.com^$document ||spyhunter.enigmasoftware.com^$document ||spyhunter-update.enigmasoftware.com^$document ||download2.enigmasoftware.com^$document ||spyhunter.com^$document ||www.spyhunter.com^$document ||spyhunter-download-v2.b-cdn.net^$document ! https://github.com/iam-py-test/my_filters_001/issues/84 ||mackeeper.com^$document ! https://www.virustotal.com/gui/file/088cbcec6b80eba99eb691968e0f972935aae301e9cb6d1c6133699530dd5621/community ||secure-browser.io^$document ||d1z0mfyqx7ypd2.cloudfront.net/securebrowser.io/$all ! locks your screen and just creates a link to their website on your desktop. Malware? ||zipfileslikeapro.net^$document ||use.zipfileslikeapro.net^$document ||www.zipfileslikeapro.net^$document ||goto.searchproonline.com^$all ||searchproonline.com^$all ! https://github.com/uBlockOrigin/uAssets/issues/11176 ||nearbyme.io^$document ||m.nearbyme.io^$document ! https://twitter.com/iam_py_test/status/1488163521540075524 ||outbyte.com^$document ||testedforyou.net^$document ! from an infected VM ||lp.pcsystemfix.com^$document ||pcsystemfix.com^$document ||download.pcsystemfix.com^$document ! https://forums.malwarebytes.com/topic/283588-mb-cant-find-malware/ ! https://forums.malwarebytes.com/topic/293374-aasearchtoolshub/ ||searchtoolshub.com^$document ||find.searchtoolshub.com^$all ! Some scam redirects brought me here (https://twitter.com/iam_py_test/status/1497351777754050562 - https://www.virustotal.com/gui/file/2e68dbec330d7ebe567dcbb67a1dffe83f6f0c278664b60f3edeee684edfe7ff/relations) ||drivermax.com^$document ! restoro ||techloris.com/go/restoro/$document ||techloris.com/lp/error8.php$document ||techloris.com/go/restoro-download/$document ! adware downloader - https://app.any.run/tasks/d1918395-7080-4292-9a71-1059bc7a90cf ||sway.office.com/flj90JK1oswcTJEO^$document ||certatd.ru^$all ! Bundled installer & PUP ||sysdriverupdater.com^$document ||www.sysdriverupdater.com^$document ! This is just Advanced System Repair Pro ||regcure.com^$document ||www.regcure.com^$document ||directbrand.com/dl/asr_regcure.php^$document ! https://blog.malwarebytes.com/threat-analysis/2022/06/forced-chrome-extensions-keep-reappearing/ ||activesearchbar.me^$all ||customsearchbar.me^$all ||securedatacorner.com^$all ||wincloudservice.com^$all ! https://forums.malwarebytes.com/topic/286395-microsoft-edge-custom-search-bar-extension-redirects-to-rbfastsearchme/ ||rb.fastsearch.me^$all ! https://forums.malwarebytes.com/topic/287338-browser-hi-jacker-royb2fastsearchme/ ||royb2.fastsearch.me^$all ! adware ||pdfconverterpower.net^$document ||downpdfpwr.com^$document ||searchpoweronline.com^$document ||goto.searchpoweronline.com^$document ||www.searchpoweronline.com^$document ! https://forums.malwarebytes.com/topic/295131-pdfpower-pdfshark-pdfsuperhero-pdftodocpro-pdfmagic/#comment-1556224 ||gifsearchutils.com^$document ||start.gifsearchutils.com^$document ||pdfsharkapp.com^$document ||start.pdfsharkapp.com^$document ||searchmagiconline.com^$document ||start.searchmagiconline.com^$document ||pdfsuperhero.com^$document ||stats.pdfsuperhero.com^$all ||bl.searchpoweronline.com^$document ! https://forums.malwarebytes.com/topic/289030-mbam-browser-guard-identifying-malware-but-mbam-not-removing-malware/ ||mysearchengine.co^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/128029 ||freddostagione.com^$all ||search.freddostagione.com^$all ||147.135.253.55^$document ||search.motherpipe.net^$document ||humanverified.net^$all ||search.potestainsula.com^$document ||search.husmicto.com^$document ||search.splendidus.net^$document ||search.optimusquaero.com^$document ||search.potenzamano.com^$document ||search.tutatagliente.com^$document ||search.megliolavoro.com^$document ||search.luminosoocchio.com^$document ||search.osservareimmaginare.com^$document ||search.avantiwendo.com^$document ||search.desideriosoldi.com^$document ||search.sottilesezione.com^$document ||search.alcunirisposta.com^$document ||search.thecanem.net^$document ||video-ad-skipper.com^$document ||search.becovi.com^$document ||luminosoocchio.com^$document ||quick-speedtest.com^$document ||husmicto.com^$document ||splendidus.net^$document ||optimusquaero.com^$document ||potenzamano.com^$document ||tutatagliente.com^$document ||megliolavoro.com^$document ||osservareimmaginare.com^$document ||desideriosoldi.com^$document ||sottilesezione.com^$document ||alcunirisposta.com^$document ||www.humanverified.net^$document ! https://github.com/AdguardTeam/AdguardFilters/issues/132840 ||adblocker-app.info^$all ||chrome.google.com/webstore/detail/ad-blocker-app/iamhhblhmpldjchjecmapgoikpjmmfoe^$document ! https://forums.malwarebytes.com/topic/291853-hijackhost-found-chrome-windows-10-home-64-bit/ ! https://blog.malwarebytes.com/detections/pup-optional-bytefence/ ! https://www.virustotal.com/gui/file/21dfa4ed47de7007c0fb6eadb3f94d2e847b3f4e301767d2320623f02f0926ba ! https://www.virustotal.com/gui/file/d41405553da0287be81722125b35405ad90923e7aa0631b5e5c6ab80358355ca ! https://safeweb.norton.com/reviews?url=bytefence.com ! https://www.mywot.com/scorecard/bytefence.com ||download.cnet.com/ByteFence-Anti-Malware/$document ||bytefence.com^$document ||cdn.bytefence.com^$all ||logs.bytefence.com^$all ||update.bytefence.com^$all ||ulogs.bytefence.com^$all ||www.bytefence.com^$document ||fr.bytefence.com^$document ||it.bytefence.com^$document ||en.bytefence.com^$document ||es.bytefence.com^$document ||shield.bytefence.com^$document ||new.bytefence.com^$document ! https://www.youtube.com/watch?v=2tW_PDVfT-E ! https://www.virustotal.com/gui/file/1c45ac42e4486ae5114cf287626ffb02eb03675f667d076d5c8f886ee0016d26/detection ! https://github.com/iam-py-test/Assets-001/tree/main/PUPs/Auslogics_PUP_regclean ! https://www.virustotal.com/gui/file/a54dffea1703732c3daf043462c289f4c9fc57fb27e1e9cc099b0cc03835940e/detection ! https://forums.malwarebytes.com/topic/199170-false-positive-with-auslogics-boostspeed/#elControls_1116195_menu ||auslogics.com^$all ||www.auslogics.com^$all ! https://www.virustotal.com/gui/file/1d26c8e2760b9d95e344dc93e4516c88c23bae5af1e888b2769186520f53021d/detection ! https://www.virustotal.com/gui/url/c9d507f4fe1720bb0b70a799abfd548f315694f59eebea676204da1cbaee4b4f/detection ! https://www.virustotal.com/gui/file/bba00552bb0a562a00aa70c8425e48bb1b407a72f84df6c8f69f0bf44fabf310/detection ! https://www.virustotal.com/gui/file/0dcf7e52492de09df39f7b1f7996d61033c6f61b43d38990f43b45dd530dcdb9/relations ! https://www.hybrid-analysis.com/sample/1d26c8e2760b9d95e344dc93e4516c88c23bae5af1e888b2769186520f53021d ! https://www.hybrid-analysis.com/sample/1d26c8e2760b9d95e344dc93e4516c88c23bae5af1e888b2769186520f53021d/60a4789f1522974edf38bd58 ! https://www.hybrid-analysis.com/sample/bba00552bb0a562a00aa70c8425e48bb1b407a72f84df6c8f69f0bf44fabf310 ! https://github.com/iam-py-test/Assets-001/tree/main/PUPs/ashampoo ||ashampoo.com^$document ! https://www.virustotal.com/gui/url/9979729afeff4472121a6faa8d4a4b7c885a5f391b082d50585bf16929597d4e/community --> https://www.virustotal.com/gui/file/c9bb2af73703f81a31ae5a3dedbf6eebf404256b679303111c1dedf0e24879db/community ! https://app.any.run/tasks/d2533d89-8e5e-4fc6-b110-bafc153c3636 (my analysis) ! walliant: https://www.youtube.com/watch?v=91w4rzBTP5o ||riversnails.club^$all ||walliant.com^$document ! clone of another screenlocker adware ||gifsmakerpro.com^$document ||www.gifsmakerpro.com^$document ! https://forums.malwarebytes.com/topic/293346-malwarebytes-not-detecting-virus-highjacking-my-search-engine-in-chrome/ ||mobilisearch.com^$all ||mobility-search.com^$document ! another clone of ziprar thing (Adware.SearchLightPro) ||imagelighteditor.com^$document ||www.imagelighteditor.com^$document ||downloadimglight.com^$document ||searchlightpro.com^$document ||start.searchlightpro.com^$all ||dsc.searchlightpro.com^$all ! https://forums.malwarebytes.com/topic/283015-pupoptionalwinsweeper ||solvusoft.com^$document ||www.solvusoft.com^$document ||exefiles.com/*/recommended/winthruster/$document ! random ad ||totalsystemcare.com^$document ||www.totalsystemcare.com^$document ||safebytes.com^$document ||driverassist.com^$document ! browsing YouTube without an adblocker ||customsearchtool.com^$document ||home.customsearchtool.com^$document ||config.customsearchtool.com^$document ||hp.customsearchtool.com^$document ||imp.customsearchtool.com^$document ||d3pxa1onb1zy4q.cloudfront.net/custom_search_tool-2022.7.15-fx.xpi^$all ! https://forums.malwarebytes.com/topic/293616-google-doc-fake-extension-not-detected/ (account required) ||gosearches.gg^$all ! https://forums.malwarebytes.com/topic/293620-adwcleaner-wont-run/ ||search-fine.com^$document ! https://github.com/uBlockOrigin/uAssets/issues/16582 (without an adblocker) ||easyprint.app^$document ||cdn.easyprint-cdn.app^$document ! https://www.virustotal.com/gui/url/c7cdd1eaf651fbf4446d189d91b52b0c6a5811fb70db18b3eec1fa575057163a/detection ||freshysearch.com^$all ||cdn.freshysearch.com^$all ! doesn't seem to do much, but clearly not legit ||tor-browser.app^$document ! two search engine hijackers ! https://www.virustotal.com/gui/url/1ca49bde04ac00c79b259a4a02b041d91c512ca55a6d0e839f69010d0bc32061/detection ||pdftab.com^$document ||cdn.pdftab.com^$document ||findmanualsnow.com^$document ! ran across this while looking for DDNS services ||ww1.pwnz.org^$document ||thesafersearch.com^$document ||get.thesafersearch.com^$all ! The makers of such wonderful programs like "Driver Genius 22" and "PC Cleaner" ||avanquest.com^$document ||www.avanquest.com^$document ||webtools.avanquest.com^$document ! 'Wave browser' which is just a scummy version of Chrome ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-968062965 ||wavebrowser.co^$document ||download.wavebrowser.co^$all ||wavebrowser.com^$document ||dl.gowavebrowser.com^$all ||gowavebrowser.com^$document ! DLL Helper ! https://www.virustotal.com/gui/file/675a72bb2b3ea39beafc73e8faf31b85b58b0dcc169b10649d5f49341936a379?nocache=1 ||dll-helper.en.softonic.com^$document ! search engine hijacker ||manualsdirectory.org^$document ||tab.freshymanuals-site.com^$document ||search.freshy.com^$document ! https://github.com/uBlockOrigin/uAssets/issues/17568 ||wigglewurm.com^$document ||n.wigglewurm.com^$all ! an infected VM --> this extension hijacks the search engine ||getsecurify.com^$document ||www8.getsecurify.com^$document ||chrome.google.com/webstore/detail/browsing-overview-by-secu/njfkgeajknkffkngdmjmjninkbgjedlo/$document ||mysecurify.com^$document ||search.mysecurify.com^$document ||ext.mysecurify.com^$all ! https://0xacab.org/my-privacy-dns/matrix/-/issues/102265 ! an infected VM --> this extension hijacks the search engine claiming it protects your searchs ||privacykeeperapp.com^$document ||get.privacykeeperapp.com^$document ||chrome.google.com/webstore/detail/privacy-keeper/acdkbikhkmpbfdmfmcogpnjchcniiipa^$document ||privacykeepersearch.com^$document ! https://0xacab.org/my-privacy-dns/matrix/-/issues/121797 ||speak-text-tab.com^$document ||search.speak-text-tab.com^$document ! https://github.com/uBlockOrigin/uAssets/issues/17880 ||office.org^$document ! https://github.com/uBlockOrigin/uAssets/issues/17960 ||templatesearch.org^$all ! ----- Spam ----- ! https://forums.malwarebytes.com/topic/281397-how-to-update-my-adwcleaner/ ||24hourhtmlcafe.com^$document ! https://forums.malwarebytes.com/topic/281787-how-many-types-of-malware-are-there/ (https://web.archive.org/web/20211214132150/https://forums.malwarebytes.com/topic/281787-how-many-types-of-malware-are-there/) -> hxxpx[:]//ilovealgarve[.]net[/]web-football-no-agents[/]) ||ilovealgarve.net^$document ! https://web.archive.org/web/20211222121009/https://forums.malwarebytes.com/topic/282084-keeping-laptop-safe/ -> hxxpx[:]//nbgpapartmani[.]com[/]register-web-ball-ufadeal[/] ||nbgpapartmani.com^$document ! https://forums.malwarebytes.com/topic/282082-hi-working-a-spreadsheet-more-than-8-years-history-mb-crashed-it/ (https://web.archive.org/web/20211222121637/https://forums.malwarebytes.com/topic/282082-hi-working-a-spreadsheet-more-than-8-years-history-mb-crashed-it/) -> hxxpx[:]//superagentconcierge[.]com[/]casino-ebet-entrance[/] ||superagentconcierge.com^$document ! https://forums.malwarebytes.com/topic/283348-update-ios-15/ (https://web.archive.org/web/20220202172538/https:/forums.malwarebytes.com/topic/283348-update-ios-15/) ||binaryreviewsrace.com^$document ! https://forums.malwarebytes.com/topic/283347-update-ios-15/ (https://web.archive.org/web/20220202172612/https:/forums.malwarebytes.com/topic/283347-update-ios-15/) ||stormlordpublishing.com^$document ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1029244954 ||quickdates1.com^$document ||lovesingle.xyz^$document ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1120210042 ||fuckbookmobile.com^$document ||www.fuckbookmobile.com^$document ! https://github.com/DandelionSprout/adfilt/issues/63#issuecomment-1179770663 ||like.xcat.buzz^$document ||disqus.com/by/disqus_AIqzI15v88/^$document ! https://web.archive.org/web/20221007114132/https://forums.malwarebytes.com/topic/290873-whats-the-hottest-temperature-in-your-city/ ||rathbunlakeassoc.com^$document ||ufadeal.info^$document ! https://web.archive.org/web/20221206113456/https://forums.malwarebytes.com/topic/292706-top-cell-phone-apps-and-games-for-your-iphoneo-verjaardagsherinnering-nu/ ! https://forums.malwarebytes.com/topic/292707-spam-post-on-this-forum/ (account required) ||mhapks.com^$document ! GH spam, i.e. https://github.com/tesla-android/issue-tracker/discussions/162#discussioncomment-4551799 ||4.fo^$document ||mylocaldates1s.com^$all ||in.sv^$document ||static.imghst-de.com/eb01eaf3-369a-423f-a31e-c4221a2ca42d.png^$all ||trk-click.pshtrk.com^$document ! https://github.com/DandelionSprout/adfilt/commit/e83dc45b60a61c6097b8c40605855a80e3282901 ||link.sv^$document ! https://www.virustotal.com/gui/url/6bbc5fc50b84711644db9739cab16fbdd5659b3d6b82dbde0a3a82427e6f03b9/community ||to.sv^$document ||go.sv^$document ! https://www.virustotal.com/gui/url/1f273d4cd56060082b8a598514f975bf4592a5f6be5f77e05f7c453266edaaad/community ||scuekpza.ws^$document ! https://forums.malwarebytes.com/topic/273013-android-unknown-chrome-hijacker/page/3/#comment-1553668 ||thedrivingtutors.com^$document ! tons of sites with keyword spam who link to each other ||sjs.sold.yachts^$document ||i.pauj0foas709824.shop^$document ||er.jrwgjwrgu1243thfd.shop^$document ||kt.rakwbiznesie.pl^$document ||vmapg.trefjehier.nl^$document ||dnar.newsnewsyes.yachts^$document ||rrwaee.dbbdh.top^$document ||gvcnm.newsnewsfor.shop^$document ||ts475173759.mm.bing.net^$document ||qwj.krowkavet.pl^$document ||r.util.yachts^$document ||ispc.chungcumoi.top^$document ||qmzux.usesgasek.top^$document ||yfvqf.changwonanma.top^$document ||le.krowkavet.pl^$document ||vxh.news1.vn.ua^$document ||dhqn.podrozegruzja.pl^$document ||hlcix.uiwangculzang.top^$document ||slxoy.baloon.yachts^$document ||b.gulospspo.top^$document ||uor.kabuyutannusantara.top^$document ||xudkkk.chungcumatphohn.top^$document ||r.greckieskarby.pl^$document ||sbqxqm.quite.yachts^$document ||ewe.kouzinti.shop^$document ||z.paseqx.top^$document ||nue.kevinashen.top^$document ||kbako.slowowarszawy.pl^$document ||ikdfpc.kevinashen.top^$document ||ikde.kabuyutannusantara.top^$document ||vwnjyh.wdmag.nl^$document ||mbv.new-host.shop^$document ||vvf.dsgjhdsf98dsfdfs.shop^$document ||afatfg.sukuncl.top^$document ||tcln.util.yachts^$document ||gcz.regeokna.pl^$document ||hiepqu.wulktir.pl^$document ||yub.danielkordos.pl^$document ||wbhji.planetacripto.top^$document ||wq.chungcumatphohn.top^$document ||upuymn.semihangingdumptrucktractoroiltankaoheng.top^$document ||xkltl.jaminjos.shop^$document ||jgo.softwarepublicoregionalbeta.net^$document ||hmc.gulospspo.top^$document ||x.blackoakgallery.pl^$document ||xeezv.xuzhouzhuangxiu.top^$document ! similar ||fwiu.kohaito.shop^$document ||iwmfo.simpletalent.pl^$document ||kxirue.teplotrassa.yachts^$document ||wmwei.kukallooy.yachts^$document ||mv.grizli.yachts^$document ||eybg.bhpprotech.pl^$document ||ktehf.out.yachts^$document ||pkxj.dbbdh.top^$document ||clo.grizli.yachts^$document ||bkxhb.xiaochong2021.top^$document ||jyvg.news1.vinnica.ua^$document ||hb.slowowarszawy.pl^$document ||sao.24hfastplumbingservice.cyou^$document ||vleuet.ptnfd2020.pl^$document ||tbs.s88s.top^$document ||qua.narlofkrc.top^$document ||sqfjpd.colko.skin^$document ||tglt.adamoption.top^$document ||hsecx.branchmodern.news^$document ||wypai.alanwin.top^$document ||v.kabuyutannusantara.top^$document ||bl.jaminjos.shop^$document ||pmwvr.kosinka.yachts^$document ||wuxjqu.nasanet.top^$document ||qyt.dotoplo.pl^$document ||xnex.newsnewsyes.yachts^$document ||hq.nhabatang.top^$document ||eiiiy.fuflo.yachts^$document ||xvrg.fresh-and-interesting.com^$document ||geraldineblog.top^$document ||cpp.babnews.cfd^$document ||hkx.new-host.shop^$document ||r.regeokna.pl^$document ||xogbx.zoxkk.top^$document ||kan.sdgoiyhds87.shop^$document ||xiaochong2021.top^$document ! even more ||planetacripto.top^$document ||yxsax.planetacripto.top^$document ||wrx.rakwbiznesie.pl^$document ||yf.news-ok.shop^$document ||fqzp.carolawolbrom.pl^$document ||qx.gzjxyy.top^$document ||m.dbbdh.top^$document ||vrqhdu.chungcumatphohn.top^$document ! additional ones ||wxere.grupabukko.pl^$document ||appwfr.rauscher-elektro.de^$document ||scxbumk.jj-tauben.de^$document ||jfanubw.david-laeuft.de^$document ||nxhbcfpy.hundebedarf-boettcher.de^$document ||guohnor.gorlice2022.pl^$document ||duxuu.hundebedarf-boettcher.de^$document ||mxzem.david-laeuft.de^$document ||qbfhcwvg.multig.pl^$document ||vcdvxl.multig.pl^$document ||spnb.david-laeuft.de^$document ||zqkgit.hundebedarf-boettcher.de^$document ! https://forums.malwarebytes.com/topic/286891-my-android-phone-was-connected-to-pc-with-charge-only-when-pc-was-hacked/#comment-1555237 (deleted) ||anonigstalk.com^$document ||bingenerator.one^$document ! https://forums.malwarebytes.com/topic/295956-from-another-malwarebytes-forum-spammer/ (account required) ||discord.onl^$document ! https://github.com/hagezi/dns-blocklists/issues/804 ||venezuelabaseballjerseys.com^$document ||italyworldbaseballclassic.com^$document ||storeoregononline.com^$document ||tlstoreonline.com^$document ||storecollegeonline.com^$document ||shoptcuhornedonline.com^$document ||shopsyracuseonline.com^$document ! ---- Abusive Cryptominers ---- ! slows browser/device to a crawl, contains no real content, and uses (attempts) to trap the user - https://github.com/uBlockOrigin/uAssets/issues/7449 ||csgo.xyz^$all ! ---- Stalkerware ---- ! copied from https://github.com/AssoEchap/stalkerware-indicators/blob/adae94598f8d628a4af90f9bf323553d3ec683a4/ioc.yaml#L1-L273 - https://github.com/AssoEchap/stalkerware-indicators#license (modified to be in uBo format, removed a few domains) ||app.phonespying.com^$document ||phonespying.com^$all ||copy9.com^$document ||fonetracker.com^$document ||thetruthspy.com^$all ||icloudappe.com^$all ||media-sync-a.copy9.com^$all ||media-sync-a.fonetracker.com^$all ||media-sync-a.thetruthspy.com^$all ||media-sync-a100.fonetracker.com^$all ||media-sync-a600.fonetracker.com^$all ||media-sync-a740.thetruthspy.com^$all ||media-sync-a743.thetruthspy.com^$all ||media-sync-a746.thetruthspy.com^$all ||media-sync-a747.thetruthspy.com^$all ||media-sync-a748.thetruthspy.com^$all ||media-sync-a749.thetruthspy.com^$all ||media-sync-a780.fonetracker.com^$all ||media-sync-a785.fonetracker.com^$all ||media-sync-a7xx.thetruthspy.com^$all ||media-sync-a810.thetruthspy.com^$all ||media-sync-a820.thetruthspy.com^$all ||media-sync-a825.thetruthspy.com^$all ||media-sync-a830.thetruthspy.com^$all ||media-sync-a835.thetruthspy.com^$all ||media-sync-a895.thetruthspy.com^$all ||media-sync-a8xx.thetruthspy.com^$all ||media-sync-a910.thetruthspy.com^$all ||media-sync-a915.thetruthspy.com^$all ||media-sync-a920.thetruthspy.com^$all ||media-sync-a925.thetruthspy.com^$all ||media-sync-a930.thetruthspy.com^$all ||media-sync-a935.thetruthspy.com^$all ||media-sync-a940.thetruthspy.com^$all ||media-sync-a941.thetruthspy.com^$all ||media-sync-a942.thetruthspy.com^$all ||media.thetruthspy.com^$all ||my.copy9.com^$all ||my.ispyoo.com^$all ||my.thetruthspy.com^$all ||my.thespyapp.com^$all ||phonetracking.net^$all ||protocol-a.copy9.com^$all ||protocol-a.exactspy.com^$all ||protocol-a.fonetracker.com^$all ||protocol-a.ispyoo.com^$all ||protocol-a.mxspy.com^$all ||protocol-a.thetruthspy.com^$all ||protocol-a100.fonetracker.com^$all ||protocol-a600.fonetracker.com^$all ||protocol-a621.copy9.com^$all ||protocol-a696.copy9.com^$all ||protocol-a710.copy9.com^$all ||protocol-a712.fonetracker.com^$all ||protocol-a740.thetruthspy.com^$all ||protocol-a741.thetruthspy.com^$all ||protocol-a742.thetruthspy.com^$all ||protocol-a743.thetruthspy.com^$all ||protocol-a744.thetruthspy.com^$all ||protocol-a745.thetruthspy.com^$all ||protocol-a746.thetruthspy.com^$all ||protocol-a747.thetruthspy.com^$all ||protocol-a748.thetruthspy.com^$all ||protocol-a749.thetruthspy.com^$all ||protocol-a780.copy9.com^$all ||protocol-a780.fonetracker.com^$all ||protocol-a780.ispyoo.com^$all ||protocol-a780.mxspy.com^$all ||protocol-a785.copy9.com^$all ||protocol-a785.fonetracker.com^$all ||protocol-a810.ispyoo.com^$all ||protocol-a810.thetruthspy.com^$all ||protocol-a811.ispyoo.com^$all ||protocol-a811.mxspy.com^$all ||protocol-a880.ispyoo.com^$all ||protocol-a910.thetruthspy.com^$all ||protocol-a915.thetruthspy.com^$all ||protocol-a920.thetruthspy.com^$all ||protocol-a925.thetruthspy.com^$all ||protocol-a930.thetruthspy.com^$all ||protocol-a935.thetruthspy.com^$all ||protocol-a940.thetruthspy.com^$all ||protocol-a941.thetruthspy.com^$all ||protocol-a942.thetruthspy.com^$all ||protocol-monitor.thetruthspy.com^$all ||protocol-viewer-a.copy9.com^$all ||protocol.copy9.com^$all ||protocol.ispyoo.com^$all ||protocol.systemserviceprovider.com^$all ||protocol.thetruthspy.com^$all ||secondclone-2d312.firebaseio.com^$all ||setupmail-a.icloudappe.com^$all ||setupmail-a720.icloudappe.com^$all ||setupmail-a722.icloudappe.com^$all ||setupmail-a724.icloudappe.com^$all ||setupmail-a725.icloudappe.com^$all ||setupmail-a726.icloudappe.com^$all ||setupmail-a727.icloudappe.com^$all ||setupmail-a729.icloudappe.com^$all ||setupmail-a732.icloudappe.com^$all ||setupmail-a733.icloudappe.com^$all ||setupmail-a734.icloudappe.com^$all ||setupmail-a735.icloudappe.com^$all ||setupmail-a737.icloudappe.com^$all ||setupmail-a738.icloudappe.com^$all ||setupmail-a740.icloudappe.com^$all ||setupmail-a741.icloudappe.com^$all ||setupmail-a742.icloudappe.com^$all ||setupmail-a743.icloudappe.com^$all ||setupmail-a744.icloudappe.com^$all ||setupmail-a745.icloudappe.com^$all ||setupmail-a746.icloudappe.com^$all ||setupmail-a747.icloudappe.com^$all ||setupmail-a748.icloudappe.com^$all ||setupmail-a910.icloudappe.com^$all ||setupmail-a915.icloudappe.com^$all ||setupmail-a920.icloudappe.com^$all ||setupmail.icloudappe.com^$all ||spyzee.com^$all ||sync-a.copy9.com^$all ||sync-a.exactspy.com^$all ||sync-a.fonetracker.com^$all ||sync-a.ispyoo.com^$all ||sync-a.mxspy.com^$all ||sync-a.thetruthspy.com^$all ||sync-a100.fonetracker.com^$all ||sync-a600.fonetracker.com^$all ||sync-a712.fonetracker.com^$all ||sync-a7xx.thetruthspy.com^$all ||sync-a8xx.thetruthspy.com^$all ||sync-a925.thetruthspy.com^$all ||sync-a930.thetruthspy.com^$all ||sync-a935.thetruthspy.com^$all ||sync-a940.thetruthspy.com^$all ||sync-a941.thetruthspy.com^$all ||sync-a942.thetruthspy.com^$all ! https://github.com/AssoEchap/stalkerware-indicators/blob/9f656217ab46b2043612808940f4387b651000a9/ioc.yaml#L3937 - under https://github.com/AssoEchap/stalkerware-indicators#license ! my analysis: https://app.any.run/tasks/57cdb248-461e-4dc5-b6b2-2235eec1e098/ ! my analysis: https://www.virustotal.com/gui/file/5809066a109718683fa1ffe3abcd0e6c9bd5f613279e081e31bc17e628d9bfba/detection ! my analysis: https://tria.ge/230505-27f8mshd2v/behavioral1 ||myspyapps.com^$document ||my-spy-a9c92.firebaseio.com^$document ! ----- include rules for just uBlock Origin and AdGuard, and the VXVault list ----- !#include special_lists/anti-malware-ubo-extension.txt ! END