Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
+ Testing out the still-odd-looking AdGuard syntax recommended in AdguardTeam/VscodeAdblockSyntax#131 + Adding yet another workaround to find actual list errors in uBO more easily.
  • Loading branch information
DandelionSprout authored Mar 27, 2024
1 parent caeeaad commit 24d8307
Show file tree
Hide file tree
Showing 6 changed files with 42 additions and 35 deletions.
10 changes: 8 additions & 2 deletions Alternate versions Anti-Malware List/AntiMalwareABP.txt
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[Adblock Plus 3.13]
! Title: 💊 Dandelion Sprout's Anti-Malware List (for Adblock Plus and AdBlock)
! Version: 24March2024v2
! Version: 27March2024v3
! Expires: 2 days
! Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists
Expand All @@ -21,7 +21,7 @@
! Palau (Put on break due to too many whitelistings being needed)
!!!||pw^$domain=~libgen.pw|~petridish.pw|~palaugov.pw|~dpc.pw|~buttercup.pw|~rezka.pw|~darkcrystal.pw|~xor.pw|~fullhdfilmizlesene.pw|~gopass.pw|~vost.pw|~core.pw|~bittor.pw|~plutonium.pw|~nitter.pw|~kge.pw
! Legitimate use is almost non-existent, but has a tiny userbase in Japan. Its extreme common-ness in malware redirections means that the entry will be kept forever.
||top^$domain=~caitlin.top|~corriente.top|~gdtot.top|~nicenature.top|~reminder.top|~magocoro.top|~castlevania.top|~suiten.top|~shucks.top|~1stream.top|~ambr.top|~techblog.top|~changlam10.top|~changlam11.top|~pdcdn1.top|~mastodon.top|~pressplay.top|~chillx.top|~strims.top|~thedesk.top|~audioforyou.top|~pegelinux.top|~awavenue.top
||top^$domain=~caitlin.top|~corriente.top|~gdtot.top|~nicenature.top|~reminder.top|~magocoro.top|~castlevania.top|~suiten.top|~shucks.top|~1stream.top|~ambr.top|~techblog.top|~changlam10.top|~changlam11.top|~pdcdn1.top|~mastodon.top|~pressplay.top|~chillx.top|~strims.top|~thedesk.top|~audioforyou.top|~pegelinux.top|~awavenue.top|~reyhub.top
! International topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent.
||loan^
!!!||agency^$domain=~battlefield.agency|~baam.agency|~robotzebra.agency|~uphotel.agency|~ws.agency (Can't remember the last time I saw it used in a redirection train.)
Expand Down Expand Up @@ -46492,6 +46492,12 @@ www.microsoft.com##a[data-pfns][href*=pac-men]


! Brazilian mobsters trying to DDoS Cisco with TXT-type DNS requests
|cisco.com|$domain=for-txt-dnstype-conversions.mint
|cloudflare.com|$domain=for-txt-dnstype-conversions.mint
|adobe.com|$domain=for-txt-dnstype-conversions.mint
|atlassian.com|$domain=for-txt-dnstype-conversions.mint
|apple.com|$domain=for-txt-dnstype-conversions.mint
|google.com|$domain=for-txt-dnstype-conversions.mint



Expand Down
56 changes: 28 additions & 28 deletions Alternate versions Anti-Malware List/AntiMalwareAdGuard.txt
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@

! Title: 💊 Dandelion Sprout's Anti-Malware List (for AdGuard)
! Version: 24March2024v2
! Version: 27March2024v3
! Expires: 2 days
! Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists
Expand All @@ -20,7 +20,7 @@
! Palau (Put on break due to too many whitelistings being needed)
!!!||pw^$document,domain=~libgen.pw|~petridish.pw|~palaugov.pw|~dpc.pw|~buttercup.pw|~rezka.pw|~darkcrystal.pw|~xor.pw|~fullhdfilmizlesene.pw|~gopass.pw|~vost.pw|~core.pw|~bittor.pw|~plutonium.pw|~nitter.pw|~kge.pw
! Legitimate use is almost non-existent, but has a tiny userbase in Japan. Its extreme common-ness in malware redirections means that the entry will be kept forever.
||top^$document,domain=~caitlin.top|~corriente.top|~gdtot.top|~nicenature.top|~reminder.top|~magocoro.top|~castlevania.top|~suiten.top|~shucks.top|~1stream.top|~ambr.top|~techblog.top|~changlam10.top|~changlam11.top|~pdcdn1.top|~mastodon.top|~pressplay.top|~chillx.top|~strims.top|~thedesk.top|~audioforyou.top|~pegelinux.top|~awavenue.top
||top^$document,domain=~caitlin.top|~corriente.top|~gdtot.top|~nicenature.top|~reminder.top|~magocoro.top|~castlevania.top|~suiten.top|~shucks.top|~1stream.top|~ambr.top|~techblog.top|~changlam10.top|~changlam11.top|~pdcdn1.top|~mastodon.top|~pressplay.top|~chillx.top|~strims.top|~thedesk.top|~audioforyou.top|~pegelinux.top|~awavenue.top|~reyhub.top
! International topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent.
||loan^$document
!!!||agency^$document,domain=~battlefield.agency|~baam.agency|~robotzebra.agency|~uphotel.agency|~ws.agency (Can't remember the last time I saw it used in a redirection train.)
Expand Down Expand Up @@ -330,7 +330,7 @@ exefiles.com##.row:has(a[href*="/recommended/"])
/^https?:\/\/((?!www)[a-z]{3,5}\.)?[-0-9a-z]{6,}\.(?:com|fun|guru|life|online|pw|site|space|top)\/\/?\?o=[0-9a-z]{7}&u=[0-9a-z]{7}/$document,match-case,domain=com|fun|guru|life|online|pw|site|space|top
/^https?:\/\/((?!www)[a-z]{3,5}\.)?[-0-9a-z]{6,}\.(?:com|fun|guru|life|online|pw|site|space|top)\/\/?\?u=[0-9a-z]{7}&o=[0-9a-z]{7}/$document,match-case,domain=com|fun|guru|life|online|pw|site|space|top
! https://github.com/AdguardTeam/AdguardFilters/issues/58737
/^https?:\/\/(?:www\.)?[-0-9a-z]{14,}\.(?:biz|fun|live)\/[a-zA-Z]{10,}\.php$/$document,domain=biz|fun|live
/^https?:\/\/(?:www\.)?[-0-9a-z]{14,}\.(?:biz|fun|live)\/[a-zA-Z]{10,}\.php\$/$document,domain=biz|fun|live

! ——— Banner for "MSN New Tab" ———
msn.com##.irisbanner
Expand Down Expand Up @@ -677,7 +677,7 @@ zombooru.com##a[href="http://www.hard55.com"]
216.21.13.14$network
216.21.13.15$network
/\.(xyz|pics)/[a-zA-Z0-9]{130,}/$document,script,subdocument,image
/\.(cloudfront\.net|xyz|pics)/[a-zA-Z0-9]{20,}/[a-zA-Z0-9]{25,}\+[a-zA-Z0-9+]{90,}$/$document,script,subdocument,image
/\.(cloudfront\.net|xyz|pics)/[a-zA-Z0-9]{20,}/[a-zA-Z0-9]{25,}\+[a-zA-Z0-9+]{90,}\$/$document,script,subdocument,image
||abaphosis.guru^$all
||abietichob.live^$all
||abyssusuntouch.guru^$all
Expand Down Expand Up @@ -1367,7 +1367,7 @@ zombooru.com##a[href="http://www.hard55.com"]
!#if !ext_ublock
142.91.159.*$network
! https://github.com/DandelionSprout/adfilt/issues/942
/^172\.255\.6\.(\d{1,2}|[12][0-689]\d|17[0-689])$/$network
/^172\.255\.6\.(\d{1,2}|[12][0-689]\d|17[0-689])\$/$network
23.109.150.*$network
23.109.248.*$network
!#endif
Expand Down Expand Up @@ -4255,7 +4255,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||virpropcnow.xyz^$all
||avprotectionoverview.com^$all
! (https://github.com/DandelionSprout/adfilt/issues/904)
/(^|\.|//)tkqlhce\.com/click-.*([?&][a-tv-z]{1,}(=[a-zA-Z0-9]{1,})?){1,}$/$document
/(^|\.|//)tkqlhce\.com/click-.*([?&][a-tv-z]{1,}(=[a-zA-Z0-9]{1,})?){1,}\$/$document
! https://github.com/DandelionSprout/adfilt/issues/288
||forwrdnow.com^$document
||7lyonline.com^$document
Expand Down Expand Up @@ -4736,7 +4736,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||download2325.mediafire.com/pmth9b9cwtkg/8h91fn11fa1dacu/Latest_Setup_active.rar^$all
! https://www.telia.no/kundeservice/mobil/malware-flubot-android/
!+ NOT_OPTIMIZED
/^https?://(www\.)?[a-z0-9-]{1,}\.[a-z]{2,17}/[a-z0-9]/\?[a-z0-9.-]{8,}$/$document
/^https?://(www\.)?[a-z0-9-]{1,}\.[a-z]{2,17}/[a-z0-9]/\?[a-z0-9.-]{8,}\$/$document
! A Discord conversation I had about Throneful
||lover-finder.life^$all
||super-datings.life^$all
Expand Down Expand Up @@ -5115,11 +5115,11 @@ zombooru.com##a[href="http://www.hard55.com"]
||zfcurqe.art^$all
||zuginmw.art^$all
!#if !ext_ublock
/^178\.253\.[0-7]\.\d{1,3}$/$network
/^178\.253\.[0-7]\.\d{1,3}\$/$network
178.253.14.*$network
178.253.15.*$network
/^178\.253\.2[0145]\\d{1,3}$/$network
/^178\.253\.3[04-7]\.\d{1,3}$/$network
/^178\.253\.2[0145]\\d{1,3}\$/$network
/^178\.253\.3[04-7]\.\d{1,3}\$/$network
178.253.46.*$network
178.253.47.*$network
178.253.54.*$network
Expand Down Expand Up @@ -5392,9 +5392,9 @@ zombooru.com##a[href="http://www.hard55.com"]
||bnbdeal.net^$all
! https://github.com/AdguardTeam/AdguardFilters/issues/129414
!+ NOT_OPTIMIZED
/^http://imgblaze.net/[a-z0-9]{6}$/$document,popup
/^http://imgblaze.net/[a-z0-9]{6}\$/$document,popup
!+ NOT_OPTIMIZED
/^http://imgblaze.net/[a-z0-9]{6}$/$third-party,subdocument
/^http://imgblaze.net/[a-z0-9]{6}\$/$third-party,subdocument
! https://github.com/AdguardTeam/AdguardFilters/issues/131156
146.19.169.98$network
146.19.169.99$network
Expand Down Expand Up @@ -11410,7 +11410,7 @@ zombooru.com##a[href="http://www.hard55.com"]
||showjoinnip.live^$all
||usedhutsold.live^$all
57.128.71.215$network
/&[a-z]{1,2}=[a-zA-Z0-9]{0,}%[a-zA-Z0-9%]{1000,}$/$document
/&[a-z]{1,2}=[a-zA-Z0-9]{0,}%[a-zA-Z0-9%]{1000,}\$/$document
! https://github.com/AdguardTeam/AdguardFilters/issues/155936
||truanet.com^$all
||rumadel.com^$all
Expand Down Expand Up @@ -20268,14 +20268,14 @@ toorgle.net##.join
46.161.31.*$network
91.243.41.*$network
91.243.42.*$network
/^5\.8\.4[4-7]\.\d{1,3}$/$network
/^5\.101\.4[67]\.\d{1,3}$/$network
/^5\.188\.5[01]\.\d{1,3}$/$network
/^5\.188\.17[67]\.\d{1,3}$/$network
/^5\.188\.19[45]\.\d{1,3}$/$network
/^5\.189\.21[89]\.\d{1,3}$/$network
/^31\.184\.20[0-3]\.\d{1,3}$/$network
/^185\.238\.15[2-5]\.\d{1,3}$/$network
/^5\.8\.4[4-7]\.\d{1,3}\$/$network
/^5\.101\.4[67]\.\d{1,3}\$/$network
/^5\.188\.5[01]\.\d{1,3}\$/$network
/^5\.188\.17[67]\.\d{1,3}\$/$network
/^5\.188\.19[45]\.\d{1,3}\$/$network
/^5\.189\.21[89]\.\d{1,3}\$/$network
/^31\.184\.20[0-3]\.\d{1,3}\$/$network
/^185\.238\.15[2-5]\.\d{1,3}\$/$network
!#endif
! https://github.com/AdguardTeam/AdguardFilters/issues/120349
||dispositionadverb.com^$all
Expand Down Expand Up @@ -23580,7 +23580,7 @@ tumblr.com#?#:is(.post,div[data-cell-id][style],div[tabindex]:is([style^=m],[dat
[2606:4700:3030::6815:5284]$network
[2606:4700:3037::ac43:9e39]$network
! Google results for «SodaStream site:no cranberry»
/^https?://[a-z0-9.-]{1,}\.([a-z]{3,}|[a-z][a-tv-z]|[a-qs-z][a-z])/.*(go\.php|redirect|url=|\?re=).*\.(xn--p1ai|рф|%D1%80%D1%84)$/$document,domain=~malware-redirection-results.*
/^https?://[a-z0-9.-]{1,}\.([a-z]{3,}|[a-z][a-tv-z]|[a-qs-z][a-z])/.*(go\.php|redirect|url=|\?re=).*\.(xn--p1ai|рф|%D1%80%D1%84)\$/$document,domain=~malware-redirection-results.*
||adservice.google.*/ddm/clk/$document,domain=~malware-redirection-results.*
/ad_click/q?&url=$document,domain=~malware-redirection-results.*
! Laughably blatant fraud site
Expand Down Expand Up @@ -24144,12 +24144,12 @@ www.microsoft.com##a[data-pfns][href*=pac-men]

!#if !ext_ublock
! Brazilian mobsters trying to DDoS Cisco with TXT-type DNS requests






|cisco.com|$dnstype=TXT
|cloudflare.com|$dnstype=TXT
|adobe.com|$dnstype=TXT
|atlassian.com|$dnstype=TXT
|apple.com|$dnstype=TXT
|google.com|$dnstype=TXT
!#endif

!#if !ext_ublock
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[Adblock Plus 3.13]
! Title: 💊 Dandelion Sprout's Anti-Malware List (for AdGuard Home, AdGuard for Android/Windows/macOS' DNS filtering, and Pi-Hole FTL ≥5.22)
! Version: 24March2024v2
! Version: 27March2024v3
! Expires: 2 days
! Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
! For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists
Expand All @@ -20,7 +20,7 @@
! Palau (Put on break due to too many whitelistings being needed)
!!!||pw^~libgen.pw|petridish.pw|palaugov.pw|dpc.pw|buttercup.pw|rezka.pw|darkcrystal.pw|xor.pw|fullhdfilmizlesene.pw|gopass.pw|vost.pw|core.pw|bittor.pw|plutonium.pw|nitter.pw|kge.pw
! Legitimate use is almost non-existent, but has a tiny userbase in Japan. Its extreme common-ness in malware redirections means that the entry will be kept forever.
||*.top^$denyallow=caitlin.top|corriente.top|gdtot.top|nicenature.top|reminder.top|magocoro.top|castlevania.top|suiten.top|shucks.top|1stream.top|ambr.top|techblog.top|changlam10.top|changlam11.top|pdcdn1.top|mastodon.top|pressplay.top|chillx.top|strims.top|thedesk.top|audioforyou.top|pegelinux.top|awavenue.top
||*.top^$denyallow=caitlin.top|corriente.top|gdtot.top|nicenature.top|reminder.top|magocoro.top|castlevania.top|suiten.top|shucks.top|1stream.top|ambr.top|techblog.top|changlam10.top|changlam11.top|pdcdn1.top|mastodon.top|pressplay.top|chillx.top|strims.top|thedesk.top|audioforyou.top|pegelinux.top|awavenue.top|reyhub.top
! International topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent.
||*.loan^
!!!||agency^~battlefield.agency|baam.agency|robotzebra.agency|uphotel.agency|ws.agency (Can't remember the last time I saw it used in a redirection train.)
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Title: 💊 Dandelion Sprout's Anti-Malware List (Domains list version)
# Version: 24March2024v2
# Version: 27March2024v3
# Expires: 2 days
# Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
# Note: The very limited syntax available to raw domains lists, considering it's, well, raw, means that outright anti-MV3 measures (which'd as of February 2024 only affect Minus, a project whose name is unworthy of the uBO label; AdGuard browser extensions has no relevant support for raw domains either way) cannot be done. However, at some 20,000 entries, Team Chromium's shameful leaders aren't liking this list anyway.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{+block}
# Title: 💊 Dandelion Sprout's Anti-Malware List (for Privoxy)
# Version: 24March2024v2-Deprecated
# Version: 27March2024v3-Deprecated
# Expires: 2 days
# Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.

Expand Down
3 changes: 2 additions & 1 deletion Alternate versions Anti-Malware List/AntiMalwareTPL.tpl
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
msFilterList
# Title: 💊 Dandelion Sprout's Anti-Malware List (Internet Explorer TPL)
# Version: 24March2024v2-Deprecated
# Version: 27March2024v3-Deprecated
: expires = 2 days
# Description: This list goes the extra kilometer to prevent more malware than other mainstream anti-malware lists. It blocks heavily abused top-level domains (and even search engine results for them), blocks domains used in malware redirection trains and in domain parking schemes, blocks sponsored Windows PUP nags on PC guide articles, uses mass blocking of domains belonging to bad IPs, and has many other subcategories that give it a solid advantage over similar lists out there.
# For other security-specific lists I've made, check out https://github.com/DandelionSprout/adfilt/tree/master/Special%20security%20lists
Expand Down Expand Up @@ -95,6 +95,7 @@ msFilterList
+d audioforyou.top
+d pegelinux.top
+d awavenue.top
+d reyhub.top
# International topical domains that have consistently horrendous scores on watchlists of bad TLDs, and whose use for legit purposes is practically non-existent.

!!!||agency
Expand Down

0 comments on commit 24d8307

Please sign in to comment.