GithubHelp home page GithubHelp logo

mitchellkrogza / the-big-list-of-hacked-malware-web-sites Goto Github PK

View Code? Open in Web Editor NEW
249.0 21.0 86.0 286.68 MB

This repository contains a list of all web sites I come across that are either hacked with or purposefully hosting malware, ransomware, viruses or trojans.

License: Other

Shell 99.93% Roff 0.07%
malware ransomware trojans viruses website clickjacking porn wannacry cybersecurity cyber-security

the-big-list-of-hacked-malware-web-sites's Introduction

The Big List of Hacked Malware Web Sites

Big List of Hacked, Suspicious or Bad Web Sites and Domains Containing Malware, Ransomware, Trojans or VirusesBuild StatusDUBGitHub StatsFollow @ubuntu101za

This repository contains a list of all web sites I come across that are hacked with malware, ransomware or trojans. Most site owners are unaware their sites have been hacked and are being used to plant malware.

DO NOT CLICK ON OR VISIT ANY OF THE SITES LISTED HERE


VERSION

Bad Site Count: 8740

# Generated by PyFunceble (v3.3.9.) / https://git.io/vpZoI
# Date of generation: 2021-01-31T17:33:39.007684

Status      Percentage   Numbers     
----------- ------------ ------------
ACTIVE      3%           9           
INACTIVE    95%          254         
INVALID     0%           2           

Some of the sites on the list are purposefully planting malware on their sites and luring people to click links in emails or social links. Some sites are merely wordpress sites that have been hacked and could contain malware.

Unfortunately to protect the public I have decided to start posting each and every one I find in this list.

DO NOT CLICK ON OR VISIT ANY OF THE SITES LISTED HERE

This is merely for information purposes only !!

I will not be held responsible if you decided to click on one of these links and get your computer infected with malware, ransomware a virus or a trojan.


If you find your domain name or web site in this list

Your web site has been compromised / hacked and is being used to push out malware to unsuspecting internet users or to redirect users to another web site with malware, ransomware, pornography or other unsavoury things, OR your web site is listed here because you are actually purposefully hosting a web site with malware, viruses, ransomware or trojans.

All listings on this list are shown with the complete url and files that have been planted and are being used to push out malware or redirect visitors to your site to a completely different web site.

This will help you and your web designer in being able to look for these files, delete them and then look further into your web site directories and sub-directories for other deceptive files that have been planted by hackers.

Help me out with a mug of beer or Help me feed my cat


Get your web site fixed or cleaned

Contact me for help or someone else who can help you clean up and secure your web site.

The list shows which files have been planted on your site so it makes it easier for you to look for them and clean your site.

Simply deleting those malware files is not enough you have to find out from an expert how they got into your web site in the first place because if you do not fix that problem they will be back and you also have no idea what else they have planted inside directories or sub-directories on your web site.


My web site has been fixed please remove my site !!

Log an Issue or send a PULL REQUEST on this file the hacked-malware-websites.txt file removing all entries related to your domain(s).

Once I confirm your site is clean and safe it will be removed.


Did you score a job from this?

If you are a web designer or specialize in Internet security and securing web sites and you scored yourself some work by contacting a site owner listed here then show some love and appreciation and help me out with a donation, no matter how small every cent counts.

Buy me Coffee


Stop Bad Bot and Bad Referrers from gaining access to your web sites.

  • Check Out The Amazing

NGINX ULTIMATE BAD BOT BLOCKER or Get the APACHE ULTIMATE BAD BOT BLOCKER


DO NOT CLICK ON OR VISIT ANY OF THE SITES LISTED HERE

This is merely for information purposes only !!

I will not be held responsible if you decided to click on one of these links and get your computer infected with malware, ransomware a virus or a trojan.


Contributors


Some other awesome free projects


Support this Project

Help me out with a mug of beer or Help me feed my cat


Into Photography?

Come drop by and visit me at https://mitchellkrog.com

the-big-list-of-hacked-malware-web-sites's People

Contributors

ameshkov avatar d-alleyne avatar funilrys avatar mitchellkrogza avatar pascalhamel avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

the-big-list-of-hacked-malware-web-sites's Issues

bit.ly

This domain is a URL shortener and is not malicious

Can i use hacked domain sites to block in host file

Thanks for collections of hacked domain site lists.
Sir just now i downloaded the hacked domain list and i opened in notepad, i seen many sites, but i want to all those hacked domain site names in HOST file in windows computer.

I Eagerly waiting for your reply sir.

Botnet domains/IP

Have spot a report of a botnet - with listing nodes and IP's. Perhaps that is worthy an addition. I post the content i found - with brackets [] !

Case 1=

This are nodes of a wide spread link relaying/spam/phishing sending botnet which makes use of a generic start-bootstrap design (with a Laptop) - Example screenshot for node design done with Urlscan tracing tool=

https://urlscan.io/screenshots/93ada930-f663-4574-874f-f929047ba6cc.png

Nodes are either used for spam link sharing or abuse sending. Link relaying function works over scripting (r.php + parameters). Nodes are also using Namecheap domains!

Example parameter - valid for single access so we add them just for explanatory reasons=
r.php?t=c&d=20107&l=264&c=39072
r.php?t=o&d=20102&l=264&c=65216

Example spam link forwarding screencapture on Urlscan with one of the nodes=
https://urlscan.io/result/1bfe3598-e26f-4101-a0ff-45a8639ef045/

Final redirect goal= https://specialoffer[.]cannablisslabs[.]com/unsubscribe/?s1=20&s2=31027&s3=748&s4=62043

Active nodes - Digital Ocean=

167[.]71[.]94[.]158
kinda[.]press

67[.]205[.]130[.]76
classscience[.]club

104[.]248[.]11[.]231
healtbeautymale[.]xyz

159[.]89[.]86[.]21

165[.]22[.]221[.]148
fungoods[.]xyz

104[.]131[.]223[.]171
lamanovix[.]website

68[.]183[.]95[.]125
piamonfree[.]club

165[.]22[.]65[.]34
houfabia[.]club

188[.]166[.]104[.]151
askorali[.]club

159[.]65[.]218[.]178
matrixlucky[.]sytes[.]net

67[.]205[.]165[.]189
gactay[.]club

206[.]81[.]24[.]120
constitueqzs[.]loan

Active nodes - Random hosts=

93[.]118[.]34[.]205
brandingnews[.]us

185[.]173[.]178[.]4
tech98-c2[.]newtimebearth[.]press

212[.]114[.]109[.]117
starsplay[.]club

Active nodes - Aruba-IT=

94[.]177[.]246[.]26
ibismo[.]us

Active nodes - Hetzner Germany=

95[.]216[.]176[.]255
http://goldtechonline[.]xyz

116[.]203[.]198[.]230
cruiset[.]space

116[.]203[.]194[.]166
bluntt[.]fun

Active nodes - Online/Scaleway=

51[.]15[.]172[.]219
cbsnews[.]press

212[.]83[.]173[.]74
poney[.]cbsnews[.]press

212[.]83[.]184[.]240
telecom[.]cbsnews[.]press

Active nodes - Selectel-RU=

79[.]143[.]30[.]36
sarrion[.]xyz

79[.]143[.]31[.]116
sauronn[.]host

IP= 31[.]184[.]254[.]112
maxvalue[.]icu

37[.]228[.]117[.]29
rainit[.]xyz

37[.]228[.]117[.]128
mrtcom[.]space

37[.]228[.]117[.]242
sidom[.]online

37[.]228[.]117[.]75
malikom[.]xyz

Active nodes - OVH=

Active nodes - Amazon=

3[.]16[.]55[.]7
hobad[.]xyz

3[.]87[.]40[.]41
champion[.]viewdns[.]net

Case2=

Report for nodes of a wide spread link relaying/spam/phishing sending botnet which makes use of a generic clone design - Example screenshot for node design

https://urlscan.io/thumbs/727b47e9-245b-4878-b120-1f59d4849431.png

Nodes are either used for spam link sharing or abuse sending. Link relaying function works over scripting (s.php + parameters). Nodes are also using Namecheap domains!

Example parameter - added them for explanatory reasons=
s.php?935291_0_30169_a1b2c3d4e5
s.php?929989_0_30298_a1b2c3d4e5

Spot Active nodes=

109[.]238[.]14[.]205
resolving domain= http://groete[.]org

65[.]19[.]158[.]10 - resolving domain= http://abadiarith[.]com
https://www[.]spamhaus[.]org/query/ip/65[.]19[.]158[.]10

185[.]103[.]196[.]107 - resolving domain= http://wisby[.]org

185[.]98[.]63[.]84 - resolving domain= http://unflecked[.]com
https://www[.]spamhaus[.]org/query/ip/185[.]98[.]63[.]84

185[.]93[.]71[.]112 - resolving domain= http://ganoblast[.]com
https://www[.]spamhaus[.]org/query/ip/185[.]93[.]71[.]112

89[.]42[.]31[.]178 - resolving domain= http://unsooty[.]com
https://www[.]spamhaus[.]org/query/ip/89[.]42[.]31[.]178

65[.]19[.]158[.]10 - resolving domain= http://abadiarith[.]com
https://www[.]spamhaus[.]org/query/ip/65[.]19[.]158[.]10

000webhostapp.com

You should take a look at this domain, as my pyf test via http returns all of them as FP (http code 410)

And manually checking some of them, shows this site

image
So it looks like they have learned there lesson, and actively doing something about these malwares they was hosting.

ps you have ~8931 of these records....

1drv.ms

This is a short URL for Microsoft's OneDrive, resulting in a onedrive.live.com URL when followed. Please remove.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.