
destroylist archives
Echtzeit-Blocklist für Phishing- und Betrugsdomains - 208k+ kuratierte Bedrohungen, 1M+ Community, kostenlose API, mehrere Formate
Destroylist: Blacklist für Phishing- & Scam-Domains
Schnellstart
Mit einem Klick zu Pi-hole oder AdGuard Home hinzufügen — fügen Sie diese URL in Ihre Blocklisten-Einstellungen ein:``` https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/hosts.txt
> **Der CDN-Link oben wird empfohlen** — bereitgestellt über das globale jsDelivr-CDN, ohne Ratenlimits.
> Raw-GitHub-Spiegel (kann bei starkem Traffic 429 zurückgeben): `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt`
> Weitere Formate: [Hosts](#-data-feeds) · [AdBlock](#-data-feeds) · [Dnsmasq](#-data-feeds) · [Unbound](#-data-feeds) · [RPZ](#-data-feeds) · [API](#-threat-intelligence-api)
<img src="https://assets.kitploit.com/production/public/readmes/9225/66755568f640f93051ca779dd85131a85bc03d6385f7c57bdaaf388de6854fbc.gif" width="100%">
## <img src="https://assets.kitploit.com/production/public/readmes/9225/375391e605e2336c5dda1b81c5194a94a192db9a096cf46c24c52a389dbd4d16.png" alt="Hochspannung" width="22" height="22" /> Schnellzugriff
<details>
<summary><b>Inhaltsverzeichnis</b></summary>
- [Schnellstart](#-quick-start)
- [Live-Statistiken](#live-statistics)
- [Daten-Feeds](#-data-feeds)
- [Root-Listen](#-root-lists)
- [Inhaltsverifizierte Feeds](#-content-verified-feeds-)
- [Threat-Intelligence-API](#-threat-intelligence-api)
- [Über Destroylist](#-about-destroylist)
- [Workflow & Behebung](#-threat-intelligence--automated-remediation-workflow)
- [Info für Betrugsopfer](#-key-info-for-online-fraud-victims)
- [Einspruchsverfahren](#-appeals-process)
- [Kontakt](#-connect-with-us)
- [Machen Sie mit](#-join-the-fight)
</details>
### Live-Statistiken
| Primary | Primary Live | Community | Community Live |
|:-------:|:------------:|:---------:|:--------------:|
|  |  |  |  |
| Primary Content | Community Content |
|:---------------:|:-----------------:|
|  |  |
| | Heute | Woche | Monat |
|:--|:-----:|:----:|:-----:|
| **Primary** |  |  |  |
| **Community** |  |  |  |
### <img src="https://assets.kitploit.com/production/public/readmes/9225/bb78fad734ffe1195b52ffbea506a7954009d8b8d2124a6f8c076aeedb2c5d84.png" alt="Dateiordner" width="22" height="22" /> Daten-Feeds
| Feed | Beschreibung | Update | Download |
|:-----|:------------|:------:|:--------:|
| **Primary** | Kuratierte Phishing-Domains | ⚡ Echtzeit | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.txt) |
| **Primary Live** | DNS-verifiziert aktiv | 🕐 24h | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/dns/active_domains.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/dns/active_domains.txt) |
| **Community** | Aus 13+ Quellen aggregiert | 🕐 2h | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/blocklist.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/blocklist.txt) |
| **Community Live** | Per Community-DNS verifiziert | 🕐 24h | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/live_blocklist.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/live_blocklist.txt) |
| **Primary Content** | Kuratiert + HTTP-Inhalt verifiziert | 🕐 12h | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/dns/content_active.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/dns/content_active.txt) |
| **Community Content** | Aggregiert + HTTP-Inhalt verifiziert | 🕐 24h | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/content_live.json) [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/community/content_live.txt) |
| **Allowlist** | Schutz vor Falschpositiven | ✋ Manuell | [](https://raw.githubusercontent.com/phishdestroy/destroylist/main/allow/allowlist.json) |
> [!TIP]
> **Produktion:** `list.json` oder `active_domains.json` · **Maximale Abdeckung:** `blocklist.json` · **Firewall/DNS:** Root-Listen
<details>
<summary>📁 <b>Alle Download-Formate</b> (TXT, Hosts, AdBlock, Dnsmasq, Unbound, RPZ)</summary>
<br>
> **Erhalten Sie 429-Fehler?** Verwenden Sie die jsDelivr-CDN-Links unten — sie umgehen die GitHub-Ratenlimits.
**Über jsDelivr CDN (empfohlen, keine Ratenlimits):**
| Format | Primary | Primary Live | Community | Community Live |
|:------:|:-------:|:------------:|:---------:|:--------------:|
| **TXT** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/domains.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/domains.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/domains.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/domains.txt) |
| **Hosts** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/hosts.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/hosts.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/hosts.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/hosts.txt) |
| **AdBlock** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/adblock.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/adblock.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/adblock.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/adblock.txt) |
| **Dnsmasq** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/dnsmasq.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/dnsmasq.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/dnsmasq.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/dnsmasq.conf) |
| **Unbound** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/unbound.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/unbound.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/unbound.conf) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/unbound.conf) |
| **RPZ** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/rpz.zone) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/rpz.zone) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/rpz.zone) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/rpz.zone) |
| **Redis** | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/redis.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary_active/redis.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community/redis.txt) | [⬇️](https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/community_active/redis.txt) |
> **Redis-Einzeiler** — lädt die vollständige Liste in ein Redis-Set (atomarer Austausch, Neuladen ohne Ausfallzeiten):
> ```
> curl -s https://cdn.jsdelivr.net/gh/phishdestroy/destroylist@main/rootlist/formats/primary/redis.txt | redis-cli --pipe
> ```
> Prüfen Sie dann jede Domain in O(1): `SISMEMBER destroylist:primary evil-domain.com`
<details>
<summary>Über raw.githubusercontent.com (kann bei starkem Traffic 429 zurückgeben)</summary>
| Format | Primary | Primary Live | Community | Community Live |
|:------:|:-------:|:------------:|:---------:|:--------------:|
| **TXT** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/domains.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/domains.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/domains.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/domains.txt) |
| **Hosts** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/hosts.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/hosts.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/hosts.txt) |
| **AdBlock** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/adblock.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/adblock.txt) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/adblock.txt) |
| **Dnsmasq** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/dnsmasq.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/dnsmasq.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/dnsmasq.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/dnsmasq.conf) |
| **Unbound** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/unbound.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/unbound.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/unbound.conf) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/unbound.conf) |
| **RPZ** | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/rpz.zone) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/rpz.zone) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/rpz.zone) | [⬇️](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/rpz.zone) |
</details>
> **Hosts** → Pi-hole, /etc/hosts, Windows · **AdBlock** → uBlock Origin, AdGuard · **Dnsmasq** → dnsmasq DNS · **Unbound** → pfSense, OPNsense · **RPZ** → BIND, Knot DNS · **Redis** → Massenimport per `redis-cli --pipe`
</details>
### <img src="https://assets.kitploit.com/production/public/readmes/9225/ce7d7fb4a40580532e4e27b60c441010f36f8f671cdfbb5e988e1258bd2c2bc5.png" alt="Laptop" width="22" height="22" /> Root-Listen
> [!TIP]
> **Nur Root-Domains** — keine Subdomains, Hosting-Anbieter ausgeschlossen
| | Alle Roots | Nur Live | Nur Dienste |
|:--|:-:|:-:|:-:|
| 🔴 **Primary** | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/active_root_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/active_root_domains.txt) | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/online_root_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/online_root_domains.txt) | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/services_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/services_domains.txt) |
| ⚫ **Community** | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_root_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_root_domains.txt) | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_online_root_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_online_root_domains.txt) | [JSON](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_services_domains.json) · [TXT](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/community_services_domains.txt) |
> **Alle Roots** — saubere Root-Domains (ohne Infrastruktur) · **Nur Live** — DNS-verifiziert aktiv · **Nur Dienste** — Subdomains von Hosting-Plattformen (Vercel, Pages.dev, Netlify usw.)
<img src="https://assets.kitploit.com/production/public/readmes/9225/66755568f640f93051ca779dd85131a85bc03d6385f7c57bdaaf388de6854fbc.gif" width="100%">
## <img src="https://assets.kitploit.com/production/public/readmes/9225/b6a803f28233508a8d026ca7dbf00c61ac4e5d863de24a7b164bc348c079cef8.webp" width="25" /> Inhaltsverifizierte Feeds <img src="https://assets.kitploit.com/production/public/readmes/9225/f9508aaeba939041deccda3064343b9e328d5722aac996f0efb873b9fc4885e4.webp" width="25" />
> [!NOTE]
> **Echte HTTP-Inhaltsverifizierung** — nicht nur DNS, sondern tatsächliche Erkennung von Phishing-Seiten
[](https://github.com/phishdestroy/destroylist/raw/main/dns/content_active.json)
[](https://github.com/phishdestroy/destroylist/raw/main/community/content_live.json)
| Feed | Update | Beschreibung |
|:-----|:------:|:------------|
| **Primary Content** | `12h` (06:00 / 18:00 UTC) | Kuratierte Phishing-Domains mit verifiziertem aktivem Inhalt |
| **Community Content** | `24h` (03:00 UTC) | Aggregierte Feeds mit verifiziertem aktivem Inhalt |
> Download-Links: siehe [Daten-Feeds](#-data-feeds) oben
> [!WARNING]
> **Cloaking-Warnung:** Betrüger nutzen Cloaking, um Phishing vor Bots zu verbergen — sie zeigen Scannern leere/gefälschte Seiten. Domain **NICHT** in der Inhaltsliste ≠ sicher! Nutzen Sie für umfassenden Schutz die vollständigen **Primary**- oder **Community**-Listen.
<img src="https://assets.kitploit.com/production/public/readmes/9225/66755568f640f93051ca779dd85131a85bc03d6385f7c57bdaaf388de6854fbc.gif" width="100%">
## <img src="https://assets.kitploit.com/production/public/readmes/9225/8473e35500f4880a4b221b0e6b9e0232c4cd8b95dd3e0e87c47b8d1d8456935f.webp" alt="Alien-Monster" width="25" height="25" /> Threat-Intelligence-API
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/9225/708e69fca236d3f5355650687e220e2d365289b763ddf4dadea90d99e53ec691.png" alt="API" width="700"/>
</p>```mermaid
%%{init: {"theme":"base", "themeVariables": { "background": "transparent", "mainBkg": "#000000", "primaryColor": "#000000", "primaryTextColor": "#FFFFFF", "primaryBorderColor": "#FF0000", "lineColor": "#FF0000", "secondaryColor": "#111111", "tertiaryColor": "#111111", "fontFamily": "Inter, system-ui, sans-serif"}, "flowchart": {"curve": "basis", "htmlLabels": true}}}%%
flowchart LR
Request["🌐 Client Request<br/>(Single / Bulk)"] e1@--> API["⚡ Live API<br/>api.destroy.tools"]
API e2@--> Engine["🧠 Threat Engine<br/>(Risk Score 0-100)"]
Engine e3@--> DB[("🗄️ Destroylist DB<br/>1M+ Threats")]
DB e4@--> Engine
Engine e5@--> Response["📋 JSON Response<br/>(Severity & Status)"]
classDef client fill:#000000,stroke:#333333,stroke-width:2px,color:#FFFFFF;
classDef api fill:#000000,stroke:#FF0000,stroke-width:2px,color:#FFFFFF;
classDef db fill:#000000,stroke:#333333,stroke-width:2px,stroke-dasharray: 5 5,color:#FFFFFF;
classDef animate stroke:#FF0000,stroke-width:2px,stroke-dasharray:10 5,stroke-dashoffset:900,animation:dash 22s linear infinite;
classDef animateDark stroke:#333333,stroke-width:2px,stroke-dasharray:10 5,stroke-dashoffset:900,animation:dash 22s linear infinite;
class Request client;
class API,Engine,Response api;
class DB db;
class e1,e2,e3,e5 animate;
class e4 animateDark;
Kostenlos, offen, ohne API-Schlüssel. Echtzeit-Domain-Risiko-Scoring (0-100) für 888K+ Bedrohungen · 2h-Sync · Einzel- & Massenprüfung (500/Anfrage) · Stichwortsuche · Vollständige Feeds
📖 API-Endpunkte, Scoring & Integrationsbeispiele
Endpunkte
| Methode | Endpunkt | Beschreibung |
|---|---|---|
GET | /v1/check?domain= | Einzelne Domain-Prüfung mit Risiko-Score & Schweregrad |
POST | /v1/check/bulk | Massenprüfung von bis zu 500 Domains pro Anfrage |
GET | /v1/search?q= | Durchsuche Domains auf der Blockliste nach Stichwort |
GET | /v1/feed/{list} | Vollständige Domain-Feeds herunterladen (primär, Community, aktiv) |
GET | /v1/stats | Live-Statistiken & Domain-Anzahl |
Bedrohungs-Scoring
Jede Domain erhält einen Risiko-Score (0-100) auf Basis mehrerer Signale:
| Signal | Punkte | Beschreibung |
|---|---|---|
| Kuratierte Blocklist | +40 | In primärer Destroylist |
| Von der Community gemeldet | +20 | Von Community-Quellen gemeldet |
| DNS aktiv | +30 | Domain wird derzeit aufgelöst |
| Mehrere Quellen | +10 | Durch mehrere Feeds bestätigt |
| Verdächtige Stichwörter | +5 je | metamask, wallet, airdrop, usw. |
| Riskante TLD | +5 | .xyz, .top, .club, .icu, usw. |
🔴 Kritisch 70-100 · 🟠 Hoch 40-69 · 🟡 Mittel 20-39 · 🟢 Niedrig 1-19
Schnelle Integration
cURL```bash curl "https://api.destroy.tools/v1/check?domain=suspicious-site.xyz"
**Python**```python
import requests
r = requests.get(f"https://api.destroy.tools/v1/check?domain={domain}")
if r.json()["threat"]:
print(f"BLOCKED: {r.json()['severity']} (score: {r.json()['risk_score']})")
JavaScript```javascript
const r = await fetch(https://api.destroy.tools/v1/check?domain=${domain});
const data = await r.json();
if (data.threat) console.warn("PHISHING:", data.severity, data.risk_score);
**Massenprüfung**```bash
curl -X POST "https://api.destroy.tools/v1/check/bulk" \
-H "Content-Type: application/json" \
-d '{"domains":["site1.com","site2.xyz","site3.top"]}'
Über Destroylist
[!NOTE] Die Live-Datenerfassung begann am 1. Juli 2025
888K+ verfolgte Domains · 13+ Bedrohungsquellen · 50+ Anbieterberichte · 6 Ausgabeformate · Kostenlose API
Destroylist ist eine Echtzeit-Bedrohungsintelligenz-Plattform von PhishDestroy – die Firewalls, DNS-Resolver, Browsererweiterungen und Sicherheitsteams weltweit schützt. Jede Domain wird entdeckt, verifiziert, den Registraren gemeldet und transparent veröffentlicht.
Daten-Pipeline```mermaid
%%{init: {"theme":"base", "themeVariables": { "background": "transparent", "mainBkg": "#000000", "primaryColor": "#000000", "primaryTextColor": "#FFFFFF", "primaryBorderColor": "#FF0000", "lineColor": "#FF0000", "secondaryColor": "#111111", "tertiaryColor": "#111111", "fontFamily": "Inter, system-ui, sans-serif"}, "flowchart": {"curve": "basis", "htmlLabels": true}}}%% flowchart TB subgraph Sources["🔍 Threat Sources"] S1[30+ Parsers] S2[Community Feeds] S3[Telegram Bot] S4[CT Logs / DNS] end
subgraph Ingestion["📥 Ingestion"] I1[smart_aggregator.py] I2[validate_and_clean.py] end
subgraph Enrichment["🧠 Enrichment"] E1[DNS Validation] E2[HTTP Content Check] E3[VirusTotal / GSB] end
subgraph Distribution["📡 Distribution"] D1[JSON / TXT] D2[Hosts / AdBlock] D3[RPZ / Unbound] D4[API Feed] end
Sources --> Ingestion Ingestion --> Enrichment Enrichment --> Distribution
classDef source fill:#000000,stroke:#333333,stroke-width:2px,color:#FFFFFF; classDef ingest fill:#000000,stroke:#FF0000,stroke-width:2px,color:#FFFFFF; classDef enrich fill:#000000,stroke:#CC0000,stroke-width:2px,color:#FFFFFF; classDef dist fill:#000000,stroke:#FF0000,stroke-width:2px,stroke-dasharray: 5 5,color:#FFFFFF;
class S1,S2,S3,S4 source; class I1,I2 ingest; class E1,E2,E3 enrich; class D1,D2,D3,D4 dist;
<details>
<summary>🔧 <b>Schnelle Integrationsbeispiele</b> (Abonnement-URLs · curl · Python · Bash)</summary>
<br>
### Ein-Klick-Abonnement-URLs
| Tool | Format | URL |
|:-----|:------:|:----|
| **Pi-hole** | Hosts | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt` |
| **AdGuard Home** | AdBlock | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt` |
| **uBlock Origin** | AdBlock | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt` |
| **pfSense / OPNsense (Unbound)** | Unbound | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/unbound.conf` |
| **BIND / Knot DNS (RPZ)** | RPZ | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/rpz.zone` |
| **Dnsmasq** | Dnsmasq | `https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/dnsmasq.conf` |
> **Pi-hole** — Einstellungen > Blocklisten > Hosts-URL einfügen<br>
> **AdGuard Home** — Filter > DNS-Blocklisten > Blockliste hinzufügen > AdBlock-URL einfügen<br>
> **uBlock Origin** — Einstellungen > Filterlisten > Importieren > AdBlock-URL einfügen<br>
> **pfSense** — Dienste > DNS-Resolver > Unbound-URL einfügen<br>
> **BIND/Knot** — RPZ-URL als Response-Policy-Zone hinzufügen
### curl-Einzeiler```bash
# Plain domain list
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/domains.txt -o domains.txt
# Hosts format (Pi-hole, /etc/hosts)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt -o hosts_blocklist.txt
# AdBlock format (uBlock Origin, AdGuard)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt -o adblock.txt
# Dnsmasq
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/dnsmasq.conf -o dnsmasq_blocklist.conf
# Unbound (pfSense / OPNsense)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/unbound.conf -o unbound_blocklist.conf
# RPZ (BIND / Knot)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/rpz.zone -o rpz_blocklist.zone
Python```python
import requests blocklist = requests.get('https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.json').json() is_malicious = "suspicious-domain.com" in blocklist
### Bash```bash
curl -s https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.txt | grep -q "suspicious-domain.com" && echo "BLOCKED"
Threat Intelligence & automatisierter Remediation-Workflow```mermaid
%%{init: {"theme":"base", "themeVariables": { "background": "transparent", "mainBkg": "#000000", "primaryColor": "#000000", "primaryTextColor": "#FFFFFF", "primaryBorderColor": "#FF0000", "lineColor": "#FF0000", "secondaryColor": "#111111", "tertiaryColor": "#111111", "fontFamily": "Inter, system-ui, sans-serif"}, "flowchart": {"curve": "basis", "htmlLabels": true}}}%%
flowchart LR
Discover["🔍 DISCOVER
30+ Parsers"] e1@--> Report["📤 REPORT
50+ Vendors"]
Report e2@--> Legal["⚖️ LEGAL
ICANN Compliance"]
Legal e3@--> Publish["📡 PUBLISH
Real-time Feed"]
classDef box fill:#000000,stroke:#333333,stroke-width:2px,color:#FFFFFF; classDef animate stroke:#FF0000,stroke-width:2px,stroke-dasharray:10 5,stroke-dashoffset:900,animation:dash 22s linear infinite;
class Discover,Report,Legal,Publish box;
class e1,e2,e3 animate;
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/9225/b44d5f0758cb8b29e42734f5d032478fbc6c2c1574e5c5dbc1042c5551cb60da.png" alt="Workflow" width="700"/>
</p>
<div align="center">
| 🔍 **ENTDECKEN** | 📤 **MELDEN** | ⚖️ **RECHTLICH** | 📡 **VERÖFFENTLICHEN** |
|:---:|:---:|:---:|:---:|
| 30+ Parser | 50+ Anbieter | ICANN-Konformität | Echtzeit |
| CT-Logs, DNS | Google, Microsoft | Missbrauchsmeldungen | GitHub, Telegram |
| Soziale Medien | VirusTotal, Cloudflare | Beweispakete | Twitter, Mastodon |
</div>
<details>
<summary>📖 <b>Vollständige Workflow-Details lesen</b></summary>
<br>
### 🔍 Phase 1: Präventive Erkennung & Aufnahme
🔎 Wir nutzen ein verteiltes Netzwerk aus **30+ proprietären Parsern**, um bösartige Domains bereits im frühesten Stadium zu identifizieren:
- **Erweiterte Heuristiken:** Kontinuierliche Überwachung von Google Ads (Malvertising), SEO-manipulierten Suchergebnissen und angesagten Social-Media-Kampagnen auf Twitter (X), YouTube und Telegram
- **Infrastrukturanalyse:** Einsatz von *dnstwist* und Typosquatting-Erkennung, um ähnlich aussehende Domains zu erkennen, die etablierte Marken imitieren
- **Community-Intelligenz:** Echtzeit-Aufnahme von von der Community gemeldeten Bedrohungen über unseren Telegram-Bot und Partner-Intelligence-Feeds
---
### 📤 Phase 2: Beitrag zum globalen Ökosystem
Sobald eine Bedrohung bestätigt ist, übermitteln wir Daten an über **50 branchenführende Anbieter**:```
Cloudflare Google Safe Browsing Microsoft Security VirusTotal
Netcraft ESET Bitdefender Norton Safe Web
Avira PhishTank Dr.Web Yandex Safe Browsing
URLScan.io PolySwarm SiteReview Urlquery
PhishStats PhishReport IsItPhish ThreatCenter
📝 Phase 3: Rechtliche Benachrichtigungen & Ermittlungsunterstützung
- Missbrauchsmeldungen: Formelle Benachrichtigungen an Domain-Registrare und Hosting-Anbieter
- Forensische Beweisoffenlegung: Vollständige Beweispakete inklusive Metadaten, Screenshots und PDF-Berichte
- ICANN-Compliance-Unterstützung: Berichte im Einklang mit ICANN-Standards
- Bedingte Wiedererkennungslogik: Folge-Warnungen nur, wenn die Bedrohung länger als 24 Stunden aktiv bleibt
📢 Phase 4: Öffentliche Transparenz & Community-Warnungen
- Offene Datenbank: Echtzeit-Commits in dieses GitHub-Repository
- Live-Überwachung: Visuelle Informationen unter phishdestroy.io/live
- Social-Media-Verbreitung: Automatisierte Warnungen auf Twitter, Telegram und Mastodon
Wichtige Informationen für Online-Betrugsopfer
Details zu Beschwerden und Transparenz anzeigen
💼 DestroyList zielt darauf ab, bösartige Domains zu deaktivieren: Betrugsseiten, Phishing und andere illegale Websites, um die Internetsicherheit zu erhöhen.
Bevor eine Domain hinzugefügt wird, führen wir Folgendes durch:
🔍 Wir scannen sie mithilfe von Cybersicherheitsplattformen auf Threat Intelligence.
📥 Wir senden eine offizielle Beschwerde an den Registrar und den Hosting-Anbieter (über WHOIS), einschließlich Scan-Ergebnissen, Screenshots und einer Aufforderung zur Untersuchung im Auftrag des Kunden. Die Beschwerde informiert sie außerdem über die Aufnahme in unsere öffentliche Datenbank.
🚔 Gemäß den ICANN-Regeln müssen Registrare solche Beschwerden innerhalb von 24 Stunden prüfen.
🦖 Wir arbeiten hart daran, Bedrohungen schnell zu beseitigen. Jede bösartige Domain wird transparent analysiert, dokumentiert, gemeldet und veröffentlicht.
Wenn eine Domain jedoch 10–30+ Missbrauchsmeldungen erhält und ein Registrar diese monatelang weiterhin ignoriert, ändert sich die Situation: Der Registrar ist keine passive Partei mehr. Er stellt effektiv Infrastruktur für illegale Aktivitäten bereit.
Manche Registrare verhalten sich so, als würden ihre internen Richtlinien die ICANN-Anforderungen und nationale Gesetze irgendwie außer Kraft setzen – als wären Phishing und Betrug „erlaubt“, solange sie persönlich entscheiden, nicht zu handeln.
👮 Wir dokumentieren dies öffentlich, damit jeder sehen kann: Bedrohungen bestehen fort, nicht weil sie unbemerkt blieben, sondern weil die verantwortlichen Anbieter schlicht beschlossen haben, nichts zu unternehmen.
Anfragen von Privatpersonen:
DestroyList ist ein Open-Source-, nichtkommerzielles Freiwilligenprojekt.
Privatpersonen können die Anzahl der Missbrauchsmeldungen anfragen, die wir für eine bestimmte Domain gesendet haben, jedoch nur über öffentliche Kanäle:
- über GitHub Issues
- über den Commit-Verlauf: https://github.com/phishdestroy/destroylist/commits/main/
❗ Wir antworten nicht auf private E-Mail-Anfragen von Einzelpersonen bezüglich der Anzahl der Meldungen.
✔️ Dies ist eine rechtliche Anforderung für Transparenz und gleichberechtigten Zugang zu Informationen.
Offizielle Anfragen von Regierungs- oder Strafverfolgungsbehörden können privat beantwortet werden.
💔 Wenn du durch eine hier bereits gelistete Domain betrogen wurdest, prüfe deren Aufnahmedatum über den Commit-Verlauf oder über unsere Telegram-/Mastodon-Kanäle.
💬 Wenn der Betrug stattfand, nachdem die Domain bereits gelistet war, kann die Verzögerung des Registrars oder Hosts darauf hindeuten, dass diese eine Mitschuld am Verlust tragen. Auch zukünftige potenzielle Opfer können diese Nachlässigkeit öffentlich dokumentiert sehen.
🔞 Von Registraren und Hosts, die Betrugsoperationen tolerieren, kann vernünftigerweise erwartet werden, dass sie Opfern oder deren Rechtsvertretern helfen.
Anwendungsfälle & Historisches Archiv
Netzwerksicherheit · Bedrohungsforschung · KI/ML-Training · Trendanalyse · Automatisierung
Point-in-time-Verlauf – jeder Zustand der Liste ist rekonstruierbar:
| Granularität | Wo | Aufbewahrung |
|---|---|---|
| Jede Änderung | Commit-Verlauf | Für immer (41.000+ Commits) |
| Tägliche Diff-Listen (hinzugefügt/entfernt) | changes/ | Für immer, durchsuchbar in der GitHub-Codesuche |
| Wöchentliche & monatliche Vollschnappschüsse | archives/ → Release-Assets | Neuere im Repository, ältere in das permanente Release ausgelagert |
[!TIP] 📩 Historisches Archiv (500.000+ Domains, 5+ Jahre archiviert): [email protected]
Widerspruchsverfahren
Falsch gelistet? Behebe es schnell:
- ✔️ Widerspruchsformular – schnellste Option
- ✔️ GitHub Issue mit Nachweisen
Genauigkeit zuerst! 🔭
Kontaktiere uns
👾 Pac-Man-Beitragsgraph
🔗 Verwandte Ermittlungen & Repositories
| Repository | Beschreibung |
|---|---|
| namesilo-evidence | Beweisarchiv – Untersuchung des NameSilo-Registrar-Missbrauchs |
| nicenic-evidence | Beweisarchiv – Untersuchung des NiceNIC-Registrar-Missbrauchs |
| trustname-evidence | Beweisarchiv – Untersuchung des TrustName-Registrar-Missbrauchs |
| ScamIntelLogs | Rohe Betrugs-Intelligence-Logs und IOC-Daten |
| DestroyScammers | Operationen zur Entlarvung und Störung von Betrügern |
📄 Lizenz
MIT – Frei, offen, ganz deins!
Mach mit!
Wir freuen uns über Beiträge:
- 🔍 Aktuelle Threat-Intelligence & neue Blocklisten-Quellen
- 💡 Verbesserungen der Erkennungsalgorithmen
- 📢 Integrationsanleitungen für neue Plattformen
- 🌐 Übersetzungen & Dokumentation
Eröffne ein Issue oder PR – lass uns Phishing gemeinsam zerschlagen! 💪