threat-intelligence auto-update

This commit is contained in:
Zelo72 2021-10-22 13:31:10 +02:00
parent 2fc64fdb98
commit 28db6d53f0
2 changed files with 95 additions and 714 deletions

File diff suppressed because it is too large Load Diff

View File

@ -32,39 +32,39 @@ Initialize ...
2 | 413 | hosts | http | online | unchanged | https://curben.gitlab.io/malware-filter/pup-filter-hosts.txt
3 | 8622 | hosts | http | online | unchanged | https://curben.gitlab.io/malware-filter/urlhaus-filter-hosts.txt
4 | 3496 | hosts | http | online | unchanged | https://gitlab.com/ZeroDot1/CoinBlockerLists/raw/master/hosts_browser
5 | 33535 | hosts | http | online | changed | https://hole.cert.pl/domains/domains_hosts.txt
5 | 33566 | hosts | http | online | changed | https://hole.cert.pl/domains/domains_hosts.txt
6 | 550 | hosts | http | online | unchanged | https://paulgb.github.io/BarbBlock/blacklists/hosts-file.txt
7 | 5997 | hosts | http | online | changed | https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/AntiMalwareHosts.txt
7 | 5997 | hosts | http | online | unchanged | https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/AntiMalwareHosts.txt
8 | 2204 | hosts | http | online | unchanged | https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Risk/hosts
9 | 59 | hosts | http | online | unchanged | https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Spam/hosts
10 | 54 | hosts | http | online | changed | https://raw.githubusercontent.com/davidonzo/Threat-Intel/master/lists/latestdomains.piHole.txt
11 | 1047 | hosts | http | online | changed | https://raw.githubusercontent.com/durablenapkin/scamblocklist/master/hosts.txt
10 | 54 | hosts | http | online | unchanged | https://raw.githubusercontent.com/davidonzo/Threat-Intel/master/lists/latestdomains.piHole.txt
11 | 1047 | hosts | http | online | unchanged | https://raw.githubusercontent.com/durablenapkin/scamblocklist/master/hosts.txt
12 | 8624 | hosts | http | online | unchanged | https://raw.githubusercontent.com/guardicore/labs_campaigns/master/Autodiscover/autodiscover-tlds.txt
13 | 695 | hosts | http | online | unchanged | https://raw.githubusercontent.com/hoshsadiq/adblock-nocoin-list/master/hosts.txt
14 | 3622 | hosts | http | online | unchanged | https://raw.githubusercontent.com/infinitytec/blocklists/master/scams-and-phishing.txt
15 | 1072 | hosts | http | online | unchanged | https://raw.githubusercontent.com/metamask/eth-phishing-detect/master/src/hosts.txt
16 | 1386 | hosts | http | online | unchanged | https://raw.githubusercontent.com/mitchellkrogza/Badd-Boyz-Hosts/master/hosts
17 | 13465 | hosts | http | online | unchanged | https://raw.githubusercontent.com/mitchellkrogza/The-Big-List-of-Hacked-Malware-Web-Sites/master/hosts
18 | 1517 | hosts | http | online | changed | https://urlhaus.abuse.ch/downloads/hostfile/
18 | 1501 | hosts | http | online | changed | https://urlhaus.abuse.ch/downloads/hostfile/
19 | 883 | adblock | http | online | unchanged | https://raw.githubusercontent.com/piperun/iploggerfilter/master/filterlist
20 | 914 | domains | http | online | changed | https://azorult-tracker.net/api/list/domain?format=plain
21 | 122584 | domains | http | online | unchanged | https://blocklist.cyberthreatcoalition.org/vetted/domain.txt
22 | 549 | domains | http | online | unchanged | https://feeds.alphasoc.net/ryuk.txt
23 | 9233 | domains | http | online | unchanged | https://gitlab.com/KevinThomas0/cryptoscamdb-lists/-/raw/master/cryptoscamdb-blocklist.txt
24 | 365 | domains | http | online | unchanged | https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-malware.txt
25 | 33535 | domains | http | online | changed | https://hole.cert.pl/domains/domains.txt
26 | 73359 | domains | http | online | changed | https://joewein.net/dl/bl/dom-bl-base.txt
27 | 751 | domains | http | online | changed | https://joewein.net/dl/bl/dom-bl.txt
28 | 2000 | domains | http | online | changed | https://kriskintel.com/feeds/ktip_covid_domains.txt
29 | 1998 | domains | http | online | changed | https://kriskintel.com/feeds/ktip_malicious_domains.txt
25 | 33566 | domains | http | online | changed | https://hole.cert.pl/domains/domains.txt
26 | 73359 | domains | http | online | unchanged | https://joewein.net/dl/bl/dom-bl-base.txt
27 | 751 | domains | http | online | unchanged | https://joewein.net/dl/bl/dom-bl.txt
28 | 2000 | domains | http | online | unchanged | https://kriskintel.com/feeds/ktip_covid_domains.txt
29 | 1998 | domains | http | online | unchanged | https://kriskintel.com/feeds/ktip_malicious_domains.txt
30 | 397 | domains | http | online | unchanged | https://kriskintel.com/feeds/ktip_ransomware_feeds.txt
31 | 2245 | domains | http | online | unchanged | https://orca.pet/notonmyshift/domains.txt
32 | 54 | domains | http | online | changed | https://osint.digitalside.it/Threat-Intel/lists/latestdomains.txt
33 | 44764 | domains | http | online | unchanged | https://phishing.army/download/phishing_army_blocklist.txt
34 | 54398 | domains | http | online | changed | https://phishing.army/download/phishing_army_blocklist_extended.txt
32 | 54 | domains | http | online | unchanged | https://osint.digitalside.it/Threat-Intel/lists/latestdomains.txt
33 | 44761 | domains | http | online | unchanged | https://phishing.army/download/phishing_army_blocklist.txt
34 | 54398 | domains | http | online | unchanged | https://phishing.army/download/phishing_army_blocklist_extended.txt
35 | 1406 | domains | http | online | unchanged | https://raw.githubusercontent.com/AmnestyTech/investigations/master/2021-07-18_nso/domains.txt
36 | 27 | domains | http | online | unchanged | https://raw.githubusercontent.com/DRSDavidSoft/additional-hosts/master/domains/blacklist/fake-domains.txt
37 | 35258 | domains | http | online | unchanged | https://raw.githubusercontent.com/PolishFiltersTeam/KADhosts/master/KADomains.txt
37 | 35322 | domains | http | online | changed | https://raw.githubusercontent.com/PolishFiltersTeam/KADhosts/master/KADomains.txt
38 | 675 | domains | http | online | unchanged | https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Cryptocurrency
39 | 22759 | domains | http | online | unchanged | https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Malware
40 | 179 | domains | http | online | unchanged | https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Risk
@ -78,7 +78,7 @@ Initialize ...
48 | 3227 | domains | http | online | unchanged | https://raw.githubusercontent.com/iam-py-test/my_filters_001/main/Alternative%20list%20formats/antimalware_domains.txt
49 | 2079 | domains | http | online | unchanged | https://raw.githubusercontent.com/matomo-org/referrer-spam-blacklist/master/spammers.txt
50 | 71289 | domains | http | online | unchanged | https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-domains-ACTIVE.txt
51 | 421 | domains | http | online | changed | https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-domains-NEW-today.txt
51 | 421 | domains | http | online | unchanged | https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-domains-NEW-today.txt
52 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.7_5000_domain.txt
53 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.7_germany.txt
54 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.8_domains.txt
@ -105,22 +105,22 @@ Initialize ...
75 | 77 | domains | http | online | unchanged | https://www.botvrij.eu/data/ioclist.domain.raw
76 | 29 | domains | http | online | unchanged | https://www.botvrij.eu/data/ioclist.hostname.raw
77 | 35065 | domains | http | online | unchanged | https://www.stopforumspam.com/downloads/toxic_domains_whole.txt
78 | 101388 | domains | http | online | changed | https://www.usom.gov.tr/url-list.txt
78 | 101388 | domains | http | OFFLINE | unchanged | USE LOCAL COPY: usom.gov.tr_url-list.txt
79 | 27 | domains | local | online | unchanged | black.list.threat-intelligence
# Build threat-intelligence Domainlist ...
Stats threat-intelligence:
** Source (raw): 1186787
== Source (unique): 859510 (-327277)
-- White: 858733 (-777)
-- White(*): 857207 (-1526)
-- Dead: 366852 (-490355)
-- Unblock: 366852 (-0)
** Source (raw): 1186894
== Source (unique): 859592 (-327302)
-- White: 858815 (-777)
-- White(*): 857289 (-1526)
-- Dead: 366934 (-490355)
-- Unblock: 366934 (-0)
366852 unique Domains - Version 2021.1022.105512
MD5 Domains RAW: 359838a18192842385f875ae0013e72a
366934 unique Domains - Version 2021.1022.132521
MD5 Domains RAW: 896f927e9550bc33409310484b683cf0
# Convert threat-intelligence to Hostlist ...
@ -142,20 +142,6 @@ Prepare domain list for compiling ... done.
"transformations": [
"Validate"
]
},
{
"source": "https://raw.githubusercontent.com/AdguardTeam/AdGuardSDNSFilter/master/Filters/rules.txt",
"transformations": [
"Validate"
],
"type": "adblock"
},
{
"source": "https://raw.githubusercontent.com/AdguardTeam/AdGuardSDNSFilter/master/Filters/exceptions.txt",
"transformations": [
"Validate"
],
"type": "adblock"
}
],
"transformations": [
@ -163,18 +149,12 @@ Prepare domain list for compiling ... done.
]
}
Start compiling threat-intelligence.adblock.raw
Original length is 346835
Original length is 346876
Filtering the list of rules using 325 exclusion rules
Excluded 2 rules. 346833 rules left.
Length after applying transformations is 346833
Start compiling https://raw.githubusercontent.com/AdguardTeam/AdGuardSDNSFilter/master/Filters/rules.txt
Original length is 576
Length after applying transformations is 570
Start compiling https://raw.githubusercontent.com/AdguardTeam/AdGuardSDNSFilter/master/Filters/exceptions.txt
Original length is 177
Length after applying transformations is 177
The list was compressed from 347589 to 319331
Final length of the list is 319337
Excluded 2 rules. 346874 rules left.
Length after applying transformations is 346874
The list was compressed from 346877 to 318628
Final length of the list is 318634
Writing output to /media/nas/git/rpi/pihole/blocklists/build/threat-intelligence/out/threat-intelligence.adblock
Finished compiling