threat-intelligence auto-update

This commit is contained in:
Zelo72 2021-12-14 19:23:28 +01:00
parent 04ca9d8b80
commit 367401581a
2 changed files with 3900 additions and 3735 deletions

File diff suppressed because it is too large Load Diff

View File

@ -34,105 +34,106 @@ Initialize ...
# Download and convert Sourcelists ...
Nr | Count | Format | Source | Status | File | URL/File
1 | 5252 | hosts | http | online | changed | https://curben.gitlab.io/malware-filter/phishing-filter-hosts.txt
2 | 380 | hosts | http | online | changed | https://curben.gitlab.io/malware-filter/pup-filter-hosts.txt
3 | 9755 | hosts | http | online | changed | https://curben.gitlab.io/malware-filter/urlhaus-filter-hosts.txt
1 | 5010 | hosts | http | online | changed | https://curben.gitlab.io/malware-filter/phishing-filter-hosts.txt
2 | 380 | hosts | http | online | unchanged | https://curben.gitlab.io/malware-filter/pup-filter-hosts.txt
3 | 9788 | hosts | http | online | changed | https://curben.gitlab.io/malware-filter/urlhaus-filter-hosts.txt
4 | 3496 | hosts | http | online | unchanged | https://gitlab.com/ZeroDot1/CoinBlockerLists/raw/master/hosts_browser
5 | 39553 | hosts | http | online | changed | https://hole.cert.pl/domains/domains_hosts.txt
5 | 39611 | hosts | http | online | changed | https://hole.cert.pl/domains/domains_hosts.txt
6 | 550 | hosts | http | online | unchanged | https://paulgb.github.io/BarbBlock/blacklists/hosts-file.txt
7 | 6108 | hosts | http | online | unchanged | https://raw.githubusercontent.com/DandelionSprout/adfilt/master/Alternate%20versions%20Anti-Malware%20List/AntiMalwareHosts.txt
8 | 2202 | hosts | http | online | unchanged | https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Risk/hosts
9 | 59 | hosts | http | online | unchanged | https://raw.githubusercontent.com/FadeMind/hosts.extras/master/add.Spam/hosts
10 | 608 | hosts | http | online | changed | https://raw.githubusercontent.com/davidonzo/Threat-Intel/master/lists/latestdomains.piHole.txt
11 | 1010 | hosts | http | online | changed | https://raw.githubusercontent.com/durablenapkin/scamblocklist/master/hosts.txt
10 | 609 | hosts | http | online | changed | https://raw.githubusercontent.com/davidonzo/Threat-Intel/master/lists/latestdomains.piHole.txt
11 | 1015 | hosts | http | online | changed | https://raw.githubusercontent.com/durablenapkin/scamblocklist/master/hosts.txt
12 | 8624 | hosts | http | online | unchanged | https://raw.githubusercontent.com/guardicore/labs_campaigns/master/Autodiscover/autodiscover-tlds.txt
13 | 696 | hosts | http | online | unchanged | https://raw.githubusercontent.com/hoshsadiq/adblock-nocoin-list/master/hosts.txt
14 | 3920 | hosts | http | online | unchanged | https://raw.githubusercontent.com/infinitytec/blocklists/master/scams-and-phishing.txt
15 | 1072 | hosts | http | online | unchanged | https://raw.githubusercontent.com/metamask/eth-phishing-detect/master/src/hosts.txt
16 | 1386 | hosts | http | online | unchanged | https://raw.githubusercontent.com/mitchellkrogza/Badd-Boyz-Hosts/master/hosts
17 | 13464 | hosts | http | online | unchanged | https://raw.githubusercontent.com/mitchellkrogza/The-Big-List-of-Hacked-Malware-Web-Sites/master/hosts
18 | 1304 | hosts | http | online | changed | https://urlhaus.abuse.ch/downloads/hostfile/
19 | 3091 | hosts | http | online | changed | https://threatfox.abuse.ch/downloads/hostfile
18 | 3083 | hosts | http | online | changed | https://threatfox.abuse.ch/downloads/hostfile
19 | 1298 | hosts | http | online | changed | https://urlhaus.abuse.ch/downloads/hostfile/
20 | 883 | adblock | http | online | unchanged | https://raw.githubusercontent.com/piperun/iploggerfilter/master/filterlist
21 | 925 | domains | http | online | changed | https://azorult-tracker.net/api/list/domain?format=plain
22 | 122584 | domains | http | OFFLINE | unchanged | USE LOCAL COPY: blocklist.cyberthreatcoalition.org_vetted_domain.txt
23 | 549 | domains | http | OFFLINE | unchanged | USE LOCAL COPY: feeds.alphasoc.net_ryuk.txt
24 | 9233 | domains | http | online | unchanged | https://gitlab.com/KevinThomas0/cryptoscamdb-lists/-/raw/master/cryptoscamdb-blocklist.txt
25 | 344 | domains | http | online | unchanged | https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-malware.txt
26 | 39553 | domains | http | online | changed | https://hole.cert.pl/domains/domains.txt
27 | 74256 | domains | http | online | changed | https://joewein.net/dl/bl/dom-bl-base.txt
28 | 592 | domains | http | online | changed | https://joewein.net/dl/bl/dom-bl.txt
29 | 2000 | domains | http | online | changed | https://kriskintel.com/feeds/ktip_covid_domains.txt
30 | 1999 | domains | http | online | changed | https://kriskintel.com/feeds/ktip_malicious_domains.txt
31 | 397 | domains | http | online | unchanged | https://kriskintel.com/feeds/ktip_ransomware_feeds.txt
32 | 2258 | domains | http | online | unchanged | https://orca.pet/notonmyshift/domains.txt
33 | 608 | domains | http | online | changed | https://osint.digitalside.it/Threat-Intel/lists/latestdomains.txt
34 | 50181 | domains | http | online | changed | https://phishing.army/download/phishing_army_blocklist.txt
35 | 60550 | domains | http | online | changed | https://phishing.army/download/phishing_army_blocklist_extended.txt
36 | 1406 | domains | http | online | unchanged | https://raw.githubusercontent.com/AmnestyTech/investigations/master/2021-07-18_nso/domains.txt
37 | 27 | domains | http | online | unchanged | https://raw.githubusercontent.com/DRSDavidSoft/additional-hosts/master/domains/blacklist/fake-domains.txt
38 | 38104 | domains | http | online | changed | https://raw.githubusercontent.com/PolishFiltersTeam/KADhosts/master/KADomains.txt
39 | 682 | domains | http | online | unchanged | https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Cryptocurrency
40 | 26507 | domains | http | online | changed | https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Malware
41 | 145 | domains | http | online | unchanged | https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Risk
42 | 3960 | domains | http | online | unchanged | https://raw.githubusercontent.com/bongochong/CombinedPrivacyBlockLists/master/NoFormatting/MD-ID-Fork.txt
43 | 18459 | domains | http | online | unchanged | https://raw.githubusercontent.com/cbuijs/shallalist/master/spyware/domains
44 | 14148 | domains | http | online | changed | https://raw.githubusercontent.com/cbuijs/ut1/master/cryptojacking/domains
45 | 169166 | domains | http | online | changed | https://raw.githubusercontent.com/cbuijs/ut1/master/malware/domains
46 | 464 | domains | http | online | unchanged | https://raw.githubusercontent.com/hpthreatresearch/iocs/main/CryptBot/domains.txt
47 | 137 | domains | http | online | unchanged | https://raw.githubusercontent.com/hpthreatresearch/iocs/main/IcedID/domains.txt
48 | 720 | domains | http | online | changed | https://raw.githubusercontent.com/hpthreatresearch/iocs/main/TA551/domains.txt
49 | 6543 | domains | http | online | changed | https://raw.githubusercontent.com/iam-py-test/my_filters_001/main/Alternative%20list%20formats/antimalware_domains.txt
50 | 2079 | domains | http | online | unchanged | https://raw.githubusercontent.com/matomo-org/referrer-spam-blacklist/master/spammers.txt
51 | 71286 | domains | http | online | unchanged | https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-domains-ACTIVE.txt
52 | 267 | domains | http | online | changed | https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-domains-NEW-today.txt
53 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.7_5000_domain.txt
54 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.7_germany.txt
55 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.8_domains.txt
56 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.9_italy.txt
57 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v4.0_uk.txt
58 | 2382 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-amnenstytech.txt
59 | 688 | domains | http | online | changed | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-certagid.txt
60 | 379 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-certego.txt
61 | 1810 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-csirt.txt
62 | 1010 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-citizenlabs.txt
63 | 110 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-cyble.txt
64 | 211 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-drweb.txt
65 | 222 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-eset.txt
66 | 24 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-kaspersky.txt
67 | 9940 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-main.txt
68 | 1918 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-malware-traffic.txt
69 | 3334 | domains | http | online | changed | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-personal.txt
70 | 147 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-sentinelone.txt
71 | 86 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-tag.txt
72 | 512 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-unit42-playbook.txt
73 | 23232 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-unit42-silverterrier.txt
74 | 3813 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-zscaler.txt
75 | 155957 | domains | http | online | changed | https://raw.githubusercontent.com/stamparm/aux/master/maltrail-malware-domains.txt
76 | 17084 | domains | http | online | unchanged | https://raw.githubusercontent.com/stamparm/blackbook/master/blackbook.txt
77 | 500 | domains | http | OFFLINE | unchanged | USE LOCAL COPY: rescure.me_covid.txt
78 | 500 | domains | http | online | changed | https://rescure.me/rescure_domain_blacklist.txt
79 | 508 | domains | http | online | unchanged | https://www.botvrij.eu/data/ioclist.domain.raw
80 | 90 | domains | http | online | unchanged | https://www.botvrij.eu/data/ioclist.hostname.raw
81 | 35865 | domains | http | online | changed | https://www.stopforumspam.com/downloads/toxic_domains_whole.txt
82 | 107321 | domains | http | online | changed | https://www.usom.gov.tr/url-list.txt
83 | 59619 | domains | http | online | changed | https://airvpn.org/api/dns_lists/?code=air_malware&block=0.0.0.0&style=domains
84 | 11528 | domains | http | online | unchanged | https://airvpn.org/api/dns_lists/?code=air_cryptojacking&block=0.0.0.0&style=domains
85 | 140 | domains | local | online | unchanged | black.list.threat-intelligence
21 | 11528 | domains | http | online | unchanged | https://airvpn.org/api/dns_lists/?code=air_cryptojacking&block=0.0.0.0&style=domains
22 | 60297 | domains | http | online | changed | https://airvpn.org/api/dns_lists/?code=air_malware&block=0.0.0.0&style=domains
23 | 926 | domains | http | online | changed | https://azorult-tracker.net/api/list/domain?format=plain
24 | 122584 | domains | http | OFFLINE | unchanged | USE LOCAL COPY: blocklist.cyberthreatcoalition.org_vetted_domain.txt
25 | 549 | domains | http | OFFLINE | unchanged | USE LOCAL COPY: feeds.alphasoc.net_ryuk.txt
26 | 9233 | domains | http | online | unchanged | https://gitlab.com/KevinThomas0/cryptoscamdb-lists/-/raw/master/cryptoscamdb-blocklist.txt
27 | 344 | domains | http | online | unchanged | https://gitlab.com/quidsup/notrack-blocklists/raw/master/notrack-malware.txt
28 | 39611 | domains | http | online | changed | https://hole.cert.pl/domains/domains.txt
29 | 74341 | domains | http | online | changed | https://joewein.net/dl/bl/dom-bl-base.txt
30 | 633 | domains | http | online | changed | https://joewein.net/dl/bl/dom-bl.txt
31 | 2000 | domains | http | online | changed | https://kriskintel.com/feeds/ktip_covid_domains.txt
32 | 1999 | domains | http | online | changed | https://kriskintel.com/feeds/ktip_malicious_domains.txt
33 | 397 | domains | http | online | unchanged | https://kriskintel.com/feeds/ktip_ransomware_feeds.txt
34 | 2258 | domains | http | online | unchanged | https://orca.pet/notonmyshift/domains.txt
35 | 609 | domains | http | online | changed | https://osint.digitalside.it/Threat-Intel/lists/latestdomains.txt
36 | 50015 | domains | http | online | changed | https://phishing.army/download/phishing_army_blocklist.txt
37 | 60285 | domains | http | online | changed | https://phishing.army/download/phishing_army_blocklist_extended.txt
38 | 1406 | domains | http | online | unchanged | https://raw.githubusercontent.com/AmnestyTech/investigations/master/2021-07-18_nso/domains.txt
39 | 27 | domains | http | online | unchanged | https://raw.githubusercontent.com/DRSDavidSoft/additional-hosts/master/domains/blacklist/fake-domains.txt
40 | 38196 | domains | http | online | changed | https://raw.githubusercontent.com/PolishFiltersTeam/KADhosts/master/KADomains.txt
41 | 682 | domains | http | online | unchanged | https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Cryptocurrency
42 | 26532 | domains | http | online | changed | https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Malware
43 | 145 | domains | http | online | unchanged | https://raw.githubusercontent.com/ShadowWhisperer/BlockLists/master/Lists/Risk
44 | 3960 | domains | http | online | unchanged | https://raw.githubusercontent.com/bongochong/CombinedPrivacyBlockLists/master/NoFormatting/MD-ID-Fork.txt
45 | 18459 | domains | http | online | unchanged | https://raw.githubusercontent.com/cbuijs/shallalist/master/spyware/domains
46 | 14148 | domains | http | online | unchanged | https://raw.githubusercontent.com/cbuijs/ut1/master/cryptojacking/domains
47 | 169166 | domains | http | online | unchanged | https://raw.githubusercontent.com/cbuijs/ut1/master/malware/domains
48 | 16 | domains | http | online | changed | https://raw.githubusercontent.com/craiu/iocs/main/log4shell/log4j_blocklist.txt
49 | 464 | domains | http | online | unchanged | https://raw.githubusercontent.com/hpthreatresearch/iocs/main/CryptBot/domains.txt
50 | 137 | domains | http | online | unchanged | https://raw.githubusercontent.com/hpthreatresearch/iocs/main/IcedID/domains.txt
51 | 720 | domains | http | online | unchanged | https://raw.githubusercontent.com/hpthreatresearch/iocs/main/TA551/domains.txt
52 | 6554 | domains | http | online | changed | https://raw.githubusercontent.com/iam-py-test/my_filters_001/main/Alternative%20list%20formats/antimalware_domains.txt
53 | 2079 | domains | http | online | unchanged | https://raw.githubusercontent.com/matomo-org/referrer-spam-blacklist/master/spammers.txt
54 | 71286 | domains | http | online | unchanged | https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-domains-ACTIVE.txt
55 | 586 | domains | http | online | changed | https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/phishing-domains-NEW-today.txt
56 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.7_5000_domain.txt
57 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.7_germany.txt
58 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.8_domains.txt
59 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v3.9_italy.txt
60 | 10000 | domains | http | online | unchanged | https://raw.githubusercontent.com/prodaft/malware-ioc/master/FluBot/v4.0_uk.txt
61 | 2382 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-amnenstytech.txt
62 | 688 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-certagid.txt
63 | 379 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-certego.txt
64 | 1010 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-citizenlabs.txt
65 | 1810 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-csirt.txt
66 | 110 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-cyble.txt
67 | 211 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-drweb.txt
68 | 222 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-eset.txt
69 | 24 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-kaspersky.txt
70 | 9940 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-main.txt
71 | 1918 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-malware-traffic.txt
72 | 3334 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-personal.txt
73 | 147 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-sentinelone.txt
74 | 86 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-tag.txt
75 | 512 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-unit42-playbook.txt
76 | 23232 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-unit42-silverterrier.txt
77 | 3813 | domains | http | online | unchanged | https://raw.githubusercontent.com/scafroglia93/blocklists/master/blocklists-zscaler.txt
78 | 155957 | domains | http | online | unchanged | https://raw.githubusercontent.com/stamparm/aux/master/maltrail-malware-domains.txt
79 | 17084 | domains | http | online | unchanged | https://raw.githubusercontent.com/stamparm/blackbook/master/blackbook.txt
80 | 500 | domains | http | OFFLINE | unchanged | USE LOCAL COPY: rescure.me_covid.txt
81 | 500 | domains | http | online | unchanged | https://rescure.me/rescure_domain_blacklist.txt
82 | 508 | domains | http | online | unchanged | https://www.botvrij.eu/data/ioclist.domain.raw
83 | 90 | domains | http | online | unchanged | https://www.botvrij.eu/data/ioclist.hostname.raw
84 | 35875 | domains | http | online | changed | https://www.stopforumspam.com/downloads/toxic_domains_whole.txt
85 | 107375 | domains | http | online | changed | https://www.usom.gov.tr/url-list.txt
86 | 140 | domains | local | online | unchanged | black.list.threat-intelligence
# Build threat-intelligence Domainlist ...
Stats threat-intelligence:
** Source (raw): 1312472
== Source (unique): 888462 (-424010)
-- Exclude: 888457 (-5)
-- White: 887660 (-797)
-- White(*): 881498 (-6162)
-- Dead: 375432 (-506066)
** Source (raw): 1313273
== Source (unique): 888349 (-424924)
-- Exclude: 888344 (-5)
-- White: 887546 (-798)
-- White(*): 881356 (-6190)
-- Dead: 375233 (-506123)
375432 unique Domains - Version 2021.1214.043152
MD5 Domains RAW: 91468bae29f3e30e20849b3154c22a5d
375233 unique Domains - Version 2021.1214.191633
MD5 Domains RAW: 9c04a153bc64fb80873b5c18eb5803b9
# Convert threat-intelligence to Hostlist ...
@ -155,10 +156,10 @@ Prepare domain list for compiling ... done.
]
}
Start compiling threat-intelligence.adblock.raw
Original length is 354638
Length after applying transformations is 354638
The list was compressed from 354641 to 324528
Final length of the list is 324534
Original length is 354402
Length after applying transformations is 354402
The list was compressed from 354405 to 324691
Final length of the list is 324697
Writing output to /media/nas/git/rpi/pihole/blocklists/build/threat-intelligence/out/threat-intelligence.adblock
Finished compiling