Skip to content

Instantly share code, notes, and snippets.

@D3vl0per
Last active March 12, 2024 15:40
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save D3vl0per/982aaba2081a9c96c8ec370f2100ba86 to your computer and use it in GitHub Desktop.
Save D3vl0per/982aaba2081a9c96c8ec370f2100ba86 to your computer and use it in GitHub Desktop.
Block lists | Cerebral cortex - Hippocampus
| Name | Source | License | Format | IOCs | Refresh interval | Components |
| :--- | :----: | :-----: | :----: | :--: | :--------------: | :- |
| Phishing-Filter | https://gitlab.com/malware-filter/phishing-filter | MIT | Raw List | Urls/Domains/IPs | 2/day | PhishTank, OpenPhish, phishunt.io |
| Botnet-Filter | https://gitlab.com/malware-filter/botnet-filter | MIT | Raw List | IP | 1/day | Abuse.ch Feodo Tracker |
| Domain blacklist | https://oisd.nl/
| Botvrij Domain Blacklist | https://botvrij.eu/data/ |
| Botvrij Domain Blacklist | https://botvrij.eu/data/ioclist.domain |
| Botvrij IP Blacklist | https://botvrij.eu/data/ioclist.ip-dst |
| Botvrij URL Blacklist | https://botvrij.eu/data/ioclist.url
| CINS Score IP Blacklist | http://cinsscore.com/list/ci-badguys.txt |
| Greensnow IP Blacklist | https://blocklist.greensnow.co/greensnow.txt |
| Phishing.Database IP Blacklist | https://github.com/mitchellkrogza/Phishing.Database/blob/master/phishing-IPs-ACTIVE.txt
| Phishing.Database Domain Blacklist | https://github.com/mitchellkrogza/Phishing.Database/blob/master/phishing-domains-ACTIVE.txt
| StopForumSpam Domain Blacklist | https://www.stopforumspam.com/downloads/toxic_domains_whole_filtered_50000.txt | ?
| PhishStats URL, IP Blacklist | https://phishstats.info/phish_score.csv | 90 min
| Phishunt URL Blacklist | https://phishunt.io/feed.txt | ?
| Phishing Army Domain Blocklist | https://phishing.army/download/phishing_army_blocklist_extended.txt
| TOR exit nodes | https://check.torproject.org/exit-addresses |
| BunkerWeb IP Blocklist | https://gist.github.com/D3vl0per/72a6b1521ad1ce3e4e3b10c325f8381a | 24h
| Turris IP Blocklist | https://view.sentinel.turris.cz/greylist-data/greylist-latest.csv | 24h
| Openphish URL Blocklist | https://openphish.com/feed.txt | 12h
| CyberCrime Tracker URL List | https://cybercrime-tracker.net/all.php |
| Snort IP Blocklist | https://snort.org/downloads/ip-block-list |
| AbuseCH ThreatFox IP Blacklist | https://threatfox.abuse.ch/export/json/ip-port/recent/ | 5min (range 48h)
| AbuseCH ThreatFox Domain Blacklist | https://threatfox.abuse.ch/export/json/domains/recent/ |
| AbuseCH ThreatFox Url Blacklist | https://threatfox.abuse.ch/export/json/urls/recent/ |
| AbuseCH ThreatFox MD5 Blacklist | https://threatfox.abuse.ch/export/json/md5/recent/ |
| AbuseCH ThreatFox SHA256 Blacklist | https://threatfox.abuse.ch/export/json/sha256/recent/ |
| AbuseCH Fedotracker IP Blocklist | https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt |
| AbuseCH SinkHoles | https://sinkdb.abuse.ch/ |
| AbuseCH URLHaus Domain Blacklist | https://urlhaus.abuse.ch/downloads/hostfile/ |
| AbuseCH URLHaus URL Blocklist | https://urlhaus.abuse.ch/downloads/text/ |
| CTU-AIPP IP BlackList | https://mcfp.felk.cvut.cz/publicDatasets/CTU-AIPP-BlackList/Todays-Blacklists/ |AIP_blacklist_for_IPs_seen_last_24_hours.csv | 24h
| CTU-AIPP IP BlackList New | https://mcfp.felk.cvut.cz/publicDatasets/CTU-AIPP-BlackList/Todays-Blacklists/ |AIP_historical_blacklist_prioritized_by_newest_attackers.csv | 24h
| CTU-AIPP IP BlackList Repeated Offense | https://mcfp.felk.cvut.cz/publicDatasets/CTU-AIPP-BlackList/Todays-Blacklists/ AIP_historical_blacklist_prioritized_by_repeated_attackers.csv |
| IPsum Threat Intelligence Feed | https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt |
| DShield Top 20 Malicious IP Subnet | https://feeds.dshield.org/block.txt |
| Blocklist DE Fail2Ban IP Blacklist | https://lists.blocklist.de/lists/all.txt |
| OpenPhish URL Blacklist | https://www.openphish.com/feed.txt |
| Spamhaus IP Subments Blacklist | https://www.spamhaus.org/drop/drop.txt |
| VXVault Last 100 Malware Links | http://vxvault.net/URL_List.php |
| Team Cymru IP Blocklist | https://www.team-cymru.org/Services/Bogons/fullbogons-ipv4.txt |
| Rulez SK IP Blocklist | http://danger.rulez.sk/projects/bruteforceblocker/blist.php |
| DigitalSide Threat-Intel Repository FQDN Blacklist | https://osint.digitalside.it/Threat-Intel/lists/latestdomains.txt | 7d
| DigitalSide Threat-Intel Repository URL Blacklist | https://osint.digitalside.it/Threat-Intel/lists/latestips.txt | 7d
| DigitalSide Threat-Intel Repository IP Blacklist | https://osint.digitalside.it/Threat-Intel/lists/latesturls.txt | 7d
| KADhosts IP Blacklist | https://raw.githubusercontent.com/FiltersHeroes/KADhosts/master/KADhosts.txt |
| KADhosts Domain Blacklist | https://raw.githubusercontent.com/FiltersHeroes/KADhosts/master/KADomains.txt |
| Alienvault IP Reputation | https://reputation.alienvault.com/reputation.generic |
| Atmos Strategic Monitoring | https://cybercrime-tracker.net/ccam.php |
| Atmos Strategic Monitoring | https://cybercrime-tracker.net/ccpmgate.php |
| Badips.com IP Blacklist | https://iplists.firehol.org/files/bi_any_2_7d.ipset |
| Binary Defense Systems Artillery Threat Intelligence Feed and Banlist Feed | https://www.binarydefense.com/banlist.txt
| Malware Domain Blocklist | https://raw.githubusercontent.com/stamparm/blackbook/master/blackbook.csv |
| Blackhole Monster IP Blocklist | https://ip.blackhole.monster/blackhole-today |
| Botscout IP Blocklist | https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/botscout_1d.ipset |
| Cruzit IP Blocklist | https://www.cruzit.com/wbl.php |
| Dataplane Blocklist | https://dataplane.org/dnsrd.txt |
| Dataplane Blocklist | https://dataplane.org/dnsrdany.txt |
| Dataplane Blocklist | https://dataplane.org/dnsversion.txt |
| Dataplane Blocklist | https://dataplane.org/sipinvitation.txt |
| Dataplane Blocklist | https://dataplane.org/sipquery.txt |
| Dataplane Blocklist | https://dataplane.org/sipregistration.txt |
| Dataplane Blocklist | https://dataplane.org/smtpdata.txt |
| Dataplane Blocklist | https://dataplane.org/smtpgreet.txt |
| Dataplane Blocklist | https://dataplane.org/sshclient.txt |
| Dataplane Blocklist | https://dataplane.org/sshpwauth.txt |192
| Dataplane Blocklist | https://dataplane.org/telnetlogin.txt |
| Dataplane Blocklist | https://dataplane.org/vncrfb.txt |
| EmergingThreats CC Bot Blocklist | https://rules.emergingthreats.net/open/suricata/rules/botcc.rules |
| EmergingThreats IP Blocklist | https://rules.emergingthreats.net/open/suricata/rules/compromised-ips.txt |
| EmergingThreats Malware Blocklist | https://rules.emergingthreats.net/open/suricata/rules/emerging-malware.rules |
| | https://iplists.firehol.org/files/gpf_comics.ipset |
| | http://sekuripy.hr/blacklist.txt |
| | https://www.maxmind.com/en/high-risk-ip-sample-list |
| | https://raw.githubusercontent.com/Hestat/minerchk/master/hostslist.txt |
| | https://myip.ms/files/blacklist/htaccess/latest_blacklist.txt |
| | https://raw.githubusercontent.com/futpib/policeman-rulesets/master/examples/simple_domains_blacklist.txt |
| | https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/proxylists_1d.ipset |
| | https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/proxyspy_1d.ipset |
| | https://ransomwaretracker.abuse.ch/downloads/RW_DOMBL.txt |
| | https://ransomwaretracker.abuse.ch/downloads/RW_IPBL.txt |
| | https://ransomwaretracker.abuse.ch/downloads/RW_URLBL.txt |
| | https://report.cs.rutgers.edu/DROP/attackers |
| | https://sblam.com/blacklist.txt |
| | https://raw.githubusercontent.com/scriptzteam/badIPS/main/ips.txt |
| | https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/socks_proxy_7d.ipset |
| | https://sslbl.abuse.ch/blacklist/sslipblacklist.rules |
| | https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/sslproxies_1d.ipset |
| | https://raw.githubusercontent.com/stamparm/aux/master/maltrail-static-trails.txt |
| | https://www.talosintelligence.com/documents/ip-blacklist |
| | https://check.torproject.org/cgi-bin/TorBulkExitList.py?ip=1.1.1.1 |
| | http://tracker.viriback.com/dump.php |
| Cloudflare Radar |
Lookups
| https://hashlookup.circl.lu/
|
Links
| https://firebog.net/
| https://github.com/blocklistproject/Lists
| http://security-research.dyndns.org/pub/
| https://github.com/stamparm/maltrail/tree/master/trails/feeds
EH
| https://feed.seguranca-informatica.pt
| https://support.clean-mx.com/clean-mx/viruses.php
Self-hosted
| https://github.com/D4-project/BGP-Ranking
| https://github.com/d-Rickyy-b/certstream-server-go
Interesting
| https://www.cisecurity.org/ms-isac/services
| https://n6.readthedocs.io/usage/streamapi/
https://github.com/stamparm/maltrail/tree/master/trails/feeds
Scanners
| https://support.censys.io/hc/en-us/articles/360043177092-from-faq
|
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment