Coder Social home page Coder Social logo

malicious-domains's Introduction

Statistics

Update of the following table: 2024-05-30 06:23 CEST

File Number of domains
full-domains-* 137 087

Introduction

[FR]

  • Agrégation de listes de domaines malveillants, utilisés pour du phishing, scindée en fichiers de 131 072 entrées au maximum pour être intégrées dans des pare-feux : Fortinet FortiGate et autres équipements.
  • Pour éviter les faux positifs, les domaines du top 1M (Cisco Umbrella et CloudFlare) des sites Web les plus visités ont été retirés.
  • Domaines ordonnés en fonction du nombre de sources dans lesquelles ils apparaissent (Domaines apparaissant dans le plus de sources sont donc dans le début du fichier full-domain-aa.txt).
  • Mise à jour toutes les heures
  • Implémentation dans les pare-feux FortiGate : lien
    • Menu "Security Fabric → External Connectors → Create New → Threat Feeds → Domain Name"
    • Copier une URL dans la partie "Links" ci-dessous
    • Menu "Security Profiles → DNS Filter"
    • Dans un profil, activer "FortiGuard Category Based Filter"
    • Ajouter les listes dans "Remote Categories group"
    • Appliquer ensuite ce profil de sécurité dans vos "Firewall Policy" autorisant le protocole DNS en sortie (LAN > WAN)

[EN]

  • Aggregation of lists of malicious domains (phishing) that can be integrated into FortiGate firewalls and other products.
  • To avoid false positives, the top 1M domains (Cisco Umbrella and CloudFlare) of the most visited websites have been removed.
  • Domains ordered according to the number of sources in which they appear (Domains appearing in the most sources are therefore at the beginning of the full-domain-aa.txt file).
  • Updated every hour
  • Implementation in FortiGate firewalls: link
    • Menu "Security Fabric → External Connectors → Create New → Threat Feeds → Domain Name"
    • Copy a URL in the "Links" section below
    • Menu "Security Profiles → DNS Filter"
    • In a profile, activate "FortiGuard Category Based Filter"
    • Add the lists to "Remote Categories group"
    • Then apply this security profile in your “Firewall Policy” authorizing the DNS protocol on output (LAN > WAN)

Links

https://raw.githubusercontent.com/romainmarcoux/malicious-domains/main/full-domains-aa.txt
https://raw.githubusercontent.com/romainmarcoux/malicious-domains/main/full-domains-ab.txt

Sources

Filename Source Description
red.flag.domains link Recently registered probably malicious domain names in french TLDs
alienvault-banking-phishtank link Verified Banking Phishing Domain
alienvault-cert-pl link List of malicious domains
alienvault-dropbox-phishtank link Verified Dropbox Phishing Domain
alienvault-googledocs-phishtank link Verified Google Docs Phishing Domain
alienvault-microsoft-phishtank link Verified Microsoft Phishing Domain
alienvault-paypal-phishtank link Verified Paypal Phishing Domain
alienvault-phishing-scam link Phishing & scam domain names
openphish.com link Phishing domain
phishing.army link Phishing domain (only .fr domains and with main keywords)
phishtank.org link Phishing domain collaborative website
red.flag.domains link Recently registered typosquatting and probably malicious domain names in french TLDs
url.abuse.ch link Sharing malicious domains
ut1-fr link Malware and phishing domains (only .fr domains and with main keywords)
full-domains-* 137 087

Release Notes

  • 2024-03-03: New sources: url.abuse.ch, alienvault-phishing-scam, alienvault-cert-pl, ut1-fr, phishing.army
  • 2024-02-18: New source: phishtank.org
  • 2024-01-20: Initial release with first sources: red.flag.domains, openphish.com, alienvault-banking-phishtank, alienvault-dropbox-phishtank, alienvault-googledocs-phishtank, alienvault-microsoft-phishtank, alienvault-paypal-phishtank

Contact

[FR]

Contactez-moi via LinkedIn (mon profil) pour :

  • m'indiquer des faux positifs
  • être notifié quand un nouveau segment de fichier est créé (pour l'ajouter dans votre pare-feu)
  • me proposer d'ajouter une autre source de domaines malveillants.

[EN]

Contact me via LinkedIn (my profile) to:

  • notify me false positives
  • be notified when a new file segment is created (to add it to your firewall)
  • suggest I add another source of malicious domains.

malicious-domains's People

Contributors

romainmarcoux avatar

Stargazers

 avatar Nicolas Vincent avatar Samuel avatar  avatar  avatar  avatar  avatar Tomparte #Thomas avatar Olivier OLEJNICZAK avatar  avatar Bad avatar  avatar Venopsis avatar Lullia avatar Jason Todd avatar  avatar

Watchers

Jason Todd avatar  avatar  avatar

malicious-domains's Issues

some irregular name makes error on loading

irregular name use RAM for nothing and leads to errors
(I am not on fortinet)
ex:

grep '..' /var/cache/malicious-domains/full-domains-ab.txt
2s5wzb.mcgo2.com..e

dig 2s5wzb.mcgo2.com..e
dig: '2s5wzb.mcgo2.com..e' is not a legal name (empty label)

should set a filter on '..' or malformed domain name.
regards.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.