2016-09-22 14:30:10 +02:00
|
|
|
{
|
|
|
|
"namespace": "domain-abuse",
|
|
|
|
"expanded": "Domain Name Abuse",
|
|
|
|
"description": "Domain Name Abuse - taxonomy to tag domain names used for cybercrime. Use europol-incident to tag abuse-activity",
|
|
|
|
"version": 1,
|
|
|
|
"predicates": [
|
|
|
|
{
|
|
|
|
"value": "domain-access-method",
|
|
|
|
"description": "Domain Access - describes how the adversary has gained access to the domain name",
|
|
|
|
"expanded": "Domain access method"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"value": "domain-status",
|
|
|
|
"description": "Domain status - describes the registration status of the domain name",
|
|
|
|
"expanded": "Domain status"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"values": [
|
|
|
|
{
|
|
|
|
"predicate": "domain-status",
|
|
|
|
"entry": [
|
|
|
|
{
|
|
|
|
"value": "active",
|
|
|
|
"expanded": "Registered & active",
|
2017-02-13 12:02:51 +01:00
|
|
|
"description": "Domain name is registered and DNS is delegated"
|
2016-09-22 14:30:10 +02:00
|
|
|
},
|
2017-02-13 12:02:51 +01:00
|
|
|
{
|
2016-09-22 14:30:10 +02:00
|
|
|
"value": "inactive",
|
|
|
|
"expanded": "Registered & inactive",
|
|
|
|
"description": "Domain name is registered and DNS is not delegated"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"value": "suspended",
|
|
|
|
"expanded": "Registered & suspended",
|
|
|
|
"description": "Domain name is registered & DNS delegation is temporarily removed by the registry"
|
|
|
|
},
|
2017-02-13 12:02:51 +01:00
|
|
|
{
|
2016-09-22 14:30:10 +02:00
|
|
|
"value": "not-registered",
|
|
|
|
"expanded": "Not registered",
|
|
|
|
"description": "Domain name is not registered and open for registration"
|
|
|
|
},
|
2017-02-13 12:02:51 +01:00
|
|
|
{
|
2016-09-22 14:30:10 +02:00
|
|
|
"value": "not-registrable",
|
|
|
|
"expanded": "Not registrable",
|
|
|
|
"description": "Domain is not registered and cannot be registered"
|
|
|
|
},
|
2017-02-13 12:02:51 +01:00
|
|
|
{
|
2016-09-22 14:30:10 +02:00
|
|
|
"value": "grace-period",
|
|
|
|
"expanded": "Grace period",
|
|
|
|
"description": "Domain is deleted and still reserved for previous owner"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"predicate": "domain-access-method",
|
|
|
|
"entry": [
|
|
|
|
{
|
|
|
|
"value": "criminal-registration",
|
|
|
|
"expanded": "Criminal registration",
|
2017-02-13 12:02:51 +01:00
|
|
|
"description": "Domain name is registered for criminal purposes"
|
2016-09-22 14:30:10 +02:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"value": "compromised-webserver",
|
|
|
|
"expanded": "Compromised webserver",
|
2017-02-13 12:02:51 +01:00
|
|
|
"description": "Webserver is compromised for criminal purposes"
|
2016-09-22 14:30:10 +02:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"value": "compromised-dns",
|
|
|
|
"expanded": "Compromised DNS",
|
2017-02-13 12:02:51 +01:00
|
|
|
"description": "Compromised authoritative DNS or compromised delegation"
|
2016-09-22 14:30:10 +02:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"value": "sinkhole",
|
|
|
|
"expanded": "Sinkhole",
|
2017-02-13 12:02:51 +01:00
|
|
|
"description": "Domain Name is sinkholed for research, detection, LE"
|
2016-09-22 14:30:10 +02:00
|
|
|
}
|
2017-02-13 12:02:51 +01:00
|
|
|
]
|
2016-09-22 14:30:10 +02:00
|
|
|
}
|
|
|
|
]
|
2017-02-13 12:02:51 +01:00
|
|
|
}
|