From 5aba6bb29608979731c8ed47f89dd7d2c844b76a Mon Sep 17 00:00:00 2001 From: Bart Date: Thu, 31 Oct 2019 19:52:16 +0100 Subject: [PATCH 1/6] Update list.json Add some systems. --- lists/automated-malware-analysis/list.json | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/lists/automated-malware-analysis/list.json b/lists/automated-malware-analysis/list.json index 2501fd6..ebab319 100644 --- a/lists/automated-malware-analysis/list.json +++ b/lists/automated-malware-analysis/list.json @@ -1,6 +1,6 @@ { "name": "List of known domains used by automated malware analysis services & security vendors", - "version": 4, + "version": 5, "description": "Domains used by automated malware analysis services & security vendors", "type": "substring", "matching_attributes": [ @@ -27,6 +27,12 @@ "securelist.com", "carbonblack.com", "app.any.run", - "cape.contextis.com" + "cape.contextis.com", + "tria.ge", + "koodous.com", + "undroid.av-comparatives.org", + "sanddroid.xjtu.edu.cn", + "jevereg.amnpardaz.com", + "analyze.intezer.com" ] } From 8bae4eaec945ae0a8768a7d5ccfda1e60da99bc2 Mon Sep 17 00:00:00 2001 From: Alex Williams Date: Mon, 4 Nov 2019 16:35:20 +0000 Subject: [PATCH 2/6] Fixed typo in akamai list description --- lists/akamai/list.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lists/akamai/list.json b/lists/akamai/list.json index 197ece2..80780b4 100644 --- a/lists/akamai/list.json +++ b/lists/akamai/list.json @@ -1,5 +1,5 @@ { - "description": "Akamai IP rannges from BGP search", + "description": "Akamai IP ranges from BGP search", "list": [ "103.12.23.0/24", "103.15.143.0/24", From 3789dbf107f8499a0a731e01f410617adcb69c37 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=D4=9C=D0=B5=D1=95?= <5124946+wesinator@users.noreply.github.com> Date: Fri, 8 Nov 2019 01:43:53 -0500 Subject: [PATCH 3/6] Add additional Sinkhole IPs https://github.com/brakmic/Sinkholes/pull/10/files https://github.com/brakmic/Sinkholes/pull/12/files https://github.com/grettir/malware-sinkholes/pull/2/files --- lists/sinkholes/list.json | 3 +++ 1 file changed, 3 insertions(+) diff --git a/lists/sinkholes/list.json b/lists/sinkholes/list.json index 77b9f8f..0a74d9c 100644 --- a/lists/sinkholes/list.json +++ b/lists/sinkholes/list.json @@ -37,6 +37,7 @@ "176.58.104.168", "178.32.140.251", "178.79.190.156", + "183.236.2.18", "192.169.69.25", "192.42.116.41", "193.166.255.171", @@ -46,6 +47,7 @@ "199.2.137.0/24", "199.231.211.108", "204.95.99.59", + "206.189.61.126", "207.46.90.0/24", "208.43.245.213", "212.227.20.19", @@ -59,6 +61,7 @@ "50.116.56.144", "50.57.148.87", "52.5.245.208", + "58.158.177.102", "67.215.255.139", "74.200.48.169", "74.208.15.160", From 57582009028b5f98f0d125670c9d7d9eabb469a1 Mon Sep 17 00:00:00 2001 From: Bart Date: Fri, 8 Nov 2019 20:20:25 +0100 Subject: [PATCH 4/6] Add sndbox --- lists/automated-malware-analysis/list.json | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/lists/automated-malware-analysis/list.json b/lists/automated-malware-analysis/list.json index ebab319..f36a84c 100644 --- a/lists/automated-malware-analysis/list.json +++ b/lists/automated-malware-analysis/list.json @@ -33,6 +33,7 @@ "undroid.av-comparatives.org", "sanddroid.xjtu.edu.cn", "jevereg.amnpardaz.com", - "analyze.intezer.com" + "analyze.intezer.com", + "app.sndbox.com" ] } From cca1f833ade11de2aa60f6debceabaef4a2c5b0c Mon Sep 17 00:00:00 2001 From: Bart Date: Sun, 10 Nov 2019 22:46:40 +0100 Subject: [PATCH 5/6] Add domain --- lists/whats-my-ip/list.json | 1 + 1 file changed, 1 insertion(+) diff --git a/lists/whats-my-ip/list.json b/lists/whats-my-ip/list.json index 9e932bf..803e1b9 100644 --- a/lists/whats-my-ip/list.json +++ b/lists/whats-my-ip/list.json @@ -26,6 +26,7 @@ "checkip.narak.com", "checkmyip.com", "check-my-ip.net", + "checkip-waw.dyndns.com", "cmyip.com", "cmyip.net", "crymyip.com", From 1e654dca9d1532570e0c580a92d2fbb75beb3b88 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=D4=9C=D0=B5=D1=95?= <5124946+wesinator@users.noreply.github.com> Date: Tue, 12 Nov 2019 16:15:51 -0500 Subject: [PATCH 6/6] add sinkhole IP https://dns.google.com/query?name=sinkhole.dynu.net https://dns.google.com/query?name=a.sinkhole.yourtrap.com&type=A&dnssec=true --- lists/sinkholes/list.json | 1 + 1 file changed, 1 insertion(+) diff --git a/lists/sinkholes/list.json b/lists/sinkholes/list.json index 0a74d9c..1faae74 100644 --- a/lists/sinkholes/list.json +++ b/lists/sinkholes/list.json @@ -30,6 +30,7 @@ "148.81.111.111", "148.81.111.114", "148.81.111.91", + "153.234.210.49", "166.78.144.80", "168.181.184.35", "173.192.192.10",