Skip to content

Commit fdaa785

Browse files
authored
Merge branch 'main' into warninglists/rewrite-google-generator
2 parents 57d0a7d + 7227439 commit fdaa785

64 files changed

Lines changed: 1477439 additions & 462427 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

README.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,8 @@ There is also a standalone software project called [misp-feedback](https://githu
1919
- [alphastrike-research-nt-scanning/list.json](./lists/alphastrike-research-nt-scanning/list.json) - **Alphastrike research IP Ranges Used for Scanning** - _List containing IP's associated with the Alphastrike research scanners. This scanner CIDR range is extracted from CIRCL Network Telescope analysis on 2026/08/10_
2020
- [alphastrike-scanning/list.json](./lists/alphastrike-scanning/list.json) - **Alpha Strike Labs IP Ranges Used for Scanning** - _List containing IP ranges associated with Alpha Strike Labs scanning infrastructure. Alpha Strike Labs GmbH (AS208843) operates legitimate security research and internet-wide scanning services [https://ipinfo.io/AS208843]_
2121
- [amazon-aws/list.json](./lists/amazon-aws/list.json) - **List of known Amazon AWS IP address ranges** - _Amazon AWS IP address ranges (https://ip-ranges.amazonaws.com/ip-ranges.json)_
22+
- [apple-ipv4/list.json](./lists/apple-ipv4/list.json) - **List of known Apple IPv4 ranges** - _Apple IPv4 ranges announced by AS714 and AS6185_
23+
- [apple-ipv6/list.json](./lists/apple-ipv6/list.json) - **List of known Apple IPv6 ranges** - _Apple IPv6 ranges announced by AS714 and AS6185_
2224
- [apple/list.json](./lists/apple/list.json) - **List of known Apple IP ranges** - _IP ranges assigned to Apple_
2325
- [automated-malware-analysis/list.json](./lists/automated-malware-analysis/list.json) - **List of known domains used by automated malware analysis services & security vendors** - _Domains used by automated malware analysis services & security vendors_
2426
- [bank-website/list.json](./lists/bank-website/list.json) - **List of known bank domains** - _Event contains one or more entries of known banking website_
@@ -31,6 +33,7 @@ There is also a standalone software project called [misp-feedback](https://githu
3133
- [circl-ssh-scanning/list.json](./lists/circl-ssh-scanning/list.json) - **CIRCL IP address used for SSH scanning** - _CIRCL IP address to conducting non-intrusive SSH scans_
3234
- [cisco_top1000/list.json](./lists/cisco_top1000/list.json) - **Top 1000 websites from Cisco Umbrella** - _Event contains one or more entries from the top 1000 of the most used websites (Cisco Umbrella)._
3335
- [cisco_top10k/list.json](./lists/cisco_top10k/list.json) - **Top 10 000 websites from Cisco Umbrella** - _Event contains one or more entries from the top 10 000 of the most used websites (Cisco Umbrella)._
36+
- [cisco_top1m/list.json](./lists/cisco_top1m/list.json) - **Top 1 000 000 websites from Cisco Umbrella** - _Event contains one or more entries from the top 1 000 000 of the most used websites (Cisco Umbrella)._
3437
- [cisco_top20k/list.json](./lists/cisco_top20k/list.json) - **Top 20 000 websites from Cisco Umbrella** - _Event contains one or more entries from the top 20 000 of the most used websites (Cisco Umbrella)._
3538
- [cisco_top5k/list.json](./lists/cisco_top5k/list.json) - **Top 5000 websites from Cisco Umbrella** - _Event contains one or more entries from the top 5000 of the most used websites (Cisco Umbrella)._
3639
- [cloudflare-top100k/list.json](./lists/cloudflare-top100k/list.json) - **Top 100,000 domains from Cloudflare Radar** - _List of top 100,000 domains from Cloudflare Radar (https://developers.cloudflare.com/radar/investigate/domain-ranking-datasets/)_
@@ -59,6 +62,7 @@ There is also a standalone software project called [misp-feedback](https://githu
5962
- [dax30/list.json](./lists/dax30/list.json) - **List of known dax30 webpages** - _Event contains one or more entries of known dax30 webpages_
6063
- [digitalside/list.json](./lists/digitalside/list.json) - **OSINT.DigitalSide.IT Warning List** - _OSINT DigitalSide Threat-Intel Repository - MISP Warninglist - List of domains should be marked as false positive in the related MISP event with IDS attribute not flagged_
6164
- [disposable-email/list.json](./lists/disposable-email/list.json) - **List of disposable email domains** - _List of disposable email domains_
65+
- [driftnet/list.json](./lists/driftnet/list.json) - **List of known Driftnet / Internet-Measurement IP ranges (https://internet-measurement.com/)** - _Driftnet / Internet-Measurement IP address ranges (https://internet-measurement.com/)_
6266
- [dynamic-dns/list.json](./lists/dynamic-dns/list.json) - **List of known dynamic DNS domains** - _Event contains one or more entries of known dynamic DNS domains._
6367
- [eicar.com/list.json](./lists/eicar.com/list.json) - **List of hashes for EICAR test virus** - _Event contains one or more entries based on hashes for EICAR test virus_
6468
- [empty-hashes/list.json](./lists/empty-hashes/list.json) - **List of known hashes for empty files** - _Event contains one or more entries of empty files based on known hashed_
@@ -92,6 +96,7 @@ There is also a standalone software project called [misp-feedback](https://githu
9296
- [microsoft-office365-ip/list.json](./lists/microsoft-office365-ip/list.json) - **List of known Office 365 IP address ranges** - _Office 365 IP address ranges_
9397
- [microsoft-office365/list.json](./lists/microsoft-office365/list.json) - **List of known Office 365 URLs** - _Office 365 URLs and IP address ranges_
9498
- [microsoft-win10-connection-endpoints/list.json](./lists/microsoft-win10-connection-endpoints/list.json) - **List of known Windows 10 connection endpoints** - _Event contains one or more entries of known Windows 10 connection endpoints (https://docs.microsoft.com/en-us/windows/privacy/manage-windows-endpoints)_
99+
- [microsoft-win11-connection-endpoints/list.json](./lists/microsoft-win11-connection-endpoints/list.json) - **List of known Windows 11 connection endpoints** - _Event contains one or more entries of known Windows 11 connection endpoints (https://learn.microsoft.com/en-us/windows/privacy/manage-windows-11-endpoints)_
95100
- [microsoft/list.json](./lists/microsoft/list.json) - **List of known microsoft domains** - _Event contains one or more entries of known microsoft domains_
96101
- [modat-nt-scanning/list.json](./lists/modat-nt-scanning/list.json) - **Modat IP Ranges Used for Scanning** - _List containing IP's associated with the Modat scanners. This scanner CIDR range is extracted from CIRCL Network Telescope analysis on 2026/08/10_
97102
- [modat-scanner/list.json](./lists/modat-scanner/list.json) - **List of published IP address ranges for Modat Scanner** - _Modat Scanner (https://www.modat.io/)_

generate_all.sh

Lines changed: 15 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -6,26 +6,31 @@ set -x
66
pushd tools
77
# python3 generate_alexa.py # not updated since February 1, 2023 and offline after July 31, 2023
88
python3 generate-amazon-aws.py
9+
python3 generate-oracle-oci.py
10+
python3 generate-apple-ip-ranges.py
911
python3 generate-cisco.py
1012
python3 generate-cloudflare.py
13+
python3 generate-fastly.py
14+
#python3 generate-cloudflare-top-domains.py # requires a CLOUDFLARE_API_TOKEN env var (Cloudflare Radar API); raises KeyError: 'CLOUDFLARE_API_TOKEN' when unset
1115
python3 generate-covid.py
1216
python3 generate-crl-ip-domains.py
1317
python3 generate-disposal.py
1418
python3 generate-google.py
15-
#python3 generate_majestic-million.py -n 10000
16-
#python3 generate-microsoft-azure.py
19+
python3 generate_majestic-million.py -n 10000
20+
python3 generate-microsoft-azure.py
1721
# See https://github.com/MISP/misp-warninglists/issues/319
1822
python3 generate_mozilla_certificates.py
1923
python3 generate_moz-top500.py
2024
python3 generate-office365.py
2125
python3 generate_phone_numbers.py
22-
#python3 generate-publicdns.py
23-
#python3 generate-stackpath.py
26+
#python3 generate-stackpath.py # source https://k3t9x2h3.map2.ssl.hwcdn.net/ipblocks.txt is dead (NXDOMAIN); StackPath wound down its CDN and hwcdn.net is now a parked domain-for-sale page
2427
python3 generate-tlds.py
2528
python3 generate-github.py
26-
#python3 generate_tranco.py
29+
python3 generate-public-ipfs-gateways.py
30+
python3 generate_tranco.py
2731
python3 generate-university-domain-list.py
2832
# python3 generate-windows-binary-hashes.py # ON HOLD DUE TO https://github.com/m417z/winbindex/commit/24dd6995fd1c8eacbf59b5ce658d34ccf00bae00
33+
python3 generate-microsoft-win11-endpoints.py
2934
python3 generate-vpn.py
3035
python3 generate-wikimedia.py
3136
python3 generate-second-level-tlds.py
@@ -37,18 +42,20 @@ python3 generate-tenable.py
3742
python3 generate-microsoft-azure-appid.py
3843
python3 generate-chrome-crux-1m.py
3944
python3 generate-digitalside.py
40-
#python3 generate-gptbot.py
45+
python3 generate-gptbot.py
4146
python3 generate-cisco-umbrella-blockpage.py
4247
python3 generate-zscaler.py
4348
python3 generate-onyphe-scanner.py
4449
python3 generate-modat-scanner.py
4550
python3 generate-internetcleanup-scanner.py
46-
#python3 generate-umich-cse-connection-attempts.py # ON HOLD DUE TO 403 (due to User-Agent)
47-
python3 generate-icloud-private-relay.py
51+
python3 generate-driftnet.py
52+
#python3 generate-umich-cse-connection-attempts.py # ON HOLD: source protected by Cloudflare managed JS challenge (HTTP 403, Cf-Mitigated: challenge header) as of 2026-08-29; not a User-Agent issue, requests-based fetch cannot pass itpython3 generate-icloud-private-relay.py
4853
python3 generate-bunny-net.py
4954
python3 generate-ovh.py
5055
python3 generate-microsoft-mdca.py
5156
python3 generate-palo-alto-networks-cortex-cloud.py
57+
python3 generate-lots-project.py
58+
python3 generate-check-host-net.py
5259
popd
5360

5461
./jq_all_the_things.sh

lists/apple-ipv4/list.json

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
{
2+
"description": "Apple IPv4 ranges announced by AS714 and AS6185",
3+
"list": [
4+
"139.178.128.0/18",
5+
"144.178.0.0/18",
6+
"17.0.0.0/8",
7+
"57.102.0.0/15",
8+
"65.199.22.0/23"
9+
],
10+
"matching_attributes": [
11+
"ip-src",
12+
"ip-dst",
13+
"domain|ip",
14+
"ip-src|port",
15+
"ip-dst|port"
16+
],
17+
"name": "List of known Apple IPv4 ranges",
18+
"type": "cidr",
19+
"version": 20260829
20+
}

lists/apple-ipv6/list.json

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
{
2+
"description": "Apple IPv6 ranges announced by AS714 and AS6185",
3+
"list": [
4+
"2403:300::/32",
5+
"2620:0:1b00::/48",
6+
"2620:149::/32",
7+
"2a01:b740::/32",
8+
"2a01:b747::/32"
9+
],
10+
"matching_attributes": [
11+
"ip-src",
12+
"ip-dst",
13+
"domain|ip",
14+
"ip-src|port",
15+
"ip-dst|port"
16+
],
17+
"name": "List of known Apple IPv6 ranges",
18+
"type": "cidr",
19+
"version": 20260829
20+
}

lists/automated-malware-analysis/list.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,5 +36,5 @@
3636
],
3737
"name": "List of known domains used by automated malware analysis services & security vendors",
3838
"type": "substring",
39-
"version": 5
39+
"version": 20200403
4040
}

lists/bank-website/list.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2236,5 +2236,5 @@
22362236
],
22372237
"name": "List of known bank domains",
22382238
"type": "hostname",
2239-
"version": 9
2239+
"version": 20260414
22402240
}

lists/check-host-net/list.json

Lines changed: 44 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -2,54 +2,72 @@
22
"description": "check-host IP addresses (https://check-host.net/nodes/ips)",
33
"list": [
44
"103.214.169.52/32",
5+
"103.42.116.205/32",
6+
"104.28.192.94/32",
7+
"107.149.201.15/32",
8+
"107.181.134.162/32",
9+
"141.255.165.104/32",
510
"141.98.234.68/32",
6-
"167.235.135.184/32",
7-
"170.205.54.119/32",
11+
"142.132.174.167/32",
12+
"143.246.193.61/32",
13+
"147.45.60.14/32",
14+
"151.243.12.65/32",
15+
"157.254.174.204/32",
16+
"162.217.248.181/32",
817
"178.17.171.235/32",
9-
"178.216.200.169/32",
10-
"179.43.148.195/32",
18+
"178.239.146.199/32",
19+
"178.83.180.17/32",
20+
"181.214.10.239/32",
1121
"185.105.238.209/32",
1222
"185.120.77.165/32",
1323
"185.130.104.238/32",
14-
"185.138.164.21/32",
15-
"185.143.223.66/32",
16-
"185.185.132.232/32",
17-
"185.209.161.169/32",
18-
"185.230.55.13/32",
19-
"185.24.253.139/32",
24+
"185.209.161.145/32",
25+
"185.221.199.82/32",
26+
"185.224.3.111/32",
27+
"185.23.17.21/32",
28+
"185.244.28.180/32",
2029
"185.25.204.60/32",
2130
"185.37.147.117/32",
22-
"185.39.205.237/32",
2331
"185.83.213.25/32",
2432
"185.86.77.126/32",
25-
"193.8.95.39/32",
2633
"194.146.57.64/32",
34+
"194.26.100.165/32",
2735
"194.26.229.20/32",
36+
"195.137.244.1/32",
37+
"195.137.245.1/32",
2838
"195.154.114.92/32",
39+
"195.182.38.164/32",
40+
"195.211.24.52/32",
2941
"195.211.27.85/32",
30-
"209.14.69.16/32",
42+
"195.234.80.20/32",
43+
"198.135.169.20/32",
44+
"217.15.166.168/32",
3145
"38.145.202.12/32",
32-
"45.12.81.15/32",
33-
"45.141.149.25/32",
34-
"45.146.7.45/32",
35-
"45.95.168.235/32",
36-
"5.159.54.120/32",
37-
"5.44.42.40/32",
46+
"45.135.242.142/32",
47+
"45.162.230.209/32",
48+
"45.252.248.142/32",
49+
"45.9.168.235/32",
50+
"64.72.205.76/32",
3851
"65.109.182.130/32",
39-
"77.75.230.51/32",
52+
"77.104.108.3/32",
4053
"77.92.151.181/32",
41-
"88.119.179.10/32",
42-
"91.102.183.15/32",
54+
"78.40.111.151/32",
55+
"83.143.119.103/32",
56+
"88.135.75.5/32",
57+
"91.102.127.2/32",
58+
"91.199.41.138/32",
4359
"91.231.182.39/32",
44-
"92.223.65.81/32",
45-
"93.123.16.89/32"
60+
"93.123.16.89/32",
61+
"94.154.123.196/32"
4662
],
4763
"matching_attributes": [
4864
"ip-src",
4965
"ip-dst",
50-
"domain|ip"
66+
"domain|ip",
67+
"ip-src|port",
68+
"ip-dst|port"
5169
],
5270
"name": "List of known check-host.net IP address ranges",
5371
"type": "cidr",
54-
"version": 20240402
72+
"version": 20260829
5573
}

0 commit comments

Comments
 (0)