Wed Apr 17 10:22:31 UTC 2024 update

This commit is contained in:
Costa Tsaousis 2024-04-14 06:42:02 +01:00
commit b92e4042f2
1358 changed files with 7181246 additions and 0 deletions

106
.gitignore vendored Normal file
View File

@ -0,0 +1,106 @@
bogons.netset
.cache
.cache.old
dragon_http.netset
dragon_*.ipset
dragon_*.netset
dragon_sshpauth.netset
dragon_vncprobe.netset
dronebl_anonymizers.netset
dronebl_auto_botnets.netset
dronebl_autorooting_worms.netset
dronebl_compromised.netset
dronebl_ddos_drones.netset
dronebl_dns_mx_on_irc.netset
dronebl_*.ipset
dronebl_irc_drones.netset
dronebl_*.netset
dronebl_unknown.netset
dronebl_worms_bots.netset
errors/
fullbogons.netset
history/
ib_*.ipset
iblocklist_ads.netset
iblocklist_ads.*set
iblocklist_badpeers.ipset
iblocklist_badpeers.*set
iblocklist_bogons.netset
iblocklist_bogons.*set
iblocklist_dshield.netset
iblocklist_dshield.*set
iblocklist_edu.netset
iblocklist_edu.*set
iblocklist_exclusions.netset
iblocklist_exclusions.*set
iblocklist_fornonlancomputers.netset
iblocklist_fornonlancomputers.*set
iblocklist_forumspam.netset
iblocklist_forumspam.*set
iblocklist_hijacked.netset
iblocklist_hijacked.*set
iblocklist_iana_multicast.netset
iblocklist_iana_multicast.*set
iblocklist_iana_private.netset
iblocklist_iana_private.*set
iblocklist_iana_reserved.netset
iblocklist_iana_reserved.*set
iblocklist_level1.netset
iblocklist_level1.*set
iblocklist_level2.netset
iblocklist_level2.*set
iblocklist_level3.netset
iblocklist_level3.*set
iblocklist_org_microsoft.netset
iblocklist_org_microsoft.*set
iblocklist_proxies.ipset
iblocklist_proxies.*set
iblocklist_rangetest.netset
iblocklist_rangetest.*set
iblocklist_spider.netset
iblocklist_spider.*set
iblocklist_spyware.netset
iblocklist_spyware.*set
iblocklist_webexploit.ipset
iblocklist_webexploit.*set
ib_*.netset
iprange*
ipv4_range_to_cidr.awk
*.lastchecked
*.setinfo
sorbs_anonymizers.netset
sorbs_dul.netset
sorbs_escalations.netset
sorbs_*.ipset
sorbs_*.netset
sorbs_new_spam.netset
sorbs_noserver.netset
sorbs_recent_spam.netset
sorbs_smtp.netset
sorbs_web.netset
sorbs_zombie.netset
*.source
*.tmp
update-ipsets*
.warn_if_last_downloaded_before_this
blueliv*.ipset
blueliv*.netset
blueliv_crimeserver_online.ipset
blueliv_crimeserver_recent.ipset
blueliv_crimeserver_last.ipset
blueliv_crimeserver_last_1d.ipset
blueliv_crimeserver_last_2d.ipset
blueliv_crimeserver_last_7d.ipset
blueliv_crimeserver_last_30d.ipset
iblocklist_badpeers.netset
dataplane_sipquery.ipset
dataplane_sshpwauth.ipset
dataplane_sshclient.ipset
dataplane_sipregistration.ipset
dataplane_sipinvitation.ipset
dataplane_vncrfb.ipset
dataplane_dnsrd.ipset
dataplane_dnsrdany.ipset
dataplane_dnsversion.ipset
shunlist.ipset
ip2proxy_px1lite.netset

228
README-EDIT.md Normal file
View File

@ -0,0 +1,228 @@
> Due to the amount of data and the frequency of the updates on this repo,
> github has requested to limit the number of updates.
> The site [https://iplists.firehol.org](https://iplists.firehol.org) has direct links
> to all the files in this repo. **This repo is now updated once per day.**
---
### Contents
- [About this repo](#about-this-repo)
- [Using these ipsets](#using-these-ipsets)
- [Which ones to use?](#which-ones-to-use)
- [Why are open proxy lists included](#why-are-open-proxy-lists-included)
- [Using them in FireHOL](#using-them-in-firehol)
* [Adding the ipsets in your firehol.conf](#adding-the-ipsets-in-your-fireholconf)
* [Updating the ipsets while the firewall is running](#updating-the-ipsets-while-the-firewall-is-running)
- [Dynamic List of ipsets included](#list-of-ipsets-included)
- [Comparison of ipsets](#comparison-of-ipsets)
---
# About this repo
This repository includes a list of ipsets dynamically updated with
[FireHOL](https://github.com/firehol/firehol)'s `update-ipsets.sh`
[documented in this wiki](https://github.com/firehol/blocklist-ipsets/wiki).
This repo is self maintained. It it updated automatically from the script via a cron job.
This repo has a site: [http://iplists.firehol.org](http://iplists.firehol.org).
## Why do we need blocklists?
As time passes and the internet matures in our life, cybercrime is becoming increasingly sophisticated.
Although there are many tools (detection of malware, viruses, intrusion detection and prevention systems,
etc) to help us isolate the bad guys, there are now a lot more than just such attacks.
What is more interesting is that the fraudsters or attackers in many cases are not going to do a direct
damage to you or your systems. They will use you and your systems to gain something else, possibly not
related or indirectly related to your business. Nowadays the attacks cannot be identified easily. They are
distributed and come to our systems from a vast amount of IPs around the world.
To get an idea, check for example the [XRumer](http://en.wikipedia.org/wiki/XRumer) software. This thing
mimics human behavior to post ads, it creates email accounts, responds to emails it receives, bypasses
captchas, it goes gently to stay unnoticed, etc.
To increase our effectiveness we need to complement our security solutions with our shared knowledge, our
shared experience in this fight.
Hopefully, there are many teams out there that do their best to identify the attacks and pinpoint the
attackers. These teams release blocklists. Blocklists of IPs (for use in firewalls), domains & URLs
(for use in proxies), etc.
What we are interested here is IPs.
Using IP blocklists at the internet side of your firewall is a key component of internet security. These
lists share key knowledge between us, allowing us to learn from each other and effectively isolate
fraudsters and attackers from our services.
I decided to upload these lists to a github repo because:
1. They are freely available on the internet. The intention of their creators is to help internet security.
Keep in mind though that a few of these lists may have special licences attached. Before using them, please check their source site for any information regarding proper use.
2. Github provides (via `git pull`) a unified way of updating all the lists together.
Pulling this repo regularly on your machines, you will update all the IP lists at once.
3. Github also provides a unified version control. Using it we can have a history of what each list has
done, which IPs or subnets were added and which were removed.
## DNSBLs
Check also another tool included in FireHOL v3+, called `dnsbl-ipset.sh`.
This tool is capable of creating an ipset based on your traffic by looking up information on DNSBLs and
scoring it according to your preferences.
More information [here](https://github.com/firehol/firehol/wiki/dnsbl-ipset.sh).
---
# Using these ipsets
Please be very careful what you choose to use and how you use it. If you blacklist traffic using these
lists you may end up blocking your users, your customers, even yourself (!) from accessing your services.
1. Go to to the site of each list and read how each list is maintained. You are going to trust these guys for doing their job right.
2. Most sites have either a donation system or commercial lists of higher quality. Try to support them.
3. I have included the TOR network in these lists (`bm_tor`, `dm_tor`, `et_tor`). The TOR network is not necessarily bad and you should not block it if you want to allow your users be anonymous. I have included it because for certain cases, allowing an anonymity network might be a risky thing (such as eCommerce).
4. Apply any blacklist at the internet side of your firewall. Be very careful. The `bogons` and `fullbogons` lists contain private, unrouteable IPs that should not be routed on the internet. If you apply such a blocklist on your DMZ or LAN side, you will be blocked out of your firewall.
5. Always have a whitelist too, containing the IP addresses or subnets you trust. Try to build the rules in such a way that if an IP is in the whitelist, it should not be blocked by these blocklists.
## Which ones to use
### Level 1 - Basic
These are the ones I trust. **Level 1** provides basic security against the most well-known attackers, with the minimum of false positives.
1. **Abuse.ch** lists `feodo`, `palevo`, `sslbl`, `zeus`, `zeus_badips`
These folks are doing a great job tracking crime ware. Their blocklists are very focused.
Keep in mind `zeus` may include some false positives. You can use `zeus_badips` instead.
2. **DShield.org** list `dshield`
It contains the top 20 attacking class C (/24) subnets, over the last three days.
3. **Spamhaus.org** lists `spamhaus_drop`, `spamhaus_edrop`
DROP (Don't Route Or Peer) and EDROP are advisory "drop all traffic" lists, consisting of netblocks that are "hijacked" or leased by professional spam or cyber-crime operations (used for dissemination of malware, trojan downloaders, botnet controllers).
According to Spamhaus.org:
> When implemented at a network or ISP's 'core routers', DROP and EDROP will help protect the network's users from spamming, scanning, harvesting, DNS-hijacking and DDoS attacks originating on rogue netblocks.
>
> Spamhaus strongly encourages the use of DROP and EDROP by tier-1s and backbones.
Spamhaus is very responsive to adapt these lists when a network owner updates them that the issue has been solved (I had one such incident with one of my users).
4. **Team-Cymru.org** list `bogons` or `fullbogons`
These are lists of IPs that should not be routed on the internet. No one should be using them.
Be very careful to apply either of the two on the internet side of your network.
### Level 2 - Essentials
**Level 2** provide protection against current brute force attacks. This level may have a small percentage of false positives, mainly due to dynamic IPs being re-used by other users.
1. **OpenBL.org** lists `openbl*`
The team of OpenBL tracks brute force attacks on their hosts. They have a very short list for hosts, under their own control, collecting this information, to eliminate false positives.
They suggest to use the default blacklist which has a retention policy of 90 days (`openbl`), but they also provide lists with different retention policies (from 1 day to 1 year).
Their goal is to report abuse to the responsible provider so that the infection is disabled.
2. **Blocklist.de** lists `blocklist_de*`
Is a network of users reporting abuse mainly using `fail2ban`. They eliminate false positives using other lists available. Since they collect information from their users, their lists may be subject to poisoning, or false positives.
I asked them about poisoning. [Here](https://forum.blocklist.de/viewtopic.php?f=4&t=244&sid=847d00d26b0735add3518ff515242cad) you can find their answer. In short, they track it down so that they have an ignorable rate of false positives.
Also, they only include individual IPs (no subnets) which have attacked their users the last 48 hours and their list contains 20.000 to 40.000 IPs (which is small enough considering the size of the internet).
Like `openbl`, their goal is to report abuse back, so that the infection is disabled.
They also provide their blocklist per type of attack (mail, web, etc).
Of course, there are more lists included. You can check them and decide if they fit for your needs.
## Why are open proxy lists included
Of course, I haven't included them for you to use the open proxies. The port the proxy is listening, or the type of proxy, are not included (although most of them use the standard proxy ports and do serve web requests).
If you check the comparisons for the open proxy lists (`ri_connect_proxies`, `ri_web_proxies`, `xroxy`, `proxz`, `proxyrss`, etc)
you will find that they overlap to a great degree with other blocklists, like `blocklist_de`, `stopforumspam`, etc.
> This means the attackers also use open proxies to execute attacks.
So, if you are under attack, blocking the open proxies may help isolate a large part of the attack.
I don't suggest to permanently block IPs using the proxy lists. Their purpose of existence is questionable.
Their quality though may be acceptable, since lot of these sites advertise that they test open proxies before including them in their lists, so that there are no false positives, at least at the time they tested them.
---
## Using them in FireHOL
`update-ipsets.sh` itself does not alter your firewall. It can be used to update ipsets both on disk and in the kernel for any firewall solution you use.
The information below, shows you how to configure FireHOL to use the provides ipsets.
### Adding the ipsets in your firehol.conf
I use something like this:
```sh
# our wan interface
wan="dsl0"
# our whitelist
ipset4 create whitelist hash:net
ipset4 add whitelist A.B.C.D/E # A.B.C.D/E is whitelisted
# subnets - netsets
for x in fullbogons dshield spamhaus_drop spamhaus_edrop
do
ipset4 create ${x} hash:net
ipset4 addfile ${x} ipsets/${x}.netset
blacklist4 full inface "${wan}" log "BLACKLIST ${x^^}" ipset:${x} \
except src ipset:whitelist
done
# individual IPs - ipsets
for x in feodo palevo sslbl zeus openbl blocklist_de
do
ipset4 create ${x} hash:ip
ipset4 addfile ${x} ipsets/${x}.ipset
blacklist4 full inface "${wan}" log "BLACKLIST ${x^^}" ipset:${x} \
except src ipset:whitelist
done
... rest of firehol.conf ...
```
If you are concerned about iptables performance, change the `blacklist4` keyword `full` to `input`.
This will block only inbound NEW connections, i.e. only the first packet for every NEW inbound connection will be checked.
All other traffic passes through unchecked.
> Before adding these rules to your `firehol.conf` you should run `update-ipsets.sh` to enable them.
### Updating the ipsets while the firewall is running
Just use the `update-ipsets.sh` script from the firehol distribution.
This script will update each ipset and call firehol to update the ipset while the firewall is running.
> You can add `update-ipsets.sh` to cron, to run every 10 mins. `update-ipsets.sh` is smart enough to download
> a list only when it needs to.
---
# List of ipsets included

626
README.md Normal file
View File

@ -0,0 +1,626 @@
> Due to the amount of data and the frequency of the updates on this repo,
> github has requested to limit the number of updates.
> The site [https://iplists.firehol.org](https://iplists.firehol.org) has direct links
> to all the files in this repo. **This repo is now updated once per day.**
---
### Contents
- [About this repo](#about-this-repo)
- [Using these ipsets](#using-these-ipsets)
- [Which ones to use?](#which-ones-to-use)
- [Why are open proxy lists included](#why-are-open-proxy-lists-included)
- [Using them in FireHOL](#using-them-in-firehol)
* [Adding the ipsets in your firehol.conf](#adding-the-ipsets-in-your-fireholconf)
* [Updating the ipsets while the firewall is running](#updating-the-ipsets-while-the-firewall-is-running)
- [Dynamic List of ipsets included](#list-of-ipsets-included)
- [Comparison of ipsets](#comparison-of-ipsets)
---
# About this repo
This repository includes a list of ipsets dynamically updated with
[FireHOL](https://github.com/firehol/firehol)'s `update-ipsets.sh`
[documented in this wiki](https://github.com/firehol/blocklist-ipsets/wiki).
This repo is self maintained. It it updated automatically from the script via a cron job.
This repo has a site: [http://iplists.firehol.org](http://iplists.firehol.org).
## Why do we need blocklists?
As time passes and the internet matures in our life, cybercrime is becoming increasingly sophisticated.
Although there are many tools (detection of malware, viruses, intrusion detection and prevention systems,
etc) to help us isolate the bad guys, there are now a lot more than just such attacks.
What is more interesting is that the fraudsters or attackers in many cases are not going to do a direct
damage to you or your systems. They will use you and your systems to gain something else, possibly not
related or indirectly related to your business. Nowadays the attacks cannot be identified easily. They are
distributed and come to our systems from a vast amount of IPs around the world.
To get an idea, check for example the [XRumer](http://en.wikipedia.org/wiki/XRumer) software. This thing
mimics human behavior to post ads, it creates email accounts, responds to emails it receives, bypasses
captchas, it goes gently to stay unnoticed, etc.
To increase our effectiveness we need to complement our security solutions with our shared knowledge, our
shared experience in this fight.
Hopefully, there are many teams out there that do their best to identify the attacks and pinpoint the
attackers. These teams release blocklists. Blocklists of IPs (for use in firewalls), domains & URLs
(for use in proxies), etc.
What we are interested here is IPs.
Using IP blocklists at the internet side of your firewall is a key component of internet security. These
lists share key knowledge between us, allowing us to learn from each other and effectively isolate
fraudsters and attackers from our services.
I decided to upload these lists to a github repo because:
1. They are freely available on the internet. The intention of their creators is to help internet security.
Keep in mind though that a few of these lists may have special licences attached. Before using them, please check their source site for any information regarding proper use.
2. Github provides (via `git pull`) a unified way of updating all the lists together.
Pulling this repo regularly on your machines, you will update all the IP lists at once.
3. Github also provides a unified version control. Using it we can have a history of what each list has
done, which IPs or subnets were added and which were removed.
## DNSBLs
Check also another tool included in FireHOL v3+, called `dnsbl-ipset.sh`.
This tool is capable of creating an ipset based on your traffic by looking up information on DNSBLs and
scoring it according to your preferences.
More information [here](https://github.com/firehol/firehol/wiki/dnsbl-ipset.sh).
---
# Using these ipsets
Please be very careful what you choose to use and how you use it. If you blacklist traffic using these
lists you may end up blocking your users, your customers, even yourself (!) from accessing your services.
1. Go to to the site of each list and read how each list is maintained. You are going to trust these guys for doing their job right.
2. Most sites have either a donation system or commercial lists of higher quality. Try to support them.
3. I have included the TOR network in these lists (`bm_tor`, `dm_tor`, `et_tor`). The TOR network is not necessarily bad and you should not block it if you want to allow your users be anonymous. I have included it because for certain cases, allowing an anonymity network might be a risky thing (such as eCommerce).
4. Apply any blacklist at the internet side of your firewall. Be very careful. The `bogons` and `fullbogons` lists contain private, unrouteable IPs that should not be routed on the internet. If you apply such a blocklist on your DMZ or LAN side, you will be blocked out of your firewall.
5. Always have a whitelist too, containing the IP addresses or subnets you trust. Try to build the rules in such a way that if an IP is in the whitelist, it should not be blocked by these blocklists.
## Which ones to use
### Level 1 - Basic
These are the ones I trust. **Level 1** provides basic security against the most well-known attackers, with the minimum of false positives.
1. **Abuse.ch** lists `feodo`, `palevo`, `sslbl`, `zeus`, `zeus_badips`
These folks are doing a great job tracking crime ware. Their blocklists are very focused.
Keep in mind `zeus` may include some false positives. You can use `zeus_badips` instead.
2. **DShield.org** list `dshield`
It contains the top 20 attacking class C (/24) subnets, over the last three days.
3. **Spamhaus.org** lists `spamhaus_drop`, `spamhaus_edrop`
DROP (Don't Route Or Peer) and EDROP are advisory "drop all traffic" lists, consisting of netblocks that are "hijacked" or leased by professional spam or cyber-crime operations (used for dissemination of malware, trojan downloaders, botnet controllers).
According to Spamhaus.org:
> When implemented at a network or ISP's 'core routers', DROP and EDROP will help protect the network's users from spamming, scanning, harvesting, DNS-hijacking and DDoS attacks originating on rogue netblocks.
>
> Spamhaus strongly encourages the use of DROP and EDROP by tier-1s and backbones.
Spamhaus is very responsive to adapt these lists when a network owner updates them that the issue has been solved (I had one such incident with one of my users).
4. **Team-Cymru.org** list `bogons` or `fullbogons`
These are lists of IPs that should not be routed on the internet. No one should be using them.
Be very careful to apply either of the two on the internet side of your network.
### Level 2 - Essentials
**Level 2** provide protection against current brute force attacks. This level may have a small percentage of false positives, mainly due to dynamic IPs being re-used by other users.
1. **OpenBL.org** lists `openbl*`
The team of OpenBL tracks brute force attacks on their hosts. They have a very short list for hosts, under their own control, collecting this information, to eliminate false positives.
They suggest to use the default blacklist which has a retention policy of 90 days (`openbl`), but they also provide lists with different retention policies (from 1 day to 1 year).
Their goal is to report abuse to the responsible provider so that the infection is disabled.
2. **Blocklist.de** lists `blocklist_de*`
Is a network of users reporting abuse mainly using `fail2ban`. They eliminate false positives using other lists available. Since they collect information from their users, their lists may be subject to poisoning, or false positives.
I asked them about poisoning. [Here](https://forum.blocklist.de/viewtopic.php?f=4&t=244&sid=847d00d26b0735add3518ff515242cad) you can find their answer. In short, they track it down so that they have an ignorable rate of false positives.
Also, they only include individual IPs (no subnets) which have attacked their users the last 48 hours and their list contains 20.000 to 40.000 IPs (which is small enough considering the size of the internet).
Like `openbl`, their goal is to report abuse back, so that the infection is disabled.
They also provide their blocklist per type of attack (mail, web, etc).
Of course, there are more lists included. You can check them and decide if they fit for your needs.
## Why are open proxy lists included
Of course, I haven't included them for you to use the open proxies. The port the proxy is listening, or the type of proxy, are not included (although most of them use the standard proxy ports and do serve web requests).
If you check the comparisons for the open proxy lists (`ri_connect_proxies`, `ri_web_proxies`, `xroxy`, `proxz`, `proxyrss`, etc)
you will find that they overlap to a great degree with other blocklists, like `blocklist_de`, `stopforumspam`, etc.
> This means the attackers also use open proxies to execute attacks.
So, if you are under attack, blocking the open proxies may help isolate a large part of the attack.
I don't suggest to permanently block IPs using the proxy lists. Their purpose of existence is questionable.
Their quality though may be acceptable, since lot of these sites advertise that they test open proxies before including them in their lists, so that there are no false positives, at least at the time they tested them.
---
## Using them in FireHOL
`update-ipsets.sh` itself does not alter your firewall. It can be used to update ipsets both on disk and in the kernel for any firewall solution you use.
The information below, shows you how to configure FireHOL to use the provides ipsets.
### Adding the ipsets in your firehol.conf
I use something like this:
```sh
# our wan interface
wan="dsl0"
# our whitelist
ipset4 create whitelist hash:net
ipset4 add whitelist A.B.C.D/E # A.B.C.D/E is whitelisted
# subnets - netsets
for x in fullbogons dshield spamhaus_drop spamhaus_edrop
do
ipset4 create ${x} hash:net
ipset4 addfile ${x} ipsets/${x}.netset
blacklist4 full inface "${wan}" log "BLACKLIST ${x^^}" ipset:${x} \
except src ipset:whitelist
done
# individual IPs - ipsets
for x in feodo palevo sslbl zeus openbl blocklist_de
do
ipset4 create ${x} hash:ip
ipset4 addfile ${x} ipsets/${x}.ipset
blacklist4 full inface "${wan}" log "BLACKLIST ${x^^}" ipset:${x} \
except src ipset:whitelist
done
... rest of firehol.conf ...
```
If you are concerned about iptables performance, change the `blacklist4` keyword `full` to `input`.
This will block only inbound NEW connections, i.e. only the first packet for every NEW inbound connection will be checked.
All other traffic passes through unchecked.
> Before adding these rules to your `firehol.conf` you should run `update-ipsets.sh` to enable them.
### Updating the ipsets while the firewall is running
Just use the `update-ipsets.sh` script from the firehol distribution.
This script will update each ipset and call firehol to update the ipset while the firewall is running.
> You can add `update-ipsets.sh` to cron, to run every 10 mins. `update-ipsets.sh` is smart enough to download
> a list only when it needs to.
---
# List of ipsets included
The following list was automatically generated on Wed Apr 17 10:22:30 UTC 2024.
The update frequency is the maximum allowed by internal configuration. A list will never be downloaded sooner than the update frequency stated. A list may also not be downloaded, after this frequency expired, if it has not been modified on the server (as reported by HTTP `IF_MODIFIED_SINCE` method).
name|info|type|entries|update|
:--:|:--:|:--:|:-----:|:----:|
[alienvault_reputation](http://iplists.firehol.org/?ipset=alienvault_reputation)|[AlienVault.com](https://www.alienvault.com/) IP reputation database|ipv4 hash:ip|609 unique IPs|updated every 6 hours from [this link](https://reputation.alienvault.com/reputation.generic)
[asprox_c2](http://iplists.firehol.org/?ipset=asprox_c2)|[h3x.eu](http://atrack.h3x.eu/) ASPROX Tracker - Asprox C&C Sites|ipv4 hash:ip|0 unique IPs|updated every 1 day from [this link](http://atrack.h3x.eu/c2)
[bambenek_banjori](http://iplists.firehol.org/?ipset=bambenek_banjori)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of banjori C&Cs with 90 minute lookback|ipv4 hash:ip|136 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/banjori-iplist.txt)
[bambenek_bebloh](http://iplists.firehol.org/?ipset=bambenek_bebloh)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of bebloh C&Cs with 90 minute lookback|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/bebloh-iplist.txt)
[bambenek_c2](http://iplists.firehol.org/?ipset=bambenek_c2)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) master feed of known, active and non-sinkholed C&Cs IP addresses|ipv4 hash:ip|1 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt)
[bambenek_cl](http://iplists.firehol.org/?ipset=bambenek_cl)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of cl C&Cs with 90 minute lookback|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/cl-iplist.txt)
[bambenek_cryptowall](http://iplists.firehol.org/?ipset=bambenek_cryptowall)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of cryptowall C&Cs with 90 minute lookback|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/cryptowall-iplist.txt)
[bambenek_dircrypt](http://iplists.firehol.org/?ipset=bambenek_dircrypt)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of dircrypt C&Cs with 90 minute lookback|ipv4 hash:ip|2 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/dircrypt-iplist.txt)
[bambenek_dyre](http://iplists.firehol.org/?ipset=bambenek_dyre)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of dyre C&Cs with 90 minute lookback|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/dyre-iplist.txt)
[bambenek_geodo](http://iplists.firehol.org/?ipset=bambenek_geodo)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of geodo C&Cs with 90 minute lookback|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/geodo-iplist.txt)
[bambenek_hesperbot](http://iplists.firehol.org/?ipset=bambenek_hesperbot)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of hesperbot C&Cs with 90 minute lookback|ipv4 hash:ip|2 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/hesperbot-iplist.txt)
[bambenek_matsnu](http://iplists.firehol.org/?ipset=bambenek_matsnu)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of matsnu C&Cs with 90 minute lookback|ipv4 hash:ip|1 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/matsnu-iplist.txt)
[bambenek_necurs](http://iplists.firehol.org/?ipset=bambenek_necurs)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of necurs C&Cs with 90 minute lookback|ipv4 hash:ip|13 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/necurs-iplist.txt)
[bambenek_p2pgoz](http://iplists.firehol.org/?ipset=bambenek_p2pgoz)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of p2pgoz C&Cs with 90 minute lookback|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/p2pgoz-iplist.txt)
[bambenek_pushdo](http://iplists.firehol.org/?ipset=bambenek_pushdo)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of pushdo C&Cs with 90 minute lookback|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/pushdo-iplist.txt)
[bambenek_pykspa](http://iplists.firehol.org/?ipset=bambenek_pykspa)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of pykspa C&Cs with 90 minute lookback|ipv4 hash:ip|5 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/pykspa-iplist.txt)
[bambenek_qakbot](http://iplists.firehol.org/?ipset=bambenek_qakbot)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of qakbot C&Cs with 90 minute lookback|ipv4 hash:ip|2 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/qakbot-iplist.txt)
[bambenek_ramnit](http://iplists.firehol.org/?ipset=bambenek_ramnit)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of ramnit C&Cs with 90 minute lookback|ipv4 hash:ip|98 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/ramnit-iplist.txt)
[bambenek_ranbyus](http://iplists.firehol.org/?ipset=bambenek_ranbyus)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of ranbyus C&Cs with 90 minute lookback|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/ranbyus-iplist.txt)
[bambenek_simda](http://iplists.firehol.org/?ipset=bambenek_simda)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of simda C&Cs with 90 minute lookback|ipv4 hash:ip|131 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/simda-iplist.txt)
[bambenek_suppobox](http://iplists.firehol.org/?ipset=bambenek_suppobox)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of suppobox C&Cs with 90 minute lookback|ipv4 hash:ip|108 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/suppobox-iplist.txt)
[bambenek_symmi](http://iplists.firehol.org/?ipset=bambenek_symmi)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of symmi C&Cs with 90 minute lookback|ipv4 hash:ip|1 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/symmi-iplist.txt)
[bambenek_tinba](http://iplists.firehol.org/?ipset=bambenek_tinba)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of tinba C&Cs with 90 minute lookback|ipv4 hash:ip|4 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/tinba-iplist.txt)
[bambenek_volatile](http://iplists.firehol.org/?ipset=bambenek_volatile)|[Bambenek Consulting](http://osint.bambenekconsulting.com/feeds/) feed of current IPs of volatile C&Cs with 90 minute lookback|ipv4 hash:ip|1 unique IPs|updated every 30 mins from [this link](http://osint.bambenekconsulting.com/feeds/volatile-iplist.txt)
[bbcan177_ms1](http://iplists.firehol.org/?ipset=bbcan177_ms1)|pfBlockerNG Malicious Threats|ipv4 hash:net|2688 subnets, 5269973 unique IPs|updated every 1 day from [this link](https://gist.githubusercontent.com/BBcan177/bf29d47ea04391cb3eb0/raw)
[bbcan177_ms3](http://iplists.firehol.org/?ipset=bbcan177_ms3)|pfBlockerNG Malicious Threats|ipv4 hash:net|1146 subnets, 30151694 unique IPs|updated every 1 day from [this link](https://gist.githubusercontent.com/BBcan177/d7105c242f17f4498f81/raw)
[bds_atif](http://iplists.firehol.org/?ipset=bds_atif)|Artillery Threat Intelligence Feed and Banlist Feed|ipv4 hash:ip|437 unique IPs|updated every 1 day from [this link](https://www.binarydefense.com/banlist.txt)
[bitcoin_blockchain_info_1d](http://iplists.firehol.org/?ipset=bitcoin_blockchain_info_1d)|[Blockchain.info](https://blockchain.info/en/connected-nodes) Bitcoin nodes connected to Blockchain.info.|ipv4 hash:ip|988 unique IPs|updated every 10 mins from [this link](https://blockchain.info/en/connected-nodes)
[bitcoin_blockchain_info_30d](http://iplists.firehol.org/?ipset=bitcoin_blockchain_info_30d)|[Blockchain.info](https://blockchain.info/en/connected-nodes) Bitcoin nodes connected to Blockchain.info.|ipv4 hash:ip|8196 unique IPs|updated every 10 mins from [this link](https://blockchain.info/en/connected-nodes)
[bitcoin_blockchain_info_7d](http://iplists.firehol.org/?ipset=bitcoin_blockchain_info_7d)|[Blockchain.info](https://blockchain.info/en/connected-nodes) Bitcoin nodes connected to Blockchain.info.|ipv4 hash:ip|2636 unique IPs|updated every 10 mins from [this link](https://blockchain.info/en/connected-nodes)
[bitcoin_nodes](http://iplists.firehol.org/?ipset=bitcoin_nodes)|[BitNodes](https://getaddr.bitnodes.io/) Bitcoin connected nodes, globally.|ipv4 hash:ip|5547 unique IPs|updated every 10 mins from [this link](https://getaddr.bitnodes.io/api/v1/snapshots/latest/)
[bitcoin_nodes_1d](http://iplists.firehol.org/?ipset=bitcoin_nodes_1d)|[BitNodes](https://getaddr.bitnodes.io/) Bitcoin connected nodes, globally.|ipv4 hash:ip|6539 unique IPs|updated every 10 mins from [this link](https://getaddr.bitnodes.io/api/v1/snapshots/latest/)
[bitcoin_nodes_30d](http://iplists.firehol.org/?ipset=bitcoin_nodes_30d)|[BitNodes](https://getaddr.bitnodes.io/) Bitcoin connected nodes, globally.|ipv4 hash:ip|12597 unique IPs|updated every 10 mins from [this link](https://getaddr.bitnodes.io/api/v1/snapshots/latest/)
[bitcoin_nodes_7d](http://iplists.firehol.org/?ipset=bitcoin_nodes_7d)|[BitNodes](https://getaddr.bitnodes.io/) Bitcoin connected nodes, globally.|ipv4 hash:ip|8229 unique IPs|updated every 10 mins from [this link](https://getaddr.bitnodes.io/api/v1/snapshots/latest/)
[blocklist_de](http://iplists.firehol.org/?ipset=blocklist_de)|[Blocklist.de](https://www.blocklist.de/) IPs that have been detected by fail2ban in the last 48 hours|ipv4 hash:ip|25569 unique IPs|updated every 15 mins from [this link](http://lists.blocklist.de/lists/all.txt)
[blocklist_de_apache](http://iplists.firehol.org/?ipset=blocklist_de_apache)|[Blocklist.de](https://www.blocklist.de/) All IP addresses which have been reported within the last 48 hours as having run attacks on the service Apache, Apache-DDOS, RFI-Attacks.|ipv4 hash:ip|8386 unique IPs|updated every 15 mins from [this link](http://lists.blocklist.de/lists/apache.txt)
[blocklist_de_bots](http://iplists.firehol.org/?ipset=blocklist_de_bots)|[Blocklist.de](https://www.blocklist.de/) All IP addresses which have been reported within the last 48 hours as having run attacks on the RFI-Attacks, REG-Bots, IRC-Bots or BadBots (BadBots = it has posted a Spam-Comment on a open Forum or Wiki).|ipv4 hash:ip|200 unique IPs|updated every 15 mins from [this link](http://lists.blocklist.de/lists/bots.txt)
[blocklist_de_bruteforce](http://iplists.firehol.org/?ipset=blocklist_de_bruteforce)|[Blocklist.de](https://www.blocklist.de/) All IPs which attacks Joomla, Wordpress and other Web-Logins with Brute-Force Logins.|ipv4 hash:ip|339 unique IPs|updated every 15 mins from [this link](http://lists.blocklist.de/lists/bruteforcelogin.txt)
[blocklist_de_ftp](http://iplists.firehol.org/?ipset=blocklist_de_ftp)|[Blocklist.de](https://www.blocklist.de/) All IP addresses which have been reported within the last 48 hours for attacks on the Service FTP.|ipv4 hash:ip|57 unique IPs|updated every 15 mins from [this link](http://lists.blocklist.de/lists/ftp.txt)
[blocklist_de_imap](http://iplists.firehol.org/?ipset=blocklist_de_imap)|[Blocklist.de](https://www.blocklist.de/) All IP addresses which have been reported within the last 48 hours for attacks on the Service imap, sasl, pop3, etc.|ipv4 hash:ip|3004 unique IPs|updated every 15 mins from [this link](http://lists.blocklist.de/lists/imap.txt)
[blocklist_de_mail](http://iplists.firehol.org/?ipset=blocklist_de_mail)|[Blocklist.de](https://www.blocklist.de/) All IP addresses which have been reported within the last 48 hours as having run attacks on the service Mail, Postfix.|ipv4 hash:ip|11552 unique IPs|updated every 15 mins from [this link](http://lists.blocklist.de/lists/mail.txt)
[blocklist_de_sip](http://iplists.firehol.org/?ipset=blocklist_de_sip)|[Blocklist.de](https://www.blocklist.de/) All IP addresses that tried to login in a SIP, VOIP or Asterisk Server and are included in the IPs list from infiltrated.net|ipv4 hash:ip|59 unique IPs|updated every 15 mins from [this link](http://lists.blocklist.de/lists/sip.txt)
[blocklist_de_ssh](http://iplists.firehol.org/?ipset=blocklist_de_ssh)|[Blocklist.de](https://www.blocklist.de/) All IP addresses which have been reported within the last 48 hours as having run attacks on the service SSH.|ipv4 hash:ip|13277 unique IPs|updated every 15 mins from [this link](http://lists.blocklist.de/lists/ssh.txt)
[blocklist_de_strongips](http://iplists.firehol.org/?ipset=blocklist_de_strongips)|[Blocklist.de](https://www.blocklist.de/) All IPs which are older then 2 month and have more then 5.000 attacks.|ipv4 hash:ip|392 unique IPs|updated every 15 mins from [this link](http://lists.blocklist.de/lists/strongips.txt)
[blocklist_net_ua](http://iplists.firehol.org/?ipset=blocklist_net_ua)|[blocklist.net.ua](https://blocklist.net.ua) The BlockList project was created to become protection against negative influence of the harmful and potentially dangerous events on the Internet. First of all this service will help internet and hosting providers to protect subscribers sites from being hacked. BlockList will help to stop receiving a large amount of spam from dubious SMTP relays or from attempts of brute force passwords to servers and network equipment.|ipv4 hash:ip|91676 unique IPs|updated every 10 mins from [this link](https://blocklist.net.ua/blocklist.csv)
[blueliv_crimeserver_last](http://iplists.firehol.org/?ipset=blueliv_crimeserver_last)|[blueliv.com](https://www.blueliv.com/) Last 6 hours Cybercrime IPs, in all categories: BACKDOOR, C_AND_C, EXPLOIT_KIT, MALWARE and PHISHING (to download the source data you need an API key from blueliv.com)|ipv4 hash:ip|24381 unique IPs|updated every 6 hours
[blueliv_crimeserver_last_1d](http://iplists.firehol.org/?ipset=blueliv_crimeserver_last_1d)|[blueliv.com](https://www.blueliv.com/) Last 6 hours Cybercrime IPs, in all categories: BACKDOOR, C_AND_C, EXPLOIT_KIT, MALWARE and PHISHING (to download the source data you need an API key from blueliv.com)|ipv4 hash:ip|58312 unique IPs|updated every 6 hours
[blueliv_crimeserver_last_2d](http://iplists.firehol.org/?ipset=blueliv_crimeserver_last_2d)|[blueliv.com](https://www.blueliv.com/) Last 6 hours Cybercrime IPs, in all categories: BACKDOOR, C_AND_C, EXPLOIT_KIT, MALWARE and PHISHING (to download the source data you need an API key from blueliv.com)|ipv4 hash:ip|71293 unique IPs|updated every 6 hours
[blueliv_crimeserver_last_30d](http://iplists.firehol.org/?ipset=blueliv_crimeserver_last_30d)|[blueliv.com](https://www.blueliv.com/) Last 6 hours Cybercrime IPs, in all categories: BACKDOOR, C_AND_C, EXPLOIT_KIT, MALWARE and PHISHING (to download the source data you need an API key from blueliv.com)|ipv4 hash:ip|87551 unique IPs|updated every 6 hours
[blueliv_crimeserver_last_7d](http://iplists.firehol.org/?ipset=blueliv_crimeserver_last_7d)|[blueliv.com](https://www.blueliv.com/) Last 6 hours Cybercrime IPs, in all categories: BACKDOOR, C_AND_C, EXPLOIT_KIT, MALWARE and PHISHING (to download the source data you need an API key from blueliv.com)|ipv4 hash:ip|77098 unique IPs|updated every 6 hours
[blueliv_crimeserver_online](http://iplists.firehol.org/?ipset=blueliv_crimeserver_online)|[blueliv.com](https://www.blueliv.com/) Online Cybercrime IPs, in all categories: BACKDOOR, C_AND_C, EXPLOIT_KIT, MALWARE and PHISHING (to download the source data you need an API key from blueliv.com)|ipv4 hash:ip|15628 unique IPs|updated every 1 day
[blueliv_crimeserver_recent](http://iplists.firehol.org/?ipset=blueliv_crimeserver_recent)|[blueliv.com](https://www.blueliv.com/) Recent Cybercrime IPs, in all categories: BACKDOOR, C_AND_C, EXPLOIT_KIT, MALWARE and PHISHING (to download the source data you need an API key from blueliv.com)|ipv4 hash:ip|64076 unique IPs|updated every 1 day
bm_tor|[torstatus.blutmagie.de](https://torstatus.blutmagie.de) list of all TOR network servers|ipv4 hash:ip|disabled|updated every 30 mins from [this link](https://torstatus.blutmagie.de/ip_list_all.php/Tor_ip_list_ALL.csv)
[bogons](http://iplists.firehol.org/?ipset=bogons)|[Team-Cymru.org](http://www.team-cymru.org) private and reserved addresses defined by RFC 1918, RFC 5735, and RFC 6598 and netblocks that have not been allocated to a regional internet registry|ipv4 hash:net|13 subnets, 592708608 unique IPs|updated every 1 day
[botscout](http://iplists.firehol.org/?ipset=botscout)|[BotScout](http://botscout.com/) helps prevent automated web scripts, known as bots, from registering on forums, polluting databases, spreading spam, and abusing forms on web sites. They do this by tracking the names, IPs, and email addresses that bots use and logging them as unique signatures for future reference. They also provide a simple yet powerful API that you can use to test forms when they're submitted on your site. This list is composed of the most recently-caught bots.|ipv4 hash:ip|45 unique IPs|updated every 30 mins from [this link](http://botscout.com/last_caught_cache.htm)
[botscout_1d](http://iplists.firehol.org/?ipset=botscout_1d)|[BotScout](http://botscout.com/) helps prevent automated web scripts, known as bots, from registering on forums, polluting databases, spreading spam, and abusing forms on web sites. They do this by tracking the names, IPs, and email addresses that bots use and logging them as unique signatures for future reference. They also provide a simple yet powerful API that you can use to test forms when they're submitted on your site. This list is composed of the most recently-caught bots.|ipv4 hash:ip|748 unique IPs|updated every 30 mins from [this link](http://botscout.com/last_caught_cache.htm)
[botscout_30d](http://iplists.firehol.org/?ipset=botscout_30d)|[BotScout](http://botscout.com/) helps prevent automated web scripts, known as bots, from registering on forums, polluting databases, spreading spam, and abusing forms on web sites. They do this by tracking the names, IPs, and email addresses that bots use and logging them as unique signatures for future reference. They also provide a simple yet powerful API that you can use to test forms when they're submitted on your site. This list is composed of the most recently-caught bots.|ipv4 hash:ip|13846 unique IPs|updated every 30 mins from [this link](http://botscout.com/last_caught_cache.htm)
[botscout_7d](http://iplists.firehol.org/?ipset=botscout_7d)|[BotScout](http://botscout.com/) helps prevent automated web scripts, known as bots, from registering on forums, polluting databases, spreading spam, and abusing forms on web sites. They do this by tracking the names, IPs, and email addresses that bots use and logging them as unique signatures for future reference. They also provide a simple yet powerful API that you can use to test forms when they're submitted on your site. This list is composed of the most recently-caught bots.|ipv4 hash:ip|3976 unique IPs|updated every 30 mins from [this link](http://botscout.com/last_caught_cache.htm)
[botvrij_dst](http://iplists.firehol.org/?ipset=botvrij_dst)|[botvrij.eu](http://www.botvrij.eu/) Indicators of Compromise (IOCS) about malicious destination IPs, gathered via open source information feeds (blog pages and PDF documents) and then consolidated into different datasets. To ensure the quality of the data all entries older than approx. 6 months are removed.|ipv4 hash:ip|143 unique IPs|updated every 1 day from [this link](http://www.botvrij.eu/data/ioclist.ip-dst.raw)
[botvrij_src](http://iplists.firehol.org/?ipset=botvrij_src)|[botvrij.eu](http://www.botvrij.eu/) Indicators of Compromise (IOCS) about malicious source IPs, gathered via open source information feeds (blog pages and PDF documents) and then consolidated into different datasets. To ensure the quality of the data all entries older than approx. 6 months are removed.|ipv4 hash:ip|0 unique IPs|updated every 1 day from [this link](http://www.botvrij.eu/data/ioclist.ip-src.raw)
[bruteforceblocker](http://iplists.firehol.org/?ipset=bruteforceblocker)|[danger.rulez.sk bruteforceblocker](http://danger.rulez.sk/index.php/bruteforceblocker/) (fail2ban alternative for SSH on OpenBSD). This is an automatically generated list from users reporting failed authentication attempts. An IP seems to be included if 3 or more users report it. Its retention pocily seems 30 days.|ipv4 hash:ip|287 unique IPs|updated every 3 hours from [this link](http://danger.rulez.sk/projects/bruteforceblocker/blist.php)
[ciarmy](http://iplists.firehol.org/?ipset=ciarmy)|[CIArmy.com](http://ciarmy.com/) IPs with poor Rogue Packet score that have not yet been identified as malicious by the community|ipv4 hash:ip|15000 unique IPs|updated every 3 hours from [this link](http://cinsscore.com/list/ci-badguys.txt)
[cidr_report_bogons](http://iplists.firehol.org/?ipset=cidr_report_bogons)|Unallocated (Free) Address Space, generated on a daily basis using the IANA registry files, the Regional Internet Registry stats files and the Regional Internet Registry whois data.|ipv4 hash:net|9122 subnets, 603238976 unique IPs|updated every 1 day from [this link](http://www.cidr-report.org/bogons/freespace-prefix.txt)
[cleanmx_phishing](http://iplists.firehol.org/?ipset=cleanmx_phishing)|[Clean-MX.de](http://support.clean-mx.de/) IPs sending phishing messages|ipv4 hash:ip|4519 unique IPs|updated every 30 mins from [this link](http://support.clean-mx.de/clean-mx/xmlphishing?response=alive&format=csv&domain=)
[cleanmx_viruses](http://iplists.firehol.org/?ipset=cleanmx_viruses)|[Clean-MX.de](http://support.clean-mx.de/clean-mx/viruses.php) IPs with viruses|ipv4 hash:ip|12190 unique IPs|updated every 30 mins from [this link](http://support.clean-mx.de/clean-mx/xmlviruses.php?response=alive&fields=ip)
[cleantalk](http://iplists.firehol.org/?ipset=cleantalk)|[CleanTalk](https://cleantalk.org/) Today's HTTP Spammers (includes: cleantalk_new cleantalk_updated)|ipv4 hash:ip|486 unique IPs|updated every 1 min
[cleantalk_1d](http://iplists.firehol.org/?ipset=cleantalk_1d)|[CleanTalk](https://cleantalk.org/) Today's HTTP Spammers (includes: cleantalk_new_1d cleantalk_updated_1d)|ipv4 hash:ip|7695 unique IPs|updated every 1 min
[cleantalk_30d](http://iplists.firehol.org/?ipset=cleantalk_30d)|[CleanTalk](https://cleantalk.org/) Today's HTTP Spammers (includes: cleantalk_new_30d cleantalk_updated_30d)|ipv4 hash:ip|60078 unique IPs|updated every 1 min
[cleantalk_7d](http://iplists.firehol.org/?ipset=cleantalk_7d)|[CleanTalk](https://cleantalk.org/) Today's HTTP Spammers (includes: cleantalk_new_7d cleantalk_updated_7d)|ipv4 hash:ip|24024 unique IPs|updated every 1 min
[cleantalk_new](http://iplists.firehol.org/?ipset=cleantalk_new)|[CleanTalk](https://cleantalk.org/) Recent HTTP Spammers|ipv4 hash:ip|250 unique IPs|updated every 15 mins from [this link](https://cleantalk.org/blacklists/submited_today)
[cleantalk_new_1d](http://iplists.firehol.org/?ipset=cleantalk_new_1d)|[CleanTalk](https://cleantalk.org/) Recent HTTP Spammers|ipv4 hash:ip|853 unique IPs|updated every 15 mins from [this link](https://cleantalk.org/blacklists/submited_today)
[cleantalk_new_30d](http://iplists.firehol.org/?ipset=cleantalk_new_30d)|[CleanTalk](https://cleantalk.org/) Recent HTTP Spammers|ipv4 hash:ip|17108 unique IPs|updated every 15 mins from [this link](https://cleantalk.org/blacklists/submited_today)
[cleantalk_new_7d](http://iplists.firehol.org/?ipset=cleantalk_new_7d)|[CleanTalk](https://cleantalk.org/) Recent HTTP Spammers|ipv4 hash:ip|3812 unique IPs|updated every 15 mins from [this link](https://cleantalk.org/blacklists/submited_today)
[cleantalk_top20](http://iplists.firehol.org/?ipset=cleantalk_top20)|[CleanTalk](https://cleantalk.org/) Top 20 HTTP Spammers|ipv4 hash:ip|20 unique IPs|updated every 1 day from [this link](https://cleantalk.org/blacklists/top20)
[cleantalk_updated](http://iplists.firehol.org/?ipset=cleantalk_updated)|[CleanTalk](https://cleantalk.org/) Recurring HTTP Spammers|ipv4 hash:ip|250 unique IPs|updated every 15 mins from [this link](https://cleantalk.org/blacklists/updated_today)
[cleantalk_updated_1d](http://iplists.firehol.org/?ipset=cleantalk_updated_1d)|[CleanTalk](https://cleantalk.org/) Recurring HTTP Spammers|ipv4 hash:ip|7785 unique IPs|updated every 15 mins from [this link](https://cleantalk.org/blacklists/updated_today)
[cleantalk_updated_30d](http://iplists.firehol.org/?ipset=cleantalk_updated_30d)|[CleanTalk](https://cleantalk.org/) Recurring HTTP Spammers|ipv4 hash:ip|57059 unique IPs|updated every 15 mins from [this link](https://cleantalk.org/blacklists/updated_today)
[cleantalk_updated_7d](http://iplists.firehol.org/?ipset=cleantalk_updated_7d)|[CleanTalk](https://cleantalk.org/) Recurring HTTP Spammers|ipv4 hash:ip|24494 unique IPs|updated every 15 mins from [this link](https://cleantalk.org/blacklists/updated_today)
[coinbl_hosts](http://iplists.firehol.org/?ipset=coinbl_hosts)|[CoinBlockerLists](https://gitlab.com/ZeroDot1/CoinBlockerLists) Simple lists that can help prevent cryptomining in the browser or other applications. This list contains all domains - A list for administrators to prevent mining in networks. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|10429 unique IPs|updated every 1 day from [this link](https://zerodot1.gitlab.io/CoinBlockerLists/hosts)
[coinbl_hosts_browser](http://iplists.firehol.org/?ipset=coinbl_hosts_browser)|[CoinBlockerLists](https://gitlab.com/ZeroDot1/CoinBlockerLists) Simple lists that can help prevent cryptomining in the browser or other applications. A hosts list to prevent browser mining only. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|627 unique IPs|updated every 1 day from [this link](https://zerodot1.gitlab.io/CoinBlockerLists/hosts_browser)
[coinbl_hosts_optional](http://iplists.firehol.org/?ipset=coinbl_hosts_optional)|[CoinBlockerLists](https://gitlab.com/ZeroDot1/CoinBlockerLists) Simple lists that can help prevent cryptomining in the browser or other applications. This list contains additional domains, for administrators to prevent mining in networks. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|471 unique IPs|updated every 1 day from [this link](https://zerodot1.gitlab.io/CoinBlockerLists/hosts_optional)
[coinbl_ips](http://iplists.firehol.org/?ipset=coinbl_ips)|[CoinBlockerLists](https://gitlab.com/ZeroDot1/CoinBlockerLists) Simple lists that can help prevent cryptomining in the browser or other applications. This list contains all IPs - An additional list for administrators to prevent mining in networks. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|1390 unique IPs|updated every 1 day from [this link](https://zerodot1.gitlab.io/CoinBlockerLists/MiningServerIPList.txt)
[cruzit_web_attacks](http://iplists.firehol.org/?ipset=cruzit_web_attacks)|[CruzIt.com](http://www.cruzit.com/wbl.php) IPs of compromised machines scanning for vulnerabilities and DDOS attacks|ipv4 hash:ip|13878 unique IPs|updated every 12 hours from [this link](http://www.cruzit.com/xwbl2txt.php)
[cta_cryptowall](http://iplists.firehol.org/?ipset=cta_cryptowall)|[Cyber Threat Alliance](http://www.cyberthreatalliance.org/cryptowall-dashboard.html) CryptoWall is one of the most lucrative and broad-reaching ransomware campaigns affecting Internet users today. Sharing intelligence and analysis resources, the CTA profiled the latest version of CryptoWall, which impacted hundreds of thousands of users, resulting in over US $325 million in damages worldwide.|ipv4 hash:ip|1360 unique IPs|updated every 1 day from [this link](https://public.tableau.com/views/CTAOnlineViz/DashboardData.csv?:embed=y&:showVizHome=no&:showTabs=y&:display_count=y&:display_static_image=y&:bootstrapWhenNotified=true)
[cybercrime](http://iplists.firehol.org/?ipset=cybercrime)|[CyberCrime](http://cybercrime-tracker.net/) A project tracking Command and Control.|ipv4 hash:ip|1254 unique IPs|updated every 12 hours from [this link](http://cybercrime-tracker.net/fuckerz.php)
[darklist_de](http://iplists.firehol.org/?ipset=darklist_de)|[darklist.de](http://www.darklist.de/) ssh fail2ban reporting|ipv4 hash:net|6008 subnets, 274857 unique IPs|updated every 1 day from [this link](http://www.darklist.de/raw.php)
[datacenters](http://iplists.firehol.org/?ipset=datacenters)|[Nick Galbreath](https://github.com/client9/ipcat) This is a list of IPv4 address that correspond to datacenters, co-location centers, shared and virtual webhosting providers. In other words, ip addresses that end web consumers should not be using.|ipv4 hash:net|4224 subnets, 95959476 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/client9/ipcat/master/datacenters.csv)
[dataplane_dnsrd](http://iplists.firehol.org/?ipset=dataplane_dnsrd)|[DataPlane.org](https://dataplane.org/) IP addresses that have been identified as sending recursive DNS queries to a remote host. This report lists addresses that may be cataloging open DNS resolvers or evaluating cache entries.|ipv4 hash:ip|3999 unique IPs|updated every 1 hour
[dataplane_dnsrdany](http://iplists.firehol.org/?ipset=dataplane_dnsrdany)|[DataPlane.org](https://dataplane.org/) IP addresses that have been identified as sending recursive DNS IN ANY queries to a remote host. This report lists addresses that may be cataloging open DNS resolvers for the purpose of later using them to facilitate DNS amplification and reflection attacks.|ipv4 hash:ip|62 unique IPs|updated every 1 hour
[dataplane_dnsversion](http://iplists.firehol.org/?ipset=dataplane_dnsversion)|[DataPlane.org](https://dataplane.org/) IP addresses that have been identified as sending DNS CH TXT VERSION.BIND queries to a remote host. This report lists addresses that may be cataloging DNS software.|ipv4 hash:ip|3471 unique IPs|updated every 1 hour
[dataplane_sipinvitation](http://iplists.firehol.org/?ipset=dataplane_sipinvitation)|[DataPlane.org](https://dataplane.org/) IP addresses that have been seen initiating a SIP INVITE operation to a remote host. This report lists hosts that are suspicious of more than just port scanning. These hosts may be SIP client cataloging or conducting various forms of telephony abuse.|ipv4 hash:ip|26 unique IPs|updated every 1 hour
[dataplane_sipquery](http://iplists.firehol.org/?ipset=dataplane_sipquery)|[DataPlane.org](https://dataplane.org/) IP addresses that has been seen initiating a SIP OPTIONS query to a remote host. This report lists hosts that are suspicious of more than just port scanning. These hosts may be SIP server cataloging or conducting various forms of telephony abuse.|ipv4 hash:ip|2698 unique IPs|updated every 1 hour
[dataplane_sipregistration](http://iplists.firehol.org/?ipset=dataplane_sipregistration)|[DataPlane.org](https://dataplane.org/) IP addresses that have been seen initiating a SIP REGISTER operation to a remote host. This report lists hosts that are suspicious of more than just port scanning. These hosts may be SIP client cataloging or conducting various forms of telephony abuse.|ipv4 hash:ip|179 unique IPs|updated every 1 hour
[dataplane_sshclient](http://iplists.firehol.org/?ipset=dataplane_sshclient)|[DataPlane.org](https://dataplane.org/) IP addresses that has been seen initiating an SSH connection to a remote host. This report lists hosts that are suspicious of more than just port scanning. These hosts may be SSH server cataloging or conducting authentication attack attempts.|ipv4 hash:ip|30295 unique IPs|updated every 1 hour
[dataplane_sshpwauth](http://iplists.firehol.org/?ipset=dataplane_sshpwauth)|[DataPlane.org](https://dataplane.org/) IP addresses that has been seen attempting to remotely login to a host using SSH password authentication. This report lists hosts that are highly suspicious and are likely conducting malicious SSH password authentication attacks.|ipv4 hash:ip|23869 unique IPs|updated every 1 hour
[dataplane_vncrfb](http://iplists.firehol.org/?ipset=dataplane_vncrfb)|[DataPlane.org](https://dataplane.org/) IP addresses that have been seen initiating a VNC remote frame buffer (RFB) session to a remote host. This report lists hosts that are suspicious of more than just port scanning. These hosts may be VNC server cataloging or conducting various forms of remote access abuse.|ipv4 hash:ip|2766 unique IPs|updated every 1 hour
[dm_tor](http://iplists.firehol.org/?ipset=dm_tor)|[dan.me.uk](https://www.dan.me.uk) dynamic list of TOR nodes|ipv4 hash:ip|5849 unique IPs|updated every 30 mins from [this link](https://www.dan.me.uk/torlist/)
[dronebl_anonymizers](http://iplists.firehol.org/?ipset=dronebl_anonymizers)|[DroneBL.org](https://dronebl.org) List of open proxies. It includes IPs which DroneBL categorizes as SOCKS proxies (8), HTTP proxies (9), web page proxies (11), WinGate proxies (14), proxy chains (10).|ipv4 hash:net|1118407 subnets, 1208748 unique IPs|updated every 1 min
[dronebl_auto_botnets](http://iplists.firehol.org/?ipset=dronebl_auto_botnets)|[DroneBL.org](https://dronebl.org) IPs of automatically detected botnets. It includes IPs for which DroneBL responds with 17.|ipv4 hash:net|3992 subnets, 4007 unique IPs|updated every 1 min
[dronebl_autorooting_worms](http://iplists.firehol.org/?ipset=dronebl_autorooting_worms)|[DroneBL.org](https://dronebl.org) IPs of autorooting worms. It includes IPs for which DroneBL responds with 16. These are usually SSH bruteforce attacks.|ipv4 hash:net|36 subnets, 36 unique IPs|updated every 1 min
[dronebl_compromised](http://iplists.firehol.org/?ipset=dronebl_compromised)|[DroneBL.org](https://dronebl.org) IPs of compromised routers / gateways. It includes IPs for which DroneBL responds with 15 (BOPM detected).|ipv4 hash:net|44313 subnets, 45774 unique IPs|updated every 1 min
[dronebl_ddos_drones](http://iplists.firehol.org/?ipset=dronebl_ddos_drones)|[DroneBL.org](https://dronebl.org) IPs of DDoS drones. It includes IPs for which DroneBL responds with 7.|ipv4 hash:net|7675 subnets, 7834 unique IPs|updated every 1 min
[dronebl_dns_mx_on_irc](http://iplists.firehol.org/?ipset=dronebl_dns_mx_on_irc)|[DroneBL.org](https://dronebl.org) List of IPs of DNS / MX hostname detected on IRC. It includes IPs for which DroneBL responds with 18.|ipv4 hash:net|18 subnets, 18 unique IPs|updated every 1 min
[dronebl_irc_drones](http://iplists.firehol.org/?ipset=dronebl_irc_drones)|[DroneBL.org](https://dronebl.org) List of IRC spam drones (litmus/sdbot/fyle). It includes IPs for which DroneBL responds with 3.|ipv4 hash:net|813326 subnets, 982885 unique IPs|updated every 1 min
[dronebl_unknown](http://iplists.firehol.org/?ipset=dronebl_unknown)|[DroneBL.org](https://dronebl.org) List of IPs of uncategorized threats. It includes IPs for which DroneBL responds with 255.|ipv4 hash:net|152 subnets, 152 unique IPs|updated every 1 min
[dronebl_worms_bots](http://iplists.firehol.org/?ipset=dronebl_worms_bots)|[DroneBL.org](https://dronebl.org) IPs of unknown worms or spambots. It includes IPs for which DroneBL responds with 6|ipv4 hash:net|164674 subnets, 174494 unique IPs|updated every 1 min
[dshield](http://iplists.firehol.org/?ipset=dshield)|[DShield.org](https://dshield.org/) top 20 attacking class C (/24) subnets over the last three days|ipv4 hash:net|19 subnets, 5120 unique IPs|updated every 10 mins from [this link](http://feeds.dshield.org/block.txt)
[dshield_1d](http://iplists.firehol.org/?ipset=dshield_1d)|[DShield.org](https://dshield.org/) top 20 attacking class C (/24) subnets over the last three days|ipv4 hash:net|21 subnets, 5632 unique IPs|updated every 10 mins from [this link](http://feeds.dshield.org/block.txt)
[dshield_30d](http://iplists.firehol.org/?ipset=dshield_30d)|[DShield.org](https://dshield.org/) top 20 attacking class C (/24) subnets over the last three days|ipv4 hash:net|42 subnets, 11776 unique IPs|updated every 10 mins from [this link](http://feeds.dshield.org/block.txt)
[dshield_7d](http://iplists.firehol.org/?ipset=dshield_7d)|[DShield.org](https://dshield.org/) top 20 attacking class C (/24) subnets over the last three days|ipv4 hash:net|29 subnets, 7936 unique IPs|updated every 10 mins from [this link](http://feeds.dshield.org/block.txt)
[dshield_top_1000](http://iplists.firehol.org/?ipset=dshield_top_1000)|[DShield.org](https://dshield.org/) top 1000 attacking hosts in the last 30 days|ipv4 hash:ip|1000 unique IPs|updated every 1 hour from [this link](https://isc.sans.edu/api/sources/attacks/1000/)
[dyndns_ponmocup](http://iplists.firehol.org/?ipset=dyndns_ponmocup)|[DynDNS.org](http://security-research.dyndns.org/pub/malware-feeds/) Ponmocup. The malware powering the botnet has been around since 2006 and its known under various names, including Ponmocup, Vundo, Virtumonde, Milicenso and Swisyn. It has been used for ad fraud, data theft and downloading additional threats to infected systems. Ponmocup is one of the largest currently active and, with nine consecutive years, also one of the longest running, but it is rarely noticed as the operators take care to keep it operating under the radar.|ipv4 hash:ip|39 unique IPs|updated every 1 day from [this link](http://security-research.dyndns.org/pub/malware-feeds/ponmocup-infected-domains-shadowserver.csv)
[esentire_14072015_com](http://iplists.firehol.org/?ipset=esentire_14072015_com)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|579 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/14072015.com_watch_ip.lst)
[esentire_14072015q_com](http://iplists.firehol.org/?ipset=esentire_14072015q_com)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|575 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/14072015q.com_watch_ip.lst)
[esentire_22072014a_com](http://iplists.firehol.org/?ipset=esentire_22072014a_com)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|1290 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/22072014a.com_watch_ip.lst)
[esentire_22072014b_com](http://iplists.firehol.org/?ipset=esentire_22072014b_com)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|1288 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/22072014b.com_watch_ip.lst)
[esentire_22072014c_com](http://iplists.firehol.org/?ipset=esentire_22072014c_com)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|1289 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/22072014c.com_watch_ip.lst)
[esentire_atomictrivia_ru](http://iplists.firehol.org/?ipset=esentire_atomictrivia_ru)|Andromeda/Gamarue Checkin|ipv4 hash:ip|7 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/atomictrivia.ru_watch_ip.lst)
[esentire_auth_update_ru](http://iplists.firehol.org/?ipset=esentire_auth_update_ru)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|1306 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/auth-update.ru_watch_ip.lst)
[esentire_burmundisoul_ru](http://iplists.firehol.org/?ipset=esentire_burmundisoul_ru)|Ursnif Variant CnC|ipv4 hash:ip|2551 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/burmundisoul.ru_watch_ip.lst)
[esentire_crazyerror_su](http://iplists.firehol.org/?ipset=esentire_crazyerror_su)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|18613 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/crazyerror.su_watch_ip.lst)
[esentire_dagestanskiiviskis_ru](http://iplists.firehol.org/?ipset=esentire_dagestanskiiviskis_ru)|Ursnif Variant CnC|ipv4 hash:ip|517 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/dagestanskiiviskis.ru_watch_ip.lst)
[esentire_differentia_ru](http://iplists.firehol.org/?ipset=esentire_differentia_ru)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|12 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/differentia.ru_watch_ip.lst)
[esentire_disorderstatus_ru](http://iplists.firehol.org/?ipset=esentire_disorderstatus_ru)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|7 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/disorderstatus.ru_watch_ip.lst)
[esentire_dorttlokolrt_com](http://iplists.firehol.org/?ipset=esentire_dorttlokolrt_com)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|23664 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/dorttlokolrt.com_watch_ip.lst)
[esentire_downs1_ru](http://iplists.firehol.org/?ipset=esentire_downs1_ru)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|7231 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/downs1.ru_watch_ip.lst)
[esentire_ebankoalalusys_ru](http://iplists.firehol.org/?ipset=esentire_ebankoalalusys_ru)|Ursnif Variant CnC|ipv4 hash:ip|898 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/ebankoalalusys.ru_watch_ip.lst)
[esentire_emptyarray_ru](http://iplists.firehol.org/?ipset=esentire_emptyarray_ru)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|20139 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/emptyarray.ru_watch_ip.lst)
[esentire_fioartd_com](http://iplists.firehol.org/?ipset=esentire_fioartd_com)|Andromeda/Gamarue Checkin|ipv4 hash:ip|601 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/fioartd.com_watch_ip.lst)
[esentire_getarohirodrons_com](http://iplists.firehol.org/?ipset=esentire_getarohirodrons_com)|Andromeda/Gamarue Checkin|ipv4 hash:ip|2156 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/getarohirodrons.com_watch_ip.lst)
[esentire_hasanhashsde_ru](http://iplists.firehol.org/?ipset=esentire_hasanhashsde_ru)|Ursnif Variant CnC|ipv4 hash:ip|1184 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/hasanhashsde.ru_watch_ip.lst)
[esentire_inleet_ru](http://iplists.firehol.org/?ipset=esentire_inleet_ru)|Ursnif Variant CnC|ipv4 hash:ip|4219 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/inleet.ru_watch_ip.lst)
[esentire_islamislamdi_ru](http://iplists.firehol.org/?ipset=esentire_islamislamdi_ru)|Ursnif Variant CnC|ipv4 hash:ip|673 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/islamislamdi.ru_watch_ip.lst)
[esentire_krnqlwlplttc_com](http://iplists.firehol.org/?ipset=esentire_krnqlwlplttc_com)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|2 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/krnqlwlplttc.com_watch_ip.lst)
[esentire_maddox1_ru](http://iplists.firehol.org/?ipset=esentire_maddox1_ru)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|11345 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/maddox1.ru_watch_ip.lst)
[esentire_manning1_ru](http://iplists.firehol.org/?ipset=esentire_manning1_ru)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|6824 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/manning1.ru_watch_ip.lst)
[esentire_misteryherson_ru](http://iplists.firehol.org/?ipset=esentire_misteryherson_ru)|Ursnif Variant CnC|ipv4 hash:ip|176 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/misteryherson.ru_watch_ip.lst)
[esentire_mysebstarion_ru](http://iplists.firehol.org/?ipset=esentire_mysebstarion_ru)|Ursnif Variant CnC|ipv4 hash:ip|1058 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/mysebstarion.ru_watch_ip.lst)
[esentire_smartfoodsglutenfree_kz](http://iplists.firehol.org/?ipset=esentire_smartfoodsglutenfree_kz)|Malicious Botnet Serving Various Malware Families|ipv4 hash:ip|2674 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/smartfoodsglutenfree.kz_watch_ip.lst)
[esentire_venerologvasan93_ru](http://iplists.firehol.org/?ipset=esentire_venerologvasan93_ru)|Ursnif Variant CnC|ipv4 hash:ip|1263 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/venerologvasan93.ru_watch_ip.lst)
[esentire_volaya_ru](http://iplists.firehol.org/?ipset=esentire_volaya_ru)|Win32/PSW.Papras.CK CnC|ipv4 hash:ip|5080 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/eSentire/malfeed/master/volaya.ru_watch_ip.lst)
[et_block](http://iplists.firehol.org/?ipset=et_block)|[EmergingThreats.net](http://www.emergingthreats.net/) default blacklist (at the time of writing includes spamhaus DROP, dshield and abuse.ch trackers, which are available separately too - prefer to use the direct ipsets instead of this, they seem to lag a bit in updates)|ipv4 hash:net|1347 subnets, 16334605 unique IPs|updated every 12 hours from [this link](http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt)
[et_botcc](http://iplists.firehol.org/?ipset=et_botcc)|[EmergingThreats.net Command and Control IPs](http://doc.emergingthreats.net/bin/view/Main/BotCC) These IPs are updates every 24 hours and should be considered VERY highly reliable indications that a host is communicating with a known and active Bot or Malware command and control server - (although they say this includes abuse.ch trackers, it does not - check its overlaps)|ipv4 hash:ip|67 unique IPs|updated every 12 hours from [this link](http://rules.emergingthreats.net/fwrules/emerging-PIX-CC.rules)
[et_compromised](http://iplists.firehol.org/?ipset=et_compromised)|[EmergingThreats.net compromised hosts](http://doc.emergingthreats.net/bin/view/Main/CompromisedHost)|ipv4 hash:ip|287 unique IPs|updated every 12 hours from [this link](http://rules.emergingthreats.net/blockrules/compromised-ips.txt)
[et_dshield](http://iplists.firehol.org/?ipset=et_dshield)|[EmergingThreats.net](http://www.emergingthreats.net/) dshield blocklist|ipv4 hash:net|19 subnets, 5120 unique IPs|updated every 12 hours from [this link](http://rules.emergingthreats.net/fwrules/emerging-PIX-DSHIELD.rules)
[et_spamhaus](http://iplists.firehol.org/?ipset=et_spamhaus)|[EmergingThreats.net](http://www.emergingthreats.net/) spamhaus blocklist|ipv4 hash:net|1319 subnets, 16330240 unique IPs|updated every 12 hours from [this link](http://rules.emergingthreats.net/fwrules/emerging-PIX-DROP.rules)
[et_tor](http://iplists.firehol.org/?ipset=et_tor)|[EmergingThreats.net TOR list](http://doc.emergingthreats.net/bin/view/Main/TorRules) of TOR network IPs|ipv4 hash:ip|6037 unique IPs|updated every 12 hours from [this link](http://rules.emergingthreats.net/blockrules/emerging-tor.rules)
[feodo](http://iplists.firehol.org/?ipset=feodo)|[Abuse.ch Feodo tracker](https://feodotracker.abuse.ch) trojan includes IPs which are being used by Feodo (also known as Cridex or Bugat) which commits ebanking fraud|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](https://feodotracker.abuse.ch/blocklist/?download=ipblocklist)
[feodo_badips](http://iplists.firehol.org/?ipset=feodo_badips)|[Abuse.ch Feodo tracker BadIPs](https://feodotracker.abuse.ch) The Feodo Tracker Feodo BadIP Blocklist only contains IP addresses (IPv4) used as C&C communication channel by the Feodo Trojan version B. These IP addresses are usually servers rented by cybercriminals directly and used for the exclusive purpose of hosting a Feodo C&C server. Hence you should expect no legit traffic to those IP addresses. The site highly recommends you to block/drop any traffic towards any Feodo C&C using the Feodo BadIP Blocklist. Please consider that this blocklist only contains IP addresses used by version B of the Feodo Trojan. C&C communication channels used by version A, version C and version D are not covered by this blocklist.|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](https://feodotracker.abuse.ch/blocklist/?download=badips)
[firehol_abusers_1d](http://iplists.firehol.org/?ipset=firehol_abusers_1d)|An ipset made from blocklists that track abusers in the last 24 hours. (includes: botscout_1d cleantalk_new_1d cleantalk_updated_1d php_commenters_1d php_dictionary_1d php_harvesters_1d php_spammers_1d stopforumspam_1d)|ipv4 hash:net|12604 subnets, 13095 unique IPs|updated every 1 min
[firehol_abusers_30d](http://iplists.firehol.org/?ipset=firehol_abusers_30d)|An ipset made from blocklists that track abusers in the last 30 days. (includes: cleantalk_new_30d cleantalk_updated_30d php_commenters_30d php_dictionary_30d php_harvesters_30d php_spammers_30d stopforumspam sblam)|ipv4 hash:net|185514 subnets, 203029 unique IPs|updated every 1 min
[firehol_anonymous](http://iplists.firehol.org/?ipset=firehol_anonymous)|An ipset that includes all the anonymizing IPs of the world. (includes: anonymous dm_tor firehol_proxies tor_exits)|ipv4 hash:net|967813 subnets, 1100049 unique IPs|updated every 1 min
[firehol_level1](http://iplists.firehol.org/?ipset=firehol_level1)|A firewall blacklist composed from IP lists, providing maximum protection with minimum false positives. Suitable for basic protection on all internet facing servers, routers and firewalls. (includes: bambenek_c2 dshield feodo fullbogons spamhaus_drop spamhaus_edrop sslbl ransomware_rw)|ipv4 hash:net|2195 subnets, 612627456 unique IPs|updated every 1 min
[firehol_level2](http://iplists.firehol.org/?ipset=firehol_level2)|An ipset made from blocklists that track attacks, during about the last 48 hours. (includes: blocklist_de dshield_1d greensnow)|ipv4 hash:net|19648 subnets, 33702 unique IPs|updated every 1 min
[firehol_level3](http://iplists.firehol.org/?ipset=firehol_level3)|An ipset made from blocklists that track attacks, spyware, viruses. It includes IPs than have been reported or detected in the last 30 days. (includes: bruteforceblocker ciarmy dshield_30d dshield_top_1000 malc0de maxmind_proxy_fraud myip shunlist snort_ipfilter sslbl_aggressive talosintel_ipfilter vxvault)|ipv4 hash:net|16721 subnets, 31017 unique IPs|updated every 1 min
[firehol_level4](http://iplists.firehol.org/?ipset=firehol_level4)|An ipset made from blocklists that track attacks, but may include a large number of false positives. (includes: blocklist_net_ua botscout_30d cruzit_web_attacks cybercrime haley_ssh iblocklist_hijacked iblocklist_spyware iblocklist_webexploit ipblacklistcloud_top iw_wormlist malwaredomainlist)|ipv4 hash:net|156391 subnets, 9252376 unique IPs|updated every 1 min
[firehol_proxies](http://iplists.firehol.org/?ipset=firehol_proxies)|An ipset made from all sources that track open proxies. It includes IPs reported or detected in the last 30 days. (includes: iblocklist_proxies maxmind_proxy_fraud ip2proxy_px1lite proxylists_30d proxz_30d socks_proxy_30d sslproxies_30d xroxy_30d)|ipv4 hash:net|962552 subnets, 1088376 unique IPs|updated every 1 min
[firehol_webclient](http://iplists.firehol.org/?ipset=firehol_webclient)|An IP blacklist made from blocklists that track IPs that a web client should never talk to. This list is to be used on top of firehol_level1. (includes: ransomware_online sslbl_aggressive cybercrime dyndns_ponmocup maxmind_proxy_fraud)|ipv4 hash:net|1715 subnets, 1876 unique IPs|updated every 1 min
[firehol_webserver](http://iplists.firehol.org/?ipset=firehol_webserver)|A web server IP blacklist made from blocklists that track IPs that should never be used by your web users. (This list includes IPs that are servers hosting malware, bots, etc or users having a long criminal history. This list is to be used on top of firehol_level1, firehol_level2, firehol_level3 and possibly firehol_proxies or firehol_anonymous). (includes: maxmind_proxy_fraud myip pushing_inertia_blocklist stopforumspam_toxic)|ipv4 hash:net|2375 subnets, 60487685 unique IPs|updated every 1 min
[fullbogons](http://iplists.firehol.org/?ipset=fullbogons)|[Team-Cymru.org](http://www.team-cymru.org) IP space that has been allocated to an RIR, but not assigned by that RIR to an actual ISP or other end-user|ipv4 hash:net|863 subnets, 596288000 unique IPs|updated every 1 day
geolite2_asn|[MaxMind GeoLite2 ASN](https://dev.maxmind.com/geoip/geoip2/geolite2/)|ipv4 hash:net|disabled|updated every 7 days from [this link](http://geolite.maxmind.com/download/geoip/database/GeoLite2-ASN-CSV.zip)
[geolite2_country](https://github.com/firehol/blocklist-ipsets/tree/master/geolite2_country)|[MaxMind GeoLite2](http://dev.maxmind.com/geoip/geoip2/geolite2/) databases are free IP geolocation databases comparable to, but less accurate than, MaxMinds GeoIP2 databases. They include IPs per country, IPs per continent, IPs used by anonymous services (VPNs, Proxies, etc) and Satellite Providers.|ipv4 hash:net|All the world|updated every 7 days from [this link](http://geolite.maxmind.com/download/geoip/database/GeoLite2-Country-CSV.zip)
gofferje_sip|[Stefan Gofferje](http://stefan.gofferje.net/it-stuff/sipfraud/sip-attacker-blacklist) A personal blacklist of networks and IPs of SIP attackers. To end up here, the IP or network must have been the origin of considerable and repeated attacks on my PBX and additionally, the ISP didn't react to any complaint. Note from the author: I don't give any guarantees of accuracy, completeness or even usability! USE AT YOUR OWN RISK! Also note that I block complete countries, namely China, Korea and Palestine with blocklists from ipdeny.com, so some attackers will never even get the chance to get noticed by me to be put on this blacklist. I also don't accept any liabilities related to this blocklist. If you're an ISP and don't like your IPs being listed here, too bad! You should have done something about your customers' behavior and reacted to my complaints. This blocklist is nothing but an expression of my personal opinion and exercising my right of free speech.|ipv4 hash:net|disabled|updated every 6 hours from [this link](http://stefan.gofferje.net/sipblocklist.zone)
[gpf_comics](http://iplists.firehol.org/?ipset=gpf_comics)|The GPF DNS Block List is a list of IP addresses on the Internet that have attacked the [GPF Comics](http://www.gpf-comics.com/) family of Web sites. IPs on this block list have been banned from accessing all of our servers because they were caught in the act of spamming, attempting to exploit our scripts, scanning for vulnerabilities, or consuming resources to the detriment of our human visitors.|ipv4 hash:ip|2905 unique IPs|updated every 1 day from [this link](https://www.gpf-comics.com/dnsbl/export.php)
[graphiclineweb](http://iplists.firehol.org/?ipset=graphiclineweb)|[GraphiclineWeb](https://graphiclineweb.wordpress.com/tech-notes/ip-blacklist/) The IPs, Hosts and Domains listed in this table are banned universally from accessing websites controlled by the maintainer. Some form of bad activity has been seen from the addresses listed. Bad activity includes: unwanted spiders, rule breakers, comment spammers, trackback spammers, spambots, hacker bots, registration bots and other scripting attackers, harvesters, nuisance spiders, spy bots and organizations spying on websites for commercial reasons.|ipv4 hash:net|2579 subnets, 330527 unique IPs|updated every 1 day from [this link](https://graphiclineweb.wordpress.com/tech-notes/ip-blacklist/)
[greensnow](http://iplists.firehol.org/?ipset=greensnow)|[GreenSnow](https://greensnow.co/) is a team harvesting a large number of IPs from different computers located around the world. GreenSnow is comparable with SpamHaus.org for attacks of any kind except for spam. Their list is updated automatically and you can withdraw at any time your IP address if it has been listed. Attacks / bruteforce that are monitored are: Scan Port, FTP, POP3, mod_security, IMAP, SMTP, SSH, cPanel, etc.|ipv4 hash:ip|8155 unique IPs|updated every 30 mins from [this link](http://blocklist.greensnow.co/greensnow.txt)
[haley_ssh](http://iplists.firehol.org/?ipset=haley_ssh)|[Charles Haley](http://charles.the-haleys.org) IPs launching SSH dictionary attacks.|ipv4 hash:ip|50957 unique IPs|updated every 4 hours from [this link](http://charles.the-haleys.org/ssh_dico_attack_hdeny_format.php/hostsdeny.txt)
[hphosts_ats](http://iplists.firehol.org/?ipset=hphosts_ats)|[hpHosts](http://hosts-file.net/?s=Download) ad/tracking servers listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|13037 unique IPs|updated every 1 day from [this link](http://hosts-file.net/ad_servers.txt)
[hphosts_emd](http://iplists.firehol.org/?ipset=hphosts_emd)|[hpHosts](http://hosts-file.net/?s=Download) malware sites listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|59204 unique IPs|updated every 1 day from [this link](http://hosts-file.net/emd.txt)
[hphosts_exp](http://iplists.firehol.org/?ipset=hphosts_exp)|[hpHosts](http://hosts-file.net/?s=Download) exploit sites listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|196 unique IPs|updated every 1 day from [this link](http://hosts-file.net/exp.txt)
[hphosts_fsa](http://iplists.firehol.org/?ipset=hphosts_fsa)|[hpHosts](http://hosts-file.net/?s=Download) fraud sites listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|24764 unique IPs|updated every 1 day from [this link](http://hosts-file.net/fsa.txt)
[hphosts_grm](http://iplists.firehol.org/?ipset=hphosts_grm)|[hpHosts](http://hosts-file.net/?s=Download) sites involved in spam (that do not otherwise meet any other classification criteria) listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|293 unique IPs|updated every 1 day from [this link](http://hosts-file.net/grm.txt)
[hphosts_hfs](http://iplists.firehol.org/?ipset=hphosts_hfs)|[hpHosts](http://hosts-file.net/?s=Download) sites spamming the hpHosts forums (and not meeting any other classification criteria) listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|245 unique IPs|updated every 1 day from [this link](http://hosts-file.net/hfs.txt)
[hphosts_hjk](http://iplists.firehol.org/?ipset=hphosts_hjk)|[hpHosts](http://hosts-file.net/?s=Download) hijack sites listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|152 unique IPs|updated every 1 day from [this link](http://hosts-file.net/hjk.txt)
[hphosts_mmt](http://iplists.firehol.org/?ipset=hphosts_mmt)|[hpHosts](http://hosts-file.net/?s=Download) sites involved in misleading marketing (e.g. fake Flash update adverts) listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|960 unique IPs|updated every 1 day from [this link](http://hosts-file.net/mmt.txt)
[hphosts_pha](http://iplists.firehol.org/?ipset=hphosts_pha)|[hpHosts](http://hosts-file.net/?s=Download) illegal pharmacy sites listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|2474 unique IPs|updated every 1 day from [this link](http://hosts-file.net/pha.txt)
[hphosts_psh](http://iplists.firehol.org/?ipset=hphosts_psh)|[hpHosts](http://hosts-file.net/?s=Download) phishing sites listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|44781 unique IPs|updated every 1 day from [this link](http://hosts-file.net/psh.txt)
[hphosts_wrz](http://iplists.firehol.org/?ipset=hphosts_wrz)|[hpHosts](http://hosts-file.net/?s=Download) warez/piracy sites listed in the hpHosts database. The maintainer's file contains hostnames, which have been DNS resolved to IP addresses.|ipv4 hash:ip|905 unique IPs|updated every 1 day from [this link](http://hosts-file.net/wrz.txt)
[iblocklist_abuse_palevo](http://iplists.firehol.org/?ipset=iblocklist_abuse_palevo)|palevotracker.abuse.ch IP blocklist.|ipv4 hash:net|12 subnets, 12 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=erqajhwrxiuvjxqrrwfj&fileformat=p2p&archiveformat=gz)
[iblocklist_abuse_spyeye](http://iplists.firehol.org/?ipset=iblocklist_abuse_spyeye)|spyeyetracker.abuse.ch IP blocklist.|ipv4 hash:net|83 subnets, 84 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=zvjxsfuvdhoxktpeiokq&fileformat=p2p&archiveformat=gz)
[iblocklist_abuse_zeus](http://iplists.firehol.org/?ipset=iblocklist_abuse_zeus)|zeustracker.abuse.ch IP blocklist that contains IP addresses which are currently beeing tracked on the abuse.ch ZeuS Tracker.|ipv4 hash:net|209 subnets, 212 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=ynkdjqsjyfmilsgbogqf&fileformat=p2p&archiveformat=gz)
[iblocklist_ads](http://iplists.firehol.org/?ipset=iblocklist_ads)|Advertising trackers and a short list of bad/intrusive porn sites.|ipv4 hash:net|3389 subnets, 888873 unique IPs|updated every 12 hours
[iblocklist_badpeers](http://iplists.firehol.org/?ipset=iblocklist_badpeers)|IPs that have been reported for bad deeds in p2p.|ipv4 hash:net|48578 subnets, 1569289 unique IPs|updated every 12 hours
[iblocklist_bogons](http://iplists.firehol.org/?ipset=iblocklist_bogons)|Unallocated address space.|ipv4 hash:net|2692 subnets, 645673639 unique IPs|updated every 12 hours
[iblocklist_ciarmy_malicious](http://iplists.firehol.org/?ipset=iblocklist_ciarmy_malicious)|ciarmy.com IP blocklist. Based on information from a network of Sentinel devices deployed around the world, they compile a list of known bad IP addresses. Sentinel devices are uniquely positioned to pick up traffic from bad guys without requiring any type of signature-based or rate-based identification. If an IP is identified in this way by a significant number of Sentinels, the IP is malicious and should be blocked.|ipv4 hash:net|12936 subnets, 15000 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=npkuuhuxcsllnhoamkvm&fileformat=p2p&archiveformat=gz)
[iblocklist_cidr_report_bogons](http://iplists.firehol.org/?ipset=iblocklist_cidr_report_bogons)|cidr-report.org IP list of Unallocated address space.|ipv4 hash:net|9125 subnets, 603242560 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=lujdnbasfaaixitgmxpp&fileformat=p2p&archiveformat=gz)
[iblocklist_cruzit_web_attacks](http://iplists.firehol.org/?ipset=iblocklist_cruzit_web_attacks)|CruzIT IP list with individual IP addresses of compromised machines scanning for vulnerabilities and DDOS attacks.|ipv4 hash:net|14096 subnets, 14397 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=czvaehmjpsnwwttrdoyl&fileformat=p2p&archiveformat=gz)
[iblocklist_dshield](http://iplists.firehol.org/?ipset=iblocklist_dshield)|known Hackers and such people.|ipv4 hash:net|16 subnets, 2566 unique IPs|updated every 12 hours
[iblocklist_edu](http://iplists.firehol.org/?ipset=iblocklist_edu)|IPs used by Educational Institutions.|ipv4 hash:net|43898 subnets, 227929603 unique IPs|updated every 12 hours
[iblocklist_exclusions](http://iplists.firehol.org/?ipset=iblocklist_exclusions)|Exclusions.|ipv4 hash:net|313 subnets, 7488 unique IPs|updated every 12 hours
[iblocklist_fornonlancomputers](http://iplists.firehol.org/?ipset=iblocklist_fornonlancomputers)|IP blocklist for non-LAN computers.|ipv4 hash:net|4 subnets, 302055424 unique IPs|updated every 12 hours
[iblocklist_forumspam](http://iplists.firehol.org/?ipset=iblocklist_forumspam)|Forum spam.|ipv4 hash:net|455 subnets, 479 unique IPs|updated every 12 hours
[iblocklist_hijacked](http://iplists.firehol.org/?ipset=iblocklist_hijacked)|Hijacked IP-Blocks. Contains hijacked IP-Blocks and known IP-Blocks that are used to deliver Spam. This list is a combination of lists with hijacked IP-Blocks. Hijacked IP space are IP blocks that are being used without permission by organizations that have no relation to original organization (or its legal successor) that received the IP block. In essence it's stealing of somebody else's IP resources.|ipv4 hash:net|512 subnets, 8736512 unique IPs|updated every 12 hours
[iblocklist_iana_multicast](http://iplists.firehol.org/?ipset=iblocklist_iana_multicast)|IANA Multicast IPs.|ipv4 hash:net|1 subnets, 268435456 unique IPs|updated every 12 hours
[iblocklist_iana_private](http://iplists.firehol.org/?ipset=iblocklist_iana_private)|IANA Private IPs.|ipv4 hash:net|58 subnets, 51643646 unique IPs|updated every 12 hours
[iblocklist_iana_reserved](http://iplists.firehol.org/?ipset=iblocklist_iana_reserved)|IANA Reserved IPs.|ipv4 hash:net|1 subnets, 536870912 unique IPs|updated every 12 hours
[iblocklist_isp_aol](http://iplists.firehol.org/?ipset=iblocklist_isp_aol)|AOL IPs.|ipv4 hash:net|16 subnets, 6627584 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=toboaiysofkflwgrttmb&fileformat=p2p&archiveformat=gz)
[iblocklist_isp_att](http://iplists.firehol.org/?ipset=iblocklist_isp_att)|AT&T IPs.|ipv4 hash:net|35 subnets, 55845128 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=grbtkzijgrowvobvessf&fileformat=p2p&archiveformat=gz)
[iblocklist_isp_cablevision](http://iplists.firehol.org/?ipset=iblocklist_isp_cablevision)|Cablevision IPs.|ipv4 hash:net|11 subnets, 1787136 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=dwwbsmzirrykdlvpqozb&fileformat=p2p&archiveformat=gz)
[iblocklist_isp_charter](http://iplists.firehol.org/?ipset=iblocklist_isp_charter)|Charter IPs.|ipv4 hash:net|21 subnets, 6138112 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=htnzojgossawhpkbulqw&fileformat=p2p&archiveformat=gz)
[iblocklist_isp_comcast](http://iplists.firehol.org/?ipset=iblocklist_isp_comcast)|Comcast IPs.|ipv4 hash:net|33 subnets, 45121536 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=rsgyxvuklicibautguia&fileformat=p2p&archiveformat=gz)
[iblocklist_isp_embarq](http://iplists.firehol.org/?ipset=iblocklist_isp_embarq)|Embarq IPs.|ipv4 hash:net|14 subnets, 2703360 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=twdblifaysaqtypevvdp&fileformat=p2p&archiveformat=gz)
[iblocklist_isp_qwest](http://iplists.firehol.org/?ipset=iblocklist_isp_qwest)|Qwest IPs.|ipv4 hash:net|73 subnets, 15777552 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=jezlifrpefawuoawnfez&fileformat=p2p&archiveformat=gz)
[iblocklist_isp_sprint](http://iplists.firehol.org/?ipset=iblocklist_isp_sprint)|Sprint IPs.|ipv4 hash:net|73 subnets, 6310570 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=hngtqrhhuadlceqxbrob&fileformat=p2p&archiveformat=gz)
[iblocklist_isp_suddenlink](http://iplists.firehol.org/?ipset=iblocklist_isp_suddenlink)|Suddenlink IPs.|ipv4 hash:net|3 subnets, 458752 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=psaoblrwylfrdsspfuiq&fileformat=p2p&archiveformat=gz)
[iblocklist_isp_twc](http://iplists.firehol.org/?ipset=iblocklist_isp_twc)|Time Warner Cable IPs.|ipv4 hash:net|56 subnets, 15015936 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=aqtsnttnqmcucwrjmohd&fileformat=p2p&archiveformat=gz)
[iblocklist_isp_verizon](http://iplists.firehol.org/?ipset=iblocklist_isp_verizon)|Verizon IPs.|ipv4 hash:net|22 subnets, 18087936 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=cdmdbprvldivlqsaqjol&fileformat=p2p&archiveformat=gz)
[iblocklist_level1](http://iplists.firehol.org/?ipset=iblocklist_level1)|Level 1 (for use in p2p): Companies or organizations who are clearly involved with trying to stop filesharing (e.g. Baytsp, MediaDefender, Mediasentry). Companies which anti-p2p activity has been seen from. Companies that produce or have a strong financial interest in copyrighted material (e.g. music, movie, software industries a.o.). Government ranges or companies that have a strong financial interest in doing work for governments. Legal industry ranges. IPs or ranges of ISPs from which anti-p2p activity has been observed. Basically this list will block all kinds of internet connections that most people would rather not have during their internet travels.|ipv4 hash:net|235638 subnets, 725210117 unique IPs|updated every 12 hours
[iblocklist_level2](http://iplists.firehol.org/?ipset=iblocklist_level2)|Level 2 (for use in p2p). General corporate ranges. Ranges used by labs or researchers. Proxies.|ipv4 hash:net|78364 subnets, 337804407 unique IPs|updated every 12 hours
[iblocklist_level3](http://iplists.firehol.org/?ipset=iblocklist_level3)|Level 3 (for use in p2p). Many portal-type websites. ISP ranges that may be dodgy for some reason. Ranges that belong to an individual, but which have not been determined to be used by a particular company. Ranges for things that are unusual in some way. The L3 list is aka the paranoid list.|ipv4 hash:net|18873 subnets, 137071177 unique IPs|updated every 12 hours
[iblocklist_malc0de](http://iplists.firehol.org/?ipset=iblocklist_malc0de)|malc0de.com IP blocklist. Addresses that have been identified distributing malware during the past 30 days.|ipv4 hash:net|21 subnets, 21 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=pbqcylkejciyhmwttify&fileformat=p2p&archiveformat=gz)
[iblocklist_onion_router](http://iplists.firehol.org/?ipset=iblocklist_onion_router)|The Onion Router IP addresses.|ipv4 hash:net|889 subnets, 1344 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=togdoptykrlolpddwbvz&fileformat=p2p&archiveformat=gz)
[iblocklist_org_activision](http://iplists.firehol.org/?ipset=iblocklist_org_activision)|Activision IPs.|ipv4 hash:net|49 subnets, 4902 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=gfnxlhxsijzrcuxwzebb&fileformat=p2p&archiveformat=gz)
[iblocklist_org_apple](http://iplists.firehol.org/?ipset=iblocklist_org_apple)|Apple IPs.|ipv4 hash:net|1 subnets, 16777216 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=aphcqvpxuqgrkgufjruj&fileformat=p2p&archiveformat=gz)
[iblocklist_org_blizzard](http://iplists.firehol.org/?ipset=iblocklist_org_blizzard)|Blizzard IPs.|ipv4 hash:net|8 subnets, 16795139 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=ercbntshuthyykfkmhxc&fileformat=p2p&archiveformat=gz)
[iblocklist_org_crowd_control](http://iplists.firehol.org/?ipset=iblocklist_org_crowd_control)|Crowd Control Productions IPs.|ipv4 hash:net|2 subnets, 768 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=eveiyhgmusglurfmjyag&fileformat=p2p&archiveformat=gz)
[iblocklist_org_electronic_arts](http://iplists.firehol.org/?ipset=iblocklist_org_electronic_arts)|Electronic Arts IPs.|ipv4 hash:net|42 subnets, 69720 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=ejqebpcdmffinaetsvxj&fileformat=p2p&archiveformat=gz)
[iblocklist_org_joost](http://iplists.firehol.org/?ipset=iblocklist_org_joost)|Joost IPs.|ipv4 hash:net|4 subnets, 16779456 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=alxugfmeszbhpxqfdits&fileformat=p2p&archiveformat=gz)
[iblocklist_org_linden_lab](http://iplists.firehol.org/?ipset=iblocklist_org_linden_lab)|Linden Lab IPs.|ipv4 hash:net|11 subnets, 23600 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=qnjdimxnaupjmpqolxcv&fileformat=p2p&archiveformat=gz)
[iblocklist_org_logmein](http://iplists.firehol.org/?ipset=iblocklist_org_logmein)|LogMeIn IPs.|ipv4 hash:net|13 subnets, 16781568 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=tgbankumtwtrzllndbmb&fileformat=p2p&archiveformat=gz)
[iblocklist_org_microsoft](http://iplists.firehol.org/?ipset=iblocklist_org_microsoft)|Microsoft IP ranges.|ipv4 hash:net|901 subnets, 1848599 unique IPs|updated every 12 hours
[iblocklist_org_ncsoft](http://iplists.firehol.org/?ipset=iblocklist_org_ncsoft)|NCsoft IPs.|ipv4 hash:net|5 subnets, 12560 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=mwjuwmebrnzyyxpbezxu&fileformat=p2p&archiveformat=gz)
[iblocklist_org_nintendo](http://iplists.firehol.org/?ipset=iblocklist_org_nintendo)|Nintendo IPs.|ipv4 hash:net|45 subnets, 3927 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=pevkykuhgaegqyayzbnr&fileformat=p2p&archiveformat=gz)
[iblocklist_org_pandora](http://iplists.firehol.org/?ipset=iblocklist_org_pandora)|Pandora IPs.|ipv4 hash:net|1 subnets, 2048 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=aevzidimyvwybzkletsg&fileformat=p2p&archiveformat=gz)
[iblocklist_org_pirate_bay](http://iplists.firehol.org/?ipset=iblocklist_org_pirate_bay)|The Pirate Bay IPs.|ipv4 hash:net|5 subnets, 323 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=nzldzlpkgrcncdomnttb&fileformat=p2p&archiveformat=gz)
[iblocklist_org_punkbuster](http://iplists.firehol.org/?ipset=iblocklist_org_punkbuster)|Punkbuster IPs.|ipv4 hash:net|1 subnets, 1 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=zvwwndvzulqcltsicwdg&fileformat=p2p&archiveformat=gz)
[iblocklist_org_riot_games](http://iplists.firehol.org/?ipset=iblocklist_org_riot_games)|Riot Games IPs.|ipv4 hash:net|6 subnets, 1792 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=sdlvfabdjvrdttfjotcy&fileformat=p2p&archiveformat=gz)
[iblocklist_org_sony_online](http://iplists.firehol.org/?ipset=iblocklist_org_sony_online)|Sony Online Entertainment IPs.|ipv4 hash:net|7 subnets, 24616 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=tukpvrvlubsputmkmiwg&fileformat=p2p&archiveformat=gz)
[iblocklist_org_square_enix](http://iplists.firehol.org/?ipset=iblocklist_org_square_enix)|Square Enix IPs.|ipv4 hash:net|2 subnets, 4112 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=odyaqontcydnodrlyina&fileformat=p2p&archiveformat=gz)
[iblocklist_org_steam](http://iplists.firehol.org/?ipset=iblocklist_org_steam)|Steam IPs.|ipv4 hash:net|53 subnets, 596448 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=cnxkgiklecdaihzukrud&fileformat=p2p&archiveformat=gz)
[iblocklist_org_ubisoft](http://iplists.firehol.org/?ipset=iblocklist_org_ubisoft)|Ubisoft IPs.|ipv4 hash:net|10 subnets, 5308 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=etmcrglomupyxtaebzht&fileformat=p2p&archiveformat=gz)
[iblocklist_org_xfire](http://iplists.firehol.org/?ipset=iblocklist_org_xfire)|XFire IPs.|ipv4 hash:net|3 subnets, 3328 unique IPs|updated every 1 day from [this link](http://list.iblocklist.com/?list=ppqqnyihmcrryraaqsjo&fileformat=p2p&archiveformat=gz)
[iblocklist_pedophiles](http://iplists.firehol.org/?ipset=iblocklist_pedophiles)|IP ranges of people who we have found to be sharing child pornography in the p2p community.|ipv4 hash:net|29188 subnets, 847889 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=dufcxgnbjsdwmwctgfuj&fileformat=p2p&archiveformat=gz)
[iblocklist_proxies](http://iplists.firehol.org/?ipset=iblocklist_proxies)|Open Proxies IPs list (without TOR)|ipv4 hash:ip|672 unique IPs|updated every 12 hours
[iblocklist_rangetest](http://iplists.firehol.org/?ipset=iblocklist_rangetest)|Suspicious IPs that are under investigation.|ipv4 hash:net|576 subnets, 4280758 unique IPs|updated every 12 hours
[iblocklist_spamhaus_drop](http://iplists.firehol.org/?ipset=iblocklist_spamhaus_drop)|Spamhaus.org DROP (Don't Route Or Peer) list.|ipv4 hash:net|900 subnets, 17338368 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=zbdlwrqkabxbcppvrnos&fileformat=p2p&archiveformat=gz)
[iblocklist_spider](http://iplists.firehol.org/?ipset=iblocklist_spider)|IP list intended to be used by webmasters to block hostile spiders from their web sites.|ipv4 hash:net|773 subnets, 846788 unique IPs|updated every 12 hours
[iblocklist_spyware](http://iplists.firehol.org/?ipset=iblocklist_spyware)|Known malicious SPYWARE and ADWARE IP Address ranges. It is compiled from various sources, including other available spyware blacklists, HOSTS files, from research found at many of the top anti-spyware forums, logs of spyware victims, etc.|ipv4 hash:net|3355 subnets, 339296 unique IPs|updated every 12 hours
[iblocklist_webexploit](http://iplists.firehol.org/?ipset=iblocklist_webexploit)|Web server hack and exploit attempts. IP addresses related to current web server hack and exploit attempts that have been logged or can be found in and cross referenced with other related IP databases. Malicious and other non search engine bots will also be listed here, along with anything found that can have a negative impact on a website or webserver such as proxies being used for negative SEO hijacks, unauthorised site mirroring, harvesting, scraping, snooping and data mining / spy bot / security & copyright enforcement companies that target and continuosly scan webservers.|ipv4 hash:ip|15382 unique IPs|updated every 12 hours
[iblocklist_yoyo_adservers](http://iplists.firehol.org/?ipset=iblocklist_yoyo_adservers)|pgl.yoyo.org ad servers|ipv4 hash:net|7839 subnets, 9235 unique IPs|updated every 12 hours from [this link](http://list.iblocklist.com/?list=zhogegszwduurnvsyhdf&fileformat=p2p&archiveformat=gz)
[ip2location_country](https://github.com/ktsaou/blocklist-ipsets/tree/master/ip2location_country)|[IP2Location.com](http://lite.ip2location.com/database-ip-country) geolocation database|ipv4 hash:net|All the world|updated every 1 day from [this link](http://download.ip2location.com/lite/IP2LOCATION-LITE-DB1.CSV.ZIP)
[ip2location_country_eh](http://iplists.firehol.org/?ipset=ip2location_country_eh)|Western Sahara (EH) -- [IP2Location.com](http://lite.ip2location.com/database-ip-country)|ipv4 hash:net|1 subnets, 256 unique IPs|updated every 1 day from [this link](http://download.ip2location.com/lite/IP2LOCATION-LITE-DB1.CSV.ZIP)
[ip2proxy_px1lite](http://iplists.firehol.org/?ipset=ip2proxy_px1lite)|[IP2Location.com](https://lite.ip2location.com/database/px1-ip-country) IP2Proxy LITE IP-COUNTRY Database contains IP addresses which are used as public proxies. The LITE edition is a free version of database that is limited to public proxies IP address.|ipv4 hash:net|949316 subnets, 1074536 unique IPs|updated every 1 day
[ipblacklistcloud_recent](http://iplists.firehol.org/?ipset=ipblacklistcloud_recent)|[IP Blacklist Cloud](http://www.ip-finder.me/) These are the most recent IP addresses that have been blacklisted by websites. IP Blacklist Cloud plugin protects your WordPress based website from spam comments, gives details about login attacks which you don't even know are happening without this plugin!|ipv4 hash:ip|32 unique IPs|updated every 4 hours from [this link](http://www.ip-finder.me/download/)
[ipblacklistcloud_recent_1d](http://iplists.firehol.org/?ipset=ipblacklistcloud_recent_1d)|[IP Blacklist Cloud](http://www.ip-finder.me/) These are the most recent IP addresses that have been blacklisted by websites. IP Blacklist Cloud plugin protects your WordPress based website from spam comments, gives details about login attacks which you don't even know are happening without this plugin!|ipv4 hash:ip|32 unique IPs|updated every 4 hours from [this link](http://www.ip-finder.me/download/)
[ipblacklistcloud_recent_30d](http://iplists.firehol.org/?ipset=ipblacklistcloud_recent_30d)|[IP Blacklist Cloud](http://www.ip-finder.me/) These are the most recent IP addresses that have been blacklisted by websites. IP Blacklist Cloud plugin protects your WordPress based website from spam comments, gives details about login attacks which you don't even know are happening without this plugin!|ipv4 hash:ip|196 unique IPs|updated every 4 hours from [this link](http://www.ip-finder.me/download/)
[ipblacklistcloud_recent_7d](http://iplists.firehol.org/?ipset=ipblacklistcloud_recent_7d)|[IP Blacklist Cloud](http://www.ip-finder.me/) These are the most recent IP addresses that have been blacklisted by websites. IP Blacklist Cloud plugin protects your WordPress based website from spam comments, gives details about login attacks which you don't even know are happening without this plugin!|ipv4 hash:ip|64 unique IPs|updated every 4 hours from [this link](http://www.ip-finder.me/download/)
[ipblacklistcloud_top](http://iplists.firehol.org/?ipset=ipblacklistcloud_top)|[IP Blacklist Cloud](http://www.ip-finder.me/) These are the top IP addresses that have been blacklisted by many websites. IP Blacklist Cloud plugin protects your WordPress based website from spam comments, gives details about login attacks which you don't even know are happening without this plugin!|ipv4 hash:ip|200 unique IPs|updated every 1 day from [this link](http://www.ip-finder.me/ip-full-list/)
[ipdeny_country](https://github.com/firehol/blocklist-ipsets/tree/master/ipdeny_country)|[IPDeny.com](http://www.ipdeny.com/) geolocation database|ipv4 hash:net|All the world|updated every 1 day from [this link](http://www.ipdeny.com/ipblocks/data/countries/all-zones.tar.gz)
[iw_spamlist](http://iplists.firehol.org/?ipset=iw_spamlist)|[ImproWare Antispam](http://antispam.imp.ch/) IPs sending spam, in the last 3 days|ipv4 hash:ip|0 unique IPs|updated every 1 hour from [this link](http://antispam.imp.ch/spamlist)
[iw_wormlist](http://iplists.firehol.org/?ipset=iw_wormlist)|[ImproWare Antispam](http://antispam.imp.ch/) IPs sending emails with viruses or worms, in the last 3 days|ipv4 hash:ip|0 unique IPs|updated every 1 hour from [this link](http://antispam.imp.ch/wormlist)
[lashback_ubl](http://iplists.firehol.org/?ipset=lashback_ubl)|[The LashBack UBL](http://blacklist.lashback.com/) The Unsubscribe Blacklist (UBL) is a real-time blacklist of IP addresses which are sending email to names harvested from suppression files (this is a big list, more than 500.000 IPs)|ipv4 hash:ip|37994 unique IPs|updated every 1 day from [this link](http://www.unsubscore.com/blacklist.txt)
[malc0de](http://iplists.firehol.org/?ipset=malc0de)|[Malc0de.com](http://malc0de.com) malicious IPs of the last 30 days|ipv4 hash:ip|21 unique IPs|updated every 1 day from [this link](http://malc0de.com/bl/IP_Blacklist.txt)
[malwaredomainlist](http://iplists.firehol.org/?ipset=malwaredomainlist)|[malwaredomainlist.com](http://www.malwaredomainlist.com) list of malware active ip addresses|ipv4 hash:ip|996 unique IPs|updated every 12 hours from [this link](http://www.malwaredomainlist.com/hostslist/ip.txt)
[maxmind_proxy_fraud](http://iplists.firehol.org/?ipset=maxmind_proxy_fraud)|[MaxMind.com](https://www.maxmind.com/en/high-risk-ip-sample-list) sample list of high-risk IP addresses.|ipv4 hash:ip|583 unique IPs|updated every 4 hours from [this link](https://www.maxmind.com/en/high-risk-ip-sample-list)
[myip](http://iplists.firehol.org/?ipset=myip)|[myip.ms](http://www.myip.ms/info/about) IPs identified as web bots in the last 10 days, using several sites that require human action|ipv4 hash:ip|1143 unique IPs|updated every 1 day from [this link](http://www.myip.ms/files/blacklist/csf/latest_blacklist.txt)
[nixspam](http://iplists.firehol.org/?ipset=nixspam)|[NiX Spam](http://www.heise.de/ix/NiX-Spam-DNSBL-and-blacklist-for-download-499637.html) IP addresses that sent spam in the last hour - automatically generated entries without distinguishing open proxies from relays, dialup gateways, and so on. All IPs are removed after 12 hours if there is no spam from there.|ipv4 hash:ip|17135 unique IPs|updated every 15 mins from [this link](http://www.dnsbl.manitu.net/download/nixspam-ip.dump.gz)
[normshield_all_attack](http://iplists.firehol.org/?ipset=normshield_all_attack)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category attack with severity all|ipv4 hash:ip|549 unique IPs|updated every 12 hours
[normshield_all_bruteforce](http://iplists.firehol.org/?ipset=normshield_all_bruteforce)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category bruteforce with severity all|ipv4 hash:ip|196 unique IPs|updated every 12 hours
[normshield_all_ddosbot](http://iplists.firehol.org/?ipset=normshield_all_ddosbot)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category ddosbot with severity all|ipv4 hash:ip|1 unique IPs|updated every 12 hours
[normshield_all_dnsscan](http://iplists.firehol.org/?ipset=normshield_all_dnsscan)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category dnsscan with severity all|ipv4 hash:ip|1 unique IPs|updated every 12 hours
[normshield_all_spam](http://iplists.firehol.org/?ipset=normshield_all_spam)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category spam with severity all|ipv4 hash:ip|17 unique IPs|updated every 12 hours
[normshield_all_suspicious](http://iplists.firehol.org/?ipset=normshield_all_suspicious)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category suspicious with severity all|ipv4 hash:ip|11 unique IPs|updated every 12 hours
[normshield_all_wannacry](http://iplists.firehol.org/?ipset=normshield_all_wannacry)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category wannacry with severity all|ipv4 hash:ip|1165 unique IPs|updated every 12 hours
[normshield_all_webscan](http://iplists.firehol.org/?ipset=normshield_all_webscan)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category webscan with severity all|ipv4 hash:ip|46 unique IPs|updated every 12 hours
[normshield_all_wormscan](http://iplists.firehol.org/?ipset=normshield_all_wormscan)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category wormscan with severity all|ipv4 hash:ip|28 unique IPs|updated every 12 hours
[normshield_high_attack](http://iplists.firehol.org/?ipset=normshield_high_attack)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category attack with severity high|ipv4 hash:ip|549 unique IPs|updated every 12 hours
[normshield_high_bruteforce](http://iplists.firehol.org/?ipset=normshield_high_bruteforce)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category bruteforce with severity high|ipv4 hash:ip|196 unique IPs|updated every 12 hours
[normshield_high_ddosbot](http://iplists.firehol.org/?ipset=normshield_high_ddosbot)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category ddosbot with severity high|ipv4 hash:ip|1 unique IPs|updated every 12 hours
[normshield_high_dnsscan](http://iplists.firehol.org/?ipset=normshield_high_dnsscan)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category dnsscan with severity high|ipv4 hash:ip|1 unique IPs|updated every 12 hours
[normshield_high_spam](http://iplists.firehol.org/?ipset=normshield_high_spam)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category spam with severity high|ipv4 hash:ip|17 unique IPs|updated every 12 hours
[normshield_high_suspicious](http://iplists.firehol.org/?ipset=normshield_high_suspicious)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category suspicious with severity high|ipv4 hash:ip|11 unique IPs|updated every 12 hours
[normshield_high_wannacry](http://iplists.firehol.org/?ipset=normshield_high_wannacry)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category wannacry with severity high|ipv4 hash:ip|1165 unique IPs|updated every 12 hours
[normshield_high_webscan](http://iplists.firehol.org/?ipset=normshield_high_webscan)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category webscan with severity high|ipv4 hash:ip|46 unique IPs|updated every 12 hours
[normshield_high_wormscan](http://iplists.firehol.org/?ipset=normshield_high_wormscan)|[NormShield.com](https://services.normshield.com/threatfeed) IPs in category wormscan with severity high|ipv4 hash:ip|28 unique IPs|updated every 12 hours
[nt_malware_dns](http://iplists.firehol.org/?ipset=nt_malware_dns)|[No Think](http://www.nothink.org/) Malware DNS (the original list includes hostnames and domains, which are ignored)|ipv4 hash:ip|235 unique IPs|updated every 1 hour from [this link](http://www.nothink.org/blacklist/blacklist_malware_dns.txt)
[nt_malware_http](http://iplists.firehol.org/?ipset=nt_malware_http)|[No Think](http://www.nothink.org/) Malware HTTP|ipv4 hash:ip|69 unique IPs|updated every 1 hour from [this link](http://www.nothink.org/blacklist/blacklist_malware_http.txt)
[nt_malware_irc](http://iplists.firehol.org/?ipset=nt_malware_irc)|[No Think](http://www.nothink.org/) Malware IRC|ipv4 hash:ip|42 unique IPs|updated every 1 hour from [this link](http://www.nothink.org/blacklist/blacklist_malware_irc.txt)
[nt_ssh_7d](http://iplists.firehol.org/?ipset=nt_ssh_7d)|[NoThink](http://www.nothink.org/) Last 7 days SSH attacks|ipv4 hash:ip|169 unique IPs|updated every 1 hour from [this link](http://www.nothink.org/blacklist/blacklist_ssh_week.txt)
[nullsecure](http://iplists.firehol.org/?ipset=nullsecure)|[nullsecure.org](http://nullsecure.org/) This is a free threat feed provided for use in any acceptable manner. This feed was aggregated using the [Tango Honeypot Intelligence Splunk App](https://github.com/aplura/Tango) by Brian Warehime, a Senior Security Analyst at Defense Point Security.|ipv4 hash:ip|29439 unique IPs|updated every 8 hours from [this link](http://nullsecure.org/threatfeed/master.txt)
[packetmail](http://iplists.firehol.org/?ipset=packetmail)|[PacketMail.net](https://www.packetmail.net/) IP addresses that have been detected performing TCP SYN to 206.82.85.196/30 to a non-listening service or daemon. No assertion is made, nor implied, that any of the below listed IP addresses are accurate, malicious, hostile, or engaged in nefarious acts. Use this list at your own risk.|ipv4 hash:ip|3986 unique IPs|updated every 4 hours from [this link](https://www.packetmail.net/iprep.txt)
[packetmail_emerging_ips](http://iplists.firehol.org/?ipset=packetmail_emerging_ips)|[PacketMail.net](https://www.packetmail.net/) IP addresses that have been detected as potentially of interest based on the number of unique users of the packetmail IP Reputation system. No assertion is made, nor implied, that any of the below listed IP addresses are accurate, malicious, hostile, or engaged in nefarious acts. Use this list at your own risk.|ipv4 hash:ip|26 unique IPs|updated every 4 hours from [this link](https://www.packetmail.net/iprep_emerging_ips.txt)
[packetmail_mail](http://iplists.firehol.org/?ipset=packetmail_mail)|[PacketMail.net](https://www.packetmail.net/) IP addresses that have been detected performing behavior not in compliance with the requirements this system enforces for email acceptance. No assertion is made, nor implied, that any of the below listed IP addresses are accurate, malicious, hostile, or engaged in nefarious acts. Use this list at your own risk.|ipv4 hash:ip|73 unique IPs|updated every 4 hours from [this link](https://www.packetmail.net/iprep_mail.txt)
[packetmail_ramnode](http://iplists.firehol.org/?ipset=packetmail_ramnode)|[PacketMail.net](https://www.packetmail.net/) IP addresses that have been detected performing TCP SYN to 81.4.103.251 to a non-listening service or daemon. No assertion is made, nor implied, that any of the below listed IP addresses are accurate, malicious, hostile, or engaged in nefarious acts. Use this list at your own risk.|ipv4 hash:ip|2502 unique IPs|updated every 4 hours from [this link](https://www.packetmail.net/iprep_ramnode.txt)
php_bad|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) bad web hosts (this list is composed using an RSS feed)|ipv4 hash:ip|disabled|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=b&rss=1)
[php_commenters](http://iplists.firehol.org/?ipset=php_commenters)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) comment spammers (this list is composed using an RSS feed)|ipv4 hash:ip|50 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=c&rss=1)
[php_commenters_1d](http://iplists.firehol.org/?ipset=php_commenters_1d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) comment spammers (this list is composed using an RSS feed)|ipv4 hash:ip|96 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=c&rss=1)
[php_commenters_30d](http://iplists.firehol.org/?ipset=php_commenters_30d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) comment spammers (this list is composed using an RSS feed)|ipv4 hash:ip|1099 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=c&rss=1)
[php_commenters_7d](http://iplists.firehol.org/?ipset=php_commenters_7d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) comment spammers (this list is composed using an RSS feed)|ipv4 hash:ip|343 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=c&rss=1)
[php_dictionary](http://iplists.firehol.org/?ipset=php_dictionary)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) directory attackers (this list is composed using an RSS feed)|ipv4 hash:ip|50 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=d&rss=1)
[php_dictionary_1d](http://iplists.firehol.org/?ipset=php_dictionary_1d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) directory attackers (this list is composed using an RSS feed)|ipv4 hash:ip|97 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=d&rss=1)
[php_dictionary_30d](http://iplists.firehol.org/?ipset=php_dictionary_30d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) directory attackers (this list is composed using an RSS feed)|ipv4 hash:ip|1097 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=d&rss=1)
[php_dictionary_7d](http://iplists.firehol.org/?ipset=php_dictionary_7d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) directory attackers (this list is composed using an RSS feed)|ipv4 hash:ip|338 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=d&rss=1)
[php_harvesters](http://iplists.firehol.org/?ipset=php_harvesters)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) harvesters (IPs that surf the internet looking for email addresses) (this list is composed using an RSS feed)|ipv4 hash:ip|50 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=h&rss=1)
[php_harvesters_1d](http://iplists.firehol.org/?ipset=php_harvesters_1d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) harvesters (IPs that surf the internet looking for email addresses) (this list is composed using an RSS feed)|ipv4 hash:ip|69 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=h&rss=1)
[php_harvesters_30d](http://iplists.firehol.org/?ipset=php_harvesters_30d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) harvesters (IPs that surf the internet looking for email addresses) (this list is composed using an RSS feed)|ipv4 hash:ip|289 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=h&rss=1)
[php_harvesters_7d](http://iplists.firehol.org/?ipset=php_harvesters_7d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) harvesters (IPs that surf the internet looking for email addresses) (this list is composed using an RSS feed)|ipv4 hash:ip|118 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=h&rss=1)
[php_spammers](http://iplists.firehol.org/?ipset=php_spammers)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) spam servers (IPs used by spammers to send messages) (this list is composed using an RSS feed)|ipv4 hash:ip|50 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=s&rss=1)
[php_spammers_1d](http://iplists.firehol.org/?ipset=php_spammers_1d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) spam servers (IPs used by spammers to send messages) (this list is composed using an RSS feed)|ipv4 hash:ip|94 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=s&rss=1)
[php_spammers_30d](http://iplists.firehol.org/?ipset=php_spammers_30d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) spam servers (IPs used by spammers to send messages) (this list is composed using an RSS feed)|ipv4 hash:ip|1074 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=s&rss=1)
[php_spammers_7d](http://iplists.firehol.org/?ipset=php_spammers_7d)|[projecthoneypot.org](http://www.projecthoneypot.org/?rf=192670) spam servers (IPs used by spammers to send messages) (this list is composed using an RSS feed)|ipv4 hash:ip|312 unique IPs|updated every 1 hour from [this link](http://www.projecthoneypot.org/list_of_ips.php?t=s&rss=1)
[proxylists](http://iplists.firehol.org/?ipset=proxylists)|[proxylists.net](http://www.proxylists.net/) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|2668 unique IPs|updated every 1 hour from [this link](http://www.proxylists.net/proxylists.xml)
[proxylists_1d](http://iplists.firehol.org/?ipset=proxylists_1d)|[proxylists.net](http://www.proxylists.net/) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|5094 unique IPs|updated every 1 hour from [this link](http://www.proxylists.net/proxylists.xml)
[proxylists_30d](http://iplists.firehol.org/?ipset=proxylists_30d)|[proxylists.net](http://www.proxylists.net/) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|10138 unique IPs|updated every 1 hour from [this link](http://www.proxylists.net/proxylists.xml)
[proxylists_7d](http://iplists.firehol.org/?ipset=proxylists_7d)|[proxylists.net](http://www.proxylists.net/) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|8263 unique IPs|updated every 1 hour from [this link](http://www.proxylists.net/proxylists.xml)
proxyrss|[proxyrss.com](http://www.proxyrss.com) open proxies syndicated from multiple sources.|ipv4 hash:ip|disabled|updated every 4 hours from [this link](http://www.proxyrss.com/proxylists/all.gz)
[proxyspy_1d](http://iplists.firehol.org/?ipset=proxyspy_1d)|[ProxySpy](http://spys.ru/en/) open proxies (updated hourly)|ipv4 hash:ip|300 unique IPs|updated every 1 hour from [this link](http://txt.proxyspy.net/proxy.txt)
[proxyspy_30d](http://iplists.firehol.org/?ipset=proxyspy_30d)|[ProxySpy](http://spys.ru/en/) open proxies (updated hourly)|ipv4 hash:ip|6720 unique IPs|updated every 1 hour from [this link](http://txt.proxyspy.net/proxy.txt)
[proxyspy_7d](http://iplists.firehol.org/?ipset=proxyspy_7d)|[ProxySpy](http://spys.ru/en/) open proxies (updated hourly)|ipv4 hash:ip|2828 unique IPs|updated every 1 hour from [this link](http://txt.proxyspy.net/proxy.txt)
[proxz](http://iplists.firehol.org/?ipset=proxz)|[proxz.com](http://www.proxz.com) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|26 unique IPs|updated every 1 hour from [this link](http://www.proxz.com/proxylists.xml)
[proxz_1d](http://iplists.firehol.org/?ipset=proxz_1d)|[proxz.com](http://www.proxz.com) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|266 unique IPs|updated every 1 hour from [this link](http://www.proxz.com/proxylists.xml)
[proxz_30d](http://iplists.firehol.org/?ipset=proxz_30d)|[proxz.com](http://www.proxz.com) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|3338 unique IPs|updated every 1 hour from [this link](http://www.proxz.com/proxylists.xml)
[proxz_7d](http://iplists.firehol.org/?ipset=proxz_7d)|[proxz.com](http://www.proxz.com) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|1201 unique IPs|updated every 1 hour from [this link](http://www.proxz.com/proxylists.xml)
[pushing_inertia_blocklist](http://iplists.firehol.org/?ipset=pushing_inertia_blocklist)|[Pushing Inertia](https://github.com/pushinginertia/ip-blacklist) IPs of hosting providers that are known to host various bots, spiders, scrapers, etc. to block access from these providers to web servers.|ipv4 hash:net|1309 subnets, 60462830 unique IPs|updated every 1 day from [this link](https://raw.githubusercontent.com/pushinginertia/ip-blacklist/master/ip_blacklist.conf)
[ransomware_cryptowall_ps](http://iplists.firehol.org/?ipset=ransomware_cryptowall_ps)|[Abuse.ch Ransomware Tracker](https://ransomwaretracker.abuse.ch) Ransomware Tracker tracks and monitors the status of domain names, IP addresses and URLs that are associated with Ransomware, such as Botnet C&C servers, distribution sites and payment sites. By using data provided by Ransomware Tracker, hosting- and internet service provider (ISPs), as well as national CERTs/CSIRTs, law enforcement agencies (LEA) and security researchers can receive an overview on infrastructure used by Ransomware and whether these are actively being used by miscreants to commit fraud. This list is CW_PS_IPBL: CryptoWall Ransomware Payment Sites IP blocklist.|ipv4 hash:ip|0 unique IPs|updated every 5 mins from [this link](https://ransomwaretracker.abuse.ch/downloads/CW_PS_IPBL.txt)
[ransomware_feed](http://iplists.firehol.org/?ipset=ransomware_feed)|[Abuse.ch Ransomware Tracker](https://ransomwaretracker.abuse.ch) Ransomware Tracker tracks and monitors the status of domain names, IP addresses and URLs that are associated with Ransomware, such as Botnet C&C servers, distribution sites and payment sites. By using data provided by Ransomware Tracker, hosting- and internet service provider (ISPs), as well as national CERTs/CSIRTs, law enforcement agencies (LEA) and security researchers can receive an overview on infrastructure used by Ransomware and whether these are actively being used by miscreants to commit fraud. The IPs in this list have been extracted from the tracker data feed.|ipv4 hash:ip|0 unique IPs|updated every 5 mins from [this link](https://ransomwaretracker.abuse.ch/feeds/csv/)
[ransomware_locky_c2](http://iplists.firehol.org/?ipset=ransomware_locky_c2)|[Abuse.ch Ransomware Tracker](https://ransomwaretracker.abuse.ch) Ransomware Tracker tracks and monitors the status of domain names, IP addresses and URLs that are associated with Ransomware, such as Botnet C&C servers, distribution sites and payment sites. By using data provided by Ransomware Tracker, hosting- and internet service provider (ISPs), as well as national CERTs/CSIRTs, law enforcement agencies (LEA) and security researchers can receive an overview on infrastructure used by Ransomware and whether these are actively being used by miscreants to commit fraud. This list is LY_C2_IPBL: Locky Ransomware C2 URL blocklist.|ipv4 hash:ip|0 unique IPs|updated every 5 mins from [this link](https://ransomwaretracker.abuse.ch/downloads/LY_C2_IPBL.txt)
[ransomware_locky_ps](http://iplists.firehol.org/?ipset=ransomware_locky_ps)|[Abuse.ch Ransomware Tracker](https://ransomwaretracker.abuse.ch) Ransomware Tracker tracks and monitors the status of domain names, IP addresses and URLs that are associated with Ransomware, such as Botnet C&C servers, distribution sites and payment sites. By using data provided by Ransomware Tracker, hosting- and internet service provider (ISPs), as well as national CERTs/CSIRTs, law enforcement agencies (LEA) and security researchers can receive an overview on infrastructure used by Ransomware and whether these are actively being used by miscreants to commit fraud. This list is LY_PS_IPBL: Locky Ransomware Payment Sites IP blocklist.|ipv4 hash:ip|0 unique IPs|updated every 5 mins from [this link](https://ransomwaretracker.abuse.ch/downloads/LY_PS_IPBL.txt)
[ransomware_online](http://iplists.firehol.org/?ipset=ransomware_online)|[Abuse.ch Ransomware Tracker](https://ransomwaretracker.abuse.ch) Ransomware Tracker tracks and monitors the status of domain names, IP addresses and URLs that are associated with Ransomware, such as Botnet C&C servers, distribution sites and payment sites. By using data provided by Ransomware Tracker, hosting- and internet service provider (ISPs), as well as national CERTs/CSIRTs, law enforcement agencies (LEA) and security researchers can receive an overview on infrastructure used by Ransomware and whether these are actively being used by miscreants to commit fraud. The IPs in this list have been extracted from the tracker data feed, filtering only online IPs.|ipv4 hash:ip|0 unique IPs|updated every 5 mins from [this link](https://ransomwaretracker.abuse.ch/feeds/csv/)
[ransomware_rw](http://iplists.firehol.org/?ipset=ransomware_rw)|[Abuse.ch Ransomware Tracker](https://ransomwaretracker.abuse.ch) Ransomware Tracker tracks and monitors the status of domain names, IP addresses and URLs that are associated with Ransomware, such as Botnet C&C servers, distribution sites and payment sites. By using data provided by Ransomware Tracker, hosting- and internet service provider (ISPs), as well as national CERTs/CSIRTs, law enforcement agencies (LEA) and security researchers can receive an overview on infrastructure used by Ransomware and whether these are actively being used by miscreants to commit fraud. This list includes TC_PS_IPBL, LY_C2_IPBL, TL_C2_IPBL, TL_PS_IPBL and it is the recommended blocklist. It might not catch everything, but the false positive rate should be low. However, false positives are possible, especially with regards to RW_IPBL. IP addresses associated with Ransomware Payment Sites (*_PS_IPBL) or Locky botnet C&Cs (LY_C2_IPBL) stay listed on RW_IPBL for a time of 30 days after the last appearance. This means that an IP address stays listed on RW_IPBL even after the threat has been eliminated (e.g. the VPS / server has been suspended by the hosting provider) for another 30 days.|ipv4 hash:ip|0 unique IPs|updated every 5 mins from [this link](https://ransomwaretracker.abuse.ch/downloads/RW_IPBL.txt)
[ransomware_teslacrypt_ps](http://iplists.firehol.org/?ipset=ransomware_teslacrypt_ps)|[Abuse.ch Ransomware Tracker](https://ransomwaretracker.abuse.ch) Ransomware Tracker tracks and monitors the status of domain names, IP addresses and URLs that are associated with Ransomware, such as Botnet C&C servers, distribution sites and payment sites. By using data provided by Ransomware Tracker, hosting- and internet service provider (ISPs), as well as national CERTs/CSIRTs, law enforcement agencies (LEA) and security researchers can receive an overview on infrastructure used by Ransomware and whether these are actively being used by miscreants to commit fraud. This list is TC_PS_IPBL: TeslaCrypt Ransomware Payment Sites IP blocklist.|ipv4 hash:ip|0 unique IPs|updated every 5 mins from [this link](https://ransomwaretracker.abuse.ch/downloads/TC_PS_IPBL.txt)
[ransomware_torrentlocker_c2](http://iplists.firehol.org/?ipset=ransomware_torrentlocker_c2)|[Abuse.ch Ransomware Tracker](https://ransomwaretracker.abuse.ch) Ransomware Tracker tracks and monitors the status of domain names, IP addresses and URLs that are associated with Ransomware, such as Botnet C&C servers, distribution sites and payment sites. By using data provided by Ransomware Tracker, hosting- and internet service provider (ISPs), as well as national CERTs/CSIRTs, law enforcement agencies (LEA) and security researchers can receive an overview on infrastructure used by Ransomware and whether these are actively being used by miscreants to commit fraud. This list is TL_C2_IPBL: TorrentLocker Ransomware C2 IP blocklist.|ipv4 hash:ip|0 unique IPs|updated every 5 mins from [this link](https://ransomwaretracker.abuse.ch/downloads/TL_C2_IPBL.txt)
[ransomware_torrentlocker_ps](http://iplists.firehol.org/?ipset=ransomware_torrentlocker_ps)|[Abuse.ch Ransomware Tracker](https://ransomwaretracker.abuse.ch) Ransomware Tracker tracks and monitors the status of domain names, IP addresses and URLs that are associated with Ransomware, such as Botnet C&C servers, distribution sites and payment sites. By using data provided by Ransomware Tracker, hosting- and internet service provider (ISPs), as well as national CERTs/CSIRTs, law enforcement agencies (LEA) and security researchers can receive an overview on infrastructure used by Ransomware and whether these are actively being used by miscreants to commit fraud. This list is TL_PS_IPBL: TorrentLocker Ransomware Payment Sites IP blocklist.|ipv4 hash:ip|0 unique IPs|updated every 5 mins from [this link](https://ransomwaretracker.abuse.ch/downloads/TL_PS_IPBL.txt)
ri_connect_proxies|[rosinstrument.com](http://www.rosinstrument.com) open CONNECT proxies (this list is composed using an RSS feed)|ipv4 hash:ip|disabled|updated every 1 hour from [this link](http://tools.rosinstrument.com/proxy/plab100.xml)
ri_web_proxies|[rosinstrument.com](http://www.rosinstrument.com) open HTTP proxies (this list is composed using an RSS feed)|ipv4 hash:ip|disabled|updated every 1 hour from [this link](http://tools.rosinstrument.com/proxy/l100.xml)
[sblam](http://iplists.firehol.org/?ipset=sblam)|[sblam.com](http://sblam.com) IPs used by web form spammers, during the last month|ipv4 hash:ip|3118 unique IPs|updated every 1 day from [this link](http://sblam.com/blacklist.txt)
[shunlist](http://iplists.firehol.org/?ipset=shunlist)|[AutoShun.org](http://autoshun.org/) IPs identified as hostile by correlating logs from distributed snort installations running the autoshun plugin|ipv4 hash:ip|500 unique IPs|updated every 4 hours
[snort_ipfilter](http://iplists.firehol.org/?ipset=snort_ipfilter)|[labs.snort.org](https://labs.snort.org/) supplied IP blacklist (this list seems to be updated frequently, but we found no information about it)|ipv4 hash:ip|836 unique IPs|updated every 12 hours from [this link](http://labs.snort.org/feeds/ip-filter.blf)
[socks_proxy](http://iplists.firehol.org/?ipset=socks_proxy)|[socks-proxy.net](http://www.socks-proxy.net/) open SOCKS proxies|ipv4 hash:ip|302 unique IPs|updated every 10 mins from [this link](http://www.socks-proxy.net/)
[socks_proxy_1d](http://iplists.firehol.org/?ipset=socks_proxy_1d)|[socks-proxy.net](http://www.socks-proxy.net/) open SOCKS proxies|ipv4 hash:ip|2664 unique IPs|updated every 10 mins from [this link](http://www.socks-proxy.net/)
[socks_proxy_30d](http://iplists.firehol.org/?ipset=socks_proxy_30d)|[socks-proxy.net](http://www.socks-proxy.net/) open SOCKS proxies|ipv4 hash:ip|6172 unique IPs|updated every 10 mins from [this link](http://www.socks-proxy.net/)
[socks_proxy_7d](http://iplists.firehol.org/?ipset=socks_proxy_7d)|[socks-proxy.net](http://www.socks-proxy.net/) open SOCKS proxies|ipv4 hash:ip|3851 unique IPs|updated every 10 mins from [this link](http://www.socks-proxy.net/)
[sorbs_anonymizers](http://iplists.firehol.org/?ipset=sorbs_anonymizers)|[Sorbs.net](https://www.sorbs.net/) List of open HTTP and SOCKS proxies.|ipv4 hash:net|597391 subnets, 610263 unique IPs|updated every 1 min
sorbs_block|[Sorbs.net](https://www.sorbs.net/) List of hosts demanding that they never be tested by SORBS.|ipv4 hash:net|disabled|
[sorbs_dul](http://iplists.firehol.org/?ipset=sorbs_dul)|[Sorbs.net](https://www.sorbs.net/) Dynamic IP Addresses.|ipv4 hash:net|607718 subnets, 375474210 unique IPs|updated every 1 min
[sorbs_escalations](http://iplists.firehol.org/?ipset=sorbs_escalations)|[Sorbs.net](https://www.sorbs.net/) Netblocks of spam supporting service providers, including those who provide websites, DNS or drop boxes for a spammer. Spam supporters are added on a 'third strike and you are out' basis, where the third spam will cause the supporter to be added to the list.|ipv4 hash:net|8 subnets, 2304 unique IPs|updated every 1 min
[sorbs_new_spam](http://iplists.firehol.org/?ipset=sorbs_new_spam)|[Sorbs.net](https://www.sorbs.net/) List of hosts that have been noted as sending spam/UCE/UBE within the last 48 hours|ipv4 hash:net|33977 subnets, 35967 unique IPs|updated every 1 min
[sorbs_noserver](http://iplists.firehol.org/?ipset=sorbs_noserver)|[Sorbs.net](https://www.sorbs.net/) IP addresses and netblocks of where system administrators and ISPs owning the network have indicated that servers should not be present.|ipv4 hash:net|15066 subnets, 22951270 unique IPs|updated every 1 min
[sorbs_recent_spam](http://iplists.firehol.org/?ipset=sorbs_recent_spam)|[Sorbs.net](https://www.sorbs.net/) List of hosts that have been noted as sending spam/UCE/UBE within the last 28 days (includes sorbs_new_spam)|ipv4 hash:net|522240 subnets, 555438 unique IPs|updated every 1 min
[sorbs_smtp](http://iplists.firehol.org/?ipset=sorbs_smtp)|[Sorbs.net](https://www.sorbs.net/) List of SMTP Open Relays.|ipv4 hash:net|1968 subnets, 1976 unique IPs|updated every 1 min
[sorbs_web](http://iplists.firehol.org/?ipset=sorbs_web)|[Sorbs.net](https://www.sorbs.net/) List of IPs which have spammer abusable vulnerabilities (e.g. FormMail scripts)|ipv4 hash:net|5895259 subnets, 6375029 unique IPs|updated every 1 min
[sorbs_zombie](http://iplists.firehol.org/?ipset=sorbs_zombie)|[Sorbs.net](https://www.sorbs.net/) List of networks hijacked from their original owners, some of which have already used for spamming.|ipv4 hash:net|78 subnets, 1903876 unique IPs|updated every 1 min
[spamhaus_drop](http://iplists.firehol.org/?ipset=spamhaus_drop)|[Spamhaus.org](http://www.spamhaus.org) DROP list (according to their site this list should be dropped at tier-1 ISPs globally)|ipv4 hash:net|1321 subnets, 16335360 unique IPs|updated every 12 hours from [this link](http://www.spamhaus.org/drop/drop.txt)
[spamhaus_edrop](http://iplists.firehol.org/?ipset=spamhaus_edrop)|[Spamhaus.org](http://www.spamhaus.org) EDROP (extended matches that should be used with DROP)|ipv4 hash:net|336 subnets, 731392 unique IPs|updated every 12 hours from [this link](http://www.spamhaus.org/drop/edrop.txt)
[sslbl](http://iplists.firehol.org/?ipset=sslbl)|[Abuse.ch SSL Blacklist](https://sslbl.abuse.ch/) bad SSL traffic related to malware or botnet activities|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](https://sslbl.abuse.ch/blacklist/sslipblacklist.csv)
[sslbl_aggressive](http://iplists.firehol.org/?ipset=sslbl_aggressive)|[Abuse.ch SSL Blacklist](https://sslbl.abuse.ch/) The aggressive version of the SSL IP Blacklist contains all IPs that SSLBL ever detected being associated with a malicious SSL certificate. Since IP addresses can be reused (e.g. when the customer changes), this blacklist may cause false positives. Hence I highly recommend you to use the standard version instead of the aggressive one.|ipv4 hash:ip|0 unique IPs|updated every 30 mins from [this link](https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.csv)
[sslproxies](http://iplists.firehol.org/?ipset=sslproxies)|[SSLProxies.org](http://www.sslproxies.org/) open SSL proxies|ipv4 hash:ip|102 unique IPs|updated every 10 mins from [this link](http://www.sslproxies.org/)
[sslproxies_1d](http://iplists.firehol.org/?ipset=sslproxies_1d)|[SSLProxies.org](http://www.sslproxies.org/) open SSL proxies|ipv4 hash:ip|206 unique IPs|updated every 10 mins from [this link](http://www.sslproxies.org/)
[sslproxies_30d](http://iplists.firehol.org/?ipset=sslproxies_30d)|[SSLProxies.org](http://www.sslproxies.org/) open SSL proxies|ipv4 hash:ip|1463 unique IPs|updated every 10 mins from [this link](http://www.sslproxies.org/)
[sslproxies_7d](http://iplists.firehol.org/?ipset=sslproxies_7d)|[SSLProxies.org](http://www.sslproxies.org/) open SSL proxies|ipv4 hash:ip|573 unique IPs|updated every 10 mins from [this link](http://www.sslproxies.org/)
[stopforumspam](http://iplists.firehol.org/?ipset=stopforumspam)|[StopForumSpam.com](http://www.stopforumspam.com) Banned IPs used by forum spammers|ipv4 hash:ip|149188 unique IPs|updated every 1 day from [this link](http://www.stopforumspam.com/downloads/bannedips.zip)
[stopforumspam_180d](http://iplists.firehol.org/?ipset=stopforumspam_180d)|[StopForumSpam.com](http://www.stopforumspam.com) IPs used by forum spammers (last 180 days)|ipv4 hash:ip|259393 unique IPs|updated every 1 day from [this link](http://www.stopforumspam.com/downloads/listed_ip_180.zip)
[stopforumspam_1d](http://iplists.firehol.org/?ipset=stopforumspam_1d)|[StopForumSpam.com](http://www.stopforumspam.com) IPs used by forum spammers in the last 24 hours|ipv4 hash:ip|4256 unique IPs|updated every 1 hour from [this link](http://www.stopforumspam.com/downloads/listed_ip_1.zip)
[stopforumspam_30d](http://iplists.firehol.org/?ipset=stopforumspam_30d)|[StopForumSpam.com](http://www.stopforumspam.com) IPs used by forum spammers (last 30 days)|ipv4 hash:ip|54018 unique IPs|updated every 1 day from [this link](http://www.stopforumspam.com/downloads/listed_ip_30.zip)
[stopforumspam_365d](http://iplists.firehol.org/?ipset=stopforumspam_365d)|[StopForumSpam.com](http://www.stopforumspam.com) IPs used by forum spammers (last 365 days)|ipv4 hash:ip|487513 unique IPs|updated every 1 day from [this link](http://www.stopforumspam.com/downloads/listed_ip_365.zip)
[stopforumspam_7d](http://iplists.firehol.org/?ipset=stopforumspam_7d)|[StopForumSpam.com](http://www.stopforumspam.com) IPs used by forum spammers (last 7 days)|ipv4 hash:ip|15113 unique IPs|updated every 1 day from [this link](http://www.stopforumspam.com/downloads/listed_ip_7.zip)
[stopforumspam_90d](http://iplists.firehol.org/?ipset=stopforumspam_90d)|[StopForumSpam.com](http://www.stopforumspam.com) IPs used by forum spammers (last 90 days)|ipv4 hash:ip|150675 unique IPs|updated every 1 day from [this link](http://www.stopforumspam.com/downloads/listed_ip_90.zip)
[stopforumspam_toxic](http://iplists.firehol.org/?ipset=stopforumspam_toxic)|[StopForumSpam.com](http://www.stopforumspam.com) Networks that have large amounts of spambots and are flagged as toxic. Toxic IP ranges are infrequently changed.|ipv4 hash:net|46 subnets, 120411 unique IPs|updated every 1 day from [this link](http://www.stopforumspam.com/downloads/toxic_ip_cidr.txt)
[taichung](http://iplists.firehol.org/?ipset=taichung)|[Taichung Education Center](https://www.tc.edu.tw/net/netflow/lkout/recent/30) Blocked IP Addresses (attacks and bots).|ipv4 hash:ip|2658 unique IPs|updated every 1 day from [this link](https://www.tc.edu.tw/net/netflow/lkout/recent/30)
[talosintel_ipfilter](http://iplists.firehol.org/?ipset=talosintel_ipfilter)|[TalosIntel.com](http://talosintel.com/additional-resources/) List of known malicious network threats|ipv4 hash:ip|732 unique IPs|updated every 15 mins from [this link](http://talosintel.com/feeds/ip-filter.blf)
[threatcrowd](http://iplists.firehol.org/?ipset=threatcrowd)|[Crowdsourced IP feed from ThreatCrowd](http://threatcrowd.blogspot.gr/2016/02/crowdsourced-feeds-from-threatcrowd.html). These feeds are not a substitute for the scale of auto-extracted command and control domains or the quality of some commercially provided feeds. But crowd-sourcing does go some way towards the quick sharing of threat intelligence between the community.|ipv4 hash:ip|977 unique IPs|updated every 1 hour from [this link](https://www.threatcrowd.org/feeds/ips.txt)
[tor_exits](http://iplists.firehol.org/?ipset=tor_exits)|[TorProject.org](https://www.torproject.org) list of all current TOR exit points (TorDNSEL)|ipv4 hash:ip|1350 unique IPs|updated every 5 mins from [this link](https://check.torproject.org/exit-addresses)
[tor_exits_1d](http://iplists.firehol.org/?ipset=tor_exits_1d)|[TorProject.org](https://www.torproject.org) list of all current TOR exit points (TorDNSEL)|ipv4 hash:ip|1355 unique IPs|updated every 5 mins from [this link](https://check.torproject.org/exit-addresses)
[tor_exits_30d](http://iplists.firehol.org/?ipset=tor_exits_30d)|[TorProject.org](https://www.torproject.org) list of all current TOR exit points (TorDNSEL)|ipv4 hash:ip|1654 unique IPs|updated every 5 mins from [this link](https://check.torproject.org/exit-addresses)
[tor_exits_7d](http://iplists.firehol.org/?ipset=tor_exits_7d)|[TorProject.org](https://www.torproject.org) list of all current TOR exit points (TorDNSEL)|ipv4 hash:ip|1409 unique IPs|updated every 5 mins from [this link](https://check.torproject.org/exit-addresses)
[turris_greylist](http://iplists.firehol.org/?ipset=turris_greylist)|[Turris Greylist](https://www.turris.cz/en/greylist) IPs that are blocked on the firewalls of Turris routers. The data is processed and clasified every week and behaviour of IP addresses that accessed a larger number of Turris routers is evaluated. The result is a list of addresses that have tried to obtain information about services on the router or tried to gain access to them. We do not recommend to use these data as a list of addresses that should be blocked but it can be used for example in analysis of the traffic in other networks.|ipv4 hash:ip|9614 unique IPs|updated every 7 days from [this link](https://www.turris.cz/greylist-data/greylist-latest.csv)
[urandomusto_dns](http://iplists.firehol.org/?ipset=urandomusto_dns)|IP Feed about dns, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|67 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=dns&out=txt&submit=go)
[urandomusto_ftp](http://iplists.firehol.org/?ipset=urandomusto_ftp)|IP Feed about ftp, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|152 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=ftp&out=txt&submit=go)
[urandomusto_http](http://iplists.firehol.org/?ipset=urandomusto_http)|IP Feed about http, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|289 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=http&out=txt&submit=go)
[urandomusto_mailer](http://iplists.firehol.org/?ipset=urandomusto_mailer)|IP Feed about mailer, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|259 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=mailer&out=txt&submit=go)
[urandomusto_malware](http://iplists.firehol.org/?ipset=urandomusto_malware)|IP Feed about malware, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|1 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=malware&out=txt&submit=go)
[urandomusto_ntp](http://iplists.firehol.org/?ipset=urandomusto_ntp)|IP Feed about ntp, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|72 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=ntp&out=txt&submit=go)
[urandomusto_rdp](http://iplists.firehol.org/?ipset=urandomusto_rdp)|IP Feed about rdp, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|133 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=rdp&out=txt&submit=go)
[urandomusto_smb](http://iplists.firehol.org/?ipset=urandomusto_smb)|IP Feed about smb, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|45 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=smb&out=txt&submit=go)
[urandomusto_spam](http://iplists.firehol.org/?ipset=urandomusto_spam)|IP Feed about spam, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|4 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=spam&out=txt&submit=go)
[urandomusto_ssh](http://iplists.firehol.org/?ipset=urandomusto_ssh)|IP Feed about ssh, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|126 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=ssh&out=txt&submit=go)
[urandomusto_telnet](http://iplists.firehol.org/?ipset=urandomusto_telnet)|IP Feed about telnet, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|299 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=telnet&out=txt&submit=go)
[urandomusto_unspecified](http://iplists.firehol.org/?ipset=urandomusto_unspecified)|IP Feed about unspecified, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|178 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=unspecified&out=txt&submit=go)
[urandomusto_vnc](http://iplists.firehol.org/?ipset=urandomusto_vnc)|IP Feed about vnc, crawled from several sources, including several twitter accounts.|ipv4 hash:ip|27 unique IPs|updated every 1 hour from [this link](http://urandom.us.to/report.php?ip=&info=&tag=vnc&out=txt&submit=go)
[urlvir](http://iplists.firehol.org/?ipset=urlvir)|[URLVir.com](http://www.urlvir.com/) Active Malicious IP Addresses Hosting Malware. URLVir is an online security service developed by NoVirusThanks Company Srl that automatically monitors changes of malicious URLs (executable files).|ipv4 hash:ip|171 unique IPs|updated every 1 day from [this link](http://www.urlvir.com/export-ip-addresses/)
[uscert_hidden_cobra](http://iplists.firehol.org/?ipset=uscert_hidden_cobra)|Since 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltration of data while others have been disruptive in nature. Commercial reporting has referred to this activity as Lazarus Group and Guardians of Peace. DHS and FBI assess that HIDDEN COBRA actors will continue to use cyber operations to advance their governments military and strategic objectives. Tools and capabilities used by HIDDEN COBRA actors include DDoS botnets, keyloggers, remote access tools (RATs), and wiper malware. Variants of malware and tools used by HIDDEN COBRA actors include Destover, Wild Positron/Duuzer and Hangman.|ipv4 hash:ip|627 unique IPs|updated every 1 day from [this link](https://www.us-cert.gov/sites/default/files/publications/TA-17-164A_csv.csv)
[voipbl](http://iplists.firehol.org/?ipset=voipbl)|[VoIPBL.org](http://www.voipbl.org/) a distributed VoIP blacklist that is aimed to protects against VoIP Fraud and minimizing abuse for network that have publicly accessible PBX's. Several algorithms, external sources and manual confirmation are used before they categorize something as an attack and determine the threat level.|ipv4 hash:net|57978 subnets, 76250 unique IPs|updated every 4 hours from [this link](http://www.voipbl.org/update/)
[vxvault](http://iplists.firehol.org/?ipset=vxvault)|[VxVault](http://vxvault.net) The latest 100 additions of VxVault.|ipv4 hash:ip|48 unique IPs|updated every 12 hours from [this link](http://vxvault.net/ViriList.php?s=0&m=100)
[xforce_bccs](http://iplists.firehol.org/?ipset=xforce_bccs)|[IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/) Botnet Command and Control Servers|ipv4 hash:ip|416 unique IPs|updated every 1 day from [this link](https://api.xforce.ibmcloud.com/taxii)
[xroxy](http://iplists.firehol.org/?ipset=xroxy)|[xroxy.com](http://www.xroxy.com) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|17 unique IPs|updated every 1 hour from [this link](http://www.xroxy.com/proxyrss.xml)
[xroxy_1d](http://iplists.firehol.org/?ipset=xroxy_1d)|[xroxy.com](http://www.xroxy.com) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|17 unique IPs|updated every 1 hour from [this link](http://www.xroxy.com/proxyrss.xml)
[xroxy_30d](http://iplists.firehol.org/?ipset=xroxy_30d)|[xroxy.com](http://www.xroxy.com) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|76 unique IPs|updated every 1 hour from [this link](http://www.xroxy.com/proxyrss.xml)
[xroxy_7d](http://iplists.firehol.org/?ipset=xroxy_7d)|[xroxy.com](http://www.xroxy.com) open proxies (this list is composed using an RSS feed)|ipv4 hash:ip|45 unique IPs|updated every 1 hour from [this link](http://www.xroxy.com/proxyrss.xml)
[yoyo_adservers](http://iplists.firehol.org/?ipset=yoyo_adservers)|[Yoyo.org](http://pgl.yoyo.org/adservers/) IPs of ad servers|ipv4 hash:ip|9235 unique IPs|updated every 12 hours from [this link](http://pgl.yoyo.org/adservers/iplist.php?ipformat=plain&showintro=0&mimetype=plaintext)
zeus|[Abuse.ch Zeus tracker](https://zeustracker.abuse.ch) standard, contains the same data as the ZeuS IP blocklist (zeus_badips) but with the slight difference that it doesn't exclude hijacked websites (level 2) and free web hosting providers (level 3). This means that this blocklist contains all IPv4 addresses associated with ZeuS C&Cs which are currently being tracked by ZeuS Tracker. Hence this blocklist will likely cause some false positives.|ipv4 hash:ip|disabled|updated every 30 mins from [this link](https://zeustracker.abuse.ch/blocklist.php?download=ipblocklist)
zeus_badips|[Abuse.ch Zeus tracker](https://zeustracker.abuse.ch) badips includes IPv4 addresses that are used by the ZeuS trojan. It is the recommened blocklist if you want to block only ZeuS IPs. It excludes IP addresses that ZeuS Tracker believes to be hijacked (level 2) or belong to a free web hosting provider (level 3). Hence the false postive rate should be much lower compared to the standard ZeuS IP blocklist.|ipv4 hash:ip|disabled|updated every 30 mins from [this link](https://zeustracker.abuse.ch/blocklist.php?download=badips)

639
alienvault_reputation.ipset Normal file
View File

@ -0,0 +1,639 @@
#
# alienvault_reputation
#
# ipv4 hash:ip ipset
#
# [AlienVault.com] (https://www.alienvault.com/) IP
# reputation database
#
# Maintainer : Alien Vault
# Maintainer URL : https://www.alienvault.com/
# List source URL : https://reputation.alienvault.com/reputation.generic
# Source File Date: Fri Nov 12 14:10:50 UTC 2021
#
# Category : reputation
# Version : 4236
#
# This File Date : Fri Nov 12 15:52:25 UTC 2021
# Update Frequency: 6 hours
# Aggregation : none
# Entries : 609 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=alienvault_reputation
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.34.58.110
1.34.226.50
1.161.219.86
1.171.103.192
1.173.242.161
1.246.222.20
1.246.222.134
1.246.222.234
1.246.223.191
2.106.156.53
3.21.74.31
4.71.37.45
4.71.37.46
14.34.157.101
14.42.145.172
14.111.220.134
14.241.244.250
18.117.69.135
18.188.148.80
23.247.108.44
24.188.100.85
27.21.147.209
27.35.154.75
27.38.61.75
27.38.61.120
27.41.36.239
27.43.119.144
27.43.178.112
27.47.116.249
27.158.79.129
27.159.92.181
27.194.89.189
27.194.122.23
27.197.24.223
27.199.237.162
27.203.233.132
27.207.195.126
27.215.53.111
27.215.109.196
27.215.114.223
27.215.122.160
27.217.163.40
27.217.243.163
36.228.50.77
36.231.35.185
37.0.10.31
39.66.73.50
39.74.177.167
39.81.71.78
41.86.5.232
41.86.18.34
41.86.18.165
41.86.19.146
42.51.55.157
42.115.33.98
42.228.193.67
42.231.171.245
43.251.99.6
44.192.244.178
45.146.164.110
45.229.54.55
45.229.54.83
45.229.54.143
45.229.54.193
45.229.54.199
45.229.54.212
45.229.55.57
45.229.55.69
45.229.55.112
45.248.192.48
46.4.123.15
46.101.13.94
46.183.218.151
49.76.60.132
49.89.62.252
49.89.90.173
49.89.93.21
49.89.95.159
49.143.32.6
49.158.196.18
49.213.183.219
49.213.187.246
51.15.228.117
51.15.246.104
51.158.64.113
51.158.102.132
51.158.108.237
51.158.117.164
51.158.125.226
51.211.24.160
51.211.112.79
51.211.117.109
58.58.41.106
58.99.99.34
58.219.232.140
58.248.147.64
58.248.193.3
58.248.193.50
58.248.193.88
58.248.193.97
58.248.193.105
58.248.193.132
58.248.193.141
58.248.193.232
58.248.193.246
58.249.12.95
58.249.87.78
58.249.110.198
58.253.12.9
59.63.204.76
59.63.204.245
59.63.207.69
59.126.96.5
59.127.209.88
59.175.63.89
60.212.108.240
60.244.133.195
61.0.168.149
61.129.101.38
61.152.197.56
61.219.98.43
61.224.147.178
61.242.40.14
61.242.40.17
61.242.40.204
61.242.40.206
61.242.40.212
61.242.40.225
61.242.40.229
61.242.40.245
61.242.54.5
61.242.54.16
61.242.54.48
61.242.54.49
61.242.54.60
61.242.54.62
61.242.54.126
61.242.54.137
61.242.54.170
61.242.54.175
61.242.54.203
61.242.54.211
61.242.54.214
61.242.54.239
61.242.54.242
61.242.54.249
61.242.58.12
61.242.58.14
61.242.58.47
61.242.58.66
61.242.58.67
61.242.58.104
61.242.58.135
61.242.58.178
61.242.58.197
61.242.58.200
61.242.58.239
61.242.58.246
62.4.14.198
62.16.41.210
62.171.159.207
62.219.229.190
64.39.108.94
65.108.11.163
68.183.107.64
69.55.55.230
69.176.89.226
70.50.152.130
70.50.155.251
71.68.229.247
78.142.18.56
78.154.219.169
78.186.248.243
78.187.196.38
78.188.240.230
79.170.30.142
80.14.216.204
80.82.65.247
80.243.181.81
80.243.181.119
81.214.72.215
81.250.169.249
83.138.53.128
84.53.229.12
85.71.26.28
86.157.2.211
86.161.0.86
86.175.105.80
86.181.4.169
89.40.73.14
89.208.122.213
91.104.31.56
91.188.215.198
91.234.62.231
93.51.27.113
93.65.23.221
93.112.152.134
94.156.58.17
95.137.248.182
100.27.42.241
100.27.42.242
100.27.42.243
100.27.42.244
101.0.32.22
101.0.41.25
101.0.57.60
101.0.57.158
101.22.144.130
101.65.131.144
101.181.0.198
101.181.17.112
101.181.17.137
101.181.26.186
101.181.27.80
101.181.34.69
101.181.40.233
101.181.60.181
101.181.68.79
101.181.73.91
101.181.82.102
101.181.98.158
101.181.102.108
101.181.104.241
101.181.114.172
101.181.132.37
103.37.3.58
103.40.172.173
103.40.172.189
103.40.196.2
103.40.196.24
103.40.197.24
103.40.197.175
103.91.19.231
103.91.245.48
103.104.106.98
103.104.106.223
103.119.55.151
103.136.82.50
103.170.92.5
103.170.92.7
103.170.92.10
103.170.92.11
103.170.92.22
103.206.21.107
103.215.240.1
103.231.172.42
104.131.14.192
104.131.82.45
104.248.162.33
106.104.116.79
109.116.204.63
109.123.118.38
110.25.95.241
110.35.227.222
110.89.11.143
110.251.198.23
111.38.106.48
111.92.75.188
111.92.75.217
111.92.116.45
111.165.36.134
111.185.227.109
111.185.228.37
111.202.167.22
111.202.190.6
111.252.213.245
112.5.37.160
112.6.221.37
112.27.124.111
112.27.124.130
112.27.124.145
112.27.124.158
112.30.4.73
112.30.4.118
112.31.87.98
112.31.211.135
112.86.255.100
112.94.96.114
112.94.97.85
112.94.97.166
112.94.98.6
112.94.98.57
112.94.98.71
112.94.98.151
112.94.99.84
112.94.99.86
112.94.99.93
112.94.99.139
112.94.101.190
112.94.101.203
112.94.101.235
112.105.10.251
112.235.46.128
112.237.2.80
112.239.103.43
112.239.120.150
112.248.109.159
112.250.243.72
112.251.18.12
112.255.126.89
113.170.128.242
113.246.130.182
113.251.235.19
114.33.64.24
114.33.190.246
114.34.135.57
114.35.131.161
114.35.175.239
114.35.194.18
114.36.34.63
114.41.226.96
114.236.52.101
114.239.51.77
114.246.35.129
115.51.122.143
115.58.202.92
115.62.58.10
115.165.221.95
116.2.173.20
116.68.99.71
116.211.100.26
116.212.156.31
117.36.199.38
117.87.18.27
117.95.137.93
117.204.149.200
117.208.51.51
117.240.142.212
118.79.140.135
118.161.210.248
118.250.154.242
119.29.119.174
119.122.114.138
119.165.111.147
119.179.238.100
119.191.160.221
119.191.217.155
119.224.91.233
120.1.140.25
120.85.92.40
120.85.93.174
120.85.94.182
120.85.97.71
120.85.112.124
120.85.112.128
120.85.112.133
120.85.113.42
120.85.113.55
120.85.113.120
120.85.113.253
120.85.114.64
120.85.114.146
120.85.114.164
120.85.114.188
120.85.115.2
120.85.115.46
120.85.115.49
120.85.115.60
120.85.115.75
120.85.115.104
120.85.115.148
120.85.115.175
120.85.115.197
120.85.115.225
120.85.116.17
120.85.116.69
120.85.116.70
120.85.116.133
120.85.116.230
120.85.116.238
120.85.117.207
120.85.118.78
120.85.118.161
120.85.118.169
120.85.118.195
120.85.118.219
120.85.118.227
120.85.118.235
120.85.118.238
120.85.148.26
120.85.149.112
120.85.172.249
120.86.236.214
120.86.236.217
120.86.237.94
120.86.237.166
120.86.238.47
120.86.238.188
120.86.239.97
120.86.239.154
120.86.254.133
120.86.254.188
120.86.255.109
120.86.255.247
120.193.91.183
120.193.91.190
120.193.91.215
120.226.28.53
120.226.28.55
120.226.28.56
120.238.189.72
120.240.48.83
120.240.48.91
121.5.155.158
121.46.232.130
121.61.98.22
121.206.154.132
122.96.12.203
122.116.229.208
122.116.240.129
122.117.28.200
122.117.212.66
122.147.22.146
122.147.62.76
122.173.23.55
122.188.150.21
122.254.29.23
123.10.15.34
123.11.152.93
123.12.23.5
123.110.213.41
123.205.156.212
124.131.55.15
124.153.136.175
125.44.11.69
125.63.105.55
125.127.132.112
125.127.139.69
125.128.28.181
125.168.147.202
125.224.126.41
125.228.33.211
125.228.43.197
125.228.89.178
125.228.90.229
134.209.218.203
137.184.62.180
140.206.86.124
146.70.34.2
156.251.136.4
157.61.212.1
157.61.212.29
157.61.212.37
157.61.212.41
157.61.212.44
157.61.212.47
157.61.212.55
157.61.212.57
157.61.212.59
157.61.212.64
157.61.212.78
157.61.212.82
157.61.212.84
157.61.212.85
157.61.212.87
157.61.212.88
157.61.212.95
157.61.212.101
157.61.212.104
157.61.212.109
157.61.212.111
157.61.212.117
157.61.212.122
157.61.213.140
157.61.213.146
157.61.213.149
157.61.213.165
157.61.213.174
157.61.213.179
157.61.213.238
157.61.213.240
159.203.186.159
160.124.138.190
161.22.34.116
161.97.143.54
163.125.211.103
163.125.211.119
163.125.211.144
163.172.140.20
163.172.176.168
163.179.167.155
163.204.211.80
164.155.88.34
165.227.74.61
165.227.84.230
167.71.249.184
167.172.59.207
170.247.76.178
170.247.76.179
174.83.73.163
175.9.135.33
175.10.19.32
175.11.64.24
175.183.4.23
175.183.16.135
176.103.88.57
176.111.173.122
176.111.173.139
176.221.206.115
177.149.164.24
178.18.254.229
178.72.69.78
178.72.70.88
178.72.70.112
178.72.70.124
178.72.70.207
178.72.70.239
178.72.76.2
178.72.78.156
178.72.78.202
178.141.14.216
180.151.24.60
180.176.99.48
180.188.232.122
180.188.232.137
180.188.237.170
181.176.155.25
181.199.162.7
181.199.170.222
182.52.136.45
182.115.173.95
182.124.92.70
182.155.120.143
182.166.180.194
182.235.208.124
183.82.144.126
183.161.1.19
183.237.146.175
183.237.146.206
184.58.233.179
185.68.230.207
185.128.41.50
185.142.239.135
185.191.32.158
185.191.246.45
185.232.64.32
186.33.90.249
186.250.115.93
187.45.116.162
188.169.36.27
188.169.174.166
190.180.154.227
192.3.194.202
193.169.252.158
193.169.252.166
193.169.252.245
195.208.154.9
198.98.62.43
201.71.186.178
201.184.16.244
201.184.49.234
201.184.54.178
201.184.54.179
201.184.54.180
201.184.64.238
201.184.89.98
202.129.58.130
202.164.138.157
202.164.139.168
202.164.139.218
202.164.139.229
203.176.129.73
203.248.175.71
203.248.175.72
206.189.111.16
207.180.219.238
210.13.110.60
210.89.63.21
210.89.63.231
210.89.63.245
210.108.70.119
210.180.237.212
211.47.83.200
211.149.191.209
212.129.26.4
212.193.30.144
213.5.47.43
216.4.95.61
216.4.95.62
218.29.126.53
218.31.123.90
218.161.106.26
219.68.238.49
219.69.110.206
219.136.172.161
219.138.140.114
219.157.139.165
220.133.64.233
220.134.64.169
220.134.206.134
220.134.236.78
220.135.135.44
220.135.241.12
220.143.33.129
221.1.225.191
221.1.226.15
221.160.177.119
221.231.169.141
222.77.181.28
222.118.4.29
222.138.119.194
222.240.117.88
222.247.5.78
222.253.45.141
223.130.31.57
223.149.1.211
223.149.140.37
223.155.34.126
223.159.88.8

30
asprox_c2.ipset Normal file
View File

@ -0,0 +1,30 @@
#
# asprox_c2
#
# ipv4 hash:ip ipset
#
# [h3x.eu] (http://atrack.h3x.eu/) ASPROX Tracker - Asprox
# C&C Sites
#
# Maintainer : h3x.eu
# Maintainer URL : http://atrack.h3x.eu/
# List source URL : http://atrack.h3x.eu/c2
# Source File Date: Mon Nov 6 03:04:11 UTC 2017
#
# Category : malware
# Version : 1
#
# This File Date : Sun Jun 3 05:36:21 UTC 2018
# Update Frequency: 1 day
# Aggregation : none
# Entries : 0 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=asprox_c2
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#

167
bambenek_banjori.ipset Normal file
View File

@ -0,0 +1,167 @@
#
# bambenek_banjori
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of banjori C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/banjori-iplist.txt
# Source File Date: Wed Jul 29 20:05:53 UTC 2020
#
# Category : malware
# Version : 17534
#
# This File Date : Wed Jul 29 20:12:14 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 136 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_banjori
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
3.216.121.17
5.79.79.212
13.59.74.74
14.192.4.75
18.213.250.117
18.215.128.143
23.89.20.107
23.89.102.123
23.107.124.53
23.110.15.74
23.226.53.226
23.227.38.65
23.231.218.195
23.236.62.147
34.98.99.30
34.102.136.180
35.186.238.101
35.226.69.129
43.230.142.125
43.241.196.105
43.249.76.176
47.91.170.222
47.245.10.59
50.117.86.130
52.4.209.250
52.25.92.0
52.58.78.16
54.65.172.3
54.85.65.140
62.149.142.219
67.20.112.155
74.208.236.219
74.220.199.8
78.24.9.52
78.46.156.194
81.169.145.88
81.169.145.159
81.169.145.160
81.169.145.161
89.188.24.70
92.53.96.22
94.130.109.30
95.211.75.10
96.30.52.60
103.70.226.182
104.24.102.57
104.24.103.57
104.24.108.92
104.24.109.92
104.164.181.36
104.171.23.69
104.171.23.70
107.165.137.88
107.180.26.185
108.59.12.99
108.59.12.101
109.70.4.246
109.71.54.17
112.78.125.29
112.121.187.246
119.3.179.174
119.188.157.23
121.40.153.149
121.54.175.96
122.10.99.22
130.211.40.170
133.130.35.90
133.242.195.32
134.73.61.187
137.175.15.6
145.131.10.247
149.255.58.42
150.95.255.38
154.95.106.131
154.195.133.14
154.195.209.90
154.201.77.14
154.213.139.148
154.216.122.13
154.216.243.104
156.224.61.139
156.225.101.57
156.238.79.182
156.247.12.40
156.250.218.137
158.177.208.8
160.121.36.178
160.153.96.67
162.209.205.67
162.210.102.66
162.210.195.111
163.43.102.74
169.50.13.61
169.50.57.89
172.67.143.254
172.67.211.10
172.106.32.42
175.29.102.46
178.22.59.66
180.153.100.94
185.104.45.33
185.135.241.4
185.216.113.170
186.202.153.222
192.169.243.26
192.190.87.140
193.222.100.37
196.22.132.17
198.23.48.104
198.38.83.24
198.54.117.197
198.54.117.198
198.54.117.199
198.54.117.200
198.54.121.133
199.58.179.10
199.59.242.153
202.124.241.178
202.181.97.76
202.254.234.152
203.156.192.80
208.73.210.202
208.73.210.217
208.73.211.165
208.73.211.177
208.91.197.91
208.109.80.14
212.12.54.87
213.176.50.208
213.186.33.5
216.40.47.17
217.26.53.16
217.26.63.20
217.70.184.38
219.118.71.121
219.235.5.224

31
bambenek_bebloh.ipset Normal file
View File

@ -0,0 +1,31 @@
#
# bambenek_bebloh
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of bebloh C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/bebloh-iplist.txt
# Source File Date: Thu Jun 7 00:02:37 UTC 2018
#
# Category : malware
# Version : 6
#
# This File Date : Thu Jun 7 00:08:33 UTC 2018
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 0 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_bebloh
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#

32
bambenek_c2.ipset Normal file
View File

@ -0,0 +1,32 @@
#
# bambenek_c2
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) master feed of
# known, active and non-sinkholed C&Cs IP addresses
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt
# Source File Date: Wed Jan 5 14:31:38 UTC 2022
#
# Category : malware
# Version : 16213
#
# This File Date : Thu Jan 6 06:56:05 UTC 2022
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 1 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_c2
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
127.200.200.200

31
bambenek_cl.ipset Normal file
View File

@ -0,0 +1,31 @@
#
# bambenek_cl
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of cl C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/cl-iplist.txt
# Source File Date: Fri Dec 14 00:05:01 UTC 2018
#
# Category : malware
# Version : 18
#
# This File Date : Fri Dec 14 00:08:08 UTC 2018
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 0 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_cl
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#

31
bambenek_cryptowall.ipset Normal file
View File

@ -0,0 +1,31 @@
#
# bambenek_cryptowall
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of cryptowall C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/cryptowall-iplist.txt
# Source File Date: Thu Dec 3 12:25:05 UTC 2015
#
# Category : malware
# Version : 5
#
# This File Date : Thu Jun 7 00:08:34 UTC 2018
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 0 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_cryptowall
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#

33
bambenek_dircrypt.ipset Normal file
View File

@ -0,0 +1,33 @@
#
# bambenek_dircrypt
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of dircrypt C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/dircrypt-iplist.txt
# Source File Date: Sat Jul 18 09:06:23 UTC 2020
#
# Category : malware
# Version : 260
#
# This File Date : Sat Jul 18 09:08:07 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 2 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_dircrypt
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
164.155.216.36
169.50.13.61

31
bambenek_dyre.ipset Normal file
View File

@ -0,0 +1,31 @@
#
# bambenek_dyre
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of dyre C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/dyre-iplist.txt
# Source File Date: Thu Jun 7 00:03:08 UTC 2018
#
# Category : malware
# Version : 6
#
# This File Date : Thu Jun 7 00:08:34 UTC 2018
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 0 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_dyre
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#

31
bambenek_geodo.ipset Normal file
View File

@ -0,0 +1,31 @@
#
# bambenek_geodo
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of geodo C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/geodo-iplist.txt
# Source File Date: Thu Jun 7 00:02:33 UTC 2018
#
# Category : malware
# Version : 6
#
# This File Date : Thu Jun 7 00:08:34 UTC 2018
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 0 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_geodo
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#

33
bambenek_hesperbot.ipset Normal file
View File

@ -0,0 +1,33 @@
#
# bambenek_hesperbot
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of hesperbot C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/hesperbot-iplist.txt
# Source File Date: Sat Jul 18 10:07:53 UTC 2020
#
# Category : malware
# Version : 234
#
# This File Date : Sat Jul 18 10:12:32 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 2 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_hesperbot
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
72.5.161.7
164.155.219.11

32
bambenek_matsnu.ipset Normal file
View File

@ -0,0 +1,32 @@
#
# bambenek_matsnu
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of matsnu C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/matsnu-iplist.txt
# Source File Date: Mon Jul 27 04:09:06 UTC 2020
#
# Category : malware
# Version : 522
#
# This File Date : Mon Jul 27 04:12:41 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 1 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_matsnu
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
64.207.152.130

44
bambenek_necurs.ipset Normal file
View File

@ -0,0 +1,44 @@
#
# bambenek_necurs
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of necurs C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/necurs-iplist.txt
# Source File Date: Wed Jul 29 01:11:02 UTC 2020
#
# Category : malware
# Version : 10186
#
# This File Date : Wed Jul 29 01:16:08 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 13 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_necurs
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
40.121.206.97
64.47.209.23
64.63.188.85
64.231.250.149
65.79.10.48
65.159.138.178
66.7.34.215
66.247.157.54
68.199.246.20
69.47.125.180
69.79.159.208
70.23.145.183
70.63.91.183

31
bambenek_p2pgoz.ipset Normal file
View File

@ -0,0 +1,31 @@
#
# bambenek_p2pgoz
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of p2pgoz C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/p2pgoz-iplist.txt
# Source File Date: Sun Jul 26 15:10:57 UTC 2020
#
# Category : malware
# Version : 478
#
# This File Date : Sun Jul 26 15:16:09 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 0 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_p2pgoz
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#

31
bambenek_pushdo.ipset Normal file
View File

@ -0,0 +1,31 @@
#
# bambenek_pushdo
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of pushdo C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/pushdo-iplist.txt
# Source File Date: Sat Jun 20 05:15:31 UTC 2020
#
# Category : malware
# Version : 12
#
# This File Date : Sat Jun 20 05:20:06 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 0 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_pushdo
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#

36
bambenek_pykspa.ipset Normal file
View File

@ -0,0 +1,36 @@
#
# bambenek_pykspa
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of pykspa C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/pykspa-iplist.txt
# Source File Date: Wed Jul 29 04:13:10 UTC 2020
#
# Category : malware
# Version : 1373
#
# This File Date : Wed Jul 29 04:16:06 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 5 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_pykspa
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
40.255.0.62
78.47.106.15
169.50.13.61
189.50.110.40
193.146.253.37

33
bambenek_qakbot.ipset Normal file
View File

@ -0,0 +1,33 @@
#
# bambenek_qakbot
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of qakbot C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/qakbot-iplist.txt
# Source File Date: Sun Jul 26 12:13:39 UTC 2020
#
# Category : malware
# Version : 453
#
# This File Date : Sun Jul 26 12:16:47 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 2 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_qakbot
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
72.26.218.72
199.21.76.82

129
bambenek_ramnit.ipset Normal file
View File

@ -0,0 +1,129 @@
#
# bambenek_ramnit
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of ramnit C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/ramnit-iplist.txt
# Source File Date: Wed Jul 29 20:18:04 UTC 2020
#
# Category : malware
# Version : 3671
#
# This File Date : Wed Jul 29 20:24:06 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 98 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_ramnit
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
5.180.102.147
13.90.196.81
18.213.250.117
18.215.128.143
34.197.76.50
34.225.182.233
35.224.11.86
46.17.47.67
46.165.220.141
46.165.220.142
46.165.220.143
46.165.220.144
46.165.220.145
46.165.220.146
46.165.220.147
46.165.220.148
46.165.220.149
46.165.220.150
46.165.220.151
46.165.220.152
46.165.220.153
46.165.220.154
46.165.220.155
46.165.221.136
46.165.221.144
46.165.221.154
46.165.229.164
46.165.229.165
46.165.229.166
46.165.229.167
46.165.254.193
46.165.254.194
46.165.254.195
46.165.254.196
46.165.254.197
46.165.254.198
46.165.254.199
46.165.254.200
46.165.254.201
46.165.254.202
46.165.254.203
46.165.254.204
46.165.254.205
46.165.254.206
46.165.254.207
46.165.254.208
46.165.254.209
46.165.254.210
46.165.254.211
46.165.254.212
46.165.254.213
46.165.254.214
47.91.170.222
52.4.209.250
72.26.218.70
82.112.184.197
88.212.208.67
109.248.10.176
154.216.211.122
160.16.199.126
160.16.223.90
164.155.216.31
169.50.13.61
173.239.5.6
173.239.8.164
178.33.69.68
193.146.253.36
193.146.253.38
193.146.253.44
194.67.71.41
194.67.71.114
208.91.197.66
213.186.33.19
213.247.47.190
217.20.116.129
217.20.116.130
217.20.116.131
217.20.116.132
217.20.116.133
217.20.116.134
217.20.116.135
217.20.116.136
217.20.116.137
217.20.116.138
217.20.116.139
217.20.116.140
217.20.116.141
217.20.116.142
217.20.116.143
217.20.116.145
217.20.116.146
217.20.116.147
217.20.116.148
217.20.116.149
217.20.116.150
217.20.116.151
217.20.116.152
217.20.116.153

31
bambenek_ranbyus.ipset Normal file
View File

@ -0,0 +1,31 @@
#
# bambenek_ranbyus
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of ranbyus C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/ranbyus-iplist.txt
# Source File Date: Thu Feb 14 14:06:27 UTC 2019
#
# Category : malware
# Version : 101
#
# This File Date : Thu Feb 14 14:12:10 UTC 2019
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 0 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_ranbyus
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#

162
bambenek_simda.ipset Normal file
View File

@ -0,0 +1,162 @@
#
# bambenek_simda
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of simda C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/simda-iplist.txt
# Source File Date: Wed Jul 29 20:19:03 UTC 2020
#
# Category : malware
# Version : 17362
#
# This File Date : Wed Jul 29 20:24:07 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 131 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_simda
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
5.157.84.170
14.128.136.68
23.89.102.127
23.236.62.147
31.11.32.144
31.186.169.41
31.217.192.121
34.98.99.30
34.102.136.180
45.82.253.244
46.28.105.107
46.30.215.127
46.30.215.202
46.242.242.252
46.249.43.105
52.25.92.0
52.58.78.16
54.65.172.3
62.97.115.37
62.129.200.14
62.149.128.72
62.149.128.74
62.149.128.151
62.149.128.154
62.149.128.157
62.149.128.160
62.149.128.163
62.149.128.166
62.149.181.236
62.153.122.95
67.229.36.115
69.162.80.54
69.162.80.58
77.111.240.49
77.111.240.59
79.170.40.236
80.85.86.6
80.237.132.180
81.2.194.62
81.2.194.128
81.2.194.176
81.169.145.68
81.169.145.84
81.169.145.93
81.169.145.94
81.169.145.105
81.169.145.161
81.177.165.51
82.98.135.43
82.100.220.53
84.38.224.155
85.13.129.76
85.13.132.239
85.114.135.128
85.128.185.12
85.236.47.218
87.98.230.60
88.198.56.106
89.31.143.1
89.46.108.57
91.121.59.137
91.121.154.229
91.174.205.10
91.195.241.136
91.199.77.50
91.212.28.29
91.223.145.130
92.43.203.171
92.61.39.239
93.185.103.42
93.190.48.3
94.152.8.56
95.211.117.215
95.211.219.65
104.27.180.160
104.27.181.160
104.28.26.243
104.28.27.243
104.28.28.252
104.28.29.252
116.202.231.184
141.105.126.87
146.148.34.125
149.216.106.61
157.7.188.207
162.217.99.134
162.255.119.102
163.172.86.124
169.50.13.61
172.67.156.67
172.67.157.206
172.67.184.127
173.236.178.74
178.254.10.14
185.26.105.244
185.51.65.38
185.66.237.14
185.114.108.15
185.181.104.74
185.183.8.67
185.232.248.163
188.93.150.101
188.165.143.5
192.64.147.231
193.41.64.176
194.9.94.85
194.9.94.86
194.150.113.18
194.242.61.31
195.74.38.62
195.110.124.188
199.34.228.76
199.59.242.153
205.144.171.124
208.91.197.91
209.140.30.61
210.172.183.32
211.43.203.53
212.57.32.149
212.85.106.71
213.186.33.5
217.70.184.38
217.74.71.168
217.116.16.235
217.160.0.59
217.160.0.97
217.160.0.169
217.160.0.225
217.160.0.239
217.160.122.61
217.160.233.84

139
bambenek_suppobox.ipset Normal file
View File

@ -0,0 +1,139 @@
#
# bambenek_suppobox
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of suppobox C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/suppobox-iplist.txt
# Source File Date: Wed Jul 29 20:19:32 UTC 2020
#
# Category : malware
# Version : 9682
#
# This File Date : Wed Jul 29 20:24:08 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 108 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_suppobox
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
18.216.20.136
23.83.35.75
23.227.38.65
23.236.62.147
34.102.136.180
34.198.7.77
34.202.122.77
34.225.38.128
35.169.225.248
35.186.238.101
35.231.184.193
39.106.40.57
43.226.23.42
45.133.2.132
45.192.23.245
45.199.245.19
46.30.213.209
46.166.189.98
52.0.7.30
54.36.56.87
54.84.104.245
62.233.121.5
63.251.235.71
66.6.44.4
66.96.161.157
67.195.197.24
67.227.226.240
69.163.184.176
69.172.201.218
72.26.218.72
74.96.70.52
74.208.236.135
75.2.37.224
80.77.123.65
81.28.232.67
83.140.241.13
84.49.232.107
87.98.242.65
89.106.12.49
94.136.40.82
95.143.172.148
97.74.182.1
98.124.199.77
103.67.235.120
104.16.12.194
104.16.13.194
104.16.14.194
104.16.15.194
104.16.16.194
104.27.188.229
104.27.189.229
104.248.50.87
104.248.60.43
104.248.63.231
104.248.63.248
106.249.28.73
112.216.156.206
121.42.239.99
121.78.197.82
121.254.178.233
137.220.193.208
138.207.69.72
139.129.156.33
150.95.255.38
151.80.184.231
154.208.167.236
157.65.171.29
157.245.130.6
159.8.210.35
161.47.102.211
162.217.99.134
162.217.99.139
162.217.99.141
162.241.194.34
162.241.224.134
162.241.224.200
162.243.212.245
162.255.119.8
162.255.119.250
172.67.154.177
173.231.184.119
173.231.189.30
173.236.166.37
185.55.85.123
192.64.119.20
192.64.119.148
192.64.119.202
192.227.107.19
193.93.253.54
194.59.222.76
198.54.117.197
198.54.117.198
198.54.117.199
198.54.117.200
199.34.228.69
199.59.242.153
206.191.152.37
206.191.152.49
207.96.1.77
208.91.197.26
208.91.197.27
208.91.197.46
208.91.197.91
208.91.197.194
212.96.137.160
213.186.33.5
213.250.113.193
217.160.0.16

32
bambenek_symmi.ipset Normal file
View File

@ -0,0 +1,32 @@
#
# bambenek_symmi
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of symmi C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/symmi-iplist.txt
# Source File Date: Fri Jun 26 10:49:11 UTC 2020
#
# Category : malware
# Version : 14
#
# This File Date : Fri Jun 26 10:56:26 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 1 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_symmi
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
208.100.26.245

35
bambenek_tinba.ipset Normal file
View File

@ -0,0 +1,35 @@
#
# bambenek_tinba
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of tinba C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/tinba-iplist.txt
# Source File Date: Wed Jul 29 16:20:23 UTC 2020
#
# Category : malware
# Version : 3576
#
# This File Date : Wed Jul 29 16:24:10 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 4 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_tinba
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
198.54.117.197
198.54.117.198
198.54.117.199
198.54.117.200

32
bambenek_volatile.ipset Normal file
View File

@ -0,0 +1,32 @@
#
# bambenek_volatile
#
# ipv4 hash:ip ipset
#
# [Bambenek Consulting]
# (http://osint.bambenekconsulting.com/feeds/) feed of
# current IPs of volatile C&Cs with 90 minute lookback
#
# Maintainer : Bambenek Consulting
# Maintainer URL : http://osint.bambenekconsulting.com/feeds/
# List source URL : http://osint.bambenekconsulting.com/feeds/volatile-iplist.txt
# Source File Date: Fri Feb 7 15:08:38 UTC 2020
#
# Category : malware
# Version : 10
#
# This File Date : Fri Feb 7 15:12:21 UTC 2020
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 1 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bambenek_volatile
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
169.50.13.61

2717
bbcan177_ms1.netset Normal file

File diff suppressed because it is too large Load Diff

1175
bbcan177_ms3.netset Normal file

File diff suppressed because it is too large Load Diff

466
bds_atif.ipset Normal file
View File

@ -0,0 +1,466 @@
#
# bds_atif
#
# ipv4 hash:ip ipset
#
# Artillery Threat Intelligence Feed and Banlist Feed
#
# Maintainer : Binary Defense Systems
# Maintainer URL : https://www.binarydefense.com/
# List source URL : https://www.binarydefense.com/banlist.txt
# Source File Date: Tue Apr 16 16:53:31 UTC 2024
#
# Category : reputation
# Version : 2054
#
# This File Date : Tue Apr 16 17:04:45 UTC 2024
# Update Frequency: 1 day
# Aggregation : none
# Entries : 437 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bds_atif
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.54.240.135
1.227.83.31
2.47.150.85
2.57.149.186
2.57.149.233
2.59.241.196
2.178.157.38
2.189.242.13
3.10.207.34
3.81.0.39
3.89.33.247
3.89.138.15
3.91.24.214
3.110.161.54
3.208.31.248
5.10.250.18
5.10.250.35
5.10.250.79
5.147.79.84
5.160.136.182
5.200.73.214
5.230.39.238
5.237.193.52
8.137.17.173
8.210.72.158
12.202.157.121
13.40.97.173
13.57.207.94
13.90.34.73
14.18.238.142
14.38.141.178
14.99.251.242
14.100.8.62
14.152.70.100
14.153.6.76
14.155.222.116
14.160.43.186
14.161.89.114
14.165.130.89
14.168.162.253
14.191.100.225
14.191.177.103
14.228.217.111
14.235.54.175
14.250.52.144
14.254.66.175
15.204.52.61
15.204.204.182
15.204.207.64
18.116.86.176
20.55.53.144
20.127.233.150
20.203.43.236
20.212.176.163
20.232.18.7
23.94.107.14
23.94.247.41
23.247.108.50
24.50.241.101
24.144.96.191
24.152.5.183
24.234.55.153
27.25.131.54
27.43.206.227
27.74.245.56
27.98.228.37
27.109.3.91
31.11.102.241
31.141.253.49
31.145.166.54
31.148.168.102
31.214.0.8
34.76.96.55
34.78.249.41
34.134.221.95
34.140.108.54
34.140.130.61
34.199.35.105
35.94.31.128
35.168.126.196
35.203.210.67
35.203.210.86
35.203.210.99
35.203.210.171
35.203.211.124
35.203.211.186
35.216.135.31
35.216.207.137
35.216.245.84
35.240.121.17
36.64.30.121
36.67.95.5
36.91.222.100
36.106.166.115
36.156.22.4
36.170.17.119
37.140.242.108
37.186.124.222
37.208.47.14
37.238.172.178
38.222.15.149
39.38.161.196
39.44.90.73
39.103.169.109
39.106.43.191
39.153.252.196
41.10.113.46
41.45.126.17
41.72.61.67
41.82.213.42
41.111.188.86
41.150.253.254
41.208.71.226
42.123.110.8
42.194.144.103
42.200.218.97
42.236.75.22
43.133.129.213
43.133.134.74
43.133.146.174
43.134.66.207
43.134.92.151
43.134.92.159
43.156.108.56
43.224.0.5
43.224.132.107
43.228.129.201
43.229.225.29
43.230.202.34
45.7.33.29
45.32.165.213
45.33.80.243
45.55.0.36
45.55.66.199
45.61.131.49
45.79.86.246
45.79.114.61
45.79.114.208
45.79.128.205
45.79.163.53
45.79.168.172
45.79.169.91
45.79.172.21
45.79.181.94
45.79.181.104
45.79.181.179
45.79.181.223
45.79.181.251
45.83.64.199
45.83.64.221
45.83.65.186
45.83.65.208
45.83.65.228
45.83.66.38
45.83.66.165
45.88.90.52
45.88.90.125
45.88.90.157
45.88.90.181
45.95.169.184
45.119.80.3
45.128.232.41
45.128.232.51
45.128.232.70
45.128.232.152
45.128.232.226
45.128.232.229
45.137.198.64
45.137.201.30
45.140.17.52
45.147.250.208
45.152.122.89
45.156.129.17
45.168.176.34
45.175.173.33
45.177.164.135
45.227.254.8
45.227.254.9
45.227.254.26
45.227.254.49
45.227.254.54
45.227.254.55
45.230.27.69
45.240.88.246
45.249.245.54
45.250.231.106
46.53.242.94
46.99.251.125
46.101.40.31
46.101.207.77
46.105.132.55
47.74.96.31
47.76.82.148
47.92.161.124
47.95.215.141
47.98.232.125
47.113.228.137
47.238.238.128
47.242.155.75
49.51.47.179
49.51.142.139
49.204.215.122
49.205.87.205
49.229.64.98
49.231.13.136
49.232.195.173
49.248.142.62
50.31.21.10
50.193.87.252
51.79.150.109
51.159.101.211
52.23.253.54
52.91.92.132
54.145.115.117
54.193.186.237
57.128.18.242
58.56.96.49
58.58.53.6
58.120.224.131
58.136.160.218
58.218.204.183
58.220.24.41
58.220.41.251
58.229.204.215
59.1.226.250
59.5.193.190
59.18.168.126
59.29.16.225
59.29.143.207
59.41.189.106
59.48.65.54
59.99.188.41
59.120.15.196
59.144.16.84
59.178.194.202
59.183.110.44
60.2.221.41
60.191.125.35
60.251.21.210
60.251.180.97
61.3.11.27
61.8.77.195
61.81.159.228
61.130.98.66
61.166.17.142
61.177.172.136
61.177.172.140
61.177.172.160
61.177.172.179
61.180.230.50
61.186.159.26
61.219.11.155
62.23.142.219
62.48.215.97
62.60.165.149
62.90.255.72
62.181.214.210
62.204.41.225
62.210.15.85
64.0.0.6
64.23.186.35
64.62.156.29
64.62.156.36
64.62.156.65
64.62.156.81
64.62.156.90
64.62.156.95
64.62.197.14
64.62.197.32
64.62.197.46
64.62.197.61
64.62.197.65
64.62.197.70
64.62.197.72
64.62.197.75
64.62.197.83
64.62.197.87
64.62.197.93
64.62.197.94
64.62.197.103
64.62.197.108
64.62.197.116
64.62.197.119
64.62.197.152
64.62.197.167
64.62.197.178
64.188.21.32
64.222.77.122
64.225.112.231
65.49.1.36
65.49.1.67
65.49.1.108
66.94.120.244
66.240.236.109
67.205.169.229
67.211.219.243
69.164.217.245
71.60.31.70
80.66.88.211
80.94.92.60
82.199.100.2
83.97.73.245
83.147.54.78
85.208.214.89
87.121.69.25
87.121.69.52
87.246.7.34
87.251.67.195
87.251.75.145
88.98.111.82
88.227.74.157
91.92.248.17
91.92.251.164
91.144.130.67
91.193.131.78
94.180.115.126
94.181.220.70
94.242.171.47
96.95.224.49
101.36.114.209
103.90.145.199
103.149.26.204
103.237.86.229
103.241.171.74
104.152.52.199
104.236.1.59
107.151.199.137
107.151.199.198
107.170.248.13
107.170.255.29
107.172.206.79
107.174.45.13
108.178.72.66
109.123.251.218
109.206.237.72
111.199.236.184
112.173.174.97
112.220.104.19
115.239.255.13
116.62.150.129
116.193.221.34
117.212.4.235
121.139.159.35
121.197.3.193
122.54.143.156
122.187.152.36
124.123.64.52
125.212.198.118
128.199.4.111
128.199.11.157
128.199.204.10
140.82.2.238
142.93.242.101
143.198.60.201
143.198.215.154
146.19.24.28
146.190.174.211
146.190.225.177
148.244.221.22
151.106.40.212
152.32.156.158
152.32.159.79
152.32.180.138
152.32.235.78
154.53.51.229
154.125.251.138
157.230.175.238
161.35.84.187
165.154.36.177
165.154.164.57
167.71.164.88
167.94.138.35
167.94.145.53
167.94.146.51
167.94.146.52
167.114.138.249
170.64.167.72
170.64.229.112
172.104.210.105
172.105.128.11
173.195.100.103
176.211.18.74
179.32.58.255
179.43.180.106
180.101.88.196
180.101.88.201
180.101.88.205
182.191.114.20
183.81.169.238
183.104.160.181
183.249.69.63
184.105.139.69
184.105.139.101
185.11.61.122
185.36.81.40
185.56.83.110
185.74.5.181
185.74.6.54
185.74.6.207
185.74.6.250
185.161.248.87
185.170.59.109
185.196.8.151
186.4.233.202
188.126.89.149
188.166.47.41
190.145.231.14
190.202.128.50
192.99.31.245
192.155.88.231
192.241.213.42
193.124.93.90
194.165.16.10
194.165.16.11
194.165.16.78
194.169.175.38
195.28.180.30
195.58.52.126
198.235.24.34
198.235.24.106
205.210.31.47
205.210.31.100
205.210.31.133
205.210.31.217
205.210.31.227
206.168.34.127
211.218.194.133
211.228.142.48
213.202.230.4
217.73.236.14
218.92.0.27
218.92.0.29
218.92.0.34
218.92.0.107
218.92.0.113
218.92.0.118
219.138.108.82

File diff suppressed because it is too large Load Diff

File diff suppressed because it is too large Load Diff

File diff suppressed because it is too large Load Diff

5577
bitcoin_nodes.ipset Normal file

File diff suppressed because it is too large Load Diff

6540
bitcoin_nodes_1d.ipset Normal file

File diff suppressed because it is too large Load Diff

12574
bitcoin_nodes_30d.ipset Normal file

File diff suppressed because it is too large Load Diff

8224
bitcoin_nodes_7d.ipset Normal file

File diff suppressed because it is too large Load Diff

25599
blocklist_de.ipset Normal file

File diff suppressed because it is too large Load Diff

8417
blocklist_de_apache.ipset Normal file

File diff suppressed because it is too large Load Diff

233
blocklist_de_bots.ipset Normal file
View File

@ -0,0 +1,233 @@
#
# blocklist_de_bots
#
# ipv4 hash:ip ipset
#
# [Blocklist.de] (https://www.blocklist.de/) All IP addresses
# which have been reported within the last 48 hours as having
# run attacks on the RFI-Attacks, REG-Bots, IRC-Bots or
# BadBots (BadBots = it has posted a Spam-Comment on a open
# Forum or Wiki).
#
# Maintainer : Blocklist.de
# Maintainer URL : https://www.blocklist.de/
# List source URL : http://lists.blocklist.de/lists/bots.txt
# Source File Date: Wed Apr 17 10:12:04 UTC 2024
#
# Category : attacks
# Version : 79471
#
# This File Date : Wed Apr 17 10:12:09 UTC 2024
# Update Frequency: 15 mins
# Aggregation : none
# Entries : 200 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=blocklist_de_bots
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.12.48.131
5.56.132.84
5.182.46.10
13.79.17.158
14.225.8.141
20.11.67.155
20.171.104.41
23.26.220.8
23.26.220.11
23.26.220.14
23.26.220.20
23.97.205.210
34.93.16.66
34.143.140.159
34.175.145.201
35.245.96.16
39.101.185.186
39.163.153.219
39.165.155.51
39.165.179.184
42.202.17.25
42.202.17.104
43.159.130.145
45.80.158.252
45.117.162.84
45.141.215.194
45.156.185.219
45.227.161.95
49.0.201.208
49.232.153.49
51.83.42.50
51.83.238.93
51.174.65.41
52.169.109.146
62.65.188.98
62.109.13.31
65.20.76.117
65.108.110.26
66.249.68.38
69.63.64.21
69.162.102.218
78.111.2.100
78.128.76.202
78.135.107.100
79.124.76.167
80.66.78.54
81.68.123.147
81.177.136.216
81.181.55.54
82.165.215.24
84.17.45.120
84.247.105.106
84.247.135.136
88.238.49.45
91.92.247.123
91.92.254.184
94.74.88.198
95.217.109.26
101.44.248.114
101.44.250.157
101.44.251.65
101.44.251.187
103.130.215.173
103.154.184.42
104.28.156.113
104.28.222.47
104.28.254.46
104.28.254.47
104.200.151.115
104.200.151.171
107.189.28.123
110.4.41.246
110.154.96.56
110.154.98.86
110.154.100.192
110.154.132.100
116.179.32.16
116.179.32.38
116.179.32.46
116.179.32.87
116.179.32.99
116.179.32.144
116.179.32.195
116.179.32.197
116.179.32.198
116.179.32.223
116.179.37.2
116.179.37.10
116.179.37.12
116.179.37.18
116.179.37.32
116.179.37.45
116.179.37.55
116.179.37.60
116.179.37.69
116.179.37.85
116.179.37.89
116.179.37.92
116.179.37.94
116.179.37.95
116.179.37.104
116.179.37.110
116.179.37.118
116.179.37.130
116.179.37.144
116.179.37.156
116.179.37.169
116.179.37.186
116.179.37.194
116.179.37.195
116.179.37.204
116.179.37.225
123.186.73.12
123.186.73.65
123.186.73.230
123.186.73.238
123.186.73.241
123.186.75.5
123.186.76.170
123.244.129.96
123.245.128.52
123.245.129.207
124.123.76.210
124.217.226.207
124.243.133.119
124.243.146.76
135.181.180.59
137.184.184.208
139.59.65.43
139.59.115.223
141.98.11.144
142.93.216.20
143.198.82.217
143.198.85.181
143.198.211.195
150.158.28.21
150.230.58.58
152.42.181.253
152.42.234.28
152.42.248.228
154.53.61.215
154.85.188.14
157.230.42.45
157.245.197.53
157.245.198.20
157.245.201.51
159.138.146.88
159.203.102.75
159.223.47.156
159.223.102.228
161.97.148.58
162.241.201.42
164.92.86.237
164.92.118.22
165.84.162.121
165.232.180.139
167.99.70.22
167.172.82.179
171.22.24.205
172.105.124.122
173.249.0.2
174.138.29.141
175.22.93.214
178.62.66.131
178.128.220.148
178.128.221.28
178.162.147.150
178.236.246.60
178.255.225.238
182.204.140.146
182.204.141.121
182.204.142.24
182.204.143.228
185.129.168.248
185.165.118.34
185.196.8.246
185.196.11.156
185.200.240.65
185.229.119.130
187.102.16.15
188.166.234.34
190.92.202.240
190.92.206.5
193.3.167.204
193.142.146.226
194.9.56.102
194.26.192.80
194.38.23.16
194.76.26.63
194.242.57.123
195.191.219.130
195.191.219.132
198.98.50.195
206.189.47.181
213.175.200.188
216.24.216.205
221.236.22.20
222.73.22.8
223.88.223.208
223.88.223.212

View File

@ -0,0 +1,370 @@
#
# blocklist_de_bruteforce
#
# ipv4 hash:ip ipset
#
# [Blocklist.de] (https://www.blocklist.de/) All IPs which
# attacks Joomla, Wordpress and other Web-Logins with
# Brute-Force Logins.
#
# Maintainer : Blocklist.de
# Maintainer URL : https://www.blocklist.de/
# List source URL : http://lists.blocklist.de/lists/bruteforcelogin.txt
# Source File Date: Wed Apr 17 10:12:04 UTC 2024
#
# Category : attacks
# Version : 140036
#
# This File Date : Wed Apr 17 10:12:09 UTC 2024
# Update Frequency: 15 mins
# Aggregation : none
# Entries : 339 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=blocklist_de_bruteforce
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.0.194.159
1.10.214.103
1.20.91.101
1.20.94.235
2.136.20.37
4.255.78.239
5.45.84.243
5.182.87.135
5.183.255.68
8.137.48.64
8.210.123.17
8.218.212.177
8.218.249.33
13.229.63.138
14.99.167.142
14.181.237.200
14.191.52.69
14.191.84.167
14.191.112.234
14.191.162.69
14.191.166.244
14.254.253.141
20.11.71.105
20.46.147.123
24.43.225.242
27.68.12.198
27.69.226.32
27.145.159.225
31.31.196.215
31.135.241.21
31.186.172.143
36.66.135.123
36.68.9.115
36.69.15.9
36.72.30.118
36.73.35.43
36.74.41.53
36.75.65.69
36.84.103.142
36.85.108.215
36.85.238.176
36.90.3.147
37.27.2.206
37.60.238.205
37.60.241.129
37.120.155.34
37.156.144.83
37.187.109.73
40.71.189.48
41.60.234.104
41.234.73.97
43.138.16.177
43.156.227.239
43.248.152.212
45.55.41.247
45.61.187.37
45.83.123.189
45.135.241.228
45.249.84.192
46.101.158.184
46.105.39.241
47.61.200.144
47.106.201.134
47.112.228.158
47.113.224.111
47.236.97.252
47.236.122.103
47.244.50.243
47.251.36.68
49.36.220.108
49.37.194.127
50.116.12.121
51.68.228.235
51.195.88.79
51.195.192.54
58.65.160.203
60.205.185.165
61.246.38.5
62.72.164.72
64.23.200.58
64.23.224.130
64.227.143.159
64.227.174.62
64.227.181.3
64.227.185.184
68.171.221.130
68.178.146.98
71.112.193.26
75.221.119.98
76.8.60.182
77.83.36.43
77.90.12.228
77.91.68.233
79.137.36.176
79.137.202.181
80.115.244.79
80.244.11.191
81.181.60.61
81.200.114.24
89.32.45.46
89.161.153.22
91.92.243.96
91.92.244.199
91.103.219.225
91.203.111.18
91.219.195.22
91.228.155.130
92.51.2.233
92.205.170.153
92.205.171.137
93.56.199.127
94.128.164.207
95.0.0.209
97.74.209.243
101.34.223.139
101.128.71.192
101.255.108.10
102.129.40.35
103.50.169.68
103.56.40.128
103.67.163.199
103.104.48.48
103.108.45.105
103.111.140.43
103.113.196.24
103.120.178.216
103.131.215.75
103.133.70.161
103.138.151.6
103.142.26.32
103.151.15.197
103.153.3.242
103.156.217.255
103.175.248.219
103.179.255.4
103.187.22.6
103.210.29.164
103.246.3.203
107.170.253.8
107.173.250.244
107.175.44.192
107.180.119.161
107.189.7.25
109.120.176.173
109.120.176.185
113.160.202.252
113.161.6.87
114.55.95.129
115.50.239.26
115.79.53.245
115.79.60.61
115.178.75.78
115.246.123.66
116.98.249.174
117.4.68.227
117.4.139.59
117.207.226.67
117.240.188.21
118.70.180.54
118.136.228.80
118.139.177.14
118.195.132.31
119.45.26.99
120.25.104.120
120.29.69.37
120.56.218.77
120.77.84.25
120.78.175.141
122.152.237.34
123.16.54.37
123.25.116.111
123.27.160.49
124.71.61.46
125.88.231.98
125.160.100.227
125.166.2.105
125.166.84.79
125.166.125.48
125.167.33.207
128.199.0.160
131.153.22.13
134.119.183.211
134.209.105.190
134.236.195.98
136.158.1.136
136.232.204.190
136.233.240.226
137.184.88.156
137.184.164.115
137.184.255.6
141.94.190.21
141.148.173.244
143.42.205.251
143.44.162.184
143.110.150.98
143.198.40.142
143.198.215.194
144.202.62.153
147.45.47.119
147.182.195.108
148.113.8.160
148.113.175.246
149.129.132.87
149.255.62.116
152.42.169.12
153.223.50.36
154.16.164.46
154.47.19.199
156.54.202.242
156.205.216.128
157.241.94.46
157.245.46.217
157.245.62.36
158.220.107.208
159.65.144.64
159.192.78.211
159.192.98.134
160.153.153.167
161.35.236.228
162.255.118.206
163.5.112.246
163.53.25.152
164.155.129.94
165.22.70.82
165.154.231.93
165.232.32.235
167.71.210.163
170.64.232.108
170.78.20.186
170.106.143.158
170.130.40.107
171.7.216.91
171.253.54.35
172.205.232.105
173.201.181.20
173.239.247.20
177.116.24.167
178.18.252.180
178.33.33.171
178.128.89.117
178.128.127.179
178.128.161.88
178.128.162.110
179.43.172.185
180.110.242.159
180.149.125.173
180.180.54.150
180.190.38.80
180.241.22.247
180.242.214.73
180.242.215.33
180.243.3.208
180.243.4.159
180.243.11.115
180.244.167.246
180.247.44.15
180.247.189.8
180.248.8.44
180.252.52.116
180.252.89.151
180.252.205.200
180.253.73.8
181.63.25.67
181.117.163.22
182.16.161.206
182.16.181.70
182.43.18.230
182.43.79.24
182.53.41.255
182.75.112.226
182.183.56.40
184.168.110.37
184.168.119.178
185.50.25.12
185.98.5.152
185.100.203.115
185.107.90.29
185.107.113.34
185.160.182.220
185.241.208.54
186.14.184.4
188.166.212.75
189.206.227.150
190.104.128.118
190.104.146.8
190.104.168.115
192.36.109.98
192.36.109.120
192.36.109.125
192.36.109.127
192.169.176.85
192.241.130.228
192.241.205.18
193.19.253.42
193.106.31.146
193.106.31.154
193.201.82.102
193.202.110.24
193.202.110.27
194.32.122.6
194.37.80.250
194.233.64.75
195.24.202.36
195.231.52.213
197.36.84.127
197.52.226.232
197.232.52.153
198.12.217.103
198.12.245.7
198.20.127.169
198.71.230.71
200.88.48.99
201.123.34.212
201.244.208.209
202.95.9.249
203.23.199.221
203.84.152.42
203.128.78.62
203.188.241.202
205.185.123.192
206.84.154.18
206.189.41.91
206.189.59.247
207.241.234.199
207.244.250.20
209.38.140.198
209.126.102.185
209.141.56.215
210.1.250.11
210.212.210.83
211.23.242.89
212.58.120.175
212.90.148.126
212.241.28.122
216.219.94.195
217.26.172.179
222.138.119.101
223.204.22.195
223.205.183.243

88
blocklist_de_ftp.ipset Normal file
View File

@ -0,0 +1,88 @@
#
# blocklist_de_ftp
#
# ipv4 hash:ip ipset
#
# [Blocklist.de] (https://www.blocklist.de/) All IP addresses
# which have been reported within the last 48 hours for
# attacks on the Service FTP.
#
# Maintainer : Blocklist.de
# Maintainer URL : https://www.blocklist.de/
# List source URL : http://lists.blocklist.de/lists/ftp.txt
# Source File Date: Wed Apr 17 10:12:03 UTC 2024
#
# Category : attacks
# Version : 96877
#
# This File Date : Wed Apr 17 10:12:08 UTC 2024
# Update Frequency: 15 mins
# Aggregation : none
# Entries : 57 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=blocklist_de_ftp
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
3.88.176.225
14.29.222.219
14.37.12.17
14.215.136.61
35.216.169.98
35.216.245.84
36.108.168.4
36.154.110.46
39.103.169.109
39.106.130.86
42.84.156.40
45.33.110.4
47.76.153.201
47.96.106.146
47.111.124.233
47.236.120.40
47.236.148.170
47.236.160.1
58.255.77.17
59.60.112.145
61.184.119.32
64.225.23.104
74.127.203.89
84.46.99.56
84.54.72.160
101.42.16.225
103.168.180.109
106.116.88.202
112.196.9.20
118.194.238.196
121.159.81.181
122.234.236.5
123.234.131.230
125.212.239.144
132.147.159.135
134.209.63.173
139.199.212.85
140.143.139.242
146.70.111.84
152.32.156.117
152.32.159.180
152.32.206.35
152.32.227.23
152.32.245.44
152.32.245.196
154.12.91.88
165.154.6.224
165.154.128.199
165.154.134.152
182.50.249.59
182.223.190.12
183.155.155.47
187.149.86.178
191.31.164.9
203.195.210.171
221.132.29.253
223.26.61.209

3035
blocklist_de_imap.ipset Normal file

File diff suppressed because it is too large Load Diff

11583
blocklist_de_mail.ipset Normal file

File diff suppressed because it is too large Load Diff

90
blocklist_de_sip.ipset Normal file
View File

@ -0,0 +1,90 @@
#
# blocklist_de_sip
#
# ipv4 hash:ip ipset
#
# [Blocklist.de] (https://www.blocklist.de/) All IP addresses
# that tried to login in a SIP, VOIP or Asterisk Server and
# are included in the IPs list from infiltrated.net
#
# Maintainer : Blocklist.de
# Maintainer URL : https://www.blocklist.de/
# List source URL : http://lists.blocklist.de/lists/sip.txt
# Source File Date: Wed Apr 17 10:12:03 UTC 2024
#
# Category : attacks
# Version : 132084
#
# This File Date : Wed Apr 17 10:12:08 UTC 2024
# Update Frequency: 15 mins
# Aggregation : none
# Entries : 59 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=blocklist_de_sip
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
15.204.166.175
31.7.70.8
35.131.2.104
37.77.107.23
43.128.109.248
43.129.185.108
43.134.228.194
43.153.82.175
43.153.90.246
43.155.159.72
43.163.224.204
45.43.37.96
45.88.90.157
45.95.147.181
45.238.232.3
49.51.187.234
51.81.156.107
51.83.72.156
54.202.120.250
61.231.230.159
62.193.106.227
62.210.122.52
72.167.42.160
83.235.21.125
89.190.156.219
92.205.108.83
101.33.80.181
103.160.37.139
103.162.20.168
103.189.237.63
104.28.157.26
104.28.206.182
114.132.249.177
117.251.96.153
119.29.215.187
119.40.89.123
119.45.199.11
123.119.237.39
124.156.211.3
125.79.74.46
132.226.126.228
146.190.53.250
149.202.90.68
154.16.56.106
156.236.72.238
170.106.168.186
185.31.200.197
185.176.220.50
191.101.3.232
193.160.119.122
195.178.203.157
198.12.118.215
201.251.51.216
202.29.222.90
202.131.233.35
207.154.233.236
212.71.233.162
212.224.88.181
213.166.70.126

13308
blocklist_de_ssh.ipset Normal file

File diff suppressed because it is too large Load Diff

View File

@ -0,0 +1,422 @@
#
# blocklist_de_strongips
#
# ipv4 hash:ip ipset
#
# [Blocklist.de] (https://www.blocklist.de/) All IPs which
# are older then 2 month and have more then 5.000 attacks.
#
# Maintainer : Blocklist.de
# Maintainer URL : https://www.blocklist.de/
# List source URL : http://lists.blocklist.de/lists/strongips.txt
# Source File Date: Wed Apr 17 07:54:03 UTC 2024
#
# Category : attacks
# Version : 53916
#
# This File Date : Wed Apr 17 07:56:08 UTC 2024
# Update Frequency: 15 mins
# Aggregation : none
# Entries : 392 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=blocklist_de_strongips
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.9.78.242
13.70.39.68
13.74.46.65
13.80.7.122
14.63.162.98
14.102.74.99
14.177.239.168
20.194.60.135
27.254.137.144
27.254.149.199
31.184.198.71
34.69.39.31
34.81.69.1
34.91.0.68
34.92.176.182
35.207.98.222
35.219.62.194
35.244.25.124
36.66.151.17
36.67.197.52
36.91.38.31
36.91.166.34
36.110.228.254
40.115.18.231
41.72.105.171
41.72.219.102
41.82.208.182
41.191.116.18
42.200.66.164
42.200.78.78
42.200.149.223
45.129.14.128
45.129.14.173
45.161.176.1
45.232.244.5
46.101.5.100
46.101.171.235
47.180.114.229
49.51.183.1
49.247.198.162
50.192.223.205
50.214.100.27
50.225.176.238
51.91.111.73
51.178.137.178
52.160.46.145
52.172.30.44
52.183.128.237
52.227.167.147
58.27.95.2
59.3.76.218
61.80.179.118
61.83.148.111
61.93.186.125
61.177.172.136
61.177.172.140
61.177.172.160
61.177.172.179
62.28.222.221
64.227.122.198
64.227.126.250
65.73.231.122
65.181.73.155
65.190.102.226
68.116.41.2
68.183.88.186
72.167.55.58
72.240.125.133
74.94.234.151
79.104.0.82
81.28.167.30
81.192.87.130
82.200.65.218
84.2.226.70
85.172.189.189
85.209.11.27
85.209.11.227
85.209.11.254
87.120.84.106
88.214.25.16
89.97.218.142
90.168.201.25
91.92.245.73
92.118.39.240
93.190.106.139
94.180.247.20
96.67.59.65
96.69.13.140
96.78.175.36
101.207.113.73
103.16.202.187
103.26.136.173
103.48.192.48
103.48.193.7
103.63.108.25
103.86.180.10
103.92.24.242
103.231.46.66
103.240.110.130
103.248.60.70
103.255.216.43
104.248.159.207
105.96.11.65
106.51.3.214
106.241.54.211
106.246.224.154
107.0.200.227
107.175.33.240
107.180.88.176
109.195.148.73
111.21.99.227
111.33.78.99
111.68.98.152
111.93.200.50
111.161.41.156
112.31.56.247
112.133.228.250
112.196.74.82
113.31.116.250
113.200.60.74
114.199.123.211
114.204.218.154
114.206.23.151
116.92.213.114
117.220.15.119
118.27.9.23
118.40.248.20
118.45.205.44
118.70.170.120
118.70.180.188
118.101.192.62
118.201.79.222
119.5.157.124
119.28.105.34
119.28.118.4
119.29.136.114
119.73.179.114
119.92.70.82
119.252.143.6
120.28.109.188
120.69.153.69
120.88.46.226
120.224.50.233
121.142.87.218
122.155.0.205
122.176.52.13
123.30.249.49
123.31.29.192
123.140.114.196
124.152.118.194
124.160.96.242
125.46.85.154
125.99.173.162
125.163.160.229
128.199.33.46
128.199.73.168
128.199.80.214
128.199.95.60
128.199.120.146
128.199.150.10
128.199.182.19
128.199.194.1
128.199.225.7
128.201.78.253
129.226.158.246
134.17.16.40
134.17.17.32
134.17.94.229
134.122.8.241
134.122.17.178
136.228.161.66
136.228.161.67
137.184.5.137
138.68.9.83
138.68.91.192
139.59.23.154
139.59.25.164
139.59.127.73
139.59.127.178
139.59.188.13
140.86.12.31
140.86.39.162
141.94.106.15
143.244.144.227
143.244.162.174
146.190.227.169
148.66.132.190
152.228.164.249
154.68.39.6
154.72.194.207
157.230.113.181
157.230.185.9
157.245.157.93
157.245.218.29
159.65.41.104
159.65.91.105
159.65.220.18
159.203.170.197
161.35.108.241
164.77.117.10
164.177.31.66
165.22.16.134
165.22.101.75
165.22.217.96
165.22.242.64
165.227.68.95
165.227.84.172
165.227.85.21
165.227.87.78
165.227.101.226
165.227.166.247
165.227.228.212
165.232.158.187
167.172.112.115
171.244.140.174
175.203.61.33
175.207.13.22
177.91.80.11
178.217.173.54
179.43.180.106
180.71.47.198
180.101.88.196
180.101.88.197
180.101.88.200
180.101.88.205
180.101.88.218
180.101.88.219
180.101.88.221
180.101.88.222
180.101.88.223
180.101.88.224
180.101.88.225
180.101.88.236
180.101.88.237
180.101.88.240
180.101.88.241
180.101.88.244
180.101.88.245
180.101.88.246
180.101.88.248
180.101.88.249
180.101.88.254
180.101.184.85
180.149.242.18
180.167.207.234
180.168.95.234
181.28.101.14
181.30.99.114
181.48.60.50
181.48.99.155
182.16.245.79
182.16.245.85
182.23.23.42
182.75.216.74
182.93.7.194
182.93.50.90
183.81.169.238
183.240.157.2
184.18.211.199
185.17.229.65
185.46.18.99
185.74.4.17
185.74.4.20
185.74.4.189
185.161.248.217
185.217.1.246
186.4.222.45
186.10.86.130
186.10.125.209
186.10.245.152
186.38.26.5
186.67.248.5
186.67.248.6
186.67.248.8
186.96.145.241
186.147.129.110
187.102.174.154
187.109.253.246
187.188.206.106
188.166.211.7
189.6.45.130
189.240.225.205
190.12.102.58
190.85.15.251
190.104.25.210
190.128.169.130
190.128.230.98
190.128.241.2
190.129.60.125
190.144.14.170
190.145.192.106
190.153.249.99
190.181.25.210
190.202.124.93
190.210.182.179
191.242.105.133
192.241.157.126
194.152.206.17
194.169.175.10
194.169.175.17
195.19.4.22
195.88.120.62
195.239.91.210
197.5.145.68
197.5.145.102
197.227.8.186
198.12.85.199
200.88.48.99
200.105.183.118
200.122.249.203
201.48.78.29
201.116.3.194
201.149.49.146
201.163.162.179
201.226.239.98
201.234.66.133
201.249.89.102
202.21.123.196
202.51.74.123
202.55.175.236
202.90.158.191
202.158.139.57
203.66.168.81
203.98.76.172
203.106.164.74
203.113.167.3
203.130.255.2
203.172.76.4
203.205.37.233
205.185.113.140
206.189.145.158
206.217.131.233
207.154.228.201
208.109.34.15
209.97.186.17
210.3.92.14
210.65.88.51
210.183.21.48
210.187.80.132
211.21.113.128
211.75.19.210
211.193.31.52
211.253.10.96
212.70.149.150
212.83.144.11
213.55.83.90
213.109.202.127
218.56.160.82
218.92.0.22
218.92.0.24
218.92.0.27
218.92.0.28
218.92.0.29
218.92.0.31
218.92.0.32
218.92.0.33
218.92.0.34
218.92.0.39
218.92.0.40
218.92.0.43
218.92.0.45
218.92.0.47
218.92.0.48
218.92.0.51
218.92.0.52
218.92.0.55
218.92.0.56
218.92.0.59
218.92.0.76
218.92.0.96
218.92.0.102
218.92.0.107
218.92.0.112
218.92.0.113
218.92.0.118
218.92.0.123
218.92.0.124
218.150.246.42
218.255.245.10
220.80.223.144
220.86.29.35
220.134.113.188
221.156.126.1
221.157.75.252
221.213.129.46
222.107.156.227
222.124.214.10
222.168.30.19
223.197.151.55
223.197.175.91
223.197.186.7
223.197.188.206

91713
blocklist_net_ua.ipset Normal file

File diff suppressed because it is too large Load Diff

82
botscout.ipset Normal file
View File

@ -0,0 +1,82 @@
#
# botscout
#
# ipv4 hash:ip ipset
#
# [BotScout] (http://botscout.com/) helps prevent automated
# web scripts, known as bots, from registering on forums,
# polluting databases, spreading spam, and abusing forms on
# web sites. They do this by tracking the names, IPs, and
# email addresses that bots use and logging them as unique
# signatures for future reference. They also provide a simple
# yet powerful API that you can use to test forms when
# they're submitted on your site. This list is composed of
# the most recently-caught bots.
#
# Maintainer : BotScout.com
# Maintainer URL : http://botscout.com/
# List source URL : http://botscout.com/last_caught_cache.htm
# Source File Date: Wed Apr 17 09:52:25 UTC 2024
#
# Category : abuse
# Version : 87312
#
# This File Date : Wed Apr 17 09:52:25 UTC 2024
# Update Frequency: 30 mins
# Aggregation : none
# Entries : 45 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=botscout
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
5.62.43.182
14.248.83.233
23.82.40.113
23.83.92.128
23.105.4.25
23.108.45.113
23.129.252.199
23.129.253.13
37.60.237.251
37.139.53.84
38.170.245.35
39.165.0.137
45.192.146.15
64.137.93.236
64.137.99.191
77.232.41.202
91.237.124.149
103.54.154.102
103.54.154.203
103.210.54.22
104.28.222.237
104.239.33.72
107.181.142.149
109.248.204.7
114.245.111.150
120.40.130.70
137.59.4.157
142.54.232.6
154.13.96.76
154.29.142.60
154.37.174.173
154.55.88.237
154.92.126.131
178.120.2.158
178.159.37.4
185.72.241.207
188.130.143.175
191.102.130.18
192.154.207.84
192.154.207.184
194.124.158.80
194.233.91.18
212.115.61.31
216.173.118.7
217.138.216.153

768
botscout_1d.ipset Normal file
View File

@ -0,0 +1,768 @@
#
# botscout_1d
#
# ipv4 hash:ip ipset
#
# [BotScout] (http://botscout.com/) helps prevent automated
# web scripts, known as bots, from registering on forums,
# polluting databases, spreading spam, and abusing forms on
# web sites. They do this by tracking the names, IPs, and
# email addresses that bots use and logging them as unique
# signatures for future reference. They also provide a simple
# yet powerful API that you can use to test forms when
# they're submitted on your site. This list is composed of
# the most recently-caught bots.
#
# Maintainer : BotScout.com
# Maintainer URL : http://botscout.com/
# List source URL : http://botscout.com/last_caught_cache.htm
# Source File Date: Wed Apr 17 09:52:25 UTC 2024
#
# Category : abuse
# Version : 87312
#
# This File Date : Wed Apr 17 09:52:26 UTC 2024
# Update Frequency: 30 mins
# Aggregation : 1 day
# Entries : 748 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=botscout_1d
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.54.214.37
1.169.72.195
2.57.122.58
5.9.61.84
5.45.98.162
5.62.43.182
5.62.56.253
5.62.57.1
5.62.58.233
5.62.59.120
5.102.119.11
5.157.5.112
5.157.33.48
5.157.33.173
5.157.55.119
5.157.55.167
5.188.210.38
5.188.210.91
5.196.78.175
5.228.80.48
5.253.161.79
14.248.83.233
20.37.207.8
23.82.40.113
23.82.106.248
23.82.110.245
23.83.81.94
23.83.81.237
23.83.88.61
23.83.88.203
23.83.90.243
23.83.92.104
23.83.92.128
23.94.6.11
23.94.6.85
23.94.251.4
23.95.99.86
23.95.187.215
23.105.4.25
23.105.4.32
23.106.16.214
23.106.216.119
23.106.216.231
23.108.45.113
23.108.50.178
23.129.252.18
23.129.252.184
23.129.252.199
23.129.253.13
23.129.253.20
23.129.254.78
23.129.254.242
23.154.177.18
23.229.26.236
23.229.35.61
23.229.57.236
23.229.67.244
23.229.70.177
23.229.73.82
23.229.73.94
23.229.75.27
23.236.142.108
23.236.149.111
23.236.166.193
23.236.170.170
23.236.214.91
23.236.214.111
23.236.228.95
23.236.229.170
23.236.233.123
27.78.220.214
27.122.12.115
31.6.26.194
31.44.59.224
31.173.85.231
37.46.113.207
37.60.237.251
37.139.53.84
38.17.46.3
38.17.46.4
38.17.46.8/31
38.17.46.13
38.17.46.15
38.17.46.19
38.17.46.96
38.17.46.209
38.85.189.154
38.152.2.161
38.152.7.186
38.152.8.140
38.152.10.65
38.152.11.56
38.152.14.99
38.152.15.248
38.152.32.190
38.152.33.149
38.152.36.142
38.152.36.149
38.152.37.56
38.152.38.56
38.152.38.93
38.152.139.58
38.152.177.217
38.152.193.46
38.152.193.178
38.153.163.221
38.154.107.224
38.154.130.196
38.154.164.83
38.154.172.195
38.154.173.124
38.154.206.54
38.162.7.171
38.170.121.171
38.170.169.162
38.170.245.35
39.165.0.137
43.229.9.53
43.229.9.101
45.8.22.207
45.15.72.228
45.15.159.167
45.41.162.4
45.66.35.35
45.67.0.240
45.67.229.87
45.84.177.106
45.87.60.42
45.90.196.57
45.95.116.55
45.131.102.249
45.133.193.89
45.134.225.36
45.137.112.62
45.138.87.238
45.138.117.51
45.147.192.147
45.149.153.131
45.192.146.15
45.199.142.34
45.199.142.47
46.8.10.200
46.8.110.171
46.8.111.240
46.8.193.123
46.8.222.130
46.146.230.89
46.148.206.226
46.158.189.36
46.246.8.16
46.246.106.41
47.218.235.227
49.228.104.161
50.3.196.232
50.3.222.114
50.62.183.223
50.111.139.176
51.79.165.8
61.133.66.69
62.128.217.86
64.113.0.160
64.137.57.142
64.137.74.119
64.137.93.236
64.137.95.152
64.137.99.191
64.137.106.84
65.109.24.145
67.78.29.115
67.218.4.129
69.58.1.173
69.58.6.55
69.58.7.186
69.58.12.221
69.61.200.104
69.123.238.104
69.172.232.4/31
69.172.232.6
69.172.232.207
75.187.81.133
77.232.41.202
78.138.127.62
78.142.18.219
80.75.64.69
82.102.30.18
82.114.197.219
83.11.91.13
84.32.64.9
84.32.64.110
84.33.26.218
84.46.204.42
87.117.225.161
87.223.50.254
88.218.148.194
88.218.149.209
89.22.232.206
89.22.233.74
89.22.234.115
89.22.235.74
89.22.235.136
89.22.235.226
89.22.237.210
89.32.41.38
89.113.152.241
89.113.154.74
89.149.87.81
89.187.163.218
91.132.115.26
91.132.251.55
91.148.127.162
91.223.102.68
91.232.143.90
91.237.124.149
91.243.88.98
92.119.36.70
92.119.36.72
92.119.36.79
92.119.36.94
92.204.188.244
94.25.225.2
94.158.20.25
94.158.20.198
95.142.116.1
95.142.121.17
95.142.121.44
95.165.157.34
95.168.173.143
95.182.125.108
96.9.211.222
98.102.62.73
98.170.57.231
98.178.72.21
102.212.88.210
103.53.82.52
103.53.83.249
103.54.154.102
103.54.154.203
103.56.183.203
103.67.186.101
103.67.186.183
103.72.96.175
103.87.142.30
103.107.197.110
103.134.154.203
103.155.118.190
103.157.59.75
103.171.109.79
103.210.54.22
103.221.234.171
103.221.235.112
103.225.202.106
103.225.202.124
103.250.10.146
103.250.11.34
104.28.156.212
104.28.156.220
104.28.157.196
104.28.157.198
104.28.158.134
104.28.160.182
104.28.160.186
104.28.198.33
104.28.222.74
104.28.222.237
104.28.254.237
104.143.229.48
104.143.244.136
104.143.252.253
104.164.183.154
104.165.127.54
104.165.127.71
104.168.112.74
104.168.170.168
104.206.81.239
104.222.187.191
104.223.157.70
104.223.223.62
104.238.37.23
104.239.33.72
104.239.77.91
104.249.27.3
104.249.27.4
104.249.27.7
104.249.27.9
104.249.27.96
104.249.55.101
107.172.18.36
107.173.30.243
107.175.144.73
107.181.142.149
108.162.221.3
108.162.221.4
109.62.204.194
109.70.100.1
109.70.100.67
109.169.34.43
109.248.14.50
109.248.49.171
109.248.142.60
109.248.204.7
109.248.204.223
111.59.4.88
113.160.173.164
114.4.220.121
114.245.111.150
116.98.248.24
118.101.107.147
118.179.168.83
120.40.130.70
121.173.146.103
122.146.89.126
124.168.232.150
130.44.201.199
130.44.203.208
134.19.38.94
134.73.70.155
136.0.109.170
137.59.4.157
137.59.5.250
138.199.59.198
139.28.136.37
139.99.68.203
141.11.20.154
141.101.104.116
142.54.232.6
142.54.237.34
144.126.150.4
146.70.111.145
146.70.111.146
146.70.165.61
146.196.32.213
147.78.141.80/31
147.78.141.84
149.40.50.5
149.71.176.50
149.71.176.63
149.71.180.201
149.71.181.164
149.71.181.232
152.89.8.250
152.89.11.122
154.6.13.35
154.6.13.44
154.9.41.116
154.12.162.29
154.12.204.1
154.13.96.73
154.13.96.76
154.13.97.103
154.13.98.167
154.13.98.174
154.13.99.136
154.13.99.149
154.13.101.151
154.13.102.121
154.13.102.125
154.13.102.199
154.13.103.18
154.13.103.182
154.13.104.254
154.13.106.116
154.13.109.96
154.13.110.232
154.13.125.186
154.13.126.195
154.13.126.245
154.13.205.179
154.13.249.229
154.13.254.98
154.16.20.107
154.17.251.133
154.21.11.155
154.21.119.253
154.21.127.60
154.21.223.197
154.22.60.227
154.29.142.60
154.29.232.220
154.29.235.130
154.30.194.117
154.30.242.232
154.37.78.185
154.37.78.234
154.37.174.173
154.47.19.132
154.53.53.200
154.55.88.237
154.55.93.160
154.57.3.36
154.85.126.227
154.92.126.131
154.95.32.151
154.95.38.105
154.194.11.249
154.201.40.13
154.201.42.193
154.202.106.168
154.202.124.151
156.238.9.110
159.242.227.96
160.20.10.236
161.123.5.173
161.123.115.218
162.158.182.172
162.158.222.22
162.212.173.252
163.5.91.98
165.225.57.52
165.231.92.12
165.231.97.50
165.231.97.154
165.231.159.67
167.160.180.203
168.80.132.126
168.81.46.100
168.81.46.151
168.81.46.236
168.90.196.160
168.90.199.160
171.25.193.80
171.225.193.92
172.56.74.205
172.64.236.138
172.68.10.156
172.68.139.130
172.68.183.82
172.68.194.142
172.68.238.47
172.68.238.133
172.68.238.145
172.68.238.151
172.69.6.128
172.69.22.22
172.69.22.168
172.69.23.131
172.69.23.166/31
172.69.34.125
172.69.134.142
172.69.134.224
172.69.151.83
172.69.194.36
172.69.234.157
172.69.234.166
172.69.234.169
172.70.42.173
172.70.46.36
172.70.47.15
172.70.47.34
172.70.85.217
172.70.114.230
172.70.115.188
172.70.207.93
172.70.210.59
172.70.210.232
172.70.243.17
172.70.250.120
172.71.11.60
172.71.94.149
172.71.99.156
172.71.99.168
172.71.118.162
172.71.126.136
172.71.134.102
172.71.154.67
172.71.154.70/31
172.71.154.126
172.71.155.43
172.71.155.60
172.71.158.183
172.71.158.194
172.71.158.214
172.71.183.4
172.71.184.35
172.71.184.143
172.71.184.144
172.71.184.164
172.71.250.37
172.71.250.42
172.85.100.90
172.96.90.182
172.96.92.160
172.96.92.222
172.241.247.196
172.245.10.60
172.255.93.195
173.44.222.9
173.211.30.91
173.214.177.189
173.238.105.239
173.238.107.127
173.238.110.196
173.238.116.244
173.238.117.105
173.238.126.32
173.238.202.247
173.238.242.141
173.238.243.150
173.239.217.135
173.239.237.81
173.239.237.138
174.198.5.24
176.8.89.36
176.215.180.76
178.20.30.214
178.20.42.231
178.20.55.182
178.120.2.102
178.120.2.158
178.159.37.4
178.159.37.60
178.159.37.142
178.159.37.156
178.176.72.48
181.214.166.233
182.106.220.252
183.199.125.16
184.174.44.119
185.72.240.133
185.72.240.179
185.72.241.89
185.72.241.207
185.100.85.25
185.103.109.246
185.104.218.33
185.186.78.160
185.192.70.103
185.192.70.115
185.192.70.121
185.192.70.127
185.197.74.6
185.217.136.67
185.220.100.244
185.220.100.248
185.220.100.255
185.220.101.31
185.221.25.94
185.242.95.84
185.244.183.87
185.253.162.25
186.14.227.32
186.179.35.32
188.65.17.23
188.126.89.67
188.130.129.129
188.130.129.207
188.130.143.175
188.130.211.142
188.138.129.64
188.157.0.110
188.243.18.244
191.96.32.3
191.96.32.4
191.96.32.148
191.96.95.61
191.96.180.66
191.96.252.193
191.96.255.188
191.101.250.67
191.102.130.3
191.102.130.5
191.102.130.6/31
191.102.130.8/31
191.102.130.10
191.102.130.18
191.102.130.130
191.102.130.235
191.102.131.3
191.102.131.4/30
191.102.131.8/31
191.102.131.10
191.102.131.189
191.102.152.196
192.3.57.229
192.3.58.6
192.3.58.149
192.3.59.26
192.3.59.104
192.42.116.181
192.42.116.191
192.42.116.196
192.42.116.214
192.42.116.217
192.111.135.17
192.126.160.80
192.154.207.2/31
192.154.207.4
192.154.207.84
192.154.207.184
192.154.214.4/31
192.154.214.6
192.154.214.10
192.171.82.240
192.186.71.14
192.186.177.248
192.186.182.36
192.198.105.209
192.241.119.55
192.252.220.92
193.7.219.26
193.36.172.37
193.151.189.20
193.188.20.66
193.188.20.96
193.188.21.49
193.188.21.238
194.32.229.140
194.34.248.168
194.36.98.32
194.36.99.172
194.113.113.27
194.124.158.80
194.169.92.171
194.169.92.182
194.169.93.97
194.169.93.104
194.169.94.82
194.169.94.157
194.169.95.3
194.169.95.52
194.169.95.110
194.169.95.141
194.233.91.18
195.2.67.223
195.154.61.146
195.201.242.237
196.0.111.194
196.51.32.154
196.51.35.126
196.51.93.248
196.51.137.102
196.51.137.183
196.57.217.15
196.58.214.28
196.196.31.13
196.196.31.178
196.196.31.224
196.196.31.248
196.196.35.164
196.196.35.175
196.196.160.26
196.196.160.45
196.196.160.126
196.196.160.172
196.196.169.20
196.196.255.86
196.198.13.200
196.198.13.223
196.198.16.154
196.198.16.159
196.198.211.86
196.198.211.117
196.198.211.149
196.198.211.220
196.199.10.55
196.199.104.32
196.199.104.148
196.199.104.180
196.199.104.236
196.240.105.176
196.240.143.57
196.240.143.80
196.240.143.188
196.240.143.198
196.240.143.238
196.240.237.201
196.240.254.206
196.241.86.130
196.242.20.187
196.242.20.211
196.242.20.235
196.242.21.97
196.242.195.105
196.242.195.145
196.244.48.47
196.245.164.64
196.245.181.84
196.247.46.28
197.156.116.38
198.12.72.229
198.16.70.52
198.20.172.78
198.20.180.156
198.20.182.104
198.23.170.169
198.46.202.198
199.229.254.129
199.255.201.170
203.80.167.62
204.8.96.161
204.44.69.97
206.41.172.63
206.206.71.7
207.70.204.53
208.102.51.6
209.58.157.8
209.127.45.185
209.171.88.56
209.171.88.70
209.171.88.79
209.171.88.122
209.171.88.128
209.242.208.28
209.242.209.135
209.242.210.76
209.242.210.84
212.21.66.6
212.30.36.62
212.30.36.76
212.30.36.93
212.30.36.94
212.30.36.97
212.30.36.101
212.30.36.166
212.112.19.20
212.115.61.31
212.192.193.46
212.251.16.33
213.87.156.248
213.219.247.57
213.219.247.125
216.173.79.232
216.173.99.127
216.173.110.230
216.173.118.2/31
216.173.118.4/30
216.173.118.8
216.173.118.38
216.173.118.252
217.138.216.153
220.134.249.220
223.190.1.172

13061
botscout_30d.ipset Normal file

File diff suppressed because it is too large Load Diff

3891
botscout_7d.ipset Normal file

File diff suppressed because it is too large Load Diff

177
botvrij_dst.ipset Normal file
View File

@ -0,0 +1,177 @@
#
# botvrij_dst
#
# ipv4 hash:ip ipset
#
# [botvrij.eu] (http://www.botvrij.eu/) Indicators of
# Compromise (IOCS) about malicious destination IPs, gathered
# via open source information feeds (blog pages and PDF
# documents) and then consolidated into different datasets.
# To ensure the quality of the data all entries older than
# approx. 6 months are removed.
#
# Maintainer : botvrij.eu
# Maintainer URL : http://www.botvrij.eu/
# List source URL : http://www.botvrij.eu/data/ioclist.ip-dst.raw
# Source File Date: Wed Apr 10 19:13:12 UTC 2024
#
# Category : attacks
# Version : 79
#
# This File Date : Thu Apr 11 21:52:03 UTC 2024
# Update Frequency: 1 day
# Aggregation : none
# Entries : 143 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=botvrij_dst
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.92.240.113
3.144.135.247
14.225.210.97
14.225.210.98
14.225.210.209
14.225.210.222
18.215.238.53
20.120.249.43
20.151.89.252
20.237.166.161
23.224.99.242
23.224.99.243
23.224.99.244
23.224.99.245
23.224.99.246
23.225.35.234
23.225.35.235
23.225.35.236
23.225.35.237
23.225.35.238
34.135.1.100
37.120.237.204
37.120.237.248
37.139.129.145
38.180.2.23
38.180.3.57
38.180.76.31
43.153.75.48
43.153.106.236
43.155.173.104
43.157.58.203
43.157.63.199
43.163.221.160
45.9.148.193
45.9.149.215
45.67.230.91
45.89.106.147
45.128.232.143
45.153.240.73
46.8.198.196
49.51.49.54
51.79.208.192
52.161.154.239
54.219.169.167
62.84.100.225
62.115.255.163
63.79.171.112
64.31.63.70
64.31.63.194
65.20.97.203
65.21.51.58
66.70.160.251
70.62.153.174
74.124.219.71
77.246.96.204
79.134.225.17
82.102.19.88
82.180.150.197
84.32.189.74
86.105.18.113
91.92.247.212
91.92.254.31
91.235.234.81
91.235.234.251
93.115.22.212
94.131.3.160
94.131.98.14
94.131.109.65
94.156.71.115
95.164.38.99
95.164.46.199
95.179.176.250
103.76.128.34
103.127.43.208
103.212.81.155
103.212.81.157
104.193.88.123
107.148.41.146
107.172.79.5
134.122.197.80
139.99.23.9
145.239.54.169
146.70.124.102
146.70.149.61
156.241.86.2
162.62.225.65
167.114.4.175
167.114.138.249
170.106.196.76
172.86.66.165
172.105.124.34
173.233.137.36
173.233.137.44
173.233.137.52
173.233.137.60
173.233.139.164
176.97.66.57
176.97.76.118
176.97.76.129
176.99.6.152
176.119.195.113
176.119.195.115
176.124.32.84
178.21.13.3
178.21.13.32
178.21.13.33
178.21.13.34
178.21.13.35
178.21.14.92
178.21.14.93
178.21.15.41
178.21.15.42
178.21.15.85
178.21.15.183
178.21.15.204
178.162.227.180
179.43.172.127
179.43.172.191
183.134.93.171
185.44.81.147
185.162.235.206
185.180.223.48
185.220.101.58
185.228.72.38
185.241.208.83
185.241.208.104
185.244.30.218
190.2.145.24
192.243.59.12
192.243.59.13
192.243.59.20
192.243.61.225
192.243.61.227
193.34.167.245
193.142.58.126
195.10.205.23
198.50.170.72
198.244.174.214
199.34.27.196
203.95.8.98
203.95.9.54
205.147.101.170
217.57.80.18

34
botvrij_src.ipset Normal file
View File

@ -0,0 +1,34 @@
#
# botvrij_src
#
# ipv4 hash:ip ipset
#
# [botvrij.eu] (http://www.botvrij.eu/) Indicators of
# Compromise (IOCS) about malicious source IPs, gathered via
# open source information feeds (blog pages and PDF
# documents) and then consolidated into different datasets.
# To ensure the quality of the data all entries older than
# approx. 6 months are removed.
#
# Maintainer : botvrij.eu
# Maintainer URL : http://www.botvrij.eu/
# List source URL : http://www.botvrij.eu/data/ioclist.ip-src.raw
# Source File Date: Tue Mar 8 13:55:10 UTC 2022
#
# Category : attacks
# Version : 7
#
# This File Date : Tue Mar 8 16:40:02 UTC 2022
# Update Frequency: 1 day
# Aggregation : none
# Entries : 0 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=botvrij_src
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#

321
bruteforceblocker.ipset Normal file
View File

@ -0,0 +1,321 @@
#
# bruteforceblocker
#
# ipv4 hash:ip ipset
#
# [danger.rulez.sk bruteforceblocker]
# (http://danger.rulez.sk/index.php/bruteforceblocker/)
# (fail2ban alternative for SSH on OpenBSD). This is an
# automatically generated list from users reporting failed
# authentication attempts. An IP seems to be included if 3 or
# more users report it. Its retention pocily seems 30 days.
#
# Maintainer : danger.rulez.sk
# Maintainer URL : http://danger.rulez.sk/index.php/bruteforceblocker/
# List source URL : http://danger.rulez.sk/projects/bruteforceblocker/blist.php
# Source File Date: Wed Apr 17 08:51:33 UTC 2024
#
# Category : attacks
# Version : 11210
#
# This File Date : Wed Apr 17 08:56:27 UTC 2024
# Update Frequency: 3 hours
# Aggregation : none
# Entries : 287 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=bruteforceblocker
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
2.57.122.110
2.57.122.233
5.189.151.15
14.6.185.28
14.32.241.81
14.99.181.98
27.35.42.85
34.216.115.104
34.223.254.251
35.224.220.188
43.245.161.230
45.125.66.43
45.137.198.64
46.23.108.249
51.81.165.111
51.159.17.182
54.67.94.62
54.193.61.199
59.31.148.130
62.171.137.67
64.23.132.161
64.23.141.137
64.23.224.234
64.23.227.68
64.23.252.16
64.225.17.76
64.225.25.253
65.182.136.237
67.205.169.229
68.183.150.225
68.183.158.20
77.238.111.74
79.1.202.214
79.110.62.53
79.161.91.35
79.175.128.161
80.94.92.63
80.94.92.65
80.94.92.115
85.215.163.137
87.98.128.18
87.98.138.142
87.246.7.206
91.148.190.170
92.53.82.117
92.251.17.0
96.19.196.214
98.18.26.150
101.33.74.13
101.202.19.199
103.77.233.166
103.155.193.186
104.131.179.45
104.236.122.69
104.248.163.11
109.120.176.139
115.91.84.132
115.241.74.34
116.98.164.71
116.98.165.174
116.98.166.100
116.98.166.152
116.98.168.158
116.98.171.29
116.98.172.187
116.98.172.239
116.98.174.78
116.98.175.9
116.98.175.241
116.105.211.26
116.105.211.185
116.105.216.247
116.110.2.185
116.110.65.90
116.110.69.207
116.110.70.16
116.110.73.171
116.110.78.151
116.110.79.134
116.110.84.124
116.110.85.73
116.110.85.226
116.110.87.230
116.110.90.200
116.110.95.213
116.110.113.80
116.110.114.192
116.110.216.204
119.200.35.45
119.203.143.121
119.236.17.187
121.123.29.141
122.151.59.40
128.199.134.136
134.122.43.224
134.122.43.240
134.209.47.156
134.209.95.26
134.209.173.51
137.184.162.173
137.184.231.177
138.197.9.198
138.197.28.1
138.197.32.99
138.197.38.20
138.197.90.231
138.197.94.22
138.197.94.49
138.197.138.89
138.197.142.73
138.197.144.78
138.197.156.205
138.197.160.20
138.197.168.139
139.19.117.129
139.59.91.160
141.94.221.28
141.98.10.44
141.98.11.179
142.93.182.54
143.110.150.244
143.110.221.98
143.198.57.210
144.126.206.54
144.126.217.20
144.126.230.251
146.190.53.250
146.190.165.237
147.182.204.147
147.182.239.105
149.202.90.68
154.198.210.95
157.245.111.228
157.245.120.62
158.160.32.99
159.65.13.60
159.65.135.177
159.65.159.128
159.65.171.208
159.203.10.201
159.203.15.96
159.203.86.109
159.203.105.136
159.203.110.20
161.35.169.163
162.243.185.202
165.227.119.16
165.227.206.84
165.227.230.101
165.232.34.226
165.232.125.47
165.232.166.202
165.232.184.60
167.71.103.194
167.71.103.243
167.71.140.9
167.71.165.27
167.99.68.198
167.99.202.59
167.172.230.140
167.172.234.135
170.64.131.175
170.64.134.116
170.64.135.91
170.64.139.24
170.64.139.117
170.64.143.22
170.64.143.46
170.64.143.247
170.64.145.6
170.64.147.55
170.64.147.152
170.64.151.56
170.64.151.208
170.64.151.213
170.64.151.227
170.64.151.228
170.64.153.3
170.64.159.4
170.64.159.223
170.64.159.243
170.64.161.109
170.64.163.40
170.64.163.173
170.64.171.42
170.64.174.86
170.64.175.83
170.64.175.157
170.64.177.118
170.64.182.191
170.64.183.211
170.64.183.233
170.64.185.159
170.64.187.22
170.64.190.158
170.64.193.147
170.64.194.165
170.64.195.5
170.64.195.7
170.64.195.135
170.64.195.147
170.64.195.157
170.64.195.167
170.64.196.151
170.64.200.50
170.64.201.96
170.64.201.121
170.64.201.130
170.64.201.148
170.64.210.129
170.64.213.4
170.64.213.30
170.64.214.250
170.64.217.106
170.64.217.107
170.64.220.63
170.64.221.251
170.64.222.255
170.64.224.23
170.64.224.105
170.64.224.150
170.64.224.178
170.64.226.205
170.64.226.206
170.64.228.15
170.64.228.132
170.64.228.188
170.64.228.219
170.64.228.239
170.64.228.241
170.64.229.96
170.64.229.109
170.64.229.112
170.64.230.67
170.64.230.189
170.64.230.226
170.64.232.170
170.64.232.239
170.64.233.15
170.64.233.43
170.64.234.33
170.64.234.171
170.64.236.26
170.64.236.134
170.64.236.207
170.64.238.12
171.251.16.109
171.251.18.42
171.251.24.119
171.251.25.9
171.251.26.34
171.251.27.170
172.233.57.39
172.233.58.223
174.138.49.67
174.138.49.182
174.138.53.141
174.138.58.211
175.214.88.184
178.62.10.177
178.128.54.7
178.128.54.194
178.128.62.89
178.128.160.55
178.128.172.26
178.128.230.173
179.43.180.106
182.72.219.186
183.81.169.238
183.179.2.185
183.245.232.31
185.100.53.58
186.96.145.241
192.227.148.214
193.32.162.11
193.32.162.12
193.32.162.19
193.231.40.144
194.169.175.35
194.187.48.251
199.45.154.4
200.150.163.69
209.38.250.200
220.71.191.234
221.167.63.25
222.114.168.244
223.18.61.211

15031
ciarmy.ipset Normal file

File diff suppressed because it is too large Load Diff

9154
cidr_report_bogons.netset Normal file

File diff suppressed because it is too large Load Diff

4549
cleanmx_phishing.ipset Normal file

File diff suppressed because it is too large Load Diff

12221
cleanmx_viruses.ipset Normal file

File diff suppressed because it is too large Load Diff

516
cleantalk.ipset Normal file
View File

@ -0,0 +1,516 @@
#
# cleantalk
#
# ipv4 hash:ip ipset
#
# [CleanTalk] (https://cleantalk.org/) Today's HTTP Spammers
# (includes: cleantalk_new cleantalk_updated)
#
# Maintainer : CleanTalk
# Maintainer URL : https://cleantalk.org/
# List source URL :
# Source File Date: Wed Apr 17 09:52:51 UTC 2024
#
# Category : abuse
# Version : 28467
#
# This File Date : Wed Apr 17 09:52:53 UTC 2024
# Update Frequency: 1 min
# Aggregation : none
# Entries : 486 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=cleantalk
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.22.130.88
1.22.168.58
1.56.151.169
1.189.229.200
2.57.149.169
3.81.1.51
3.81.68.18
3.82.10.74
3.86.57.1
3.89.37.10
3.92.55.49
3.216.46.22
4.236.87.125
5.45.37.249
5.157.5.39
5.157.33.27
5.178.111.69
5.178.111.70
5.178.111.149
5.178.111.170
5.178.111.171
5.178.111.191
5.178.111.229
5.181.168.251
14.177.1.221
14.226.60.133
14.241.230.248
18.213.110.60
18.215.232.182
18.215.244.137
20.172.185.51
23.27.240.108
23.27.240.199
23.81.61.21
23.108.47.139
23.129.254.166
23.148.64.49
23.229.26.231
23.229.36.156
23.229.59.172
23.236.227.181
23.236.247.26
24.133.172.35
27.79.153.89
27.79.156.88
27.79.177.88
31.7.38.186
31.40.203.78
31.40.203.239
31.173.86.91
34.73.29.50
34.201.8.109
34.207.107.243
34.212.103.221
34.230.52.255
34.231.71.87
34.235.145.5
35.90.44.199
35.90.100.155
35.167.46.245
35.175.125.210
35.175.236.99
36.88.190.114
37.28.52.74
37.34.88.165
37.34.90.104
37.34.93.238
37.143.62.20
37.143.62.30
37.143.62.115
37.169.147.56
37.170.211.186
38.109.254.217
38.130.38.2
38.140.46.186
38.153.200.203
38.153.205.181
38.199.66.55
39.48.214.183
41.76.242.102
41.207.248.18
41.211.127.77
43.229.11.30
45.11.20.144
45.14.192.34
45.14.192.82
45.15.73.148
45.81.137.82
45.84.177.76
45.87.253.149
45.90.196.76
45.115.209.238
45.127.250.253
45.136.106.41
45.151.161.33
45.170.14.44
45.229.214.241
45.249.106.178
46.8.111.45
46.8.111.203
46.8.156.243
46.138.85.140
46.159.14.220
47.15.99.23
47.128.18.67
47.128.52.196
49.0.200.245
49.0.202.9
49.0.204.143
49.0.204.165
49.0.204.178
49.0.205.79
49.0.205.155
49.0.205.171
49.0.206.16
49.12.56.176
49.85.250.4
50.118.141.12
52.5.174.13
52.138.48.230
54.152.170.100
54.152.198.39
54.161.69.63
54.162.127.149
54.172.22.183
54.197.204.222
54.212.242.253
54.242.181.118
58.136.162.132
58.187.211.33
61.2.25.184
61.147.93.121
61.170.238.213
65.20.160.61
65.154.226.168
66.165.246.34
69.58.6.4
69.58.78.3
69.160.160.56
79.137.203.195
79.150.214.224
81.16.128.251
82.221.136.1
85.25.237.50
85.108.198.13
85.203.36.224
85.203.44.229
85.203.44.234
85.239.36.102
89.33.223.18
89.36.231.153
89.149.24.108
89.252.185.76
91.149.255.102
91.225.217.62
92.118.40.101
92.118.43.226
92.119.36.59
92.119.36.81
92.119.36.98
93.177.60.218
94.25.225.56
94.74.80.161
94.74.83.225
94.74.85.211
94.74.86.73
94.74.88.87
94.74.89.69
94.74.90.33
94.74.94.172
94.158.20.14
94.158.20.151
94.158.190.29
95.70.229.196
95.139.217.182
100.24.69.164
101.44.160.37
101.44.160.128
101.44.160.189
101.44.160.204
101.44.160.236
101.44.161.51
101.44.161.254
101.44.162.16
101.44.250.35
101.44.250.248
101.44.251.150
101.128.100.44
102.0.2.220
103.56.19.252
103.70.115.167
103.74.68.131
103.111.207.154
103.113.71.230
103.133.68.171
103.171.172.235
103.186.128.122
103.187.99.198
103.215.248.156
103.216.59.222
103.220.209.4
103.225.202.155
103.235.198.46
104.28.157.197
104.28.230.165
104.139.74.25
104.239.7.244
104.249.27.4
104.252.131.107
106.214.192.157
107.21.90.183
107.174.232.198
109.73.178.123
109.120.133.12
109.230.218.215
109.248.54.87
109.248.204.41
110.42.217.219
110.154.102.5
110.154.133.64
110.238.104.161
110.238.106.18
110.238.107.76
110.238.108.232
110.238.109.169
110.238.110.36
110.238.110.188
110.238.111.43
110.238.111.118
110.249.201.148
110.249.201.155
110.249.202.8
110.249.202.20
110.249.202.152
110.249.202.167
111.67.58.119
111.88.44.227
111.88.45.166
111.88.47.192
111.225.148.48
111.225.148.142
113.88.208.28
114.7.121.182
114.119.173.19
114.119.180.25
116.96.167.6
116.103.154.173
116.104.54.41
117.30.139.21
118.194.252.58
119.13.103.43
119.13.104.14
119.13.104.159
119.13.104.210
119.13.105.88
119.13.105.163
119.13.105.197
119.13.107.86
119.13.109.251
119.39.69.182
119.39.79.15
120.77.2.102
122.53.47.83
122.160.112.18
122.176.202.105
123.13.59.91
123.20.217.140
123.142.115.107
124.243.132.85
124.243.133.174
124.243.133.248
124.243.134.87
124.243.134.126
124.243.135.114
124.243.135.236
124.243.136.12
124.243.136.24
124.243.136.43
124.243.136.201
124.243.138.168
124.243.138.234
124.243.139.173
124.243.145.41
124.243.146.203
124.243.147.133
124.243.148.208
124.243.151.1
124.243.151.144
125.164.18.30
125.164.25.233
128.201.77.9
129.205.124.169
131.72.68.222
137.135.81.91
138.128.151.101
138.199.59.44
138.229.98.160
138.255.215.78
139.180.136.106
139.192.201.238
140.213.200.68
142.147.111.22
142.147.129.233
142.214.182.64
142.214.182.80
143.55.135.244
149.71.178.24
149.71.182.225
152.44.99.46
152.53.3.82
154.12.108.102
154.12.111.11
154.12.111.37
154.12.111.48
154.12.111.167
154.12.128.234
154.13.102.188
154.21.239.98
154.28.132.19
154.28.132.82
154.28.135.87
154.28.135.159
154.28.135.237
154.28.143.109
154.30.194.51
154.30.227.8
154.55.92.0
154.72.171.9
154.202.101.8
154.202.101.171
154.202.101.236
154.202.120.186
154.202.121.221
156.239.37.177
156.239.38.82
156.239.38.134
156.239.39.106
156.239.48.79
156.239.52.112
156.239.52.254
156.239.62.193
157.245.45.247
159.138.96.117
159.138.96.146
159.138.97.75
159.138.102.121
159.138.103.36
159.138.105.87
159.138.105.133
159.138.105.142
159.138.107.49
159.138.107.151
159.138.108.179
159.138.110.8
159.138.110.35
159.138.123.188
159.223.46.52
163.5.71.235
163.5.138.145
165.231.108.108
166.88.122.107
166.88.125.24
166.88.235.161
170.244.133.254
171.233.77.129
171.242.125.202
171.245.72.129
171.245.252.58
171.252.208.212
172.111.139.20
172.121.142.104
173.249.0.2
176.232.9.163
177.93.71.114
178.20.30.235
178.128.208.138
178.140.136.62
178.176.75.123
180.158.21.114
180.244.160.12
182.139.6.153
182.244.111.145
184.174.30.233
185.45.66.11
185.72.242.215
185.99.175.4
185.123.50.131
185.136.206.209
185.136.206.230
185.181.245.121
185.192.69.186
185.192.69.187
185.192.69.193
185.192.69.204
185.192.70.122
185.199.231.32
185.212.139.223
185.242.93.213
186.179.100.166
188.130.128.179
188.130.136.152
188.130.137.170
188.130.188.210
188.130.189.193
188.138.17.213
188.138.57.53
188.165.60.102
188.253.4.203
190.92.199.19
190.92.199.75
190.92.201.147
190.92.202.87
190.92.203.43
190.92.206.247
190.92.208.153
190.92.209.33
190.92.209.117
190.92.209.184
190.92.210.9
190.92.210.141
190.92.210.227
190.92.211.188
190.92.213.10
190.92.213.52
190.92.215.12
192.144.25.140
192.144.27.250
192.154.207.3
192.186.130.155
192.186.160.194
192.198.105.202
192.198.119.52
193.47.238.74
193.47.238.144
193.47.238.202
193.56.252.43
193.141.60.143
193.203.14.240
193.233.40.30
194.32.120.186
194.32.120.208
194.32.229.160
194.34.248.64
194.34.248.192
194.169.94.78
196.11.90.242
196.51.207.7
196.57.225.38
196.58.225.20
196.112.62.1
196.196.23.204
196.196.53.140
196.216.70.214
196.242.70.18
196.243.240.119
197.57.232.69
198.23.170.169
202.57.210.111
202.79.34.148
202.137.134.214
202.137.154.86
203.78.146.162
203.188.243.98
206.232.127.252
207.182.28.34
209.242.210.118
209.242.210.176
212.30.33.6
212.30.33.48
212.66.41.121
212.102.35.20
212.102.46.41
212.102.51.249
212.115.49.187
213.207.39.218
216.24.213.56
216.158.139.194
216.173.118.2
216.173.118.4
217.113.194.134
217.113.194.141
217.113.194.190
221.200.219.48
222.136.167.231
223.205.137.145
223.205.193.139

7725
cleantalk_1d.ipset Normal file

File diff suppressed because it is too large Load Diff

60108
cleantalk_30d.ipset Normal file

File diff suppressed because it is too large Load Diff

24054
cleantalk_7d.ipset Normal file

File diff suppressed because it is too large Load Diff

279
cleantalk_new.ipset Normal file
View File

@ -0,0 +1,279 @@
#
# cleantalk_new
#
# ipv4 hash:ip ipset
#
# [CleanTalk] (https://cleantalk.org/) Recent HTTP Spammers
#
# Maintainer : CleanTalk
# Maintainer URL : https://cleantalk.org/
# List source URL : https://cleantalk.org/blacklists/submited_today
# Source File Date: Wed Apr 17 09:52:43 UTC 2024
#
# Category : abuse
# Version : 26795
#
# This File Date : Wed Apr 17 09:52:43 UTC 2024
# Update Frequency: 15 mins
# Aggregation : none
# Entries : 250 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=cleantalk_new
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.22.130.88
1.22.168.58
1.56.151.169
1.189.229.200
3.81.1.51
3.81.68.18
3.82.10.74
3.86.57.1
3.89.37.10
3.92.55.49
5.178.111.69
5.178.111.70
5.178.111.149
5.178.111.170
5.178.111.171
5.178.111.191
5.178.111.229
14.177.1.221
14.226.60.133
18.213.110.60
18.215.244.137
20.172.185.51
23.148.64.49
24.133.172.35
27.79.153.89
27.79.156.88
27.79.177.88
34.73.29.50
34.201.8.109
34.212.103.221
34.230.52.255
34.235.145.5
35.90.44.199
35.90.100.155
35.167.46.245
35.175.125.210
36.88.190.114
37.28.52.74
37.169.147.56
37.170.211.186
38.109.254.217
38.130.38.2
38.199.66.55
39.48.214.183
45.14.192.34
45.14.192.82
45.115.209.238
45.136.106.41
45.151.161.33
45.229.214.241
46.138.85.140
46.159.14.220
47.15.99.23
49.0.200.245
49.0.202.9
49.0.204.143
49.0.204.165
49.0.204.178
49.0.205.79
49.0.205.155
49.0.205.171
49.0.206.16
49.85.250.4
52.138.48.230
54.152.198.39
54.161.69.63
54.172.22.183
54.197.204.222
54.212.242.253
54.242.181.118
58.136.162.132
58.187.211.33
61.170.238.213
79.137.203.195
79.150.214.224
81.16.128.251
85.108.198.13
89.36.231.153
89.252.185.76
91.149.255.102
92.118.40.101
92.118.43.226
93.177.60.218
94.74.80.161
94.74.83.225
94.74.85.211
94.74.86.73
94.74.88.87
94.74.89.69
94.74.90.33
94.74.94.172
95.70.229.196
95.139.217.182
100.24.69.164
101.44.160.37
101.44.160.128
101.44.160.189
101.44.160.204
101.44.160.236
101.44.161.51
101.44.161.254
101.44.162.16
101.128.100.44
103.70.115.167
103.111.207.154
103.171.172.235
103.186.128.122
103.215.248.156
103.220.209.4
106.214.192.157
107.21.90.183
109.73.178.123
109.120.133.12
110.154.102.5
110.238.104.161
110.238.106.18
110.238.107.76
110.238.108.232
110.238.110.36
110.238.110.188
110.238.111.43
110.238.111.118
111.67.58.119
111.88.44.227
111.88.45.166
113.88.208.28
114.7.121.182
114.119.173.19
114.119.180.25
116.96.167.6
116.103.154.173
116.104.54.41
117.30.139.21
119.13.103.43
119.13.104.14
119.13.104.159
119.13.104.210
119.13.105.88
119.13.105.163
119.13.105.197
119.13.107.86
119.13.109.251
119.39.69.182
119.39.79.15
120.77.2.102
122.53.47.83
122.176.202.105
123.20.217.140
123.142.115.107
124.243.132.85
124.243.133.174
124.243.133.248
124.243.134.126
124.243.135.114
124.243.135.236
124.243.136.12
124.243.136.24
124.243.136.43
124.243.136.201
124.243.138.168
124.243.138.234
124.243.139.173
124.243.146.203
124.243.147.133
124.243.148.208
124.243.151.1
124.243.151.144
125.164.18.30
125.164.25.233
137.135.81.91
139.192.201.238
140.213.200.68
142.214.182.64
142.214.182.80
143.55.135.244
152.53.3.82
154.12.108.102
154.12.111.11
154.12.111.37
154.12.111.48
154.12.111.167
154.28.132.19
154.28.132.82
154.28.135.87
154.28.135.159
154.28.135.237
154.55.92.0
157.245.45.247
159.138.96.117
159.138.96.146
159.138.97.75
159.138.102.121
159.138.103.36
159.138.105.87
159.138.105.142
159.138.107.49
159.138.107.151
159.138.108.179
159.138.110.8
159.138.110.35
159.138.123.188
166.88.125.24
166.88.235.161
171.233.77.129
171.242.125.202
171.245.72.129
171.252.208.212
172.111.139.20
176.232.9.163
180.158.21.114
180.244.160.12
182.139.6.153
182.244.111.145
185.123.50.131
185.136.206.209
185.136.206.230
185.212.139.223
188.165.60.102
188.253.4.203
190.92.199.19
190.92.199.75
190.92.201.147
190.92.202.87
190.92.203.43
190.92.206.247
190.92.208.153
190.92.209.33
190.92.209.117
190.92.209.184
190.92.210.9
190.92.210.141
190.92.210.227
190.92.211.188
190.92.213.10
190.92.213.52
192.144.25.140
192.144.27.250
193.47.238.74
193.47.238.144
193.47.238.202
193.141.60.143
196.11.90.242
196.112.62.1
196.216.70.214
197.57.232.69
206.232.127.252
221.200.219.48
222.136.167.231
223.205.137.145
223.205.193.139

878
cleantalk_new_1d.ipset Normal file
View File

@ -0,0 +1,878 @@
#
# cleantalk_new_1d
#
# ipv4 hash:ip ipset
#
# [CleanTalk] (https://cleantalk.org/) Recent HTTP Spammers
#
# Maintainer : CleanTalk
# Maintainer URL : https://cleantalk.org/
# List source URL : https://cleantalk.org/blacklists/submited_today
# Source File Date: Wed Apr 17 09:52:43 UTC 2024
#
# Category : abuse
# Version : 26742
#
# This File Date : Wed Apr 17 09:52:44 UTC 2024
# Update Frequency: 15 mins
# Aggregation : 1 day
# Entries : 853 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=cleantalk_new_1d
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.22.130.88
1.22.168.58
1.23.233.170
1.23.233.175
1.23.233.201
1.23.233.248
1.56.151.169
1.58.31.209
1.189.229.200
3.15.143.181
3.17.28.48
3.80.167.197
3.80.178.167
3.81.1.51
3.81.9.244
3.81.39.44
3.81.68.18
3.81.124.82
3.82.10.74
3.84.96.251
3.84.129.48
3.84.173.5
3.85.4.227
3.85.105.180
3.86.57.1
3.87.109.90
3.88.71.18
3.89.28.28
3.89.37.10
3.89.44.85
3.89.182.254
3.92.43.177
3.92.55.49
3.128.199.162
3.129.45.92
3.131.110.169
3.133.131.168
3.134.85.87
3.137.218.215
3.141.47.221
3.144.113.30
3.144.124.232
3.144.189.177
3.144.243.184
3.144.251.72
3.145.8.42
3.145.108.9
3.145.119.199
3.146.65.212
3.235.153.100
4.227.199.141
5.114.146.77
5.140.67.155
5.178.111.69
5.178.111.70
5.178.111.149
5.178.111.170/31
5.178.111.191
5.178.111.229
5.227.210.49
13.58.82.79
13.214.116.235
14.176.174.199
14.177.1.221
14.180.166.216
14.226.60.133
18.117.91.153
18.118.140.108
18.118.200.86
18.119.133.228
18.163.5.214
18.188.61.223
18.188.175.182
18.191.211.66
18.191.234.62
18.206.100.36
18.206.178.173
18.213.110.60
18.215.232.182
18.215.244.137
18.218.129.100
18.226.222.12
18.227.161.132
18.232.78.35
18.232.95.142
18.232.100.207
18.234.96.65
18.234.123.248
18.234.245.80
18.237.3.248
20.49.35.127
20.163.146.252
20.163.228.26
20.169.245.55
20.172.185.51
20.172.204.121
20.185.80.183
20.185.80.243
20.185.83.118
20.186.11.243
23.109.208.70
23.109.212.166
23.137.253.109
23.137.253.110
23.148.64.49
23.178.16.90
23.229.59.122
23.236.122.206
24.133.172.35
27.65.112.49
27.66.26.55
27.69.244.241
27.74.155.180
27.75.149.105
27.77.234.53
27.79.153.89
27.79.156.88
27.79.176.30
27.79.177.88
27.79.221.227
27.79.224.67
31.8.103.12
31.155.130.230
31.223.189.236
32.218.62.63
34.73.29.50
34.140.87.85
34.148.244.55
34.201.8.109
34.207.108.30
34.210.67.128
34.212.103.221
34.226.124.190
34.227.72.122
34.228.220.30
34.229.45.75
34.229.118.230
34.229.226.3
34.229.241.249
34.230.52.255
34.235.141.203
34.235.145.5
34.238.139.195
35.87.123.219
35.89.113.199
35.90.44.199
35.90.100.155
35.93.68.125
35.167.46.245
35.171.85.224
35.171.183.244
35.173.255.144
35.175.125.210
35.175.202.92
35.175.236.99
36.37.195.222
36.88.190.114
36.143.95.247
36.161.206.103
37.28.52.74
37.28.63.213
37.169.147.56
37.170.27.112
37.170.211.186
37.170.221.225
37.221.47.157
38.47.104.11
38.47.105.215
38.54.25.20
38.109.254.217
38.130.38.2
38.130.46.82
38.153.205.185
38.165.178.112
38.170.102.72
38.170.104.182
38.170.124.15
38.170.124.123
38.199.66.55
39.35.4.118
39.35.29.232
39.35.79.235
39.35.95.53
39.35.125.232
39.35.163.117
39.36.222.35
39.48.214.183
39.51.64.230
40.69.143.64
40.69.145.136
40.69.164.36
40.76.71.190
40.88.34.22
40.114.41.140
40.118.172.23
42.84.156.38
42.231.20.207
43.130.42.4
43.224.118.137
43.229.47.18
44.203.218.67
44.211.255.150
44.223.34.148
45.14.192.34
45.14.192.82
45.33.156.90
45.43.70.113
45.43.185.125
45.76.18.197
45.115.209.238
45.127.222.252
45.131.94.107
45.131.103.239
45.135.139.146
45.135.139.230
45.136.106.41
45.138.119.213
45.151.161.33
45.155.126.188
45.156.62.6
45.157.52.131
45.196.137.118
45.229.214.241
45.230.76.191
45.251.63.17
46.24.40.120
46.73.102.109
46.117.107.89
46.117.210.253
46.138.85.140
46.158.189.36
46.159.14.220
46.159.85.12
46.216.224.159
47.15.99.23
47.128.206.95
49.0.200.245
49.0.202.9
49.0.204.143
49.0.204.165
49.0.204.178
49.0.205.79
49.0.205.155
49.0.205.171
49.0.206.16
49.13.129.5
49.50.25.129
49.72.9.208
49.85.250.4
49.114.241.195
50.17.5.231
50.114.185.75
52.23.247.27
52.55.127.182
52.90.138.255
52.90.218.35
52.91.177.109
52.91.236.97
52.138.48.230
52.138.61.113
52.168.136.20
52.200.42.235
52.202.195.35
52.205.31.40
52.234.139.135
52.234.250.47
52.248.70.69
54.73.15.46
54.80.55.181
54.80.60.114
54.80.107.76
54.80.133.151
54.80.223.105
54.81.133.165
54.81.205.175
54.83.116.109
54.84.155.190
54.84.237.175
54.88.2.27
54.89.95.100
54.89.113.90
54.89.152.212
54.89.239.44
54.92.180.8
54.145.92.108
54.145.125.91
54.145.195.102
54.149.46.93
54.152.92.45
54.152.198.39
54.157.192.129
54.158.128.61
54.161.69.63
54.161.164.181
54.162.38.203
54.162.185.87
54.162.230.34
54.164.20.195
54.165.252.66
54.166.207.117
54.166.245.202
54.167.200.75
54.167.216.5
54.172.22.183
54.174.179.73
54.188.207.53
54.191.247.70
54.196.66.101
54.197.204.222
54.197.212.214
54.197.216.88
54.198.38.243
54.198.161.28
54.205.227.75
54.208.252.31
54.210.41.108
54.211.180.83
54.212.242.253
54.224.177.218
54.224.194.74
54.224.208.58
54.225.1.160
54.227.78.151
54.234.129.188
54.237.204.86
54.242.22.97
54.242.181.118
58.136.162.132
58.187.211.33
61.170.238.213
61.223.77.248
62.16.34.34
64.137.42.247
64.137.43.64
65.21.132.14
65.108.232.252
65.109.217.239
67.60.253.73
70.109.137.112
70.163.198.28
71.161.222.43
72.214.108.67
74.127.87.80
75.140.76.165
75.217.236.169
75.222.101.243
77.34.169.18
77.35.143.100
77.35.186.174
77.90.12.228
78.10.122.86
78.151.170.97
79.137.203.195
79.150.214.224
79.191.174.198
80.72.90.237
80.134.1.115
80.191.254.106
81.16.128.67
81.16.128.244
81.16.128.251
82.24.184.122
82.153.138.119
82.159.202.208
83.22.182.84
84.33.243.37
84.232.112.54
84.239.43.172
84.239.43.178
84.247.105.82
85.108.198.13
86.38.154.108
86.102.213.92
87.3.117.232
87.248.157.49
88.28.217.179
89.36.231.153
89.39.170.14
89.45.125.132
89.116.78.183
89.252.185.76
91.135.26.8
91.149.255.102
91.191.23.207
91.223.126.132
92.17.178.53
92.24.45.211
92.118.39.120
92.118.40.101
92.118.43.226
93.175.249.138
93.177.60.218
93.177.102.188
93.180.132.155
94.74.80.161
94.74.83.225
94.74.85.211
94.74.86.73
94.74.88.87
94.74.89.69
94.74.90.33
94.74.94.172
94.74.135.144
94.131.64.144
94.131.64.197
94.154.16.42
95.26.208.165
95.67.184.185
95.70.229.196
95.139.217.182
95.164.207.85
95.164.207.129
95.205.169.134
100.24.15.114
100.24.65.32
100.24.69.164
101.44.160.37
101.44.160.128
101.44.160.189
101.44.160.204
101.44.160.236
101.44.161.51
101.44.161.254
101.44.162.16
101.70.140.42
101.128.100.44
102.0.6.120
103.39.49.45
103.55.90.49
103.70.115.167
103.73.92.124
103.77.51.44
103.91.95.39
103.99.33.154
103.111.207.154
103.112.14.125
103.114.247.233
103.159.155.41
103.171.172.235
103.177.66.27
103.182.103.137
103.186.128.122
103.194.175.138
103.213.242.140
103.215.248.156
103.220.209.4
103.250.70.58
104.60.28.207
104.209.255.228
104.233.19.243
104.239.20.162
104.243.214.50
106.194.123.158
106.201.241.252
106.207.58.249
106.214.192.157
106.214.193.39
106.214.194.79
106.214.195.149
107.21.90.183
107.22.23.128
107.22.70.129
107.22.118.160
107.22.156.124
107.23.225.191
107.150.0.60
107.187.39.18
108.181.43.186
108.246.199.209
109.73.178.123
109.120.133.12
109.184.21.157
109.184.57.0
109.184.236.58
110.44.124.87
110.74.195.214
110.138.94.43
110.154.98.159
110.154.102.5
110.235.247.140
110.238.104.161
110.238.106.18
110.238.107.76
110.238.108.232
110.238.110.36
110.238.110.188
110.238.111.43
110.238.111.118
110.244.95.205
111.67.58.119
111.88.26.251
111.88.44.227
111.88.45.166
112.92.70.43
113.11.37.6
113.88.208.28
114.7.121.182
114.119.173.19
114.119.180.25
114.130.153.106
115.178.101.70
115.223.43.85
116.96.167.6
116.96.210.249
116.98.49.112
116.99.35.157
116.100.92.125
116.101.24.117
116.101.131.95
116.103.23.223
116.103.154.173
116.103.248.109
116.104.54.41
116.105.172.56
116.107.179.41
116.109.11.58
116.109.27.125
116.109.183.21
116.109.186.178
116.109.192.142
116.109.195.53
116.110.54.142
116.212.142.155
116.212.156.188
117.3.197.207
117.30.139.21
117.212.0.87
117.212.9.206
117.212.220.49
117.233.136.235
117.233.141.236
117.233.148.30
117.241.236.83
118.172.227.112
118.193.57.126
118.194.252.203
118.194.255.163
119.13.103.43
119.13.104.14
119.13.104.159
119.13.104.210
119.13.105.88
119.13.105.163
119.13.105.197
119.13.107.86
119.13.109.251
119.39.69.104
119.39.69.182
119.39.79.15
119.41.195.55
119.41.199.161
120.11.97.219
120.36.203.123
120.77.2.102
120.79.170.197
121.67.103.3
121.123.87.94
121.239.170.92
122.52.29.48
122.53.47.83
122.102.27.57
122.173.203.241
122.176.202.105
122.176.202.173
122.176.203.31
122.176.206.239
122.177.103.216
122.180.189.40
123.20.154.185
123.20.217.140
123.27.47.26
123.142.115.107
123.241.94.51
124.243.132.85
124.243.133.174
124.243.133.248
124.243.134.126
124.243.135.114
124.243.135.236
124.243.136.12
124.243.136.24
124.243.136.43
124.243.136.201
124.243.138.168
124.243.138.234
124.243.139.173
124.243.146.203
124.243.147.133
124.243.148.208
124.243.151.1
124.243.151.144
125.27.83.181
125.164.18.30
125.164.25.233
125.211.94.251
128.14.236.16
128.14.239.189
128.90.59.13
128.90.101.15
130.25.28.199
134.17.38.198
136.0.88.171
136.0.109.240
137.117.102.9
137.135.81.91
138.88.144.159
139.192.201.238
140.213.200.68
142.44.235.212
142.214.182.64
142.214.182.80
143.55.135.244
147.235.220.220
149.5.4.203
149.28.156.201
149.50.218.215
149.71.178.177
149.109.103.2
150.230.4.171
152.32.149.40
152.32.164.109
152.32.165.123
152.32.231.121
152.44.104.3
152.53.3.82
153.3.32.104/31
154.12.76.148
154.12.76.186
154.12.77.231
154.12.108.102
154.12.111.11
154.12.111.37
154.12.111.48
154.12.111.167
154.12.117.5
154.12.117.51
154.12.117.133
154.12.117.167
154.13.10.16
154.13.10.158
154.13.10.210
154.13.10.230
154.13.11.43
154.21.239.213
154.26.161.67
154.26.161.88
154.26.161.244
154.26.163.140
154.28.132.19
154.28.132.82
154.28.135.87
154.28.135.159
154.28.135.237
154.29.105.26
154.29.238.22
154.29.238.164
154.30.59.27
154.30.59.254
154.37.248.248
154.37.251.41
154.37.251.145
154.44.23.6
154.55.92.0
154.72.76.122
154.72.79.218
154.80.39.205
154.128.158.125
155.94.232.23
157.39.71.187
157.245.45.247
159.69.182.73
159.138.96.117
159.138.96.146
159.138.97.75
159.138.102.121
159.138.103.36
159.138.105.87
159.138.105.142
159.138.107.49
159.138.107.151
159.138.108.179
159.138.110.8
159.138.110.35
159.138.123.188
159.223.195.61
160.19.136.133
160.218.103.53
161.188.33.147
162.0.217.169
163.116.203.117
165.154.104.183
165.154.121.176
166.88.125.24
166.88.235.161
167.160.69.2
167.160.74.75
167.160.176.87
167.160.176.158
167.160.180.140
168.196.238.211
170.106.140.249
171.5.163.75
171.61.176.199
171.212.240.9
171.227.69.124
171.233.77.129
171.239.132.159
171.240.190.254
171.241.78.13
171.242.42.241
171.242.76.25
171.242.125.202
171.245.72.129
171.248.26.117
171.251.0.81
171.252.128.55
171.252.208.212
172.111.139.20
172.111.185.72
172.203.150.14
172.223.49.79
172.235.0.82
173.182.86.200
173.242.108.43
175.121.203.84
176.161.229.10
176.232.9.163
177.36.33.16
177.47.155.67
177.87.71.47
177.184.176.176
177.234.209.146
178.45.82.224
178.71.204.175
178.122.19.77
179.197.80.146
180.158.17.163
180.158.21.114
180.210.191.74
180.244.160.12
182.52.149.50
182.53.253.216
182.69.135.74
182.139.6.153
182.181.237.13
182.244.111.145
183.22.251.173
183.212.184.186
185.70.187.140
185.72.240.13
185.122.144.171
185.123.50.131
185.136.206.209
185.136.206.230
185.178.255.222
185.196.178.77
185.196.179.40
185.212.139.184
185.212.139.223
185.221.253.226
186.225.180.237
188.165.60.102
188.253.4.203
190.71.50.27
190.92.199.19
190.92.199.75
190.92.201.147
190.92.202.87
190.92.203.43
190.92.206.247
190.92.208.153
190.92.209.33
190.92.209.117
190.92.209.184
190.92.210.9
190.92.210.141
190.92.210.227
190.92.211.188
190.92.213.10
190.92.213.52
191.253.68.27
192.144.25.140
192.144.27.250
192.171.84.38
193.35.94.223
193.47.238.74
193.47.238.144
193.47.238.202
193.141.60.143
194.116.249.66
195.224.195.148
196.11.90.242
196.77.108.93
196.112.62.1
196.112.110.89
196.112.146.156
196.216.70.214
197.14.17.230
197.57.232.69
197.63.233.113
198.167.201.232
200.10.70.35
200.125.213.0
200.215.161.48
202.29.224.58
202.178.127.78
204.8.96.64
204.8.96.67
204.8.96.84
204.8.96.86
204.8.96.89
204.8.96.140
204.8.96.142
204.8.96.168
204.236.249.110
205.161.88.170
205.161.89.130
205.161.89.217
205.161.89.233
205.161.92.165
205.161.92.207
205.161.93.196
205.161.95.97
205.161.95.98
206.206.66.89
206.232.13.31
206.232.127.252
211.233.24.7
211.233.42.203
212.35.174.211
212.35.188.156
213.202.235.26
216.173.103.148
216.228.197.246
217.69.121.24
217.69.126.51
217.69.127.16
217.69.127.239
218.102.135.214
221.200.208.28
221.200.219.48
222.95.237.88
222.136.160.232
222.136.167.101
222.136.167.231
223.65.102.166/31
223.65.102.168/31
223.205.137.145
223.205.193.139

16825
cleantalk_new_30d.ipset Normal file

File diff suppressed because it is too large Load Diff

3729
cleantalk_new_7d.ipset Normal file

File diff suppressed because it is too large Load Diff

49
cleantalk_top20.ipset Normal file
View File

@ -0,0 +1,49 @@
#
# cleantalk_top20
#
# ipv4 hash:ip ipset
#
# [CleanTalk] (https://cleantalk.org/) Top 20 HTTP Spammers
#
# Maintainer : CleanTalk
# Maintainer URL : https://cleantalk.org/
# List source URL : https://cleantalk.org/blacklists/top20
# Source File Date: Wed Apr 17 03:25:12 UTC 2024
#
# Category : abuse
# Version : 1648
#
# This File Date : Wed Apr 17 03:25:12 UTC 2024
# Update Frequency: 1 day
# Aggregation : none
# Entries : 20 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=cleantalk_top20
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
5.188.210.25
5.188.210.87
45.133.172.23
45.133.172.46
62.210.80.33
89.234.157.254
156.146.63.145
156.146.63.163
178.159.37.4
178.159.37.34
185.190.42.200
188.126.94.176
188.126.94.179
188.126.94.189
188.241.178.25
191.101.31.36
191.101.217.24
199.167.138.22
212.102.57.2
213.159.38.90

279
cleantalk_updated.ipset Normal file
View File

@ -0,0 +1,279 @@
#
# cleantalk_updated
#
# ipv4 hash:ip ipset
#
# [CleanTalk] (https://cleantalk.org/) Recurring HTTP Spammers
#
# Maintainer : CleanTalk
# Maintainer URL : https://cleantalk.org/
# List source URL : https://cleantalk.org/blacklists/updated_today
# Source File Date: Wed Apr 17 09:52:51 UTC 2024
#
# Category : abuse
# Version : 26738
#
# This File Date : Wed Apr 17 09:52:52 UTC 2024
# Update Frequency: 15 mins
# Aggregation : none
# Entries : 250 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=cleantalk_updated
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
2.57.149.169
3.216.46.22
4.236.87.125
5.45.37.249
5.157.5.39
5.157.33.27
5.178.111.69
5.181.168.251
14.241.230.248
18.215.232.182
23.27.240.108
23.27.240.199
23.81.61.21
23.108.47.139
23.129.254.166
23.229.26.231
23.229.36.156
23.229.59.172
23.236.227.181
23.236.247.26
27.79.156.88
31.7.38.186
31.40.203.78
31.40.203.239
31.173.86.91
34.207.107.243
34.231.71.87
35.175.236.99
37.34.88.165
37.34.90.104
37.34.93.238
37.143.62.20
37.143.62.30
37.143.62.115
38.140.46.186
38.153.200.203
38.153.205.181
41.76.242.102
41.207.248.18
41.211.127.77
43.229.11.30
45.11.20.144
45.15.73.148
45.81.137.82
45.84.177.76
45.87.253.149
45.90.196.76
45.127.250.253
45.170.14.44
45.249.106.178
46.8.111.45
46.8.111.203
46.8.156.243
46.138.85.140
47.128.18.67
47.128.52.196
49.12.56.176
50.118.141.12
52.5.174.13
54.152.170.100
54.162.127.149
61.2.25.184
61.147.93.121
65.20.160.61
65.154.226.168
66.165.246.34
69.58.6.4
69.58.78.3
69.160.160.56
82.221.136.1
85.25.237.50
85.203.36.224
85.203.44.229
85.203.44.234
85.239.36.102
89.33.223.18
89.149.24.108
91.225.217.62
92.119.36.59
92.119.36.81
92.119.36.98
94.25.225.56
94.74.89.69
94.158.20.14
94.158.20.151
94.158.190.29
101.44.162.16
101.44.250.35
101.44.250.248
101.44.251.150
102.0.2.220
103.56.19.252
103.74.68.131
103.113.71.230
103.133.68.171
103.187.99.198
103.215.248.156
103.216.59.222
103.225.202.155
103.235.198.46
104.28.157.197
104.28.230.165
104.139.74.25
104.239.7.244
104.249.27.4
104.252.131.107
107.174.232.198
109.230.218.215
109.248.54.87
109.248.204.41
110.42.217.219
110.154.133.64
110.238.109.169
110.249.201.148
110.249.201.155
110.249.202.8
110.249.202.20
110.249.202.152
110.249.202.167
111.88.47.192
111.225.148.48
111.225.148.142
118.194.252.58
119.13.103.43
122.160.112.18
123.13.59.91
124.243.134.87
124.243.135.114
124.243.138.168
124.243.145.41
124.243.148.208
128.201.77.9
129.205.124.169
131.72.68.222
138.128.151.101
138.199.59.44
138.229.98.160
138.255.215.78
139.180.136.106
142.147.111.22
142.147.129.233
149.71.178.24
149.71.182.225
152.44.99.46
154.12.128.234
154.13.102.188
154.21.239.98
154.28.143.109
154.30.194.51
154.30.227.8
154.72.171.9
154.202.101.8
154.202.101.171
154.202.101.236
154.202.120.186
154.202.121.221
156.239.37.177
156.239.38.82
156.239.38.134
156.239.39.106
156.239.48.79
156.239.52.112
156.239.52.254
156.239.62.193
159.138.96.146
159.138.105.133
159.138.110.35
159.223.46.52
163.5.71.235
163.5.138.145
165.231.108.108
166.88.122.107
170.244.133.254
171.245.252.58
172.121.142.104
173.249.0.2
177.93.71.114
178.20.30.235
178.128.208.138
178.140.136.62
178.176.75.123
184.174.30.233
185.45.66.11
185.72.242.215
185.99.175.4
185.181.245.121
185.192.69.186
185.192.69.187
185.192.69.193
185.192.69.204
185.192.70.122
185.199.231.32
185.242.93.213
186.179.100.166
188.130.128.179
188.130.136.152
188.130.137.170
188.130.188.210
188.130.189.193
188.138.17.213
188.138.57.53
190.92.199.19
190.92.215.12
192.154.207.3
192.186.130.155
192.186.160.194
192.198.105.202
192.198.119.52
193.56.252.43
193.203.14.240
193.233.40.30
194.32.120.186
194.32.120.208
194.32.229.160
194.34.248.64
194.34.248.192
194.169.94.78
196.51.207.7
196.57.225.38
196.58.225.20
196.196.23.204
196.196.53.140
196.216.70.214
196.242.70.18
196.243.240.119
198.23.170.169
202.57.210.111
202.79.34.148
202.137.134.214
202.137.154.86
203.78.146.162
203.188.243.98
207.182.28.34
209.242.210.118
209.242.210.176
212.30.33.6
212.30.33.48
212.66.41.121
212.102.35.20
212.102.46.41
212.102.51.249
212.115.49.187
213.207.39.218
216.24.213.56
216.158.139.194
216.173.118.2
216.173.118.4
217.113.194.134
217.113.194.141
217.113.194.190

7466
cleantalk_updated_1d.ipset Normal file

File diff suppressed because it is too large Load Diff

52367
cleantalk_updated_30d.ipset Normal file

File diff suppressed because it is too large Load Diff

22916
cleantalk_updated_7d.ipset Normal file

File diff suppressed because it is too large Load Diff

10464
coinbl_hosts.ipset Normal file

File diff suppressed because it is too large Load Diff

661
coinbl_hosts_browser.ipset Normal file
View File

@ -0,0 +1,661 @@
#
# coinbl_hosts_browser
#
# ipv4 hash:ip ipset
#
# [CoinBlockerLists]
# (https://gitlab.com/ZeroDot1/CoinBlockerLists) Simple lists
# that can help prevent cryptomining in the browser or other
# applications. A hosts list to prevent browser mining only.
# The maintainer's file contains hostnames, which have been
# DNS resolved to IP addresses.
#
# Maintainer : CoinBlockerLists
# Maintainer URL : https://gitlab.com/ZeroDot1/CoinBlockerLists
# List source URL : https://zerodot1.gitlab.io/CoinBlockerLists/hosts_browser
# Source File Date: Mon Mar 4 10:58:09 UTC 2024
#
# Category : organizations
# Version : 53
#
# This File Date : Mon Mar 4 20:32:08 UTC 2024
# Update Frequency: 1 day
# Aggregation : none
# Entries : 627 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=coinbl_hosts_browser
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
3.5.3.185
3.5.20.209
3.18.7.81
3.19.116.195
3.20.137.44
3.33.130.190
3.33.152.147
3.33.243.145
3.64.163.50
3.70.101.28
3.72.140.173
3.130.204.160
3.130.253.23
3.140.13.188
3.141.96.53
3.209.172.72
3.210.192.5
3.216.88.24
3.219.96.23
3.229.186.102
5.35.170.72
5.79.79.211
5.135.131.112
5.206.224.162
5.252.178.30
13.32.99.92
13.32.172.43
13.32.172.77
13.32.172.85
13.32.172.122
13.39.145.251
13.58.215.234
13.224.222.15
13.224.222.25
13.224.222.33
13.224.222.109
13.224.227.45
13.224.227.87
13.224.227.131
13.224.227.205
13.248.148.254
13.248.169.48
13.248.213.45
15.188.219.54
15.197.142.173
15.197.148.33
15.197.192.55
15.197.204.56
18.119.154.66
18.192.94.96
18.192.231.252
18.193.115.229
18.208.60.216
18.211.231.38
18.220.2.62
18.233.173.50
18.244.115.31
18.244.115.84
18.244.115.91
18.244.115.150
23.22.52.7
23.22.130.173
23.22.144.165
23.82.12.30
23.88.53.29
23.101.76.219
23.236.55.104
23.239.5.88
31.11.36.28
31.31.196.245
34.128.82.12
34.203.33.230
34.241.115.67
34.249.160.71
35.156.224.161
35.157.241.235
35.181.89.222
35.184.126.39
35.186.223.180
35.187.160.226
35.192.89.115
35.197.8.113
35.198.107.58
35.199.54.100
35.229.196.203
35.231.101.114
37.48.65.136
37.48.65.144
37.48.65.149
37.48.65.150
37.48.65.151
37.48.65.152
37.48.65.155
37.48.76.140
37.221.212.115
38.48.131.173
44.196.193.227
44.227.65.245
44.227.76.166
45.33.2.79
45.33.18.44
45.33.20.235
45.33.23.183
45.33.28.34
45.33.30.197
45.33.110.230
45.56.79.23
45.56.81.204
45.58.190.82
45.79.0.55
45.79.19.196
45.79.70.13
45.79.73.145
45.79.81.15
45.79.81.196
45.79.97.218
45.79.130.66
45.79.163.250
45.79.199.14
45.79.203.37
45.79.218.212
45.126.210.34
46.4.34.174
46.8.8.100
46.8.8.200
46.38.243.234
46.105.88.234
47.254.33.193
49.212.235.29
50.28.56.190
50.116.24.178
51.75.146.174
51.91.14.108
51.138.9.198
52.5.82.174
52.20.84.62
52.29.9.68
52.57.47.41
52.57.140.222
52.58.3.82
52.58.78.16
52.58.254.253
52.59.100.80
52.59.171.33
52.59.174.115
52.71.57.184
52.216.217.185
52.217.13.124
52.217.133.177
52.217.207.41
54.36.108.36
54.36.108.37
54.36.108.38
54.36.108.39
54.36.168.61
54.36.168.211
54.36.168.213
54.36.175.162
54.36.175.163
54.37.83.70
54.37.84.221
54.37.206.58
54.38.33.16
54.38.192.132
54.38.192.133
54.38.226.140
54.39.52.205
54.39.243.181
54.67.42.145
54.78.134.111
54.83.6.65
54.146.248.82
54.159.116.102
54.165.58.209
54.205.8.205
54.205.31.215
54.209.32.212
54.228.42.199
54.231.162.89
54.231.171.49
54.235.77.118
54.243.238.66
62.138.18.13
64.32.22.102
64.70.19.203
64.91.248.15
64.91.248.18
64.91.249.20
64.190.63.222
64.225.91.73
65.21.140.250
65.21.240.245
66.254.114.211
69.16.230.42
69.16.230.227
69.85.85.20
69.162.95.2
70.32.1.32
70.39.125.243
72.14.178.174
72.14.185.43
72.52.179.174
74.63.241.21
74.207.247.136
75.2.37.224
76.76.21.9
76.76.21.22
76.76.21.61
76.76.21.93
76.76.21.98
76.76.21.123
76.76.21.142
76.76.21.164
76.76.21.241
76.223.26.96
76.223.54.146
76.223.67.189
77.247.182.242
78.46.5.205
78.47.161.84
80.209.230.221
81.171.8.143
81.171.28.43
82.180.157.75
82.192.82.226
83.242.236.76
84.22.115.32
84.32.84.33
84.255.242.136
85.17.26.67
86.105.245.69
87.236.16.207
88.80.191.137
88.86.123.38
88.191.185.113
89.46.102.6
89.58.14.251
89.58.15.35
89.58.15.169
89.252.133.125
91.193.180.124
91.195.240.12
91.195.240.19
91.195.240.123
91.239.200.44
92.222.94.129
93.115.28.104
93.190.139.217
94.23.29.144
94.23.161.19
94.130.138.161
94.229.72.122
94.237.99.118
94.237.103.119
95.168.216.7
95.168.216.9
95.216.77.205
95.216.161.60
95.217.57.182
96.45.82.32
96.45.82.215
96.45.83.19
96.45.83.223
96.126.123.244
100.38.9.220
103.224.182.240
103.224.182.250
103.224.182.253
103.224.212.210
103.224.212.211
103.224.212.213
103.224.212.214
103.224.212.215
103.224.212.216
103.224.212.217
104.16.164.101
104.17.151.12
104.21.3.251
104.21.5.136
104.21.6.144
104.21.14.18
104.21.25.12
104.21.25.70
104.21.25.184
104.21.25.228
104.21.27.195
104.21.28.242
104.21.30.41
104.21.30.115
104.21.32.63
104.21.33.141
104.21.33.168
104.21.34.227
104.21.38.104
104.21.38.218
104.21.39.74
104.21.39.244
104.21.44.248
104.21.45.44
104.21.46.157
104.21.46.191
104.21.48.22
104.21.48.175
104.21.51.238
104.21.53.92
104.21.56.113
104.21.57.121
104.21.57.186
104.21.58.10
104.21.58.197
104.21.59.245
104.21.60.32
104.21.61.200
104.21.63.111
104.21.66.19
104.21.66.49
104.21.66.61
104.21.70.6
104.21.72.157
104.21.75.140
104.21.76.5
104.21.81.117
104.21.82.45
104.21.83.69
104.21.85.170
104.21.86.88
104.21.86.114
104.21.86.228
104.21.88.26
104.21.92.20
104.21.92.27
104.21.92.144
104.21.93.72
104.21.233.213
104.21.233.214
104.22.56.80
104.22.57.80
104.26.0.139
104.26.1.139
104.26.4.31
104.26.5.31
104.31.16.1
104.155.138.21
104.198.14.52
104.198.108.234
104.238.249.57
104.248.84.141
107.6.169.59
107.22.57.98
107.161.23.204
107.178.223.183
108.58.121.94
108.198.190.75
109.123.254.50
116.202.9.166
116.202.21.136
116.203.213.72
127.0.0.1
127.0.0.2
130.211.161.97
134.122.109.150
134.122.174.133
136.243.80.170
138.68.36.34
138.68.67.193
138.68.71.37
138.68.112.220
138.201.35.59
138.201.83.215
139.45.197.250
139.45.197.251
139.99.121.222
139.162.223.125
141.94.96.71
141.94.96.144
141.94.96.195
141.95.72.59
141.95.72.60
141.95.72.61
141.95.206.77
142.44.138.161
142.132.202.70
142.250.200.33
143.204.192.134
143.204.192.161
143.204.192.166
143.204.192.225
143.244.42.32
144.76.35.207
145.239.0.218
145.239.7.163
145.239.70.127
145.239.70.128
145.239.70.129
145.239.141.5
145.239.206.122
145.239.244.5
145.239.244.9
145.239.244.13
145.239.244.74
145.239.253.103
145.239.253.125
146.59.26.8
146.148.34.125
147.135.253.210
148.251.139.94
148.251.178.132
149.56.19.3
149.56.19.43
149.56.20.201
149.56.89.160
149.102.143.109
149.202.83.240
149.202.84.228
154.41.237.70
154.222.233.225
156.224.207.148
156.232.219.34
157.90.144.85
157.230.168.89
157.245.174.176
159.69.42.212
159.69.83.207
159.69.112.37
159.69.152.150
159.69.186.9
162.19.139.184
162.55.172.212
162.240.48.238
162.254.207.52
162.255.119.213
163.172.103.102
164.132.95.123
165.22.209.237
165.232.114.226
168.119.141.228
168.119.185.228
168.119.245.137
168.235.88.209
169.47.130.72
170.39.226.155
170.178.183.18
172.66.41.13
172.66.42.243
172.67.5.10
172.67.68.60
172.67.71.15
172.67.131.100
172.67.133.127
172.67.133.197
172.67.134.118
172.67.134.218
172.67.137.109
172.67.139.83
172.67.140.108
172.67.141.144
172.67.143.168
172.67.145.100
172.67.145.205
172.67.147.232
172.67.150.137
172.67.152.116
172.67.153.103
172.67.153.223
172.67.155.39
172.67.155.78
172.67.159.208
172.67.165.9
172.67.165.117
172.67.165.240
172.67.169.161
172.67.171.251
172.67.172.43
172.67.172.224
172.67.176.30
172.67.177.121
172.67.184.61
172.67.184.200
172.67.184.223
172.67.184.252
172.67.185.87
172.67.186.72
172.67.187.107
172.67.190.93
172.67.191.29
172.67.191.181
172.67.195.50
172.67.201.29
172.67.201.133
172.67.202.6
172.67.206.103
172.67.206.152
172.67.207.56
172.67.208.133
172.67.209.176
172.67.211.53
172.67.214.70
172.67.216.92
172.67.217.49
172.67.217.69
172.67.218.149
172.67.221.141
172.67.221.252
172.98.192.36
172.104.11.229
172.104.21.26
172.104.153.105
172.105.77.223
172.217.16.244
172.234.25.151
173.44.37.208
173.176.230.167
173.255.194.134
173.255.253.174
174.129.128.48
176.9.147.178
178.32.111.67
178.63.8.69
178.79.150.219
178.79.180.12
185.39.18.98
185.53.177.13
185.53.177.31
185.53.177.51
185.53.177.52
185.53.177.53
185.53.177.54
185.53.178.50
185.53.178.51
185.53.178.52
185.107.56.54
185.107.56.194
185.107.56.199
185.107.56.200
185.166.141.7
185.166.141.8
185.166.141.9
185.173.160.140
185.173.160.141
185.199.108.153
185.199.109.153
185.199.110.153
185.199.111.153
185.240.242.35
188.40.2.4
188.40.87.121
188.165.1.80
188.165.36.206
188.165.223.152
190.2.139.23
192.64.119.58
192.134.5.38
192.169.69.26
192.171.18.197
192.185.4.93
193.29.105.150
193.77.224.191
193.238.27.24
194.58.112.174
194.190.130.86
195.20.43.36
195.20.43.198
195.20.44.138
195.20.46.118
195.20.47.173
195.20.49.172
195.20.50.170
195.20.51.116
195.20.55.30
195.154.222.63
195.154.243.212
195.161.41.222
195.181.172.26
195.201.74.132
195.201.83.239
195.201.105.119
195.201.124.255
195.201.162.230
195.201.162.231
198.58.118.167
198.58.126.31
198.251.81.30
198.251.84.49
198.251.84.92
199.59.243.225
202.61.204.169
202.61.225.215
204.11.56.48
204.16.169.54
204.145.90.53
204.188.203.154
207.60.41.68
207.148.248.143
208.80.122.40
208.80.122.139
208.80.123.4
208.80.123.142
208.100.26.250
208.116.56.2
209.17.116.160
209.42.197.18
209.97.140.241
209.126.123.11
209.141.38.71
212.32.237.90
212.32.237.92
212.32.237.101
212.32.255.4
212.32.255.5
212.32.255.6
212.32.255.12
212.32.255.13
212.32.255.72
212.32.255.137
212.32.255.139
212.32.255.141
212.32.255.148
212.32.255.198
212.32.255.212
212.83.168.39
212.129.44.155
212.129.44.156
212.129.44.157
213.186.33.5
216.155.158.140
216.189.56.129
217.160.0.82

506
coinbl_hosts_optional.ipset Normal file
View File

@ -0,0 +1,506 @@
#
# coinbl_hosts_optional
#
# ipv4 hash:ip ipset
#
# [CoinBlockerLists]
# (https://gitlab.com/ZeroDot1/CoinBlockerLists) Simple lists
# that can help prevent cryptomining in the browser or other
# applications. This list contains additional domains, for
# administrators to prevent mining in networks. The
# maintainer's file contains hostnames, which have been DNS
# resolved to IP addresses.
#
# Maintainer : CoinBlockerLists
# Maintainer URL : https://gitlab.com/ZeroDot1/CoinBlockerLists
# List source URL : https://zerodot1.gitlab.io/CoinBlockerLists/hosts_optional
# Source File Date: Mon Mar 4 10:58:09 UTC 2024
#
# Category : organizations
# Version : 35
#
# This File Date : Mon Mar 4 20:31:55 UTC 2024
# Update Frequency: 1 day
# Aggregation : none
# Entries : 471 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=coinbl_hosts_optional
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
2.16.128.122
2.16.128.202
2.18.66.120
2.18.66.138
2.19.117.68
2.19.117.69
2.19.117.70
2.19.117.72
2.19.117.74
2.19.117.78
2.19.117.81
2.19.117.90
2.19.117.94
2.19.117.96
2.19.117.99
2.19.117.104
2.19.117.106
2.22.156.233
3.20.137.44
3.33.130.190
3.33.152.147
3.35.88.113
3.36.156.26
3.93.123.68
3.94.41.167
3.140.13.188
3.141.96.53
3.209.224.13
3.210.221.105
3.212.210.237
3.218.85.198
3.225.137.152
3.234.186.113
4.194.208.209
13.112.244.197
13.114.246.229
13.115.46.163
13.224.135.12
13.224.222.2
13.224.222.10
13.224.222.42
13.224.222.78
13.224.222.79
13.224.222.84
13.224.222.96
13.224.222.122
13.224.245.2
13.224.245.42
13.224.245.64
13.224.245.70
13.224.245.71
13.224.245.77
13.224.245.84
13.224.245.96
13.229.36.104
13.248.169.48
13.248.213.45
15.197.142.173
15.197.148.33
18.119.154.66
18.164.68.16
18.164.68.23
18.164.68.38
18.164.68.91
18.165.201.11
18.165.201.86
18.165.201.91
18.165.201.123
18.165.227.9
18.165.227.10
18.165.227.13
18.165.227.33
18.165.227.34
18.165.227.38
18.165.227.91
18.165.227.117
18.172.153.36
18.172.153.38
18.172.153.48
18.172.153.83
18.178.24.173
18.178.240.248
18.204.200.228
18.239.236.9
18.239.236.12
18.239.236.18
18.239.236.21
18.239.236.50
18.239.236.54
18.239.236.115
18.239.236.129
18.245.218.59
18.245.218.83
18.245.218.89
18.245.218.102
23.44.64.218
23.227.38.74
34.102.239.211
34.193.227.67
34.203.99.107
34.205.242.146
34.225.59.56
34.236.52.129
34.244.67.113
34.245.84.181
34.252.240.199
35.72.42.247
35.73.106.176
35.76.35.125
35.76.35.223
35.168.141.127
35.172.157.117
35.173.176.69
35.176.92.19
35.176.92.20
35.176.92.21
35.194.162.135
35.234.28.23
35.234.86.61
35.236.135.177
37.48.65.136
43.206.57.92
44.193.54.110
44.205.223.88
44.207.20.63
44.210.169.104
45.162.168.175
47.91.167.174
49.50.108.72
49.50.108.73
52.1.179.177
52.3.130.236
52.18.13.109
52.21.111.192
52.22.200.146
52.23.22.9
52.44.138.87
52.45.205.8
52.48.160.204
52.68.7.163
52.71.57.184
52.71.91.166
52.84.150.36
52.84.150.48
52.84.150.52
52.84.150.65
52.86.6.113
52.92.1.28
52.92.2.148
52.92.16.36
52.92.19.164
52.92.35.44
52.97.146.184
52.97.211.216
52.97.211.248
52.97.219.248
52.98.207.40
52.98.207.168
52.98.207.184
52.98.227.104
52.193.113.187
52.195.45.65
52.196.250.127
52.203.29.35
52.207.181.104
52.213.196.130
52.218.36.68
52.218.96.252
52.218.108.100
52.219.8.167
52.219.16.148
52.219.68.196
52.219.136.4
52.219.150.159
52.219.152.67
52.219.152.115
52.219.200.35
54.64.215.50
54.77.119.238
54.89.42.45
54.89.43.13
54.156.9.35
54.157.239.184
54.161.222.85
54.173.84.248
54.178.166.59
54.209.32.212
54.238.90.11
57.181.12.48
58.228.236.210
58.228.236.211
58.228.236.212
58.228.236.213
58.228.236.214
58.228.236.215
63.33.16.125
64.91.248.15
66.22.39.88
66.23.195.156
66.235.200.146
72.14.191.28
74.220.199.8
76.76.21.9
76.76.21.21
76.76.21.22
76.76.21.61
76.76.21.98
76.76.21.123
76.76.21.142
76.76.21.164
76.76.21.241
76.223.54.146
76.223.67.189
78.46.32.91
79.125.84.18
82.192.82.228
88.198.54.148
91.195.241.232
94.23.50.33
99.84.9.22
99.84.9.36
99.84.9.38
99.84.9.44
99.84.9.51
99.84.9.57
99.84.9.59
99.84.9.71
99.84.9.96
99.84.9.98
99.84.9.110
103.224.212.213
104.16.51.111
104.16.53.111
104.16.145.58
104.16.146.58
104.16.155.13
104.16.156.13
104.16.157.13
104.16.158.13
104.16.159.13
104.16.214.13
104.16.241.118
104.16.242.118
104.16.247.71
104.16.248.71
104.17.70.206
104.17.71.206
104.17.72.206
104.17.73.206
104.17.74.206
104.17.86.98
104.17.97.53
104.18.18.23
104.18.19.23
104.18.32.222
104.18.33.123
104.18.35.15
104.18.36.178
104.18.37.73
104.18.37.145
104.18.38.60
104.18.39.123
104.18.39.184
104.18.40.248
104.18.42.136
104.18.42.203
104.18.82.103
104.18.172.197
104.18.173.197
104.18.174.197
104.18.175.197
104.18.176.197
104.20.0.37
104.20.1.37
104.20.80.175
104.20.81.175
104.21.1.165
104.21.12.149
104.21.13.111
104.21.40.202
104.21.48.5
104.21.49.161
104.21.53.208
104.21.54.180
104.21.58.139
104.21.58.197
104.21.68.9
104.21.74.183
104.21.75.130
104.21.78.247
104.21.85.183
104.21.88.73
104.21.89.253
104.21.91.134
104.21.91.204
104.21.94.110
104.21.96.110
104.22.10.221
104.22.11.221
104.22.28.145
104.22.29.145
104.22.68.176
104.22.69.176
104.22.78.220
104.22.79.220
104.26.2.224
104.26.2.240
104.26.3.224
104.26.3.240
104.26.4.159
104.26.5.159
104.26.6.20
104.26.7.20
104.26.8.106
104.26.9.106
104.26.10.219
104.26.11.219
104.26.12.88
104.26.12.198
104.26.13.88
104.26.13.198
104.26.14.247
104.26.15.247
104.128.239.75
104.199.134.19
104.248.121.107
107.21.169.51
107.180.124.16
108.156.39.12
108.156.39.21
108.156.39.31
108.156.39.44
108.156.39.68
108.156.39.79
108.156.39.86
108.156.39.88
108.156.39.89
108.156.39.116
108.156.39.128
109.109.135.110
110.10.90.180
116.203.46.114
116.203.78.40
121.242.224.82
121.242.224.83
121.242.224.84
121.242.224.85
121.242.224.86
121.242.224.87
121.242.224.88
121.242.224.89
121.242.224.90
121.242.224.91
134.122.6.5
138.113.149.153
143.204.68.8
143.204.68.21
143.204.68.31
143.204.68.47
143.204.68.69
143.204.68.97
143.204.68.99
143.204.68.104
143.204.68.110
143.204.68.115
143.204.68.124
143.204.68.128
143.204.191.51
143.204.191.79
143.204.191.120
143.204.191.127
143.244.42.33
145.14.145.245
162.214.217.188
162.241.194.182
162.241.218.88
163.171.146.42
167.89.115.56
167.89.115.120
167.89.115.150
167.89.123.54
167.89.123.124
167.89.123.204
167.114.97.165
172.64.145.53
172.64.145.120
172.64.147.8
172.64.148.72
172.64.148.133
172.64.149.196
172.64.150.111
172.64.150.183
172.64.151.78
172.64.152.241
172.64.154.133
172.64.155.34
172.66.40.231
172.66.43.25
172.67.14.95
172.67.21.61
172.67.25.63
172.67.33.208
172.67.40.154
172.67.68.82
172.67.69.167
172.67.70.52
172.67.70.65
172.67.72.162
172.67.73.73
172.67.73.151
172.67.75.36
172.67.75.45
172.67.129.162
172.67.138.225
172.67.141.5
172.67.150.125
172.67.155.224
172.67.157.5
172.67.161.56
172.67.164.245
172.67.174.6
172.67.175.39
172.67.177.24
172.67.177.70
172.67.179.87
172.67.184.32
172.67.194.235
172.67.204.125
172.67.207.56
172.67.208.227
172.67.218.212
172.67.220.84
172.67.222.187
172.104.233.20
176.34.2.176
178.62.70.245
178.63.62.94
185.26.156.18
185.85.241.244
185.178.208.185
185.199.108.153
185.199.109.153
185.199.110.153
185.199.111.153
185.225.115.110
190.210.186.207
192.3.11.20
192.64.119.92
192.99.12.221
192.124.249.52
192.185.5.105
192.243.100.192
192.254.232.90
193.70.122.58
193.160.66.104
194.36.191.196
195.39.222.84
195.181.172.27
198.23.50.77
198.37.155.136
198.245.62.172
199.16.172.126
199.48.210.115
199.127.61.148
206.189.144.244
208.87.98.37
216.58.204.83
216.137.44.31
216.137.44.56
216.137.44.58
216.137.44.119

1425
coinbl_ips.ipset Normal file

File diff suppressed because it is too large Load Diff

13909
cruzit_web_attacks.ipset Normal file

File diff suppressed because it is too large Load Diff

1396
cta_cryptowall.ipset Normal file

File diff suppressed because it is too large Load Diff

1284
cybercrime.ipset Normal file

File diff suppressed because it is too large Load Diff

6038
darklist_de.netset Normal file

File diff suppressed because it is too large Load Diff

4257
datacenters.netset Normal file

File diff suppressed because it is too large Load Diff

5879
dm_tor.ipset Normal file

File diff suppressed because it is too large Load Diff

49
dshield.netset Normal file
View File

@ -0,0 +1,49 @@
#
# dshield
#
# ipv4 hash:net ipset
#
# [DShield.org] (https://dshield.org/) top 20 attacking class
# C (/24) subnets over the last three days
#
# Maintainer : DShield.org
# Maintainer URL : https://dshield.org/
# List source URL : http://feeds.dshield.org/block.txt
# Source File Date: Mon Dec 5 16:00:11 UTC 2022
#
# Category : attacks
# Version : 8476
#
# This File Date : Mon Dec 5 16:28:02 UTC 2022
# Update Frequency: 10 mins
# Aggregation : none
# Entries : 19 subnets, 5120 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=dshield
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
5.188.206.0/24
45.95.146.0/24
45.142.192.0/24
45.143.200.0/24
62.204.41.0/24
62.233.50.0/24
64.62.197.0/24
78.128.113.0/24
87.246.7.0/24
89.248.163.0/24
89.248.165.0/24
91.191.209.0/24
92.63.196.0/23
94.102.61.0/24
146.88.240.0/24
173.214.175.0/24
185.81.68.0/24
185.156.73.0/24
193.163.125.0/24

51
dshield_1d.netset Normal file
View File

@ -0,0 +1,51 @@
#
# dshield_1d
#
# ipv4 hash:net ipset
#
# [DShield.org] (https://dshield.org/) top 20 attacking class
# C (/24) subnets over the last three days
#
# Maintainer : DShield.org
# Maintainer URL : https://dshield.org/
# List source URL : http://feeds.dshield.org/block.txt
# Source File Date: Mon Dec 5 15:00:12 UTC 2022
#
# Category : attacks
# Version : 7698
#
# This File Date : Mon Dec 5 15:20:02 UTC 2022
# Update Frequency: 10 mins
# Aggregation : 1 day
# Entries : 21 subnets, 5632 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=dshield_1d
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
5.188.206.0/24
45.95.146.0/24
45.142.192.0/24
45.143.200.0/24
62.204.41.0/24
62.233.50.0/24
64.62.197.0/24
78.128.113.0/24
80.82.77.0/24
87.246.7.0/24
89.248.163.0/24
89.248.165.0/24
91.191.209.0/24
92.63.196.0/23
94.102.61.0/24
146.88.240.0/24
173.214.175.0/24
185.81.68.0/24
185.156.73.0/24
192.241.212.0/24
193.163.125.0/24

72
dshield_30d.netset Normal file
View File

@ -0,0 +1,72 @@
#
# dshield_30d
#
# ipv4 hash:net ipset
#
# [DShield.org] (https://dshield.org/) top 20 attacking class
# C (/24) subnets over the last three days
#
# Maintainer : DShield.org
# Maintainer URL : https://dshield.org/
# List source URL : http://feeds.dshield.org/block.txt
# Source File Date: Sun Dec 4 13:40:03 UTC 2022
#
# Category : attacks
# Version : 2569
#
# This File Date : Sun Dec 4 14:00:03 UTC 2022
# Update Frequency: 10 mins
# Aggregation : 30 days
# Entries : 42 subnets, 11776 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=dshield_30d
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
2.57.122.0/24
5.8.18.0/24
5.188.206.0/24
45.95.146.0/23
45.142.192.0/24
45.143.200.0/24
45.143.203.0/24
62.204.41.0/24
62.233.50.0/24
64.62.197.0/24
78.128.112.0/23
80.82.77.0/24
87.246.7.0/24
89.190.156.0/24
89.248.163.0/24
89.248.165.0/24
91.191.209.0/24
91.240.118.0/24
92.63.196.0/23
92.118.39.0/24
94.102.61.0/24
104.156.155.0/24
109.205.213.0/24
138.99.216.0/24
141.255.166.0/24
146.88.240.0/24
154.89.5.0/24
173.214.175.0/24
185.81.68.0/24
185.156.73.0/24
185.196.220.0/24
185.224.128.0/24
192.241.197.0/24
192.241.205.0/24
192.241.206.0/23
192.241.212.0/24
193.56.146.0/24
193.163.125.0/24
194.26.29.0/24
198.235.24.0/24
205.210.31.0/24
213.226.123.0/24

59
dshield_7d.netset Normal file
View File

@ -0,0 +1,59 @@
#
# dshield_7d
#
# ipv4 hash:net ipset
#
# [DShield.org] (https://dshield.org/) top 20 attacking class
# C (/24) subnets over the last three days
#
# Maintainer : DShield.org
# Maintainer URL : https://dshield.org/
# List source URL : http://feeds.dshield.org/block.txt
# Source File Date: Mon Dec 5 15:00:12 UTC 2022
#
# Category : attacks
# Version : 4179
#
# This File Date : Mon Dec 5 15:20:02 UTC 2022
# Update Frequency: 10 mins
# Aggregation : 7 days
# Entries : 29 subnets, 7936 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=dshield_7d
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
2.57.122.0/24
5.8.18.0/24
5.188.206.0/24
45.95.146.0/24
45.142.192.0/24
45.143.200.0/24
62.204.41.0/24
62.233.50.0/24
64.62.197.0/24
78.128.112.0/23
80.82.77.0/24
87.246.7.0/24
89.248.163.0/24
89.248.165.0/24
91.191.209.0/24
92.63.196.0/23
92.118.39.0/24
94.102.61.0/24
104.156.155.0/24
146.88.240.0/24
154.89.5.0/24
173.214.175.0/24
185.81.68.0/24
185.156.73.0/24
185.224.128.0/24
192.241.212.0/24
193.163.125.0/24
198.235.24.0/24
205.210.31.0/24

1030
dshield_top_1000.ipset Normal file

File diff suppressed because it is too large Load Diff

78
dyndns_ponmocup.ipset Normal file
View File

@ -0,0 +1,78 @@
#
# dyndns_ponmocup
#
# ipv4 hash:ip ipset
#
# [DynDNS.org]
# (http://security-research.dyndns.org/pub/malware-feeds/)
# Ponmocup. The malware powering the botnet has been around
# since 2006 and its known under various names, including
# Ponmocup, Vundo, Virtumonde, Milicenso and Swisyn. It has
# been used for ad fraud, data theft and downloading
# additional threats to infected systems. Ponmocup is one of
# the largest currently active and, with nine consecutive
# years, also one of the longest running, but it is rarely
# noticed as the operators take care to keep it operating
# under the radar.
#
# Maintainer : DynDNS.org
# Maintainer URL : http://security-research.dyndns.org/pub/malware-feeds/
# List source URL : http://security-research.dyndns.org/pub/malware-feeds/ponmocup-infected-domains-shadowserver.csv
# Source File Date: Tue Apr 16 19:28:10 UTC 2024
#
# Category : malware
# Version : 2039
#
# This File Date : Tue Apr 16 19:40:35 UTC 2024
# Update Frequency: 1 day
# Aggregation : none
# Entries : 39 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=dyndns_ponmocup
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
3.18.7.81
3.130.204.160
3.140.13.188
18.119.154.66
31.11.36.8
45.251.240.114
54.153.111.129
54.161.222.85
64.70.19.52
66.96.149.32
69.30.245.146
69.61.26.162
72.167.78.221
72.172.132.43
74.208.236.193
74.208.236.248
78.47.71.170
79.124.76.10
82.118.24.217
85.13.140.101
94.130.190.96
94.152.142.140
104.21.11.31
122.201.84.241
144.76.45.43
162.255.166.188
173.209.47.104
173.254.30.178
192.99.161.26
199.67.250.59
200.170.151.200
203.174.34.49
206.188.193.120
213.186.33.18
213.186.33.19
217.76.132.246
217.160.0.152
217.160.0.225
217.160.0.240

608
esentire_14072015_com.ipset Normal file
View File

@ -0,0 +1,608 @@
#
# esentire_14072015_com
#
# ipv4 hash:ip ipset
#
# Malicious Botnet Serving Various Malware Families
#
# Maintainer : eSentire
# Maintainer URL : https://github.com/eSentire/malfeed
# List source URL : https://raw.githubusercontent.com/eSentire/malfeed/master/14072015.com_watch_ip.lst
# Source File Date: Wed Jun 6 11:52:14 UTC 2018
#
# Category : malware
# Version : 6
#
# This File Date : Thu Jun 7 00:08:50 UTC 2018
# Update Frequency: 1 day
# Aggregation : none
# Entries : 579 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=esentire_14072015_com
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.175.3.90
2.133.85.150
5.1.2.227
5.56.25.29
5.105.50.179
5.105.52.34
5.105.130.241
5.140.106.180
5.143.150.71
5.149.216.46
5.248.99.180
5.248.124.161
5.248.140.201
5.248.141.34
5.248.144.87
5.248.165.65
5.248.194.148
5.248.196.203
5.248.254.4
10.1.120.31
10.1.120.34
23.243.180.132
24.193.190.169
24.214.18.167
31.41.116.88
31.43.4.212
31.43.28.113
31.43.61.73
31.43.82.41
31.43.102.34
31.43.132.156
31.128.74.100
31.128.104.215
31.129.94.180
31.129.95.173
31.129.109.172
31.129.110.6
31.131.101.222
31.131.108.202
31.131.115.55
31.133.66.75
31.133.68.81
31.135.130.27
31.170.130.120
31.170.152.131
31.170.178.179
31.202.176.54
31.207.167.5
36.237.101.56
37.1.58.55
37.25.119.138
37.25.123.252
37.25.126.4
37.54.161.154
37.57.27.184
37.57.37.69
37.57.240.152
37.57.246.121
37.115.15.172
37.115.20.149
37.115.93.155
37.139.165.201
37.143.88.42
37.221.142.213
37.229.13.98
37.229.24.30
46.33.225.80
46.37.197.144
46.46.79.62
46.46.90.65
46.46.96.199
46.63.35.252
46.63.59.44
46.98.1.8
46.98.75.118
46.98.78.188
46.98.97.89
46.98.97.130
46.98.100.46
46.98.113.153
46.98.132.170
46.98.152.107
46.98.203.70
46.98.204.117
46.98.204.188
46.98.213.95
46.98.220.186
46.98.247.222
46.98.254.210
46.118.23.179
46.118.51.117
46.118.54.10
46.118.69.177
46.118.81.195
46.118.84.37
46.118.147.106
46.118.149.108
46.118.158.172
46.118.178.113
46.118.253.204
46.119.0.170
46.119.11.137
46.119.16.18
46.119.17.234
46.119.76.220
46.119.105.213
46.119.173.111
46.119.179.81
46.119.195.170
46.119.209.176
46.146.132.76
46.148.180.102
46.150.8.215
46.150.91.176
46.151.248.27
46.151.253.25
46.160.99.66
46.160.113.116
46.164.188.85
46.172.192.160
46.172.209.208
46.172.212.54
46.173.77.180
46.173.84.239
46.174.240.33
46.174.246.197
46.175.77.227
46.175.137.124
46.185.81.27
46.185.107.224
46.200.44.135
46.201.77.153
46.211.18.203
46.211.27.11
46.211.28.176
46.211.53.116
46.211.74.218
46.211.88.32
46.211.195.139
46.211.217.205
46.211.235.48
46.211.235.195
46.211.238.141
46.250.4.228
46.250.15.111
46.250.17.227
46.250.120.231
54.83.4.26
54.235.166.93
62.16.38.131
62.84.253.186
62.122.93.147
69.84.107.186
70.51.44.188
71.3.191.208
71.61.172.133
71.182.234.109
71.226.78.56
72.53.89.52
73.36.213.39
73.128.180.27
73.172.10.82
74.134.99.228
77.89.226.21
77.91.184.71
77.109.58.50
77.109.58.246
77.120.153.195
77.120.155.24
77.121.59.193
77.121.83.134
77.121.172.23
77.121.186.193
77.121.214.247
77.121.248.109
77.121.248.142
77.122.27.116
77.122.48.50
77.122.50.141
77.122.117.112
77.122.121.122
77.122.150.135
77.122.153.68
77.122.184.9
77.122.184.233
77.122.225.133
77.122.225.173
77.122.232.43
77.123.33.194
77.123.73.204
77.123.222.54
77.247.21.163
77.247.23.79
78.30.226.103
78.111.243.83
78.137.16.80
78.137.21.217
78.137.42.84
78.137.45.30
78.137.45.113
78.162.208.223
78.169.94.241
79.112.62.143
79.113.160.90
79.132.3.138
79.135.222.84
79.142.207.184
79.171.124.211
80.245.117.198
80.252.249.153
80.252.250.121
80.252.253.160
81.9.24.250
81.22.139.55
81.22.141.34
83.99.245.186
83.167.28.121
83.218.228.46
85.114.216.12
85.198.166.158
85.237.34.129
85.238.101.24
86.125.251.15
87.76.36.212
87.76.53.178
87.76.57.222
87.110.28.220
87.244.34.238
88.135.94.164
88.135.238.111
88.135.251.129
88.156.84.155
88.222.173.33
89.65.63.95
89.66.136.116
89.185.15.235
89.185.21.82
89.185.29.54
91.124.201.223
91.196.81.167
91.198.143.44
91.201.71.41
91.202.133.86
91.209.96.67
91.215.55.41
91.218.74.89
91.219.199.248
91.221.29.181
91.224.253.6
91.225.57.30
91.229.54.147
91.237.14.8
91.243.200.132
91.244.8.216
91.244.24.5
91.244.29.60
91.244.36.90
91.244.37.3
92.52.177.95
92.52.186.215
92.112.58.245
92.113.69.127
92.243.113.105
92.244.103.244
92.244.116.165
92.249.119.9
93.76.66.62
93.76.104.167
93.76.104.241
93.76.164.173
93.77.104.109
93.77.204.131
93.77.220.9
93.78.19.128
93.78.67.85
93.78.163.201
93.78.181.144
93.79.34.155
93.79.111.83
93.79.168.251
93.79.241.161
93.114.246.153
93.118.90.170
93.118.202.150
93.127.3.177
93.127.16.170
93.127.119.6
93.170.50.15
93.170.50.91
93.170.51.47
93.170.152.201
93.170.153.170
93.170.155.207
93.181.197.194
93.181.211.186
93.183.243.116
93.185.211.46
94.45.73.242
94.45.92.6
94.45.140.60
94.76.65.93
94.76.121.245
94.76.127.113
94.154.35.51
94.158.43.155
94.178.84.198
94.178.129.75
94.178.230.215
94.181.80.232
94.181.160.141
94.231.70.97
94.231.71.95
94.231.184.85
94.232.76.137
94.232.78.220
94.244.48.229
94.244.141.40
95.47.28.117
95.47.128.209
95.57.228.161
95.67.46.154
95.67.75.154
95.77.219.240
95.81.247.208
95.87.84.203
95.105.11.115
95.105.249.36
95.132.207.171
95.134.158.152
95.135.17.8
95.135.69.19
95.135.213.151
95.164.40.91
95.173.33.100
95.215.118.45
97.75.107.134
98.27.145.224
100.3.73.52
100.6.61.161
104.162.93.136
107.4.129.77
107.15.99.91
108.29.104.102
108.54.179.254
109.72.120.184
109.86.147.39
109.86.206.111
109.86.210.227
109.86.230.210
109.86.234.51
109.87.3.16
109.87.68.203
109.87.120.8
109.87.165.28
109.87.187.170
109.87.205.126
109.87.209.171
109.87.249.48
109.104.177.13
109.104.189.67
109.108.233.47
109.122.19.239
109.162.68.86
109.162.91.114
109.185.112.235
109.200.141.15
109.200.230.5
109.200.240.83
109.200.248.30
109.207.205.3
109.227.67.70
109.227.117.230
109.227.120.202
109.229.19.28
109.229.19.84
109.237.47.9
109.251.77.14
109.251.107.244
109.251.126.134
109.254.33.29
109.254.108.51
113.252.179.249
119.246.242.148
123.110.207.41
134.249.12.41
134.249.17.76
134.249.24.249
134.249.40.43
134.249.42.37
134.249.73.124
134.249.78.208
134.249.149.69
134.249.238.140
141.101.3.36
141.101.19.13
141.138.115.144
151.0.12.101
151.0.57.159
159.224.247.95
173.51.221.110
173.71.98.228
173.224.248.55
176.8.33.121
176.8.51.96
176.8.140.178
176.8.209.58
176.8.253.189
176.36.17.197
176.36.186.138
176.37.147.11
176.37.234.30
176.38.40.16
176.38.95.43
176.38.106.4
176.38.125.64
176.73.13.72
176.73.173.163
176.98.20.110
176.99.112.249
176.99.126.224
176.103.202.65
176.104.10.54
176.104.46.61
176.104.171.139
176.106.31.227
176.107.198.34
176.109.75.175
176.109.238.102
176.109.238.201
176.110.22.247
176.111.36.66
176.111.41.206
176.111.184.13
176.113.149.167
176.113.249.15
176.113.251.172
176.113.255.207
176.114.37.72
176.114.45.237
176.117.64.103
176.118.146.15
176.122.107.41
176.122.107.221
176.124.8.118
176.124.12.180
176.124.13.103
176.124.239.170
176.195.156.193
176.212.209.85
176.241.155.43
178.54.238.73
178.74.194.82
178.74.214.9
178.74.228.191
178.94.49.166
178.94.52.156
178.136.122.47
178.136.130.171
178.136.131.30
178.136.229.208
178.137.11.129
178.137.66.0
178.137.82.42
178.137.140.96
178.137.224.117
178.137.242.146
178.137.243.182
178.137.251.70
178.150.112.132
178.150.114.140
178.150.153.18
178.150.184.9
178.150.195.215
178.150.196.136
178.150.213.134
178.151.11.33
178.151.23.241
178.151.24.112
178.151.34.85
178.151.73.157
178.151.105.24
178.151.116.140
178.151.144.68
178.151.161.143
178.151.175.121
178.151.194.16
178.151.197.61
178.158.131.20
178.158.148.195
178.158.203.91
178.159.113.114
178.164.145.39
178.165.6.62
178.165.44.250
178.165.83.3
178.165.113.39
178.213.169.171
178.213.190.164
178.215.185.23
178.215.191.156
178.216.2.64
178.216.225.249
181.165.34.50
184.144.198.231
185.6.184.146
185.10.3.232
185.28.193.193
185.28.193.195
185.35.102.6
188.0.122.38
188.0.125.41
188.26.120.193
188.43.105.49
188.122.2.225
188.130.192.163
188.190.65.214
188.190.76.247
188.190.90.148
188.190.200.145
188.190.203.178
188.190.213.100
188.190.214.24
188.230.15.191
188.230.31.190
188.230.65.72
188.230.75.141
188.230.84.45
188.231.147.199
188.239.2.247
188.239.91.46
189.219.75.244
190.137.215.190
192.168.114.199
193.93.216.149
193.107.135.125
193.107.227.46
193.108.49.57
193.111.188.230
193.189.127.121
194.8.156.226
194.8.159.12
194.44.2.22
194.44.2.75
194.44.37.3
194.44.113.79
194.44.250.92
194.116.195.132
195.58.254.206
195.64.143.36
195.114.149.110
195.114.157.81
195.135.236.138
195.191.247.98
195.225.228.156
200.116.20.61
212.15.151.42
212.22.192.224
212.28.84.202
212.80.56.118
212.92.246.198
212.115.243.25
212.142.90.46
213.111.137.90
213.111.138.73
213.111.151.140
213.111.161.210
213.111.163.0
213.111.184.48
213.111.203.203
213.111.248.124
213.130.8.151
213.142.49.167
213.231.22.235
213.231.39.31
217.24.64.168
217.30.203.39
217.67.67.229
217.73.85.49
217.73.85.156

View File

@ -0,0 +1,604 @@
#
# esentire_14072015q_com
#
# ipv4 hash:ip ipset
#
# Malicious Botnet Serving Various Malware Families
#
# Maintainer : eSentire
# Maintainer URL : https://github.com/eSentire/malfeed
# List source URL : https://raw.githubusercontent.com/eSentire/malfeed/master/14072015q.com_watch_ip.lst
# Source File Date: Wed Jun 6 11:52:14 UTC 2018
#
# Category : malware
# Version : 6
#
# This File Date : Thu Jun 7 00:08:50 UTC 2018
# Update Frequency: 1 day
# Aggregation : none
# Entries : 575 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=esentire_14072015q_com
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
1.175.3.90
2.133.85.150
5.1.2.227
5.56.25.29
5.105.50.179
5.105.52.34
5.105.130.241
5.140.106.180
5.143.150.71
5.149.216.46
5.248.99.180
5.248.124.161
5.248.140.201
5.248.141.34
5.248.144.87
5.248.194.148
5.248.196.203
5.248.254.4
10.1.120.31
10.1.120.34
23.243.180.132
24.193.190.169
24.214.18.167
31.41.116.88
31.43.4.212
31.43.28.113
31.43.61.73
31.43.82.41
31.43.102.34
31.43.132.156
31.128.74.100
31.128.104.215
31.129.94.180
31.129.95.173
31.129.109.172
31.129.110.6
31.131.101.222
31.131.108.202
31.131.115.55
31.133.66.75
31.133.68.81
31.135.130.27
31.170.130.120
31.170.152.131
31.170.178.179
31.202.176.54
31.207.167.5
36.237.101.56
37.1.58.55
37.25.119.138
37.25.123.252
37.25.126.4
37.54.161.154
37.57.27.184
37.57.37.69
37.57.240.152
37.57.246.121
37.115.15.172
37.115.20.149
37.115.93.155
37.139.165.201
37.143.88.42
37.221.142.213
37.229.13.98
37.229.24.30
46.33.225.80
46.37.197.144
46.46.79.62
46.46.90.65
46.46.96.199
46.63.35.252
46.63.59.44
46.98.1.8
46.98.75.118
46.98.78.188
46.98.97.89
46.98.97.130
46.98.100.46
46.98.113.153
46.98.132.170
46.98.152.107
46.98.203.70
46.98.204.188
46.98.213.95
46.98.220.186
46.98.247.222
46.98.254.210
46.118.23.179
46.118.51.117
46.118.54.10
46.118.69.177
46.118.81.195
46.118.84.37
46.118.147.106
46.118.149.108
46.118.158.172
46.118.178.113
46.118.253.204
46.119.0.170
46.119.11.137
46.119.16.18
46.119.17.234
46.119.76.220
46.119.105.213
46.119.173.111
46.119.179.81
46.119.195.170
46.119.209.176
46.146.132.76
46.148.180.102
46.150.8.215
46.150.91.176
46.151.248.27
46.151.253.25
46.160.99.66
46.160.113.116
46.164.188.85
46.172.192.160
46.172.209.208
46.172.212.54
46.173.77.180
46.173.84.239
46.174.240.33
46.174.246.197
46.175.77.227
46.175.137.124
46.185.81.27
46.185.107.224
46.200.44.135
46.201.77.153
46.211.18.203
46.211.27.11
46.211.28.176
46.211.53.116
46.211.74.218
46.211.88.32
46.211.195.139
46.211.217.205
46.211.235.48
46.211.238.141
46.250.4.228
46.250.15.111
46.250.17.227
46.250.120.231
54.83.4.26
54.235.166.93
62.16.38.131
62.84.253.186
62.122.93.147
69.84.107.186
70.51.44.188
71.3.191.208
71.61.172.133
71.182.234.109
71.226.78.56
72.53.89.52
73.36.213.39
73.128.180.27
73.172.10.82
74.134.99.228
77.89.226.21
77.91.184.71
77.109.58.50
77.109.58.246
77.120.153.195
77.120.155.24
77.121.59.193
77.121.83.134
77.121.172.23
77.121.186.193
77.121.214.247
77.121.248.109
77.121.248.142
77.122.27.116
77.122.48.50
77.122.50.141
77.122.117.112
77.122.121.122
77.122.150.135
77.122.153.68
77.122.184.9
77.122.184.233
77.122.225.133
77.122.225.173
77.122.232.43
77.123.33.194
77.123.73.204
77.123.222.54
77.247.21.163
77.247.23.79
78.30.226.103
78.111.243.83
78.137.16.80
78.137.21.217
78.137.42.84
78.137.45.30
78.137.45.113
78.162.208.223
78.169.94.241
79.112.62.143
79.113.160.90
79.132.3.138
79.135.222.84
79.142.207.184
79.171.124.211
80.245.117.198
80.252.249.153
80.252.250.121
80.252.253.160
81.9.24.250
81.22.139.55
81.22.141.34
83.99.245.186
83.167.28.121
83.218.228.46
85.114.216.12
85.198.166.158
85.237.34.129
85.238.101.24
86.125.251.15
87.76.36.212
87.76.53.178
87.76.57.222
87.110.28.220
87.244.34.238
88.135.94.164
88.135.238.111
88.135.251.129
88.156.84.155
88.222.173.33
89.65.63.95
89.66.136.116
89.185.15.235
89.185.21.82
89.185.29.54
91.124.201.223
91.196.81.167
91.198.143.44
91.201.71.41
91.202.133.86
91.209.96.67
91.215.55.41
91.218.74.89
91.219.199.248
91.221.29.181
91.224.253.6
91.225.57.30
91.229.54.147
91.237.14.8
91.243.200.132
91.244.8.216
91.244.24.5
91.244.29.60
91.244.36.90
91.244.37.3
92.52.177.95
92.52.186.215
92.112.58.245
92.113.69.127
92.243.113.105
92.244.103.244
92.244.116.165
92.249.119.9
93.76.66.62
93.76.104.167
93.76.104.241
93.76.164.173
93.77.104.109
93.77.204.131
93.77.220.9
93.78.19.128
93.78.67.85
93.78.163.201
93.78.181.144
93.79.34.155
93.79.111.83
93.79.168.251
93.79.241.161
93.114.246.153
93.118.90.170
93.118.202.150
93.127.3.177
93.127.16.170
93.127.119.6
93.170.50.15
93.170.50.91
93.170.51.47
93.170.152.201
93.170.153.170
93.170.155.207
93.181.197.194
93.181.211.186
93.183.243.116
93.185.211.46
94.45.73.242
94.45.140.60
94.76.65.93
94.76.121.245
94.76.127.113
94.154.35.51
94.158.43.155
94.178.84.198
94.178.129.75
94.178.230.215
94.181.80.232
94.181.160.141
94.231.70.97
94.231.71.95
94.231.184.85
94.232.76.137
94.232.78.220
94.244.48.229
94.244.141.40
95.47.28.117
95.47.128.209
95.57.228.161
95.67.46.154
95.67.75.154
95.77.219.240
95.81.247.208
95.87.84.203
95.105.11.115
95.105.249.36
95.132.207.171
95.134.158.152
95.135.17.8
95.135.69.19
95.135.213.151
95.164.40.91
95.173.33.100
95.215.118.45
97.75.107.134
98.27.145.224
100.3.73.52
100.6.61.161
104.162.93.136
107.4.129.77
107.15.99.91
108.29.104.102
108.54.179.254
109.72.120.184
109.86.147.39
109.86.206.111
109.86.210.227
109.86.230.210
109.86.234.51
109.87.3.16
109.87.68.203
109.87.120.8
109.87.165.28
109.87.187.170
109.87.205.126
109.87.209.171
109.87.249.48
109.104.177.13
109.104.189.67
109.108.233.47
109.122.19.239
109.162.68.86
109.162.91.114
109.185.112.235
109.200.141.15
109.200.230.5
109.200.240.83
109.200.248.30
109.207.205.3
109.227.67.70
109.227.117.230
109.227.120.202
109.229.19.28
109.229.19.84
109.237.47.9
109.251.77.14
109.251.107.244
109.251.126.134
109.254.33.29
109.254.108.51
113.252.179.249
119.246.242.148
123.110.207.41
134.249.12.41
134.249.17.76
134.249.24.249
134.249.40.43
134.249.42.37
134.249.73.124
134.249.78.208
134.249.149.69
134.249.238.140
141.101.3.36
141.101.19.13
141.138.115.144
151.0.12.101
151.0.57.159
159.224.247.95
173.51.221.110
173.71.98.228
173.224.248.55
176.8.33.121
176.8.51.96
176.8.140.178
176.8.209.58
176.8.253.189
176.36.17.197
176.36.186.138
176.37.147.11
176.37.234.30
176.38.40.16
176.38.95.43
176.38.106.4
176.38.125.64
176.73.13.72
176.73.173.163
176.98.20.110
176.99.112.249
176.99.126.224
176.103.202.65
176.104.10.54
176.104.46.61
176.104.171.139
176.106.31.227
176.107.198.34
176.109.75.175
176.109.238.102
176.109.238.201
176.110.22.247
176.111.36.66
176.111.41.206
176.111.184.13
176.113.149.167
176.113.249.15
176.113.251.172
176.113.255.207
176.114.37.72
176.114.45.237
176.117.64.103
176.118.146.15
176.122.107.41
176.122.107.221
176.124.8.118
176.124.12.180
176.124.13.103
176.124.239.170
176.195.156.193
176.212.209.85
176.241.155.43
178.54.238.73
178.74.194.82
178.74.214.9
178.74.228.191
178.94.49.166
178.94.52.156
178.136.122.47
178.136.130.171
178.136.131.30
178.136.229.208
178.137.11.129
178.137.66.0
178.137.82.42
178.137.140.96
178.137.224.117
178.137.242.146
178.137.243.182
178.137.251.70
178.150.112.132
178.150.114.140
178.150.153.18
178.150.184.9
178.150.195.215
178.150.196.136
178.150.213.134
178.151.11.33
178.151.23.241
178.151.24.112
178.151.34.85
178.151.73.157
178.151.105.24
178.151.116.140
178.151.144.68
178.151.161.143
178.151.175.121
178.151.194.16
178.151.197.61
178.158.131.20
178.158.148.195
178.158.203.91
178.159.113.114
178.164.145.39
178.165.6.62
178.165.44.250
178.165.83.3
178.165.113.39
178.213.169.171
178.213.190.164
178.215.185.23
178.215.191.156
178.216.2.64
178.216.225.249
181.165.34.50
184.144.198.231
185.6.184.146
185.10.3.232
185.28.193.193
185.28.193.195
185.35.102.6
188.0.122.38
188.0.125.41
188.26.120.193
188.43.105.49
188.122.2.225
188.130.192.163
188.190.65.214
188.190.76.247
188.190.90.148
188.190.200.145
188.190.203.178
188.190.213.100
188.190.214.24
188.230.15.191
188.230.31.190
188.230.65.72
188.230.75.141
188.230.84.45
188.231.147.199
188.239.2.247
188.239.91.46
189.219.75.244
190.137.215.190
192.168.114.199
193.93.216.149
193.107.135.125
193.107.227.46
193.108.49.57
193.111.188.230
193.189.127.121
194.8.156.226
194.8.159.12
194.44.2.22
194.44.2.75
194.44.37.3
194.44.113.79
194.44.250.92
194.116.195.132
195.58.254.206
195.64.143.36
195.114.149.110
195.114.157.81
195.135.236.138
195.191.247.98
195.225.228.156
200.116.20.61
212.15.151.42
212.22.192.224
212.28.84.202
212.80.56.118
212.92.246.198
212.115.243.25
212.142.90.46
213.111.137.90
213.111.138.73
213.111.151.140
213.111.161.210
213.111.163.0
213.111.184.48
213.111.203.203
213.111.248.124
213.130.8.151
213.142.49.167
213.231.22.235
213.231.39.31
217.24.64.168
217.30.203.39
217.67.67.229
217.73.85.49
217.73.85.156

1319
esentire_22072014a_com.ipset Normal file

File diff suppressed because it is too large Load Diff

1317
esentire_22072014b_com.ipset Normal file

File diff suppressed because it is too large Load Diff

1318
esentire_22072014c_com.ipset Normal file

File diff suppressed because it is too large Load Diff

View File

@ -0,0 +1,36 @@
#
# esentire_atomictrivia_ru
#
# ipv4 hash:ip ipset
#
# Andromeda/Gamarue Checkin
#
# Maintainer : eSentire
# Maintainer URL : https://github.com/eSentire/malfeed
# List source URL : https://raw.githubusercontent.com/eSentire/malfeed/master/atomictrivia.ru_watch_ip.lst
# Source File Date: Wed Jun 6 11:52:13 UTC 2018
#
# Category : malware
# Version : 11
#
# This File Date : Thu Jun 7 00:08:51 UTC 2018
# Update Frequency: 1 day
# Aggregation : none
# Entries : 7 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=esentire_atomictrivia_ru
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
46.4.114.61
54.83.4.26
54.235.166.93
95.213.192.71
176.9.48.86
176.9.82.215
178.63.12.207

File diff suppressed because it is too large Load Diff

File diff suppressed because it is too large Load Diff

18642
esentire_crazyerror_su.ipset Normal file

File diff suppressed because it is too large Load Diff

View File

@ -0,0 +1,546 @@
#
# esentire_dagestanskiiviskis_ru
#
# ipv4 hash:ip ipset
#
# Ursnif Variant CnC
#
# Maintainer : eSentire
# Maintainer URL : https://github.com/eSentire/malfeed
# List source URL : https://raw.githubusercontent.com/eSentire/malfeed/master/dagestanskiiviskis.ru_watch_ip.lst
# Source File Date: Wed Jun 6 11:52:15 UTC 2018
#
# Category : malware
# Version : 6
#
# This File Date : Thu Jun 7 00:08:51 UTC 2018
# Update Frequency: 1 day
# Aggregation : none
# Entries : 517 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=esentire_dagestanskiiviskis_ru
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
2.62.23.234
5.2.216.120
5.12.168.83
5.14.69.38
5.14.172.95
5.79.191.198
5.105.98.241
5.105.130.241
5.136.100.50
5.143.140.236
5.143.166.83
5.153.129.193
5.164.66.183
5.164.207.221
5.165.232.191
5.167.9.135
5.189.221.99
5.199.233.176
5.228.106.212
5.248.51.11
5.248.58.154
5.248.106.201
5.248.124.161
5.248.126.218
5.248.175.139
5.248.186.248
5.248.198.111
5.248.235.69
5.248.242.211
5.255.161.252
14.42.158.45
24.70.124.49
24.96.222.4
24.136.95.254
31.6.123.150
31.6.125.172
31.8.144.14
31.8.161.217
31.8.175.111
31.23.21.219
31.41.116.88
31.42.125.15
31.43.75.153
31.44.11.217
31.47.122.245
31.47.167.142
31.128.44.20
31.128.74.100
31.128.104.215
31.129.95.173
31.131.101.222
31.131.137.63
31.133.77.119
31.134.21.170
31.134.69.230
31.135.38.197
31.135.48.147
31.135.114.203
31.135.133.237
31.135.136.176
31.162.8.8
31.170.130.120
31.170.152.131
31.202.223.141
31.207.178.78
31.207.228.197
31.207.229.67
37.1.128.96
37.19.78.212
37.21.23.21
37.25.109.92
37.25.114.125
37.25.116.19
37.25.117.182
37.46.249.235
37.54.230.239
37.57.28.153
37.57.37.69
37.57.240.187
37.113.204.90
37.115.24.106
37.115.90.157
37.115.134.56
37.115.171.164
37.115.231.247
37.194.118.106
37.221.142.213
37.229.43.110
37.229.247.52
37.229.249.54
37.235.161.13
46.0.18.88
46.0.105.75
46.33.240.159
46.33.251.145
46.35.240.81
46.37.197.134
46.43.224.57
46.48.147.97
46.50.179.195
46.63.1.192
46.63.6.16
46.98.18.231
46.98.37.161
46.98.73.53
46.98.86.240
46.98.105.164
46.98.117.134
46.98.202.20
46.98.202.163
46.98.219.38
46.118.29.25
46.118.84.22
46.118.130.60
46.118.155.53
46.118.239.72
46.118.252.166
46.119.35.231
46.119.89.198
46.119.94.122
46.119.155.141
46.119.173.111
46.146.3.235
46.147.179.93
46.148.182.219
46.148.183.5
46.150.91.176
46.162.36.98
46.164.164.200
46.164.170.15
46.164.189.238
46.172.207.21
46.172.232.202
46.172.238.213
46.172.252.79
46.173.74.179
46.175.77.186
46.175.98.254
46.181.215.20
46.185.9.53
46.185.18.158
46.185.51.76
46.185.73.44
46.185.94.136
46.185.119.82
46.211.60.80
46.237.30.185
50.83.33.15
50.161.246.210
61.244.34.238
62.80.161.74
62.84.253.186
62.84.255.35
62.244.60.154
67.161.171.204
73.143.88.158
73.182.13.78
73.209.189.206
74.139.176.131
77.52.183.30
77.75.135.92
77.78.210.179
77.91.184.71
77.93.62.84
77.120.25.214
77.120.159.89
77.120.170.83
77.121.47.43
77.121.58.49
77.121.114.54
77.121.161.66
77.122.125.49
77.122.152.5
77.122.154.230
77.122.189.45
77.122.226.163
77.122.235.183
77.232.214.172
77.239.190.247
78.27.183.113
78.29.101.224
78.96.153.47
78.97.195.40
79.114.76.25
79.116.111.187
79.117.27.88
79.119.76.40
79.119.81.24
79.119.192.205
79.142.200.140
79.171.124.211
80.240.40.174
80.243.155.25
80.252.252.7
80.252.252.171
80.252.255.128
81.9.24.250
81.22.135.82
81.163.46.209
81.163.54.83
81.163.93.101
82.76.65.108
82.77.43.35
82.79.21.91
82.209.117.176
83.234.253.227
84.53.214.22
84.117.156.67
84.232.210.248
85.237.35.122
86.100.133.94
86.121.248.49
86.124.111.205
86.125.184.115
86.125.231.223
88.85.206.166
88.135.121.221
88.203.3.130
88.233.78.205
89.32.218.56
89.42.87.41
89.121.205.190
89.185.10.36
89.252.7.39
89.252.8.138
89.252.41.9
91.104.21.62
91.190.235.194
91.198.143.44
91.204.250.227
91.211.175.7
91.218.89.197
91.219.251.28
91.221.179.42
91.225.161.106
91.225.161.207
91.237.14.19
91.241.227.106
91.243.218.240
91.244.12.138
91.246.7.211
92.52.165.90
92.52.181.125
92.52.188.52
92.113.29.192
92.113.143.87
92.248.135.141
92.248.136.100
92.248.216.12
92.248.242.249
92.249.212.75
93.76.72.58
93.76.104.226
93.76.164.173
93.76.181.42
93.76.205.64
93.77.115.10
93.77.204.131
93.77.221.41
93.78.54.197
93.78.96.225
93.78.217.148
93.79.24.199
93.79.65.222
93.79.168.251
93.79.199.156
93.79.200.105
93.88.57.78
93.113.90.28
93.113.176.105
93.118.209.118
93.119.139.39
93.119.155.220
93.124.44.131
93.127.89.112
93.170.153.170
93.171.21.27
93.171.253.155
93.183.246.105
94.28.137.173
94.45.92.6
94.45.140.60
94.76.65.93
94.76.127.113
94.125.51.117
94.179.47.27
94.181.97.145
94.240.165.141
94.243.14.31
94.244.141.40
94.253.13.174
95.67.46.154
95.67.75.154
95.79.217.131
95.105.249.36
95.106.203.206
95.106.214.42
95.110.24.171
95.139.66.62
95.139.212.72
95.139.253.60
95.190.15.238
95.190.16.138
95.215.209.73
96.50.181.81
98.116.11.226
100.6.61.161
104.162.93.136
107.15.99.91
108.7.231.42
108.183.203.14
109.63.193.84
109.86.76.58
109.86.143.188
109.86.230.210
109.86.234.51
109.87.131.54
109.87.148.237
109.87.165.28
109.87.204.143
109.87.249.48
109.104.189.67
109.105.78.238
109.120.5.115
109.161.41.46
109.162.118.190
109.184.213.234
109.196.71.193
109.200.230.148
109.200.232.184
109.201.76.89
109.201.198.206
109.227.200.151
109.236.217.151
109.251.77.14
109.251.148.252
109.254.58.99
109.254.108.51
109.254.116.68
113.252.180.74
119.247.219.135
123.202.249.155
130.204.240.145
134.249.30.72
134.249.31.13
134.249.81.148
136.169.169.63
136.169.169.197
145.249.167.167
146.120.25.65
151.0.61.118
151.249.101.99
159.224.62.162
159.224.101.52
159.224.140.219
159.224.253.208
176.36.23.31
176.36.68.13
176.36.174.59
176.36.202.68
176.37.109.5
176.37.122.224
176.37.172.33
176.49.142.86
176.77.24.129
176.77.111.200
176.98.2.232
176.99.106.204
176.99.176.112
176.101.193.179
176.101.207.64
176.102.211.159
176.103.205.207
176.104.41.120
176.104.102.59
176.104.185.139
176.105.131.208
176.106.31.227
176.113.246.139
176.113.251.1
176.114.44.50
176.116.221.106
176.116.221.246
176.116.222.84
176.117.72.184
176.118.113.253
176.124.13.36
176.195.253.219
176.210.68.73
176.212.97.227
176.212.185.229
176.213.67.155
176.213.75.210
176.213.239.205
176.213.253.173
176.226.147.109
178.34.19.159
178.35.161.136
178.45.197.114
178.46.96.169
178.54.167.147
178.54.182.27
178.74.203.125
178.93.163.70
178.136.222.214
178.136.241.135
178.137.11.129
178.137.61.90
178.137.80.252
178.137.82.42
178.137.115.109
178.137.156.59
178.137.158.86
178.137.186.180
178.137.213.13
178.137.224.117
178.150.172.207
178.150.213.134
178.151.11.33
178.151.73.157
178.151.114.33
178.151.139.25
178.151.144.68
178.151.241.177
178.158.148.195
178.158.201.252
178.158.228.24
178.159.113.246
178.165.36.80
178.165.98.17
178.165.106.161
178.165.107.138
178.206.127.150
178.207.168.102
178.211.185.203
178.217.163.77
178.219.253.37
178.234.243.161
178.234.247.85
181.45.0.138
185.17.17.111
185.22.17.85
185.27.103.79
185.86.3.171
187.240.23.29
188.0.122.38
188.0.125.41
188.18.80.50
188.24.15.92
188.24.182.130
188.25.68.106
188.25.185.202
188.27.58.58
188.27.224.223
188.27.236.220
188.75.198.19
188.75.240.44
188.75.243.36
188.123.45.117
188.168.146.203
188.190.66.19
188.190.67.242
188.190.195.238
188.191.235.161
188.191.238.171
188.191.239.79
188.209.109.154
188.212.158.206
188.230.84.45
188.231.147.199
188.231.244.193
188.234.116.93
188.234.119.59
188.239.6.96
188.239.21.192
188.240.0.34
188.241.106.118
188.241.131.14
188.242.4.131
188.255.93.37
190.19.48.93
190.190.179.2
192.162.232.198
192.166.113.83
193.111.188.230
193.242.156.56
193.254.233.26
195.18.43.216
195.160.220.110
197.7.101.165
197.9.198.102
204.195.156.186
212.2.142.108
212.3.107.202
212.21.7.79
212.22.192.224
212.34.126.162
212.91.214.42
212.92.225.115
212.92.240.222
212.92.254.38
212.115.239.200
212.115.250.13
213.111.140.203
213.111.155.155
213.111.167.62
213.111.168.163
213.111.232.28
213.111.251.240
213.154.205.150
213.231.10.126
213.231.15.11
213.231.28.245
213.231.61.231
217.73.81.60
217.73.85.49
217.73.93.154

View File

@ -0,0 +1,41 @@
#
# esentire_differentia_ru
#
# ipv4 hash:ip ipset
#
# Malicious Botnet Serving Various Malware Families
#
# Maintainer : eSentire
# Maintainer URL : https://github.com/eSentire/malfeed
# List source URL : https://raw.githubusercontent.com/eSentire/malfeed/master/differentia.ru_watch_ip.lst
# Source File Date: Wed Jun 6 11:52:10 UTC 2018
#
# Category : malware
# Version : 6
#
# This File Date : Thu Jun 7 00:08:49 UTC 2018
# Update Frequency: 1 day
# Aggregation : none
# Entries : 12 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=esentire_differentia_ru
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
46.4.114.61
54.83.4.26
54.235.166.93
95.213.186.51
95.213.192.71
109.70.26.37
109.206.186.164
176.9.48.86
176.9.82.215
176.9.174.220
178.63.12.207
194.85.61.76

View File

@ -0,0 +1,36 @@
#
# esentire_disorderstatus_ru
#
# ipv4 hash:ip ipset
#
# Malicious Botnet Serving Various Malware Families
#
# Maintainer : eSentire
# Maintainer URL : https://github.com/eSentire/malfeed
# List source URL : https://raw.githubusercontent.com/eSentire/malfeed/master/disorderstatus.ru_watch_ip.lst
# Source File Date: Wed Jun 6 11:52:13 UTC 2018
#
# Category : malware
# Version : 6
#
# This File Date : Thu Jun 7 00:08:50 UTC 2018
# Update Frequency: 1 day
# Aggregation : none
# Entries : 7 unique IPs
#
# Full list analysis, including geolocation map, history,
# retention policy, overlaps with other lists, etc.
# available at:
#
# http://iplists.firehol.org/?ipset=esentire_disorderstatus_ru
#
# Generated by FireHOL's update-ipsets.sh
# Processed with FireHOL's iprange
#
46.4.114.61
54.83.4.26
54.235.166.93
95.213.192.71
109.206.186.164
176.9.48.86
176.9.82.215

Some files were not shown because too many files have changed in this diff Show More