Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add CNCERT/CC sinkhole IP #12

Merged
merged 3 commits into from
Jul 25, 2019
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions Sinkholes_List.csv
Original file line number Diff line number Diff line change
Expand Up @@ -69,3 +69,4 @@ Zinkhole.org,178.32.140.251,suspended-domain.org,
Zinkhole.org,94.23.175.2,suspended-domain.org,
OpenDNS,146.112.61.104-110,"hit-{block,botnet,adult,malware,phish,block,malware}.opendns.com",https://support.opendns.com/hc/en-us/articles/227986927-What-are-the-Cisco-Umbrella-Block-Page-IP-Addresses-
infosec.jp,58.158.177.102,UCOM Corp.,https://github.com/grettir/malware-sinkholes/blob/905841db3b3cd86052d577c137ac9868c92dcb3b/malware_sinkholes.txt#L256
CNCERT/CC,183.236.2.18,China Mobile communications corporation,
2 changes: 1 addition & 1 deletion Sinkholes_List.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
[{"Organization": "Anubis", "IP Range": "195.22.26.192/26", "Whois": "anubisnetworks.com", "Notes": "https://www.proofpoint.com/us/daily-ruleset-update-summary-2015-08-14"}, {"Organization": "Arbor Networks ASERT", "IP Range": "23.253.126.58", "Whois": "arbor-sinkhole.net", "Notes": "http://www.malwareurl.com/ns_listing.php?ns=ns1.arbor-sinkhole.net"}, {"Organization": "Arbor Networks ASERT", "IP Range": "168.181.184.35", "Whois": "arbor-sinkhole.net", "Notes": "http://www.malwareurl.com/ns_listing.php?ns=ns1.arbor-sinkhole.net"}, {"Organization": "Blacklab.io", "IP Range": "67.215.255.139", "Whois": "sinkhole.blacklab.io", "Notes": ""}, {"Organization": "blacklistthisdomain", "IP Range": "106.187.96.49", "Whois": "sinkhole.blacklistthisdomain.com", "Notes": ""}, {"Organization": "blacklistthisdomain", "IP Range": "81.166.122.234", "Whois": "sinkhole.blacklistthisdomain.com", "Notes": ""}, {"Organization": "Botnet Hunter", "IP Range": "52.5.245.208", "Whois": "ec2-52-5-245-208.compute-1.amazonaws.com", "Notes": ""}, {"Organization": "CERT Polska", "IP Range": "148.81.111.111", "Whois": "sinkhole.cert.pl", "Notes": ""}, {"Organization": "CERT Polska", "IP Range": "148.81.111.91", "Whois": "sinkhole.cert.pl", "Notes": ""}, {"Organization": "CERT Polska", "IP Range": "148.81.111.114", "Whois": "sinkhole.cert.pl", "Notes": ""}, {"Organization": "Conficker Working Group", "IP Range": "136.161.101.53", "Whois": "conficker-sinkhole.com", "Notes": ""}, {"Organization": "Dr. Web", "IP Range": "91.233.244.106", "Whois": "http://doc.emergingthreats.net/bin/view/Main/2016997", "Notes": ""}, {"Organization": "Endgame", "IP Range": "166.78.144.80", "Whois": "s01.snkhole.mal-ware.susp-nded.domain", "Notes": "http://www.kleissner.org"}, {"Organization": "Farsight", "IP Range": "104.244.12.0/22", "Whois": "sinkhole-iad1-2.cwg.fsi.io", "Notes": ""}, {"Organization": "FBI", "IP Range": "142.0.36.234", "Whois": "VolumeDrive", "Notes": ""}, {"Organization": "Fitsec", "IP Range": "193.166.255.171", "Whois": "Funet CERT", "Notes": ""}, {"Organization": "Georgia Tech", "IP Range": "143.215.130.0/24", "Whois": "Georgia Institute of Technology", "Notes": ""}, {"Organization": "Georgia Tech", "IP Range": "198.61.227.6", "Whois": "Rackspace", "Notes": "www.kleissner.org"}, {"Organization": "Georgia Tech", "IP Range": "50.57.148.87", "Whois": "Slicehost", "Notes": "www.kleissner.org"}, {"Organization": "Gladtech", "IP Range": "74.200.48.169", "Whois": "sinkhole.gladtech.net", "Notes": ""}, {"Organization": "Helse CSIRT", "IP Range": "91.186.66.36", "Whois": "NORWEGIAN-HEALTH-NETWORK", "Notes": ""}, {"Organization": "Hyas", "IP Range": "192.169.69.25", "Whois": "sinkhole.hyas.com", "Notes": ""}, {"Organization": "Kaspersky", "IP Range": "93.159.228.22", "Whois": "sinkhole.kaspersky.com", "Notes": ""}, {"Organization": "Kaspersky", "IP Range": "95.211.172.143", "Whois": "sinkhole.kaspersky.com", "Notes": ""}, {"Organization": "MalwareDomains", "IP Range": "139.146.167.25", "Whois": "Computer Problem Solving (CPS)", "Notes": ""}, {"Organization": "Microsoft", "IP Range": "131.253.18.11-12", "Whois": "Microsoft", "Notes": "http://doc.emergingthreats.net/bin/view/Main/2016101"}, {"Organization": "Microsoft", "IP Range": "199.2.137.0/24", "Whois": "Microsoft", "Notes": "https://lists.emergingthreats.net/pipermail/emerging-sigs/2013-June/022148.html"}, {"Organization": "Microsoft", "IP Range": "204.95.99.59", "Whois": "Microsoft", "Notes": "https://lists.emergingthreats.net/pipermail/emerging-sigs/2013-June/022148.html"}, {"Organization": "Microsoft", "IP Range": "207.46.90.0/24", "Whois": "Microsoft", "Notes": "https://lists.emergingthreats.net/pipermail/emerging-sigs/2013-June/022148.html"}, {"Organization": "PublicDomainRegistry", "IP Range": "109.74.196.143", "Whois": "Linode", "Notes": "www.kleissner.org"}, {"Organization": "PublicDomainRegistry", "IP Range": "50.116.56.144", "Whois": "Linode", "Notes": "www.kleissner.org"}, {"Organization": "PublicDomainRegistry", "IP Range": "50.116.32.177", "Whois": "Linode", "Notes": "www.kleissner.org"}, {"Organization": "PublicDomainRegistry", "IP Range": "178.79.190.156", "Whois": "Linode", "Notes": "www.kleissner.org"}, {"Organization": "Shadowserver", "IP Range": "87.106.24.200", "Whois": "sinkhole-00.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "87.106.26.9", "Whois": "sinkhole-01.shadowserver.org", "Notes": "http://marc.info/?l=emerging-sigs&m=135764068231008&w=2"}, {"Organization": "Shadowserver", "IP Range": "74.208.64.145", "Whois": "sinkhole-02.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "74.208.64.191", "Whois": "sinkhole-03.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "74.208.164.166", "Whois": "sinkhole-04.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "212.227.55.84", "Whois": "sinkhole.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "74.208.15.160", "Whois": "sinkhole.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "74.208.15.97", "Whois": "sinkhole.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "87.106.250.34", "Whois": "sinkhole.shadowserver.org", "Notes": "http://marc.info/?l=emerging-sigs&m=135764068231008&w=2"}, {"Organization": "Shadowserver", "IP Range": "87.106.86.28", "Whois": "sinkhole.shadowserver.org", "Notes": "http://marc.info/?l=emerging-sigs&m=135764068231008&w=2"}, {"Organization": "SIDN Labs", "IP Range": "176.58.104.168", "Whois": "sinkhole.sidnlabs.nl", "Notes": ""}, {"Organization": "sinkhole.DK", "IP Range": "212.227.20.19", "Whois": "sinkhole.dk", "Notes": ""}, {"Organization": "sinkhole.in", "IP Range": "86.124.164.25", "Whois": "sinkhole.in", "Notes": ""}, {"Organization": "sinkhole.tech", "IP Range": "79.137.66.14", "Whois": "http3.sinkhole.tech", "Notes": ""}, {"Organization": "sinkhole.tech", "IP Range": "95.211.174.92", "Whois": "sinkhole.tech", "Notes": ""}, {"Organization": "sinkhole.tech", "IP Range": "144.217.254.3", "Whois": "http4.sinkhole.tech", "Notes": ""}, {"Organization": "sinkhole.tech", "IP Range": "217.182.172.139", "Whois": "http1.sinkhole.tech", "Notes": ""}, {"Organization": "sinkhole.tech", "IP Range": "144.217.74.156", "Whois": "http2.sinkhole.tech", "Notes": ""}, {"Organization": "SISRA / Abuse.ch", "IP Range": "104.155.11.149", "Whois": "this-domain-is-sinkholed-by.abuse.ch", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "208.43.245.213", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "173.192.192.10", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "199.231.211.108", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "198.98.120.157", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "192.42.116.41", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "87.255.51.229", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Team Cymru", "IP Range": "38.102.150.29", "Whois": "conficker-sinkhole.net", "Notes": ""}, {"Organization": "Team Cymru", "IP Range": "38.229.70.125", "Whois": "conficker-sinkhole.net", "Notes": ""}, {"Organization": "Torpig-Sinkhole", "IP Range": "212.227.55.84", "Whois": "torpig-sinkhole.org", "Notes": ""}, {"Organization": "Torpig-Sinkhole", "IP Range": "87.106.240.162", "Whois": "torpig-sinkhole.org", "Notes": ""}, {"Organization": "Torpig-Sinkhole", "IP Range": "87.106.140.254", "Whois": "torpig-sinkhole.org", "Notes": ""}, {"Organization": "Torpig-Sinkhole", "IP Range": "87.106.141.15", "Whois": "torpig-sinkhole.org", "Notes": ""}, {"Organization": "Wapack Labs", "IP Range": "23.253.46.64", "Whois": "", "Notes": "https://wapacklabs.blogspot.com/2016/07/wapack-labs-sinkhole-results-18.html"}, {"Organization": "Zinkhole.org", "IP Range": "176.31.62.76", "Whois": "suspended-domain.org", "Notes": ""}, {"Organization": "Zinkhole.org", "IP Range": "178.32.140.251", "Whois": "suspended-domain.org", "Notes": ""}, {"Organization": "Zinkhole.org", "IP Range": "94.23.175.2", "Whois": "suspended-domain.org", "Notes": ""}, {"Organization": "OpenDNS", "IP Range": "146.112.61.104-110", "Whois": "hit-{block,botnet,adult,malware,phish,block,malware}.opendns.com", "Notes": "https://support.opendns.com/hc/en-us/articles/227986927-What-are-the-Cisco-Umbrella-Block-Page-IP-Addresses-"}, {"Organization": "infosec.jp", "IP Range": "58.158.177.102", "Whois": "UCOM Corp.", "Notes": "https://github.com/grettir/malware-sinkholes/blob/905841db3b3cd86052d577c137ac9868c92dcb3b/malware_sinkholes.txt#L256"}]
[{"Organization": "Anubis", "IP Range": "195.22.26.192/26", "Whois": "anubisnetworks.com", "Notes": "https://www.proofpoint.com/us/daily-ruleset-update-summary-2015-08-14"}, {"Organization": "Arbor Networks ASERT", "IP Range": "23.253.126.58", "Whois": "arbor-sinkhole.net", "Notes": "http://www.malwareurl.com/ns_listing.php?ns=ns1.arbor-sinkhole.net"}, {"Organization": "Arbor Networks ASERT", "IP Range": "168.181.184.35", "Whois": "arbor-sinkhole.net", "Notes": "http://www.malwareurl.com/ns_listing.php?ns=ns1.arbor-sinkhole.net"}, {"Organization": "Blacklab.io", "IP Range": "67.215.255.139", "Whois": "sinkhole.blacklab.io", "Notes": ""}, {"Organization": "blacklistthisdomain", "IP Range": "106.187.96.49", "Whois": "sinkhole.blacklistthisdomain.com", "Notes": ""}, {"Organization": "blacklistthisdomain", "IP Range": "81.166.122.234", "Whois": "sinkhole.blacklistthisdomain.com", "Notes": ""}, {"Organization": "Botnet Hunter", "IP Range": "52.5.245.208", "Whois": "ec2-52-5-245-208.compute-1.amazonaws.com", "Notes": ""}, {"Organization": "CERT Polska", "IP Range": "148.81.111.111", "Whois": "sinkhole.cert.pl", "Notes": ""}, {"Organization": "CERT Polska", "IP Range": "148.81.111.91", "Whois": "sinkhole.cert.pl", "Notes": ""}, {"Organization": "CERT Polska", "IP Range": "148.81.111.114", "Whois": "sinkhole.cert.pl", "Notes": ""}, {"Organization": "Conficker Working Group", "IP Range": "136.161.101.53", "Whois": "conficker-sinkhole.com", "Notes": ""}, {"Organization": "Dr. Web", "IP Range": "91.233.244.106", "Whois": "http://doc.emergingthreats.net/bin/view/Main/2016997", "Notes": ""}, {"Organization": "Endgame", "IP Range": "166.78.144.80", "Whois": "s01.snkhole.mal-ware.susp-nded.domain", "Notes": "http://www.kleissner.org"}, {"Organization": "Farsight", "IP Range": "104.244.12.0/22", "Whois": "sinkhole-iad1-2.cwg.fsi.io", "Notes": ""}, {"Organization": "FBI", "IP Range": "142.0.36.234", "Whois": "VolumeDrive", "Notes": ""}, {"Organization": "Fitsec", "IP Range": "193.166.255.171", "Whois": "Funet CERT", "Notes": ""}, {"Organization": "Georgia Tech", "IP Range": "143.215.130.0/24", "Whois": "Georgia Institute of Technology", "Notes": ""}, {"Organization": "Georgia Tech", "IP Range": "198.61.227.6", "Whois": "Rackspace", "Notes": "www.kleissner.org"}, {"Organization": "Georgia Tech", "IP Range": "50.57.148.87", "Whois": "Slicehost", "Notes": "www.kleissner.org"}, {"Organization": "Gladtech", "IP Range": "74.200.48.169", "Whois": "sinkhole.gladtech.net", "Notes": ""}, {"Organization": "Helse CSIRT", "IP Range": "91.186.66.36", "Whois": "NORWEGIAN-HEALTH-NETWORK", "Notes": ""}, {"Organization": "Hyas", "IP Range": "192.169.69.25", "Whois": "sinkhole.hyas.com", "Notes": ""}, {"Organization": "Kaspersky", "IP Range": "93.159.228.22", "Whois": "sinkhole.kaspersky.com", "Notes": ""}, {"Organization": "Kaspersky", "IP Range": "95.211.172.143", "Whois": "sinkhole.kaspersky.com", "Notes": ""}, {"Organization": "MalwareDomains", "IP Range": "139.146.167.25", "Whois": "Computer Problem Solving (CPS)", "Notes": ""}, {"Organization": "Microsoft", "IP Range": "131.253.18.11-12", "Whois": "Microsoft", "Notes": "http://doc.emergingthreats.net/bin/view/Main/2016101"}, {"Organization": "Microsoft", "IP Range": "199.2.137.0/24", "Whois": "Microsoft", "Notes": "https://lists.emergingthreats.net/pipermail/emerging-sigs/2013-June/022148.html"}, {"Organization": "Microsoft", "IP Range": "204.95.99.59", "Whois": "Microsoft", "Notes": "https://lists.emergingthreats.net/pipermail/emerging-sigs/2013-June/022148.html"}, {"Organization": "Microsoft", "IP Range": "207.46.90.0/24", "Whois": "Microsoft", "Notes": "https://lists.emergingthreats.net/pipermail/emerging-sigs/2013-June/022148.html"}, {"Organization": "PublicDomainRegistry", "IP Range": "109.74.196.143", "Whois": "Linode", "Notes": "www.kleissner.org"}, {"Organization": "PublicDomainRegistry", "IP Range": "50.116.56.144", "Whois": "Linode", "Notes": "www.kleissner.org"}, {"Organization": "PublicDomainRegistry", "IP Range": "50.116.32.177", "Whois": "Linode", "Notes": "www.kleissner.org"}, {"Organization": "PublicDomainRegistry", "IP Range": "178.79.190.156", "Whois": "Linode", "Notes": "www.kleissner.org"}, {"Organization": "Shadowserver", "IP Range": "87.106.24.200", "Whois": "sinkhole-00.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "87.106.26.9", "Whois": "sinkhole-01.shadowserver.org", "Notes": "http://marc.info/?l=emerging-sigs&m=135764068231008&w=2"}, {"Organization": "Shadowserver", "IP Range": "74.208.64.145", "Whois": "sinkhole-02.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "74.208.64.191", "Whois": "sinkhole-03.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "74.208.164.166", "Whois": "sinkhole-04.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "212.227.55.84", "Whois": "sinkhole.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "74.208.15.160", "Whois": "sinkhole.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "74.208.15.97", "Whois": "sinkhole.shadowserver.org", "Notes": ""}, {"Organization": "Shadowserver", "IP Range": "87.106.250.34", "Whois": "sinkhole.shadowserver.org", "Notes": "http://marc.info/?l=emerging-sigs&m=135764068231008&w=2"}, {"Organization": "Shadowserver", "IP Range": "87.106.86.28", "Whois": "sinkhole.shadowserver.org", "Notes": "http://marc.info/?l=emerging-sigs&m=135764068231008&w=2"}, {"Organization": "SIDN Labs", "IP Range": "176.58.104.168", "Whois": "sinkhole.sidnlabs.nl", "Notes": ""}, {"Organization": "sinkhole.DK", "IP Range": "212.227.20.19", "Whois": "sinkhole.dk", "Notes": ""}, {"Organization": "sinkhole.in", "IP Range": "86.124.164.25", "Whois": "sinkhole.in", "Notes": ""}, {"Organization": "sinkhole.tech", "IP Range": "79.137.66.14", "Whois": "http3.sinkhole.tech", "Notes": ""}, {"Organization": "sinkhole.tech", "IP Range": "95.211.174.92", "Whois": "sinkhole.tech", "Notes": ""}, {"Organization": "sinkhole.tech", "IP Range": "144.217.254.3", "Whois": "http4.sinkhole.tech", "Notes": ""}, {"Organization": "sinkhole.tech", "IP Range": "217.182.172.139", "Whois": "http1.sinkhole.tech", "Notes": ""}, {"Organization": "sinkhole.tech", "IP Range": "144.217.74.156", "Whois": "http2.sinkhole.tech", "Notes": ""}, {"Organization": "SISRA / Abuse.ch", "IP Range": "104.155.11.149", "Whois": "this-domain-is-sinkholed-by.abuse.ch", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "208.43.245.213", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "173.192.192.10", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "199.231.211.108", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "198.98.120.157", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "192.42.116.41", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Spamhaus", "IP Range": "87.255.51.229", "Whois": "sl-reverse.com", "Notes": ""}, {"Organization": "Team Cymru", "IP Range": "38.102.150.29", "Whois": "conficker-sinkhole.net", "Notes": ""}, {"Organization": "Team Cymru", "IP Range": "38.229.70.125", "Whois": "conficker-sinkhole.net", "Notes": ""}, {"Organization": "Torpig-Sinkhole", "IP Range": "212.227.55.84", "Whois": "torpig-sinkhole.org", "Notes": ""}, {"Organization": "Torpig-Sinkhole", "IP Range": "87.106.240.162", "Whois": "torpig-sinkhole.org", "Notes": ""}, {"Organization": "Torpig-Sinkhole", "IP Range": "87.106.140.254", "Whois": "torpig-sinkhole.org", "Notes": ""}, {"Organization": "Torpig-Sinkhole", "IP Range": "87.106.141.15", "Whois": "torpig-sinkhole.org", "Notes": ""}, {"Organization": "Wapack Labs", "IP Range": "23.253.46.64", "Whois": "", "Notes": "https://wapacklabs.blogspot.com/2016/07/wapack-labs-sinkhole-results-18.html"}, {"Organization": "Zinkhole.org", "IP Range": "176.31.62.76", "Whois": "suspended-domain.org", "Notes": ""}, {"Organization": "Zinkhole.org", "IP Range": "178.32.140.251", "Whois": "suspended-domain.org", "Notes": ""}, {"Organization": "Zinkhole.org", "IP Range": "94.23.175.2", "Whois": "suspended-domain.org", "Notes": ""}, {"Organization": "OpenDNS", "IP Range": "146.112.61.104-110", "Whois": "hit-{block,botnet,adult,malware,phish,block,malware}.opendns.com", "Notes": "https://support.opendns.com/hc/en-us/articles/227986927-What-are-the-Cisco-Umbrella-Block-Page-IP-Addresses-"}, {"Organization": "infosec.jp", "IP Range": "58.158.177.102", "Whois": "UCOM Corp.", "Notes": "https://github.com/grettir/malware-sinkholes/blob/905841db3b3cd86052d577c137ac9868c92dcb3b/malware_sinkholes.txt#L256"}, {"Organization": "CNCERT/CC", "IP Range": "183.236.2.18", "Whois": "China Mobile communications corporation", "Notes": ""}]
Binary file modified Sinkholes_List.ods
Binary file not shown.
Binary file modified Sinkholes_List.xls
Binary file not shown.
Binary file modified Sinkholes_List.xlsx
Binary file not shown.