Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ransomwaretracker.abuse.ch discontinued #184

Closed
rkmbaxed opened this issue Jan 7, 2020 · 5 comments · Fixed by #183 or #185
Closed

ransomwaretracker.abuse.ch discontinued #184

rkmbaxed opened this issue Jan 7, 2020 · 5 comments · Fixed by #183 or #185
Assignees

Comments

@rkmbaxed
Copy link

rkmbaxed commented Jan 7, 2020

https://ransomwaretracker.abuse.ch/ says bye bye

Ransomware Tracker has been discontinued on Dec 8th, 2019

The Data Adadpter for abuse.ch ransomware Domains and IP gets no new food.

Expected Behavior

Use of URLhaus instead (https://urlhaus.abuse.ch/api/)

Current Behavior

ransomwaretracker.abuse.ch stops its service.

Possible Solution

Use of URLhaus instead (https://urlhaus.abuse.ch/api/)

@ortizleo
Copy link

ortizleo commented May 6, 2020

+1
Please!

@H2Cyber
Copy link

H2Cyber commented Nov 22, 2020

Does this mean that the Abuse.ch Ransomware tracker lookups in Graylog are no longer useful ?

@rkmbaxed
Copy link
Author

When they did not changed anything in the meantime, that it is not useful since Dec 8th, 2019

@waab76
Copy link
Contributor

waab76 commented Nov 25, 2020

Had a look at the the API for urlhaus.abuse.ch and it seems like it might support something roughly like the ransomware URL data adapter, but I'm not sure there's a solution for the Domain and IP ransomware adapters. Discussing with the team about the best path forward for this issue.

@H2Cyber
Copy link

H2Cyber commented Nov 25, 2020

I have removed the abuse.ch plugin, rules, pipeline, and events/alerts from my setup, to save the wasted processing power and storage space.

The rest of the GL userbase should probably be prompted to do so (be it via the notification system or in a future update).

Also the blog entry on the GL website on the abuse.ch setup should probably get updated.

Finally I think it would be better to treat the URLhaus integration separately as it has a different use case.

@waab76 waab76 self-assigned this Nov 30, 2020
@waab76 waab76 transferred this issue from Graylog2/graylog2-server Dec 2, 2020
@waab76 waab76 linked a pull request Dec 2, 2020 that will close this issue
@waab76 waab76 linked a pull request Dec 10, 2020 that will close this issue
@waab76 waab76 reopened this Dec 10, 2020
@waab76 waab76 closed this as completed Dec 10, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
4 participants