You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

191 lines
10 KiB

  1. {
  2. "asn": {
  3. "url_4": "https://asn.ipinfo.app/api/text/list/",
  4. "url_6": "https://asn.ipinfo.app/api/text/list/",
  5. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add asn_4 \"$1}",
  6. "rule_6": "/^(([0-9A-f]{0,4}:){1,7}[0-9A-f]{0,4}:?(\\/(1?[0-2][0-8]|[0-9][0-9]))?)([[:space:]]|$)/{print \"add asn_6 \"$1}",
  7. "focus": "ASN blocks",
  8. "descurl": "https://asn.ipinfo.app"
  9. },
  10. "bogon": {
  11. "url_4": "https://www.team-cymru.org/Services/Bogons/fullbogons-ipv4.txt",
  12. "url_6": "https://www.team-cymru.org/Services/Bogons/fullbogons-ipv6.txt",
  13. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add bogon_4 \"$1}",
  14. "rule_6": "/^(([0-9A-f]{0,4}:){1,7}[0-9A-f]{0,4}:?(\\/(1?[0-2][0-8]|[0-9][0-9]))?)([[:space:]]|$)/{print \"add bogon_6 \"$1}",
  15. "focus": "Bogon prefixes",
  16. "descurl": "https://team-cymru.com"
  17. },
  18. "country": {
  19. "url_4": "https://www.ipdeny.com/ipblocks/data/aggregated/",
  20. "url_6": "https://www.ipdeny.com/ipv6/ipaddresses/aggregated/",
  21. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add country_4 \"$1}",
  22. "rule_6": "/^(([0-9A-f]{0,4}:){1,7}[0-9A-f]{0,4}:?(\\/(1?[0-2][0-8]|[0-9][0-9]))?)([[:space:]]|$)/{print \"add country_6 \"$1}",
  23. "focus": "Country blocks",
  24. "descurl": "https://www.ipdeny.com/ipblocks"
  25. },
  26. "darklist": {
  27. "url_4": "https://darklist.de/raw.php",
  28. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add darklist_4 \"$1}",
  29. "focus": "Blocks suspicious attacker IPs",
  30. "descurl": "https://darklist.de"
  31. },
  32. "debl": {
  33. "url_4": "https://www.blocklist.de/downloads/export-ips_all.txt",
  34. "url_6": "https://www.blocklist.de/downloads/export-ips_all.txt",
  35. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add debl_4 \"$1}",
  36. "rule_6": "/^(([0-9A-f]{0,4}:){1,7}[0-9A-f]{0,4}:?(\\/(1?[0-2][0-8]|[0-9][0-9]))?)([[:space:]]|$)/{print \"add debl_6 \"$1}",
  37. "focus": "Fail2ban IP blacklist",
  38. "descurl": "https://www.blocklist.de"
  39. },
  40. "doh": {
  41. "url_4": "https://raw.githubusercontent.com/dibdot/DoH-IP-blocklists/master/doh-ipv4.txt",
  42. "url_6": "https://raw.githubusercontent.com/dibdot/DoH-IP-blocklists/master/doh-ipv6.txt",
  43. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add doh_4 \"$1}",
  44. "rule_6": "/^(([0-9A-f]{0,4}:){1,7}[0-9A-f]{0,4}:?(\\/(1?[0-2][0-8]|[0-9][0-9]))?)([[:space:]]|$)/{print \"add doh_6 \"$1}",
  45. "focus": "Public DoH-Provider",
  46. "descurl": "https://github.com/dibdot/DoH-IP-blocklists"
  47. },
  48. "drop": {
  49. "url_4": "https://www.spamhaus.org/drop/drop.txt",
  50. "url_6": "https://www.spamhaus.org/drop/dropv6.txt",
  51. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add drop_4 \"$1}",
  52. "rule_6": "/^(([0-9A-f]{0,4}:){1,7}[0-9A-f]{0,4}:?(\\/(1?[0-2][0-8]|[0-9][0-9]))?)([[:space:]]|$)/{print \"add drop_6 \"$1}",
  53. "focus": "Spamhaus drop compilation",
  54. "descurl": "https://www.spamhaus.org"
  55. },
  56. "dshield": {
  57. "url_4": "https://feeds.dshield.org/block.txt",
  58. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add dshield_4 \"$1 \"/\"$3}",
  59. "focus": "Dshield IP blocklist",
  60. "descurl": "https://www.dshield.org"
  61. },
  62. "edrop": {
  63. "url_4": "https://www.spamhaus.org/drop/edrop.txt",
  64. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add edrop_4 \"$1}",
  65. "focus": "Spamhaus edrop compilation",
  66. "descurl": "https://www.spamhaus.org"
  67. },
  68. "feodo": {
  69. "url_4": "https://feodotracker.abuse.ch/downloads/ipblocklist.txt",
  70. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add feodo_4 \"$1}",
  71. "focus": "Feodo Tracker",
  72. "descurl": "https://feodotracker.abuse.ch"
  73. },
  74. "firehol1": {
  75. "url_4": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level1.netset",
  76. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add firehol1_4 \"$1}",
  77. "focus": "Firehol Level 1 compilation",
  78. "descurl": "https://iplists.firehol.org/?ipset=firehol_level1"
  79. },
  80. "firehol2": {
  81. "url_4": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level2.netset",
  82. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add firehol2_4 \"$1}",
  83. "focus": "Firehol Level 2 compilation",
  84. "descurl": "https://iplists.firehol.org/?ipset=firehol_level2"
  85. },
  86. "firehol3": {
  87. "url_4": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level3.netset",
  88. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add firehol3_4 \"$1}",
  89. "focus": "Firehol Level 3 compilation",
  90. "descurl": "https://iplists.firehol.org/?ipset=firehol_level3"
  91. },
  92. "firehol4": {
  93. "url_4": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/firehol_level4.netset",
  94. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add firehol4_4 \"$1}",
  95. "focus": "Firehol Level 4 compilation",
  96. "descurl": "https://iplists.firehol.org/?ipset=firehol_level4"
  97. },
  98. "greensnow": {
  99. "url_4": "https://blocklist.greensnow.co/greensnow.txt",
  100. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add greensnow_4 \"$1}",
  101. "focus": "Blocks suspicious server IPs",
  102. "descurl": "https://greensnow.co"
  103. },
  104. "iblockads": {
  105. "url_4": "https://list.iblocklist.com/?list=dgxtneitpuvgqqcpfulq&fileformat=cidr&archiveformat=gz",
  106. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add iblockads_4 \"$1}",
  107. "focus": "Advertising blocklist",
  108. "descurl": "https://www.iblocklist.com",
  109. "comp": "gz"
  110. },
  111. "iblockspy": {
  112. "url_4": "https://list.iblocklist.com/?list=llvtlsjyoyiczbkjsxpf&fileformat=cidr&archiveformat=gz",
  113. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add iblockspy_4 \"$1}",
  114. "focus": "Malicious spyware blocklist",
  115. "descurl": "https://www.iblocklist.com",
  116. "comp": "gz"
  117. },
  118. "myip": {
  119. "url_4": "https://myip.ms/files/blacklist/general/latest_blacklist.txt",
  120. "url_6": "https://myip.ms/files/blacklist/general/latest_blacklist.txt",
  121. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add myip_4 \"$1}",
  122. "rule_6": "/^(([0-9A-f]{0,4}:){1,7}[0-9A-f]{0,4}:?(\\/(1?[0-2][0-8]|[0-9][0-9]))?)([[:space:]]|$)/{print \"add myip_6 \"$1}",
  123. "focus": "Myip Live IP blacklist",
  124. "descurl": "https://myip.ms"
  125. },
  126. "nixspam": {
  127. "url_4": "http://www.dnsbl.manitu.net/download/nixspam-ip.dump.gz",
  128. "rule_4": "/(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add nixspam_4 \"$2}",
  129. "focus": "iX spam protection",
  130. "descurl": "http://www.nixspam.org",
  131. "comp": "gz"
  132. },
  133. "proxy": {
  134. "url_4": "https://raw.githubusercontent.com/firehol/blocklist-ipsets/master/proxylists.ipset",
  135. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add proxy_4 \"$1}",
  136. "focus": "Firehol list of open proxies",
  137. "descurl": "https://iplists.firehol.org/?ipset=proxylists"
  138. },
  139. "sslbl": {
  140. "url_4": "https://sslbl.abuse.ch/blacklist/sslipblacklist.csv",
  141. "rule_4": "BEGIN{FS=\",\"}/(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)/{print \"add sslbl_4 \"$2}",
  142. "focus": "SSL botnet IP blacklist",
  143. "descurl": "https://sslbl.abuse.ch"
  144. },
  145. "talos": {
  146. "url_4": "https://www.talosintelligence.com/documents/ip-blacklist",
  147. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add talos_4 \"$1}",
  148. "focus": "Cisco Talos IP Blacklist",
  149. "descurl": "https://talosintelligence.com/reputation_center"
  150. },
  151. "threat": {
  152. "url_4": "https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt",
  153. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add threat_4 \"$1}",
  154. "focus": "Emerging Threats",
  155. "descurl": "https://rules.emergingthreats.net"
  156. },
  157. "tor": {
  158. "url_4": "https://lists.fissionrelays.net/tor/exits-ipv4.txt",
  159. "url_6": "https://lists.fissionrelays.net/tor/exits-ipv6.txt",
  160. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add tor_4 \"$1}",
  161. "rule_6": "/^(([0-9A-f]{0,4}:){1,7}[0-9A-f]{0,4}:?(\\/(1?[0-2][0-8]|[0-9][0-9]))?)([[:space:]]|$)/{print \"add tor_6 \"$1}",
  162. "focus": "Tor exit nodes",
  163. "descurl": "https://fissionrelays.net/lists"
  164. },
  165. "uceprotect1": {
  166. "url_4": "http://wget-mirrors.uceprotect.net/rbldnsd-all/dnsbl-1.uceprotect.net.gz",
  167. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)$/{print \"add uceprotect1_4 \"$1}",
  168. "focus": "Spam protection level 1",
  169. "descurl": "http://www.uceprotect.net/en/index.php",
  170. "comp": "gz"
  171. },
  172. "uceprotect2": {
  173. "url_4": "http://wget-mirrors.uceprotect.net/rbldnsd-all/dnsbl-2.uceprotect.net.gz",
  174. "rule_4": "BEGIN{IGNORECASE=1}/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]+NET[[:space:]]+)/{print \"add uceprotect2_4 \"$1}",
  175. "focus": "Spam protection level 2",
  176. "descurl": "http://www.uceprotect.net/en/index.php",
  177. "comp": "gz"
  178. },
  179. "voip": {
  180. "url_4": "http://www.voipbl.org/update/",
  181. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add voip_4 \"$1}",
  182. "focus": "VoIP fraud blocklist",
  183. "descurl": "http://www.voipbl.org"
  184. },
  185. "yoyo": {
  186. "url_4": "https://pgl.yoyo.org/adservers/iplist.php?ipformat=plain&showintro=0&mimetype=plaintext",
  187. "rule_4": "/^(([0-9]{1,3}\\.){3}(1?[0-9][0-9]?|2[0-4][0-9]|25[0-5])(\\/(1?[0-9]|2?[0-9]|3?[0-2]))?)([[:space:]]|$)/{print \"add yoyo_4 \"$1}",
  188. "focus": "Ad protection blacklist",
  189. "descurl": "https://pgl.yoyo.org/adservers/"
  190. }
  191. }