brakmic/Sinkholes

Please remove 195.22.26.248

RichieB2B opened this issue · 0 comments

This repo is a great idea. You probably want to remove 195.22.26.248 from your list as it will generate a lot of false positives. For example last summer a popular advertisement server was sinkholed to that IP.

Anubis has indicated they use this IP to sinkhole domains they are not sure are malicious yet, see https://www.alienvault.com/forums/discussion/10634/multiple-alarms-for-sinkhole-anubis-this-week