/blackbook

Blackbook of malware domains

Logo

License

blackbook is a historical (black)list of malicious domains created as part of the periodic automated heuristic check (i.e. WHOIS, HTTP, etc.) of newly reported entries from public lists of malicious URLs (currently CyberCrime, URLhaus, ScumBots, Benkow and VirusTracker). Main goal is listing those that are/were malware dedicated (e.g. C&C) - thus, excluding compromised sites. It is supposed to be used for detection of malware beaconing infected clients by inspection of associated DNS traffic with significantly reduced number of false-positives.

Example

Up-to-date list of domains can be found here.

Note: If you just need a (newline delimited) domain list you can run:

curl https://raw.githubusercontent.com/stamparm/blackbook/master/blackbook.csv 2>/dev/null | cut -d ',' -f 1 | tail -n +2