Malware Domain List Active IPs Feed Deprecated
Deprecated. This feed is no longer supported. No available replacement.
Data Enrichment & Threat Intelligence · MalwareDomainList Feed (Deprecated) · Feed
Details
| ID | Malware Domain List Active IPs Feed |
|---|---|
| Provider | Open Source |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.5.0 |
| Docker Image | demisto/python3:3.10.13.74666 |
| Supported Modules | Agentix |
Configuration parameters
feed— Fetch indicatorsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)tlp_color— Traffic Light Protocol ColorfeedExpirationPolicy—cidr_32_to_ip— Set /32 CIDRs as IP IndicatorsfeedExpirationInterval—feedFetchInterval— Feed Fetch IntervalfeedBypassExclusionList— Bypass exclusion listfeedTags— Tagsinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (1)
-
malwaredomainlist-get-indicatorsGets the feed indicators.
from CommonServerPython import * def main(): params = {k: v for k, v in demisto.params().items() if v is not None} params['indicator_type'] = FeedIndicatorType.IP params['url'] = 'http://www.malwaredomainlist.com/hostslist/ip.txt' params['indicator'] = json.dumps({ "regex": r"^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}", }) # Call the main execution of the HTTP API module. feed_main('Malware Domain List Active IPs Feed', params, 'malwaredomainlist') from HTTPFeedApiModule import * # noqa: E402 if __name__ == '__builtin__' or __name__ == 'builtins': main()