Skip to content

Commit 4df816b

Browse files
authored
Merge pull request #303 from HiS3/add_shadowserver_list
add new list: List of Shadowserver IP-Ranges.
2 parents cde689a + 1c8b553 commit 4df816b

File tree

2 files changed

+43
-0
lines changed

2 files changed

+43
-0
lines changed

README.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,7 @@ are reused in many other open source projects.
7979
- [rfc6598/list.json](./lists/rfc6598/list.json) - **List of RFC 6598 CIDR blocks** - _Event contains one or more entries part of the Shared Address Space CIDR blocks (RFC 6598)_
8080
- [rfc6761/list.json](./lists/rfc6761/list.json) - **List of RFC 6761 Special-Use Domain Names** - _Event contains one or more entries part of the Special-Use Domain Names (RFC 6761)_
8181
- [second-level-tlds/list.json](./lists/second-level-tlds/list.json) - **Second level TLDs as known by Mozilla Foundation** - _Event contains one or more second level TLDs as attribute with an IDS flag set._
82+
- [shadowserver/list.json](./shadowserver/list.json) - **List of Shadowserver IP-Ranges. Potentially associated with Shadowserver scans.** - Event contains public IPv4 and IPv6 addresses belonging to AS22168 - The Shadowserver Foundation, Inc.
8283
- [security-provider-blogpost/list.json](./lists/security-provider-blogpost/list.json) - **List of known security providers/vendors blog domain** - _Event contains one or more entries of known security providers/vendors blog domain with an IDS flag set_
8384
- [sinkholes/list.json](./lists/sinkholes/list.json) - **List of known sinkholes** - _List of known sinkholes_
8485
- [smtp-receiving-ips/list.json](./lists/smtp-receiving-ips/list.json) - **List of known SMTP receiving IP addresses** - _List of IP addresses for known SMTP servers._

lists/shadowserver/list.json

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
{
2+
"description": "List of Shadowserver IP-Ranges. Potentially associated with Shadowserver scans. based on [https://bgp.he.net/search?search%5Bsearch%5D=shadowserver&commit=Search]",
3+
"list": [
4+
"108.165.44.0/24",
5+
"146.19.20.0/24",
6+
"154.16.223.0/24",
7+
"154.16.230.0/24",
8+
"154.16.240.0/24",
9+
"154.16.250.0/24",
10+
"154.9.2.0/23",
11+
"162.249.64.0/21",
12+
"166.0.195.0/24",
13+
"179.61.168.0/24",
14+
"181.214.234.0/24",
15+
"181.214.245.0/24",
16+
"181.214.62.0/24",
17+
"181.214.90.0/24",
18+
"181.215.138.0/24",
19+
"181.215.145.0/24",
20+
"181.215.208.0/24",
21+
"181.41.192.0/24",
22+
"185.181.1.0/24",
23+
"185.91.204.0/24",
24+
"191.101.103.0/24",
25+
"191.96.127.0/24",
26+
"191.96.20.0/24",
27+
"191.96.22.0/24",
28+
"2001:550:d0c::/48",
29+
"45.143.160.0/24",
30+
"50.114.88.0/24"
31+
],
32+
"matching_attributes": [
33+
"ip-src",
34+
"ip-dst",
35+
"domain|ip",
36+
"ip-dst|port",
37+
"ip-src|port"
38+
],
39+
"name": "Shadowserver IP-Ranges, pot. used for Scanning",
40+
"type": "cidr",
41+
"version": 1
42+
}

0 commit comments

Comments
 (0)