About OSINT feeds

February 27, 2024

ID 175360

This section describes OSINT feeds supported by Kaspersky CyberTrace.

OSINT feeds are publicly available threat intelligence data sources provided by organizations and individuals.

OSINT feeds supported by Kaspersky CyberTrace

Kaspersky CyberTrace supports OSINT feeds from the following sources:

  • Abuse.ch

    This source has several associated sources of information:

    • Feodo Tracker is an abuse.ch project that has the goal of sharing botnet C&C servers associated with the Feodo malware family (Dridex, Emotet/Heodo).
    • SSLBL is an abuse.ch project that has the goal of detecting malicious SSL connections, by identifying the SSL certificates used by botnet C&C servers and adding them to a denylist.
  • Proofpoint ET intelligence

    This source provides information about new threats.

  • BlockList.de

    This is a free and voluntary service provided by a Fraud/Abuse specialist, whose servers are often attacked.

    BlockList.de has reported more than 70,000 attacks in twelve hours in real time and uses Whois (abuse-mailbox, abuse@, security@, email, remarks), RIPE Abuse Finder, and Abuse Contact Database from abusix.org to find the abuse addresses assigned to the attacking hosts.

  • Cyber Crime Tracker

    Cyber Crime Tracker monitors and tracks various malware families that are used to perpetrate cyber crimes, such as banking trojans and ransomware. It lists mainly malware C&Cs, and file hashes of Zeus and Zeus-originated malware families.

The following table lists supported OSINT feeds:

OSINT feeds

Identifier

Description

Link

Abuse.ch_Feodo_BlockIP

Feodo IP Blocklist

https://feodotracker.abuse.ch/downloads/ipblocklist.txt

Abuse.ch_SSL_Certificate_BlockIP

Botnet C2 IP Denylist

https://sslbl.abuse.ch/

Abuse.ch_SSL_Certificate_BlockHash

SSL Certificate Denylist

https://sslbl.abuse.ch/

Blocklist.de_BlockIP

Blocklist.de IP Blocklist

https://lists.blocklist.de/lists/all.txt

CyberCrime_Tracker_BlockUrl

Cyber Crime Tracker URL Blocklist

http://cybercrime-tracker.net/all.php

EmergingThreats_BlockIP

Raw IPs for the firewall block lists

https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt

EmergingThreats_CompromisedIP

Compromised IP addresses

https://rules.emergingthreats.net/blockrules/compromised-ips.txt

The OSINT feeds in the table above are maintained by third parties only. Some URLs in the table may, for various reasons, become obsolete over time.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.