Skip to content

Commit 4e4fe31

Browse files
committed
Update hosts for extra, spy and update rules
Update IPs for extra, spy and update rules
1 parent 71e978b commit 4e4fe31

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

58 files changed

+6820
-14945
lines changed

README.md

-5
Original file line numberDiff line numberDiff line change
@@ -40,11 +40,6 @@ Tools used to capture traffic :
4040
* [Sysmon](../../wiki/appDevSysmon) : capture + logs
4141
* [Proxifier](../../wiki/devProxifier) : logs
4242

43-
All traffic events are available in the `logs` folder :
44-
45-
* `*-hosts-count.csv` : number of events per host
46-
* `*-unique.csv` : first trigger of an event per host / process / destination port
47-
4843
The `data` folder contains the blocking rules based on domains or IPs detected during the capture process :
4944

5045
* `data/<type>/extra.txt` : Block third party applications

app/bindata/bindata.go

+12-12
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

app/cmds/dev/firewall/firewall.go

+1-1
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ func testIpsByRule(rule string) {
6060

6161
testCsv := path.Join(pathu.Logs, fmt.Sprintf("firewall-test-%s.csv", rule))
6262

63-
fmt.Printf("Get IPs for %s %s... ", rule)
63+
fmt.Printf("Get IPs for %s... ", rule)
6464
fwIps, err := data.GetFirewallIpsByRule(rule)
6565
if err != nil {
6666
print.Error(err)

data/dnscrypt/extra.txt

+25-1
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,19 @@
11
*.2mdn.net
2+
*.appex-rf.msn.com
23
*.messenger.live.com
34
*.msedge.net
45
*.msftncsi.com
6+
*.services.appex.bing.com
57
*.smartscreen.microsoft.com
8+
*.tile.appex.bing.com
69
*.vo.msecnd.net
710
*.weather.microsoft.com
811
*.xboxlive.com
12+
activation-v2.sls.microsoft.com
13+
activation.sls.microsoft.com
914
answers.microsoft.com
15+
api.bing.com
16+
appex-rf.msn.com
1017
apps.skype.com
1118
candycrushsoda.king.com
1219
cdn.content.prod.cms.msn.com
@@ -15,36 +22,53 @@ choice.microsoft.com
1522
choice.microsoft.com.nsatc.net
1623
client.wns.windows.com
1724
clientconfig.passport.net
25+
co2.sls.microsoft.com
26+
crl.microsoft.com
1827
deploy.static.akamaitechnologies.com
1928
dmd.metaservices.microsoft.com
2029
feedback.microsoft-hohm.com
2130
feedback.search.microsoft.com
2231
feedback.windows.com
32+
g.bing.com
2333
g.live.com
34+
global.sam.msn.com
2435
iecvlist.microsoft.com
2536
img-s-msn-com.akamaized.net
37+
img.stb.s-msn.com
2638
insiderppe.cloudapp.net
2739
insiderservice.microsoft.com
2840
licensing.mp.microsoft.com
2941
login.live.com
3042
m.hotmail.com
3143
mediaredirect.microsoft.com
3244
msftncsi.com
45+
next-services.apps.microsoft.com
3346
officeclient.microsoft.com
3447
oneclient.sfx.ms
48+
otf.msn.com
3549
pricelist.skype.com
3650
pti.store.microsoft.com
3751
query.prod.cms.rt.microsoft.com
52+
r20swj13mr.microsoft.com
3853
register.cdpcs.microsoft.com
3954
search.msn.com
4055
storage.live.com
4156
store-images.s-microsoft.com
4257
storeedgefd.dsx.mp.microsoft.com
4358
support.microsoft.com
59+
t.urs.microsoft.com
4460
time.windows.com
4561
tk2.plt.msn.com
62+
uhf.microsoft.com
4663
ui.skype.com
64+
urs.microsoft.com
65+
validation-v2.sls.microsoft.com
66+
validation.sls.microsoft.com
4767
wdcp.microsoft.com
4868
wdcpalt.microsoft.com
4969
wscont.apps.microsoft.com
50-
www.msftconnecttest.com
70+
wscont.apps.microsoft.com.edgesuite.net
71+
wscont1.apps.microsoft.com
72+
wscont2.apps.microsoft.com
73+
www.msftconnecttest.com
74+
www.windowssearch.com

data/dnscrypt/spy.txt

+93-1
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,7 @@
2020
a-msedge.net
2121
ac3.msn.com
2222
activity.windows.com
23+
adl.windows.com
2324
adnexus.net
2425
adnxs.com
2526
ads.msn.com
@@ -84,21 +85,106 @@ by3301-c.1drv.com
8485
by3301-e.1drv.com
8586
c.msn.com
8687
cache.datamart.windows.com
88+
cds1143.lon.llnw.net
89+
cds1203.lon.llnw.net
8790
cds1204.lon.llnw.net
91+
cds1209.lon.llnw.net
92+
cds1219.lon.llnw.net
93+
cds1228.lon.llnw.net
94+
cds1244.lon.llnw.net
95+
cds1257.lon.llnw.net
96+
cds1265.lon.llnw.net
97+
cds1269.lon.llnw.net
98+
cds1273.lon.llnw.net
99+
cds1285.lon.llnw.net
100+
cds1287.lon.llnw.net
88101
cds1289.lon.llnw.net
89102
cds1293.lon.llnw.net
103+
cds1307.lon.llnw.net
104+
cds1310.lon.llnw.net
105+
cds1325.lon.llnw.net
90106
cds1327.lon.llnw.net
107+
cds177.dus.llnw.net
108+
cds20005.stn.llnw.net
109+
cds20404.lcy.llnw.net
110+
cds20411.lcy.llnw.net
111+
cds20415.lcy.llnw.net
112+
cds20416.lcy.llnw.net
91113
cds20417.lcy.llnw.net
114+
cds20424.lcy.llnw.net
115+
cds20425.lcy.llnw.net
92116
cds20431.lcy.llnw.net
117+
cds20435.lcy.llnw.net
118+
cds20440.lcy.llnw.net
119+
cds20443.lcy.llnw.net
120+
cds20445.lcy.llnw.net
93121
cds20450.lcy.llnw.net
122+
cds20452.lcy.llnw.net
94123
cds20457.lcy.llnw.net
124+
cds20461.lcy.llnw.net
125+
cds20469.lcy.llnw.net
95126
cds20475.lcy.llnw.net
127+
cds20482.lcy.llnw.net
128+
cds20485.lcy.llnw.net
129+
cds20495.lcy.llnw.net
130+
cds21205.lon.llnw.net
131+
cds21207.lon.llnw.net
132+
cds21225.lon.llnw.net
133+
cds21229.lon.llnw.net
134+
cds21233.lon.llnw.net
135+
cds21238.lon.llnw.net
96136
cds21244.lon.llnw.net
137+
cds21249.lon.llnw.net
138+
cds21256.lon.llnw.net
139+
cds21257.lon.llnw.net
140+
cds21258.lon.llnw.net
141+
cds21261.lon.llnw.net
142+
cds21267.lon.llnw.net
143+
cds21278.lon.llnw.net
144+
cds21281.lon.llnw.net
145+
cds21293.lon.llnw.net
146+
cds21309.lon.llnw.net
147+
cds21313.lon.llnw.net
148+
cds21321.lon.llnw.net
97149
cds299.lcy.llnw.net
150+
cds308.lcy.llnw.net
151+
cds310.lcy.llnw.net
152+
cds320.lcy.llnw.net
153+
cds333.lcy.llnw.net
154+
cds334.lcy.llnw.net
155+
cds335.lcy.llnw.net
156+
cds339.lcy.llnw.net
157+
cds344.lcy.llnw.net
98158
cds405.lcy.llnw.net
159+
cds406.lcy.llnw.net
160+
cds407.fra.llnw.net
161+
cds416.lcy.llnw.net
162+
cds421.lcy.llnw.net
163+
cds422.lcy.llnw.net
99164
cds425.lcy.llnw.net
165+
cds426.lcy.llnw.net
166+
cds447.lcy.llnw.net
167+
cds458.lcy.llnw.net
100168
cds459.lcy.llnw.net
169+
cds461.lcy.llnw.net
170+
cds468.lcy.llnw.net
171+
cds469.lcy.llnw.net
172+
cds471.lcy.llnw.net
173+
cds483.lcy.llnw.net
174+
cds484.lcy.llnw.net
175+
cds489.lcy.llnw.net
176+
cds493.lcy.llnw.net
101177
cds494.lcy.llnw.net
178+
cds812.lon.llnw.net
179+
cds815.lon.llnw.net
180+
cds818.lon.llnw.net
181+
cds832.lon.llnw.net
182+
cds836.lon.llnw.net
183+
cds840.lon.llnw.net
184+
cds843.lon.llnw.net
185+
cds857.lon.llnw.net
186+
cds868.lon.llnw.net
187+
cds869.lon.llnw.net
102188
cds965.lon.llnw.net
103189
ch1-cor001.api.p001.1drv.com
104190
ch1-cor002.api.p001.1drv.com
@@ -114,6 +200,8 @@ cp101-prod.do.dsp.mp.microsoft.com
114200
cp201-prod.do.dsp.mp.microsoft.com
115201
cp401-prod.do.dsp.mp.microsoft.com
116202
cs1.wpc.v0cdn.net
203+
cy2.settings.data.microsoft.com.akadns.net
204+
db5.settings.data.microsoft.com.akadns.net
117205
diagnostics.support.microsoft.com
118206
disc101-prod.do.dsp.mp.microsoft.com
119207
disc201-prod.do.dsp.mp.microsoft.com
@@ -122,7 +210,9 @@ flex.msn.com
122210
fs.microsoft.com
123211
g.msn.com
124212
geo-prod.do.dsp.mp.microsoft.com
213+
geo.settings.data.microsoft.com.akadns.net
125214
geover-prod.do.dsp.mp.microsoft.com
215+
gwx.windows.com
126216
h1.msn.com
127217
h2.msn.com
128218
hk2.wns.windows.com
@@ -246,6 +336,7 @@ survey.watson.microsoft.com
246336
telemetry.appex.bing.net
247337
telemetry.microsoft.com
248338
telemetry.urs.microsoft.com
339+
teredo.ipv6.microsoft.com
249340
test.activity.windows.com
250341
tsfe.trafficshaping.dsp.mp.microsoft.com
251342
version.hybrid.api.here.com
@@ -257,4 +348,5 @@ vortex.data.microsoft.com
257348
watson.live.com
258349
watson.microsoft.com
259350
win10.ipv6.microsoft.com
260-
win1710.ipv6.microsoft.com
351+
win1710.ipv6.microsoft.com
352+
win8.ipv6.microsoft.com

data/dnscrypt/update.txt

+1
Original file line numberDiff line numberDiff line change
@@ -277,6 +277,7 @@ db6sch102091606.wns.windows.com
277277
db6sch102091607.wns.windows.com
278278
displaycatalog.mp.microsoft.com
279279
download.microsoft.com
280+
fe2.wq.microsoft.com
280281
microsoftwindowsupdate.net
281282
windowsupdate.com
282283
windowupdate.org

data/firewall/extra.txt

+10-1
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,19 @@
1-
### firewall extra (07/05/2018 02:26)
1+
### firewall extra (02/06/2018 22:32)
22
### More info: https://github.com/crazy-max/WindowsSpyBlocker
33

4+
13.78.235.126
5+
13.78.235.247
46
13.79.239.69
57
13.79.239.82
68
13.80.12.54
79
13.107.3.128
10+
13.107.3.254
811
13.107.5.80
912
13.107.5.88
1013
13.107.13.88
1114
13.107.21.200
15+
13.107.46.88
16+
13.107.47.88
1217
23.96.52.53
1318
23.96.208.208
1419
23.97.178.173
@@ -39,6 +44,7 @@
3944
52.164.191.55
4045
52.164.227.208
4146
52.166.110.64
47+
52.166.110.215
4248
52.166.120.77
4349
52.169.71.150
4450
52.170.194.77
@@ -64,6 +70,7 @@
6470
65.52.108.153
6571
65.52.108.154
6672
65.52.108.185
73+
65.55.130.50
6774
65.55.223.0-65.55.223.255
6875
65.55.252.43
6976
104.40.210.32
@@ -76,6 +83,7 @@
7683
104.214.77.221
7784
104.215.146.200
7885
131.253.61.0-131.253.61.255
86+
134.170.178.97
7987
134.170.185.70
8088
134.170.188.248
8189
137.117.235.16
@@ -92,6 +100,7 @@
92100
157.55.134.140
93101
157.55.135.128
94102
157.55.135.130
103+
157.56.57.5
95104
168.63.18.79
96105
191.232.139.2
97106
191.237.208.126

0 commit comments

Comments
 (0)