Once upon a time, in 2015, I used to offer a feed of malware URLs, it was hosted in a subdomain of mine at malwareurls.joxeankoret.com. I closed it down +10 years ago because it caused me too many problems and costed quite some money. Today, still today, I get many requests a day for that fucking malware feed I took down on 2015.
@buherator This has been my last attempt to stop some of them:
$ cat /var/www/normal.txt
X5O!P%@ap[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
@joxean Still referenced in many places https://github.com/search?q=malwareurls.joxeankoret.com&type=code
It might difficult to remove all the references. We tried to maintain the osint feed for misp but it’s difficult to know the status of a feed. We wanted to have a special HTTP header or even a file to give the status in a standard format for the publisher.