GitPedia

Blackbook

Blackbook of malware domains

From stamparm·Updated June 5, 2026·View on GitHub·
·Archived

**blackbook** is a historical (black)list of malicious domains created as part of the periodic automated heuristic check (i.e. WHOIS, HTTP, etc.) of newly reported entries from public lists of malicious URLs (currently [CyberCrime](https://cybercrime-tracker.net/), [URLhaus](https://urlhaus.abuse.ch/), [ScumBots](https://twitter.com/scumbots), [Benkow](http://benkow.cc/passwords.php) and [ViriBack](http://tracker.viriback.com/)). Main goal is listing those that are/were malware **dedicated** (e.... The project is first published in 2018. Key topics include: domains, intrusion-detection, malware-detection, network-forensics, network-monitoring.

Logo

License

blackbook is a historical (black)list of malicious domains created as part of the periodic automated heuristic check (i.e. WHOIS, HTTP, etc.) of newly reported entries from public lists of malicious URLs (currently CyberCrime, URLhaus, ScumBots, Benkow and ViriBack). Main goal is listing those that are/were malware dedicated (e.g. C&C) - thus, excluding compromised sites. It is supposed to be used for detection of malware beaconing infected clients by inspection of associated DNS traffic, with significant reduce of false-positives.

Example

Up-to-date detailed CSV list of domains can be found here, while the raw TXT version can be found here.

Contributors

Showing top 1 contributor by commit count.

View all contributors on GitHub →

This article is auto-generated from stamparm/blackbook via the GitHub API.Last fetched: 6/29/2026