chore: remove dead malwaredomainlist.com integration (#2687)

MALWARE_DB_URL pointed at malwaredomainlist.com, a service that has
been defunct for years, and nothing in the codebase ever fetched or
refreshed it - the only "data" behind malware_check() was a static
snapshot bundled in the repo whose newest entries date back to 2009.
That check ran on every scan against 16+ year old data without
anyone noticing, while maltrail_check() (which does self-update from
a live source) was the only domain check actually doing real work.

Removes malware_check(), its now-unused get_netloc() helper, the
stale bundled data file, and the unused MALWARE_DB_URL setting.
maltrail_check() is unaffected and remains the sole domain check.

Co-authored-by: alanhasn

Co-authored-by: Ajin Abraham <[email protected]>
This commit is contained in:
Vorsynth
2026-09-25 17:19:52 -07:00
committed by GitHub
co-authored by alanhasn Ajin Abraham
parent 1262d3a5ec
commit 7a4785fb3b
3 changed files with 0 additions and 2321 deletions
@@ -26,7 +26,6 @@ class MalwareDomainCheck:
def __init__(self):
self.sig_dir = Path(settings.SIGNATURE_DIR)
self.malwaredomainlist = self.sig_dir / 'malwaredomainlist'
self.maltrail = self.sig_dir / 'maltrail-malware-domains.txt'
self.iplocbin = self.sig_dir / 'IP2LOCATION-LITE-DB5.IPV6.BIN'
self.result = {}
@@ -104,53 +103,6 @@ class MalwareDomainCheck:
if self.IP2Loc:
self.IP2Loc.close()
def malware_check(self):
"""Check domains against malware database."""
try:
mal_db = self.malwaredomainlist
if not mal_db.exists():
logger.warning('Malware domain list not found: %s', mal_db)
return
if not os.access(mal_db, os.R_OK):
logger.error('Insufficient permissions to read: %s', mal_db)
return
with io.open(mal_db,
mode='r',
encoding='utf8',
errors='ignore') as flip:
entry_list = flip.readlines()
if not entry_list:
logger.warning('Malware domain database is empty')
return
for entry in entry_list:
enlist = entry.split('","')
if len(enlist) > 5:
details_dict = {}
details_dict['domain_or_url'] = enlist[1]
details_dict['ip'] = enlist[2]
details_dict['desc'] = enlist[4]
details_dict['bad'] = 'yes'
dmn_url = details_dict['domain_or_url']
for domain in self.domainlist:
dmn_neturl = get_netloc(dmn_url)
if (((dmn_neturl == domain or dmn_neturl == domain[4:])
and (len(dmn_url) > 1))
or details_dict['ip'].startswith(domain)):
self.result[domain] = details_dict
except FileNotFoundError:
logger.error('Malware domain database file not found: %s', mal_db)
except PermissionError:
logger.error('Permission denied accessing malware database: %s', mal_db)
except IOError:
logger.exception('I/O error reading malware database')
except Exception:
logger.exception('[ERROR] Performing Malware check')
def maltrail_check(self):
"""Check domains against maltrail database."""
try:
@@ -221,7 +173,6 @@ class MalwareDomainCheck:
logger.info('Analyzing %d domains', len(self.domainlist))
self.update()
self.malware_check()
self.maltrail_check()
self.gelocation()
@@ -259,22 +210,6 @@ def verify_domain(checkeddom):
return False
def get_netloc(url):
"""Get Domain."""
try:
domain = ''
parse_uri = urlparse(url)
if not parse_uri.scheme:
url = '//' + url
parse_uri = urlparse(url)
domain = '{uri.netloc}'.format(uri=parse_uri)
if verify_domain(domain):
return domain
except Exception:
logger.exception('[ERROR] Extracting Domain form URL')
return None
def sanitize_domain(domain):
"""Sanitize domain to be RFC1034 compliant."""
try:
-1
View File
@@ -127,7 +127,6 @@ WINDOWS_EXTS = ('appx',)
API_ONLY = os.getenv('MOBSF_API_ONLY', '0')
# -----External URLS--------------------------
MALWARE_DB_URL = 'https://www.malwaredomainlist.com/mdlcsv.php'
MALTRAIL_DB_URL = ('https://github.com/stamparm/trails/'
'releases/latest/download/maltrail-malware-domains.txt')
VIRUS_TOTAL_BASE_URL = 'https://www.virustotal.com/api/v3/files'
File diff suppressed because it is too large Load Diff