mirror of
https://github.com/MobSF/Mobile-Security-Framework-MobSF.git
synced 2026-10-11 22:50:09 +00:00
chore: remove dead malwaredomainlist.com integration (#2687)
MALWARE_DB_URL pointed at malwaredomainlist.com, a service that has been defunct for years, and nothing in the codebase ever fetched or refreshed it - the only "data" behind malware_check() was a static snapshot bundled in the repo whose newest entries date back to 2009. That check ran on every scan against 16+ year old data without anyone noticing, while maltrail_check() (which does self-update from a live source) was the only domain check actually doing real work. Removes malware_check(), its now-unused get_netloc() helper, the stale bundled data file, and the unused MALWARE_DB_URL setting. maltrail_check() is unaffected and remains the sole domain check. Co-authored-by: alanhasn Co-authored-by: Ajin Abraham <[email protected]>
This commit is contained in:
co-authored by
alanhasn
Ajin Abraham
parent
1262d3a5ec
commit
7a4785fb3b
@@ -26,7 +26,6 @@ class MalwareDomainCheck:
|
||||
|
||||
def __init__(self):
|
||||
self.sig_dir = Path(settings.SIGNATURE_DIR)
|
||||
self.malwaredomainlist = self.sig_dir / 'malwaredomainlist'
|
||||
self.maltrail = self.sig_dir / 'maltrail-malware-domains.txt'
|
||||
self.iplocbin = self.sig_dir / 'IP2LOCATION-LITE-DB5.IPV6.BIN'
|
||||
self.result = {}
|
||||
@@ -104,53 +103,6 @@ class MalwareDomainCheck:
|
||||
if self.IP2Loc:
|
||||
self.IP2Loc.close()
|
||||
|
||||
def malware_check(self):
|
||||
"""Check domains against malware database."""
|
||||
try:
|
||||
mal_db = self.malwaredomainlist
|
||||
|
||||
if not mal_db.exists():
|
||||
logger.warning('Malware domain list not found: %s', mal_db)
|
||||
return
|
||||
|
||||
if not os.access(mal_db, os.R_OK):
|
||||
logger.error('Insufficient permissions to read: %s', mal_db)
|
||||
return
|
||||
|
||||
with io.open(mal_db,
|
||||
mode='r',
|
||||
encoding='utf8',
|
||||
errors='ignore') as flip:
|
||||
entry_list = flip.readlines()
|
||||
|
||||
if not entry_list:
|
||||
logger.warning('Malware domain database is empty')
|
||||
return
|
||||
|
||||
for entry in entry_list:
|
||||
enlist = entry.split('","')
|
||||
if len(enlist) > 5:
|
||||
details_dict = {}
|
||||
details_dict['domain_or_url'] = enlist[1]
|
||||
details_dict['ip'] = enlist[2]
|
||||
details_dict['desc'] = enlist[4]
|
||||
details_dict['bad'] = 'yes'
|
||||
dmn_url = details_dict['domain_or_url']
|
||||
for domain in self.domainlist:
|
||||
dmn_neturl = get_netloc(dmn_url)
|
||||
if (((dmn_neturl == domain or dmn_neturl == domain[4:])
|
||||
and (len(dmn_url) > 1))
|
||||
or details_dict['ip'].startswith(domain)):
|
||||
self.result[domain] = details_dict
|
||||
except FileNotFoundError:
|
||||
logger.error('Malware domain database file not found: %s', mal_db)
|
||||
except PermissionError:
|
||||
logger.error('Permission denied accessing malware database: %s', mal_db)
|
||||
except IOError:
|
||||
logger.exception('I/O error reading malware database')
|
||||
except Exception:
|
||||
logger.exception('[ERROR] Performing Malware check')
|
||||
|
||||
def maltrail_check(self):
|
||||
"""Check domains against maltrail database."""
|
||||
try:
|
||||
@@ -221,7 +173,6 @@ class MalwareDomainCheck:
|
||||
|
||||
logger.info('Analyzing %d domains', len(self.domainlist))
|
||||
self.update()
|
||||
self.malware_check()
|
||||
self.maltrail_check()
|
||||
self.gelocation()
|
||||
|
||||
@@ -259,22 +210,6 @@ def verify_domain(checkeddom):
|
||||
return False
|
||||
|
||||
|
||||
def get_netloc(url):
|
||||
"""Get Domain."""
|
||||
try:
|
||||
domain = ''
|
||||
parse_uri = urlparse(url)
|
||||
if not parse_uri.scheme:
|
||||
url = '//' + url
|
||||
parse_uri = urlparse(url)
|
||||
domain = '{uri.netloc}'.format(uri=parse_uri)
|
||||
if verify_domain(domain):
|
||||
return domain
|
||||
except Exception:
|
||||
logger.exception('[ERROR] Extracting Domain form URL')
|
||||
return None
|
||||
|
||||
|
||||
def sanitize_domain(domain):
|
||||
"""Sanitize domain to be RFC1034 compliant."""
|
||||
try:
|
||||
|
||||
@@ -127,7 +127,6 @@ WINDOWS_EXTS = ('appx',)
|
||||
API_ONLY = os.getenv('MOBSF_API_ONLY', '0')
|
||||
|
||||
# -----External URLS--------------------------
|
||||
MALWARE_DB_URL = 'https://www.malwaredomainlist.com/mdlcsv.php'
|
||||
MALTRAIL_DB_URL = ('https://github.com/stamparm/trails/'
|
||||
'releases/latest/download/maltrail-malware-domains.txt')
|
||||
VIRUS_TOTAL_BASE_URL = 'https://www.virustotal.com/api/v3/files'
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user