smicallef / spiderfoot

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
http://www.spiderfoot.net
MIT License
12.71k stars 2.22k forks source link

[suggestion] Stop Forum Spam API #356

Open Dr-Flay opened 5 years ago

Dr-Flay commented 5 years ago

I wonder if the Stop Forum Spam API could help with some email addresses.

It contains a great deal of stolen, disposable and fake email addresses which can be linked to active IPs They label known disposable and fake emails, and blacklisted IPs

They also group related derivatives of an email name which is very handy. Some of the recent spam emails I have been looking up are variations on the same original email name, which it shows if I search for a variation or the original name. Try searching for this active spambot variation e.s.t.at.es.haro.n@gmail.com and you'll see what I mean. https://www.stopforumspam.com/search

Free API https://www.stopforumspam.com/usage

Dr-Flay commented 4 years ago

BTW. the SFS API is now included with other reputation checks in the OPSWAT browser extension. I got a warning when opening a spam domain so saw a basic but handy use of it (wasn't my request to add it).

If you do decide to add it, I wonder if you could also support the sending of text evidence back to SFS ? They support and encourage the inclusion of evidence for each report (I currently do this with a desktop tool). The use of evidence in their system is very important for giving context and making certain patterns more visible.

Worth mentioning, IPs used for long-term mass spambot activity get marked as Toxic IPs, so even without checking the evidence they stand out with big alarm bells in the system.