*(I haven't seen anything regarding "I made a thing" posts, but if there is a better way, just let me know!)
I've put together a couple of threat feeds that might interest you and your teams.
https://github.com/1NobleCyber/ThreatFeed/tree/main/Afraid_org
First is a list of all current Afraid.org (FreeDNS) domains available. Threat actors and scammers will use these for phishing and standing up proxy sites. These sites are frequently miscategorized, so blocking the whole list is what I do.
https://github.com/1NobleCyber/ThreatFeed/tree/main/S3_WebProxies
Second is a list of "found in the wild" AmazonAWS S3 proxies. I have a script checking our weblogs every 5 minutes and determining if it is a known web proxy. I also list all of the variations in the subdomains since the threat actors frequently just switch to a different variation (for example, s3.amazonaws[.]com/SecretProxy123 and s3-external-2.amazonaws[.]com/SecretProxy123). If you are finding others in your environment, put in a pull request and we can get them added.
If you find these helpful and wouldn't mind, give the project a star on Github!
Thanks in advance!
Source: r/k12sysadmin · by /u/Aboredprogrammr