Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

GitHub RadarBlue team tool

Chocolate4U/Iran-v2ray-rules

Enhanced v2ray/xray and v2ray/xray-clients routing rules with built-in Iranian domains and a focus on security and adblocking. Primary language: Shell. 677 stars.

Shell677 stars53 forkspushed Jun 12, 2026GPL-3.0

Project links:Open GitHub projectBack to radar

README Preview

Fetched from GitHub

<picture> <source media="(prefers-color-scheme: dark)" srcset="assets/logo-white.png"> <source media="(prefers-color-scheme: light)" srcset="assets/logo-dark.png"> <img alt="a logo for iran v2ray rules in both dark and light mode" src="assets/logo-dark.png"> </picture>

<p align="center"> <img alt="GitHub Workflow Status" src="https://img.shields.io/github/actions/workflow/status/Chocolate4U/Iran-v2ray-rules/release.yml?event=schedule&style=for-the-badge&logo=github&cacheSeconds=3600"> <img alt="GitHub release" src="https://img.shields.io/github/v/release/Chocolate4U/Iran-v2ray-rules?style=for-the-badge&cacheSeconds=3600"> <img alt="GitHub Release Date" src="https://img.shields.io/github/release-date/Chocolate4U/Iran-v2ray-rules?display_date=published_at&style=for-the-badge&cacheSeconds=3600"> <img alt="GitHub" src="https://img.shields.io/github/license/Chocolate4U/Iran-v2ray-rules?style=for-the-badge&color=blue&cacheSeconds=3600"> </p>

فارسی

:writing_hand: Introduction

This is an Enhanced and All-in-One set of geo-location routing files optimized for Iranian users to use in v2ray/xray and all their compatible clients.

:bulb: For Sing-Box geolocation rules please refer to Iran Sing-Box Rules :bulb: For Clash geolocation rules please refer to Iran Clash Rules

:arrow_down: How to download

<picture><source media="(prefers-color-scheme: dark)" srcset="https://cdn.simpleicons.org/github/white"><source media="(prefers-color-scheme: light)" srcset="https://cdn.simpleicons.org/github/dark"><img height="32" width="32" alt="github logo in dark and light mode." src="https://cdn.simpleicons.org/github/dark"></picture> From GitHub

geoip.dat

https://raw.githubusercontent.com/Chocolate4U/Iran-v2ray-rules/release/geoip.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading geoip.dat file from github" src="assets/geoip.png" width="200" height="200"> </details>

---

geosite.dat

https://raw.githubusercontent.com/Chocolate4U/Iran-v2ray-rules/release/geosite.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading geosite.dat file from github" src="assets/geosite.png" width="200" height="200"> </details>

---

geoip-lite.dat

https://raw.githubusercontent.com/Chocolate4U/Iran-v2ray-rules/release/geoip-lite.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading geoip-lite.dat file from github" src="assets/geoip-lite.png" width="200" height="200"> </details>

---

geosite-lite.dat

https://raw.githubusercontent.com/Chocolate4U/Iran-v2ray-rules/release/geosite-lite.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading geosite-lite.dat file from github" src="assets/geosite-lite.png" width="200" height="200"> </details>

---

security-ip.dat

https://raw.githubusercontent.com/Chocolate4U/Iran-v2ray-rules/release/security-ip.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading security-ip.dat file from github" src="assets/security-ip.png" width="200" height="200"> </details>

---

security.dat

https://raw.githubusercontent.com/Chocolate4U/Iran-v2ray-rules/release/security.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading security.dat file from github" src="assets/security.png" width="200" height="200"> </details>

---

<picture><source media="(prefers-color-scheme: dark)" srcset="https://cdn.simpleicons.org/jsdelivr/white"><source media="(prefers-color-scheme: light)" srcset="https://cdn.simpleicons.org/jsdelivr/dark"><img height="32" width="32" alt="github logo in dark and light mode." src="https://cdn.simpleicons.org/jsdelivr/dark"></picture> From jsDelivr CDN

geoip.dat

https://cdn.jsdelivr.net/gh/chocolate4u/Iran-v2ray-rules@release/geoip.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading geoip.dat file from jsdelivr" src="assets/geoip-jsdelivr.png" width="200" height="200"> </details>

---

geosite.dat

https://cdn.jsdelivr.net/gh/chocolate4u/Iran-v2ray-rules@release/geosite.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading geosite.dat file from jsdelivr" src="assets/geosite-jsdelivr.png" width="200" height="200"> </details>

---

geoip-lite.dat

https://cdn.jsdelivr.net/gh/chocolate4u/Iran-v2ray-rules@release/geoip-lite.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading geoip-lite.dat file from jsdelivr" src="assets/geoip-lite-jsdelivr.png" width="200" height="200"> </details>

---

geosite-lite.dat

https://cdn.jsdelivr.net/gh/chocolate4u/Iran-v2ray-rules@release/geosite-lite.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading geosite-lite.dat file from jsdelivr" src="assets/geosite-lite-jsdelivr.png" width="200" height="200"> </details>

---

security-ip.dat

https://cdn.jsdelivr.net/gh/chocolate4u/Iran-v2ray-rules@release/security-ip.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading security-ip.dat file from jsdelivr" src="assets/security-ip-jsdelivr.png" width="200" height="200"> </details>

---

security.dat

https://cdn.jsdelivr.net/gh/chocolate4u/Iran-v2ray-rules@release/security.dat

<details> <summary><strong>QR Code</strong></summary> <img alt="QrCode for downloading security.dat file from jsdelivr" src="assets/security-jsdelivr.png" width="200" height="200"> </details>

---

:computer: Usage

v2ray/xray core

Add the following to your v2ray/xray client configuration:

"outbounds": [
  {
    "tag": "direct",
    "protocol": "freedom",
    "settings": {}
  },
  {
    "tag": "block",
    "protocol": "blackhole",
    "settings": {}
  }
],
"routing": {
  "domainStrategy": "IPIfNonMatch",
  "rules": [
    {
      "outboundTag": "block",
      "domain": [
        "geosite:category-ads-all",
        "geosite:malware",
        "geosite:phishing",
        "geosite:cryptominers"
      ],
      "type": "field"
    },
    {
      "outboundTag": "block",
      "ip": [
        "geoip:malware",
        "geoip:phishing"
      ],
      "type": "field"
    },
    {
      "outboundTag": "direct",
      "domain": [
        "geosite:ir"
      ],
      "type": "field"
    },
    {
      "outboundTag": "direct",
      "ip": [
        "geoip:ir",
        "geoip:private"
      ],
      "type": "field"
    },
  ]
}

:page_with_curl: Categories

GeoIP

<details> <summary><strong>Categories in <code>geoip.dat</code></strong></summary>

  • Contains IP Addresses of all countries from Maxmind and IP2Location databases.
  • geoip:ir

Contains Iran IP addresses from Maxmind and IP2Location databases, IP addresses of Iranian messengers such as eitaa, rubika, etc. and IP addresses of arvancloud, derakcloud, iranserver and parspack CDNs.

  • geoip:private

Contains a list of local (LAN) IP addresses.

  • geoip:arvancloud

Contains the IP addresses of ArvanCloud.ir CDN. :information_source: Integrated in geoip:ir and no longer needed to be written as a separate rule.

  • geoip:derakcloud

Contains the IP addresses of Derak.cloud CDN. :information_source: Integrated in geoip:ir and no longer needed to be written as a separate rule.

  • geoip:iranserver

Contains the IP addresses of IranServer.com CDN. :information_source: Integrated in geoip:ir and no longer needed to be written as a separate rule.

  • geoip:parspack

Contains the IP addresses of ParsPack.com CDN. :information_source: Integrated in geoip:ir and no longer needed to be written as a separate rule.

  • geoip:cloudflare

Contains the IP addresses of Cloudflare CDN.

  • geoip:cloudfront

Contains the IP addresses of Cloudfront CDN.

  • geoip:fastly

Contains the IP addresses of Fastly CDN.

  • geoip:gcore

Contains the IP addresses of G-Core CDN.

  • geoip:google

Contains the IP addresses of Google, GoogleCloud and GoogleBot.

  • geoip:amazon

Contains the IP addresses of Amazon and Amazon Web Services (AWS).

  • geoip:microsoft

Contains the IP addresses of Microsoft and Azure Platform.

  • geoip:netflix

Contains the IP addresses of Netflix.

  • geoip:bing

Contains the IP addresses of Bing and Bingbot.

  • geoip:github

Contains the IP addresses of GitHub.

  • geoip:facebook

Contains the IP addresses of the Meta ecosystem, including Facebook, Instagram and WhatsApp.

  • geoip:twitter

Contains the IP addresses of Twitter (now called X!).

  • geoip:telegram

Contains the IP addresses of Telegram Messenger.

  • geoip:oracle

Contains the IP addresses of Oracle Cloud.

  • geoip:digitalocean

Contains the IP addresses of DigitalOcean-related services.

  • geoip:linode

Contains the IP addresses of Linode-related services.

  • geoip:openai

Contains the IP addresses of OpenAI and ChatGPT.

  • geoip:tor

Contains the IP addresses of Tor exit nodes.

  • geoip:phishing

Contains Phishing IP addresses.

  • geoip:malware

Contains Active Malware IP addresses.

</details>

<details> <summary><strong>Categories in <code>geoip-lite.dat</code></strong></summary>

  • geoip:ir

Contains Iran IP addresses from Maxmind and IP2Location databases, IP addresses of Iranian messengers such as eitaa, rubika, etc. and IP addresses of arvancloud, derakcloud, iranserver and parspack CDNs.

  • geoip:private

Contains a list of local (LAN) IP addresses.

</details>

<details> <summary><strong>Categories in <code>security-ip.dat</code></strong></summary>

  • geoip:phishing

Contains Phishing IP addresses.

  • geoip:malware

Contains Active Malware IP addresses.

</details>

<details> <summary><strong>Categories in <code>geoip-services.dat</code></strong></summary>

  • geoip:arvancloud

Contains the IP addresses of ArvanCloud.ir CDN.

  • geoip:derakcloud

Contains the IP addresses of Derak.cloud CDN.

  • geoip:iranserver

Contains the IP addresses of IranServer.com CDN.

  • geoip:parspack

Contains the IP addresses of ParsPack.com CDN.

  • geoip:cloudflare

Contains the IP addresses of Cloudflare CDN.

  • geoip:cloudfront

Contains the IP addresses of Cloudfront CDN.

  • geoip:fastly

Contains the IP addresses of Fastly CDN.

  • geoip:gcore

Contains the IP addresses of G-Core CDN.

  • geoip:google

Contains the IP addresses of Google, GoogleCloud and GoogleBot.

  • geoip:amazon

Contains the IP addresses of Amazon and Amazon Web Services (AWS).

  • geoip:microsoft

Contains the IP addresses of Microsoft and Azure Platform.

  • geoip:netflix

Contains the IP addresses of Netflix.

  • geoip:bing