Threat Intelligence Feeds
Curated, continuously updated collections of Indicators of Compromise: command & control servers, phishing sites, malware distribution points and more. Every feed is downloadable in plain text, STIX2 or MISP format.
| Feed | Author | Downloads | Indicators |
|---|---|---|---|
|
Command and Controls
This feed allocates all the alive Command & Controls from different RAT's and Botnets. It generates low noise when used with border log sources like firewalls. |
agomez | 20625408 | 106450 |
|
Malware Distribution
Collection IoCs that are actively distributing malware. These endpoints are contacted to download following stages after exploitation phase. |
agomez | 17477515 | 48408 |
|
TOR Nodes
Tor, short for The Onion Router, is free and open-source software for enabling anonymous communication. It is intended use is to protect the personal privacy of its users, as well as their freedom and ability to conduct confidential communication by keeping their Internet activities unmonitored. This Feed contains a fresh list of active TOR Nodes |
agomez | 10433438 | 14874 |
|
T1566 - Phishing
Contains Phishing URLs that an adversary uses normally via email or other communication channels to trick a victim into providing sensitive information like passwords or to infect a host. |
agomez | 9099919 | 250000 |
|
Malicious IP
Set of IP addresses with context covering malicious hosts |
agomez | 7772015 | 247878 |
|
Advanced Persistent Threats
Maltiverse APT threat intelligence feed provides IoCs related to highly skilled, sophisticated and focused Attack Groups currenty active. That includes Nation-State Sponsored APTs, Corporate-Sponsored APTs, Cybercriminal Groups, Hacktivist Groups and Terrorist Groups |
agomez | 7372694 | 3342 |
|
Cybercrime
Covers most active and prolific threats used by active organized cybercrime. It contemplates IoCs from diverse malware families in its different stages. |
agomez | 5846405 | 81107 |
|
Malicious URL
Covers malicious URL's disregarding phishing |
agomez | 5069720 | 43214 |
|
Malicious Hostnames
Collection of malicious hostnames disregarding DGA |
agomez | 4359087 | 249990 |
|
Malware
Covering the most dangerous, prevalent and emerging malware |
agomez | 3740836 | 54358 |
|
S0367 - Emotet
Emotet is a Trojan that is primarily spread through spam emails (malspam). The infection may arrive either via malicious script, macro-enabled document files, or malicious link. |
agomez | 3560147 | 1686 |
|
Known Attackers
Contains a selection of active known attacker IPs. SSH Attackers, HTTP Attackers, Spammers and Bots, Mail Spammers, DDoS attackers, Bruteforcers, IMAP Attackers, Compromised Hosts and Low reputation IP's amongst others. This collection can generate so much unmeaningful noise when used against border log sources published to the internet like firewalls. |
agomez | 3482834 | 249150 |
|
S0154 - Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as "adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors". Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system. |
agomez | 3381372 | 115134 |
|
Unreliable subdomains
This collection contains subdomains that are belonging to legit parent domains that are abused and used for non-legit purposes. Some examples are free web hosting sites or dynamic DNS services |
agomez | 1296523 | 1379 |
|
S0650 - Qakbot
QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor |
agomez | 860758 | 7601 |
|
S0561 - GuLoader
GuLoader is a file downloader that has been used since at least December 2019 to distribute a variety of remote administration tool (RAT) malware, including NETWIRE, Agent Tesla, NanoCore, FormBook, and Parallax RAT. |
agomez | 701556 | 348 |
|
Industrial Control Systems
This feeds provides IOC's related to well known malware and threat actors that are normally interested in Industrial Sector plus specific malware families targeting these environments. |
agomez | 687962 | 6035 |
|
S0386 - Ursnif
Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links. Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors. |
agomez | 501633 | 967 |
|
IoT
Feed that contains a collection of alive IoCs relate to Internet of Things threats like Mozi or Mirai |
agomez | 496656 | 24283 |
|
G0099 - APT-C-36
APT-C-36 is a suspected South America espionage group that has been active since at least 2018. The group mainly targets Colombian government institutions as well as important corporations in the financial sector, petroleum industry, and professional manufacturing. |
agomez | 422691 | 47 |
|
S0332 - Remcos
Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. Remcos has been observed being used in malware campaigns. |
agomez | 414393 | 12699 |
|
S0453 - Pony
Pony is a credential stealing malware, though has also been used among adversaries for its downloader capabilities. The source code for Pony Loader 1.0 and 2.0 were leaked online, leading to their use by various threat actors. |
agomez | 404114 | 180 |
|
S0344 - Azorult
Azorult is a commercial Trojan that is used to steal information from compromised hosts. Azorult has been observed in the wild as early as 2016.In July 2018, Azorult was seen used in a spearphishing campaign against targets in North America. Azorult has been seen used for cryptocurrency theft. |
agomez | 398843 | 114 |
|
S0331 - AgentTesla
AgentTesla is a sophisticated and widely-used Remote Access Trojan (RAT) that has been active since 2014. It is a form of malware designed to infiltrate and steal sensitive information from victims' systems, such as login credentials, system information, and other critical data. This Trojan is often delivered through phishing emails with malicious attachments or embedded links. |
agomez | 393659 | 23762 |
|
AsyncRAT
AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection |
h | 389014 | 15017 |
|
S0670 - WarzoneRAT
WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least late 2018. |
agomez | 383690 | 13 |
|
S0002 - Mimikatz
Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. |
agomez | 376531 | 1067 |
|
S0385 - njRAT
njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East |
agomez | 375233 | 1732 |
|
S0334 - DarkComet
DarkComet is a Windows remote administration tool and backdoor. |
agomez | 375116 | 546 |
|
S0379 - Revenge RAT
Revenge RAT is a freely available remote access tool written in .NET (C#). |
agomez | 374679 | 425 |
|
S0262 - QuasarRAT
QuasarRAT is an open-source, remote access tool that has been publicly available on GitHub since at least 2014. QuasarRAT is developed in the C# language. |
agomez | 362627 | 1169 |
|
S0266 - TrickBot
TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns. |
agomez | 356246 | 490 |
|
S0226 - Smoke Loader
Smoke Loader is a malicious bot application that can be used to load other malware.Smoke Loader has been seen in the wild since at least 2011 and has included a number of different payloads. It is notorious for its use of deception and self-protection. It also comes with several plug-ins. |
agomez | 347557 | 254 |
|
G0032 - Lazarus Group
Lazarus Group is a North Korean state-sponsored cyber threat group that has been attributed to the Reconnaissance General Bureau. The group has been active since at least 2009 and was reportedly responsible for the November 2014 destructive wiper attack against Sony Pictures Entertainment as part of a campaign named Operation Blockbuster by Novetta. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. |
agomez | 333244 | 166 |
|
S0483 - IcedID
IcedID is a modular banking malware designed to steal financial information that has been observed in the wild since at least 2017. IcedID has been downloaded by Emotet in multiple campaigns. |
agomez | 332642 | 219 |
|
S0336 - NanoCore
NanoCore is a modular remote access tool developed in .NET that can be used to spy on victims and steal information. It has been used by threat actors since 2013 |
agomez | 330167 | 2786 |
|
G0034 - Sandworm Team
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.This group has been active since at least 2009. |
agomez | 325232 | 14 |
|
S0220 - Chaos
Chaos is Linux malware that compromises systems by brute force attacks against SSH services. Once installed, it provides a reverse shell to its controllers, triggered by unsolicited packets. |
agomez | 324142 | 360 |
|
S0455 - Metamorfo
Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico. |
agomez | 323451 | 21 |
|
G0027 - Emissary Panda
Emissary Panda is a Chinese threat group that is believed to be sponsored by the Chinese Government. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors |
agomez | 322988 | 39 |
|
S0575 - Conti
Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies, particularly those in North America. As with other ransomware families, actors using Conti steal sensitive files and information from compromised networks, and threaten to publish this data unless the ransom is paid. |
agomez | 304419 | 110 |
|
S0534 - Bazar
Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data. |
agomez | 303359 | 112 |
|
G0129 - Mustang Panda
Mustang Panda is a China-based cyber espionage threat actor that was first observed in 2017 but may have been conducting operations since at least 2014. Mustang Panda has targeted government entities, nonprofits, religious, and other non-governmental organizations in the U.S., Europe, Mongolia, Myanmar, Pakistan, and Vietnam, among others. |
agomez | 298656 | 48 |
|
G1006 - Earth Lusca
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. |
agomez | 295804 | 9 |
|
G0010 - Turla
Turla is a Russian-based threat group that has infected victims in over 45 countries, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies since 2004. Heightened activity was seen in mid-2015. Turla is known for conducting watering hole and spearphishing campaigns and leveraging in-house tools and malware. Turla’s espionage platform is mainly used against Windows machines, but has also been seen used against macOS and Linux machines. |
agomez | 291104 | 433 |
|
G0067 - APT37
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018 |
agomez | 290731 | 258 |
|
G0135 - BackdoorDiplomacy
BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia. |
agomez | 289659 | 88 |
|
G1002 - BITTER
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has primarily targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia. |
agomez | 285601 | 32 |
|
S0115 - Crimson
Crimson is a remote access Trojan that has been used by Transparent Tribe since at least 2016 |
agomez | 281108 | 1 |
|
S0198 - Netwire
NETWIRE is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012. |
agomez | 279069 | 4258 |
|
S0384 - Dridex
Dridex is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasury estimated Dridex had infected computers in hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. Dridex was created from the source code of the Bugat banking Trojan (also known as Cridex). |
agomez | 274893 | 1552 |
|
G0121 - Sidewinder
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily focusing on Pakistan, China, Nepal, and Afghanistan. |
agomez | 268866 | 225 |
|
S0253 - RunningRAT
RunningRAT is a remote access tool that appeared in operations surrounding the 2018 Pyeongchang Winter Olympics along with Gold Dragon and Brave Prince. |
agomez | 267433 | 27 |
|
G0004 - Ke3chang
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010. |
agomez | 230812 | 14 |
|
G0049 - OilRig
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government, energy, chemical, and telecommunications. It appears the group carries out supply chain attacks, leveraging the trust relationship between organizations to attack their primary targets. FireEye assesses that the group works on behalf of the Iranian government based on infrastructure details that contain references to Iran, use of Iranian infrastructure, and targeting that aligns with nation-state interests. |
agomez | 222095 | 104 |
|
Anonymization IPs
|
agomez | 48444 | 249962 |
|
Malicious Anonymization IPs
List of Malicious Anonymization IPs |
h | 42748 | 109473 |
|
S1213 - Lumma Stealer
Lumma Stealer is a Malware-as-a-Service (MaaS) infostealer that targets Windows systems to steal sensitive data such as passwords, crypto wallets, and 2FA tokens. It spreads through phishing, fake downloads, and malicious websites, allowing attackers to collect and sell stolen information or use it to deploy other malware. |
agomez | 35884 | 2777 |
|
TEST FEED Prevent CrowdStrike
|
test11 | 33495 | 1 |