DNS DADDY
--:--:-- UTC
wire
awaiting upstream telemetry…
live ingest · syncing

The DNS threat landscape, as it moves

Every host below is live malicious infrastructure observed by open abuse feeds — botnet command-and-control, malware distribution and DNS abuse — normalised, scored and mapped against its hosting network.

Live indicators
····

Normalised indicators in the current ingestion window

Critical severity
····

Active infrastructure scored critical by family and status

C2 endpoints
····

Botnet command-and-control hosts under observation

Countries affected
····

Distinct hosting countries attributed via ASN registry data

Global hosting concentration

Country intensity by attributed indicator volume · hover a hot-spot for detail

lowhigh
resolving geospatial layer…
low
high

Top territories

Ranked by live indicator count

  1. awaiting attribution data

Observation timeline

Last seven days · total observations against critical-severity share

Severity distribution

CRIT0
HIGH0
MED0
LOW0

Dominant families

  • no family attribution

Infrastructure relationships

Which hosting networks carry which malware families · hover to isolate a path

no attributable asn ↔ family relationships in this window

Freshest observations

Most recently confirmed malicious infrastructure

full feed
no indicators matched

0 indicators · 0 seen in the last 24h · top territory Unattributed

Sources: abuse.ch Feodo Tracker · abuse.ch URLhaus — public dumps, no credentials. Data is advisory only.