The DNS threat landscape, as it moves
Every host below is live malicious infrastructure observed by open abuse feeds — botnet command-and-control, malware distribution and DNS abuse — normalised, scored and mapped against its hosting network.
Normalised indicators in the current ingestion window
Active infrastructure scored critical by family and status
Botnet command-and-control hosts under observation
Distinct hosting countries attributed via ASN registry data
Global hosting concentration
Country intensity by attributed indicator volume · hover a hot-spot for detail
Top territories
Ranked by live indicator count
- awaiting attribution data
Observation timeline
Last seven days · total observations against critical-severity share
Severity distribution
Dominant families
- no family attribution
Infrastructure relationships
Which hosting networks carry which malware families · hover to isolate a path
Freshest observations
Most recently confirmed malicious infrastructure
0 indicators · 0 seen in the last 24h · top territory Unattributed