Tracker
Ransomware Tracker to distinguishes between the following threats:
- Ransomware botnet Command & Control servers (C&Cs)
- Ransomware Payment Sites
- Ransomware Distribution Sites
Each entry in Ransomware Tracker is tagged to a threat and a malware. Currently, the following Ransomware families are tracked:
- TeslaCrypt
- CryptoWall (if you do want to know more about CryptoWall, check out CryptoWall Tracker)
- TorrentLocker
- PadCrypt
- Locky
- CTB-Locker
- FAKBEN
- PayCrypt
New submissions for Ransomware Tracker are warmly welcome. You can send new additions to rt-RintANel@abuse.ch (remove all letters in uppercase). Malware binaries that you suspect to be associated with a certain Ransomware family can be send to rt-malwSOareM@abuse.ch (remove all letters in uppercase) for analysis.
Search
You can search for a host or URL using the following search form:
Set a filter for the list below
Below is a list of Ransomware botnet C&C servers tracked by Ransomware Tracker. You have the possibility to filter the list below using certain pre-defined filters shown below.
General filters: Remove filter (Show all) | Online hosts
Filter by threat: | |
Filter by malware: | | | | | | | | | | |
Dateadded (UTC) | Threat | Malware | Host (?Domain name or IP address used by the Ransomware. The leading dots (Red, Green, Grey) indicate whether the Host is active or not. Red = Online Green = Offline Grey = Unknown) | Domain Registrar (?In some cases Ransomware Tracker is not able to determine the sponsoring Registrar of a domain name. Thats either because the Registry does not reveal this information in the whois or because the Registry doesn't offer a whois service.) | IP address (ASN, Country) |
---|---|---|---|---|---|
2016-08-15 11:40 | www.scoutvda.it | TISCALIDOMAIN-REG | 213.205.40.169 (![]() | ||
2016-08-15 11:39 | devierdemuur.50webs.com | GODADDY.COM, LLC | 198.23.52.99 (![]() | ||
2016-08-15 11:18 | unocl45trpuoefft.zn9cme.bid | Eranet International Limited | (n/a) | ||
2016-08-15 10:12 | marcinha.50webs.com | GODADDY.COM, LLC | 162.210.101.23 (![]() | ||
2016-08-15 10:11 | www.reniero.org | Ascio Technologies, Inc. Danmark[...] | 213.205.40.169 (![]() | ||
2016-08-15 10:11 | www.vinyljazzrecords.com | ASCIO TECHNOLOGIES, INC. DANMARK[...] | 213.205.40.169 (![]() | ||
2016-08-15 10:11 | xn--kukuk-gstrow-jlb.de | (n/a) | |||
2016-08-15 10:10 | marimo1963430.web.fc2.com | INSTRA CORPORATION PTY, LTD. | 104.244.99.44 (![]() | ||
2016-08-15 10:09 | www.pescatoridelpontile.it | TOPHOST-REG | (n/a) | ||
2016-08-15 10:09 | orquestracaravan.com | REGISTER.IT SPA | 81.88.57.70 (![]() | ||
2016-08-15 10:08 | mondialmt2.hi2.ro | ICI - ROTLD | (n/a) | ||
2016-08-15 10:07 | www.lancerortho.com | NETWORK SOLUTIONS, LLC. | 85.187.149.233 (![]() | ||
2016-08-15 08:54 | pmenboeqhyrpvomq.gnuvaw.bid | Eranet International Limited | (n/a) | ||
2016-08-15 06:42 | unocl45trpuoefft.9lx4s6.bid | Eranet International Limited | (n/a) | ||
2016-08-15 06:21 | 52uo5k3t73ypjije.snwy26.top | Alpnames Limited | (n/a) | ||
2016-08-15 04:02 | unocl45trpuoefft.sp4o1t.bid | Eranet International Limited | (n/a) | ||
2016-08-15 03:25 | unocl45trpuoefft.lk0bzc.top | Eranet International Limited | (n/a) | ||
2016-08-14 21:18 | unocl45trpuoefft.knowhands.us | PDR Ltd. d/b/a PublicDomainRegis[...] | (n/a) | ||
2016-08-14 20:59 | 52uo5k3t73ypjije.hv42mo.bid | Eranet International Limited | (n/a) | ||
2016-08-14 19:33 | 52uo5k3t73ypjije.ep493u.top | Eranet International Limited | (n/a) | ||
2016-08-14 18:13 | 52uo5k3t73ypjije.dkro3u.top | Eranet International Limited | (n/a) | ||
2016-08-14 14:34 | 52uo5k3t73ypjije.eoivrm.bid | Eranet International Limited | (n/a) | ||
2016-08-14 13:54 | 52uo5k3t73ypjije.u2r7tm.bid | Eranet International Limited | (n/a) | ||
2016-08-14 13:21 | 52uo5k3t73ypjije.xtppp8.bid | Eranet International Limited | (n/a) | ||
2016-08-14 11:56 | 52uo5k3t73ypjije.7asel7.top | Eranet International Limited | (n/a) | ||
2016-08-14 11:13 | 52uo5k3t73ypjije.5zxii2.bid | Eranet International Limited | (n/a) | ||
2016-08-14 10:12 | unocl45trpuoefft.086ux2.top | Eranet International Limited | (n/a) | ||
2016-08-14 09:57 | unocl45trpuoefft.rie9py.bid | Eranet International Limited | (n/a) | ||
2016-08-14 07:24 | 52uo5k3t73ypjije.gnuvaw.bid | Eranet International Limited | (n/a) | ||
2016-08-14 06:59 | unocl45trpuoefft.givxuf.bid | Eranet International Limited | (n/a) | ||
2016-08-14 06:41 | unocl45trpuoefft.uaol08.bid | Eranet International Limited | (n/a) | ||
2016-08-14 04:41 | 52uo5k3t73ypjije.vt3dg6.bid | Eranet International Limited | (n/a) | ||
2016-08-14 02:49 | 52uo5k3t73ypjije.sx90yk.bid | Eranet International Limited | (n/a) | ||
2016-08-14 00:46 | unocl45trpuoefft.9u3iy1.top | Eranet International Limited | (n/a) | ||
2016-08-13 23:03 | 52uo5k3t73ypjije.en3oyw.bid | Eranet International Limited | (n/a) | ||
2016-08-13 22:34 | unocl45trpuoefft.meetsface.win | Alpnames Limited | (n/a) | ||
2016-08-13 21:48 | 52uo5k3t73ypjije.7wrwp4.top | Eranet International Limited | (n/a) | ||
2016-08-13 18:03 | 52uo5k3t73ypjije.gtnfgj.top | Eranet International Limited | (n/a) | ||
2016-08-13 17:32 | 52uo5k3t73ypjije.ywszbe.bid | Eranet International Limited | (n/a) | ||
2016-08-13 14:26 | gsmdqrmqddqtuv.xyz | Gandi SAS | 54.67.27.43 (![]() | ||
2016-08-13 12:48 | pmenboeqhyrpvomq.y7fjr4.bid | Eranet International Limited | (n/a) | ||
2016-08-13 10:28 | 52uo5k3t73ypjije.0nyi6l.bid | Eranet International Limited | (n/a) | ||
2016-08-13 09:55 | 52uo5k3t73ypjije.r2ok0b.bid | Eranet International Limited | (n/a) | ||
2016-08-13 09:01 | 52uo5k3t73ypjije.uw7w05.bid | Eranet International Limited | (n/a) | ||
2016-08-13 08:40 | digiwebstore.fr | OVH | 213.186.33.19 (![]() | ||
2016-08-12 15:51 | 52uo5k3t73ypjije.lrraca.bid | Eranet International Limited | (n/a) | ||
2016-08-12 13:22 | pmenboeqhyrpvomq.0nyi6l.bid | Eranet International Limited | (n/a) | ||
2016-08-12 13:21 | portraitstaffa.de | (n/a) | |||
2016-08-12 13:21 | sportpferde-weihmayer.homepage.t-online.de | 80.150.6.138 (![]() | |||
2016-08-12 13:21 | www.bitupont.hu | 185.51.191.25 (![]() | |||
2016-08-12 13:21 | files.zdaspb.ru | R01-RU | 80.64.105.78 (![]() | ||
2016-08-12 13:20 | www.herinvest.be | Telenet BVBA | (n/a) | ||
2016-08-12 13:20 | www.milleniumbar.it | TISCALIDOMAIN-REG | 213.205.40.169 (![]() | ||
2016-08-12 13:19 | muteofficial.web.fc2.com | INSTRA CORPORATION PTY, LTD. | 104.244.99.16 (![]() | ||
2016-08-12 13:19 | broda.50webs.com | GODADDY.COM, LLC | 162.210.101.86 (![]() | ||
2016-08-12 13:19 | www.ceccosport.it | TISCALIDOMAIN-REG | 188.116.55.57 (![]() | ||
2016-08-12 13:19 | scom2.web.fc2.com | INSTRA CORPORATION PTY, LTD. | 104.244.99.16 (![]() | ||
2016-08-12 13:19 | kolkhoz.web.fc2.com | INSTRA CORPORATION PTY, LTD. | 104.244.99.16 (![]() | ||
2016-08-12 13:19 | studiocorrado.org | Ascio Technologies, Inc. Danmark[...] | 79.98.45.16 (![]() | ||
2016-08-12 13:18 | bonmoment.web.fc2.com | INSTRA CORPORATION PTY, LTD. | 104.244.99.42 (![]() | ||
2016-08-12 13:17 | www.meteoerba.it | TISCALIDOMAIN-REG | 31.11.34.54 (![]() | ||
2016-08-12 13:17 | birthday-cards.50webs.com | GODADDY.COM, LLC | 162.210.101.23 (![]() | ||
2016-08-12 13:17 | www.hi-segno.com | ASCIO TECHNOLOGIES, INC. DANMARK[...] | 213.205.40.169 (![]() | ||
2016-08-12 13:16 | tianooze.web.fc2.com | INSTRA CORPORATION PTY, LTD. | 104.244.99.38 (![]() | ||
2016-08-12 13:16 | dopelx.com | REGISTER.IT SPA | 204.11.56.48 (![]() | ||
2016-08-12 13:16 | www.nikawilliam.net | TUCOWS DOMAINS INC. | 195.238.0.64 (![]() | ||
2016-08-12 13:16 | preglitzer.heimat.eu | Key-Systems GmbH | 213.208.133.41 (![]() | ||
2016-08-12 13:15 | www.oxxengarde.de | 80.150.6.143 (![]() | |||
2016-08-12 13:15 | einfachwalter.homepage.t-online.de | 80.150.6.138 (![]() | |||
2016-08-12 13:15 | www.homesplus.nf.net | NETWORK SOLUTIONS, LLC. | 216.251.43.11 (![]() | ||
2016-08-12 13:15 | sv-sportscars.nl | WebReus | 46.235.42.86 (![]() | ||
2016-08-12 11:59 | 52uo5k3t73ypjije.2gbbja.top | Eranet International Limited | (n/a) | ||
2016-08-11 16:36 | agarty.kz | ICPS | 195.210.46.61 (![]() | ||
2016-08-11 11:04 | www.EastsideAutoSalvage.com | GODADDY.COM, LLC | 216.116.20.36 (![]() | ||
2016-08-11 11:04 | iceninegr.web.fc2.com | INSTRA CORPORATION PTY, LTD. | 104.244.99.42 (![]() | ||
2016-08-11 11:03 | www.halloweenparty.go.ro | ICI - ROTLD | 81.196.20.134 (![]() | ||
2016-08-11 11:03 | www.tommasobovone.com | ASCIO TECHNOLOGIES, INC. DANMARK[...] | 213.205.40.169 (![]() | ||
2016-08-11 11:02 | momoselok.ru | RU-CENTER-RU | (n/a) | ||
2016-08-11 11:01 | mccrarys.us | DELUXE SMALL BUSINESS SALES, INC[...] | 64.29.151.209 (![]() | ||
2016-08-11 11:01 | antonello.messina.it | EUTELIA-REG | 83.211.227.140 (![]() | ||
2016-08-11 11:00 | 151.ru | RU-CENTER-RU | 90.156.201.30 (![]() ![]() 90.156.201.77 (AS25532, ![]() 90.156.201.86 (AS25532, ![]() | ||
2016-08-11 10:59 | fcm-makler.de | 91.195.240.126 (![]() | |||
2016-08-11 10:59 | www.fasulo.org | Ascio Technologies, Inc. Danmark[...] | 213.205.40.169 (![]() | ||
2016-08-11 10:59 | sando.oboroduki.com | GMO INTERNET, INC. DBA ONAMAE.CO[...] | 112.140.42.29 (![]() | ||
2016-08-10 12:42 | bfc-sas.fr | LIGNE WEB SERVICES - LWS | 91.216.107.44 (![]() | ||
2016-08-10 12:42 | user48339.vs.easily.co.uk | Ascio Technologies Inc. Denmark [...] | 91.194.151.38 (![]() | ||
2016-08-10 12:42 | www.monzesetraslochi.it | TISCALIDOMAIN-REG | (n/a) | ||
2016-08-10 12:41 | www.italius.com | ASCIO TECHNOLOGIES, INC. DANMARK[...] | 35.169.58.188 (![]() ![]() | ||
2016-08-10 12:41 | nuestraskejas.50webs.com | GODADDY.COM, LLC | 162.210.101.105 (![]() | ||
2016-08-10 12:41 | www.rocchienoteca.it | TISCALIDOMAIN-REG | 213.205.40.169 (![]() | ||
2016-08-10 12:41 | colpi.telerete.it | TELERETE-REG | 217.148.123.3 (![]() | ||
2016-08-10 12:41 | hbfx.home.ro | ICI - ROTLD | 81.196.20.133 (![]() | ||
2016-08-10 12:40 | www.locgest.com | ASCIO TECHNOLOGIES, INC. DANMARK[...] | 213.205.40.169 (![]() | ||
2016-08-10 12:40 | www.forestg.com | NETWORK SOLUTIONS, LLC. | (n/a) | ||
2016-08-10 12:40 | www.xback.be | Telenet BVBA | 195.130.132.84 (![]() | ||
2016-08-10 12:39 | zsz_szyn.republika.pl | 213.180.141.189 (![]() | |||
2016-08-10 12:39 | computekpdx.comcastbiz.net | CSC CORPORATE DOMAINS, INC. | 216.87.186.166 (![]() | ||
2016-08-10 12:39 | helloworldfc2.web.fc2.com | INSTRA CORPORATION PTY, LTD. | 104.244.99.45 (![]() | ||
2016-08-10 12:39 | sibkojin.web.fc2.com | INSTRA CORPORATION PTY, LTD. | 104.244.99.47 (![]() | ||
2016-08-10 12:38 | www.portuense.it | TISCALIDOMAIN-REG | 213.205.40.169 (![]() |
# of rows displayed: 100
# of entries in database: 13'865