Tracker
Ransomware Tracker to distinguishes between the following threats:
- Ransomware botnet Command & Control servers (C&Cs)
- Ransomware Payment Sites
- Ransomware Distribution Sites
Each entry in Ransomware Tracker is tagged to a threat and a malware. Currently, the following Ransomware families are tracked:
- TeslaCrypt
- CryptoWall (if you do want to know more about CryptoWall, check out CryptoWall Tracker)
- TorrentLocker
- PadCrypt
- Locky
- CTB-Locker
- FAKBEN
- PayCrypt
New submissions for Ransomware Tracker are warmly welcome. You can send new additions to rt-RintANel@abuse.ch (remove all letters in uppercase). Malware binaries that you suspect to be associated with a certain Ransomware family can be send to rt-malwSOareM@abuse.ch (remove all letters in uppercase) for analysis.
Search
You can search for a host or URL using the following search form:
Set a filter for the list below
Below is a list of Ransomware botnet C&C servers tracked by Ransomware Tracker. You have the possibility to filter the list below using certain pre-defined filters shown below.
General filters: Remove filter (Show all) | Online hosts
Filter by threat: | |
Filter by malware: | | | | | | | | | | |
Dateadded (UTC) | Threat | Malware | Host (?Domain name or IP address used by the Ransomware. The leading dots (Red, Green, Grey) indicate whether the Host is active or not. Red = Online Green = Offline Grey = Unknown) | Domain Registrar (?In some cases Ransomware Tracker is not able to determine the sponsoring Registrar of a domain name. Thats either because the Registry does not reveal this information in the whois or because the Registry doesn't offer a whois service.) | IP address (ASN, Country) |
---|---|---|---|---|---|
2017-11-01 06:12 | cirad.or.id | 202.145.0.45 (![]() | |||
2017-11-01 06:12 | givagarden.com | Tucows Domains Inc. | 93.186.244.43 (![]() | ||
2017-11-01 06:12 | ingress.kannste.net | Cronon AG | 85.214.249.115 (![]() | ||
2017-11-01 06:12 | internet-webshops.de | 217.160.224.147 (![]() | |||
2017-10-31 09:53 | hotelxaguate.com | PDR Ltd. d/b/a PublicDomainRegis[...] | 162.144.46.116 (![]() | ||
2017-10-31 09:53 | rosiautosuli.hu | 87.229.45.38 (![]() | |||
2017-10-31 09:53 | edificioexpo.com | Arsys Internet, S.L. d/b/a NICLI[...] | 94.23.221.122 (![]() | ||
2017-10-31 09:53 | cqaqualite.com | 1&1 Internet SE | 23.20.239.12 (![]() | ||
2017-10-31 09:52 | first-paris-properties.com | OVH | (n/a) | ||
2017-10-31 09:43 | aechjic.pw | Namecheap | 208.100.26.251 (![]() | ||
2017-10-31 09:43 | 95.85.19.195 | 95.85.19.195 (![]() | |||
2017-10-30 15:44 | pciholog.ru | RD-RU | 90.156.201.115 (![]() ![]() 90.156.201.48 (AS25532, ![]() 90.156.201.64 (AS25532, ![]() | ||
2017-10-30 15:39 | hobbystube.net | CPS-Datensysteme GmbH | 83.220.128.111 (![]() | ||
2017-10-30 15:39 | fuettern24.de | 176.28.9.111 (![]() | |||
2017-10-30 15:39 | dvprojekt.hr | 213.202.100.90 (![]() | |||
2017-10-29 00:14 | calicutsaawariya.com | GoDaddy.com, LLC | 192.185.182.56 (![]() | ||
2017-10-29 00:14 | calicutsaawariya.com | GoDaddy.com, LLC | 192.185.182.56 (![]() | ||
2017-10-28 22:59 | the-arts-today.com | GoDaddy.com, LLC | 192.185.41.213 (![]() | ||
2017-10-24 11:20 | themclarenfamily.com | Key-Systems GmbH | 92.48.90.34 (![]() | ||
2017-10-24 11:20 | tatianadecastelbajac.fr | AMEN / Agence des Médias Numériq[...] | (n/a) | ||
2017-10-24 11:20 | video.rb-webdev.de | 85.214.28.187 (![]() | |||
2017-10-20 00:03 | lvanwwbyabcfevyi.pw | Namecheap | n/a | ||
2017-10-20 00:03 | 88.214.236.11 | 88.214.236.11 (![]() | |||
2017-10-18 06:21 | mbfce24rgn65bx3g.is0hvt1.com | Trunkoz Technologies Pvt Ltd. d/[...] | (n/a) | ||
2017-10-14 12:52 | vpuroeit.pw | Namecheap | n/a | ||
2017-10-13 14:52 | mbfce24rgn65bx3g.0ny42p.com | Web Commerce Communications Limi[...] | (n/a) | ||
2017-10-13 14:52 | mbfce24rgn65bx3g.hp8ewo.net | PakNIC (Private) Limited | (n/a) | ||
2017-10-12 05:08 | lacosturera.es | 86.109.170.198 (![]() | |||
2017-10-12 05:08 | missiegeslaagd.nl | WebReus | 46.235.40.31 (![]() | ||
2017-10-12 05:08 | itsmaterial.us | eNom, LLC | 98.124.252.176 (![]() | ||
2017-10-12 05:08 | sambad.com.np | 162.222.225.172 (![]() | |||
2017-10-12 05:07 | fetchstats.net | Eranet International Limited | (n/a) | ||
2017-10-12 05:07 | download.justowin.it | ARUBA-REG | 95.110.225.147 (![]() | ||
2017-10-12 05:07 | centralbaptistchurchnj.org | GoDaddy.com, LLC | (n/a) | ||
2017-10-12 05:07 | motifahsap.com | PDR Ltd. d/b/a PublicDomainRegis[...] | 188.132.180.113 (![]() | ||
2017-10-12 05:07 | shamanic-extracts.biz | GoDaddy.com, Inc. | 184.168.131.241 (![]() | ||
2017-10-12 05:07 | basedow-bilder.de | 194.116.187.130 (![]() | |||
2017-10-12 05:07 | pacalik.net | PDR Ltd. d/b/a PublicDomainRegis[...] | (n/a) | ||
2017-10-12 05:07 | hair-select.jp | 180.222.185.74 (![]() | |||
2017-10-11 11:28 | old.tuttoggi.info | Tucows Domains Inc. | 66.71.182.143 (![]() | ||
2017-10-11 11:28 | wiskundebijles.nu | Key-Systems GmbH | 62.212.95.30 (![]() | ||
2017-10-11 11:28 | georginabringas.com | Tucows Domains Inc. | 68.183.167.43 (![]() | ||
2017-10-11 11:28 | team-bobcat.org | EPAG Domainservices GmbH | (n/a) | ||
2017-10-11 11:28 | pdj.co.id | 104.244.120.69 (![]() | |||
2017-10-11 11:27 | t-plesk.com | PDR Ltd. d/b/a PublicDomainRegis[...] | 77.92.99.9 (![]() | ||
2017-10-11 11:27 | resortphotographics.com | eNom, Inc. | 184.168.131.241 (![]() | ||
2017-10-11 11:27 | eurecas.org | OnlineNIC Inc. | 188.65.87.2 (![]() | ||
2017-10-11 11:27 | highpressurewelding.co.uk | LCN.com Ltd | (n/a) | ||
2017-10-11 11:27 | vithos.de | 87.106.52.12 (![]() | |||
2017-10-11 11:27 | maule.biz | eNom, LLC | 98.124.251.176 (![]() | ||
2017-10-11 11:27 | areanuova.it | WIDE-REG | 46.231.27.51 (![]() | ||
2017-10-11 11:27 | missinglynxsystems.com | GoDaddy.com, LLC | 66.36.173.181 (![]() | ||
2017-10-11 11:27 | fetchstats.net | Eranet International Limited | (n/a) | ||
2017-10-11 11:27 | jns.co.th | T.H.NIC Co., Ltd. | 203.146.43.65 (![]() | ||
2017-10-11 10:44 | hellonwheelsthemovie.com | Tucows Domains Inc. | 66.36.165.149 (![]() | ||
2017-10-11 10:30 | estudiperceptiva.com | Arsys Internet, S.L. d/b/a NICLI[...] | 86.109.170.66 (![]() | ||
2017-10-11 10:30 | mh-service.ru | RU-CENTER-RU | 89.253.235.118 (![]() | ||
2017-10-11 10:29 | bit-chasers.com | eNom, Inc. | (n/a) | ||
2017-10-11 10:29 | bjp.co.id | 103.58.102.38 (![]() | |||
2017-10-11 10:29 | paulcruse.com | Tucows Domains Inc. | 91.215.186.147 (![]() | ||
2017-10-11 10:29 | nsaflow.info | Eranet International Limited | (n/a) | ||
2017-10-11 10:29 | monstermx.com | PDR Ltd. d/b/a PublicDomainRegis[...] | 72.34.251.187 (![]() | ||
2017-10-11 10:29 | suncoastot.com | eNom, Inc. | 98.124.252.176 (![]() | ||
2017-10-11 10:29 | logica-info.com | PDR Ltd. d/b/a PublicDomainRegis[...] | 103.58.102.36 (![]() | ||
2017-10-10 18:54 | estudiperceptiva.com | Arsys Internet, S.L. d/b/a NICLI[...] | 86.109.170.66 (![]() | ||
2017-10-10 18:53 | monstermx.com | PDR Ltd. d/b/a PublicDomainRegis[...] | 72.34.251.187 (![]() | ||
2017-10-10 18:50 | bjp.co.id | 103.58.102.38 (![]() | |||
2017-10-10 18:50 | nsaflow.info | Eranet International Limited | (n/a) | ||
2017-10-10 18:50 | paulcruse.com | Tucows Domains Inc. | 91.215.186.147 (![]() | ||
2017-10-10 18:50 | suncoastot.com | eNom, Inc. | 98.124.252.176 (![]() | ||
2017-10-10 18:49 | bit-chasers.com | eNom, Inc. | (n/a) | ||
2017-10-10 18:49 | logica-info.com | PDR Ltd. d/b/a PublicDomainRegis[...] | 103.58.102.36 (![]() | ||
2017-10-10 18:49 | mh-service.ru | RU-CENTER-RU | 89.253.235.118 (![]() | ||
2017-10-10 18:49 | hellonwheelsthemovie.com | Tucows Domains Inc. | 66.36.165.149 (![]() | ||
2017-10-10 18:49 | handhi.com | Tucows Domains Inc. | 162.213.255.19 (![]() | ||
2017-10-10 18:49 | m-tensou.net | Tucows Domains Inc. | 202.218.252.73 (![]() | ||
2017-10-10 08:55 | henweekendsbirmingham.co.uk | Pulsant (Scotland) Ltd | 35.240.15.72 (![]() | ||
2017-10-10 08:55 | test.sisap.ro | Hostvision SRL | (n/a) | ||
2017-10-10 08:54 | deltasec.net | CSL Computer Service Langenbach [...] | (n/a) | ||
2017-10-10 08:54 | agrourbis.com | Arsys Internet, S.L. d/b/a NICLI[...] | 86.109.170.66 (![]() | ||
2017-10-10 08:54 | xploramail.com | Soluciones Corporativas IP, SL | (n/a) | ||
2017-10-10 08:54 | mastertenniscoach.com | GoDaddy.com, LLC | 69.16.209.47 (![]() | ||
2017-10-10 08:54 | likiihillschool.com | Tucows Domains Inc. | (n/a) | ||
2017-10-10 08:54 | axtes.com | OVH | 37.59.210.47 (![]() | ||
2017-10-10 08:54 | dueeffepromotion.com | eNom, Inc. | 31.11.34.199 (![]() | ||
2017-10-10 08:54 | nsaflow.info | Eranet International Limited | (n/a) | ||
2017-10-10 08:54 | shahanabiomedicals.com | Name.com, Inc. | 64.140.170.18 (![]() | ||
2017-10-10 08:51 | mediatrendsistem.com | DNC Holdings, Inc. | (n/a) | ||
2017-10-10 08:51 | bodywork-sf.net | eNom, Inc. | (n/a) | ||
2017-10-10 08:51 | brascopperchile.cl | (n/a) | |||
2017-10-10 08:51 | fls-portal.co.uk | ukfast.net Ltd t/a UKFast.Net Li[...] | (n/a) | ||
2017-10-10 08:50 | evlilikpsikolojisi.com | Nics Telekomunikasyon Tic Ltd. S[...] | (n/a) | ||
2017-10-10 08:50 | ashtontan.com | Tucows Domains Inc. | 103.6.198.208 (![]() | ||
2017-10-10 08:50 | essenza.co.id | 202.169.44.141 (![]() | |||
2017-10-10 08:50 | gilgroup.com | Network Solutions, LLC. | 216.177.130.203 (![]() | ||
2017-10-10 08:50 | scottfranch.org | Todaynic.com, Inc. | (n/a) | ||
2017-10-10 08:50 | aeaccting.com | eNom, Inc. | 208.67.23.166 (![]() | ||
2017-10-10 08:49 | bsfotodesign.com | eNom, Inc. | 80.172.241.44 (![]() | ||
2017-10-10 08:49 | galeona.com | Arsys Internet, S.L. d/b/a NICLI[...] | 212.89.16.142 (![]() | ||
2017-10-10 08:49 | ashapeforlife.com | 1&1 Internet SE | 217.160.0.51 (![]() |
# of rows displayed: 100
# of entries in database: 13'867