Tracker
Ransomware Tracker to distinguishes between the following threats:
- Ransomware botnet Command & Control servers (C&Cs)
- Ransomware Payment Sites
- Ransomware Distribution Sites
Each entry in Ransomware Tracker is tagged to a threat and a malware. Currently, the following Ransomware families are tracked:
- TeslaCrypt
- CryptoWall (if you do want to know more about CryptoWall, check out CryptoWall Tracker)
- TorrentLocker
- PadCrypt
- Locky
- CTB-Locker
- FAKBEN
- PayCrypt
New submissions for Ransomware Tracker are warmly welcome. You can send new additions to rt-RintANel@abuse.ch (remove all letters in uppercase). Malware binaries that you suspect to be associated with a certain Ransomware family can be send to rt-malwSOareM@abuse.ch (remove all letters in uppercase) for analysis.
Search
You can search for a host or URL using the following search form:
Set a filter for the list below
Below is a list of Ransomware botnet C&C servers tracked by Ransomware Tracker. You have the possibility to filter the list below using certain pre-defined filters shown below.
General filters: Remove filter (Show all) | Online hosts
Filter by threat: | |
Filter by malware: | | | | | | | | | | |
Dateadded (UTC) | Threat | Malware | Host (?Domain name or IP address used by the Ransomware. The leading dots (Red, Green, Grey) indicate whether the Host is active or not. Red = Online Green = Offline Grey = Unknown) | Domain Registrar (?In some cases Ransomware Tracker is not able to determine the sponsoring Registrar of a domain name. Thats either because the Registry does not reveal this information in the whois or because the Registry doesn't offer a whois service.) | IP address (ASN, Country) |
---|---|---|---|---|---|
2016-11-13 09:14 | host71.net | DOMAIN.COM, LLC | (n/a) | ||
2016-11-13 09:14 | jalapodist.net | IP MIRROR PTE LTD. DBA IP MIRROR | (n/a) | ||
2016-11-13 09:14 | hostingforall.gr | (n/a) | |||
2016-11-13 09:14 | huodaibbs.com | HICHINA ZHICHENG TECHNOLOGY LTD. | (n/a) | ||
2016-11-13 09:14 | almahaconsultants.com | GODADDY.COM, LLC | 213.158.187.42 (![]() | ||
2016-11-13 09:14 | eddermiaul.net | PAKNIC (PRIVATE) LIMITED | (n/a) | ||
2016-11-13 09:14 | joyannainsurance.com | TUCOWS DOMAINS INC. | 45.56.217.23 (![]() | ||
2016-11-13 09:13 | longyimumen.com | CHENGDU WEST DIMENSION DIGITAL T[...] | 119.28.229.117 (![]() | ||
2016-11-13 09:13 | plusideaad.com | INTERNET DOMAIN SERVICE BS CORP | (n/a) | ||
2016-11-13 09:13 | icefon.eu | TLD Registrar Solutions Ltd | 104.31.68.179 (![]() ![]() | ||
2016-11-13 09:13 | hostscom.com | 1 API GMBH | (n/a) | ||
2016-11-13 09:13 | jalapodist.net | IP MIRROR PTE LTD. DBA IP MIRROR | (n/a) | ||
2016-11-13 09:13 | jssmsc.com | HICHINA ZHICHENG TECHNOLOGY LTD. | 107.186.212.71 (![]() | ||
2016-11-13 09:13 | jalapodist.net | IP MIRROR PTE LTD. DBA IP MIRROR | (n/a) | ||
2016-11-13 09:13 | goodswand.net | KEY-SYSTEMS GMBH | (n/a) | ||
2016-11-13 09:13 | darbyreis.com | KEY-SYSTEMS GMBH | (n/a) | ||
2016-11-13 09:13 | goodswand.net | KEY-SYSTEMS GMBH | (n/a) | ||
2016-11-13 09:13 | myiaiaonline.com | NETWORK SOLUTIONS, LLC. | 208.91.197.132 (![]() | ||
2016-11-13 09:12 | goodswand.net | KEY-SYSTEMS GMBH | (n/a) | ||
2016-11-13 09:12 | goodswand.net | KEY-SYSTEMS GMBH | (n/a) | ||
2016-11-13 09:12 | informatie-over.nl | TransIP BV | 91.220.37.56 (![]() | ||
2016-11-13 09:12 | coolnshop.com | ONLINENIC, INC. | 117.18.105.78 (![]() | ||
2016-11-13 09:12 | iwebsdns.com | DNC HOLDINGS, INC. | 74.117.221.144 (![]() | ||
2016-11-13 09:12 | darbyreis.com | KEY-SYSTEMS GMBH | (n/a) | ||
2016-11-13 09:12 | loveweb.org | Xin Net Technology Corporation | 198.177.124.23 (![]() | ||
2016-11-13 09:11 | multipartnersistem.com | ASCIO TECHNOLOGIES, INC. DANMARK[...] | 93.188.2.51 (![]() | ||
2016-11-13 09:11 | hurricanefilters.com | PDR LTD. D/B/A PUBLICDOMAINREGIS[...] | 203.146.117.249 (![]() | ||
2016-11-13 09:11 | darbyreis.com | KEY-SYSTEMS GMBH | (n/a) | ||
2016-11-13 09:11 | hottao.cn | Beijing New Net Digital Informat[...] | (n/a) | ||
2016-11-13 09:11 | icdsarch.com | TUCOWS DOMAINS INC. | (n/a) | ||
2016-11-13 09:11 | ledetdom.ru | R01-RU | (n/a) | ||
2016-11-13 09:11 | laguna-utes.com | ONLINENIC, INC. | 141.8.194.53 (![]() | ||
2016-11-13 09:11 | facecapsule.com | GODADDY.COM, LLC | (n/a) | ||
2016-11-13 09:11 | jalapodist.net | IP MIRROR PTE LTD. DBA IP MIRROR | (n/a) | ||
2016-11-13 09:11 | it.gr | 91.195.240.126 (![]() | |||
2016-11-13 09:11 | infradebt.com.au | TPP Wholesale Pty Ltd | 23.236.62.147 (![]() | ||
2016-11-13 09:10 | markibernadett.hu | (n/a) | |||
2016-11-13 09:10 | ifeb.eu | Key-Systems GmbH | 193.46.215.132 (![]() | ||
2016-11-13 09:10 | konsultanasuransi.com | PDR LTD. D/B/A PUBLICDOMAINREGIS[...] | 153.92.9.111 (![]() | ||
2016-11-13 09:10 | my-vintage.com | 1&1 INTERNET SE | 217.160.0.13 (![]() | ||
2016-11-13 09:10 | huayudianlan.net | XIN NET TECHNOLOGY CORPORATION | 103.251.88.65 (![]() | ||
2016-11-13 09:10 | solmevini.com | NETEARTH ONE INC. D/B/A NETEARTH | 5.196.200.16 (![]() | ||
2016-11-13 09:10 | luczko.pl | Active 24 sp. z o.o. | 78.46.37.186 (![]() | ||
2016-11-13 09:10 | konet.org | Network Solutions, LLC | 50.116.80.43 (![]() | ||
2016-11-13 09:10 | eddermiaul.net | PAKNIC (PRIVATE) LIMITED | (n/a) | ||
2016-11-13 09:10 | jingshieye.com | CHENGDU WEST DIMENSION DIGITAL T[...] | 154.95.160.173 (![]() | ||
2016-11-13 09:10 | angeredo.com | PAKNIC (PRIVATE) LIMITED | 208.91.197.46 (![]() | ||
2016-11-13 09:10 | keyloggers.ro | ROSPOT SRL | (n/a) | ||
2016-11-13 09:10 | angeredo.com | PAKNIC (PRIVATE) LIMITED | 208.91.197.46 (![]() | ||
2016-11-13 09:09 | spoiltgirlsclub.com | GODADDY.COM, LLC | (n/a) | ||
2016-11-13 09:09 | eddermiaul.net | PAKNIC (PRIVATE) LIMITED | (n/a) | ||
2016-11-13 09:09 | huojiasf.com | SHANGHAI MEICHENG TECHNOLOGY INF[...] | (n/a) | ||
2016-11-13 09:09 | angeredo.com | PAKNIC (PRIVATE) LIMITED | 208.91.197.46 (![]() | ||
2016-11-13 09:09 | lasentea.com | ONLINENIC, INC. | 112.78.2.41 (![]() | ||
2016-11-13 09:09 | m3t.cz | REG-PIPNI | 93.185.104.26 (![]() | ||
2016-11-13 09:09 | lebeier520.com | CHENGDU WEST DIMENSION DIGITAL T[...] | (n/a) | ||
2016-11-13 09:09 | langevin.jp | 219.118.65.31 (![]() | |||
2016-11-13 09:09 | darbyreis.com | KEY-SYSTEMS GMBH | (n/a) | ||
2016-11-13 09:08 | inormann.it | OMNIBUS-REG | 80.211.73.228 (![]() | ||
2016-11-13 09:05 | ffoqr3ug7m726zou.rxmbsm.top | Eranet International Limited | (n/a) | ||
2016-11-13 08:23 | vyohacxzoue32vvk.mpduf5.bid | Eranet International Limited | (n/a) | ||
2016-11-13 01:13 | ffoqr3ug7m726zou.b31wkh.bid | Eranet International Limited | (n/a) | ||
2016-11-13 00:04 | ffoqr3ug7m726zou.tsrwj3.top | Eranet International Limited | (n/a) | ||
2016-11-12 23:37 | vyohacxzoue32vvk.fp6fj6.top | Eranet International Limited | (n/a) | ||
2016-11-12 21:22 | vyohacxzoue32vvk.c4cwr4.bid | Eranet International Limited | (n/a) | ||
2016-11-12 21:14 | ahuqfrqk54v3vnzj.9sfk22.bid | Eranet International Limited | (n/a) | ||
2016-11-12 20:55 | vyohacxzoue32vvk.h2xun1.top | Eranet International Limited | (n/a) | ||
2016-11-12 19:07 | ffoqr3ug7m726zou.ptnbfm.top | Eranet International Limited | (n/a) | ||
2016-11-12 14:26 | ffoqr3ug7m726zou.2fu7bc.top | Eranet International Limited | (n/a) | ||
2016-11-12 14:23 | ffoqr3ug7m726zou.x8p2m7.bid | Eranet International Limited | (n/a) | ||
2016-11-12 12:20 | vyohacxzoue32vvk.w67y8u.bid | Eranet International Limited | (n/a) | ||
2016-11-12 10:11 | ffoqr3ug7m726zou.w67y8u.bid | Eranet International Limited | (n/a) | ||
2016-11-12 09:43 | vyohacxzoue32vvk.zu3fzc.bid | Eranet International Limited | (n/a) | ||
2016-11-12 07:30 | ahuqfrqk54v3vnzj.c8jxpp.top | Eranet International Limited | (n/a) | ||
2016-11-12 03:54 | vyohacxzoue32vvk.chnbyl.bid | Eranet International Limited | (n/a) | ||
2016-11-12 03:03 | ffoqr3ug7m726zou.4tkb0d.top | Eranet International Limited | (n/a) | ||
2016-11-11 23:07 | ffoqr3ug7m726zou.hpwom3.top | Eranet International Limited | (n/a) | ||
2016-11-11 20:06 | lfdachijzuwx4bc4.iuzppd.top | Eranet International Limited | (n/a) | ||
2016-11-11 19:02 | vyohacxzoue32vvk.7m7ujm.bid | Eranet International Limited | (n/a) | ||
2016-11-11 18:01 | ffoqr3ug7m726zou.ffsm1a.bid | Eranet International Limited | (n/a) | ||
2016-11-11 16:10 | holmebjerg.dk | 77.111.240.34 (![]() | |||
2016-11-11 16:10 | healwithbill.com | GODADDY.COM, LLC | 23.236.62.147 (![]() | ||
2016-11-11 16:10 | itemweb.fr | 1&1 Internet SE | 217.160.9.174 (![]() | ||
2016-11-11 16:10 | gossipsjunction.com | NAME.COM, INC. | 122.10.117.200 (![]() | ||
2016-11-11 16:10 | jlhack.com | BEIJING INNOVATIVE LINKAGE TECHN[...] | 23.83.174.35 (![]() | ||
2016-11-11 16:10 | furniturefactory.lk | 67.231.243.47 (![]() | |||
2016-11-11 16:10 | g2el.com | GODADDY.COM, LLC | (n/a) | ||
2016-11-11 16:10 | godgetaways.com | GODADDY.COM, LLC | 198.54.116.94 (![]() | ||
2016-11-11 16:10 | sport-grace.by | Open Contact, Ltd | (n/a) | ||
2016-11-11 16:10 | scupwail.com | IP MIRROR PTE LTD. DBA IP MIRROR | (n/a) | ||
2016-11-11 16:09 | scupwail.com | IP MIRROR PTE LTD. DBA IP MIRROR | (n/a) | ||
2016-11-11 16:09 | scupwail.com | IP MIRROR PTE LTD. DBA IP MIRROR | (n/a) | ||
2016-11-11 16:09 | oatloyd.com | PAKNIC (PRIVATE) LIMITED | (n/a) | ||
2016-11-11 16:09 | just-say-yes.nl | AXC | 158.69.64.5 (![]() | ||
2016-11-11 16:09 | thirlnak.net | KEY-SYSTEMS GMBH | (n/a) | ||
2016-11-11 16:09 | kyotoeyewear.com | NETWORK SOLUTIONS, LLC. | 216.110.144.243 (![]() | ||
2016-11-11 16:09 | putidwipe.com | IP MIRROR PTE LTD. DBA IP MIRROR | (n/a) | ||
2016-11-11 16:09 | mospi.ru | REGTIME-RU | 91.221.37.14 (![]() | ||
2016-11-11 16:09 | magical-connection.com | TUCOWS DOMAINS INC. | 67.210.101.227 (![]() | ||
2016-11-11 16:09 | motefugue.com | PAKNIC (PRIVATE) LIMITED | (n/a) |
# of rows displayed: 100
# of entries in database: 13'867