Tracker
Ransomware Tracker to distinguishes between the following threats:
- Ransomware botnet Command & Control servers (C&Cs)
- Ransomware Payment Sites
- Ransomware Distribution Sites
Each entry in Ransomware Tracker is tagged to a threat and a malware. Currently, the following Ransomware families are tracked:
- TeslaCrypt
- CryptoWall (if you do want to know more about CryptoWall, check out CryptoWall Tracker)
- TorrentLocker
- PadCrypt
- Locky
- CTB-Locker
- FAKBEN
- PayCrypt
New submissions for Ransomware Tracker are warmly welcome. You can send new additions to rt-RintANel@abuse.ch (remove all letters in uppercase). Malware binaries that you suspect to be associated with a certain Ransomware family can be send to rt-malwSOareM@abuse.ch (remove all letters in uppercase) for analysis.
Search
You can search for a host or URL using the following search form:
Set a filter for the list below
Below is a list of Ransomware botnet C&C servers tracked by Ransomware Tracker. You have the possibility to filter the list below using certain pre-defined filters shown below.
General filters: Remove filter (Show all) | Online hosts
Filter by threat: | |
Filter by malware: | | | | | | | | | | |
Dateadded (UTC) | Threat | Malware | Host (?Domain name or IP address used by the Ransomware. The leading dots (Red, Green, Grey) indicate whether the Host is active or not. Red = Online Green = Offline Grey = Unknown) | Domain Registrar (?In some cases Ransomware Tracker is not able to determine the sponsoring Registrar of a domain name. Thats either because the Registry does not reveal this information in the whois or because the Registry doesn't offer a whois service.) | IP address (ASN, Country) |
---|---|---|---|---|---|
2016-10-03 10:27 | eskrow.ru | DOMENUS-RU | 136.144.28.42 (![]() | ||
2016-10-03 10:27 | rondeaho.com | KEY-SYSTEMS GMBH | (n/a) | ||
2016-10-03 10:26 | rosewong.com | PDR LTD. D/B/A PUBLICDOMAINREGIS[...] | 216.239.32.21 (![]() ![]() 216.239.36.21 (AS15169, ![]() 216.239.38.21 (AS15169, ![]() | ||
2016-10-03 10:26 | medicangka.com | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-10-03 10:25 | shinipri.com | ONLINENIC, INC. | 204.11.56.48 (![]() | ||
2016-10-03 10:25 | louisirby.com | ONLINENIC, INC. | 50.116.19.249 (![]() | ||
2016-10-03 10:25 | yuzhuyuan.com | HICHINA ZHICHENG TECHNOLOGY LTD. | (n/a) | ||
2016-10-03 10:25 | ferumusky.com | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-10-03 10:25 | welsell.com | ENOM, INC. | 68.65.120.219 (![]() | ||
2016-10-03 10:24 | honeine.com | FASTDOMAIN, INC. | 162.241.216.56 (![]() | ||
2016-10-03 10:24 | demo.academia-moscow.ru | RU-CENTER-RU | 62.213.68.172 (![]() | ||
2016-10-03 10:23 | vipmarketing.co.il | 185.37.151.174 (![]() | |||
2016-10-03 10:23 | joplinglobeonline.com | TUCOWS DOMAINS INC. | 12.160.112.27 (![]() | ||
2016-10-03 10:23 | jetxaviation.com | TUCOWS DOMAINS INC. | 91.136.49.102 (![]() | ||
2016-10-03 10:23 | mrwebdirectory.net | ENOM, INC. | 93.119.153.41 (![]() | ||
2016-10-03 10:22 | crossroadspd.com | TUCOWS DOMAINS INC. | 208.71.139.66 (![]() | ||
2016-10-03 10:22 | medicangka.com | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-10-03 10:21 | arcworks.ca | Promo People Inc. | 65.39.193.70 (![]() | ||
2016-10-03 10:21 | dangras.net | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-10-03 10:20 | superoriente.com | REGISTER.COM, INC. | 200.13.249.8 (![]() | ||
2016-10-03 10:20 | mucicsitta.net | KEY-SYSTEMS GMBH | (n/a) | ||
2016-10-03 10:20 | anthonycarducci.lawyerpublicity.com | GODADDY.COM, LLC | 162.215.248.207 (![]() | ||
2016-10-03 10:20 | p2pbikini.com | MAT BAO TRADING & SERVICE COMPAN[...] | (n/a) | ||
2016-10-03 10:20 | ferumusky.com | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-10-03 10:19 | 5v5.net | NAME.COM, INC. | (n/a) | ||
2016-10-03 10:19 | nonprofitbenefit.com | ONLINENIC, INC. | 204.11.56.48 (![]() | ||
2016-10-03 10:19 | hoamiu.info | Name.com LLC | (n/a) | ||
2016-10-03 10:19 | klipink.com | PDR LTD. D/B/A PUBLICDOMAINREGIS[...] | 103.31.233.232 (![]() | ||
2016-10-03 10:18 | dangras.net | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-10-03 10:18 | rondeaho.com | KEY-SYSTEMS GMBH | (n/a) | ||
2016-10-03 10:18 | ferumusky.com | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-10-03 10:18 | vinabuhmwoo.com | ONLINENIC, INC. | (n/a) | ||
2016-10-03 09:51 | new2.aaomg.com | GODADDY.COM, LLC | 162.215.248.207 (![]() | ||
2016-10-03 09:51 | mucicsitta.net | KEY-SYSTEMS GMBH | (n/a) | ||
2016-10-03 09:50 | ferumusky.com | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-10-03 09:49 | icdsarch.com | TUCOWS DOMAINS INC. | (n/a) | ||
2016-10-03 09:48 | glosalonline.com | ENOM, INC. | (n/a) | ||
2016-10-03 09:48 | hrbqcc.com | HICHINA ZHICHENG TECHNOLOGY LTD. | 125.211.217.121 (![]() | ||
2016-10-03 09:47 | cedrussauna.com | GODADDY.COM, LLC | 162.215.248.207 (![]() | ||
2016-10-03 09:47 | acaciainvest.ro | ICI - ROTLD | (n/a) | ||
2016-10-03 09:47 | test.cedrussauna.net | GODADDY.COM, LLC | (n/a) | ||
2016-10-03 09:47 | far-infraredsaunas.com | GODADDY.COM, LLC | 162.215.248.207 (![]() | ||
2016-10-03 09:46 | boservice.info | Tucows Domains Inc. | 77.79.239.195 (![]() | ||
2016-10-03 09:46 | antiquescollectablesandjuststuff.com | TUCOWS DOMAINS INC. | (n/a) | ||
2016-10-03 09:45 | ifsaiumumi.com | NICS TELEKOMUNIKASYON TIC LTD. S[...] | (n/a) | ||
2016-10-03 09:45 | dickenshandchimes.com | GODADDY.COM, LLC | 162.215.248.207 (![]() | ||
2016-10-03 09:45 | arabhashtag.com | NAME.COM, INC. | 23.20.239.12 (![]() | ||
2016-10-03 09:44 | yogajourneyretreat.com | ENOM, INC. | (n/a) | ||
2016-10-03 09:44 | craftsreviews.com | ENOM, INC. | 23.20.239.12 (![]() | ||
2016-10-03 09:43 | lesscellantshautegamme.ca | Tucows.com Co. | 173.192.139.27 (![]() | ||
2016-10-03 09:43 | orhangazitur.com | FBS INC. | 109.232.220.235 (![]() | ||
2016-10-03 09:42 | monkeysdragon.net | FASTDOMAIN, INC. | (n/a) | ||
2016-10-03 09:40 | webhost911.com | GODADDY.COM, LLC | 204.11.56.48 (![]() | ||
2016-10-03 09:39 | villadiana.lv | (n/a) | |||
2016-10-03 09:39 | catlong.com | P.A. VIET NAM COMPANY LIMITED | 112.213.86.196 (![]() | ||
2016-10-03 09:38 | atronis.com | FASTDOMAIN, INC. | 74.220.219.133 (![]() | ||
2016-10-03 09:27 | tsukasagiku.com | GMO INTERNET, INC. DBA ONAMAE.CO[...] | (n/a) | ||
2016-10-03 09:25 | gcandcbuilderssite.aaomg.com | GODADDY.COM, LLC | 162.215.248.207 (![]() | ||
2016-10-03 09:25 | maxleather.aaomg.com | GODADDY.COM, LLC | 162.215.248.207 (![]() | ||
2016-10-03 09:24 | bluewaterappco.com | 1&1 INTERNET SE | (n/a) | ||
2016-10-03 09:23 | mmm2.aaomg.com | GODADDY.COM, LLC | 162.215.248.207 (![]() | ||
2016-10-03 09:23 | parkerneem.com | JAPAN REGISTRY SERVICES CO., LTD[...] | (n/a) | ||
2016-10-03 09:22 | inmopromo.com | ACENS TECHNOLOGIES, S.L.U. | 185.129.248.51 (![]() | ||
2016-10-03 09:21 | denvertracy.com | GODADDY.COM, LLC | 151.101.64.119 (![]() | ||
2016-10-03 06:28 | 4kqd3hmqgptupi3p.5b4ej6.bid | Eranet International Limited | (n/a) | ||
2016-10-03 03:09 | 52uo5k3t73ypjije.50cs7p.bid | Eranet International Limited | (n/a) | ||
2016-10-02 10:34 | 4kqd3hmqgptupi3p.goodslet.win | Alpnames Limited | (n/a) | ||
2016-10-01 13:03 | wjtqjleommc4z46i.993hev.bid | Eranet International Limited | (n/a) | ||
2016-10-01 12:43 | unocl45trpuoefft.88wz5p.bid | Eranet International Limited | (n/a) | ||
2016-10-01 12:29 | unocl45trpuoefft.7tooul.bid | Eranet International Limited | (n/a) | ||
2016-10-01 11:35 | 52uo5k3t73ypjije.8rrxd9.bid | Eranet International Limited | (n/a) | ||
2016-10-01 09:30 | 52uo5k3t73ypjije.x9a6yb.bid | Eranet International Limited | (n/a) | ||
2016-09-30 17:02 | unocl45trpuoefft.jnd0bj.bid | Eranet International Limited | (n/a) | ||
2016-09-30 12:04 | purebanquet.com | GODADDY.COM, LLC | (n/a) | ||
2016-09-30 12:04 | binhminh-group.com | ONLINENIC, INC. | 123.30.210.74 (![]() | ||
2016-09-30 12:04 | theweekwines.com | CSC CORPORATE DOMAINS, INC. | 23.227.38.32 (![]() | ||
2016-09-30 12:04 | endwithcare.org | GoDaddy.com, LLC | 23.229.131.166 (![]() | ||
2016-09-30 12:03 | bushidotactical.com | GODADDY.COM, LLC | 64.78.222.79 (![]() | ||
2016-09-30 12:03 | serwing.com | GODADDY.COM, LLC | 23.20.239.12 (![]() | ||
2016-09-30 12:03 | unityquire.com | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-09-30 12:03 | karacanalbum.com | FBS INC. | 185.86.13.202 (![]() | ||
2016-09-30 12:03 | hotelikbej.pl | AZ.pl Sp. z o.o. | 91.219.209.166 (![]() | ||
2016-09-30 12:03 | travelnesia.net | HOSTINGER UAB | (n/a) | ||
2016-09-30 12:03 | judgedeborahshallcross.com | NETWORK SOLUTIONS, LLC. | (n/a) | ||
2016-09-30 12:03 | techscape4.com | ENOM, INC. | 118.98.75.66 (![]() | ||
2016-09-30 12:02 | localxmobi.com | GODADDY.COM, LLC | 198.100.149.32 (![]() | ||
2016-09-30 12:02 | puchipuchivirus.com | ENOM, INC. | 23.254.240.58 (![]() | ||
2016-09-30 12:02 | fungasoap.net | TUCOWS DOMAINS INC. | 209.200.244.79 (![]() | ||
2016-09-30 12:02 | asotelepathology.org | Register.com, Inc. | 50.63.202.35 (![]() | ||
2016-09-30 12:01 | unityquire.com | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-09-30 12:01 | iambestone.com | KEY-SYSTEMS GMBH | (n/a) | ||
2016-09-30 12:01 | ecoledesalsa.com | GODADDY.COM, LLC | 192.186.239.68 (![]() | ||
2016-09-30 12:01 | australiandesignerweddings.com | CRAZY DOMAINS FZ-LLC | 198.46.89.61 (![]() | ||
2016-09-30 12:01 | juleswham.com | KEY-SYSTEMS GMBH | (n/a) | ||
2016-09-30 12:00 | unityquire.com | PAKNIC (PRIVATE) LIMITED | 184.105.192.2 (![]() | ||
2016-09-30 12:00 | amsterdamrent.com | GODADDY.COM, LLC | (n/a) | ||
2016-09-30 12:00 | sudep-registry.org | eNom, Inc. | 198.185.159.144 (![]() ![]() 198.49.23.144 (AS53831, ![]() 198.49.23.145 (AS53831, ![]() | ||
2016-09-30 11:59 | resboiu.ro | ICI - ROTLD | 89.44.138.57 (![]() | ||
2016-09-30 11:59 | relaywebsample.com | INTERNET DOMAIN SERVICE BS CORP | (n/a) | ||
2016-09-30 11:59 | copsro.sk | 217.67.30.55 (![]() |
# of rows displayed: 100
# of entries in database: 13'867