Feeds

FeedWhat it listsFinding
abuse.ch Feodo TrackerBotnet command-and-control server IPs. Always on.reputation.listed-feodo
abuse.ch URLhausHosts distributing malware. Additional abuse.ch feed, when enabled.reputation.listed-urlhaus
abuse.ch ThreatFoxMalware indicators of compromise. Additional abuse.ch feed, when enabled.reputation.listed-threatfox

Feeds are downloaded nightly and matched locally, so your hostnames are never sent to a third party. We only use feeds whose licence allows commercial use, which is why Spamhaus, Google Safe Browsing and the OpenPhish community feed are not included (see Data sources).

Severity and alerts

A listing is high. When the only listed address is a shared CDN IP, it is downgraded to info, because the listing is almost certainly about another customer of that CDN. Being listed and being cleared both appear in the change feed (reputation.listed, reputation.cleared).

Responding to a listing

  1. Check whether the listing is for your hostname or for a shared IP address. A shared-hosting or CDN IP can be listed because of another customer.
  2. For a hostname or dedicated IP listing, treat the system as compromised: look for injected scripts, unknown files, unexpected processes and new admin accounts, and rotate credentials.
  3. Once clean, follow the feed's own process. The finding links to the feed's entry for your host. URLhaus marks a URL offline once it stops serving malware, Feodo Tracker entries age out when the server stops acting as a C2, and ThreatFox indicators expire after six months; false positives are reported to abuse.ch from the entry page.