Feeds
| Feed | What it lists | Finding |
|---|---|---|
| abuse.ch Feodo Tracker | Botnet command-and-control server IPs. Always on. | reputation.listed-feodo |
| abuse.ch URLhaus | Hosts distributing malware. Additional abuse.ch feed, when enabled. | reputation.listed-urlhaus |
| abuse.ch ThreatFox | Malware indicators of compromise. Additional abuse.ch feed, when enabled. | reputation.listed-threatfox |
Feeds are downloaded nightly and matched locally, so your hostnames are never sent to a third party. We only use feeds whose licence allows commercial use, which is why Spamhaus, Google Safe Browsing and the OpenPhish community feed are not included (see Data sources).
Severity and alerts
A listing is high. When the only listed address is a shared CDN IP, it is downgraded
to info, because the listing is almost certainly about another customer of that CDN.
Being listed and being cleared both appear in the change feed (reputation.listed,
reputation.cleared).
Responding to a listing
- Check whether the listing is for your hostname or for a shared IP address. A shared-hosting or CDN IP can be listed because of another customer.
- For a hostname or dedicated IP listing, treat the system as compromised: look for injected scripts, unknown files, unexpected processes and new admin accounts, and rotate credentials.
- Once clean, follow the feed's own process. The finding links to the feed's entry for your host. URLhaus marks a URL offline once it stops serving malware, Feodo Tracker entries age out when the server stops acting as a C2, and ThreatFox indicators expire after six months; false positives are reported to abuse.ch from the entry page.