Free feed · sign-up required
Block ClickFix at the domain and URL level
PrecisionSec's free ClickFix feed tracks lure domains, distribution URLs and C2 infrastructure, refreshed as fast as every minute — every indicator, no defanging, free forever.
Free forever · no credit card · HTTPS-protected CSV
Drops straight into the tools your SOC already runs
What you get
The full feed, free
- The full feed, not a sample: all tracked lure domains, distribution URLs and C2 infrastructure
- Refreshed as fast as every minute
- Full, un-defanged indicators delivered via an HTTPS-protected CSV feed
How it works
Live in your stack in three steps
- Sign up with your work email
- We email CSV access credentials as quickly as we can
- Pull ClickFix IOCs into your SIEM, firewall or TIP
Why free?
ClickFix moves fast, and targets everyone
ClickFix is one of the fastest-growing initial-access techniques, and it doesn't discriminate by industry or company size. Getting these indicators into more defenders' hands shrinks the window attackers count on. The full ClickFix feed is our standing free tier: a 15-day trial opens every other malware, C2 and ransomware feed we track.
See it live
Live ClickFix indicators, pulled straight from our threat feed and refreshed as fast as every minute. Public preview indicators are shown defanged; sign up above to get the full, un-defanged feed.
| First seen | Indicator | Type | Confidence |
|---|---|---|---|
| 3m | secure-update-cdn[.]net | ClickFix domain | High |
| 9m | 91.213.50[.]114 | ClickFix IP | High |
| 15m | api-telemetry-sync[.]com/load | ClickFix URL | High |
| 22m | b7e2f48c…3d90af | ClickFix SHA256 | Medium |
| 38m | node-relay-7f1c[.]org | ClickFix domain | High |
Frequently asked questions
Free ClickFix feed: delivery, coverage and access
What's in the CSV?
Every tracked ClickFix indicator — lure domains, distribution URLs and C2 infrastructure — with its type and the time it was first seen, as a plain CSV you can import into any SIEM, firewall or TIP.
How is the feed delivered?
Full, un-defanged indicators delivered via an HTTPS-protected CSV feed. Once your request is approved, we email CSV access credentials as quickly as we can.
Is it really free forever, not a trial?
Yes. The ClickFix feed has no trial window and no expiration — it's PrecisionSec's standing free tier, not a promotional offer.
What does the 15-day trial add that the free feed doesn't?
The trial opens every other malware family, C2 framework and ransomware feed PrecisionSec tracks, plus STIX/TAXII, MISP and REST API delivery. The free feed stays CSV-only and scoped to ClickFix. Start a 15-day trial.
Do I need to use MISP or a specific SIEM to sign up?
No — the CSV works with any tool that can import a CSV file. If you run MISP specifically, a separate native MISP feed is available for free.
Can I use this feed on a FortiGate firewall?
Yes. A domain-only version of the feed is published specifically for FortiGate External Connectors. See the FortiGate setup guide.
Want the full picture?
The ClickFix feed is free forever as CSV. Start a 15-day trial for every other malware, C2 and ransomware feed, plus STIX/TAXII, MISP and API delivery.