Free feed · sign-up required

Block ClickFix at the domain and URL level

PrecisionSec's free ClickFix feed tracks lure domains, distribution URLs and C2 infrastructure, refreshed as fast as every minute — every indicator, no defanging, free forever.

Work email required. We review every request and email CSV access credentials as quickly as we can.

By submitting, you agree that PrecisionSec may contact you about this request. See our Privacy Policy.

Free forever · no credit card · HTTPS-protected CSV

Drops straight into the tools your SOC already runs

What you get

The full feed, free

  • The full feed, not a sample: all tracked lure domains, distribution URLs and C2 infrastructure
  • Refreshed as fast as every minute
  • Full, un-defanged indicators delivered via an HTTPS-protected CSV feed

How it works

Live in your stack in three steps

  1. Sign up with your work email
  2. We email CSV access credentials as quickly as we can
  3. Pull ClickFix IOCs into your SIEM, firewall or TIP

Why free?

ClickFix moves fast, and targets everyone

ClickFix is one of the fastest-growing initial-access techniques, and it doesn't discriminate by industry or company size. Getting these indicators into more defenders' hands shrinks the window attackers count on. The full ClickFix feed is our standing free tier: a 15-day trial opens every other malware, C2 and ransomware feed we track.

Want to see how ClickFix works and how we identify a lure? See the anatomy of a ClickFix attack →

See it live

Live ClickFix indicators, pulled straight from our threat feed and refreshed as fast as every minute. Public preview indicators are shown defanged; sign up above to get the full, un-defanged feed.

Live feedUpdated 41s ago
First seenIndicatorTypeConfidence
3msecure-update-cdn[.]netClickFix domainHigh
9m91.213.50[.]114ClickFix IPHigh
15mapi-telemetry-sync[.]com/loadClickFix URLHigh
22mb7e2f48c…3d90afClickFix SHA256Medium
38mnode-relay-7f1c[.]orgClickFix domainHigh
Live ClickFix indicators, surfaced and verified the moment they appear. Shown defanged — the ↗ icon opens the full record in Indicator Search, free. Raw, real-time data via the REST API or a free trial.

Frequently asked questions

Free ClickFix feed: delivery, coverage and access

What's in the CSV?

Every tracked ClickFix indicator — lure domains, distribution URLs and C2 infrastructure — with its type and the time it was first seen, as a plain CSV you can import into any SIEM, firewall or TIP.

How is the feed delivered?

Full, un-defanged indicators delivered via an HTTPS-protected CSV feed. Once your request is approved, we email CSV access credentials as quickly as we can.

Is it really free forever, not a trial?

Yes. The ClickFix feed has no trial window and no expiration — it's PrecisionSec's standing free tier, not a promotional offer.

What does the 15-day trial add that the free feed doesn't?

The trial opens every other malware family, C2 framework and ransomware feed PrecisionSec tracks, plus STIX/TAXII, MISP and REST API delivery. The free feed stays CSV-only and scoped to ClickFix. Start a 15-day trial.

Do I need to use MISP or a specific SIEM to sign up?

No — the CSV works with any tool that can import a CSV file. If you run MISP specifically, a separate native MISP feed is available for free.

Can I use this feed on a FortiGate firewall?

Yes. A domain-only version of the feed is published specifically for FortiGate External Connectors. See the FortiGate setup guide.

Want the full picture?

The ClickFix feed is free forever as CSV. Start a 15-day trial for every other malware, C2 and ransomware feed, plus STIX/TAXII, MISP and API delivery.

Request a 15-day trial