Free feed · sign-up required

Block ClickFix at the domain and URL level

PrecisionSec's free ClickFix feed tracks lure domains, distribution URLs and C2 infrastructure, refreshed as fast as every minute — every indicator, no defanging, free forever.

Work email required. We review every request and email your access credentials as quickly as we can.

By submitting, you agree that PrecisionSec may contact you about this request. See our Privacy Policy.

Free forever · no credit card · HTTPS-protected CSV

Drops straight into the tools your SOC already runs

What you get

The full feed, free

  • The full feed, not a sample: all tracked lure domains, distribution URLs and C2 infrastructure
  • Refreshed as fast as every minute
  • Full, un-defanged indicators delivered via an HTTPS-protected CSV feed, a JSON REST API, or a STIX/TAXII 2.1 collection

How it works

Live in your stack in three steps

  1. Sign up with your work email
  2. We email your access credentials as quickly as we can
  3. Pull ClickFix IOCs into your SIEM, firewall or TIP

Why free?

ClickFix moves fast, and targets everyone

ClickFix is one of the fastest-growing initial-access techniques, and it doesn't discriminate by industry or company size. Getting these indicators into more defenders' hands shrinks the window attackers count on. The full ClickFix feed is our standing free tier: a 15-day trial opens every other malware, C2 and ransomware feed we track.

Want to see how ClickFix works and how we identify a lure? See the anatomy of a ClickFix attack →

See it live

Live ClickFix indicators, pulled straight from our threat feed and refreshed as fast as every minute. Public preview indicators are shown defanged; sign up above to get the full, un-defanged feed.

Live feedUpdated 41s ago
First seenIndicatorTypeConfidence
3msecure-update-cdn[.]netClickFix domainHigh
9m91.213.50[.]114ClickFix IPHigh
15mapi-telemetry-sync[.]com/loadClickFix URLHigh
22mb7e2f48c…3d90afClickFix SHA256Medium
38mnode-relay-7f1c[.]orgClickFix domainHigh
Live ClickFix indicators, surfaced and verified the moment they appear. Shown defanged — the ↗ icon opens the full record in Indicator Search, free. Raw, real-time data via the REST API or a free trial.

Frequently asked questions

Free ClickFix feed: delivery, coverage and access

What's in the feed?

Every tracked ClickFix indicator — lure domains, distribution URLs and C2 infrastructure — with its type and the time it was first seen, as a plain CSV or a STIX/TAXII 2.1 collection you can pull into any SIEM, firewall or TIP.

How is the feed delivered?

Full, un-defanged indicators delivered via an HTTPS-protected CSV feed, a JSON REST API, or a STIX/TAXII 2.1 collection. Once your request is approved, we email your access credentials as quickly as we can.

Is it really free forever, not a trial?

Yes. The ClickFix feed has no trial window and no expiration — it's PrecisionSec's standing free tier, not a promotional offer.

What does the 15-day trial add that the free feed doesn't?

The trial opens every other malware family, C2 framework and ransomware feed PrecisionSec tracks, plus MISP and REST API delivery. The free feed stays scoped to ClickFix only. Start a 15-day trial.

Can I pull the free feed over STIX/TAXII?

Yes. A free STIX/TAXII 2.1 collection scoped to ClickFix indicators is available alongside the CSV. See the ClickFix STIX/TAXII guide.

Do I need to use MISP or a specific SIEM to sign up?

No — the CSV works with any tool that can import a CSV file, and the STIX/TAXII collection works with any TAXII 2.1 client. If you run MISP specifically, a separate native MISP feed is available for free.

Can I use this feed on a FortiGate firewall?

Yes. A domain-only version of the feed is published specifically for FortiGate External Connectors. See the FortiGate setup guide.

Want the full picture?

The ClickFix feed is free forever via CSV or STIX/TAXII. Start a 15-day trial for every other malware, C2 and ransomware feed, plus MISP and API delivery.

Request a 15-day trial