Threat intelligence feed
Malware Domain List
Most domain blocklists tell you what to block. They don't tell you why. PrecisionSec attributes domains to the malware family behind them, so a blocked hit tells your team exactly what it stopped: phishing, C2, or payload delivery, not just that something matched.
15-day free trial · no credit card · work email required
Live indicators, defanged. Every indicator ships with malware-family attribution where available — not just a bare domain. Illustrative sample. Every indicator ships with malware-family attribution where available — not just a bare domain.
Drops straight into the tools your SOC already runs
Recent Malware Domain List indicators
Live domain indicators, including phishing lures, C2 and payload-hosting infrastructure, pulled straight from our threat feed and refreshed hourly. For full coverage and API delivery, start a free trial.
A sample from our threat feed. For live data updated hourly, including malware-family attribution, start a free trial.
| First seen | Indicator | Type | Confidence |
|---|---|---|---|
| 4m | mail-sync-relay[.]net | Lokibot domain | High |
| 11m | cdn-assets-update[.]org | Nanocore domain | High |
| 19m | secure-portal-auth[.]info | Phishing domain | High |
| 26m | node-telemetry-cache[.]com | AgentTesla domain | High |
| 33m | billing-update-portal[.]net | Cobalt Strike domain | High |
More than a blocklist
Supplement your domain coverage where it matters
Most domain blocklists tell you what to block. They don't give you the context to understand why. PrecisionSec's Malware Domain List adds malware-family attribution to every indicator, so a blocked hit comes with the context your team needs to prioritize and respond.
Broad malware domain coverage
Add broad domain coverage for phishing lures, malware download sites, distribution hosts and command-and-control infrastructure without building your own collection pipeline.
Attribution on every indicator
Family attribution turns a blocklist hit into useful context, helping analysts understand whether a domain is tied to commodity malware, ransomware precursors or active C2 tooling.
Flexible delivery, no new tooling
Consume the list as CSV, REST API, STIX/TAXII or MISP. Push domains directly into FortiGate NGFW as an external threat feed, or into any SIEM, TIP or MSSP workflow with no new tooling required.
When to use this feed
Built for how domain intelligence actually gets used
MSSP and multi-tenant blocking
Add broad domain coverage across customer environments with a predictable feed format.
Data reseller enrichment
Integrate curated malware-domain intelligence into your own platform or data product.
SOC alert triage
Pivot from a domain hit to malware-family context so analysts can prioritize response.
Threat hunting and retro-hunting
Search historical logs for recently added malware domains and identify exposed hosts.
FortiGate and firewall blocking
Add the feed as an external threat feed in FortiGate NGFW, or push domains into any DNS or SIEM control that sits in the path of user traffic.
Because domains are attributed to specific malware families wherever possible, a single match can tell your team whether an alert is tied to credential theft, commodity malware, ransomware precursor activity or a C2 framework such as Cobalt Strike. Coverage spans dozens of active families, including tracked threats such as Lokibot andNanocore.
Works with
Deploy the same feed across your stack
Validate freshness, format and fit against your existing workflow: test firewall or DNS blocking, enrich SIEM incidents, or populate a threat-intelligence platform.
- FortiGate NGFWAdd the list as an external threat feed and block matching domains at the firewall.
- Microsoft SentinelIngest through the built-in Threat Intelligence – TAXII connector and enrich incidents automatically.
- MISPPull the feed directly, or enrich attributes with the PrecisionSec MISP module instead.
- STIX/TAXIIPoll a STIX 2.1 collection where each domain arrives already linked to the malware family behind it.
Frequently asked questions
Coverage, attribution and access
How often does the domain list update?
Hourly. New phishing, malware-hosting, payload-distribution and C2 domains are added continuously, with family attribution wherever it can be determined.
What's included besides the domain?
Each indicator carries a type (phishing lure, payload host, C2 domain, …) and, where available, the malware family behind it (Lokibot, Nanocore, Cobalt Strike and others).
What delivery formats are available?
CSV and REST API (JSON) for bulk ingestion, plus STIX/TAXII and MISP for teams standardizing on a threat-intelligence platform. All four carry the same underlying data.
How is this different from a free domain blocklist?
Free lists tell you what to block. This feed adds malware-family attribution, hourly updates and a verification pipeline behind every indicator, so a hit tells your team what it stopped, not just that something was blocked.
Is this related to malwaredomainlist.com?
No affiliation. That community project went inactive some years ago. PrecisionSec's Malware Domain List is a separate, actively maintained commercial feed with hourly updates and per-indicator family attribution.
Is the Malware Domain List included in the 15-day trial?
Yes. A trial includes the full PrecisionSec feed set: Malware Domain List, malicious IP, URL and hash feeds, in every delivery format above.
Get started
Request a 15-day trial
Access includes the full PrecisionSec feed set: Malware Domain List, malicious IP, URL and hash feeds, in every delivery format above.
Want the full picture?
Start your 15-day free trial and get the Malware Domain List alongside every other malware, C2 and ransomware feed, plus STIX/TAXII, MISP and API delivery.