Threat intelligence feed

Malware Domain List

An hourly-updated malware domain feed with family attribution on every indicator. Every blocked hit tells you which threat you stopped, not just that something was blocked.

15-day free trial · no credit card · reply within one business day

Drops straight into the tools your SOC already runs

More than a blocklist

Supplement your domain coverage where it matters

Most domain blocklists tell you what to block. They don't give you the context to understand why. PrecisionSec's Malware Domain List adds malware-family attribution to every indicator. A blocked hit comes with the context your team needs to prioritize and respond.

Broad malware domain coverage

Add broad domain coverage for phishing lures, malware download sites, distribution hosts and command-and-control infrastructure without building your own collection pipeline.

Attribution on every indicator

Family attribution turns a blocklist hit into useful context, helping analysts understand whether a domain is tied to commodity malware, ransomware precursors or active C2 tooling.

Flexible delivery, no new tooling

Consume the list as CSV, REST API, STIX/TAXII or MISP. Push domains directly into FortiGate NGFW as an external threat feed, or into any SIEM, TIP or MSSP workflow with no new tooling required.

Because domains are attributed to specific malware families wherever possible, the Malware Domain List does more than block known-bad infrastructure. A single match can tell your team whether an alert is tied to credential theft, commodity malware, ransomware precursor activity or a C2 framework such as Cobalt Strike.

The feed covers the domains attackers use for phishing lures, malware hosting, payload distribution and C2. It’s updated hourly and drops into the tools you already use.

You get coverage you can action immediately, whether you’re an MSSP protecting multi-tenant environments, a data reseller building security products, or a SOC team enriching alerts and pushing domain intelligence into firewalls, SIEMs and threat-intelligence platforms.

What’s in the feed

  • Hourly-updated domains used for phishing, malware hosting, payload delivery and C2
  • Coverage across dozens of active malware, infostealer, RAT, loader and ransomware-related families
  • Family attribution where available, including tracked threats such as Lokibot, Nanocore and Cobalt Strike
  • Simple CSV and REST API (JSON) delivery for bulk ingestion and automation
  • Available through STIX/TAXII and MISP feeds for teams standardizing on threat-intelligence platforms
  • Ready for firewall and DNS-blocking workflows, including FortiGate external threat feeds

Evaluate before you commit

You’re probably trying to do one of three things: add a reliable blocklist, enrich alerts with domain context, or feed domain intelligence into a product or managed service. You get all three without having to normalize raw threat data first.

You can validate freshness, format and fit against your existing workflow. Test DNS or firewall blocking, enrich Microsoft Sentinel incidents, populate MISP events, or compare coverage against your current sources.

Start a 15-day free trial. Access is immediate and includes the full PrecisionSec feed set: Malware Domain List, malicious IP, URL and hash feeds.

When to use this feed

  • MSSP and multi-tenant blocking: add broad domain coverage across customer environments with a predictable feed format.
  • Data reseller enrichment: integrate curated malware-domain intelligence into your own platform or data product.
  • SOC alert triage: pivot from a domain hit to malware-family context so analysts can prioritize response.
  • Threat hunting and retro-hunting: search historical logs for recently added malware domains and identify exposed hosts.
  • FortiGate and firewall blocking: add the feed as an external threat feed in FortiGate NGFW, or push domains into any DNS or SIEM control that sits in the path of user traffic.

You get the Malware Domain List with every PrecisionSec intelligence subscription, alongside malicious IP, URL and hash feeds. Request evaluation access to see live data, delivery formats and integration options.

Ready to see all of our data?

Start your 15-day free trial and get the full Malware Domain List feed, plus every other malware and C2 feed.

Request a 15-day trial