Threat intelligence feed

Malware Domain List

Most domain blocklists tell you what to block. They don't tell you why. PrecisionSec attributes domains to the malware family behind them, so a blocked hit tells your team exactly what it stopped: phishing, C2, or payload delivery, not just that something matched.

15-day free trial · no credit card · work email required

Malware Domain List · attributed hourly5 of 40,000+ tracked domains
mail-sync-relay[.]net4mLokibot
cdn-assets-update[.]org11mNanocore
secure-portal-auth[.]info19mPhishing
node-telemetry-cache[.]com26mAgentTesla
billing-update-portal[.]net33mCobalt Strike

Illustrative sample. Every indicator ships with malware-family attribution where available — not just a bare domain.

Drops straight into the tools your SOC already runs

Recent Malware Domain List indicators

Live domain indicators, including phishing lures, C2 and payload-hosting infrastructure, pulled straight from our threat feed and refreshed hourly. For full coverage and API delivery, start a free trial.

Live feedUpdated 41s ago
First seenIndicatorTypeConfidence
4mmail-sync-relay[.]netLokibot domainHigh
11mcdn-assets-update[.]orgNanocore domainHigh
19msecure-portal-auth[.]infoPhishing domainHigh
26mnode-telemetry-cache[.]comAgentTesla domainHigh
33mbilling-update-portal[.]netCobalt Strike domainHigh
Live indicators, surfaced and verified the moment they appear. Shown defanged. Raw, real-time data via the REST API or a free trial.

More than a blocklist

Supplement your domain coverage where it matters

Most domain blocklists tell you what to block. They don't give you the context to understand why. PrecisionSec's Malware Domain List adds malware-family attribution to every indicator, so a blocked hit comes with the context your team needs to prioritize and respond.

Broad malware domain coverage

Add broad domain coverage for phishing lures, malware download sites, distribution hosts and command-and-control infrastructure without building your own collection pipeline.

Attribution on every indicator

Family attribution turns a blocklist hit into useful context, helping analysts understand whether a domain is tied to commodity malware, ransomware precursors or active C2 tooling.

Flexible delivery, no new tooling

Consume the list as CSV, REST API, STIX/TAXII or MISP. Push domains directly into FortiGate NGFW as an external threat feed, or into any SIEM, TIP or MSSP workflow with no new tooling required.

When to use this feed

Built for how domain intelligence actually gets used

MSSP and multi-tenant blocking

Add broad domain coverage across customer environments with a predictable feed format.

Data reseller enrichment

Integrate curated malware-domain intelligence into your own platform or data product.

SOC alert triage

Pivot from a domain hit to malware-family context so analysts can prioritize response.

Threat hunting and retro-hunting

Search historical logs for recently added malware domains and identify exposed hosts.

FortiGate and firewall blocking

Add the feed as an external threat feed in FortiGate NGFW, or push domains into any DNS or SIEM control that sits in the path of user traffic.

Because domains are attributed to specific malware families wherever possible, a single match can tell your team whether an alert is tied to credential theft, commodity malware, ransomware precursor activity or a C2 framework such as Cobalt Strike. Coverage spans dozens of active families, including tracked threats such as Lokibot andNanocore.

Frequently asked questions

Coverage, attribution and access

How often does the domain list update?

Hourly. New phishing, malware-hosting, payload-distribution and C2 domains are added continuously, with family attribution wherever it can be determined.

What's included besides the domain?

Each indicator carries a type (phishing lure, payload host, C2 domain, …) and, where available, the malware family behind it (Lokibot, Nanocore, Cobalt Strike and others).

What delivery formats are available?

CSV and REST API (JSON) for bulk ingestion, plus STIX/TAXII and MISP for teams standardizing on a threat-intelligence platform. All four carry the same underlying data.

How is this different from a free domain blocklist?

Free lists tell you what to block. This feed adds malware-family attribution, hourly updates and a verification pipeline behind every indicator, so a hit tells your team what it stopped, not just that something was blocked.

Is this related to malwaredomainlist.com?

No affiliation. That community project went inactive some years ago. PrecisionSec's Malware Domain List is a separate, actively maintained commercial feed with hourly updates and per-indicator family attribution.

Is the Malware Domain List included in the 15-day trial?

Yes. A trial includes the full PrecisionSec feed set: Malware Domain List, malicious IP, URL and hash feeds, in every delivery format above.

Get started

Request a 15-day trial

Access includes the full PrecisionSec feed set: Malware Domain List, malicious IP, URL and hash feeds, in every delivery format above.

We review every request and follow up as quickly as we can. Access requires a work email address; we can't provision free accounts (Gmail, Outlook, and similar).

By submitting, you agree that PrecisionSec may contact you about this request. See our Privacy Policy.

Want the full picture?

Start your 15-day free trial and get the Malware Domain List alongside every other malware, C2 and ransomware feed, plus STIX/TAXII, MISP and API delivery.

Request a 15-day trial