Feodo Tracker C2 Scraper
Pricing
from $6.00 / 1,000 results
Feodo Tracker C2 Scraper
Tap the abuse.ch Feodo Tracker blocklist for live botnet command and control servers tied to Emotet, QakBot, and Dridex. Each row carries IP address, port, online status, ASN, country, and malware family. Built for firewall blocklisting, SOC alert enrichment, and threat hunting.
Pricing
from $6.00 / 1,000 results
Rating
0.0
(0)
Developer
ParseForge
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
21 hours ago
Last modified
Categories
Share

π‘οΈ Feodo Tracker C2 Scraper
π Pull the live abuse.ch Feodo Tracker botnet C2 blocklist in one run. Get every command-and-control server with IP, port, online status, ASN, country, and malware family, ready for blocklisting and SOC enrichment.
Feodo Tracker is a public threat-intelligence project run by abuse.ch that tracks the command-and-control (C2) infrastructure behind major banking trojans and loaders such as Emotet, QakBot, Dridex, TrickBot, BumbleBee and Pikabot. This Actor fetches the official Feodo Tracker IP blocklist and returns one clean row per C2 server so security teams can ingest fresh indicators of compromise (IOCs) without scraping HTML.
This is a defensive, public-data threat-intelligence tool. Every record comes straight from the abuse.ch public download feed. Use it to feed firewall and SIEM blocklists, enrich alerts in a SOC, hunt for malicious infrastructure, or back research into botnet hosting patterns.
| π― Target Audience | π‘ Primary Use Cases |
|---|---|
| SOC and blue-team analysts | Blocklist firewalls, proxies, and DNS |
| Threat intelligence teams | Enrich alerts with C2 context |
| Incident responders | Confirm whether an IP is a known C2 |
| Detection engineers | Build and tune IOC detections |
| Security researchers | Study botnet hosting and ASN trends |
π What the Feodo Tracker C2 Scraper does
- Fetches the official abuse.ch Feodo Tracker IP blocklist (full or recommended).
- Returns one row per C2 server with IP, port, status, ASN, country, and malware family.
- Filters by malware family (for example Emotet or QakBot), online status, and country.
- Caps the number of rows returned so you can pull a quick sample or the whole list.
- Uses only the public download feed, no login, no API key, no images.
π Data fields
Each record includes: asName, asNumber, country, firstSeen, hostname, ipAddress, lastOnline, listType, malware, port, results, scrapedAt, status. These field names come straight from the actor's dataset schema, so what you see here is what lands in your dataset.
π How to use
- Sign in or create a free Apify account using this sign-up link.
- Open the Feodo Tracker C2 Scraper and pick the
fullorrecommendedblocklist. - Optionally set a malware family, status, or country filter.
- Set
maxItemsand click Start. - When the run finishes, browse the dataset or pull it through the API into your tools.
π Recommended Actors
- URLhaus Malware URLs Scraper. Pull the abuse.ch URLhaus feed of malware distribution URLs.
- Vulnerability Security Intel Scraper. Collect structured vulnerability and security intelligence.
- GitHub Security Advisories Scraper. Track CVE-backed advisories across open source packages.
- IP Geolocation Scraper. Enrich any IP with country, ASN, and network details.
- RIPEstat Scraper. Query RIPE network and routing data for ASNs and prefixes.
π‘ Pro Tip: browse the complete ParseForge collection.
β οΈ Disclaimer: This is an independent tool and is not affiliated with abuse.ch or the Feodo Tracker project. Only publicly available data is collected, and it is provided for defensive security and research purposes.
π Need Help?
If you hit a bug, have questions about setup, or need a scraper we haven't built yet, open our contact form or write to parseforge@protonmail.com. We also take on paid custom data projects.
For faster answers, join our Discord. It's the best place to get support and suggest new actors.