Skip to main content
Data Products

C2 Feeds Command & control infrastructure

Track active C2 infrastructure in real-time. Identify Cobalt Strike, Metasploit, and other framework servers before they're used in attacks.

Get the full list — Basic, €49/month

Monthly billing · cancel anytime

GET/downloads/blocklist/blocklist-ips-c2.txt
# IsMalicious.com Blocklist - IPs (All Levels)# Format: Plain# Generated: 2026-10-06T21:08:59.332387002+00:00# Total entries: 44466# Update frequency: every 12 hours# Category: C2# Threat level: All Levels# Website: https://ismalicious.com# © 2026 IsMalicious (compilation). Licensed to the downloading account under https://ismalicious.com/terms; redistribution of the compilation prohibited. Third-party entries remain under their providers' licences — see https://ismalicious.com/sources.# Filtered by category: c2154.220.94.4646.224.162.14880.98.145.41190.53.144.120
44 466 entriesgenerated 14 min. ago
Download the free sample (4 446 entries)10 % of the list · no account needed

Same family, other types

All lists and formats

15K+

Active C2s

50+

Frameworks

Hourly

Updates

2yr

History

Capabilities

Key features. Everything you need to protect your infrastructure and users.

Framework Detection

Identify Cobalt Strike, Metasploit, Sliver, and more.

Active Verification

All C2s verified active within 24 hours.

IP & Domain Data

Both IP addresses and domain names tracked.

SSL Fingerprints

JARM and JA3 fingerprints for identification.

Malware Families

Associated malware campaigns and actors.

Historical Data

First seen, last seen, and activity timeline.

Applications

Use cases. How security teams use this tool.

Firewall Blocking

Proactively block C2 infrastructure.

Threat Detection

Alert on connections to known C2 servers.

Incident Response

Identify C2 during malware investigations.

Threat Hunting

Search for C2 beacons in your environment.

Support

Frequently asked questions.

What C2 frameworks do you track?

Cobalt Strike, Metasploit, Brute Ratel, Sliver, and 50+ other frameworks and custom C2.

How do you detect C2 servers?

Active scanning, traffic analysis, SSL certificate patterns, and honeypot data.

How often are C2 feeds updated?

Feeds are updated hourly with active C2 servers verified within the last 24 hours.

Can I get historical C2 data?

Yes, we retain 2 years of C2 data including when servers were first/last seen active.

Cite this data

These figures may be quoted in research, articles and reports. Attribute them to isMalicious with a link to this page, so readers can check the numbers at the source and see how they move.

Attribution text: Source: isMalicious, C2 Infrastructure Feed — https://ismalicious.com/data/c2-feeds

Get Started

Ready to get started?

Join thousands of security teams using isMalicious to protect their infrastructure.

No credit card required · Free API key