Active Malware Hosting Domains

The domains listed below are currently hosting active malware. These are not just historically flagged domains -- each entry has at least one confirmed online malware URL at the time of this page's last update. Malware-hosting domains distribute payloads including information stealers, banking trojans, remote access tools, and ransomware droppers. Blocking these domains at the DNS level is one of the most effective ways to protect your network.

# Domain Active Malware URLs Total URLs Tracked Status
1 raw.githubusercontent.com 5590 5590 ACTIVE THREAT
2 github.com 673 673 ACTIVE THREAT
3 kpq.at 48 48 ACTIVE THREAT
4 cliftycreek.anondns.net 46 46 ACTIVE THREAT
5 everycarebd.com 43 43 ACTIVE THREAT
6 firebasestorage.googleapis.com 39 39 ACTIVE THREAT
7 simbhaolisugars.in 33 33 ACTIVE THREAT
8 www.simbhaolisugars.in 31 31 ACTIVE THREAT
9 solar-sanat.net 31 31 ACTIVE THREAT
10 aixcijiax.mcv.kr 27 27 ACTIVE THREAT
11 newdc35635.duckdns.org 26 26 ACTIVE THREAT
12 drive.google.com 26 26 ACTIVE THREAT
13 respaldo30000.duckdns.org 26 26 ACTIVE THREAT
14 dl.armour-inc-down.net 24 24 ACTIVE THREAT
15 coolcams.duckdns.org 24 24 ACTIVE THREAT
16 banking.bankaustria.at.dswcontracting.work 22 22 ACTIVE THREAT
17 my.com.au.debbiesimril.com 22 22 ACTIVE THREAT
18 bbos.minet.vn 21 21 ACTIVE THREAT
19 91-92-241-8.cprapid.com 21 21 ACTIVE THREAT
20 libss.0x504.com 20 20 ACTIVE THREAT
21 devilnet.xyz 20 20 ACTIVE THREAT
22 christophercheung.com 20 20 ACTIVE THREAT
23 mn.34509.su 20 20 ACTIVE THREAT
24 cms.hoangddt.net 19 19 ACTIVE THREAT
25 www.srv892825.hstgr.cloud 19 19 ACTIVE THREAT
26 img.ipxxxx.com 18 18 ACTIVE THREAT
27 fenbushijujuefuwu.com 18 18 ACTIVE THREAT
28 sc.c1s.su 18 18 ACTIVE THREAT
29 teamc2.duckdns.org 18 18 ACTIVE THREAT
30 beesoft.vn 18 18 ACTIVE THREAT

About Malware Hosting Domains

Malware hosting domains serve as distribution points for malicious software. Attackers use these domains to host payloads that are delivered through phishing emails, drive-by downloads, or exploit kits. Some domains are purpose-built for malware delivery, while others are legitimate services (such as file sharing platforms or compromised websites) being abused by threat actors.

Recommended actions: Block listed domains at your DNS resolver or firewall. Add them to your organization's blocklist. For DNS-level blocking, consider using Pi-hole, pfBlockerNG, or your enterprise DNS security solution. For detailed analysis of any domain, click its name in the table above.

Top Malicious IPs SSH Attacks Botnet C2 IPs How to Block Threats API Access