Search reference
C2 Tracker’s search works like a threat-intel platform’s: paste almost any indicator and get instant results, or combine typed operators for precise filters. Operators combine with AND โ every term must match.
Quick search
Type anything in the box. The engine auto-detects what you gave it:
| You type | It matches |
|---|---|
example.com |
that domain, plus any malware family using it |
93.184.216.34 |
that IP, plus every domain currently resolving to it |
65c655663b9b... (64 or 32 hex chars) |
the sample by SHA-256 / MD5 |
spynote |
the family name (fuzzy โ spynote also finds SpyNote v2 entries) |
bankbot |
free-text across domains, family names and tags |
Results show each indicator with its family, sample hash, first seen date and country flag; click through to the indicator page for the full Whois panel.
Operators
| Operator | Matches |
|---|---|
family:spynote |
Malware family (substring, case-insensitive) |
type:domain / type:ip / type:hash |
Indicator type |
actor:bitter |
Attributed threat group |
country:SG |
Country of the IP (or of IPs the domain resolves to) โ ISO code |
asn:9009 |
Autonomous system number |
port:2222 |
C2 port |
tag:banking |
Dataset tag (e.g. android, banking, iot) |
cert:ab12cdโฆ |
Samples signed with this certificate (SHA-256 fingerprint prefix; see the certificate pages) |
signer:android |
Certificate subject CN / organization (substring) |
signed:true / signed:false |
Whether the sample carries a code-signing certificate |
sha256:ab12cdโฆ |
The sample by SHA-256 prefix |
registrar:namecheap |
Domain registrar (substring) |
source:local |
How the record entered the dataset |
resolves:true |
Domain answered DNS at the last refresh |
first_seen:2026-01 |
First seen (month YYYY-MM or date YYYY-MM-DD) โ also relative: first_seen:<7d (last 7 days), first_seen:>90d (older than 90 days); units d/w/y |
dead:true |
Domain/IP seen before but no longer responding |
Anything without a : is treated as a quick-search term (IOC detection
first, then family, then free-text).
Facets
The sidebar mirrors the Hybrid Analysis workflow: click Family,
Type, Status, Country, Tags (including apt, banking,
signed, dead, resolving), First seen ranges or Source and
the matching operator:value token is added to your query (click again
to remove it). Counts update against everything except that facet
group, so you can see what each filter would add. The full filter state
lives in the URL โ searches are shareable as links.
Examples
family:xenomorph type:domainโ all Xenomorph C2 domains.family:spynote port:2222โ SpyNote panels on port 2222.93.184.216.34โ pivot: which families use this IP, and which domains point at it.country:SG last_seen:2026-09โ anything Singapore-hosted still live this month.family:androrat dead:trueโ AndroRat infrastructure that has gone dark (useful when comparing against your own telemetry).cert:ab12cd34โ every indicator from samples signed with this certificate. A lead, not proof: signing keys are reused, and Android samples are often signed with the public Android debug certificate, so a shared certificate doesn’t by itself mean one operator. Certificate pages list every signed sample.
You can also browse the full dataset in the filterable Indicators table โ per-column filters, sorting and pagination, no query syntax needed.
Indicator page fields
Every indicator has a detail page:
- IOC & type โ the indicator, its type, port and protocol.
- Family / actor / sample โ which malware uses it, the attributed group where known, and the sample hash it was extracted from.
- Seen โ first and last time the tracker confirmed it.
- Resolution โ current A records (domains) or PTR context (IPs).
- Whois panel โ for domains: registrar, registration/expiration dates, nameservers, domain status codes. For IPs: network range (CIDR), network name, country, abuse contact. Data comes from RDAP and is refreshed on the tracker’s daily schedule; the queried at timestamp on the page tells you how fresh it is.
Data caveats
- Whois is a point-in-time snapshot. Registrar and expiry data is exactly what the registry returned on the query date.
dead:truemeans “not responding at last refresh”, not “never coming back” โ botnet C2s routinely rotate back online.- Country for a domain is derived from where its current IP resolves; fast-flux or CDN-fronted C2s will show the CDN’s country, not the operator’s.