Data as of Aug 25, 2026 · Based on 338 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
For an affordable threat intelligence API tracking malware C2 servers, Hunt.io is frequently noted for providing high-confidence, actionable data. If budget is a primary concern, community-driven projects like Abuse.ch (specifically
ThreatFox) and AlienVault OTX offer free, near real-time access to indicators, often serving as critical, cost-effective base components for security defense workflows.
Named in 48% of answers
Named in 45% of answers
Best for high-confidence data on active malware infrastructure. It is purpose-built for C2 detection and integrates directly into security platforms, offering a clear advantage for actionable threat intelligence.
Named in 40% of answers
Named in 36% of answers
For affordable and actionable data specifically tracking malware command-and-control (C2) servers, **Feodo Tracker** and **URLhaus** by Abuse.ch provide **free, high-utility APIs** with **no cost** or paid tiers…
For affordable and actionable data specifically tracking malware command-and-control (C2) servers, Feodo Tracker and URLhaus by Abuse.ch provide free, high-utility APIs with no cost or paid tiers required.
Top affordable and open-source threat intelligence options specializing in C2 and malicious infrastructure include:
| Feed / API Source | Primary Focus | Cost | API Format / Integration |
|---|---|---|---|
| Feodo Tracker | Botnet C2 IP addresses (Emotet, Dridex, QakBot) | Free | JSON, CSV, RSS via Feodo Tracker API |
| URLhaus | Malicious URLs and payload drop/C2 sites | Free | JSON API, CSV, AbuseHelper |
| AlienVault OTX | Community-driven IoCs and C2 "pulses" | Free | Robust REST API, STIX/TAXII |
| MalwareBazaar | Malware samples and associated infrastructure hashes | Free | JSON API for querying hashes/payloads |
Details on Top Recommendations
Would you like help with sample API integration scripts (like Python or cURL) for Feodo Tracker or URLhaus, or are you looking for commercial options that include advanced attribution and risk-scoring?
If your main requirement is **“new malware C2 infrastructure, with enough context to act on it,”** I’d start with **abuse.ch ThreatFox**, rather than paying for a broad commercial CTI feed. ### Best options - **[threatfox.abuse.ch](https://threatfox.abuse.ch/api/?utm_source=chatgpt.com) — best overall value**
If your main requirement is “new malware C2 infrastructure, with enough context to act on it,” I’d start with abuse.ch ThreatFox, rather than paying for a broad commercial CTI feed.
threatfox.abuse.ch — best overall value
Free community API under fair-use terms.
Specifically exposes botnet_cc indicators, including domains, IPs and URLs.
Returns useful context such as malware family, IOC type, first-seen data, confidence and references.
You can query IOCs from the last 1–7 days, which makes it practical for detecting newly reported C2 infrastructure.
Good fit for feeding a SIEM/TIP, automatically creating detection rules, or enriching outbound-connection alerts.
urlhaus.abuse.ch — excellent complementary feed
Free community API under fair-use terms.
Focuses on malicious URLs used to distribute malware rather than C2 exclusively.
Data is updated frequently; database/IDS exports are generated every five minutes.
Particularly useful for catching infrastructure associated with malware delivery and then correlating it with C2 indicators from ThreatFox.
feodotracker.abuse.ch — very actionable, but currently narrower
Provides C2 IPs and is designed specifically for blocking/hunting.
Its IP blocklist is generated every five minutes and only adds an IP after it produces a valid botnet-C2 response.
However, the current Feodo Tracker datasets are empty because the malware families it tracks have been disrupted by takedowns. Its FAQ points users toward Spamhaus' broader Botnet Controller List instead.
spamhaus.com — worth considering if you need production SLAs
Provides a unified API over URLhaus, ThreatFox, MalwareBazaar and YARAify.
Better choice if you need commercial-grade reliability/support rather than relying on community-feed fair-use terms.
For a budget-conscious SOC, I'd use:
ThreatFox → C2 IOC ingestion → enrichment with URLhaus/MalwareBazaar → SIEM/TIP → automated detection/blocking
The important distinction is that ThreatFox is closer to what you asked for: its API explicitly identifies botnet_cc indicators and associates them with malware families.
If you tell me your approximate budget (e.g. $0, <$100/mo, <$500/mo, or enterprise) and whether you need IP-only, domains/URLs, or full STIX/MISP, I can narrow this down to 3–5 feeds and compare their APIs, freshness, coverage, and licensing.
Finding an affordable or free threat intelligence feed with high-confidence, actionable data on malware command-and-control (C2) infrastructure usually means leaning into reputable open-source intelligence (OSINT) projects or developer-friendly commercial…
Finding an affordable or free threat intelligence feed with high-confidence, actionable data on malware command-and-control (C2) infrastructure usually means leaning into reputable open-source intelligence (OSINT) projects or developer-friendly commercial APIs.
The best options range from completely free community projects to specialized, cost-effective commercial feeds:
If you tell me your budget range and how you plan to consume the data (e.g., direct firewall blocking vs. SIEM enrichment vs. automated threat hunting), I can help narrow down which API format and provider fits your stack best.
If your priority is **new malware C2 infrastructure at low cost**, I’d start with **ThreatFox**, then consider a paid feed only if you need higher reliability or broader coverage. ### Best options - **[threatfox.abuse.ch](https://threatfox.abuse.ch/api/?utm_source=chatgpt.com) — best budget choice**
If your priority is new malware C2 infrastructure at low cost, I’d start with ThreatFox, then consider a paid feed only if you need higher reliability or broader coverage.
threatfox.abuse.ch — best budget choice
Free under its fair-use policy; commercial use may require the enhanced paid API.
Specifically focused on malware IOCs and associates indicators with malware families.
You can query recent IOCs and search by IOC, malware family, hash, tag, etc.
Particularly useful for extracting IP/domain C2 indicators, rather than merely generic malicious domains.
Supports JSON/CSV plus MISP, Suricata and RPZ exports.
One caveat: IOCs older than six months are now expired from API/export results, which is actually useful for keeping an operational feed fresh.
urlhaus.abuse.ch — excellent companion feed
Also free under fair use.
More focused on malware-delivery URLs than C2 specifically, so I wouldn't use it alone for C2 detection.
Its database exports are regenerated every five minutes, making it useful for near-real-time ingestion.
spamhaus.com — best upgrade path
Commercial-grade API built around ThreatFox, URLhaus, MalwareBazaar and YARAify data.
Offers more reliable infrastructure and support than the community API.
Importantly, Spamhaus says it has separate APIs for botnet C2 intelligence and Passive DNS, which may be a better fit if your requirement is specifically discovering active C2 servers.
For a cost-conscious SOC, I'd use:
ThreatFox → filter for C2-related IOC types → enrich with DNS/ASN/WHOIS → score by recency + malware family + confidence → push to SIEM/firewall/EDR.
That gives you something considerably more actionable than a raw "bad IP" feed. ThreatFox IOCs also have confidence and contextual information available, which can be incorporated into scoring.
If you tell me your approximate budget (e.g. <$100/mo, $500/mo, $2k/mo) and whether you need IPs only, domains, or IP+domain+URL, I can compare 5–8 current feeds specifically for fresh C2 discovery, API limits, coverage, and price.
If your main requirement is **“new malware C2 servers, with enough context to act on them”**, I’d start with **abuse.ch’s ThreatFox**, rather than paying for a large commercial TI platform. ### Best options | Feed/API | Cost | C2 coverage | Actionability | My take |
If your main requirement is “new malware C2 servers, with enough context to act on them”, I’d start with abuse.ch’s ThreatFox, rather than paying for a large commercial TI platform.
| Feed/API | Cost | C2 coverage | Actionability | My take |
|---|---|---|---|---|
| ThreatFox | Free under fair-use; commercial tier available | IPs, domains, URLs, hashes, ip:port | ⭐⭐⭐⭐⭐ | Best starting point |
| Feodo Tracker | Free | C2 IPs, ports, malware family | ⭐⭐⭐⭐⭐ | Excellent for specific botnets |
| URLhaus | Free under fair-use; commercial tier available | Malware-hosting URLs/domains | ⭐⭐⭐⭐ | Great companion feed |
| Spamhaus BCL | Commercial | Active botnet-controller IPs | ⭐⭐⭐⭐⭐ | Strong choice when reliability matters |
| RelayShield TI API | $499/mo starting tier | Aggregated IOC/TI data | ⭐⭐⭐⭐ | Convenient, but expensive for a small deployment |
ThreatFox is particularly well suited to your use case. Its API exposes malware IOCs including ip:port, domains, URLs and hashes, along with malware attribution and confidence levels. It also has a “recent IOCs” query, so you can poll for newly observed infrastructure.
For example, a new C2 record can look conceptually like:
IOC: 76.x.x.x:443
IOC type: ip:port
Malware: <family>
Confidence: 75
Threat type: botnet_cc
That combination is much more useful operationally than a bare IP blocklist.
I'd combine:
Feodo Tracker is especially useful because its recommended C2 blocklist is restricted to infrastructure that has actually responded with a valid botnet C2 response, and its feeds are regenerated every five minutes.
One caveat: Feodo Tracker currently has no active entries because the malware families it tracks were heavily disrupted by takedowns. abuse.ch now points users toward Spamhaus's broader Botnet Controller List for currently active botnet C2 infrastructure.
The newer abuse.ch/Spamhaus commercial API is probably the most natural upgrade. It provides unified access to ThreatFox, URLhaus, MalwareBazaar and YARAify data, rather than forcing you to integrate several APIs independently.
If you're a small SOC, though, I'd prototype with the free ThreatFox + URLhaus feeds first. You can build a useful pipeline without committing to a $500+/month vendor.
If you tell me roughly how many IOCs/day you need and whether you're feeding a SIEM, SOAR, firewall, or custom application, I can narrow this down to 2–3 APIs and compare their pricing, freshness, fields, and integration effort.
When looking for actionable and affordable intelligence specifically targeting command-and-control (C2) infrastructure, you don't necessarily have to jump straight into expensive enterprise platforms like Recorded Future or…
When looking for actionable and affordable intelligence specifically targeting command-and-control (C2) infrastructure, you don't necessarily have to jump straight into expensive enterprise platforms like Recorded Future or ThreatConnect.
The best options range from high-grade, zero-cost open-source projects to specialized commercial feeds that won't break the bank.
Top Free & Open-Source C2 Feeds (with APIs/Downloads)
Affordable Specialized Commercial Feeds
Community Perspectives
If you'd like to narrow this down, let me know:
C2
c2.com
Finding an affordable threat intelligence feed that specializes explicitly in fresh, actionable malware Command-and-Control (C2) infrastructure—without paying enterprise prices like Recorded Future or Flashpoint—comes down to a mix of specialized commercial scrapers/scanners and top-tier community-driven…
Finding an affordable threat intelligence feed that specializes explicitly in fresh, actionable malware Command-and-Control (C2) infrastructure—without paying enterprise prices like Recorded Future or Flashpoint—comes down to a mix of specialized commercial scrapers/scanners and top-tier community-driven projects.
The best options balancing high-actionability on C2 infrastructure with accessible or low-cost API models include:
To help narrow down the right fit, could you share:
If your priority is **affordable + actionable C2 infrastructure**, I’d start with **ThreatFox** rather than a broad commercial TI platform. ### Best options | Feed/API | Cost | C2-specific data | Actionability | Best for |
If your priority is affordable + actionable C2 infrastructure, I’d start with ThreatFox rather than a broad commercial TI platform.
| Feed/API | Cost | C2-specific data | Actionability | Best for |
|---|---|---|---|---|
| ThreatFox / abuse.ch | Free under fair-use; commercial use may require paid access | Excellent | High | New malware C2 IPs/domains |
| URLhaus / abuse.ch | Free under fair-use | Indirect | High | Malware delivery infrastructure |
| Pulsedive | Free tier; Pro currently listed at $29/mo | Good, broader TI | Good | Enrichment + multiple intelligence sources |
| Commercial abuse.ch API | Paid | Excellent | Very high | Production/commercial deployments |
My pick: ThreatFox. Its API specifically exposes botnet_cc indicators, including C2 domains and IP:port combinations, and you can request IOCs first seen within the last 1–7 days. It also associates indicators with malware families and provides confidence/context fields.
For example, your ingestion pipeline could poll recent IOCs and filter for:
threat_type = botnet_ccioc_type = domain, ip, or ip:portfirst_seen within your desired freshness windowThat gives you a much more useful feed for "alert me when a new C2 appears" than simply consuming a giant IP/domain blacklist.
URLhaus focuses on malware-distribution URLs rather than C2, but it complements ThreatFox well: you can correlate newly observed payload-delivery infrastructure with C2 infrastructure. Its database exports are generated every five minutes, and its API supports automated queries.
Pulsedive is worth considering if you want one API for indicator lookups, threat/malware context, feeds, and on-demand analysis. Its API supports indicator, threat, explore, and feed endpoints, and API access is available with a free account.
The important distinction is that Pulsedive's full bulk feeds are much more expensive than its basic API access, so I wouldn't buy a feed subscription if your only requirement is newly discovered C2s.
For a small SOC/security engineering team, I'd do:
ThreatFox → normalize/deduplicate → confidence/age filtering → SIEM/SOAR → DNS/firewall/EDR enrichment
Then optionally add URLhaus for malware-delivery infrastructure and Pulsedive for enrichment.
One caveat: ThreatFox's free API is subject to fair-use rules, and abuse.ch explicitly says commercial/for-profit usage may require its paid commercial API. threatfox.abuse.ch If this is going into a commercial product or a high-volume production pipeline, I'd get the commercial-use terms sorted out rather than building around the community endpoint.
If you tell me roughly how many IOCs/day you need (e.g. 1K, 10K, 100K) and whether this is internal SOC use or a commercial product, I can narrow it down to the cheapest viable feed and compare current pricing/API limits.
If your priority is **new malware C2 infrastructure + an API + low cost**, I’d start with **ThreatFox**. | Feed | Best for | Cost | Actionable fields | |---|---|---|---|
If your priority is new malware C2 infrastructure + an API + low cost, I’d start with ThreatFox.
| Feed | Best for | Cost | Actionable fields |
|---|---|---|---|
| ThreatFox API | Broad, newly observed malware C2 IOCs | Free | IP:port, domains, URLs, malware family, first-seen, confidence, tags |
| Feodo Tracker | High-confidence botnet C2 IPs | Free | C2 IP, port, malware, first/last seen, status, ASN |
| URLhaus API | Malware delivery infrastructure | Free community tier | Malicious URLs, hosts, payloads, hashes, timestamps |
ThreatFox is particularly well suited to your requirement because its API explicitly labels botnet_cc indicators and distinguishes domain, IP:port, URL, etc. It also associates indicators with malware families and provides confidence information. You can query IOCs from the last 1–7 days, making it useful for detecting newly appearing infrastructure.
You can get an API key for free, and the project provides example scripts for pulling recent IOCs programmatically.
For example, your ingestion pipeline could periodically pull recent indicators and filter on:
threat_type = botnet_cc
first_seen >= now - 24h
confidence_level >= 70
ioc_type in (ip:port, domain, url)
That gives you a much more useful stream than a generic malicious-IP blocklist.
Feodo Tracker is excellent if high-confidence active C2 IPs are more important than breadth. Its C2 blocklist is regenerated every 5 minutes, and an IP is only added after it produces a valid botnet-C2 response, specifically to keep false positives down. It also exposes JSON and SIEM/IDS-friendly formats.
One caveat: the traditional Feodo Tracker dataset is currently empty because the tracked malware families have largely been disrupted by takedowns. The project now points users toward Spamhaus's broader Botnet Controller List for active botnet C2 coverage.
URLhaus is complementary rather than a direct C2 feed. It is particularly good for catching malware distribution URLs and compromised infrastructure associated with campaigns. Its community API is free under fair-use principles, although commercial users may need the paid enhanced API.
Recommended inexpensive stack:
ThreatFox → primary C2 feed, Feodo/Spamhaus → high-confidence active C2, and URLhaus → malware delivery infrastructure.
If you tell me roughly how many IOCs/day you need and whether you want STIX/TAXII, JSON REST, or a simple CSV feed, I can narrow this down to 2–3 commercial options with current pricing and API limits.
For an affordable or free, highly actionable API feed tracking live malware command-and-control (**C2** ) infrastructure, [Hunt.io C2 Feed](https://hunt.io/products/cyber-threat-intelligence-feeds) and abuse.ch URLhaus / ThreatFox are the top choices. **Hunt.io** provides low-cost, high-confidence active…
For an affordable or free, highly actionable API feed tracking live malware command-and-control (C2 ) infrastructure, Hunt.io C2 Feed and abuse.ch URLhaus / ThreatFox are the top choices. Hunt.io provides low-cost, high-confidence active infrastructure telemetry via daily JSON API pulls, while abuse.ch provides robust, free community-driven intelligence.
Top Affordable and Actionable C2 Feeds
If you can share your budget range (free OSINT vs. paid commercial) and whether you need automatic STIX/TAXII integration or simple JSON, I can help you narrow down the best API implementation.