Frequently Asked Questions (FAQ)
The Feodo Tracker datasets are empty - is that right?
The Feodo Tracker datasets are currently empty thanks to various successful takedowns conducted by Law Enforcement Agencies, including Emotet in 2021 and Operation Endgame in 2024, which targeted the malware families tracked by Feodo Tracker. As a result, there are no active botnet C2 servers associated with these malware families at the moment, which is why the datasets are currently empty.
If you are looking for additional datasets to protect your organization/users from botnet C2 communications, we recommend contacting Spamhaus about their Botnet C2 IPs dataset (formerly BCL), which is available through access methods such as Border Gateway Protocol.
We at abuse.ch work closely with Spamhaus to maintain this dataset, which contains single IPv4 addresses hosting active botnet C2s. The status of these botnet controllers is re-evaluated several times a day to identify active botnet controllers only. The dataset contains approximately 2,000 – 3,000 entries, with up to 50 new detections every 24 hours, and is available in various formats.