Live threat ranking

Top C2 Servers

The 10 most active command and control servers currently observed delivering malware across our honeypot network.

Ranked by downloads Malware hashes 31-day activity

Top 10 Most Active C2 Servers

Intelligence brief

Understanding C2 Infrastructure

How honeypot-detected C2 intelligence helps you disrupt botnet operations

What this ranking shows

Command and Control (C2) servers coordinate botnets and malware campaigns. Compromised systems call back to this infrastructure for instructions, payloads, data exfiltration, and attacks such as DDoS or spam.

Whatoblock's honeypot sensor network observes the chain from an inbound scanner to the C2 endpoint and any attempted malware download. The cards summarize detections, download attempts, distinct source scanners, and first- and last-seen activity.

Servers are ranked by observed malware-download activity, with detections used as additional context. The 31-day timeline separates isolated bursts from persistent infrastructure without treating activity volume as attribution.

Methodology

Data is sourced from Whatoblock's proprietary honeypot network. For programmatic access, explore our API documentation. To access the full botnet analysis tools, create a free account.