webfilteringdatabase.com
Home Find Your Solution
Features
Domain Categorization API Real-Time Classification 59 Filtering Categories Offline Database (100M) ML Classification Content Classification
Industries
K-12 Schools Corporate Healthcare Government ISPs
Tools
Domain Lookup Bulk Categorization Category Explorer
Resources
Pricing API Documentation Login / Sign Up
Security Category

Botnet & C2 Domain Filtering

Cut off malware at the network layer by blocking the command-and-control domains botnets rely on. Over 2.1 million malicious infrastructure domains classified with multi-signal detection for SOC teams, firewalls, and DNS security platforms.

How Botnet & C2 Domains Are Detected

Botnet command-and-control (C2) infrastructure is the nervous system of a malware campaign. Once a device is infected, it reaches back to a controller domain to receive instructions, exfiltrate stolen data, or download additional payloads. Blocking that callback is one of the highest-leverage defensive actions available: even if an endpoint is compromised, severing its link to the controller neutralises most of the damage. Our botnet category maps this infrastructure across more than 2.1 million domains, updated continuously as campaigns rotate through new hosts.

Detection combines passive DNS analysis, malware sandbox telemetry, and network-behaviour modelling. When a sample is detonated in a sandbox, the domains and IP addresses it contacts are recorded and correlated against known campaign fingerprints. Fast-flux networks that rotate hundreds of IP addresses behind a single domain, and domain-generation algorithms (DGAs) that produce thousands of pseudo-random hostnames per day, are identified by their statistical signatures rather than by any single blocklist entry.

Because attackers register disposable domains in bulk and burn them quickly, static lists go stale within hours. Our pipeline weights registration recency, hosting reputation, name-server clustering, and TLS-certificate reuse to score newly observed domains before they have been widely reported. This predictive layer is what allows the category to flag emerging C2 infrastructure rather than only cataloguing yesterday's attacks.

The Botnet Threat Landscape

Botnets remain one of the most durable business models in cybercrime. A single operator can marshal tens of thousands of compromised devices into a rented platform for spam distribution, credential stuffing, distributed denial-of-service, or ransomware staging. What ties every one of these operations together is the command-and-control channel: the moment an infected device needs an instruction, a payload, or a place to send stolen data, it must reach out to infrastructure the attacker controls. That reach-out is both the botnet's greatest strength and its most exploitable weakness.

Modern botnets have grown resilient precisely because their operators expect that channel to be attacked. Fast-flux DNS rotates a domain across hundreds of compromised hosts in minutes. Domain-generation algorithms give each bot a daily list of thousands of candidate rendezvous points, only one of which the attacker needs to register. Peer-to-peer topologies remove the single point of failure entirely, and increasingly, controllers hide behind legitimate cloud services and content-delivery networks to blend in with normal traffic. A defensive approach built on static blocklists cannot keep pace with any of this.

The answer is to treat C2 detection as a continuous intelligence problem rather than a lookup. By fusing passive DNS history, sandbox-observed callbacks, DGA modelling, TLS fingerprinting, and registration analytics, it becomes possible to score infrastructure predictively — flagging the domain an algorithm will generate tomorrow, or the certificate an actor will reuse next week, before it has been weaponised against anyone. This is the philosophy behind our botnet category, and it is why the feed refreshes on a five-minute cycle rather than a daily one.

For defenders, the practical payoff is dwell-time reduction. Most breaches are not discovered at the moment of infection; they are discovered weeks later, often by an outside party. A device that beacons to a known C2 domain betrays itself the instant it is compromised, turning a silent, long-running intrusion into an immediate, high-confidence alert. Blocking the channel does not just stop data leaving — it converts the attacker's own infrastructure into a tripwire.

Detection Methodology

Multiple threat-intelligence signals combine to identify command-and-control infrastructure

Passive DNS Correlation

Historical resolution data reveals the IP addresses a domain has pointed to over time. Domains that share hosting with confirmed C2 servers, rotate through fast-flux IP pools, or resolve to bulletproof hosting ranges are flagged. Passive DNS lets us connect a freshly registered domain to established malicious infrastructure before it is used in an active campaign.

Sandbox Telemetry

Malware samples are detonated in isolated sandbox environments, and every network callback is logged. The domains contacted during execution become high-confidence C2 indicators. This behavioural evidence is the strongest possible signal: the domain is not merely suspicious, it is observably part of a live malware control channel.

DGA Recognition

Domain-generation algorithms produce large volumes of random-looking hostnames so that a botnet always has a fallback controller. Machine-learning classifiers trained on character-level entropy, n-gram distribution, and pronounceability detect DGA output even for families that have never been seen before, blocking the algorithm rather than chasing individual domains.

Registration Analysis

Bulk registration through privacy proxies, use of disposable email addresses, and clustering under a handful of registrars are strong risk multipliers. C2 domains are frequently registered days or hours before deployment. Our scoring treats registration recency combined with malicious hosting neighbourhoods as an early-warning indicator.

TLS Fingerprinting

Attackers reuse TLS certificates, self-signed certificate patterns, and JA3/JA3S fingerprints across their infrastructure. Correlating certificate metadata surfaces domains operated by the same threat actor even when hosting, registrar, and naming vary, extending coverage across an entire campaign from a single confirmed sample.

Continuous Re-scoring

Infrastructure is re-evaluated constantly. A domain may be dormant for weeks before activation, or a legitimate expired domain may be re-registered for malicious use. Continuous re-scoring promotes and demotes domains as evidence accumulates, so the feed reflects live threat activity rather than a static historical snapshot.

Policy & Use Cases

Botnet and C2 blocking is a core control for security operations, network defence, and DNS-layer protection

SOC & Threat Hunting

Security operations centres consume the botnet category as a threat-intelligence feed, matching outbound connections and DNS queries against known C2 infrastructure. A single hit on a C2 domain is often the first evidence of a compromised host, turning a silent infection into an actionable alert.

  • High-confidence indicators for SIEM correlation rules
  • Enables early detection of post-exploitation callbacks
  • Reduces dwell time by flagging infected endpoints
  • Contextual metadata: malware family, first-seen, hosting
  • Machine-readable feeds for automated enrichment

Firewall & IPS Enforcement

Next-generation firewalls and intrusion-prevention systems import the category to block egress traffic to malicious controllers. Because the control channel is severed, malware that has already bypassed endpoint defences cannot receive instructions or exfiltrate data.

  • Egress filtering that neutralises active infections
  • Blocks data exfiltration to attacker infrastructure
  • Integrates with NGFW and IPS policy engines
  • Covers fast-flux and DGA infrastructure
  • Updated frequently to track campaign rotation

Protective DNS

DNS-layer security services and recursive resolvers use the feed to return NXDOMAIN or a sinkhole address for C2 lookups. Protective DNS stops the callback before a TCP connection is ever attempted, protecting every device on the network without endpoint agents.

  • Blocks callbacks at the resolution stage
  • Protects unmanaged and IoT devices
  • No client software required
  • Sinkhole support for infection visibility
  • RPZ feeds for standard resolver integration

Critical Infrastructure & OT

Operational-technology and critical-infrastructure networks, where endpoint agents are often impossible to deploy, rely on network-layer botnet blocking to protect legacy and embedded systems that cannot defend themselves.

  • Agentless protection for embedded and legacy devices
  • Reduces risk to ICS and SCADA environments
  • Segmentation-friendly deployment models
  • Supports air-gapped feed delivery
  • Auditable blocking for compliance reporting

Botnet Category Statistics

Coverage and freshness metrics for malicious command-and-control infrastructure

2.1M+
C2 Domains Tracked
98.9%
Detection Precision
<0.2%
False Positive Rate
5 min
Feed Refresh Interval

Precision Without Over-Blocking

The cost of a false positive in a threat feed is high: block a legitimate domain and you may break a business-critical service. Botnet classification therefore demands both aggression against genuine infrastructure and restraint everywhere else. Compromised-but-legitimate hosts, shared hosting environments, and content-delivery networks that occasionally serve malicious payloads require careful handling so that one bad tenant does not blacklist an entire platform.

Our scoring separates dedicated malicious infrastructure from collateral hosting. A domain that exists solely to run a controller is blocked outright; a shared platform that has hosted a malicious subdomain is flagged at the subdomain or path level where possible, preserving access to the legitimate service. Confidence scores accompany every entry so that defenders can tune enforcement to their risk tolerance.

Analysts can choose strict enforcement for high-security segments and advisory-only scoring for general networks. Every classification carries supporting evidence — first-seen timestamps, associated malware families, and the signals that triggered the score — so security teams can validate an indicator before acting on it.

Integration Guide for Botnet Filtering

Deploy C2 blocking across DNS, firewall, and SIEM layers

Deployment Options

DNS-layer deployment is the fastest path to protection. Point recursive resolvers at our RPZ feed or query the API in-line, and callbacks to known C2 domains are blocked or sinkholed for every device on the network. This model requires no endpoint software and covers IoT and OT devices that cannot run agents.

Firewall and IPS integration adds egress enforcement. Import the category as a dynamic address or domain group and apply block rules to outbound traffic, ensuring that even fully compromised endpoints cannot reach their controllers. SIEM integration turns the same feed into detection: correlate DNS and proxy logs against the indicator set to surface infected hosts.

For automated pipelines, the real-time API returns classification, malware family, and confidence in a single sub-10ms call, while batch and streaming feeds support bulk enrichment and continuous synchronisation with your own intelligence platform.

  • DNS RPZ feeds with sinkhole support, refreshed every 5 minutes
  • STIX/TAXII and JSON feeds for SIEM and TIP integration
  • REST API with sub-10ms response times
  • SDKs for Python, Node.js, Go, Java, and C#

Domain Classification API

// Check botnet_c2 classification
curl -X GET "https://api.webfilteringdb.com/v1/lookup" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{"domain": "example-domain.com"}'

// Response
{
  "domain": "example-domain.com",
  "categories": ["botnet_c2"],
  "subcategory": "command_control",
  "confidence": 0.98,
  "action": "block"
}

Protective DNS RPZ Config

# BIND RPZ configuration for C2 sinkholing
zone "rpz.webfilteringdb.com" {
    type slave;
    masters { 198.51.100.1; };
    file "rpz-botnet-c2.db";
};

# Sinkhole C2 lookups to an internal collector
options {
    response-policy {
        zone "rpz.webfilteringdb.com"
            policy cname sinkhole.internal;
    };
};

Frequently Asked Questions

Common questions about deployment, coverage, and policy

What is a command-and-control (C2) domain?

A C2 domain is the address a piece of malware contacts to receive instructions, download additional payloads, or exfiltrate stolen data. It is the control channel between an infected device and the attacker. Blocking C2 domains severs that channel, so even a successfully installed piece of malware cannot be operated or used to remove data from the network.

How is this different from general malware filtering?

Malware filtering typically blocks the domains that deliver an infection — the drive-by download or malicious attachment source. The botnet category focuses on the post-infection control channel. The two are complementary: malware filtering reduces initial compromise, while C2 blocking neutralises infections that slip through, making them detectable and inert.

Will blocking C2 domains break legitimate services?

Our scoring separates dedicated malicious infrastructure from shared or compromised-but-legitimate hosting. Confidence scores accompany every entry, and where a controller hides on a shared platform we classify at the most specific level available. This keeps the false-positive rate below 0.2% so that legitimate cloud and CDN services remain reachable.

How quickly is new C2 infrastructure detected?

The feed refreshes every five minutes and uses predictive signals — DGA modelling, TLS fingerprint reuse, and registration analytics — to flag infrastructure before it is widely reported. This means many domains are scored as high-risk within hours of registration, often before an active campaign begins using them.

Can I use this to find already-infected devices?

Yes. Correlating your DNS and proxy logs against the botnet feed surfaces internal hosts that are beaconing to known controllers. A single match is strong evidence of compromise. Sinkholing C2 lookups to an internal collector gives you both the block and the visibility to identify which device is affected.

What delivery formats are available?

The category is available as DNS RPZ zones with sinkhole support, STIX/TAXII and JSON feeds for SIEM and threat-intelligence platforms, a real-time REST API with sub-10ms responses, and bulk downloads for offline enrichment. SDKs are provided for Python, Node.js, Go, Java, and C#.

Related Categories

Combine botnet blocking with related threat categories for defence in depth

Block Botnet Infrastructure at the Network Layer

Sever the command-and-control channel that malware depends on. 2.1 million C2 domains, refreshed every five minutes, ready for your DNS, firewall, and SIEM.