Kicking ACKs and taking domain names
Only domain trees from most common 8* C2 shown
Follow @SarlackLab on BlueSky/Mastodon for daily updates on malicious servers
Map history and C2 trends available in /C2-Logs/ directory
The redder: a square appears, the more command-and-control (C2) servers are hosted in that /8 space.
XKCD has a comic explaining IPv4 Hilbert curves
- 178.16.52.0/22
- 43.136.0.0/13
- 124.220.0.0/14
- 104.233.252.0/22
- 45.192.192.0/20
- 202.95.8.0/21
- 38.32.0.0/11
- 47.92.0.0/14
- 38.128.0.0/9
- 101.42.0.0/15
- 94.154.35.0/24
- 213.209.150.0/24
- 155.94.155.0/24
- 107.150.0.0/24
- 66.63.187.0/24
- 124.198.132.0/24
- 178.16.52.0/22
- 94.26.90.0/24
- 45.141.233.0/24
- 172.94.9.0/24
I built the Sarlack to "devour malware in a sandbox". The server automatically grabbed and analyzed malware samples for personal research and to assist my SOC. While studying network detection trends, I began to notice patterns among malicious IP addresses and abused parent-domains. I created maps to visualize this threat landscape using the fantastic resources provided by abuse.ch, drb-ra, Dee, Fred HK, Benkow_, Good__Bear, and Paul Melson (as well as the IOCs that the Sarlack uncovers too).
Read more about Sarlack-Lab map generation here