Skip to content

Fast-Flux Behavior Detected

It indicates that the domain frequently changes its associated IP addresses, a known technique used by threat actors to evade detection, takedown, and blocking mechanisms. This pattern is typical in botnet infrastructures, phishing campaigns, and malware C2 systems.

Also surfaces as:
Aggressive Fast-Flux Activity
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Fast-Flux Behavior Detected' mean?

It indicates that the domain frequently changes its associated IP addresses, a known technique used by threat actors to evade detection, takedown, and blocking mechanisms. This pattern is typical in botnet infrastructures, phishing campaigns, and malware C2 systems.

Why it matters02

What is the difference between normal Fast-Flux and Aggressive Fast-Flux?

Standard Fast-Flux involves periodic IP changes, while Aggressive Fast-Flux Activity refers to extremely rapid IP rotation — sometimes every few minutes or seconds — making it nearly impossible for traditional defense systems to track or blacklist the infrastructure effectively.

How analysts use it03

Why is Fast-Flux a strong malicious indicator?

Because legitimate services rarely need such frequent IP rotation. Attackers use this technique to hide behind a large pool of compromised hosts or proxy nodes, spreading malicious traffic across dynamic networks.

Often paired with:block_domain
Evidence shape

What Fast-Flux Behavior Detected looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "too_many_ip_change",
  "name": "Fast-Flux Behavior Detected",
  "group": "relational_intelligence",
  "subgroup": "dns_relational_infra",
  "direction": "malicious",
  "evidence": {
    "shared_ip_domain_count": 1247,
    "ns_overlap_with": [
      "bad-domain-1.tld",
      "bad-domain-2.tld"
    ],
    "proximity_score": 0.84,
    "rapid_ip_change_count_30d": 38
  }
}
See in API reference
Siblings

Peers in DNS Relational Infrastructure

2 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Highly Shared IP

It indicates that a single IP address is used by a significantly large number of domains. This assessment is based on a

Malicious
Low Popularity Public NS Usage Rare Provider

It shows that the domain uses a rarely seen or low-visibility public nameserver provider. Such providers often lack stro

Malicious
In the wild

See Fast-Flux Behavior Detected fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Fast-Flux Behavior Detected. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.