Skip to content

Listed in Malware Feeds (Domain-Level)

It means that the domain has appeared in public or open-source malware intelligence feeds. These feeds collect indicators of compromise (IOCs) from security vendors, sandboxes, and malware-sharing communities.

Also surfaces as:
Listed in Malware Feeds (Subdomain-Level)Listed in Malware Feeds (URL-Level)Previously Listed in Malware Feeds (Domain-Level)Previously Listed in Malware Feeds (Subdomain-Level)Previously Listed in Malware Feeds (URL-Level)
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Listed in Malware Feeds' mean?

It means that the domain has appeared in public or open-source malware intelligence feeds. These feeds collect indicators of compromise (IOCs) from security vendors, sandboxes, and malware-sharing communities.

Why it matters02

What is the difference between Domain-Level, Subdomain-Level, and URL-Level listings?

Domain-Level listings indicate that the root domain itself (e.g., example.com) has been reported as malicious — a strong indicator. Subdomain-Level refers to specific hostnames (e.g., login.example.com) and URL-Level to specific paths or resources (e.g., example.com/malware.exe), which may represent partial or historical associations.

How analysts use it03

What does 'Previously Listed' mean?

It indicates that the domain appeared in malware feeds in the past but is no longer listed. This could mean the malicious infrastructure was dismantled, rebranded, or repurposed. However, historical association still increases risk.

Often paired with:block_domain
Evidence shape

What Listed in Malware Feeds (Domain-Level) looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "malware_sources",
  "name": "Listed in Malware Feeds (Domain-Level)",
  "group": "threat_intelligence_feed",
  "subgroup": "malware_association",
  "direction": "malicious",
  "evidence": {
    "sources_referencing": 12,
    "malware_families": [
      "emotet",
      "qakbot"
    ],
    "first_reference_days_ago": 11,
    "confidence": 0.91
  }
}
See in API reference
Siblings

Peers in Malware Association

1 other signal shares the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Flagged by Limited Security Vendors

It means that one or more commercial security vendors — including antivirus engines, sandboxes, or threat intelligence p

MaliciousCore
In the wild

See Listed in Malware Feeds (Domain-Level) fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Listed in Malware Feeds (Domain-Level). See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.