Search reference

C2 Tracker’s search works like a threat-intel platform’s: paste almost any indicator and get instant results, or combine typed operators for precise filters. Operators combine with AND โ€” every term must match.

Type anything in the box. The engine auto-detects what you gave it:

You type It matches
example.com that domain, plus any malware family using it
93.184.216.34 that IP, plus every domain currently resolving to it
65c655663b9b... (64 or 32 hex chars) the sample by SHA-256 / MD5
spynote the family name (fuzzy โ€” spynote also finds SpyNote v2 entries)
bankbot free-text across domains, family names and tags

Results show each indicator with its family, sample hash, first seen date and country flag; click through to the indicator page for the full Whois panel.

Operators

Operator Matches
family:spynote Malware family (substring, case-insensitive)
type:domain / type:ip / type:hash Indicator type
actor:bitter Attributed threat group
country:SG Country of the IP (or of IPs the domain resolves to) โ€” ISO code
asn:9009 Autonomous system number
port:2222 C2 port
tag:banking Dataset tag (e.g. android, banking, iot)
cert:ab12cdโ€ฆ Samples signed with this certificate (SHA-256 fingerprint prefix; see the certificate pages)
signer:android Certificate subject CN / organization (substring)
signed:true / signed:false Whether the sample carries a code-signing certificate
sha256:ab12cdโ€ฆ The sample by SHA-256 prefix
registrar:namecheap Domain registrar (substring)
source:local How the record entered the dataset
resolves:true Domain answered DNS at the last refresh
first_seen:2026-01 First seen (month YYYY-MM or date YYYY-MM-DD) โ€” also relative: first_seen:<7d (last 7 days), first_seen:>90d (older than 90 days); units d/w/y
dead:true Domain/IP seen before but no longer responding

Anything without a : is treated as a quick-search term (IOC detection first, then family, then free-text).

Facets

The sidebar mirrors the Hybrid Analysis workflow: click Family, Type, Status, Country, Tags (including apt, banking, signed, dead, resolving), First seen ranges or Source and the matching operator:value token is added to your query (click again to remove it). Counts update against everything except that facet group, so you can see what each filter would add. The full filter state lives in the URL โ€” searches are shareable as links.

Examples

You can also browse the full dataset in the filterable Indicators table โ€” per-column filters, sorting and pagination, no query syntax needed.

Indicator page fields

Every indicator has a detail page:

Data caveats