Statistics
Aggregates over the tracked dataset. Hover any chart for exact counts; definitions and methodology at the bottom of the page.
First seen, by year
Distribution of 59 samples with a confirmed first-seen date. Undated samples are excluded rather than estimated.
Infrastructure by family all families โ
APT vs non-APT samples
30 of 59 tracked samples belong to an APT-attributed family (the apt tag on family metadata) โ 50%. The rest are commodity or crimeware families.
Definitions & methodology
Record โ one (family, indicator, sample) combination. One sample with three C2s produces three records; one C2 seen in five samples produces five.
First seen โ the earliest observation date from VirusTotal, Hybrid Analysis or MalwareBazaar, or a date manually backfilled from a verifiable source. It is never the date this tracker ingested the sample. Samples without a confirmed date are excluded from the timeline instead of being estimated.
Resolving / dead โ a domain counts as resolving if it answered DNS at the most recent scheduled refresh; dead means it answered before but not now. Dead is a point-in-time observation, not a verdict โ botnet C2s routinely rotate back online.
Shared certificates โ a certificate counts as shared when samples from more than one family are signed with it. Because Android malware authors reuse public templates and leaked keys, a shared certificate is a pivot to investigate, not proof of a common operator.
Whois freshness โ cached per indicator and re-queried on the daily refresh once older than 7 days; each indicator page shows its query timestamp. Sub-domains of dynamic-DNS services (e.g. *.ddns.net) have no per-hostname registry record โ their whois legitimately shows nothing.
Samples are analysed locally and never published; only extracted indicators and metadata leave the machine. Data generated 2026-10-04.