Dashboard
New Direct Connection Alerts
Direct connections observed within the last 7 days.
Loading alerts...
Weekly Unique Direct IPs by Domain
Unique direct source IPs observed per domain by week.
Results
| Evidence | Domain | Source IP | Location | ASN | Subdomains | HTTP Hosts | TLS SNI | Destination Ports | Protocols | First Seen | Last Seen | Events |
|---|
About MalWhere
Malware Domains and Corresponding Families
Worm:Win32/Rimecud.B is a malware family that spreads through removable media and instant messaging platforms. It also contains backdoor functionality that allows unauthorized access to an affected machine. This type of worm was prevalent between 2009 and 2013 and still exists today, as evidenced by this project.
- prichaonica.com
- brand-clothes.net
- arminboutique.com
- dnsentrymx.com
- sexy-serbian-girls.info
About This Platform
This platform provides visibility into near real-time activity associated with historical malware domains that may still be active. The intent is that service providers, law enforcement, and SOC teams can use this platform to search, identify, locate, and respond to remove beaconing malware as well as determine how it remained undetected for so long.
Most networks that still host this malware are utilizing significantly outdated operating systems and/or have major visibility and detection gaps in their overall network environment. This platform will remain free to reinforce the security of organizations with limited visibility.
Telemetry Window
The telemetry displayed on this site is collected during a limited observation window every day and should be interpreted as a snapshot rather than a complete historical record. This sinkhole automation was started in June 2026.
Want to Support?
If you own a malware domain that is likely still beaconing from victim networks, you can transfer ownership to us for daily monitoring in this dashboard. Serious inquiries can email us at research@venatorcyber.io.
Methodology
Understanding the Data
DNS resolution activity typically represents requests made by recursive DNS infrastructure, which may or may not be inside the affected organization. Direct traffic connections are stronger evidence because they identify a public-facing network path that attempted to reach the sinkhole infrastructure.
DNS Resolves vs Direct Traffic
- DNS Resolves: Requests observed from recursive DNS servers.
- Direct Traffic: Connections directly observed hitting the sinkhole IPs.
- New Direct Connection Alerts: Direct connections first observed within the last 7 days.
Scanner Filtering
MalWhere attempts to filter obvious internet scanners using reputation sources and behavior-based filtering. Some new or unknown scanners may still appear in the dataset.
First Seen and Last Seen
First Seen is the earliest observed event for that source IP, domain, and evidence type. Last Seen is the most recent observed event for the same grouping.
IP searches may show multiple domains for the same IP because one endpoint or network can contact more than one monitored malware domain.