VORANT. Threat Intelligence Sign in Get the full feed

abuse.ch sinkholing 20K domains for botnet tracking

low vulnerability

abuse.ch operates a nonprofit sinkhole infrastructure handling 20,000+ malicious domains to identify infected machines and assist ISPs and CERTs with remediation efforts.

abuse.ch describes their operational sinkholing infrastructure used to track and remediate malware infections at scale. The organization currently sinkholes over 20,000 domain names handling up to 1,000 HTTP requests per second, working with partners Shadowserver and Spamhaus to deliver botnet infection data to network owners and national CERTs. Over the past six years, abuse.ch has sinkholed more than 50,000 domains and helped identify millions of infected computers worldwide.

Sinkholes operate by taking control of botnet command-and-control infrastructure—either by registering expired domains or through legal seizure—and directing bot traffic to monitoring servers that log connection details including source IPs, timestamps, user agents, and HTTP headers. This data enables ISPs to identify infected subscribers and implement remediation measures such as walled gardens that isolate compromised systems until they are cleaned. The technique has been instrumental in botnet takedowns conducted by security researchers and law enforcement.

Operating sinkholes presents both technical and legal challenges, particularly around handling personally identifiable information that infected machines may transmit. The EU's GDPR regulation has complicated sinkhole operations, raising questions about data protection compliance when collecting IP addresses and other potentially identifying information. Despite these challenges, abuse.ch continues to operate their sinkhole infrastructure on a nonprofit basis, providing free reporting services to network owners and CERTs through their partnerships.

Source reporting: https://abuse.ch/blog/sinkholes-and-internet-hygiene

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free