# Feodo Tracker C2 Scraper (`parseforge/feodo-tracker-c2-scraper`) Actor

Tap the abuse.ch Feodo Tracker blocklist for live botnet command and control servers tied to Emotet, QakBot, and Dridex. Each row carries IP address, port, online status, ASN, country, and malware family. Built for firewall blocklisting, SOC alert enrichment, and threat hunting.

- **URL**: https://apify.com/parseforge/feodo-tracker-c2-scraper.md
- **Developed by:** [ParseForge](https://apify.com/parseforge) (community)
- **Categories:** Other, Developer tools, Automation
- **Stats:** 2 total users, 1 monthly users, 90.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $6.00 / 1,000 results

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

![ParseForge Banner](https://github.com/ParseForge/apify-assets/blob/ad35ccc13ddd068b9d6cba33f323962e39aed5b2/banner.jpg?raw=true)

## 🛡️ Feodo Tracker C2 Scraper

> 🚀 **Pull the live abuse.ch Feodo Tracker botnet C2 blocklist in one run.** Get every command-and-control server with IP, port, online status, ASN, country, and malware family, ready for blocklisting and SOC enrichment.

Feodo Tracker is a public threat-intelligence project run by abuse.ch that tracks the command-and-control (C2) infrastructure behind major banking trojans and loaders such as Emotet, QakBot, Dridex, TrickBot, BumbleBee and Pikabot. This Actor fetches the official Feodo Tracker IP blocklist and returns one clean row per C2 server so security teams can ingest fresh indicators of compromise (IOCs) without scraping HTML.

This is a defensive, public-data threat-intelligence tool. Every record comes straight from the abuse.ch public download feed. Use it to feed firewall and SIEM blocklists, enrich alerts in a SOC, hunt for malicious infrastructure, or back research into botnet hosting patterns.

| 🎯 Target Audience | 💡 Primary Use Cases |
|---|---|
| SOC and blue-team analysts | Blocklist firewalls, proxies, and DNS |
| Threat intelligence teams | Enrich alerts with C2 context |
| Incident responders | Confirm whether an IP is a known C2 |
| Detection engineers | Build and tune IOC detections |
| Security researchers | Study botnet hosting and ASN trends |

### 📋 What the Feodo Tracker C2 Scraper does

- Fetches the official abuse.ch Feodo Tracker IP blocklist (full or recommended).
- Returns one row per C2 server with IP, port, status, ASN, country, and malware family.
- Filters by malware family (for example Emotet or QakBot), online status, and country.
- Caps the number of rows returned so you can pull a quick sample or the whole list.
- Uses only the public download feed, no login, no API key, no images.

### 📊 Data fields

Each record includes: `asName`, `asNumber`, `country`, `firstSeen`, `hostname`, `ipAddress`, `lastOnline`, `listType`, `malware`, `port`, `results`, `scrapedAt`, `status`. These field names come straight from the actor's dataset schema, so what you see here is what lands in your dataset.

### 🚀 How to use

1. Sign in or create a free Apify account using [this sign-up link](https://console.apify.com/sign-up?fpr=vmoqkp).
2. Open the Feodo Tracker C2 Scraper and pick the `full` or `recommended` blocklist.
3. Optionally set a malware family, status, or country filter.
4. Set `maxItems` and click Start.
5. When the run finishes, browse the dataset or pull it through the API into your tools.

### 🔗 Recommended Actors

- [URLhaus Malware URLs Scraper](https://apify.com/parseforge/urlhaus-malware-urls-scraper). Pull the abuse.ch URLhaus feed of malware distribution URLs.
- [Vulnerability Security Intel Scraper](https://apify.com/parseforge/vulnerability-security-intel-scraper). Collect structured vulnerability and security intelligence.
- [GitHub Security Advisories Scraper](https://apify.com/parseforge/github-security-advisories-scraper). Track CVE-backed advisories across open source packages.
- [IP Geolocation Scraper](https://apify.com/parseforge/ipapi-geolocation-scraper). Enrich any IP with country, ASN, and network details.
- [RIPEstat Scraper](https://apify.com/parseforge/ripestat-scraper). Query RIPE network and routing data for ASNs and prefixes.

> 💡 **Pro Tip:** browse the complete [ParseForge collection](https://apify.com/parseforge).

> **⚠️ Disclaimer:** This is an independent tool and is not affiliated with abuse.ch or the Feodo Tracker project. Only publicly available data is collected, and it is provided for defensive security and research purposes.

### 🆘 Need Help?

If you hit a bug, have questions about setup, or need a scraper we haven't built yet, open our [contact form](https://tally.so/r/BzdKgA) or write to parseforge@protonmail.com. We also take on paid custom data projects.

For faster answers, join our [Discord](https://parseforge.co/discord). It's the best place to get support and suggest new actors.

# Actor input Schema

## `listType` (type: `string`):

Which abuse.ch Feodo Tracker feed to fetch. 'Full' returns every tracked botnet C2 server. 'Recommended' returns the curated subset abuse.ch suggests for active blocking.

## `malware` (type: `string`):

Optional. Keep only C2 servers tied to this malware family, for example 'Emotet', 'QakBot', or 'Dridex'. Case insensitive, partial match. Leave empty to return every family.

## `status` (type: `string`):

Filter by C2 server status. 'Online' returns servers seen responding recently. 'Offline' returns sinkholed or dead C2s. 'Any' returns both.

## `country` (type: `string`):

Optional. Keep only C2 servers hosted in this country, given as a two letter ISO code, for example 'US', 'GB', or 'RU'. Leave empty for all countries.

## `maxItems` (type: `integer`):

How many C2 servers to collect per run.

## Actor input object example

```json
{
  "listType": "full",
  "status": "any",
  "maxItems": 10
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "maxItems": 10
};

// Run the Actor and wait for it to finish
const run = await client.actor("parseforge/feodo-tracker-c2-scraper").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "maxItems": 10 }

# Run the Actor and wait for it to finish
run = client.actor("parseforge/feodo-tracker-c2-scraper").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "maxItems": 10
}' |
apify call parseforge/feodo-tracker-c2-scraper --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=parseforge/feodo-tracker-c2-scraper",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/QDY3W2eoI7dqGUcZg/builds/zDjEVPajSsUOfx78A/openapi.json
