Malware distributors often rely on "living" infrastructure—sites that stay up just long enough to infect a few thousand victims before moving to a new domain. By aggregating these ephemeral threats into one place, Malc0de allows security professionals to: Proactively Block Traffic:
You’ll need to scrape or periodically download the static list. No real-time query API, which limits integration into automated SOAR playbooks.
However, for historians of malware, researchers studying the evolution of exploit kits (specifically the RIG EK), or those maintaining legacy air-gapped systems, the archived data from the Malc0de database remains an invaluable reference corpus.
Commercial feeds often produce false positives. Malc0de’s entries are almost universally malicious. They were either caught by a sandbox executing a live malware sample or manually verified. There is no "suspicious" category—only "malicious."
Get monthly behaviour change content and insights
Check out our Monash University accredited courses, along with our short and bespoke training programs.


We offer a broad range of research services to help governments, industries and NGOs find behavioural solutions.

We believe in building capacity and sharing knowledge through multiple channels to our partners, collaborators and the wider community.