Takedown-Proof Malware Still Needs a Landlord. We Mapped 36 of Them This Morning — and Six Are Serving the Exact Same Payload Set.
- Patrick Duggan
- 2 hours ago
- 5 min read
The whole pitch of hiding malware on IPFS is that there is no landlord to serve papers to. You address a file by its content hash, not its location, so there is no domain to seize and no server to name in a takedown notice. The hash is the same whether the bytes live in Frankfurt or Singapore, and that is supposed to be the end of the conversation.
It is not the end of the conversation, because content addressing does not levitate. Somebody's actual computer is holding those bytes and answering the network when it asks who has them. IPFS is not anonymous — it is just indirect. We have been saying that since early July, when we built a collector that takes a "un-seizable" content hash and resolves it, through the network's own routing, to the IP address currently serving it. This morning that collector did something worth showing you, so here is the honest picture of who is actually renting space to the takedown-proof crowd.
What we ran, and what is ours versus what is not
Let us be precise about provenance before anyone accuses us of taking credit for other people's work. The list of malicious content hashes we chase does not come from us. Those CIDs come from phishing feeds like OpenPhish, from malware feeds like SSLBL, and from our own OTX submissions — a mix of phishing kits and malware payloads that other researchers and our own sensors flagged as bad. That determination is not the novel part.
The novel part is the resolution. For each of those "un-seizable" hashes, our collector asks IPFS's delegated-routing layer which nodes are currently advertising that they hold it, takes the ones answering as direct providers rather than relays, and enriches each to a real IP, ASN, and country. The output is the thing the takedown-proof story insists cannot exist: a list of physical machines, each one blockable at the network edge, each one currently serving content that was supposed to have no address. That mapping is DugganUSA's, and it is in our feed at confidence 95 right now, which means the edge-shield is already dropping traffic to these hosts for anyone pulling our blocklist. A cash-poor defender does not need to solve the philosophy of content addressing. They need the IPs, and the IPs are free.
The morning's map
This morning the board promoted 36 hosts. Most are serving a single malicious hash — background noise, one bad file pinned on one box. But the distribution has a shape, and the shape is the story.
Cluster by hosting provider and the "distributed" network turns out to be renting from a very short list of the same commodity shops everyone else uses. Hetzner is serving seven of this morning's malware hosts. DigitalOcean and Scaleway are four apiece. Contabo three. After that a tail of OVH, Akamai-Linode, netcup, noris, a Czech provider, a Canadian worker co-operative, and — the one that stands out from the European VPS crowd — a Russian outfit called Etersoft. This is the same lesson as our old "ten hosting providers account for sixty percent of the malicious traffic we see" finding, arriving from a completely different direction. Malware that has gone to great lengths to be locationless still ends up sitting on Hetzner, because Hetzner is cheap and takes crypto and does not ask hard questions at signup.
Six landlords, one identical box
Here is the detail that made me stop scrolling. Six of this morning's hosts are each serving not one malicious hash but the same six. The same payload set — a bundle of phishing and malware content — is pinned redundantly across a DigitalOcean box, a Contabo box, an OVH box, a netcup box, and the Russian Etersoft host, among others. Six landlords, six different countries and companies, holding six identical illicit boxes.
That is not an accident of the network and it is not six unrelated criminals who happened to pick the same files. That is one operator deliberately paying for redundant hosting across multiple providers so that the content survives any single one of them pulling the plug. It is the IPFS-native version of bulletproof hosting: you do not need a bulletproof provider if you spread the same payload thin across six ordinary ones, because a takedown at any single landlord changes nothing — the other five keep answering, and the content hash never moved. It is a resilience strategy, and it is a fingerprint. A payload pinned identically across six providers is a payload someone is protecting on purpose.
And these are not drive-by pins. The DigitalOcean host in that group has been serving its set since July 6 — the day our collector first came online. Sixteen days of the same machine answering for the same "un-takedownable" content. That is not a hit and run. That is a tenancy.
Why this is now a standing part of what we watch
We are going to keep this board running and report it when the shape changes, the same way we track bulletproof ASNs by abuse density and dead-drop addresses on-chain. The move to IPFS for payload delivery is not slowing down — the AsyncAPI supply-chain attack last week pulled its second-stage RAT from IPFS, and it will not be the last to do it. Every time a campaign reaches for a content hash to be un-seizable, it hands us the same opening: the hash leads to a provider, the provider leads to an IP, and the IP goes in the feed. The attacker's resilience trick — spreading the payload across many hosts — just means many IPs to block instead of one, all of them ours to map.
We hold this at 95 percent, as always. The malicious-content determinations belong to the feeds and researchers who made them; the count is a single morning's snapshot and tomorrow's will differ; and IPFS routing is noisy enough that a provider can answer for a hash briefly without being the operator's chosen home. What we are confident about is the direction: takedown-proof is a claim about content, not about hosting, and hosting is where you catch them. The six identical boxes on six different landlords are not a network being clever. They are an operator leaving the same fingerprint in six places at once, and we wrote all six down.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.




Comments