Overview
abuse.ch Drone specifically tracks known botnet command-and-control (C&C) node IPs. These IPs have been confirmed to participate in botnet control infrastructure. Being listed means your server has very likely been compromised and is being used as part of a botnet.
How It Works
The abuse.ch research team identifies botnet C&C communication patterns through malware sample reverse engineering and network traffic monitoring, extracting C&C server IP addresses from the analysis.
How to Get Delisted
Priority one is thoroughly cleaning malware from your server and severing the botnet connection. Once done, submit a removal request through the abuse.ch website.