The sample text
This 4-line snippet is fed verbatim into the extractor to produce every result on this page. It deliberately includes a defanged indicator so you can see refang detection at work.
Campaign infrastructure: primary C2 malicious[.]top, staging at cdn-update[.]xyz, and phishing lure login-secure(dot)net.
Fast-flux rotation across evil-domain.com, tracker.example.org and data-exfil[.]io.
Benign check-in traffic to github.com and microsoft.com is expected and can be ignored.
Newly registered: bad-actor{.}ru observed resolving after the refang. What was extracted
The extractor found 9 unique indicators across 9 occurrences, of which 9 were domains. 5 indicator swere only found after refanging — proof that defanged inputs are caught.
Detected types
Every indicator type present in the sample, with domains highlighted. In the live tool these chips filter the table; here they show the mix the engine pulled out.
Extracted indicators
Deduped, counted, and honestly flagged. Rows marked was defanged appeared neutralized in the source and were recovered by the refang stage; private, benign and heuristic badges are kept, never silently dropped.
| type | value | count | line | flags | copy |
|---|---|---|---|---|---|
| Domain | cdn-update.xyz | 1 | 1 | was defanged | |
| Domain | login-secure.net | 1 | 1 | was defanged | |
| Domain | malicious.top | 1 | 1 | was defanged | |
| Domain | data-exfil.io | 1 | 2 | was defanged | |
| Domain | evil-domain.com | 1 | 2 | ||
| Domain | tracker.example.org | 1 | 2 | ||
| Domain | github.com | 1 | 3 | benign | |
| Domain | microsoft.com | 1 | 3 | benign | |
| Domain | bad-actor.ru | 1 | 4 | was defanged |
What was detected, in context
The refanged sample with every detected indicator underlined in its type color — the same preview the live tool paints as you type.
FAQ
- Does it refang domains like malicious[.]top or evil(dot)com?
- Yes. Bracketed, parenthesized, braced and word-form dots ([.], (.), {.}, [dot], (dot)) are all refanged before detection, so a domain written to be un-clickable is still recovered as a real value and marked “was defanged”.
- How does it avoid flagging legitimate domains as threats?
- Domains on a curated allowlist (major platforms and CDNs) are kept but labelled “benign”, so you can visually skip them or hide them. Nothing is dropped without a visible reason.
- Does it separate domains from full URLs?
- Yes. A bare host like malicious.top is classified as a domain, while http://malicious.top/gate.php is classified as a URL — each gets its own type and filter chip, so you can copy just the domains or just the URLs.
Extract other indicator types
See the full IOC types & defang-styles reference, or open the extractor and paste your own text.
Try it on your own text
Paste a report, advisory, or log, review the deduped indicators, filter to Domain, and copy them with one click. Free, no account, nothing uploaded — extraction runs entirely in your browser.
Open this sample in the IOC Extractor →