malware-intel
Maltiverse
A threat-intelligence aggregator for checking IPs, domains, URLs and file hashes against a large pooled IOC dataset. Lookups go through its JSON API, with keys available on a free tier. Use it to enrich an artifact from your research, a hash or domain pulled from an archived page, say, with what threat feeds collectively know about it.
Warum es nützlich ist & wie es funktioniert
Maltiverse aggregates threat intelligence from over 100 public and private feeds and lets you look up a file hash, IP address, domain or URL against that pooled dataset in a single query. The result tells you what the collective community knows: which threat feeds flagged the artifact, which malware families it has been linked to and how recently. It was acquired by Lumu in 2025 but continues to offer a free tier with API key access. It works well for enriching an artifact quickly when you want a broad cross-feed view rather than a deep sandbox report.
Was drinsteckt
Maltiverse pulls from over 100 threat intelligence sources and covers file hashes, IPs, domains and URLs. The aggregate IOC dataset is large, though the company does not publish a specific total figure for the indexed collection.
API-Zugang
https://api.maltiverse.com/sample/ <sha256> (Bearer JWT)
Ein API-Schlüssel ist erforderlich (meist kostenlos); siehe die Endpunkte oben, wo du einen bekommst.
Zugang
Programmatic API access (a key may be required, see the API tag).