Archivarix

malware-intel

URLhaus (abuse.ch)

abuse.ch's database of malware-distribution URLs, holding millions of malicious links searchable by URL, host or payload hash. Lookups run through a simple API using the same free abuse.ch Auth-Key as their other services. Check it when you want to know whether a URL found in an archived page or old dataset was known to push malware.

API key required

Por qué es útil y cómo funciona

URLhaus focuses specifically on URLs that were actively distributing malware payloads, giving it a different angle from hash repositories: you can trace a suspicious link found in archived content back to known campaigns, or look up a payload hash to find which distribution URLs were serving it. It is run by abuse.ch in partnership with Spamhaus. Queries go through its API using the same free abuse.ch Auth-Key that covers MalwareBazaar and ThreatFox.

Qué contiene

URLhaus tracks roughly 3.8 million malicious URLs collected since the project launched in 2018. Each entry records the URL, its current status, associated threat tags and any payload file hashes, giving a longitudinal view of how distribution infrastructure has changed over time.

Acceso por API

POST https://urlhaus-api.abuse.ch/v1/ (url=/host=/payload=); header Auth-Key

Se requiere una clave de API (normalmente gratuita); consulta los endpoints anteriores para saber dónde obtenerla.

Acceso

Programmatic API access (a key may be required, see the API tag).

Página principal

https://urlhaus.abuse.ch/