malware-intel
URLhaus (abuse.ch)
abuse.ch's database of malware-distribution URLs, holding millions of malicious links searchable by URL, host or payload hash. Lookups run through a simple API using the same free abuse.ch Auth-Key as their other services. Check it when you want to know whether a URL found in an archived page or old dataset was known to push malware.
Por qué es útil y cómo funciona
URLhaus focuses specifically on URLs that were actively distributing malware payloads, giving it a different angle from hash repositories: you can trace a suspicious link found in archived content back to known campaigns, or look up a payload hash to find which distribution URLs were serving it. It is run by abuse.ch in partnership with Spamhaus. Queries go through its API using the same free abuse.ch Auth-Key that covers MalwareBazaar and ThreatFox.
Qué contiene
URLhaus tracks roughly 3.8 million malicious URLs collected since the project launched in 2018. Each entry records the URL, its current status, associated threat tags and any payload file hashes, giving a longitudinal view of how distribution infrastructure has changed over time.
Acceso por API
POST https://urlhaus-api.abuse.ch/v1/ (url=/host=/payload=); header Auth-Key
Se requiere una clave de API (normalmente gratuita); consulta los endpoints anteriores para saber dónde obtenerla.
Acceso
Programmatic API access (a key may be required, see the API tag).