Archivarix

malware-intel

URLhaus (abuse.ch)

abuse.ch's database of malware-distribution URLs, holding millions of malicious links searchable by URL, host or payload hash. Lookups run through a simple API using the same free abuse.ch Auth-Key as their other services. Check it when you want to know whether a URL found in an archived page or old dataset was known to push malware.

API key required

Son utilité et son fonctionnement

URLhaus focuses specifically on URLs that were actively distributing malware payloads, giving it a different angle from hash repositories: you can trace a suspicious link found in archived content back to known campaigns, or look up a payload hash to find which distribution URLs were serving it. It is run by abuse.ch in partnership with Spamhaus. Queries go through its API using the same free abuse.ch Auth-Key that covers MalwareBazaar and ThreatFox.

Ce qu’elle contient

URLhaus tracks roughly 3.8 million malicious URLs collected since the project launched in 2018. Each entry records the URL, its current status, associated threat tags and any payload file hashes, giving a longitudinal view of how distribution infrastructure has changed over time.

Accès API

POST https://urlhaus-api.abuse.ch/v1/ (url=/host=/payload=); header Auth-Key

Une clé API est requise (généralement gratuite) ; consultez les points d’accès ci-dessus pour savoir où l’obtenir.

Accès

Programmatic API access (a key may be required, see the API tag).

Page d’accueil

https://urlhaus.abuse.ch/