malware-intel
URLhaus (abuse.ch)
abuse.ch's database of malware-distribution URLs, holding millions of malicious links searchable by URL, host or payload hash. Lookups run through a simple API using the same free abuse.ch Auth-Key as their other services. Check it when you want to know whether a URL found in an archived page or old dataset was known to push malware.
Son utilité et son fonctionnement
URLhaus focuses specifically on URLs that were actively distributing malware payloads, giving it a different angle from hash repositories: you can trace a suspicious link found in archived content back to known campaigns, or look up a payload hash to find which distribution URLs were serving it. It is run by abuse.ch in partnership with Spamhaus. Queries go through its API using the same free abuse.ch Auth-Key that covers MalwareBazaar and ThreatFox.
Ce qu’elle contient
URLhaus tracks roughly 3.8 million malicious URLs collected since the project launched in 2018. Each entry records the URL, its current status, associated threat tags and any payload file hashes, giving a longitudinal view of how distribution infrastructure has changed over time.
Accès API
POST https://urlhaus-api.abuse.ch/v1/ (url=/host=/payload=); header Auth-Key
Une clé API est requise (généralement gratuite) ; consultez les points d’accès ci-dessus pour savoir où l’obtenir.
Accès
Programmatic API access (a key may be required, see the API tag).