malware-intel
URLhaus (abuse.ch)
abuse.ch's database of malware-distribution URLs, holding millions of malicious links searchable by URL, host or payload hash. Lookups run through a simple API using the same free abuse.ch Auth-Key as their other services. Check it when you want to know whether a URL found in an archived page or old dataset was known to push malware.
Por que é útil e como funciona
URLhaus focuses specifically on URLs that were actively distributing malware payloads, giving it a different angle from hash repositories: you can trace a suspicious link found in archived content back to known campaigns, or look up a payload hash to find which distribution URLs were serving it. It is run by abuse.ch in partnership with Spamhaus. Queries go through its API using the same free abuse.ch Auth-Key that covers MalwareBazaar and ThreatFox.
O que há dentro
URLhaus tracks roughly 3.8 million malicious URLs collected since the project launched in 2018. Each entry records the URL, its current status, associated threat tags and any payload file hashes, giving a longitudinal view of how distribution infrastructure has changed over time.
Acesso via API
POST https://urlhaus-api.abuse.ch/v1/ (url=/host=/payload=); header Auth-Key
É necessária uma chave de API (geralmente gratuita); veja os endpoints acima para saber onde obtê-la.
Acesso
Programmatic API access (a key may be required, see the API tag).