malware-intel
Maltiverse
A threat-intelligence aggregator for checking IPs, domains, URLs and file hashes against a large pooled IOC dataset. Lookups go through its JSON API, with keys available on a free tier. Use it to enrich an artifact from your research, a hash or domain pulled from an archived page, say, with what threat feeds collectively know about it.
Чем полезен и как работает
Maltiverse aggregates threat intelligence from over 100 public and private feeds and lets you look up a file hash, IP address, domain or URL against that pooled dataset in a single query. The result tells you what the collective community knows: which threat feeds flagged the artifact, which malware families it has been linked to and how recently. It was acquired by Lumu in 2025 but continues to offer a free tier with API key access. It works well for enriching an artifact quickly when you want a broad cross-feed view rather than a deep sandbox report.
Что внутри
Maltiverse pulls from over 100 threat intelligence sources and covers file hashes, IPs, domains and URLs. The aggregate IOC dataset is large, though the company does not publish a specific total figure for the indexed collection.
Доступ по API
https://api.maltiverse.com/sample/ <sha256> (Bearer JWT)
Требуется ключ API (обычно бесплатный); где его получить — см. эндпоинты выше.
Доступ
Programmatic API access (a key may be required, see the API tag).