URLhaus

URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries.

With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware and botnet-related cyber threats.

URLhaus database »

URLhaus data

Browse malware URLs

Gain valuable insights and find the latest malicious URLs being used for malware distribution.

Access database »

Share malware URLs

Help others protect their network from malware by sharing malicious URLs with the community.

Report URLs »

URLhaus API

Integrate intel from URLhaus into your SIEM or threat intel platform using the API.

Access API »

Spamhaus datasets enhanced by URLhaus

Access Spamhaus’ datasets, enriched with malicious URLs from URLhaus.

Data for threat hunting

Context-rich metadata relating to IP, domain and malware signals.

Access dataset »

Perimeter protection

Border Gateway Protocol feeds to stop compromised devices communicating with active botnet C2 servers.

Access dataset »

Network protection

A range of response policy zones (RPZs) protecting against malicious threats at DNS level.

Access dataset »