Public APIs
URLhaus favicon

URLhaus

Anti-Malware

Bulk queries and Download Malware Samples.

URLhaus's website screenshot

About URLhaus

URLhaus is a threat-intelligence API operated by abuse.ch that provides programmatic access to data on malicious URLs, file hashes, tags, and malware payloads it tracks. It supports queries for recent URL additions, recent payloads, and lookups by URL, host, payload, tag, or malware signature, and also allows downloading collected malware samples individually or in hourly/daily batches.

Each URL record returned includes status (online, offline, or unknown), associated host, date added, threat classification, blacklist status on SURBL and Spamhaus DBL, reporter handle, and tags. Payload records include file hashes (MD5, SHA256, imphash, ssdeep, tlsh), file type and size, malware family signature, first-seen timestamp, a download link, and VirusTotal detection results where available.

Access requires an Auth-Key sent via HTTP header, obtainable free through the abuse.ch Authentication Portal. Requests are made via HTTP GET, with Python3 sample scripts provided for querying and for submitting URLs to URLhaus. The service is intended for users needing automated access to malware URL and payload intelligence, such as security researchers and threat analysts.

Key features

  • Query URL, host, payload, tag, and signature information via REST API
  • Retrieve recent malware URL additions from the past 3 days (up to 1000 entries)
  • Retrieve recent malware payloads seen by URLhaus
  • Download malware samples collected from tracked malware URLs
  • Download hourly and daily malware batches
  • Cross-reference URLs against SURBL and Spamhaus DBL blacklists

Frequently asked questions

Is URLhaus free to use?

You can obtain an Auth-Key for free through the abuse.ch Authentication Portal.

How do I authenticate API requests?

You must include an Auth-Key HTTP header with every request to the URLhaus API.

What data can I query from the API?

You can query information on a specific URL, file hash, host, tag, or signature, and download malware samples URLhaus has collected.

How much data does the recent additions endpoint return?

The recent URLs and recent payloads endpoints return entries from the past 3 days, up to a maximum of 1000 entries, with an optional limit parameter.

Are results cross-checked against other threat lists?

Yes, responses include blacklist status from SURBL and Spamhaus DBL for queried URLs.

Advertise here

Featured products

  • SerpApi - Search API favicon
  • Screenshot Scout favicon
  • TalorData favicon
  • CoreClaw favicon

Show your product to thousands of developers

· 100k monthly pageviews
· 7k newsletter subscribers

Advertise your product