URLhaus

URLhaus has the goal of sharing malicious URLs that are being used for malware distribution.

Data Enrichment & Threat Intelligence · URLhaus

Details

IDURLhaus
ProviderOpen Source
CategoryData Enrichment & Threat Intelligence
From Version5.0.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

URLhaus leverages abuse.ch and shares malicious URLs that are being used for malware distribution.
This integration was integrated and tested with version v1 of URLhaus.

Configure URLhaus in Cortex

Parameter Description Required
Server URL (e.g. https://192.168.0.1)   False
Auth Key Auth Key for authentication with abuse.ch True
Source Reliability Reliability of the source providing the intelligence data. True
Trust any certificate (not secure)   False
Use system proxy settings   False
Create relationships   False
Maximum number of relationships to fetch per indicator Maximal value is 1000. False
Blacklists appearances threshold   False
Compromised (is malicious)   False
Number of retries Determines how many times a command should be retried before raising an error. False

Create a required Auth Key for abuse.ch

Note: If you already have a profile, you can skip steps 1 and 2.

  1. Sign up for an abuse.ch account. You can do this easily by using an existing account that you may already have on X, LinkedIn, Google or Github. Just log in with the authentication provider of your choice here: https://auth.abuse.ch/

  2. Once you are authenticated on abuse.ch, ensure that you connect at least one additional authentication provider. This will ensure that you have access to abuse.ch platforms, even if one of the authentication providers you use shuts down (yes, it happened with Twitter!)

  3. Ensure that you hit the “Save profile” button. In the “Optional” section, you can now generate an “Auth-Key”. This is your personal Auth-Key that you can now use in the integration.

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

url


Retrieves URL information from URLhaus.

Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.

Base Command

url

Input

Argument Name Description Required
url A comma-separated list of URLs to query. Required

Context Output

Path Type Description
URL.Data string The URL.
URL.Malicious.Vendor string Vendor that reported the URL as malicious.
URL.Malicious.Description string Description of the malicious URL.
URL.Tags string A list of tags associated with the queried malware URL.
URL.Relationships.EntityA String The source of the relationship.
URL.Relationships.EntityB String The destination of the relationship.
URL.Relationships.Relationship String The name of the relationship.
URL.Relationships.EntityAType String The type of the source of the relationship.
URL.Relationships.EntityBType String The type of the destination of the relationship.
URLhaus.URL.ID String Unique identifier of the URLhaus database entry.
URLhaus.URL.Status String The current status of the URL.
URLhaus.URL.Host String The extracted host of the malware URL (IP address or domain name/FQDN).
URLhaus.URL.DateAdded date Date the URL was added to URLhaus.
URLhaus.URL.Threat String The threat corresponding to this malware URL.
URLhaus.URL.Blacklist.Name String Name of the block list.
URLhaus.URL.Tags String A list of tags associated with the queried malware URL.
URLhaus.URL.Payload.Name String Payload file name.
URLhaus.URL.Payload.Type String Payload file type.
URLhaus.URL.Payload.MD5 String MD5 hash of the HTTP response body (payload).
URLhaus.URL.Payload.VT.Result Number VirusTotal results for the payload.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score Number The actual score.
DBotScore.Reliability String Reliability of the source providing the intelligence data.
URLhaus.URL.Blacklist.Status String Status of the URL in the block list.
URLhaus.URL.Payload.VT.Link String Link to the VirusTotal report.

Command example

!url using-brand=URLhaus url=http://example.com/anklet/WQG1/?i=1

Context Example

{
    "DBotScore": {
        "Indicator": "http://example.com/anklet/WQG1/?i=1",
        "Reliability": "C - Fairly reliable",
        "Score": 2,
        "Type": "url",
        "Vendor": "URLhaus"
    },
    "URL": {
        "Data": "http://example.com/anklet/WQG1/?i=1",
        "Relationships": [
            {
                "EntityA": "http://example.com/anklet/WQG1/?i=1",
                "EntityAType": "URL",
                "EntityB": "example.com",
                "EntityBType": "Domain",
                "Relationship": "hosted-on"
            }
        ],
        "Tags": [
            "doc",
            "emotet",
            "epoch5",
            "heodo",
            "malware_download"
        ]
    },
    "URLhaus": {
        "URL": {
            "Blacklist": [
                {
                    "Name": "spamhaus_dbl",
                    "Status": "not listed"
                },
                {
                    "Name": "surbl",
                    "Status": "not listed"
                }
            ],
            "DateAdded": "2022-01-20T14:11:09",
            "Host": "example.com",
            "ID": "1992762",
            "Payload": [
                {
                    "MD5": "716c3aa1e0da98b6e99cadd60363ae7e",
                    "Name": "BC-77388.xlsm",
                    "SHA256": "64c6ba33444e5db3cc9c99613d04fd163ec1971ee5eb90041a17068e37578fc0",
                    "Type": "xls",
                    "VT": null
              }
            ],
            "Status": "offline",
            "Tags": [
                "doc",
                "emotet",
                "epoch5",
                "heodo",
                "malware_download"
            ],
            "Threat": "malware_download"
        }
    }
}

Human Readable Output

URLhaus reputation for http://example.com/anklet/WQG1/?i=1

Date added Description Status Threat URLhaus ID URLhaus link
2022-01-20T14:11:09 The URL is inactive (offline) and serving no payload offline malware_download 1992762 https://urlhaus.abuse.ch/url/1992762/

domain


Retrieves domain information from URLhaus.

Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.

Base Command

domain

Input

Argument Name Description Required
domain A comma-separated list of domains to query. Required

Context Output

Path Type Description
Domain.Name String The domain name, for example, google.com.
Domain.Tags string A list of tags associated with the queried malware Domain.
Domain.Relationships.EntityA String The source of the relationship.
Domain.Relationships.EntityB String The destination of the relationship.
Domain.Relationships.Relationship String The name of the relationship.
Domain.Relationships.EntityAType String The type of the source of the relationship.
Domain.Relationships.EntityBType String The type of the destination of the relationship.
DBotScore.Indicator String The indicator that was tested.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score Number The actual score.
DBotScore.Reliability String Reliability of the source providing the intelligence data.
URLhaus.Domain.FirstSeen Date Date that the IP was seen for the first time (UTC).
URLhaus.Domain.Blacklist.Name String The status of the domain in different block lists.
URLhaus.Domain.URL String URLs observed on this domain.
Domain.Malicious.Vendor String Vendor that reported the domain as malicious.
Domain.Malicious.Description String Description of the malicious domain.
URLhaus.Domain.Blacklist.Status String Status of the URL in the block list.

Command example

!domain using-brand=URLhaus domain=example.com

Context Example

{
    "DBotScore": {
        "Indicator": "example.com",
        "Reliability": "C - Fairly reliable",
        "Score": 1,
        "Type": "domain",
        "Vendor": "URLhaus"
    },
    "Domain": {
        "Name": "example.com",
        "Relationships": [
            {
                "EntityA": "example.com",
                "EntityAType": "Domain",
                "EntityB": "http://example.com:443/wp-content/plugins/wp-roilbask/includes/",
                "EntityBType": "URL",
                "Relationship": "hosts"
            }
        ],
        "Tags": [
            "abused_legit_malware"
        ]
    },
    "URLhaus": {
        "Domain": {
            "Blacklist": {
                "spamhaus_dbl": "abused_legit_malware",
                "surbl": "not listed"
            },
            "FirstSeen": "2022-01-27T12:51:03",
            "URL": [
                {
                    "date_added": "2022-01-28 04:41:03 UTC",
                    "id": "2010874",
                    "larted": "false",
                    "reporter": "Cryptolaemus1",
                    "tags": [
                        "IcedID"
                    ],
                    "takedown_time_seconds": null,
                    "threat": "malware_download",
                    "url": "http://example.com:443/wp-content/plugins/wp-roilbask/includes/",
                    "url_status": "offline",
                    "urlhaus_reference": "https://urlhaus.abuse.ch/url/2010874/"
                }
            ]
        }
    }
}

Human Readable Output

URLhaus reputation for example.com

Description First seen URLhaus link
There is no information about Domain in the blacklist 2022-01-27T12:51:03 https://urlhaus.abuse.ch/host/example.com/

file


Retrieves file information from URLhaus.

Base Command

file

Input

Argument Name Description Required
file A comma-separated list of MD5 or SHA256 hashes of the file to query. Required

Context Output

Path Type Description
File.Size Number File size (in bytes).
File.MD5 String MD5 hash of the file.
File.SHA256 String SHA256 hash of the file.
File.SSDeep String SSDeep of the file.
File.Type String Type of the file.
File.Relationships.EntityA String The source of the relationship.
File.Relationships.EntityB String The destination of the relationship.
File.Relationships.Relationship String The name of the relationship.
File.Relationships.EntityAType String The type of the source of the relationship.
File.Relationships.EntityBType String The type of the destination of the relationship.
URLhaus.File.MD5 String MD5 hash of the file.
URLhaus.File.SHA256 String SHA256 hash of the file.
URLhaus.File.Type String File type guessed by URLhaus, for example: .exe, .doc.
URLhaus.File.Size Number File size (in bytes).
URLhaus.File.Signature String Malware family.
URLhaus.File.FirstSeen Date Date and time (UTC) that URLhaus first saw this file (payload).
URLhaus.File.LastSeen Date Date and time (UTC) that URLhaus last saw this file (payload).
URLhaus.File.DownloadLink String Location (URL) where you can download a copy of this file.
URLhaus.File.VirusTotal.Percent Number AV detection (percentage), for example: 24.14.
URLhaus.File.VirusTotal.Link String Link to the VirusTotal report.
URLhaus.File.URL Unknown A list of malware URLs associated with this payload (max. 100).
DBotScore.Indicator String The indicator that was tested.
DBotScore.Type String The indicator type.
DBotScore.Vendor String The vendor used to calculate the score.
DBotScore.Score Number The actual score.
DBotScore.Reliability String Reliability of the source providing the intelligence data.

Command example

!file using-brand=URLhaus file=7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89

Context Example

{
    "DBotScore": {
        "Indicator": "7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89",
        "Reliability": "C - Fairly reliable",
        "Score": 3,
        "Type": "file",
        "Vendor": "URLhaus"
    },
    "File": {
        "Malicious": {
            "Description": "This file is malicious",
            "Vendor": "URLhaus"
        },
        "Relationships": [
            {
                "EntityA": "7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89",
                "EntityAType": "File",
                "EntityB": "BazaLoader",
                "EntityBType": "Malware",
                "Relationship": "indicator-of"
            }
        ],
        "SHA256": "7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89",
        "SSDeep": "24576:la1QHwgJMrQqj/wAc6QORNx2nAjwkaMm0GV9igWwlnwXQBwfalj21X4GtZ+FdnZ8:vH5qloBMd8A",
        "Type": "dll"
    },
    "URLhaus": {
        "File": {
            "DownloadLink": "https://urlhaus-api.abuse.ch/v1/download/7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89/",
            "FirstSeen": "2022-01-18T11:18:31",
            "LastSeen": "2022-01-28T09:36:21",
            "MD5": "2ff9cce7a08215ded0945de5965d2a0a",
            "SHA256": "7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89",
            "Signature": "BazaLoader",
            "Size": 1816064,
            "Type": "dll",
            "URL": [
                {
                    "filename": "DH-1643319814.xll",
                    "firstseen": "2022-01-27",
                    "lastseen": null,
                    "url": "http://www.example.com/wp-content/plugins/wp-roilbask/includes/",
                    "url_id": "2009726",
                    "url_status": "online",
                    "urlhaus_reference": "https://urlhaus.abuse.ch/url/2009726/"
                }
            ]
        }
    }
}

Human Readable Output

URLhaus reputation for SHA256 : 7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89

First seen Last seen MD5 SHA256 Signature URLhaus link
2022-01-18T11:18:31 2022-01-28T09:36:21 2ff9cce7a08215ded0945de5965d2a0a 7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89 BazaLoader https://urlhaus-api.abuse.ch/v1/download/7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89/

urlhaus-download-sample


Downloads a malware sample from URLhaus.

Base Command

urlhaus-download-sample

Input

Argument Name Description Required
file SHA256 hash of the file to download. Required

Context Output

Path Type Description
File.Size number File size.
File.SHA1 string SHA1 hash of the file.
File.SHA256 string SHA256 hash of the file.
File.Name string File name.
File.SSDeep string SSDeep hash of the file.
File.EntryID string File entry ID.
File.Info string File information.
File.Type string File type.
File.MD5 string MD5 hash of the file.
File.Extension string File extension.

Command example

!urlhaus-download-sample file=254ca6a7a7ef7f17d9884c4a86f88b5d5fd8fe5341c0996eaaf1d4bcb3b2337b

Human Readable Output

{
   "HumanReadable": "No results for SHA256: 254ca6a7a7ef7f17d9884c4a86f88b5d5fd8fe5341c0996eaaf1d4bcb3b2337b",
   "HumanReadableFormat": "markdown",
   "Type": 1
}

Configuration parameters

  • url — Server URL (e.g. https://192.168.0.1)
  • credentials
  • integrationReliability — Source Reliability (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • create_relationships — Create relationships
  • max_num_of_relationships — Maximum number of relationships to fetch per indicator
  • threshold — Blacklists appearances threshold
  • compromised_is_malicious — Compromised (is malicious)
  • retry — Number of retries
  • should_error — Return Error

Commands (4)

  • domain

    Retrieves domain information from URLhaus.

  • file

    Retrieves file information from URLhaus.

  • url

    Retrieves URL information from URLhaus.

  • urlhaus-download-sample

    Downloads a malware sample from URLhaus.

category: Data Enrichment & Threat Intelligence
provider: Open Source
commonfields:
  id: URLhaus
  version: -1
sectionorder:
- Connect
configuration:
- defaultvalue: https://urlhaus-api.abuse.ch/v1/
  display: Server URL (e.g. https://192.168.0.1)
  name: url
  type: 0
  required: false
  section: Connect
- displaypassword: Auth Key
  hiddenusername: true
  name: credentials
  type: 9
  section: Connect
  required: false
  additionalinfo: Starting June 30th 2025 this parameter is mandatory.
- additionalinfo: Reliability of the source providing the intelligence data.
  defaultvalue: C - Fairly reliable
  display: Source Reliability
  name: integrationReliability
  options:
  - A+ - 3rd party enrichment
  - A - Completely reliable
  - B - Usually reliable
  - C - Fairly reliable
  - D - Not usually reliable
  - E - Unreliable
  - F - Reliability cannot be judged
  required: true
  type: 15
  section: Connect
- display: Trust any certificate (not secure)
  name: insecure
  type: 8
  required: false
  section: Connect
- display: Use system proxy settings
  name: proxy
  type: 8
  required: false
  section: Connect
- defaultvalue: 'true'
  display: Create relationships
  name: create_relationships
  type: 8
  required: false
  section: Connect
- additionalinfo: Maximal value is 1000.
  defaultvalue: '10'
  display: Maximum number of relationships to fetch per indicator
  name: max_num_of_relationships
  type: 0
  required: false
  section: Connect
- defaultvalue: '1'
  hidden: true
  display: Blacklists appearances threshold
  name: threshold
  type: 0
  required: false
  section: Connect
- display: Compromised (is malicious)
  hidden: true
  name: compromised_is_malicious
  type: 8
  required: false
  section: Connect
- additionalinfo: Determines how many times a command should be retried before raising an error.
  defaultvalue: '3'
  display: Number of retries
  name: retry
  type: 0
  required: false
  section: Connect
- name: should_error
  additionalinfo: Does the file command should error when using unsupported hash.
  display: Return Error
  type: 8
  required: false
  defaultvalue: 'true'
  section: Connect
description: URLhaus has the goal of sharing malicious URLs that are being used for malware distribution.
display: URLhaus
name: URLhaus
script:
  commands:
  - arguments:
    - default: true
      description: A comma-separated list of URLs to query.
      isArray: true
      name: url
      required: true
    description: Retrieves URL information from URLhaus.
    name: url
    outputs:
    - contextPath: URL.Data
      description: The URL.
      type: string
    - contextPath: URL.Malicious.Vendor
      description: Vendor that reported the URL as malicious.
      type: string
    - contextPath: URL.Malicious.Description
      description: Description of the malicious URL.
      type: string
    - contextPath: URL.Tags
      description: A list of tags associated with the queried malware URL.
      type: string
    - contextPath: URL.Relationships.EntityA
      description: The source of the relationship.
      type: String
    - contextPath: URL.Relationships.EntityB
      description: The destination of the relationship.
      type: String
    - contextPath: URL.Relationships.Relationship
      description: The name of the relationship.
      type: String
    - contextPath: URL.Relationships.EntityAType
      description: The type of the source of the relationship.
      type: String
    - contextPath: URL.Relationships.EntityBType
      description: The type of the destination of the relationship.
      type: String
    - contextPath: URLhaus.URL.ID
      description: Unique identifier of the URLhaus database entry.
      type: String
    - contextPath: URLhaus.URL.Status
      description: The current status of the URL.
      type: String
    - contextPath: URLhaus.URL.Host
      description: The extracted host of the malware URL (IP address or domain name/FQDN).
      type: String
    - contextPath: URLhaus.URL.DateAdded
      description: Date the URL was added to URLhaus.
      type: date
    - contextPath: URLhaus.URL.Threat
      description: The threat corresponding to this malware URL.
      type: String
    - contextPath: URLhaus.URL.Blacklist.Name
      description: Name of the block list.
      type: String
    - contextPath: URLhaus.URL.Tags
      description: A list of tags associated with the queried malware URL.
      type: String
    - contextPath: URLhaus.URL.Payload.Name
      description: Payload file name.
      type: String
    - contextPath: URLhaus.URL.Payload.Type
      description: Payload file type.
      type: String
    - contextPath: URLhaus.URL.Payload.MD5
      description: MD5 hash of the HTTP response body (payload).
      type: String
    - contextPath: URLhaus.URL.Payload.VT.Result
      description: VirusTotal results for the payload.
      type: Number
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Reliability
      description: Reliability of the source providing the intelligence data.
      type: String
    - contextPath: URLhaus.URL.Blacklist.Status
      description: Status of the URL in the block list.
      type: String
    - contextPath: URLhaus.URL.Payload.VT.Link
      description: Link to the VirusTotal report.
      type: String
  - arguments:
    - default: true
      description: A comma-separated list of domains to query.
      isArray: true
      name: domain
      required: true
    description: Retrieves domain information from URLhaus.
    name: domain
    outputs:
    - contextPath: Domain.Name
      description: The domain name, for example, google.com.
      type: String
    - contextPath: Domain.Tags
      description: A list of tags associated with the queried malware domain.
      type: string
    - contextPath: Domain.Relationships.EntityA
      description: The source of the relationship.
      type: String
    - contextPath: Domain.Relationships.EntityB
      description: The destination of the relationship.
      type: String
    - contextPath: Domain.Relationships.Relationship
      description: The name of the relationship.
      type: String
    - contextPath: Domain.Relationships.EntityAType
      description: The type of the source of the relationship.
      type: String
    - contextPath: Domain.Relationships.EntityBType
      description: The type of the destination of the relationship.
      type: String
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Reliability
      description: Reliability of the source providing the intelligence data.
      type: String
    - contextPath: URLhaus.Domain.FirstSeen
      description: Date that the IP address was seen for the first time (UTC).
      type: Date
    - contextPath: URLhaus.Domain.Blacklist.Name
      description: The status of the domain in different block lists.
      type: String
    - contextPath: URLhaus.Domain.URL
      description: URLs observed on this domain.
      type: String
    - contextPath: Domain.Malicious.Vendor
      description: Vendor that reported the domain as malicious.
      type: String
    - contextPath: Domain.Malicious.Description
      description: Description of the malicious domain.
      type: String
    - contextPath: URLhaus.Domain.Blacklist.Status
      description: Status of the domain in the block list.
      type: String
  - arguments:
    - default: true
      description: A comma-separated list of MD5 or SHA256 hashes of the file to query.
      isArray: true
      name: file
      required: true
    description: Retrieves file information from URLhaus.
    name: file
    outputs:
    - contextPath: File.Size
      description: File size (in bytes).
      type: Number
    - contextPath: File.MD5
      description: MD5 hash of the file.
      type: String
    - contextPath: File.SHA256
      description: SHA256 hash of the file.
      type: String
    - contextPath: File.SSDeep
      description: SSDeep of the file.
      type: String
    - contextPath: File.Type
      description: Type of the file.
      type: String
    - contextPath: File.Relationships.EntityA
      description: The source of the relationship.
      type: String
    - contextPath: File.Relationships.EntityB
      description: The destination of the relationship.
      type: String
    - contextPath: File.Relationships.Relationship
      description: The name of the relationship.
      type: String
    - contextPath: File.Relationships.EntityAType
      description: The type of the source of the relationship.
      type: String
    - contextPath: File.Relationships.EntityBType
      description: The type of the destination of the relationship.
      type: String
    - contextPath: URLhaus.File.MD5
      description: MD5 hash of the file.
      type: String
    - contextPath: URLhaus.File.SHA256
      description: SHA256 hash of the file.
      type: String
    - contextPath: URLhaus.File.Type
      description: 'File type guessed by URLhaus, for example: .exe, .doc.'
      type: String
    - contextPath: URLhaus.File.Size
      description: File size (in bytes).
      type: Number
    - contextPath: URLhaus.File.Signature
      description: Malware family.
      type: String
    - contextPath: URLhaus.File.FirstSeen
      description: Date and time (UTC) that URLhaus first saw this file (payload).
      type: Date
    - contextPath: URLhaus.File.LastSeen
      description: Date and time (UTC) that URLhaus last saw this file (payload).
      type: Date
    - contextPath: URLhaus.File.DownloadLink
      description: Location (URL) where you can download a copy of this file.
      type: String
    - contextPath: URLhaus.File.VirusTotal.Percent
      description: 'AV detection (percentage), for example: 24.14.'
      type: Number
    - contextPath: URLhaus.File.VirusTotal.Link
      description: Link to the VirusTotal report.
      type: String
    - contextPath: URLhaus.File.URL
      description: A list of malware URLs associated with this payload (max. 100).
      type: Unknown
    - contextPath: DBotScore.Indicator
      description: The indicator that was tested.
      type: String
    - contextPath: DBotScore.Type
      description: The indicator type.
      type: String
    - contextPath: DBotScore.Vendor
      description: The vendor used to calculate the score.
      type: String
    - contextPath: DBotScore.Score
      description: The actual score.
      type: Number
    - contextPath: DBotScore.Reliability
      description: Reliability of the source providing the intelligence data.
      type: String
  - arguments:
    - default: true
      description: SHA256 hash of the file to download.
      name: file
      required: true
    description: Downloads a malware sample from URLhaus.
    execution: true
    name: urlhaus-download-sample
    outputs:
    - contextPath: File.Size
      description: File size.
      type: number
    - contextPath: File.SHA1
      description: SHA1 hash of the file.
      type: string
    - contextPath: File.SHA256
      description: SHA256 hash of the file.
      type: string
    - contextPath: File.Name
      description: File name.
      type: string
    - contextPath: File.SSDeep
      description: SSDeep hash of the file.
      type: string
    - contextPath: File.EntryID
      description: File entry ID.
      type: string
    - contextPath: File.Info
      description: File information.
      type: string
    - contextPath: File.Type
      description: File type.
      type: string
    - contextPath: File.MD5
      description: MD5 hash of the file.
      type: string
    - contextPath: File.Extension
      description: File extension.
      type: string
  dockerimage: demisto/python3:3.12.13.10116658
  runonce: false
  script: '-'
  subtype: python3
  type: python
tests:
- Test_URLhaus
fromversion: 5.0.0