URLhaus
URLhaus has the goal of sharing malicious URLs that are being used for malware distribution.
Data Enrichment & Threat Intelligence · URLhaus
Details
| ID | URLhaus |
|---|---|
| Provider | Open Source |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.0.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | Agentix XSIAM |
README
URLhaus leverages abuse.ch and shares malicious URLs that are being used for malware distribution.
This integration was integrated and tested with version v1 of URLhaus.
Configure URLhaus in Cortex
| Parameter | Description | Required |
|---|---|---|
| Server URL (e.g. https://192.168.0.1) | False | |
| Auth Key | Auth Key for authentication with abuse.ch | True |
| Source Reliability | Reliability of the source providing the intelligence data. | True |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Create relationships | False | |
| Maximum number of relationships to fetch per indicator | Maximal value is 1000. | False |
| Blacklists appearances threshold | False | |
| Compromised (is malicious) | False | |
| Number of retries | Determines how many times a command should be retried before raising an error. | False |
Create a required Auth Key for abuse.ch
Note: If you already have a profile, you can skip steps 1 and 2.
-
Sign up for an abuse.ch account. You can do this easily by using an existing account that you may already have on X, LinkedIn, Google or Github. Just log in with the authentication provider of your choice here: https://auth.abuse.ch/
-
Once you are authenticated on abuse.ch, ensure that you connect at least one additional authentication provider. This will ensure that you have access to abuse.ch platforms, even if one of the authentication providers you use shuts down (yes, it happened with Twitter!)
-
Ensure that you hit the “Save profile” button. In the “Optional” section, you can now generate an “Auth-Key”. This is your personal Auth-Key that you can now use in the integration.
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
url
Retrieves URL information from URLhaus.
Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.
Base Command
url
Input
| Argument Name | Description | Required |
|---|---|---|
| url | A comma-separated list of URLs to query. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| URL.Data | string | The URL. |
| URL.Malicious.Vendor | string | Vendor that reported the URL as malicious. |
| URL.Malicious.Description | string | Description of the malicious URL. |
| URL.Tags | string | A list of tags associated with the queried malware URL. |
| URL.Relationships.EntityA | String | The source of the relationship. |
| URL.Relationships.EntityB | String | The destination of the relationship. |
| URL.Relationships.Relationship | String | The name of the relationship. |
| URL.Relationships.EntityAType | String | The type of the source of the relationship. |
| URL.Relationships.EntityBType | String | The type of the destination of the relationship. |
| URLhaus.URL.ID | String | Unique identifier of the URLhaus database entry. |
| URLhaus.URL.Status | String | The current status of the URL. |
| URLhaus.URL.Host | String | The extracted host of the malware URL (IP address or domain name/FQDN). |
| URLhaus.URL.DateAdded | date | Date the URL was added to URLhaus. |
| URLhaus.URL.Threat | String | The threat corresponding to this malware URL. |
| URLhaus.URL.Blacklist.Name | String | Name of the block list. |
| URLhaus.URL.Tags | String | A list of tags associated with the queried malware URL. |
| URLhaus.URL.Payload.Name | String | Payload file name. |
| URLhaus.URL.Payload.Type | String | Payload file type. |
| URLhaus.URL.Payload.MD5 | String | MD5 hash of the HTTP response body (payload). |
| URLhaus.URL.Payload.VT.Result | Number | VirusTotal results for the payload. |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Reliability | String | Reliability of the source providing the intelligence data. |
| URLhaus.URL.Blacklist.Status | String | Status of the URL in the block list. |
| URLhaus.URL.Payload.VT.Link | String | Link to the VirusTotal report. |
Command example
!url using-brand=URLhaus url=http://example.com/anklet/WQG1/?i=1
Context Example
{
"DBotScore": {
"Indicator": "http://example.com/anklet/WQG1/?i=1",
"Reliability": "C - Fairly reliable",
"Score": 2,
"Type": "url",
"Vendor": "URLhaus"
},
"URL": {
"Data": "http://example.com/anklet/WQG1/?i=1",
"Relationships": [
{
"EntityA": "http://example.com/anklet/WQG1/?i=1",
"EntityAType": "URL",
"EntityB": "example.com",
"EntityBType": "Domain",
"Relationship": "hosted-on"
}
],
"Tags": [
"doc",
"emotet",
"epoch5",
"heodo",
"malware_download"
]
},
"URLhaus": {
"URL": {
"Blacklist": [
{
"Name": "spamhaus_dbl",
"Status": "not listed"
},
{
"Name": "surbl",
"Status": "not listed"
}
],
"DateAdded": "2022-01-20T14:11:09",
"Host": "example.com",
"ID": "1992762",
"Payload": [
{
"MD5": "716c3aa1e0da98b6e99cadd60363ae7e",
"Name": "BC-77388.xlsm",
"SHA256": "64c6ba33444e5db3cc9c99613d04fd163ec1971ee5eb90041a17068e37578fc0",
"Type": "xls",
"VT": null
}
],
"Status": "offline",
"Tags": [
"doc",
"emotet",
"epoch5",
"heodo",
"malware_download"
],
"Threat": "malware_download"
}
}
}
Human Readable Output
URLhaus reputation for http://example.com/anklet/WQG1/?i=1
Date added Description Status Threat URLhaus ID URLhaus link 2022-01-20T14:11:09 The URL is inactive (offline) and serving no payload offline malware_download 1992762 https://urlhaus.abuse.ch/url/1992762/
domain
Retrieves domain information from URLhaus.
Notice: Submitting indicators using this command might make the indicator data publicly available. See the vendor’s documentation for more details.
Base Command
domain
Input
| Argument Name | Description | Required |
|---|---|---|
| domain | A comma-separated list of domains to query. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| Domain.Name | String | The domain name, for example, google.com. |
| Domain.Tags | string | A list of tags associated with the queried malware Domain. |
| Domain.Relationships.EntityA | String | The source of the relationship. |
| Domain.Relationships.EntityB | String | The destination of the relationship. |
| Domain.Relationships.Relationship | String | The name of the relationship. |
| Domain.Relationships.EntityAType | String | The type of the source of the relationship. |
| Domain.Relationships.EntityBType | String | The type of the destination of the relationship. |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Reliability | String | Reliability of the source providing the intelligence data. |
| URLhaus.Domain.FirstSeen | Date | Date that the IP was seen for the first time (UTC). |
| URLhaus.Domain.Blacklist.Name | String | The status of the domain in different block lists. |
| URLhaus.Domain.URL | String | URLs observed on this domain. |
| Domain.Malicious.Vendor | String | Vendor that reported the domain as malicious. |
| Domain.Malicious.Description | String | Description of the malicious domain. |
| URLhaus.Domain.Blacklist.Status | String | Status of the URL in the block list. |
Command example
!domain using-brand=URLhaus domain=example.com
Context Example
{
"DBotScore": {
"Indicator": "example.com",
"Reliability": "C - Fairly reliable",
"Score": 1,
"Type": "domain",
"Vendor": "URLhaus"
},
"Domain": {
"Name": "example.com",
"Relationships": [
{
"EntityA": "example.com",
"EntityAType": "Domain",
"EntityB": "http://example.com:443/wp-content/plugins/wp-roilbask/includes/",
"EntityBType": "URL",
"Relationship": "hosts"
}
],
"Tags": [
"abused_legit_malware"
]
},
"URLhaus": {
"Domain": {
"Blacklist": {
"spamhaus_dbl": "abused_legit_malware",
"surbl": "not listed"
},
"FirstSeen": "2022-01-27T12:51:03",
"URL": [
{
"date_added": "2022-01-28 04:41:03 UTC",
"id": "2010874",
"larted": "false",
"reporter": "Cryptolaemus1",
"tags": [
"IcedID"
],
"takedown_time_seconds": null,
"threat": "malware_download",
"url": "http://example.com:443/wp-content/plugins/wp-roilbask/includes/",
"url_status": "offline",
"urlhaus_reference": "https://urlhaus.abuse.ch/url/2010874/"
}
]
}
}
}
Human Readable Output
URLhaus reputation for example.com
Description First seen URLhaus link There is no information about Domain in the blacklist 2022-01-27T12:51:03 https://urlhaus.abuse.ch/host/example.com/
file
Retrieves file information from URLhaus.
Base Command
file
Input
| Argument Name | Description | Required |
|---|---|---|
| file | A comma-separated list of MD5 or SHA256 hashes of the file to query. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| File.Size | Number | File size (in bytes). |
| File.MD5 | String | MD5 hash of the file. |
| File.SHA256 | String | SHA256 hash of the file. |
| File.SSDeep | String | SSDeep of the file. |
| File.Type | String | Type of the file. |
| File.Relationships.EntityA | String | The source of the relationship. |
| File.Relationships.EntityB | String | The destination of the relationship. |
| File.Relationships.Relationship | String | The name of the relationship. |
| File.Relationships.EntityAType | String | The type of the source of the relationship. |
| File.Relationships.EntityBType | String | The type of the destination of the relationship. |
| URLhaus.File.MD5 | String | MD5 hash of the file. |
| URLhaus.File.SHA256 | String | SHA256 hash of the file. |
| URLhaus.File.Type | String | File type guessed by URLhaus, for example: .exe, .doc. |
| URLhaus.File.Size | Number | File size (in bytes). |
| URLhaus.File.Signature | String | Malware family. |
| URLhaus.File.FirstSeen | Date | Date and time (UTC) that URLhaus first saw this file (payload). |
| URLhaus.File.LastSeen | Date | Date and time (UTC) that URLhaus last saw this file (payload). |
| URLhaus.File.DownloadLink | String | Location (URL) where you can download a copy of this file. |
| URLhaus.File.VirusTotal.Percent | Number | AV detection (percentage), for example: 24.14. |
| URLhaus.File.VirusTotal.Link | String | Link to the VirusTotal report. |
| URLhaus.File.URL | Unknown | A list of malware URLs associated with this payload (max. 100). |
| DBotScore.Indicator | String | The indicator that was tested. |
| DBotScore.Type | String | The indicator type. |
| DBotScore.Vendor | String | The vendor used to calculate the score. |
| DBotScore.Score | Number | The actual score. |
| DBotScore.Reliability | String | Reliability of the source providing the intelligence data. |
Command example
!file using-brand=URLhaus file=7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89
Context Example
{
"DBotScore": {
"Indicator": "7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89",
"Reliability": "C - Fairly reliable",
"Score": 3,
"Type": "file",
"Vendor": "URLhaus"
},
"File": {
"Malicious": {
"Description": "This file is malicious",
"Vendor": "URLhaus"
},
"Relationships": [
{
"EntityA": "7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89",
"EntityAType": "File",
"EntityB": "BazaLoader",
"EntityBType": "Malware",
"Relationship": "indicator-of"
}
],
"SHA256": "7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89",
"SSDeep": "24576:la1QHwgJMrQqj/wAc6QORNx2nAjwkaMm0GV9igWwlnwXQBwfalj21X4GtZ+FdnZ8:vH5qloBMd8A",
"Type": "dll"
},
"URLhaus": {
"File": {
"DownloadLink": "https://urlhaus-api.abuse.ch/v1/download/7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89/",
"FirstSeen": "2022-01-18T11:18:31",
"LastSeen": "2022-01-28T09:36:21",
"MD5": "2ff9cce7a08215ded0945de5965d2a0a",
"SHA256": "7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89",
"Signature": "BazaLoader",
"Size": 1816064,
"Type": "dll",
"URL": [
{
"filename": "DH-1643319814.xll",
"firstseen": "2022-01-27",
"lastseen": null,
"url": "http://www.example.com/wp-content/plugins/wp-roilbask/includes/",
"url_id": "2009726",
"url_status": "online",
"urlhaus_reference": "https://urlhaus.abuse.ch/url/2009726/"
}
]
}
}
}
Human Readable Output
URLhaus reputation for SHA256 : 7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89
First seen Last seen MD5 SHA256 Signature URLhaus link 2022-01-18T11:18:31 2022-01-28T09:36:21 2ff9cce7a08215ded0945de5965d2a0a 7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89 BazaLoader https://urlhaus-api.abuse.ch/v1/download/7855068e0cfb093ab9be9ec172676e3c119e16511f3d631d715a4e77ddad9d89/
urlhaus-download-sample
Downloads a malware sample from URLhaus.
Base Command
urlhaus-download-sample
Input
| Argument Name | Description | Required |
|---|---|---|
| file | SHA256 hash of the file to download. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| File.Size | number | File size. |
| File.SHA1 | string | SHA1 hash of the file. |
| File.SHA256 | string | SHA256 hash of the file. |
| File.Name | string | File name. |
| File.SSDeep | string | SSDeep hash of the file. |
| File.EntryID | string | File entry ID. |
| File.Info | string | File information. |
| File.Type | string | File type. |
| File.MD5 | string | MD5 hash of the file. |
| File.Extension | string | File extension. |
Command example
!urlhaus-download-sample file=254ca6a7a7ef7f17d9884c4a86f88b5d5fd8fe5341c0996eaaf1d4bcb3b2337b
Human Readable Output
{ "HumanReadable": "No results for SHA256: 254ca6a7a7ef7f17d9884c4a86f88b5d5fd8fe5341c0996eaaf1d4bcb3b2337b", "HumanReadableFormat": "markdown", "Type": 1 }
Configuration parameters
url— Server URL (e.g. https://192.168.0.1)credentials—integrationReliability— Source Reliability (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settingscreate_relationships— Create relationshipsmax_num_of_relationships— Maximum number of relationships to fetch per indicatorthreshold— Blacklists appearances thresholdcompromised_is_malicious— Compromised (is malicious)retry— Number of retriesshould_error— Return Error
Commands (4)
-
domainRetrieves domain information from URLhaus.
-
fileRetrieves file information from URLhaus.
-
urlRetrieves URL information from URLhaus.
-
urlhaus-download-sampleDownloads a malware sample from URLhaus.
category: Data Enrichment & Threat Intelligence provider: Open Source commonfields: id: URLhaus version: -1 sectionorder: - Connect configuration: - defaultvalue: https://urlhaus-api.abuse.ch/v1/ display: Server URL (e.g. https://192.168.0.1) name: url type: 0 required: false section: Connect - displaypassword: Auth Key hiddenusername: true name: credentials type: 9 section: Connect required: false additionalinfo: Starting June 30th 2025 this parameter is mandatory. - additionalinfo: Reliability of the source providing the intelligence data. defaultvalue: C - Fairly reliable display: Source Reliability name: integrationReliability options: - A+ - 3rd party enrichment - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Connect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - defaultvalue: 'true' display: Create relationships name: create_relationships type: 8 required: false section: Connect - additionalinfo: Maximal value is 1000. defaultvalue: '10' display: Maximum number of relationships to fetch per indicator name: max_num_of_relationships type: 0 required: false section: Connect - defaultvalue: '1' hidden: true display: Blacklists appearances threshold name: threshold type: 0 required: false section: Connect - display: Compromised (is malicious) hidden: true name: compromised_is_malicious type: 8 required: false section: Connect - additionalinfo: Determines how many times a command should be retried before raising an error. defaultvalue: '3' display: Number of retries name: retry type: 0 required: false section: Connect - name: should_error additionalinfo: Does the file command should error when using unsupported hash. display: Return Error type: 8 required: false defaultvalue: 'true' section: Connect description: URLhaus has the goal of sharing malicious URLs that are being used for malware distribution. display: URLhaus name: URLhaus script: commands: - arguments: - default: true description: A comma-separated list of URLs to query. isArray: true name: url required: true description: Retrieves URL information from URLhaus. name: url outputs: - contextPath: URL.Data description: The URL. type: string - contextPath: URL.Malicious.Vendor description: Vendor that reported the URL as malicious. type: string - contextPath: URL.Malicious.Description description: Description of the malicious URL. type: string - contextPath: URL.Tags description: A list of tags associated with the queried malware URL. type: string - contextPath: URL.Relationships.EntityA description: The source of the relationship. type: String - contextPath: URL.Relationships.EntityB description: The destination of the relationship. type: String - contextPath: URL.Relationships.Relationship description: The name of the relationship. type: String - contextPath: URL.Relationships.EntityAType description: The type of the source of the relationship. type: String - contextPath: URL.Relationships.EntityBType description: The type of the destination of the relationship. type: String - contextPath: URLhaus.URL.ID description: Unique identifier of the URLhaus database entry. type: String - contextPath: URLhaus.URL.Status description: The current status of the URL. type: String - contextPath: URLhaus.URL.Host description: The extracted host of the malware URL (IP address or domain name/FQDN). type: String - contextPath: URLhaus.URL.DateAdded description: Date the URL was added to URLhaus. type: date - contextPath: URLhaus.URL.Threat description: The threat corresponding to this malware URL. type: String - contextPath: URLhaus.URL.Blacklist.Name description: Name of the block list. type: String - contextPath: URLhaus.URL.Tags description: A list of tags associated with the queried malware URL. type: String - contextPath: URLhaus.URL.Payload.Name description: Payload file name. type: String - contextPath: URLhaus.URL.Payload.Type description: Payload file type. type: String - contextPath: URLhaus.URL.Payload.MD5 description: MD5 hash of the HTTP response body (payload). type: String - contextPath: URLhaus.URL.Payload.VT.Result description: VirusTotal results for the payload. type: Number - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: URLhaus.URL.Blacklist.Status description: Status of the URL in the block list. type: String - contextPath: URLhaus.URL.Payload.VT.Link description: Link to the VirusTotal report. type: String - arguments: - default: true description: A comma-separated list of domains to query. isArray: true name: domain required: true description: Retrieves domain information from URLhaus. name: domain outputs: - contextPath: Domain.Name description: The domain name, for example, google.com. type: String - contextPath: Domain.Tags description: A list of tags associated with the queried malware domain. type: string - contextPath: Domain.Relationships.EntityA description: The source of the relationship. type: String - contextPath: Domain.Relationships.EntityB description: The destination of the relationship. type: String - contextPath: Domain.Relationships.Relationship description: The name of the relationship. type: String - contextPath: Domain.Relationships.EntityAType description: The type of the source of the relationship. type: String - contextPath: Domain.Relationships.EntityBType description: The type of the destination of the relationship. type: String - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - contextPath: URLhaus.Domain.FirstSeen description: Date that the IP address was seen for the first time (UTC). type: Date - contextPath: URLhaus.Domain.Blacklist.Name description: The status of the domain in different block lists. type: String - contextPath: URLhaus.Domain.URL description: URLs observed on this domain. type: String - contextPath: Domain.Malicious.Vendor description: Vendor that reported the domain as malicious. type: String - contextPath: Domain.Malicious.Description description: Description of the malicious domain. type: String - contextPath: URLhaus.Domain.Blacklist.Status description: Status of the domain in the block list. type: String - arguments: - default: true description: A comma-separated list of MD5 or SHA256 hashes of the file to query. isArray: true name: file required: true description: Retrieves file information from URLhaus. name: file outputs: - contextPath: File.Size description: File size (in bytes). type: Number - contextPath: File.MD5 description: MD5 hash of the file. type: String - contextPath: File.SHA256 description: SHA256 hash of the file. type: String - contextPath: File.SSDeep description: SSDeep of the file. type: String - contextPath: File.Type description: Type of the file. type: String - contextPath: File.Relationships.EntityA description: The source of the relationship. type: String - contextPath: File.Relationships.EntityB description: The destination of the relationship. type: String - contextPath: File.Relationships.Relationship description: The name of the relationship. type: String - contextPath: File.Relationships.EntityAType description: The type of the source of the relationship. type: String - contextPath: File.Relationships.EntityBType description: The type of the destination of the relationship. type: String - contextPath: URLhaus.File.MD5 description: MD5 hash of the file. type: String - contextPath: URLhaus.File.SHA256 description: SHA256 hash of the file. type: String - contextPath: URLhaus.File.Type description: 'File type guessed by URLhaus, for example: .exe, .doc.' type: String - contextPath: URLhaus.File.Size description: File size (in bytes). type: Number - contextPath: URLhaus.File.Signature description: Malware family. type: String - contextPath: URLhaus.File.FirstSeen description: Date and time (UTC) that URLhaus first saw this file (payload). type: Date - contextPath: URLhaus.File.LastSeen description: Date and time (UTC) that URLhaus last saw this file (payload). type: Date - contextPath: URLhaus.File.DownloadLink description: Location (URL) where you can download a copy of this file. type: String - contextPath: URLhaus.File.VirusTotal.Percent description: 'AV detection (percentage), for example: 24.14.' type: Number - contextPath: URLhaus.File.VirusTotal.Link description: Link to the VirusTotal report. type: String - contextPath: URLhaus.File.URL description: A list of malware URLs associated with this payload (max. 100). type: Unknown - contextPath: DBotScore.Indicator description: The indicator that was tested. type: String - contextPath: DBotScore.Type description: The indicator type. type: String - contextPath: DBotScore.Vendor description: The vendor used to calculate the score. type: String - contextPath: DBotScore.Score description: The actual score. type: Number - contextPath: DBotScore.Reliability description: Reliability of the source providing the intelligence data. type: String - arguments: - default: true description: SHA256 hash of the file to download. name: file required: true description: Downloads a malware sample from URLhaus. execution: true name: urlhaus-download-sample outputs: - contextPath: File.Size description: File size. type: number - contextPath: File.SHA1 description: SHA1 hash of the file. type: string - contextPath: File.SHA256 description: SHA256 hash of the file. type: string - contextPath: File.Name description: File name. type: string - contextPath: File.SSDeep description: SSDeep hash of the file. type: string - contextPath: File.EntryID description: File entry ID. type: string - contextPath: File.Info description: File information. type: string - contextPath: File.Type description: File type. type: string - contextPath: File.MD5 description: MD5 hash of the file. type: string - contextPath: File.Extension description: File extension. type: string dockerimage: demisto/python3:3.12.13.10116658 runonce: false script: '-' subtype: python3 type: python tests: - Test_URLhaus fromversion: 5.0.0