Checks any URL or domain against the URLhaus malware feed by abuse.ch. Free, no API key required.
Queries the URLhaus API by abuse.ch. Checks both the full URL and the root domain.
Queries the URLhaus database by abuse.ch to check whether a URL or domain has been associated with malware distribution. Checks both the exact URL and the root domain, and returns the verdict, threat classification, status, and any associated blocklist entries.
URLhaus tracks URLs actively used to distribute malware, including payloads, command-and-control infrastructure, and phishing delivery mechanisms. It is widely used by security teams, threat intelligence platforms, and email security products.
Use this during incident response triage when you have a suspicious URL from an email, log entry, or endpoint alert and need a fast first check before deeper investigation. It is also useful for validating whether a domain a vendor or contractor is connecting to has any threat history.
A clean result here does not mean a URL is safe — URLhaus covers known-bad infrastructure, not unknown threats. Treat it as one signal alongside other threat intelligence sources.