Abuse URLhaus
The Abuse URLhaus connector provides automated access to a comprehensive database of URLs known to distribute malware, enabling enhanced threat intelligence and incident response.
Abuse URLhaus is a threat intelligence service that tracks and shares data on malicious URLs. The Abuse URLhaus connector for Swimlane Turbine enables users to query and retrieve detailed information about malware samples, malicious URLs, and associated threats directly within their security workflows. By integrating with Abuse URLhaus, Swimlane Turbine users can enhance their incident response and threat hunting capabilities with real-time data, streamline their security operations, and rapidly identify and mitigate cyber threats.
Prerequisites
To effectively utilize the Abuse URLhaus connector with Swimlane, ensure you have the following prerequisites:
- Host URL authentication with the following parameters:
- URL: The endpoint for the Abuse URLhaus API service.
- Auth Key: Your personal authentication key for accessing Abuse URLhaus API.
Capabilities
The abuse.ch URLhaus integration provides the following capabilities:
- Query
- URL
- Host
- IP
- MD5
- SHA256
Notes
This connector was last tested against product version: V1 API
Additional Documentation
Configurations
Abuse URLhaus Authentication
Authenticates using Host URL
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
Auth-Key | The authentication key for accessing the API. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Lookup Hash
Retrieve details for a specified MD5 or SHA256 hash from Abuse URLhaus, including associated URLs and malware samples.
Endpoint
- URL: v1/payload
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Response data |
data_body.md5_hash | string | Optional | Response data |
data_body.sha256_hash | string | Optional | Response data |
Input Example
{"data_body":{"md5_hash":"12c8aec5766ac3e6f26f2505e2f4a8f2","sha256_hash":"01fa56184fcaa42b6ee1882787a34098c79898c182814774fd81dc18a6af0b00"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
query_status | string | Status value |
md5_hash | string | Output field: md5_hash |
sha256_hash | string | Output field: sha256_hash |
file_type | string | Type of the resource |
file_size | string | Output field: file_size |
signature | string | Output field: signature |
firstseen | string | Output field: firstseen |
lastseen | string | Output field: lastseen |
url_count | string | URL endpoint for the request |
urlhaus_download | string | URL endpoint for the request |
virustotal | object | Output field: virustotal |
imphash | object | Output field: imphash |
ssdeep | object | Output field: ssdeep |
tlsh | object | Output field: tlsh |
urls | array | URL endpoint for the request |
urls.url_id | string | URL endpoint for the request |
urls.url | string | URL endpoint for the request |
urls.url_status | string | URL endpoint for the request |
urls.urlhaus_reference | string | URL endpoint for the request |
urls.filename | string | URL endpoint for the request |
urls.firstseen | string | URL endpoint for the request |
urls.lastseen | object | URL endpoint for the request |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 08 Dec 2022 18:15:26 GMT","Server":"Apache","Strict-Transport-Security":"max-age=15768000 ; includeSubDomains","Permissions-Policy":"accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), encrypted-med...","Referrer-Policy":"strict-origin-when-cross-origin","Content-Security-Policy":"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanag...","Expect-CT":"enforce, max-age=86400","Cross-Origin-Embedder-Policy...
Lookup IP, Host or Domain
Retrieve detailed threat analysis for an IP, host, or domain from Abuse URLhaus, requiring a data body input.
Endpoint
- URL: v1/host
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Response data |
data_body.host | string | Required | Response data |
Input Example
{"data_body":{"host":"185.141.25.242"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 08 Dec 2022 14:44:53 GMT","Server":"Apache","Strict-Transport-Security":"max-age=15768000 ; includeSubDomains","Permissions-Policy":"accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), encrypted-med...","Referrer-Policy":"strict-origin-when-cross-origin","Content-Security-Policy":"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanag...","Expect-CT":"enforce, max-age=86400","Cross-Origin-Embedder-Policy...
Lookup URL
Retrieve detailed information, status, and related data for a specific URL from Abuse URLhaus.
Endpoint
- URL: v1/url
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Response data |
data_body.url | string | Required | Response data |
Input Example
{"data_body":{"url":"http://sskymedia.com/VMYB-ht_JAQo-gi/INV/99401FORPO/20673114777/US/Outstanding-Invoices/"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
query_status | string | Status value |
id | string | Unique identifier |
urlhaus_reference | string | URL endpoint for the request |
url | string | URL endpoint for the request |
url_status | string | URL endpoint for the request |
host | string | Output field: host |
date_added | string | Output field: date_added |
last_online | string | Output field: last_online |
threat | string | Output field: threat |
blacklists | object | Output field: blacklists |
blacklists.spamhaus_dbl | string | Output field: blacklists.spamhaus_dbl |
blacklists.surbl | string | Output field: blacklists.surbl |
reporter | string | Output field: reporter |
larted | string | Output field: larted |
takedown_time_seconds | string | Output field: takedown_time_seconds |
tags | array | Output field: tags |
payloads | array | Output field: payloads |
payloads.firstseen | string | Output field: payloads.firstseen |
payloads.filename | string | Name of the resource |
payloads.file_type | string | Type of the resource |
payloads.response_size | string | Output field: payloads.response_size |
payloads.response_md5 | string | Output field: payloads.response_md5 |
payloads.response_sha256 | string | Output field: payloads.response_sha256 |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 08 Dec 2022 18:12:24 GMT","Server":"Apache","Strict-Transport-Security":"max-age=15768000 ; includeSubDomains","Permissions-Policy":"accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), encrypted-med...","Referrer-Policy":"strict-origin-when-cross-origin","Content-Security-Policy":"default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanag...","Expect-CT":"enforce, max-age=86400","Cross-Origin-Embedder-Policy...
Response Headers
Header | Description | Example |
|---|---|---|
Connection | HTTP response header: Connection | Keep-Alive |
Content-Length | The length of the response body in bytes | 0 |
Content-Security-Policy | HTTP response header: Content-Security-Policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com:443; img-src 'self' data: https://www.google-analytics.com:443; style-src 'self'; object-src 'none' |
Content-Type | The media type of the resource | application/json |
Cross-Origin-Embedder-Policy | HTTP response header: Cross-Origin-Embedder-Policy | require-corp; report-to="default" |
Cross-Origin-Opener-Policy | HTTP response header: Cross-Origin-Opener-Policy | same-origin; report-to="default" |
Cross-Origin-Resource-Policy | HTTP response header: Cross-Origin-Resource-Policy | same-site |
Date | The date and time at which the message was originated | Thu, 08 Dec 2022 18:15:26 GMT |
Expect-CT | HTTP response header: Expect-CT | enforce, max-age=86400 |
Keep-Alive | HTTP response header: Keep-Alive | timeout=5, max=100 |
Permissions-Policy | HTTP response header: Permissions-Policy | accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), speaker=(), usb=(), vr=() |
Referrer-Policy | HTTP response header: Referrer-Policy | strict-origin-when-cross-origin |
Server | Information about the software used by the origin server | Apache |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=15768000 ; includeSubDomains |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
X-Frame-Options | HTTP response header: X-Frame-Options | sameorigin |
X-XSS-Protection | HTTP response header: X-XSS-Protection | 1; mode=block |