Is this indicator known-bad?
An IOC from a log comes back with malware family, threat type, confidence, and seen dates.
Runs on: threatfox.ioc
Integrations · Security
Threat-intel from abuse.ch in your agents' hands — indicator checks and malware URL sweeps, with plain receipts.
3 actions · out of the box: Threat Analyst
Missions
An IOC from a log comes back with malware family, threat type, confidence, and seen dates.
Runs on: threatfox.ioc
A file hash check returns malware family, threat type, confidence, and the first time ThreatFox saw it.
Runs on: threatfox.hash
Recent URLhaus entries arrive newest first with host, threat label, status, and tags for triage.
Runs on: urlhaus.recent
ThreatFox misses are reported as unknown, not clean, while URLhaus sweeps keep watchlists moving.
Runs on: threatfox.ioc · threatfox.hash · urlhaus.recent
The catalog
threatfox.iocThreatFox IOC lookupIOC lookup: malware family, confidence, first/last seen.
threatfox.hashThreatFox hash lookupHash lookup: malware family, confidence, first seen.
urlhaus.recentURLhaus recent malware URLsRecent malware URLs feed: host, threat, status, tags.
Connect
abuse.ch runs ThreatFox and URLhaus as a free non-commercial threat-intel service with a community key. Their service, their terms; Ahel adds no markup.
FAQ
Yes — ThreatFox and URLhaus are abuse.ch's free non-commercial threat-intel service. Ahel adds no markup.
Three seeded reads: threatfox.ioc, threatfox.hash, and urlhaus.recent. URLhaus here is a feed sweep, not a one-URL lookup.
No. query_status no_result means unknown to ThreatFox, not clean.