Blacklist Monitoring now checks your hosts against URLhaus, the abuse.ch project that tracks URLs used to distribute malware. A listing means URLhaus has seen malware served from your IP address or domain. URLhaus is a premium source, available on any plan that includes premium data sources, with no separate charge.
Three New Sources
- URLhaus: IPv4 lists an IPv4 host when that IP is currently serving malware.
- URLhaus: IPv6 does the same for IPv6 hosts.
- URLhaus: Domains lists a domain host when URLhaus lists it as serving malware.
All three appear on the premium sources tab of your Monitoring Profiles, next to PhishTank. Profiles set to use all sources pick them up automatically; custom profiles need to select them.
The URLhaus host file leaves out domains in the Tranco top one million, so large shared platforms such as github.com are not flagged because someone uploaded malware there.
Clearing a Listing
Each listing links to the host's page on URLhaus, which shows the URLs behind it. The host file carries hosts that are actively serving malware or were added in the last 48 hours, so a listing clears on its own roughly 48 hours after the malware goes offline. To get removed sooner, take the malware down and contact abuse.ch through the URLhaus site.