Smart Domain Check Logo

URLhaus malware URL check

Check any URL or domain against the URLhaus malware database. See instantly whether a link is associated with malware distribution, command-and-control servers, or phishing.

What is URLhaus?

URLhaus is a community-driven project operated by abuse.ch with the goal of collecting, tracking, and sharing URLs that are being used for malware distribution. Security researchers around the world submit suspicious URLs, which are then verified and added to the database. The data is freely available and used by security vendors, browser protection tools, and CERTs to block access to known malicious URLs and protect end users from malware infections including trojans, ransomware, banking malware, and more.

Frequently asked questions

What is URLhaus?

URLhaus is a project by abuse.ch that collects and shares URLs used for malware distribution. Security researchers and vendors contribute malicious URLs to help protect users and organizations from threats like trojans, ransomware, and phishing kits.

What does "listed" mean?

If a URL or domain is listed in URLhaus, it means the database contains reports of that URL or host being associated with malware distribution. This could include hosting malware payloads, acting as a command-and-control server, or distributing phishing content.

My domain is listed — what do I do?

First, investigate the reported URLs to determine if your server was compromised. Remove any malicious content, patch vulnerabilities, change credentials, and scan for backdoors. Once cleaned, you can contact abuse.ch to request review and potential removal from the database.

How often is URLhaus updated?

URLhaus is updated continuously as security researchers submit new malicious URLs. The database is community-driven and typically reflects newly discovered threats within minutes to hours of their initial report.

More free tools