Threat intelligence feed
Malware URL Feed
Real-time malicious URL intelligence covering payload-distribution sites, C2 endpoints and phishing pages. Every URL is attributed to a specific family or campaign, so you can block the exact path without taking down a shared host.
15-day free trial · no credit card · reply within one business day
Drops straight into the tools your SOC already runs
Precision at the URL level
Block malicious paths without overblocking shared hosts
A single compromised host can serve both legitimate traffic and an active payload. Domain- or IP-level blocklists force an all-or-nothing call. The Malware URL Feed works at the path level, so you block the exact malicious URL and leave the rest of the host reachable, with every indicator attributed to the family or campaign behind it.
URL-level precision
Block specific malicious paths instead of whole domains. That keeps false positives down on shared hosting, CDNs and compromised legitimate sites, where a domain- or IP-level block would take out everything else on the host.
Attribution on every URL
Every URL is mapped to a known malware family or campaign. A block tells you whether you're looking at a phishing kit, a loader's payload host, or a command-and-control (C2) callback, not just an anonymous hit.
Flexible delivery, no new tooling
Consume the feed as CSV, REST API (JSON), STIX/TAXII or MISP. Push URLs straight into a proxy, secure web gateway, firewall or SIEM/TIP workflow without building a new ingestion pipeline.
The Malware URL Feed is a real-time list of the malicious URLs behind active malware and credential-theft operations: payload-distribution sites, command-and-control (C2) endpoints and phishing pages. Because it works at the URL level, you block the specific malicious path without taking down an entire domain, which cuts false positives on shared or compromised hosts.
Every URL is attributed to a known malware family or campaign. A block doesn’t just generate an alert. It tells you whether you’re looking at a ClickFix lure and distribution URL or a Cobalt Strike C2 callback.
You get targeted URL coverage that works alongside your domain and IP blocklists: fewer indicators, higher confidence, and the campaign context your analysts need to triage and respond.
What’s in the feed
- Real-time feed of malware-distribution, C2 and phishing URLs tied to active operations
- URL-level precision for blocking exact paths without overblocking shared hosts
- Family and campaign attribution on every indicator
- Coverage across dozens of currently tracked malware, infostealer, RAT and loader families
- CSV and REST API (JSON) delivery for bulk ingestion and automation
- Available through STIX/TAXII and MISP feeds for teams standardizing on threat-intelligence platforms
Evaluate before you commit
You can validate freshness, attribution quality and feed fit against your existing stack before committing. Test URL indicators against your Microsoft Sentinel incidents, populate MISP or OpenCTI events, or compare coverage overlap with your current sources to see where this feed adds signal.
Start a 15-day free trial. Access is immediate and includes the full PrecisionSec feed set: malicious URL, domain, IP and hash feeds, plus the malware domain list.
When to use this feed
- SOC alert enrichment: pivot from a URL hit to family and campaign context so analysts know what they’re dealing with before escalation.
- Proxy and secure web gateway blocking: push high-confidence malicious URLs into a proxy, secure web gateway, firewall or DNS control in the path of user traffic, without blocking the rest of a shared host.
- Phishing response and takedown: act on attributed phishing URLs, and feed them into user-reporting and takedown workflows.
- Threat hunting: use attributed URL indicators to search current and historical logs for related campaign infrastructure.
- MSSP and multi-tenant coverage: apply curated malicious URL intelligence across customer environments with a predictable feed format.
- Data resellers and security products: integrate high-confidence malicious URL intelligence into your own platform without building a collection pipeline.
You get the Malware URL Feed with every PrecisionSec intelligence subscription, alongside the malicious domain, IP and hash feeds and the malware domain list. Request evaluation access to see live data, delivery formats and integration options.
Ready to see all of our data?
Start your 15-day free trial and get the full Malware URL Feed feed, plus every other malware and C2 feed.