URLhaus Recent Payloads
Automatic deploy
Supported by Filigran
Infrastructure & Attack Surface Visibility
Overview
Imports the most recent malware payloads from URLhaus (abuse.ch) into OpenCTI as file observables and malware entities.
URLhaus Recent Payloads imports the most recently submitted malware payloads from URLhaus (abuse.ch) into OpenCTI. It fetches the latest malware samples distributed via malicious URLs, creating file observables (MD5, SHA-256) and malware entities, providing near-real-time visibility into active malware distribution activity.