← Aviso Legal

Data Sources & Attributions

Last updated: August 8, 2026

MalwareIntel aggregates, normalizes, and presents cyber threat intelligence from publicly available sources. This page lists all data sources, their respective licenses, and attribution requirements.

Core Intelligence Feeds

Primary data sources ingested on a recurring schedule.

SourceProviderLicenseData Type
MalwareBazaarabuse.chCC0 1.0 (Public Domain)Malware sample hashes, signatures, tags
ThreatFoxabuse.chCC0 1.0 (Public Domain)IOCs (C&C IPs, domains, URLs)
URLhausabuse.chCC0 1.0 (Public Domain)Malware distribution URLs
Feodo Trackerabuse.chCC0 1.0 (Public Domain)Botnet C&C server IPs
SSL Blacklist (SSLBL)abuse.chCC0 1.0 (Public Domain)Malicious SSL certificates, JA3 fingerprints
YARAifyabuse.chCC0 1.0 (Public Domain)YARA rules and scan results
MITRE ATT&CKThe MITRE CorporationApache 2.0

ATT&CK is a registered trademark of The MITRE Corporation.

TTPs, threat groups, software (STIX 2.1 via TAXII)
MITRE D3FENDThe MITRE CorporationApache 2.0

D3FEND is a registered trademark of The MITRE Corporation.

Defensive technique ontology and mitigations
CISA Known Exploited Vulnerabilities (KEV)Cybersecurity and Infrastructure Security Agency (CISA)U.S. Government Public DomainActively exploited CVEs with remediation deadlines
MalpediaFraunhofer FKIECC BY-NC-SA 3.0 DE

Non-commercial use. MalwareIntel references Malpedia data for enrichment and family identification. YARA rules from Malpedia are subject to individual author licenses.

Malware family profiles, YARA rules, actor mappings
MISP OSINT FeedCIRCL (Computer Incident Response Center Luxembourg)AGPL-3.0 (software), CC BY-SA (data)

MalwareIntel consumes published OSINT feed data; it does not distribute MISP software.

IOCs, events, galaxies, taxonomies
Ransomware.liveJulien MousquetonCC BY-NC-SA 4.0

Non-commercial license. Enriched by Zscaler ThreatLabz (ransom notes), Will Thomas (tools matrix), Crocodyli (MITRE ATT&CK mapping), Hudson Rock (infostealer data), and Valery Riess-Marchive (negotiation data).

Ransomware groups, victims, TTPs, IOCs, ransom notes, KQL queries
Ransomlook.ioRansomlookPublic APIRansomware victim data, negotiation metadata, data leak tracking
RansomwatchjoshhighetMITRansomware leak site monitoring, group status tracking
SigmaHQSigmaHQ CommunityDetection Rule License (DRL) 1.1

Author attribution retained per DRL 1.1 requirements.

Sigma detection rules mapped to MITRE ATT&CK

Enrichment Sources

APIs used to augment and contextualize existing IOCs.

SourceProviderLicenseData Type
NVD (National Vulnerability Database)NISTU.S. Government Public DomainCVE details, CVSS scores, CPE entries
EPSS (Exploit Prediction Scoring System)FIRST.orgCC BY-SA 4.0Exploit probability scores for CVEs
GreyNoiseGreyNoise IntelligenceAPI Terms of Service (Community API)

Used via Community API within published rate limits.

IP noise/benign classification
AbuseIPDBMarathon Studios Inc.API Terms of Service

Used via API within published rate limits.

IP reputation and abuse reports
ShodanShodanAPI Terms of Service

Used via API within published rate limits.

Banner data, port/service identification
HoneyDBHoneyDBFree API (attribution requested)Honeypot threat data, bad host IPs
WebamonWebamon Ltd.Free tier API (20 calls/day)

Used for domain IOC enrichment within free tier limits.

Domain fingerprinting, tech stack, ASN, campaign clusters (750M+ domains)

Reference Datasets

Additional data sources used for threat context and blocklists.

SourceProviderLicenseData Type
MaltiverseMaltiverseAPI Terms of Service (MSSP tier)

API key with MSSP-level access.

IOC enrichment, blacklists, threat context
AlienVault OTXAT&T CybersecurityOTX Terms of Service

Community API with published rate limits.

Pulses, IOCs, threat context
CrowdSecCrowdSecMIT (software), Community Blocklists ToSCommunity threat signals, IP blocklists
SpamhausThe Spamhaus ProjectSpamhaus Technology Data License

Non-commercial/low-volume use. Commercial redistribution requires separate license.

Blocklists (SBL, XBL, DROP, EDROP)

Ransomware Research Credits

Researchers whose work enriches ransomware intelligence via ransomware.live.

Researcher / OrganizationContribution
Zscaler ThreatLabzRansomware profiles and ransom note artifacts
Valery Riess-Marchive (LeMagIT)Cyberattack reporting and negotiation chat data
Will Thomas (@BushidoToken)Ransomware Tools Matrix and Vulnerability Matrix
CrocodyliMITRE ATT&CK TTP mapping for ransomware groups
Hudson RockInfostealer attribution and credential exposure data

Disclaimer

MalwareIntel does not claim ownership of threat intelligence data sourced from third parties. All data is presented with attribution to its original source and under the terms of the respective licenses listed above.

The value provided by MalwareIntel lies in the aggregation, normalization, correlation, contextual enrichment, and presentation of publicly available data, not in the raw data itself.

IOCs (indicators of compromise) are factual data published for defensive purposes. MalwareIntel does not store or distribute malware binaries, connect to active C&C infrastructure, or provide tools for offensive use.

If you are a data provider and believe your content is being used in a manner inconsistent with your license terms, please contact us at [email protected].