Last updated: August 8, 2026
MalwareIntel aggregates, normalizes, and presents cyber threat intelligence from publicly available sources. This page lists all data sources, their respective licenses, and attribution requirements.
Primary data sources ingested on a recurring schedule.
| Source | Provider | License | Data Type |
|---|---|---|---|
| MalwareBazaar | abuse.ch | CC0 1.0 (Public Domain) | Malware sample hashes, signatures, tags |
| ThreatFox | abuse.ch | CC0 1.0 (Public Domain) | IOCs (C&C IPs, domains, URLs) |
| URLhaus | abuse.ch | CC0 1.0 (Public Domain) | Malware distribution URLs |
| Feodo Tracker | abuse.ch | CC0 1.0 (Public Domain) | Botnet C&C server IPs |
| SSL Blacklist (SSLBL) | abuse.ch | CC0 1.0 (Public Domain) | Malicious SSL certificates, JA3 fingerprints |
| YARAify | abuse.ch | CC0 1.0 (Public Domain) | YARA rules and scan results |
| MITRE ATT&CK | The MITRE Corporation | Apache 2.0 ATT&CK is a registered trademark of The MITRE Corporation. | TTPs, threat groups, software (STIX 2.1 via TAXII) |
| MITRE D3FEND | The MITRE Corporation | Apache 2.0 D3FEND is a registered trademark of The MITRE Corporation. | Defensive technique ontology and mitigations |
| CISA Known Exploited Vulnerabilities (KEV) | Cybersecurity and Infrastructure Security Agency (CISA) | U.S. Government Public Domain | Actively exploited CVEs with remediation deadlines |
| Malpedia | Fraunhofer FKIE | CC BY-NC-SA 3.0 DE Non-commercial use. MalwareIntel references Malpedia data for enrichment and family identification. YARA rules from Malpedia are subject to individual author licenses. | Malware family profiles, YARA rules, actor mappings |
| MISP OSINT Feed | CIRCL (Computer Incident Response Center Luxembourg) | AGPL-3.0 (software), CC BY-SA (data) MalwareIntel consumes published OSINT feed data; it does not distribute MISP software. | IOCs, events, galaxies, taxonomies |
| Ransomware.live | Julien Mousqueton | CC BY-NC-SA 4.0 Non-commercial license. Enriched by Zscaler ThreatLabz (ransom notes), Will Thomas (tools matrix), Crocodyli (MITRE ATT&CK mapping), Hudson Rock (infostealer data), and Valery Riess-Marchive (negotiation data). | Ransomware groups, victims, TTPs, IOCs, ransom notes, KQL queries |
| Ransomlook.io | Ransomlook | Public API | Ransomware victim data, negotiation metadata, data leak tracking |
| Ransomwatch | joshhighet | MIT | Ransomware leak site monitoring, group status tracking |
| SigmaHQ | SigmaHQ Community | Detection Rule License (DRL) 1.1 Author attribution retained per DRL 1.1 requirements. | Sigma detection rules mapped to MITRE ATT&CK |
APIs used to augment and contextualize existing IOCs.
| Source | Provider | License | Data Type |
|---|---|---|---|
| NVD (National Vulnerability Database) | NIST | U.S. Government Public Domain | CVE details, CVSS scores, CPE entries |
| EPSS (Exploit Prediction Scoring System) | FIRST.org | CC BY-SA 4.0 | Exploit probability scores for CVEs |
| GreyNoise | GreyNoise Intelligence | API Terms of Service (Community API) Used via Community API within published rate limits. | IP noise/benign classification |
| AbuseIPDB | Marathon Studios Inc. | API Terms of Service Used via API within published rate limits. | IP reputation and abuse reports |
| Shodan | Shodan | API Terms of Service Used via API within published rate limits. | Banner data, port/service identification |
| HoneyDB | HoneyDB | Free API (attribution requested) | Honeypot threat data, bad host IPs |
| Webamon | Webamon Ltd. | Free tier API (20 calls/day) Used for domain IOC enrichment within free tier limits. | Domain fingerprinting, tech stack, ASN, campaign clusters (750M+ domains) |
Additional data sources used for threat context and blocklists.
| Source | Provider | License | Data Type |
|---|---|---|---|
| Maltiverse | Maltiverse | API Terms of Service (MSSP tier) API key with MSSP-level access. | IOC enrichment, blacklists, threat context |
| AlienVault OTX | AT&T Cybersecurity | OTX Terms of Service Community API with published rate limits. | Pulses, IOCs, threat context |
| CrowdSec | CrowdSec | MIT (software), Community Blocklists ToS | Community threat signals, IP blocklists |
| Spamhaus | The Spamhaus Project | Spamhaus Technology Data License Non-commercial/low-volume use. Commercial redistribution requires separate license. | Blocklists (SBL, XBL, DROP, EDROP) |
Researchers whose work enriches ransomware intelligence via ransomware.live.
| Researcher / Organization | Contribution |
|---|---|
| Zscaler ThreatLabz | Ransomware profiles and ransom note artifacts |
| Valery Riess-Marchive (LeMagIT) | Cyberattack reporting and negotiation chat data |
| Will Thomas (@BushidoToken) | Ransomware Tools Matrix and Vulnerability Matrix |
| Crocodyli | MITRE ATT&CK TTP mapping for ransomware groups |
| Hudson Rock | Infostealer attribution and credential exposure data |
MalwareIntel does not claim ownership of threat intelligence data sourced from third parties. All data is presented with attribution to its original source and under the terms of the respective licenses listed above.
The value provided by MalwareIntel lies in the aggregation, normalization, correlation, contextual enrichment, and presentation of publicly available data, not in the raw data itself.
IOCs (indicators of compromise) are factual data published for defensive purposes. MalwareIntel does not store or distribute malware binaries, connect to active C&C infrastructure, or provide tools for offensive use.
If you are a data provider and believe your content is being used in a manner inconsistent with your license terms, please contact us at [email protected].