Privacy:  No cookies. No personal data collected. IPs logged for security only and purged periodically.
POST https://zapi.urlabuse.com/feed/report_url

Report a URL

Trusted reporters

Report malicious activity to URLAbuse. This API is only given to trusted third parties who want to report URLs to URLAbuse.

All data received through this API is verified by the URLAbuse team.

Parameters

NameRequiredDefaultDescription
tokenYes—Contact us for a token
urlYes—Malicious or suspicious URL
date_typeYes—One of phishing, malware, hacked, bet or scam
targetNoOTHERTarget of the phishing or malware type (e.g. #pe32), or scam type
geofencedNo—Two-letter country code (e.g. US) from which the phishing or malware content is reachable
reporterNoanonymousName of the reporter or your company (maximum 30 characters)

Return value

The API always returns a JSON object like this:

JSON
{
    "success": true,
    "code": 200,
    "msg": "Reported successfully"
}

Example (Python)

Python
# Report a malicious activity to URLAbuse
import requests, json, sys

reported_url = 'https://vendorknewkaraoke60.sbs'
api_url = "https://zapi.urlabuse.com/feed/report_url"
data_type = 'phishing'
target = 'Payment'
geofenced = 'US'

params = {"token": "PUT-YOUR-TOKEN-HERE", "target": target, "data_type": data_type,
          "url": reported_url, "geofenced": geofenced}

r = requests.get(api_url, params=params, timeout=10)
if r.status_code != 200:
    print("Failed to get the result from service")
    sys.exit(1)

result = json.loads(r.text)
print(result)
POST https://urlabuse.com/get_trusted_report

Trusted report

Trusted reporters

Report malicious activity to URLAbuse. This API is only given to trusted third parties who want to report URLs to URLAbuse.

We don’t manually verify data received through this API. It is only given to trusted third parties.

Parameters

NameRequiredDefaultDescription
tokenYes—Contact us for a token
urlYes—Malicious or suspicious URL
rtypeYes—One of phishing, malware, hacked, bet or scam
targetNoOTHERTarget of the phishing or malware type (e.g. #pe32), or scam type
screenshotNo—Base64-encoded JPG screenshot (only for phishing, bet, scam or hacked)
reporterNoanonymousName of the reporter or your company (maximum 30 characters)
is_publicNo1 (public)Report the data privately with 0, or publicly with 1

Return value

The API always returns a JSON object like this:

JSON
{
    "success": true
}

Example (Python)

Python
# Report a malicious activity to URLAbuse
import requests
import json
import sys
import base64

# this is the URL we want to report
to_report_url = 'https://webmail.50-6-111-32.cprapid.com/security-chec/signin?verify_id=62054'

# this is the API URL
api_url = "https://urlabuse.com/get_trusted_report"

# we want to report a phishing attack
rtype = 'phishing'

# targeting AT&T
target = "AT&T"

# with screenshot already saved on our machine
screenshot = open("/temp/att_image.jpg", "rb").read()
screenshot = base64.b64encode(screenshot)

reporter = "SOURENA"
is_public = 0
params = {
    "token": "YOUR-TOKEN-HERE",
    "target": target, "rtype": rtype,
    "url": to_report_url, "is_public": is_public,
    "screenshot": screenshot, "reporter": reporter
}

r = requests.post(api_url, data=params, timeout=10)
if r.status_code != 200:
    print("Failed to get the result from service")
    sys.exit(1)

result = json.loads(r.text)
print(result)
POST https://urlabuse.com/get_report_from_cti_data

Internal report

Administrators only

Report a URL to URLAbuse from internal services. This API is only available to administrators of the system.

Data sent through this API has already been collected and verified by the internal system.

Parameters

NameRequiredDefaultDescription
tokenYes—Administrator token
cti_urlYes—Permanent URL of the internal system
rtypeYes—One of phishing, malware, hacked, bet or scam
targetNoOTHERTarget of the phishing or malware type (e.g. #pe32), or scam type
is_publicNo1 (public)Report the data privately with 0, or publicly with 1

Return value

The API always returns a JSON object like this:

JSON
{
    "success": true
}

Example code

If you are an administrator, contact us and we will provide you with sample code.