API documentation
This guide describes each endpoint: its parameters, what it returns, and an example in Python. We provide two APIs for trusted reporters (report_url and get_trusted_report) and one endpoint for administrators (internal report).
To get an API token, use the contact form or email
.
Report a URL
Trusted reportersReport malicious activity to URLAbuse. This API is only given to trusted third parties who want to report URLs to URLAbuse.
Parameters
| Name | Required | Default | Description |
|---|---|---|---|
token | Yes | — | Contact us for a token |
url | Yes | — | Malicious or suspicious URL |
date_type | Yes | — | One of phishing, malware, hacked, bet or scam |
target | No | OTHER | Target of the phishing or malware type (e.g. #pe32), or scam type |
geofenced | No | — | Two-letter country code (e.g. US) from which the phishing or malware content is reachable |
reporter | No | anonymous | Name of the reporter or your company (maximum 30 characters) |
Return value
The API always returns a JSON object like this:
{
"success": true,
"code": 200,
"msg": "Reported successfully"
}
Example (Python)
# Report a malicious activity to URLAbuse
import requests, json, sys
reported_url = 'https://vendorknewkaraoke60.sbs'
api_url = "https://zapi.urlabuse.com/feed/report_url"
data_type = 'phishing'
target = 'Payment'
geofenced = 'US'
params = {"token": "PUT-YOUR-TOKEN-HERE", "target": target, "data_type": data_type,
"url": reported_url, "geofenced": geofenced}
r = requests.get(api_url, params=params, timeout=10)
if r.status_code != 200:
print("Failed to get the result from service")
sys.exit(1)
result = json.loads(r.text)
print(result)
Trusted report
Trusted reportersReport malicious activity to URLAbuse. This API is only given to trusted third parties who want to report URLs to URLAbuse.
Parameters
| Name | Required | Default | Description |
|---|---|---|---|
token | Yes | — | Contact us for a token |
url | Yes | — | Malicious or suspicious URL |
rtype | Yes | — | One of phishing, malware, hacked, bet or scam |
target | No | OTHER | Target of the phishing or malware type (e.g. #pe32), or scam type |
screenshot | No | — | Base64-encoded JPG screenshot (only for phishing, bet, scam or hacked) |
reporter | No | anonymous | Name of the reporter or your company (maximum 30 characters) |
is_public | No | 1 (public) | Report the data privately with 0, or publicly with 1 |
Return value
The API always returns a JSON object like this:
{
"success": true
}
Example (Python)
# Report a malicious activity to URLAbuse
import requests
import json
import sys
import base64
# this is the URL we want to report
to_report_url = 'https://webmail.50-6-111-32.cprapid.com/security-chec/signin?verify_id=62054'
# this is the API URL
api_url = "https://urlabuse.com/get_trusted_report"
# we want to report a phishing attack
rtype = 'phishing'
# targeting AT&T
target = "AT&T"
# with screenshot already saved on our machine
screenshot = open("/temp/att_image.jpg", "rb").read()
screenshot = base64.b64encode(screenshot)
reporter = "SOURENA"
is_public = 0
params = {
"token": "YOUR-TOKEN-HERE",
"target": target, "rtype": rtype,
"url": to_report_url, "is_public": is_public,
"screenshot": screenshot, "reporter": reporter
}
r = requests.post(api_url, data=params, timeout=10)
if r.status_code != 200:
print("Failed to get the result from service")
sys.exit(1)
result = json.loads(r.text)
print(result)
Internal report
Administrators onlyReport a URL to URLAbuse from internal services. This API is only available to administrators of the system.
Parameters
| Name | Required | Default | Description |
|---|---|---|---|
token | Yes | — | Administrator token |
cti_url | Yes | — | Permanent URL of the internal system |
rtype | Yes | — | One of phishing, malware, hacked, bet or scam |
target | No | OTHER | Target of the phishing or malware type (e.g. #pe32), or scam type |
is_public | No | 1 (public) | Report the data privately with 0, or publicly with 1 |
Return value
The API always returns a JSON object like this:
{
"success": true
}
Example code
If you are an administrator, contact us and we will provide you with sample code.