Country Profile & Intelligence Analyzer avatar

Country Profile & Intelligence Analyzer

Deprecated

Pricing

$100.00 / 1,000 charged when a domain threat intelligence analyses

Go to Apify Store
Country Profile & Intelligence Analyzer

Country Profile & Intelligence Analyzer

Deprecated

Get detailed country profiles with economic, political, and development data for market research and business decisions.

Pricing

$100.00 / 1,000 charged when a domain threat intelligence analyses

Rating

0.0

(0)

Developer

daehwan kim

daehwan kim

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

10 days ago

Last modified

Share

Domain Threat Intelligence Scorer

Instantly check whether any domain or URL is a phishing site, malware host, or abusive IP — without running your own threat feed infrastructure. Cross-checks PhishTank, URLhaus (abuse.ch), and AbuseIPDB in parallel to produce a 0–100 threat score with grade and actionable verdict, so security teams and platforms can block threats at scale.

What does Domain Threat Intelligence Scorer do?

  • Checks domains against PhishTank's verified phishing URL database via POST API
  • Queries URLhaus (abuse.ch) malware feed for active malicious URLs and Spamhaus/SURBL blacklist status
  • Resolves the domain to its IP address and checks AbuseIPDB for confidence score and total abuse reports
  • Extracts malware family tags (e.g. Emotet, Cobalt Strike) from URLhaus metadata
  • Returns a composite threat score, grade (Clean/Low/Medium/High/Critical), and specific threat flags

Key Features

  • Multi-Source Cross-Validation: Combines PhishTank, URLhaus/abuse.ch, and AbuseIPDB for comprehensive threat intelligence across phishing, malware, and IP abuse vectors
  • Scoring System: Produces a 0–100 threat score with grades from Clean to Critical
  • Threat Flag Detection: Flags CONFIRMED_PHISHING, ACTIVE_MALWARE_HOST, RANSOMWARE, BLACKLISTED, and more
  • Malware Family Identification: Surfaces specific malware families associated with the domain from URLhaus tags
  • Batch Processing: Analyze multiple domains in a single run
  • Pay Per Event: Only $0.05 per analysis — no subscription needed

Input

ParameterTypeRequiredDescription
domainsarrayYesList of domains or URLs to analyze (protocol and path are stripped automatically)

Output Example

{
"domain": "evil-phishing-example.com",
"threatScore": 75,
"grade": "High",
"verdict": "High risk — active threats identified, blocking recommended",
"phishingStatus": "Confirmed phishing site",
"phishDetailPage": "https://www.phishtank.com/phish_detail.php?phish_id=12345",
"malwareUrls": 2,
"malwareBlacklisted": true,
"abuseConfidence": 87,
"resolvedIp": "192.0.2.45",
"ipTotalReports": 234,
"ipUsageType": "Data Center/Web Hosting/Transit",
"threatTypes": ["Emotet", "phishing"],
"flags": ["CONFIRMED_PHISHING", "MALWARE_URLS_DETECTED", "BLACKLISTED", "HIGH_ABUSE_CONFIDENCE"],
"scoreBreakdown": {
"phishing": 40,
"malware": 20,
"ipAbuse": 25,
"total": 75
},
"sources": [
"PhishTank (https://www.phishtank.com)",
"URLhaus / abuse.ch (https://urlhaus.abuse.ch)",
"AbuseIPDB (https://www.abuseipdb.com)"
],
"timestamp": "2024-01-15T10:30:00Z"
}

Use Cases

  • Email Security Gateways: Enrich inbound link scanning with real-time phishing and malware verdicts
  • SOC Threat Hunting: Batch-screen domains from log files, SIEM alerts, or threat intel feeds
  • Brand Protection: Monitor for impersonation domains distributing phishing kits using your brand name
  • Threat Intelligence Platforms: Integrate domain scoring as an enrichment step in existing workflows

Data Sources

SourceCoverageRate Limit
PhishTank2M+ verified phishing URLsFree; key increases limits
URLhaus / abuse.chActive malware URL feed, Spamhaus/SURBL blacklistsFree, no key required
AbuseIPDB8M+ IP abuse reports (90-day window)Free tier: 1,000 req/day with key

Scoring Breakdown

DimensionMax PointsWhat It Measures
Phishing (PhishTank)40Verified = 40, unverified = 25, not found = 0
Malware (URLhaus)355+ active URLs = 35, 1–4 = 20, blacklisted only = 30
IP Abuse (AbuseIPDB)25Confidence >80% = 25, 50–80% = 15, 20–50% = 8

Pricing

This actor uses Pay Per Event pricing at $0.05 per analysis. You only pay for successful analyses.

API Keys (Optional)

Some data sources work better with API keys. Set these as environment variables:

Without AbuseIPDB key, the IP abuse dimension is skipped and the max possible score is 75/100. PhishTank and URLhaus work without any keys.


Extend this actor with the ntriqpro intelligence network:

⭐ Love it? Leave a Review

Your rating helps professionals discover this actor. Rate it here.

Disclaimer

RISK ASSESSMENT DISCLAIMER: This tool provides data-driven risk analysis based on publicly available and curated sources. Assessments are indicative only and NOT professional risk management advice. You must engage qualified professionals (risk managers, insurance brokers, compliance officers) to validate findings before making investment or operational decisions. Risk scores do not constitute investment advice or due diligence completion. We assume no liability for business decisions based on this tool's output.