VOOZH about

URL: https://apify.com/crawland/ioc-lookup

โ‡ฑ IOC Lookup & Threat Intelligence API ยท Apify


Pricing

from $2.00 / 1,000 ioc lookups

Go to Apify Store

Real-time IoC reputation lookups (URL, hash, IP, domain) served from the Crawland threat-intelligence backend.

Pricing

from $2.00 / 1,000 ioc lookups

Rating

0.0

(0)

Developer

๐Ÿ‘ Crawland

Crawland

Maintained by Community

Actor stats

0

Bookmarked

1

Total users

1

Monthly active users

18 days ago

Last modified

Share

Real-time threat intelligence for file hashes, IPv4 addresses, domains, and URLs โ€” 70+ vendor verdicts in a single call.

API Overview

IoC Lookup is a real-time threat intelligence API that answers a simple question: "Is this indicator dangerous?"

Send any of four indicator types โ€” a file hash (MD5 / SHA-1 / SHA-256), a URL, an IPv4 address, or a domain โ€” and get a structured risk overview that helps you understand the indicator faster.

  • Vendor-level insight: Compare verdicts from 70+ security engines including BitDefender, Sophos, Forcepoint, Cisco, ESET, Kaspersky, Fortinet, McAfee, and more.
  • Reputation summary: Quickly assess whether an indicator is trusted, suspicious, or malicious.
  • Detection breakdown: Review malicious, suspicious, harmless, and undetected counts for faster decision-making.
  • Indicator-specific context: Get relevant enrichment data depending on the indicator type, such as domain, IP, URL, or file-related intelligence.

Response Highlights

An IoC Lookup response can include security vendor analysis, detection statistics, reputation data, categories, threat names, URL metadata, redirects, response codes, outgoing links, trackers, DNS records, WHOIS data, certificate details, sandbox verdicts, contacted domains/IPs, and file intelligence depending on the indicator type.

What can you do with this API?

  • ๐Ÿ”Ž Look up URLs, domains, IPs, and hashes
  • ๐Ÿ›ก๏ธ Check vendor-level security analysis
  • ๐Ÿ“Š Review malicious, suspicious, harmless, and undetected counts
  • ๐ŸŒ Inspect URL redirects, metadata, response codes, and trackers
  • ๐Ÿงฉ Analyze domain data such as DNS, WHOIS, certificates, and reputation
  • ๐Ÿ“ Investigate hashes with file metadata, threat labels, and sandbox results

Response model

Every successful request returns:

{
"is_success":true,
"response_code":200,
"message":"Success",
"data":{/* indicator-specific payload */}
}

When an indicator can't be processed (e.g. a malformed value), the call still returns HTTP 200 with is_success: false and the underlying response_code in the body โ€” inspect is_success rather than relying on the HTTP status alone.

Use cases

GET /url

Look up a URL โ€” phishing, defacement, content classification, vendor verdicts. Pro tip: pass the full URL including scheme. Query strings and fragments are accepted but normalised internally.

GET /hash

Look up a file by MD5 / SHA-1 / SHA-256. Returns file metadata, signing info, behavioural tags, and 70+ vendor verdicts.

GET /ip

Look up an IPv4 address โ€” reputation, ASN / network ownership, country, vendor verdicts. IPv6 is not currently supported.

GET /domain

Look up a domain โ€” reputation, WHOIS, DNS records, popularity ranks (Alexa, Cisco Umbrella, Cloudflare Radar, Majestic), content categories, JARM fingerprint.

Need something custom or need support?

Looking for a different response format, a bulk lookup option, a custom integration, or help with setup? Send us a DM and we'll be happy to support you and help you find the best setup for your use case.

You might also like

Subdomain Discovery API

crawland/subdomain-discovery-api

Paginated subdomain enumeration for any registered domain โ€” DNS records, registrar, WHOIS, vendor reputation, and category labels per subdomain, served from the Crawland threat-intelligence backend.

IoC Enrichment API

crawland/ioc-enrichment-api

Enrich URLs, domains, IPs, and hashes with threat intelligence, related references, malware associations, adversary links, attack techniques, targeted regions, and affected industries.

Domain Reputation Checker API

dev00/domain-reputation-checker-api

Assess the reputation of a domain using OSINT and SIGINT signals from Spamhaus threat intelligence, showing threat score, dimensions, whois data and abuse tags.

dev00

2

IP Address Risk Scoring (IP Intelligence)

greip/ip-scoring

Access comprehensive threat intelligence data for IP addresses. Provides insights into malicious activity, reputation scoring, and potential security risks for enhanced fraud detection and security.

IP Intelligence Aggregator ๐ŸŒ

easyapi/ip-intelligence-aggregator

Comprehensive IP address intelligence tool that aggregates data from 7 different IP information services, providing detailed geolocation, ISP, timezone, and threat intelligence data for any IPv4 address.

urlscan.io Threat Intelligence Scraper

parseforge/urlscan-scraper

Search the urlscan.io public scan database with Lucene queries (domain, page.url, hash, IP, ASN, tag) and export scan metadata: page URL, IP, ASN, server, TLS, screenshot, redirect chain, country, brand, verdict.

IP Address Information Lookup

calm_necessity/ip-info-actor

IP Address Information Lookup is a fast and lightweight Actor that returns detailed geolocation and network metadata for any IP address. Simply provide an IP address, and the Actor will fetch structured information used for analytics

๐Ÿ‘ User avatar

Taher Ali Badnawarwala

6