2s.io

https://2s.io/api/security/ioc-reputation

Threat-intelligence reputation for an indicator of compromise (IOC) — pass ioc as an IP, domain, URL, or file hash (md5/sha1/sha256) and the type is auto-detected. Returns a malicious boolean plus a per-source breakdown: abuse.ch ThreatFox (IOC→malware/threat mapping), URLhaus (malicious URLs on a host/URL), MalwareBazaar (known malware samples by hash), Feodo Tracker (active botnet C2 IPs), Tor exit-node membership, and Spamhaus DROP (hijacked/criminal netblocks). Each source reports listed + a detail. Sourced from live, hourly-rotating threat feeds an LLM cannot know — a ground-truth liveness check for SOC alert triage, log enrichment, and blocklist decisions. Absence of a match is not proof of safety.

last updated: Jun 17, 2026 · type: http · x402 v2

Payment Options

NetworkSchemeAmountPay To
Baseexact$0.002160 USDC0x2b6D...32C5
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdpexact0.00 tokensTW6nta...yWhn

Try It

Resource Activity

via Bazaar · last 30 days
Calls
1
Unique Payers
1
Last Called
Jun 17, 2026