VORANT. Threat Intelligence Sign in Get the full feed

URLhaus adds DNS RPZ blocklist feature

low threat

Abuse.ch's URLhaus, tracking over 200,000 malware URLs, now offers a DNS Response Policy Zone feed to help admins block malware domains via Bind.

This is a technical tutorial from abuse.ch describing how to integrate the URLhaus RPZ (Response Policy Zone) dataset into a Bind DNS server to block resolution of domains actively distributing malware. URLhaus, a community-driven malware URL tracking project, recently surpassed 200,000 tracked malicious URLs, with the majority linked to Emotet (Heodo), followed by Mirai, Gafgyt, and Gozi ISFB (Ursnif).

The article walks through configuring Bind9 on Ubuntu to consume the URLhaus RPZ feed, which updates every 5 minutes and excludes Alexa Top 1M domains to reduce false positives. Once configured, DNS queries for known malware distribution domains return NXDOMAIN, effectively acting as a DNS-layer firewall. The post also includes guidance on logging blocked queries and applying access control lists to prevent the DNS server from becoming an open resolver vulnerable to amplification attacks.

This is a defensive tooling/how-to piece rather than a report on active threat activity, though it references the malware families most commonly associated with URLhaus-tracked distribution infrastructure.

Mentioned in this report

Malware EmotetGafgytGozi ISFBMirai

Source reporting: https://abuse.ch/blog/using-urlhaus-as-response-policy-zone-rpz

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free