# URLhaus adds DNS RPZ feed for malware blocking

Published: 2019-06-17 · Severity: low
Canonical: https://vorant.io/reports/11181c31-c1ce-5b4a-8de2-4b7b7a0a4881/urlhaus-adds-dns-rpz-feed-for-malware-blocking

> abuse.ch released a DNS Response Policy Zone feed from URLhaus data to block malware distribution domains, updated every 5 minutes and excluding Alexa Top 1M sites.

abuse.ch has introduced a DNS Response Policy Zone (RPZ) feed derived from URLhaus, which has tracked over 200,000 malware URLs. The RPZ feed enables system administrators to block DNS resolution for domains actively distributing malware by returning NXDOMAIN responses. The feed updates every 5 minutes and excludes Alexa Top 1M sites to minimize false positives.

The primary threats tracked by URLhaus include Emotet (Heodo), Mirai, Gayfgyt, and Gozi ISFB (Ursnif). The RPZ implementation is compatible with DNS servers supporting the RPZ standard, including Bind and PowerDNS. The blog post provides detailed configuration instructions for Bind on Ubuntu 18.04.2 LTS, including setup of automated updates via cron and optional logging of blocked queries.

This defensive capability allows organizations to leverage community-sourced threat intelligence to prevent users from accessing known malware distribution infrastructure at the DNS layer, providing an additional control point for network security.

## Mentioned in this report

- Malware: Emotet, Gayfgyt, Gozi ISFB, Heodo, Mirai, Ursnif

Source reporting: https://abuse.ch/blog/using-urlhaus-as-response-policy-zone-rpz

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/11181c31-c1ce-5b4a-8de2-4b7b7a0a4881/urlhaus-adds-dns-rpz-feed-for-malware-blocking.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
