IOC / Threat Intel Lookup
You're using IOC Lookup as a guest (3 lookups/day, shared with Domain + URL Lookup). Sign up or sign in for 100 lookups/day.
About this tool
- Enter an IP address, IP range (CIDR), domain, URL, email address, or file hash (SHA-256/SHA-1/MD5) to check it against cached, authorised threat-intelligence data CyberBlink has already correlated and stored. Common defanged formats (for example, 185[.]220[.]101[.]7) are accepted.
- Every result is produced by deterministic, rule-based correlation across sources -- no AI is used anywhere in this analysis, and every conclusion is traceable to the sources that reported it.
- An indicator not found in CyberBlink's store is not proof it is safe, only that it has not been reported by any correlated source yet.
- This tool is a decision aid, not a guarantee. Always verify against your own security controls before acting.
- This checks whether an indicator has been observed in CyberBlink's cached threat-intelligence data -- it does not analyze a domain or URL's own structure. For CyberBlink's own deterministic structural and DNS analysis of a domain or URL, use Domain + URL Lookup instead.
Look up an indicator
Enter an IP address, IP range (CIDR), domain, URL, email address, or file hash to check it against CyberBlink's cached, correlated threat-intelligence store.
What this result means
- Coverage
- CyberBlink checks its cached threat-intelligence data from authorised sources including URLhaus, ThreatFox, and MalwareBazaar -- not the entire internet.
- Freshness
- This data is refreshed periodically and is not queried live from those providers for every lookup.
- Interpretation
- A not-found result is not proof an indicator is safe. A found result is one security signal -- validate it alongside your own controls and investigation context.