Open navigation

AbuseIPDB

Modified on: Tue, 8 Oct, 2024 at 8:38 AM

Overview

AbuseIPDB is a project dedicated to helping combat the spread of hackers, spammers, and abusive activity on the internet.


AbuseIPDB’s mission is to help make the internet a safer place by providing a central blacklist for webmasters, system administrators, and other interested parties to report and find IP addresses that have been associated with malicious activity online.


With AbuseIPDB Transforms, you can discover information about IPv4 and IPv6 Addresses, such as abuse score, IP usage type, hostname associated with the IP, Country, and ISP Details.


Don't miss our blog article, The Power of AbuseIPDB is now in Maltego, where we walk you through AbuseIPDB data and illustrate how to use the AbuseIPDB Transforms in Maltego to speed up investigations involving suspicious IP addresses.


Access

Access to AbuseIPDB is free and can be used with any Maltego license and AbuseIPDB API key. Installation can be completed directly from the Data Hub in the Maltego Graph Client.


Register here for a free API key (limited to 1000 requests per day).


For more information about the AbuseIPDB integration visit our website here.


AbuseIPDB Transforms

Check Abuse Score [AbuseIPDB]

Description

This Transform returns the input IP address Entity with the confidence score in the detail view and a bookmark overlay


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
API Keystringfalsetruetrue

Transform Meta Info

InformationValue
Display NameCheck Abuse Score [AbuseIPDB]
Owner
AuthorMaltego
Data SourceAbuseIPDB
Short DescriptionThis Transform returns the input IP address Entity with the confidence score in the detail view and a bookmark overlay

Variants

Transform NameInput EntitiesOutput Entities
abuseipdb.ipv6AddressToReputationmaltego.IPv6Addressmaltego.IPv6Address
abuseipdb.ipv4AddressToReputationmaltego.IPv4Addressmaltego.IPv4Address

To ISP Domain [AbuseIPDB]

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
API Keystringfalsetruetrue

Transform Meta Info

InformationValue

Display Name Owner

To ISP Domain [AbuseIPDB]

AuthorMaltego
Data SourceAbuseIPDB
Output Entitiesmaltego.Domain

Variants

Transform NameInput EntitiesShort Description
abuseipdb.ipv6AddressToDomainmaltego.IPv6AddressThis Transform returns the ISP domain for the given IPv6 Address
abuseipdb.ipv4AddressToDomainmaltego.IPv4AddressThis Transform returns the ISP domain for the given IPv4 Address

Report IP Address [AbuseIPDB]

Description

Report the input IP address to AbuseIPDB


Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
1 DNS Compromise Altering DNS records resulting in improper redirection.booleantruetruefalse
10 Web Spam Comment/forum spam, HTTP referer spam, or other CMS spam.booleantruetruefalse
11 Email Spam Spam email content, infected attachments, and phishing emails. Note: Limit comments to only relevent information (instead of log dumps) and be sure to remove PII if you want to remain anonymous.booleantruetruefalse
12 Blog Spam CMS blog comment spam.booleantruetruefalse
13 VPN IP Conjunctive category.booleantruetruefalse
14 Port Scan Scanning for open ports and vulnerable services.booleantruetruefalse
15 Hackingbooleantruetruefalse
16 SQL Injection Attempts at SQL injection.booleantruetruefalse
17 Spoofing Email sender spoofing.booleantruetruefalse
18 Brute-Force Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc. This category is seperate from DDoS attacks.booleantruetruefalse
19 Bad Web Bot Webpage scraping (for email addresses, content, etc) and crawlers that do not honor robots.txt. Excessive requests and user agent spoofing can also be reported here.booleantruetruefalse
2 DNS Poisoning Falsifying domain server cache (cache poisoning).booleantruetruefalse
20 Exploited Host Host is likely infected with malware and being used for other attacks or to host malicious content. The host owner may not be aware of the compromise. This category is often used in combination with other attack categories.booleantruetruefalse
21 Web App Attack Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions.booleantruetruefalse
22 SSH Secure Shell (SSH) abuse. Use this category in combination with more specific categories.booleantruetruefalse
23 IoT Targeted Abuse was targeted at an “Internet of Things” type device. Include information about what type of device was targeted in the comments.booleantruetruefalse
3 Fraud Orders Fraudulent orders.booleantruetruefalse
4 DDoS Attack Participating in distributed denial-of-service (usually part of botnet).booleantruetruefalse
5 FTP Brute-Forcebooleantruetruefalse
6 Ping of Death Oversized IP packet.booleantruetruefalse
7 Phishing Phishing websites and/or email.booleantruetruefalse
8 Fraud VoIPbooleantruetruefalse
9 Open Proxy Open proxy, open relay, or Tor exit node.booleantruetruefalse
API Keystringfalsetruetrue
Commentstringtruetruefalse

Transform Meta Info

InformationValue

Display Name Owner

Report IP Address [AbuseIPDB]

AuthorMaltego

Data Source Output Entities

AbuseIPDB

Short DescriptionReport the input IP address to AbuseIPDB

Variants

Transform NameInput Entities
abuseipdb.reportIpv6Addressmaltego.IPv6Address
abuseipdb.reportIpv4Addressmaltego.IPv4Address

To Usage Type [AbuseIPDB]

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
API Keystringfalsetruetrue

Transform Meta Info

InformationValue

Display Name Owner

To Usage Type [AbuseIPDB]

AuthorMaltego
Data SourceAbuseIPDB
Output Entitiesmaltego.Phrase

Variants

Transform NameInput EntitiesShort Description
abuseipdb.ipv4AddressToUsageTypemaltego.IPv4AddressThis Transform returns the usage type for the IPv4 address
abuseipdb.ipv6AddressToUsageTypemaltego.IPv6AddressThis Transform returns the usage type for the IPv6 address

To Reporter [AbuseIPDB]

Description

This Transform returns the reporter ID to the report


Transform Meta Info

InformationValue
Display NameTo Reporter [AbuseIPDB]
Owner
AuthorMaltego
Data SourceAbuseIPDB
Transform Nameabuseipdb.reportToReporterId
Input Entitiesmaltego.abuseipdb.Report
Output Entitiesmaltego.Alias
Short DescriptionThis Transform returns the reporter ID in the report

To Category [AbuseIPDB]

Description

This Transform returns the categories mentioned in the report for the given IPv4 Address


Transform Meta Info

InformationValue
Display NameTo Category [AbuseIPDB]
Owner
AuthorMaltego
Data SourceAbuseIPDB
Transform Nameabuseipdb.reportToCategories
Input Entitiesmaltego.abuseipdb.Report
Output Entitiesmaltego.maltego.abuseipdb.Tag
Short DescriptionThis Transform returns the categories mentioned in the report for the given IPv4 Address

To Report [AbuseIPDB]

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
API Keystringfalsetruetrue

Transform Meta Info

InformationValue

Display Name Owner

To Report [AbuseIPDB]

AuthorMaltego
Data SourceAbuseIPDB
Output Entitiesmaltego.abuseipdb.Report

Variants

Transform NameInput EntitiesShort Description
abuseipdb.ipv4AddressToAbuseReportmaltego.IPv4AddressThis Transform returns the AbuseIPDB report for the IPv4 address
abuseipdb.ipv6AddressToAbuseReportmaltego.IPv6AddressThis Transform returns the AbuseIPDB report for the IPv6 address

To ISP [AbuseIPDB]

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
API Keystringfalsetruetrue

Transform Meta Info

InformationValue

Display Name Owner

To ISP [AbuseIPDB]

AuthorMaltego
Data SourceAbuseIPDB
Output Entitiesmaltego.ISP

Variants

Transform NameInput EntitiesShort Description
abuseipdb.ipv6AddressToIspmaltego.IPv6AddressThis Transform returns the AbuseIPDB report for the IPv6 address
abuseipdb.ipv4AddressToIspmaltego.IPv4AddressThis Transform returns the AbuseIPDB report for the IPv4 address

To Hostnames [AbuseIPDB]

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
API Keystringfalsetruetrue

Transform Meta Info

InformationValue

Display Name Owner

To Hostnames [AbuseIPDB]

AuthorMaltego
Data SourceAbuseIPDB
Output Entitiesmaltego.DNSName

Variants

Transform NameInput EntitiesShort Description
abuseipdb.ipv4AddressToHostnamesmaltego.IPv4AddressThis Transform returns the host names seen on the given IPv4 Address
abuseipdb.ipv6AddressToHostnamesmaltego.IPv6AddressThis Transform returns the host names seen on the given IPv6 Address

To Country [AbuseIPDB]

Transform Settings

Display NameSetting TypeDefault ValueOptionalPopupAuthentication
API Keystringfalsetruetrue

Transform Meta Info

InformationValue

Display Name Owner

To Country [AbuseIPDB]

AuthorMaltego
Data SourceAbuseIPDB
Output Entitiesmaltego.Country

Variants

Transform NameInput EntitiesShort Description
abuseipdb.ipv4AddressToCountrymaltego.IPv4AddressThis Transform returns the AbuseIPDB report for the IPv4 address
abuseipdb.ipv6AddressToCountrymaltego.IPv6AddressThis Transform returns the AbuseIPDB report for the IPv6 address

Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.