Criminal IP Malicious Link Detector, developed by AI Spera, is a threat intelligence platform that aggregates data on malicious and masked IP addresses, including historical abuse records such as IDS hits, malware, phishing, ransomware, and blocked IPs. The dataset encompasses detection of botnet and command-and-control infected servers, as well as identification of IPs utilizing VPNs, proxies, and hosting services. The platform supports fraud detection, malicious IP filtering, attack surface management, abnormal user detection, phishing detection, and tracking of hacking group activity. Data is delivered through a subscription model with daily updates and includes a complimentary trial of up to 1,000 data items via the Snowflake Marketplace.
The platform integrates with Palo Alto Networks Cortex XSOAR, enabling automated analysis of IP and domain indicators within security playbooks. Integration features include multi-stage domain scanning (Quick, Lite, Full), automatic multi-dimensional IP analysis encompassing IDS rule hits, WHOIS data, associated domains, port and CVE information, and generation of reports and attack surface assessments via the Micro-ASM playbook. Additionally, Criminal IP Malicious Link Detector functions as an Outlook add-in that analyzes URLs in incoming emails in real time, scanning each link to identify phishing sites and malicious URLs and presenting scanned URL lists, result summaries, and detailed domain information including scoring, abuse records, and hidden HTML elements. The add-in requires a Criminal IP account and performs automatic email scanning upon login, displaying the number of scanned URLs, detected threats, and domain details within the Outlook interface.