Skip to content

Threat feed

Phishing Database: URLs

Last fetched

Phishing · refreshed hourly · last verified

Phishing Database: URLs is a Phishing threat-intelligence feed, refreshed hourly, indexed by WhisperGraph.

What is Phishing Database: URLs

Phishing Database: URLs is the full-URL export from the same Phishing.Database project, providing path-level detail beyond the domain- and IP-level exports also indexed here. The URL-level granularity matters most for phishing kits hosted on compromised legitimate sites or free web-hosting platforms, where blocking the whole domain would over-block unrelated, legitimate content on the same host. It shares the project's high-frequency update cadence and multi-source aggregation methodology. It is indexed here as the most granular export of one of the most widely re-used open phishing aggregators.

Refresh cadence
hourly

Category drift. The curated category for this feed is Phishing, while WhisperGraph currently files it under phishing.

Indicators currently listed

Indicators currently listed is temporarily unavailable.

The graph did not answer within the page budget. Refresh in a moment to retry — fresh data is fetched on the next visit.

Related pages

Pivot from Phishing Database: URLs into the indicators it lists.

Queries

Resolves the feed's categories.


MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categories
Run yourself →

The indicator-kind rollup and sample listed above.


MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESC
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.