resources/2s.io/GET /api/security/ioc-reputation
GET402 quotelive quote

https://2s.io/api/security/ioc-reputationGET /api/security/ioc-reputation · x402 API by 2s.io

Threat-intelligence reputation for an indicator of compromise (IOC) — pass ioc as an IP, domain, URL, or file hash (md5/sha1/sha256) and the type is auto-detected. Returns a malicious boolean plus a per-source breakdown: abuse.ch ThreatFox (IOC→malware/threat mapping), URLhaus (malicious URLs on a host/URL), MalwareBazaar (known malware samples by hash), Feodo Tracker (active botnet C2 IPs), Tor exit-node membership, and Spamhaus DROP (hijacked/criminal netblocks). Each source reports listed + a detail. Sourced from live, hourly-rotating threat feeds an LLM cannot know — a ground-truth liveness check for SOC alert triage, log enrichment, and blocklist decisions. Absence of a match is not proof of safety.

https://2s.io/api/security/ioc-reputation

What does this x402 API do?

https://2s.io/api/security/ioc-reputation. This is an x402-gated GET API resource from 2s.io. TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-07-21. No normalized USD price is recorded; the listing names Base and Solana. No settled paid call has been verified.

Published price
No normalized USD price is recorded
Networks
Base · Solana
Latest evidence
TOLL·402 confirmed a protocol-valid HTTP 402 quote on 2026-07-21
Resource ID
a612a460017e7a177273945c
USE THIS RESOURCE

Start with a quote-only recipe. Payment signing stays in your project.

CODE
AI CODING TOOLS
quote-check.ts
const response = await fetch("https://2s.io/api/security/ioc-reputation", {
  method: "GET",
});

console.log(response.status);
console.log(Object.fromEntries(response.headers));
console.log((await response.text()).slice(0, 1000));

// A valid 402 is a quote, not a completed paid call.

This sends no payment. Inspect the 402 response before adding a wallet-enabled client.

STATUS HISTORY

  1. Live 402 quote confirmed

    GET returned a protocol-valid 402 quote (402). No payment was made.

  2. Origin reachable

    HEAD https://2s.io/ returned 200.

  3. Observed in cdp-bazaar

    The registry record was observed and retained with provenance.

  4. Observed in 402-index

    Discovered through bazaar.

  5. Registry record checked

    Registry health: healthy.

What evidence supports this listing?

cdp-bazaarobserved 2026-07-10 · open source record ↗
402-indexobserved 2026-07-10 · open source record ↗
origin checkHEAD https://2s.io/ → 200 on 2026-07-21
route quotelive 402 quote confirmed · GET 402 · 2026-07-21

Each record has an exact-route quote outcome. Unresolved templates and potentially mutating methods are labeled instead of being invoked without provider-specific test input. A quote is still separate from a settled paid call. Read the discovery and verification methodology →

Which networks and payment options does it accept?

The normalized listing price is No normalized USD price is recorded. Raw protocol requirements remain visible below for implementation and audit use.

Baseexact2160 atomic · 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Solanaexact2160 atomic · EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
2s.io GET /api/security/ioc-reputation · a612a4 x402 API · TOLL·402