Developers

USAGE:
https://api.musubu.io/MusubuAPI/Musubu?IP={IP_ADDRESS}&key={API_KEY}&format={FORMAT}&level={LEVEL}
PARAMETERS
IP REQUIRED. The IPv4 address to investigate (in 4-octet dot notation).
key REQUIRED. Your API key string.
format Takes the values "TEXT" or "JSON".  Default is "JSON".
Note: the results will always be returned as JSON; this value sets HttpResponse type.  If set to JSON, some browsers (for instance, Internet Explorer) will download the result as a JSON file instead of displaying the results in your browser.
level Takes the values "terse" or "verbose". Default is "terse".
TERSE OUTPUT
ipaddress IPv4 address in 4-octet dot notation, from 0.0.0.0 to 255.255.255.255
threat_potential_score_pct Numeric threat score. Integer 0-100.
threat_classification Overall characterization of threat. String, with one of the following values:
High
Medium
Low
Nuisance
EXAMPLE TERSE OUTPUT:
{
 "ipaddress":"204.16.0.243",
 "threat_potential_score_pct":"82",
 "threat_classification":"High"
}
VERBOSE OUTPUT
ipaddress IPv4 address in 4-octet dot notation, from 0.0.0.0 to 255.255.255.255
ipintIPv4 address as 8 byte integer representation. Integer 0-4294967295.
threat_potential_score_pctNumeric threat score. Integer 0-100.
threat_classificationOverall characterization of threat. String, with one of the following values:
High
Medium
Low
Nuisance
blacklist_classString, with one of the following values:
apache
blacklisted
botnet
botnetcnc
bruteforce
compromised
ftp
http
imap
mail
malware
phishing
ransomware
shunned
sips
ssh
tor
worm
zeus
blacklist_class_cntCount of distinct sources which have identified the address as malicious. Integer.
blacklist_network_neighborsCount of addresses present on the same subnet which have been identified as malicious. Integer.
blacklist_observationsCount of observations in the last 90 days. Integer.
countryTwo character country designation based on ISO 3166-1 alpha-2. String.
stateprovState or province. String.
districtString.
cityString.
zipcodeString.
latitudeLatitude. Float.
longitudeLongitude. Float.
timezone_offsetTimezone offset in hours. Float.
timezone_nameString.
ispnameInternet Service Provider (ISP) or associated organization. String, alphanumeric and punctuation.
network_typeThe service classification for the associated network. String, with one of the following values:
ACADEMIA(universities, schools, labs, and institutes)
BROADBAND(residential and small business)
CDN(commercial, P2P, and free content delivery networks)
CLOUDHOSTING(cloud and web hosting environments)
ENTERTAINMENT(music, TV, video sharing, and gaming)
FILESHARING(commercial and free)
GOVERNMENT(federal, state & local, and foreign governments)
HEALTHCARE(commercial)
INTERNETAUTHORITIES(government, non-profit, and international authorities)
INTERNETSECURITY(commercial internet security firms)
SEARCHENGINE(commercial)
SOCIALNETWORKING(commercial social networking sites)
SOFTWAREDOWNLOADS(commercial and free)
CRYPTOCURRENCY
NODES(public and hidden TOR services)
COUNTRY
network_groupString.
network_nameString, alphanumeric plus punctuation.
EXAMPLE VERBOSE OUTPUT:
{
 "ipaddress":"204.16.0.243",
 "ipint":"3423600883",
 "threat_potential_score_pct":"82",
 "threat_classification":"High",
 "blacklist_class":"bruteforce",
 "blacklist_class_cnt":0,
 "blacklist_network_neighbors":1,
 "blacklist_observations":0,
 "country":"US",
 "stateprov":"Florida",
 "district":"Miami-Dade",
 "city":"Miami",
 "zipcode":"33132",
 "latitude":"25.77",
 "longitude":"-80.168",
 "timezone_offset":"-4.0",
 "timezone_name":"America/New_York",
 "ispname":"Braslink Network Inc",
 "network_type":"INTERNETAUTHORITIES",
 "network_group":"ALL",
 "network_name":"Internet Assigned Numbers Authority"
}