Closed ryanalexander closed 1 year ago
What about checking domains via the API of URLhaus? Unlike Virustotal, their API is not limited to 500 Requests per day and they offer downloads for their Lists which means they could be cached incase their API ever goes down.
Discord does have a list of phishing domains (hashed with SHA256) While they are obviously tailored to Discord, it could at least stop a few Steam scams etc.
https://api.syrus.gg/workers/safelink?site=
Can use that, it will catch all steam scam links
Closing due to rewrite, marking as potential issue in future by linking to https://github.com/revoltchat/frontend/issues/134.
Check against a list like virustotal.com to check for a malicious domain.
These domains should show a red warning under the embed saying the link could be dangerous