MalwareBazaar Database

You are browsing the malware sample database of MalwareBazaar. If you would like to contribute malware samples to the corpus, you can do so through either using the web upload or the API.


551

Submissions (past 24 hours)

Mirai

Most seen malware family (past 24 hours)

569'196

Malware samples in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • md5:1b109efade90ace7d953507adb1f1563 ( run)
  • sha256:11b16ba733f2f4f10ac58021eecaf5668551a73e2a1acfae99745c50bfccbb44 ( run)
  • signature:CobaltStrike ( run)
  • tag:TA505 ( run)
  • file_type:rtf ( run)
  • user:malware_traffic ( run)
  • clamav:SecuriteInfo.com.Artemis1FBB04F6EAF7.17086.UNOFFICIAL ( run)
  • yara:win_asyncrat_j1 ( run)
  • serial_number:51CD5393514F7ACE2B407C3DBFB09D8D ( run)
  • issuer_cn:Sectigo RSA Code Signing CA ( run)
  • imphash:756fdea446bc618b4804509775306c0d ( run)
  • tlsh:8DD484F440EF10A2F25F852936ADBE9401B2B1C7DBDA5E08137DE5311BBDA633A0564D ( run)
  • telfhash:52d0a7c198b4972c99e60578ed5c5bb29106216620070b20cf10a5d4d83b440f40db59 ( run)
  • gimphash:b43f35a8610180bcb184238555a0858a6c160a2d872566e7e9633221308b34fd ( run)
  • dhash_icon:f8dcbeffbffecee8 ( run)

Date (UTC)SHA256 hashTypeSignatureTagsReporterDL
2022-09-26 18:26897d0d6582a5feb51ad47a96fb4a37bfedf267f2a03d42fde5b288dcdcd28e54Executable exeGuLoaderexe GuLoader signed @GovCERT_CH
2022-09-26 09:28b52def88e2fc65a2ca17420fbdb79a044fa67d93f974c95fe815234e7f69cd75Executable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-09-23 01:33296d3276af7f064b6e29fd453f3273c4fbf7d47d5afa4a2ecb80b594467d85dfExecutable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-09-22 13:0003c0b10be2c560acd4c9772a9fb19c271ee143592ec316c580a3b4a6e433a219Executable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-09-21 18:1810a21f1899dd0e83ead2011c4638017bc4723a06be0c2058a9f3214da4974a8dExecutable exeFormbookexe FormBook signed @GovCERT_CH
2022-09-21 07:4203b2061c89af19fbf1683e4cc28f50505aa6b86208ab5d00d85a9b294a69b076Executable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-09-21 07:42af8cf9119e7ade358e08c2a28df607187db8490c860a6f84fc4b01e99957e53eExecutable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-09-21 07:397a1d7c9fb8a92a5aafdde76e611168b30b24bcf83f56d216b008b0c630f2d946Executable exeFormbookexe FedEx FormBook signed @abuse_ch
2022-09-21 06:1664838dfcbbe16affd2aefc5de3448644669df0a2a8d11065670b1a2f51f4da9cExecutable exeGuLoader32 exe GuLoader signed trojan @zbetcheckin
2022-09-21 05:07978d41eb58d330a1d7a400bfbfd6b5f1bac073ce5da85671942e80699919a871Executable exeGuLoader32 exe GuLoader trojan @zbetcheckin
2022-09-21 05:06958a7ace6ba6d811e001353ff6ca2fa0861b3c0eb6459ba5f1c3645e3ded5058Executable exeGuLoader32 exe GuLoader signed trojan @zbetcheckin
2022-09-21 04:47b1142e155bc97b08b5ba6d8997986c6c59d5a6d29428183f62f4c83fed07e3ffExecutable exeGuLoader32 exe GuLoader signed @zbetcheckin
2022-09-20 14:50466a8e22e7c7b6f48e4ad215d7366ef595748a37f4ce4a50449ecc89fbe16d2bExecutable exeGuLoader32 exe GuLoader signed trojan @zbetcheckin
2022-09-20 07:472f35e754d4ed60b61a7621e22710426b1d1ade21cd31cb4b2d71a88b2a53deccExecutable exeGuLoaderexe GuLoader signed @adrian__luca
2022-09-19 14:10d3a66173013a037b63d6ab4eb79916bb7e32cea117a3a12ed823f1f41ee69ce2Executable exeGuLoaderexe GuLoader signed @0x746f6d6669
2022-09-19 01:44d510754209735ed82b7e8606242cd6334945d9be346ea18c81d7c738c6229c27Executable exeGuLoaderexe GuLoader @SecuriteInfoCom
2022-09-17 17:03fbe01e695b2a6b560da2025bc32a0269b9a4b97417ae6982e99c35cd14352ff9Executable exeFormbookexe FormBook signed @TeamDreier
2022-09-14 13:2552d92e235f3ed9e01c52fbdc5694e99085e050105362881f6d552768b44506c0Executable exeGuLoaderDHL exe GuLoader signed @abuse_ch
2022-09-14 02:22cbbf5f08eb9fd0467576bf23b709d414ce9e7061b028c29ce08f179af6e60a97Executable exeGuLoaderexe GuLoader signed @GovCERT_CH
2022-09-13 20:01a49e28d3786ee9a8094272c550a96d72b84c4fbf33705bca506e5c405fd3259aExecutable exeFormbookexe FormBook signed @TeamDreier
2022-09-13 13:033a364b193d256ee86f9c7dc66ca6322f64ffacda0685e98d9909ad90a595831bExecutable exeGuLoaderAgentTesla exe GuLoader signed @malwarelabnet
2022-09-13 10:07ab1f192fb8f916dcd581face8064290632cc84049382de572156f4538cdec085Executable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-09-13 06:25fac68be8d34387e18062a7bc14ce9c070022c9cb3ff9ce8cc6cd58c18c00764dExecutable exeGuLoaderexe FedEx GuLoader signed @abuse_ch
2022-09-12 12:4853cd75c785b440cbc32ded5c23144e59ec2d910618f3733dff686cefb699310cExecutable exeGuLoaderexe GuLoader signed @pr0xylife
2022-09-12 06:526ab1444d305f5a3ffafd05cadd42ac71f058ad19257f67b0210d847848b8a06eExecutable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-09-12 03:54153fb690a1f464ba3a1c37d1d8d103010a54a00bd10eb86ead709e275dc5d302Executable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-09-07 13:375b1569630a8d68e7d915be129f136ec83f52d9fd3428fedac5cb4627ff298e42Executable exeGuLoaderexe GuLoader signed @adrian__luca
2022-09-02 15:13c4f21c30390102bb2cfb96fb355c99641b457850f97ad136d1fa021429164ac7Executable exeGuLoaderexe GuLoader signed @malwarelabnet
2022-09-02 05:3189599ae785aa5f919018882cd10534cbae8ac89047ebbeda0b232d52fa545944Executable exe 32 exe signed trojan @zbetcheckin
2022-09-02 04:358e48488f65614bf7356e44697013c3dcee57463f91e04c225070439c555e6cd9Executable exeLokiexe Loki signed @SecuriteInfoCom
2022-09-02 02:342c343836c7e44fa32816621f6903399cade80b4bebc2253ff9a6bb25bdb88106Executable exeLokiexe Loki signed @SecuriteInfoCom
2022-09-02 01:34e13ba108870feac2d8623df98a72971e8c3b0f4954a06f0fe79ca3ebd33d4763Executable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-09-01 12:08d9944c8cc5404e0d4a3323ef088db3a94c42bd4e077d59ab2a9a4e1a0b366743Executable exe exe signed @JAMESWT_MHT
2022-08-31 09:46ffcce35d4896562beaf95b7bb73d14d421f1e41be4e6031d671fa10f37a33603Executable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-08-31 05:31ae82bc9492d5d94d7d5e28db012676037f48a716aba72304055f54158013aedcExecutable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-08-30 06:409f47ed5d4825d6cf54c46856454b381f0a594dfdaa5027af5dc8379df03bcaa8Executable exeGuLoaderexe GuLoader signed @lowmal3
2022-08-29 10:21d827e104b371b3007b170c02cd72ac018eeac21b99304efb3042ab79928133adExecutable exeGuLoaderexe GuLoader signed @JAMESWT_MHT
2022-08-29 10:2039f7c1971006cb42f261299ef2a05ed79573b96aab9cfcfed213abad2e0eb8d7Executable exeGuLoaderexe GuLoader signed @abuse_ch
2022-08-29 09:3190903410062ac828233bd91ed1adb4781ba522a6131b19330bcd8ef7c791672bExecutable exeGuLoaderexe GuLoader signed @TeamDreier
2022-08-29 06:478363d74b6b26b441bb493232b67b36b67a582b0cfa568da08a278bcfdef317a9Executable exeLokiexe Loki signed @SecuriteInfoCom
2022-08-29 02:37ef98f88e2af062e52962b309ec92736c485ce509e6319271cdde46e030455b5bExecutable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-08-25 10:354717101ad9b433dbae626233b2d92e0ff37b921ec0fe34e97ce9469faca85658Executable exeGuLoaderexe GuLoader signed @lowmal3
2022-08-22 08:34fe00f0b94120e6994117bf92c39940b5a499821e3684163cae07a8fb0ea1c5f1Executable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-08-22 08:3478fc852976d4f8e68360f4bd282b78abb21f7aa02b52cf885203b43d0838c5efExecutable exeGuLoaderexe GuLoader signed @SecuriteInfoCom
2022-08-12 05:34f93da7562182b8456d6c88c58d90c745004aaef0979a2a98a06341b219bfe03eExecutable exeGuLoaderexe GuLoader signed @lowmal3
2022-08-09 06:171d3e8941eb686b154fca77b2c80b84a19fdf21ebd298dc55d4519310ed011addExecutable exeGuLoaderexe GuLoader signed @TeamDreier
2022-08-08 11:206730e52c8075c7e044c2bbaf9f7ad8c0f7f8d03fb23adbd2331adc8b591caec7Executable exeGuLoaderexe GuLoader signed @GovCERT_CH
2022-08-06 07:4057db1a9611191d01fbe260f052e87a6fb0cf7dbb1644079727627252ee3e109aExecutable exeGuLoaderDHL exe GuLoader signed @abuse_ch
2022-04-14 17:014d4d221fa98163aa9b8be6b342188405f191427ffeb8da3d262f6e2c7e3db9b6Executable exeRemcosRATexe remcos RemcosRAT @adm1n_usa32
2021-12-24 01:518963139d8eeaf07185aba34c8a1abccfedd92e271c8ee30e6bf603d144349a9bExecutable exe 32 exe @zbetcheckin
2021-08-19 13:3247d9aeb26536b9d9c74b69c0e7510cbdb6c3858e953711db573a5ff9112214cbExecutable exe exe Anonymous
2021-06-24 12:132aa855e58f1d16de00731cb9406d658533187046015073f293265f85ce07ba45Executable exe 32 exe @zbetcheckin
2021-06-24 08:16c829830d55396b4d79630c268cc875bc59c950daac4ee0476560a2edc3f8f87aExecutable exe 32 exe @zbetcheckin
2021-06-24 01:4707dd788eaf264a645dce4b24536deda60690bba09125d2c9babc7ec786734344Executable exe 32 exe @zbetcheckin
2021-01-05 22:24cf77727aa2cfcd3d6dd85cb492ddee28ff9191def60a9e00ea08ccddf817d143Executable exe ElectroRAT exe @ArkbirdDevil
2021-01-05 22:23a32ef780ba235f8222c05302f7537b4123c41b048449c6ec8744d64103d428a3Executable exe ElectroRAT exe @ArkbirdDevil
2020-11-17 15:34db2436d70a1c9323f0839ae2bc9ac41137bf7a0fc806098ae4cca009beb8e4b0Executable exe @Seifreed
2020-04-30 07:33b076cbf14c6f0a9bbb4aaaf8242622cefb6bccdf2aef9e130b48a0552bb5016fExecutable exeLokiLoki @jarumlus
2020-04-30 07:320c29fcb16f0bc0a524c29586c44d794ee69324968d58eb42dde0c184754d96ecExecutable exeLokiLoki @jarumlus
2020-04-30 07:324b1e07f367e2c29e90cad5cd928dc1572dbcedfb04cd722fba01c67a7d349361Executable exeLokiLoki @jarumlus
2020-03-23 18:484d056b87049ec7fce672b40190bf8b5f9185395b7313d05bc196a655e7fe0c7aExecutable exeRaccoonStealerexe RaccoonStealer @Marco_Ramilli