Authenticate for API access | If you are experiencing issues with receiving data from abuse.ch platforms via API, please ensure your requests are authenticated.
➡️ Read here for more info

Statistics

MalwareBazaar produces detailed statistics on shared malware samples, including associated detections - find the available statistics below.

You can also access Spamhaus's Malware Digest report, based on MalwareBazaar data:

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1 abuse_ch2025-11-023'249
2 JAMESWT_WT2025-11-02699
3 lowmal32025-10-31187
4 cocaman2025-11-02155
5 aachum2025-11-02146
6 smica832025-11-02145
7 SecuriteInfoCom2025-11-02143
8 burger2025-10-30141
9 juroots2025-11-01118
10 Bitsight2025-11-0297
11 mohit2025-10-3190
12 01Xyris2025-10-2652
13 threatcat_ch2025-10-3150
14 FXOLabs2025-11-0240
15 James_inthe_box2025-10-3133

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
1'691unixredflags3Tim Brown @timb_machine2025-11-02
1'358linux_generic_ipv6_catcher@_lubiedo2025-11-02
1'275Sus_CMD_Powershell_UsageXiAnzheng2025-11-02
1'035CP_Script_Inject_DetectorDiegoAnalytics2025-11-02
824ELF_MiraiNDA0E2025-11-02
805golang_bin_JCorn_CSC846Justin Cornwell2025-11-02
765Linux_Trojan_Gafgyt_28a2fe0cElastic Security2025-11-02
741DebuggerCheck__APINone2025-11-02
666NETmalware-lu2025-11-02
658DetectEncryptedVariantsZinyth2025-11-02
522pe_detect_tls_callbacksNone2025-11-02
486Skystars_Malware_ImphashSkystars LightDefender2025-11-02
486pe_imphashNone2025-11-02
461Linux_Trojan_Gafgyt_ea92cca8Elastic Security2025-11-02
459botnet_YakuzaNDA0E2025-11-02

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
3'083fa22249ff51657484072c83e53e154212f12d7659a44feb49e16982dd4ebf552Executable exeQuasarRAT 01Xyris
2'716f395c932fc71ab8c2145984283490d55f895c2f47cef98a63c50cdaa8260c52dExecutable exe  Sigma12329838
417a44f4bb4f077dd6ef056d8d460c29218534fb1cfa6a3ec6e2468cc3f18061cd3Executable exeAgentTesla abuse_ch
217dbdab701feecc382b037b61b4268f1f796c28f3c30d77e18506cb1646bf9cb0bExecutable exe  GDHJDSYDH1
2159dd12ff611668b5ccf5807c5fac04185988be087c65027451c61101c9aae95e6Executable exeVidar abuse_ch
21057aebadf554e03a405a30d8ddad8caa8cfe9fa86eb32f672066dcf63691481caExecutable exeRustyStealer cocaman
206b8f225189e10b6eba893191bda9b633b5ae42302aa74323c51373c8069c381faExecutable exeGuLoader threatcat_ch
20076655dbbcd2bbe9d4372270257ce2f9349fb7a2ed3f2821119f9584b544bbe81Executable exeVidar Bitsight
200be127489937f1f8730ef6d8f24f526e58d27d6673b61a66911b4988ccb6f84deExecutable exeRedLineStealer threatcat_ch
19847929177ca687f37d0a34d43078b6bcc379813af5c99fc0b09e50488519ba092Executable exeVidar Bitsight
196e7e43cba43e64e576650033a0e60080d6d2b6ba01d1777597188d4285f0a3ef3Executable exeGuLoader threatcat_ch
194f5ec65b652a9b9d969996f05819eb6df32bbfcba437465e229fdbbdad6ac621fDLL dll  Bitsight
191809b67ff6e9e4623014772f056f0bc300749e019ebcd5c661d7939e59c4847bcExecutable exeGuLoader pr0xylife
18753d52508d4fbf502264ff4e8482ff3c988f86f4727326d09a71724b61a152e92Executable exenjrat abuse_ch
186b6604865391a19e802488001817e0e6b22b6504aa656b784275da15c20468f8dExecutable exeLummaStealer SecuriteInfoCom

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

CyberFortress CyberFortress


Top classifications by CyberFortress for malware samples on MalwareBazaar.

ThreatZone ThreatZone


Top classifications by ThreatZone for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
360f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger RedLineStealer
654cea7ae85c87ddc7295d39ff9cda31d1RedLineStealer LummaStealer Rhadamanthys Smoke Loader
62d42595b695fc008ef2c56aabd8efd68eRhadamanthys Vidar LummaStealer CobaltStrike
4412e12319f1029ec4f8fcbed7e82df162DCRat RedLineStealer Formbook SnakeKeylogger
421895460fffad9475fda0c84755ecfee1Formbook AgentTesla SnakeKeylogger a310Logger
412eabe9054cad5152567f0699947a2c5bLummaStealer Stealc Healer Amadey
22f8e4a22bcb1b836585534b93f63c1414GoToResolve
22a56f115ee5ef2625bd949acaeec66b76PureHVNC Stealc RedLineStealer CoinMiner
18dcaf48c1f10b0efa0a4472200f3850edBlankGrabber PythonStealer SalatStealer RedTigerStealer
150951d9f67c9a9e1b6ea746ed01bccc26Rhadamanthys AmateraStealer

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
3393216:sIGdBtIDiCqWtLxXBi1/62Ocwf2o0b8MANHjLiB/ekS/mdVhReXpV:q9WtLzgOTbjZvk/ekS/mcpVGoToResolve
349152:MR5CbBq56hIF1XrwzMtmEMQh2Uc0RL6lxSDfsWBxTh28h/kY:WEThIF1XrwzMtm
21536:WAp5eznKUlIOp3YjVCguHEvQEbFqVC3woFRKpT4XP:d5eznsjsguGDFqG/njrat
21536:gfHlPDdJaEcLAeF9TUDWog1HHH8Q0QkiuVn4P:yHlPZMEcTFZ2A1HHHP0hVn4PMirai
23072:+cZqf7D34qp/0+mAQkygQAQEgTLB1fA0PuTVAtkxzf3RQeqiOL2bBOA:+cZqf7DIqnyzjB1fA0GTV8kdwLRedLineStealer
2393216:sIGdBtIDiCqWtLxXBi1/62Ocwf2o0b8MANHjLiB/ekS/mdVhReXpc:q9WtLzgOTbjZvk/ekS/mcpcGoToResolve
21536:6nJRT4QPfZfW5XTOeY3Dve3AGAZq/4Qw7bn2iPe:Gv4QPfZfW5XTOeoEz0qAQwf2iMirai
2768:3SjbGSLlRrYj0a8C/dQOhPC/+I20Ja6ZZ+GwPS4yns96BktDgIPi8Tw1:ivW3jdQGqt7Y+Z+zN9cGgI6b1Mirai
21536:WNWiFOX1g040LIZYijOzI/+0+aRW3umSeHy/EZsS4QUCS5ALuBd:Aea040MJjJW0hRW39SwqgtXLuBdMirai
2768:3SjbGSLlRrYj0a8C/dQOhPC/+I20Ja6ZZ+GwPS4yns96BktDgIPi8Twn:ivW3jdQGqt7Y+Z+zN9cGgI6bnMirai

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 12 months.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1 abuse_ch2025-11-02274'866
2 zbetcheckin2024-11-0978'688
3 lazyactivist1922024-01-1769'729
4 Cryptolaemus12024-03-2067'837
5 seifreed2021-10-1948'947
6 JAMESWT_WT2025-11-0247'770
7 SecuriteInfoCom2025-11-0241'229
8 andretavare52024-01-1835'831
9 cocaman2025-11-0232'152
10 Libranalysis2024-01-1717'035
11 adrian__luca2025-10-2815'683
12 GovCERT_CH2024-10-1815'559
13 lowmal32025-10-3115'123
14 Bitsight2025-11-0210'394
15 James_inthe_box2025-10-3110'357

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
131'336Skystars_Malware_ImphashSkystars LightDefender2025-11-02
94'561pe_imphashNone2025-11-02
82'700unixredflags3Tim Brown @timb_machine2025-11-02
80'010linux_generic_ipv6_catcher@_lubiedo2025-11-02
78'522SharedStringsKatie Kleemola2025-10-23
76'712Email_stealer_bin_memJames_inthe_box2024-06-13
74'506Select_from_enumerationJames_inthe_box2025-07-30
73'333UAC_bypass_bin_memJames_inthe_box2023-03-07
72'592Sus_Obf_Enc_Spoof_Hide_PEXiAnzheng2025-11-01
71'651IPPort_combo_memJames_inthe_box2025-03-26
60'193NETmalware-lu2025-11-02
57'586DebuggerCheck__APINone2025-11-02
51'182pe_imphash2025-11-02
45'508Cobalt_functions@j0sm12023-08-23
31'955pdb_YARAify@wowabiy3142025-08-19

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
72'09470ab26000929d26e0e4e567bd0dc4158054538485fcfd51dd4b60a534967814b lzhFirebirdRAT GovCERT_CH
52'969c88a22dae5d5564a33736d8cd43835eb46153bafe47fc6e8c267c3b89d4abf04 zip  l205306
42'34659494a51618f234021c0dae2d87667ce9e431b8a75a1b4952d3e48bf71492fbbExecutable exeAgentTesla cocaman
40'693c24ff50a15372a69690f4c7cd783609e92924ec38f2f42148573d35980f07cd3Executable exeLummaStealer abuse_ch
40'663b828382168a0077c7d5cd8faf44d5da19a4d852cfca7c85dae63de97e5dd6753Executable exeLummaStealer abuse_ch
32'6799fd06d80534b729cca8ad2affa0be6b3108c6a117e7b20f81470b2c01335453b elfMirai abuse_ch
32'5701509cb4a59087be095de34a01f19e292933a3133bc63de252555d0188d0710bd elf  abuse_ch
32'5702ee2eaa1fce89b91fb70dd2e853ac63b600c11feae4a1624fa90f1c6e33bc67c elfMirai abuse_ch
32'559a0f145290eaa8b3b74d83702f391952617262388779aa607dbaac524b4567266 elfMirai abuse_ch
32'543216ab12c56bba575bd40aaa5d602c062abb5fc8ac405f27a43619c3370d11707 elf  abuse_ch
30'787cdff50f4126445f55098d307fa40396a80396cc50d4d94c0c8a849b4de2b7da2Executable exeLummaStealer abuse_ch
30'491eb097b81a3a0a5510aec27b28fd7a140152eb217520fca3dd92f27a72d817045 elfMirai abuse_ch
30'454515eb18d3f105eb377e73dfa2ee34a24f50da54f0600d02d7914d41c916f3848 elfMirai abuse_ch
24'753b97e12807dcde2a8fd53d7f8e74336442d0cf8dbed19c0a44fcef359160bdd77PowerPoint file pptx  Neiki
24'7204e09c7b070043bd5bf50b7b2038dd170b491128eb28f5fdf61d9a07e831ece3cPowerPoint file pptx  cocaman

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

CyberFortress CyberFortress


Top classifications by CyberFortress for malware samples on MalwareBazaar.

ThreatZone ThreatZone


Top classifications by ThreatZone for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
152'057f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger RedLineStealer
14'754646167cce332c1c252cdcb1839e0cf48RedLineStealer Amadey Smoke Loader LummaStealer
9'777c9f7e018b269f1b5fe81cf757d6f8e93Heodo
8'6652eabe9054cad5152567f0699947a2c5bLummaStealer Stealc Healer Amadey
8'608987b9d7dc84d935c3675da82d40e06f2Dridex Gozi Tofsee VelvetSweatshopDridex
7'830884310b1928934402ea6fec1dbd3cf5eGCleaner Socks5Systemz RaccoonStealer RedLineStealer
4'377afcdf79be1557326c854b6e20cb900a7FormBook AgentTesla RemcosRAT RedLineStealer
3'62487bed5a7cba00c7e1f4015f1bdae2183Jadtre IcedID Blackmoon TrickBot
3'30461259b55b8912888e90f516ca08dc514Formbook AgentTesla GuLoader SnakeKeylogger
3'107948cc502fe9226992dce9417f952fce3CredentialFlusher Formbook AgentTesla RedLineStealer

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
1'12412288:J2+J+l5QvSoOUkQNPRoswLLjfsHJNF05s:AJl5QrrkQFCHspN4Quakbot
1'12312288:U2+J+l5QvSoOUkQGPRoswLLjfsHJNF05F:PJl5QrrkQOCHspN4Quakbot
1'12112288:l2+J+l5QvSoOUkQiPRoswLLjfsHJNF05h:8Jl5QrrkQaCHspN4Quakbot
5281536:1I+Hymsbck3hbdlylKsgqopeJBWhZFGkE+cMLxAAISQ5gQ72IotO6nitSU6U+x:1I+HymsYk3hbdlylKsgqopeJBWhZFGkzSilentBuilder Heodo
52612288:iD6LPBCvMk0O9na1M80cLt9i5aIaTtpc4W:2+QGO9naz0Szi5anTtRMirai
4191536:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIzSEV2NnX4Ia3gg5W8IuD7PoHsP7e3/:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxzSilentBuilder Heodo
416768:0Jlk3hbdlylKsgqopeJBWhZFGkE+cMLxAAIZEtm/piJaiyH5YnJe+eO+8WoFYpLd:0rk3hbdlylKsgqopeJBWhZFGkE+cMLx6SilentBuilder Heodo
41012288:0GCt9AoZDmbOxeQPTyDez9kQ8jGMKhmmMnRpOeHc:Y9tZQO92DnhDmc
40812288:NbX5mTA3bZNKiG01B7crv+SF7GW5a65jx:tX5m83bZNKi3B7AZXaGafgyt
40112288:5D+Azf/CVCW3ISw+hRNb3W/aTyA9VV/cZWLnR98V+:5D+AznCVNIZ+vNbG/WYWrR98V

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
15'390f8f0f4c8c8c8d8f08'803 x RedLineStealer, 5'078 x Amadey, 288 x Smoke Loader
6'664aae2f3e38383b6292'034 x Formbook, 1'183 x CredentialFlusher, 666 x AgentTesla
5'757b2a89c96a2cada722'283 x Formbook, 981 x Loki, 803 x AgentTesla
4'862b298acbab2ca7a722'327 x GCleaner, 1'631 x Socks5Systemz, 67 x RedLineStealer
3'90071b119dcce5763333'570 x Heodo, 203 x TrickBot, 19 x Gh0stRAT
3'3730000000000000000872 x AgentTesla, 496 x Formbook, 296 x RedLineStealer
2'708848c5454baf474742'088 x Adware.Neoreklami, 101 x RedLineStealer, 33 x DiamondFox
2'3329494b494d4aeaeac832 x DCRat, 172 x RedLineStealer, 134 x CryptOne
1'172399998ecd4d46c0e572 x Quakbot, 137 x ArkeiStealer, 82 x GCleaner
1'150fefce49e86c0fcfe884 x Socks5Systemz, 259 x RaccoonStealer