Statistics
MalwareBazaar produces detailed statistics on shared malware samples, including associated detections - find the available statistics below.
You can also access Spamhaus's Malware Digest report, based on MalwareBazaar data:
Malware sample shared
The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 30 days.
Top Reporters
It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.
Rank | Reporter | Last activity | Submissions |
---|---|---|---|
1 | abuse_ch | 2024-11-21 | 2'487 |
2 | Bitsight | 2024-11-21 | 1'156 |
3 | JAMESWT_MHT | 2024-11-20 | 889 |
4 | NDA0E | 2024-11-21 | 334 |
5 | adrian__luca | 2024-11-18 | 196 |
6 | lowmal3 | 2024-11-20 | 189 |
7 | zbetcheckin | 2024-11-09 | 97 |
8 | threatcat_ch | 2024-11-20 | 97 |
9 | SecuriteInfoCom | 2024-11-09 | 74 |
10 | cocaman | 2024-11-18 | 59 |
11 | aachum | 2024-11-17 | 55 |
12 | Porcupine | 2024-11-21 | 47 |
13 | elfdigest | 2024-11-20 | 40 |
14 | smica83 | 2024-11-20 | 34 |
15 | Chainskilabs | 2024-11-17 | 28 |
Top Malware Families
Top Tags
Most matching YARA rules
YARA rules that matched most on malware samples in MalwareBazaar.
Malware Samples | YARA rule | Author | Last match |
---|---|---|---|
1'003 | unixredflags3 | Tim Brown @timb_machine | 2024-11-20 |
985 | DebuggerCheck__API | None | 2024-11-21 |
977 | NET | malware-lu | 2024-11-21 |
832 | linux_generic_ipv6_catcher | @_lubiedo | 2024-11-21 |
739 | vmdetect | nex | 2024-11-21 |
730 | pe_imphash | None | 2024-11-21 |
730 | Skystars_Malware_Imphash | Skystars LightDefender | 2024-11-21 |
700 | RANSOMWARE | ToroGuitar | 2024-11-21 |
610 | Sus_Obf_Enc_Spoof_Hide_PE | XiAnzheng | 2024-11-21 |
556 | pe_detect_tls_callbacks | None | 2024-11-21 |
552 | DebuggerCheck__QueryInfo | None | 2024-11-21 |
550 | NETexecutableMicrosoft | malware-lu | 2024-11-21 |
539 | MD5_Constants | phoul (@phoul) | 2024-11-21 |
489 | RansomPyShield_Antiransomware | XiAnzheng | 2024-11-21 |
441 | RIPEMD160_Constants | phoul (@phoul) | 2024-11-21 |
Most downloaded Malware Samples
Most downloaded malware samples on MalwareBazaar.
ANY.RUN
Top detections by ANY.RUN for malware samples on MalwareBazaar.
ClamAV
Top detections by ClamAV for malware samples on MalwareBazaar.
Intezer
Top detections by Intezer for malware samples on MalwareBazaar.
Joe Sandbox
Top detections by Joe Sandbox for malware samples on MalwareBazaar.
CERT.PL MWDB
Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.
ReversingLabs
Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.
Threatray
Top detections by Threatray for malware samples on MalwareBazaar.
Triage
Top detections by Triage for malware samples on MalwareBazaar.
UnpacMe
Top detections by UnpacMe for malware samples on MalwareBazaar.
VMRay
Top detections by VMRay for malware samples on MalwareBazaar.
FileScan.IO
Top classifications by FileScan.IO for malware samples on MalwareBazaar.
CyberFortress
Top classifications by CyberFortress for malware samples on MalwareBazaar.
ThreatZone
Top classifications by ThreatZone for malware samples on MalwareBazaar.
Top File Types
Most seen file types
associated with malware samples on MalwareBazaar.
Top imphashes
Most seen imphashes on MalwareBazaar.
Top ssdeep hashes
Most seen ssdeep hashes on MalwareBazaar.
Malware Sample | ssdeep | Signature(s) |
---|---|---|
5 | 98304:jWs6efPY+bzk5yVWOY0DGICCQO5t0DoF:6fefPjzMOWOY3CQO5tU | ConnectWise |
4 | 768:Oa2vU7eng2qGJert7LrLMU6fgatQh+YbT/9+m3CZQoV/bnmCozw:Oa4U7G7SvT6ftBTm3KVrmCo8 | Mirai |
3 | 98304:LWs6efPY+bzk5yVWOY0DGICCQO5t0DoF:SfefPjzMOWOY3CQO5tU | ConnectWise |
2 | 12288:00Bw2wHeeJgR3asIAksAi0uObzkzOgFr1qwRcFjV1D7a9KbsaKjpeFmz4T28bLvl:00BnRED/TwOjX0a5xTdvl | |
2 | 12:7XOTtvmZPuXOpqXYcGFyZow4+2bgEiJbmVLHeuET3VLHeuNK/VLHeu3:Twv53GFyZou2Rb+BZ+gA+M | Mirai |
2 | 6144:zGOdIWe48wn1obslh391UmaFyjDZSbGqJA:zGOdRn1obsl5XURQFSQ | ShipUp |
2 | 49152:F+1Ypn4N2MGVv1zyIBWGppT9jnMHRjOOozjcqZJN8dUZTwYaH7oqPxMbY+K/tzQz:F+lUlz9FKbsodq0YaH7ZPxMb8tT | AteraAgent EternalRocks |
2 | 12288:8zBB2EzqBTMudgkVJnQb7WvpQOSSQNx6qZ5:aB2EzqBIudgkTQb7Wu58i5 | RemcosRAT |
2 | 49152:U+1Ypn4N2MGVv1zyIBWGppT9jnMHRjOOozjcqZJN8dUZTwYaH7oqPxMbY+K/tzQz:U+lUlz9FKbsodq0YaH7ZPxMb8tT | AteraAgent EternalRocks |
2 | 6144:O7HI/0S6GcV6yabg0OLe//fRD/uzc+8fJpgY08g:gH6b6GcV6wq/fJ/rDfJpgYE | Simda |
Top dhash icon
Most seen dhashes of icons from PE32 executables and their signatures.
Malware Sample | dhash icon | Signature(s) |
---|---|---|
201 | aae2f3e38383b629 | 89 x CredentialFlusher, 68 x Formbook, 11 x RedLineStealer |
71 | b150b26869b2d471 | 41 x Formbook, 9 x AgentTesla, 5 x RedLineStealer |
60 | b67ee8c2f2f0711a | 60 x ShipUp |
35 | 0000000000000000 | 9 x Formbook, 5 x SnakeKeylogger, 5 x AgentTesla |
14 | c4d48eaa8ad4d4f8 | 14 x RemcosRAT |
13 | 334b0b0f271b6b23 | 3 x PureCrypter, 3 x GuLoader, 2 x RemcosRAT |
12 | b298acbab2ca7a72 | 4 x Socks5Systemz, 1 x LummaStealer, 1 x AsyncRAT |
12 | 9494b494d4aeaeac | 5 x DCRat, 1 x BlankGrabber, 1 x Formbook |
11 | 13607332330b0bb3 | 7 x MassLogger, 2 x AgentTesla, 1 x RedLineStealer |
11 | 1a6a6ad59b43c674 | 3 x SnakeKeylogger, 2 x Formbook, 1 x MassLogger |
Malware sample shared
The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 12 months.
Top Reporters
It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.
Rank | Reporter | Last activity | Submissions |
---|---|---|---|
1 | abuse_ch | 2024-11-21 | 182'090 |
2 | zbetcheckin | 2024-11-09 | 78'688 |
3 | lazyactivist192 | 2024-01-17 | 69'729 |
4 | Cryptolaemus1 | 2024-03-20 | 67'837 |
5 | seifreed | 2021-10-19 | 48'947 |
6 | SecuriteInfoCom | 2024-11-09 | 36'997 |
7 | andretavare5 | 2024-01-18 | 35'831 |
8 | cocaman | 2024-11-18 | 28'805 |
9 | JAMESWT_MHT | 2023-04-29 | 26'183 |
10 | Libranalysis | 2024-01-17 | 17'035 |
11 | GovCERT_CH | 2024-10-18 | 15'559 |
12 | lowmal3 | 2024-11-20 | 12'887 |
13 | James_inthe_box | 2024-11-08 | 9'538 |
14 | adrian__luca | 2024-11-18 | 8'569 |
15 | JAMESWT_MHT | 2024-11-20 | 8'148 |
Top Malware Families
Top Tags
Most matching YARA rules
YARA rules that matched most on malware samples in MalwareBazaar.
Malware Samples | YARA rule | Author | Last match |
---|---|---|---|
103'906 | Skystars_Malware_Imphash | Skystars LightDefender | 2024-11-21 |
78'487 | SharedStrings | Katie Kleemola | 2024-11-20 |
76'713 | Email_stealer_bin_mem | James_inthe_box | 2024-08-20 |
74'506 | Select_from_enumeration | James_inthe_box | 2024-08-20 |
73'333 | UAC_bypass_bin_mem | James_inthe_box | 2023-03-07 |
71'652 | IPPort_combo_mem | James_inthe_box | 2024-10-20 |
66'734 | pe_imphash | None | 2024-11-21 |
51'184 | pe_imphash | 2024-11-21 | |
45'549 | Cobalt_functions | @j0sm1 | 2024-10-19 |
36'029 | unixredflags3 | Tim Brown @timb_machine | 2024-11-20 |
34'462 | linux_generic_ipv6_catcher | @_lubiedo | 2024-11-21 |
29'571 | MALWARE_Win_DLLLoader | ditekSHen | 2024-07-25 |
29'038 | NET | malware-lu | 2024-11-21 |
28'713 | pdb_YARAify | @wowabiy314 | 2024-10-13 |
28'424 | DridexV4 | kevoreilly | 2024-11-15 |
Most downloaded Malware Samples
Most downloaded malware samples on MalwareBazaar.
ANY.RUN
Top detections by ANY.RUN for malware samples on MalwareBazaar.
ClamAV
Top detections by ClamAV for malware samples on MalwareBazaar.
Intezer
Top detections by Intezer for malware samples on MalwareBazaar.
Joe Sandbox
Top detections by Joe Sandbox for malware samples on MalwareBazaar.
CERT.PL MWDB
Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.
ReversingLabs
Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.
Threatray
Top detections by Threatray for malware samples on MalwareBazaar.
Triage
Top detections by Triage for malware samples on MalwareBazaar.
UnpacMe
Top detections by UnpacMe for malware samples on MalwareBazaar.
VMRay
Top detections by VMRay for malware samples on MalwareBazaar.
FileScan.IO
Top classifications by FileScan.IO for malware samples on MalwareBazaar.
CyberFortress
Top classifications by CyberFortress for malware samples on MalwareBazaar.
ThreatZone
Top classifications by ThreatZone for malware samples on MalwareBazaar.
Most discussed Malware Samples
Most discussed (commented) malware samples on MalwareBazaar.
Top File Types
Most seen file types
associated with malware samples on MalwareBazaar.
Top imphashes
Most seen imphashes on MalwareBazaar.
Top ssdeep hashes
Most seen ssdeep hashes on MalwareBazaar.
Malware Sample | ssdeep | Signature(s) |
---|---|---|
1'124 | 12288:J2+J+l5QvSoOUkQNPRoswLLjfsHJNF05s:AJl5QrrkQFCHspN4 | Quakbot |
1'123 | 12288:U2+J+l5QvSoOUkQGPRoswLLjfsHJNF05F:PJl5QrrkQOCHspN4 | Quakbot |
1'121 | 12288:l2+J+l5QvSoOUkQiPRoswLLjfsHJNF05h:8Jl5QrrkQaCHspN4 | Quakbot |
528 | 1536:1I+Hymsbck3hbdlylKsgqopeJBWhZFGkE+cMLxAAISQ5gQ72IotO6nitSU6U+x:1I+HymsYk3hbdlylKsgqopeJBWhZFGkz | SilentBuilder Heodo |
419 | 1536:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIzSEV2NnX4Ia3gg5W8IuD7PoHsP7e3/:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxz | SilentBuilder Heodo |
416 | 768:0Jlk3hbdlylKsgqopeJBWhZFGkE+cMLxAAIZEtm/piJaiyH5YnJe+eO+8WoFYpLd:0rk3hbdlylKsgqopeJBWhZFGkE+cMLx6 | SilentBuilder Heodo |
401 | 1536:u8rk3hbdlylKsgqopeJBWhZFGkE+cL2NdAE6yHBEL70drpFk0GX/s2C6ORQYDBhQ:ugk3hbdlylKsgqopeJBWhZFGkE+cL2N8 | SilentBuilder Heodo |
373 | 3072:IFNthWQl/rSJ7lvt9filcZritkrINAEYsm2:IBhWQ/mJLflrOAp2 | Gozi Heodo |
351 | 3072:zs+Hyms0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIb4UgCEqM5mheHRAjNKnlGIz/:o+Hyms0k3hbdlylKsgqopeJBWhZFVE+P | SilentBuilder Heodo |
307 | 12288:xyP2Md2hn+tDKFtKwK5KLK6KYK5KlK3K1aoNl7Mv+lwVwy:grdO+tDKFQoNOml | TrickBot |
Top dhash icon
Most seen dhashes of icons from PE32 executables and their signatures.
Malware Sample | dhash icon | Signature(s) |
---|---|---|
15'168 | f8f0f4c8c8c8d8f0 | 8'775 x RedLineStealer, 5'019 x Amadey, 288 x Smoke Loader |
5'638 | b2a89c96a2cada72 | 2'281 x Formbook, 981 x Loki, 800 x AgentTesla |
4'624 | b298acbab2ca7a72 | 2'327 x GCleaner, 1'533 x Socks5Systemz, 67 x RedLineStealer |
3'893 | 71b119dcce576333 | 3'570 x Heodo, 203 x TrickBot, 19 x Gh0stRAT |
3'154 | aae2f3e38383b629 | 736 x Formbook, 633 x CredentialFlusher, 395 x AgentTesla |
2'780 | 0000000000000000 | 831 x AgentTesla, 379 x Formbook, 239 x RedLineStealer |
2'679 | 848c5454baf47474 | 2'038 x Adware.Neoreklami, 100 x RedLineStealer, 33 x DiamondFox |
1'702 | 9494b494d4aeaeac | 583 x DCRat, 171 x RedLineStealer, 134 x CryptOne |
1'150 | fefce49e86c0fcfe | 884 x Socks5Systemz, 259 x RaccoonStealer |
1'055 | 399998ecd4d46c0e | 572 x Quakbot, 137 x ArkeiStealer, 54 x RecordBreaker |
Most discussed Malware Samples
Most discussed (commented) malware samples on MalwareBazaar.