Statistics

MalwareBazaar produces various statistics on malware samples shared, including their detections. The available statistics can be found below.

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1 Neiki__2023-06-011'746
2 abuse_ch2023-06-021'575
3 zbetcheckin2023-06-021'031
4 JAMESWT_MHT2023-06-01353
5 SecuriteInfoCom2023-06-01240
6 lowmal32023-06-01197
7 andretavare52023-06-01179
8 ChainskiLabs2023-06-02165
9 JaffaCakes1182023-06-01158
10 TeamDreier2023-06-01116
11 James_inthe_box2023-06-0181
12 pr0xylife2023-06-0174
13 threatcat_ch2023-05-2473
14 r3dbU7z2023-06-0172
15 adrian__luca2023-05-2959

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
1'468Skystars_Malware_ImphashSkystars LightDefender2023-06-02
1'468pe_imphashNone2023-06-02
925pdb_YARAify@wowabiy3142023-05-30
526myMiraiNone2023-06-01
475linux_generic_ipv6_catcher@_lubiedo2023-06-01
475cobalt_strike_tmp01925d3fThe DFIR Report2023-06-01
465MALWARE_Win_RedLineditekSHen2023-06-02
451unixredflags3Tim Brown @timb_machine2023-06-01
408INDICATOR_EXE_Packed_ConfuserExditekSHen2023-06-02
354redline_stealer_1Nikolaos 'n0t' Totosis2023-06-02
335BitcoinAddressDidier Stevens (@DidierStevens)2023-06-02
324win_amadey_a9f4Johannes Bader2023-05-30
308PE_Digital_Certificatealbertzsigovits2023-06-01
265PE_Potentially_Signed_Digital_Certificatealbertzsigovits2023-06-01
245Linux_Trojan_Gafgyt_28a2fe0cElastic Security2023-06-01

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
1'30420cf945541d245468ff9f86e3339a5ce537e33ed06951f3f2dcc6acdcf90a31eExecutable exeFabookie SecuriteInfoCom
9247e7a3c1b228d54fb07952dac151a49c0620d8b82fff7723d0d856aad574c8634Executable exe  pmmkowalczyk
825e4ff3d138daf42cc71613a0b2b9131e672ab42e3fc8f12779efa2f882985c40cExecutable exeSmoke Loader zbetcheckin
4319acece99f4c28d2bd3855e18ebdb8e5240be3521f89b6f0f9769c7216757e286Executable exeLoki threatcat_ch
409d1d74ec1039ff5aab99faf99bf70fb07f6b4c763a0c2fbc08b702ec9dcb03834Executable exe Twitter Anonymous
3982c2c265388a6a35791a4bb896cfcfbb7f14022b3e0256dbb5e0c14b81e1a47ddExecutable exeFormbook James_inthe_box
370fcc9e86561e2eef4cb3d9be190882d9ce1596c5d673acf67a54a0f54f3722f1dExecutable exeLokiTwitter Anonymous
3666e3cf5c7cccc4369fbed86c4de5bb59d7bb40c1ced10cab8b0bc733299d45ea1Executable exeRemcosRAT James_inthe_box
356fbdd2e5779904ac37f1a5322c29bc20cae75832553a0f519ed5f23a15e7f86abExecutable exenjrat abuse_ch
353ba93ee7bb38e10c6b38fb3c37798ad618e20b4f3d5125bd8d5de77f23afc3dcdExecutable exenjrat abuse_ch
350a82b10031aa29d8164b9c4599148641ab843312a405e83775295d5001860849cExecutable exeRemcosRAT jstrosch
3494b96a2bc629d40819ad85f26579a704999ca4e9d544ee83e7e89752c7279891fExecutable exeRedLineStealer zbetcheckin
34436c9da9b5e0eb4cc9453f946144cdf968f3485a1f9e4d015d54a526865aa51a4Executable exeGCleaner zbetcheckin
34369d565496f44573290fb467941ffb5635eb38eb62c3ebe538fb3c7fd1fc50197Executable exe  SecuriteInfoCom
343accb38ba3b9d6dfd9ad074145c53f8970ded5799e75f028bf57c3f3af80dc298Executable exeRedLineStealer abuse_ch

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
1'791646167cce332c1c252cdcb1839e0cf48RedLineStealer Amadey njrat Lu0Bot
1'160f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger Loki
6361259b55b8912888e90f516ca08dc514Formbook AgentTesla GuLoader SnakeKeylogger
28e92b45c54aa05ec107d5ef90662e6b33GCleaner
2547e01530ad43ec939d1c47709a80a5c6BumbleBee
21bb27c4958c76443fcfe46f9765d838a2Stop RedLineStealer GCleaner Amadey
19bd191f6a78cc98a8bbe61db18ad8e9a2Glupteba Smoke Loader ArkeiStealer Stop
18dae02f32a21e03ce65412f6e56942daaYellowCockatoo CobaltStrike MassLogger AsyncRAT
17b78ecf47c0a3e24a6f4af114e2d1f5deGuLoader CoinMiner Loki AgentTesla
17697c6731df2df92c82c75859d21c5f77Glupteba Stop Smoke Loader RedLineStealer

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
263072:2V+m5cNQmRSxWWAcP+DDXedh7Z58e8hk:2jwCUudh7zRedLineStealer
133072:PV+m5chQmRSZQ1avem1eJwfUuMyNiOhjZR8e8hX:PjENURTIOhj7RedLineStealer
103072:vV+m5cVQmRSx9WCEkEhPW67V8BjVhtZN8e8ht:vj4oihwlVht3RedLineStealer
83072:oV+m5czQmRS9Ynk5QXNhhRbG5h5Zx8e8h/:ojKtM5h5bRedLineStealer
71536:o2BGlTP+mZP61sEYDmRSNIgcscLDuRwH77+u8oxQKHbuxGBNM740wuei/Qv+R+Fn:6V+m5cvQmRSN90+82iTi74h9ZF8e8hURedLineStealer
712288:6tLTyenMEh/rI+Ea4seWbh1/PjsrCe3NsGTzbEr6JeUc/X016JNHJPXFk2LxvTr2:6tieMEe+HeWXjsldP3Amadey RedLineStealer
53072:sV+m5c/QmRSNY7WKA7vGJv3xnhMZx8e8hp:sj2BUanhMbRedLineStealer
51536:czvQSZpGS4/31A6mQgL2eYCGDwRcMkVQd8YhY0/EqfIzmd:nSHIG6mQwGmfOQd8YhY0/EqUGLoki Heodo
46144:bDKW1Lgbdl0TBBvjc/XYrcjaYJ8CTzkLFEPrg7VuQJY2HK:vh1Lk70TnvjcvNJhUEGcOKRedLineStealer
43072:FV+m5c/QmRSNAwMqLza9nDEFth2ZG8e8hR:Fj2FD0IQth2cRedLineStealer

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
1'785f8f0f4c8c8c8d8f01'171 x RedLineStealer, 605 x Amadey, 2 x CoinMiner
10510f0d4d0d4d4cc33105 x RedLineStealer
60000000000000000017 x Loki, 15 x AgentTesla, 9 x Formbook
38224472b2a0c0428013 x AgentTesla, 10 x Formbook, 8 x Loki
34b298acbab2ca7a7229 x GCleaner, 1 x RecordBreaker, 1 x Stealc
33b2a89c96a2cada7213 x AgentTesla, 7 x Formbook, 4 x AveMariaRAT
2800606969697144108 x AgentTesla, 7 x SnakeKeylogger, 7 x Loki
2368ec9acaabd0dcf011 x Loki, 5 x AgentTesla, 4 x Formbook
225169ccd4b2968e9610 x AgentTesla, 5 x Loki, 4 x Formbook
19e869f1f070f030547 x Formbook, 5 x AgentTesla, 4 x Loki

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 12 months.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1 abuse_ch2023-06-02140'472
2 lazyactivist1922022-05-1869'727
3 Cryptolaemus12023-04-0567'820
4 zbetcheckin2023-06-0254'598
5 Seifreed2021-10-1948'947
6 andretavare52023-06-0128'149
7 JAMESWT_MHT2023-04-2926'183
8 SecuriteInfoCom2023-06-0121'328
9 cocaman2023-05-1919'175
10 Libranalysis2023-04-1717'030
11 GovCERT_CH2022-11-1415'557
12 lowmal32023-06-018'361
13 James_inthe_box2023-06-017'796
14 tolisec2022-07-196'610
15 OSimao2022-08-315'845

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
78'471SharedStringsKatie Kleemola2022-12-20
76'708Email_stealer_bin_memJames_inthe_box2023-05-13
74'501Select_from_enumerationJames_inthe_box2022-12-29
73'333UAC_bypass_bin_memJames_inthe_box2023-03-07
72'353Skystars_Malware_ImphashSkystars LightDefender2023-06-02
71'646IPPort_combo_memJames_inthe_box2022-11-11
51'138pe_imphash2023-06-02
45'507Cobalt_functions@j0sm12023-01-19
35'193pe_imphashNone2023-06-02
29'569MALWARE_Win_DLLLoaderditekSHen2022-09-07
28'690pdb_YARAify@wowabiy3142023-05-30
28'421DridexV4kevoreilly2022-09-07
28'072ach_Dridex_xls_20200528abuse.ch2022-05-06
25'457Win32_Trojan_EmotetReversingLabs2023-01-19
25'044DridexLoaderkevoreilly2022-09-07

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
72'07770ab26000929d26e0e4e567bd0dc4158054538485fcfd51dd4b60a534967814b lzhFirebirdRAT GovCERT_CH
52'951c88a22dae5d5564a33736d8cd43835eb46153bafe47fc6e8c267c3b89d4abf04 zip  l205306
42'30259494a51618f234021c0dae2d87667ce9e431b8a75a1b4952d3e48bf71492fbbExecutable exeAgentTesla cocaman
22'8262ae29fff50afc21422c12b4e64b055df4d342fb493a667e18b6dda7ad3403857Executable exeSmoke Loader andretavare5
17'746430dbb439bf85fd2a8846a43c0b0615305ef25ac8b9496d272c2dbefd3158ed2Executable exeSnakeKeylogger abuse_ch
7'249094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78dExecutable exeAgentTesla abuse_ch
5'70448f3ef54ff2ed0b44d5e4836c56a3a8f3214d7214278172ef84166f6d42cc067Excel file xlsmHeodo James_inthe_box
5'588d66cdab94fb0231de6ddd6201c606115b2fa8174cc9f25816aabcb3347acc398Executable exeGCleaner andretavare5
5'496d39f90416649c99f47627f47166815b9a661339e40e290b80be7f3b85efbda65Executable exeAsyncRATTwitter Anonymous
4'6586d3259011b9f2abd3b0c3dc5b609ac503392a7d8dea018b78ecd39ec097b3968DLL dllCobaltStrike pr0xylife
4'332759ef75e133383af768b2be302dc256ad4e6720fb64eda70af76954dd29caf73Word file docPony abuse_ch
4'323cc08642ddbbb8f735a3263180164cda6cf3b73a490fc742d5c3e31130504e97c htmlMatanbuchus pr0xylife
4'307c6e9477fd41ac9822269486c77d0f5d560ee2f558148ca95cf1de39dea034186Microsoft Software Installer (MSI) msiMatanbuchus pr0xylife
4'297b9720e833fa96fec76f492295d7a46b6f524b958278d322c4ccecdc313811f11 zipMatanbuchus k3dg3
4'2932d8740ea16e9457a358ebea73ad377ff75f7aa9bdf748f0d801f5a261977eda4Microsoft Software Installer (MSI) msiMatanbuchus pr0xylife

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
107'513f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger Loki
9'777c9f7e018b269f1b5fe81cf757d6f8e93Heodo
8'608987b9d7dc84d935c3675da82d40e06f2Dridex Gozi Tofsee VelvetSweatshopDridex
7'321646167cce332c1c252cdcb1839e0cf48RedLineStealer Amadey njrat Lu0Bot
3'760884310b1928934402ea6fec1dbd3cf5eGCleaner RedLineStealer Socelars ManusCrypt
3'28887bed5a7cba00c7e1f4015f1bdae2183Jadtre IcedID TrickBot Netsky
2'40161259b55b8912888e90f516ca08dc514Formbook AgentTesla GuLoader SnakeKeylogger
2'180433637d5d88b1ab11a7e5bfc30abfe93Dridex
2'0273786a4cf8bfee8b4821db03449141df4Adware.Neoreklami RedLineStealer
1'9727fa974366048f9c551ef45714595665eFormbook Loki AgentTesla SnakeKeylogger

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
1'12412288:J2+J+l5QvSoOUkQNPRoswLLjfsHJNF05s:AJl5QrrkQFCHspN4Quakbot
1'12312288:U2+J+l5QvSoOUkQGPRoswLLjfsHJNF05F:PJl5QrrkQOCHspN4Quakbot
1'12112288:l2+J+l5QvSoOUkQiPRoswLLjfsHJNF05h:8Jl5QrrkQaCHspN4Quakbot
5281536:1I+Hymsbck3hbdlylKsgqopeJBWhZFGkE+cMLxAAISQ5gQ72IotO6nitSU6U+x:1I+HymsYk3hbdlylKsgqopeJBWhZFGkzSilentBuilder Heodo
4191536:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIzSEV2NnX4Ia3gg5W8IuD7PoHsP7e3/:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxzSilentBuilder Heodo
416768:0Jlk3hbdlylKsgqopeJBWhZFGkE+cMLxAAIZEtm/piJaiyH5YnJe+eO+8WoFYpLd:0rk3hbdlylKsgqopeJBWhZFGkE+cMLx6SilentBuilder Heodo
4011536:u8rk3hbdlylKsgqopeJBWhZFGkE+cL2NdAE6yHBEL70drpFk0GX/s2C6ORQYDBhQ:ugk3hbdlylKsgqopeJBWhZFGkE+cL2N8SilentBuilder Heodo
3733072:IFNthWQl/rSJ7lvt9filcZritkrINAEYsm2:IBhWQ/mJLflrOAp2Gozi Heodo
3513072:zs+Hyms0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIb4UgCEqM5mheHRAjNKnlGIz/:o+Hyms0k3hbdlylKsgqopeJBWhZFVE+PSilentBuilder Heodo
30712288:xyP2Md2hn+tDKFtKwK5KLK6KYK5KlK3K1aoNl7Mv+lwVwy:grdO+tDKFQoNOmlTrickBot

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
7'823f8f0f4c8c8c8d8f04'773 x RedLineStealer, 2'891 x Amadey, 16 x Lu0Bot
4'660b2a89c96a2cada721'892 x Formbook, 963 x Loki, 641 x AgentTesla
3'82871b119dcce5763333'557 x Heodo, 201 x TrickBot, 10 x Gh0stRAT
2'669b298acbab2ca7a722'281 x GCleaner, 66 x RecordBreaker, 57 x RedLineStealer
2'295848c5454baf474741'793 x Adware.Neoreklami, 99 x RedLineStealer, 33 x DiamondFox
1'4400000000000000000314 x AgentTesla, 174 x Formbook, 162 x SnakeKeylogger
922399998ecd4d46c0e571 x Quakbot, 137 x ArkeiStealer, 52 x RecordBreaker
8929494b494d4aeaeac223 x DCRat, 146 x RedLineStealer, 128 x CryptOne
80479756cecb29999b9731 x Heodo, 20 x Nitol, 20 x ManusCrypt
688480c1c4c4f594b14172 x Smoke Loader, 134 x RedLineStealer, 98 x Amadey