Statistics

MalwareBazaar produces various statistics on malware samples shared, including their detections. The available statistics can be found below.

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1Twitter @abuse_ch2023-03-201'791
2Twitter @zbetcheckin2023-03-201'088
3Twitter @ChainskiLabs2023-03-20389
4Twitter @elfdigest2023-03-20283
5Twitter @cocaman2023-03-20239
6Twitter @andretavare52023-03-20224
7Twitter @JAMESWT_MHT2023-03-20223
8Twitter @petikvx2023-03-20191
9Twitter @SecuriteInfoCom2023-03-20151
10Twitter @adrian__luca2023-03-20145
11Twitter @lowmal32023-03-17134
12Twitter @jstrosch2023-03-20114
13Twitter @pr0xylife2023-03-20101
14Twitter @James_inthe_box2023-03-1978
15Twitter @fabiodemartin2023-03-2067

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
1'143Skystars_Malware_ImphashSkystars LightDefender2023-03-20
1'142pe_imphashNone2023-03-20
907pdb_YARAify@wowabiy3142023-03-20
789Windows_Trojan_Smokeloader_3687686fElastic Security2023-03-20
674linux_generic_ipv6_catcher@_lubiedo2023-03-20
648myMiraiNone2023-03-20
599MALWARE_Win_RedLineditekSHen2023-03-20
554unixredflags3Tim Brown @timb_machine2023-03-20
540BitcoinAddressDidier Stevens (@DidierStevens)2023-03-20
360Linux_Trojan_Gafgyt_28a2fe0cElastic Security2023-03-20
325meth_get_eipWilli Ballenthin2023-03-20
307shellcodenex2023-03-20
305setsockoptTim Brown @timb_machine2023-03-20
237PE_Digital_Certificatealbertzsigovits2023-03-20
214PE_Potentially_Signed_Digital_Certificatealbertzsigovits2023-03-20

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
885d0c1ac6f5df5c198d890adcc7f7f7cd6b8c9b9c81f78175677d45c5c045938ddJava Script (JS) jsSTRRATTwitter @abuse_ch
884f5e9af8a842e3d0ab3b48e83151a43a1514ed4f8772da1819d27558b62901b3bExecutable exeAveMariaRATTwitter @abuse_ch
87675e794dd1ddfe6d2585dc9031c32fa1c27515d08476d7d2dd52dd650bfbb934dExecutable exenjratTwitter @abuse_ch
865061c271c0617e56aeb196c834fcab2d24755afa50cd95cc6a299d76be496a858Executable exeGoziTwitter @0xToxin
84789bad8eeff38f1e5ea58348314ee05352b1eb22d3a4ee8c15be9d0098779487eExecutable exeRedLineStealerTwitter @zbetcheckin
774f094258e2cc0b89d4ebac6f87e9061a13698435614fddc95b855718dd3e0c31cExecutable exeRedLineStealerTwitter @abuse_ch
7735bebe0a5a633bb72179113bca4fe7d0ac366ad77160eb85eeef4f7d8fdd29846Executable exeDCRatTwitter @abuse_ch
768287c6eb55dc5eab6eb08b4345626b37569f8addb9c29ff12a8fabe2d9852d650Executable exeRecordBreakerTwitter @abuse_ch
67407fa172e1404c76738226cefc6e5d45559430c9946e419ed089d9ae5690783f9Executable exeLokiTwitter @abuse_ch
67309ddb64646d92e7c0187a53719ce98c46caad936ff3c525dcca29ea27db2a7cbExecutable exe Twitter @SecuriteInfoCom
6483abea4ab1fa4c8497722e9b58c5981fbc90fefe5a1d0bda707bdabfe3c1bdb1fExecutable exeAveMariaRATTwitter @abuse_ch
6221800b167dbdf8e9516259296c65c7039763a34900d55bb4a4ddb1b38785b323eExecutable exenjratTwitter @abuse_ch
6106ecbc0d9795b7fa1869f113c5a05fca4d8ff17f2312ac8f973277989cf64a67bExecutable exeAsyncRATTwitter @ChainskiLabs
59533a74190a5d5c9bf019083aeb8068c676ca044e3bf5d25d03ccbad22ee7b59f3Executable exeDCRatTwitter @abuse_ch
592296985e566c978fc095ae09686f69f8ddc80a2b6f6b26dfab6ce11ddf7daab02Executable exeAgentTeslaTwitter @zbetcheckin

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
1'067f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger Loki
18761259b55b8912888e90f516ca08dc514Formbook AgentTesla GuLoader SnakeKeylogger
99646167cce332c1c252cdcb1839e0cf48RedLineStealer Amadey njrat Smoke Loader
78d5555405ac36a198d312d7dfaf56a1edRedLineStealer Amadey Rhadamanthys Stop
478b512f0a0b2cd54ff600ee8ace8b2bd0RedLineStealer Amadey Rhadamanthys Smoke Loader
436585b9b9ad7d80299a944a8f7e11d434RedLineStealer Amadey Smoke Loader
439c97db954c6eab8dfde4a4fd207d98ccRedLineStealer Amadey Stop LaplasClipper
30a567e4b58eb4a1e8b4fddc91e9b45967RedLineStealer Amadey LaplasClipper
26884310b1928934402ea6fec1dbd3cf5eGCleaner RedLineStealer Socelars Adware.InstallCore
25a4182fd8d83730115cc46da88cd0978cAmadey RedLineStealer Smoke Loader Gozi

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
9768:Oa2vU7eng2qGJert7LrLMU6fgatQh+YbT/9+m3CZQoV/bnmCozw:Oa4U7G7SvT6ftBTm3KVrmCo8Mirai
61536:PaAtVnz1/mUUNztiYmW6ihiYLTofs3wfpWIDNEJ7JC7:P/tVz1eUUfwN0T0f+whWONEJ7JMirai
512288:zNfg7ayYgZHRXnW0liwD8L9GlB/TSJRBzfVE/+AqD0eBkvkJl6h4MEFvhAkRoAG5:zRTyV2ZxybQvh9RoOUzux82V8PPikabot
524576:m1F4VX4ZsIETa80JWFst9LqGfEBz9terTMH9MbMx9upUenl6O:m1FWWbETahMszqGfu0rYHqbMxQpPlRedLineStealer Amadey
46144:x5UguSWlTtbveMH2QRObpNSEmV5cvWeKwDWusJkUpCvpniMWJlHQhynq3W4qOmc/:x5JGFveBQETwyjdJiGEEgSo5XwFabookie
424576:0LdkRpGh0fHRQSSbvuODeV8CBrRiO4rTdTlJr/fYO:eko0vRzSPDARizTlPrRedLineStealer
424576:bogX4PvpDseL3ckNcZQrKxl3fXZ16b4PEPtYn1h7Xn6iZGyF:bdoPLrcepKfBG4PEED7XFAmadey RedLineStealer
424576:hogX4PvpDseL3ckNcZQrKxl3fXZ16b4PEPtYn1h7Xn6iZGyF:hdoPLrcepKfBG4PEED7XFRedLineStealer Amadey
324576:O1F4VX4ZsIETa80JWFst9LqGfEBz9terTMH9MbMx9upUenl6O:O1FWWbETahMszqGfu0rYHqbMxQpPlRedLineStealer
324576:YLdkRpGh0fHRQSSbvuODeV8CBrRiO4rTdTlJr/fYO:Kko0vRzSPDARizTlPrAmadey RedLineStealer

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
117b2a89c96a2cada7246 x Formbook, 39 x AgentTesla, 15 x SnakeKeylogger
100f8f0f4c8c8c8d8f092 x RedLineStealer, 3 x Amadey, 1 x Lu0Bot
34eeacac8cb6e2ba8624 x SnakeKeylogger, 7 x AgentTesla
318ceaaa9abaa6ba0031 x CryptBot
30b298acbab2ca7a7222 x GCleaner, 1 x RedLineStealer, 1 x LummaStealer
3000000000000000004 x AgentTesla, 4 x RemcosRAT, 3 x AsyncRAT
29d49e21a29696866011 x AgentTesla, 9 x Loki, 8 x SnakeKeylogger
280018dac28a8eb89818 x RedLineStealer, 10 x Amadey
2870f0e6d4cca8f07015 x AgentTesla, 6 x SnakeKeylogger, 5 x Loki
2763032a23030a422223 x RedLineStealer, 4 x Amadey

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 12 months.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1Twitter @abuse_ch2023-03-20133'224
2Twitter @lazyactivist1922022-05-1869'727
3Twitter @Cryptolaemus12023-03-0667'816
4Twitter @zbetcheckin2023-03-2049'629
5Twitter @Seifreed2021-10-1948'947
6Twitter @andretavare52023-03-2026'942
7Twitter @JAMESWT_MHT2023-03-2025'892
8Twitter @SecuriteInfoCom2023-03-2020'349
9Twitter @cocaman2023-03-2018'368
10Twitter @Libranalysis2022-03-2917'029
11Twitter @GovCERT_CH2022-11-1415'557
12Twitter @lowmal32023-03-177'481
13Twitter @James_inthe_box2023-03-197'454
14Twitter @tolisec2022-07-196'610
15Twitter @OSimao2022-08-315'845

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
78'471SharedStringsKatie Kleemola2022-12-20
76'707Email_stealer_bin_memJames_inthe_box2023-03-10
74'501Select_from_enumerationJames_inthe_box2022-12-29
73'333UAC_bypass_bin_memJames_inthe_box2023-03-07
71'646IPPort_combo_memJames_inthe_box2022-11-11
66'680Skystars_Malware_ImphashSkystars LightDefender2023-03-20
51'124pe_imphash2023-03-20
45'507Cobalt_functions@j0sm12023-01-19
29'569MALWARE_Win_DLLLoaderditekSHen2022-09-07
28'421DridexV4kevoreilly2022-09-07
28'072ach_Dridex_xls_20200528abuse.ch2022-05-06
25'701pdb_YARAify@wowabiy3142023-03-20
25'457Win32_Trojan_EmotetReversingLabs2023-01-19
25'044DridexLoaderkevoreilly2022-09-07
23'595win_dridex_autoFelix Bilstein2022-09-07

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
72'07270ab26000929d26e0e4e567bd0dc4158054538485fcfd51dd4b60a534967814b lzhFirebirdRATTwitter @GovCERT_CH
52'950c88a22dae5d5564a33736d8cd43835eb46153bafe47fc6e8c267c3b89d4abf04 zip Twitter @l205306
42'30159494a51618f234021c0dae2d87667ce9e431b8a75a1b4952d3e48bf71492fbbExecutable exeAgentTeslaTwitter @cocaman
22'8252ae29fff50afc21422c12b4e64b055df4d342fb493a667e18b6dda7ad3403857Executable exeSmoke LoaderTwitter @andretavare5
17'744430dbb439bf85fd2a8846a43c0b0615305ef25ac8b9496d272c2dbefd3158ed2Executable exeSnakeKeyloggerTwitter @abuse_ch
6'979094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78dExecutable exeAgentTeslaTwitter @abuse_ch
5'69948f3ef54ff2ed0b44d5e4836c56a3a8f3214d7214278172ef84166f6d42cc067Excel file xlsmHeodoTwitter @James_inthe_box
5'584d66cdab94fb0231de6ddd6201c606115b2fa8174cc9f25816aabcb3347acc398Executable exeGCleanerTwitter @andretavare5
5'017d39f90416649c99f47627f47166815b9a661339e40e290b80be7f3b85efbda65Executable exeAsyncRATTwitter Anonymous
4'6556d3259011b9f2abd3b0c3dc5b609ac503392a7d8dea018b78ecd39ec097b3968DLL dllCobaltStrikeTwitter @pr0xylife
4'330759ef75e133383af768b2be302dc256ad4e6720fb64eda70af76954dd29caf73Word file docPonyTwitter @abuse_ch
4'317cc08642ddbbb8f735a3263180164cda6cf3b73a490fc742d5c3e31130504e97c htmlMatanbuchusTwitter @pr0xylife
4'305c6e9477fd41ac9822269486c77d0f5d560ee2f558148ca95cf1de39dea034186Microsoft Software Installer (MSI) msiMatanbuchusTwitter @pr0xylife
4'296b9720e833fa96fec76f492295d7a46b6f524b958278d322c4ccecdc313811f11 zipMatanbuchusTwitter @k3dg3
4'2912d8740ea16e9457a358ebea73ad377ff75f7aa9bdf748f0d801f5a261977eda4Microsoft Software Installer (MSI) msiMatanbuchusTwitter @pr0xylife

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
101'963f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger Loki
9'777c9f7e018b269f1b5fe81cf757d6f8e93Heodo
8'608987b9d7dc84d935c3675da82d40e06f2Dridex Gozi Tofsee VelvetSweatshopDridex
3'638884310b1928934402ea6fec1dbd3cf5eGCleaner RedLineStealer Socelars Adware.InstallCore
3'589646167cce332c1c252cdcb1839e0cf48RedLineStealer Amadey njrat Smoke Loader
3'26387bed5a7cba00c7e1f4015f1bdae2183Jadtre IcedID TrickBot Netsky
2'180433637d5d88b1ab11a7e5bfc30abfe93Dridex
2'0153786a4cf8bfee8b4821db03449141df4Adware.Neoreklami RedLineStealer
1'9717fa974366048f9c551ef45714595665eFormbook Loki AgentTesla SnakeKeylogger
1'95850f8a2255c4baf188eb0098c86160f78Heodo

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
1'12412288:J2+J+l5QvSoOUkQNPRoswLLjfsHJNF05s:AJl5QrrkQFCHspN4Quakbot
1'12312288:U2+J+l5QvSoOUkQGPRoswLLjfsHJNF05F:PJl5QrrkQOCHspN4Quakbot
1'12112288:l2+J+l5QvSoOUkQiPRoswLLjfsHJNF05h:8Jl5QrrkQaCHspN4Quakbot
5281536:1I+Hymsbck3hbdlylKsgqopeJBWhZFGkE+cMLxAAISQ5gQ72IotO6nitSU6U+x:1I+HymsYk3hbdlylKsgqopeJBWhZFGkzSilentBuilder Heodo
4191536:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIzSEV2NnX4Ia3gg5W8IuD7PoHsP7e3/:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxzSilentBuilder Heodo
416768:0Jlk3hbdlylKsgqopeJBWhZFGkE+cMLxAAIZEtm/piJaiyH5YnJe+eO+8WoFYpLd:0rk3hbdlylKsgqopeJBWhZFGkE+cMLx6SilentBuilder Heodo
4011536:u8rk3hbdlylKsgqopeJBWhZFGkE+cL2NdAE6yHBEL70drpFk0GX/s2C6ORQYDBhQ:ugk3hbdlylKsgqopeJBWhZFGkE+cL2N8SilentBuilder Heodo
3733072:IFNthWQl/rSJ7lvt9filcZritkrINAEYsm2:IBhWQ/mJLflrOAp2Gozi Heodo
3513072:zs+Hyms0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIb4UgCEqM5mheHRAjNKnlGIz/:o+Hyms0k3hbdlylKsgqopeJBWhZFVE+PSilentBuilder Heodo
30712288:xyP2Md2hn+tDKFtKwK5KLK6KYK5KlK3K1aoNl7Mv+lwVwy:grdO+tDKFQoNOmlTrickBot

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
4'311b2a89c96a2cada721'756 x Formbook, 927 x Loki, 575 x AgentTesla
3'82171b119dcce5763333'557 x Heodo, 201 x TrickBot, 10 x Gh0stRAT
3'578f8f0f4c8c8c8d8f01'981 x RedLineStealer, 1'481 x Amadey, 12 x ZLoader
2'464b298acbab2ca7a722'111 x GCleaner, 63 x RecordBreaker, 55 x RedLineStealer
2'280848c5454baf474741'781 x Adware.Neoreklami, 99 x RedLineStealer, 33 x DiamondFox
1'1830000000000000000226 x AgentTesla, 145 x Formbook, 131 x Heodo
902399998ecd4d46c0e568 x Quakbot, 137 x ArkeiStealer, 51 x RecordBreaker
80379756cecb29999b9731 x Heodo, 20 x Nitol, 20 x ManusCrypt
7709494b494d4aeaeac206 x DCRat, 127 x CryptOne, 100 x RedLineStealer
687480c1c4c4f594b14172 x Smoke Loader, 134 x RedLineStealer, 98 x Amadey