Statistics

MalwareBazaar produces various statistics on malware samples shared, including their detections. The available statistics can be found below.

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1Twitter @zbetcheckin2021-10-221'534
2Twitter @abuse_ch2021-10-221'514
3Twitter @GovCERT_CH2021-10-22391
4Twitter @SecuriteInfoCom2021-10-22336
5Twitter @cocaman2021-10-22270
6Twitter @tolisec2021-10-22256
7Twitter @pr0xylife2021-10-22143
8Twitter @lowmal32021-10-22130
9Twitter @JAMESWT_MHT2021-10-22103
10Twitter @malwarelabnet2021-10-2298
11Twitter @unidentified0xc2021-10-1680
12Twitter @adrian__luca2021-10-2265
13Twitter @JaffaCakes1182021-10-2263
14Twitter @James_inthe_box2021-10-2257
15Twitter @info_sec_ca2021-10-2223

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
1'393Skystars_Malware_ImphashSkystars LightDefender2021-10-22
1'393pe_imphash2021-10-22
846unixredflags3Tim Brown @timb_machine2021-10-22
771linux_generic_ipv6_catcher@_lubiedo2021-10-22
448INDICATOR_SUSPICIOUS_Stomped_PECompilation_Timestamp_InTheFutureditekSHen2021-10-22
263AgentTeslaV3ditekshen2021-10-22
263win_agent_tesla_v1Johannes Bader @viql2021-10-22
263MALWARE_Win_AgentTeslaV3ditekSHen2021-10-22
260ach_AgentTesla_20200929abuse.ch2021-10-22
235SUSP_XORed_MozillaFlorian Roth2021-10-22
235SUSP_XORed_Mozilla_RID2DB4Florian Roth2021-10-22
208BitcoinAddressDidier Stevens (@DidierStevens)2021-10-22
204MALWARE_Win_RedLineditekSHen2021-10-22
185SUSP_ELF_LNX_UPX_Compressed_FileFlorian Roth2021-10-22
170enterpriseapps2Tim Brown @timb_machine2021-10-22

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
55494036ecca794753179e68c331482c2b42b0c06a067169c8b004fad4e7dda673aExecutable exeRaccoonStealerTwitter @abuse_ch
5483737e2198a159ed5a530bf687d8cb40ca6c284db86d4bd076affefffc3a5ef0aExecutable exeShikataGaNaiTwitter @zbetcheckin
544ee72d76436717cfab41a33950d641e7e6820d23369b21fe937cc2fc2549c6869Executable exeRaccoonStealerTwitter @abuse_ch
543175857c3f9480499cf56d30f394f885d51ac9ef05bbc1d6bd86d3b4af393c261Executable exeRaccoonStealerTwitter @abuse_ch
54040c987e5f3c9bd1cd458ac2212623378e5c9832190371e232e48a726221db255Executable exeRedLineStealerTwitter Anonymous
536afe55746d2518c2515aa74761b02e6f7236de7bb1baefd81230fa9411628bee1Executable exeRedLineStealerTwitter Anonymous
5359534643f38e9d47c07b32097a951351d0b24da96927b5dc8f9e84e9cb371915eExecutable exeRedLineStealerTwitter Anonymous
534e1cc6919dab72162001993bd37c43673104428f21b696bd51e934112f8cfbb35Executable exenjratTwitter @abuse_ch
529c7faae85681abe125b9a81b798daf845c62ddab8014784b6fd1b184b02d5a22bExecutable exeRedLineStealerTwitter Anonymous
523cc98ee14bc8504ed2dae9d010c7f209775de51f9f31086814e2fb6b42baa7cb5Executable exeRaccoonStealerTwitter @abuse_ch
51997dbb2b9d161dd2b5f26eb48acef6ef70701b75a75b2d281e3dbb7fd946de319Executable exeRaccoonStealerTwitter @abuse_ch
5140be3682accde2a88d78e2516998a4e19a01d116a1a66fadf903b60326b92cca8Executable exeAgentTeslaTwitter @SecuriteInfoCom
513b43dde5ca3d23d16af5bf34c522869dff9624a78be67dfc3acde5c81ef24d318Executable exeOskiStealerTwitter @abuse_ch
507e45562980424366481dbd17982b5773aa120d0c6410a0d45ef4daa156ca7c478Executable exeRaccoonStealerTwitter @abuse_ch
5076c2ad98af84288aff6f49ae92f9f71befbfaa4ac35d1a05b1441f1ce15124ee0Executable exeTeamBotTwitter @abuse_ch

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
1'230f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook Loki njrat
183b76363e9cb88bf9390860da8e50999d2Formbook AgentTesla SnakeKeylogger Loki
634328f7206db519cd4e82283211d98e83RedLineStealer DCRat RaccoonStealer CoinMiner
28fcf1390e9ce472c7270447fc5c61a0c1NanoCore DCRat njrat RemcosRAT
180aa8675e96bbc2351e2af940f447c93eRedLineStealer Loki Smoke Loader Stop
16c7269d59926fa4252270f407e4dab043ServHelper CobaltStrike
1633155a730e036f2480434cae8e547169RaccoonStealer CryptBot TeamBot DanaBot
1525e96726029c322936cf0033b6a07058RedLineStealer Smoke Loader Formbook Loki
14c05041e01f84e1ccca9c4451f3b6a383DiamondFox RedLineStealer RaccoonStealer Adware.FileTour
14be41bf7b8cc010b614bd36bbca606973DanaBot CryptBot RedLineStealer DarkVNC

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
81536:S5Z4fJ6tL/yXFeL5zvL5nrHwcA7WhKpQY:S5ZIs5LL5nEcAihWNMirai
61536:EaDIpuRZhJRAAMA+xVZtWaWhK3+y6MdD:EaIe6ZtWhhQ1dDMirai
66144:5Kpb8rGYrMPe3q7Q0XV5xtuEsi8/dg59jWvcZZdtjq15OD7IvOEPD0lgvS3enw7I:U9jFrjmkD7IvLDK3vLvfn1+2GSilentBuilder
61536:StnwsWjjS5+8hEWZc+mQM4fJL4Okw/RqO1do3YpPz9I5iY5UJ/k:MWjA+QEWZbbZx4OjcO3o3H5UJ/kMirai
56144:5Kpb8rGYrMPe3q7Q0XV5xtuEsi8/dg59jWvcZZdtjq15OD7IvOEPD0lgvS3enw7o:U9jFrjmkD7IvLDK3vLvfn1+2mSilentBuilder
51536:czvQSZpGS4/31A6mQgL2eYCGDwRcMkVQd8YhY0/EqfIzmd:nSHIG6mQwGmfOQd8YhY0/EqUGLoki Heodo
412288:Zz7yBuBh3IpMiw4Ef6MU4ntMe1AofagCuOqPQkH5a:VwuBhfkMUe11fCuZPtQuakbot
412288:7NP2qgMhn9VbKac3cM15xIKR5pduDkgcKOuCEUz+ovYJXA8ZRA5cXO/+uBY2F0cC:RPp2abM15xIxD4KXJg/vYRbKDBhF1TSzTrickBot
412288:Jz7yBuBh3IpMiw4Ef6MU4ntMe1AofagCuOqPQkH59:FwuBhfkMUe11fCuZPtQuakbot
312288:+z7yduBV3IpMiw44f6Mw4ntMe5AofygCuOqPLkH5:mMuBVfQMwe51HCuZPQQuakbot

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
118b2a89c96a2cada7256 x Formbook, 25 x Loki, 9 x AgentTesla
56ead8ac9cc6a68ee031 x RedLineStealer, 7 x Smoke Loader, 5 x DanaBot
471003873d31213f1042 x GuLoader, 2 x Formbook, 1 x Gozi
3569e1c892f664c88832 x GuLoader, 3 x AgentTesla
27aad8ac9cc6a68ee010 x RedLineStealer, 5 x Smoke Loader, 5 x RaccoonStealer
2671b119dcce57633323 x TrickBot, 3 x BazaLoader
25ead8ac9cc6e68ee08 x RedLineStealer, 4 x ArkeiStealer, 3 x Smoke Loader
2588a28e9494aa94d214 x AgentTesla, 5 x Formbook, 2 x AsyncRAT
22e884030dcedeb4e812 x AgentTesla, 7 x Loki, 1 x NanoCore
21c4f0d0d4d0d4d4d413 x RemcosRAT, 7 x Formbook, 1 x AveMariaRAT

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 12 months.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1Twitter @abuse_ch2021-10-2282'959
2Twitter @lazyactivist1922021-04-2669'725
3Twitter @Cryptolaemus12021-06-1754'205
4Twitter @Seifreed2021-10-1948'947
5Twitter @c4llsec2021-05-1923'982
6Twitter @JAMESWT_MHT2021-10-2217'403
7Twitter @Libranalysis2021-07-1917'024
8Twitter @zbetcheckin2021-10-2212'010
9Twitter @cocaman2021-10-2210'826
10Twitter @SecuriteInfoCom2021-10-229'983
11Twitter @GovCERT_CH2021-10-227'320
12Twitter @FORMALITYDE2021-10-205'550
13Twitter @jarumlus2021-09-285'360
14Twitter @James_inthe_box2021-10-224'961
15Twitter @lowmal32021-10-222'780

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleLast match
78'467SharedStringsKatie Kleemola2021-07-19
76'690Email_stealer_bin_memJames_inthe_box2021-09-06
74'495Select_from_enumerationJames_inthe_box2021-10-03
73'324UAC_bypass_bin_memJames_inthe_box2021-08-08
71'631IPPort_combo_memJames_inthe_box2021-08-31
45'492Cobalt_functions@j0sm12021-07-13
28'926MALWARE_Win_DLLLoaderditekSHen2021-10-22
28'052ach_Dridex_xls_20200528abuse.ch2021-09-14
27'772DridexV4kevoreilly2021-10-22
25'318Win32_Trojan_EmotetReversingLabs2021-09-14
24'319DridexLoaderkevoreilly2021-10-22
23'034ach_Quakbot_xlsb_20201023abuse.ch2021-09-14
22'965win_dridex_autoFelix Bilstein2021-10-22
22'029win_sisfader_autoFelix Bilstein2021-05-07
18'724win_emotet_autoFelix Bilstein2021-09-30

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
72'03070ab26000929d26e0e4e567bd0dc4158054538485fcfd51dd4b60a534967814b lzhFirebirdRATTwitter @GovCERT_CH
3'005759ef75e133383af768b2be302dc256ad4e6720fb64eda70af76954dd29caf73Word file docPonyTwitter @abuse_ch
2'72210547fbcab56e5eeced75b4db50aac92a2eafe3581ad35018e27ea840b6abcb6Excel file xlsGet2Twitter @ffforward
2'70847b9b9ddc9f9e6c66cd6ea322a51bec7b843502b30db19f119fa59794ee19cd6Excel file xlsTA505Twitter @erdbaerkuchen
2'7069ad7ce27ce7da3c4b2639771869b20b78fff34f32dab3355c2be2980e708ab07DLL dllGet2Twitter @ffforward
2'604f0ad6a854cc6b8511c0499267c59c3e9a987845c912f3da030dd5a2201978385 sh Twitter @ov3rflow1
2'509afb4b0092c76214b9ac99cf9c00ae56163916c04e7713bd56a38abf07a81a7d7 html Twitter @TheGing3rm4n
2'502094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78dExecutable exeAgentTeslaTwitter @abuse_ch
2'48602419de92a33a88bc17701008182ca9f7ea8d4645311b837b98738acdea83254 sh Twitter @ov3rflow1
2'481455e09d22b9e9b172e5cf25a87f70c079bf97edc0295251a42f48211caf5043fVisual Basic Script (vbs) vbs Twitter @creP_R2point0
2'479e6507f36045c13dee736bea44d61e90169ea69de61e9dc50b5743960c5b8f85aExecutable exeBlackNETTwitter @abuse_ch
2'474d4b6920e28ddba697f8e2e33f6479d16c9b92fefdc36894e3c594e3f71095e4dExecutable exeDharmaTwitter @JAMESWT_MHT
2'4707fad486d054e36626a9842c99b2ff58dbf9e264d8faf45b3376afa02f0e829a7 sh Twitter @ov3rflow1
2'462fd19ea1f1a732ad23c4020ac775bf30041cae72642b9bc8269a89b3c54a72054Executable exeOrcusRATTwitter @Jouliok
2'4577ffa8a4939cf92caf8983afa85749d4fcb5eaa78769fe4f5dc7794a263ee5ed3Executable exeOrcusRATTwitter @Jouliok

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
54'596f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook Loki njrat
9'777c9f7e018b269f1b5fe81cf757d6f8e93Heodo
8'608987b9d7dc84d935c3675da82d40e06f2Dridex Gozi Tofsee VelvetSweatshopDridex
3'22687bed5a7cba00c7e1f4015f1bdae2183IcedID TrickBot Netsky Rapid
2'180433637d5d88b1ab11a7e5bfc30abfe93Dridex
1'95850f8a2255c4baf188eb0098c86160f78Heodo
1'723d20e8b584b1e294911b88a699c987910Dridex
1'586f71b9cb9891e9cf4bae79d2b5aa115c6Dridex
1'562afcdf79be1557326c854b6e20cb900a7AgentTesla RemcosRAT NanoCore QuasarRAT
1'506015974618e9105226f001019d35e62e5Quakbot

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
1'12412288:J2+J+l5QvSoOUkQNPRoswLLjfsHJNF05s:AJl5QrrkQFCHspN4Quakbot
1'12312288:U2+J+l5QvSoOUkQGPRoswLLjfsHJNF05F:PJl5QrrkQOCHspN4Quakbot
1'12112288:l2+J+l5QvSoOUkQiPRoswLLjfsHJNF05h:8Jl5QrrkQaCHspN4Quakbot
3733072:IFNthWQl/rSJ7lvt9filcZritkrINAEYsm2:IBhWQ/mJLflrOAp2Gozi Heodo
30712288:xyP2Md2hn+tDKFtKwK5KLK6KYK5KlK3K1aoNl7Mv+lwVwy:grdO+tDKFQoNOmlTrickBot
180384:fnqmQF9b8PdvtUuiyaFwrEnO2/7vUU2aGcuFjqZ5g:yme9bodlpkqkOOjUdaGciq5gQuakbot
180384:/nqmQF9b8PdvtUuiyaFwrEnO2/7vUU2aGcuFjqZ5g:Sme9bodlpkqkOOjUdaGciq5gQuakbot
180384:PnqmQF9b8PdvtUuiyaFwrEnO2/7vUyV2aGcuFjqZUb:Cme9bodlpkqkOOjU/aGciqUbQuakbot
179384:jnqmQF9b8PdvtUuiyaFwrEnO2/7vUjqN2aGcuFjqZM:eme9bodlpkqkOOjUjqgaGciqMQuakbot
179384:/nqmQF9b8PdvtUuiyaFwrEnO2/7vUjqN2aGcuFjqZM:Sme9bodlpkqkOOjUjqgaGciqMQuakbot

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
399b2a89c96a2cada72107 x Formbook, 49 x Loki, 47 x DiamondFox
379ead8ac9cc6e68ee0116 x RaccoonStealer, 96 x RedLineStealer, 45 x Smoke Loader
2754839b2b4e8c38890137 x RaccoonStealer, 37 x Smoke Loader, 29 x RedLineStealer
2644839b2b0e8c38890105 x RaccoonStealer, 38 x Smoke Loader, 33 x RedLineStealer
2544839b234e8c38890103 x RaccoonStealer, 44 x ArkeiStealer, 43 x RedLineStealer
186ead8ac9cc6a68ee079 x RedLineStealer, 46 x RaccoonStealer, 13 x ArkeiStealer
17971b119dcce576333167 x TrickBot, 5 x BazaLoader, 3 x CobaltStrike
140000000000000000025 x RedLineStealer, 21 x AgentTesla, 13 x Formbook
134ead8a89cc6e68ee043 x RaccoonStealer, 31 x RedLineStealer, 19 x Smoke Loader
1171003873d31213f1084 x GuLoader, 12 x RemcosRAT, 5 x Pony