Statistics

MalwareBazaar produces various statistics on malware samples shared, including their detections. The available statistics can be found below.

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1Twitter @andretavare52023-01-282'131
2Twitter @abuse_ch2023-01-281'213
3Twitter @zbetcheckin2023-01-28558
4Twitter @SecuriteInfoCom2023-01-20214
5Twitter @jstrosch2023-01-27182
6Twitter @cocaman2023-01-27159
7Twitter @lowmal32023-01-27115
8Twitter @atomiczsec2023-01-28111
9Twitter @0xToxin2023-01-2892
10Twitter @JAMESWT_MHT2023-01-2684
11Twitter @James_inthe_box2023-01-2670
12Twitter @petikvx2023-01-2865
13Twitter @adm1n_usa322023-01-2860
14Twitter @pr0xylife2023-01-2752
15Twitter @TeamDreier2023-01-2651

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
1'594pdb_YARAify@wowabiy3142023-01-28
1'191pe_imphashNone2023-01-28
1'189Skystars_Malware_ImphashSkystars LightDefender2023-01-28
919shellcodenex2023-01-28
899cobalt_strike_tmp01925d3fThe DFIR Report2023-01-28
898Windows_Trojan_Smokeloader_3687686fElastic Security2023-01-28
595win_gcleaner_autoFelix Bilstein2023-01-28
385MALWARE_Win_RedLineditekSHen2023-01-28
316BitcoinAddressDidier Stevens (@DidierStevens)2023-01-28
308meth_get_eipWilli Ballenthin2023-01-28
195myMiraiNone2023-01-28
187unixredflags3Tim Brown @timb_machine2023-01-28
177yara_templateNone2023-01-28
163linux_generic_ipv6_catcher@_lubiedo2023-01-28
153meth_stackstringsWilli Ballenthin2023-01-28

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
22'8122ae29fff50afc21422c12b4e64b055df4d342fb493a667e18b6dda7ad3403857Executable exeSmoke LoaderTwitter @andretavare5
17'739430dbb439bf85fd2a8846a43c0b0615305ef25ac8b9496d272c2dbefd3158ed2Executable exeSnakeKeyloggerTwitter @abuse_ch
3'489aa6f57bb39808d9948c98d82c592be6db51230e74be46a1181103c246e8c6681Executable exe Twitter @abuse_ch
1'2996326bea9cec6e2baec63ed96cd31a97770c6a63b96d1169a8b5586ec071c8778Executable exeLgoogLoaderTwitter @andretavare5
598737bff8488486744c65118caaadaa03cc43981ec3c5b6c6bea544f3366f0873aExecutable exeGoziTwitter @JAMESWT_MHT
415acc70eb94782931ab5f817a91b3c4cedf4c3077fb497a63e90a55e500da7676eExecutable exeRecordBreakerTwitter @abuse_ch
329212fff7721e43dff7db6bd7a5df41d57dac21bbf9a9c7c952e5a4a11092761b7Executable exeEmotetTwitter @zbetcheckin
328f2f8c2730204c757eb01c80258a2e1b260f2f525ab0e1d7453ff2f8b31174f25Executable exe Twitter Anonymous
3208090338badc224da17e784bdc511fd10d00896698338dcd2194d3002c733f782Executable exe Twitter @abuse_ch
312ed5225bcf35b63d220552d1a6fb95c9653565dfc4c33b6ee9402390e56db4f9cExecutable exe Twitter @andretavare5
2984fe7ef88c01a7271b02b96363e19a3d4169ca21ab0254fb487e64354609bb82bExecutable exeGCleanerTwitter @andretavare5
29770dddee5260354519c01b84b2d66783f7aacd89b4c6654bc765cbf34996b7018Executable exeCoinMinerTwitter @andretavare5
292a43850888151cc034d4a18616338702a3675d99c5041324a15090f5d20eabb9bExecutable exe Twitter @petikvx
2905fc77394fd32986a32fe00746df98db40d11fb240cb6646513aec9157e104ff3Executable exeDCRatTwitter @abuse_ch
2892874f19d385565b1c5d5e630163aef1d87280af5de2cba4a583ab683768df1f4Executable exeEmotetTwitter @zbetcheckin

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
1'102f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger Loki
588884310b1928934402ea6fec1dbd3cf5eGCleaner RedLineStealer Adware.InstallCore Socelars
22361259b55b8912888e90f516ca08dc514GuLoader Formbook AgentTesla Loki
1873786a4cf8bfee8b4821db03449141df4Adware.Neoreklami RedLineStealer
64e72f606dd0982c47d40a1b2d2827cdc0Smoke Loader Tofsee CoinMiner TeamBot
39e3155d9cfab86b6c5c15edea4a8741d5Smoke Loader RedLineStealer LummaStealer TeamBot
360f2c785ca8bc5088ca1685c62509469dSmoke Loader RedLineStealer LummaStealer
284ad169539e30f4fdc9cb467ca358dbdbSmoke Loader Tofsee CoinMiner TeamBot
28f59055ddf5d9b2bfdec5b43ba63509a2Smoke Loader CoinMiner Tofsee Rhadamanthys
26831efd74b04212c71384962d1e3b11acSmoke Loader RedLineStealer TeamBot AsyncRAT

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
46144:uC1Y5jpr0602TzhldWqIk6jKSxPMkksMoK:uC18jpg60OCHNMBxoKRhadamanthys
249152:ySg8kOqBMdDhtQM4I+MkmJm9LcBwQYdXQ4J:tfkOqGhhtn9+nmJm9LcBCXvJDCRat
249152:CSg8kOqBMdDhtQM4I+MkmJm9LcBwQYdXQ4J:dfkOqGhhtn9+nmJm9LcBCXvJDCRat
212288:aCe8LxGQ7MRSRAsDYeQBWlWc4b70eU06zTwjZ++R5Mi6/ZVgCp0TLAXZoCzZWpfb:aN88Q7aQjDYLWlhW7JUyZ++R5PyZ5pcNMatiex
298304:JCeCsdoOk1Qqrx+14KBDYauafqeu3M5qOmCc8:hdnkOq4iYEauaft4gtZDCRat
212288:RiRpPsdFZd2r35wVWg7FbrFu7JyNbU2/O+cYg:uiBdY3yhdFu7OP2+WAgentTesla
23072:SxqZWpzalMMeZhTje75F3hWRHosxqZWpzalMMeZhTje75F3hWZH:AqZahTu3huqZahTu3hRedLineStealer
249152:4EAW6oV1uWgMzCAKcNqGAonnXvjGt8YxKIh3i2L:bADWgmNqGAKKBliDCRat
212288:lCjuH1KTxj0YvURk9DVz+v4AnhoYWGxBXxcVGrj4W:l4uH1AI1Rk9pzq4uasnXEcSnakeKeylogger
26144:BhcCpT3BG6bzRvc2a5YA5NQ+z9/Xf/BhJTXz/jPGiiM+4+hdFVXNDVZHNjI3lTkj:0CpNvc2o/vndz/ju0+4WFN5RSmIdSnakeKeylogger

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
188848c5454baf474741 x Adware.Neoreklami, 1 x RedLineStealer
182b298acbab2ca7a72165 x GCleaner, 7 x RedLineStealer, 2 x RustyStealer
14071f0e0ccccf0f0f0128 x GCleaner
67b2a89c96a2cada7223 x AgentTesla, 21 x Formbook, 5 x SnakeKeylogger
58b9e8f2f0ac9bd8da58 x GCleaner
5178f8f9d9ccc088e151 x GCleaner
50c1c0d8ccb434cce850 x GCleaner
45000000000000000025 x AgentTesla, 4 x SnakeKeylogger, 3 x NetWire
42b9f8f2d2b6a8ec7642 x GCleaner
269494b494d4aeaeac11 x DCRat, 7 x RedLineStealer, 1 x njrat

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 12 months.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1Twitter @abuse_ch2023-01-28126'769
2Twitter @lazyactivist1922022-05-1869'727
3Twitter @Cryptolaemus12023-01-2367'815
4Twitter @Seifreed2021-10-1948'947
5Twitter @zbetcheckin2023-01-2846'677
6Twitter @JAMESWT_MHT2023-01-2625'372
7Twitter @andretavare52023-01-2821'075
8Twitter @SecuriteInfoCom2023-01-2019'949
9Twitter @cocaman2023-01-2717'340
10Twitter @Libranalysis2022-03-2917'029
11Twitter @GovCERT_CH2022-11-1415'557
12Twitter @James_inthe_box2023-01-267'119
13Twitter @lowmal32023-01-276'919
14Twitter @tolisec2022-07-196'610
15Twitter @OSimao2022-08-315'845

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
78'471SharedStringsKatie Kleemola2022-12-20
76'706Email_stealer_bin_memJames_inthe_box2022-11-17
74'501Select_from_enumerationJames_inthe_box2022-12-29
73'332UAC_bypass_bin_memJames_inthe_box2022-09-27
71'646IPPort_combo_memJames_inthe_box2022-11-11
62'779Skystars_Malware_ImphashSkystars LightDefender2023-01-28
51'111pe_imphash2023-01-28
45'507Cobalt_functions@j0sm12023-01-19
29'569MALWARE_Win_DLLLoaderditekSHen2022-09-07
28'421DridexV4kevoreilly2022-09-07
28'072ach_Dridex_xls_20200528abuse.ch2022-05-06
25'457Win32_Trojan_EmotetReversingLabs2023-01-19
25'044DridexLoaderkevoreilly2022-09-07
23'595win_dridex_autoFelix Bilstein2022-09-07
23'320SUSP_Excel4Macro_AutoOpenJohn Lambert @JohnLaTwC2022-11-28

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
72'07270ab26000929d26e0e4e567bd0dc4158054538485fcfd51dd4b60a534967814b lzhFirebirdRATTwitter @GovCERT_CH
52'946c88a22dae5d5564a33736d8cd43835eb46153bafe47fc6e8c267c3b89d4abf04 zip Twitter @l205306
42'29459494a51618f234021c0dae2d87667ce9e431b8a75a1b4952d3e48bf71492fbbExecutable exeAgentTeslaTwitter @cocaman
22'8122ae29fff50afc21422c12b4e64b055df4d342fb493a667e18b6dda7ad3403857Executable exeSmoke LoaderTwitter @andretavare5
17'739430dbb439bf85fd2a8846a43c0b0615305ef25ac8b9496d272c2dbefd3158ed2Executable exeSnakeKeyloggerTwitter @abuse_ch
6'845094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78dExecutable exeAgentTeslaTwitter @abuse_ch
5'69548f3ef54ff2ed0b44d5e4836c56a3a8f3214d7214278172ef84166f6d42cc067Excel file xlsmHeodoTwitter @James_inthe_box
4'6536d3259011b9f2abd3b0c3dc5b609ac503392a7d8dea018b78ecd39ec097b3968DLL dllCobaltStrikeTwitter @pr0xylife
4'567d39f90416649c99f47627f47166815b9a661339e40e290b80be7f3b85efbda65Executable exeAsyncRATTwitter Anonymous
4'329759ef75e133383af768b2be302dc256ad4e6720fb64eda70af76954dd29caf73Word file docPonyTwitter @abuse_ch
4'312cc08642ddbbb8f735a3263180164cda6cf3b73a490fc742d5c3e31130504e97c htmlMatanbuchusTwitter @pr0xylife
4'303c6e9477fd41ac9822269486c77d0f5d560ee2f558148ca95cf1de39dea034186Microsoft Software Installer (MSI) msiMatanbuchusTwitter @pr0xylife
4'295b9720e833fa96fec76f492295d7a46b6f524b958278d322c4ccecdc313811f11 zipMatanbuchusTwitter @k3dg3
4'2892d8740ea16e9457a358ebea73ad377ff75f7aa9bdf748f0d801f5a261977eda4Microsoft Software Installer (MSI) msiMatanbuchusTwitter @pr0xylife
4'276c117b17bf187a3d52278eb229a1f2ac8a73967d162ad0cfc55089d304b1cc8a7 htmlMatanbuchusTwitter @pr0xylife

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
98'151f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger Loki
9'777c9f7e018b269f1b5fe81cf757d6f8e93Heodo
8'608987b9d7dc84d935c3675da82d40e06f2Dridex Gozi Tofsee VelvetSweatshopDridex
3'25987bed5a7cba00c7e1f4015f1bdae2183Jadtre IcedID TrickBot Netsky
2'677884310b1928934402ea6fec1dbd3cf5eGCleaner RedLineStealer Adware.InstallCore Socelars
2'180433637d5d88b1ab11a7e5bfc30abfe93Dridex
1'9697fa974366048f9c551ef45714595665eFormbook Loki AgentTesla SnakeKeylogger
1'95850f8a2255c4baf188eb0098c86160f78Heodo
1'8403786a4cf8bfee8b4821db03449141df4Adware.Neoreklami RedLineStealer
1'79540306b615af659fc1f93cfb121cc38d9GandCrab

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
1'12412288:J2+J+l5QvSoOUkQNPRoswLLjfsHJNF05s:AJl5QrrkQFCHspN4Quakbot
1'12312288:U2+J+l5QvSoOUkQGPRoswLLjfsHJNF05F:PJl5QrrkQOCHspN4Quakbot
1'12112288:l2+J+l5QvSoOUkQiPRoswLLjfsHJNF05h:8Jl5QrrkQaCHspN4Quakbot
5281536:1I+Hymsbck3hbdlylKsgqopeJBWhZFGkE+cMLxAAISQ5gQ72IotO6nitSU6U+x:1I+HymsYk3hbdlylKsgqopeJBWhZFGkzSilentBuilder Heodo
4191536:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIzSEV2NnX4Ia3gg5W8IuD7PoHsP7e3/:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxzSilentBuilder Heodo
416768:0Jlk3hbdlylKsgqopeJBWhZFGkE+cMLxAAIZEtm/piJaiyH5YnJe+eO+8WoFYpLd:0rk3hbdlylKsgqopeJBWhZFGkE+cMLx6SilentBuilder Heodo
4011536:u8rk3hbdlylKsgqopeJBWhZFGkE+cL2NdAE6yHBEL70drpFk0GX/s2C6ORQYDBhQ:ugk3hbdlylKsgqopeJBWhZFGkE+cL2N8SilentBuilder Heodo
3733072:IFNthWQl/rSJ7lvt9filcZritkrINAEYsm2:IBhWQ/mJLflrOAp2Gozi Heodo
3513072:zs+Hyms0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIb4UgCEqM5mheHRAjNKnlGIz/:o+Hyms0k3hbdlylKsgqopeJBWhZFVE+PSilentBuilder Heodo
30712288:xyP2Md2hn+tDKFtKwK5KLK6KYK5KlK3K1aoNl7Mv+lwVwy:grdO+tDKFQoNOmlTrickBot

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
3'82171b119dcce5763333'557 x Heodo, 201 x TrickBot, 10 x Gh0stRAT
3'773b2a89c96a2cada721'606 x Formbook, 897 x Loki, 353 x AgentTesla
2'384b298acbab2ca7a722'066 x GCleaner, 63 x RecordBreaker, 53 x RedLineStealer
2'102848c5454baf4747497 x RedLineStealer, 33 x DiamondFox, 33 x GCleaner
1'0590000000000000000204 x AgentTesla, 137 x Formbook, 131 x Heodo
890399998ecd4d46c0e558 x Quakbot, 137 x ArkeiStealer, 51 x RecordBreaker
78179756cecb29999b9731 x Heodo, 20 x Nitol, 16 x CobaltStrike
687480c1c4c4f594b14171 x Smoke Loader, 134 x RedLineStealer, 98 x Amadey
6369494b494d4aeaeac150 x DCRat, 95 x CryptOne, 74 x RedLineStealer
623b2dacabecee6baa6148 x RedLineStealer, 143 x Stop, 100 x Smoke Loader