Statistics

MalwareBazaar produces various statistics on malware samples shared, including their detections. The available statistics can be found below.

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1 abuse_ch2023-10-041'091
2 andretavare52023-10-04740
3 zbetcheckin2023-10-04515
4 SecuriteInfoCom2023-10-04490
5 JAMESWT_MHT2023-10-04318
6 elfdigest2023-10-04297
7 cocaman2023-10-04252
8 lowmal32023-10-04143
9 r3dbU7z2023-10-04142
10 onecert_ir2023-10-03116
11 g0njxa2023-10-03113
12 TeamDreier2023-10-0485
13 James_inthe_box2023-10-0370
14 smica832023-10-0351
15 malwarelabnet2023-10-0346

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
1'168NETmalware-lu2023-10-04
928pe_imphashNone2023-10-04
927Skystars_Malware_ImphashSkystars LightDefender2023-10-04
909DebuggerCheck__APINone2023-10-04
736maldoc_find_kernel32_base_method_1Didier Stevens (https://DidierStevens.com)2023-10-04
660NETexecutableMicrosoftmalware-lu2023-10-04
457MALWARE_Win_RedLineditekSHen2023-10-03
451INDICATOR_EXE_Packed_ConfuserExditekSHen2023-10-04
414redline_stealer_1Nikolaos 'n0t' Totosis2023-10-04
371cobalt_strike_tmp01925d3fThe DFIR Report2023-10-04
314linux_generic_ipv6_catcher@_lubiedo2023-10-04
301detect_Redline_StealerVarp0s2023-10-04
295myMiraiNone2023-10-04
217unixredflags3Tim Brown @timb_machine2023-10-04
214DebuggerHiding__ActiveNone2023-10-04

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
4'2316be57566a72c81a9336d39b56627c14aa6a04e604954b71a84e83125171a742cExecutable exeRedLineStealer abuse_ch
1'283fbce59f489095cf06a8eb6e039cba2e85d289884c846d50c462a969454406b2fExecutable exeRedLineStealer abuse_ch
1'117bec121e347e5f64ef30e748468dce2e46e111a010193eeb6a3eb859492653a54Executable exeRedLineStealer abuse_ch
97019ded7361c826d6fad11c44d30ef7828d7e21588ce66cdbc6d1f3977f0c21ca6Executable exeRedLineStealer r3dbU7z
9609820a940d57022d72f7aa0834e2a75b04db340127779f8f4ac222f0cb3dd31ebExecutable exeRiseProStealer abuse_ch
84870f3e3111eeac71b52843f25ac554e7124831a73aa9e9574c30380d652e49ae3Executable exeAmadey abuse_ch
817fac05aabb4be950e24a4baed4f3c2c18f94666f18b82828d680bb5886137bd87Executable exeAmadey abuse_ch
816f1c959df7dd61d396faee6edf36d31f1616db1fe55520b51c71510f5fb664e56Executable exeAmadey abuse_ch
568df11d45e08d143198fce9f338ea6cf5b7ad714bac62add4a4674ab08b2374737Executable exe  lowmal3
557ee524f5314131071c292f5ff2cf0e55bad26d76a922fa73b37aa435ae2f13849Executable exeAmadey abuse_ch
55217b8a85528c7289b4abfb794dbd2f45ec98604ee7e40aedcfa471235e7157cc3Executable exeRedLineStealer abuse_ch
5494c1f3093ffec2c14d7c83d45756f181d3c0fdb84ea66ccfcf6035257a45a1f97Executable exeAmadey abuse_ch
4750331ca586f68e8a853e9030635f249dba8337da5ef7c29521c373807fcce1a6fExecutable exeAgentTesla cocaman
4257bc96cb82739ddadf27b1fea759b61aedabba949660d1b5c29034ef531568a36 apkIRATA onecert_ir
411886342b2453f5e52cc908b181da9ddfd3d47ba2b63e85a8e00a23253c1d51192Executable exeArkeiStealer r3dbU7z

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
803f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger Loki
435646167cce332c1c252cdcb1839e0cf48RedLineStealer Amadey Smoke Loader njrat
9496baacc90461fcd4b5d9fcc50047c098MysticStealer Amadey RedLineStealer Smoke Loader
63383ebf01ac19979467e97d3debc83542RedLineStealer MysticStealer Backdoor.TeamViewer Smoke Loader
598ddc982ec86bc15061e6b2eab1424decMysticStealer Smoke Loader RedLineStealer AveMariaRAT
549dda1a1d1f8a1d13ae0297b47046b26eFormbook AgentTesla NanoCore RemcosRAT
44f15d7c61281219835473a0dcb1929653MysticStealer RedLineStealer Smoke Loader Backdoor.TeamViewer
353865972614d44e518713c9a6183fed14Amadey
28e6417806f636d3a26a1e8916d3e05d01RedLineStealer MysticStealer Amadey
25fd410436ce0407a0a8f79bfce8af0bc3DarkGate

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
9512288:WXoJfAycbXpNU0bamorfNq4dYU1Uu65dRvwB1na+XyEfrWEN7wr:U9hbjtbrorFq0YUKLaXn3yhE
326144:DEPAc72ss5pKL93yMax7pH3F2d1ugMeSWp:DE32xpoaxBFg1ugMeSAmadey
91536:PaAtVnz1/mUUNztiYmW6ihiYLTofs3wfpWIDNEJ7JC7:P/tVz1eUUfwN0T0f+whWONEJ7JMirai
812288:JMGiNz/PUAg4Nq474U1ue65dRDwdFBg+3oEpVQaoKk:mNzkyqi4UQ7m3BRo5ao
5768:Oa2vU7eng2qGJert7LrLMU6fgatQh+YbT/9+m3CZQoV/bnmCozw:Oa4U7G7SvT6ftBTm3KVrmCo8Mirai
324576:U2G/nvxW3Ww0tRp8GiXTBhq7yRDvHcUcjUvy0lr3Tl6icOB/UWoT:UbA30H4zF0UMSAicOB/UWkDarkTortilla QuasarRAT
348:8Uw2oMnZ78UT+iDuYwUBWDHVxaMnyc2pU:8MZ78Wrut3arcaDarkGate
349152:epUPfjpSNeHaHGYayNId4pWL56Hq05vHjYL57CBN4/6sT:epeeHGKId+W1n6/01kN4ysTDarkGate
26144:V7Vj3uVUn27+6qQx41QPF2nnugMeS2SpY:xwYfQx9FOnugMeS2Amadey
2768:RqowmZPu9wtnfbltWgC6BSJsBcfDSTFIuQKqgESnmC/xO+KpAwz:RqtmZPuutfbltZFBSJsBcfDSTFI+BEzMirai

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
437f8f0f4c8c8c8d8f0286 x RedLineStealer, 84 x Amadey, 35 x Smoke Loader
49000000000000000024 x AgentTesla, 9 x Loki, 6 x Formbook
42b26969e8e8e8f0f023 x AgentTesla, 13 x Formbook, 3 x SnakeKeylogger
36b2a89c96a2cada7228 x Formbook, 4 x AgentTesla, 1 x RemcosRAT
34229878f8b4f031c424 x AgentTesla, 5 x Loki, 3 x Formbook
29848c5454baf474743 x Adware.Neoreklami
1700e49a72729ae4009 x AgentTesla, 4 x SnakeKeylogger, 3 x Loki
1661ccae5d69b28c616 x Loki, 6 x AgentTesla, 2 x SnakeKeylogger
16d2e8ecb2b2a2b2829 x Formbook, 6 x RedLineStealer, 1 x AgentTesla
149494b494d4aeaeac5 x DCRat, 3 x DarkTortilla

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 12 months.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1 abuse_ch2023-10-04154'285
2 lazyactivist1922022-05-1869'727
3 Cryptolaemus12023-04-0567'820
4 zbetcheckin2023-10-0461'047
5 Seifreed2021-10-1948'947
6 andretavare52023-10-0431'360
7 JAMESWT_MHT2023-04-2926'183
8 SecuriteInfoCom2023-10-0424'499
9 cocaman2023-10-0422'001
10 Libranalysis2023-04-1717'030
11 GovCERT_CH2022-11-1415'557
12 lowmal32023-10-049'745
13 James_inthe_box2023-10-038'371
14 tolisec2022-07-196'610
15 OSimao2022-08-315'845

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
83'717Skystars_Malware_ImphashSkystars LightDefender2023-10-04
78'471SharedStringsKatie Kleemola2022-12-20
76'708Email_stealer_bin_memJames_inthe_box2023-05-13
74'501Select_from_enumerationJames_inthe_box2022-12-29
73'333UAC_bypass_bin_memJames_inthe_box2023-03-07
71'647IPPort_combo_memJames_inthe_box2023-08-23
51'151pe_imphash2023-10-04
46'555pe_imphashNone2023-10-04
45'508Cobalt_functions@j0sm12023-08-23
29'569MALWARE_Win_DLLLoaderditekSHen2022-09-07
28'707pdb_YARAify@wowabiy3142023-09-07
28'421DridexV4kevoreilly2022-09-07
28'072ach_Dridex_xls_20200528abuse.ch2022-05-06
25'457Win32_Trojan_EmotetReversingLabs2023-01-19
25'044DridexLoaderkevoreilly2022-09-07

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
72'08070ab26000929d26e0e4e567bd0dc4158054538485fcfd51dd4b60a534967814b lzhFirebirdRAT GovCERT_CH
52'956c88a22dae5d5564a33736d8cd43835eb46153bafe47fc6e8c267c3b89d4abf04 zip  l205306
42'31159494a51618f234021c0dae2d87667ce9e431b8a75a1b4952d3e48bf71492fbbExecutable exeAgentTesla cocaman
22'8322ae29fff50afc21422c12b4e64b055df4d342fb493a667e18b6dda7ad3403857Executable exeSmoke Loader andretavare5
17'757430dbb439bf85fd2a8846a43c0b0615305ef25ac8b9496d272c2dbefd3158ed2Executable exeSnakeKeylogger abuse_ch
16'1642190623b860d6783e4c6758c057ceecb9023c3b89b824cacc74e6a9c84ed99c1Executable exeRedLineStealer abuse_ch
7'647094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78dExecutable exeAgentTesla abuse_ch
7'32195381fed0ea5e87bb60b34d47463c830f31176b4b444176cea7c0a45c0e434d0PowerPoint file pptx  cocaman
7'113061e17f3b2fd4a4dce1bf4f8a31198273f1abc47c32456d06fd5997ea4363578PowerPoint file pptx  Jagdtiger88mm
7'09992779228416f0dce42fd4e3d1ead5cfaecf563694391c01f421c53edd773b72ePowerPoint file pptx  cocaman
7'0414dd75e9c997abbb78aff675a28039b49ed7ebbfc2d97a4e378f7fd0d03d7e2fdPowerPoint file pptx  cocaman
6'9935206fb8a22102a8cda01faed36f0b860d191df697ee327ddb6855c8821e00af3PowerPoint file pptx  cocaman
6'9657e6aaa62831f2c2d26fbd3af7a7650fced824eb60c8dcbb85bb61c25a9614674PowerPoint file pptx  EldadViola
6'960b206ac5443480cdf5dfec41a5ff725efa5aa550251c908f1309f848d0ce57600PowerPoint file pptx Twitter Anonymous
6'9074e09c7b070043bd5bf50b7b2038dd170b491128eb28f5fdf61d9a07e831ece3cPowerPoint file pptx  cocaman

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
115'470f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger Loki
11'943646167cce332c1c252cdcb1839e0cf48RedLineStealer Amadey Smoke Loader njrat
9'777c9f7e018b269f1b5fe81cf757d6f8e93Heodo
8'608987b9d7dc84d935c3675da82d40e06f2Dridex Gozi Tofsee VelvetSweatshopDridex
3'914884310b1928934402ea6fec1dbd3cf5eGCleaner RedLineStealer Socelars ManusCrypt
3'31987bed5a7cba00c7e1f4015f1bdae2183Jadtre IcedID TrickBot Netsky
3'09561259b55b8912888e90f516ca08dc514Formbook AgentTesla GuLoader SnakeKeylogger
2'180433637d5d88b1ab11a7e5bfc30abfe93Dridex
2'0463786a4cf8bfee8b4821db03449141df4Adware.Neoreklami RedLineStealer
1'9797fa974366048f9c551ef45714595665eFormbook Loki AgentTesla SnakeKeylogger

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
1'12412288:J2+J+l5QvSoOUkQNPRoswLLjfsHJNF05s:AJl5QrrkQFCHspN4Quakbot
1'12312288:U2+J+l5QvSoOUkQGPRoswLLjfsHJNF05F:PJl5QrrkQOCHspN4Quakbot
1'12112288:l2+J+l5QvSoOUkQiPRoswLLjfsHJNF05h:8Jl5QrrkQaCHspN4Quakbot
5281536:1I+Hymsbck3hbdlylKsgqopeJBWhZFGkE+cMLxAAISQ5gQ72IotO6nitSU6U+x:1I+HymsYk3hbdlylKsgqopeJBWhZFGkzSilentBuilder Heodo
4191536:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIzSEV2NnX4Ia3gg5W8IuD7PoHsP7e3/:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxzSilentBuilder Heodo
416768:0Jlk3hbdlylKsgqopeJBWhZFGkE+cMLxAAIZEtm/piJaiyH5YnJe+eO+8WoFYpLd:0rk3hbdlylKsgqopeJBWhZFGkE+cMLx6SilentBuilder Heodo
4011536:u8rk3hbdlylKsgqopeJBWhZFGkE+cL2NdAE6yHBEL70drpFk0GX/s2C6ORQYDBhQ:ugk3hbdlylKsgqopeJBWhZFGkE+cL2N8SilentBuilder Heodo
3733072:IFNthWQl/rSJ7lvt9filcZritkrINAEYsm2:IBhWQ/mJLflrOAp2Gozi Heodo
3513072:zs+Hyms0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIb4UgCEqM5mheHRAjNKnlGIz/:o+Hyms0k3hbdlylKsgqopeJBWhZFVE+PSilentBuilder Heodo
30712288:xyP2Md2hn+tDKFtKwK5KLK6KYK5KlK3K1aoNl7Mv+lwVwy:grdO+tDKFQoNOmlTrickBot

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
12'471f8f0f4c8c8c8d8f07'442 x RedLineStealer, 4'748 x Amadey, 56 x Smoke Loader
5'249b2a89c96a2cada722'189 x Formbook, 981 x Loki, 762 x AgentTesla
3'84071b119dcce5763333'557 x Heodo, 202 x TrickBot, 13 x Gh0stRAT
2'792b298acbab2ca7a722'327 x GCleaner, 66 x RecordBreaker, 61 x RedLineStealer
2'345848c5454baf474741'812 x Adware.Neoreklami, 99 x RedLineStealer, 33 x DiamondFox
1'8750000000000000000538 x AgentTesla, 229 x Formbook, 195 x SnakeKeylogger
1'1589494b494d4aeaeac266 x DCRat, 159 x RedLineStealer, 134 x CryptOne
953399998ecd4d46c0e571 x Quakbot, 137 x ArkeiStealer, 52 x RecordBreaker
81079756cecb29999b9731 x Heodo, 20 x Nitol, 20 x ManusCrypt
688480c1c4c4f594b14172 x Smoke Loader, 134 x RedLineStealer, 98 x Amadey