Statistics

MalwareBazaar produces various statistics on malware samples shared, including their detections. The available statistics can be found below.

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 30 days.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1Twitter @abuse_ch2022-08-101'208
2Twitter @zbetcheckin2022-08-10854
3Twitter @GovCERT_CH2022-08-10319
4Twitter @SecuriteInfoCom2022-08-10313
5Twitter @JAMESWT_MHT2022-08-10248
6Twitter @elfdigest2022-08-10191
7Twitter @cocaman2022-08-05162
8Twitter @adrian__luca2022-08-09139
9Twitter @lowmal32022-08-09101
10Twitter @malwarelabnet2022-08-0990
11Twitter @0xToxin2022-08-0975
12Twitter @James_inthe_box2022-08-0959
13Twitter @TeamDreier2022-08-1056
14Twitter @pmelson2022-08-0838
15Twitter @tech_skeech2022-08-1037

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
1'556Skystars_Malware_ImphashSkystars LightDefender2022-08-10
1'556pe_imphash2022-08-10
622pdb_YARAify@wowabiy3142022-08-10
452linux_generic_ipv6_catcher@_lubiedo2022-08-10
447myMirai2022-08-10
359BitcoinAddressDidier Stevens (@DidierStevens)2022-08-10
336unixredflags3Tim Brown @timb_machine2022-08-10
307meth_get_eipWilli Ballenthin2022-08-10
172MALWARE_Win_RedLineditekSHen2022-08-10
154SUSP_XORed_URL_in_EXEFlorian Roth2022-08-10
154SUSP_XORed_URL_in_EXE_RID2E46Florian Roth2022-08-10
146win_stop_autoFelix Bilstein2022-08-09
146MALWARE_Win_STOPditekSHen2022-08-09
142SUSP_ELF_LNX_UPX_Compressed_FileFlorian Roth2022-08-10
130INDICATOR_SUSPICIOUS_Binary_References_BrowsersditekSHen2022-08-10

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
855d39f90416649c99f47627f47166815b9a661339e40e290b80be7f3b85efbda65Executable exeAsyncRATTwitter Anonymous
644e67249b07a122a07e14c8a5ce4af521b5f97bd474fc200a3722173c26a1be43dExecutable exe Twitter @JaffaCakes118
56534e7a32e97d667d008ff62c423132d64a982bbfe4ee8e438abb8781028d01e9bExecutable exeRecordBreakerTwitter @abuse_ch
551656e31365da959aac67f8fe882d402942f921300d2713370657ba625c216686aExecutable exeCoinMinerTwitter @zbetcheckin
54834c7513173ccee7e341fe1ab4b55ba15356e3377aea4cac87965a2a459a09bccExecutable exeAsyncRATTwitter @abuse_ch
5352cd327b0ef59c4df71ca429ac256d6da4a87138e149ce614a61de5b80b6c72dfExecutable exeAgentTeslaTwitter @James_inthe_box
53272687cd9277d3e851fda2cd2788fba6c8df65caff553599b3ed50e01be005067Executable exeRustyStealerTwitter Anonymous
51505b81ebe094dccc3e9ea4bc2c593cb7feadead09aa7c811a2fba6ec8b50a52f3Executable exe Twitter @GovCERT_CH
51459455abda1b88849b821c2680aac74455e17cc0b7abf770f98596f33c857b8a0Executable exeRedLineStealerTwitter @abuse_ch
5119eb13c2c82f7e1172a0f30c4bb9e98a1b5fc13c2bacecdaf270249ea3c4ae99aExecutable exeAveMariaRATTwitter @abuse_ch
5037f1601721954de07576e3f37b9de86c30310363646fc5b1ae08ee35a836a92f3Executable exeFormbookTwitter @malwarelabnet
50205b0155e2323876de55c6893f7a6114d327eec632252db59dcb59a6fb8ee2c02Executable exeRemcosRATTwitter @zbetcheckin
502b20218ce17c3ddf455af2367397eda4e28d400484687c9d6b720e6e388a5b6d7Executable exeRecordBreakerTwitter @abuse_ch
495501ca8701afb41ddeda6c612ad9558642e7d34e6e53f46f87be747d120e680aeExecutable exeLokiTwitter @malwarelabnet
494ca4a862e957347dc3501e55fcf6ab8d130f141afea00c22f3bf25bf938531a35Executable exeNeshtaTwitter @zbetcheckin

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
1'524f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger Loki
4956a78d55f3f7af51443e58e0ce2fb5f6GuLoader Formbook Loki AgentTesla
441e33718404ffbe0d91b536c10bf053f8RedLineStealer N-W0rm Formbook RecordBreaker
2361259b55b8912888e90f516ca08dc514GuLoader Formbook Loki RemcosRAT
224419e484e276ee1537b37e2081fdee7a
19c9adc83b45e363b21cd6b11b5da0501fArkeiStealer RedLineStealer RecordBreaker Adware.FileTour
145484ce5c455789abe08c01ba8c35b619RedLineStealer Stop TeamBot
12d69e4c13e25f0ad622344ac56118c0dfSocelars
125f0c714c36e6cc016b3a1f4bc86559e4GuLoader Formbook Neshta AveMariaRAT
11c05041e01f84e1ccca9c4451f3b6a383RedLineStealer DiamondFox RaccoonStealer GCleaner

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
924576:5DA1mchKTwkH17WtMBhiUDxvHiMYStUtVSn52pAf2rDNtl2aCHX:5Dhc8ZPbVI5Sn52KNDBatLoader ModiLoader AveMariaRAT RemcosRAT
9768:Oa2vU7eng2qGJert7LrLMU6fgatQh+YbT/9+m3CZQoV/bnmCozw:Oa4U7G7SvT6ftBTm3KVrmCo8Mirai
812288:F+xn0/znwyVdboAk2SE+BOx7o1sf6hm7fWzHyW+K:w07nxdb7k2SnB2o1A6hsaSPKDBatLoader AveMariaRAT
724576:QCWYilFBNf4sLUY8qEDGX8whubd52Ep8r:QXPL65orDBatLoader AveMariaRAT Formbook RemcosRAT
649152:AiSzCD+K95aLs7zeqLTVtXtHFIDP8EehiM8qZA:AiSzCD+K95aUeqFtXtHwEEehig
624576:Bm61dayOdUWInvCsMX3aHkJmpxoPs5zd52Ep8r:BVDVEXuorDBatLoader ModiLoader Formbook RemcosRAT
524576:eXGq9fNAehxNnn+MsgnUQ0+vgd9Ulk5R/+VKkccpScpuw72sEeh8Sx8y:PqVNxhxFVKQKHgk5RmVKG7drDCRat
424576:+XGq9fNAehxNnn+MsgnUQ0+vgd9Ulk5R/+VKkccpScpuw72sEeh8Sx8y:vqVNxhxFVKQKHgk5RmVKG7drDCRat
324576:MryWRujk9kBBuNpHb9t0GrvBPUaxXd52Ep8r:Mr9fkByDorDBatLoader ModiLoader
2768:gduPBFnHooqR8qOCKq2cH4Kg9e+TK806MMUVjzkfQXObHud2oGN:r/hqaJMDg9eqK806MHdkfQX6HuCNMirai

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
41b2dacabecee6baa620 x Stop, 9 x RedLineStealer, 3 x RecordBreaker
39f0f0e8d8d4e4f4f013 x Formbook, 7 x AgentTesla, 6 x SnakeKeylogger
3738b078cccacccc4321 x Stop, 4 x RedLineStealer, 4 x Smoke Loader
35c6ccc84ec8cc8ad810 x AgentTesla, 9 x Formbook, 6 x SnakeKeylogger
32b2a89c96a2cada7211 x GuLoader, 9 x Formbook, 5 x RedLineStealer
274ccccccccc7070309 x AgentTesla, 8 x Formbook, 3 x Loki
27b6dacabecee6baa621 x Stop, 2 x RedLineStealer, 2 x ArkeiStealer
2638b078eccacccc4313 x Stop, 7 x ArkeiStealer, 4 x RedLineStealer
2586738c8d869669928 x AgentTesla, 4 x Loki, 4 x Formbook
24f0b83c3c3c3ab8f06 x Formbook, 6 x SnakeKeylogger, 5 x Loki

Malware sample shared


The chart below shows the number of unique malware samples shared on MalwareBazaar per day over a period of 12 months.


Top Reporters


It wouldn't be possible to operate MalwareBazaar without the help of volunteers who contribute malware samples to MalwareBazaar. The table below shows the top reporters and their Twitter handle.

RankReporterLast activitySubmissions
1Twitter @abuse_ch2022-08-10110'801
2Twitter @lazyactivist1922022-05-1869'727
3Twitter @Cryptolaemus12022-05-0467'812
4Twitter @Seifreed2021-10-1948'947
5Twitter @zbetcheckin2022-08-1038'794
6Twitter @JAMESWT_MHT2022-08-1023'590
7Twitter @Libranalysis2022-03-2917'029
8Twitter @cocaman2022-08-0515'393
9Twitter @SecuriteInfoCom2022-08-1015'172
10Twitter @GovCERT_CH2022-08-1014'059
11Twitter @tolisec2022-07-196'610
12Twitter @James_inthe_box2022-08-096'385
13Twitter @FORMALITYDE2022-08-085'683
14Twitter @lowmal32022-08-095'553
15Twitter @jarumlus2021-09-285'360

Top Malware Families

Top Tags

Most matching YARA rules


YARA rules that matched most on malware samples in MalwareBazaar.

Malware SamplesYARA ruleAuthorLast match
78'469SharedStringsKatie Kleemola2022-07-20
76'699Email_stealer_bin_memJames_inthe_box2022-07-15
74'496Select_from_enumerationJames_inthe_box2021-12-26
73'330UAC_bypass_bin_memJames_inthe_box2022-06-30
71'639IPPort_combo_memJames_inthe_box2022-06-28
46'570Skystars_Malware_ImphashSkystars LightDefender2022-08-10
45'498Cobalt_functions@j0sm12022-05-19
39'147pe_imphash2022-08-10
29'568MALWARE_Win_DLLLoaderditekSHen2022-07-13
28'413DridexV4kevoreilly2022-07-13
28'072ach_Dridex_xls_20200528abuse.ch2022-05-06
25'452Win32_Trojan_EmotetReversingLabs2022-03-29
25'037DridexLoaderkevoreilly2022-07-28
23'587win_dridex_autoFelix Bilstein2022-07-13
23'306SUSP_Excel4Macro_AutoOpenJohn Lambert @JohnLaTwC2022-08-08

Most downloaded Malware Samples


Most downloaded malware samples on MalwareBazaar.

DownloadsMalware SampleTypeSignatureReporter
72'05270ab26000929d26e0e4e567bd0dc4158054538485fcfd51dd4b60a534967814b lzhFirebirdRATTwitter @GovCERT_CH
6'389094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78dExecutable exeAgentTeslaTwitter @abuse_ch
4'290cc08642ddbbb8f735a3263180164cda6cf3b73a490fc742d5c3e31130504e97c htmlMatanbuchusTwitter @pr0xylife
4'288b9720e833fa96fec76f492295d7a46b6f524b958278d322c4ccecdc313811f11 zipMatanbuchusTwitter @k3dg3
4'287c6e9477fd41ac9822269486c77d0f5d560ee2f558148ca95cf1de39dea034186Microsoft Software Installer (MSI) msiMatanbuchusTwitter @pr0xylife
4'2786d3259011b9f2abd3b0c3dc5b609ac503392a7d8dea018b78ecd39ec097b3968DLL dllCobaltStrikeTwitter @pr0xylife
4'2722d8740ea16e9457a358ebea73ad377ff75f7aa9bdf748f0d801f5a261977eda4Microsoft Software Installer (MSI) msiMatanbuchusTwitter @pr0xylife
4'259c117b17bf187a3d52278eb229a1f2ac8a73967d162ad0cfc55089d304b1cc8a7 htmlMatanbuchusTwitter @pr0xylife
4'227f8cc2cf36e193774f13c9c5f23ab777496dcd7ca588f4f73b45a7a5ffa96145eDLL dllMatanbuchusTwitter @0x49736b
4'203759ef75e133383af768b2be302dc256ad4e6720fb64eda70af76954dd29caf73Word file docPonyTwitter @abuse_ch
4'1866c5eb5d9a66200f0ab69ee49ba6411abf29840bce00ed0681ec8b48e24fd83da zipMatanbuchusTwitter @JAMESWT_MHT
4'185e22ec74cd833a85882d5a8e76fa3b35daff0b7390bfbcd6b1ab270fd3741ceeaMicrosoft Software Installer (MSI) msiMatanbuchusTwitter @JAMESWT_MHT
4'1757e37d028789ab2b47bcab159da6458da2e8198617b0e7760174e4a0eea07d9c9Microsoft Software Installer (MSI) msiMatanbuchusTwitter @JAMESWT_MHT
4'1734fd90cf681ad260f13d3eb9e38b0f05365d3984e38cfba28f160b0f810ffd4d3Microsoft Software Installer (MSI) msiMatanbuchusTwitter @JAMESWT_MHT
4'172face46e6593206867da39e47001f134a00385898a36b8142a21ad54954682666Microsoft Software Installer (MSI) msiMatanbuchusTwitter @JAMESWT_MHT

ANY.RUN ANY.RUN


Top detections by ANY.RUN for malware samples on MalwareBazaar.

CAPE Sandbox CAPE Sandbox


Top detections by CAPE Sandbox for malware samples on MalwareBazaar.

ClamAV ClamAV


Top detections by ClamAV for malware samples on MalwareBazaar.

Intezer Intezer


Top detections by Intezer for malware samples on MalwareBazaar.

Joe Sandbox Joe Sandbox


Top detections by Joe Sandbox for malware samples on MalwareBazaar.

CERT.PL MWDB CERT.PL MWDB


Top detections by CERT.PL MWDB for malware samples on MalwareBazaar.

ReversingLabs ReversingLabs


Top detections by ReversingLabs Titanium Platform for malware samples on MalwareBazaar.

Threatray Threatray


Top detections by Threatray for malware samples on MalwareBazaar.

Triage Triage


Top detections by Triage for malware samples on MalwareBazaar.

UnpacMe UnpacMe


Top detections by UnpacMe for malware samples on MalwareBazaar.

VMRay VMRay


Top detections by VMRay for malware samples on MalwareBazaar.

FileScan.IO FileScan.IO


Top classifications by FileScan.IO for malware samples on MalwareBazaar.

Most discussed Malware Samples


Most discussed (commented) malware samples on MalwareBazaar.

CommentsMalware SampleTypeSignature
1097bb6f30d2fe5546a810da356e41652d1bccfe2130cf77dec36b9ee17c19259dExcel file xlsDridex
6d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77bExecutable exeTrickBot
47277388a0a82e85fe6eb38ed47bd5640c74f10be64ee6e9b8610c49b73328859 7zHawkEye
3f4841b9b9006e327d58c8d6fb6e1bb3699d05fcd10fcaf7adcdde47efccb13b3 zipAgentTesla
3e97b35c4339e0412571a445b2fe20e30fe91585cad505820b56a098a66e54c23Executable exeAgentTesla
30994e0972430f7cf02b66c290b6e62666c14da2ca9ad369e7cf5447313dc8550Executable exeTrickBot
3667f88e8dcd4a15529ed02bb20da6ae2e5b195717eb630b20b9732c8573c4e83Word file docPhobos
2df822aa4ae822b89d8f1c6b4afe3f9bf4679b7c9872bd95d3cbfab366a57edcaHTML Application (hta) hta 
22b7bdd0b8bde43d8e9d9a32352a408c5028e2a39c694be064a6ed18d0aa830e7Executable exeStop
2251643f0b539eb872ebeb216f1b71f0f8dc8301276ea63dbfdf10a7267ac7379 zip 

Top File Types


Most seen file types associated with malware samples on MalwareBazaar.

Top imphashes


Most seen imphashes on MalwareBazaar.

Malware SampleimphashTop 4 Signatures
81'883f34d5f2d4577ed6d9ceec516c1f5a744AgentTesla Formbook SnakeKeylogger Loki
9'777c9f7e018b269f1b5fe81cf757d6f8e93Heodo
8'608987b9d7dc84d935c3675da82d40e06f2Dridex Gozi Tofsee VelvetSweatshopDridex
3'24787bed5a7cba00c7e1f4015f1bdae2183Jadtre IcedID TrickBot Netsky
2'180433637d5d88b1ab11a7e5bfc30abfe93Dridex
1'9617fa974366048f9c551ef45714595665eFormbook Loki AgentTesla SnakeKeylogger
1'95850f8a2255c4baf188eb0098c86160f78Heodo
1'723d20e8b584b1e294911b88a699c987910Dridex
1'677afcdf79be1557326c854b6e20cb900a7AgentTesla RemcosRAT NanoCore QuasarRAT
1'586f71b9cb9891e9cf4bae79d2b5aa115c6Dridex

Top ssdeep hashes


Most seen ssdeep hashes on MalwareBazaar.

Malware SamplessdeepSignature(s)
1'12412288:J2+J+l5QvSoOUkQNPRoswLLjfsHJNF05s:AJl5QrrkQFCHspN4Quakbot
1'12312288:U2+J+l5QvSoOUkQGPRoswLLjfsHJNF05F:PJl5QrrkQOCHspN4Quakbot
1'12112288:l2+J+l5QvSoOUkQiPRoswLLjfsHJNF05h:8Jl5QrrkQaCHspN4Quakbot
5281536:1I+Hymsbck3hbdlylKsgqopeJBWhZFGkE+cMLxAAISQ5gQ72IotO6nitSU6U+x:1I+HymsYk3hbdlylKsgqopeJBWhZFGkzSilentBuilder Heodo
4191536:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIzSEV2NnX4Ia3gg5W8IuD7PoHsP7e3/:H0k3hbdlylKsgqopeJBWhZFGkE+cMLxzSilentBuilder Heodo
416768:0Jlk3hbdlylKsgqopeJBWhZFGkE+cMLxAAIZEtm/piJaiyH5YnJe+eO+8WoFYpLd:0rk3hbdlylKsgqopeJBWhZFGkE+cMLx6SilentBuilder Heodo
4011536:u8rk3hbdlylKsgqopeJBWhZFGkE+cL2NdAE6yHBEL70drpFk0GX/s2C6ORQYDBhQ:ugk3hbdlylKsgqopeJBWhZFGkE+cL2N8SilentBuilder Heodo
3733072:IFNthWQl/rSJ7lvt9filcZritkrINAEYsm2:IBhWQ/mJLflrOAp2Gozi Heodo
3513072:zs+Hyms0k3hbdlylKsgqopeJBWhZFGkE+cMLxAAIb4UgCEqM5mheHRAjNKnlGIz/:o+Hyms0k3hbdlylKsgqopeJBWhZFVE+PSilentBuilder Heodo
30712288:xyP2Md2hn+tDKFtKwK5KLK6KYK5KlK3K1aoNl7Mv+lwVwy:grdO+tDKFQoNOmlTrickBot

Top dhash icon


Most seen dhashes of icons from PE32 executables and their signatures.

Malware Sampledhash iconSignature(s)
3'63871b119dcce5763333'387 x Heodo, 200 x TrickBot, 9 x BazaLoader
3'023b2a89c96a2cada721'339 x Formbook, 779 x Loki, 256 x AgentTesla
8360000000000000000147 x AgentTesla, 129 x Heodo, 124 x Formbook
77979756cecb29999b9729 x Heodo, 20 x Nitol, 16 x CobaltStrike
754399998ecd4d46c0e481 x Quakbot, 137 x ArkeiStealer, 26 x Smoke Loader
456b2dacabecee6baa6137 x RedLineStealer, 76 x Stop, 58 x RaccoonStealer
389ead8ac9cc6e68ee0118 x RaccoonStealer, 102 x RedLineStealer, 46 x Smoke Loader
33171e87c746071f0ec324 x Heodo, 6 x BazaLoader, 1 x TrickBot
3299494b494d4aeaeac84 x DCRat, 35 x njrat, 34 x RedLineStealer
3104839b234e8c38890121 x RaccoonStealer, 54 x RedLineStealer, 51 x ArkeiStealer