Provide malware datasets and threat intelligence feeds.
MalDatabase provides an API for accessing threat intelligence data on malware samples. The API offers a single GET /download endpoint that returns a daily feed (updated at 1:00 UTC), authenticated via an API key issued after registration. Response data is gzip-encoded JSON.
Each feed entry includes sample identifiers (SHA256, SHA1, MD5 hashes), a threat level rating from 0 to 2, the detected malware family, file size and type, along with observed behavioral indicators such as contacted domains, executed processes, and dropped files.
The service is intended for building scripts and integrating malware feed data into other systems. Use in commercial services or on behalf of a third-party business is prohibited without a partnership agreement, and violations result in indefinite account suspension.
Requests use an Authorization header containing an API key that is provided by the Maldatabase team after registration.
No, the API must not be used in commercial services or for the benefit of a third-party business without contacting Maldatabase for a partnership.
The daily feed is updated every day at 1:00 UTC.
The feed is returned as gzip-encoded JSON containing sample records with hashes, threat level, family, and behavioral indicators.
Show your product to thousands of developers
· 100k monthly pageviews
· 7k newsletter subscribers
Fraud & reputation detection.
A volunteer cybersecurity project focused on providing resources and services that improve safety across Discord.
Google Link/Domain Flagging.
Malware Archive / file sourcing.
Collect and share malware samples.
Metacert Link Flagging.