Collect and share malware samples.
MalwareBazaar is an API operated by abuse.ch for submitting, downloading, and querying malware samples. It supports queries by hash, tag, signature, filetype, ClamAV signature, imphash, TLSH, telfhash, gimphash, icon dhash, YARA rule, and code signing certificate details, as well as retrieval of recent detections, latest sample additions, hourly and daily malware batches, and a code signing certificate blocklist. Access requires an Auth-Key obtained free of charge through the abuse.ch Authentication Portal, and all API interactions must include this key in the request header.
Use of the community API is free under fair use principles; companies, networks, or individuals with commercial or for-profit needs may require a paid subscription to an enhanced commercial API that offers additional reliability, stability, and a unified query language across abuse.ch APIs. Submissions to MalwareBazaar are subject to a policy restricting uploads to confirmed and vetted malware no older than 10 days, excluding adware and file infectors; repeated policy violations can result in account bans. Downloaded samples are provided as password-protected zip files, and a daily download limit applies.
The service is intended for security researchers, threat intelligence teams, and malware analysts who need to contribute to or query a shared malware sample repository, with example Python scripts and a Java API client provided for integration.
The Community API is available free of charge under fair use principles. Commercial or for-profit use may require a paid subscription to the enhanced abuse.ch commercial API.
You must obtain a free Auth-Key from the abuse.ch Authentication Portal and include it in the Auth-Key HTTP header on every request.
You can upload confirmed malware samples and download samples by SHA256 hash; downloaded files are zipped and password protected with the password "infected".
Example Python3 scripts and a Java API client are provided for interacting with the API.
It is intended for security researchers and organizations doing malware analysis, with a submission policy restricting uploads to confirmed, fresh malware samples and prohibiting adware or file infectors.
Show your product to thousands of developers
· 100k monthly pageviews
· 7k newsletter subscribers
Google Link/Domain Flagging.
Provide malware datasets and threat intelligence feeds.
Malware Archive / file sourcing.
Metacert Link Flagging.
Simple REST API that can scan submitted documents/files for the presence of threats.
Bulk queries and Download Malware Samples.