Public APIs
MalwareBazaar favicon

MalwareBazaar

Anti-Malware

Collect and share malware samples.

MalwareBazaar's website screenshot

About MalwareBazaar

MalwareBazaar is an API operated by abuse.ch for submitting, downloading, and querying malware samples. It supports queries by hash, tag, signature, filetype, ClamAV signature, imphash, TLSH, telfhash, gimphash, icon dhash, YARA rule, and code signing certificate details, as well as retrieval of recent detections, latest sample additions, hourly and daily malware batches, and a code signing certificate blocklist. Access requires an Auth-Key obtained free of charge through the abuse.ch Authentication Portal, and all API interactions must include this key in the request header.

Use of the community API is free under fair use principles; companies, networks, or individuals with commercial or for-profit needs may require a paid subscription to an enhanced commercial API that offers additional reliability, stability, and a unified query language across abuse.ch APIs. Submissions to MalwareBazaar are subject to a policy restricting uploads to confirmed and vetted malware no older than 10 days, excluding adware and file infectors; repeated policy violations can result in account bans. Downloaded samples are provided as password-protected zip files, and a daily download limit applies.

The service is intended for security researchers, threat intelligence teams, and malware analysts who need to contribute to or query a shared malware sample repository, with example Python scripts and a Java API client provided for integration.

Key features

  • Submit and download malware samples via API
  • Query samples by hash, tag, signature, filetype, or imphash
  • Query Code Signing Certificates by issuer, subject, or serial number
  • Download hourly and daily malware sample batches
  • Query latest malware samples and recent detections
  • Add comments and update entries via API

Frequently asked questions

Is the MalwareBazaar API free to use?

The Community API is available free of charge under fair use principles. Commercial or for-profit use may require a paid subscription to the enhanced abuse.ch commercial API.

How do I authenticate API requests?

You must obtain a free Auth-Key from the abuse.ch Authentication Portal and include it in the Auth-Key HTTP header on every request.

What can I submit or retrieve through the API?

You can upload confirmed malware samples and download samples by SHA256 hash; downloaded files are zipped and password protected with the password "infected".

Are there example clients available?

Example Python3 scripts and a Java API client are provided for interacting with the API.

Who is this API for?

It is intended for security researchers and organizations doing malware analysis, with a submission policy restricting uploads to confirmed, fresh malware samples and prohibiting adware or file infectors.

Advertise here

Featured products

  • SerpApi - Search API favicon
  • Screenshot Scout favicon
  • TalorData favicon
  • CoreClaw favicon

Show your product to thousands of developers

· 100k monthly pageviews
· 7k newsletter subscribers

Advertise your product