Threat-Intel Contributions
Every payload our scanners trip is captured, defanged, hashed, and contributed back to the community's most trusted threat-intel platforms: abuse.ch MalwareBazaar and ThreatFox, VirusTotal, and AlienVault OTX. Samples go to MalwareBazaar; the URLs that served them go to ThreatFox as attributed IOCs. This page is live, public proof that whack.sh's multi-egress capture pipeline catches real, current malware, including samples that only appear when the target is probed from a residential or mobile vantage.
1116 contributed to VirusTotal • 1528 to MalwareBazaar • 4836 to OTX • 330 IOCs to ThreatFox
unclassified ×940 Mirai ×384 VShell ×54 CoinMiner ×41 ConnectWise ×31 Snowlight ×13 Vidar ×13 Gafgyt ×11 RemusStealer ×6 njrat ×6 AsyncRAT ×4 Formbook ×3 QuasarRAT ×2 MaskGramStealer ×2 AdaptixC2 ×2 SalatStealer ×1 Troldesh ×1 MillenuimRAT ×1 SantaStealer ×1 NetSupport ×1 Meterpreter ×1 Blackmoon ×1 Amadey ×1 AgentTesla ×1 Stealc ×1 MassLogger ×1 Worm.Ramnit ×1 XWorm ×1 Redosdru ×1 SVCStealer ×1 VenomRAT ×1
| Family | Type | Size | First seen | Detection | Vantage | Sample |
|---|---|---|---|---|---|---|
| unclassified | 0 B | - | Cloaked 96% | 62ee3a4c45d7 |
||
| unclassified | 0 B | - | Cloaked 95% | 47ea48df2b1f |
||
| unclassified | 0 B | - | Cloaked 90% | 4eca4d922535 |
||
| unclassified | 0 B | - | Cloaked 85% | 4255633e0b66 |
||
| unclassified | 0 B | - | Cloaked 95% | 1b7d970654a2 |
||
| unclassified | 0 B | - | Cloaked 99% | b16b9268496e |
||
| unclassified | 0 B | - | Cloaked 89% | 42c1c6f55b3d |
||
| unclassified | 0 B | - | Cloaked 95% | 191258cac084 |
||
| unclassified | 0 B | - | Cloaked 100% | 3341d939b43c |
||
| unclassified | 0 B | - | Cloaked 95% | ec0e9d822556 |
||
| unclassified | 0 B | - | Cloaked 89% | fa02ab08a5c0 |
||
| unclassified | 0 B | - | Cloaked 100% | 95304928e122 |
||
| unclassified | 0 B | - | Cloaked 92% | 3325db3b0a33 |
||
| unclassified | 0 B | - | Cloaked 89% | 9ae9121f3f56 |
||
| unclassified | 0 B | - | Cloaked 93% | a4acb7d88595 |
||
| unclassified | 0 B | - | Cloaked 99% | 7da8c7aa6b48 |
||
| unclassified | 0 B | - | Cloaked 95% | f8d105d5ae7e |
||
| unclassified | 0 B | - | Cloaked 85% | 68a5be8895dd |
||
| unclassified | 0 B | - | Cloaked 90% | 18e203c42d61 |
||
| unclassified | 0 B | - | Cloaked 100% | 7628144c2c2c |
||
| unclassified | 0 B | - | Cloaked 93% | e705548bb935 |
||
| unclassified | 0 B | - | Cloaked 80% | 6759c72365d0 |
||
| unclassified | 0 B | - | Cloaked 99% | 0249201e9aa9 |
||
| CoinMiner | EXE | 5.0 MB | 2026-08-22 | SecuriteInfo.com.Win64.Evo-gen.11832556.UNOFF... | Cloaked 96% | 7dc2493b4e86 |
| unclassified | 0 B | - | Cloaked 81% | e9639e3c4681 |
Vantage shows how a sample stayed hidden: Residential/Mobile-only means our datacenter leg was served a decoy while a residential or mobile leg was handed the real payload; Cloaked N% is the multi-egress divergence measured on an actively-evasive target. A dash means the sample was captured on the datacenter leg too.
Live from our scanners, refreshed daily. Showing the most recent 25 of 1528 contributions on MalwareBazaar.
ThreatFox: IOCs
Where MalwareBazaar takes the sample, ThreatFox takes the indicator: the URL that
served it, attributed to a malware family wherever an independent source (abuse.ch's own
classification of the hash, or VirusTotal's cross-engine consensus) will name one. Where
nobody will, we publish it as unknown and let the tags carry the detail, rather than
guess. Every URL below is defanged; the live record is on ThreatFox.
330 IOCs contributed • 313 carrying a named malware family
Mirai ×86 Unknown Loader ×53 VShell ×34 Bashlite ×18 Coinminer ×14 Unknown Stealer ×14 Vidar ×11 Phorpiex ×9 Remcos ×8 Tsunami ×6 Formbook ×6 AsyncRAT ×5
| IOC | Type | Malware | Confidence | Tags | First seen | Record |
|---|---|---|---|---|---|---|
52aba825c78ba1c28abf967c21a92232dd689eae0ad682c124c84... |
sha256_hash | Coinminer | 100% | a47659cdad283e9dcd10da78ff795967 CoinMiner dropped-by-remus exe | 2026-09-16 | view → |
dc834c0c0982771016202f3ca1808d3bba329379eba79e1d04db3... |
sha256_hash | Unknown Loader | 85% | Dropper exe | 2026-09-16 | view → |
f959a8494f2a1c4e11f346ae8e3099593f156be2a5c8010d1747e... |
sha256_hash | Venom RAT | 100% | exe venomrat | 2026-09-16 | view → |
9109d9bd117f540aed9afa6f293c1396cc18ed979056eadca97c6... |
sha256_hash | AsyncRAT | 100% | asyncrat exe | 2026-09-16 | view → |
f6f7dbd6561e7ee6ba7e6abffdb1e5de01bf511318aade34825d8... |
sha256_hash | AsyncRAT | 100% | asyncrat exe | 2026-09-16 | view → |
afd47ef7378e573c8e575b2030355a2b65a888bdaf56c00a1e6f8... |
sha256_hash | Unknown Loader | 85% | Dropper exe | 2026-09-16 | view → |
9b1d38cd728ec1a478db668e86f7445ab5f0335b388feefc15502... |
sha256_hash | Venom RAT | 100% | exe venomrat | 2026-09-16 | view → |
1a0c3d520e16ae12ffa918032e608f573b716f009a05c35f64b53... |
sha256_hash | Unknown Loader | 85% | Dropper exe | 2026-09-16 | view → |
28f83470b477e89081c08772af0470c6e841cc01c6bef4472f3b8... |
sha256_hash | Unknown Loader | 85% | Dropper exe | 2026-09-16 | view → |
5d66aefd528ecd9fbd31bf6def4d9f045cbbfd237a3e5e565e9a2... |
sha256_hash | Coinminer | 100% | a47659cdad283e9dcd10da78ff795967 CoinMiner dropped-by-remus exe | 2026-09-15 | view → |
35c226d7a959c858a6c0f91215a949371d60210939154d5e63d78... |
sha256_hash | Coinminer | 100% | a47659cdad283e9dcd10da78ff795967 CoinMiner dropped-by-remus exe | 2026-09-15 | view → |
9b1f88a9438254cf36932cf0ab696411ac2891c698f9d98da6556... |
sha256_hash | Mirai | 100% | elf Mirai | 2026-09-15 | view → |
37cbee9242444dffe560c8f2dfefa6ec0ff4bda186824bb5ace22... |
sha256_hash | SalatStealer | 95% | exe SalatStealer stealer upx | 2026-09-15 | view → |
74a28581cdc96b69d58c1b2f640c2f3c6932d11eb4b53fb5bf9cf... |
sha256_hash | Unknown Loader | 95% | d52f85 dropped-by-amadey Dropper exe | 2026-09-15 | view → |
052f0caff530a67f9a17df5795806d9b01a551f309e434cd4eb92... |
sha256_hash | GCleaner | 100% | d52f85 dropped-by-amadey exe GCleaner | 2026-09-15 | view → |
b9956521c3fb26cfb49791e6c3b29faae02ab8ac12314c2207f4f... |
sha256_hash | Unknown Loader | 85% | Dropper exe | 2026-09-15 | view → |
2e54785c850529f281f91edd3f90ed866c883dd034bc7053c4068... |
sha256_hash | Mirai | 100% | elf Mirai | 2026-09-15 | view → |
07bfd97e419f739258c04c8bc976ae6add8bd2936c97471642a75... |
sha256_hash | Mirai | 100% | elf Mirai | 2026-09-15 | view → |
50774a5f75176f9698fc536e82a6106c04ccd1db4f1d788574fdb... |
sha256_hash | Unknown Stealer | 100% | exe RemusStealer stealer | 2026-09-14 | view → |
d2f5c40128718130f164c3e2423bd2fb346c8c6ba7b7e0d08caf2... |
sha256_hash | VShell | 95% | exe Vshell | 2026-09-14 | view → |
ff69af09f1dba3c4ede99a5f5837ddff5ac3cb71621d4cd3f2da1... |
sha256_hash | Mirai | 100% | elf Mirai | 2026-09-14 | view → |
0f017eac0a0bd2f5c04a2be165a1f3e9d3146b9bf20e6cc7f96c1... |
sha256_hash | Troldesh | 95% | exe Troldesh | 2026-09-14 | view → |
994b914dc77a84a9adbe5ba1c49cd6bab320924c4d0938134d5c4... |
sha256_hash | VShell | 95% | exe Vshell | 2026-09-14 | view → |
c66e9d85ddd7bb98a60b1823e1cc7cb27035da727744c03735317... |
sha256_hash | VShell | 95% | exe Vshell | 2026-09-14 | view → |
fc04b7b1134f7c2f1d7e9fb71294d9c623e4c5455284ceb562af3... |
sha256_hash | VShell | 95% | exe Vshell | 2026-09-14 | view → |
compromised host marks a legitimate site serving malware without its owner's
knowledge, reported to ThreatFox as a compromised asset rather than as attacker
infrastructure, so the domain's reputation is not damaged by our report.
Showing the most recent 25 of 330 IOCs.
Get these before they hit MalwareBazaar
Real-time push of novel captures via the whack.sh Pro Feed API: sub-second webhook callbacks the moment a payload is captured, hours before it propagates to the public feeds. STIX 2.1 / CSV / JSON.
Start scanning free
whack