Threat-Intel Contributions

Every payload our scanners trip is captured, defanged, hashed, and contributed back to the community's most trusted threat-intel platforms: abuse.ch MalwareBazaar and ThreatFox, VirusTotal, and AlienVault OTX. Samples go to MalwareBazaar; the URLs that served them go to ThreatFox as attributed IOCs. This page is live, public proof that whack.sh's multi-egress capture pipeline catches real, current malware, including samples that only appear when the target is probed from a residential or mobile vantage.

1116 contributed to VirusTotal  •  1528 to MalwareBazaar  •  4836 to OTX  •  330 IOCs to ThreatFox

unclassified ×940 Mirai ×384 VShell ×54 CoinMiner ×41 ConnectWise ×31 Snowlight ×13 Vidar ×13 Gafgyt ×11 RemusStealer ×6 njrat ×6 AsyncRAT ×4 Formbook ×3 QuasarRAT ×2 MaskGramStealer ×2 AdaptixC2 ×2 SalatStealer ×1 Troldesh ×1 MillenuimRAT ×1 SantaStealer ×1 NetSupport ×1 Meterpreter ×1 Blackmoon ×1 Amadey ×1 AgentTesla ×1 Stealc ×1 MassLogger ×1 Worm.Ramnit ×1 XWorm ×1 Redosdru ×1 SVCStealer ×1 VenomRAT ×1

Family Type Size First seen Detection Vantage Sample
unclassified 0 B - Cloaked 96% 62ee3a4c45d7
unclassified 0 B - Cloaked 95% 47ea48df2b1f
unclassified 0 B - Cloaked 90% 4eca4d922535
unclassified 0 B - Cloaked 85% 4255633e0b66
unclassified 0 B - Cloaked 95% 1b7d970654a2
unclassified 0 B - Cloaked 99% b16b9268496e
unclassified 0 B - Cloaked 89% 42c1c6f55b3d
unclassified 0 B - Cloaked 95% 191258cac084
unclassified 0 B - Cloaked 100% 3341d939b43c
unclassified 0 B - Cloaked 95% ec0e9d822556
unclassified 0 B - Cloaked 89% fa02ab08a5c0
unclassified 0 B - Cloaked 100% 95304928e122
unclassified 0 B - Cloaked 92% 3325db3b0a33
unclassified 0 B - Cloaked 89% 9ae9121f3f56
unclassified 0 B - Cloaked 93% a4acb7d88595
unclassified 0 B - Cloaked 99% 7da8c7aa6b48
unclassified 0 B - Cloaked 95% f8d105d5ae7e
unclassified 0 B - Cloaked 85% 68a5be8895dd
unclassified 0 B - Cloaked 90% 18e203c42d61
unclassified 0 B - Cloaked 100% 7628144c2c2c
unclassified 0 B - Cloaked 93% e705548bb935
unclassified 0 B - Cloaked 80% 6759c72365d0
unclassified 0 B - Cloaked 99% 0249201e9aa9
CoinMiner EXE 5.0 MB 2026-08-22 SecuriteInfo.com.Win64.Evo-gen.11832556.UNOFF... Cloaked 96% 7dc2493b4e86
unclassified 0 B - Cloaked 81% e9639e3c4681

Vantage shows how a sample stayed hidden: Residential/Mobile-only means our datacenter leg was served a decoy while a residential or mobile leg was handed the real payload; Cloaked N% is the multi-egress divergence measured on an actively-evasive target. A dash means the sample was captured on the datacenter leg too.
Live from our scanners, refreshed daily. Showing the most recent 25 of 1528 contributions on MalwareBazaar.

ThreatFox: IOCs

Where MalwareBazaar takes the sample, ThreatFox takes the indicator: the URL that served it, attributed to a malware family wherever an independent source (abuse.ch's own classification of the hash, or VirusTotal's cross-engine consensus) will name one. Where nobody will, we publish it as unknown and let the tags carry the detail, rather than guess. Every URL below is defanged; the live record is on ThreatFox.

330 IOCs contributed  •  313 carrying a named malware family

Mirai ×86 Unknown Loader ×53 VShell ×34 Bashlite ×18 Coinminer ×14 Unknown Stealer ×14 Vidar ×11 Phorpiex ×9 Remcos ×8 Tsunami ×6 Formbook ×6 AsyncRAT ×5

IOCTypeMalwareConfidenceTagsFirst seenRecord
52aba825c78ba1c28abf967c21a92232dd689eae0ad682c124c84... sha256_hash Coinminer 100% a47659cdad283e9dcd10da78ff795967 CoinMiner dropped-by-remus exe 2026-09-16 view →
dc834c0c0982771016202f3ca1808d3bba329379eba79e1d04db3... sha256_hash Unknown Loader 85% Dropper exe 2026-09-16 view →
f959a8494f2a1c4e11f346ae8e3099593f156be2a5c8010d1747e... sha256_hash Venom RAT 100% exe venomrat 2026-09-16 view →
9109d9bd117f540aed9afa6f293c1396cc18ed979056eadca97c6... sha256_hash AsyncRAT 100% asyncrat exe 2026-09-16 view →
f6f7dbd6561e7ee6ba7e6abffdb1e5de01bf511318aade34825d8... sha256_hash AsyncRAT 100% asyncrat exe 2026-09-16 view →
afd47ef7378e573c8e575b2030355a2b65a888bdaf56c00a1e6f8... sha256_hash Unknown Loader 85% Dropper exe 2026-09-16 view →
9b1d38cd728ec1a478db668e86f7445ab5f0335b388feefc15502... sha256_hash Venom RAT 100% exe venomrat 2026-09-16 view →
1a0c3d520e16ae12ffa918032e608f573b716f009a05c35f64b53... sha256_hash Unknown Loader 85% Dropper exe 2026-09-16 view →
28f83470b477e89081c08772af0470c6e841cc01c6bef4472f3b8... sha256_hash Unknown Loader 85% Dropper exe 2026-09-16 view →
5d66aefd528ecd9fbd31bf6def4d9f045cbbfd237a3e5e565e9a2... sha256_hash Coinminer 100% a47659cdad283e9dcd10da78ff795967 CoinMiner dropped-by-remus exe 2026-09-15 view →
35c226d7a959c858a6c0f91215a949371d60210939154d5e63d78... sha256_hash Coinminer 100% a47659cdad283e9dcd10da78ff795967 CoinMiner dropped-by-remus exe 2026-09-15 view →
9b1f88a9438254cf36932cf0ab696411ac2891c698f9d98da6556... sha256_hash Mirai 100% elf Mirai 2026-09-15 view →
37cbee9242444dffe560c8f2dfefa6ec0ff4bda186824bb5ace22... sha256_hash SalatStealer 95% exe SalatStealer stealer upx 2026-09-15 view →
74a28581cdc96b69d58c1b2f640c2f3c6932d11eb4b53fb5bf9cf... sha256_hash Unknown Loader 95% d52f85 dropped-by-amadey Dropper exe 2026-09-15 view →
052f0caff530a67f9a17df5795806d9b01a551f309e434cd4eb92... sha256_hash GCleaner 100% d52f85 dropped-by-amadey exe GCleaner 2026-09-15 view →
b9956521c3fb26cfb49791e6c3b29faae02ab8ac12314c2207f4f... sha256_hash Unknown Loader 85% Dropper exe 2026-09-15 view →
2e54785c850529f281f91edd3f90ed866c883dd034bc7053c4068... sha256_hash Mirai 100% elf Mirai 2026-09-15 view →
07bfd97e419f739258c04c8bc976ae6add8bd2936c97471642a75... sha256_hash Mirai 100% elf Mirai 2026-09-15 view →
50774a5f75176f9698fc536e82a6106c04ccd1db4f1d788574fdb... sha256_hash Unknown Stealer 100% exe RemusStealer stealer 2026-09-14 view →
d2f5c40128718130f164c3e2423bd2fb346c8c6ba7b7e0d08caf2... sha256_hash VShell 95% exe Vshell 2026-09-14 view →
ff69af09f1dba3c4ede99a5f5837ddff5ac3cb71621d4cd3f2da1... sha256_hash Mirai 100% elf Mirai 2026-09-14 view →
0f017eac0a0bd2f5c04a2be165a1f3e9d3146b9bf20e6cc7f96c1... sha256_hash Troldesh 95% exe Troldesh 2026-09-14 view →
994b914dc77a84a9adbe5ba1c49cd6bab320924c4d0938134d5c4... sha256_hash VShell 95% exe Vshell 2026-09-14 view →
c66e9d85ddd7bb98a60b1823e1cc7cb27035da727744c03735317... sha256_hash VShell 95% exe Vshell 2026-09-14 view →
fc04b7b1134f7c2f1d7e9fb71294d9c623e4c5455284ceb562af3... sha256_hash VShell 95% exe Vshell 2026-09-14 view →

compromised host marks a legitimate site serving malware without its owner's knowledge, reported to ThreatFox as a compromised asset rather than as attacker infrastructure, so the domain's reputation is not damaged by our report.
Showing the most recent 25 of 330 IOCs.

View all on ThreatFox →

Get these before they hit MalwareBazaar

Real-time push of novel captures via the whack.sh Pro Feed API: sub-second webhook callbacks the moment a payload is captured, hours before it propagates to the public feeds. STIX 2.1 / CSV / JSON.

Start scanning free

View all on MalwareBazaar → Our abuse.ch profile →