Threat-Intel Contributions

Every payload our scanners trip is captured, defanged, hashed, and contributed back to the community’s most trusted threat-intel platforms — abuse.ch MalwareBazaar, VirusTotal, and AlienVault OTX. This page is live, public proof that whack.sh’s multi-egress capture pipeline catches real, current malware — including samples that only appear when the target is probed from a residential or mobile vantage.

303 contributed to VirusTotal  •  328 to MalwareBazaar  •  1748 to OTX

Mirai ×136 unclassified ×110 CoinMiner ×29 Vidar ×7 njrat ×5 ConnectWise ×4 DDoSAgent ×3 AgentTesla ×2 PureLogsStealer ×2 RemusStealer ×2 MaskGramStealer ×2 Ladvix ×1 AsyncRAT ×1 Formbook ×1 RustyStealer ×1 ZigClipper ×1 SantaStealer ×1 Redosdru ×1 QuasarRAT ×1

Family Type Size First seen Detection Vantage Sample
unclassified EXE 2.8 MB 2026-08-16 Cloaked 96% 77981cb7370d
unclassified EXE 5.0 MB 2026-08-16 Cloaked 96% 47ec52063197
unclassified EXE 2.9 MB 2026-08-15 Cloaked 96% df159312ca87
unclassified EXE 2.8 MB 2026-08-15 Cloaked 96% 9b2a69e41403
unclassified EXE 2.8 MB 2026-08-15 Cloaked 96% 74e636d09c7a
unclassified EXE 5.0 MB 2026-08-15 Cloaked 97% f91b79e3699e
Mirai ELF 118.2 KB 2026-08-15 Sanesecurity.Malware.31075.LX.BOT.UNOFFICIAL Cloaked 98% 70c037b40986
unclassified EXE 2.8 MB 2026-08-15 Cloaked 96% 9430beeddeb4
unclassified EXE 2.8 MB 2026-08-15 Cloaked 96% 1a92991e4723
unclassified EXE 2.8 MB 2026-08-15 Cloaked 96% cd4d9ce29b22
CoinMiner EXE 5.0 MB 2026-08-15 Cloaked 96% 7aff13bfb7e0
unclassified EXE 2.8 MB 2026-08-15 SecuriteInfo.com.Win64.Evo-gen.25195333.UNOFF… Cloaked 96% 1adc02d8d3ed
unclassified EXE 2.8 MB 2026-08-15 SecuriteInfo.com.Win64.Evo-gen.22846626.UNOFF… Cloaked 96% 286b9aae20d8
CoinMiner EXE 5.0 MB 2026-08-15 SecuriteInfo.com.Win64.Evo-gen.46497519.UNOFF… Cloaked 96% 79c3a51a94ba
unclassified ZIP 3.7 MB 2026-08-15 Sanesecurity.Malware.32567.UNOFFICIAL Cloaked 85% b2aea974ca63
ConnectWise MSI 9.6 MB 2026-08-15 Cloaked 95% b66415933fbe
unclassified EXE 2.8 MB 2026-08-15 SecuriteInfo.com.Win64.Evo-gen.66722253.UNOFF… Cloaked 96% 43ed61242830
Ladvix ELF 2.3 MB 2026-08-15 SecuriteInfo.com.Linux.DownLoader.2773.6040.7… Cloaked 95% 3b2cbd1dd7e0
unclassified EXE 2.8 MB 2026-08-15 SecuriteInfo.com.Win64.Evo-gen.44138731.UNOFF… Cloaked 96% 692e5fff4ad9
CoinMiner EXE 5.0 MB 2026-08-15 SecuriteInfo.com.Win64.Evo-gen.33151136.UNOFF… Cloaked 96% acc1d1aab8ac
Mirai ELF 70.2 KB 2026-08-15 SecuriteInfo.com.Linux.Rootkit.420.13131.5020… Cloaked 90% 8edbfc6979fd
unclassified ZIP 481.0 KB 2026-08-15 SecuriteInfo.com.VBS.Obfus-141.UNOFFICIAL Cloaked 87% 839b184f7816
Mirai ELF 46.7 KB 2026-08-15 SecuriteInfo.com.Linux.Mirai-18.UNOFFICIAL Cloaked 90% 5fa395bbe688
Mirai ELF 51.0 KB 2026-08-15 SecuriteInfo.com.Linux.Mirai-20.UNOFFICIAL Cloaked 90% e3b410b16785
Mirai ELF 45.0 KB 2026-08-14 SecuriteInfo.com.Linux.Mirai-18.UNOFFICIAL Cloaked 90% 376c342dc426

Vantage shows how a sample stayed hidden — Residential/Mobile-only means our datacenter leg was served a decoy while a residential or mobile leg was handed the real payload; Cloaked N% is the multi-egress divergence measured on an actively-evasive target. A dash means the sample was captured on the datacenter leg too.
Live from our scanners — refreshed daily. Showing the most recent 25 of 310 contributions on MalwareBazaar.

Get these before they hit MalwareBazaar

Real-time push of novel captures via the whack.sh Pro Feed API — sub-second webhook callbacks the moment a payload is captured, hours before it propagates to the public feeds. STIX 2.1 / CSV / JSON.

Start scanning free

View all on MalwareBazaar → Our abuse.ch profile →