#4 on MalwareBazaar, nineteen days in — what that proves, and what it does not
whack.sh launched on August 6th. Nineteen days later it is the fourth-largest contributor to abuse.ch MalwareBazaar over the past thirty days — listed alongside GovCERT.ch, Switzerland's national computer emergency response team, and researchers with unbroken streaks going back two, three and six years.
We did not set out to climb a leaderboard. But it is a useful thing to be able to point at, so here is what it does and does not mean.
What we have contributed
Every payload our scanners trip is captured, defanged, hashed and given back to the community's threat-intel platforms. Free, no account, no gate — the same feeds every defender already uses:
- 780 samples to MalwareBazaar
- 2,975 indicators to AlienVault OTX
- 673 samples to VirusTotal
Those are per-platform counts, not three slices of one number and not a total to be added up — a single sample frequently goes to more than one destination, and OTX counts indicators rather than payloads alone. The live figures, the family breakdown and the SHA-256 list are on our threat-intel contributions page, which updates every six hours.
What is actually in it
Twenty-four distinct families so far, and the shape is worth being honest about:
- Mirai — 418 samples (55%)
- Unclassified — 219 (28%)
- CoinMiner — 52
- ConnectWise, Vidar — 13 each
- A long tail: PureLogsStealer, RemusStealer, njrat, AgentTesla, Formbook, AsyncRAT, QuasarRAT, Amadey, MassLogger and a dozen more, down to single samples
Mirai dominating is not a surprise and it is not a boast. Mirai droppers are among the most widely distributed payloads on the internet, and any pipeline pointed at live malicious URLs will surface them in volume. If you want to read that skew as "a lot of one common thing", that is a fair reading.
What this proves, and what it does not
The honest claim is narrow, so we will make it precisely.
It proves the detection pipeline works on real, current, live malware. Not on a curated test corpus, not on samples from a paper. These are payloads that were being served to real visitors at the moment we captured them, on infrastructure that was live, verified independently by three separate platforms that had no reason to take our word for anything. When a scanner tells you a URL is hosting something dangerous, the reasonable question is whether it is right. This is the third-party answer to that question, and anyone can check it — the submissions are public and attributed.
It does not prove we are finding things nobody else could. A leaderboard measures volume, and volume is the easiest thing to measure. Much of this corpus originates from URLs that were already known to be malicious. Being fourth by count is a statement about throughput and coverage, not about novelty, and we would rather say so than let you infer otherwise.
The interesting work is the part that does not show up in these numbers yet, and we will write about it when we can show it rather than assert it.
Why give it away
Every sample we contribute makes the feeds slightly better for everyone, including people who will never pay us anything, including our competitors. That is the correct trade. Threat intelligence that only circulates among paying customers protects the people who can afford it and leaves everyone else carrying the same risk with less warning. The economics of malware distribution already favour the attacker; hoarding indicators widens that gap.
abuse.ch in particular runs a set of platforms that a very large part of the defensive internet quietly depends on, largely without funding and largely without credit. Contributing to MalwareBazaar is the cheapest possible way for us to be a net positive to that, and it costs us nothing we would not have spent anyway.
What is next
There is a structural gap in the public corpora that we keep running into: payloads gated behind traffic distribution systems are systematically underrepresented, because the thing that makes a TDS a TDS is that it does not serve to whoever asks. A scanner that looks like a datacenter gets a harmless page. Someone on a residential connection with the right referrer gets the payload.
We are building toward measuring that properly. When we have something demonstrable we will publish the measurements, not the conclusions.
In the meantime, the contribution page is live and public: whack.sh/malware-bazaar. If you are a researcher and want the SHA-256 list or the JSON, both are one click from that page, and you do not need an account.
whack