ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


562

IOCs shared (past 24 hours)

ClearFake

Most seen malware family (past 24 hours)

1'727'147

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2022-01-21 19:00c76482802a369e6230d198123ceba32a801c6300fc7af306872a5a642adc445a Retefe Virus_Deck
2022-01-21 19:00f44b80767dd5d095a338f4a2ef6f80358b43764b4ec00827922bd7e4b19ecc83 Retefe Virus_Deck
2022-01-21 19:00fd0e2aab29278cdbb6fc77665adcbf334040b7a0a3bbda315b943009e84618a0 Retefe Virus_Deck
2022-01-21 19:008e679f87ba503f3dfad96266ca79de7bfe3092dc6a58c0fe0438f7d4b19f0bbd Retefe Virus_Deck