🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


1'878

IOCs shared (past 24 hours)

Unknown Loader

Most seen malware family (past 24 hours)

1'784'866

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2026-09-22 14:29b8466d751faa6f9b65a47ef57cfd258d WolfRAT Grim
2026-09-22 14:29318596313d7128a17761c04566ae7668ae2af41d WolfRAT Grim
2026-09-22 14:292c530f2e10db77881730e7a9ec4e72244d59149fc8981a4f49c6e0fadc5fecee WolfRAT Grim