ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


525

IOCs shared (past 24 hours)

ClearFake

Most seen malware family (past 24 hours)

1'730'475

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2026-08-07 20:127544d0d40c63ea020416d01832a366e5 Bateleur Grim
2026-08-07 20:12802dee2011a757a13f6afc236e66c6e8440bc733eb001d849286c22d43b0017e Bateleur Grim
2026-08-07 20:12659986fef1ee9fb6f019304a435a69ffe9335082 Bateleur Grim