ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


532

IOCs shared (past 24 hours)

ClearFake

Most seen malware family (past 24 hours)

1'730'493

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2026-06-22 16:57ea41ab57edc9a9a1cb1ae258325d6519f5d23571 GHOSTBLADE Grim
2026-06-22 16:573b2a2777cead3c4981d4b2106c1ec4b4 GHOSTBLADE Grim
2026-06-22 16:57ecaedc68c09154f9e97673d84d1860d5755828182a42f6aab64ab3766ce47396 GHOSTBLADE Grim
2026-06-22 16:57d7982957ccd47d3603494688dc4a3d1a6d5183f9 GHOSTBLADE Grim
2026-06-22 16:574b1fd32206aa2831edead99efe88549a GHOSTBLADE Grim
2026-06-22 16:57be4bb2ea6fc6959cdeb63238018761be56adb2d1e69e7c3d3340272187198b5d GHOSTBLADE Grim