🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


1'863

IOCs shared (past 24 hours)

Unknown Loader

Most seen malware family (past 24 hours)

1'785'213

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2026-08-08 17:26a4895d35b29bd056cfedbf16a7fc28f4d1ce00795e395a68155c02eb89d616bc ElectroRAT Grim
2026-08-08 17:2617e2bab3497fe60327d2f145e93f5e6cf22abae6 ElectroRAT Grim
2026-08-08 17:2637ac69c903d0c1c196b3159a55417dcb ElectroRAT Grim
2026-08-02 15:20c6c0210e1e5828aef772a030ce9a4e93f31c1848 ElectroRAT Grim
2026-08-02 15:2024dc5145757e9f438e801518bc74c0c7 ElectroRAT Grim
2026-08-02 15:200ffec6082c9540ac473d603f278168458f574ac9018ba5ed9b7b1e7ec1539133 ElectroRAT Grim