🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


739

IOCs shared (past 24 hours)

Unknown malware

Most seen malware family (past 24 hours)

1'775'125

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2026-09-07 07:342a0e7f4e5f72631fbf592d6d1797f512f6c6eda2509aeb8e91f60c237d283720 GovRAT Grim
2026-09-07 07:34413e51015c071ec5b8632c81f64ba833ed6be15a GovRAT Grim
2026-09-07 07:3462d70cdf6d752d0e01c8bffcb46a7643 GovRAT Grim
2025-11-28 15:36aff7013afa70173409bf45460d8487279a458d7f GovRAT Grim
2025-11-28 15:36487b24cc7d7e6b803487df96271844c23b9235a43821d8e0447007f29babf5d0 GovRAT Grim
2025-11-28 15:36f090e9508efe48f62787097710ff4135 GovRAT Grim