🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


750

IOCs shared (past 24 hours)

Unknown malware

Most seen malware family (past 24 hours)

1'775'083

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2026-09-10 17:5562b07d9d1a68010bfdc39df0f22996c386162d53a328ab59a9becb1a30d1a454 Redosdruexe Redosdru whack_sh
2026-07-05 16:220b5439d135dc4d685e3fa346ac56dc89713b1a86 Redosdru Grim
2026-07-05 16:22b2f641209efa51dda327fb48bafd0986 Redosdru Grim
2026-07-05 16:22f65a25e37c7abc88d641e13004c4e5523502b4568cfcf6713f4f50e34f23e770 Redosdru Grim
2025-05-25 02:18a160027f695207ee2a699583542a1bd7 Redosdru Grim
2025-05-25 02:18794dac27e06ce148fc15fb150b3da035b602f009ef849adae9cd45d3ffeccf84 Redosdru Grim
2025-05-25 02:1807385f7ba5428e3e728ef6aa047c8b2211ecdb37 Redosdru Grim