🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.


417

IOCs shared (past 24 hours)

Cobalt Strike

Most seen malware family (past 24 hours)

1'775'735

IOCs in corpus


Using the form below, you can search for malware samples by a hash (MD5, SHA256, SHA1), imphash, tlsh hash, ClamAV signature, tag or malware family.

Browse Database


Search syntax is as follow: keyword:search_term

Following is a list of accepted keywords along with an example search_term

  • ioc:ms-debug-services.com ( run)
  • malware:CobaltStrike ( run)
  • tag:TA505 ( run)
  • threat_type:cc_skimming ( run)
  • uuid:87f310f3-540b-11eb-922c-42010aa4000a ( run)

Date (UTC)IOCMalwareTagsReporter
2026-09-12 15:314a88c4a8fd4ae358387fe70e97e93a1a Running RAT Grim
2026-09-12 15:31d68bd997fea85e2b9e2438e989397798ad214635dd4e43b733214876ac6fa19f Running RAT Grim
2026-09-12 15:31e132e1b5667f14a545166dbbf91a3a53c9afcd0c Running RAT Grim
2023-01-16 09:41sky.hobuff.info Running RATRAT RunningRAT abuse_ch
2023-01-16 09:41a.micrsoft.top Running RATRAT RunningRAT abuse_ch