Statistics
ThreatFox produces detailed statistics on indicators of compromise shared - find the available statistics below.
You can also access Spamhaus's Malware Digest report, based on ThreatFox data:
The statistics below consider indicators of compromise (IOCs) submitted to ThreatFox within the past 14 days.
Number of IOCs shared
The chart below documents the number of indicators of compromise (IOCs) shared on ThreatFox per day over a period of 30 days.
Top Contributors
Threatfox is "just" a platform for sharing IOCs. It would be worthless without the help of volunteers who contribute their IOCs to the project. The table below shows the top contributors by credits earned for the past 30 days.
Rank | Reporter | Last activity | Credits earned | Submissions |
---|---|---|---|---|
1 | @Cryptolaemus1 | 2024-11-20 | 4'307'305 | 679'871 |
2 | @abuse_ch | 2024-11-20 | 703'830 | 107'562 |
3 | @drb_ra | 2024-11-13 | 694'965 | 88'255 |
4 | @Gi7w0rm | 2024-11-12 | 225'515 | 43'167 |
5 | @Grim | 2024-11-13 | 148'110 | 29'552 |
6 | @DonPasci | 2024-11-20 | 100'490 | 14'583 |
7 | @NDA0E | 2024-11-20 | 42'195 | 8'417 |
8 | @crep1x | 2024-11-19 | 35'570 | 7'041 |
9 | @abus3reports | 2024-11-12 | 35'060 | 6'336 |
10 | @Rony | 2024-11-20 | 25'750 | 4'551 |
Top Malware Families
Top Tags
IOCs by type
IOCs on ThreatFox are categorized so called IOC types. The following table shows the number of IOCs observed on ThreatFox per IOC type (past 14 days).
IOCs | IOC Type | IOC description |
---|---|---|
997 | ip:port | ip:port combination that is used for botnet Command&control (C&C) |
637 | domain | Domain that is used for botnet Command&control (C&C) |
620 | url | URL that delivers a malware payload |
576 | url | URL that is used for botnet Command&control (C&C) |
202 | domain | Domain name that delivers a malware payload |
200 | sha256_hash | SHA256 hash of a malware sample (payload) |
46 | md5_hash | MD5 hash of a malware sample (payload) |
32 | sha1_hash | SHA1 hash of a malware sample (payload) |
22 | ip:port | ip:port combination that delivery a malware payload |
The statistics below consider indicators of compromise (IOCs) submitted to ThreatFox since it's launch in March 2021.
Number of IOCs shared
The chart below documents the number of indicators of compromise (IOCs) shared on ThreatFox per day over a period of 12 months.
Top Contributors
Threatfox is "just" a platform for sharing IOCs. It would be worthless without the help of volunteers who contribute their IOCs to the project. The table below shows the top contributors by credits earned.
Rank | Reporter | Last activity | Credits earned | Submissions |
---|---|---|---|---|
1 | Cryptolaemus1 | 2024-11-20 | 4'307'305 | 679'871 |
2 | abuse_ch | 2024-11-20 | 703'830 | 107'562 |
3 | drb_ra | 2024-11-13 | 694'965 | 88'255 |
4 | Gi7w0rm | 2024-11-12 | 225'515 | 43'167 |
5 | lazyactivist192 | 2024-01-17 | 148'745 | 29'736 |
6 | Grim | 2024-11-13 | 148'110 | 29'552 |
7 | Virus_Deck | 2022-09-30 | 147'930 | 29'150 |
8 | thehappydinoa | 2024-10-15 | 142'150 | 23'608 |
9 | TheTallJohnBrown | 2024-03-14 | 129'115 | 25'823 |
10 | _CarlosCabal | 2022-06-09 | 107'965 | 21'593 |
Top Malware Families
Top Tags
IOCs by type
IOCs on ThreatFox are categorized so called IOC types. The following table shows the number of IOCs observed on ThreatFox per IOC type (overall).
IOCs | IOC Type | IOC description |
---|---|---|
724'799 | sha256_hash | SHA256 hash of a malware sample (payload) |
180'194 | url | URL that delivers a malware payload |
157'641 | ip:port | ip:port combination that is used for botnet Command&control (C&C) |
84'387 | url | URL that is used for botnet Command&control (C&C) |
58'538 | domain | Domain that is used for botnet Command&control (C&C) |
27'234 | domain | Domain name that delivers a malware payload |
13'039 | md5_hash | MD5 hash of a malware sample (payload) |
10'291 | sha1_hash | SHA1 hash of a malware sample (payload) |
2'532 | ip:port | ip:port combination that delivery a malware payload |
419 | domain | Domain used for credit card skimming (usually related to Magecart attacks) |
21 | sha3_384_hash | SHA3-384 hash of a malware sample (payload) |