Threat feed
MalwareBazaar Full
Last fetched
Malware Distribution · refreshed hourly · last verified
MalwareBazaar Full is a Malware Distribution threat-intelligence feed, refreshed hourly, indexed by WhisperGraph.
What is MalwareBazaar Full
MalwareBazaar Full is the complete historical export of abuse.ch's MalwareBazaar malware-sample repository, as opposed to the rolling-window Recent view also indexed here. It carries every sample abuse.ch has catalogued since the project launched, each tagged with a malware family, a first-seen timestamp, and community-submitted YARA rules. Because it is the full archive rather than a recent slice, it is primarily used for retrospective hunting and for building family-level detection signatures rather than for real-time blocking. It is indexed here because the full export is the canonical reference dataset behind most YARA-based malware classification tooling.
- Source
- https://bazaar.abuse.ch/
- Refresh cadence
- hourly
Category drift. The curated category for this feed is Malware Distribution, while WhisperGraph currently files it under malware-distribution.
Indicators currently listed
No indicator in WhisperGraph currently links to MalwareBazaar Full. That is not the same as the feed being empty — the graph indexes a subset of every feed’s published entries.
Related pages
Pivot from MalwareBazaar Full into the indicators it lists.
Queries
Resolves the feed's categories.
MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categoriesRun yourself →The indicator-kind rollup and sample listed above.
MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESCRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.