Skip to content

Threat feed

MalwareBazaar Full

Last fetched

Malware Distribution · refreshed hourly · last verified

MalwareBazaar Full is a Malware Distribution threat-intelligence feed, refreshed hourly, indexed by WhisperGraph.

What is MalwareBazaar Full

MalwareBazaar Full is the complete historical export of abuse.ch's MalwareBazaar malware-sample repository, as opposed to the rolling-window Recent view also indexed here. It carries every sample abuse.ch has catalogued since the project launched, each tagged with a malware family, a first-seen timestamp, and community-submitted YARA rules. Because it is the full archive rather than a recent slice, it is primarily used for retrospective hunting and for building family-level detection signatures rather than for real-time blocking. It is indexed here because the full export is the canonical reference dataset behind most YARA-based malware classification tooling.

Refresh cadence
hourly

Category drift. The curated category for this feed is Malware Distribution, while WhisperGraph currently files it under malware-distribution.

Indicators currently listed

No indicator in WhisperGraph currently links to MalwareBazaar Full. That is not the same as the feed being empty — the graph indexes a subset of every feed’s published entries.

Related pages

Pivot from MalwareBazaar Full into the indicators it lists.

Queries

Resolves the feed's categories.


MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categories
Run yourself →

The indicator-kind rollup and sample listed above.


MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESC
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.