Skip to content

Threat feed

MalwareBazaar MD5 Hashes

Last fetched

Malware Distribution · refreshed hourly · last verified

MalwareBazaar MD5 Hashes is a Malware Distribution threat-intelligence feed, refreshed hourly, indexed by WhisperGraph.

What is MalwareBazaar MD5 Hashes

MalwareBazaar MD5 Hashes is the MD5-indexed export of abuse.ch's MalwareBazaar malware-sample repository, structured for direct ingestion into tools and SIEM rules that key on the MD5 algorithm rather than the project's default SHA256. Coverage matches the main MalwareBazaar corpus — droppers, loaders, and packed executables submitted by sandbox runs and the contributor community — with only the hash format changed. Legacy antivirus and EDR products that still index by MD5 rely on exports like this one to stay current without a full pipeline rewrite. It is indexed here as the MD5-specific slice of a widely-cited malware-sample archive.

Refresh cadence
hourly

Category drift. The curated category for this feed is Malware Distribution, while WhisperGraph currently files it under malware-distribution.

Indicators currently listed

No indicator in WhisperGraph currently links to MalwareBazaar MD5 Hashes. That is not the same as the feed being empty — the graph indexes a subset of every feed’s published entries.

Related pages

Pivot from MalwareBazaar MD5 Hashes into the indicators it lists.

Queries

Resolves the feed's categories.


MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categories
Run yourself →

The indicator-kind rollup and sample listed above.


MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESC
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.