Threat feed
MalwareBazaar MD5 Hashes
Last fetched
Malware Distribution · refreshed hourly · last verified
MalwareBazaar MD5 Hashes is a Malware Distribution threat-intelligence feed, refreshed hourly, indexed by WhisperGraph.
What is MalwareBazaar MD5 Hashes
MalwareBazaar MD5 Hashes is the MD5-indexed export of abuse.ch's MalwareBazaar malware-sample repository, structured for direct ingestion into tools and SIEM rules that key on the MD5 algorithm rather than the project's default SHA256. Coverage matches the main MalwareBazaar corpus — droppers, loaders, and packed executables submitted by sandbox runs and the contributor community — with only the hash format changed. Legacy antivirus and EDR products that still index by MD5 rely on exports like this one to stay current without a full pipeline rewrite. It is indexed here as the MD5-specific slice of a widely-cited malware-sample archive.
- Source
- https://bazaar.abuse.ch/
- Refresh cadence
- hourly
Category drift. The curated category for this feed is Malware Distribution, while WhisperGraph currently files it under malware-distribution.
Indicators currently listed
No indicator in WhisperGraph currently links to MalwareBazaar MD5 Hashes. That is not the same as the feed being empty — the graph indexes a subset of every feed’s published entries.
Related pages
Pivot from MalwareBazaar MD5 Hashes into the indicators it lists.
Queries
Resolves the feed's categories.
MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categoriesRun yourself →The indicator-kind rollup and sample listed above.
MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESCRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.