Threat feed
MalwareBazaar SHA1 Hashes
Last fetched
Malware Distribution · refreshed hourly · last verified
MalwareBazaar SHA1 Hashes is a Malware Distribution threat-intelligence feed, refreshed hourly, indexed by WhisperGraph.
What is MalwareBazaar SHA1 Hashes
MalwareBazaar SHA1 Hashes is the SHA1-indexed export of the same abuse.ch MalwareBazaar sample repository, published alongside the MD5 and SHA256 forms for tooling that standardises on SHA1. Entries are malware samples confirmed by abuse.ch's analysis pipeline and community contributors, each carrying a family tag and first-seen date. Publishing the corpus under all three common hash algorithms removes a conversion step from downstream detection engineering, at the cost of a larger combined download. It is indexed here as the SHA1-specific slice of one of the most widely-integrated free malware-sample sources.
- Source
- https://bazaar.abuse.ch/
- Refresh cadence
- hourly
Category drift. The curated category for this feed is Malware Distribution, while WhisperGraph currently files it under malware-distribution.
Indicators currently listed
No indicator in WhisperGraph currently links to MalwareBazaar SHA1 Hashes. That is not the same as the feed being empty — the graph indexes a subset of every feed’s published entries.
Related pages
Pivot from MalwareBazaar SHA1 Hashes into the indicators it lists.
Queries
Resolves the feed's categories.
MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categoriesRun yourself →The indicator-kind rollup and sample listed above.
MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESCRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.