Skip to content

Threat feed

MalwareBazaar SHA1 Hashes

Last fetched

Malware Distribution · refreshed hourly · last verified

MalwareBazaar SHA1 Hashes is a Malware Distribution threat-intelligence feed, refreshed hourly, indexed by WhisperGraph.

What is MalwareBazaar SHA1 Hashes

MalwareBazaar SHA1 Hashes is the SHA1-indexed export of the same abuse.ch MalwareBazaar sample repository, published alongside the MD5 and SHA256 forms for tooling that standardises on SHA1. Entries are malware samples confirmed by abuse.ch's analysis pipeline and community contributors, each carrying a family tag and first-seen date. Publishing the corpus under all three common hash algorithms removes a conversion step from downstream detection engineering, at the cost of a larger combined download. It is indexed here as the SHA1-specific slice of one of the most widely-integrated free malware-sample sources.

Refresh cadence
hourly

Category drift. The curated category for this feed is Malware Distribution, while WhisperGraph currently files it under malware-distribution.

Indicators currently listed

No indicator in WhisperGraph currently links to MalwareBazaar SHA1 Hashes. That is not the same as the feed being empty — the graph indexes a subset of every feed’s published entries.

Related pages

Pivot from MalwareBazaar SHA1 Hashes into the indicators it lists.

Queries

Resolves the feed's categories.


MATCH (f:FEED_SOURCE {name: $slug})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
WITH f, collect(c.name) AS categories
RETURN f.name AS slug, f.id AS id, categories
Run yourself →

The indicator-kind rollup and sample listed above.


MATCH (f:FEED_SOURCE {name: $slug})<-[:LISTED_IN]-(x)
WITH labels(x)[0] AS kind, count(*) AS listed, collect(x.name)[0..5] AS sample
RETURN kind, listed, sample
ORDER BY listed DESC
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.