Malwarebazaar
MalwareBazaar is a platform for sharing and analyzing malware samples, fostering collaboration among cybersecurity professionals.
MalwareBazaar is a community-driven platform for sharing and analyzing malware samples. It allows users to upload, query, and comment on malware samples, facilitating collaborative threat intelligence. By integrating MalwareBazaar with Swimlane Turbine, users can automate the enrichment of threat intelligence, streamline malware analysis, and enhance their security operations. This integration empowers security teams to efficiently manage malware data, improve incident response times, and leverage community insights for proactive threat mitigation.
Limitations
None to date.
Supported Versions
This MalwareBazaar connector uses the latest Version.
Prerequisites
Before you can use the MalwareBazaar connector for Turbine, you'll need access to the MalwareBazaar API. This requires the following:
- API key authentication using the following parameters:
- URL: The endpoint for accessing the MalwareBazaar API.
- Auth Key: A unique key provided by MalwareBazaar for authenticating API requests.
Authentication Methods
To effectively utilize the MalwareBazaar connector within Swimlane Turbine, ensure you have the following:
- API Key Authentication with the necessary parameters:
- URL: The endpoint URL for the MalwareBazaar API.
- Auth Key: Your personal authentication key to access the MalwareBazaar services.
Capabilities
This MalwareBazaar connector provides the following capabilities:
- Add a Comment
- Query a Malware Sample
- Upload Malware Samples
Add a Comment
- Add a comment to a specific malware sample in MalwareBazaar using the provided data body Click Here.
Query a Malware Sample
- Check the presence of a specific malware sample in the MalwareBazaar database using the provided data body Click Here.
Upload Malware Samples
- Upload malware samples directly to MalwareBazaar for analysis and sharing with the cybersecurity community Click Here.
Additional Documentation
Configurations
Malwarebazaar URLhaus Authentication
Authenticates using Host URL and Auth-Key to access.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
Auth-Key | The authentication key for accessing the API. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Add a Comment
Add a comment to a malware sample in MalwareBazaar using the specified data body.
Endpoint
- URL: api/v1/
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Response data |
data_body.query | string | Required | The query type for the API. |
data_body.sha256_hash | string | Required | The SHA256 hash of the malware sample to which the comment is added. |
data_body.comment | string | Required | The comment to be added to the malware sample. |
Input Example
{"data_body":{"query":"add_comment","sha256_hash":"d9b05da007d51cf86d4a6448d17183ab69a195436fe17b497185149676d0e77b","comment":"Swiss chocolate is the best chocolate"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
query_status | string | Status value |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx/1.22.1","Date":"Thu, 14 Aug 2025 06:47:50 GMT","Content-Type":"application/json","Content-Length":"33","Strict-Transport-Security":"max-age=15768000 ; includeSubDomains, max-age=31536000; includeSubDomains","Permissions-Policy":"accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), encrypted-med...","Referrer-Policy":"strict-origin-when-cross-origin","Expect-Ct":"enforce, max-age=86400","Content-Security-Policy":"default-src 'se...
Query a Malware Sample
Check for a specific malware sample in the MalwareBazaar database using the provided data body.
Endpoint
- URL: api/v1/
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
data_body | object | Required | Response data |
data_body.query | string | Required | The query type for the API. |
data_body.hash | string | Required | SHA256, MD5 or SHA1 hash of the malware sample you want to query. |
Input Example
{"data_body":{"query":"get_info","hash":"094fd325049b8a9cf6d3e5ef2a6d4cc6a567d7d49c35f8bb8dd9e3c6acf3d78d"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
query_status | string | Status value |
data | array | Response data |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx/1.22.1","Date":"Thu, 14 Aug 2025 06:44:30 GMT","Content-Type":"application/json","Transfer-Encoding":"chunked","Strict-Transport-Security":"max-age=15768000 ; includeSubDomains, max-age=31536000; includeSubDomains","Permissions-Policy":"accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), encrypted-med...","Referrer-Policy":"strict-origin-when-cross-origin","Expect-Ct":"enforce, max-age=86400","Content-Security-Policy":"default...
Upload Malware Samples
Upload malware samples to MalwareBazaar for analysis and community sharing. Requires file inputs.
Endpoint
- URL: api/v1/
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
file | object | Optional | The malware sample you want to upload |
file.file | string | Optional | Parameter for Upload Malware Samples |
file.file_name | string | Optional | Name of the resource |
anonymous | number | Optional | If set to 1, your submission will be anonymous. |
delivery_method | string | Optional | Delivery method used to spread this malware sample. |
tags | array | Optional | List of tags. Allowed characters are [A-Za-z0-9.- ] |
references | object | Optional | References for this malware sample |
references.any_run | array | Optional | Parameter for Upload Malware Samples |
references.joe_sandbox | array | Optional | Parameter for Upload Malware Samples |
references.malpedia | array | Optional | Parameter for Upload Malware Samples |
references.twitter | array | Optional | Parameter for Upload Malware Samples |
references.links | array | Optional | Parameter for Upload Malware Samples |
context | object | Optional | Context for this malware sample. |
context.dropped_by_md5 | array | Optional | Parameter for Upload Malware Samples |
context.dropped_by_sha256 | array | Optional | Parameter for Upload Malware Samples |
context.dropped_by_malware | array | Optional | Parameter for Upload Malware Samples |
context.comment | string | Optional | Parameter for Upload Malware Samples |
Input Example
{"json_body":{"anonymous":1,"delivery_method":"email_attachment","tags":["exe","test"],"references":{"any_run":["https://app.any.run/tasks/1","https://app.any.run/tasks/2"],"joe_sandbox":["https://www.joesecurity.org/reports/1","https://www.joesecurity.org/reports/2"],"malpedia":["https://malpedia.caad.fkie.fraunhofer.de/details/win.gozi"],"twitter":["https://twitter.com/abuse_ch/status/1224269018506330112"],"links":["https://urlhaus.abuse.ch/url/306613/"]},"context":{"dropped_by_md5":["68b329da9893e34099c7d8ad5cb9c940"],"dropped_by_sha256":["01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b","4355a46b19d348dc2f57c046f8ef63d4538ebb936000f3c9ee954a27460dd865"],"dropped_by_malware":["Gozi"],"comment":"this malware sample is very nasty!"}}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
query_status | string | Status value |
Output Example
{"status_code":200,"response_headers":{"Server":"nginx/1.22.1","Date":"Tue, 19 Aug 2025 07:46:34 GMT","Content-Type":"application/json","Content-Length":"34","Strict-Transport-Security":"max-age=15768000 ; includeSubDomains, max-age=31536000; includeSubDomains","Permissions-Policy":"accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), encrypted-med...","Referrer-Policy":"strict-origin-when-cross-origin","Expect-Ct":"enforce, max-age=86400","Content-Security-Policy":"default-src 'se...
Response Headers
Header | Description | Example |
|---|---|---|
Alt-Svc | HTTP response header: Alt-Svc | h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 |
Content-Length | The length of the response body in bytes | 34 |
Content-Security-Policy | HTTP response header: Content-Security-Policy | default-src 'self'; style-src 'self'; script-src 'self'; img-src 'self'; object-src 'none' |
Content-Type | The media type of the resource | application/json |
Cross-Origin-Embedder-Policy | HTTP response header: Cross-Origin-Embedder-Policy | require-corp; report-to="default" |
Cross-Origin-Opener-Policy | HTTP response header: Cross-Origin-Opener-Policy | same-origin; report-to="default" |
Cross-Origin-Resource-Policy | HTTP response header: Cross-Origin-Resource-Policy | same-site |
Date | The date and time at which the message was originated | Thu, 14 Aug 2025 06:44:30 GMT |
Expect-Ct | HTTP response header: Expect-Ct | enforce, max-age=86400 |
Permissions-Policy | HTTP response header: Permissions-Policy | accelerometer=(), ambient-light-sensor=(), autoplay=(), camera=(), encrypted-media=(), fullscreen=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), speaker=(), usb=(), vr=() |
Referrer-Policy | HTTP response header: Referrer-Policy | strict-origin-when-cross-origin |
Server | Information about the software used by the origin server | nginx/1.22.1 |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=15768000 ; includeSubDomains, max-age=31536000; includeSubDomains |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Via | HTTP response header: Via | 1.1 google |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
X-Frame-Options | HTTP response header: X-Frame-Options | sameorigin |
X-Xss-Protection | HTTP response header: X-Xss-Protection | 1; mode=block |