Threat intelligence feed
Malware Hash Feed
Real-time malware file hashes (MD5, SHA-1, SHA-256) for detection, blocking and enrichment. Every hash is attributed to a specific family and campaign, so a single match tells you what the file is, not just that it's bad.
15-day free trial · no credit card · reply within one business day
Drops straight into the tools your SOC already runs
Detection at the file level
Turn a hash match into an identified threat
A hash match is the most portable indicator you have: it works the same in your EDR, your AV, your SIEM and your gateway, and it holds up retrospectively against months of stored telemetry. The Malware Hash Feed gives you a current set of known-bad MD5, SHA-1 and SHA-256 hashes, each attributed to the family and campaign behind the sample, so a match is an identification, not just an alert.
Attribution on every hash
Each hash is mapped to a known malware family and observed campaign. A single match tells you whether you're looking at an infostealer, a loader or a post-exploitation tool, and how the sample fits a broader intrusion, not just that a file is bad.
Detect and block anywhere
Hashes are the most portable indicator there is. Push the same list into EDR, AV, SIEM and firewall workflows to detect and block known-bad files across endpoints and gateways, with no per-tool reformatting.
Flexible delivery, no new tooling
Consume the feed as CSV, REST API (JSON), STIX/TAXII or MISP. Load hashes straight into your endpoint, SIEM or TIP workflow without building a new ingestion pipeline.
The Malware Hash Feed is a real-time list of file hashes (MD5, SHA-1 and SHA-256) for known malware samples: the payloads, loaders and tools seen in active campaigns. A current set of malware hashes is the fastest way to detect and block known-bad files across your endpoints and gateways, whether you’re a SOC analyst, a security engineer or a data reseller.
Every hash is attributed to a known malware family and observed campaign. A match doesn’t just tell you a file is malicious. It tells you whether you’re looking at an Agent Tesla infostealer sample, a Lokibot payload, or a Cobalt Strike beacon, turning an isolated detection into campaign context.
You get portable file-level coverage that works alongside your network indicators: the same hashes detect in your SIEM, block in your EDR and hold up retrospectively against months of stored telemetry.
What’s in the feed
- Real-time feed of MD5, SHA-1 and SHA-256 hashes for known malware samples
- Family and campaign attribution on every hash
- Coverage across dozens of currently tracked malware, infostealer, RAT and loader families
- Ready to action in EDR, AV, SIEM and TIP workflows
- CSV and REST API (JSON) delivery for bulk ingestion and automation
- Available through STIX/TAXII and MISP feeds for teams standardizing on threat-intelligence platforms
Evaluate before you commit
You can validate freshness, attribution quality and feed fit against your existing stack before committing. Match hash indicators against your Microsoft Sentinel incidents, populate MISP or OpenCTI events, or compare coverage overlap with your current sources to see where this feed adds signal.
Start a 15-day free trial. Access is immediate and includes the full PrecisionSec feed set: malicious URL, domain, IP and hash feeds, plus the malware domain list.
When to use this feed
- EDR and AV blocklisting: push high-confidence known-bad hashes into endpoint controls to block malicious files before they execute.
- SIEM detection and retro hunting: match hashes against live and historical telemetry to catch samples that landed before the indicator was published.
- SOC alert enrichment: pivot from a hash match to family and campaign context so analysts know what they’re dealing with before escalation.
- Malware analysis and triage: confirm and attribute samples pulled from sandboxes, quarantine or user submissions against a current known-bad set.
- MSSP and multi-tenant coverage: apply curated malware hash intelligence across customer environments with a predictable feed format.
- Data resellers and security products: integrate high-confidence malware hash intelligence into your own platform without building a collection pipeline.
You get the Malware Hash Feed with every PrecisionSec intelligence subscription, alongside the malicious URL, domain and IP feeds and the malware domain list. Request evaluation access to see live data, delivery formats and integration options.
Ready to see all of our data?
Start your 15-day free trial and get the full Malware Hash Feed feed, plus every other malware and C2 feed.