icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

Thank You

Downloading MalwareBazaar
SHA256 checksum (malwarebazaar_106.tgz) cf2da81d008da4c91141240893908d09806cb5dd95f2bc7cdb2a655c621a391e SHA256 checksum (malwarebazaar_105.tgz) e1f93b45c85ab5b286f64affe7c19c20065c7e5979407307b5ab8fc577ebd609 SHA256 checksum (malwarebazaar_104.tgz) bb987095fb8342cac1f1401ae14c5accac0462e3cb3bace59a18b142b7ada5d9 SHA256 checksum (malwarebazaar_103.tgz) d7e662a9c9abe7327b4b4c7d789f74bd7e87ae3ae386f26071a63d9467613198 SHA256 checksum (malwarebazaar_101.tgz) ac1d9325e845a11b4df74ada498517765cc233f64fd75a61634b7647d459a69e

Flag As Inappropriate

soar

MalwareBazaar

Splunk SOAR Cloud
Splunk Built
Overview
This app integrates with MalwareBazaar from abuse.ch to provide investigative actions

Supported Actions Version 1.0.6

  • test connectivity: Validate the asset configuration for connectivity using supplied configuration
  • get file info: Query the MalwareBazaar API for the corresponding hash
  • get file: Fetch malware sample from MalwareBazaar and store in vault

Supported Actions Version 1.0.5

  • test connectivity: Validate the asset configuration for connectivity using supplied configuration
  • get file info: Query the MalwareBazaar API for the corresponding hash
  • get file: Fetch malware sample from MalwareBazaar and store in vault

Supported Actions Version 1.0.4

  • test connectivity: Validate the asset configuration for connectivity using supplied configuration
  • get file info: Query the MalwareBazaar API for the corresponding hash
  • get file: Fetch malware sample from MalwareBazaar and store in vault

Supported Actions Version 1.0.3

  • test connectivity: Validate the asset configuration for connectivity using supplied configuration
  • get file info: Query the MalwareBazaar API for the corresponding hash
  • get file: Fetch malware sample from MalwareBazaar and store in vault

Supported Actions Version 1.0.1

  • test connectivity: Validate the asset configuration for connectivity using supplied configuration
  • get file info: Query the MalwareBazaar API for the corresponding hash
  • get file: Fetch malware sample from MalwareBazaar and store in vault

Release Notes

Version 1.0.6
April 11, 2025
  • Update Python dependencies for vulnerabilities, package updates, and platform built-in removals
  • Update Python dependencies for Python 3.13 support
  • Update NOTICE file with updated dependencies
  • Apply pre-commit fixes
Version 1.0.5
Feb. 2, 2024
  • Updated requests and certifi dependencies in order to use platform packages [PAPP-30822, PAPP-31096]
Version 1.0.4
Dec. 5, 2023
  • Use the Vault API to retrieve the temp directory path, instead of assuming a constant value [PAPP-32438]
  • Update min_phantom_version to 6.1.1
  • Remove the requests library, instead using the one built into the SOAR platform
Version 1.0.3
April 7, 2022
  • Certified this app under Splunk [PAPP-25202]
Version 1.0.1
Sept. 21, 2021

MalwareBazaar Release Notes - Published by Splunk Community April 19, 2021

Version 1.0.1 - Released April 19, 2021

  • Initial Release with Python 3 support

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.