• Last Updated
    Jun 10, 2025
  • Version
    1.1.0
  • Compatibility
    ThreatQ Versions >= 5.6.0
  • abuse.ch MalwareBazaar Action

    ThreatQuotient

    Overview

    The abuse.ch Malwarebazaar action submits data collection containing MD5, SHA-1 and SHA-256 IOCs to abuse.ch MalwareBazaar and returns Indicators, TTPs and Malware. The abuse.ch MalwareBazaar queries the submitted objects for enrichment and returns related threat intelligence to be ingested into the ThreatQ library.
     
    The action can perform the following function:
    • abuse.ch MalwareBazaar - submits indicators to abuse.ch MalwareBazaar to be enriched with related threat intelligence.
    The action is compatible with the following indicator types:
    • MD5
    • SHA-1
    • SHA-256
    The action returns the following enriched system objects:
    • Indicators
      • Indicator Attributes
    • Indicator Tags
    • Malware
    • TTP
    Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.

     

    Copyright © 2025, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy