Report Malware and Get It Removed
A neutral reporting workflow for malware URLs, droppers and payloads: filed with the right blocklists and pushed to the hosting provider until the file is offline.
The 4-Step Malware Reporting Workflow
Isolate the sample
Never open the malware from your daily machine. Use a sandboxed VM (any.run, Hybrid Analysis, Joe Sandbox) or an air-gapped host to observe behaviour and pull indicators.
Collect indicators
Record the delivery URL, SHA-256 hash, dropper domains, command-and-control endpoints, mutex names and persistence keys. Solid IoCs make triage a matter of minutes.
File the report
Submit to URLhaus, MalwareBazaar, Google Safe Browsing and Microsoft Defender in parallel. Send the same case to Blackwall so the hosting layer is contacted, not just the blocklists.
Confirm the takedown
Blackwall escalates to the host and upstream ASN if the payload is still reachable after 24 hours. The case is closed once the URL returns 404 or the storage bucket is deleted.
Where to Report Malware
Every list protects a different ecosystem. File in parallel for the widest coverage.
BlackwallInfrastructure
Contacts the hosting provider, registrar and upstream ASN so the malware file is disabled. You receive updates until the URL returns 404.
File on BlackwallURLhaus by abuse.ch
Community database for malware-distribution URLs. Feeds dozens of security products and threat-intel platforms worldwide.
urlhaus.abuse.chMalwareBazaar
For submitting the actual sample or hash so AV vendors can extract signatures. Complements the URL report on URLhaus.
bazaar.abuse.chGoogle Safe Browsing
Adds the URL to Safe Browsing so Chrome, Gmail and Android show interstitial warnings before download.
safebrowsing.google.comFrequently Asked Questions
Found a URL serving malware?
Submit the URL in under two minutes. The Blackwall team handles the host correspondence so the payload is removed, not just flagged.
