Report Malware and Get It Removed

    A neutral reporting workflow for malware URLs, droppers and payloads: filed with the right blocklists and pushed to the hosting provider until the file is offline.

    The 4-Step Malware Reporting Workflow

    Step 1

    Isolate the sample

    Never open the malware from your daily machine. Use a sandboxed VM (any.run, Hybrid Analysis, Joe Sandbox) or an air-gapped host to observe behaviour and pull indicators.

    Step 2

    Collect indicators

    Record the delivery URL, SHA-256 hash, dropper domains, command-and-control endpoints, mutex names and persistence keys. Solid IoCs make triage a matter of minutes.

    Step 3

    File the report

    Submit to URLhaus, MalwareBazaar, Google Safe Browsing and Microsoft Defender in parallel. Send the same case to Blackwall so the hosting layer is contacted, not just the blocklists.

    Step 4

    Confirm the takedown

    Blackwall escalates to the host and upstream ASN if the payload is still reachable after 24 hours. The case is closed once the URL returns 404 or the storage bucket is deleted.

    Where to Report Malware

    Every list protects a different ecosystem. File in parallel for the widest coverage.

    BlackwallInfrastructure

    Contacts the hosting provider, registrar and upstream ASN so the malware file is disabled. You receive updates until the URL returns 404.

    File on Blackwall

    URLhaus by abuse.ch

    Community database for malware-distribution URLs. Feeds dozens of security products and threat-intel platforms worldwide.

    urlhaus.abuse.ch

    MalwareBazaar

    For submitting the actual sample or hash so AV vendors can extract signatures. Complements the URL report on URLhaus.

    bazaar.abuse.ch

    Google Safe Browsing

    Adds the URL to Safe Browsing so Chrome, Gmail and Android show interstitial warnings before download.

    safebrowsing.google.com

    Frequently Asked Questions

    Found a URL serving malware?

    Submit the URL in under two minutes. The Blackwall team handles the host correspondence so the payload is removed, not just flagged.

    Cookie Notice

    We use cookies to ensure the functionality of our website. Necessary cookies are required for operation. Optional cookies help us improve our services. For more information, see our Privacy Policy.