Live Android Malware Threat Feed
Public, continuously updated feed of Android malware samples analyzed by Droidwatch. sha256 hashes, package names, verdicts and severity scores — ingestible by your SIEM / MISP / OpenCTI in STIX 2.1, JSON, JSONL or CSV. No registration, no API key.
Total IOCs
3
Last 24 h
0
Generated
2026-07-30T05:21:12Z
License
CC BY 4.0
Download the feed
Latest 2 samples
| SHA-256 | Package | Verdict | Score | Seen |
|---|---|---|---|---|
| 0aa75f0754ecc35a… | com.com.rjblackbox.swl | High Risk | 58 | 2026-07-28 |
| 0c7490f3800562e6… | dex.6e7bd5fe-ccce-410f-b7cf-cb47e9c1df8d | High Risk | 50 | 2026-07-28 |
Programmatic access: all endpoints accept
?limit (max 500),
?page, ?verdict=Malicious|High Risk|Suspicious, and ?search=<pkg>.
Lookup individual hashes via GET /api/threat-feed/lookup?sha256=…. Stats via
GET /api/threat-feed/stats. See the API reference.