MalwareBazaar is a project from abuse.ch with the goal of sharing malware samples with the infosec community, AV vendors and cyber threat intelligence providers.
In order to query the MalwareBazaar API, you need to obtain an Auth-Key. If you don't have an Auth-Key yet, you can get one at https://auth.abuse.ch/ for free.
This scripts submits a malware sample to the MalwareBazaar database
python3 submit_sample.py <YOUR-AUTH-KEY> <PATH-TO-FILE>
The documentation for the MalwareBazaar API is available here:
https://bazaar.abuse.ch/api/
MalwareBazaar provides an hourly and daily batch of malware samples submitted to the platform. The feeds are available here:
Hourly feed: https://datalake.abuse.ch/malware-bazaar/hourly/
Daily feed: https://datalake.abuse.ch/malware-bazaar/daily/