


Overview
Turn a MalwareBazaar page into a clean, complete report you can print, share or import into your own tooling. Unofficial tool.
MalwareBazaar is where a lot of threat work starts, but there is no way to take an entry with you. The site has no export and no print view, so the sample you just analysed ends up as a browser print with panels cut in half, or as copy and paste into a ticket. Bazaar Report Exporter fixes that. One click on the page you are viewing and you get a clean, complete report of what is on the screen, ready to attach to a case, send to a colleague, or keep in your archive. WHAT IT DOES - Builds a full report from the page you are already looking at. No API key, no account, no setup. - Opens every collapsed panel first, including the vendor entries that load on demand, and waits for them to finish before it exports. Nothing quietly goes missing because a section was closed. - Puts the verdict spread at the top, so you can see at a glance how many vendors called the sample malicious, how many called it suspicious, and how many returned nothing at all. - Keeps the detail you actually need: hashes, file metadata, where the file was first seen, per vendor results and behaviour lines, rule matches, external references and community comments. - Carries sandbox process graphs across as vector images, so they stay sharp when you zoom or print. HOW YOU CAN SAVE IT The report itself is a single self contained HTML page. It opens on any machine with nothing installed, and it comes with a dark mode toggle, a filter that hides everything except the malicious or suspicious vendors, and a button that copies every indicator at once. If you need a document, the report is rendered and sent to the print dialog, so you save a proper A4 PDF instead of a screenshot of a web page. If you work in tickets and wikis, there is a Markdown version that pastes cleanly into Jira, Confluence or a case note. If you automate, the same content is available as structured JSON, and that JSON is embedded inside the HTML report too, so a single file serves both a human reader and a script. Listing and search pages can be saved as a spreadsheet. If you run a threat intelligence platform, the sample can be handed over as a ready made event for MISP or as a STIX 2.1 bundle, with the hashes, tags and references already filled in. WORKS ACROSS THE SITE Sample pages are fully mapped. Every other page type is handled by a generic reader that picks up tables and field lists wherever it finds them, which covers browse and search results, signature and tag pages, rule pages, statistics and hunting pages. If a new section appears on the site, it still lands in your report. Listing pages also offer a bulk save, deliberately capped and rate limited so that it stays inside fair use. OPTIONAL BRANDING Every branding field is empty by default, so what you get out of the box is a neutral document. If you report to customers or to management, you can add your team name, your logo, an analyst name, a TLP marking and a handling caveat, and choose which sections to include. All of it is optional and all of it stays in your browser. PRIVACY - No accounts, no sign in, no keys. - No analytics, no telemetry, no tracking. - No servers operated by the developer. The extension has no backend at all. - It reads only pages on bazaar.abuse.ch, and only while you are on one. - Reports are built in your browser and saved to your own machine. Nothing is uploaded anywhere. WHO IT IS FOR Analysts writing up a sample, responders attaching evidence to a case, intelligence teams feeding a platform, researchers keeping a readable archive, and anyone who has ever retyped a hash table into an email. HOW TO USE IT 1. Open any page on bazaar.abuse.ch. 2. Click the floating button at the bottom right, or the toolbar icon, or press Alt+Shift+E. 3. Choose how you want it saved. The file lands in your downloads. CREDIT WHERE IT IS DUE All data in every report comes from MalwareBazaar, a malware sample database operated by abuse.ch. Reports credit them on the cover, in a dedicated source and attribution section, and in the footer, with links back to the original entry, to the database, to the operator and to their terms of use. Vendor verdicts, rule matches and sandbox results belong to the vendors named beside them, and MalwareBazaar makes no guarantee that a listed sample is malicious. This is an independent tool. It is not affiliated with, endorsed by or operated by abuse.ch or the Spamhaus Project. Please respect the abuse.ch terms of use, in particular the limits on automated bulk collection and the rules around commercial use of their data.
0 out of 5No ratings
Details
- Version1.1.1
- UpdatedAugust 21, 2026
- Size51.96KiB
- LanguagesEnglish
- DeveloperWebsite
Email
maor@maordayan.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, please open this page on your desktop browser