<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Threat Data Feeds Malicious Hashes?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Malicious file hashes</strong> – MD5 per record, with optional SHA1 and SHA256.<br /> <strong>Threat context</strong> – Kaspersky threat name, file type, file size, common filenames.<br /> <strong>Timing and spread</strong> – First seen, last seen and a five-level popularity index.<br /> <strong>Attack mapping</strong> – MITRE ATT&amp;CK tactic and technique pairs per object.<br /> <strong>Distribution data</strong> – Top ten hosting IP addresses and download URLs.<br /> <strong>Important</strong> – No console, no agent and no blocking on its own.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Threat Data Feeds Malicious Hashes?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Threat Data Feeds Malicious Hashes is a threat intelligence subscription, not a protection product: it delivers a continuously updated set of malicious file hashes with context that your own SIEM, firewall or gateway consumes. Kaspersky also markets the same catalogue as Kaspersky Threat Intelligence Data Feeds, and the feed itself is documented as Malicious Hash Data Feed, so both names refer to this data set.<br /><br /> <strong>Faster alert triage</strong> – Analysts see the threat name instead of an unknown hash.<br /> <strong>Fewer false positives</strong> – Indicators are filtered against a large legitimate-file database.<br /> <strong>Near real-time updates</strong> – New records arrive without waiting for OSINT publication.<br /> <strong>Reuse of existing tools</strong> – No new platform, the feed enters your current stack.<br /> <strong>Free matching engine</strong> – Kaspersky CyberTrace Community Edition matches feeds at no cost.<br /> <strong>Retrospective hunting</strong> – Old file hashes can be rechecked against newer feed records.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Threat Data Feeds Malicious Hashes suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This feed only produces value if something in your infrastructure already collects file hashes from logs or network traffic and can match them. Without a SIEM, a next generation firewall or a mail and web gateway that ingests indicator lists, there is nothing to feed the data into.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">SIEM, NGFW or gateway able to ingest indicators</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Partial</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Malicious Hashes meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In Switzerland the reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every company, so most SMEs are not directly affected. Affected operators must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Within that window the feed helps in one specific way: a file hash pulled from your logs can be resolved to a Kaspersky threat name, a first seen date and MITRE ATT&amp;CK tactics, which is exactly the substance a first report needs instead of the phrase unknown binary. What the feed does not do is detect the file, produce the log in the first place, keep an incident record or submit anything to BACS; those come from your endpoint protection, your log management and your own process. It also covers no mobile or ICS objects, so an operator with those environments still has a gap. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Malicious Hashes meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates NIS 2 compliance, because the directive addresses organisational risk management rather than a shopping list of tools. NIS 2 requires measure categories including risk analysis and security policies, incident handling, business continuity, supply chain security, security in acquisition and development, cryptography and access control, basic cyber hygiene and staff training. This feed contributes to one of them, incident handling, by shortening the step between a suspicious file hash and a named, dated and classified threat. It does not contribute to continuity planning, cryptography, access control, training or policy documentation, and it produces no audit evidence by itself since it is a data set rather than a reporting system. Supply chain security is only partially served here, because software supply chain indicators sit in the separate Open Source Software Threats Data Feed.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Two official measures are in force. The German Federal Office for Information Security issued a warning against Kaspersky antivirus software on 15 March 2022; it remains active and is now regulated under Section 13 of the German BSI Act following the amendment that took effect on 6 December 2025. In the United States, the Bureau of Industry and Security prohibited new Kaspersky sales from 20 July 2024 and the delivery of updates from 29 September 2024, and added Kaspersky entities to the Entity List. Kaspersky states that these decisions rest on the company's country of origin rather than on a published technical finding about its products, and it has publicly pressed for the German warning to be withdrawn. Switzerland has taken no equivalent step: BACS has issued neither a warning nor a ban, and the products are sold and updated normally in Switzerland, the European Union and the United Kingdom. In practice this matters most if you sell into German or other European public-sector contracts, if you have United States operations, or if a large customer's supplier questionnaire asks about vendors of Russian origin. For a private Swiss company with no public-sector exposure, no restriction applies.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />A side-by-side look at how the two vendors compare on detection and features.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Threat Data Feeds Malicious Hashes help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only for a narrow set of items. It answers questions on whether you subscribe to commercial threat intelligence, whether indicators of compromise are matched against your log data, in which formats intelligence is consumed, and how quickly new indicators reach your controls. It answers nothing about endpoint protection, patch management, encryption, multi-factor authentication, backup and restore, log retention periods, access control or awareness training, and it produces no certificate or attestation you can attach. It also gives no evidence of coverage for mobile devices or industrial systems. If a questionnaire exposes gaps beyond hash matching, the cheaper route is usually to widen within the same family, for example adding IP Reputation, URL or Vulnerability feeds, or moving to a broader Kaspersky Threat Intelligence subscription, rather than mixing feed vendors and then having to reconcile different context formats.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between Malicious Hash Data Feed and Mobile Malicious Hash Data Feed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is scope of objects, and the feeds do not overlap: buying malicious hashes alone leaves mobile and industrial systems uncovered. Malicious Hash Data Feed targets prevalent and emerging malware on desktop and server files, Mobile Malicious Hash Data Feed covers objects infecting Android and iPhone devices, and ICS Hash Data Feed covers files used against industrial control systems and the IT systems integrated into them. All three share the same record structure, so no separate parsing work is needed if you add one later. Kaspersky also publishes demo versions of these feeds, which carry a lower detection rate than the commercial versions and are intended for evaluation rather than production.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Property</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Malicious Hash</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Mobile Malicious Hash</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">ICS Hash</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Objects covered</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Prevalent malware</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Mobile malware</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">ICS malware</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Platforms</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Desktop and server</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Android and iPhone</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">ICS and linked IT</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">MD5, SHA1 and SHA256</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Popularity index and threat name</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Included in this listing</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most important limitation is that this is data, not defence: it detects nothing, blocks nothing and has no console, so it is worthless without a SIEM, next generation firewall or gateway that already ingests indicator lists. Regional availability is restricted in one market, the United States, where the Bureau of Industry and Security prohibition covers new sales and updates; sale and updates in Switzerland, the European Union and the United Kingdom are unaffected. If you match feeds with Kaspersky CyberTrace rather than inside your SIEM, the free Community Edition is capped at 250 events per second and one million records across all intelligence sources, which is the point where follow-up purchases most often become necessary. Matching directly inside a SIEM avoids that licence but typically costs SIEM performance. Finally, hashes only identify files that have already been seen and classified, so this feed adds nothing against a genuinely unique binary built for one target.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains why a built-in scanner leaves gaps that additional security layers have to close.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Threat Data Feeds Malicious Hashes</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Do I need Kaspersky endpoint protection to use this feed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. The feed is a standalone threat intelligence subscription and does not require a Kaspersky endpoint product. It is consumed by whichever SIEM, firewall or gateway you already run, regardless of vendor.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">In which formats is the feed delivered?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Malicious Hash Data Feed with extra context is provided in JSON. Across the Kaspersky Threat Data Feeds catalogue, JSON, CSV, OpenIoC and STIX are supported, delivered over HTTPS, TAXII or an agreed alternative mechanism.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which security tools can consume the feed out of the box?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky publishes ready-made integrations for IBM QRadar, Splunk Enterprise Security, ArcSight ESM, RSA NetWitness, Azure Sentinel, Anomali ThreatStream, ThreatConnect, EclecticIQ, ThreatQ, MISP, Cisco Firepower, Suricata, McAfee Web Gateway and Maltego, plus a REST API for anything not on that list.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Where does the data come from?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Records are aggregated from Kaspersky Security Network telemetry contributed by over 400 million voluntary participants, web crawlers, botnet research, spam traps, honeypots and sinkholes, passive DNS from hosting providers and ISPs, OSINT and vendor partnerships. Each indicator passes automated screening and sandbox analysis before release.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,compliance-ch-isg,compliance-nis2" data-audience="b2b" data-count="3"> </div>