6 items
Turn a MalwareBazaar page into a clean, complete report you can print, share or import into your own tooling. Unofficial tool. MalwareBazaar is where a lot of threat work starts, but there is no way to take an entry with you. The site has no export and no print view, so the sample you just analysed ends up as a browser print with panels cut in half, or as copy and paste into a ticket. Bazaar Report Exporter fixes that. One click on the page you are viewing and you get a clean, complete report of what is on the screen, ready to attach to a case, send to a colleague, or keep in your archive. WHAT IT DOES - Builds a full report from the page you are already looking at. No API key, no account, no setup. - Opens every collapsed panel first, including the vendor entries that load on demand, and waits for them to finish before it exports. Nothing quietly goes missing because a section was closed. - Puts the verdict spread at the top, so you can see at a glance how many vendors called the sample malicious, how many called it suspicious, and how many returned nothing at all. - Keeps the detail you actually need: hashes, file metadata, where the file was first seen, per vendor results and behaviour lines, rule matches, external references and community comments. - Carries sandbox process graphs across as vector images, so they stay sharp when you zoom or print. HOW YOU CAN SAVE IT The report itself is a single self contained HTML page. It opens on any machine with nothing installed, and it comes with a dark mode toggle, a filter that hides everything except the malicious or suspicious vendors, and a button that copies every indicator at once. If you need a document, the report is rendered and sent to the print dialog, so you save a proper A4 PDF instead of a screenshot of a web page. If you work in tickets and wikis, there is a Markdown version that pastes cleanly into Jira, Confluence or a case note. If you automate, the same content is available as structured JSON, and that JSON is embedded inside the HTML report too, so a single file serves both a human reader and a script. Listing and search pages can be saved as a spreadsheet. If you run a threat intelligence platform, the sample can be handed over as a ready made event for MISP or as a STIX 2.1 bundle, with the hashes, tags and references already filled in. WORKS ACROSS THE SITE Sample pages are fully mapped. Every other page type is handled by a generic reader that picks up tables and field lists wherever it finds them, which covers browse and search results, signature and tag pages, rule pages, statistics and hunting pages. If a new section appears on the site, it still lands in your report. Listing pages also offer a bulk save, deliberately capped and rate limited so that it stays inside fair use. OPTIONAL BRANDING Every branding field is empty by default, so what you get out of the box is a neutral document. If you report to customers or to management, you can add your team name, your logo, an analyst name, a TLP marking and a handling caveat, and choose which sections to include. All of it is optional and all of it stays in your browser. PRIVACY - No accounts, no sign in, no keys. - No analytics, no telemetry, no tracking. - No servers operated by the developer. The extension has no backend at all. - It reads only pages on bazaar.abuse.ch, and only while you are on one. - Reports are built in your browser and saved to your own machine. Nothing is uploaded anywhere. WHO IT IS FOR Analysts writing up a sample, responders attaching evidence to a case, intelligence teams feeding a platform, researchers keeping a readable archive, and anyone who has ever retyped a hash table into an email. HOW TO USE IT 1. Open any page on bazaar.abuse.ch. 2. Click the floating button at the bottom right, or the toolbar icon, or press Alt+Shift+E. 3. Choose how you want it saved. The file lands in your downloads. CREDIT WHERE IT IS DUE All data in every report comes from MalwareBazaar, a malware sample database operated by abuse.ch. Reports credit them on the cover, in a dedicated source and attribution section, and in the footer, with links back to the original entry, to the database, to the operator and to their terms of use. Vendor verdicts, rule matches and sandbox results belong to the vendors named beside them, and MalwareBazaar makes no guarantee that a listed sample is malicious. This is an independent tool. It is not affiliated with, endorsed by or operated by abuse.ch or the Spamhaus Project. Please respect the abuse.ch terms of use, in particular the limits on automated bulk collection and the rules around commercial use of their data.
Aug 21, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.