Defund the Police.
-
Updated
Oct 11, 2020
{{ message }}
Defund the Police.
A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
Android virtual machine and deobfuscator
Collection of malware source code for a variety of platforms in an array of different programming languages.
Program for determining types of files for Windows, Linux and MacOS.
VirusTotal Wanna Be - Now with 100% more Hipster
A curated list of awesome YARA rules, tools, and people.
Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android
Sandboxed Execution Environment
yarGen is a generator for YARA rules
FAME Automates Malware Evaluation
A collection of malware samples and relevant dissection information, most probably referenced from http://blog.inquest.net
Modular file scanning/analysis framework
Leaked Linux.Mirai Source Code for Research/IoC Development Purposes
WinDBG Anti-RootKit Extension
Reflective PE packer.
Extract and aggregate threat intelligence.
The PE file analysis toolkit
A pattern based Dalvik deobfuscator which uses limited execution to improve semantic analysis
An open source framework for enterprise level automated analysis.
Sandbox for semi-automatic Javascript malware analysis, deobfuscation and payload extraction. Written for Node.js
Collection of almost 40.000 javascript malware samples
Obfuscate specific windows apis with different apis
WinAppDbg Debugger
It will be great to see a tumbler at the web interface to turn on and off the internet connection for the scan.
I suppose, you can turn on/off it in drakrun/main.py file using ifconfig vif manipulation, like sudo ifconfig vifX.0 down at the "process" function. Plus self.current_task.payload.get to obtain the tumbler state.
Collaborative malware analysis framework
Defanged Indicator of Compromise (IOC) Extractor.
Code written as part of our various malware investigations http://www.welivesecurity.com/
Phishing Domains, urls websites and threats database. We use the PyFunceble testing tool to validate the status of all known Phishing domains and provide stats to reveal how many unique domains used for Phishing are still active.
Add a description, image, and links to the malware-research topic page so that developers can more easily learn about it.
To associate your repository with the malware-research topic, visit your repo's landing page and select "manage topics."
Some old programs versions can be found here if someone needs them to test old exploits for instance.