Author Topic: Where do you get malware samples to study?  (Read 1630 times)

0 Members and 1 Guest are viewing this topic.

Offline parad0x

  • VIP
  • Royal Highness
  • *
  • Posts: 638
  • Cookies: 118
    • View Profile
Where do you get malware samples to study?
« on: May 14, 2015, 11:29:11 am »
Well, the title says it all. In some days I am going to start malware analysis but haven't came across any decent malware repo from where I can dl them and then study them. IF you have some links that you use to dl malware from, post it here. :)

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: Where do you get malware samples to study?
« Reply #1 on: May 14, 2015, 01:24:54 pm »
What about VX heavens, they have a huge DB - like 60GB worth.

Offline ColonelPanic

  • Serf
  • *
  • Posts: 27
  • Cookies: 7
    • View Profile
Re: Where do you get malware samples to study?
« Reply #2 on: May 14, 2015, 01:28:13 pm »
I've been wondering this myself lately. Thanks man!

Offline parad0x

  • VIP
  • Royal Highness
  • *
  • Posts: 638
  • Cookies: 118
    • View Profile
Re: Where do you get malware samples to study?
« Reply #3 on: May 14, 2015, 04:09:23 pm »
What about VX heavens, they have a huge DB - like 60GB worth.
But most of them are quite old, really old that will be fun to study but as the advancements in OS implementations, some may cease to work and with this net connection, I can't dl 60GB torrent even in 2 lives. Any other repo that, you know has some recent malware?
« Last Edit: May 14, 2015, 04:34:32 pm by parad0x »


Offline 0E 800

  • Not a VIP
  • VIP
  • Baron
  • *
  • Posts: 895
  • Cookies: 131
  • • тнε ιηтεяηεт ιs мү яεcүcℓε-вιη •
    • View Profile
Re: Where do you get malware samples to study?
« Reply #5 on: May 14, 2015, 11:53:24 pm »
I am guessing your talking about malware sourcecode. If not, then I suggest downloading any number of keygens or cracks from torrents.

The invariable mark of wisdom is to see the miraculous in the common.

Offline parad0x

  • VIP
  • Royal Highness
  • *
  • Posts: 638
  • Cookies: 118
    • View Profile
Re: Where do you get malware samples to study?
« Reply #6 on: May 15, 2015, 02:37:10 am »
I am guessing your talking about malware sourcecode. If not, then I suggest downloading any number of keygens or cracks from torrents.
I was talking about executable malwares but if you have any resources that have source code of malwares, I would love to have it. :)

https://www.reddit.com/r/Malware/comments/35pd40/good_database_sites/
https://www.reddit.com/r/Malware/comments/2yclnp/is_there_any_database_i_could_download_malware/

Thanks you man. :) +1 for you. That link has some good resources.

Offline xor

  • Peasant
  • *
  • Posts: 59
  • Cookies: 32
    • View Profile
Re: Where do you get malware samples to study?
« Reply #7 on: May 15, 2015, 03:14:29 am »
If you're not talking about malware source code and you just want executables, just open up those spam emails you get and start clicking all the links. Easiest way to get the latest malware.

Offline parad0x

  • VIP
  • Royal Highness
  • *
  • Posts: 638
  • Cookies: 118
    • View Profile
Re: Where do you get malware samples to study?
« Reply #8 on: May 15, 2015, 04:27:20 am »
If you're not talking about malware source code and you just want executables, just open up those spam emails you get and start clicking all the links. Easiest way to get the latest malware.
To be honest, I have 0 spam mails in my inbox and as I said to 0E 800, if you have resources that have malware source code, let me know.

Offline Psycho_Coder

  • Knight
  • **
  • Posts: 166
  • Cookies: 84
  • Programmer, Forensic Analyst
    • View Profile
    • Code Hackers Blog
Re: Where do you get malware samples to study?
« Reply #9 on: May 15, 2015, 01:51:22 pm »
Google would have fetched you much better results. Searching Google with terms like "Malware samples download" or "Malware dataset" or "Malware samples for research" will fetch you lots of results.

The following link will help you not just with Datasets but much more.

https://github.com/rshipp/awesome-malware-analysis
« Last Edit: May 15, 2015, 01:54:31 pm by Psycho_Coder »
"Don't do anything by half. If you love someone, love them with all your soul. When you hate someone, hate them until it hurts."--- Henry Rollins


Offline nozzlechunks

  • Serf
  • *
  • Posts: 22
  • Cookies: -3
    • View Profile
Re: Where do you get malware samples to study?
« Reply #11 on: June 18, 2015, 04:37:04 pm »
Just go to your google junk mail bin and detonate all the attachments in VM with Wireshark on.

A lof of the lures are macro-enabled docs that actually POLITELY ASK the victim to enable macros. I wrote a Python script using oletools to extract the VBA from from these docs, then insert the VBA into a new doc, comment out all the AutoRun and Shell lines, and step through it.

You'll see callbacks, the location of the instructions its pull, as well as what the file names itself and its path.