Author Topic: OS X Malware.  (Read 503 times)

0 Members and 1 Guest are viewing this topic.

Offline hack3rcon

  • Peasant
  • *
  • Posts: 80
  • Cookies: -216
    • View Profile
OS X Malware.
« on: September 16, 2015, 11:06:47 am »
Hello.
I want to test some OS X malware and I need one of below malware :

1- Renepo/Leap-A, 2004 and 2006
2- RSPlug-A, 2007
3- iWorkS-A Trojan, 2009
4- MacDefender, 2011
5- Flashback/SabPub, 2012

I just want test my OS X and Kaspersky antivirus.

Thank you.
« Last Edit: September 16, 2015, 11:08:24 am by hack3rcon »

Offline Deque

  • P.I.N.N.
  • Global Moderator
  • Overlord
  • *
  • Posts: 1203
  • Cookies: 518
  • Programmer, Malware Analyst
    • View Profile
Re: OS X Malware.
« Reply #1 on: September 16, 2015, 03:01:36 pm »
If you just want to test your antivirus software, you only need an EICAR file.
EICAR is a non-malicious file with a specific string that is detected by all antivirus products.

http://www.eicar.org/85-0-Download.html

If you really want malware for testing, search for file hashes and we might be able to help you.
« Last Edit: September 16, 2015, 03:06:24 pm by Deque »

Offline hack3rcon

  • Peasant
  • *
  • Posts: 80
  • Cookies: -216
    • View Profile
Re: OS X Malware.
« Reply #2 on: September 16, 2015, 09:35:19 pm »
If you just want to test your antivirus software, you only need an EICAR file.
EICAR is a non-malicious file with a specific string that is detected by all antivirus products.

http://www.eicar.org/85-0-Download.html

If you really want malware for testing, search for file hashes and we might be able to help you.

Thank you.
Can you show me some some web sites for download malware for test?

Offline Deque

  • P.I.N.N.
  • Global Moderator
  • Overlord
  • *
  • Posts: 1203
  • Cookies: 518
  • Programmer, Malware Analyst
    • View Profile
Re: OS X Malware.
« Reply #3 on: September 16, 2015, 10:34:57 pm »
Thank you.
Can you show me some some web sites for download malware for test?

Depends what you need.

hybrid-analysis.com allows you to download shared samples, so do some other automated analysis platforms.
And then there are huge databases, some free (virusshare.com, open malware), some not (virustotal).

Honeypots and malwareurl lists (e.g. malwareurl.com) are a possibility too. With malwareurls you can download pretty fresh samples from the listed domains and IPs.

Most free illegal stuff, hacking tools too good to be true (e.g. promising to hack facebook accounts with a click), are riddled with malware. This is good to get new malware in the wild, but of course not good if you want a particular sample.

Forums like kernelmode.info discuss reverse engineering of malware and provide a subforum to ask for specific samples.