{"id":21988569,"url":"https://github.com/lubyruffy/malware-catalog","last_synced_at":"2026-04-13T12:31:36.180Z","repository":{"id":78834835,"uuid":"194040598","full_name":"LubyRuffy/malware-catalog","owner":"LubyRuffy","description":null,"archived":false,"fork":false,"pushed_at":"2019-04-23T20:27:58.000Z","size":1970,"stargazers_count":0,"open_issues_count":0,"forks_count":1,"subscribers_count":0,"default_branch":"master","last_synced_at":"2025-03-23T02:42:46.048Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/LubyRuffy.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2019-06-27T07:01:15.000Z","updated_at":"2024-07-04T10:50:39.000Z","dependencies_parsed_at":"2023-04-13T05:48:48.721Z","dependency_job_id":null,"html_url":"https://github.com/LubyRuffy/malware-catalog","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/LubyRuffy/malware-catalog","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LubyRuffy%2Fmalware-catalog","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LubyRuffy%2Fmalware-catalog/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LubyRuffy%2Fmalware-catalog/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LubyRuffy%2Fmalware-catalog/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/LubyRuffy","download_url":"https://codeload.github.com/LubyRuffy/malware-catalog/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/LubyRuffy%2Fmalware-catalog/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31753050,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-13T09:16:15.125Z","status":"ssl_error","status_checked_at":"2026-04-13T09:16:05.023Z","response_time":93,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-29T19:19:17.077Z","updated_at":"2026-04-13T12:31:36.153Z","avatar_url":"https://github.com/LubyRuffy.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"\n\n\tSet of tools that is easy to use and modify\n\n\tthis repo has:\n\t\t\n\t\tsetup/ (for getting all your shitware files ready!)\n\t\t\tsfile.sh - generate hash for versioning file\n\t\t\tmulti-sfile.sh - my multi-infile adaptation\n\t\t\tsd7z.sh - autoextract archives (use this after sfile)\n\t\t\tsha1dir.sh - sfile for directories\n\n\n\t\texploits/ folder -\n\t\t\tsource files for each exploit\n\t\t\t\t(file names are referenced in the exploit yaml entries)\n\t\t\t\n\t\tscripts/\n\t\t\tmakeyaml.py - establish yaml for each of the provided variants\n\t\t\ttest.py (main) - everything else\n\t\t\ty2j.py - convert yaml to json\n\n\t\t\tscripts/input/\n\t\t\t\tyara.txt - output from running yara against everything\n\t\t\t\tall the exploits.yml\n\t\t\t\texploits.txt - each exploit name \n\t\t\t\tmirai.txt - mirai variant names\n\t\t\t\tqbot.txt - qbot variant names\n\t\t\tscripts/output/\n\t\t\t\texamples/\n\t\t\t\t\tjson output example\n\t\t\t\t\texploits-by-variant and vice versa - populated structure output (just print the return values)\n\n\n\t\tyara/\n\t\t\ttemplate.yar\n\t\t\teach rule file\n\n\n\n\n\tscript details-\n\t### makeyaml.py\n\tcontains the function for establishing YAML scaffolding - uses provided variant list (.txt, one name per line)\n\n\t### test.py - main\n\tload_exploits: heavy lifter - reads yaml entries for all exploits (currently being used as a single sequential file)\n\n\tFunctions for auto-generating lists:\n\t\tUses yara output to scrape exploit names and the bot variant whose directory they're appearing in to map out relationships.\n\t\t\n\t\tThere are two structures:\n\t\n\t\t\tKey: Exploit name\n\t\t\tValue: List of bot variants that use it\n\n\t\t\t\tand\n\n\t\t\tKey: Variant name\n\t\t\tValue: List of exploits it uses\n\n\t\tThese are used for generating other aspects of the structure, and I plan to use the (key:exploit/value:variants that use it) one\n\t\tto populate the used_by field throughout my exploit yaml entries - it is currently lacking.\n\n\tEstablishing these tools means every aspect of this is automated - all you need to provide is a few text files to read names from\n\tThis makes the whole thing easy to expand to any sort of file. All that would need to be written in is consideration for any new relevant fields\n\n\n\tCurrently perfectly easy to dump yaml then convert directly to json.\n\n\n\tFlow:\n\t\tRun full set of yara rules recursively in parent bot directory. Use (quite robust) output as input for this script - it scrapes\n\t\tunique pairings of exploit and variant, mapping them accurately, and leaving you with a complete set of exploits-by-variant and variants-by-exploit\n\t\t\n\t\tUse YAML auto-scaffolding functionality w/ list of variant names to auto-generate yaml structure + designated fields for each variant\n\t\t\n\t\trun function to populate \"exploits\" field for each variant with whatever exploits are relevant to them (again, the inverse will work for populating exploits.yaml's \"used_by\" field)\n\n\n\t\tthe outermost data structure can be dumped directly via yaml.dump(), and even passed right into the yaml to json function - \n\n\t\trun just python3 test.py, w/ resources in place as intended, and you will have console output of accurate json for all of your variants (or exploits, or anything else you've constructed.)\n\n\n\n\n\tTodo:\n\tHandling for dicts/better handling of nested data. Haven't specialized it enough for all cases.\n\n\tWrite a quick loop for splitting yaml or json entries into individual files w/ hashed or timestamped name\n\t\n\tSpecify outstanding fields for YAML auto-scaffolding  (identify which variants have external creds or other stuff - easy to do w/ diff)\n\n\tFinish yara rules\n\t\n\tReplace yara.txt with new output from running complete set of rules\n\t\n\tUpdate any other word lists\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Flubyruffy%2Fmalware-catalog","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Flubyruffy%2Fmalware-catalog","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Flubyruffy%2Fmalware-catalog/lists"}