{"id":26654164,"url":"https://github.com/malice-plugins/floss","last_synced_at":"2025-04-11T07:19:20.080Z","repository":{"id":57605157,"uuid":"62006598","full_name":"malice-plugins/floss","owner":"malice-plugins","description":"Malice Floss Plugin","archived":false,"fork":false,"pushed_at":"2019-01-07T16:43:43.000Z","size":3499,"stargazers_count":6,"open_issues_count":0,"forks_count":5,"subscribers_count":3,"default_branch":"master","last_synced_at":"2025-03-21T22:11:20.402Z","etag":null,"topics":["docker","fire-eye","floss","malice","malware","plugin","strings"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/malice-plugins.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2016-06-26T20:16:15.000Z","updated_at":"2023-07-07T02:48:56.000Z","dependencies_parsed_at":"2022-08-27T22:03:12.896Z","dependency_job_id":null,"html_url":"https://github.com/malice-plugins/floss","commit_stats":null,"previous_names":["maliceio/malice-floss"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/malice-plugins%2Ffloss","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/malice-plugins%2Ffloss/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/malice-plugins%2Ffloss/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/malice-plugins%2Ffloss/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/malice-plugins","download_url":"https://codeload.github.com/malice-plugins/floss/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":245401369,"owners_count":20609167,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["docker","fire-eye","floss","malice","malware","plugin","strings"],"created_at":"2025-03-25T04:57:35.589Z","updated_at":"2025-03-25T04:57:36.158Z","avatar_url":"https://github.com/malice-plugins.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"![FLOSS-logo](https://raw.githubusercontent.com/malice-plugins/floss/master/logo.png)\n\n# malice-floss\n\n[![Circle CI](https://circleci.com/gh/malice-plugins/floss.png?style=shield)](https://circleci.com/gh/malice-plugins/floss) [![License](http://img.shields.io/:license-mit-blue.svg)](http://doge.mit-license.org) [![Docker Stars](https://img.shields.io/docker/stars/malice/floss.svg)](https://hub.docker.com/r/malice/floss/) [![Docker Pulls](https://img.shields.io/docker/pulls/malice/floss.svg)](https://hub.docker.com/r/malice/floss/) [![Docker Image](https://img.shields.io/badge/docker%20image-90.4MB-blue.svg)](https://hub.docker.com/r/malice/floss/)\n\nMalice FLOSS Plugin\n\n\u003e This repository contains a **Dockerfile** of the [FLOSS](https://github.com/fireeye/flare-floss) malice plugin **malice/floss**.\n\n---\n\n### Dependencies\n\n- [malice/alpine](https://hub.docker.com/r/malice/alpine/)\n\n## Installation\n\n1. Install [Docker](https://www.docker.io/).\n2. Download [trusted build](https://hub.docker.com/r/malice/floss/) from public [DockerHub](https://hub.docker.com): `docker pull malice/floss`\n\n## Usage\n\n```bash\ndocker run --rm -v /path/to/file:/malware:ro malice/floss FILE\n\nUsage: floss [OPTIONS] COMMAND [arg...]\n\nMalice FLOSS Plugin\n\nVersion: v0.1.0, BuildTime: 20180903\n\nAuthor:\n  blacktop - \u003chttps://github.com/blacktop\u003e\n\nOptions:\n  --verbose, -V          verbose output\n  --timeout value        malice plugin timeout (in seconds) (default: 120) [$MALICE_TIMEOUT]\n  --elasticsearch value  elasticsearch url for Malice to store results [$MALICE_ELASTICSEARCH_URL]\n  --callback, -c         POST results to Malice webhook [$MALICE_ENDPOINT]\n  --proxy, -x            proxy settings for Malice webhook endpoint [$MALICE_PROXY]\n  --table, -t            output as Markdown table\n  --all, -a              output ascii/utf-16 strings\n  --help, -h             show help\n  --version, -v          print the version\n\nCommands:\n  web   Create a FLOSS scan web service\n  help  Shows a list of commands or help for one command\n\nRun 'floss COMMAND --help' for more information on a command.\n```\n\nThis will output to stdout and POST to malice results API webhook endpoint.\n\n## Sample Output\n\n### [JSON](https://github.com/malice-plugins/floss/blob/master/docs/results.json)\n\n```json\n{\n  \"floss\": {\n    \"ascii\": null,\n    \"utf-16\": null,\n    \"decoded\": [\n      {\n        \"location\": \"0x401059\",\n        \"strings\": [\n          \"*lecnaC*\",\n          \"Software\\\\Microsoft\\\\CurrentNetInf\",\n          \"SYSTEM\\\\CurrentControlSet\\\\Control\\\\Lsa\",\n          \"Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies\\\\Explorer\\\\Run\",\n          \"MicrosoftZj\",\n          \"LhbqnrnesDwhs\",\n          \"MicrosoftHaveExit\",\n          \"LhbqnrnesG`ud@bj\",\n          \"IEXPLORE.EXE\",\n          \"/ver.htm\",\n          \"/exe.htm\",\n          \"/app.htm\",\n          \"/myapp.htm\",\n          \"/hostlist.htm\",\n          \".a`j-gsl\",\n          \"/SomeUpList.htm\",\n          \"/SomeUpVer.htm\",\n          \"www.flyeagles.com\",\n          \"www.km-nyc.com\",\n          \"/restore\",\n          \"/dizhi.gif\",\n          \"/connect.gif\",\n          \"\\\\$NtUninstallKB900727$\",\n          \"\\\\netsvc.exe\",\n          \"\\\\netscv.exe\",\n          \"\\\\netsvcs.exe\",\n          \"System Idle Process\",\n          \"Program Files\",\n          \"\\\\Internet Exp1orer\",\n          \"forceguest\",\n          \"AudioPort\",\n          \"AudioPort.sys\",\n          \"SYSTEM\\\\CurrentControlSet\\\\Services\",\n          \"SYSTEM\\\\ControlSet001\\\\Services\",\n          \"SYSTEM\\\\ControlSet002\\\\Services\",\n          \"\\\\drivers\\\\\",\n          \"\\\\DriverNum.dat\"\n        ]\n      },\n      {\n        \"location\": \"0x404DDE\",\n        \"strings\": [\n          \"SMBs\",\n          \"NTLMSSP\",\n          \"Windows 2000 2195\",\n          \"Windows 2000 5.0\",\n          \"SMBr\",\n          \"PC NETWORK PROGRAM 1.0\",\n          \"LANMAN1.0\",\n          \"Windows for Workgroups 3.1a\",\n          \"LM1.2X002\",\n          \"LANMAN2.1\",\n          \"NT LM 0.12\"\n        ]\n      },\n      {\n        \"location\": \"0x401047\",\n        \"strings\": [\"Ie_nkokbpAtep\", \"+^]g*dpi\", \"Ie_nkokbpD]ra=_g\"]\n      }\n    ],\n    \"stack\": [\"cmd.exe\"]\n  }\n}\n```\n\n### [Markdown](https://github.com/malice-plugins/floss/blob/master/docs/SAMPLE.md)\n\n---\n\n#### Floss\n\n##### Decoded Strings\n\nLocation: `0x401059`\n\n- `*lecnaC*`\n- `Software\\Microsoft\\CurrentNetInf`\n- `SYSTEM\\CurrentControlSet\\Control\\Lsa`\n- `Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run`\n- `MicrosoftZj`\n- `LhbqnrnesDwhs`\n- `MicrosoftHaveExit`\n- `LhbqnrnesG`ud@bj\\`\n- `IEXPLORE.EXE`\n- `/ver.htm`\n- `/exe.htm`\n- `/app.htm`\n- `/myapp.htm`\n- `/hostlist.htm`\n- `.a`j-gsl\\`\n- `/SomeUpList.htm`\n- `/SomeUpVer.htm`\n- `www.flyeagles.com`\n- `www.km-nyc.com`\n- `/restore`\n- `/dizhi.gif`\n- `/connect.gif`\n- `\\$NtUninstallKB900727$`\n- `\\netsvc.exe`\n- `\\netscv.exe`\n- `\\netsvcs.exe`\n- `System Idle Process`\n- `Program Files`\n- `\\Internet Exp1orer`\n- `forceguest`\n- `AudioPort`\n- `AudioPort.sys`\n- `SYSTEM\\CurrentControlSet\\Services`\n- `SYSTEM\\ControlSet001\\Services`\n- `SYSTEM\\ControlSet002\\Services`\n- `\\drivers\\`\n- `\\DriverNum.dat`\n\nLocation: `0x404DDE`\n\n- `SMBs`\n- `NTLMSSP`\n- `Windows 2000 2195`\n- `Windows 2000 5.0`\n- `SMBr`\n- `PC NETWORK PROGRAM 1.0`\n- `LANMAN1.0`\n- `Windows for Workgroups 3.1a`\n- `LM1.2X002`\n- `LANMAN2.1`\n- `NT LM 0.12`\n\nLocation: `0x401047`\n\n- `Ie_nkokbpAtep`\n- `+^]g*dpi`\n- `Ie_nkokbpD]ra=_g`\n\n##### Stack Strings\n\n- `cmd.exe`\n\n---\n\n## Documentation\n\n- [To write results to ElasticSearch](https://github.com/malice-plugins/floss/blob/master/docs/elasticsearch.md)\n- [To create a FLOSS scan micro-service](https://github.com/malice-plugins/floss/blob/master/docs/web.md)\n- [To post results to a webhook](https://github.com/malice-plugins/floss/blob/master/docs/callback.md)\n\n## Issues\n\nFind a bug? Want more features? Find something missing in the documentation? Let me know! Please don't hesitate to [file an issue](https://github.com/malice-plugins/floss/issues/new)\n\n## CHANGELOG\n\nSee [`CHANGELOG.md`](https://github.com/malice-plugins/floss/blob/master/CHANGELOG.md)\n\n## Contributing\n\n[See all contributors on GitHub](https://github.com/malice-plugins/floss/graphs/contributors).\n\nPlease update the [CHANGELOG.md](https://github.com/malice-plugins/floss/blob/master/CHANGELOG.md) and submit a [Pull Request on GitHub](https://help.github.com/articles/using-pull-requests/).\n\n## TODO\n\n- [ ] https://bitbucket.org/cse-assemblyline/alsvc_frankenstrings\n- [ ] prevent URLs from being rendered as links in MarkDown :warning:\n\n## License\n\nMIT Copyright (c) 2016 **blacktop**\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmalice-plugins%2Ffloss","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmalice-plugins%2Ffloss","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmalice-plugins%2Ffloss/lists"}