Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

Malware

Malware can take various forms, including viruses, worms, Trojans, ransomware, spyware, and more. Its primary goal is to compromise the integrity, confidentiality, or availability of information, often for financial gain, espionage, or other malicious purposes.

https://github.com/jpcertcc/impfuzzy

Fuzzy Hash calculated from import API of PE files

clustering impfuzzy malware neo4j python security volatility

Last synced: 10 Jan 2025

https://github.com/JPCERTCC/impfuzzy

Fuzzy Hash calculated from import API of PE files

clustering impfuzzy malware neo4j python security volatility

Last synced: 29 Dec 2024

https://github.com/alichtman/malware-techniques

A collection of techniques commonly used in malware to accomplish core tasks.

linux macos malware malware-analysis malware-development malware-research reverse-engineering

Last synced: 27 Oct 2024

https://github.com/te-k/pecli

CLI tool to analyze PE files

malware malware-analysis reverse-engineering

Last synced: 29 Nov 2024

https://github.com/nyan-x-cat/dropless-malware

Download a payload and make it run from registry without droppng.

backdoor downloader drop dropper malware persistence

Last synced: 08 Nov 2024

https://github.com/clrxbl/nekoclient

Deobfuscated June 2023 CurseForge malware ("fractureiser") stage 3 payload

2023 curseforge fractureiser malware minecraft

Last synced: 11 Nov 2024

https://github.com/peterdavehello/threat-hostlist

Comprehensive domain blocklists for 🚨 threats (🕷malware, 🎣phishing, 🕵️spyware, 🤖botnets). Ideal for DNS-based filtering tools like Pi-Hole, AdGuard Home, Blocky.

adguard-blocklist blocklist botnets cybersecurity dns domain hacktoberfest hosts infosec malware osint phishing ransomware security spyware threat-intelligence threats

Last synced: 20 Dec 2024

https://github.com/qeeqbox/mitre-visualizer

🧬 Mitre Interactive Network Graph (APTs, Malware, Tools, Techniques & Tactics)

advanced-persistent-threat attack malware mitre network-graph tactic technique tool

Last synced: 15 Nov 2024

https://github.com/hackthedev/teardrop

Open-Source Ransomware Project for learning purpose only written in C# (csharp). Dont use it for bad things.

csharp educational educational-project encryption executeable gpl3 gplv3 leaning learning-by-doing malicious malware ransomware virus windows

Last synced: 23 Nov 2024

https://github.com/adulau/malwareclassifier

Malware Classifier From Network Captures

malware malware-classifier network-capture python tshark visualization

Last synced: 18 Nov 2024

https://github.com/byt3n33dl3/thefatrat_v2

TFRv2 : Remote control Access, used as a Bypasser for Anti Virus (Software) and Penetrate a FLAGSHIP Such as Android, Windows, and MacOS.

autorun backdoor bypass-av linux malware msfvenom remoteaccess shellcode thefatrat trojan

Last synced: 08 Jan 2025

https://github.com/sisoma2/shellcodeloader

Small tool to load shellcodes or PEs to analyze them

breakpoint malware malware-analysis shellcode visual-studio windows

Last synced: 16 Oct 2024

https://github.com/lennolium/privacyshield

A comprehensive All-in-One AdGuard Filter List optimized for DNS level blocking of Ads, Analytics, Tracking, Malware & Scam.

ad-blocker adblock adguard ads analytics blacklist blocklist dns filter hosts malware phishing pi-hole privacy protection scam security tracking whitelist

Last synced: 10 Oct 2024

https://github.com/mueller-ma/block-ads-via-dns

Block ads and malware via local DNS server

debian-server dns-server malware

Last synced: 07 Nov 2024

https://github.com/processust/venoma

Yet another C++ Cobalt Strike beacon dropper with Compile-Time API hashing and custom indirect syscalls execution

antivirus bypass c2 cobalt dropper edr indirect malware payload pentest red strike syscalls team

Last synced: 09 Dec 2024

https://github.com/ryuchen/panda-sandbox

这是一个基于 Cuckoo 开源版本的沙箱的修订版本, 该版本完全为了适配国内软件环境所打造

cuckoo cuckoo-sandbox malware malware-analysis sandbox security

Last synced: 28 Oct 2024

https://github.com/ayoubfaouzi/binary-auditing-solutions

Learn the fundamentals of Binary Auditing. Know how HLL mapping works, get more inner file understanding than ever.

binary-analysis decompilation disassembly ida-pro malware reverse-engineering static-analysis unpacking

Last synced: 10 Dec 2024

https://github.com/adrianlois/dfir-detection-engineering

Digital Forensics Incident Response and Detection engineering: Análisis forense de artefactos comunes y no tan comunes. Técnicas anti-forense y detección de técnicas utilizadas por actores maliciosos para la evasión de sistemas de protección y monitorización.

anti-forense artefactos artefacts cybersecurity deteccion detection-engineering dfir digital-forensics evidencias forense forensics incident-response linux macosx malware security tips tricks windows

Last synced: 22 Jan 2025

https://github.com/mgeeky/msi-shenanigans

Proof of Concept code and samples presenting emerging threat of MSI installer files.

malware red-team security

Last synced: 29 Oct 2024

https://github.com/deadbits/malware-analysis-scripts

Collection of scripts for different malware analysis tasks

malware malware-analysis malware-research reverse-engineering

Last synced: 13 Dec 2024

https://github.com/billythegoat356/vulture

Vulture is a tool allowing you to access all the files on a second computer from your terminal.

cd client dir directories directory dirs file files ftp ls malware server tcp udp

Last synced: 10 Nov 2024

https://github.com/albertzsigovits/malware-tools

A curated list of malware repositories, trackers and malware analysis tools

malware malware-analysis malware-research malware-tools malwareanalysis reverse-engineering

Last synced: 18 Nov 2024

https://github.com/PeterDaveHello/chkdomain

🔍 Discover if a domain is resolvable or blocked by secure DNS and Ad-blocking services, and experience the innovative idea of DaaS - DNS as an Intelligence Service.

adblock cybersecurity dns domain filter hacktoberfest infosec malware osint phishing security threat-intelligence

Last synced: 14 Dec 2024

https://github.com/peterdavehello/chkdomain

🔍 Discover if a domain is resolvable or blocked by secure DNS and Ad-blocking services, and experience the innovative idea of DaaS - DNS as an Intelligence Service.

adblock cybersecurity dns domain filter hacktoberfest infosec malware osint phishing security threat-intelligence

Last synced: 23 Jan 2025

https://github.com/pchaigno/dga-collection

A collection of known Domain Generation Algorithms

dga dga-collection malware

Last synced: 28 Oct 2024

https://github.com/wurstcommander/win10appremove

A Powershell-Script for removing / debloating Windows 10 apps. Mandatory apps which can't be uninstalled via start menu will be removed too.

appstore appxpackages bloatware debloat debloater explorer folders libraries malware microsoft powershell-script preinstalled regedit remove remover win10 windows windows10 windowsapp windowsstore

Last synced: 11 Oct 2024

https://github.com/darkcodersc/inno-shellcode-example

Run shellcode through InnoSetup code engine.

inno inno-setup malware shellcode windows

Last synced: 28 Oct 2024

https://github.com/WurstCommander/Win10AppRemove

A Powershell-Script for removing / debloating Windows 10 apps. Mandatory apps which can't be uninstalled via start menu will be removed too.

appstore appxpackages bloatware debloat debloater explorer folders libraries malware microsoft powershell-script preinstalled regedit remove remover win10 windows windows10 windowsapp windowsstore

Last synced: 04 Dec 2024

https://github.com/zhuagenborn/windows-dll-injector

💉 A Windows dynamic-link library injection tool written in C++20. It can inject a dynamic-link library into a running process by its window title or create a new process with an injection.

cpp20 cybersecurity dll-inection malware windows

Last synced: 24 Jan 2025

https://github.com/dbrennand/virustotal-python

A Python library to interact with the public VirusTotal v3 and v2 APIs.

malware malware-analysis python python3 security virustotal virustotal-python wrapper

Last synced: 10 Jan 2025

https://github.com/ngn13/shrk

LKM rootkit for modern kernels, with DNS C2 and a simple web interface

linux-rootkit lkm-rootkit malware rootkit

Last synced: 23 Jan 2025

https://github.com/darkempire78/windows-keylogger

A Windows keylogger undetected by all major anti-virus. Log keys, clipboard, window titles and send logs to a server.

antivirus keylogger keylogging malware malware-sample windows windows-keylogger

Last synced: 15 Nov 2024

https://github.com/cvar1984/sussyfinder

Single file php webshell scanner to detect potentially malicious backdoor based on token and hash with web interface and VirusTotal integration

antivirus backdoor forensics hacktoberfest malware malware-analysis php webshells

Last synced: 23 Jan 2025

https://github.com/zhuagenborn/goasm-rat

💻 A Windows console remote administration tool written in Go & Intel x86 Assembly. It supports remote shell and screenshot.

cybersecurity malware network remote-administration-tool socket windows

Last synced: 08 Nov 2024

https://github.com/darxisr/cryline-v5.0

Cryline project - It's a simple test ransomware for Windows OS without stable encryption. Pls use this source code for study purposes only. The author is't responsible for your actions.

assembly bootkit bootloader cipher cplusplus development drive encryption hardware malware mbr notpetya petya programming ransomware security source-code subsystem virus windows

Last synced: 23 Jan 2025

https://github.com/brosck/frosty

「🧊」Ring 3 Rootkit for Windows 10

dll frosty malware ring3 rootkit service windows

Last synced: 21 Jan 2025

https://github.com/waja/maldetect

Debian packaging of Linux Malware Detect (https://github.com/rfxn/linux-malware-detect)

debian debian-packages malware malware-analysis shell

Last synced: 29 Nov 2024

https://github.com/machine1337/fudshell

An efficent Script To Generate FUD Persistent Reverse Shell For Red Teaming. Don't Upload Generated Stub On Virustotal

antivirus-evasion evasion fud fud-rat hacking kali-linux machine1337 malware python rat redteaming reverse-shell windows windows-rat

Last synced: 10 Nov 2024

https://github.com/nyan-x-cat/csharp-loader

Download a .NET payload and run it on memory

backdoor dropper loader malware payload stub

Last synced: 08 Nov 2024

https://github.com/nyan-x-cat/malwareshell

Create a powershell malware loader to run C#.cs code on runtime

backdoor downloader loader malware payload poweshell ps1

Last synced: 08 Nov 2024

https://github.com/nyan-x-cat/njrat-0.7d-stub-csharp

njRAT C# Stub - Fixed For PowerShell

backdoor client malware njrat powershell rat stub

Last synced: 08 Nov 2024

https://github.com/jaybrown/macos-security-updates

Notifies the user when macOS Security components like Gatekeeper and XProtect have been updated

catalina efi gatekeeper ibridge launchagent macos malware mrt privacy protection security tcc xplorer xprotect

Last synced: 20 Nov 2024

https://github.com/qeeqbox/rhino

Agile Sandbox for analyzing Windows, Linux and macOS malware and execution behaviors

agile analysis api behavior customizable linux macos malware react-interface sandbox virtualbox vms webinterface windows

Last synced: 15 Nov 2024

https://github.com/nyan-x-cat/js-downloader

JS Jscript - download file from url then run it

backdoor download downloader js jscript malware run

Last synced: 08 Nov 2024

https://github.com/darkarp/malwaredevseries

Malware develoment in Rust

malware reverse-shell rust twitch youtube

Last synced: 28 Oct 2024

https://github.com/rpgeeganage/file-less-ransomware-demo

Demonstrate about file-less malware approach using JavaScript

file-less javascript malware ransom-worm ransomware ransomware-resources

Last synced: 27 Oct 2024

https://github.com/nyan-x-cat/limelogger

Simple C# Keylogger (Keyboard Layout)

backdoor keylogger language lime logger malware multi payload

Last synced: 08 Nov 2024

https://github.com/jpcertcc/lazarus-research

Lazarus analysis tools and research report

malware security

Last synced: 05 Nov 2024

https://github.com/rickmark/mojo_thor

Research about malware that infects the EFI and SMC of Apple MacBooks.

apple efi malware rootkit

Last synced: 14 Oct 2024

https://github.com/checkpointsw/anti-debug-db

Anti-Debug encyclopedia contains methods used by malware to verify if they are executed under debugging. It includes the description of various anti-debug tricks, their implementation, and recommendations of how to mitigate the each trick.

anti-debug malware research

Last synced: 11 Jan 2025

https://github.com/guitmz/go-liora

Probably the first binary (PE/ELF) infector ever created in GoLang.

elf go golang linux malware virus vx

Last synced: 09 Nov 2024

https://github.com/imp0rtp3/Yobi

Yara Based Detection Engine for web browsers

add-on antivirus dfir firefox javascript malware scanner yara

Last synced: 13 Nov 2024

https://github.com/krisnova/kush

Kubernetes Unhinged Shell 😎

kubernetes malware

Last synced: 08 Nov 2024

https://github.com/scrapbird/sarlacc

SMTP server / sinkhole for collecting spam

malware sinkhole smtp-server spam

Last synced: 17 Nov 2024

https://github.com/mucoze/Umay

IoT Malware Similarity Analysis Platform

django infosec iot malware malware-analysis reverse-engineering static-analysis

Last synced: 21 Nov 2024

https://github.com/eset/wslink-vm-analyzer

WslinkVMAnalyzer is a tool to facilitate analysis of code protected by a virtual machine featured in Wslink malware

deobfuscation malware miasm reverse-engineering virtual-machine

Last synced: 09 Nov 2024

https://github.com/accidentalrebel/ratwurst

Windows-only Remote Access Tool (RAT) with anti-debugging and anti-sandbox checks. For educational purposes only.

malware rat

Last synced: 26 Jan 2025

https://github.com/cristianzsh/csharp-keylogger

:keyboard: A keylogger written in C# + Send by email

csharp email keylogger malware security security-tools send-email windows

Last synced: 17 Nov 2024

https://github.com/billythegoat356/cerberus

A complete Grabber, sending data to a TCP server that you have to host and stocking all in a database.

discord discord-webhook grabber host malware poc python stealer tcp token-grabber virus webhook

Last synced: 10 Nov 2024

https://github.com/te-k/apkcli

CLI tool to analyze APKs

android malware malware-analysis reverse-engineering

Last synced: 07 Nov 2024

https://github.com/whokilleddb/injection-for-dummies

A collection of PoCs for different injection techniques on Windows!

dll-injection hacking injection injection-attacks malware red-team shellcode shellcode-injection windows

Last synced: 08 Nov 2024

https://github.com/ruzickap/malware-cryptominer-container

Container image with malware and crypto miner for testing purposes

container crypto cryptominer dockerfile eicar image malware test xmrig

Last synced: 26 Jan 2025

https://github.com/guitmz/midrashim

PT_NOTE to PT_LOAD x64 ELF infector written in Assembly

asm assembly elf infector linux malware virus

Last synced: 09 Nov 2024

https://github.com/elastic/die-python

Native Python3 bindings for @horsicq's Detect-It-Easy

detect-it-easy malware malware-analysis malware-research python python3

Last synced: 07 Oct 2024

https://github.com/PL-V/Firefox-WebInject

Firefox webInjector capable of injecting codes into webpages using a mitmproxy.

hacking-tool hooking malware malware-development red-teaming

Last synced: 04 Nov 2024

https://github.com/fmind/euphony

Harmonious Unification of Cacophonous Anti-Virus Vendor Labels for Android Malware

android antivirus clustering label malware

Last synced: 06 Nov 2024

https://github.com/gdatasoftwareag/vaas

Verdict-as-a-Service SDKs: Analyze files for malicious content

it-security malware malware-analysis malware-detection security

Last synced: 11 Nov 2024

https://github.com/GDATASoftwareAG/vaas

Verdict-as-a-Service SDKs: Analyze files for malicious content

it-security malware malware-analysis malware-detection security

Last synced: 21 Nov 2024

https://github.com/mandiant/apooxml

Generate YARA rules for OOXML documents.

detection malware ooxml security yara

Last synced: 10 Nov 2024

https://github.com/aress31/sci

Framework designed to automate the process of assembly code injection (trojanising) within Android applications.

android assembly code-injection framework malware mobile-security pentesting python reverse-engineering smali spyware trojan

Last synced: 28 Oct 2024

https://github.com/nyan-x-cat/vbs-shell

using VBS to download and install a powershell malware

backdoor downloader loader malware powershell vbs

Last synced: 08 Nov 2024