diff --git a/.gitignore b/.gitignore index 39f332e..9c658c5 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,178 @@ +# Created by .ignore support plugin (hsz.mobi) +### macOS template +# General +.DS_Store +.AppleDouble +.LSOverride + +# Icon must end with two \r +Icon + +# Thumbnails +._* + +# Files that might appear in the root of a volume +.DocumentRevisions-V100 +.fseventsd +.Spotlight-V100 +.TemporaryItems +.Trashes +.VolumeIcon.icns +.com.apple.timemachine.donotpresent + +# Directories potentially created on remote AFP share +.AppleDB +.AppleDesktop +Network Trash Folder +Temporary Items +.apdisk + +### Python template +# Byte-compiled / optimized / DLL files +__pycache__/ +*.py[cod] +*$py.class + +# C extensions +*.so + +# Distribution / packaging +.Python +build/ +develop-eggs/ +dist/ +downloads/ +eggs/ +.eggs/ +lib/ +lib64/ +parts/ +sdist/ +var/ +wheels/ +share/python-wheels/ +*.egg-info/ +.installed.cfg +*.egg +MANIFEST + +# PyInstaller +# Usually these files are written by a python script from a template +# before PyInstaller builds the exe, so as to inject date/other infos into it. +*.manifest +*.spec + +# Installer logs +pip-log.txt +pip-delete-this-directory.txt + +# Unit test / coverage reports +htmlcov/ +.tox/ +.nox/ +.coverage +.coverage.* +.cache +nosetests.xml +coverage.xml +*.cover +*.py,cover +.hypothesis/ +.pytest_cache/ +cover/ + +# Translations +*.mo +*.pot + +# Django stuff: +*.log +local_settings.py +db.sqlite3 +db.sqlite3-journal + +# Flask stuff: +instance/ +.webassets-cache + +# Scrapy stuff: +.scrapy + +# Sphinx documentation +docs/_build/ + +# PyBuilder +.pybuilder/ +target/ + +# Jupyter Notebook +.ipynb_checkpoints + +# IPython +profile_default/ +ipython_config.py + +# pyenv +# For a library or package, you might want to ignore these files since the code is +# intended to run in multiple environments; otherwise, check them in: +# .python-version + +# pipenv +# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control. +# However, in case of collaboration, if having platform-specific dependencies or dependencies +# having no cross-platform support, pipenv may install dependencies that don't work, or not +# install all needed dependencies. +#Pipfile.lock + +# PEP 582; used by e.g. github.com/David-OConnor/pyflow +__pypackages__/ + +# Celery stuff +celerybeat-schedule +celerybeat.pid + +# SageMath parsed files +*.sage.py + +# Environments +.env +.venv +env/ +venv/ +ENV/ +env.bak/ +venv.bak/ + +# Spyder project settings +.spyderproject +.spyproject + +# Rope project settings +.ropeproject + +# mkdocs documentation +/site + +# mypy +.mypy_cache/ +.dmypy.json +dmypy.json + +# Pyre type checker +.pyre/ + +# pytype static type analyzer +.pytype/ + +# Cython debug symbols +cython_debug/ + +# Installer logs +pip-log.txt + +imports/*.pyd +imports/*.pyc + bin/ tmp/ *.idea/ @@ -35,5 +210,4 @@ develop-eggs/ # Installer logs pip-log.txt -imports/*.pyd -imports/*.pyc +.gitattributes diff --git a/conf/db.ver b/conf/db.ver index caf52e3..f66f5b7 100644 --- a/conf/db.ver +++ b/conf/db.ver @@ -1 +1 @@ -1593511930000 +1596631782000 diff --git a/conf/maldb.db b/conf/maldb.db index c90d4dd..d8b6f3c 100644 Binary files a/conf/maldb.db and b/conf/maldb.db differ diff --git a/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.md5 b/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.md5 new file mode 100644 index 0000000..21871c3 --- /dev/null +++ b/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.md5 @@ -0,0 +1 @@ +MD5 (Linux.Mirai.B.zip) = 23282f4301170e8ee3b157dcfaae6317 diff --git a/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.pass b/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.pass new file mode 100644 index 0000000..58737a9 --- /dev/null +++ b/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.pass @@ -0,0 +1 @@ +infected \ No newline at end of file diff --git a/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.shasum b/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.shasum new file mode 100644 index 0000000..961bf28 --- /dev/null +++ b/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.shasum @@ -0,0 +1 @@ +b50681094c040883f3da8fe697bd3a9e35e62d1672f59d9f14e0db494f9d41c2 Linux.Mirai.B.zip diff --git a/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.zip b/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.zip new file mode 100644 index 0000000..96dfc56 Binary files /dev/null and b/malwares/Binaries/Linux.Mirai.B/Linux.Mirai.B.zip differ diff --git a/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.md5 b/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.md5 new file mode 100644 index 0000000..c69ec93 --- /dev/null +++ b/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.md5 @@ -0,0 +1 @@ +MD5 (Win32.RedDelta.zip) = 761d0c4b38af5d9fed3b1abd2b8ebed2 diff --git a/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.pass b/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.pass new file mode 100644 index 0000000..58737a9 --- /dev/null +++ b/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.pass @@ -0,0 +1 @@ +infected \ No newline at end of file diff --git a/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.shasum b/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.shasum new file mode 100644 index 0000000..bd01f76 --- /dev/null +++ b/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.shasum @@ -0,0 +1 @@ +c0d678478b68084c7750369ddcdfb1afd13aae114ece242cae06dc7a34a84ca9 Win32.RedDelta.zip diff --git a/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.zip b/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.zip new file mode 100644 index 0000000..f091520 Binary files /dev/null and b/malwares/Binaries/Win32.RedDelta/Win32.RedDelta.zip differ diff --git a/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.md5 b/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.md5 new file mode 100644 index 0000000..295b030 --- /dev/null +++ b/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.md5 @@ -0,0 +1 @@ +MD5 (NjRAT_0.7d.zip) = c35fdeebdede1d3a555e05209e61bb73 diff --git a/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.pass b/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.pass new file mode 100644 index 0000000..58737a9 --- /dev/null +++ b/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.pass @@ -0,0 +1 @@ +infected \ No newline at end of file diff --git a/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.shasum b/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.shasum new file mode 100644 index 0000000..dcfa079 --- /dev/null +++ b/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.shasum @@ -0,0 +1 @@ +d1b368392d8143ba7038493570f34c994018cc46855918e3022085de32f6b653 NjRAT_0.7d.zip diff --git a/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.zip b/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.zip new file mode 100644 index 0000000..e436f76 Binary files /dev/null and b/malwares/Source/Original/NjRAT_0.7d/NjRAT_0.7d.zip differ diff --git a/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.md5 b/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.md5 new file mode 100644 index 0000000..83747d2 --- /dev/null +++ b/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.md5 @@ -0,0 +1 @@ +MD5 (CobianRAT_v1.0.40.7.zip) = 5b5404e695ce3ff37bfcab2dd70a43a3 diff --git a/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.pass b/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.pass new file mode 100644 index 0000000..58737a9 --- /dev/null +++ b/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.pass @@ -0,0 +1 @@ +infected \ No newline at end of file diff --git a/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.shasum b/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.shasum new file mode 100644 index 0000000..ee0b080 --- /dev/null +++ b/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.shasum @@ -0,0 +1 @@ +1e2fe08d58beee863f95cf264f871647676fbd96c82d39e660d0bd777723b2f2 CobianRAT_v1.0.40.7.zip diff --git a/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.zip b/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.zip new file mode 100644 index 0000000..fe789fc Binary files /dev/null and b/malwares/Source/Reversed/CobianRAT_v1.0.40.7/CobianRAT_v1.0.40.7.zip differ diff --git a/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.md5 b/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.md5 new file mode 100644 index 0000000..e9bdb77 --- /dev/null +++ b/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.md5 @@ -0,0 +1 @@ +MD5 (RevengeRAT_v3_NYANxCAT.zip) = 92100f76eec604e09dccc3f260100376 diff --git a/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.pass b/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.pass new file mode 100644 index 0000000..58737a9 --- /dev/null +++ b/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.pass @@ -0,0 +1 @@ +infected \ No newline at end of file diff --git a/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.shasum b/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.shasum new file mode 100644 index 0000000..8c07ce6 --- /dev/null +++ b/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.shasum @@ -0,0 +1 @@ +2cf26e5fe9f31386d57170cc51ec46d6e4b73e4760826d65ca1a7afc8c82acc2 RevengeRAT_v3_NYANxCAT.zip diff --git a/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.zip b/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.zip new file mode 100644 index 0000000..ebe8a45 Binary files /dev/null and b/malwares/Source/Reversed/RevengeRAT_v3_NYANxCAT/RevengeRAT_v3_NYANxCAT.zip differ diff --git a/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.md5 b/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.md5 new file mode 100644 index 0000000..ebfa56b --- /dev/null +++ b/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.md5 @@ -0,0 +1 @@ +MD5 (SpyNote5.0.zip) = 68cdc4dbfb199b39a135031da05cfb27 diff --git a/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.pass b/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.pass new file mode 100644 index 0000000..58737a9 --- /dev/null +++ b/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.pass @@ -0,0 +1 @@ +infected \ No newline at end of file diff --git a/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.shasum b/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.shasum new file mode 100644 index 0000000..f8906a2 --- /dev/null +++ b/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.shasum @@ -0,0 +1 @@ +077b4fd180fb6b348d58d0a36a5ecd170e381b67b3d36cf41f1d2a64a59f2de1 SpyNote5.0.zip diff --git a/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.zip b/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.zip new file mode 100644 index 0000000..f4b3fbe Binary files /dev/null and b/malwares/Source/Reversed/SpyNote_5.0/SpyNote5.0.zip differ