23/04/2024
๐ ๐ฎ๐น๐๐ผ๐๐ฒ๐ฟ๐๐ถ๐ฒ๐ : ๐ฎ ๐ณ๐ถ๐ฟ๐๐ ๐ฟ๐ฒ๐๐ฝ๐ผ๐ป๐๐ฒ ๐๐ผ๐ผ๐น ๐๐๐ฒ๐ฑ ๐ณ๐ผ๐ฟ ๐๐ต๐ฟ๐ฒ๐ฎ๐ ๐ต๐๐ป๐๐ถ๐ป๐ด ๐ฎ๐ป๐ฑ ๐ผ๐ณ๐ณ๐ฒ๐ฟ๐ ๐ถ๐ป๐๐ฒ๐น ๐ถ๐ป๐ณ๐ผ๐ฟ๐บ๐ฎ๐๐ถ๐ผ๐ป ๐ณ๐ฟ๐ผ๐บ ๐ฉ๐ถ๐ฟ๐๐ ๐ง๐ผ๐๐ฎ๐น, ๐๐๐ฏ๐ฟ๐ถ๐ฑ ๐๐ป๐ฎ๐น๐๐๐ถ๐, ๐จ๐ฅ๐๐๐ฎ๐๐, ๐ฃ๐ผ๐น๐๐๐๐ฎ๐ฟ๐บ, ๐ ๐ฎ๐น๐๐ต๐ฎ๐ฟ๐ฒ, ๐๐น๐ถ๐ฒ๐ป ๐ฉ๐ฎ๐๐น๐, ๐ ๐ฎ๐น๐ฝ๐ฒ๐ฑ๐ถ๐ฎ, ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ ๐๐ฎ๐๐ฎ๐ฎ๐ฟ, ๐ง๐ต๐ฟ๐ฒ๐ฎ๐๐๐ผ๐
, ๐ง๐ฟ๐ถ๐ฎ๐ด๐ฒ, ๐๐ป๐ค๐๐ฒ๐๐ ๐ฎ๐ป๐ฑ ๐ถ๐ ๐ถ๐ ๐ฎ๐ฏ๐น๐ฒ ๐๐ผ ๐๐ฐ๐ฎ๐ป ๐๐ป๐ฑ๐ฟ๐ผ๐ถ๐ฑ ๐ฑ๐ฒ๐๐ถ๐ฐ๐ฒ๐ ๐ฎ๐ด๐ฎ๐ถ๐ป๐๐ ๐ฉ๐ง.
Malwoverview performs an initial and quick triage of malware samples, URLs, IP addresses, domains, malware families, IOCs and hashes. Additionally, Malwoverview is able to get dynamic and static behavior reports, submit and download samples from several endpoints. In few words, it works as a client to main existing sandboxes.
1. Determine similar executable malware samples (PE/PE+) according to the import table (imphash) and group them by different colors (pay attention to the second column from output). Thus, colors matter!
2. Show hash information on Virus Total, Hybrid Analysis, Malshare, Polyswarm, URLhaus, Alien Vault, Malpedia and ThreatCrowd engines.
3. Determining whether the malware samples contain overlay and, if you want, extract it.
4. Check suspect files on Virus Total, Hybrid Analysis and Polyswarm.
5. Check URLs on Virus Total, Malshare, Polyswarm, URLhaus engines and Alien Vault.
6. Download malware samples from Hybrid Analysis, Malshare, URLHaus, Polyswarm and Malpedia engines.
7. Submit malware samples to VirusTotal, Hybrid Analysis and Polyswarm.
8. List last suspected URLs from URLHaus.
9. List last payloads from URLHaus.
10. Search for specific payloads on the Malshare.
https://github.com/alexandreborges/malwoverview