下载恶意pcap包的网站

说几个我经常用的,免费的:
1.  Malware  Traffic  Analysis:  http://www.malware-traffic-analysis.net/2018/index.html    这个网站每天更新,主要是欧美地区的新鲜流行木马样本,基本上当天更新的马都很新~
2.Virus  Bay:  https://beta.virusbay.io/    这个算是社区贡献吧

收费的:
1.Virustotal  Intelligence:https://www.virustotal.com/intelligence  这个是VT提供的,你所在的公司要付钱给VT,这样你可以去根据HASH和自定义YARA去找样本。
2.Abusix:恶意垃圾邮件提供商,每天提供大量的新鲜的垃圾邮件,80%内容是恶意的。
3.Support  Intelligence:收集各大反病毒厂商收集的样本,然后转手卖给各大IOC提取商~
4.Lexsi:同Support  Intelligence

 

 

你好,比如说,我想分析利用MS17_010漏洞的病毒,又或者我想分析某款病毒分变种,有没有什么网站能够跟你条件来查样本呢?

网站能够根据条件来查样本,一般你需要去各大在线沙盘的网站,例如  Hybird-Analysis,根据Tag来找,找到了根据HASH来找样本

曾经也遇到楼主的问题,收集了一些国外的样本下载网站:
1)https://www.hybrid-analysis.com/    这个网站可以下载,但是需要注册账号,个人注册需要提交三个以上博客或者原创技术文章链接,使用企业邮箱申请的通过的比较快一些

2)https://app.any.run/    这个网站是一个免费沙箱,可以浏览其他人跑的样本结果,也可以下载样本,不需要注册账号就能下载,注册也是免费的!

3)http://vxvault.net/ViriList.php  这个!!没下载过

4)http://malc0de.com/database/  每天更新最新样本

最后老外推荐的样本资源:https://zeltser.com/malware-sample-sources/

 

我用  VirusTotal  Intelligence,很好用,可以搜索类似样本,按杀软报毒名搜索,按漏洞标签搜索。几年前发封邮件过去申请的,免费拿到访问权,现在不知道还行不行。另外就是  Kernelmode.info  里面的  Malware  版块可以求样本,不过需要你先对论坛做出点贡献。


在微步的云沙箱上可以下载一些样本,并且有API接口可用,网址为https://s.threatbook.cn/
 

 

https://virusshare.com/

 

一个练习恶意软件流量分析网站

 

 

https://www.malware-traffic-analysis.net/

https://www.malware-traffic-analysis.net/2018/07/15/index.html

其他报文下载站

wireshark
https://wiki.wireshark.org/SampleCaptures/

security-onion
https://github.com/security-onion-solutions/security-onion/wiki/Pcaps

asecuritysite
https://asecuritysite.com/forensics/pcap?infile=imap.pcap

NCTU (台湾) 國立交通大學
http://speed.cis.nctu.edu.tw/pcaplib/

packetlife
http://packetlife.net/captures/

 

 

https://www.malware-traffic-analysis.net/training-exercises.html

TRAFFIC ANALYSIS EXERCISES

 

 

https://github.com/tatsui-geek/malware-traffic-analysis.net

 

恶意加密的:

2017 2017-01-05-Brazil-malspam-traffic.pcap
-rw-r--r--. 1 root root 163756 Jan 10 2017 2017-01-09-DHL-malspam-traffic.pcap
-rw-r--r--. 1 root root 6455066 Feb 18 2017 2017-02-17-Brazilian-malspam-traffic.pcap
-rw-r--r--. 1 root root 1080088 Feb 21 2017 2017-02-20-malspam-traffic.pcap
-rw-r--r--. 1 root root 914342 Feb 22 2017 2017-02-21-ZeusPandaBanker-malspam-traffic.pcap
-rw-r--r--. 1 root root 2987259 Mar 11 2017 2017-03-10-income-report-malspam-traffic.pcap
-rw-r--r--. 1 root root 3703929 Mar 15 2017 2017-03-15-unidentified-campaign-Rig-EK-sends-DELoader.pcap
-rw-r--r--. 1 root root 14943807 Mar 30 2017 2017-03-29-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 188871 Mar 31 2017 2017-03-30-booking-malspam-Dridex-traffic.pcap
-rw-r--r--. 1 root root 1022706 Mar 31 2017 2017-03-30-Dridex-confirmation-letter-Dridex-traffic.pcap
-rw-r--r--. 1 root root 10643014 Apr 4 2017 2017-04-03-DHL-malspam-traffic.pcap
-rw-r--r--. 1 root root 3138096 Apr 5 2017 2017-04-04-Cerber-Kovter-malspam-traffic.pcap
-rw-r--r--. 1 root root 15048404 Apr 5 2017 2017-04-04-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 1277728 Apr 7 2017 2017-04-05-Cerber-Kovter-malspam-traffic.pcap
-rw-r--r--. 1 root root 14582657 Apr 6 2017 2017-04-05-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 1555889 Apr 20 2017 2017-04-19-Dridex-malspam-traffic-example.pcap
-rw-r--r--. 1 root root 13312274 Apr 25 2017 2017-04-24-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 330328 May 5 2017 2017-04-25-Smoke-Loader-post-infection-traffic.pcap
-rw-r--r--. 1 root root 13425601 Apr 27 2017 2017-04-26-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 599140 Apr 28 2017 2017-04-28-UPS-malspam-traffic.pcap
-rw-r--r--. 1 root root 24779 May 2 2017 2017-05-01-Mordor-from-seahomevb.top.pcap
-rw-r--r--. 1 root root 31466 May 2 2017 2017-05-02-Mordor-from-seahomevb.top.pcap
-rw-r--r--. 1 root root 11646696 May 5 2017 2017-05-04-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 817920 May 12 2017 2017-05-11-Fedex-malspam-sends-Kovter.pcap
-rw-r--r--. 1 root root 1338055 May 13 2017 2017-05-12-FedEx-malspam-traffic.pcap
-rw-r--r--. 1 root root 13624335 May 26 2017 2017-05-25-Hancitor-malspam-1st-run.pcap
-rw-r--r--. 1 root root 181914 May 26 2017 2017-05-25-Jaff-ransomware-malspam-traffic.pcap
-rw-r--r--. 1 root root 1495969 May 26 2017 2017-05-26-DHL-malspam-traffic.pcap
-rw-r--r--. 1 root root 13200366 May 31 2017 2017-05-30-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 680294 May 31 2017 2017-05-30-Rig-EK-sends-Kovter-1st-run.pcap
-rw-r--r--. 1 root root 794493 May 31 2017 2017-05-30-Rig-EK-sends-Kovter-2nd-run.pcap
-rw-r--r--. 1 root root 14566953 Jun 1 2017 2017-05-31-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 3978012 Jun 1 2017 2017-06-01-ZeusPandaBanker-malspam-traffic.pcap
-rw-r--r--. 1 root root 464734 Jun 2 2017 2017-06-02-Dridex-malspam-traffic.pcap
-rw-r--r--. 1 root root 80182 Jun 6 2017 2017-06-05-Dridex-malspam-traffic.pcap
-rw-r--r--. 1 root root 146597 Jun 8 2017 2017-06-07-Loki-Bot-malspam-traffic.pcap
-rw-r--r--. 1 root root 8831992 Jun 9 2017 2017-06-08-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 712789 Jun 12 2017 2017-06-12-payment-malspam-traffic.pcap
-rw-r--r--. 1 root root 1881782 Jun 13 2017 2017-06-12-Trickbot-malspam-traffic.pcap
-rw-r--r--. 1 root root 11719772 Jun 15 2017 2017-06-14-Trickbot-malspam-traffic.pcap
-rw-r--r--. 1 root root 9577473 Jun 16 2017 2017-06-15-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 3819524 Jun 17 2017 2017-06-16-1st-run-HookAds-Rig-EK-sends-Dreambot.pcap
-rw-r--r--. 1 root root 3963196 Jun 17 2017 2017-06-16-2nd-run-HookAds-Rig-EK-sends-Dreambot.pcap
-rw-r--r--. 1 root root 8271730 Jun 30 2017 2017-06-28-UPS-themed-Kovter-malspam-traffic.pcap
-rw-r--r--. 1 root root 9399867 Jun 30 2017 2017-06-29-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 4082112 Jun 30 2017 2017-06-29-UPS-themed-Kovter-malspam-traffic.pcap
-rw-r--r--. 1 root root 7316883 Jul 4 2017 2017-07-03-UPS-themed-Kovter-malspam-traffic.pcap
-rw-r--r--. 1 root root 315863 Jul 6 2017 2017-07-05-Japanese-malspam-traffic.pcap
-rw-r--r--. 1 root root 3575975 Jul 8 2017 2017-07-07-Brazil-Detran-malspam-traffic.pcap
-rw-r--r--. 1 root root 8338159 Jul 11 2017 2017-07-10-Kovter-Nemucod-malspam-traffic.pcap
-rw-r--r--. 1 root root 7857287 Jul 13 2017 2017-07-12-Brazil-boleto-malspam-traffic.pcap
-rw-r--r--. 1 root root 6668017 Jul 18 2017 2017-07-17-2nd-run-HookAds-Rig-EK-sends-Dreambot-with-post-infection-traffic.pcap
-rw-r--r--. 1 root root 1794866 Jul 18 2017 2017-07-17-5th-run-Seamless-Rig-EK-sends-Ramnit-with-post-infection-traffic.pcap
-rw-r--r--. 1 root root 8654555 Jul 21 2017 2017-07-20-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 3391724 Jul 22 2017 2017-07-21-Boleto-malspam-infection-from-PDF-attachment.pcap
-rw-r--r--. 1 root root 8660170 Aug 2 2017 2017-08-01-2nd-run-HookAds-Rig-EK-sends-Drembot-with-post-infection-traffic.pcap
-rw-r--r--. 1 root root 9882970 Aug 4 2017 2017-08-03-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 7386344 Aug 9 2017 2017-08-08-contract-malspam-traffic.pcap
-rw-r--r--. 1 root root 8099283 Aug 11 2017 2017-08-10-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 1380325 Aug 12 2017 2017-08-11-Trickbot-infection-from-carriereiter.com.pcap
-rw-r--r--. 1 root root 561377 Aug 13 2017 2017-08-12-Trickbot-infection-from-carriereiserphotography.com.pcap
-rw-r--r--. 1 root root 428091 Aug 13 2017 2017-08-12-Trickbot-infection-from-carriereiter.com.exe.pcap
-rw-r--r--. 1 root root 1212113 Aug 13 2017 2017-08-12-Trickbot-infection-from-usdata.estoreseller.com.pcap
-rw-r--r--. 1 root root 9174063 Aug 22 2017 2017-08-21-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 1246136 Aug 22 2017 2017-08-21-Trickbot-malspam-traffic.pcap
-rw-r--r--. 1 root root 3645873 Aug 29 2017 2017-08-28-Boleto-malspam-traffic.pcap
-rw-r--r--. 1 root root 9608961 Sep 19 2017 2017-09-18-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 865555 Sep 23 2017 2017-09-22-Boleto-malspam-traffic.pcap
-rw-r--r--. 1 root root 2200771 Oct 4 2017 2017-10-03-Brazil-malspam-traffic.pcap
-rw-r--r--. 1 root root 4339019 Oct 7 2017 2017-10-06-Boleto-malspam-traffic.pcap
-rw-r--r--. 1 root root 9546728 Oct 17 2017 2017-10-16-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 3870836 Oct 18 2017 2017-10-17-post-infection-traffic-from-Terror-EK-payload.pcap
-rw-r--r--. 1 root root 12729380 Oct 24 2017 2017-10-23-Brazil-malspam-traffic-example.pcap
-rw-r--r--. 1 root root 81615 Oct 24 2017 2017-10-24-banking-phish-traffic.pcap
-rw-r--r--. 1 root root 125764 Oct 25 2017 2017-10-24-coinminer-javascript-after-pawsprings.ca.pcap
-rw-r--r--. 1 root root 3154362 Oct 27 2017 2017-10-26-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 6960713 Nov 3 2017 2017-11-02-Neutrino-traffic.pcap
-rw-r--r--. 1 root root 1239529 Nov 3 2017 2017-11-02-Smoke-Loader-traffic.pcap
-rw-r--r--. 1 root root 10065400 Nov 15 2017 2017-11-15-Brazil-malspam-pushes-Banload.pcap
-rw-r--r--. 1 root root 1987090 Nov 22 2017 2017-11-21-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 1257005 Nov 22 2017 2017-11-21-Zeus-Panda-Banker-malspam-traffic.pcap
-rw-r--r--. 1 root root 2169538 Nov 28 2017 2017-11-27-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 660862 Nov 29 2017 2017-11-28-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 3864251 Nov 29 2017 2017-11-28-payment-slip-malspam-traffic.pcap
-rw-r--r--. 1 root root 226490 Dec 1 2017 2017-11-30-GlobeImposter-ransomware-from-bit-chasers-com-full-traffic.pcap
-rw-r--r--. 1 root root 540425 Dec 5 2017 2017-12-04-Dridex-malspam-traffic.pcap
-rw-r--r--. 1 root root 1365419 Dec 9 2017 2017-12-08-Necurs-Botnet-malspam-pushes-Trickbot.pcap
-rw-r--r--. 1 root root 2364151 Dec 12 2017 2017-12-11-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 2034523 Dec 12 2017 2017-12-12-Necurs-Botnet-malspam-pushes-Trickbot.pcap
-rw-r--r--. 1 root root 961426 Dec 14 2017 2017-12-13-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 171402 Dec 14 2017 2017-12-13-Necurs-Botnet-malspam-pushes-GlobeImposter.pcap
-rw-r--r--. 1 root root 664104 Dec 22 2017 2017-12-21-Hancitor-malspam-traffic.pcap
-rw-r--r--. 1 root root 264114 Dec 27 2017 2017-12-26-Necurs-Botnet-malspam-traffic.pcap
-rw-r--r--. 1 root root 2505252 Dec 28 2017 2017-12-27-Emotet-malspam-traffic.pcap
-rw-r--r--. 1 root root 150599 Dec 28 2017 2017-12-27-Necurs-Botnet-malspam-traffic.pcap
-rw-r--r--. 1 root root 321812 Dec 29 2017 2017-12-28-Necurs-Botnet-malspam-traffic.pcap
-rw-r--r--. 1 root root 230785 Dec 30 2017 2017-12-29-Necurs-Botnet-malspam-traffic.pcap
-rw-r--r--. 1 root root 258533 Jan 3 2018 2018-01-03-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 3183730 Jan 9 2018 2018-01-09-Emotet-and-Zeus-Panda-Banker-traffic.pcap
-rw-r--r--. 1 root root 534031 Jan 9 2018 2018-01-09-Java-based-RAT-malspam-traffic.pcap
-rw-r--r--. 1 root root 2783529 Jan 9 2018 2018-01-09-Seamless-campaign-Rig-EK-sends-Ramnit.pcap
-rw-r--r--. 1 root root 2681664 Jan 10 2018 2018-01-10-Hancitor-malspam-traffic-with-Zeus-Panda-Banker.pcap
-rw-r--r--. 1 root root 6040488 Jan 22 2018 2018-01-22-malspam-pushing-smoke-loader-and-other-malware.pcap
-rw-r--r--. 1 root root 9461350 Jan 24 2018 2018-01-24-Hancitor-infection-traffic.pcap
-rw-r--r--. 1 root root 10122972 Feb 1 2018 2018-02-01-Trickbot-infection-traffic.pcap
-rw-r--r--. 1 root root 280586 Feb 5 2018 2018-02-05-Dridex-malspam-traffic.pcap
-rw-r--r--. 1 root root 2551886 Feb 6 2018 2018-02-06-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 803943 Feb 13 2018 2018-02-13-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 3383487 Feb 14 2018 2018-02-14-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2173787 Feb 20 2018 2018-02-20-Hancitor-JS-file-download-and-infection-traffic.pcap
-rw-r--r--. 1 root root 1206208 Feb 21 2018 2018-02-21-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 684138 Feb 26 2018 2018-02-26-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 618534 Feb 27 2018 2018-02-27-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 327381 Feb 28 2018 2018-02-28-Hancitor-infection-traffic-1st-run.pcap
-rw-r--r--. 1 root root 309891 Feb 28 2018 2018-02-28-Hancitor-infection-traffic-2nd-run.pcap
-rw-r--r--. 1 root root 421314 Feb 28 2018 2018-02-28-Hancitor-infection-traffic-3rd-run.pcap
-rw-r--r--. 1 root root 2928554 Mar 5 2018 2018-03-05-Boleto-Mestre-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 11999900 Mar 5 2018 2018-03-05-CoinsLTD-campaign-Rig-EK-and-post-infection-traffic.pcap
-rw-r--r--. 1 root root 2561762 Mar 6 2018 2018-03-06-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 15218 Mar 7 2018 2018-03-07-Zeus-Panda-Banker-infection-traffic.pcap
-rw-r--r--. 1 root root 648394 Mar 14 2018 2018-03-14-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 12252097 Mar 30 2018 2018-03-30-Ursnif-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2313650 Apr 4 2018 2018-04-04-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 7684387 Apr 5 2018 2018-04-05-Trickbot-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2645333 Apr 11 2018 2018-04-11-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 542331 Apr 13 2018 2018-04-13-Zero-Gand-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 616294 Apr 14 2018 2018-04-14-Rig-EK-sends-GandCrab-ransomware.pcap
-rw-r--r--. 1 root root 8551757 Apr 17 2018 2018-04-17-Trickbot-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2696677 Apr 18 2018 2018-04-18-Fattura-malspam-pushes-Zeus-Panda-Banker-infection-traffic.pcap
-rw-r--r--. 1 root root 5194979 Apr 19 2018 2018-04-19-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 17329384 Apr 23 2018 2018-04-23-DHL-themed-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 3056973 Apr 23 2018 2018-04-23-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 784611 May 1 2018 2018-05-01-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 7121402 May 1 2018 2018-05-01-Trickbot-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2561158 May 2 2018 2018-05-02-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2546485 May 3 2018 2018-05-03-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2447254 May 3 2018 2018-05-03-Trickbot-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 675733 May 8 2018 2018-05-08-Gozi-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 12621466 May 8 2018 2018-05-08-Trickbot-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 23238047 May 9 2018 2018-05-09-Sigma-ransomware-infection-traffic-from-malspam-attachment.pcap
-rw-r--r--. 1 root root 3088055 May 14 2018 2018-05-14-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 5060546 May 15 2018 2018-05-15-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 5709307 May 15 2018 2018-05-15-Trickbot-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2663401 May 16 2018 2018-05-16-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 14899917 May 16 2018 2018-05-16-Trickbot-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2597163 May 24 2018 2018-05-24-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 5956510 May 25 2018 2018-05-25-Trickbot-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 708946 Jun 3 2018 2018-05-31-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 744846 Jun 10 2018 2018-06-11-Lokibot-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 4823683 Jun 12 2018 2018-06-12-Emotet-malspam-infection-traffic-with-Zeus-Panda-Banker.pcap
-rw-r--r--. 1 root root 16313354 Jun 14 2018 2018-06-14-Emotet-infection-traffic-with-Trickbot.pcap
-rw-r--r--. 1 root root 20399620 Jun 26 2018 2018-06-26-Trickbot-infection-traffic.pcap
-rw-r--r--. 1 root root 662123 Jun 27 2018 2018-06-27-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2789779 Jun 30 2018 2018-06-28-Hancitor-malspam-infection-traffic.pcap
-rw-r--r--. 1 root root 2198687 Oct 12 2018 gozi1.pcap
-rw-r--r--. 1 root root 344119 Oct 12 2018 gozi2.pcap

posted @ 2019-08-19 20:50  bonelee  阅读(3736)  评论(1编辑  收藏  举报