A collection of malware samples and relevant dissection information, most probably referenced from http://blog.inquest.net or https://twitter.com/inquest. Be sure to also check out the Deep File Inspection (DFI) portion of https://labs.inquest.net for an interactive searchable interface to a large corpus (>500K) of downloadable malware lures.
- CVE-2018-4878-Adobe-Flash-DRM-UAF-0day
- 14c58e38... Carrier: Microsoft Excel 2007+ XLSX, JSON VT Report
- 3b1395f6... Carrier: Composite Document File V2 Document DOC, JSON VT Report
- 88d7aa16... Stage-1: Macromedia Flash data, version 32 SWF, JSON VT Report, Decompiled ActionScript
- 1a326925... Stage-2: (0day) Macromedia Flash data (compressed), version 32 SWF, JSON VT Report, Decompiled ActionScript
- e1546323... Payload: (ROKRAT) PE32 executable (GUI) Intel 80386, for MS Windows PE, JSON VT Report
- 2018-04-GandCrab-Swarm
- Document Carrier: DOC
- Document Dropper Macro: VBA
- Additional Extracted Macros: VBAs
- Obfuscated JavaScript payloads: JS
- 2018-05-Agent-Tesla-Open-Directory
- Agent Tesla Payload 1:
EXE
- Agent Tesla Payload 2: EXE
- Agent Tesla Payload 3: EXE
- Web Panel: ZIP
- 2018-05-22 Interesting Macro Obfuscation
- 2018-08 Hidden Bee Elements
- 2019-01 Malicious Excel XLM Macros
- 2019-03 Sophisticated PowerShell Script (Dropping URLZone)
- 2019-07 Base64 Encoded Powershell Pivots
- 2020-05 Zloader 4.0 Macrosheet Evolution
- 2020-07 Tale of a Polished Carrier
- 2023-06 Mystic Stealer: The New Kid on the Block
- 2024-01 Shortcut To Malice: URL Files
Some additional GitHub repositories to explore for those curious to gather more public domain samples.