/maltrieve

A tool to retrieve malware directly from the source for security researchers.

Primary LanguagePythonGNU General Public License v3.0GPL-3.0

 _______ _______        _______  ______ _____ _______ _    _ _______     
 |  |  | |_____| |         |    |_____/   |   |______  \  /  |______     
 |  |  | |     | |_____    |    |    \_ __|__ |______   \/   |______     
                                                                         

Maltrieve

Maltrieve originated as a fork of mwcrawler. It retrieves malware directly from the sources as listed at a number of sites, including:

These lists will be implemented if/when they return to activity.

Other improvements include:

  • Proxy support
  • Multithreading for improved performance
  • Logging of source URLs
  • Multiple user agent support
  • Better error handling
  • VxCage and Cuckoo Sandbox support

Dependencies

License

Released under GPL version 3. See the LICENSE file for full details.

Known bugs

We list all the bugs we know about (plus some things we know we need to add) at the Github issues page.

How you can help

Aside from pull requests, non-developers can open issues on Github. Things we'd really appreciate:

  • Bug reports, preferably with error logs
  • Suggestions of additional sources for malware lists
  • Descriptions of how you use it and ways we can improve it for you

If you'd prefer not to open an issue, you can contact me on Twitter or email.