This project is built to organize a collection of malware in order to gain knowledge from commonalities between certain pieces of malware. With a large database of malware and information about the malware it will be easier to answer questions like: “How many samples use this x DLL?”, “How many ransomware sampes use this x DLL?” “What is the full list of DLLs used by all known backdoors?”
The front end utilizes Django & Django ORM operations on the mySQL database The data stored in the mySQL database is pulled from multiple major antivirus databases as well as local research. The log malware scan log files are processed with python.
-
The mySQL database provides storage for the malware information. make tables
-
The Django interface provides a front end for viewing and sorting the malware samples.database views interface
-
The VMAutomation portion providing malware information collection.python scripts
In Progress:
Django interface for Cuckoo uploads