![](/assets/headers/header-logo.png)

![](https://img.shields.io/badge/Tools%20%26%20Resources%20Available-33-757575?style=for-the-badge)

!!!danger Danger
Infosec House is not held responsible for any damages when proceeding to the below resources. Live malware/ransomeware below proceed with caution. Remember, engaging in illegal activities is frowned upon, and compliance with local state laws is your sole responsibility.
!!!

### Distribution Centers

* [Any.Run](https://app.any.run/submissions/) - Interactive online malware analysis service for dynamic and static research of most types of threats using any environments. 
* [Contagio Malware Dump](https://contagiodump.blogspot.com/) - Password Required. A collection of the latest malware samples, threats, observations, and analyses. 
* [Cape Sandbox](https://capesandbox.com/) - A malware sandbox derived from Cuckoo and is designed to automate the process of malware analysis with the goal of extracting payloads and configuration from malware. 
* [Hatching Triage](https://tria.ge/) - A malware sandboxing solution. It leverages a unique architecture, developed with scaling in mind from the start! 
* [Hybrid Analysis](https://www.hybrid-analysis.com/) - A free malware analysis service for the community. Using this service you can submit files for in-depth static and dynamic analysis. 
* [InQuest](https://github.com/InQuest/malware-samples) - A free malware analysis service for the community. Using this service you can submit files for in-depth static and dynamic analysis. ![last-commit](https://img.shields.io/github/last-commit/InQuest/malware-samples?style=flat)
* [Malshare](https://www.malshare.com/) - A free Malware repository providing researchers access to samples, malicious feeds, and Yara results. 
* [Malware Bazaar](https://bazaar.abuse.ch/browse/) - Project operated by abuse.ch. A project to collect and share malware samples. 
* [Malware Samples](https://github.com/MalwareSamples/Malware-Feed/) - An ongoing and updated archive of files collected which are associated with specific public malicious threat reports ![last-commit](https://img.shields.io/github/last-commit/MalwareSamples/Malware-Feed?style=flat)
* [Malware-DB (theZoo)](https://github.com/ytisf/theZoo) - theZoo is a project created to make the possibility of malware analysis open and available to the public. ![last-commit](https://img.shields.io/github/last-commit/ytisf/theZoo?style=flat)
* [Objective-See](https://objective-see.com/malware.html) - Mac malware samples collected by the Objective-See team 
* [PhishingKitTracker](https://github.com/marcoramilli/PhishingKitTracker) - An extensible and freshly updated collection of phishingkits for forensics and future analysis topped with simple stats ![last-commit](https://img.shields.io/github/last-commit/marcoramilli/PhishingKitTracker?style=flat)
* [Polyswarm](https://polyswarm.network/) - Threat Intelligence Marketplace 
* [SoReL-20M](https://github.com/sophos-ai/SOREL-20M) - Sophos-ReversingLabs 20 Million dataset. HUGE dataset. ![last-commit](https://img.shields.io/github/last-commit/sophos-ai/SOREL-20M?style=flat)
* [URLhaus](https://urlhaus.abuse.ch/browse/) - Project operated by abuse.ch. A project to collect and share malware samples. 
* [VirusShare](https://virusshare.com/) - Because Sharing is Caring 
* [VirusSign](https://virussign.com/) - A huge collection of high quality malware samples 
* [Virus Samples](https://www.virussamples.com/) - Over 150,000+ malicious files, viruses, malware, trojans, executables, scripts, and other forms of malware payloads across a variety of file types and architectures 
* [VX-Underground](https://github.com/vxunderground/MalwareSourceCode) - Over 150,000+ malicious files, viruses, malware, trojans, executables, scripts, and other forms of malware payloads across a variety of file types and architectures. ![last-commit](https://img.shields.io/github/last-commit/vxunderground/MalwareSourceCode?style=flat)
* [Yori](https://yomi.yoroi.company/upload) - Free sandbox-based file analysis service. 

### Emulation

* [Al-Khaser](https://github.com/LordNoteworthy/al-khaser) - Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection. ![last-commit](https://img.shields.io/github/last-commit/LordNoteworthy/al-khaser?style=flat)

### Ransomware Decryption

* [NoMoreRansom](https://www.nomoreransom.org/) - Ransomware decryption tool.

### Ransomware/Malware/Worms/etc.

* [Coldfire](https://github.com/redcode-labs/Coldfire) - Golang malware development library. ![last-commit](https://img.shields.io/github/last-commit/redcode-labs/Coldfire?style=flat)
* [GonnaCry](https://github.com/tarcisio-marinho/GonnaCry) - A linux ransomware that encrypts all the user files with a strong encryption scheme. ![last-commit](https://img.shields.io/github/last-commit/tarcisio-marinho/GonnaCry?style=flat)
* [Neurax](https://github.com/redcode-labs/Neurax) - A framework for constructing self-spreading binaries. ![last-commit](https://img.shields.io/github/last-commit/redcode-labs/Neurax?style=flat)

### Scanners

* [FileScan](https://www.filescan.io/) - Next-Gen Sandbox and free malware analysis service. Operating at 10x speed compared to traditional sandboxes with 90% less resource usage, its unique adaptive threat analysis technology also enables zero-day malware detection and more Indicator of Compromise (IOCs) extraction. 
* [Hybrid Analysis](https://www.hybrid-analysis.com/) - A free malware analysis service for the community that detects and analyzes unknown threats using a unique Hybrid Analysis technology. 
* [ID Ransomware](https://id-ransomware.malwarehunterteam.com/index.php) - Upload a ransom note and/or sample encrypted file to identify the ransomware that has encrypted your data. 
* [Jotti](https://virusscan.jotti.org/) - Free service that lets you scan suspicious files with several anti-virus programs. 
* [Kaspersky Threat Portal](https://opentip.kaspersky.com/) - Сheck any suspicious threat indicator, whether it is a file, file hash, IP address or web address. 
* [Malcore](https://malcore.io) - An advanced sandbox solution that is designed with speed and scalability in mind. Most leading sandbox solutions can take multiple minutes to perform analysis on a single file, Malcore solves this problem by taking seconds where it takes minutes. 
* [Opswat](https://metadefender.opswat.com/) - Simply submit suspicious files to MetaDefender Cloud for analysis. 
* [VirusTotal](https://www.virustotal.com/gui/) - Analyze suspicious files and URLs to detect types of malware, automatically share them with the security community. 
