# jstrosch/malware-samples

Malware samples, analysis exercises and other interesting resources.

Repository: https://github.com/jstrosch/malware-samples
Canonical: https://ross.abutalabs.com/products/jstrosch-malware-samples
Homepage: https://thecyberyeti.com
Language: HTML
License Family: other
Topics: malware-samples, trickbot, pcaps, lokibot, emotet, maldoc-templates, azorult, malware, training
Last push: 2024-01-13T17:39:44+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2445, "days_push": 963, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1671, forks 240 (observed 2026-08-28T04:05:20.104132+00:00)

## What it is
A curated collection of password-protected malware samples, malicious documents, and training PCAPs for malware analysis practice. It also includes guided malware analysis exercises with detailed walkthroughs and links to video tutorials.

## Use cases
- download malware samples for reverse engineering practice
- find PCAPs of malware network traffic for rule writing
- learn malware analysis with guided exercises
- get maldoc templates for macro analysis training
- study specific families like TrickBot, Emotet, or Lokibot
- practice deobfuscating malicious JavaScript and shellcode

## When to choose
- you need real-world malware specimens in a safe lab environment
- you want structured exercises with solutions for learning malware analysis
- you need network captures to practice writing IDS/Suricata rules

## When to avoid
- you need production security tooling rather than training artifacts
- you cannot safely handle live malware in an isolated environment
- you need a license-cleared dataset for commercial redistribution

## Facets
- artifact type: dataset
- maturity: active
- function: security, reverse-engineering, developer-tools
- domain: security, penetration-testing, tutorials, developer-tools
- platform: cross-platform
- tags: malware-samples, malware-analysis, reverse-engineering, pcap, training, maldoc, password-protected-zips

## Member repositories
- jstrosch/malware-samples (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:20.104132+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:42:41.281876+00:00, confidence not recorded.
  - readme: https://github.com/jstrosch/malware-samples (fetched 2026-08-28T04:05:20.104132+00:00, sha a84b50ad032d)
  - homepage: https://thecyberyeti.com (fetched 2026-08-29T11:15:47.482527+00:00, sha daf2200bfd39)
- Data as of 2026-08-30T08:39:29.467469+00:00.
