MalwareNet Project

14
SecurityXploded Team MalwareNet.co m Crowd Sourced Malware Analysis and Intelligence Portal. © SecurityXploded Research Group

description

Presented by SecurityXploded team in our quarterly Cyber security meet. visit: http://www.securitytrainings.net for more information.

Transcript of MalwareNet Project

Page 1: MalwareNet Project

SecurityXploded Team

MalwareNet.com

Crowd Sourced Malware Analysis and Intelligence Portal.

© SecurityXploded Research Group

Page 2: MalwareNet Project

Mission!

1. Central Repository for Malware

analysis.

2. API integration - accessible to

everyone/product/tool.

3. Community collaboration

© SecurityXploded Research Group

Page 3: MalwareNet Project

MalwareNet Components

❖ Search

❖ Submit Analysis

❖ Request Analysis

❖ Trust Key

❖ API

© SecurityXploded Research Group

Page 4: MalwareNet Project

MalwareNet Search

❖ Search the sample analysis reports.

❖ Download reports

❖ Search fields (few may not be available yet)

❖ SHA256

❖ Domain/IP

❖ Malware family/campaign name

❖ Entire analysis report*

© SecurityXploded Research Group

Page 5: MalwareNet Project

Submit Analysis

❖ Anonymous submission

❖ currently we support only text submission.

❖ Use reference section to add more resources (eg:

your blog etc.)

❖ Pcap/Sample upload is optional.

© SecurityXploded Research Group

Page 6: MalwareNet Project

Submit Analysis (Web)

Page 7: MalwareNet Project

Request Analysis

❖ Submit sample - request for analysis.

❖ Anonymous submission

❖ Anyone can download the samples

❖ Anyone can submit the analysis

❖ Our dedicated analysts will work on this for free. :)

❖ Send private/confidential analysis requests to [email protected] (this is not free)

© SecurityXploded Research Group

Page 8: MalwareNet Project

Request Analysis (Web)Thanks to Nagareshwar for cool logo and webUi!

Page 9: MalwareNet Project

Trust Key❖ MalwareNet is based on the concept of virtual trusted

network.

❖ Trust key is optional in web submission but mandatory in API submission

❖ We recommend use the trust key for all submissions (submit analysis or request analysis) because the submissions using trust key will be given priority.

❖ Request trust key: send an email to [email protected] with "Trust key" subject (without quotes).

© SecurityXploded Research Group

Page 10: MalwareNet Project

API❖ API is free and accessible to everyone.

❖ currently we support:

❖ submit analysis

❖ Request analysis

❖ we are working on search

❖ Download the client and feel free to integrate it in your analysis tools.

❖ Trust key is mandatory for API submission.

© SecurityXploded Research Group

Page 11: MalwareNet Project

Submit Analysis (API)• Json for-

mat

Page 12: MalwareNet Project

Request Analysis (API)• Json format

• Request Trust Key: send an email to [email protected] with

• subject – Trust key

Page 13: MalwareNet Project

MawareNet.com

❖ Use the API, integrate it with your analysis tools

❖ We will also release some tools to automate the analysis process.

❖ For any questions/queries please email to [email protected]

© SecurityXploded Research Group

Page 14: MalwareNet Project

Thank You!

© SecurityXploded Research Group