MalwareBazaar – Malware Sample Exchange
bazaar.abuse.ch
bazaar.abuse.ch
As a side note, for some reason, there's way more malware on usenet than bittorrent, I've even found it on games on major NZB sites, possibly just due to the seed counts weeding out the malicious ones via simple popularity in the public bittorrent world.
I'm not sure your run of the mill malware is doing anything that can't be fixed by a format and reinstall, but yes, use an isolated VM.
VM detecting malware however is exceedingly common: plan to have to bypass basic VM detection, minimal knowledge of reverse engineering should make that pretty easy.
If you want/need to allow it access to the internet for dynamic analysis or botnet monitoring, I'd suggest looking into setting up a separate VM to route all the traffic over Tor or a commercial VPN provider and allowing it access only via that VM. This way if you manage to piss off any script kiddies you won't be the one who gets DDoS'd.
Nothing is perfect and if you're serious about this consider separate hardware, but if you're not quite that paranoid this setup is highly workable.
We're already at the point where one could theoretically infect the HHD firmware: https://spritesmods.com/?art=hddhack&page=1
I never heard of malware soldering hardware implants onto the device ^^
For firmware you need to dump it and then compare afterwards.
>I don’t think we’re at a point where a firmware compromised graphics card can’t reinfect the processor?
Nation state based firmware attacks exists since at least a decade. Some professional hacking teams are also already making use of those. You can find POCs, publications, talks, blogposts for probably everything which has flashable firmware. These attacks are very real. Only reasons you don't find that stuff in the wild is because no one is looking for it, your average antivirus won't detect it and it's used mostly for targeted attacks where you need advanced persistence/stealth and early compromise of the OS. Firmware security is a mess. USB, HDD, GPU in particular. Even for all the UEFI verified/secure/whatever boot where at least some more mitigations are in place, holes get found once in a while. Just a while ago had an attacker pwn through a standard qemu/kvm setup trying to flash the BIOS. Wasn't that successful with flashing though ... because muh mitigations. You either need to check or keep the firmware read only.
Needless to say, the script kiddies were not happy. Not happy at all. I think my poor old DSL line was dead for a week, got AT&T to give me a different address block and they said they were black holing "hundreds of gigabites" (which at the time was a lot) of spurious packets. Now I just use fail2ban and ignore them, doesn't help their other victims but it keeps me off their radar.
Running the server on AWS hosts might be an interesting alternative.
Anyways have fun, good luck and be safe. Most of all happy hacking :)
Ghidra is great but its got a long uphill battle before it dethrones IDA as the choice of professional malware analysts.
VS
Open, community oriented project with open API access and published archives from abuse.ch