GT Malware HTTP Daily Feed 2018 (01/01/2018 to 12/31/2018)
收藏资源简介:
This dataset contains a daily feed of HTTP data produced by the Georgia Tech Information Security Center's malware analysis system in 2018. Supplemental metadata included with the feed associates each URL and HTTP object with a specific suspect Windows executable, which is run in a sterile, isolated environment, with controlled access to the Internet, for a short period of time. Network activity comprising each sample's use of HTTP is recorded, processed, and made available as URL CSV files, extracted HTTP object sets, and raw PCAPs. The feed is structured as a set of archives that each correspond to a single day of sample processing-based HTTP activity collection. Each archive decompresses to a top-level folder containing a URL CSV file, a PCAP subdirectory, and an HTTP objects subdirectory for that day. The PCAP and objects subdirectories each contain files that are named according to the MD5 of the sample that performed the corresponding activities over HTTP.



