遇见数据集

WinMET Dataset

收藏
Zenodo2024-07-13 更新2026-05-29 收录
官方服务:

资源简介:

WinMET (Windows Malware Execution Traces) Dataset WinMET dataset contains the reports generated with CAPE sandbox after analyzing several malware samples. The reports are valid JSON files that contain the spawned processes, the sequence of WinAPI and system calls invoked by each process, their parameters, their return values, and OS accesed resources, amongst many others. This dataset was generated using the MALVADA framework, which you can read more about in our publication: TBA. The article also provides insights about the contents of this dataset. How to use the dataset The 7z file is password protected. The password is: infected. Compressed size on disk: ~2.5GiB.Decompressed size on disk: ~105GiB.Total decompressed .json files: 9889. The name of each .json file is irrelevant. It corresponds to its analysis ID. Integrity checks: MD5: 75b3354fb186ae5a47c320e253bd96ee SHA256: 00faac011f4938a29ba9afbd9f0b50d89ede342d1d0d6877cb90b46eabd92c72 SHA512: 038ca9303623cadaa72eab680221e81e1d335449d08f6395b39eb99baad4092e02c00955089fba31ce1a9dd04260ae80b622491f754774331bced18e8e3be1c4 Citation If you use this dataset, cite it as follows: TBA. Statistics The following statistic (and many more) can be obtained by analyzing the WinMET dataset with the MALVADA framework. Total reports: 9889. Average VT (VirusTotal) detections: ~53. There 268 benign or undetected reports. That is, 10 or less VT detections (default threshold). There are 2584 reports with no CAPE consensus label. There are 695 reports with no AVClass consensus label. Top 20 CAPE consensus labels (there are many more): "(n/a)": 2584 "Redline": 1227 "Agenttesla": 1010 "Crifi": 622 "Amadey": 606 "Smokeloader": 538 "Virlock": 471 "Msilheracles": 408 "Tedy": 364 "Disabler": 343 "Xorstringsnet": 321 "Snake": 252 "Autorun": 252 "Metastealer": 246 "Formbook": 244 "Lokibot": 202 "Strab": 188 "Loki": 185 "Mint": 179 "Taskun": 178 Top 20 AVClass consensus labels (there are many more) "Reline": 2187 "Disabler": 732 "(n/a)": 695 "Amadey": 575 "Agenttesla": 478 "Taskun": 382 "Virlock": 293 "Equationdrug": 270 "Stop": 268 "Strab": 260 "Noon": 259 "Gamarue": 181 "Dofoil": 135 "Makoob": 113 "Mokes": 110 "Snakelogger": 110 "Bladabindi": 98 "Zard": 84 "Gcleaner": 83 "Deyma": 80

WinMET(Windows恶意软件执行轨迹,Windows Malware Execution Traces)数据集 WinMET数据集包含使用CAPE沙箱(CAPE Sandbox)分析多款恶意软件样本后生成的分析报告。此类报告均为合规JSON格式文件,涵盖衍生进程、各进程调用的WinAPI(Windows应用程序编程接口)与系统调用序列、其参数及返回值,以及操作系统访问的资源等诸多内容。 本数据集基于MALVADA框架(MALVADA)生成,更多相关细节可参阅我们待公开(TBA)的研究论文,该文章亦对本数据集的内容进行了详细阐释。 数据集使用说明 该数据集以7z压缩包形式分发,压缩包受密码保护,解压密码为:infected。压缩后磁盘占用空间约2.5GiB,解压后磁盘占用空间约105GiB,总计包含9889个JSON格式文件。每个JSON文件的文件名无实际业务意义,仅对应其分析ID。 完整性校验 MD5:75b3354fb186ae5a47c320e253bd96ee SHA256:00faac011f4938a29ba9afbd9f0b50d89ede342d1d0d6877cb90b46eabd92c72 SHA512:038ca9303623cadaa72eab680221e81e1d335449d08f6395b39eb99baad4092e02c00955089fba31ce1a9dd04260ae80b622491f754774331bced18e8e3be1c4 引用规范 若使用本数据集,请按照以下格式进行引用:待公开(TBA)。 统计信息 通过MALVADA框架分析WinMET数据集,可获取如下(及更多)统计结果: 总报告数:9889份。 平均VirusTotal(简称VT)检测次数:约53次。 其中包含268份良性或未被检测到的报告,即VT检测数小于等于10(默认阈值)。 另有2584份报告无CAPE共识标签,695份报告无AVClass共识标签。 CAPE共识标签前20名(尚有更多标签): "(n/a)": 2584 "Redline": 1227 "Agenttesla": 1010 "Crifi": 622 "Amadey": 606 "Smokeloader": 538 "Virlock": 471 "Msilheracles": 408 "Tedy": 364 "Disabler": 343 "Xorstringsnet": 321 "Snake": 252 "Autorun": 252 "Metastealer": 246 "Formbook": 244 "Lokibot": 202 "Strab": 188 "Loki": 185 "Mint": 179 "Taskun": 178 AVClass共识标签前20名(尚有更多标签): "Reline": 2187 "Disabler": 732 "(n/a)": 695 "Amadey": 575 "Agenttesla": 478 "Taskun": 382 "Virlock": 293 "Equationdrug": 270 "Stop": 268 "Strab": 260 "Noon": 259 "Gamarue": 181 "Dofoil": 135 "Makoob": 113 "Mokes": 110 "Snakelogger": 110 "Bladabindi": 98 "Zard": 84 "Gcleaner": 83 "Deyma": 80

提供机构:
Zenodo
创建时间:
2024-07-04
二维码
社区交流群
二维码
科研交流群
商业服务