A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #28498  by enkidu
 Sat May 14, 2016 3:34 pm
Hi guys,
i know malwares can be categorized below same families. also same family malwares (dynamic analysis) have similar behaviour (pattern).
i have cuckoo sandbox and reports in malheur, json and maec formats.
my question is: how can i use report (lets say malheur) of one malware, to use it for detecting all other malwares from same family?
json in cuckoo got vt hashtag( virustotal) but i dont want to use that, i want use a method that can find similarity between malwares of same family.
any kind of help, such as links for guides, books or any idea would be very appreciated.
thank you
 #28505  by Xylitol
 Sun May 15, 2016 10:47 am
Image
in facts there is a lot of way to find similar samples.
you can write your own signatures, this advantage you don't need memory analysis to extract the c&c, etc... it's just parsers.
https://github.com/spender-sandbox/comm ... signatures
you can search engine also with specific mutex etc...