Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Executable Packing
  3. Malware Archive

Malware Archive

HTML

A collection of real-world malware samples, analysis exercises, and training resources for cybersecurity education and research.

Visit WebsiteGitHubGitHub
1.7k stars241 forks0 contributors

What is Malware Archive?

Malware-samples is a GitHub repository that provides a curated collection of real-world malicious files, analysis exercises, and training resources for cybersecurity education. It offers password-protected malware samples from numerous families like Emotet, TrickBot, and AgentTesla, along with detailed walkthroughs and network captures to help professionals develop practical malware analysis skills in a safe environment.

Target Audience

Cybersecurity professionals, malware analysts, threat hunters, incident responders, security researchers, and students who need hands-on experience with real malware samples for training, research, or skill development.

Value Proposition

This repository provides immediate access to a vast, organized collection of real malware samples and educational materials that are typically difficult to obtain legally. The accompanying analysis exercises and workshop materials offer structured learning paths, making it a comprehensive resource for both beginners and experienced analysts.

Overview

Malware samples, analysis exercises and other interesting resources.

Use Cases

Best For

  • Practicing static and dynamic malware analysis techniques
  • Developing threat hunting skills with real network captures
  • Studying malware delivery mechanisms through malicious documents
  • Learning reverse engineering with actual packed samples
  • Creating detection rules and signatures from real threats
  • Preparing for cybersecurity certifications and job interviews

Not Ideal For

  • Organizations requiring legally vetted, commercially licensed training materials with vendor support
  • Complete beginners with no prior experience in malware analysis or safe lab setup
  • Teams needing real-time, up-to-date threat intelligence feeds for active defense
  • Projects where structured curricula and certification paths are essential

Pros & Cons

Pros

Vast Real-World Collection

Includes password-protected executables, documents, and scripts from numerous malware families like Emotet and TrickBot, organized by date and campaign for trend analysis, as seen in the detailed summary of samples.

Hands-On Learning Exercises

Provides step-by-step walkthroughs on topics like shellcode execution and macro deobfuscation, with detailed solutions to reinforce practical skills, as listed in the malware analysis exercises section.

Rich Supplementary Resources

Offers training PCAPs for network analysis and workshop materials from conferences like DefCon, enhancing threat hunting and detection development, as highlighted in the training PCAPs and workshops sections.

Safety-First Approach

All samples are in password-protected archives (password: infected) to prevent accidental execution, aligning with educational intent and clear disclaimers in the README.

Cons

Irregular Maintenance

As a personal GitHub repository, updates and new samples depend on the maintainer's availability, leading to potential gaps in current threat coverage, with the latest exercises dated 2022.

Steep Learning Curve

Assumes users have foundational knowledge of malware analysis tools and techniques, with limited guidance for absolute beginners, as exercises jump into advanced topics without basic tutorials.

No Formal Support

Lacks official documentation, community forums, or guaranteed responses to issues, unlike commercial training platforms, relying solely on GitHub discussions for user help.

Frequently Asked Questions

Quick Stats

Stars1,657
Forks241
Contributors0
Open Issues0
Last commit2 years ago
CreatedSince 2019

Tags

#malware-samples#malware-analysis#threat-intelligence#malware#training#security-research#forensics#cybersecurity-training#incident-response#reverse-engineering#threat-hunting#pcap-analysis

Links & Resources

Website

Included in

Executable Packing1.6k
Auto-fetched 6 hours ago

Related Projects

theZootheZoo

A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.

Stars13,231
Forks2,762
Last commit3 months ago
EmberEmber

Elastic Malware Benchmark for Empowering Researchers

Stars1,168
Forks312
Last commit1 year ago
Ember2024Ember2024

EMBER2024 is an updated malware dataset designed for researchers to explore a variety of classification tasks, including malicious/benign detection, malware family classification, and behavior prediction. It provides raw features and multiple label types for 3.2 million files, enabling holistic evaluation of machine learning models in cybersecurity. ## Key Features - **Multi-File Type Support** — Includes Win32, Win64, .NET, APK, ELF, and PDF files for cross-platform analysis. - **Temporal Split** — Training and test sets are separated by time to simulate detection of newer malware. - **Challenge Set** — Contains 6,315 evasive malicious files initially undetected by antivirus products. - **Feature Version 3** — Re-implemented feature vector format using the stable pefile library, with additions like DOS header and Authenticode signature features. - **Extended Labels** — Seven types of labels and tags support diverse classification tasks beyond simple detection. - **Capa Integration** — Includes malware behavior analysis results (ATT&CK techniques, MBC behaviors) for Win32, Win64, .NET, and ELF files. ## Philosophy EMBER2024 aims to provide a comprehensive, realistic benchmark that reflects the evolving malware landscape, enabling robust evaluation of classifier performance on novel and evasive threats.

Stars127
Forks27
Last commit11 months ago
BODMASBODMAS

Code for our DLS'21 paper - BODMAS: An Open Dataset for Learning based Temporal Analysis of PE Malware. BODMAS is short for Blue Hexagon Open Dataset for Malware AnalysiS.

Stars94
Forks18
Last commit10 days ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub