Live malware sample download and unpack
malware_bazaar_live_sample
Downloads real malware samples from MalwareBazaar as password-protected ZIP archives and unpacks them into the sandbox, to see whether the download or the on-disk write is detected. THE SAMPLES ARE NEVER EXECUTED. Requires --live-samples and an abuse.ch key in addition to consent, and everything is deleted immediately.
What it needs before it will run
-
--i-understandNeeds explicit consent: this test changes machine state or fetches real offensive tooling.
-
sends trafficGenerates outbound traffic. --no-network suppresses it entirely.
Gates are cumulative and none of them is implied by another: see the three gates for why they are separate decisions.
ATT&CK techniques it exercises
| Technique | Name | Tactic | Across public reports |
|---|---|---|---|
| T1105 | Ingress Tool Transfer | Command and Control | coverage statistics |
| T1204.002 | Malicious File | Execution | coverage statistics |
| T1588.001 | Obtain Capabilities: Malware | Resource Development | coverage statistics |
How often anything notices
Not enough data: fewer than 3 public reports have run this test, so no rate is published for it. Groups below that threshold are withheld everywhere on the site — with one or two contributors an average is one organisation's result with a percent sign after it.
Other malware samples tests
| Test | What it does | Severity |
|---|---|---|
| Offensive tooling download (mimikatz) offensive_tool_download | Downloads mimikatz and two PowerSploit scripts to a temporary file to see whether the proxy, DNS filter or on-access scanner intervenes. The files are… | high |
| MalwareBazaar metadata query malware_bazaar_hash_query | Queries abuse.ch's MalwareBazaar API for recently submitted samples and records the hashes and family labels it returns. Metadata only: no sample is r… | low |
Catalogue generated from client 0.1.0. A test's behaviour can
change between releases; this page describes the version named here.