sudosecure.net

              is anything truly secure…

UploadMalware.com Perl Submission Script

Posted by jeremy on April 14th, 2008

I was recently introduced to UploadMalware.com, which is a site made up of several security professional volunteers. They actively accept your Malware binary submissions and submit them to several Antivirus companies to help in speeding up the process of identifying, classifying, and the development of Malware signatures, which may I say benefits everyone. You can find a list of vendors they work with here: Vendors. In support of what these volunteers are attempting to do I have created a small Perl script that will allow anyone to submit suspicious binaries to their site without having to use the web interface. I have included all of the options available to you via their web form. All options except for the binary file are optional when submitting binaries to them, but I would encourage you to provide as much information as possible. They also offer an IRC channel where many of these professionals can be found hanging out willing to talk with you about your submissions or anything else Malware and/or Security related. You can find their channel "#uploadmalware" on the WyldRyde IRC Network, or use their instant chat web client located on their website.

If you have a honeypot or harvest Malware, may I suggest using this script to automatically submit binaries by creating a cron job or writing a small wrapper script. Just a suggestion. ;)

Here is a link to the script I created: uploadmalware_submit_pl. As always if you have any issues with this script or find any bugs feel free to contact me anytime.

4 Responses to “UploadMalware.com Perl Submission Script”

  1. Nice Says:

    Thanks. Any chance of a virustotal.com uploader script as well? It would be great to maximize the number of places one could upload malware too. This would be great because it would be yet another place to upload malware and have is distributed to those who don’t detect the piece of malicious code.

  2. jeremy Says:

    Yea, I guess I could give it a shot… I know virustotal.com’s web interface is a little different than your normal fire and forget HTTP POSTs, but I am sure it is do able. Next chance I get I will see what I can do. Thanks for the feedback!

    –jeremy

  3. amaximciuc Says:

    you could try my colleague’s http://hype-free.blogspot.com/2007/08/unofficial-virustotal-uploader.html

  4. jeremy Says:

    I will definitely give it a look over, but I had heard it was broken. Thanks for the reference!

Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>