UploadMalware.com Perl Submission Script
Posted by jeremy on April 14th, 2008
I was recently introduced to UploadMalware.com, which is a site made up of several security professional volunteers. They actively accept your Malware binary submissions and submit them to several Antivirus companies to help in speeding up the process of identifying, classifying, and the development of Malware signatures, which may I say benefits everyone. You can find a list of vendors they work with here: Vendors. In support of what these volunteers are attempting to do I have created a small Perl script that will allow anyone to submit suspicious binaries to their site without having to use the web interface. I have included all of the options available to you via their web form. All options except for the binary file are optional when submitting binaries to them, but I would encourage you to provide as much information as possible. They also offer an IRC channel where many of these professionals can be found hanging out willing to talk with you about your submissions or anything else Malware and/or Security related. You can find their channel "#uploadmalware" on the WyldRyde IRC Network, or use their instant chat web client located on their website.
If you have a honeypot or harvest Malware, may I suggest using this script to automatically submit binaries by creating a cron job or writing a small wrapper script. Just a suggestion.
Here is a link to the script I created: uploadmalware_submit_pl. As always if you have any issues with this script or find any bugs feel free to contact me anytime.
April 14th, 2008 at 10:33 pm
Thanks. Any chance of a virustotal.com uploader script as well? It would be great to maximize the number of places one could upload malware too. This would be great because it would be yet another place to upload malware and have is distributed to those who don’t detect the piece of malicious code.
April 14th, 2008 at 10:38 pm
Yea, I guess I could give it a shot… I know virustotal.com’s web interface is a little different than your normal fire and forget HTTP POSTs, but I am sure it is do able. Next chance I get I will see what I can do. Thanks for the feedback!
–jeremy
April 15th, 2008 at 6:17 am
you could try my colleague’s http://hype-free.blogspot.com/2007/08/unofficial-virustotal-uploader.html
April 15th, 2008 at 6:48 am
I will definitely give it a look over, but I had heard it was broken. Thanks for the reference!