More than twice for last 24 hours I was asked non-trivial question:
Where You find targets for malware hunt, if You not part of big team, malware researcher or not own a honeynet.
Actually, if You want to fight malware, IMHO it very useful to have honey-pot system, or at least be in security business somehow. It will provide You non-stop flow of malicious targets to review. But if not, and You still want to help?
Disclamer: All links provided lead to lists of malicious or potentially malicious resources. Do not click there on any link, or don’t run any file, without proper knowledge, env prepared and skills trained.
Well, here are few links, that aggregate latest known threats, that You can practice on:
1. Malware Domain List:
http://www.malwaredomainlist.com/update.php
2. URL Query
http://urlquery.net/
3. Malekal.com list of malware
http://www3.malekal.com/malwares/
4. VX Vault
http://vxvault.siri-urz.net/ViriList.php?
5. Site Inspector (by Comodo)
http://siteinspector.comodo.com/recent_detections
6. Scumware.org
http://www.scumware.org/index.scumware
7. Malc0de Database
http://malc0de.com/database/
8. Sucuri Malware Labs
http://labs.sucuri.net/?malware
9. Clean-MX Realtime database
http://support.clean-mx.de/clean-mx/viruses
10. Sourcefire Vulnerability Research Team Labs
http://labs.snort.org/iplists/
11. Zeus Tracker
https://zeustracker.abuse.ch/monitor.php?browse=binaries
12. NovCon Minotaur Analysis System
http://minotauranalysis.com/malwarelist-urls.aspx
p.s. Many thanks to DrM for almost tripling the list!
Note: threats usually detected by many participants, blocked and dead, as result (and this is good!), so if You looking for alive target- see recent updates, search for simulate domains, hosted on same IP etc.
Happy and lucky hunt. Share Your findings (You can do it also here http://twitter.com/MalwareMustDie ), and in case You know another good lists of malware urls and targets – comment and I will add it to list.
Happy and lucky hunt
Cheers
D.L.