{"repo":"alexandreborges/malwoverview","free":true,"listed":false,"github":"https://github.com/alexandreborges/malwoverview","clone":"git clone https://github.com/alexandreborges/malwoverview.git","description":"Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.","language":"Python","stars":4068,"topics":["malware","virustotal","malpedia","urlhaus","alienvault","malshare","threathunting","malwarebazaar","threatfox","cybersecurity"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":"Malwoverview Copyright (C) 2018-2026 Alexandre Borges (https://exploitreversing.com) This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. See GNU Public License on . Current Version: 8.1.0 (Codename: Revolutions) Important note: Malwoverview does NOT submit samples to any endpoint by default, so it respects possible Non-Disclosure Agreements (NDAs). There're specific options that explicitly submit samples, but these options are explained in the help. ABOUT Malwoverview.py is a first response tool for threat hunting, which performs an initial and quick triage of malware samples, URLs, IP addresses, domains, malware families, IOCs and hashes. Additionally, Malwoverview is able to get dynamic and static behavior reports, submit and download samples from several endpoints. In few words, it works as a client to main existing sandboxes. This tool aims to : 01. Determine similar executable malware samples (PE/PE+) according to the import table (imphash) and group them by different colors (pay attention to the second column from output). Thus, colors matter! 02. Show hash","default_branch":null,"files":null,"tree":[],"storefront":"/r/alexandreborges","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/alexandreborges/malwoverview/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}