{"repo":"momenbasel/malware-check","free":true,"listed":false,"github":"https://github.com/momenbasel/malware-check","clone":"git clone https://github.com/momenbasel/malware-check.git","description":"Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations","language":"Python","stars":63,"topics":["appsec","binary-analysis","devsecops","docker","malware-analysis","mobile-security","privacy","python","reverse-engineering","sarif"],"license":"MIT","category":"security-tools","readme_excerpt":"Install - Usage - Dynamic Analysis - YARA Rules - CI/CD Docs: English Tiếng Việt --- Static and dynamic analysis tool for detecting malicious code, suspicious binaries, and privacy violations. Analyzes source code, compiled executables (.exe, .dll, .elf), macOS bundles (.app, .dmg, .pkg), mobile apps (.apk, .ipa), and application packages with YARA rules, Docker behavioral sandboxing, MobSF mobile analysis, payload deobfuscation, and multi-format reporting (JSON, HTML, SARIF). Features Static Analysis - Source Code Scanner - Detects reverse shells, backdoors, web shells, obfuscated payloads, crypto miners, ransomware patterns, keyloggers, credential theft, supply chain attacks, and persistence mechanisms across 15+ languages - Binary Analyzer - PE (Windows), Mach-O (macOS), and ELF (Linux) analysis with entropy detection, import table inspection, string extraction, code signing verification, and RWX section detection - AI File Type Detection - Optional Magika integration for content-based detection of extensionless or disguised files - YARA Engine - Signature-based scanning with bundled rules for malware families, packers, and suspicious patterns. Supports custom rule directories - Privacy Analyzer - Detects tracking SDKs, PII field handling, invasive permissions (Android/iOS manifests), device fingerprinting, clipboard monitoring, and unauthorized data transmission Dynamic Analysis (Docker Sandbox) - Runs suspicious binaries in an isolated Docker container with: - syscall tr","default_branch":null,"files":null,"tree":[],"storefront":"/r/momenbasel","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/momenbasel/malware-check/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}