This tool is a proof-of-concept packer for .NET executables designed to provide a starting point to explain the basic principles of runtime packing.
00edbbabaeeafd89302340cee6a316b6a2882f9c7f305be53f952d2c234eaf60
Gaara virus disinfector type 2 for the TI-89.
c46a539d643fc30ff3478167bae29e7253581e2f89e76263868c198af95635cd
Gaara virus disinfector type 1 for the TI-89.
5002b3c671866ead144a18c3b95a917630f242e0feae1773607598b790fa952c
Gaara is world's first resident entry-point-obscuring virus for ti89 Titanium calculators. Written fully in Motorola 68K assembly. For educational purposes only.
aa998ae04814d1ea2b39e6c48d02662c8a362c312cc066a3221330cfb51f3e3f
ELF binary infector written in assembly. Infects all binaries in /bin and opens a backdoor on port 30464. Shellcode can be added at the end.
b9973eeb2a742b906827bee86168be04984e30a36b880c9138bb8905fd7d0d35
File::Scan allows users to make multiplatform virus scanners which can detect Windows/DOS/Macintosh viruses. It includes a virus scanner and signature database.
6210231618d7fa636c6e3ddd222c0db3ad532514bb990311f4bff175c288f0d4
UPolyX version 0.3 is a simple polymorphic open-source UPX scrambler. Comes with VC6 source code.
76f803c4a241d2b65788305267750d8bb9e1ae284387570a49288f288b7670e9
Virus disinfection utility to be used against the Win32.HLLP.Sharp virus. Windows executable and source code included.
044c1da88409f73df196c8a644e1213ae3f6c9a089c2533ea8ce590607232212
Crew.tgz is the executable package for the lion worm. Includes 1i0n.sh and helper binaries.
5de32a8d054084c06a44e71b6ef7c6475b8ec6ac6a7c15cd0811b265835d949c
PolyPedoWorm is an example of a way to create a polymorphic, Microsoft Encoded Worm. Features include Polymorphism, Varying file size, and renaming of the variants.
e74664f147dc85254938e493894d8e2b62a8a7ba77085864ba73ebeeb1b0b6e8
AnnaKlean is a Console Application To Wipe Out Anna Kournikova Worm From Registry.
522ec8bac3d8dfb030025065881e023fb6d2300bd4835c00911457dba60cddf0
Unencrypted source code for the AnnaKournikova email worm, which is written in vbs.
86c35688afe1835d9e6e38b13aa455773d3fcefe6f171b6da95592401874aae0
AnnaKournikova.jpg.vbs email virus source code. Warning - Do not rename.
3f6a109c57ebf27b61497acb4a5f4d0206d1eca264a1361f4a275872c2528c81
Membrain.zip is a functional overwriting virus written in Quickbasic 4.5. Full source included.
c808586fe792bb028718b6975a2ffc17b47b38ef4d984be48f581bc9406590ad
Possible source to the Love Letter virus. Originally submitted to Packet Storm as Win32DLL.txt. Submitted by Ingenius N.N. who warns "Do not rename Win32DLL.txt with .vbs extention".
4ae4b7187960ee682b407a426778c63f0296772866564c5fe3472dd9db6982b2
Divorce the Love Letter virus. Cleans the rubbish out that the Virus caused. Not elegant but does the job! Read then run the Run_Fix.bat. Use at your own risk.
f8b8322a8efd0771596276ebaf05a1e132dbf3f08833e9ffcc6dc278c4adc7ff
vengine.zip (engine + virus source code) is a polymorphizer that can be used to polymorphize any MS-Word macro virus. This file includes Melissa and Polyssa scripts, and instructions simple enough for idiots who desire to spread viruses maliciously.
8a3305dc70826f7beab1c8eb07c903a97f5e263137d81f1c020e1b22cea20ad0
Excellent Mini-FAQ entitled "antivirus software for Linux".
8ec7d7f939cb46be15d339be9c7aea9dd505a02e0bbc3322c1c0a616b12b2da9
VDAT, the virus scene database, version 1.80 is THE resource for anything and everything related to the virus scene. Authors, Groups, Interviews, Magazines, Creators, Engines & Tools, Tutorials, Essays & Papers, Legal Issues, Anti-Virus, Virus Glossary, Editorials, and much, much more. At over 13 MB in uncompressed HTML format, there is simply too much to list here. Check out the VDAT web site for a detailed list of new additions in this release. Make sure you check out the interview with Stealthf0rk, Tally's Virus Link Reference, the Wild list March 1999, all of the new zines, and the excellent tutorials. 6.8 MB.
6683e6802e8ea6a609ae6300c2b84396102de4df883d754fe37bd3d49d574c2d
vengine.txt (just the engine) is a polymorphizer that can be used to polymorphize any MS-Word macro virus.
f9a85c09415cb674b8c4f2334b73722bc1e0d35ab6e1edbb349ed43b45811534
MS-DOS/Linux source-code demonstration virii by SVAT. califax replaces the stdio.h file in the /usr/local/include directory and gets compiled into every file compiled with gcc.
e5897aa26ea057b56d4cce3e983c3c207aae4055db9d19c54c3aef98d8af7837
Linux kernel module infecting virus source code.
4cc1797216f352db9f908e905ba9e0d67c81e943a765030fa5d4081833802886
VDAT v1.6 - THE virus scene database. 5.93MB.
0d948d89f17236acf5628330f88dd555eaccd82a82cf5df4be6a9f236a26af40
VLP I is a Linux source-code demonstration virus that infects ELF-execs.
aeea0606e577024feca6519adcdda2715b11ce0f2a2b0418ca5c06222c25ce98
UNIX/Linux source-code demonstration virii by the NetW0rker and Stealthf0rk of the SVAT-group. Stealth's web site
e918dfa8b2259e6042f8e75cf1567f8ae5a1dd1a447495841d08be0267caeaa2