Join us for the Honeynet Workshop 2024: May 27th–29th, Copenhagen, Denmark

Identifying unknown files by using fuzzy hashing

14 Feb 2012 Leon van der Eijk fuzzy-hashing
Identifying unknown files by using fuzzy hashing Over the last couple of years I have captured about 2 gigabytes of malware using the Dionaea honeypot. Analysing and identifying those files can mostly be done by sites as Virustotal, Anubis or CWsandbox. By modifying the ihandler section in the dionaea.conf this can be done fully automated. Every now and then even these excellent analysis sites come up with nothing. No result or whatsoever.