trisulnsm / trisul-scripts

Ready to run scripts for network analysis
84 stars 27 forks source link

Added fingerprints generated from all PCAPs on malware-traffic-analys… #4

Closed JunPritsker closed 6 years ago

JunPritsker commented 6 years ago

I downloaded and processed the PCAPs at malware-traffic-analysis.net and produced ja3 hashes. I organized the data by unique hashes where the description for a given hash lists all the malware that produced that hash. Some hashes I've added already exist in the data set. These hashes need to be further tested and verified.

trisulnsm commented 6 years ago

Awesome work !

trisulnsm commented 6 years ago

What does the FP in "Malware Test FP" mean in each of the descriptions ?

JunPritsker commented 6 years ago

"Fingerprint". At least that's what I assumed lines 290-293 meant.