controlled research corpus

Malware Sample
Collections

Purpose-built Windows PE sets for reverse engineering, detector validation and malware-analysis education. Every file is hash-verified and assigned to exactly one collection.

index / 2026.08

Choose a signal

50 samples per set · SHA-256 named · R2 delivery

01 native language

Rust Windows Malware

Native Windows PE samples with high-confidence Rust compiler and runtime artifacts.

set
50 PE
raw
1.20 GiB
arch
49 x64 · 1 x86
02 native language

Go Windows Malware

Go-compiled Windows executables confirmed through readable build metadata and runtime structures.

set
50 PE
raw
344.7 MiB
arch
44 x64 · 6 x86
03 managed code

Managed .NET Samples

Managed Windows malware selected through structural CLR metadata in the PE optional header.

set
50 PE
raw
205.9 MiB
arch
5 x64 · 45 x86
04 packing

Packed & Protected

Samples carrying recognizable packer or commercial protector section signatures.

set
50 PE
raw
75.7 MiB
arch
50 x86
05 obfuscation

Strongly Obfuscated

PE files selected from multiple independent entropy, import, string, section and entry-point signals.

set
50 PE
raw
29.7 MiB
arch
50 x86
06 virtualization

Obfuscated Functions

A balanced set protected by VMProtect, Themida, WinLicense, Secure VMP, VProtect or Enigma.

set
50 PE
raw
873.7 MiB
arch
22 x64 · 28 x86
07 execution chain

Loaders, Droppers & Injectors

Samples with direct remote-memory, thread, APC, process-hollowing or context-manipulation capabilities.

set
50 PE
raw
410.7 MiB
arch
46 x64 · 4 x86
08 collection

Credential Theft & Stealers

Credential-focused PE files targeting DPAPI, browser databases, LSASS or keyboard input.

set
50 PE
raw
453.7 MiB
arch
33 x64 · 17 x86
09 command & control

RATs, Backdoors & C2

Remote-access samples combining network communication with command execution and control artifacts.

set
50 PE
raw
517.9 MiB
arch
34 x64 · 16 x86
10 impact

Ransomware & Destructive

File-impacting samples combining enumeration, modification and encryption with recovery inhibition.

set
50 PE
raw
519.1 MiB
arch
31 x64 · 19 x86
11 kernel

Windows Kernel Drivers

Native-subsystem PE drivers with structural kernel characteristics and kernel import evidence.

set
50 PE
raw
15.6 MiB
arch
1 x64 · 49 x86
TOP