Big changes to Minotaur
by dave on Jun.18, 2011, under Analytics, Minotaur
Minotaur now presents all stats on every malware family we track here.
The list page presents little maps of the average location of our detections of each malware family. While still in the very early stages of developing these tools, I have noticed the vast majority of these maps center in on europe. At this time, I believe this is due to that region being the intersection of all the points from otherwise very diverse geographic locations, and is not indicative of raised activity in europe.
Clicking on a family name will take you to our detailed statistics for that malware family, including a map of the most recently observed distribution servers. There is also a list of the actual samples here. Clicking on a sample will bring you to our detailed report on that particular sample.
This page will show you everything we know about a particular sample, including filetype probabilities, vendor concurrence, detections by all vendor engines, and links to outside information. In the near future, upgrades will allow you to pull the raw data reports from our tools for each sample.
We’ve also been busy integrating our different toolsets. For instance, in the detailed malware sample reports, near the bottom we have integrated our anti-malware DNS system’s known info for the originating site’s domain:
And very importantly, we are working on integrating a discussion engine into every page for every family, every sample, every category, everything. Feel free to leave a comment on any object you want, as it builds our community and could help out the malware research community as a whole by sharing what we know with each other.




