Published April 28, 2024 | Version 0.9

API traces for malware detection

Description

The dataset consists of traces of benign and malware samples. There are approximately 330k traces in the dataset, each meticulously collected and curated for research and analysis purposes, with an uncompressed size of 550GB. The dataset was collected during the second half of 2023. The file "shas_by_families.json" links each SHA(which is also the individual filenames) with the associated malware or benign family.  Each file is in json format and includes the parameters of the API call as well.

 

If you are using this dataset, please cite our work on Arxiv.
@misc{fellicious2025malwaredetectionbasedapi,
      title={Malware Detection based on API calls}, 
      author={Christofer Fellicious and Manuel Bischof and Kevin Mayer and Dorian Eikenberg and Stefan Hausotte and Hans P. Reiser and Michael Granitzer},
      year={2025},
      eprint={2502.12863},
      archivePrefix={arXiv},
      primaryClass={cs.CR},
      url={https://arxiv.org/abs/2502.12863}, 
}

Files

shas_by_families.json

Files (9.4 GB)

Name Size
md5:03d9610cadb30ee5d6cad50251f111bf
9.3 GB Download
md5:b07c925aef91e8f5d76a6a5cf1b4ea6e
25.8 MB Preview Download

Additional details

Dates

Collected
2023-05-01
Start of data collection
Collected
2023-11-01
End of data collection

Software

Repository URL
https://github.com/smartvmi
Development Status
Active