# Endermanch/MalwareDatabase: a curated malware collection with a password on every archive

> The repository is one of the few public malware collections on GitHub, organised into rogues, trojans, ransomwares, jokes and more. It is a study archive, not a detection tool, and every sample is live code.

**Endermanch/MalwareDatabase** — One of a few malware collections on the GitHub.

- Repository: https://github.com/Endermanch/MalwareDatabase
- Website: https://malwarewatch.org
- Stars: 2,925 · Forks: 589
- Language: Python
- License: not declared
- Published: 2026-09-24 · Updated: 2026-09-24 · Language: en
- Canonical page: https://hysenlabs.com/projects/endermanch-malwaredatabase

## What Endermanch/MalwareDatabase is for

The README frames the project as a learning collection rather than a feed. Its stated purpose is cybersecurity education through hands-on tinkering, and it warns that almost every sample is malicious, that incorrect use can cause data leaks, device inoperability and data loss, and that the owner and contributors accept no responsibility for damage. That disclaimer is the most important line in the repository, because it tells you the intended user is someone who already knows how to build a disposable environment.

The audience is narrow. The README says advanced computer knowledge is recommended before dealing with malware in general, and the collection is aimed at people who want to inspect samples rather than feed them to a scanner. If you are looking for a corpus to benchmark an antivirus engine, this is the wrong shape of data. The repository's own statistics table puts Rogue/PUP at roughly 40 percent, malicious websites at 20 percent, jokes at 15 percent, trojans at 10 percent, ransomware at 10 percent and custom-made samples at 5 percent. A collection that is four parts adware and jokes to one part trojan is a poor proxy for what a modern detection pipeline faces.

## How the collection is laid out on disk

The layout is flat and human-readable, which is the main design decision here. The top level holds ddom.py, a README, and directories named davepl, enderware, fakescanners, jokes, modern, ransomwares, rogues and trojans, plus loose archives such as 2989‮.zip, Ana.zip and NoEscape.zip. There is no manifest, no index file and no hash list in the repository listing, so discovery means reading directory names and opening archives.

That structure is a trade-off. It makes browsing easy and keeps sample provenance visible in the directory name, but it gives you nothing machine-readable. There is no JSON index mapping a filename to a family, a platform or a date, and no hash database despite hash-related search terms being common around this subject. If you want to script over the collection, you will be building that index yourself from filenames. The presence of a Python file, ddom.py, at the top level is the only sign of tooling in the repository listing, and the README does not describe what it does.

## Getting a sample open: install and first use

There is no package to install and no install command in the README. The project is a set of archives in a Git repository, and the README's only operational instruction is the archive password, which it states is mysubsarethebest, used verbatim for every archive. The repository listing shows the archives themselves as the entry point: 2989‮.zip, Ana.zip and NoEscape.zip sit at the top level alongside the rogues, trojans, ransomwares, fakescanners, jokes, modern, enderware and davepl directories.

Because the README does not document a clone, a download or an extraction command, the setup is whatever your own tooling for handling password-protected archives already is. The one thing you need from the project is the password string. If extraction fails, the README's own advice is to check for typing mistakes first and then open an issue so the sample can be reuploaded with the correct password. That is a real failure mode of this collection: a wrong password on a reuploaded archive is a support request, not a bug you can patch locally.

Before you extract anything, note the README's warning that samples should not be executed on real hardware and should not be sent to other people as a prank. The repository is a source of files, not a sandbox; isolation is something you bring.

## Where this collection falls short

The biggest limitation is currency. The README says the maintainer does not have much time to collect malware anymore, and the last push to the repository was on 2026-07-21. That is recent enough that the repository is not abandoned, but the stated intent is a slow trickle of additions rather than a feed. Anyone who needs samples of a family discovered last week should look elsewhere.

The second limitation is composition. With 40 percent of the collection classified as Rogue/PUP and 15 percent as jokes, the archive is heavy on software that annoys rather than software that persists, escalates or exfiltrates. For reverse engineering practice on packers, loaders or kernel components, the yield per hundred files is low.

The third is the lack of metadata. There are no hashes, no family labels beyond directory names, and no dates on individual samples in the repository listing. That makes deduplication and triage manual work.

Finally, there is a licensing gap. The repository listing gives no license, and the README's copyright line covers the repository itself rather than the samples inside it. Malware authorship and redistribution are not something a repository license can settle.

## Alternatives and how they differ

The obvious alternative people search for alongside this project is VirusTotal. The difference in approach is fundamental: VirusTotal is a query and scanning service where you submit a file or a hash and get multi-engine verdicts and behavioural reports back, while Endermanch/MalwareDatabase is a local, offline archive of actual sample files. VirusTotal answers "is this file known and what does it do"; this repository answers "give me a file to look at". They are complementary, and the README's own framing of the project as a place to tinker assumes you already have analysis tooling around it.

Other public malware collections exist on GitHub and in academic and vendor sample portals. The README here does not name them, so treat any comparison you read elsewhere as unverified. What can be said from this repository alone is that its distinguishing choice is curation by a single maintainer with a stated aesthetic filter: contributed self-made malware has to be well made, original and have artistic value, and only the cream of the crop is reviewed and uploaded. That is a very different selection rule from a bulk feed that ingests everything a crawler finds, and it explains both the small size and the odd composition.

## Maintenance, contributions and what the license does not cover

The repository is not archived, and the last push was on 2026-07-21, so the project is still receiving changes, but the README's own note that the maintainer has little collection time sets expectations: do not plan around a steady supply of new samples. The README footer says it was last updated on July 31st, 2024, which is a long gap before the most recent push and suggests documentation lags behind the archive.

Contributions go through email rather than pull requests, according to the README, which directs malware submissions to the maintainer's mailbox and asks that requests for missing samples go there too rather than into issues. The README also asks people not to spam issues with sample requests. If you want a specific sample added, that is the documented channel.

The license field is unknown. Nothing in the repository grants rights to redistribute the samples, and the copyright notice at the bottom of the README covers the repository, not the malware authors' code. That distinction matters if you plan to mirror the collection or include samples in a published dataset. This is not legal advice, and the practical reading is simple: the repository gives you files to study, not a redistribution grant.

## Conclusion

Adopt this repository only if you already run an isolated analysis lab and want a small, hand-curated set of samples for reverse engineering practice, and read the README's disclaimer before you download anything. Do not use it as a detection corpus, a training set for a scanner, or a source of samples to run on hardware you care about; the collection is weighted toward rogue software and joke programs rather than modern malware families. Before you commit disk space, verify three things: that the archive password mysubsarethebest still opens the files you downloaded, that the specific family you want is actually present in the directory listing rather than only in a YouTube review, and that your lab has no route back to your production network.

## FAQ

### What is Endermanch/MalwareDatabase?

It is a public malware collection hosted on GitHub, described in its README as one of the few such collections on the site. Samples are stored in password-protected archives and organised into directories such as rogues, trojans, ransomwares and jokes.

### What is the password for the archives in Endermanch/MalwareDatabase?

The README states that the password for every archive in the repository is mysubsarethebest, used verbatim. If extraction still fails, the README advises checking for typing mistakes and then opening an issue so the sample can be reuploaded.

### What types of malware does Endermanch/MalwareDatabase contain?

The README's statistics table gives an approximate ratio: Rogue/PUP 40 percent, malicious website 20 percent, joke 15 percent, trojan 10 percent, ransomware 10 percent and custom-made 5 percent. The collection therefore leans toward rogue software and jokes rather than trojans and ransomware.

### Can I contribute samples to Endermanch/MalwareDatabase?

Yes, according to the README, by sending submissions to the maintainer's mailbox. Self-made malware has to be well made, original and have artistic value, and the README says only the cream of the crop will be reviewed and uploaded.

### Why is the Solaris sample missing from Endermanch/MalwareDatabase?

The README states that the original creator of the malware, nikitpad, does not want the sample shared online, and the maintainer respects that decision. The README asks users not to bother either of them about it.

## Sources

- [Endermanch/MalwareDatabase on GitHub](https://github.com/Endermanch/MalwareDatabase)
- [Issues](https://github.com/Endermanch/MalwareDatabase/issues)
- [Project website](https://malwarewatch.org)
- [README](https://github.com/Endermanch/MalwareDatabase/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/endermanch-malwaredatabase
