Open-source project
ytisf/theZoo avatar
ytisf/theZoo

theZoo: A Live Malware Repository for Analysts Who Need Samples

A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.

13,422 stars2,773 forksPythonNOASSERTION

At a glance

What is it?
theZoo collects live malware binaries and source code in encrypted archives with checksums, driven by a Python CLI and a SQLite database. It is built for analysts who need real samples, and it is dangerous by design.
Who is it for?
theZoo suits malware analysts and students who work inside an isolated VM and understand that every archive is live and dangerous. It does not suit anyone who wants to run samples on a daily-use machine, and it does not suit teams looking for a maintained sample feed with an API, because the README describes a CLI over a local SQLite database and the newest tagged release is v0.60 from 2014.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 16 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What theZoo Solves, and Who It Is Actually For

Getting a real malware sample is harder than it sounds. The README states the project's founding observation plainly: almost all versions of malware are very hard to come by in a way that allows analysis. Samples circulate through private channels, arrive with unknown provenance, or come as a single binary with no source. theZoo's answer is a public repository where samples and source code sit in a fixed structure, so an analyst can pull one down and know what the checksums are.

The audience is narrow on purpose. The disclaimer names people who study malware, people who analyse it as part of a job, and people who want to block specific malware in their own environment. The README also warns that some samples are worms that will try to spread on their own. That warning defines the real user: someone with an isolated VM, no internet connection (or an internal virtual network), and no guest additions or equivalents installed. If that is not your setup, theZoo is not for you, and the README says so in capital letters.

How theZoo Stores Samples: Encrypted ZIPs, Hashes, and a Password File

The interesting part of theZoo is not the CLI, it is the packaging convention. Each malware directory is composed of four files: the malware itself inside an encrypted ZIP archive, a SHA256 sum of that archive, an MD5 sum of it, and a password file for the archive. Nothing is stored unpacked. The README explains the reason without hedging: these are live and dangerous malware and they come encrypted and locked for a reason.

That four-file layout gives you a verification step before you ever touch the payload. You can hash the archive and compare both the SHA256 and the MD5 against the shipped files, then read the password from the fourth file to open it. The duplication of both hash algorithms is worth noting. MD5 is fine for catching accidental corruption and useless against a deliberate collision, so the SHA256 file is the one that matters if you care about integrity. The README does not explain why both are kept, and the older format is likely a legacy of the project's age.

Samples are split into malware/Binaries and malware/Source. Source is further divided: files under Original are, in the README's own words, supposed to be (NO PROMISES!) the original source that leaked, while files under Reversed are reversed, decompiled or partially reconstructed. Treat that distinction as a provenance hint, not a guarantee. The README itself declines to promise anything about the Original folder.

Installing theZoo and Running Your First Search

theZoo is a Python project. The README gives a three-line setup: clone the repository, enter the directory, and install the requirements into your user site-packages. The requirements file lists urllib3, pyzipper and streamlit, so pyzipper is what handles the encrypted archives and streamlit belongs to the browser interface.

bash
git clone https://www.github.com/ytisf/theZoo
cd theZoo
pip install --user -r requirements.txt

Once the dependencies are in place, the README says to start the console by running the main script. There is no daemon, no server and no service file: the CLI is the default runtime state.

bash
python theZoo.py

After that, theZoo drops you into an interactive console. Version 0.60 moved the database to SQLite3 and reworked searching into what the changelog calls a freestyle fashion, so you type search terms rather than exact index keys. The database lives at conf/maldb.db according to the contribution instructions, which is also where the EULA file sits. The README notes that the program also accepts command-line arguments, so the same operations can be scripted instead of typed. Beyond the search and get commands named in the changelog, the README does not document the full command set, so expect to explore the console to find what it offers.

Adding Your Own Samples with prep_file.py

The contribution path is documented and short. Take the file you want to submit and run the preparation script against it, passing the filename as an argument. The README states that this creates a directory for you, which is presumably the four-file structure described above.

bash
python prep_file.py file_tosubmit.exe

The remaining step is manual: you submit the created directory along with changes to conf/maldb.db so the project knows which malware it is. That means contributors need to edit the SQLite database directly, and the README gives no schema, no migration tool and no validation command. If you are indexing samples at any volume, that is a real friction point. The changelog for v0.43 mentions an automatic reporting system for malwares not indexed in the framework, but no later entry describes it as finished, and a VirusTotal upload and indexing module is explicitly marked as not possible due to VirusTotal's restrictions.

Where theZoo Falls Short

The repository's own roadmap is the clearest statement of its limits. Under the predicted changelog for v1.0, two items remain unchecked: a light version without malwares built around a MalwareFetch function, and package releases. Under Hopeful, a GUI and package releases are both still open. The practical consequence is that cloning theZoo means cloning the samples. There is no supported way to get the index without the payload, so disk usage and clone time scale with the collection.

The release history reinforces this. The newest tagged release is v0.60 from 2014, and v0.50 before it in June 2014. The repository continues to receive commits (the last push was on 2026-09-14), but the versioned releases stopped over a decade ago, so there is no changelog for anything after 0.60. Anyone expecting a versioned upgrade path should look elsewhere.

The safety model is also entirely on you. The README's only containment advice is the VM recommendation. There is no sandbox, no execution wrapper, no detonation environment and no network isolation enforced by the tooling. theZoo is a download and storage system, not an analysis platform. If you want automated execution and behavioural reports, this is the wrong layer of the stack.

Finally, the licence carve-out deserves attention. The GPL v3 text in the README covers the program, and the README then states that the licence section does not apply to any of the malicious samples, including samples and source code, reversed or otherwise. The samples come with no licence grant at all. That is a legal question for your organisation, not something this article can settle.

theZoo Compared with MalwareBazaar, VirusShare and MalShare

The related searches around theZoo are dominated by other sample sources: VirusTotal, MalwareBazaar, VirusShare and MalShare. The difference in approach is worth stating precisely, because it decides which one you want.

theZoo is a Git repository. Its unit of distribution is a commit, and its index is a SQLite file you clone along with the samples. That makes it reproducible and offline-friendly: once cloned, you have the index and the payloads locally, with hashes stored beside each archive. Nothing about it requires a network call at analysis time.

MalwareBazaar, VirusShare and MalShare are feeds. They distribute samples over HTTP, with their own query interfaces and their own retention policies. You do not clone them, and you do not get a local index file you can diff. VirusTotal is a different thing again: it is primarily an analysis and reputation service, and theZoo's own changelog records that integrating VirusTotal upload and indexing was not possible due to that service's restrictions. That is a useful data point, because it shows the project tried to bridge the two models and could not.

So the trade-off is local reproducibility against freshness and scale. theZoo gives you a fixed, hash-verified collection you can archive and cite. The feeds give you volume and recency but no local snapshot. If your work is teaching, controlled lab exercises or repeatable research against a known sample set, the Git model fits. If you need the sample that appeared this morning, a feed is the right tool and theZoo is not.

Maintenance, Upgrades and Licence Cost

Upgrade cost here is low in the conventional sense and high in an unusual one. There is no package to upgrade, so you update by pulling the repository. That pulls new samples as well as new code, which means every update changes the contents of your malware store. If you keep theZoo inside a VM snapshot, plan for the clone to grow and for the pull to be the moment you re-verify hashes.

Because the last release is v0.60 from 2014, there is no semantic version to track and no release notes for the years of commits that followed. You cannot tell from version numbers whether a given change affects the CLI, the database format or only the sample collection. The changelog entries in the README stop at 0.60 as well.

On licensing, the README places the program under GPL v3, with the standard warranty disclaimer, and points to LICENSE.md for more. It then states that the licence does not apply to the malicious samples, including source code, reversed or otherwise. So the code you run is GPL, and the material you analyse is not covered by that grant. How that interacts with your internal redistribution or retention rules is a question for your legal team; the repository does not answer it.

Editorial conclusion

theZoo suits malware analysts and students who work inside an isolated VM and understand that every archive is live and dangerous. It does not suit anyone who wants to run samples on a daily-use machine, and it does not suit teams looking for a maintained sample feed with an API, because the README describes a CLI over a local SQLite database and the newest tagged release is v0.60 from 2014. Before adopting it, verify the repository layout under malware/Binaries and malware/Source, confirm that conf/maldb.db is present, and read the EULA in conf plus the licence note in LICENSE.md, since the GPL section explicitly does not cover the malicious samples.

Frequently asked questions

What are some good malware samples for analysis?

theZoo's answer is its own collection: samples and source code gathered in one repository so analysts can retrieve them in an organized fashion. The README splits them into malware/Binaries and malware/Source, with source further divided into Original and Reversed, and it declines to promise that the Original files are truly original.

How do I install theZoo?

Clone the repository, enter the directory, and run pip install --user -r requirements.txt. The README then says to start the console with python theZoo.py.

Are theZoo samples safe to run?

No. The README states that these are live and dangerous malware and that they come encrypted and locked for a reason. It recommends running them only in a VM with no internet connection, or an internal virtual network if necessary, and without guest additions or equivalents, because some samples are worms that will try to spread.

What files make up each malware entry in theZoo?

Each directory contains four files: the malware in an encrypted ZIP archive, a SHA256 sum of that archive, an MD5 sum of it, and a password file for the archive. The README describes this structure directly.

How do I submit a sample to theZoo?

Run python prep_file.py file_tosubmit.exe, which creates a directory for the sample. You then submit that directory together with changes to conf/maldb.db so the project knows which malware it is.

Does the GPL licence cover theZoo's malware samples?

No. The README states that the licence section does not apply to any of the malicious samples in the repository, including samples and source code, reversed or otherwise. The GPL v3 text covers the program itself.

Official sources

  1. Issues
  2. Project website
  3. README
  4. Releases
  5. ytisf/theZoo on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/ytisf-thezoo.svg)](https://hysenlabs.com/projects/ytisf-thezoo)