Hackers of India

Malware clustering using unsupervised ML : CalMal

By  Himanshu Anand  on 19 Apr 2024 @ Blackhat : Arsenal

This Tool Demo covers following tools where the speaker has contributed or authored
CALMAL

Abstract

CalMal uses unsupervised machine learning for categorising and clustering of malware based upon the behaviour of the malware. Currently CalMal uses data from VirusTotal . It provides following functionalities :

  1. Cluster different malware family.
  2. Identifying similarities with any APT malware
  3. Identify new samples.
  4. Providing visual clustering It can easily be extended to use data from any sandbox.