YALIH YALIH (Yet Another Low Interaction Honeyclient) is a low Interaction Client honeypot designed to identify malicious websites using techniques such as signature detection, anomaly detection, and pattern matching.
* Collection of suspicious URLs from three different malicious website databases.
* URL collection via the Bing API.
* Gathering suspicious URLs from your inbox and SPAM folder using the POP3 and IMAP protocols.
* Extraction, de-obfuscation, and de-minification of JavaScript scripts embedded in websites.
* Handling referrer emulation and redirection.
* Management of cookies and session data.
* Emulation of browsers, browser agents, and operating systems.
* Proxy capabilities to detect geo-location and/or IP cloaking attacks.
* Signature detection utilizing the ClamAV antivirus database.
* Anomaly and pattern matching detection through Yara (http://plusvic.github.io/yara/).
* Automated generation of Yara signatures.
=================================== Easy Installation and Documentation ====================================
Authors/Contributors:
* Victoria University of Wellington
* Masood Mansoori
-
[email protected]
* Singapore Polytechnic
* Lai Qi Wei
-
[email protected]
Requirements: