
Vthunting هو برنامج نصي صغير يُستخدم لإنشاء تقرير عن الصيد على Virus Total وإرساله عبر البريد الإلكتروني أو Slack أو Telegram.
VThunting متوفر الآن على VirusTotal.
Virus Total Hunting هي أداة صغيرة تعتمد على إصدار VT API 3 لتشغيل تقرير يومي أو أسبوعي أو شهري حول صيد البرامج الضارة. يمكن إرسال التقرير عبر البريد الإلكتروني أو قناة Slack أو Telegram. يمكن أيضًا استخدام الأداة في CLI للحصول على تقرير في أي وقت. العدد الافتراضي للنتائج هو 10 ولكن يمكن زيادته أو تقليله في جزء الإعدادات. تعمل هذه الأداة فقط مع Virus Total Intelligence API.
المقتطف أدناه هو مثال لتقرير مُنشأ.
__ _______ _ _ _ _
\ \ / /_ _| | | |_ _ _ __ | |_(_)_ __ __ _
\ \ / / | | | |_| | | | | '_ \| __| | '_ \ / _` |
\ V / | | | _ | |_| | | | | |_| | | | | (_| |
\_/ |_| |_| |_|\__,_|_| |_|\__|_|_| |_|\__, |
|___/
McAfee ATR | Thomas Roccia | @fr0gger_
Get latest hunting notification from VirusTotal
Latest report from 2018-12-24 10:20:30.158831
-------------------------------------------------------------------------------------
Rule name: FancyBear_ComputraceAgent
Match date: 2018-12-24 17:38:17
SHA256: f5157e5b8afe1f79f29c947449477d13ede3d7341699256e62966474a7ee1eb5
Tags: [apt28, fancybear_computraceagent]
-------------------------------------------------------------------------------------
Rule name: Winexe_RemoteExecution
Match date: 2018-12-24 15:01:15
SHA256: 1e194647c05b0068c31cd443b5bcacc2dd41799e5d21a40e0c58adbad01c28c6
Tags: [winexe_remoteexecution, apt28]
-------------------------------------------------------------------------------------
Rule name: hatman_compiled_python: hatman
Match date: 2018-12-24 00:28:21
SHA256: 14c64fc93ae68f01989db992bf8ee47ffd33edf66223b84f3fae52f9a843a03f
Tags: [triton, hatman, hatman_compiled_python]
-------------------------------------------------------------------------------------
Rule name: Stuxnet_unpacked
Match date: 2018-12-24 15:00:00
SHA256: 86b05279bf4930ffc0c00e4fd22c8ab9e964e8d45d39bfca42e129b95dc33481
Tags: [stuxnet, stuxnet_unpacked]
-------------------------------------------------------------------------------------
Rule name: Stuxnet
Match date: 2018-12-24 14:59:59
SHA256: 86b05279bf4930ffc0c00e4fd22c8ab9e964e8d45d39bfca42e129b95dc33481
Tags: [stuxnet]
-------------------------------------------------------------------------------------
[truncated]
ما عليك سوى تنزيل البرنامج النصي:
git clone https://github.com/fr0gger/vthunting
ثم قم بتكوين جزء الإعدادات باستخدام مفاتيح API والمعلومات الخاصة بك:
# Virus Total API
VTAPI = "<API_KEY>"
number_of_result = "" # 10 by default
# Email configuration
smtp_serv = "<SMTP_SERV>"
smtp_port = ""
gmail_login = "<EMAIL>"
gmail_pass = "<APP_PASS>" # pass from APP
gmail_dest = "<DEST_EMAIL>"
# Slack Bot config
SLACK_BOT_TOKEN = "<API>"
SLACK_CHANNEL = "<SLACK_CHANNEL>"
# Telegram Bot config
TOKEN = "<API>"
chat_id = "<CHAT_ID>"
# Microsoft Teams Bot config
TEAMS_CHANNEL_WEBHOOK = ""
بمجرد أن يصبح الإعداد جاهزًا، يمكنك تشغيل الملف باستخدام:
python vthunting.py --help
usage: vthunting.py [OPTION]
-h, --help Print this help
-r, --report Print the VT hunting report
-s, --slack_report Send the report to a Slack channel
-e, --email_report Send the report by email
-t, --telegram_report Send the report to Telegram
-m, --teams_report Send the report to Microsoft Teams
-j, --json Get full JSON report
تحتاج أولاً إلى تثبيت المتطلبات:
pip install -r requirements.txt
احصل على مفتاح API الخاص بك من Virus Total. https://developers.virustotal.com/v3.0/reference
لإنشاء تطبيق، يمكنك العثور على الوثائق هنا: https://support.google.com/accounts/answer/185833
لتوليد رمز مميز، تحتاج إلى الانتقال إلى هنا واتباع الخطوات: https://api.slack.com/custom-integrations/legacy-tokens
للحصول على رمز مميز، تحتاج إلى إنشاء بوت Telegram عن طريق التحدث إلى @BotFather، وسيساعدك في تكوين البوت والحصول على الرمز المميز الخاص بك. بمجرد حصولك على الرمز المميز، قم بزيارة https://api.telegram.org/bot<YOUR_TOKEN>/getUpdates للحصول على معرف القناة.
أضف موصل webhook إلى قناة Microsoft Teams التي ترغب في تلقي التقارير عليها. https://docs.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/connectors-using#setting-up-a-custom-incoming-webhook
إذا كنت ترغب في الوصول إلى هذا البرنامج النصي من أي مكان، يمكنك نسخه بدون الامتداد إلى:
cp vthunting.py /usr/local/bin/vthunting
يمكنك استخدام crontab لتشغيل البرنامج النصي وتلقي التقرير بشكل دوري.
crontab -e
فيما يلي مثال لتلقي التقرير كل يوم في الساعة 10:15 صباحًا.
# Example of job definition:
# .---------------- minute (0 - 59)
# | .------------- hour (0 - 23)
# | | .---------- day of month (1 - 31)
# | | | .------- month (1 - 12) OR jan,feb,mar,apr ...
# | | | | .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat
# | | | | |
# * * * * * user command to be executed
15 10 * * * /usr/local/bin/vthunting -r -t -e -s >> vthunt.log
قم باستنساخ المستودع وقم بتكوين API الخاص بك لإعداد التقارير في البرنامج النصي. أضف VirusTotal API الخاص بك في ملف Dockerfile.
ثم قم بتشغيل الأوامر التالية:
# Build the container
docker build -t vthunting:latest .
# run the script:
docker run -t vthunting -r
هذا المشروع مرخص بموجب رخصة MIT - راجع ملف LICENSE.md للحصول على التفاصيل.