
Vthunting ist ein winziges Skript, das verwendet wird, um einen Bericht über VirusTotal-Jagd zu erstellen und ihn per E-Mail, Slack oder Telegram zu senden.
VThunting ist jetzt auf VirusTotal vorgestellt.
Virus Total Hunting ist ein kleines Werkzeug, das auf der VT API Version 3 basiert, um tägliche, wöchentliche oder monatliche Berichte über die Malware-Jagd zu erstellen. Der Bericht kann per E-Mail, Slack-Kanal oder Telegram versendet werden. Das Tool kann auch in der CLI verwendet werden, um jederzeit einen Bericht zu erhalten. Die Standardanzahl der Ergebnisse ist 10, kann aber im Konfigurationsteil erhöht oder verringert werden. Dieses Tool funktioniert nur mit einer Virus Total Intelligence API.
Der folgende Auszug ist ein Beispiel für einen generierten Bericht.
__ _______ _ _ _ _
\ \ / /_ _| | | | |_ _ _ __ | |_(_)_ __ __ _
\ \ / / | | | |_| | | | | '_ \| __| | '_ \ / _` |
\ V / | | | _ | |_| | | | | |_| | | | | (_| |
\_/ |_| |_| |_|\__,_|_| |_|\__|_|_| |_|\__, |
|___/
McAfee ATR | Thomas Roccia | @fr0gger_
Erhalten Sie die neuesten Jagdbenachrichtigungen von VirusTotal
Latest report from 2018-12-24 10:20:30.158831
-------------------------------------------------------------------------------------
Rule name: FancyBear_ComputraceAgent
Match date: 2018-12-24 17:38:17
SHA256: f5157e5b8afe1f79f29c947449477d13ede3d7341699256e62966474a7ee1eb5
Tags: [apt28, fancybear_computraceagent]
-------------------------------------------------------------------------------------
Rule name: Winexe_RemoteExecution
Match date: 2018-12-24 15:01:15
SHA256: 1e194647c05b0068c31cd443b5bcacc2dd41799e5d21a40e0c58adbad01c28c6
Tags: [winexe_remoteexecution, apt28]
-------------------------------------------------------------------------------------
Rule name: hatman_compiled_python: hatman
Match date: 2018-12-24 00:28:21
SHA256: 14c64fc93ae68f01989db992bf8ee47ffd33edf66223b84f3fae52f9a843a03f
Tags: [triton, hatman, hatman_compiled_python]
-------------------------------------------------------------------------------------
Rule name: Stuxnet_unpacked
Match date: 2018-12-24 15:00:00
SHA256: 86b05279bf4930ffc0c00e4fd22c8ab9e964e8d45d39bfca42e129b95dc33481
Tags: [stuxnet, stuxnet_unpacked]
-------------------------------------------------------------------------------------
Rule name: Stuxnet
Match date: 2018-12-24 14:59:59
SHA256: 86b05279bf4930ffc0c00e4fd22c8ab9e964e8d45d39bfca42e129b95dc33481
Tags: [stuxnet]
-------------------------------------------------------------------------------------
[truncated]
Laden Sie einfach das Skript herunter:
git clone https://github.com/fr0gger/vthunting
Konfigurieren Sie dann den Konfigurationsteil mit Ihren API-Schlüsseln und Informationen:
# Virus Total API
VTAPI = "<API_KEY>"
number_of_result = "" # 10 by default
# Email configuration
smtp_serv = "<SMTP_SERV>"
smtp_port = ""
gmail_login = "<EMAIL>"
gmail_pass = "<APP_PASS>" # pass from APP
gmail_dest = "<DEST_EMAIL>"
# Slack Bot config
SLACK_BOT_TOKEN = "<API>"
SLACK_CHANNEL = "<SLACK_CHANNEL>"
# Telegram Bot config
TOKEN = "<API>"
chat_id = "<CHAT_ID>"
# Microsoft Teams Bot config
TEAMS_CHANNEL_WEBHOOK = ""
Sobald die Konfiguration bereit ist, können Sie die Datei ausführen mit:
python vthunting.py --help
usage: vthunting.py [OPTION]
-h, --help Print this help
-r, --report Print the VT hunting report
-s, --slack_report Send the report to a Slack channel
-e, --email_report Send the report by email
-t, --telegram_report Send the report to Telegram
-m, --teams_report Send the report to Microsoft Teams
-j, --json Get full JSON report
Sie müssen zunächst die Abhängigkeiten installieren:
pip install -r requirements.txt
Holen Sie sich Ihren API-Schlüssel von Virus Total. https://developers.virustotal.com/v3.0/reference
Zum Erstellen einer App finden Sie die Dokumentation hier: https://support.google.com/accounts/answer/185833
Um ein Token zu generieren, müssen Sie hierher gehen und die Schritte befolgen: https://api.slack.com/custom-integrations/legacy-tokens
Um ein Token zu erhalten, müssen Sie einen Telegram-Bot erstellen, indem Sie mit @BotFather sprechen. Er hilft Ihnen, Ihren Bot zu konfigurieren und Ihr Token zu erhalten. Sobald Sie Ihr Token haben, besuchen Sie https://api.telegram.org/bot<YOUR_TOKEN>/getUpdates, um die Kanal-ID zu erhalten.
Fügen Sie einen Webhook-Connector zum Microsoft Teams-Kanal hinzu, an den Sie die Berichte senden möchten. https://docs.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/connectors-using#setting-up-a-custom-incoming-webhook
Wenn Sie von überall auf dieses Skript zugreifen möchten, können Sie es ohne Erweiterung kopieren nach:
cp vthunting.py /usr/local/bin/vthunting
Sie können Crontab verwenden, um das Skript auszuführen und regelmäßig Berichte zu erhalten.
crontab -e
Nachfolgend ein Beispiel, um den Bericht jeden Tag um 10:15 Uhr zu erhalten.
# Example of job definition:
# .---------------- minute (0 - 59)
# | .------------- hour (0 - 23)
# | | .---------- day of month (1 - 31)
# | | | .------- month (1 - 12) OR jan,feb,mar,apr ...
# | | | | .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat
# | | | | |
# * * * * * user command to be executed
15 10 * * * /usr/local/bin/vthunting -r -t -e -s >> vthunt.log
Klonen Sie das Repository und konfigurieren Sie Ihre API für die Berichterstattung im Skript. Fügen Sie Ihre VirusTotal-API in der dockerfile hinzu.
Führen Sie dann die folgenden Befehle aus:
# Build the container
docker build -t vthunting:latest .
# run the script:
docker run -t vthunting -r
Dieses Projekt ist unter der MIT-Lizenz lizenziert - siehe die Datei LICENSE.md für Details.