
Vthunting est un petit script utilisé pour générer un rapport sur le hunting Virus Total et l'envoyer par email, Slack ou Telegram.
VThunting est désormais présenté sur VirusTotal.
Virus Total Hunting est un petit outil basé sur l'API VT version 3 pour générer un rapport quotidien, hebdomadaire ou mensuel sur la chasse aux malwares. Le rapport peut être envoyé par e-mail, sur un canal Slack ou Telegram. L'outil peut également être utilisé en CLI pour obtenir un rapport à tout moment. Le nombre de résultats par défaut est de 10, mais il peut être augmenté ou diminué dans la partie configuration. Cet outil fonctionne uniquement avec une API Virus Total Intelligence.
L'extrait ci-dessous est un exemple de rapport généré.
__ _______ _ _ _ _
\ \ / /_ _| | | | |_ _ _ __ | |_(_)_ __ __ _
\ \ / / | | | |_| | | | | '_ \| __| | '_ \ / _` |
\ V / | | | _ | |_| | | | | |_| | | | | (_| |
\_/ |_| |_| |_|\__,_|_| |_|\__|_|_| |_|\__, |
|___/
McAfee ATR | Thomas Roccia | @fr0gger_
Get latest hunting notification from VirusTotal
Latest report from 2018-12-24 10:20:30.158831
-------------------------------------------------------------------------------------
Rule name: FancyBear_ComputraceAgent
Match date: 2018-12-24 17:38:17
SHA256: f5157e5b8afe1f79f29c947449477d13ede3d7341699256e62966474a7ee1eb5
Tags: [apt28, fancybear_computraceagent]
-------------------------------------------------------------------------------------
Rule name: Winexe_RemoteExecution
Match date: 2018-12-24 15:01:15
SHA256: 1e194647c05b0068c31cd443b5bcacc2dd41799e5d21a40e0c58adbad01c28c6
Tags: [winexe_remoteexecution, apt28]
-------------------------------------------------------------------------------------
Rule name: hatman_compiled_python: hatman
Match date: 2018-12-24 00:28:21
SHA256: 14c64fc93ae68f01989db992bf8ee47ffd33edf66223b84f3fae52f9a843a03f
Tags: [triton, hatman, hatman_compiled_python]
-------------------------------------------------------------------------------------
Rule name: Stuxnet_unpacked
Match date: 2018-12-24 15:00:00
SHA256: 86b05279bf4930ffc0c00e4fd22c8ab9e964e8d45d39bfca42e129b95dc33481
Tags: [stuxnet, stuxnet_unpacked]
-------------------------------------------------------------------------------------
Rule name: Stuxnet
Match date: 2018-12-24 14:59:59
SHA256: 86b05279bf4930ffc0c00e4fd22c8ab9e964e8d45d39bfca42e129b95dc33481
Tags: [stuxnet]
-------------------------------------------------------------------------------------
[truncated]
Téléchargez simplement le script :
git clone https://github.com/fr0gger/vthunting
Configurez ensuite la partie configuration avec vos clés API et informations :
# Virus Total API
VTAPI = "<API_KEY>"
number_of_result = "" # 10 by default
# Email configuration
smtp_serv = "<SMTP_SERV>"
smtp_port = ""
gmail_login = "<EMAIL>"
gmail_pass = "<APP_PASS>" # pass from APP
gmail_dest = "<DEST_EMAIL>"
# Slack Bot config
SLACK_BOT_TOKEN = "<API>"
SLACK_CHANNEL = "<SLACK_CHANNEL>"
# Telegram Bot config
TOKEN = "<API>"
chat_id = "<CHAT_ID>"
# Microsoft Teams Bot config
TEAMS_CHANNEL_WEBHOOK = ""
Une fois la configuration prête, vous pouvez exécuter le fichier avec :
python vthunting.py --help
usage: vthunting.py [OPTION]
-h, --help Print this help
-r, --report Print the VT hunting report
-s, --slack_report Send the report to a Slack channel
-e, --email_report Send the report by email
-t, --telegram_report Send the report to Telegram
-m, --teams_report Send the report to Microsoft Teams
-j, --json Get full JSON report
Vous devez d'abord installer les dépendances :
pip install -r requirements.txt
Obtenez votre clé API depuis Virus Total. https://developers.virustotal.com/v3.0/reference
Pour créer une application, vous pouvez trouver la documentation ici : https://support.google.com/accounts/answer/185833
Pour générer un token, rendez-vous ici et suivez les étapes : https://api.slack.com/custom-integrations/legacy-tokens
Pour obtenir un token, vous devez créer un bot Telegram en discutant avec @BotFather, qui vous aidera à configurer votre bot et à récupérer votre token. Une fois votre token obtenu, visitez https://api.telegram.org/bot<YOUR_TOKEN>/getUpdates pour obtenir l'ID du canal.
Ajoutez un connecteur webhook au canal Microsoft Teams dans lequel vous souhaitez recevoir les rapports. https://docs.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/connectors-using#setting-up-a-custom-incoming-webhook
Si vous souhaitez accéder à ce script depuis n'importe où, vous pouvez le copier sans l'extension dans :
cp vthunting.py /usr/local/bin/vthunting
Vous pouvez utiliser crontab pour exécuter le script et recevoir le rapport périodiquement.
crontab -e
Voici un exemple pour recevoir le rapport tous les jours à 10h15.
# Example of job definition:
# .---------------- minute (0 - 59)
# | .------------- hour (0 - 23)
# | | .---------- day of month (1 - 31)
# | | | .------- month (1 - 12) OR jan,feb,mar,apr ...
# | | | | .---- day of week (0 - 6) (Sunday=0 or 7) OR sun,mon,tue,wed,thu,fri,sat
# | | | | |
# * * * * * user command to be executed
15 10 * * * /usr/local/bin/vthunting -r -t -e -s >> vthunt.log
Clonez le dépôt Git et configurez votre API pour le rapport dans le script. Ajoutez votre API VirusTotal dans le Dockerfile.
Exécutez ensuite les commandes suivantes :
# Build the container
docker build -t vthunting:latest .
# run the script:
docker run -t vthunting -r
Ce projet est sous licence MIT – voir le fichier LICENSE.md pour plus de détails.