
Virustotal और अन्य सेवाओं के लिए ऑनलाइन हैश जाँचकर्ता
_________ _ _ ______ _____ ______
| | | | | \ | | | | | | \ \ | | | | \ \ /.)
| | | | | | | | | | | | | | | | | | | | /)\|
|_| |_| |_| \_|__|_| |_| |_| _|_|_ |_| |_| // /
/'" "
वायरसटोटल और अन्य सेवाओं के लिए ऑनलाइन हैश जाँचकर्ता
फ्लोरियन रोथ
मुनिन एक ऑनलाइन हैश जाँचकर्ता उपयोगिता है जो विभिन्न ऑनलाइन स्रोतों से मूल्यवान जानकारी प्राप्त करता है
मुनिन का वर्तमान संस्करण निम्नलिखित सेवाओं से पूछताछ करता है:
डिफ़ॉल्ट मोड - फ़ाइल से हैश पढ़ें

usage: munin.py [-h] [-f path] [--vh search-string]
[--vhrule search-string] [-o output] [--vtwaitquota]
[--vtminav min-matches] [--limit hash-limit]
[--vhmaxage days] [-c cache-db] [-i ini-file]
[-s sample-folder] [--comment] [-p vt-comment-prefix]
[--download] [-d download_path] [--nocache] [--nocsv]
[--verifycert] [--sort] [--web] [-w port] [--cli]
[--rescan] [--debug]
Online Hash Checker
optional arguments:
-h, --help show this help message and exit
-f path File to process (hash line by line OR csv with hash
in each line - auto-detects position and comment)
--vh search-string Query Valhalla for hashes by keyword, tags, YARA
rule name, Mitre ATT&CK software (e.g. S0154),
technique (e.g. T1023) or threat group (e.g. G0049)
--vhrule search-string
Query Valhalla for hashes via rules by keyword,
tags, YARA rule name, Mitre ATT&CK software (e.g.
S0154), technique (e.g. T1023) or threat group
(e.g. G0049)
-o output Output file for results (CSV)
--vtwaitquota Do not continue if VT quota is exceeded but wait
for the next day
--vtminav min-matches
Minimum number of AV matches to query hash info
from VT"
--limit hash-limit Exit after handling this much new hashes in batch
mode (cache ignored).
--vhmaxage days Maximum age of sample on Valhalla to process
-c cache-db Name of the cache database file (default: vt-hash-
db.json)
-i ini-file Name of the ini file that holds the API keys
-s sample-folder Folder with samples to process
--comment Posts a comment for the analysed hash which
contains the comment from the log line
-p vt-comment-prefix Virustotal comment prefix
--download Enables Sample Download from Hybrid Analysis.
SHA256 of sample needed.
-d download_path Output Path for Sample Download from Hybrid
Analysis. Folder must exist
--nocache Do not use cache database file
--nocsv Do not write a CSV with the results
--verifycert Verify SSL/TLS certificates
--sort Sort the input lines
--web Run Munin as web service
-w port Web service port
--cli Run Munin in command line interface mode
--rescan Trigger a rescan of each analyzed file
--debug Debug output
pip3 install -r requirements.txt (macOS पर --user जोड़ें)cp munin.ini my.ini (सहायता के लिए अनुभाग API कुंजियाँ प्राप्त करें देखें)python munin.py -i my.ini -f munin-demo.txtVirustotal Retrohunt परिणाम को संसाधित करें और जाँच करने से पहले पंक्तियों को क्रमबद्ध करें ताकि मिलान किए गए हस्ताक्षर ब्लॉक में जाँचे जा सकें
python3 munin.py -i my.ini -f ~/Downloads/retro_hunt
नमूनों वाली निर्देशिका को संसाधित करें और उनके हैश ऑनलाइन जाँचें
python3 munin.py -i my.ini -s ~/malware/case34
कमांड लाइन इंटरफ़ेस मोड का उपयोग करें (v0.14 में नया)
python3 munin.py -i my.ini
प्रोफ़ाइल > मेरी API कुंजी जाँचेंयहाँ पंजीकरण करें https://malshare.com/register.php
यहाँ पंजीकरण करें https://bazaar.abuse.ch/। आप अपनी API कुंजी अपने खाता अवलोकन में पा सकते हैं।
प्रोफ़ाइल > API कुंजी जाँचें