
Virustotal 및 기타 서비스를 위한 온라인 해시 검사기
_________ _ _ ______ _____ ______
| | | | | \ | | | | | | \ \ | | | | \ \ /.)
| | | | | | | | | | | | | | | | | | | | /)\|
|_| |_| |_| \_|__|_| |_| |_| _|_|_ |_| |_| // /
/'" "
Online Hash Checker for Virustotal and Other Services
Florian Roth
Munin은 다양한 온라인 소스에서 유용한 정보를 검색하는 온라인 해시 검사 유틸리티입니다.
현재 버전의 Munin은 다음 서비스를 조회합니다:
기본 모드 - 파일에서 해시 읽기

usage: munin.py [-h] [-f path] [--vh search-string]
[--vhrule search-string] [-o output] [--vtwaitquota]
[--vtminav min-matches] [--limit hash-limit]
[--vhmaxage days] [-c cache-db] [-i ini-file]
[-s sample-folder] [--comment] [-p vt-comment-prefix]
[--download] [-d download_path] [--nocache] [--nocsv]
[--verifycert] [--sort] [--web] [-w port] [--cli]
[--rescan] [--debug]
Online Hash Checker
optional arguments:
-h, --help show this help message and exit
-f path File to process (hash line by line OR csv with hash
in each line - auto-detects position and comment)
--vh search-string Query Valhalla for hashes by keyword, tags, YARA
rule name, Mitre ATT&CK software (e.g. S0154),
technique (e.g. T1023) or threat group (e.g. G0049)
--vhrule search-string
Query Valhalla for hashes via rules by keyword,
tags, YARA rule name, Mitre ATT&CK software (e.g.
S0154), technique (e.g. T1023) or threat group
(e.g. G0049)
-o output Output file for results (CSV)
--vtwaitquota Do not continue if VT quota is exceeded but wait
for the next day
--vtminav min-matches
Minimum number of AV matches to query hash info
from VT"
--limit hash-limit Exit after handling this much new hashes in batch
mode (cache ignored).
--vhmaxage days Maximum age of sample on Valhalla to process
-c cache-db Name of the cache database file (default: vt-hash-
db.json)
-i ini-file Name of the ini file that holds the API keys
-s sample-folder Folder with samples to process
--comment Posts a comment for the analysed hash which
contains the comment from the log line
-p vt-comment-prefix Virustotal comment prefix
--download Enables Sample Download from Hybrid Analysis.
SHA256 of sample needed.
-d download_path Output Path for Sample Download from Hybrid
Analysis. Folder must exist
--nocache Do not use cache database file
--nocsv Do not write a CSV with the results
--verifycert Verify SSL/TLS certificates
--sort Sort the input lines
--web Run Munin as web service
-w port Web service port
--cli Run Munin in command line interface mode
--rescan Trigger a rescan of each analyzed file
--debug Debug output
pip3 install -r requirements.txt (macOS에서는 --user 추가)cp munin.ini my.ini (도움말은 API 키 얻기 섹션 참조)python munin.py -i my.ini -f munin-demo.txtVirustotal Retrohunt 결과를 처리하기 전에 줄을 정렬하여 일치하는 시그니처가 블록 단위로 확인되도록 합니다
python3 munin.py -i my.ini -f ~/Downloads/retro_hunt
샘플이 포함된 디렉터리를 처리하고 해시를 온라인에서 확인합니다
python3 munin.py -i my.ini -s ~/malware/case34
명령줄 인터페이스 모드 사용 (v0.14 신규)
python3 munin.py -i my.ini
프로필 > 내 API 키에서 공개 API 키 확인여기에서 등록: https://malshare.com/register.php
여기에서 등록: https://bazaar.abuse.ch/. 그런 다음 계정 개요에서 API 키를 찾을 수 있습니다.
프로필 > API 키 확인Authkey 값을 API 키로 사용현재 고객 또는 초청 연구원 전용
https://valhalla.nextron-systems.com/
Hashlookup CIRCL의 인스턴스는 무료로 제공되며 최선의 노력을 기준으로 제공됩니다.
--cli로 munin을 시작하고 지시를 따릅니다.
예:
python3 munin.py -i my.ini --cli
해시 값이 포함된 내용을 붙여넣고 CTRL+D를 눌러 입력을 완료합니다. 마지막 줄은 끝에 줄 바꿈이 필요합니다.
기본적으로 파일 이름에 현재 날짜가 포함된 CSV 파일이 생성됩니다.

--web으로 munin을 시작하고 선택적으로 포트 -w port를 지정합니다.
예:
python3 munin.py -i my.ini --web -w 8080
웹 서비스는 다음 URL 구성표에 문자열을 기다립니다.
http://server:port/<string>
문자열은 줄 바꿈이 없는 임의의 문자열일 수 있습니다. 예:
Emotet:1585ad28f7d1e0ca696e6c6c2f1d008a
ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa;IOC1
dc9b5e8aa6ec86db8af0a7aa897ca61db3e5f3d2e0942e319074db1aaccfdc83