Objective: Enrichment of threat sharing database for providing Behaviour Analytics through malware analysis and extraction of Indicators and Behaviour.
Implementation:
-
files.json Extraction hashes are done from Malpedia and Vx-underground. This code uses the burp suite proxy server for analysing the enormous data without causing overload. Also the quota per day analysis in VirusTotal is limited to 500. So, it prevents data limit from going over this limit.
-
get_vt_collection Gets the hashes from vx-underground. Handles the collection of information from VirusTotal APIs for the hashes fed. If the sample is analysed in VT then it provides the details of the sample in JSON format.
-
extract_indicators.py Performs analysis of the complex data in the JSON file and processes the data to extract relevant indicators
-
stix_bundle.py Normalization of the samples and collected in STIX format
-
attack_pattern.py Check the similarity between the attack patterns
-
misp_analysis.py Data analysis in MISP platform is performed.
-
Example of the JSON file extracted and used are Sample_vt_collection and Sample_vt_hash
