-
Notifications
You must be signed in to change notification settings - Fork 23
/
Copy pathread_avclass_report.py
53 lines (36 loc) · 1.35 KB
/
read_avclass_report.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
import json, sys, re, subprocess, os
import requests
def run_avclass (vt_key, sha256):
#Download VT report
params = {'apikey': vt_key, 'resource':sha256}
headers = {
"Accept-Encoding": "gzip, deflate",
"User-Agent" : "Retrieving file scan reports"
}
response = requests.get('https://www.virustotal.com/vtapi/v2/file/report', params=params, headers=headers)
json_response = response.json()
file_name = params['resource']+".json"
if json_response['response_code']==0:
return ({"flag":False, "data":"It does not exist in VirusTotal"})
with open (file_name, 'w') as f:
json.dump(json_response, f)
vt_url = "https://www.virustotal.com/#/file/" + sha256 + "/detection"
#run AVClass
cmd = ["python3 ./avclassplusplus/avclass_labeler.py", "-vt", file_name, "-v"]
subprocess.call(cmd)
#read AVClass results
with open(sha256 +".verbose", 'r') as f:
read_data = f.read()
r = re.compile('(%s.*%s)' % ("\[", "\]"))
m = r.search(read_data)
if m != None:
fam = m.group(0)
fam= (eval(fam))
fam_json=[]
for column in fam:
fam_json.append({"family_name":column[0], "count":column[1]})
else:
fam_json=[]
os.remove(sha256+".json")
os.remove(sha256+".verbose")
return ({"flag":True, "data":fam_json})