Skip to content

malice-plugins/team-cymru

Repository files navigation

IPSW Logo

team-cymru

Malice TeamCymru - Malware Hash Registry Plugin


This repository contains a Dockerfile of TeamCymru's Malware Hash Registry for Docker's trusted build published to the public DockerHub.

Dependencies

Installation

  1. Install Docker.
  2. Download trusted build from public DockerHub: docker pull malice/team-cymru

Usage

docker run --rm malice/team-cymru (MD5|SHA1)
Usage: team-cymru [OPTIONS] COMMAND [arg...]

Malice TeamCymru - Malware Hash Registry Plugin

Version: v0.1.0, BuildTime: 20160228

Author:
  blacktop - <https://github.com/blacktop>

Options:
  --post, -p	POST results to Malice webhook [$MALICE_ENDPOINT]
  --proxy, -x	proxy settings for Malice webhook endpoint [$MALICE_PROXY]
  --table, -t	output as Markdown table
  --help, -h	show help
  --version, -v	print the version

Commands:
  help	Shows a list of commands or help for one command

Run 'team-cymru COMMAND --help' for more information on a command.

This will output to stdout and POST to malice results API webhook endpoint.

Sample Output JSON:

{
  "team-cymru": {
    "found": true,
    "lastseen": "2017-01-12",
    "detection": "86%"
  }
}

Sample Output STDOUT (Markdown Table):


TeamCymru

Found Detection LastSeen
true 86% 2017-01-12

To Run on OSX

$ brew install caskroom/cask/brew-cask
$ brew cask install virtualbox
$ brew install docker
$ brew install docker-machine
$ docker-machine create --driver virtualbox malice
$ eval $(docker-machine env malice)

Documentation

Issues

Find a bug? Want more features? Find something missing in the documentation? Let me know! Please don't hesitate to file an issue and I'll get right on it.

Credits

License

MIT Copyright (c) 2016 blacktop