Python ve VirusTotal ile SOC İş Akışını Otomatikleştirme

import requests
import json

API_KEY= "YOUR_API_KEY"

IP_ADDR = ["147.78.47.250",
           "94.102.61.28",                               
            "94.102.61.6",
            "8.8.8.8"]

for x in IP_ADDR:

    res = f"https://www.virustotal.com/api/v3/ip_addresses/{x}"
    headers = {"accept": "application/json",
               "x-apikey":API_KEY}

    response = requests.get(res, headers=headers)
    response_data = json.loads(response.text)

    # Check if the IP address is malicious
    if "data" in response_data and "attributes" in response_data["data"] and "last_analysis_stats" in response_data["data"]["attributes"] and response_data["data"]["attributes"]["last_analysis_stats"]["malicious"] > 0:
        print(f"The IP address {x} is malicious with a score of {response_data['data']['attributes']['last_analysis_stats']['malicious']}")
    else:
        print(f"The IP address {x} is not malicious")
#Output
The IP address 147.78.47.250 is malicious with a score of 11
The IP address 94.102.61.28 is malicious with a score of 8
The IP address 94.102.61.6 is malicious with a score of 4
The IP address 8.8.8.8 is malicious with a score of 2

import requests
import json

# Replace YOUR_API_KEY with your actual API key
API_KEY = "YOUR_API_KEY"

# Domains to look up
domains = [
"zn.squeamarundo.com",
"fr.talerselrage.com",
"gw.dummiedkhodja.com",
"cpanel.genixcares.com",
"as.mailsyntec.com",
"replacestuntissue.com",
"7B85A160-A4D9-43BD-8B32-295B3F23E62E.server-77.beshopbooks.com,"
"tl.corkeextatic.com",
"so.ohoycaline.com",
"erdeallyighab.com",
"ih.ijorecepous.com",
"trendvidaa.com",
"version.ffmax.purplevioleto.com",
"rg.trotletekphore.com",
"server13.mydomelem.com",
"oxodigital.tv",
"serhatyolacan.com",
"dc.forkedtrizoic.com",
"gf.tummingfass.com",
"jz.dunnedemicant.com",
"topservicepool.com"]

for x in domains:
    url = "https://www.virustotal.com/api/v3/domains/{}".format(x)

    headers = {
        "x-apikey": API_KEY,
        "Accept": "application/json"
    }

    params = {
        "include": "last_analysis_stats"
    }
    response = requests.get(url, headers=headers, params=params)
    response_data = json.loads(response.text)
    try:
        if "last_analysis_stats" in response_data["data"]["attributes"] and response_data["data"]["attributes"]["last_analysis_stats"]["malicious"] > 0:
            malicious_score = response_data["data"]["attributes"]["last_analysis_stats"]["malicious"]
            print(f"The domain {x} has a malicious score of {malicious_score}.")
        else:
            print(f"The domain {x} is not detected as malicious by VirusTotal.")    
    except KeyError:
        print("The domain {} not found by VirusTotal.".format(x))
#Output

The domain zn.squeamarundo.com is not detected as malicious by VirusTotal.
The domain fr.talerselrage.com is not detected as malicious by VirusTotal.
The domain gw.dummiedkhodja.com is not detected as malicious by VirusTotal.
The domain cpanel.genixcares.com is not detected as malicious by VirusTotal.
The domain as.mailsyntec.com is not detected as malicious by VirusTotal.
The domain replacestuntissue.com has a malicious score of 6.
The domain 7B85A160-A4D9-43BD-8B32-295B3F23E62E.server-77.beshopbooks.com,tl.corkeextatic.com not found by VirusTotal.
The domain so.ohoycaline.com is not detected as malicious by VirusTotal.
The domain erdeallyighab.com is not detected as malicious by VirusTotal.
The domain ih.ijorecepous.com is not detected as malicious by VirusTotal

Suggested posts

O Tehdit Arşivi: Cilt 7 Black Basta

O Tehdit Arşivi: Cilt 7 Black Basta

Günümüzün birbirine bağlı dünyasında, siber saldırı tehdidi her zamankinden daha yaygın. Siber suçlular ve ulus-devlet aktörleri sürekli olarak güvenlik açıklarından yararlanmaya ve değerli verileri çalmaya çalışarak her büyüklükteki kuruluş için önemli bir risk oluşturuyor.

Langchain kullanarak ChatGPT eklentilerini ücretsiz çalıştırma

Langchain kullanarak ChatGPT eklentilerini ücretsiz çalıştırma

Tarayıcı, Kod Tercüman vb. tüm yeni güçlü ChatGPT eklentilerini duymuş olmalısınız. Ancak bir sorun var, eklentilere erişim bir bekleme listesiyle sınırlıdır ve bu nedenle birçoğunun buna erişimi yoktur.

Related posts

Bekleme mevsiminizde yapabilecekleriniz (teknikte ilk işinizi yapmak için beklerken)

Bekleme mevsiminizde yapabilecekleriniz (teknikte ilk işinizi yapmak için beklerken)

Tek başınıza yapmaya çalışırsanız, yeni bir kariyere geçmek son derece zor olabilir. Sizinle aynı öğrenme düzeyinde olan, benzer hedefleri, kararlılığı ve güdüyü paylaşan sorumlu ortaklar bulmak önemlidir.

Sadece Bir Telefon Numarasıyla Herkesi Takip Edin | OSINT Soruşturması

Sadece Bir Telefon Numarasıyla Herkesi Takip Edin | OSINT Soruşturması

Bir OSINT Araştırmacısı, CTF Oyuncusu veya yalnızca istenmeyen aramalar alan biri olabilirsiniz. Bir reklamda gördüğünüz numarayı doğrulamaya çalışan biri.

Tasarımda iki yıl - İyi, kötü ve çirkin…

Tasarımda iki yıl - İyi, kötü ve çirkin…

"Hey Siri, Olivia Dean'in Me Dive oyununu çal." Nijerya, Akure'deki Future Academy Africa'da stajıma başladığımda Mayıs 2021'di.

İşyeri Devrimi: En İyi Uzmanlar Hibrit ve Uzaktan Çalışmayı Tartışıyor

İşyeri Devrimi: En İyi Uzmanlar Hibrit ve Uzaktan Çalışmayı Tartışıyor

Günümüzün hızla gelişen iş ortamında, hibrit ve uzaktan çalışma kavramı benzeri görülmemiş bir ivme kazandı. Şirketler, çalışanlarının değişen ihtiyaç ve beklentilerine uyum sağlamaya devam ederken, çeşitli alanlardan uzmanlar bu dönüştürücü çalışma biçiminin faydalarını, zorluklarını ve geleceğini tartışmak için bir araya geldi.