FCTI

Download 15
Last updated May 15, 2022

fcti-malware-hashes

Fetch malware hashes from FCTI

fcti-malware-hashes [proxy=PROXY] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss]
proxy=PROXY
URL of the proxy server
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.

Output Fields

FieldTypeNameDescription
_timeDateTime
md5StringMD5
sha1StringSHA1
sha256StringSHA256
file_nameStringFile name
versionStringFile versione.g. 1.0.0.0
file_sizeLongFile size
file_typeStringFile typee.g. PE
importanceStringSeveritye.g. H (High), M (Medium), L (Low)
confirm_ynStringConfirm requeste.g. Y, N
confirm_statusStringConfirm status
static_reportStringStatic reportStatic file analysis report
dynamic_reportStringDynamic reportDynamic file analysis report
packerStringPacker
descriptionStringDescription
detect_enginesIntegerDetect enginesNumber of antivirus engines that have diagnosed the file as malware
total_enginesIntegerTotal enginesNumber of the antivirus engines
av_resultListAV result
sign_nameStringSigner
sign_publisherStringIssuere.g. Symantec Class 3 Extended Validation Code Signing CA - G2
sign_timeDateSign time
is_signedBoolIs signed
is_valid_signBoolIs valid sign
countryStringCountry
pdb_pathStringPDB path
copyrightStringCopyright
organizationStringOrganization
writerStringAuthor
stix_idStringSTIX ID
shared_scopeStringShared scopee.g. ALL, FSI, BANK, INVEST, INSURANCE, NONBANK, CUSTOM
dnsListDNS flowsElements with dnsHash, request, answers properties
ircListIRC flowsElements with type, command, params properties
icmpListICMP flowsElements with type, src, dst properties
smtpListSMTP flowsElements with src, raw properties
tcpListTCP flowsElements with src, sport, dst, dport properties
udpListUDP flowsElements with src, sport, dst, dport properties