PyMISP/pymisp/tools/create_misp_object.py

94 lines
4.0 KiB
Python
Raw Normal View History

#!/usr/bin/env python
2017-07-21 18:47:10 +02:00
# -*- coding: utf-8 -*-
2019-02-06 11:31:05 +01:00
import sys
2017-08-30 12:47:32 +02:00
from . import FileObject, PEObject, ELFObject, MachOObject
from ..exceptions import MISPObjectException
import logging
logger = logging.getLogger('pymisp')
2017-07-21 18:47:10 +02:00
try:
import lief
2017-08-25 15:57:12 +02:00
from lief import Logger
Logger.disable()
2017-07-21 18:47:10 +02:00
HAS_LIEF = True
except ImportError:
HAS_LIEF = False
class FileTypeNotImplemented(MISPObjectException):
pass
2017-12-20 14:27:31 +01:00
def make_pe_objects(lief_parsed, misp_file, standalone=True, default_attributes_parameters={}):
pe_object = PEObject(parsed=lief_parsed, standalone=standalone, default_attributes_parameters=default_attributes_parameters)
misp_file.add_reference(pe_object.uuid, 'includes', 'PE indicators')
2017-07-21 18:47:10 +02:00
pe_sections = []
2017-08-25 15:57:12 +02:00
for s in pe_object.sections:
pe_sections.append(s)
2017-08-25 15:57:12 +02:00
return misp_file, pe_object, pe_sections
2017-12-20 14:27:31 +01:00
def make_elf_objects(lief_parsed, misp_file, standalone=True, default_attributes_parameters={}):
elf_object = ELFObject(parsed=lief_parsed, standalone=standalone, default_attributes_parameters=default_attributes_parameters)
misp_file.add_reference(elf_object.uuid, 'includes', 'ELF indicators')
2017-08-25 15:57:12 +02:00
elf_sections = []
for s in elf_object.sections:
elf_sections.append(s)
return misp_file, elf_object, elf_sections
2017-12-20 14:27:31 +01:00
def make_macho_objects(lief_parsed, misp_file, standalone=True, default_attributes_parameters={}):
macho_object = MachOObject(parsed=lief_parsed, standalone=standalone, default_attributes_parameters=default_attributes_parameters)
misp_file.add_reference(macho_object.uuid, 'includes', 'MachO indicators')
2017-08-25 15:57:12 +02:00
macho_sections = []
for s in macho_object.sections:
macho_sections.append(s)
return misp_file, macho_object, macho_sections
2017-07-21 18:47:10 +02:00
2017-12-20 14:27:31 +01:00
def make_binary_objects(filepath=None, pseudofile=None, filename=None, standalone=True, default_attributes_parameters={}):
2017-12-12 17:34:09 +01:00
misp_file = FileObject(filepath=filepath, pseudofile=pseudofile, filename=filename,
2017-12-20 14:27:31 +01:00
standalone=standalone, default_attributes_parameters=default_attributes_parameters)
if HAS_LIEF and (filepath or (pseudofile and filename)):
2017-08-25 17:41:58 +02:00
try:
if filepath:
lief_parsed = lief.parse(filepath=filepath)
else:
2019-02-06 11:31:05 +01:00
if sys.version_info < (3, 0):
logger.critical('Pseudofile is not supported in python2. Just update.')
lief_parsed = None
else:
lief_parsed = lief.parse(raw=pseudofile.getvalue(), name=filename)
2017-08-25 17:41:58 +02:00
if isinstance(lief_parsed, lief.PE.Binary):
2017-12-20 14:27:31 +01:00
return make_pe_objects(lief_parsed, misp_file, standalone, default_attributes_parameters)
2017-08-25 17:41:58 +02:00
elif isinstance(lief_parsed, lief.ELF.Binary):
2017-12-20 14:27:31 +01:00
return make_elf_objects(lief_parsed, misp_file, standalone, default_attributes_parameters)
2017-08-25 17:41:58 +02:00
elif isinstance(lief_parsed, lief.MachO.Binary):
2017-12-20 14:27:31 +01:00
return make_macho_objects(lief_parsed, misp_file, standalone, default_attributes_parameters)
2017-08-25 17:41:58 +02:00
except lief.bad_format as e:
logger.warning('Bad format: {}'.format(e))
2017-08-25 17:41:58 +02:00
except lief.bad_file as e:
logger.warning('Bad file: {}'.format(e))
except lief.conversion_error as e:
logger.warning('Conversion file: {}'.format(e))
except lief.builder_error as e:
logger.warning('Builder file: {}'.format(e))
2017-08-25 17:41:58 +02:00
except lief.parser_error as e:
logger.warning('Parser error: {}'.format(e))
except lief.integrity_error as e:
logger.warning('Integrity error: {}'.format(e))
except lief.pe_error as e:
logger.warning('PE error: {}'.format(e))
except lief.type_error as e:
logger.warning('Type error: {}'.format(e))
except lief.exception as e:
logger.warning('Lief exception: {}'.format(e))
except FileTypeNotImplemented as e:
logger.warning(e)
if not HAS_LIEF:
logger.warning('Please install lief, documentation here: https://github.com/lief-project/LIEF')
return misp_file, None, []