2016-03-25 11:02:32 +01:00
|
|
|
import json
|
|
|
|
import pypdns
|
2019-12-17 11:18:21 +01:00
|
|
|
from pymisp import MISPAttribute, MISPEvent, MISPObject
|
2016-03-25 11:02:32 +01:00
|
|
|
|
2020-06-03 11:12:47 +02:00
|
|
|
mispattributes = {'input': ['hostname', 'domain', 'ip-src', 'ip-dst', 'ip-src|port', 'ip-dst|port'], 'format': 'misp_standard'}
|
2019-12-17 11:18:21 +01:00
|
|
|
moduleinfo = {'version': '0.2', 'author': 'Alexandre Dulaunoy',
|
|
|
|
'description': 'Module to access CIRCL Passive DNS',
|
|
|
|
'module-type': ['expansion', 'hover']}
|
2016-03-25 11:02:32 +01:00
|
|
|
moduleconfig = ['username', 'password']
|
|
|
|
|
|
|
|
|
2019-12-17 11:18:21 +01:00
|
|
|
class PassiveDNSParser():
|
|
|
|
def __init__(self, attribute, authentication):
|
|
|
|
self.misp_event = MISPEvent()
|
|
|
|
self.attribute = MISPAttribute()
|
|
|
|
self.attribute.from_dict(**attribute)
|
|
|
|
self.misp_event.add_attribute(**self.attribute)
|
|
|
|
self.pdns = pypdns.PyPDNS(basic_auth=authentication)
|
|
|
|
|
|
|
|
def get_results(self):
|
|
|
|
if hasattr(self, 'result'):
|
|
|
|
return self.result
|
|
|
|
event = json.loads(self.misp_event.to_json())
|
2019-12-17 14:29:29 +01:00
|
|
|
results = {key: event[key] for key in ('Attribute', 'Object')}
|
2019-12-17 11:18:21 +01:00
|
|
|
return {'results': results}
|
|
|
|
|
2020-06-03 11:12:47 +02:00
|
|
|
def parse(self):
|
|
|
|
value = self.attribute.value.split('|')[0] if '|' in self.attribute.type else self.attribute.value
|
|
|
|
|
2019-12-17 11:18:21 +01:00
|
|
|
try:
|
2020-06-03 11:12:47 +02:00
|
|
|
results = self.pdns.query(value)
|
2019-12-17 11:18:21 +01:00
|
|
|
except Exception:
|
|
|
|
self.result = {'error': 'There is an authentication error, please make sure you supply correct credentials.'}
|
|
|
|
return
|
2020-06-03 10:48:43 +02:00
|
|
|
|
|
|
|
if not results:
|
|
|
|
self.result = {'error': 'Not found'}
|
|
|
|
return
|
|
|
|
|
2019-12-17 11:18:21 +01:00
|
|
|
mapping = {'count': 'counter', 'origin': 'text',
|
|
|
|
'time_first': 'datetime', 'rrtype': 'text',
|
|
|
|
'rrname': 'text', 'rdata': 'text',
|
|
|
|
'time_last': 'datetime'}
|
|
|
|
for result in results:
|
|
|
|
pdns_object = MISPObject('passive-dns')
|
|
|
|
for relation, attribute_type in mapping.items():
|
|
|
|
pdns_object.add_attribute(relation, type=attribute_type, value=result[relation])
|
|
|
|
pdns_object.add_reference(self.attribute.uuid, 'associated-to')
|
|
|
|
self.misp_event.add_object(**pdns_object)
|
|
|
|
|
|
|
|
|
2016-03-25 11:02:32 +01:00
|
|
|
def handler(q=False):
|
|
|
|
if q is False:
|
|
|
|
return False
|
|
|
|
request = json.loads(q)
|
2019-12-17 11:18:21 +01:00
|
|
|
if not request.get('config'):
|
|
|
|
return {'error': 'CIRCL Passive DNS authentication is missing.'}
|
|
|
|
if not request['config'].get('username') or not request['config'].get('password'):
|
|
|
|
return {'error': 'CIRCL Passive DNS authentication is incomplete, please provide your username and password.'}
|
|
|
|
authentication = (request['config']['username'], request['config']['password'])
|
|
|
|
if not request.get('attribute'):
|
|
|
|
return {'error': 'Unsupported input.'}
|
|
|
|
attribute = request['attribute']
|
|
|
|
if not any(input_type == attribute['type'] for input_type in mispattributes['input']):
|
|
|
|
return {'error': 'Unsupported attributes type'}
|
|
|
|
pdns_parser = PassiveDNSParser(attribute, authentication)
|
2020-06-03 11:12:47 +02:00
|
|
|
pdns_parser.parse()
|
2019-12-17 11:18:21 +01:00
|
|
|
return pdns_parser.get_results()
|
2016-03-25 11:02:32 +01:00
|
|
|
|
|
|
|
|
|
|
|
def introspection():
|
|
|
|
return mispattributes
|
|
|
|
|
|
|
|
|
|
|
|
def version():
|
|
|
|
moduleinfo['config'] = moduleconfig
|
|
|
|
return moduleinfo
|